Back to blog FinOps & Governance

Azure cost: what a FinOps review typically finds

DN
Drazen Nikolic
| | 10 min read

When organizations talk about Azure cost being too high, it is almost never about prices being too high. It is about nobody being able to say precisely what the money buys. The invoice grows faster than the understanding of it, and at some point the question arises whether moving to the cloud was the right decision at all. In most cases it was. What is missing is control.

Azure bills exactly what was ordered, not what is used. A virtual machine nobody has touched for eight months costs the same as a productive one.

Cost problems are structural problems

A storage account in the wrong access tier costs a multiple of what is necessary. A development system running around the clock costs three times as much as one that is only available during working hours. None of this is exotic. It is the normal result of an environment that grew organically.

The pattern repeats regardless of company size: responsibilities are unclear, and nobody has the mandate to switch something off. That is exactly why a cost review does not start with prices, but with attribution.

The recurring findings

In established environments the same items keep appearing: orphaned resources such as unattached disks, reserved public IP addresses and old snapshots; oversized VMs and databases ordered one size too large and never revisited; dev, test and training systems running at night and on weekends; rarely used data sitting in expensive storage tiers without lifecycle rules; stable base load paid at full on-demand price without reservations; and existing Windows or SQL licenses that are never applied to Azure.

Individually these findings look small. Together they often add up to a noticeable share of the monthly invoice, and none of them requires changing a production application.

Azure Hybrid Benefit: the most frequently unused lever

Organizations with existing Windows Server or SQL Server licenses including Software Assurance can apply those licenses in Azure. The effect is substantial, especially for SQL workloads. Still, in grown environments this benefit is often only partially enabled, for example because new VMs were created from templates where the option was not set.

The check is simple: which VMs run with an Azure-provided Windows license although the organization owns licenses? Switching is often a configuration change rather than a migration. The licensing review upfront matters more than speed here.

Reservations: applied deliberately, not blanket

Reserved capacity significantly lowers cost for predictable base load. The mistake is rarely having no reservations. It is buying them without analysis. Reserving an environment that will be migrated or rebuilt next year ties money to an architecture that will no longer exist.

A useful split is three categories: stable base load (reserve), fluctuating load (on demand), and everything that will change within twelve months anyway (do nothing for now). That split needs usage data across several months, not a snapshot from one Tuesday.

Why tagging is not bureaucracy

Tagging sounds like paperwork and is therefore postponed. In reality it is the precondition for any meaningful cost discussion: without attribution to cost centers, applications and owners, every optimization stays an internal IT exercise.

Once every resource has an owner, the dynamic changes. "The cloud is expensive" becomes, for example, "department X causes 40 % of the cost, 30 % of it in a test environment". Only the second statement leads to a decision.

For this to last, tagging has to be enforced through Azure Policy rather than requested in chat messages. Resources without mandatory tags are either rejected or automatically flagged and tracked.

The real work starts after the review

A cost review delivers a prioritized list of measures with estimated impact. That is the easy part. The hard part is that without guardrails the environment drifts back within months.

What helps is routine: budgets per cost center with alerts, policies for allowed regions and resource types, a monthly cost report to the owners, and a fixed quarterly slot to discuss deviations. Cost control is not a project, it is a routine, comparable to patch management.

An environment where every resource has an owner and a purpose is also safer and easier to operate.

Need an independent view on your Azure environment?

Calandor reviews Azure architecture, cost and security and delivers prioritised findings your team can act on: as an architecture review, a second opinion or a cost and migration analysis.

Book an initial call