Azure provides lot of services for governance of its usage including Azure monitor, Azure Cost Management, and so on. For our subscription, we have observed very high usage in previous month and planned to implement some control over the Azure resource usage to reduce the cost.
One of the steps taken is to restrict the provisioning of Azure resources. Earlier, we used to provision new resource groups and provide owner and contributor access to the team to provision required resources. We have started the implementation by defining a custom role based on existing role – Reader.
Please refer my LinkedIn article for more details about our custom role @ https://www.linkedin.com/pulse/azure-governance-custom-role-ambily-kk/