Skip to main content
discount · azure

Windows Server VMs paying the pay-as-you-go Windows license instead of using Azure Hybrid Benefit

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a Windows Server VM on Azure whose `licenseType` shows no Azure Hybrid Benefit, meaning the hourly rate still includes the Windows license. If you own Windows Server core licenses with active Software Assurance, switching the VM to `Windows_Server` removes that component. ZopNight prices it from the billed license line, else the Windows minus Linux rate over 730 hours.

Signal and threshold

How ZopNight evaluates Windows Server VMs paying the pay-as-you-go Windows license instead of using Azure Hybrid Benefit.
Field Value
Rule IDsRC-214
Categorydiscount
Severitylow
MetricPercentage CPU, Available Memory Percentage (evidence only)
ThresholdWindows VM, licenseType not set
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read

The license line inside a Windows VM’s hourly rate

A pay-as-you-go Windows VM is charged for two things: the compute, which costs the same as the Linux meter for that size, and the Windows Server license. Microsoft’s reserved instance guide describes the Windows usage meter as split into exactly those two parts. Azure Hybrid Benefit lets you bring on-premises Windows Server core licenses that carry active Software Assurance or a qualifying subscription, and stop paying Azure for the license part.

The switch is a metadata flag: Microsoft notes that changing the license type does not restart the VM or interrupt service.

Listing Windows VMs without the benefit

Terminal window
az vm list \
--query "[?storageProfile.osDisk.osType=='Windows' && licenseType==null].{name:name, rg:resourceGroup, size:hardwareProfile.vmSize}" \
-o table

VMs already on the benefit show licenseType as Windows_Server; the same filter with licenseType=='Windows_Server' lists them.

Which Windows VMs ZopNight considers

  1. The operating system type recorded for the VM is Windows.
  2. The VM is running, or it is deallocated but covered by a reservation or savings plan (the commitment keeps billing, and its license part can still be cut).
  3. No existing license entitlement is recorded: licenseType is not Windows_Server, Windows_Client or AHB, compared without regard to letter case, whether it arrives as a property or as a tag.
  4. The VM has a known monthly cost and a license saving ZopNight can price: the Windows Server license line on your bill, or failing that a Windows and Linux rate pair for its size.

CPU and memory over the last 30 days are attached as context. They do not decide whether the finding fires.

When the license saving is not reported

A stopped or deallocated pay-as-you-go VM is skipped because it is not paying for the license at that moment. So is any VM with neither a billed license line nor a positive Windows minus Linux rate difference. If a rate-card difference comes out above 40% of the VM’s list-price cost, ZopNight drops the finding, since that pattern points to a stale rate pair. A saving taken from the Windows license line on your invoice skips that check. A saving that would equal or exceed the VM’s whole bill is never shown.

Pricing the license component

Terminal window
with billing data: saving = billed Windows license hourly rate x 730 hours
otherwise: saving = (Windows hourly rate - Linux hourly rate) x 730 hours
cost after fix = current monthly cost - saving

This is the license cost only. Compute is unchanged, so the benefit stacks with reservations and savings plans rather than competing with them.

Turning on Azure Hybrid Benefit

  1. Confirm the entitlement with whoever owns licensing: at least 8 core licenses per VM, even for a 4-core size, and as many core licenses as the VM has cores above that. A processor license counts as 16 cores.
  2. Apply it: az vm update --resource-group my-rg --name my-vm --set licenseType=Windows_Server.
  3. Verify with az vm show --resource-group my-rg --name my-vm --query licenseType.
  4. For scale sets, set virtualMachineProfile.licenseType on the scale set model.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·