DevTest Lab私有网络创建VM触发公网IP配额超限问题求助
I’ve run into this exact head-scratching issue with DevTest Lab and private subnets before, so let’s break down the likely causes and actionable troubleshooting steps:
Possible Causes & Fixes
1. DevTest Lab-Level Policies Are Overriding Subnet Settings
Even if your subnet has public IP options disabled, the lab itself might have policies that enforce public IP creation by default:
- Navigate to your DevTest Lab → Configuration and Policies
- Check the Public IP addresses policy: ensure it’s set to Deny public IP creation (not set to force allocation)
- Also review the Virtual machines policies section for any rules that might mandate public IPs for new VMs
2. Soft-Deleted Public IPs Are Eating Your Quota
Azure retains deleted public IPs in a soft-deleted state for 30 days, and these still count against your regional quota. You might only see one active IP (your gateway), but hidden soft-deleted entries could be pushing you to the 10 limit:
- Use Azure CLI to list all public IPs including deleted ones:
az network public-ip list --subscription <your-subscription-id> --location <your-region> --include-deleted --output table - In the Azure Portal, go to Public IP addresses, click the filter icon, and check the Show deleted resources box to view these hidden entries
- If you find soft-deleted IPs, select them and choose Permanent delete to free up quota
3. Hidden Public IP Configs in VM Templates
If you’re using custom ARM templates or modified lab templates, there might be a publicIPAddress resource defined that overrides your subnet settings:
- Go to your DevTest Lab → Virtual machine library
- Select the template you’re using, click View template to inspect the JSON
- Search for
publicIPAddressentries—if any exist without conditional logic to skip them for private subnets, remove or adjust those sections
4. Azure Policy Enforcement
Check for subscription or resource-group level policies that force public IP allocation for VMs, regardless of subnet settings:
- Go to Azure Policy in the Portal → Assignments
- Filter by your subscription/resource group and look for policies like "Require public IP address on virtual network interfaces"
- If such a policy exists, exclude your DevTest Lab resource group from it or adjust the policy to allow private-only VMs
5. Unexpected Extensions/Services Creating IPs
Rare but possible: some VM extensions or attached services might attempt to create public IPs in the background:
- For existing VMs, go to the Extensions tab and check if any extensions require outbound public access
- Verify you haven’t configured services like Azure Bastion in the same VNet (Bastion uses its own IP, which counts against quota)
Quick Verification Step
Before creating another VM, run this CLI command to check your total IP count (including deleted):
az network public-ip list --subscription <your-subscription-id> --location <your-region> --include-deleted --query "length(@)"
If the output is 10, soft-deleted resources are almost certainly the culprit.
内容的提问来源于stack exchange,提问作者another_one

