Skip to main content
idle · azure

Azure AI services accounts with zero API calls that still carry a monthly charge

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Azure AI services (Cognitive Services) account when its `TotalCalls` metric averages zero with a zero peak over at least 7 days of data, and ZopNight's billing data still shows a monthly cost. That charge is not coming from traffic, so deleting the account or moving it to a free tier removes it.

Signal and threshold

How ZopNight evaluates Azure AI services accounts with zero API calls that still carry a monthly charge.
Field Value
Rule IDsRC-1378
Categoryidle
Severitylow
MetricTotalCalls, TokenTransaction
Thresholdaverage and peak = 0
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.CognitiveServices/accounts/read · Microsoft.Insights/Metrics/Read

How an unused AI services account still costs money

An Azure AI services account that answered no calls should, in principle, have nothing to bill for requests. When ZopNight’s billing data still shows a monthly charge for it, that charge is coming from something other than traffic: a fixed-price tier, or a provisioned model deployment that is billed while it exists. Either way, the account is paying for capacity nobody uses.

Deletion has a detail worth knowing. Microsoft’s recover or purge guide explains that a deleted resource is kept for 48 hours, and that charges for provisioned deployments on a deleted resource continue until it is purged. Delete the deployments first.

Measuring API traffic on an account

Terminal window
az cognitiveservices account list \
--query "[].{name:name, rg:resourceGroup, kind:kind, sku:sku.name}" -o table
az monitor metrics list --resource <account-resource-id> \
--metric TotalCalls TokenTransaction --offset 30d --interval PT24H --aggregation Total Maximum

TotalCalls counts calls to the service. Microsoft’s metric reference says not to use it for Azure OpenAI, where TokenTransaction, the prompt plus generated tokens per deployment, is the better signal.

The traffic gate ZopNight applies

  1. The TotalCalls series is present for the account.
  2. Its 30-day average is zero.
  3. The peak on TotalCalls, and on TokenTransaction when that series exists, is also zero. A non-zero peak proves the account was used, even if a nightly batch averages out near zero.
  4. At least 7 days of data, so a new account is not flagged before it goes live.
  5. A known monthly cost above zero.

Accounts that are not treated as idle

With no TotalCalls data there is no finding, since there is no fallback signal to lean on. Any burst of calls in the window, however short, also clears the account. And an account with no cost in the billing data is left alone: there would be nothing to recover.

ZopNight lists this as an advisory finding. It does not change the account for you, because cutting network access, the only toggle it could automate, would not reduce the bill.

Saving is the full monthly charge

Terminal window
saving = current monthly cost of the AI services account
cost after fix = 0 (delete, or downgrade to a free tier where one exists)

Removing or downgrading the account

  1. Check which applications hold its keys or endpoint, and confirm with the owners.
  2. Delete any model deployments on the account first, so their charges stop at once.
  3. Delete the account: az cognitiveservices account delete --resource-group my-rg --name my-account.
  4. Purge it if you need the name back or want to be sure nothing still bills: az cognitiveservices account purge --location eastus --resource-group my-rg --name my-account.
  5. If the account is still needed occasionally, check az cognitiveservices account list-skus for a free tier and move to it instead of deleting.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·