IAM (Access control) changes from Grafana Viewer to Grafana Limited Viewer are not recognized in Azure Managed Grafana - Users section

Mike Rees 40 Reputation points Microsoft Employee
2026-05-07T19:13:28.32+00:00

I changed 5 users role assignments in the Azure Managed Grafana portal, through IAM (Access control) from "Grafana Viewer" role to "Grafana Limited Viewer" role.

When I log into the AMG workspace, I check the Users page (which is managed by syncing with Azure), I see no changes for these users. They are still showing with the 'Viewer' role. I have refereshed, signed out, ctrl-shift-r, and logged out of my desktop and back in. I've even waited an hour before refreshing again.

Should that change? Or does Grafana Limited Viewer role appear as Viewer in that screen too?
Is there a way to trigger the sync?

I know the syncing isn't working. I'm certain of it since there are still users showing up that no longer have access to grafana. These users left the company and their group memberships are gone (groups that provided them access), and they still appear. These users have been gone for almost a year, so something is wrong with the syncing for sure.

Azure Managed Grafana
Azure Managed Grafana

An Azure service used to deploy Grafana dashboards for analytics and monitoring solutions.


Answer accepted by question author

AI answer

2026-05-07T19:14:03.2133333+00:00

The behavior described is by design for Azure Managed Grafana.

Azure Managed Grafana stores Grafana built‑in RBAC role assignments (such as Grafana Viewer and Grafana Limited Viewer) in Microsoft Entra ID. The Users list in the Grafana UI is not continuously synchronized with Microsoft Entra ID. Instead:

  • Users and their assigned roles are only listed or updated in Administration > Users and access > Users after they sign in to the Azure Managed Grafana workspace.
  • There is no automatic background sync that removes users who no longer have access or immediately reflects role changes.
  • For performance reasons, Azure Managed Grafana does not periodically query Microsoft Entra ID for current assignments, and there is no manual “sync now” control.

Therefore:

  1. Changing a user’s role assignment in Azure IAM from Grafana Viewer to Grafana Limited Viewer will not immediately update what is shown in the Grafana Users page.
  2. The entry for a user is refreshed only when that user signs in again; until then, the old role can continue to appear.
  3. Users who left the company or lost access can remain visible in the Users list because their entries are not automatically removed; their presence there does not mean they still have access.

There is no supported way to force a global sync from the Grafana side. To see updated roles:

  • Have each affected user sign in to the Azure Managed Grafana workspace again; their role will then be refreshed and reflected in the Users list.

References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. Mike Rees 40 Reputation points Microsoft Employee
    2026-05-07T19:59:56.2866667+00:00

    Well, that explains this, but as far as the design of users that have left the company, that is a crappy design IMO. I have to continue to see users who have left the company, with the visual indicating they still have access? Yikes. If someone else is managing user access into these workspaces, these questions will popup again. We shall see if the display updates for role changes when they log in next, but again this seems odd to me. Why store and display old information? Part of good security is understanding what is currently set up. Seeing old data is not helpful IMO. I'll mark this as the answer even though I dislike the answer

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.