(General Feedback)

Do you have an idea or suggestion based on your experience with Azure? We would love to hear it! Please take a few minutes to submit your idea in the one of the forums available on the right or vote up an idea submitted by another Azure customer. All of the feedback you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Azure.

This forum (General Feedback) is used for any broad feedback related to Azure. If you have feedback on a specific service such as Azure Virtual Machines, Web Apps, or SQL Database, please submit your feedback in one of the forums available on the right.

Remember that this site is only for feature suggestions and ideas!

If you have technical questions or need help with Azure, please try StackOverflow or visit our MSDN forums

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Web App should use private IP in a VNet with Service Endpoints

    Remove the limitation that prevents us from using Web Apps with Service Endpoints to limit access to Azure SQL database.

    Limitation is described here: https://docs.microsoft.com/en-us/azure/sql-database/sql-database-vnet-service-endpoint-rule-overview?toc=%2fazure%2fvirtual-network%2ftoc.json#limitations
    "•A Web App can be mapped to a private IP in a VNet/subnet. Even if service endpoints are turned ON from the given VNet/subnet, connections from the Web App to the server will have an Azure public IP source, not a VNet/subnet source. To enable connectivity from a Web App to a server that has VNet firewall rules, you must Allow all Azure services on the server."

    212 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      2 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
    • [REQUEST] Please implement NTP Servers inside the Azure Data centers.

      For security reasons, we can't use NTP servers such as ”time.windows.com” through the internet. Please implement NTP Servers inside the Azure Data centers.

      66 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
      • Send SUPPORT invoices via email

        Glad to see the ability to send invoices via email has been implemented.

        However, it's still NOT possible to opt-in for SUPPORT invoices via email. This minimizes the usefulness of invoices via email if I still need to go to the billing portal to access by support invoice.

        Please implement the ability send support invoices via email. Thank you.

        59 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          1 comment  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
        • 49 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            3 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
          • The limit of tag count for a resource is too small

            The limit of tag count for a resource is 15, which is too small.
            Is it possible to increase the value?

            39 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
            • Recovery Service Vault, Backup storage Replication in ARM

              Currently there is no way to sepcify which storage replication is wanted when you create a Recovery Services Vault via ARM templates.

              The default when spinning up a vault is GRS, and the only way to change it is to log into the portal and choose LRS before any backups have been applied.

              The fact that the type of storage replication cannot be changed after a backup has been set does not help the situation.

              This makes automating infrastrucutre builds painful as I have to login and change the setting in the portal before i am able to continue adding…

              37 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
              • azure zones dns-forwarder

                Please extend DNS zones solution to add forwarding & client features to implement the following in PaaS instead of with VMs:
                https://github.com/Azure/azure-quickstart-templates/tree/master/301-dns-forwarder

                Use case: use azure dns to forward dns queries to 168.63.129.16 & between subnets. Enterprise DNS would forward to Azure DNS. VNET has Azure-provided name resolution (*.internal.cloudapp.net). In this way Enterprise DNS could dynamically learn of a PaaS offering on VNET.

                37 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                • Add slider bar

                  Add slider bar in Choose VM Size pane in portal.azure.com when you do View all so you don't get the whole sha-bang all the time

                  30 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    1 comment  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                  • When moving a resource

                    When moving a resource (or resource group) to a new subscription.
                    ask for real movement after the validation, this would enable a dry test upfront for planning

                    28 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      1 comment  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                    • assign Security Group to Authentication Method

                      Add the option to assign a security group to specific authentication methods.
                      i.e, Security Group "Azure Security Question" can be assigned to the Security Question authentication method. So that only objects in the group are given the Security Question method.

                      27 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                      • enable Azure MFA server to accept RADIUS attribute 31 for trusted IP evaluation.

                        Currently the RADIUS client must send the authenticating user's IP address via attribute 66 for Azure MFA RADIUS server to correctly evaluate trusted IP addresses. It would be tremendously helpful if that was configurable so that an admin could select a different RADIUS attribute (such as 31) for trusted IP evaluation. We use a NetScaler gateway and it will currently only send RADIUS attribute 31 (Calling-Station-Id) to the RADIUs server. Quick fix I presume!

                        27 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          4 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                        • Let Web Apps to be PCI compliance

                          Despite that PCI compliance is promoted at Azure, a Web App created at Azure is non compliant by default, and cannot be set-up appropriately.

                          I understand that a Web App is not as isolated as an ASE (that still is not compliance by default, needs advanced set-up), with instances sharing system level settings with other clients (so cannot be changed independently), and I understand some set-up changes that apply to all clients, even ones that do not require PCI, can lead to problems to some of them.

                          I propose an option to opt-in to PCI compliance at Web App level;…

                          24 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                          • Add description field to NSG Rule

                            It would be nice to have a way to describe the reason for a given NSG rule.

                            This would greatly simplify, for instance, bookkeeping for PCI DSS 3.1 item 1.1.6 which demands a business notification for each NSG rule.

                            Name field allows 80 chars but type description there is just not the right thing. Specially when you need to refer to a given rule while using CLI tools. Huge plus if it appears as a column while listing rules.

                            23 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                            • Whitelist all Microsoft services in Storage account Firewall

                              Whitelist all Microsoft services including Azure Data Factory when the "Firewall and Virtual Network" option is enabled on Storage account and "Allow trusted Microsoft services to access this storage account" option is selected.

                              Similar option is already available on Azure Data Lake store, where we can access Data Lake from Data Factory pipelines after the firewall option is enabled.

                              23 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                2 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                              • Azure Revered Instances - Applying reservation to single or multiple VMs

                                Azure Revered Instances - Applying reservation to single or multiple VMs.

                                Looks like someone in Azure product team really missed ball on this. Basic things like selecting a VM to apply reservation is not even properly setup or documented. This shows poor work effort provided by the group worked on it.

                                20 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                • Allow NSG for VPN Gateway Subnet

                                  We want to connect several devices with our Azure VNET via the VPN Gateway. Therefore the VPN Gateway is configured for P2S connections.

                                  We want to restrict the devices so that they can only communicate with certain other devices.

                                  To implement this functionality we need to assign the VPN Gateway subnet a NSG. Furthermore this NSG should be dynamic, because the IPs provided by the VPN Gateway to its clients clould not be predetermined.

                                  Currently NSGs are not supported for VPN Gateway subnets as well as there is no way to control IP allocation for connecting devices.

                                  20 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Invoices for Azure Add-On customers (external services)

                                    Currently, invoices are not prepared for payments of the Azure Add-On customers (external services) (i.e. SendGrid).

                                    This causes problems in our accounting. Could you make them available?

                                    19 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      1 comment  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Need for RBAC permission specialized for "Local Network Gateway".

                                      At the moment, we do not have a permission specialized for RBAC.

                                      As its background, we want to limit the amount of the permission which we assign to our user.
                                      Since there are too many permissions when we add "Microsoft.Network/*", our user needs a permission specialized for Local Network Gateway.

                                      We can set following permissions (Actions and NotActions) by setting up the NotActions listed below.
                                      However, in order to avoid unexpected permissions when a new feature is released, could you kindly add specialized Local Network Gateway permission?

                                      [Japanese]
                                      RBAC の権限として、ローカル ネットワーク ゲートウェイに特化したものがありません。

                                      各ユーザーに対して、必要最小限の権限のみを与えたいと考えていますが、
                                      "Microsoft.Network/*" を付与する方法では付与される権限が多すぎるため
                                      ローカル ネットワーク ゲートウェイに特化した権限を必要としています。

                                      以下のように NotActions…

                                      19 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        1 comment  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Allow firewall rules on Azure SQL DB to be removed via ARM templates

                                        Currently it seems that because the firewall rules for an Azure SQL DB are just proxy resources in an ARM template that you can not remove them via this mechanism. If you remove them from the ARM template, they are not removed from the Azure SQL DB resource. This means that it is not possible to properly source control the configuration as the source controlled configuration can differ from reality. I think it is vital to allow people to properly manage the Azure SQL DB as code that you work allow the rules to be removed via the ARM template.

                                        18 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Rename European regions

                                          Please rename the North and West Europe regions so they are aligned with France, UK, Switzerland naming convention.

                                          18 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Other  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4 5 22 23
                                          • Don't see your idea?

                                          (General Feedback)

                                          Feedback and Knowledge Base