Requirements To discover Application Gateways and query their metrics, it is recommended to use a Service Principal with read permissions. The plugin requires read permissions to: List Microsoft.Network/applicationGateways resources. Read the basic Application Gateway configuration, including SKU and resource group. Query Azure Monitor metrics associated with the resource. In most environments, the Reader role over the subscription or over the resource group is enough. If permissions are limited to a single resource group, it is recommended to also configure the Resource group field in the Discovery task.