Connect an Azure Data Source
KOSTRA connects to Azure through an app registration (a service principal) that has read-only access to your subscriptions. Once connected, KOSTRA imports your Azure spend, discovers your resources, and evaluates them for recommendations alongside your other providers.Choose a connection type
On the Azure connection form, KOSTRA offers two connection types: Tenant and Subscription. The Subscription type can also read costs from a Cost Management billing export.
Every type needs the same three credentials from an app registration: Directory (tenant) ID, Application (client) ID, and a client secret. The Subscription type also needs the Subscription ID.
Before you begin
- You need permission in Azure to create an app registration and to assign roles on the subscriptions you want to connect (for example Owner or User Access Administrator on those subscriptions).
- Check your currency. KOSTRA rejects a subscription whose billing currency differs from the KOSTRA organization’s currency, and reports
Account currency '<X>' doesn't match organization currency '<Y>'. Confirm the organization currency before you connect.
Step 1 — Register an application
- In the Azure portal, open Microsoft Entra ID (formerly Azure Active Directory) → App registrations.
- Select + New registration.
- Enter a name, for example
KOSTRA, keep the default account type, and select Register. - On the application’s Overview page, copy:
- Application (client) ID
- Directory (tenant) ID
Step 2 — Create a client secret
- In the same app registration, open Certificates & secrets → Client secrets.
- Select + New client secret, add a description, and choose an expiry.
- Copy the secret’s Value, not its Secret ID, right away.
Important: Azure hides the secret value shortly after you create it. If you lose it, create a new secret. When the secret expires, KOSTRA stops importing data. Before that date, create a new secret and update it in KOSTRA under Data Sources → your Azure source → Update credentials.
Step 3 — Grant the Reader role
KOSTRA needs only the built-in Reader role. Reader is enough to read cost data through the Consumption API and to discover resources. Do not grant Contributor or Owner. For each subscription you want KOSTRA to see:- Open Subscriptions and select the subscription.
- Open Access control (IAM) → Role assignments.
- Select + Add → Add role assignment.
- On the Role tab, choose Reader.
- On the Members tab, choose User, group, or service principal, select + Select members, search for your app registration by name, and select it.
- Select Review + assign.
Step 4 (optional) — Set up a billing export
Skip this step unless you plan to use Use billing export on a Subscription connection. KOSTRA does not create exports. It reads only an export you have already set up.- In the Azure portal, open Cost Management → Exports, with the subscription selected as the scope.
- Create an export with these settings:
- Scope: the subscription
- Type of data: Cost and usage details (usage only also works)
- Frequency: Daily export of month-to-date costs
- Overwrite data: enabled
- Storage: a storage account, container, and directory of your choice
- Run the export once, or wait for its first run, so that a file exists before you connect.
- Collect the four values KOSTRA asks for:
- Export name: the export’s name as shown in Cost Management.
- Storage account connection string: on the storage account, open Security + networking → Access keys and copy a Connection string. It looks like
DefaultEndpointsProtocol=https;AccountName=<name>;AccountKey=<key>;EndpointSuffix=core.windows.net. - Storage container and Storage directory: shown in the export’s Essentials section.
Step 5 — Connect in KOSTRA
- In the left navigation, open Data Sources and select Connect data source.
- Choose Azure, then choose the connection type: Tenant or Subscription.
- Enter a name for the data source.
- Fill in the fields:
- Select Connect.
What happens after you connect
Subscription. KOSTRA checks that the subscription exists and that the app can read it. Then it picks how to import costs:- Billing export, if you provided export settings.
- Consumption API (usage details), if the subscription supports it.
- Raw usage as a fallback, for subscriptions where the Consumption API returns nothing. This includes sponsored subscriptions and some Enterprise Agreement subscriptions.
Troubleshooting
Verify the connection
- On Data Sources, check that the Azure source (and, for a tenant, its child subscriptions) shows a recent successful import.
- Open Cost Explorer to watch Azure spend appear as imports complete.
- Open Resources to confirm that virtual machines, disks, and other resources are listed.