Skip to main content

Azure Cloud Account Permissions Reference

Spotto can connect to Azure with basic Reader access and still report missing data for specific sync steps. When that happens, Cloud Accounts sync diagnostics can show Permission required for a tenant or subscription capability.

Automatic Connect treats root-management-group Reader and each selected subscription's Reader as independent assignments. A root-management-group warning does not block a subscription whose own Reader check succeeded, and a successful root assignment does not replace the per-subscription readiness check.

Missing Permission Warnings

Use the table below to map the warning to the Azure permission that needs to be added.

Spotto warningAzure permissionAssign atMissing feature impact
GDAP relationship or authorization profileActive GDAP relationship, active security group assignment, usable partner authorization profile, and Spotto pilot enablementMicrosoft Partner Center relationship, partner security group, and Spotto MSP root companyMSP customer onboarding and delegated tenant scans after GDAP pilot validation is enabled
GDAP delegated Entra rolesDirectory Readers, plus Cloud Application Administrator, Global Reader, Security Reader, or Reports Reader as neededRoles requested on the GDAP relationship and assigned to the partner security groupDelegated directory access, customer application consent, and identity or governance findings for GDAP customers
GDAP Azure subscription accessPartner security group nested under Admin Agents for CSP/Azure Plan, or Azure RBAC assigned by the customer for EA and MCA-directPartner tenant group membership, or the customer's subscriptions and management groupsAll Azure data for a GDAP customer. Without it, validation finds no readable subscriptions
Subscription ReaderReaderSubscription or inherited management groupResource inventory, Resource Graph reads, Advisor import, and activity context
Cost Management ReaderCost Management Reader and ReaderSubscriptionCost trends, budgets, savings calculations, usage attribution, and cost overlays
Billing export storage accessApplicable Cost Management exports, read access at broad export scopes, and Storage Blob Data Reader for SpottoSubscription, management-group, or billing export scope, plus export storage destinationExport-first Cost Analysis, Cost Tree, dashboard spend widgets, and billing history ingestion
CSP Azure Usage visibilityCSP Azure Usage visibility plus ReaderCSP partner billing account customer policy and subscriptionCost Analysis, Cost Tree, dashboard spend widgets, and billing overlays
Monitoring ReaderMonitoring ReaderSubscription or monitored resource scopeAzure Monitor metrics, performance evidence, rightsizing, alerts, and diagnostics
Security ReaderSecurity Reader and ReaderSubscriptionDefender for Cloud assessments, secure score, and security posture summaries
Management Group ReaderManagement Group ReaderExact root management group when available, or each intended management groupManagement group hierarchy and governance context available at the assigned scopes
Key Vault ReaderKey Vault ReaderCovering management group, subscription, resource group, or vaultCurrent enabled secret, key, and certificate expiry metadata in Retirement Tracker and proactive expiry notifications; never secret values or private key material
Reservations ReaderReservations ReaderReservations provider scopeReserved Instance inventory, coverage, utilization, expiry, and recommendations
Reservations ContributorReservations ContributorReservations provider scopeReservation refund quote calculation and reservation management workflows
Savings plan ReaderSavings plan ReaderSavings plans provider scopeSavings Plan inventory, coverage, utilization, expiry, and missed savings
Microsoft Graph governance permissionsApplication.Read.All, RoleAssignmentSchedule.Read.Directory, RoleEligibilitySchedule.Read.Directory, RoleManagement.Read.Directory, GroupMember.Read.All, User.Read.All, AuditLog.Read.All, Policy.Read.All, and LicenseAssignment.Read.All application permissionsMicrosoft Graph application permission with admin consentApp registration, service principal, Global Admin/PIM, group membership, user, audit, tenant policy, licensing, and MFA posture diagnostics
Log Analytics ReaderLog Analytics ReaderSubscription, workspace, or inherited scopeLog Analytics queries, Application Insights evidence, and reliability diagnostics
Advisor suppression custom roleCustom role with Advisor suppression actionsSubscriptionSync dismissed or restored recommendations back to Azure Advisor
Storage inventory policy custom roleCustom role with storage inventory policy read/write actionsSelected storage accountAutomated blob inventory policy configuration
Azure Policy exemption custom rolepolicyExemptions/write plus policyAssignments/exempt/actionExemption target plus exact policy assignment scopeCreate scoped exemptions from Regulatory Compliance

Assign Cost Management Reader

This role lets Spotto read Azure Cost Management and Consumption data where API-based billing reads are used.

  1. Open the affected subscription.
  2. Open Access Control (IAM).
  3. Select Add -> Add role assignment.
  4. Select Cost Management Reader.
  5. Assign it to the Spotto service principal.
  6. Confirm the same service principal also has Reader on the subscription.

Cost Management Reader enables API fallback but is not a substitute for export storage access. If your cloud account uses exported billing data, also complete Azure billing export setup.

If a Cost Management export is created at billing scope instead of subscription scope, assign Spotto read access at that billing scope as well. Use Cost Management Reader for Azure RBAC cost scopes, the matching MCA billing reader role for Microsoft Customer Agreement scopes, or the equivalent EA read role for Enterprise Agreement scopes.

GDAP Permissions For MSP Customer Accounts

GDAP access is three independent grants, configured in three different places. Getting one right does nothing for the other two, so identify which layer a warning belongs to before changing anything.

LayerWhat it grantsConfigured in
A. Delegated Entra rolesDelegated read access inside the customer's Microsoft Entra directoryPartner Center relationship and partner security group
B. Azure subscription accessVisibility of the customer's Azure subscriptions, resources, and metricsPartner tenant group nesting, or Azure RBAC assigned by the customer
C. CSP billing visibilityCost and usage amounts for CSP-billed subscriptionsThe partner's own billing account customer policy

Check these items when a GDAP scan reports missing access:

  1. The customer approved the GDAP relationship in Microsoft 365 admin center.
  2. The GDAP relationship is still active and has not expired or been terminated.
  3. The partner security group has been added to the relationship.
  4. The required Microsoft Entra roles have been assigned to that security group.
  5. The Spotto partner profile has been authorized in the same Spotto region as the customer cloud account.
  6. The customer tenant has granted the required Spotto application consent for the GDAP flow.
  7. The customer subscriptions are visible through delegated access or direct Azure RBAC.
  8. CSP Azure Usage visibility is enabled when the customer uses CSP billing and Spotto needs cost data.

For what the partner authorization itself grants, see Partner Access And Consent.

GDAP Delegated Entra Roles

These are the Microsoft Entra roles requested on the GDAP relationship and assigned to the partner security group.

Microsoft Entra roleNeededWhat it is for
Directory ReadersRequiredMicrosoft's documented least-privileged role for GDAP Azure access. Nothing else works without it.
Cloud Application AdministratorRequired unless the customer's own Global Administrator grants consent directlyGranting the Spotto application consent inside the customer tenant.
Global ReaderRecommendedDirectory Readers does not cover audit logs, role management and PIM, or app registrations.
Security ReaderOptionalDefender for Cloud assessments and secure score.
Reports ReaderOptionalUsage and activity reporting.
caution

Roles cannot be added to a GDAP relationship after the customer approves it. Adding one means requesting a new relationship, having the customer approve again, reassigning the security group, and updating the relationship ID in Spotto. Choose the full set up front. Reference: Obtain granular admin permissions to manage a customer's service.

GDAP Azure Subscription Access

important

GDAP Entra roles grant no Azure RBAC at all. This is a separate grant, and missing it is the most common cause of a GDAP account that validates its relationship correctly and then finds no subscriptions.

  • CSP or Azure Plan: the security group assigned to the relationship must be nested under Admin Agents in the partner tenant. This is what makes the admin-on-behalf-of path work. No Entra role substitutes for it.
  • Enterprise Agreement or MCA-direct: the customer assigns Azure RBAC directly to the partner security group. Reader is the minimum. Add Cost Management Reader, Monitoring Reader, Log Analytics Reader, Security Reader, Management Group Reader at the root management group, and Reservations and Savings plan Reader at their provider scopes for the matching Spotto features.

Step-by-step guidance for both paths is in Layer B: Give Spotto Access To Azure Subscriptions. Individual role assignment steps are in the warning matrix above.

Creating Cost Management billing exports is not supported under the GDAP delegated path by design. Use the service principal setup paths when export-based billing ingestion is required.

Billing Prerequisites For CSP / Azure Plan Subscriptions

If your Azure subscriptions are provided through a CSP partner and billed under Microsoft Azure Plan or Microsoft Customer Agreement, billing features can depend on Azure Cost Management visibility in addition to subscription Reader access.

Before expecting billing-driven features such as Cost Analysis, Cost Tree, or dashboard spend widgets to populate, confirm all of the following:

  1. The subscription is on Microsoft Azure Plan or Microsoft Customer Agreement, not the older classic CSP offer.

  2. Your CSP partner has enabled customer cost visibility in the partner tenant:

    • Open Cost Management + Billing.
    • Select the billing account.
    • Open Customers and choose your customer.
    • Open Policies.
    • Set Azure Usage to Yes.

    Changing this policy requires an Admin agent who is also a Billing admin in the partner tenant.

  3. The Spotto service principal has Reader access on the relevant subscriptions or inherited scope. For GDAP accounts, the partner security group has that read access instead.

caution

Spotto onboarding, PowerShell, Terraform, and manual Azure RBAC assignments cannot enable the partner-side billing policy. If Azure Usage cost visibility is off, credential validation can still succeed while billing-driven features remain empty or denied.

Assign Security Reader

This role lets Spotto read Defender for Cloud assessments and secure score data.

  1. Open the affected subscription.
  2. Open Access Control (IAM).
  3. Select Add -> Add role assignment.
  4. Select Security Reader.
  5. Assign it to the Spotto service principal.
  6. Confirm the same service principal also has Reader on the subscription.

Advisor Suppression Custom Role

This is optional write automation for syncing dismissed or restored recommendations back to Azure Advisor.

Use Azure Advisor write permissions for the required actions and assignment flow.

Storage Inventory Policy Custom Role

Storage Inventory analysis is reader-only in the current phase, and Spotto does not create or update Blob Inventory policies from this workflow.

If write-based provisioning is enabled later, use Azure Blob Inventory: Storage Inventory Access Model.

Azure Policy Exemption Custom Role

This write capability is separately optional. Use Azure Policy exemption write permissions for direct versus inherited assignment scopes, Terraform/PowerShell options, exact actions, and rollback guidance.

How To Fix A Warning

  1. Open the warning in Spotto.
  2. Note the missing permission, assignment scope, tenant, and subscription.
  3. In Azure, Partner Center, or Microsoft 365 admin center, assign the listed role, Graph application permission, GDAP access assignment, or billing visibility.
  4. Wait 5-10 minutes for Azure RBAC or Microsoft Graph consent propagation.
  5. Return to Spotto. For an Automatic Connect setup warning, select Repair Setup or Update Access so Spotto can verify and reconcile the failed exact scope. For a later sync warning, run the affected tenant or subscription sync again.