# Idle Azure Storage Account

> Flags Azure storage accounts with almost no ingress or egress in 30 days, proposing deletion or a move to the cool tier.

Source: https://zop.dev/integrations/azure/recommendations/idle-azure-storage-account

---

## Stored data costs money even when nobody touches it

A storage account's biggest line is usually capacity. Microsoft's
[access tier overview](https://learn.microsoft.com/en-us/azure/storage/blobs/access-tiers-overview)
describes the trade: the hot tier has the highest storage cost and the lowest access cost, while
the cool tier has lower storage cost and higher access cost, and data in cool should stay for at
least 30 days. An account that sits in hot with almost no reads or writes is paying the premium
price for access it never uses, and one with no traffic at all may not be needed.

## Measuring an account's traffic

`Ingress` and `Egress` are the bytes moving in and out of the account, and `UsedCapacity` is how
much it holds:

```bash
az monitor metrics list \
  --resource /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Storage/storageAccounts/<account> \
  --metric Ingress Egress UsedCapacity --aggregation Average --interval PT1H --offset 30d
```

ZopNight compares the Average aggregation of these metrics with its floors. Azure's Average for
`Ingress` and `Egress` is a traffic-volume signal rather than a literal bytes-per-hour rate, so use
the numbers to rank accounts, not to read throughput.

## Two thresholds, two different proposals

- Above 10,240 on either `Ingress` or `Egress`: the account is in normal use and nothing is raised.
- Between 1,024 and 10,240: the account is quiet but alive. The proposal is to move data to the
  cool tier, and it is only made when a real hot-to-cool price difference can be computed.
- At or below 1,024 on both: the account looks unused. The proposal is to delete it, but only if
  the account is at least 30 days old and its traffic data spans at least 30 distinct days.

The decision always uses the full averages, so an account busy earlier in the period is not
flipped to deletion because its most recent weeks were calm.

## Accounts the rule will not touch

Accounts whose names contain `tfstate`, `diagnostics`, `cloudshell` or `bootdiag` are skipped,
because Terraform state, diagnostics and Cloud Shell storage are structurally needed even when
quiet. If Azure Monitor returns no ingress or egress data for an account, there is no finding;
the rule does not treat missing data as zero traffic. A related tiering check for hot accounts
lives in <a href="https://zop.dev/integrations/azure/recommendations/azure-storage-account-hot-tier-with-low-access">Azure Storage Account Hot Tier with Low Access</a>.

## Pricing the delete and the retier

```text
delete path:  saving = full monthly cost of the account; cost after = 0
retier path:  saving = (hot rate - cool rate) x stored GB x 730 hours, capped at current cost
```

If the retier difference cannot be computed, the quiet-but-alive account gets no finding rather
than an estimated percentage.

## Cleaning up a quiet account

1. List the containers, file shares, queues and tables in the account and identify their owners.
2. Copy anything still required to a consolidated account.
3. For a quiet account that must stay, change the default tier:
   `az storage account update --resource-group <rg> --name <account> --access-tier Cool`.
4. For an unused account, delete it once the data is safely elsewhere.

**Warning**
Moving blobs out of the cool tier, or deleting them, before 30 days can trigger an early deletion charge. Deleting the account removes all its data.
