Skip to content

Microsoft Azure

  • Spend by service and resource group
  • Cost by subscription
  • Reservation utilization and expiration alerts

Method: Service Principal (Client Credentials)

  1. In the Azure Portal, go to Azure Active Directory → App registrations, and click New registration to create a service principal for Plutus.
  2. On the new app’s overview page, note the Application (client) ID and Directory (tenant) ID — you’ll need both below.
  3. Go to Certificates & secrets → New client secret. Create one and copy the secret value immediately; Azure only shows it once.
  4. Go to Subscriptions → your subscription → Access control (IAM) → Add role assignment, and assign the Cost Management Reader role to the service principal you just created.
  5. In Plutus, enter the Tenant ID, Client ID, Client Secret, and Subscription ID.
  6. Optionally, enter a Cost Allocation Tag Key — an Azure resource tag key whose values you want to use in cost-tag rules.
  7. If you’re on a Microsoft Customer Agreement and want Plutus to track your Azure credit balance, also enter the Billing Account ID and Billing Profile ID, found under Cost Management → Billing scopes → your billing account → Properties. Leave both blank on any other agreement type (pay-as-you-go, EA) — everything else still works without them.

Azure Reservation utilization on the commitment utilization page needs the same Billing Account ID and Billing Profile ID as step 7 (the in-app hint mentions only the credit balance), plus one more role assignment: Reservations Reader at billing scope, which is broader than the subscription-scoped Cost Management Reader in step 4. Without it, cost sync is unaffected and the reservation step is skipped. A subscription with no billing profile reports as not applicable rather than failing.

Azure savings plans (a separate product from reservations) and Azure commitment-expiration alerts are not covered.