Home

Microsoft Peering with ExpressRoute (Transitioning to from Public Peering)

%3CLINGO-SUB%20id%3D%22lingo-sub-391903%22%20slang%3D%22en-US%22%3EMicrosoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-391903%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EAzure%20public%20peering%20has%20been%20deprecated%2C%20as%20is%20not%20available%20for%20new%20ExpressRoute%20circuits.%20New%20Circuits%20support%20Microsoft%20peering%20and%20private%20peering.%26nbsp%3BPublic%20peering%20has%20been%20disabled%20on%20new%20ExpressRoute%20circuits.%20Azure%20services%20are%20available%20on%20Microsoft%20peering.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20issue%20is%20our%20DR%20environment%20hosted%20in%20Azure%20Site%20Recovery%20uses%20an%20ExpressRoute%20circuit%20that%20is%20configured%20with%20Microsoft%20peering.%20However%2C%20Azure%20AD%20pass%20through%20authentication%26nbsp%3Bdoes%20not%20seem%20to%20wrok%20in%20Azure.%20Do%20we%20need%20an%20ExpressRoute%20premium%20connector%20to%20support%20this%3F%20please%20help%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-391903%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Site%20Recovery%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-394099%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-394099%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3Eif%20your%20internal%20IT%20policy%20requires%2C%20that%20the%20traffic%20for%20Azure%20AD%20Authentication%20routes%20over%20express%20route%2C%20you%20have%20to%20change%20the%20peering.%3CBR%20%2F%3EAt%20the%20moment%20there%20isn%E2%80%99t%20any%20official%20statement%20from%20Microsoft%20when%20the%20public%20peering%20will%20be%20disabled%20for%20exist%20connections.%3CBR%20%2F%3EHere%20is%20a%20migration%20guide%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fexpressroute%2Fhow-to-move-peering%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fexpressroute%2Fhow-to-move-peering%3C%2FA%3E%3CBR%20%2F%3EBut%20keep%20in%20mind%2C%20you%20maybe%20need%20the%20premium%20addon%20for%20the%20%E2%80%9COther%20Office%20365%20Services%E2%80%9C%20which%20include%20the%20Azure%20AD%20IPs.%3CBR%20%2F%3EFor%20my%20point%20of%20view%20there%20is%20no%20need%20to%20route%20the%20Azure%20AD%20pass%20through%20authentication%20over%20the%20express%20route%20circuit%2C%20but%20when%20the%20security%20required%20that%20option%20it%E2%80%99s%20okay.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-393991%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-393991%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F289860%22%20target%3D%22_blank%22%3E%40Hannes_LG%3C%2FA%3E%26nbsp%3Bappears%20to%20be%20working%20now%20over%20the%20public%20peer.%20My%20issue%20is%20can%20I%20still%20use%20the%20public%20peer%20or%20do%20I%20need%20to%20move%20to%20the%20Microsoft%20peer%3F%20Public%20peering%20has%20been%20deprecated%20for%20new%20circuits%20but%20how%20long%20will%20it%20last%20on%20my%20existing%20circuit%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392747%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392747%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3Ewhere%20is%20the%20Problem%3F%20If%20you%20can%E2%80%99t%20use%20the%20Microsoft%20peering%2C%20Azure%20AD%20pass%20through%20Authentication%20works%20over%20the%20Internet.%20Open%20the%20required%20ports%20(outgoing)%20and%20everything%20was%20well.%20If%20you%20want%20to%20route%20the%20traffic%20to%20the%20express%20route%2C%20use%20the%20Microsoft%20peering.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392223%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392223%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F289860%22%20target%3D%22_blank%22%3E%40Hannes_LG%3C%2FA%3E%26nbsp%3BI%20have%20no%20option%20but%20to%20use%20Microsoft%20Peering.%20The%20public%20peering%20model%20has%20been%20deprecated%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392096%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392096%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EIf%20you%20want%20to%20route%20Azure%20AD%20traffic%20(Pass%20Through)%20over%20Microsoft%20peering%20you%20have%20to%20enable%20%E2%80%9EOther%20Office%20365%20Services%E2%80%9C%20at%20the%20route%20filter.%3CBR%20%2F%3EI%20don%E2%80%98t%20know%20if%20that%20requires%20the%20premium%20ADD-On%20but%20the%20questions%20are%3A%3CBR%20%2F%3E1.)%20How%20many%20Office%20365%20seats%20do%20you%20have%3F%3CBR%20%2F%3EIf%20you%20have%20at%20least%20500%20seats%20the%20premium%20Add-On%20is%20free%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Foptimizing-your-network%2Fmedia-quality-and-network-connectivity-performance%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Foptimizing-your-network%2Fmedia-quality-and-network-connectivity-performance%3C%2FA%3E)%3CBR%20%2F%3E2.)%20Why%20it%E2%80%99s%20so%20important%20to%20route%20the%20Azure%20AD%20pass%20through%20authentication%20over%20the%20express%20route%3F%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20that%20helps.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392071%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392071%22%20slang%3D%22en-US%22%3EWe%20need%20Azure%20AD%20pass%20through%20authentication%20working%20in%20Azure.%20But%20my%20question%20is%20does%20ti%20require%20Express%20route%20premium%3F%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20you%20say%20its%20working%20for%20you%2C%20do%20you%20have%20it%20working%20with%20ExpressRoute%20non-premium%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392038%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392038%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EI%20had%20many%20customer%20engagements%20in%20the%20past%20where%20we%20use%20the%20Microsoft%20peering%20for%20Office365.%3CBR%20%2F%3EWe%20always%20had%20many%20troubles%20after%20we%20enable%20the%20service%2C%20that%E2%80%99s%20the%20reason%20why%20Microsoft%20disable%20that%20feature%20per%20default.%3CBR%20%2F%3EFor%20my%20point%20of%20view%20Office365%20over%20express%20route%20make%20sense%20if%20you%20use%20Skype%20voice%20because%20you%20can%20use%20QoS.%3CBR%20%2F%3EI%20don%E2%80%99t%20think%20that%E2%80%99s%20your%20issue.%20Do%20you%20see%20any%20connection%20issues%20in%20AzureAD%20(Pass%20through%20Authentication)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392031%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392031%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F289860%22%20target%3D%22_blank%22%3E%40Hannes_LG%3C%2FA%3E%26nbsp%3BDo%20you%20have%20Other%20Office%20365%20services%20enabled%20for%20the%20BGP%20filter%3F%20I%20requested%20this%20from%20MS%20but%20still%20dont%20have%20approval.%20Can%20you%20confirm%20that%20is%20what%20you%20need%20to%20get%20that%20working%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-392002%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Peering%20with%20ExpressRoute%20(Transitioning%20to%20from%20Public%20Peering)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-392002%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20don%E2%80%98t%20here%2Fsee%20about%20any%20issues%20with%20ExpressRoute%20and%20AD%20pass%20through%20authentication.%3CBR%20%2F%3EDo%20you%20have%20any%20express%20route%20filters%20configured%3F%3C%2FLINGO-BODY%3E
HB2019-
Occasional Contributor

Azure public peering has been deprecated, as is not available for new ExpressRoute circuits. New Circuits support Microsoft peering and private peering. Public peering has been disabled on new ExpressRoute circuits. Azure services are available on Microsoft peering.

 

The issue is our DR environment hosted in Azure Site Recovery uses an ExpressRoute circuit that is configured with Microsoft peering. However, Azure AD pass through authentication does not seem to wrok in Azure. Do we need an ExpressRoute premium connector to support this? please help

 

 

9 Replies
Hi,

I don‘t here/see about any issues with ExpressRoute and AD pass through authentication.
Do you have any express route filters configured?

@Hannes_LG Do you have Other Office 365 services enabled for the BGP filter? I requested this from MS but still dont have approval. Can you confirm that is what you need to get that working?

Hi,
I had many customer engagements in the past where we use the Microsoft peering for Office365.
We always had many troubles after we enable the service, that’s the reason why Microsoft disable that feature per default.
For my point of view Office365 over express route make sense if you use Skype voice because you can use QoS.
I don’t think that’s your issue. Do you see any connection issues in AzureAD (Pass through Authentication)
We need Azure AD pass through authentication working in Azure. But my question is does ti require Express route premium?

When you say its working for you, do you have it working with ExpressRoute non-premium?
Hi,
If you want to route Azure AD traffic (Pass Through) over Microsoft peering you have to enable „Other Office 365 Services“ at the route filter.
I don‘t know if that requires the premium ADD-On but the questions are:
1.) How many Office 365 seats do you have?
If you have at least 500 seats the premium Add-On is free (https://docs.microsoft.com/en-us/skypeforbusiness/optimizing-your-network/media-quality-and-network-...)
2.) Why it’s so important to route the Azure AD pass through authentication over the express route?

Hope that helps.

@Hannes_LG I have no option but to use Microsoft Peering. The public peering model has been deprecated 

Hi,

where is the Problem? If you can’t use the Microsoft peering, Azure AD pass through Authentication works over the Internet. Open the required ports (outgoing) and everything was well. If you want to route the traffic to the express route, use the Microsoft peering.

@Hannes_LG appears to be working now over the public peer. My issue is can I still use the public peer or do I need to move to the Microsoft peer? Public peering has been deprecated for new circuits but how long will it last on my existing circuit? 

Hi,
if your internal IT policy requires, that the traffic for Azure AD Authentication routes over express route, you have to change the peering.
At the moment there isn’t any official statement from Microsoft when the public peering will be disabled for exist connections.
Here is a migration guide:
https://docs.microsoft.com/en-us/azure/expressroute/how-to-move-peering
But keep in mind, you maybe need the premium addon for the “Other Office 365 Services“ which include the Azure AD IPs.
For my point of view there is no need to route the Azure AD pass through authentication over the express route circuit, but when the security required that option it’s okay.

Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies