Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
HI @Wang, Qinjie
Thank you for the clear explanation—this is a common challenge when migrating an App Service that uses regional VNet integration.
Here are quick answers to your questions:
- What does VNet integration do, and what happens if it’s removed? It provides your app with outbound access to resources within the VNet, such as private endpoints, VMs, or on-prem connections via VPN/ExpressRoute. If you detach it, any connections to those private resources will stop working immediately, but the public site will remain accessible. The only downtime will be a brief app restart when disconnecting (usually less than 2 minutes) and another restart when reconnecting.
- Will detaching, moving, and re-attaching cause any lasting issues? No, as long as you re-attach to the same VNet and subnet, everything will return to its previous state. This process is done routinely without problems.
The disconnect usually fails silently due to one of these common reasons:
- There are stale “Service association links” remaining on the subnet.
- Permissions are missing on the subnet or VNet—you need Contributor access or higher on the subnet itself.
Here is the quickest way to resolve the issue and finish the move:
- Use the built-in troubleshooter (this quickly identifies the blocker). Go to App Service → Diagnose and solve problems > search for “VNet” > run “Subnet/VNet deletion issue”. This will check for any locks, stale links, or delegation issues and often provides a one-click solution.
- If the portal still does not work, try forcing the disconnect
This almost always succeeds even when the portal is stuck.az webapp vnet-integration remove --name <YourAppName> --resource-group <CurrentResourceGroup> - Please move the App Service and the App Service Plan to the new resource group. Once the integration is removed, the transfer will be completed immediately.
- Please reattach the same VNet by navigating to Networking > VNet integration >Add VNet, and then selecting the original subnet. This process typically takes about 60 seconds and includes one restart.
Reference :
https://learn.microsoft.com/en-us/cli/azure/webapp/vnet-integration?view=azure-cli-latest
Kindly let us know if the above helps or you need further assistance on this issue.