1
Authorize CloudMonitor
Enter your Azure tenant ID and work email, then approve read-only access through the standard Microsoft admin-consent screen. Only a Global Administrator can approve it.
Get started
Two details and one click. Enter your Azure tenant ID and work email, then approve read-only access through Microsoft's standard admin-consent screen. CloudMonitor runs entirely in our Microsoft Fabric tenancy — nothing to deploy in yours — and can never change your resources.
We'll record your details, then hand you to Microsoft to authorize.
By continuing you agree to our Privacy Policy and Terms and Conditions.
Not ready to connect your data? Estimate your savings first.
How it works
You stay in control the whole way — you choose what CloudMonitor can see, and every role we ask for is read-only.
1
Enter your Azure tenant ID and work email, then approve read-only access through the standard Microsoft admin-consent screen. Only a Global Administrator can approve it.
2
Assign the read-only Reader role to the CloudMonitor service principal on the subscriptions (or management group) you want monitored, plus billing read access. Our access guide walks through every step.
3
Our team finishes wiring up cost and usage ingestion against your billing scope and subscriptions. There is nothing to deploy in your tenancy.
4
We email you when your CloudMonitor reports and FinOps agents are ready — usually within a couple of business days.
A look inside the Fabric app
CloudMonitor is a Microsoft Fabric app of pre-built FinOps reports, an admin app for governance, and a Teams agent — one data model your CFO, engineers, and FinOps leads all read in the same language.
Executive overview
A single-glance view of your FinOps program — Azure spend trend, forecast accuracy, and the cost groups moving the total. The proof points that justify the investment to finance.
Cost analytics
Break spend down by subscription, cost group, and tag, with cross-filtered drill-down from the total to a single resource. The report finance and engineering both open first thing Monday.
Anomaly detection
Per-resource daily spend is compared against a 30-day forecast, and divergences fire as Critical, High, or Medium alerts with the owner and cost group already attached — so a creeping overspend surfaces in hours, not at month-end.
Recommendations
Every right-sizing, reservation, idle-resource, storage-tier, and hybrid-licensing recommendation in one report, sorted by projected annual saving and backed by 14 days of CPU, RAM, IOPS, and network telemetry. The $14k item surfaces ahead of the long tail worth cents.
Cost groups
Define cost groups from tag values, resource groups, or subscription IDs, nest them up to five levels deep, and assign Finance, Technical, and Business owners to each. Allocation maps to projects and programs, not the Azure subscription layout.
Teams agent
The CloudMonitor FinOps agent posts anomaly and budget-breach cards into per-cost-group Microsoft Teams channels — acknowledge, snooze, or hand off to ITSM in place. Cost decisions happen in the channels engineers already watch, not a dashboard nobody opens.
CloudMonitor is a hosted SaaS platform running in our Microsoft Fabric tenancy. Your billing data stays in the storage account you own. CloudMonitor reads it in place through a OneLake shortcut, read-only, and never makes a second copy. The CloudMonitor environment that reads it and serves your reports runs in the data residency region you choose at sign-up — encrypted in transit and at rest. Every customer gets a dedicated Microsoft Fabric workspace, so your data lives in its own isolated workspace and is never co-mingled with another customer's. CloudMonitor staff access is restricted, audited, and gated by least-privilege controls, and only your authorized users see your reports.
You configure a FOCUS cost export to an Azure Storage account in your tenant and grant CloudMonitor scoped read-only access to it. CloudMonitor ingests that export into your dedicated Microsoft Fabric workspace, where it becomes your reports. Only billing and resource metadata moves — never the data inside your resources. See the Information Trust Center for the full data-flow detail.
Read-only, scoped to your billing data. You can limit it to specific subscriptions and revoke it from the Azure portal at any time. CloudMonitor has no write access to your workloads or the data inside your services. The one exception is a tightly scoped management role on the single storage account that receives your cost exports, used only to set up that export. Nothing else in your environment is writable by CloudMonitor.
Yes. FOCUS is the native schema, and CloudMonitor always tracks the latest version Microsoft Cost Management exports — currently FOCUS 1.2, which Azure publishes as its 1.2-preview schema alongside the generally available 1.0 export. See Microsoft's FOCUS metadata reference for the current Azure schema. If you already have a FOCUS export in Azure Storage, CloudMonitor reads it directly. As we add Amazon Web Services and Google Cloud, we'll support the latest published FOCUS specification for those clouds too — so your Azure, AWS, and GCP spend all normalize to one schema.
Most customers are live within 15 minutes — the setup guide walks through each step. The longest step is usually getting access approval through your change-management process.
Connection takes under fifteen minutes — sign up, point CloudMonitor at your FOCUS billing export, grant scoped read-only access to the billing scope. The first set of reports populates the same day. A FinOps Assessment in the admin app gives a Crawl, Walk, Run baseline per Capability after the first refresh, so you can plan the practice maturity path from week one.
You are provisioning the CloudMonitor application in your Microsoft Entra tenant so we can grant it read-only access to your costs. CloudMonitor cannot change your resources and cannot read the data inside your services.
As soon as you authorize, we start processing your cost data and setting up your reports. We'll reach out by email with your access once it's ready, and we'll let you know if we run into any issues connecting your account.
In the Microsoft Entra admin center under Overview → Tenant ID, or in the Azure portal as the Directory ID. It is a 36-character GUID.
Approving access requires the Microsoft Entra Cloud Application Administrator role — the least-privilege role for this step, and the one we encourage rather than using a Global Administrator. On the get-started page you can enter your details and forward the authorization link to whoever holds that role.
Only your authorized team and the CloudMonitor onboarding team helping you set up. Staff access is limited and audited, and ongoing support access is used only to respond to a request.
No. There's no personally identifiable information in any of the cost datasets. See what data CloudMonitor can see for the exact schemas.
Next to nothing. CloudMonitor's platform runs entirely in our Microsoft Fabric tenancy — no Fabric capacity for you to license, no Hubs deployment, no compute or managed app in your tenant. The only Azure resource you create is one storage account that receives your scheduled cost exports; CloudMonitor reads it in place and needs nothing else. The annual license covers the Fabric capacity we run for you, and your team just gets a hosted SaaS URL and a Fabric app.