last sync: 2022-May-23 08:52:49 UTC

Azure RBAC Role definition

Log Analytics Contributor

NameLog Analytics Contributor
Microsoft docs
Id92aaf0da-9dab-42b6-94a3-d43ce8d16293
DescriptionLog Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; adding solutions; and configuring Azure diagnostics on all Azure resources.
CreatedOn2017-04-25 21:51:45 UTC
UpdatedOn2021-11-11 20:13:37 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2021-08-06 15:06:08 change: Description, Actions New Description: 'Log Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; adding solutions; and configuring Azure diagnostics on all Azure resources.'
Old Description: 'Log Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; creating and configuring Automation accounts; adding solutions; and configuring Azure diagnostics on all Azure resources.',
Actions: 'remove Microsoft.Automation/automationAccounts/*'
Actions
Operation Description Used in other Roles
*/readno description given Log Analytics Reader, Managed Application Contributor Role, Managed Application Operator Role , Managed Applications Reader, Monitoring Contributor, Monitoring Reader, Reader, Resource Policy Contributor, User Access Administrator
Microsoft.ClassicCompute/virtualMachines/extensions/*no description given none
Microsoft.ClassicStorage/storageAccounts/listKeys/actionLists the access keys for the storage accounts. Classic Storage Account Key Operator Service Role, Classic Virtual Machine Contributor, Logic App Contributor
Microsoft.Compute/virtualMachines/extensions/*no description given none
Microsoft.HybridCompute/machines/extensions/writeInstalls or Updates an Azure Arc extensions Azure Connected Machine Resource Administrator
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Load Test Contributor, Load Test Owner, Load Test Reader, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Insights/diagnosticSettings/*no description given Automation Contributor, Cognitive Services Contributor, Logic App Contributor , Monitoring Contributor, Storage Account Contributor
Microsoft.OperationalInsights/*no description given none
Microsoft.OperationsManagement/*no description given none
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Connected Machine Resource Administrator, Azure Kubernetes Service Contributor Role, Azure Kubernetes Service Policy Add-on Deployment, Azure Maps Contributor, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Chamber Admin, Chamber User, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, CodeSigning Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, DevCenter Project Admin, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Resolver Contributor, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, Guest Configuration Resource Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Lab Assistant, Lab Contributor, Lab Creator, Lab Operator, Lab Services Contributor, Lab Services Reader, Load Test Contributor, Load Test Owner, Load Test Reader, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Network Contributor, New Relic APM Account Contributor, PlayFab Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourcegroups/deployments/*no description given Cognitive Services Contributor
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account. DevTest Labs User, Disk Snapshot Contributor, Logic App Contributor , Reader and Data Access, Storage Account Key Operator Service Role, Virtual Machine Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Microsoft Sentinel Contributor, Microsoft Sentinel Reader, Microsoft Sentinel Responder, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
[Deprecated]: Deploy default Log Analytics Extension for Ubuntu VMs 3d8640fc-63f6-4734-8dcb-cfd3d8c78f38 Compute Deprecated
[Preview]: Configure Azure Arc enabled Kubernetes clusters to install Microsoft Defender for Cloud extension 708b60a6-d253-4fe0-9114-4be4c00f012c Kubernetes Preview
[Preview]: Configure Azure Kubernetes Service clusters to enable Defender profile 64def556-fbad-4622-930e-72d1d5589bf5 Kubernetes Preview
[Preview]: Configure ChangeTracking Extension for Linux Arc machines 10caed8a-652c-4d1d-84e4-2805b7c07278 Security Center Preview
[Preview]: Configure ChangeTracking Extension for Windows Arc machines 4bb303db-d051-4099-95d2-e3e1428a4cd5 Security Center Preview
[Preview]: Configure supported Linux Arc machines to automatically install the Azure Security agent 2f47ec78-4301-4655-b78e-b29377030cdc Security Center Preview
[Preview]: Configure supported Windows Arc machines to automatically install the Azure Security agent d01f3018-de9f-4d75-8dae-d12c1875da9f Security Center Preview
Configure Arc-enabled machines running SQL Server to have SQL Server extension installed. fd2d1a6e-6d95-4df2-ad00-504bf0273406 SQL GA
Configure Azure Activity logs to stream to specified Log Analytics workspace 2465583e-4e78-4c15-b6be-a36cbc7c8b0f Monitoring GA
Configure Azure Log Analytics workspaces to disable public network access for log ingestion and querying d3ba9c42-9dd5-441a-957c-274031c750c0 Monitoring GA
Configure Azure SQL database servers diagnostic settings to Log Analytics workspace 7ea8a143-05e3-4553-abfe-f56bef8b0b70 SQL GA
Configure Dependency agent on Azure Arc enabled Linux servers deacecc0-9f84-44d2-bb82-46f32d766d43 Monitoring GA
Configure Dependency agent on Azure Arc enabled Windows servers 91cb9edd-cd92-4d2f-b2f2-bdd8d065a3d4 Monitoring GA
Configure diagnostic settings for Azure Network Security Groups to Log Analytics workspace 98a2e215-5382-489e-bd29-32e7190a39ba Network GA
Configure diagnostic settings for storage accounts to Log Analytics workspace 6f8f98a4-f108-47cb-8e98-91a0d85cd474 Storage GA
Configure Linux Arc Machines to be associated with a Data Collection Rule d5c37ce1-5f52-4523-b949-f19bf945b73a Monitoring GA
Configure Linux Machines to be associated with a Data Collection Rule 2ea82cdd-f2e8-4500-af75-67a2e084ca74 Monitoring GA
Configure Linux Virtual Machine Scale Sets to be associated with a Data Collection Rule 050a90d5-7cce-483f-8f6c-0df462036dda Monitoring GA
Configure Linux Virtual Machines to be associated with a Data Collection Rule 58e891b9-ce13-4ac3-86e4-ac3e1f20cb07 Monitoring GA
Configure Log Analytics extension on Azure Arc enabled Linux servers 9d2b61b4-1d14-4a63-be30-d4498e7ad2cf Monitoring GA
Configure Log Analytics extension on Azure Arc enabled Windows servers 69af7d4a-7b18-4044-93a9-2651498ef203 Monitoring GA
Configure SQL servers to have auditing enabled to Log Analytics workspace 25da7dfb-0666-4a15-a8f5-402127efd8bb SQL GA
Configure Synapse workspaces to have auditing enabled to Log Analytics workspace 32ba8d30-07c0-4136-ab18-9a11bf4a67b7 Synapse GA
Configure Windows Arc Machines to be associated with a Data Collection Rule c24c537f-2516-4c2f-aac5-2cd26baa3d26 Monitoring GA
Configure Windows Machines to be associated with a Data Collection Rule eab1f514-22e3-42e3-9a1f-e1dc9199355c Monitoring GA
Configure Windows Virtual Machine Scale Sets to be associated with a Data Collection Rule 0a3b9bf4-d30e-424a-af6b-9a93f6f78792 Monitoring GA
Configure Windows Virtual Machines to be associated with a Data Collection Rule 244efd75-0d92-453c-b9a3-7d73ca36ed52 Monitoring GA
Deploy - Configure Dependency agent to be enabled on Windows virtual machines 1c210e94-a481-4beb-95fa-1571b434fb04 Monitoring GA
Deploy - Configure diagnostic settings for Azure Key Vault to Log Analytics workspace 951af2fa-529b-416e-ab6e-066fd85ac459 Key Vault GA
Deploy - Configure diagnostic settings for Azure Kubernetes Service to Log Analytics workspace 6c66c325-74c8-42fd-a286-a74b0e2939d8 Kubernetes GA
Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace b79fa14e-238a-4c2d-b376-442ce508fc84 SQL GA
Deploy - Configure diagnostic settings to a Log Analytics workspace to be enabled on Azure Key Vault Managed HSM b3884c81-31aa-473d-a9bb-9466fe0ec2a0 Monitoring GA
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machine scale sets 3c1b3629-c8f8-4bf6-862c-037cb9094038 Monitoring GA
Deploy - Configure Log Analytics extension to be enabled on Windows virtual machines 0868462e-646c-4fe3-9ced-a733534b6a2c Monitoring GA
Deploy Dependency agent for Linux virtual machines 4da21710-ce6f-4e06-8cdb-5cc4c93ffbee Monitoring GA
Deploy Diagnostic Settings for Batch Account to Log Analytics workspace c84e5349-db6d-4769-805e-e14037dab9b5 Monitoring GA
Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace d56a5a7c-72d7-42bc-8ceb-3baf4c0eae03 Monitoring GA
Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace 25763a0a-5783-4f14-969e-79d4933eb74b Monitoring GA
Deploy Diagnostic Settings for Event Hub to Log Analytics workspace 1f6e93e8-6b31-41b1-83f6-36e449a42579 Monitoring GA
Deploy Diagnostic Settings for Key Vault to Log Analytics workspace bef3f64c-5290-43b7-85b0-9b254eef4c47 Monitoring GA
Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace b889a06c-ec72-4b03-910a-cb169ee18721 Monitoring GA
Deploy Diagnostic Settings for Recovery Services Vault to Log Analytics workspace for resource specific categories. c717fb0c-d118-4c43-ab3d-ece30ac81fb3 Backup GA
Deploy Diagnostic Settings for Search Services to Log Analytics workspace 08ba64b8-738f-4918-9686-730d2ed79c7d Monitoring GA
Deploy Diagnostic Settings for Service Bus to Log Analytics workspace 04d53d87-841c-4f23-8a5b-21564380b55e Monitoring GA
Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace 237e0f7e-b0e8-4ec4-ad46-8c12cb66d673 Monitoring GA
Deploy Log Analytics extension for Linux virtual machine scale sets 5ee9e9ed-0b42-41b7-8c9c-3cfb2fbe2069 Monitoring GA
Deploy Log Analytics extension for Linux VMs 053d3325-282c-4e5c-b944-24faffd30d77 Monitoring GA
Public IP addresses should have resource logs enabled for Azure DDoS Protection Standard 752154a7-1e0f-45c6-a880-ac75a7e4f648 Monitoring GA
JSON