Evaluate Infralign
Exact permissions
A pre-sales summary of the two Azure roles Infralign uses, their material caveats, and where to find the full reference and validation runbook.
Two Azure built-in roles, both read-only, both assigned per subscription to a service principal your organisation creates in its own tenant. The permissions reference carries the endpoint-level tables, the least-privilege custom role, and the revocation steps.
What is granted
Section titled “What is granted”| Item | Scope | Read-only | Notes |
|---|---|---|---|
| Cost Management Reader | Each subscription you include | Yes | Authorises the Cost Details report operation. Plain Reader returns 403 on it. Bundles an unused Microsoft.Support/* permission — see the caveat below. |
| Reader | Each subscription you include | Yes | */read — Resource Graph inventory, control-plane metadata, Advisor, Monitor metrics, Activity Log. No DataActions. |
| Storage Blob Data Reader (optional) | One FOCUS export container | Yes | Only if you opt into the FOCUS export lane. Not part of the default set. |
| Microsoft Teams webhook (optional) | One channel | — | Delivers pipeline summary and failure cards. |
| Owner, Contributor, User Access Administrator | — | — | Never requested, at any scope, at any stage. |
| Management-group or tenant scope | — | — | Not used unless you choose it for your own convenience. |
| Microsoft Graph application permissions | — | — | None. The ingestion service principal needs no admin consent. |
| Source repository access | — | — | None. |
| Agent on a VM | — | — | None installed. |
The caveat to put in front of your security reviewer
Section titled “The caveat to put in front of your security reviewer”Microsoft’s Cost Management Reader definition bundles cost and billing read operations and Microsoft.Support/* — permission to create and update a support ticket. Infralign does not use it, but assigning the built-in role grants it. A customer that cannot accept an unused permission must agree and validate the custom-role alternative before connecting.
Reader is broad control-plane visibility, and a security owner should approve that scope deliberately. Why the platform asks for that breadth, and the least-privilege custom role that replaces it, are in why Reader, and what it cannot see.
Dashboard user sign-in, if enabled, is a separate identity flow. Confirm the application identity, publisher state, requested permissions, and revocation before consent — see dashboard sign-in.
Validate before data collection
Section titled “Validate before data collection”Use the validation runbook to confirm authentication, subscription discovery, Resource Graph, metrics, Advisor, Activity Log, and cost access. The one-business-day visibility target starts after the agreed access passes validation.
Revocation is yours: remove both role assignments on every included subscription, delete the app registration or rotate its credential, and remove any separately approved storage access. New pulls stop immediately. Data already collected is deleted through the 30-day offboarding process in security and data handling.
Next: Savings measurement methodology — how an indicative opportunity becomes a verified saving.