Azure
Connect your Azure subscriptions to StackSpend via the Cost Management Query API.
What StackSpend tracks
StackSpend connects to the Azure Cost Management Query API and pulls spend daily at the subscription, service, and resource-group level. Tag-based attribution is included where tags are present on resources. Up to 90 days of history is loaded on first sync.
| Latency | Historical | Setup time |
|---|---|---|
| Daily | 90 days | 5 min |
What's included
StackSpend uses Azure's Actual Cost, summed daily by subscription, service, and resource group at your negotiated/effective prices (including reservation and savings-plan effects). This matches the Azure portal's Cost Analysis → Actual cost view. Figures are pre-tax and exclude tax, support charges, and credits. A connection can cover a single subscription, a management group (all subscriptions in the tenant), or a billing account.
Like the Azure portal's Cost Analysis, StackSpend reports pre-tax costs. Tax isn't available from Azure's cost API — it appears only on the monthly invoice — so StackSpend's Azure total reads lower than a tax-inclusive invoice by the amount of tax.
Authentication
StackSpend reads cost data with the Cost Management Reader role — read-only, with no access to your resources or data. You authorize the StackSpend app in your tenant and assign it that role: there is no app registration to create and no client secret to manage or rotate.
Authorize the StackSpend app
In StackSpend, go to Settings → Integrations → Azure, leave the method on Authorize StackSpend (recommended), and click Connect.
Sign in as a tenant administrator and approve the consent screen. This adds StackSpend as a service principal in your tenant — there is nothing to create, and nothing that expires. After approving, you'll be shown your Tenant ID; copy it.
Assign the Cost Management Reader role
Open Subscriptions in the Azure Portal, select your subscription, then go to Access control (IAM) → Add role assignment.
Search for the Cost Management Reader role, select it, and click Next. Click Select members, search for StackSpend Azure Provider, select the record, click Select, then Review + assign. Assign it at the subscription scope (a resource-group assignment won't make the subscription discoverable).
Connect in StackSpend
Back in StackSpend, your Tenant ID is filled in automatically from the consent step. Pick your subscription from the Subscription dropdown (StackSpend lists the ones it can read) — or paste a Subscription ID — then click Test and Connect to begin the first sync.
Your Tenant ID is also available any time in Microsoft Entra ID → Overview.
Any issues? Contact support@stackspend.app.
Frequently asked questions
What Azure access does StackSpend need?
StackSpend needs a read-only service principal assigned the Cost Management Reader role, which lets it read cost data through the Cost Management Query API. You authorize the StackSpend app in your tenant rather than creating an app registration or managing a client secret.
Is the Azure connection read-only?
Yes, the Cost Management Reader role is strictly read-only and grants no access to your resources or data. StackSpend only reads cost figures and never writes to your Azure environment.
Can StackSpend track multiple subscriptions?
Yes, a connection can cover a single subscription, a management group spanning all subscriptions in the tenant, or a billing account. Setup takes about 5 minutes and the first sync loads up to 90 days of history.
Why don't I see cost data yet?
Role assignments can take a minute or two to propagate after you assign Cost Management Reader, so a subscription may not be discoverable immediately. Make sure the role was assigned at the subscription scope rather than a resource group, then re-test the connection.