An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
This needs to be split because the four permissions don't all live at the same Azure RBAC scope.
Reader + Cost Management Reader at tenant-root management group
These can be deployed through Bicep using Microsoft. Authorization/role Assignments at management-group scope. Bicep supports RBAC role assignments at different scopes.
Reservations Reader / Savings Plan Reader
Don't treat Home → Reservations/Savings Plans as normal management-group resources. Their scopes/resource providers differ from conventional subscription/management-group RBAC, so trying to assign them from the same root-MG Bicep deployment can fail. Reservations, for example, use the Microsoft. Capacity/reservation Orders resource hierarchy.
Recommended: handle these role assignments separately using the appropriate REST/CLI/API scope, or a Bicep deployment script if you need one automated deployment workflow.
Cost export + previous 3 months
Bicep can create the storage account and Microsoft.CostManagement/exports resource, including a custom time Period.
However, think of Bicep as creating/configuring the export. For historical backfill, use the Cost Management export run/rerun operation after deployment. Microsoft specifically supports selectively rerunning exports for historical periods.