What you need to know
How are Windows container endpoints addressed when attached to an SDN tenant virtual network?
Potentially affected
Administrators connecting Windows container endpoints to existing SDN tenant networks.
DSE recommendation
Prepare an endpoint allocation worksheet before configuring the host.
Source facts
Microsoft’s procedure uses the l2bridge network driver, with l2tunnel as another option, for container networks within a tenant VM. For these SDN drivers, container endpoints occupy the same virtual subnet as the tenant VM that hosts them. The Host Networking Service assigns endpoint addresses through the private-cloud plugin. The endpoints have distinct IP addresses but share their host VM’s MAC address because Layer-2 address translation is used. Microsoft documentation.
Applicability
Check the existing tenant network, subnet, VM NIC resource, container host, and documented software prerequisites. Treat the source’s sample addresses as examples and substitute only addresses approved for the actual tenant subnet.
DSE recommendation
Prepare an endpoint allocation worksheet before configuring the host. Identify the tenant network, container address range, responsible network controller, and expected isolation boundary. Review the relationship between endpoint IP identities and the shared MAC identity with the operators who will investigate connectivity.
Verification
Create a controlled endpoint and compare its assigned address with the approved range and tenant subnet. Test its allowed connections and isolation from a separate tenant. Preserve the controller, host, and container observations together so address allocation and policy enforcement can be assessed for the same endpoint.
Official references
Microsoft Learn: Connect container endpoints to a tenant virtual network. Source reviewed September 8, 2026.
Review the official source
Connect container endpoints to a tenant virtual network · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE