Skip to content

Commit c166376

Browse files
committed
Add Grafana Limited Viewer role
1 parent 1463d06 commit c166376

File tree

4 files changed

+47
-4
lines changed

4 files changed

+47
-4
lines changed

articles/managed-grafana/concept-role-based-access-control.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,12 @@ The following built-in roles are available in Azure Managed Grafana, each provid
2525
> | --- | --- | --- |
2626
> | <a name='grafana-admin'></a>[Grafana Admin](../role-based-access-control/built-in-roles/monitor.md#grafana-admin) | Perform all Grafana operations, including the ability to manage data sources, create dashboards, and manage role assignments within Grafana. | 22926164-76b3-42b3-bc55-97df8dab3e41 |
2727
> | <a name='grafana-editor'></a>[Grafana Editor](../role-based-access-control/built-in-roles/monitor.md#grafana-editor) | View and edit a Grafana instance, including its dashboards and alerts. | a79a5197-3a5c-4973-a920-486035ffd60f |
28+
> | <a name='grafana-limited-viewer'></a>[Grafana Limited Viewer](../role-based-access-control/built-in-roles/monitor.md#grafana-limited-viwer) | View a Grafana home page. | 41e04612-9dac-4699-a02b-c82ff2cc3fb5 |
2829
> | <a name='grafana-viewer'></a>[Grafana Viewer](../role-based-access-control/built-in-roles/monitor.md#grafana-viewer) | View a Grafana instance, including its dashboards and alerts. | 60921a7e-fef1-4a43-9b16-a26c52ad4769 |
2930
3031
To access the Grafana user interface, users must possess one of these roles.
3132

32-
These permissions are included within the broader roles of resource group Contributor and resource group Owner roles. If you're not a resource group Contributor or resource group Owner, a User Access Administrator, you will need to ask a subscription Owner or resource group Owner to grant you one of the Grafana roles on the resource you want to access.
33+
These permissions are included within the broader roles of resource group Contributor and resource group Owner roles. If you're not a resource group Contributor or a resource group Owner, you will need to ask a subscription Owner or resource group Owner to grant you one of the Grafana roles on the resource you want to access.
3334

3435
## Adding a role assignment to an Azure Managed Grafana resource
3536

articles/role-based-access-control/built-in-roles.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -391,6 +391,7 @@ The following table provides a brief description of each built-in role. Click th
391391
> | <a name='application-insights-snapshot-debugger'></a>[Application Insights Snapshot Debugger](./built-in-roles/monitor.md#application-insights-snapshot-debugger) | Gives user permission to view and download debug snapshots collected with the Application Insights Snapshot Debugger. Note that these permissions are not included in the [Owner](/azure/role-based-access-control/built-in-roles#owner) or [Contributor](/azure/role-based-access-control/built-in-roles#contributor) roles. When giving users the Application Insights Snapshot Debugger role, you must grant the role directly to the user. The role is not recognized when it is added to a custom role. | 08954f03-6346-4c2e-81c0-ec3a5cfae23b |
392392
> | <a name='grafana-admin'></a>[Grafana Admin](./built-in-roles/monitor.md#grafana-admin) | Perform all Grafana operations, including the ability to manage data sources, create dashboards, and manage role assignments within Grafana. | 22926164-76b3-42b3-bc55-97df8dab3e41 |
393393
> | <a name='grafana-editor'></a>[Grafana Editor](./built-in-roles/monitor.md#grafana-editor) | View and edit a Grafana instance, including its dashboards and alerts. | a79a5197-3a5c-4973-a920-486035ffd60f |
394+
> | <a name='grafana-editor'></a>[Grafana Editor](./built-in-roles/monitor.md#grafana-limited-viewer) | View home page. | 41e04612-9dac-4699-a02b-c82ff2cc3fb5 |
394395
> | <a name='grafana-viewer'></a>[Grafana Viewer](./built-in-roles/monitor.md#grafana-viewer) | View a Grafana instance, including its dashboards and alerts. | 60921a7e-fef1-4a43-9b16-a26c52ad4769 |
395396
> | <a name='monitoring-contributor'></a>[Monitoring Contributor](./built-in-roles/monitor.md#monitoring-contributor) | Can read all monitoring data and edit monitoring settings. See also [Get started with roles, permissions, and security with Azure Monitor](/azure/azure-monitor/roles-permissions-security#built-in-monitoring-roles). | 749f88d5-cbae-40b8-bcfc-e573ddc772fa |
396397
> | <a name='monitoring-metrics-publisher'></a>[Monitoring Metrics Publisher](./built-in-roles/monitor.md#monitoring-metrics-publisher) | Enables publishing metrics against Azure resources | 3913510d-42f4-4e42-8a64-420c390055eb |

articles/role-based-access-control/built-in-roles/monitor.md

Lines changed: 43 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -136,7 +136,7 @@ Gives user permission to view and download debug snapshots collected with the Ap
136136

137137
Perform all Grafana operations, including the ability to manage data sources, create dashboards, and manage role assignments within Grafana.
138138

139-
[Learn more](/azure/managed-grafana/how-to-share-grafana-workspace)
139+
[Learn more](/azure/managed-grafana/concept-role-based-access-control)
140140

141141
> [!div class="mx-tableFixed"]
142142
> | Actions | Description |
@@ -177,7 +177,7 @@ Perform all Grafana operations, including the ability to manage data sources, cr
177177

178178
View and edit a Grafana instance, including its dashboards and alerts.
179179

180-
[Learn more](/azure/managed-grafana/how-to-share-grafana-workspace)
180+
[Learn more](/azure/managed-grafana/concept-role-based-access-control)
181181

182182
> [!div class="mx-tableFixed"]
183183
> | Actions | Description |
@@ -214,11 +214,51 @@ View and edit a Grafana instance, including its dashboards and alerts.
214214
}
215215
```
216216

217+
## Grafana Limited Viewer
218+
219+
View a Grafana home page.
220+
221+
[Learn more](/azure/managed-grafana/concept-role-based-access-control)
222+
223+
> [!div class="mx-tableFixed"]
224+
> | Actions | Description |
225+
> | --- | --- |
226+
> | *none* | |
227+
> | **NotActions** | |
228+
> | *none* | |
229+
> | **DataActions** | |
230+
> | [Microsoft.Dashboard](../permissions/monitor.md#microsoftdashboard)/grafana/ActAsGrafanaLimitedViewer/action | Act as Grafana Limited Viewer role |
231+
> | **NotDataActions** | |
232+
> | *none* | |
233+
234+
```json
235+
{
236+
"id": "/providers/Microsoft.Authorization/roleDefinitions/41e04612-9dac-4699-a02b-c82ff2cc3fb5",
237+
"properties": {
238+
"roleName": "Grafana Limited Viewer",
239+
"description": "View home page.",
240+
"assignableScopes": [
241+
"/"
242+
],
243+
"permissions": [
244+
{
245+
"actions": [],
246+
"notActions": [],
247+
"dataActions": [
248+
"Microsoft.Dashboard/grafana/ActAsGrafanaLimitedViewer/action"
249+
],
250+
"notDataActions": []
251+
}
252+
]
253+
}
254+
}
255+
```
256+
217257
## Grafana Viewer
218258

219259
View a Grafana instance, including its dashboards and alerts.
220260

221-
[Learn more](/azure/managed-grafana/how-to-share-grafana-workspace)
261+
[Learn more](/azure/managed-grafana/concept-role-based-access-control)
222262

223263
> [!div class="mx-tableFixed"]
224264
> | Actions | Description |

articles/role-based-access-control/permissions/monitor.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,7 @@ Azure service: [Azure Managed Grafana](/azure/managed-grafana/)
8989
> | **DataAction** | **Description** |
9090
> | Microsoft.Dashboard/grafana/ActAsGrafanaAdmin/action | Act as Grafana Admin role |
9191
> | Microsoft.Dashboard/grafana/ActAsGrafanaEditor/action | Act as Grafana Editor role |
92+
> | Microsoft.Dashboard/grafana/ActAsGrafanaLimitedViewer/action | Act as Grafana Viewer role |
9293
> | Microsoft.Dashboard/grafana/ActAsGrafanaViewer/action | Act as Grafana Viewer role |
9394
9495
## Microsoft.Insights

0 commit comments

Comments
 (0)