Share via

Failed to Delete Basic Public Ip Reference for Basic SKU VPN Gateway

John Sletten 0 Reputation points
2026-06-25T20:40:28.22+00:00

Hi,

After clicking "Delete Basic Public Ip Reference" I encountered two error messages.

Failed to execute migration

Failed to execute migration to Remove Public IP. Error: There was an error processing your request. Try again in a few moments.

Deployment validation failed

Deployment validation failed. Additional details from the underlying API that might be helpful. The template deployment "VirtualNetworkGatewayUpdate-20260625222321" is not valid according to the validation procedure. The following resource provider(s) -"Microsoft.Network/virtualNetworkGateways (2025-05-01) reported preflight validation errors. Tracking id (REDACTED) . See inner errors for details.

Clicking on "Help me troubleshoot" provided rather general tips on checking public IP associations, gateway configurations, subnet and IP capacity.

I did notice that in a similar case, https://learn.microsoft.com/en-us/answers/questions/5864157/failed-to-remove-the-basic-sku-public-ip-address-r the solution involved opening the Point-to-site configuration to remove a certificate. In my setup there are three certs and I would not know which one(s) to safely remove.

I am therefore reaching out to see if anyone else has seen this.

I would be grateful for any advice.

Kind Regards,
John Sletten

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

1 answer

Sort by: Most helpful
  1. John Sletten 0 Reputation points
    2026-06-25T21:54:35.9933333+00:00

    Update

    I managed to identify the expired certificate and duly removed it from the Point-to-site configuration.

    After a delay of about 2 minutes, I got: "Successfully saved virtual network gateway 'VPNGatewayPrimary'.

    Upon retrying the "Delete Basic Public Ip Reference" button I got a different message:

    No migration necessary.

    *Your Gateway does not have a PublicIpAddress reference or is using a PublicIpAddress with Standard Sku. No migration is necessary.

    *The VPN connections are healthy and the old (basic) PublicIp resource no longer has an associated IP address.

    I will monitor the gateway closely for the next 24 hours, but it seems that this matter is resolved now.

    Thanks in any case.

    John

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.