StudyToCert

All certifications / Azure Fundamentals / Lessons

Microsoft Certified: Azure Fundamentals AZ-900 · Domain 2: Describe Azure architecture and services

Hybrid connectivity: VPN Gateway (site-to-site, point-to-site) vs ExpressRoute

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Many organizations need their on-premises networks and Azure virtual networks (VNets) to work as one, for example so office users can reach an application running on Azure VMs, or so Azure servers can query a database still in the datacenter. Azure offers two main hybrid connectivity options, VPN Gateway and ExpressRoute, and the Microsoft Azure Fundamentals exam (AZ-900) expects you to know when to choose each. A virtual private network (VPN) creates an encrypted tunnel between two networks over an untrusted network, usually the public internet. Azure VPN Gateway is a type of virtual network gateway deployed into a dedicated subnet of your VNet, which must be named GatewaySubnet. It uses Internet Protocol Security (IPsec) and Internet Key Exchange (IKE) to encrypt traffic between the VNet and other locations over the internet. Gateways can be policy-based, using static rules, or route-based, using routing tables; route-based is the more flexible and common choice.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Fundamentals for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Fundamentals study plan