StudyToCert

All certifications / Azure Administrator / Lessons

Microsoft Certified: Azure Administrator Associate AZ-104 · Domain 4: Implement and manage virtual networking

User-defined routes: route tables, next hop types (virtual appliance, virtual network gateway, internet, none) and forced tunneling

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Azure routes traffic automatically with system routes, which you cannot delete. Each subnet gets a route for the VNet's own address space (next hop Virtual network), a default route 0.0.0.0/0 to the Internet, routes for peered VNets and routes learned from gateways. Certain private and reserved ranges not used in the VNet get next hop None, so traffic to them is dropped. This works well until you want traffic to go somewhere else, most often through a firewall for inspection, or back to on-premises. User-defined routes (UDRs) let you override system routes. You create a route table resource, add routes to it, and associate the route table with one or more subnets. A route table affects traffic leaving resources in the subnets it is associated with; it is never associated with a network interface (NIC) or with a whole VNet, and each subnet can have at most one route table. The route table must be in the same region and subscription as the VNet. The steps look like this:

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Administrator for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Administrator study plan