# DDoS Network Protection Plan Protecting Few Public IPs

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/ddos-network-protection-plan-protecting-few-public-ips

Azure DDoS Protection has two paid tiers. Network Protection is a plan with a fixed monthly fee that covers up to 100 public IP resources in the linked...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Azure DDoS Protection has two paid tiers.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure DDoS Protection](https://www.pointfive.co/efficiency-hub/cloud-services/azure-ddos-protection)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0420

Type

Suboptimal Tier or SKU

## Explanation

Why the waste happens and who it affects.

Network Protection is a plan with a fixed monthly fee that covers up to 100 public IP resources in the linked virtual networks, while IP Protection is enabled on individual Standard public IPs and billed per protected IP. Network Protection is often enabled as a platform default and then linked to a handful of virtual networks that expose only a few public IPs, so the organization pays the full plan fee to protect far fewer resources than it includes.

Microsoft's own guidance is that IP Protection is more cost-effective when fewer than 15 public IP resources need protection, and Network Protection becomes cheaper above that. The choice is not purely about price: Network Protection adds DDoS Rapid Response support, cost protection for scale-out during an attack, and a WAF discount on Application Gateway, so the comparison must include whether those features are used.

## Billing model

The pricing dimensions that drive this cost.

The two tiers are billed on different units, which creates a break-even point around 15 protected public IPs.

Network Protection plan

A fixed monthly fee per plan that includes 100 protected public IP resources, with a per-resource monthly overage above 100

IP Protection

A fixed monthly charge per protected public IP resource; listed at 199 USD per public IP per month (Central US), with the plan fee listed at 2,944 USD per month

WAF discount

Application Gateway WAF and WAF\_v2 in a virtual network protected by Network Protection are billed at the non-WAF gateway rate; IP Protection does not include this discount

Network Protection only features

DDoS Rapid Response support, cost protection credits for scale-out during an attack, and Basic public IP protection are not available with IP Protection

## How to detect

5 checks to find it in your estate.

- List DDoS protection plans (microsoft.network/ddosprotectionplans) and, for each, open Settings \> Protected resources to count the public IP resources it actually protects across the linked virtual networks

- Flag plans that protect fewer than 15 public IP resources in total across the tenant, since Microsoft states IP Protection is cheaper below that count

- Check whether Application Gateway WAF or WAF\_v2 instances sit in the protected virtual networks; the WAF discount they receive under Network Protection must be added to the comparison

- Confirm with the security owner whether DDoS Rapid Response or cost protection are required for the protected workloads

- For the opposite case, run the FinOps networking query that counts public IPs whose ddosSettings are Enabled (per-IP protection); 15 or more per-IP protected addresses suggests a single Network Protection plan would be cheaper

## How to fix

4 ways to remove the waste.

- Where the protected public IP count is well below 15 and Network Protection only features are not needed, enable IP Protection on each public IP (Properties \> DDoS protection \> Protection type IP), then disable Network Protection on the virtual networks and delete the plan; disabling alone does not stop the plan fee

- Enable IP Protection before removing the plan so the public IPs are never left with only the free infrastructure protection; IP Protection can be enabled only on Standard SKU public IPs

- Keep Network Protection where the protected count is near or above the break-even, where WAF discounts on Application Gateway offset the fee, or where Rapid Response and cost protection are required

- Review the decision when public IP counts change, since the break-even applies across the whole tenant rather than per virtual network

## Documentation

Vendor references for pricing and configuration.

- [Azure DDoS Protection Pricing  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/ddos-protection/)

- [About Azure DDoS Protection Tier Comparison  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-protection-sku-comparison)

- [FinOps best practices for Networking  learn.microsoft.com](https://learn.microsoft.com/en-us/cloud-computing/finops/best-practices/networking)

- [QuickStart: Create and configure Azure DDoS IP Protection - Azure portal  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-ip-protection-portal)

- [Quickstart: Create and configure Azure DDoS Network Protection using the Azure portal  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure DDoS Protection  CER-0419

### [Unassociated or Redundant DDoS Network Protection Plans](https://www.pointfive.co/efficiency-hub/inefficiencies/unassociated-or-redundant-ddos-network-protection-plans)

An Azure DDoS Network Protection plan carries a fixed monthly fee for as long as the plan resource exists, whether or not any virtual network is linked to it. Plans are left behind when the virtual networks they protected are deleted or...

Networking

- Azure API Management  CER-0459

### [Premium or Standard API Management Tiers on Non-Production Instances](https://www.pointfive.co/efficiency-hub/inefficiencies/premium-or-standard-api-management-tiers-on-non-production-instances)

Development, test and proof-of-concept API Management instances are often deployed on the same Premium or Standard tier as production, sometimes with several units, because environments are cloned from the production template. Dedicated...

Networking

- Azure NAT Gateway  CER-0319

### [Idle Azure NAT Gateway Attached to Subnet Without Active Workloads](https://www.pointfive.co/efficiency-hub/inefficiencies/idle-azure-nat-gateway-attached-to-subnet-without-active-workloads)

Azure NAT Gateways are commonly deployed to provide outbound internet connectivity for resources within virtual network subnets. Over time, the workloads that originally required this outbound access may be scaled down, migrated, or...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

