How to Manage Multiple Azure Subscriptions Without Losing Track
The portal shows you one subscription at a time, and the free tool that shows you all of them will hand you a partial answer without saying so.
Nobody sets out to have six Azure subscriptions. You get them one reasonable decision at a time. A client needed their own billing. Someone split dev from prod. A team inherited one in an acquisition. Each choice made sense on the day.
Then one morning somebody asks what you are spending in total, or whether anything anywhere has port 22 open, and you realise you have no way to answer that does not involve clicking through six portals and a spreadsheet.
The portal is showing you less than you think
Start by checking your subscription filter. Top right of the portal, the Directories and subscriptions panel. There is a good chance a filter is set from something you did months ago, and every list you have looked at since has been quietly excluding subscriptions.
This is the first thing to rule out, because it makes everything else below pointless. You cannot manage what the screen is hiding.
The free tool almost nobody uses
Azure Resource Graph queries across all your subscriptions at once. It is free, it is already enabled, and it is in your portal right now under Resource Graph Explorer.
You are probably using it without knowing. Microsoft notes that Resource Graph "powers Azure portal's search bar, the new browse All resources experience, and Azure Policy's Change history". The engine behind the screens you already click is available to you directly, and directly is where it gets useful.
The query language is KQL, the same one Azure Data Explorer uses. It looks intimidating for about ten minutes and then it does not. A query that counts every resource type across every subscription you can see is one line:
resources | summarize count() by type | order by count_ desc
That is the inventory question answered for the whole estate, in one box, for free. The three or four queries you write in your first session will answer more questions than a month of clicking.
The trap: it will give you a partial answer and not tell you
This is the part to actually remember, and it is the reason multi-subscription audits go wrong.
Resource Graph only returns what you have permission to read. That is correct and expected. What is dangerous is how it behaves when you are missing permission on some of them. Microsoft's own wording: "you get resource groups that you can access, without any indication that the result might be partial".
Without any indication. You run a query asking what is exposed to the internet across the company, you get four results, and you feel good about it. The two subscriptions you do not have read access to contributed nothing, and nothing on screen said so.
The only defence is to count first. Get the list of subscriptions you can actually see, compare it against the list you believe exists, and reconcile the difference before you trust a single answer. If you have no access to any subscription in the list, you get a 403, which is at least honest. The silent partial is the one that bites.
One more thing worth knowing about the same tool: the data "isn't strongly consistent", it is "indexed with a short latency". For inventory questions that is fine. For "did my change land", go and look at the resource itself.
Seeing what changed, across everything
Resource Graph keeps "the last 14 days of resource configuration changes to see which properties changed and when", across subscriptions.
Fourteen days is not an audit trail and it is not meant to be one. It is exactly the window you need for the question that actually gets asked, which is always some version of "this worked last week, what changed". Before you start bisecting your own application, spend two minutes here.
Money across subscriptions
Cost Management works on a scope. Open it inside a subscription and you see that subscription, which is the default and the reason people think there is no combined view.
Change the scope to the billing account or a management group and you get the total, with subscription as something you can group by. That single change turns six separate cost conversations into one.
Set a budget at that higher scope as well as the per-subscription ones. A subscription that doubles is easy to miss when it is small. A total that moves is not.
When management groups are worth it
A management group is a container above subscriptions. Permissions and policies you set on it flow down to everything underneath.
With two or three subscriptions, skip it. The setup cost is not repaid and you will spend longer explaining the hierarchy than it saves.
It starts earning its place when you find yourself making the same role assignment in several places, or when you want one rule to be true everywhere. Assigning a role once at the management group instead of five times is both less work and less likely to drift, and drift is the actual enemy here. Five copies of a rule become five different rules eventually.
One thing to know before you do it: you cannot put a resource lock on a management group. Locks stop at the subscription level.
The part that does not scale
All of the above works. The reason people still end up with a spreadsheet is that none of it is one place. Inventory is Resource Graph, money is Cost Management at a different scope, permissions are per subscription, and changes are a fourteen day window in a third screen.
You can hold that in your head for two subscriptions. At six you are doing a join in your head every time somebody asks a question, and the join is where the mistakes live.
The shorter way
Liberra connects each subscription once and then stops caring how many there are. It keeps an index of all of them together, so a question is just a question: what is running everywhere, what am I spending in total, which subscription has something open to the internet.
The account selector in the interface is a view filter and nothing more. It changes what you are looking at, never what the AI can reach. So you never get the silent partial answer, because the answer is not scoped to whichever subscription you happened to have selected.
It also connects through Azure Lighthouse, the same delegation model Microsoft built for service providers managing many customers. You approve it in your own portal, per subscription, and removing the delegation removes the access.
And across every one of them, it cannot delete anything. The delete commands are blocked in the code rather than in a permission you would have to get right six times. Every write waits for your approval first. Six subscriptions is six times the surface area for a mistake, which is exactly when a tool that cannot make the worst one starts to matter.
Founder, Liberra AI