Key Concepts
- Networking Gateway Maintenance Windows
- Azure Virtual Network Manager (AVNM) in Gov Cloud
- Shared Access Signature (SAS) Expiration Actions
- Premium SSD v2 and Ultra Disk Live Resize
- Power BI Desktop Entra ID Authentication
- Azure Arc-powered SQL Database Migration
- Azure SQL String Functions (UNISTR, Concatenation)
- PostgreSQL Flexible Cascading Read Replicas
- MySQL Accelerated Logs GA for General Purpose Tier
- MySQL Configurable Backup Interval
- Azure Confidential Ledger Tagging
- Microsoft Authentication Dark Mode
- Azure Dedicated HSM Retirement
Networking Updates
- Networking Gateway Maintenance Windows: All networking gateway types (Express Route, Site-to-Site, Point-to-Site) now have the ability to configure custom maintenance windows, specifically for Point-to-Site VPN gateways in Virtual WAN. Users can set a minimum 5-hour window for maintenance to occur, accommodating different critical or quiet times based on geography.
- Azure Virtual Network Manager (AVNM) in Gov Cloud GA: AVNM is now generally available in the Gov Cloud. AVNM provides centralized, at-scale management of networks, including connectivity, security admin rules (enforced before NSGs), user-defined routes, and IP address management (IPAM).
Storage Updates
- Shared Access Signature (SAS) Expiration Actions: Storage accounts can now define expiration action policies for Shared Access Signatures (SAS). These policies determine what happens when a SAS token's expiry exceeds the maximum validity period set on the storage account. Options include:
- Log an event: (Default, recommended starting point) Logs an event when a SAS token exceeds the validity policy, allowing monitoring and communication with teams using long expiry times.
- Block the request: Enforces the validity policy by blocking requests using SAS tokens that exceed the allowed expiry.
- Premium SSD v2 and Ultra Disk Live Resize GA: Premium SSD v2 and Ultra Disks connected via NVMe controllers now support live resizing in GA. This allows increasing the size of the disk without downtime. Note: Decreasing disk size is not supported; a new disk must be created and data copied over. This feature enables starting with smaller, cheaper disks and scaling up as needed, optimizing spending.
Database Updates
- Power BI Desktop Entra ID Authentication: Power BI Desktop can now authenticate to PostgreSQL Flexible Server using Entra ID, eliminating the need to store database usernames and passwords and leveraging Entra ID's security policies.
- Azure Arc-powered SQL Database Migration (Preview): A new Azure Arc-powered SQL database migration capability is available in preview within the Azure portal. It's designed to migrate SQL workloads to Azure SQL MI instances, leveraging real-time database replication (distributed availability groups) or log shipping. Microsoft Copilot can assist in these migrations.
- Azure SQL String Functions (GA): Two new string functions are generally available in Azure SQL, aligning with ANCSQL compliance:
- UNISTR: Allows defining Unicode string literals using Unicode encoding values (escape sequence + numeric value). The function then outputs the actual Unicode character.
- Concatenation (||): A simple operator for concatenating character or binary strings (e.g.,
string1 || string2).
- PostgreSQL Flexible Cascading Read Replicas (Preview): PostgreSQL Flexible Server now supports cascading read replicas in preview. This allows creating a two-tier hierarchy of read replicas, where each of the initial five replicas can have its own five replicas (up to 30 replicas total). This reduces the workload on the primary server, as replicas replicate from other replicas instead of directly from the primary.
- MySQL Accelerated Logs GA for General Purpose Tier: MySQL Accelerated Logs are now generally available for the General Purpose tier (previously only Business Critical). Accelerated Logs use faster underlying storage, reducing transaction latency and increasing throughput, improving overall database performance. While free for Business Critical, it has a cost for General Purpose. It can be enabled/disabled on new and existing servers.
- MySQL Configurable Backup Interval (GA): MySQL now allows configuring the backup interval. The default is daily full backups with transaction logs backed up every 5 minutes. Users can now change the full backup interval to 6, 12, or 24 hours. Shorter intervals reduce the time required to restore to a specific point in time, as fewer transaction logs need to be replayed.
Miscellaneous Updates
- Azure Confidential Ledger Tagging (Preview): Azure Confidential Ledger now supports tagging transactions in preview. Users can add up to five tags (secondary keys) of up to 64 characters each to transactions. These tags facilitate easier data organization and retrieval.
- Microsoft Authentication Dark Mode: Microsoft Authentication (Entra ID and consumer authentication) will receive a new background image and, importantly, a dark mode option that aligns with the operating system's dark mode setting. This will roll out over the next couple of months.
- Azure Dedicated HSM Retirement: Azure Dedicated HSM is being retired in 3 years. Users should migrate to Azure Cloud HSM (which offers the same or better compliance) or Azure Managed HSM.
Synthesis/Conclusion
This Azure update covers a range of improvements and new features across networking, storage, databases, and miscellaneous services. Key takeaways include enhanced control over maintenance windows, expanded availability of management tools in Gov Cloud, improved data protection and cost optimization options for storage, enhanced security and migration capabilities for databases, and usability improvements like dark mode for authentication. The retirement of Azure Dedicated HSM highlights the importance of staying updated with service lifecycle changes and planning for migrations.
AI summaries can miss context or contain errors. Check important details against the original video.





