Azure AI services accounts with zero API calls that still carry a monthly charge
What does ZopNight detect here?
ZopNight flags an Azure AI services (Cognitive Services) account when its `TotalCalls` metric averages zero with a zero peak over at least 7 days of data, and ZopNight's billing data still shows a monthly cost. That charge is not coming from traffic, so deleting the account or moving it to a free tier removes it.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1378 |
| Category | idle |
| Severity | low |
| Metric | TotalCalls, TokenTransaction |
| Threshold | average and peak = 0 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.CognitiveServices/accounts/read · Microsoft.Insights/Metrics/Read |
Where it applies
How an unused AI services account still costs money
An Azure AI services account that answered no calls should, in principle, have nothing to bill for requests. When ZopNight’s billing data still shows a monthly charge for it, that charge is coming from something other than traffic: a fixed-price tier, or a provisioned model deployment that is billed while it exists. Either way, the account is paying for capacity nobody uses.
Deletion has a detail worth knowing. Microsoft’s recover or purge guide explains that a deleted resource is kept for 48 hours, and that charges for provisioned deployments on a deleted resource continue until it is purged. Delete the deployments first.
Measuring API traffic on an account
az cognitiveservices account list \ --query "[].{name:name, rg:resourceGroup, kind:kind, sku:sku.name}" -o table
az monitor metrics list --resource <account-resource-id> \ --metric TotalCalls TokenTransaction --offset 30d --interval PT24H --aggregation Total MaximumTotalCalls counts calls to the service. Microsoft’s metric reference says not to use it for
Azure OpenAI, where TokenTransaction, the prompt plus generated tokens per deployment, is the
better signal.
The traffic gate ZopNight applies
- The
TotalCallsseries is present for the account. - Its 30-day average is zero.
- The peak on
TotalCalls, and onTokenTransactionwhen that series exists, is also zero. A non-zero peak proves the account was used, even if a nightly batch averages out near zero. - At least 7 days of data, so a new account is not flagged before it goes live.
- A known monthly cost above zero.
Accounts that are not treated as idle
With no TotalCalls data there is no finding, since there is no fallback signal to lean on. Any
burst of calls in the window, however short, also clears the account. And an account with no
cost in the billing data is left alone: there would be nothing to recover.
ZopNight lists this as an advisory finding. It does not change the account for you, because cutting network access, the only toggle it could automate, would not reduce the bill.
Saving is the full monthly charge
saving = current monthly cost of the AI services accountcost after fix = 0 (delete, or downgrade to a free tier where one exists)Removing or downgrading the account
- Check which applications hold its keys or endpoint, and confirm with the owners.
- Delete any model deployments on the account first, so their charges stop at once.
- Delete the account:
az cognitiveservices account delete --resource-group my-rg --name my-account. - Purge it if you need the name back or want to be sure nothing still bills:
az cognitiveservices account purge --location eastus --resource-group my-rg --name my-account. - If the account is still needed occasionally, check
az cognitiveservices account list-skusfor a free tier and move to it instead of deleting.