Microsoft is making a fundamental change to how outbound internet connectivity works for virtual machines within Azure Virtual Networks. From March 2026, default outbound access will be retired for new virtual networks, requiring organisations to explicitly design and configure outbound connectivity for their workloads.
What VNET outbound settings are changing?
Historically, Azure has provided implicit outbound internet access for virtual machines deployed into virtual networks without a defined egress path. This behaviour, known as default outbound access, allowed workloads to reach the internet without additional configuration. Microsoft is now retiring this approach in favour of a more secure, explicit networking model.
Why is this change being made?
Default outbound access provides limited visibility, control, and governance over egress traffic. By removing implicit connectivity, Azure is aligning more closely with secure by default and Zero Trust networking principles, encouraging customers to deliberately design outbound paths that are auditable, predictable, and appropriate for production environments.
Who is affected by VNET outbound network changes?
These changes primarily affect organisations that deploy virtual machines or scale sets into new Azure virtual networks without explicitly configuring outbound connectivity. This is particularly relevant for development, testing, and legacy deployments that rely on implicit internet access for updates, licensing, telemetry, or third-party integrations. Microsoft has said that this change does not affect existing virtual networks:
Please note that this change does not affect existing virtual networks, including any new virtual machines deployed within them. If required, you can still create new subnets without the private setting by choosing the appropriate configuration option during creation. However, we strongly recommend transitioning to an explicit outbound method so that:
- Your workloads won’t be affected by public IP address changes.
- You have greater control over how your VMs connect to public endpoints.
- Your VMs use traceable IP resources that you own.
When will the changes take effect?
From 31 March 2026, new virtual networks and subnets will default to private. Virtual machines deployed into these environments will not have outbound internet access unless an explicit outbound method is configured. Existing virtual networks created prior to this date will continue to function as they do today unless modified.
Supported approaches to VNET outbound network access
Microsoft recommends configuring one of the following outbound methods depending on workload requirements:
- Azure NAT Gateway for scalable, predictable egress
- Load Balancer outbound rules for environments already using load balancers
- Public IP addresses for individual workloads
- Azure Firewall or network virtual appliances for centralised policy enforcement.
What happens to existing virtual machines?
Virtual machines deployed into private subnets without an explicit outbound configuration will be unable to reach the internet or public Azure services. This may impact operating system updates, package repositories, monitoring agents, authentication flows, and external API integrations.
What should I do to avoid dispruption?
If you are unsure whether your Azure environment relies on default outbound access, now is the right time to review your network design. Proactive planning will ensure a smooth transition and avoid connectivity issues as Azure moves to a more secure networking baseline.
Organisations should begin reviewing their Azure estate to identify workloads that rely on default outbound access. Infrastructure-as-code templates and deployment pipelines should be updated to include explicit outbound connectivity by default. Testing these changes ahead of the March 2026 deadline will help avoid unexpected service disruption.
How can Sentrium help?
Sentrium can help perform a review of your Microsoft Azure environment with our cloud security testing services. Our team have expert knowledge of Microsoft Azure virtual networks. We understand the complexities in configuring a cloud environment securely, and can help you navigate complex mechanisms like VNET networking configurations and security best practices. Get in touch to find out more about our cloud services.