Azure CSP Cost Exports
Onboarding Guide
This guide is for Azure administrators who need to grant SHI access to copy Cost Management exports into your storage account.
You will run one script in your own Azure tenant. It takes approximately 5 minutes. When complete, you send SHI a single credentials file and no further action is required on your end.
What you are authorizing
SHI will be granted write-only access to a single container in a storage account you control. Specifically, the script creates an App Registration (Service Principal) in your Entra ID tenant and assigns it the Storage Blob Data Contributor role scoped to a container of your choosing.
SHI receives no access to any other resources in your tenant.
Manual Deployment
Prerequisites
- Your account must be able to create new Application Registrations.
- Your account must be able to create Azure Resources.
- Your account must have Owner or User Access Administrator on the target subscription (needed to create a role assignment).
Step 1 — Configure
You may reuse existing resources for this process, however, we recommend you create dedicated resources for this purpose.
- Create a resource group
- Create a storage account
- Create a blob container in the storage account
These resources should be dedicated to SHI.
- Create a new app registration and document the client ID
- Assign a new secret and document for sending to SHI
- Assign the app registration Storage Blob Data Contributor on the created blob container
Step 2 — Send credentials to SHI
Send the following information to your SHI contact securely (encrypted email, secure file transfer, etc.).
Security note: This information contains a client secret. Treat it like a password — do not email it in plain text or commit it to source control. The secret is scoped only to the single container specified above.
Once SHI has the file, your task is complete. SHI will need the following information:
- Tenant ID
- Storage Account ID
- Container Name
- App Registration Client ID
- App Registration Secret
Automated Deployment
Prerequisites
Azure CLI installed and authenticated against your tenant:
- Your account must have Owner or User Access Administrator on the target subscription (needed to create a role assignment)
- jq installed (brew install jq on macOS)
Download the deployment script.
Step 1 — Configure
Copy the example config and fill in your values:
Edit config.json:
Field | Description |
|---|---|
customerSubscriptionId | Your Azure subscription ID |
location | Azure region (default: eastus2) |
destinationResourceGroup | Resource group for the destination storage account, created if needed (default: rg-shi-cost-exports) |
destinationStorageAccount | Storage account name where exports will be delivered. If Public network access is Enable from selected networks then see Step 4 - Further securing your environment. |
destinationContainer | Container within that account (default: exports) |
The App Registration will be named shi-cost-export but you may rename it as desired.
Step 2 — Run the script
The script will:
- Create an App Registration in your Entra ID tenant.
- Generate a client secret.
- Assign Storage Blob Data Contributor to the App Registration on your container.
- Write the credentials to customer-credentials.json.
Step 3 — Send credentials to SHI
The script produces a file customer-credentials.json. Send this file to your SHI contact securely (encrypted email, secure file transfer, etc.).
Security note: This file contains a client secret. Treat it like a password — do not email it in plain text or commit it to source control. The secret is scoped only to the single container specified above.
Once SHI has the file, your task is complete. You can delete your local copy of customer-credentials.json.
Step 4 — Further securing your environment (optional)
Allow Azure Services:
The solution copys blobs between storage accounts. This requires the source and destination storage accounts to allow Azure services to access them. This is typically configured by enabling the "Allow trusted Microsoft services to access this storage account" option in the storage account's firewall settings.
Allow Outbound IP Addresses
The solution is running as an Azure Function (in East US 2), your storage account must be running in a region other than East US 2 (as traffic within the same region does not support dedicated public IP addresses) and your storage account firewall must allow the IP addresses of the Azure Function App as shown below.
52.247.3.29Service Principal Access:
The solution uses a service principal to authenticate to your storage account. The service principal must maintain the "Storage Blob Data Contributor" role assigned at the container level. This design ensures least privilege access best practices.
What SHI does with the credentials
SHI stores the credentials in an Azure Key Vault in the SHI tenant. They are never stored in plain text or in any config file. The automated copy job retrieves them from Key Vault at runtime.
Revoking access
To revoke SHI's access at any time:
Or via the Azure portal: Entra ID → App Registrations → [app name] → Delete.