You can only associate a route table to subnets in virtual networks that exist in the same Azure location and subscription as the route table. https://learn.microsoft.com/en-us/azure/virtual-network/manage-route-table You can associate zero, or one, network security group to each subnet and network interface in a virtual machine. The same network security group can be associated to as many subnets and network interfaces as you choose. https://learn.microsoft.com/en-us/azure/virtual-network/network-security-group-how-it-works