

Default outbound access for VMs in Azure will be retired
Default outbound access connectivity for virtual machines in Azure will be retired on 30 September 2025. From then, all new VMs that require internet access will need to use explicit outbound connectivity methods such as Azure NAT Gateway, Azure Load Balancer outbound rules, or a directly attached Azure public IP address.
In Azure, VMs that are created in a virtual network without a defined explicit outbound method are assigned a default public IP address that enables internet connectivity. Existing VMs that use default outbound access will continue to work after this retirement, however, we strongly recommend transitioning to an explicit outbound method so that:
- Your workloads won’t be affected by public IP address changes.
- You have greater control over how your VMs connect to the internet.
- Your VMs use traceable IP resources that you own.
What is default outbound access? Check here: Default outbound access in Azure – Azure Virtual Network | Microsoft Learn
How to transition your customers away from default outbound access in Azure? Check here: https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/default-outbound-access#how-can-i-transition-to-an-explicit-method-of-public-connectivity-and-disable-default-outbound-access
As always, do get in touch with our Microsoft team should you require further details or support.
