Is it possible to deny vnet peering between subscriptions that are in different management groups with azure policy ?

Ben B 0 Reputation points
2024-11-24T11:42:57.1233333+00:00

Hi,

We are in the process of setting up sandbox subscriptions in a dedicated management group and we would like to deny vnet peerings between these subscriptions and production subscriptions which are also in their dedicated management group. Vnet peerings between sandboxes would remain allowed.

Thanks in advance

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
939 questions
{count} votes

1 answer

Sort by: Most helpful
  1. amon 126 Reputation points Microsoft Employee
    2024-11-24T20:18:54.29+00:00

    Absolutely.

    Check out this policy here

    Use that policy exactly if you want to manually specify which vnets can peer, or you can change the policy condition to a contains and add the required subscription ID.

    Important note: "AZ Policy Advertizer" is NOT an official Microsoft website, I personally find it very useful but all information there must be treated as public and validated before usage.

    Good luck!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.