Azure Monitor built-in role
Workbook Contributor
Creates, updates, reads, and deletes shared Azure Workbooks and workbook templates. The role is control-plane only and has no DataActions; workbook access does not itself grant access to the data sources referenced by a workbook.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: e8ddcd69-c73f-4f9f-9844-4100522f16ad
Control-plane actions (7)
Microsoft.Insights/workbooks/writeMicrosoft.Insights/workbooks/deleteMicrosoft.Insights/workbooks/readMicrosoft.Insights/workbooks/revisions/readMicrosoft.Insights/workbooktemplates/writeMicrosoft.Insights/workbooktemplates/deleteMicrosoft.Insights/workbooktemplates/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the parent resource group where the shared workbook is saved. Microsoft states that workbooks are shared Azure resources and require write access to their parent resource group.
Common use cases (2)
- Create, edit, save, share, and delete an Azure Workbook in an approved resource group.
- Create or maintain shared workbook templates for an operations or application team.
Prerequisites (2)
- Select the subscription, resource group, location, and owner resource where the workbook will be saved.
- Grant the author separate access to every metric, log, resource, or other data source used by the workbook.
Best practices (3)
- Assign at the workbook's resource group rather than a broader subscription when the author manages only that workbook collection.
- Keep workbook authoring permission separate from access to referenced resources and data sources.
- Use workbook version history and the recycle bin for supported recovery, and account for the documented exceptions for bring-your-own-storage workbooks.
Security considerations (3)
- The role can change or delete shared workbooks and templates used by other operators.
- Workbook definitions can contain queries, resource references, links, and presentation logic, but the role has no DataActions for the referenced data.
- A shared workbook recipient still requires read permission on both the workbook resource and every referenced resource.
Assignment guidance
Assign Workbook Contributor on the resource group where the approved shared workbook or template is stored. Grant source-data access separately and use Workbook Reader for consumers who do not author or delete workbook resources.
Related roles (2)
- Workbook Reader: Read-only role for viewing workbook and template resources without saving or deleting them.
- Monitoring Contributor: Microsoft documents Monitoring Contributor as also including workbook write permission within its broader monitoring role.
Editorial sources (6)
- Azure built-in roles for Monitor →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Azure Workbooks →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Manage Azure Monitor Workbooks →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.