# Keep both GatewaySubnet prefixes after an ExpressRoute gateway migration uses them

> Adding a second prefix does not make the original subnet prefix disposable after migration.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-551-keep-both-gatewaysubnet-prefixes-after-an-expressroute-gateway-migration-uses-them/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:45+00:00
- Modified: 2026-09-10T02:14:30+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Adding a second prefix does not make the original subnet prefix disposable after migration.

## Potentially affected

Eligible guided ExpressRoute gateway migrations that expand GatewaySubnet with an additional prefix.

## DSE recommendation

Treat both prefixes as active gateway dependencies and exclude the original prefix from automatic cleanup.

## Article

## Source facts

Microsoft’s ExpressRoute gateway migration guidance states that the migrated gateway uses both the original and added GatewaySubnet prefixes. It explicitly instructs operators not to delete the old prefix. Multiple prefixes are configured through PowerShell, CLI or Resource Manager templates.

The guided migration is for ExpressRoute gateways within the same virtual network, not VPN gateways or cross-region moves. The new gateway is a separate resource with its own monitoring metrics. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/expressroute/gateway-migration).

## Applicability

Confirm that the actual migration uses an additional subnet prefix and that the gateway meets current eligibility requirements. Do not apply a replace-old-prefix assumption from another network migration to this workflow.

## DSE recommendation

DSE recommends carrying both prefixes into the post-migration address plan, dependency inventory and change record. Review any infrastructure cleanup script that interprets the older prefix as temporary. Keep old gateway-resource retirement separate from subnet-prefix retention. Have the network owner approve address-plan changes only after examining the migrated gateway’s documented requirements.

## Verification

Inspect the migrated gateway, GatewaySubnet prefix list and updated ownership record after the approved transition. Confirm that automation preserves both prefixes and that monitoring refers to the new gateway resource. Validate expected connectivity without deleting a prefix as an experiment. Retain any discrepancy between the deployed address plan and the intended retained configuration as an unresolved migration finding.

## Official references

[Microsoft Learn: About migrating to an availability zone-enabled ExpressRoute virtual network gateway](https://learn.microsoft.com/en-us/azure/expressroute/gateway-migration). Source retrieved September 9, 2026.

## Primary reference

- Name: About migrating to an availability zone-enabled ExpressRoute virtual network gateway - Azure ExpressRoute | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/expressroute/gateway-migration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep both GatewaySubnet prefixes after an ExpressRoute gateway migration uses them,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-551-keep-both-gatewaysubnet-prefixes-after-an-expressroute-gateway-migration-uses-them/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
