{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
        "slug": "dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/"
        },
        "title": "Define the isolation boundary of Virtual WAN's branch-to-branch switch",
        "summary": "Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:56+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 214,
        "potentially_affected": "Azure Virtual WAN networks with VPN or ExpressRoute branches and connected VNets.",
        "dse_recommendation": "Translate the desired isolation into explicit connection pairs and test them instead of treating the switch as universal segmentation.",
        "primary_source": {
            "name": "Architecture: Global transit network architecture - Azure Virtual WAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.</p>\n<p>That setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.</p>\n<h2>Verification</h2>\n<p>In an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Architecture: Global transit network architecture</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.\nThat setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. Microsoft Learn.\nApplicability\nIdentify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.\nDSE recommendation\nDSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.\nVerification\nIn an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.\nOfficial references\nMicrosoft Learn: Architecture: Global transit network architecture. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.\n\nThat setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture).\n\n## Applicability\n\nIdentify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.\n\n## DSE recommendation\n\nDSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.\n\n## Verification\n\nIn an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.\n\n## Official references\n\n[Microsoft Learn: Architecture: Global transit network architecture](https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Define the isolation boundary of Virtual WAN's branch-to-branch switch",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/",
                "headline": "Define the isolation boundary of Virtual WAN's branch-to-branch switch",
                "description": "Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.",
                "abstract": "Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.",
                "articleBody": "Source facts\nAzure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.\nThat setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. Microsoft Learn.\nApplicability\nIdentify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.\nDSE recommendation\nDSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.\nVerification\nIn an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.\nOfficial references\nMicrosoft Learn: Architecture: Global transit network architecture. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:26:56+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-300-define-the-isolation-boundary-of-virtual-wan-s-branch-to-branch-switch/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Define the isolation boundary of Virtual WAN's branch-to-branch switch"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 214,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Architecture: Global transit network architecture - Azure Virtual WAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-global-transit-network-architecture"
                }
            }
        ]
    }
}