Documentation

Troubleshooting

The handful of things that actually go wrong, and what each one means.

"Verify access" does not succeed

In order of likelihood:

  • The assignment has not propagated yet. Azure role assignments can take a minute or two. Wait, then press verify again.
  • Reader was assigned to the wrong principal. Search for TenantThrift under User, group, or service principal — not under users. The onboarding page shows the exact app ID to match.
  • Reader was assigned on a scope you did not mean. A resource group is not enough; assign at subscription or management-group level.
  • Admin consent never completed. If the enterprise application does not exist in your tenant, start the connection again from the dashboard.
  • You do not have the right role in TenantThrift. Verifying requires Editor or Admin.

Subscriptions are missing from the scan scope

Scope is exactly what Reader was granted on. Assign the role on the missing subscriptions and press re-verify in Settings → Scan scope; the list is rebuilt from what can actually be reached.

The scan button does nothing, or refuses

  • Connection not verified — finish onboarding first.
  • Trial or plan lapsed — scanning pauses. The billing page states the reason; picking a plan resumes it immediately.
  • A scan is already running — pressing again joins it instead of starting a second.
  • You are a Reader — running scans requires Editor or Admin.

A colleague signs in and sees nothing

Almost always one of two things:

  • No app role assigned in Entra. Signing in with Microsoft without an assigned TenantThrift app role does not join them to your organization — they land in an empty one of their own. Assign the role (see Users & roles) and have them sign in again.
  • The same Azure tenant is connected from two organizations. The automatic join refuses to guess which one a person belongs to, and does nothing. Delete the duplicate connection and it starts working again.

If neither applies, invite them by email instead — that path does not depend on Entra at all.

Cannot connect a second tenant

Personal and Business allow one connected tenant; MSP and the trial allow any number. Upgrade, or remove the existing connection first.

Checkout asks for a country

Accounts created through Microsoft sign-in never provided one. Pick it once and checkout continues. The United States and Canada are not served.

Cost numbers look wrong or stale

  • The current month is partial — it is marked as such in the trend; do not read it as a drop.
  • Azure's own cost data lags by up to a day or two.
  • Refresh is queued, not instant — the ↻ button hands the job to the background worker.
  • Unattributed spend is real cost without a resource behind it (marketplace, support). It is not a bug and no finding can act on it.

Locked out by two-factor

If you enrolled an authenticator app and lost the device, the code cannot be recovered by us from the outside — write to info@simonvedder.com from the address on the account. For Microsoft sign-in, the reset happens in your own Entra tenant, not here.

Reports do not arrive

  • Check the destination and its cadence under Settings → Notifications — a channel can exist with reports set to off.
  • Reports are attached to scheduled scans; a manual scan does not mail anyone.
  • For Slack or Teams, re-paste the webhook URL — it is stored write-only, so an expired one cannot be checked by looking at it.

Still stuck

Write to info@simonvedder.com with your organization name and roughly when the problem happened. A person answers.