Skip to main content
Cloud / Azure / Products / Azure Virtual Network TAP - Mirror VM Network Traffic

Azure Virtual Network TAP - Mirror VM Network Traffic

Azure Virtual Network TAP continuously streams virtual machine network traffic to a packet collector or analytics tool. Currently in public preview.

networking
Pricing Model Pricing model per vendor / see official documentation; collector and partner solution costs apply additionally
Availability Public preview in select regions, including West Europe and Germany West Central
Data Sovereignty The destination for mirrored traffic sits in the same or a peered virtual network in the same region
Reliability No SLA stated; preview terms apply SLA

What is Azure Virtual Network TAP?

Azure Virtual Network TAP (Terminal Access Point) allows you to continuously stream your virtual machine network traffic to a network packet collector or analytics tool. The collector or analytics tool is provided by a network virtual appliance partner; Microsoft maintains a list of partner solutions validated to work with virtual network TAP.

Microsoft states explicitly: “Virtual network TAP is now in public preview in select Azure regions.” The service is therefore not yet generally available and is subject to preview terms. Configuration happens through a TAP configuration on a network interface attached to a virtual machine in your virtual network.

Core Features

Continuous traffic mirroring: Traffic from a VM network interface is continuously mirrored to the defined destination.

Aggregation across subscriptions: One virtual network TAP resource can aggregate traffic from multiple network interfaces, including across subscriptions, provided they are associated with the same Microsoft Entra tenant.

Highly available collector: The collector solution can be deployed behind an Azure internal load balancer.

Role-based control: Creating and changing TAP configurations requires defined permissions, such as the network contributor role.

Broad partner ecosystem: Validated solutions across network packet brokers, security analytics, and network and application performance management.

Typical Use Cases

Network detection and response: Security solutions analyze original traffic to detect attacks and unusual behavior.

Forensics and incident response: Mirrored traffic is available for downstream analysis.

Performance analysis: Network and application performance management based on real packet data.

Central packet distribution: Network packet brokers distribute mirrored traffic to several analytics tools.

Benefits

  • Access to original virtual machine traffic without agents on the source VM
  • Aggregation of multiple network interfaces across subscriptions in the same tenant
  • Integration with established partner solutions for security and performance analysis
  • High availability of the collector through an internal load balancer
  • Fine-grained permission control through Azure RBAC

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you in evaluating and introducing Azure Virtual Network TAP: reviewing preview limitations, selecting and sizing the collector solution, network design for source and destination networks, and integration into existing security processes.

Contact us for a no-obligation consultation on Azure Virtual Network TAP.

Typical Use Cases

Continuously mirror VM network traffic to network detection and response (NDR) solutions
Security analytics and threat detection based on original traffic
Network and application performance management
Running network packet brokers in Azure

Technical Specifications

0th A TAP configuration is added on a network interface attached to a virtual machine
1st The destination is an IP address in the same or a directly peered virtual network; virtual WAN peering is not supported
2nd The collector solution can run behind an Azure internal load balancer for high availability
3rd One TAP resource can aggregate traffic from multiple network interfaces, including across subscriptions in the same Entra tenant
4th Permissions: the network contributor role or a custom role with Microsoft.Network/virtualNetworkTaps/*, networkInterfaces/read and tapConfigurations/*
5th Supported regions per documentation: East Asia, Southeast Asia, Canada Central, West Europe, Germany West Central, Central India, Korea Central, UAE North, UK South, Central US, Central US EUAP, East US, East US 2, East US 2 EUAP, West US 3
6th Limitations: only VM network interfaces as sources, no IPv6 and no SWIFT, no VMs behind a Basic Load Balancer, no sources in encrypted virtual networks, no mirroring of inbound Private Link Service traffic
7th Public preview limitations: v6 VM SKUs are not supported as sources, a source VM must be stopped (deallocated) and started once after deploying the TAP resource, up to 60 seconds of network downtime when adding or removing a source, and live migration is not supported for source VMs

Frequently Asked Questions

Is Azure Virtual Network TAP generally available?

No. The Microsoft documentation states explicitly: 'Virtual network TAP is now in public preview in select Azure regions.' The supported regions are listed in the documentation.

Where is the mirrored traffic sent?

The destination is an IP address in the same virtual network as the monitored network interface, or in a peered virtual network. Mirrored traffic can be sent only to a load balancer or a VM network interface.

Which partner solutions are supported?

Microsoft lists network packet brokers from Gigamon (GigaVUE Cloud Suite for Azure) and Keysight (CloudLens), plus security and performance solutions from Darktrace, Netscout, Corelight, Vectra, Fortinet, cPacket, Trend Micro, ExtraHop, Progress, Bitdefender, eSentire, LinkShadow, AttackFence, Arista Networks and Rapid7.

Which permissions are required?

The accounts used must be assigned the network contributor role or a custom role that includes the actions Microsoft.Network/virtualNetworkTaps/*, Microsoft.Network/networkInterfaces/read and Microsoft.Network/tapConfigurations/*.

Are there limitations when adding source VMs?

Yes. In public preview, a VM must be stopped (deallocated) and started once after the Virtual Network TAP resource is deployed before it can act as a source. Adding or removing a source can cause up to 60 seconds of network downtime, and live migration is disabled for source VMs.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Azure Virtual Network TAP - Mirror VM Network Traffic?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation