CloudMonitor on Fabric fabric
CloudMonitor runs on Microsoft Fabric. By default we deploy CloudMonitor into a Fabric workspace on capacity you own, in your own Microsoft Fabric tenant. CloudMonitor-hosted stays available if you would rather we ran that capacity. Architecture and data flow sets out where each layer runs in both arrangements.
To get started you authorize our multi-tenant service principal, create one export storage account, and grant the required least-privilege roles. In your own Fabric tenant you also supply the workspace and the Fabric capacity CloudMonitor is deployed onto, which Configure Fabric Access covers.
Architecture and data flow Where each layer runs in both arrangements, and how CloudMonitor reads your raw cost export with scoped, least-privilege access.
Granting CloudMonitor access to your Azure environment Authorize the service principal and grant scoped, least-privilege access to subscriptions, billing, and cost-export storage.
Configure Fabric Access What your Fabric administrator sets up so CloudMonitor can be deployed into a workspace in your own Microsoft Fabric tenant.
What data CloudMonitor can see Microsoft-published field schemas, including where customer-defined names and tags may contain personal or confidential data.
Getting started with the CloudMonitor Fabric Workload Add CloudMonitor to your Fabric workspace, connect it to your semantic model, and tour the Inform, Optimize, and Operate screens.
Granting CloudMonitor access to Microsoft 365 data Optional: authorize CloudMonitor’s Microsoft 365 service principal for usage, licensing, and security reporting.