All documentation
Microsoft Azure

Cloud integration

Microsoft Azure

Connect Azure by granting admin consent to OptCloud's multi-tenant application and assigning it read-only roles. No app registration or client secret ever needs to leave your tenant.

Connection

Multi-tenant app consent + RBAC role assignment (no secrets)

Access model

Read-only

Time to value

Typically under an hour after the first export or API sync

How OptCloud connects with Azure

OptCloud maintains a single multi-tenant application registered in our own Microsoft Entra ID tenant. A Global Administrator in your tenant grants admin consent to that application, which creates an enterprise application (service principal) inside your own tenant — you then assign it Cost Management Reader (and optionally Reader) on the subscriptions or management group you want OptCloud to see. Because you never create an app registration or generate a client secret on our behalf, there is no long-lived credential to hand over, rotate, or leak. Resource metadata is used for rightsizing, idle disk detection, and Reservation / Hybrid Benefit coverage — not for reading application secrets or disk contents.

Required permissions (read-only)

  • Admin consent for OptCloud's multi-tenant application (one-time, by a Global Administrator)
  • Cost Management Reader on subscriptions or management group, assigned to OptCloud's enterprise application
  • Reader (optional) for richer resource inventory and VM metrics
  • Storage Blob Data Reader on the export container (if using Cost Management exports)
  • Reservations Reader (optional) for RI coverage analysis

No Contributor or Owner roles are required, and OptCloud never asks for or stores an app client secret from your tenant. Access is entirely via RBAC role assignments on our published application identity.

Cost Management API vs. exports — what you see, and when

Once Cost Management Reader is assigned, OptCloud pulls historical totals via the Cost Management API within the hour. API data supports subscription- and service-level totals immediately, but resource-level filtering (by resource group, meter, or tag) is most reliable once a daily Cost Management export is flowing into your storage account — exports usually start landing within 24 hours of being configured. Until the first export lands, Rightsizing and Idle Resources will show partial data.

Connecting multiple subscriptions (management groups)

If your subscriptions sit under a management group, assign Cost Management Reader (and the export configuration) at the management group scope instead of per subscription. This lets OptCloud automatically pick up every subscription under that group, including ones added later, without a separate consent or role assignment each time. Assigning access subscription-by-subscription still works, but you'll need to repeat the role assignment whenever a new subscription is created.

Create a connection

  1. 1

    Start an Azure connection in OptCloud

    Go to Cloud Accounts → Add account → Azure. OptCloud generates an admin consent link for our multi-tenant application — no app registration needed on your side.

  2. 2

    Grant admin consent

    A Global Administrator (or Privileged Role Administrator) in your tenant opens the consent link and approves the OptCloud application. This creates an enterprise application for OptCloud inside your own tenant; nothing is shared back to us except your tenant ID.

  3. 3

    Assign Cost Management Reader

    At the management group or subscription scope, assign Cost Management Reader to OptCloud's enterprise application. Add Reader if you want inventory-based recommendations.

  4. 4

    (Recommended) Enable Cost Management exports

    Configure a daily FOCUS or amortized cost export to a storage account. Grant OptCloud's enterprise application Storage Blob Data Reader on that container for stable, detailed ingestion.

  5. 5

    Confirm subscriptions in OptCloud

    Enter your tenant ID and the subscription IDs (or management group) you assigned access to. Save and run the first sync — no secret is entered anywhere in this flow.

  6. 6

    Validate spend by subscription

    Confirm Cloud Distribution and Cost Explorer show Azure spend. Check Idle Resources for unattached managed disks and rightsizing for underused VMs.

Backfilling historical cost data

Cost Management exports only capture data going forward from when they're created. For historical months, OptCloud pulls what's available from the Cost Management API (typically up to the last 12 months of subscription/service-level totals), but resource- and tag-level detail for those historical months may be limited. There's no manual backfill request needed — historical API data becomes available automatically once access is granted.

Data collected

  • Cost by subscription, resource group, service, meter, and tags
  • VM, disk, and networking inventory metadata
  • Reservation and savings-plan coverage where permissions allow

What you get in OptCloud

  • Multi-subscription rollups without spreadsheet merges
  • VM rightsizing and auto-shutdown candidates for non-prod
  • Reservation / Hybrid Benefit coverage gaps
  • Tag hygiene across resource groups

Filterable dimensions

Once connected, you can filter and group cost data in Cost Explorer and Reports by:

  • Subscription — subscription name and ID
  • Category — compute, storage, network, database, other (OptCloud's normalized category)
  • Service / meter — e.g. Virtual Machines, Managed Disks, Azure SQL
  • Resource group — logical grouping within a subscription
  • Region — e.g. East US, West Europe
  • Resource — specific resource ID
  • Tag / Not tagged — any Azure resource or resource group tag
  • Charge type — usage, purchase, refund, Reservation/Hybrid Benefit amortization

Updating or rotating your connection

OptCloud's application identity never holds a secret you issued, so there's nothing for you to rotate on a schedule. If OptCloud expands its required role set, we'll prompt you (and your Global Administrator) to re-run admin consent and assign any new roles — existing data collection continues uninterrupted while that happens. If you ever want to revoke access, remove the OptCloud enterprise application's role assignments or delete it from Enterprise Applications in Entra ID.

Troubleshooting

Sync fails with authorization errors

Confirm a Global Administrator completed admin consent and that Cost Management Reader is assigned to OptCloud's enterprise application on every subscription you listed. If your tenant enforces periodic app consent review, re-approval may be required.

EA / MCA / CSP billing accounts

Enterprise Agreement, Microsoft Customer Agreement, and CSP setups differ in export paths. Use the billing account type that matches your contract; OptCloud supports standard Cost Management scopes first — contact us for CSP partner tenancy patterns.

Related integrations

Ready to connect Azure?

Open the dashboard to add the account, or book a walkthrough with our team.