Will the retirement of Inbound NAT Pools affect the load balancer on our managed domain

ad@stptrans.com 0 Reputation points
2026-05-25T09:40:59.7133333+00:00

We have a managed domain on Azure and it appears that its load balancer uses an inbound NAT pool for its domain controllers. As inbound NAT pools/v1 NAT rules are being retired, I wonder if our managed domain is affected by the deprecation and if we actively have to migrate the rules, or if this happens automatically. I would appreciate some guidance for our specific scenario beyond the documentation here: https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer-nat-pool-migration

Azure Load Balancer
Azure Load Balancer

An Azure service that delivers high availability and network performance to applications.


2 answers

Sort by: Most helpful
  1. Alex Burlachenko 25,120 Reputation points MVP Volunteer Moderator
    2026-05-26T08:44:01.83+00:00

    hi ******@stptrans.com & thanks for join me here at Q&A portal,

    if this is a Microsoft managed domain, for example Microsoft Entra Domain Services, u normally should not migrate those load balancer NAT rules yourself. Customer-owned Load Balancer inbound NAT pool retirement applies to load balancers u manage directly. Managed service infrastructure should be handled by Microsoft, unless Microsoft explicitly tells u there is customer action.

    The migration doc is for customer-managed Load Balancer inbound NAT pools and v1 inbound NAT rules pretty clear and nice https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer-nat-pool-migration

    If the load balancer is inside a managed resource group or tied to a managed domain service, dont edit NAT rules manually. Those resources can be part of the service control plane, and changing them can break domain controller access. If the portal email or Advisor recommendation points to a resource u own directly, then u need to migrate. If it points to Microsoft-managed infrastructure, open support and ask them to confirm whether the managed domain service will be migrated automatically.

    Copy the load balancer resource ID from the retirement notice, check who owns it, and confirm whether it is in ur normal resource group or a managed service resource group. If u can edit it like a normal load balancer, it may be customer-managed. If it belongs to the managed domain deployment, raise a support case under Microsoft Entra Domain Services and Load Balancer retirement.

    Do not migrate those NAT pools blindly. For managed domain controllers, Microsoft should confirm the path.

    rgds,

    Alex

    &

    If my answer was helpful pls mark it and additional thx if u follow me at Q&A portal
    

    Was this answer helpful?

    0 comments No comments

  2. Venkatesan S 10,830 Reputation points Microsoft External Staff Moderator
    2026-05-25T15:21:54.4566667+00:00

    Hi ******@stptrans.com,

    Since your subscription is under the Azure Developer Plan, the request will initially be handled through the Microsoft Q&A forum. We will review the issue and engage the backend team for further investigation if required.

    I'm currently checking with backend team will update you.

    Here is the link: https://learn.microsoft.com/en-us/azure/azure-portal/supportability/priority-community-support

    Update:

    Thank you for your patience while we reviewed this scenario internally with the relevant product groups.

    Microsoft is actively working with Azure PaaS services that use Azure Load Balancer to ensure they are not impacted by the retirement of Inbound NAT Rules/Pools v1.

    For Azure Managed Domain Services specifically, there is currently no action required from customers regarding the managed load balancers deployed by the service. Any required backend updates or migration activities for service-managed resources are expected to be handled by the Azure Managed Domain Services product team.

    If this guidance changes or customer action becomes necessary in the future, the Azure Managed Domain Services team will communicate the required steps accordingly.

    However, we would also like to clarify that if you have independently deployed your own Azure Load Balancers within your environment (separate from the managed load balancers created by Azure Managed Domain Services), you would be responsible for reviewing and completing any required migration from Inbound NAT Rules v1 to v2 for those customer-managed resources.

    Kindly let us know if the above helps or you need further assistance on this issue.

    Please do not forget to 210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.