Edit

Share via


Support requirements and considerations for private endpoint connectivity

This article describes how to use Azure Migrate to discover, assess, and migrate servers over a private network by using Azure Private Link. You can use the tools in Azure Migrate to connect to the service over an Azure ExpressRoute private peering connection or a site-to-site VPN connection by using Private Link. For more information about these tools, see What is Azure Migrate?.

We recommend the method of private endpoint connectivity when there's an organizational requirement to access Azure Migrate and other Azure resources without traversing public networks. By using Private Link, you can use your existing ExpressRoute private peering circuits for better bandwidth or latency requirements.

Supported geographies

The functionality is now in general availability in supported public cloud and government cloud geographies.

Required permissions

You must have Contributor, User Access Administrator, or Owner permissions on the subscription.

Supported scenarios and tools

Deployment Details Tools
Discovery and assessment Perform an agentless, at-scale discovery and assessment of your servers running on any platform. Examples include hypervisor platforms such as VMware vSphere or Microsoft Hyper-V, public clouds such as AWS or GCP, or even bare-metal servers. Azure Migrate Discovery and Assessment
Software inventory Discover apps, roles, and features running on VMware VMs. Azure Migrate Discovery and Assessment
Dependency visualization Use dependency analysis to identify and understand dependencies across servers.

Agentless dependency visualization is supported natively with Azure Migrate support for Private Link.

Agent-based dependency visualization requires internet connectivity. Learn how to use private endpoints for agent-based dependency visualization.
Azure Migrate Discovery and Assessment
Migration Perform agentless VMware migrations, perform agentless Hyper-V migrations, or use the agent-based approach to migrate your VMware VMs, Hyper-V VMs, physical servers, VMs running on AWS, VMs running on GCP, or VMs running on a different virtualization provider. Azure Migrate and Modernize

Other integrated tools

Other migration tools might not be able to upload usage data to the Azure Migrate project if public network access is turned off. The Azure Migrate project should be configured to allow traffic from all networks so that it can receive data from other Microsoft or external offerings.

To turn on public network access for the Azure Migrate project:

  1. Sign in to the Azure portal and go to Azure Migrate.
  2. Under Manage, select Properties.
  3. Select No > Save.

Screenshot that shows the toggle for changing the network access mode.

Other considerations

Consideration Details
Pricing See Azure page blobs pricing and Azure Private Link pricing.
Virtual network requirements The ExpressRoute/VPN gateway endpoint should reside in the selected virtual network or a virtual network connected to it. You might need about 15 IP addresses in the virtual network.
PowerShell support PowerShell isn't supported. We recommend using the Azure portal or REST APIs for Private Link support in Azure Migrate.