Skip to content
Cloud Efficiency Hub

Unassociated or Redundant DDoS Network Protection Plans

The short version

An Azure DDoS Network Protection plan carries a fixed monthly fee for as long as the plan resource exists, whether or not any virtual network is linked to it.

PointFive Research

Cloud cost research at PointFive

Category
Networking
Reference
CER-0419
Type
Idle or Unused Resource

Explanation

Why the waste happens and who it affects.

Plans are left behind when the virtual networks they protected are deleted or migrated, or when a team disables DDoS protection on a virtual network and assumes that stops the charge. Microsoft notes explicitly that disabling protection on a virtual network does not delete the plan and the plan keeps incurring costs.

A second pattern is paying for several plans where one would do. A single plan can protect virtual networks in any region and in any subscription under the same Microsoft Entra tenant, and Microsoft suggests one plan per organization. Estates where each subscription, landing zone or business unit created its own plan pay the fixed fee once per plan instead of once per tenant.

Billing model

The pricing dimensions that drive this cost.

DDoS Network Protection is priced per plan, not per virtual network.

Plan monthly charge
A fixed monthly fee per DDoS protection plan that includes protection for 100 public IP resources; listed at 2,944 USD per month (Central US) and billed to the subscription that holds the plan
Overage
Each protected public IP resource beyond 100 is billed per resource per month; resources are counted at the enrollment level
Partial month
A plan active for only part of a month is billed prorated for the hours it existed
Cross-subscription linking
One plan can be linked to virtual networks in multiple subscriptions and regions in the same tenant at no extra plan fee

How to detect

5 checks to find it in your estate.

  • Run the Azure Resource Graph query from the Microsoft FinOps networking guidance: resources where type =~ 'microsoft.network/ddosprotectionplans' and properties.virtualNetworks is null or has length 0; these plans protect nothing
  • FinOps hubs includes a built-in Remove unassociated DDoS plans recommendation that runs this check daily
  • Count microsoft.network/ddosprotectionplans resources per tenant; more than one plan in the same tenant is a candidate for consolidation
  • For each plan, open Settings > Protected resources to see which virtual networks and public IPs it protects, and compare the count with the 100 resources included in the fee
  • In Cost Management, filter to the Azure DDoS Protection service and group by resource to see which subscriptions are paying a plan fee

How to fix

4 ways to remove the waste.

  • Delete plans that have no linked virtual networks; disabling DDoS protection on virtual networks alone does not stop the charge
  • Consolidate multiple plans into one tenant-wide plan: link each virtual network to the surviving plan from the plan's Protected resources page or the virtual network's DDoS protection setting, then dissociate all virtual networks from the redundant plans and delete them, since a plan cannot be deleted while virtual networks are still associated
  • Keep separate plans only where there is a hard requirement such as separate tenants or separate billing ownership, and document the reason
  • Standardize on the central plan for new virtual networks, for example through landing zone templates or the built-in Azure Policy definition that detects virtual networks without DDoS Network Protection and can create remediation tasks, so teams do not create additional plans

Documentation

Vendor references for pricing and configuration.