Skip to content

Evaluate Infralign

Exact permissions

A pre-sales summary of the two Azure roles Infralign uses, their material caveats, and where to find the full reference and validation runbook.

Two Azure built-in roles, both read-only, both assigned per subscription to a service principal your organisation creates in its own tenant. The permissions reference carries the endpoint-level tables, the least-privilege custom role, and the revocation steps.

ItemScopeRead-onlyNotes
Cost Management ReaderEach subscription you includeYesAuthorises the Cost Details report operation. Plain Reader returns 403 on it. Bundles an unused Microsoft.Support/* permission — see the caveat below.
ReaderEach subscription you includeYes*/read — Resource Graph inventory, control-plane metadata, Advisor, Monitor metrics, Activity Log. No DataActions.
Storage Blob Data Reader (optional)One FOCUS export containerYesOnly if you opt into the FOCUS export lane. Not part of the default set.
Microsoft Teams webhook (optional)One channelDelivers pipeline summary and failure cards.
Owner, Contributor, User Access AdministratorNever requested, at any scope, at any stage.
Management-group or tenant scopeNot used unless you choose it for your own convenience.
Microsoft Graph application permissionsNone. The ingestion service principal needs no admin consent.
Source repository accessNone.
Agent on a VMNone installed.

The caveat to put in front of your security reviewer

Section titled “The caveat to put in front of your security reviewer”

Microsoft’s Cost Management Reader definition bundles cost and billing read operations and Microsoft.Support/* — permission to create and update a support ticket. Infralign does not use it, but assigning the built-in role grants it. A customer that cannot accept an unused permission must agree and validate the custom-role alternative before connecting.

Reader is broad control-plane visibility, and a security owner should approve that scope deliberately. Why the platform asks for that breadth, and the least-privilege custom role that replaces it, are in why Reader, and what it cannot see.

Dashboard user sign-in, if enabled, is a separate identity flow. Confirm the application identity, publisher state, requested permissions, and revocation before consent — see dashboard sign-in.

Use the validation runbook to confirm authentication, subscription discovery, Resource Graph, metrics, Advisor, Activity Log, and cost access. The one-business-day visibility target starts after the agreed access passes validation.

Revocation is yours: remove both role assignments on every included subscription, delete the app registration or rotate its credential, and remove any separately approved storage access. New pulls stop immediately. Data already collected is deleted through the 30-day offboarding process in security and data handling.


Next: Savings measurement methodology — how an indicative opportunity becomes a verified saving.