Category Archives: Announcements and updates

Azure IaaS and Azure Local: announcements and updates (May 2025 – Weeks: 17 and 18)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Microsoft Announces New European Digital Commitments

Microsoft has introduced five new commitments to deepen its partnership with Europe, focusing on digital resilience, data privacy, cybersecurity, and competitiveness. These actions reflect Microsoft’s goal to align with European values and regulations.

1. Expanding AI and Cloud Infrastructure
Microsoft will boost its European datacenter capacity by 40% over two years, covering 16 countries. This includes public and sovereign cloud operations, and partnerships with firms like Bleu (France) and Delos Cloud (Germany). Microsoft aims to support innovation while complying with EU laws.

2. Strengthening Digital Resilience
Microsoft will operate European cloud services under a Europe-based board and uphold a Digital Resilience Commitment, pledging to challenge any external attempts to disrupt services. Code backups in Switzerland and continuity partnerships will ensure service reliability.

3. Safeguarding Data Privacy
With the EU Data Boundary project completed, Microsoft enables customers to keep data within the EU. Customers can encrypt data with their own keys, use lockboxes, and restrict Microsoft access. Microsoft also legally defends against unlawful data requests.

4. Boosting Cybersecurity
Microsoft has supported Ukraine and NATO with $500 million in cybersecurity aid and intelligence. A new Deputy CISO for Europe will oversee compliance with EU cybersecurity regulations like DORA and CRA. Independent audits will confirm adherence.

5. Supporting Competitiveness and Open Source
Through its AI Access Principles, Microsoft ensures open access to over 1,800 AI models, many of them open-source. The company supports European businesses and research institutions in applying AI, and commits to continued local collaboration.

These commitments underline Microsoft’s long-term dedication to Europe’s digital future and its respect for local governance.

Semantic Ranker for Azure AI Search now available on ItalyNorth

The Semantic Ranker feature in Azure AI Search is now generally available in the ItalyNorth region. This capability enhances the relevance of search results by using deep learning models to understand the semantic meaning behind user queries. It enables more accurate and contextually appropriate responses, particularly beneficial for AI-powered applications requiring advanced search functionalities.

Azure Functions Flex Consumption plan hosting now available on ItalyNorth

The Flex Consumption plan for Azure Functions is now available in the ItalyNorth cloud region. This Linux-based hosting option builds upon the pay-as-you-go Consumption model, offering greater flexibility and customization. It introduces capabilities such as private networking, selectable instance memory sizes, and rapid, large-scale out scenarios—all while maintaining a serverless billing model. This provides developers with enhanced control over their serverless workloads without compromising on scalability or cost-efficiency.

UAE North regional availability with Microsoft Dev Box

Microsoft Dev Box is now available in the United Arab Emirates (UAE) North region. This expansion enables customers in the UAE and nearby areas to provision developer workstations closer to their users and data sources, enhancing performance and ensuring compliance with data residency requirements. With this regional support, organizations can now benefit from faster provisioning times and improved network performance for Dev Box environments.

Compute

Azure Compute Fleet

Azure Compute Fleet is now generally available across all Azure regions, offering a scalable and flexible way to deploy up to 10,000 virtual machines in a single fleet. This service intelligently selects and provisions VM instances that match specified parameters—such as core count, RAM, region, pricing model, and VM SKU—ensuring optimal resource allocation for diverse workloads. Azure Compute Fleet also includes robust management features to automatically adjust deployment based on factors like Spot VM evictions, capacity shortages, and cost optimization needs. It is particularly valuable for customers requiring dynamic scaling with a wide variety of VM configurations.

Instance Mix for Virtual Machine Scale Sets

Instance mix is now generally available for Virtual Machine Scale Sets, enabling the use of multiple VM sizes within a single scale set deployment. This new feature offers enhanced flexibility and cost optimization by allowing customers to specify a mix of VM sizes tailored to their workload requirements. It also includes allocation strategies that can prioritize either price or capacity based on customer preferences. With instance mix, deployments benefit from increased capacity availability and simplified management of diverse VM resources within a unified scale set. In addition, customers leveraging Spot Priority Mix can combine both Spot and On-Demand VM instances, further increasing their ability to secure necessary capacity at optimized costs.

Improve the security of Generation 2 VMs via Trusted Launch in Azure DevTest Labs (preview)

Trusted Launch is now available in public preview for Generation 2 virtual machines (Gen2 VMs) within Azure DevTest Labs. This feature introduces a set of coordinated infrastructure technologies that enhance protection against sophisticated and persistent threats. By leveraging Trusted Launch, users can enable key security capabilities—such as secure boot and virtual TPM—independently, thereby hardening their Gen2 VMs without significant configuration overhead. This enhancement is part of Azure’s ongoing efforts to provide secure-by-default infrastructure for development and testing environments.

Improve the security of Generation 2 VMs via Trusted Launch in Azure DevTest Labs (preview)

Trusted Launch is now available in public preview for Generation 2 virtual machines (Gen2 VMs) within Azure DevTest Labs. This feature introduces a set of coordinated infrastructure technologies that enhance protection against sophisticated and persistent threats. By leveraging Trusted Launch, users can enable key security capabilities—such as secure boot and virtual TPM—independently, thereby hardening their Gen2 VMs without significant configuration overhead. This enhancement is part of Azure’s ongoing efforts to provide secure-by-default infrastructure for development and testing environments.

Networking

Azure Firewall integration in Security Copilot

The integration of Azure Firewall with Microsoft Security Copilot enhances the way analysts investigate threats by leveraging natural language interactions. This feature enables users to analyze malicious traffic intercepted by the Intrusion Detection and Prevention System (IDPS) across all deployed firewalls without writing complex KQL queries. Through either the Security Copilot portal or the Copilot in Azure experience, users can: retrieve the top IDPS signature hits, enrich threat profiles with additional intelligence, perform fleet-wide signature searches across tenants, and generate environment-specific security recommendations. This integration streamlines threat analysis and empowers teams with faster, more actionable insights.

Azure Firewall Log Tables Now Supported in Azure Monitor Basic Plan

All resource-specific log tables for Azure Firewall now support the Azure Monitor Basic log plan. This addition enables customers to reduce their logging costs by up to 80%. While this plan provides significant savings, it is important to note that it does not support integrations with Policy Analytics or Microsoft Security Copilot. Organizations looking to balance cost efficiency with basic firewall logging capabilities may find this update especially beneficial.

Next hop IP support for Virtual WAN

Azure Virtual WAN has introduced support for Next hop IP, enhancing routing flexibility for complex networking scenarios. The virtual hub router within Azure Virtual WAN can now peer with Network Virtual Appliances (NVAs) or BGP-enabled endpoints to exchange routes directly. This enables customers to advertise routes for virtual machines that reside behind load balancers, streamlining traffic flows and optimizing network architecture across virtual hubs. This improvement significantly simplifies route management in hybrid and large-scale cloud networks.

Azure virtual network terminal access point (TAP) (preview)

Azure Virtual Network TAP is now in public preview, offering a powerful way to stream virtual machine network traffic directly to packet collectors or analysis tools. This agentless solution eliminates the need for additional appliances or changes to existing network topologies, enabling transparent traffic mirroring with zero impact on VM performance. Furthermore, mirrored traffic does not count against the VM’s bandwidth quota. With broad compatibility across third-party tools, Virtual Network TAP facilitates robust integration into existing security and monitoring frameworks—an essential advancement for organizations requiring deep network visibility in their cloud environments.

Azure WAF CAPTCHA Challenge for Azure Front Door (preview)

Azure Web Application Firewall (WAF) for Azure Front Door now includes CAPTCHA challenge support in public preview. This new capability introduces an adaptive layer of defense to mitigate threats from automated attacks such as bots, scrapers, and brute-force attempts, which often bypass traditional protections like IP filtering or rate limiting. By requiring real-time human verification through an interactive CAPTCHA, this feature enhances application security while maintaining usability for legitimate users. It provides a modern and effective way to safeguard web applications from malicious automated traffic.

Storage

Next-Generation Azure Data Box Devices Now Available

Microsoft has announced the general availability of the next-generation Azure Data Box 120 and Azure Data Box 525. These compact, NVMe-based devices are now available for order in the US, US Gov, Canada, EU, and UK Azure regions, with broader regional availability expected soon. Since their preview debut at Ignite ’24, these devices have successfully facilitated petabyte-scale data ingestion across numerous customer projects and industry verticals. Customers have reported up to 10x improvements in data transfer speeds, citing enhanced reliability and efficiency as key benefits. The design of these devices is based on extensive customer feedback and reflects the growing demands of large-scale data migrations. Azure Data Box continues to offer one of the most cost-effective solutions for offline data transfers, with a competitive price per terabyte and seamless ordering through the Azure portal.

Cross-Region Data Transfer Support in Azure Data Box

Azure Data Box now supports cross-region data transfer for all Azure region pairs, marking a significant enhancement in flexibility for distributed storage strategies. Customers can now upload data from any on-premises location directly to any Azure region, eliminating the need to physically transport the device across commerce boundaries. For example, data collected in Japan can be uploaded to an Azure data center in the European Union, while the Data Box itself remains within Japan. The transfer is carried out over the Azure network at no additional cost, making this feature particularly valuable for global enterprises managing multi-regional data workloads.

Azure Files: Metadata Cache for Azure SSD (Premium) SMB

Azure Files has introduced a new enhancement that significantly improves metadata operations performance for both SMB and REST protocols. This capability is automatically available at no extra cost and benefits both new and existing file shares. Whether used to support critical business applications, streamline DevOps workflows, or provide storage for large-scale virtual desktop environments, Azure Files now offers improved speed, scalability, and performance optimization. This update reinforces Azure Files as a high-performance storage option for demanding enterprise workloads.

Azure Premium SSD v2 and Ultra Disk Storage Now Available in Australia Central 2 and Norway West

Azure Premium SSD v2 and Ultra Disk Storage have been made generally available in the Australia Central 2 and Norway West regions. Azure Ultra Disk Storage provides high throughput, elevated IOPS, and consistently low latency, making it an optimal choice for data-heavy applications such as SAP HANA, high-performance databases, and applications requiring intensive transactional operations. Azure Premium SSD v2, designed as a next-generation block storage solution, delivers sub-millisecond latencies and cost-efficient performance for IO-intensive workloads. It is ideal for a wide spectrum of enterprise production scenarios, including SQL Server, Oracle, MariaDB, SAP, big data analytics, gaming on virtual machines, and stateful containers.

Cross-tenant customer-managed keys for Azure NetApp Files volume encryption (preview)

A new feature in public preview enables cross-tenant customer-managed keys (CMK) for Azure NetApp Files volume encryption. This capability allows end users to manage their own encryption keys across different Azure tenancies, rather than relying on the SaaS provider’s key management. Particularly useful in SaaS provider-to-customer models, it ensures that customers maintain full control over their data protection. Available in all regions that support Azure NetApp Files, this enhancement provides increased flexibility and transparency in key management strategies for both providers and consumers.

Azure Local

Azure Local 2504: new OS version, feature enhancements, and improved update experience

The 2504 release of Azure Local introduces several enhancements aimed at improving performance, security, and manageability. New deployments now use OS version 261000.3775, while existing systems remain on version 23598.1551. Customers can obtain this OS image and compatible drivers through the Azure portal or via their OEM partners.

Significant improvements have been made in several areas. .NET update installations are now more reliable, and update processes benefit from enhanced health checks and simplified tracking via the Azure portal. Registration and deployment processes are more flexible, allowing customers to select from up to six supported software versions, and error logging has been improved.

Security is also strengthened: Dynamic Root of Trust for Measurement (DRTM) is now enabled by default for new deployments. Azure Local VMs gain new capabilities, such as data disk expansion and live migration for VMs using GPU partitioning (GPU-P), provided the latest NVIDIA vGPU drivers are used.

Additional changes include renamed OEM licenses to reflect Azure Local branding, improved handling of solution extensions, a new crash dump collection feature for observability, and updates to billing logic for newer deployments. Documentation for version 22H2 will be archived after May 31, 2025.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (April 2025 – Weeks: 15 and 16)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Microsoft Copilot in Azure is Now Generally Available

Microsoft Copilot in Azure has reached general availability, bringing AI-powered assistance to users across the Azure ecosystem. Designed to enhance productivity, Copilot in Azure leverages Large Language Models (LLMs), the Azure control plane, and real-time insights from the user’s environment to streamline tasks and uncover cloud benefits. With GA, users can now rely on Copilot in production scenarios, benefiting from improved performance, higher response accuracy, and full localization support across all Azure portal languages. Current capabilities are included at no additional cost, though future features may introduce pricing considerations. Microsoft has also implemented safeguards such as temporary throttling to manage excessive use of generative AI services.

Microsoft Azure Now Available from New Cloud Regions

Microsoft has announced the general availability of new Azure cloud regions, further expanding its global infrastructure. The Indonesia Central region is now live, marking Azure’s first presence in Indonesia. Equipped with Azure Availability Zones, this region offers scalable, resilient, and secure cloud services to support digital transformation and AI innovation across the country. In addition, a new Azure for U.S. Government Secret region is now generally available, providing increased capacity and flexibility for classified workloads. Designed to meet the strict requirements of the U.S. Department of Defense and other federal agencies, the new region offers geographically distributed data residency options, continuity of operations, and native connectivity to U.S. Government classified networks. Customers benefit from a consistent platform experience and can access foundational Azure services, including Azure ExpressRoute, to support mission-critical scenarios with private, high-bandwidth connectivity.

ExpressRoute Metro and Global Reach Available in Italy North

ExpressRoute Metro and Global Reach are now available in the Italy North region, expanding Azure’s private connectivity capabilities in the area. ExpressRoute Metro allows customers to connect to Microsoft’s global network from two different physical locations within a metro area for higher resiliency and performance. With Global Reach, users can connect their on-premises networks across different regions through the Microsoft backbone, improving global connectivity and optimizing traffic flow.

Compute

DCesv6 and ECesv6 Series Confidential VMs with Intel® TDX (private preview)

Azure has introduced the DCesv6 and ECesv6 series Confidential Virtual Machines in private preview, leveraging 5th Gen Intel® Xeon® processors with Intel® Trust Domain Extensions (TDX). These next-generation VMs are designed to support highly sensitive and confidential workloads in the cloud without requiring changes to application code. The new SKUs include the general-purpose DCesv6-series and the memory-optimized ECesv6-series. These VMs maintain data privacy by keeping it encrypted even during processing, and they offer in-guest attestation, enabling verification of VM integrity. This marks a significant advancement in Azure’s confidential computing offerings.

Networking

Azure Networking Capabilities for Microsoft Copilot in Azure

Azure networking capabilities for Microsoft Copilot in Azure are now generally available, enhancing the AI-powered assistant with deep, contextual insights into network design, operations, and security. Users can now query Copilot for information on Azure networking products, receive guidance on architecture planning, resilience strategies, and migration from on-premises environments. Copilot also supports detailed inventory and traffic path queries, providing topology maps and network connectivity graphs. For operational needs, it offers troubleshooting and diagnostic capabilities by analyzing network configurations, control plane data, and resource health. Additionally, Copilot now integrates with Security Copilot to enable attack investigation on malicious traffic intercepted by Azure Firewall’s IDPS feature—directly within the Azure portal.

Application Gateway as a Private Link Enabled Origin for Front Door Premium

Application Gateway resources can now be configured as Private Link enabled origins within Azure Front Door Premium profiles. This integration allows customers to deliver web content via public Front Door endpoints while keeping the origin infrastructure isolated from the public internet. The use of Private Link ensures that the communication between Front Door and the origin remains secure and private, enhancing the security posture of internet-facing applications. This feature is particularly valuable for scenarios requiring strict network isolation without compromising performance or global reach.

Azure Front Door: Enhanced Server Variable Support

Azure Front Door has expanded its server variable capabilities by enabling the capture of request header, response header, and request query string values. This builds on the previously released feature to capture URL path segments. With these new enhancements, server variables can now be used in the rules engine to enable more dynamic and flexible HTTP request manipulation and routing at the edge. Scenarios enabled by this feature include modifying a response header based on a request header value, renaming cloud provider-generated headers to branded ones, and redirecting based on query string values. These capabilities unlock new customization opportunities for developers aiming to fine-tune edge routing behavior.

Azure Front Door: Custom Cipher Suite Support

Custom cipher suite support for Azure Front Door is now generally available across both Standard and Premium tiers. Azure Front Door provides several predefined TLS policies based on Microsoft Security best practices to ensure strong encryption and protocol support. With this update, customers can also define custom TLS policies to meet specific business and compliance requirements. This includes setting the minimum supported TLS version and selecting allowed cipher suites, offering granular control over security settings and enabling organizations to tailor their Front Door configuration to their unique security posture.

Azure Bastion Developer Now Available in 36 Regions

Azure Bastion Developer, previously limited to six regions, is now generally available in 36 public regions worldwide. Designed for Dev/Test scenarios, this version of Azure Bastion provides secure-by-default RDP and SSH access to virtual machines without the need for a public IP address. It allows users to connect to one VM at a time through the virtual machine’s connect blade—all at no cost. While it lacks the advanced features and scalability options of the standard Bastion offering, Bastion Developer is ideal for users seeking a streamlined and secure connection method for development and testing environments.

Expanded Availability of ExpressRoute Metro, Peering Locations, and Global Reach

Azure continues to expand its networking footprint with broader availability of ExpressRoute Metro and Global Reach. ExpressRoute Metro is now accessible in four new locations—Atlanta (USA), Jakarta (Indonesia), Madrid (Spain), and Milan (Italy)—providing increased resiliency for organizations requiring high-performance, private connectivity to Azure. Additionally, two new ExpressRoute Peering locations, Brussels and Brussels2 in Belgium, have been introduced, further enhancing secure access across Europe. ExpressRoute Direct is now available in all these new regions. Furthermore, ExpressRoute Global Reach has expanded to include Belgium, Italy, and Spain, enabling private site-to-site connectivity through Microsoft’s global network infrastructure.

Route-Maps for Azure Virtual WAN

Azure Virtual WAN now includes support for route-maps, empowering users with enhanced control over routing behavior within Virtual WAN virtual hubs. This feature enables fine-grained management of route advertisements and route selection for various connection types, including site-to-site VPN, point-to-site VPN, ExpressRoute, and virtual network (VNet) links. Route-maps allow for advanced routing scenarios, such as filtering or modifying route advertisements, offering greater flexibility in managing complex network topologies and optimizing traffic flows.

Storage

ACLs for Local Users in Azure Blob Storage SFTP

Access Control Lists (ACLs) for Azure Blob Storage SFTP local users are now generally available. This capability provides administrators with an intuitive way to implement fine-grained access control over blobs and directories for users configured for SFTP access. With ACLs, organizations can enforce security and access policies more precisely, simplifying the management of user-level permissions while enhancing data protection within Azure Blob Storage environments.

Performance Plus for Azure Disk Storage

Azure Disk Storage has introduced the Performance Plus feature in general availability, bringing enhanced performance to Premium SSD, Standard SSD, and Standard HDD disks of 513 GB or larger. With Performance Plus, users benefit from increased IOPS and throughput at no additional cost. This feature is accessible via Azure CLI, PowerShell, and the Azure Portal, enabling customers to optimize their disk performance with minimal effort and without changing disk SKUs. Performance Plus helps meet demanding workload requirements by improving disk responsiveness and efficiency.

Azure NetApp Files: File Access Logs (preview)

Azure NetApp Files now supports file access logs in public preview, offering organizations enhanced visibility into file activity for improved security and operational monitoring. This new feature captures detailed information about file access, including user identity, operation type, and timestamps. It supports SMB, NFSv4.1, and dual-protocol volumes, allowing organizations to detect unauthorized access, ensure compliance, resolve operational incidents, and analyze usage patterns. By incorporating file access logs, enterprises can strengthen data protection, meet compliance requirements, and align with the Well-Architected Framework’s security best practices.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (April 2025 – Weeks: 13 and 14)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

Compute

Retirement of D, Ds, Dv2, Dsv2, and Ls Series Virtual Machines

Microsoft has announced the retirement of the D, Ds, Dv2, Dsv2, and Ls series virtual machines, effective May 1, 2028. After this date, these VM series will no longer be available for use or purchase. Customers currently utilizing these VM types are advised to begin planning their migration strategies toward newer VM generations to ensure ongoing compatibility and support for their applications. As part of the phased retirement process, three-year reserved instances for these VMs will no longer be available for purchase or renewal starting May 1, 2025. One-year reservations will continue to be offered until 2027. For those with active three-year reservation contracts, the benefits will remain valid until contract expiration. Beyond that point, instances will revert to pay-as-you-go pricing. To avoid billing surprises and ensure continuity, customers should review their reservations and take action to transition affected workloads.

Networking

Azure Firewall Updates – Parallel IP Group Updates

Azure Firewall now supports Parallel IP Group Updates, enabling administrators to update multiple IP Groups simultaneously as part of their firewall or firewall policy changes.

Key Benefits

  • Faster & Scalable Updates: Update up to 20 IP Groups in parallel, achieving up to 2x faster update times compared to sequential updates.
  • Improved Visibility: Enhanced error messaging allows administrators to quickly identify and resolve issues. Even if one IP Group fails, other updates continue uninterrupted, preserving overall system integrity.

This update significantly improves management efficiency and scalability for large-scale or dynamic firewall policy environments.

New Regions for Azure Front Door Premium with Private Link-Enabled Origins

Azure Front Door Premium now supports Private Link-enabled origins in West US 2 and Southeast Asia regions. This feature allows content to be delivered through public Front Door endpoints while keeping backend origins inaccessible from the public internet, enhancing security and privacy. With the addition of these new regions, organizations can now deploy Private Link-enabled architectures in more geographies, improving network performance and meeting regional compliance requirements.

Network isolated cluster in AKS

Azure Kubernetes Service (AKS) now offers network isolated clusters, enabling a simplified approach to securing network access to Kubernetes workloads. While customers have traditionally relied on Azure Firewall to control egress traffic and enforce isolation, this approach often introduces added complexity and cost. With network isolated clusters, organizations can reduce the risk of unintentional exposure of public endpoints and strengthen the security posture of their AKS deployments. This built-in feature helps minimize attack surfaces by ensuring tighter control over how clusters connect to external networks, supporting compliance and data protection goals with greater ease.

ExpressRoute Resiliency Enhancements (preview)

Microsoft has introduced new resiliency validation and insight capabilities for ExpressRoute, now available in public preview. These enhancements aim to improve the assessment and monitoring of ExpressRoute-enabled workloads, offering more robust and transparent insights into network reliability. The resiliency validation feature allows customers to simulate site failovers on their Virtual Network Gateways, enabling proactive testing during planned migrations or outage scenarios. This helps verify failover mechanisms and ensures continued connectivity to Azure services. In addition, the new resiliency insights capability introduces a resiliency index — a percentage-based score that evaluates ExpressRoute reliability based on criteria such as route resilience, use of zone-redundant gateways, advisory feedback, and test results from resiliency validation. These metrics allow organizations to identify weak points in their network architecture and make informed improvements to enhance the robustness of their connectivity.

Increased VNet limits for Private Endpoints (preview)

Microsoft has introduced High Scale Private Endpoints, now in public preview, enabling significantly increased limits for deploying Azure Private Endpoints within Virtual Networks (VNets) and across peered VNets. Previously, customers could only create up to 1,000 private endpoints within a single VNet, and exceeding this limit required a support request. Additionally, Microsoft recommended a soft limit of 4,000 private endpoints across peered VNets to avoid connectivity issues. With the introduction of High Scale Private Endpoints, these limits are substantially raised—allowing up to 5,000 private endpoints within a single VNet and 20,000 across peered VNets. This capability is especially beneficial for large-scale, service-rich environments where extensive use of private connectivity is essential. Customers seeking greater scalability for their private networking configurations are encouraged to adopt High Scale Private Endpoints to support growing infrastructure needs without the complexity of manual quota increases.

Storage

Vaulted Backup for Azure Files

Azure Backup has announced the general availability of Vaulted Backup support for Azure Files – Standard tier, providing a robust, enterprise-grade solution to protect data and applications hosted on Azure SMB file shares.

Key Features & Benefits

  • Integrated Protection Policy: Combine snapshot and vaulted backup in a single policy to protect data in a secure Recovery Services vault.

  • Regional Recovery: Ensure data resilience with support for cross-region restore.

  • Advanced Protection Capabilities:

    • Ransomware protection and immutability

    • Restore capability even if the file share is deleted

  • Azure File Sync Integration: Seamlessly protect cloud-tiered data from Azure File Sync, enabling long-term retention in a cost-effective way.

With this release, customers can meet compliance, security, and business continuity requirements while simplifying backup management and reducing data protection costs.

Azure File Sync support for managed identities

Azure File Sync now supports managed identities, a feature that has reached general availability. This enhancement replaces the need for shared keys with a more secure and streamlined authentication mechanism through system-assigned managed identities provided by Microsoft Entra ID. By configuring managed identities within an Azure File Sync deployment, these identities will handle authentication in several key scenarios: the Storage Sync Service authenticating to the Azure file share, registered servers authenticating to the Azure file share, and registered servers authenticating to the Storage Sync Service. To further simplify the setup and improve security, managed identities are now enabled by default for all new Storage Sync Services. Configuration can be completed directly through the Azure portal, eliminating the previous dependency on PowerShell. This updated experience is being gradually rolled out across all Azure regions. The feature is available at no additional cost in all Azure Public and Government cloud regions, making it a recommended approach for customers seeking enhanced security and simplified identity management.

Azure NetApp Files Flexible Service Level (Preview)

Azure has introduced a Flexible Service Level for Azure NetApp Files, now in public preview, allowing customers to independently configure storage capacity and throughput for greater cost and performance optimization.

Key Features & Benefits

  • Customizable Throughput: Scale throughput independently from capacity, up to 640 MiB/s per provisioned TiB, which is up to 5x higher than the Ultra tier.

  • Manual QoS Pools: Supported with manual QoS capacity pools, offering a baseline throughput of 128 MiB/s at no additional cost.

  • Right-Sized Performance:

    • High throughput for smaller pools – Ideal for SAP HANA, Oracle, and other demanding workloads.

    • Cost savings for high-capacity/low-throughput workloads – Reduce cost without compromising storage footprint.

  • No Volume Moves Required: Avoid service disruptions or reconfigurations when scaling performance or storage.

This new service level offers unprecedented flexibility, allowing customers to fine-tune Azure NetApp Files performance and cost based on exact workload requirements.

Azure Local

Azure Local – 2503 Update Released

The 2503 update for Azure Local has been officially released as of March 31st, introducing a set of baseline enhancements focused on improving registration, deployment, and overall management experience. This update reflects ongoing efforts to simplify operations and bolster security within Azure Local environments.

Key changes include a shift in the extension installation process: extensions are no longer installed during the registration phase but are now deployed during machine validation. Additionally, the local UI used for bootstrapping has been deprecated in favor of the Configurator app, providing a more modern and flexible onboarding experience. The Arc registration flow has also been streamlined—Service Principal Name (SPN) is deprecated, and a simplified Arc installer script now relies solely on the Start-ArcBootstrap command.

The update also supports composed images for OEMs and enables deployment of both current and previous versions of Azure Local. While the Azure portal supports the latest version, prior versions must be deployed using dedicated Azure Resource Manager templates.

Other notable improvements include enhanced security for the Bootstrap service, integrated environment checks for connectivity and validation, improved update applicability logic, and support for downloading platform update packages via URLs. Finally, users can now connect to Azure Local VMs over SSH or RDP from within the host network, removing the requirement for line-of-sight access.

Azure Local Performance Metrics Dashboard

Microsoft has introduced the Azure Local Performance Metrics Dashboard, a powerful new tool designed to provide comprehensive visibility into the health and performance of Azure Local systems. With over 60 metrics collected by default—at no additional cost—this out-of-the-box solution delivers actionable insights across storage, network, and compute resources.

Metrics are automatically gathered by the TelemetryAndDiagnostics agent, which is configured during deployment, enabling seamless access to system telemetry without requiring manual setup. The dashboard offers deep visibility into several critical performance areas:

  • Storage Performance: Includes disk read/write operations and throughput, volume latency, and insights into VHD and physical disk activity to help optimize storage usage.

  • Network Performance: Monitors data transmission metrics such as Netadapter Bytes Sent/Received, RDMA traffic, and VM-level network activity for early detection of bottlenecks or connectivity issues.

  • Compute Metrics: Tracks memory usage (available, assigned, used, pressure) across host and guest environments, along with CPU utilization metrics for both host and virtual machines.

This centralized performance dashboard empowers administrators to proactively manage their Azure Local environments, facilitating data-driven decisions to maintain system efficiency and reliability.

Support for 4-node switchless configuration

Microsoft has introduced official documentation to support 4-node switchless configurations, expanding the deployment options for Azure Stack HCI and other Azure-integrated infrastructure solutions.

This update provides organizations with the flexibility to deploy smaller, cost-effective clusters without the need for dedicated network switches between nodes. The switchless architecture simplifies the physical setup and reduces hardware requirements while maintaining essential performance and connectivity capabilities for supported scenarios.

By adding support for this topology, Microsoft continues to enhance deployment versatility, especially for edge and branch environments where simplicity and space efficiency are crucial.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (March 2025 – Weeks: 11 and 12)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Microsoft Named a Leader in The Forrester Wave: Public Cloud Platforms, Q4 2024

Microsoft has once again been recognized as a Leader in The Forrester Wave™: Public Cloud Platforms, Q4 2024. This acknowledgment highlights Microsoft’s continued commitment to building a trusted and comprehensive cloud platform with Azure, capable of supporting enterprise innovation at scale in today’s AI-driven landscape.

Forrester’s evaluation focused on both current capabilities and strategic direction, citing Microsoft’s generative AI (genAI) strategy and AI offerings such as Azure OpenAI Service, Azure AI Studio, GitHub Copilot Enterprise, and Microsoft Fabric as key differentiators. The report noted that “Azure is a good fit for organizations seeking quick uptake of AI innovation as well as core cloud offerings for longstanding Microsoft environments.”

This recognition reaffirms Microsoft’s position as a cloud leader committed to enabling customers to migrate, modernize, and innovate with AI, all on a secure and scalable cloud foundation.

OpenAI Global Provisioned Now Available in ItalyNorth

OpenAI Global Provisioned services are now available in the ItalyNorth region. This enables customers to access OpenAI capabilities, including services like Azure OpenAI, from a closer geographic location for improved performance.

⚠️ Note: This deployment does not offer data residency guarantees—data may still be processed globally.

This availability supports broader AI adoption for organizations operating in or near Italy, reducing latency and enhancing responsiveness for AI-powered applications.

ARM-Based VMs (EPsv5/DPsv5) Now Available in ItalyNorth

Azure has expanded the availability of its ARM-based virtual machines, EPsv5 and DPsv5 series, to the ItalyNorth region. These VMs are powered by Ampere Altra processors and are designed for energy-efficient, cost-optimized performance, especially for scale-out workloads.

Key benefits include:

  • High core density and predictable performance

  • Ideal for web servers, microservices, Java applications, and open-source databases

  • Lower total cost of ownership due to energy efficiency

This expansion brings greater architectural diversity and performance options to customers in ItalyNorth looking to optimize both cost and compute performance.

Compute

VM Hibernation Now Generally Available for GPU Virtual Machines

Azure has announced the general availability of VM hibernation for GPU Virtual Machines, offering a cost-efficient method to pause GPU-intensive workloads while preserving the in-memory state.

This feature is now supported on select sizes in the NVv4 and NVadsA10v5 VM series and is available for both Linux and Windows operating systems across all public regions.

Key Benefits

  • Cost Optimization: Save on compute costs by deallocating the VM, paying only for storage and networking resources.

  • State Preservation: Resume VMs from the exact state they were in before hibernation—ideal for long-running GPU workloads.

  • Broad Availability: Supported on both new and existing GPU VMs, making it easy to integrate into existing environments.

This feature enhances flexibility and efficiency for organizations leveraging GPU-based workloads such as AI/ML training, rendering, and visualization.

Networking

Azure Virtual Network Manager – Network Verifier

Azure has introduced Network Verifier, a powerful feature within Azure Virtual Network Manager that helps validate whether your network policies and configurations are enabling or blocking desired traffic flows between Azure resources.

With multiple factors like connectivity rules, network security, routing, and resource-specific settings influencing traffic flow, Network Verifier helps users answer critical questions about reachability, diagnose issues, and ensure compliance with security requirements.

Key Capabilities

  • Reachability Analysis: Create a verifier workspace and define intents that specify the traffic flow you want to evaluate.

  • Visual and JSON Results: Run analyses to get a visual representation of the network path or parse detailed JSON output.

  • Broad Scope Evaluation: Analyze network reachability across multiple Azure resources and policies within a Virtual Network Manager scope.

  • Delegated Access: Non-network manager users can be given access to run network verifier analyses without needing elevated subscription or management group permissions, allowing broader teams to troubleshoot network issues effectively.

Network Verifier helps organizations simplify network diagnostics, validate policy effectiveness, and improve network governance across complex Azure environments.

Storage

Azure NetApp Files Application Volume Group for SAP HANA – Extension 1

Azure has released Extension 1 for Azure NetApp Files Application Volume Group (AVG) for SAP HANA, introducing several enhancements to further simplify and optimize SAP HANA infrastructure deployments.

Key Enhancements

  • Zonal Deployments for All HANA Volumes: Customers can now deploy all SAP HANA volumes across availability zones, aligning with Microsoft’s High Availability (HA) recommendations for SAP virtual machines.

  • Simplified Deployment: The use of Proximity Placement Groups (PPG) and manual AVset pinning is no longer required, reducing deployment complexity.

  • Standard Network Features: Support for standard networking allows customers to benefit from features like NSGs, UDRs, and ExpressRoute FastPath.

  • Customer-Managed Keys (CMK): Improved security with support for user-provided encryption keys, enhancing data protection and compliance posture.

These updates make SAP HANA deployments on Azure more resilient, secure, and easier to manage, while ensuring optimal performance and HA readiness.

Azure NetApp Files Application Volume Group for Oracle Now Available

Azure has introduced Application Volume Group (AVG) for Oracle, a feature designed to streamline, standardize, and accelerate the deployment of storage infrastructure for Oracle databases using Azure NetApp Files.

Key Capabilities

  • One-Step Deployment: Automatically deploy all required volumes for Oracle databases in a single, optimized workflow, ensuring best practices and optimal performance.

  • Zonal Placement: All volumes are automatically deployed in the same availability zone as the associated VMs, minimizing latency and maximizing consistency.

  • Scalable Architecture: Supports a wide range of Oracle workloads, from small single-volume setups to multi-hundred TiB databases with up to 8 data volumes.

  • High Performance: Leverages Azure NetApp Files to deliver latency-optimized performance, only limited by the network capabilities of the database VM.

  • Multi-Endpoint Support: Designed for enterprise-scale deployments, including complex configurations and multiple storage endpoints.

Application Volume Group for Oracle is now available in all Azure NetApp Files enabled regions, enabling faster deployments and improved performance and stability for critical Oracle workloads in Azure.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (March 2025 – Weeks: 09 and 10)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Custom Secure Boot UEFI Keys for Azure Trusted Launch VM Now Generally Available

Azure Trusted Launch VMs now support customizing Secure Boot UEFI keys, offering greater flexibility to enhance workload security. Customers can fully replace or update one or more of the Secure Boot UEFI keys and databases (PK, KEK, DB, or DBX) to align with their security policies and compliance requirements.

Key Benefits:

  • Enhanced Security: Protect against persistent boot/kernel malware.
  • Trusted Boot State: Ensures VMs always boot to a defined and trusted state.
  • Compliance with Standards: Meets NIST security best practices, Microsoft security benchmarks, and industry standards.

This enhancement strengthens workload protection for organizations using Trusted Launch VMs in Azure.

AutonomousDb Available on ItalyNorth

Microsoft has announced the availability of AutonomousDb in the ItalyNorth region. This expansion allows organizations operating in Italy to benefit from a fully managed database service with automated scaling, self-healing capabilities, and advanced security features. By leveraging AutonomousDb, customers can optimize performance, reduce operational overhead, and ensure high availability for their mission-critical workloads while complying with local data residency requirements.

Networking

Azure Load Balancer Health Event Logs Now Generally Available

Azure Load Balancer health event logs are now generally available across all public, Azure China, and Government regions. These logs enable users to collect, store, and analyze health-related data for their Azure Load Balancer resources, simplifying troubleshooting and availability monitoring. With built-in health event logs, customers can identify and address traffic distribution issues, detect SNAT port exhaustion that may impact outbound connectivity, and receive alerts when there are no healthy backend instances available. This feature enhances visibility into load balancer operations without requiring custom data ingestion pipelines or complex metric-based alerting configurations, ensuring a more proactive approach to maintaining application performance and availability.

Storage

Edit Network Features for Azure NetApp Files with No Downtime Now Generally Available

Azure has announced the general availability of Edit Network Features for Azure NetApp Files, allowing users to upgrade Basic network features to Standard network features without downtime.

Key Benefits of Standard Network Features:

  • Increased IP Limits: Virtual networks with Azure NetApp Files volumes now have IP limits on par with VMs, eliminating network topology constraints.
  • Enhanced Security: Network Security Groups (NSGs) are now supported on Azure NetApp Files delegated subnets for improved security controls.
  • Advanced Network Control: User-defined routes (UDRs) now enable custom routing to and from Azure NetApp Files subnets.
  • Active/Active VPN Gateway Support: Ensures high availability for on-premises to Azure NetApp Files connectivity.
  • ExpressRoute FastPath Support: Improves data path latency and bandwidth performance for ExpressRoute connectivity to Azure NetApp Files.

This zero-downtime upgrade allows organizations to enhance their network security, control, and performance for Azure NetApp Files across all Azure-enabled regions.

Azure Storage Object Replication Metrics for Visibility into Replication Progress (Preview)

Azure has introduced the public preview of Object Replication Metrics, providing enhanced visibility into the progress of Azure Storage object replication. The new metrics include:

  • Pending Operations: Displays the number of replication operations waiting to be processed.
  • Pending Bytes: Shows the amount of data pending replication.

Additionally, the Pending Operations metric categorizes data based on replication delay time, displaying replication wait times in intervals such as:

  • Less than 5 minutes
  • Between 5–10 minutes
  • Between 10–15 minutes, and so on.

These new metrics improve monitoring, troubleshooting, and performance optimization for object replication in Azure Storage.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Local. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (February 2025 – Weeks: 07 and 08)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

Compute

6th Generation Intel-Based VMs – Dv6/Ev6 Now Generally Available

Azure has announced the general availability of the Dv6 and Ev6 series Virtual Machines (VMs), powered by the 5th Gen Intel® Xeon® Platinum 8537C (Emerald Rapids) processor. These new Intel-based VMs offer three different memory-to-core ratios and come in 84 different sizes, ranging from 2 to 192 vCPUs with up to 1.8TB of memory. Customers can choose options with or without local SSDs across the new VM families, including:

  • General Purpose: Dsv6, Dlsv6, Ddvs6, and Dldsv6 series.
  • Memory Optimized: Esv6 and Edsv6 series, with constrained core variants for high data throughput workloads.

These next-generation VMs deliver:

  • Up to 27% higher vCPU performance and 3x larger L3 cache compared to previous Intel-based Dl/D/Ev5 VMs.
  • Azure Boost capabilities, including:
    • Up to 400K IOPS and 12 GB/s remote storage throughput.
    • Up to 200 Gbps VM network bandwidth.
    • 46% larger local SSD capacity with 3x read IOPS.
    • NVMe interface for local and remote disks.
  • Enhanced security through Total Memory Encryption (TME) technology.

These improvements significantly extend Intel-based VM performance in Azure, providing customers with high-throughput, high-memory, and high-security computing options. The new Dv6/Ev6 VMs are now available in multiple regions across North America, Europe, and Asia, with further expansion planned.

Upgrade Existing Azure Gen1 VMs to Gen2-Trusted Launch (preview)

Azure has introduced public preview support for upgrading existing Azure Generation 1 VMs to Generation 2-Trusted Launch, improving security without requiring full VM redeployment.

Trusted Launch VMs enhance security by enabling:

  • Secure Boot: Protects against rootkits and bootkits.
  • Virtual Trusted Platform Module (vTPM): Strengthens OS integrity and enables attestation by measuring the VM’s boot chain.

This upgrade option provides foundational compute security for existing workloads, allowing organizations to strengthen their virtual infrastructure without disrupting operations.

Networking

New Pricing for Azure Virtual Network Manager Now Generally Available

Azure has introduced new pricing for Azure Virtual Network Manager (AVNM), a centralized network management service that enables users to manage virtual network connectivity, security, and routing at scale.

Starting February 11, 2025, all newly created Azure Virtual Network Manager instances will be charged based on the number of virtual networks where an active AVNM configuration is deployed. This replaces the previous subscription-based pricing model. Charges will only apply when using configuration features such as:

  • Connectivity
  • Security Admin
  • Routing

This new virtual network-based pricing aligns costs more closely with actual usage, providing greater flexibility for a broader range of customers.

Transition for Existing AVNM Instances:

  • Existing Azure Virtual Network Manager instances can opt-in to the new pricing model.
  • No automatic changes will be applied to existing AVNM instances before February 2028, allowing businesses to maintain their current billing structure until then.

This pricing adjustment ensures a more scalable and cost-effective approach for organizations managing large virtual network infrastructures in Azure.

Fallback to Internet on Private DNS Zones Now Generally Available

Azure has introduced Fallback to Internet on Private DNS Zones, a new feature that simplifies network isolation and enhances Private Link and Private DNS adoption. This fully managed solution eliminates the need for IaaS-based DNS servers, providing seamless public DNS resolution when a Private DNS Zone returns an authoritative NXDOMAIN response.

Key Benefits:

  • Automatic Public DNS Recursion: When an authoritative NXDOMAIN response is received, Azure’s recursive resolver fleet provides public DNS resolution.
  • Fully Managed Native Solution: No need to deploy and maintain IaaS-based DNS servers.
  • Simplified Private Link Integration: Enhances usability and adoption of Private Link and Private DNS configurations.
  • Configurable via API, CLI, and PowerShell: The feature is already available, with Azure Portal support rolling out in the next two weeks.

This resolution policy is enabled at the Virtual Network Link level. In the Azure Portal, users can enable this feature by selecting “Enable fallback to internet” in the virtual network link configuration.

With this enhancement, Azure provides a more flexible and efficient DNS resolution experience for customers implementing private networking solutions.

Azure Firewall Updates – Increased IP Group Limits Now Generally Available

Azure has doubled the IP Group limit in Azure Firewall policies, increasing the maximum from 100 to 200 per policy.

Key Benefits:

  • Better Policy Organization: Allows management of more IP addresses within a single firewall policy.
  • Greater Flexibility: Optimizes configurations for complex network security needs.

This enhancement improves scalability and efficiency in managing large-scale network security policies, providing greater flexibility for enterprises using Azure Firewall.

Azure Firewall Updates – BYOIP Support for Secured Virtual Hubs (Preview)

Azure Firewall now supports Customer Provided Public IP (BYOIP) for Secured Virtual Hub deployments, allowing administrators to assign and manage customer-managed public IPs for new firewall instances.

Key Benefits

  • Full Control: Customers can own and manage the lifecycle of their firewall’s public IPs.
  • Enhanced Security: Enables DDoS mitigation for better protection against cyber threats.
  • IP Address Flexibility: Public IPs can be allocated from an IP prefix pool, offering more control over network configurations.

This update enhances security, flexibility, and manageability for customers leveraging Azure Firewall in Secured Virtual Hubs.

Storage

Azure File Sync v20 Agent Now Available

The Azure File Sync v20 agent is now flighting and available on the Microsoft Update Catalog. Servers configured for automatic updates will receive the latest version when available.

Managed Identities Preview Enhancements

Azure File Sync support for managed identities (preview) was first announced in November 2024. Since then, Microsoft has introduced the following improvements:

  • Portal Integration:
    • You can now configure Azure File Sync with managed identities via the Azure Portal.
    • This feature will be gradually enabled across all regions in the next few weeks.
  • Storage Account Security Improvements:
    • The following settings on your storage account are no longer required and can now be disabled:
      • Allow storage account key access
      • Allow Azure services on the trusted services list to access this storage account

These updates enhance security and simplify management by enabling a more secure, identity-based authentication approach for Azure File Sync deployments.

Modern Version of the Azure Storage Data Movement Library Now Generally Available

The modern version of the Azure Storage Data Movement Library has reached General Availability, delivering a streamlined and efficient data transfer experience for Azure Blob and Azure File Storage users.

This update introduces enhanced capabilities, including:

  • Progress Tracking: Monitor real-time transfer status.
  • Pause and Resume: Gain flexibility in managing data transfers.
  • Checkpointing: Resume transfers from the last saved state in case of interruptions.

Additionally, the library now shares infrastructure with the modern v12 Azure Storage libraries, improving integration with Azure Identity packages to align with modern security standards. These improvements simplify and enhance data movement in Azure.

Azure Premium SSD v2 Disk Storage and Azure Ultra Disk Storage Now Available in New Zealand North

Azure Premium SSD v2 Disk Storage and Azure Ultra Disk Storage are now generally available in the New Zealand North region, enhancing Azure’s global storage capabilities. Premium SSD v2 delivers sub-millisecond latencies for IO-intensive workloads at a low cost, offering the best price-performance ratio for general-purpose block storage. Optimized for demanding workloads like SQL Server, Oracle, SAP, big data analytics, and gaming, it ensures high performance, enterprise readiness, and cost efficiency. For regions where Premium SSD v2 is unavailable, Microsoft provides a survey for customers to express interest. Additionally, Azure Ultra Disk Storage, now available in the same region, offers high throughput, high IOPS, and consistently low latency, further empowering enterprises with scalable and performant storage solutions.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (February 2025 – Weeks: 05 and 06)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Azure VMware Solution Now Available on Two Availability Zones in ItalyNorth

Azure VMware Solution (AVS) in the ItalyNorth cloud region now supports deployment across two availability zones, enhancing resiliency and disaster recovery capabilities.

With this update, AVS hosts can be provisioned across two availability zones, enabling organizations to implement robust Disaster Recovery (DR) scenarios through VMotion, ensuring seamless workload mobility between zones. This advancement strengthens business continuity for critical infrastructures, making ItalyNorth a viable and secure option for hosting VMware workloads in Azure.

Azure AI Speech Service Now Available in ItalyNorth

Azure AI Speech Service is now accessible in the ItalyNorth region. This expansion allows businesses and developers in Italy to leverage the capabilities of Azure AI Speech Service closer to their operations, enhancing performance and reducing latency for speech-to-text, text-to-speech, and other speech-enabled applications. By being available in the ItalyNorth region, Azure AI Speech Service provides improved compliance with local data residency requirements, offering organizations greater control and assurance when handling sensitive data. This development underscores Azure’s commitment to meeting regional needs while delivering world-class AI capabilities.

Defender for Storage v2 Now Available in ItalyNorth

Defender for Storage v2, featuring Antimalware Scanning and Data Threat Detection, is now available in the ItalyNorth region. Part of Microsoft Defender for Cloud, this Azure-native security layer provides advanced threat detection and protection for storage accounts, enhancing the security of your data and workloads. Defender for Storage v2 helps prevent malicious file uploads, sensitive data exfiltration, and data corruption by analyzing telemetry from Azure Blob Storage, Azure Files, and Azure Data Lake Storage services. Powered by Microsoft Threat Intelligence, Microsoft Defender Antivirus, and Sensitive Data Discovery, it offers robust security capabilities, enabling organizations to detect and mitigate potential threats effectively. This service ensures both the integrity and security of your storage environments in ItalyNorth.

Compute

Changes to Instance Size Flexibility Ratios for Azure Reserved Virtual Machine Instances for M-series

Microsoft has updated the instance size flexibility ratios for Azure Reserved Virtual Machine Instances for M-series. This update, effective December 6, 2024, aims to optimize the reservation discounts within instance size flexibility groups and their corresponding SKUs. As Azure continues to expand its range of SKUs for M-series Virtual Machines, this adjustment ensures customers can maximize the value of their reservations while maintaining flexibility in their deployments. These changes reflect Azure’s commitment to providing cost-efficient and adaptable solutions for memory-intensive workloads.

Enhanced Support for Generation 2 VMs in Azure DevTest Labs (Preview)

Azure DevTest Labs now supports enhanced capabilities for Generation 2 Virtual Machines (VMs), allowing users to choose between Generation 1 and Generation 2 versions of the same marketplace image. Generation 2 VMs offer key advantages over their Generation 1 counterparts, including:

  • Increased memory support for workloads that require higher RAM capacity.
  • Intel Software Guard Extensions (Intel SGX) for enhanced security and confidential computing.
  • Virtualized Persistent Memory (vPMEM) to improve storage performance for applications that benefit from persistent memory.

With this enhancement, Azure DevTest Labs continues to expand its flexibility and efficiency for developers and testers working with virtualized environments.

Reduce Costs with Hibernation in Azure DevTest Labs (Preview)

Azure DevTest Labs now offers hibernation for virtual machines (VMs), a feature designed to help organizations optimize cloud costs. With this public preview, customers can pause VMs while preserving their state, allowing them to resume work seamlessly without losing progress.

Key benefits of the hibernation feature include:

  • Cost Savings: Hibernated VMs do not incur compute costs, similar to a stopped (deallocated) state.
  • Resource Optimization: Users only pay for storage (OS disk, data disks) and networking resources (such as IP addresses) attached to the VM.
  • Seamless Resumption: VMs can quickly return to their previous state, improving workflow efficiency.

This feature provides a cost-effective way to manage virtualized environments while maintaining productivity.

Networking

New Origin Types for Azure Front Door Premium Private Link-Enabled Origins (Preview)

Azure Front Door Premium now supports additional Private Link-enabled origin types, including Application Gateway, API Management, and Container Apps. This enhancement allows organizations to securely deliver content through public Front Door endpoints while keeping their origins isolated from the public internet.

By leveraging Private Link-enabled origins, customers can enhance security, reduce exposure to external threats, and maintain a seamless and reliable content delivery experience. This update expands the flexibility of Azure Front Door Premium, providing more options for securely integrating backend services with Front Door’s global edge network.

Storage

Next-Generation Azure Data Box Devices (Preview)

Azure has announced the public preview of Azure Data Box 120 and Azure Data Box 525, the next-generation NVMe-based Data Box devices designed to accelerate offline data transfers to Azure. These new devices offer several enhancements, including:

  • Fast Copy: NVMe drives provide high-speed transfers, improved reliability, and support for faster network connections.
  • Ease of Use: The compact design includes a larger capacity option of up to 525 TB for simplified handling.
  • Resilience: Ruggedized devices are built to withstand harsh transport conditions.
  • Enhanced Security: Advanced physical, hardware, and software security features ensure data protection.
  • Broader Availability: The devices are now available in the US, Canada, EU, UK, and US Gov Azure regions, with plans to expand further.

These improvements make Azure Data Box an efficient and secure solution for large-scale data migration to Azure.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (January 2025 – Weeks: 03 and 04)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Troubleshoot Disk Performance with Copilot in Azure (preview)

The Disk Performance Troubleshooting Capability for Azure Copilot is now available in Public Preview. This feature allows users to optimize disk performance seamlessly through Azure Copilot. By leveraging a comprehensive range of disk metrics, Azure provides detailed insights into the performance of Virtual Machines (VMs) and disks, enabling users to identify and address performance bottlenecks. Azure Copilot enhances this process by analyzing these metrics and offering guided recommendations to improve VM and disk performance, ensuring a superior application experience.

Azure Confidential Ledger Achieves ISO 27001 Certification

Azure Confidential Ledger has achieved ISO 27001 certification, a globally recognized standard for information security management systems (ISMS). This certification highlights the implementation of a comprehensive framework designed to manage and safeguard customer data effectively. By meeting ISO 27001 compliance requirements, Azure Confidential Ledger demonstrates its commitment to exceeding industry standards. This achievement assures customers that they can rely on Azure Confidential Ledger to securely manage their most sensitive and critical workloads, reinforcing trust in its robust security capabilities.

Networking

WebSocket Support in Application Gateway for Containers

Azure has introduced WebSocket support in Application Gateway for Containers, enabling interactive and real-time applications such as chat platforms, live dashboards, and gaming services to achieve better performance and reduced latency. This enhancement provides several benefits:

  • Bidirectional Communication: Facilitates two-way data exchange between clients and servers.
  • Reduced Latency: Enhances application performance through faster data transmission using full-duplex communication over a single TCP connection.
  • Improved User Experience: Delivers more engaging and responsive applications for end-users.

This addition significantly boosts the capabilities of Application Gateway for Containers, making it ideal for applications requiring real-time interactivity.

Storage

Customer Managed Unplanned Failover for Azure Data Lake Storage and SSH File Transfer Protocol

Customer managed unplanned failover for Azure Data Lake Storage (ADLS) and storage accounts with SSH File Transfer Protocol (SFTP) enabled is now generally available. This feature empowers users to failover their geo-redundant (GRS) or geo-zone-redundant (GZRS) storage accounts to a secondary region when primary storage service endpoints become inaccessible. During a failover, the secondary region becomes the new primary, redirecting all storage service endpoints and restoring write access to the account.

Previously, unplanned failover support was limited to Blobs, Tables, Files, and Queue data. Now, this capability extends to include Azure Data Lake Storage and SFTP-enabled accounts. After resolving the primary region’s outage, users can reconfigure geo-redundancy and fail back to the original primary region, ensuring greater resilience for mission-critical storage solutions.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (January 2025 – Weeks: 01 and 02)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Msv3 and Mdsv3 Series Now Available on ItalyNorth

The Msv3 and Mdsv3 High Memory (HM) Virtual Machine (VM) series are now available in the ItalyNorth region. These VMs represent the next generation of memory-optimized sizes, offering significant advancements in performance, cost efficiency, and resilience compared to their predecessors, the Mv2-series VMs. The Mv3 HM series supports configurations with memory ranging from 6TB to an impressive 16TB. These VMs deliver up to 8,000 MBps throughput to remote storage and provide up to 25% improvements in networking performance over earlier generations, making them an excellent choice for memory-intensive workloads.

ND H100 v5 GPU-Powered VM Now Available on ItalyNorth

Azure has introduced the ND H100 v5 series virtual machines (VMs) in the ItalyNorth region, expanding its portfolio of GPU-powered instances. This flagship series is engineered for demanding deep learning training and generative AI workloads, as well as high-performance computing (HPC) applications. The ND H100 v5 series starts with a single VM containing eight NVIDIA H100 Tensor Core GPUs and can scale to deployments involving thousands of GPUs. Each VM offers 3.2 Tbps of interconnect bandwidth and a dedicated 400 Gb/s NVIDIA Quantum-2 CX7 InfiniBand connection for each GPU, ensuring optimized performance. These VMs feature NVLINK 4.0 for intra-VM communication and are powered by 96 physical fourth Gen Intel Xeon Scalable processor cores. Designed to integrate seamlessly with AI and ML frameworks like TensorFlow, PyTorch, and RAPIDS, as well as HPC tools leveraging NVIDIA’s NCCL communication libraries, the ND H100 v5 series provides unparalleled scalability and performance for AI-driven innovations.

Storage

Azure NetApp Files Enhances Minimum Volume Size to 50 GiB

Azure NetApp Files now supports a minimum volume size of 50 GiB, reducing the previous limit of 100 GiB. This improvement caters to workloads requiring smaller volumes, such as Kubernetes, allowing customers to optimize storage volumes more effectively. By right-sizing volumes in the range of 50 GiB to 100 GiB, organizations can achieve cost savings and maximize capacity pool utilization. The feature is accessible across all Azure NetApp Files-enabled regions, further broadening its usability for diverse storage needs.

Azure Files Introduces Provisioned v2 Billing Model for HDD (Standard)

The provisioned v2 billing model for Azure Files HDD (standard) is now generally available, offering customers greater control and predictability in managing their storage costs. This model allows independent provisioning of storage, IOPS, and throughput, ensuring alignment with specific performance requirements. With enhanced scalability and performance, customers can configure file shares up to 256 TiB, with 50,000 IOPS and 5 GiB/sec of throughput. Additionally, provisioned v2 enables per-share monitoring for better resource management. Currently, this feature is available in select Azure regions, making it a versatile option for businesses with varying storage needs.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Local: announcements and updates (December 2024 – Weeks: 51 and 52)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Local, as officially released by Microsoft in the past two weeks.

Azure

General

Italy North – Azure AI Vision

Azure AI Vision is now available in the Italy North region. This expansion allows businesses and developers in the region to leverage Azure’s advanced computer vision capabilities, including image and video analysis. By utilizing the local datacenter, users can benefit from reduced latency and meet regional compliance requirements. Azure AI Vision empowers organizations to build intelligent applications with enhanced performance and accessibility tailored to their geographical needs.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.