{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
        "slug": "dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/"
        },
        "title": "Preserve Virtual WAN route configuration before enabling routing intent",
        "summary": "Prepare an explicit restoration plan because removing routing intent does not restore the previous hub configuration.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:11+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 199,
        "potentially_affected": "Azure Virtual WAN hubs being changed to routing intent.",
        "dse_recommendation": "Capture gateway, connection, and route-table configuration and define restoration steps before enabling routing intent.",
        "primary_source": {
            "name": "How to configure Virtual WAN Hub routing policies - Azure Virtual WAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Routing intent manages route associations and propagation for hub connections. When it is completely removed, connections propagate to the default label rather than automatically returning to their earlier configuration.</p>\n<p>Microsoft therefore advises retaining the existing gateway, connection, and route-table configurations before the change. Removing the feature and restoring the previous routing design are separate operations. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review before a hub transition, including changes affecting branch, spoke, or security-appliance traffic. Identify the current associations, propagated tables, and intended inspection path for each connection.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends attaching an explicit restoration plan to the routing-intent change. Name the saved configuration objects, responsible operator, recovery sequence, and traffic conditions that would trigger rollback. Have the network and security owners agree which previous paths must return, rather than accepting feature removal as the rollback instruction.</p>\n<h2>Verification</h2>\n<p>Rehearse the transition and reversal in a representative nonproduction hub. Compare the restored associations, propagation, and effective routes with the saved state. Test the required branch-to-spoke and internet paths, including prohibited traffic. Preserve any intentional differences and obtain approval before calling the routing design restored.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: How to configure Virtual WAN Hub routing policies</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nRouting intent manages route associations and propagation for hub connections. When it is completely removed, connections propagate to the default label rather than automatically returning to their earlier configuration.\nMicrosoft therefore advises retaining the existing gateway, connection, and route-table configurations before the change. Removing the feature and restoring the previous routing design are separate operations. Microsoft Learn.\nApplicability\nUse this review before a hub transition, including changes affecting branch, spoke, or security-appliance traffic. Identify the current associations, propagated tables, and intended inspection path for each connection.\nDSE recommendation\nDSE recommends attaching an explicit restoration plan to the routing-intent change. Name the saved configuration objects, responsible operator, recovery sequence, and traffic conditions that would trigger rollback. Have the network and security owners agree which previous paths must return, rather than accepting feature removal as the rollback instruction.\nVerification\nRehearse the transition and reversal in a representative nonproduction hub. Compare the restored associations, propagation, and effective routes with the saved state. Test the required branch-to-spoke and internet paths, including prohibited traffic. Preserve any intentional differences and obtain approval before calling the routing design restored.\nOfficial references\nMicrosoft Learn: How to configure Virtual WAN Hub routing policies. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nRouting intent manages route associations and propagation for hub connections. When it is completely removed, connections propagate to the default label rather than automatically returning to their earlier configuration.\n\nMicrosoft therefore advises retaining the existing gateway, connection, and route-table configurations before the change. Removing the feature and restoring the previous routing design are separate operations. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies).\n\n## Applicability\n\nUse this review before a hub transition, including changes affecting branch, spoke, or security-appliance traffic. Identify the current associations, propagated tables, and intended inspection path for each connection.\n\n## DSE recommendation\n\nDSE recommends attaching an explicit restoration plan to the routing-intent change. Name the saved configuration objects, responsible operator, recovery sequence, and traffic conditions that would trigger rollback. Have the network and security owners agree which previous paths must return, rather than accepting feature removal as the rollback instruction.\n\n## Verification\n\nRehearse the transition and reversal in a representative nonproduction hub. Compare the restored associations, propagation, and effective routes with the saved state. Test the required branch-to-spoke and internet paths, including prohibited traffic. Preserve any intentional differences and obtain approval before calling the routing design restored.\n\n## Official references\n\n[Microsoft Learn: How to configure Virtual WAN Hub routing policies](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve Virtual WAN route configuration before enabling routing intent",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/",
                "headline": "Preserve Virtual WAN route configuration before enabling routing intent",
                "description": "Prepare an explicit restoration plan because removing routing intent does not restore the previous hub configuration.",
                "abstract": "Prepare an explicit restoration plan because removing routing intent does not restore the previous hub configuration.",
                "articleBody": "Source facts\nRouting intent manages route associations and propagation for hub connections. When it is completely removed, connections propagate to the default label rather than automatically returning to their earlier configuration.\nMicrosoft therefore advises retaining the existing gateway, connection, and route-table configurations before the change. Removing the feature and restoring the previous routing design are separate operations. Microsoft Learn.\nApplicability\nUse this review before a hub transition, including changes affecting branch, spoke, or security-appliance traffic. Identify the current associations, propagated tables, and intended inspection path for each connection.\nDSE recommendation\nDSE recommends attaching an explicit restoration plan to the routing-intent change. Name the saved configuration objects, responsible operator, recovery sequence, and traffic conditions that would trigger rollback. Have the network and security owners agree which previous paths must return, rather than accepting feature removal as the rollback instruction.\nVerification\nRehearse the transition and reversal in a representative nonproduction hub. Compare the restored associations, propagation, and effective routes with the saved state. Test the required branch-to-spoke and internet paths, including prohibited traffic. Preserve any intentional differences and obtain approval before calling the routing design restored.\nOfficial references\nMicrosoft Learn: How to configure Virtual WAN Hub routing policies. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:30:11+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve Virtual WAN route configuration before enabling routing intent"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 199,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "How to configure Virtual WAN Hub routing policies - Azure Virtual WAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies"
                }
            }
        ]
    }
}