Explanation
Why the waste happens and who it affects.
Network Protection is a plan with a fixed monthly fee that covers up to 100 public IP resources in the linked virtual networks, while IP Protection is enabled on individual Standard public IPs and billed per protected IP. Network Protection is often enabled as a platform default and then linked to a handful of virtual networks that expose only a few public IPs, so the organization pays the full plan fee to protect far fewer resources than it includes.
Microsoft's own guidance is that IP Protection is more cost-effective when fewer than 15 public IP resources need protection, and Network Protection becomes cheaper above that. The choice is not purely about price: Network Protection adds DDoS Rapid Response support, cost protection for scale-out during an attack, and a WAF discount on Application Gateway, so the comparison must include whether those features are used.
Billing model
The pricing dimensions that drive this cost.
The two tiers are billed on different units, which creates a break-even point around 15 protected public IPs.
- Network Protection plan
- A fixed monthly fee per plan that includes 100 protected public IP resources, with a per-resource monthly overage above 100
- IP Protection
- A fixed monthly charge per protected public IP resource; listed at 199 USD per public IP per month (Central US), with the plan fee listed at 2,944 USD per month
- WAF discount
- Application Gateway WAF and WAF_v2 in a virtual network protected by Network Protection are billed at the non-WAF gateway rate; IP Protection does not include this discount
- Network Protection only features
- DDoS Rapid Response support, cost protection credits for scale-out during an attack, and Basic public IP protection are not available with IP Protection
How to detect
5 checks to find it in your estate.
- List DDoS protection plans (microsoft.network/ddosprotectionplans) and, for each, open Settings > Protected resources to count the public IP resources it actually protects across the linked virtual networks
- Flag plans that protect fewer than 15 public IP resources in total across the tenant, since Microsoft states IP Protection is cheaper below that count
- Check whether Application Gateway WAF or WAF_v2 instances sit in the protected virtual networks; the WAF discount they receive under Network Protection must be added to the comparison
- Confirm with the security owner whether DDoS Rapid Response or cost protection are required for the protected workloads
- For the opposite case, run the FinOps networking query that counts public IPs whose ddosSettings are Enabled (per-IP protection); 15 or more per-IP protected addresses suggests a single Network Protection plan would be cheaper
How to fix
4 ways to remove the waste.
- Where the protected public IP count is well below 15 and Network Protection only features are not needed, enable IP Protection on each public IP (Properties > DDoS protection > Protection type IP), then disable Network Protection on the virtual networks and delete the plan; disabling alone does not stop the plan fee
- Enable IP Protection before removing the plan so the public IPs are never left with only the free infrastructure protection; IP Protection can be enabled only on Standard SKU public IPs
- Keep Network Protection where the protected count is near or above the break-even, where WAF discounts on Application Gateway offset the fee, or where Rapid Response and cost protection are required
- Review the decision when public IP counts change, since the break-even applies across the whole tenant rather than per virtual network
Documentation
Vendor references for pricing and configuration.
- Azure DDoS Protection Pricingazure.microsoft.com
- About Azure DDoS Protection Tier Comparisonlearn.microsoft.com
- FinOps best practices for Networkinglearn.microsoft.com
- QuickStart: Create and configure Azure DDoS IP Protection - Azure portallearn.microsoft.com
- Quickstart: Create and configure Azure DDoS Network Protection using the Azure portallearn.microsoft.com