Main content
Azure cost management tool

Azure cost management that turns spend into ranked, fixable findings

Varcio is an Azure cost management and optimization tool that connects through a Service Principal, reads Cost Management, Resource Graph and Azure Monitor across your subscriptions and resource groups, and runs 73 Azure detectors. Every finding is costed and ranked, and approved fixes such as deallocating idle VMs run behind protected tags, dry-run and full audit logging.

73Azure detectors, plus 23 cross-cloud detectors on the shared ledger
Service PrincipalClient ID and secret encrypted; access scoped to what you grant
Read-onlyThe complete analytical product runs on read-only credentials
AuditedEvery write action is logged; reservation purchases need explicit approval
Detection

What Varcio finds on Azure

73 Azure detectors look across subscriptions and resource groups for resources that bill without delivering value, and put a monthly cost on each one.

Azure estates tend to sprawl along organisational lines. Each team gets a subscription or a resource group, resources are created quickly, and cleanup depends on whoever remembers what a disk or IP address was for. Managed disks and public IPs can outlive the VMs they served, and Microsoft documents that a VM shut down from inside the guest operating system stays allocated and is still billed for compute.

Varcio treats each of these as a costed finding with an estimated monthly saving, a confidence score, an effort level, a risk note and a recommended action. Ranking on those scores puts safe, high-value work at the top of the queue.

Unattached storage

Managed disks that outlive their virtual machines are one of the most common sources of silent Azure spend.

  • Unattached disks
  • Disks still billing on deallocated VMs
  • Orphaned snapshots

Unused networking

Public IP addresses that are provisioned but no longer associated with a running workload.

  • Unused public IP addresses

Idle databases

Azure SQL databases that remain provisioned while showing no meaningful activity in Azure Monitor.

  • Idle SQL databases

Idle compute and hosting

Compute that is paid for but not used, including App Service plans that no longer host any workload.

  • Zero-workload App Service plans
  • Idle VMs that are candidates for deallocation
  • Empty AKS clusters on the paid tier

Spend drift, retention and policy

Spend tracked across subscriptions and resource groups, with anomaly detection, forecasting, budget enforcement and policy guardrails, plus log retention that costs more than it needs to.

  • Anomalous cost changes by subscription
  • Log Analytics retention beyond what is needed
  • Policy and tag violations

Rates, licensing and cross-cloud

Steady usage suited to reservations or savings plans, licences you already own but are not applying, and 23 cross-cloud detectors that catch duplication between Azure and your other clouds.

  • Azure Hybrid Benefit gaps
  • 1- and 3-year reservations or a 1-year savings plan
  • Duplicated environments spanning clouds

The signals behind Azure findings

Each Azure detector uses the signals that answer its question. Not every signal applies to every resource type; these are the kinds of evidence Varcio reads.

  1. Spend data

    The Cost Management Query API and, for EA and MCA billing, Cost Management FOCUS exports show cost that is moving without a matching change in demand.

  2. Live resource inspection

    Azure Resource Graph supplies current inventory and configuration, which is how unattached disks, unused public IPs and disks on deallocated VMs are found.

  3. Utilisation metrics

    Azure Monitor metrics identify idle SQL databases, idle VMs and App Service plans with no workload.

  4. Advisor and reservations

    Azure Advisor recommendations and reservation utilisation are read alongside Varcio’s own detectors.

  5. Identity and security configuration

    Microsoft Graph provides Entra ID context, and security settings are evaluated alongside cost, so findings carry their access context.

Connection

How Varcio connects to Azure

A Service Principal with an encrypted secret, Azure’s own inventory and monitoring APIs, and a clear boundary between reading and acting.

Service Principal

You create a Service Principal in Microsoft Entra ID and grant it read access to the subscriptions you want analysed. Varcio stores the client ID and client secret encrypted. You can scope, rotate or revoke the credential from Azure at any time.

Azure data sources

  • Cost Management Query API for spend
  • Cost Management FOCUS exports for EA and MCA billing
  • Azure Resource Graph for inventory and configuration
  • Azure Monitor for utilisation metrics
  • Azure Advisor recommendations and reservation utilisation
  • Microsoft Graph for Entra ID context

Read-only, indefinitely

Findings, forecasts, anomaly detection, allocation, tag governance and Apex questions all run on read-only credentials with no time limit, so you can evaluate and operate Varcio without granting write access.

Write access on the same Service Principal

When you want Varcio to act, you grant write roles to the same Service Principal. Varcio checks those write permissions separately from the read connection, and every change still passes the guardrails below.

Azure is one of the three clouds, with AWS and Google Cloud, where Varcio’s automation goes deepest.

Rate optimization

Commitments and rate optimization

Once idle and oversized resources are gone, reservations and savings plans reduce the rate you pay for steady Azure usage.

Microsoft describes savings of up to 72% for reservations and up to 65% for savings plans compared with pay-as-you-go prices. Those ceilings depend on term, region and service, and a commitment only saves money if the usage it covers is still running when the term ends.

That is why order matters. Microsoft’s own guidance notes that Advisor rightsizing estimates do not account for existing reservations or savings plans, so resizing and committing need to be considered together. Varcio models commitment options from Azure retail prices and your usage, shows projected savings and break-even periods, and supports a dry-run simulation. Reservations can be purchased through Varcio after approval. Savings plans are modelled only, and Varcio does not buy Azure commitments automatically.

What Varcio covers on Azure

  • 1-Year and 3-Year reservations, modelled from Azure retail prices
  • 1-Year savings plans, modelled
  • Projected savings and break-even period for each option
  • Dry-run simulation before purchase
  • Approval-gated reservation purchases with an audit record
Remediation

Remediation with guardrails

From a ranked finding to a completed, audited change, inside the guardrails you set.

Deallocating an idle VM is the classic Azure saving: a deallocated VM releases its hardware lease and stops accruing compute charges, while disks and networking continue to bill. Varcio can carry out that deallocation for you, inside an execution window and with protected resources excluded.

Requests made through Apex come back as a plan listing the affected resources and expected saving, and run only after someone types APPROVE with a single-use token or approves in Slack or Teams. Afterwards Varcio tracks realised savings against subsequent spend, not just the savings it identified.

Example actions on Azure

  • Compute: deallocate or rightsize VMs, stop Application Gateways and App Services, delete App Service plans with no apps, stop Azure Machine Learning compute
  • Cleanup: delete unattached disks and orphaned snapshots, release public IPs, delete unused network interfaces, network security groups and route tables, delete orphaned load balancers
  • Hardening: require secure transport and remove public access on storage, turn on Key Vault soft delete, and turn off public network access for SQL, Key Vault and storage
  • Parking: VMs and scale sets on a schedule

Guardrails every remediation inherits

These controls apply to all remediation Varcio executes, on every cloud, alongside the write permissions you grant and Varcio verifies before anything changes.

Protected-tag exemption

Resources carrying a protected tag are excluded from every remediation run, so a production database or a regulated workload cannot be changed by a rule that happens to match it.

Execution windows

Approved changes run only inside the windows you define, which keeps stops, deletions and resizes away from peak traffic, release trains and change freezes.

Rollout-safety gates

Before a live run, Varcio checks for step-up approval on high blast-radius changes, a rollback success floor, and a maintenance window for larger blast radius. If a gate is not met, the run drops to a dry run instead.

Dry run, action caps and budgets

Any action can be previewed without making live API calls, and individual rules can be held to dry run. Per-rule action caps, a maximum number of actions per run and a monthly action budget bound how much changes at once.

Approval, and Autopilot limits

Write actions requested through Apex come back as a plan that runs only after an authorised person types APPROVE, backed by a single-use token, or approves from Slack or Microsoft Teams. Autopilot runs in observe, suggest or autopilot mode. In autopilot mode it can act without a person above a confidence threshold, including deleting unattached volumes and orphaned snapshots, but resources that look production, public, critical or deletion-protected go to approval instead.

Full audit logging

Every action records who requested it, who approved it, what changed and when, so finance, security and auditors can reconstruct any change after the fact.

Native tools

Microsoft Cost Management, Azure Advisor and Varcio

Microsoft Cost Management and Azure Advisor are included with Azure and do a great deal well. Here is what each provides, according to Microsoft Learn.

Microsoft Cost Management

Cost analysis in the Azure portal and Power BI, budgets on every supported scope, anomaly alerts for subscriptions, scheduled alerts, exports and the Cost Details API, plus tag inheritance and cost allocation rules that split shared costs.

Azure Advisor

Cost recommendations, updated daily, to shut down or resize underutilised VMs and scale sets based on CPU, memory and outbound network, with lookback periods configurable from 7 to 90 days and estimated savings.

Reservations and savings plans

Commitment offers purchased in the Azure portal. Reservation utilisation alerts in Cost Management help you track whether commitments are being used.

Azure native tools and Varcio, capability by capability. Native-tool details are summarised from the provider documentation listed under Sources.
CapabilityAzure native toolsVarcio
Cost visibilityCost analysis across billing accounts, management groups, subscriptions and resource groupsOne normalised ledger across Azure, AWS, Google Cloud, OCI and Kubernetes
Waste and rightsizingAdvisor shutdown and resize recommendations for VMs and scale sets73 Azure detectors, including unattached disks, unused public IPs, idle SQL databases and zero-workload App Service plans
AllocationTag inheritance and cost allocation rules for shared costsTag governance, cost allocation and showback across every connected cloud
Budgets and alertsBudget, anomaly, scheduled and reservation utilisation alertsAnomaly detection, forecasting, budget and policy guardrails, with alerts in Slack or Teams
CommitmentsReservations and savings plans purchased in the Azure portal1- and 3-year reservation and 1-year savings plan modelling, with approval-gated reservation purchases
Acting on findingsChanges made in the portal, CLI or infrastructure code; budgets can notify action groupsPlan confirmed with APPROVE, protected tags, execution windows, rollout-safety gates, dry-run, action caps and audit log
Pre-merge cost reviewNot covered by the tools listed herePR cost review prices Terraform changes before they merge

Scroll sideways to see the full table.

What Varcio adds

For an organisation that runs almost entirely on Azure and has a FinOps function comfortable in Cost Management, the native tooling covers reporting, budgets and allocation well. Varcio adds value when Azure is one of several clouds, when findings need to travel to the team that owns a resource group, and when changes need an approval trail.

Varcio puts Azure in a single ledger with AWS, Google Cloud, OCI and Kubernetes, runs cross-cloud detectors across them, ranks every finding by savings, confidence and effort, reviews infrastructure pull requests for cost before merge, and handles approvals in Slack or Teams. Apex answers spend questions in plain language and turns requests into governed plans.

Teams

Who uses Varcio for Azure

Cost is shared work. Each team sees the same findings and ledger, framed for the decisions it owns.

Platform engineering

Receives findings for the subscriptions and resource groups it owns, with evidence and a recommended action, and sees cost deltas on Terraform pull requests before merge.

FinOps and finance

Allocates Azure cost through tag governance and showback in the same ledger as other clouds, enforces budgets and policies, and reports identified against realised savings.

SRE and operations

Approves deallocations and other changes from Slack or Teams, with protected tags and execution windows keeping critical workloads out of scope.

Engineering leadership

Uses Apex to ask where Azure spend is going and why it changed, and plans a ranked savings backlog alongside other engineering priorities.

FAQ

Azure cost questions, answered

How do I reduce my Azure costs?

Start by deleting unattached disks and unused public IP addresses, and deallocating or removing idle VMs. Then look at idle SQL databases and App Service plans with no workload, and rightsize the VMs that remain. Cover steady usage with reservations or savings plans once sizing is settled, and use budgets, policies and tag governance so the waste does not return. Varcio finds and ranks these opportunities with 73 Azure detectors.

What is the difference between Microsoft Cost Management and Azure Advisor?

Microsoft Cost Management is where you analyse, allocate, budget and export Azure costs. Azure Advisor generates recommendations, including cost recommendations to shut down or resize underutilised VMs and scale sets. Cost Management pulls Advisor cost recommendations in so they appear alongside your spend.

Does Varcio replace Microsoft Cost Management?

It does not need to. Many teams keep using Cost Management for Azure-native reporting. Varcio adds a multi-cloud ledger, 73 Azure detectors plus 23 cross-cloud detectors, costed and ranked findings, PR cost review, and approval-gated execution with a full audit trail.

Is it safe to connect a cost management tool to my Azure subscriptions?

Varcio connects through a Service Principal with an encrypted client ID and secret, and the whole analytical product runs on read-only access for as long as you like. If you want Varcio to act, you grant write roles to the same Service Principal and Varcio verifies them separately. Every write action is protected by tag exemptions, execution windows, rollout-safety gates, dry-run, approval or Autopilot limits, and audit logging.

Does a stopped Azure VM still cost money?

It depends on the state. According to Microsoft, a VM shut down from inside the guest OS or with the PowerOff operation is Stopped (allocated) and still billed for compute. A deallocated VM releases its hardware and is not billed for compute, although disks and networking continue to incur charges.

Can Varcio purchase Azure reservations or savings plans?

Varcio models 1-Year and 3-Year reservations and 1-Year savings plans from Azure retail prices and your usage, shows projected savings and break-even periods, and supports a dry-run simulation. Reservations can be purchased through Varcio after explicit approval, with the purchase recorded in the audit log. Savings plans are modelled only, and Varcio does not buy Azure commitments automatically.

Which Azure data does Varcio read?

The Cost Management Query API and Cost Management FOCUS exports for EA and MCA billing, Azure Resource Graph for inventory and configuration, Azure Monitor for utilisation, Azure Advisor recommendations, reservation utilisation, and Microsoft Graph for Entra ID context.

When will I see Azure findings?

Findings appear from the first scan after you connect a subscription. The free trial runs entirely on read-only access.

Rank your Azure savings from the first scan

Connect a read-only Service Principal, see costed findings across your subscriptions, and grant write access only when you are ready.