Skip to content

Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write

Azure

Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write

service: Azure - Network
techniques:

Event

Writes a VNet peering configuration. Both sides must reach Connected for peering to be established, and address spaces must not overlap. Peering is not inherently transitive; NSGs, routes, forwarded-traffic settings, and gateways still control usable paths.

Security Context

Unauthorized peering can bridge an intended network boundary (contextual T1599). An approved topology change is also common. One successful write does not demonstrate completed cross-subscription connectivity or access to security tooling.

Log Source

Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.

Key Fields

FieldInvestigation value
caller, claims, authorizationRecorded actor and authorization context; verify effective permissions.
resourceId, correlationIdExact target and related operations.
status, subStatusOutcome, including acceptance versus final completion.
properties.requestbody, httpRequestSubmitted configuration or request URL where available; secret material may be omitted.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify authority and change approval on both VNets and recover both peering configurations/states.
  3. Review allowVirtualNetworkAccess, forwarded traffic, gateway settings, address spaces, effective routes, and NSGs.
  4. Correlate actual traffic and workload authentication before claiming access to the remote network.

Sample Event

Synthetic scenario. The sample requests a production-to-security peering with forwarded traffic allowed and gateway options disabled. It does not show the reverse peering or a Connected state.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"authorization": {
"action": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write",
"scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering"
},
"caller": "draco@fantasticlogs.cloud",
"channels": "Operation",
"claims": {
"appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
"ipaddr": "203.0.113.66",
"name": "Draco Malfoy",
"http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010",
"puid": "1003200000000666",
"http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud",
"http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814",
"uti": "vnetPeer209ExampleUti",
"ver": "1.0"
},
"correlationId": "90000000-0000-4000-8000-000100011000",
"description": "",
"eventDataId": "90000000-0000-4000-8000-000100011001",
"eventName": {
"value": "EndRequest",
"localizedValue": "End request"
},
"category": {
"value": "Administrative",
"localizedValue": "Administrative"
},
"eventTimestamp": "2026-04-15T18:38:11.3211087Z",
"level": "Informational",
"operationId": "90000000-0000-4000-8000-000100011010",
"operationName": {
"value": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write",
"localizedValue": "Create or Update Virtual Network Peering"
},
"resourceGroupName": "rg-fantasticlogs-prod",
"resourceProviderName": {
"value": "Microsoft.Network",
"localizedValue": "Microsoft.Network"
},
"resourceType": {
"value": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings",
"localizedValue": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings"
},
"resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering",
"status": {
"value": "Succeeded",
"localizedValue": "Succeeded"
},
"subStatus": {
"value": "Created",
"localizedValue": "Created (HTTP Status Code: 201)"
},
"submissionTimestamp": "2026-04-15T18:38:11.8902154Z",
"subscriptionId": "20000000-0000-4000-8000-000000000001",
"tenantId": "10000000-0000-4000-8000-000000000001",
"properties": {
"statusCode": "Created",
"serviceRequestId": null,
"eventCategory": "Administrative",
"entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering",
"message": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write",
"hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001",
"requestbody": "{\"properties\":{\"allowVirtualNetworkAccess\":true,\"allowForwardedTraffic\":true,\"allowGatewayTransit\":false,\"useRemoteGateways\":false,\"remoteVirtualNetwork\":{\"id\":\"/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.Network/virtualNetworks/vnet-security-eastus\"}}}"
},
"relatedEvents": []
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1599 — Network Boundary Bridging — Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation. Breaching these devices may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.