Azure integration
Private betaAzure cost management, from a read-only service principal
The Azure integration is in private beta — enabled per organization on request. Ask us to turn it on, and Azure spend lands in the same ledger, dashboards, and allocation as your other clouds.
CloudQuell reads Azure through a read-only Microsoft Entra ID service principal, on whichever path fits your account: an invoice-accurate Cost Management export in FOCUS format, or a zero-setup API pull. Nothing is written back to your tenant.
What CloudQuell ingests
Azure's own cost record, on whichever path fits your account — an invoice-accurate FOCUS export, or a zero-setup API pull.
- Cost Management export (FOCUS)
- The recommended path: a daily Cost and usage (FOCUS) export in Parquet, delivered to a storage account you own. Invoice-accurate billed and amortized cost at any scale.
- Quick connect (API)
- No export setup — list the subscriptions to read and CloudQuell pulls from Azure's cost API, backfilling up to 13 months. On this path billed cost equals amortized; add an export later for the invoice-accurate split.
- Subscriptions & resource groups
- Each subscription lands as its own sub-account; resource groups and invoice sections arrive as tags, so allocation works the same as it does for AWS accounts.
- Commitments
- Reservations and savings plans, via optional read roles, so Azure commitment coverage shows up on the same Commitments view.
What the data looks like normalized
An Azure line item lands on the same schema as an AWS one — subscription as sub-account, resource group as a tag.
| Normalized field | Azure source | Example |
|---|---|---|
| Date | export / API day | 2026-08-04 |
| Provider | constant | Azure |
| Service | meter category | Virtual Machines |
| Scope | subscription | prod-sub (…9f2c) |
| Cost (USD) | billed + amortized | $612.30 |
| Usage | quantity + unit | 720 hrs |
| Attribution | resource-group tag | team=platform |
How it connects
A read-only Entra ID service principal. Nothing is written back to your tenant.
- Credential
- A Microsoft Entra ID app registration (service principal) with read-only cost roles — Cost Management Reader on the subscription, or the billing-account reader role for MCA and EA accounts. The client secret is stored in AWS Secrets Manager, and CloudQuell warns you before it expires.
- Access scope
- Read-only. On the export path, Storage Blob Data Reader on the export container and nothing more. Nothing is written back, and live checks run against Azure before anything is saved.
- Setup
- A five-step wizard: create the service principal, grant cost-read access at your billing scope, choose the export or quick-connect path, optionally add commitment roles, then connect. Checks must pass before it saves.
- Time to first data
- Azure reports with an 8–24 hour lag. On the export path, data appears after the first export run; quick connect backfills up to 13 months on connect. Daily sync at 07:30 UTC after that.
What it unlocks (in beta)
During the beta, Azure spend flows into the same views as the rest of your bill — with one exception noted below.
One ledger
Azure spend by subscription, service, and resource-group tag in the same dashboard, reports, and cost centers as AWS, Snowflake, and your AI bill.
Allocation
Subscriptions as sub-accounts and resource groups as tags feed the same allocation rules and cost-center hierarchy as everything else.
How allocation works →Budgets & anomalies
Budget thresholds, trend and anomaly rules all cover Azure spend, routed to Slack, Teams, or email like any other source.
Commitments
Reservation and savings-plan coverage counts toward Effective Coverage %. Savings recommendations stay AWS-only during the beta.
Effective Coverage % →
Common questions
- Is the Azure integration available now?
- It is in limited availability (private beta), enabled per organization on request. When it is on, reporting, budgets, allocation, alert rules, and anomaly detection all cover Azure spend; savings recommendations remain AWS-only during the beta. Email us to have it turned on for your org.
- How does CloudQuell read Azure cost?
- Through a read-only Microsoft Entra ID service principal with cost-reader roles. Two paths: a Cost Management export in FOCUS format delivered to a storage account you own (invoice-accurate billed and amortized cost), or a quick API connect with no export setup that backfills up to 13 months. Nothing is written back to your tenant.
- Does the Azure integration use the FOCUS format?
- On the recommended path, yes — CloudQuell reads the Cost and usage (FOCUS) export (version 1.0r2). It then normalizes that into the same internal cost model as every other provider, so Azure sits on the same ledger, allocation, and alerts as your AWS and AI spend.
- How are Azure subscriptions represented?
- Each subscription appears as its own sub-account — the Azure analog of an AWS linked account — so you can filter, report, and allocate per subscription. Resource groups and invoice sections arrive as tags, filterable anywhere tags are.
Azure is in private beta, enabled per organization on request. Free under $10K/month of tracked spend once it is on.