Skip to main content

FAQs

A role you assign on a management group applies to every subscription under it, including subscriptions you add later. With Reader there, nOps can see all your subscriptions and their resources, with no setup on each subscription.Reader is read-only. nOps can’t create, change, or delete anything. It can’t read data inside storage accounts, and it can’t read Key Vault secrets.To cover everything, use your tenant root management group. Its ID is your tenant ID.
You create the FOCUS export at your billing account (MCA) or enrollment (EA). nOps uses Billing account reader (MCA) or EnrollmentReader (EA) to find your billing account and billing profiles, and to check that the FOCUS export exists and runs.These roles are read-only. nOps can’t change billing settings or make purchases. For MCA, one assignment at the billing account covers every billing profile, including profiles you add later.
We recommend the billing account. One Billing account reader assignment covers every billing profile, including profiles you add later, and you only need one FOCUS export.Choose billing profiles only if your organization gives access per billing profile. In that case:
  • You need a Billing profile owner for each profile.
  • Each profile needs its own FOCUS export.
  • Billing profiles you don’t add aren’t included in Savings Analysis.
Billing profiles apply to MCA only. EA always connects at the enrollment.
  • MCA: Yes. First, give yourself Billing account owner. In Cost Management + Billing, open Billing scopes, select the box to view all billing accounts, and open your billing account. Then go to Access control (IAM) → Add, choose Billing account owner, and add yourself. Microsoft explains this in Elevate access to manage billing accounts.
  • EA: No. A Global Administrator can’t give themselves EA billing roles. An Enterprise Administrator has to do the EA billing steps.
No. The setup steps are the same. A mix of CSP and MCA billing profiles under your billing account doesn’t change anything in onboarding.You still need a billing account of your own (EA or MCA). Tenants billed only through a CSP partner aren’t supported.
FOCUS (FinOps Open Cost and Usage Specification) is an open standard format for cost data. Azure writes a daily FOCUS export to a storage account you own, and nOps reads those files.One export at the billing account covers every subscription and billing profile in it. It includes amortized costs for reservations and savings plans, and the discounts you receive. The files stay in your storage account, and you control them.
There are two sides:
  • The person who sets up the export needs a billing role at the billing scope, because that’s where the export is created. They also need rights to create a storage account in the export subscription, such as Owner or Contributor.
  • nOps needs the billing reader role to find the export and check that it runs daily. It also needs Storage Blob Data Owner on that one storage account to read the export files.
The storage role applies only to that storage account, which only holds the export files.
You create these yourself in the Azure portal, in Step C. nOps doesn’t create them.
  • A resource group named nops-focus-exports-rg
  • A storage account named nopsfocus + the first 15 characters of your tenant ID (without dashes), with a container named focus-exports
  • A FOCUS cost export with the prefix nops-clara, at your billing account (MCA), your enrollment (EA), or each billing profile you connect
You choose the region when you create the storage account. These resources cost only the storage for the export files.
No. Create the new storage account the wizard names in Step C. A dedicated storage account keeps the export files on their own, and the Storage Blob Data Owner role you give nOps.io applies to that storage account only.
If your organization uses Azure Policy to enforce storage account firewalls, allow the nOps IP addresses on the FOCUS export storage account.
  1. Go to the storage account > Security + networking > Networking
  2. Under Firewall, add the nOps IP addresses: 44.246.45.84, 52.11.53.164, and 52.39.155.200
  3. Make sure “Allow Azure services on the trusted services list” is checked
  4. Click Save
FOCUS cost exports run daily. Cost data is typically available within 24-48 hours of the export run. Your first Run now includes the current month, and the backfill runs in Step C add the previous three months.
Azure role assignments typically take 2-5 minutes to take effect. In some cases, it can take up to 10 minutes. If verification fails right after you finish setup, wait a few minutes and try again.

Overview

Savings Analysis is the first tier of Azure onboarding. It gives nOps read-only access to your Azure environment for:
  • Cost visibility across all subscriptions
  • Resource inventory (VMs, disks, networks)
  • Optimization recommendations (rightsizing, idle resources)
  • Daily FOCUS cost exports for cost tracking
Supported Billing Account Types: nOps supports Enterprise Agreement (EA) and Microsoft Customer Agreement (MCA) billing accounts only. If you have a Pay-As-You-Go (MOSP) subscription, please contact your Microsoft account representative to upgrade to an EA or MCA billing account before proceeding.
Savings Analysis does not allow purchasing reservations or savings plans. To enable automated commitment purchasing, complete this setup first, then follow the Commitment Management Setup guide.
Prerequisites — Before you start, review the Azure Integration Prerequisites. You’ll need:
  • Your billing account type (EA or MCA)
  • EA only: Your EA enrollment number. In Cost Management + Billing, select your EA billing account and copy the Billing account ID from Settings > Properties
  • Your Management Group ID (or your tenant ID, to cover every subscription)
  • A subscription to hold the storage account for the FOCUS export
  • The three roles listed under Required access. Different people often hold them, so you may need help from other teams
The nOps Azure Savings Analysis wizard has 4 steps:
  1. Get Started — Name your integration, pick your billing account type, and confirm your team has the required access
  2. Grant Admin Consent — Add the nOps.io app to your Microsoft Entra ID tenant
  3. Run Setup — Assign roles and create the FOCUS cost export in the Azure portal (Steps A–D)
  4. Verify — nOps checks that everything is in place

1. Get Started

Before you begin: make sure your organization has its own EA or MCA billing account. Tenants billed only through a CSP partner aren’t supported. The wizard’s Before you begin box shows how to run Microsoft’s CSP eligibility check. You can also run the nOps onboarding qualifier, a read-only script that classifies each billing account (EA / MCA / Reseller / CSP) and gives a PASS / FAIL verdict.
1

Open Cloud Provider Integrations

Log in to nOps and go to Settings > Cloud Provider Integrations. Scroll down to the Add a provider section and click the Microsoft Azure card.
2

Enter an Integration Name

Provide a friendly name for this integration (e.g., “Production Azure Environment”). This name helps you identify the integration in the nOps dashboard.
3

Select Your Billing Account Type

Choose EA (Enterprise Agreement) or MCA (Microsoft Customer Agreement). This decides which billing steps you follow later.If you are unsure which type you have, see Understanding Billing Account Types.
4

Enter Your EA Enrollment Number (EA only)

If you selected EA, enter your EA enrollment number. You need it to continue.Find it in Azure Portal > Cost Management + Billing: select your EA billing account and copy the Billing account ID from Settings > Properties. For an EA, this is your numeric enrollment number. MCA users skip this step.
5

Check the Required Access List

The wizard lists the three roles your team needs (described in Required access below). Tick each one you have, or know who has. You can continue once all three are ticked.
6

Click Continue

Click Continue to move on to Grant Admin Consent.

Required Access

Setup needs three roles. Different people often hold them, so check who on your team has each one before you start.
  1. Global Administrator or Privileged Role Administrator (a Microsoft Entra ID role)
    • Used for: Grant Admin Consent
    • nOps gets: its app, the nOps.io enterprise application, in your tenant
  2. A billing role (separate from Microsoft Entra ID roles and Azure RBAC roles)
    • MCA billing account (default): Billing account owner
    • MCA billing profiles option: Billing profile owner on each profile
    • EA: Enterprise Administrator. Enterprise Administrator (read only) can’t do it, and neither can Department Administrator or Account Owner
    • Used for: Run Setup Step A and Step C
    • nOps gets: Billing account reader (MCA), Billing profile reader on each selected profile, or EnrollmentReader (EA), plus a FOCUS export at that billing scope
  3. Owner (an Azure RBAC role) on the management group and on the export subscription
    • Used for: Run Setup Steps B, C, and D
    • nOps gets: Reader on the management group and Storage Blob Data Owner on the export storage account
    • User Access Administrator can do the role assignments in Steps B and D but can’t create the storage account in Step C, so pair it with Contributor on the export subscription
MCA: billing account or billing profiles By default, the wizard shows nOps connects at your billing account (recommended). If you only have access to specific billing profiles, click Only have access to specific billing profiles? and then Connect billing profiles instead. You’ll need a Billing profile owner for each profile, and each profile gets its own FOCUS export. To switch back, click Use the billing account instead (recommended). EA always connects at the enrollment, so there’s no billing profile option.
MCA: are you a Global Administrator? You can give yourself Billing account owner first. In Cost Management + Billing, open Billing scopes, select the box to view all billing accounts, and open your billing account. Then go to Access control (IAM) → Add → Billing account owner, and add yourself. See Microsoft’s guide, Elevate access to manage billing accounts.This doesn’t work for EA. An Enterprise Administrator has to do the EA billing steps.

Admin consent adds the nOps.io enterprise application (a service principal) to your Microsoft Entra ID tenant. You need to do this before you can assign any roles to nOps.
1

Click Grant Admin Consent

In the nOps wizard, click the Grant Admin Consent button. Microsoft’s sign-in page opens.
2

Sign In with an Admin Account

Sign in with an account that has the Global Administrator or Privileged Role Administrator role in Microsoft Entra ID.
3

Review and Accept Permissions

Microsoft shows the app nOps.io from nOps Inc (a verified publisher) and the permissions it asks for. Review them and click Accept.
4

Return to nOps

Microsoft sends you back to the nOps wizard. Your Azure Tenant ID now shows, which confirms that consent was granted.
  • Consent adds the nOps.io enterprise application to your tenant and approves its permissions for your whole organization, so no one else is asked to approve them. For the full list of permissions, see What does Grant Admin Consent do? in the FAQs.
  • Consent by itself gives nOps no access to your subscriptions, billing, or storage. nOps only gets Azure access from the roles you assign in Run the Setup.
  • nOps never signs in as your users. It connects with the app’s own identity, using only the roles you assign.
What is an enterprise application? It’s how an app from another organization appears in your Microsoft Entra ID tenant. It’s also called a service principal. Consent adds it to your tenant. It isn’t an app registration: the nOps app registration lives in nOps’s own tenant, not yours.
Don’t delete the nOps.io enterprise application after you grant consent. If you delete it, nOps loses access and you’ll need to grant admin consent again from the wizard.

3. Run the Setup

You do this part in the Azure portal. It has four parts, A to D. Only the EA billing role in Step A needs the Azure CLI.
The nOps wizard walks you through the same steps (labeled A through D), with your own values filled in. Follow along in the wizard or use the steps below.
For every role, its ID, and what it allows, see Permissions & Resources.

A. Billing Role

Follow only the tab that matches your billing account type and how you connect it.

B. Reader on the Management Group

Assign Reader on the management group that holds the subscriptions you want in Savings Analysis. You need Owner or User Access Administrator on that management group.
1

Enter Your Management Group ID

In the nOps wizard, enter the Management Group ID. To cover every subscription, click Use tenant root. Your tenant ID is the ID of the root management group.Find your management groups in Azure Portal > Management Groups.
2

Open the Management Group

Go to Management Groups in the Azure portal and select the management group.
3

Open Access Control

Click Access control (IAM) in the left menu, then click Add > Add role assignment.
4

Select the Role

On the Role tab, search for and select Reader, then click Next.
5

Assign to nOps.io

  1. On the Members tab, set “Assign access to” to “User, group, or service principal” (not “Managed identity”).
  2. Click ”+ Select members”.
  3. Search for “nOps.io” by name and select it.
  4. Click Select.
  5. Click Review + assign.
Repeat only if your subscriptions are split across separate management groups.

C. FOCUS Cost Export

1

Choose the Export Subscription

In the nOps wizard, enter the subscription that will hold the export’s storage account. Choose the subscription with the most spend.To create the storage account, you need Owner or Contributor on this subscription.
2

Register Resource Providers

Make sure these resource providers are registered on that subscription: Microsoft.Storage, Microsoft.CostManagement, and Microsoft.CostManagementExports.Go to Subscriptions → select the subscription → Settings → Resource providers, and click Register on any that aren’t registered. Most subscriptions already have these registered. If a provider already shows “Registered”, no action is needed.
3

Open Exports and Set the Scope

Go to Cost Management > Exports in the Azure portal. At the top, click Change scope if needed, and select:
  • MCA billing account: your Microsoft Customer Agreement billing account
  • EA: your EA enrollment (the same enrollment number you entered in the nOps wizard, e.g., 12345678)
  • MCA billing profiles: one of your billing profiles. You’ll create a separate export for each profile
4

Create the Export

  1. Click + Create.
  2. Basics tab: Select the “Cost and usage (FOCUS)” template.
  3. Datasets tab: Set the export prefix to nops-clara. The template sets the frequency to Daily.
    • MCA billing profiles only: use the prefix the nOps wizard shows for that profile. It’s nops-clara- followed by letters and digits from the billing profile ID, in lowercase. This keeps the exports from overwriting each other.
  4. Destination tab:
    • Storage type: Azure blob storage
    • Subscription: the subscription you entered in the nOps wizard
    • Storage account: Click Create new
      • Resource group: create a new one named nops-focus-exports-rg
      • Name: nopsfocus + the first 15 characters of your tenant ID, without dashes
      • Region: any region you choose
    • Container: focus-exports
    • Directory: nops-clara
    • Format: Parquet
    • Compression type: Snappy
    • File partitioning: checked
    • Overwrite data: checked
  5. Click Review + create, then Create.
5

Run the Export and Backfill 3 Months

  1. Open the export and click Run now to trigger the first export.
  2. Click Export selected dates to backfill the previous 3 months, one run per month:
    • Run 1: Start date = first day of three months ago, End date = last day of three months ago
    • Run 2: Start date = first day of two months ago, End date = last day of two months ago
    • Run 3: Start date = first day of previous month, End date = last day of previous month
Data will be available within a few hours.
MCA billing profiles: repeat these export steps for each billing profile you connect, with that profile’s prefix. After the first profile, select the storage account you already created instead of creating a new one.
The nOps wizard shows the exact storage account name, resource group, container, and directory you need. Copy these values from the wizard so they match what nOps checks in Verify.

D. Storage Blob Data Owner

You must be an Owner or User Access Administrator on the storage account to assign Storage Blob Data Owner.
1

Open the Storage Account

Search for “Storage accounts” in the Azure portal’s top search bar, then select the storage account you created in Step C (e.g., nopsfocus<tenant-prefix>).
2

Assign Storage Blob Data Owner

  1. Go to Access control (IAM) → Add → Add role assignment.
  2. Under Job function roles, select Storage Blob Data Owner.
  3. Select User, group, or service principal.
  4. Search for and select nOps.io.
  5. Click Review + assign.
3

Configure Firewall (if applicable)

If your organization restricts storage account network access (through Azure Policy or manual settings):
  1. Go to the storage account > Security + networking > Networking
  2. Under Firewall, add the nOps IP addresses: 44.246.45.84, 52.11.53.164, and 52.39.155.200
  3. Make sure “Allow Azure services on the trusted services list” is checked
  4. Click Save
Skip this step if your storage account allows public network access (the default). nOps reads the export files from outside Azure, so if a firewall is on, it must allow the nOps IP addresses.
Azure role assignments can take 2-5 minutes to propagate. If verification fails right after you assign roles, wait a few minutes and try again.

Finish in nOps

When you’ve completed Steps A through D, return to the nOps wizard and click “I’ve completed all steps” to go to Verify.

4. Verify Connection

nOps checks that each part of the setup is in place.
1

Click Verify Permissions

Click the Verify Permissions button. nOps checks:
  • Reader — nOps can list your subscriptions
  • Billing role — nOps has Billing account reader (MCA), Billing profile reader (MCA billing profiles), or EnrollmentReader (EA)
  • FOCUS export — a FOCUS export exists at the right billing scope
  • Storage Blob Data Owner — nOps can list the export container
If you connected billing profiles, nOps checks Billing profile reader and a FOCUS export on each profile. It skips a profile’s export check until that profile’s billing role is in place.
2

Review Results

The wizard shows a pass or fail result for each check. When they all pass, you’ll see “Savings Analysis Verified” with the number of connected subscriptions.
Verification Failed? — If some checks don’t pass yet:
  1. Wait a few more minutes. Azure role assignments can take time to propagate
  2. Check that each role was assigned to nOps.io at the right scope: the billing role (Step A), Reader on the management group (Step B), and Storage Blob Data Owner on the storage account (Step D)
  3. Check that the FOCUS export exists at your billing account, enrollment, or each billing profile you connected (Step C)
  4. Click Verify Permissions to check again

Next Steps

Once the Savings Analysis integration is verified, nOps begins ingesting your cost data and generating optimization recommendations. To enable automated purchasing and management of Azure Reservations and Savings Plans, you can upgrade your integration to the Commitment Management tier:

Azure Commitment Management Setup

Configure nOps to manage Azure Reservations and Savings Plans on your behalf, including automated purchasing and optimization.