Azure Hybrid Management & Security: What’s New and Insights from the Field – July 2026

Once again this month, I’m back with my recurring series focused on the evolution of Azure management and security services, with a special focus on hybrid and multicloud scenarios enabled by Azure Arc and enhanced by the use of Artificial Intelligence.

This monthly series aims to:

  • Provide an overview of the most relevant updates released by Microsoft;

  • Share operational tips and field-proven best practices to help architects and IT leaders manage complex and distributed environments more effectively;

  • Follow the evolution towards a centralized, proactive, and AI-driven management model, in line with Microsoft’s vision of AI-powered Management.

The main areas addressed in this series, together with the corresponding tools and services, are described in this article.

Hybrid and multicloud environment management

Azure Arc

Azure Arc SQL migration capabilities extended to SQL Server on Azure Virtual Machines

The SQL migration solution integrated with Azure Arc now supports SQL Server on Azure Virtual Machines as a target for migration jobs. SQL Server instances enabled through Azure Arc can therefore be moved either to Azure SQL Managed Instance or to SQL Server running on IaaS infrastructure in Azure, using a single centralized workflow.

This extension broadens the options available to organizations that need to modernize or relocate SQL Server databases deployed across on-premises, edge or multicloud environments. The target can be chosen according to application requirements, compatibility needs and the desired level of management, without having to adopt different tools or procedures for each scenario.

Support for SQL Server on Azure Virtual Machines is particularly relevant for workloads that require a high degree of compatibility with the source SQL Server instance, control over the operating system, or application configurations that cannot readily be moved to a PaaS service. Azure Arc thereby strengthens its role as a unified control plane for assessing, planning and executing migrations of heterogeneous SQL Server estates.

Security posture across hybrid and multicloud infrastructures

Microsoft Defender for Cloud

Microsoft Defender security assessments for Azure Database for PostgreSQL Flexible Server

Microsoft Defender Cloud Security Posture Management security assessments are now available for Azure Database for PostgreSQL Flexible Server. The capability continuously analyzes the security posture of PostgreSQL Flexible Server, identifying vulnerabilities, misconfigurations and conditions that could increase risk exposure.

The checks have been designed around PostgreSQL-specific security best practices and return actionable recommendations that help harden the protection baseline, prioritize remediation and support compliance requirements. The guidance provided therefore enables a more structured response, focusing effort on the configurations with the greatest potential impact.

No additional configuration is required for resources on which Microsoft Defender CSPM is already enabled. Findings and recommendations can be reviewed directly on the Azure Database for PostgreSQL Flexible Server resource page, in the main Microsoft Defender for Cloud experience, or in the Microsoft Defender portal. Microsoft has released an initial set of built-in assessments and plans to progressively expand coverage in future releases.

Foundational CSPM becomes optional for new Azure subscriptions

Starting 27 October 2026, Foundational CSPM will no longer be enabled automatically on new Azure subscriptions and will have to be turned on explicitly. The change gives organizations greater control over how security posture management is configured for each new subscription, and is part of the ongoing move of Cloud Security Posture Management capabilities to the Microsoft Defender portal.

Foundational CSPM will remain available at no additional cost and can be enabled at any time, according to the organization’s governance and security needs. The change applies only to Azure subscriptions created after the new model takes effect: existing ones will retain their current configuration, while AWS and Google Cloud environments are not affected.

The change makes it even more important to build the activation of security posture capabilities into provisioning processes and enterprise landing zones. Without automation defined through policy, Infrastructure as Code or operational procedures, a new subscription could be created without the baseline capabilities needed to assess its configurations, risks and compliance level.

Database-level recommendations for SQL Vulnerability Assessment

Database-level recommendations generated by SQL Vulnerability Assessment are now available. The update completes the shift from the previous model, in which multiple checks were grouped into a single recommendation, to a more granular approach in which each security rule is presented separately and mapped directly to the affected SQL resource.

SQL Vulnerability Assessment analyzes databases by comparing their configurations against Microsoft security best practices and against requirements commonly adopted in regulatory contexts. Each deviation is reported as a specific recommendation on the scanned database, improving the ability to identify the failed check, understand its impact and assign remediation work more precisely.

The new recommendations contribute to the risk-based Cloud Score but do not affect the classic Secure Score. A failed result does not necessarily represent a vulnerability that must be fixed immediately: it may stem either from an unintended configuration or from a deliberate design decision. Each finding should therefore be evaluated in the technical and operational context of the workload.

Three main approaches are available for handling findings. The configuration can be corrected by applying the remediation steps or scripts provided; it can be approved as a baseline where the current state is intentional and accepted; or the recommendation can be exempted at subscription or management group level where the check is not relevant to the organization. The new level of detail makes both exception management and the measurement of risk associated with individual databases more transparent.

New container security capabilities

Microsoft has made several new container security capabilities generally available in Defender for Cloud, strengthening posture analysis, vulnerability management and multicloud protection for Kubernetes environments.

Kubernetes Security Posture Management recommendations can now analyze the configuration of individual containers agentlessly, rather than being limited to aggregated cluster-level assessments. This makes it possible to pinpoint the resources affected by non-compliant configurations more precisely, and supersedes some previous related cluster-level recommendations.

A new recommendation for upgrading the Azure Kubernetes Service version is also available, designed to identify the minimum AKS version required to fix vulnerabilities in platform-managed system pods. The guidance makes remediation more actionable by linking the vulnerabilities identified directly to the upgrade required.

Vulnerability assessment has also been extended to container images detected at runtime in Amazon EKS and Google Kubernetes Engine clusters. In parallel, Defender for Cloud can now assess vulnerabilities on EKS and GKE Kubernetes nodes, bringing capabilities already available for AKS to AWS and Google Cloud environments. Multicloud coverage is therefore more consistent at both the image and the underlying host level.

Finally, support for scanning Docker Hardened Images has been introduced, expanding the range of distributions and image formats that can undergo vulnerability assessment. Taken together, these capabilities consolidate Defender for Cloud as a central point for monitoring the security posture of containers deployed across Azure, AWS and Google Cloud.

Kubernetes configuration enforcement in Defender for Containers

Kubernetes configuration enforcement is now available in Microsoft Defender for Containers. The service evaluates Kubernetes resources during the admission phase and makes it possible to audit or block deployments that do not comply with the security rules and best practices defined by Microsoft.

Control is therefore applied before a non-compliant resource is actually created or modified in the cluster. Depending on the mode configured, an organization can start with an audit-oriented approach — useful for measuring the impact of policies — or move to stricter enforcement that prevents disallowed configurations from being released.

With general availability, the capability can be deployed through automatic provisioning. For AKS and for Azure Arc-enabled Kubernetes clusters, Defender for Containers must be enabled with Kubernetes API access. In AWS and Google Cloud environments, enablement takes place through agentless protection capabilities instead. Manual installation via Helm remains supported.

This evolution allows posture management to be integrated more closely with deployment processes, shifting security checks toward a preventive model. Defender for Containers therefore no longer merely flags a misconfiguration after release, but can help prevent the non-compliant resource from entering the operational environment in the first place.

Discovery and posture management for serverless container workloads

Microsoft Defender for Cloud is making discovery and security posture management capabilities available for serverless container workloads. Coverage includes Azure Container Apps, Azure Container Instances and Amazon Elastic Container Service running on AWS Fargate.

The capability provides a centralized inventory view of resources, together with recommendations on misconfigurations and vulnerability assessment findings. Organizations can therefore gain more complete visibility over container workloads that do not use Kubernetes clusters or directly managed compute infrastructure.

The information collected is also fed into Defender for Cloud attack path analysis. It becomes possible to correlate vulnerabilities, configurations, network exposure, permissions and relationships between resources in order to identify the paths an attacker could exploit to reach critical assets.

Extending coverage to serverless container services closes a potential blind spot in modern cloud environments, where the simplicity of the operating model does not remove the need to control images, configurations, identities and exposure surfaces. Defender for Cloud thus extends its posture model beyond virtual machines and Kubernetes clusters, offering more consistent coverage of the various containerized execution models.

Governance and policy management

Azure Policy

Compliance Substate for Azure Policy exemptions

Azure Policy introduces the Compliance Substate property to improve visibility into the actual state of resources covered by an exemption. Exemptions are often necessary during a migration, while handling an incident, or for the period an application team needs to complete remediation work. Until now, however, an exempted resource was simply classified as “Exempt”, hiding the result it would have received without the exemption.

The new property instead makes it possible to see the resource’s underlying compliance state and to understand whether it is still non-compliant or has since become compliant. This allows a more precise assessment of which exemptions are still needed and which can be removed without introducing policy violations.

The operational benefit is particularly evident in environments with a large number of exceptions. A set of resources shown as “Exempt” can now be broken down, for example, into resources that are already compliant — and therefore candidates for exemption removal — and resources that are still non-compliant, where the exception must be maintained or paired with remediation work. This reduces the need for manual checks and simplifies periodic exemption reviews.

Compliance Substate is available directly in the Azure Policy Compliance tab, as an optional column in the resource table associated with an assignment’s compliance report. The new information helps eliminate one of the main blind spots in exception management, making it possible to monitor the real posture of resources, confirm that remediation has taken place and remove exemptions on the basis of objective evidence.

Kubernetes-native policy validation with CEL and Validating Admission Policy

Azure Policy for Kubernetes now supports the integration of Gatekeeper with native Kubernetes Validating Admission Policies and the Common Expression Language. The capability leverages the features introduced with Kubernetes 1.30 to apply checks directly within the Kubernetes API Server process, providing a more efficient and reliable validation mechanism than the traditional model based solely on admission webhooks.

Previously, Azure Policy for Kubernetes mainly used OPA Rego-based evaluation: the request sent to the Kubernetes API Server was forwarded to Gatekeeper, which applied the constraints defined in the Constraint Templates and returned the result to the API server. With the new approach, CEL expressions are instead executed natively within the Kubernetes admission process, reducing decision latency and removing some of the intermediate components involved in the validation flow.

The integration also simplifies rule authoring, thanks to CEL expressions that are more readable and immediate than Rego-based templates, and allows a stricter fail-close behavior to be adopted. If the validation process becomes unavailable or encounters problems, Kubernetes can therefore prevent the creation or modification of resources that have not been properly verified, reducing the risk of non-compliant components being deployed to the cluster.

The operating model separates responsibilities clearly: CEL defines which conditions must be validated, while Azure Policy governs how those checks are managed at enterprise level. Centralized assignment, scope management through management groups and subscriptions, definition versioning, compliance monitoring, controlled rollouts and the handling of any exclusions all remain available.

The new integration therefore makes it possible to apply Kubernetes-native controls — for example to restrict authorized container registries, enforce specific security contexts or verify resource configurations — while maintaining a centralized, scalable governance model through Azure Policy.

Azure Enclave for isolated environments and highly sensitive workloads (preview)

Azure Enclave is available in public preview as a managed service for creating and managing secure, isolated and compliant Azure environments intended for workloads with particularly high protection requirements. The solution is designed to support both commercial scenarios and air-gapped environments, where connectivity and the ability to interact with external systems must be tightly controlled.

The service adopts a hierarchical model based on communities, enclaves and workloads. A community acts as the central hub for managing connectivity, governance, monitoring and trusted connections. Enclaves, by contrast, are isolated software-defined networks based on a zero trust approach and built using Azure Virtual Network. Workloads are deployed into resource groups associated with a specific enclave, from which they automatically inherit security configurations, policies and permissions.

Azure Enclave combines a range of native platform controls, including managed routing, Azure Firewall, Network Security Groups, Azure Policy, Role-Based Access Control deny assignments, flow logs and centralized diagnostics. These components are used to create protected virtual boundaries and reduce the risk of unauthorized access or non-compliant changes.

The network resources associated with communities and enclaves cannot be modified directly, but are administered through platform-specific resources and endpoints. This approach helps limit configuration drift, reduces the scope for uncontrolled changes and reinforces the consistency of the security posture over time.

According to Microsoft’s positioning, the service can significantly reduce the time required to stand up high-security environments, turning work that traditionally takes weeks or months into processes that can be completed within hours or days. Azure Enclave therefore fits into the wider move toward managed infrastructure models in which isolation, governance and compliance are built directly into the platform.

Backup & Resilience

Azure Site Recovery

Azure Site Recovery supports workloads with up to five times higher churn

Azure Site Recovery now supports, in General Availability, a data change rate of up to 500 MB/s per virtual machine — a fivefold increase on the churn limit previously handled by the service. Churn is the amount of data changed on a virtual machine’s disks that must be transferred to the target environment in order to keep the replica up to date. The higher limit makes it possible to protect I/O-intensive Azure workloads with Azure Site Recovery, reducing the risk that the volume of changes exceeds the capacity supported by the replication process. The improvement is particularly relevant for enterprise databases, big data platforms, analytics systems and transactional applications that generate large volumes of disk writes. Before adopting the capability, it remains advisable to carefully analyze the churn profile of the virtual machines, the storage configuration, the available bandwidth and the recovery objectives, so as to verify that the entire disaster recovery architecture is consistently sized.

Monitoring

Azure Monitor

Exporting historical data from Log Analytics with Export Jobs (preview)

Log Analytics Export Jobs, available in public preview, allows historical data held in a Log Analytics workspace to be exported to an Azure Storage account by applying a query and a specific time range. Unlike continuous export mechanisms, this capability makes it possible to select precisely which data to extract, simplifying its transfer to external systems for further processing or for long-term retention needs. Use cases include handling audit requests and regulatory requirements, building datasets for forensic investigations and integrating with third-party SIEM solutions. Exported data can also be used for advanced analytics and machine learning, to feed business intelligence platforms, or to support migration initiatives toward other analysis and archiving systems. The capability therefore introduces greater flexibility into log lifecycle management, especially in complex environments where cost control, compliance and data portability must be balanced.

Mirroring Azure Monitor logs into Microsoft Fabric (preview)

Microsoft has released in public preview a new capability that allows telemetry collected in Azure Monitor Log Analytics workspaces to be shared with Microsoft Fabric. The data is made available in OneLake in the open Delta Parquet format, in near real time and without the need to create additional copies.

The capability supports all Azure Monitor Logs plans, including Analytics, Basic and Auxiliary, allowing observability data to be used regardless of the log tier adopted. Once available in Microsoft Fabric, the data can be analyzed through services such as Eventhouse, Power BI and Spark, alongside other operational and business data sources.

This integration makes it possible, for example, to correlate infrastructure and application events with data from ERP, CRM or other business platforms. Organizations can therefore gain a more precise understanding of the operational impact of anomalies, performance degradation or service outages, improving cross-domain analysis and supporting more timely decisions.

Making Azure Monitor data available within Fabric also opens up new scenarios for applying machine learning models, advanced analytics, richer reporting and long-term trend assessment. Observability can thus be embedded in a broader analytical model in which technical information is related to business context and indicators.

Advanced platform metrics in Azure Monitor (preview)

As of 15 July 2026, Microsoft has made Azure Monitor advanced platform metrics available in public preview. The new experience introduces additional telemetry signals to improve visibility into service performance, resource health and the operational behavior of supported Azure environments.

With a broader and more detailed set of metrics, organizations can identify anomalies and potential issues more quickly, reduce the time required for troubleshooting and gain a deeper understanding of how resources behave. The additional information can also help build dashboards, alerts and analysis processes that more closely match the characteristics of individual workloads.

This development is part of the ongoing strengthening of Azure Monitor’s observability capabilities — a key element in the increasingly centralized and proactive management of cloud environments. During the preview phase, customers can evaluate the new experience, verify its effectiveness in their own operational scenarios and provide feedback to Microsoft ahead of future general availability.

Conclusions

This month’s updates confirm the evolution of Azure services toward an increasingly centralized, preventive and cross-cutting management model that extends to hybrid and multicloud environments. Azure Arc strengthens its role as a unified control plane, while Defender for Cloud extends coverage to databases, Kubernetes, serverless containers and infrastructure distributed across Azure, AWS and Google Cloud.

Particularly significant is the shift from simply detecting non-compliant configurations to preventing them. Kubernetes enforcement, Validating Admission Policies and more granular recommendations make it possible to embed security and governance directly into deployment and remediation processes.

Azure Monitor is also evolving toward a more strategic use of operational data, thanks to historical log export, integration with Microsoft Fabric and more advanced metrics. To this is added the enhancement of Azure Site Recovery for protecting workloads characterized by high write volumes.

These capabilities do, however, require structured processes. The new opt-in model for Foundational CSPM, for example, makes it even more important to embed security and compliance into landing zones, policies and Infrastructure as Code pipelines.

Microsoft’s direction therefore appears clear: to move beyond fragmented, reactive management by converging governance, security, resilience and observability into a single operating model, in which AI will be able to support IT teams in analyzing signals and setting priorities.

Please follow and like us: