Blog Post

Core Infrastructure and Security Blog
13 MIN READ

Check This Out! (CTO!) Guide (August 2026)

TysonPaul's avatar
TysonPaul
Icon for Microsoft rankMicrosoft
Aug 03, 2026

Hi everyone! Tyson Paul here with this month’s “Check This Out!” (CTO!) guide. Our goal with these posts is to guide you toward content that piques your interest, whether it's for learning, troubleshooting, or discovering new sources. Each month, we’ll give you a snapshot of intriguing blog content, provide direct links to the source material, and introduce you to other valuable blogs you might not know about yet. Thank you for your continued support from all of us on the Core Infrastructure and Security Tech Community blog team!

Member: TysonPaul | Microsoft Community Hub

Enhanced host pool management for Azure Virtual Desktop is now generally available

Team Blog: Azure Virtual Desktop

Author: NeoCai

Published: 07/09/2026

Summary: Azure Virtual Desktop has introduced enhanced host pool management, now generally available, featuring session host configuration and update, dynamic autoscale, and ephemeral OS disks. These improvements streamline management, reduce operational overhead, and support secure, reliable, and scalable virtual environments. Session host configuration enables centralized settings and easy updates, ephemeral OS disks improve performance and rapid refresh for stateless workloads, and dynamic autoscale optimizes resource allocation and cost efficiency based on demand. Administrators can easily configure these features through the Azure portal for more efficient and consistent host pool management.

Embedded Image

How SCBX built AI literacy at scale and made AI part of daily work

Team Blog: Microsoft Learn

Author: ToddMinor

Published: 07/30/2026

Summary: SCBX partnered with Trainocate and Microsoft to boost AI literacy and embed AI in daily work across thousands of employees. Through a phased, role-based training approach—combining foundational learning, practical application, and advanced technical tracks—SCBX ensured adoption at scale while maintaining governance standards. Over 15,000 participants engaged, with measurable gains in productivity and satisfaction as teams automated repetitive tasks and applied AI in their roles. SCBX’s experience highlights the value of structured, outcome-focused skilling to drive AI readiness and business transformation across a regulated enterprise.

Embedded Image

New Microsoft 365 Certified: AI Services Administrator Associate Certification

Team Blog: Microsoft Learn

Author: LibertyMunson

Published: 07/28/2026

Summary: Microsoft has launched the Microsoft 365 Certified: AI Services Administrator Associate certification, validating skills to configure, manage, secure, and optimize Microsoft 365 and AI services like Copilot at enterprise scale. Candidates must pass Exam AB-650 (beta), which is discounted 80% for the first 300 test-takers before August 18, 2026, using code AB-650SkyClub. The certification is designed for experienced Microsoft 365 administrators with knowledge of Entra ID, Defender XDR, and Microsoft Graph PowerShell. Preparation resources and exam details are available online, with general availability expected in October 2026.

Embedded Image

Hunting Local AI Tools on macOS with Microsoft Defender for Endpoint

Team Blog: Core Infrastructure and Security

Author: Vytas_Boyev

Published: 07/14/2026

Summary: The article discusses emerging security challenges as developers increasingly run AI tools locally on macOS, expanding the attack surface for organizations. It outlines how Microsoft Defender for Endpoint (MDE) can detect and inventory local AI agents, such as Ollama and OpenClaw, using advanced KQL queries for process, file, and network telemetry. Recommendations include establishing a baseline inventory, monitoring new AI tool usage, skill file changes, suspicious behaviors, and external network connections. The article emphasizes a layered, tuned detection strategy, practical limitations, and the importance of visibility over default blocking to manage AI risks effectively.

Embedded Image

Azure Database Security Newsletter - July 2026

Team Blog: Core Infrastructure and Security

Author: PieterVanhove

Published: 07/07/2026

Summary: **Summary:** The July 2026 Azure Database Security Newsletter highlights the evolving impact of AI agents on database security, emphasizing identity-first access, least privilege, data-aware protection, and continuous monitoring. Key updates include support for AES keys in Transparent Data Encryption, Microsoft Entra server principals for Azure SQL Database, cross-tenant key management for PostgreSQL, and Defender security posture assessments. Best practices urge secure-by-default configurations, data classification, and ongoing vulnerability assessments. The newsletter also features recent blogs, events, and calls to review agent access as AI-driven workloads increase, stressing proactive database security adaptation.

Embedded Image

Agent governance is organizational readiness

Team Blog: FastTrack

Author: AuzinAhmadi

Published: 07/30/2026

Summary: The article emphasizes that effective agent governance is essential for scaling AI in healthcare organizations. It argues that success depends less on technology and more on readiness—specifically, whether governance structures ensure agents fit clinical workflows, assign clear accountability, manage risk, and secure stakeholder trust. A governance triad (IT, Legal, Business) is needed to vet, approve, and monitor agents before deployment. A checklist ensures readiness by confirming ownership, data access, measurable outcomes, and shutdown conditions. Ultimately, strong governance—not just technical capability—determines whether AI agents are safely and successfully integrated into healthcare operations.

Embedded Image

Understanding Copilot Risk: Mapping Exposure Across Zero Trust Pillars

Team Blog: FastTrack

Author: AuzinAhmadi

Published: 07/06/2026

Summary: The article examines Microsoft 365 Copilot’s impact on organizational data security, highlighting how Copilot accelerates data discovery based on existing user permissions. It maps Copilot-related risks across four Zero Trust pillars—identity, endpoints, apps, and data—emphasizing the importance of access governance, permission hygiene, and data protection. Copilot doesn’t grant new access but amplifies the exposure of overshared or poorly governed content. Organizations should assess who can access Copilot and what data it surfaces, using Zero Trust strategies to identify and mitigate risks before scaling deployments.

Embedded Image

Azure Arc Server June Forum

Team Blog: Azure Arc

Author: Aurnov_Chattopadhyay

Published: 07/29/2026

Summary: The June 2026 Azure Arc Server Forum covered updates on Arc Server AI Agent integration, new multicloud connectors for GCP and EKS clusters, and ESU timelines for Windows Server 2016 and SQL Server 2016. Attendees received guidance on enrollment and licensing, and were informed about upcoming end-of-support dates. The forum will pause for July and August, resuming in September. Leadership of the community calls is transitioning to Mason Torres, Yunis Hussein, and Meagan McCrory. Registration and agent release notes are available online.

Embedded Image

Plan for Upcoming Changes to Extended Security Updates on Azure Local

Team Blog: Azure Arc

Author: sydbruck

Published: 07/09/2026

Summary: Starting April 1, 2026, Microsoft will implement a uniform pricing model for Extended Security Updates (ESU) for SQL Server and Windows products, regardless of deployment location or purchasing channel. This affects new ESU offerings, such as Windows 10 Enterprise LTSB 2016 and Windows Server 2016, but not existing ESUs. Customers are encouraged to upgrade to newer versions before end of support; further ESU pricing and availability details will be announced. Existing ESUs remain free on Azure Local via Azure Verification for VMs.

Embedded Image

Beyond the Canvas: The Azure Architecture Diagram Builder Becomes Agent-Ready

Team Blog: Azure Architecture

Author: arturoqu

Published: 07/10/2026

Summary: The Azure Architecture Diagram Builder has evolved from a click-based app to an agent-ready platform. Key updates include Architecture Chat for iterative, conversational design, Blueprint Diagrams for whiteboard-style visuals, and support for 14 AI models. The tool now operates as a Model Context Protocol (MCP) server, enabling agents to generate, validate, estimate costs, and render Azure architectures programmatically. Enhancements include deployment guides grounded in Microsoft Learn, cost badges, theme options, and metadata panels. The platform remains open-source, offering evidence-based model comparison and integration for both human users and AI agents.

Embedded Image

Skill or Sub-Agent. Choosing AI Capabilities You Will Actually Reuse

Team Blog: Azure Architecture

Author: KishoreKumarPattabiraman

Published: 07/30/2026

Summary: The article advises cloud architects and engineering leaders to prioritize choosing the right AI capability shape—skill or sub-agent—over model selection. Skills are iterative, voice-driven, and require ongoing human involvement, ideal for craft and subjective tasks. Sub-agents handle structured, repeatable work with one-off outputs and minimal human gating. The recommended approach is to match the capability to the work's nature, sometimes combining both, to maximize reuse and effectiveness. Teams should assess iteration, output, blast radius, and frequency before building, avoiding the mistake of forcing all tasks into a single delivery shape.

Embedded Image

Introducing Kubernetes-Native Policy Validation with CEL and VAP in Azure Policy

Team Blog: Azure Governance and Management

Author: stevenbucher

Published: 07/23/2026

Summary: Azure Policy for Kubernetes now supports Kubernetes-native policy validation using Common Expression Language (CEL) and Validating Admission Policy (VAP) with Gatekeeper integration. This enables faster, in-process policy enforcement directly in the Kubernetes API server, improving reliability and latency over previous OPA Rego-based webhook methods. Users write CEL constraint templates, package them as Azure Policy definitions, and deploy them for governance, audit, and enforcement. This approach enhances compliance tracking and centralized management for AKS clusters running Kubernetes v1.30+, combining native validation logic with Azure Policy’s robust governance capabilities.

Embedded Image

Introducing Compliance Substate for Azure Policy Exemptions!

Team Blog: Azure Governance and Management

Author: stevenbucher

Published: 07/28/2026

Summary: Azure Policy now introduces a compliance substate for exempted resources, revealing their underlying compliance status even when exemptions are applied. Previously, exemptions hid whether a resource was compliant or not, making audits difficult. Now, resources show "Exempt" plus a substate ("Compliant" or "Non-compliant"), enabling easier exemption management and cleanup. The compliance substate can be viewed in the Azure Policy blade, added as a column, and queried across subscriptions using Azure Resource Graph, improving governance visibility and confidence in policy enforcement.

Embedded Image

Reservation exchanges for Azure services covered by savings plans end starting Feb. 1, 2027

Team Blog: FinOps

Author: kyleikeda

Published: 07/30/2026

Summary: Starting February 1, 2027, Azure reservation exchanges will no longer be available for services covered by savings plans, aligning policies for greater clarity. Impacted services include several compute and database offerings. Existing reservations purchased before this date retain one final exchange right. Reservations remain available for stable workloads, while savings plans offer flexibility for dynamic needs. Instance size flexibility and cancellation policies are unchanged. Customers should review their reservation portfolios and consider savings plans for future flexibility. Policy details may evolve as savings plan coverage expands.

Embedded Image

Introducing Cost Management and Pricing Toolsets in Azure Resource Manager MCP Server

Team Blog: FinOps

Author: demiajayi

Published: 07/29/2026

Summary: Microsoft has integrated Cost Management and Pricing toolsets into Azure Resource Manager MCP, allowing AI agents to access and analyze Azure cost, pricing, budget, and optimization data directly within cloud workflows. This enables users to estimate costs before deployment, track and explain spending, manage budgets, identify savings, and analyze AKS workloads without switching tools. The release provides APIs for querying costs, managing budgets, reviewing savings opportunities, and retrieving pricing details, making cloud operations more cost-aware and efficient. Installation requires VS Code, an Azure account, and specific configuration steps. Future enhancements and feedback opportunities are planned.

Embedded Image

From hours to minutes: Rethinking Microsoft Intune compliance reporting with the Export API

Team Blog: Intune Customer Success

Author: Intune_Support_Team

Published: 07/24/2026

Summary: The article explains how Microsoft Intune’s Export API dramatically improves compliance reporting for large device fleets. By replacing thousands of per-device Graph API calls with a single bulk export, reporting jobs drop from ~100,000 calls and 2.5 hours runtime to ~15 calls and 15 minutes. The Export API delivers identical data in one file, simplifying maintenance, reducing failure points, and enabling scalability without downstream changes. It’s ideal for scheduled, bulk reports, while traditional endpoints remain best for real-time, single-device queries. Overall, the Export API offers faster, more reliable, and scalable compliance reporting.

Embedded Image

Build a patch strategy for today’s threat pace with Microsoft

Team Blog: Intune Customer Success

Author: Intune_Support_Team

Published: 07/09/2026

Summary: Microsoft outlines a modern patch strategy to address today’s fast-paced threat landscape, leveraging AI and integrated tools like Intune and Microsoft Defender. The approach focuses on three stages: automating updates for quick mitigation, prioritizing remediation based on risk and exposure, and enforcing compliance to contain unpatched vulnerabilities. Intune centralizes management for Windows, Apple, and Android devices, supporting automated updates, risk assessment dashboards, and compliance controls. This operational discipline helps organizations reduce risk, accelerate response times, and maintain secure, up-to-date endpoints across diverse device fleets. Licensing requirements for advanced features vary by Microsoft 365 subscription.

Embedded Image

Azure Elastic SAN: Pooled, Cloud-Native Block Storage That Actually Acts Like a SAN

Team Blog: ITOps Talk

Author: Pierre_Roman

Published: 07/17/2026

Summary: Azure Elastic SAN is Azure’s fully managed, cloud-native SAN storage, offering pooled block storage accessible via iSCSI. It enables IT pros to provision combined capacity and performance, dynamically sharing resources across multiple workloads, reducing over-provisioning and costs. Supporting up to petabyte-scale, millions of IOPS, and high throughput, Elastic SAN integrates with Azure VMs, Kubernetes, VMware, and container storage. It provides familiar SAN resource hierarchy, network isolation, encryption, snapshots, and cost-effective scaling. Best suited for consolidating many IO-intensive workloads, Elastic SAN delivers significant TCO savings and simplifies migration from on-prem SANs.

Embedded Image

Premium SSD v2 and Instant Access Snapshots: A Better, Faster, Cheaper Disk for Your Azure VMs

Team Blog: ITOps Talk

Author: Pierre_Roman

Published: 07/20/2026

Summary: Premium SSD v2 (PV2) for Azure VMs offers significant improvements over Premium SSD v1, delivering up to 4x more IOPS, 2x more throughput, and 42% lower costs. Key features include independent scaling of capacity, IOPS, and throughput, sub-millisecond latency, and live resizing without VM downtime. Instant Access Snapshots enable near-instant restores and faster, lower-latency hydration. PV2 is ideal for I/O-intensive workloads like SQL, SAP, and analytics, and supports efficient scaling, rapid recovery, and cost optimization. However, it cannot be used as an OS disk or with host caching.

Embedded Image

Microsoft Discovery: Where HPC meets agentic AI for the next era of EDA

Team Blog: Azure High Performance Computing (HPC)

Author: richpaw

Published: 07/21/2026

Summary: Microsoft Discovery is an enterprise agentic AI platform designed to enhance electronic design automation (EDA) by combining high-performance computing (HPC) with intelligent orchestration. Built on Azure, it coordinates specialized AI agents to reason, plan, execute, and learn across complex engineering workflows, optimizing tasks such as simulation, analysis, and documentation. Discovery integrates seamlessly with Azure HPC, storage, and automation tools, enabling hybrid workflows and improving engineering productivity. Its human-in-the-loop approach ensures transparency and validation through established EDA practices, allowing engineers to focus on creative problem-solving while repetitive tasks are automated.

Embedded Image

Connecting Microsoft Discovery App to Azure HPC with Azure NetApp Files and CycleCloud

Team Blog: Azure High Performance Computing (HPC)

Author: richpaw

Published: 07/21/2026

Summary: The article outlines how to integrate Microsoft Discovery, an AI platform for R&D, with traditional Azure HPC environments using Azure NetApp Files and CycleCloud. By running Discovery on a Windows VM within the Azure network, mapping shared storage, and utilizing SSH for job submission, users can bridge AI-native and HPC workflows. This enables Discovery agents to manage files, submit jobs, and interact securely with HPC clusters, leveraging AI to automate and enhance engineering workloads without disrupting existing processes, while maintaining security, performance, and operational best practices.

Embedded Image

Move a live GitLab project between groups without breaking Terraform state or CI/CD

Team Blog: Azure Infrastructure

Author: HimanshuYadav

Published: 07/31/2026

Summary: Moving a live GitLab project between groups can disrupt Terraform state, CI/CD variables, runners, and cloud authentication if paths are hardcoded or inherited resources aren’t handled. The project ID remains unchanged, but group-level variables and runners must be recreated or reconfigured. Key the Terraform backend to the project ID, not the project path, and update any cloud credentials mapped to the old namespace. Thorough inventory, backups, and a freeze window ensure a safe transfer and rollback. Validate everything post-move to avoid drift or broken pipelines. Proper preparation and verification prevent common pitfalls.

Embedded Image

Azure Cobalt: Workload-Aware Power Management for More Efficient Datacenters

Team Blog: Azure Infrastructure

Author: redsa

Published: 07/16/2026

Summary: Microsoft’s Azure Cobalt CPUs introduce industry-first, per-VM power monitoring and capping, achieved through hardware/software co-design. This enables fine-grained, workload-aware power management, selectively throttling non-critical VMs while preserving performance for priority workloads. The approach allows up to 20% more power oversubscription and 24% higher performance compared to software-only capping, supporting more efficient datacenter operations and sustainability. End-to-end integration across Azure infrastructure enables optimized VM placement and real-time telemetry, demonstrating the benefits of deep hardware/software collaboration for balancing performance, efficiency, and sustainability in cloud environments.

Embedded Image

Microsoft is headed to VMware Explore 2026 in Las Vegas

Team Blog: Azure Migration and Modernization

Author: KirstenMegahan

Published: 07/28/2026

Summary: Microsoft will participate in VMware Explore 2026 in Las Vegas, offering breakout sessions and expert roundtables focused on Azure and its partnership with VMware by Broadcom. Attendees can learn about streamlined migration of VMware workloads to Azure, maximizing on-premises investments, and leveraging AI innovation. Sessions will cover migration best practices, security, and unlocking data and AI capabilities, along with enticing migration offers. The event aims to help businesses gain a competitive edge by transitioning from on-premises to Azure.

Embedded Image

Azure Front Door edge actions: programmable compute for a secure, resilient, AI-ready edge

Team Blog: Azure Networking

Author: AbhishekTiwari

Published: 07/30/2026

Summary: Azure Front Door edge actions introduces programmable compute at Microsoft's global edge, enabling customer-defined logic for secure, low-latency web experiences. Its architecture prioritizes hyperscale performance, strong security, tenant isolation, and resiliency using Hyperlight micro-VMs for hardware-backed isolation. Edge actions maintains local execution to minimize latency, employs fast-fail and circuit-breakers for stability, and continuously validates resiliency through Game Days. Designed for current and future intelligent workloads, it ensures programmability without compromising Azure Front Door’s reliability, security, or performance, making edge programmability a foundational capability for modern applications.

Embedded Image

Scale limits in network security perimeter

Team Blog: Azure Networking

Author: shashankamalladi

Published: 07/31/2026

Summary: The article outlines updated hard limits for network security perimeters in PaaS deployments, including 1,000 perimeters per subscription, 200 profiles per perimeter, 200 rule elements per profile, and 2,500 associated PaaS resources. Rule elements per profile are now capped at 200 for new customers. Existing customers exceeding 200 can edit or reduce rules until October 31, 2026; after that, only reductions are allowed. These changes aim to enforce consistent security scalability and operational boundaries.

Embedded Image

Secure Native Access to Azure Kubernetes Service (AKS) Private Clusters with Azure Bastion

Team Blog: Azure Network Security

Author: saikishor

Published: 07/09/2026

Summary: The article explains how Azure Bastion's native client tunneling (now in public preview) enables secure, simplified access to private Azure Kubernetes Service (AKS) clusters without needing VPNs or jump hosts. Bastion establishes an encrypted tunnel from engineers’ local machines to the private AKS API server, maintaining strong network isolation. It supports modern authentication methods, including Microsoft Entra ID and Azure RBAC, for centralized, auditable access control. This approach streamlines cluster management while enhancing security by removing public endpoints and reducing exposure to credential theft or infrastructure compromise.

Embedded Image

Optimize Oracle workloads on Azure with Azure NetApp Files

Team Blog: Azure Storage

Author: GeertVanTeylingen

Published: 07/09/2026

Summary: The article details recent advancements in Azure NetApp Files that optimize Oracle workloads on Azure, focusing on predictable performance, flexible scaling, and enhanced data protection. Key features include flexible service level capacity pools, automated application volume group deployment, availability zone-aware volume placement, integrated migration tools, space-efficient short-term clones, cool access tiering, and rapid backup and test/dev refreshes. These improvements enable easier Oracle environment sizing, deployment, protection, and scaling, reducing costs and complexity while supporting business continuity and modernization of Oracle workloads in the Azure cloud.

Embedded Image

Terraform AzureRM provider 5.0 now generally available

Team Blog: Azure Tools

Author: stevenjma

Published: 07/29/2026

Summary: Terraform AzureRM Provider 5.0 is now generally available, offering major improvements for managing Azure infrastructure as code. Key updates include greater control over Azure Resource Provider registration, optional Azure preflight validation to catch issues earlier, and removal of deprecated resources and properties. Users are advised to carefully review their configurations before upgrading due to breaking changes. The release aims to provide clearer provider behavior, faster feedback during workflows, and a cleaner foundation for future Azure features. Detailed migration guidance and changelog are available to assist with upgrading.

Embedded Image
Published Aug 03, 2026
Version 1.0