AzureSeptember 22, 20266 min read

How to Find Unused Azure Resources That Are Quietly Billing You

Azure already did most of this work for you and put the answer somewhere nobody opens. Here is what is in there, and the parts it still misses.

Waste in a cloud account is almost never one big embarrassing thing. It is eleven small reasonable things, each one added by somebody who meant well, none of them owned by anybody now.

The good news is that Azure already went looking. There is a free tool sitting in your portal that has been quietly building the list this whole time, and most people have never opened it.

Start where Microsoft already did the work

Azure Advisor is free. It is not a trial, not a preview, and it costs nothing to look at. In the portal, search for Advisor, then open the Cost tab.

What you get is a list of specific resources with specific findings, written by Microsoft, based on your own telemetry. They can see usage patterns on your machines that no outside tool can, because they run the hypervisor.

Worth knowing before you read it: Advisor works on different time windows depending on what it is looking at. Virtual machine and App Service sizing is based on the last 7 days. Idle Cosmos DB containers are 30 days. Stopped Data Explorer resources have to have been stopped for at least 60 days before it says anything. So a machine you spun up on Monday will not appear, and that is correct rather than broken.

The findings actually worth acting on

Most of Advisor's cost list is reservation advice, which is only useful if you already know your baseline. Skip past those on the first pass. These are the ones that find real, dead money.

"Review disks that aren't attached to a VM." This is the big one on almost every subscription. When you delete a virtual machine, Azure does not automatically take its disk with it. The disk stays, at full price, attached to nothing. A few deleted test machines over a year and you are paying monthly for storage holding operating systems nobody will ever boot.

"Unused/Empty App Service plan." Microsoft's wording is blunt: "Your App Service plan has no apps running." The plan is the thing that costs money, not the app. Delete the web app and the plan underneath it keeps billing at whatever tier you picked, serving nothing.

"Consider taking action on the idle Azure Cosmos DB containers." Advisor says it has not "detected any activity over the past 30 days" on those containers. Cosmos bills on provisioned throughput, so an idle container is not cheap just because nothing is reading it. You pay for the capacity you reserved, busy or not.

"Delete failing ADF pipelines." This one surprises people, and Microsoft says it plainly: "Know that you're being billed for them even though they aren't serving you while failing." A Data Factory pipeline that has been red for three months has been charging you for three months of failure.

"Configure automatic renewal for the expiring reservations." Read what happens if you ignore it: "Your resources will continue to operate normally, however, you will be billed at the on-demand rates going forward." Nothing breaks. Nothing alerts. The same machines just quietly cost more from that day on. Advisor rates this one High impact and it deserves it.

The one that is free money

There is a recommendation called "Use Standard Storage to store Managed Disks snapshots", and Microsoft's own estimate on it is a "60% reduction in the snapshot cost for Managed Disks".

Snapshots default to Standard storage now, but any snapshot taken from a Premium disk under older settings may be sitting on Premium storage, and there is no reason for it to be. A snapshot is a backup. It is read once, if ever, on the worst day of your year. Paying premium speed for something you hope never to open is the clearest waste on this whole list.

You lose nothing. The snapshot restores the same either way.

What Advisor does not tell you

Advisor is good and it is not complete. It watches the services it watches, and things that fall between services do not get a recommendation.

Public IP addresses are the clearest gap. A static public IP bills whether or not it is attached to anything, and Microsoft is explicit that "you're charged for a static public IP address irrespective of the associated resource". Delete the machine, keep the address, keep paying. Go to the Public IP addresses list in the portal and sort by the Associated to column. Anything blank is money.

Network interfaces are the same story in miniature. They are cheap individually and they accumulate, and an orphaned NIC is usually a sign that a whole machine was half-deleted and other pieces are still lying around.

Then there are machines in the wrong kind of off. A VM shut down from inside the operating system sits in a state Azure calls Stopped, and Stopped is still billed for compute. Only Stopped (deallocated) ends the charge. Advisor will not flag this because as far as Azure is concerned the machine is allocated and working as configured.

Deciding what is actually safe to remove

Finding it is the easy half. The reason most of this waste survives an audit is that nobody is confident enough to remove it, and that caution is sensible rather than lazy.

Microsoft puts the warning right in the disk recommendation: "Deleting a disk is irreversible. Create a snapshot before deletion and confirm the data is no longer needed."

That is the right order for all of it. Snapshot first, then wait, then delete. A snapshot of an unattached disk costs a fraction of the disk and buys you the ability to be wrong. Give yourself thirty days between the snapshot and the deletion, and if nobody has shouted by then, nobody was using it.

For anything you are unsure about, the tag is your friend. Put a tag on it saying who found it and when, and come back. A resource nobody claims in a month is a resource nobody needs.

Doing it more than once

Run the list. It is an afternoon, it is free, and the money you find is money you keep every month afterwards rather than once.

The part that does not survive is the repeat. Waste rebuilds itself from ordinary work: somebody tests something, somebody deletes a machine in a hurry, somebody scales up for a launch. Nobody is doing anything wrong, and in four months the list is full again.

The shorter way

That is where Liberra fits. It reads Azure Advisor directly, so the sizing advice and the savings numbers come from Microsoft rather than from us guessing off a fortnight of CPU. Advisor has telemetry we do not have, and reading what it already worked out beats inventing a second opinion on top of it.

Alongside that it keeps its own index of the subscription and checks it on every sync, which covers the gaps Advisor leaves: unattached disks, public IPs bound to nothing, machines stopped in the expensive way.

Then you ask in plain English. "What is costing me money and doing nothing." You get the list, with the reasoning, against your real subscription.

One thing it will not do is clean up for you. Liberra cannot delete anything, and that is built into the code rather than set in a menu. It will find the dead disk, tell you what is on it, tell you what it costs and what depends on it. Pulling the trigger stays with you, in your own portal. For a list like this one, where the whole risk is deleting something that turned out to matter, that is the right place for it to sit.

Founder, Liberra AI