Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion docs-mslearn/toolkit/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: FinOps toolkit changelog
description: Review the latest features and enhancements in the FinOps toolkit, including updates to FinOps hubs, Power BI reports, and more.
author: MSBrett
ms.author: brettwil
ms.date: 09/11/2026
ms.date: 10/07/2026
ms.topic: reference
ms.service: finops
ms.subservice: finops-toolkit
Expand All @@ -29,6 +29,7 @@ The following section lists features and enhancements that are currently in deve

- **Added**
- Added VNet and private network modes, including opt-in NAT Gateway support for private mode; NAT Gateway incurs additional cost when enabled ([#2163](https://github.com/microsoft/finops-toolkit/pull/2163)).
- Added Azure Data Explorer disk and double encryption options for FinOps hub deployments ([#2196](https://github.com/microsoft/finops-toolkit/issues/2196)).

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in f12bf19. Changed ms.date to 10/07/2026 to match the current changelog update.

- **Changed**
- Clarified that the FinOps toolkit exclusively manages the FinOps hub virtual network and documented customer-managed private endpoints as the preferred private-access topology, with virtual network peering as a secondary option ([#2156](https://github.com/microsoft/finops-toolkit/issues/2156)).
- Replaced redundant `tolower()` comparisons in hub KQL with case-insensitive operators (`has`, `=~`, `!~`) so the engine can use the term index instead of scanning every row ([#2213](https://github.com/microsoft/finops-toolkit/issues/2213)).
Expand Down
16 changes: 16 additions & 0 deletions src/templates/finops-hub/createUiDefinition.json
Original file line number Diff line number Diff line change
Expand Up @@ -671,6 +671,20 @@
"text": "Configure data retention settings for Azure Data Explorer."
}
},
{
"name": "enableDataExplorerDiskEncryption",
"type": "Microsoft.Common.CheckBox",
"label": "Enable Data Explorer disk encryption",
"toolTip": "Enable disk encryption for the Azure Data Explorer cluster.",
"defaultValue": false
},
{
"name": "enableDataExplorerDoubleEncryption",
"type": "Microsoft.Common.CheckBox",
"label": "Enable Data Explorer double encryption",
"toolTip": "Enable double encryption for the Azure Data Explorer cluster. This setting can only be enabled when the cluster is created.",
"defaultValue": false
},
{
"name": "rawDays",
"type": "Microsoft.Common.TextBox",
Expand Down Expand Up @@ -1006,6 +1020,8 @@
"enableNatGateway": "[steps('advanced').networking.enableNatGateway]",
"virtualNetworkAddressPrefix": "[steps('advanced').networking.virtualNetworkAddressPrefix]",
"dataExplorerSku": "[steps('pricing').dataExplorer.dataExplorerSku]",
"enableDataExplorerDiskEncryption": "[steps('retention').dataExplorer.enableDataExplorerDiskEncryption]",
"enableDataExplorerDoubleEncryption": "[steps('retention').dataExplorer.enableDataExplorerDoubleEncryption]",
"exportRetentionInDays": "[steps('retention').storage.msexportsDays]",
"ingestionRetentionInMonths": "[steps('retention').storage.ingestionMonths]",
"dataExplorerRawRetentionInDays": "[steps('retention').dataExplorer.rawDays]",
Expand Down
8 changes: 8 additions & 0 deletions src/templates/finops-hub/main.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,12 @@ param enableSpotRecommendations bool = false
@description('Optional. Name of the Azure Data Explorer cluster to use for advanced analytics. If empty, Azure Data Explorer will not be deployed. Required to use with Power BI if you have more than $2-5M/mo in costs being monitored. Default: "" (do not use).')
param dataExplorerName string = ''

@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.')
param enableDataExplorerDiskEncryption bool = false

@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.')
param enableDataExplorerDoubleEncryption bool = false

// https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku
@description('Optional. Name of the Azure Data Explorer SKU. Default: "Dev(No SLA)_Standard_D11_v2".')
@allowed([
Expand Down Expand Up @@ -184,6 +190,8 @@ module hub 'modules/hub.bicep' = {
enableAHBRecommendations: enableAHBRecommendations
enableSpotRecommendations: enableSpotRecommendations
dataExplorerName: dataExplorerName
enableDataExplorerDiskEncryption: enableDataExplorerDiskEncryption
enableDataExplorerDoubleEncryption: enableDataExplorerDoubleEncryption
dataExplorerSku: dataExplorerSku
dataExplorerCapacity: dataExplorerCapacity
fabricQueryUri: fabricQueryUri
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,12 @@ param core CoreMetadata
@maxLength(22)
param clusterName string = ''

@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.')
param enableDataExplorerDiskEncryption bool = false

@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.')
param enableDataExplorerDoubleEncryption bool = false

// https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku
@description('Optional. Name of the Azure Data Explorer SKU. Default: "Dev(No SLA)_Standard_E2a_v4".')
@allowed([
Expand Down Expand Up @@ -142,6 +148,13 @@ var ftkReleaseUri = indexOf(finOpsToolkitVersion, '-dev') != -1
var useFabric = !empty(fabricQueryUri)
var useAzure = !useFabric && !empty(clusterName)

var diskEncryptionProperties = !enableDataExplorerDiskEncryption ? {} : {
enableDiskEncryption: true
}
var doubleEncryptionProperties = !enableDataExplorerDoubleEncryption ? {} : {
enableDoubleEncryption: true
}

// cSpell:ignore ftkver, privatelink
var dataExplorerDnsSuffixLookup = {
AzureCloud: 'kusto.windows.net'
Expand Down Expand Up @@ -306,6 +319,8 @@ resource cluster 'Microsoft.Kusto/clusters@2023-08-15' = if (useAzure) {
}
properties: {
enableStreamingIngest: true
...diskEncryptionProperties
...doubleEncryptionProperties
enableAutoStop: false
Comment on lines 321 to 324

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in f12bf19. The encryption properties are now conditionally added only when the corresponding option is enabled, so the default false values do not emit enableDiskEncryption or enableDoubleEncryption during redeployment. This follows the existing conditional property pattern used for storage infrastructure encryption.

publicNetworkAccess: app.hub.options.privateRouting ? 'Disabled' : 'Enabled'
// TODO: Figure out why this is breaking upgrades
Expand Down
8 changes: 8 additions & 0 deletions src/templates/finops-hub/modules/hub.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,12 @@ param fabricCapacityUnits int = 2
@description('Optional. Name of the Azure Data Explorer cluster to use for advanced analytics. If empty, Azure Data Explorer will not be deployed. Required to use with Power BI if you have more than $2-5M/mo in costs being monitored. Default: "" (do not use).')
param dataExplorerName string = ''

@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.')
param enableDataExplorerDiskEncryption bool = false

@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.')
param enableDataExplorerDoubleEncryption bool = false

// https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku
@description('Optional. Name of the Azure Data Explorer SKU. Ignore when using Microsoft Fabric or not deploying Data Explorer. Default: "Dev(No SLA)_Standard_D11_v2".')
@allowed([
Expand Down Expand Up @@ -307,6 +313,8 @@ module analytics 'Microsoft.FinOpsHubs/Analytics/app.bicep' = if (useFabric || u
fabricQueryUri: fabricQueryUri
fabricCapacityUnits: fabricCapacityUnits
clusterName: dataExplorerName
enableDataExplorerDiskEncryption: enableDataExplorerDiskEncryption
enableDataExplorerDoubleEncryption: enableDataExplorerDoubleEncryption
clusterSku: dataExplorerSku
clusterCapacity: dataExplorerCapacity
rawRetentionInDays: dataExplorerRawRetentionInDays
Expand Down
12 changes: 12 additions & 0 deletions src/templates/finops-hub/test/main.test.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -15,4 +15,16 @@ module hub '../main.bicep' = {
}
}

// Test 2 - Creates a FinOps hub with Azure Data Explorer encryption enabled.
module hubWithAdxEncryption '../main.bicep' = {
name: 'finops-hub-adx-encryption'
params: {
hubName: '${uniqueName}-adx'
location: location
dataExplorerName: '${uniqueName}-adx'
enableDataExplorerDiskEncryption: true
enableDataExplorerDoubleEncryption: true
}
}

output hubName string = hub.outputs.name