A partner subscription owns the ExpressRoute circuit and your subscription owns the VNet that must connect to that circuit. You need to attach the VNet to the partner's circuit. What sequence of steps and constraints correctly describes how to establish this cross‑subscription connection using ExpressRoute circuit authorization?
Choose an answer
Tap an option to check your answer.
Correct answer: In the subscription that owns the ExpressRoute circuit generate an authorization key on the circuit. In your subscription use that authorization key when creating an ExpressRouteConnection (or connection) to authorize the circuit to use your VNet. Authorization keys are short‑lived (they expire) and can be regenerated if needed..
Why this is the answer
To connect a VNet in your subscription to an ExpressRoute circuit owned by a partner, the partner must first generate an authorization key on their ExpressRoute circuit. This key acts as a permission token. You then use this authorization key in your subscription when creating an ExpressRouteConnection (or connection) resource to link your VNet Gateway to the partner's circuit. Authorization keys are designed to be temporary and can be regenerated by the circuit owner for security purposes. Incorrect options: Exporting the ExpressRoute service key and pasting it into the virtual network gateway's peer configuration is not the correct method for cross-subscription VNet attachment; service keys are for different purposes like service provider configuration. Azure Lighthouse is for delegated management, not for authorizing cross-subscription ExpressRoute circuit connections. Anonymous peering is not a feature of Azure ExpressRoute and would pose a significant security risk by allowing unauthorized connections.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed