Skip to main content
orphan · azure

Managed disks in the Unattached state for at least 7 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Azure managed disks keep billing at their full provisioned tier after they are detached or their VM is deleted. ZopNight flags disks whose `diskState` is exactly `Unattached`, skips Site Recovery and Kubernetes volumes, waits 7 days after detachment when that time is known, and reports the disk's full monthly cost as the saving.

Signal and threshold

How ZopNight evaluates Managed disks in the Unattached state for at least 7 days.
Field Value
Rule IDsRC-212
Categoryorphan
Severitylow
Metricnone — pure configuration read
ThresholdUnattached for at least 7 days
Evaluation window7d
SourceZopNight
Permissions usedMicrosoft.Compute/disks/read

Detached disks bill as if they were in use

Microsoft’s unattached disk guide is blunt: deleting a VM does not delete its disks by default, and after the VM is gone you continue to pay for them. Managed disk pricing bills each disk hourly at the tier that fits its size, at the same rate regardless of how much of the disk is used. A 1 TiB Premium SSD left over from a deleted database server costs the same every hour as the day it was in service.

Finding unattached disks

A disk attached to a VM has its managedBy property set to the VM’s ID; an unattached disk has it set to null. LastOwnershipUpdateTime records when the disk’s state last changed, which for an unattached disk is the moment it was detached:

Terminal window
az disk list \
--query '[?managedBy==`null`].{name:name, group:resourceGroup, sizeGB:diskSizeGB, sku:sku.name, state:diskState}' -o table
az disk show --resource-group <rg> --name <disk> --query "{state:diskState, since:lastOwnershipUpdateTime}"

Conditions for an unattached-disk finding

  1. The disk’s diskState is exactly Unattached. Other states, including Reserved and ActiveSAS, are never flagged.
  2. When the detachment time is known, it is at least 7 days in the past. A disk detached moments ago is usually mid-rebuild or mid-migration.
  3. The disk has a price for its size and tier.

Disks ZopNight deliberately ignores

Azure Site Recovery keeps unattached disks on purpose. Names containing ASRReplica (Azure-to-Azure replication) or starting with asrseeddisk (VMware and physical server replication seeds) are skipped. So are disks provisioned by Kubernetes, recognised by pvc- or kubernetes-dynamic-pvc- name prefixes or Kubernetes tags, because deleting one would strand the pod that owns the volume. When the detachment time is missing, the state check alone decides.

A newly created empty Premium SSD, Standard SSD or Standard HDD disk is not billed until it is first attached, per the pricing FAQ, so a disk that has never been attached may have no price and no finding. Snapshots of deleted disks are covered by Orphaned Azure Snapshot.

The saving is the full disk charge

Terminal window
saving = provisioned size x disk tier rate, per month
cost after fix = 0

Deleting a disk you no longer need

  1. Confirm no VM, scale set or cluster expects to reattach the disk.
  2. Take a snapshot if the data may be needed; an incremental snapshot is billed only for used size.
  3. Delete the disk: az disk delete --resource-group <rg> --name <disk>.
  4. Remove any snapshots of it that are no longer needed.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·