last sync: 2021-Sep-22 19:36:53 UTC

Azure RBAC Role definition

Log Analytics Contributor

NameLog Analytics Contributor
Microsoft docs
Id92aaf0da-9dab-42b6-94a3-d43ce8d16293
DescriptionLog Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; adding solutions; and configuring Azure diagnostics on all Azure resources.
CreatedOn2017-04-25 21:51:45 UTC
UpdatedOn2021-08-05 16:47:17 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2021-08-06 15:06:08 change: Description, Actions New Description: 'Log Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; adding solutions; and configuring Azure diagnostics on all Azure resources.'
Old Description: 'Log Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; creating and configuring Automation accounts; adding solutions; and configuring Azure diagnostics on all Azure resources.',
Actions: 'remove Microsoft.Automation/automationAccounts/*'
Actions
Operation Description Used in other Roles
*/readno description given Log Analytics Reader, Managed Application Contributor Role, Managed Application Operator Role , Managed Applications Reader, Monitoring Contributor, Monitoring Reader, Reader, Resource Policy Contributor, User Access Administrator
Microsoft.ClassicCompute/virtualMachines/extensions/*no description given none
Microsoft.ClassicStorage/storageAccounts/listKeys/actionLists the access keys for the storage accounts. Classic Storage Account Key Operator Service Role, Classic Virtual Machine Contributor, Logic App Contributor
Microsoft.Compute/virtualMachines/extensions/*no description given none
Microsoft.HybridCompute/machines/extensions/writeInstalls or Updates an Azure Arc extensions Azure Connected Machine Resource Administrator
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Kubernetes Extension Contributor, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Insights/diagnosticSettings/*no description given Automation Contributor, Cognitive Services Contributor, Logic App Contributor , Monitoring Contributor, Storage Account Contributor
Microsoft.OperationalInsights/*no description given none
Microsoft.OperationsManagement/*no description given none
Microsoft.Resources/deployments/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Kubernetes Service Contributor Role, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, CodeSigning Certificate Profile Signer, Cognitive Services Contributor, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Operator, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, Disk Pool Operator, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Extension Contributor, Logic App Contributor, Managed Application Contributor Role, Managed Applications Reader, Managed Identity Contributor, Managed Identity Operator, Media Services Account Administrator, Media Services Live Events Administrator, Media Services Media Operator, Media Services Policy Administrator, Media Services Streaming Endpoints Administrator, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Services Hub Operator, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/subscriptions/resourcegroups/deployments/*no description given Cognitive Services Contributor
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account. DevTest Labs User, Disk Snapshot Contributor, Logic App Contributor , Reader and Data Access, Storage Account Key Operator Service Role, Virtual Machine Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Group Contributor, Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Contributor, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Reader, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Collaborative Runtime Operator, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Desktop Virtualization Application Group Contributor, Desktop Virtualization Application Group Reader, Desktop Virtualization Contributor, Desktop Virtualization Host Pool Contributor, Desktop Virtualization Host Pool Reader, Desktop Virtualization Reader, Desktop Virtualization Session Host Operator, Desktop Virtualization User Session Operator, Desktop Virtualization Workspace Contributor, Desktop Virtualization Workspace Reader, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator, Key Vault Certificates Officer, Key Vault Contributor, Key Vault Crypto Officer, Key Vault Reader, Key Vault Secrets Officer, Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Quota Request Operator, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR/Web PubSub Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in Policy
Policy DisplayName Policy Id Category State
[Deprecated]: Deploy default Log Analytics Agent for Ubuntu VMs 3d8640fc-63f6-4734-8dcb-cfd3d8c78f38 Compute Deprecated
[Preview]: Configure Azure Arc enabled Kubernetes clusters to install Azure Defender's extension 708b60a6-d253-4fe0-9114-4be4c00f012c Kubernetes Preview
[Preview]: Configure Azure Kubernetes Service clusters to enable Azure Defender profile 64def556-fbad-4622-930e-72d1d5589bf5 Kubernetes Preview
[Preview]: Configure supported Linux Arc machines to automatically install the Azure Security agent 2f47ec78-4301-4655-b78e-b29377030cdc Security Center Preview
[Preview]: Configure supported Windows Arc machines to automatically install the Azure Security agent d01f3018-de9f-4d75-8dae-d12c1875da9f Security Center Preview
Configure Arc-enabled machines running SQL Server to have SQL Server extension installed. fd2d1a6e-6d95-4df2-ad00-504bf0273406 SQL GA
Configure Azure Activity logs to stream to specified Log Analytics workspace 2465583e-4e78-4c15-b6be-a36cbc7c8b0f Monitoring GA
Configure Azure Log Analytics workspaces to disable public network access for log ingestion and querying d3ba9c42-9dd5-441a-957c-274031c750c0 Monitoring GA
Configure Azure SQL database servers diagnostic settings to Log Analytics workspace 7ea8a143-05e3-4553-abfe-f56bef8b0b70 SQL GA
Configure Dependency agent on Azure Arc enabled Linux servers deacecc0-9f84-44d2-bb82-46f32d766d43 Monitoring GA
Configure Dependency agent on Azure Arc enabled Windows servers 91cb9edd-cd92-4d2f-b2f2-bdd8d065a3d4 Monitoring GA
Configure diagnostic settings for storage accounts to Log Analytics workspace 6f8f98a4-f108-47cb-8e98-91a0d85cd474 Storage GA
Configure Log Analytics agent on Azure Arc enabled Linux servers 9d2b61b4-1d14-4a63-be30-d4498e7ad2cf Monitoring GA
Configure Log Analytics agent on Azure Arc enabled Windows servers 69af7d4a-7b18-4044-93a9-2651498ef203 Monitoring GA
Deploy - Configure Dependency agent to be enabled on Windows virtual machines 1c210e94-a481-4beb-95fa-1571b434fb04 Monitoring GA
Deploy - Configure diagnostic settings for Azure Key Vault to Log Analytics workspace 951af2fa-529b-416e-ab6e-066fd85ac459 Key Vault GA
Deploy - Configure diagnostic settings for Azure Kubernetes Service to Log Analytics workspace 6c66c325-74c8-42fd-a286-a74b0e2939d8 Kubernetes GA
Deploy - Configure diagnostic settings for SQL Databases to Log Analytics workspace b79fa14e-238a-4c2d-b376-442ce508fc84 SQL GA
Deploy - Configure diagnostic settings to a Log Analytics workspace to be enabled on Azure Key Vault Managed HSM b3884c81-31aa-473d-a9bb-9466fe0ec2a0 Monitoring GA
Deploy - Configure Log Analytics agent to be enabled on Windows virtual machine scale sets 3c1b3629-c8f8-4bf6-862c-037cb9094038 Monitoring GA
Deploy - Configure Log Analytics agent to be enabled on Windows virtual machines 0868462e-646c-4fe3-9ced-a733534b6a2c Monitoring GA
Deploy Dependency agent for Linux virtual machines 4da21710-ce6f-4e06-8cdb-5cc4c93ffbee Monitoring GA
Deploy Diagnostic Settings for Batch Account to Log Analytics workspace c84e5349-db6d-4769-805e-e14037dab9b5 Monitoring GA
Deploy Diagnostic Settings for Data Lake Analytics to Log Analytics workspace d56a5a7c-72d7-42bc-8ceb-3baf4c0eae03 Monitoring GA
Deploy Diagnostic Settings for Data Lake Storage Gen1 to Log Analytics workspace 25763a0a-5783-4f14-969e-79d4933eb74b Monitoring GA
Deploy Diagnostic Settings for Event Hub to Log Analytics workspace 1f6e93e8-6b31-41b1-83f6-36e449a42579 Monitoring GA
Deploy Diagnostic Settings for Key Vault to Log Analytics workspace bef3f64c-5290-43b7-85b0-9b254eef4c47 Monitoring GA
Deploy Diagnostic Settings for Logic Apps to Log Analytics workspace b889a06c-ec72-4b03-910a-cb169ee18721 Monitoring GA
Deploy Diagnostic Settings for Recovery Services Vault to Log Analytics workspace for resource specific categories. c717fb0c-d118-4c43-ab3d-ece30ac81fb3 Backup GA
Deploy Diagnostic Settings for Search Services to Log Analytics workspace 08ba64b8-738f-4918-9686-730d2ed79c7d Monitoring GA
Deploy Diagnostic Settings for Service Bus to Log Analytics workspace 04d53d87-841c-4f23-8a5b-21564380b55e Monitoring GA
Deploy Diagnostic Settings for Stream Analytics to Log Analytics workspace 237e0f7e-b0e8-4ec4-ad46-8c12cb66d673 Monitoring GA
Deploy Log Analytics agent for Linux virtual machine scale sets 5ee9e9ed-0b42-41b7-8c9c-3cfb2fbe2069 Monitoring GA
Deploy Log Analytics agent for Linux VMs 053d3325-282c-4e5c-b944-24faffd30d77 Monitoring GA
Public IP addresses should have resource logs enabled for Azure DDoS Protection Standard 752154a7-1e0f-45c6-a880-ac75a7e4f648 Monitoring GA
JSON
{
  "Name": "Log Analytics Contributor",
  "Id": "92aaf0da-9dab-42b6-94a3-d43ce8d16293",
  "IsCustom": false,
  "Description": "Log Analytics Contributor can read all monitoring data and edit monitoring settings. Editing monitoring settings includes adding the VM extension to VMs; reading storage account keys to be able to configure collection of logs from Azure Storage; adding solutions; and configuring Azure diagnostics on all Azure resources.",
  "Actions": [
    "*/read",
    "Microsoft.ClassicCompute/virtualMachines/extensions/*",
    "Microsoft.ClassicStorage/storageAccounts/listKeys/action",
    "Microsoft.Compute/virtualMachines/extensions/*",
    "Microsoft.HybridCompute/machines/extensions/write",
    "Microsoft.Insights/alertRules/*",
    "Microsoft.Insights/diagnosticSettings/*",
    "Microsoft.OperationalInsights/*",
    "Microsoft.OperationsManagement/*",
    "Microsoft.Resources/deployments/*",
    "Microsoft.Resources/subscriptions/resourcegroups/deployments/*",
    "Microsoft.Storage/storageAccounts/listKeys/action",
    "Microsoft.Support/*"
  ],
  "NotActions": [],
  "DataActions": [],
  "NotDataActions": [],
  "AssignableScopes": [
    "/"
  ]
}