Build Network Manager connectivity configs with network groups, hub-and-spoke topology, and security admin rules.
Build Network Manager connectivity configs with network groups, hub-and-spoke topology, and security admin rules.
Required Fields
nameresourceGroupscopescopeAccessesnetworkGroupsconnectivityConfigurationsOutput will appear here...Build an Azure Virtual Network Manager configuration spanning scope (which management groups/subscriptions the manager governs), networkGroups (static or conditional/tag-based VNet membership), connectivityConfigurations (hub-and-spoke topology), and securityAdminConfigurations (organization-wide NSG-like rules that take precedence over individual NSGs). Security admin rules are the feature most likely to surprise someone: a securityAdminConfigurations rule with a Deny action for a given traffic pattern is enforced ahead of and cannot be overridden by an individual VNet's own NSG rules, meaning a network admin can enforce a baseline (like blocking inbound RDP/SSH from the internet) across every VNet in a network group even if a resource owner's own NSG would otherwise allow it.
The builder validates that name, resourceGroup, scope, scopeAccesses, networkGroups, and connectivityConfigurations all resolve before accepting the JSON as a valid Network Manager configuration, the fields Azure needs to know what the manager governs and how; it can't verify referenced management group or VNet resource IDs actually exist, or that conditional membership tag conditions will match any real resources, those are only confirmed against the live Azure Resource Graph.
Security admin rules are a genuinely powerful centralized override, understand and communicate to VNet owners that these rules can't be worked around at the individual NSG level, this is by design but can be a confusing support case ('my NSG allows this but it's still blocked') if teams aren't aware Network Manager-level rules exist.
Prefer conditional (tag-based) network group membership over static membership lists for anything expected to grow, a static list needs manual maintenance every time a new VNet should join, while a well-designed tag convention scales automatically.
Scope Network Manager at the management group level rather than individually listing subscriptions whenever your organization's subscription count is expected to grow, avoiding the ongoing maintenance burden of updating scope for every new subscription.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.