Recent Discussions
How to create a active bugs trend chart
Hi everybody! I'd like to create a Active bug trends, like this: However, everytime that I try to create this, I always have this result My chart always sum the quantity of bugs, not the trend When I try to setup my chart, I have this screen Note that I have the option Count. My question is: How to create a active bug trend chart? I try this documentation but, no success: https://learn.microsoft.com/en-us/azure/devops/boards/backlogs/manage-bugs?view=azure-devops#monitor-bug-status-assignments-and-trends Thanks for Advice Mauricio976Views0likes2CommentsMicrosoft 365 business tenant blocked – AADSTS5000228 – sole Global Administrator
Please create a service request for a blocked Microsoft Entra tenant and escalate it to the Data Protection / Tenant Recovery Team. Tenant: valtechme.onmicrosoft.com Tenant ID: 80940ba0-e307-45b2-b5fd-05b9759a4594 Error: AADSTS5000228 I am the sole Global Administrator. I am posting this here, since getting microsoft support is almost impossible , via phone, email or web. Can someone please help me with this issue.28Views0likes1CommentHow to recover global admin access to tenant
I have already tried posting this to the general Microsoft Q&A forums and received no response. We are desperate to figure something out so if this is not the correct line of communication, please direct me to where I should go. My company is in a bit of a bind right now, and I am at my wit's end after almost a week of trying to get in contact with anyone who could help. We have multiple directories in Azure that belong to us, but they are all independent of each other. As such, some directories have multiple global admins (and thus are not an issue); others -- and quite frankly, the most important ones -- only have one global admin, and it was our DevOps person, who is no longer employed with us. We have no way of accessing his account, and thus no way of accessing a global admin account for these directories/tenants. Access to these directories is critical to our operations. We were informed last Friday by someone from the data protection team that they could not give us access to these tenants we pay thousands of dollars a month for because: Our former DevOps person registered all other users as guests/external users, and DPT "can't give external users admin permissions", and To reset the MFA of the current global admin account, the owner of the account (who no longer works for our company) would need to contact them and verify their identity What options do we have here? We have blobs full of user-uploaded files in these tenants. Starting over from scratch is a doomsday scenario we are trying everything we can to avoid. Surely there has to be something that can be done?125Views0likes5CommentsProblems with FSLogix 3.26 - W11 MU - 10 users per Vm
Scenario Overview We are documenting a recurring intermittent Denial of Service (DoS) regarding user profiles in an AVD multi-session environment using Azure Files Premium (SMB). The issue consistently surfaces after updating to the FSLogix 3.26 branch (v3.26.126.19110). Root Cause Analysis (Failure Logs) Through deep log analysis, we identified a "driver poisoning" pattern unique to version 3.26: SMB/Kerberos Handshake Sensitivity: Under varying storage response times (latency spikes of ~350ms vs. the usual ~40ms), version 3.26 triggers an intermittent 1326 error (Logon failure: unknown user name or bad password). Driver Execution Flow Corruption: Unlike previous versions, after this initial network/authentication glitch, the 3.26 driver fails to release execution threads or volume handles properly. Catastrophic Failure (Error 267): The system attempts to access the SecuredProfileRegData path within the mounted VHDX, but the driver returns Event ID 26: "0x10b - The directory name is invalid". Unrecoverable "Zombie" State: Once Error 267 occurs, the VM becomes "poisoned." It blocks all subsequent login attempts and even prevents a clean uninstallation of the agent (MSI Error 0x80070643 due to files being "in use"), necessitating a full VM reboot or redeployment. Has anyone else been through this? My first step was to go back to Agent Version 2506 (2210 Hotfix 4) Evidence of Success with Version 2506 (2210 Hotfix 4) After performing a clean deployment and reverting to version 3.25.626.21064, metrics from April 24, 2026, show absolute stability on the same infrastructure: Consistent Logon Times: Average profile load time of 1.6 seconds across multiple concurrent users Storage Efficiency: FindFile response times remained stable between 39ms and 45ms, with the agent successfully retrying any momentary delays. Error Resilience: Unlike v3.26, if this version encounters an authentication glitch (e.g., on a local service account), it bypasses the error and remains functional, allowing domain users to log in without collateral blockages. Concurrency Support: Seamlessly managed over 20 simultaneously mounted volumes without pointer collisions or kernel hangs.444Views1like4CommentsCost increases when selecting Amortised cost in cost analysis
Hi, this seems like a bug. When i select Amortized cost in Cost analysis, our monthly cost jumps from $25,664.54 to $76,315.83. The resource that causes the jump is a Reservation for a D4asv5 virtual machine. It jumps to $3,120.09 per day. Can someone please try it their side.16Views0likes1CommentConversion of epoch / unixtimestamps within Log Analytics
we re using a lot of epoch / unixtimestamps (seconds since 1970-1-1) in our solution and are wondering right now if there is the possibilty to convert those timestamps to datetime objects within loganalytics queries? Unfortunately we couldn't find anything in the documentation on that matter. Would be great if someone could point us in the right direction.5.2KViews1like4CommentsBLOG: Explaining Azure Local additions to licensing and hardware ecosystem - June 2026
Changelog: 1.2 - improved readability in licensing comparison section, adding sources. 1.1 - corrections for S2D + SAN / or SAN only, added link for solution comparison. 1.0 - initial version In this blog I will inform you about noteable additions and changes in terms of Azure Local Licensing and changes to the qualified, certified hardware required. Some of these changes also making it much easier re-using existing hardware with Azure Local, such as SANs. As this blog uses a couple of acronyms, please make yourself familiar with these in the terminology section at the end of this post, as it differs a bit from what is used with Windows Server. 🆕Change 1 - Licensing updates: Microsoft has released an addition to their all-known Azure Local pricelist and licensing conditions. What's new? Host Servicing Fee and revoked Azure Hybrid Benefits for Azure Local have been clarified based on its deployment decisions, when used with S2D + SAN or SAN and ALDO. Formerly revoked for M365 Local through product terms changes. With this Microsoft has introduced a new tier model for Azure Local Host fees based on the specific assignment of the deployed instance. Tier 1: Azure Local using Storage Spaces Direct (default) Tier 2: Azure Local for disaggregated deployments or hyperconverged deployments with external storage. Tier 3: Azure Local with disconnected operations, locally hosted control plane. Learn more about the the new Azure Local pricing tiers. Important note: Please always consult Microsoft Product Terms preferably over other pages, slides etc., understanding the definitive terms that apply. Any licensing statements written or displayed outside Product Terms - including this blogpost - are considered complementary. They might be incomplete or outdated given the context and respective licensing program that applies. 🆕Change 2 - Azure Local Solutions - hardware and ecosystem changes: Microsoft Azure Local Solutions page, formerly Azure Local Solution catalog, has seen a subtle but major overhaul some time ago. I would like to elaborate on these. The previously well-known "pyramid" of hardware certification and defined feature and support set for Azure Local has been revised. Tier 1: Premier Solutions Tier 2: Integrated Systems Tier 3: Validated Nodes The new hardware certification and defined feature and support sets: Tier 1: Premier Solutions Tier 2: Integrated Systems 𝗪𝗵𝗮𝘁 𝗵𝗮𝗽𝗽𝗲𝗻𝗲𝗱 𝗼𝗿 𝘄𝗶𝗹𝗹 𝗵𝗮𝗽𝗽𝗲𝗻 𝘁𝗼 𝘆𝗼𝘂𝗿 𝗩𝗮𝗹𝗶𝗱𝗮𝘁𝗲𝗱 𝗡𝗼𝗱𝗲𝘀? First, Validated Systems not to confuse with Azure Local validated hardware - have been entirely removed from the Azure Local Solutions | Microsoft, as a selectable solution category. Given the indications and filtering options - to my understanding - it is very unlikely that future hardware refreshes will be provided by the OEMs based on the Validated Systems. Thus I consider Validated Systems phased out / deprecated based on the readings on the Solution page, while there is no official announcement I am aware of. 𝗗𝗼𝗲𝘀 𝘁𝗵𝗶𝘀 𝘃𝗼𝗶𝗱 𝘆𝗼𝘂𝗿 validated solution 𝘆𝗼𝘂 𝗵𝗮𝘃𝗲 𝗱𝗲𝗽𝗹𝗼𝘆𝗲𝗱 𝗮𝗻𝗱 𝗿𝘂𝗻𝗻𝗶𝗻𝗴? I'd say no in most cases based on the age of the hardware and would like to advise the following: Brace and keep calm. 🙏🏻 Please consult the Azure Local Catalog for changes at your pace, identifying your deployed hardware. Checking for supportability (limited support or end of support statements). Validated Nodes are still visible in the Azure Catalog when choosing the filter options as shown in the picture, while the category filter itself has been removed. Please check with your Microsoft Partner and OEM, if deployed and still supported Validated Solutions actually got upgraded / or are upgradeable to Premier Nodes. I have been informed some are upgradeable from Validated Solution directly to Premier Nodes but this requires a redeployment of the nodes. How can I find my running Validated Nodes, when not listed (upgraded) in Premier Solutions or Integrated Systems? There is a selector in the Azure Local Solutions overview, call qualification generation. Wait, is that a kind of upselling? Speaking about the hardware for Azure Local, in my understanding this consolidation from a 3-tier model to a 2-tier model was long overdue and in my personal opinion I welcome it based on the technical changes and requirements Azure Local 23H2 and 24H2 implied. I wouldn't describe it as upselling and here is a pointer why: Some time ago, most Integrated Systems (Nodes) have been upgraded to Premier Solutions at no additional cost to partners and customers by Dell Technologies. While Dell took the lead, many OEMs followed suit. This also means that all fully supported deployed Azure Local nodes consistently support Quick Reboot, skipping lenghty BIOS POST time, when no UEFI firmware is pending for installation. Thankfully though, the inital Azure Local 23H2 approach by Dell, which involved pairing Premier Nodes with a mandantory layer of OEM provided software, has been dismissed. This approach required customers accepting the benefits of Premier Solutions while getting charged , storage capacity, CPU and RAM in return for a OEM specific management software and other OEM provided benefits. Vae victis, early adopters. While these remain supported, this is no longer the case for Premier Solutions of neither OEM offering these. What are your benefits when after the change potential upgrade? Please find this verbose comparison and also check the tabs on the top of the linked page: Comparison of Azure Local solutions. The benefits are huge, beneficial and practical for everyday operation, troubleshooting and support. Why the change? Microsoft has drastically improved the servicing workflow by using Azure Update Manager, Cluster Aware Update mechanisms and healthchecks, with the goal to near one-click automate the download, deployment and installation of SBE while also maintaining the Azure Local solution and keeping it up-to-date, with a friction-less and production-safe upgrade mechanism. This means monthly patching for Azure Local, since version 12.x builds based on Windows Server 2025 kernel were introduced, upgrade and monthly update reliability has finally met and exceeded expectations. Note that 11.x builds starting from 23H2 had some 'first release issues', but all teams at Microsoft worked extremely hard to overcome these. Learn more about the Azure Local releases and their update, upgrade and supportability terms. Azure Local Licensing Changes - Azure Hybrid Benefits for Windows Server Datacenter Tier / Scenario CSP Subscription (MCA) EA with SA MCA‑E with SA or Subscription Other Programs with SA 🟩 Tier 1 — Azure Local w. S2D Full AHB benefits Host fee pricing: 10$ per active core per month, unless exempted. 🖥️ No Azure Local fees or Windows Server Guest OS fees 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ No Azure Local fees or Guest OS fees 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ No Azure Local fees or Guest OS fees 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌 Connected 🟧 Tier 2 — Azure Local w. S2D + SAN or Azure w. SAN Azure Local host fees apply Host fee pricing: 20.1 $ per active core per month. No exemption. 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🗄️S2D + SAN or SAN only 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🗄️S2D + SAN or SAN only 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🗄️S2D + SAN or SAN only 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🗄️S2D + SAN or SAN only 🪪 WS Arc Management benefits elibigle 🔌 Connected 🟥 Tier 3 — Azure Local ALDO Offline, no Azure Arc access Host fee pricing: Contact Microsoft or eligible Microsoft partner 🖥️💲 Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌❌ fully disconnected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌❌ fully disconnected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌❌ fully disconnected 🖥️💲 Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌❌ fully disconnected 🟦 M365 Local on Azure Azure Local host fees apply Host fee pricing: Contact Microsoft or eligible Microsoft partner 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌 Connected 🖥️ 💲Azure Host and Guest OS fees apply - you might license Guest OS with Windows Server Azure Subscription or through volume licensing. 🪪 WS Arc Management benefits elibigle 🔌 Connected sources: https://www.microsoft.com/licensing/terms/productoffering/MicrosoftAzure/MCA#clause-2250-h3-1 (primary) https://learn.microsoft.com/en-us/azure/azure-arc/servers/windows-server-management-overview (complementary) https://azure.microsoft.com/en-us/pricing/details/azure-local/ (complementary) https://learn.microsoft.com/en-us/windows-server/get-started/azure-hybrid-benefit?tabs=azure-local (complementary) Azure Local Terminology Term / Category Definition Nodes Physical servers participating in an Azure Local deployment. Instance A cluster of Azure Local nodes forming a single logical deployment. AzL S2D Azure Local using highest‑performance, highly available local Software‑Defined Storage (S2D). System Builder Extension (SBE) packages Fully tested and supported driver + firmware recipes for the current Azure Local release, provided by OEMs in partnership with Microsoft for Premier Solutions. Solution Categories Defines ease of deployment, support boundaries, and feature availability across Azure Local solution types. Azure Local hyperconverged deployments with external storage (Azure Local S2D + SAN) Azure Local S2D combined with qualified SAN‑attached storage. Azure Local for disaggregated deployments (Azure Local with SAN) Azure Local without S2D, using qualified SAN‑attached storage. Azure Local Disconnected Operations (ALDO) Fully disconnected, locally hosted control plane mimicking Azure Portal functionality, ensuring full‑stack data locality for strict governance requirements. Azure Local M365 Azure Local configuration enabling Microsoft 365‑like services on‑premises using a specialized node and instance setup. Azure Local The on‑premises Azure‑consistent platform for compute, storage, and hybrid management. CSP (Cloud Solution Provider) Sales motion/program. Not related to Intune CSP policies. MCA (Microsoft Customer Agreement) Licensing framework underlying CSP purchases. Microsoft Product Terms (PT) Official licensing terms — the single authoritative source for Microsoft licensing information. Windows Server / Azure (Local) Hybrid Benefits (AHB) Licensing benefits for applicable programs, especially valuable for Arc‑enabled servers with active Software Assurance. Particularly beneficial for customers licensing Windows Server Datacenter hardware cores via Enterprise Agreement with SA or CSP Subscription. AHB varies by product and program; Product Terms remain the authoritative source. Software Assurance (SA) Term based or compulsory in Subscriptions, bundle of licensing and usage benefits compared to perpetual licensing. Since Arc and Azure Local ROI goes far beyond "running the latest". Missed anything, spotted wrong? Let me know in the comments below.Solved818Views3likes4CommentsMicrosoft.Maps reports Registered but account creation returns InvalidSubscription
Subscription de4c9e7e-6aea-487d-aace-3d1cf56a5a7c is Enabled PAYG. ARM reports Microsoft.Maps Registered and lists accounts/API versions/locations, but Microsoft.Maps is absent from the Portal provider list. Creating a Gen2 G2 Maps account through Portal, Azure CLI, and REST in Global or East US returns InvalidSubscription. We re-registered and waited over 30 minutes. Latest correlation ID: 50e56235-39b7-493e-9faf-fabf329b61db, timestamp 2026-07-28T18:09:02.3104310Z. How can the Maps subscription registration be repaired?27Views1like2CommentsOpen in VS Code for the web fails ... tunnel 400 error ?
Hello everyone, The last week I have problem connecting to VS Code for the Web, my cloudshell works correctly, my account is ok, everything works BUT when tryont to open through browser - azure portal the VS Code for the Web, I got errors similar to .... *************************** https://ccon-prod-northeurope-aci-01.servicebus.windows.net/.../tunnel Result: 400 Bad Request Response: {"error":{"message":"Error creating dev tunnel","details":""}} Tested from: - Multiple browsers - InPrivate - Different PC - Azure VM *************************** I even renamed ~/code , ~/.vscode-server-insiders and restart cloudshell and VSCode web, same errors (and folders were not recreated) Any help would be greatly appreciated !! BR, Panos60Views0likes4CommentsAzure Open AI
Hi Team, I have been trying to use gpt-4o capability on azure open-ai to pass base64 encoded image. But I m getting this response: {"requestPayload":null,"meta":{"blocking":true},"status":"completed","planId":"38334edf2b3242102d79fa97ce91bf37","capabilities":{"35070ec3fbb68e5007e5f69605efdc04":{"provider":"Azure OpenAI","response":"The provided JSON contains a structure with two main elements: a text prompt and an image URL. The text prompt asks, \"What’s in this image?\" and the image URL is encoded in base64 format. However, the base64 string for the image is incomplete and appears to be corrupted or truncated.\n\nTo properly analyze the image, the complete base64 string is required. If you can provide the full base64 string, I can help you decode and analyze the image. Alternatively, you can upload the image to a file-sharing service and provide the link.","logId":"7b40eb2b3b32c210f27a3c8c24e45ae1","status":"success"}},"startedAt":"2024-06-21 03:38:59","completedAt":"2024-06-21 03:39:07","transactionId":"e5564919-b644-43fb-b0ba-a2bc60016513","message":null} I have ensured the image URL is correct and contains correct base64 value but still its not working. What could be the issue?418Views0likes2CommentsAgentic AIOps vs Traditional AIOps: What Actually Changes in Practice?
Artificial Intelligence for IT Operations (AIOps) has transformed how organizations monitor, manage, and optimize modern IT infrastructure. By combining machine learning, analytics, and automation, Traditional AIOps has helped IT teams reduce alert fatigue, identify anomalies faster, and improve operational efficiency. https://dellenny.com/agentic-aiops-vs-traditional-aiops-what-actually-changes-in-practice/29Views0likes0CommentsHow to Build Your First IT Support Agent Using Azure AI
Artificial Intelligence is transforming the way businesses provide IT support. Instead of waiting for a technician to answer every question, organizations are increasingly using AI-powered support agents that can troubleshoot common issues, answer employee questions, and automate repetitive tasks. Thanks to Microsoft Azure AI, building an intelligent IT support agent is no longer limited to data scientists or large enterprises. Even beginners can create a functional AI assistant with minimal coding. https://dellenny.com/how-to-build-your-first-it-support-agent-using-azure-ai/30Views0likes0CommentsDealing with Legacy Systems and Services in Cloud Computing
Every organization reaches a point where technology that once powered innovation begins to slow progress. Legacy systems, although reliable and familiar, often become barriers to growth, agility, and digital transformation. As businesses increasingly adopt cloud computing to improve scalability, reduce operational costs, and enhance security, one major challenge remains how to deal with legacy systems and services without disrupting business operations. https://dellenny.com/dealing-with-legacy-systems-and-services-in-cloud-computing/21Views0likes0CommentsCannot run "Get-SolutionUpdate" or "Get-SolutionUpdateEnvironment" after updating to 2604
My Azure Local environment had been a bit out of date for the last few months so I was catching it up with the updates, stepping from 2602 to 2603 and then to 2604 last night. Since that update, when I run "Get-SolutionUpdate" or "Get-SolutionUpdateEnvironment" the command hangs for a few minutes and then eventually returns with something like the following: get-solutionUpdate : A WebException occurred while sending a RestRequest. WebException.Status: SendFailure on https://FQDN:4900/providers/Microsoft.Update.Admin/updateLocations?api-version=2022-08-01 + CategoryInfo : ConnectionError: (:) [Get-SolutionUpdate], SendFailureException + FullyQualifiedErrorId : SendFailureException,Microsoft.AzureStack.Lcm.PowerShell.GetSolutionUpdateCmdlet get-solutionUpdate : Object reference not set to an instance of an object. + CategoryInfo : InvalidOperation: (:) [Get-SolutionUpdate], NullReferenceException + FullyQualifiedErrorId : NullReferenceException,Microsoft.AzureStack.Lcm.PowerShell.GetSolutionUpdateCmdlet I have tried https://github.com/Azure/AzureLocal-Supportability/blob/main/TSG/Update/Get-SolutionUpdate-GatewayTimeout.md to try resolve it as it seemed similar but it hasn't helped. Any idea what might be going on?Solved64Views0likes4CommentsAzure App Service Environments Internal and External access
I am looking to deploy a internal Intranet site and an external internet site and i would like to try and use Azure Web Apps to do this. The intranet should only be accessible from internal networks however the public facing website will obviously need to be accessible from anywhere. At the moment it is looking like i would need to deploy an App Service Environment and host the intranet site in there but it would be nice if i could then create a separate app and host that from within the same ASE. I suspect i could do it if i put a web application gateway on the network with a public IP but i want to try and avoid that as it is additional management and overhead. How have others done this? Do you just host Web Apps using multiple app service plans?2.7KViews0likes4CommentsAzure App Service secure hostname
Hey Everyone, I see a new change in app service deployment related to the secure hostname. Is it now mandatory to have a secure hostname, because I don't see the option to toggle between the secure hostname and just the format for appservicename.azurewebsites.net ? I wasn't able to find any update notification to verify this change.378Views0likes5CommentsEmail Notification for failed Scheduled Pipleline runs on azure devops for Specific Env CD BUild
Hello All, I have a pipeline running to do a certain task and when the pipeline fails I get an email stating the build failed. However, I'm also scheduling this pipeline to run at 1am every day only for XX Env CD build in this case even if the build fails I don't get any notification email at all. I need to set up extra alert to get notified to my email if my schuduled build fails at Env Level. referd this but here I can do any Custome to have aaddition filter for My Env:https://learn.microsoft.com/en-us/azure/devops/organizations/notifications/manage-your-personal-notifications?view=azure-devops Thank you.411Views0likes2CommentsAdmin‑On‑Behalf‑Of issue when purchasing subscription
Hello everyone! I want to reach out to you on the internet and ask if anyone has the same issue as we do when creating PAYG Azure subscriptions in a customer's tenant, in which we have delegated access via GDAP through PartnerCenter. It is a bit AI formatted question. When an Azure NCE subscription is created for a customer via an Indirect Provider portal, the CSP Admin Agent (foreign principal) is not automatically assigned Owner on the subscription. As a result: AOBO (Admin‑On‑Behalf‑Of) does not activate The subscription is invisible to the partner when accessing Azure via Partner Center service links The partner cannot manage and deploy to a subscription they just provided This breaks the expected delegated administration flow. Expected Behavior For CSP‑created Azure subscriptions: The CSP Admin Agent group should automatically receive Owner (or equivalent) on the subscription AOBO should work immediately, without customer involvement The partner should be able to see the subscription in Azure Portal and deploy resources Actual Behavior Observed For Azure NCE subscriptions created via an Indirect Provider: No RBAC assignment is created for the foreign AdminAgent group The subscription is visible only to users inside the customer tenant Partner Center role (Admin Agent foreign group) is present, but without Azure RBAC. Required Customer Workaround For each new Azure NCE subscription, the customer must: Sign in as Global Admin Use “Elevate access to manage all Azure subscriptions and management groups” Assign themselves Owner on the subscription Manually assign Owner to the partner’s foreign AdminAgent group Only after this does AOBO start working. Example Partner tries to access the subscription: https://portal.azure.com/#@customer.onmicrosoft.com/resource/subscriptions/<subscription-id>/overview But there is no subscription visible "None of the entries matched the given filter" https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal%2Centra-audit-logs#step-1-elevate-access-for-a-global-administrator from the customer's global admin. and manual RBAC fix in Cloud console: az role assignment create \ --assignee-object-id "<AdminAgent-Foreign-Group-ObjectId>" \ --role "Owner" \ --scope "/subscriptions/<subscription-id>" \ --assignee-principal-type "ForeignGroup" After this, AOBO works as expected for delegated administrators (foreign user accounts). Why This Is a Problem Partners sell Azure subscriptions that they cannot access Forces resources from customers to involvement from customers Breaks delegated administration principles For Indirect CSPs managing many tenants, this is a decent operational blocker. Key Question to Microsoft / Community Does anyone else struggle with this? Is this behavior by design for Azure NCE + Indirect CSP? Am I missing some point of view on why not to do it in the suggested way?210Views0likes2CommentsVisual Studio Sign In Issues (Restricted IE)
Hi, Does anyone know how to get around the VS sign in issue when your organisation restrict the use of Internet Explorer for external sites? I get a blank screen as connection is blocked. Changing the default brower in VS doesnt seem to effect the sign page either. Thanks1.1KViews0likes2CommentsFree Extension: Generate AI Development Prompts from Azure DevOps Work Items — Verity Framework
Hi Azure DevOps community, I wanted to share a free extension we just published to the Visual Studio Marketplace: the Verity Framework ADO Extension. **What it does** It adds a "Verity Prompt" tab to your work items. When you populate five custom fields on a User Story or Delivery Item, the extension generates a structured prompt ready to paste into Claude Code, Cursor, or GitHub Copilot Workspace. The five fields: - VF Intent — the problem and who experiences it - VF Value — the expected outcome - VF Appetite — time/resource ceiling (not an estimate) - VF Trust Criteria — Gate 2 hardening requirements - VF Failure Scope — Narrow / Moderate / Broad / Systemic **Why it matters** Most engineers using AI tools start from a blank context or a vague task description. The extension carries the team's planning judgment — including production risk level and hardening requirements — directly into the implementation context. It also includes field validation that flags vague Trust Criteria, incorrectly formatted Appetite values, and solution-framed Intent statements before generating the prompt. **Setup** About 20 minutes. You add five custom fields to your existing User Story work item type (no new work item type required). Full instructions are in the extension tab. **Install** Search "Verity Framework" on the Visual Studio Marketplace or visit idearoost.com/verity for the full framework context. Free. No subscription required. Happy to answer questions about the field definitions or the setup process. — Jacques Steward, IdeaRoost29Views0likes0Comments
Events
Recent Blogs
- Presently, network security perimeter functionality can be used to support deployments of PaaS resources with common public network controls with following scale limitations: Limitation Descri...Jul 31, 202665Views0likes0Comments
- Maps have long served as the foundation for how organizations understand, navigate, and make decisions about the world. Yet generating and maintaining maps remains a highly manual, time-consuming, a...Jul 31, 2026186Views2likes0Comments