Azure IaaS and Azure Local: announcements and updates (June 2025 – Weeks: 25 and 26)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Microsoft announces comprehensive sovereign solutions for European organizations (preview)

Microsoft has introduced a broad expansion of its sovereign cloud offerings with the goal of empowering European organizations with enhanced data privacy, operational autonomy, and digital resilience. Building on its longstanding presence in Europe, the new Microsoft Sovereign Cloud initiative spans public cloud, private cloud infrastructure, and national partner environments. Among the new capabilities announced are Data Guardian, which ensures only European personnel oversee remote system access; External Key Management, allowing customers to control encryption with their own HSMs; and Regulated Environment Management, a centralized portal for configuring and monitoring sovereign workloads.

The Sovereign Public Cloud—an evolution of the Microsoft Cloud for Sovereignty—supports Microsoft Azure, Microsoft 365, Security, and Power Platform services across all European datacenter regions, guaranteeing data stays within the EU and is operated under European law by local staff. Additionally, Sovereign Private Cloud (preview), powered by Azure Local and the newly announced Microsoft 365 Local, enables deployment of productivity and cloud services in customer-controlled environments, supporting high levels of compliance and business continuity.

Microsoft is also expanding support for National Partner Clouds through collaborations such as Bleu in France and Delos Cloud in Germany, offering independently operated sovereign environments. These initiatives aim to deliver the most comprehensive sovereignty solutions in the industry, allowing European customers to operate confidently and in full compliance with evolving regulations—without sacrificing access to innovation or requiring data migration.

Microsoft Azure now available from new cloud region in Chile

Microsoft has announced the general availability of its first cloud region in Chile, further expanding its global infrastructure footprint. The new Chile Central region offers Azure Availability Zones and provides scalable, highly available, and resilient cloud services to customers across Latin America and beyond. This launch reinforces Microsoft’s commitment to accelerating digital transformation and innovation in Chile, while ensuring high standards of security, privacy, and regulatory compliance for data residency. Organizations in the region can now benefit from low-latency access to trusted Microsoft Cloud services hosted within the country.

Compute

Azure FXv2-series Virtual Machines

Microsoft has announced the General Availability of Azure FXv2-series Virtual Machines (VMs), powered by the 5th Generation Intel® Xeon® Platinum 8573C processor. These VMs deliver substantial enhancements in CPU performance, memory capacity, and storage throughput, making them ideal for compute-intensive workloads such as databases and data analytics. The FXv2-series VMs provide up to 50% better CPU performance compared to the previous generation, with sizes supporting up to 96 vCPUs and 1,832 GiB of memory. NVMe support ensures high-performance remote storage, with up to 400K IOPS and 11.25 GBps throughput. Designed for high-demand scenarios, such as SQL Server and electronic design automation (EDA), the FXv2-series offers enhanced memory configurations and improved I/O bandwidth.

Networking

Azure WAF integration in Microsoft Security Copilot

The integration of Azure Web Application Firewall (WAF) with Microsoft Copilot for Security has reached general availability. This integration spans both Azure Front Door WAF and Azure Application Gateway WAF, enabling organizations to enhance their threat detection and response capabilities through AI-powered insights. The solution provides automated analysis of SQL Injection (SQLi) and Cross-Site Scripting (XSS) attacks, delivering summaries and justifications for WAF actions. It also includes advanced diagnostics such as tracking attack trends, identifying top offending IPs, and analyzing frequently triggered WAF rules. These features help security teams streamline investigations and proactively adjust their defenses based on real-time intelligence.

Azure Virtual Network Manager IP address management

The IP address management capability in Azure Virtual Network Manager is now generally available, offering centralized tools to enhance IP planning and allocation across complex network environments. This feature allows automatic assignment of non-overlapping IP addresses, supports IP reservations for specific workloads, and prevents conflicts across Azure, on-premises, and multi-cloud environments. Integrated with Azure Policy, it also enforces network creation using designated IP pools, ensuring consistency and compliance. The feature provides clear visibility into IP usage across network resources, helping organizations maintain efficient and conflict-free IP address spaces.

Draft & Deploy on Azure Firewall (preview)

The new Draft & Deploy feature for Azure Firewall Policy introduces a more efficient, two-phase approach to managing firewall configurations, now available in public preview. Previously, any change to a policy would initiate a full deployment of both the policy and associated firewall, resulting in delays of 2–4 minutes per update. With this feature, users can create a draft version cloned from the current policy, allowing collaborative edits without impacting the live environment. Once all changes are finalized, the updated policy can be deployed in a single operation, streamlining the update process and reducing operational disruption.

Azure Front Door supports managed certificate for wildcard domains (preview)

Azure Front Door Standard and Premium profiles now support managed certificates for wildcard domains, a feature previously limited to Bring Your Own Certificate (BYOC) configurations. This enhancement allows customers to secure multiple subdomains using a single managed certificate, which is especially beneficial for SaaS providers and organizations operating large-scale, multi-tenant applications. The new capability simplifies operations by eliminating the need to manage certificates per subdomain, improves scalability by reducing configuration overhead, and enhances security through automated certificate renewals.

Storage

Transition existing platform-managed keys to customer-managed keys for Azure NetApp Files volumes

Customers can now seamlessly transition Azure NetApp Files volumes from platform-managed keys (PMK) to customer-managed keys (CMK), without requiring data migration. This capability is now generally available across all Azure NetApp Files supported regions. Using CMK provides enhanced security and control, allowing organizations to manage their own encryption key lifecycle, including renewals and rotations. It also aligns with stringent regulatory and compliance requirements typical in industries such as finance, healthcare, and government. Importantly, there is no performance impact when using CMK, as the feature simply secures the account encryption key with Azure Key Vault, offering protection against unauthorized access and insider threats.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Please follow and like us: