A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
Also called virtual network.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AZ-900AI-200DP-900SC-900ALZ
Each book explains VNet in context, with comparison tables and the common traps.
Terms in this definition
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Availability zones
Separate physical datacentre locations inside one region. Placing VMs in at least two of them earns a 99.99% SLA.
Related terms
- Accessibility level
Whether a Container Apps environment is reachable publicly or only privately, fixed when the environment is made. With external, its virtual IP sits on a public address; with internal, an internal load balancer in your own virtual network holds it.
- Address space
The CIDR block or blocks that define a VNet. Every subnet has to fall inside it; blocks can be added, or altered when nothing is using them.
- Allow forwarded traffic
Peering option permitting traffic that did not start in the peer VNet, but was forwarded by a gateway or NVA, to pass over the peering.
- Allow gateway transit
Peering option set on the hub, which owns the gateway, so that peered VNets can share its ExpressRoute or VPN gateway. The spoke sets Use remote gateways to match; on a VNet lacking a gateway the option has no effect.
- AllowVnetOutBound
Built-in NSG outbound rule at priority 65000 that lets VMs open connections towards their own VNet and peered VNets. The NSG at the destination still has to permit the port.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- API Management
Azure's API gateway, where policies like rate limits, quotas, ip-filter and validate-jwt are defined once and apply to every API. Production VNet injection is offered in the Premium tier.
- Application security group
Named collection of VM NICs that NSG rules can use as source or destination in place of IP addresses. NICs join only when explicitly added, and they must all belong to one VNet.