Skip to main content

Azure Cloud Account Permission Required Warnings

Fix this error

Spotto shows Azure cloud account Permission required warnings when Azure has confirmed that required access is missing. Not confirmed and Optional results do not prove a permission is missing.

Use the warning text shown in the portal to find the Azure role, consent, or billing policy that needs to be added.

Find the missing permission in Spotto

  1. Open Connectors -> Connectors -> Cloud Accounts.
  2. Open the affected Azure cloud account.
  3. Open Sync diagnostics.
  4. Select the affected tenant or subscription row.
  5. In Sync Step Details, find the result in the Detail column.
  6. If it says <permission name> required, open the info icon and note the Missing permission and Assign at fields.
  7. If it says Not confirmed, retry validation before changing Azure roles.
  8. If it says Optional, no action is required for standard read-only onboarding.

Fix the warning in Azure

These are the same warning labels and tooltip fields shown in the front end.

What Spotto showsMissing permission in tooltipAssign atWhat to fixWhat is affected
Resource Groups Reader requiredReaderSubscription or inherited management groupAssign Reader to the Spotto app.Resource grouping and subscription inventory context
Resource Inventory Reader requiredReaderSubscription or inherited management groupAssign Reader to the Spotto app.Resource inventory, recommendations, relationship graphs, and resource views
Activity Log Reader requiredReaderSubscriptionAssign Reader to the Spotto app on the subscription.Activity-aware refresh, operational context, and cost-impacting change detection
Resource Graph Reader requiredReaderSubscription or inherited management groupAssign Reader to the Spotto app.Resource Graph queries used by recommendations, governance, reliability, and security checks
Cost Management Reader requiredCost Management Reader + ReaderSubscriptionAssign Cost Management Reader and confirm Reader.Cost trends, budgets, savings calculations, and cost overlays
Consumption Usage Reader requiredCost Management Reader + ReaderSubscriptionAssign Cost Management Reader and confirm Reader.Usage attribution, commitment analysis, and cost decomposition
Azure Cost Management visibility requiredCSP Azure Usage visibility + ReaderCSP partner billing account customer policy and subscriptionAsk the CSP partner to enable Azure Usage for the customer and confirm Spotto has Reader.Cost Analysis, Cost Tree, dashboard spend widgets, and billing overlays
Azure Monitor metrics access requiredMonitoring ReaderSubscription or monitored resource scopeAssign Monitoring Reader.Azure Monitor metrics, rightsizing, performance evidence, alerts, and diagnostics
Log Analytics Data Reader requiredLog Analytics ReaderSubscription or Log Analytics workspaceAssign Log Analytics Reader at the subscription, workspace, or inherited scope.Log Analytics queries, Application Insights evidence, and reliability diagnostics
Defender for Cloud assessments access requiredSecurity Reader + ReaderSubscriptionAssign Security Reader and confirm Reader.Defender for Cloud assessments, secure score, and security posture summaries
Advisor Recommendations Reader requiredReaderSubscriptionAssign Reader to the Spotto app.Azure Advisor recommendation import and optimization workflows
Management Group Reader requiredManagement Group ReaderRoot management groupAssign Management Group Reader at the exact root management group.Management group hierarchy and tenant-level governance context
Reservations Reader requiredReservations ReaderReservations provider scopeAssign Reservations Reader from the Azure Reservations area.Reserved Instance inventory, coverage, utilization, and commitment opportunities
Reservations Contributor requiredReservations ContributorReservations provider scopeAssign Reservations Contributor from the Azure Reservations area.Reservation refund quote calculation and reservation management workflows
Savings Plan Reader requiredSavings plan ReaderSavings plans provider scopeAssign Savings plan Reader from the Azure Savings plans area.Savings Plan inventory, coverage, utilization, and missed savings
Active directory role assignments access requiredRoleAssignmentSchedule.Read.DirectoryMicrosoft Graph application permission with admin consentAdd the permission and grant tenant admin consent. If Azure returns AadPremiumLicenseRequired, no permission is missing; see the licensing note below.Active Global Admin and privileged-role assignments
Eligible directory role assignments access requiredRoleEligibilitySchedule.Read.DirectoryMicrosoft Graph application permission with admin consentAdd the permission and grant tenant admin consent. If Azure returns AadPremiumLicenseRequired, no permission is missing; see the licensing note below.Eligible Global Admin and privileged-role assignments through PIM
Directory role definitions access requiredRoleManagement.Read.DirectoryMicrosoft Graph application permission with admin consentAdd the permission and grant tenant admin consent.Directory role definitions and role-management context
Graph governance permissions requiredMicrosoft Graph governance permissionsMicrosoft Graph application permission with admin consentAdd the complete Spotto Graph governance application-permission set, including Policy.Read.All and LicenseAssignment.Read.All, and grant tenant admin consent.Application registration, service principal, Global Admin/PIM, group membership, user, audit, tenant policy, licensing, and MFA posture diagnostics

Handle optional billing export results

Optional subscription billing export, Optional tenant-level billing export, and Optional billing-account billing export report whether Spotto can use an existing Cost Management export. They do not block standard read-only onboarding and are not counted as missing permissions.

No action is required unless you want export-first billing ingestion. Locating an export definition and reading its files are separate checks: Spotto needs read access at the exact export scope, Storage Blob Data Reader on the destination, and a reachable storage network path. See Azure Billing Exports.

Retry checks that are not confirmed

Not confirmed means Azure or Microsoft Graph did not return a conclusive response. It does not mean the role shown for that capability is missing.

For example, Defender for Cloud assessments not confirmed with Azure did not respond before the validation timeout. Try validation again. is a timeout. Retry validation. Assign Security Reader only if a later result explicitly reports Missing or access required.

The same rule applies to Directory role definitions not confirmed. Retry validation before changing RoleManagement.Read.Directory consent.

Some cloud account form warnings are not subscription sync steps, but they use the same Missing permission pattern:

What Spotto showsMissing permission in tooltipAssign atWhat to fix
Advisor suppressions requiredCustom role with Advisor suppression actionsSubscriptionAssign a custom role with the Advisor suppression actions documented in the write-permissions guide.
Storage inventory write requiredCustom role with storage inventory policy read/write actionsSelected storage accountAssign the storage inventory policy read/write custom role if that automation is enabled.
Azure Policy exemptions requiredpolicyExemptions/write and policyAssignments/exempt/actionExemption target and exact policy assignment scopeFollow the policy exemption permission guide; inherited initiatives need the assignment action at their management group.

Retry validation or the affected sync

After the Azure change:

  1. Wait 5-15 minutes for Azure RBAC or Microsoft Graph consent to propagate.
  2. Return to the affected Azure cloud account in Spotto.
  3. Rerun account validation, the tenant sync, or the subscription sync that reported the result.
  4. Reopen Sync diagnostics and confirm the warning is gone.

What this error means

Error type: capabilityMissing

The Azure account can authenticate, but a specific dataset is unavailable. Spotto keeps the rest of the sync moving where it can and marks a confirmed authorization denial with the missing permission.

This is why credential validation can succeed while one feature still looks empty. Authentication worked. The narrower read path did not.

Why it happens

Azure uses different access models for different data sources:

  • Subscription inventory, resource groups, Activity Log, Resource Graph, and Advisor data usually depend on subscription Reader.
  • Core billing reads depend on Cost Management Reader, Reader, and sometimes CSP partner-side Azure Usage visibility. Cost Management exports and Storage Blob Data Reader are optional enhancements for export-first ingestion.
  • Management group governance depends on root management group access.
  • Reservations and Savings Plans use provider-scope roles. Reservation refund quote and management workflows need Reservations Contributor, not just Reservations Reader.
  • Microsoft Graph application, service principal, Global Admin/PIM, group membership, user, audit, tenant policy, subscribed-license, and MFA posture data require the documented Graph application permissions and tenant admin consent.
  • Monitoring and Log Analytics data can require roles at subscription, workspace, or monitored-resource scope.

These validation outcomes do not mean another role is missing:

  • Microsoft Graph error AadPremiumLicenseRequired means PIM schedule data is unavailable because the tenant does not have Microsoft Entra ID P2 or Microsoft Entra ID Governance. Spotto marks that schedule check Not applicable.
  • Azure resources such as microsoft.insights/actiongroups do not expose a platform metric namespace. Spotto skips them as metric-validation candidates instead of reporting a Monitoring Reader warning.
  • A client timeout or another Not confirmed response means the read was inconclusive. Retry validation before changing access.
  • An Optional billing-export result describes an enhancement that is not configured or could not be confirmed. It does not reduce standard onboarding readiness.

Who can fix it

The person who can fix the warning depends on the missing permission. In Spotto, the warning tooltip shows Assign at to identify the Azure scope. If the scope is outside your access, send this page to the Azure owner for that scope.

For CSP billing visibility, the customer tenant administrator may not be able to fix the partner policy. The CSP partner or billing administrator must enable Azure Usage visibility.

For Enterprise Agreement billing visibility, an Enterprise Administrator must enable Account owners can view charges (AO view charges). Subscription RBAC cannot override that enrollment policy.

Important notes

  • Spotto onboarding scripts and Terraform can assign Azure RBAC, but they cannot enable CSP partner-side billing visibility.
  • Billing export setup is optional. If enabled, Azure must write Cost Management exports to storage and the Spotto service principal needs Storage Blob Data Reader. Billing-scope exports also need read access at that billing scope for discovery.
  • Azure RBAC, management group permissions, and Microsoft Graph admin consent can take several minutes to propagate.
  • If the warning remains after the permission is granted, confirm the role was assigned to the same app registration/client ID configured in Spotto.
  • If multiple subscriptions show the same warning, check whether the role should be assigned at an inherited management group scope instead of one subscription at a time.