How Pump Works with Azure
This page is for Azure account managers who want to understand how Pump operates within the Microsoft Azure ecosystem. For customer-facing setup instructions, see Connecting Your Azure Subscription.
Pump's Azure Partner Status
Program
Authorized Microsoft Azure Partner
Distribution
Ingram Micro
How the Azure Relationship Works
Pump participates in the Microsoft Cloud Solution Provider (CSP) program as an indirect solutions provider through Ingram Micro. When a customer joins Pump on Azure, Pump manages billing and commitment optimization for the customer's Azure subscriptions.
The customer's Azure tenant, subscriptions, resource groups, and workloads remain entirely under the customer's control.
What changes for the customer
Customer pays Microsoft directly
Customer receives a consolidated invoice from Pump
Customer manages their own reservation and savings plan purchases
Pump manages commitment purchases on the customer's behalf (if Autopilot is enabled)
What does not change
The customer retains full ownership and administrative control of their Azure tenant and subscriptions. The customer's existing Microsoft support plan remains active. The customer's AM relationship is unaffected.
How Connection Works
The customer connection flow uses a service principal (application registration) approach:
Service principal creation. The customer runs
az ad sp create-for-rbac --name pumpin Azure Cloud Shell to create a service principal for Pump.Role assignment. The customer runs Pump-provided
azCLI commands to assign specific RBAC roles to the service principal at the subscription or management group level.Credential registration. The customer provides the tenant ID, application ID, and client secret to Pump. Pump authenticates using OAuth2 client credentials.
No ARM templates, Bicep files, or Terraform modules are involved. The setup is done entirely through Azure CLI commands.
Permissions Pump Receives
Read-only role (all customers)
Billing Reader (built-in)
Per subscription
Access to cost and usage data for analysis and dashboards
Autopilot role (customers who opt into automated commitment management)
Pump Autopilot Role (custom)
Management group or tenant
Commitment purchase actions
Reservations Contributor (built-in)
Management group or tenant
Reservation management
Reservations Purchaser (built-in)
Management group or tenant
Reservation purchase execution
Savings Plan Contributor (built-in)
Management group or tenant
Savings plan management
Savings Plan Purchaser (built-in)
Management group or tenant
Savings plan purchase execution
How Commitments Are Managed
Pump analyzes the customer's Azure usage patterns and existing reservation and savings plan portfolio using the Cost Management API. It calculates optimal commitment purchases based on usage trends and existing coverage.
Commitments purchased by Pump are scoped to the customer's own subscriptions. Pump does not pool commitments across customers. If a customer leaves Pump, their reservations and savings plans remain in their subscriptions and run off on their natural expiration schedule.
Customers can choose between two modes:
Autopilot
Pump automatically executes recommended commitment purchases. Customer can block individual recommendations.
Manual
Pump generates recommendations. Customer reviews and explicitly approves before any purchase is made.
Impact on AM Quota
Customer spend that flows through Pump still counts toward the Azure AM's quota and attribution. Pump does not take commission from Azure AMs. Pump's solutions provider model is additive to the AM relationship.
Data Sources Pump Uses
Cost Management API (generateDetailedCostReport)
Detailed cost reports
Cost analysis, dashboards
Consumption API (usageDetails)
Usage detail records
Commitment planning, utilization analysis
Billing API
Billing accounts, profiles, invoice sections
Account structure mapping
Resource Groups API
Resource group listing
Subscription and resource visibility
Reservations/Savings Plan APIs
Existing commitment inventory and utilization
Commitment portfolio management
Data backfill
On first connection with read-only access, Pump pulls up to 90 days of historical cost data (chunked into 7-day jobs). Routine refreshes operate on a 7-day rolling window.
SOC 2 Type II
Pump is SOC 2 Type II certified. Audit reports are available on request through partnerships@pump.co.
Questions?
If you have questions about a specific customer's Pump setup or about Pump's Azure partner status, contact partnerships@pump.co.
Last updated
Was this helpful?

