Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write
Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write
Event
Writes a VNet peering configuration. Both sides must reach Connected for peering to be established, and address spaces must not overlap. Peering is not inherently transitive; NSGs, routes, forwarded-traffic settings, and gateways still control usable paths.
Security Context
Unauthorized peering can bridge an intended network boundary (contextual T1599). An approved topology change is also common. One successful write does not demonstrate completed cross-subscription connectivity or access to security tooling.
Log Source
Azure Activity Log, Administrative category, with operationName.value: Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write. Correlate status, subStatus, and final resource state; accepted asynchronous requests may still fail. Request bodies and HTTP details are optional and export-dependent.
Key Fields
| Field | Investigation value |
|---|---|
caller, claims, authorization | Recorded actor and authorization context; verify effective permissions. |
resourceId, correlationId | Exact target and related operations. |
status, subStatus | Outcome, including acceptance versus final completion. |
properties.requestbody, httpRequest | Submitted configuration or request URL where available; secret material may be omitted. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify authority and change approval on both VNets and recover both peering configurations/states.
- Review allowVirtualNetworkAccess, forwarded traffic, gateway settings, address spaces, effective routes, and NSGs.
- Correlate actual traffic and workload authentication before claiming access to the remote network.
Sample Event
Synthetic scenario. The sample requests a production-to-security peering with forwarded traffic allowed and gateway options disabled. It does not show the reverse peering or a Connected state.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "authorization": { "action": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write", "scope": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering" }, "caller": "draco@fantasticlogs.cloud", "channels": "Operation", "claims": { "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46", "ipaddr": "203.0.113.66", "name": "Draco Malfoy", "http://schemas.microsoft.com/identity/claims/objectidentifier": "30000000-0000-4000-8000-001010011010", "puid": "1003200000000666", "http://schemas.microsoft.com/identity/claims/tenantid": "10000000-0000-4000-8000-000000000001", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "draco@fantasticlogs.cloud", "http://schemas.microsoft.com/identity/claims/wids": "e8611ab8-c189-46e8-94e1-60213ab1f814", "uti": "vnetPeer209ExampleUti", "ver": "1.0" }, "correlationId": "90000000-0000-4000-8000-000100011000", "description": "", "eventDataId": "90000000-0000-4000-8000-000100011001", "eventName": { "value": "EndRequest", "localizedValue": "End request" }, "category": { "value": "Administrative", "localizedValue": "Administrative" }, "eventTimestamp": "2026-04-15T18:38:11.3211087Z", "level": "Informational", "operationId": "90000000-0000-4000-8000-000100011010", "operationName": { "value": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write", "localizedValue": "Create or Update Virtual Network Peering" }, "resourceGroupName": "rg-fantasticlogs-prod", "resourceProviderName": { "value": "Microsoft.Network", "localizedValue": "Microsoft.Network" }, "resourceType": { "value": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings", "localizedValue": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings" }, "resourceId": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering", "status": { "value": "Succeeded", "localizedValue": "Succeeded" }, "subStatus": { "value": "Created", "localizedValue": "Created (HTTP Status Code: 201)" }, "submissionTimestamp": "2026-04-15T18:38:11.8902154Z", "subscriptionId": "20000000-0000-4000-8000-000000000001", "tenantId": "10000000-0000-4000-8000-000000000001", "properties": { "statusCode": "Created", "serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/20000000-0000-4000-8000-000000000001/resourceGroups/rg-fantasticlogs-prod/providers/Microsoft.Network/virtualNetworks/vnet-prod-eastus/virtualNetworkPeerings/prod-to-security-peering", "message": "Microsoft.Network/virtualNetworks/virtualNetworkPeerings/write", "hierarchy": "10000000-0000-4000-8000-000000000001/20000000-0000-4000-8000-000000000001", "requestbody": "{\"properties\":{\"allowVirtualNetworkAccess\":true,\"allowForwardedTraffic\":true,\"allowGatewayTransit\":false,\"useRemoteGateways\":false,\"remoteVirtualNetwork\":{\"id\":\"/subscriptions/20000000-0000-4000-8000-000000000010/resourceGroups/rg-security/providers/Microsoft.Network/virtualNetworks/vnet-security-eastus\"}}}" }, "relatedEvents": []}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1599 — Network Boundary Bridging — Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation. Breaching these devices may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks.