Both connect your on-premises network to Azure, but one runs encrypted over the internet and the other runs privately through a provider. How each works, the SKU changes, encryption, failover, Virtual WAN and three exam traps.
By Tony Rough
Your datacentre needs to talk to your Azure virtual networks. Azure gives you two main ways to do it: Azure VPN Gateway or ExpressRoute. The difference is the path your traffic takes.
It’s the cheaper, quicker option: Learn puts gateway provisioning at about 45 minutes.
An ExpressRoute circuit connects you to Microsoft at a peering location, with two connections to two Microsoft edge routers for built-in redundancy and BGP for routing. A circuit has two peerings:
Getting a circuit takes weeks to months, because the provider has to provision physical infrastructure.
Because ExpressRoute isn’t encrypted by default, Learn lists two add-ons:
| VPN Gateway | ExpressRoute | |
|---|---|---|
| Path | Public internet, IPsec | Private, via provider |
| Encrypted by default | Yes | No |
| Bandwidth | Up to 10 Gbps aggregate (VpnGw5AZ); one tunnel is much lower | Provider circuits 50 Mbps to 10 Gbps; Direct ports of 10, 100 or 400 Gbps |
| Latency | Variable (internet) | Low and predictable |
| SLA | 99.95% for every SKU except Basic | Depends on design: single site, Metro or multiple peering locations |
| Set-up time | Hours to days | Weeks to months |
For maximum ExpressRoute resiliency, Microsoft recommends two circuits in two peering locations.
The two can coexist in one virtual network, so a site-to-site VPN can act as a secure failover path for ExpressRoute, or connect branch sites that have no circuit. The rules:
Virtual WAN puts S2S VPN, P2S, ExpressRoute and SD-WAN partner devices into Microsoft-managed hubs, with transit between VPN and ExpressRoute sites. Learn’s SKU page says that if you need more than 100 site-to-site tunnels, use Virtual WAN instead of VPN Gateway. A Basic virtual WAN does site-to-site VPN only; ExpressRoute needs Standard.
| You need… | Choose |
|---|---|
| Encrypted link on a budget, up and running today | Site-to-site VPN |
| Individual remote users into a VNet | Point-to-site VPN |
| Private, predictable, high-bandwidth, no internet path | ExpressRoute (private peering) |
| Microsoft 365 or PaaS over ExpressRoute | Microsoft peering |
| Encryption on ExpressRoute | MACsec (Direct) or IPsec over private peering |
| Two on-premises sites linked through Microsoft’s network | Global Reach |
| A cheap safety net if the circuit fails | Coexisting site-to-site VPN |
| Dozens of branches, or more than 100 tunnels | Virtual WAN |
Hybrid connectivity is covered in the AZ-700 study guide, the AZ-104 study guide the AZ-305 study guide and, for the basics, the AZ-900 study guide, with the traps called out like these. Facts checked against Microsoft Learn on 8 October 2026.
Microsoft has confirmed that Always Encrypted with Intel SGX enclaves in Azure SQL Database retires on 31 October 2027, and that App Service support for Java 8, 11 and 17 ends on 1 September 2027. Defender for Storage can now scan individual blobs and containers on demand, and Application Gateway WAF inspects IPv6 traffic in preview.
Three Azure services all "block traffic", but at different layers and in different places. What each one inspects, how they fit together, and three exam traps.
Three Azure governance controls that people mix up. RBAC decides who can act, Azure Policy decides what a resource may look like, and locks stop changes even by an Owner. Scopes, effects, exemptions, remediation, deny assignments and three traps.
The October review of Microsoft's announcements found two changes that affect the AZ-305 guide. The retirement date for Application Insights URL ping tests has moved, and Azure IoT Central is being retired.
Both lock an Azure service down to your virtual network, but they work in completely different ways. How each one works, the on-premises trap, DNS, data exfiltration, and a five-second way to choose.