Skip to main content
resource · azure

Azure Private Endpoint

schedulable
no
category
networking-services

Does ZopNight manage Azure Private Endpoint?

Azure private endpoints bill per hour from creation plus a per-GB charge on data processed, and the hourly meter runs whether or not the target PaaS service still exists. ZopNight discovers each `private-endpoint` via Resource Graph and attributes spend through Cost Management; it does not record the target service, and no rule flags endpoints whose targets are missing.

Rules that fire on Azure Private Endpoint

no live rules

No active rule family targets Azure Private Endpoint today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Browse every live recommendation for this platform →

At a glance

Azure Private Endpoint coverage facts.
Field Value
Scheduling notesdiscovery and cost visibility only.

Private endpoints inject a private IP for a PaaS service into your VNet, billed hourly plus data processed. Endpoints pointing at deleted services keep billing silently.

A private endpoint runs two meters from the moment it exists: an hourly resource charge, and a per-gigabyte charge on data processed through the link. Neither depends on whether the endpoint is used. An endpoint carrying production database traffic and an endpoint whose target was deleted last quarter pay the identical hourly rate. The per-GB component simply drops to nothing on the dead one, leaving a clean, constant charge with no workload behind it. Because a security-conscious estate creates an endpoint per service per VNet, the count multiplies quickly: one storage account reached from three networks is three endpoints, each on its own meter.

Target-service linkage as orphan evidence

Discovered via Azure Resource Graph. Cost Management billing attributes spend. ZopNight does not record each endpoint’s target or flag orphaned endpoints automatically, but in Azure the linkage is the discriminating fact: an endpoint always names the PaaS resource it fronts, so joining endpoints against the live resource inventory cleanly separates working private-link paths from husks. Private endpoints are discovery and cost visibility only: there is no stop operation, and the hourly charge cannot be paused, only ended by deletion.

Endpoints that outlive their targets

Deleting a storage account, SQL database, or key vault does not delete the private endpoints pointing at it. The endpoint stays, bills hourly, and keeps a private IP and DNS record alive that now leads nowhere. The same residue appears when environments are cloned: infrastructure-as-code that stamps out endpoints per environment leaves a full set behind whenever an environment is torn down incompletely. A third pattern is duplication, with two endpoints from the same VNet to the same service after a rebuild, one of them idle forever.

Private endpoint inventory in the portal

Azure portal → Private endpoints (under Private Link Center) lists each endpoint with its target resource and connection state. Endpoints whose target shows as deleted or disconnected are the deletion candidates, and ZopNight’s cost view shows what each has accumulated.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·