Data Connections

Connecting an Azure account

Overview

To connect your Azure environment to DigiUsher, you create an App Registration. It needs read-only access to your cost data, usage data, and resource metadata. This page gives the permissions, the reason for each permission, and the credentials that you enter in DigiUsher.

Supported Agreement Types

Agreement TypeTerraform ExampleNotes
Enterprise Agreement (EA)terraform.tfvars.scenario1-ea-billing-accountBilling data of the whole organization. DigiUsher recommends this type for most enterprises.
EA — Enrollment Accountterraform.tfvars.scenario2-ea-enrollment-accountOne enrollment account of the EA only (billing_scope_level = "enrollment_account").
Microsoft Customer Agreement (MCA)terraform.tfvars.scenario3-mcaA colon (:) in the billing account ID identifies an MCA.
MCA — Invoice Sectionterraform.tfvars.scenario3-mcaThe same file as MCA. Set billing_scope_level = "invoice_section", and also billing_profile_id and invoice_section_id.

Summary of Access Required

ComponentDetails
IdentityAzure App Registration (DigiUsherApp). It is a service principal, without an interactive login
AuthenticationClient secret. DigiUsher recommends an expiry of 24 months
Access levelRead-only. The Reader role at the level of the Management Group
ScopeAll subscriptions under the root Management Group
BillingFOCUS cost export from your billing scope: EA, MCA, or MPA
Data accessStorage Blob Data Reader on the cost export storage account only
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsReservation and Savings Plan analysis, idle resource cleanup
Utilization metricsResource usage for rightsizing analysis

DigiUsher cannot create, change, or delete an Azure resource. The only exception is the optional Terraform flag enable_power_scheduler, which is off by default. This flag creates a custom role that can start and deallocate virtual machines.

Use Terraform for the fastest setup

DigiUsher recommends the Terraform configuration. It does the full setup, and it makes the maintenance simpler.

Terraform Repository: https://github.com/digiusher/digiusher-iac/

If the policies of your organization need a setup by hand, use the manual steps on this page.


Prerequisites

Information to Gather

ItemHow to Find
Tenant IDAzure Portal > Microsoft Entra ID > Overview
Billing Account IDCost Management + Billing > Billing scopes
Subscription IDA subscription to host the storage account for cost exports

Roles Required by the Person Performing Setup

RoleWhy
Global Administrator or Application AdministratorTo create the App Registration and assign IAM roles
Enterprise Administrator (EA) or Billing account owner (MCA)To assign billing roles and create cost exports at billing scope
Subscription OwnerTo create storage resources for cost exports

If you do not know whether you have these billing roles, or at which level, read Check Your Permission Level.

Check Your Permission Level

DigiUsher reads the cost data from a FOCUS export at your billing scope. For the data of the whole organization, create the export at the top-level billing scope. This scope is the EA billing account, which Azure calls the enrollment, or the MCA billing account.

Azure also lets you create an export at a lower scope, such as an EA enrollment account, an MCA billing profile, an invoice section, or one subscription. An export at a lower scope contains the spend of that scope only, and Azure gives no warning. Before you start, make sure that you know the level of your billing access.

1. Identify your agreement type

  1. Go to Cost Management + Billing → Billing scopes.
  2. Read the column Billing account type:
    • Enterprise Agreement: use the EA steps on this page.
    • Microsoft Customer Agreement: use the MCA steps on this page.
    • Microsoft Online Services Program, which is pay-as-you-go: DigiUsher does not support it. A FOCUS export needs EA or MCA.

You can also use the Azure CLI:

az billing account list --query "[].{Name:displayName, ID:name, Type:agreementType}" -o table

Quick tell

An MCA billing account ID contains a colon (:), for example da605be5-...:a04cc649-..._2019-05-31. An EA enrollment number is a plain number, for example 123456.

2. Check your role and its scope

  1. Go to Cost Management + Billing → Billing scopes and select your EA billing account.
  2. Open Access control (IAM) and find your user.
  • Top level, which you need: Enterprise Administrator on the billing account, which Azure calls the enrollment. With this role you can give the billing role Cost Management Contributor to DigiUsherApp, and you can create an export for all subscriptions.
  • Lower level: Department Administrator or Account Owner. You can create exports and give roles inside that department or enrollment account only. The export therefore contains those subscriptions only.
  • No enrollment access: if Billing scopes shows subscriptions only, and no EA billing account, you have no access at the level of the enrollment. Ask your Enterprise Administrator.

What if I only have lower-level access?

You can connect at a lower scope. The types EA — Enrollment Account and MCA — Invoice Section in Supported Agreement Types do this. The cost export then contains the spend of that scope only, and DigiUsher does not see the rest of your organization. For the data of the whole organization, ask your Enterprise Administrator on EA, or your Billing account owner on MCA. That person can do the setup, or give you the top-level access.

Network & Email Access (For Regulated Environments)

If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:

  • Domain allowlist. Add *.digiusher.com to the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers.
  • Email allowlist. Add digiusher.com as a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from @digiusher.com addresses.

The DigiUsher Terraform configuration does the full setup.

git clone https://github.com/digiusher/digiusher-iac.git
cd digiusher-iac/azure

Copy the example file of your agreement type. The section Supported Agreement Types gives the file names:

# Pick ONE of the following:
cp terraform.tfvars.scenario1-ea-billing-account terraform.tfvars     # EA — Billing Account
cp terraform.tfvars.scenario2-ea-enrollment-account terraform.tfvars  # EA — Enrollment Account
cp terraform.tfvars.scenario3-mca terraform.tfvars                    # MCA — Billing Account or Invoice Section

# Edit terraform.tfvars with your values.
# For an MCA invoice section, set billing_scope_level = "invoice_section"
# and fill in billing_profile_id and invoice_section_id.
terraform init
terraform plan
terraform apply

Terraform Feature Flags

VariableDefaultDescription
enable_cost_exportstrueCreates the storage account, the container, and the FOCUS cost export
enable_reservations_accesstrueGives Reservations Reader and Savings Plan Reader at the level of the tenant
target_subscription_ids[] (all)Limits the Reader role to selected subscriptions, in place of the root Management Group
enable_power_schedulerfalseCreates the custom role DigiUsher Power Scheduler. This role can start and deallocate virtual machines (Microsoft.Compute/virtualMachines/start/action, deallocate/action, and read). It is the only write access of the configuration. Keep it off when you do not use the power scheduling of virtual machines.

The digiusher-iac README is the full Terraform documentation. It gives all parameters and the troubleshooting steps.


Option B: Manual Setup

Note

The manual steps on this page are the Enterprise Agreement (EA) setup in the Azure Portal. For MCA, for MPA and CSP, and for the other billing types, use the Terraform option.

Use these steps for a setup in the Azure Portal.

Create App Registration

  1. Go to Azure Portal → Microsoft Entra ID → App registrations
  2. Click New registration
  3. Configure:
    • Name: DigiUsherApp
    • Supported account types: "Accounts in this organizational directory only"
  4. Click Register
  5. Note down:
    • Application (client) ID
    • Directory (tenant) ID

Azure App Registration overview page Azure App Registration details with Client and Tenant IDs

Create Client Secret

  1. In your app registration, go to Certificates & secrets
  2. Click New client secret
  3. Configure:
    • Description: DigiUsher secret
    • Expires: 24 months (recommended)
  4. Click Add
  5. Copy the Value immediately. Azure does not show it again.

Azure client secret creation

Assign Reader Role

  1. Go to Management Groups → Select your root management group
  2. Click Access Control (IAM) → Add → Add role assignment
  3. Configure:
    • Role: Reader
    • Members: Search for and select DigiUsherApp
  4. Click Review + assign

Note

A role at the level of the Management Group covers the subscriptions of today and every new subscription.

Azure Reader role assignment at Management Group level

Create Storage Account for Exports

4a. Create Resource Group

  1. Go to Resource Groups → Create
  2. Configure:
    • Name: digiusher-billing-exports
    • Region: East US, or another region
  3. Click Review + create → Create

4b. Create Storage Account

  1. Go to Storage accounts → Create
  2. On the Basics tab:
    • Resource group: digiusher-billing-exports
    • Storage account name: a unique name with lowercase letters and digits only, for example digiusherexports<yourcompany>
    • Region: Same as resource group
    • Performance: Standard
    • Redundancy: LRS (Locally-redundant storage)
  3. On the Networking tab:
    • Public network access: Enable
    • Public network access scope: Enable from all networks
  4. Click Review + create → Create

4c. Create Container

  1. Open your new storage account
  2. Go to Containers → + Container
  3. Configure:
    • Name: digiusher-focus-exports
    • Anonymous access level: Private (no anonymous access)
  4. Click Create

4d. Grant Storage Access

  1. On the storage account, go to Access Control (IAM) → Add → Add role assignment
  2. Configure:
    • Role: Storage Blob Data Reader
    • Members: Search for and select DigiUsherApp
  3. Click Review + assign

Create FOCUS Cost Export

  1. Go to Cost Management + Billing → Exports
  2. Make sure that you are at the Billing Account scope, and not at a subscription scope
  3. Click Add
  4. Select FOCUS cost and usage (preview)

Azure FOCUS cost export type selection

  1. Configure:
    • Export name: digiusher-focus-export
    • Frequency: Daily export of month-to-date costs
    • Dataset version: 1.2-preview
    • File format: Parquet
    • Compression: Snappy
    • Export directory/path: focus
    • Storage account: Select the account created in Step 4
    • Container: digiusher-focus-exports
  2. Click Create

Note

The first export runs in the next 24 hours. To start it immediately, click "Run now".

Azure FOCUS export configuration

Azure FOCUS export creation confirmation

Backfill historical data

  1. Go to Cost Management → Exports → select your export
  2. Click Export selected dates
  3. Run the export for each of the last 3 months, one month at a time.
    • For a large account, wait until one export finishes before you start the next month.

Azure export selected dates for backfill

(Optional) Reservations & Savings Plans Access

For the roles at the level of the tenant, you need elevated access for a short time.

6a. Enable Elevated Access

  1. Go to Azure Portal → Microsoft Entra ID → Properties

Azure Entra ID Properties page

  1. Scroll to Access management for Azure resources
  2. Toggle to Yes

Azure elevated access toggle

  1. Click Save

6b. Assign Reservations Reader

  1. Go to Reservations → Access Control (IAM) → Add role assignment
  2. Configure:
    • Role: Reservations Reader
    • Members: DigiUsherApp
  3. Click Review + assign

6c. Assign Savings Plan Reader

  1. Do the same steps again with the role Savings Plan Reader.

6d. Disable Elevated Access

  1. Go back to Microsoft Entra ID → Properties
  2. Toggle Access management for Azure resources to No
  3. Click Save

Important

CAUTION: Disable the elevated access after you give these roles. Elevated access gives you rights on every resource of the tenant.


Connect in DigiUsher

After you complete the Terraform setup or the manual setup, go to Connectors > Add Source and select Microsoft Azure. On the Configure step, enter the values in the table, then click Review. On the Connect step, click Connect source.

If you use Terraform, one output gives all values:

terraform output -json digiusher_onboarding
FieldWhere to Find
Display NameAny label you prefer (for example Azure Production)
Tenant IDAzure Portal > Microsoft Entra ID > Overview, or tenant_id in the Terraform output
Application (Client) IDApp Registration > Overview, or application_id in the Terraform output
Client SecretThe secret from the App Registration setup, or client_secret in the Terraform output
Storage Account NameThe storage account of the exports, or storage_account_name in the Terraform output
Container NameThe container in the storage account (for example digiusher-focus-exports), or storage_container_name in the Terraform output
Export Root PathThe path of the FOCUS export (for example focus), or export_root_path in the Terraform output
SAS Token (optional)A SAS token of the storage account. With this token, DigiUsher reads the blob storage with the token in place of the App Registration credentials.

Setup Checklist

  • Top-level billing access confirmed (EA: Enterprise Administrator, MCA: Billing account owner), or you accept the data of a lower scope
  • App registration created, with a client secret
  • Reader role given at the level of the Management Group or the Subscription
  • Storage account and container created
  • Storage Blob Data Reader role given on the storage account
  • FOCUS export created and scheduled
  • Reservations Reader and Savings Plan Reader given (optional)
  • Elevated access disabled again (if you used it)
  • *.digiusher.com in the allowlist of the network and the firewall (if your organization restricts this)
  • digiusher.com in the allowlist for incoming email (if your organization restricts this)

Security

What DigiUsher CAN Access (Read-Only)

  • The cost data and the usage data in the FOCUS exports in Azure Storage
  • The resource metadata, such as names, types, regions, and tags, through the Reader role
  • The information about the Reservations and the Savings Plans, when you give that optional access
  • The hierarchy of the Management Groups, the subscriptions, and the resource groups

What DigiUsher CANNOT Do

  • Create, change, or delete an Azure resource
  • Read application data, databases, or the content of your storage. It reads the cost exports only
  • Change an IAM policy or a role assignment
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration

Monitoring

To monitor the activity of the App Registration, open Microsoft Entra ID > Enterprise applications > DigiUsherApp > Sign-in logs and Audit logs.

Credential Rotation

  • With Terraform, run terraform apply -replace="azuread_application_password.app_password". Then read the new secret with terraform output -json digiusher_onboarding, and enter it in the DigiUsher platform.
  • By hand, open the App Registration and click Certificates & secrets > New client secret to create a new secret. Then delete the old secret, and enter the new secret in the DigiUsher platform.

Revocation

  • With Terraform, run terraform destroy. It removes the App Registration and all role assignments, and it invalidates the client secret.
  • By hand, delete the App Registration DigiUsherApp in Microsoft Entra ID > App registrations. Azure then immediately invalidates the client secret and all its role assignments.

Troubleshooting

Export not appearing

  • Make sure that the resource provider Microsoft.CostManagementExports is registered.
  • Go to Subscription → Resource providers, search for CostManagementExports, and click Register.

Permission denied on billing scope

  • On EA, make sure that you have Enterprise Administrator access at the level of the billing account, which Azure calls the enrollment. Read Check Your Permission Level. In some EA accounts, the enrollment admin must give this access in the EA Portal first.
  • On MCA, make sure that you have Billing account owner access on the billing account itself, and not on a billing profile or an invoice section. Read Check Your Permission Level. MCA uses its own billing RBAC system, and a standard ARM role such as Cost Management Contributor does not work there. The Terraform configuration does this correctly.

Cannot see Management Groups

  • Go to Management Groups → Start using management groups.
  • To see the root group of the tenant, you can need the elevated access from Step 6a.

Need Help?

If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.

On this page