Bicep resource definition
The virtualHubs/connectionPolicies resource type can be deployed with operations that target:
For a list of changed properties in each API version, see change log.
To create a Microsoft.Network/virtualHubs/connectionPolicies resource, add the following Bicep to your template.
resource symbolicname 'Microsoft.Network/virtualHubs/connectionPolicies@2025-09-01' = {
parent: resourceSymbolicName
name: 'string'
properties: {
enableInternetSecurity: bool
routingConfiguration: {
associatedRouteTable: {
id: 'string'
}
inboundRouteMap: {
id: 'string'
}
outboundRouteMap: {
id: 'string'
}
propagatedRouteTables: {
ids: [
{
id: 'string'
}
]
labels: [
'string'
]
}
vnetRoutes: {
staticRoutes: [
{
addressPrefixes: [
'string'
]
name: 'string'
nextHopIpAddress: 'string'
}
]
staticRoutesConfig: {
propagateStaticRoutes: bool
vnetLocalRouteOverrideCriteria: 'string'
}
}
}
}
}
Property Values
Microsoft.Network/virtualHubs/connectionPolicies
| Name |
Description |
Value |
| name |
The resource name |
string
Constraints: Pattern = ^(?![.-])[a-zA-Z0-9_.-]{1,128}$ (required) |
| parent |
In Bicep, you can specify the parent resource for a child resource. You only need to add this property when the child resource is declared outside of the parent resource.
For more information, see Child resource outside parent resource. |
Symbolic name for resource of type: virtualHubs |
| properties |
Properties of the ConnectionPolicy resource. |
ConnectionPolicyProperties |
ConnectionPolicyProperties
| Name |
Description |
Value |
| enableInternetSecurity |
Enable internet security. |
bool |
| routingConfiguration |
The Routing Configuration indicating the associated and propagated route tables on this connection. |
RoutingConfiguration |
PropagatedRouteTable
| Name |
Description |
Value |
| ids |
The list of resource ids of all the RouteTables. |
SubResource[] |
| labels |
The list of labels. |
string[] |
RoutingConfiguration
| Name |
Description |
Value |
| associatedRouteTable |
The resource id RouteTable associated with this RoutingConfiguration. |
SubResource |
| inboundRouteMap |
The resource id of the RouteMap associated with this RoutingConfiguration for inbound learned routes. |
SubResource |
| outboundRouteMap |
The resource id of theRouteMap associated with this RoutingConfiguration for outbound advertised routes. |
SubResource |
| propagatedRouteTables |
The list of RouteTables to advertise the routes to. |
PropagatedRouteTable |
| vnetRoutes |
List of routes that control routing from VirtualHub into a virtual network connection. |
VnetRoute |
StaticRoute
| Name |
Description |
Value |
| addressPrefixes |
List of all address prefixes. |
string[] |
| name |
The name of the StaticRoute that is unique within a VnetRoute. |
string |
| nextHopIpAddress |
The ip address of the next hop. |
string |
StaticRoutesConfig
| Name |
Description |
Value |
| propagateStaticRoutes |
Boolean indicating whether static routes on this connection are automatically propagate to route tables which this connection propagates to. |
bool |
| vnetLocalRouteOverrideCriteria |
Parameter determining whether NVA in spoke vnet is bypassed for traffic with destination in spoke. |
'Contains' 'Equal' |
SubResource
| Name |
Description |
Value |
| id |
Resource ID. |
string |
VnetRoute
| Name |
Description |
Value |
| staticRoutes |
List of all Static Routes. |
StaticRoute[] |
| staticRoutesConfig |
Configuration for static routes on this HubVnetConnection. |
StaticRoutesConfig |
ARM template resource definition
The virtualHubs/connectionPolicies resource type can be deployed with operations that target:
Usage Examples
To create a Microsoft.Network/virtualHubs/connectionPolicies resource, add the following JSON to your template.
{
"type": "Microsoft.Network/virtualHubs/connectionPolicies",
"apiVersion": "2025-09-01",
"name": "string",
"properties": {
"enableInternetSecurity": "bool",
"routingConfiguration": {
"associatedRouteTable": {
"id": "string"
},
"inboundRouteMap": {
"id": "string"
},
"outboundRouteMap": {
"id": "string"
},
"propagatedRouteTables": {
"ids": [
{
"id": "string"
}
],
"labels": [ "string" ]
},
"vnetRoutes": {
"staticRoutes": [
{
"addressPrefixes": [ "string" ],
"name": "string",
"nextHopIpAddress": "string"
}
],
"staticRoutesConfig": {
"propagateStaticRoutes": "bool",
"vnetLocalRouteOverrideCriteria": "string"
}
}
}
}
}
Property Values
Microsoft.Network/virtualHubs/connectionPolicies
| Name |
Description |
Value |
| apiVersion |
The api version |
'2025-09-01' |
| name |
The resource name |
string
Constraints: Pattern = ^(?![.-])[a-zA-Z0-9_.-]{1,128}$ (required) |
| properties |
Properties of the ConnectionPolicy resource. |
ConnectionPolicyProperties |
| type |
The resource type |
'Microsoft.Network/virtualHubs/connectionPolicies' |
ConnectionPolicyProperties
| Name |
Description |
Value |
| enableInternetSecurity |
Enable internet security. |
bool |
| routingConfiguration |
The Routing Configuration indicating the associated and propagated route tables on this connection. |
RoutingConfiguration |
PropagatedRouteTable
| Name |
Description |
Value |
| ids |
The list of resource ids of all the RouteTables. |
SubResource[] |
| labels |
The list of labels. |
string[] |
RoutingConfiguration
| Name |
Description |
Value |
| associatedRouteTable |
The resource id RouteTable associated with this RoutingConfiguration. |
SubResource |
| inboundRouteMap |
The resource id of the RouteMap associated with this RoutingConfiguration for inbound learned routes. |
SubResource |
| outboundRouteMap |
The resource id of theRouteMap associated with this RoutingConfiguration for outbound advertised routes. |
SubResource |
| propagatedRouteTables |
The list of RouteTables to advertise the routes to. |
PropagatedRouteTable |
| vnetRoutes |
List of routes that control routing from VirtualHub into a virtual network connection. |
VnetRoute |
StaticRoute
| Name |
Description |
Value |
| addressPrefixes |
List of all address prefixes. |
string[] |
| name |
The name of the StaticRoute that is unique within a VnetRoute. |
string |
| nextHopIpAddress |
The ip address of the next hop. |
string |
StaticRoutesConfig
| Name |
Description |
Value |
| propagateStaticRoutes |
Boolean indicating whether static routes on this connection are automatically propagate to route tables which this connection propagates to. |
bool |
| vnetLocalRouteOverrideCriteria |
Parameter determining whether NVA in spoke vnet is bypassed for traffic with destination in spoke. |
'Contains' 'Equal' |
SubResource
| Name |
Description |
Value |
| id |
Resource ID. |
string |
VnetRoute
| Name |
Description |
Value |
| staticRoutes |
List of all Static Routes. |
StaticRoute[] |
| staticRoutesConfig |
Configuration for static routes on this HubVnetConnection. |
StaticRoutesConfig |
The virtualHubs/connectionPolicies resource type can be deployed with operations that target:
- Resource groups
For a list of changed properties in each API version, see change log.
To create a Microsoft.Network/virtualHubs/connectionPolicies resource, add the following Terraform to your template.
resource "azapi_resource" "symbolicname" {
type = "Microsoft.Network/virtualHubs/connectionPolicies@2025-09-01"
name = "string"
parent_id = "string"
body = {
properties = {
enableInternetSecurity = bool
routingConfiguration = {
associatedRouteTable = {
id = "string"
}
inboundRouteMap = {
id = "string"
}
outboundRouteMap = {
id = "string"
}
propagatedRouteTables = {
ids = [
{
id = "string"
}
]
labels = [
"string"
]
}
vnetRoutes = {
staticRoutes = [
{
addressPrefixes = [
"string"
]
name = "string"
nextHopIpAddress = "string"
}
]
staticRoutesConfig = {
propagateStaticRoutes = bool
vnetLocalRouteOverrideCriteria = "string"
}
}
}
}
}
}
Property Values
Microsoft.Network/virtualHubs/connectionPolicies
| Name |
Description |
Value |
| name |
The resource name |
string
Constraints: Pattern = ^(?![.-])[a-zA-Z0-9_.-]{1,128}$ (required) |
| parent_id |
The ID of the resource that is the parent for this resource. |
ID for resource of type: virtualHubs |
| properties |
Properties of the ConnectionPolicy resource. |
ConnectionPolicyProperties |
| type |
The resource type |
"Microsoft.Network/virtualHubs/connectionPolicies@2025-09-01" |
ConnectionPolicyProperties
| Name |
Description |
Value |
| enableInternetSecurity |
Enable internet security. |
bool |
| routingConfiguration |
The Routing Configuration indicating the associated and propagated route tables on this connection. |
RoutingConfiguration |
PropagatedRouteTable
| Name |
Description |
Value |
| ids |
The list of resource ids of all the RouteTables. |
SubResource[] |
| labels |
The list of labels. |
string[] |
RoutingConfiguration
| Name |
Description |
Value |
| associatedRouteTable |
The resource id RouteTable associated with this RoutingConfiguration. |
SubResource |
| inboundRouteMap |
The resource id of the RouteMap associated with this RoutingConfiguration for inbound learned routes. |
SubResource |
| outboundRouteMap |
The resource id of theRouteMap associated with this RoutingConfiguration for outbound advertised routes. |
SubResource |
| propagatedRouteTables |
The list of RouteTables to advertise the routes to. |
PropagatedRouteTable |
| vnetRoutes |
List of routes that control routing from VirtualHub into a virtual network connection. |
VnetRoute |
StaticRoute
| Name |
Description |
Value |
| addressPrefixes |
List of all address prefixes. |
string[] |
| name |
The name of the StaticRoute that is unique within a VnetRoute. |
string |
| nextHopIpAddress |
The ip address of the next hop. |
string |
StaticRoutesConfig
| Name |
Description |
Value |
| propagateStaticRoutes |
Boolean indicating whether static routes on this connection are automatically propagate to route tables which this connection propagates to. |
bool |
| vnetLocalRouteOverrideCriteria |
Parameter determining whether NVA in spoke vnet is bypassed for traffic with destination in spoke. |
'Contains' 'Equal' |
SubResource
| Name |
Description |
Value |
| id |
Resource ID. |
string |
VnetRoute
| Name |
Description |
Value |
| staticRoutes |
List of all Static Routes. |
StaticRoute[] |
| staticRoutesConfig |
Configuration for static routes on this HubVnetConnection. |
StaticRoutesConfig |