Skip to main content

Automatic Azure Connect: Setup and Repair

Automatic Azure Connect is the recommended setup path when an Azure or Entra admin can sign in and approve the setup from the Spotto portal. Setup usually takes several minutes, although Azure permission propagation or throttling can make larger setups take longer. Once Spotto shows that setup is queued, you can close the page without stopping the work.

What It Does

The portal flow creates or reuses the Spotto Azure service principal and configures the recommended Azure access. New app registrations use the display name Spotto; existing Spotto AI app registrations can still be reused when updating an existing account. It can also update an existing Azure cloud account to repair missing access.

Automatic setup can configure:

  • Azure Reader at the root management group and independently on every selected subscription. Automatic Connect does not assign Reader at tenant scope (/).
  • Key Vault Reader at the root management group, or the visible management-group targets available to the operator, and independently on every selected subscription. It covers secret, key, and certificate expiry metadata but cannot read secret values or private key material.
  • Management Group Reader at the root management group.
  • Reservations Reader and Savings plan Reader. Reservations Contributor is optional write access and is off by default.
  • Microsoft Graph governance permissions with admin consent for application, Global Admin/PIM, group, user, audit, tenant policy, and subscribed-license visibility. See the complete permission list.
  • Recommended Monitoring Reader, Log Analytics Reader, and Security Reader on every selected subscription.
  • Cost Management billing exports to customer-owned Azure Storage.
  • The matching read role on linked billing scopes when compatible billing-scope exports are discovered and the scope is available.
  • Storage Blob Data Reader on the selected export container.
  • Optional Azure Policy exemption roles at each selected subscription and visible management-group scope, selected separately from Advisor/Storage writes.

Policy exemption access is disabled by default. Automatic setup discovers the management groups visible to the signed-in operator and shows a separate role-definition and role-assignment choice for each exact scope. Spotto keeps those two choices paired so it cannot request an assignment without its matching narrow role definition. Selecting a management-group pair also selects both policy-exemption items for every subscription currently selected in the setup, because an inherited assignment needs permission at both the exemption target and assignment scopes. It does not select any other management group.

Prerequisites

You need:

  • A Spotto user with permission to manage cloud accounts for the company.
  • An Azure or Entra account with enough permission to create or update app registrations, service principals, role assignments, Graph consent, and billing export resources.
  • Owner at the selected subscription or inherited parent scope for full automation.
  • If Owner is not available, both Contributor and User Access Administrator at the selected subscription or inherited parent scope. Contributor covers billing export and storage resource changes; User Access Administrator covers RBAC assignments.
  • User Access Administrator alone is not enough when billing export setup is enabled because it cannot create Cost Management exports, resource groups, storage accounts, or containers.
  • Permission to assign Reservations Reader at /providers/Microsoft.Capacity, and Reservations Contributor there if you enable reservation management workflows.
  • Permission to create or update Cost Management exports and the selected export storage account/container if billing exports are enabled.
  • Permission to grant the Spotto service principal read access at linked billing scopes when billing-scope exports are reused.
  • Permission to grant the Spotto service principal Storage Blob Data Reader on the selected export container.
  • Microsoft.Authorization/roleDefinitions/write and Microsoft.Authorization/roleAssignments/write at every subscription or management group where you choose to enable policy exemption writes.

These elevated permissions belong to the person running setup and can be activated temporarily through PIM. They are not granted to the Spotto service principal. The service principal receives only the access selected in the reviewed setup plan.

If your organization uses PIM or just-in-time access, activate the required roles before selecting Connect Azure. See Operator Permissions And PIM.

If a Global Administrator needs temporary Azure resource access to make the root-management-group assignments, they may need to enable Microsoft Entra ID -> Properties -> Access management for Azure resources, sign out, and sign back in before running setup.

Connect a New Azure Account

  1. In Spotto, go to Connectors -> Connectors -> Cloud Accounts.
  2. Select Add Cloud Account.
  3. Choose Automated Setup.
  4. Select Connect Azure.
  5. Sign in to Microsoft as an Azure or Entra admin.
  6. Select the tenant and up to 100 subscriptions Spotto should analyze in this initial setup. If more than 100 are visible, complete this setup first, then use Update Access for the remaining subscriptions.
  7. Review the recommended access plan. Key Vault Reader is selected and locked for the planned hierarchy targets and every selected subscription. A failed assignment produces a repair warning rather than hiding the missing expiry-notification coverage. Security Reader is selected by default for every selected subscription so Spotto can collect Defender for Cloud assessments, secure score, and security posture.
  8. Keep billing exports enabled unless your organization needs to configure them separately.
  9. To allow exemption creation, expand the tenant/application permission group and select the paired Spotto Policy Exemptions items only for the required management-group assignment scopes. Spotto also checks both target-write items for every subscription currently selected in the setup. Review those visible subscription choices before continuing; unrelated management groups remain off.
  10. Review the billing export storage choice if Spotto asks for confirmation. Each broad management-group or billing-hierarchy export target has its own checkbox. Confirm the selected scopes before continuing; discovery by itself does not grant Spotto permission to create an export.
  11. Select Set Up Recommended Access, or open the access details and select Run Setup after customizing the plan.
  12. Keep the setup link if you want to return later. After the setup is saved and queued, you can safely leave the page; provisioning and validation continue in the background.

Spotto saves the generated credential and cloud account before the remaining access checks finish so interrupted work can resume without creating a duplicate identity. This early save does not mean every subscription is ready. Spotto starts a subscription's first sync only after Reader is verified for that subscription.

Recommended items such as root-management-group access, Key Vault metadata access, Graph consent, commitments, or billing exports can produce repair warnings while subscriptions with verified Reader remain usable. Spotto reports those outcomes as partial instead of hiding them behind a successful credential check.

After the next subscription sync, enabled Key Vault secrets, keys, and certificates with an expiry date appear in Retirement Tracker. The credentials-expiry quick alert can then notify you before those dates. Spotto reads only the current object metadata returned by the Key Vault list APIs; it does not retrieve values or enumerate historical versions. If one vault or object family is blocked, Spotto reports partial coverage and preserves existing alerts instead of treating the inaccessible vault as empty.

Update an Existing Azure Account

Use this path when Spotto shows missing permission warnings or billing export repair guidance for an existing Azure cloud account.

  1. Open Connectors -> Connectors -> Cloud Accounts.
  2. Open the Azure cloud account.
  3. On the configuration view, select Update Access or Repair Setup under Update Azure Access or Repair Azure Access.
  4. Choose Automated Update.
  5. Sign in and approve the setup.
  6. Review the subscriptions and permission plan. Missing or failed recommended access is selected for repair, while required Reader access for a selected subscription cannot be omitted. You can also select newly discovered subscriptions; healthy subscriptions outside this repair keep their existing readiness.
  7. Policy exemption choices remain off by default. Selecting a management-group pair also checks both policy-exemption items for every currently selected subscription target. Review the resulting scopes before continuing; unrelated management groups stay off.
  8. Review Service-principal credential renewal. It is preselected and recommended when the stored credential expires within 90 days, and required when the credential has expired. When the expiry is more than 90 days away or unknown, renewal remains optional.
  9. Select Run Setup.

The update flow reuses the exact existing cloud account, Microsoft Entra application, and service principal. It never creates a replacement identity or duplicate cloud account. If renewal is selected, Spotto tries a 24-month credential, then 12 months, then 6 months when tenant policy rejects a longer duration. It validates the replacement before switching the credential stored by Spotto, and it does not delete the previous Azure password.

If optional renewal fails while the old credential still works, Spotto preserves that credential and reports a repair warning. If the stored credential is expired or unusable, scanning remains blocked until renewal or a manual credential replacement succeeds.

Understand Setup Status

Automatic Connect checkpoints completed Azure changes, so a retry or worker restart continues from saved progress instead of replaying the whole setup.

Status in SpottoWhat it meansWhat to do
Scheduling Azure Access or Azure Setup QueuedThe plan is saved and waiting for background processing.You can leave the page and return with the same setup link.
Running SetupSpotto is applying and validating the selected access.No action is required unless Spotto shows a failed step.
Retrying Azure SetupA temporary Azure, network, or propagation issue interrupted a step. Completed work is preserved.Wait for the displayed retry, or select Refresh Status when offered.
Setup CompleteRequired Reader access succeeded for the ready subscriptions. The page can still show warnings for recommended items.Review any warning and use Repair Setup for missing access.
Needs AttentionAn Azure or Entra administrator must approve or apply one or more items.Follow the role, scope, and error-code guidance, then select Repair Setup or Reauthorize Microsoft.
Setup CancelledSpotto stopped at a safe checkpoint. Any cloud account and credential already saved are preserved.Open the account and run Repair Setup when you are ready to continue.
Setup ExpiredThe Microsoft authorization session can no longer be used.Start setup again and reconnect to Microsoft.
Setup FailedSpotto could not safely continue. If a cloud account was already saved, it remains available for repair.Use the failed step and setup ID to correct the issue, then retry or repair.

Cancelling is also a background request: Spotto finishes the current safe checkpoint before stopping. Do not create another app registration just because cancellation is still being processed.

Policy Exemption Access Safety

For each selected subscription, Spotto creates a dedicated custom role containing only:

  • Microsoft.Authorization/policyExemptions/write
  • Microsoft.Authorization/policyAssignments/exempt/action

For each selected management group, Spotto creates a separate exact-scope role containing only Microsoft.Authorization/policyAssignments/exempt/action. Azure custom roles can contain only one management group in AssignableScopes, so each scope has its own deterministic role name.

Automatic setup refuses to reuse or assign a matching role if it contains unrelated actions, data actions, exclusions, or additional assignable scopes. It does not silently broaden an existing role. Grant All Permissions also selects every visible optional management-group pair, so review those scopes before continuing.

Clearing a management-group pair removes that assignment-scope consent only. The selected subscription pairs remain enabled because they can still support direct subscription assignments; clear those pairs separately if Spotto should not create exemptions at those targets.

For permission details and rollback guidance, see Azure Policy exemption permissions.

Billing Export Choices

When billing exports are enabled, Spotto can:

  • Reuse compatible existing daily Cost Management exports.
  • Reuse compatible billing-scope exports where the signed-in operator has access, and grant Spotto read access at the linked billing scope when available.
  • Use an existing storage account and container.
  • Create a new customer-owned StorageV2 account and private container.
  • Grant Storage Blob Data Reader to the Spotto service principal on the export container so Spotto can read exported files.
  • Create daily actual cost exports and amortized exports where supported.
  • Queue historical backfill for recent closed months where supported.

Compatible broad exports can be reused when selected. Creating a new export at a management-group, billing-account, billing-profile, or invoice-section scope always requires an explicit choice; seeing a discovered target is not consent to create one. Spotto keeps the supported subscription Actual and Amortized exports as completeness fallbacks when broad coverage is unavailable or incomplete.

At subscription and management-group scopes, Spotto can assign Cost Management Contributor to the signed-in administrator only when that administrator already has permission to create role assignments at the exact scope. It never grants that role to the Spotto service principal. Azure billing-hierarchy scopes use the applicable EA or MCA billing authorization model instead of Azure subscription RBAC, and unsupported agreements remain a manual action.

Setup queues export runs and backfill requests with Azure, but it does not wait for Azure Cost Management to finish generating export files. Billing files can appear later depending on Azure export timing.

If Azure does not support a dataset for a subscription or agreement, Spotto records that item as unavailable and continues with the available billing data.

A compatible export can write to customer-owned storage in a different subscription from the subscriptions selected for analysis. Spotto reuses that centralized destination only when Azure discovery or the server-generated setup plan identifies the exact storage account and container. The service principal still needs Storage Blob Data Reader and a reachable network path to the container.

Spotto uses Azure billing APIs for the newest interval after the latest complete export and for other uncovered dates. If no applicable readable export is available, those APIs remain the fallback where Azure supports them. See Azure Billing Exports for scope, storage, and gap-filling details.

After Setup

Azure RBAC and Graph consent can take several minutes to propagate. If Spotto reports a temporary access issue immediately after setup, wait 5-15 minutes and refresh or run sync again.

If Spotto verified Azure Reader at the tenant-root management group, later subscriptions discovered beneath that root can be added automatically. Spotto checks each new subscription's effective Reader access before enabling and syncing it. Subscriptions that you explicitly left unselected during the initial setup stay disabled; Spotto does not reinterpret them as new subscriptions.

A cloud account with a Partial result can still run tenant sync when its base service-principal access is usable. Optional Graph, billing, commitment, Key Vault, or broad-scope gaps remain visible in sync diagnostics and Update Access.

Troubleshoot Automatic Connect

Azure setup is queued or retrying for several minutes

What you're seeing: Azure Setup Queued or Retrying Azure Setup remains visible.

Likely cause: Azure is propagating a new identity or role assignment, throttling a request, or temporarily unavailable.

How to fix:

  1. Keep the setup URL and wait for the displayed retry time.
  2. Select Refresh Status when it is available.
  3. Do not start another setup or create another app registration. Spotto resumes from its saved checkpoint.

Root management group access is unavailable

What you're seeing: Spotto reports management_group_authority_missing, but one or more subscriptions are ready.

Likely cause: The signed-in administrator can assign access on the selected subscriptions but not at the exact tenant-root management group.

How to fix:

  1. Allow ready subscriptions to continue syncing.
  2. Activate Owner, User Access Administrator, or Role Based Access Control Administrator at the tenant-root management group.
  3. Open the cloud account and select Repair Setup.

No subscriptions appear, or the selection exceeds 100

What you're seeing: Azure returns no subscriptions, or Spotto reports azure_sp_setup_subscription_limit_exceeded.

Likely cause: The signed-in account cannot list subscriptions in the selected tenant, or more than 100 subscriptions were selected for one setup.

How to fix:

  1. Confirm the intended Azure tenant and activate Reader or another role that can list the required subscriptions.
  2. Sign out and start again so Microsoft issues a token with the active access.
  3. Select no more than 100 subscriptions. Add further subscriptions later through Update Access.

Setup needs Microsoft authorization again

What you're seeing: Needs Attention offers Reauthorize Microsoft.

Likely cause: The setup authorization expired, was revoked, or no longer carries the required administrator privilege.

How to fix: Select Reauthorize Microsoft and sign in with an administrator whose PIM roles are already active. Any Spotto cloud-account credential saved earlier is preserved.

For more warning-specific repair steps, see Azure Cloud Account Troubleshooting and Azure Cloud Account Permissions.

Get Help

If the same setup remains blocked after the recommended repair, follow the Spotto support checklist. Include the company, cloud account, setup ID, failed step, exact safe error code, and approximate time. Never include a client secret, authorization code, access token, or downloaded onboarding JSON.