Skip to main content
idle · azure

Azure storage accounts with near-zero ingress and egress for 30 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Azure storage accounts bill for stored data whether or not anything reads it. ZopNight compares 30 days of `Ingress` and `Egress` against two floors: at or below 1,024 it proposes deleting the account for its full cost, and between 1,024 and 10,240 it proposes moving data to the cool tier, priced from the real hot-to-cool rate gap.

Signal and threshold

How ZopNight evaluates Azure storage accounts with near-zero ingress and egress for 30 days.
Field Value
Rule IDsRC-274
Categoryidle
Severitylow
MetricIngress / Egress
Thresholdaverage at or below 10,240 (delete at or below 1,024)
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.Storage/storageAccounts/read · Microsoft.Insights/Metrics/Read

Stored data costs money even when nobody touches it

A storage account’s biggest line is usually capacity. Microsoft’s access tier overview describes the trade: the hot tier has the highest storage cost and the lowest access cost, while the cool tier has lower storage cost and higher access cost, and data in cool should stay for at least 30 days. An account that sits in hot with almost no reads or writes is paying the premium price for access it never uses, and one with no traffic at all may not be needed.

Measuring an account’s traffic

Ingress and Egress are the bytes moving in and out of the account, and UsedCapacity is how much it holds:

Terminal window
az monitor metrics list \
--resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Storage/storageAccounts/<account> \
--metric Ingress Egress UsedCapacity --aggregation Average --interval PT1H --offset 30d

ZopNight compares the Average aggregation of these metrics with its floors. Azure’s Average for Ingress and Egress is a traffic-volume signal rather than a literal bytes-per-hour rate, so use the numbers to rank accounts, not to read throughput.

Two thresholds, two different proposals

  • Above 10,240 on either Ingress or Egress: the account is in normal use and nothing is raised.
  • Between 1,024 and 10,240: the account is quiet but alive. The proposal is to move data to the cool tier, and it is only made when a real hot-to-cool price difference can be computed.
  • At or below 1,024 on both: the account looks unused. The proposal is to delete it, but only if the account is at least 30 days old and its traffic data spans at least 30 distinct days.

The decision always uses the full averages, so an account busy earlier in the period is not flipped to deletion because its most recent weeks were calm.

Accounts the rule will not touch

Accounts whose names contain tfstate, diagnostics, cloudshell or bootdiag are skipped, because Terraform state, diagnostics and Cloud Shell storage are structurally needed even when quiet. If Azure Monitor returns no ingress or egress data for an account, there is no finding; the rule does not treat missing data as zero traffic. A related tiering check for hot accounts lives in Azure Storage Account Hot Tier with Low Access.

Pricing the delete and the retier

Terminal window
delete path: saving = full monthly cost of the account; cost after = 0
retier path: saving = (hot rate - cool rate) x stored GB x 730 hours, capped at current cost

If the retier difference cannot be computed, the quiet-but-alive account gets no finding rather than an estimated percentage.

Cleaning up a quiet account

  1. List the containers, file shares, queues and tables in the account and identify their owners.
  2. Copy anything still required to a consolidated account.
  3. For a quiet account that must stay, change the default tier: az storage account update --resource-group <rg> --name <account> --access-tier Cool.
  4. For an unused account, delete it once the data is safely elsewhere.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·