Skip to main content

Azure Cloud Account Troubleshooting

Use this page when Azure credential validation succeeds but Spotto data is incomplete, or when validation fails after manual, PowerShell, Terraform, or automatic setup.

For selected GDAP pilots through Partner Center, use this page for failed authorization, missing subscriptions, billing gaps, or stopped scans after Spotto has enabled the GDAP workflow for the MSP and customer company.

Credential Validation Fails

Likely causes:

  • Application client ID or tenant ID was copied from the wrong app or tenant.
  • The client secret value was copied incorrectly.
  • The client secret expired.
  • Reader access has not propagated yet.

Fix:

  1. Re-check the Application (client) ID and Directory (tenant) ID from the same app registration.
  2. Create a new client secret if needed and copy the secret value immediately.
  3. Confirm the Spotto service principal has Reader at the subscription or inherited scope.
  4. Wait 5-10 minutes for Azure RBAC propagation.
  5. Validate again in Spotto.

Existing Service Principal Needs Replacement

Likely causes:

  • The previous app registration or service principal was blocked or disabled.
  • A new service principal exists, but Spotto is still using old credentials.

Fix:

  1. In Spotto, go to Connectors -> Connectors -> Cloud Accounts.
  2. Edit the affected Azure cloud account.
  3. Replace the Application (client) ID, tenant ID, secret, and secret expiry date.
  4. Select Validate Credentials.
  5. Select Update to save.

GDAP Authorization Fails Or Returns To Spotto With An Error

Likely causes:

  • The selected partner profile was authorized with the wrong partner tenant.
  • The signed-in partner user cannot use the customer GDAP relationship.
  • Microsoft consent was cancelled or blocked by tenant policy.
  • The Spotto region callback URL does not match the region where the profile is being authorized.

Fix:

  1. Switch to the MSP root company in Spotto.
  2. Open Connectors -> Connectors -> Cloud Accounts.
  3. Select the GDAP setup path.
  4. Select the affected partner profile.
  5. Confirm the partner tenant ID is correct.
  6. Select Authorize Profile again and complete Microsoft sign-in.
  7. Return to the customer company and retry Check details.

GDAP Customer Account Saves But First Scan Fails

Likely causes:

  • The GDAP relationship ID belongs to a different customer tenant.
  • The GDAP relationship is approved but no partner security group has been assigned.
  • The access assignment exists but is still pending.
  • Azure subscription access is not available through delegated access or Azure RBAC.
  • CSP Azure Usage visibility is disabled for the customer.

Fix:

  1. In Partner Center, confirm the customer, tenant ID, relationship ID, and relationship status.
  2. Confirm the partner security group is assigned to the relationship and the status is active.
  3. Confirm the roles assigned to the security group match the agreed customer scope.
  4. Confirm the delegated access path can see the customer's Azure subscriptions.
  5. For GDAP billing data, review CSP Billing Prerequisites. GDAP billing export setup is not supported yet; use the service principal setup paths when Cost Management exports are required.
  6. Return to Spotto and run the scan again.

GDAP Daily Scans Stopped

Likely causes:

  • The customer terminated the GDAP relationship.
  • The relationship expired.
  • The partner security group assignment was removed.
  • Microsoft revoked the refresh token or the partner profile needs reauthorization.

Fix:

  1. Confirm the relationship is still active in Partner Center.
  2. Confirm the access assignment is still active.
  3. Reauthorize the Spotto partner profile from the MSP root company.
  4. Run the customer cloud account scan again.

Monitoring Or Log-Backed Data Is Missing

Likely causes:

  • Monitoring Reader has not been assigned.
  • Log Analytics Reader has not been assigned.
  • Azure role assignments have not propagated.

Fix:

  1. Assign Monitoring Reader on relevant subscriptions.
  2. Assign Log Analytics Reader on relevant subscriptions, workspaces, or the root management group.
  3. Wait 5-10 minutes.
  4. Refresh the affected Spotto view or run sync again.

Billing Data Is Missing Or Incomplete

Likely causes:

  • Cost Management exports were not created for each subscription.
  • The exports are not daily actual/amortized cost exports.
  • Spotto does not have Storage Blob Data Reader on the export container.
  • The storage account network settings block Azure Cost Management export writes or Spotto's authenticated reads.
  • CSP Azure Usage visibility is disabled by the partner.
  • Azure Cost Management has not generated export files yet.

Fix:

  1. Confirm billing exports are configured for each subscription.
  2. Confirm the export container is private and reachable by Azure Cost Management.
  3. Confirm the Spotto service principal has Storage Blob Data Reader on the container.
  4. For CSP subscriptions, confirm CSP Billing Prerequisites.
  5. Wait for the next export run or manually run the export in Azure where supported.
  6. Run Spotto sync again.

Governance Or Commitment Data Is Missing

Likely causes:

  • Management Group Reader is missing at the root management group.
  • Reservations Reader is missing.
  • Reservations Contributor is missing for reservation refund quote or management workflows.
  • Savings plan Reader is missing.
  • Microsoft Graph governance admin consent is missing.

Fix:

  1. Review the permission warning matrix.
  2. Assign the missing Azure role or Graph governance permission.
  3. Wait 5-15 minutes.
  4. Run tenant sync again.

Automatic Setup Completed With Warnings

Automatic setup can complete the cloud account while returning warnings for recommended items such as billing exports or Graph consent.

Fix:

  1. Open the Azure cloud account in Spotto.
  2. Review sync diagnostics and setup warnings.
  3. Select Repair Azure Access or Update Azure Access if available.
  4. Run automatic update again, or use the relevant manual permission steps.