Standard public IP addresses that are not attached to any resource
What does ZopNight detect here?
Azure charges for a static public IP address irrespective of whether anything uses it, and every Standard SKU address is static. ZopNight flags a Standard public IP with no `ipConfiguration` and no NAT gateway, meaning no VM, load balancer or gateway uses it, and reports its full priced hourly charge as the saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1363 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | Standard SKU with no association |
| Source | ZopNight |
| Permissions used | Microsoft.Network/publicIPAddresses/read |
Where it applies
A reserved address bills by the hour
The public IP pricing FAQ says that in the Resource Manager model you are charged for a static public IP address irrespective of the associated resource, and that the billing clock stops only when you delete the IP address resource. Microsoft’s public IP overview lists Standard SKU addresses as static, so every Standard address that exists is billing.
Basic SKU public IPs were retired on September 30, 2025, which makes Standard the address type you will find almost everywhere. An address left behind after its VM or load balancer was deleted keeps charging for as long as nobody notices.
Listing addresses nothing uses
An address used by a NIC, load balancer frontend or VPN gateway has an ipConfiguration; one
attached to a NAT gateway carries a natGateway reference instead. Filter for Standard addresses
with neither:
az network public-ip list \ --query "[?ipConfiguration==null && natGateway==null && sku.name=='Standard'].{name:name, group:resourceGroup, ip:ipAddress}" \ -o tableCheck DNS records and partner allowlists for the listed addresses before doing anything with them.
What ZopNight checks
- The address is marked unassociated from its own IP configuration when ZopNight scans the subscription. Customer tags are never used as the signal.
- The SKU is Standard, compared without regard to case.
- The address has a positive monthly price.
There is no metric and no waiting period. The check is a configuration read on every evaluation.
Addresses that are skipped
A Basic SKU address, or one whose SKU could not be read, gets no finding, so ZopNight never prices a Basic address with the Standard rate. If the association state is missing, the address is treated as possibly in use. An address attached to a NAT gateway or other resource is associated and is not flagged; if that gateway itself is idle, see Idle Azure NAT Gateway.
The saving is the whole address charge
saving = full monthly charge of the unassociated Standard public IPcost after fix = 0The figure comes from the priced rate for that address; the rule never uses a fixed estimate.
Releasing an unused address
- Note the IP address and check whether anything outside Azure refers to it, such as DNS, firewall allowlists or partner configurations.
- Check whether it was left over from a VM or load balancer deletion and whether that workload is coming back.
- Delete it:
az network public-ip delete --resource-group <rg> --name <ip>.