Enterprise Application Access
Resource Lens uses an enterprise application in your tenant with Azure role assignments you control.
Key points
- Tenant consent is reviewed during setup before any Azure scope is configured.
- Azure access is defined by role assignments on the management groups or subscriptions you select.
- Reader is required; Cost Management Reader, Monitoring Reader, and Advisor Reviews Reader add optional evidence.
- Portal settings show the roles held on each subscription and let authorized administrators grant or revoke them.
- The workspace reset workflow removes Resource Lens role assignments before data is purged.