For a production Microsoft Foundry Agent Service deployment using a customer-managed virtual network, Microsoft recommends starting with a /24 agent subnet. Treat that as a planning baseline, not a concurrency guarantee: subnet capacity is shared across projects in the Foundry account, hosted-agent sessions and project components consume addresses, and your regional session quota may be lower than the subnet’s capacity.
Plan for peak account-wide demand, keep expected subnet utilization below 80%, and leave room for temporary capacity needs during rollouts and maintenance. A /27 is the documented minimum, but its limited headroom makes it a poor default for production planning.
As an Amazon Associate I earn from qualifying purchases.
Choose the networking model before assigning address space
The account networking choice affects its projects, so decide whether your team will manage the network before finalizing a subnet size. The options differ in who owns address planning and network operations.
| Option | Network and address ownership | When it may fit |
|---|---|---|
| Public egress | Outbound traffic remains public. A private endpoint can restrict inbound access. | Isolation is not required, or private inbound access is sufficient. |
| Bring your own VNet (BYO VNet) | Your team controls address ranges, routing, peering, and firewall rules. | You need integration with a network your organization manages and can plan for dedicated subnets, DNS, and dependencies. |
| Managed VNet | Microsoft manages the network boundary; managed private endpoints are abstracted from your VNet resources. | You want isolation without managing your own address ranges, or overlapping address space makes BYO VNet difficult. |
Managed networking modes and supported regions can change. Check Microsoft’s current requirements for the intended deployment, and confirm that the tools your agents need work with the selected isolation model.
#1 Best Overall
Which agents and components use subnet addresses?
For BYO VNet, subnet capacity is an account-level concern, not a separate pool reserved for each project. Include projects across the Foundry account when estimating demand.
- Hosted agents: Hosted-agent sessions consume subnet addresses. Plan around peak concurrent sessions across the account, rather than counting only one project or the number of agent definitions.
- Project-level components: These also consume addresses and reduce the capacity available for sessions.
- Prompt agents: They use a small static pool rather than taking one subnet address for every revision. Their address use therefore differs from hosted-agent session use.
Microsoft Learn describes a default one-to-one mapping between usable subnet IPs and concurrent sessions, subject to regional limits. Because project components and operational events also need capacity, the mapping should not be treated as a promise of usable session capacity.
Rank #2
What the approximate subnet figures do—and do not—tell you
Microsoft Learn’s networking deep dive gives the following approximate concurrent-session capacities under the default mapping. These are illustrations, not production targets or guaranteed limits.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →| Subnet size | Approximate concurrent sessions |
|---|---|
/27 |
20 |
/26 |
50 |
/25 |
100 |
/24 |
250 |
/23 |
500 |
/22 |
1,000 |
/21 |
2,000 |
The same guidance recommends a /24 starting point for production and identifies /27 as the minimum. It also advises keeping subnet utilization below 80%. The approximate /24 figure of 250 sessions is therefore not a recommendation to run 250 sessions in production: project components and headroom consume capacity, while the regional quota can impose a lower session ceiling.
Rank #3
Project count is not a reliable substitute for session demand. Microsoft’s deep dive gives an illustration of about 250 projects at low traffic, potentially falling to about 25 under heavy traffic, depending on IP availability. Those figures are context-dependent estimates, not project limits.
How to size for account-wide peak demand
- Estimate simultaneous hosted-agent sessions. Combine expected peak concurrency across all projects in the Foundry account for the relevant region. Use anticipated demand, not an average or a per-project estimate.
- Check the regional session quota. Compare the intended workload with the applicable subscription and regional limit. A larger subnet adds address capacity; it does not itself raise that quota.
- Allow for components and operations. Account for project-level components and keep expected utilization below Microsoft’s 80% guidance. Leave additional room for rollouts, scaling, and maintenance, when old and new infrastructure may run in parallel.
- Select a subnet with headroom. Use Microsoft’s approximate mapping as a planning illustration, then check it against your workload, the account’s other projects, and the regional quota. For production, Microsoft’s
/24starting recommendation is more useful than treating the/27minimum as a target. - Revisit the plan when demand changes. New projects, higher peak concurrency, or changes to deployment patterns can consume the headroom that made the original allocation workable.
If the regional quota is too low, Microsoft’s guidance is to request a limit increase; availability depends on regional capacity. If expected concurrency exceeds available subnet IP capacity and the subnet cannot be expanded, the deep dive also describes asking support about a higher IP-to-session mapping. Neither path should be assumed to be available without confirmation.
Rank #4
- Server 2022 Standard 16 Core
BYO VNet checks before deployment
Subnet size is only one part of the network design. Microsoft’s setup guidance identifies several dependencies that can block deployment or agent connectivity.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Reserve a dedicated agent subnet and delegate it to
Microsoft.App/environmentsfor the applicable BYO setup. - Leave separate address space for private endpoints, and avoid ranges that overlap with peered networks.
- Set up private DNS for dependent private resources and configure outbound rules for required dependencies. Microsoft specifically calls out
AzureActiveDirectoryfor Microsoft Entra authentication. - Verify the allowed address ranges for the exact deployment path. Microsoft’s FAQ and networking deep dive describe RFC 1918 ranges for the delegated subnet, while the networking-options page also mentions RFC 6598/CGNAT space with exclusions. That documentation does not establish CGNAT support for every deployment path, so confirm the current requirement before allocating it.
How to spot and respond to capacity trouble
Subnet exhaustion can prevent new projects or compute from provisioning. It may also appear as data proxy HTTP 500 errors. Microsoft says it does not proactively warn when IP capacity is running low, and the portal has no direct IP monitoring, so do not rely on an automatic low-capacity alert.
Quick Recap
- Record the symptom and scope. Note whether the failure affects new project or compute provisioning, data proxy requests, or both, and which projects and deployments are involved.
- Review the account-level capacity plan. Reconcile current projects and expected peak hosted-agent sessions against available subnet capacity, including the room reserved for components and operational events.
- Check the regional quota separately. If the quota is the limiting factor, pursue a limit increase; adding subnet addresses alone will not change it.
- Use the documented support path when address capacity is the constraint. If the subnet cannot be expanded and session demand exceeds available IP capacity, ask support whether a higher IP-to-session mapping is possible.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




