# Preserve Virtual WAN route configuration before enabling routing intent

> Prepare an explicit restoration plan because removing routing intent does not restore the previous hub configuration.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:11+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Prepare an explicit restoration plan because removing routing intent does not restore the previous hub configuration.

## Potentially affected

Azure Virtual WAN hubs being changed to routing intent.

## DSE recommendation

Capture gateway, connection, and route-table configuration and define restoration steps before enabling routing intent.

## Article

## Source facts

Routing intent manages route associations and propagation for hub connections. When it is completely removed, connections propagate to the default label rather than automatically returning to their earlier configuration.

Microsoft therefore advises retaining the existing gateway, connection, and route-table configurations before the change. Removing the feature and restoring the previous routing design are separate operations. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies).

## Applicability

Use this review before a hub transition, including changes affecting branch, spoke, or security-appliance traffic. Identify the current associations, propagated tables, and intended inspection path for each connection.

## DSE recommendation

DSE recommends attaching an explicit restoration plan to the routing-intent change. Name the saved configuration objects, responsible operator, recovery sequence, and traffic conditions that would trigger rollback. Have the network and security owners agree which previous paths must return, rather than accepting feature removal as the rollback instruction.

## Verification

Rehearse the transition and reversal in a representative nonproduction hub. Compare the restored associations, propagation, and effective routes with the saved state. Test the required branch-to-spoke and internet paths, including prohibited traffic. Preserve any intentional differences and obtain approval before calling the routing design restored.

## Official references

[Microsoft Learn: How to configure Virtual WAN Hub routing policies](https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies). Source retrieved September 9, 2026.

## Primary reference

- Name: How to configure Virtual WAN Hub routing policies - Azure Virtual WAN | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve Virtual WAN route configuration before enabling routing intent,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-105-preserve-virtual-wan-route-configuration-before-enabling-routing-intent/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
