Azure Management and governance built-in role

Cost Management Reader

Reads cost and usage data and Cost Management configuration, including budgets and exports, without changing that configuration. It also reads Advisor recommendations and Azure hierarchy information and has no DataActions.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 72fafb9e-0641-4937-9268-a91bfd8191a3

Control-plane actions (10)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign at the Azure management group, subscription, or resource group whose costs the principal must inspect. Parent assignments inherit to child scopes; billing-account and billing-profile access use provider-specific billing roles rather than this Azure hierarchy alone.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign to analysts and stakeholders at the cost scope they are authorized to view. Escalate to Cost Management Contributor only for approved budget, export, or configuration changes.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →