Category Archives: Azure Networking

Azure IaaS and Azure Stack: announcements and updates (June 2024 – Weeks: 25 and 26)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

Compute

Upgrade Policies for Virtual Machine Scale Sets with Flexible Orchestration (preview)

Azure has introduced public preview support for upgrade policies in Virtual Machine Scale Sets with Flexible Orchestration. Previously available only for Uniform Orchestration, these policies—Automatic, Manual, and Rolling—now extend to Flexible Orchestration. The Rolling upgrade policy also includes the MaxSurge option to create new instances with the updated scale set model, replacing virtual machines using the old model.

ED25519 SSH Key Support for Linux Virtual Machines (preview)

Azure now supports ED25519 SSH key pairs for Linux virtual machines, enhancing security and performance with a smaller key size compared to RSA encryption. Customers can create ED25519 SSH key pairs directly within the Azure Portal and use them via Azure CLI and PowerShell, simplifying key management while improving security and deployment efficiency.

Networking

Azure Cross-Subscription Load Balancer (preview)

Azure announces the public preview of cross-subscription load balancing. This feature allows load balancer components to be located in different subscriptions, enabling the frontend IP address or backend instances to reside in separate subscriptions from the load balancer. Cross-subscription load balancing is available in all Azure public regions, China cloud regions, and Government cloud regions.

ExpressRoute Resiliency Enhancements (preview)

Azure introduces several enhancements to ExpressRoute for improved resiliency. Customers can now create ExpressRoute circuits with three levels of resiliency: maximum, high (ExpressRoute Metro), and standard. Zonal resiliency is also supported, allowing non-zone redundant gateways to migrate to availability zone-enabled gateways. Upcoming features include resiliency validation, insights, and a revised SLA model effective October 1, 2024, with differentiated levels of network availability.

JavaScript (JS) Challenge on Azure WAF Integrated with Azure Application Gateway (preview)

Azure Web Application Firewall (WAF) integrated with Azure Application Gateway now supports JavaScript (JS) challenge. The JavaScript challenge is an invisible web challenge used to distinguish between legitimate users and bots, protecting web applications by causing malicious bots to fail the challenge. This feature, part of the Bot Manager rule set and custom rules, reduces friction for legitimate users as it does not require human intervention.

Azure CDN Standard from Microsoft (Classic) Zero-Downtime Migration to Azure Front Door (preview)

Azure announces the public preview of zero-downtime migration from Azure CDN Standard from Microsoft (classic) to Azure Front Door. Azure Front Door is a modern cloud content delivery network (CDN) and global load balancer service that enhances security, performance, and scalability. The migration capability allows for a seamless transition to Azure Front Door Standard or Premium, offering improved security, flexible routing logic, and enhanced logging and metrics.

Storage

Force Detach Zone Redundant Data Disks During Zone Outage (preview)

Azure announces the public preview support for force detaching ZRS data disks from VMs affected by zone outages. This feature allows customers to detach ZRS data disks and attach them to another VM, reducing the Recovery Time Objective (RTO). Zone-redundant storage (ZRS) synchronously replicates Azure managed disks across three availability zones, providing 99.9999999999% (12 9’s) durability annually, and is supported on Premium SSDs and Standard SSDs.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (June 2024 – Weeks: 23 and 24)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

Compute

Azure VMware Solution: Microsoft and Broadcom to support license portability for VMware Cloud Foundation

Microsoft and Broadcom are expanding their partnership to support VMware Cloud Foundation subscriptions on Azure VMware Solution. This initiative allows customers who own or purchase VMware Cloud Foundation licenses to use them on Azure VMware Solution and in their own data centers, providing greater flexibility to adapt to changing business needs.

Key Benefits and Features:

  • License Portability: customers with eligible VMware Cloud Foundation entitlements can purchase subscriptions and use them interchangeably between on-premises environments and Azure VMware Solution. This flexibility supports seamless mobility and transfer of licenses as business requirements evolve.
  • Continued Purchase Options: customers can still buy Azure VMware Solution with VMware licenses included or use their own existing VMware licenses. This provides a range of purchasing options to suit different preferences and needs.

In addition to the new VMware license portability benefit, VMware Rapid Migration Plan provides an additional and comprehensive set of licensing benefits and programs to reduce the cost and time it takes for organizations to migrate to Azure VMware Solution:

  • Price Protection: customers can secure pricing for one, three, or five years through reserved instances.
  • Savings on Windows Server and SQL Server: organizations with Software Assurance for on-premises Windows Server and SQL Server licenses can benefit from the Azure Hybrid Benefit, allowing them to use these licenses on Azure VMware Solution. Additionally, free Extended Security Updates are available for older versions facing end of support.
  • Migration Support: the Azure Migrate and Modernize program offers resources, expert assistance, and funding from Microsoft and its partners to streamline the migration process.
  • Azure Credits: customers purchasing a new reserved instance for Azure VMware Solution can receive additional Azure credits, applicable to Azure VMware Solution or other Azure services.

This collaboration enhances the flexibility and cost-effectiveness of deploying VMware environments in the cloud, enabling businesses to optimize their operations and infrastructure with greater ease.

Storage

Azure NetApp Files Launch in Italy North Region

Azure NetApp Files has expanded its availability to the Italy North Azure Region. This expansion allows customers in the region to leverage high-performance file storage solutions, enhancing their ability to manage and scale their data storage needs efficiently.

Azure File Sync Agent v17.3 and v18.1 Security-Only Updates Released

Microsoft has announced the release of the Azure File Sync agent versions v17.3 and v18.1, focusing solely on security updates. The v17.3 update addresses a critical issue that might have allowed unauthorized users to delete files in restricted locations, as outlined in CVE-2024-35253. This update is available for servers running Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022, and is applicable to servers with agent versions v16.x and v17.x installed. The corresponding agent version is 17.3.0.0, with installation instructions detailed in KB5039814.

Similarly, the v18.1 update is targeted at servers with the v18 agent version installed and is compatible with Windows Server 2016, Windows Server 2019, and Windows Server 2022. The agent version for this release is 18.1.0.0, with installation instructions available in KB5023058. Notably, these updates are distributed through Microsoft Update and not the Microsoft Download Center. The next release, version 18.2, expected in the coming weeks, will be available across all prior versions of Azure File Sync agents and through multiple distribution channels, including the Microsoft Download Center, Microsoft Update, and Microsoft Update Catalog.

Azure Stack

Azure Stack HCI

Azure Stack HCI – 2405 Update

The Azure Stack HCI, version 23H2, introduces multiple release trains including 2306 (limited release), 2311, 2402, and now 2405. Each release train encompasses a baseline build and subsequent updates. The baseline build is the initial software version in a release train, and upgrading to the next version within the same train necessitates deploying the baseline build first.

The baseline update 2405 addresses several issues and improvements. Key fixes include:

  • During cluster deployments with a large Active Directory, a timeout issue when adding users to the local administrator group has been resolved.
  • New ARM templates for cluster creation are released, simplifying the creation of dependency resources and addressing missing mandatory fields.
  • The secret rotation PowerShell command Set-AzureStackLCMUserPassword now supports a parameter to skip the confirmation message.
  • Secret rotation reliability is improved, especially when services do not restart promptly.
  • Deployment is now enabled when a disjoint namespace is used.
  • Fixed an issue in deployment related to setting the diagnostic level in Azure and on the device.
  • A new PowerShell command is released to update the SBE partner property values provided at deployment.
  • An issue preventing the update service from responding after an SBE-only update run is fixed.
  • An issue preventing a node from joining Active Directory during an add server operation is resolved.
  • Improved reliability of Network ATC when configuring host networking with certain network adapter types.
  • Enhanced reliability in detecting firmware versions for disk drives.
  • Update notifications for health check results sent from the device to AUM (Azure Update Manager) are improved. Previously, large message sizes caused no results to be shown in AUM.
  • Fixed a file lock issue causing update failures for the trusted launch VM agent (IGVM).
  • Resolved an issue preventing the orchestrator agent from restarting during an update run.
  • Addressed a rare condition causing delays in the update service discovering or starting an update.
  • Fixed an issue with Cluster-Aware Updating (CAU) interaction with the orchestrator when an update is in progress.
  • The naming schema for updates is adjusted to differentiate between feature and cumulative updates.
  • Enhanced reliability in reporting cluster update progress to the orchestrator.
  • Resolved an issue where the Azure Arc connection was lost when the Hybrid Instance Metadata service (HIMDS) restarted, ensuring the device now automatically reinitiates the Azure Arc connection.

Known issues in this release involve:

  • When viewing readiness check results for an Azure Stack HCI cluster via the Azure Update Manager, there may be multiple readiness checks with the same name.
  • During the registration of Azure Stack HCI servers, an error may appear in the debug logs: “Encountered internal server error. One of the mandatory extensions for device deployment may not be installed.”
  • There is an intermittent issue where the Azure portal incorrectly reports the update status as “Failed to update” even though the update is complete.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (June 2024 – Weeks: 21 and 22)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

RISE with SAP is Available on ItalyNorth Azure Region

RISE with SAP, a comprehensive Platform-as-a-Service offering, is now accessible in the ItalyNorth Azure Region. This service bundles SAP software licensing, cloud infrastructure, and managed services under a single SAP contract, applicable to R3, SAP Business Suite, and S/4HANA. This availability in the Italy North region aims to provide localized support and optimized performance for enterprises utilizing SAP solutions.

Update on Inter-Availability Zone Data Transfer Pricing

Azure has announced that it will no longer charge for data transfers across availability zones, regardless of whether private or public IPs are used on Azure resources. Availability zones enable Azure services to enhance greater resiliency for customers’ cloud infrastructure. This change aims to further encourage and support customers’ efforts in building more resilient and efficient applications and solutions on Azure.

Activity Log Alerts Can Now Run in EU Data Boundary

Activity log alert rules can now be saved in one of the following EU Data Boundary regions: North Europe and West Europe. This capability is available when creating a new activity log alert rule. Saving the rule in a European region ensures that the alert rule metadata and its processing remain within the EU Data Boundary. In all other cases, users can select the default Global region. Additionally, action groups can also be saved in EU regions, allowing for an end-to-end experience within Europe, encompassing alert evaluation and actions.

Next-Gen Dashboards Experience in Azure Portal (preview

A new Dashboards experience within the Azure Portal has been introduced. This experience includes a richer editing experience, dashboard as a view, mobile support, and works in parallel with the current experience. Currently, dashboards provide a focused and organized view of cloud resources in the Azure portal, allowing users to monitor resources and quickly launch tasks for day-to-day operations. The new experience is accessible through the Dashboard Hub, the Browse experience, and the Azure Mobile app. Users can create new dashboards or transform existing ones into the new experience. Both the new and current experiences will run in parallel to ensure parity and safely roll out new features.

Compute

VM Hibernation for General Purpose VMs

VM hibernation for general-purpose VMs is now generally available in all public regions. Hibernation is supported on both Linux and Windows operating systems. This feature enables users to hibernate their VMs to save compute costs. When a VM is hibernated, Azure persists the VM’s in-memory state in the OS disk and deallocates the VM, so users do not have to pay for the VM during hibernation, only for associated storage and networking resources. When the VM is restarted, applications and processes resume from their previous state, allowing users to quickly pick up from where they left off. This feature can be used on both existing and new VMs.

Azure Cobalt 100 Arm-based Virtual Machines (preview)

Microsoft is announcing the preview of the new Cobalt 100 Arm-based virtual machines (VMs). These are the first generation of VMs that feature the new Cobalt 100 chipset, custom-built using an Arm-based architecture, and optimized for efficiency and performance when running general-purpose and cloud-native workloads. Users can expect up to 40% improved performance compared to the previous generation of Arm-based Azure VMs. These VMs offer performance consistency and linear performance scaling with workloads like web applications, microservices, and open-source databases.

Azure Compute Fleet (preview)

Azure is pleased to announce the public preview of Azure Compute Fleet, a new service that streamlines the provisioning and management of Azure compute capacity across different virtual machine (VM) types, availability zones, and pricing models to achieve desired scale, performance, and cost. Azure Compute Fleet provides features to deploy and manage diverse groups of VMs at scale, including integration of multiple pricing models within a single fleet request, automated configuration of a fleet of VMs, and adjustable settings to prioritize deployment speed, operational cost, or a balance of both. It can manage and deploy up to 10,000 VMs in a region within a single fleet, providing flexibility and reliability through automated spot VMs, VM mix, and cross-zonal deployment features.

Networking

Azure Firewall: New Regions Availability

To meet new workload demands, Azure Firewall Basic, Standard, Premium, and Azure Firewall Manager are now generally available in four new regions: Israel Central, Italy North, Mexico Central, and Spain Central. With these new regions, Azure Firewall is now available in 64 regions worldwide, utilizing the Microsoft global network backbone.

Azure Firewall Integration in Microsoft Copilot for Security (preview)

The public preview of Azure Firewall integration in Microsoft Copilot for Security is now available. This feature allows users to retrieve the top IDPS signature hits for an Azure Firewall, enriching the threat profile of IDPS signatures with additional details. Users can perform fleet-wide searches for threats across all their Firewalls and generate recommendations to secure their environment using Azure Firewall’s IDPS feature.

Azure Web Application Firewall (WAF) Integration in Microsoft Copilot for Security (preview)

Azure Web Application Firewall (WAF) integrated into the Microsoft Copilot for Security standalone experience is now available in public preview. This integration is available with both Azure Front Door WAF and Azure Application Gateway WAF. It provides top WAF rules triggered analysis, generating summaries of WAF requests blocked due to web application and API attacks. Additionally, it includes an analysis of the top offending IPs, highlighting malicious IPs in customer environments along with related WAF rules triggered. The SQL injection and cross-site scripting WAF detection summaries provide contextual details about WAF blocks, including WAF rules, pattern matches, and related IPs.

Azure Application Gateway v2 Basic SKU (preview)

The Application Gateway Basic SKU is a new offering within the Application Gateway family, designed for small and medium-sized customers. It is ideal for applications with lower traffic and SLA requirements that do not need advanced traffic management features. The Basic SKU includes built-in high availability and supports HTTP2/HTTPS and WebSocket protocols. It offers core application-level load balancing features such as URL-based, host-based, and multi-site routing, along with cookie-based affinity. It supports flexible backends, including AKS, VMSS, App Services, and on-premises deployments. Customers can select the Basic SKU either directly from the Azure Portal or through their preferred scripting languages.

Azure Load Balancer Health Event Logs (preview)

Azure Load Balancer health event logs are now available in public preview. These logs enable users to collect, store, and analyze information to understand the health of their Azure Load Balancer resources. They help troubleshoot specific scenarios and identify availability issues affecting the load balancer. Examples include traffic distribution issues, port exhaustion, and the absence of healthy backends. Health event logs allow monitoring of load balancer health without the need for complex metric-based alerts or custom data ingestion pipelines. The preview is currently rolling out to all public regions.

Azure Front Door Server Variable Enhancement Generally Available

Azure Front Door’s rule set and server variable feature, allowing dynamic modification of request and response at the edge, is now generally available. This feature enables the redirection of clients based on request information, URL rewriting, and HTTP header modifications. It supports security headers to prevent browser-based vulnerabilities, routing requests based on geographic or device data, and applying different caching policies. The new enhancement includes support for URL path segment capture and rewrite, adding more flexibility for users needing to manipulate URL paths dynamically.

Azure Virtual Network Manager’s virtual network verifier (preview)

Virtual network verifier enables users to check if their network policies allow or disallow traffic between their Azure network resources, helping them answer simple diagnostic questions, triage why reachability isn’t working as expected, and prove conformance of their Azure setup to their organization’s security compliance requirements. Within their network manager resource, users can access Virtual Network Verifier’s capabilities by creating a verifier workspace, then defining reachability analysis intents that capture the traffic they want to evaluate. Once they run an analysis on their intent, they can visualize the reachability outcome and parse the reachability analysis results’ JSON. Virtual network verifier’s reachability analysis evaluates several Azure policies and resources within the network manager’s scope. Users can even delegate Virtual Network Verifier resources to non-network manager users for troubleshooting reachability.

Azure Bastion Premium (preview)

Azure Bastion Premium is a new SKU targeting customers handling highly sensitive virtual machine workloads. Its mission is to offer enhanced security features that ensure customer virtual machines are connected securely and to monitor VMs for any anomalies that may arise. The first set of features focuses on ensuring private connectivity and graphical recordings of virtual machines connected through Bastion. With the new Azure Bastion Premium SKU, users can now record all virtual machine sessions that are connected via a session-recording Bastion and view the configured session recording. Additionally, users can connect to Bastion via a private endpoint.

Azure Load Balancer now supports Admin State (preview)

Azure has announced the public preview of Azure Load Balancer Administrative State (Admin State) to simplify and enhance the management of VMs in the backend pool of Azure Load Balancer. With Admin State, users can override the Load Balancer’s health probe behavior for each individual backend pool instance (usually VMs or VMSS instances) without making changes to network security rules or closing ports on their VM. Users can set the Admin State of the backend instance to be up or down, overriding the Load Balancer health probe. This setting changes how the Load Balancer directs new or existing connections to the backend instance. Admin State allows for easy removal of virtual machines from the backend pool for maintenance, patching, or applying fixes without additional overhead of closing ports or updating security rules. Admin State is available in all Azure public regions, Azure China cloud regions, and Azure Government cloud regions.

Storage

Azure NetApp Files Backup

Azure NetApp Files has enhanced its online snapshots with the addition of backup capabilities. This new feature allows users to offload their Azure NetApp Files snapshots to a Backup Vault efficiently and cost-effectively, protecting data from accidental deletion. The backup mechanism extends Azure NetApp Files’ snapshot technology by only copying and storing changed data blocks relative to previously vaulted snapshots. These vaulted snapshots are represented in full and can be restored individually and directly, which eliminates the need for an iterative full-incremental recovery process.

Azure NetApp Files Support for Large Volumes up to 500TiB in Size

Azure NetApp Files now supports the creation of large volumes ranging from 50TiB to 500TiB, significantly expanding beyond the previous 100TiB limit. This enhancement supports various high-performance computing (HPC), AI/ML, and large file content repositories that require a single namespace. Additionally, these large volumes feature cross-zone and cross-region replication, ensuring data resilience and business continuity. HPC workloads, crucial for simulating processes and electronic design automation, benefit from enhanced data protection and availability. AI/ML workloads, involving extensive datasets, gain improved security and recovery options, while large file repositories enjoy optimized cost and scale with robust data protection.

Azure NetApp Files Application Volume Group for Oracle (preview)

The application volume group (AVG) for Oracle is now in public preview, enabling the deployment of all necessary Azure NetApp Files volumes for Oracle databases in a single, optimized workflow. This feature ensures that all volumes are placed in the same availability zone as the VMs, optimizing latency and performance. With technical improvements that streamline the deployment process, this feature supports various Oracle database layouts from small to multi-hundred TiB sizes. It promises reduced deployment times and enhanced application performance and stability across all Azure NetApp Files enabled regions.

Azure NetApp Files support for Active Directory connection per NetApp account (preview)

The Azure NetApp Files support for Active Directory connection per NetApp account feature now allows each NetApp account to connect to its own Active Directory Forest and Domain, providing the ability to manage more than one Active Directory connection within a single region under a subscription. This enhancement enables distinct Active Directory connections for each NetApp account, facilitating operational isolation and specialized hosting scenarios. Active Directory connections can be configured multiple times for multiple NetApp accounts to make use of it. With the creation of SMB volumes in Azure NetApp Files now tied to these Active Directory connections in the NetApp account, the management of Active Directory environments becomes more scalable, streamlined, and efficient. Additionally, the public preview for the “Shared AD support for multiple accounts to one Active Directory per region per subscription” feature is concluding, and new registrations will no longer be accepted. Customers are recommended to transition to this new capability instead.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (May 2024 – Weeks: 19 and 20)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

The Availability of Azure Compute Reservations Will Continue Until Further Notice

Initially planned to end on January 1, 2024, the availability of Azure compute reservation exchanges for Azure Virtual Machine, Azure Dedicated Host, and Azure App Service has been extended indefinitely. Customers can continue exchanging their compute reservations for different instance series and regions until further notice, with a minimum of six months’ notice prior to any changes. Additionally, any compute reservations purchased during this extended period will retain the right to one more exchange after the grace period ends. This extension allows for better cost savings assessments and planning. For more information, see the updated Azure reservation exchange policy.

Microsoft Azure Now Available from New Cloud Region in Mexico

The first cloud region in Mexico is now available, providing organizations across the globe with access to scalable, highly available, and resilient Microsoft Cloud services. With Azure Availability Zones, the Mexico Central region strengthens Microsoft’s commitment to promoting digital transformation and sustainable innovation in the country. This new region connects Mexico to the world’s largest and most trusted global cloud infrastructure, delivering the highest standards of security, privacy, and regulatory-compliant data storage.

Cloud Services (Classic) Deployment Model Retirement (31 August 2024)

The Cloud Services (classic) deployment model will also be retired on 31 August 2024. Users must migrate their services to the Cloud Services (extended support) in Azure Resource Manager to benefit from new features like deployment templates, role-based access control, and regional resiliency. After the retirement date, Cloud Services deployments will be stopped, and data will be permanently lost unless migrated.

Compute

Ubuntu 24.04 LTS for Azure Virtual Machines

Ubuntu 24.04 LTS, also known as “Noble Numbat,” is now available for Azure Virtual Machines. This new release includes Linux kernel version 6.8 and systemd version v255.4, bringing new features, enhanced performance, enterprise security, and expanded support for .NET 8. Ubuntu 24.04 LTS images can be found in the Azure Marketplace, providing users with the latest advancements and improvements for their virtual machines.

Standby Pools for Virtual Machine Scale Sets with Flexible Orchestration (preview)

Azure introduces the public preview of Standby Pools for Virtual Machine Scale Sets with flexible orchestration, a feature designed to enhance scaling performance by establishing a pool of pre-provisioned virtual machines. These standby pools expedite the scale-out process by undergoing initialization tasks such as software installation and data loading in advance. The number of virtual machines in a standby pool is dynamically adjusted based on the maximum ready capacity minus the virtual machines already deployed in the scale set. When scaling down, virtual machines are deleted as per the configured scale-in policy, and the standby pool refills accordingly. Virtual machines within the standby pool can either be kept running—recommended for scenarios with strict latency and reliability requirements—or be deallocated to save costs while still maintaining quick scale-out capabilities.

Networking

ExpressRoute Seamless Gateway Migration

ExpressRoute customers can now benefit from a seamless migration to a new Gateway SKU that supports Availability Zones. This update facilitates the migration of Public IP configurations from Basic to Standard without the need to delete and recreate existing virtual network gateways. The new feature provides a guided experience, allowing for seamless migration of circuit connections by deploying a second gateway to the Gateway Subnet, thus improving the overall migration process and reducing downtime.

Azure Front Door Log Scrubbing of Sensitive Data is Generally Available

Azure Front Door’s log scrubbing tool has reached General Availability, providing a secure way to remove sensitive data such as personally identifiable information (PII) from Azure Front Door access logs. By enabling log scrubbing at the Azure Front Door profile level, users can choose specific log fields to scrub. The tool then replaces sensitive information in the logs with “****,” ensuring sensitive data like customer passwords, client IPs, and socket IPs are protected.

Azure Front Door Server Variable Enhancement Generally Available

Azure Front Door now offers enhanced server variable functionality, allowing dynamic modification of requests and responses at the edge. With this feature, users can redirect clients based on request information, rewrite URLs, paths, and query strings, and insert, modify, or delete HTTP headers. Security headers can be implemented to prevent browser-based vulnerabilities, and requests from different countries or devices can be routed to different origins. Additionally, different caching policies can be applied based on content type. New capabilities include support for URL path segment capture and rewrite, enabling more flexible handling of dynamic URLs. For example, if an incoming URL path includes variable-length GUIDs, these can be extracted and inserted elsewhere in the URL path using URL Rewrite rules. For more details, refer to the Azure Front Door documentation.

Retirement of Five Azure Classic Networking Services (31 August 2024)

As announced in August 2021, Azure will retire its classic networking services—including Azure Cloud Services (classic), Classic Virtual Network, reserved IP addresses, Azure ExpressRoute Gateway, Azure Application Gateway, and Azure VPN Gateway—on 31 August 2024. Users are advised to migrate their resources to the Azure Resource Manager deployment model before this date to avoid any service disruptions. The Azure Resource Manager model offers simplified resource deployment, enhanced resource grouping, and the ability to apply access control policies at a group level.

Azure Application Gateway v2 Basic SKU (preview)

The Application Gateway Basic SKU is a new addition to the Application Gateway family, designed for small and medium-sized customers. This SKU is ideal for applications with lower traffic and SLA requirements that do not require advanced traffic management features. It includes built-in high availability and supports HTTP2/HTTPS and WebSocket protocols. Core application-level load balancing features such as URL-based, host-based, and multi-site routing, along with cookie-based affinity, are also included. The Basic SKU supports flexible backends, including Azure Kubernetes Service (AKS), Virtual Machine Scale Sets (VMSS), App Services, and on-premises deployments. Customers can select the Basic SKU directly from the Azure Portal or through their preferred scripting languages.

Storage

Azure File Sync Agent v18 Release

The Azure File Sync agent v18 is now available through Microsoft Update Catalog, offering enhanced capabilities for server provisioning and disaster recovery for Azure File Sync server endpoints. Key improvements include faster server provisioning times—significantly reducing the duration from hours or days to much quicker readiness. This is especially beneficial when creating the first server endpoint of a new sync topology after data is transferred to the Azure File Share, or adding a new empty server endpoint to an existing sync topology. Additional upgrades include enhanced sync performance for initial uploads and high-volume file changes, such as ACL adjustments, alongside miscellaneous reliability and telemetry enhancements for cloud tiering and sync. This release supports Windows Server 2016, 2019, and 2022.

Premium SSDv2 Now Available in Italy North Azure Region with Two Availability Zones (3rd AZ Coming Soon)

Microsoft has announced that Premium SSDv2 is now available in the Italy North Azure region, featuring support for two Availability Zones. This offering ensures high performance and availability for users in the region. A third Availability Zone is on the horizon, enhancing redundancy and fault tolerance.

Azure Ultra Disk Storage Now Available in Italy North

Azure Ultra Disk Storage, known for its high throughput, high IOPS, and consistently low latency, is now available in the Italy North region. This storage solution is ideally suited for data-heavy applications such as SAP HANA, top-tier databases, and transaction-intensive workloads, providing robust and reliable disk storage for Azure virtual machines.

Azure Storage Actions (preview)

Azure Storage Actions has expanded its preview to 14 additional Azure public regions. This fully managed platform simplifies data management operations for Azure Blob Storage and Azure Data Lake Storage by merging serverless infrastructure with a no-code user experience. Azure Storage Actions is designed to be high-performing, cost-efficient, and scalable, automatically adjusting to the size and needs of your data management tasks. Now in public preview in regions including Australia East, Brazil South, Canada Central, and several others across the globe, Azure Storage Actions offers a versatile solution for automating data management in Azure environments.

NFS Azure Files Volume Mount Support in Azure Container Apps (preview)

Azure Container Apps now supports mounting Network File System (NFS) Azure Files volumes, currently in public preview. This feature enhances the scalability and performance of file systems used by containerized applications. NFS Azure Files volumes are ideal for sharing data between multiple containers or maintaining data persistence across container restarts, providing a robust solution for application data management and storage needs.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (May 2024 – Weeks: 17 and 18)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

Azure Governance Update – Management Groups

Beginning May 3, 2024, Azure will commence enabling the root management group for tenants that have not yet enabled it. This proactive step aligns with best practices for applying Azure Policy and reduces the initial setup work for following governance best practices. Upon creation of the root management group, all subscriptions will become children of this group, facilitating efficient management and compliance enforcement. This update does not alter access permissions or change subscriptions’ configurations; rather, it streamlines governance processes and enhances organizational compliance with Azure Policy standards.

Extensibility Model in Azure Deployment Environments (preview)

Azure Deployment Environments introduces a new extensibility model, now available in public preview, aimed at empowering customers to customize their deployment workflows using various infrastructure-as-code (IaC) frameworks. This model enables users to harness their preferred IaC framework, such as Bicep, Terraform, or Pulumi, to tailor deployment workflows to meet specific organizational needs. With support for Terraform and Bicep, users can seamlessly integrate their chosen IaC framework into Azure Deployment Environments, enhancing flexibility and efficiency in app infrastructure provisioning.

Compute

Azure Dedicated Host – Redeploy (preview)

In a move towards enhancing service resilience and user control, Azure Dedicated Host introduces the “Redeploy” feature, now available in public preview. This feature simplifies the process of moving an Azure Dedicated Host and its associated Virtual Machines (VMs) from one node to another within the same hardware generation. Termed as user-initiated service healing, the redeploy process ensures minimal disruption to services while addressing issues caused by user configurations or underlying host infrastructure. With support available across all regions of the Azure public cloud, users can utilize the Azure Portal or CLI to initiate host redeployment, maintaining host properties while ensuring data integrity on VMs’ temporary disks.

Networking

Application Gateway Web Application Firewall (WAF) Inspection Limit & Size Enforcement

Azure’s Application Gateway v2, integrated with the regional Web Application Firewall (WAF), now provides enhanced control over inspection limits and size enforcement for WAF policies running Core Rule Set (CRS) 3.2 or later. This update enables users to finely tune request body inspection, maximum request body limit, and maximum file upload limit independently. Moreover, users can disable enforcement of these limits without compromising request body inspection. These enhancements empower users to manage WAF policies more effectively, allowing larger requests to pass through without impediment.

Virtual Network Flow Logs

Azure Network Watcher introduces Virtual Network Flow Logs, a new capability enabling users to capture detailed information about IP traffic within their virtual networks. Whether for usage monitoring, optimization, troubleshooting, compliance, or security analysis, flow logs offer valuable insights into network activity. Users can record network traffic at the scope of the virtual network, subnet, or Network Interface Card (NIC), facilitating audit and compliance requirements, identifying traffic patterns, troubleshooting connectivity issues, and detecting malicious activity. Flow data is stored in Azure Storage accounts and can be exported to various analysis tools and security solutions for further examination.

Azure Virtual Network Manager Security Admin Rule Generally Available

The Azure Virtual Network Manager Security Admin Rule is now generally available across all public regions. This rule empowers users to enforce security policies consistently across virtual networks, regardless of subscriptions or regions. By evaluating rules before network security groups (NSGs), organizations can standardize security enforcement, mitigate misconfigurations, and ensure compliance with company policies. With streamlined security management and default settings to prevent errors, users can enhance network security while simplifying operational complexities.

Azure Virtual Network Manager User-Defined Route (UDR) Management (preview)

Azure Virtual Network Manager introduces user-defined route (UDR) management in public preview, offering users the ability to define and apply routing rules across multiple subnets and virtual networks. With this feature, users can easily describe their desired routing behavior within Azure Virtual Network Manager, streamlining the application of routing rules at scale without manual configuration of route tables for each subnet. This capability allows for various scenarios, including routing traffic between spokes across different hubs and directing traffic to specific destinations based on predefined rules, enhancing network management and flexibility within Azure environments.

Storage

Ultra Disks now available on Italy North Azure Region

Azure users in the Italy North region can now leverage the power of Ultra Disks for their virtual machines. Ultra Disks offer high throughput, low latency, and consistent performance, making them ideal for I/O-intensive workloads. With Ultra Disks, users can experience enhanced storage capabilities to meet the demands of their applications while maintaining scalability and reliability.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (April 2024 – Weeks: 15 and 16)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

Announcing New Cloud Governance Guidance in the Microsoft Cloud Adoption Framework for Azure

Microsoft is pleased to announce a significant update to the Cloud Adoption Framework (CAF) for Azure, introducing new and enhanced cloud governance guidance. This update is a pivotal part of Microsoft’s dedication to facilitating effective cloud adoption strategies across various organizations. The revised governance guidance covers critical areas such as identity, cost, resource, data, and AI governance, aiming to provide a comprehensive and accessible roadmap for organizations at any stage of their cloud journey. Whether it’s a startup aiming to scale operations efficiently or a large enterprise refining its governance practices, the new guidance is structured to support their evolving needs.

Retirement of Cloud Services (classic) Deployment Model (31 August 2024)

On 31 August 2024, Microsoft will retire the Cloud Services (classic) deployment model. Customers are advised to migrate their services to Cloud Services (extended support) in Azure Resource Manager before this date to avoid service disruption. The new deployment model offers significant improvements including deployment templates, role-based access control, and regional resiliency. Note that related services like Azure Virtual Network and Azure ExpressRoute gateway will also be retired, necessitating a migration to the Azure Resource Manager model which features enhanced resource deployment and management capabilities.

Compute

NVv4 Series VMs Now Available in Italy North Azure Region

Microsoft Azure has expanded its infrastructure offerings by making NVv4 Series Virtual Machines (VMs) available in the Italy North region. These VMs feature the AMD Radeon Instinct MI25 GPU and AMD EPYC 7V12 (Rome) CPU, offering robust performance options for computational and graphic-intensive applications. This deployment in Italy North provides local customers enhanced capabilities for graphics rendering, virtual desktop infrastructure (VDI), and AI workloads, further supporting the demands of diverse business environments in the region.

HBv4-series & HX-series VMs Now Available in Sweden Central

The HBv4-series and HX-series VMs are now available in the Sweden Central region. These VMs are equipped with up to 176 AMD EPYC™ 9V33X (“Genoa-X”) CPU cores and provide impressive memory and storage capacities. The HBv4-series VMs come with 768 GB of RAM, while the HX-series offers 1.4 TB of RAM. Both series feature a 2.3 GB L3 cache per VM, delivering substantial bandwidth capabilities. These VMs are particularly suitable for high-performance computing needs, featuring 400 Gb/s NDR InfiniBand from NVIDIA Networking to support supercomputer-scale workloads.

Networking

Azure Virtual Network Encryption Available in All Regions

Azure Virtual Network encryption is now available across all Azure regions, enabling encryption of traffic between Virtual Machines and Virtual Machines Scale Sets within the same virtual network, as well as between regionally and globally peered virtual networks. This rollout enhances the already robust encryption-in-transit capabilities of Azure, providing an additional layer of security for data traveling within the cloud infrastructure.

Azure Virtual Network Manager Network Groups in Public Preview

The use of Azure Virtual Network Manager network groups in security admin rules is now available in public preview. This feature allows administrators to use network groups in the source and/or destination of security rules, facilitating easier network isolation and management. With network groups, administrators can logically group virtual networks or subnets, enabling scenarios like segregating production from non-production environments. This capability simplifies the enforcement of traffic control, eliminating the need to manually identify CIDR ranges or resource IDs, thereby enhancing security administration across Azure environments.

Storage

Azure Data Box Disk Now Available with Hardware Encryption

Azure Data Box Disk is now generally available with AES-256 hardware encryption for Linux-based hosts. This new offering is available to customers in the US, EU, and Japan, providing an option to choose between software encryption (BitLocker) and hardware encryption (self-encrypted). These self-encrypted disks offer copy performance on Linux that is on par with BitLocker encrypted disks on Windows, enhancing data security and performance for Azure users.

New Disk Property: LastOwnershipUpdateTime

Microsoft Azure introduces a new property for Disks, named LastOwnershipUpdateTime, available in the Azure Portal, PowerShell (PS), and Command-Line Interface (CLI). This property indicates the time when the Disk’s ownership or state was last updated, providing a clear timeline of changes. It is particularly useful when used alongside the diskState to monitor and verify the current state of the Disk and its recent updates. This addition aims to enhance transparency and control for Azure users managing disk resources.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (April 2024 – Weeks: 13 and 14)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

Compute

Some Virtual Machines Size Will Be Retired

Microsoft Azure has announced the upcoming retirement of several virtual machine (VM) sizes within the NCv3-series, specifically the Standard_NC6s_v3, Standard_NC12s_v3, and Standard_NC24s_v3 VMs, scheduled for September 30th, 2025. Additionally, the Standard_NC24rs_v3 VM size will retire on March 31st, 2025. To ensure continuity and prevent service disruption, users are advised to transition their workloads to newer VM series within the same NC product line. In a related update, support for Basic and Standard A-series VMs in Batch pools will conclude on August 31, 2024. Users are encouraged to migrate their Batch pools to Av2-series VMs or other supported VM sizes to benefit from enhanced memory per vCPU and faster SSD storage.

On-demand capacity reservations for Specialty SKUs (preview)

Azure now offers on-demand capacity reservations for specialty VM sizes, currently in Public Preview. This feature allows for the reservation of compute capacity with SLA for specific VM sizes including Mv3, NC-series (v3 and newer), NV-series (v2 and newer), and Lsv2 series. It introduces the ability to ensure compute capacity—with SLA guarantees—is available ahead of VM deployments, crucial for maintaining the availability of business-critical applications. On-demand capacity reservations can be used in any public Azure region or availability zone, for any length of time, without commitment. These reservations can also be combined with Azure Reserved VM Instances (RIs) to further reduce costs.

Networking

Azure Virtual Network Manager Security Admin Rule Generally Available in 45 Regions

Azure Virtual Network Manager’s security admin rule configuration feature is now generally available in 45 regions. This pivotal update empowers users to enforce security policies for their virtual networks comprehensively across subscriptions and regions globally. Positioned to be evaluated before network security groups (NSGs), these rules underscore a commitment to standardized security enforcement. They are designed to mitigate potential misconfigurations and oversights, thereby safeguarding critical services and ensuring adherence to company policies. The feature highlights the ease of managing security with reduced operational complexities and introduces a default setting to minimize errors in NSG setups. For detailed insights and use cases, the virtual network flow logs documentation offers guidance on monitoring traffic allowed or denied by these rules.

Rate Limiting on ExpressRoute Direct Circuits

The general availability of Rate Limiting for ExpressRoute Direct port circuits brings a significant Quality of Service (QoS) enhancement, allowing for precise control over bandwidth usage. This feature helps prevent performance and reliability issues by enabling throttling of traffic throughput in accordance with the configured bandwidth, thus avoiding the potential for circuits to burst beyond their allocated bandwidth. Rate Limiting is available for both Private Peering and Microsoft Peering, in all Azure public cloud regions, and can be enabled for individual circuits during or after their creation process.

ExpressRoute Metro for High Resiliency (preview)

In a significant advancement for network resilience, Azure announces the public preview of ExpressRoute Metro. This high-resiliency configuration is designed to provide multi-site redundancy through a dual-homed setup, allowing for diverse connections to two distinct edge sites within a city. Initially available in Amsterdam, Singapore, and Zurich, ExpressRoute Metro enhances the reliability and uptime of connectivity from on-premises networks to Azure. This addition introduces three tiers of resiliency for ExpressRoute – Standard, High, and Maximum – enabling customers to tailor their connectivity according to desired resilience levels.

Azure Front Door (classic) will be retired on 31 March 2027

On 31 March 2027, Azure Front Door (classic) will be retired for the public cloud. Users are encouraged to migrate to Front Door Standard or Premium by that date. Starting 1 April 2025, creation of new Front Door (classic) resources will no longer be possible via the Azure portal, Terraform, or any command line tools. However, modifications to existing resources will be allowed until its retirement. Azure Front Door Standard and Premium offer enhanced capabilities for static and dynamic content delivery, along with improved security, DevOps experiences, and pricing. Migration to these newer versions is recommended to avoid service disruptions and to take advantage of better integration with Azure services.

Storage

Azure File Sync Extension on Windows Admin Center Version 4.13.0 Now Available

The release of version 4.13.0 of the Azure File Sync extension for Windows Admin Center has been announced, marking a significant update that went live on March 20th. This version brings a series of enhancements and fixes aimed at improving the Azure File Sync experience within the Windows Admin Center platform. The key improvements include an optimized setup process designed to reduce unexpected failures, facilitating smoother and more efficient deployments of Azure File Sync. Additionally, the update introduces enhanced status checks, offering a proactive approach to verify compatibility and ensure full support for the selected configurations. Furthermore, the error reporting mechanism has been overhauled to provide more detailed and actionable insights. In case of issues during the Azure File Sync setup, users will now receive comprehensive error messages, enabling them to swiftly and effectively resolve any problems. Users are encouraged to update to version 4.13.0 of the Azure File Sync extension via the Windows Admin Center public extension feed to take advantage of these improvements.

Azure Files geo-redundancy for standard large file shares

Azure Files has expanded its offerings to include geo-redundancy for 100 TiB standard SMB file shares, now generally available. Previously capped at 5TiB, these geo-redundant file shares can now scale up to 100TiB with enhanced IOPS and throughput limits. This update brings a significant improvement to the performance and scalability of Azure Files, making it more viable for larger and more demanding storage needs. Geo-redundant standard large file shares are available in 30 regions, with plans to extend this to all regions in the future.

Improved Throughput Performance on Azure Disks’ Standard SSD

Azure unveils increased throughput limits for Standard SSD Disks sizes E50 and below, now offering 100 MB/s, up from 60 MB/s. This enhancement benefits workloads requiring higher throughput, including big data processing, online analytical processing (OLAP), high-performance computing (HPC), and artificial intelligence/machine learning (AI/ML). The improved performance is accessible across all regions without requiring additional steps, while the bursting performance for Standard SSD Disk tiers remains unchanged.

Availability Zone Volume Placement for Azure NetApp Files

The availability zone volume placement feature for Azure NetApp Files has reached general availability. This enhancement enables the deployment of new volumes in the selected logical availability zone, bolstering support for enterprise-level, high availability (HA) deployments across multiple availability zones. It facilitates cross-zone replication of volumes, enhancing resilience against zonal failures. Now available in all regions with Azure NetApp Files presence that support availability zones, this feature marks a significant step forward in cloud storage flexibility and reliability.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (March 2024 – Weeks: 11 and 12)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

Free Data Transfer Out to Internet for Azure Departures

In a bold move to support customer freedom, Azure has introduced free egress for data transfers out of Azure infrastructure to other cloud providers or on-premises data centers. This policy, which aligns with the European Data Act, applies globally across all Azure regions, further facilitating customer transitions and migrations with financial and operational ease. Azure already offers the first 100GB/month of egressed data for free to all customers in all Azure regions around the world. If you need to egress more than 100GB/month, follow these steps to claim your credit.

Azure Classic Administrator Roles Retiring

On 31 August 2024, Azure will retire its classic administrator roles. Organizations using Co-Administrator or Service Admin roles are advised to transition to Azure Role-Based Access Control (RBAC) roles before this date. The retirement also applies to all Azure classic resources and the Azure Service Manager. From 3 April 2024, adding new Co-Administrator roles through the Azure portal will not be possible. Transitioning to Azure RBAC roles is necessary to avoid service disruptions

Modernized Azure Resource Manager Throttling (preview)

Azure Resource Manager’s throttling mechanism is set for a major overhaul in 2024, implementing a token bucket algorithm to manage API requests more efficiently. This update will significantly increase throttling limits and offer a smoother, more scalable experience for managing Azure resources, benefiting developers and administrators alike.

Networking

IPv6 Support for Azure Application Gateway (v2)

IPv6 support for Azure Application Gateway (v2) is now generally available, addressing the growing need for larger address spaces and improved routing efficiency. This update facilitates the support for IPv6 clients and helps customers dealing with IPv4 address scarcity, reinforcing Azure’s commitment to advanced networking solutions.

App Service Backup and Restore over Azure Virtual Network

Azure now enables customers to conduct custom backups for web apps directly to a firewall-protected storage account, provided the app is either integrated with a virtual network or resides in a v3 App Service environment, and the storage account permits access from the connected virtual network. This feature enhances the security and flexibility of web app data management within Azure’s ecosystem.

Retirement of Application Gateway WAF v2 Configuration

The retirement date for Application Gateway WAF v2 Configuration is set for March 15, 2027. Customers are encouraged to migrate to the Application Gateway WAF v2 Policy for enhanced security features and performance without downtime. This transition underscores Azure’s ongoing efforts to streamline and improve security offerings.

Listener TLS Certificates Management in Azure Portal

Azure Application Gateway now supports TLS certificate management directly within the Azure portal, simplifying the management of .PFX certificates for HTTPS or TLS listeners. This enhancement makes it easier for administrators to handle certificate details, such as expiry and issuer name, improving operational efficiency in secure application delivery.

Microsoft Open Sources Retina: Container Networking Observability

Microsoft has open-sourced Retina, a cloud-native container networking observability platform designed by the Azure Container Networking team. Retina provides comprehensive network insights for cloud-native applications, facilitating non-intrusive troubleshooting and supporting diverse environments. This initiative reflects Azure’s commitment to community-driven innovation and enhanced cloud application management.

Host Network Security Group (NSG) Control in AKS

Azure Kubernetes Service (AKS) now offers enhanced security through Host Network Security Group (NSG) control, allowing for precise traffic management on AKS nodes with public IPs. By specifying allowed host ports in node pool settings, administrators can automatically generate allow rules in the cluster’s NSG, bolstering security for public-facing services.

Public IP Domain Name Label Scope (preview)

Azure introduces a public preview of a new capability for Public IP addresses to prevent DNS subdomain takeover while allowing DNS name re-use. The Domain Name Label Scope parameter ensures that a public IP address retains a consistent, hashed string within a specified scope, enhancing security against malicious attempts to hijack DNS subdomains.

Storage

Azure Blob Storage Cold Tier Expansion

Azure Blob Storage Cold Tier, a cost-efficient solution for storing infrequently accessed data, has expanded its availability to Poland Central, Qatar Central, and all regions in Azure China since its general availability on August 10th, 2023. This expansion provides more geographical options for users seeking long-term data retention with instant access, highlighting Azure’s dedication to global accessibility and data storage optimization.

Azure NetApp Files Support for 1 TiB Capacity Pools

Azure NetApp Files now supports creating capacity pools with a minimum size of 1TiB, offering more flexibility and cost savings for customers with smaller data storage needs. This update allows for incremental pool size adjustments, catering to diverse customer requirements and optimizing storage resource allocation.

Force Detach Zone Redundant Disks During Zone Outage (Private Preview)

Azure introduces a private preview feature allowing the force detachment of zone redundant disks during zone outages. This capability ensures business continuity by enabling disks to be detached from VMs in the impacted zone and reattached to VMs in active zones, leveraging Azure’s robust disaster recovery solutions.

Azure Stack

Azure Stack HCI

Introducing Azure Virtual Desktop workload in Azure Stack HCI Sizer

Earlier in February 2024, Microsoft announced the general availability of Azure Virtual Desktop for Azure Stack HCI, a significant enhancement that extends the capabilities of the Microsoft Cloud to datacenters and edge locations. Following this advancement, Microsoft has now integrated ‘Azure Virtual Desktop’ as a new workload category within the Azure Stack HCI sizer. This integration facilitates organizations in efficiently planning and sizing their Azure Virtual Desktop deployments on Azure Stack HCI. By calculating the number of VMs required, suggesting per VM configuration, and advising on hardware procurement, the Azure Stack HCI Sizer, a comprehensive web-based tool, supports organizations in accurately estimating hardware needs for their deployments. The synergy of Azure Virtual Desktop and Azure Stack HCI empowers organizations to securely operate virtualized desktops and applications on-premises, whether at the edge or in their datacenter. This is especially beneficial for organizations with strict data residency requirements, latency-sensitive workloads, or those needing proximity to their data.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (March 2024 – Weeks: 09 and 10)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

Retirement of Cloud Services (classic) Deployment Model

Azure has announced the retirement of the Cloud Services (classic) deployment model on August 31, 2024. Users are encouraged to migrate their services to Cloud Services (extended support) within Azure Resource Manager before this date to avoid service disruption. This transition enables access to new capabilities such as deployment templates, role-based access control, and regional resiliency.

Change Actor in Azure Resource Graph (preview)

Azure introduces the public preview of Change Actor in Azure Resource Graph, a tool that enhances audit, troubleshooting, and governance capabilities. This feature allows users to identify who made changes to resources, the client used for the change, and the operation called. By integrating Change Actor functionality, Azure offers improved visibility and control over resource changes, facilitating better management across tenants and subscriptions.

Compute

New Generation AMD VMs – Dasv6/Easv6/Fasv6 (preview)

Azure announces the public preview of the new generation AMD-based VMs, leveraging the 4th Generation AMD EPYC™ 9004 (Genoa) CPU. These VMs, available in Dasv6, Easv6, and Fasv6 series, offer enhanced performance and reliability. They support various memory to core ratios, catering to general-purpose, memory-optimized, and compute-optimized needs. Equipped with Azure Boost and NVMe interfaces, these VMs promise up to 80% better remote storage performance, faster local storage speeds, and improved networking bandwidth. Initially available in the East US 2 region, these VMs represent a significant expansion in Azure’s AMD VM offerings.

Networking

Azure Route Server Now Available in ItalyNorth Azure Region

Azure Route Server has been introduced to the ItalyNorth Azure Region, offering simplified dynamic routing between network virtual appliances (NVAs) and Azure virtual networks. This service facilitates the direct exchange of routing information via the Border Gateway Protocol (BGP) without the manual configuration of route tables. Azure Route Server, as a fully managed service, ensures high availability and seamless integration with the Azure Software Defined Network (SDN), enhancing network management and efficiency.

Azure Virtual Network Encryption Expanded to Additional Regions

Azure has extended its Virtual Network encryption feature to additional regions, including West US, East US, Europe, and more. This enhancement allows for the encryption of traffic within the same virtual network and across peered networks, bolstering security for data in transit. The expansion of this feature underscores Azure’s commitment to providing robust security options for its users.

Application Gateway for Containers

Microsoft Azure has announced the general availability of Application Gateway for Containers, marking a significant evolution in application load balancing technology. This service enhances the capabilities of the traditional Application Gateway and its Ingress Controller by offering advanced layer 7 load balancing and dynamic traffic management for Kubernetes workloads. With features like Custom Health Probes, URL Redirect, and URL/Header Rewrite, the service ensures near-to-real-time updates in response to changes within the Kubernetes environment. The general availability version also introduces Controller High Availability, Gateway API v1 integration, additional regional availability, and a service level agreement (SLA) to support production workloads confidently.

Azure Application Gateway introduces support for TLS and TCP protocols (preview)

Azure Application Gateway expands its functionality by introducing support for TLS and TCP protocols in public preview. This enhancement allows for the utilization of Application Gateway in non-HTTP applications, catering to protocols such as SQL, MQTT, and AMQP. It facilitates the use of custom domains with Application Gateway’s TLS certificate management, ensuring secure connections for clients and access to any backend service. Moreover, this feature provides a unified endpoint for client access, as a single Application Gateway resource can now support both Layer 7 (HTTP/S) and Layer 4 (TCP and TLS) protocols. Available for Standard V2 and Web Application Firewall V2 SKUs, this update broadens the scope of Application Gateway’s capabilities.

Internet inbound for Network Virtual Appliances in Virtual WAN Hubs (preview)

The introduction of Internet inbound (Destination NAT) for Next-Generation Firewall Network Virtual Appliances (NVAs) in Virtual WAN hubs is now in public preview. This feature enables network administrators to publish applications to a wider internet audience without directly exposing the application or server’s public IP. Instead, users access applications through a public IP address assigned to a Firewall NVA, which is configured to filter, translate, and control access to backend applications. With the ability to associate public IP addresses to Firewall NVAs deployed in Virtual WAN Hubs and utilize NVA management and orchestration software, Virtual WAN customers can now seamlessly program both the Virtual WAN infrastructure and the NVAs to accept and forward inbound traffic, enhancing security and accessibility.

Storage

Azure File Sync Agent v17.2 Release

The Azure File Sync Agent v17.2 has been officially released, consolidating improvements and fixes from its predecessors, versions 17.0 and 17.1. This update is crucial for users with the Azure File Sync agent version 16 or below, as both versions 16.2 and 17.2 are now available for update. This version marks the final planned release for Windows Server 2012 R2, with support for this server ending on March 4th, 2025. The agent is compatible with Windows Server 2012 R2, 2016, 2019, and 2022, providing enhanced functionality and stability.

Azure Blob Storage Cold Tier SLA

As of August 10th, 2023, Azure Blob Storage Cold Tier is generally available, providing a cost-effective solution for long-term storage of infrequently accessed data. The service level agreement (SLA) for Azure Blob Storage now includes this new online access tier, ensuring Microsoft’s commitment to uptime and connectivity.

Encryption at Host for Premium SSD v2 and Ultra Disks Expanded

Encryption at host for Premium SSD v2 and Ultra Disks is now generally available in additional regions including Canada East, West Europe, South Central US, and West US 3. This feature enhances security by starting encryption at the VM host level, ensuring data is encrypted at rest and in transit to the Storage service. The expansion of this feature demonstrates Azure’s ongoing commitment to providing secure and reliable cloud storage options.

Azure NetApp Files Volume Enhancement (preview)

Azure NetApp Files introduces a significant enhancement in public preview, allowing volumes in different availability zones within the same region to share the same volume mount path. This feature supports highly available architectures through cross-zone replication, simplifying automation and minimizing manual intervention during disaster recovery failovers. It is applicable to SMB, NFS, and dual-protocol volumes, facilitating improved recovery times and data availability across various scenarios, including host-based replication and test/dev environments.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.

Azure IaaS and Azure Stack: announcements and updates (February 2024 – Weeks: 07 and 08)

This blog post series highlights the key announcements and major updates related to Azure Infrastructure as a Service (IaaS) and Azure Stack, as officially released by Microsoft in the past two weeks.

Azure

General

Windows Admin Center for Azure Virtual Machines

The Windows Admin Center for Azure Virtual Machines marks a significant step forward in cloud management by integrating directly into the Azure Portal. This tool is engineered to streamline the administration of Windows Server Operating Systems for Azure Virtual Machines. By facilitating in-browser RDP and PowerShell sessions, managing files, viewing events, and monitoring performance, it significantly reduces the necessity for remote desktop connections. A standout feature is its integration with Azure Active Directory for single sign-on capabilities, offering a cohesive identity experience across Azure services. This innovation not only simplifies virtual machine deployment and maintenance but also enhances security by minimizing dependence on local administrator accounts.

Compute

NVv5 Series VMs Now Available in Italy North Azure Region

Azure’s NVv5 Series Virtual Machines, equipped with NVIDIA A10 GPUs and AMD EPYC 74F3V CPUs, are now accessible in the Italy North region. These VMs cater to the needs of high-performance computing and graphics-intensive applications, offering a blend of powerful computational resources and graphical processing capabilities. This expansion into the Italy North region underscores Azure’s commitment to providing geographically diverse options for compute-intensive workloads.

Trusted Launch for Azure VMs in China Regions

Microsoft is proud to announce the general availability of Trusted Launch for Azure virtual machines in all Azure regions across China, encompassing China East, China East 2, China East 3, China North, China North 2, and China North 3. This major update introduces a strengthened security framework for Azure Virtual Machines. Trusted Launch enhances foundational VM security by guaranteeing booting to a defined and trusted state, a crucial step in combating sophisticated malware threats, including boot kits and rootkits, by offering kernel-mode level security on par with the operating system.

Furthermore, Trusted Launch activates Credential Guard, a significant security measure that protects user passwords and derived domain credentials via secure boot, virtualization-based security, and vTPM, which are critical for domain controllers. This feature also provides ongoing insights into the health state and boot chain integrity of virtual machines, along with remediation pathways for attestation failures through Microsoft Defender for Cloud.

Especially for Windows 11 virtual machines, Trusted Launch bolsters defense mechanisms against lower layer malware through the support of UEFI, secure boot, and vTPM. This comprehensive security enhancement ensures a more secure and reliable environment for Azure VMs, marking a significant advancement in cloud security measures tailored to meet the evolving threats in the digital landscape.

Networking

Azure Firewall Enhancements: Flow Trace Logs and Autoscaling

Azure Firewall’s new enhancements, including Flow Trace Logs and autoscaling based on the number of connections, provide granular insights and improved scalability. Flow Trace Logs offer detailed visibility into TCP handshake logs, aiding in troubleshooting packet drops and route asymmetry. The autoscaling feature now adjusts firewall resources based on traffic connection counts, alongside throughput and CPU usage, enabling a more responsive and efficient firewall performance.

Parallel IP Group Update Support for Azure Firewall

The introduction of Parallel IP Group update support in public preview marks a significant improvement in Azure Firewall’s configuration management. This feature allows for the simultaneous update of up to 20 IP Groups within a Firewall Policy, streamlining administrative tasks and enabling faster, more scalable changes. This update is particularly beneficial for administrators utilizing dev ops methodologies for configuration changes, enhancing efficiency and agility in firewall management.

Storage

Azure Elastic SAN (General Availability)

Azure Elastic SAN’s transition to general availability signifies a milestone in cloud storage solutions, offering a fully-managed, cloud-native SAN experience. This service is designed for seamless migration of extensive SAN environments to Azure, simplifying the deployment, scaling, management, and configuration of storage area networks in the cloud. It introduces a SAN-like resource hierarchy and provisions resources at the appliance level, dynamically allocating these to accommodate various workloads, including databases, VDIs, and business applications. The integration of Azure Monitor Metrics and Azure Policy aids in managing performance and preventing misconfigurations, respectively, merging the efficiency of traditional SAN systems with the flexibility and scalability of cloud storage.

Azure File Sync Agent Releases: v17.1 and v16.2 (Security Only Updates)

The release of Azure File Sync agent versions 17.1 and 16.2 as security-only updates addresses a critical vulnerability (CVE-2024-21397) that previously allowed unauthorized file creation. These updates underscore Azure’s commitment to security, providing essential patches for Windows Server installations ranging from version 2012 R2 to 2022. Detailed installation instructions are provided (KB5023054 and KB5023052), ensuring users can securely synchronize files across their environments.

Azure Blob Storage Cold Tier: Enhanced Support for Change Feed and Object Replication

The general availability of Azure Blob Storage Cold Tier’s support for Change Feed and Object Replication introduces significant enhancements for data storage and management. This feature enables the capturing of changes to blobs and their metadata within the cold tier, facilitating efficient data replication and access. It represents Azure’s ongoing efforts to provide cost-effective, flexible storage solutions for infrequently accessed data with long-term retention requirements.

Zone Redundant Storage (ZRS) for Azure Disks in Canada Central

The general availability of Zone Redundant Storage for Azure Disk Storage in the Canada Central region provides a robust solution for data resilience and availability. By offering synchronous replication across three availability zones, ZRS enables Azure Disks to withstand zonal failures, ensuring uninterrupted application performance. This feature is particularly valuable for applications requiring high availability without the complexity of application-level data replication.

Azure NetApp Files Standard Network Features

Azure NetApp Files now supports the general availability of Standard network features, allowing for the editing of network features for Azure NetApp Files volumes. This update brings an enhanced Virtual Networking experience, ensuring seamless integration and improved security posture. Users can now edit existing Azure NetApp Files volumes and upgrade from Basic to Standard network features. This enhancement includes increased IP limits for VNets with Azure NetApp Files volumes, aligning them with VM capabilities to facilitate customer integration into existing network topologies. Moreover, it introduces enhanced network security with support for Network Security Groups (NSGs) on Azure NetApp Files delegated subnets, a feature long requested by customers for meeting enterprise security requirements. Enhanced network control is also achieved through support for User-defined routes (UDRs), allowing traffic direction via chosen Network Virtual Appliances. Additionally, connectivity has been improved with Active/Active VPN gateway setup and ExpressRoute FastPath connectivity, ensuring low latency and high bandwidth connectivity from on-premises networks to Azure.

Introducing Azure Storage Actions: Serverless Storage Data Management (Preview)

Microsoft has recently announced the public preview of Azure Storage Actions, a fully managed platform specifically crafted to streamline data management tasks for Azure Blob Storage and Azure Data Lake Storage. With the exponential growth of data, organizations find themselves grappling with the complexities of efficiently managing their data assets. Azure Storage Actions seeks to alleviate these challenges by offering a serverless infrastructure that dynamically scales to meet data management demands, eliminating the need for resource provisioning or management.

This innovative platform provides a no-code experience, enabling users to easily define conditional logic for processing data objects. It supports an array of tasks aimed at enhancing data utility and security, such as cost optimization, data protection, rehydration from archives, and tagging, among others. Additional functionalities are expected to be added in future updates, further expanding its capabilities.

Azure Storage Actions facilitates the rapid composition, validation, and deployment of data management tasks. It features an intuitive Azure portal interface that simplifies the process of defining operations and validating them, ensuring a seamless user experience. Moreover, the platform offers robust support for programmatic management through various tools including REST APIs, the Azure SDK, PowerShell, the Azure Command-Line Interface (CLI), and Azure Resource Manager (ARM) templates. This versatility makes Azure Storage Actions a comprehensive solution for managing large-scale data assets across Azure Blob Storage and Azure Data Lake Storage, promising to significantly enhance data management efficiency and effectiveness for organizations worldwide.

Azure Stack

Azure Stack HCI

Supported Azure Stack HCI Scenarios with System Center

The integration of Azure Stack HCI, version 23H2, with System Center Virtual Machine Manager (SCVMM) marks a significant step forward in hybrid cloud management. Azure Stack HCI 23H2 elevates cloud-based management capabilities through Azure Arc, catering to the needs of large-scale datacenter customers who rely on System Center VMM for their virtualization environment management. The recent announcement from the System Center team outlines the supported scenarios in SCVMM for managing Azure Stack HCI 23H2, providing clarity and direction for system administrators and IT professionals.

SCVMM Support for Azure Stack HCI 23H2

The supported scenarios in SCVMM for Azure Stack HCI 23H2 include:

  • Addition and Management of Azure Stack HCI Clusters: SCVMM facilitates the addition of Azure Stack HCI clusters into your management framework, allowing for comprehensive oversight.
  • Virtual Machine Operations: Provisioning, deploying, and performing lifecycle operations on VMs within Azure Stack HCI clusters are fully supported, streamlining virtual machine management.
  • Storage and Volume Management: SCVMM enables the management of storage pool settings, creation of virtual disks, cluster shared volumes (CSVs), and application of Quality of Service (QoS) settings to optimize storage performance.
  • Workload Migration: The migration of VMware and Windows Server-based workloads to Azure Stack HCI is supported, offering flexibility in transitioning to Azure Stack HCI environments.
  • Cluster Management via PowerShell: Azure Stack HCI clusters can be managed using the same PowerShell cmdlets as Windows Server clusters, ensuring a consistent management experience.
  • Azure Integration: Azure-based VM self-serve capabilities and management services are extended through Azure Arc-enabled SCVMM, enhancing cloud connectivity and management.

Limitations and Azure/WAC Exclusive Scenarios

While SCVMM supports a broad range of management functions, certain scenarios remain exclusive to Azure Portal/Windows Admin Center (WAC) for Azure Stack HCI 23H2:

  • Cluster Creation and Registration: The creation and registration processes for Azure Stack HCI clusters are integrated into deployment and exclusively managed through Azure Portal/WAC.
  • Upgrades and Azure Benefits: Upgrading from Azure Stack HCI 22H2 to 23H2 and enabling Azure benefits on VMs are managed only via Azure Portal/WAC.
  • Advanced Features: New features of Azure Stack HCI 23H2, such as GPU-Partitioning and SDN Multi-site, along with previously unsupported features like Stretched clustering with 22H2, are managed outside of SCVMM.

Future Support and Availability

Support for Azure Stack HCI 23H2 in SCVMM is scheduled to be included in the next Long-Term Servicing Channel (LTSC) version of System Center. The general availability of this version is anticipated to align closely with the release of Windows Server 2025, offering forward-looking compatibility and support for Azure Stack HCI environments.

This integration underscores Microsoft’s commitment to hybrid cloud environments, providing the tools necessary for seamless management of virtualized infrastructure both on-premises and in the cloud. As the landscape of Azure Stack HCI evolves, the synergy between Azure Stack HCI and System Center continues to strengthen, offering a robust, scalable, and efficient management solution for modern datacenters.

Conclusion

Over the past two weeks, Microsoft has introduced a slew of updates and announcements pertaining to Azure Infrastructure as a Service (IaaS) and Azure Stack. These developments underscore the tech giant’s unwavering commitment to enhancing its cloud offerings and adapting to the ever-evolving needs of businesses and developers. Users of Azure can anticipate improved functionalities, streamlined services, and enriched features as a result of these changes. Stay tuned for more insights as I continue to monitor and report on Azure’s progression in the cloud sphere.