TL
The short answer

The biggest Azure waste categories are idle and deallocated but still billed resources, oversized virtual machines and managed disks, orphaned disks, public IPs, and load balancers left behind by deleted workloads, premium storage and disk tiers on data with no performance need, and uncapped Log Analytics and Azure Monitor ingestion. Each is fixed by removing or resizing the resource, not by a discount, which is why they are the first work on any Azure estate and why they pay back without any commitment. Together they routinely account for a large share of an unmanaged Azure bill. The pattern is consistent: spend created by inertia and default settings rather than by genuine demand.

Here is each category, why it accumulates, and the move that removes it.

Which categories waste the most, and how do you cut them?

Waste categoryWhy it happensThe no regret move
Idle and underused VMsProvisioned for peak, never scaled downRightsize or deallocate; schedule non production off
Orphaned disks, IPs, load balancersLeft behind when workloads are deletedSweep and delete unattached resources
Oversized managed disksProvisioned with large unused headroomRightsize tier and size to actual use
Premium tiers without needDefault chosen for safety, not requirementMove to standard where performance allows
Uncapped Log AnalyticsVerbose ingestion nobody cappedSet ingestion caps, sampling, and retention

Why do deallocated VMs still cost money?

Stopping a virtual machine from inside the guest operating system leaves it allocated, so Azure keeps billing the compute. Only deallocating the VM through Azure releases the compute charge, though attached managed disks and reserved public IPs continue to bill regardless. This distinction quietly costs real money on estates where teams stop machines expecting the meter to stop. The fix is to deallocate non production machines rather than stop them, and to schedule them off entirely outside working hours, which on development and test fleets removes a large block of compute hours that delivered nothing.

How does Log Analytics become a quiet budget eater?

Log Analytics and Azure Monitor bill largely on data ingested and retained, and verbose diagnostic settings can ingest far more than anyone reads. Without ingestion caps, sampling on high volume sources like Application Insights, and a retention policy matched to what you actually query, the line grows with the estate and is easy to miss because it is not tied to a visible resource. The discipline is to cap ingestion, sample chatty telemetry, route only the logs you need to the paid workspace, and set retention deliberately. Done once and governed, it keeps a fast growing line flat.

A worked example

Worked example

A Fortune 500 retailer ran an Azure estate where development machines were stopped each evening from the guest, not deallocated, so the compute kept billing overnight and at weekends. A sweep also found hundreds of orphaned disks and public IPs from deleted projects, a cluster of premium disks on workloads that never needed the throughput, and a Log Analytics workspace ingesting verbose traces nobody queried. Deallocating and scheduling non production off, deleting the orphans, moving disks to standard, and capping log ingestion removed a large block of spend with no commitment and no impact on production, verified against billing data and anonymised.

Frequently asked questions

What wastes the most money on Azure?
Idle and deallocated but still billed compute, orphaned disks, IPs and load balancers, oversized VMs and disks, premium tiers used without need, and uncapped Log Analytics ingestion. These need no commitment to fix and usually come before any reservation purchase.
Why does a stopped Azure VM still cost money?
Stopping a VM from inside the guest operating system leaves it allocated, so Azure keeps charging for compute. You must deallocate it through Azure to release the compute charge, and even then attached disks and reserved public IPs continue to bill.
How do I control Log Analytics costs?
Set daily ingestion caps, sample high volume sources like Application Insights, route only the logs you actually query to the paid workspace, and set retention deliberately. Log Analytics bills largely on data ingested and retained, so capping the inputs controls the line.

Clear the waste before you commit

We help enterprises find and remove Azure waste first, so any reservation or savings plan is sized to a clean, proven footprint, as an independent advisory that takes zero provider commissions and answers only to you. Our guarantee: we reduce your cloud spend or we reimburse our service fee, on a Fixed Fee or a no risk Gainshare basis. Download the Azure cost optimization kit, read the deeper Azure cost optimization guide, and start with the Azure cost optimization guide for buyers.

Independent · buyer-side

Put a defensible number on your cloud spend.

No provider in the room, no published price list. Tell us your footprint and we will scope the savings against your billing data — we reduce your cloud spend or we reimburse our service fee.

Buyer-side intelligence, monthly.

The Cloud Spend Navigator: what changed in cloud pricing, commitments, and FinOps — no vendor spin.