Application Gateways with zero requests and zero connections for 7+ days
What does ZopNight detect here?
ZopNight flags an Azure Application Gateway when its `TotalRequests` and `CurrentConnections` metrics average zero, with at least 7 days of data on each reported series, and the gateway has a known cost. A v2 gateway pays a fixed hourly charge for as long as it is provisioned, even with no instances reserved.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-272 |
| Category | idle |
| Severity | medium |
| Metric | TotalRequests, CurrentConnections |
| Threshold | average = 0 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Network/applicationGateways/read · Microsoft.Insights/Metrics/Read |
Where it applies
The fixed part of an Application Gateway bill
Microsoft’s Application Gateway pricing guide splits a v2 bill into two parts. Fixed costs are charged for the time the gateway is provisioned and available, and apply even if zero instances are reserved; the number of running instances does not change them. Capacity unit costs then track the work done, computed hourly. A partial hour is billed as a full hour, and the public IP attached to the gateway is billed separately.
With no traffic, capacity units fall away but the fixed hourly charge, plus the WAF premium on a WAF v2 gateway, stays for as long as the resource exists.
Checking a gateway’s traffic
az network application-gateway list \ --query "[].{name:name, rg:resourceGroup, sku:sku.name, state:operationalState}" -o table
az monitor metrics list --resource <app-gateway-resource-id> \ --metric TotalRequests CurrentConnections --offset 30d --interval PT24H --aggregation Total AverageTotalRequests counts requests served; CurrentConnections is the number of client connections
established with the gateway.
Traffic conditions for the finding
- At least one of the request or connection series is present.
- Every present series has an average of zero.
- Every present series covers at least 7 days, so a gateway that went live this week is not flagged.
- The gateway has a known monthly cost above zero.
The finding reports the window it actually observed, up to 30 days.
Gateways that are left alone
With neither metric available there is no finding. Any request or connection in the window clears the gateway. Gateways without a recorded cost are skipped, because the full cost is what the finding would claim as the saving.
Saving is the gateway’s full cost
saving = current monthly cost of the Application Gatewaycost after fix = 0Retiring an idle gateway
- Confirm no DNS record or Front Door origin points at its frontend IP, and that no listener is waiting for a planned cutover.
- If some routes are still needed, move them to a shared gateway or to Azure Front Door.
- Delete the gateway:
az network application-gateway delete --resource-group my-rg --name my-appgw. - Delete its public IP addresses, which keep billing on their own.