Grant Admin Consent
Granting consent requires the Global Administrator role in Azure AD.
-
Open a new browser window (private browsing is best).
-
Insert your tenant ID into this URL and open it:
https://login.microsoftonline.com/YOUR_TENANT_ID_HERE/adminconsent?client_id=08b8b2cc-48f0-4ce1-8323-411cba07eb78&state=54321&redirect_uri=https://spotter.cloud2.fi/azure-admin-consent -
Grant consent with your Global Admin account.
-
Verify that Spotter appears in Enterprise Applications.
Be mindful of possible device authentication failures.
Assign Permissions to Spotter
Assigning permissions requires ownership of the target object. As a Global Admin you can elevate to the User Access Administrator role to reach all management groups and subscriptions. Use the Access Control (IAM) panel to make the assignments.
Assign the Reader role at the management group level to cover all subscriptions, or at an individual subscription scope to limit visibility. Reader rights give no access to customer data.
Reader is not enough for cost and sustainability data, which comes only from the cost and usage export. That also needs Cost Management Contributor on your subscriptions and Owner plus Storage Blob Data Reader on the export storage account — see Azure cost and usage export setup for Spotter.