[metadata]
adobe-target: true
asset_id: cost-management-billing/automate/cost-management-api-permissions
author: vikramdesai01
breadcrumb_path: /azure/bread/toc.json
cmProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/1d9b4802-f23d-41f1-9e27-65deeceacb8d
cmProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/4e834929-0ce1-4c1d-9c81-fcb14721edfb
cmProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/68ec7f3a-2bc6-459f-b959-19beb729907d
color-scheme: light dark
depot_name: Azure.azure-documents
description: This article describes what you need to know to successfully assign permissions to an Azure service principal.
document_id: f8f7541c-dc50-e155-f12e-775e72339223
document_version_independent_id: c87db0f9-72dc-5d74-9a11-5d17c4f279fc
feedback_help_link_type: get-help-at-qna
feedback_help_link_url: https://learn.microsoft.com/answers/tags/118/azure-cost-management/
feedback_product_url: https://feedback.azure.com/d365community/forum/748a4eaa-0e25-ec11-b6e6-000d3a4f07b8
feedback_system: Standard
git_commit_id: e2507938b2a97d1c5db073fc57046b84254900a0
gitcommit: https://github.com/MicrosoftDocs/azure-docs-pr/blob/e2507938b2a97d1c5db073fc57046b84254900a0/articles/cost-management-billing/automate/cost-management-api-permissions.md
github_feedback_content_git_url: https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/cost-management-billing/automate/cost-management-api-permissions.md
item_type: Content
learn_banner_products: azure
locale: en-us
markdown_url: https://learn.microsoft.com/en-us/azure/cost-management-billing/automate/cost-management-api-permissions?accept=text/markdown
ms.author: vikdesai
ms.custom: devx-track-arm-template
ms.date: 2025-06-26T00:00:00Z
ms.reviewer: vikdesai
ms.service: cost-management-billing
ms.subservice: cost-management
ms.suite: office
ms.topic: how-to
og:description: This article describes what you need to know to successfully assign permissions to an Azure service principal.
og:image: https://learn.microsoft.com/en-us/media/open-graph-image.png
og:image:alt: Microsoft Learn
og:title: Assign permissions to Cost Management APIs - Microsoft Cost Management
og:type: website
og:url: https://learn.microsoft.com/en-us/azure/cost-management-billing/automate/cost-management-api-permissions
original_content_git_url: https://github.com/MicrosoftDocs/azure-docs-pr/blob/live/articles/cost-management-billing/automate/cost-management-api-permissions.md
page_type: conceptual
pdf_url_template: https://learn.microsoft.com/pdfstore/en-us/Azure.azure-documents/{branchName}{pdfName}
permissioned-type: public
platform_id: 336b79a0-5e46-fe57-30ee-98c149bfc6b8
previous_tlsh_hash: 78E56441120FC260BD834613BA5B7311C57684D9F5B5A9C8049BDB66C6B81D77167965A7DF4771C80A32DBB51BD77E5801E23F2C881DA0E8335ADABD812C12F3B9F4303148
recommendation_types: Certification
recommendation_types: Training
recommendations: true
schema: Conceptual
scope: Azure,Cost Management Billing
site_name: Docs
source_path: articles/cost-management-billing/automate/cost-management-api-permissions.md
spProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/75670257-a3f0-4627-9981-8046f99219e6
spProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/820483fb-3aa1-4b86-bc99-9a906a24f579
spProducts: https://authoring-docs-microsoft.poolparty.biz/devrel/90370425-aca4-4a39-9533-d52e5e002a5d
toc_rel: ../costs/toc.json
twitter:card: summary_large_image
twitter:site: @MicrosoftLearn
uhfHeaderId: azure
updated_at: 2026-03-25T22:12:00Z
viewport: width=device-width, initial-scale=1.0
word_count: 339

[canonical-links]
https://learn.microsoft.com/en-us/azure/cost-management-billing/automate/cost-management-api-permissions

[document-links]
AI Disclaimer: https://learn.microsoft.com/en-us/principles-for-ai-generated-content
Assign roles to Azure Enterprise Agreement service principal names: ../manage/assign-roles-azure-service-principals
Azure PowerShell: ../../active-directory/develop/howto-authenticate-service-principal-powershell#assign-the-application-to-a-role
Azure Resource Manager REST APIs: /en-us/rest/api/azure
Billing Role Assignments API: /en-us/rest/api/billing/2020-05-01/billing-role-assignments
Blog: https://techcommunity.microsoft.com/t5/microsoft-learn-blog/bg-p/MicrosoftLearnBlog
Consumer Health Privacy: https://go.microsoft.com/fwlink/?linkid=2259814
Contribute: https://learn.microsoft.com/en-us/contribute
Cost Management automation overview: automation-overview
Download Microsoft Edge: https://go.microsoft.com/fwlink/p/?LinkID=2092881
Edit: https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/cost-management-billing/automate/cost-management-api-permissions.md
Manage billing roles in the Azure portal: ../manage/understand-mca-roles#manage-billing-roles-in-the-azure-portal
Microsoft Entra authentication: /en-us/rest/api/azure/#create-the-request
More info about Internet Explorer and Microsoft Edge: https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge
Previous Versions: https://learn.microsoft.com/en-us/previous-versions/
Privacy: https://go.microsoft.com/fwlink/?LinkId=521839
Terms of Use: https://learn.microsoft.com/en-us/legal/termsofuse
Trademarks: https://www.microsoft.com/legal/intellectualproperty/Trademarks/
Understand and work with scopes: ../costs/understand-work-scopes
Your Privacy Choices: https://aka.ms/yourcaliforniaprivacychoices
in the Azure portal: ../../active-directory/develop/howto-create-service-principal-portal#assign-a-role-to-the-application
register your client app with Microsoft Entra ID: /en-us/rest/api/azure/#register-your-client-application-with-azure-ad

[content]
Assign permissions to Cost Management APIs - Microsoft Cost Management | Microsoft Learn
Skip to main content
Skip to Ask Learn chat experience
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Download Microsoft Edge
More info about Internet Explorer and Microsoft Edge
Table of contents
Exit editor mode
Ask Learn
Ask Learn
Reading mode
Table of contents
Read in English
Add
Add to Plans
Edit
Copy Markdown
Print
Note
Access to this page requires authorization. You can try
signing in
or
changing directories
.
Access to this page requires authorization. You can try
changing directories
.
Assign permissions to Cost Management APIs
Feedback
Summarize this article for me
In this article
Get familiar with the
Azure Resource Manager REST APIs
.
Determine which Cost Management APIs you want to use. For more information about available APIs, see
Cost Management automation overview
.
Configure service authorization and authentication for the Azure Resource Manager APIs.
If you're not already using Azure Resource Manager APIs,
register your client app with Microsoft Entra ID
. Registration creates a service principal for you to use to call the APIs.
Assign the service principal access to the scopes needed, as outlined below.
Update any programming code to use
Microsoft Entra authentication
with your service principal.
Assign service principal access to Azure Resource Manager APIs
After you create a service principal to programmatically call the Azure Resource Manager APIs, you need to assign it the proper permissions to authorize against and execute requests in Azure Resource Manager. There are two permission frameworks for different scenarios.
Azure billing hierarchy access
If you have an Azure Enterprise Agreement or a Microsoft Customer Agreement, you can configure service principal access to Cost Management data in your billing account. To learn more about the billing hierarchies available and what permissions are needed to call each API in Azure Cost Management, see
Understand and work with scopes
.
Enterprise Agreements - To assign service principal permissions to your enterprise billing account, departments, or enrollment account scopes, see
Assign roles to Azure Enterprise Agreement service principal names
.
Microsoft Customer Agreements - To assign service principal permissions to your Microsoft Customer Agreement billing account, billing profile, invoice section or customer scopes, see
Manage billing roles in the Azure portal
. Configure the permission to your service principal in the portal as you would a normal user. If you want to automate permissions assignment, see the
Billing Role Assignments API
.
Azure role-based access control
Service principal support extends to Azure-specific scopes, like management groups, subscriptions, and resource groups. You can assign service principal permissions to thee scopes directly
in the Azure portal
or by using
Azure PowerShell
.
Related content
Learn more about Cost Management automation at
Cost Management automation overview
.
Feedback
Was this page helpful?
Yes
No
No
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Ask Learn
Ask Learn
Suggest a fix?
Additional resources
Last updated on
2025-09-26
In this article
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Ask Learn
Ask Learn
Suggest a fix?
en-us
Your Privacy Choices
Theme
Light
Dark
High contrast
AI Disclaimer
Previous Versions
Blog
Contribute
Privacy
Consumer Health Privacy
Terms of Use
Trademarks
© Microsoft 2026
