Built-in Azure role for viewing resources only: it cannot modify or use them, for example by joining or associating them, and gives no keys or data access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Reader in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Modify
Policy effect in Azure that can add, replace or remove tags and other properties. Resources that already exist are brought into line by running a remediation task.
Related terms
- Email Azure Resource Manager role
Action group notification type: when an alert fires, it emails every user or group assigned the chosen subscription-level role, whether Monitoring Reader, Reader, Owner, Monitoring Contributor or Contributor.
- Feed roles
In ascending order of rights, each including the last: Feed Reader; Feed and Upstream Reader, or Collaborator, who may save from upstream sources; Feed Publisher, or Contributor, who may publish; and Feed Owner.
- join/action permission
Network Contributor has this Azure RBAC action but Reader does not. It allows an identity to attach one resource to another, such as associating a firewall with a subnet, public IP or firewall policy.
- Microsoft Sentinel Responder
Built-in Azure role combining Sentinel Reader rights with managing incidents, such as assigning owners and changing severity or status. Guests additionally need Directory Reader before they can assign incidents.
- Personal bookmarks
A reader without edit rights can capture their own view of a report in the Power BI service this way, keeping as many as 20 for each report. They stay with that person rather than being saved inside the report itself.
- Readers
Gives view-only rights within an Azure DevOps project, for example over releases and pipelines. Don't confuse it with Azure's Reader role or the agent pool Reader role.
- Role definition
A set of permissions, for example read, write and delete, that is either built in (Owner, Contributor, Reader and others) or custom. People normally just call it a role.
- Storage Blob Data Contributor
Data-plane built-in role that can read, write and delete blobs and containers. Paired with Reader, it is the least privilege needed to upload through the portal.