Help: Can't Detach VNet to Move App Service

Wang, Qinjie 240 Reputation points
2025-11-26T09:42:29.11+00:00

Hello Dev Team,

I want to move my App Service to another resource group, but I'm getting an error: `(Code: ResourceMoveProviderValidationFailed) Cannot move resources because some site(s) are connected to regional VNet integration. Disconnect all sites from regional VNet integration and try again.`.

I tried to detach the VNet, but it failed without any reason. I have two questions:

If I detach the VNet and move the App Service to a new resource group, will this affect my app's functionality? What is the purpose of this VNet?

Are there any prerequisites for detaching a VNet? Why might the detachment be failing?

Thanks!

Azure App Service
Azure App Service

Azure App Service is a service used to create and deploy scalable, mission-critical web apps.


Answer accepted by question author
Praneeth Maddali 12,670 Reputation points Microsoft External Staff Moderator
2025-11-27T07:34:12.8566667+00:00

HI @Wang, Qinjie

Thank you for the clear explanation—this is a common challenge when migrating an App Service that uses regional VNet integration.

Here are quick answers to your questions:

  1. What does VNet integration do, and what happens if it’s removed? It provides your app with outbound access to resources within the VNet, such as private endpoints, VMs, or on-prem connections via VPN/ExpressRoute. If you detach it, any connections to those private resources will stop working immediately, but the public site will remain accessible. The only downtime will be a brief app restart when disconnecting (usually less than 2 minutes) and another restart when reconnecting.
  2. Will detaching, moving, and re-attaching cause any lasting issues? No, as long as you re-attach to the same VNet and subnet, everything will return to its previous state. This process is done routinely without problems.

The disconnect usually fails silently due to one of these common reasons:

  • There are stale “Service association links” remaining on the subnet.
  • Permissions are missing on the subnet or VNet—you need Contributor access or higher on the subnet itself.

Here is the quickest way to resolve the issue and finish the move:

  1. Use the built-in troubleshooter (this quickly identifies the blocker). Go to App Service → Diagnose and solve problems > search for “VNet” > run “Subnet/VNet deletion issue”. This will check for any locks, stale links, or delegation issues and often provides a one-click solution.
  2. If the portal still does not work, try forcing the disconnect
       az webapp vnet-integration remove --name <YourAppName> --resource-group <CurrentResourceGroup>
    
    This almost always succeeds even when the portal is stuck.
  3. Please move the App Service and the App Service Plan to the new resource group. Once the integration is removed, the transfer will be completed immediately.
  4. Please reattach the same VNet by navigating to Networking > VNet integration >Add VNet, and then selecting the original subnet. This process typically takes about 60 seconds and includes one restart.

Reference :

https://learn.microsoft.com/en-us/cli/azure/webapp/vnet-integration?view=azure-cli-latest

https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/move-resource-group-and-subscription?tabs=azure-cli#use-the-portal

https://learn.microsoft.com/en-us/troubleshoot/azure/app-service/troubleshoot-vnet-integration-apps#cant-remove-vnet-integration

Kindly let us know if the above helps or you need further assistance on this issue.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.