Skip to content
Ops Log
Decision MemoSecurity & Infrastructure15 September 20268 min read

The Azure role called Cost Management Reader is not read-only

Cost Management Reader is described as able to view cost data, yet its action list carries a Microsoft.Support wildcard that includes creating and updating support tickets. The built-in Reader role matches it on every Cost Management feature and cannot write a ticket.

Cover image for The Azure role called Cost Management Reader is not read-only
MJ

The Azure built-in role named Cost Management Reader is described as a role that can view cost data, and its own action list contains a wildcard over the Microsoft.Support resource provider, which includes the action that creates and updates a support ticket. An administrator who assigns it to a monitoring identity because the name and the one-line description both say view is granting write access to support tickets that the description never mentions.

Last verified: 2026-09-15.

What the role definition says

The definition is published on Azure built-in roles for Management and governance, read 2026-09-15. Its description for the role is "Can view cost data and configuration (e.g. budgets, exports)". The action list in the role's JSON definition (role id 72fafb9e-0641-4937-9268-a91bfd8191a3) has ten entries: Microsoft.Consumption/*/read, Microsoft.CostManagement/*/read, Microsoft.Billing/billingPeriods/read, Microsoft.Resources/subscriptions/read, Microsoft.Resources/subscriptions/resourceGroups/read, Microsoft.Support/*, Microsoft.Advisor/configurations/read, Microsoft.Advisor/recommendations/read, Microsoft.Management/managementGroups/read and Microsoft.Billing/billingProperty/read. Nine of the ten end in /read, the substring that Understand Azure role definitions, read the same day, says "Enables read actions (GET)". The sixth entry, Microsoft.Support/*, ends in a bare wildcard, which the same page says "grants access to all actions that match the string". The description column on the built-in roles page reads "Create and update a support ticket" against that row.

The permission list for the provider, on Azure permissions for General, read the same day, names twelve actions under Microsoft.Support. Six end in /read, among them Microsoft.Support/supportTickets/read, "Lists one or all support tickets". Five end in /action, among them Microsoft.Support/register/action, "Registers Support Resource Provider". The twelfth is Microsoft.Support/supportTickets/write, "Allows creating and updating a support ticket". An identity holding Cost Management Reader holds all twelve through the one wildcard entry, and none of the twelve concerns cost data.

Why it reads as read-only

The name says Reader and the description says view. The role's own Learn more link on the built-in roles page points to Understand and work with scopes, read 2026-09-15, which lists Cost Management Reader among the roles Cost Management supports as "View-only access to cost data and recommendations". The table on that page headed Feature behavior for each role in RBAC scopes then gives Cost Management Reader Read only on Cost Analysis, Forecast, Query and the Cost Details API, and on Shared views, Budgets, Alerts and Exports: the same entries it gives the built-in Reader role on every row.

Everything on the page a reader is sent to for capability is accurate about Cost Management, and none of it mentions support tickets: the word ticket does not appear on it. The support permission is visible only in the action table and the JSON block on the built-in roles page itself, a general RBAC reference that a reader following the Cost Management documentation has no reason to open.

What it costs

A least-privilege review that records Cost Management Reader as read access to billing understates what the identity can do. Through Microsoft.Support/supportTickets/write it can create a support ticket and update an existing one. Through Microsoft.Support/register/action it can register the Support resource provider, a custom action of the kind Understand Azure role definitions describes as "Enables custom actions like restart virtual machines (POST)". The scopes page adds that a role assigned at a management group "also grants the same permissions to nested subscriptions and resource groups", so one assignment high in the hierarchy carries the ticket write to every subscription beneath it. For an unattended collector whose credential leaks, the exposure the review recorded was a read of cost data; the exposure that exists includes a write path to Microsoft support at every scope the role reaches.

How to check it

The role definition returned by Azure Resource Manager is the object the claim rests on, and it can be read without any write permission:

powershell
az role definition list --name "Cost Management Reader" --query "[0].permissions[0].actions" -o tsv
az role definition list --name "Reader" --query "[0].permissions[0].actions" -o tsv
az role definition list --name "Cost Management Reader" --query "[0].[createdOn,updatedOn]" -o tsv

Run with the Azure CLI on 2026-09-15, the first command printed the same ten action strings the documentation lists, Microsoft.Support/* sixth among them, and the second printed one line, */read. The third reported that the Cost Management Reader definition was created on 2018-03-14 and last updated on 2021-11-11. All three commands list a role definition; none assigns a role or changes anything.

Recommendation

Where the job is reading cost, consumption and Advisor data, assign the built-in Reader role instead of Cost Management Reader. Its description on Azure built-in roles for General, read 2026-09-15, is "View all resources, but does not allow you to make any changes". Its whole action list is */read, which Understand Azure role definitions describes as granting "access to read actions for all resource types of all Azure resource providers", and the scopes page's feature table gives Reader the same entry as Cost Management Reader on every Cost Management row. Because Microsoft.Support/supportTickets/read is a read action, Reader can still list support tickets. It cannot create or update one, and it matches none of the five Support actions that end in /action.

Trade-offs

Reader narrows the Support grant and widens everything else. On support tickets it keeps the list and drops the create and update. On every Cost Management feature in the scopes table it matches Cost Management Reader row for row. Outside Cost Management, */read reaches read actions for every resource type of every resource provider, so the identity can read the control plane configuration of every resource in scope as well as its cost. Understand Azure role definitions bounds that reach at the control plane: a user with Reader on a subscription "can view the storage account, but by default they can't view the underlying data". Cost Management Reader's ten entries stop at consumption, cost management, two billing reads, subscription and resource group reads, two Advisor reads, management group reads and the Support wildcard.

Neither built-in role is limited to cost data. The narrowest option derived from the published definitions is a custom role that copies Cost Management Reader's nine /read entries and leaves out Microsoft.Support/*. The permissions page presents its action strings as permissions to use "in your own Azure custom roles to provide granular access control to resources in Azure". That custom role was not built or tested for this note, so whether every Cost Management portal view works under it is unverified.

The first five rows below come from the scopes page's feature table; the last two follow from the two action lists.

CapabilityReaderCost Management Reader
Cost Analysis, Forecast, Query, Cost Details APIRead onlyRead only
Shared viewsRead onlyRead only
BudgetsRead onlyRead only
AlertsRead onlyRead only
ExportsRead onlyRead only
Support ticketsList, through */readList, create and update, through Microsoft.Support/*
Other resource providersRead, through */readNothing beyond the ten listed entries

Where it does not apply

A job that creates budgets, exports or shared views needs neither read role. The scopes page's feature table gives Reader and Cost Management Reader Read only on Budgets, Shared views and Exports, and gives Create, Read, Update, Delete on all three to Owner, Contributor and Cost Management Contributor. The Support finding does not decide that choice.

An identity that already holds Contributor at the same scope gains nothing from losing Cost Management Reader. The Contributor definition shown on Understand Azure role definitions has a single action, *, with NotActions limited to authorization, Blueprints assignment, gallery sharing and Purview consent entries, so the Support actions sit inside its grant regardless.

A human administrator who is expected to open Microsoft support cases needs the ticket write. For that person the Support wildcard is part of the job, and moving them to Reader would take it away.

Billing scopes are outside this note. The scopes page describes Enterprise Agreement and Microsoft Customer Agreement billing roles as a separate set, and this note reads only the two Azure RBAC roles.

Limitations

This note establishes what the published role definition authorizes. It does not establish what happens when an identity holding only Cost Management Reader calls the support ticket API or opens the portal's support request form: no identity was created and no ticket was opened for it. The live check above read the definition, which is the object Azure Resource Manager evaluates, and it matched the documentation on 2026-09-15.

The count of twelve Support actions is the permissions page's. A live listing of the provider's operations with az provider operation show --namespace Microsoft.Support on the same day returned ten, without the two classify actions the page lists (classifyServices/action and services/classifyProblems/action); supportTickets/write and register/action appeared in both. Both roles carry empty DataActions arrays, so nothing here concerns data plane access to resource contents.

The Azure cost review names the built-in Reader role, and not Cost Management Reader, as the role its subscription connection asks for, for the reason set out above.

Sources and further reading

Was this field note useful?
Make the decision

Turn the trade-off into a scoped brief.

Share the constraints that differ in your environment. Michal will identify the next check needed before a delivery decision.

Start a scoped brief