Azure Permissions
Introduction
Azure Permissions are the least-privilege policies CoreStack requires to onboard and manage an Azure account. CoreStack uses these permissions to ingest cost, inventory, configuration, and security data from your subscription, and — where read-write access is granted — to execute policy-based remediation. This page is relevant before onboarding any Azure account, or when adding a new product (FinOps, SecOps, CloudOps) to an existing one. It applies to Account Admin and Provider Admin users who manage cloud account onboarding
How It Works
Once Azure permissions are granted, Azure cost and usage data syncs approximately 3 times daily (an 8-hour cycle) via the Cost Management export file in Azure Storage. Inventory, configuration, policy evaluation, and access-posture data all sync every 24 hours (configurable). Utilization metrics sync on a 4, 8, or 24-hour user-selectable interval via Azure Monitor. Activity and audit events ingest near real-time via Activity Log alerts and action groups. Threat findings ingest near real-time once Microsoft Defender for Cloud is customer-configured. Each ingestion path runs as an independently observable process with its own run history and on-demand re-run, visible in Governance > Cloud Accounts > Account Status & Configurations.
Refer to the following user guides to get a summary of which least privilege policies are required to setup in your Azure cloud portal for different products and access levels::
Updated 3 days ago