Deallocated Azure VMs whose disks and public IPs keep billing
What does ZopNight detect here?
A deallocated Azure VM stops paying for compute, but its managed disks and static public IPs keep charging. ZopNight flags standalone VMs in the `VM deallocated` power state that still have priced disks or public IPs attached, and reports the sum of those residual charges as the saving, itemised by disk and IP.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1384 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | power state deallocated with priced attachments |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Compute/disks/read · Microsoft.Network/publicIPAddresses/read |
Where it applies
Deallocation stops compute, not storage or addresses
Azure’s VM states table shows Deallocated as not billed for instance usage, with a footnote that disks and networking continue to incur charges. The two leftovers that matter:
- Managed disks. The OS disk and any data disks keep billing at their provisioned tier.
- Static public IPs. The public IP pricing FAQ says a dynamic public IP is not charged while its VM is stopped and deallocated, but a static one is charged irrespective of the associated resource.
A VM switched off months ago and never deleted is a small, steady storage and address bill.
Listing deallocated VMs and what they hold
az vm list -d --query "[?powerState=='VM deallocated'].{name:name, group:resourceGroup}" -o table
az disk list --query "[?managedBy=='<vm-resource-id>'].{name:name, sizeGB:diskSizeGB, sku:sku.name}" -o table
az vm list-ip-addresses --resource-group <rg> --name <vm> -o tableConditions for a residual-cost finding
- The VM’s status is deallocated. A VM that is merely stopped (still allocated) keeps billing for compute, so the residual-only view does not apply to it.
- The VM is standalone, not an instance inside a scale set.
- At least one child resource is linked to it: a managed disk that the VM manages, or a public IP reached through the VM’s network interface.
- At least one of those children has a price.
When nothing is reported
If no disk or public IP is linked to the VM, or none of them can be priced, there is no finding; the rule never reports a $0 residual or an advisory with no number. Running VMs belong to Idle Azure VM, and a reservation that keeps paying for a deallocated VM is covered by Azure RI/SP Covering Deallocated VM.
Summing the residual
saving = sum of priced managed disk costs + sum of priced public IP costscost after fix = 0The finding lists the managed disk and public IP components separately, and they add up to the saving. Compute is $0 for a deallocated VM, so no compute rate is ever included.
Retiring a VM that stays off
- Check whether the VM is intentionally deallocated, for example a batch worker that only runs a few times a year.
- If it should run, start it with
az vm start --resource-group <rg> --name <vm>and let the idle checks judge it. - If it is no longer needed, snapshot any disk you may need, then delete the VM with
az vm delete. - Delete the disks left behind; Microsoft notes that deleting a VM does not delete its attached disks by default.
- Delete or release any static public IP the VM used.