Azure Firewall Auto-Learn SNAT Routes Is Generally Available

The SNAT problem that needed solving Here is a scenario that plays out in half the hybrid networks I have seen: traffic from Azure toward an on-premises range that is not one of the standard private ranges silently gets source-NATted by Azure Firewall. The on-prem firewall sees an unexpected source IP, a policy match fails, […]

Azure Monitor Auxiliary Logs reach sovereign clouds, and log pricing gets interesting

Azure Monitor’s Auxiliary Logs plan is now generally available in the sovereign clouds, specifically Azure Government (Fairfax) and Microsoft Azure operated by 21Vianet (Mooncake). The September 1 update closes a gap that has mattered to anyone running compliance or audit logging for public-sector or regulated workloads, and it caps a year of quiet expansion for […]

Azure Multicloud Interconnect: Microsoft and AWS finally wired the clouds together

Microsoft and AWS announced a joint service this week that neither company would have shipped five years ago: a managed private connection between the two clouds, provisioned from both portals, operated by both providers. Azure Multicloud Interconnect is in public preview now, with AWS as the first supported partner, and it replaces what has historically […]

Azure Front Door WAF policies now attach at profile and route level

Azure Front Door’s Web Application Firewall has always had a scoping problem. You could associate a WAF policy with a custom domain, and that was mostly it. One policy per domain, which sounds fine until you run a real Front Door profile with a dozen domains behind it and every team wants different rules. The […]

Azure SRE Agent VNet Integration Reaches General Availability with Private Network Controls

Microsoft has officially announced the general availability of Virtual Network (VNet) integration for Azure SRE Agent. The capability allows operations and platform teams to deploy and operate Microsoft’s autonomous site reliability engineering agent entirely within their private virtual network topology. By routing the agent’s outbound management traffic through dedicated subnets, organizations can enforce corporate Network […]

Snowflake Deprecates Service Account Passwords as Teams Face Credential Mapping

Snowflake is systematically eliminating single-factor password authentication for legacy service accounts across its data platform. Under the enforcement timeline, automated service accounts designated with the legacy service user type will no longer be permitted to authenticate using static passwords. Instead, data engineering and platform teams must transition automated workloads to public-key cryptography, OAuth flows, or […]

Azure SQL Database Provisioning in VS Code MSSQL Extension Reaches General Availability

Bridging Local Development and Cloud Databases Microsoft has announced the general availability of Azure SQL Database provisioning directly within the MSSQL extension for Visual Studio Code. This release streamlines how developers create, configure, and connect to managed cloud databases without leaving their code editor. The feature includes direct support for the Azure SQL Database free […]

CISA Warns of In-the-Wild Exploits Targeting Critical MLflow SSRF Vulnerability

The Cybersecurity and Infrastructure Security Agency added a critical vulnerability in the open-source machine learning platform MLflow to its Known Exploited Vulnerabilities catalog after telemetry confirmed attackers are actively scanning and compromising exposed instances. The flaw, tracked as CVE-2026-64849, allows unauthenticated remote attackers to trigger server-side request forgery requests from vulnerable MLflow servers to internal […]

Azure VMware Solution license-included service gets retirement date as Broadcom licensing shift bites

What changed Microsoft confirmed the Azure VMware Solution (AVS) license-included service will retire on August 30, 2027. The decision follows Broadcom’s VMware Cloud Foundation (VCF) licensing policy changes, which now require customers to bring their own portable licenses across all hyperscaler platforms. For AVS customers on license-included SKUs, this means a mandatory transition to bring-your-own-license […]

AKS control plane metrics now generally available with Managed Prometheus

Azure has made control plane metrics collection for AKS generally available, and it runs on Azure Monitor Managed Service for Prometheus. Until now, getting visibility into the managed Kubernetes control plane meant either accepting whatever Azure surfaced in its own dashboards or standing up your own Prometheus and scraping whatever you could reach. This closes […]

Batch Rule Updates for Azure Front Door Are Now Generally Available

Anyone who has managed Azure Front Door for any length of time has felt the pain of touching a rule set. Rule sets are where you define how traffic gets inspected, rewritten, and routed, and they sit right at the edge of your application where a bad change is immediately visible to real users. Historically, […]

Microsoft Fabric Flips Item Recovery On By Default, and That Is a Good Thing

Microsoft is about to make a quiet change to Fabric that most tenants will never notice, but it will save a few of them from real pain. Starting August 23, 2026, Fabric will enable Item Recovery by default for any tenant that has not explicitly configured the setting. For supported item types, that means a […]