Azure Weekly
Issue 583
11th October 2026
A number of retirements announced this week: Azure Deployment Environments (Feb 2027), App Service Java 8/11/17 (Sep 2027), the AKS pod name metrics dimension (Sep 2027), Always Encrypted with SGX enclaves (Oct 2027), the Key Vault Secrets Provider extension for Arc Kubernetes (Oct 2027), Microsoft Dev Box (Sep 2028) and App Service on Azure Stack Hub (Sep 2029).
Other highlights this week include:
- Introducing Microsoft-Decision-1 in Microsoft Foundry for decision and classification workloads by Saumil Shrivastava - Microsoft-Decision-1 is a specialized decision model for Foundry, optimized for quick choice selection with low latency, ideal for high-volume AI applications needing structured decisions such as intent analysis and data validation.
- BicepFlex - Advanced Formatter for Bicep by Stanislav Zhelyazkov - BicepFlex streamlines Azure Bicep file formatting with Prettier, offering customizable rules to enhance code consistency and readability.
- Closing the AI Agent Governance Gap with Microsoft Foundry by Alexandra Miller-Browne - Closing the AI agent governance gap with Microsoft Foundry introduces four layered controls-resources, builders, behavior, and dependencies-to integrate existing security and compliance policies into an operational model for managing visibility, guardrails, and cost accountability across AI agents.
- 3 lessons from frontier AI vulnerability research by Taesoo Kim - Microsoft FORGE Lab reports that scaling AI vulnerability research requires shifting focus from raw model intelligence to the economics of validation, remediation, and human coordination.
And finally, one from my colleague Mike Evans-Larah:
- Introducing Survive the Sprint: a pixel-art game built (almost) in one shot with Claude Opus 5.5 - Survive the Sprint is a fully playable pixel-art browser survive-the-horde browser game created almost entirely by Claude Opus 5.5. It started as an experiment, and turned into a ridiculously fun and addictive game, featuring endjin-eers as playable characters. I particularly like my "Azure Storm" attack, that my dog Bean features and "PR Comment Tsunami" is my special attack (I'm well known for providing reviews which are often longer than the material I'm reviewing!). You can play it right now in your browser (it works on your phone too).
🤖 AI
- Banking Challenges with AI and Agents Banking institutions like BNY must balance AI autonomy with regulatory control when deploying agent systems using solutions such as runtime hosting, network isolation, and technologies from Microsoft including Copilot Studio, Agent Harness, Foundry model deployments, IQ for grounding, and M365 for distribution.
- Voice agents in Foundry Agent Service: architecture, trust boundaries, and real-audio latency Foundry Agent Service simplifies runtime orchestration, but enterprise teams must still manage identity, networking, and a connection startup time of up to 12 seconds.
- From User inputs to Retrieval optimization: Making Retrieval Smarter with LLMs LLMs improve retrieval accuracy by automatically generating OData filters, boosting relevant documents, and identifying multi-word expressions from natural language queries.
- Your Agents Need More Than a Place to Run Azure provides various methods to build and manage agents, such as the Foundry Agent Service for integrated runtimes, Azure Kubernetes Service for Kubernetes control, and Azure Container Apps for managed containers, catering to diverse workload requirements.
- Sharing a few tips and tricks about AI on Azure, that Claude itself isn’t always aware of! Azure AI Foundry agents require full resource ownership for private link resolution, while FastMCP simplifies Entra ID authentication for MCP servers using proxy-based token acquisition.
- From Business Brief to Production Agent: Building in Three Stages, Not One AI agent development follows a three-stage sequence that prioritizes UI prototyping and local execution to minimize infrastructure costs before committing to production.
- Build Automated Agents, Workflows, and Apps - New in Copilot Studio Copilot Studio allows users to create custom agents with detailed instructions, integrate specialized tools and models, test performance, and build automated workflows for tasks like multi-vendor bid review and approval.
- Introducing Grok 4.7 on Microsoft Foundry Grok 4.7 on Microsoft Foundry provides advanced reasoning and long-horizon problem-solving for software engineering and agentic workflows, achieving high performance in coding benchmarks (71.0% on DeepSWEv1.1) and CAD generation tasks.
- Closing the AI Agent Governance Gap with Microsoft Foundry Closing the AI agent governance gap with Microsoft Foundry introduces four layered controls-resources, builders, behavior, and dependencies-to integrate existing security and compliance policies into an operational model for managing visibility, guardrails, and cost accountability across AI agents.
- Claude Haiku 5.5 is now available in Microsoft Foundry Claude Haiku 5.5 in Microsoft Foundry is 75% cheaper than Haiku 4.5, offering efficient models for high-volume agentic workloads like live customer support and complex subtasks, enabling faster AI applications with built-in effort controls for optimal cost-performance balance.
- Making evaluations cost-efficient Microsoft Foundry's initiatives have reduced token usage by up to 70%, cut output tokens by about 30%, and decreased input tokens by 61-71%, while speeding up evaluations.
- When the Answer Isn’t in the Document: Metadata-Aware Agentic RAG with Foundry IQ Foundry IQ improves RAG by incorporating SharePoint metadata into the search index for better context.
- Are bigger agents better? How to design agents that scale Designing scalable AI agents demands careful management of perception, decision-making, and delegation to tackle issues such as ambiguous tool selection, context overload, complex execution, and governance as their capabilities grow.
- Evaluating Voice Agents: How Reliable Are Foundry's Multi-turn Evaluators? The evaluation shows Foundry’s multi-turn evaluators achieve about an 83% task completion accuracy, with perfect agreement between rankings and benchmark agents for similar performance levels.
- Beyond the Script: Evaluating Voice Agents with Voice User Simulator The voice user simulator from Microsoft Foundry enables developers to test voice agents' responses to diverse speech patterns, acoustic settings, and interactions without requiring extensive human testing or scripted dialogues.
- Introducing Microsoft-Decision-1 in Microsoft Foundry for decision and classification workloads Microsoft-Decision-1 is a specialized decision model for Foundry, optimized for quick choice selection with low latency, ideal for high-volume AI applications needing structured decisions such as intent analysis and data validation.
- Qwen3.8-27B on a $2 H100 Azure Spot VM: does it pay off? Running Qwen3.8-27B on an Azure Spot H100 VM costs about $2 per hour yielding a return of roughly $8.12 per VM hour for 1,434 requests generating $24.35 worth of token output demonstrating significant cost efficiency despite high computational demands.
🔎 Analytics
- Announcing: Table discovery in OneLake Catalog search Table discovery in OneLake Catalog search lets users locate specific tables across semantic models, lakehouses, and mirrored databases with precise name or column-name searches starting October 15, 2026.
- FabCon Europe 2026: News from Barcelona! FabCon Europe 2026 introduced Fabric IQ, a unified semantic model and real-time signal layer enabling AI agents such as Copilot to reason over OneLake data using grounded answers from published models.
- From Real-Time Ingestion to Cold Analytics: Designing for Data Usage Designing data architectures for tyre telemetry requires distinguishing between real-time ingestion and cold analytics based on freshness, access frequency, and response time to optimize storage and processing technologies.
- Announcements from the Microsoft Fabric Community Conference — Barcelona 2026 The conference showcased Fabric's transition to an "AI-first" model with new features like Fabric IQ in Copilot Chat and Cowork, Osmos for agentic data engineering, Modern Report Builder, and Power BI’s Agentic Experiences, indicating a shift from manual pipeline creation to defining outcomes while AI handles implementation.
- Optimizing Oracle-to-Power BI Performance and the Path to Modern Analytics Power BI performance issues with Oracle often stem from small FetchSize settings, which architects can mitigate by benchmarking the built-in provider against the Oracle Client for Microsoft Tools.
🖥️ Compute
- Run Ollama on Windows Server Without Exposing Your LLMs Run Ollama on Windows Server securely by using NSSM to host it as a service, restricting access to loopback only, and protecting it with IIS reverse proxies, TLS encryption, and user authentication.
- AI transformation across the infrastructure lifecycle: From supply chain to fleet operations At Microsoft, AI integrates into every stage of the infrastructure lifecycle from supply chain to fleet operations, adapting continuously as hardware needs change globally within Azure.
🚢 Containers
- Generally Available: Anyscale on Azure Anyscale on Azure provides a managed service for running distributed Python apps via Ray, integrating smoothly with Azure Kubernetes Service for easy deployment and management.
- Generally Available: Managed StandardV2 NAT Gateway for AKS Azure Kubernetes Service (AKS) now offers a generally available Managed StandardV2 NAT Gateway that automatically provisions and manages an enhanced networking resource for clusters using AKS-managed virtual networks, making it the default choice in supported regions for new deployments with the managedNATGateway outbound type.
- Public Preview: AKS on bare metal now on Ubuntu Azure Kubernetes Service on bare metal now on Ubuntu eliminates the need for a virtualization layer, offering more control and potentially lower latency for AI workloads running locally.
- Retirement: Pod name dimension in AKS pod platform metrics Azure will retire the pod name dimension on AKS pod platform metrics starting September 30, 2027, replacing it with aggregated pod counters for phase and total counts.
- Building a Governed Multi-Agent Content Factory on Azure Building a Governed Multi-Agent Content Factory on Azure shows how three specialized A2A agents, Azure Container Apps Sandboxes, and Microsoft Foundry work together to turn a topic into various content formats while ensuring secure, private networking with default-deny policies.
- GitOps with Argo CD extension for AKS is Now Generally Available GitOps with Argo CD on AKS provides secure enterprise-grade authentication, automated security patching, and smooth Azure service integration, streamlining lifecycle management while preserving Argo CD's core features.
- Testing AKS Node Auto Provisioning: When Our Managed Disk Policy Blocked Every New Node During an evaluation of AKS Node Auto Provisioning, a managed disk policy inadvertently blocked all new node creation by rejecting the required managed disks.
- Kubernetes Pending Pods: Fix Scheduling and Resource Limits Kubernetes pending pods often result from misconfigured resource limits, taints, node affinities, storage issues, or namespace quotas; examining FailedScheduling events helps pinpoint and resolve the root cause.
- Anyscale on Azure is now Generally Available Anyscale on Azure provides enterprises with a fully managed Ray distributed runtime in Azure Kubernetes Service, ensuring production-grade AI workflows with data and control plane hosted in customers' Azure subscriptions, backed by SLA-supported service from both Microsoft and Anyscale.
- Multi-NIC Support on AKS powered by DRANET – Now in Public Preview AKS now offers public preview multi-NIC support via DRANET driver, enabling pods to have dedicated network interfaces for isolation and performance without extra components or custom CNI setups.
🗄️ Databases
- Generally Available: SQL Server on Azure Virtual Machines in Azure Bleu SQL Server on Azure Virtual Machines is now generally available in Azure Bleu, allowing French organizations to run compliant workloads in a sovereign cloud environment with minimal latency.
- Generally Available: Azure Database for PostgreSQL flexible server in East US 3 Azure now offers General Availability of its PostgreSQL flexible server in the East US 3 region, expanding geographic access for businesses.
- Public Preview: Azure HorizonDB expands to additional regions Azure HorizonDB’s public preview now includes deployment in multiple new regions, enabling organizations to place PostgreSQL workloads nearer to their apps and customers for reduced latency.
- Retirement: Always Encrypted with Intel SGX Enclaves Always Encrypted with Intel SGX enclaves in Azure SQL Database will end support on October 31, 2027, prompting customers to migrate to Virtualization-Based Security (VBS) enclaves.
- Using Friendly Names for SQL Servers via DNS DNS CNAME records allow database administrators to redirect application traffic to new servers without updating connection strings across the entire codebase.
- SQL Server Network Latency: When the Database Isn’t the Slow Part SQL Server network latency can significantly impact application performance; even small delays-like thirty-two milliseconds of ping-can cause major slowdowns if overlooked in optimization efforts.
- Building a SQL Server Fleet Audit That Leadership Actually Reads The tool uses a YAML inventory, automated connection strings for multiple platforms, standardized diagnostic queries covering encryption, backups, security posture, and compliance, and generates an HTML report with severity classification to give leadership actionable insights into SQL Server fleet health.
- Azure SQL Database is retiring Always Encrypted with Intel SGX enclaves Azure SQL Database will retire Intel SGX enclave support on October 31, 2027, prompting migration to Virtualization-Based Security (VBS) enclaves for continued secure-enclave functionality.
- Learn T-SQL With Erik: Time Zones and Offsets Erik Darling's video series explains T-SQL time zone handling in SQL Server and PostgreSQL using functions like AT TIME ZONE and SWITCHOFFSET, providing best practices for storing and querying temporal data across regions.
- Lessons Learned #556: Finding the SQL Statement Behind a Query Hash in Azure SQL Database Azure SQL Database administrators can map query hashes to specific SQL statements by joining the sys.query_store_query and sys.query_store_query_text catalog views.
- Rethinking Memory Management for Azure HorizonDB on Disaggregated Storage Azure HorizonDB restructures PostgreSQL's memory management by using shared buffers as the main cache, removing double buffering and necessitating remote storage access for page misses, impacting prefetching, sequential scans, and writes.
- Free Database Performance Monitoring – The Web Viewer and Custom Views The free database performance monitoring tool now supports SQL Server, Postgres, and Aurora Postgres, offering a web viewer with enhanced security features and customizable dashboards.
- The SQL Project preplan script - the missing step in DACPAC publishing The SQL Project adds a preplan script feature to run before schema comparison in DACPAC deployments, addressing challenges with adding non-nullable columns or migrating data for destructive changes.
- Text to SQL: The SQL Was Never the Hard Part Text to SQL tools struggle due to multiple table versions and ambiguous term definitions, causing inaccurate results despite flawless SQL generation.
- Azure SQL Data Sync After a Database Restore: Troubleshooting Leftover Sync Metadata Azure SQL Data Sync may retain leftover sync metadata and system schemas post-restore, necessitating validation of the Sync Metadata Database and inspection of the DataSync schema to address synchronization issues.
- What sustained PostgreSQL performance really requires: Lessons from an independent benchmark Azure Database for PostgreSQL outperformed Amazon RDS by 72.7% without high availability and 79.2% with it, showing that compute, storage, and HA collectively influence sustained performance in transaction-intensive workloads.
- The flight recorder: Replaying what an AI agent did on my SQL Server AgentDBA provides detailed logs of every decision an AI agent makes on a SQL Server, enabling DBAs to replay and audit the agent’s actions for transparency and troubleshooting.
- Lessons Learned #557: Investigating an unexpected query slowdown Azure SQL Database query performance regressions often stem from forced plans failing due to missing indexes, which the NO_INDEX flag in Query Store helps identify.
🛠️ Developer tools
- Retirement: Microsoft Dev Box will be retired on September 18, 2028 Beginning on September 14, 2026, users of the now-retiring service must transition to alternative development tools before it becomes unavailable on September 18, 2028.
- A Local Hybrid Retrieval Pattern for Health Records Rust powers this hybrid retrieval pattern, which uses reciprocal rank fusion and local cross-encoder reranking to ensure sensitive health data never leaves the facility.
- Azure AD Graph API retirement: action required for older versions of Azure CLI and Azure PowerShell Azure AD Graph API retires on July 1, 2025; upgrade Azure CLI and PowerShell to latest versions using the supported Microsoft Graph endpoint by October 6, 2026, when legacy access ends.
- Sprint Zero is about building momentum Sprint Zero traditionally focuses on architecture setup but author argues that using modern tools and Agentic AI to deliver a working feature first builds momentum and reduces wasted preparation time.
- Designing APIs for AI agents: your API has a new user Designing APIs for AI agents involves creating discoverable, understandable, and safe endpoints using ASP.NET Core, implementing enums for fixed values, setting up a database context with proper model configurations, and defining strong Data Transfer Objects (DTOs) to prevent direct exposure of the underlying database schema.
- Introducing Survive the Sprint: a pixel-art game built (almost) in one shot with Claude Opus 5.5 Survive the Sprint is a fully playable pixel-art browser game created almost entirely by Claude Opus 5.5 from endjin employee headshots and bios, featuring unique character abilities inspired by real team members' quirks and roles.
- Stripping extra dependencies in .NET NativeAOT apps using linker substitutions Developers can reduce .NET application binary size and improve performance by removing unnecessary dependencies like ClrMD using linker substitutions with NativeAOT.
- I Built My First VS Code Extension: Meet Rainbow SQL Rainbow SQL is a free VS Code extension that colors columns and values in INSERT statements to aid quick data identification, offers hover tooltips for column info, flags mismatched row counts, and supports various SQL dialects with customizable themes.
- What Would You Build in Azure If You Didn’t Have to Ask for a Budget First? Eligible Visual Studio subscribers receive monthly Azure credits ranging from $50 to $150, enabling hands-on experimentation with cloud services without needing a separate budget.
- Part 4: Wiring MCP Tools to Azure SQL and External APIs This summary explains connecting MCP tools to Azure SQL and external APIs, using EF Core for database management, adding a currency conversion tool via an online API, and implementing irreversible write operations for expense reports.
- MCP and Microsoft Agent Framework MCP standardizes AI model tool invocation via a single API, enabling dynamic calls to published functions, data endpoints, or long-running operations across various transports, simplifying skill management and integration.
- Stack Overflow 2026 Survey: VS Code Leads, Visual Studio Takes Third In the 2026 Stack Overflow survey, Visual Studio placed third behind VS Code, with GitHub Copilot lagging and ASP.NET Core ranking fourth for web technologies.
- Streaming Grounded Chat to Desktop and Mobile Through a Rust Bridge Tauri v2 Rust bridges secure chat applications by isolating credentials and SSE streams from the web view, preventing unauthorized data egress and ensuring consistent state across concurrent sessions.
- JetBrains posts a loss (but revenue is up), puts spotlight on future of IDEs JetBrains reported its first loss due to rising staff and operating expenses as the company pivots toward AI-enhanced IDEs amid developer skepticism about AI's necessity for coding tools.
- Part 5: Hosting an MCP Server in ASP.NET Core with Streamable HTTP ASP.NET Core enables MCP servers to move beyond local stdio constraints, allowing for network-based access, multi-client support, and standard logging without protocol interference.
- EmbeddingGemma 2 Integration EmbeddingGemma 2 Integration provides local text-only embeddings in C# with adjustable settings for sequence length, vector dimensions, and model caching, using an Apache 2.0 licensed multimodal model via ONNX Runtime.
- Azure CLI on macOS got security upgrade: native broker authentication Azure CLI on macOS now supports native broker authentication in preview with version 2.91.0, enabling secure device-bound token management and single sign-on while maintaining control over feature activation.
- Run Deterministic SQL Before Asking a Local LLM to Plan QuerySpec uses a custom grammar and compiler to resolve structured questions into SQL, reserving local LLM inference only for queries that fail deterministic parsing.
- Test Time-Dependent Code Without Waiting Use NETs TimeProvider to inject a FakeTimeProvider in tests, enabling precise control over time for verifying expiry boundaries and delays without waiting, ensuring accurate testing of time-dependent code like invitation expirations.
- Less chat. More decisions: introducing ElBruno.AI.Decisions for .NET ElBruno.AI.Decisions is a .NET SDK transforming AI models into decision-making tools with structured outputs for classification, scoring, and assessment tasks.
- Experimenting with Claude Code Experimental Agent Teams Agent teams in Claude Code allow multiple independent Claude sessions to collaborate through a shared task list and direct messaging, enhancing coordination for complex workflows though at higher token costs than subagents.
🔩 DevOps
- Retirement: Azure Deployment Environments will be retired on February 22, 2027 Azure Deployment Environments will end operations on February 22, 2027, after a six-month transition starting September 14, 2026, so users must move their workloads elsewhere.
- ReviewBench: An open benchmark for AI code review ReviewBench is an open-source benchmark evaluating AI code reviewers on over 100 million GitHub pull requests with metrics like precision, recall, and F1 scores to assist teams in selecting optimal reviewers.
- Exploring GitHub Copilot Code Review for Azure DevOps GitHub Copilot integrates AI assistance into Azure DevOps pull requests for automated code analysis and multi-language commenting with customizable context.
- Building Git infrastructure for agent-scale development GitHub is redesigning its Git infrastructure to manage high commit rates, ultra-high write throughput, and thousands of concurrent reads per push, resolving bottlenecks for agentic development and improving repository scalability.
- BicepFlex - Advanced Formatter for Bicep BicepFlex streamlines Azure Bicep file formatting with Prettier, offering customizable rules to enhance code consistency and readability.
- Secret protection must scale with software GitHub's new classifier quickly blocks unstructured secrets, possibly doubling prevented exposures and reducing manual remediation.
- Cross Operating System Test Probes with GitHub Actions GitHub Actions workflows can run targeted test subsets on demand, allowing AI agents to debug cross-platform failures without requiring local Windows environments.
- New Wiki Editor Experience The new Wiki editor uses Monaco Editor's VS Code features, including Markdown editing with syntax highlighting, native find and replace, enhanced undo/redo, autocomplete for various elements, and persistent preferences like word wrap and synchronized scrolling.
🧬 Hybrid + multicloud
- Retirement: Azure App Service on Azure Stack Hub Azure App Service on Azure Stack Hub will retire on September 30, 2029, meaning existing deployments will lose support for new features after September 30, 2026.
- Retirement: Azure Key Vault Secrets Provider Extension for Azure Arc enabled Kubernetes clusters The Azure Key Vault Secrets Provider Extension for Azure Arc-enabled Kubernetes clusters will retire on October 9, 2027, prompting users to migrate to the newer Azure Key Vault Secret Store Extension.
- Public Preview: Onboard Kubernetes Clusters to Azure Arc with the Multicloud Connector The Azure Arc Multicloud Connector's public preview automatically discovers and onboardes Amazon EKS and Google GKE clusters to Azure, integrating them for unified governance, security, and observability without custom scripts.
🎭 Identity
- Bridge Azure Workload Identity to Client Identity with Dynamic Client Registration Dynamic client registration bridges Azure Workload Identity and client identity, enabling seamless authentication without secrets in config files.
- AI MCP Skills as IAM Policy: Guardrails for Agentic Identity Lifecycle Orchestration (Part 1) The new v0.3.0 release of entra-scim-mcp aligns with recent changes in the Entra ID SCIM Provisioning API, enabling more robust agentic identity lifecycle orchestration through AI MCP skills modeled as IAM policies.
- AI MCP Skills as IAM Policy: Guardrails for Agentic Identity Lifecycle Orchestration (Part 2) Part 2 explains how AI MCP skills can enforce IAM policies to prevent identity lifecycle errors, such as malformed SCIM calls or inconsistent group assignments during account disablement.
🔌 Integration
- Public Preview: Microsoft Agent 365 integration with Azure API Management The preview release lets organizations use Azure API Management to enforce security policies on Microsoft Agent 365 services in real time.
- Update network rules for the API Management service tag Azure will update its API Management service tag to include expanded control-plane IP addresses, requiring users on VNet internal or classic (v1) tiers to adjust their NSGs, UDRs, and firewalls by November 30, 2026.
- 💲Announcing Free Grant and Pricing for Logic Apps Automation Azure Logic Apps now provides monthly free grants for managed environments, workflow runtime, data retention, and usage across AI, connectors, knowledge storage, and code execution.
- Power Automate | Flows Without the Designer The Power Automate plugin for GitHub Copilot CLI and Claude Code facilitates terminal-based creation, editing, running, debugging, and management of cloud flows, integrating with Azure services while maintaining existing licensing and governance policies.
- Automate Expense Report Approvals with Power Automate Power Automate automates expense report approvals by creating a seamless workflow on SharePoint lists, enabling automatic routing, closing loops, and exporting finalized data to finance teams.
- Microsoft Agent 365 and Azure API Management integration for MCP governance The new integration allows AI administrators to set access policies in Agent 365 with enforcement handled by Azure API Management at the runtime gateway.
- From Form to Action: A Governed, Event-Driven AI Intake Pipeline with Azure Integration Services The architecture uses Azure Integration Services and Microsoft Foundry to create a governed, event-driven intake pipeline that handles document-heavy forms with authenticated entry, controlled model consumption, real-time processing, and full audit trails.
💡 Internet of Things
- Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for Global Industrial AIoT Platforms Microsoft is recognized as a Leader in Gartner’s 2026 Magic Quadrant for Global Industrial AIoT Platforms highlighting its focus on intelligent adaptive industrial operations via Azure IoT, Azure Arc, and Fabric.
🎓 Learning and Certifications
- SQL Server 2025 Cheat Sheet: Every Query Tested, Free PDF The SQL Server 2025 cheat sheet includes tested T-SQL queries covering read-only, data-changing, object-modifying, and server-changing operations, with clear labels for each type of query.
- Responsible AI in Azure: The 6 Principles Every AI Solution Needs Responsible AI in Azure encompasses six key principles fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability illustrated through real-world examples of neglecting each.
- Join Us for the Microsoft Agent Bootcamp: Turn AI Potential into Real-World Impact in Miami! Experience hands-on training at the Microsoft Agent Bootcamp in Miami to build intelligent agents for boosting productivity, automating workflows, and driving business impact on the Microsoft platform.
- Meet Microsoft at Oracle AI World 2026 At Oracle AI World 2026, Microsoft will demonstrate how Azure integrates with Oracle data via the new Oracle AI Database@Azure for seamless AI innovation in multicloud settings.
- Recent and upcoming Microsoft exam changes – Wednesday 7 October 2026 Microsoft retires the AZ-800 and AZ-801 Windows Server exams while scheduling an update for the SC-100 Cybersecurity Architect certification.
- Episode 438: Taking your WorkOS and LLM Wiki to the Next Level Episode 438 shows how LLM wikis have transformed into personalized WorkOS solutions integrating tasks, meetings, research, communications, and workflows within Microsoft 365.
- Open-source databases in the AI era: Meet Microsoft at All Things Open At All Things Open 2026, Microsoft will demonstrate how open-source databases are being redesigned for AI applications, cloud scalability, and consistent developer experience with improved performance and reliability.
- CKS Exam 2026: Study Guide, Practice Labs and Five-Week Plan CKS 2026 certification preparation requires mastering Trivy, Falco, and AppArmor through a structured five-week lab-based curriculum.
- Where Community and Code Connect: MVPs at Nebraska.Code 2026 Nebraska.Code 2026 gathered Microsoft MVPs from North America to showcase AI, infrastructure tools, and career balance through technical talks and networking.
- Microsoft at OCP Global Summit 2026 At the OCP Global Summit 2026, Microsoft will unveil its next-generation Cobalt 200 and Maia silicon, advanced cooling solutions, sustainability initiatives, and cutting-edge security technologies to enhance fleet reliability.
- Hack the World: Why hackathons are still the best place to learn to build Hackathons offer a fast-paced setting for diverse participants to quickly develop ideas with AI tools, enhancing skills and careers without prior computer science knowledge.
⚖️ Management and Governance
- How to Find Azure Log Analytics Workspace Keys You can quickly retrieve Azure Log Analytics workspace keys using an Azure CLI command that returns the key without JSON formatting, simplifying access when portal searches are unproductive.
- A closer look at noise reduction in Stacks What-If Noise reduction in Azure Deployment Stacks What-If eliminates false changes reported by what-if, improving trust and reducing manual review time for infrastructure-as-code deployments.
🚌 Migration
- Azure Site Recovery for Azure Local Is Now Generally Available! Azure Site Recovery for Azure Local provides a simplified one-page deployment wizard automating vault creation, agent installation, host registration, and supports Windows Defender Application Control in enforced mode with built-in proxy configuration.
- VMware to Azure: Avoid the Broadcom Per-Core Trap Azure VMware Solution helps organizations bypass Broadcom's per-core licensing costs by migrating workloads to native cloud infrastructure in phased waves.
🌐 Networking
- Generally Available: Exceptions in WAF for Azure Application Gateway and Azure Front Door Azure has made its Web Application Firewall (WAF) exceptions generally available for both Application Gateway and Front Door, allowing more precise control over which traffic bypasses security checks.
- Public Preview: IPv6 Support for Application Gateway WAF Azure’s Application Gateway WAF enters public preview with IPv6 support, enabling comprehensive inspection and security enforcement for next-generation network traffic.
- Proactively monitor Azure VPN Gateway tunnel disconnections Proactively monitoring Azure VPN Gateway tunnel disconnections with Azure Monitor alerts helps organizations quickly detect and address issues from internet outages, device failures, or network maintenance, reducing Mean Time to Detection and ensuring uninterrupted hybrid connectivity.
- Azure VNET Integration Doesn’t Mean Your Resources Are Private Azure Virtual Network integration lacks inherent private isolation requiring extra security measures.
🔐 Security
- Remote Desktop Protocol and PQC TLS 1.3 Hybrid RDP can now use a TLS 1.3 post-quantum hybrid key establishment to protect connections against future quantum attacks, requiring system-wide setting adjustments that may affect other services.
- CISO perspectives on managing vulnerability risks in the age of AI CISOs must balance rapid AI-driven patching with accuracy using tools like Microsoft Baseline Security Mode to ensure resilience against fast cyberattacks from frontier AI models.
- 3 lessons from frontier AI vulnerability research Microsoft FORGE Lab reports that scaling AI vulnerability research requires shifting focus from raw model intelligence to the economics of validation, remediation, and human coordination.
- The Microsoft AI and Agent Platform — Securing and Governing Intelligent Agents Microsoft integrates security and governance across the agent lifecycle by applying control rails to identity, data access, tool usage, and runtime isolation.
- Introducing the Microsoft Sentinel ASIM EmailEvent schema The new Microsoft Sentinel ASIM EmailEvent schema standardizes email delivery, inspection, authentication, and attachment details across products, enabling consistent security analytics.
- Azure Key Vault and BYOK: Lessons Learned Preserving both key material and its versions is essential for successful recovery when using Azure Key Vault’s BYOK feature.
- Enable Agentless VM Scanning in Microsoft Defender for Cloud Enable Agentless VM Scanning in Microsoft Defender for Cloud to gain posture visibility on unmanaged or multicloud virtual machines without deploying agents, using platform-side discovery and analysis while complementing endpoint protection.
- How one bug bounty researcher chooses the features they investigate @vaib25vicky, a top GitHub VIP researcher specializing in authorization and access control, explains how childhood coding curiosity led him to bug bounty, his preference for feature-centric research over class-based hunting, and the role of AI as a productivity tool while stressing personal verification of findings.
- Finding the Elusive MDE PUA Audit Events on Linux Locating audit events for potentially unwanted applications on Linux involves finding log entries marked "potentially_unwanted_application," unlike Windows which shows similar detections easily via the XDR Security portal.
- Why DLP for External Web Search in Microsoft 365 Copilot Matters? The new DLP feature in Microsoft Purview blocks Copilot from performing external web searches when user prompts include sensitive data such as credit card numbers or Social Security numbers, preventing that information from leaving your organization.
- Post-quantum authentication: Why organizations should start testing certificate ecosystems now Post-quantum authentication presents unique challenges impacting certificates, PKI services, devices, and applications, necessitating early testing and preparation.
📦 Storage
- Public Preview: Azure Backup for PostgreSQL flexible server and elastic cluster (v2) Azure Backup for PostgreSQL v2 offers enterprise-level long-term retention with physical backup storage on managed disk snapshots, vaulted in Azure Backup solutions for enhanced data protection.
- Azure Backup for PostgreSQL flexible server and elastic cluster (v2) is now in public preview Azure Backup for PostgreSQL flexible servers and clusters (v2) in preview provides physical snapshot-based backups up to 64 TB with customizable retention from 7 days to 10 years, including an instant "Restore as Server" feature.
- Bulk changing blob tiers using Azure Storage Actions Azure Storage Actions simplifies bulk blob tier changes with a no-code interface, allowing users to configure conditions and operations visually without writing custom scripts or automation runbooks.
💻 Virtual Desktop Infrastructure
- Remote PC connections in Windows App on Windows is now generally available Remote PC connections in the Windows App now let users manage physical and virtual Windows devices without a work or school account, simplifying remote management.
- Windows 365 Local Admin – Cloud PC Configurations vs User Settings + PowerShell (Graph REST API) Windows 365 provides two methods for granting local admin rights via Cloud PC configurations and User settings, each differing in conflict resolution, management priorities, and future support.
🔗 Web
- Retirement: Support for Java 8, 11 and 17 will end on September 1, 2027 On September 1, 2027, support for Java 8, 11, and 17 on Azure App Service will end, leaving running applications without future security updates or assistance.