Untagged resources cost allocation
02 Oct 2026
Untagged resources: why you can't charge costs back
Ask an Azure administrator to split last month's spend by business unit and you get a chart with four slices and a fifth one, larger than the rest, called Unallocated — or worse, just blank. Everyone agrees it should be fixed. Nobody can say which resources are in it, because the thing you'd use to find out is exactly the thing that's missing. This is not a discipline problem. It's a mechanism problem, and the mechanism is worth understanding before you send another "please tag your resources" email.
The tag isn't on the bill — it's on a copy of it
A tag is a key-value pair stored on the resource, the resource group or the subscription. A cost row is something else entirely: a usage record emitted by the meter, with the tags copied onto it at the moment it was written. That copy is the whole story. Tag a virtual machine today and yesterday's usage records don't change — they were stamped with what the resource carried when they were emitted.
Microsoft is explicit about this in the tag inheritance documentation: inherited tags "are applied to child resource usage records and not the resources themselves". Cost Management is grouping a snapshot, not querying your infrastructure live. Which means a tagging project that ends with "every resource is tagged now" has fixed next month's bill and nothing before it.
Nothing inherits, and that's the whole bug
The intuition almost everyone has — tag the resource group, the resources in
it are covered — is wrong, and it's wrong in one flat sentence in the
docs: "Resources
don't inherit the tags you apply to a resource group or a subscription."
There is no propagation. A resource group tagged CostCenter=Finance
containing forty untagged VMs produces forty untagged cost rows.
Cost Management has a setting that papers over this: tag inheritance, available on Enterprise Agreement billing accounts, Microsoft Customer Agreement billing profiles and individual subscriptions. Turn it on and billing, subscription and resource group tags are stamped onto child resource usage records — the resources stay untagged, but the cost rows stop being blank. It is the single highest-leverage switch in this entire article, and most tenants have never opened the page.
Where a cost row loses its tag
Three distinct failures feed the same bucket, and they need three different answers. Treating them as one "tagging problem" is why the bucket never shrinks:
| What happened | What the bill shows | The actual fix |
|---|---|---|
| Never tagged | Blank tag column, cost lands in Unallocated. | Tag inheritance for the data; an Azure Policy modify rule for the resources. |
| Tagged inconsistently | Two cost centres where you have one — Finance and finance are different values. |
A deny policy with an allowed-values list. Decide the casing once. |
| Can't be tagged | Reservations, savings plans, Marketplace charges, classic resources. | Cost allocation rules, or a split agreed outside Azure. No tag will ever reach these. |
The casing row deserves its own warning. Tag names are
case-insensitive for operations, but the resource provider keeps whatever
casing you typed — and, in Microsoft's words, "you see that casing in cost
reports". Tag values are case-sensitive outright. So
CostCenter=Finance and costcenter=finance are one
logical cost centre and two rows in your chart, and no amount of inheritance
merges them.
Inheritance is not a backfill
Turning the switch on does reach backwards — but only to the first of the current month. Microsoft's own example: enable it on 20 October and child resource usage records are updated from 1 October, using the tags that existed on 20 October. September stays exactly as broken as it was. If you want chargeback for a quarter that has already closed, the answer is a spreadsheet and a conversation, not a setting.
Two behaviours worth knowing before you flip it. First, when a resource tag and an inherited tag share a key, the resource tag wins by default — which is usually right, and is switchable if your policy is that the resource group is authoritative. Second, the note buried at the end of the page: if a purchase or a resource doesn't emit usage at subscription scope, it never gets the subscription tag applied, switch or no switch. That's the residue.
The residue you can't tag
Shared infrastructure is the part tags were never going to solve. One
Log Analytics workspace, one firewall, one ExpressRoute circuit serving six
business units doesn't have six tags — it has one resource and a fight about
who pays. Cost
allocation rules exist for exactly this: pick a subscription, resource group
or tag as the source, pick targets, and distribute by a fixed percentage or
proportionally to the targets' compute, storage, network or total cost. The
rules show up in Cost Analysis and in exports as a
costAllocationRuleName column.
Three limits matter. They don't change your invoice — billing responsibilities are untouched, this is a reporting layer for internal chargeback. They don't support purchases, so reservations and savings plans stay outside the model. And they're EA and MCA only, created by an Enterprise Administrator or a billing account owner, taking up to 24 hours to process.
For the narrower case of "these twelve resources are really one thing",
there's a cheaper trick: the cm-resource-parent tag. Set its value
to the resource ID of a parent resource and Cost Management groups the children
under it in the Resources view, without filters. It's a tag doing structural
work, which is unusual enough to be worth remembering.
Make Unallocated a number you watch
Note that Azure Policy's modify effect doesn't retroactively tag
anything on its own — it alters new and updated requests, and existing
non-compliant resources only get fixed when you run a remediation task. So the
realistic sequence is: enable tag inheritance today so this month's data stops
being blank, assign a modify initiative so new resources arrive
tagged, then run remediation over what already exists. And one hygiene note
while you're in there — tags are stored as plain text and surface in cost
reports, deployment history and exported templates, so a tag value is never the
place for anything sensitive.
What makes this stick isn't the initial cleanup, it's the metric. Untagged spend as a percentage of total spend, watched monthly, is one of the few governance numbers that moves when someone does the work and drifts back up when they stop. It behaves like the orphaned-resource count: a standing report, not a project.
- Group and allocate costs using tag inheritance — inherited tags land on usage records not resources, the EA/MCA/MPA scope list, the 8–24 hour delay, the current-month-only 20 October example, resource tag winning by default, and the purchases-that-emit-no-usage exclusion.
- Use tags to organize your Azure resources — resources don't inherit resource group or subscription tags, the 50-pair and 15-tag limits, tag names case-insensitive but casing preserved in cost reports, values case-sensitive, classic resources unsupported, the plain-text warning, and
cm-resource-parent. - Manage tag governance with Azure Policy — the
modifyeffect withaddversusaddOrReplace,denyon resource groups missing a tag, and that policy doesn't update existing non-compliant resources without a remediation task. - Allocate Azure costs — sources and targets, proportional distribution by compute/storage/network/total, no effect on the invoice, no support for reservations and savings plans, EA/MCA prerequisites, the 24-hour processing window and the
costAllocationRuleNamecolumn.
GraphPaaS reads Azure spend per tenant and breaks it down by resource, type and resource group — the two axes that still work when the tags don't — with the month-by-month drill-down beside them. For an MSP, that's every client's unallocated pile on one screen instead of twenty portal tabs, which is usually the moment the tagging conversation finally gets a budget.
See where your Azure spend actually goes — by resource, type and resource group, across every tenant you manage.
Break down your Azure bill →