All network interfaces allocated to an application security group (ASG) must exist in the same virtual network that the 1st network interface allocated to the application security group (ASG) is present. If the 1st network interface allocated to an application security group titled AsgWeb is in the virtual network titled VNet1, all subsequent network interfaces allocated to ASGWeb must exist in VNet1. You can't add network interfaces from different virtual networks to the same application security group (ASG). Reference: https://docs.microsoft.com/en-us/azure/virtual-network/application-security- groups?WT.mc_id=modinfra-33046-thmaure