Azure Weekly
Issue 577
30th August 2026
Highlights this week include:
- Copilot Code Reviews for Azure Repos (public preview) by Dan Hellem - GitHub Copilot now provides onboarding controls at organization, project, and repository levels, supports Managed DevOps Pools, allows customizable instructions for team standards, triggers automatic reviews via branch policies, and offers enhanced billing visibility with Azure Cost Management tags.
- The Economics of Agent Optimization: Four ways to lower the cost by Steve Sweetman - Microsoft Foundry introduces four runtime levers to lower AI outcome costs by optimizing model selection, caching, prompt efficiency, and resource usage based on task complexity.
- Beyond Tokens: Rethinking AI Economics with Microsoft Foundry by Ashok Karania - Microsoft Foundry redefines AI economics by measuring value through outcomes instead of token consumption.
- AKS Prepared Image Specification Is in Preview by Richard Hooper - The AKS Prepared Image Specification preview lets you pre-load stable container images into node images, reducing pod boot times by eliminating the need to download updates during node initialization.
- More Performance, Same Price: Azure Postgres V3 & V5 Compute Compared by Jared Meade - Azure's new V5 PostgreSQL offers about 40% higher transaction throughput and lower latency than V3 at the same price via real-time scaling.
🤖 AI
- Understanding Harnesses: The Concept That Changes How You Build Agents in Copilot Studio The GitHub Copilot harness in Copilot Studio introduces three distinct runtime layers-Chat, Standard, and GitHub Copilot-to allow developers to choose between model-agnostic goal-directed reasoning, explicit conversational flow construction, or traditional scripted agents, marking a significant evolution from the previous singular approach.
- Building Production-Ready AI Agents in Microsoft Foundry: 10 Lessons Learned Building production-ready AI agents in Microsoft Foundry requires focusing on grounding, observability, resiliency, governance, and continuous monitoring to address issues like API timeouts, outdated content, tool failures, and unexpected token usage.
- Building Enterprise RAG on Azure: GPT-4o + Azure AI Search + Azure DevOps — End to End Building Enterprise RAG on Azure combines GPT-4o with Azure AI Search’s hybrid search and Azure DevOps for seamless integration, ensuring precise, secure, and scalable generative AI applications.
- Enabling A2A endpoint and Agent Card for a Hosted Agent With Microsoft Foundry’s hosted agents, developers can quickly set up an A2A endpoint and Agent Card, enabling other agents to discover and communicate with their containerized service via the standardized Agent-to-Agent protocol, while keeping configuration separate in control and data planes.
- Reducing Token Usage Reducing Token Usage explores techniques like token management, context pruning, efficient history handling, lightweight summarization, TOON compression, and server-side computation to minimize token consumption in AI applications using the Microsoft Agent Framework.
- Benchmark Retrieval Patterns for Copilot Studio and Foundry IQ The summary offers a reproducible framework to objectively compare retrieval patterns in Copilot Studio and Foundry IQ by separating latency, billing units, and quality signals.
- Consume Dataverse MCP server in Microsoft Foundry-Bringing business data to AI Agents The Dataverse MCP Server allows AI agents to securely access and interact with Dynamics 365 and Power Platform data in real time, reducing custom integration needs to under 30 minutes.
- How to evaluate LLMs before production Evaluating language models for production requires assessing real-world inputs, ambiguous labels, missing context, and distribution mismatches-issues not captured by clean benchmarks alone.
- Deploying to Foundry Deploy the app using Docker, push to Azure Container Registry, register with Foundry, poll for active status, and invoke via its endpoint.
- AI overconfidence risks The experiment assesses how various AI models impact code quality, architecture decision consistency, and associated risks in an inner source tool handling architectural choices.
- Copilot Studio | Adding Dataverse Knowledge Sources with the Web API (the "UI-Only" Rule That Isn't) This article explains how to add Dataverse knowledge sources to Copilot Studio agents programmatically using the Web API, despite UI limitations, noting that these methods are undocumented and may change.
- The Economics of Agent Optimization: Four ways to lower the cost Microsoft Foundry introduces four runtime levers to lower AI outcome costs by optimizing model selection, caching, prompt efficiency, and resource usage based on task complexity.
- Grok 4.6 comes to Microsoft Foundry Models: Built for long-horizon reasoning and complex workflows Grok 4.6 for Microsoft Foundry Models is engineered for long-horizon reasoning and complex workflows, excelling across coding, engineering, office productivity, and technical problem solving with strong performance on benchmarks like Terminal-Bench 3.0 and 3DCodeBench.
- The Dark Side of Autonomous Agents - How to Stop Them The presentation highlights how autonomous AI agents can become malicious execution vectors through manipulation of external file specifications, stressing the necessity of a zero-trust architecture with Policy Enforcement Points for security.
- Adding a Fallback Model to Hermes with Microsoft Foundry Adding a fallback model with Microsoft Foundry to Hermes ensures redundancy and enterprise controls, allowing seamless failover when Bedrock is unavailable, all at pay-as-you-go token costs.
- Evaluating a Ternary Protein Language Model Architecture for Rapid Antibody Sequence Generation The peleke-1bit architecture, using a ternary BitNet model with 26 tokens and 33.6 million parameters, achieves comparable antibody design performance to larger models while running efficiently on CPUs with minimal latency impact.
- Cohere Parse v5 is now available in Microsoft Foundry Cohere Parse v5 integrates with Microsoft Foundry to convert enterprise documents into structured Markdown while preserving layout and supporting nine languages at up to 36 pages per second on an H100 node.
- Introducing Cohere Parse V5 Cohere Parse V5 transforms enterprise documents into structured Markdown, handling tables, forms, diagrams, and images across nine languages at 4.5 pages per second per GPU on Azure Foundry.
- Copilot Cowork browser use – First Look Copilot Cowork's new feature enables AI to perform website tasks directly in Edge with your sign-in, following existing security policies, but needs admin activation and is active only when you're present.
- Azure Machine Learning AutoML for FinTech Startups: From Idea to Production Azure Machine Learning AutoML accelerates FinTech startups' path from concept to production by automatically training and assessing various ML pipelines for classification, regression, and forecasting, allowing swift creation of dependable models with minimal data science resources.
- MCP vs. Tools vs. Skills: What AI Architects Need to Know Understanding the distinctions between tools, MCP, and skills clarifies how AI architects should design reliable secure maintainable low-latency cost-efficient systems.
- Beyond Tokens: Rethinking AI Economics with Microsoft Foundry Microsoft Foundry redefines AI economics by measuring value through outcomes instead of token consumption.
🔎 Analytics
- The Complete Guide to Azure Databricks Cost Optimization The guide offers a three-phase approach to reduce Databricks spending by 20-30%.
- Episode 435: Power BI Meets Git and MCP Episode 435 explores how Power BI's MCP servers automate data modeling, turning complex datasets like a 44-table QuickBooks mess into usable models, and discusses PBIP’s Git integration for collaborative report development despite ongoing challenges with CI/CD guidance.
- How to use the Power BI Desktop Bridge to automate tasks in Power BI Desktop and GitHub Copilot The Power BI Desktop Bridge enables automation of repetitive tasks in Power BI Desktop, integrating seamlessly with GitHub Copilot for enhanced coding assistance.
🖥️ Compute
- Generally Available: Azure 248 and 372 vCPU sizes for D/E v7 series VMs Azure’s new Dl/D/E v7 VM sizes with 248 and 372 vCPUs, based on Intel® Xeon® 6 processors, offer up to 20% improved compute performance compared to previous generations.
- Generally Available: Azure VM Image Builder in sovereign and air-gapped clouds Azure VM Image Builder is now GA in multiple sovereign clouds and air-gapped environments, enabling consistent managed image creation across government, China, and secret/top-secret Azure regions.
- How to Download and prepare for vNext – Windows Server 2028 This guide shows how to download Windows Server vNext from the Insider Program and set up an isolated evaluation lab to prepare for its architectural advancements such as new storage formats and post-quantum cryptography.
- Retirement of Microsoft HPC Pack Microsoft plans to retire HPC Pack on August 27, 2027, encouraging customers to migrate their workloads to Azure Batch for continued support and modern cloud-native capabilities.
- Maia 200: Software-defined dataflow and all-Ethernet networking for efficient inference on Azure Azure Maia 200 combines software-defined local access dataflow architecture with all-Ethernet networking to deliver 30% better performance per dollar for frontier-scale inference workloads.
- Windows Update Failures in Japanese-Localized Azure VM SQL2022-WS2022 Images: Cause and Workaround The article explains why Windows Update fails with error codes 0x800f081f or 0x800f0831 on Japanese-localized Azure VM SQL2022-WS2022 images due to issues in the marketplace image's language resources and provides steps to remove and re-add Japanese language packs without restarting the OS.
- Boxed In: Working With Azure's Region Constraints Instead of Getting Surprised By Them This article explains Azure's region constraints and provides actionable insights for resolving AllocationFailed errors and slow quota approvals.
- Stop paying for idle VMs — safely: ringed start/stop waves for your Azure estate Azure VM Scheduler safely sequences non-production VMs into ordered waves using two safety gates, reducing idle compute costs by up to 36% without impacting storage or other metered resources.
🚢 Containers
- Generally Available: eBPF host routing in Advanced Container Networking Services for AKS eBPF Host Routing in Azure Kubernetes Service enhances network performance by offloading packet processing to the kernel, reducing latency and increasing throughput for container workloads.
- Generally Available: Workload identity support for Azure Files CSI driver (SMB) in Azure Azure has introduced general availability of workload identity support for the SMB version of its CSI driver in AKS, enabling secure pod-level authentication to Azure File Shares.
- Docker for Students & Teachers: Innovating from your Laptop — Anywhere, Anytime Docker for Students & Teachers provides a secure sandbox to experiment with AI agents, databases, and microservices, enhancing real-world DevOps skills valuable in tech careers.
- AKS Prepared Image Specification Is in Preview The AKS Prepared Image Specification preview lets you pre-load stable container images into node images, reducing pod boot times by eliminating the need to download updates during node initialization.
🗄️ Databases
- Announcing: Extended Support for Azure Database for PostgreSQL Flexible Server Azure Database for PostgreSQL Flexible Server now offers extended support, ensuring continued security, critical bug fixes, and technical assistance during migrations to newer PostgreSQL versions.
- What AI Thinks a DBA Does All Day The article contrasts AI's idealized depiction of a DBA's daily tasks with real-life experiences, highlighting discrepancies such as omitted printer work and frequent interruptions.
- Anna Hoffman: AI Database Development - Episode 416 Anna Hoffman explains how agentic database developers use AI tools such as GitHub Copilot Agent Mode in SSMS to enhance data management efficiency.
- Introducing Simplified Regional Limits for Azure SQL Managed Instance Azure SQL Managed Instance now provides hardware-generation-specific regional vCore limits, enabling customers to request capacity based on workload needs and simplifying subnet management within broader Azure Resource Manager networking limits.
- Full, Differential and Log Backups: A Practical Guide This guide explains how full, differential, and log backups interact under SQL Server's FULL recovery model, highlighting that differentials depend on a particular full backup rather than the last differential to minimize restore files in emergencies.
- Why PostgreSQL Still Inspires Builders PostgreSQL's 30-year legacy, reliability focus, open governance, and permissive license create a stable core that supports many extensions, forks, and cloud services, sustaining its popularity.
- Kerberos Authentication for Aurora PostgreSQL: Mapping AD Groups to Database Roles Kerberos authentication for Aurora PostgreSQL maps Active Directory groups directly to database roles, enabling automatic onboarding and offboarding of users without manual login provisioning.
- Using Historical Data to Confirm Performance Improvements Using historical data to confirm performance improvements requires comparing execution metrics like per-call duration, CPU usage, logical reads, writes, waits across matched workload windows while accounting for execution counts and total workloads to avoid misleading conclusions.
- ICYMI: New Azure SQL Foundations video series with GitHub samples The Azure SQL Foundations video series, featuring GitHub sample repositories, guides viewers through creating their first Hyperscale database and leveraging AI features on operational data.
- Connectivity Errors caused by slow logins in a Microsoft Fabric SQL Database The article explains how slow logins in a Microsoft Fabric SQL Database can cause connectivity errors, with Azure App Service intermittently failing to establish TDS connections within 15 seconds and returning HTTP 500 errors.
- Understanding and Reclaiming Storage After DELETE in Azure Database for PostgreSQL Understanding Azure Database for PostgreSQL’s MVCC shows that DELETE operations don’t change storage because dead tuples remain until vacuuming frees space, impacting Azure Monitor graphs and possibly raising storage costs.
- SQL Server 2016 End of Support: ESU dates, pricing and what to do next SQL Server 2016 ended support on July 14, 2026, with Extended Security Updates available through July 17, 2029, at increasing annual costs totaling over five times the original license price.
- What is cloud database vendor lock-in? The 3 types explained (and how to audit yours) Understanding cloud database vendor lock-in involves distinguishing between engine, feature, and operational lock-in; use a four-question framework to assess dependency levels before committing.
- Managed PostgreSQL vs. self-hosted PostgreSQL: Key benefits and trade-offs Managed PostgreSQL reduces operational overhead for security, backups, scaling, monitoring, and high availability compared to self-hosted deployments, ideal for organizations focused on application development.
- Transaction ID (XID) Wraparound Protection in Azure Database for PostgreSQL Flexible Server Azure Database for PostgreSQL Flexible Server adds XID wraparound protection with improved autovacuum and monitoring to avoid write operation failures.
- I Let AI Recommend SQL Server Indexes Across a Week of Queries The AI model recommended SQL Server indexes using only query text and table definitions, yielding varied results with some queries improving significantly and others not at all.
- Why SQL Server’s default trigger execution model is a security flaw – and what Microsoft should do about it SQL Server's default trigger execution model allows hijacking of elevated authority through maliciously triggered events.
- More Performance, Same Price: Azure Postgres V3 & V5 Compute Compared Azure's new V5 PostgreSQL offers about 40% higher transaction throughput and lower latency than V3 at the same price via real-time scaling.
- mssql-python 1.14.0: Faster Parameter Binding, Safer Errors, Correct Timeouts mssql-python 1.14.0 improves performance by using native C++ for parameter detection and execution, reducing timeout errors and fixing Decimal conversion issues to avoid data leakage.
🛠️ Developer tools
- Announcing: Aspire 13.5 has shipped Aspire 13.5 introduces a refreshed dashboard, enhanced interaction services, expanded Azure integrations, and new features like cross-scope referencing and persistent Kubernetes volumes to improve workflow efficiency.
- Your alt text passes automated checks. That doesn’t mean it’s any good. GitHub launched an alt text plugin for its accessibility scanner using deterministic rules and optional AI to flag unclear, repetitive, or inadequate descriptions of web images, enhancing image description accuracy.
- Unlocking the Power of AI for Every Developer in Visual Studio with Bring your Own Model Bring Your Own Model (BYOM) enables developers in Visual Studio to use their preferred AI models for various tasks with upcoming flexible management and support.
- Building your first MCP server in ASP.NET Core Building your first MCP server in ASP.NET Core shows how to expose a book catalog and search functionality via the Model Context Protocol for easy AI assistant integration.
- Visual Studio August Update — Work Smarter Across Models and Branches Visual Studio's August update adds customizable model effort levels for AI assistance, organization-wide custom agents for Copilot consistency, and worktrees to manage multiple branches smoothly.
- The Visual Studio Debugger Agentic Workflow Gets a Test-Driven Upgrade The Visual Studio Debugger now offers a Test-Driven Investigation workflow that automatically creates or identifies focused tests to help diagnose and validate fixes for hard-to-reproduce bugs.
- Visual Studio August Update Adds More Copilot Controls, Git Worktrees Visual Studio 2026's August update adds adjustable AI reasoning controls, organization-wide agent support, enhanced Git worktrees, and integrated submodules to improve development workflows.
- Microsoft Formalizes VS Code Agent Host as Open Architecture for Persistent AI Sessions Microsoft opens the Agent Host Protocol to third-party clients, enabling persistent AI sessions across diverse development environments.
- Enabling WSL Support for the GitHub Copilot App GitHub Copilot App now supports Windows Subsystem for Linux (WSL) repositories, expanding its compatibility for developers using both Windows and Linux environments.
- Composition and Modular Verification of TLA+ specs The article explains how to handle shared state constraints in TLA+ specifications by using open specs with rely-guarantee reasoning, enabling modular verification without fully composing systems.
- CoPilot Harness and Microsoft Agent Framework The integration of GitHub Copilot with the Microsoft Agent Framework enables developers to build intelligent agents for automating tasks, boosting productivity, and streamlining workflows via planning, tool execution, shell access, file manipulation, and URL retrieval.
- VSLive! @ Microsoft HQ: Developer Takeaways and Must-Watch Sessions VSLive! showcased AI integration across all developer workflows at Microsoft HQ in 2026, stressing the ongoing relevance of core development skills in Visual Studio.
- VS Code Tries Rubber Duck for AI Second Opinions VS Code 1.135 introduces a "rubber duck" feature that lets developers ask GitHub Copilot for second opinions during AI-assisted coding sessions, enhancing debugging and code quality.
- 🚀 Foundry Toolkit for VS Code — August 2026 Update The August 2026 update to the Foundry Toolkit for VS Code introduces prompt agent toolboxes, previewed agent-to-agent connections, an Agent Inspector Overview for detailed run analytics, user-scoped hosted sessions for isolation, and a redesigned Create Agent page.
🔩 DevOps
- Your PC Is a Build Agent: Self-Hosted GitHub Actions in Docker Desktop Docker Desktop lets you run a self-hosted GitHub Actions runner locally via a simple Dockerfile and entrypoint setup, enabling seamless CI/CD workflows on your PC without cloud dependencies.
- Copilot Code Reviews for Azure Repos (public preview) GitHub Copilot now provides onboarding controls at organization, project, and repository levels, supports Managed DevOps Pools, allows customizable instructions for team standards, triggers automatic reviews via branch policies, and offers enhanced billing visibility with Azure Cost Management tags.
- GitHub Copilot app for Beginners: Automate Dependabot pull request triage GitHub Copilot’s new app automations simplify Dependabot pull request triage by grouping updates by risk, verifying CI status, and delivering a concise summary daily.
- Azure DevOps in the GitHub Copilot App The Azure DevOps plugin for GitHub Copilot lets developers view, open, edit, and complete pull requests and work items directly within the Copilot interface without switching applications.
- OpenClaw went viral. Meet the maintainers building and securing it. OpenClaw's swift growth from a personal project to an open-source success story with 388k stars showcases effective handling of massive pull requests, inclusive contributor engagement including non-developers assisted by AI, and adaptive trust models amid software supply chain challenges.
- Copilot Studio | Real ALM for Agents (and the One Click That Breaks Your Pipeline) Copilot Studio's ALM path fails critically due to missing agent deployment support, reliance on undocumented "standard harness," and lack of automated solution import without authentication, making it unsuitable for real-world production.
🧬 Hybrid + multicloud
- Simpler, private connectivity between Azure and AWS with Azure Multicloud Interconnect Azure Multicloud Interconnect replaces manual cross-cloud networking with a managed, quad-redundant service that features 400G-class bandwidth and automatic MACsec encryption.
🎭 Identity
- Instant Revocation of Service Principal Bearer Tokens with CAE Continuous Access Evaluation in Entra instantly revokes service principal bearer tokens upon detecting high-risk events.
- Agentifying Entra ID using SCIM The article explains how SCIM automation streamlines Entra ID provisioning, reducing manual clicks and errors for joiner-mover-leaver workflows.
- Global Secure Access – Now with Windows Update support! Global Secure Access now integrates Windows Update support, allowing seamless patch management within its zero-trust network framework.
- Tell us how you use ObjectGuid, SamAccountName, and DistinguishedName in Exchange Online The Exchange team seeks feedback on the current use of ObjectGuid, SamAccountName, and DistinguishedName to guide potential simplification of identifier properties during directory modernization.
- What’s New in Entra Global Secure Access Client v2.32.294.0 The updated Entra Global Secure Access Client v2.32.294 resolves overlapping network address issues, boosts tunnel creation speed, and integrates with Windows Update for seamless future patches.
- New Graph API permissions point to Entra ID diagnostics Microsoft introduced four new IdentityDiagnostic Graph permissions, indicating the development of diagnostic APIs within Entra ID for enhanced user and tenant-wide troubleshooting capabilities.
- Sync Entra ID users to Active Directory with Cloud Sync Microsoft Entra Cloud Sync in preview enables seamless provisioning of Entra ID users directly to Active Directory, with guidance on prerequisites, scoping, and current limitations.
🔌 Integration
- APIM Policy Patterns for AI Governance: Part 1 – Rate Limits, Token Quotas & Observability This article introduces APIM policy patterns for AI governance focusing on rate limits, token quotas, and enhanced observability to control request bursts bound token consumption and track responsible consumers effectively.
- Azure Service Bus: Designing for blast radius Designing Azure Service Bus topologies for blast radius involves splitting event streams across topics to contain failures and improve observability.
- Zonal redundancy in API management Standard v2 Zone redundancy in Azure API Management Standard v2 enhances service availability by distributing it across multiple Azure Availability Zones with minimal configuration.
💡 Internet of Things
- Reviving the Tessel 2 - The First Rung Reviving the Tessel 2 project aims to upgrade from OpenWrt 15.05 to 17.01 to test if Tessel-specific configurations and bridge software remain compatible with current upstream releases.
🎓 Learning and Certifications
- What's New in Microsoft EDU - Back to School August 2026 Microsoft EDU launches Teach with Remember Settings for unified class management, multilingual AI content generation, and upcoming Unit Plans integrating standards, pacing, and assessments.
- AI-901: Model Deployment Options and Configuration Parameters AI-901 focuses on selecting appropriate deployment options in Microsoft Foundry and understanding key inference parameters like temperature, max tokens, top-p, penalties, and system prompts to shape model output behavior for exam scenarios.
⚖️ Management and Governance
- Generally Available: Azure SRE Agent 30-Day Trial Azure SRE Agent offers a free 30-day trial letting new users experiment with creating agents, connecting them to tools and data sources, and exploring features risk-free.
- Generally Available: Azure SRE Agent VNet Integration Azure SRE Agent’s new Virtual Network Integration lets you run it inside your own networks with full control over NSGs, private DNS, and firewalls.
- Public Preview: Introducing Live Reports for Azure SRE Agent Live Reports for Azure SRE Agent enables operations teams to create real-time, automatically refreshed dashboards directly from agent interactions, streamlining monitoring and incident response.
- Power Automate | Cloud Flow Telemetry with Azure Application Insights, Down to the Action Level Power Automate cloud flow telemetry in Azure Application Insights now offers detailed action-level insights for precise failure identification via tailored Kusto queries.
- Azure SRE Agent VNet integration is now generally available Azure SRE Agent's VNet integration routes agent traffic through a virtual network to securely access private resources like databases and AKS API servers while applying existing networking policies, enhancing control over outbound communications for enterprise workloads.
- Azure SRE Agent: Introducing Live Reports Azure SRE Agent's Live Reports enable ops teams to create a single dashboard that updates with real-time data each time it's accessed, cutting down on tool requirements and LLM token usage while supporting interactive charts and optional AI-driven insights.
- Remote Help on Windows: Unattended support with remote sign-in is here Remote Help on Windows enables helpdesk staff to troubleshoot physical devices remotely without user presence, enhancing after-hours support and efficiency while maintaining security through isolated sessions and least-privilege access.
- Tracking Batch node state and duration in Log Analytics Tracking Batch node state and duration in Log Analytics provides a reusable Python collector that extracts per-node details from the Azure Batch REST API, storing them in Log Analytics for queries that identify which nodes are stuck or experiencing errors, enabling alerts after thresholds like more than 60 minutes in a problematic state.
- Cost Management with Azure Resource Manager MCP The ARM MCP server adds default cost management tools enabling AI agents to integrate cost context into Azure workflows with minimal setup for querying, pricing checks, and budgeting.
- Your on-call rotation has a new member: 10 production incidents, end to end, with Azure SRE Agent Azure SRE Agent automates the time-consuming investigation phase of incident response by correlating telemetry and logs across ten common production failure modes.
- Introducing device association for Windows Autopilot device preparation Device association for Windows Autopilot enables organizations to securely bind Windows 11 devices to their tenant via hardware-backed attestation, facilitating consistent onboarding with tailored policies applied during OOBE.
- What’s new in Microsoft Intune – August Microsoft Intune adds Windows Autopilot for early device trust, unattended remote help access, and enhanced App Settings on macOS for better app management including AI tools.
- Application Insights: Everyone Sets It Up, Almost Nobody Reviews It Application Insights often remains unreviewed despite widespread setup, highlighting a gap in monitoring practices that can leave performance issues undetected.
- INFO: Options for Teams Meeting “summaries” with or without Transcriptions Organizations can minimize transcript retention by applying expiration policies or using Copilot without recording, though this prevents generating post-meeting recaps.
🌐 Networking
- Generally Available: Custom block response code and body for Application Gateway WAF Azure's Application Gateway now allows customizable response codes and bodies for blocked requests through its WAF, enhancing developer control over security responses.
- Generally Available: Connect to AKS clusters using Azure Bastion Azure Bastion’s general availability for connecting to AKS clusters simplifies secure remote access, allowing users to manage Kubernetes resources directly via familiar tools with enhanced security.
- Generally Available: Azure Bastion shareable link expiration Azure Bastion now allows administrators to set custom expiration dates for shareable links, enhancing security by automatically revoking access after the specified timeframe.
- Public Preview: IPv6 dual-stack support for Azure Bastion Azure Bastion’s public preview introduces dual-stack (IPv4 and IPv6) support, allowing seamless configuration of both address types on new deployments for enhanced connectivity options.
- Azure DNS + Traffic Manager linked records Azure DNS linked with Traffic Manager allows direct return of endpoint IP addresses for A/AAAA records, removing intermediate CNAME responses while maintaining routing and failover capabilities in a public preview.
- Build an Azure Network Security Perimeter Around PaaS Resources This guide demonstrates creating an Azure Network Security Perimeter to control traffic for PaaS resources, reducing exposure while allowing essential access.
- Debugging my new network, when 10 Gigabit Ethernet Runs at 300 Megabits Disabling LSO V2 on an Intel E610-XT2 10GbE NIC increased network throughput from about 313 Mbps to nearly 7 Gbps, resolving slowdowns and emphasizing the need to test individual networking components.
- Advertised gateway prefixes in Azure Advertised gateway prefixes allow Azure hybrid gateways to summarize multiple address spaces into a single CIDR block, enhancing route management and compliance with ExpressRoute's prefix limits.
🔐 Security
- Unified AI Defense: Security Copilot, Project Perception, and MDASH Unified AI Defense offers Security Copilot, Project Perception, and MDASH to form a cohesive framework for managing software vulnerabilities and responding to threats.
- Agent Governance Toolkit: Giving AI Agents Rules of the Road The Agent Governance Toolkit offers deterministic policy enforcement and real-time auditing to prevent unauthorized transactions and destructive operations in autonomous AI agents, filling key security gaps not addressed by system prompts.
- The patch window is collapsing: Why security needs a new control plane The patch window is shrinking rapidly due to vulnerability disclosure, multicloud environments, and AI-assisted attacks, necessitating urgent strategic rethinking for risk mitigation.
- 357 - Microsoft 365 E7 – let there be agents and security Microsoft 365 E7 introduces Agent 365 for enhanced security via Purview data protection and provides a clear upgrade path from E5 and E3 plus Defender Suite, with detailed licensing guidance available.
- Navigating the Azure Databricks CSP Mandate Azure Databricks must comply with a September 1, 2026 deadline mandating the CSP for HIPAA, HITRUST, and IRAP regulated data, necessitating major architectural adjustments like VNet encryption and default disabling of partner-powered AI features.
- How to protect against DDoS attacks (Extended edition) This article details Norway's recent DDoS attacks amid defense cooperation with Ukraine, explains attack mechanisms ranging from TCP floods to reflection amplification, and highlights statistics from Cloudflare’s RADAR showing 90% of attacks last under ten minutes but increasingly stretch up to three hours.
- Manage and retrieve credentials securely inside Browser Automation Tool (BAT) using Azure Key Vault The article explains how Azure AI Foundry’s Browser Automation Tool integrates with Azure Key Vault to securely store and retrieve credentials for browser automation tasks, enhancing enterprise security and compliance.
- What’s new in Microsoft Security: August 2026 The update adds expert-led threat intelligence, broader MDR coverage including Palo Alto Networks and AWS, and tools to enhance identity foundations for AI operations.
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion The TerminalFix campaign employs compromised sites to deceive users into running a malicious PowerShell script that downloads hidden payloads via steganography, granting persistent network access through a custom reverse-tunnel C2 implant.
📦 Storage
- In-Place Upgrade Veeam Backup Enterprise Manager to v13.1.1.18 with Windows Server 2025 The upgrade simplifies transitioning to Windows Server 2025 by fixing critical bugs in software appliance and cloud connect while keeping compatibility with existing Hyper-V environments.
- From Azure to Anywhere: Redesigning Image Storage Architecture for this Blog Moonglade switched to isolated filesystem roots using Azure Files and Docker volumes for improved flexibility and security.
- Azure Files Backup and Recovery: What IT Pros Need to Know Azure Files backup provides two tiers one with regional snapshots and another with geo-redundant Recovery Services vaults for cross-region disaster recovery essential for premium file shares lacking built-in redundancy.
🔗 Web
- Retirement: Support for Node 22 LTS ends on April 30, 2027 Node 22 LTS will reach its end-of-life on April 30, 2027, meaning apps running it on App Service will still operate but lose security patches and official support thereafter.