相关文章推荐
发财的蚂蚁  ·  python ...·  1 年前    · 

This browser is no longer supported.

Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.

Download Microsoft Edge More info about Internet Explorer and Microsoft Edge

This document lists some of the most common Microsoft Azure limits, which are also sometimes called quotas.

To learn more about Azure pricing, see Azure pricing overview . There, you can estimate your costs by using the pricing calculator . You also can go to the pricing details page for a particular service, for example, Windows VMs . For tips to help manage your costs, see Prevent unexpected costs with Azure billing and cost management .

Managing limits

Some services have adjustable limits.

When a service doesn't have adjustable limits, the following tables use the header Limit . In those cases, the default and the maximum limits are the same.

When the limit can be adjusted, the tables include Default limit and Maximum limit headers. The limit can be raised above the default limit but not above the maximum limit.

If you want to raise the limit or quota above the default limit, open an online customer support request at no charge .

The terms soft limit and hard limit often are used informally to describe the current, adjustable limit (soft limit) and the maximum limit (hard limit). If a limit isn't adjustable, there won't be a soft limit, only a hard limit.

Free Trial subscriptions aren't eligible for limit or quota increases. If you have a Free Trial subscription , you can upgrade to a Pay-As-You-Go subscription. For more information, see Upgrade your Azure Free Trial subscription to a Pay-As-You-Go subscription and the Free Trial subscription FAQ .

Some limits are managed at a regional level.

Let's use vCPU quotas as an example. To request a quota increase with support for vCPUs, you must decide how many vCPUs you want to use in which regions. You then request an increase in vCPU quotas for the amounts and regions that you want. If you need to use 30 vCPUs in West Europe to run your application there, you specifically request 30 vCPUs in West Europe. Your vCPU quota isn't increased in any other region--only West Europe has the 30-vCPU quota.

As a result, decide what your quotas must be for your workload in any one region. Then request that amount in each region into which you want to deploy. For help in how to determine your current quotas for specific regions, see Resolve errors for resource quotas .

General limits

For limits on resource names, see Naming rules and restrictions for Azure resources .

For information about Resource Manager API read and write limits, see Throttling Resource Manager requests .

Management group limits

The following limits apply to management groups .

Resource Limit

1 The 6 levels don't include the subscription level.

2 If you reach the limit of 800 deployments, delete deployments from the history that are no longer needed. To delete management group level deployments, use Remove-AzManagementGroupDeployment or az deployment mg delete .

Subscription limits

The following limits apply when you use Azure Resource Manager and Azure resource groups.

Resource Limit

1 You can apply up to 50 tags directly to a subscription. However, the subscription can contain an unlimited number of tags that are applied to resource groups and resources within the subscription. The number of tags per resource or resource group is limited to 50.

2 Resource Manager returns a list of tag name and values in the subscription only when the number of unique tags is 80,000 or less. A unique tag is defined by the combination of resource ID, tag name, and tag value. For example, two resources with the same tag name and value would be calculated as two unique tags. You still can find a resource by tag when the number exceeds 80,000.

3 Deployments are automatically deleted from the history as you near the limit. For more information, see Automatic deletions from deployment history .

Resource group limits

Resource Limit Resources per resource group Resources aren't limited by resource group. Instead, they're limited by resource type in a resource group. See next row. Resources per resource group, per resource type 800 - Some resource types can exceed the 800 limit. See Resources not limited to 800 instances per resource group . Deployments per resource group in the deployment history 800 1 Resources per deployment Management locks per unique scope Number of tags per resource or resource group Tag key length Tag value length

1 Deployments are automatically deleted from the history as you near the limit. Deleting an entry from the deployment history doesn't affect the deployed resources. For more information, see Automatic deletions from deployment history .

Template limits

Value Limit

You can exceed some template limits by using a nested template. For more information, see Use linked templates when you deploy Azure resources . To reduce the number of parameters, variables, or outputs, you can combine several values into an object. For more information, see Objects as parameters .

You may get an error with a template or parameter file of less than 4 MB, if the total size of the request is too large. For more information about how to simplify your template to avoid a large request, see Resolve errors for job size exceeded .

Azure Active Directory limits

Here are the usage constraints and other service limits for the Azure AD service.

Category Limit Tenants
  • A single user can belong to a maximum of 500 Azure AD tenants as a member or a guest.
  • A single user can create a maximum of 200 directories.
  • Limit of 300 license-based subscriptions (such as Microsoft 365 subscriptions) per tenant
  • Domains
  • You can add no more than 5,000 managed domain names.
  • If you set up all of your domains for federation with on-premises Active Directory, you can add no more than 2,500 domain names in each tenant.
  • Resources
    • By default, a maximum of 50,000 Azure AD resources can be created in a single tenant by users of the Azure Active Directory Free edition. If you have at least one verified domain, the default Azure AD service quota for your organization is extended to 300,000 Azure AD resources.
      The Azure AD service quota for organizations created by self-service sign-up remains 50,000 Azure AD resources, even after you perform an internal admin takeover and the organization is converted to a managed tenant with at least one verified domain. This service limit is unrelated to the pricing tier limit of 500,000 resources on the Azure AD pricing page.
      To go beyond the default quota, you must contact Microsoft Support.
    • A non-admin user can create no more than 250 Azure AD resources. Both active resources and deleted resources that are available to restore count toward this quota. Only deleted Azure AD resources that were deleted fewer than 30 days ago are available to restore. Deleted Azure AD resources that are no longer available to restore count toward this quota at a value of one-quarter for 30 days.
      If you have developers who are likely to repeatedly exceed this quota in the course of their regular duties, you can create and assign a custom role with permission to create a limitless number of app registrations.
    • Resource limitations apply to all directory objects in a given Azure AD tenant, including users, groups, applications, and service principals.
    Schema extensions
    • String-type extensions can have a maximum of 256 characters.
    • Binary-type extensions are limited to 256 bytes.
    • Only 100 extension values, across all types and all applications, can be written to any single Azure AD resource.
    • Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.
    Applications
    • A maximum of 100 users and service principals can be owners of a single application.
    • A user, group, or service principal can have a maximum of 1,500 app role assignments. The limitation is on the service principal, user, or group across all app roles and not on the number of assignments on a single app role.
    • A user can have credentials configured for a maximum of 48 apps using password-based single sign-on. This limit only applies for credentials configured when the user is directly assigned the app, not when the user is a member of a group which is assigned.
    • A group can have credentials configured for a maximum of 48 apps using password-based single sign-on.
    • See additional limits in Validation differences by supported account types .
    Application manifest A maximum of 1,200 entries can be added to the application manifest.
    See additional limits in Validation differences by supported account types . Groups
    • A non-admin user can create a maximum of 250 groups in an Azure AD organization. Any Azure AD admin who can manage groups in the organization can also create an unlimited number of groups (up to the Azure AD object limit). If you assign a role to a user to remove the limit for that user, assign a less privileged, built-in role such as User Administrator or Groups Administrator.
    • An Azure AD organization can have a maximum of 5,000 dynamic groups and dynamic administrative units combined.
    • A maximum of 500 role-assignable groups can be created in a single Azure AD organization (tenant).
    • A maximum of 100 users can be owners of a single group.
    • Any number of Azure AD resources can be members of a single group.
    • A user can be a member of any number of groups. When security groups are being used in combination with SharePoint Online, a user can be a part of 2,049 security groups in total. This includes both direct and indirect group memberships. When this limit is exceeded, authentication and search results become unpredictable.
    • By default, the number of members in a group that you can synchronize from your on-premises Active Directory to Azure Active Directory by using Azure AD Connect is limited to 50,000 members. If you need to sync a group membership that's over this limit, you must onboard the Azure AD Connect Sync V2 endpoint API .
    • When you select a list of groups, you can assign a group expiration policy to a maximum of 500 Microsoft 365 groups. There is no limit when the policy is applied to all Microsoft 365 groups.

    At this time, the following scenarios are supported with nested groups:
    • One group can be added as a member of another group, and you can achieve group nesting.
    • Group membership claims. When an app is configured to receive group membership claims in the token, nested groups in which the signed-in user is a member are included.
    • Conditional access (when a conditional access policy has a group scope).
    • Restricting access to self-serve password reset.
    • Restricting which users can do Azure AD Join and device registration.

    The following scenarios are not supported with nested groups:
    • App role assignment, for both access and provisioning. Assigning groups to an app is supported, but any groups nested within the directly assigned group won't have access.
    • Group-based licensing (assigning a license automatically to all members of a group).
    • Microsoft 365 Groups.
    Application Proxy
    • A maximum of 500 transactions* per second per Application Proxy application.
    • A maximum of 750 transactions per second for the Azure AD organization.

      *A transaction is defined as a single HTTP request and response for a unique resource. When clients are throttled, they'll receive a 429 response (too many requests).
    Access Panel There's no limit to the number of applications per user that can be displayed in the Access Panel, regardless of the number of assigned licenses. Reports A maximum of 1,000 rows can be viewed or downloaded in any report. Any additional data is truncated. Administrative units
    • An Azure AD resource can be a member of no more than 30 administrative units.
    • A maximum of 30 restricted management administrative units in a tenant.
    • An Azure AD organization can have a maximum of 5,000 dynamic groups and dynamic administrative units combined.
    Azure AD roles and permissions
    • A maximum of 100 Azure AD custom roles can be created in an Azure AD organization.
    • A maximum of 150 Azure AD custom role assignments for a single principal at any scope.
    • A maximum of 100 Azure AD built-in role assignments for a single principal at non-tenant scope (such as an administrative unit or Azure AD object). There is no limit to Azure AD built-in role assignments at tenant scope. For more information, see Assign Azure AD roles at different scopes .
    • A group can't be added as a group owner .
    • A user's ability to read other users' tenant information can be restricted only by the Azure AD organization-wide switch to disable all non-admin users' access to all tenant information (not recommended). For more information, see To restrict the default permissions for member users .
    • It might take up to 15 minutes or you might have to sign out and sign back in before admin role membership additions and revocations take effect.
    Conditional Access Policies A maximum of 195 policies can be created in a single Azure AD organization (tenant). Terms of use You can add no more than 40 terms to a single Azure AD organization (tenant).

    API Center (preview) limits

    Resource Limit 1

    1 Scaling limits depend on the pricing tier. For details on the pricing tiers and their scaling limits, see API Management pricing .
    2 Per unit cache size depends on the pricing tier. To see the pricing tiers and their scaling limits, see API Management pricing .
    3 Connections are pooled and reused unless explicitly closed by the back end.
    4 This limit is per unit of the Basic, Standard, and Premium tiers. The Developer tier is limited to 1,024. This limit doesn't apply to the Consumption tier.
    5 This limit applies to the Basic, Standard, and Premium tiers. In the Consumption tier, policy document size is limited to 16 KiB.
    6 Multiple custom domains are supported in the Developer and Premium tiers only.
    7 CA certificates are not supported in the Consumption tier.
    8 This limit applies to the Consumption tier only. There are no specific limits in other tiers but depends on service infrastructure, policy configuration, number of concurrent requests, and other factors.
    9 Applies to the Consumption tier only. Includes an up to 2048-bytes long query string.
    10 To increase this limit, contact support .
    11 Self-hosted gateways are supported in the Developer and Premium tiers only. The limit applies to the number of self-hosted gateway resources . To raise this limit contact support . Note, that the number of nodes (or replicas) associated with a self-hosted gateway resource is unlimited in the Premium tier and capped at a single node in the Developer tier.
    12 This limit does not apply to Developer tier. In the Developer tier, the limit is 2,500.

    App Service limits

    Resource Shared Basic Standard Premium (v1-v3) Isolated App Service plan 10 per region

    1 free Linux App Service plan per region 10 per resource group 100 per resource group 100 per resource group 100 per resource group 100 per resource group Compute instance type Shared Shared Dedicated 3 Dedicated 3 Dedicated 3 Dedicated 3 Scale out (maximum instances) 1 shared 1 shared 3 dedicated 3 10 dedicated 3 20 dedicated for v1; 30 dedicated for v2 and v3. 3 100 dedicated 4 Storage 5 1 GB 5 1 GB 5 10 GB 5 50 GB 5 250 GB 5 1 TB 12

    The available storage quota is 999 GB. CPU time (5 minutes) 6 3 minutes 3 minutes Unlimited, pay at standard rates Unlimited, pay at standard rates Unlimited, pay at standard rates Unlimited, pay at standard rates CPU time (day) 6 60 minutes 240 minutes Unlimited, pay at standard rates Unlimited, pay at standard rates Unlimited, pay at standard rates Unlimited, pay at standard rates Memory (1 hour) 1,024 MB per App Service plan 1,024 MB per app Bandwidth 165 MB Unlimited, data transfer rates apply Unlimited, data transfer rates apply Unlimited, data transfer rates apply Unlimited, data transfer rates apply Unlimited, data transfer rates apply Application architecture 32-bit 32-bit 32-bit/64-bit 32-bit/64-bit 32-bit/64-bit 32-bit/64-bit Web sockets per instance 7 Unlimited Unlimited Unlimited Outbound IP connections per instance Depends on instance size 8 Depends on instance size 8 Depends on instance size 8 16,000 Concurrent debugger connections per application App Service Certificates per subscription Not supported Not supported Custom domains per app 0 (azurewebsites.net subdomain only) Custom domain SSL support Not supported, wildcard certificate for *.azurewebsites.net available by default Not supported, wildcard certificate for *.azurewebsites.net available by default Unlimited SNI SSL connections Unlimited SNI SSL and 1 IP SSL connections included Unlimited SNI SSL and 1 IP SSL connections included Unlimited SNI SSL and 1 IP SSL connections included Hybrid connections 5 per plan 25 per plan 220 per app 220 per app Virtual Network Integration Private Endpoints 100 per app Integrated load balancer Access restrictions 512 rules per app 512 rules per app 512 rules per app 512 rules per app 512 rules per app 512 rules per app Always On Scheduled backups Scheduled backups every 2 hours, a maximum of 12 backups per day (manual + scheduled Scheduled backups every 2 hours, a maximum of 12 backups per day (manual + scheduled) Scheduled backups every hour, a maximum of 50 backups per day (manual + scheduled) Scheduled backups every hour, a maximum of 50 backups per day (manual + scheduled) Autoscale WebJobs 10 Endpoint monitoring Staging slots per app Testing in Production Diagnostic Logs Authentication and Authorization App Service Managed Certificates 11 99.95% 99.95% 99.95% 99.95%

    1 Apps and storage quotas are per App Service plan unless noted otherwise.

    2 The actual number of apps that you can host on these machines depends on the activity of the apps, the size of the machine instances, and the corresponding resource utilization.

    3 Dedicated instances can be of different sizes. For more information, see App Service pricing .

    4 More are allowed upon request.

    5 The storage limit is the total content size across all apps in the same App service plan. The total content size of all apps across all App service plans in a single resource group and region cannot exceed 500 GB. The file system quota for App Service hosted apps is determined by the aggregate of App Service plans created in a region and resource group.

    6 These resources are constrained by physical resources on the dedicated instances (the instance size and the number of instances).

    7 If you scale an app in the Basic tier to two instances, you have 350 concurrent connections for each of the two instances. For Standard tier and above, there are no theoretical limits to web sockets, but other factors can limit the number of web sockets. For example, maximum concurrent requests allowed (defined by maxConcurrentRequestsPerCpu ) are: 7,500 per small VM, 15,000 per medium VM (7,500 x 2 cores), and 75,000 per large VM (18,750 x 4 cores).

    8 The maximum IP connections are per instance and depend on the instance size: 1,920 per B1/S1/P1V3 instance, 3,968 per B2/S2/P2V3 instance, 8,064 per B3/S3/P3V3 instance.

    9 App Service Isolated SKUs can be internally load balanced (ILB) with Azure Load Balancer, so there's no public connectivity from the internet. As a result, some features of an ILB Isolated App Service must be used from machines that have direct access to the ILB network endpoint.

    10 Run custom executables and/or scripts on demand, on a schedule, or continuously as a background task within your App Service instance. Always On is required for continuous WebJobs execution. There's no predefined limit on the number of WebJobs that can run in an App Service instance. There are practical limits that depend on what the application code is trying to do.

    11 Only issuing standard certificates (wildcard certificates aren't available). Limited to only one free certificate per custom domain.

    12 Total storage usage across all apps deployed in a single App Service Environment (regardless of how they're allocated across different resource groups).

    Automation limits

    Process automation

    Resource Limit Notes Maximum number of new jobs that can be submitted every 30 seconds per Azure Automation account (nonscheduled jobs) When this limit is reached, the subsequent requests to create a job fail. The client receives an error response. Maximum number of concurrent running jobs at the same instance of time per Automation account (nonscheduled jobs) When this limit is reached, the subsequent requests to create a job fail. The client receives an error response. Maximum storage size of job metadata for a 30-day rolling period 10 GB (approximately 4 million jobs) When this limit is reached, the subsequent requests to create a job fail. Maximum job stream limit 1 MiB A single stream cannot be larger than 1 MiB. Maximum job stream limit on Azure Automation portal 200KB Portal limit to show the job logs. Maximum number of modules that can be imported every 30 seconds per Automation account Maximum size of a module 100 MB Maximum size of a node configuration file Applies to state configuration Job run time, Free tier 500 minutes per subscription per calendar month Maximum amount of disk space allowed per sandbox 1 Applies to Azure sandboxes only. Maximum amount of memory given to a sandbox 1 400 MB Applies to Azure sandboxes only. Maximum number of network sockets allowed per sandbox 1 1,000 Applies to Azure sandboxes only. Maximum runtime allowed per runbook 1 3 hours Applies to Azure sandboxes only. Maximum number of Automation accounts in a subscription No limit Maximum number of system hybrid runbook workers per Automation Account 4,000 Maximum number of user hybrid runbook workers per Automation Account 4,000 Maximum number of concurrent jobs that can be run on a single Hybrid Runbook Worker Maximum runbook job parameter size 512 kilobytes Maximum runbook parameters If you reach the 50-parameter limit, you can pass a JSON or XML string to a parameter and parse it with the runbook. Maximum webhook payload size 512 kilobytes Maximum days that job data is retained 30 days Maximum PowerShell workflow state size Applies to PowerShell workflow runbooks when checkpointing workflow. Maximum number of tags supported by an Automation account Maximum number of characters in the value field of a variable 1048576

    1 A sandbox is a shared environment that can be used by multiple jobs. Jobs that use the same sandbox are bound by the resource limitations of the sandbox.

    Change Tracking and Inventory

    The following table shows the tracked item limits per machine for change tracking.

    Resource Limit Notes Configuration store requests for Free tier 1,000 requests per day Once the quota is exhausted, HTTP status code 429 will be returned for all requests until the end of the day Configuration store requests for Standard tier 30,000 per hour Once the quota is exhausted, requests may return HTTP status code 429 indicating Too Many Requests - until the end of the hour Storage for Free tier 10 MB Storage for Standard tier Keys and Values 10 KB For a single key-value item, including all metadata

    Azure Cache for Redis limits

    Resource Limit

    Azure Cache for Redis limits and sizes are different for each pricing tier. To see the pricing tiers and their associated sizes, see Azure Cache for Redis pricing .

    For more information on Azure Cache for Redis configuration limits, see Default Redis server configuration .

    Because configuration and management of Azure Cache for Redis instances is done by Microsoft, not all Redis commands are supported in Azure Cache for Redis. For more information, see Redis commands not supported in Azure Cache for Redis .

    Azure Cloud Services limits

    Resource Limit

    1 Each Azure Cloud Service with web or worker roles can have two deployments, one for production and one for staging. This limit refers to the number of distinct roles, that is, configuration. This limit doesn't refer to the number of instances per role, that is, scaling.

    Azure Cognitive Search limits

    Pricing tiers determine the capacity and limits of your search service. Tiers include:

  • Free multi-tenant service, shared with other Azure subscribers, is intended for evaluation and small development projects.
  • Basic provides dedicated computing resources for production workloads at a smaller scale, with up to three replicas for highly available query workloads.
  • Standard , which includes S1, S2, S3, and S3 High Density, is for larger production workloads. Multiple levels exist within the Standard tier so that you can choose a resource configuration that best matches your workload profile.
  • Limits per subscription

    You can create multiple services, limited only by the number of services allowed at each tier. For example, you could create up to 16 services at the Basic tier and another 16 services at the S1 tier within the same subscription. For more information about tiers, see Choose an SKU or tier for Azure Cognitive Search .

    Maximum service limits can be raised upon request. If you need more services within the same subscription, file a support request .

    Resource Free 1 Basic S3 HD

    1 Free is based on infrastructure that's shared with other customers. Because the hardware isn't dedicated, scale-up isn't supported on the free tier.

    2 Search units are billing units, allocated as either a replica or a partition . You need both resources for storage, indexing, and query operations. To learn more about SU computations, see Scale resource levels for query and index workloads .

    Limits per search service

    A search service is constrained by disk space or by a hard limit on the maximum number of indexes or indexers, whichever comes first. The following table documents storage limits. For maximum object limits, see Limits by resource .

    Resource Basic 1 S3 HD

    1 Basic has one fixed partition. Additional search units can be used to add replicas for larger query volumes.

    2 Service level agreements are in effect for billable services on dedicated resources. Free services and preview features have no SLA. For billable services, SLAs take effect when you provision sufficient redundancy for your service. Two or more replicas are required for query (read) SLAs. Three or more replicas are required for query and indexing (read-write) SLAs. The number of partitions isn't an SLA consideration.

    To learn more about limits on a more granular level, such as document size, queries per second, keys, requests, and responses, see Service limits in Azure Cognitive Search .

    Azure Cognitive Services limits

    The following limits are for the number of Cognitive Services resources per Azure subscription. There is a limit of only one allowed 'Free' account, per Cognitive Service type, per subscription. Each of the Cognitive Services may have other limitations, for more information, see Azure Cognitive Services .

    Limit Example A mixture of Cognitive Services resources Maximum of 200 total Cognitive Services resources per region. 100 Computer Vision resources in West US, 50 Speech Service resources in West US, and 50 Text Analytics resources in West US. A single type of Cognitive Services resources. Maximum of 100 resources per region 100 Computer Vision resources in West US 2, and 100 Computer Vision resources in East US.

    Azure Communications Gateway limits

    Some of the following default limits and quotas can be increased. To request a change, create a change request stating the limit you want to change.

    The following restrictions apply to all Azure Communications Gateways:

  • All traffic must use IPv4.
  • All traffic must use TLS 1.2 or greater. Earlier versions aren't supported.
  • The number of active calls is limited to 15% of the number of Users assigned to the Azure Communications Gateway as defined in Plan and manage costs for Azure Communications Gateway .
  • Azure Communications Gateway also has limits on the SIP signaling.

    Resource Limit

    Some endpoints might add parameters in the following headers to an in-dialog message when those parameters weren't present in the dialog-creating message. In that case, Azure Communications Gateway will strip them, because this behavior isn't permitted by RFC 3261.

  • Request URI
  • To header
  • From header
  • Azure Container Apps limits

    For Azure Container Apps limits, see Quotas in Azure Container Apps .

    Azure Cosmos DB limits

    For Azure Cosmos DB limits, see Limits in Azure Cosmos DB .

    Azure Data Explorer limits

    The following table describes the maximum limits for Azure Data Explorer clusters.

    Resource Limit Number of follower clusters (data share consumers) per leader cluster (data share producer)

    The following table describes the limits on management operations performed on Azure Data Explorer clusters.

    Scope Operation Limit

    Azure Database for MySQL

    For Azure Database for MySQL limits, see Limitations in Azure Database for MySQL .

    Azure Database for PostgreSQL

    For Azure Database for PostgreSQL limits, see Limitations in Azure Database for PostgreSQL .

    Azure Deployment Environments limits

    Subscription Runtime limit per deployment​ Runtime limit per month per region per subscription​ Storage limit per Environment​

    Azure Files and Azure File Sync

    To learn more about the limits for Azure Files and File Sync, see Azure Files scalability and performance targets .

    Azure Functions limits

    Resource Consumption plan Premium plan Dedicated plan Kubernetes Custom domain SSL support unbounded SNI SSL connection included unbounded SNI SSL and 1 IP SSL connections included unbounded SNI SSL and 1 IP SSL connections included unbounded SNI SSL and 1 IP SSL connections included

    1 By default, the timeout for the Functions 1.x runtime in an App Service plan is unbounded.
    2 Requires the App Service plan be set to Always On . Pay at standard rates .
    3 These limits are set in the host .
    4 The actual number of function apps that you can host depends on the activity of the apps, the size of the machine instances, and the corresponding resource utilization.
    5 The storage limit is the total content size in temporary storage across all apps in the same App Service plan. Consumption plan uses Azure Files for temporary storage.
    6 When your function app is hosted in a Consumption plan , only the CNAME option is supported. For function apps in a Premium plan or an App Service plan , you can map a custom domain using either a CNAME or an A record.
    7 Guaranteed for up to 60 minutes.
    8 Workers are roles that host customer apps. Workers are available in three fixed sizes: One vCPU/3.5 GB RAM; Two vCPU/7 GB RAM; Four vCPU/14 GB RAM.
    9 See App Service limits for details.
    10 Including the production slot.
    11 There's currently a limit of 5000 function apps in a given subscription.

    For more information, see Functions Hosting plans comparison .

    Azure Health Data Services

    Azure Health Data Services limits

    Health Data Services is a set of managed API services based on open standards and frameworks. Health Data Services enables workflows to improve healthcare and offers scalable and secure healthcare solutions. Health Data Services includes Fast Healthcare Interoperability Resources (FHIR) service, the Digital Imaging and Communications in Medicine (DICOM) service, and MedTech service.

    FHIR service is an implementation of the FHIR specification within Health Data Services. It enables you to combine in a single workspace one or more FHIR service instances with optional DICOM and MedTech service instances. Azure API for FHIR is generally available as a stand-alone service offering.

    FHIR service in Azure Health Data Services has a limit of 4 TB for structured storage.

    Quota Name Default Limit Maximum Limit Notes 100,000 RUs Contact support Maximum available is 1,000,000. You need a minimum of 400 RUs or 40 RUs/GB, whichever is larger. Concurrent connections 15 concurrent connections on two instances (for a total of 30 concurrent requests) Contact support Azure API for FHIR Service Instances per Subscription Contact support Maximum clusters per subscription 5000
    Note: spread clusters across different regions to account for Azure API throttling limits Maximum nodes per cluster with Virtual Machine Scale Sets and Standard Load Balancer SKU 5000 across all node-pools (default limit: 1000)
    Note: Running more than a 1000 nodes per cluster requires increasing the default node limit quota. Contact support for assistance. Maximum nodes per node pool (Virtual Machine Scale Sets node pools) Maximum node pools per cluster Maximum pods per node: with Kubenet networking plug-in Maximum: 250
    Azure CLI default: 110
    Azure Resource Manager template default: 110
    Azure portal deployment default: 30 Maximum pods per node: with Azure Container Networking Interface Maximum: 250
    Default: 30 Open Service Mesh (OSM) AKS addon Kubernetes Cluster Version: AKS Supported Versions
    OSM controllers per cluster: 1
    Pods per OSM controller: 1600
    Kubernetes service accounts managed by OSM: 160 Maximum load-balanced kubernetes services per cluster with Standard Load Balancer SKU Maximum nodes per cluster with Virtual Machine Availability Sets and Basic Load Balancer SKU Standard tier Automatically scales Kubernetes API server based on load. Larger control plane component limits and API server/etc instances. Free tier Limited resources with inflight requests limit of 50 mutating and 100 read-only calls. Recommended node limit of 10 nodes per cluster. Best for experimenting, learning, and simple testing. Not advised for production/critical workloads .

    Azure Lab Services

    The following limits are for the number of Azure Lab Services resources.

    Per resource type

    Grouping Resource type Limit

    For more information about Azure Lab Services capacity limits, see Capacity limits in Azure Lab Services .

    Contact support to request an increase your limit.

    Azure Load Testing limits

    For Azure Load Testing limits, see Service limits in Azure Load Testing .

    Azure Machine Learning limits

    The latest values for Azure Machine Learning Compute quotas can be found in the Azure Machine Learning quota page

    Azure Maps limits

    The following table shows the usage limit for the Azure Maps S0 pricing tier. Usage limit depends on the pricing tier.

    Resource S0 pricing tier limit

    For more information on the Azure Maps pricing tiers, see Azure Maps pricing .

    Azure Monitor limits

    For Azure Monitor limits, see Azure Monitor service limits .

    Azure Data Factory limits

    Azure Data Factory is a multitenant service that has the following default limits in place to make sure customer subscriptions are protected from each other's workloads. To raise the limits up to the maximum for your subscription, contact support.

    Version 2

    Resource Default limit Maximum limit Total number of entities, such as pipelines, data sets, triggers, linked services, Private Endpoints, and integration runtimes, within a data factory 5,000 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Total CPU cores for Azure-SSIS Integration Runtimes under one subscription [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent pipeline runs per data factory that's shared among all pipelines in the factory 10,000 10,000 Concurrent External activity runs per subscription per Azure Integration Runtime region
    External activities are managed on integration runtime but execute on linked services, including Databricks, stored procedure, Web, and others. This limit does not apply to Self-hosted IR. 3,000 3,000 Concurrent Pipeline activity runs per subscription per Azure Integration Runtime region
    Pipeline activities execute on integration runtime, including Lookup, GetMetadata, and Delete. This limit does not apply to Self-hosted IR. 1,000 1,000 Concurrent authoring operations per subscription per Azure Integration Runtime region
    Including test connection, browse folder list and table list, preview data. This limit does not apply to Self-hosted IR. Concurrent Data Integration Units 1 consumption per subscription per Azure Integration Runtime region Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500 Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500 Concurrent Data Integration Units 1 consumption per subscription per Azure Integration Runtime region in managed virtual network 2,400 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Maximum activities per pipeline, which includes inner activities for containers Maximum number of linked integration runtimes that can be created against a single self-hosted integration runtime Maximum number of node that can be created against a single self-hosted integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ Maximum parameters per pipeline ForEach items 100,000 100,000 ForEach parallelism Maximum queued runs per pipeline Characters per expression 8,192 8,192 Minimum tumbling window trigger interval 5 min 15 min Maximum timeout for pipeline activity runs 7 days 7 days Bytes per object for pipeline objects 3 200 KB 200 KB Bytes per object for dataset and linked service objects 3 100 KB 2,000 KB Bytes per payload for each activity run 4 896 KB 896 KB Data Integration Units 1 per copy activity run Write API calls 1,200/h 1,200/h

    This limit is imposed by Azure Resource Manager, not Azure Data Factory. Read API calls 12,500/h 12,500/h

    This limit is imposed by Azure Resource Manager, not Azure Data Factory. Monitoring queries per minute 1,000 1,000 Maximum time of data flow debug session 8 hrs 8 hrs Concurrent number of data flows per integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flows per integration runtime in managed vNet [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flow debug sessions per user per factory Data Flow Azure IR TTL limit 4 hrs 4 hrs Meta Data Entity Size limit in a factory [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ .

    1 The data integration unit (DIU) is used in a cloud-to-cloud copy operation, learn more from Data integration units (version 2) . For information on billing, see Azure Data Factory pricing .

    2 Azure Integration Runtime is globally available to ensure data compliance, efficiency, and reduced network egress costs.

    Region group Regions Region group 1 Central US, East US, East US 2, North Europe, West Europe, West US, West US 2 Region group 2 Australia East, Australia Southeast, Brazil South, Central India, Japan East, North Central US, South Central US, Southeast Asia, West Central US Region group 3 Other regions

    If managed virtual network is enabled, the data integration unit (DIU) in all region groups are 2,400.

    3 Pipeline, data set, and linked service objects represent a logical grouping of your workload. Limits for these objects don't relate to the amount of data you can move and process with Azure Data Factory. Data Factory is designed to scale to handle petabytes of data.

    4 The payload for each activity run includes the activity configuration, the associated dataset(s) and linked service(s) configurations if any, and a small portion of system properties generated per activity type. Limit for this payload size doesn't relate to the amount of data you can move and process with Azure Data Factory. Learn about the symptoms and recommendation if you hit this limit.

    Version 1

    Resource Default limit Maximum limit Pipelines within a data factory 2,500 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Data sets within a data factory 5,000 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent slices per data set Bytes per object for pipeline objects 1 200 KB 200 KB Bytes per object for data set and linked service objects 1 100 KB 2,000 KB Azure HDInsight on-demand cluster cores within a subscription 2 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Cloud data movement units per copy activity run 3 Retry count for pipeline activity runs 1,000 MaxInt (32 bit)

    1 Pipeline, data set, and linked service objects represent a logical grouping of your workload. Limits for these objects don't relate to the amount of data you can move and process with Azure Data Factory. Data Factory is designed to scale to handle petabytes of data.

    2 On-demand HDInsight cores are allocated out of the subscription that contains the data factory. As a result, the previous limit is the Data Factory-enforced core limit for on-demand HDInsight cores. It's different from the core limit that's associated with your Azure subscription.

    3 The cloud data movement unit (DMU) for version 1 is used in a cloud-to-cloud copy operation, learn more from Cloud data movement units (version 1) . For information on billing, see Azure Data Factory pricing .

    Resource Default lower limit Minimum limit

    Web service call limits

    Azure Resource Manager has limits for API calls. You can make API calls at a rate within the Azure Resource Manager API limits .

    Azure NetApp Files

    Azure NetApp Files has a regional limit for capacity. The standard capacity limit for each subscription is 25 TiB, per region, across all service levels. To increase the capacity, use the Service and subscription limits (quotas) support request.

    To learn more about the limits for Azure NetApp Files, see Resource limits for Azure NetApp Files .

    Azure Policy limits

    There's a maximum count for each object type for Azure Policy. For definitions, an entry of Scope means the management group or subscription. For assignments and exemptions, an entry of Scope means the management group , subscription, resource group, or individual resource.

    Where Maximum count

    Policy rules have additional limits to the number of conditions and their complexity. See Policy rule limits for more details.

    Azure Quantum limits

    Provider Limits & Quota

    The Azure Quantum Service supports both first and third-party service providers. Third-party providers own their limits and quotas. Users can view offers and limits in the Azure portal when configuring third-party providers.

    You can find the published quota limits for Microsoft's first party Optimization Solutions provider below.

    Learn & Develop SKU

    Resource Limit

    While on the Learn & Develop SKU, you cannot request an increase on your quota limits. Instead you should switch to the Performance at Scale SKU.

    Performance at Scale SKU

    Resource Default Limit Maximum Limit

    Reach out to Azure Support to request a limit increase.

    For more information, please review the Azure Quantum pricing page . Review the relevant provider pricing pages in the Azure portal for details on third-party offerings.

    1 Describes the number of jobs that can be queued at the same time.

    Azure RBAC limits

    The following limits apply to Azure role-based access control (Azure RBAC) .

    Resource Limit

    To request an update to your subscription's default limits, open a support ticket.

    For more information about how connections and messages are counted, see Messages and connections in Azure SignalR Service .

    If your requirements exceed the limits, switch from Free tier to Standard tier and add units. For more information, see How to scale an Azure SignalR Service instance? .

    If your requirements exceed the limits of a single instance, add instances. For more information, see How to scale SignalR Service with multiple instances? .

    Azure Spring Apps limits

    To learn more about the limits for Azure Spring Apps, see Quotas and service plans for Azure Spring Apps .

    Azure Storage limits

    This section lists the following limits for Azure Storage:

  • Standard storage account limits
  • Azure Storage resource provider limits
  • Azure Blob Storage limits
  • Azure Queue storage limits
  • Azure Table storage limits
  • Standard storage account limits

    The following table describes default limits for Azure general-purpose v2 (GPv2), general-purpose v1 (GPv1), and Blob storage accounts. The ingress limit refers to all data that is sent to a storage account. The egress limit refers to all data that is received from a storage account.

    Microsoft recommends that you use a GPv2 storage account for most scenarios. You can easily upgrade a GPv1 or a Blob storage account to a GPv2 account with no downtime and without the need to copy data. For more information, see Upgrade to a GPv2 storage account .

    You can request higher capacity and ingress limits. To request an increase, contact Azure Support .

    Maximum number of storage accounts with standard endpoints per region per subscription, including standard and premium storage accounts. 250 by default, 500 by request 1 Maximum number of storage accounts with Azure DNS zone endpoints (preview) per region per subscription, including standard and premium storage accounts. 5000 (preview) Default maximum storage account capacity 5 PiB 2 Maximum number of blob containers, blobs, file shares, tables, queues, entities, or messages per storage account. No limit Default maximum request rate per storage account 20,000 requests per second 2 Default maximum ingress per general-purpose v2 and Blob storage account in the following regions (LRS/GRS):
    • Australia East
    • Central US
    • East Asia
    • East US 2
    • Japan East
    • Korea Central
    • North Europe
    • South Central US
    • Southeast Asia
    • UK South
    • West Europe
    • West US
    60 Gbps 2 Default maximum ingress per general-purpose v2 and Blob storage account in the following regions (ZRS):
    • Australia East
    • Central US
    • East US
    • East US 2
    • Japan East
    • North Europe
    • South Central US
    • Southeast Asia
    • UK South
    • West Europe
    • West US 2
    60 Gbps 2 Default maximum ingress per general-purpose v2 and Blob storage account in regions that aren't listed in the previous row. 25 Gbps 2 Default maximum ingress for general-purpose v1 storage accounts (all regions) 10 Gbps 2 Default maximum egress for general-purpose v2 and Blob storage accounts in the following regions (LRS/GRS):
    • Australia East
    • Central US
    • East Asia
    • East US 2
    • Japan East
    • Korea Central
    • North Europe
    • South Central US
    • Southeast Asia
    • UK South
    • West Europe
    • West US
    120 Gbps 2 Default maximum egress for general-purpose v2 and Blob storage accounts in the following regions (ZRS):
    • Australia East
    • Central US
    • East US
    • East US 2
    • Japan East
    • North Europe
    • South Central US
    • Southeast Asia
    • UK South
    • West Europe
    • West US 2
    120 Gbps 2 Default maximum egress for general-purpose v2 and Blob storage accounts in regions that aren't listed in the previous row. 50 Gbps 2 Maximum number of IP address rules per storage account Maximum number of virtual network rules per storage account Maximum number of resource instance rules per storage account Maximum number of private endpoints per storage account

    1 With a quota increase, you can create up to 500 storage accounts with standard endpoints per region. For more information, see Increase Azure Storage account quotas . 2 Azure Storage standard accounts support higher capacity limits and higher limits for ingress and egress by request. To request an increase in account limits, contact Azure Support .

    Azure Storage resource provider limits

    The following limits apply only when you perform management operations by using Azure Resource Manager with Azure Storage. The limits apply per region of the resource in the request.

    Resource Limit

    1 Throughput for a single blob depends on several factors. These factors include but aren't limited to: concurrency, request size, performance tier, speed of source for uploads, and destination for downloads. To take advantage of the performance enhancements of high-throughput block blobs , upload larger blobs or blocks. Specifically, call the Put Blob or Put Block operation with a blob or block size that is greater than 4 MiB for standard storage accounts. For premium block blob or for Data Lake Storage Gen2 storage accounts, use a block or blob size that is greater than 256 KiB.

    2 Page blobs aren't yet supported in accounts that have a hierarchical namespace enabled.

    The following table describes the maximum block and blob sizes permitted by service version.

    Service version Maximum block size (via Put Block) Maximum blob size (via Put Block List) Maximum blob size via single write operation (via Put Blob) Version 2016-05-31 through version 2019-07-07 100 MiB Approximately 4.75 TiB (100 MiB X 50,000 blocks) 256 MiB Versions prior to 2016-05-31 4 MiB Approximately 195 GiB (4 MiB X 50,000 blocks) 64 MiB

    Azure Queue storage limits

    Resource Target Maximum request rate per storage account 20,000 messages per second, which assumes a 1-KiB message size Target throughput for a single queue (1-KiB messages) Up to 2,000 messages per second

    Azure Table storage limits

    The following table describes capacity, scalability, and performance targets for Table storage.

    Resource Target Number of tables in an Azure storage account Limited only by the capacity of the storage account Number of partitions in a table Limited only by the capacity of the storage account Number of entities in a partition Limited only by the capacity of the storage account Maximum size of a single table 500 TiB Maximum size of a single entity, including all property values 1 MiB Maximum number of properties in a table entity 255 (including the three system properties, PartitionKey , RowKey , and Timestamp ) Maximum total size of an individual property in an entity Varies by property type. For more information, see Property Types in Understanding the Table Service Data Model . Size of the PartitionKey A string up to 1 KiB in size Size of the RowKey A string up to 1 KiB in size Size of an entity group transaction A transaction can include at most 100 entities and the payload must be less than 4 MiB in size. An entity group transaction can include an update to an entity only once. Maximum number of stored access policies per table Maximum request rate per storage account 20,000 transactions per second, which assumes a 1-KiB entity size Target throughput for a single table partition (1 KiB-entities) Up to 2,000 entities per second

    Azure subscription creation limits

    To learn more about the creation limits for Azure subscriptions, see Billing accounts and scopes in the Azure portal .

    Azure Virtual Desktop Service limits

    The following table describes the maximum limits for Azure Virtual Desktop.

    Azure Virtual Desktop Object Per Parent Container Object Service Limit

    1 If you require over 500 Application groups then please raise a support ticket via the Azure portal.

    All other Azure resources used in Azure Virtual Desktop such as Virtual Machines, Storage, Networking etc. are all subject to their own resource limitations documented in the relevant sections of this article. To visualise the relationship between all the Azure Virtual Desktop objects, review this article Relationships between Azure Virtual Desktop logical components .

    To get started with Azure Virtual Desktop, use the getting started guide . For deeper architectural content for Azure Virtual Desktop, use the Azure Virtual Desktop section of the Cloud Adoption Framework . For pricing information for Azure Virtual Desktop, add "Azure Virtual Desktop" within the Compute section of the Azure Pricing Calculator .

    Azure VMware Solution limits

    The following table describes the maximum limits for Azure VMware Solution.

    Resource Limit Maximum number of Azure VMware Solution ExpressRoute linked private clouds from a single location to a single Virtual Network Gateway 4
    The virtual network gateway used determines the actual max linked private clouds. For more details, see About ExpressRoute virtual network gateways
    If you exceed this threshold use Azure VMware Solution Interconnect to aggregate private cloud connectivity within the Azure region. Maximum Azure VMware Solution ExpressRoute port speed 10 Gbps (use Ultra Performance Gateway SKU with FastPath enabled)
    The virtual network gateway used determines the actual bandwidth. For more details, see About ExpressRoute virtual network gateways Maximum number of Azure Public IPv4 addresses assigned to NSX-T Data Center 2,000 Maximum number of Azure VMware Solution Interconnects per private cloud vSAN capacity limits 75% of total usable (keep 25% available for SLA) VMware Site Recovery Manager - Maximum number of protected Virtual Machines 3,000 VMware Site Recovery Manager - Maximum number of Virtual Machines per recovery plan 2,000 VMware Site Recovery Manager - Maximum number of protection groups per recovery plan VMware Site Recovery Manager - RPO Values 5 min or higher * (hard-limit) VMware Site Recovery Manager - Maximum number of virtual machines per protection group VMware Site Recovery Manager - Maximum number of recovery plans

    * For information about Recovery Point Objective (RPO) lower than 15 minutes, see How the 5 Minute Recovery Point Objective Works in the vSphere Replication Administration guide .

    For other VMware-specific limits, use the VMware configuration maximum tool .

    Backup limits

    For a summary of Azure Backup support settings and limitations, see Azure Backup Support Matrices .

    Batch limits

    Resource Default limit Maximum limit Active jobs and job schedules per Batch account ( completed jobs have no limit) 100-300 1,000 2 Pools per Batch account 0-100 1 500 2 Private endpoint connections per Batch account

    1 For capacity management purposes, the default quotas for new Batch accounts in some regions and for some subscription types have been reduced from the above range of values. In some cases, these limits have been reduced to zero. When you create a new Batch account, check your quotas and request an appropriate core or service quota increase , if necessary. Alternatively, consider reusing Batch accounts that already have sufficient quota or user subscription pool allocation Batch accounts to maintain core and VM family quota across all Batch accounts on the subscription. Service quotas like active jobs or pools apply to each distinct Batch account even for user subscription pool allocation Batch accounts.

    2 To request an increase beyond this limit, contact Azure Support.

    Default limits vary depending on the type of subscription you use to create a Batch account. Cores quotas shown are for Batch accounts in Batch service mode. View the quotas in your Batch account .

    Classic deployment model limits

    If you use classic deployment model instead of the Azure Resource Manager deployment model, the following limits apply.

    Resource Default limit Maximum limit

    1 Extra small instances count as one vCPU toward the vCPU limit despite using a partial CPU core.

    2 The storage account limit includes both Standard and Premium storage accounts.

    Container Instances limits

    Resource Actual Limit

    1 To request a limit increase, create an Azure Support request . Free subscriptions including Azure Free Account and Azure for Students aren't eligible for limit or quota increases. If you have a free subscription, you can upgrade to a Pay-As-You-Go subscription.
    2 Default limit for Pay-As-You-Go subscription. Limit may differ for other category types.

    Container Registry limits

    The following table details the features and limits of the Basic, Standard, and Premium service tiers .

    Resource Basic Standard Premium

    1 Storage included in the daily rate for each tier. Additional storage may be used, up to the registry storage limit, at an additional daily rate per GiB. For rate information, see Azure Container Registry pricing . If you need storage beyond the registry storage limit, please contact Azure Support.

    2 ReadOps , WriteOps , and Bandwidth are minimum estimates. Azure Container Registry strives to improve performance as usage requires. Both resources, ACR, and the device must be in the same region to achieve a fast download speed.

    3 A docker pull translates to multiple read operations based on the number of layers in the image, plus the manifest retrieval.

    4 A docker push translates to multiple write operations, based on the number of layers that must be pushed. A docker push includes ReadOps to retrieve a manifest for an existing image.

    5 Individual actions of content/delete , content/read , content/write , metadata/read , metadata/write corresponds to the limit of Repositories per scope map.

    Content Delivery Network limits

    Resource Limit

    A Content Delivery Network subscription can contain one or more Content Delivery Network profiles. A Content Delivery Network profile can contain one or more Content Delivery Network endpoints. You might want to use multiple profiles to organize your Content Delivery Network endpoints by internet domain, web application, or some other criteria.

    Data Lake Analytics limits

    Azure Data Lake Analytics makes the complex task of managing distributed infrastructure and complex code easy. It dynamically provisions resources, and you can use it to do analytics on exabytes of data. When the job completes, it winds down resources automatically. You pay only for the processing power that was used. As you increase or decrease the size of data stored or the amount of compute used, you don't have to rewrite code. To raise the default limits for your subscription, contact support.

    Resource Limit Comments Maximum number of analytics units (AUs) per account Use any combination of up to a maximum of 250 AUs across 20 jobs. To increase this limit, contact Microsoft Support. Maximum script size for job submission Maximum number of Data Lake Analytics accounts per region per subscription To increase this limit, contact Microsoft Support.

    Data Factory limits

    Azure Data Factory is a multitenant service that has the following default limits in place to make sure customer subscriptions are protected from each other's workloads. To raise the limits up to the maximum for your subscription, contact support.

    Version 2

    Resource Default limit Maximum limit Total number of entities, such as pipelines, data sets, triggers, linked services, Private Endpoints, and integration runtimes, within a data factory 5,000 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Total CPU cores for Azure-SSIS Integration Runtimes under one subscription [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent pipeline runs per data factory that's shared among all pipelines in the factory 10,000 10,000 Concurrent External activity runs per subscription per Azure Integration Runtime region
    External activities are managed on integration runtime but execute on linked services, including Databricks, stored procedure, Web, and others. This limit does not apply to Self-hosted IR. 3,000 3,000 Concurrent Pipeline activity runs per subscription per Azure Integration Runtime region
    Pipeline activities execute on integration runtime, including Lookup, GetMetadata, and Delete. This limit does not apply to Self-hosted IR. 1,000 1,000 Concurrent authoring operations per subscription per Azure Integration Runtime region
    Including test connection, browse folder list and table list, preview data. This limit does not apply to Self-hosted IR. Concurrent Data Integration Units 1 consumption per subscription per Azure Integration Runtime region Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500 Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500 Concurrent Data Integration Units 1 consumption per subscription per Azure Integration Runtime region in managed virtual network 2,400 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Maximum activities per pipeline, which includes inner activities for containers Maximum number of linked integration runtimes that can be created against a single self-hosted integration runtime Maximum number of node that can be created against a single self-hosted integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ Maximum parameters per pipeline ForEach items 100,000 100,000 ForEach parallelism Maximum queued runs per pipeline Characters per expression 8,192 8,192 Minimum tumbling window trigger interval 5 min 15 min Maximum timeout for pipeline activity runs 7 days 7 days Bytes per object for pipeline objects 3 200 KB 200 KB Bytes per object for dataset and linked service objects 3 100 KB 2,000 KB Bytes per payload for each activity run 4 896 KB 896 KB Data Integration Units 1 per copy activity run Write API calls 1,200/h 1,200/h

    This limit is imposed by Azure Resource Manager, not Azure Data Factory. Read API calls 12,500/h 12,500/h

    This limit is imposed by Azure Resource Manager, not Azure Data Factory. Monitoring queries per minute 1,000 1,000 Maximum time of data flow debug session 8 hrs 8 hrs Concurrent number of data flows per integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flows per integration runtime in managed vNet [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flow debug sessions per user per factory Data Flow Azure IR TTL limit 4 hrs 4 hrs Meta Data Entity Size limit in a factory [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ .

    1 The data integration unit (DIU) is used in a cloud-to-cloud copy operation, learn more from Data integration units (version 2) . For information on billing, see Azure Data Factory pricing .

    2 Azure Integration Runtime is globally available to ensure data compliance, efficiency, and reduced network egress costs.

    Region group Regions Region group 1 Central US, East US, East US 2, North Europe, West Europe, West US, West US 2 Region group 2 Australia East, Australia Southeast, Brazil South, Central India, Japan East, North Central US, South Central US, Southeast Asia, West Central US Region group 3 Other regions

    If managed virtual network is enabled, the data integration unit (DIU) in all region groups are 2,400.

    3 Pipeline, data set, and linked service objects represent a logical grouping of your workload. Limits for these objects don't relate to the amount of data you can move and process with Azure Data Factory. Data Factory is designed to scale to handle petabytes of data.

    4 The payload for each activity run includes the activity configuration, the associated dataset(s) and linked service(s) configurations if any, and a small portion of system properties generated per activity type. Limit for this payload size doesn't relate to the amount of data you can move and process with Azure Data Factory. Learn about the symptoms and recommendation if you hit this limit.

    Version 1

    Resource Default limit Maximum limit Pipelines within a data factory 2,500 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Data sets within a data factory 5,000 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent slices per data set Bytes per object for pipeline objects 1 200 KB 200 KB Bytes per object for data set and linked service objects 1 100 KB 2,000 KB Azure HDInsight on-demand cluster cores within a subscription 2 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Cloud data movement units per copy activity run 3 Retry count for pipeline activity runs 1,000 MaxInt (32 bit)

    1 Pipeline, data set, and linked service objects represent a logical grouping of your workload. Limits for these objects don't relate to the amount of data you can move and process with Azure Data Factory. Data Factory is designed to scale to handle petabytes of data.

    2 On-demand HDInsight cores are allocated out of the subscription that contains the data factory. As a result, the previous limit is the Data Factory-enforced core limit for on-demand HDInsight cores. It's different from the core limit that's associated with your Azure subscription.

    3 The cloud data movement unit (DMU) for version 1 is used in a cloud-to-cloud copy operation, learn more from Cloud data movement units (version 1) . For information on billing, see Azure Data Factory pricing .

    Resource Default lower limit Minimum limit

    Web service call limits

    Azure Resource Manager has limits for API calls. You can make API calls at a rate within the Azure Resource Manager API limits .

    Data Lake Storage limits

    Azure Data Lake Storage Gen2 is not a dedicated service or storage account type. It is the latest release of capabilities that are dedicated to big data analytics. These capabilities are available in a general-purpose v2 or BlockBlobStorage storage account, and you can obtain them by enabling the Hierarchical namespace feature of the account. For scale targets, see these articles.

  • Scale targets for Blob storage .
  • Scale targets for standard storage accounts .
  • Azure Data Lake Storage Gen1 is a dedicated service. It's an enterprise-wide hyper-scale repository for big data analytic workloads. You can use Data Lake Storage Gen1 to capture data of any size, type, and ingestion speed in one single place for operational and exploratory analytics. There's no limit to the amount of data you can store in a Data Lake Storage Gen1 account.

    Resource Limit Comments Maximum number of Data Lake Storage Gen1 accounts, per subscription, per region To request an increase for this limit, contact support. Maximum number of access ACLs, per file or folder This is a hard limit. Use groups to manage access with fewer entries. Maximum number of default ACLs, per file or folder This is a hard limit. Use groups to manage access with fewer entries.

    Data Share limits

    Azure Data Share enables organizations to simply and securely share data with their customers and partners.

    Resource Limit

    When a given resource or operation doesn't have adjustable limits, the default and the maximum limits are the same. When the limit can be adjusted, the following table includes both the default limit and maximum limit. The limit can be raised above the default limit but not above the maximum limit. Limits can only be adjusted for the Standard SKU. Limit adjustment requests are not accepted for Free SKU. Limit adjustment requests are evaluated on a case-by-case basis and approvals are not guaranteed.

    If you want to raise the limit or quota above the default limit, open an online customer support request .

    This table provides the limits for the Device Update for IoT Hub resource in Azure Resource Manager:

    Resource Standard SKU Limit Free SKU Limit Adjustable? Number of active deployments per instance 50 (includes 1 reserved deployment for Cancels) 5 (includes 1 reserved deployment for Cancels) Number of total deployments per instance Number of update providers per instance Number of update names per provider per instance Number of update versions per update provider and name per instance Total number of updates per instance Maximum single update file size Maximum combined size of all files in a single import action Total data storage included per instance 100 GB

    Digital Twins limits

    Some areas of this service have adjustable limits, and others do not. This is represented in the tables below with the Adjustable? column. When the limit can be adjusted, the Adjustable? value is Yes .

    Functional limits

    The following table lists the functional limits of Azure Digital Twins.

    Capability Default limit Adjustable? Digital twins Number of digital twins that can be imported in a single Jobs API job 2,000,000 Digital twins Number of incoming relationships to a single twin 50,000 Digital twins Number of outgoing relationships from a single twin 50,000 Digital twins Total number of relationships in an Azure Digital Twins instance 20,000,000 Digital twins Number of relationships that can be imported in a single Jobs API job 10,000,000 Digital twins Maximum size (of JSON body in a PUT or PATCH request) of a single twin 32 KB Digital twins Maximum request payload size 32 KB Digital twins Maximum size of a string property value (UTF-8) Digital twins Maximum size of a property name Routing Number of endpoints for a single Azure Digital Twins instance Routing Number of routes for a single Azure Digital Twins instance Models Number of models within a single Azure Digital Twins instance 10,000 Models Number of models that can be imported in a single API call (not using the Jobs API ) Models Number of models that can be imported in a single Jobs API job 10,000 Models Maximum size (of JSON body in a PUT or PATCH request) of a single model Models Number of items returned in a single page Query Number of items returned in a single page Query Number of AND / OR expressions in a query Query Number of array items in an IN / NOT IN clause Query Number of characters in a query 8,000 Query Number of JOINS in a query

    Rate limits

    The following table reflects the rate limits of different APIs.

    Capability Default limit Adjustable? Digital Twins API Number of create/delete operations per second across all twins and relationships Digital Twins API Number of create/update/delete operations per second on a single twin or its incoming/outgoing relationships Digital Twins API Number of outstanding operations on a single twin or its incoming/outgoing relationships Query API Number of requests per second Query API Query Units per second 4,000 Event Routes API Number of requests per second

    Other limits

    Limits on data types and fields within DTDL documents for Azure Digital Twins models can be found within its spec documentation in GitHub: Digital Twins Definition Language (DTDL) - version 2 .

    Query latency details are described in Query language . Limitations of particular query language features can be found in the query reference documentation .

    Event Grid limits

  • The following limits listed in this article are per region.
  • See throughput units (TUs) for more information.
  • Namespace resource limits

    Azure Event Grid namespaces is available in public preview and enables MQTT messaging, and HTTP pull delivery. The following limits apply to namespace resources in Azure Event Grid.

    Limit description Limit MQTT inbound publish requests Up to 1,000 messages per second or 1 MB per second per TU (whichever comes first) MQTT outbound publish requests Up to 1,000 messages per second or 1 MB per second per TU Clients 10,000 clients per TU CA certificates Client groups Topic spaces Topic templates 10 per topic space Permission bindings Max message size 512 KB Topic size 256 B Topic alias 10 per connection New connect requests 200 requests per second per TU Subscribe and unsubscribe operations 200 requests per second per TU Total number of subscriptions per MQTT client session Maximum number of topic filters per MQTT SUBSCRIBE packet Maximum number of segments per topic filter Maximum number of concurrent connections allowed per namespace 10,000 per TU

    Events limits in namespace

    The following limits apply to events in Azure Event Grid namespace resource.

    Limit description Limit Event ingress Up to 1,000 events per second or 1 MB per second per TU (whichever comes first) Event egress Up to 2,000 events per second or 2 MB per second per TU Event duration period in topic 1 day Subscriptions per topic Connected clients per namespace (queue subscriptions) 1,000 Maximum event size Batch size Events per request 1,000

    Custom topic, system topic and partner topic resource limits

    The following limits apply to Azure Event Grid custom topic, system topic and partner topic resources.

    Limit description Limit Custom topics per Azure subscription 100
    When the limit is reached, you can consider a different region or consider using domains, which can support 100,000 topics. Event subscriptions per topic 500
    This limit can’t be increased. Publish rate for a custom or a partner topic (ingress) 5,000 events per second or 5 MB per second (whichever comes first) Event size 1 MB
    This limit can’t be increased. Number of incoming events per batch 5,000
    This limit can’t be increased Private endpoint connections per topic 64
    This limit can’t be increased IP Firewall rules per topic

    Domain resource limits

    The following limits apply to Azure Event Grid domain resource.

    Limit description Limit Publish rate for a domain (ingress) 5,000 events per second or 5 MB per second (whichever comes first) Private endpoint connections per domain IP Firewall rules per topic

    Event Hubs limits

    The following tables provide quotas and limits specific to Azure Event Hubs . For information about Event Hubs pricing, see Event Hubs pricing .

    Common limits for all tiers

    The following limits are common across all tiers.

    Limit Notes Value Size of a consumer group name Kafka protocol doesn't require the creation of a consumer group.

    Kafka: 256 characters

    AMQP: 50 characters

    Number of non-epoch receivers per consumer group Number of authorization rules per namespace Subsequent requests for authorization rule creation are rejected. Number of calls to the GetRuntimeInformation method 50 per second Number of virtual networks (VNet) Number of IP Config rules Maximum length of a schema group name Maximum length of a schema name Size in bytes per schema Number of properties per schema group Size in bytes per schema group property key Size in bytes per schema group property value

    Basic vs. standard vs. premium vs. dedicated tiers

    The following table shows limits that may be different for basic, standard, premium, and dedicated tiers.

  • In the table, CU is capacity unit , PU is processing unit , and TU is throughput unit .
  • You can configure TUs for a basic or standard tier namespace or PUs for a premium tier namespace.
  • When you create a dedicated cluster , 1 CU is assigned to the cluster. If you enable the Support Scaling option while creating the cluster, you'll be able to scale out by increasing CUs or scale in by decreasing CUs for the cluster yourself. For step-by-step instructions, see Scale dedicated cluster . For clusters that don't support the Support Scaling feature, submit a ticket To adjust CUs for the cluster.
  • 5,000 10000 per PU

    For example, if the namespace is assigned 3 PUs, the limit is 30000. 100, 000 per CU Maximum retention period of event data 1 day 7 days 90 days 90 days Maximum TUs or PUs or CUs 40 TUs 40 TUs 16 PUs 20 CUs Number of partitions per event hub 100 per event hub, but there's a limit of 200 per PU at the namespace level.

    For example, if a namespace is assigned 2 PUs, the limit for total number of partitions in all event hubs in the namespace is 2 * 200 = 400. 1024 per event hub
    2000 per CU Number of namespaces per subscription 1000 (50 per CU) Number of event hubs per namespace 100 per PU Capture Pay per hour Included Included Size of compacted event hub 1 GB per partition 250 GB per partition 250 GB per partition Size of the schema registry (namespace) in mega bytes Number of schema groups in a schema registry or namespace 1 - excluding the default group 100
    1 MB per schema 1000
    1 MB per schema Number of schema versions across all schema groups 10000 Throughput per unit Ingress - 1 MB/s or 1000 events per second
    Egress – 2 MB/s or 4096 events per second Ingress - 1 MB/s or 1000 events per second
    Egress – 2 MB/s or 4096 events per second No limits per PU * No limits per CU *

    * Depends on various factors such as resource allocation, number of partitions, storage, and so on.

    You can publish events individually or batched. The publication limit (according to SKU) applies regardless of whether it is a single event or a batch. Publishing events larger than the maximum threshold will be rejected.

    IoT Central limits

    IoT Central limits the number of applications you can deploy in a subscription to 100. If you need to increase this limit, contact Microsoft support . To learn more, see Azure IoT Central quota and limits .

    IoT Hub limits

    The following table lists the limits associated with the different service tiers S1, S2, S3, and F1. For information about the cost of each unit in each tier, see Azure IoT Hub pricing .

    Resource S1 Standard S2 Standard S3 Standard F1 Free

    If you anticipate using more than 200 units with an S1 or S2 tier hub or 10 units with an S3 tier hub, contact Microsoft Support.

    The following table lists the limits that apply to IoT Hub resources.

    Resource Limit Maximum size of device-to-cloud batch AMQP and HTTP: 256 KB for the entire batch
    MQTT: 256 KB for each message Maximum messages in device-to-cloud batch Maximum size of cloud-to-device message 64 KB Maximum TTL for cloud-to-device messages 2 days Maximum delivery count for cloud-to-device
    messages Maximum cloud-to-device queue depth per device Maximum delivery count for feedback messages
    in response to a cloud-to-device message Maximum TTL for feedback messages in
    response to a cloud-to-device message 2 days Maximum size of device twin 8 KB for tags section, and 32 KB for desired and reported properties sections each Maximum length of device twin string key Maximum length of device twin string value Maximum depth of object in device twin Maximum size of direct method payload 128 KB Job history maximum retention 30 days Maximum concurrent jobs 10 (for S3), 5 for (S2), 1 (for S1) Maximum additional endpoints (beyond built-in endpoints ) 10 (for S1, S2, and S3) Maximum message routing rules 100 (for S1, S2, and S3) Maximum number of concurrently connected device streams 50 (for S1, S2, S3, and F1 only) Maximum device stream data transfer 300 MB per day (for S1, S2, S3, and F1 only)

    If you need more than 50 paid IoT hubs in an Azure subscription, contact Microsoft Support.

    Currently, the total number of devices plus modules that can be registered to a single IoT hub is capped at 1,000,000. If you want to increase this limit, contact Microsoft Support .

    IoT Hub throttles requests when the following quotas are exceeded.

    Throttle Per-hub value Identity registry operations
    (create, retrieve, list, update, and delete),
    individual or bulk import/export 83.33/sec/unit (5,000/min/unit) (for S3).
    1.67/sec/unit (100/min/unit) (for S1 and S2). Device connections 6,000/sec/unit (for S3), 120/sec/unit (for S2), 12/sec/unit (for S1).
    Minimum of 100/sec. Device-to-cloud sends 6,000/sec/unit (for S3), 120/sec/unit (for S2), 12/sec/unit (for S1).
    Minimum of 100/sec. Cloud-to-device sends 83.33/sec/unit (5,000/min/unit) (for S3), 1.67/sec/unit (100/min/unit) (for S1 and S2). Cloud-to-device receives 833.33/sec/unit (50,000/min/unit) (for S3), 16.67/sec/unit (1,000/min/unit) (for S1 and S2). File upload operations 83.33 file upload initiations/sec/unit (5,000/min/unit) (for S3), 1.67 file upload initiations/sec/unit (100/min/unit) (for S1 and S2).
    10 concurrent file uploads per device. Direct methods 24 MB/sec/unit (for S3), 480 KB/sec/unit (for S2), 160 KB/sec/unit (for S1).
    Based on 8-KB throttling meter size. Device twin reads 500/sec/unit (for S3), Maximum of 100/sec or 10/sec/unit (for S2), 100/sec (for S1) Device twin updates 250/sec/unit (for S3), Maximum of 50/sec or 5/sec/unit (for S2), 50/sec (for S1) Jobs operations
    (create, update, list, and delete) 83.33/sec/unit (5,000/min/unit) (for S3), 1.67/sec/unit (100/min/unit) (for S2), 1.67/sec/unit (100/min/unit) (for S1). Jobs per-device operation throughput 50/sec/unit (for S3), maximum of 10/sec or 1/sec/unit (for S2), 10/sec (for S1). Device stream initiation rate 5 new streams/sec (for S1, S2, S3, and F1 only).

    IoT Hub Device Provisioning Service limits

    Some areas of this service have adjustable limits. This is represented in the tables below with the Adjustable? column. When the limit can be adjusted, the Adjustable? value is Yes .

    The actual value to which a limit can be adjusted may vary based on each customer’s deployment. Multiple instances of DPS may be required for very large deployments.

    If your business requires raising an adjustable limit or quota above the default limit, you can submit a request for additional resources by opening a support ticket . Requesting an increase does not guarantee that it will be granted, as it needs to be reviewed on a case-by-case basis. Please contact Microsoft support as early as possible during your implementation, to be able to determine if your request could be approved and plan accordingly.

    The following table lists the limits that apply to Azure IoT Hub Device Provisioning Service resources.

    Resource Limit Adjustable?

    If the hard limit on symmetric key enrollment groups is a blocking issue, it is recommended to use individual enrollments as a workaround.

    The Device Provisioning Service has the following rate limits.

    Per-unit value Adjustable?

    Key Vault limits

    Azure Key Vault service supports two resource types: Vaults and Managed HSMs. The following two sections describe the service limits for each of them respectively.

    Resource type: vault

    This section describes service limits for resource type vaults .

    Key transactions (maximum transactions allowed in 10 seconds, per vault per region 1 ):

    Key type HSM key
    CREATE key HSM key
    All other transactions Software key
    CREATE key Software key
    All other transactions

    In the previous table, we see that for RSA 2,048-bit software keys, 4,000 GET transactions per 10 seconds are allowed. For RSA 2,048-bit HSM-keys, 2,000 GET transactions per 10 seconds are allowed.

    The throttling thresholds are weighted, and enforcement is on their sum. For example, as shown in the previous table, when you perform GET operations on RSA HSM-keys, it's eight times more expensive to use 4,096-bit keys compared to 2,048-bit keys. That's because 2,000/250 = 8.

    In a given 10-second interval, an Azure Key Vault client can do only one of the following operations before it encounters a 429 throttling HTTP status code:

  • 4,000 RSA 2,048-bit software-key GET transactions
  • 2,000 RSA 2,048-bit HSM-key GET transactions
  • 250 RSA 4,096-bit HSM-key GET transactions
  • 248 RSA 4,096-bit HSM-key GET transactions and 16 RSA 2,048-bit HSM-key GET transactions
  • Secrets, managed storage account keys, and vault transactions:

    Transactions type Maximum transactions allowed in 10 seconds, per vault per region 1

    For information on how to handle throttling when these limits are exceeded, see Azure Key Vault throttling guidance .

    1 A subscription-wide limit for all transaction types is five times per key vault limit.

    Backup keys, secrets, certificates

    When you back up a key vault object, such as a secret, key, or certificate, the backup operation will download the object as an encrypted blob. This blob cannot be decrypted outside of Azure. To get usable data from this blob, you must restore the blob into a key vault within the same Azure subscription and Azure geography

    Transactions type Maximum key vault object versions allowed

    Attempting to backup a key, secret, or certificate object with more versions than above limit will result in an error. It is not possible to delete previous versions of a key, secret, or certificate.

    Limits on count of keys, secrets and certificates:

    Key Vault does not restrict the number of keys, secrets or certificates that can be stored in a vault. The transaction limits on the vault should be taken into account to ensure that operations are not throttled.

    Key Vault does not restrict the number of versions on a secret, key or certificate, but storing a large number of versions (500+) can impact the performance of backup operations. See Azure Key Vault Backup .

    Resource type: Managed HSM

    This section describes service limits for resource type managed HSM .

    Object limits

    Limits All RBAC operations
    (includes all CRUD operations for role definitions and role assignments) Full HSM Backup/Restore
    (only one concurrent backup or restore operation per HSM instance supported)

    Transaction limits for cryptographic operations (number of operations per second per HSM instance)

  • Each Managed HSM instance constitutes three load balanced HSM partitions. The throughput limits are a function of underlying hardware capacity allocated for each partition. The tables below show maximum throughput with at least one partition available. Actual throughput may be up to 3x higher if all three partitions are available.
  • Throughput limits noted assume that one single key is being used to achieve maximum throughput. For example, if a single RSA-2048 key is used the maximum throughput will be 1100 sign operations. If you use 1100 different keys with one transaction per second each, they will not be able to achieve the same throughput.
  • RSA key operations (number of operations per second per HSM instance)
    Operation 2048-bit 3072-bit 4096-bit
    AES key operations (number of operations per second per HSM instance)
  • Encrypt and Decrypt operations assume a 4KB packet size.
  • Throughput limits for Encrypt/Decrypt apply to AES-CBC and AES-GCM algorithms.
  • Throughput limits for Wrap/Unwrap apply to AES-KW algorithm.
  • Managed identity limits

  • Each managed identity counts towards the object quota limit in an Azure AD tenant as described in Azure AD service limits and restrictions .

  • The rate at which managed identities can be created have the following limits:

  • Per Azure AD Tenant per Azure region: 400 create operations per 20 seconds.
  • Per Azure Subscription per Azure region : 80 create operations per 20 seconds.
  • The rate at which a user-assigned managed identity can be assigned with an Azure resource :

  • Per Azure AD Tenant per Azure region: 400 assignment operations per 20 seconds.
  • Per Azure Subscription per Azure region : 300 assignment operations per 20 seconds.
  • Media Services limits

    For resources that aren't fixed, open a support ticket to ask for an increase in the quotas. Don't create additional Azure Media Services accounts in an attempt to obtain higher limits.

    Account limits

    Resource Default Limit File size In some scenarios, there is a limit on the maximum file size supported for processing in Media Services. (1) Storage accounts 100 (2) (fixed)

    1 The maximum size supported for a single blob is currently up to 5 TB in Azure Blob Storage. Additional limits apply in Media Services based on the VM sizes that are used by the service. The size limit applies to the files that you upload and also the files that get generated as a result of Media Services processing (encoding or analyzing). If your source file is larger than 260-GB, your Job will likely fail.

    2 The storage accounts must be from the same Azure subscription.

    Jobs (encoding & analyzing) limits

    Resource Default Limit

    3 This number includes queued, finished, active, and canceled Jobs. It does not include deleted Jobs.

    Any Job record in your account older than 90 days will be automatically deleted, even if the total number of records is below the maximum quota.

    Live streaming limits

    Resource Default Limit

    4 For detailed information about Live Event limitations, see Live Event types comparison and limitations .

    5 Live Outputs start on creation and stop when deleted.

    Packaging & delivery limits

    Resource Default Limit

    6 When using a custom Streaming Policy , you should design a limited set of such policies for your Media Service account, and re-use them for your StreamingLocators whenever the same encryption options and protocols are needed. You should not be creating a new Streaming Policy for each Streaming Locator.

    7 Streaming Locators are not designed for managing per-user access control. To give different access rights to individual users, use Digital Rights Management (DRM) solutions.

    Protection limits

    Resource Default Limit Licenses per month for each of the DRM types on Media Services key delivery service per account 1,000,000

    Support ticket

    For resources that are not fixed, you may ask for the quotas to be raised, by opening a support ticket . Include detailed information in the request on the desired quota changes, use-case scenarios, and regions required.
    Do not create additional Azure Media Services accounts in an attempt to obtain higher limits.

    Media Services v2 (legacy)

    For limits specific to Media Services v2 (legacy), see Media Services v2 (legacy)

    Mobile Services limits

    Basic Standard Push notifications Azure Notification Hubs Free tier included, up to 1 million pushes Notification Hubs Basic tier included, up to 10 million pushes Notification Hubs Standard tier included, up to 10 million pushes Real-time messaging/
    Web Sockets Limited 350 per mobile service Unlimited Offline synchronizations Limited Included Included Scheduled jobs Limited Included Included Azure SQL Database (required)
    Standard rates apply for additional capacity 20 MB included 20 MB included 20 MB included CPU capacity 60 minutes per day Unlimited Unlimited Outbound data transfer 165 MB per day (daily rollover) Included Included

    For more information on limits and pricing, see Azure Mobile Services pricing .

    Multi-Factor Authentication limits

    Resource Default limit Maximum limit

    Networking limits

    Networking limits - Azure Resource Manager

    The following limits apply only for networking resources managed through Azure Resource Manager per region per subscription. Learn how to view your current resource usage against your subscription limits .

    We have increased all default limits to their maximum limits. If there's no maximum limit column, the resource doesn't have adjustable limits. If you had these limits manually increased by support in the past and are currently seeing limits lower than what is listed in the following tables, open an online customer support request at no charge

    Application security groups that can be specified within all security rules of a network security group User-defined route tables User-defined routes per route table Point-to-site root certificates per Azure VPN Gateway Point-to-site revoked client certificates per Azure VPN Gateway Virtual network TAPs Network interface TAP configurations per virtual network TAP

    Public IP address limits

    Resource Default limit Maximum limit Public IP Prefixes limited by number of Standard Public IPs in a subscription Contact support. Public IP prefix length Contact support.

    1 Default limits for Public IP addresses vary by offer category type, such as Free Trial, Pay-As-You-Go, CSP. For example, the default for Enterprise Agreement subscriptions is 1000.

    2 Public IP addresses limit refers to the total amount of Public IP addresses, including Basic and Standard.

    Load balancer limits

    The following limits apply only for networking resources managed through Azure Resource Manager per region per subscription. Learn how to view your current resource usage against your subscription limits .

    Standard Load Balancer

    Resource Limit

    1 Backend IP configurations are aggregated across all load balancer rules including load balancing, inbound NAT, and outbound rules. Each rule a backend pool instance is configured to counts as one configuration.

    Load Balancer doesn't apply any throughput limits. However, throughput limits for virtual machines and virtual networks still apply. For more information, see Virtual machine network bandwidth .

    Gateway Load Balancer

    Resource Limit Resources chained per Load Balancer (LB frontend configurations or VM NIC IP configurations combined)

    All limits for Standard Load Balancer also apply to Gateway Load Balancer.

    Basic Load Balancer

    Resource Limit

    3 The limit for a single discrete resource in a backend pool (standalone virtual machine, availability set, or virtual machine scale-set placement group) is to have up to 250 Frontend IP configurations across a single Basic Public Load Balancer and Basic Internal Load Balancer.

    The following limits apply only for networking resources managed through the classic deployment model per subscription. Learn how to view your current resource usage against your subscription limits .

    Resource Default limit Maximum limit Concurrent TCP or UDP flows per NIC of a virtual machine or role instance 500,000, up to 1,000,000 for two or more NICs. 500,000, up to 1,000,000 for two or more NICs. Network Security Groups (NSGs) NSG rules per NSG 1,000 User-defined route tables User-defined routes per route table Public IP addresses (dynamic) Reserved public IP addresses Public IP per deployment Contact support Private IP (internal load balancing) per deployment Endpoint access control lists (ACLs)

    Application Gateway limits

    The following table applies to v1, v2, Standard, and WAF SKUs unless otherwise stated.

    Resource Limit HTTP listeners 200 1 Limited to 100 active listeners that are routing traffic. Active listeners = total number of listeners - listeners not active.
    If a default configuration inside a routing rule is set to route traffic (for example, it has a listener, a backend pool, and HTTP settings) then that also counts as a listener. For more information, see Frequently asked questions about Application Gateway . HTTP load-balancing rules 400 1 Backend HTTP settings 100 1 Instances per gateway V1 SKU - 32
    V2 SKU - 125 SSL certificates 100 1 1 per HTTP listener Maximum SSL certificate size V1 SKU - 10 KB
    V2 SKU - 16 KB Maximum trusted client CA certificate size 25 KB 25 KB is the maximum aggregated size of root and intermediate certificates contained in an uploaded pem or cer file. Maximum trusted client CA certificate chains Authentication certificates Trusted root certificates Request timeout minimum 1 second Request timeout maximum to private backend 24 hours Request timeout maximum to external backend 4 minutes Number of sites 100 1 1 per HTTP listener URL maps per listener Host names per listener Maximum path-based rules per URL map Redirect configurations 100 1 Number of rewrite rule sets Number of Header or URL configuration per rewrite rule set Number of conditions per rewrite rule set Concurrent WebSocket connections Medium gateways 20k 2
    Large gateways 50k 2 Maximum URL length 32 KB Maximum header size 32 KB Maximum header field size for HTTP/2 Maximum header size for HTTP/2 16 KB Maximum file upload size (Standard SKU) V2 - 4 GB
    V1 - 2 GB Maximum file upload size (WAF SKU) V1 Medium - 100 MB
    V1 Large - 500 MB
    V2 - 750 MB
    V2 (with CRS 3.2 or newer) - 4 GB 3 WAF body size limit (without files) V1 or V2 (with CRS 3.1 and older) - 128 KB
    V2 (with CRS 3.2 or newer) - 2 MB 3 Maximum Private Link Configurations 1 for public IP, 1 for private IP Maximum Private Link IP Configurations Maximum WAF custom rules WAF IP address ranges per match condition 540
    600 - with CRS 3.2 or newer Maximum WAF exclusions per Application Gateway 40
    200 - with CRS 3.2 or newer WAF string match values per match condition

    1 The number of resources listed in the table applies to standard Application Gateway SKUs and WAF-enabled SKUs running CRS 3.2 or higher. For WAF-enabled SKUs running CRS 3.1 or lower, the supported number is 40. For more information, see WAF engine .

    2 Limit is per Application Gateway instance not per Application Gateway resource.

    3 Must define the value via WAF Policy for Application Gateway.

    Azure Bastion limits

    An instance is an optimized Azure VM that is created when you configure Azure Bastion. When you configure Azure Bastion using the Basic SKU, 2 instances are created. If you use the Standard SKU, you can specify the number of instances between 2-50.

    Workload Type* Session Limit per Instance**

    *These workload types are defined here: Remote Desktop workloads
    **These limits are based on RDP performance tests for Azure Bastion. The numbers may vary due to other on-going RDP sessions or other on-going SSH sessions.

    Azure DNS limits

    Public DNS zones

    Resource Limit Number of private DNS zones a virtual network can get linked to with autoregistration enabled Number of private DNS zones a virtual network can get linked

    Azure-provided DNS resolver

    Resource Limit

    1 These limits are applied to every individual virtual machine and not at the virtual network level. DNS queries exceeding these limits are dropped.

    DNS private resolver 1

    Resource Limit

    1 Different limits might be enforced by the Azure portal until the portal is updated. Use PowerShell to provision elements up to the most current limits.

    Azure Firewall limits

    Resource Limit Max Data throughput 100 Gbps for Premium, 30 Gbps for Standard, 250 Mbps for Basic (preview) SKU

    For more information, see Azure Firewall performance . Rule limits 20,000 unique source/destinations in network rules

    Unique source/destinations in network = sum of (unique source addresses * unique destination addresses for each rule)

    You can track the Firewall Policy network rule count in the policy analytics under the Insights tab. As a proxy, you can also monitor your Firewall Latency Probe metrics to ensure it stays within 20 ms even during peak hours. Total size of rules within a single Rule Collection Group 1 MB for Firewall policies created before July 2022
    2 MB for Firewall policies created after July 2022 Number of Rule Collection Groups in a firewall policy 50 for Firewall policies created before July 2022
    60 for Firewall policies created after July 2022 Maximum DNAT rules (Maximum external destinations) 250 maximum [number of firewall public IP addresses + unique destinations (destination address, port, and protocol)]

    The DNAT limitation is due to the underlying platform.

    For example, you can configure 500 UDP rules to the same destination IP address and port (one unique destination), while 500 rules to the same IP address but to 500 different ports exceeds the limit (500 unique destinations). Minimum AzureFirewallSubnet size Port range in network and application rules 1 - 65535 Public IP addresses 250 maximum. All public IP addresses can be used in DNAT rules and they all contribute to available SNAT ports. IP addresses in IP Groups Maximum of 100 IP Groups per firewall.
    Maximum 5000 individual IP addresses or IP prefixes per each IP Group. Route table By default, AzureFirewallSubnet has a 0.0.0.0/0 route with the NextHopType value set to Internet .

    Azure Firewall must have direct Internet connectivity. If your AzureFirewallSubnet learns a default route to your on-premises network via BGP, you must override that with a 0.0.0.0/0 UDR with the NextHopType value set as Internet to maintain direct Internet connectivity. By default, Azure Firewall doesn't support forced tunneling to an on-premises network.

    However, if your configuration requires forced tunneling to an on-premises network, Microsoft will support it on a case by case basis. Contact Support so that we can review your case. If accepted, we'll allow your subscription and ensure the required firewall Internet connectivity is maintained. FQDNs in network rules For good performance, do not exceed more than 1000 FQDNs across all network rules per firewall. TLS inspection timeout 120 seconds

    Azure Front Door (classic) limits

  • In addition to the following limits, there are composite limit on the number of routing rules, front-end domains, protocols, and paths .
  • Azure Front Door Standard and Premium service limits

  • Maximum of 500 total Standard and Premium profiles per subscription.
  • In addition to the following limits, there are composite limit on the number of routes, domains, protocols, and paths .
  • Resources with * are new limits for Azure Front Door Standard and Premium.

  • Front Door has an idle TCP connection timeout of 61 seconds.
  • Front Door to application back-end
  • After the HTTP request gets forwarded to the back end, Azure Front Door waits for 60 seconds (Standard and Premium) or 30 seconds (classic) for the first packet from the back end. Then it returns a 503 error to the client, or 504 for a cached request. You can configure this value using the originResponseTimeoutSeconds field in Azure Front Door Standard and Premium API, or the sendRecvTimeoutSeconds field in the Azure Front Door (classic) API.

  • After the back end receives the first packet, if the origin pauses for any reason in the middle of the response body beyond the originResponseTimeoutSeconds or sendRecvTimeoutSeconds, the response will be canceled.

  • Front Door takes advantage of HTTP keep-alive to keep connections open for reuse from previous requests. These connections have an idle timeout of 90 seconds. Azure Front Door would disconnect idle connections after reaching the 90-second idle timeout. This timeout value can't be configured.

    Upload and download data limit

    Other limits

  • Maximum URL size - 8,192 bytes - Specifies maximum length of the raw URL (scheme + hostname + port + path + query string of the URL)
  • Maximum Query String size - 4,096 bytes - Specifies the maximum length of the query string, in bytes.
  • Maximum HTTP response header size from health probe URL - 4,096 bytes - Specified the maximum length of all the response headers of health probes.
  • Maximum rules engine action header value character: 640 characters.
  • Maximum rules engine condition header value character: 256 characters.
  • Maximum ETag header size: 128 bytes
  • Maximum endpoint name for Standard and Premium: 46 characters.
  • For more information about limits that apply to Rules Engine configurations, see rules engine terminology

    Azure Network Watcher limits

    Resource Limit Network Watcher instances per region per subscription 1 (One instance in a region to enable access to the service in the region) Connection monitors per region per subscription Maximum test groups per a connection monitor Maximum sources and destinations per a connection monitor Maximum test configurations per a connection monitor Packet capture sessions per region per subscription 10,000 (Number of sessions only, not saved captures) VPN troubleshoot operations per subscription 1 (Number of operations at one time)

    Azure Route Server limits

    Resource Limit Number of VMs in the virtual network (including peered virtual networks) that Azure Route Server can support 2 4,000

    1 If your NVA advertises more routes than the limit, the BGP session gets dropped.

    2 The number of VMs that Azure Route Server can support isn’t a hard limit and it depends on the availability and performance of the underlying infrastructure.

    The total number of routes advertised from VNet address space and Route Server towards ExpressRoute circuit, when Branch-to-branch enabled, must not exceed 1,000. For more information, see Route advertisement limits of ExpressRoute.

    ExpressRoute limits

    Resource Limit Maximum number of circuits in the same peering location linked to the same virtual network Maximum number of circuits in different peering locations linked to the same virtual network Standard / ERGw1Az - 4 High Perf / ERGw2Az - 8 Ultra Performance / ErGw3Az - 16 Maximum number of IPs for ExpressRoute provider circuit with Fastpath 25,000 Maximum number of IPs for ExpressRoute Direct 10 Gbps with Fastpath 100,000 Maximum number of IPs for ExpressRoute Direct 100 Gbps with Fastpath 200,000 Maximum number of flows for ExpressRoute Traffic Collector 30,000

    Route advertisement limits

    Resource Local / Standard SKU Premium SKU Maximum number of IPv4 routes advertised from Azure private peering from the VNet address space 1,000 1,000 Maximum number of IPv6 routes advertised from Azure private peering from the VNet address space 1,000 1,000 Maximum number of IPv4 routes advertised to Microsoft peering Maximum number of IPv6 routes advertised to Microsoft peering Circuit size Local / Standard SKU Premium SKU

    Global Reach connections count against the limit of virtual network connections per ExpressRoute Circuit. For example, a 10 Gbps Premium Circuit would allow for 5 Global Reach connections and 95 connections to the ExpressRoute Gateways or 95 Global Reach connections and 5 connections to the ExpressRoute Gateways or any other combination up to the limit of 100 connections for the circuit.

    ExpressRoute gateway performance limits

    The following table shows the gateway types and the estimated performance scale numbers. These numbers are derived from the following testing conditions and represent the max support limits. Actual performance may vary, depending on how closely traffic replicates these testing conditions.

    Testing conditions

    Gateway SKU Traffic sent from on-premises Number of routes advertised by gateway Number of routes learned by gateway

    Important

  • Application performance depends on multiple factors, such as end-to-end latency, and the number of traffic flows the application opens. The numbers in the table represent the upper limit that the application can theoretically achieve in an ideal environment. Additionally, Microsoft performs routine host and OS maintenance on the ExpressRoute Virtual Network Gateway, to maintain reliability of the service. During a maintenance period, the control plane and data path capacity of the gateway is reduced.
  • During a maintenance period, you may experience intermittent connectivity issues to private endpoint resources.
  • NAT Gateway limits

    The following limits apply to NAT gateway resources managed through Azure Resource Manager per region per subscription. Learn how to view your current resource usage against your subscription limits .

    Resource Limit Connections to same destination endpoint 50,000 connections to the same destination per public IP Connections total 2M connections per NAT gateway

    The following limits apply to Azure private link:

    Resource Limit Number of IP Configurations on a private link service    8 (This number is for the NAT IP addresses used per PLS) Number of private endpoints on the same private link service  Number of subscriptions allowed in visibility setting on private link service  Number of subscriptions allowed in auto-approval setting on private link service  Number of private endpoints per key vault Number of key vaults with private endpoints per subscription Number of private DNS zone groups that can be linked to a private endpoint Number of DNS zones in each group

    Traffic Manager limits

    Resource Limit

    Microsoft Purview limits

    The latest values for Microsoft Purview quotas can be found in the Microsoft Purview quota page .

    Microsoft Sentinel limits

    The following limit applies to analytics rules in Microsoft Sentinel.

    Description Limit Dependency Alerts per rule
    Applicable when Event grouping is set to Trigger an alert for each event 150 alerts Alerts per rule for NRT rules 30 alerts

    Incident limits

    The following limits apply to incidents in Microsoft Sentinel.

    Description Limit Dependency Total count of these assets per machine learning workspace: datasets, runs, models, and artifacts 10 million assets Azure Machine Learning Default limit for total compute clusters per region. Limit is shared between a training cluster and a compute instance. A compute instance is considered a single-node cluster for quota purposes. 200 compute clusters per region Azure Machine Learning Storage accounts per region per subscription 250 storage accounts Azure Storage Maximum size of a file share by default Azure Storage Maximum size of a file share with large file share feature enabled 100 TB Azure Storage Maximum throughput (ingress + egress) for a single file share by default 60 MB/sec Azure Storage Maximum throughput (ingress + egress) for a single file share with large file share feature enabled 300 MB/sec Azure Storage

    Repositories limits

    The following limits apply to repositories in Microsoft Sentinel.

    Description Limit Dependency Indicators per call that use Graph security API 100 indicators Microsoft Graph security API CSV indicator file import size JSON indicator file import size 250MB

    TI upload indicators API limits

    The following limit applies to the threat intelligence upload indicators API in Microsoft Sentinel.

    Description Limit Dependency Lowest retention configuration in days for the IdentityInfo table. All data stored on the IdentityInfo table in Log Analytics is refreshed every 14 days. 14 days Log Analytics

    Watchlist limits

    The following limits apply to watchlists in Microsoft Sentinel. The limits are related to the dependencies on other services used by watchlists.

    Description Limit Dependency Total number of active watchlist items per workspace. When the max count is reached, delete some existing items to add a new watchlist. 10 million active watchlist items Log Analytics Total rate of change of all watchlist items per workspace 1% rate of change per month Log Analytics Number of large watchlist uploads per workspace at a time One large watchlist Azure Cosmos DB Number of large watchlist deletions per workspace at a time One large watchlist Azure Cosmos DB

    Workbook limits

    Workbook limits for Sentinel are the same result limits found in Azure Monitor. For more information, see Workbooks result limits .

    Service Bus limits

    The following table lists quota information specific to Azure Service Bus messaging. For information about pricing and other quotas for Service Bus, see Service Bus pricing .

    Quota name Scope Value Notes Namespace 1000 (default and maximum) Subsequent requests for additional namespaces are rejected. Queue or topic size Entity

    1, 2, 3, 4 GB or 5 GB

    In the Premium SKU, and the Standard SKU with partitioning enabled, the maximum queue or topic size is 80 GB.

    Total size limit for a premium namespace is 1 TB per messaging unit . Total size of all entities in a namespace can't exceed this limit.

    Defined upon creation/updation of the queue or topic.

    Subsequent incoming messages are rejected, and an exception is received by the calling code.

    Currently, a large message (size > 1 MB) sent to a queue is counted twice. And, a large message (size > 1 MB) sent to a topic is counted X + 1 times, where X is the number of subscriptions to the topic.

    Number of concurrent connections on a namespace Namespace Net Messaging: 1,000.

    AMQP: 5,000. Subsequent requests for additional connections are rejected, and an exception is received by the calling code. REST operations don't count toward concurrent TCP connections. Number of concurrent receive requests on a queue, topic, or subscription entity Entity 5,000 Subsequent receive requests are rejected, and an exception is received by the calling code. This quota applies to the combined number of concurrent receive operations across all subscriptions on a topic. Number of topics or queues per namespace Namespace 10,000 for the Basic or Standard tier. The total number of topics and queues in a namespace must be less than or equal to 10,000.

    For the Premium tier, 1,000 per messaging unit (MU). Subsequent requests for creation of a new topic or queue on the namespace are rejected. As a result, if configured through the Azure portal , an error message is generated. If called from the management API, an exception is received by the calling code. Number of partitioned topics or queues per namespace Namespace Basic and Standard tiers: 100. Each partitioned queue or topic counts toward the quota of 1,000 entities per namespace. Subsequent requests for creation of a new partitioned topic or queue in the namespace are rejected. As a result, if configured through the Azure portal , an error message is generated. If called from the management API, the exception QuotaExceededException is received by the calling code.

    If you want to have more partitioned entities in a basic or a standard tier namespace, create additional namespaces.

    Maximum size of any messaging entity path: queue or topic Entity 260 characters. Maximum size of any messaging entity name: namespace, subscription, or subscription rule Entity 50 characters. Maximum size of a message ID Entity Maximum size of a message session ID Entity Message size for a queue, topic, or subscription entity Entity 256 KB for Standard tier
    100 MB for Premium tier .

    The message size includes the size of properties (system and user) and the size of payload. The size of system properties varies depending on your scenario. Incoming messages that exceed these quotas are rejected, and an exception is received by the calling code. Message property size for a queue, topic, or subscription entity Entity

    Maximum message property size for each property is 32 KB.

    Cumulative size of all properties can't exceed 64 KB. This limit applies to the entire header of the brokered message, which has both user properties and system properties, such as sequence number, label, and message ID.

    Maximum number of header properties in property bag: byte/int.MaxValue .

    The exception SerializationException is generated. Number of subscriptions per topic Entity 2,000 per-topic for the Standard tier and Premium tier. Subsequent requests for creating additional subscriptions for the topic are rejected. As a result, if configured through the portal, an error message is shown. If called from the management API, an exception is received by the calling code. Number of SQL filters per topic Entity 2,000 Subsequent requests for creation of additional filters on the topic are rejected, and an exception is received by the calling code. Number of correlation filters per topic Entity 100,000 Subsequent requests for creation of additional filters on the topic are rejected, and an exception is received by the calling code. Size of SQL filters or actions Namespace Maximum length of filter condition string: 1,024 (1 K).

    Maximum length of rule action string: 1,024 (1 K).

    Maximum number of expressions per rule action: 32. Subsequent requests for creation of additional filters are rejected, and an exception is received by the calling code. Number of shared access authorization rules per namespace, queue, or topic Entity, namespace Maximum number of rules per entity type: 12.

    Rules that are configured on a Service Bus namespace apply to all types: queues, topics. Subsequent requests for creation of additional rules are rejected, and an exception is received by the calling code. Number of messages per transaction Transaction 100

    For both Send() and SendAsync() operations. Additional incoming messages are rejected, and an exception stating "Can't send more than 100 messages in a single transaction" is received by the calling code. Number of virtual network and IP filter rules Namespace

    SQL Database limits

    For SQL Database limits, see SQL Database resource limits for single databases , SQL Database resource limits for elastic pools and pooled databases , and SQL Database resource limits for SQL Managed Instance .

    The maximum number of private endpoints per Azure SQL Database logical server is 250.

    Azure Synapse Analytics limits

    Azure Synapse Analytics has the following default limits to ensure customer's subscriptions are protected from each other's workloads. To raise the limits to the maximum for your subscription, contact support.

    Azure Synapse limits for workspaces

    For Pay-As-You-Go, Free Trial, Azure Pass, and Azure for Students subscription offer types:

    Resource Default limit Maximum limit

    For additional limits for Spark pools, see Concurrency and API rate limits for Apache Spark pools in Azure Synapse Analytics .

    Azure Synapse limits for pipelines

    Resource Default limit Maximum limit Total number of entities, such as pipelines, data sets, triggers, linked services, Private Endpoints, and integration runtimes, within a workspace 5,000 [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Total CPU cores for Azure-SSIS Integration Runtimes under one workspace [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent pipeline runs per workspace that's shared among all pipelines in the workspace 10,000 10,000 Concurrent External activity runs per workspace per Azure Integration Runtime region
    External activities are managed on integration runtime but execute on linked services, including Databricks, stored procedure, HDInsight, Web, and others. This limit does not apply to Self-hosted IR. 3,000 3,000 Concurrent Pipeline activity runs per workspace per Azure Integration Runtime region
    Pipeline activities execute on integration runtime, including Lookup, GetMetadata, and Delete. This limit does not apply to Self-hosted IR. 1,000 1,000 Concurrent authoring operations per workspace per Azure Integration Runtime region
    Including test connection, browse folder list and table list, preview data. This limit does not apply to Self-hosted IR. Concurrent Data Integration Units 1 consumption per workspace per Azure Integration Runtime region Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500
    Managed virtual network 2 : 2,400 Region group 1 2 : 6,000
    Region group 2 2 : 3,000
    Region group 3 2 : 1,500
    Managed virtual network: [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Maximum activities per pipeline, which includes inner activities for containers Maximum number of linked integration runtimes that can be created against a single self-hosted integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Maximum parameters per pipeline ForEach items 100,000 100,000 ForEach parallelism Maximum queued runs per pipeline Characters per expression 8,192 8,192 Minimum tumbling window trigger interval 5 min 15 min Maximum timeout for pipeline activity runs 7 days 7 days Bytes per object for pipeline objects 3 200 KB 200 KB Bytes per object for dataset and linked service objects 3 100 KB 2,000 KB Bytes per payload for each activity run 4 896 KB 896 KB Data Integration Units 1 per copy activity run Write API calls 1,200/h 1,200/h

    This limit is imposed by Azure Resource Manager, not Azure Synapse Analytics. Read API calls 12,500/h 12,500/h

    This limit is imposed by Azure Resource Manager, not Azure Synapse Analytics. Monitoring queries per minute 1,000 1,000 Maximum time of data flow debug session 8 hrs 8 hrs Concurrent number of data flows per integration runtime [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flows per integration runtime in managed vNet [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ . Concurrent number of data flow debug sessions per user per workspace Data Flow Azure IR TTL limit 4 hrs 4 hrs Meta Data Entity Size limit in a workspace [Find out how to request a quota increase from support]( https://azure.microsoft.com/blog/azure-limits-quotas-increase-requests/ .

    1 The data integration unit (DIU) is used in a cloud-to-cloud copy operation, learn more from Data integration units (version 2) . For information on billing, see Azure Synapse Analytics Pricing .

    2 Azure Integration Runtime is globally available to ensure data compliance, efficiency, and reduced network egress costs.

    Region group Regions Region group 1 Central US, East US, East US 2, North Europe, West Europe, West US, West US 2 Region group 2 Australia East, Australia Southeast, Brazil South, Central India, Japan East, North Central US, South Central US, Southeast Asia, West Central US Region group 3 Other regions

    If managed virtual network is enabled, the data integration unit (DIU) in all region groups are 2,400.

    3 Pipeline, data set, and linked service objects represent a logical grouping of your workload. Limits for these objects don't relate to the amount of data you can move and process with Azure Synapse Analytics. Synapse Analytics is designed to scale to handle petabytes of data.

    4 The payload for each activity run includes the activity configuration, the associated dataset(s) and linked service(s) configurations if any, and a small portion of system properties generated per activity type. Limit for this payload size doesn't relate to the amount of data you can move and process with Azure Synapse Analytics. Learn about the symptoms and recommendation if you hit this limit.

    Azure Synapse limits for dedicated SQL pools

    For details of capacity limits for dedicated SQL pools in Azure Synapse Analytics, see dedicated SQL pool resource limits .

    Azure Resource Manager limits for web service calls

    Azure Resource Manager has limits for API calls. You can make API calls at a rate within the Azure Resource Manager API limits .

    Virtual machine disk limits

    You can attach a number of data disks to an Azure virtual machine (VM). Based on the scalability and performance targets for a VM's data disks, you can determine the number and type of disk that you need to meet your performance and capacity requirements.

    Important

    For optimal performance, limit the number of highly utilized disks attached to the virtual machine to avoid possible throttling. If all attached disks aren't highly utilized at the same time, the virtual machine can support a larger number of disks. Additionally, when creating a managed disk from an existing managed disk, only 49 disks can be created concurrently. More disks can be created after some of the initial 49 have been created.

    For Azure managed disks:

    The following table illustrates the default and maximum limits of the number of resources per region per subscription. The limits remain the same irrespective of disks encrypted with either platform-managed keys or customer-managed keys. There is no limit for the number of Managed Disks, snapshots and images per resource group.

    1 An individual disk can have 500 incremental snapshots.

    2 This is the default max but higher capacities are supported by request. To request an increase in capacity, request a quota increase or contact Azure Support.

    For standard storage accounts:

    A Standard storage account has a maximum total request rate of 20,000 IOPS. The total IOPS across all of your virtual machine disks in a Standard storage account should not exceed this limit.

    For unmanaged disks, you can roughly calculate the number of highly utilized disks supported by a single standard storage account based on the request rate limit. For example, for a Basic tier VM, the maximum number of highly utilized disks is about 66, which is 20,000/300 IOPS per disk. The maximum number of highly utilized disks for a Standard tier VM is about 40, which is 20,000/500 IOPS per disk.

    For premium storage accounts:

    A premium storage account has a maximum total throughput rate of 50 Gbps. The total throughput across all of your VM disks should not exceed this limit.

    For more information, see Virtual machine sizes .

    Disk encryption sets

    There's a limitation of 1000 disk encryption sets per region, per subscription. For more information, see the encryption documentation for Linux or Windows virtual machines. If you need to increase the quota, contact Azure support.

    Managed virtual machine disks

    Standard HDD managed disks

    Standard Disk Type

    *Applies only to disks with on-demand bursting enabled.

    ** Only applies to disks with performance plus (preview) enabled.

    Premium SSD managed disks: Per-VM limits

    Resource Limit

    1 Ingress refers to all data from requests that are sent to a storage account. Egress refers to all data from responses that are received from a storage account.

    Premium unmanaged virtual machine disks: Per-disk limits

    Premium storage disk type Maximum number of schedules per bandwidth template A schedule for every hour, every day of the week. Maximum size of a tiered volume on physical devices 64 TB for StorSimple 8100 and StorSimple 8600 StorSimple 8100 and StorSimple 8600 are physical devices. Maximum size of a tiered volume on virtual devices in Azure 30 TB for StorSimple 8010
    64 TB for StorSimple 8020 StorSimple 8010 and StorSimple 8020 are virtual devices in Azure that use Standard storage and Premium storage, respectively. Maximum size of a locally pinned volume on physical devices 9 TB for StorSimple 8100
    24 TB for StorSimple 8600 StorSimple 8100 and StorSimple 8600 are physical devices. Maximum number of iSCSI connections Maximum number of iSCSI connections from initiators Maximum number of access control records per device Maximum number of volumes per backup policy Maximum number of backups retained per backup policy Maximum number of schedules per backup policy Maximum number of snapshots of any type that can be retained per volume This amount includes local snapshots and cloud snapshots. Maximum number of snapshots that can be present in any device 10,000 Maximum number of volumes that can be processed in parallel for backup, restore, or clone
    • If there are more than 16 volumes, they're processed sequentially as processing slots become available.
    • New backups of a cloned or a restored tiered volume can't occur until the operation is finished. For a local volume, backups are allowed after the volume is online.
    Restore and clone recover time for tiered volumes <2 minutes
    • The volume is made available within 2 minutes of a restore or clone operation, regardless of the volume size.
    • The volume performance might initially be slower than normal as most of the data and metadata still resides in the cloud. Performance might increase as data flows from the cloud to the StorSimple device.
    • The total time to download metadata depends on the allocated volume size. Metadata is automatically brought into the device in the background at the rate of 5 minutes per TB of allocated volume data. This rate might be affected by Internet bandwidth to the cloud.
    • The restore or clone operation is complete when all the metadata is on the device.
    • Backup operations can't be performed until the restore or clone operation is fully complete.
    Restore recover time for locally pinned volumes <2 minutes
    • The volume is made available within 2 minutes of the restore operation, regardless of the volume size.
    • The volume performance might initially be slower than normal as most of the data and metadata still resides in the cloud. Performance might increase as data flows from the cloud to the StorSimple device.
    • The total time to download metadata depends on the allocated volume size. Metadata is automatically brought into the device in the background at the rate of 5 minutes per TB of allocated volume data. This rate might be affected by Internet bandwidth to the cloud.
    • Unlike tiered volumes, if there are locally pinned volumes, the volume data is also downloaded locally on the device. The restore operation is complete when all the volume data has been brought to the device.
    • The restore operations might be long and the total time to complete the restore will depend on the size of the provisioned local volume, your Internet bandwidth, and the existing data on the device. Backup operations on the locally pinned volume are allowed while the restore operation is in progress.
    Thin-restore availability Last failover Maximum client read/write throughput, when served from the SSD tier* 920/720 MB/sec with a single 10-gigabit Ethernet network interface Up to two times with MPIO and two network interfaces. Maximum client read/write throughput, when served from the HDD tier* 120/250 MB/sec Maximum client read/write throughput, when served from the cloud tier* 11/41 MB/sec Read throughput depends on clients generating and maintaining sufficient I/O queue depth.

    *Maximum throughput per I/O type was measured with 100 percent read and 100 percent write scenarios. Actual throughput might be lower and depends on I/O mix and network conditions.

    Stream Analytics limits

    Maximum number of streaming units per subscription per region To request an increase in streaming units for your subscription beyond 83, contact Microsoft Support . Maximum number of inputs per job There's a hard limit of 60 inputs per Azure Stream Analytics job. Maximum number of outputs per job There's a hard limit of 60 outputs per Stream Analytics job. Maximum number of functions per job There's a hard limit of 60 functions per Stream Analytics job. Maximum number of streaming units per job There's a hard limit of 66 streaming units per Stream Analytics job. Maximum number of jobs per region 1,500 Each subscription can have up to 1,500 jobs per geographical region. Reference data blob MB Up to 5 GB when using 1 or more SUs. Maximum number of characters in a query 512000 There's a hard limit of 512k characters in an Azure Stream Analytics job query.

    Virtual Machines limits

    Virtual Machines limits

    Resource Limit

    1 Virtual machines created by using the classic deployment model instead of Azure Resource Manager are automatically stored in a cloud service. You can add more virtual machines to that cloud service for load balancing and availability.

    2 Input endpoints allow communications to a virtual machine from outside the virtual machine's cloud service. Virtual machines in the same cloud service or virtual network can automatically communicate with each other.

    Virtual Machines limits - Azure Resource Manager

    The following limits apply when you use Azure Resource Manager and Azure resource groups.

    Resource Limit Azure Spot VM total cores per subscription 20 1 per region. Contact support to increase limit. VM per series, such as Dv2 and F, cores per subscription 20 1 per region. Contact support to increase limit. Availability sets per subscription 2,500 per region. Virtual machines per availability set Proximity placement groups per resource group Certificates per availability set 199 2 Certificates per subscription Unlimited 3

    1 Default limits vary by offer category type, such as Free Trial and Pay-As-You-Go, and by series, such as Dv2, F, and G. For example, the default for Enterprise Agreement subscriptions is 350. For security, subscriptions default to 20 cores to prevent large core deployments. If you need more cores, submit a support ticket.

    2 Properties such as SSH public keys are also pushed as certificates and count towards this limit. To bypass this limit, use the Azure Key Vault extension for Windows or the Azure Key Vault extension for Linux to install certificates.

    3 With Azure Resource Manager, certificates are stored in the Azure Key Vault. The number of certificates is unlimited for a subscription. There's a 1-MB limit of certificates per deployment, which consists of either a single VM or an availability set.

    Virtual machine cores have a regional total limit. They also have a limit for regional per-size series, such as Dv2 and F. These limits are separately enforced. For example, consider a subscription with a US East total VM core limit of 30, an A series core limit of 30, and a D series core limit of 30. This subscription can deploy 30 A1 VMs, or 30 D1 VMs, or a combination of the two not to exceed a total of 30 cores. An example of a combination is 10 A1 VMs and 20 D1 VMs.

    There are limits, per subscription, for deploying resources using Compute Galleries:

  • 100 compute galleries, per subscription, per region
  • 1,000 image definitions, per subscription, per region
  • 10,000 image versions, per subscription, per region
  • Virtual Machine Scale Sets limits

    Resource Limit

    To request higher usage limits for dev tunnels, open an issue in our GitHub repo . In the issue, include which limit you'd like increased and why.

    See also

  • Understand Azure limits and increases
  • Virtual machine and cloud service sizes for Azure
  • Sizes for Azure Cloud Services
  • Naming rules and restrictions for Azure resources
  •