Azure Update - August 22nd
Key Concepts:
- Microsoft Fabric: Unified data platform with Delta Parquet as the standard format.
- Azure File Sync: Synchronizes on-premises Windows file shares with Azure file shares.
- Confidential VMs: VMs with encryption in use, using Intel TDX.
- Azure Bastion: Managed jumpbox for secure access to VMs.
- AKS: Azure Kubernetes Service.
- App Gateway Max Surge: Feature to maintain capacity during App Gateway upgrades.
- Azure Files Premium/Standard v2 Billing Model: Provision storage, IOPS, and throughput independently.
- Blob Archive Tier: Storage tier for infrequently accessed data with rehydration period.
- Azure NetApp Files Flexible: Separately configure capacity and throughput for NetApp files.
- Log Analytics Search Jobs: Query data across different tiers in Log Analytics.
- CNAME Based Domain Control Validation: Certificate validation method being deprecated.
Microsoft Fabric
- Main Point: Microsoft Fabric unifies data capabilities using Delta Parquet as a standard format.
- Details:
- Avoids data silos and duplication.
- Enables using different data integration tools and notebooks without data translation.
- Allows easy setup of transactional SQL databases integrated with Fabric's analytics.
- Example: Using various data integration tools without needing to copy and translate data between different solutions.
Azure File Sync
- Main Point: Azure File Sync now supports managed identities for authentication.
- Details:
- Simplifies operations and enhances security.
- Managed identities are used for server endpoints to the sync service and the sync service to the Azure file share.
- Functionality: Synchronizes content from up to 100 Windows Server-based file shares via an Azure file share.
Compute Updates: Confidential VMs
- Main Point: New DC and EC series confidential VMs using Intel TDX (Trust Domain Extension) offer whole VM encryption.
- Details:
- Intel TDX: Provides whole VM encryption, meaning applications don't need modification to benefit from encryption in use.
- DC Series: General purpose VMs.
- EC Series: Memory optimized VMs.
- Azure Boost: Provides high storage IOPS, throughput, and network bandwidth.
- Memory: Up to 512 GB.
- vCPUs: Up to 128 for DC, up to 64 for EC.
- Advantage: Unlike other Intel confidential compute solutions with secure enclaves, these VMs don't require application changes.
Compute Updates: Azure Bastion for AKS
- Main Point: Azure Bastion can now be used to manage AKS clusters.
- Details:
- Azure Bastion is a managed jumpbox service.
- Allows communication with both private and public AKS clusters.
- Enables running Kubernetes commands (kubectl) via Azure Bastion.
- Process: Use AKS Bastion, then use kubectl commands.
Compute Updates: Azure Functions
- Main Point: New 512 MB instance size for Azure Functions Flex Consumption plan.
- Details:
- Provides a smaller size option for optimizing costs.
- Existing 48 MB and 4096 MB memory size options remain available.
- New diagnostic settings for Flex Consumption to collect application logs and resource metrics.
- Logs and metrics can be sent to Log Analytics Workspace, Storage Account, and Event Hub.
Networking Updates: App Gateway Max Surge
- Main Point: App Gateway Max Surge support is now generally available.
- Details:
- Maintains capacity during App Gateway upgrades by provisioning new instances.
- Avoids capacity drops during rolling upgrades.
- Automatic and requires no configuration.
- Uses additional IP addresses during upgrades.
- If the IP space is insufficient, the traditional non-max surge method is used.
Storage Updates: Azure Files v2 Billing Model
- Main Point: Azure Files Premium and Standard now use the v2 billing model, allowing independent provisioning of storage, IOPS, and throughput.
- Details:
- Applies to both Premium (SSD) and Standard (HDD) tiers.
- Allows matching storage requirements precisely.
- Volumes can be up to 256 TB for Premium and 4 PB for Standard, down to 32 GB.
- Mirrors the billing model of Premium SSD v2 and Ultra Disk managed disks.
Storage Updates: Blob Archive Tier
- Main Point: Blob Archive tier is now available in Malaysia West.
- Details:
- For infrequently accessed data that needs to be retained.
- Data is not available online and requires rehydration to Cold, Cool, or Hot tiers.
- Useful for compliance purposes.
Storage Updates: Azure NetApp Files Flexible
- Main Point: Azure NetApp Files Flexible now has access in preview, allowing tiering of less accessed data to Azure Storage.
- Details:
- Flexible lets you separately configure capacity and throughput.
- Cold tier moves least accessed data to Azure Storage for cost savings.
- Azure NetApp Files file access logs are now generally available.
- Provides detailed telemetry for file access activities on SMB, NFSv4.1, and dual protocol volumes (not NFSv3).
- Logs include identity, operation type, and timestamp.
- Each entry is about 1 KB in size and can be enabled per volume.
Log Analytics Updates
- Main Point: Log Analytics search jobs now return up to 100 million results in a result set.
- Details:
- Increased from 1 million results.
- Search jobs can work across various tiers, including the long-term tier.
Microsoft Sentinel and Defender for Cloud Retirement
- Main Point: Microsoft Sentinel and Microsoft Defender for Cloud are being retired in the China cloud (operated by 21 VNET) on August 18, 2026.
- Details:
- Due to evaluations, it's no longer feasible to operate these services at the required levels of protection and reliability.
- Users in the China cloud need to find alternate solutions.
CNAME Based Domain Control Validation Deprecation
- Main Point: CNAME based domain control validation is being deprecated, requiring action to avoid certificate renewal issues.
- Details:
- Affects App Service Managed Certificates, Content Delivery Network, Azure Front Door Classic, and Azure Container Apps.
- Users need to meet the new multi-perspective issuance collaboration requirements to renew certificates.
Conclusion
This Azure update covers a range of improvements and new features across compute, networking, storage, and security. Key takeaways include the unified data capabilities of Microsoft Fabric, the enhanced security of Azure File Sync with managed identities, the cost optimization options in Azure Functions and Azure Files, and the importance of addressing the CNAME deprecation for certificate renewals. The update also highlights the retirement of Sentinel and Defender for Cloud in the China cloud, urging users to seek alternative solutions.
AI summaries can miss context or contain errors. Check important details against the original video.





