Connection guide · Microsoft Azure

Connect Microsoft Azure

FinOpsAI reads a Cost Management FOCUS export from a storage account in your subscription. Your Azure administrator does two things — one admin consent and one Deploy to Azure click — and FinOpsAI creates the export for you inside a resource group called rg-finopsai. Access is keyless: no client secrets, certificates, SAS tokens or storage keys exist anywhere in the flow. Forward this page to your Azure administrator as-is.

Time: about 10 minutes
Who: Entra Global/Application Administrator (consent) + Owner or User Access Administrator of the subscription (template)
First data: within minutes — FinOpsAI runs the export and the first sync itself
Updated: September 18, 2026
On this page
How access worksBefore you startSteps 1–6What FinOpsAI createsWhat FinOpsAI verifiesAfter connectingRevoking accessTroubleshooting

00How access works

Admin consent creates a service principal for FinOpsAI's application in your Entra tenant — visible under Enterprise applications, removable at any time. Every permission it ever gets is a role assignment you make, generated as a one-page ARM template for your tenant and deployed with one click. FinOpsAI's ingestion identity then obtains one-hour Azure tokens through Entra workload identity federation (Microsoft trusts a Google-signed token for FinOpsAI's own application), so there is no secret to issue, rotate or leak.

FinOpsAI applicationfinopsai-ingestor-fed — application (client) ID 4a6091c5-1e2d-4a98-b223-0f2600b70975, multi-tenant. After consent it appears under Entra ID → Enterprise applications in your tenant.
Two ways to connectSet it up for me (recommended) — FinOpsAI creates the storage account, container, FOCUS export and its own read role inside rg-finopsai, then runs the export. I already have a FOCUS export — FinOpsAI lists your exports and storage accounts; you pick one and grant one read role on its storage account.
Roles — Set it up for meOn the subscription: Reader, Cost Management Reader, Cost Management Contributor. Inside rg-finopsai only: Contributor and Role Based Access Control Administrator limited by an ABAC condition to assigning exactly one role, Storage Blob Data Reader. Nothing is created outside that resource group.
Roles — existing exportOn the subscription: Reader, Cost Management Reader (both read-only, so the wizard can list exports and storage accounts). On the export's storage account: Storage Blob Data Reader.
Export formatCost Management export Cost and usage details (FOCUS) 1.0r2, daily, month-to-date, CSV
What FinOpsAI never asks forStorage account keys, SAS tokens, client secrets, certificates, Owner, or any role outside the list above
Data residencySet it up for me creates the storage account in Central India. FinOpsAI reports the storage region on the account page and flags accounts outside India.

01Before you start

Two people may be involved. Admin consent needs a Global Administrator, Application Administrator or Privileged Role Administrator of your Entra tenant. The template needs an Owner or User Access Administrator of the subscription. Often that is one person; if not, each wizard step has a Copy this step for my cloud admin button that produces a self-contained message.

02Steps

  1. FinOpsAI → Connections → Add a cloud → Microsoft Azure → step 1 "Your tenant" Type your sign-in domain (contoso.com) or the tenant ID. FinOpsAI resolves it through Microsoft's public discovery document and shows the tenant it found. Click Next.
  2. Step 2 "Admin consent" → Grant admin consent You are sent to Microsoft. Sign in as the Entra administrator, tick Consent on behalf of your organization and click Accept. You return to FinOpsAI, which now shows done · tenant …. The tenant is proven from the consent response itself — it can never be mistyped.

    Not an administrator yourself? Click Copy this step for my cloud admin and send it; the wizard resumes where you left it once consent is recorded.

  3. Step 3 "Access" → Deploy to Azure Choose Set it up for me (recommended) or I already have a FOCUS export. Click Deploy to Azure: the Azure portal opens on Custom deployment with the template already loaded — nothing to download, upload or edit. Pick the subscription, leave Region as offered, Review + create → Create. About a minute. Back in FinOpsAI, Check access confirms the roles within a minute (it also polls by itself).

    The template is generated for your tenant after consent and lists the roles it grants in plain text — open it in the portal editor if you want to read it. Roles you already hold are left out, so redeploying is harmless. Prefer a file? Download the file instead and use Deploy a custom template → Build your own template → Load file.

  4. Step 4 "Export" Set it up for me: click Set up now. Seven checks run in about a minute — resource group present, storage account, soft delete, container focus, export finopsai-focus, Storage Blob Data Reader, first export run requested. Re-running after a failure resumes; nothing is duplicated. Existing export: pick your export from the list (each shows its scope, format and whether FinOpsAI can read it) or click I'll type the values myself.
  5. Step 5 "Storage role" Set it up for me: already granted in step 4 — the wizard skips ahead. Existing export: the one-click link opens the storage account's IAM page; assign Storage Blob Data Reader to finopsai-ingestor-fed. Role assignments take 1–5 minutes to propagate.
  6. Step 6 "Test and connect" → Run the test → Connect FinOpsAI runs the checks below. No export delivered yet is acceptable for a brand-new export — Connect still works. Connect triggers the first sync immediately; the account page shows Healthy once the first file is read, usually within 5–10 minutes for a new export, and keeps re-checking on its own until then.

03What FinOpsAI creates (Set it up for me)

ResourceNameSettings
Resource grouprg-finopsaiCentral India. Created by the template; everything below lives inside it.
Storage accountfinopsai + 14 characters derived from your tenant and subscriptionStandard LRS, hot tier, TLS 1.2 minimum, public blob access off, HTTPS only, blob and container soft delete 14 days
ContainerfocusPrivate
Cost Management exportfinopsai-focusFOCUS 1.0r2, daily, month-to-date, CSV (gzip), partitioned, overwrite previous report, directory finopsai, subscription scope
Role assignmentStorage Blob Data Reader → finopsai-ingestor-fedOn that one storage account only

Every call is idempotent, so a retry resumes rather than creates twins. The storage account carries the tags managedBy=FinOpsAI and your workspace name.

04What FinOpsAI verifies, and what a failure means

CheckPassFail — likely cause and fix
Admin consent recordedConsent exists for this tenant.Step 2 was not completed, or was completed in a different tenant. Repeat step 2 as an administrator of the tenant you typed in step 1.
Federated Azure token mintedEntra exchanged FinOpsAI's Google token for an Azure token in your tenant.The enterprise application was deleted after consent. Repeat step 2.
Storage home tenant matches the consent tenantThe storage account belongs to the tenant that consented.The subscription that owns the storage account is homed in another tenant. Consent in that tenant, or pick a storage account in this one.
Storage container listedBlob listing succeeded under the directory.Storage Blob Data Reader not yet assigned, assigned to the wrong principal, or still propagating (wait five minutes and run the test again).
FOCUS export manifestA FOCUS file set was read for the latest period.No export delivered yet is normal for a new export — Connect anyway; the first run lands within minutes. If it stays pending for an hour, open the export in the portal and check its Run history.
ResidencyRegion shown, flagged resident / outside India.Informational. Set it up for me always uses Central India.

05After connecting

06Revoking access

Set it up for me: delete the resource group rg-finopsai (removes the storage account, the export files and the Storage Blob Data Reader assignment) and remove the three subscription-level role assignments for finopsai-ingestor-fed under Subscription → Access control (IAM). Existing export: remove the Storage Blob Data Reader assignment on the storage account and the two Reader roles on the subscription. To remove FinOpsAI from your tenant entirely, delete finopsai-ingestor-fed under Entra ID → Enterprise applications; every token stops minting immediately. Disconnecting in FinOpsAI removes the workspace's copy of the data.

07Troubleshooting

The consent page says "Need admin approval"

You are signed in as a non-administrator. Sign out and repeat step 2 as a Global, Application or Privileged Role Administrator, or use Copy this step for my cloud admin.

The template deployment says "The role assignment already exists"

The template was generated before FinOpsAI had checked which roles you already hold. Back in step 3 click Check access, then Deploy to Azure again — held roles are left out of the regenerated template.

Set up now fails at "Creating the FOCUS export"

Cost Management Contributor on the subscription is missing — usually the template was deployed on a different subscription. Redeploy it on the subscription shown in step 4, then click Retry.

We have an Enterprise Agreement / MCA with many subscriptions

Choose I already have a FOCUS export. FinOpsAI lists exports at subscription, billing-account and billing-profile scope, and the wizard shows the extra Billing account reader grant needed to see billing-scope exports. One billing-account export covers every subscription under it; FinOpsAI reports per subscription and per resource group from the FOCUS rows.

Our policy forbids third-party role assignments at subscription scope

Use I already have a FOCUS export and assign Storage Blob Data Reader at the container scope (Container → Access control (IAM)). FinOpsAI only ever reads under the export directory. The two subscription-level Reader roles can be skipped by typing the values yourself in step 4.

The storage account is behind a firewall / private endpoint

FinOpsAI reads over the storage account's public endpoint from Google Cloud asia-south1 and does not use fixed source IP addresses, so an IP allow-list cannot be configured for it. Use a dedicated storage account for the export (Set it up for me does exactly that).

Who to contact

finops@samsofttechnologies.com — include the check that failed and its detail text.