A read-only role that exists both in Microsoft Entra and as an Azure built-in role, letting holders see Defender for Cloud and other security information. It gives no Microsoft Sentinel workspace access and cannot assign roles.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104SC-500SC-200SC-300AZ-400
Each book explains Security Reader in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- Conditional Access insights and reporting
Using sign-in data sent to a Log Analytics workspace, this workbook estimates what all your Conditional Access policies, report-only ones included, would do together over a chosen window between 4 hours and 90 days. It needs an Entra ID P1 licence and a role of Security Reader or above.
- Microsoft Sentinel MCP server
Lets AI assistants like Security Copilot or Visual Studio Code ask questions of Sentinel data lake data in everyday language, investigate entities and help triage incidents. Microsoft runs it for you; most of its tools assume you have onboarded to the data lake and hold Security Reader.
- Sensitivity Label Reader
Purview role giving view-only access to sensitivity label settings and usage. It belongs to the Security Reader, Global Reader and Organization Management role groups.