Networking

How to Detect and Delete Unassociated Azure Public IP Addresses

Static and dynamic Public IPv4 addresses in Azure incur continuous hourly reservation fees even when they are not associated with a Network Interface (NIC), Load Balancer, or Application Gateway. Learn how to audit and release orphan IPs across all subscriptions.

Odinext Cloud Engineering

Azure Infrastructure & FinOps Research

Published: August 20, 2026
5 min read
(Updated: August 22, 2026)

Why Unused Public IPs Accumulate

When an Azure Virtual Machine, Bastion Host, or Application Gateway is decommissioned, its allocated Public IP resource is often preserved as an independent Azure Resource Manager (ARM) asset.

Because Microsoft charges for provisioned IPv4 reservations regardless of whether active traffic flows through them, forgotten public IPs quietly consume monthly cloud budget.

IPv4 Pricing Policy

Microsoft Azure charges hourly rates for all static and standard public IPv4 addresses, even if they have null network interface bindings.

Azure Resource Graph Query for Orphan IPs

You can scan all subscriptions in your Azure tenant for unassociated Public IPs using this Kusto query in Azure Resource Graph Explorer:

Azure Resource Graph Query
kusto
Resources
| where type =~ 'microsoft.network/publicipaddresses'
| where properties.ipConfiguration == '' or isnull(properties.ipConfiguration)
| project name, resourceGroup, subscriptionId, location, properties.publicIPAllocationMethod, sku = properties.sku.name

Monthly Financial Impact of Reserved IPv4

While a single unused IP costs approximately $3.60 to $5.00/month, microservices and Kubernetes clusters with automated ingress controllers often leave dozens of orphan IPs behind, wasting hundreds of dollars every quarter across multiple subscription environments.

Releasing Unassociated IPs via Azure CLI

Once you have confirmed an IP is no longer required by any active DNS record or firewall allowlist, delete it using the Azure CLI:

Azure CLI Command
bash
# Delete an unassociated public IP
az network public-ip delete --resource-group rg-networking --name pip-decommissioned-vm

Continuous IP Hygiene with WasteRadar

WasteRadar automatically scans your entire Azure estate daily, flagging unassociated public IPs the moment workloads are destroyed and routing instant remediation alerts to your engineering team.

Odinext Cloud Engineering

Azure Infrastructure & FinOps Research

The Odinext engineering team specializes in Azure cost management, ARM resource optimization, and automated cloud waste detection across enterprise multi-subscription architectures.

Automate This Analysis with WasteRadar

Stop running manual resource queries and spreadsheets. Odinext WasteRadar detects idle compute, unattached disks, and orphaned snapshots automatically with 100% read-only Azure IAM integration.

Related Technical Guides

Continue exploring Azure cloud cost optimization and FinOps architecture