An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Azure VPN Gateway stuck in "Updating" after removing P2S configuration
Disclaimer: Error log written with AI.
I have an Azure Virtual Network Gateway in West Europe that has been stuck in Updating after I attempted to remove the existing Point-to-Site (P2S) configuration.
The reason for the change was to migrate the P2S configuration away from SSTP and configure OpenVPN instead.
What happened
At approximately 2026-10-04 08:52 UTC, I initiated an update of the Virtual Network Gateway to remove the existing P2S configuration.
The Activity Log shows:
08:52:43 UTC – Creates or updates a VirtualNetworkGateway – Started
08:52:46 UTC – Creates or updates a VirtualNetworkGateway – Accepted
Correlation ID: c9f2a911-26c1-4b28-8079-cb7bead5b796
There has been no corresponding Succeeded or Failed event for this operation.
Since then, Azure has continued polling the Virtual Network Gateway, but the gateway remains in:
{
"protocols": null,
"provisioningState": "Updating"
}
Subsequent attempts
I initially assumed the operation had stalled and attempted another gateway update. That operation also did not resolve the issue.
I also attempted to reset the gateway:
az network vnet-gateway reset `
--name UB-Network-gw `
--resource-group UB-Network
The reset cannot start and returns:
(AnotherOperationInProgress) Another operation on this or dependent resource is in progress.
Azure reports the blocking operation as:
Microsoft.Network/locations/westeurope/operations/
18463fad-5e6d-4619-b7a2-0f88d24409d0
Current situation
The gateway remains:
Provisioning state: Updating
P2S VPN client protocols: null
Any write operation against the gateway, including a gateway reset, is blocked by the existing asynchronous Microsoft.Network operation.
The subscription only has Basic support, so opening a normal Azure technical support case is not available to me.
Questions
Is there any supported way for the customer to clear or cancel a stuck Microsoft.Network asynchronous operation on a Virtual Network Gateway?
Can the gateway's provisioning state or operation lock be recovered without deleting and recreating the Virtual Network Gateway?
Is this something that requires intervention from the Microsoft Networking backend team?
If Microsoft intervention is required, is there a way to have this escalated from Microsoft Q&A for a subscription without a paid technical support plan?
I would prefer to avoid deleting/recreating the gateway if possible, as the intended change was only to replace the existing SSTP P2S configuration with OpenVPN.