Skip to main content

Azure Permissions: What Spotto Needs and Why

Spotto needs Reader on the subscriptions you want it to see. Everything else is optional. Each extra permission switches on more of Spotto, and you can add or remove any of them later without reconnecting.

This page covers the Spotto service principal, the identity Spotto uses after setup. The person running setup needs broader, temporary access: see Permissions To Run Setup.

Four access levels. Level 1, required: Reader on each subscription, for inventory, costs, Advisor recommendations, activity log and policy checks. Level 2, recommended: Azure read roles for security, metrics, Log Analytics savings, Key Vault expiry and commitments. Level 3, recommended: Entra ID read through Microsoft Graph, for app secret expiry, real names in activity logs and admin posture. Level 4, optional and off by default: write-back custom roles.Four access levels. Level 1, required: Reader on each subscription, for inventory, costs, Advisor recommendations, activity log and policy checks. Level 2, recommended: Azure read roles for security, metrics, Log Analytics savings, Key Vault expiry and commitments. Level 3, recommended: Entra ID read through Microsoft Graph, for app secret expiry, real names in activity logs and admin posture. Level 4, optional and off by default: write-back custom roles.
LevelWhat you grantOn by default in automated setup?
1. RequiredReader on each subscriptionAlways
2. RecommendedAzure read roles: Security Reader, Monitoring Reader, Log Analytics Reader, Key Vault Reader, Reservations Reader, Savings plan Reader, Management Group ReaderYes
3. RecommendedEntra ID read: nine read-only Microsoft Graph application permissionsYes
4. OptionalWrite-back: small custom roles, one per feature you turn onNo

Every automated path (Click & Connect, the PowerShell script, the Terraform module) grants levels 1 to 3 by default. They differ only in billing exports and write-back; see What each setup path grants.

Access Matrix​

Find the feature you care about, then check what it needs and what happens without it.

Spotto featureNeedsWithout it
Resource inventory, relationship graphs, tagsReaderSpotto can't connect the subscription
Recommendations from Azure Advisor and Spotto's own rulesReaderRequired
Cost Analysis and Cost TreeReader, plus billing exports for full historyWithout exports, Spotto uses billing APIs: slower, and history can have gaps
Governance: Azure Policy and RBAC reviewReaderRequired
Change Monitoring: what changedReaderRequired
Change Monitoring: who made the changeMicrosoft Graph (Application.Read.All)Apps, pipelines and managed identities show as GUIDs instead of names
Security: secure score and Defender findingsSecurity ReaderSecurity page is incomplete
Rightsizing and oversized compute from real CPU and memory useMonitoring ReaderFewer recommendations, and savings estimates without metric evidence
Log Analytics cost savings, such as switching off verbose loggingLog Analytics ReaderSpotto sees the workspace bill, but not which logs drive it
Server uptime in reports: servers running longer than 45 days without a rebootLog Analytics Reader, with servers reporting to a Log Analytics workspaceServer Uptime in reports has no data
Retirement Tracker: Key Vault secret, key and certificate expiry, with alertsKey Vault ReaderKey Vault expiries are not tracked
Retirement Tracker: app registration and service principal secret expiry, with alertsMicrosoft Graph (Application.Read.All)App credential expiries are not tracked
Commitments: reservations, utilization and expiry alertsReservations ReaderYour reservations are invisible, so no expiry warnings and coverage looks lower than it is
Commitments: savings plans, utilization and expiry alertsSavings plan ReaderYour savings plans are invisible, with the same effect
New subscriptions picked up automatically, management group hierarchyReader and Management Group Reader at the root management groupAdd new subscriptions to Spotto yourself; no hierarchy view
Identity posture: Global Admins, PIM, MFA and Conditional AccessMicrosoft Graph (role, user, audit and policy permissions)Identity findings are empty
Dismiss in Spotto, also dismissed in Azure AdvisorWrite-back: Advisor custom roleDismiss it in Azure Advisor yourself
Resource schedules for VMs and Azure BastionWrite-back: resource scheduling custom roleStart and stop resources yourself
Azure Policy exemptions from Regulatory ComplianceWrite-back: policy exemption custom roleCreate the exemption in Azure yourself
Reservation refund quotesWrite-back: Reservations ContributorNo refund estimate on the Commitments page

Can't Grant Everything?​

That's fine, and common. Spotto works with whatever you grant, shows Permission required where data is missing, and picks up new access on the next sync. Here is what the usual trade-offs mean:

Your situationStill worksWhat you miss
Reader onlyInventory, costs, recommendations, activity log, governanceSecurity, metric-based rightsizing, Log Analytics savings, server uptime, Key Vault expiry, commitments, identity
No Entra ID access. Many customers treat the directory as sensitive.Every Azure featureApp secret expiry alerts, names instead of GUIDs in activity logs, identity posture
No Reservations or Savings plan Reader. Often missed, because it is assigned at a special billing scope.Everything elseExisting reservations and savings plans, their utilization and expiry alerts. The Commitments page is much less useful.
Selected subscriptions only, no root management groupEverything, for the selected subscriptionsNew subscriptions don't appear until you add them
No billing exportsCosts through Azure billing APIsLong history, and the most complete daily data. Recent days can be estimated.
Read-only, no write-backAll read featuresChanges made from Spotto still have to be made in Azure by hand

To add a permission later, assign it in Azure (or run Update Access on the cloud account in Spotto) and wait for the next sync. See Fix a missing permission.

What Spotto Reads, And What It Never Reads​

Every permission Spotto asks for reads metadata: names, settings, dates, totals. None of them let Spotto read the data inside your resources.

What Spotto reads and never reads. Reader: resource settings, costs and activity log, never data inside resources or access keys. Key Vault Reader: names and expiry dates, never secret values or key material. Log Analytics Reader: log volume per table, counts by level, and each server's last boot time and heartbeat, never log entries. Microsoft Graph: app names, credential expiry and admin settings, never mail, files or chats, and no directory changes. Reservations and Savings plan Reader: term, expiry and utilization, never purchases or changes.What Spotto reads and never reads. Reader: resource settings, costs and activity log, never data inside resources or access keys. Key Vault Reader: names and expiry dates, never secret values or key material. Log Analytics Reader: log volume per table, counts by level, and each server's last boot time and heartbeat, never log entries. Microsoft Graph: app names, credential expiry and admin settings, never mail, files or chats, and no directory changes. Reservations and Savings plan Reader: term, expiry and utilization, never purchases or changes.

Entra ID (Microsoft Graph)​

Directory access is the permission customers most often hold back. It is read-only, it never touches mail, files or chats, and it can't change your directory. Here is what each permission is for:

Graph permissionWhat Spotto uses it for
Application.Read.AllApp registration and service principal secret and certificate expiry, and names for apps and managed identities in activity logs
User.Read.AllNames for users in admin, MFA and principal findings
GroupMember.Read.AllWorking out who has privileged access through a group
RoleManagement.Read.DirectoryDirectory roles such as Global Administrator
RoleAssignmentSchedule.Read.DirectoryActive privileged role assignments, including PIM activations
RoleEligibilitySchedule.Read.DirectoryPIM eligible roles
AuditLog.Read.AllPIM activation history, MFA registration and admin sign-in activity
Policy.Read.AllSecurity defaults, Conditional Access and authentication method policies
LicenseAssignment.Read.AllWhich Entra licences the tenant has, so Spotto only checks what you are licensed for

Grant them all, some, or none. Click & Connect lets you untick individual permissions. Manual steps are in Grant Microsoft Graph permissions.

Key Vault Reader​

Spotto lists the secrets, keys and certificates in each vault and reads their expiry dates, then warns you in the Retirement Tracker before something expires and breaks. Key Vault Reader can't read secret values or private keys.

It works for vaults that use Azure RBAC. Vaults that still use access policies also need a List access policy for the Spotto service principal.

Log Analytics Reader​

Spotto uses this role to work out where your Log Analytics money goes and how long your servers have been running, not to read your logs. It runs a few aggregate queries per workspace:

  • Billable GB ingested per table over the last 31 days.
  • Counts of log records by level or category, such as Verbose, Information and Error, for App Service console logs, event logs and Azure diagnostics.
  • For each server, its last boot time and its first and last heartbeat over the last 90 days, from the VMComputer (VM insights) and Heartbeat tables. This feeds the Server Uptime section of reports, which lists servers running longer than 45 days without a reboot. Servers that don't send these tables to a workspace can't be included.

An example: a workspace costs $10,000 a month, and 80% of what it ingests is verbose logging. Spotto can recommend switching verbose logging off and turning it on only while you troubleshoot, saving up to $8,000 a month. Without this role, Spotto sees the $10,000 bill but not what is inside it.

note

Log Analytics Reader is the smallest built-in role that can run queries, so Azure lets it read log data. Spotto only runs the aggregate queries above.

Reservations And Savings Plan Reader​

These roles let the Commitments page show the reservations and savings plans you already own: how well they are used and when they expire, so you can renew before costs jump back to pay-as-you-go. They are read-only and can't buy, exchange or cancel anything.

They are assigned at tenant-wide billing scopes (/providers/Microsoft.Capacity and /providers/Microsoft.BillingBenefits), not on a subscription, which is why they are the ones most often missed. See Permissions To Run Setup for who can assign them.

Optional Write-Back​

Spotto is read-only by default. Write-back lets actions you take in Spotto reach Azure. Each feature has its own custom role with only the actions it needs, and each is off until you turn it on.

Optional write-back. Dismissing a recommendation uses an Advisor suppression role on the subscription and also dismisses it in Azure Advisor. Scheduling a VM uses start and deallocate on that VM only. Scheduling Azure Bastion uses delete and recreate on its resource group, so there are no Bastion charges outside your access windows. Exempting a policy uses policy exemption write, and the exemption and reason appear in Azure Policy. Quoting a reservation refund uses Reservations Contributor and changes nothing.Optional write-back. Dismissing a recommendation uses an Advisor suppression role on the subscription and also dismisses it in Azure Advisor. Scheduling a VM uses start and deallocate on that VM only. Scheduling Azure Bastion uses delete and recreate on its resource group, so there are no Bastion charges outside your access windows. Exempting a policy uses policy exemption write, and the exemption and reason appear in Azure Policy. Quoting a reservation refund uses Reservations Contributor and changes nothing.
FeatureCustom role actionsScope
Dismissals sync to Azure AdvisorWrite and delete Advisor suppressionsSubscription
VM schedulesRead, start and deallocate the VMThat VM
Azure Bastion schedulesRead, delete and recreate the Bastion hostThe Bastion's resource group
Azure Policy exemptionsWrite policy exemptions, exempt from policy assignmentsSubscription, plus the policy assignment's scope
Reservation refund quotesReservations Contributor (built-in role)/providers/Microsoft.Capacity

How they get set up: Click & Connect, the PowerShell script (Custom mode) and Terraform can create the Advisor, policy exemption and Reservations Contributor roles. VM and Bastion schedule roles are granted when you activate a schedule: Spotto shows the exact actions and asks you to approve them. The full action lists are in Advisor write permissions and Policy exemptions.

Before a schedule runs, Spotto checks for resource locks, deny assignments and policies that would block it. Bastion schedules remove the Bastion host outside your access windows and recreate it when a window opens, because Azure has no way to pause a Bastion host.

To keep read and write access apart, you can give write-back its own credential. See Configure write permissions. For the remediation actions you can run on recommendations, see the Remediation Action Catalog.

What Each Setup Path Grants​

PermissionClick & ConnectPowerShell (Recommended mode)Terraform
Reader on selected subscriptionsYesYesYes
Reader above your subscriptions, so new ones appear automaticallyYes, at the root management groupYes, at tenant rootOnly in tenant-wide mode (assign_reader_to_all_subscriptions) or for listed management_group_ids
Azure read roles (level 2)YesYesYes, each has a toggle
Microsoft Graph read (level 3)Yes, untick any you don't wantYesYes (enable_graph_permission)
Billing exportsOff. Opt in.Asks, defaults to yesOff (enable_billing_exports)
Write-back (level 4)Off. Opt in.Off. Custom mode only.Off (grant_optional_write_permissions)
Resource schedulesWhen you activate a scheduleNot availableNot available

The Manual Azure Portal Setup walks through the same permissions one at a time.

Fix A Missing Permission​

When a sync step can't read something, Cloud Accounts sync diagnostics show Permission required with the missing role and scope.

  1. Open the warning in Spotto and note the permission, scope, tenant and subscription.
  2. Assign the permission in Azure, or on a Click & Connect account select Update Access (or Repair Setup) and let Spotto do it.
  3. Wait 5 to 10 minutes for Azure role assignments or Graph consent to take effect.
  4. Run the tenant or subscription sync again.
Warning mentionsAssignAt
ReaderReaderSubscription, or a management group above it
Security ReaderSecurity ReaderSubscription
Monitoring ReaderMonitoring ReaderSubscription or management group
Log Analytics ReaderLog Analytics ReaderSubscription, workspace or management group
Key Vault ReaderKey Vault ReaderManagement group, subscription or vault
Management Group ReaderManagement Group ReaderRoot management group
Reservations ReaderReservations Reader/providers/Microsoft.Capacity
Savings plan ReaderSavings plan Reader/providers/Microsoft.BillingBenefits
Microsoft GraphThe named Graph application permission, with admin consentTenant
Cost Management ReaderCost Management ReaderThe billing or management group scope that holds your export
Billing export storageStorage Blob Data ReaderThe export storage container

Every warning, with its exact text, is listed in Azure Cloud Account Permission Warnings. Step-by-step role assignment is in Manual Azure Portal Setup.

GDAP Accounts​

Accounts connected through GDAP use delegated partner access instead of a Spotto service principal, and they need three separate grants: delegated Entra roles, Azure subscription access and CSP billing visibility. Getting one right does nothing for the others. See How Azure access works under GDAP. Billing exports aren't supported under GDAP.

CSP Billing Prerequisites​

Subscriptions bought through a CSP partner on Microsoft Azure Plan need the partner to switch on cost visibility. Without it, the connection validates but cost features stay empty.

  1. The subscription is on Microsoft Azure Plan or Microsoft Customer Agreement, not the older classic CSP offer.
  2. In the partner tenant, an Admin agent who is also a Billing admin opens Cost Management + Billing, selects the billing account, then Customers, the customer, and Policies.
  3. Set Azure Usage to Yes.
  4. Spotto (or, for GDAP, the partner security group) has Reader on the subscriptions.
caution

No Spotto setup path can change this partner-side policy. Only the CSP partner can.