#
168.63.129.16 (WireServer)
Azure's fixed virtual public IP for platform services (VM agent, Azure-provided DNS, DHCP and load balancer health probes); blocking it breaks platform functions and has nothing to do with filtering SQL or Storage.
5-tuple
Source IP, source port, destination IP, destination port and protocol; the default Load Balancer hash and the input IP flow verify tests.
_dnsauth TXT record
DNS TXT record (_dnsauth.<subdomain>) that proves domain ownership to Front Door Standard/Premium; it validates only and never routes traffic.
A
A record
DNS record mapping a name to an IPv4 address; used to map a root domain to an app.
Access package
Entitlement management bundle of groups, apps and sites with request policies and expiry; when the assignment expires its resource access is removed.
Access policies (Key Vault)
The legacy Key Vault permission model; the Azure RBAC permission model is the current one.
Access restrictions (App Service access restrictions)
App Service inbound allow/deny rules by IP range, service tag or subnet; the way to limit an app to specific public IPs such as corporate NAT addresses.
Action groups
Azure Monitor notification targets; they deliver alerts but do not detect problems themselves.
Active-active VPN gateway
VPN gateway mode where both instances hold tunnels, each with its own Standard static public IP; required (with ASN 65515) for Route Server branch-to-branch.
Activity log
Subscription log of management-plane operations (deployments, Policy events), kept 90 days; it records no data-plane access such as Key Vault reads.
Activity log alert
Stateless alert rule that fires when an Activity log event matches its condition (for example Delete management lock); it needs a scope, a condition and an action group, and no Log Analytics workspace.
AD CS (Active Directory Certificate Services)
Windows Server role that runs a private PKI/CA; its certificates aren't accepted by Front Door BYOC.
AD DS (Active Directory Domain Services)
The on-premises Windows domain service with domain controllers; see also Microsoft Entra Domain Services for the managed version.
Add-AzNetworkInterfaceIpConfig
Az.Network cmdlet that adds an IP configuration to an existing NIC; with -PrivateIpAddressVersion IPv6 it gives a VM IPv6 without a second NIC.
Add-AzVirtualNetworkPeering
Az.Network cmdlet that creates one direction of a VNet peering; use -AllowGatewayTransit on the hub-to-spoke peering and -UseRemoteGateways on the spoke-to-hub peering.
Address space
CIDR range(s) assigned to a VNet; a new range outside it must be added to the address space before a subnet can use it, and it can be changed freely while unused.
Administrative (Activity log category)
Activity log event category holding all create, update, delete and action (write) operations through Resource Manager, such as creating a resource group, adding a tag or attaching a disk.
afdverify
Front Door (classic) CNAME (afdverify.<host> to afdverify.<name>.azurefd.net) that validates a custom domain without moving live traffic.
Agentless scanning (agentless machine scanning)
Defender for Cloud scanning of VM disk snapshots for vulnerabilities, software and secrets without installing an agent.
AGWFirewallLogs
Resource-specific Log Analytics table for Application Gateway WAF events; not a Front Door table.
AllMetrics
Diagnostic setting category that exports a resource's platform metrics; selecting only log categories exports no metrics.
Allow forwarded traffic
Peering setting that lets traffic forwarded by an NVA or gateway (not originating in the peer VNet) cross the peering; it doesn't make a Basic load balancer frontend reachable over global peering.
Allow gateway transit (allowGatewayTransit)
Peering setting on the gateway-owning (hub) side that lets peered VNets use its VPN or ExpressRoute gateway; it does nothing on a VNet without a gateway and pairs with Use remote gateways on the spoke.
AllowAzureLoadBalancerInBound
Default inbound NSG rule (priority 65001) allowing Azure Load Balancer health probes.
AllowInternetOutBound
Default outbound NSG rule (priority 65001) allowing outbound internet; override with a lower-numbered outbound deny.
AllowVNetInBound
Default inbound NSG rule (priority 65000) allowing traffic from the VirtualNetwork tag, including peered VNets.
AllowVnetOutBound
Default outbound NSG rule (priority 65000) letting VMs start connections to the VNet and peered VNets; the destination NSG must still allow the port.
Apex domain (root domain, zone apex)
Domain with no subdomain (example.com); it can't be a CNAME, so onboarding it to Front Door needs Azure DNS alias records or CNAME flattening.
API Management (APIM)
API gateway applying policies such as validate-jwt, ip-filter, rate limits and quotas once for all APIs; Premium tier for production VNet injection.
App registration
Entra ID object defining an application's identity, permissions and supported account types; used for OpenID Connect sign-in and multi-tenant apps.
App Service
Managed PaaS web hosting (web apps, Web App for Containers) in a sandbox with no OS access; autoscale and slots from Standard.
App Service Environment (ASE)
Single-tenant, network-isolated App Service (Isolated plan); far dearer, so only for isolation requirements.
App Service plan
Compute (region, OS, instance size and count, pricing tier) that hosts one or more apps and is the unit of billing; Windows and Linux apps need separate plans in the app's region.
Application Gateway
Regional layer-7 load balancer with SSL offload, URL routing, cookie affinity and optional WAF; plays no part in Entra SSO to on-premises apps.
Application Gateway autoscaling
V2 feature scaling instances between a minimum and maximum count (up to 125); size the subnet for the maximum count plus one per private frontend IP.
Application Gateway v1 (Standard / WAF tiers)
Original Application Gateway SKU (Standard and WAF tiers, authentication certificates) retired on 28 April 2026; a Standard_v2 gateway can't change back to it.
Application Gateway v2
Current Application Gateway SKU (Standard_v2, WAF_v2) with autoscaling, zone redundancy, static VIP, header rewrite and Key Vault integration; needs a dedicated subnet (/24 recommended).
Application rule
Azure Firewall rule filtering outbound HTTP, HTTPS and MSSQL by destination FQDN (URL filtering needs Premium); processed after DNAT and network rules.
Application security group (ASG)
Group of VM network interfaces used as a source or destination in NSG rules instead of IP addresses; each NIC must be added explicitly and all NICs must be in the same VNet.
AS path (autonomous system path)
BGP attribute listing the ASNs a route crossed; shorter wins under the AS Path preference, so a branch that prepends its ASN loses.
AS Path (hub routing preference)
Hub routing preference that picks the route with the shortest BGP AS path whatever its source; on a tie between local routes, ExpressRoute beats S2S VPN.
AS-path prepending (autonomous system path)
BGP technique that lengthens a route's AS path so the nearer site is preferred.
ASN (autonomous system number)
Identifier of a BGP routing domain; Azure VPN gateways default to 65515 (reserved, so on-premises peers need a different ASN) and the local network gateway holds the on-premises ASN.
Assignment required
Enterprise application property that limits sign-in to assigned users and groups; used on each custom-audience app to restrict which group can use which P2S gateway.
Association
Virtual hub routing setting: the one route table a connection is associated with decides which routes that connection learns.
Attack paths (attack path analysis)
Defender CSPM feature that maps exploitable chains of weaknesses leading to critical assets.
Audience
Entra ID P2S gateway field holding the Azure VPN Client app ID or a custom app's ID; a gateway supports only one Audience value.
Authentication certificate
Application Gateway v1 backend trust: the backend certificate's public key (.cer) uploaded to backend settings; replaced by trusted root certificates on v2.
Autoregistration (auto registration)
Virtual network link option that creates and maintains A records for VMs (primary NIC, Azure DHCP-assigned IP) in the linked private zone, updating or removing them as IPs change or VMs are deleted; a VNet can autoregister to only one private zone.
Availability set
VMs spread over fault domains (up to 3) and update domains (up to 20) in one datacentre; 99.95% SLA; no autoscale or zone spread.
Availability zones
Physically separate datacentres within a region; VMs across two or more give a 99.99% SLA.
AZ SKU (availability zone SKU)
Gateway SKU ending in AZ (VpnGw1AZ–5AZ, ErGw1Az–3Az) that deploys zone-redundant instances where the region supports availability zones.
AZFWThreatIntel
Resource-specific Log Analytics table for Azure Firewall threat intelligence events.
Azure Arc-enabled servers
Windows and Linux machines outside Azure connected through the Azure Connected Machine agent so they appear as Azure resources and can run AMA with DCRs.
Azure Backup
Backup service storing recovery points in a Recovery Services vault, including long-term retention; not DR failover like Site Recovery.
Azure Bastion
Brokers RDP and SSH over TLS on port 443 from the portal, so VMs need no public IPs; unlike JIT, which opens 3389/22.
Azure Content Delivery Network (CDN)
Caches static web content at edge points of presence near users; Azure CDN Standard from Microsoft (classic) accepts no new profiles and retires on 30 September 2027, so new deployments use Azure Front Door Standard or Premium.
Azure Dedicated HSM
Single-tenant Thales HSM appliance in your VNet (being retired, no new customers); Application Gateway can't use HSM-validated certificates from it.
Azure DNS
Azure's DNS hosting and resolution family: public zones, private zones and DNS Private Resolver; it is not a domain registrar.
Azure DNS name servers
The four authoritative servers (ns1-xx.azure-dns.com, .net, .org, .info) assigned to a public zone and shown on its overview page; all four go into the registrar's NS records.
Azure DNS Private Resolver
Managed DNS service in a VNet with inbound and outbound endpoints (each in its own /28-minimum subnet delegated to Microsoft.Network/dnsResolvers) that replaces DNS server VMs for hybrid resolution; a resolver can reference only a VNet in its own region.
Azure endpoint
Traffic Manager endpoint type for Azure services (web apps, public IP resources with a DNS name); not allowed in a MultiValue profile.
Azure Event Hubs
High-volume telemetry ingestion over HTTPS/AMQP; a destination for diagnostic settings.
Azure Extended Network (extended network for Azure)
Windows Admin Center feature that stretches an on-premises subnet into Azure over a VXLAN tunnel between two appliance VMs so migrated VMs keep their IPs (up to 250 addresses).
Azure Extended-Network Gateway
Azure-side appliance VM of Azure Extended Network; it must run Windows Server 2022 Datacenter: Azure Edition with two NICs (routable subnet and extended subnet).
Azure Files
Managed SMB/NFS file shares; no Archive tier and one account-wide encryption key.
Azure Firewall
Managed stateful network firewall, deployable in Virtual WAN hubs and managed by Firewall Manager.
Azure Firewall Manager
Central management of Azure Firewall policies with parent-child inheritance across regions and subscriptions.
Azure Firewall Standard
Azure Firewall SKU with network and application rules, threat intelligence filtering and DNS proxy, but no TLS inspection or IDPS.
Azure Front Door
Global layer-7 entry point with anycast failover, TLS termination, URL routing and WAF with rate limiting.
Azure Instance Metadata Service (IMDS)
Non-routable endpoint 169.254.169.254, reachable only from inside a VM, that serves VM metadata and managed-identity tokens; block it with an outbound NSG deny to the AzurePlatformIMDS tag.
Azure Internet Analyzer
Retired service that measured end-user internet performance to Azure endpoints.
Azure Key Vault (Key Vault)
Store for secrets, keys and certificates; where a same-geography pair exists it replicates there, with best-effort Microsoft-initiated failover during which the vault is read-only.
Azure KMS (Key Management Service)
Azure endpoint (azkms.core.windows.net, 20.118.99.224 and 40.83.235.53, TCP 1688) that activates Windows VMs; under forced tunnelling add UDRs for the KMS IPs with next hop Internet.
Azure Load Balancer
Regional layer-4 load balancer (Standard is zone-redundant); no WAF, TLS termination or URL routing.
Azure Monitor
Azure's unified observability service that collects, analyses and alerts on metrics, logs and traces from Azure and hybrid resources.
Azure Monitor agent (AMA)
Current agent collecting guest-OS logs according to DCRs; replaced the Log Analytics agent (MMA).
Azure Monitor Metrics
The metrics half of the Azure Monitor data platform, a time-series store of numeric values; platform metrics are collected automatically and kept 93 days.
Azure Network Adapter
Windows Admin Center feature that connects a single Windows Server to a VNet over a P2S VPN, creating the VPN gateway if missing (about 25 minutes); needs no on-premises VPN device.
Azure Policy
Enforces and audits resource configuration (location, SKU, tags) through definitions and assignments; not a deployment tool or access control.
Azure PowerShell (Az PowerShell module)
Microsoft's PowerShell modules (Az.*) for managing Azure resources, for example Set-AzStorageAccount.
Azure Private Link (Private Link)
Platform that exposes PaaS services such as Azure Storage on a private endpoint in your VNet over the Microsoft backbone; needs VNet and DNS setup and does not admit a public IP.
Azure public peering
Legacy ExpressRoute peering to Azure public endpoints, deprecated for new circuits and replaced by Microsoft peering.
Azure RBAC permission model (Key Vault)
Key Vault access granted through role assignments such as Key Vault Secrets User; replaces access policies.
Azure reserved addresses
The five addresses Azure withholds in every subnet (network address, default gateway, two for Azure DNS, broadcast), so a /29 leaves 3 usable and a /24 leaves 251; /30 and /31 IPv4 subnets aren't supported.
Azure Route Server
Managed service that exchanges BGP routes with NVAs in a VNet and programs them into VM routes; it's a control-plane service and never in the data path.
Azure SQL connection policy (Proxy / Redirect)
Azure SQL setting for whether clients connect through the gateway (Proxy) or directly to the node (Redirect); it changes routing, not access.
Azure SQL Database
PaaS single database or elastic pool; up to 4 TB (128 TB Hyperscale); no cross-database queries, SQL Agent or CLR.
Azure SQL Managed Instance (MI)
PaaS SQL Server instance with near-full compatibility (SQL Agent, CLR, cross-database queries); regional DR only via auto-failover groups.
Azure Virtual Network Manager
Central management of connectivity (hub-and-spoke or mesh) and security admin rules across VNets and subscriptions; not a packet capture or diagnostic tool.
Azure VPN Client
Microsoft VPN client app (Windows 11, macOS) required for Entra ID P2S connections; configured by importing azurevpnconfig.xml from the profile package.
Azure-provided DNS
Default VNet resolver at 168.63.129.16 that returns private DNS zone records to linked VNets; custom DNS servers must forward to it to see them.
AzureBastionSubnet
Required name of Azure Bastion's dedicated subnet, /26 or larger for every SKU since 2 November 2021 (/27 was accepted before).
AzureCosmosDB (service tag)
Service tag for Azure Cosmos DB IP ranges, usable as an outbound NSG destination and regionally scoped.
AzureFirewallManagementSubnet
Dedicated subnet, at least /26, used by the Firewall Management NIC; it needs its own public IP and a default route to the internet.
AzureFirewallSubnet
Required name of the dedicated subnet (/26 or larger) that Azure Firewall is deployed into.
AzureFrontDoor.Backend
Service tag for Front Door's origin-facing IPs; combine it in an access restriction with an X-Azure-FDID header filter to accept only your Front Door.
AzureFrontDoor.FirstParty
Service tag reserved for Microsoft services hosted on Front Door; not for locking your origin.
AzureFrontDoor.Frontend
Service tag for the IPs clients use to reach Front Door, used for outbound control.
AzureLoadBalancer (service tag)
Service tag for the Azure infrastructure load balancer (168.63.129.16) health probes only, not client traffic.
AzureMetrics
Log Analytics table that receives platform metrics exported by a diagnostic setting with AllMetrics selected.
AzureNetworkAnalytics_CL
Log Analytics table where Traffic Analytics writes NSG flow log results; fields carry type suffixes such as SubType_s, FlowType_s and FlowStartTime_t.
AzurePlatformIMDS (service tag)
Outbound-only service tag for the Instance Metadata Service (169.254.169.254); an outbound NSG deny to it blocks IMDS from the VM, while an inbound rule has no effect.
azurevpnconfig.xml
Azure VPN Client profile file inside the downloaded P2S profile package for Entra ID authentication; users import it (or it's distributed) after the gateway is configured.
B
Backend pool
Load balancer targets by NIC IP configuration (or IP); limited to one VNet, and a Standard pool can't include a VM with a Basic public IP.
Backend settings (backend HTTP settings)
Application Gateway configuration for how the gateway connects to backends: protocol, port, host name override, custom probe and backend certificate trust; reusable across rules.
Basic Load Balancer
Retired (30 September 2025) Load Balancer SKU with a backend pool limited to one availability set, scale set or standalone VM, no zones or HA Ports, Basic public IPs only and open by default.
Basic SKU public IP
Retired public IP SKU (static or dynamic, open by default) that couldn't be used with Standard Load Balancer, Bastion or Azure Firewall; retired 30 September 2025.
Bastion Developer SKU
Free Azure Bastion tier on shared infrastructure that connects to one VM at a time with no AzureBastionSubnet and no peering support; Basic, Standard and Premium need a dedicated /26-or-larger AzureBastionSubnet.
BFD (Bidirectional Forwarding Detection)
Protocol that detects link failure in under a second on ExpressRoute; enabled on MSEEs for new peerings, so you configure it on the customer edge routers and bind it to BGP.
BGP (Border Gateway Protocol)
Dynamic routing protocol used over ExpressRoute and VPN; over ExpressRoute private peering, the only way routes (including a forced-tunnelling 0.0.0.0/0) are exchanged.
BGP community
Tag value on advertised prefixes (e.g. 12076:5010 for a Microsoft service or region) that route filters and on-premises routers use to select routes.
BGP peer IP
Address a BGP speaker uses for its session: the Azure gateway gets one when BGP is enabled, and the on-premises device's internal IP goes in the local network gateway.
BGP peering with the virtual hub (hub BGP peering)
Virtual WAN feature in which an NVA in a directly connected spoke peers BGP with the hub router; its VNet connection must associate with defaultRouteTable.
BGP transit routing
VPN Gateway behaviour of re-advertising prefixes learned from one BGP peer to others, so BGP-enabled S2S and VNet-to-VNet chains reach each other (default routes aren't re-advertised).
Blob storage
Object storage for unstructured data such as video and images; block blobs up to about 190.7 TiB.
Block blob
Blob made of blocks for text and binary data, up to about 190.7 TiB; the only blob type that supports access tiers and object replication.
BlockBlobStorage
Premium SSD account for block and append blobs with lowest latency; LRS or ZRS only, no access tiers.
Bot Manager rule set (Bot Manager)
Managed WAF rule set that classifies and acts on good, bad and unknown bots.
Branch-to-branch (route exchange)
Azure Route Server setting that lets it exchange routes between NVAs and ExpressRoute and VPN gateways in the same VNet, giving ExpressRoute-to-S2S VPN transit; off by default.
BYOC (bring your own certificate)
Front Door custom-domain HTTPS using your certificate from Azure Key Vault (managed identity or registered service principal access); it can't be uploaded directly and needs a Microsoft Trusted CA chain.
C
CA (certificate authority)
Issuer of certificates; for P2S it's needed only for certificate authentication (root and client certificates), not for RADIUS or Entra ID.
Capacity unit (CU)
Application Gateway v2 billing and sizing unit: the highest of 2,500 persistent connections, 2.22 Mbps or one compute unit; each instance gives about 10 CUs.
Certificate authentication (P2S) (Azure certificate)
P2S authentication type in which the gateway trusts an uploaded root certificate and each client presents a client certificate issued from it.
CheckingEndpoint
Temporary Traffic Manager monitor status before the first probe result; the endpoint is still included in DNS responses.
ChecksFailedPercent (% Checks Failed)
Connection Monitor metric (with RoundTripTimeMs and Test Result) that Azure Monitor metric alerts fire on, e.g. to alert on an S2S VPN failure.
Child zone
Separate DNS zone for a subdomain (e.g. research.adatum.com) delegated by an NS record set of that name in the parent zone.
CIDR (Classless Inter-Domain Routing)
IP address range notation of address plus prefix length, e.g. 10.1.255.0/24.
Circuit authorization (authorization key)
Authorization a circuit owner creates to produce a key that another subscription redeems when connecting its ExpressRoute gateway; one per connection, no new circuit needed.
Client address pool
Private IP range, not overlapping the VNet or on-premises, from which P2S VPN clients get addresses; configured after the VPN gateway exists.
Cloud Device Administrator
Microsoft Entra role that enables, disables and deletes devices and reads BitLocker keys; it grants nothing on Azure resources.
Cloud security explorer
Defender for Cloud tool that runs graph queries over the cloud security graph (inventory, internet exposure, OS); it needs Defender CSPM with agentless scanning and records no traffic.
CNAME (canonical name record)
DNS alias record mapping a name to another name, such as www to <app>.azurewebsites.net; not allowed at a zone apex.
Conditional Access
Entra ID P1 policy engine that grants access with controls such as MFA or compliant device, based on conditions like named locations or risk.
Conditional forwarder
DNS server rule forwarding queries for one domain to specific servers; it gives no network reachability.
Connection (virtual network gateway connection)
Azure resource that joins a virtual network gateway to a local network gateway (IPsec), another gateway (Vnet2Vnet) or an ExpressRoute circuit; resetting it restores one tunnel without rebooting the gateway.
Connection Monitor
Network Watcher test of network paths between sources and destinations over time; source VMs must be in the monitor's region, so you need one monitor per source region.
Connection troubleshoot
Network Watcher one-off test from a VM to a VM, FQDN, URI or IP:port that reports reachability, latency and the failing hop (NSG or route).
Connectivity configuration
Azure Virtual Network Manager configuration that builds hub-and-spoke or mesh topologies (peerings or connected groups) across a network group; it doesn't make gateways exchange routes.
Connectivity provider (ExpressRoute partner)
Carrier that provisions an ExpressRoute circuit at a peering location using the service key; ExpressRoute Direct bypasses it.
Cosmos DB (Azure Cosmos DB)
Globally distributed NoSQL database with multi-region writes, automatic indexing and under 10 ms latency.
CPE (customer premises equipment)
Branch device (router or SD-WAN appliance) that connects a site to the Virtual WAN hub.
Cross-region load balancer (global load balancer)
Standard Load Balancer tier with one global anycast public frontend whose backend pool holds regional public Standard load balancers, routing to the closest healthy region; Basic isn't supported.
Custom audience (custom audience app ID)
App registration whose client ID is used as a P2S gateway's Audience, with the Azure VPN Client app added as an authorized client; one per gateway gives per-group gateway access.
Custom DNS server
DNS server IPs set on a VNet (or overriding per NIC) instead of Azure-provided DNS, e.g. domain controllers for AD DS; VMs must be able to reach its private IP.
Custom domain
Your own DNS name added to a service: bound to an App Service app so it accepts that host name (validated by a CNAME or TXT record), or verified in an Entra tenant via a TXT or MX record.
Custom health probe (custom probe)
Application Gateway probe with your own host, path, port (v2), interval and match criteria, associated with backend settings, for example to check port 8080.
Custom IPsec/IKE policy (IPsec/IKE connection policy)
Per-connection set of IKE (Phase 1) and IPsec (Phase 2) algorithms, DH and PFS groups and SA lifetimes; every parameter must be specified and one policy applies per connection, not per gateway.
Custom route table
User-created hub route table used for isolation (e.g. RT1 for a VNet group); not allowed when routing intent is enabled.
Customer edge router (CE)
Customer or partner router that peers BGP with the MSEEs; where BFD must be configured.
D
Data collection rule (DCR)
Defines what AMA or the Logs Ingestion API collects (e.g. XPath event filters) and where it goes.
DDoS Network Protection
DDoS plan applied to VNets that protects their public IPs (Basic and Standard SKU) and adds DDoS rapid response, cost protection and WAF discounts.
Default health probe
Application Gateway probe created automatically from the backend settings' protocol and port (to 127.0.0.1 unless a host is set); it can't detect failures on other ports.
Default outbound access
Implicit Microsoft-owned public IP for outbound internet from VMs with no explicit outbound method; not provided in private subnets, which are the default for VNets created after 31 March 2026.
Default route (0.0.0.0/0)
Catch-all route; on-premises routers can advertise it over ExpressRoute private peering (not Microsoft peering) via BGP, forcing internet-bound traffic from linked VNets, including gateway-transit spokes, back on-premises.
Default security rules (NSG)
Six rules every NSG gets at priority 65000-65500 (AllowVnetInBound, AllowAzureLoadBalancerInBound, DenyAllInBound and the outbound AllowVnetOutBound, AllowInternetOutBound, DenyAllOutBound); you can't delete them, only override them with custom rules numbered 100-4096.
Default Site
Local network gateway assigned to a route-based VPN gateway for forced tunnelling, receiving all internet-bound traffic; the on-premises device must accept 0.0.0.0/0 as a traffic selector.
defaultRouteTable (Default route table)
Built-in hub route table with the Default label that all connections associate with and propagate to by default; branches must associate with it.
Defender CSPM
Paid Defender for Cloud posture plan adding attack path analysis, cloud security explorer, agentless scanning and AI security posture management.
Degraded
Traffic Manager endpoint monitor status after failed health checks; the endpoint is left out of DNS responses unless every endpoint is degraded.
DenyAllInBound
Default inbound NSG rule (priority 65500) denying everything not allowed earlier, including internet traffic.
Deployment (Virtual Network Manager)
Commit of a Virtual Network Manager configuration to chosen regions (the goal state); changes take effect only after deployment, and one deployment covers all VNets in a region.
Detection mode
WAF mode that logs matches from managed and custom rules but blocks nothing.
DH group (Diffie-Hellman group)
Key-exchange group used in IKE Main Mode (Phase 1) of a custom IPsec/IKE policy, e.g. DHGroup14 or DHGroup24.
DHCP (Dynamic Host Configuration Protocol)
Azure's DHCP service hands the NIC's private IP to the guest OS, so leave the OS on DHCP and set static IPs on the Azure NIC instead.
Diagnostic setting
Routes a resource's logs and metrics to storage, Log Analytics, Event Hubs or a partner; up to five per resource.
Disconnected (peering state)
Peering status meaning the link from the other VNet was deleted and no traffic flows; fix by deleting and re-creating the peering on both VNets (not by changing address space).
DNAT rule (destination network address translation)
Azure Firewall rule that translates the firewall's public IP and port to a private IP and port and implicitly allows that traffic; always processed first.
DNS forwarding ruleset
Set of up to 1,000 domain-to-target-IP forwarding rules attached to an outbound endpoint and linked to VNets in the same region; 168.63.129.16 isn't a permitted target, and linked VNets needn't be peered to the resolver VNet.
DNS proxy
Azure Firewall setting that makes the firewall listen on port 53 of its private IP and forward queries to its configured DNS (Azure DNS by default); required for FQDNs in network rules and usable as an on-premises forwarding target.
Domain delegation
Making Azure DNS authoritative for a domain by setting the registrar's NS records to all four name servers of the Azure zone; it uses name-server names, not IP addresses.
Domain registrar
Organization that sells public domain names and holds their NS records in the parent zone; Azure DNS is not a registrar, so delegation is done at the registrar.
DRS (Default Rule Set)
Microsoft-managed WAF rule set (successor to OWASP CRS) protecting against SQL injection, XSS and other common attacks; rules can be disabled or overridden but not rate-limited.
Dual-stack
VNet or subnet carrying both an IPv4 range and an IPv6 range; every IPv6 subnet must be exactly /64, added to an existing subnet from the VNet's IPv6 address space.
E
Effective security rules
Network Watcher view listing the combined NIC and subnet NSG rules on a NIC; tests no flow.
Email Azure Resource Manager role
Action group notification that emails users or groups holding a role (Owner, Contributor, Reader, Monitoring Contributor or Monitoring Reader) assigned at subscription scope.
End-to-end TLS
Application Gateway mode that terminates client TLS and re-encrypts to the backend; backend settings must use HTTPS and trust the backend certificate.
Endpoint (Front Door)
Front Door Standard/Premium host name (<name>-<hash>.z01.azurefd.net) that custom domains CNAME to and routes attach to.
Enterprise application
Entra service-principal object where users are assigned and SSO and Conditional Access are applied.
ErGw1Az
Zone-redundant ExpressRoute gateway SKU (about 1 Gbps, like Standard); no FastPath.
ErGw2Az
Zone-redundant ExpressRoute gateway SKU matching High Performance; no FastPath.
ErGw3Az
Zone-redundant ExpressRoute gateway SKU matching Ultra Performance; supports FastPath.
ErGwScale (ExpressRoute scalable gateway)
Zone-redundant ExpressRoute gateway SKU sized in 1-Gbps scale units (1–40, fixed or autoscaling); FastPath needs at least 10 scale units.
ExpressRoute
Private dedicated connection from on-premises to Azure via private or Microsoft peering.
ExpressRoute and S2S VPN coexistence (coexisting connections)
ExpressRoute gateway plus a route-based VPN gateway (VpnGw1 or higher, not Basic) in the same VNet's GatewaySubnet of /27 or larger, with VPN as failover or for other sites.
ExpressRoute circuit
Logical connection from on-premises to Microsoft through a connectivity provider or ExpressRoute Direct, identified by a service key and carrying private and Microsoft peering.
ExpressRoute Direct
Dedicated 10 or 100 Gbps port pair directly into the Microsoft edge, bypassing a connectivity provider; the only circuit type that supports MACsec.
ExpressRoute FastPath
Sends on-premises traffic straight to VMs, bypassing the ExpressRoute gateway in the data path; needs Ultra Performance, ErGw3Az or ErGwScale with at least 10 scale units, and it doesn't speed up failover.
ExpressRoute gateway
Virtual network gateway of type ExpressRoute in GatewaySubnet that links a VNet to a circuit; a VNet can have only one, and it can't also serve as the VPN gateway.
ExpressRoute gateway migration (gateway migration experience)
Guided process that moves a Standard, HighPerformance or UltraPerformance gateway to an AZ SKU by creating a second gateway in the same GatewaySubnet; otherwise delete and recreate.
ExpressRoute gateway Standard SKU
Non-AZ ExpressRoute gateway SKU (about 1 Gbps) with no FastPath and no zone redundancy.
ExpressRoute Global Reach (Global Reach)
Add-on that links two ExpressRoute circuits' private peerings so on-premises sites exchange traffic over the Microsoft backbone; not on ExpressRoute Local, and Premium only across geopolitical regions.
ExpressRoute Local
ExpressRoute circuit SKU reaching only the one or two Azure regions in or near the peering location's metro; always Unlimited data with egress included, and no Global Reach.
ExpressRoute Standard
ExpressRoute circuit SKU reaching all Azure regions in the circuit's geopolitical region, with Metered or Unlimited data.
External endpoint
Traffic Manager endpoint type for an FQDN or IPv4/IPv6 address, including non-Azure hosts; IP-address External endpoints are the only type MultiValue accepts.
ExternalPublic
Traffic Analytics flow type for flows between an Azure VM and a non-Microsoft, non-malicious public IP; filter FlowType_s == "ExternalPublic" (FlowType in NTANetAnalytics).
F
Firewall Management NIC (previously forced tunneling mode)
Separate Azure Firewall interface in AzureFirewallManagementSubnet with its own public IP that carries the firewall's management traffic; required for forced tunnelling and can be added to an existing firewall by stopping and restarting it.
Firewall policy (Azure Firewall policy)
Resource holding Azure Firewall rules and settings that can be applied to many firewalls across regions and hubs; Standard or Premium tier.
Floating IP (direct server return)
Load-balancing rule option that keeps the frontend IP as the packet's destination so backend ports can be reused; gives no session affinity.
Flow log version 2
NSG flow log format that adds flow state and packet and byte counts per direction; B (begin) has no counts, and C (continuing) and E (end) count traffic since the previous tuple, so totals sum all C and E records.
Forced tunnelling
Sending internet-bound traffic to an on-premises or NVA next hop instead of straight to the internet; Azure Firewall supports it only with the Firewall Management NIC (AzureFirewallManagementSubnet plus a management public IP).
FQDN (fully qualified domain name)
Complete DNS name including the zone, such as www.example.com.
Front Door (classic) (Azure Front Door classic)
Original Azure Front Door tier with frontend hosts, routing rules and backend pools; no Private Link origins, no new domains, retiring 31 March 2027.
Front Door Standard (Azure Front Door Standard)
Azure Front Door tier with custom domains, routes, rule sets and custom WAF rules but no Private Link origins or managed WAF rule sets; upgrade to Premium for those.
FrontDoorAccessLog
Front Door log category recording every request (client IP, URI, status); in the AzureDiagnostics table it's queried by clientIp_s to size rate limits.
FrontDoorWebApplicationFirewallLog
Front Door log category recording requests that match a WAF rule, with the rule and action taken.
Frontend host (Front Door (classic) frontend endpoint)
Front Door (classic) host name (e.g. *.azurefd.net or a custom domain) that a WAF policy is associated with; the association alone filters nothing.
Frontend IP configuration
Load balancer IP address clients connect to, public or private; rules and inbound NAT rules reference it.
G
Gateway Load Balancer
Chains transparent third-party NVAs inline to a Standard Load Balancer frontend via VXLAN.
Gateway transit
Peering setting (Allow gateway transit on the hub, Use remote gateways on the spoke) letting peered VNets share the hub's route-based VPN or ExpressRoute gateway.
Gateway-required VNet integration
Legacy App Service outbound integration through an SSTP point-to-site VPN to a route-based virtual network gateway, for VNets in other regions; it adds gateway cost and is being retired in favour of regional VNet integration.
GatewayDiagnosticLog
VPN Gateway resource log auditing configuration changes on the gateway.
GatewayManager (service tag)
Service tag for Azure infrastructure management traffic; an Application Gateway v2 subnet NSG must allow it inbound on ports 65200-65535 (v1: 65503-65534).
GatewaySubnet
Dedicated subnet for VPN or ExpressRoute gateways; /27 recommended minimum.
General-purpose v1 (GPv1, Storage)
Legacy storage account kind (kind Storage) with no access tiers, Archive or premium file shares, retiring by October 2026; upgrade to GPv2 (irreversible) before converting to ZRS.
Geographic (routing)
Traffic Manager method sending users to endpoints by their location.
Geomatch
WAF custom rule operator that matches the client's country or region (RemoteAddr) to allow or block traffic by geography.
Geopolitical region
Group of Azure regions a Standard ExpressRoute circuit can reach; going beyond it (or Global Reach between regions) needs ExpressRoute Premium.
Get-AzLocalNetworkGateway
Az.Network cmdlet that retrieves a local network gateway object, e.g. to pass as -GatewayDefaultSite for forced tunnelling.
Get-AzVirtualNetworkGateway
Az.Network cmdlet that retrieves a virtual network gateway object; it reads but doesn't set the default site.
Global Secure Access
Microsoft's Security Service Edge umbrella for Microsoft Entra Internet Access and Microsoft Entra Private Access, managed in the Entra admin center.
Global VNet peering (global virtual network peering)
VNet peering between different Azure regions; works within one cloud but not between Azure public, Azure Government and Azure operated by 21Vianet.
Global WAF policy (Global WAF (Front Door))
WAF policy type for Azure Front Door, associated with a profile, domain or route; it can't be linked to an application gateway.
H
HA Ports (high availability ports)
Internal Standard Load Balancer rule (protocol All, port 0) balancing all TCP/UDP flows on all ports, e.g. for active-active NVAs.
Health probe
Load balancer check (TCP, HTTP or HTTPS) marking backends healthy; an HTTP probe needs HTTP 200 from its path.
High Performance (HighPerformance)
Non-AZ ExpressRoute gateway SKU with no FastPath and no zone redundancy.
HTTP listener (Application Gateway)
Application Gateway component that accepts requests on a frontend IP, port, protocol and (multi-site) host name; the per-site WAF policy scope.
Hub router (virtual hub router)
Route manager inside each virtual hub that exchanges routes with gateways, connections and BGP peers and carries VNet-to-VNet traffic.
Hub routing preference (HRP)
Virtual hub setting (ExpressRoute default, VPN or AS Path) that picks among equal-prefix on-premises routes after longest prefix match and static-over-BGP.
Hub-spoke topology (hub-spoke)
Network design where a central hub VNet holds shared services such as the firewall and gateway, and peered spoke VNets hold workloads.
Hyper-V
Microsoft's Windows hypervisor; the Azure Extended Network appliance VMs need the Hyper-V role (nested virtualization) and one external virtual switch per NIC.
Hyper-V virtual switch (external virtual switch)
Hyper-V software switch bound to a physical or virtual NIC; the Extended Network appliance needs one external switch per NIC.
I
ICMP (Internet Control Message Protocol)
Protocol used by ping; between peered VNets it's allowed by the default AllowVnetInBound NSG rule.
IDPS (intrusion detection and prevention system)
Azure Firewall Premium signature-based detection that alerts on or blocks malicious traffic; works only when a Premium policy is attached.
IKEDiagnosticLog
VPN Gateway resource log with verbose IKE/IPsec negotiation detail (proposals, SAs, PSK failures); the first place to look when a tunnel won't connect or keeps dropping.
IKEv2 (Internet Key Exchange version 2)
Standards-based IPsec protocol used for S2S tunnels and as a P2S tunnel type with certificate or RADIUS authentication; it doesn't support Microsoft Entra ID authentication.
ILPIP (instance-level public IP)
Public IP assigned directly to a VM NIC (1:1, no SNAT); a NAT gateway on the subnet takes precedence for new outbound flows, but the ILPIP still serves inbound.
Inbound endpoint
DNS Private Resolver endpoint with a private IP in its dedicated subnet that on-premises DNS targets as a conditional forwarder; it resolves against private zones linked to its VNet.
Inbound NAT rule
Port forwarding from a frontend IP:port to one VM's NIC; needs no pool, rule or probe, and two rules can't share a frontend port on the same frontend IP.
Indirect spoke
VNet peered to an NVA VNet rather than connected to the hub; reached via a hub static route to the NVA VNet connection plus a connection static route to the NVA IP, with a UDR back to the NVA.
Infrastructure rule collection (Azure Firewall)
Built-in, non-configurable collection that allows platform FQDNs; processed after application rules and before the final default deny.
Initial domain (onmicrosoft.com domain)
The <name>.onmicrosoft.com domain every Entra tenant is created with; it can't be changed or deleted and has nothing to do with App Service host names.
Insecure Protocols workbook
Microsoft Sentinel workbook that finds use of SSL/TLSv1, SMBv1, NTLMv1, unsigned LDAP binds and similar; the remediation for MCSB NS-8.
Intermediate CA certificate (Azure Firewall Premium)
Exportable CA certificate stored as a Key Vault secret that the firewall uses to issue server certificates for TLS inspection; read through a user-assigned managed identity, and clients must trust its root.
Internal load balancer (ILB)
Load balancer with a private frontend IP in a subnet, spreading traffic between tiers or for VPN users; it can't accept internet traffic.
Internet (service tag)
Service tag for public IP space outside the VNet; a deny from Internet doesn't block intra-VNet traffic.
IP configuration
Setting on a NIC that holds its private IP (dynamic or static) and optional public IP; load balancer backend pools and NAT rules reference it.
IP flow verify
Network Watcher tool that says whether a packet is allowed or denied and by which NSG rule.
IP forwarding
NIC setting that lets a VM (such as an NVA) receive and forward traffic not addressed to its own IP; required when UDRs send traffic through the appliance.
IP Group (Azure Firewall)
Reusable top-level resource holding IP addresses and ranges, used as the source of DNAT and application rules and the source or destination of network rules.
IP network rule
Storage firewall rule that allows a public IPv4 address or CIDR range, such as an on-premises egress range; up to 400 per account and not usable for private addresses.
ip-filter policy (API Management)
API Management inbound policy that allows or forbids callers by IP address or range; it applies only to APIM and can't be attached to an application gateway.
IPMatch
WAF custom-rule operator that matches the client IP against listed addresses or CIDR ranges.
IPsec (Internet Protocol Security)
Protocol suite that encrypts and negotiates S2S and VNet-to-VNet VPN tunnels.
IPsec/IKE (Internet Protocol Security / Internet Key Exchange)
Protocol suite that encrypts and negotiates S2S and VNet-to-VNet VPN tunnels.
IPv6 (Internet Protocol version 6)
128-bit addressing supported in dual-stack VNets and Standard public IPs; Bastion and Azure Firewall public IPs must be IPv4.
Issuer
Entra ID P2S gateway field set to the Secure Token Service URL https://sts.windows.net/{TenantID}/ (with trailing slash); not the login or Graph URL.
J
join/action permission (Microsoft.Network/.../join/action)
Azure RBAC action that lets an identity link a resource to another (for example a firewall to a firewall policy, subnet or public IP); Network Contributor includes it, Reader doesn't.
K
Key Vault integration (Application Gateway)
Application Gateway v2 retrieval of listener certificates from Key Vault via a user-assigned managed identity; only software-validated certificates, not HSM-validated.
KQL (Kusto Query Language)
Query language of Log Analytics and Azure Data Explorer, used for log alerts.
L
Latency sensitivity (additional latency)
Front Door origin group setting (ms, default 0) that widens the window around the fastest origin so origins within it share traffic by weight.
LinkID (linkIdentifier)
Numeric identifier of a private endpoint connection, passed in the TCP Proxy V2 header so a provider can tell consumers apart.
Listener
Application Gateway component matching frontend IP, port, protocol and host name (basic or multi-site); the HTTPS certificate and SSL profile bind here, and it carries no traffic without a rule.
Load-balancing rule
Maps a frontend IP and port to a backend pool using a health probe; the load balancer forwards only traffic a rule defines.
Local network gateway
Azure object representing the on-premises site (VPN device public IP and address prefixes) for S2S connections; not used for P2S.
Log Analytics workspace
Store for logs queried with KQL; used by Sentinel, VM insights and workspace-based Application Insights.
Logical server (Azure SQL server)
Azure SQL Database server resource holding logins, the Entra admin, firewall rules, auditing and TDE settings for its databases; not a SQL Server instance.
Longest prefix match
Azure route selection rule: when several routes match a destination, the one with the most specific prefix wins, so a 0.0.0.0/0 UDR does not capture intra-VNet traffic.
M
Managed identity
Entra identity for Azure resources with no stored secret; system-assigned or user-assigned.
Managed Instance link
Near real-time replication between SQL Server and Azure SQL Managed Instance using distributed availability groups; it plays no part in VNet access to storage.
Managed rule set
Azure-maintained WAF attack-signature rules (OWASP CRS/DRS, bot rules) that inspect request content; they don't filter by client address, geography or rate.
Match rule (WAF custom rule)
WAF custom rule type that applies one action (Allow, Block, Log or Redirect) when all its ANDed match conditions are true.
Metered data plan (MeteredData)
ExpressRoute billing model with outbound data charged per GB; can be changed to Unlimited but not back.
Metric alert
Alert rule that evaluates numeric resource metrics at regular intervals, targeted at the resource; it can't see event log entries.
Microsoft 365 (Office 365)
SaaS productivity suite using one Entra tenant; Azure RBAC does not govern its data.
Microsoft cloud security benchmark (MCSB)
Microsoft's security best-practice framework and the only standard assigned by default in Defender for Cloud (formerly Azure Security Benchmark).
Microsoft Defender External Attack Surface Management (Defender EASM)
Service that discovers an organisation's internet-facing assets (domains, hosts, IPs, ASNs, certificates) and flags their vulnerabilities, unlike Defender for Cloud, which assesses resources you connect.
Microsoft Defender for Cloud (formerly Azure Security Center)
Security posture service with a regulatory compliance dashboard that reports but blocks nothing.
Microsoft Entra application proxy (Azure AD Application Proxy)
Publishes on-premises web apps via an outbound-only connector, with no VPN or inbound ports.
Microsoft Entra Domain Services (Azure AD DS)
Managed Azure domain offering LDAP, Kerberos and NTLM, populated from Entra ID with no on-premises connectivity.
Microsoft Entra ID (Azure AD)
Microsoft's cloud identity service and tenant for Azure and Microsoft 365.
Microsoft Entra ID authentication (P2S) (Azure AD authentication)
P2S authentication type that signs users in with Entra ID (enabling Conditional Access and MFA); requires the OpenVPN tunnel type and the Azure VPN Client.
Microsoft Entra Private Access
Global Secure Access service giving users VPN-less, Conditional Access-controlled access to private apps; it doesn't route VNet-to-storage traffic.
Microsoft Entra tenant
Dedicated Entra ID directory instance with an initial .onmicrosoft.com domain chosen at creation; each Azure subscription trusts exactly one.
Microsoft Graph
API for Microsoft 365 and Entra data, authorised with delegated or application permissions, not Azure RBAC.
Microsoft network routing (Microsoft global network)
Default routing preference that brings traffic onto Microsoft's global network at the POP nearest the client for best performance.
Microsoft peering
ExpressRoute routing domain to Microsoft 365 and Azure PaaS public endpoints over public IP prefixes you own; on circuits from August 2017 no prefixes are advertised until a route filter is attached.
Microsoft Trusted CA List
List of certificate authorities whose roots Front Door accepts for BYOC certificates; private CAs such as AD CS and self-signed certificates don't qualify.
Microsoft-registered Azure VPN Client app
App ID pre-registered by Microsoft and used as the Audience for Entra ID P2S, so no manual app registration or separate admin consent is needed.
Microsoft.Authorization
Resource provider namespace for role assignments, role definitions, resource locks and policy; roleAssignments/write is held only by Owner, User Access Administrator and similar roles.
Microsoft.HybridNetwork
Resource provider namespace for Azure Network Function Manager; registering it has nothing to do with VPN Gateway.
Microsoft.Sql service endpoint
Service endpoint routing subnet traffic to Azure SQL over the backbone, bypassing forced tunnelling.
Microsoft.Storage
Service endpoint for Azure Storage; one per subnet covers every storage account in the region.
Microsoft.Storage.Global (cross-region service endpoint)
Azure Storage service endpoint reaching storage accounts in any region, unlike the regional Microsoft.Storage; a subnet can hold only one of the two.
MinChildEndpoints
Nested-endpoint setting (default 1) giving the minimum healthy child endpoints; below it the parent treats the whole child profile as degraded.
Monitoring Contributor
Azure role that reads all monitoring data and edits monitoring settings (alerts, diagnostic settings, action groups) but can't modify other resources or locks.
MPSJ (multi-plan subnet join)
App Service feature letting several App Service plans in the same subscription share one VNet integration subnet, which must be at least /26.
MSEE (Microsoft Enterprise Edge)
Microsoft edge routers where ExpressRoute circuits terminate; BGP keep-alive 60 s and hold time 180 s by default.
Multi-site listener
Application Gateway listener that routes by host name (up to five host names or wildcards on v2), letting many sites share one frontend IP and port.
MultiValue
Traffic Manager routing method returning several healthy endpoints (maximum 10) per query; only External endpoints given as IPv4/IPv6 addresses are allowed.
N
NAT gateway (Azure NAT Gateway)
Managed outbound-only SNAT for a subnet through static public IPs; the recommended explicit outbound method, allowing no unsolicited inbound connections.
NAT IP configuration (Private Link service)
Private Link service IP(s) from the provider VNet that source-NAT consumer traffic; each gives about 64,000 TCP ports per backend VM, and up to eight can be added to scale connections.
Nested endpoint
Traffic Manager endpoint type that adds a child profile to a parent profile, so two routing methods can be combined.
Nested Traffic Manager profiles
Parent profile treating child profiles as endpoints to combine routing methods (for example Geographic parent with Weighted children); each profile uses one method only.
Nested virtualization
Running Hyper-V inside a VM; the Azure Extended Network appliance VMs need it to enable the Hyper-V role.
Network Contributor
Azure built-in role for managing networking resources (Microsoft.Network/*); it lacks the storage, Log Analytics workspace and DCR actions that flow logs and Traffic Analytics need.
Network Controller
Windows Server SDN role that centrally manages virtual network infrastructure; plays no part in Azure Extended Network.
Network group
Azure Virtual Network Manager group of VNets or subnets from within the manager's scope, populated statically or dynamically through Azure Policy; out-of-scope VNets never join.
Network Performance Monitor (NPM)
Retired Log Analytics agent-based network monitoring solution, replaced by Connection Monitor.
Network rule
Azure Firewall rule filtering by IP address, port, protocol, service tag, or FQDN when DNS proxy is enabled; processed after DNAT and before application rules.
Network Watcher
Azure network diagnostics, including IP flow verify, flow logs and Connection Monitor.
Network Watcher Agent extension
VM extension (AzureNetworkWatcherExtension) used by packet capture and Connection Monitor; installs only on Azure VMs or Azure Arc-enabled servers.
NetworkAccessTraffic
Log Analytics table of Global Secure Access (Microsoft Entra Internet and Private Access) traffic events; it holds no Azure VNet flow data.
New-AzApplicationGatewayFirewallCondition
PowerShell cmdlet that creates a match condition (operator such as IPMatch or GeoMatch plus match values) from a match variable; step 2.
New-AzApplicationGatewayFirewallCustomRule
PowerShell cmdlet that creates the custom rule (name, priority, MatchRule or RateLimitRule, conditions, action); step 3.
New-AzApplicationGatewayFirewallMatchVariable
PowerShell cmdlet that creates the match variable (e.g. RemoteAddr) for an Application Gateway WAF custom-rule condition; step 1 of building a custom rule.
New-AzApplicationGatewayFirewallPolicyExclusion
PowerShell cmdlet that creates a managed-rule exclusion entry; not needed to block an IP range.
New-AzIpsecPolicy
Az.Network cmdlet that builds a custom IPsec/IKE policy (IKE encryption/integrity, DH group, IPsec encryption/integrity, PFS group, SA lifetime and size) for a connection.
New-AzIpsecTrafficSelectorPolicy
Az.Network cmdlet that defines only local and remote address ranges for a connection's traffic selectors; it has no encryption settings.
New-AzServiceEndpointPolicy
Az.Network cmdlet that creates a service endpoint policy for storage egress; unrelated to VPN connections.
New-AzVirtualHub
Az.Network cmdlet that creates a Virtual WAN virtual hub; it doesn't configure VPN connection policies.
New-AzVirtualNetworkGateway
Az.Network cmdlet that creates a VPN or ExpressRoute virtual network gateway in GatewaySubnet; it doesn't create or change a connection policy.
New-AzVirtualNetworkGatewayConnection
Az.Network cmdlet that creates an S2S (IPsec), VNet-to-VNet or ExpressRoute connection, taking -SharedKey, -IpsecPolicies, -UsePolicyBasedTrafficSelectors and -EnableBgp.
New-AzVirtualNetworkGatewayNatRule
Az.Network cmdlet that creates a NAT rule on a VPN gateway for overlapping address spaces; it doesn't set IPsec/IKE parameters.
New-AzVirtualNetworkGatewayPolicyGroup
Az.Network cmdlet that creates a P2S policy group (user group) based on identity or certificate attributes; unrelated to S2S IPsec policy.
New-AzVpnClientIpsecPolicy
Az.Network cmdlet that creates a custom IPsec policy for P2S VPN clients, applied to the gateway rather than to an S2S connection.
Next hop
Network Watcher tool returning the next hop type, IP and route table for a destination; checks routing only.
Next hop type
Where a route sends traffic: Virtual appliance (NVA or firewall private IP), Virtual network gateway, Virtual network, Internet or None.
noneRouteTable (None route table)
Built-in hub route table; propagating to it means a connection's routes are propagated nowhere.
NPS (Network Policy Server)
Windows Server RADIUS server role; the usual RADIUS server for P2S authentication against AD DS and the host for the Entra MFA NPS extension.
NS controls (network security controls)
Microsoft cloud security benchmark network domain, e.g. NS-2 secure cloud services with network controls (Private Link), NS-8 detect and disable insecure protocols (Sentinel workbook), NS-9 connect privately (ExpressRoute or VPN).
NS record
DNS name-server record used for delegation; created automatically at a zone's apex.
NSG diagnostic logging (NSG resource logs)
Network security group diagnostic log categories (NetworkSecurityGroupEvent and NetworkSecurityGroupRuleCounter) enabled with a diagnostic setting on the NSG; distinct from NSG flow logs.
NSG diagnostics
Network Watcher tool that simulates a flow and evaluates every applicable NSG and Virtual Network Manager security admin rule, returning allow or deny and the responsible rule; it also tests ICMP and scale sets.
NSG flow logs
Logs of allowed and denied traffic through NSGs over time; none can be created since 30 June 2025 and they retire on 30 September 2027, so use VNet flow logs.
NTANetAnalytics
Log Analytics table where Traffic Analytics writes virtual network flow log results, replacing AzureNetworkAnalytics_CL; fields have no type suffixes (FlowType).
NVA in the hub (integrated NVA)
Partner network virtual appliance (SD-WAN, NGFW or dual-role) deployed directly into a Virtual WAN hub, peering BGP with the hub router; one per hub.
O
Object replication
Asynchronous copy of block blobs from a source container to a destination container in another account in any region; needs versioning on both accounts and change feed on the source, and supports GPv2 and premium block blob accounts.
On-premises data gateway
Bridge for Power BI, Logic Apps and Power Apps to on-premises data; not for Data Factory.
On-Premises Extended-Network Gateway
On-premises Windows Server 2019/2022 appliance VM of Azure Extended Network, connected to a routable subnet and the subnet being extended.
OpenVPN (OpenVPN (SSL))
TLS-based P2S tunnel type over TCP 443 for Windows, macOS, Linux, iOS and Android; the only tunnel type that supports Microsoft Entra ID authentication.
OpenVPN Connect
Third-party OpenVPN client (2.x/3.x) that works with certificate-based OpenVPN P2S but not with Microsoft Entra ID authentication.
Origin
Front Door backend host (App Service app, storage, load balancer, custom host by FQDN) that serves content; an App Service app is one origin however many workers it has.
Origin group
Front Door set of origins sharing health probes and load-balancing settings (latency, priority, weight); it never selects an origin by path.
Outbound endpoint
DNS Private Resolver endpoint in its own dedicated subnet that sends queries out of Azure according to a forwarding ruleset; it has no listening IP and can't be a rule destination.
Outbound rules
Standard Load Balancer rules that give backend pool VMs explicit outbound SNAT through the frontend public IPs.
OWASP (Open Web Application Security Project)
Body behind the Top 10 attacks that WAF rules block.
P
P2SDiagnosticLog
VPN Gateway resource log of point-to-site client connection and authentication events.
Packet capture
Network Watcher capture of VM traffic with 5-tuple filters and a time limit (default 18,000 s = 5 h), using the Network Watcher Agent extension.
Peering location
Physical Microsoft edge meeting point where an ExpressRoute circuit connects; circuits have no availability-zone setting, so extra circuits don't add zone resilience.
Per-site WAF policy
WAF policy associated with an Application Gateway HTTP listener; it overrides the gateway's global policy for that site only.
Performance (routing)
Traffic Manager method sending users to the lowest-latency endpoint.
PFS group (Perfect Forward Secrecy group)
Diffie-Hellman group used in IPsec Quick Mode (Phase 2); PFS enabled on only one side is a common cause of policy-mismatch tunnel failures.
PFX (PKCS #12)
Password-protected certificate file containing the private key and chain; installs client certificates for certificate-based P2S and plays no part in Microsoft Entra ID P2S.
Platform metrics
Numeric metrics every Azure resource emits automatically at one-minute frequency with no configuration or cost; guest OS counters are not included and need an agent.
Point-to-site VPN (P2S)
VPN from individual clients to an Azure virtual network gateway; used by gateway-required VNet integration.
Policy-based traffic selectors (UsePolicyBasedTrafficSelectors)
Connection setting that lets a route-based VPN gateway connect to on-premises policy-based devices; it requires a custom IPsec/IKE policy and the device must support IKEv2.
Policy-based VPN
VPN type that uses static traffic selectors (prefix pairs) instead of any-to-any routing; supports no BGP, P2S or transit, so a route-based gateway reaches such devices with policy-based traffic selectors.
Prevention mode
WAF mode that blocks requests matching managed or custom rules and logs them.
Priority (routing)
Traffic Manager active/passive failover method that fails away from unhealthy endpoints.
Private Application Gateway deployment (private-only frontend)
V2 deployment with only a private frontend IP and no public IP resource, removing the GatewayManager inbound and outbound Internet NSG requirements.
Private DNS zone
Azure DNS zone linked to a VNet holding private A records; queryable only via 168.63.129.16, so on-premises needs a forwarder or DNS Private Resolver.
Private DNS zone group (DNS zone group)
Private endpoint child resource that binds it to up to five private DNS zones and automatically creates, updates and deletes its A records.
Private endpoint
NIC with a private IP from your subnet that connects to one specific service instance through Private Link; each endpoint consumes one subnet IP, endpoints can share a subnet, and it is reachable from peered VNets and on-premises.
Private endpoint connection
Approval record on the target resource for a private endpoint (Pending, Approved, Rejected or Disconnected); consumers without permission on the resource, such as another tenant, stay Pending until the owner approves.
Private endpoint network policies (PrivateEndpointNetworkPolicies)
Subnet setting (Disabled by default, NetworkSecurityGroupEnabled, RouteTableEnabled or Enabled) that must be turned on before NSGs or UDRs apply to private endpoint traffic; subnet delegation doesn't do this.
Private Link origin (Front Door managed Private Link)
Front Door Premium feature where Front Door creates a managed private endpoint to your origin (App Service, Storage, internal load balancer), which the origin owner must approve.
Private Link service
Your own service published behind a Standard Load Balancer frontend IP so consumers reach it through private endpoints; not used to expose PaaS services such as Azure SQL Database.
Private Link service alias (alias)
Globally unique read-only name Azure generates for a Private Link service, which the provider shares so consumers can request a private endpoint connection with it or the resource ID.
Private peering (Azure private peering)
ExpressRoute routing domain that connects on-premises networks to Azure VNets over private IP addresses; not encrypted unless you add IPsec or MACsec.
privatelink zone
Private DNS zone named after a service's privatelink CNAME target (e.g. privatelink.database.windows.net for Azure SQL Database) that holds the private endpoint's A record; don't name the zone after the public suffix (database.windows.net).
Propagation
Virtual hub routing setting: the route tables or labels a connection propagates to learn its prefixes.
Provider status (ServiceProviderProvisioningState)
Provider-side circuit state (Not provisioned, Provisioning, Provisioned); must be Provisioned before peering is configured.
PTR record
Reverse-lookup DNS record mapping an IP to a name; not supported by private zone autoregistration.
Public DNS zone
Azure DNS zone hosting internet-resolvable records for a domain; creating one doesn't make it authoritative until the registrar's NS records point to its four Azure name servers, and it can't autoregister VMs.
Public IP address
Azure resource holding an internet-routable IPv4 or IPv6 address that you associate with a NIC, load balancer, gateway, firewall or Bastion; its SKU sets allocation, zone support and default security.
Public IP address prefix (public IP prefix)
Reserved contiguous range of Standard static public IPs (up to /28 by default) that can supply a load balancer outbound rule or NAT gateway with more addresses.
Public IP SKU upgrade
In-place, irreversible Basic-to-Standard upgrade that keeps the address, allowed only for a static Basic public IP that is dissociated from any resource; re-associate it afterwards.
Public load balancer
Load balancer with a public frontend IP for internet-facing Layer 4 traffic; Standard needs Standard SKU public IPs.
Public network access
Storage account setting (Enabled from all networks, from selected networks, or Disabled) that governs only the public endpoint; private endpoints still work when it is disabled.
R
RA-GRS (read-access geo-redundant storage)
GRS plus a read-only secondary endpoint usable without failover.
RADIUS authentication (Remote Authentication Dial-In User Service)
P2S authentication type in which the VPN gateway forwards credentials to a RADIUS server (such as NPS) that checks them against on-premises AD DS.
Rate limiting (WAF)
Custom WAF rule type that throttles or blocks clients exceeding a request threshold, optionally combined with conditions such as geo-match; managed rule sets can't do this.
RBAC (role-based access control)
Azure role assignments governing who can manage resources, inherited down scopes; not where or what size resources are.
RDP (Remote Desktop Protocol)
Windows remote-session protocol on port 3389; Bastion carries it over TLS on 443.
Reader
Built-in role that can view resources but not write to or join them (e.g. can't associate a firewall policy).
Real User Measurements (RUM)
Traffic Manager feature where client JavaScript reports latency to Azure regions, improving the latency table used by Performance routing only.
Regional service tag
Service tag narrowed to one region by a suffix, e.g. Sql.EastUS or Storage.WestUS; the unsuffixed tag covers every region in the cloud.
Regional VNet integration
Outbound App Service access into a VNet (Basic tier up) via a subnet delegated to Microsoft.Web/serverFarms; inbound access needs a private endpoint.
Regional WAF policy (Regional WAF (Application Gateway))
WAF policy type for Application Gateway, created in the gateway's region and associated globally, per listener or per path; it can be created before the gateway exists.
Registration virtual network
VNet linked to a private DNS zone with autoregistration on; a zone can have many, but each VNet can have only one registration zone (other links are resolution-only).
Regulatory compliance dashboard
Defender for Cloud view reporting against standards such as ISO 27001 and PCI DSS; it blocks nothing.
RemoteAddr
WAF match variable for the original client IP, usually taken from X-Forwarded-For; used with IPMatch or GeoMatch.
Request routing rule
Application Gateway rule binding one listener to a backend pool and backend settings, either basic or path-based through a URL path map.
RequestHeader (match variable)
WAF custom-rule match variable that inspects a named request header (e.g. X-Azure-FDID, or Contains a value for a header-based redirect).
Reset a connection (connection reset)
Operation that resets and restores one gateway connection without rebooting the gateway; the least disruptive first step for one failed branch tunnel.
Reset a VPN gateway
Operation that reboots the gateway's instances and reapplies configuration, briefly dropping every tunnel; it doesn't update P2S client routes.
Resource group (RG)
Container for resources whose location stores only metadata; its location can't change and it can't nest.
Resource locks
CanNotDelete or ReadOnly locks on management-plane operations; they do not restrict regions or sizes or protect blob data.
Resource logs
Per-resource platform logs of operations inside a resource; they aren't collected or stored until a diagnostic setting routes them somewhere.
Resource Policy Contributor
Azure role that creates and assigns policy and initiative definitions; Contributor lacks policyDefinitions/write.
Resource provider
Service that supplies Azure resource types under a namespace such as Microsoft.Compute or Microsoft.Network; role actions are written as namespace/resourceType/operation.
Resource-specific tables
Diagnostic-setting destination mode that writes each log category to its own table (for example AZFWNetworkRule for Azure Firewall) instead of the shared AzureDiagnostics table.
ResponderOnly
VPN connection mode in which the Azure gateway never initiates the tunnel and only answers the peer; it doesn't provide policy-based compatibility.
Rewrite rules (Application Gateway header and URL rewrite)
Application Gateway v2 rule sets that modify request/response headers and URLs; they don't apply to redirects or to 4xx/5xx responses the gateway generates itself.
Rewrite set
Application Gateway v2 collection of rewrite rules that add, remove or change request and response headers and rewrite URL path and query string; it doesn't choose the backend.
Route (Front Door)
Front Door Standard/Premium object linking domains, protocols and patterns to match to one origin group; exact path wins, then the longest wildcard.
Route filter
Resource attached to ExpressRoute Microsoft peering that allow-lists BGP community values so only the chosen services' prefixes are advertised; it can't inject a default route into private peering.
Route table
Resource holding UDRs, associated with subnets; it affects traffic leaving those subnets (associate it with GatewaySubnet to steer inbound VPN traffic).
Route table label (label)
Logical group of hub route tables (e.g. Default spans every hub's defaultRouteTable) used as a propagation target.
Route-based VPN
VPN gateway type using routing tables and any-to-any traffic selectors; required for P2S, gateway transit and BGP, and the only type the portal creates.
RouteDiagnosticLog
VPN Gateway resource log recording static route changes and BGP events such as learned routes.
Routing intent (routing policies)
Virtual WAN hub setting that sends private and/or internet traffic to Azure Firewall, an NGFW NVA or SaaS in the hub, securing inter-hub and branch-to-branch traffic without custom route tables.
RRAS (Routing and Remote Access Service)
Windows Server Remote Access role for VPN and routing; it can't route between overlapping subnets, so it doesn't replace Azure Extended Network.
Rule 920300 (Request Missing an Accept Header)
CRS protocol-enforcement rule that fires when a request has no Accept header (403 in Prevention mode); fix by disabling the rule or sending the header, since exclusions can't satisfy a missing header.
Rule collection
Group of security admin rules inside a security admin configuration, targeted at one or more network groups; rules with different destination prefixes can share one collection.
Rule collection group
Container in a firewall policy that groups rule collections; priority orders groups and same-type collections, but DNAT, then network, then application rules always run in that order.
Rule processing order (Azure Firewall)
Threat intelligence filtering (when enabled) runs first, then DNAT, network and application rules, the infrastructure rule collection and finally default deny.
Rule set (Front Door Rules Engine)
Front Door rules engine that modifies headers, redirects, rewrites URLs and overrides routing or caching after WAF processing; it has no rate-limit action.
Rule set (Front Door)
Front Door Standard/Premium rules applied after a route matches, able to modify requests or override the origin group; it doesn't give an origin a private endpoint.
S
S2S VPN (site-to-site VPN)
IPsec/IKE tunnel over the internet between an on-premises VPN device and a VNet's VPN gateway, needing a local network gateway and a connection; cheaper than ExpressRoute.
SA lifetime (security association lifetime)
Time (seconds) or data (KB) after which an IPsec SA is rekeyed; set in the IPsec part of a custom policy, while the IKE Main Mode SA is fixed at 28,800 seconds on Azure.
Scale unit (gateway scale unit)
Virtual WAN gateway capacity unit: 1 S2S VPN unit is 500 Mbps and 1 ExpressRoute unit is 2 Gbps, set separately per gateway type on the existing hub gateway.
SD-WAN (software-defined WAN)
Vendor overlay that links branches over multiple transports with central path selection; in Virtual WAN it terminates on an SD-WAN NVA in the hub, not on Microsoft's VPN or ExpressRoute gateways.
SD-WAN NVA
Integrated connectivity NVA in a Virtual WAN hub that terminates vendor SD-WAN tunnels from branch CPEs and exchanges routes with the hub router over BGP.
Secure transfer required (supportsHttpsTrafficOnly)
Storage account setting that rejects unencrypted HTTP (and unencrypted SMB) requests; it forces HTTPS only and does not restrict networks.
Secured virtual hub
Virtual WAN hub made Secured by Azure Firewall Manager deploying Azure Firewall or a security partner provider (SECaaS) into it; Front Door, NAT Gateway or WAF don't secure a hub.
Security admin configuration
Azure Virtual Network Manager configuration holding one or more rule collections of security admin rules; only one can be deployed per region, so add rule collections instead of more configurations.
Security admin rule
Azure Virtual Network Manager rule evaluated before any NSG rule, with actions Allow (continue to NSGs), Always allow (skip NSGs) or Deny (block regardless of NSGs).
Security partner provider (SECaaS)
Third-party security-as-a-service (e.g. Zscaler) deployed into a hub via Azure Firewall Manager to filter internet traffic, connecting through the hub's VPN gateway; makes the hub Secured.
Security policy (Front Door)
Front Door Standard/Premium resource associating a WAF policy with domains (or the profile or routes).
Security rule priority (NSG)
Number from 100 to 4096 that orders NSG rules within one direction; the lowest number is evaluated first and processing stops at the first match, so an allow must have a lower number than the deny it carves out.
SecurityDetection
Log Analytics security table populated by Microsoft Defender for Cloud detections; unrelated to Front Door traffic.
Server Manager
Windows Server console for managing roles and features on servers; Azure Extended Network is deployed from Windows Admin Center, not Server Manager.
Server variables
Application Gateway variables such as add_x_forwarded_for_proxy, client_ip, client_port and host usable in rewrite conditions and actions.
Service endpoint
Routes a subnet's traffic to a service's public endpoint over the Azure backbone with the subnet as source identity; it consumes no subnet IPs, is free, and isn't usable from on-premises.
Service endpoint policies
Policy on a subnet's service endpoint that limits egress to specific Azure resources (for example named storage accounts); generally available only for Azure Storage.
Service key (s-key)
GUID that identifies an ExpressRoute circuit and is given to the connectivity provider; not a security secret, and billing starts when it's issued.
Service principal
App-registration identity with a stored secret or certificate that must be rotated and can be copied; suits code outside Azure.
Service tag
Microsoft-maintained group of IP prefixes for an Azure service (e.g. Storage, AzureKeyVault, optionally regional) usable as an NSG source or destination.
Session persistence
Load Balancer distribution mode: None (5-tuple hash, default), Client IP (2-tuple) or Client IP and Protocol (3-tuple) affinity.
Set-AzApplicationGateway
Az.Network cmdlet that commits changes made to an application gateway object to Azure.
Set-AzApplicationGatewayFirewallPolicy
PowerShell cmdlet that saves changes (custom rules, managed rules, policy settings) to an Application Gateway WAF policy; the final step.
Set-AzApplicationGatewayIPConfiguration
Az.Network cmdlet that changes the gateway IP configuration (the subnet) on the in-memory gateway object; commit with Set-AzApplicationGateway.
Set-AzFirewallPolicy
Az.Network cmdlet that updates an Azure Firewall policy; unrelated to VPN connection policies.
Set-AzVirtualNetworkGateway
Az.Network cmdlet that updates the virtual network gateway itself (e.g. P2S address pool, protocols, RADIUS or client IPsec policy), not a connection's IPsec policy.
Set-AzVirtualNetworkGatewayConnection
Az.Network cmdlet that changes an existing connection, e.g. applies -IpsecPolicies or enables policy-based traffic selectors; it doesn't set a gateway's default site.
Set-AzVirtualNetworkGatewayDefaultSite
Az.Network cmdlet that assigns a local network gateway as the forced-tunnelling Default Site of a route-based VPN gateway (-GatewayDefaultSite, -VirtualNetworkGateway).
Set-AzVirtualNetworkSubnetConfig
Az.Network cmdlet that updates a subnet's configuration in a VNet object; it doesn't set a VPN gateway's default site.
SFTP (SSH File Transfer Protocol)
File transfer protocol over SSH (TCP 22); non-HTTP, so Application Gateway doesn't suit it.
SIEM (security information and event management)
Security log collection, correlation and alerting platform; Microsoft Sentinel is Azure's cloud SIEM on a Log Analytics workspace.
SMTP (Simple Mail Transfer Protocol)
Email transfer protocol on TCP port 25.
SNAT (source network address translation)
Rewriting a flow's source address; Azure Firewall automatically SNATs outbound internet traffic to its public IP (no separate enable step), and a NAT gateway only adds SNAT ports.
SNAT port exhaustion
Outbound connection failures when a source runs out of SNAT ports for new flows to the same destination; fix it on a NAT gateway by adding public IPs or a prefix, not by binding more subnets.
SNAT ports
Ephemeral ports used for outbound SNAT; each public frontend IP gives about 64,000, shared across the backend pool, so only more frontend IPs (or a prefix) raise the total.
SOA record (start of authority record)
DNS record created and managed automatically at every Azure zone apex (its host can't be changed); nothing needs changing at the registrar for it.
SocketAddr
Front Door WAF match variable for the source IP the WAF actually sees (a proxy's address if the client is behind one); used for geo-filtering and rate limiting.
Split-horizon DNS (split-brain DNS)
Public and private Azure DNS zones with the same name: internet clients get the public zone, linked VNets get the private zone, and private records are never resolvable from the internet.
Sql (service tag)
Service tag for Azure SQL Database, Azure Database for MariaDB and Azure Synapse Analytics IP ranges (outbound); it represents the service, not a specific server, and doesn't cover SQL Managed Instance.
SQL FQDN filtering
Azure Firewall application rules that allow specific SQL servers by FQDN (e.g. sqldb1.database.windows.net); supported only when Azure SQL uses the Proxy connection policy on port 1433.
SQL injection
Web attack inserting SQL into requests; detected by WAF managed rule sets, not by NSGs or custom geo/IP rules.
SRV record
DNS service-location record, e.g. the domain controller records AD DS clients need; Azure-provided DNS can't serve AD's SRV records.
SSL (Secure Sockets Layer)
TLS's predecessor; in VPN Gateway, "SSL" labels the TLS-based P2S tunnel types OpenVPN (SSL) and SSTP (SSL), which use TCP 443.
SSL profile
Application Gateway v2 listener-level settings holding the client authentication (trusted client CA chain for mutual TLS) and a listener-specific SSL policy.
SSTP (Secure Socket Tunneling Protocol)
Microsoft TLS-based P2S tunnel type for Windows clients only, limited to 128 connections and supporting certificate or RADIUS authentication but not Entra ID; being retired in favour of IKEv2/OpenVPN.
Standard general-purpose v2 (StorageV2, GPv2)
Standard account for all storage services with access tiers and every redundancy option.
Standard SKU public IP
Static-only public IP that can be zonal, zone-redundant or IPv6 and is closed to inbound traffic until an NSG allows it; required by Standard Load Balancer, Bastion, Azure Firewall and VPN gateways.
Standard V2 (Standard_v2)
Application Gateway tiers: Basic (no URL rewrite, no WAF), Standard_v2 (rewrites, no WAF) and WAF_v2 (adds WAF); a WAF policy can attach only to WAF_v2.
StandardV2 NAT gateway (NAT Gateway V2)
Zone-redundant NAT gateway SKU adding IPv6, flow logs and higher throughput; it requires StandardV2 public IPs or prefixes and can't be upgraded from Standard.
StandardV2 public IP
Zone-redundant public IP or prefix SKU usable only with a StandardV2 NAT gateway; Standard public IPs can't attach to StandardV2.
Start-AzApplicationGateway
Az.Network cmdlet that starts a stopped application gateway.
Static allocation
Public or private IP assignment that keeps the address until the resource is deleted; Standard public IPs are static only, and a Basic public IP must be static before it can be upgraded.
Static route (Virtual WAN)
Route added to a hub route table or a virtual network connection with a next hop of a connection, Azure Firewall or an NVA IP; used to reach indirect spokes behind an NVA.
Stop-AzApplicationGateway
Az.Network cmdlet that stops an application gateway, required before moving it to another subnet.
Storage (service tag)
Service tag for Azure Storage's IP ranges (outbound); it covers the service, not a specific account.
Storage account
Top-level Azure Storage resource providing a unique namespace for blob, file, queue and table data; its kind, performance and location are fixed at creation.
Storage firewall
Storage account network rules (VNet, IP, resource instance and trusted-service rules) limiting its public endpoint; with none set, any network can reach it.
Subnet
Range of a VNet's address space where resources get private IPs; Azure reserves 5 addresses in each (first four and last), so /24 gives 251 usable and the smallest IPv4 subnet, /29, gives 3.
Subnet (Traffic Manager routing)
Traffic Manager routing method mapping client source IP ranges to a specific endpoint; returns a single endpoint per query.
Subnet delegation
Designates a subnet for one Azure service (e.g. Microsoft.Web/serverFarms for App Service VNet integration); the subnet must not already contain other resources such as VMs.
System route
Default route Azure creates for every subnet, e.g. VNet-local traffic and 0.0.0.0/0 to Internet; overridden by UDRs.
System-assigned managed identity
Identity created and deleted with one resource; ten VMs get ten identities; Azure Policy remediation can use one.
T
Target sub-resource
The storage service (blob, dfs, file, queue, table, web) a private endpoint connects to; one endpoint per type covers every container or share of that type, and ADLS Gen2 needs both dfs and blob.
TCP (Transmission Control Protocol)
Connection-oriented transport protocol.
TCP Proxy V2 (EnableProxyProtocol)
Private Link service setting that adds a proxy protocol v2 header carrying the consumer's source IP and private endpoint LinkID; it adds no connection capacity.
Tenant (P2S)
Entra ID P2S gateway field set to https://login.microsoftonline.com/{TenantID} for Azure public cloud; never graph.microsoft.com.
Test group
Connection Monitor unit combining sources, destinations and test configurations (TCP, ICMP or HTTP); one monitor per source region holds the test groups.
Threat intelligence-based filtering
Azure Firewall feature (Standard and Premium) that alerts on or denies traffic to and from known malicious IPs and domains from Microsoft's threat intelligence feed.
TLS (Transport Layer Security)
Encryption for network traffic, e.g. Bastion sessions on port 443.
TLS inspection
Azure Firewall Premium feature that decrypts, inspects and re-encrypts outbound and east-west TLS traffic using an intermediate CA certificate from Key Vault.
TLS termination (SSL offload)
Decrypting TLS at a gateway such as Application Gateway so backend servers receive plain HTTP (or re-encrypt for end-to-end TLS).
Traffic Analytics
Analyses NSG or VNet flow logs into traffic patterns and top talkers; does not evaluate rules.
Traffic Manager
Global DNS-based routing (priority, performance, weighted, geographic) for any protocol; never sees HTTP and stores no content.
Traffic selector
Pair of local and remote prefixes an IPsec tunnel is allowed to carry; route-based gateways propose any-to-any, policy-based devices need every prefix pair.
Transparent proxy
Azure Firewall's default mode for application rules: clients send traffic through it via UDRs without proxy settings; it's not a reverse proxy for inbound web traffic.
Trusted root certificate
Application Gateway v2 backend trust: the root CA certificate (.cer) of the backend certificate in backend settings; not needed for certificates from well-known CAs.
Tunnel type
P2S gateway setting (OpenVPN, IKEv2, SSTP or combinations) that must match the client software; Microsoft Entra ID authentication applies only to OpenVPN connections.
TunnelDiagnosticLog
VPN Gateway resource log of historical tunnel connect/disconnect events, useful to time outages before drilling into IKEDiagnosticLog.
U
UDP (User Datagram Protocol)
Connectionless transport protocol.
UDR (user-defined route)
Static route-table entry, e.g. next hop virtual network gateway; not dynamic like BGP.
Ultra Performance (UltraPerformance)
Non-AZ ExpressRoute gateway SKU that supports FastPath; more throughput doesn't speed up failure detection.
Unlimited data plan (UnlimitedData)
ExpressRoute billing model with inbound and outbound data included in the monthly fee; the only plan for ExpressRoute Local.
URL path-based routing
Application Gateway rule that sends requests to different backend pools based on the URL path (for example /images/* and /videos/*).
Usage + quotas
View of deployed network resources against subscription and region limits; it shows limits only and records no traffic.
Use Azure Private IP Address
VPN connection option that terminates the tunnel on the gateway's private IP for IPsec over ExpressRoute private peering; it doesn't make a route-based gateway work with policy-based devices.
Use remote gateways
Spoke-side peering option to send traffic through the peered hub's gateway; affects gateway transit only, not VM-to-VM traffic across the peering.
User Access Administrator
Azure role that manages access (Microsoft.Authorization/*, so role assignments and management locks) but can't manage other resources; least privilege for creating or deleting locks.
User VPN (point-to-site in Virtual WAN)
Virtual WAN point-to-site gateway and configuration for individual clients; needs a Standard WAN and isn't how branch offices connect.
User-assigned managed identity
Standalone identity attached to many resources, so roles are granted once.
V
Virtual hub (hub)
Microsoft-managed VNet in a Virtual WAN (one per region) that hosts the VPN, ExpressRoute and User VPN gateways and the hub router.
Virtual network connection (hub virtual network connection)
Link between a VNet and a Virtual WAN hub carrying routing settings (association, propagation, static routes); the VNet can't have its own virtual network gateway.
Virtual network flow logs (VNet flow logs)
Network Watcher logs of flow-level (not packet) traffic enabled on the VNet, written to a storage account and used by Traffic Analytics; replace NSG flow logs.
Virtual network gateway
Azure gateway resource in GatewaySubnet, either VPN or ExpressRoute type; as a UDR next hop it sends traffic to on-premises.
Virtual network link
Link between a private DNS zone and a VNet, needed for resolution (resolution-only link) or registration (autoregistration on); peering alone gives neither.
Virtual network peering (VNet peering)
Private, low-latency connection between VNets in the same or different regions over the Microsoft backbone; on its own it gives App Service no VNet access.
Virtual network rule (VNet rule)
Storage firewall rule that admits a specific subnet, which must have the Microsoft.Storage service endpoint enabled; the endpoint alone grants nothing.
Virtual WAN
Hub-based networking; Basic supports site-to-site VPN only, Standard adds ExpressRoute, point-to-site and transit.
Virtual WAN Basic
Virtual WAN type with Basic hubs supporting site-to-site VPN only (no ExpressRoute, User VPN or full transit); can be upgraded to Standard but not downgraded.
Virtual WAN Standard
Virtual WAN type adding ExpressRoute, User VPN, full any-to-any transit, hub-to-hub links, Azure Firewall and NVAs in the hub.
Virtual WAN static route
Route on a Virtual WAN hub route table or virtual network connection sending prefixes to a next hop such as an NVA IP in a spoke VNet; the static route belongs on the connection of the VNet hosting the NVA.
VirtualNetwork (service tag)
Service tag covering the VNet address space, peered VNets and connected on-premises ranges.
VM scale set (VMSS)
Group of load-balanced VMs with autoscale, in Uniform or Flexible mode.
VMProtectionAlerts
The only resource log category of a virtual network (the allLogs group); NetworkSecurityGroupEvent and NetworkSecurityGroupRuleCounter belong to NSGs.
VNet (virtual network)
Private network in one subscription and one region that spans all the region's availability zones; VMs must use a VNet in their own region.
VNet peering (virtual network peering)
Private, low-latency connection between VNets over the Microsoft backbone, across subscriptions and tenants; it is not transitive, so spokes peered to one hub can't reach each other without a direct peering or a hub NVA/firewall plus UDRs.
VNet-to-VNet connection (Vnet2Vnet)
IPsec/IKE connection between two Azure VPN gateways; with BGP enabled on it, chained VNets and sites learn each other's prefixes.
VNet-to-VNet VPN (VNet-to-VNet connection)
Encrypted IPsec/IKE connection between the VPN gateways of two VNets; it needs a gateway in each VNet and costs more with higher latency than VNet peering.
VPN (virtual private network)
Encrypted tunnel, e.g. site-to-site to a VPN gateway in GatewaySubnet.
VPN client profile configuration package (VPN client configuration package)
Zip generated from the gateway's P2S settings; Windows clients hold only the routes present when it was generated, so re-download and reinstall it after any peering or topology change.
VPN configuration file
File downloaded from a hub's VPN (Site to site) page with the hub gateway instance IPs, connected address spaces and connection settings for configuring the on-premises device.
VPN gateway
Virtual network gateway of type VPN in GatewaySubnet for S2S, P2S and VNet-to-VNet IPsec tunnels; its Standard static public IP is fixed at creation and can't be swapped.
VPN Gateway Basic SKU
Development-only VPN gateway SKU (10 S2S tunnels, 100 Mbps) with no BGP, no zone redundancy, no ExpressRoute coexistence and no OpenVPN/Entra ID P2S; the only SKU allowed a /29 GatewaySubnet.
VPN gateway health probe
HTTPS endpoint https://<gateway public IP>:8081/healthprobe that answers if the gateway is healthy; the second active-active instance answers on port 8083.
VPN Gateway NAT (NAT rule)
VPN gateway feature that translates overlapping on-premises or VNet prefixes on S2S connections via ingress and egress NAT rules.
VPN site
Virtual WAN object describing an on-premises VPN device (public IP, address space, links, optional BGP) that you connect to a hub's S2S VPN gateway.
VPN troubleshoot
On-demand Network Watcher diagnosis of a route-based VPN gateway or connection that writes logs to a storage account; it can't raise alerts and doesn't support ExpressRoute.
Vpnconfig.ovpn
OpenVPN client profile file in the P2S package, used with OpenVPN Connect for certificate authentication; not used for Entra ID P2S.
VpnGw1
Lowest non-Basic VPN gateway SKU (30 S2S tunnels, BGP); the minimum for ExpressRoute coexistence and OpenVPN/Entra ID P2S, and new deployments use VpnGw1AZ instead.
VpnGw1AZ
Zone-redundant VPN gateway SKU (Generation1, up to 30 S2S tunnels, 650 Mbps); AZ SKUs keep tunnels up if a zone fails and are the recommended SKUs for new gateways.
VpnGw2AZ
Zone-redundant VPN gateway SKU with up to 30 S2S tunnels (1–1.25 Gbps); the AZ suffix means gateway instances spread across availability zones.
VpnGw3AZ
Zone-redundant VPN gateway SKU with up to 30 S2S tunnels (up to 2.5 Gbps on Generation2); the highest AZ SKU capped at 30 tunnels.
VpnGw4AZ
Zone-redundant Generation2 VPN gateway SKU with up to 100 S2S tunnels (5 Gbps); the cheapest SKU for more than 30 zone-redundant tunnels.
VpnGw5AZ
Zone-redundant Generation2 VPN gateway SKU with up to 100 S2S tunnels (10 Gbps); valid for 31–100 tunnels but dearer than VpnGw4AZ.
VXLAN (Virtual Extensible LAN)
Layer-2-over-UDP encapsulation; Azure Extended Network tunnels the stretched subnet between its two appliances with VXLAN (UDP 4789), and Gateway Load Balancer uses it to chain NVAs.
W
WAF custom rules
User-defined WAF rules (match or rate-limit type) evaluated before managed rules, using conditions such as IP, geo-location, headers or URI.
WAF exclusion (exclusion list)
Removes a named request attribute (header, cookie or argument, selected with Equals, Starts with, Ends with, Contains) from managed-rule inspection; it can't match on a client IP or satisfy a rule that fires on a missing header.
WAF policy
Resource holding WAF managed and custom rules, associated with a Front Door endpoint or Application Gateway, never directly with a web app or Azure Firewall.
WAF V2 (WAF_v2)
Application Gateway tier (WAF_v2; the v1 WAF tier retired on 28 April 2026) adding OWASP Core Rule Set protection; the Standard tier has no WAF.
Web Application Firewall (WAF)
Layer-7 protection against OWASP Top 10 attacks such as SQL injection and XSS, on Front Door or Application Gateway.
Web categories (Azure Firewall)
Application-rule destinations such as gambling or social networking; Standard classifies by FQDN only, Premium by full URL.
Wildcard certificate
TLS certificate for *.domain that covers any single-level subdomain (for example new host names on a listener) but not the apex or deeper subdomains.
Windows Admin Center (WAC)
Browser-based Windows Server management tool whose extensions set up Azure Network Adapter (P2S from one server) and Azure Extended Network; not the Azure portal.
Windows Server 2022 Datacenter: Azure Edition (Azure Edition)
VM-only Windows Server edition optimized for Azure (Hotpatch, SMB over QUIC, Extended Network); the only edition the Extended network wizard lists for the Azure appliance.
Workbook (Azure Workbooks)
Azure Monitor interactive report combining logs, metrics and text; not a prerequisite for Traffic Analytics.
X
X-Azure-FDID
HTTP header carrying the Front Door profile ID, used to restrict an origin to one specific Front Door instance.
X-Forwarded-For (XFF)
HTTP header listing the client IP:port chain; Application Gateway appends client IP and port, and rewriting it to add_x_forwarded_for_proxy or client_ip removes the port.
X-Forwarded-Host
HTTP header carrying the original host name requested by the client; it doesn't carry the client port.
Z
Zonal
Deployment pinned to one availability zone (e.g. a Standard NAT gateway); it still serves resources in its subnets in other zones but fails with its own zone.
Zone transfer (AXFR/IXFR)
Copying a DNS zone to secondary servers; Azure DNS public and private zones don't support it, so secondary or stub zones on-premises can't hold an Azure zone.
Zone-redundant
Deployment spread across all availability zones in a region so it survives a zone loss, e.g. a StandardV2 NAT gateway.
Zone-redundant gateway
Virtual network gateway (AZ SKU with a Standard zone-redundant public IP) whose instances are spread across availability zones; this, not extra ExpressRoute circuits, gives zone resilience.
Zscaler
Security partner provider that can be deployed into a secured virtual hub through Azure Firewall Manager.
ZZ (country code) (Unknown country/region)
Geo-match value for IP addresses not yet mapped to a country; include it in negated geo rules to avoid blocking legitimate users.