Skip to main content
idle · azure

Application Gateways with zero requests and zero connections for 7+ days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure Application Gateway when its `TotalRequests` and `CurrentConnections` metrics average zero, with at least 7 days of data on each reported series, and the gateway has a known cost. A v2 gateway pays a fixed hourly charge for as long as it is provisioned, even with no instances reserved.

Signal and threshold

How ZopNight evaluates Application Gateways with zero requests and zero connections for 7+ days.
Field Value
Rule IDsRC-272
Categoryidle
Severitymedium
MetricTotalRequests, CurrentConnections
Thresholdaverage = 0
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.Network/applicationGateways/read · Microsoft.Insights/Metrics/Read

The fixed part of an Application Gateway bill

Microsoft’s Application Gateway pricing guide splits a v2 bill into two parts. Fixed costs are charged for the time the gateway is provisioned and available, and apply even if zero instances are reserved; the number of running instances does not change them. Capacity unit costs then track the work done, computed hourly. A partial hour is billed as a full hour, and the public IP attached to the gateway is billed separately.

With no traffic, capacity units fall away but the fixed hourly charge, plus the WAF premium on a WAF v2 gateway, stays for as long as the resource exists.

Checking a gateway’s traffic

Terminal window
az network application-gateway list \
--query "[].{name:name, rg:resourceGroup, sku:sku.name, state:operationalState}" -o table
az monitor metrics list --resource <app-gateway-resource-id> \
--metric TotalRequests CurrentConnections --offset 30d --interval PT24H --aggregation Total Average

TotalRequests counts requests served; CurrentConnections is the number of client connections established with the gateway.

Traffic conditions for the finding

  1. At least one of the request or connection series is present.
  2. Every present series has an average of zero.
  3. Every present series covers at least 7 days, so a gateway that went live this week is not flagged.
  4. The gateway has a known monthly cost above zero.

The finding reports the window it actually observed, up to 30 days.

Gateways that are left alone

With neither metric available there is no finding. Any request or connection in the window clears the gateway. Gateways without a recorded cost are skipped, because the full cost is what the finding would claim as the saving.

Saving is the gateway’s full cost

Terminal window
saving = current monthly cost of the Application Gateway
cost after fix = 0

Retiring an idle gateway

  1. Confirm no DNS record or Front Door origin points at its frontend IP, and that no listener is waiting for a planned cutover.
  2. If some routes are still needed, move them to a shared gateway or to Azure Front Door.
  3. Delete the gateway: az network application-gateway delete --resource-group my-rg --name my-appgw.
  4. Delete its public IP addresses, which keep billing on their own.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·