StudyToCert

All certifications / Azure Administrator / Lessons

Microsoft Certified: Azure Administrator Associate AZ-104 · Domain 4: Implement and manage virtual networking

Virtual networks and subnets: address space planning, the 5 reserved IPs per subnet

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

An Azure virtual network (VNet) is your private network in the cloud. Resources such as virtual machines (VMs), private endpoints and internal load balancers get private IP addresses from it and can talk to each other, reach the internet outbound, and, through peering or a VPN (virtual private network), connect to other networks. A VNet belongs to one region and one subscription, and it automatically spans all availability zones in that region, so you do not create a separate network per zone. Good address planning at the start saves painful rebuilds later. When you create a VNet you give it one or more address spaces in CIDR (Classless Inter-Domain Routing) notation, normally from the private ranges defined in RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. The most important planning rule is to avoid overlap. Two VNets with overlapping address spaces cannot be peered, and a VNet that overlaps your on-premises network cannot be connected to it by VPN or ExpressRoute. Large organizations therefore keep an IP address management (IPAM) plan and give each VNet its own non-overlapping block, with room to grow. You can add further address spaces to an existing VNet later if you run out.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Administrator for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Administrator study plan