This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.
Azure
Networking
IPv6 support for Azure VPN Gateway
Azure VPN Gateway now supports IPv6 inner traffic across VPN tunnels in dual-stack configurations, enabling customers to carry both IPv4 and IPv6 workloads through the same gateway. IPv6 is supported on all production gateway SKUs that use Standard public IP addresses and can be enabled for both new and existing VPN Gateway deployments. In Site-to-Site scenarios, branch offices and on-premises networks can connect to Azure through IPsec/IKE tunnels while carrying IPv6 traffic inside the tunnel. Point-to-Site VPN deployments can also support IPv6 client address pools and routed IPv6 traffic, allowing remote users to connect securely to dual-stack Azure environments.
Azure Front Door edge actions (preview)
Azure Front Door edge actions are now available in Public Preview, introducing serverless compute capabilities directly at the Azure edge. This feature allows customers to execute lightweight JavaScript functions during Azure Front Door request processing, enabling real-time decisions closer to end users without adding complexity to the origin infrastructure. Common scenarios include A/B testing, canary deployments, header manipulation, request filtering, dynamic origin selection, URL rewrites, and authentication at the edge. Edge actions integrate with existing Azure Front Door capabilities such as the rules engine, caching, routing, and Web Application Firewall (WAF), allowing organizations to combine application delivery, security, and custom processing within a single edge platform. The capability is built on Hyperlight, Microsoft’s secure micro-VM technology, which provides hardware-backed isolation for customer code execution.
Azure DDoS Protection custom policy (preview)
Azure DDoS Protection custom policy is now available in Public Preview, providing per-resource control over mitigation thresholds for protected Standard Load Balancer frontend IP configurations. Customers can define fixed inbound detection thresholds for TCP, UDP, and TCP SYN traffic, with supported values ranging from 50,000 to 2,000,000 packets per second. This capability is designed for workloads with predictable but unusual traffic patterns, including product launches, seasonal demand, gaming events, and sustained high-volume applications. When a custom threshold is configured for a protocol, Azure uses that value instead of adaptive auto-tuning, while protocols without custom settings continue to use Azure DDoS Protection’s adaptive detection model. During the preview, custom policies can be created and managed through the Azure portal, Azure CLI, Azure Resource Manager templates, and REST APIs. Support is currently limited to inbound traffic for Standard Load Balancer frontend IP configurations and to selected Azure regions.
Standard service endpoint (preview)
The Standard service endpoint is now available in Public Preview, introducing a more scalable and secure approach for connecting Infrastructure as a Service (IaaS) workloads to Azure Platform as a Service (PaaS) resources within the broader Azure Private Link family. The capability addresses the scale and management limitations of traditional service endpoints by integrating with Network Security Perimeter and using public IP addresses or prefixes as network identifiers. Customers can associate a single public IP address or prefix with multiple subnets or virtual networks across subscriptions in the same Microsoft Entra tenant and Azure region. When combined with Network Security Perimeter, organizations can define controlled boundaries around supported services—including Azure Storage, Azure SQL, Azure Cosmos DB, and Azure Key Vault—and restrict access to approved networks and workloads. Microsoft states that the capability has already been validated at large scale, including use across more than 42,000 virtual networks supporting Microsoft first-party services.
Storage
Azure Local
Azure Local expands SAN capabilities with iSCSI support
Microsoft has expanded Azure Local external storage capabilities by introducing support for iSCSI SAN connectivity, complementing the existing generally available Fibre Channel (FC) integration. This enhancement extends Azure Local’s disaggregated architecture model to IP-based storage networks, allowing organizations to reuse existing SAN investments, deploy more cost-efficient architectures without requiring Fibre Channel infrastructure, and scale compute and storage independently while retaining an Azure-consistent management experience.
Azure Local supports iSCSI in both hybrid deployments, where external SAN volumes coexist with Storage Spaces Direct (S2D), and fully disaggregated SAN-only deployments, where external storage is used for both infrastructure and workload volumes. The current architecture uses six-adapter configurations to provide dedicated, redundant iSCSI paths and balance performance, resiliency, and cost. At this stage, iSCSI configuration follows a manual workflow during deployment, with Microsoft planning to integrate node configuration more directly into the Azure Local deployment experience.
The expanded SAN architecture also supports larger-scale connected and disconnected deployments, independent compute and storage growth, and local availability zones that align virtual machine placement with physical infrastructure boundaries. Azure Local validates connected SAN arrays against the supported storage vendor ecosystem, helping customers deploy fully supported configurations. In addition, Azure Migrate can now migrate workloads to Azure Local environments that use external SAN storage, including NTFS-based volumes, enabling organizations to modernize compute platforms while preserving existing storage architectures and operational processes.
Microsoft is also investing in broader lifecycle capabilities for SAN-backed Azure Local environments, including simplified Day-N storage management, replication monitoring, and Business Continuity and Disaster Recovery features such as replication, failover, and failback between SAN-attached or disaggregated Azure Local clusters. With support for both Fibre Channel and iSCSI, Azure Local provides a more complete enterprise storage strategy for organizations modernizing infrastructure from edge locations to sovereign-scale datacenters.
Conclusion
Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.