Azure Cloud Account Permissions Reference
Spotto can connect to Azure with basic Reader access and still report missing data for specific sync steps. When that happens, Cloud Accounts sync diagnostics can show Permission required for a tenant or subscription capability.
Automatic Connect treats root-management-group Reader and each selected subscription's Reader as independent assignments. A root-management-group warning does not block a subscription whose own Reader check succeeded, and a successful root assignment does not replace the per-subscription readiness check.
Missing Permission Warnings
Use the table below to map the warning to the Azure permission that needs to be added.
| Spotto warning | Azure permission | Assign at | Missing feature impact |
|---|---|---|---|
| GDAP relationship or authorization profile | Active GDAP relationship, active security group assignment, usable partner authorization profile, and Spotto pilot enablement | Microsoft Partner Center relationship, partner security group, and Spotto MSP root company | MSP customer onboarding and delegated tenant scans after GDAP pilot validation is enabled |
| GDAP delegated Entra roles | Directory Readers, plus Cloud Application Administrator, Global Reader, Security Reader, or Reports Reader as needed | Roles requested on the GDAP relationship and assigned to the partner security group | Delegated directory access, customer application consent, and identity or governance findings for GDAP customers |
| GDAP Azure subscription access | Partner security group nested under Admin Agents for CSP/Azure Plan, or Azure RBAC assigned by the customer for EA and MCA-direct | Partner tenant group membership, or the customer's subscriptions and management groups | All Azure data for a GDAP customer. Without it, validation finds no readable subscriptions |
| Subscription Reader | Reader | Subscription or inherited management group | Resource inventory, Resource Graph reads, Advisor import, and activity context |
| Cost Management Reader | Cost Management Reader and Reader | Subscription | Cost trends, budgets, savings calculations, usage attribution, and cost overlays |
| Billing export storage access | Applicable Cost Management exports, read access at broad export scopes, and Storage Blob Data Reader for Spotto | Subscription, management-group, or billing export scope, plus export storage destination | Export-first Cost Analysis, Cost Tree, dashboard spend widgets, and billing history ingestion |
| CSP Azure Usage visibility | CSP Azure Usage visibility plus Reader | CSP partner billing account customer policy and subscription | Cost Analysis, Cost Tree, dashboard spend widgets, and billing overlays |
| Monitoring Reader | Monitoring Reader | Subscription or monitored resource scope | Azure Monitor metrics, performance evidence, rightsizing, alerts, and diagnostics |
| Security Reader | Security Reader and Reader | Subscription | Defender for Cloud assessments, secure score, and security posture summaries |
| Management Group Reader | Management Group Reader | Exact root management group when available, or each intended management group | Management group hierarchy and governance context available at the assigned scopes |
| Key Vault Reader | Key Vault Reader | Covering management group, subscription, resource group, or vault | Current enabled secret, key, and certificate expiry metadata in Retirement Tracker and proactive expiry notifications; never secret values or private key material |
| Reservations Reader | Reservations Reader | Reservations provider scope | Reserved Instance inventory, coverage, utilization, expiry, and recommendations |
| Reservations Contributor | Reservations Contributor | Reservations provider scope | Reservation refund quote calculation and reservation management workflows |
| Savings plan Reader | Savings plan Reader | Savings plans provider scope | Savings Plan inventory, coverage, utilization, expiry, and missed savings |
| Microsoft Graph governance permissions | Application.Read.All, RoleAssignmentSchedule.Read.Directory, RoleEligibilitySchedule.Read.Directory, RoleManagement.Read.Directory, GroupMember.Read.All, User.Read.All, AuditLog.Read.All, Policy.Read.All, and LicenseAssignment.Read.All application permissions | Microsoft Graph application permission with admin consent | App registration, service principal, Global Admin/PIM, group membership, user, audit, tenant policy, licensing, and MFA posture diagnostics |
| Log Analytics Reader | Log Analytics Reader | Subscription, workspace, or inherited scope | Log Analytics queries, Application Insights evidence, and reliability diagnostics |
| Advisor suppression custom role | Custom role with Advisor suppression actions | Subscription | Sync dismissed or restored recommendations back to Azure Advisor |
| Storage inventory policy custom role | Custom role with storage inventory policy read/write actions | Selected storage account | Automated blob inventory policy configuration |
| Azure Policy exemption custom role | policyExemptions/write plus policyAssignments/exempt/action | Exemption target plus exact policy assignment scope | Create scoped exemptions from Regulatory Compliance |
Assign Cost Management Reader
This role lets Spotto read Azure Cost Management and Consumption data where API-based billing reads are used.
- Open the affected subscription.
- Open Access Control (IAM).
- Select Add -> Add role assignment.
- Select Cost Management Reader.
- Assign it to the Spotto service principal.
- Confirm the same service principal also has Reader on the subscription.
Cost Management Reader enables API fallback but is not a substitute for export storage access. If your cloud account uses exported billing data, also complete Azure billing export setup.
If a Cost Management export is created at billing scope instead of subscription scope, assign Spotto read access at that billing scope as well. Use Cost Management Reader for Azure RBAC cost scopes, the matching MCA billing reader role for Microsoft Customer Agreement scopes, or the equivalent EA read role for Enterprise Agreement scopes.
GDAP Permissions For MSP Customer Accounts
GDAP access is three independent grants, configured in three different places. Getting one right does nothing for the other two, so identify which layer a warning belongs to before changing anything.
| Layer | What it grants | Configured in |
|---|---|---|
| A. Delegated Entra roles | Delegated read access inside the customer's Microsoft Entra directory | Partner Center relationship and partner security group |
| B. Azure subscription access | Visibility of the customer's Azure subscriptions, resources, and metrics | Partner tenant group nesting, or Azure RBAC assigned by the customer |
| C. CSP billing visibility | Cost and usage amounts for CSP-billed subscriptions | The partner's own billing account customer policy |
Check these items when a GDAP scan reports missing access:
- The customer approved the GDAP relationship in Microsoft 365 admin center.
- The GDAP relationship is still active and has not expired or been terminated.
- The partner security group has been added to the relationship.
- The required Microsoft Entra roles have been assigned to that security group.
- The Spotto partner profile has been authorized in the same Spotto region as the customer cloud account.
- The customer tenant has granted the required Spotto application consent for the GDAP flow.
- The customer subscriptions are visible through delegated access or direct Azure RBAC.
- CSP Azure Usage visibility is enabled when the customer uses CSP billing and Spotto needs cost data.
For what the partner authorization itself grants, see Partner Access And Consent.
GDAP Delegated Entra Roles
These are the Microsoft Entra roles requested on the GDAP relationship and assigned to the partner security group.
| Microsoft Entra role | Needed | What it is for |
|---|---|---|
| Directory Readers | Required | Microsoft's documented least-privileged role for GDAP Azure access. Nothing else works without it. |
| Cloud Application Administrator | Required unless the customer's own Global Administrator grants consent directly | Granting the Spotto application consent inside the customer tenant. |
| Global Reader | Recommended | Directory Readers does not cover audit logs, role management and PIM, or app registrations. |
| Security Reader | Optional | Defender for Cloud assessments and secure score. |
| Reports Reader | Optional | Usage and activity reporting. |
Roles cannot be added to a GDAP relationship after the customer approves it. Adding one means requesting a new relationship, having the customer approve again, reassigning the security group, and updating the relationship ID in Spotto. Choose the full set up front. Reference: Obtain granular admin permissions to manage a customer's service.
GDAP Azure Subscription Access
GDAP Entra roles grant no Azure RBAC at all. This is a separate grant, and missing it is the most common cause of a GDAP account that validates its relationship correctly and then finds no subscriptions.
- CSP or Azure Plan: the security group assigned to the relationship must be nested under Admin Agents in the partner tenant. This is what makes the admin-on-behalf-of path work. No Entra role substitutes for it.
- Enterprise Agreement or MCA-direct: the customer assigns Azure RBAC directly to the partner security group. Reader is the minimum. Add Cost Management Reader, Monitoring Reader, Log Analytics Reader, Security Reader, Management Group Reader at the root management group, and Reservations and Savings plan Reader at their provider scopes for the matching Spotto features.
Step-by-step guidance for both paths is in Layer B: Give Spotto Access To Azure Subscriptions. Individual role assignment steps are in the warning matrix above.
Creating Cost Management billing exports is not supported under the GDAP delegated path by design. Use the service principal setup paths when export-based billing ingestion is required.
Billing Prerequisites For CSP / Azure Plan Subscriptions
If your Azure subscriptions are provided through a CSP partner and billed under Microsoft Azure Plan or Microsoft Customer Agreement, billing features can depend on Azure Cost Management visibility in addition to subscription Reader access.
Before expecting billing-driven features such as Cost Analysis, Cost Tree, or dashboard spend widgets to populate, confirm all of the following:
-
The subscription is on Microsoft Azure Plan or Microsoft Customer Agreement, not the older classic CSP offer.
-
Your CSP partner has enabled customer cost visibility in the partner tenant:
- Open Cost Management + Billing.
- Select the billing account.
- Open Customers and choose your customer.
- Open Policies.
- Set Azure Usage to Yes.
Changing this policy requires an Admin agent who is also a Billing admin in the partner tenant.
-
The Spotto service principal has Reader access on the relevant subscriptions or inherited scope. For GDAP accounts, the partner security group has that read access instead.
Spotto onboarding, PowerShell, Terraform, and manual Azure RBAC assignments cannot enable the partner-side billing policy. If Azure Usage cost visibility is off, credential validation can still succeed while billing-driven features remain empty or denied.
Assign Security Reader
This role lets Spotto read Defender for Cloud assessments and secure score data.
- Open the affected subscription.
- Open Access Control (IAM).
- Select Add -> Add role assignment.
- Select Security Reader.
- Assign it to the Spotto service principal.
- Confirm the same service principal also has Reader on the subscription.
Advisor Suppression Custom Role
This is optional write automation for syncing dismissed or restored recommendations back to Azure Advisor.
Use Azure Advisor write permissions for the required actions and assignment flow.
Storage Inventory Policy Custom Role
Storage Inventory analysis is reader-only in the current phase, and Spotto does not create or update Blob Inventory policies from this workflow.
If write-based provisioning is enabled later, use Azure Blob Inventory: Storage Inventory Access Model.
Azure Policy Exemption Custom Role
This write capability is separately optional. Use Azure Policy exemption write permissions for direct versus inherited assignment scopes, Terraform/PowerShell options, exact actions, and rollback guidance.
How To Fix A Warning
- Open the warning in Spotto.
- Note the missing permission, assignment scope, tenant, and subscription.
- In Azure, Partner Center, or Microsoft 365 admin center, assign the listed role, Graph application permission, GDAP access assignment, or billing visibility.
- Wait 5-10 minutes for Azure RBAC or Microsoft Graph consent propagation.
- Return to Spotto. For an Automatic Connect setup warning, select Repair Setup or Update Access so Spotto can verify and reconcile the failed exact scope. For a later sync warning, run the affected tenant or subscription sync again.