← Integrations

Azure integration

Private beta

Azure cost management, from a read-only service principal

The Azure integration is in private beta — enabled per organization on request. Ask us to turn it on, and Azure spend lands in the same ledger, dashboards, and allocation as your other clouds.

CloudQuell reads Azure through a read-only Microsoft Entra ID service principal, on whichever path fits your account: an invoice-accurate Cost Management export in FOCUS format, or a zero-setup API pull. Nothing is written back to your tenant.

What CloudQuell ingests

Azure's own cost record, on whichever path fits your account — an invoice-accurate FOCUS export, or a zero-setup API pull.

Cost Management export (FOCUS)
The recommended path: a daily Cost and usage (FOCUS) export in Parquet, delivered to a storage account you own. Invoice-accurate billed and amortized cost at any scale.
Quick connect (API)
No export setup — list the subscriptions to read and CloudQuell pulls from Azure's cost API, backfilling up to 13 months. On this path billed cost equals amortized; add an export later for the invoice-accurate split.
Subscriptions & resource groups
Each subscription lands as its own sub-account; resource groups and invoice sections arrive as tags, so allocation works the same as it does for AWS accounts.
Commitments
Reservations and savings plans, via optional read roles, so Azure commitment coverage shows up on the same Commitments view.

What the data looks like normalized

An Azure line item lands on the same schema as an AWS one — subscription as sub-account, resource group as a tag.

Illustrative — an Azure cost record in CloudQuell's unified model. On the export path, both billed and amortized cost arrive.
Normalized fieldAzure sourceExample
Dateexport / API day2026-08-04
ProviderconstantAzure
Servicemeter categoryVirtual Machines
Scopesubscriptionprod-sub (…9f2c)
Cost (USD)billed + amortized$612.30
Usagequantity + unit720 hrs
Attributionresource-group tagteam=platform

How it connects

A read-only Entra ID service principal. Nothing is written back to your tenant.

Credential
A Microsoft Entra ID app registration (service principal) with read-only cost roles — Cost Management Reader on the subscription, or the billing-account reader role for MCA and EA accounts. The client secret is stored in AWS Secrets Manager, and CloudQuell warns you before it expires.
Access scope
Read-only. On the export path, Storage Blob Data Reader on the export container and nothing more. Nothing is written back, and live checks run against Azure before anything is saved.
Setup
A five-step wizard: create the service principal, grant cost-read access at your billing scope, choose the export or quick-connect path, optionally add commitment roles, then connect. Checks must pass before it saves.
Time to first data
Azure reports with an 8–24 hour lag. On the export path, data appears after the first export run; quick connect backfills up to 13 months on connect. Daily sync at 07:30 UTC after that.
Azure setup guide

What it unlocks (in beta)

During the beta, Azure spend flows into the same views as the rest of your bill — with one exception noted below.

  • One ledger

    Azure spend by subscription, service, and resource-group tag in the same dashboard, reports, and cost centers as AWS, Snowflake, and your AI bill.

  • Allocation

    Subscriptions as sub-accounts and resource groups as tags feed the same allocation rules and cost-center hierarchy as everything else.

    How allocation works
  • Budgets & anomalies

    Budget thresholds, trend and anomaly rules all cover Azure spend, routed to Slack, Teams, or email like any other source.

  • Commitments

    Reservation and savings-plan coverage counts toward Effective Coverage %. Savings recommendations stay AWS-only during the beta.

    Effective Coverage %

Common questions

Is the Azure integration available now?
It is in limited availability (private beta), enabled per organization on request. When it is on, reporting, budgets, allocation, alert rules, and anomaly detection all cover Azure spend; savings recommendations remain AWS-only during the beta. Email us to have it turned on for your org.
How does CloudQuell read Azure cost?
Through a read-only Microsoft Entra ID service principal with cost-reader roles. Two paths: a Cost Management export in FOCUS format delivered to a storage account you own (invoice-accurate billed and amortized cost), or a quick API connect with no export setup that backfills up to 13 months. Nothing is written back to your tenant.
Does the Azure integration use the FOCUS format?
On the recommended path, yes — CloudQuell reads the Cost and usage (FOCUS) export (version 1.0r2). It then normalizes that into the same internal cost model as every other provider, so Azure sits on the same ledger, allocation, and alerts as your AWS and AI spend.
How are Azure subscriptions represented?
Each subscription appears as its own sub-account — the Azure analog of an AWS linked account — so you can filter, report, and allocate per subscription. Resource groups and invoice sections arrive as tags, filterable anywhere tags are.
Request Azure access

Azure is in private beta, enabled per organization on request. Free under $10K/month of tracked spend once it is on.