Requirements and considerations for sharing ExpressRoute between different tenants.

Anonymous
2024-02-06T09:10:04.8766667+00:00

Hello. Please tell me about the requirements and considerations for sharing Azure's ExpressRoute between different tenants. While researching how to share Azure ExpressRoute between different tenants, I found the following article. https://video2.skills-academy.com/ja-jp/azure/expressroute/expressroute-faqs#i-have-multiple-azure-subscriptions-associated-to-different-microsoft-entra-tenants-or-enterprise-agreement-enrollments-can-i-connect-virtual-networks-that-are-in-separate-tenants-and-enrollments-to-a-single-expressroute-circuit-not-in-the-same-tenant-or-enrollment Additionally, for information on how to share ExpressRoute between different tenants, please refer to the following article. ・How to share ExpressRoute between different subscriptions. https://video2.skills-academy.com/ja-jp/azure/expressroute/expressroute-howto-linkvnet-arm#connect-a-virtual-network-in-a-different-subscription-to-a-circuit The information provided is about how to share Azure ExpressRoute between different subscriptions. Can the same steps be applied to share Azure ExpressRoute between different tenants as well? The process for sharing ExpressRoute between different tenants and different subscriptions can be achieved in exactly the same way. Could you please inform me if there are any considerations, precautions, or conditions to keep in mind when sharing ExpressRoute between different tenants?

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
340 questions
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 49,006 Reputation points Microsoft Employee
    2024-02-06T09:57:34.32+00:00

    Hello @rufi ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you would like to know about the requirements and considerations for sharing ExpressRoute circuit between different tenants.

    As mentioned in the Azure ExpressRoute FAQ, ExpressRoute authorizations can span subscription, tenant, and enrollment boundaries with no extra configuration required.

    And the steps provided on how to share Azure ExpressRoute between different subscriptions are the same steps which needs to be applied to share Azure ExpressRoute between different tenants.

    The circuit owner can create authorizations that can be redeemed by 'circuit users'. Circuit users are owners of virtual network gateways that aren't within the same subscription as the ExpressRoute circuit. Circuit users can redeem authorizations (one authorization per virtual network).

    The circuit owner creates an authorization, and the circuit user will use the resource ID of the ExpressRoute circuit and the authorization key from the circuit owner to create a connection between the ExpressRoute circuit and their ExpressRoute gateway.

    The only considerations are the ones already mentioned in the public article:

    • Connecting virtual networks between Azure sovereign clouds and Public Azure cloud is not supported. You can only link virtual networks from different subscriptions in the same cloud.
    • Connectivity and bandwidth charges for the dedicated circuit will be applied to the ExpressRoute circuit owner. All virtual networks share the same bandwidth.
    • An authorization is valid for only one connection.
    • The circuit owner has the power to modify and revoke authorizations at any time. Revoking an authorization result in all link connections being deleted from the subscription whose access was revoked.
    • You can link up to 10 virtual networks to a standard ExpressRoute circuit. All virtual networks must be in the same geopolitical region when using a standard ExpressRoute circuit.
    • A single virtual network can be linked to up to 16 ExpressRoute circuits.
    • If you enable the ExpressRoute premium add-on, you can link virtual networks outside of the geopolitical region of the ExpressRoute circuit. The premium add-on also allows you to connect more than 10 virtual networks to your ExpressRoute circuit depending on the bandwidth chosen.

    Refer: https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-howto-linkvnet-portal-resource-manager?pivots=expressroute-current#connect-a-virtual-network-to-a-circuit---different-subscription

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please don’t forget to "Accept the answer" wherever the information provided helps you, this can be beneficial to other community members.


0 additional answers

Sort by: Most helpful