Skip to main content
schedule · azure

Dev and test VMs tagged for scheduling whose Azure auto-shutdown is switched off

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags a dev or test Azure VM that carries a `schedule` or `auto-shutdown` tag while its Azure auto-shutdown setting is explicitly disabled. The saving is the VM's monthly cost multiplied by the share of hours ZopNight measured it sitting idle, and the recommendation includes a suggested start and stop schedule.

Signal and threshold

How ZopNight evaluates Dev and test VMs tagged for scheduling whose Azure auto-shutdown is switched off.
Field Value
Rule IDsRC-1302
Categoryschedule
Severitymedium
Metricnone — pure configuration read
Thresholdauto-shutdown disabled on a dev/test VM tagged for scheduling
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.DevTestLab/schedules/read · Microsoft.Insights/Metrics/Read

A tag that promises a shutdown the VM never gets

Azure has a built-in answer for machines that only need to run during working hours. The auto-shutdown guide describes turning it on from the VM’s Operations menu, choosing a daily shutdown time, and optionally being notified first; it can also be set with az vm auto-shutdown. Behind the scenes the setting is a schedule resource of type Microsoft.DevTestLab/schedules that targets the VM.

The gap this rule looks for is organisational. A team tags a development VM schedule or auto-shutdown to say it should be switched off out of hours, but the Azure setting itself is still off, so the VM runs and bills around the clock.

Checking auto-shutdown across your VMs

List the shutdown schedules in the subscription and compare them with your dev and test VMs:

Terminal window
az resource list --resource-type Microsoft.DevTestLab/schedules \
--query "[].{name:name, rg:resourceGroup}" -o table
az vm list --query "[?tags.schedule!=null || tags.\"auto-shutdown\"!=null].{name:name, rg:resourceGroup}" -o table

A tagged VM with no matching schedule, or a schedule that is disabled, is a candidate.

Conditions for flagging a tagged dev VM

  1. The VM name matches a dev or test pattern (dev, test, qa, staging, sandbox or demo, but not tooling names such as devops, runner, agent, bastion or jumpbox) and neither the name nor an environment tag marks it as production.
  2. Azure reports auto-shutdown as disabled for the VM. Only if that setting cannot be read does ZopNight fall back to your own auto_shutdown=false tag. With neither saying “false”, nothing is raised.
  3. The VM carries a schedule or auto-shutdown tag.
  4. The VM has a monthly cost, and ZopNight has measured its hour-by-hour activity and found idle time.

Dev VMs outside this check

VMs without a scheduling tag are not assessed here; untagged non-production VMs are handled by Azure VM Non-Production Scheduling, which builds a schedule from their activity. When there is no measured idle time, or no cost, the rule produces nothing rather than assume a fixed share of the bill.

Idle share of the monthly bill

Terminal window
monthly saving = VM monthly cost x measured idle fraction

The idle fraction comes from ZopNight’s weekly activity heatmap for the VM, the same data that produces the suggested schedule in the recommendation.

Turning auto-shutdown on

  1. Check the suggested stop time and time zone in the recommendation against how the team works.
  2. In the portal, open the VM, then Auto-shutdown, switch it on and set the time.
  3. Or run az vm auto-shutdown --resource-group my-rg --name my-dev-vm --time 1900.
  4. Auto-shutdown only stops machines. Start them in the morning manually, with a start schedule, or by applying ZopNight’s suggested schedule, which covers both directions.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·