Enterprise Application Access

Resource Lens uses an enterprise application in your tenant with Azure role assignments you control.

Key points

  • Tenant consent is reviewed during setup before any Azure scope is configured.
  • Azure access is defined by role assignments on the management groups or subscriptions you select.
  • Reader is required; Cost Management Reader, Monitoring Reader, and Advisor Reviews Reader add optional evidence.
  • Portal settings show the roles held on each subscription and let authorized administrators grant or revoke them.
  • The workspace reset workflow removes Resource Lens role assignments before data is purged.