Skip to main content
rightsizing · azure

VM scale sets that scale out when average CPU is still under 30%

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure virtual machine scale set whose autoscale rule scales out on `Percentage CPU` at a threshold below 30. Such a low trigger keeps adding instances while the existing ones are mostly idle. ZopNight recommends raising the threshold to 70 and prices the saving as the share of the scale set's own cost that the higher target removes.

Signal and threshold

How ZopNight evaluates VM scale sets that scale out when average CPU is still under 30%.
Field Value
Rule IDsRC-ASC-005
Categoryrightsizing
Severitymedium
MetricPercentage CPU (autoscale threshold)
Thresholdscale-out threshold < 30
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachineScaleSets/read · Microsoft.Insights/AutoscaleSettings/Read

A scale-out trigger set so low the fleet never shrinks

Autoscale compares a metric with a threshold and adds instances when the rule’s condition holds. The autoscale settings schema shows each rule as a metric trigger (metric, threshold, time window, aggregation) paired with a scale action. Put the CPU threshold at 20 and the set adds VMs whenever average CPU passes 20%, which for most services is barely warm.

The effect is a fleet that settles at several times the size its load needs. Every extra instance bills at the full VM rate while running at a fraction of its capacity.

Reading the scale-out threshold on a scale set

Terminal window
az monitor autoscale list --resource-group my-rg \
--query "[].{name:name, target:targetResourceUri}" -o table
az monitor autoscale show --resource-group my-rg --name my-autoscale \
--query "profiles[].rules[?metricTrigger.metricName=='Percentage CPU' && scaleAction.direction=='Increase'].metricTrigger.threshold" \
-o tsv

A value below 30 is what this rule reports.

Target value and cost conditions

  1. The scale set is provisioned successfully or running.
  2. ZopNight has read the Percentage CPU scale-out threshold from the autoscale setting that targets the scale set, and it is a number from 0 up to, but not including, 30.
  3. The scale set has a monthly cost in ZopNight’s cost data. The saving is attributed to the scale set itself, so it is not counted a second time on its instances.

Scale sets left out

A scale set whose threshold is missing, unreadable, or 30 and above gets no finding, as does one without cost data. The opposite problem, a threshold so high that capacity arrives too late, is Scaling Target Too High. A set with no autoscale setting at all is covered by VMSS Autoscale Setting Not Configured.

Headroom arithmetic behind the estimate

Raising the target from T% to 70% shrinks the steady-state instance count by roughly T/70, so the over-provisioned share of the bill is what remains:

Terminal window
monthly saving = scale set monthly cost x (1 - current threshold / 70)

A set triggering at 20% would show about 71% of its cost as saving. Treat it as an estimate: real fleets also respect their minimum instance count and scale-in rules.

Raising the threshold to 70%

  1. Open the scale set’s autoscale setting in the portal (the scale set, then Scaling), or export it with az monitor autoscale show.
  2. Recreate the CPU scale-out rule at 70, for example az monitor autoscale rule create --resource-group my-rg --autoscale-name my-autoscale --condition "Percentage CPU > 70 avg 5m" --scale out 1, and delete the old rule.
  3. Move the scale-in threshold up too, keeping a clear gap below 70 on the same metric so the set does not flap.
  4. Watch response times and instance counts for a few days after the change.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·