# Map container endpoint addresses onto an SDN tenant subnet

> How are Windows container endpoints addressed when attached to an SDN tenant virtual network?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-094-map-container-endpoint-addresses-onto-an-sdn-tenant-subnet/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:37+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

How are Windows container endpoints addressed when attached to an SDN tenant virtual network?

## Potentially affected

Administrators connecting Windows container endpoints to existing SDN tenant networks.

## DSE recommendation

Prepare an endpoint allocation worksheet before configuring the host.

## Article

## Source facts

Microsoft’s procedure uses the l2bridge network driver, with l2tunnel as another option, for container networks within a tenant VM. For these SDN drivers, container endpoints occupy the same virtual subnet as the tenant VM that hosts them. The Host Networking Service assigns endpoint addresses through the private-cloud plugin. The endpoints have distinct IP addresses but share their host VM’s MAC address because Layer-2 address translation is used. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Connect-container-endpoints-to-a-Tenant-Virtual-Network).

## Applicability

Check the existing tenant network, subnet, VM NIC resource, container host, and documented software prerequisites. Treat the source’s sample addresses as examples and substitute only addresses approved for the actual tenant subnet.

## DSE recommendation

Prepare an endpoint allocation worksheet before configuring the host. Identify the tenant network, container address range, responsible network controller, and expected isolation boundary. Review the relationship between endpoint IP identities and the shared MAC identity with the operators who will investigate connectivity.

## Verification

Create a controlled endpoint and compare its assigned address with the approved range and tenant subnet. Test its allowed connections and isolation from a separate tenant. Preserve the controller, host, and container observations together so address allocation and policy enforcement can be assessed for the same endpoint.

## Official references

[Microsoft Learn: Connect container endpoints to a tenant virtual network](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Connect-container-endpoints-to-a-Tenant-Virtual-Network). Source reviewed September 8, 2026.

## Primary reference

- Name: Connect container endpoints to a tenant virtual network
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Connect-container-endpoints-to-a-Tenant-Virtual-Network
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Map container endpoint addresses onto an SDN tenant subnet,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-094-map-container-endpoint-addresses-onto-an-sdn-tenant-subnet/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
