Define the isolation boundary of Virtual WAN's branch-to-branch switch

Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.

Potentially affected

Azure Virtual WAN networks with VPN or ExpressRoute branches and connected VNets.

DSE recommendation

Translate the desired isolation into explicit connection pairs and test them instead of treating the switch as universal segmentation.

Source facts

Azure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.

That setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. Microsoft Learn.

Applicability

Identify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.

DSE recommendation

DSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.

Verification

In an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.

Official references

Microsoft Learn: Architecture: Global transit network architecture. Source retrieved September 9, 2026.

Primary reference

Review the official source

Architecture: Global transit network architecture - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE