Service for centrally managing connectivity, as hub-and-spoke or mesh, and security admin rules across VNets in many subscriptions. VNets in other tenants must be added as static members, because dynamic membership driven by Azure Policy works only within one tenant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Virtual Network Manager in context, with comparison tables and the common traps.
Terms in this definition
- Hub-and-spoke
A network layout in which a central hub virtual network holds shared services and the on-premises gateway, and each workload's spoke network is peered with the hub. Peering by itself does not let spokes reach one another via the hub.
- Security Admin
Built-in Azure role whose holders manage security policy, alerts and recommendations in Microsoft Defender for Cloud. Role assignment and the creation of general policy definitions fall outside what it allows.
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
Related terms
- Direct connectivity
A setting in an Azure Virtual Network Manager hub-and-spoke configuration that lets spokes in the same network group reach each other without going through the hub. Their effective routes list ConnectedGroup as the next hop, and no peerings appear.
- IPAM (Virtual Network Manager)
Capability in Azure Virtual Network Manager for building IP address pools and allocating CIDRs that do not overlap to VNets. It plans addressing only, without routing or filtering.
- Network group
Collection of VNets or subnets in Azure Virtual Network Manager, drawn only from within the manager's scope and filled either statically or dynamically by Azure Policy. VNets outside the scope can never be members.
- Network manager scope
Defines which subscriptions and management groups an Azure Virtual Network Manager covers. Configuration never reaches VNets beyond it, and where two managers overlap and disagree, the higher scope takes effect.
- Routing configuration (Virtual Network Manager)
Kind of configuration in Azure Virtual Network Manager: its rule collections produce user-defined routes, specifying next hops, for the members of a network group. It changes where traffic goes without filtering ports.
- Rule collection
A set of security admin rules, aimed at one or more network groups, held inside a security admin configuration of Azure Virtual Network Manager.
- Security admin configuration
In Azure Virtual Network Manager, the container for one or more collections of security admin rules. Each region accepts just one deployed configuration, so extra rules belong in new rule collections, not further configurations.
- Security admin rule
A rule from Azure Virtual Network Manager that takes effect ahead of NSG rules. Its action is Deny (blocks whatever NSGs say), Always allow (bypasses NSGs) or Allow (hands traffic on for NSG evaluation).