Dev and test VMs tagged for scheduling whose Azure auto-shutdown is switched off
What does ZopNight detect here?
ZopNight flags a dev or test Azure VM that carries a `schedule` or `auto-shutdown` tag while its Azure auto-shutdown setting is explicitly disabled. The saving is the VM's monthly cost multiplied by the share of hours ZopNight measured it sitting idle, and the recommendation includes a suggested start and stop schedule.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1302 |
| Category | schedule |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | auto-shutdown disabled on a dev/test VM tagged for scheduling |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.DevTestLab/schedules/read · Microsoft.Insights/Metrics/Read |
Where it applies
A tag that promises a shutdown the VM never gets
Azure has a built-in answer for machines that only need to run during working hours. The
auto-shutdown guide
describes turning it on from the VM’s Operations menu, choosing a daily shutdown time, and
optionally being notified first; it can also be set with az vm auto-shutdown. Behind the scenes
the setting is a schedule resource of type Microsoft.DevTestLab/schedules that targets the VM.
The gap this rule looks for is organisational. A team tags a development VM schedule or
auto-shutdown to say it should be switched off out of hours, but the Azure setting itself is still
off, so the VM runs and bills around the clock.
Checking auto-shutdown across your VMs
List the shutdown schedules in the subscription and compare them with your dev and test VMs:
az resource list --resource-type Microsoft.DevTestLab/schedules \ --query "[].{name:name, rg:resourceGroup}" -o table
az vm list --query "[?tags.schedule!=null || tags.\"auto-shutdown\"!=null].{name:name, rg:resourceGroup}" -o tableA tagged VM with no matching schedule, or a schedule that is disabled, is a candidate.
Conditions for flagging a tagged dev VM
- The VM name matches a dev or test pattern (dev, test, qa, staging, sandbox or demo, but not tooling names such as devops, runner, agent, bastion or jumpbox) and neither the name nor an environment tag marks it as production.
- Azure reports auto-shutdown as disabled for the VM. Only if that setting cannot be read does
ZopNight fall back to your own
auto_shutdown=falsetag. With neither saying “false”, nothing is raised. - The VM carries a
scheduleorauto-shutdowntag. - The VM has a monthly cost, and ZopNight has measured its hour-by-hour activity and found idle time.
Dev VMs outside this check
VMs without a scheduling tag are not assessed here; untagged non-production VMs are handled by Azure VM Non-Production Scheduling, which builds a schedule from their activity. When there is no measured idle time, or no cost, the rule produces nothing rather than assume a fixed share of the bill.
Idle share of the monthly bill
monthly saving = VM monthly cost x measured idle fractionThe idle fraction comes from ZopNight’s weekly activity heatmap for the VM, the same data that produces the suggested schedule in the recommendation.
Turning auto-shutdown on
- Check the suggested stop time and time zone in the recommendation against how the team works.
- In the portal, open the VM, then Auto-shutdown, switch it on and set the time.
- Or run
az vm auto-shutdown --resource-group my-rg --name my-dev-vm --time 1900. - Auto-shutdown only stops machines. Start them in the morning manually, with a start schedule, or by applying ZopNight’s suggested schedule, which covers both directions.