What you need to know
Disabling branch-to-branch connectivity does not disable branch-to-VNet or VNet-to-VNet connectivity.
Potentially affected
Azure Virtual WAN networks with VPN or ExpressRoute branches and connected VNets.
DSE recommendation
Translate the desired isolation into explicit connection pairs and test them instead of treating the switch as universal segmentation.
Source facts
Azure Virtual WAN can disable branch-to-branch connectivity. Microsoft describes this as blocking route propagation between site-to-site VPN, point-to-site VPN and ExpressRoute-connected sites.
That setting does not affect branch-to-VNet or VNet-to-VNet route propagation and connectivity. Virtual WAN also supports VNets connected to hubs in a different Azure region, so the topology review should identify the actual hub connections. Microsoft Learn.
Applicability
Identify each branch connection, remote-user connection, VNet and hub in scope. State which pairs should communicate and which must remain isolated.
DSE recommendation
DSE recommends a small connection matrix before changing the switch. Mark branch-to-branch, branch-to-VNet and VNet-to-VNet paths separately and assign an expected outcome to each. If the desired restriction extends beyond the documented branch boundary, have the network and security owners review the additional design required. Do not present a disabled switch as evidence that every attached workload is isolated from every other workload.
Verification
In an approved test, inspect relevant route propagation and exercise representative allowed and excluded connection pairs. Include a branch-to-VNet path expected to remain available so an unrelated failure is not mistaken for successful isolation. Retain source, destination and observed path with each result. Investigate any unexpected surviving connection before closing the segmentation change.
Official references
Microsoft Learn: Architecture: Global transit network architecture. Source retrieved September 9, 2026.
Review the official source
Architecture: Global transit network architecture - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE