Skip to main content

Connect Azure

AvailableReviewed 24 August 2026

Connect Azure by pointing FinomateAI at a Cost Management export in a storage account and a Microsoft Entra service principal that can read that export. The principal must not be a subscription Owner.

This is the primary onboarding path. AWS and Google Cloud can be added later.

Connect Azure form with Entra tenant ID, application ID, subscriptions, storage account and container
Keep the service principal to Cost Management Reader and Storage Blob Data Reader.

Before you begin​

  • Access to the Microsoft Entra tenant that owns the subscriptions
  • Permission to create an app registration and assign RBAC
  • A Cost Management export writing to a dedicated storage container
  • Agreement on billing account type: Microsoft Customer Agreement (MCA) or Enterprise Agreement (EA) — both work if the export includes the subscriptions you care about

What FinomateAI asks for​

FieldPurpose
Microsoft Entra tenant IDDirectory (tenant) ID
Application (client) IDApp registration
Client secretService principal secret, stored only in onboarding
Subscription IDsComma-separated subscriptions in scope
Storage accountAccount that receives the export
Container nameContainer for the export
Blob prefixOptional path

Step 1: Confirm the Cost Management export​

In Azure Portal:

  1. Open Cost Management + Billing → Cost Management → Exports.
  2. Scope = the billing account or the subscriptions you want in FinomateAI.
  3. Create an export:
    • Metric: Actual cost (add a second amortised export later if you need both)
    • Format: CSV or Parquet
    • Dataset: FOCUS if your tenant asked for it, otherwise Cost Management actual-cost
    • Frequency: daily
    • Destination: a dedicated storage account and container (focus-exports in the sample)
  4. Run Export now once and wait until blobs exist.
  5. Record storage account, container and prefix.

An empty container looks like a permissions failure. Do not complete onboarding until the first file is there.

Recommended destination:

SettingUse
Storage accountDedicated, not an application account
RedundancyLRS is enough
FirewallAllow FinomateAI if the account is locked to selected networks
LifecycleKeep at least 13 months if you want year-on-year Explorer

Step 2: Create the service principal​

  1. Open Microsoft Entra ID → App registrations → New registration.
  2. Name it FinomateReadOnly (or your standard).
  3. Create a client secret. Store it for the onboarding form only — do not paste it into tickets, chat or git.
  4. Copy Application (client) ID and Directory (tenant) ID.
  5. Grant RBAC:
    • Storage Blob Data Reader on the export container (or account)
    • Cost Management Reader on each in-scope subscription (needed for reservation metadata and some API checks)
    • Reader on the subscriptions only if Cost Management Reader is not enough in your tenant
  6. Do not grant Contributor, User Access Administrator, Owner, or any role that can create or resize VMs.

Step 3: Complete onboarding​

  1. In FinomateAI, open Complete onboarding and select Azure.
  2. Enter tenant ID, application ID, subscription IDs, storage account, container, optional prefix and client secret.
  3. Select Complete onboarding.
  4. Wait until Connected accounts shows Healthy.

Step 4: Validate​

  1. Open the Azure Dashboard and select Azure.
  2. Confirm monthly spend is non-zero.
  3. Open Azure Cost Explorer on a completed month.
  4. In Azure Portal, open Cost analysis for the same subscriptions, actual cost, same currency.
  5. Variance under ~2% after credits and Azure Hybrid Benefit is expected.

Troubleshooting​

SymptomCheck
Authentication failsTenant ID, application ID, secret value, secret expiry
Container emptyExport schedule, first run, prefix
403 on blobsBlob Data Reader on the right container; storage firewall
Subscriptions missingForm list vs export scope
Totals differPeriod, MCA credits, Hybrid Benefit, actual vs amortised
Reservations missingCost Management Reader on the subscription that owns the reservation order

If AWS or GCP is healthy and Azure is not, the fault is this connector.

Expected result​

FinomateAI can read the approved Azure export, expected subscriptions appear, and a completed period reconciles to Cost Analysis.

Next steps​