Skip to main content

Azure Governance: Policy and RBAC Review

Overview

Azure Governance in Spotto is an Azure governance review page for understanding how technical governance is implemented across a tenant. It connects management groups, subscriptions, resource-level scopes, Azure Policy, RBAC, privileged roles, custom roles, exemptions, Global Administrator posture, findings, and graph relationships into one review workflow.

Use Governance when you need to answer: "How is this Azure environment governed, where are controls assigned, and which risks need review?" That answer should not require five Azure Portal blades, a directory export, and a spreadsheet that mysteriously has seven owners.

Feature overview

Governance summarizes tenant and subscription governance data for the selected Azure cloud account:

  • Tenant posture: subscriptions, management groups, findings, high and critical findings, non-compliant resources, privileged assignments, policy assignments, and RBAC assignments.
  • Subscription drill-through: findings, policy assignments, policy exemptions, RBAC assignments, privileged role assignments, custom roles, and management group path.
  • Coverage status: complete, partial, unavailable, skipped, or unknown data coverage for each governance collection area.
  • Policy and access context: assignment scope, policy effect, compliance state, principal, role, inheritance, and privileged access signals.
  • Global Admin posture: direct and group-derived principals, PIM status, assignment mode, collection coverage, and unresolved identities.
  • Governance graph: visual relationships between hierarchy, policy, RBAC, definitions, assignments, exemptions, roles, and principals.

Questions Governance answers

Use Governance when you need direct answers to Azure governance and access review questions:

  • Which subscriptions and management groups exist in this tenant, and how are they arranged?
  • Which policy assignments apply, what effect do they use, and where are they scoped?
  • Which policy exemptions exist, when do they expire, and what scopes do they affect?
  • Which RBAC assignments are present, which are inherited, and which are privileged?
  • Which custom roles exist and what scopes can they be assigned to?
  • Which findings are critical or high, and which subscription or scope do they affect?
  • Is missing or partial collection coverage changing what the report can prove?
  • How do policies, assignments, exemptions, roles, principals, subscriptions, and management groups relate?

That makes the page useful for Azure governance review, RBAC review, policy exemption review, access troubleshooting, audit preparation, and technical governance handover work.

Why use this? (Jobs, pains, gains)

Jobs to be done

  • When I review Azure governance posture, I want to see management groups, subscriptions, policy, RBAC, findings, and coverage together, so I can understand the implementation without stitching it together manually.
  • When a subscription has risk, I want to drill into policy, exemptions, RBAC, privileged roles, and custom roles, so I can separate expected governance from drift or over-permissioned access.
  • When a compliance or access question comes up, I want to trace scope and inheritance, so I can explain why a policy or role applies where it does.
  • When governance relationships are unclear, I want a graph of policies, assignments, roles, principals, and hierarchy, so I can follow the chain instead of reading raw IDs.

Common pains

  • Azure governance data is spread across Management Groups, Policy, IAM, Entra ID, subscriptions, and Resource Graph.
  • Inheritance makes simple questions difficult: an assignment at a management group can explain behavior far below it.
  • Empty tables can be misleading unless you know whether data coverage is complete, partial, unavailable, skipped, or unknown.
  • Policy exemptions and custom roles are easy to miss, even though they often explain why governance differs from the expected baseline.
  • Privileged RBAC assignments can hide in normal access lists unless they are surfaced as review items.

What you gain

  • A tenant-level governance overview with the metrics that usually drive review work.
  • Subscription drill-through for policy, exemption, RBAC, privileged role, custom role, and finding evidence.
  • Coverage-aware interpretation so missing data is visible instead of silently becoming "nothing to see here."
  • A relationship graph for understanding scope, inheritance, assignment, definition, role, and principal links.
  • A faster handover path for platform, security, audit, and operations teams working from the same evidence.

Turn the evidence into a decision

Select the labelled briefcase Business Value button beside Notes. The brief combines live findings, high/critical severity, policy or privileged-access metrics, and evidence coverage with a decision narrative.

The displayed facts remain live and missing evidence is called out. Generate tailors only the narrative for permitted users, saves it for the exact scope, and shows a freshness warning when evidence changes. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Above 100 subscriptions, the curated live brief remains available without tailoring.

Current position and priority work

Address critical and high-impact policy, privileged-access, and ownership gaps first. Restore incomplete evidence sources before treating the posture as complete, then define the standard control baseline and time-bound exception process.

Business outcomes

Governance turns cloud standards into repeatable delivery guardrails. Strong hierarchy, policy, and access ownership can make secure, compliant delivery easier rather than relying on manual review for every workload.

Cost of delay

Control drift can increase security exposure, audit effort, and the cost of correcting inconsistent environments. Broad privilege or unclear ownership can also make incidents harder to prevent, investigate, and contain.

Decision required

Approve the minimum control baseline, remediation owners, exception authority, and next compliance review date.

Validate with stakeholders

When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.

  • Which standards must apply everywhere, and where are exemptions legitimate?
  • Who owns policy, privileged access, exceptions, and remediation at each scope?
  • Which audits or platform changes make governance work time-sensitive?

Key capabilities

Review tenant governance posture

The Overview tab starts with tenant-level governance data for the selected cloud account. It shows summary metrics for:

  • Subscriptions.
  • Management groups.
  • Findings.
  • High and critical findings.
  • Non-compliant resources.
  • Privileged assignments.
  • Policy assignments.
  • RBAC assignments.

The page also includes breakdown cards for findings by severity, category, and subscription, so you can quickly see whether risk is isolated or spread across the environment. The intent is to capture the governance implementation from the management group hierarchy down to subscription and resource-related evidence, then make it readable enough to act on.

Check governance data coverage

The coverage panel shows whether Spotto has complete, partial, unavailable, skipped, or unknown data for each collection area. Coverage is important because missing governance data can change the meaning of an empty table.

For example, no RBAC rows with complete RBAC coverage is different from no RBAC rows because RBAC collection is unavailable. The labels are shown as text, not just color, so the status is readable in exports, screenshots, and assistive technology.

Review Global Administrator posture

Open Global Admins to review tenant-level Global Administrator access. Summary cards show total principals, PIM-backed access, permanent assignments, and unresolved principals. The table identifies direct or group-derived assignment, assignment modes, PIM status, and last activation evidence when collected.

Review the collection coverage notice before treating an empty or incomplete result as a clean posture. Missing Microsoft Graph role, eligibility, audit, user, group, or membership evidence can limit the assessment.

Drill into subscriptions

Use Subscription Drill-Through or View Details from the subscription table to inspect one subscription. Subscription detail includes:

  • Findings by severity, category, and scope.
  • Policy assignments, effects, compliance state, and scope.
  • Policy exemptions, category, expiry, and scope.
  • RBAC assignments, role, principal, scope, and inheritance.
  • Privileged role assignments.
  • Custom roles and assignable scopes.
  • The management group path for the subscription.

This is useful when an incident, failed deployment, sensitive action, or access review needs subscription-level evidence.

Inspect policy and RBAC relationships

The Graph tab shows governance relationships for the selected tenant or subscription. It can include tenant, management group, subscription, policy assignment, policy definition, policy set definition, policy exemption, role assignment, role definition, and principal nodes.

Use graph search and the node-type filter to isolate a policy, role, principal, or subscription. Selecting a node opens a detail panel with metadata, and selecting a subscription node provides Open Subscription Detail so you can jump back into the subscription review.

Investigate findings that need attention

Governance findings are normalized by severity: Critical, High, Medium, Low, Info, or Unknown. Spotto treats findings, high and critical findings, non-compliant resources, and privileged assignments as attention metrics when their count is greater than zero.

Start with critical and high findings, then check whether they are tied to a specific subscription, management group path, policy assignment, or privileged role.

Where to find it

In the Spotto Portal, go to Investigate -> Analyze -> Governance.

Governance preserves the selected cloud account, subscription drill-through, and active view while you stay on the page. Leaving the page clears those Governance-specific query parameters so other pages do not inherit stale scope.

  1. Select the company and Azure cloud account you want to review.
  2. Check the tenant metrics for findings, high and critical findings, non-compliant resources, and privileged assignments.
  3. Review coverage before trusting an empty table.
  4. Open Tenant Governance Data and scan the Subscriptions, Findings, Policy, and RBAC tabs.
  5. Use View Details on a subscription with elevated risk or incomplete coverage.
  6. Review subscription findings, policy exemptions, RBAC inheritance, privileged assignments, and custom roles.
  7. Open Global Admins to check permanent, unresolved, direct, and group-derived tenant administrators.
  8. Switch to Graph when you need to understand inheritance or relationships between policies, assignments, roles, and principals.

Technical reference

ComponentDetails
Primary scopeSelected company and Azure cloud account.
Optional drill-throughSelected Azure subscription.
Tenant report dataManagement group hierarchy, subscriptions, findings, policy assignments, RBAC assignments, coverage, and summary metrics.
Subscription report dataFindings, policy assignments, policy exemptions, RBAC assignments, privileged assignments, custom roles, coverage, management group path, and resource-level governance evidence where available.
Global Admin dataMicrosoft Graph directory role, active and eligible assignment, activation audit, user, group, and membership evidence when the required collection coverage is available.
Graph dataRelationship nodes and edges for hierarchy, policy, RBAC, definitions, assignments, exemptions, roles, and principals.
Graph filtersText search, node-type filter, reset action, minimap, and graph controls.
Coverage statesComplete, partial, unavailable, skipped, and unknown.
Visible errorsSeparate error states for tenant report, subscription report, and graph data.

How it differs from Azure-native views

Azure Portal is authoritative for making governance changes, but its governance data is spread across Management Groups, Policy, IAM, Entra ID, subscriptions, and Resource Graph. Spotto is read-oriented: it brings the evidence together so you can review posture, troubleshoot changes, and explain relationships faster.

Use Azure Portal when you need to change policy assignments, exemptions, RBAC, roles, or management group structure. Use Spotto Governance when you need to understand the current implementation and decide what deserves follow-up.

How it works

Spotto collects Azure governance data from the selected cloud account and builds tenant and subscription reports. The tenant report focuses on hierarchy, summaries, findings, policy, RBAC, and coverage. The subscription report adds drill-through detail for exemptions, privileged assignments, custom roles, and resource-level governance evidence. A separate tenant access artifact supplies the Global Admins view when Microsoft Graph collection is available.

The graph view uses the collected governance model to render relationships such as containment, assignment scope, definition references, policy set membership, role grants, and principal links.

Troubleshooting

Governance report could not be loaded

What you're seeing: The page shows Governance report could not be loaded.

Likely causes:

  • The tenant governance collection has not completed yet.
  • The selected cloud account is unavailable.
  • Spotto could not retrieve the governance report for that scope.

How to fix:

  1. Refresh the page and try again.
  2. Confirm the selected cloud account is the account you expected.
  3. If the issue persists, wait for the Azure tenant governance collection to complete and retry.

No governance report data found

What you're seeing: The page shows No governance report data found.

Likely causes:

  • The selected cloud account has not returned tenant governance data yet.
  • Governance collection completed without report data for that account.

How to fix:

  1. Check whether another cloud account has governance data.
  2. Confirm the Azure account still has subscriptions connected to Spotto.
  3. Retry after the next collection run.

Subscription governance could not be loaded

What you're seeing: The subscription section shows Subscription governance could not be loaded.

Likely causes:

  • The selected subscription report is unavailable.
  • The subscription was removed, renamed, or is no longer accessible.
  • The report is still processing.

How to fix:

  1. Select another subscription and confirm tenant data loads.
  2. Return to the original subscription and retry.
  3. Refresh the page if the subscription was recently added or changed.

Governance graph could not be loaded

What you're seeing: The Graph tab shows Governance graph could not be loaded.

Likely causes:

  • The graph artifact is still processing for the selected scope.
  • Graph data is unavailable for the selected tenant or subscription.

How to fix:

  1. Refresh the page and retry the Graph tab.
  2. Switch between tenant and subscription scope to see whether one graph is available.
  3. Use the Overview tables while the graph artifact finishes processing.

No matching graph nodes

What you're seeing: The Graph tab shows No matching graph nodes.

Likely causes:

  • Search text is too specific.
  • The selected node type filter excludes matching nodes.

How to fix:

  1. Clear the search box.
  2. Set the node-type filter back to All node types.
  3. Use Reset to return the graph to its default view.
Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation