Skip to main content
resource · azure

Azure Virtual Network

schedulable
no
category
networking-services

Does ZopNight manage Azure Virtual Network?

Azure virtual networks are free to create, and the charges hang off what runs inside them: VNet peering bills per GB in each direction, and egress traffic meters separately. ZopNight discovers every VNet via Resource Graph and uses it to anchor the topology graph linking VMs, subnets, NICs, and gateways.

Rules that fire on Azure Virtual Network

no live rules

No active rule family targets Azure Virtual Network today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Browse every live recommendation for this platform →

At a glance

Azure Virtual Network coverage facts.
Field Value
Scheduling notesdiscovery and topology only.

Virtual networks are the fundamental network boundary in Azure, hosting subnets, NICs, and peerings. VNets are free themselves but anchor peering, gateway, and egress charges and define the topology ZopNight maps.

A free boundary that anchors paid traffic

Creating a VNet costs nothing: there is no hourly meter, no per-VNet charge, and no fee for the address space it claims. The money moves the moment traffic crosses its edges. VNet peering bills per gigabyte in both directions, egress to the internet meters separately, and every gateway attached to the network, VPN or ExpressRoute, runs its own hourly charge. So while the VNet row on an invoice is blank, the network design it encodes decides several real line items. A hub-and-spoke layout with chatty spokes, for example, pays peering on every hop that a flatter design would avoid.

How ZopNight maps VNet topology

Discovered via Azure Resource Graph and used to build the network topology that connects VMs, subnets, and gateways for blast-radius and dependency views. When ZopNight evaluates stopping a machine or flags an idle gateway, the VNet graph is what shows which resources sit behind the same boundary and would feel the change. One known enrichment gap: placing a VM inside its VNet requires NIC join data, so VNet placement of VMs depends on the NIC linkage being present.

VNet hygiene worth a look

Because deletion is blocked while any resource remains inside, VNets almost never disappear. Abandoned environments tend to leave an empty or near-empty VNet behind, still holding address space and sometimes still linked to private DNS zones or peerings. Reviewing VNets with few or no attached NICs is a quick way to find whole environments that were half-torn-down. Peerings that connect to networks nobody uses anymore are a second pattern: the link itself is easy to forget, but any residual traffic across it keeps metering.

Locating virtual networks in the Azure portal

Azure portal → Virtual networks lists every VNet with its address space, resource group, and subscription. Opening one shows its subnets, peerings, and connected devices, the same relationships ZopNight assembles automatically across every subscription it can see.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·