
Public IP addresses are easy to forget. You create one because a VM, load balancer or another service needs it. Later, the resource is removed or migrated, but the IP address is still sitting there in the subscription.
One forgotten IP probably won’t make anyone worry about the Azure bill. But if you have dozens of them across multiple subscriptions, it’s worth taking a closer look.
Unattached doesn’t always mean unused
I wouldn’t recommend deleting every unattached public IP automatically. There may be a reason why someone is keeping it. For example, the IP might be reserved for a future deployment, be part of a migration, or be documented as a known dependency.
This is why I prefer to treat unattached IPs as candidates for investigation, rather than resources that should immediately be deleted.
Automating the discovery
Checking every subscription manually isn’t particularly practical, especially in a larger Azure environment. That’s why I created a small PowerShell runbook to do the boring part for me. It scans Azure subscriptions for unattached public IP addresses and saves the results to an Azure Storage Account. The report includes details such as subscription, resource group, resource ID, IP address, SKU, tags and provisioning state.
You can find the script on GitHub:
GitHub – Azure FinOps Unattached Public IPs
The script is intentionally focused on discovery, not automatic deletion.
I prefer this approach because an unattached resource can still have a valid reason for existing. The automation helps you find potential savings, while the final cleanup decision stays with the resource owner.
A simple FinOps win
Unattached public IPs probably won’t be the biggest item on your Azure invoice. But they are easy to find, easy to investigate and, once confirmed as unnecessary, easy to clean up. That’s exactly why I like including them in a regular FinOps review.

Leave a Reply