Azure FinOps for managed service providers

FinOps for every customer, from one portal

Add Azure cost optimisation to your services. AzureScan scans your customers' tenants, your consultants turn the recommendations into work, and your customers approve in their own portal.

Your customers, for you onlyYour own team and rolesNo guest accounts
AzureScan dashboard with monthly Azure spend and savings per area (demo)

Demo environment with fictional customer data

Why MSPs choose AzureScan

Everything you need to offer FinOps as a service

All customers, one overview

Every customer tenant with savings per area, last scan and the status of every action. No separate tool per customer.

Your own team

Your administrator adds colleagues as admin or consultant. Everyone signs in with your organisation's own work accounts.

Customers decide with you

Your customer gets a portal with a report and savings tracker, and approves or dismisses actions, down to the resource.

Concrete work packages

Every approved action lists exactly which resources, what to do and the risk. Ready to plan and carry out.

Provable savings

After 30 days AzureScan compares the actual cost with the cost before the change, so you can show the value of your work.

Monthly overview

A monthly report of your connected customers: new, ended and active, with CSV export.

How it works

How it works for you and your customers

  1. Connect a customer

    You add the customer tenant. The customer's administrator gives consent and runs a short script for read-only access.

  2. First scan

    AzureScan reads costs, metrics and configuration. Your consultants see the recommendations in the consultant view.

  3. Report and decision

    You release the report. The customer approves what they want in their own portal, per action or per resource.

  4. Implement and follow up

    Your team carries out the actions. AzureScan recognises what was done and measures the saving on the bill.

Your team, your customers

Your organisation's administrators manage who has access and see the monthly overview of connected customers.

  • Admin and consultant roles
  • Sign in with your own organisation's work accounts
  • Monthly overview with CSV export
MSP team management and monthly overview of connected customers in AzureScan (demo)

Demo environment with fictional customer data

A portal your customer understands

Your customer sees no technical noise, but a report with actions, savings and risk, and decides for themselves.

  • Approve or dismiss per resource
  • A reason with every dismissal, visible to your team
  • Savings tracker with measured results
Assessment report with Azure savings per resource, approved disk by disk (demo)

Demo environment with fictional customer data

What AzureScan checks

From virtual machines to licences

Virtual machines

Downsize oversized VMs within their family, switch off idle test VMs, run development VMs on a schedule and replace older generations with cheaper ones.

Storage

Unattached disks, old snapshots, Premium disks on test systems, over-provisioned file shares, geo-redundancy without a reason and missing lifecycle management.

Networking

Public IP addresses, load balancers, application gateways, NAT and VPN gateways that are still billed but no longer used.

Platform services

Empty App Service plans, and Log Analytics workspaces with long retention or a commitment tier that doesn't match their volume.

Licences

Use the Windows Server and SQL Server licences you already own through Azure Hybrid Benefit, without assigning more cores than you have.

Reservations

Underused reservations, reservations about to expire, and which VMs are worth reserving, decided per VM.

Security

Designed to be trusted

AzureScan looks, but never touches. You stay in control of what changes.

Read-only access

AzureScan gets the Reader, Cost Management Reader and (optionally) Reservations Reader roles. It cannot change anything in your environment.

No agents, nothing to install

Everything goes through the official Azure APIs. No software on your servers, no network changes.

Hosted in Belgium

The dashboard and your data live in an Azure data centre in Belgium (Belgium Central).

Sign in with Microsoft

Everyone signs in with their own work account through Microsoft Entra. No extra passwords, no guest accounts.

Strictly separated

Each customer sees only its own data. An MSP sees only its own customers, never anyone else's.

Revoke at any time

Remove the AzureScan app from your tenant and access ends immediately. On request we delete your data completely.

FAQ

Frequently asked questions

Do our customers need to install anything?

No. The customer's administrator gives the AzureScan app consent once and runs a short script that grants read-only roles. No software goes into their environment.

Can AzureScan change anything in a customer's environment?

No. AzureScan only has read access. Changes are made by your team, with your own tools and procedures.

Can other MSPs see our customers?

Never. Each MSP sees only its own customers, and each customer only its own data.

Do our consultants need guest accounts?

No. Your colleagues sign in with the work account of your own Microsoft Entra tenant. Your administrator decides who gets access.

What about multi-factor authentication (MFA)?

MFA is required for every user on your team. You enforce it with your own tenant's security settings, just as for Microsoft 365.

Where is the data stored?

In an Azure data centre in Belgium. When a customer leaves, you delete their data with one click.

Ready to add FinOps to your services?

Get in touch. We'll show you the platform and discuss how it fits your customers and the way you work.

Contact us →