Azure · Cloud service
Azure Virtual Network with OrchestrAI
Catalog exported 2026-09-02
Build Azure Virtual Networks from chat: VNets, subnets, network security groups, and NSG rules.
OrchestrAI exposes 4 Virtual Network operations: 4 create or modify resources and run only after you confirm the plan.
What teams use it for
Infrastructure teams use OrchestrAI to lay out a VNet with its subnets and create a network security group with the inbound rules an app needs, all in one conversation. Adding a single NSG rule to allow a new port is a frequent follow-up. Coverage is create-only, with no list or delete and no peering operation, so tearing down a network or connecting two VNets is done outside chat.
Every Virtual Network operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Create Azure NSG |
Create an Azure Network Security Group | Creates resources | No |
Create Azure Subnet |
Create a subnet in an Azure Virtual Network | Creates resources | No |
Create Azure VNet |
Create an Azure Virtual Network | Creates resources | No |
Create NSG Rule |
Create a rule in an Azure Network Security Group | Creates resources | No |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
Prompts that work
- Create a VNet called vnet-prod at 10.20.0.0/16 in rg-network in eastus with a subnet app at 10.20.1.0/24
- Create an NSG named nsg-app in rg-network and add a rule allowing inbound 443 from the internet
- Add a subnet called db at 10.20.2.0/24 to vnet-prod
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Are Azure Virtual Network changes through OrchestrAI reversible?
- The VNet, subnet, NSG, and NSG rule operations are all rated medium, which means they create new resources you can remove later. Each one is recorded in the ledger.
- Can OrchestrAI set up VNet peering?
- Peering is not yet available, and the network operations offered are create VNet, create subnet, create NSG, and create NSG rule.
- Which Virtual Network operations need an extra approval step?
- None of the Virtual Network operations currently carries a step-level approval gate; they are read-only or run after plan confirmation like any other change.
Other Azure services
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.