Azure EpicsšŸ”

# Azure Governance āš–ļø & Management šŸ”Ø

Azure Governance & Management
  • by torreyt
    Following the general availability of what-if for Azure Deployment Stacks, this article deep dives into the co-released feature of "noise reduction", which was a top community feature ask from Deployment Stacks customers. In this article, we will cover what noise […]
  • by stevenbucher
    Today we’re excited to share that theĀ Azure Policy Linter is now open source on GitHub: github.com/Azure/azure-policy-linter. It’s a command-line linter for Azure Policy definitions that surfaces known issues, gotchas, and best practices that you can run when authoring your policy […]
  • by stevenbucher
    In 2024 we introducedĀ versioning for built-in definitions and initiatives. Today we are extending that capability to your own policies! Custom policy versioning is now in public preview. Custom definitions and custom initiatives can store and reference multiple versions under a […]
  • by gurjsing
    Cloud compliance certifications like C5, ISO 27001, HIPAA, or PCI DSS never cover the whole platform. They only cover a defined set of services, listed in an official document published by Microsoft. A common and costly mistake is to assume […]
  • by torreyt
    We are proud to announce that what-if for Azure Deployment Stacks is now generally available, in all regions. To be precise about what this is, since the names are similar: what-if for standard template deployments has been around for a […]
  • by stevenbucher
    When a policy is applied, some resources in scope may need to be temporarily exempted from enforcement, whether it be during a migration, an incident, or while an app team works through its compliance requirements. However, the moment you grant […]
  • by jtracey93msft
    Azure landing zone (ALZ) is now maintained by the Azure Migrate team. Nothing has changed in relation to getting support and making requests; still head toĀ aka.ms/alz/issues (GitHub) and file your ask. ALZ continues to be open-source, maintained by the Azure […]
  • by stevenbucher
    Azure Policy for Kubernetes now supportsĀ Gatekeeper’s integration with native Kubernetes Validating Admission Policy (VAP) using Common Expression Language (CEL)! This integration leverages the new VAP feature introduced in Kubernetes 1.30, providing a more efficient, reliable and in-process way to enforce […]

# Azure Infrastructure šŸ—ļø

Azure Infrastructure
  • by ceciliaxia
    At OCP Global Summit 2026, Microsoft will showcase how we’re advancing the infrastructure needed to scale AI, from silicon and systems to the datacenter. Come visit Microsoft at Booth C73 and hear from Microsoft leaders and experts through our keynote […]
  • by gurjsing
    Bring Your Own Key (BYOK) lets you import externally generated key material into Azure Key Vault. Importing that material again creates a new version; it does not recreate the original version identifier. If Azure Storage still requires the originalĀ customer-managed key […]
  • by frrey
    Rethinking connectivity for distributed AI infrastructure AI is changing more than the applications organizations build. It is reshaping where the infrastructure powering those applications is deployed. For years, cloud computing has been anchored by hyperscale regions that combine compute, storage, […]
  • by abbyhamilton
    In the Catalyst series, we explore the transformative power of AI by showcasing visionary companies driving scientific and industry breakthroughs powered by Azure and NVIDIA. This video series spotlights how innovation ignites action and how today’s visionaries are shaping tomorrow […]
  • by Trinidad_Salazar
    Enterprise AI has entered a new phase. For much of the past decade, the challenge was building enough compute for machine learning. Today, organizations need platforms for foundation model training, fine-tuning, large-scale inference, agentic systems, and enterprise AI. As these […]
  • by javedeqbal
    Author's Note: Vendor names referenced in this article are used solely as illustrative architectural examples and should not be interpreted as endorsements, recommendations, orĀ advertisements. Introduction In Part 1, we looked at how Azure-native services can establish the foundation for a […]
  • by Prakhar-Sharma
    Solution at a glanceĀ  Source imageĀ  →  Packer buildĀ  →  Azure Compute GalleryĀ  →  Validation VMĀ  →  EvidenceĀ  →  Controlled promotionĀ  IntroductionĀ  Maintaining enterprise virtual machine images manually can lead to configuration drift, inconsistent builds, slow remediation and limited release […]
  • by abhilashasr
    Problem statement Azure Private Endpoints let applications connect to Azure platform services through private IP addresses. They reduce public exposure, keep traffic on private networks, and support a Zero Trust architecture. In a single Microsoft Entra tenant, Azure Policy can […]

# Azure Network SecurityšŸ”

Azure Network Security
  • by saikishor
    Written in Collaboration withĀ AvirupChat​ ShabazShaik​ Mohit_Kumar​ YuriDiogenes​  Introduction: As organizations move towardĀ containerized workloads such as Azure Kubernetes Service (AKS), secure access to cluster resources becomes critical. Making the Kubernetes API server private, therefore, significantly reduces the attack surface. However, it also […]
  • by saikishor
    Ā  Introduction: The Need for Layered DDoS Defense Organizations today operate in an environment where Distributed Denial of Service (DDoS) attacks continue to evolve across both network and application layers. To help organizations build resilient, internet-facing applications and services, Microsoft […]
  • by AvanishYadav
    As enterprises adopt Microsoft Azure for large‑scale and regulated workloads, security architecture must be driven by traffic trust boundaries and inspection intent, not connectivity alone. Regulatory frameworks consistently require a clear separation between Internet‑untrusted and private enterprise traffic, enforced through […]
  • by juquint
    If you’ve worked with Azure Bastion’s Premium SKU, you’ve likely encountered one of its most powerful security features: graphical session recording. Capturing RDP and SSH sessions end to end strengthens compliance, supports forensic investigations, and improves operational accountability. How you […]
  • by aarontsang
    Ā  Overview Azure Bastion provides secure RDP and SSH access to Azure virtual machines directly via the Azure portal or via the native SSH/RDP client already installed on your local computer. Today, we are introducing public preview for managed identity […]
  • by andrewmathu
    Introduction As attackers continue to evolve their techniques, organizations require web application security that keeps pace with emerging threats without disrupting legitimate traffic. Azure Web Application Firewall (WAF) continues to evolve to meet these demands and now supports Default Rule […]
  • by saikishor
    Introduction: Azure Firewall Premium provides strong protection with a built-in Intrusion Detection and Prevention System (IDPS). It inspects inbound, outbound, and east-west traffic against Microsoft’s continuously updated signature set and can block threats before they reach your workloads. IDPS works […]
  • by SaleemBseeu
    Introduction Distributed Denial of Service (DDoS) attacks continue to be one of the most prevalent threats facing organizations with internet-facing workloads. Azure DDoS Protection provides cloud-scale protection against L3/4 volumetric attacks, helping ensure your applications remain available during an attack. […]

# Azure Virtual Desktop (AVD) šŸ–„ļø

Azure Virtual Desktop (AVD)
  • by Vidya_Iyer
    Editor’s note (October 1, 2026): This post was updated to clarify the benefits of regional host pools and provide additional context on recent resiliency improvements. Resiliency improvements are arriving for Azure Virtual Desktop. Regional host pools reduce cross-region metadata dependencies […]
  • by Steve_Downs
    Extend Azure Virtual Desktop to your on-premises environment. Run desktops where you need them. Manage on-premises session hosts from Azure. Many organizations want to modernize their virtual desktop infrastructure but face practical constraints that make a full cloud migration difficult […]
  • by TomHickling
    Ā  Editor's Note: August 2026 | This post has been updated to reflect changes since its original publication in January 2026. Opting in to the preview through a feature flag is no longer required, and the Azure portal is now […]
  • by NeoCai
    We’re excited to announce the general availability of enhanced host pool management for Azure Virtual Desktop. Enhanced host pool management includes: Session host configuration and update Dynamic autoscale Ephemeral OS disks These features make it easier than ever to manage […]
  • by Christian_Montoya
    At Microsoft Ignite 2025, we announced both the general availability of external identity support in Azure Virtual Desktop and the public preview support of using FSLogix and Azure Files as a user profile management solution for external identities in Azure […]
  • by Rinku_Dalwani
    Reliable connectivity is essential for ensuring consistent productivity in Azure Virtual Desktop (AVD) environments. Network variability—whether due to packet loss, NAT misconfiguration, UDP‑restricted networks, or restrictive enterprise network policies—continues to be one of the most common causes of session interruptions […]
  • by Steve_Downs
    Azure Virtual Desktop is a secured, cloud-based virtual desktop infrastructure (VDI) service that enables organizations to deliver Windows desktops and applications to users. Originally launched in 2019, Azure Virtual Desktop has evolved rapidly to meet the changing needs of modern […]
  • by Michelle_Moya
    Managing applications in virtualized desktop and server environments has traditionally required IT teams to bake apps directly into baseĀ images,Ā driving image sprawl, slower updates, and higher operational overhead. AppĀ attachĀ inĀ Azure Virtual DesktopĀ changes that model by enabling applications to be delivered dynamically to […]
Scroll to Top