StudyToCert

All certifications / Azure Fundamentals / Lessons

Microsoft Certified: Azure Fundamentals AZ-900 · Domain 2: Describe Azure architecture and services

Virtual networks, subnets, peering, Azure DNS, and public vs private endpoints

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

An Azure virtual network (VNet) is your own private network in Azure. It lets Azure resources such as VMs communicate with each other, with the internet, and with your on-premises networks. When you create a VNet you give it an address space in private IP ranges, such as 10.1.0.0/16, written in Classless Inter-Domain Routing (CIDR) notation, and it lives in one region and one subscription. VNets provide isolation: resources in one VNet cannot reach resources in another until you connect them. You divide a VNet into subnets, smaller address ranges such as 10.1.1.0/24, to organize and secure resources. For example, you might put web servers in one subnet and database servers in another. Resources in different subnets of the same VNet can talk to each other by default. You filter traffic with network security groups (NSGs), which contain prioritized allow and deny rules based on source, destination, port and protocol, and can be attached to a subnet or a network interface.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Azure Fundamentals for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Azure Fundamentals study plan