An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
Yep - your understanding is correct - VNets cannot directly consume or route traffic through an ExpressRoute Microsoft peering path.
ExpressRoute supports two distinct peering types. Private Peering connects to IaaS and PaaS resources deployed inside or integrated with your VNets, while Microsoft Peering connects on-premises networks to Microsoft 365, Dynamics 365, and Azure public/PaaS services.
BGP routes learned through Microsoft Peering are advertised to your on-premises edge routers, not to Azure virtual network gateways or VNet route tables. An Azure VNet therefore has no mechanism to consume or insert Microsoft Peering routes.
By default, VNet traffic destined for Azure public endpoints, such as Azure Storage or Azure SQL, uses the built-in system route pointing to the Internet. If you want to keep traffic to Azure PaaS services off the public Internet, without sending it out to on-premises through Microsoft Peering, you should use Virtual Network Service Endpoints or Azure Private Link/Private Endpoints. Service Endpoints keep traffic on the Microsoft backbone, while Private Endpoints assign a private IP address from your VNet to the PaaS resource.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin