Azure Weekly
Issue 580
20th September 2026
Highlights this week include:
- Public Preview: HTTP/3 over QUIC support in Azure Application Gateway by The Azure Updates Team - Azure Application Gateway offers a public preview of HTTP/3 over QUIC support, enabling faster connections, lower latency, and enhanced resilience for contemporary web services and APIs.
- Public Preview: Azure Payments HSM v2 by The Azure Updates Team - Azure Payments HSM v2 provides enhanced security with dedicated hardware isolation and advanced key management for protecting sensitive financial data while offering full administrative control.
- Migrating the GitHub Copilot runtime to Rust, using Copilot by Stephen Toub - GitHub Copilot migrated its agent runtime from TypeScript to 800,000 lines of Rust, using AI to complete the rewrite in months rather than years.
- Automating Azure VM Image Baking and Validation with Packer and Azure DevOps by Prakhar Sharma - Packer and Azure DevOps pipelines ensure image quality by validating the final gallery version rather than just the temporary build VM.
- How and Why We Bought 4x DGX Sparks by Alex Ellis - OpenFaaS deploys local DGX Sparks to process sensitive Kubernetes dumps and avoid the privacy risks inherent in third-party inference services like data retention and legal subpoenas.
🤖 AI
- Generally Available: Publishing Microsoft Foundry agents to Microsoft 365 Copilot and Teams The launch makes it easier for Foundry agents to reach users in Copilot and Teams, enhancing accessibility and real-world utility.
- Generally Available: Enable and disable controls for Microsoft Foundry agents in Agent 365 Administrators can now enable or disable individual Microsoft Foundry agents directly through Agent 365 in the Microsoft Admin Center, giving fine-grained control over agent usage and compliance.
- Public Preview: Network egress controls for hosted agents in Microsoft Foundry With the public preview of Network egress controls in Microsoft Foundry, users can create detailed outbound connection rules for hosted agents, specifying allowed destinations like *.contoso.com and enforcing permit or block actions.
- Public Preview: Foundry Routines in Foundry Agent Service Foundry Routines automate agent execution via scheduled triggers or business events in the public preview of Foundry Agent Service.
- Can a Harmless Prompt Break an AI Guardrail? A study reveals that 65% of winning AI attacks involve only benign-sounding turns leading to successful breaches after just a few harmless messages.
- NEWS: Microsoft 365 Copilot adds SpaceXAI Grok models for Word, Excel, PowerPoint Microsoft 365 Copilot now integrates SpaceXAI Grok models for Word, Excel, and PowerPoint, requiring Frontier Program enrollment and a Copilot license, while maintaining data privacy commitments similar to other subprocessor partnerships.
- Data Meets Agents Data Meets Agents explores secure integration of enterprise agents with data across platforms like Azure Databricks, Snowflake, and Google BigQuery using three complementary patterns while recommending Azure API Management for runtime governance.
- Microsoft Foundry Observability: How to Trace, Evaluate, Monitor, and Secure AI Agents Microsoft Foundry's AI observability framework enhances traditional logs, metrics, and traces by adding agent execution, safety policies, quality checks, and business outcome layers to help identify and fix semantic failures such as incorrect refunds.
- How and Why We Bought 4x DGX Sparks OpenFaaS deploys local DGX Sparks to process sensitive Kubernetes dumps and avoid the privacy risks inherent in third-party inference services like data retention and legal subpoenas.
- Moving Your Agent to Foundry Agent Service: Telemetry Deep Dive (Sample 10) The video demonstrates hosting a prompt agent in Foundry and integrating telemetry to monitor performance when calling it from a C# application.
- Bring Azure AI to your private workloads on Azure VMware Solution Azure AI Foundry integrates with Azure VMware Solution using a managed agent and bridges to let AI agents securely access private resources without revealing sensitive data.
- Your Agent Found the Right Schema. Then Ignored It. GPT-4o-mini accuracy drops from 58% to 18% when agents retrieve schemas alongside distractors, a failure fine-tuning recovers better than scaling to larger models.
- Closing the Recruiting Context Gap with Microsoft Foundry Closing the Recruiting Context Gap with Microsoft Foundry proposes a workflow that preserves nuanced job requirements such as distinguishing required from preferred skills and uses Azure AI Search to suggest relevant terminology allowing recruiters to review and approve search queries before execution.
- Copilots All the Way Down: A Field Guide to Microsoft's AI Naming Chaos (and Where Claude Randomly Snuck In) Microsoft applies the Copilot brand to over a dozen products while quietly integrating Claude models under three distinct sets of licensing terms.
- Practical Local AI for Enterprise Architects: A Workload Placement Approach Enterprise architects can map AI workloads across a spectrum of device, edge, private, and cloud environments to satisfy specific data residency and connectivity constraints.
- AI Is Changing How We Code. It’s Also Changing How We Learn. VSLive! emphasizes learning from experienced developers through hands-on sessions, hallway conversations, and expert insights on AI integration with .NET and modern development practices.
- The bottleneck isn't AI. It's transformation capacity. The key challenge for enterprises deploying AI is their transformation capacity to quickly convert ideas into scalable, measurable outcomes, says Kevin Shatzkamer of Microsoft Frontier Company.
- Foundry IQ with D365F&O and Fabric IQ Foundry IQ integrates D365 Finance and Operations data with Fabric IQ, Web IQ, and SharePoint to provide business recommendations for a retail organization analyzing promotional sales performance in multiple cities.
🔎 Analytics
- Implementing Type 4 Slowly Changing Dimensions in SQL Server Type 4 SCD separates current and historical data to enhance query performance for dynamic attributes like bank customers' loan repayments while maintaining complete audit trails.
- Running Fabric Pipelines from a Notebook Fabric REST APIs allow notebooks to trigger pipelines by polling activity-level statuses to ensure every individual task reaches a terminal state before proceeding.
- What Does It Mean to Make Data AI-Ready? Making Data AI-Ready involves ensuring data accuracy, clear semantics, governance, accessibility, and business context enrichment.
- Agent experience with data in Onelake using Fabric IQ Fabric IQ performs conversational analytics on integrated third-party and ERP data in Onelake, normalizing inputs such as misspelled city names to swiftly identify top revenue stores and customer footprints during retail promotions.
- Foreign Keys and Performance in a Microsoft Fabric Warehouse Microsoft Fabric warehouses ignore foreign key constraints during query execution, meaning developers must enforce data integrity at the ingestion layer to ensure performance.
🖥️ Compute
- Public Preview: Mdsv4 and Msv4 Series Virtual Machines for SAP The Mdsv4 and Msv4 SAP VM series, powered by 6th Gen Intel Xeon processors and Azure Boost, offer enhanced security and up to 40% faster performance for memory-intensive workloads.
- Announcing Public Preview of new Mv4 Medium Memory Virtual Machines Azure launches Msv4 and Mdsv4 Medium Memory VMs featuring 6th-generation Intel processors, up to 225,000 IOPS, 5,500 MBps bandwidth, Ultra Disk support, Total Memory Encryption, Trusted Launch, and sizes from M16ls_v4 to M256ls_v4.
- SSL/TLS certificates and end-to-end encryption for Azure Functions Flex Consumption Azure Functions Flex Consumption now supports site-scoped TLS/SSL certificates with up to three private and public certs per function app, multiple certificate sources including Azure Key Vault, enhancing security in serverless applications.
- Deploying Custom Images and Implementing CI/CD for Azure Virtual Machine Scale Sets Deploying custom images and implementing CI/CD for Azure Virtual Machine Scale Sets enables automated, consistent scaling of applications with rapid updates via integrated tools.
- Exploring hidden patterns in high-dimensional data with the Microsoft Quantum Development Kit for analytics The new Microsoft Quantum Development Kit introduces Quantum Tensor Principal Component Analysis for analyzing noisy, high-dimensional datasets in finance and life sciences.
- Azure Delivers Strong MLPerf Inference v6.1 Results with NVIDIA GB300 & GB200 Azure achieved the highest Interactive score on GB300 NVL72 and top Server and Offline scores on GB200 NVL72 in MLPerf Inference v6.1, demonstrating its ability to sustain high throughput across diverse latency-constrained and throughput-optimized deployment scenarios with DeepSeek-R1 model.
- Enable Dynamic Workflows in Azure Functions hosted skills Dynamic Workflows in Azure Functions hosted skills enable AI tasks to run independently post-initial request via Durable Functions, cutting model token usage by 56% for single services and 93% for ten services.
- Automating Azure VM Image Baking and Validation with Packer and Azure DevOps Packer and Azure DevOps pipelines ensure image quality by validating the final gallery version rather than just the temporary build VM.
🚢 Containers
- Public Preview: Azure Red Hat OpenShift with hosted control planes Azure Red Hat OpenShift’s new public preview offers a hosted control plane, separating it from worker nodes to simplify management and scaling for customers.
- Azure Red Hat OpenShift with hosted control planes now available in public preview Azure Red Hat OpenShift now offers a public preview of hosted control planes, enabling full management by Microsoft and Red Hat SREs in a separate subscription from worker nodes, improving agility, security, and efficiency for AI applications and modernization.
🗄️ Databases
- Generally Available: PG18 support for Azure Database for PostgreSQL elastic clusters Azure Database for PostgreSQL elastic clusters now support PostgreSQL 18, enabling developers to use advanced features like logical decoding and enhanced partitioning.
- Generally Available: New and improved troubleshooting guides for Azure Database for PostgreSQL The updated Azure Database for PostgreSQL troubleshooting guides offer detailed steps to diagnose and resolve common issues like high CPU, memory usage, IOPS limits, excessive temporary files, and inefficient autovacuum operations.
- Generally Available: Logical replication slot sync status metric for Azure PostgreSQL Flexible Server The new Azure Monitor metric lets you track logical replication slot sync status in real time, improving reliability for Azure PostgreSQL Flexible Server workloads.
- Public Preview: PostgreSQL skills and MCP plugin for Azure Database for PostgreSQL The new Azure Database for PostgreSQL plugin integrates AI coding assistants to enhance developer productivity with context-aware guidance and direct database actions.
- Public Preview: Azure SQL updates for mid-September 2026 Azure SQL introduces a new soft delete feature that preserves logical servers during deletion, allowing them to be restored within a configurable timeframe when accidentally removed.
- Preview PG18 for Elastic Clusters of Azure Postgres Azure previews PostgreSQL 18 for flexible server's elastic clusters adding managed horizontal scaling with Citus 14 for distributed SQL, sharding, and sub-second CDC latency up to 100 million rows.
- Automating Azure SQL DB index and statistics maintenance using Elastic Jobs. Automating Azure SQL DB index and statistics maintenance with Elastic Jobs reduces manual effort, ensures optimal performance, and integrates seamlessly with Azure Automation for scheduled execution.
- How a Microsoft-signed SQL Server stored procedure lets sysadmins bypass disabled xp_cmdshell A new SQL injection flaw in the internal `sys.sp_MSdeletefoldercontents` procedure allows running `xp_cmdshell` despite its disablement, circumventing crucial security settings.
- August 2026 Recap: Azure Database for PostgreSQL Azure Database for PostgreSQL introduces Adaptive autovacuum to automatically adjust vacuum processes based on workload signals, reducing bloat and maintenance overhead without manual tuning.
- SQL Server Performance Office Hours Episode 79 – Dang is it hot again In Episode 79, Erik Darling addresses persistent TempDB contention issues and explains how forced query plans can cause serial execution on multi-core machines due to optimizer costing.
- Postgres Skills: Give Your AI Agent PostgreSQL Expertise PostgreSQL Skills provides AI coding agents with 32 expert sub-skills to generate accurate, context-aware SQL for any PostgreSQL deployment, including Azure Database for PostgreSQL and HorizonDB, ensuring reliable execution through live database access.
- Should your SQL Server database use foreign key constraints? Foreign key constraints in SQL Server help prevent bad data but some teams avoid them due to perceived performance issues and development convenience, potentially overlooking integrity risks especially in multi-application environments.
- Recovering TPS After a Cross-Database Migration PostgreSQL performance drops after migration because the planner fails to convert NOT IN subqueries into anti-joins, forcing a costly materialization that is fixed by using NOT EXISTS instead.
- Your Index Rebuild Maintenance Plan Is Rebuilding Indexes Nobody Uses A weekly index rebuild may not improve performance as it often updates statistics without fixing fragmentation, causing extra logging, bigger backups, and wasted effort.
- Automating Azure Managed Redis capacity acquisition with bounded retries The Azure Managed Redis capacity poller safely creates capacity in approved regions and SKUs until a successful deployment occurs without risking infinite retries.
- SQL Server Performance Office Hours Episode 81 – A Slightly Disordered Release Schedule In Episode 81, Erik Darling covers SQL Server performance topics including key lookups, lock escalation, Query Store issues, latch contention vs. locking, and detecting worker thread starvation.
- Database Change Management - Azure Database for PostgreSQL, GitHub Actions and Liquibase OSS Liquibase automates schema migrations by treating database changes as version-controlled code, enabling automated rollbacks and drift detection within GitHub Actions pipelines.
- What happens when your AI coding agent starts a database on its own (building an app with AI, part six) In this sixth installment of Grant Fritchey’s series, Claude generates prompts to iterate on dbRosetta's app interface, enabling users to input a term and its data platform while receiving translations for multiple platforms including PostgreSQL, MySQL, Oracle, and SQL Server.
- Query Store Cleaning And Mysterious Broker Tasks SQL Server background processes labeled BRKR TASK often mask intensive Query Store cleanup operations that consume significant CPU resources.
- mssql-django 2.0: Now with mssql-python mssql-django 2.0 adds the mssql-python driver for enhanced datetimeoffset support and Entra ID auth with backward-compatible alias configurations.
🛠️ Developer tools
- Today I will… improve test coverage Visual Studio's Test Agent uses solution-wide analysis to boost code coverage from 37% to 81% by identifying gaps and automatically generating targeted unit tests.
- Explore the latest in MCP: All recordings from MCP Live! The MCP Live! event recordings cover the latest protocol updates, enterprise tooling, and practical demos of integrating MCP with GitHub Copilot, VS Code, and Foundry.
- Introducing a Guided Copilot Experience for Building Azure Apps in VS Code The new Guided Copilot experience for Azure app development in VS Code provides structured stages, local development with automation, and deployment with cost estimates to reduce unpredictability and ensure a reliable path from idea to deployed application.
- Migrating the GitHub Copilot runtime to Rust, using Copilot GitHub Copilot migrated its agent runtime from TypeScript to 800,000 lines of Rust, using AI to complete the rewrite in months rather than years.
- Agentic Mentor: A Specification-Driven, Multi-Agent Learning Tool Agentic Mentor employs a multi-agent pipeline with Research, Ingestion, Mentoring, and Viva agents to verify student understanding before progression, using locally hosted models for accessible educational initiatives such as GitHub Education.
- VS Code Release Notes Now Generated by Copilot -- 'Might Contain Inaccuracies' The VS Code release notes are now generated by GitHub Copilot, which may introduce inaccuracies, alongside new features like Dev Container agent sessions, enhanced Codex support, and automated session cleanup.
- Announcing the Playwright Workspaces Remote MCP Server for Agentic Browser Automation The Playwright Workspaces remote MCP Server allows AI agents to automate web tasks remotely without local browser needs, integrating seamlessly with platforms like Foundry and GitHub Copilot CLI.
- Why we turned Copilot's Auto mode off by default Michelex GitHub Copilot admins disabled Auto mode by default after finding it chose poor models and cost more despite a claimed 10% savings.
- Adding an Index Made This Query Slower Adding an index on created_at DESC can increase query latency by causing Postgres to scan more irrelevant rows despite its potential benefits.
- New Course Coming Soon: Integrating AI Agents in Enterprise Systems The new Pluralsight course covers integrating AI agents into enterprise systems, focusing on connections, workflows, failure handling, and governance using C# and the Microsoft Agent Framework.
🔩 DevOps
- Dashboards are for AI agents too, not just humans Azure SRE Agent shows how AI interprets and acts on dashboards similar to human operators using Grafana data to diagnose lengthy GitHub Copilot sessions.
- Tell AI Everything Twice, Then Tell It a Second Time LLMs suffer from context drift during long coding sessions, so developers should implement automated check gates and persistent rule files to enforce critical requirements.
- Patching in 2026 with Susan Bradley Susan Bradley discusses how patching in 2026 is complicated by increased vulnerability disclosures, growing patch volumes, and slow vendor responses to drivers and firmware updates, creating a heightened pressure on sysadmins to balance security with operational stability.
- Unexpected error when using the wrong ADO build agent Using an ADO self-hosted agent in a mixed public/private Azure environment can cause deployment errors due to its restricted network configuration preventing access to publicly accessible resources needed for the build process.
- Ctrl+Alt+Azure Episode 360 - GitHub Enterprise explained 360 explains GitHub Enterprise, covering essential features, compliance options, licensing models, total cost of ownership, and recommended deployment strategies for organizations of any size.
- Fixing complex bugs with AI - A deepdive into the PowerShellScriptAnalyzer The PowerShellScriptAnalyzer identified and partially fixed a bug causing Get-Command errors with AI assistance, emphasizing the necessity of thorough performance optimization.
🧬 Hybrid + multicloud
- Microsoft recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Distributed Hybrid Infrastructure Microsoft is recognized as a Leader in Gartner’s 2026 Magic Quadrant for Distributed Hybrid Infrastructure for its strong Ability to Execute through unified Azure Local and Azure Arc solutions.
- Beyond Virtualization: Why Microsoft and Azure Local Stands Out as a leader in Two Gartner Magic Quadrants Microsoft Azure Local excels in both Gartner’s Server Virtualization Platforms and Distributed Hybrid Infrastructure Magic Quadrants, thanks to its robust support for hybrid operations, edge computing, AI integration, and digital sovereignty requirements.
- Two modes combined: Windows Admin Center version 2610 is now in public preview! Windows Admin Center's new combined installer unifies Administration Mode and Virtualization Mode, simplifying deployment with added features like Azure Arc onboarding, backup, and certificate lifecycle management.
- When Azure Arc Says 400 Bad Request, the Network Is Probably Fine When Azure Arc returns a 400 Bad Request during onboarding, it often indicates network connectivity or configuration issues rather than problems with the service itself.
🎭 Identity
- Simplify Employee Identity Lifecycle with HiBob and Microsoft Entra The integration of HiBob with Microsoft Entra automates and governs employee identity lifecycle events, reducing manual handoffs and ensuring secure access across on-premises and cloud applications.
- Entra Auth Tracer + WebMCP – Letting an AI Agent Debug Your Authenticaiton Traffic Entra Auth Tracer integrates with WebMCP to streamline AI agent analysis and debugging of authentication traffic for identity provider updates.
- Microsoft delays Entra SMS and voice retirement dates Microsoft has postponed the retirement of its Entra SMS and voice services for Global Administrators and external users, introducing paid telecom providers as a replacement option.
- Replace VPN access with identity-driven security Replacing VPN access with identity-driven security using Microsoft Entra Private Access reduces risk and operational overhead while aligning private resource connectivity with Zero Trust principles.
- Microsoft Entra Connect Sync – Passwordless Authentication is now GA, plus the new Entra Connect Migration Tool is here! (v2.6.91.0) The new GA release of Passwordless Authentication in Entra Connect Sync simplifies user logins, while the accompanying migration tool v2.6.91.0 streamlines transitions from older versions.
- Public preview of self-service onboarding for new Microsoft Entra App Gallery applications The public preview enables independent software vendors to validate integrations and manage publishing processes directly in the Microsoft Entra admin center, reducing review cycle times.
- A2A Endpoints and A2A Tool in Microsoft Foundry agents The new A2A Endpoints and Tool in Microsoft Foundry simplify agent-to-agent collaboration using standardized protocol version 1.0, enabling secure discoverable interactions across agents without custom APIs or tight framework coupling.
🔌 Integration
- Azure Service Bus sessions: Delayed retries may need a hold-back Azure Service Bus sessions may let later messages override failed ones during retries, necessitating a hold-back mechanism to record failures and block processing until success.
- Agent Framework + Azure API Management: Proxying Model Calls with Telemetry (Sample 9) Azure API Management captures granular telemetry for agentic model calls, ensuring developers maintain full visibility into request patterns and performance metrics.
- API Management + Foundry Agent Service: Stitching Together End-to-End Telemetry (Sample 11) Foundry agent services gain centralized monitoring capabilities by routing all requests through an API Management layer to capture granular telemetry.
- Prepare for the launch of growth margins with API readiness resources The upcoming growth margins program, launching October 1, 2026, offers eligible partners additional revenue through enhanced deal structuring flexibility and automated data export and billing.
- Power Apps | Seven Skills, One Prompt: The Dataverse Plugin for Coding Agents The new Dataverse plugin enhances AI coding agents by streamlining seven key skills including metadata management, data manipulation, and administration tasks when working with tools like GitHub Copilot.
- Your Certificate Renewed. Your Gateway Didn't Notice. Azure API Management needs a direct CNAME to its default hostname for custom domain certificate validation; otherwise, issues arise with global entry points causing silent sync errors and possible outages.
- Build a Local RAG Application in C# with Ollama and Qdrant – Part 4 This fourth part replaces manual document ingestion with Microsoft.Extensions.DataIngestion, using token-based chunking for improved AI model alignment while maintaining the rest of the C# RAG pipeline.
💡 Internet of Things
- The Things Conference 2026 presents: Azure IoT Operations, the edge of tomorrow At this year’s Things Conference 2026, Sande Van Develde will demonstrate how Azure IoT Operations integrates with Microsoft Fabric for real-time edge intelligence using LoRaWAN sensors and ONVIF cameras.
🎓 Learning and Certifications
- From Exam Prep to Career Momentum: How MVP-Led Study Groups Help Communities Build Skills MVP-led study groups enhance certification prep with practical, community-driven learning in 14 countries, improving exam understanding for tests like PL-300 and DP-600 through hands-on sessions and peer support.
- Updates to Azure Cosmos DB and Power Platform Developer Certifications The updates to Azure Cosmos DB and Power Platform Developer Certifications reflect evolving developer roles, emphasizing cloud-native solutions, AI integration, and modern application architectures.
- Learn Uno Platform with Tim Corey, Free for Two Weeks The "Uno Platform From Start to Finish" course by Tim Corey provides 66 lessons totaling 6.5 hours of video content to teach C#/.NET developers how to build real apps with Uno Platform across Windows, macOS, and Linux, including productivity tools like Hot Reload and Hot Design.
⚖️ Management and Governance
- Public Preview Annoucement: Azure Policy Custom Policy Versioning! Azure Policy now lets you version custom policies with predictable updates, safer rollouts, and easy rollback, enhancing governance for both built-in and user-defined definitions.
- Bicep vs Terraform for Azure Landing Zones: How to Choose? Choosing between Bicep and Terraform for Azure Landing Zones depends more on organizational operating models such as ownership boundaries, governance controls, deployment processes, recovery capabilities, and existing investments than on tool features.
- Advanced Microsoft Intune capabilities are now available for GCC High Microsoft is expanding Intune's capabilities for GCC High customers with new features including Remote Help, Endpoint Privilege Management, Enterprise Application Management, and Cloud PKI from September 2026.
- Are your Azure alerts reaching the right people? Inside Azure Support Agent's Alerts Manager Azure Support Agent's Alerts Manager verifies alert scoping, action group recipients, and notification routes for better explainability and efficiency.
- New Agent 365 controls for Microsoft admins Agent 365 offers a unified registry and governance framework to track control AI agents apply security policies block shadow AI and provide usage analytics for IT admins and leaders.
- What changed, who changed it, and what evidence should you preserve? Azure Support Agent introduces Change Explorer, Evidence Locker, and Case Files to help operators distinguish between observed changes like a 60-second gateway timeout increase and their impact on latency, preserving evidence for future reviews.
- Find the workload’s bottleneck, not just a busy resource Azure Support Agent's Performance Profiler identifies bottlenecks by merging Azure Monitor metrics with Azure Resource Graph data, applying AMBA-aligned thresholds to target relevant resources and metrics during key periods.
- Moving from Windows Autopilot to Windows Autopilot device preparation Moving to Windows Autopilot device preparation offers a phased approach, allowing organizations to adopt a simpler provisioning model while preserving existing workflows and investments.
- INFO: Quick Ways to Reduce Your Azure Costs Learn practical techniques such as leveraging Azure Hybrid Benefit, using constrained vCPUs, and committing to savings plans to quickly reduce your Azure monthly costs.
- Action required: PromQL regex matching in Azure Monitor Workspace is becoming spec-compliant Azure Monitor Workspace is transitioning PromQL regex matching to fully anchored patterns per Prometheus spec, requiring users to adjust queries with ^...$ anchors or = for exact matches before updating the workspace's query engine by September 2026.
- Bicep vs Terraform for Azure Landing Zones: How to evaluate the right fit? Evaluating Bicep versus Terraform for Azure Landing Zones requires testing reproducibility, team ownership, governance changes, subscription vending, upgrades, scale, and traceability beyond deployment capabilities to determine the sustainable implementation model.
- FinOps-Ready Azure Landing Zone - Part 2 Turbo360 enhances Azure-native FinOps tools with application-level monitoring, unified multi-subscription visibility, and actionable cost optimization insights.
- Upgrade Veeam Backup for Microsoft 365 to v8.6.0.1102 Veeam Backup for Microsoft 365 v8.6 introduces enhanced data protection capabilities and resolves critical bugs, improving reliability for Azure-hosted Office 365 workloads.
🌐 Networking
- Generally Available: High-scale mesh in Azure Virtual Network Manager Azure Virtual Network Manager’s high-scale mesh feature now in GA lets customers connect up to 3,000 virtual networks per mesh by default across supported regions.
- Public Preview: HTTP/3 over QUIC support in Azure Application Gateway Azure Application Gateway offers a public preview of HTTP/3 over QUIC support, enabling faster connections, lower latency, and enhanced resilience for contemporary web services and APIs.
- Automating Private Endpoint DNS Across Azure Tenants with Azure Policy and Azure Lighthouse Azure Policy and Azure Lighthouse automate secure Private Endpoint DNS record management across tenants without needing app team modifications.
🔐 Security
- Public Preview: Multi-account support for Microsoft Sentinel codeless connectors The public preview allows a single connector in Microsoft Sentinel to manage connections across multiple accounts within one workspace, streamlining security operations.
- Public Preview: Azure Payments HSM v2 Azure Payments HSM v2 provides enhanced security with dedicated hardware isolation and advanced key management for protecting sensitive financial data while offering full administrative control.
- Windows, TLS 1.3 and Post Quantum Crypto FAQ Windows 11 from update KB5089573 supports TLS 1.3 and post-quantum cryptography with need for configuring hybrid PQ algorithms such as X25519_MLKEM768 for future quantum attack protection.
- Securing AI Agent Tool Calls in Azure: Identity, Authorization, and Verified Execution Azure AI agents use an Agent Control Loop to enforce security checks across five critical stages, including token validation, retrieval permissions, and least-privilege execution.
- From DLP Alert Volume to Measurable Detection Assurance Data Security Workbench converts high DLP alert volumes into measurable detection assurance and controlled response through a closed-loop process that explains alert reasons, creates reviewable improvement plans, and verifies change effectiveness with detailed reports and Purview steps.
- Improve Campaign Reach and Measurement with Azure Confidential Clean Rooms Azure Confidential Clean Rooms facilitates secure collaborative campaign analysis by enabling advertisers and partners to merge first-party datasets while adhering to privacy regulations such as GDPR, HIPAA, and the EU Digital Markets Act without revealing raw data.
- Cached Token Theft: Extracting Azure and Microsoft Graph Refresh Tokens from the macOS Keychain via PowerShell Cached Token Theft shows that PowerShell modules on macOS store refresh tokens insecurely in the Keychain, enabling unauthorized scripts to access sensitive privileges without prompting for authentication.
- Improving email security outcomes with real-world Microsoft Defender insights The latest Microsoft Defender email security benchmark shows it missed 55% fewer high-severity threats than the closest competitor, highlighting continuous measurement's role in improving protection outcomes.
- From guidance to action: Security fundamentals that materially reduce risk Secure Now offers prioritized guidance to strengthen security against AI-driven cyber threats by addressing key vulnerabilities such as excessive permissions and unprotected authentication flows.
📦 Storage
- Action immediately for Microsoft EWS retirement on Veeam Backup for Microsoft 365 Veeam advises immediate action as Microsoft plans to retire the Exchange Web Services (EWS) API starting October 1, 2026, affecting tenants without explicit EWS enablement.
💻 Virtual Desktop Infrastructure
- General Availability: User-initiated provisioning for Windows 365 Reserve User-initiated provisioning in Windows 365 Reserve enables eligible employees to swiftly request their own Cloud PC via the app, streamlining device recovery and boosting productivity during outages.
- Announcing: New Windows App client-side endpoints for Azure Virtual Desktop The new FQDNs enable smoother and more flexible connections for Windows App clients accessing Azure Virtual Desktop, enhancing scalability and reliability.