vNet one way Traffic route help

Eric Schroeder 1 Reputation point

I have 3 subscriptions (One Production, 2 development). Since the development environments are managed by the developers we cannot allow traffic from those two vnets into production for security purposes. I would like to find a way to have all users (devs included) access to the main production but send one-way traffic to the dev subscription vnets without separate VPNs to each vnet GW. The goal would be so they can get into their environment but anything they do in there wont have traffic access back to Production.

I currently have three vpn profiles rolled out via Intune and AOVPN installed on everyone's machine since we have half the people working at home and 15+ offices to manage. I am thinking possibly moving it all over to Virtual WAN but I can see how to block traffic from the Dev subs after peering.

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
201 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,290 questions
{count} votes