Skip to main content

Azure Guest Assessment Access for Customers

Use this Azure guest assessment access template when a customer wants evidence-based guidance without setting up a durable Azure integration. It gives managed service providers and consultants a complete customer email covering the reason for the assessment, the access required, what read-only means, setup steps, and the agreed outcome.

The copied wording is deliberately tool-neutral. Replace the bracketed placeholders, add only the optional paragraphs relevant to the engagement, and agree on the deliverable before sending it.

Choose the assessment objective

Replace [customer objective] and [cost growth / performance / resilience / security / governance / modernization] with the problem the customer wants to investigate.

Common starting points include:

  • Unexpected Azure cost growth or commitment coverage
  • Performance bottlenecks or reliability concerns
  • Security posture or governance gaps
  • Disaster recovery and resilience planning
  • Operational excellence
  • Virtual machine or application modernization
  • Azure Well-Architected Framework or landing-zone reviews

Copy the customer email

Copy the complete template below, replace the bracketed text, and then add any relevant optional paragraphs from the next section.

Customer email template
Subject: Read-only Azure assessment for [customer objective]

Hi [Name],

You mentioned that [cost growth / performance / resilience / security / governance / modernization] is creating concern. We would like to run a focused, evidence-led assessment of the Azure subscriptions in scope so we can validate the likely causes, identify practical opportunities, and recommend appropriate next steps based on the actual environment.

To carry out the assessment, please invite [person's name and email address], a person in our team, as a guest in your Microsoft Entra tenant. Grant them Reader access to each Azure subscription you want included in the assessment.

Reader access allows us to see the Azure resources and review their configuration and permitted operational metadata. It does not allow us to create, change, or delete resources, and it does not grant access to the data stored inside them. For example, we may see that a Storage Account exists and review its Azure configuration, but we cannot open the blobs or files stored in it. Likewise, we cannot view Key Vault secret values or query the data inside your application databases.

If all subscriptions to be assessed are grouped under the same Azure management group, you can instead assign Reader at that management group. Reader access will be inherited by every subscription beneath it, so please use a management group only when all of its child subscriptions should be included.

Setup instructions

1. Sign in to https://portal.azure.com.
2. In the Azure portal search bar, search for and select Microsoft Entra ID.
3. Under Manage, select Users.
4. Select New user > Invite external user.
5. Enter [person's name and email address].
6. Select Review + invite to send the invitation.
7. Use the Azure portal search bar to open Subscriptions.
8. Select a subscription to include in the assessment.
9. Open Access control (IAM).
10. Select Add > Add role assignment.
11. Select the Reader role.
12. Choose User, group, or service principal, then select the invited person.
13. Select Review + assign.
14. Repeat steps 8-13 for each subscription you want included.

If you are assigning access through a management group instead, open that management group, select Access control (IAM), and assign Reader to the invited person there.

Once access is ready, please let us know and we will begin the assessment.

We will review the resulting evidence with you and provide the agreed outcome, typically a prioritized findings summary, remediation roadmap, review checklist, proposal, or draft statement of work. Any implementation work will be separately scoped and agreed with you.

Kind regards,
[Name]

Add optional access where relevant

Do not request every optional role by default. Add a paragraph only when it supports the customer's stated objective.

Cost and commitments

Add this paragraph when the assessment includes reservation or savings-plan coverage:

Optional cost and commitments paragraph
If the assessment includes reservation or savings-plan coverage, please also assign Reservations Reader from the Azure Reservations area and Savings plan Reader from the Azure Savings plans area. These roles provide read-only access to commitment information that is not inherited from subscription Reader access.

To assign Reservations Reader, open Reservations in the Azure portal, select Role assignment, and add the invited person as Reservations Reader. To assign Savings plan Reader, open Savings plans, select Role assignment, and add the invited person as Savings plan Reader.

Identity and governance

Add this paragraph when the person conducting the assessment will manually review Microsoft Entra governance, enterprise applications, or service-principal credential expiry:

Optional identity and governance paragraph
If the assessment includes Microsoft Entra governance, enterprise applications, or service-principal credential expiry, please also assign the Global Reader role to the invited person. Global Reader permits directory-wide inspection without allowing the person to make changes.

To assign it without leaving the Azure portal, search for and select Microsoft Entra ID, open Roles & admins, select Global Reader, select Add assignments, and add the invited person.
note

Global Reader supports a human directory and governance review. It does not grant access to secret values, and it should not be described as a requirement for a subscription-only Azure resource assessment.

Select the narrowest practical scope

Assignment scopeWhen to use itScope effect
Individual subscriptionsDefault for most assessmentsThe invited person can read only the subscriptions where Reader is assigned.
Scoped management groupSeveral intended subscriptions already share one management groupReader is inherited by every current and future child subscription under that management group.
Tenant root management groupThe customer explicitly wants the entire Azure estate assessedReader is inherited across the root hierarchy. Do not use this as the default convenience option.

Microsoft recommends granting Azure roles at the narrowest scope needed. See Understand scope for Azure RBAC for the inheritance model.

Understand the read-only boundary

Azure Reader grants control-plane read access to resource inventory and configuration. It has no Azure RBAC data actions and does not allow resource changes. See the Azure Reader role definition.

Resource the person can seeData the Reader role does not grant access to
Storage Account resource and Azure configurationBlobs, files, queues, or table records stored in the account
Key Vault resource and Azure configurationSecret, key, or certificate values
SQL, Cosmos DB, or other database resource and Azure configurationApplication tables, documents, or database rows
Virtual machine resource and Azure configurationFiles inside the operating system or interactive sign-in to the VM

Read-only does not mean invisible activity. Azure records sign-ins and permitted read operations in its normal audit and activity logs.

Validate access

Before starting the assessment:

  1. Confirm the invited person has accepted the Microsoft Entra invitation.
  2. Confirm Reader appears under Access control (IAM) > Role assignments at each intended subscription or the chosen management group.
  3. Allow time for Azure RBAC changes to propagate.
  4. Confirm the invited person can switch to the customer directory and see the intended subscriptions.

The subscriptions visible through the assigned Reader roles define the available assessment scope. The customer does not need to send a separate subscription list.

Revoke access after the assessment

When access is no longer required:

  1. Remove the person's Reader assignment from each subscription or management group where it was granted.
  2. Remove optional Reservations Reader, Savings plan Reader, or Global Reader assignments where applicable.
  3. Remove the guest user from Microsoft Entra ID if no further collaboration is required.

Removing one subscription assignment does not remove inherited Reader access from a parent management group. Check the assignment's Scope when validating revocation.

Troubleshooting

The invited person cannot see subscriptions

What you're seeing: The person can sign in to the customer directory, but no intended subscriptions are visible.

Likely causes:

  • Reader was not assigned to the guest user at the subscription or parent management-group scope.
  • The person is viewing a different Microsoft Entra directory.
  • The role assignment is still propagating.

How to fix:

  1. Check Access control (IAM) > Role assignments at the intended scope.
  2. Confirm the role is assigned to the correct guest object.
  3. Switch to the customer directory and retry after role propagation completes.

More subscriptions are visible than expected

What you're seeing: The invited person can see subscriptions that were not individually assigned.

Likely cause: Reader is inherited from a parent management group, possibly the tenant root management group.

How to fix:

  1. Open the unexpected subscription's Access control (IAM) page.
  2. Check the inherited Reader assignment and its parent scope.
  3. Remove the broad assignment and grant Reader at individual subscriptions or a narrower management group.

Commitment information is missing

What you're seeing: Subscription resources are visible, but reservation or savings-plan information is unavailable.

Likely cause: Reservations and savings plans use separate permissions that are not inherited from subscription Reader.

How to fix:

  1. Assign Reservations Reader for reservation visibility.
  2. Assign Savings plan Reader for savings-plan visibility.
  3. Retry after the assignments propagate.