Azure Hybrid Management & Security: What’s New and Insights from the Field – September 2026
Once again this month, I’m back with my recurring series focused on the evolution of Azure management and security services, with a special focus on hybrid and multicloud scenarios enabled by Azure Arc and enhanced by the use of Artificial Intelligence.
This monthly series aims to:
-
Provide an overview of the most relevant updates released by Microsoft;
-
Share operational tips and field-proven best practices to help architects and IT leaders manage complex and distributed environments more effectively;
-
Follow the evolution towards a centralized, proactive, and AI-driven management model, in line with Microsoft’s vision of AI-powered Management.
The main areas addressed in this series, together with the corresponding tools and services, are described in this article.
Hybrid and multicloud environment management
Azure Arc
Workload Orchestration for Azure Arc now available in the Azure portal
Workload Orchestration for Azure Arc is now available directly in the Azure portal, simplifying the centralized definition, configuration, and deployment of applications across cloud, on-premises, and edge environments.
The capability lets you consistently manage workloads distributed across multiple Azure Arc-enabled Kubernetes clusters, while preserving configurations specific to individual sites or deployment targets. The new onboarding experience in the portal also lets you quickly try out the service by deploying preconfigured applications to clusters already connected to Azure Arc.
Once the model has been validated, the same approach can be extended to production environments by organizing sites into hierarchies and defining shared configurations. This makes it possible to scale from a single cluster to a distributed fleet while maintaining centralized governance, repeatable deployments, and local flexibility.
Certificate Management for Azure Arc-enabled Kubernetes
Microsoft has announced the general availability of Certificate Management for Kubernetes clusters connected through Azure Arc. The new extension automates the management of TLS certificates and trust bundles in distributed Kubernetes environments, with a particular focus on edge scenarios and large-scale deployments.
The extension combines two well-established CNCF projects, cert-manager and trust-manager, into a single Microsoft-managed component that is installed once per cluster. Once enabled, it automates certificate issuance, renewal, and rotation, distributes trusted Certificate Authority certificates to the namespaces that need them, and supports both a built-in self-signed CA, useful for development and test environments, and enterprise issuers for production scenarios.
One of the most significant aspects is the reduction in operational overhead. Certificate management in edge environments can quickly become complex due to expiration dates, differing component versions, vulnerabilities to be patched, and the need to maintain compatibility and supportability over time. By using the managed Azure Arc extension, part of these responsibilities shifts to the Microsoft platform, which provides security updates, maintenance, and enterprise support under standard support agreements.
The solution is also designed for scenarios with intermittent connectivity: certificates and trust bundles remain usable even when the cluster temporarily loses its connection to Azure. This behavior is especially important for industrial, retail, or distributed edge sites that may operate offline for extended periods.
The generally available release also broadens the range of supported platforms and includes ARM64 architectures. The extension has been validated on, among others, AKS Edge Essentials, AKS on Azure Local, Red Hat OpenShift, SUSE Rancher RKE2, VMware Tanzu, and K3s. Installations deployed during the public preview can be retained by simply updating the extension to the latest available version, with no changes to the existing configuration.
AI and intelligent automation
Microsoft Copilot in Azure
Azure Copilot Observability Agent supports Log Analytics Basic and Auxiliary plans
Azure Copilot Observability Agent, the AI-powered component of Azure Monitor dedicated to operations and troubleshooting, now extends its analysis capabilities to data stored in Log Analytics tables configured with the Basic and Auxiliary plans.
This update allows operations teams to move high-volume telemetry to lower-cost log plans without giving up the ability to use that data during interactive analysis and in-depth investigations performed by the agent. Log data can therefore be correlated with metrics, traces, resource topology, and Azure context, providing a more complete view of the environment’s operational conditions.
The benefit is particularly relevant in Kubernetes scenarios, where sources such as ContainerLogV2, AKS audit logs, container stdout and stderr, node syslog, and control plane logs can generate significant volumes. Where compatible with retention and query requirements, using the Basic or Auxiliary plans helps optimize costs while keeping this data available to AI-driven analysis capabilities.
No additional action is required for eligible tables already configured with the Basic or Auxiliary plans. This extension therefore represents an important step toward an observability model in which AI can operate on a broader information base without necessarily requiring the most expensive log tiers for all collected telemetry.
Security posture across hybrid and multicloud infrastructures
Microsoft Defender for Cloud
Microsoft Defender for Cloud extends security posture to Azure Container Apps
Microsoft Defender for Cloud expands its Serverless Containers Posture capabilities to include Azure Container Apps. Security teams can now bring Container Apps environments into the same posture management model used for other containerized workloads, gaining greater visibility from a single point of control.
The capability makes it possible to inventory resources and assess their risks, taking into account aspects such as identity, network configuration, container settings, and image security. This extends Cloud Security Posture Management controls to serverless workloads, where the underlying infrastructure is fully managed by the platform.
The collected information is also used in Defender for Cloud’s attack path analysis, making it possible to correlate misconfigurations, vulnerabilities, privileges, and exposure conditions to identify more quickly the paths that could lead to the compromise of critical resources.
The integration of Azure Container Apps thus strengthens Defender for Cloud’s unified approach to container security, reducing blind spots between Kubernetes and serverless models and simplifying risk assessment in increasingly heterogeneous application environments.
Aggregated vulnerability assessment recommendation for machines deprecated
The recommendation “Machines should have a vulnerability assessment solution” will be deprecated on December 14, 2026, as part of Microsoft Defender for Cloud’s transition from aggregated to individual recommendations.
Organizations will therefore need to use the individual recommendations available in Defender for Cloud to verify and manage vulnerability assessment coverage on their machines. This change provides greater granularity in analyzing security status and managing remediation activities.
Amazon GuardDuty status visibility for S3 buckets
Microsoft Defender for Cloud now displays Amazon GuardDuty coverage status directly on the S3 asset page, within the cloud security details section.
For each bucket, the status of GuardDuty Extended Threat Detection and GuardDuty Malware Protection is shown separately, each marked as Enabled or Disabled. Since the two features are enabled independently in AWS, any coverage gaps can be quickly identified.
This update makes it possible to verify S3 bucket protection directly from the Defender portal, without having to access the AWS console separately.
Defender for Cosmos DB available in Azure Government
Microsoft Defender for Cosmos DB is now also available in Azure Government. The plan thus reaches a level of feature coverage and runtime protection aligned with that of the commercial Azure cloud.
This expansion enables organizations operating in government environments to use the same Cosmos DB protection capabilities already available in commercial environments, improving the consistency of their security posture across different cloud environments.
Governance and policy management
Azure Policy
Automating compliance scope enforcement with Azure Policy
Compliance management in Azure requires particular attention to the scope actually covered by the various certifications. Standards and frameworks such as C5, ISO 27001, HIPAA, or PCI DSS do not automatically apply to every service available on the platform; rather, they refer to a specific set of services declared in the official documentation published by Microsoft.
One of the most common mistakes is therefore to consider an environment automatically compliant simply because Azure holds the relevant certification. In reality, the set of services in scope can change over time and may differ between Azure Public, Azure Government, and other cloud environments. It is therefore essential to verify that the services used by the workload actually fall within the scope defined by the specific standard.
On top of this comes the shared responsibility model. Even when an Azure service formally falls within the certification, the customer remains responsible for numerous implementation aspects, including access control through RBAC and Privileged Identity Management, network segmentation, logging and monitoring, key management, backup, and recovery processes. Service certification is therefore a prerequisite, but it does not automatically equate to workload compliance.
Azure Policy can be used to turn this verification into a preventive control. Starting from the official list of services in scope for the relevant standard, you can build policies that restrict the resource types that can be deployed within specific subscriptions, landing zones, or management groups. This way, services outside the compliance scope can be blocked directly at deployment time, rather than being detected later through audits.
This approach is particularly effective in enterprise landing zones, where compliance can be translated into technical guardrails applied centrally. However, the process must also include periodic policy reviews, since the certified scope can change as new versions of Microsoft’s documentation are published. Combining scope verification, Azure Policy, and governance controls therefore makes it possible to move from a predominantly documentation-based compliance model to a preventive, automated, and continuously verifiable approach.
Custom policy versioning (preview)
Azure Policy now extends versioning support, in public preview, to custom definitions and initiatives, adopting the same model already available for built-in policies. Each custom policy can now use a version property in the {major}.{minor}.{patch} format, keeping multiple revisions under the same definition ID.
This update makes change management more predictable: assignments can be pinned to a specific version, preventing a definition update from automatically changing what is enforced. You can also test a new version on limited scopes, keep production on an already validated release, and, if needed, quickly roll back to the previous version.
All versions are retained and remain viewable in the Azure portal, simplifying auditing, troubleshooting, and lifecycle management of custom policies.
Backup & Resilience
Azure Backup
Instant Access for virtual machine restore points
Microsoft has made Instant Access available for application-consistent restore points of virtual machines using Premium SSD v2 or Ultra Disk data disks. The capability allows a disk restore to begin as soon as the snapshot is created, without waiting for background data replication to complete, helping to reduce the Recovery Time Objective.
With general availability, the instantAccessState property is also introduced at the restore point level. Compared to the preview, it is no longer necessary to check the access state of each individual disk: a single property indicates whether the restore point can be used for restore, copy, or download operations, which also simplifies recovery automation.
Instant Access can be enabled on the restore point collection via instantAccess=true, while its duration can be configured via instantAccessDurationMinutes, with values between 60 and 300 minutes and 300 minutes as the default.
Monitoring
Azure Monitor
Azure Monitor Auxiliary Logs plan available in Azure Government and China regions
Microsoft has extended support for the Azure Monitor Auxiliary Logs plan to Azure Government and Azure China regions, broadening the availability of a model designed for the cost-effective management of large volumes of telemetry used primarily for occasional investigations, audits, and long-term analysis.
Conclusions
The September 2026 updates provide new tools to simplify the management and protection of hybrid and multicloud environments. Azure Arc makes it easier to centrally manage workloads distributed across cloud, datacenter, and remote sites. Azure Monitor extends AI-driven analysis to logs retained in lower-cost plans, while Microsoft Defender for Cloud broadens security coverage and risk visibility. Azure Policy, in turn, helps prevent the use of services outside the required compliance scope and allows policy changes to be tested before they are applied in production. These tools support organizations, which nonetheless remain responsible for configuring services correctly and ensuring the compliance of their workloads. The practical recommendation is to start with tests in limited environments, verifying the requirements, limitations, and benefits of each capability before extending its adoption. Results depend on the ability to embed these tools, including AI-based ones, into day-to-day operations, with clearly defined responsibilities and measurable goals: reducing manual work, detecting issues earlier, and keeping costs and risks under control.