Skip to main content
resource · azure

Azure Public IP Address

live rule families
1
schedulable
no
category
networking-services

Does ZopNight manage Azure Public IP Address?

Azure public IP addresses bill hourly whether or not they are attached to anything. An address orphaned by a deleted VM keeps metering indefinitely. ZopNight discovers every address with its association state via Resource Graph and flags idle or unassociated IPs with estimated savings, since releasing the address is the only fix.

Rules that fire on Azure Public IP Address

At a glance

Azure Public IP Address coverage facts.
Field Value
Scheduling notesdiscovery and cost visibility only; savings come from releasing unused addresses.

Public IP addresses provide internet-routable endpoints and bill hourly, including when unassociated. Idle public IPs left behind by deleted resources are textbook orphan waste.

Hourly metering that ignores association state

The public IP meter runs by the hour from allocation to deletion, and association is not part of the equation. A Standard-SKU static address bills the same whether it fronts a production load balancer or sits attached to nothing at all. That design makes sense for reservation semantics (the address stays yours), but it also means the meter never pauses on its own. Deleting the VM, NAT gateway, or load balancer an address served does not delete the address; the IP simply becomes an unassociated line item that survives every cleanup pass focused on compute.

ZopNight’s orphan sweep for public IPs

Discovered via Azure Resource Graph with association state. Recommendation rules flag idle and unassociated public IPs with estimated savings, and Cost Management billing attributes spend. ML auto-tagging covers this type. There is nothing to schedule here, since an address has no stop operation and its charge is not usage-driven. The leverage is purely detection: surfacing every address that no longer routes traffic and quantifying what releasing it recovers. Because the fix is a deletion rather than a pause, each flagged IP is a one-decision saving.

How unassociated addresses accumulate

Two habits produce most of the orphans. Tearing down VMs without their networking: the NIC and its address were created alongside the machine but survive its deletion. And environment rebuilds that allocate fresh addresses each time: infrastructure-as-code runs that create rather than reuse leave a trail of prior static IPs, each still metering hourly. A third, quieter pattern is the address reserved “just in case” for a migration that finished a year ago.

Auditing public IPs in the Azure portal

Azure portal → Public IP addresses lists every address in the subscription with its associated-to column. Sort or filter on that column: any row showing no association is billing for an endpoint that leads nowhere, and releasing it ends the charge the same hour.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·