Azure Monitor built-in role

Workbook Reader

Reads Azure Workbook resources, their revisions, and workbook templates without saving or deleting them. The role is control-plane only and has no DataActions; viewing query results still depends on access to each referenced resource and data source.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: b279062a-9be3-42a0-92ae-8b3cf002ec4d

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the resource group containing the shared workbooks the principal must view. A broader assignment is inherited by workbook resources in every child scope.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Workbook Reader on the resource group containing the shared workbooks the principal consumes. Grant data-source access separately and elevate to Workbook Contributor only for approved authoring or deletion duties.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →