Microsoft Azure BYOIP Integration Overview
This page outlines the technical and procedural information required for integrating Bring Your Own IP (BYOIP) with Microsoft Azure infrastructure.
Looking for the best IP providers? Azure offers advanced BYOIP capabilities with automation, reputation management, and global availability. This guide covers Azure setup docs, reviews, requirements, benefits, and pricing for seamless BYOIP integration.
Provider Details
| Field | Information |
|---|---|
| Provider Name | Microsoft Azure |
| Website | Cloud Computing Services | Microsoft Azure |
| ASN(s) | AS8075 (Microsoft’s ASN; use your own ASN if required) |
| Regions Supported | All Azure public regions |
| Support Contact | Azure Support Options |
| Tech Article & Date | Bring your own IP addresses (BYOIP) to Azure with Custom IP Prefix - February 2022 |
| BYOIP Scope | General Availability (IPv4 and IPv6) |
| Supported Versions | IPv4 and IPv6 |
| Supported Services | VMs, Load Balancers, Azure Firewall, VPN Gateway, Application Gateway, Azure Front Door, and others using Standard SKU Public IPs |
Technical Requirements
| Requirement | Details |
|---|---|
| Prefix Size | IPv4: /21 to /24 (Parent), /22 to /26 (Regional) IPv6: /48 (Parent), /64 (Regional) |
| ASN Ownership Required | Not strictly required; ROA needed for the ASN that originates the route |
| IRR or RADb Object | Not required |
| ROA or LOA | ROA required; LOA not required |
| RIR Limitations | Prefixes must be registered with ARIN, RIPE, or APNIC |
Step-by-Step BYOIP Process
Estimated Setup Time:Varies by provisioning and prefix validationTested By Us:Not tested
Preparation
Provisioning
Usage
1
Preparation
- Register your IP prefix with ARIN, RIPE, or APNIC
- Create a ROA using your ASN or Microsoft’s ASN
- Add a self-signed X.509 certificate to the WHOIS public comment for the prefix
Step 0 of 0
Cost and Limitations
| Item | Details |
|---|---|
| Fees | No additional fees; standard public IP and data transfer rates apply |
| Bundled or Standalone | BYOIP integrates with DDoS Protection, Azure Firewall, etc. |
| Traffic/Peering Restrictions | BYOIP not allowed over ExpressRoute Microsoft Peering; no global tier or Internet routing preference |
| Other Limitations | Reverse DNS must be managed externally; cannot move Custom IP Prefix between subscriptions; default limit of 5 custom IP prefixes per region (can be increased on request); a Custom IP Prefix cannot be attached directly to a resource; Public IP Prefixes with Standard v2 IPs cannot be derived from a Custom IP Prefix |
Automation & Developer Access
- API Access: Supported via Azure REST API, CLI, and PowerShell
Abuse & Reputation Management
- IP Reputation Monitoring: Not provided
- Blacklist Removal Support: Customer-managed
Related Resources
Published 8 August 2025 · Updated 7 September 2026