GuideInformationCybersecurityIT

Test resource-context access before trusting Log Analytics row conditions

Why might a reader still see unrestricted logs after a conditional Log Analytics role assignment is added?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Why might a reader still see unrestricted logs after a conditional Log Analytics role assignment is added?

Potentially affected

Azure Monitor Log Analytics workspaces using granular RBAC conditions.

DSE recommendation

Review additive role grants and every resource-context workspace access mode before accepting row-level restrictions.

Source facts

Log Analytics granular RBAC is additive: a separate broader role grant can override the practical restriction of a conditional assignment. Microsoft also requires resource-context queries to use workspaces configured as Require workspace permissions, with ABAC applied to every relevant workspace. Under Use resources or workspace permissions, resource read permission grants access to all logs and bypasses workspace conditions. Microsoft Learn.

These conditions govern queries, not the exported data’s continuing access policy. LAQueryLogs can record whether a query used an applicable condition through ConditionalDataAccess, when query diagnostics are enabled. Microsoft Learn.

Applicability

Use this review for Azure Monitor Log Analytics workspaces using granular RBAC conditions. Inventory every workspace contributing to the reader’s resource-context query, not just the workspace where the new assignment was created.

DSE recommendation

DSE recommends testing with the intended reader’s complete effective role set. Identify broader grants before removing anything, and coordinate required changes with the access owner. Review the workspace access mode and conditions together. Maintain separate authorization for exported or replicated copies; do not assume a successful restricted query establishes the policy of downstream data.

Verification

Choose known permitted and excluded records, then query through both the intended resource context and workspace context using the test identity. Compare visible rows with the approved conditions and inspect ConditionalDataAccess where available. Investigate any broader result before closing the access change. Retain the role assignments, workspace modes, query scope and observed rows as one reproducible test.

Official references

Microsoft Learn: Granular RBAC in Azure Monitor.

Primary reference

Review the official source

Granular RBAC - Azure Monitor Log Analytics | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE