Azure Weekly
Issue 582
4th October 2026
There are a number of data & analytics related announcements this week as it's FabCon and SQLCon 2026 in Barcelona, I'd recommend reading Fabric Weekly Issue 12 and subscribing so that you receive Issue 13 on Tuesday for the rest of the FabCon announcements!
While I was editing this edition, I recieved an email from Microsoft about Azure Price increases (VMs and Storage) happening on the 1st February 2027, the best link I could find was this Reddit discussion.
There are lots of GA, Public Preview and Retirement notices this week. As a reminder if you want the "overview view" where you can toggle summaries on and off you can view the web based version of the newsletter.
Other highlights this week include:
- Retirement: Azure IoT Central will be retired on September 20, 2029 by The Azure Updates Team - Azure IoT Central will retire on September 20, 2029 due to ongoing platform evolution and a shift toward newer IoT solutions.
- Generally Available: Luxembourg - Azure Extended Zones by The Azure Updates Team - Luxembourg Azure Extended Zones provide low-latency compute and data residency compliance for local industries by deploying small-footprint infrastructure directly within the metro area.
- This Cybersecurity Awareness Month, build skills to secure the future by Phil Evans - This Cybersecurity Awareness Month provides role-based learning, live expert events, interactive challenges, and credential pathways to boost cybersecurity skills for an AI-driven future.
- Using Jev with Agents in Microsoft Foundry for Model Evaluation by Robin Lester - Using Jev with Agents in Microsoft Foundry enables structured, probabilistic judgements for model evaluation workflows, enhancing consistency and decision-making.
- Open Sourcing the Azure Policy Linter! by Steven Bucher - The Azure Policy Linter, now open source on GitHub, automates detection of common governance mistakes in policy definitions, improving compliance and deployment reliability.
🤖 AI
- From Jev to Your Laptop: Building "System One" Decision Models in ONNX with Mobius Mobius converts Jev decision models into ONNX graphs for fast local execution with 70-500 ms response times.
- Bringing AI-Powered Grid Optimization Offline: Quantizing GridSFM for Local Deployment GridSFM quantization enables offline power grid optimization on edge hardware by identifying safety thresholds across 53 topologies and integrating a RAG-enabled SLM interface.
- Connecting Azure AI Foundry to OpenCode, and some troubleshooting steps Azure AI Foundry integrations often fail due to the max_completion_tokens parameter requirement, which replaces the deprecated max_tokens field in standard OpenAI-compatible API requests.
- Why Microsoft is bringing Copilot together Microsoft integrates Copilot’s Home, Code, and Autopilot features to streamline tasks like proposal preparation, balancing protection of user relationships with cost efficiency concerns.
- Change Management Best Practices to Drive Value with Agent Builder Mastering change management is crucial for driving Agent Builder adoption; this guide offers practical strategies to build awareness, confidence, and engagement across your organization.
- Claude Sonnet 5.5 is now available in Microsoft Foundry Claude Sonnet 5.5 in Microsoft Foundry enhances efficiency and reduces costs for coding and knowledge work, ideal for developers handling complex tasks in modular agent systems.
- Comparing Three Approaches to AI Agent Evaluation and Observability Microsoft Foundry, Azure Container Apps, and self-hosted Langfuse offer distinct trade-offs between operational overhead, Azure-native integration, and unified observability for AI agents.
- Introducing GPT-6.1 Sol in Microsoft Foundry: Advanced intelligence, optimized for production agents GPT-6.1 Sol in Microsoft Foundry enhances agentic coding, computer use, and professional tasks with performance close to GPT-6 Astra at a more affordable price for frequent production agents.
- Using Jev with Agents in Microsoft Foundry for Model Evaluation Using Jev with Agents in Microsoft Foundry enables structured, probabilistic judgements for model evaluation workflows, enhancing consistency and decision-making.
- Developing Bioinformatics Workflows for Phage Therapy with Inspectable Agents Microsoft Discovery app uses a task-tree structure to help scientists build, inspect, and refine reproducible bioinformatics pipelines for phage therapy research.
- Let the query decide: introducing auto retrieval reasoning effort Foundry IQ's new "auto" retrieval reasoning mode boosts evidence recall to 97.6% and reduces token usage by 46.9%, suitable for diverse enterprise queries.
- Cohere Embed V5 brings more relevant retrieval to Microsoft Foundry Cohere Embed V5 in Microsoft Foundry offers Fast and Pro options with support for over 100 languages, flexible vector sizes, and improved multimodal retrieval quality across text and images.
- From "Agent Deployed" to "Agent Ready" - Agent Acceptance Gateway The Agent Acceptance Gateway introduces a clear handover process ensuring the application team verifies a deployed prompt agent's readiness through authentication, endpoint reachability, and service integration using a passwordless validator.
- What a Burger Combo Taught Me About Agents: Jev, LLMs, and Model Routers Jev automates decision-making tasks by returning typed choices with probabilities, unlike traditional LLMs that perform broader reasoning and may overstep into administrative duties.
- Beyond Agent Scores: Building Consequence-Aware Release Gates with Microsoft Foundry Beyond relying solely on agent scores, Microsoft Foundry's Consequence-Aware Agent Release Contract integrates tracing and evaluation to block releases when expected behavior like respecting policy limits is violated, despite high response quality.
- Build and govern AI agents across a multitenant organization Microsoft Entra and Azure API Management enable a federated agent factory that enforces central governance while keeping business data and runtime operations local to individual tenant boundaries.
- Build expressive voice experiences with new MAI models in Microsoft Foundry Microsoft Foundry launches MAI-Transcribe-2-Streaming for real-time speech transcription with sub-500 ms latency in 60 languages, boosting conversational AI capabilities.
- Foundry IQ in Microsoft Copilot Studio is now generally available The Foundry IQ integration with Microsoft Copilot Studio allows secure access to enterprise knowledge bases through private connectivity options, preventing public exposure and meeting network compliance.
- Deploying hosted agents in Foundry Agent Service via Terraform Terraform enables fully automated deployment of Foundry Hosted Agents, integrating them into existing IaC pipelines for consistent management and versioning alongside other Azure resources.
- Your Agent Shouldn't Wait for a Prompt: Build an Event-Driven Microsoft Foundry Routine Microsoft Foundry routines automate agent workflows by triggering actions directly from external events like GitHub issue creation, bypassing the need for manual chat prompts.
- How to make AI responses faster on Microsoft Foundry: lessons from 2,040 measurements Microsoft Foundry optimizations, including concurrent processing and reduced tool definitions, cut median AI-path latency by up to 50 percent across 2,040 test cases.
- Evaluate More, Spend Less: Batching Microsoft Foundry Evaluators for Efficient Evaluation Batching multiple evaluation criteria into a single Foundry call reduces model calls by 5-6x, cuts input and token usage by up to 71%, and speeds run time nearly in half while maintaining high-quality scores.
- Agent Trajectory Evaluation: LLM-as-Judge vs. Jev-as-Judge Agent Trajectory Evaluation examines LLM-as-Judge and Jev-as-Judge methods for assessing AI agent behavior along task trajectories, showing that LLM-as-Judge gives detailed explanations but is slower and more expensive, whereas Jev-as-Judge provides quick, consistent results with higher confidence.
🔎 Analytics
- FabCon and SQLCon 2026 in Barcelona: Building the data foundation for Microsoft Copilot and agents FabCon and SQLCon 2026 in Barcelona demonstrate building an AI-ready data foundation with Microsoft Fabric and agents for unified enterprise workloads, emphasizing governance and security.
- 10 Decisions to Make Before You Create A Fabric Workspace Before creating a Fabric workspace, decide on capacity and region as changing it later cannot move non-movable items or reassign regions without rebuilding content, considering data location, residency rules, tenant home region, and workload isolation needs.
- Building a Pattern-Based Engine to Migrate ADF Pipelines from Synapse to Databricks ADF migration engines treat pipeline JSON as a parseable AST, automating the conversion of 500+ activities by programmatically normalizing schemas and auto-discovering Synapse dependencies.
- Azure Databricks Cost and Workload Assessment: a Local Web UI Azure Databricks Cost and Workload Assessment provides an easy-to-navigate dashboard for optimizing Databricks environments by consolidating billing data, workload efficiency metrics, job health insights, inventory posture checks, and evidence collection.
- Prep data for AI vs. Fabric Data Agent Instructions: What Goes Where? Microsoft Fabric separates orchestration from model-specific logic, using Data Agent instructions to select sources and Prep data for AI to define how those models generate DAX queries.
- How to mirror data from SQL Server to Microsoft Fabric: complete guide Microsoft Fabric enables near real-time data replication from SQL Server by using change data capture to bypass traditional ETL pipelines.
🖥️ Compute
- Generally Available: Storage optimized Lasv5 and Laosv5 Azure VM series The Lasv5 and Laosv5 Azure VM series feature AMD’s 5th Gen EPYC Turin processors, scalable sizes from 2 to 160 vCPUs, 8 GiB memory, and up to 720 GB local NVMe storage per vCPU.
- Public Preview: Automatic Zone Placement for Virtual Machine Scale Sets Azure’s new Public Preview feature automatically selects optimal availability zones for Virtual Machine Scale Sets, optimizing performance and reducing manual management effort.
- Retirement: Microsoft HPC Pack Microsoft will phase out HPC Pack over a year, with full end-of-support on August 27, 2027, and only limited retirement-specific assistance available during the transition.
- Retirement: Dv3, Dsv3, Ev3, and Esv3 Azure VMs Azure will retire the Dv3, Dsv3, Ev3, and Esv3 VM series on November 15, 2029, prompting users to migrate to newer generations for continued support and performance.
- Retirement: NVv4-series Azure Virtual Machines Azure will retire its NVv4-series VMs on September 30, 2026, including sizes from standard NV4 to NV32 across both a- and h-series configurations.
- Retirement: NVv3-series Azure Virtual Machines Azure will retire its NVv3-series VMs on September 30, 2026, phasing out older high-performance instances like the Standard_NV12s_v3 and Standard_NV48s_v3 in favor of newer generations optimized for AI workloads.
- Retirement: DCsv3 and DCdsv3-series Azure Virtual Machines will be retired on October 31, 2029 Azure will retire the DCsv3 and DCdsv3-series VM series on October 31, 2029, prompting users to migrate their workloads to newer alternatives before the deprecation.
- Do stopped Azure VMs still cost money? Azure VMs continue to incur compute costs unless they reach the specific Stopped (deallocated) state, as OS-level shutdowns often leave hardware allocated to a host.
- Enhancing Microsoft Azure Virtual Machine lifecycle The new Azure Virtual Machine lifecycle policy offers transparency into technology status, predictability with defined stages and advance notice, and actionable guidance for modernizing workloads aligned with Azure’s latest innovations.
- Announcing General Availability of Azure Lasv5 and Laosv5 VMs Based on 5th Gen AMD EPYC™ processors Azure Lasv5 and Laosv5 VMs feature 5th Gen AMD EPYC processors with up to 30.7 TB and 138 TB of local NVMe storage per vCPU, ideal for high-density data-intensive workloads.
- Microsoft and IBM bring enterprise-scale workload orchestration to Azure with IBM Spectrum Symphony IBM Spectrum Symphony now uses a new Azure resource connector to dynamically burst HPC workloads into Azure Compute Fleet, optimizing costs through automated Spot instance management.
🚢 Containers
- Public Preview: Ubuntu 26.04 support in AKS AKS public preview adds Ubuntu 26.04 support with a minimal OS SKU to help teams manage package footprint, security, and compatibility during LTS transitions.
- Retirement: Azure Functions v1 hosting model on Azure Container Apps Azure is retiring the v1 hosting model for Azure Functions on Container Apps on September 29, 2027, requiring developers to migrate to newer versions to maintain app functionality.
- Sending Email from an AKS Pod Without a Single Secret Azure Workload Identity combined with Exchange Online RBAC for Applications allows pods to send email via Microsoft Graph without storing secrets or granting tenant-wide permissions.
- AKS: Ship Production-Ready Apps with Helm and CNI Overlay Azure Kubernetes Service (AKS) helps developers deploy production-ready apps using Azure CNI Overlay networking, Azure Container Registry, Helm, the Gateway API, Entra ID, and advanced NetworkPolicies.
- From Docker Desktop to a 10 Node Kubernetes AI Cluster – My Journey with Helm and OpenWebUI This project transforms Docker Desktop into a 10-node Kubernetes AI cluster using Helm and OpenWebUI, enabling scalable containerized AI model deployment with GPU support and real-time monitoring.
- Run an Ollaya decision model on Azure Container Apps Running Ollaya decision models on Azure Container Apps serverless GPUs enables predictable, low-latency inference with token savings and calibrated probabilities, ideal for bounded tasks like intent classification or policy checks.
- When AI Starts Taking Action: Building Execution Boundaries with OpenSandbox and AKS OpenSandbox integrates with AKS to offer secure, per-session sandbox environments for AI agents using Kata Containers and the Model Context Protocol.
- Understanding Azure Container Apps Costs: ACA Compute, Metrics and Cost observability - Part 2 Azure Container Apps reserves resources for each replica without separate requests or limits, making right-sizing the main cost control method in dedicated profiles.
🗄️ Databases
- Generally Available: Azure SQL Managed Instance updates for late-September 2026 Azure SQL Managed Instance now offers a flexible memory feature that lets users adjust instance memory without downtime, enhancing scalability for late-September 2026 GA updates.
- Generally Available: Vector search and vector indexes in Azure SQL Azure SQL now offers native vector search and index capabilities via T-SQL, enabling efficient approximate nearest neighbor queries for AI applications like semantic search.
- Generally Available: Database DevOps in SSMS powered by SQL projects SQL Server Management Studio now includes Database DevOps capabilities via SQL Build projects, allowing teams to define, implement, and collaborate on database changes locally with integrated version control and deployment features.
- Generally Available: SQL Server support on Azure Local connected mode SQL Server on Azure Local connects on-premises workloads to Azure services, enabling centralized management, enhanced security, and unified licensing across hybrid environments.
- Generally Available: SQL Server on Azure Local Disconnected (ALDO) SQL Server on Azure Local Disconnected (ALDO) enables continuous database operation in offline, highly regulated environments by caching transactions and syncing when connectivity is restored.
- Generally Available: Azure Database for PostgreSQL Flexible Server supports cross-tenant customer-managed keys (CMK) Azure Database for PostgreSQL Flexible Server now offers a GA feature allowing customers to use cross-tenant customer-managed keys for encryption via Azure Key Vault or Azure Managed HSM.
- Generally Available: Azure SQL updates for late-September 2026 Azure SQL now offers newly launched 160-vCore and 192-vCore options in its Hyperscale Premium series, providing up to 50% more compute capacity for scaling larger workloads.
- Generally Available: Azure Arc-enabled SQL Server Available in Italy North Azure Arc-enabled SQL Server’s general availability in Italy North lets organizations manage SQL Server instances with native Azure tools for inventory, governance, security, and licensing.
- Generally Available: Azure Arc-enabled SQL Server in Germany West Central Azure Arc-enabled SQL Server is now generally available in Germany West Central, allowing direct management of SQL Server instances using native Azure tools for inventory, governance, security, and licensing.
- Public Preview: Azure SQL Dev Hub Azure SQL Dev Hub offers developers comprehensive guides and tools for connecting to Azure SQL across multiple languages, streamlining application development workflows.
- Public Preview: Long-term retention (LTR) v2 for Azure Database for PostgreSQL Azure Database for PostgreSQL's new Long-term Retention v2 uses physical snapshot-based backups in Azure Backup Vaults, providing faster restores and lower storage costs than the old logical backup approach.
- Public Preview: Azure SQL Database Hyperscale Serverless auto-pause and auto-resume Azure SQL Database Hyperscale’s new Serverless tier offers automatic pausing and resuming, optimizing costs by stopping idle workloads and quickly restarting them as needed.
- Public Preview: Azure SQL updates for late-September 2026 Azure SQL introduces Database Hub in Microsoft Fabric, providing a single interface to manage and optimize databases spanning both on-premises SQL Server and Azure SQL configurations.
- Public preview: Script-based deployment for SQL Server on Linux Azure VM The public preview introduces a script-based deployment method for SQL Server on Linux Azure VMs, offering enhanced flexibility, streamlined management, and deeper customization options.
- Public Preview: Performance monitoring for Azure Arc–enabled SQL Server The public preview now offers customizable exploration and visualization tools, allowing direct querying of Azure Arc-enabled SQL Server’s managed monitoring data via a dedicated telemetry endpoint.
- Public Preview: SQL Performance Monitoring for Azure SQL Database Azure SQL Database’s new public preview offers built-in SQL Performance Monitoring, eliminating the need for custom scripts and cross-tool correlation.
- Public Preview: Azure Database for PostgreSQL Ultra Disk Azure Database for PostgreSQL Ultra Disk preview offers the highest-performance managed disks, ideal for I/O-intensive and high-transaction workloads needing consistently low latency.
- Public Preview: SQL performance monitoring for SQL Server on Azure Virtual Machines The public preview introduces managed SQL performance monitoring for SQL Server on Azure VMs, eliminating the need for custom scripts and simplifying telemetry correlation.
- Public Preview: Major version upgrades (MVU) for Azure Database for PostgreSQL elastic clusters Azure Database for PostgreSQL’s major version upgrades allow in-place upgrades of elastic clusters to newer PostgreSQL versions without downtime or data migration.
- More performance and flexibility for Azure SQL Managed Instance Business Critical Azure SQL Managed Instance Business Critical introduces higher transaction log throughput and flexible memory options to optimize performance for demanding workloads starting September 28, 2026.
- Announcing the public preview of Local Time Zone Support in Azure SQL Database Azure SQL Database’s public preview introduces local time zone support via T-SQL, enabling apps to display dates and times in their regional format while keeping underlying data stored in UTC.
- Public Preview: Performance monitoring for Azure SQL Azure SQL’s public preview provides unified performance monitoring across multiple services with consistent dashboards and direct query access via Azure Data Explorer.
- The same connection string keywords now work across our SQL drivers The updated SQL drivers now share connection string keywords like Server, Database, UID, and others for consistent configuration across C#, Go, Python, and C++ applications.
- SQLCon Barcelona 2026: Advancing SQL with greater control, scale, and intelligence SQLCon Barcelona 2026 announced the general availability of SQL Server on Azure Local, featuring connected and disconnected operations with local control planes, plus enhanced Azure SQL Database Hyperscale options such as increased compute choices, serverless auto-pause, vector search support, and an easier migration experience for enterprises focused on data sovereignty and scalability.
- PostGIS and AI Retrieval in Azure HorizonDB Azure HorizonDB integrates PostGIS and pgvector with DiskANN to enable spatial filtering, semantic retrieval, and AI-assisted queries on a single PostgreSQL database.
- MI link support for multiple databases in an Always On availability group for SQL Server (Preview) Managed Instance link now supports replicating entire availability groups as a single unit, eliminating the need to create individual links for every database.
- SQL Server Performance Office Hours Episode 85 – Lisbon is for Lovers In Episode 85 of SQL Server Performance Office Hours, held in Lisbon, Erik Darling discusses optimized locking for specific use cases, explains why server restarts can temporarily boost performance by clearing caches, and shows how to identify high-execution-count queries that impact overall throughput despite being fast individually.
- Announcing flexible provisioning for SQL Server on Linux Azure VMs (Public Preview) The new script-based provisioning model for SQL Server on Linux Azure VMs offers greater flexibility to choose distributions, versions, and configurations while automatically registering instances with the SQL IaaS Agent extension for licensing and compliance benefits.
- SQL Server on Azure Local is now generally available SQL Server on Azure Local enables organizations to run mission-critical databases in disconnected environments, preserving data control while integrating AI through Foundry Local.
- Database Hub in Fabric: Now in Public Preview -Turn Database Signals into Guided Action Database Hub in Fabric's public preview unifies insights across multiple database services to help administrators prioritize actions.
- Public Preview: Auto-pause and auto-resume for Azure SQL Database Hyperscale Serverless Azure SQL Database introduces a public preview of auto-pause and auto-resume features for its Hyperscale Serverless tier, enabling automatic pausing of databases during inactivity and rapid resumption to cut costs for idle workloads while preserving familiar configuration settings.
- A Single View of Your PostgreSQL Estate: Database Hub in Public Preview Database Hub’s public preview for Azure Database for PostgreSQL offers fleet visibility, security posture assessment, and real-time performance monitoring without data replication or new telemetry pipelines.
- SQL Server Performance Office Hours Episode 86 – Drinking Champagne in an Algarve Bathtub In Episode 86, Erik Darling covers managed instances, misleading performance counters, time-specific issue diagnosis, effective partitioning with columnstore indexes, and Query Store's limitations on wait stats.
- Announcing the Public Preview of Reader Endpoint for Azure Database for MySQL The new Azure Database for MySQL Reader Endpoint simplifies read scaling with automatic connection routing across eligible replicas using rotational or performance routing methods, configurable via replica participation, replication lag thresholds, and DNS settings to enhance application performance.
- Dynamic Data Masking – What it is, What it isn’t, and How to use it effectively Dynamic Data Masking in SQL Server hides sensitive query results like email addresses without altering stored data, simplifying developer tasks but requiring careful control of privileged users to prevent inference or bypass.
- BULKADMIN role support for SQL Server on Linux is now Generally Available The GA release of SQL Server on Linux now supports the bulkadmin role and ADMINISTER BULK OPERATIONS permission, enabling bulk data imports without sysadmin privileges to enhance security.
- Optimized Locking in SQL Server 2025 SQL Server 2025 introduces optimized locking with Transaction ID (TID) locking and LAQ to reduce memory usage and lock escalation, improving concurrency and performance in databases such as Azure SQL Database and Managed Instance.
- SQL Server Developer Edition: Free Download Links From SQL Server 2017 to SQL Server 2025 SQL Server Developer Edition provides free download links for versions 2017 to 2025, offering non-production features with support until 2030.
- Evidence-bound: what AgentDBA will and won’t link AgentDBA accurately identifies when database evidence is available to link issues but deliberately omits records lacking full backups, ensuring only substantiated connections are reported.
- AI features in Azure databases Hybrid ranking outperforms pure vector or keyword searches in benchmarking Azure Database for PostgreSQL and Azure Cosmos DB with 1,000 records, though calling models directly from the database adds latency but supports retrieval-augmented generation; a graph extension offers no extra benefit over SQL.
🛠️ Developer tools
- Generally Available: SQL Formatter SQL Formatter's General Availability in Visual Studio Code allows developers to automatically format SQL scripts for consistency and readability with customizable options.
- Public Preview: Microsoft SQL Agent Skills Microsoft SQL Agent Skills offer tailored AI assistance for managing and migrating SQL workloads across Azure SQL Database, Azure SQL Database containers, and SQL Server to Azure.
- Announcing: Azure canvases for GitHub Copilot Azure canvases for GitHub Copilot let developers explore, manage, visualize costs, and create custom skills in one workspace during Copilot-assisted coding.
- Mark Michaelis: Mastering the Agentic Coding Workflow - Episode 421 Mark Michaelis, a long-time C# expert and Microsoft Regional Director, shares insights on integrating AI into the agentic coding workflow in his recent episode.
- How we built a course with humans in the loop and agents in the workflow The GitHub Copilot app for Beginners course involved human input for ideas, strategy, and QA while AI assisted with content scaffolding, visual generation, and repetitive tasks.
- Microsoft Agent Framework for .NET (part 4): static methods, instance methods, MCP Clients as custom Agent tools Microsoft Agent Framework for .NET enables developers to expose static methods, instance methods, and MCP clients as functional tools for autonomous agents.
- DocumentDB as an Internal Hybrid Store: Documents, Vectors, State, and Safe Publication The prototype employs a local DocumentDB engine as an internal hybrid store integrating text, vectors, schema metadata, conversation history, and publication state while hiding identical search operators and PostgreSQL layers from users.
- Visual Studio September Update – Power Your Workflow with Your Model The September Visual Studio update lets developers choose their preferred LLM for tasks like fixing vulnerable packages and reviewing pull requests, with new debugging tools and support for bringing your own model via GitHub Copilot or external providers.
- Amid AI Debate, Copilot Adds Latest Models, Offers Limits on Agent Access GitHub Copilot provides updated models, sandboxing, and enterprise monitoring to address concerns over unauthorized agent use and enhance AI safety.
- Bring managed browser automation to your agent applications Cloud Browsers lets AI agents automate workflows via a managed browser service using the Model Context Protocol for tasks like navigation and data capture.
- Visual Studio September Update Expands BYOM, Adds NuGet Fixes The September Visual Studio update introduces Bring Your Own Machine learning models, enhances Copilot for package management, adds PR exploration tools, and improves debugging capabilities.
- VS Code 1.140 Expands Agent Coordination Across Folders and Machines VS Code 1.140 introduces experimental agent coordination across folders and machines, integrating HydraFusion for model orchestration and auto-tier settings tailored for enterprises.
- Meet the Hosted Skills Canvas: Build, Run, and Debug in GitHub Copilot The Azure Functions Hosted Skills Canvas integrates with GitHub Copilot to let developers define event triggers and AI instructions in one interface for building, debugging, and invoking function apps seamlessly.
- RAG in Microsoft Agent Framework Step By Step Learn how to integrate Retrieval-Augmented Generation into the Microsoft Agent Framework using a step-by-step C# example that covers document chunking, embedding storage, and attaching a search delegate via TextSearchProvider for traceable model responses.
- Postgres MCP Server: Connect AI coding agents to PostgreSQL The open-sourced Postgres MCP Server lets AI coding agents inspect and interact with PostgreSQL databases in real time, offering tools for querying, schema design, performance diagnosis, and connection management.
- From standards to software: Microsoft’s ongoing work on OpenAPI and developer tooling Microsoft is enhancing OpenAPI and JSON Schema support across its products and open-source projects to improve API precision, tooling reliability, and AI-assisted development efficiency.
- Part 1: What is the Model Context Protocol? An Introduction for .NET Developers The Model Context Protocol (MCP) standardizes how AI models discover and invoke tools across processes and networks, reducing repetitive integration work for .NET developers building AI agents.
- Part 2: Building Your First MCP Server in C# This C# tutorial demonstrates building a basic MCP server with two expense report tools via stdio, stressing the need to direct all output to stderr to maintain JSON-RPC communication.
- Part 3: MCP Tools, Resources and Prompts in .NET This third part of the MCP Servers in .NET series focuses on enhancing Model Context Protocol tools, adding an expense policy resource, and improving prompt handling for better AI agent interactions.
- Resumable Health-Record Ingestion Without Sacrificing the Last-Known-Good Index The pattern bounds memory and concurrency, persists checkpoint state for recovery, stages new chunks outside active retrieval, and atomically publishes only complete generations to preserve the last-known-good index even when failures occur.
- Beyond the Trace: The Science of Insight Quality Foundry's Insight feature automates evidence analysis to improve developer efficiency by transforming repetitive agent behavior into reviewable findings with linked traces and suggested actions.
- What It Actually Took to Port the GitHub Copilot Runtime to Rust GitHub moved Copilot's runtime from TypeScript/Node.js to Rust, writing over 800,000 lines of production-ready code in two months with significantly faster performance.
🔩 DevOps
- Highlights from Git 2.56 Git 2.56 adds a safer `git add --resolved` mode staging only conflicted paths and optimizes ancestor search for faster performance in large repos.
- Enterprise Live Migrations: Moving Azure DevOps Repos to GitHub Without the Freeze Azure DevOps teams can migrate repos to GitHub with minimal downtime using automated tools that sync history and branch protections.
- Bring Your Azure DevOps Repos to Azure SRE Agent Plugins Azure DevOps teams can now connect their repositories directly to Azure SRE Agent plugins, streamlining the process without needing separate mirrors for runbooks and tools.
- Are AI agents the new platform engineering customers? AI agents are becoming platform engineering customers by rapidly consuming APIs and workflows, requiring designs for both human developers and automated agents.
- Updates to Copilot Code Reviews for Azure Repos Copilot Code Reviews for Azure Repos now allows teams to set effort levels (Lite or Balanced) at project and repository levels, streamlines comment resolution by grouping related comments for simultaneous resolution upon commit, and adds detailed audit log events for monitoring usage and configuration changes.
- GitHub-hosted agents with Pay-as-you-Go pricing are now generally available in Azure Pipelines Azure Pipelines now offers GitHub-hosted agents with pay-as-you-go pricing, allowing teams to access more compute options like native Apple silicon and larger Linux and Windows machines without upfront capacity purchase.
- Azure DevOps Agent Pools: Fix Idle Agents and Queue Stalls Azure DevOps provides diagnostic steps to address idle agents causing queue stalls by examining parallel job limits, agent demand mismatches, stuck leases, and adjusting pool scaling appropriately.
- AI is rewriting the developer career ladder. Here’s how to stand out. AI is reshaping developer roles, emphasizing the need to direct AI outputs, critically evaluate them, and focus on higher-level problem-solving rather than just coding.
- Azure Bicep: Bulletproof Production Deployment Patterns Azure Bicep offers robust deployment patterns with version-controlled modules via private registries, enforced code quality through linting and rules, and precise change audits via stack tracking.
🧬 Hybrid + multicloud
- Generally Available: Luxembourg - Azure Extended Zones Luxembourg Azure Extended Zones provide low-latency compute and data residency compliance for local industries by deploying small-footprint infrastructure directly within the metro area.
- Retirement: Azure Arc enabled System Center Virtual Machine Manager will be retired September 30, 2029 Customers must migrate from Azure Arc-enabled System Center Virtual Machine Manager by September 30, 2029, due to its end of support and development.
- Strengthen SQL Server security on Azure Local with Trusted Launch Trusted Launch enhances SQL Server on Azure Local security by enabling Secure Boot, a virtual TPM, and automatic vTPM state preservation during VM migrations.
- Episode 2: Reduce restarts with Hotpatch for Windows Server 2025 | The Azure Arc Check-In Azure Arc’s Hotpatch feature lets Windows Server 2025 machines receive security updates without restarts, reducing maintenance windows while keeping servers protected at no extra cost.
- Released: September 2026 V2 Exchange Server Security Updates The September 2026 V2 Exchange Server Security Updates include CVE-2026-96940 and address responsibly reported vulnerabilities, with specific versions available only to customers enrolled in the Period 2 ESU program.
🎭 Identity
- Global Secure Access – Multiple Traffic Forwarding profiles for Private Access is finally here! Global Secure Access now supports multiple Traffic Forwarding profiles for Private Access, enabling more granular control and optimization of secure connections.
- Microsoft Global Secure Access (GSA) Traffic Forwarding Profiles v2 Microsoft's Global Secure Access (GSA) Traffic Forwarding Profiles v2 lets admins tailor private app access per user, group, device, or platform, with detailed guidance on assignment priorities and handling overlapping IP ranges.
- Sign in to Microsoft apps with passkeys from external identity providers Browser authentication lets organizations use external identity provider passkeys and security keys for signing into many Windows apps on Android, iOS, and macOS without needing an embedded web view.
- Entra SCIM MCP v0.3.0 updates for changes to the Entra SCIM API Entra SCIM MCP v0.3.0 updates reflect recent changes in the Entra ID SCIM Provisioning API, adjusting required fields for create requests and streamlining integration workflows.
- Stop Service Principal Sprawl in Entra ID with PowerShell Use PowerShell and Microsoft Graph to inventory App Registrations and Service Principals in Azure Active Directory, automating ownership management, credential rotation, and secure disabling to curb Service Principal sprawl.
🔌 Integration
- Connect Claude Code to MCP hosted in Azure API Management The guide shows how to integrate Claude Code with MCP servers running on Azure API Management, enabling secure and scalable code execution workflows.
- Bring Azure Logic Apps connectors into your .NET applications with the Azure Connectors SDK The Azure Connectors SDK allows .NET developers to use typed clients and managed authentication for Azure Logic Apps connectors, simplifying integration with services such as Office 365 Outlook by hiding service-specific details.
💡 Internet of Things
- Retirement: Azure IoT Central will be retired on September 20, 2029 Azure IoT Central will retire on September 20, 2029 due to ongoing platform evolution and a shift toward newer IoT solutions.
🎓 Learning and Certifications
- A Day of Azure: My Experience at Azure Fest 2026 At Azure Fest 2026, the author explored cutting-edge AI tools and networked with industry leaders, highlighting innovative solutions for enterprise cloud adoption.
- AI-901 Explained: What’s New in Microsoft’s Azure AI Fundamentals Exam The AI-901 certification replaces the retired AI-900 exam with expanded content on generative AI, large language models, and hands-on use of Microsoft Foundry's unified platform.
- This Cybersecurity Awareness Month, build skills to secure the future This Cybersecurity Awareness Month provides role-based learning, live expert events, interactive challenges, and credential pathways to boost cybersecurity skills for an AI-driven future.
- Microsoft makes repo’s for Learn documentation private, now what? Developers seek alternative methods like community-driven mirrors and enhanced API access due to the privatization of GitHub Learn documentation repositories.
- Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 Attend Microsoft Ignite 2026 to explore an AI-first security platform protecting various assets with experts and peers.
⚖️ Management and Governance
- Open Sourcing the Azure Policy Linter! The Azure Policy Linter, now open source on GitHub, automates detection of common governance mistakes in policy definitions, improving compliance and deployment reliability.
- System Center 2022 Update Rollup 4 System Center 2022 Update Rollup 4 enhances stability and security, adding support for newer Linux distributions like RHEL 10 and Ubuntu 26, improving VM deployment networking, and fixing authentication issues across Operations Manager, Service Manager, Virtual Machine Manager, and Orchestrator components.
- Now Available: Management Group–Scoped Savings Plan and Reservation Recommendations in Azure Azure provides savings plan and reservation recommendations at the management group scope for centralized cost optimization across organizational hierarchies.
- SCOM 2016 and Windows Server 2016 Reach End of Support in January 2027 — Here’s Your Plan Planning for SCOM 2016’s end of extended support in January 2027 is crucial; migrating to SCOM 2025-supported through ten more years-is recommended over costly ESU extensions.
- SCOM 2022 UR4 Console Authoring Pane Issue – Déjà Vu from SCOM 2025 The SCOM 2022 console encounters a recurring error post Update Rollup 4 due to IE Enhanced Security Configuration affecting the WebBrowser control.
- Azure Data Sovereignty Guardrails: Cut Jurisdictional Risk Azure introduces guardrails for enforcing data residency policies, controlling encryption key management, ensuring operator oversight, and meeting compliance requirements to reduce unauthorized cross-jurisdictional data access risks.
- Patching on a Schedule You Can Actually Explain: Azure Update Manager Maintenance Configurations Azure Update Manager introduces clear, explainable maintenance configurations that simplify patch scheduling, reducing uncertainty for IT teams.
- How to Stop AI Sprawl in Azure with a Governance Hub Azure’s new governance hub stops AI sprawl by centralizing inventory, routing all model calls through a secure gateway, and enforcing identity, data loss prevention, and policy compliance.
- Explore App Advisor for details on how Frontier Accelerate for Marketplace can help you sell more App Advisor streamlines Frontier Accelerate for Marketplace with free and premium paths offering tech benefits, cloud credits, and stage-specific consultations.
- Microsoft FinOps News - September 2026 The September 2026 FinOps news roundup covers new Azure OpenAI Foundry pricing updates, the launch of GPT-5.6 and GPT-6.1 models in Foundry, and innovative cost-management features across Copilot, Agent 365, and GitHub Copilot.
🎬 Media
- Azure Communication Services Chat is retiring - and your chat history goes with it Azure Communication Services Chat requires manual data extraction via REST APIs before the September 2028 retirement, as Microsoft provides no automated migration tools for chat history.
🚌 Migration
- Generally Available: SQL Migration Agent Skills for assessment, migration, and validation The SQL Migration Agent Skills provide automated, AI-powered guidance for every stage of migrating from SQL Server to Azure, from initial assessment to final validation.
- Public Preview: Migrate directly from Azure Arc to Azure SQL Database, including Hyperscale Azure Arc's public preview enables direct migration to Azure SQL Database, including Hyperscale, via a streamlined integrated workflow for Azure Database Migration Service and Self-hosted Integration Runtime.
- Migrate to Azure SQL Database, including Hyperscale, straight from Azure Arc (public preview) Azure Arc now provides a unified experience to migrate directly from Azure Arc-enabled SQL Server to Azure SQL Database, including the Hyperscale tier, thus reducing migration complexity.
- SQL Server Migration, Reimagined with AI-Powered Skills SQL Migration Agent uses AI to streamline the entire migration process from pre-assessment to post-migration verification for SQL Server to Azure.
- Know Before You Migrate: Bringing Readiness, Sizing, and Pricing Together in SSMS The enhanced SSMS migration assessment evaluates database and source configuration readiness, recommends Azure SQL targets with sizing and pricing details, and indicates next steps for unresolved issues.
🌐 Networking
- Network security perimeter metrics are now generally available in Public Cloud Network security perimeter metrics in Azure Monitor offer real-time visibility into access patterns, rule impacts, and unexpected traffic behavior for better monitoring, alerting, and trend analysis.
- Scaling distributed AI infrastructure with Azure’s ExpressRoute and AI Points of Presence (AI PoPs) Azure's AI Points of Presence extend private high-bandwidth connectivity via ExpressRoute for seamless integration and management of distributed GPUs in North America, Europe, and Asia Pacific.
- An unexpected friendship: subnet peering and advertised gateway prefixes To enable subnet peering in Azure's Firewall-as-a-Service for SAP RISE, deploy Linux BGP routers alongside Azure Firewall as a workaround to advertise non-hub subnet prefixes via ExpressRoute.
- Azure Firewall Explicit Proxy: Architecture, Configuration Guide, and Enterprise Deployment Azure Firewall Explicit Proxy lets applications send HTTP and HTTPS traffic directly to Azure Firewall using its private IP, enabling centralized outbound control without UDRs, and is configured via the Azure portal or CLI with support for PAC files for automated client settings.
🔐 Security
- Updating Purview DLP Sensitive Service Domain Groups with PowerShell This PowerShell guide demonstrates how to safely update Purview DLP sensitive service domain groups by adding new URLs only if absent, with backup steps and validation before finalizing changes.
- From Domain Lists to Decisions: Scaling WHOIS Threat Intelligence with MDTI and Microsoft Graph Scaling WHOIS threat intelligence with MDTI and Microsoft Graph automates consistent, audit-ready enrichment of suspicious domains, turning fragmented alerts into actionable campaign insights within incident response timelines.
- NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis, active since October 2025, employs modular C++ loaders and custom archives to evade detection and sustain long-term access post-compromise.
- How we found 24 Android vulnerabilities using our open source AI security agent The open source AI security agent discovered 24 Android vulnerabilities by automating and customizing AI prompts to focus on complex mobile-specific threat models.
- Escalating Privileges as a Catalog Owner: How Microsoft Entra Identity Governance’s API Permission Management Could Be Abused The post describes a vulnerability in Microsoft Entra Identity Governance allowing unauthorized catalog owners to grant excessive API permissions to service principals, emphasizing the need for securing escalation paths after resource onboarding.
- Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard has refined its phishing and malware delivery using the RedFlick technique, targeting Ukrainian individuals, NGOs, think tanks, governments, and financial institutions.
- Beyond source code: A path to the keys to the kingdom The report describes how threat actor Storm-3068 exploited legitimate Azure DevOps pipelines and identity management tools for persistent access after compromising a user account via self-service password reset.
- Phishing Abuses RMM Tools for Persistent Access Attackers use phishing to deliver masqueraded MSP360 RMM installers, gaining remote access and installing ConnectWise ScreenConnect for persistent control.
- AI and Penetration Testing with Paula Januszkiewicz Paula Januszkiewicz discusses how large language models accelerate vulnerability research, data analysis, penetration testing, and incident response in cybersecurity without replacing human security professionals.
- 362 - Sentinel isn’t just a SIEM anymore Microsoft Sentinel has expanded its capabilities with AI-driven features, an ISOC program for threat hunting, and a transition plan moving the user experience to the Defender portal.
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 CVE-2026-73570 allows unauthenticated OS command injection on Zimbra mail servers via crafted SMTP requests, enabling threat actors to execute shell commands with zimbra service privileges and maintain persistence using JSP webshells and reverse shells.
- What’s new in Microsoft Sentinel: September 2026 In September 2026, Microsoft Sentinel launched Case Management for efficient investigation and collaboration in Defender, along with Unified RBAC custom roles for fine-grained delegated admin privileges to MSSPs.
- Meet the New Microsoft Purview Classifiers Experience: Your Admin Playbook for Public Preview The new Microsoft Purview Classifiers centralize management of all supported classification types, providing admins with real-time visibility into item counts and policy dependencies for safer governance changes.
- Insights from the 2026 Microsoft Digital Defense Report The 2026 Microsoft Digital Defense Report emphasizes that AI is increasingly integrated into threat activities and stresses the importance of treating AI as part of enterprise security through identity management, access control, and comprehensive monitoring.
- Preparing governments for an era of interconnected cyber risk Preparing governments for an era of interconnected cyber risk means focusing on rapid threat response, integrating AI security into infrastructure, planning for incident spread across sectors, and enabling timely public-private information sharing to mitigate hidden, long dwell-time attacks.
- ISOC In Microsoft Defender: Deep Dive And When You Need An ISOC Workspace The ISOC workspace in Microsoft Defender offers centralized threat detection and response, ideal for organizations needing unified security operations with automated playbook execution.
📦 Storage
- Generally Available: Storage with cool access enhancement Azure NetApp Files introduces a GA "cool access" feature that dynamically adjusts throughput as data moves between hot and cool tiers, enhancing performance while reducing costs in hybrid workloads.
- Generally Available: Support for large volume breakthrough mode Azure NetApp Files now provides general availability support for large volume breakthrough mode handling up to 2 petabytes with up to 80 Gbps throughput for HPC and EDA workloads.
- Public Preview: Microsoft entra kerberos authentication for Azure NetApp Files Azure NetApp Files gains public preview support for Microsoft Entra Kerberos authentication, allowing hybrid and cloud-only users to securely access SMB volumes via cloud-issued Kerberos tickets.
- More EDA Job Sets per Volume: Azure NetApp Files Raises the Performance Bar Azure NetApp Files launched a large volume breakthrough mode achieving 38,776 MB/s throughput, 2.4 million ops per second, and sub-millisecond latency, doubling previous single-volume EDA performance.
- Azure capacity constraints in Europe: Microsoft puts dates and prices on the problem Microsoft plans to retire Dv3/Dsv3 VMs on November 15, 2029 and raise prices by 25% on February 1, 2027 for v1/v2 series with regional increases up to 17% in North Europe due to supply constraints.
💻 Virtual Desktop Infrastructure
- Now generally available: Regional resiliency for Azure Virtual Desktop Azure Virtual Desktop introduces regional host pools in East US 2 and Central US to boost resiliency and meet data sovereignty requirements.
- What’s new in Windows 365: September 2026 recap Windows 365 adds TWAIN scanner redirection, user provisioning for Reserve Cloud PCs, improved RDP connectivity via Multipath and Shortpath, and broader macOS/iOS identity support to enhance enterprise flexibility, security, and resilience.
- Windows news you can use: September 2026 Windows 11 version 26H2 adds enhanced device management tools with a new security baseline, updated admin templates, better backup settings, user-initiated provisioning for Windows 365 Reserve, and finer control over Windows Autopatch updates.