Untagged resources cost allocation

02 Oct 2026

Untagged resources: why you can't charge costs back

Ask an Azure administrator to split last month's spend by business unit and you get a chart with four slices and a fifth one, larger than the rest, called Unallocated — or worse, just blank. Everyone agrees it should be fixed. Nobody can say which resources are in it, because the thing you'd use to find out is exactly the thing that's missing. This is not a discipline problem. It's a mechanism problem, and the mechanism is worth understanding before you send another "please tag your resources" email.

0
tags a resource inherits by default
50
tag pairs per resource (15 on some)
8–24h
before inheritance reaches the data
1 month
how far back a fix reaches

The tag isn't on the bill — it's on a copy of it

A tag is a key-value pair stored on the resource, the resource group or the subscription. A cost row is something else entirely: a usage record emitted by the meter, with the tags copied onto it at the moment it was written. That copy is the whole story. Tag a virtual machine today and yesterday's usage records don't change — they were stamped with what the resource carried when they were emitted.

Microsoft is explicit about this in the tag inheritance documentation: inherited tags "are applied to child resource usage records and not the resources themselves". Cost Management is grouping a snapshot, not querying your infrastructure live. Which means a tagging project that ends with "every resource is tagged now" has fixed next month's bill and nothing before it.

Nothing inherits, and that's the whole bug

The intuition almost everyone has — tag the resource group, the resources in it are covered — is wrong, and it's wrong in one flat sentence in the docs: "Resources don't inherit the tags you apply to a resource group or a subscription." There is no propagation. A resource group tagged CostCenter=Finance containing forty untagged VMs produces forty untagged cost rows.

Cost Management has a setting that papers over this: tag inheritance, available on Enterprise Agreement billing accounts, Microsoft Customer Agreement billing profiles and individual subscriptions. Turn it on and billing, subscription and resource group tags are stamped onto child resource usage records — the resources stay untagged, but the cost rows stop being blank. It is the single highest-leverage switch in this entire article, and most tenants have never opened the page.

The mechanism
Two different objects carry tags: the resource (what you edit) and the usage record (what you group by). Tagging fixes the first. Only tag inheritance — or a policy that writes the tag onto the resource before the meter fires — fixes the second.

Where a cost row loses its tag

HOW ONE COST ROW GETS ITS TAG — OR DOESN'T Resource carries the tag? the value on the resource itself Tag inheritance enabled? billing account, profile or subscription Parent scope tagged? resource group or subscription yes no no yes yes no Tagged the resource value wins by default Unallocated nothing to fall back on Tagged by inheritance current month only, 8–24h to land Unallocated nothing above it is tagged either Purchases and resources that emit no usage at subscription scope skip this tree entirely — they never inherit.

Three distinct failures feed the same bucket, and they need three different answers. Treating them as one "tagging problem" is why the bucket never shrinks:

What happened What the bill shows The actual fix
Never tagged Blank tag column, cost lands in Unallocated. Tag inheritance for the data; an Azure Policy modify rule for the resources.
Tagged inconsistently Two cost centres where you have one — Finance and finance are different values. A deny policy with an allowed-values list. Decide the casing once.
Can't be tagged Reservations, savings plans, Marketplace charges, classic resources. Cost allocation rules, or a split agreed outside Azure. No tag will ever reach these.

The casing row deserves its own warning. Tag names are case-insensitive for operations, but the resource provider keeps whatever casing you typed — and, in Microsoft's words, "you see that casing in cost reports". Tag values are case-sensitive outright. So CostCenter=Finance and costcenter=finance are one logical cost centre and two rows in your chart, and no amount of inheritance merges them.

Inheritance is not a backfill

Turning the switch on does reach backwards — but only to the first of the current month. Microsoft's own example: enable it on 20 October and child resource usage records are updated from 1 October, using the tags that existed on 20 October. September stays exactly as broken as it was. If you want chargeback for a quarter that has already closed, the answer is a spreadsheet and a conversation, not a setting.

Two behaviours worth knowing before you flip it. First, when a resource tag and an inherited tag share a key, the resource tag wins by default — which is usually right, and is switchable if your policy is that the resource group is authoritative. Second, the note buried at the end of the page: if a purchase or a resource doesn't emit usage at subscription scope, it never gets the subscription tag applied, switch or no switch. That's the residue.

The residue you can't tag

Shared infrastructure is the part tags were never going to solve. One Log Analytics workspace, one firewall, one ExpressRoute circuit serving six business units doesn't have six tags — it has one resource and a fight about who pays. Cost allocation rules exist for exactly this: pick a subscription, resource group or tag as the source, pick targets, and distribute by a fixed percentage or proportionally to the targets' compute, storage, network or total cost. The rules show up in Cost Analysis and in exports as a costAllocationRuleName column.

Three limits matter. They don't change your invoice — billing responsibilities are untouched, this is a reporting layer for internal chargeback. They don't support purchases, so reservations and savings plans stay outside the model. And they're EA and MCA only, created by an Enterprise Administrator or a billing account owner, taking up to 24 hours to process.

For the narrower case of "these twelve resources are really one thing", there's a cheaper trick: the cm-resource-parent tag. Set its value to the resource ID of a parent resource and Cost Management groups the children under it in the Resources view, without filters. It's a tag doing structural work, which is unusual enough to be worth remembering.

Make Unallocated a number you watch

Note that Azure Policy's modify effect doesn't retroactively tag anything on its own — it alters new and updated requests, and existing non-compliant resources only get fixed when you run a remediation task. So the realistic sequence is: enable tag inheritance today so this month's data stops being blank, assign a modify initiative so new resources arrive tagged, then run remediation over what already exists. And one hygiene note while you're in there — tags are stored as plain text and surface in cost reports, deployment history and exported templates, so a tag value is never the place for anything sensitive.

What makes this stick isn't the initial cleanup, it's the metric. Untagged spend as a percentage of total spend, watched monthly, is one of the few governance numbers that moves when someone does the work and drifts back up when they stop. It behaves like the orphaned-resource count: a standing report, not a project.

Sources
  • Group and allocate costs using tag inheritance — inherited tags land on usage records not resources, the EA/MCA/MPA scope list, the 8–24 hour delay, the current-month-only 20 October example, resource tag winning by default, and the purchases-that-emit-no-usage exclusion.
  • Use tags to organize your Azure resources — resources don't inherit resource group or subscription tags, the 50-pair and 15-tag limits, tag names case-insensitive but casing preserved in cost reports, values case-sensitive, classic resources unsupported, the plain-text warning, and cm-resource-parent.
  • Manage tag governance with Azure Policy — the modify effect with add versus addOrReplace, deny on resource groups missing a tag, and that policy doesn't update existing non-compliant resources without a remediation task.
  • Allocate Azure costs — sources and targets, proportional distribution by compute/storage/network/total, no effect on the invoice, no support for reservations and savings plans, EA/MCA prerequisites, the 24-hour processing window and the costAllocationRuleName column.

GraphPaaS reads Azure spend per tenant and breaks it down by resource, type and resource group — the two axes that still work when the tags don't — with the month-by-month drill-down beside them. For an MSP, that's every client's unallocated pile on one screen instead of twenty portal tabs, which is usually the moment the tagging conversation finally gets a budget.

GraphPaaS

See where your Azure spend actually goes — by resource, type and resource group, across every tenant you manage.

Break down your Azure bill →

Newsletter

Get the next article by email

Practical M365 & Azure cost pieces like this one. No spam, unsubscribe anytime.