We received an email from Microsoft Azure - Action recommended: Remove Basic SKU public IP references before 30 June 2026/ Update your Basic SKU VPN Gateway configurations before 30 June 2026.

Zayan zay 40 Reputation points
2026-06-20T11:39:31.17+00:00

I have checked our setup. The gateway SKU is Basic, and we currently have two Site-to-Site VPN tunnels configured.

Could you please advise how we should approach this and what steps we need to take?

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

Answer accepted by question author
Andreas Baumgarten 132.9K Reputation points MVP Volunteer Moderator
2026-06-20T12:42:28.6133333+00:00

Hi @Zayan zay ,

please take a look here:

Upgrade a VPN Gateway SKU

VPN Gateway SKU consolidation and migration

About migrating a Basic SKU public IP address to Standard SKU


(If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

Regards

Andreas Baumgarten

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Newest
  1. AI answer

    2026-06-20T11:39:45.7133333+00:00

    For a Basic SKU VPN gateway that shows a Basic SKU public IP in the portal, there are two separate concerns:

    1. Basic SKU public IP retirement (deadline 30 June 2026)
    2. Basic VPN Gateway SKU being a non‑production, no‑SLA SKU

    Given the environment uses a Basic gateway SKU with two S2S tunnels, the recommended approach is:


    1. Handle the Basic SKU public IP reference

    For a Basic VPN Gateway SKU, if the gateway still shows a Basic SKU public IP reference, the only required action for the IP retirement is to remove that reference. This does not change the gateway’s IP address and does not interrupt connectivity.

    Steps in the Azure portal:

    1. Go to Virtual network gateway (the Basic VPN gateway).
    2. In the left menu, under Settings, select Configuration.
    3. In the Validation section, verify all resources show Succeeded.
    4. If validation is succeeded, select Delete Basic Public Ip Reference.

    Key effects and clarifications:

    • The public IP address value stays the same and the VPN gateway continues to use it.
    • Azure has already moved the IP internally to a Standard SKU public IP resource that is not visible in the subscription.
    • Removing the reference only:
      • Detaches the old, customer‑visible Basic public IP resource from the gateway.
      • Leaves the gateway using the same IP via an internal Standard SKU resource.
    • There is no connectivity interruption for S2S tunnels.
    • After removing the reference, the old Basic public IP resource remains in the subscription and should be deleted to stop billing for it.
    • Do not try to upgrade that old Basic public IP resource to Standard; doing so can put it into a failed state.

    If this step is not done by the deadline, the gateway may continue to function but will be in an unsupported configuration with no SLA, and Microsoft will not fix it automatically.


    2. Decide whether to stay on Basic gateway SKU or move to a supported SKU

    The Basic VPN Gateway SKU is a developer SKU with no SLA and is not intended for production use. Even after removing the Basic public IP reference, the gateway remains a Basic SKU gateway with no SLA.

    For production workloads or where reliability/support are important, the long‑term recommendation is to move to a newer VPN Gateway SKU (for example, VpnGw1 or higher). That migration is separate from the Basic IP reference removal and, unlike the IP reference removal, does cause downtime and a public IP change:

    • To move from a legacy/Basic‑family gateway SKU to a new SKU, the general workflow is:
      1. Remove connections to the existing virtual network gateway.
      2. Delete the old VPN gateway.
      3. Create a new VPN gateway using a supported SKU (e.g., VpnGw1/VpnGw2, etc.).
      4. Update on‑premises VPN devices with the new gateway public IP.
      5. Update any local network gateways that reference the old gateway IP.
      6. Recreate the S2S connections.
    • This operation changes the gateway public IP and incurs connectivity downtime while the new gateway is created and tunnels are re‑established.

    Given there are two S2S tunnels, plan a maintenance window for any future SKU change and coordinate updates with both on‑premises VPN endpoints.


    1. Immediately (no downtime, same IP):
      • On the Basic VPN gateway, go to Configuration and run Delete Basic Public Ip Reference once validation is succeeded.
      • Delete the now‑unused Basic public IP resource from the subscription to stop its billing.
    2. Plan (with downtime and IP change):
      • Evaluate whether to migrate from the Basic gateway SKU to a supported VpnGw* SKU before upcoming deprecations and to obtain SLA.
      • If migrating, follow the delete‑and‑recreate pattern and update both S2S VPN devices with the new gateway IP.

    This sequence ensures compliance with the Basic public IP retirement while keeping the current tunnels running, and provides a path to a supported, SLA‑backed gateway configuration.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.