Skip to main content

Connect an Azure Data Source

KOSTRA connects to Azure through an app registration (a service principal) that has read-only access to your subscriptions. Once connected, KOSTRA imports your Azure spend, discovers your resources, and evaluates them for recommendations alongside your other providers.

Choose a connection type

On the Azure connection form, KOSTRA offers two connection types: Tenant and Subscription. The Subscription type can also read costs from a Cost Management billing export. Every type needs the same three credentials from an app registration: Directory (tenant) ID, Application (client) ID, and a client secret. The Subscription type also needs the Subscription ID.

Before you begin

  • You need permission in Azure to create an app registration and to assign roles on the subscriptions you want to connect (for example Owner or User Access Administrator on those subscriptions).
  • Check your currency. KOSTRA rejects a subscription whose billing currency differs from the KOSTRA organization’s currency, and reports Account currency '<X>' doesn't match organization currency '<Y>'. Confirm the organization currency before you connect.

Step 1 — Register an application

  1. In the Azure portal, open Microsoft Entra ID (formerly Azure Active Directory) → App registrations.
  2. Select + New registration.
  3. Enter a name, for example KOSTRA, keep the default account type, and select Register.
  4. On the application’s Overview page, copy:
    • Application (client) ID
    • Directory (tenant) ID
Store both values somewhere safe. You will enter them in KOSTRA.

Step 2 — Create a client secret

  1. In the same app registration, open Certificates & secrets → Client secrets.
  2. Select + New client secret, add a description, and choose an expiry.
  3. Copy the secret’s Value, not its Secret ID, right away.
Important: Azure hides the secret value shortly after you create it. If you lose it, create a new secret. When the secret expires, KOSTRA stops importing data. Before that date, create a new secret and update it in KOSTRA under Data Sources → your Azure source → Update credentials.

Step 3 — Grant the Reader role

KOSTRA needs only the built-in Reader role. Reader is enough to read cost data through the Consumption API and to discover resources. Do not grant Contributor or Owner. For each subscription you want KOSTRA to see:
  1. Open Subscriptions and select the subscription.
  2. Open Access control (IAM) → Role assignments.
  3. Select + Add → Add role assignment.
  4. On the Role tab, choose Reader.
  5. On the Members tab, choose User, group, or service principal, select + Select members, search for your app registration by name, and select it.
  6. Select Review + assign.
For a Tenant connection, repeat this step on every subscription you want included. A subscription on which the app has no Reader role is invisible to KOSTRA. Granting Reader at a management group gives the same result and also covers subscriptions added to that group later. For a Subscription connection, also copy the Subscription ID from the subscription’s Overview page.

Step 4 (optional) — Set up a billing export

Skip this step unless you plan to use Use billing export on a Subscription connection. KOSTRA does not create exports. It reads only an export you have already set up.
  1. In the Azure portal, open Cost Management → Exports, with the subscription selected as the scope.
  2. Create an export with these settings:
    • Scope: the subscription
    • Type of data: Cost and usage details (usage only also works)
    • Frequency: Daily export of month-to-date costs
    • Overwrite data: enabled
    • Storage: a storage account, container, and directory of your choice
  3. Run the export once, or wait for its first run, so that a file exists before you connect.
  4. Collect the four values KOSTRA asks for:
    • Export name: the export’s name as shown in Cost Management.
    • Storage account connection string: on the storage account, open Security + networking → Access keys and copy a Connection string. It looks like DefaultEndpointsProtocol=https;AccountName=<name>;AccountKey=<key>;EndpointSuffix=core.windows.net.
    • Storage container and Storage directory: shown in the export’s Essentials section.
KOSTRA downloads one report while you connect to check these settings. If the download fails, the connection is rejected and you can fix the values on the spot.

Step 5 — Connect in KOSTRA

  1. In the left navigation, open Data Sources and select Connect data source.
  2. Choose Azure, then choose the connection type: Tenant or Subscription.
  3. Enter a name for the data source.
  4. Fill in the fields:
  1. Select Connect.

What happens after you connect

Subscription. KOSTRA checks that the subscription exists and that the app can read it. Then it picks how to import costs:
  • Billing export, if you provided export settings.
  • Consumption API (usage details), if the subscription supports it.
  • Raw usage as a fallback, for subscriptions where the Consumption API returns nothing. This includes sponsored subscriptions and some Enterprise Agreement subscriptions.
If the subscription has no usage data yet, KOSTRA still connects and shows a warning. Costs appear once Azure starts reporting them. Tenant. KOSTRA checks that the app can list subscriptions in the tenant. Then it creates a child Subscription data source for each subscription the app can read. Each child is named after the subscription’s display name. If that name is already taken in your organization, KOSTRA adds the tenant ID in parentheses. KOSTRA checks the tenant on a schedule, so subscriptions you grant access to later are added automatically. If a child subscription can’t be created, for example because of a currency mismatch, KOSTRA skips it, records the reason on the tenant data source, and raises a warning event. The rest of the tenant keeps importing.

Troubleshooting

Verify the connection

  1. On Data Sources, check that the Azure source (and, for a tenant, its child subscriptions) shows a recent successful import.
  2. Open Cost Explorer to watch Azure spend appear as imports complete.
  3. Open Resources to confirm that virtual machines, disks, and other resources are listed.
The first complete data set takes a full scheduling cycle. Recommendations appear after the first optimization run.