Skip to content

Getting started

Granting CloudMonitor read-only Azure access and getting your reports live.

Does it support FOCUS 1.2?

Yes. FOCUS is the native schema for CloudMonitor's Azure cost reporting. Azure publishes its 1.2-preview schema alongside the generally available 1.0 export. See Microsoft's FOCUS metadata reference for the current Azure schema. CloudMonitor also supports AWS billing data today. Google Cloud is planned and is not a connected data source yet.

How long does setup take?

Installation normally takes a couple of hours. Total elapsed time depends on how quickly your Azure administrator approves the CloudMonitor application and grants the required scoped roles. In your own Fabric tenant, you provide the Fabric capacity and the workspace we deploy into; under CloudMonitor-hosted, we provide both. The setup guide walks through each step.

What exactly am I approving?

Approve the CloudMonitor app in your Microsoft Entra tenant so Azure creates its service principal. Then grant the required scoped roles. These include read access for billing and resource metadata. One management role is limited to the dedicated export storage account, where CloudMonitor creates and runs the scheduled export. In your own Fabric tenant you also provide the Fabric capacity and the workspace we deploy into, and you grant us a role on that workspace; under CloudMonitor-hosted, that capacity and workspace are ours. CloudMonitor holds a scoped workspace role in both arrangements so we can deploy, update and support the app. In your own Fabric tenant that role covers only the workspace you granted it on. It carries no visibility of any other workspace in your tenant and no rights over your Entra directory. CloudMonitor cannot read the data inside your workloads or services.

What happens next?

As soon as you authorize, we start processing your cost data and setting up your reports. We'll reach out by email with your access once it's ready, and we'll let you know if we run into any issues connecting your account.

Where do I find my tenant ID?

In the Microsoft Entra admin center under Overview → Tenant ID, or in the Azure portal as the Directory ID. It is a 36-character GUID.

Do I need to be an administrator?

Approving access requires the Microsoft Entra Cloud Application Administrator role — the least-privilege role for this step, and the one we encourage rather than using a Global Administrator. On the get-started page you can enter your details and forward the authorization link to whoever holds that role.

Live chat didn’t load

This browser blocked our chat widget, so the support button can’t open. A privacy shield or content blocker is the usual cause.

  1. Click the Brave Shields icon (the lion) beside the address bar.
  2. Turn Shields off for cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.
  1. Open your content blocker or privacy extension.
  2. Allow cloudmonitor.ai.
  3. Reload this page. The chat icon returns bottom right.

Rather leave the blocker on? Send us a message or search the help desk.