# Review the routing implications of extending an on-premises subnet into Azure

> What must be evaluated before using extended network for Azure to retain VM addresses?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:27+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What must be evaluated before using extended network for Azure to retain VM addresses?

## Potentially affected

Administrators evaluating extended network for Azure for migrating on-premises VMs.

## DSE recommendation

Have the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses.

## Article

## Source facts

Microsoft describes extending an on-premises subnet so migrated VMs can retain their existing private IP addresses. The documented feature supports extending up to 250 addresses and presents throughput as dependent on appliance CPU performance. Where a firewall lies between the sites, the source requires consideration of asymmetric routing and directs administrators to the firewall vendor’s instructions. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network).

## Applicability

Identify the exact address-retention requirement and compare it with an ordinary routed migration. Review appliance placement, subnet planning, and current capacity guidance before selecting the extension. Treat firewall behavior as part of the design rather than a last-minute connectivity exception.

## DSE recommendation

Have the network and application owners map the intended traffic paths and list which VMs genuinely need their current addresses. Ask the firewall owner to assess the documented asymmetric-routing requirement and any implications for the existing controls. Pilot a small address set with agreed throughput and recovery expectations. Preserve the original route and security configuration before introducing the appliances.

## Verification

Move an approved test workload and confirm its intended address, application reachability, and observed traffic path. Test representative return traffic and the agreed interruption scenario. Measure actual appliance behavior under the pilot load rather than treating an example throughput as a guarantee. Resolve routing or control gaps before extending additional addresses.

## Official references

[Microsoft Learn: Extend your on-premises subnets into Azure using extended network for Azure](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network). Source reviewed September 8, 2026.

## Primary reference

- Name: Extend your on-premises subnets into Azure using extended network for Azure
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/azure-extended-network
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review the routing implications of extending an on-premises subnet into Azure,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-224-review-the-routing-implications-of-extending-an-on-premises-subnet-into-azure/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
