Skip to main content
orphan · azure

Standard public IP addresses that are not attached to any resource

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Azure charges for a static public IP address irrespective of whether anything uses it, and every Standard SKU address is static. ZopNight flags a Standard public IP with no `ipConfiguration` and no NAT gateway, meaning no VM, load balancer or gateway uses it, and reports its full priced hourly charge as the saving.

Signal and threshold

How ZopNight evaluates Standard public IP addresses that are not attached to any resource.
Field Value
Rule IDsRC-1363
Categoryorphan
Severitylow
Metricnone — pure configuration read
ThresholdStandard SKU with no association
SourceZopNight
Permissions usedMicrosoft.Network/publicIPAddresses/read

A reserved address bills by the hour

The public IP pricing FAQ says that in the Resource Manager model you are charged for a static public IP address irrespective of the associated resource, and that the billing clock stops only when you delete the IP address resource. Microsoft’s public IP overview lists Standard SKU addresses as static, so every Standard address that exists is billing.

Basic SKU public IPs were retired on September 30, 2025, which makes Standard the address type you will find almost everywhere. An address left behind after its VM or load balancer was deleted keeps charging for as long as nobody notices.

Listing addresses nothing uses

An address used by a NIC, load balancer frontend or VPN gateway has an ipConfiguration; one attached to a NAT gateway carries a natGateway reference instead. Filter for Standard addresses with neither:

Terminal window
az network public-ip list \
--query "[?ipConfiguration==null && natGateway==null && sku.name=='Standard'].{name:name, group:resourceGroup, ip:ipAddress}" \
-o table

Check DNS records and partner allowlists for the listed addresses before doing anything with them.

What ZopNight checks

  1. The address is marked unassociated from its own IP configuration when ZopNight scans the subscription. Customer tags are never used as the signal.
  2. The SKU is Standard, compared without regard to case.
  3. The address has a positive monthly price.

There is no metric and no waiting period. The check is a configuration read on every evaluation.

Addresses that are skipped

A Basic SKU address, or one whose SKU could not be read, gets no finding, so ZopNight never prices a Basic address with the Standard rate. If the association state is missing, the address is treated as possibly in use. An address attached to a NAT gateway or other resource is associated and is not flagged; if that gateway itself is idle, see Idle Azure NAT Gateway.

The saving is the whole address charge

Terminal window
saving = full monthly charge of the unassociated Standard public IP
cost after fix = 0

The figure comes from the priced rate for that address; the rule never uses a fixed estimate.

Releasing an unused address

  1. Note the IP address and check whether anything outside Azure refers to it, such as DNS, firewall allowlists or partner configurations.
  2. Check whether it was left over from a VM or load balancer deletion and whether that workload is coming back.
  3. Delete it: az network public-ip delete --resource-group <rg> --name <ip>.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·