The Azure Footguns Database
The ways Azure quietly costs you money or exposes you to risk, documented one by one. What it is, why it happens, what it costs, and how to fix it.
Every entry has a stable ID: AZF-0001 is Azure Footgun No. 1. Search or filter by service, category, or ID.
Search results
A forgotten DDoS Protection Plan bills ~$2,944/mo while protecting nothing
Network DDoS Protection Plans charge a flat monthly fee even with zero VNets attached. A detached plan is pure waste.
~$2,944/month at list price while unassociated Basis: Azure list price. Estimate, not a measurement.
Key Vault purge protection is off by default, so a deleted vault can be gone for good
Without purge protection, a deleted Key Vault can be permanently purged before the retention window ends, taking the data its keys encrypted with it.
Permanent, unrecoverable loss of keys and secrets if the vault is purged Basis: Azure behavior (authored assessment). Estimate, not a measurement.
An unattached managed disk bills its full provisioned size forever
Delete a VM and its data disks usually survive. A managed disk in the Unattached state bills its full provisioned capacity whether or not anything reads it.
~$135/month at list price for a 1 TiB P30 premium SSD doing nothing Basis: Azure list price. Estimate, not a measurement.
A reserved Standard public IP keeps billing after whatever it fronted is gone
Standard SKU public IPs are always statically allocated and always billed. When the load balancer or NIC they fronted goes away, the IP keeps charging.
~$3.65/month at list price per idle Standard static IP Basis: Azure list price. Estimate, not a measurement.
An Azure Bastion bills by the hour even on the days nobody connects
Bastion is billed per deployment-hour, not per session. A host left running in a low-traffic or abandoned VNet charges around the clock for sessions nobody opens.
~$140/month at list price for a Basic SKU, billed hourly regardless of use Basis: Azure list price. Estimate, not a measurement.
An NSG rule allowing 0.0.0.0/0 inbound exposes whatever is behind it to the entire internet
A single inbound allow rule with source Any (0.0.0.0/0) turns whatever sits behind it into a target for the internet's background scanning traffic.
Whatever listens behind the rule is reachable from the entire internet Basis: Azure behavior (authored assessment). Estimate, not a measurement.
An idle VPN Gateway with zero tunnels bills ~$140/mo and up, 24/7
A VPN Gateway bills a fixed hourly rate whether or not a single tunnel is up. There is no stopped state, so an idle gateway is pure waste.
~$140/month at list price for a VpnGw1 with zero active connections Basis: Azure list price. Estimate, not a measurement.
An unattached NAT Gateway routes nothing but still bills ~$32/mo base
A NAT Gateway with no subnet associations provides zero outbound connectivity, but its hourly base rate runs 24/7 with no way to pause it.
~$32/month at list price for the base rate alone, before any data processing Basis: Azure list price. Estimate, not a measurement.
An idle Application Gateway serving zero requests still bills ~$144/mo and up
A fully configured Application Gateway left running bills a flat hourly rate even when it serves zero requests. The only ways to end the charge are to stop it or delete it.
~$144/month at list price for a Standard_v2 that serves no traffic Basis: Azure list price. Estimate, not a measurement.
A "Stopped" VM keeps billing full compute; only "Stopped (deallocated)" stops the meter
Shutting a VM down from inside the guest OS leaves it Stopped, not Deallocated. Azure keeps charging full compute, disks, and reserved IPs as if it were running.
the VM's full hourly compute rate, plus disks and reserved IPs, for as long as it sits Stopped Basis: Azure list price. Estimate, not a measurement.
Disk snapshots nobody deletes bill per-GB storage forever
A disk snapshot is a point-in-time copy that never expires on its own. Kept past its useful life, it accrues per-GB storage charges every month until someone deletes it.
~$0.05/GB/month at list price for Standard HDD snapshot storage, indefinitely Basis: Azure list price. Estimate, not a measurement.
An App Service Plan with zero apps still bills its full tier rate
An App Service Plan bills for its reserved compute tier, not for the apps on it. Delete every app and the plan keeps charging the full rate for hosting nothing.
~$55/mo (B1) to ~$146/mo (P1v2) at list price with no apps hosted Basis: Azure list price. Estimate, not a measurement.
A storage account with zero transactions still bills for every GB it holds
A storage account with zero transactions still bills for the data sitting in it. The charge is the stored bytes, not the activity, so an untouched account keeps costing money.
~$0.02/GB/month at list price for stored data: an idle 1 TiB account is ~$20/month for bytes nobody reads Basis: Azure list price. Estimate, not a measurement.
An empty SQL Elastic Pool bills its full provisioned capacity with no databases in it
A SQL Elastic Pool with no databases keeps billing its provisioned eDTU/vCore capacity. The pool charges for the compute it reserves, whether or not a single database sits in it.
~$75–$465/month at list price depending on tier (Basic/Standard/Premium) for a pool with zero databases Basis: Azure list price. Estimate, not a measurement.
An attached NAT Gateway passing zero traffic keeps billing; there is no paused state
A NAT Gateway still wired to a subnet but moving zero bytes and packets keeps billing its hourly base rate. Azure has no way to pause it.
~$32/month at list price for the base resource charge, plus data-processing, even at zero bytes Basis: Azure list price. Estimate, not a measurement.
An ExpressRoute circuit that was never provisioned still bills, and its gateway bills separately
An ExpressRoute circuit that never completed provisioning with a provider bills its full monthly rate anyway, and the gateway you stood up for it bills on top.
$51 to $11,235/month at list price by bandwidth and peering, plus a separate gateway charge Basis: Azure list price. Estimate, not a measurement.
An empty Traffic Manager profile routes nothing and holds a DNS name for no reason
A Traffic Manager profile with no endpoints can resolve nothing, yet it holds a trafficmanager.net name and sits in inventory as finished-looking dead config.
Negligible standalone charge (Traffic Manager has no per-profile fee); the cost is the abandoned config it signals Basis: Azure list price. Estimate, not a measurement.
A Traffic Manager profile with endpoints but zero DNS queries keeps paying for health checks
A profile that still has endpoints but receives zero DNS queries keeps billing per-endpoint health monitoring for a name no client is using anymore.
~$0.36/endpoint/month at list price for health checks that keep running while nobody resolves the name Basis: Azure list price. Estimate, not a measurement.
A Private DNS zone with zero VNet links resolves nothing and still bills
A Private DNS zone needs a virtual network link to answer queries. With zero links it resolves nothing, yet it keeps billing its per-zone base charge.
~$0.50/month per zone at list price, plus query charges, while resolving nothing Basis: Azure list price. Estimate, not a measurement.
A Front Door WAF policy attached to no profile protects nothing and still bills
A Front Door WAF policy only inspects traffic it is linked to. With no security-policy or endpoint links it protects nothing, but it keeps billing its per-policy rate.
~$5-$20/month per policy at list price (classic Front Door WAF) while attached to nothing Basis: Azure list price. Estimate, not a measurement.
An idle Container Registry with zero pulls and pushes bills its tier's daily rate
Azure Container Registry bills a fixed daily rate for its tier regardless of use. A registry with zero pulls and pushes keeps charging as if it were in active service.
~$5/month Basic, ~$20 Standard, ~$50 Premium at list price while idle Basis: Azure list price. Estimate, not a measurement.
An oversized VM runs at single-digit CPU while billing for a SKU the workload never uses
A VM sits at a fraction of its provisioned CPU and memory, so you pay for a SKU far larger than the workload uses. Nothing is broken, so nothing prompts a resize.
~$210/month at list price for the gap between a D8s_v5 and the D2s_v5 the workload actually needs Basis: Azure list price. Estimate, not a measurement.
A single resource's daily spend spikes above its baseline while the subscription budget stays quiet
One resource's daily cost jumps sharply above its normal level. Subscription-total budget alerts don't see it, so the spike inflates the bill until month-end.
The overspend equals the gap between a resource's baseline daily cost and its spiked daily cost, sustained until someone notices Basis: Azure behavior (authored assessment). Estimate, not a measurement.
A resource quietly settles into a new, higher cost baseline and the step-up becomes the new normal
A resource's spend steps up to a permanently higher level and stays there. Unlike a spike it never comes back down, so it's easy to accept as the new normal.
The step-up in daily cost, paid every day indefinitely because the new higher level never trips a threshold twice Basis: Azure behavior (authored assessment). Estimate, not a measurement.
Every footgun, by Azure service
The complete index of all 97 published entries. The search above is faster if you know what you are looking for; this is the list to browse.
Azure AI Search
Azure AI services (incl. Azure OpenAI)
Azure App Service
- Azure Footgun No. 12An App Service Plan with zero apps still bills its full tier rate
- Azure Footgun No. 32App Service public network access flipped back on exposes the app to the whole internet
- Azure Footgun No. 89An App Service with no managed identity runs on secrets that leak, sprawl, and never expire
Azure Application Gateway
- Azure Footgun No. 9An idle Application Gateway serving zero requests still bills ~$144/mo and up
- Azure Footgun No. 38An Application Gateway with empty backend pools returns silent 502s while billing hourly
- Azure Footgun No. 90A Standard-SKU Application Gateway load-balances attacks as happily as legitimate traffic
Azure Bastion
- Azure Footgun No. 5An Azure Bastion bills by the hour even on the days nobody connects
Azure Cache for Redis
Azure Compute quotas
Azure Container Registry
- Azure Footgun No. 21An idle Container Registry with zero pulls and pushes bills its tier's daily rate
- Azure Footgun No. 66A container registry with public network access enabled exposes your image supply chain to the internet
- Azure Footgun No. 67The ACR admin user is one shared credential with full push and pull over every image
- Azure Footgun No. 68Anonymous pull enabled: anyone on the internet can download your container images
Azure Cosmos DB
- Azure Footgun No. 28Cosmos DB with public network access enabled puts your database on the internet
- Azure Footgun No. 64Cosmos DB master keys are on by default: full account access outside Entra ID and RBAC
- Azure Footgun No. 65A multi-region Cosmos DB account with automatic failover off still needs a human during the outage
Azure Cost Management
Azure DDoS Protection
- Azure Footgun No. 1A forgotten DDoS Protection Plan bills ~$2,944/mo while protecting nothing
Azure DNS (Private)
- Azure Footgun No. 19A Private DNS zone with zero VNet links resolves nothing and still bills
Azure Database for MySQL
Azure Database for PostgreSQL
Azure Event Hubs
Azure ExpressRoute
Azure Firewall
- Azure Footgun No. 47An orphaned IP Group is a stale allowlist no firewall rule references
- Azure Footgun No. 48An orphaned Firewall Policy is a full ruleset that protects nothing
Azure Front Door
- Azure Footgun No. 20A Front Door WAF policy attached to no profile protects nothing and still bills
Azure Key Vault
- Azure Footgun No. 2Key Vault purge protection is off by default, so a deleted vault can be gone for good
- Azure Footgun No. 29Key Vault with public network access enabled exposes your secrets to any network
- Azure Footgun No. 30A Key Vault firewall set to default Allow quietly undoes every network rule you added
- Azure Footgun No. 31A Key Vault with soft-delete disabled makes deleted secrets and keys unrecoverable
- Azure Footgun No. 63Key Vault legacy access policies: a parallel permission system your RBAC reviews never see
Azure Kubernetes Service
- Azure Footgun No. 73An AKS cluster's public API server puts the Kubernetes control plane on the internet
- Azure Footgun No. 74AKS local accounts hand out a cluster-admin kubeconfig that bypasses Entra ID
- Azure Footgun No. 75An AKS cluster with Kubernetes RBAC disabled makes every credential cluster-admin, and only a rebuild fixes it
- Azure Footgun No. 76An AKS cluster with no network policy engine lets one compromised pod reach every other pod
Azure Load Balancer
- Azure Footgun No. 39A Load Balancer with an empty backend pool silently drops all inbound traffic
Azure Logic Apps
- Azure Footgun No. 49An orphaned API Connection is a stored credential no workflow uses
Azure Managed Disks
- Azure Footgun No. 3An unattached managed disk bills its full provisioned size forever
- Azure Footgun No. 11Disk snapshots nobody deletes bill per-GB storage forever
- Azure Footgun No. 77A managed disk open to public export is one SAS URL from full disk exfiltration
Azure NAT Gateway
- Azure Footgun No. 8An unattached NAT Gateway routes nothing but still bills ~$32/mo base
- Azure Footgun No. 15An attached NAT Gateway passing zero traffic keeps billing; there is no paused state
Azure Network Security Groups
- Azure Footgun No. 6An NSG rule allowing 0.0.0.0/0 inbound exposes whatever is behind it to the entire internet
- Azure Footgun No. 94An NSG public-IP allowlist on SSH, RDP, or database ports is still a management port on the internet
- Azure Footgun No. 97RDP, SSH, or a database port open to the internet: the misconfiguration bots find in minutes
Azure Private Link
Azure Public IP
- Azure Footgun No. 36A newly attached public IP quietly puts a resource on the internet
Azure RBAC
- Azure Footgun No. 50An Owner role that only ever reads: over-privileged RBAC no one downgrades
- Azure Footgun No. 51Subscription-wide RBAC for work that lives in one resource group
- Azure Footgun No. 52A privileged role assignment nobody has used, still standing
- Azure Footgun No. 53A privileged role assignment keeps full standing access for months after anyone last used it
- Azure Footgun No. 54The same role granted separately across 5+ subscriptions signals blanket over-provisioning, not intent
- Azure Footgun No. 55A role assignment already covered by a broader grant adds no access, only audit noise
Azure RBAC / Entra ID
Azure RBAC / Entra ID PIM
Azure Reservations & Savings Plans
Azure Resource Manager
- Azure Footgun No. 46An empty resource group is dead scaffolding that complicates governance
Azure SQL Database
Azure Service Bus
Azure SignalR Service / Web PubSub
Azure Storage
- Azure Footgun No. 13A storage account with zero transactions still bills for every GB it holds
- Azure Footgun No. 25A storage account with public network access enabled puts its data at the internet edge
- Azure Footgun No. 26Blob public access turns containers into an anonymous, unauthenticated download link
- Azure Footgun No. 35Storage infrastructure encryption silently drops your second at-rest layer
- Azure Footgun No. 59A storage firewall set to default Allow leaves every network path to the account open
- Azure Footgun No. 60Shared key authorization lets anyone holding a storage account key bypass Entra ID entirely
- Azure Footgun No. 61Cross-tenant replication left enabled lets a storage account copy blobs into someone else's tenant
- Azure Footgun No. 62A general-purpose v1 storage account runs production data on a retired-in-2026 account model
Azure Storage / App Service
Azure Storage / SQL / App Service
Azure Traffic Manager
Azure VPN Gateway
- Azure Footgun No. 7An idle VPN Gateway with zero tunnels bills ~$140/mo and up, 24/7
Azure Virtual Machines
- Azure Footgun No. 10A "Stopped" VM keeps billing full compute; only "Stopped (deallocated)" stops the meter
- Azure Footgun No. 22An oversized VM runs at single-digit CPU while billing for a SKU the workload never uses
- Azure Footgun No. 78A VM without Trusted Launch has no Secure Boot or vTPM: rootkits load below your EDR
- Azure Footgun No. 79Boot diagnostics disabled: when the VM won't start, you're debugging a black box
- Azure Footgun No. 80A VM still on unmanaged OS disks runs a retired storage model Azure can stop and deallocate
- Azure Footgun No. 81A Linux VM accepting SSH passwords puts brute-forceable credentials on the internet's most attacked port
Azure Virtual Network
- Azure Footgun No. 4A reserved Standard public IP keeps billing after whatever it fronted is gone
- Azure Footgun No. 41An unattached NIC costs nothing but leaves stale NSG rules pointing at a ghost
- Azure Footgun No. 42An orphaned NSG protects nothing and drifts into a misleading audit trail
- Azure Footgun No. 43An unattached route table is free config clutter with zero effect on traffic
- Azure Footgun No. 44An empty VNet provides no networking and just complicates your address plan
- Azure Footgun No. 45An empty subnet reserves address space and serves no workload
- Azure Footgun No. 92A subnet with no NSG leaves every workload in it with zero network filtering
- Azure Footgun No. 93A VNet peering stuck outside the Connected state silently black-holes cross-network traffic
Azure Web Application Firewall
- Azure Footgun No. 91A WAF policy stuck in Detection mode logs every attack and blocks none of them
Stop hunting these one at a time
Every footgun in this database, checked on every scan, inside your own tenant. You find out from a report, not from the bill.
When the 14 days end, billing starts on your Azure invoice at your tier. One toggle in Settings turns it off, any time.