Azure Update - 10th October 2025

By John Savill's Technical Training

Share:

Key Concepts

  • Multi-cloud Networking: Strategies for connecting resources across Azure, AWS, GCP, and Oracle.
  • Static Web App Database Connection: A deprecated public preview feature.
  • Data API Builder: A recommended replacement for connecting to data services via API.
  • AKS Migrations: Using Azure CLI to move AKS clusters from availability sets to VM node pools with availability zones and standard load balancers.
  • AKS Kato Add-on: A GA AI toolchain operator for deploying and operating models on AKS.
  • Network Policy Manager (NPM): Being retired for Windows node pools in AKS.
  • Project Calico: An open-source Kubernetes networking solution with security and observability.
  • VPN Gateway SSTP: A deprecated VPN protocol due to inferior performance and scale.
  • Azure Firewall IP Groups: Lists of IP addresses for reuse in firewall policies, with increased scale.
  • Azure Firewall Secured Hub (BYO IP): Ability to use custom public IP addresses for Azure Virtual WAN secured hubs.
  • General Purpose V1 Storage Accounts: Legacy storage accounts being retired.
  • Unmanaged Disks: Original VM disk type being retired.
  • Azure NetApp Files (ANF): Enterprise-grade file storage with new authentication, cross-tenant customer-managed keys, and short-term clones.
  • Azure Data Lake Storage Gen 2 (ADLS Gen 2) Vaulted Backup: A new preview feature for resilient backups with long-term retention and multi-user authorization.
  • PostgreSQL Flexible Server: Managed PostgreSQL service supporting new minor versions.
  • Azure Cache for Redis: Older SKUs being retired in favor of Azure Managed Redis.
  • Azure Managed Redis: A new, enterprise-built Redis service with consistent capabilities across SKUs.
  • Azure MySQL Flexible Custom Port: Ability to configure a non-default port for MySQL connections.
  • System Center Operations Manager (SCOM) Managed Instance: A managed version of SCOM being retired.
  • OpenAI Models on Azure & AI Foundry: Integration of advanced OpenAI models (GPT5 Pro, GPT5 Chat, Mini variants, Codex, Sora 2) into Azure services.
  • AI Foundry Content Safety (PII Detection): New capability to identify and block Personally Identifiable Information from LLM outputs.
  • Azure Arc Firmware Analysis: A GA feature for analyzing firmware of IoT/network devices for vulnerabilities without an agent.

New Videos This Week: Multi-Cloud Networking

The speaker introduced a new video detailing multi-cloud networking strategies. This covers connecting resources across various cloud providers like Azure, AWS, GCP, and Oracle. The discussion emphasizes that there's no "magic solution" but rather an optimization of familiar networking concepts to connect these disparate cloud environments effectively.


Deprecations and Migrations

This section outlines several services being retired or updated, requiring user action or providing new migration paths.

Static Web App Database Connection Retirement

The Static Web App Database Connection feature, which was in public preview, is being retired at the end of November. Users are advised to migrate to using a self-hosted Data API Builder within their applications. This builder simplifies connecting to various data services by automatically creating an API.

Azure CLI for AKS Migrations

A new Azure CLI command (aks update) is now available to facilitate AKS migrations. Specifically, it enables moving from older configurations using availability sets (which rely on different racks/fault domains) to newer VM node pools that support availability zones and allow upgrading from a basic load balancer to a standard load balancer in a single command.

AKS Kato Add-on General Availability

The AKS Kato add-on has reached General Availability (GA). This add-on functions as an AI toolchain operator, making it easier to deploy and operate various types of AI models on an AKS cluster. It supports use cases such as inferencing and fine-tuning of models hosted on AKS.

Windows Node Pools Network Policy Manager Retirement

The use of Network Policy Manager (NPM) for Windows node pools in Azure Kubernetes Service (AKS) is being retired by the end of September 2026. Depending on the specific functionality being used, users will need to find alternative solutions. Options include leveraging Network Security Groups (NSGs) on the network layer or adopting Project Calico, an open-source Kubernetes networking solution that offers security and observability features.

VPN Gateway SSTP Option Phased Out

The SSTP (Secure Socket Tunneling Protocol) option for Virtual Private Network (VPN) gateways is being phased out over the next year and a half. This is due to its inferiority in performance and scale compared to modern protocols like IKEv2 and OpenVPN. Users are strongly advised to migrate to one of these alternative protocols. For very old on-premise VPN gateways, a replacement of the on-premise hardware/software solution might be necessary to support IKEv2 or OpenVPN.


Networking Enhancements

Significant updates to Azure's networking services focus on increased scale and flexibility.

Azure Firewall IP Groups Scale Increase

Azure Firewall now supports up to 600 IP groups per policy, a substantial increase from the previous limit of 200. An IP group is a reusable list of IP addresses (single IPs, multiple IPs, or IP address ranges) that can be applied across DNA rules, network rules, and application rules, simplifying policy management and reducing duplication.

Azure Firewall Secured Hub: Bring Your Own IP

For Azure Firewall Secured Hubs within Azure Virtual WAN, users can now bring their own public IP address. This means the public IP address used by the firewall can be sourced from a prefix URL to Azure. This feature is particularly useful for scenarios where existing systems have allow lists and require a consistent, pre-approved IP address for outbound traffic, ensuring compatibility with external policies.


Storage Updates

This section details the retirement of older storage services and the introduction of new capabilities for modern storage solutions.

General Purpose V1 Storage Accounts and Legacy Blob Retirement

General Purpose V1 storage accounts and legacy blob storage are being retired by October 2026. Users are encouraged to migrate to General Purpose V2 storage accounts, which consolidate many advanced features, or to specialized options like Block Blob Storage or File Storage depending on specific requirements. If no action is taken, GPv1 accounts will be auto-migrated to GPv2 after October 13, 2026.

Unmanaged Disks Retirement

Unmanaged disks, the original disk type for virtual machines that sat on top of page blobs and required manual management of storage accounts and IOPS, are being retired in 6 months. This date was previously September 2025. Users must migrate to managed disks, which abstract away the underlying storage complexities.

Azure NetApp Files (ANF) Enhancements

  • New Authentication Methods for TLS Encryption: Azure NetApp Files now supports additional LDAP services for TLS encryption of NFS v3 and v4.1 volumes. Supported services include FreeIPA, OpenLDAP, and Red Hat Directory Server, enhancing authentication flexibility for encrypted traffic.
  • Cross-Tenant Customer Managed Key (CMK) General Availability: This feature allows the Key Vault holding a customer-managed encryption key to reside in a different subscription under a different tenant. This is highly beneficial for Software as a Service (SaaS) providers, enabling their customers to maintain control over the encryption keys for their data stored within the SaaS provider's Azure NetApp Files service. Customers can roll keys or revoke access, effectively controlling data access.
  • Short-Term Clones General Availability: ANF now offers short-term clones, which are temporary, thin clones created on top of an existing volume snapshot. These clones only store incremental changes, avoiding a full data copy. They can be used for up to 32 days and are ideal for quick tests, analytics, or disaster recovery (DR) scenarios, especially with large datasets, without the overhead of full data replication.

Azure Data Lake Storage Gen 2 (ADLS Gen 2) Vaulted Backup Preview

Azure Data Lake Storage Gen 2 now supports vaulted backup in preview. When hierarchical namespace is enabled on a storage account, it functions as a data lake with true directory structures and POSIX-style ACLs. The vaulted backup feature stores data in a separate location (not just a snapshot on the same media), providing enhanced resilience against malicious or accidental activity. It leverages Azure Backup service capabilities, offering long-term retention up to 10 years and multi-user authorizations to prevent a single actor from deleting backups.


Database Updates

This section covers new versions and retirement plans for Azure's managed database services.

PostgreSQL Flexible Server Minor Versions

PostgreSQL Flexible Server now supports new minor versions, including 17.6, 10.15, 14.19, 13.22, and 18 beta 3. These updates will be applied automatically during the user's next maintenance window.

Azure Cache for Redis Retirement and Azure Managed Redis

  • Retirement: The Basic, Standard, and Premium SKUs of Azure Cache for Redis (which run on open-source Redis) are being retired by the end of September 2028 (in 3 years). The Enterprise SKUs are being retired earlier, by the end of March 2027.
  • Migration: Users are advised to migrate to the new Azure Managed Redis. This service features all SKUs built on the Enterprise tier, offering consistent capabilities across the board. Users select different virtual machine SKUs based on the desired ratio of memory to processor, allowing for a balance between in-memory capacity and performance.

Azure MySQL Flexible Custom Port General Availability

Azure MySQL Flexible now supports a custom port in General Availability (GA). While the default port is 3306, users can now select a custom port within the range of 25001 to 26000 during creation. This custom port will be used for both public and private access, though only one custom port can be configured.


Miscellaneous Updates

This section covers a range of updates from management tools to cutting-edge AI and security features.

System Center Operations Manager (SCOM) Managed Instance Retirement

The System Center Operations Manager (SCOM) Managed Instance is being retired by this time next year. This managed version of Ops Manager will no longer be available. Organizations requiring SCOM functionality will need to revert to managing their own versions of Ops Manager on their own OS instances. Alternatives like Azure Monitor for Arc-enabled OS instances may be suitable depending on the specific management packs and functionalities required.

OpenAI Models on Azure and AI Foundry

Microsoft's partnership with OpenAI continues to bring advanced models to Azure and AI Foundry.

  • GPT5 Pro: Now available, offering advanced reasoning and analytics capabilities, ideal for complex analytics, code generation, and intelligent decision-making.
  • GPT5 Chat: Also available, featuring enhanced safety guardrails for sensitive conversations, focusing on responsible AI and interactive chat experiences.
  • GPT Image 1 Mini, GPT Realtime Mini, and GPT Audio Mini: These "mini" models are now available for real-time image, voice, and audio generation. Their smaller footprint requires less infrastructure and cost, emphasizing speed and affordability while integrating easily with existing workflows.
  • GPT5 Codex: Specifically designed for AI coding assistant scenarios.
  • Sora 2: Coming soon to Foundry, this model offers highly advanced video and audio generation from a single API, including physics-driven animation, synchronized dialogue, and dynamic media creation.

AI Foundry Content Safety and Content Filter: PII Detection

The content safety and content filter capabilities within AI Foundry now include PII (Personally Identifiable Information) detection. In addition to existing checks for categories like violence, harm, copyrighted material, and prompt/jailbreaking attacks, the system will now identify and block PII from the large language models' output, significantly enhancing privacy.

Azure Arc Firmware Analysis General Availability

Azure Arc Firmware Analysis has reached General Availability (GA). Azure Arc extends the Azure control plane to various operating systems and Kubernetes environments. This new feature allows it to analyze the firmware of IoT or network devices. Crucially, no agent is required on the device. Users upload the firmware image to the cloud, where it is inspected for vulnerabilities, weak security configurations, hard-coded credentials, and software inventory. A comprehensive report is then provided, offering deep insights into the firmware's security posture.


Synthesis and Conclusion

This Azure update highlights a strong push towards modernization, enhanced security, and the rapid integration of advanced AI capabilities. Key themes include the deprecation of older, less efficient services (Static Web App DB, GPv1 Storage, Unmanaged Disks, Redis Basic/Standard/Premium, SCOM Managed Instance) in favor of more performant, scalable, and secure alternatives. Networking services gain significant scale with Azure Firewall IP Groups and flexibility with Bring Your Own IP for secured hubs. Storage solutions are evolving with advanced features like cross-tenant Customer Managed Keys for SaaS providers, efficient short-term clones for Azure NetApp Files, and resilient vaulted backups for Azure Data Lake Storage Gen 2. The integration of cutting-edge OpenAI models (GPT5 Pro, Chat, Mini variants, Codex, Sora 2) into Azure and AI Foundry underscores Microsoft's commitment to AI, complemented by critical content safety features like PII detection. Finally, Azure Arc continues to expand its reach, now offering agentless firmware analysis for IoT and network devices, demonstrating a comprehensive approach to security and management across diverse IT landscapes. These updates collectively provide users with more robust, secure, and intelligent tools for their cloud environments.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video