Virtual Network: Subnet Deletion Blocked by Orphaned Power Platform Service Association Link

AndersonGuimaraes-6487 0 Reputation points
2026-10-08T19:11:55.12+00:00

Problem description

I am trying to delete an Azure subnet, but the operation fails because the subnet is reported as being in use by a Power Platform Service Association Link (SAL) named PowerPlatformSAL.

The subnet deletion error indicates that the subnet is still referenced by a Service Association Link and therefore cannot be deleted.

Based on my investigation, the SAL appears to be orphaned because I cannot identify any existing Power Platform resource that owns it.

Environment

  • Azure Virtual Network
  • Dedicated subnet previously used for Power Platform networking
  • Service Association Link (SAL): PowerPlatformSAL
  • Linked Resource Type: Microsoft.PowerPlatform/vnetaccesslinks

The subnet is delegated to:

Microsoft.PowerPlatform/vnetaccesslinks

What I've already tried

Verified subnet configuration

The subnet contains:

  • A delegation to Microsoft.PowerPlatform/vnetaccesslinks
  • A Service Association Link named PowerPlatformSAL
  • The SAL has:
    • allowDelete = false
      • provisioningState = Succeeded

Searched for Power Platform resources

I searched the subscription for:

  • Microsoft.PowerPlatform/vnetaccesslinks
  • Microsoft.PowerPlatform/enterprisePolicies

No resources of either type were found.

Attempted direct SAL deletion

I attempted to delete the Service Association Link directly through Azure Resource Manager APIs.

The operation failed with an authorization error indicating that the SAL is managed by the resource provider and cannot be deleted directly.

Attempted subnet deletion

The subnet deletion continues to fail because Azure reports that the subnet is in use by:

PowerPlatformSAL

Checked provider registration

The Microsoft.PowerPlatform resource provider is registered in the subscription and exposes the enterprisePolicies resource type, but no associated resources are present.

Current findings

At this point, the following appears to be true:

  • The subnet contains an active Service Association Link named PowerPlatformSAL.
  • The SAL references Microsoft.PowerPlatform/vnetaccesslinks.
  • No corresponding Power Platform resources can be found in the subscription.
  • The SAL cannot be deleted directly through ARM APIs.
  • The subnet cannot be deleted while the SAL exists.

This leads me to believe the subnet contains an orphaned Power Platform Service Association Link.

Question

    • How did you identify the owning Power Platform resource ?
    • Is there a supported self-service process to remove the orphaned SAL?

Any guidance would be greatly appreciated.

Resource Group: rg-calsaver-qa

Virtual Network: vnet-calsaver-qa-eus2

Subnet: vnet-data-gateway

Service Association Link: PowerPlatformSAL

Linked Resource Type: Microsoft.PowerPlatform/vnetaccesslinks

Support request number is 2610080040006180

Azure Virtual Network
Azure Virtual Network

An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.

0 comments No comments

1 answer

Sort by: Newest
  1. Rukshan edirisinghe 1,320 Reputation points
    2026-10-09T02:59:18.23+00:00

    Hi @AndersonGuimaraes-6487

    That SAL isn't created by an Azure resource in your subscription, which is why the resource search comes back empty. A subnet delegated to Microsoft.PowerPlatform/vnetaccesslinks is usually held by one of two things on the Power Platform side: a VNet data gateway, or a Power Platform environment using subnet injection through an enterprise policy (and that policy can live in a different subscription).

    I'd work through it in this order:

    1. In the Power Platform admin center, open the virtual network data gateways list and look for any gateway on this VNet and subnet. If one exists, remove it. Microsoft notes that after removing the last gateway on a subnet, it can take up to 48 to 72 hours before the subnet can be deleted.
    2. Check your environments for an enterprise policy link. If one is still linked, run Disable-SubnetInjection -EnvironmentId <id> from the Microsoft.PowerPlatform.EnterprisePolicies module to unlink it.
    3. Keep the Microsoft.PowerPlatform provider registered while this cleans up, then retry the subnet delete.
    4. If nothing is linked on either side and it still fails after waiting, add what you found to the support request you already opened, since the resource provider has to release the SAL.

    One small thing: you may want to edit the subscription ID out of your post. It's safer to keep it only in the support case.

    Was this subnet used for a VNet data gateway, or for environment-level VNet support?

    If this resolved your issue, please consider accepting it as the answer. If the subnet still won't delete, let me know and I'll be happy to keep helping.

    Reference:

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.