# Azure Showback and Cost Attribution: Cut Cloud Cost

> Showback and Cost Attribution on Azure with ZopNight. Schedule non-production, detect idle, rightsize the oversized. Read-only setup, production excluded by default.

Source: https://zop.dev/azure-showback
Published: 2026-07-01 · Author: avinash-gaurav · Tags: zopnight, azure, showback

---

Team and tag attribution on a unified cost_allocation_daily table. Equal split for shared resources via shareCount. Tags from cloud (AWS tags, GCP labels, Azure tags) and accepted smart tags. Sankey cost flow on Reports for click-to-drill breakdowns.

On Azure, showback and cost attribution starts with the same realization every time: non-production runs around the clock, the same as production while being used a fraction of the time. ZopNight closes that gap against your measured usage, not a projection.

Here is the shape of it. Say a box runs at a typical on-demand rate of $0.17 an hour. Left on around the clock that is about $124 a month, because a month is roughly 730 hours. Confine it to a single-shift work week, about 50 hours, and you pay for 50 hours instead of 730. Your own rate and hours will differ, but the ratio is the point: in non-production, most of the meter runs while nobody is working.

## What ZopNight does on Azure

It discovers your Azure resources through a read-only role, schedules the non-production ones to your working hours, flags the idle and oversized, and reports what each cycle recovered. It ships 490 built-in audit rules across AWS (216), GCP (127), and Azure (147), and 124 of those recommendations are wired to act end to end, 28 one-click and 96 guided.

## Where to start

Begin with scheduling, the fastest, most reversible win, then layer in idle detection and guided rightsizing. See it applied to [Azure EC2](https://zop.dev/zopnight/aws/ec2) and the discipline behind it in [FinOps](https://zop.dev/learn/finops).

## How ZopNight schedules non-production resources

The loop that does this is deliberately mechanical, and it starts read-only. You connect Azure with a read-only role, and ZopNight discovers every non-production resources across your regions and accounts. It records a per-action permission verdict for each one, so you can see where it can list a resource but not yet stop it, and you review that inventory, filter it by status or type, and search for the specific resources you care about before anything is scheduled.

Scheduling itself is a cron you write once in plain terms, stop at 7 PM, start at 8 AM on weekdays, pinned to your timezone so the jobs fire at local business hours rather than UTC. A weekly 24-hour grid shows the schedule visually so you catch gaps and overlaps before you save, and an estimate of active versus inactive hours appears before you commit. Resources attach individually or bundle into groups like "dev-cluster" or "staging-db" so a whole environment follows one cadence.

Actions run in dependency order, so a database comes up before the app server that depends on it. When something needs to stay up, an override forces a non-production resources ON or OFF for a defined window, carries a reason so teammates understand why it exists, and expires automatically so nothing is left running by accident. If a start or stop fails, ZopNight retries up to three times and falls back to a dead-letter queue rather than silently dropping the action, and every state change lands in an audit trail that records whether a schedule, an override, or a specific user triggered it.

## Getting started

Getting started is intentionally low-stakes:

- Connect Azure with a read-only role. Nothing is scheduled or changed at this stage.
- Let ZopNight discover your non-production resources and review exactly what it found, filtered by account, region, and status.
- Create a schedule in your timezone and attach the non-production resources or groups you want it to cover.
- Watch the first cycle run, with Slack, Teams, or Google Chat notifications on every start, stop, and failure, then layer in idle cleanup and guided rightsizing.

Production stays excluded by default throughout, and because discovery and recommendations are read-only, you can prove the value before you enable a single action.

## Frequently asked questions

### Is production at risk on Azure?

No. Production is excluded by default; ZopNight acts only on the non-production Azure resources you choose.

### What access does ZopNight need?

A read-only role to start. Discovery and recommendations run read-only; you enable actions when you are ready.
