Permissions
The recommended approach is to assign the Reader role to the Service Principal on every subscription that should be monitored. At a minimum, a custom role must allow the application to list accessible subscriptions and read Service Health events, including Microsoft.ResourceHealth/events/read.
Sensitive details from some security advisories may be hidden from identities without elevated permissions. The plugin queries the event list but does not call the additional fetchEventDetails operation required to retrieve sensitive content.