Azure Billing
Use Azure Billing integration to ingest Azure cost and usage data into Cloudaware Cost Management.
info
- Audience: Cloudaware administrators, FinOps, finance teams
- Outcome: Microsoft Cost Management exports are available in Cloudaware for cost analysis, reporting, and optimization
This section covers:
- Supported Microsoft Cost Management export options.
- Required Azure permissions for Cost Management exports and storage access.
- Microsoft Cost Management export setup for billing account and subscription scopes.
- Azure Billing configuration in Cloudaware.
- Verification and troubleshooting steps.
note
The Azure EA portal was retired on February 15, 2024, and is now read-only. EA customers and partners should use Cost Management + Billing in the Azure portal to manage their enrollments. For more information, see the Microsoft documentation.
Prerequisites
- Microsoft Azure cloud integration configured in Cloudaware. If it is not configured, refer to the Azure Setup Guide first.
- Azure subscription and/or billing account with permissions to:
- Assign roles in Cost Management + Billing.
- Configure Cost Management exports.
- Grant access to Storage accounts.
- Name or identifier of the Cloudaware app/service principal used for billing access.
Supported Microsoft Cost Management Exports
Cloudaware supports Microsoft Cost Management exports configured at the following levels:
- Billing account-level exports, including MCA, MPA, and EA billing accounts.
- Subscription-level exports when billing account-level exports are not available or not exposed.
Address the export setup guide to configure the preferred billing source in Cloudaware.
Security Notes
- Use least-privilege roles for the Cloudaware app/service principal, such as Billing reader at the billing scope and Storage Blob Data Reader on the export Storage account.
- Restrict Storage accounts and containers used for billing data to dedicated, well-controlled resources.
- Regularly review role assignments and rotate credentials for the Cloudaware app according to your security policies.