Collection of VNets or subnets in Azure Virtual Network Manager, drawn only from within the manager's scope and filled either statically or dynamically by Azure Policy. VNets outside the scope can never be members.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Network group in context, with comparison tables and the common traps.
Terms in this definition
- Azure Virtual Network Manager
Service for centrally managing connectivity, as hub-and-spoke or mesh, and security admin rules across VNets in many subscriptions. VNets in other tenants must be added as static members, because dynamic membership driven by Azure Policy works only within one tenant.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Azure Policy
Azure service that audits and enforces how resources are configured, for example their location, SKU or tags, using definitions and assignments. It neither deploys resources nor controls access.
Related terms
- Connectivity configuration
Virtual Network Manager setting that creates mesh or hub-and-spoke topologies, using peerings or connected groups, over a network group; route exchange between gateways isn't part of it.
- Direct connectivity
A setting in an Azure Virtual Network Manager hub-and-spoke configuration that lets spokes in the same network group reach each other without going through the hub. Their effective routes list ConnectedGroup as the next hop, and no peerings appear.
- Mesh topology (Virtual Network Manager)
Connectivity configuration in Virtual Network Manager where a connected group links each VNet in the network group to all the others in both directions. It is regional unless you opt for global mesh.
- Routing configuration (Virtual Network Manager)
Kind of configuration in Azure Virtual Network Manager: its rule collections produce user-defined routes, specifying next hops, for the members of a network group. It changes where traffic goes without filtering ports.