|  |  |  |  |  | 

Azure IaaS and Azure Local: announcements and updates (August 2026 – Weeks: 33 and 34)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms

Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms, marking the third consecutive year in which Microsoft has been positioned as a Leader in this report. Microsoft views this recognition as reflecting the growing role of cloud-native application platforms as the foundation not only for modern application development, but also for enterprise AI transformation. According to Microsoft, the key challenge for organizations is no longer generating AI ideas, but turning them into production systems that integrate with existing applications and data, operate reliably at global scale, and meet established security and governance requirements.

Microsoft’s cloud-native application platform brings together application modernization, AI innovation, operations, and security across a common Azure foundation. Azure App Service provides a managed platform for enterprise web applications and modernization, Azure Container Apps supports cloud-native applications, APIs, AI inference workloads, and agents without requiring teams to manage infrastructure, and Azure Functions provides event-driven execution and integration. Azure API Management adds a consistent policy and governance layer for APIs, models, and agent tools. Combined with Microsoft Foundry, GitHub Copilot, and shared Azure capabilities for identity, networking, observability, and security, these services provide organizations with an integrated platform for both existing applications and new AI-driven workloads.

Azure Copilot introduces direct access to agents

Starting in August 2026, Azure Copilot enables users to interact directly with specialized agents from the Azure Copilot chat experience, helping them move more quickly from questions to operational actions. Users can select the agent that best matches their objective, while Azure Copilot agents are enabled by default for users who already have access to Azure Copilot. Global administrators retain granular governance through the Azure Copilot Admin Center, where individual agents can be enabled or disabled. At launch, four agents can be invoked directly: Troubleshooting, Deployment, Optimization, and Resiliency, providing focused assistance across common Azure operational scenarios.

What-If for Azure Deployment Stacks

What-If for Azure Deployment Stacks is now Generally Available (GA) in all Azure regions, allowing customers to preview the impact of stack changes before deployment. Unlike the existing what-if capability for standard ARM or Bicep deployments, this feature is specifically designed for the Deployment Stacks resource type and shows not only which resources will be created, modified, or deleted, but also changes to the stack itself—such as deny settings—and changes to resources managed by the stack, including resources that would be detached or removed.

The capability also reduces false positives by filtering out noisy property changes using a baseline captured when the stack was originally deployed. In addition, each evaluation produces a persistent Stacks What-If Resource that can be named, stored, and retrieved later, rather than transient output that disappears from a terminal or pipeline log. This makes the feature particularly useful in CI/CD workflows, where teams can run a what-if evaluation during a pull request, review the predicted impact alongside the infrastructure-as-code changes, and gate deployment on approval. Because the same stored evaluation can be retrieved later, reviewers can validate exactly the change set that was originally assessed without rerunning the analysis and potentially getting different results due to environmental drift.

Compute

VM vCore Customization with SMT/HT control and configurable constrained cores

VM vCore Customization for Azure Virtual Machines is now Generally Available (GA), introducing support for disabling Simultaneous Multi-Threading/Hyper-Threading (SMT/HT) and configuring constrained core counts. Customers can disable SMT/HT on supported VMs to provide workloads with exclusive access to physical cores, helping improve latency consistency and performance, or select from supported vCPU counts without changing the VM’s memory, storage, or network bandwidth characteristics. By decoupling active core count from VM size, organizations can deploy larger-memory or higher-bandwidth virtual machines while activating only the vCores required by the workload. This is particularly relevant for software such as SQL Server, Oracle, and SAP, where licensing costs may depend on core count. VM vCore Customization is available across all Azure public regions, supports Virtual Machine Scale Sets (VMSS) Uniform orchestration mode, and can be configured through the Azure portal, ARM templates, Azure CLI, and PowerShell. Support currently applies to first-party Azure operating system images, while Marketplace images that include third-party licensing are excluded.

Retirement: Azure VMware Solution license-included service on August 30, 2027

Microsoft has announced that the Azure VMware Solution (AVS) license-included service will be retired on August 30, 2027, following Broadcom’s licensing policy changes requiring customers on hyperscaler platforms to use portable VMware Cloud Foundation (VCF) licenses. Customers currently using license-included Reserved Instance SKUs must acquire portable Broadcom VCF licenses and transition to an AVS VCF Bring Your Own License (BYOL) SKU, or migrate away from Azure VMware Solution, before the retirement date. Environments that have not completed the transition by August 30, 2027, risk service disruption beginning August 31, 2027. Microsoft recommends that customers begin evaluating their current AVS environments, licensing requirements, and modernization options early enough to establish a transition or migration roadmap.

Networking

Summarized advertised gateway prefixes for route advertisement

Summarized advertised gateway prefixes for route advertisement are now Generally Available (GA) for both ExpressRoute Gateway and VPN Gateway, supporting IPv4 and IPv6 address spaces. This capability allows customers to advertise aggregated prefixes to on-premises networks instead of propagating every individual virtual network or spoke address space. In large hub-and-spoke environments, route summarization can significantly reduce the number of advertised prefixes—for example, advertising a covering prefix such as 10.0.0.0/16 instead of hundreds of individual spoke routes—helping deployments remain within gateway route limits as the environment grows. Address spaces that fall outside the configured summarized prefix continue to be advertised individually, preserving existing connectivity when the feature is enabled.

Azure DNS Traffic Manager linked records (preview)

Azure DNS Traffic Manager linked records are now available in Public Preview, enabling customers to directly associate Azure Public DNS record sets with Azure Traffic Manager profiles without using an intermediate CNAME record pointing to the trafficmanager.net domain. With this capability, Azure DNS resolves Traffic Manager routing decisions internally and returns the selected endpoint information directly to DNS clients, simplifying the resolution path and eliminating an additional DNS lookup. Customers can continue to use Traffic Manager’s existing DNS-based load balancing capabilities, including routing methods, endpoint health monitoring, and automatic failover, while benefiting from a more integrated DNS experience across Azure, hybrid, and multi-cloud application environments.

Azure Front Door mutual TLS (preview)

Azure Front Door now supports mutual TLS (mTLS), also known as client certificate authentication, in Public Preview. This capability enables Azure Front Door to authenticate clients using X.509 certificates before requests reach the application origin, strengthening access controls for sensitive applications and APIs across scenarios such as business-to-business integrations, Internet of Things (IoT), financial services, VPN-related applications, and enterprise networks. Customers can choose among four validation modes: Require and validate, where a certificate is mandatory and validated at the edge; Require without validation, where the certificate is mandatory but validation is delegated to the origin; Validate when presented, where certificates are optional but validated when supplied; and Pass through to the origin, where certificates are forwarded without validation. Azure Front Door supports certificates issued by both public and private Certificate Authorities (CAs), with trusted CA chains stored in Azure Key Vault and associated with Front Door custom domains. 

IDPS performance optimization in Azure Firewall

Azure Firewall Premium now provides significantly higher performance for workloads using Intrusion Detection and Prevention System (IDPS) and TLS inspection. The service can now deliver up to 22 Gbps of throughput with TLS inspection and IDPS in Deny mode, representing a 120% increase compared with the previous 10 Gbps limit. Per-connection performance has also doubled, with Azure Firewall Premium supporting up to 600 Mbps per TCP connection when IDPS is enabled in either Alert or Deny mode, compared with the previous 300 Mbps. These improvements allow customers to apply advanced threat inspection and encrypted traffic analysis to higher-throughput workloads while reducing the performance trade-offs traditionally associated with deep packet inspection.

IPv6 support in Azure Firewall (preview)

Azure Firewall now supports IPv6 in Public Preview, enabling Azure Firewall and Firewall Policy to operate in dual-stack IPv4 and IPv6 configurations. This preview introduces native IPv6 network-rule filtering and DNS Proxy support, allowing organizations to secure IPv6 traffic using Azure Firewall as they transition toward dual-stack network architectures. The capability is designed to support cloud, hybrid, and internal IPv6 communication scenarios while extending existing Azure Firewall security controls to IPv6 workloads.

Storage

Live Resize for shared Premium SSD v2 and Ultra data disks

Live Resize for shared Azure Premium SSD v2 and Ultra data disks is now Generally Available (GA). This capability allows customers to dynamically increase disk capacity without disrupting running applications, eliminating the need for downtime when storage requirements grow. Organizations can therefore start with smaller disk sizes and expand capacity over time as demand increases, helping optimize storage costs while maintaining application availability. The feature is particularly useful for shared-disk scenarios and workloads that require continuous access to high-performance block storage while scaling capacity dynamically.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Articoli simili