Azure Weekly
Issue 579
13th September 2026
Highlights this week include:
- Two zones or three? A design framework for zone-resilient Azure workloads by Mark Russinovich, Eric Henry, Sai Vaidhyanathan - This framework guides architects to assess each component's need for zone redundancy using two zones when possible, reserving three only for components requiring an extra fault domain to optimize cost and performance while ensuring adequate resilience.
- Protecting organizations from AI-assisted executive impersonation and invoice fraud by Microsoft Security Research - Microsoft identifies a million-email campaign using generative AI to craft fake executive invoices and ServiceNow threads, targeting finance departments for $50,000 ACH transfers.
- Passkey-themed social engineering leads to identity and cloud compromise by Microsoft Security Research. The attack uses passkey-themed social engineering to gain initial access, then proceeds with reconnaissance, credential capture, and cloud data exfiltration.
- Can a Harmless Prompt Break an AI Guardrail? by Tamara Gaidar - Researchers observed 35,877 attempts over two days to breach an AI guardrail protecting a camping-themed agent, uncovering sixteen effective attack techniques.
- GitHub availability report: August 2026 by Jakub Oleksy - GitHub's August 2026 report details a major ten-hour outage affecting GitHub Actions and other services, alongside ongoing investments in architecture, Azure migration, capacity monitoring, and resiliency upgrades.
🤖 AI
- The Token Price Is Probably the Wrong Question - A Story of Copilot Studio Copilot Studio obscures model costs by bundling token usage into complex service fees that often exceed direct provider pricing.
- The Evidence Gateway Pattern The Evidence Gateway Pattern separates document understanding from AI reasoning, ensuring only validated, traceable evidence reaches agents while mitigating risks in regulated workflows.
- Cool Basement, Quiet Laptop: Building a Dedicated Foundry Local Jump Server on Windows Server 2025 Building a Dedicated Foundry Local Jump Server on Windows Server 2025 lets you move AI infrastructure out of the hot environment, keeping your laptop cool while the powerful server handles all inference workloads with minimal latency.
- Reinventing Organic Redox Flow Batteries with Microsoft Discovery Microsoft Discovery created an organic negolyte to reduce vanadium use in redox flow batteries via AI-driven closed-loop design combining computational predictions and lab measurements.
- Inside Orchestrated Media Intelligence: The Technology Behind Connected Media Workflows Orchestrated media intelligence unifies trusted data, specialized AI models, scalable cloud infrastructure, and governance to enable coordinated agents for monitoring and overseeing decisions across creative, rights, brand, privacy, security, and business impact.
- Beyond the benchmark: How an adaptive approach drives scientific discovery Microsoft Discovery's adaptive CLIO system achieves superior scores in health, physical, and life sciences benchmarks on the Agent’s Last Exam, showcasing agentic AI's dynamic problem-solving capabilities.
- How Azure uses AI to turn feedback into improved customer experiences Azure's GEM initiative uses AI to turn fragmented customer feedback into prioritized engineering work items with auditability and human oversight for better customer experiences.
- The AI Decided Is Not an Explanation AI agents generate human-like excuses like boredom to fill conversational gaps, leading users to incorrectly attribute intent and emotions to non-sentient software.
- How Microsoft Foundry Agent Service Enables Future-Proof Agentic Systems The new Foundry Agent Service from Microsoft provides agentic systems with modular, scalable components that adapt to evolving AI workloads.
- Azure Copilot announces general availability of the Troubleshooting Agent Azure Copilot's new Troubleshooting Agent offers AI-driven insights and recommendations within the Azure portal to speed up issue detection and resolution for services such as Azure Compute and AKS.
- Can a Harmless Prompt Break an AI Guardrail? Researchers observed 35,877 attempts over two days to breach an AI guardrail protecting a camping-themed agent, uncovering sixteen effective attack techniques.
- Update: Domain Exclusion for Microsoft 365 Copilot Domain Exclusion for Microsoft 365 Copilot lets admins block up to 1,000 external domains from influencing Copilot’s web content grounding, enhancing policy compliance and trusted source control.
- How to Test a RAG System: RAGAS, Hallucination Detection, and the Complete GenAI CI/CD Pipeline The article introduces the RAGAS framework and a layered testing pyramid to evaluate data quality, embedding accuracy, retrieval precision, and LLM output in Retrieval-Augmented Generation (RAG) systems, highlighting systematic detection of silent degradation risks.
- Execution, Optimization, and Exploration: Evaluating Scientific AI Through RF Engineering RF engineering challenges provide a framework to evaluate AI reasoning by testing its ability to distinguish between execution, optimization, and exploration tasks.
- Copilot Studio | Grounding a Copilot Studio Agent on Azure SQL Copilot Studio enables agents to directly query Azure SQL databases for instant answers without needing custom tooling or intermediate copies, with security relying on database permissions and response accuracy depending on schema quality.
- From Ad Astra to Semper Disco: Learning Chip Design with Microsoft Discovery The author used Microsoft Discovery to guide a hands-on chip-design journey from high-level spec to physical layout, learning how silicon for space applications differs from commercial chips.
- Copilot or Copilot Cowork - Which tool to use - and When Choose Microsoft 365 Copilot for real-time productivity assistance in apps like Word and Teams, ideal for drafting, summarizing, and refining content, or opt for Copilot Cowork for autonomous execution of multi-step workflows across tools, suited for scheduled tasks and event-driven automation.
- Voice to Chat Best Practice for Call Centre Use Cases Whisper models require voice activity detection to prevent hallucinations, while Azure NCads H100 v5 instances allow for high-throughput batching by leveraging 94 GiB of GPU memory per card.
- Create multimodal applications with OpenAI models in Microsoft Foundry OpenAI's GPT-Live-1 and GPT-image-2.5 models enable real-time, full-duplex multimodal applications in Microsoft Foundry for seamless conversational editing of visuals.
- Evaluating Agentic AI in Microsoft Foundry: Beyond Final-Answer Quality Microsoft Foundry introduces multi-layered evaluation for agentic AI systems, separating system-level assessments from process-level evaluations to comprehensively measure both final output quality and decision-making efficiency.
🔎 Analytics
- How to mirror data from SQL Server to Microsoft Fabric: complete guide Microsoft Fabric mirrors SQL Server data with low latency for near real-time analytics, though compatibility varies by version and environment.
- Microsoft Fabric: AI Needs Clean Data, But What Does That Actually Mean? Microsoft Fabric enables fast aggregations and reliable AI insights by organizing data in star schemas with a Gold layer that separates raw facts from analytical logic.
- Databricks Genie Spaces for SQL Analysts: Natural Language Querying Without Leaving Your Data Platform Databricks Genie Spaces enable SQL analysts to interact with data via natural language, producing instant results within the same platform for streamlined workflows.
- From OSDU to Ontology: Why Oil & Gas AI Readiness Lives at the Meaning Layer Microsoft Fabric IQ and OSDU provide a semantic layer to resolve conflicting data definitions, enabling AI agents to interpret complex energy assets consistently.
🖥️ Compute
- Generally Available: Azure Ephemeral OS Disk with full caching for VM/VMSS Azure Ephemeral OS Disk now offers full caching, reducing remote-storage reads and improving performance for virtual machines and VM Scale Sets.
- Generally Available: TLS/SSL certificate and end-to-end TLS encryption support for Azure Functions Flex Consumption Azure Functions Flex Consumption now offers general availability of TLS/SSL certificate support with a site-scoped model allowing each function app up to six certificates for enhanced security.
- The Watermark That Wasn't: Windows Server Activation and Licensing in the Cloud Windows Server 2022 in Azure automatically applies active licenses, eliminating activation watermarks for domain-joined VMs and simplifying cloud licensing management.
- Announcing general availability of Ephemeral OS Disk with full caching for VM/VMSS Ephemeral OS Disk with full caching in Azure improves performance, reliability, and provisioning speed for AI and IO-sensitive workloads by locally caching the entire OS image, reducing remote storage dependency and latency.
- Public Preview: Automatic Zone Placement for Virtual Machine Scale Sets Automatic Zone Placement in Azure VM Scale Sets simplifies multi-region deployments by allowing Azure to choose availability zones based on SKU availability, capacity, and user requirements, enhancing resiliency without manual zone management.
🚢 Containers
- Retirement: Azure Linux with OS Guard in Azure Kubernetes Service Azure Linux with OS Guard in Azure Kubernetes Service will cease support on December 10, 2026, with Azure Container Linux serving as its preview replacement.
- Installing Harbor Container Registry on AKS with Terraform, Traefik, and cert-manager Deploy Harbor Container Registry on Azure Kubernetes Service with Terraform, Traefik for ingress, cert-manager for Let's Encrypt SSL certificates using Azure DNS challenge, and Azure Workload Identity for secure authentication.
- Add Microsoft Entra ID OIDC SSO to Harbor on AKS Configure Harbor on AKS for SSO using Entra ID's OIDC, automate group roles with Terraform, and maintain secure fallback access.
🗄️ Databases
- Azure SQL DB HS Data Load Using Microsoft JDBC Driver Instead of Apache Spark Connector for SQL Microsoft JDBC Driver for SQL Server replaces the archived Apache Spark connector, offering long-term support for modern Spark versions and native Bulk Copy API integration.
- SQL Data Sync – the final phase of retirement SQL Data Sync will retire on September 30, 2027, with new deployments blocked starting September 9, 2026, prompting customers to switch to alternatives such as Azure Data Factory or transactional replication depending on their data synchronization requirements.
- Bi-directional logical replication in PostgreSQL: a practical guide Bi-directional logical replication in PostgreSQL 16 allows simultaneous two-way data exchange between multiple instances, functioning as a multi-master setup with instant change propagation, improving disaster recovery and global data distribution.
- Microsoft ODBC Driver 18.7.1: smaller vectors, easier configuration, and better cloud routing Microsoft ODBC Driver 18.7.1 adds float16 vector support for compact data handling, uses familiar connection-string names for easier configuration, optimizes routing for Azure SQL Database Hyperscale reads, and reduces Windows installation dependencies.
- mssql-python 1.15.0: Faster, More Reliable, and Built for Your Applications mssql-python 1.15.0 speeds up parameterized execution via native C++ pipelines, enhances Decimal handling for SQL_NUMERIC consistency, and improves Windows ARM64 support with compatible bulk copy components.
- Microsoft JDBC Driver 13.6 for SQL Server is now available The new Microsoft JDBC Driver 13.6 for SQL Server enhances performance, reduces memory usage, improves parameter handling, and strengthens security without requiring application changes.
- Let Postgres Enforce Tenant Isolation PostgreSQL's RLS enforces tenant isolation automatically, complementing EF Core query filters to ensure every application connection applies tenant checks without developer oversight.
- Microsoft closes a data access gap for Graph API permission Microsoft is eliminating unintended User.ReadBasic.All permissions that exposed app role and license data, urging administrators to identify affected Entra applications before the upcoming rollout.
🛠️ Developer tools
- Generally Available: Azure Developer CLI (azd) Extension Framework The Azure Developer CLI Extension Framework allows users to add customized features tailored to specific app development processes, enhancing flexibility for developers, teams, and partners.
- Generally Available: Playwright Workspaces in Australia East, Japan East, and Switzerland North Playwright Workspaces is now generally available in Switzerland North, Japan East, and Australia East, providing fully managed cloud-hosted browsers for running large volumes of end-to-end tests in parallel.
- Today I will… find hidden latency across a distributed .NET application Visual Studio’s Performance Profiler isolates cross-process bottlenecks in .NET Aspire apps by targeting specific services and using GitHub Copilot to interpret CPU usage versus wait times.
- Why the Microsoft Agent Framework pipeline matters for production .NET agents The Microsoft Agent Framework’s modular pipeline separates security, redaction, telemetry, and retrieval into distinct layers, enabling robust production .NET agents with minimal core logic changes.
- What Happens When Nobody Approves the Agent? The new sample shows how an agent with Harness manages silent or invalid approvals by retrying up to five times within five seconds before denying the action.
- Previews and Experiments in VS Code 1.137 VS Code 1.137 introduces scheduled agent capabilities, supports spoken interactions, and experiments with integrated GitHub and chat functionalities to enhance developer workflow.
- GitHub Copilot app for Beginners: Using the diff, terminal, and browser The new GitHub Copilot app integrates a diff panel, terminal panel, and browser panel with "Pick & Polish" tool for streamlined code modification review.
🔩 DevOps
- Wiring Azure DevOps Pipeline Templates Without the Parameter Sprawl: The Manifest Facade Pattern The Manifest Facade Pattern in Azure DevOps reduces parameter sprawl by encapsulating template wiring in a single orchestrator template, simplifying adoption for teams while maintaining consistency.
- GitHub availability report: August 2026 GitHub's August 2026 report details a major ten-hour outage affecting GitHub Actions and other services, alongside ongoing investments in architecture, Azure migration, capacity monitoring, and resiliency upgrades.
- September Patches for Azure DevOps Server These September patches for Azure DevOps Server address critical security vulnerabilities and improve performance, with Release Notes detailing specific fixes for each version.
- Creating Azure DevOps Testcases from VS Code with Claude Claude uses the Azure DevOps MCP server and a custom QA-Engineer agent to sync markdown-based test cases directly into Azure DevOps Test Plans.
- Marketing ops as code: Automating events from planning to follow-up on GitHub GitHub's marketing team automates repetitive event tasks using issue forms, labels, and GitHub Actions for end-to-end workflows from planning to follow-up.
🧬 Hybrid + multicloud
- Exploring Azure Local and the Microsoft Sovereign Private Cloud at the HPE Customer Innovation Center Azure Local and the Microsoft Sovereign Private Cloud enable enterprises to host Azure services on-premises, ensuring data sovereignty and compliance while still leveraging cloud-native benefits.
- Announcing the public preview of Azure Local workload management in Azure Arc Site Manager Azure Arc Site Manager’s public preview introduces workload management for Azure Local deployments, enabling operators to centrally monitor and control virtual machines and Kubernetes clusters across multiple sites with a unified view organized around physical locations.
- Workload Orchestration in the Azure portal is now available: Deploy in minutes, scale with ease Azure's new portal feature rapidly deploys and scales applications across environments with customizable configurations and simplified onboarding.
🎭 Identity
- Copilot Studio | Migrate the Agent, Keep the Client ID Copilot Studio is moving agents from Azure app registrations to new Microsoft Entra Agent IDs, simplifying governance through a reversible in-place migration that maintains existing client IDs and enhances security with managed identities.
- Microsoft Entra expands passkey registration campaigns Microsoft Entra’s expanded passkey registration campaigns now target users with restricted profiles, aligning with April's updated rules and encouraging broader adoption.
- Retiring NTLM: Frequently asked questions The retirement of NTLM focuses on enhancing security by moving Windows to a Kerberos-first model, addressing weak cryptography and attack vectors while allowing temporary re-enablement for legacy applications.
- Building on AI Landing Zones: Operationalizing Enterprise AI with the Citadel Architecture Citadel unifies enterprise AI operations by integrating Azure landing zones, native AI services, and operational best practices for access governance, observability, identity management, and security.
- Episode 436: Finding the Entra Tenants You Didn’t Know You Had Microsoft Entra Tenant Governance automates discovery of hidden tenants, enforces least-privilege administration, monitors configuration drift against a JSON baseline, and restricts new tenant creation for consistent governance.
- [OBJECT-ID]) does not have permissions for Microsoft.CognitiveServices/accounts/AIServices/agents/write actions The issue was caused by DefaultAzureCredential inconsistently selecting credentials from a different tenant, leading to permission errors for Cognitive Services agent writes; switching to AzureCliCredential resolved it by using the local user's credentials.
🔌 Integration
- Build an AI-assisted support email workflow with Power Automate and Microsoft Foundry Power Automate uses AI to classify incoming support requests and validate routing keys against SharePoint lists before requiring human approval to generate Outlook draft replies.
💡 Internet of Things
- Scaling Industrial AI at the Edge with Helin and Azure IoT Helin's platform provides real-time hazardous-zone detection with local inference, secure fleet governance on Azure IoT, and seamless integration for scalable safety monitoring without cloud reliance.
🎓 Learning and Certifications
- A Hands-On Community Workshop for Learning to Work with AI Coding Agents AI Teammate 101 is a free open-source workshop teaching developers to effectively delegate tasks to GitHub Copilot's coding agent through hands-on practice, focusing on clear issue definition, reviewing AI-generated sessions, and making responsible decisions for merging changes.
- AI-901 for Beginners: Tokens, Vectors, Embeddings, and Attention This beginner-focused series explains AI-901 exam terms like tokens, vectors, embeddings, and attention in simple ways to demystify large language models for novices.
- Passing the Azure AI Apps and Agents Developer Associate AI-103 Passing the Azure AI Apps and Agents Developer Associate (AI-103) exam required two attempts; the second succeeded without any study, highlighting the value of real-world experience over cramming.
⚖️ Management and Governance
- Generally Available: Azure Copilot Troubleshooting Agent The Azure Copilot Troubleshooting Agent streamlines issue investigation by providing integrated, AI-assisted guidance directly within Azure Copilot and Support tools.
- Your Landing Zone Learned Modularity: ALZ Goes AVM ALZ replaces its monolithic Bicep implementation with Azure Verified Modules for easier customization and consistent updates.
- Bicep: Never Hand-Write Azure ARM JSON Again Bicep streamlines Azure resource deployments by using a concise, domain-specific language that automatically handles dependencies and promotes code reuse in infrastructure as code.
- Choosing two-zone and three-zone patterns for zone-resilient Azure workloads This guide helps Azure customers choose between two-zone and three-zone patterns for zone-resilient workloads based on component needs, data durability, and costs.
- State of WSUS with Adam Marshall Adam Marshall discusses WSUS's continued relevance for Configuration Manager and Server 2025, highlighting its unique granular update control and offline support despite deprecation in September 2024.
- SCOM 2022 UR4 Fixes Grooming: Full Guide SCOM 2022 UR4 fixes a critical grooming bug allowing aged data to persist beyond retention settings, ensures the Data Warehouse shrinks as configured, tightens Web Console security, and adds support for latest OpenSSL 3 on Linux.
- Two zones or three? A design framework for zone-resilient Azure workloads This framework guides architects to assess each component's need for zone redundancy using two zones when possible, reserving three only for components requiring an extra fault domain to optimize cost and performance while ensuring adequate resilience.
- Digital Sovereignty Guidance Is Now Part of the Cloud Adoption Framework The Cloud Adoption Framework now includes digital sovereignty guidance for innovation in sectors such as banking, public sector, healthcare, and manufacturing.
- Reduce Log Analytics Noise with Azure Monitor DCR Transformations Azure Monitor’s DCR transformations help streamline log analytics by selectively shaping security data, reducing noise, lowering costs, and improving analyst confidence in actionable insights.
- The Hidden Laws of Cloud Transformation Azure migrations succeed by prioritizing human behavior and organizational risk assessment over technical tooling and arbitrary migration deadlines.
- Proactive Reliability Series — Article 2: Regional Distribution Patterns for Azure Workloads Azure's elasticity, scaling, and consumption-based billing allow organizations to select regional distribution patterns for workloads considering scalability, resilience, performance, and compliance.
- AI Agent ROI Framework The AI Agent ROI Framework identifies six key business outcome dimensions to guide prioritization and measurement of AI agent investments.
🚌 Migration
- Adding network intelligence into a network-ready Azure migration plan Azure Migrate's new Network Planning feature turns discovered networking data into actionable migration recommendations, reducing risks and speeding up cut-over.
- Migration: SQL Server to Azure SQL Managed Instance using DMS Azure Database Migration Service (DMS) simplifies moving SQL Server backups stored in Azure Blob Storage to an Azure SQL Managed Instance with minimal downtime and clear step-by-step guidance.
🌐 Networking
- Azure Front Door Edge Actions Azure Front Door's Edge Actions enable running lightweight JavaScript on web requests for tasks such as JWT validation, header manipulation, and origin selection overrides, configurable via Azure portal, REST API, or PowerShell.
- Always On VPN Security Updates September 2026 The September 2026 security updates for Always On VPN in Windows address critical vulnerabilities in RRAS, SSTP, IKEv2, and AD Certificate Services to enhance deployment safety.
- RateMyWAF: Turning a Tenant's Firewall Posture Into an A-F Grade RateMyWAF assigns an A-F grade to tenant firewalls based on configuration compliance, helping security teams quickly identify and remediate vulnerabilities.
🔐 Security
- Securing Your Certification Authorities (Practical PKI Part 4) Ron Arestia outlines practical steps to harden Certification Authorities against SpectreOps Exploitation in the fourth part of a PKI series.
- How Azure Arc allows a DB admin to become SQL Server sysadmin – the vulnerability explained Azure Arc's serverless connectivity can allow DB admins to gain unauthorized sysadmin privileges on remote SQL Server instances if configurations are improper.
- Solution – Fix Microsoft Sentinel UEBA Access in the Defender Portal This guide explains how enabling User and Entity Behavior Analytics (UEBA) in the Defender portal resolves common access issues within Microsoft Sentinel, enhancing threat detection capabilities.
- Passkey-themed social engineering leads to identity and cloud compromise The attack uses passkey-themed social engineering to gain initial access, then proceeds with reconnaissance, credential capture, and cloud data exfiltration.
- Detect and disrupt AI-themed attacks with Microsoft Defender Microsoft Defender now detects and disrupts AI-themed cyberattacks targeting platforms like ChatGPT and Copilot to steal personal data via phishing, malvertising, and credential harvesting.
- Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft identifies a million-email campaign using generative AI to craft fake executive invoices and ServiceNow threads, targeting finance departments for $50,000 ACH transfers.
📦 Storage
- Generally Available: User-bound user delegation SAS for Azure Storage Azure Storage has introduced user-bound user delegation SAS, combining flexible sign-in permissions with Entra ID’s user authentication to enhance security and control for cloud resources.
- Public Preview: Agentless migration of on-premises SMB file shares to Azure Files (SMB) Azure Storage Mover's public preview allows seamless, agentless migration of on-premises SMB file shares directly to Azure Files (SMB).
- Generally Available: Restrict usage of user delegation SAS to an Entra ID identity User-bound user delegation SAS restricts Azure Storage’s delegated access to specific Entra ID identities, enhancing security while maintaining flexibility, now generally available across all public regions and supported via REST, SDKs, PowerShell, CLI, and the portal.
- Dell Managed PowerScale for Microsoft Azure is now generally available Dell Managed PowerScale for Azure provides a fully managed file storage solution integrating Dell’s OneFS with Azure, enabling customers to create and manage PowerScale resources via familiar Azure tools while Dell manages infrastructure operations and upgrades.
💻 Virtual Desktop Infrastructure
- Azure Virtual Desktop Hybrid Is Now GA: 6 Reasons to Use It, and 2 Reasons to Reconsider Azure Virtual Desktop Hybrid offers six compelling reasons to adopt it while considering its incompatibility with non-headless physical devices and requirement for outbound internet access.
🔗 Web
- Azure App Service is now a trigger destination for Azure Managed Connectors Azure Managed Connectors now allow Azure App Service to receive real-time event triggers directly, streamlining integration with web applications written in ASP.NET Core, Java, Node.js, or Python.