Keep both GatewaySubnet prefixes after an ExpressRoute gateway migration uses them

Adding a second prefix does not make the original subnet prefix disposable after migration.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Adding a second prefix does not make the original subnet prefix disposable after migration.

Potentially affected

Eligible guided ExpressRoute gateway migrations that expand GatewaySubnet with an additional prefix.

DSE recommendation

Treat both prefixes as active gateway dependencies and exclude the original prefix from automatic cleanup.

Source facts

Microsoft’s ExpressRoute gateway migration guidance states that the migrated gateway uses both the original and added GatewaySubnet prefixes. It explicitly instructs operators not to delete the old prefix. Multiple prefixes are configured through PowerShell, CLI or Resource Manager templates.

The guided migration is for ExpressRoute gateways within the same virtual network, not VPN gateways or cross-region moves. The new gateway is a separate resource with its own monitoring metrics. Microsoft Learn.

Applicability

Confirm that the actual migration uses an additional subnet prefix and that the gateway meets current eligibility requirements. Do not apply a replace-old-prefix assumption from another network migration to this workflow.

DSE recommendation

DSE recommends carrying both prefixes into the post-migration address plan, dependency inventory and change record. Review any infrastructure cleanup script that interprets the older prefix as temporary. Keep old gateway-resource retirement separate from subnet-prefix retention. Have the network owner approve address-plan changes only after examining the migrated gateway’s documented requirements.

Verification

Inspect the migrated gateway, GatewaySubnet prefix list and updated ownership record after the approved transition. Confirm that automation preserves both prefixes and that monitoring refers to the new gateway resource. Validate expected connectivity without deleting a prefix as an experiment. Retain any discrepancy between the deployed address plan and the intended retained configuration as an unresolved migration finding.

Official references

Microsoft Learn: About migrating to an availability zone-enabled ExpressRoute virtual network gateway. Source retrieved September 9, 2026.

Primary reference

Review the official source

About migrating to an availability zone-enabled ExpressRoute virtual network gateway - Azure ExpressRoute | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE