An Azure machine learning service for building and deploying models.
Can not create compute instance in Azure ML studio
Hi.
We tried to create compute instances in Azure Machine Learning Studio with the following types: Standard_A2m_v2 (2 cores, 16 GB RAM, 20 GB disk), Standard_DS2_v2 (2 cores, 7 GB RAM, 14 GB disk), and Standard_DS3_v2 (4 cores, 14 GB RAM, 28 GB disk). The first two returned a “Create failed” error. The last one has been in the “Creating” state for more than an hour.
We are using the North Europe region. All instances except the last one used the default settings; for the last one, SSO was disabled.
Azure Machine Learning
-
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-11T11:54:47.23+00:00 Hi Johann L'Hour,
We attempted to reproduce the issue from our side by creating compute instances with the same VM sizes you mentioned (Standard_A2m_v2,Standard_DS2_v2, andStandard_DS3_v2) in the North Europe region, and they were all created successfully. Since these VM sizes are working as expected in North Europe from our side, the issue is likely related to configuration, quota, or networking within your subscription.
The
Standard_DS3_v2instance being stuck in the “Creating” state for more than an hour can indicate a potential issue with quota limits, VM size availability, or network configuration. Please try the steps below to resolve the issue.First, go to the Compute page in Azure Machine Learning Studio, locate the stuck instance, and try stopping and restarting it. If that does not work, delete the stuck instance and attempt to create a new one using a different name.
Next, review the quota availability for your subscription in the North Europe region. Each subscription has a limited number of vCPUs available per VM family and region, and if that quota is exhausted, new instances will fail to start or remain stuck in the creating state. You can check this by going to your Azure Machine Learning workspace, selecting your subscription → Usage + quotas, and verifying the available vCPUs for the Standard A and Standard DSv2 families. If you are at the quota limit, please request a quota increase from the same page.
Please also ensure there are no network restrictions or security rules preventing the instance from starting. If your workspace is deployed inside a Virtual Network (VNet) or uses private endpoints, the compute instance must be able to connect to required Azure services such as
*.azurecr.io(Azure Container Registry),mcr.microsoft.com(base images), andlogin.microsoftonline.com(authentication). Any DNS resolution issues or blocked outbound traffic can cause the instance creation to hang.If the issue continues, you can also try using a different VM size (for example,
Standard_B2ms) or attempt the deployment in a different region such as West Europe to confirm if the problem is specific to the current VM size or region capacity.If the problem persists after trying the above steps, we can raise a support request on your behalf to have this investigated further.
-
Johann L'Hour • 0 Reputation points
2025-09-11T16:30:11.47+00:00 Thank you for the fast answer.
- there is no stuck instance as we never managed to create one
- not a quota issue as for now we are using 0 cores
How can we look for network restrictions or security rules?
-
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-12T02:15:42.8633333+00:00 Hi Johann L'Hour,
Since no compute instances are being created and quota usage is at zero, this strongly suggests that the issue is related to network restrictions preventing outbound connectivity from your subnet. When a compute instance is created, it needs to contact multiple Azure services for authentication, pulling container images, registering the node, and provisioning resources. If your workspace is deployed inside a Virtual Network (VNet) and your subnet is secured with Network Security Groups (NSGs) or firewall rules, please verify that the required service tags and ports are allowed for outbound traffic. Missing outbound rules is a common reason for compute creation to hang indefinitely.In particular, ensure that the following service tags are allowed for outbound traffic on port 443:
- AzureActiveDirectory (80, 443) – For Microsoft Entra ID authentication
- AzureMachineLearning (443, 8787, 18881, UDP 5831) – To access core Azure ML services
- BatchNodeManagement.<region> (443) – For provisioning and managing compute nodes
- AzureResourceManager (443) – To create Azure resources during instance provisioning
- Storage.<region> (443) – To access workspace storage during setup
- MicrosoftContainerRegistry (443) and Frontdoor.FirstParty (443) – To pull base images and environments
- AzureMonitor (443) – To send logs and monitoring metrics (optional, but recommended)
- VirtualNetwork (443) – If using private endpoints or VNet peering
If these are blocked, the compute will fail silently during creation. Please check your NSG outbound rules and ensure that these service tags are present and not being denied. If you use a corporate firewall or proxy, ensure that these endpoints and ports are whitelisted as well.
For reference, you can follow this Microsoft Learn article on configuring network traffic for Azure Machine Learning: Configure inbound and outbound network traffic - Azure Machine Learning
Once these service tags are allowed, the compute instance should be able to connect and provision successfully. Please let us know if your workspace is VNet-integrated so we can share the exact steps to validate and update your NSG rules.
-
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-15T06:54:46.86+00:00 Hi Johann L'Hour,
Did you get any chance to check the response. Thank you! -
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-16T04:11:48.4933333+00:00 Hi Johann L'Hour,
Just following up to see if you had a chance to review the above response. Thank you! -
Johann L'Hour • 0 Reputation points
2025-09-16T07:54:49.5233333+00:00 Hi @Pavankumar Purilla ,
We showed to our Azure people our problem and your guidelines. We tried together to create a compute instance, but it didn't work. Diagnosis shows no network problem between ML Studio and other Azure services, but it could be not correct.
We are looking for a meeting with our contacts in Microsoft.
-
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-17T12:03:33.79+00:00 Hi Johann L'Hour,
I kindly request you to provide the details mentioned in the private message -
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-18T03:08:11.69+00:00 Hi Johann L'Hour,
I kindly request you to provide the details mentioned in the private message to create support ticket which is needed as part of process to arrange teams call.Thank you for understanding.
-
Johann L'Hour • 0 Reputation points
2025-09-19T12:08:00.1733333+00:00 Hi Pavankumar,
Sorry for the delay, I was on a business trip. I replied to the private message.
BR,
Johann
-
Pavankumar Purilla • 11,655 Reputation points • Moderator
2025-09-24T08:58:43.87+00:00 Hi Johann L'Hour,
Thank you for your patience. We have submitted a support ticket on your behalf. We will inform you as soon as we receive an update. -
Manas R Mohanty • 17,270 Reputation points • Moderator
2025-10-01T13:10:53.42+00:00 Hi Johann L'Hour,
Thank you for confirming that issue on provisioning compute is resolved now.
You are facing some issue on running jobs with managed identity now. Have share relevant document on managed identity.
Feel free to create a new thread to keep the context on issues clear.
Thank you.
Sign in to comment