A tagging model for Azure cost allocation should be short, enforced, and inherited. Require an owner or team tag, a cost centre or product tag, and an environment tag, apply them with Azure Policy at creation, and inherit them from resource groups so engineers do not have to remember. That gets the majority of spend cleanly attributed. The remaining judgement calls are how to split shared platform costs and how to drive down the untagged pool, both of which are policy and agreement problems rather than technical ones.
This is the allocation companion to Azure Cost Management: strengths and gaps and the biggest Azure waste categories. Cost Management reports the numbers; tagging is what makes those numbers land on the team that can act.
What tags do you actually need?
Allocation fails far more often from too many tags than too few. A long taxonomy looks thorough and gets applied inconsistently, which means nothing reconciles. Start with three mandatory tags and earn the right to add more.
- Owner or team. Who is accountable for this resource. This is the tag that turns a cost line into a conversation with a named owner.
- Cost centre or product. The financial or product dimension finance and leadership care about, so the allocation maps to how the business is run.
- Environment. Production, staging, development. This one alone surfaces a surprising amount of waste, because non production spend that nobody owns is among the most common Azure waste categories.
Anything beyond these should justify itself. A fourth or fifth tag is fine if a real report depends on it, but every optional tag is one more thing to enforce and reconcile.
How do you enforce tags on Azure?
Enforcement at creation is the whole game. A tag applied by hope is a tag that is missing on a quarter of resources by month end. Two mechanisms do the work.
Azure Policy to require and inherit
Use Azure Policy to require the mandatory tags when a resource is created, and to inherit tags from the parent resource group where a resource does not set its own. Inheritance is the unsung hero: engineers tag the resource group once, and the resources inside pick the tags up, so the human effort is small and the coverage is high.
Management groups for reach
Apply the policy at the management group level so it covers every subscription, including new ones created later. A tagging standard that only applies to today's subscriptions decays the moment someone spins up a new one. We cover the structure in the subscription and management group material linked from the pillar guide.
Buyer takeaway: prevention beats clean up. The cost of a policy that blocks or auto tags at creation is trivial against the cost of an analyst reconciling untagged spend every month.
How do you allocate shared and untagged costs?
Even with good tagging, two pools resist attribution: genuinely shared costs and the untagged remainder. Handle them explicitly and publicly.
Shared costs, such as shared networking, reserved capacity benefits, or a platform team's services, split by an agreed key. Common keys are each team's share of directly tagged spend, or a usage metric. The key matters less than agreeing it openly, because an allocation teams did not see the logic for is an allocation they will dispute. Reservation and Azure Savings Plan benefits in particular need a rule for who gets the discount.
Untagged costs should shrink over time, not be redistributed forever. Track the untagged percentage as a health metric, set a target, and use policy to push it down. A small untagged pool can be spread by the same key as shared costs; a large one is a signal your enforcement is not working yet.
A worked example
A Fortune 500 retailer had over a dozen tags in its standard and roughly a third of Azure spend untagged, so allocation reports were argued about rather than acted on. We cut the mandatory set to three tags, enforced them with Azure Policy at the management group level with resource group inheritance, and published a single rule for splitting shared networking and reservation benefits. Within two reporting cycles untagged spend fell into the low single digits, and the monthly cost review shifted from disputing the numbers to deciding what to cut. The savings did not come from tagging itself; they came from owners finally seeing costs they could act on. Figures are verified against billing data and anonymised.
Frequently asked questions
What tags do you need for Azure cost allocation?
How do you enforce tags on Azure?
How do you allocate shared and untagged costs?
Where allocation fits the program
Tagging is the foundation that makes budgets, showback, and unit economics possible. Without it, every other FinOps discipline argues about whose cost is whose. We install allocation models that hold up as an independent buyer side advisory across AWS, Azure, GCP, and OCI, with zero provider commissions and a guarantee: we reduce your cloud spend or we reimburse our service fee.
For monthly buyer side analysis, subscribe to The Cloud Spend Navigator.
Put a defensible number on your cloud spend.
No provider in the room, no published price list. Tell us your footprint and we will scope the savings against your billing data — we reduce your cloud spend or we reimburse our service fee.
The Cloud Spend Navigator: what changed in cloud pricing, commitments, and FinOps — no vendor spin.