Azure resource naming rules
Length limits, uniqueness scopes and naming profiles for 29 Azure resources, with examples and links to the generator.
Open the Azure, AWS and GCP name generator
A naming convention helps a team recognise resources. Azure naming restrictions decide whether a resource name is accepted. A recommended prefix alone does not establish validity.
Supported Azure naming profiles
These 29 profiles cover common application infrastructure. App Service and VM profiles use a conservative ASCII subset. Checks do not establish name availability, reserved-word acceptance, subscription permissions or policy compliance.
| Resource | Length | Scope | Local profile |
|---|---|---|---|
| Resource group | 1–90 | subscription | Letters, digits, underscores, hyphens, periods and parentheses; no trailing period.^[\p{L}\p{Nd}_.()\-]+$ |
| Storage account | 3–24 | global | 3–24 lowercase letters or digits; no separators.^[a-z0-9]+$ |
| Virtual machine / hostname (Windows, conservative ASCII) | 1–15 | resource group | 1–15 ASCII letters, digits or hyphens; no trailing hyphen or all-numeric hostname. Conservative hostname profile.^[A-Za-z0-9-]+$ |
| Virtual machine / hostname (Linux, conservative ASCII) | 1–64 | resource group | 1–64 ASCII letters, digits or hyphens; no trailing hyphen. Conservative hostname profile.^[A-Za-z0-9-]+$ |
| Virtual network | 2–64 | resource group | 2–64 ASCII letters, digits, underscores, periods or hyphens; start alphanumeric, end alphanumeric or underscore.^[A-Za-z0-9][A-Za-z0-9_.-]*[A-Za-z0-9_]$ |
| Key Vault | 3–24 | global | 3–24 characters; resource-specific character and start/end restrictions. Uniqueness scope: global.^[A-Za-z][A-Za-z0-9-]*[A-Za-z0-9]$no-double |
| Web app (ASCII profile) | 2–60 | global or App Service Environment domain | 2–60 characters; conservative ASCII profile; provider also supports mapped Unicode. Uniqueness scope: global or App Service Environment domain.^[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?$ |
| Function app (ASCII profile) | 2–60 | global or App Service Environment domain | 2–60 characters; conservative ASCII profile; provider also supports mapped Unicode. Uniqueness scope: global or App Service Environment domain.^[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?$ |
| App Service plan (ASCII profile) | 1–60 | resource group | 1–60 characters; conservative ASCII profile; provider also supports mapped Unicode. Uniqueness scope: resource group.^[A-Za-z0-9-]+$ |
| AKS cluster | 1–63 | resource group | 1–63 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_-]*[A-Za-z0-9])?$ |
| Container registry | 5–50 | global | 5–50 characters; letters and digits only. Uniqueness scope: global.^[A-Za-z0-9]+$ |
| Container app | 2–32 | resource group | 2–32 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[a-z][a-z0-9-]*[a-z0-9]$ |
| SQL server | 1–63 | global | 1–63 characters; resource-specific character and start/end restrictions. Uniqueness scope: global.^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$ |
| SQL database | 1–128 | server | 1–128 characters; resource-specific character and start/end restrictions. Uniqueness scope: server.^[^<>*%&:\\/?\x00-\x1f\x7f]+$no-dot-space |
| Cosmos DB for NoSQL account | 3–44 | global | 3–44 characters; resource-specific character and start/end restrictions. Uniqueness scope: global.^[a-z0-9][a-z0-9-]*$ |
| Service Bus namespace | 6–50 | global | 6–50 characters; resource-specific character and start/end restrictions. Uniqueness scope: global.^[A-Za-z][A-Za-z0-9-]*[A-Za-z0-9]$ |
| Log Analytics workspace | 4–63 | resource group | 4–63 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9-]*[A-Za-z0-9])?$ |
| Application Insights | 1–260 | resource group | 1–260 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[^%&\\/?\x00-\x1f\x7f]+$no-dot-space |
| Private endpoint | 2–64 | resource group | 2–64 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Network security group | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Network interface | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Public IP address | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Application gateway | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| External load balancer | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Route table | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Azure Firewall | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Bastion host | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
| Managed data disk | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9_-]+$ |
| Availability set | 1–80 | resource group | 1–80 characters; resource-specific character and start/end restrictions. Uniqueness scope: resource group.^[A-Za-z0-9](?:[A-Za-z0-9_.-]*[A-Za-z0-9_])?$ |
Validate before provisioning
For example, stpaymentsprodeus001 uses concatenated components for a storage account, while rg-payments-prod-eus-001 retains separators. A long workload can push a storage account or Key Vault name over its length limit. The generator reports this rather than silently cutting the name.
Function apps longer than 32 characters deserve a separate host-ID collision review when sharing storage. The resource name can pass its own length check while that operational risk remains.
Sources and review date
Reviewed October 10, 2026 against Microsoft naming restrictions and Microsoft resource abbreviations. Provider documentation takes precedence when rules change.