Direct peering walkthrough

In this article, you learn how to set up and manage a Direct peering.

Create a Direct peering

Diagram showing Direct peering workflow and connection states.

To provision a Direct peering, complete the following steps:

  1. Review Microsoft peering policy to understand requirements for Direct peering.
  2. Follow the instructions in Create or modify a Direct peering to submit a peering request.
  3. After you submit a peering request, Microsoft will contact using your registered email address to provide LOA (Letter Of Authorization) or for other information.
  4. Once peering request is approved, connection state changes to ProvisioningStarted. Then, you need to:
    1. complete wiring according to the LOA.
    2. (optionally) perform link test using
    3. configure BGP session and then notify Microsoft.
  5. Microsoft provisions BGP session with DENY ALL policy and validate end-to-end.
  6. If successful, you receive a notification that peering connection state is Active.
  7. Traffic is then allowed through the new peering.


Connection states are different from standard BGP session states.

Convert a legacy Direct peering to an Azure resource

To convert a legacy Direct peering to an Azure resource, complete the following steps:

  1. Follow the instructions in Convert a legacy Direct peering to Azure resource
  2. After you submit the conversion request, Microsoft reviews the request and contacts you if necessary.
  3. Once approved, you see your Direct peering with a connection state as Active.

Deprovision Direct peering

Contact Microsoft peering team to deprovision a Direct peering.

When a Direct peering is set for deprovision, the connection state changes to PendingRemove.


If you run PowerShell cmdlet to delete the Direct peering when the ConnectionState is ProvisioningStarted or ProvisioningCompleted, the operation will fail.