It adds the nOps.io enterprise application (a service principal) to your Microsoft Entra ID tenant. It also approves the app’s permissions for your whole organization, so no one else is asked to approve them.Microsoft’s consent screen shows the app nOps.io from nOps Inc (a verified publisher). It lists these permissions:
Permission
What Microsoft says it allows
Access Azure Resource Manager as organization users
Allows the application to access Azure Resource Manager acting as users in the organization
Read directory data
Allows the app to read data in your organization’s directory, such as users, groups and apps
Sign in and read user profile
Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users
The screen also says that if you accept, the app gets access to the specified resources for all users in your organization, and no one else will be prompted to review these permissions.Consent by itself gives nOps no access to your subscriptions, billing, or storage. nOps only gets Azure access from the roles you assign in Run the Setup.nOps never signs in as your users. When Microsoft sends you back to nOps, nOps only learns your tenant ID and whether you accepted. After that, nOps connects with the app’s own identity, using only the roles you assign.You need Global Administrator or Privileged Role Administrator to grant consent. To stop nOps’s access later, delete or disable the nOps.io enterprise application in Microsoft Entra ID → Enterprise applications. You can also remove the role assignments you made during setup.
Why does nOps need Reader on the management group?
A role you assign on a management group applies to every subscription under it, including subscriptions you add later. With Reader there, nOps can see all your subscriptions and their resources, with no setup on each subscription.Reader is read-only. nOps can’t create, change, or delete anything. It can’t read data inside storage accounts, and it can’t read Key Vault secrets.To cover everything, use your tenant root management group. Its ID is your tenant ID.
Why does nOps need a reader role at the billing account level?
You create the FOCUS export at your billing account (MCA) or enrollment (EA). nOps uses Billing account reader (MCA) or EnrollmentReader (EA) to find your billing account and billing profiles, and to check that the FOCUS export exists and runs.These roles are read-only. nOps can’t change billing settings or make purchases. For MCA, one assignment at the billing account covers every billing profile, including profiles you add later.
Should I connect the billing account or specific billing profiles?
We recommend the billing account. One Billing account reader assignment covers every billing profile, including profiles you add later, and you only need one FOCUS export.Choose billing profiles only if your organization gives access per billing profile. In that case:
You need a Billing profile owner for each profile.
Each profile needs its own FOCUS export.
Billing profiles you don’t add aren’t included in Savings Analysis.
Billing profiles apply to MCA only. EA always connects at the enrollment.
I'm a Global Administrator. Can I do the billing steps myself?
MCA: Yes. First, give yourself Billing account owner. In Cost Management + Billing, open Billing scopes, select the box to view all billing accounts, and open your billing account. Then go to Access control (IAM) → Add, choose Billing account owner, and add yourself. Microsoft explains this in Elevate access to manage billing accounts.
EA: No. A Global Administrator can’t give themselves EA billing roles. An Enterprise Administrator has to do the EA billing steps.
My billing account has some billing profiles from a CSP partner and some that are MCA. Does that change onboarding?
No. The setup steps are the same. A mix of CSP and MCA billing profiles under your billing account doesn’t change anything in onboarding.You still need a billing account of your own (EA or MCA). Tenants billed only through a CSP partner aren’t supported.
Why does nOps use FOCUS exports?
FOCUS (FinOps Open Cost and Usage Specification) is an open standard format for cost data. Azure writes a daily FOCUS export to a storage account you own, and nOps reads those files.One export at the billing account covers every subscription and billing profile in it. It includes amortized costs for reservations and savings plans, and the discounts you receive. The files stay in your storage account, and you control them.
Why does nOps need roles for the usage (FOCUS) export?
There are two sides:
The person who sets up the export needs a billing role at the billing scope, because that’s where the export is created. They also need rights to create a storage account in the export subscription, such as Owner or Contributor.
nOps needs the billing reader role to find the export and check that it runs daily. It also needs Storage Blob Data Owner on that one storage account to read the export files.
The storage role applies only to that storage account, which only holds the export files.
What resources do I create during setup?
You create these yourself in the Azure portal, in Step C. nOps doesn’t create them.
A resource group named nops-focus-exports-rg
A storage account named nopsfocus + the first 15 characters of your tenant ID (without dashes), with a container named focus-exports
A FOCUS cost export with the prefix nops-clara, at your billing account (MCA), your enrollment (EA), or each billing profile you connect
You choose the region when you create the storage account. These resources cost only the storage for the export files.
Can I use an existing storage account instead?
No. Create the new storage account the wizard names in Step C. A dedicated storage account keeps the export files on their own, and the Storage Blob Data Owner role you give nOps.io applies to that storage account only.
What if my organization restricts storage account network access?
If your organization uses Azure Policy to enforce storage account firewalls, allow the nOps IP addresses on the FOCUS export storage account.
Go to the storage account > Security + networking > Networking
Under Firewall, add the nOps IP addresses: 44.246.45.84, 52.11.53.164, and 52.39.155.200
Make sure “Allow Azure services on the trusted services list” is checked
Click Save
How often is billing data refreshed?
FOCUS cost exports run daily. Cost data is typically available within 24-48 hours of the export run. Your first Run now includes the current month, and the backfill runs in Step C add the previous three months.
How long does it take for Azure role assignments to propagate?
Azure role assignments typically take 2-5 minutes to take effect. In some cases, it can take up to 10 minutes. If verification fails right after you finish setup, wait a few minutes and try again.
Supported Billing Account Types: nOps supports Enterprise Agreement (EA) and Microsoft Customer Agreement (MCA) billing accounts only. If you have a Pay-As-You-Go (MOSP) subscription, please contact your Microsoft account representative to upgrade to an EA or MCA billing account before proceeding.
Savings Analysis does not allow purchasing reservations or savings plans. To enable automated commitment purchasing, complete this setup first, then follow the Commitment Management Setup guide.
EA only: Your EA enrollment number. In Cost Management + Billing, select your EA billing account and copy the Billing account ID from Settings > Properties
Your Management Group ID (or your tenant ID, to cover every subscription)
A subscription to hold the storage account for the FOCUS export
The three roles listed under Required access. Different people often hold them, so you may need help from other teams
The nOps Azure Savings Analysis wizard has 4 steps:
Get Started — Name your integration, pick your billing account type, and confirm your team has the required access
Grant Admin Consent — Add the nOps.io app to your Microsoft Entra ID tenant
Run Setup — Assign roles and create the FOCUS cost export in the Azure portal (Steps A–D)
Before you begin: make sure your organization has its own EA or MCA billing account. Tenants billed only through a CSP partner aren’t supported. The wizard’s Before you begin box shows how to run Microsoft’s CSP eligibility check. You can also run the nOps onboarding qualifier, a read-only script that classifies each billing account (EA / MCA / Reseller / CSP) and gives a PASS / FAIL verdict.
Provide a friendly name for this integration (e.g., “Production Azure Environment”). This name helps you identify the integration in the nOps dashboard.
3
Select Your Billing Account Type
Choose EA (Enterprise Agreement) or MCA (Microsoft Customer Agreement). This decides which billing steps you follow later.If you are unsure which type you have, see Understanding Billing Account Types.
4
Enter Your EA Enrollment Number (EA only)
If you selected EA, enter your EA enrollment number. You need it to continue.Find it in Azure Portal > Cost Management + Billing: select your EA billing account and copy the Billing account ID from Settings > Properties. For an EA, this is your numeric enrollment number. MCA users skip this step.
5
Check the Required Access List
The wizard lists the three roles your team needs (described in Required access below). Tick each one you have, or know who has. You can continue once all three are ticked.
nOps gets:Billing account reader (MCA), Billing profile reader on each selected profile, or EnrollmentReader (EA), plus a FOCUS export at that billing scope
Owner (an Azure RBAC role) on the management group and on the export subscription
nOps gets:Reader on the management group and Storage Blob Data Owner on the export storage account
User Access Administrator can do the role assignments in Steps B and D but can’t create the storage account in Step C, so pair it with Contributor on the export subscription
MCA: billing account or billing profilesBy default, the wizard shows nOps connects at your billing account (recommended). If you only have access to specific billing profiles, click Only have access to specific billing profiles? and then Connect billing profiles instead. You’ll need a Billing profile owner for each profile, and each profile gets its own FOCUS export. To switch back, click Use the billing account instead (recommended).EA always connects at the enrollment, so there’s no billing profile option.
MCA: are you a Global Administrator? You can give yourself Billing account owner first. In Cost Management + Billing, open Billing scopes, select the box to view all billing accounts, and open your billing account. Then go to Access control (IAM) → Add → Billing account owner, and add yourself. See Microsoft’s guide, Elevate access to manage billing accounts.This doesn’t work for EA. An Enterprise Administrator has to do the EA billing steps.
Admin consent adds the nOps.io enterprise application (a service principal) to your Microsoft Entra ID tenant. You need to do this before you can assign any roles to nOps.
1
Click Grant Admin Consent
In the nOps wizard, click the Grant Admin Consent button. Microsoft’s sign-in page opens.
2
Sign In with an Admin Account
Sign in with an account that has the Global Administrator or Privileged Role Administrator role in Microsoft Entra ID.
3
Review and Accept Permissions
Microsoft shows the app nOps.io from nOps Inc (a verified publisher) and the permissions it asks for. Review them and click Accept.
4
Return to nOps
Microsoft sends you back to the nOps wizard. Your Azure Tenant ID now shows, which confirms that consent was granted.
Consent adds the nOps.io enterprise application to your tenant and approves its permissions for your whole organization, so no one else is asked to approve them. For the full list of permissions, see What does Grant Admin Consent do? in the FAQs.
Consent by itself gives nOps no access to your subscriptions, billing, or storage. nOps only gets Azure access from the roles you assign in Run the Setup.
nOps never signs in as your users. It connects with the app’s own identity, using only the roles you assign.
What is an enterprise application? It’s how an app from another organization appears in your Microsoft Entra ID tenant. It’s also called a service principal. Consent adds it to your tenant. It isn’t an app registration: the nOps app registration lives in nOps’s own tenant, not yours.
Don’t delete the nOps.io enterprise application after you grant consent. If you delete it, nOps loses access and you’ll need to grant admin consent again from the wizard.
You do this part in the Azure portal. It has four parts, A to D. Only the EA billing role in Step A needs the Azure CLI.
The nOps wizard walks you through the same steps (labeled A through D), with your own values filled in. Follow along in the wizard or use the steps below.
Step
What you do
Why nOps needs it
A. Billing role
Give nOps.io a billing reader role
To find your billing account and billing profiles, and check your FOCUS export
B. Reader
Give nOps.io Reader on your management group
To see your subscriptions and their resources
C. FOCUS cost export
Create a daily FOCUS cost export and its storage account
So Azure writes your cost data to a storage account you own
D. Storage Blob Data Owner
Give nOps.io Storage Blob Data Owner on that storage account
Follow only the tab that matches your billing account type and how you connect it.
MCA: billing account (recommended)
MCA: billing profiles
Enterprise Agreement (EA)
You need Billing account owner on the MCA billing account. Azure RBAC Owner doesn’t include billing roles. If you’re a Global Administrator, you can give yourself Billing account owner first (see the tip under Required access). If you can’t, ask your Billing account owner to do this step. To see who holds this role, go to Cost Management + Billing → select your billing account → Access control (IAM).
1
Open Your Billing Account
Go to Cost Management + Billing in the Azure portal and select your Microsoft Customer Agreement billing account.
2
Assign Billing account reader
Click Access control (IAM) in the left menu.
Click Add at the top.
Select the role Billing account reader.
Search for “nOps.io” and select it.
Click Review + assign (or Save).
Use this tab only if your organization gives access per billing profile. Billing profiles you don’t add aren’t included in Savings Analysis.
You need Billing profile owner on each billing profile you add. If you don’t have it, ask the Billing profile owner of that profile to do this step.
1
Enter Your Billing Account and Billing Profile IDs
In the nOps wizard, enter your billing account ID and the billing profile ID of each profile you want to connect.
Billing profile ID: open Billing profiles → select the profile → Properties
2
Assign Billing profile reader on Each Profile
Do this on each billing profile you entered:
In Cost Management + Billing, open your billing account → Billing profiles → select the profile.
Click Access control (IAM) → Add.
Select the role Billing profile reader.
Search for “nOps.io” and select it.
Click Review + assign (or Save).
You must be an Enterprise Administrator on the EA enrollment to complete this step. Microsoft requires enrollment write access to assign EnrollmentReader to a service principal, so Enterprise Administrator (read only), Department Administrator, and Account Owner cannot do it. Global Administrator and Azure RBAC Owner don’t include EA billing roles, and a Global Administrator can’t give themselves one. If you don’t have this role, ask an Enterprise Administrator to run the script below. Check who holds it in Cost Management + Billing → select your EA billing account → Access control (IAM).
Microsoft only supports assigning EA billing roles (such as EnrollmentReader) to a service principal through the REST API, not the Azure portal. Run the script below in Azure Cloud Shell (Bash, not PowerShell) or a local terminal with the Azure CLI installed. You run this script yourself. nOps doesn’t assign billing roles.
1
Sign in to Azure CLI
Open Azure Cloud Shell (Bash) or run az login in your local terminal.
2
Run the EnrollmentReader assignment script
Copy and run the following script. Replace <app-client-id>, <enrollment-number>, and <tenant-id> with your values (the nOps wizard pre-fills these in its generated script):
# Assign EnrollmentReader role to nOps service principal# Run in Azure Cloud Shell (Bash, not PowerShell) or a local terminal with Azure CLINOPS_APP_CLIENT_ID="<app-client-id>"# Look up the nOps service principal Object IDNOPS_SP_OBJECT_ID=$(az ad sp show --id "$NOPS_APP_CLIENT_ID" --query "id" -o tsv 2>/dev/null || true)if [ -z "$NOPS_SP_OBJECT_ID" ]; then echo "ERROR: nOps service principal not found. Complete the Admin Consent step first." exit 1fiecho "Found nOps service principal: $NOPS_SP_OBJECT_ID"ROLE_ASSIGNMENT_GUID=$(uuidgen 2>/dev/null || cat /proc/sys/kernel/random/uuid)az rest --method PUT \ --url "https://management.azure.com/providers/Microsoft.Billing/billingAccounts/<enrollment-number>/billingRoleAssignments/${ROLE_ASSIGNMENT_GUID}?api-version=2024-04-01" \ --body '{ "properties": { "principalId": "'"$NOPS_SP_OBJECT_ID"'", "principalTenantId": "<tenant-id>", "roleDefinitionId": "/providers/Microsoft.Billing/billingAccounts/<enrollment-number>/billingRoleDefinitions/24f8edb6-1668-4659-b5e2-40bb5f3a7d7e" } }'echo "Done. A 200 OK response confirms the EnrollmentReader role was assigned."
The nOps wizard generates a ready-to-run script with all values pre-filled (App Client ID, enrollment number, and tenant ID). Copy it directly from the wizard for the easiest experience.
Fallback: If az ad sp show fails, you can find the service principal manually: az ad sp list --filter "startswith(displayName, 'nops')" --query "[].{name:displayName, objectId:id}" -o table and use the objectId value.
A 200 OK response confirms the role was assigned. Service principal role assignments on an EA enrollment are not shown in the Azure portal, so use the nOps Verify step to confirm access. If you have more than one EA billing account, repeat the script for each enrollment.
Assign Reader on the management group that holds the subscriptions you want in Savings Analysis. You need Owner or User Access Administrator on that management group.
1
Enter Your Management Group ID
In the nOps wizard, enter the Management Group ID. To cover every subscription, click Use tenant root. Your tenant ID is the ID of the root management group.Find your management groups in Azure Portal > Management Groups.
2
Open the Management Group
Go to Management Groups in the Azure portal and select the management group.
3
Open Access Control
Click Access control (IAM) in the left menu, then click Add > Add role assignment.
4
Select the Role
On the Role tab, search for and select Reader, then click Next.
5
Assign to nOps.io
On the Members tab, set “Assign access to” to “User, group, or service principal” (not “Managed identity”).
Click ”+ Select members”.
Search for “nOps.io” by name and select it.
Click Select.
Click Review + assign.
Repeat only if your subscriptions are split across separate management groups.
In the nOps wizard, enter the subscription that will hold the export’s storage account. Choose the subscription with the most spend.To create the storage account, you need Owner or Contributor on this subscription.
2
Register Resource Providers
Make sure these resource providers are registered on that subscription: Microsoft.Storage, Microsoft.CostManagement, and Microsoft.CostManagementExports.Go to Subscriptions → select the subscription → Settings → Resource providers, and click Register on any that aren’t registered. Most subscriptions already have these registered. If a provider already shows “Registered”, no action is needed.
3
Open Exports and Set the Scope
Go to Cost Management > Exports in the Azure portal. At the top, click Change scope if needed, and select:
MCA billing account: your Microsoft Customer Agreement billing account
EA: your EA enrollment (the same enrollment number you entered in the nOps wizard, e.g., 12345678)
MCA billing profiles: one of your billing profiles. You’ll create a separate export for each profile
4
Create the Export
Click + Create.
Basics tab: Select the “Cost and usage (FOCUS)” template.
Datasets tab: Set the export prefix to nops-clara. The template sets the frequency to Daily.
MCA billing profiles only: use the prefix the nOps wizard shows for that profile. It’s nops-clara- followed by letters and digits from the billing profile ID, in lowercase. This keeps the exports from overwriting each other.
Destination tab:
Storage type: Azure blob storage
Subscription: the subscription you entered in the nOps wizard
Storage account: Click Create new
Resource group: create a new one named nops-focus-exports-rg
Name: nopsfocus + the first 15 characters of your tenant ID, without dashes
Region: any region you choose
Container: focus-exports
Directory: nops-clara
Format: Parquet
Compression type: Snappy
File partitioning: checked
Overwrite data: checked
Click Review + create, then Create.
5
Run the Export and Backfill 3 Months
Open the export and click Run now to trigger the first export.
Click Export selected dates to backfill the previous 3 months, one run per month:
Run 1: Start date = first day of three months ago, End date = last day of three months ago
Run 2: Start date = first day of two months ago, End date = last day of two months ago
Run 3: Start date = first day of previous month, End date = last day of previous month
Data will be available within a few hours.
MCA billing profiles: repeat these export steps for each billing profile you connect, with that profile’s prefix. After the first profile, select the storage account you already created instead of creating a new one.
The nOps wizard shows the exact storage account name, resource group, container, and directory you need. Copy these values from the wizard so they match what nOps checks in Verify.
You must be an Owner or User Access Administrator on the storage account to assign Storage Blob Data Owner.
1
Open the Storage Account
Search for “Storage accounts” in the Azure portal’s top search bar, then select the storage account you created in Step C (e.g., nopsfocus<tenant-prefix>).
2
Assign Storage Blob Data Owner
Go to Access control (IAM) → Add → Add role assignment.
Under Job function roles, select Storage Blob Data Owner.
Select User, group, or service principal.
Search for and select nOps.io.
Click Review + assign.
3
Configure Firewall (if applicable)
If your organization restricts storage account network access (through Azure Policy or manual settings):
Go to the storage account > Security + networking > Networking
Under Firewall, add the nOps IP addresses: 44.246.45.84, 52.11.53.164, and 52.39.155.200
Make sure “Allow Azure services on the trusted services list” is checked
Click Save
Skip this step if your storage account allows public network access (the default). nOps reads the export files from outside Azure, so if a firewall is on, it must allow the nOps IP addresses.
Azure role assignments can take 2-5 minutes to propagate. If verification fails right after you assign roles, wait a few minutes and try again.
nOps checks that each part of the setup is in place.
1
Click Verify Permissions
Click the Verify Permissions button. nOps checks:
Reader — nOps can list your subscriptions
Billing role — nOps has Billing account reader (MCA), Billing profile reader (MCA billing profiles), or EnrollmentReader (EA)
FOCUS export — a FOCUS export exists at the right billing scope
Storage Blob Data Owner — nOps can list the export container
If you connected billing profiles, nOps checks Billing profile reader and a FOCUS export on each profile. It skips a profile’s export check until that profile’s billing role is in place.
2
Review Results
The wizard shows a pass or fail result for each check. When they all pass, you’ll see “Savings Analysis Verified” with the number of connected subscriptions.
Verification Failed? — If some checks don’t pass yet:
Wait a few more minutes. Azure role assignments can take time to propagate
Check that each role was assigned to nOps.io at the right scope: the billing role (Step A), Reader on the management group (Step B), and Storage Blob Data Owner on the storage account (Step D)
Check that the FOCUS export exists at your billing account, enrollment, or each billing profile you connected (Step C)
Once the Savings Analysis integration is verified, nOps begins ingesting your cost data and generating optimization recommendations.To enable automated purchasing and management of Azure Reservations and Savings Plans, you can upgrade your integration to the Commitment Management tier:
Azure Commitment Management Setup
Configure nOps to manage Azure Reservations and Savings Plans on your behalf, including automated purchasing and optimization.