Skip to main content

Perimeter Insights: Public IP Risk Review

Overview

Perimeter Insights in Spotto is a public IP exposure and Azure public IP inventory view for understanding how internet-facing traffic can enter your Azure environment. It shows which public IP addresses are assigned, what they are attached to, where they live, whether Spotto has confirmed exposure evidence, and which items need risk or ownership review.

It is built for the recurring question: "What is exposed to the internet, why does it exist, and who owns it?" The answer should not require four portal tabs and a brave spreadsheet.

Feature overview

Perimeter Insights lists public IP addresses across the selected Azure subscriptions and adds operational context:

  • Risk level and reason for each public IP address.
  • Confirmed exposure evidence for public RDP, SSH, and HTTPS listeners when detected.
  • Assignment context, including associated service, resource, resource type, resource group, and region.
  • Resource links that help you move from a public IP row to the attached resource or Azure context when Spotto has enough relationship data.
  • Governance signals, including missing Azure tags and other public IP concerns.
  • Breakdowns by service, region, and concern so patterns are visible before you drill into individual rows.

Questions Perimeter Insights answers

Use Perimeter Insights when you need direct answers to public perimeter and attack surface questions:

  • Which Azure public IP addresses exist across the selected subscriptions?
  • Which public IPs are assigned, unassigned, dynamically unassigned, or unresolved?
  • Which public IPs have confirmed RDP, SSH, or HTTPS exposure evidence?
  • Which services are using public IPs: virtual machines, network interfaces, application gateways, load balancers, NAT gateways, or other edge resources?
  • Which regions and resource groups contain internet-facing entry points?
  • Which public IPs are missing tags, making owner, environment, or service attribution unclear?
  • Which public IPs should be reviewed first based on risk level and risk reason?

That makes the page useful for Azure perimeter review, public IP risk review, internet-facing resource cleanup, and governance follow-up.

Why use this? (Jobs, pains, gains)

Jobs to be done

  • When I review cloud perimeter risk, I want to see every public IP address and its attachment, so I can separate intended entry points from accidental exposure.
  • When public management ports are open, I want to find RDP or SSH exposure quickly, so the team can remove, restrict, or justify it.
  • When ownership is unclear, I want to see missing tags and service context together, so follow-up work lands with the right team.
  • When someone asks "how does traffic get in?", I want service and region breakdowns, so the answer is based on inventory rather than memory.

Common pains

  • Azure public IPs are easy to list, but harder to connect to service intent, resource ownership, and exposure risk.
  • Load balancers, application gateways, NAT gateways, and network interfaces all make "is this public IP expected?" a contextual question.
  • Public IPs without tags create the usual ownership problem: everyone agrees they matter, nobody remembers who deployed them.
  • Public HTTPS can be normal; public RDP or SSH usually deserves a much louder conversation.

What you gain

  • A single view of public IP addresses across the subscriptions you select.
  • Fast triage using High, Medium, Low, and Info risk labels with plain-language risk reasons.
  • Separate signals for confirmed exposure, unassigned capacity, Basic SKU usage, unresolved attachments, and missing tags.
  • CSV export for remediation planning, governance review, and follow-up with service owners.

Turn the evidence into a decision

Select the labelled briefcase Business Value button beside Notes. The brief combines live public IP, confirmed exposure, broad management exposure, and ownership-tag facts with a reduction plan.

Live facts remain deterministic. Generate tailors only the narrative for permitted users and saves it to the exact scope. Clear removes that saved narrative and immediately restores the standard Business Value content without deleting Customer Context or changing live facts. Regenerate when evidence changes. Above 100 subscriptions, the curated live brief remains available without tailoring.

Current position and priority work

Review confirmed and broadly reachable exposures first, especially management or customer-data paths. Assign ownership and business justification to remaining public endpoints, then remove or restrict those without a valid need.

Business outcomes

Perimeter review makes public exposure intentional. It helps retain required customer-facing services while reducing avoidable attack surface and establishing ownership for every externally reachable endpoint.

Cost of delay

Unnecessary or weakly restricted endpoints can increase the likelihood and blast radius of unauthorized access. Unknown ownership and missing context can delay containment when an exposed resource needs urgent attention.

Decision required

Agree which endpoints are required, which controls are mandatory, who owns each exception, and when unnecessary exposure will be removed.

Validate with stakeholders

When you can manage Company Notes, select any question in the portal to retain the answer in the relevant Customer Context note.

  • Which public endpoints support a documented business service?
  • What authentication, filtering, monitoring, and response controls protect them?
  • Who owns each exposure and accepts its residual risk?

Key capabilities

Where to find it

In the Spotto Portal sidebar, open Investigate -> Analyze -> Perimeter Insights.

Use the company and subscription selector at the top of the page to choose the subscriptions you want to review. Perimeter Insights combines the selected subscriptions into one inventory table.

Review the perimeter summary

The summary cards show:

  • Public IPs: total public IP addresses, split into assigned and unassigned counts.
  • Confirmed Exposures: detected HTTPS, RDP, and SSH exposure evidence.
  • Follow-Up Items: Basic SKU public IPs, dynamic unused public IPs, and unresolved assigned attachments.
  • Missing Tags: public IP addresses with no Azure tags.

These counts help you decide whether the review is about urgent exposure, cleanup, governance, or all three. It is often all three.

Use insight cards for immediate priorities

Perimeter Insights generates plain-language insight cards from the selected data. Examples include:

  • Public management exposure detected when RDP or SSH exposure evidence is present.
  • No public RDP or SSH exposure detected when management-port evidence is absent in the selected dataset.
  • Public HTTPS listeners found when HTTPS listener evidence is confirmed.
  • Load balancer edge IPs need intent review when load balancer public IPs are attached but listener exposure evidence is not present.
  • Unused public IP capacity found when unassigned public IPs exist.
  • Governance tags are missing when public IPs have no Azure tags.

Understand risk levels

Risk is a triage signal, not a final verdict. It helps you decide what to review first.

Risk levelWhat it usually means
HighPublic RDP or SSH exposure evidence is present.
MediumThe public IP is unassigned, dynamically unassigned, Basic SKU, has a confirmed public HTTPS listener, or is assigned without a resolved attachment.
LowThe public IP is attached to a public edge resource and no higher-risk evidence is present.
InfoNo exposure evidence is present in the selected dataset.
note

Color is not the only indicator in the UI. Each row also includes a text label such as High, Medium, Low, or Info, plus a risk reason.

Inspect public IP assignment and exposure

The inventory table includes:

  • Risk: risk level and risk reason.
  • IP Address: public IP address and public IP resource name.
  • Attachment: associated resource, service, and resource type when resolved.
  • Exposure: confirmed exposure labels, or None detected when Spotto has no exposure evidence.
  • Location: Azure region and resource group.
  • SKU: SKU, tier, allocation method, and IP version.
  • Governance: whether tags are present and any concerns Spotto found.

Use this table to answer practical questions:

  • Is this public IP assigned or unassigned?
  • Is it attached to a VM, network interface, application gateway, load balancer, NAT gateway, or another edge service?
  • Is there confirmed RDP, SSH, or HTTPS exposure evidence?
  • Is the public IP in the expected region?
  • Does it have tags that identify ownership or environment?

When relationship data is available, Perimeter Insights links the public IP row to the relevant resource context so you can move from inventory to action:

  • Open the public IP resource when you need to confirm SKU, allocation method, DNS label, or Azure-level ownership.
  • Open the attached resource when the issue belongs to a network interface, VM, application gateway, load balancer, NAT gateway, or another edge component rather than the IP object itself.
  • Use the resource group and subscription context to route the follow-up to the right service owner.
  • If a row is assigned but unresolved, treat the link gap as part of the review. Confirm the attachment in Azure before deleting or changing anything.

The useful distinction is simple: sometimes you remediate the public IP, and sometimes the public IP is only the signpost.

Use filters to narrow the inventory:

  • Search by IP address, resource name, service, region, resource group, risk reason, exposure, concern, tag key, or tag value.
  • Filter by risk level: All Risk Levels, High, Medium, Low, or Info.
  • Filter by associated service, such as application gateway, load balancer, network interface, or unassigned.

The table shows how many rows match the current filters, so you can confirm whether you narrowed the review intentionally or just typed something too specific.

Export the current review

Use Export CSV to download the currently filtered public IP inventory. The export includes risk, risk reason, subscription, IP address, name, exposure, associated service, associated resource, resource group, location, SKU, allocation, use, concerns, and missing tag status.

This is useful for remediation backlogs, owner follow-up, and security review packs.

1. Scope the subscriptions

Select the subscriptions that belong to the environment you are reviewing. For example, review production separately from development if the risk threshold and service ownership differ.

2. Start with High risk rows

Filter risk to High and review public management exposure first. These rows indicate RDP or SSH exposure evidence, which usually deserves immediate validation and remediation unless there is a documented exception.

3. Review Medium risk cleanup and intent

Switch to Medium to review public IPs that are unassigned, dynamically unassigned, Basic SKU, attached without a resolved resource, or exposing HTTPS. Some of these will be normal public services; the goal is to confirm intent and remove leftovers.

4. Choose a remediation path

Do not treat every public IP finding as "delete the IP". Use the attachment and exposure context to choose the least disruptive fix.

FindingReview firstCommon remediation options
Public RDP or SSHConfirm whether public management access is still required and who owns it.Remove the VM public IP, restrict inbound NSG rules to approved source ranges, move administration behind Azure Bastion, use just-in-time VM access, or use private connectivity through VPN/ExpressRoute.
Public HTTPSConfirm whether the listener is an intended public service and whether TLS, WAF, and ownership are current.Keep it public with documented ownership, move traffic behind Application Gateway or Front Door where appropriate, restrict source ranges for non-public services, or retire the listener if it is no longer used.
Unassigned public IPCheck whether it is reserved for a near-term change, disaster recovery plan, or documented static address dependency.Delete it, reassign it to the intended resource, or tag it with owner, purpose, and review date if it must be retained.
Basic SKU public IPCheck service compatibility, inbound/outbound behavior, and change windows before migration.Plan a move to Standard SKU where supported, replace the dependent edge resource if required, or document the exception with an owner and retirement date.
Assigned but unresolvedValidate the attachment in Azure and check whether inventory is still syncing.Wait for sync if the resource is new, correct missing relationship data, or investigate stale/deleted dependencies before making changes.
Missing tagsConfirm the owner, environment, and service purpose.Add tags directly, use Spotto Tagging for repeatable fixes, or route the item to the owning team with the exported CSV.

5. Check service and region patterns

Use the By Service and By Region breakdowns to spot clusters. A concentration of public IPs on one service or in one region can point to a shared gateway pattern, a deployment habit, or a cleanup target.

6. Fix ownership gaps

Review Missing Tags and the Governance column. Public entry points should have enough metadata to identify the owner, environment, and service purpose. Mystery internet doors are not a governance strategy.

7. Export the filtered view

Export the filtered inventory once you have the review scope you need. Use the CSV for remediation tickets, change records, security review notes, or service owner follow-up.

Technical reference

ComponentDetails
InputsPublic IP address reports for each selected Azure subscription, including resource metadata, assignment evidence, associated service/resource data, exposure evidence, concerns, location, SKU, allocation method, IP version, and Azure tags.
OutputsSummary cards, insight cards, service/region/concern breakdowns, a searchable and filterable public IP inventory table, and CSV export.
DefaultsData is fetched per selected subscription and cached briefly in the Portal. The table page size is 25 rows. Risk filtering defaults to All Risk Levels and service filtering defaults to All Services.

How it differs from Azure-native views

Azure is the system of record for public IP addresses, but public IP review is usually spread across resource lists, networking blades, security rules, load balancer configuration, application gateways, and tags.

Perimeter Insights is optimized for the operating workflow:

  • Combine public IP inventory with assignment and exposure context.
  • Separate confirmed management-port exposure from ordinary public edge attachments.
  • Highlight public IPs with missing governance tags.
  • Review multiple subscriptions from one table and export the filtered result.

It does not replace packet capture, firewall log analysis, or application-layer security testing. It gives you a perimeter inventory and risk triage layer so you know where to look first.

How it works (high level)

  • You select one or more Azure subscriptions.
  • Spotto loads the public IP address report for each selected subscription.
  • The Portal combines the reports into one model and calculates summary counts, breakdowns, insights, and risk labels.
  • Each public IP row is classified using exposure evidence, assignment state, SKU, associated service/resource data, and tag presence.

Coverage and limitations

  • Not a live traffic monitor: Perimeter Insights shows public IP inventory, assignment, and exposure evidence from Spotto's data. It does not show live packet flows.
  • Evidence-driven exposure: None detected means Spotto does not have exposure evidence in the selected dataset. It does not prove a service is unreachable from every network path.
  • HTTPS can be intentional: Public HTTPS listeners are treated as review items because they often represent valid public services.
  • Assignment can be unresolved: Some assigned public IPs may not have a resolved attachment if the relationship data is incomplete or still syncing.
  • Azure only today: This page currently covers Azure public IP addresses.
  • Use Security to review Azure secure score and security recommendations that may relate to exposed resources.
  • Use Cloud Resources to inspect the resource inventory behind a public IP attachment and review related recommendations.
  • Use Relationship Graph to understand how public IPs, network interfaces, subnets, load balancers, and application gateways connect.
  • Use Tagging when missing or inconsistent tags make public IP ownership unclear.

Troubleshooting

No public IP addresses found

What you're seeing: The page shows No public IP addresses found. Likely causes:

  • The selected subscriptions do not have public IP address data available.
  • The subscriptions have not completed their first sync.
  • You selected subscriptions that genuinely have no public IP addresses.

How to fix:

  1. Confirm at least one subscription is selected.
  2. Check that the selected subscriptions are connected and syncing in Spotto.
  3. Refresh after the next ingestion cycle.

No public IPs match these filters

What you're seeing: The table shows No public IPs match these filters. Likely causes:

  • The search term is too specific.
  • The selected risk level or service filter excludes the rows you expected.

How to fix:

  1. Clear the search box.
  2. Reset risk to All Risk Levels.
  3. Reset service to All Services.

Public IP address data could not be loaded

What you're seeing: The page shows Public IP address data could not be loaded. Likely causes:

  • Temporary API or network issue.
  • The selected company or subscriptions are not available in your current session.

How to fix:

  1. Refresh the page.
  2. Re-select the subscriptions.
  3. If it continues, capture the time, company, and subscription IDs and contact support.

Some subscriptions unavailable

What you're seeing: A notification says Some subscriptions unavailable and lists subscription names. Likely causes:

  • Spotto loaded public IP data for some selected subscriptions but failed to load others.
  • One or more subscriptions are temporarily unavailable or still syncing.

How to fix:

  1. Review the rows that did load.
  2. Retry after the unavailable subscriptions finish syncing.
  3. If the same subscriptions fail repeatedly, contact support with the listed subscription names.

A public IP has no exposure evidence, but it is attached to a load balancer

What you're seeing: A public IP is attached to a load balancer, but the exposure field says None detected. Likely causes:

  • The public IP is attached, but listener exposure evidence is not present in the selected dataset.
  • The load balancer may be intentionally public, but the traffic intent still needs validation.

How to fix:

  1. Review the associated resource and service owner.
  2. Check listener, rule, and backend configuration in Azure.
  3. Add ownership/environment tags if they are missing.
Optimize Your Azure Environment

Looking to enhance your cloud setup for cost efficiency, performance, reliability, or security?

Talk to a cloud specialist. Email us or schedule a 30-minute consultation and let's optimize your cloud environment together.

Book a Free Consultation