Overview
nOps offers two integration tiers, each requiring different levels of access:- Savings Analysis — Read-only cost visibility, resource inventory, and optimization recommendations
- Commitment Management — Automated purchasing and management of Azure Reservations and Savings Plans (builds on Savings Analysis)
Permissions — Savings Analysis
Savings Analysis uses three roles: Reader, Storage Blob Data Owner, and one billing role. That’s the complete list. You assign all of them to nOps.io during Run the Setup.Management Group Scope
Storage Account Scope
The Storage Blob Data Owner role is granted only on the storage account you create for the FOCUS export (
nopsfocus<tenant-prefix>) — it does not grant access to any other resources in your environment. Savings Analysis does not need the Azure RBAC Owner role on the storage account. Owner is a management-plane role and cannot read blob data.Billing Scope
You assign one of these, depending on your billing account type and how you connect it:
These billing roles are read-only. nOps can’t change billing settings or make purchases with them.
Not used by Savings Analysis: Cost Management Contributor, Monitoring Reader, Reservations Reader, Savings Plan Reader, Owner on the storage account, Azure Lighthouse, and Azure Policy.
Permissions — Commitment Management
These additional roles are assigned on top of Savings Analysis.Management Group Scope (Additional)
Tenant Scope (Additional)
Storage Account Scope (Additional)
Dedicated Subscription Scope (via Lighthouse)
Billing Scope (Additional)
Complete Role Summary
All roles at a glance (Savings Analysis + Commitment Management)
All roles at a glance (Savings Analysis + Commitment Management)
Resources in Your Environment
Admin consent adds the nOps.io enterprise application to your tenant. You create everything else yourself during setup: the FOCUS export resources for Savings Analysis, and the Lighthouse delegation for Commitment Management.nOps.io Enterprise Application (created by admin consent)
When you grant admin consent, Microsoft adds the nOps.io enterprise application (a service principal) to your Microsoft Entra ID tenant. This is the identity nOps uses to connect to Azure. It isn’t an app registration: the nOps app registration lives in nOps’s own tenant. Consent by itself gives nOps no access to your subscriptions, billing, or storage. nOps only gets access from the roles you assign.FOCUS Export Resources (created by you)
You create these in the Azure portal during Step C of the setup. nOps doesn’t create them.These resources cost only the storage for the exported cost data.
Lighthouse Delegation (Commitment Management only)
You deploy this delegation during the Commitment Management Setup. Savings Analysis doesn’t use Azure Lighthouse or Azure Policy.
Required Resource Providers
FOCUS Export Subscription
Dedicated Subscription (Commitment Management only)
Required Purchase Policies
Required for Commitment Management only.Network Requirements
If your organization enforces storage account firewalls, whitelist the following nOps IP addresses on the FOCUS export storage account:
Also ensure “Allow Azure services on the trusted services list” is enabled on the storage account firewall.
If your storage account allows public network access (the default), no firewall configuration is needed.
Related Guides
Prerequisites
Prepare your Azure environment for nOps onboarding.
Savings Analysis Setup
Step-by-step guide to connect Azure for read-only cost visibility.
Commitment Management Setup
Configure automated purchasing of Azure Reservations and Savings Plans.