Skip to main content

Overview

nOps offers two integration tiers, each requiring different levels of access:
  1. Savings Analysis — Read-only cost visibility, resource inventory, and optimization recommendations
  2. Commitment Management — Automated purchasing and management of Azure Reservations and Savings Plans (builds on Savings Analysis)
Cloud Solution Provider (CSP) subscriptions are NOT supported. nOps only works with direct Microsoft agreements — Enterprise Agreement (EA) or Microsoft Customer Agreement (MCA).

Permissions — Savings Analysis

Savings Analysis uses three roles: Reader, Storage Blob Data Owner, and one billing role. That’s the complete list. You assign all of them to nOps.io during Run the Setup.

Management Group Scope

Storage Account Scope

The Storage Blob Data Owner role is granted only on the storage account you create for the FOCUS export (nopsfocus<tenant-prefix>) — it does not grant access to any other resources in your environment. Savings Analysis does not need the Azure RBAC Owner role on the storage account. Owner is a management-plane role and cannot read blob data.

Billing Scope

You assign one of these, depending on your billing account type and how you connect it: These billing roles are read-only. nOps can’t change billing settings or make purchases with them.
Not used by Savings Analysis: Cost Management Contributor, Monitoring Reader, Reservations Reader, Savings Plan Reader, Owner on the storage account, Azure Lighthouse, and Azure Policy.

Permissions — Commitment Management

These additional roles are assigned on top of Savings Analysis.

Management Group Scope (Additional)

Tenant Scope (Additional)

Storage Account Scope (Additional)

Owner is added alongside Storage Blob Data Owner, not instead of it. Owner cannot read blob data, so removing Storage Blob Data Owner breaks cost data ingestion even though setup verification passes.

Dedicated Subscription Scope (via Lighthouse)

Billing Scope (Additional)

Complete Role Summary


Resources in Your Environment

Admin consent adds the nOps.io enterprise application to your tenant. You create everything else yourself during setup: the FOCUS export resources for Savings Analysis, and the Lighthouse delegation for Commitment Management. When you grant admin consent, Microsoft adds the nOps.io enterprise application (a service principal) to your Microsoft Entra ID tenant. This is the identity nOps uses to connect to Azure. It isn’t an app registration: the nOps app registration lives in nOps’s own tenant. Consent by itself gives nOps no access to your subscriptions, billing, or storage. nOps only gets access from the roles you assign.

FOCUS Export Resources (created by you)

You create these in the Azure portal during Step C of the setup. nOps doesn’t create them.
These resources cost only the storage for the exported cost data.

Lighthouse Delegation (Commitment Management only)

You deploy this delegation during the Commitment Management Setup. Savings Analysis doesn’t use Azure Lighthouse or Azure Policy.

Required Resource Providers

FOCUS Export Subscription

Dedicated Subscription (Commitment Management only)


Required Purchase Policies

Required for Commitment Management only.

Network Requirements

If your organization enforces storage account firewalls, whitelist the following nOps IP addresses on the FOCUS export storage account: Also ensure “Allow Azure services on the trusted services list” is enabled on the storage account firewall.
If your storage account allows public network access (the default), no firewall configuration is needed.

Prerequisites

Prepare your Azure environment for nOps onboarding.

Savings Analysis Setup

Step-by-step guide to connect Azure for read-only cost visibility.

Commitment Management Setup

Configure automated purchasing of Azure Reservations and Savings Plans.