LEARNING AZURE / YOUR CLOUD LEARNING SPACE
No account neededAbout
Networking / 30–40 min

Build your first virtual network

Design a small private address space and create a virtual network with one subnet. Focus on the network itself before adding virtual machines or connectivity services.

What you’ll be able to do

  • Describe the relationship between a virtual network and a subnet.
  • Choose a non-overlapping private address range.
  • Verify the resulting network configuration with Azure CLI.
Before you beginComplete lesson 1. Permission to create Microsoft.Network resources in rg-learningazure. Use Bash Cloud Shell or a local Azure CLI session. Validate address ranges against your organization’s networks.

Get the idea

A private network boundary

An Azure virtual network provides an address space for connected resources. A subnet divides that space into smaller ranges. Existing on-premises routing knowledge is useful, but Azure manages the underlying network fabric.

Design before connecting

Overlapping address spaces can complicate peering and hybrid connectivity. The example uses 10.42.0.0/16 for the network and 10.42.1.0/24 for one subnet. These are practice values, not a universal recommendation.

Access and connectivity are separate

A resource group organizes resources; it is not a network boundary. Network security groups control traffic rules, while identity permissions control management operations. Do not assume a newly created subnet provides an explicit outbound connectivity design.

Try it yourself

  1. Check whether the example ranges overlap with existing networks. Substitute approved ranges if necessary.
  2. Run the create command below to create vnet-learningazure and subnet-app.
  3. Inspect the network output, then open the IP addresses view in the portal.
  4. Confirm that 10.42.1.0/24 fits inside the network’s 10.42.0.0/16 address space.
  5. Draw two additional subnet ranges that would fit without overlap. Do not deploy VMs, Bastion, NAT gateways, or public IPs in this exercise.

Example · commands or prompt

az network vnet create --resource-group rg-learningazure --name vnet-learningazure --address-prefixes 10.42.0.0/16 --subnet-name subnet-app --subnet-prefixes 10.42.1.0/24
az network vnet show --resource-group rg-learningazure --name vnet-learningazure --output json
Check your resultThe network contains the expected address space and subnet, and you can explain why the ranges do not overlap.

Finish the lab

Keep the virtual network for the course, or delete only vnet-learningazure after confirming it has no connected resources. Additional network services and traffic can incur charges; this exercise creates only the network and subnet.

Quick knowledge check

Does placing two resources in the same resource group make them part of the same network?

Reveal the explanation

No. Resource groups and virtual networks have different purposes. Network attachment and routing determine network connectivity.

Take this with you

Plan address space and traffic requirements before you create connected workloads.

Go deeper

AI-assisted lesson · Reference links checked October 3, 2026. Exercises are teaching examples; they have not been executed against your Azure subscription.