How many usable addresses each prefix gives in Azure, why five are always reserved, and how to size subnets for gateways, Bastion and VMs.
From Ultra Transcenders AZ-700 by Tony Rough (publishing soon)
Azure takes a fixed number of addresses from every subnet, so the usable count is always smaller than the raw prefix size, and that shapes every sizing decision.
| Prefix | Addresses | Usable in Azure |
|---|---|---|
| /29 | 8 | 3 |
| /28 | 16 | 11 |
| /27 (255.255.255.224) | 32 | 27 |
| /26 | 64 | 59 |
| /25 | 128 | 123 |
| /24 | 256 | 251 |
| /23 | 512 | 507 |
Common trap: Splitting a /24 into 128 subnets with 7 usable addresses each - that would mean /31 subnets, which Azure doesn’t support, and a /31 has only 2 addresses anyway. The most you can get from a /24 is 32 /29s with 3 usable addresses each.
Common trap: Choosing a /25 for 507 or 510 hosts - a /25 gives only 123 usable addresses; 507 hosts need a /23.
Because every subnet costs 5 addresses, the fewer subnets you create, the more addresses you keep for workloads.
Common trap: Splitting the /24 into /26s when it must hold a gateway plus VMs - two /25s lose fewer addresses to Azure’s reservations.
Common trap: Making a /26 the larger VM subnet alongside Bastion to reach 182 addresses - 182 usable addresses need a /25 as the larger VM subnet (123 + 59).
This note is one section of Ultra Transcenders AZ-700: Designing and Implementing Microsoft Azure Networking Solutions, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free AZ-700 glossary · All AZ-700 study notes
Resolving Azure private zones from on-premises and on-premises names from Azure, with subnet sizing and ruleset rules.
Where each peering setting goes, what spokes can reach, and why peering isn't transitive.
Longest prefix match, system routes versus user-defined routes, and how a 0.0.0.0/0 route forces internet traffic on-premises.
What each ExpressRoute feature does, which SKUs and gateways it needs, and where it fits on a circuit.
A decision guide by traffic type (HTTP or not) and scope (regional or global).
The CNAME chain from a public service name to a private endpoint, zone groups and zone links.
Rule order, the default rules, and what happens to a flow between subnets and to return traffic.