Skip to main content
idle · azure

Recovery Services vaults that look idle, and why this review raises no finding

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

Azure Backup bills a Recovery Services vault on two axes, a fee per protected instance priced in 500 GB increments and a charge for backup storage consumed, so a single "idle vault" saving would be guesswork. ZopNight raises nothing from this review and prices vault waste through narrower checks: empty vaults, geo-redundant storage downgrade (not yet priced), and retention tuning.

Signal and threshold

How ZopNight evaluates Recovery Services vaults that look idle, and why this review raises no finding.
Field Value
Rule IDsRC-1379
Categoryidle
Severitymedium
MetricBackupHealthEvent (context only)
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.RecoveryServices/vaults/read · Microsoft.RecoveryServices/Vaults/backupProtectedItems/read

Two separate meters on every vault

Azure Backup pricing charges each protected instance a fee that depends on the size of the data backed up, in 500 GB increments, plus the storage the backups consume. Backup storage is billed separately, and on the Standard tier you choose locally redundant, zone-redundant or geo-redundant storage, each at its own rate.

Those two meters move independently. A vault can protect nothing new and still hold years of recovery points, or protect many small VMs with little stored data. Without a way to split the bill between the two, no single number describes what an “idle” vault would save.

Reviewing what a vault still holds

Terminal window
az backup vault list --query "[].{name:name, rg:resourceGroup, location:location}" -o table
az backup item list --resource-group my-rg --vault-name my-vault -o table

Protected items with a stopped protection state, and items for machines that no longer exist, are the ones to question.

What ZopNight looks at for this review

The vault’s backup health events over 30 days are collected as context. Beyond that, this review intentionally does not decide anything on its own: there is no signal here that turns into an action with a price attached.

Why it stays silent

ZopNight only reports a cost finding when the saving is concrete. For a vault, the concrete cases are narrower than “this vault seems idle”, so they have their own checks:

No saving on this page

This review never carries a dollar figure. The checks above do, each for one lever, once they can price it.

Cleaning up a vault by hand

  1. List protected items and stop protection for machines that were decommissioned, choosing whether to retain or delete their existing recovery points.
  2. Review backup policies for retention longer than your requirements.
  3. Consider whether geo-redundant storage is needed for non-production backups.
  4. Once a vault protects nothing and holds no recovery points, delete it. Azure Backup is moving to soft delete enforced by default (in preview), under which deleted backup data and even a deleted vault pass through a recoverable soft-deleted state first, per Microsoft’s soft delete guide.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·