Lighthouse overview

Prev Next

This article explains how to use Turbo360 with Azure Lighthouse, covering the app registration model, setup steps, and key considerations specific to MSP environments.

Overview


Azure Lighthouse lets managed service providers (MSPs) manage customer Azure subscriptions from a single MSP tenant. When you use Turbo360 in a Lighthouse environment, the app registration that Turbo360 uses to access customer subscriptions lives in your MSP tenant rather than in each customer's tenant. This differs from the standard Turbo360 setup, where the app registration resides in the same tenant as the subscription being managed.

Business value

A single app registration in your MSP tenant can access all delegated customer subscriptions through Lighthouse, eliminating the need to create and maintain separate app registrations in each customer tenant. This simplifies credential management and keeps access control centralised in your MSP tenant.

How it works


Turbo360 authenticates against your MSP tenant using the app registration you create there. Lighthouse then delegates that app registration's access to the customer subscriptions you have onboarded. All cost imports and subscription data flow through that single MSP tenant identity.

App registration in MSP tenant


You create one or more app registrations in your MSP tenant — the service provider tenant. The app registration is granted permission to access customer subscriptions through Lighthouse. How you grant that permission depends on your Lighthouse configuration. Common approaches include:

  • Adding the app registration to a security group in your MSP tenant that has already been delegated the required permissions through Lighthouse.

  • Modifying your Lighthouse configuration directly to include the app registration you will use for Turbo360.

Setup


Configure Lighthouse for each customer in the standard way, ensuring the app registration in your MSP tenant has access to the customer's subscriptions. Then complete the following steps in Turbo360:

  1. When adding the app registration to Turbo360, use the client ID, client secret, and tenant ID from your MSP tenant — not from the customer tenant.

  2. Turbo360 will import cost and subscription data from the delegated subscriptions, authenticating through your MSP tenant.

All other Turbo360 functionality works the same as a standard deployment from this point.

Considerations


Cost Analyzer

  • Reservations and Savings Plans are typically held in your MSP tenant rather than in customer tenants. To surface these in Cost Analyzer, ensure the MSP tenant app registration has permission to read reservation and savings plan data from the MSP tenant.

  • Subscriptions from multiple customers all appear under the MSP tenant. To distinguish between customers, use either separate app registrations per customer or a consistent subscription naming convention that identifies which customer each subscription belongs to.