What you need to know
Can two secured-hub virtual networks still communicate when their routes are not propagated to each other?
Potentially affected
Apply this check to the documented secured-hub Azure Firewall static-route design without routing intent. Identify aggregate routes as well as specific prefixes before declaring two connected virtual networks isolated.
DSE recommendation
Express the intended denial in the firewall policy and validate the complete path.
Source facts
Microsoft warns that Virtual WAN route associations and propagation settings do not guarantee isolation between virtual networks in a secured hub. An aggregate static route pointing to Azure Firewall can still provide a path between networks that do not propagate to each other. The source directs administrators to firewall network rules for the required block. Its Azure Firewall static-route pattern excludes hubs with routing intent enabled. Microsoft Learn.
Applicability
Apply this check to the documented secured-hub Azure Firewall static-route design without routing intent. Identify aggregate routes as well as specific prefixes before declaring two connected virtual networks isolated.
DSE recommendation
Express the intended denial in the firewall policy and validate the complete path. Have the network and security owners review the associated route tables, propagated prefixes and aggregate next hops together. Document which traffic must be denied and which neighboring traffic must remain permitted. Keep a routing omission separate from a reviewed security rule. Propose only the required policy change and preserve the existing route and rule state for the authorized test.
Verification
From approved endpoints, test both the intended denied connection and an explicitly allowed control flow. Retain the actual route and firewall decision with the result. Include destinations covered by a broader static prefix, not only directly listed routes. If traffic still passes through the firewall, investigate the matching rule instead of treating absent peer propagation as proof that the observation is impossible.
Official references
Review the official source
Static routes in Azure Virtual WAN - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE