Explanation
Why the waste happens and who it affects.
Plans are left behind when the virtual networks they protected are deleted or migrated, or when a team disables DDoS protection on a virtual network and assumes that stops the charge. Microsoft notes explicitly that disabling protection on a virtual network does not delete the plan and the plan keeps incurring costs.
A second pattern is paying for several plans where one would do. A single plan can protect virtual networks in any region and in any subscription under the same Microsoft Entra tenant, and Microsoft suggests one plan per organization. Estates where each subscription, landing zone or business unit created its own plan pay the fixed fee once per plan instead of once per tenant.
Billing model
The pricing dimensions that drive this cost.
DDoS Network Protection is priced per plan, not per virtual network.
- Plan monthly charge
- A fixed monthly fee per DDoS protection plan that includes protection for 100 public IP resources; listed at 2,944 USD per month (Central US) and billed to the subscription that holds the plan
- Overage
- Each protected public IP resource beyond 100 is billed per resource per month; resources are counted at the enrollment level
- Partial month
- A plan active for only part of a month is billed prorated for the hours it existed
- Cross-subscription linking
- One plan can be linked to virtual networks in multiple subscriptions and regions in the same tenant at no extra plan fee
How to detect
5 checks to find it in your estate.
- Run the Azure Resource Graph query from the Microsoft FinOps networking guidance: resources where type =~ 'microsoft.network/ddosprotectionplans' and properties.virtualNetworks is null or has length 0; these plans protect nothing
- FinOps hubs includes a built-in Remove unassociated DDoS plans recommendation that runs this check daily
- Count microsoft.network/ddosprotectionplans resources per tenant; more than one plan in the same tenant is a candidate for consolidation
- For each plan, open Settings > Protected resources to see which virtual networks and public IPs it protects, and compare the count with the 100 resources included in the fee
- In Cost Management, filter to the Azure DDoS Protection service and group by resource to see which subscriptions are paying a plan fee
How to fix
4 ways to remove the waste.
- Delete plans that have no linked virtual networks; disabling DDoS protection on virtual networks alone does not stop the charge
- Consolidate multiple plans into one tenant-wide plan: link each virtual network to the surviving plan from the plan's Protected resources page or the virtual network's DDoS protection setting, then dissociate all virtual networks from the redundant plans and delete them, since a plan cannot be deleted while virtual networks are still associated
- Keep separate plans only where there is a hard requirement such as separate tenants or separate billing ownership, and document the reason
- Standardize on the central plan for new virtual networks, for example through landing zone templates or the built-in Azure Policy definition that detects virtual networks without DDoS Network Protection and can create remediation tasks, so teams do not create additional plans
Documentation
Vendor references for pricing and configuration.
- Azure DDoS Protection Pricingazure.microsoft.com
- FinOps best practices for Networkinglearn.microsoft.com
- Quickstart: Create and configure Azure DDoS Network Protection using the Azure portallearn.microsoft.com
- Configure FinOps hubs recommendationslearn.microsoft.com
- About Azure DDoS Protection Tier Comparisonlearn.microsoft.com