Assign access to Cost Management data - Microsoft Cost Management (2024)

  • Article

For users with Azure Enterprise agreements, a combination of permissions granted in the Azure portal and the Enterprise (EA) portal define a user's level of access to Cost Management data. For users with other Azure account types, defining a user's level of access to Cost Management data is simpler by using Azure role-based access control (RBAC). This article walks you through assigning access to Cost Management data. After the combination of permissions is assigned, the user views data in Cost Management based on their access scope and on the scope that they select in the Azure portal.

The scope that a user selects is used throughout Cost Management to provide data consolidation and to control access to cost information. When scopes are used, users don't multi-select them. Instead, they select a larger scope that child scopes roll up to and then they filter-down to what they want to view. Data consolidation is important to understand because some people shouldn't access a parent scope that child scopes roll up to.

Watch the Cost Management controlling access video to learn about assigning access to view costs and charges with Azure role-based access control (Azure RBAC). To watch other videos, visit the Cost Management YouTube channel.

Cost Management scopes

Cost management supports various Azure account types. To view the full list of supported account types, see Understand Cost Management data. The type of account determines available scopes.

Azure EA subscription scopes

To view cost data for Azure EA subscriptions, a user must have at least read access to one or more of the following scopes.

ScopeDefined atRequired access to view dataPrerequisite EA settingConsolidates data to
Billing account¹https://portal.azure.com• Enterprise Admin
• Enrollment reader (Enterprise admin read-only)
NoneAll subscriptions from the enterprise agreement
Departmenthttps://portal.azure.comDepartment AdminDA view charges enabledAll subscriptions belonging to an enrollment account that is linked to the department
Enrollment account²https://portal.azure.comAccount OwnerAO view charges enabledAll subscriptions from the enrollment account
Management grouphttps://portal.azure.comCost Management Reader (or Contributor)AO view charges enabledAll subscriptions below the management group
Subscriptionhttps://portal.azure.comCost Management Reader (or Contributor)AO view charges enabledAll resources/resource groups in the subscription
Resource grouphttps://portal.azure.comCost Management Reader (or Contributor)AO view charges enabledAll resources in the resource group

¹ The billing account is also referred to as the Enterprise Agreement or Enrollment.

² The enrollment account is also referred to as the account owner.

Enterprise administrators can assign the billing account, department, and enrollment account scope in the Azure portal. For more information, see Azure portal administration for direct Enterprise Agreements.

Other Azure account scopes

To view cost data for other Azure subscriptions, a user must have at least read access to one or more of the following scopes:

  • Management group
  • Subscription
  • Resource group

Various scopes are available after partners onboard customers to a Microsoft Customer Agreement. Cloud solution providers (CSP) customers can then use Cost Management features when enabled by their CSP partner. For more information, see Get started with Cost Management for partners.

Enable access to costs in the Azure portal

The department scope requires the Department admins can view charges (DA view charges) option set to On. Configure the option in the Azure portal. All other scopes require the Account owners can view charges (Account owner (AO) view charges) option set to On.

To enable an option in the Azure portal:

  1. Sign in to the Azure portal with an enterprise administrator account.
  2. Select the Cost Management + Billing menu item.
  3. Select Billing scopes to view a list of available billing scopes and billing accounts.
  4. Select your Billing Account from the list of available billing accounts.
  5. Under Settings, select the Policies menu item and then configure the setting.
    Assign access to Cost Management data - Microsoft Cost Management (1)

After the view charge options are enabled, most scopes also require Azure role-based access control (Azure RBAC) permission configuration in the Azure portal.

Enterprise administrator role

By default, an enterprise administrator can access the billing account (Enterprise Agreement/enrollment) and all other scopes, which are child scopes. The enterprise administrator assigns access to scopes for other users. As a best practice for business continuity, you should always have two users with enterprise administrator access. The following sections are walk-through examples of the enterprise administrator assigning access to scopes for other users.

Assign billing account scope access

Access to the billing account scope requires enterprise administrator permission. The enterprise administrator can view costs across the entire EA enrollment or multiple enrollments. The enterprise administrator can assign access to the billing account scope to another user with read only access. For more information, see Add another enterprise administrator.

It might take up to 30 minutes before the user can access data in Cost Management.

Assign department scope access

Access to the department scope requires department administrator (DA view charges) access. The department administrator can view costs and usage data associated with a department or to multiple departments. Data for the department includes all subscriptions belonging to an enrollment account that are linked to the department.

Enterprise administrators can assign department administrator access. For more information, see Add a department administrator.

Assign enrollment account scope access

Access to the enrollment account scope requires account owner (AO view charges) access. The account owner can view costs and usage data associated with the subscriptions created from that enrollment account. Enterprise administrators can assign account owner access. For more information, see Add an account owner in the Azure portal.

Assign management group scope access

Access to view the management group scope requires at least the Cost Management Reader (or Reader) permission. You can configure permissions for a management group in the Azure portal. You must have at least the User Access Administrator (or Owner) permission for the management group to enable access for others. And for Azure EA accounts, you must also enable the AO view charges setting.

You can assign the Cost Management Reader (or reader) role to a user at the management group scope. For more information, see Assign Azure roles using the Azure portal.

Assign subscription scope access

Access to a subscription requires at least the Cost Management Reader (or Reader) permission. You can configure permissions to a subscription in the Azure portal. You must have at least the User Access Administrator (or Owner) permission for the subscription to enable access for others. And for Azure EA accounts, you must also enable the AO view charges setting.

You can assign the Cost Management Reader (or reader) role to a user at the subscription scope. For more information, see Assign Azure roles using the Azure portal.

Assign resource group scope access

Access to a resource group requires at least the Cost Management Reader (or Reader) permission. You can configure permissions to a resource group in the Azure portal. You must have at least the User Access Administrator (or Owner) permission for the resource group to enable access for others. And for Azure EA accounts, you must also enable the AO view charges setting.

You can assign the Cost Management Reader (or reader) role to a user at the resource group scope. For more information, see Assign Azure roles using the Azure portal.

Cross-tenant authentication issues

Currently, Cost Management provides limited support for cross-tenant authentication. In some circ*mstances when you try to authenticate across tenants, you may receive an Access denied error in cost analysis. This issue might occur if you configure Azure role-based access control (Azure RBAC) to another tenant's subscription and then try to view cost data.

To work around the problem: After you configure cross-tenant Azure RBAC, wait an hour. Then, try to view costs in cost analysis or grant Cost Management access to users in both tenants.

Next steps

  • If you haven't read the first quickstart for Cost Management, read it at Start analyzing costs.
Assign access to Cost Management data - Microsoft Cost Management (2024)

FAQs

Who can access Azure cost management? ›

To access Cost Management at the subscription scope, any user with Azure RBAC access to a subscription can view costs at retail (pay-as-you-go) rates. However the cost visibility policy for the customer tenant must be enabled. To view a full list of supported account types, see Understand Cost Management data.

How do I enable access to costs in the Azure portal? ›

Enable access to costs in the Azure portal

To enable an option in the Azure portal: Sign in to the Azure portal with an enterprise administrator account. Select the Cost Management + Billing menu item. Select Billing scopes to view a list of available billing scopes and billing accounts.

How to access cost analysis in Azure? ›

Cost analysis is available from every resource group, subscription, management group, and billing account in the Azure portal. If you manage one of these scopes, you can start there and select Cost analysis from the menu.

Can you use Azure Cost Management to view costs associated to management groups? ›

While Cost Management is available from within the Billing experience, Cost Management is also available from every subscription, resource group, and management group in the Azure portal to ensure everyone has full visibility into the costs they're responsible for and can optimize their workloads to maximize efficiency ...

How do I give access to Azure management group? ›

Assign Azure roles to other users
  1. Sign in to the Azure portal.
  2. Search for and select Management Groups.
  3. Select the relevant management group.
  4. Select Access control (IAM), open the Role assignments tab and select Add > Add role assignment.
  5. From the Add role assignment page, select the relevant role.
Mar 12, 2024

Where do customers access the Azure Cost Management tools? ›

Where is Microsoft Cost Management available? The product is available in the Azure Portal and can also be accessed through APIs.

How do I assign permissions in Azure portal? ›

Follow these steps assign a role to an external user at different scopes.
  1. Sign in to the Azure portal.
  2. In the Search box at the top, search for the scope you want to grant access to. ...
  3. Select the specific resource for that scope.
  4. Select Access control (IAM).
Feb 28, 2024

How do I enable access management for Azure resources? ›

Step 1: Elevate access for a Global Administrator
  1. Sign in to the Azure portal as a Global Administrator. ...
  2. Open Microsoft Entra ID.
  3. Under Manage, select Properties.
  4. Under Access management for Azure resources, set the toggle to Yes. ...
  5. Click Save to save your setting. ...
  6. Sign out and sign back in to refresh your access.

What is the difference between Azure Advisor and Azure Cost Management? ›

Cost Management works with Azure Advisor to provide cost optimization recommendations. Azure Advisor helps you optimize and improve efficiency by identifying idle and underutilized resources.

Is Azure Cost Management free? ›

Microsoft Cost Management for Azure is available at no additional cost. Microsoft Cost Management for AWS is charged at 1 percent of the total AWS managed spend at general availability, and free during preview.

Is Azure Cost Management real time? ›

Yes, it is possible to see real-time costs of the current day in the cost analysis of the Azure dashboard. Here are the steps to do so: In the Azure portal, navigate to cost analysis for your scope. For example: Cost Management + Billing > Cost Management > Cost analysis.

Which benefit of Azure cloud services supports Cost Management? ›

Which benefit of Azure Cloud Services supports cost management for this type of usage pattern? Elasticity in this case is the ability to provide additional compute resource when needed and reduce the compute resource when not needed to reduce costs.

How do I add a user to my Azure billing administrator? ›

Give a user access to manage billing

Enter subscriptions in the search box and select Subscriptions. Choose the subscription > Access control (IAM) > + Add, and then Add co-administrator from the dropdown menu. Select the user, and then select Add.

What is required for Azure Cost Management? ›

You can integrate Azure Cost Management with Azure Advisor, and gain cost recommendations tailored to your usage. To further customize your cost management, you can use REST APIs and integrate with Microsoft Power BI.

Who can access Azure government? ›

Determine if you're eligible for Azure Government—a cloud platform available to US federal, state, local, or tribal government entities and their solution providers—or apply for a free trial. There are different purchase options, depending on the size and needs of your organization.

Can anyone access my Azure Container Registry? ›

An Azure container registry by default accepts connections over the internet from hosts on any network. This article shows how to configure your container registry to allow access from only specific public IP addresses or address ranges. Equivalent steps using the Azure CLI and Azure portal are provided.

Who can access Azure storage account? ›

By default, every resource in Azure Storage is secured, and every request to a secure resource must be authorized. Authorization ensures that the client application has the appropriate permissions to access a particular resource in your storage account.

Top Articles
Latest Posts
Article information

Author: Prof. Nancy Dach

Last Updated:

Views: 5747

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Prof. Nancy Dach

Birthday: 1993-08-23

Address: 569 Waelchi Ports, South Blainebury, LA 11589

Phone: +9958996486049

Job: Sales Manager

Hobby: Web surfing, Scuba diving, Mountaineering, Writing, Sailing, Dance, Blacksmithing

Introduction: My name is Prof. Nancy Dach, I am a lively, joyous, courageous, lovely, tender, charming, open person who loves writing and wants to share my knowledge and understanding with you.