Overview
Azure Documenter is a Turbo360 module that generates technical documentation for your Azure subscriptions, covering resource inventory, cost, compliance, and security posture.
Azure Documenter is organized into two areas: Documentation and Diagrams, each covering a distinct aspect of subscription reporting.
Setting up Azure Documenter requires a Service Principal in Microsoft Entra ID with Reader access to the Azure subscriptions you want to document.
Business value
- Produce audit-ready reports on resources, cost, and compliance without manual compilation
- Surface rightsizing and reservation recommendations to support ongoing cost optimization
- Give security and compliance teams a consolidated view of access and security compliance across subscriptions
- Visualize Azure infrastructure across subscriptions without switching to the Azure portal
- Reduce time spent building recurring status reports for stakeholders
- Track carbon emissions and identify sustainability improvements across Azure resources
- Optimize Microsoft 365 licensing with consumption reports and right-sizing recommendations
How it works
Azure Documenter is organized into two sections, accessible from the module's top-level tabs.
Documentation
Generates different document types, each covering a distinct use case. Select the document type in the Basics step of the configuration wizard.
1. Executive summary
Provides a high-level summary of resource inventory and billing for one or more subscriptions. Configurable by billing date range and currency. Use this when you need a concise overview for leadership or stakeholders who want a snapshot of Azure spend and resource posture without detailed breakdowns.
2. Resource details
Provides a comprehensive inventory of all resources across the selected subscriptions, including resource type, configuration, and technical metadata. Use this when you need a full record of what is deployed, for audits, handovers, or change management reviews.
3. Billing details
Provides a detailed cost report with graphical representations of spend by resource, resource group, and subscription over a selected billing period. Use this when finance or operations teams need a breakdown of Azure charges rather than a summary-level view.
4. Security compliance
Provides a security assessment report covering regulatory compliance adherence, policy evaluation results, and security recommendations across the subscription. Use this when you need to demonstrate compliance posture to auditors or internal governance teams.
5. Cost comparison
Provides a side-by-side comparison of Azure spend across two billing periods, highlighting increases and decreases by resource or service. Use this when you need to explain cost changes between months, quarters, or project phases.
6. Resource auditing
Provides a strategic audit of resource states, including idle, stopped, and under-utilized resources, to support governance reviews and cleanup decisions. Use this when you want to identify resources that may no longer be needed or are not being used as intended.
7. Access details - By subscription
Provides a breakdown of role assignments across the selected subscriptions, organized by subscription scope. Configurable to include resource groups and to filter by scope level (subscription, resource group, or individual resource) and role type (built-in or custom). Use this when security or compliance teams need to review who has access to what across all subscriptions.
8. Access details - By type
Provides a breakdown of role assignments grouped by identity type: groups, service principals, and users. Configurable by scope and role filter. Use this when you need to audit access by who holds it rather than what they have access to.
9. Rightsizing recommendations
Provides SKU-level recommendations for resizing over-provisioned or under-utilized resources to better match actual workload demands. Use this when you want to identify cost savings opportunities before a budget review or optimization exercise.
10. Reservation recommendations
Provides recommendations for purchasing Azure Reserved Instances (RI) based on usage patterns, with potential savings of up to 60% compared to pay-as-you-go pricing. Use this when you want to evaluate commitment-based purchasing options to reduce predictable workload costs.
11. Carbon summary
Provides a summary of carbon emissions across your Azure resources and subscriptions. Optionally includes the top 100 resources by carbon impact. Use this when you need an emissions baseline for sustainability reporting or internal environmental governance.
12. Carbon optimizations
Provides recommendations to reduce the Azure carbon footprint across the selected subscription. Covers three emission scopes: Scope 1 (direct emissions), Scope 2 (indirect energy emissions), and Scope 3 (value chain emissions). Use this when you need actionable steps toward emissions reduction targets or ESG reporting commitments.
13. License consumption
Provides a summary of Microsoft 365 licensing SKUs and their service plan inventories, including license allocation, usage, and availability across your tenant. Use this when you need an accurate picture of M365 license utilization before a licensing review or renewal.
14. License optimizations
Identifies opportunities to optimize Microsoft 365 licensing by surfacing unused or underutilized licenses and right-sizing recommendations. Use this when preparing for a licensing audit or reducing unnecessary M365 spend.
15. Service plan matrix
Provides an interactive cross-reference of Microsoft 365 license SKUs and the service plans included in each. Use this when you need to understand what capabilities are included in each license or plan end-user entitlements.
Diagrams
Generates visual maps of your Azure infrastructure across one or more subscriptions. Diagrams are managed from a dedicated Diagrams tab on each document group page and are versioned, so you can compare the current state of your infrastructure against any previous snapshot.
Azure Documenter provides three diagram types:
- Network generates a visual map of your VNet topology, showing virtual networks, subnets, peering connections, and network security groups.
- Workload generates an app stack diagram per resource group, mapping compute, storage, and dependent services.
- Resource visualizer generates a dependency map using Azure Resource Graph (ARG) queries, with support for cross-subscription scoping and external dependencies.
Each diagram can be generated on demand or on a schedule, and exported as draw.io, PNG, or SVG.
Limitations
- Document generation time varies depending on the document type and the volume of resources being processed.
- Cost-related document types (Executive summary, Billing details, Cost comparison, Resource auditing, Rightsizing recommendations) require a currency selection before generation.