Skip to main content
orphan · azure

Connection monitors still billing tests after every source VM was deleted

rule IDs covered
1
severity
medium

What does ZopNight detect here?

Azure Network Watcher Connection Monitor bills per test per month beyond the first 10, where a test is one source, destination and test configuration combined. ZopNight flags a connection monitor when every source endpoint it tests from has provably been deleted, so it runs nothing, and reports the monitor's full priced cost as the saving.

Signal and threshold

How ZopNight evaluates Connection monitors still billing tests after every source VM was deleted.
Field Value
Rule IDsRC-1403
Categoryorphan
Severitymedium
Metricnone — pure configuration read
Thresholdall source endpoints deleted
SourceZopNight
Permissions usedMicrosoft.Network/networkWatchers/connectionMonitors/read · Microsoft.Compute/virtualMachines/read

A monitor with no source still counts its tests

Connection Monitor organises checks into test groups of sources, destinations and test configurations, and defines a test as the combination of one source, one destination and one configuration. The Network Watcher pricing page includes the first 10 tests per month and bills every test beyond that per month, for tests created from the portal, PowerShell, CLI or REST.

Sources are the machines that run the checks: Azure VMs, scale sets, or Azure Arc-enabled hosts with the Network Watcher extension. Once those machines are decommissioned, the monitor has nothing to run from, yet its test count and the charge stay in place. This is the usual leftover when a fleet is rebuilt and the monitoring configuration is not.

Listing a monitor’s sources

Connection monitors are regional. List them, then list the endpoints of a suspect monitor and check whether each source resource still exists:

Terminal window
az network watcher connection-monitor list --location <region> -o table
az network watcher connection-monitor endpoint list \
--connection-monitor <monitor> --location <region> -o table
az vm show --ids <source-resource-id> --query name -o tsv

A monitor whose portal view shows no recent results is a strong hint as well.

Proving every source is gone

ZopNight works from the monitor’s enabled test groups: the full list of source resource IDs and the number of billed tests. The finding needs all of the following:

  1. The monitor has at least one billed test.
  2. Not one of its sources appears in ZopNight’s inventory.
  3. Each source sits in a subscription ZopNight actually scans, so its absence is meaningful.
  4. Each source is a type ZopNight would have discovered had it existed: a virtual machine, a scale set, a virtual network or a Log Analytics workspace.
  5. The monitor has a positive price.

Sources that make the verdict unprovable

Azure Arc machines, subnet endpoints and anything in a subscription ZopNight does not scan cannot be proven deleted, so a monitor using any of them gets no finding. The rule also stays silent when only some sources are gone: those tests still run, and splitting the bill would require knowing which sources pair with which destinations and configurations.

Why the whole cost is recoverable

Terminal window
saving = full monthly cost of the connection monitor
cost after fix = 0

A test executes from its source. With every source deleted, no test in the monitor can run, so deleting the monitor loses no data you currently receive.

Clearing out the dead monitor

  1. Open Network Watcher, Connection monitor, and confirm the source endpoints refer to machines that no longer exist.
  2. If the monitoring is still wanted, add the replacement machines as sources and remove the dead ones instead of deleting.
  3. Otherwise delete it: az network watcher connection-monitor delete --location <region> --name <monitor>.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·