Azure storage accounts with near-zero ingress and egress for 30 days
What does ZopNight detect here?
Azure storage accounts bill for stored data whether or not anything reads it. ZopNight compares 30 days of `Ingress` and `Egress` against two floors: at or below 1,024 it proposes deleting the account for its full cost, and between 1,024 and 10,240 it proposes moving data to the cool tier, priced from the real hot-to-cool rate gap.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-274 |
| Category | idle |
| Severity | low |
| Metric | Ingress / Egress |
| Threshold | average at or below 10,240 (delete at or below 1,024) |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Storage/storageAccounts/read · Microsoft.Insights/Metrics/Read |
Where it applies
Stored data costs money even when nobody touches it
A storage account’s biggest line is usually capacity. Microsoft’s access tier overview describes the trade: the hot tier has the highest storage cost and the lowest access cost, while the cool tier has lower storage cost and higher access cost, and data in cool should stay for at least 30 days. An account that sits in hot with almost no reads or writes is paying the premium price for access it never uses, and one with no traffic at all may not be needed.
Measuring an account’s traffic
Ingress and Egress are the bytes moving in and out of the account, and UsedCapacity is how
much it holds:
az monitor metrics list \ --resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Storage/storageAccounts/<account> \ --metric Ingress Egress UsedCapacity --aggregation Average --interval PT1H --offset 30dZopNight compares the Average aggregation of these metrics with its floors. Azure’s Average for
Ingress and Egress is a traffic-volume signal rather than a literal bytes-per-hour rate, so use
the numbers to rank accounts, not to read throughput.
Two thresholds, two different proposals
- Above 10,240 on either
IngressorEgress: the account is in normal use and nothing is raised. - Between 1,024 and 10,240: the account is quiet but alive. The proposal is to move data to the cool tier, and it is only made when a real hot-to-cool price difference can be computed.
- At or below 1,024 on both: the account looks unused. The proposal is to delete it, but only if the account is at least 30 days old and its traffic data spans at least 30 distinct days.
The decision always uses the full averages, so an account busy earlier in the period is not flipped to deletion because its most recent weeks were calm.
Accounts the rule will not touch
Accounts whose names contain tfstate, diagnostics, cloudshell or bootdiag are skipped,
because Terraform state, diagnostics and Cloud Shell storage are structurally needed even when
quiet. If Azure Monitor returns no ingress or egress data for an account, there is no finding;
the rule does not treat missing data as zero traffic. A related tiering check for hot accounts
lives in Azure Storage Account Hot Tier with Low Access.
Pricing the delete and the retier
delete path: saving = full monthly cost of the account; cost after = 0retier path: saving = (hot rate - cool rate) x stored GB x 730 hours, capped at current costIf the retier difference cannot be computed, the quiet-but-alive account gets no finding rather than an estimated percentage.
Cleaning up a quiet account
- List the containers, file shares, queues and tables in the account and identify their owners.
- Copy anything still required to a consolidated account.
- For a quiet account that must stay, change the default tier:
az storage account update --resource-group <rg> --name <account> --access-tier Cool. - For an unused account, delete it once the data is safely elsewhere.