Skip to main content

Azure Cloud Account Setup: Choose a Path

Connect Azure to Spotto by choosing the setup path that matches how your team manages Azure access. Every path that creates a Spotto service principal ends with the same read-only permissions.

Decision tree. Is this a one-off, read-only assessment? Yes: use Guest access. No: are you connecting customers through Partner Center? Yes: use GDAP. No: choose how the Azure changes are made: Click and Connect (recommended, sign in to Spotto and it does the rest), a PowerShell script, Terraform, or manual steps in the Azure portal. All four end with the same Spotto service principal and permissions.Decision tree. Is this a one-off, read-only assessment? Yes: use Guest access. No: are you connecting customers through Partner Center? Yes: use GDAP. No: choose how the Azure changes are made: Click and Connect (recommended, sign in to Spotto and it does the rest), a PowerShell script, Terraform, or manual steps in the Azure portal. All four end with the same Spotto service principal and permissions.

Choose Your Setup Path​

PathBest forWho makes the Azure changes
Click & Connect (Automatic Azure Connect)Most teams. Recommended.Spotto, after an admin signs in with Microsoft
PowerShell ScriptAdmins who prefer a guided script they run locally. Get the script.The script, as the signed-in admin
Terraform ModuleTeams that manage Azure access as code. Get the module.Terraform
Manual Azure Portal SetupOrganizations where every change is made by handYou, step by step
Azure Guest Assessment AccessA one-off, read-only assessmentThe customer invites a guest with Reader. No service principal.
GDAPMSPs and CSP partners connecting customer tenants through Partner CenterPartner Center relationship and delegated access

If you are using GDAP, read How Azure Access Actually Works first. GDAP roles, Azure access and CSP billing visibility are three separate grants, and the roles on a relationship can't be changed after the customer approves it.

What Permissions Do I Need?​

Two questions, two pages:

  • What does Spotto need? Only Reader on your subscriptions is required. Extra read roles, Entra ID read and optional write-back each unlock more features. See Permissions Spotto Needs for the access matrix and what you lose if you skip something.
  • What do I need to run setup? Temporary admin roles, such as Global Administrator and Owner, ideally through PIM. See Permissions To Run Setup.

The automated paths grant the same read permissions by default. They differ in two places:

  • Billing exports. Click & Connect and Terraform leave them off until you opt in, because they create a storage account in your tenant. The PowerShell script asks and defaults to yes. See Azure Billing Exports.
  • Write-back. Off in every path until you turn it on.

Video Walkthroughs​

Connect With Click & Connect​

Follow the Click & Connect flow to create a durable Azure connection in Spotto.

Scan With Guest Access​

See how to run a read-only Azure tenant assessment using guest access without a service principal.

Manual Setup Warning​

Manual setup is the easiest place to miss a step. If you use the Manual Azure Portal Setup, grant the complete Microsoft Graph permission set and set up billing exports for the subscriptions you want analyzed. Without readable exports, Spotto relies on Azure billing APIs and may have gaps in cost history even when the connection validates.

Add Or Update The Azure Account In Spotto​

If your setup path gives you a tenant ID, client ID, and client secret, enter them in Spotto from Connectors -> Connectors -> Cloud Accounts. Full steps are in Add Or Update The Azure Account In Spotto.

Missing Permission Warnings​

If Spotto shows Permission required in sync diagnostics, use the permission warning reference.

Configure Cost Management Exports To Storage​

Manual billing export steps are now documented in Manual Azure Portal Setup.

Billing Prerequisites For CSP / Azure Plan Subscriptions​

CSP billing visibility requirements are documented in CSP Billing Prerequisites.