# Overprovisioned Minimum Instance Count on Application Gateway v2

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/overprovisioned-minimum-instance-count-on-application-gateway-v2

Application Gateway v2 (Standard_v2 and WAF_v2) bills reserved capacity for every instance in the manual instance count or the autoscale minimum.

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

Application Gateway v2 (Standard\_v2 and WAF\_v2) bills reserved capacity for every instance in the manual instance count or the autoscale minimum.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure Application Gateway](https://www.pointfive.co/efficiency-hub/cloud-services/azure-application-gateway)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0411

Type

Overprovisioned Resource

## Explanation

Why the waste happens and who it affects.

Each such instance reserves 10 capacity units, and those units are billed every hour the gateway is active whether or not any traffic uses them. Teams often choose a high manual count or a high autoscale minimum at launch for safety, or copy production settings into every environment, and never revisit it once real traffic is known.

The result is that Estimated Billed Capacity Units sits flat at the Fixed Billable Capacity Units level while Current Capacity Units stay far below it. Some headroom is deliberate: new instances take three to five minutes to provision, and Microsoft suggests keeping the minimum well above zero for gateways with sharp traffic bursts. The waste is the gap between that justified buffer and a minimum sized for a peak that never arrives, which is most common on gateways left in manual mode and on non-production gateways configured like production.

## Billing model

The pricing dimensions that drive this cost.

v2 gateways are billed as a fixed hourly charge plus capacity units, computed hourly.

Capacity unit

The highest of compute units, persistent connections (2,500 per CU) and throughput (1 GB per hour per CU) consumed in the hour

Reserved capacity units

10 per instance of the manual count or autoscale minimum, billed while the gateway is active regardless of consumption

Estimated billed capacity units

The greater of current capacity units and fixed billable capacity units, which is what the variable charge is based on

Maximum instance count

An upper limit only; raising it does not add cost because only consumed capacity is billed

## How to detect

4 checks to find it in your estate.

- Chart the gateway metrics Fixed Billable Capacity Units, Current Capacity Units and Estimated Billed Capacity Units over the last 30 days; when estimated billed units equal fixed billable units most of the time, the reservation from the instance count is driving the bill

- List v2 gateways and their scaling mode with Azure Resource Graph (type microsoft.network/applicationgateways, properties.sku.capacity for manual mode and properties.autoscaleConfiguration.minCapacity for autoscaling) and flag high manual counts or minimums

- Compare the configured minimum with Microsoft's sizing guidance: take the peak Current Compute Units over the past month and divide by 10 to estimate the instances needed

- Flag non-production gateways whose minimum or manual instance count matches production

## How to fix

5 ways to remove the waste.

- Switch gateways from manual mode to autoscaling so capacity follows traffic instead of being fixed at the provisioned count

- Lower the autoscale minimum to a level derived from observed compute units plus the buffer your burst profile needs, remembering that scale-out takes three to five minutes

- Set a minimum of 0 for low-traffic and non-production gateways where brief latency during scale-out is acceptable; the fixed hourly charge still applies

- Set the maximum instance count high (up to 125, subnet size permitting) instead of relying on a high minimum for protection, since the maximum does not add cost

- Add alerts on Current Compute Units and Current Capacity Units so the minimum can be raised deliberately if sustained traffic grows

## Documentation

Vendor references for pricing and configuration.

- [Understanding pricing - Azure Application Gateway  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/application-gateway/understanding-pricing)

- [Scaling and Zone-redundant Application Gateway v2  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-autoscaling-zone-redundant)

- [Application Gateway high traffic volume support  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/application-gateway/high-traffic-support)

- [Architecture Best Practices for Azure Application Gateway v2  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/well-architected/service-guides/azure-application-gateway)

- [Application Gateway pricing  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/application-gateway/)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure Firewall  CER-0313

### [Azure Firewall Premium SKU Deployed Without Using Premium Features](https://www.pointfive.co/efficiency-hub/inefficiencies/azure-firewall-premium-sku-deployed-without-using-premium-features)

Azure Firewall is available in three SKUs - Basic, Standard, and Premium - each designed for different security requirements and priced accordingly. The Premium SKU includes advanced threat protection capabilities such as TLS inspection,...

Networking

- Azure Virtual WAN  CER-0300

### [Overprovisioned Azure Virtual WAN Hub Capacity](https://www.pointfive.co/efficiency-hub/inefficiencies/overprovisioned-azure-virtual-wan-hub-capacity-a123)

An Azure Virtual WAN hub is provisioned with more capacity than required to support real network traffic. Because hub costs scale with the number of configured scale units, overprovisioned hubs continue to incur higher charges even when...

Networking

- Azure NAT Gateway  CER-0319

### [Idle Azure NAT Gateway Attached to Subnet Without Active Workloads](https://www.pointfive.co/efficiency-hub/inefficiencies/idle-azure-nat-gateway-attached-to-subnet-without-active-workloads)

Azure NAT Gateways are commonly deployed to provide outbound internet connectivity for resources within virtual network subnets. Over time, the workloads that originally required this outbound access may be scaled down, migrated, or...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

