Azure IaaS and Azure Local: announcements and updates (September 2026 – Weeks: 35 and 36)
This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.
Azure
General
Azure VM Image Builder in sovereign and air-gapped clouds
Azure VM Image Builder is now Generally Available (GA) in Azure Government, China North 3, Azure Government Secret, and Azure Government Top Secret, extending the managed image-building experience to sovereign and air-gapped cloud environments. Customers can use the same service model adopted in global Azure to automate image customization without deploying or maintaining self-hosted build infrastructure. This enables consistent image pipelines across Azure commercial and sovereign clouds, with reusable templates and workflows for operating system hardening, security baselines, validation, and compliance checks. Build outputs can also be published to Azure Compute Gallery and replicated across regions within the same cloud, helping organizations standardize golden images while maintaining strict residency, sovereignty, and isolation requirements.
Azure SRE Agent 30-day trial
A 30-day trial for Azure SRE Agent is now Generally Available (GA) for new customers, allowing teams to explore the service without baseline always-on charges. During the trial, customers can create SRE Agents, connect them to operational tools and data sources, and pay only for Azure Agent Units (AAUs) consumed when agents perform work. Typical scenarios include root-cause investigation across alerts, logs, metrics, traces, Azure resource state, code, and recent deployments; automated alert response from platforms such as Azure Monitor, Datadog, Dynatrace, or PagerDuty; proactive checks for configuration drift, certificate expiration, costs, and compliance; and integration with systems such as GitHub, ServiceNow, Jira, or Azure DevOps to capture evidence, remediation actions, and follow-up work.
Purchase order mapping in Microsoft Marketplace
Purchase order mapping is now available in Microsoft Marketplace, helping organizations align Marketplace purchases with internal accounting and cost-allocation requirements. Customers can associate Microsoft invoice and Marketplace spending with purchase orders, obtain supplemental invoice views organized by purchase order, and remap spend for up to three months after invoicing. This capability provides finance and cloud management teams with greater flexibility when reconciling cloud, software, and Artificial Intelligence (AI) spending across business units and accounting structures.
Compute
Confidential VMs for Azure Linux on AKS
Confidential Virtual Machines (CVMs) for Azure Linux on Azure Kubernetes Service (AKS) are now Generally Available (GA), enabling customers to create AKS node pools designed for highly sensitive container workloads without requiring application code refactoring. New node pools can use supported confidential VM sizes together with Azure Linux 3, using a customized Azure Linux image specifically configured for confidential computing. This allows organizations to combine hardware-backed confidentiality protections with the operational capabilities of AKS, helping migrate sensitive containerized workloads while maintaining the Kubernetes management and orchestration model already used across Azure.
Azure 248 and 372 vCPU sizes for D/E v7 series Virtual Machines
Azure has announced the General Availability (GA) of new 248 and 372 vCPU sizes for the Dlsv7, Dsv7, and Esv7 VM families powered by Intel® Xeon® 6 processors. These larger general-purpose and memory-optimized virtual machines extend the v7 series to up to 372 vCPUs and 2.8 TiB of memory, enabling larger in-memory databases, agentic AI workloads with broader context requirements, and applications that benefit from reduced cross-node communication. Microsoft reports up to 20% better compute performance than prior-generation Intel-based v6 VMs. With the latest Azure Boost capabilities, the largest configurations can deliver up to 400 Gbps of network bandwidth, up to 800k IOPS and 20 GBps of remote storage throughput with Premium SSD v2 and Ultra Disk, and up to 9.6 million IOPS and 53 GBps of local NVMe temporary storage performance on supported Ddsv7 and Edsv7 sizes. These VM sizes are now generally available in Central US, East US, East US 2, Germany West Central, South Central US, Sweden Central, West US 2, and West US 3.
Per-disk resiliency for Azure VMs (preview)
Per-disk resiliency for Azure Virtual Machines is now available in Public Preview in selected Azure regions, providing an alternative recovery model for applications that can tolerate the temporary loss of an individual data disk. By default, Azure continues to recover a VM that loses access to an attached managed disk for an extended period by shutting down the VM and restarting it once disk connectivity is restored. With per-disk resiliency enabled, however, Azure can take only the affected data disk offline while allowing the VM and its remaining disks to continue running. When connectivity is restored, Azure automatically reattaches the disk and brings it back online.
The feature is configured on a per-disk basis and is designed for workloads where a single data disk is not a single point of failure, including VMs with auxiliary or backup disks, clustered or shared-disk applications with their own high-availability mechanisms, and containerized workloads where individual persistent volumes can recover independently. While a disk is offline, I/O requests to that disk return errors, so applications must be capable of continuing operation without it. OS disks are not covered by this behavior and continue to use the standard VM shutdown and recovery model.
Networking
Azure Multicloud Interconnect (preview)
Azure Multicloud Interconnect is now available in Public Preview, providing a managed service for private connectivity between Azure and supported cloud providers, with Amazon Web Services (AWS) as the first supported provider in preview. The service is designed to simplify cloud-to-cloud connectivity for organizations running applications, data platforms, AI services, and business-critical workloads across multiple clouds, reducing the operational complexity traditionally associated with building and maintaining private multicloud network connections.
Customers can create a multicloud connection directly from the Azure portal by selecting the cloud provider, region, and required bandwidth and completing a guided onboarding experience. Once provisioned, Azure virtual networks and supported cloud-provider virtual networks can communicate through a private cloud-to-cloud connection. The service provides managed private connectivity, simplified deployment, and built-in resiliency intended for mission-critical workloads, giving organizations a more Azure-native way to build and operate high-performance multicloud network architectures.
Azure Bastion shareable link expiration
Azure Bastion shareable link expiration is now Generally Available (GA), allowing administrators to define a specific expiration date and time when creating a shareable link. After the configured expiration time, the link can no longer be used to connect to the target resource. This capability helps organizations reduce the risk of persistent temporary access and provides more precise control over time-limited connectivity through Azure Bastion.
IPv6 dual-stack support for Azure Bastion (preview)
Azure Bastion now supports IPv4 and IPv6 dual-stack configurations in Public Preview. Customers can configure newly created Bastion deployments with both IPv4 and IPv6 public IP addresses, enabling IPv6 connectivity between the user and Azure Bastion. Connections from Azure Bastion to target virtual machines continue to use IPv4. Existing IPv4-only Bastion deployments cannot currently be converted to dual-stack mode, so the capability must be configured during the creation of a new deployment.
Connect to AKS clusters using Azure Bastion
Azure Bastion integration with Azure Kubernetes Service (AKS) is now Generally Available (GA), enabling customers to establish a secure tunnel from a local machine through Azure Bastion to an AKS cluster API server. This allows administrators and developers to use standard Kubernetes tools while keeping private cluster endpoints off the public internet. The integration reduces the need to deploy and maintain separate jump boxes, VPN servers, or additional access agents, simplifying secure administrative access to private AKS environments.
Azure SRE Agent VNet Integration
Azure SRE Agent VNet Integration is now Generally Available (GA), enabling Azure SRE Agent to operate within existing customer network boundaries and security controls. With VNet integration, the agent can access private resources, including services behind private endpoints, while respecting controls such as Network Security Groups (NSGs), private DNS, and firewall policies. This allows organizations to use Azure SRE Agent for incident investigation and remediation in security-sensitive environments without requiring changes to the existing network boundary, helping preserve established compliance, segmentation, and access-control models.
Azure Virtual Network Manager IPAM expands to additional Azure regions
Azure Virtual Network Manager IP Address Management (IPAM) is now Generally Available (GA) in additional sovereign regions, including US Gov Virginia, US Gov Texas, US Gov Arizona, China North 3, and China East 3. IPAM centralizes address-space planning and allocation, helping organizations automatically assign non-overlapping IP ranges and prevent conflicts across Azure, on-premises, and multi-cloud environments. Integration with Azure Policy can enforce the use of designated address pools for virtual networks, while cross-region pool associations allow customers to plan and govern address spaces globally across multiple Azure regions.
Azure Firewall auto-learn SNAT routes
Azure Firewall auto-learn SNAT routes is now Generally Available (GA), simplifying Source Network Address Translation (SNAT) configuration by automatically learning registered and private destination prefixes and applying them as No-SNAT ranges. Azure Firewall periodically refreshes these routes, helping preserve original source IP addresses for traffic destined to private networks without requiring administrators to manually maintain SNAT exclusion lists. This capability reduces configuration overhead and helps keep SNAT behavior aligned as hybrid and private network environments evolve.
Azure Front Door profile and route level WAF policies (preview)
Azure Front Door Web Application Firewall (WAF) now supports profile-level and route-level policy associations in Public Preview, providing more granular control over how WAF protections are applied across applications. Customers can associate policies at the profile, domain, or route level, allowing a common baseline policy to protect an entire Front Door profile while more targeted policies are applied to sensitive applications or paths such as authentication, checkout, or API routes. When multiple scopes match the same request, Azure Front Door applies the most specific policy: route-level policies take precedence over domain-level policies, which in turn take precedence over profile-level policies. This model helps reduce policy duplication while preserving application-specific security controls.
Azure Local
Azure Local: Features and improvements in 2608
Microsoft has released the August 2026 update for hyperconverged deployments of Azure Local, identified as version 12.2608.1003.8. The release includes general reliability improvements and bug fixes, together with enhancements across VM operations, centralized management, cluster scale-out, update workflows, and GPU management. In the 2608 release, all new and existing Azure Local deployments run OS version 26100.33296, and customers must use drivers compatible with this OS version or Windows Server 2025. The build also updates the runtime stack to .NET 8.0.30 and .NET 10.0.11 for both .NET Runtime and ASP.NET Core.
For Azure Local VMs, the Azure portal now distinguishes between Shut down (recommended) and Turn off operations. The first gracefully shuts down the guest operating system before powering off the VM, while the second immediately powers it off. This experience requires Azure Local version 2604 or later. In addition, Azure Arc Site Manager support is now available in Public Preview, providing a centralized experience to view and manage Azure Local VMs across multiple sites, with support for Kubernetes clusters as well.
Cluster lifecycle management is also improved with a new Add node via Azure portal capability in Public Preview. Administrators can now scale out an existing Azure Local cluster through a guided portal-based workflow, reducing the operational complexity associated with adding nodes. The update process also introduces a new prepare updates workflow, allowing administrators to stage updates in advance and install them later. Feature updates can now also enter a new Pending OEM Validation state, clearly indicating when an update is waiting for validation from the hardware vendor before proceeding.
A major addition in this release is GPU Management from Azure, now available in Public Preview. This capability enables centralized management and monitoring of GPU resources across Azure Local environments directly from Azure, including GPU inventory visibility, partition configuration, assignment of GPUs to workloads, and lifecycle management of GPU-accelerated workloads. This strengthens Azure Local’s role as a platform for distributed and sovereign AI infrastructure by bringing GPU resource governance and operational control into the same Azure-based management experience used for the rest of the platform.
New Azure Local host service fee tiers
Microsoft has introduced a new tiered host service fee model for Azure Local, with pricing now determined by the deployment architecture. Tier 1 applies to traditional hyperconverged deployments using Storage Spaces Direct (S2D) and remains priced at $10 per active physical core/month; for eligible customers, this fee can continue to be waived through Azure Hybrid Benefit (AHB). Tier 2 applies to disaggregated deployments and to hyperconverged configurations that use external SAN storage, with a host service fee of $20.10 per active physical core/month and no Azure Hybrid Benefit waiver. Tier 3 covers Azure Local deployments operating in disconnected mode with a locally hosted control plane, for which pricing is provided through Microsoft or its partners.
This change makes the underlying storage architecture a direct factor in the Azure Local cost model. In particular, attaching external SAN storage or adopting a disaggregated architecture moves the deployment into the higher-priced tier and removes the Azure Hybrid Benefit host-fee waiver. As a result, customers evaluating SAN reuse or disaggregated Azure Local architectures should include the host service fee, alongside storage infrastructure and licensing costs, in their Total Cost of Ownership (TCO) analysis before finalizing the design.
Cisco to discontinue Azure Local solution sales
Cisco has announced that it will stop selling its Azure Local solution bundles on October 24, 2026, following an announcement made on July 24, 2026. According to the announcement, no direct replacement Azure Local offering is currently planned, and Cisco linked the decision to changes in Azure Local hardware requirements introduced earlier in the year.
Organizations currently running Azure Local on Cisco UCS infrastructure should therefore review their hardware lifecycle and support strategy with Cisco and their Microsoft account teams. Existing environments are not necessarily affected immediately, but the end of new solution sales can influence future cluster expansions, hardware refreshes, and long-term platform standardization. Customers planning new Azure Local investments or refresh cycles should take this change into account when selecting hardware partners and defining their infrastructure roadmap.
Conclusion
Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.