Getting started
Granting CloudMonitor read-only Azure access and getting your reports live.
Does it support FOCUS 1.2?
Yes. FOCUS is the native schema, and CloudMonitor always tracks the latest version Microsoft Cost Management exports — currently FOCUS 1.2, which Azure publishes as its 1.2-preview schema alongside the generally available 1.0 export. See Microsoft's FOCUS metadata reference for the current Azure schema. If you already have a FOCUS export in Azure Storage, CloudMonitor reads it directly. As we add Amazon Web Services and Google Cloud, we'll support the latest published FOCUS specification for those clouds too — so your Azure, AWS, and GCP spend all normalize to one schema.
How long does setup take?
Installation normally takes a couple of hours. Total elapsed time depends on how quickly your Azure administrator approves the CloudMonitor application and grants the required scoped roles. The setup guide walks through each step.
What exactly am I approving?
Approve the CloudMonitor app in your Microsoft Entra tenant so Azure creates its service principal. Then grant the required scoped roles. These include read access for billing and resource metadata. One management role is limited to the dedicated export storage account, where CloudMonitor creates and runs the scheduled export. CloudMonitor cannot read the data inside your workloads or services.
What happens next?
As soon as you authorize, we start processing your cost data and setting up your reports. We'll reach out by email with your access once it's ready, and we'll let you know if we run into any issues connecting your account.
Where do I find my tenant ID?
In the Microsoft Entra admin center under Overview → Tenant ID, or in the Azure portal as the Directory ID. It is a 36-character GUID.
Do I need to be an administrator?
Approving access requires the Microsoft Entra Cloud Application Administrator role — the least-privilege role for this step, and the one we encourage rather than using a Global Administrator. On the get-started page you can enter your details and forward the authorization link to whoever holds that role.