# Preserve the VM adapter identity before starting an SDN tenant workload

> Which VM network-adapter identity must be established before an SDN-connected VM starts?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-130-preserve-the-vm-adapter-identity-before-starting-an-sdn-tenant-workload/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:01+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which VM network-adapter identity must be established before an SDN-connected VM starts?

## Potentially affected

Administrators attaching VMs to Microsoft SDN tenant networks or VLANs.

## DSE recommendation

Prepare a binding record linking the VM adapter to its Network Controller interface and tenant network.

## Article

## Source facts

Microsoft’s procedure attaches a tenant VM either to a virtualized tenant network or to a VLAN. The VM adapter requires a static MAC address for the VM’s lifetime. A MAC change prevents Network Controller from configuring the required adapter policy and stops network communication. For a VM needing connectivity at startup, the source instructs administrators to set the interface identifier on the adapter port before starting it. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Create-a-Tenant-VM).

## Applicability

Identify the VM, adapter, controller interface resource, MAC address, target subnet, and startup dependencies. Replace the source’s sample identifiers with the approved values for this tenant.

## DSE recommendation

Prepare a binding record linking the VM adapter to its Network Controller interface and tenant network. Have the platform and network owners review those identities before first boot. Define how the binding will be maintained if the VM is moved or its adapter is recreated.

## Verification

Inspect the identities before startup, then test the intended tenant communication from the guest. Compare the observed policy association and network path with the binding record. Treat a changed MAC or missing interface resource as an unresolved configuration issue before allowing the application to depend on that connection.

## Official references

[Microsoft Learn: Create a VM and connect to a tenant virtual network or VLAN](https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Create-a-Tenant-VM). Source reviewed September 8, 2026.

## Primary reference

- Name: Create a VM and connect to a tenant virtual network or VLAN
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/Create-a-Tenant-VM
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve the VM adapter identity before starting an SDN tenant workload,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-130-preserve-the-vm-adapter-identity-before-starting-an-sdn-tenant-workload/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
