Microsoft Azure BYOIP Integration Overview
This page outlines the technical and procedural information required for integrating Bring Your Own IP (BYOIP) with Microsoft Azure infrastructure.
Looking for the best IP providers? Azure offers advanced BYOIP capabilities with automation, reputation management, and global availability. This guide covers Azure setup docs, reviews, requirements, benefits, and pricing for seamless BYOIP integration.
Provider Details
| Field | Information |
|---|---|
| Provider Name | Microsoft Azure |
| Website | Cloud Computing Services | Microsoft Azure |
| ASN(s) | AS8075 (Microsoft’s ASN; use your own ASN if required) |
| Regions Supported | All Azure public regions |
| Support Contact | Azure Support Options |
| Tech Article & Date | Bring your own IP addresses (BYOIP) to Azure with Custom IP Prefix - February 2022 |
| BYOIP Scope | General Availability (IPv4 and IPv6) |
| Supported Versions | IPv4 and IPv6 |
| Supported Services | VMs, Load Balancers, Azure Firewall, VPN Gateway, Application Gateway, Azure Front Door, and others using Standard SKU Public IPs |
Technical Requirements
| Requirement | Details |
|---|---|
| Prefix Size | IPv4: /21 to /24 (Parent), /22 to /26 (Regional) IPv6: /48 (Parent), /64 (Regional) |
| ASN Ownership Required | Not strictly required; ROA needed for the ASN that originates the route |
| IRR or RADb Object | Not required |
| ROA or LOA | ROA required; LOA not required |
| RIR Limitations | Prefixes must be registered with ARIN, RIPE, or APNIC |
Step-by-Step BYOIP Process
Estimated Setup Time:Varies by provisioning and prefix validationTested By Us:Not tested
Preparation
Provisioning
Usage
1
Preparation
- Register your IP prefix with ARIN, RIPE, or APNIC
- Create a ROA using your ASN or Microsoft’s ASN
- Add a self-signed X.509 certificate to the WHOIS public comment for the prefix
Step 0 of 0
Cost and Limitations
| Item | Details |
|---|---|
| Fees | No additional fees; standard public IP and data transfer rates apply |
| Bundled or Standalone | BYOIP integrates with DDoS Protection, Azure Firewall, etc. |
| Traffic/Peering Restrictions | BYOIP not allowed over ExpressRoute Microsoft Peering; no global tier or Internet routing preference |
| Other Limitations | Reverse DNS must be managed externally; cannot move Custom IP Prefix between subscriptions |
Automation & Developer Access
- API Access: Supported via Azure REST API, CLI, and PowerShell
Abuse & Reputation Management
- IP Reputation Monitoring: Not provided
- Blacklist Removal Support: Customer-managed