What you need to know
Which traffic is covered by encryption on an SDN virtual subnet?
Potentially affected
Administrators enabling encryption on Windows Server SDN virtual networks.
DSE recommendation
Create a protection matrix with one row per application flow.
Source facts
Microsoft describes subnet encryption using DTLS for virtual machines communicating inside an encryption-enabled subnet. The configuration requires encryption certificates on the SDN Hyper-V hosts and a Network Controller credential referencing the certificate thumbprint. The source states that traffic crossing between subnets, or leaving the virtual network, is not encrypted by this feature even when the subnets are marked for encryption. Microsoft Learn.
Applicability
Map the actual source and destination subnets for the protected workload. Distinguish a same-subnet conversation from cross-subnet and external traffic. Decide which additional protection is needed for each path rather than treating one enabled setting as a complete traffic inventory.
DSE recommendation
Create a protection matrix with one row per application flow. Identify the certificate and credential objects used by the intended hosts, the subnet setting, and the expected protection at every boundary. Ask the workload owner to approve coverage gaps explicitly. Keep certificate handling and renewal ownership in the configuration record and preserve the original settings for the pilot.
Verification
Test representative traffic within a protected subnet, across a subnet boundary, and outside the virtual network. Use authorized observations that can distinguish the relevant protection without collecting unnecessary payloads. Compare the evidence with the flow matrix and investigate any unsupported assumption before expanding encryption to more workloads.
Official references
Microsoft Learn: Configure Encryption for a Virtual Network. Source reviewed September 8, 2026.
Review the official source
Configure Encryption for a Virtual Network · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE