Skip to content
Linxus Infotech
Product Features How it works Pricing Compare Blog
Sign in Start free scan›
Guide · FinOps · Azure

Azure Cost Optimization: Advisor Savings, Capped at What You Actually Pay

Azure Advisor tells you what to shut down, resize or commit to — at retail prices. The honest number is what each resource actually cost you.

By Linxus Infotech Updated Oct 2, 2026 6 min read

Azure Advisor already recommends cost changes for every subscription: shut down this VM, resize that one, buy a reservation for steady usage. What it does not do is price them at what you pay. Advisor's shutdown and resize figures are retail estimates that ignore reservations, savings plans and negotiated rates — Microsoft's own documentation warns the listed savings can be higher than what is actually possible.

This page describes what InfraSync reads from an Azure subscription, the rules that turn Advisor's estimates into a total you can defend, and what it needs from you. The rules are the same as for AWS and Google Cloud: a claim never exceeds the data behind it, and anything that cannot be priced honestly ships at $0 rather than as a guess.

  • What it reads
  • Seven rules between Advisor and your total
  • Connecting a subscription
  • Checked before the first report
  • What it does not cover yet
  • Frequently asked questions

What it reads

SourceWhat it contributes
Azure Advisor (cost)Shutdown and resize advice for VMs and scale sets, reservation and savings-plan recommendations, and Advisor's other cost advice.
Cost ManagementWhat each resource actually cost over the last 30 complete days. Every figure below is checked against it.
Resource GraphVMs that are stopped but not deallocated, and so still billed for compute; unattached managed disks; public IPs attached to nothing.

Seven rules between Advisor and your total

1. A figure is capped at what the resource actually cost

Each shutdown or resize figure is capped at the resource's actual cost over the last 30 complete days. A VM that a reservation already covers costs you close to nothing, so shutting it down saves close to nothing while the reservation runs: it ships at $0, with that reason. A resource that cannot be matched to a billed cost — an AKS node bills to its scale set, and a new resource can lag — also ships at $0 and says why.

2. Shutdown or resize is read, not guessed

Advisor uses one recommendation type, with one wording, for both shutting a VM down and resizing it. The difference is in the recommended target size, so that is what InfraSync reads. A scale set's advice to run fewer instances reads as "scale in", never as "resize X to X".

3. A commitment needs a month of evidence

Reservation and savings-plan recommendations count only when Advisor's lookback is 30 days or longer. Its 7-day default cannot justify a one- or three-year purchase, so those ship at $0 and tell you to raise the lookback. A recommendation scoped to several subscriptions is a note, not a finding, because counting it in each subscription's report would count it more than once.

4. Advice you have snoozed or dismissed stays out

If you have postponed or dismissed a recommendation in Advisor, the report leaves it out and says how many it skipped.

5. One resource, one finding

A resource flagged by both Advisor and a Resource Graph check is counted once.

6. Every figure is in US dollars, or unpriced

Figures in another currency are converted at a dated exchange rate, and the report states the rate and its date. A figure whose currency Azure does not state is not assumed to be dollars; it stays unpriced.

7. A report that could read nothing fails

If sign-in is refused — an expired client secret, say — or nothing in the subscription can be read, the report fails and names the fix. It does not complete at $0, which would read as "nothing to save" and, on the free plan, spend the one free check.

Connecting a subscription

A subscription connects through an app registration (a service principal) and its client secret, with two read-only roles on the subscription: Reader, for resources, Advisor and Resource Graph, and Cost Management Reader, for actual cost. The setup on InfraSync's Connect page gives the commands with your subscription ID filled in:

az ad sp create-for-rbac --name infrasync-cost-reader --role Reader --scopes /subscriptions/SUBSCRIPTION_ID
az role assignment create --assignee APP_ID --role "Cost Management Reader" --scope /subscriptions/SUBSCRIPTION_ID

Paste the JSON the first command prints, and the form fills in the app ID, secret and tenant for you. The client secret is encrypted at rest and never shown again. A subscription takes one slot of your plan's account allowance, like an AWS account or a Google Cloud project.

Important

Client secrets expire on the date Entra ID sets. When yours does, the next report fails and names the fix, but there is no warning before it happens yet. Federated credentials, which need no secret, are not supported yet.

Checked before the first report

Connecting proves the subscription is visible — not that the analysis can read what it needs. Right after you connect, InfraSync repeats the analysis's own reads — Advisor, a Cost Management query and Resource Graph — and shows each as passing, needing a fix, limited, or unknown. A missing role comes with the az role assignment command that grants it. A subscription whose offer type has no cost data is marked limited, because its figures could not be checked against your bill.

What it does not cover yet

  • Terraform and drift for Azure are coming soon. Today, InfraSync does cost analysis for Azure, and Terraform and drift for AWS.
  • Not analysed yet: old snapshots, empty App Service plans, idle load balancers and application gateways, and AKS node pools beyond Advisor's scale-set advice.
  • No schedules yet. Azure analyses run when you start them.
  • No cost data, no count. If Cost Management cannot be read — for example, an Enterprise Agreement where viewing charges is turned off — Advisor's figures cannot be checked against your bill, so they are reported but not counted.

Frequently asked questions

Does it need write access to my subscription?

No. Reader and Cost Management Reader are both read-only.

Why is the total lower than Azure Advisor's?

Because each of Advisor's retail figures is capped at what the resource actually cost, and commitments need a 30-day lookback. Advisor's own estimate stays in each finding's text.

Why does it need Cost Management Reader?

To read what each resource actually cost. That caps Advisor's estimates, and prices the findings Advisor does not make, such as unattached disks.

Can I analyse Azure alongside AWS and Google Cloud?

Yes. Each subscription, account and project takes one slot of the same allowance, and each gets its own reports.

Try it on a subscription

To see what Advisor's advice is worth at your actual prices, connect a subscription to InfraSync. Access is read-only, and the access checks tell you before the first report whether anything is missing.

Keep reading

Guide · FinOps

Google Cloud Cost Optimization: Recommender Savings You Can Defend

The same rules applied to Google Recommender's figures.

Read the guide ›

Guide · FinOps

AWS Cost Optimization & FinOps: Finding Waste Without Inflating the Number

The same honesty rules, applied to an AWS account.

Read the guide ›

Guide · FinOps

AWS Savings Plans: Sizing a Commitment You Will Not Regret

Every other finding asks you to change something. This one asks you to change nothing and pay less.

Read the guide ›
Linxus Infotech

Live AWS infrastructure, codified as production-grade Terraform. Maker of InfraSync.

support@linxusinfotech.com
+91 8828 757 008

Product

  • InfraSync app
  • Features
  • How it works
  • Pricing
  • Compare
  • Blog

Legal

  • Privacy policy
  • Terms & conditions
  • Acceptable use policy
  • Security
  • Cookie policy
  • Cancellation & refunds
  • Service level agreement
  • Shipping & delivery
  • Contact us

Company

  • Try InfraSync
  • Contact sales
  • Support
  • Sitemap

© 2026 Linxus Infotech Pvt. Ltd. All rights reserved.

Made for engineers who refuse to click things in production.