Migrate to Standard Public IP SKU fails

Brendan 20 Reputation points
2025-09-23T15:01:04.45+00:00

Azure is deprecating the Basic Public IP blocks and encouraging people to upgrade to the Standard SKU as detailed here. There is a migrate tool in the VPN which my Public IP is associated with which is documented here however this fails despite having all the pre-requisites in green. I've attached a screenshot.

image (21)

Can someone suggest why this may be failing?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
{count} votes

Answer accepted by question author
  1. TP 144.3K Reputation points Volunteer Moderator
    2025-09-23T15:21:33.7633333+00:00

    Hi @Brendan ,

    UPDATE: Since you have Standard SKU VPN Gateway, please don't attempt to use migrate in portal at this time.

    According to current timeline documentation there is no action needed. Your Standard SKU VPN Gateway will be automatically migrated before February 28, 2026 with no downtime expected.

    Please see excerpt from documentation below:

    Migrate a gateway SKU

    Your legacy gateway will be migrated seamlessly from backend without any connectivity impact before February 28, 2026(extended from September 30, 2025). This is different from the initial approach of providing a migration path.

    Excerpt from timeline below:

    Event Customer impact Anticipated timelines Customer action/Prerequisites Documentation Announcement links
    Gateway SKU retirement: Standard and High Performance SKUs. - New Standard/High Perf SKU gateway creations blocked Nov 2023. - Standard/High Perf SKU gateways will be migrated to VpnGw1/VpnGw2 on non-AZ regions and to VpnGw1AZ/VpnAz2 on AZ regions. - No downtime is expected for migration. - May 2025 to Sep 2025: Standard/HighPerf SKU migration. - Feb 2026: Standard/HighPerf SKU retirement (extended from Sep 2025). - No action required Working with VPN Gateway legacy SKUs Standard and HighPerf gateway SKU retirement

    See this excerpt from FAQ:

    Will my IP address change when my Legacy VPN gateway SKU (Standard or HighPerformance) is migrated to a Non-AZ SKU (VpnGw1 or VpnGw2)? No, the IP address will not change when the Legacy SKU is migrated to a Non-AZ SKU. After SKU migration, you can choose to migrate the Basic SKU IP address to Standard SKU IP address through a customer controlled portal experience. For more information about Basic SKU IP migration, see About migrating a Basic SKU public IP address to Standard SKU for VPN Gateway article.

    The deadline for Basic SKU Public IP when used with VPN Gateway is end of January 2026, so there is plenty of time.

    NOTE: They just extended the migration deadline to February 28, 2026 within past week, however, they didn't change the "end of January 2026" text for Basic SKU IP deadline. I assume they are making exception for Standard SKU VPN Gateway.

    Please click Accept Answer and upvote if the above was helpful.

    Thanks.

    -TP

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Pranitha Maddi 1,195 Reputation points Microsoft External Staff Moderator
    2025-09-24T12:55:10.6266667+00:00

    Hi Brendan,

    Thank you for sharing the details and screenshots.

    AS you are trying to migrate your VPN Gateway (Standard SKU, Generation 1, active-passive) from a Basic SKU Public IP to a Standard SKU Public IP using the Azure Portal migration tool. Even though all prerequisites are passing (“green”), you get the error:

    Failed to prepare for migration to Standard IP Based Deployment. Error: Migration type UpgradeDeploymentToStandardIP not allowed for the gateway.

    This is because:

    The “UpgradeDeploymentToStandardIP not allowed” error typically means the migration preview tool is not yet fully supported for certain gateway SKUs (including Standard, HighPerformance, sometimes legacy configurations, or gateways in regions where the rollout isn’t complete).

    Standard SKU VPN gateways will be migrated to newer consolidated SKUs automatically as part of Azure’s retirement and consolidation process. So no manual action is required; Azure will handle migration for you before the retirement deadline.

    You can always check for the latest status and steps in the Microsoft documentation:https://learn.microsoft.com/en-us/azure/vpn-gateway/basic-public-ip-migrate-howto?tabs=portal

    Here are the further steps to perform:

    • If the official migration tool isn’t working for your gateway, there is no need to worry. Azure will automatically migrate Standard VPN Gateways with Basic SKU public IPs to Standard SKU public IPs before the end-of-support in January 2026.
    • Do not delete or recreate your gateway; just monitor your gateway and await further updates from Microsoft via the Azure portal (look out for retirement or upgrade notifications).

    Useful Microsoft documents:

    I hope this helps to clarify the issue.

    Thanks!

     

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.