Azure Virtual WAN gets chosen because it sounds like the grown-up option. Sometimes it is. Often it's a managed premium a team pays before it needs to, because the decision was made on instinct rather than arithmetic.
Both patterns solve the same problem: connecting spoke networks, on-premises sites, and shared services so traffic flows where it should and nowhere it shouldn't. They differ in who carries the operational weight.
Hub-and-spoke gives you a hub network you own completely. You run the firewall, the route tables, the gateways, and the peering. Total control, and total responsibility for every piece. When something routes oddly at 2am, it's yours to understand and fix.
Virtual WAN hands the transit core to Microsoft. Routing, scale, and branch connectivity become a managed service. You give up some fine-grained control and rent the convenience, billed per hub, per connection, and per hour of data processed.
The decision turns on a few honest questions.
How much network will you actually run in the next two years? Not the roadmap fantasy, the real count of regions and branches. Two regions and a handful of spokes rarely justify vWAN's managed transit. Thirty branches across continents almost always do.
Does your team want to hand-manage route tables and firewall failover? A capable network team that values that control will find hub-and-spoke cheaper and clearer. A small team whose hours are better spent elsewhere is making a rational trade by paying Microsoft to run the hard part.
What does your traffic actually look like? If it mostly flows through a central hub to shared services and the internet, hub-and-spoke fits naturally. If you genuinely need any-to-any connectivity between many sites, vWAN's transit earns its price quickly.
The mistake I see most is treating this as a status decision, assuming vWAN is "more enterprise" and therefore right. Run it as an economic one instead. Model both against your real topology and expected growth, put the run-cost and the staff-time side by side, and the answer usually stops being a matter of opinion.
If you take one thing from this: the right topology is the one whose total cost, including the hours your team spends running it, is lowest for the scale you actually operate at. That's rarely the flashiest option, and almost never a decision to make on vibes.
Next: why identity, not the firewall, is your real security perimeter now.