Key Concepts:
- Entra ID: Cloud-based identity and access management service.
- App Gateway for Containers (AGC): Azure's container-native application gateway.
- AKS Agentic CLI: Command-line interface for diagnosing and resolving AKS issues using natural language.
- AKS Managed Namespaces: Azure-managed Kubernetes namespaces with policy enforcement.
- AKS Virtual Network Verifier: Tool for detecting and troubleshooting outbound connectivity issues in AKS.
- Managed Prometheus: Azure Monitor's Prometheus-compatible monitoring service.
- AKS Local DNS: DNS proxy running on each node for faster DNS lookups and improved resiliency.
- Azure Bastion: Managed jumpbox service for secure RDP/SSH access.
- AKSMCP Server: Model Context Protocol server for AI application integration with AKS.
- Streaming Encoding: Optimization for Kubernetes list responses to reduce server memory usage.
- AKS Security Dashboard: Centralized view for AKS security posture and threat protection.
- AKS Static Public Prefix Egress Gateway: Allows outbound traffic from annotated pods to route through a static public IP prefix.
- AKS Deployment Safeguards: Enforces best practices during AKS deployments.
- Confidential VMs: VMs with encryption in use using AMD SEV-SNP.
- AKS Advanced Container Networking: Fine-grained traffic inspection and control for Cilium clusters.
- NFS Encryption for Azure Files: Encryption for Azure Files NFS shares using TLS.
- Azure DNS DNSSEC: Security extensions for DNS to provide cryptographic authentication.
- Azure Virtual Network Manager: Centralized management for virtual networks, including mesh connectivity.
- Network Security Perimeter: Secures PaaS resources without virtual networks.
- Azure File Sync: Synchronizes Windows file servers with Azure file shares.
- Azure Arc: Extends Azure management to on-premises and multi-cloud resources.
- Azure Data Box: Physical data transfer device.
- Azure Storage Actions: Granular actions on storage accounts beyond lifecycle management.
- Azure Storage Discovery: Analysis tool for storage usage, capacity, and cost optimization.
- GPT-5: Advanced language model available in Azure AI Foundry.
- GPT Image 1: Image generation model with fidelity control.
- Open Source LLMs: Openly available large language models with accessible weights.
- Azure Backup: Azure's backup service.
- AI Shell: Shell experience leveraging language models.
- MCP: Model Context Protocol
1. Identity and Access Management
- Source of Authority Conversion: A new feature allows converting the source of authority for groups from on-premises Active Directory to Entra ID. This facilitates the transition to cloud-based identity management and enables the use of Entra ID features like governance, dynamic groups, and access reviews. This is a "huge step" for organizations moving towards cloud-centric identity.
2. Application Gateway
- App Gateway for Containers (AGC) WAF Compatibility: The App Gateway for Containers now supports Web Application Firewall (WAF), removing a major obstacle for migrating from the original App Gateway. The original App Gateway was not designed for containers, while AGC is specifically built for containerized applications.
3. Compute (AKS and Virtual Machines)
- AKS Agentic CLI (Private Preview): This CLI uses natural language to diagnose and resolve AKS cluster issues. The
AKS agentic helpcommand provides access to these capabilities. - AKS Managed Namespaces (Public Preview): Azure control plane now manages Kubernetes namespaces, enabling policy enforcement for networking and resource quotas. It allows configuration of interactions and takeover of existing namespaces. Azure ARM roles are used for control and data plane activities.
- AKS Virtual Network Verifier (Preview): Detects and troubleshoots outbound connectivity issues by analyzing traffic between the cluster and a public egress endpoint. It helps identify misconfigured NSGs, firewalls, user-defined routes, V-Net peering, and load balancers.
- Multiple Standard Load Balancers (Preview): AKS now supports multiple standard load balancers, overcoming the previous limitation of one load balancer per cluster. This allows for more than 300 inbound rules and eight private link services by distributing workloads.
- Managed Prometheus Increased Ingestion Quota (Preview): The ingestion quota for Managed Prometheus can be increased to 20 million events per minute, benefiting busier clusters. Managed Prometheus uses a special workspace in Azure Monitor.
- AKS Local DNS (Preview): A DNS proxy running on each node caches DNS lookups, resulting in faster DNS resolution for pods and reduced load on the core DNS service. It also provides resiliency by resolving requests from the cache even if the regular DNS is unavailable, as long as the DNS lookup is within the time-to-live (TTL).
- Azure Bastion with AKS CLI (Preview): Azure Bastion, a managed jumpbox service, can now be used with the AKS CLI to access both private and public AKS clusters using
kubectl. It supports RDP and SSH and integrates with Entra ID for authentication. - AKSMCP Server (Preview): An MCP (Model Context Protocol) server is now available for AKS, enabling AI applications to easily integrate with AKS clusters. This allows AI apps to perform tasks like creating, scaling, and retrieving metrics/logs from AKS clusters.
- AKS Control Plane Improvements (GA): Kubernetes 1.31.9+ includes streaming encoding for list responses, reducing server memory usage by up to 10x for large list calls. The encoder processes objects individually and streams them to the client, avoiding the need to hold the entire response in memory. This may slightly increase CPU usage.
- AKS Security Dashboard (GA): A centralized view for security posture and runtime threat protection for AKS clusters. It allows enabling Defender for Containers and provides recommendations for misconfigurations, which can be assigned to users.
- AKS Static Public Prefix Egress Gateway (GA): Allows annotated pods to route outbound traffic through a static public IP prefix, useful for scenarios where external services require allowlisting based on IP addresses.
- AKS Deployment Safeguards: Enforces best practices during AKS deployments, warning or blocking non-compliant configurations. Enabled by default for AKS automatic, but can be disabled at the namespace level.
- Confidential VMs Support: AKS Azure Linux and Ubuntu 24.04 now support confidential VMs, providing encryption in use using AMD SEV-SNP.
- AKS Advanced Container Networking Layer 7 Policies (GA): Part of the advanced container network services and Cilium clusters, providing fine-grained inspection and control over application traffic.
- NFS Encryption Support: AKS now supports NFS encryption for Azure Files-based NFS shares, requiring an NFS client component that enables encryption in a tunnel using TLS. All AKS nodes now support this.
- Disable HTTP Proxy (Preview): The HTTP proxy feature can now be disabled on existing AKS clusters, as it is enabled by default.
- EV6 Series Virtual Machines: The memory-optimized E series VMs now have 128 and 192 virtual CPU sizes. V6 includes Azure Boost for improved storage and network throughput, Intel TME for system memory data protection, and NVMe for higher throughput. Up to 1,832 GB of RAM is available.
4. Networking
- Azure DNS DNSSEC (GA in US Gov and China Clouds): DNSSEC provides cryptographic authentication for DNS records, preventing spoofing and cache poisoning. Records are signed, and clients can validate the signature against the public key.
- Azure Virtual Network Manager (AVNM) Mesh Limit: AVNM now supports up to 5,000 virtual networks in a mesh configuration. The mesh provides complete connectivity between all networks without traditional peering, enabling direct communication between spokes even with a hub-and-spoke architecture.
- Network Security Perimeter (GA): Allows grouping PaaS resources that don't reside within a virtual network into a network security perimeter. This enables secure communication between these resources and defines allowed inbound/outbound connections, reducing data exfiltration risks.
5. Storage
- Azure File Sync Azure Arc Extension (GA): The Azure File Sync agent can now be deployed via Azure Arc to Windows Servers (2012R2 or later), enabling synchronization between on-premises file servers and Azure file shares.
- Azure Data Box Next Gen: The new form factor with 120 and 525 TB versions is now available in more regions with next-day shipping and cross-region copy at no extra cost.
- Azure Storage Actions: Available in 22 more regions, providing granular capabilities to perform actions on storage accounts beyond Azure lifecycle management, including blob data lake actions, large-scale operations, complex criteria, immutability, data protection, and deletion.
- Azure Storage Discovery (Preview): Performs analysis at scale to understand usage capacity, activity, and patterns for cost optimization. The free offering provides basic capacity insights, while the standard offering includes additional insights into transactions and configurations. Standard billing starts October 1st, with 18 months of retention for standard and 15 days for free. It integrates with Azure C-Pilot for natural language interactions and covers multiple storage accounts across subscriptions within the same tenant.
6. Miscellaneous (AI and Backup)
- GPT-5 in Azure AI Foundry: GPT-5 is available in Azure AI Foundry, GitHub models playground, and GitHub API. Four versions are available:
- GPT-5: Logic and multi-step tasks, 272,000 token context, improved reasoning and coding.
- GPT-5 Mini: Lightweight version for cost-sensitive apps.
- GPT-5 Nano: Optimized for speed and low latency, good for Q&A.
- GPT-5 Chat: Advanced natural multimodal context-aware conversations, up to 128,000 model context. GPT-5 can determine the appropriate path for the right level of response. Older models are being retired due to GPT-5's flexibility.
- GPT Image 1 Update: Improved control over fidelity based on source materials, allowing for better brand identity maintenance. It can also stream partial images.
- Open Source LLMs in Foundry: Open-source versions of GPT are available, with 120 billion and 20 billion parameter versions. The 120 billion parameter model is on par with OpenAI 04 mini on core reasoning and requires an 80 GB GPU. The 20 billion parameter model is suitable for agentic AI tasks, code execution, and tool use, and can run on a 16 GB VRAM GPU. These are compatible with the OpenAI responses API. Open source means the weights and biases of the neural network are publicly available.
- Azure Backup Multi-Disk Agentless Crash Consistent Backup: Takes backups without agent software in the guest OS, capturing all disks at the same moment in time. It is not app-consistent. The consistency type must be set to "crash consistent snapshot" in the enhanced VM backup policy.
- AI Shell MCP Support: The Azure AI shell now acts as an MCP client, allowing it to integrate with multiple MCP servers for added knowledge and tools via a configuration file.
Conclusion:
This Azure update covers a wide range of enhancements and new features across various services, with a strong focus on AKS, AI, and storage. Key takeaways include the advancements in AKS networking, security, and management, the availability of GPT-5 in Azure AI Foundry, and the improvements to Azure storage capabilities. The update also highlights the growing importance of cloud-native technologies and the increasing integration of AI into Azure services.
AI summaries can miss context or contain errors. Check important details against the original video.





