# Unassociated or Redundant DDoS Network Protection Plans

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/unassociated-or-redundant-ddos-network-protection-plans

An Azure DDoS Network Protection plan carries a fixed monthly fee for as long as the plan resource exists, whether or not any virtual network is linked...

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

An Azure DDoS Network Protection plan carries a fixed monthly fee for as long as the plan resource exists, whether or not any virtual network is linked to it.

PointFive Research

Cloud cost research at PointFive

Azure service

[Azure DDoS Protection](https://www.pointfive.co/efficiency-hub/cloud-services/azure-ddos-protection)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0419

Type

Idle or Unused Resource

## Explanation

Why the waste happens and who it affects.

Plans are left behind when the virtual networks they protected are deleted or migrated, or when a team disables DDoS protection on a virtual network and assumes that stops the charge. Microsoft notes explicitly that disabling protection on a virtual network does not delete the plan and the plan keeps incurring costs.

A second pattern is paying for several plans where one would do. A single plan can protect virtual networks in any region and in any subscription under the same Microsoft Entra tenant, and Microsoft suggests one plan per organization. Estates where each subscription, landing zone or business unit created its own plan pay the fixed fee once per plan instead of once per tenant.

## Billing model

The pricing dimensions that drive this cost.

DDoS Network Protection is priced per plan, not per virtual network.

Plan monthly charge

A fixed monthly fee per DDoS protection plan that includes protection for 100 public IP resources; listed at 2,944 USD per month (Central US) and billed to the subscription that holds the plan

Overage

Each protected public IP resource beyond 100 is billed per resource per month; resources are counted at the enrollment level

Partial month

A plan active for only part of a month is billed prorated for the hours it existed

Cross-subscription linking

One plan can be linked to virtual networks in multiple subscriptions and regions in the same tenant at no extra plan fee

## How to detect

5 checks to find it in your estate.

- Run the Azure Resource Graph query from the Microsoft FinOps networking guidance: resources where type =~ 'microsoft.network/ddosprotectionplans' and properties.virtualNetworks is null or has length 0; these plans protect nothing

- FinOps hubs includes a built-in Remove unassociated DDoS plans recommendation that runs this check daily

- Count microsoft.network/ddosprotectionplans resources per tenant; more than one plan in the same tenant is a candidate for consolidation

- For each plan, open Settings \> Protected resources to see which virtual networks and public IPs it protects, and compare the count with the 100 resources included in the fee

- In Cost Management, filter to the Azure DDoS Protection service and group by resource to see which subscriptions are paying a plan fee

## How to fix

4 ways to remove the waste.

- Delete plans that have no linked virtual networks; disabling DDoS protection on virtual networks alone does not stop the charge

- Consolidate multiple plans into one tenant-wide plan: link each virtual network to the surviving plan from the plan's Protected resources page or the virtual network's DDoS protection setting, then dissociate all virtual networks from the redundant plans and delete them, since a plan cannot be deleted while virtual networks are still associated

- Keep separate plans only where there is a hard requirement such as separate tenants or separate billing ownership, and document the reason

- Standardize on the central plan for new virtual networks, for example through landing zone templates or the built-in Azure Policy definition that detects virtual networks without DDoS Network Protection and can create remediation tasks, so teams do not create additional plans

## Documentation

Vendor references for pricing and configuration.

- [Azure DDoS Protection Pricing  azure.microsoft.com](https://azure.microsoft.com/en-us/pricing/details/ddos-protection/)

- [FinOps best practices for Networking  learn.microsoft.com](https://learn.microsoft.com/en-us/cloud-computing/finops/best-practices/networking)

- [Quickstart: Create and configure Azure DDoS Network Protection using the Azure portal  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/ddos-protection/manage-ddos-protection)

- [Configure FinOps hubs recommendations  learn.microsoft.com](https://learn.microsoft.com/en-us/cloud-computing/finops/toolkit/hubs/configure-recommendations)

- [About Azure DDoS Protection Tier Comparison  learn.microsoft.com](https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-protection-sku-comparison)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- Azure DDoS Protection  CER-0420

### [DDoS Network Protection Plan Protecting Few Public IPs](https://www.pointfive.co/efficiency-hub/inefficiencies/ddos-network-protection-plan-protecting-few-public-ips)

Azure DDoS Protection has two paid tiers. Network Protection is a plan with a fixed monthly fee that covers up to 100 public IP resources in the linked virtual networks, while IP Protection is enabled on individual Standard public IPs and...

Networking

- Azure NAT Gateway  CER-0319

### [Idle Azure NAT Gateway Attached to Subnet Without Active Workloads](https://www.pointfive.co/efficiency-hub/inefficiencies/idle-azure-nat-gateway-attached-to-subnet-without-active-workloads)

Azure NAT Gateways are commonly deployed to provide outbound internet connectivity for resources within virtual network subnets. Over time, the workloads that originally required this outbound access may be scaled down, migrated, or...

Networking

- Azure Private Link  CER-0318

### [Orphaned Private Endpoints After Target Service Deletion](https://www.pointfive.co/efficiency-hub/inefficiencies/orphaned-private-endpoints-after-target-service-deletion)

Azure Private Endpoints are network interfaces that provide private connectivity from a virtual network to Azure PaaS services such as Storage Accounts, SQL Databases, or Key Vaults. When the target service behind a private endpoint is...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

