# Make Event Hubs relocation fail when the target service endpoint is missing

> A copied network rule must reference the target subnet and retain the check for its configured service endpoint.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-525-make-event-hubs-relocation-fail-when-the-target-service-endpoint-is-missing/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:11+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

A copied network rule must reference the target subnet and retain the check for its configured service endpoint.

## Potentially affected

Event Hubs regional relocation using exported templates and virtual-network service endpoint restrictions.

## DSE recommendation

Review the target subnet reference and keep ignoreMissingVnetServiceEndpoint false in the approved relocation template.

## Article

## Source facts

Microsoft’s Event Hubs relocation guidance requires recreating source-region service-endpoint restrictions in the destination. In the network rule set, the virtual-network rule must identify the target subnet.

The guidance sets ignoreMissingVnetServiceEndpoint to false so deployment fails when the required service endpoint is not configured at the destination. Exporting the old configuration is therefore not the whole target-network preparation. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-event-hub).

## Applicability

Identify whether the source namespace actually uses service-endpoint rules and which target network replaces each source reference. This check is for that network-control path, not a claim that it configures private endpoints or completes event migration.

## DSE recommendation

DSE recommends pairing each migrated network rule with evidence that the intended target subnet has been prepared. Keep the missing-endpoint validation enabled instead of suppressing it to make a deployment pass. Coordinate the network and messaging owners so a source-region identifier is not mistaken for a valid target reference. Review other relocation dependencies separately.

## Verification

Inspect the proposed template’s target subnet identifier and missing-endpoint flag before deployment. In an approved test environment, verify that the absent prerequisite produces the intended failure and that a correctly prepared target permits the expected deployment. Then test authorized client connectivity through the selected network path. A successful template deployment should not be recorded as proof that every producer, consumer or retained event has migrated.

## Official references

[Microsoft Learn: Relocate Azure Event Hubs to another region](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-event-hub). Source retrieved September 9, 2026.

## Primary reference

- Name: Relocate Azure Event Hubs to another region - Azure Resource Manager | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/relocation/relocation-event-hub
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Make Event Hubs relocation fail when the target service endpoint is missing,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-525-make-event-hubs-relocation-fail-when-the-target-service-endpoint-is-missing/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
