Azure Roles for Log Analytics and How they Relate to Services Hub

Overview

To run Microsoft Assessments through Services Hub, your workspace must be linked to an Azure Log Analytics workspace. This integration ensures that assessment data is stored securely and can be accessed for analysis.

Purpose of linking

  • Azure Log Analytics workspaces are used to store assessment data generated by Services Hub.
  • Linking Services Hub to an Azure Log Analytics workspace allows assessment solutions to be deployed and results to be viewed.
  • Only users with specific Azure roles can successfully link Services Hub to a Log Analytics workspace.

Important

The same user account that signs in to Services Hub must have the required permissions in Azure to perform the actions.

Azure Roles and Permissions

The following roles define what actions can be performed when linking Services Hub to Log Analytics and managing assessments:

1. Owner (Subscription Level)

Permissions:

  • Full access to the subscription.
  • Can link the Log Analytics workspace at Services Hub portal.
  • Can add or remove assessment solutions from the Services Hub portal.

Use Case: Recommended for administrators who manage all aspects of the workspace and assessments.

2. Contributor (Subscription Level)

Permissions:

  • Can link the Log Analytics workspace at the Services Hub portal.
  • Can add or remove assessment solutions from the Services Hub.

Minimum Requirement: This is the minimum role required to add or remove assessments from the Services Hub.

Use Case: Ideal for users responsible for managing assessments but not subscription-wide settings.

3. Log Analytics Reader (Subscription Level)

Permissions:

  • Read-only access to view assessment results in:
    • Log Analytics workbooks.
    • Services Hub portal.
  • Cannot add or remove assessment tiles from Services Hub.

Minimum Requirement: If the purpose is only to review assessment results.

Use Case: Suitable for users who need visibility into assessment results without making changes.

Role Assignment Considerations

If assigning roles at the subscription level is a concern, ensure the following minimum permissions:

  • Log Analytics Reader role at:
    • Log Analytics workspace level.
    • Machine level (Azure Arc / Virtual Machine).

This ensures users can at least view assessment results without full access to the subscription.

Summary Table

Role Scope Permissions
Owner Subscription Level Full access: edit workspace, add/remove assessments
Contributor Subscription Level Link workspace, add/remove assessments (minimum for assessment management)
Log Analytics Reader Subscription Level Read-only: view results in Log Analytics and Services Hub; link Log Analytics workspace at Services Hub portal

Next Steps

  • Verify your Azure role before attempting to link Services Hub to Log Analytics.
  • For more details on assigning roles, refer to Azure RBAC documentation.

Note

The minimum level required is Azure Log Analytics Reader.

Note

Add/Remove solutions in Log Analytics Workspace are able to change the costs incurred by your organization. For that reason, it requires higher levels of permission.

Note

If you don’t know the Azure owner or other roles of your Azure subscriptions, see Role assignments in Azure Subscriptions.

Configure roles in Azure

See Assign Azure roles using the Azure portal.

For guidance and details on working with assessment results, visit Working with Assessment Results in Services Hub.