Migrating from Basic SKU to Standard for Azure Public IP addresses

Tom 276 Reputation points
2026-05-28T09:30:10.8266667+00:00

I have a public IP address that I'm using for an Azure VPN Gateway. According to the documentation, "Basic IP deprecation timeline for all VPN Gateways is moved to End of June 2026".

According to this document the Azure portal should provide a migration tool to help with the migration. I checked the public IP address and this tool is still not available.

When will this tool become generally available?

Is the deadline for a Basic SKU public IP is being used with a VPN Gateway still end of June 2026?

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

Answer accepted by question author
Ravi Varma Mudduluru 12,625 Reputation points Microsoft External Staff Moderator
2026-05-28T10:37:12.52+00:00

Hello @Tom

Thank you for reaching out to Microsoft Q&A.

The deadline for Basic SKU public IP addresses used with VPN Gateways is still end of June 2026. Microsoft has extended this timeline a few times to give customers more time.

Since the migration tool isn't showing up for you, it's very likely you're using a Basic SKU VPN Gateway. In this case, you don't need the full migration tool. Instead, you just need to remove the Basic public IP reference from your gateway.

Quick Summary of What Happens:

  • Your actual public IP address will not change.
  • There will be no downtime or connectivity impact.
  • This is a simple cleanup step that Microsoft has made available in the portal.

How to Do It:

  1. Go to your Virtual Network Gateway in the Azure portal.
  2. In the left menu, under Settings, select Configuration.
  3. You should see an option to Delete Basic Public IP Reference (make sure all resources show as "Succeeded" first).
  4. Follow the prompts to complete the action.

Here are the official Microsoft docs for this exact scenario:

If the Delete Basic Public IP Reference button is still missing, feel free to share an error screenshot in the private message and also share us the requested details there.

If the answer is helpful, please click "Accept Answer " and kindly upvote it. If you have extra questions about this answer, please click "Comment".

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Jerald Felix 18,760 Reputation points Volunteer Moderator
    2026-05-28T10:25:50.2433333+00:00

    Hello Tom

    Greetings! Thanks for raising this question in Q&A forum.

    These are two very timely and important questions given the End of June 2026 deadline is approaching. Let me answer both clearly.

    Answering your first question When will the migration tool be available in your region?

    Migration functionality is rolling out to regions. If you don't see the Migrate tab in the Azure portal, it means that the migration process isn't available yet in your region.

    So the migration tool is still in the process of being rolled out across all Azure regions — you haven't missed anything, and this is expected behavior. Here's what to do while you wait:

    Step 1: Check back regularly in the portal Go to your VPN Gateway resource in the Azure Portal > Settings > Configuration, and look for a "Migrate" tab next to the "Configure" tab. Once the rollout reaches your region, this tab will appear and you can proceed with the migration.

    Step 2: Use PowerShell as an alternative if the portal tab is not yet available You do not have to wait for the portal migration tool. You can perform the full migration right now using PowerShell. Here is the complete sequence:

    Prepare for migration:

    $gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
    $migrationParams = New-AzVirtualNetworkGatewayMigrationParameter -MigrationType UpgradeDeploymentToStandardIP
    Invoke-AzVirtualNetworkGatewayPrepareMigration -InputObject $gateway -MigrationParameter $migrationParams
    

    Execute the migration (expect up to 10 minutes of VPN downtime):

    $gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
    Invoke-AzVirtualNetworkGatewayExecuteMigration -InputObject $gateway
    

    Validate traffic is flowing, then commit:

    $gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
    Invoke-AzVirtualNetworkGatewayCommitMigration -InputObject $gateway
    

    If anything is wrong after migration, you can roll back before committing:

    Invoke-AzVirtualNetworkGatewayAbortMigration -InputObject $gateway
    

    Your IP address assigned to the gateway does not change during the migration, so your VPN connections and on-premises configurations do not need to be updated.

    Step 3: Check your gateway subnet size before starting Before initiating migration, verify that your gateway subnet has at least three available IP addresses in your current prefix. If your current gateway subnet is /28 or smaller, the migration tool might error out you need to add multiple prefixes for the gateway subnet before you can proceed with migration.

    Answering your second question — Is the End of June 2026 deadline still in effect?

    Yes, the Basic IP deprecation timeline for all VPN Gateways is confirmed as End of June 2026. Active-Passive gateways migration is Generally Available, and Active-Active gateways migration reached GA in April 2026.

    Given how close we are to the deadline, I strongly recommend using the PowerShell path (Step 2 above) to complete your migration now rather than waiting for the portal tool to appear in your region. The PowerShell approach is fully supported and does the same job.

    One important thing to note: When you migrate the Basic SKU public IP to Standard SKU, your VPN Gateway SKU is also automatically migrated from a non-AZ SKU to an AZ SKU for example, VpnGw2 becomes VpnGw2AZ. New AZ SKU pricing has been active since January 2025, so please review the updated pricing at the Azure IP Addresses pricing page before proceeding.

    If this answer helps you kindly accept the answer which will help others who have similar questions.

    Best Regards,

    Jerald Felix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.