Automatic Azure Connect
Automatic Azure Connect is the recommended setup path when an Azure or Entra admin can sign in and approve the setup from the Spotto portal.
What It Does
The portal flow creates or reuses the Spotto Azure service principal and configures the recommended Azure access. New app registrations use the display name Spotto; existing Spotto AI app registrations can still be reused when updating an existing account. It can also update an existing Azure cloud account to repair missing access.
Automatic setup can configure:
- Reader access for selected subscriptions, or inherited access for all subscriptions where supported.
- Reader and Management Group Reader at the root management group.
- Reservations Reader, Reservations Contributor, and Savings plan Reader.
- Microsoft Graph governance permissions with admin consent for application, Global Admin/PIM, group, user, and audit visibility.
- Optional Monitoring Reader and Log Analytics Reader.
- Cost Management billing exports to customer-owned Azure Storage.
- Cost Management Reader on linked billing scopes when compatible billing-scope exports are discovered and the scope is available.
- Storage Blob Data Reader on the selected export container.
Prerequisites
You need:
- A Spotto user with permission to manage cloud accounts for the company.
- An Azure or Entra account with enough permission to create or update app registrations, service principals, role assignments, Graph consent, and billing export resources.
- Owner at the selected subscription or inherited parent scope for full automation.
- If Owner is not available, both Contributor and User Access Administrator at the selected subscription or inherited parent scope. Contributor covers billing export and storage resource changes; User Access Administrator covers RBAC assignments.
- User Access Administrator alone is not enough when billing export setup is enabled because it cannot create Cost Management exports, resource groups, storage accounts, or containers.
- Permission to assign Reservations Reader and Reservations Contributor at
/providers/Microsoft.Capacity. - Permission to create or update Cost Management exports and the selected export storage account/container if billing exports are enabled.
- Permission to grant the Spotto service principal read access at linked billing scopes when billing-scope exports are reused.
- Permission to grant the Spotto service principal Storage Blob Data Reader on the selected export container.
If your organization uses PIM or just-in-time access, activate the required roles before selecting Connect Azure. See Operator Permissions And PIM.
If assigning Reader at the tenant root scope, a Global Administrator may need to enable Microsoft Entra ID -> Properties -> Access management for Azure resources, sign out, and sign back in before running setup.
Connect a New Azure Account
- In Spotto, go to Connectors -> Connectors -> Cloud Accounts.
- Select Add Cloud Account.
- Choose Automated Setup.
- Select Connect Azure.
- Sign in to Microsoft as an Azure or Entra admin.
- Select the tenant and subscriptions Spotto should analyze.
- Review the recommended access plan.
- Keep billing exports enabled unless your organization needs to configure them separately.
- Review the billing export storage choice if Spotto asks for confirmation.
- Select Set Up Recommended Access.
- Wait for Spotto to finish setup and validation.
Spotto saves the cloud account after the service principal validates. Recommended items such as billing exports can produce repair warnings if Azure rejects one dataset or a storage choice, but the cloud account can still be usable for resource discovery.
Update an Existing Azure Account
Use this path when Spotto shows missing permission warnings or billing export repair guidance for an existing Azure cloud account.
- Open Connectors -> Connectors -> Cloud Accounts.
- Open the Azure cloud account.
- On the configuration view, select Update Azure Access or Repair Azure Access.
- Choose Automated Update.
- Sign in and approve the setup.
- Review the plan and run the update.
The update flow reuses the existing cloud account and service principal where possible. It should not create a duplicate cloud account.
Billing Export Choices
When billing exports are enabled, Spotto can:
- Reuse compatible existing daily Cost Management exports.
- Reuse compatible billing-scope exports where the signed-in operator has access, and grant Spotto read access at the linked billing scope when available.
- Use an existing storage account and container.
- Create a new customer-owned StorageV2 account and private container.
- Grant Storage Blob Data Reader to the Spotto service principal on the export container so Spotto can read exported files.
- Create daily actual cost exports and amortized exports where supported.
- Queue historical backfill for recent closed months where supported.
Setup queues export runs and backfill requests with Azure, but it does not wait for Azure Cost Management to finish generating export files. Billing files can appear later depending on Azure export timing.
If Azure does not support a dataset for a subscription or agreement, Spotto records that item as unavailable and continues with the available billing data.
After Setup
Azure RBAC and Graph consent can take several minutes to propagate. If Spotto reports a temporary access issue immediately after setup, wait 5-15 minutes and refresh or run sync again.
For warning-specific repair steps, see Azure Cloud Account Permissions.