What core architectural capabilities does an Azure Virtual Network (VNet) provide when establishing secure, isolated cloud networking environments, and why is orchestrating micro-segmentation through subnets and network security groups the definitive strategy for safeguarding enterprise-grade hybrid cloud communications?