Azure FinOps on Microsoft Fabric
Turn Azure billing data into reports, cost controls, and evidence-backed decisions.
CloudMonitor turns your FOCUS export into one cost model. It runs in a dedicated workspace within our Microsoft Fabric tenancy. Approved users explore reports and manage cost rules. Ask Finn is limited to active, licensed organization administrators and verified support staff in Support mode. Your team approves every workload change.
Working product
The governed cost model connects reports, controls, and investigations.
The product surfaces share data and permissions, but each one serves a different job.
- FinOps Reports
- Explore Azure cost by subscription, service, cost group, or tag, then continue to the Ledger for source rows.
- Admin App
- Define allocation rules, cost groups, owners, budgets, and audience access while unallocated spend remains visible.
- Ask Finn
- Active, licensed organization administrators and verified support staff using Support mode can investigate cost changes, anomalies, budgets, forecasts, and savings against organization-wide CloudMonitor cost data.
Installation responsibilities
Access, setup, and action each have a clear owner.
Your Azure admin approves scoped access. CloudMonitor connects the export and checks the first refresh. Finance and engineering choose what to act on.
Elapsed time depends on your Azure approval process and CloudMonitor's connection checks.
- You approveYour team Azure administrator
Approve access
Approve the CloudMonitor app in Azure. Grant the required roles, then make the FOCUS export available.
- Application approval
- Billing scope + FOCUS export
- We configureCloudMonitor Onboarding team
Connect and validate
We set up your dedicated workspace, connect the export, and check the first data refresh.
- Connection check
- First data refresh
- People decideYour team Finance + engineering
Review the findings
Your teams use reports and cost controls. Active, licensed organization admins can use Ask Finn. Verified support staff can use Support mode. People choose which changes move forward.
- Reports + allocation
- Role-gated Ask Finn
- Human-approved action
Billing data flow
Your export stays in customer-owned storage; processing runs in CloudMonitor’s Fabric tenancy.
Azure Cost Management writes the raw FOCUS export to a storage account you own. Billing and resource metadata access is read-only. One management role is limited to the export storage account. CloudMonitor uses it only to create and run the scheduled export. It does not provide write access to your workloads.
Swipe the diagram to follow the full data flow.
Inform · Optimize · Operate
Each investigation returns evidence to the next FinOps decision.
Reports help teams explain a signal, compare options, and carry an approved decision into normal operations. Eligible administrators can use Ask Finn to assemble an investigation. The cycle repeats as cost and context change.
-
Inform
Explain the signal
Set the period, cost basis, and scope. Reports establish the evidence. Eligible administrators can use Ask Finn to explain a variance or anomaly.
-
Optimize
Compare the options
Compare savings, usage, rates, licenses, and design options. Review the evidence and limits before you choose a path.
-
Operate
Keep the decision accountable
Your team assigns the work, follows its approval process, and checks the result. CloudMonitor does not change the workload.
As spend changes, the team returns to Inform with new evidence.
See how Ask Finn supports the cycle →Operating model
CloudMonitor supports the practice while your teams keep ownership.
Finance, engineering, and business teams work from the same cost model. CloudMonitor keeps setup and findings clear. Your teams set priorities, run the FinOps process, and approve each change.
FinOps Framework alignment
Use the same evidence across the current Domains.
Before onboarding
Questions security and Azure teams ask before they approve access.
What exactly am I approving?
Approve the CloudMonitor app in your Microsoft Entra tenant so Azure creates its service principal. Then grant the required scoped roles. These include read access for billing and resource metadata. One management role is limited to the dedicated export storage account, where CloudMonitor creates and runs the scheduled export. CloudMonitor cannot read the data inside your workloads or services.
How does our Azure billing data reach CloudMonitor?
Set up a FOCUS cost export to an Azure Storage account in your tenant, then grant CloudMonitor the required scoped roles. Raw source files stay in that account. Billing and resource metadata access is read-only. One management role is limited to the export account so CloudMonitor can create and run the scheduled export. CloudMonitor reads the files through a OneLake shortcut. Fabric then builds the cost models and report data in your dedicated Microsoft Fabric workspace within our tenancy. CloudMonitor cannot read content inside your resources. See the Information Trust Center for the full data-flow detail.
Why does CloudMonitor need a write role on the storage account if cost access is read-only?
CloudMonitor's access to your cost and usage data is read-only. The one management role is limited to the storage account that receives your cost exports. CloudMonitor uses it only to create and run the scheduled Azure Cost Management export. Azure requires write access on the destination account to set up the export. That role cannot access your other resources or workload data. CloudMonitor reads the exported files with a separate read-only role. See the access guide.
Can CloudMonitor see our application data?
No. CloudMonitor processes billing and resource metadata, its own setup data, and account profile fields used for sign-in. If you connect Fabric or AI features, it also processes Fabric capacity or AI token usage metrics. It cannot read secrets or content inside your VMs, databases, storage objects, or other workloads.
Where is our data stored?
CloudMonitor runs as a hosted SaaS platform in our Microsoft Fabric tenancy. Azure Cost Management writes raw FOCUS files to a storage account you own, where they remain. During onboarding, CloudMonitor confirms which Azure and Microsoft Fabric regions are available for the service. We deploy a dedicated customer shard in the agreed region, and Fabric stores the processed cost model and reporting data in the shard's dedicated workspace. See the current service-provider register for management-plane and supporting-service locations.
See CloudMonitor against sample Azure cost data.
Explore interactive reports and a recorded Ask Finn investigation on sample data, then compare service levels and onboarding paths.