FinOpsAI reads a Cost Management FOCUS export from a storage account in your subscription. Your Azure administrator does two things — one admin consent and one Deploy to Azure click — and FinOpsAI creates the export for you inside a resource group called rg-finopsai. Access is keyless: no client secrets, certificates, SAS tokens or storage keys exist anywhere in the flow. Forward this page to your Azure administrator as-is.
Admin consent creates a service principal for FinOpsAI's application in your Entra tenant — visible under Enterprise applications, removable at any time. Every permission it ever gets is a role assignment you make, generated as a one-page ARM template for your tenant and deployed with one click. FinOpsAI's ingestion identity then obtains one-hour Azure tokens through Entra workload identity federation (Microsoft trusts a Google-signed token for FinOpsAI's own application), so there is no secret to issue, rotate or leak.
| FinOpsAI application | finopsai-ingestor-fed — application (client) ID 4a6091c5-1e2d-4a98-b223-0f2600b70975, multi-tenant. After consent it appears under Entra ID → Enterprise applications in your tenant. |
|---|---|
| Two ways to connect | Set it up for me (recommended) — FinOpsAI creates the storage account, container, FOCUS export and its own read role inside rg-finopsai, then runs the export. I already have a FOCUS export — FinOpsAI lists your exports and storage accounts; you pick one and grant one read role on its storage account. |
| Roles — Set it up for me | On the subscription: Reader, Cost Management Reader, Cost Management Contributor. Inside rg-finopsai only: Contributor and Role Based Access Control Administrator limited by an ABAC condition to assigning exactly one role, Storage Blob Data Reader. Nothing is created outside that resource group. |
| Roles — existing export | On the subscription: Reader, Cost Management Reader (both read-only, so the wizard can list exports and storage accounts). On the export's storage account: Storage Blob Data Reader. |
| Export format | Cost Management export Cost and usage details (FOCUS) 1.0r2, daily, month-to-date, CSV |
| What FinOpsAI never asks for | Storage account keys, SAS tokens, client secrets, certificates, Owner, or any role outside the list above |
| Data residency | Set it up for me creates the storage account in Central India. FinOpsAI reports the storage region on the account page and flags accounts outside India. |
Two people may be involved. Admin consent needs a Global Administrator, Application Administrator or Privileged Role Administrator of your Entra tenant. The template needs an Owner or User Access Administrator of the subscription. Often that is one person; if not, each wizard step has a Copy this step for my cloud admin button that produces a self-contained message.
contoso.com) or your tenant ID (Entra admin center → Overview). That is the only thing typed in the whole flow.contoso.com) or the tenant ID. FinOpsAI resolves it through Microsoft's public discovery document and shows the tenant it found. Click Next.Not an administrator yourself? Click Copy this step for my cloud admin and send it; the wizard resumes where you left it once consent is recorded.
The template is generated for your tenant after consent and lists the roles it grants in plain text — open it in the portal editor if you want to read it. Roles you already hold are left out, so redeploying is harmless. Prefer a file? Download the file instead and use Deploy a custom template → Build your own template → Load file.
focus, export finopsai-focus, Storage Blob Data Reader, first export run requested. Re-running after a failure resumes; nothing is duplicated.
Existing export: pick your export from the list (each shows its scope, format and whether FinOpsAI can read it) or click I'll type the values myself.Storage Blob Data Reader to finopsai-ingestor-fed. Role assignments take 1–5 minutes to propagate.| Resource | Name | Settings |
|---|---|---|
| Resource group | rg-finopsai | Central India. Created by the template; everything below lives inside it. |
| Storage account | finopsai + 14 characters derived from your tenant and subscription | Standard LRS, hot tier, TLS 1.2 minimum, public blob access off, HTTPS only, blob and container soft delete 14 days |
| Container | focus | Private |
| Cost Management export | finopsai-focus | FOCUS 1.0r2, daily, month-to-date, CSV (gzip), partitioned, overwrite previous report, directory finopsai, subscription scope |
| Role assignment | Storage Blob Data Reader → finopsai-ingestor-fed | On that one storage account only |
Every call is idempotent, so a retry resumes rather than creates twins. The storage account carries the tags managedBy=FinOpsAI and your workspace name.
| Check | Pass | Fail — likely cause and fix |
|---|---|---|
| Admin consent recorded | Consent exists for this tenant. | Step 2 was not completed, or was completed in a different tenant. Repeat step 2 as an administrator of the tenant you typed in step 1. |
| Federated Azure token minted | Entra exchanged FinOpsAI's Google token for an Azure token in your tenant. | The enterprise application was deleted after consent. Repeat step 2. |
| Storage home tenant matches the consent tenant | The storage account belongs to the tenant that consented. | The subscription that owns the storage account is homed in another tenant. Consent in that tenant, or pick a storage account in this one. |
| Storage container listed | Blob listing succeeded under the directory. | Storage Blob Data Reader not yet assigned, assigned to the wrong principal, or still propagating (wait five minutes and run the test again). |
| FOCUS export manifest | A FOCUS file set was read for the latest period. | No export delivered yet is normal for a new export — Connect anyway; the first run lands within minutes. If it stays pending for an hour, open the export in the portal and check its Run history. |
| Residency | Region shown, flagged resident / outside India. | Informational. Set it up for me always uses Central India. |
Set it up for me: delete the resource group rg-finopsai (removes the storage account, the export files and the Storage Blob Data Reader assignment) and remove the three subscription-level role assignments for finopsai-ingestor-fed under Subscription → Access control (IAM). Existing export: remove the Storage Blob Data Reader assignment on the storage account and the two Reader roles on the subscription. To remove FinOpsAI from your tenant entirely, delete finopsai-ingestor-fed under Entra ID → Enterprise applications; every token stops minting immediately. Disconnecting in FinOpsAI removes the workspace's copy of the data.
You are signed in as a non-administrator. Sign out and repeat step 2 as a Global, Application or Privileged Role Administrator, or use Copy this step for my cloud admin.
The template was generated before FinOpsAI had checked which roles you already hold. Back in step 3 click Check access, then Deploy to Azure again — held roles are left out of the regenerated template.
Cost Management Contributor on the subscription is missing — usually the template was deployed on a different subscription. Redeploy it on the subscription shown in step 4, then click Retry.
Choose I already have a FOCUS export. FinOpsAI lists exports at subscription, billing-account and billing-profile scope, and the wizard shows the extra Billing account reader grant needed to see billing-scope exports. One billing-account export covers every subscription under it; FinOpsAI reports per subscription and per resource group from the FOCUS rows.
Use I already have a FOCUS export and assign Storage Blob Data Reader at the container scope (Container → Access control (IAM)). FinOpsAI only ever reads under the export directory. The two subscription-level Reader roles can be skipped by typing the values yourself in step 4.
FinOpsAI reads over the storage account's public endpoint from Google Cloud asia-south1 and does not use fixed source IP addresses, so an IP allow-list cannot be configured for it. Use a dedicated storage account for the export (Set it up for me does exactly that).
finops@samsofttechnologies.com — include the check that failed and its detail text.