@napblanket
Yes, when VPN and Express route both co-exist, the ExpressRoute circuit is always the primary link from Azure to on-premise. Data flows through the Site-to-Site VPN path only if the ExpressRoute circuit fails. Please let us know if you have any more questions. Thank you!
Remember:
Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.
Want a reminder to come back and check responses? Here is how to subscribe to a notification.