Azure BYOIP — Bring Your Own IP Addresses with Custom IP Prefix
Eliminate Azure Standard public IP charges by deploying your own IPv4 addresses through Custom IP Prefix. Save up to 86% on IP costs while maintaining full control over your address space.
What Is Azure BYOIP?
Azure BYOIP is implemented through the Custom IP Prefix (CIP) feature, which allows you to bring your own public IPv4 address ranges into Azure and use them as Standard SKU public IPs. Once provisioned and commissioned, these addresses behave identically to Azure-allocated IPs but without the recurring per-IP hourly charges. Azure charges approximately $0.005/hour ($3.60/month) for each Standard public IP — a cost that scales rapidly with large deployments. Custom IP Prefix eliminates these charges entirely, making BYOIP a compelling strategy for organizations running workloads that require many public IP addresses.
Custom IP Prefix is supported in most Azure regions globally. Azure offers both regional and global prefix types — a global prefix can be provisioned once and then derived into multiple regional prefixes, enabling centralized IP management across geographies without re-provisioning.
Azure BYOIP Requirements
Ensure you meet all prerequisites before creating a Custom IP Prefix in Azure.
Minimum /24 Prefix (Custom IP Prefix)
Azure requires a minimum /24 IPv4 prefix (256 addresses) for Custom IP Prefix resources. Smaller blocks are not supported. The prefix must be owned by your organization and registered with an RIR such as ARIN, RIPE NCC, or APNIC.
ROA with AS8075
A valid Route Origin Authorization (ROA) must be created in the appropriate RIR portal, authorizing AS8075 (Microsoft) to announce your prefix. The ROA must include the exact prefix and maximum length, and RPKI validation must pass before Azure will accept it.
Signed Authorization Message
Azure requires a specially formatted signed authorization message that includes your subscription ID, the prefix to be onboarded, and an expiration date. This message must be added to the RDAP/Whois record of the prefix as a public comment or remark before provisioning.
Azure Subscription with Network Contributor Role
You need an active Azure subscription and at least the Network Contributor RBAC role (or a custom role with Microsoft.Network/customIpPrefixes/* permissions) to create and manage Custom IP Prefix resources.
Provisioning + Commissioning Steps
After creating the Custom IP Prefix resource, Azure performs a two-phase process: provisioning (validation and BGP advertisement preparation, 12–24 hours) and commissioning (activating the prefix for use with public IPs). Both steps must complete before addresses are usable.
Azure BYOIP Setup Guide
Follow these steps to bring your own IP addresses into Azure using Custom IP Prefix.
Prepare Authorization Message
30 minutesGenerate the signed authorization message in the format Azure requires, including your Azure subscription ID, the IP prefix, and an expiration date. Add this message to your prefix's RDAP or Whois record as a public remark through your RIR portal.
Create ROA with AS8075
2–4 hoursLog into your RIR's RPKI dashboard (ARIN, RIPE NCC, or APNIC) and create a Route Origin Authorization for your prefix with AS8075 as the authorized origin. Allow 2–4 hours for global RPKI propagation and validation.
Create Custom IP Prefix Resource in Azure
1 hourIn the Azure portal or via Azure CLI/PowerShell, create a Custom IP Prefix resource specifying your prefix CIDR, the signed authorization message, and whether it is a global or regional prefix. Select the target Azure region.
Provision the Prefix
12–24 hoursTrigger provisioning on the Custom IP Prefix resource. Azure validates your ROA, verifies the signed authorization, and prepares BGP advertisement. This validation phase typically takes 12–24 hours to complete.
Commission the Prefix
1–2 hoursOnce provisioning succeeds, commission the prefix to start BGP advertisement from Azure's edge network. After commissioning, the prefix state changes to "Commissioned" and addresses become available for allocation.
Associate with Public IP Resources
30 minutesCreate Standard SKU public IP addresses from your commissioned Custom IP Prefix and associate them with your Azure resources — virtual machines, load balancers, NAT gateways, or Virtual Machine Scale Sets.
Total: Approximately 48 hours (including Azure provisioning validation)
Azure BYOIP Cost Comparison
Compare native Azure public IP pricing against BYOIP with leased addresses to see how much you can save.
Azure Standard Public IP
Azure charges approximately $0.005 per hour for each Standard SKU public IP address, whether attached or unattached. For a full /24 (256 IPs), this adds up to $922 per month in IP charges alone.
BYOIP with Leased IPv4
Lease a /24 block and bring it to Azure via Custom IP Prefix. You pay only the lease cost — Azure does not charge per-IP fees for BYOIP addresses, making this dramatically more economical for IP-intensive workloads.
Your Savings
Advantages of Azure BYOIP
Key benefits of using Custom IP Prefix to bring your own addresses into Azure.
Eliminates Azure IP Charges
Standard public IP fees ($0.005/hour per IP) are completely eliminated for BYOIP addresses. For deployments using dozens or hundreds of public IPs, the savings are substantial and immediate.
Custom IP Prefix Flexibility
Azure allows you to carve a Custom IP Prefix into smaller allocations and distribute individual public IPs across multiple resources. You retain full control over how your address space is allocated within Azure.
Global & Regional Prefix Support
Azure supports both global and regional Custom IP Prefixes. A global prefix can be onboarded once and then derived into regional child prefixes, enabling efficient multi-region IP management from a single block.
Load Balancer & VMSS Compatibility
BYOIP addresses work seamlessly with Azure Load Balancer (Standard SKU), Virtual Machine Scale Sets, NAT Gateway, and other networking services — no feature limitations compared to Azure-allocated IPs.
ExpressRoute Integration
Custom IP Prefix addresses can be used alongside ExpressRoute for hybrid cloud scenarios, enabling consistent IP addressing between on-premises infrastructure and Azure workloads.
Azure BYOIP FAQ
Frequently asked questions about bringing your own IP addresses to Azure.
What is the difference between provisioning and commissioning a Custom IP Prefix?
Which Azure services support BYOIP addresses from Custom IP Prefix?
Does Azure support IPv6 BYOIP?
Can I use BYOIP addresses with Azure ExpressRoute?
What permissions do I need to create a Custom IP Prefix in Azure?
How long does it take to decommission and remove a Custom IP Prefix from Azure?
Ready to Bring Your IPs to Azure?
Get a /24 or larger IPv4 block for Azure Custom IP Prefix. Our team handles RIR transfers, ROA setup, and provides full onboarding guidance to get you live on Azure quickly.
Free consultation — no commitment required