What you need to know
Which connections must be configured explicitly when SDN virtual networks are peered?
Potentially affected
Administrators designing peering between Windows Server SDN virtual networks.
DSE recommendation
Draw the intended connections as explicit network pairs.
Source facts
Microsoft describes peered virtual machines communicating over private addresses through the underlying infrastructure, without an internet connection or gateway for that communication. Peering does not extend transitively: connecting the first network to a second, and the second to a third, does not connect the first and third. Access control lists can restrict communication between peered networks, subnets, or individual virtual machines. Microsoft Learn.
Applicability
List every network pair that the application requires. Identify the relevant SDN implementation before applying this behavior to another networking product. Treat peering reachability, permitted application flows, and on-premises gateway use as separate design entries.
DSE recommendation
Draw the intended connections as explicit network pairs. Beside each pair, identify the initiating workload, destination service, and permitted traffic. Have the network owner approve any broad connectivity before the application team enables it. Include a deliberately unpeered pair in the acceptance plan so an indirect relationship cannot silently become the assumed route. Preserve the prior peering and filtering configuration.
Verification
Test an allowed flow and a prohibited flow across each configured pair. Then test between the first and third networks in the three-network example. Record the actual routes, applied access rules, and results from both ends. Resolve unexpected connectivity before extending the design to additional tenants.
Official references
Microsoft Learn: Virtual network peering. Source reviewed September 8, 2026.
Review the official source
Virtual network peering · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE