Azure Monitor built-in role
Workbook Reader
Reads Azure Workbook resources, their revisions, and workbook templates without saving or deleting them. The role is control-plane only and has no DataActions; viewing query results still depends on access to each referenced resource and data source.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: b279062a-9be3-42a0-92ae-8b3cf002ec4d
Control-plane actions (3)
microsoft.insights/workbooks/readmicrosoft.insights/workbooks/revisions/readmicrosoft.insights/workbooktemplates/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the resource group containing the shared workbooks the principal must view. A broader assignment is inherited by workbook resources in every child scope.
Common use cases (2)
- View and share links to approved Azure Workbooks without changing their saved definitions.
- Consume interactive reports backed by metrics, logs, and other data sources for which the principal already has access.
Prerequisites (2)
- The principal needs at least reader permission for the workbook resource and every resource referenced by the workbook.
- The workbook must be saved in a resource group visible to the principal; private browser autosaves are not shared Azure resources.
Best practices (3)
- Use Workbook Reader for report consumers instead of Workbook Contributor when no authoring or deletion is required.
- Assign at the workbook resource group and grant referenced-resource access separately at its own narrow scope.
- Review workbook sharing links together with the Azure RBAC assignments that make the workbook and its data visible.
Security considerations (3)
- Workbook definitions can reveal resource names, queries, parameters, and operational context even when the principal cannot edit them.
- The role alone does not grant access to referenced metric, log, or application data.
- A broad parent-scope assignment exposes every inherited workbook and template in that scope.
Assignment guidance
Assign Workbook Reader on the resource group containing the shared workbooks the principal consumes. Grant data-source access separately and elevate to Workbook Contributor only for approved authoring or deletion duties.
Related roles (2)
- Workbook Contributor: Adds workbook and template create, update, and delete authority.
- Monitoring Reader: Microsoft documents Monitoring Reader as another standard role that provides workbook read access together with broader monitoring visibility.
Editorial sources (6)
- Azure built-in roles for Monitor →
Supports: Description, Security considerations, Related roles. Retrieved 2026-07-16.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-16.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-16.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-16.
- Azure Workbooks →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-16.
- Manage Azure Monitor Workbooks →
Supports: Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-16.