Azure Advisor already recommends cost changes for every subscription: shut down this VM, resize that one, buy a reservation for steady usage. What it does not do is price them at what you pay. Advisor's shutdown and resize figures are retail estimates that ignore reservations, savings plans and negotiated rates — Microsoft's own documentation warns the listed savings can be higher than what is actually possible.
This page describes what InfraSync reads from an Azure subscription, the rules that turn Advisor's estimates into a total you can defend, and what it needs from you. The rules are the same as for AWS and Google Cloud: a claim never exceeds the data behind it, and anything that cannot be priced honestly ships at $0 rather than as a guess.
- What it reads
- Seven rules between Advisor and your total
- Connecting a subscription
- Checked before the first report
- What it does not cover yet
- Frequently asked questions
What it reads
| Source | What it contributes |
|---|---|
| Azure Advisor (cost) | Shutdown and resize advice for VMs and scale sets, reservation and savings-plan recommendations, and Advisor's other cost advice. |
| Cost Management | What each resource actually cost over the last 30 complete days. Every figure below is checked against it. |
| Resource Graph | VMs that are stopped but not deallocated, and so still billed for compute; unattached managed disks; public IPs attached to nothing. |
Seven rules between Advisor and your total
1. A figure is capped at what the resource actually cost
Each shutdown or resize figure is capped at the resource's actual cost over the last 30 complete days. A VM that a reservation already covers costs you close to nothing, so shutting it down saves close to nothing while the reservation runs: it ships at $0, with that reason. A resource that cannot be matched to a billed cost — an AKS node bills to its scale set, and a new resource can lag — also ships at $0 and says why.
2. Shutdown or resize is read, not guessed
Advisor uses one recommendation type, with one wording, for both shutting a VM down and resizing it. The difference is in the recommended target size, so that is what InfraSync reads. A scale set's advice to run fewer instances reads as "scale in", never as "resize X to X".
3. A commitment needs a month of evidence
Reservation and savings-plan recommendations count only when Advisor's lookback is 30 days or longer. Its 7-day default cannot justify a one- or three-year purchase, so those ship at $0 and tell you to raise the lookback. A recommendation scoped to several subscriptions is a note, not a finding, because counting it in each subscription's report would count it more than once.
4. Advice you have snoozed or dismissed stays out
If you have postponed or dismissed a recommendation in Advisor, the report leaves it out and says how many it skipped.
5. One resource, one finding
A resource flagged by both Advisor and a Resource Graph check is counted once.
6. Every figure is in US dollars, or unpriced
Figures in another currency are converted at a dated exchange rate, and the report states the rate and its date. A figure whose currency Azure does not state is not assumed to be dollars; it stays unpriced.
7. A report that could read nothing fails
If sign-in is refused — an expired client secret, say — or nothing in the subscription can be read, the report fails and names the fix. It does not complete at $0, which would read as "nothing to save" and, on the free plan, spend the one free check.
Connecting a subscription
A subscription connects through an app registration (a service principal) and its client secret, with two read-only roles on the subscription: Reader, for resources, Advisor and Resource Graph, and Cost Management Reader, for actual cost. The setup on InfraSync's Connect page gives the commands with your subscription ID filled in:
az ad sp create-for-rbac --name infrasync-cost-reader --role Reader --scopes /subscriptions/SUBSCRIPTION_ID
az role assignment create --assignee APP_ID --role "Cost Management Reader" --scope /subscriptions/SUBSCRIPTION_ID
Paste the JSON the first command prints, and the form fills in the app ID, secret and tenant for you. The client secret is encrypted at rest and never shown again. A subscription takes one slot of your plan's account allowance, like an AWS account or a Google Cloud project.
Client secrets expire on the date Entra ID sets. When yours does, the next report fails and names the fix, but there is no warning before it happens yet. Federated credentials, which need no secret, are not supported yet.
Checked before the first report
Connecting proves the subscription is visible — not that the analysis can read what it needs. Right after you connect, InfraSync repeats the analysis's own reads — Advisor, a Cost Management query and Resource Graph — and shows each as passing, needing a fix, limited, or unknown. A missing role comes with the az role assignment command that grants it. A subscription whose offer type has no cost data is marked limited, because its figures could not be checked against your bill.
What it does not cover yet
- Terraform and drift for Azure are coming soon. Today, InfraSync does cost analysis for Azure, and Terraform and drift for AWS.
- Not analysed yet: old snapshots, empty App Service plans, idle load balancers and application gateways, and AKS node pools beyond Advisor's scale-set advice.
- No schedules yet. Azure analyses run when you start them.
- No cost data, no count. If Cost Management cannot be read — for example, an Enterprise Agreement where viewing charges is turned off — Advisor's figures cannot be checked against your bill, so they are reported but not counted.
Frequently asked questions
Does it need write access to my subscription?
No. Reader and Cost Management Reader are both read-only.
Why is the total lower than Azure Advisor's?
Because each of Advisor's retail figures is capped at what the resource actually cost, and commitments need a 30-day lookback. Advisor's own estimate stays in each finding's text.
Why does it need Cost Management Reader?
To read what each resource actually cost. That caps Advisor's estimates, and prices the findings Advisor does not make, such as unattached disks.
Can I analyse Azure alongside AWS and Google Cloud?
Yes. Each subscription, account and project takes one slot of the same allowance, and each gets its own reports.
Try it on a subscription
To see what Advisor's advice is worth at your actual prices, connect a subscription to InfraSync. Access is read-only, and the access checks tell you before the first report whether anything is missing.