Azure State of the Union 2026

By John Savill's Technical Training

Share:

Key Concepts

  • Workloads & Capacity: Azure provides the capacity to run workloads comprised of application layers, stateful stores, and communication components, managed through the Azure Resource Manager (ARM).
  • Service Models (IaaS, PaaS, SaaS): Varying levels of responsibility shared between customer and Microsoft, impacting management overhead and control.
  • Azure Resource Manager (ARM): The central control plane for all Azure operations, enforcing policy and enabling governance.
  • Identity as the First Layer of Security: Utilizing Entra ID (formerly Azure AD) for authentication and authorization, leveraging Managed Identities for secure resource access.
  • Governance & Delegation: Hierarchical structure with Enterprise Agreements, Management Groups, and RBAC for decentralized resource provisioning and centralized control.
  • Virtual Machines (VMs) as Foundation: VMs are the core compute building block, with various SKUs, generations, and disk options optimized for different workloads.
  • Networking Fundamentals: Virtual Networks (VNets), Subnets, NSGs, and Private Endpoints are crucial for connectivity, security, and isolation.
  • Scalability & Higher-Level Services: Utilizing VM Scale Sets, AKS, ACI, and Azure Container Apps to achieve scalability and leverage managed services.

Enterprise Agreements & Governance

Azure operates on a hierarchical structure governed by Enterprise Agreements (EA), focusing on usage and spend management. Departments within an EA can create Accounts, which in turn create Subscriptions – the fundamental unit for resource deployment. This delegation model empowers business units while maintaining centralized oversight. A key shift in cloud governance involves moving from direct IT control to establishing guardrails enforced through the Azure Resource Manager (ARM), the central control plane for all Azure operations. All interactions – portal, CLI, templates, APIs – pass through ARM, ensuring consistent policy enforcement.

Identity & Access Management

The network is no longer the primary security perimeter; identity is now paramount. Entra ID serves as the central identity provider, supporting Users, Applications (with Service Principals), Azure Resources (with Managed Identities), and even AI Agents (with Agent Identities). Every subscription trusts one Entra ID tenant. Entra Connect or Entra Cloud Sync synchronize on-premises Active Directory with Entra ID, with a trend towards Entra ID as the source of truth. External Identities can be added for partners and vendors. Management Groups provide a layer of organization above subscriptions, enabling policy and Role-Based Access Control (RBAC) at scale. RBAC assigns permissions at various scopes (resource, resource group, subscription, management group) through role assignments, utilizing built-in or custom roles.

Virtual Machines & Compute Fundamentals

Workloads require specific resources (CPU, memory, IO, network), addressed by various VM SKUs. Burstable VMs offer cost savings, while Spot VMs provide discounted pricing with potential interruption. VM Generations (Gen1 vs. Gen2) impact security features. Managed Disks provide durable storage, with options like Standard HDD, Standard SSD, Premium SSD, and Ultra Disk. Ephemeral OS Disks offer faster provisioning for stateless VMs. Disk Encryption Sets (DES) and Encryption at Host enhance data security.

Data Protection & Security

Customer-Managed Keys (CMK) stored in Azure Key Vault allow customers to encrypt data on managed disks, providing greater control. Azure Key Vault securely stores keys, secrets, and certificates with item-level RBAC. Managed Identities eliminate the need to store credentials within VMs, offering a secure way to access resources. System-Assigned Managed Identity creates a one-to-one mapping, while User-Assigned Managed Identity allows sharing across resources. Tokens are proactively refreshed for resilience. Snapshots and Restore Points provide data protection and recovery options.

Networking & Connectivity

Virtual Networks (VNets) define address spaces and are segmented into Subnets. Peering connects VNets across subscriptions or regions. Network Security Groups (NSGs) and Application Security Groups (ASGs) control network traffic. User-Defined Routes (UDRs) direct traffic through NVAs. Private Endpoints provide private IP addresses for secure access to Azure services via Private Link. Connectivity to on-premises networks is achieved through ExpressRoute, Private Peering, and Site-to-Site VPNs.

Scalability & Higher-Level Services

Virtual Machine Scale Sets (VMSS) automate VM creation and deletion for scalability, offering Uniform and Flexible deployment modes. Azure Kubernetes Service (AKS) manages Kubernetes clusters, utilizing VM Scale Sets for node pools. Azure Container Instances (ACI) provide on-demand scaling, while Azure Container Apps abstract AKS. App Services and Databases are built on VMs, offering managed services. AI Services also rely on underlying VM infrastructure.


Conclusion

Azure provides a comprehensive cloud platform built on a foundation of scalable compute, robust networking, and secure identity management. The shift to cloud computing necessitates a change in governance, emphasizing self-service provisioning within defined guardrails enforced by the Azure Resource Manager. Understanding the core concepts of workloads, service models, and the underlying infrastructure – particularly Virtual Machines – is crucial for effectively leveraging Azure’s capabilities and optimizing cost, performance, and security. The platform’s evolution continues with higher-level services like AKS and Azure Container Apps, abstracting complexity while still relying on the foundational elements described.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video