DDoS Network Protection plans linked to zero virtual networks
What does ZopNight detect here?
Azure DDoS Network Protection plans carry a fixed monthly charge that covers up to 100 public IP resources, whether or not any network uses the plan. ZopNight flags a plan whose count of linked virtual networks is exactly 0 and reports the full monthly charge as the saving, since deleting an unused plan removes the fee entirely.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1366 |
| Category | rightsizing |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | 0 protected virtual networks |
| Source | ZopNight |
| Permissions used | Microsoft.Network/ddosProtectionPlans/read · Microsoft.Network/virtualNetworks/read |
Where it applies
A fixed fee with nothing behind it
The DDoS Protection pricing page describes Network Protection as a fixed monthly charge that includes protection for 100 public IP resources, with extra resources charged per resource per month. One plan can be linked to virtual networks across multiple subscriptions in the tenant, and every protected resource type in a linked network is covered.
Within that 100-resource allowance, the fee is the same whether the plan protects one network, fifty, or none. Plans outlive their networks when an environment is torn down, or when a second plan is created by mistake in another subscription.
Checking which networks a plan protects
az network ddos-protection list \ --query "[].{name:name, group:resourceGroup, vnets:virtualNetworks[].id}" -o json
az network ddos-protection show --resource-group <rg> --name <plan> \ --query "virtualNetworks[].id" -o tsvThe single branch that raises a finding
ZopNight counts the virtual networks that reference each plan when it scans the tenant. The rule fires only when:
- That count is known and is exactly 0.
- The plan has a positive monthly cost.
If the count is missing or unreadable, there is no finding, because a plan that is actually in use must never be reported as empty.
Plans that protect something are left alone
A plan linked to one or more virtual networks gets no finding today. Whether a lightly used plan would be cheaper on the per-IP DDoS IP Protection tier depends on how many public IP resources sit behind it, and a virtual network count is not a reliable stand-in for that: one network can front many addresses through load balancers, application gateways, VPN gateways and VMs. Rather than report a figure built on the wrong axis, the rule stays silent. If you want to test that trade-off, count your protected public IPs and compare the two tiers on the pricing page.
Deleting the plan recovers its whole fee
saving = full monthly cost of the DDoS Network Protection plancost after fix = 0Every Azure resource with a public IP still gets Azure’s built-in infrastructure-level DDoS protection at no additional cost, as the SKU comparison explains. What goes away is the enhanced Network Protection tier.
Removing an unused plan
- Confirm no virtual network in any subscription references the plan, and check with the security team that no rollout is about to link one.
- If any network still points at it, disable protection there first:
az network vnet update --resource-group <rg> --name <vnet> --ddos-protection-plan <plan> --ddos-protection false. - Delete the plan:
az network ddos-protection delete --resource-group <rg> --name <plan>.