Hello Tom
Greetings! Thanks for raising this question in Q&A forum.
These are two very timely and important questions given the End of June 2026 deadline is approaching. Let me answer both clearly.
Answering your first question When will the migration tool be available in your region?
Migration functionality is rolling out to regions. If you don't see the Migrate tab in the Azure portal, it means that the migration process isn't available yet in your region.
So the migration tool is still in the process of being rolled out across all Azure regions — you haven't missed anything, and this is expected behavior. Here's what to do while you wait:
Step 1: Check back regularly in the portal Go to your VPN Gateway resource in the Azure Portal > Settings > Configuration, and look for a "Migrate" tab next to the "Configure" tab. Once the rollout reaches your region, this tab will appear and you can proceed with the migration.
Step 2: Use PowerShell as an alternative if the portal tab is not yet available You do not have to wait for the portal migration tool. You can perform the full migration right now using PowerShell. Here is the complete sequence:
Prepare for migration:
$gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
$migrationParams = New-AzVirtualNetworkGatewayMigrationParameter -MigrationType UpgradeDeploymentToStandardIP
Invoke-AzVirtualNetworkGatewayPrepareMigration -InputObject $gateway -MigrationParameter $migrationParams
Execute the migration (expect up to 10 minutes of VPN downtime):
$gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
Invoke-AzVirtualNetworkGatewayExecuteMigration -InputObject $gateway
Validate traffic is flowing, then commit:
$gateway = Get-AzVirtualNetworkGateway -Name "YourGatewayName" -ResourceGroupName "YourRGName"
Invoke-AzVirtualNetworkGatewayCommitMigration -InputObject $gateway
If anything is wrong after migration, you can roll back before committing:
Invoke-AzVirtualNetworkGatewayAbortMigration -InputObject $gateway
Your IP address assigned to the gateway does not change during the migration, so your VPN connections and on-premises configurations do not need to be updated.
Step 3: Check your gateway subnet size before starting Before initiating migration, verify that your gateway subnet has at least three available IP addresses in your current prefix. If your current gateway subnet is /28 or smaller, the migration tool might error out you need to add multiple prefixes for the gateway subnet before you can proceed with migration.
Answering your second question — Is the End of June 2026 deadline still in effect?
Yes, the Basic IP deprecation timeline for all VPN Gateways is confirmed as End of June 2026. Active-Passive gateways migration is Generally Available, and Active-Active gateways migration reached GA in April 2026.
Given how close we are to the deadline, I strongly recommend using the PowerShell path (Step 2 above) to complete your migration now rather than waiting for the portal tool to appear in your region. The PowerShell approach is fully supported and does the same job.
One important thing to note: When you migrate the Basic SKU public IP to Standard SKU, your VPN Gateway SKU is also automatically migrated from a non-AZ SKU to an AZ SKU for example, VpnGw2 becomes VpnGw2AZ. New AZ SKU pricing has been active since January 2025, so please review the updated pricing at the Azure IP Addresses pricing page before proceeding.
If this answer helps you kindly accept the answer which will help others who have similar questions.
Best Regards,
Jerald Felix.