Azure Weekly
Issue 573
2nd August 2026
Highlights this week include:
- Microsoft Tops $90B Quarterly Revenue as Azure Hits $100B Annual Milestone by Sean Parker - Microsoft's $90 billion quarterly revenue reflects robust Azure growth and expanding AI market penetration across enterprises.
- Public Preview: Azure Enclave by The Azure Updates Team - Azure Enclave’s public preview supports high-security tenants, offering automated setup and centralized governance for isolating critical applications in Azure Government regions.
- Introducing Physical-World Intelligence: How GeoAI Is Helping Expand Enterprise AI by Nora Zhang - Physical-World Intelligence integrates real-world data including weather, satellite imagery, and infrastructure maps with enterprise information via AI to improve operational decision-making, such as forecasting storm effects on utilities.
- AI-Enabled Map Production Using Microsoft's MARS Model by Nelson Tam - The new Map Autoregressive (MARS) model from Microsoft automatically converts satellite images into structured GIS-ready vector maps, streamlining and accelerating automated feature extraction for enterprise mapping needs.
- Bring Your Own Orchestrator to Azure Container Apps Jobs by Hetvi Patel - Bring Your Own Orchestrator to Azure Container Apps Jobs lets teams use familiar workflow engines like Airflow, Temporal, or Dapr with Azure Container Apps Job execution layers, maintaining control plane familiarity while leveraging ACA Jobs for task processing.
Finally, I was renewed as a Microsoft MVP for the 11th year. This time around for the dual categories of Azure and .NET. These two interests come together in the Rx .NET framework, which was designed ~20 years ago for a cloud native future. We've just released v7.0 and my colleague and fellow MVP Ian Griffiths has just published a ~25 minute talk - Rx.NET v7.0 Released - and it could save you 95MB! - Rx.NET 7.0 reduces application deployment size by up to 95 MB through separated UI framework support in dedicated NuGet packages for .NET 8+, fixes breaking changes, and maintains binary compatibility.
🤖 AI
- Generally Available: Claude Opus 5 on Azure Databricks Azure Databricks now offers Anthropic’s Claude Opus 5 model with advanced AI features like complex reasoning, coding assistance, and agentic workflows integrated into its platform.
- Building Archon: Where Models Stop and Financial Controls Begin Archon is an Agentic Financial Intelligence prototype that defines engineering boundaries between AI model assistance, deterministic software checks, and human review in financial document processing.
- MCP Connect: Why Every AI Engineer and Developer Should Care About the Model Context Protocol MCP Connect unites AI engineers and developers to explore how the Model Context Protocol enhances agent integration with tools, data, and peers through workshops, client talks, and real-world showcases.
- Bruno Borges on Different Ways to User Microsoft Copilot Bruno Borges explores lesser-known features of GitHub Copilot, demonstrating how to leverage them through the GitHub App, CLI, web interface, and popular IDE integrations.
- The harness is all you need (mostly) This article emphasizes using existing features of GitHub Copilot-referred to as the "harness"-to boost AI productivity without needing complex prompts or advanced skills.
- How I Built CurriculumCraft AI — A Microsoft Hackathon Winning EdTech Solution for Ghana's Teachers CurriculumCraft AI, developed by Gideon K.
- Introducing Physical-World Intelligence: How GeoAI Is Helping Expand Enterprise AI Physical-World Intelligence integrates real-world data including weather, satellite imagery, and infrastructure maps with enterprise information via AI to improve operational decision-making, such as forecasting storm effects on utilities.
- More control over web grounding with Domain Exclusion for Microsoft 365 Copilot Domain Exclusion for Microsoft 365 Copilot lets admins block specific external websites from influencing AI-generated responses, enhancing policy compliance and trusted source management.
- Introducing Kimi K3 through Fireworks AI on Microsoft Foundry Kimi K3, an open-weight 2.8 trillion-parameter model from Moonshot AI with a 1 million-token context window, is now deployable on Microsoft Foundry via Fireworks AI for full codebase analysis, long document processing, and extended conversation memory in a single prompt.
- What's New in Excel (July 2026) The July 2026 Excel update adds inline citations for Copilot, synced connectors for cross-platform data integration, and improved Power BI grounding for analyzing trusted business metrics within Excel.
- Token Economics in Practice Token economics emphasizes cost per accepted task over token price, noting that cheaper inference can result in significantly higher variable costs due to longer stochastic trajectories in agentic workloads.
- When Your AI Agent Lies: Silent LLM Fallbacks The article details how silent LLM fallbacks in an AI agent system silently degraded performance over time due to three hidden bugs-API version mismatches, parameter incompatibilities, and misconfigured defaults-that each individually went unnoticed until combined, highlighting the importance of monitoring fallback usage and token consumption.
- Avoiding Reasoning Model Failures with Microsoft Foundry Avoiding Reasoning Model Failures with Microsoft Foundry emphasizes four key pitfalls that lead to unexpected issues despite minor changes.
- Treat prompt changes like code deploys Implementing prompt change evaluation gates, like CI for code, ensures LLM-driven features maintain quality by catching subtle regressions before they reach production.
- Grounded AI That Won't Invent Facts: Building "Tell My Day" with Microsoft Foundry IQ Tell My Day employs Microsoft Foundry IQ to fetch factual information, mandates verbatim citations, and validates them server-side for reliable content delivery.
- Join us for our MCP Live! — A free livestream covering all things MCP MCP Live! will showcase presentations from key industry leaders on the latest advancements and best practices for implementing the Model Context Protocol in AI tools and enterprise solutions.
- Building and Deploying Microsoft Hosted Agents to Microsoft Teams Using the BRK241 FibreOps reference implementation, deploy and manage identity, scaling, monitoring, rollback, and user access for AI agents in Azure Foundry and Teams environments.
- Microsoft Foundry Models: A Field Guide for Cloud Solution Architects Microsoft Foundry Models provides a comprehensive field guide for cloud solution architects covering prioritized model families, use cases, and informed routing decisions via the Azure Well-Architected Framework's five pillars.
- Executive AI Avatar Platform on Azure: Frontier Intelligence Meets Fireworks AI Open-Source The platform integrates photorealistic avatars and customizable language models for cost-effective, high-performance enterprise deployments on Azure.
- The Microsoft AI and Agent Platform — The Platform Behind Intelligent Agents The platform centers on delivering enterprise value via integrated foundation models, data grounding, tool access, user experiences, operational support, and governance for scalable intelligent agents across various sectors.
- Why Your LLM Doesn’t Know Anything About Your Company And How RAG Fixes That RAG solves large language models' limitation by dynamically fetching relevant enterprise documents at query time, ensuring accurate and contextually grounded answers.
- Introducing GPT-transcribe and GPT-live-transcribe in Microsoft Foundry GPT-transcribe and GPT-live-transcribe in Microsoft Foundry provide high-accuracy transcription for both stored audio files and live voice interactions, addressing real-world challenges like background noise, short utterances, alphanumeric codes, domain terminology, mixed languages, accents, whispering speech, and delivering text suitable for downstream workflows such as search, summarization, routing, analytics, automation, and quality review.
- ARGUS: Compliance Infrastructure That Believes Financial Access Is a Human Right ARGUS is an open, explainable compliance system using five AI agents for KYC checks, offering transparent risk reports to aid financially excluded individuals in accessing banking services.
- Securing On-Device AI: Evaluating Foundry Local Models with AI Red Teaming Agent The article demonstrates how to secure on-device AI models using Foundry Local's runtime and an AI Red Teaming Agent that systematically evaluates safety risks before deployment.
- Agent governance is organizational readiness Agent governance ensures safe integration of agents into healthcare by addressing clinical workflow disruption, risk types, physician trust, and liability accountability.
- Skill or Sub-Agent. Choosing AI Capabilities You Will Actually Reuse Choosing between building an AI skill for iterative, voice-rich tasks or a sub-agent for bounded, structured outputs depends on iteration model, voice fidelity, human review placement, and risk blast radius.
- CivicGrant IQ: The Five-Agent AI That Reads Federal Grants So Cities Don't Have To CivicGrant IQ automates federal grant analysis using five AI agents with six-step reasoning and real-time data to assist cities in qualifying, matching projects, verifying finances, scoring gaps, drafting applications, and planning timelines in under a minute.
- 🚀 Foundry Toolkit for VS Code — July 2026 Update The July 2026 update for Foundry Toolkit in VS Code streamlines workflows by flattening resource management into tabbed pages, adding an inline Tool Catalog, enhancing the Agent Inspector to display detailed event logs, and introducing a preview feature called Agent Optimization that lets users iteratively fine-tune agents with measurable improvements.
- AI-Enabled Map Production Using Microsoft's MARS Model The new Map Autoregressive (MARS) model from Microsoft automatically converts satellite images into structured GIS-ready vector maps, streamlining and accelerating automated feature extraction for enterprise mapping needs.
- NEWS: Anthropic Models coming to Microsoft 365 Copilot Government Community Cloud (GCC) Government Community Cloud users of Premium Microsoft 365 Copilot will soon gain direct access to Anthropic’s Claude Sonnet and Opus 5 models for enhanced deep reasoning at no extra cost or token usage.
- Azure AI Foundry: from zero to production Azure AI Foundry provides a unified platform guiding engineering teams from prototype to production with model catalog, deployment options (PAYGO for low traffic and PTU for high-volume workloads), governance tools, and cost management calculators.
- Building Agentic Experiences with Website Search Capabilities in Microsoft Foundry Microsoft Foundry streamlines AI integration for websites by allowing agents to conduct web searches, illustrated via a step-by-step guide on creating an agentic search tool for the cocktail blog SirShaker.com.
- RAG in .NET: The Complete Series The RAG in .NET series dives deep into practical challenges like chunking, retrieval quality, observability, and tooling for maintaining healthy production pipelines beyond basic tutorials.
- Reproducing an AI Action Plan Analysis with the Microsoft Discovery App The Microsoft Discovery app generates a detailed 43-page research report from 10,000 AI Action Plan responses in three hours, showcasing advanced AI-driven discovery.
🔎 Analytics
- Public Preview: Azure Monitor Logs mirroring into Microsoft Fabric Azure Monitor Logs provides a public preview to mirror telemetry directly into OneLake as Delta Parquet files for efficient analysis without duplication or loss of real-time data.
- Working Around the Lack of Partition Switching in Microsoft Fabric SQL Database The article explains how disabling foreign key constraints allowed for faster bulk deletions in Microsoft Fabric’s SQL Database, reducing operation time significantly.
- Share Azure Monitor Logs to Microsoft Fabric (preview) Sharing Azure Monitor Logs to Microsoft Fabric in Delta Parquet format enables real-time analytics across observability data and business tools without duplication or extra cost.
🖥️ Compute
- Find Alternative Azure VM SKUs with azqr The new alternative-vm-sku command in Azure Quick Review helps users find compatible VM SKUs for workload modernization, quota management, and cost optimization.
🚢 Containers
- Generally Available: Resource placement in Azure Kubernetes Fleet Manager Azure Kubernetes Fleet Manager’s new resource placement feature automates updates and ensures consistency across multiple clusters, reducing manual workload by 40%.
- Generally Available: Application Routing with Gateway API Application routing with Gateway API's GA on AKS simplifies modernizing ingress management by aligning older deployments with newer Kubernetes standards seamlessly.
- Public Preview: Prepared Image Specification Azure Kubernetes Service’s new Prepared Image Specification reduces node startup times by pre-pulling and caching container images, cutting initialization delays for AI, GPU, and performance-critical workloads.
- Public Preview: Maximum allowed failures for update runs in Azure Kubernetes Fleet Manager Azure Kubernetes Fleet Manager’s new preview feature lets you define the maximum allowed update run failures, preventing cascading issues during fail-fast deployments.
- Bring Your Own Orchestrator to Azure Container Apps Jobs Bring Your Own Orchestrator to Azure Container Apps Jobs lets teams use familiar workflow engines like Airflow, Temporal, or Dapr with Azure Container Apps Job execution layers, maintaining control plane familiarity while leveraging ACA Jobs for task processing.
🗄️ Databases
- Generally Available: Azure Database for PostgreSQL flexible server in India South Central Azure now offers general availability of its PostgreSQL flexible server in the India South Central region, expanding cloud database options locally.
- Public Preview: Azure SQL updates for late-July Azure SQL introduces a preview of regex-based dynamic data masking, allowing central hiding of sensitive information such as emails, phone numbers, and identifiers.
- SQL Server index tuning: common mistakes and how to fix them This guide identifies common SQL Server indexing errors like over-indexing, oversized INCLUDE lists, unnecessary fill factors, misuse of SORT_IN_TEMPDB, and aggressive maintenance that can degrade performance despite adding indexes.
- What customers value most in Microsoft Databases—from reliability to AI readiness Customer feedback emphasizes reliability, scalability, operational simplicity, developer productivity, and AI readiness as key values in Microsoft databases influencing investments in SQL Server, Azure SQL Database, Azure Cosmos DB, and Azure Database for PostgreSQL.
- SQL Server Performance Office Hours Episode 70 In Episode 70, Erik Darling addresses audience questions on SQL Server performance issues such as Performance Monitor queries, temp tables' effects, and table variables' efficiency.
- AI-Powered Retrieval in PostgreSQL with Azure HorizonDB Azure HorizonDB integrates AI-powered retrieval into PostgreSQL using BM25 text search, AI Model Management for embeddings, pgvector for storage, DiskANN for indexing, and an AI pipeline to maintain consistency without procedural code.
- The “Successful Login” Dilemma: Why Your Login Auditing Strategy Might Be Hurting Your Server The article explains that default login auditing methods can cause performance issues and poor queryability, recommending ultra-lightweight Extended Events as a better alternative.
- Enabling DB Auditing in Azure SQL DB hangs for a long time The article explains that enabling database auditing in Azure SQL DB can cause the portal to hang, with a workaround involving correct settings for "Allow protected append writes" and adjusted predicate expressions.
- Lesson Learned #548: From Symptoms to Evidence – How I Approach an Azure SQL Investigation This article details a method for moving from unclear Azure SQL issues like slow performance or connection problems to collecting specific evidence via thorough questioning, clear symptom description, and separating observed facts from possible causes.
- Give Your E-Commerce App a Memory: Adding Agents That Actually Remember Your Customers The article introduces an AI shopping assistant with persistent memory for e-commerce apps, using the Microsoft Agent Framework and SQL Server to let customers discuss preferences across sessions without forgetting their past interactions.
- Troubleshooting SQL Authentication Failures on Azure SQL Database Geo-Secondary Replicas SQL authentication failures on Azure SQL Database geo-secondary replicas often result from mismatches in server-level login configurations that aren't automatically replicated.
- Why SQL Server Database Attach fails and how to repair it SQL Server database attach failures commonly result from incomplete file transfers, missing or corrupted transaction logs, version mismatches, locked files, thread pool limits, and physical file corruption.
- Binary Event Serialization for Marten Marten 9.0 introduces binary event serialization via MemoryPack or MessagePack, reducing throughput and storage costs for hot streams while allowing JSON and binary events to coexist without data migration.
- Spin Up MongoDB Atlas Clusters in Azure (Preview) You can now create and manage MongoDB Atlas clusters directly from the Azure portal, choosing performance tiers, data residency regions, and keeping billing unified through your existing Azure Marketplace plan.
- How a SQL Server backup can execute attacker code during restore – and how to prevent it (CVE-2026-47295 vulnerability) CVE-2026-47295 enables a malicious SQL Server backup to execute attacker-controlled code with sysadmin privileges during restore via a truncation flaw in the replication cleanup procedure, potentially compromising the entire instance.
- Understanding Azure SQL Long-Term Retention Immutability Configuration with Terraform and AzAPI Azure SQL's resource provider prevents disabling time-based immutability when immutability mode is specified, leading to Terraform/AzAPI deployment failures that can be resolved by omitting or setting immutability mode to null.
🛠️ Developer tools
- GitHub Copilot app for Beginners: Getting started The GitHub Copilot app for beginners offers a workspace with complex software workflow support, enabling multiple AI agent sessions in one project, streamlining task management, and integrating interactive UI previews to boost productivity.
- Speak Your Vibe: VS Code Insiders Talks Up Voice-Driven Development In the latest VS Code 1.131 Insiders build, Microsoft is placing a significant focus on integrating voice-driven development tools, including enhanced dictation and Voice Mode functionalities.
- Dev Containers in VS Code: Why every project needs one Dev containers in VS Code standardize project environments, ensuring consistent tool versions and reducing "works on my machine" issues for infrastructure engineers by encapsulating all dependencies within a reproducible Docker setup.
- Visual Studio July Update — Meet the New Agent, Powered by the GitHub Copilot SDK The July Visual Studio update adds a new Agent (Preview) in Copilot Chat using the GitHub Copilot SDK for improved AI assistance across tools, enabling customization with .NET and Azure skills.
- Talk: Rx.NET v7.0 Released Rx.NET 7.0 reduces application deployment size by up to 95 MB through separated UI framework support in dedicated NuGet packages for .NET 8+, fixes breaking changes, and maintains binary compatibility.
- Tell your model when to think harder Visual Studio 18.9 Insiders adds a thinking effort control for models, letting developers adjust reasoning depth from low to extra high according to task complexity, improving AI credit efficiency and answer quality.
- Limit token usage in Microsoft Agent Framework ChatClientAgentRunOptions in the Microsoft Agent Framework lets developers cap output tokens per interaction, helping control costs by limiting token usage to specified thresholds like 150 tokens.
- Terraform AzureRM provider 5.0 now generally available Terraform AzureRM provider 5.0 adds finer control over Resource Provider registration, optional preflight validation for Azure resources, and updated default validation settings to improve deployment flexibility and error detection.
- VS Code 1.131 Adds Built-In Dictation, Hybrid Markdown Editing and Subagent Status VS Code 1.131 adds built-in dictation, hybrid Markdown editing, and subagent status for improved development visibility.
- Uno Platform 6.6: Native AOT, Vulkan Rendering, MCP Auto Registration and More Uno Platform 6.6 introduces Native AOT compilation across five platforms reducing startup times by up to 60%, adds an opt-in Vulkan rendering backend for improved performance, and streamlines Model Context Protocol setup with auto-registration in popular AI agents.
- Drawio Agent Skill The Draw.io Agent Skill automates generation of clear, editable diagrams for diverse use cases like cloud architecture and CI/CD pipelines using a consistent diagramming methodology.
- Visual Studio July Update Brings Copilot Agent and Built-In Skills The July Visual Studio update introduces a Copilot Chat agent for streamlined coding assistance, along with workload-specific skills and enhanced C++ build controls.
- Stacked sessions and pull requests in the GitHub Copilot app The GitHub Copilot app introduces stacked sessions to help developers sequentially tackle related tasks like modernizing frontend styles and refactoring code, streamlining complex updates with clear progress tracking.
- Migrating ts-loader to TypeScript 7.1 with AI Migrating ts-loader to TypeScript 7.1 with AI explores using GitHub Copilot and Claude to automate part of the porting process while preserving backward compatibility and gradually phasing out older APIs.
- OpenTelemetry in Microsoft Agent Framework Apps OpenTelemetry integration in the Microsoft Agent Framework enhances observability by automatically emitting spans and metrics using semantic conventions while supporting multi-agent systems, though it lacks Activity Events.
🔩 DevOps
- Stop giving developers System Administrator access just so they can deploy Power Platform Pipelines introduces delegated deployments allowing makers to request production changes under a separate identity, improving governance while maintaining deployment efficiency.
- Audit Your Application Insights API Keys Before Entra Auth Takes Over in September The retirement date for Application Insights API Keys has been moved from March 2026 to September 30, 2026, allowing more time for migration to Entra ID authentication.
- Track AI Token Usage in VS Code: OpenTelemetry Collector Setup (Part 1) This guide demonstrates configuring the OpenTelemetry Collector as a Windows service to monitor and log AI token consumption from GitHub Copilot and Claude Code within Visual Studio Code, forwarding data to Azure Application Insights for unified team usage tracking.
- Configure GitHub Copilot for OpenTelemetry: Send VS Code Telemetry to Azure App Insights (Part 2) This part 2 guide explains how to configure GitHub Copilot Chat in VS Code to transmit detailed telemetry such as prompt data and latency metrics to Azure App Insights for unified team analysis.
- Configure Claude Code for OpenTelemetry: Send VS Code Telemetry to Azure App Insights (Part 3) This guide demonstrates configuring Claude Code to send VS Code telemetry including cost, token usage, and prompt data directly to Azure App Insights for comprehensive AI analytics.
- Track AI Token Usage by Team & Feature in Claude Code with OpenTelemetry (Part 4) Part 4 shows how to tag Claude Code requests with custom attributes for precise tracking of token usage and costs in Azure Application Insights.
- Find any commit in seconds: Commit Search comes to Azure DevOps Commit Search for Azure DevOps lets developers find commits by title and description across all organization repositories, with filtering, sorting, and instant UI integration.
- Disrupting supply chain attacks on npm and GitHub Actions npm and GitHub Actions have introduced new security measures targeting common supply chain attacks to protect open source projects.
- Surprise AI bill? GitHub Billing controls to the rescue! GitHub's new Billing controls help administrators track AI costs by SKU, identify accountable organizations, link usage to cost centers, and set targeted guardrails.
- Tame Dependabot: Group your updates, slow the cadence, keep security fast Grouping Dependabot updates into a monthly batch reduces review noise and improves efficiency without compromising security.
- Power Platform least privilege: How to remove production admin access without slowing developers down (Part 2) The Power Platform's least privilege model can cause operational friction for developers when production admin access is removed, requiring solutions like observability without authority, break-glass emergency access, and simplifying the governed route.
- Shift-Left Infrastructure Compliance Automation Shift-Left Infrastructure Compliance Automation uses n8n, Azure DevOps, FastAPI, RAG, and AI to audit Terraform changes in pull requests, mapping findings to CIS and SOC2 standards for immediate PASS/FAIL notifications before code merge.
- Move a live GitLab project between groups without breaking Terraform state or CI/CD Moving a live GitLab project between groups requires careful handling of Terraform state, CI/CD variables, group-runners, and cloud authentication to avoid breaking infrastructure management workflows.
🧬 Hybrid + multicloud
- Azure Arc Server June Forum The June Azure Arc Server Forum featured AI-assisted onboarding with an LLM in Azure Copilot, new GCP and EKS connectors in preview, extended support for Windows Server 2016 and SQL Server 2016, and announced a September forum.
🎭 Identity
- Device Code Flow: The Gift That Keeps on Giving - To Attackers Device Code Flow can be exploited by attackers to gain valid tokens via fake sign-in URLs and code prompts, necessitating restricted usage and preferring Managed Identity or certificate-based authentication.
- Microsoft make silent but frequent changes to Entra ID roles Microsoft quietly updated four Entra ID built-in roles multiple times, prompting administrators to review changed permissions for security and compliance reasons.
- Implement SAML as an external provider in an ASP.NET Core Identity application using Duende as an OIDC server This article shows how to configure SAML federation in an ASP.NET Core Identity app using Duende as the OIDC server and Entra ID for authentication, storing user claims securely in a cookie.
- The Microsoft AD Tier Model explained Microsoft opens its Active Directory Tier Model on GitHub, raising questions about its timing and relevance.
- Resetting Escrowed Accounts on a Microsoft Entra Provisioning Job The article explains how to clear escrowed accounts in a Microsoft Entra provisioning job using either the Microsoft Graph API or an upcoming cmdlet in the ECMA2HostTools PowerShell module.
- How to disable group nesting in Microsoft Entra ID You can disable group nesting in Microsoft Entra ID by using the Microsoft Graph beta API via PowerShell, enhancing access control for security groups.
- Episode 433: Passkeys, Passwords, and the End of SMS MFA Episode 433 explores how Microsoft is phasing out SMS and voice MFA in favor of passkeys, offering IT pros guidance on transitioning to phishing-resistant passwordless authentication.
🔌 Integration
- Public Preview: AI Gateway in Azure API Management The AI Gateway tier in Azure API Management’s public preview offers a specialized interface tailored for high-performance AI workloads, enhancing scalability and integration efficiency.
- AsyncAPI Code Generation with Corvus: Request/Reply Corvus generates comprehensive request/reply methods in AsyncAPI specifications, handling correlation IDs, reply channel filtering, timeouts, and cleanup to simplify conversational messaging patterns.
- Azure Logic Apps vs Azure Functions: A practical decision guide This guide compares Azure Functions, Durable Functions, and Azure Logic Apps across cost, observability, orchestration, security, networking, and delivery practices to help architects choose a sustainable implementation model for their teams.
- AI Gateway tier of API Management now in public preview Azure's new AI Gateway tier provides platform teams with an intuitive interface to manage AI models and MCP servers using policy controls via cards instead of XML, supporting OpenAI, Anthropic, and Mistral.
- Ten Days of Critter Stack Releases The Critter Stack team released multiple critical updates over ten days, including Wolverine 6.23.1 and Marten 9.20.0, which introduced enhanced monitoring for projection failures and improved graceful shutdown processes.
- Azure Logic Apps Standard | Testing Series Azure Logic Apps Standard introduces a comprehensive testing series to mitigate risk as integration workloads grow, offering automated validation tools for complex, multi-workflow environments.
- AsyncAPI Code Generation with Corvus: Health and Telemetry Corvus enhances AsyncAPI messaging observability with OpenTelemetry tracing, health checks, and per-subscription liveness monitoring to detect consumer failures despite silent message drops.
- AsyncAPI Code Generation with Corvus: Durability and Resumption Corvus offers durable and resumable AsyncAPI message handling across Kafka, AMQP/RabbitMQ, and NATS transports, preventing message loss on consumer restarts via configurable offset or acknowledgment mechanisms.
- AsyncAPI Code Generation with Corvus: Filtering Channel filtering in Corvus enables developers to generate only necessary message channels and operations, reducing code bloat and clarifying messaging boundaries.
- Protect Azure API Management APIs with Microsoft Defender for APIs Microsoft Defender for APIs enhances Azure API Management security by automatically detecting and mitigating threats such as unauthorized access, data leakage, and outdated endpoints.
- AsyncAPI Code Generation with Corvus: Testing Focus on testing custom handler logic, error policies, and domain integration when using Corvus, as the generator’s serialization and validation are already thoroughly tested.
💡 Internet of Things
- Generally Available: Azure Sphere OS version 26.09 is now available for evaluation Azure Sphere OS 26.09 introduces a major upgrade to its Linux kernel, enhancing security and compatibility without altering customer-facing features during the evaluation phase.
- Azure Sphere OS version 26.09 RC1 is now available for evaluation Azure Sphere OS 26.09 RC1 introduces a major Linux kernel upgrade for enhanced long-term support and security, available for an extended nine-month evaluation period until September 2026.
- How Mesh Systems Builds on Azure IoT Hub and Azure IoT Operations to Accelerate Industrial AI Mesh Systems boosts industrial AI adoption by combining Azure IoT Hub’s connectivity, Azure IoT Operations’ insights, and MeshCloud for unified data and faster AI decisions.
🎓 Learning and Certifications
- Microsoft Azure Certification Roadmap: Choose the Right Path The article helps readers compare various Azure certifications like AZ-900, AZ-104, and AZ-305 to align with their career goals and study timelines before the 2026 retirements.
- Level Up Your Security Skills This August with the Microsoft Defender Challenge and Learn Live The challenge offers hands-on training in Defender XDR, Sentinel, and cloud security, with winners receiving 50% off SC-200 or SC-500 certification exams.
- New Microsoft 365 Certified: AI Services Administrator Associate Certification The new certification validates skills for securing, monitoring, and optimizing enterprise AI services such as Copilot within the platform.
- How SCBX built AI literacy at scale and made AI part of daily work SCBX partnered with Trainocate to develop a structured skilling plan using Microsoft’s program, providing role-based AI training that enhanced efficiency and empowered thousands of employees in Thailand’s regulated financial sector.
- Microsoft Tops $90B Quarterly Revenue as Azure Hits $100B Annual Milestone Microsoft's $90 billion quarterly revenue reflects robust Azure growth and expanding AI market penetration across enterprises.
⚖️ Management and Governance
- Generally Available: Azure Automation supports PowerShell 7.6 runbooks and Runtime environment Azure Automation now offers general availability for PowerShell 7.6 runbooks and a dedicated Runtime environment, allowing users to modernize legacy scripts with minimal disruption.
- Generally Available: Single-click purchase for public SaaS offers The new single-click purchase feature in the Azure portal simplifies buying public SaaS offers from the Microsoft Marketplace by presenting all essential information on one user-friendly page.
- Building an AI Azure Ops Workbench — Part 2: The War Room — watch AI root-cause a 5xx in 90 seconds The AI Azure Ops Workbench's War Room uses eight specialized agents to parallelize complex incident investigations, ranking validated root causes in under 90 seconds.
- Cap it with GitHub, make it count with Azure: governing GitHub Copilot spend Azure API Management with bring-your-own-key enables real-time token quotas for GitHub Copilot, shifting consumption to Azure meters while bypassing GitHub’s native credit-based controls.
- Introducing Compliance Substate for Azure Policy Exemptions! Azure Policy's new compliance substate shows if exempted resources are compliant without exemptions, aiding teams in managing and retiring exemptions confidently.
- Now Generally Available: Built-in CIS Benchmark Auditing for Linux on Azure Azure provides general availability built-in CIS Benchmark auditing for Linux using the kompli engine to enable continuous compliance assessment and detailed reporting across Azure and hybrid environments.
- Introducing Cost Management and Pricing Toolsets in Azure Resource Manager MCP Server The new Azure Resource Manager MCP Server toolsets integrate cost management and pricing capabilities into AI agent workflows for estimating costs, analyzing trends, setting budgets, and identifying savings opportunities.
- Reservation exchanges for Azure services covered by savings plans end starting Feb. 1, 2027 Azure will stop supporting reservation exchanges for services covered by savings plans on February 1, 2027, urging users to adopt savings plans for enhanced cost flexibility in compute and database services.
- Building an AI Azure Ops Workbench — Part 3: Reverse engineer Azure Architecture Diagrams The Azure Support Agent creates an always-up-to-date map of application resources using read-only queries, automatically defining workloads with management groups, subscriptions, resource groups, or individual IDs while respecting exclusions and attaching critical metadata for accurate assessments and architecture diagrams.
- Proactive Reliability Series — Article 2: Regional Distribution Patterns for Azure Workloads This article examines Azure's regional distribution to highlight how multi-region deployments boost scalability, resilience, and performance with key strategic considerations for selecting a cloud footprint.
- Governing Log Analytics retention at scale The article explains configuring Log Analytics retention at workspace and table levels for cost optimization using an open-sourced Azure Policy solution called law-retention-guardrails.
- From reactive firefighting to proactive operations: custom skills for Azure SRE Agent The Azure SRE Agent open-source skills pack adds governance audits, FinOps reporting, capacity planning, postmortems, and more to move operations from reactive firefighting to proactive management.
🌐 Networking
- Generally Available: HTTP header insertion in Azure Firewall Azure Firewall’s new HTTP header insertion feature lets administrators dynamically add or modify request headers in application rules, enhancing security enforcement and tenant isolation capabilities.
- Generally Available: Microsoft Azure now available from new cloud region in India (India South Central) Microsoft’s new India South Central region in Hyderabad and Telangana offers locally hosted, high-performance Azure services tailored for AI workloads with reduced latency for Indian enterprises.
- Generally Available: NAT64 on StandardV2 NAT Gateway The new General Availability of NAT64 on StandardV2 NAT Gateway lets IPv6 services reach IPv4-only sites with minimal latency and no custom software changes.
- Public Preview: Route-Maps for Azure Route Server Azure Route Server’s new public preview route maps enable detailed management of inbound and outbound traffic across hybrid connections via BGP peerings.
- Preserve a Legacy IP During Azure Migration with Private Link Service Direct Connect Azure Private Link Service with Direct Connect lets legacy apps keep their private IP addresses during migration, enabling web tiers to shift to Azure while the on-premises database stays unchanged until later stages.
- Azure Front Door edge actions: programmable compute for a secure, resilient, AI-ready edge Azure Front Door adds programmable edge compute for lightweight logic, maintaining high performance, security, and isolation with fast execution.
🔐 Security
- Public Preview: Azure Enclave Azure Enclave’s public preview supports high-security tenants, offering automated setup and centralized governance for isolating critical applications in Azure Government regions.
- Public Preview: Symmetric keys on Azure Key Vault Premium Azure Key Vault Premium’s public preview introduces symmetric keys with the oct-HSM key type, supporting AES for enhanced evaluation of advanced encryption standards.
- How Nationwide stays ahead of attackers with Project Perception Nationwide employs Project Perception's coordinated multi-agent systems-red for offense, blue for defense, and green for remediation-to reduce threat response time from weeks to hours while maintaining expert oversight.
- Prioritize exposure resolution with a new dashboard experience (public preview) The new Exposure Management dashboard helps security teams prioritize high-impact risks, link findings to remediation workflows, and use categorized recommendations (Patch, Mitigate, Fix) for quicker risk reduction.
- Enhancing AI security through global AI red teaming The External Red Team Alliance (EXTRA) funds global academic collaborations and builds a specialist network to tackle multilingual, regional, and domain-specific AI safety challenges.
- Rethinking security for the age of AI Project Perception reimagines cybersecurity by integrating continuous risk perception, AI reasoning, and machine-speed action into a unified Cyber Stack for autonomous systems and evolving threats.
- Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365 Microsoft Defender for Agent 365 adds real-time protection and advanced threat detection to secure AI agents against complex attacks on interactions, tools, and data.
- Enabling the Compliance Security Profile (CSP) for HIPAA on Azure Databricks Enabling Azure Databricks’ Compliance Security Profile (CSP) for HIPAA by September 1, 2026, adds mandatory security hardening with a 10% cost increase and requires Azure VNet encryption, supported VM types, and the Enhanced Security & Compliance add-on.
- MDTI convergence in Microsoft Sentinel and Defender XDR is complete MDTI convergence unifies real-time threat intelligence across detection, investigation, response, hunting, and automation tools in Defender XDR and Sentinel, streamlining SecOps workflows.
- Better security starts with better questions Better security begins by identifying what needs protection, the most critical risks, and necessary confident decisions to ensure intelligence and trust in responsible AI innovation.
- What’s new in Microsoft Security: July 2026 What's new in Microsoft Security for July 2026 includes Project Perception with agentic defense workflows, expanded Defender protections against prompt injection attacks, unified posture and runtime protection for cloud agents, and enhanced AI integration into SecOps.
- Built to Protect: The Architecture Behind Codename MDASH Built to Protect explains how Codename MDASH uses AI for vulnerability detection in production MS security services while maintaining data control via shared governance, privacy, and compliance with tools such as Defender XDR and Sentinel.
- Securing Enterprise AI Agents with Microsoft Sentinel Microsoft Sentinel improves enterprise AI agent security by offering full visibility into user prompts, agent actions, tool use, safety alerts, and identities via integrated connectors and monitoring tools.
- What’s new in Microsoft Sentinel: July 2026 Microsoft Sentinel adds custom detections management as code, table-level observability, and new connectors for GitHub Audit logs, Agari, and Airlock Digital to boost threat detection and integration.
- Detecting CVE-2026-54121 (Certighost) with Microsoft Defender Microsoft Defender detects CVE-2026-54121, an Active Directory Certificate Services authentication bypass vulnerability, by monitoring suspicious certificate enrollment activities and advising immediate patches.
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch, a sub-cluster of Midnight Blizzard, uses AI and doppelganger domains to manipulate captive portal traffic for credential theft and malware delivery across global hospitality networks.
- Saturday Heat – Bonus Walkthrough! This Saturday bonus walkthrough guides you through building practical security queries using raw Entra sign-in data, highlighting recent AzureTracks website improvements.
📦 Storage
- Public Preview: Support for SMB Opportunistic Locking (Oplocks) configuration Azure NetApp Files now offers public preview support for SMB opportunistic locking to boost client caching performance, with settings usable on both new and existing volumes.
- Introducing Everpure Cloud Azure Native for Azure VMs Everpure Cloud Azure Native enables Azure VM customers to provision and manage high-performance elastic block storage within the Azure portal, eliminating appliances with pay-as-you-go pricing, independent scaling of capacity and IOPS, and built-in enterprise data services.
💻 Virtual Desktop Infrastructure
- Azure Virtual Desktop Hybrid with Travis Roberts Azure Virtual Desktop Hybrid introduces on-premises operation via Azure Local and seamless migration paths from existing virtual desktop infrastructures, expanding its hybrid deployment flexibility.
- Regional Azure Virtual Desktop Host Pools: What You Need to Know Regional Azure Virtual Desktop host pools improve resilience by localizing control plane metadata, reducing cross-region dependencies with detailed architectural considerations and configurations.
🔗 Web
- Understanding the Fetch Metadata HTTP headers: Sec-Fetch-Site and friends The Fetch Metadata HTTP headers-Sec-Fetch-Dest, Sec-Fetch-Site, Sec-Fetch-Mode, and Sec-Fetch-User-provide servers with contextual information about the origin and intent of browser requests, enhancing security by distinguishing legitimate user-initiated navigation from potentially malicious cross-site requests.
- Fast Web Services with Marten and Polecat Marten and Polecat enable ultra-fast web services by streaming raw JSON directly from PostgreSQL or SQL Server, reducing overhead and improving performance in CQRS architectures.