> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vortexiq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Azure on Vortex IQ

> Monitor Microsoft Azure health, cost and reliability signals, and catch incidents and runaway spend early.

Monitor Microsoft Azure health, cost and reliability signals, and catch incidents and runaway spend early.

[Connect or manage this source](https://app.vortexiq.ai/workbench/settings/sources) · [How connecting works](/integrations/connector-catalogue) · [Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=azure)

<CardGroup cols={5}>
  <Card title="20">
    performance signals
  </Card>

  <Card title="3">
    automated checks
  </Card>

  <Card title="Build your own">
    automated fixes
  </Card>

  <Card title="Ready to build yours">
    workflows
  </Card>

  <Card title="3">
    API operations
  </Card>
</CardGroup>

<Tabs>
  <Tab title="Overview">
    ### What you can achieve

    Capabilities are grouped around merchant outcomes, not API terminology.

    <CardGroup cols={2}>
      <Card title="Run operations">
        Monitor orders, fulfilment, delivery and settlement.
      </Card>

      <Card title="Control risk and change">
        Keep tracking, access and change under governed control.
      </Card>
    </CardGroup>

    ### From connection to verified outcome

    The controlled sequence every capability follows. Nothing changes a connected system without the approval step.

    <Steps>
      <Step title="Connect">
        Authorise the source. Scopes are shown before access is granted.
      </Step>

      <Step title="Monitor">
        Watch the signals against your own baselines, not universal defaults.
      </Step>

      <Step title="Detect">
        Run checks and gather evidence specific to your store.
      </Step>

      <Step title="Recommend">
        Explain what happened, why it matters and the proposed action.
      </Step>

      <Step title="Approve">
        You review scope, risk and reversibility before anything changes.
      </Step>

      <Step title="Execute">
        Apply through governed connector operations.
      </Step>

      <Step title="Verify">
        Confirm the intended result and keep the receipt.
      </Step>
    </Steps>

    No changes are made without the configured approval policy. Read-only operations do not modify the connected system; schedules, access scopes, API usage and data handling remain governed by Vortex IQ controls.
  </Tab>

  <Tab title="Monitor (20)">
    ### Monitor performance

    20 performance signals. Open an outcome to see its signals and how each one alerts. Read-only operations do not modify the connected system.

    <AccordionGroup>
      <Accordion title="Run operations (19 signals)">
        | Signal                           | Alert behaviour    | What it tracks                                                                                                                                         |
        | -------------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
        | **Active Services (30d)**        | Watch only         | Count of distinct ServiceName values with Cost > 0 in the last 30d of the cost rows.                                                                   |
        | **Annualised Run Rate**          | Watch only         | Avg daily spend (30d Cost sum / days with spend) x 365; what the current burn costs over a year.                                                       |
        | **Avg Cost per Service (30d)**   | Watch only         | 30d Cost sum / count of distinct ServiceName values with Cost > 0 in the window.                                                                       |
        | **Avg Daily Spend (30d)**        | Watch only         | 30d Cost sum / count of distinct UsageDate values with Cost > 0 in the window.                                                                         |
        | **Azure Spend (30d)**            | Alert band 10 / 50 | Sum of Cost over the last 30d of daily rows from the CostManagement/query 60d Daily ActualCost response; change vs the previous 30d window. Cost Manag |
        | **Azure Spend (7d)**             | Watch only         | Sum of Cost for daily rows with UsageDate in the last 7 days.                                                                                          |
        | **Billing Currency**             | Watch only         | Currency column value from the CostManagement/query rows (e.g. USD, GBP); also drives the currency symbol on every spend card.                         |
        | **Cloud Health Score**           | Alert band 90 / 70 | Composite 0-100: start at 100, minus 30 if 30d spend is up >50% vsP (15 if up >25%), minus 10 if the top service is >80% of 30d spend, minus           |
        | **Cost by Service (30d)**        | Watch only         | Cost summed per ServiceName over the last 30d of the CostManagement/query rows; top 10 services by spend.                                              |
        | **Daily Spend Trend**            | Watch only         | Cost summed per UsageDate over the last 30d of the CostManagement/query Daily rows.                                                                    |
        | **Days with Spend (30d)**        | Watch only         | Count of distinct UsageDate values with Cost > 0 in the last 30d; gaps mean idle days or missing cost data.                                            |
        | **Month-to-Date Spend**          | Watch only         | Sum of Cost for daily rows with UsageDate on or after the 1st of the current month, from the same CostManagement/query response.                       |
        | **New Cost Services (30d)**      | Watch only         | Count of ServiceName values with Cost > 0 in the current 30d window but zero cost in the previous 30d window; new services quietly adding spend.       |
        | **Peak Daily Spend (30d)**       | Watch only         | Max of the per-UsageDate Cost sums over the last 30d; detail names the peak day.                                                                       |
        | **Previous 30d Spend**           | Watch only         | Sum of Cost over the previous 30d window (days 31-60) of the same 60d Daily cost response; the vsP baseline.                                           |
        | **Service Concentration (30d)**  | Watch only         | Top service 30d Cost sum / total 30d Cost sum x 100; a very concentrated bill is a single point of cost failure.                                       |
        | **Spend Change vs Previous 30d** | Watch only         | (current 30d Cost sum - previous 30d Cost sum) / previous 30d Cost sum x 100, from the 60d Daily cost rows.                                            |
        | **Spend Spike Alert**            | Alert band 10 / 50 | Spend change vs the prior 30d from the 60d Daily cost rows; fires on a spike per the ai\_spend\_trend band.                                            |
        | **Top Service by Cost (30d)**    | Watch only         | The single largest ServiceName by 30d Cost sum; detail names the service.                                                                              |
      </Accordion>

      <Accordion title="Control risk and change (1 signals)">
        | Signal                 | Alert behaviour | What it tracks                                                                                                                                         |
        | ---------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
        | **Subscription State** | Watch only      | state from GET /subscriptions/{subscription_id} (api-version=2022-12-01), e.g. Enabled or Disabled; detail shows displayName. Renders with the token + |
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Audit (3)">
    ### Audit risks and opportunities

    A fix status appears only where the action, inputs, approval, verification and recovery controls are mapped. Candidate remediations are never executable. Open a check for the detail.

    <AccordionGroup>
      <Accordion title="API key invalid, expired or lacking the scopes the cards need">
        **Severity** high · **Outcome** Control risk and change · **Fix status** Report only

        Once this credential fails, VortexIQ stops seeing usage, cost and health data from this platform entirely, and every finding here that depends on it goes stale from that moment, silently, until someone notices the numbers stopped updating.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `CLOUD-AUTH-001`
      </Accordion>

      <Accordion title="Spend up more than 50% vs the prior period">
        **Severity** high · **Outcome** Run operations · **Fix status** Report only

        Spend on this platform rose more than 50% versus the prior period. A jump this size is either a deliberate scale-up worth confirming was intentional, or an unbounded process, a stuck job, a misconfigured autoscaler, quietly running up a bill nobody approved.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `CLOUD-SPEND-001`
      </Accordion>

      <Accordion title="Usage dropped more than 50% vs the prior period (silent stall)">
        **Severity** medium · **Outcome** Control risk and change · **Fix status** Report only

        Usage halving against the prior period is the earliest sign of a silent stall: a broken schedule, an expired credential, or a team that quietly stopped.

        Vortex IQ detects and explains this; resolution is manual, with evidence and recommended steps.

        Reference: `CLOUD-USAGE-001`
      </Accordion>
    </AccordionGroup>

    #### Build your own automated fixes

    Turn any finding into an automated fix with a Vortex IQ workflow: **over 13,000 read and write operations across more than 200 connectors** are available as building blocks, with approval, verification and rollback on every change.
  </Tab>

  <Tab title="Automate">
    ### Automate approved work

    Vortex IQ is integrated with **1 read** and **2 write** operations across oauth2tokens, subscriptions, subscription providermicrosoftcostmanagementquerys on Microsoft Azure. Combine them with anything from the **over 13,000 operations across more than 200 connectors** to automate the work in your own words.

    Changes follow your configured approval policy: the target, proposed change, affected records, risk, reversibility and verification plan are shown before execution.

    [Create a workflow](https://app.vortexiq.ai/workbench/flows/create?connector=azure)

    #### Ready to build your first Microsoft Azure workflow

    Pick a trigger, add the operations above as steps, and every step that changes data pauses for your approval. Monitoring and audits are live now and can start any workflow you build.

    <Accordion title="Browse the operations you can build with">
      | Resource                                           | Read operations | Write operations |
      | -------------------------------------------------- | --------------- | ---------------- |
      | oauth2tokens                                       | 0               | 1                |
      | subscriptions                                      | 1               | 0                |
      | subscription providermicrosoftcostmanagementquerys | 0               | 1                |

      Signed-in users see the full catalogue in the workflow builder, filtered to the sources they have connected.
    </Accordion>
  </Tab>
</Tabs>
