How to Backfill CUR From AWS to Stratusphere
Discover how to efficiently backfill Cost and Usage Reports (CUR) from AWS into StratusGrid's cost optimization platform Stratusphere in our guide.
This article describes how to connect your Microsoft Azure environment to StratusGrid's Stratusphere SaaS tool.
This article tells you how to connect an Azure tenant to Stratusphere as a data source.
There are two ways to connect your tenant:
Choose one method. Using both could result in your Azure costs being counted twice in Stratusphere.
Both methods create the following in your tenant:
stratusgrid-stratusphere, its service principal, and the certificate that Stratusphere made for your tenant.rg-stratusphere). It contains a storage account and an Event Grid subscription. The subscription tells Stratusphere when new cost data is available.Stratusphere gets read-only access. StratusGrid can't change or manage anything in your tenant.

The Quickstart command downloads the script for you, so you don't need to download anything. If you want to review the files before you run them, here they are:
| File | Purpose | Link |
|---|---|---|
Connect-Stratusphere.ps1 |
Onboarding script. Run it in Azure Cloud Shell. | https://stratusphere.app/Connect-Stratusphere.ps1 |
stratusphere-azure.json |
ARM template. It deploys the ingestion resources and the Cost Management exports. | https://stratusphere.app/stratusphere-azure.json |
These files are the same for every customer. Your API token and certificate link are passed in when you run them, so you don't need to edit either file.
Before you start, make sure you have:
By default, even a Global Administrator can't assign roles at the Tenant Root Group. To turn this on, a Global Administrator must:




-DryRun.irm https://stratusphere.app/Connect-Stratusphere.ps1 -OutFile Connect-Stratusphere.ps1
./Connect-Stratusphere.ps1 `
-ApiToken <your-api-token> `
-PublicKeyUrl <your-certificate-link>
It's safe to run the script again. It reuses anything it already created instead of making duplicates.
More than one tenant? Add each tenant in Stratusphere, then run its command in that tenant. If your tenants share one billing account, only the first run creates the cost exports. Later runs connect the tenant without creating new exports and show the message "Already set up by another tenant, left untouched". This is expected, and you don't need to do anything.
If you close the setup before you enter the client ID, the tenant shows Action needed · Finish setup on the Data Sources page. Click ⋯ on the tenant's row, and then:

stratusphere-diagnostics.json file from the folder where you ran the script. It shows which billing account the script found and which exports it created or left in place. To get the file from Cloud Shell, select Manage files → Download.stratusphere-error.log file from the same folder, if there is one.The manual setup still starts in Stratusphere, which creates your API token and certificate link.
-ApiToken (your API token) and the value after -PublicKeyUrl (your certificate link). Save both somewhere secure. The API token is shown only once..pem file). Use the link that Stratusphere gave you. The link expires after 24 hours. You can also get the certificate from the Data Sources page: click ⋯ on the tenant's row, and then View credentials.stratusgrid-stratusphere. Select single tenant. Do not set a redirect URI..pem file.az ad sp create --id <app-client-id>.Assign these two roles to the service principal at the Tenant Root Group (management group scope):
In the portal, go to Management groups → Tenant Root Group → Access control (IAM) → Add role assignment.
The template deploys at the subscription scope. It creates the resource group, the storage account, the Event Grid subscription, and the Cost Management exports.
First, find your billing scope. This is where the cost exports are created. In the Azure portal, go to Cost Management + Billing → Billing scopes, select your billing account, and copy its ID from Properties. You can also run:
az billing account list --query "[].{id:id, name:displayName, type:agreementType}" -o table
Billing scopes normally have this format: /providers/Microsoft.Billing/billingAccounts/<billing-account-id>. If you're using pay-as-you-go, use this instead: /subscriptions/<subscription-id>.
Then deploy the template:
az deployment sub create `
--location eastus `
--template-uri https://stratusphere.app/stratusphere-azure.json `
--parameters `
servicePrincipalId=<service-principal-client-id> `
stratusphereAPIToken=<your-api-token> `
billingScope=<your-billing-scope>
If the deployment reports an unregistered resource provider, register Microsoft.EventGrid, Microsoft.Storage, and Microsoft.CostManagement on the subscription (Subscriptions → Resource providers), and then deploy again.
Template parameters (the first three are required):
| Parameter | Default | Notes |
|---|---|---|
servicePrincipalId |
— (required) | The Client ID of the service principal from Step 2 |
stratusphereAPIToken |
— (required) | The API token from Stratusphere |
billingScope |
— (required) | The billing scope that you found above |
resourceGroupName |
rg-stratusphere |
The resource group that the template creates |
location |
eastus |
The region for the ingestion resources |
storageSubscriptionId |
the current subscription | The subscription that contains the storage account |
deployFocusExport |
true |
Set this to false only if your agreement type does not support FOCUS |
The template in Step 4 makes a managed identity for each Cost Management export. The export uses this identity to write data to the storage account.
Each identity must have the Storage Blob Data Contributor role on the storage account. If an identity does not have this role, its export cannot send data.
The Exports page does not show the identities. Use Microsoft Entra ID to find them.
Find the export identities
stratusphere.stratusphere-actualstratusphere-amortizedstratusphere-focusNOTE: The stratusphere-focus identity shows only if you set deployFocusExport to true in Step 4.
Give the role to the identities
CAUTION: DO NOT SELECT MANAGED IDENTITY IN THE ASSIGN ACCESS TO FIELD. THAT LIST DOES NOT SHOW COST MANAGEMENT EXPORTS.
Make sure that the role is correct
NOTE: Azure can take some minutes to apply a new role. Wait 5 minutes before you start Step 6.
Stratusphere needs data for both the current month and the previous month to process your costs correctly. For each export:
az costmanagement export execute.On the Data Sources page, click ⋯ on the tenant's row, and then Add client ID. Paste the Application (client) ID from Step 2 and click Connect and verify. Stratusphere checks the credentials and confirms when the tenant is connected.
Have questions or need additional help? Contact StratusGrid support.
Discover how to efficiently backfill Cost and Usage Reports (CUR) from AWS into StratusGrid's cost optimization platform Stratusphere in our guide.
Discover AWS DocumentDB: a MongoDB-compatible, AWS-managed database service. Learn how to optimize costs using Stratusphere™ by StratusGrid..
Optimize your AWS Lambda functions by uncovering over-provisioning with Stratusphere™ FinOps by StratusGrid. Ensure cost efficiency and performance...