# Requirements

<div id="bkmrk-for-the-plugin-to"><div>To discover Application Gateways and query their metrics, it is recommended to use a Service Principal with read permissions.</div></div><div id="bkmrk-"></div>The plugin requires read permissions to:

- List **Microsoft.Network/applicationGateways** resources.
- Read the basic Application Gateway configuration, including SKU and resource group.
- Query Azure Monitor metrics associated with the resource.

In most environments, the `Reader` role over the subscription or over the resource group is enough. If permissions are limited to a single resource group, it is recommended to also configure the **Resource group** field in the Discovery task.