Azure Red Hat OpenShift moves the control plane out of your subscription
Azure Red Hat OpenShift (ARO) is now available with hosted control planes in public preview. Red Hat announced the change on September 15, and it restructures where the most expensive and least visible part of your cluster actually runs: instead of three control plane virtual machines sitting in your Azure subscription, the control plane runs […]
Azure Functions Flex Consumption gets site-scoped certificates and end-to-end TLS
TLS/SSL certificate support for Azure Functions Flex Consumption is now generally available. Microsoft announced the milestone this week alongside end-to-end TLS encryption support, and together the two close a gap that has kept some teams on the older App Service plans longer than they wanted to be. If you run function apps on custom domains, […]
The azd extension framework is generally available
The Azure Developer CLI’s extension framework is now generally available. If you haven’t followed the azd project, extensions are the plugin system that lets teams add their own commands, automation, and service integrations to the CLI without forking it or wrapping it in scripts. The GA applies to the framework itself: the parts of azd […]
Storage Mover can now migrate SMB shares to Azure Files without agents
Azure Storage Mover now supports agentless migration from on-premises SMB file shares to Azure Files, in public preview. Until now, moving file shares into Azure with Storage Mover meant deploying and managing migration agents on VMs near the source data. The agentless path removes that step entirely: the service reads the SMB share over the […]
Azure Copilot’s Troubleshooting Agent hits general availability
Microsoft has taken the Troubleshooting Agent in Azure Copilot to general availability. It lives in the Azure portal, in both the Copilot chat experience and the Support + Troubleshooting blade, and its job is to take a vague complaint like “my VM rebooted itself last night” and turn it into a diagnosis, a fix, or […]
Azure says goodbye to OS Guard: what AKS operators should do before December 10
The short version Microsoft will retire Azure Linux with OS Guard on Azure Kubernetes Service on December 10, 2026. On that date you will not be able to create new OS Guard node pools, and existing ones stop receiving support. The stated replacement is Azure Container Linux, which went generally available on AKS starting with […]
Extended Support for Azure Database for PostgreSQL is now billing
If you run PostgreSQL 11, 12 or 13 on Azure Database for PostgreSQL Flexible Server, a quiet billing change went live on September 1. Azure automatically enrolled servers on unsupported PostgreSQL versions in Extended Support when standard support ended on July 31. A one-month grace period covered August at no charge. The meter started running […]
Defender for Cloud brings serverless container posture to Azure Container Apps
Microsoft has made Azure Container Apps environments available in Defender for Cloud’s Serverless Containers Posture experience, now generally available. Security teams can pull their Container Apps estate into posture management from a single workflow instead of treating each serverless platform separately. The capability also covers Azure Container Instances and Amazon ECS on AWS Fargate. The […]
Azure Storage SAS tokens can now be locked to an Entra ID identity
Azure Storage has made user-bound user delegation SAS generally available. The feature ties a shared access signature not just to who created it, but to who is allowed to use it. The delegator names a specific Entra ID security principal inside the token, and that principal has to authenticate to Entra ID before the token […]
Azure Firewall Auto-Learn SNAT Routes Is Generally Available
The SNAT problem that needed solving Here is a scenario that plays out in half the hybrid networks I have seen: traffic from Azure toward an on-premises range that is not one of the standard private ranges silently gets source-NATted by Azure Firewall. The on-prem firewall sees an unexpected source IP, a policy match fails, […]
AKS Artifact Streaming Reaches General Availability
Pulling images is the slow part nobody budgets for If you have ever watched a scale-out event on AKS with one eye on the pod list, you know the pattern: the scheduler places pods in seconds, then everything sits in ContainerCreating while each node drags a multi-gigabyte image out of Azure Container Registry. Your autoscaler […]
Azure Monitor Auxiliary Logs reach sovereign clouds, and log pricing gets interesting
Azure Monitor’s Auxiliary Logs plan is now generally available in the sovereign clouds, specifically Azure Government (Fairfax) and Microsoft Azure operated by 21Vianet (Mooncake). The September 1 update closes a gap that has mattered to anyone running compliance or audit logging for public-sector or regulated workloads, and it caps a year of quiet expansion for […]