{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
        "slug": "dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/"
        },
        "title": "Resynchronize Azure peering after changing a member's address space",
        "summary": "Include the peering connection in the address-space change rather than closing the work at the VNet update.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:10+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Peered Azure virtual networks, including networks in different subscriptions or Entra tenants.",
        "dse_recommendation": "Include connection resynchronization and tests of the changed prefixes in the address-space change record.",
        "primary_source": {
            "name": "Create Virtual Network Peering Between Different Subscriptions - Azure Virtual Network | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s cross-subscription peering guidance requires resynchronizing a connection after changing a member network&#8217;s address space. The synchronization reflects the changed prefixes in the peering relationship.</p>\n<p>The same procedure considers peering established when both networks show Connected. It supports peering Resource Manager virtual networks across different subscriptions and Entra tenants. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the network being changed and every peering relationship that depends on its address space. Record the old and proposed ranges, the owner of each peer and the application paths that must use the new range.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends making synchronization a named task with an owner in the address-change plan. Coordinate the two network owners before the change window and retain the original prefix map for comparison. Do not close the change solely because the VNet&#8217;s address-space field displays the intended value. Keep unrelated routing or access-policy changes separate so failures can be attributed accurately.</p>\n<h2>Verification</h2>\n<p>After an approved change and synchronization, inspect both peering states and compare the resulting configuration with the planned prefix map. Exercise a representative permitted connection using the changed range, as well as a path that should remain restricted. Record the addresses actually tested and any unresolved discrepancy. Treat Connected as one configuration check, not a substitute for validating the intended application path.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create Virtual Network Peering Between Different Subscriptions</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s cross-subscription peering guidance requires resynchronizing a connection after changing a member network’s address space. The synchronization reflects the changed prefixes in the peering relationship.\nThe same procedure considers peering established when both networks show Connected. It supports peering Resource Manager virtual networks across different subscriptions and Entra tenants. Microsoft Learn.\nApplicability\nIdentify the network being changed and every peering relationship that depends on its address space. Record the old and proposed ranges, the owner of each peer and the application paths that must use the new range.\nDSE recommendation\nDSE recommends making synchronization a named task with an owner in the address-change plan. Coordinate the two network owners before the change window and retain the original prefix map for comparison. Do not close the change solely because the VNet’s address-space field displays the intended value. Keep unrelated routing or access-policy changes separate so failures can be attributed accurately.\nVerification\nAfter an approved change and synchronization, inspect both peering states and compare the resulting configuration with the planned prefix map. Exercise a representative permitted connection using the changed range, as well as a path that should remain restricted. Record the addresses actually tested and any unresolved discrepancy. Treat Connected as one configuration check, not a substitute for validating the intended application path.\nOfficial references\nMicrosoft Learn: Create Virtual Network Peering Between Different Subscriptions. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s cross-subscription peering guidance requires resynchronizing a connection after changing a member network’s address space. The synchronization reflects the changed prefixes in the peering relationship.\n\nThe same procedure considers peering established when both networks show Connected. It supports peering Resource Manager virtual networks across different subscriptions and Entra tenants. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions).\n\n## Applicability\n\nIdentify the network being changed and every peering relationship that depends on its address space. Record the old and proposed ranges, the owner of each peer and the application paths that must use the new range.\n\n## DSE recommendation\n\nDSE recommends making synchronization a named task with an owner in the address-change plan. Coordinate the two network owners before the change window and retain the original prefix map for comparison. Do not close the change solely because the VNet’s address-space field displays the intended value. Keep unrelated routing or access-policy changes separate so failures can be attributed accurately.\n\n## Verification\n\nAfter an approved change and synchronization, inspect both peering states and compare the resulting configuration with the planned prefix map. Exercise a representative permitted connection using the changed range, as well as a path that should remain restricted. Record the addresses actually tested and any unresolved discrepancy. Treat Connected as one configuration check, not a substitute for validating the intended application path.\n\n## Official references\n\n[Microsoft Learn: Create Virtual Network Peering Between Different Subscriptions](https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Resynchronize Azure peering after changing a member's address space",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/",
                "headline": "Resynchronize Azure peering after changing a member's address space",
                "description": "Include the peering connection in the address-space change rather than closing the work at the VNet update.",
                "abstract": "Include the peering connection in the address-space change rather than closing the work at the VNet update.",
                "articleBody": "Source facts\nMicrosoft’s cross-subscription peering guidance requires resynchronizing a connection after changing a member network’s address space. The synchronization reflects the changed prefixes in the peering relationship.\nThe same procedure considers peering established when both networks show Connected. It supports peering Resource Manager virtual networks across different subscriptions and Entra tenants. Microsoft Learn.\nApplicability\nIdentify the network being changed and every peering relationship that depends on its address space. Record the old and proposed ranges, the owner of each peer and the application paths that must use the new range.\nDSE recommendation\nDSE recommends making synchronization a named task with an owner in the address-change plan. Coordinate the two network owners before the change window and retain the original prefix map for comparison. Do not close the change solely because the VNet’s address-space field displays the intended value. Keep unrelated routing or access-policy changes separate so failures can be attributed accurately.\nVerification\nAfter an approved change and synchronization, inspect both peering states and compare the resulting configuration with the planned prefix map. Exercise a representative permitted connection using the changed range, as well as a path that should remain restricted. Record the addresses actually tested and any unresolved discrepancy. Treat Connected as one configuration check, not a substitute for validating the intended application path.\nOfficial references\nMicrosoft Learn: Create Virtual Network Peering Between Different Subscriptions. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:28:10+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-226-resynchronize-azure-peering-after-changing-a-member-s-address-space/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Resynchronize Azure peering after changing a member's address space"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create Virtual Network Peering Between Different Subscriptions - Azure Virtual Network | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-network/create-peering-different-subscriptions"
                }
            }
        ]
    }
}