> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kostra.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect an Azure Data Source

> Step-by-step: connect an Azure tenant or subscription to KOSTRA, with or without a Cost Management billing export.

# Connect an Azure Data Source

KOSTRA connects to Azure through an app registration (a service principal) that has read-only access to your subscriptions. Once connected, KOSTRA imports your Azure spend, discovers your resources, and evaluates them for recommendations alongside your other providers.

## Choose a connection type

On the Azure connection form, KOSTRA offers two connection types: **Tenant** and **Subscription**. The Subscription type can also read costs from a Cost Management billing export.

| Connection type | Use it when | What KOSTRA creates |
| - | - | - |
| **Tenant** | You want every subscription in an Azure AD (Entra ID) tenant, including ones added later | One tenant data source with a child data source for each subscription the app can see |
| **Subscription** | You want one specific subscription | One data source for that subscription |
| **Subscription + billing export** | One subscription where the Consumption API is unavailable or incomplete, for example some Enterprise Agreement or sponsored subscriptions | One data source that reads costs from your export files |

Every type needs the same three credentials from an app registration: **Directory (tenant) ID**, **Application (client) ID**, and a **client secret**. The Subscription type also needs the **Subscription ID**.

## Before you begin

* You need permission in Azure to create an app registration and to assign roles on the subscriptions you want to connect (for example **Owner** or **User Access Administrator** on those subscriptions).
* **Check your currency.** KOSTRA rejects a subscription whose billing currency differs from the KOSTRA organization's currency, and reports `Account currency '<X>' doesn't match organization currency '<Y>'`. Confirm the organization currency before you connect.

## Step 1 — Register an application

1. In the Azure portal, open **Microsoft Entra ID** (formerly Azure Active Directory) → **App registrations**.
2. Select **+ New registration**.
3. Enter a name, for example `KOSTRA`, keep the default account type, and select **Register**.
4. On the application's **Overview** page, copy:
   * **Application (client) ID**
   * **Directory (tenant) ID**

Store both values somewhere safe. You will enter them in KOSTRA.

## Step 2 — Create a client secret

1. In the same app registration, open **Certificates & secrets** → **Client secrets**.
2. Select **+ New client secret**, add a description, and choose an expiry.
3. Copy the secret's **Value**, not its Secret ID, right away.

> **Important:** Azure hides the secret value shortly after you create it. If you lose it, create a new secret. When the secret expires, KOSTRA stops importing data. Before that date, create a new secret and update it in KOSTRA under **Data Sources → *your Azure source* → Update credentials**.

## Step 3 — Grant the Reader role

KOSTRA needs only the built-in **Reader** role. Reader is enough to read cost data through the Consumption API and to discover resources. Do not grant Contributor or Owner.

For each subscription you want KOSTRA to see:

1. Open **Subscriptions** and select the subscription.
2. Open **Access control (IAM)** → **Role assignments**.
3. Select **+ Add** → **Add role assignment**.
4. On the **Role** tab, choose **Reader**.
5. On the **Members** tab, choose **User, group, or service principal**, select **+ Select members**, search for your app registration by name, and select it.
6. Select **Review + assign**.

**For a Tenant connection,** repeat this step on every subscription you want included. A subscription on which the app has no Reader role is invisible to KOSTRA. Granting Reader at a **management group** gives the same result and also covers subscriptions added to that group later.

**For a Subscription connection,** also copy the **Subscription ID** from the subscription's **Overview** page.

## Step 4 (optional) — Set up a billing export

Skip this step unless you plan to use **Use billing export** on a Subscription connection. KOSTRA does not create exports. It reads only an export you have already set up.

1. In the Azure portal, open **Cost Management** → **Exports**, with the subscription selected as the scope.
2. Create an export with these settings:
   * **Scope:** the subscription
   * **Type of data:** Cost and usage details (usage only also works)
   * **Frequency:** Daily export of month-to-date costs
   * **Overwrite data:** enabled
   * **Storage:** a storage account, container, and directory of your choice
3. Run the export once, or wait for its first run, so that a file exists before you connect.
4. Collect the four values KOSTRA asks for:
   * **Export name**: the export's name as shown in Cost Management.
   * **Storage account connection string**: on the storage account, open **Security + networking** → **Access keys** and copy a **Connection string**. It looks like `DefaultEndpointsProtocol=https;AccountName=<name>;AccountKey=<key>;EndpointSuffix=core.windows.net`.
   * **Storage container** and **Storage directory**: shown in the export's **Essentials** section.

KOSTRA downloads one report while you connect to check these settings. If the download fails, the connection is rejected and you can fix the values on the spot.

## Step 5 — Connect in KOSTRA

1. In the left navigation, open **Data Sources** and select **Connect data source**.
2. Choose **Azure**, then choose the connection type: **Tenant** or **Subscription**.
3. Enter a **name** for the data source.
4. Fill in the fields:

| Field | Tenant | Subscription | Where to find it |
| - | - | - | - |
| Directory (tenant) ID | ✓ | ✓ | App registration → Overview |
| Subscription ID | — | ✓ | Subscription → Overview |
| Application (client) ID | ✓ | ✓ | App registration → Overview |
| Secret | ✓ | ✓ | The client secret **Value** from Step 2 |
| Use billing export | — | optional | Turn on to show the four export fields from Step 4 |

5. Select **Connect**.

## What happens after you connect

**Subscription.** KOSTRA checks that the subscription exists and that the app can read it. Then it picks how to import costs:

* **Billing export**, if you provided export settings.
* **Consumption API** (usage details), if the subscription supports it.
* **Raw usage** as a fallback, for subscriptions where the Consumption API returns nothing. This includes sponsored subscriptions and some Enterprise Agreement subscriptions.

If the subscription has no usage data yet, KOSTRA still connects and shows a warning. Costs appear once Azure starts reporting them.

**Tenant.** KOSTRA checks that the app can list subscriptions in the tenant. Then it creates a **child Subscription data source** for each subscription the app can read. Each child is named after the subscription's display name. If that name is already taken in your organization, KOSTRA adds the tenant ID in parentheses. KOSTRA checks the tenant on a schedule, so subscriptions you grant access to later are added automatically.

If a child subscription can't be created, for example because of a currency mismatch, KOSTRA skips it, records the reason on the tenant data source, and raises a warning event. The rest of the tenant keeps importing.

## Troubleshooting

| Symptom | Likely cause and fix |
| - | - |
| Authentication error on connect | Wrong tenant ID, client ID, or secret. Check that you copied the secret **Value**, not its Secret ID, and that the secret hasn't expired. |
| `The subscription '<id>' could not be found` | The Subscription ID is wrong, or the app has no Reader role on that subscription (Step 3). |
| Tenant connects but shows no subscriptions | The app has no Reader role on any subscription. Assign Reader on each subscription or on a management group. |
| `Account currency ... doesn't match organization currency ...` | The subscription bills in a different currency from your KOSTRA organization. Connect it in an organization with the matching currency. |
| `Cloud validation timed out` | Azure didn't respond in time. Try again. If it keeps happening, check for an Azure service incident. |
| Export-related error on connect | The export name, connection string, container, or directory is wrong, or the export hasn't produced a file yet. Run the export once and try again. |
| Data stops importing after a while | The client secret probably expired. Create a new secret and update the data source credentials. |

## Verify the connection

1. On **Data Sources**, check that the Azure source (and, for a tenant, its child subscriptions) shows a recent successful import.
2. Open **Cost Explorer** to watch Azure spend appear as imports complete.
3. Open **Resources** to confirm that virtual machines, disks, and other resources are listed.

The first complete data set takes a full scheduling cycle. Recommendations appear after the first optimization run.

## Related pages

* [Connect AWS, Azure, or Google Cloud](/guides/connect-aws-azure-google)
* [Connect a Huawei Cloud Data Source](/guides/connect-huawei-cloud)
* [Explore Your Costs](/guides/explore-costs)
* [Supported Clouds & Services](/supported-clouds)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.