<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>New blog articles in Microsoft Community Hub</title>
    <link>https://techcommunity.microsoft.com/t5/</link>
    <description>Microsoft Community Hub</description>
    <pubDate>Thu, 23 Jul 2026 19:02:36 GMT</pubDate>
    <dc:creator>Community</dc:creator>
    <dc:date>2026-07-23T19:02:36Z</dc:date>
    <item>
      <title>🏆 Agents League: Celebrating the Builders Who Made Agents Battle for Glory</title>
      <link>https://techcommunity.microsoft.com/t5/educator-developer-blog/agents-league-celebrating-the-builders-who-made-agents-battle/ba-p/4538007</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The arena has closed, the scores are in, and the champions are crowned.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Agents League, the esports-inspired hackathon at the heart of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;AI Skills Fest 2026&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, brought together tens of thousands of developers to build, ship, and compete with agentic AI. This is the celebration post: a spotlight on the winners across every category, the numbers behind the movement, and the engineering lessons worth carrying into your next build.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you competed, watched a Reactor battle, or completed a skilling playlist, this recap is for you. You&amp;nbsp;didn't&amp;nbsp;just attend an event. You helped set a record.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before we get to the winners, there is a useful playbook hiding in their submissions. Later in this post, the section&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;“What the Winners Teach Us: Patterns Worth Stealing”&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;breaks down the build patterns future attendees should pay attention to: multi-agent orchestration, meeting users where they already work, testing discipline, and accessibility-first design. If you are planning to enter next time, read the winners not just as inspiration, but as a practical checklist for what great agent projects have in common.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;🥇 Best Overall: $15,000 Grand Prize&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;img /&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Afterlogin&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;: The Hunt — &lt;A class="lia-external-url" href="https://github.com/jlynch160/afterlogin-the-hunt" target="_blank" rel="noopener"&gt;https://github.com/jlynch160/afterlogin-the-hunt&lt;/A&gt;&amp;nbsp; (Creative Apps track)&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/H3&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The top weighted score of the entire field. Afterlogin: The Hunt is described by its builders as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;"one engine, two faces"&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: a cinematic Security Operations Centre (SOC) night on one side, and a coached training game on the other. The same underlying engine powers both an atmospheric narrative experience and a hands-on learning simulation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Why it won:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;it fused genuinely creative design with a real-world use case (security operations training) and&amp;nbsp;executed both at a high polish level. Built with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;GitHub Copilot&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for AI-assisted development,&amp;nbsp;it's&amp;nbsp;a masterclass in using one well-architected engine to serve two&amp;nbsp;very different&amp;nbsp;user experiences.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🏅 Category Champions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Best Creative App:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;StudyMate&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, "Study with Matey" — &lt;A class="lia-external-url" href="https://github.com/adetorojeremiahfadesayo/StudyMate" target="_blank" rel="noopener"&gt;https://github.com/adetorojeremiahfadesayo/StudyMate&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Tech: GitHub Copilot&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;StudyMate turns a student's&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;own&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;notes into a gamified, story-driven revision session, complete with XP and progression. Instead of generic flashcards, it grounds the experience in the learner's real material and wraps it in a narrative loop that keeps motivation high. It is&amp;nbsp;a great example&amp;nbsp;of pairing&amp;nbsp;personalisation&amp;nbsp;with game mechanics to solve a persistent problem: staying engaged while revising.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Best Reasoning Agent: DELPHAI — &lt;A class="lia-external-url" href="https://github.com/jlynch160/delphai" target="_blank" rel="noopener"&gt;https://github.com/jlynch160/delphai&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Tech: Microsoft Foundry&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;DELPHAI is an &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;11-agent reasoning council&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;that checks the&amp;nbsp;maths, explains the risk, and refines its own answer before responding. Rather than a single model producing&amp;nbsp;a one-shot&amp;nbsp;response, DELPHAI orchestrates a panel of&amp;nbsp;specialised&amp;nbsp;agents that debate, verify, and converge, a pattern that directly addresses the reliability gap in high-stakes reasoning.&amp;nbsp;It's&amp;nbsp;a textbook demonstration of multi-agent orchestration on&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Foundry&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Best Enterprise Agent: Archon — &lt;A class="lia-external-url" href="https://github.com/upgradedev/archon_azure" target="_blank" rel="noopener"&gt;https://github.com/upgradedev/archon_azure&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Tech: Microsoft 365 Copilot&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Archon is a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;7-agent financial-intelligence pipeline for small and medium businesses&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, delivered right inside Microsoft Teams. It meets users where they already work, chaining&amp;nbsp;specialised&amp;nbsp;agents to turn raw financial data into actionable intelligence. Archon shows how enterprise-ready agents built for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;can deliver serious business value without forcing users to leave their daily workflow.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🌟 Special Awards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Award&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Winner&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td colspan="2"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What made it stand out&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Best Use of IQ Tools&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CivicGrant&amp;nbsp;IQ —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/JonEricEubanks/CivicGrant-IQ" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/JonEricEubanks/CivicGrant-IQ&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td colspan="2"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Stood out for making the IQ layers genuinely useful: Foundry IQ, Fabric IQ and Work IQ were combined into a traceable grant-analysis workflow with grounded citations, specialist agents,&amp;nbsp;GraphRAG-style evidence handling, guardrails and evaluation coverage.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Accessibility&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CLARO —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/jagaor/claro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/jagaor/claro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;SchemeSaathi —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/red-coder-27/SchemeSaathi" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/red-coder-27/SchemeSaathi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Solace —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/MaksymY11/solace-reasoning" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/MaksymY11/solace-reasoning&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td colspan="2"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These teams treated accessibility as core product architecture, not a feature add-on: CLARO combined deterministic public-benefit rules with grounded bilingual reasoning;&amp;nbsp;SchemeSaathi&amp;nbsp;made health-scheme discovery usable across Indian languages; Solace delivered cited, plain-language immigration-rights support with safety escalation for sensitive situations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Hack for Good&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Tell My Day —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/stork066/TellMyDay" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/stork066/TellMyDay&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;BRIEF — AI Bias &amp;amp; Research Intelligence Evaluation Framework —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/shiwakshir/brief-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/shiwakshir/brief-agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;ARGUS — Agentic Risk &amp;amp; Governance Unified Screening —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/iarjunganesh/argus" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/iarjunganesh/argus&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td colspan="2"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each winner used agents for tangible social value: Tell My Day turns picture symbols into grounded stories for non-verbal users; BRIEF audits assumptions and bias before research begins; ARGUS turns manual KYC and governance screening into cited, auditable risk assessment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Top Student&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Athenaeum —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/theCodeForgerHQ/msf-reasoning-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/theCodeForgerHQ/msf-reasoning-agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Narrative Alchemist —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/10ANT/narrative-alchemist" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/10ANT/narrative-alchemist&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;CurriculumCraft AI —&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/gideonagbavor8/curriculumcraft-ai" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://github.com/gideonagbavor8/curriculumcraft-ai&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td colspan="2"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These student-led projects stood out for ambition and execution: Athenaeum showed exceptional engineering discipline with a deep safety and test harness; Narrative Alchemist&amp;nbsp;demonstrated&amp;nbsp;a complete four-agent creative production pipeline;&amp;nbsp;CurriculumCraft&amp;nbsp;AI translated AI into practical instructional design for Ghanaian JHS teachers.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.4436%" /&gt;&lt;col style="width: 34.7406%" /&gt;&lt;col style="width: 31.7761%" /&gt;&lt;col style="width: 0%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Across&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;8 categories&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;14 winners&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;shared a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;$55,000 prize pool&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. Congratulations to every one of them, and to the thousands of builders who&amp;nbsp;submitted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🧠 What the Winners Teach Us:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Patterns Worth Stealing&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Look across the champions and clear engineering patterns&amp;nbsp;emerge. These are the&amp;nbsp;takeaways&amp;nbsp;AI engineers and developers should carry into their own projects.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30); font-size: 28px;"&gt;1. Multi-agent orchestration beats the monolithic prompt&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The two reasoning-heavy winners, DELPHAI (11 agents) and Archon (7 agents), both won by decomposing a hard problem into&amp;nbsp;specialised, cooperating agents. A "council" or "pipeline" of narrow agents that verify each other outperforms a single model asked to do everything at once.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Here's&amp;nbsp;the shape of that pattern, illustrated conceptually with the Microsoft Agent Framework style used with Microsoft Foundry. (This is an illustrative pattern, not the winners' actual code.)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang=""&gt;# Illustrative multi-agent "reasoning council" pattern
# Conceptual sketch, not the winning team's source code.

async def reasoning_council(question: str) -&amp;gt; str:
    # 1. Specialised agents each own one responsibility
    solver = create_agent(
        role="Propose an answer with its reasoning"
    )

    math_check = create_agent(
        role="Verify every calculation, flag errors"
    )

    risk_agent = create_agent(
        role="Explain the risks and assumptions"
    )

    # 2. Draft, then critique
    draft = await solver.run(question)
    math = await math_check.run(draft)
    risk = await risk_agent.run(draft)

    # 3. Refine using the critiques before answering the user
    refined = await solver.run(
        f"Question: {question}\n"
        f"Draft: {draft}\n"
        f"Math review: {math}\n"
        f"Risk review: {risk}\n"
        "Produce a corrected, final answer."
    )

    return refined&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The lesson:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;reliability comes from structure. Give each agent one job, let them check each other, and refine before you respond. That is exactly how DELPHAI "checks the math, explains the risk, and refines its answer."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30); font-size: 28px;"&gt;2. Meet users where they already are&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Archon delivers financial intelligence&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;inside Microsoft Teams&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;StudyMate&amp;nbsp;builds on a student's&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;own notes&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. Winning agents reduce friction by integrating into existing workflows rather than asking users to adopt a new destination. When you build enterprise agents, target the surface, such as Microsoft 365 Copilot, Teams, and Copilot Studio, where the work already happens.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;3. Test &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;rigour&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;is a differentiator, not an afterthought&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Athenaeum won Top Student with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;611 tests&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;behind its multi-agent learning system. In a field of prototypes, evidence of engineering discipline stood out to judges. Agentic systems are non-deterministic, so a strong evaluation and&amp;nbsp;test&amp;nbsp;harness is what turns a demo into something trustworthy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;4. Design for everyone from day one&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CLARO (accessibility-first reasoning) and Tell My Day (assistive storytelling for non-verbal users) prove that responsible, inclusive AI&amp;nbsp;isn't&amp;nbsp;a constraint;&amp;nbsp;it's&amp;nbsp;a source of the most meaningful innovation. Accessibility completions were a top skilling path this year, and the winners&amp;nbsp;reflected&amp;nbsp;it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🎮 The Three Tracks and Their Toolchains&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Agents League ran three build&amp;nbsp;tracks,&amp;nbsp;each anchored to a Microsoft developer platform. The winners map directly onto them:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Creative Apps → GitHub Copilot.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;AI-assisted development from concept to code. Winners:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Afterlogin&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;The Hunt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;StudyMate&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;. (35% of the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;field.)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Reasoning Agents → Microsoft Foundry.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;Multi-step reasoning and agent orchestration. Winner:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;DELPHAI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;. (46% of the field, the most popular&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;track.)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Enterprise Agents → Microsoft 365 Copilot &amp;amp; Copilot Studio.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;Business-ready knowledge agents. Winner:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Archon&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;. (19% of the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;field.)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🔴 The Reactor Battles: Learning in Public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;The live Microsoft Reactor build battles were where the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;thousands of developers&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;learned&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;together&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;in real time.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;The community connected over&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;four&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;live&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;broadcasts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt; &lt;A class="lia-external-url" href="https://developer.microsoft.com/en-us/reactor/series/S-1658/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Reactor Agents League series&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A standout moment:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Kyle Daigle&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, CMO of Microsoft Developer and COO of GitHub, live-coded his own project on stream during the Creative Apps Reactor Battle, an authentic build-along that resonated with the developer audience. As one attendee put it:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;"These types of sessions are the best, where we can see code and flows. It's like we learn more by&amp;nbsp;visualising."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;📚 Skill Up Like a Champion: The Developer&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Playlists&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Winners&amp;nbsp;don't&amp;nbsp;appear from nowhere; many skilled up first. Seven role-based developer paths on&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;AI Skills Navigator&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;drove&amp;nbsp;thousands of&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;completions&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, spanning GitHub Copilot, Microsoft Foundry, and Microsoft 365. The top&amp;nbsp;five&amp;nbsp;learning playlists:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Develop your first agent with Microsoft Foundry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;, completions (the runaway&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;favourite&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Learn AI-assisted coding with GitHub Copilot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="7" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Accessibility in practice&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Optimise&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;agentic DevOps with Azure DevOps &amp;amp; GitHub Copilot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="9" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Build and orchestrate agents with Microsoft Foundry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Completion earned free GitHub &amp;amp; Microsoft certification vouchers and&amp;nbsp;Credly&amp;nbsp;badges. If you want to be on next year's winners list, this is where to start.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🔧 One Honest Lesson for Next Time&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Transparency matters, so&amp;nbsp;here's&amp;nbsp;a builder-to-builder tip drawn from the judging data. Of&amp;nbsp;the final&amp;nbsp;submissions, the single biggest disqualifier was a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;missing demo video&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, followed by no listed repository. Brilliant projects were screened out on&amp;nbsp;a technicality.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The takeaway&amp;nbsp;for future hackathons:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;treat your&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;demo video&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;public repository&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;as first-class deliverables, not last-minute additions. A working agent nobody can see or reproduce&amp;nbsp;can't&amp;nbsp;win. Record the demo early, keep the repo public, and document how to run it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;✅ Key Takeaways&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="10" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Multi-agent architectures dominated the podium&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;: DELPHAI's 11-agent council and Archon's 7-agent pipeline show that decomposition and self-verification win.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="11" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Integration and inclusivity are differentiators&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;: winners met users inside Teams, in their own notes, and designed for accessibility from day one.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="12" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Engineering&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;rigour&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;gets noticed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;611 tests&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;helped Athenaeum&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;win&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;one&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;the&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;Top Student&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;awards&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{" data-aria-posinset="13" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Submission hygiene is non-negotiable&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;: a demo video and public repo are the price of admission to judging.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;🚀 Your Next Move&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether&amp;nbsp;you're&amp;nbsp;a returning competitor or inspired to enter your first battle,&amp;nbsp;here's&amp;nbsp;how to keep building:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;🎬&amp;nbsp;&lt;STRONG&gt;Rewatch the battles:&lt;/STRONG&gt;&amp;nbsp;&lt;A href="https://developer.microsoft.com/en-us/reactor/series/S-1658/" target="_blank" rel="noopener"&gt;Microsoft Reactor Agents League series&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;📘&amp;nbsp;&lt;STRONG&gt;Start skilling:&lt;/STRONG&gt;&amp;nbsp;&lt;A href="https://aiskillsnavigator.microsoft.com/events/AISF2026" target="_blank" rel="noopener"&gt;AI Skills Navigator AISF 2026 developer playlists&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;🤖&amp;nbsp;&lt;STRONG&gt;Build reasoning agents:&lt;/STRONG&gt;&amp;nbsp;explore&amp;nbsp;&lt;A href="https://ai.azure.com/" target="_blank" rel="noopener"&gt;Microsoft Foundry&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;💡&amp;nbsp;&lt;STRONG&gt;Ship with AI assistance:&lt;/STRONG&gt;&amp;nbsp;&lt;A href="https://github.com/features/copilot" target="_blank" rel="noopener"&gt;GitHub Copilot&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;🏢&amp;nbsp;&lt;STRONG&gt;Build enterprise agents:&lt;/STRONG&gt;&amp;nbsp;&lt;A href="https://www.microsoft.com/microsoft-copilot/microsoft-copilot-studio" target="_blank" rel="noopener"&gt;Microsoft Copilot Studio&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To every builder who entered the arena, streamed a battle, or completed a playlist:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;thank you.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;You&amp;nbsp;didn't&amp;nbsp;just compete; you showed the world what's possible when developers and agentic AI build together. The champions above earned their moment, but the real story is a global community of 31,000 developers levelling up at once.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The arena will open again. When it does, will your agent be on the podium? 🏆&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Agents&amp;nbsp;League was part of AI Skills Fest 2026 and was open to the public at no cost. Figures reflect the completed submission and judging period after excluding Microsoft-affiliated participants. Winner descriptions are drawn from the official Agents League Hackathon summary.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/educator-developer-blog/agents-league-celebrating-the-builders-who-made-agents-battle/ba-p/4538007</guid>
      <dc:creator>Lee_Stott</dc:creator>
      <dc:date>2026-07-23T19:00:00Z</dc:date>
    </item>
    <item>
      <title>1 million documents to 300+agents: Building an enterprise-scale Microsoft 365 Copilot connector</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/1-million-documents-to-300-agents-building-an-enterprise-scale/ba-p/4540155</link>
      <description>&lt;P&gt;&lt;STRONG&gt;1 million documents. 100,000+ monthly users. 300+ Copilot Studio agents. &lt;/STRONG&gt;Here's what we learned building the Microsoft 365 Copilot connector behind them.&lt;/P&gt;
&lt;P&gt;Most enterprise knowledge lives in portals and repositories that people trust but rarely visit in the flow of work. That's the gap this connector was built to close.&lt;/P&gt;
&lt;P&gt;At Microsoft, we built an enterprise-scale Microsoft 365 Copilot connector to make internal documentation available as grounded context across supported Copilot experiences. The connector runs in production today, serving teams across engineering, support, and field roles.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Who this post is for: &lt;/STRONG&gt;platform teams, developers, and connector owners who are past prototype and thinking about production. We cover the design choices, security and governance considerations, schema decisions, operational patterns, and retrieval-quality practices that helped us make enterprise knowledge easier to discover and reuse through Microsoft 365 Copilot.&lt;/P&gt;
&lt;H3&gt;Understand why a Microsoft 365 Copilot connector matters&lt;/H3&gt;
&lt;P&gt;New to Microsoft 365 Copilot connectors? Start with the &lt;A href="https://learn.microsoft.com/microsoft-365/copilot/connectors/overview" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot connectors overview&lt;/A&gt; and the &lt;A href="https://learn.microsoft.com/graph/connecting-external-content-connectors-api-overview" target="_blank" rel="noopener"&gt;Copilot connectors API documentation&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;The real power of a Microsoft 365 Copilot connector isn't the ingestion — it's what becomes possible once your content is in the platform.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The moment your connector is live and configured for supported Microsoft 365 Copilot experiences, your content can become available as grounded context in those experiences. That means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot Chat&lt;/STRONG&gt; — users ask questions in natural language and get answers grounded in your content, alongside emails, files, and Teams messages. No portal visit required.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot in Microsoft 365 apps&lt;/STRONG&gt; — in Copilot for Word, PowerPoint, and Excel (where supported), your knowledge can appear as context when users draft, summarize, or build presentations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot Studio agents&lt;/STRONG&gt; — users with appropriate permissions and licensing can build custom agents scoped to your connector's content. In our case, 300+ agents were created by teams within Microsoft — incident response assistants, onboarding copilots, domain-specific Q&amp;amp;A bots — all without additional work from us.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot CLI and developer tools&lt;/STRONG&gt; — Copilot CLI is the command-line experience for developers working in a terminal. Engineers get answers in their terminal or IDE, grounded in the same authoritative content.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The Copilot Retrieval API&lt;/STRONG&gt; — teams with appropriate access can programmatically query the indexed knowledge to build custom experiences we never anticipated.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The key insight is that a connector is not just an ingestion pipeline. When you invest in clean schema, reliable ingestion, and the right access controls, supported Copilot experiences can reuse that content without requiring a separate integration for every surface.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A quick note on terminology. &lt;/STRONG&gt;This post describes a Microsoft 365 Copilot sync connector (previously known as a Graph connector). Sync connectors ingest and index your content into the Microsoft 365 substrate, which is different from federated connectors that query content in place.&lt;/P&gt;
&lt;H3&gt;Plan for production gaps&lt;/H3&gt;
&lt;P&gt;The public documentation gets you from zero to a working connector. Getting from a working connector to a production one uncovered four gaps we hadn't planned for: tenant configuration, security and compliance readiness, discoverability, and shared throttling limits.&lt;/P&gt;
&lt;H3&gt;Validate tenant configuration early&lt;/H3&gt;
&lt;P&gt;The documented path starts with creating a connector in your tenant and ingesting data. In our environment, we had to validate architecture before full production, and hit a few things that weren't in the docs. Watch out for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Cross-tenant data flow. &lt;/STRONG&gt;There is no supported model for cross-tenant data flow between Entra ID tenants today. We resolved this by consolidating connector operations into a single tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;"Draft" state limbo. &lt;/STRONG&gt;Connectors can get stuck in "Draft" state despite correct permissions. Escalating through the platform team was the fastest unblock.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Ownership gaps. &lt;/STRONG&gt;Multiple platform teams have overlapping responsibilities and no single owner. Identify your escalation path before you need it.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dev tenant lifecycles. &lt;/STRONG&gt;Dev tenants may have undocumented auto-deletion policies. Don't rely on a dev tenant as a long-lived staging environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Start security and compliance early&lt;/H3&gt;
&lt;P&gt;Registering an app and configuring permissions is the easy part. For a cross-tenant connector at enterprise scale, we also needed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A threat model.&lt;/LI&gt;
&lt;LI&gt;A privacy review.&lt;/LI&gt;
&lt;LI&gt;A Responsible AI review.&lt;/LI&gt;
&lt;LI&gt;Design reviews from platform teams.&lt;/LI&gt;
&lt;LI&gt;Security exception approvals.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;No template existed. No checklist. No predefined path. This was a significant effort that started well before we wrote code.&lt;/P&gt;
&lt;H3&gt;Make connector content discoverable&lt;/H3&gt;
&lt;P&gt;Even with successful ingestion, Copilot may not prioritize your content. Emails and user files rank higher by default. Connector content ranking varies across clients. There's no visibility into why a result was or wasn't surfaced.UserPrincipal support — the ability to attach a user identity to an indexed item so it's ranked with the same signals as that user's emails and files — is an important platform improvement for us. We plan to adopt it in the near future, with the goal of making connector content show up more reliably alongside a user's other work in Copilot results.&lt;/P&gt;
&lt;H3&gt;Design for throttling and shared limits&lt;/H3&gt;
&lt;P&gt;At approximately 1 million documents, throttling became an important design consideration. We handled it with retry logic, exponential back-off, monitoring for 429 responses, and operational alerts so we could detect ingestion slowdowns quickly.&lt;/P&gt;
&lt;P&gt;The Microsoft 365 Copilot connectors platform has a global rate limit shared across all connectors in a tenant. If another connector spikes ingestion, yours gets throttled — and the 429 doesn't tell you why or who's consuming the budget. Today, there's no visibility into the shared quota, no priority system, and no way to reserve capacity, so it's worth designing your pipeline to tolerate unexpected back-pressure.&lt;/P&gt;
&lt;H3&gt;Build the connector for scale&lt;/H3&gt;
&lt;P&gt;Our architecture focused on one principle: keep the source content separate from the ingestion compute. That choice made the pipeline easier to retry, easier to monitor, and easier to evolve as the documentation platform changed.&lt;/P&gt;
&lt;img /&gt;
&lt;H3&gt;Separate data from compute&lt;/H3&gt;
&lt;P&gt;A core design principle was keeping the data layer completely separate from the ingestion compute. The documentation platform stores content in Azure Blob Storage — that's the source of truth. The ingestion pipeline never owns or duplicates that data. Instead, it reacts to changes and transforms on the fly.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Blob Change Feed&lt;/STRONG&gt; — &lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-change-feed" target="_blank" rel="noopener"&gt;Azure Blob Storage's change feed&lt;/A&gt; emits events whenever documents are created, updated, or deleted. This is the trigger for all ingestion work — no polling, no scheduled full crawls.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Function (event-driven)&lt;/STRONG&gt; — an Azure Function listens to the change feed and processes each event. It reads the blob, transforms the content, enriches metadata, and pushes the item to the Microsoft Graph connectors API. The function is stateless — all state lives in the storage layer and the Microsoft Graph platform.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Storage as the boundary&lt;/STRONG&gt; — the function has read access to blob storage but never writes back. Data flows one direction: storage → function → Graph API. This keeps the pipeline simple to reason about and safe to retry — reprocessing a blob event is always idempotent.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Graph API ingestion&lt;/STRONG&gt; — items are &lt;A href="https://learn.microsoft.com/graph/api/externalconnectors-externalconnection-put-items?view=graph-rest-1.0" target="_blank" rel="noopener"&gt;pushed with retry logic&lt;/A&gt;, back-off on &lt;A href="https://learn.microsoft.com/graph/throttling" target="_blank" rel="noopener"&gt;429s&lt;/A&gt;, and observability via Application Insights.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This separation means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The documentation platform can evolve its storage independently — new formats, new metadata, reorganizations — without touching the ingestion pipeline.&lt;/LI&gt;
&lt;LI&gt;The pipeline scales horizontally via Azure Functions consumption plan — spikes in content updates don't require capacity planning.&lt;/LI&gt;
&lt;LI&gt;Failures are isolated — a bad blob doesn't block other ingestion, and the change feed provides natural retry semantics.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Iterate on schema design&lt;/H3&gt;
&lt;P&gt;We treated &lt;A href="https://learn.microsoft.com/graph/connecting-external-content-manage-schema" target="_blank" rel="noopener"&gt;schema design&lt;/A&gt; as the highest-leverage decision. Through four iterations, we significantly improved retrieval quality — entirely through schema and metadata refinement:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Mapped document types (TSGs, runbooks, architecture docs, onboarding guides) to distinct property sets.&lt;/LI&gt;
&lt;LI&gt;Wrote detailed connection descriptions optimized for Copilot's ranking.&lt;/LI&gt;
&lt;LI&gt;Added custom properties for freshness and ownership signals.&lt;/LI&gt;
&lt;LI&gt;Tested with real user queries, not synthetic data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Use secure authentication and deployment patterns&lt;/H3&gt;
&lt;P&gt;A few patterns kept the deployment story simple across environments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Managed Identity&lt;/STRONG&gt; for service-to-service communication in production.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Infrastructure-as-code&lt;/STRONG&gt; for consistent deployment across commercial and sovereign clouds.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Environment-specific configuration&lt;/STRONG&gt; abstracted from the start.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Measure retrieval quality&lt;/H3&gt;
&lt;P&gt;One benefit of onboarding to the Microsoft 365 Copilot platform was access to the Search Evaluation framework used by the Copilot team. This helped us measure retrieval quality, including precision and recall against real user queries, without building evaluation infrastructure from scratch. We used this framework to test pipeline changes and catch regressions before they reached users.&lt;/P&gt;
&lt;H3&gt;Monitor connector health&lt;/H3&gt;
&lt;P&gt;A healthy connector is a prerequisite for everything else, so we built:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Alerting on ingestion failures and throttling spikes.&lt;/LI&gt;
&lt;LI&gt;Recovery automation for re-ingestion scenarios.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;See the impact&lt;/H3&gt;
&lt;P&gt;Once the connector was live, three things stood out: the portal became a platform, an ecosystem of agents formed on top of it, and we kept the controls we needed while gaining new ways to measure quality.&lt;/P&gt;
&lt;H4&gt;From portal to platform&lt;/H4&gt;
&lt;P&gt;The documentation platform moved from being a destination people visited to a knowledge source that powers AI experiences across Microsoft. Users no longer need to navigate to the portal — knowledge surfaces directly in Copilot Chat, Copilot in Word, Copilot in VS Code, and Azure Copilot. Consumption is ambient and contextual, embedded in existing workflows.&lt;/P&gt;
&lt;H4&gt;An ecosystem of agents&lt;/H4&gt;
&lt;P&gt;The core value proposition of the Microsoft 365 Copilot platform is this: push your content once, and it's enabled across multiple AI surfaces. That's exactly what happened.&lt;/P&gt;
&lt;P&gt;300+ Copilot Studio agents now build on the connector. Content surfaces in Copilot Chat, Copilot CLI, Work IQ (Microsoft's workplace intelligence experience), and other AI-powered developer tools — all from a single ingestion pipeline. Teams within Microsoft created:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Incident response assistants that help surface relevant troubleshooting guides.&lt;/LI&gt;
&lt;LI&gt;Onboarding copilots that pull architecture docs contextually.&lt;/LI&gt;
&lt;LI&gt;Domain-specific Q&amp;amp;A agents scoped to their team's content.&lt;/LI&gt;
&lt;LI&gt;Support augmentation workflows with human oversight.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because we invested in getting the connector right once — clean schema, proper access controls, reliable ingestion — supported Copilot experiences reuse that content automatically. None of the 300+ agents required additional integration work from our team.&lt;/P&gt;
&lt;H4&gt;Measurable quality and preserved governance&lt;/H4&gt;
&lt;P&gt;Alongside the new capabilities, the shift preserved what mattered most: existing controls and a way to measure what we were doing.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Programmatic access at scale. &lt;/STRONG&gt;The Copilot Retrieval API lets teams with appropriate access query the indexed knowledge programmatically, without the documentation team's involvement. Single ingestion, multi-surface consumption.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governance stayed centralized. &lt;/STRONG&gt;Despite AI integration, the connector continues to rely on existing Microsoft 365 security and access controls. Governance policies and access restrictions remain centrally managed. This was critical for sovereign cloud deployment and regulated environments.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Quality became measurable. &lt;/STRONG&gt;With evaluation frameworks in place, we can quantify answer quality and continuously improve — something that wasn't possible when the platform was purely a static portal.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Apply these recommendations when building connectors&lt;/H3&gt;
&lt;P&gt;If you are planning a Microsoft 365 Copilot connector, these are the practices we would prioritize before moving from prototype to production:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Start security and compliance conversations before writing code&lt;/STRONG&gt; — budget significantly more time than you expect.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Treat &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/graph/connecting-external-content-manage-schema" target="_blank" rel="noopener"&gt;schema design&lt;/A&gt;&lt;STRONG&gt; as your highest-leverage decision&lt;/STRONG&gt; — test with real Copilot queries early and iterate aggressively.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Build evaluation from day one&lt;/STRONG&gt; — you need to measure whether Copilot is actually using your content effectively.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Build health monitoring for the connector itself&lt;/STRONG&gt; — not just the pipeline.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Design for the ecosystem&lt;/STRONG&gt; — if you build it well, people will build on it in ways you didn't anticipate.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Make the investment worthwhile&lt;/H3&gt;
&lt;P&gt;The public docs for &lt;A href="https://learn.microsoft.com/graph/connecting-external-content-connectors-api-overview" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot connectors&lt;/A&gt; cover the "what." This post covers the "how" — and more importantly, the "why it's worth it."&lt;/P&gt;
&lt;P&gt;Security approvals took months. Schema iteration took four rounds. Operational readiness took ownership none of us had budgeted for. But the payoff is real: your organization's knowledge becomes accessible through AI, grounded in authoritative content and available across supported Microsoft 365 Copilot experiences.&lt;/P&gt;
&lt;P&gt;The platform is powerful. Getting there takes work. In our first year of production, 300+ agents were built on the connector — none of which required additional integration work from our team.&lt;/P&gt;
&lt;H3&gt;Get started&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/microsoftsearch/connectors-overview" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot connectors overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/connecting-external-content-connectors-api-overview" target="_blank" rel="noopener"&gt;Work with the Copilot connectors API&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/connecting-external-content-manage-connections" target="_blank" rel="noopener"&gt;Create and manage connections&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/connecting-external-content-manage-schema" target="_blank" rel="noopener"&gt;Register and manage schema&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/microsoft-copilot-studio/knowledge-copilot-connectors" target="_blank" rel="noopener"&gt;Add Copilot connectors as a knowledge source in Copilot Studio&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/throttling" target="_blank" rel="noopener"&gt;Microsoft Graph throttling guidance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-change-feed" target="_blank" rel="noopener"&gt;Azure Blob Storage change feed&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Join the conversation&lt;/H3&gt;
&lt;P&gt;Have you built a Microsoft 365 Copilot connector at scale? We'd love to hear what you learned — share your experience in the comments below, and let us know which patterns worked (or didn't) in your environment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Did you know? &lt;/STRONG&gt;The Microsoft 365 Roadmap is where you can track upcoming updates across Microsoft 365 apps and services. Microsoft 365 Copilot release notes are where you can review generally available Copilot features by platform. Check both resources regularly for the latest status, and note that roadmap dates are tentative and subject to change.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 18:57:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/1-million-documents-to-300-agents-building-an-enterprise-scale/ba-p/4540155</guid>
      <dc:creator>supramo</dc:creator>
      <dc:date>2026-07-23T18:57:12Z</dc:date>
    </item>
    <item>
      <title>Announcing public preview of Azure DDoS Protection custom policy</title>
      <link>https://techcommunity.microsoft.com/t5/azure-networking-blog/announcing-public-preview-of-azure-ddos-protection-custom-policy/ba-p/4538963</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We are excited to announce the public preview of Azure DDoS Protection custom policy, a new capability that gives customers more granular control over how Azure DDoS Protection detects and mitigates attacks against protected workloads.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure DDoS Protection has always focused on delivering automatic, adaptive protection at scale. With custom policy, customers can now fine-tune mitigation behaviour for supported resources and configure protocol-specific detection thresholds. This allows customers to better align protection settings with any planned or projected changes in their application traffic patterns upfront, while giving them additional control over supported protocol thresholds.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{}"&gt;Azure DDoS Protection custom policy is currently in preview. See the&amp;nbsp;&lt;A href="vscode-file://vscode-app/c:/Users/ofirsarfaty/AppData/Local/Programs/Microsoft%20VS%20Code%20Insiders/5e212606d5/resources/app/out/vs/sessions/electron-browser/sessions.html" target="_blank" rel="noopener" data-href="https://azure.microsoft.com/en-us/support/legal/preview-supplemental-terms/"&gt;Supplemental Terms of Use for Microsoft Azure Previews&lt;/A&gt; for legal terms that apply to Azure features that are in beta, preview, or otherwise not yet generally available.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why customers asked for more control&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure DDoS Protection automatically analyses traffic patterns and applies adaptive mitigation during attacks. While this approach works well for most workloads, some organizations require additional flexibility to support unique traffic characteristics, operational environments, or changes around big releases and events.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers running latency-sensitive applications, high-throughput services, gaming platforms, or workloads with predictable traffic spikes often want the ability to customize mitigation trigger behavior for specific protocols.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Example scenarios include:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Applications with known peak traffic periods&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Workloads that experience sustained high packet-per-second rates&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Services requiring protocol-specific tuning&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="9" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Organizations that need separate mitigation policies across environments or applications&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Custom policy allows organizations to align DDoS protection behaviour with their operational traffic baselines while still leveraging Azure’s global-scale mitigation infrastructure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="auto"&gt;Key benefits:&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Granular, protocol-level&amp;nbsp;control&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Configure custom detection thresholds for TCP, UDP, and TCP SYN traffic, so mitigation triggers reflect how your application behaves rather than generic baselines.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Predictable protection during planned&amp;nbsp;events&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt; Align mitigation behaviour with&amp;nbsp;anticipated&amp;nbsp;traffic&amp;nbsp;changes&amp;nbsp;product launches, seasonal peaks, gaming events,&amp;nbsp;so legitimate traffic surges&amp;nbsp;aren't&amp;nbsp;mistaken for attacks.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Flexibility without sacrificing scale&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Fine-tune&amp;nbsp;triggers for&amp;nbsp;specific workloads while still&amp;nbsp;benefiting&amp;nbsp;from Azure's global-scale mitigation infrastructure and adaptive protection everywhere else.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Per-resource policy management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Apply separate policies across environments or applications, giving teams the ability to tune protection independently for dev, test, and production workloads.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Full operational visibility&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Existing Azure Monitor and DDoS Protection telemetry continue to work with custom policies, so you can&amp;nbsp;validate&amp;nbsp;threshold changes and monitor mitigation activity end to end.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Public preview walkthrough&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers can deploy and manage DDoS custom policies directly from the Azure portal.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To create a new policy:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Open the Azure portal.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Search for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;DDoS custom policies&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Select&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Create&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Choose the subscription, resource group, and region.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Select a supported frontend IP configuration.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Configure protocol detection rules.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Review and deploy.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Once deployed, the custom policy can be associated with supported frontend IP resources to apply protocol-specific mitigation settings.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Current public preview scope&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;During public preview, Azure DDoS Protection custom policy supports:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Standard Load Balancer frontend IP configurations&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;TCP, UDP, and TCP SYN threshold customization&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Azure portal management&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="8" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;ARM and REST API deployment&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Current limitations include:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Support is currently limited to&amp;nbsp;Standard Load Balancer frontend&amp;nbsp;IPs&amp;nbsp;and no Power Shell support&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As with all preview features, functionality and supported scenarios may evolve before general availability.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Important considerations&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When a customer configures a custom threshold for a protocol, Azure disables&amp;nbsp;autotuning&amp;nbsp;triggers&amp;nbsp;for&amp;nbsp;that protocol and uses the configured static value.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers should:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Use&amp;nbsp;anticipated&amp;nbsp;traffic baselines to guide threshold&amp;nbsp;selection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Start with conservative tuning changes&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Validate behaviour in lower environments before broad deployment&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Monitor mitigation telemetry after configuration changes&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure Monitor and existing Azure DDoS Protection telemetry continue to provide visibility into mitigation activity and operational behavior.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Looking ahead&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure DDoS Protection continues to evolve to support modern application architectures, large-scale internet exposure, and advanced operational requirements.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Custom policy extends Azure DDoS Protection's automatic, adaptive baseline with optional per-resource control, without changing the turnkey default that protects every workload out of the box. Autotuning stays on everywhere a custom threshold is not explicitly configured.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We want customers to know that Azure DDoS continues to be a hands-off fully automated service, and that policy customization is not a new operational model, but rather an optional override-on-top automated/adaptive engine.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Get started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers can begin using Azure DDoS Protection custom policy today through the public preview experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Review the Azure REST API documentation for DDoS Custom Policies&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/rest/api/virtualnetwork/ddos-custom-policies?view=rest-virtualnetwork-2025-05-01" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Deploy a test policy in a supported subscription&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Explore the Azure portal experience for policy management&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Evaluate protocol-specific threshold tuning for your applications&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We look forward to&amp;nbsp;hearing&amp;nbsp;your&amp;nbsp;feedback.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 17:16:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-networking-blog/announcing-public-preview-of-azure-ddos-protection-custom-policy/ba-p/4538963</guid>
      <dc:creator>OfirSarfaty</dc:creator>
      <dc:date>2026-07-23T17:16:28Z</dc:date>
    </item>
    <item>
      <title>Coming soon: the Frontier Partner specialization</title>
      <link>https://techcommunity.microsoft.com/t5/specialization-updates/coming-soon-the-frontier-partner-specialization/ba-p/4540152</link>
      <description>&lt;P&gt;One of two Frontier-focused offerings in the Microsoft AI Cloud Partner Program, the Frontier Partner specialization validates partners who can design, build, deploy, govern, and secure AI agents across the Microsoft tech stack, including Microsoft 365 Copilot, Azure AI Foundry, GitHub Copilot, Microsoft Defender, Entra, and Purview.&lt;/P&gt;
&lt;P&gt;Partners who earn this specialization signal their deep expertise to customers—and get access to badging, priority search, and skill-aligned benefits such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Eligibility for Frontier-aligned co-sell opportunities&lt;/LI&gt;
&lt;LI&gt;Microsoft Agent prepurchase plan credits and Microsoft 365 E7 licensing&lt;/LI&gt;
&lt;LI&gt;Packaged go-to-market resources including marketing campaigns and case study opportunities&lt;/LI&gt;
&lt;LI&gt;Microsoft AI Cloud Partner Program Concierge support through the qualification process&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The specialization will be open for enrollment later in FY27, but you can start preparing now.&lt;/P&gt;
&lt;P&gt;Requirements across three components must be met simultaneously under the same Partner Global Account:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Specializations:&lt;/STRONG&gt; Partners must hold the following four prerequisite specializations: Microsoft 365 Copilot, AI Apps on Microsoft Azure OR AI Platform on Microsoft Azure, Data Security, and Identity and Access Management.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Skilling: &lt;/STRONG&gt;Five individuals from your organization must complete the Frontier Transformation Engineer badge; three individuals must earn the Fabric Analytics Engineer Associate (DP-600) certification. The people who hold the badge and the certification can be the same or different.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Audit: &lt;/STRONG&gt;You must get a third-party audit validating delivery capability across design, build, deploy, govern, secure, and operate. There is a two-year audit cadence.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Review the &lt;A class="lia-external-url" href="https://assetsprod.microsoft.com/mpn/frontier-partner-specialization-walking-deck.pdf?wt.mc_id=a2fea3elo2" target="_blank" rel="noopener"&gt;walking deck&lt;/A&gt; for more details on this exciting opportunity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 17:54:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/specialization-updates/coming-soon-the-frontier-partner-specialization/ba-p/4540152</guid>
      <dc:creator>JS5</dc:creator>
      <dc:date>2026-07-23T17:54:06Z</dc:date>
    </item>
    <item>
      <title>Partner Blog | Navigating the next era of hosting: Your playbook is here</title>
      <link>https://techcommunity.microsoft.com/t5/partner-news/partner-blog-navigating-the-next-era-of-hosting-your-playbook-is/ba-p/4539853</link>
      <description>&lt;P&gt;Hosting and hybrid cloud partners are currently navigating significant infrastructure transitions.&amp;nbsp;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fpartner.microsoft.com%2Fblog%2Farticle%2Fhosters&amp;amp;data=05%7C02%7Cv-armourjill%40microsoft.com%7Cc894a6ba16254e6f2ca408dee82386e8%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639203436461471372%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=MJ57n%2Bj80AEoGbUCOATmRDr03kzhN91ieqlmwed93TY%3D&amp;amp;reserved=0" target="_blank"&gt;In a May blog&lt;/A&gt;, we explored why changes in virtualization licensing, rising infrastructure costs, and evolving customer expectations are creating both pressure and opportunity for hosting businesses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now the conversation shifts from understanding the opportunity to taking action. It is about evolution without disruption: preserving what works, modernizing where it matters, and growing into higher-value services with Microsoft Adaptive Cloud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is why we created the new e-book,&amp;nbsp;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FDCO-eBook&amp;amp;data=05%7C02%7Cv-armourjill%40microsoft.com%7Cc894a6ba16254e6f2ca408dee82386e8%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639203436461482722%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=iqa9kmyTzjThBdTxerit2vltXEse%2BE2hxreE0Gsrl0A%3D&amp;amp;reserved=0" target="_blank"&gt;Navigating the Next Era of Hosting&lt;/A&gt;. It is a practical guide for hosting partners looking to protect margins, retain customer trust, and define a clear modernization path across Azure, hybrid, and AI-ready scenarios.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;From awareness to action&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Hosting partners are already fielding more complex customer conversations. Customers want flexibility across on-premises, edge, partner datacenter, and public cloud environments. They want consistent management, built-in security, stronger governance, and clear modernization options without being forced into a single destination or timeline.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the same time, many partners are reevaluating long-standing platform strategies. Licensing changes, evolving commercial models, and rising infrastructure costs are prompting new questions about margin predictability, platform control, and long-term differentiation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is where action matters. Partners that move early can shape the conversation with customers instead of reacting to it. You can explain what will stay consistent, where modernization can begin, and how customers can retain choice while preparing for what comes next.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/Partnerblog-Playbook2026" target="_blank"&gt;Continue reading here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/partner-news/partner-blog-navigating-the-next-era-of-hosting-your-playbook-is/ba-p/4539853</guid>
      <dc:creator>JillArmourMicrosoft</dc:creator>
      <dc:date>2026-07-23T17:00:00Z</dc:date>
    </item>
    <item>
      <title>Designing Intune enrollment for frontline workers: Choosing the right path for real-world devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Shawn Catlin – Senior Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Practitioner perspective from Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune), with deep experience in secure frontline mobility, including regulated healthcare environments.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Enrollment &lt;U&gt;methodology&lt;/U&gt;&amp;nbsp;is one of the most consequential design decisions teams make for frontline environments. It shapes how devices are used, how identity is handled, how failures are recovered from, and how much friction workers experience before they can do their jobs.&lt;/P&gt;
&lt;P&gt;Frontline use cases aren’t limited to shared devices. They can span nearly every enrollment type available in Microsoft Intune, including user-assigned, shared, dedicated, kiosk, corporate-owned, BYOD, and zero-touch deployment models. The right choice is often influenced by business need, operational workflow, budget, support model, and security requirements. But it must also account for platform and operating system design. Android, iOS, and iPadOS may offer similar enrollment concepts, but they don’t always behave the same way or support the same management patterns.&lt;/P&gt;
&lt;P&gt;That distinction matters. A kiosk or dedicated-device model, for example, is intentionally designed for a locked-down, task-focused experience. It manages the device around a specific function, not around a personalized user workspace. In that model, broad app availability, persistent personalization, and user-driven app installation are not the primary management paradigm. Similarly, a shared-device model should not be selected simply because an organization cannot provide a dedicated device to every worker. If identity, app access, compliance, or user context are required, those needs must be part of the enrollment decision from the beginning.&lt;/P&gt;
&lt;P&gt;There is no copy-and-paste frontline enrollment strategy that works across every industry, business unit, or device scenario. Some frontline devices are shared across shifts and must remain reliable where connectivity, identity, and support are not guaranteed. Others are assigned to supervisors, clinicians, field workers, or shift leads who need persistent access to apps, settings, and data. When enrollment choices are made without accounting for these realities, especially platform differences and OS-level limitations, friction surfaces quickly during pilots and scales painfully during rollout.&lt;/P&gt;
&lt;P&gt;This article explains how to approach Intune enrollment for frontline devices through a practical, reality-first lens: start with how the device is used, align the management model to the workflow, and then plan how the device will be enrolled, replaced, and reprovisioned at scale.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;In a hospital environment, frontline does not mean one type of device or one type of worker. A shared clinical workstation, a nurse’s mobile device, a patient check-in kiosk, a barcode scanner, and a supervisor’s assigned device may all be considered frontline, but they each have very different identity, security, app, and recovery requirements. That is why enrollment decisions have to start with the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment Is a Design Decision, not a Checkbox&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Enrollment does more than bring a device under management. It defines how the device is expected to work, where the security boundary sits, how identity is applied, and what recovery looks like when something fails in the field.&lt;/P&gt;
&lt;P&gt;There is no single “best” enrollment model for frontline. There is only the model that best fits how the device is actually used. The right choice depends on whether the device follows a person, a shift, a task, or a business process. It also depends on how much identity matters to the experience, whether apps need to be personalized, whether Conditional Access or compliance is required, and how quickly the device must be replaced or recovered.&lt;/P&gt;
&lt;P&gt;This is why many problems that look like policy, app, or configuration failures are actually enrollment design problems in disguise. A device can be successfully enrolled and still be poorly designed for the job it needs to do.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;A device can be successfully enrolled and still fail the workflow. If a shift worker cannot access the right app quickly, if a shared device retains the wrong user context, or if a replacement device cannot be brought online during a shift, the issue may look like an app or support problem. In reality, it often traces back to an enrollment model that did not match the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Separate Two Decisions: Management Model and Provisioning Method&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment planning becomes easier when teams separate two related but different decisions.&lt;/P&gt;
&lt;P&gt;The first decision is the &lt;STRONG&gt;management model&lt;/STRONG&gt;. This is the architectural choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does the device need to represent a specific person?&lt;/LI&gt;
&lt;LI&gt;Is the device shared across multiple workers?&lt;/LI&gt;
&lt;LI&gt;Is it dedicated to a narrow task or workflow?&lt;/LI&gt;
&lt;LI&gt;Does the device require personal apps, persistent settings, or user-specific data?&lt;/LI&gt;
&lt;LI&gt;Does the workflow require Conditional Access, compliance, auditability, or individual identity?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This decision determines whether the device should be user-associated, shared, dedicated, kiosk-style, personally owned, or corporate-owned with a work profile.&lt;/P&gt;
&lt;P&gt;The second decision is the &lt;STRONG&gt;provisioning and reprovisioning method&lt;/STRONG&gt;. This is the lifecycle choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How will the device get into management the first time?&lt;/LI&gt;
&lt;LI&gt;Will it be staged by IT, a depot, a partner, or the site?&lt;/LI&gt;
&lt;LI&gt;What happens after a wipe, repair, refresh, or reassignment?&lt;/LI&gt;
&lt;LI&gt;Can the device recover without a specific user’s credentials?&lt;/LI&gt;
&lt;LI&gt;Will Wi-Fi, certificates, tokens, apps, and policies be available at first boot?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Zero-touch, pre-staging, depot workflows, and reprovisioning plans support the selected management model. They should not replace the decision about which model is right for the scenario.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Start With How the Device Is Used&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;In the previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/A&gt;, we discussed why successful frontline migrations begin with understanding how devices are actually used in the field. That discovery work should now feed directly into enrollment design.&lt;/P&gt;
&lt;P&gt;The most reliable starting point is not the department, license, or ownership model. It is the device’s behavior in the field.&lt;/P&gt;
&lt;P&gt;Ask:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does this device follow a person?&lt;/LI&gt;
&lt;LI&gt;Does it follow a shift?&lt;/LI&gt;
&lt;LI&gt;Does it follow a task?&lt;/LI&gt;
&lt;LI&gt;Does it need to know who the user is?&lt;/LI&gt;
&lt;LI&gt;Does it need persistent user context?&lt;/LI&gt;
&lt;LI&gt;Does it need to be quickly replaced with minimal IT involvement?&lt;/LI&gt;
&lt;LI&gt;Does the platform support the experience you expect?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The answers help map real-world requirements to the right Intune enrollment approach. Before selecting an enrollment model, organizations should also understand how identity is expected to function on the device. If you have not yet reviewed assigned versus shared identity patterns, see our previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-Identity" target="_blank" rel="noopener"&gt;Migrating frontline mobile devices: Identity considerations for assigned and shared devices&lt;/A&gt;, which explores how user identity, authentication, auditability, and device ownership assumptions can influence frontline management decisions.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Decision indicator&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Usually points toward&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Validate before choosing&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs persistent apps, settings, approvals, or data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-driven or user-associated enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether identity and personalization are truly required for the workflow&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers use the same device across shifts and need individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared or device-first enrollment with identity support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;How sign-in, sign-out, session cleanup, and auditability will work&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device performs a narrow, repeatable task&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or kiosk-style enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can operate with a locked-down app set and minimal user choice&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device needs corporate control but may allow limited personal use&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned work profile where supported&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the OS supports the expected separation between work and personal data&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device is personally owned and only work data needs to be protected&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD / personally owned work profile / user enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can tolerate limited organizational control&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device must be replaced quickly with minimal IT involvement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Pre-staged, zero-touch, or easily reprovisioned device-first model&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Reset behavior, network readiness, certificate delivery, and replacement speed&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The environment has inconsistent connectivity or limited support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Simpler enrollment paths with fewer live dependencies&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;What the device needs at first boot, during sign-in, and after wipe or reset&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Map Frontline Scenarios to Enrollment Models&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;A practical Intune strategy starts by accepting that frontline is not one scenario. It is a collection of scenarios. Standardization is important, but standardizing on one enrollment method for every frontline use case is rarely the right goal. Mature organizations standardize the decision framework, not necessarily the deployment model.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Device usage pattern&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Typical characteristics&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;iOS/iPadOS enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Android enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-assigned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs personalized apps, settings, and data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with user affinity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Fully Managed or Corporate-Owned Work Profile if personal use is permitted&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared device with individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers share the device and sign in with their own identities&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with Microsoft Entra Shared Device Mode; Shared iPad when multi-user iPad support is required&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or task-based device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Device performs a specific function and does not require a personalized user experience&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment without user affinity, with supervised device and app restrictions&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android device without Google Mobile Services&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned specialty device, often shared or task-focused&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Not applicable&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android AOSP userless or AOSP user-associated enrollment&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Personally owned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Employee-owned device used for work&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD User Enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Personally Owned Work Profile&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Zero-touch or pre-staged deployment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned device that needs scalable provisioning or replacement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment through Apple Business Manager or Apple School Manager&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Zero-touch Enrollment, Samsung Knox Mobile Enrollment, or equivalent supported provisioning path&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If the device follows a person, choose a model optimized for identity and personalized access. If the device follows a shift, workflow, or task, choose a model optimized for simplicity, consistency, and easy replacement.&lt;/P&gt;
&lt;P&gt;If you’re looking for more platform-specific guidance please see frontline enrollment resources for both Android and iOS/iPadOS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/android?tabs=ae" target="_blank" rel="noopener"&gt;Get started with Android frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/ios-ipados?tabs=sharedipad" target="_blank" rel="noopener"&gt;Get started with iOS/iPadOS frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These resources provide detailed implementation guidance, recommended enrollment approaches, and platform-specific considerations for frontline deployments.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Platform and OS Differences Matter&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Teams often assume that similar enrollment concepts behave the same way across platforms. They do not.&lt;/P&gt;
&lt;P&gt;On Android, a shared frontline device that needs a locked-down experience and individual worker sign-in often maps to Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode. Android Enterprise Dedicated Device provides the task-focused management model. Entra Shared Device Mode adds the identity layer so workers can sign in as themselves. Intune Managed Home Screen then helps present a consistent launcher experience and enforce the sign-in flow between shifts.&lt;/P&gt;
&lt;P&gt;On iPadOS, a shared device with individual sign-in may be designed using Shared iPad for Business or Automated Device Enrollment with Microsoft Entra Shared Device Mode. The distinction becomes important when security requirements are involved. Shared iPad can support multi-user scenarios, but organizations should review its limitations carefully, especially if Conditional Access or device compliance enforcement is required. Where Conditional Access, compliance, and security-driven access controls are mandatory, ADE with Entra Shared Device Mode may be the better fit, although it introduces additional configuration considerations and dependency on compatible apps. See &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/apple/shared-device-solutions-ios" target="_blank" rel="noopener"&gt;Shared iOS and iPadOS devices&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;Platform differences also matter for corporate-owned devices that allow personal use. Android Corporate-Owned Work Profile provides a native work profile boundary between corporate and personal data. iOS and iPadOS do not provide that same OS-level separation for corporate-owned personally enabled devices, so organizations often rely more heavily on app-level controls and MAM policies.&lt;/P&gt;
&lt;P&gt;The practical point is simple: choose the enrollment model that fits the workflow, but confirm that the platform supports the management pattern you expect.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;When User-Driven Enrollment Makes Sense&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;User-driven enrollment still has a place in frontline, but the use cases are narrower than many teams expect. It makes sense when the device needs to reflect a specific person, not just a task.&lt;/P&gt;
&lt;P&gt;This can work well for shift managers, supervisors, clinicians, field workers, or frontline leads who need persistent access to apps, approvals, notifications, data, and settings. In these cases, user-driven or user-associated enrollment can provide cleaner app targeting, stronger identity context, and a more familiar experience for the person carrying the device.&lt;/P&gt;
&lt;P&gt;Common indicators include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The worker keeps the device for most of its working life.&lt;/LI&gt;
&lt;LI&gt;The user needs email, Teams, approvals, or real-time app badges.&lt;/LI&gt;
&lt;LI&gt;The workflow depends on user-specific apps, settings, or data.&lt;/LI&gt;
&lt;LI&gt;The device may support some personal enablement where the platform supports separation.&lt;/LI&gt;
&lt;LI&gt;The worker is responsible for keeping the device available, charged, and ready for use.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But personalization comes with operational cost. User-driven enrollment increases dependency on credentials, adds friction when sign-in steps fail, and makes recovery more complex when a device must be replaced quickly. It is usually a poor fit for shared workflows, high-turnover roles, or task-based devices where speed and predictability matter more than personalization.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Designing for Shared and Shift-Based Devices&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Shared and shift-based devices are passed from one worker to the next. They are expected to stay productive across handoffs and often operate in environments where there is little time for sign-in friction or troubleshooting.&lt;/P&gt;
&lt;P&gt;For these scenarios, device-first enrollment usually aligns better with reality because the device is treated as a managed tool for a shared workflow, not as a personal endpoint tied to one individual. The goal is consistency: the next worker should be able to pick up the device, authenticate if required, and get to work without recovering from leftover state or complex setup steps.&lt;/P&gt;
&lt;P&gt;If shared devices require individual sign-in, identity must be designed into the enrollment model. Microsoft Entra Shared Device Mode and QR code authentication can help preserve individual identity without forcing workers through a full username and password flow at every handoff. This is especially relevant in environments such as retail, healthcare, warehousing, and field operations where shared devices still need auditability, Conditional Access, app access, or user-specific sessions.&lt;/P&gt;
&lt;P&gt;Shared-device success does not come from default settings alone. Teams should define:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How sign-in and sign-out should work.&lt;/LI&gt;
&lt;LI&gt;What user context should persist.&lt;/LI&gt;
&lt;LI&gt;What should be cleared between sessions.&lt;/LI&gt;
&lt;LI&gt;Which apps need to support shared-device behavior.&lt;/LI&gt;
&lt;LI&gt;How quickly a device can be swapped or reprovisioned.&lt;/LI&gt;
&lt;LI&gt;Whether access depends on the user, the device, the app session, or a combination.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;Especially in healthcare and clinical settings, shared devices have to be absolutely ready for the next worker, the next patient, and the next task. There is rarely time for complex recovery steps, unclear ownership, or leftover user state from the previous shift. A good shared-device design should support quick handoff, clean session behavior, and predictable recovery under pressure.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Dedicated and Kiosk Devices: Avoid Personalization Drift&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Dedicated and kiosk-style enrollment is ideal when the device performs a narrow, repeatable function and individual identity is secondary or unnecessary. Examples include scanners, point-of-sale systems, check-in kiosks, digital signage, inventory devices, and task-specific handhelds.&lt;/P&gt;
&lt;P&gt;The strength of kiosk-style design is that it limits choice. That is also the boundary teams must respect. A kiosk is not intended to behave like a general-purpose device where users browse a catalog of available apps, personalize settings, or install what their business unit needs on demand.&lt;/P&gt;
&lt;P&gt;A common friction point occurs when organizations try to simplify IT support with one shared kiosk configuration for multiple businesses or personas, and then expect users to install the apps they need. That creates a mismatch. User-installed available apps are not the kiosk paradigm. If each business unit needs a different set of apps, the better design is usually to do the work upfront: segment the device scenarios, define the required app sets, and deploy the right configuration to the right devices.&lt;/P&gt;
&lt;P&gt;This is also important for identity and certificates. User certificates, persistent user sessions, and shared secrets can conflict with the assumptions of a device-first or kiosk model. If the workflow requires user identity, auditability, or user-specific access, that requirement should be addressed through the right shared-device identity pattern, not bolted onto a kiosk design after the fact.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment at Scale: Plan for Provisioning and Replacement&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Once the right management model is selected, teams should plan how devices will be enrolled and reprovisioned at scale.&lt;/P&gt;
&lt;P&gt;At scale, enrollment becomes a lifecycle capability. The question is not only how a device gets into management the first time. Instead, it is how quickly that same device can be staged, replaced, wiped, repaired, reassigned, or reintroduced into service.&lt;/P&gt;
&lt;P&gt;Some organizations ship devices directly to frontline locations and complete setup during out-of-box experience. Others rely on depot, partner, or white-glove processes to front-load setup before the device reaches the site. Neither model is automatically better. The right choice depends on network readiness, site support, variability at first boot, app dependencies, certificate delivery, and replacement expectations.&lt;/P&gt;
&lt;P&gt;Replacement velocity is a real design constraint. In many frontline settings, a broken device cannot wait for a full troubleshooting cycle. A worker may need to drop one device at a charging bay and pick up another with minimal disruption. The more the enrollment and reprovisioning model supports a known-good state, the less productivity depends on one specific device surviving the shift.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Common Friction Points in Frontline Enrollment&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment problems are rarely caused by one dramatic failure. More often, they come from reasonable decisions made in the wrong order or optimized for the wrong thing.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Friction point&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Why it happens&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Better design approach&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating frontline as only shared&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The organization assumes all frontline workers use devices the same way&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Segment by workflow: person, shift, task, or business process&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Choosing shared because dedicated devices are too expensive&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Budget drives the model before identity and workflow are understood&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate identity, app, compliance, and recovery needs before choosing shared&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using kiosk for personalized workflows&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Kiosk seems simple and locked down&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use kiosk only when the workflow is task-focused and does not require broad personalization&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Wanting available apps on kiosk devices&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One configuration is used for too many personas&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Build scenario-specific app sets and configurations instead of relying on user installation&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using shared credentials&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Enrollment was not designed for individual identity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use Entra Shared Device Mode, QR code authentication, or another supported identity pattern&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Requiring user certificates on device-first or kiosk scenarios&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Security assumptions are copied from knowledge-worker designs&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate whether access can be controlled through device, app, or session design&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Over-securing setup at the expense of recovery&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Controls are designed for ideal conditions, not shift pressure&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design security that holds up during replacement, poor connectivity, and limited support&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating enrollment as a one-time event&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Success is measured by initial provisioning only&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design for wipe, repair, reassignment, refresh, and reprovisioning&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A deployment path that saves time on day one can create years of friction if it does not match how the device is used. In frontline scenarios, the best enrollment model is not always the fastest one to provision. It is the one that is easiest to sustain.&lt;/P&gt;
&lt;/DIV&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Closing&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Successful frontline deployments are rarely defined by the sophistication of their policies alone. They are defined by how well design choices hold up under real-world pressure. Enrollment is one of the earliest and most visible signals to frontline teams about whether the technology is there to support their work or get in the way.&lt;/P&gt;
&lt;P&gt;By treating enrollment as a deliberate design decision and grounding it in how devices are actually used, organizations can reduce friction, improve resilience, and create a foundation that scales as frontline operations evolve. Getting enrollment right does not guarantee success, but getting it wrong sets a ceiling that no amount of policy refinement can overcome.&lt;/P&gt;
&lt;P&gt;For more frontline examples and implementation guidance, see related Microsoft frontline worker management resources, including the blog, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-the-frontlines-frontline-worker-management-with-microsoft-intune/4387449" target="_blank" rel="noopener" data-lia-auto-title="From the frontlines: Frontline worker management with Microsoft Intune" data-lia-auto-title-active="0"&gt;&lt;EM&gt;From the frontlines: Frontline worker management with Microsoft Intune&lt;/EM&gt;&lt;/A&gt;, and the earlier article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;&lt;EM&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;When enrollment, identity, security, and recovery are designed well, frontline teams can stay focused on the people they serve - customers, patients, guests, employees, students, and communities - instead of the device in their hands. That is the standard a frontline enrollment strategy should be measured against.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As always, we welcome your feedback and experience. If you’ve navigated identity decisions for shared or frontline devices, share your advice and lessons learned in the comments, or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 16:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-23T16:59:40Z</dc:date>
    </item>
    <item>
      <title>Introducing MAI-Image-2.5 Pro and MAI-Voice-2 Flash in Microsoft Foundry</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-foundry-blog/introducing-mai-image-2-5-pro-and-mai-voice-2-flash-in-microsoft/ba-p/4539446</link>
      <description>&lt;P&gt;One of the core principles in Microsoft Foundry is giving customers flexibility to choose the right model for the right job. As we've continued to expand the Microsoft AI (MAI) model family, we've heard a consistent theme from developers and enterprises: they want more choice based on their specific workload requirements. Some need the highest possible quality, fidelity, and consistency for professional production workflows. Others prioritize responsiveness and cost-efficiency for frequent, real-time responses.&lt;/P&gt;
&lt;P&gt;Today, we're introducing two new additions to the MAI portfolio:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;MAI-Image-2.5 Pro&lt;/STRONG&gt;, designed for customers who need maximum visual fidelity and creative control&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;MAI-Voice-2 Flash&lt;/STRONG&gt;, built for low-latency voice applications where every millisecond matters.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these models extend the MAI family with specialized options that help developers optimize for the jobs they need to do. Let’s dive in.&lt;/P&gt;
&lt;H1&gt;MAI-Image-2.5 Pro: Built for professional creative workflows&lt;/H1&gt;
&lt;P&gt;MAI-Image-2.5 Pro is our newest high-fidelity image generation model, designed for scenarios where visual accuracy, consistency, and creative control are critical. The model delivers stronger object consistency, improved alignment with creative intent, and enhanced visual reasoning and world knowledge, making it the ideal choice when quality and fidelity matter more than throughput.&lt;/P&gt;
&lt;P&gt;As generative AI moves from experimentation to production, creative teams increasingly need models that can reliably generate assets that meet professional standards without extensive manual editing. MAI-Image-2.5 Pro was built to address those needs. Here are some of the scenarios it best fits:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Campaign Hero Assets &amp;amp; Multi-Frame Storytelling. &lt;/STRONG&gt;Creative agencies and marketing teams can create polished campaign visuals while maintaining consistent products, characters, and brand elements across every asset. Whether producing launch campaigns, social media variants, retail signage, or digital advertising, Image-2.5 Pro helps ensure visual consistency throughout the customer journey.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Product Photography &amp;amp; E-Commerce Catalogs.&lt;/STRONG&gt; Retailers and consumer brands can generate high-quality product imagery with accurate rendering of packaging, labels, materials, and reflections. The model's improved object consistency helps maintain identical product representation across multiple angles, color variations, and lifestyle settings.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Storyboarding &amp;amp; Pre-Visualization.&lt;/STRONG&gt; Film studios, game developers, and creative production teams can rapidly develop visual concepts while maintaining consistency across characters, environments, props, and scenes. Enhanced visual reasoning enables more accurate interpretation of camera direction, lighting, and staging instructions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Regulated Industry Content Creation.&lt;/STRONG&gt; Organizations in healthcare, financial services, manufacturing, and other regulated industries can generate imagery that requires greater real-world accuracy and domain understanding, reducing the effort needed to correct inaccuracies before customer-facing use&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;H4&gt;When should customers use MAI-Image-2.5 Pro vs. MAI-Image-2.5?&lt;/H4&gt;
&lt;P&gt;Both models deliver high-quality image generation capabilities, but they are optimized for different priorities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Choose MAI-Image-2.5 Pro when:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You need maximum image fidelity and creative quality.&lt;/LI&gt;
&lt;LI&gt;Object consistency across multiple images is critical.&lt;/LI&gt;
&lt;LI&gt;Your workflow depends on visual reasoning, world knowledge, and close adherence to creative direction.&lt;/LI&gt;
&lt;LI&gt;You are producing professional marketing, advertising, product design, or enterprise creative assets.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;MAI-Voice-2 Flash: Real-time voice experiences at scale&lt;/H1&gt;
&lt;P&gt;We're also introducing MAI-Voice-2 Flash, a new low-latency text-to-speech model that extends MAI-Voice-2 with faster response times and greater cost efficiency across more than 15 supported languages.&lt;/P&gt;
&lt;P&gt;As voice becomes a critical interface for AI applications, responsiveness is increasingly important to the end-user experience. Whether a customer is speaking with an AI-powered support agent, interacting with a voice assistant, or navigating a self-service phone system, long pauses can make experiences feel slow and unnatural. MAI-Voice-2 Flash was built to address those scenarios. Here are some of the scenarios on when to choose MAI-Voice-2 Flash:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Call Center Agents: &lt;/STRONG&gt;Customer support organizations can generate spoken responses in real time, minimizing delays between conversation turns and enabling more natural customer interactions. Low latency helps improve customer experiences while supporting AI-powered service, support, and sales workflows.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Conversational Voice Assistants:&lt;/STRONG&gt; Developers can build voice-enabled copilots, assistants, and intelligent applications that respond nearly instantly. The result is a more fluid, natural conversation that feels interactive rather than turn-based.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Interactive Voice Response (IVR) Systems: &lt;/STRONG&gt;Organizations can modernize traditional phone systems with dynamic AI-generated speech that responds contextually to customer requests while maintaining a responsive user experience.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;When should customers use MAI-Voice-2 Flash vs. MAI-Voice-2?&lt;/H4&gt;
&lt;P&gt;The distinction between the two voice models comes down to whether customers are optimizing for &lt;STRONG&gt;voice identity&lt;/STRONG&gt; or &lt;STRONG&gt;real-time responsiveness&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Choose MAI-Voice-2 Flash when:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Low latency is a primary requirement.&lt;/LI&gt;
&lt;LI&gt;You are building conversational assistants, IVR systems, or call center experiences.&lt;/LI&gt;
&lt;LI&gt;Users expect immediate spoken responses as part of a live interaction.&lt;/LI&gt;
&lt;LI&gt;Cost efficiency and responsiveness are more important.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Get started today in Microsoft Foundry&lt;/H1&gt;
&lt;P&gt;MAI-Image-2.5 Pro is available through &lt;A href="https://aka.ms/mai-image-2.5-pro-foundrycard" target="_blank"&gt;Microsoft Foundry&lt;/A&gt;, providing developers with access to Microsoft's latest advancements in image generation. Pricing starts at $5 per 1M tokens for text input, and $106 per 1M tokens for image output.&lt;/P&gt;
&lt;P&gt;MAI-Voice-2 Flash is available through &lt;A href="https://aka.ms/mai-voice-2-flash-foundrycard" target="_blank"&gt;Azure Speech&lt;/A&gt;, allowing customers to leverage Azure Speech's enterprise-grade reliability, scalability, and ecosystem while benefiting from Microsoft's latest voice technology. Pricing starts at $15 per 1M characters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 16:32:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-foundry-blog/introducing-mai-image-2-5-pro-and-mai-voice-2-flash-in-microsoft/ba-p/4539446</guid>
      <dc:creator>Naomi Moneypenny</dc:creator>
      <dc:date>2026-07-23T16:32:22Z</dc:date>
    </item>
    <item>
      <title>Your startup doesn't have an SRE team. Now what?</title>
      <link>https://techcommunity.microsoft.com/t5/startups-at-microsoft/your-startup-doesn-t-have-an-sre-team-now-what/ba-p/4540142</link>
      <description>&lt;P&gt;Most startups I work with have between 3 and 15 engineers. None of them have a dedicated SRE. The infrastructure runs on Azure, the team ships fast, and reliability is everyone's job until something breaks at 2 AM and it becomes one person's problem.&lt;/P&gt;
&lt;P&gt;This is not a criticism. It is the rational allocation of scarce engineering time. But it creates a gap: nobody is watching the slow drift toward misconfiguration, overspend, and compliance debt. By the time these surface, they surface as incidents.&lt;/P&gt;
&lt;P&gt;I spent the last few months building something to close that gap, and I want to share both the tool and the thinking behind it.&lt;/P&gt;
&lt;H2&gt;The problem with reactive operations&lt;/H2&gt;
&lt;P&gt;When a 10-person startup hits its first real outage, the postmortem usually reveals the same pattern: a quota was at 94% and nobody checked, a Network Security Group rule was too broad and nobody audited, a storage account had public access enabled six months ago during a debugging session and nobody reverted it.&lt;/P&gt;
&lt;P&gt;The fixes are trivial. The problem is that nobody had the bandwidth to look. Traditional monitoring covers the "is it up?" question well. It does not cover "are we accumulating risk?"&lt;/P&gt;
&lt;P&gt;Azure SRE Agent was built to fill exactly this space. It runs proactive, scheduled checks against your infrastructure and surfaces findings before they become pages. The built-in skills cover common scenarios, but every environment has its own shape. A fintech startup cares about different things than a gaming company.&lt;/P&gt;
&lt;H2&gt;Custom skills: teaching the agent your priorities&lt;/H2&gt;
&lt;P&gt;SRE Agent supports custom skills, which are structured prompts that tell the agent what to check, how to check it, and how to present findings. Think of them as runbooks that execute themselves on a schedule.&lt;/P&gt;
&lt;P&gt;I built a pack of 8 skills that cover the gaps I kept seeing across startup engagements:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A Well-Architected Framework review that scores all 5 pillars and flags the weakest one&lt;/LI&gt;
&lt;LI&gt;A compliance audit covering RBAC drift, missing resource locks, inconsistent tagging&lt;/LI&gt;
&lt;LI&gt;Capacity planning that checks quota utilization and projects when you will hit limits&lt;/LI&gt;
&lt;LI&gt;FinOps analysis combining cost optimization with chargeback allocation&lt;/LI&gt;
&lt;LI&gt;Blameless postmortem generation using the 5 Whys method&lt;/LI&gt;
&lt;LI&gt;Defender for Cloud Secure Score monitoring with prioritized remediation&lt;/LI&gt;
&lt;LI&gt;A governance maturity assessment designed specifically for Digital Native companies&lt;/LI&gt;
&lt;LI&gt;An AI Foundry and Azure OpenAI posture check for teams running LLM workloads&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Each skill runs read-only. No write operations, no deployments, no changes to your environment. The agent reads your infrastructure state and produces a scored report with specific remediation commands you can choose to run or ignore.&lt;/P&gt;
&lt;H2&gt;Design decisions that matter&lt;/H2&gt;
&lt;P&gt;A few choices shaped how these skills work, and I think they are worth explaining because they apply to anyone building custom skills.&lt;/P&gt;
&lt;H3&gt;Scoring over pass/fail&lt;/H3&gt;
&lt;P&gt;Every skill produces a numeric score. A binary "compliant / not compliant" result is less useful than knowing you are at 41/100 on governance maturity and your weakest area is identity management. Scores let you track improvement over time and prioritize effort.&lt;/P&gt;
&lt;H3&gt;Inline documentation links&lt;/H3&gt;
&lt;P&gt;Each finding includes a link to the relevant Microsoft Learn page. When the agent tells you that your Azure OpenAI deployment lacks a private endpoint, the remediation section includes the exact &lt;CODE&gt;az&lt;/CODE&gt; CLI command and a link to the documentation explaining why it matters. The goal is that an engineer can go from finding to fix without opening a browser to search.&lt;/P&gt;
&lt;H3&gt;Tiered scheduling&lt;/H3&gt;
&lt;P&gt;Not all checks need the same frequency. The capacity planning skill should run daily because quotas can spike fast. The Well-Architected review is a weekly check because architectural drift happens slowly. I organized the 8 skills into three priority tiers so teams can configure schedules that match the volatility of each risk category.&lt;/P&gt;
&lt;H3&gt;No write operations, ever&lt;/H3&gt;
&lt;P&gt;This was a hard line from day one. These skills read infrastructure state through Azure Resource Graph, Azure CLI queries, and REST API calls. They never create, modify, or delete resources. The remediation commands appear in the output as suggestions for a human to review and execute. This constraint makes the skills safe to run on production subscriptions without additional approval workflows.&lt;/P&gt;
&lt;H2&gt;What the output looks like&lt;/H2&gt;
&lt;P&gt;Here is a real example from the Digital Native Governance skill running against a test subscription.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://raw.githubusercontent.com/ricmmartins/azure-sre-agent-skills/main/docs/images/skill-07-governance.png" alt="Digital Native Governance skill output showing a 41/100 maturity score" /&gt;&lt;/P&gt;
&lt;P&gt;The agent checks 6 governance categories: Alerting, Subscription Topology, Cost Controls, Identity, Web Protection, and Operational Foundations. Each category gets a score against its maximum, and the total determines a maturity level (Foundation, Developing, Established, or Optimized).&lt;/P&gt;
&lt;P&gt;In my test run, the subscription scored 41/100, placing it at "Developing" maturity. Web Protection scored 0/15 because there was no WAF, no custom domain, no DDoS protection. Alerting scored 3/20 because Service Health and Resource Health alerts were missing entirely. That is specific enough to act on immediately.&lt;/P&gt;
&lt;P&gt;The FinOps skill found ~$43/month in recoverable waste on a subscription that costs about $177/month. Empty container registries, deallocated VMs still paying for disks and public IPs, overprovisioned Defender plans. Not a huge number, but for a pre-seed startup running lean, that is real money sitting idle.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://raw.githubusercontent.com/ricmmartins/azure-sre-agent-skills/main/docs/images/skill-04-finops.png" alt="FinOps Intelligence skill showing waste detection with prioritized savings" /&gt;&lt;/P&gt;
&lt;P&gt;And here is what the Well-Architected review looks like when it scores all five pillars:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://raw.githubusercontent.com/ricmmartins/azure-sre-agent-skills/main/docs/images/skill-01-waf-review.png" alt="Well-Architected Framework review with 5-pillar scoring" /&gt;&lt;/P&gt;
&lt;H2&gt;Lessons from building this&lt;/H2&gt;
&lt;P&gt;Three things I did not expect when I started.&lt;/P&gt;
&lt;P&gt;First, prompt structure matters more than prompt length. Early versions of these skills were verbose, with long explanations of each check. The agent performed better with terse, structured instructions that clearly separated what to check, how to check it, and how to format the result. Clarity beats volume.&lt;/P&gt;
&lt;P&gt;Second, the LLM behind the agent occasionally rendered emoji shortcodes (&lt;CODE&gt;:red_circle:&lt;/CODE&gt;) as literal text instead of Unicode characters. This sounds minor but it made the output hard to scan visually. The fix was a single line in the skill definition: "Use Unicode emoji characters directly, never use emoji shortcodes." Explicit formatting instructions prevent the model from making stylistic choices that degrade readability.&lt;/P&gt;
&lt;P&gt;Third, scoring philosophy requires intentional calibration. If you weight security checks too heavily, every subscription looks terrible and the report loses signal. If you weight them too lightly, teams ignore real risk. I landed on roughly 35% security, 30% reliability, 25% cost, and 10% architecture for the AI workload skill after testing against several real environments and seeing which distributions produced actionable variance between "good" and "needs work" subscriptions.&lt;/P&gt;
&lt;H2&gt;How to use this&lt;/H2&gt;
&lt;P&gt;The skills are open-source at &lt;A href="https://github.com/ricmmartins/azure-sre-agent-skills" target="_blank"&gt;github.com/ricmmartins/azure-sre-agent-skills&lt;/A&gt;. Each skill is a single Markdown file you paste into the SRE Agent portal at &lt;A href="https://sre.azure.com" target="_blank"&gt;sre.azure.com&lt;/A&gt;. Setup takes about five minutes per skill.&lt;/P&gt;
&lt;P&gt;You do not need all eight. If your startup is pre-revenue and running a single subscription, start with Capacity Planning and FinOps. If you are preparing for an enterprise customer's security questionnaire, start with Compliance and Defender Secure Score. Pick the two or three that match your current pain.&lt;/P&gt;
&lt;P&gt;The skills are MIT-licensed and designed to be forked. If your compliance requirements include specific tagging conventions or naming standards, edit the skill to check for those. The structure is documented so you can build your own from scratch if none of mine fit.&lt;/P&gt;
&lt;H2&gt;How this differs from Azure Advisor&lt;/H2&gt;
&lt;P&gt;The first question people ask: why not just use Azure Advisor?&lt;/P&gt;
&lt;P&gt;Advisor gives you a flat list of recommendations per resource. It tells you "this VM could be smaller" or "enable HTTPS on this App Service." Useful, but limited in three ways.&lt;/P&gt;
&lt;P&gt;First, Advisor has no concept of correlation. It does not know that your failing health probe, your missing Resource Health alert, and your absent backup vault are three symptoms of the same problem: nobody set up operational foundations for that workload. These skills connect findings across domains and produce a single maturity score that tells you where you actually stand.&lt;/P&gt;
&lt;P&gt;Second, Advisor does not generate narrative reports. It exports a CSV of individual recommendations, but there is no scored document with correlated findings, maturity levels, and prioritized remediation commands that you can forward to a CTO or attach to a security questionnaire. These skills produce that artifact directly in the chat, ready to copy or download.&lt;/P&gt;
&lt;P&gt;Third, Advisor is passive. You go to the portal and look at it. SRE Agent runs your skills on a schedule and surfaces problems before they surface themselves as incidents. The difference between "there is a recommendation waiting in the portal" and "the agent flagged a quota at 85% utilization this morning" is the difference between a suggestion and a safety net.&lt;/P&gt;
&lt;P&gt;Think of Advisor as a linter. These skills are closer to a staff SRE who reads everything, correlates the findings, and writes you a report with priorities and az CLI commands ready to paste.&lt;/P&gt;
&lt;H2&gt;What this is not&lt;/H2&gt;
&lt;P&gt;This is not a replacement for proper observability, incident management, or SRE staffing. When your startup reaches the scale where you need a dedicated SRE function, you should build one.&lt;/P&gt;
&lt;P&gt;What these skills give you is coverage during the phase when you do not have that function yet. They catch the slow-moving risks that slip through the cracks when everyone is heads-down shipping features. Think of them as a part-time auditor who checks in daily and tells you what drifted since yesterday.&lt;/P&gt;
&lt;P&gt;For startups on Azure, that gap between "we should probably check our security posture" and "we have someone whose job it is to check our security posture" can last years. These skills are one way to fill it.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 15:47:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/startups-at-microsoft/your-startup-doesn-t-have-an-sre-team-now-what/ba-p/4540142</guid>
      <dc:creator>rmmartins</dc:creator>
      <dc:date>2026-07-23T15:47:17Z</dc:date>
    </item>
    <item>
      <title>Understanding Microsoft 365 Copilot Risk Surface and Mitigations</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/understanding-microsoft-365-copilot-risk-surface-and-mitigations/ba-p/4538712</link>
      <description>&lt;P&gt;It’s a shift that carries important security implications organizations should understand&amp;nbsp;before scaling deployment.&amp;nbsp;Customers with Microsoft 365 E5 licensing may already have access to many of the tools that can help identify and reduce Copilot-related risk, but licensing alone does not reduce exposure.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What’s often missing during early Copilot deployments is a clear understanding of the risk surface itself: &lt;EM&gt;what data is exposed, who can access it, and &lt;/EM&gt;t&lt;EM&gt;hrough which vectors&lt;/EM&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Organizations beginning their Zero Trust journey can use the Zero Trust Workshop to assess their current posture, identify gaps, and better understand how existing permissions and governance impact Copilot readiness. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this post, we take a broader look at the types of risks Copilot can amplify and how those risks align to key Zero Trust pillars.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Why Copilot changes the risk conversation&lt;/H2&gt;
&lt;P&gt;Before assessing specific risks, it's worth understanding why AI solutions like Copilot introduce a different risk conversation than traditional Microsoft 365 applications.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most enterprise applications operate within a bounded context. A user opens a file, reads an email, or searches a SharePoint one item at a time. The time and effort required to manually locate, connect, and synthesize information across systems creates a natural friction layer. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;While that friction was never designed as a formal security control, it did create a practical limit on how quickly users could surface and act on organizational data at scale.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft 365 Copilot removes much of that friction entirely. It operates at the speed of a prompt across the full scope of a user's access rights, synthesizing information from emails, files, meetings, chats, and other Microsoft 365 data sources into a single response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The exposure is not the result of new permissions; it comes from how quickly and easily existing access can be discovered and aggregated. In short, Copilot makes data once hidden by volume discoverable by intent.&lt;/P&gt;
&lt;H2&gt;Use Zero Trust to assess Copilot risk&lt;/H2&gt;
&lt;P&gt;Zero Trust rests on three principles: &lt;STRONG&gt;verify explicitly&lt;/STRONG&gt;, &lt;STRONG&gt;use least-privileged access&lt;/STRONG&gt;, and &lt;STRONG&gt;assume breach&lt;/STRONG&gt;. Rather than trusting users or devices by network location, it requires continuous validation of every user, endpoint, and request. This analysis focuses on the four pillars most directly involved in Copilot deployments.&lt;/P&gt;
&lt;P&gt;Together, these pillars answer three questions: who can access Copilot; from which endpoints and applications; and what data Copilot can surface once access is granted.&lt;/P&gt;
&lt;H2&gt;The two-layer Copilot risk model&lt;/H2&gt;
&lt;P&gt;The foundation is simple: Copilot acts as a force multiplier for whatever access a user already has. If that access is governed well, Copilot improves productivity; if not, it amplifies exposure. Risk is therefore examined in two layers — access to the Copilot service itself, and access to the data Copilot can ground on and surface.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;MICROSOFT 365 COPILOT&amp;nbsp; ·&amp;nbsp; TWO-LAYER RISK MODEL&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 70.2778%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 43.6545%" /&gt;&lt;col style="width: 56.3455%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;STRONG&gt;Layer-1 Access Risk&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;&lt;STRONG&gt;Device&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Who can access copilot&lt;/td&gt;&lt;td&gt;From which devices&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Under what conditions&lt;/td&gt;&lt;td&gt;Device compliance posture&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;STRONG&gt;Layer-2 Data &amp;amp; Governance Risk&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Apps&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;&lt;STRONG&gt;Data&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What copilot can access and surface&lt;/td&gt;&lt;td&gt;Sharing and permissions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Connected data sources&lt;/td&gt;&lt;td&gt;Labeling, classification, output context&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table-1:&lt;/STRONG&gt; Two-layer model for Microsoft 365 Copilot risk&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Risk Layer-1: Who can access Microsoft 365 Copilot?&lt;/H1&gt;
&lt;P&gt;The first layer of risk begins at the point of entry: the conditions that determine whether a user can access Copilot. Organizations don’t need to address every potential exposure point at once. Think of the following table as a map of where exposure &lt;EM&gt;can&lt;/EM&gt; exist across identity and device controls. For details of how remediation works for this layer of risks; you may refer to the blog post: &lt;A href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener"&gt;Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The following risks are primarily governed by the Identity and Devices pillars of Zero Trust and define whether Copilot is being accessed by the right person, from a trusted device, under appropriate authentication and access conditions.&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 948px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Risk&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Pillar&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Description&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R1&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Unmanaged identity access&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;A compromised, shared, or former employee account can authenticate to Microsoft 365 and access Copilot. Because Copilot operates across the full scope of a user’s permissions, compromised accounts expose a much larger&amp;nbsp;risk surface than before Copilot existed. Strong account hygiene and identity lifecycle management therefore directly reduce Copilot exposure.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R2&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Weak or absent multi-factor authentication&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;If organizations do not enforce MFA, or if legacy authentication bypasses modern sign-in controls, users can start Copilot sessions using only a password. In environments with inconsistent MFA coverage, attackers may need only&amp;nbsp;stolen credentials to gain access. Because Copilot synthesizes data across services, compromised accounts create significantly greater risk than access to a single application.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R3&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Unmanaged or non-compliant devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Users can access Copilot through browsers and native applications from any device where they can authenticate. Unmanaged devices without EDR coverage, disk encryption enforcement, or compliance posture evaluation can expose Copilot sessions and allow attackers or unauthorized users to store or exfiltrate outputs locally.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R4&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;License sprawl without role-based scoping&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Enterprise Copilot pilots often start with broad license assignments across departments, floors, or business units instead of deliberate, security-reviewed pilot groups. When organizations assign licenses without reviewing each user’s access rights, permission posture, and role sensitivity, Copilot can amplify risk across both highly governed and minimally governed users. Broad pilot enrollment without access review is itself a risk factor.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R5&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Missing real-time risk evaluation at sign-in&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;If Conditional Access does not evaluate sign-in and user risk signals—such as impossible travel, anomalous token activity, or identity protection alerts—high-risk sessions may still gain access to Copilot. Without real-time risk gating, controls respond only after access is granted, by which point Copilot may already have surfaced and synthesized sensitive content.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R6&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;App protection gap on mobile devices&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Users can access Microsoft 365 Copilot mobile—and the broader Microsoft 365 mobile surface that exposes Copilot—from personal devices that are not enrolled in MDM or MAM. Without an application protection policy, organizations cannot prevent users from copying Copilot outputs into unmanaged apps, remotely wipe organizational data from lost devices, or restrict screenshots and screen recordings during Copilot sessions containing sensitive data.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 101px" /&gt;&lt;col style="width: 236px" /&gt;&lt;col style="width: 155px" /&gt;&lt;col style="width: 456px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table - 2: &lt;/STRONG&gt;&lt;/EM&gt;Risks in Layer-1: Who can access Microsoft 365 Copilot&lt;/P&gt;
&lt;H2&gt;Key observations from Layer 1:&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Identity appears most frequently across Layer 1 risks, reflecting how tightly Copilot access depends on authenticated user permissions and sign-in conditions. Device-related risks also play a major role because unmanaged or non-compliant endpoints can expose Copilot sessions and outputs beyond the organization’s trusted environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Together, these risks highlight a central theme: securing Copilot access is not just about controlling who can sign in, but also validating the devices, conditions, and access patterns associated with every session.&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Risk layer 2: What data can Microsoft 365 Copilot reach?&amp;nbsp;&lt;/H1&gt;
&lt;P&gt;The second layer of risk assumes that the user is already authenticated and actively using Copilot.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this stage, the focus shifts from who can access Copilot to what data Copilot can surface on the user’s behalf.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These risks reflect the full scope of data exposure created by existing permissions, overshared content, connected systems, and governance gaps. &amp;nbsp;Layer 2 risks are governed primarily by the Apps and Data pillar, with Identity playing a secondary role in defining the scope of data each user can access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For mitigating risks in this layer, you may refer to the blog post: &lt;A href="https://techcommunity.microsoft.com/blog/fasttrackblog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero-trust-apps-and-data-/4534642" target="_blank" rel="noopener"&gt;Limiting Microsoft 365 Copilot data exposure risk with Zero Trust apps and data controls.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 939px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Risk&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Pillar&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Description&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R7&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Overshared SharePoint and OneDrive content&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Content shared with "Everyone," "Everyone except external users," or broad groups becomes part of Copilot’s query able surface for any licensed user, even if that user would never have found those files manually. Years of SharePoint oversharing, combined with Copilot’s ability to traverse and synthesize content in a single prompt, can turn long-standing governance debt into immediate exposure. Copilot makes data once hidden by volume, discoverable by intent.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R8&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Sensitivity label gaps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Microsoft Purview sensitivity labels tell Copilot how to handle content, including whether it can summarize, cite, or include that content in responses. Leaving content unlabeled, mislabeling, or miss inheriting labels across containers such as SharePoint sites and Teams, Copilot treats the content as unclassified and may surface it freely. Many enterprise tenants still contain large volumes of unlabeled legacy content, and Copilot cannot infer classification on its own.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R9&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Excessive user permissions&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity &amp;amp; Apps&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Like overshared content, Copilot follows each user’s existing Microsoft Graph permissions and does not surface content users cannot access. In many enterprise environments, however, users accumulate access far beyond their current role through leftover project permissions, broad temporary group memberships, and inherited rights from outdated organizational structures. Copilot does not create this overprovisioning, but it makes the full scope of that access immediately visible and usable.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R10&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;No DLP coverage on Copilot-generated outputs&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Copilot outputs—including summaries, drafts, and synthesized answers—are generated content, and traditional DLP policies do not always preserve links to original source data.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Users may receive Copilot responses containing aggregated PII, financial data, or confidential project details and paste that information into emails, Teams messages, or external documents without triggering DLP policies designed to detect the original source files. As content shifts from source material to generated output, organizations often lose the underlying sensitivity context.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R11&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Plugin and connector data surface expansion&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Identity&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Organizations can extend Microsoft 365 Copilot through plugins and Microsoft Graph connectors that pull external data from CRM systems, ITSM platforms, HR applications, and custom line-of-business tools. Each connector expands the data surface Copilot can query on a user’s behalf and often reaches into systems whose access control models do not align natively with Microsoft 365 permissions.&amp;nbsp;As organizations add connectors, each connected source introduces governance and audit risk that expands alongside the broader Copilot data surface.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R12&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Audit and visibility gap&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Organizations need visibility into what users asked Copilot, what data Copilot accessed, , and what responses it generated to maintain an effective security posture for both incident response and risk monitoring. Disabling Copilot interaction logging, retaining audit logs for too short a period, or failing to forward logs to a SIEM, obscures the organization’s visibility into how users interact with Copilot, whether Copilot surfaces unexpected content, and whether activity may indicate compromise. Without audit data, organizations cannot reliably detect misuse or investigate incidents.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;R13&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Privileged user data amplification&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Identity, Apps &amp;amp; Data&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Administrators, senior IT staff, and other privileged users often hold access that spans organizational boundaries, including mailboxes, site collections, security groups, and configuration data that most users never access.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A compromised admin account with Copilot access gives adversaries an organization-wide view of data that far exceeds the exposure associated with a compromised end-user account. Organizations therefore need to apply the strictest Copilot access governance to privileged identities.&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 101px" /&gt;&lt;col style="width: 213px" /&gt;&lt;col style="width: 183px" /&gt;&lt;col style="width: 441px" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Table – 3:&lt;/STRONG&gt;&lt;/EM&gt; Layer-2 Risks: What data can Microsoft 365 Copilot reach?&lt;/P&gt;
&lt;H2&gt;Key observations from Layer 2:&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;Apps-related risks appear throughout Layer 2 because Microsoft 365 Copilot depends heavily on connected systems, accessible data sources, and governance over generated outputs. The Data pillar further emphasizes the need to protect not only sensitive source content but also AI-generated responses that aggregate and surface information across systems.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The table above maps each identified risk to its primary and secondary Zero Trust pillars. Primary pillars represent control areas that most directly govern a given risk, while secondary pillars represent contributing dimensions.&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Conclusion &amp;amp; next steps&lt;/H1&gt;
&lt;P&gt;Copilot typically does not grant broader access than a user already has — it makes existing access easier to discover, connect, and use across Microsoft 365. Organizations that successfully scale Copilot are the ones that understand and govern that access first.&lt;/P&gt;
&lt;P&gt;Reducing Copilot data exposure is not a one-time cleanup; it is a continuous governance posture. Oversharing accumulates, labels drift, permissions grow, and connectors are added. Together, the Layer 1 and Layer 2 controls in this guide create the feedback loops that keep the risk surface governed as the organization and its use of Copilot evolve — governing not only who can access the service, but what it can reach on their behalf.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;WHERE TO GO NEXT&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess your current posture: &lt;/STRONG&gt;Zero Trust Workshop — &lt;A href="http://zerotrust.microsoft.com" target="_blank" rel="noopener"&gt;http://zerotrust.microsoft.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Understand the framework: &lt;/STRONG&gt;Zero Trust Overview on Microsoft Learn (&lt;A href="http://learn.microsoft.com/security/zero-trust" target="_blank" rel="noopener"&gt;http://learn.microsoft.com/security/zero-trust&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 15:37:20 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/understanding-microsoft-365-copilot-risk-surface-and-mitigations/ba-p/4538712</guid>
      <dc:creator>AtilGurcan</dc:creator>
      <dc:date>2026-07-23T15:37:20Z</dc:date>
    </item>
    <item>
      <title>New in Microsoft Marketplace: offers published June 23-24, 2026</title>
      <link>https://techcommunity.microsoft.com/t5/marketplace-blog/new-in-microsoft-marketplace-offers-published-june-23-24-2026/ba-p/4522363</link>
      <description>&lt;P&gt;Learn about 221 new offers that went live in Microsoft Marketplace, a single destination to find, try, and buy cloud solutions, AI apps, and agents to meet your business needs.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="0" style="width: 95%; border-width: 0px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th colspan="2" style="padding: 20px 0px 20px 0px;"&gt;
&lt;H3&gt;&lt;EM&gt;Get it now in our marketplace&lt;/EM&gt;&lt;/H3&gt;
&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/pscinc.mashu-dev-a9655340-69f8-48d0-813e-97021a4d9fe5/image1_MashuIcon350x350.png" alt="" width="100" height="100" /&gt;
&lt;P aria-hidden="true"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/pscinc.mashu-dev" target="_blank" rel="noopener"&gt;Mashu Server&lt;/A&gt;: Mashu is a SaaS data catalog that automatically collects and integrates metadata from distributed systems like data lakes and warehouses. It centralizes metadata management, enabling quick data discovery and use; supports easy, low-risk implementation; offers pay-as-you-go pricing; and improves data access, collaboration, and governance for data-driven decisions.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ackomas1638438212608.koa-cloud-prod-b3362de4-41da-4bb1-96ca-bd17ede3538e/image7_63b9cbd4dd8d402191c5ec7cf189d3aa.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/ackomas1638438212608.koa-cloud-prod" target="_blank" rel="noopener"&gt;Ackomas Koa Cloud&lt;/A&gt;: Ackomas is a SaaS platform for medical device regulatory data governance, offering centralized data management, automated submissions, and global database connectivity. It supports multi-entity workflows, integrates with IT systems, enhances data reliability, and helps anticipate regulatory changes, enabling scalable, efficient access to international markets.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/inspiraenterpriseinc1683208138220.advanced_threat_hunting_agent_by_inspira-31ca514b-b5be-46b0-ac1b-e8dc46aa6e73/image4_logo1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/inspiraenterpriseinc1683208138220.advanced_threat_hunting_agent_by_inspira" target="_blank" rel="noopener"&gt;Advanced Threat Hunting Agent by Inspira&lt;/A&gt;: This autonomous threat hunting agent for Microsoft Sentinel and Microsoft Defender XDR detects suspicious activity, correlates data, reconstructs attacks, adds threat intelligence, and provides actionable insights. Outputs include executive summary, findings, entity analysis, MITRE ATT&amp;amp;CK mapping, attack timeline, evidence, recommendations, and a final verdict.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/perseus.aegis-4dd90aa1-20a4-464d-9646-0779d1e9cefc/image5_AegisLogo300x300.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.perseus|AID.aegis|PAPPID.b7e3a1d4-f592-4c80-9a1b-dc8723ef5601" target="_blank" rel="noopener"&gt;Aegis Capital Forecasting&lt;/A&gt;: Aegis Capital Forecasting is an earned value management extension for Microsoft Dynamics 365 Business Central, enabling real-time cost control, budget tracking, and automated forecasting for capital projects. It offers WBS hierarchy, AFE spending gates, and progress measurement and eliminates the need for spreadsheets and costly platform changes.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/inspiraenterpriseinc1683208138220.ai-incident-investigation-agent-by-inspira-7b0c5b29-3754-47a7-b87a-6077d4325d01/image3_logo1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/inspiraenterpriseinc1683208138220.ai-incident-investigation-agent-by-inspira" target="_blank" rel="noopener"&gt;AI Incident Investigation Agent by Inspira&lt;/A&gt;: Autonomous AI agent for Microsoft Sentinel and Microsoft Defender XDR conducts deep incident investigations, correlating alerts, entities, and threat intelligence. It reconstructs attack timelines, identifies root causes, maps MITRE ATT&amp;amp;CK techniques, and provides evidence-based reports with actionable recommendations, enhancing SOC analyst efficiency and accelerating incident response.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/dcassociatesgroupinc.superset-aks-ed8b66d0-bad4-4acd-a3cc-abb3069b1928/image4_216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/dcassociatesgroupinc.superset-aks" target="_blank" rel="noopener"&gt;Apache Superset on Azure Kubernetes Service&lt;/A&gt;: Apache Superset is an Apache 2.0 licensed data exploration and visualization platform deployed on Azure Kubernetes Service using the official ASF Helm chart. It features Celery async query execution, Valkey cache backend, PostgreSQL metadata database, and PVC storage.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/usabilitydynamicsinc1664553940144.apim-dr-40d80e5f-146e-4600-9a42-254e8790213a/image4_udxcloud216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/usabilitydynamicsinc1664553940144.apim-dr" target="_blank" rel="noopener"&gt;API Management Backup by UDX&lt;/A&gt;: API Management Backup by UDX offers automated backup, efficient restore, and disaster recovery for API instances. It ensures high availability, security, compliance, and scalability with an easy-to-use interface. This solution enhances resilience, operational efficiency, and cost-effectiveness, safeguarding API services against data loss and downtime for business continuity.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/bizaginoram.c9bc87c2-7a47-46ff-8c55-b5dd30b24879-51f49e7f-ed6d-444c-80b3-650fb758961d/image6_logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bizaginoram.c9bc87c2-7a47-46ff-8c55-b5dd30b24879" target="_blank" rel="noopener"&gt;Bizagi - NORAM&lt;/A&gt;: Bizagi is a low-code process automation platform offering rapid solution delivery, business agility, and governance. It integrates seamlessly with Microsoft Azure, supports AI-powered features like Ask Ada, and serves citizen to pro developers. Bizagi’s scalable, usage-based pricing and expert services drive enterprise-wide automation and efficiency.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/boltinsight.f9f33682-3e2b-4097-994e-ef04f07e5f96-56e1b598-b0ad-4f27-91f5-2aa98e193a87/image8_logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/boltinsight.f9f33682-3e2b-4097-994e-ef04f07e5f96" target="_blank" rel="noopener"&gt;Bolt Intelligence&lt;/A&gt;: Bolt Intelligence is an AI-native consumer insight platform combining qualitative research, quantitative research, UX testing, and social listening. It delivers fast, decision-ready findings with expert oversight, saving time and reducing costs. Trusted by top global brands, it offers advanced tools like AI-moderated interviews, emotion analysis, and dynamic personas for enterprise teams.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/celltrust.celltrust-sl2-verizon-carrier-capture-c9978ae3-a2c5-4121-8fc8-746aebeeefc5/image0_CellTrustLogoLarge.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/celltrust.celltrust-sl2-verizon-carrier-capture" target="_blank" rel="noopener"&gt;CellTrust SL2 for Verizon Carrier Capture&lt;/A&gt;: CellTrust’s Carrier Capture enables compliant text message archiving on corporate-owned devices without extra apps. It captures SMS/MMS directly via carriers, preserving native format and attachments. The self-service portal offers easy deployment, policy control, and monitoring, supporting COBO strategies for secure, business-only device use and seamless compliance.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/climavision1758733249697.horizon_ai-54d7ff5b-869b-416e-84a4-f56a597e5bdd/image4_Climavisionsquarelogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/climavision1758733249697.horizon_ai" target="_blank" rel="noopener"&gt;Climavision Horizon AI Point Weather Model&lt;/A&gt;: Horizon AI Point by Climavision offers precise, site-specific weather forecasts up to 15 days ahead using AI and proprietary radar data. It supports energy traders, utilities, renewable operators, and others by delivering localized, high-resolution forecasts to optimize operations, reduce risk, and improve weather-driven decision-making.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/hoshebartartech.costguard-9cdf3eb1-d1fd-49f6-8560-52099bd862ea/image8_marketplace.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/hoshebartartech.costguard" target="_blank" rel="noopener"&gt;CostGuard&lt;/A&gt;: CostGuard is a cost management tool for SaaS teams using Azure. It provides clear insights into cloud spending, tracks trends, identifies top cost drivers, offers optimization recommendations, and forecasts future costs. Designed for startups and DevOps, it enables proactive Azure cost control through a user-friendly, multi-tenant workspace.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/centralsolutions1591256491708.cs_sscc_management-b7be5fb5-76ec-4536-a763-00a03168cb94/image5_CSLogoVierkantNaam.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.centralsolutions1591256491708|AID.cs_sscc_management|PAPPID.a46d5b1f-9650-4c9c-9cf4-b61a3b0f7e3b" target="_blank" rel="noopener"&gt;CS SSCC Management&lt;/A&gt;: CS SSCC Management adds GS1-compliant unique identification numbers to packages, enhancing traceability and efficiency in supply chains. It supports various package types, integrates with external devices via API, and complies with global standards. Compatible with Dynamics 365 Business Central, it streamlines logistics for retail and other industries worldwide.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/towerswatson1764089740231.cyberquantified2025-3b3b9167-4fac-427b-b49c-95a6b250e060/image3_Azure.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/towerswatson1764089740231.cyberquantified2025" target="_blank" rel="noopener"&gt;Cyber Quantified&lt;/A&gt;: Cyber Quantified is a cyber risk modeling tool that predicts financial impacts of cyber threats, helping organizations optimize risk management and insurance coverage. Designed for risk professionals, it enhances collaboration between security and risk teams, providing clarity, transparency, and improved resilience against evolving cyber risks.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/enkaytech.document_intelligent-3630f4e4-e3fe-408c-80b3-6a1eb6995f07/image1_1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/enkaytech.document_intelligent" target="_blank" rel="noopener"&gt;Document Intelligence – Automate Document Processing&lt;/A&gt;: Document Intelligence uses AI, OCR, NLP, and machine learning to automate document processing, extracting and validating data from emails, PDFs, invoices, and more. It integrates with ERP systems, speeds workflows from minutes to seconds, reduces manual entry errors, lowers costs, and enhances productivity, supporting digital transformation and efficient business operations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ensureendpointtechnologiesinc1713258254571.standard_per-user_v1-214c0ed2-8ca0-48ad-8fa1-b3f9b92e80aa/image0_EnsureLogomarketplace.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/ensureendpointtechnologiesinc1713258254571.standard_per-user_v1" target="_blank" rel="noopener"&gt;Ensure PosturePass Compliance Verification System&lt;/A&gt;: PosturePass extends Microsoft Entra Conditional Access to external devices without changing Microsoft Entra ID setup. It installs quickly, verifies device compliance, and integrates natively, securing unmanaged contractor devices. No VPN, MDM, or IT help is needed. The solution ensures privacy, fast deployment, and seamless control for Microsoft 365 environments with external users.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ensureendpointtechnologiesinc1713258254571.proof_of_concept_v1-a021f1ac-1a23-468b-9d9d-6da74784a1c4/image5_EnsureLogomarketplace.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/ensureendpointtechnologiesinc1713258254571.proof_of_concept_v1" target="_blank" rel="noopener"&gt;Ensure PosturePass Proof of Concept for 25 Users&lt;/A&gt;: PosturePass extends Microsoft Entra Conditional Access to external devices without changing Microsoft Entra ID setup. It installs quickly, verifies device compliance, and integrates natively, securing unmanaged contractor devices. No VPN, MDM, or IT help is needed. The solution ensures privacy, supports Windows/macOS, and works seamlessly with Microsoft 365 environments.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/carahsofttechnologycorporation1595268429697.everfoxdataguard-9ef36d6f-64ac-4a8b-ba11-dd9323c3e36e/image2_everfoxlogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/carahsofttechnologycorporation1595268429697.everfoxdataguard" target="_blank" rel="noopener"&gt;Everfox Data Guard Bundle&lt;/A&gt;: Everfox Data Guard is a defense-grade, high-assurance software solution for securely transferring and controlling data between physically separated networks. It ensures robust data protection without hardware, providing a reliable method to maintain data security across isolated systems.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/carahsofttechnologycorporation1595268429697.evershield_insider_risk-b3850465-1586-43ad-91e7-2ce0d23a1576/image0_everfoxlogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/carahsofttechnologycorporation1595268429697.evershield_insider_risk" target="_blank" rel="noopener"&gt;EverShield Insider Risk Case Manager&lt;/A&gt;: EverShield Insider Risk Case Manager is a secure, centralized platform for managing evidence and documentation. It features in-app messaging and workflows to enhance team collaboration, enabling faster case handling. The tool offers operational and strategic metrics to monitor caseloads, assess organizational risk, and address critical inquiries efficiently.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/carahsofttechnologycorporation1595268429697.evershield_uam-8f13b8f9-bfa4-42f0-b599-3b7150680f09/image1_everfoxlogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/carahsofttechnologycorporation1595268429697.evershield_uam" target="_blank" rel="noopener"&gt;EverShield User Activity Monitoring&lt;/A&gt;: Everfox EverShield User Activity Monitoring helps security analysts and investigators by gathering behavioral data from various endpoints, providing comprehensive context of user activities for enhanced monitoring and analysis.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/carahsofttechnologycorporation1595268429697.evershield_ueba-902d2553-6147-4b8c-a305-851024588269/image3_everfoxlogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/carahsofttechnologycorporation1595268429697.evershield_ueba" target="_blank" rel="noopener"&gt;EverShield User Entity Behavioral Analytics&lt;/A&gt;: Everfox's Activity Insights dashboard enhances security teams' efficiency by integrating with EverShield User Activity Monitoring's Investigation Workbench. It streamlines workflows, helping prioritize and investigate risky user activities for improved security management.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ubitech1606239403921.ubitech_gaia-d4f6af35-f1ad-435b-9c5d-515bbb3f2b43/image0_gaialogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/ubitech1606239403921.ubitech_gaia" target="_blank" rel="noopener"&gt;Gaia - Agentic AI Application Platform&lt;/A&gt;: Gaia is an enterprise platform for designing, operating, and governing AI agents and applications. It integrates agent design, runtime orchestration, risk controls, evaluation, and governance in one system. Gaia supports multicloud environments, ensures auditability, and helps organizations scale AI from pilots to governed, mission-critical deployments.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/deelinc1779278270159.327d9d64-e502-4bca-8e18-687b39138452-9f542837-5b45-43fa-a7bc-7f91a0d3c834/image7_logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/deelinc1779278270159.327d9d64-e502-4bca-8e18-687b39138452" target="_blank" rel="noopener"&gt;Global Payroll and HR&lt;/A&gt;: Deel simplifies global hiring by managing payroll, compliance, benefits, and immigration in more than 150 countries without needing local entities. The solution offers a unified platform for onboarding, performance, and IT management to confidently scale remote teams worldwide.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/innovaccerinc1585921027287.gravity_the_autonomous_healthcare_platform-4d18d2b4-4030-4b4a-954a-1f1125f6a449/image0_icon350x350.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/innovaccerinc1585921027287.gravity_the_autonomous_healthcare_platform" target="_blank" rel="noopener"&gt;Gravity - The Autonomous Healthcare Platform&lt;/A&gt;: Gravity is an AI-powered healthcare platform that unifies data from multiple sources into a secure, cloud-agnostic system. It enables low-code AI application development, automates workflows, and offers healthcare-specific AI models. Gravity enhances collaboration, ensures compliance, and delivers rapid insights to improve patient outcomes and operational efficiency.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ginetai.90ebf44c-2789-4b37-8b19-8c904abb8d3e-a8742b8c-5483-4196-b9d8-0f54a41166bb/image2_logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/ginetai.90ebf44c-2789-4b37-8b19-8c904abb8d3e" target="_blank" rel="noopener"&gt;Humanix&lt;/A&gt;: Humanix uses conversational AI to detect and respond to social engineering attacks targeting enterprise help desks and identity workflows. It analyzes voice, chat, and email interactions in real time, identifying manipulation, impersonation, and procedure violations. Humanix integrates with platforms like Microsoft 365 and ServiceNow for proactive security and compliance.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/inspiraenterpriseinc1683208138220.identity_threat_analyst_agent_by_inspira-cf7d1b4d-4b21-41dd-9479-48594bfb8bc5/image1_logo1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/inspiraenterpriseinc1683208138220.identity_threat_analyst_agent_by_inspira" target="_blank" rel="noopener"&gt;Identity Threat Analyst Agent by Inspira&lt;/A&gt;: This autonomous agent for Microsoft Entra ID investigates identity threats by analyzing risk events, sign-in anomalies, privilege exposure, MFA/token abuse, and Microsoft Entra Conditional Access gaps. It provides evidence-based analysis with MITRE ATT&amp;amp;CK mapping, risk assessments, prioritized remediation guidance, and a comprehensive final verdict for enhanced security management.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/inspiraenterpriseinc1683208138220.incident_intelligence_reporting_agent-a302df4c-2a1f-4d20-b8a1-675ba6460ae4/image1_logo1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/inspiraenterpriseinc1683208138220.incident_intelligence_reporting_agent" target="_blank" rel="noopener"&gt;Incident Intelligence Reporting Agent&lt;/A&gt;: This autonomous agent for Microsoft Sentinel and Microsoft Defender XDR incidents automates deep investigations, retrieving metadata, alerts, threat intelligence, and attack timelines. It generates detailed reports with MITRE ATT&amp;amp;CK mapping, root cause analysis, risk scoring, and remediation guidance, providing downloadable HTML, PDF, and Microsoft Word outputs for SOC teams and management.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/lbc030124.lex_fixed_fee-bcf3687b-f25f-4696-a4d1-b49d892df6dd/image1_LOLogoSimple216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/lbc030124.lex_fixed_fee" target="_blank" rel="noopener"&gt;LEX Risk Management Coach&lt;/A&gt;: Lockbase Exposure Agent (LEX) identifies and prioritizes pre-breach risks across Microsoft Entra ID, Active Directory, and Azure. It analyzes telemetry and configuration data to reveal exploitable escalation paths, vulnerabilities, and exposure, providing CISOs with actionable, prioritized risk findings to reduce attack surfaces before exploitation occurs.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/spektra.neural-data-synthesis-hub-89530403-5be2-4fe3-83e8-39a61fb5edcf/image3_image2024.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/spektra.neural-data-synthesis-hub" target="_blank" rel="noopener"&gt;NeuralData Synthesis Hub&lt;/A&gt;: NeuralData Synthesis Hub is an advanced AI-driven platform that integrates and analyzes data using neural networks. It enhances data processing and provides real-time insights, making it ideal for businesses needing intelligent data synthesis and improved decision-making capabilities.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/spektra.neural-net-integrato-2fr-7650dab7-85e4-468c-abb3-53145473db61/image3_image2024.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/spektra.neural-net-integrato-2fr" target="_blank" rel="noopener"&gt;NeuralNet Integrator&lt;/A&gt;: NeuralNet Integrator is an advanced AI platform for seamless integration and deployment of neural network models. It offers robust tools for developing, training, and managing networks, ensuring optimal performance and scalability across various applications.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/panzurainc.panzura_nexus-dbb82388-3743-40b6-8c0d-a2521d20fdcc/image0_1780973941iconpanzuranexus250x250.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/panzurainc.panzura_nexus" target="_blank" rel="noopener"&gt;Panzura Nexus&lt;/A&gt;: Panzura Nexus is an enterprise AI platform that securely integrates unstructured file data with Microsoft 365 Copilot. It enables real-time, permission-aware access to file content without data migration, enhancing productivity and insights for industries like AEC and manufacturing. The extensible platform supports future AI integrations while preserving security and governance.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/siemensindustrysoftwaresrl1749134989492.polarion_x_italy-d5728636-2b53-4b57-9d83-89692d6f6df2/image0_Siemens216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/siemensindustrysoftwaresrl1749134989492.polarion_x_italy" target="_blank" rel="noopener"&gt;Polarion X Italy&lt;/A&gt;: Polarion is a browser-based application lifecycle management tool for teams of any size. It enables unified definition, building, testing, and management of software with end-to-end traceability, agile support, secure collaboration, granular permissions, and workflow automation, enhancing productivity and compliance across distributed teams.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/spektra.quantum-pulse-analyzer-2s-b8f5d3a1-8fcb-4509-ae7b-a17ced173629/image1_image2024.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/spektra.quantum-pulse-analyzer-2s" target="_blank" rel="noopener"&gt;QuantumPulse Analyzer&lt;/A&gt;: This solution uses AutoML to analyze real-time data streams, helping businesses gain timely insights and make informed decisions. The service offers efficient, automated data handling and analysis, enhancing operational agility and supporting data-driven strategies.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/quest.quest_dm-06714bf5-ed1f-49eb-9e99-9416935f9ce3/image3_QuestLogo216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/quest.quest_dm" target="_blank" rel="noopener"&gt;Quest Data Modeler&lt;/A&gt;: Quest Data Modeler is a cloud-native SaaS platform enabling AI-assisted, collaborative data modeling with enterprise governance. It ensures consistent data definitions across teams and tools, supports full-stack modeling, integrates with major cloud platforms, and bridges legacy and modern workflows—accelerating delivery, enhancing trust, and aligning business meaning with technical data.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/awpbi.reality_capture-701bbb67-2dd4-40e8-b1af-b63eaa35b743/image2_RealityCaptureLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/awpbi.reality_capture" target="_blank" rel="noopener"&gt;Reality Capture&lt;/A&gt;: Reality Capture embeds 360-degree panoramas into Microsoft Power BI, offering a street-view interface for site monitoring and spatial data tracking. It includes tools for project progress comparison.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/trainocateholdingsltd6207954.reset_trainocatehl-9bdcc015-d1fd-435e-98a9-3b2ba9fd72eb/image0_reset.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/trainocateholdingsltd6207954.reset_trainocatehl" target="_blank" rel="noopener"&gt;RESET – Microsoft 365 Digital Skills and Enablement Platform&lt;/A&gt;: RESET is a self-service digital learning platform offering more than 5,000 task-based videos on Microsoft 365, AI, and Microsoft 365 Copilot. It supports role-based, multilingual, and self-paced learning with tracking, gamification, and SSO integration, helping individuals and organizations improve digital skills, productivity, and technology adoption efficiently.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/inspiraenterpriseinc1683208138220.risk_intelligence_executive_narrator_by_inspira-9abef33c-f002-4b64-b555-5b2ce8060683/image3_logo1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/inspiraenterpriseinc1683208138220.risk_intelligence_executive_narrator_by_inspira" target="_blank" rel="noopener"&gt;Risk Intelligence Executive Narrator by Inspira&lt;/A&gt;: This autonomous risk intelligence agent for Microsoft Sentinel and Microsoft Defender XDR incidents converts technical data into clear business narratives, risk summaries, impact assessments, and stakeholder communications. It supports executive leadership, SOC, IT, and compliance teams by generating tailored email drafts based on incident IDs, enhancing security response efficiency.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/towerswatson1764089740231.risk_iq-50047a48-001b-4ae5-afc7-230f4a546138/image5_Azure.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/towerswatson1764089740231.risk_iq" target="_blank" rel="noopener"&gt;Risk IQ Suite&lt;/A&gt;: Risk IQ enhances transparency, efficiency, and resilience by offering advanced risk modeling across the spectrum. It enables clients to independently measure and model risk outcomes or collaborate with experts. This modern, connected platform optimizes total risk and insurance programs, moving beyond spreadsheets for smarter risk management.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/9341436.schedule_pro-e312665d-49ea-44e9-b428-5920de7001fe/image2_icon300x300.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/9341436.schedule_pro" target="_blank" rel="noopener"&gt;Schedule Pro&lt;/A&gt;: Schedule Pro integrates with Power BI to visualize Primavera P6 and Microsoft Project schedules. It offers interactive Gantt charts, S-Curves, EVM dashboards, risk analysis, and baseline comparisons. Features include customizable themes, multi-project support, and privacy-focused local processing.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/socio-dm.sdm-gradientheatmap-5685563b-cd1f-4acc-92a7-3641326d93cc/image16_heatmaplogo300.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/socio-dm.sdm-gradientheatmap" target="_blank" rel="noopener"&gt;SDM Gradient Heatmap&lt;/A&gt;: SDM Gradient Heatmap creates smooth, continuous color surfaces from sparse XY points using interpolation algorithms. Features include customizable color presets, isolines, sample markers, category labels, axes, legends, cross-filtering, and rich tooltips. The solution is ideal for spatial analysis, scientific visualization, and enterprise dashboards requiring continuous data surfaces.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cybwell.cybwell-fastonboarding-cfa45a30-2c65-4265-8835-be42ac6b7906/image5_cybwelllogomarketplace350.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/cybwell.cybwell-fastonboarding" target="_blank" rel="noopener"&gt;Swiss fastOnboarding API&lt;/A&gt;: Swiss fastOnboarding API offers fast, accurate Swiss company and address data validation with daily updates from the Swiss Commercial Register. It reduces manual entry, prevents errors, and enhances onboarding for banking, CRM, ERP, and more. Usage-based billing enables cost-effective integration into digital applications and business processes.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/textminelimited1781886869381.txm_azure-023ae01a-98e7-407b-b41c-41136f59a6ad/image1_textminelargelogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/textminelimited1781886869381.txm_azure" target="_blank" rel="noopener"&gt;TextMine&lt;/A&gt;: TextMine is a context layer for enterprise agents that enhances data analysis by providing advanced contextual insights. It integrates seamlessly with existing systems, helping businesses improve decision-making and operational efficiency. Ideal for handling complex datasets, TextMine enables precise, actionable results, boosting competitiveness in data-driven environments.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/upstage-marketplace.studio-91cf8fa8-ed31-438c-a424-b4fa5d21b3b8/image3_UpstageLogoAzure.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/upstage-marketplace.studio" target="_blank" rel="noopener"&gt;Upstage Studio&lt;/A&gt;: Upstage Studio is a no-code platform for building document agents that manage complex workflows using multiple AI models. It supports various document formats; ensures repeatability, verifiability, and human oversight; and allows integration of your language models for precise data extraction and classification without technical expertise.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/versoinc.labtestkitmanagement-3bf045ac-77df-4e88-a916-ca7331e3feb2/image4_largegraylogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/versoinc.labtestkitmanagement" target="_blank" rel="noopener"&gt;VERSO KitBridge – Lab Kit Orchestration Platform&lt;/A&gt;: VERSO KitBridge bridges the gap between LIMS and logistics for healthcare testing programs. It standardizes kit assembly and offers real-time tracking, AI-driven analytics, blockchain compliance, and multi-site coordination. Designed for CROs, specialty labs, and home testing, it boosts efficiency, reduces errors, and ensures scalable, compliant operations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th colspan="2" style="padding: 20px 0px 20px 0px;"&gt;
&lt;H3&gt;&lt;EM&gt;Easily deploy virtual machine images&lt;/EM&gt;&lt;/H3&gt;
&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/anarion-technologies.apache-accumulo_v-3-0-0-fb801a6c-e0bf-498d-99a8-971cb041031c/image1_Logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.apache-accumulo_v-3-0-0" target="_blank" rel="noopener"&gt;Apache Accumulo on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.apachearrow_v-24-0-0" target="_blank" rel="noopener"&gt;Apache Arrow on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.apache-avro_v-1-12-1" target="_blank" rel="noopener"&gt;Apache Avro on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.apachebeam_v-2-74-0" target="_blank" rel="noopener"&gt;Apache Beam on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.duckdb" target="_blank" rel="noopener"&gt;DuckDB v1.5.4 on Debian 13&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.fusionpbx" target="_blank" rel="noopener"&gt;FusionPBX v5.5 on Debian 13&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.haproxy_debian" target="_blank" rel="noopener"&gt;HAProxy on Debian 13&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.haproxy_ubuntu" target="_blank" rel="noopener"&gt;HAProxy v3.4.0 on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.mosquitto_mqtt" target="_blank" rel="noopener"&gt;Mosquitto MQTT v2.1.2 on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.pyarrow_v-24-0-0" target="_blank" rel="noopener"&gt;PyArrow on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.quay_container_registry_ubuntu" target="_blank" rel="noopener"&gt;Quay Container Registry on Ubuntu 26.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/anarion-technologies.wireguard" target="_blank" rel="noopener"&gt;WireGuard v1.0.2 on Debian 13&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/articentgroupllc1635512619530.postgresql-16-enterprise-linux-10-47f985ce-f569-4975-bf4b-199b6a84bf9b/image0_LargeLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-16-enterprise-linux-10" target="_blank" rel="noopener"&gt;Database for PostgreSQL 16 on Enterprise Linux 10&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-16-linux-stream-9" target="_blank" rel="noopener"&gt;Database for PostgreSQL 16 on Linux Stream 9&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-17-enterprise-linux-10" target="_blank" rel="noopener"&gt;Database for PostgreSQL 17 on Enterprise Linux 10&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-17-linux-stream-9" target="_blank" rel="noopener"&gt;Database for PostgreSQL 17 on Linux Stream 9&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-18-rhel-9" target="_blank" rel="noopener"&gt;Database for PostgreSQL 18 Based on Red Hat Enterprise Linux 9&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-18-linux-stream-10" target="_blank" rel="noopener"&gt;Database for PostgreSQL 18 on Linux Stream 10&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.postgresql-18-linux-stream-9" target="_blank" rel="noopener"&gt;Database for PostgreSQL 18 on Linux Stream 9&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/articentgroupllc1635512619530.linux-stream-9-pytorch-nvidia-cuda" target="_blank" rel="noopener"&gt;Linux Stream 9 VM for PyTorch Workloads with NVIDIA CUDA GPU Support&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/athinfosystems1641442221349.airflowww-b5140492-b69d-407c-835c-42beb0364f35/image2_ath.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.airflowww" target="_blank" rel="noopener"&gt;Airflow&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.bob111" target="_blank" rel="noopener"&gt;Bob&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.coast123" target="_blank" rel="noopener"&gt;Coaster CMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.couchdb11" target="_blank" rel="noopener"&gt;CouchDB&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.elgg123" target="_blank" rel="noopener"&gt;Elgg&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.evol" target="_blank" rel="noopener"&gt;Evolution CMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.laravel1" target="_blank" rel="noopener"&gt;Laravel&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.noco123" target="_blank" rel="noopener"&gt;NocoDB&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.pres" target="_blank" rel="noopener"&gt;Prestashop&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.prom" target="_blank" rel="noopener"&gt;Prometheus-Grafana&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.red333" target="_blank" rel="noopener"&gt;Red5&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.redminee" target="_blank" rel="noopener"&gt;Redmine&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.sqlite123" target="_blank" rel="noopener"&gt;SQLite&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/athinfosystems1641442221349.waga" target="_blank" rel="noopener"&gt;Wagtail&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.anythingllm-ubuntu-24-04-aeda5bbf-6349-4eb2-b047-e084970d9a76/image3_logolarge.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.anythingllm-ubuntu-24-04" target="_blank" rel="noopener"&gt;AnythingLLM on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.bun-ubuntu-24-04" target="_blank" rel="noopener"&gt;Bun on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.concrete-cms-ubuntu-24-04" target="_blank" rel="noopener"&gt;Concrete CMS on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.crowdsec-ubuntu-24-04" target="_blank" rel="noopener"&gt;CrowdSec on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.ferretdb-ubuntu-24-04" target="_blank" rel="noopener"&gt;FerretDB on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.krakend-ubuntu-24-04" target="_blank" rel="noopener"&gt;KrakenD API Gateway on Ubuntu 24.04&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.localai-ubuntu-24-04" target="_blank" rel="noopener"&gt;LocalAI on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.reposilite-ubuntu-24-04" target="_blank" rel="noopener"&gt;Reposilite on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.traefik-ubuntu-24-04" target="_blank" rel="noopener"&gt;Traefik Proxy on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.trivy-ubuntu-24-04" target="_blank" rel="noopener"&gt;Trivy on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.umami-ubuntu-24-04" target="_blank" rel="noopener"&gt;Umami on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.verdaccio-ubuntu-24-04" target="_blank" rel="noopener"&gt;Verdaccio on Ubuntu 24.04 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/cloudimg1647283583153.vikunja-ubuntu-24-04" target="_blank" rel="noopener"&gt;Vikunja on Ubuntu 24.04 LTS&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/gottaphish.keycloak-scim-magiclink-vm-65914d05-d43b-40f1-bb5d-2d5e126534a8/image3_logosmall216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/gottaphish.keycloak-scim-magiclink-vm" target="_blank" rel="noopener"&gt;Alvanit Keycloak - Magic Link and SCIM&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/meanio.linnovate-amneziavpn-fafcb79a-4a43-4548-9c0e-5ad4fde587e4/image1_amnezia.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/meanio.linnovate-amneziavpn" target="_blank" rel="noopener"&gt;Amnezia VPN Supported and Secured by the Hossted Platform&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/kcloudhubllc1763357129530.ajenti4444-0376d51b-bcdb-4f75-9c6d-ceaef1c5436e/image1_kCloud216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.ajenti4444" target="_blank" rel="noopener"&gt;Ajenti&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.bigtreecms4444" target="_blank" rel="noopener"&gt;BigTree CMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.dolibarr444" target="_blank" rel="noopener"&gt;Dolibarr&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.gibbon444" target="_blank" rel="noopener"&gt;Gibbon LMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.golang33" target="_blank" rel="noopener"&gt;Go (Golang)&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.instantcms444" target="_blank" rel="noopener"&gt;InstantCMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.oauthlib444" target="_blank" rel="noopener"&gt;oAuthlib&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.oxideshop444" target="_blank" rel="noopener"&gt;OXID eShop&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.piwigo6666" target="_blank" rel="noopener"&gt;Piwigo&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.wondercms444" target="_blank" rel="noopener"&gt;WonderCMS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/kcloudhubllc1763357129530.zenario444" target="_blank" rel="noopener"&gt;Zenario&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/lynxroute.grafana-95ed909a-6a6a-46e5-809b-27807f907ee1/image3_Azureready.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/lynxroute.grafana" target="_blank" rel="noopener"&gt;Grafana + Prometheus - Hardened Observability Stack&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/nacarattosolutions.redhat_enterprise_linux_9_2-77ba0fee-a49c-4f55-ad40-d2e07b964d7d/image2_1.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/nacarattosolutions.redhat_enterprise_linux_9_2" target="_blank" rel="noopener"&gt;Red Hat Enterprise Linux 9.2&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/pcloudhosting.bill-a55e0a15-f1fc-40f5-85da-38cd85e7141d/image3_pcloud.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.bill" target="_blank" rel="noopener"&gt;Billing Lago&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.prox" target="_blank" rel="noopener"&gt;Cilium Proxy&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.press" target="_blank" rel="noopener"&gt;FlatPress&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.parse" target="_blank" rel="noopener"&gt;Parse Server&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.py7" target="_blank" rel="noopener"&gt;PyTorch&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.rustc" target="_blank" rel="noopener"&gt;Rust&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/pcloudhosting.stiching" target="_blank" rel="noopener"&gt;Stitching Tools&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/supportedimagesllc1615494954880.windowsservers-4ffdaa01-9176-4e06-ac52-ff2cd77ddd50/image2_SupportedImages.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/supportedimagesllc1615494954880.windowsservers" target="_blank" rel="noopener"&gt;VM for Windows Server&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/tidalmediainc.ubuntu-26-04-lts-min-0827328f-98ef-41e7-8c7b-1054c38b7e7a/image1_LargeLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/tidalmediainc.ubuntu-26-04-lts-min" target="_blank" rel="noopener"&gt;VM with Ubuntu 26.04 LTS Minimal&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/tidalmediainc.wiki-js-ubuntu-26-04-lts" target="_blank" rel="noopener"&gt;Wiki Engine (Wiki.js-based) on Ubuntu 26.04 LTS&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/virtualpulsesro1607008728942.calls-voip-server-debian-12-lts-babd5d83-27e1-4603-aab7-05375167bde4/image0_ICON.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/virtualpulsesro1607008728942.calls-voip-server-debian-12-lts" target="_blank" rel="noopener"&gt;Calls VoIP Server on Debian 12 LTS&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/virtualpulsesro1607008728942.linux-stream-9-wireguard" target="_blank" rel="noopener"&gt;Linux Stream 9 VM with VPN Server (WireGuard Protocol)&lt;/A&gt;&lt;BR /&gt;&lt;A style="text-decoration: none; color: #007bff;" href="https://marketplace.microsoft.com/marketplace/apps/virtualpulsesro1607008728942.softether_vpn_windows_server2022_dc" target="_blank" rel="noopener"&gt;SoftEther VPN for Windows Server 2022 Datacenter&lt;/A&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th colspan="2" style="padding: 20px 0px 20px 0px;"&gt;
&lt;H3&gt;&lt;EM&gt;Go further with workshops, proofs of concept, and implementations&lt;/EM&gt;&lt;/H3&gt;
&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/vivictaoy1766065150408.vivicta_no_agent_factory-55c1023f-8cea-4cbb-8e64-1343340eff82/image1_VivictaFavicon216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/vivictaoy1766065150408.vivicta_no_agent_factory" target="_blank" rel="noopener"&gt;Agent Factory - Explore, Build, Govern, Secure, and Scale Agents&lt;/A&gt;: Vivicta's Agent Factory helps organizations implement Microsoft Copilot Agents through three models: kickstart for pilot projects, advisory for building internal skills, and delivery for full lifecycle management. It accelerates value, ensures governance, and offers flexible, expert-led services tailored to organizational maturity and needs.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/nexergroupab1652510841646.ai_service_agent-a7a0050e-ec37-4a1a-a694-dfed3968ef76/image1_nexerlogolarge.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nexergroupab1652510841646.ai_service_agent" target="_blank" rel="noopener"&gt;AI Customer Service Agent - Retail Accelerator&lt;/A&gt;: Nexer’s AI Customer Service Agent enhances customer service by integrating with existing platforms like Dynamics 365. It provides real-time guidance, suggested responses, and customer data to improve case handling, reduce errors, and boost agent confidence. Quick to deploy, it delivers measurable benefits from day one, helping teams during peak times and onboarding.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/nexergroupab1652510841646.ai_store_assistant-0e83b8aa-8ba4-4bf5-be7b-62bfe4b74534/image2_nexerlogolarge.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nexergroupab1652510841646.ai_store_assistant" target="_blank" rel="noopener"&gt;AI Store Assistant&lt;/A&gt;: Nexer’s AI Store Assistant integrates with existing platforms to enhance Dynamics 365 Sales usage. It provides store teams instant access to product details, stock, and customer context, enabling faster service, cross-selling, upselling, and efficient handling of sales and returns to boost sales and improve customer experience.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/litsservices1588138020299.lits_assesment-f77e340a-4300-4a3c-964c-7439b06b3ef0/image3_litslogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/litsservices1588138020299.lits_assesment" target="_blank" rel="noopener"&gt;Assessment and Upgrade to Dynamics 365 Business Central&lt;/A&gt;: LITS Services offers a comprehensive offering to assess and upgrade your ERP system to Dynamics 365 Business Central. It evaluates compatibility, customization, and data migration needs, ensuring a smooth transition. This upgrade enhances operational efficiency and leverages new features, minimizing business disruption during modernization.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/manaosoftwarecompanylimited1674962973297.azure_cloud_migration-34e0810b-4798-4113-8b9a-aaa4eea9401a/image3_ManaoLogoSecondaryGreenLoRes.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/manaosoftwarecompanylimited1674962973297.azure_cloud_migration" target="_blank" rel="noopener"&gt;Azure Cloud Migration and Managed Services&lt;/A&gt;: Manao Software specializes in Azure services, offering cloud migration, architecture, cost optimization, and managed operations. Certified experts ensure secure, compliant, and efficient solutions tailored for businesses using Microsoft technologies. Founded in 2007, they serve Nordic and Thai enterprises, providing practical, results-focused cloud modernization and support.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/logicvinc1717228303427.logicv-azure-migration-modernization-e787abd9-8d5a-4f94-8ed1-a7ab5a6c65d9/image2_IconBarsRedWhite256.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/logicvinc1717228303427.logicv-azure-migration-modernization" target="_blank" rel="noopener"&gt;Azure Migration and Modernization&lt;/A&gt;: Logic V offers a comprehensive Azure Migration and Modernization service, transitioning organizations from legacy systems to scalable, secure Azure environments. They assess infrastructure, plan and execute migrations, and optimize performance, cost, and governance. This engagement is ideal for modernizing applications, consolidating datacenters, and enabling cloud-native growth and innovation.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/logicvinc1717228303427.logicv-azure-storage-implementation-355f5e97-c548-45ad-8214-2a289a904f4c/image2_IconBarsRedWhite256.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/logicvinc1717228303427.logicv-azure-storage-implementation" target="_blank" rel="noopener"&gt;Azure Storage and Secure Data Management Implementation&lt;/A&gt;: Logic V's Azure Storage service includes designing and deploying secure, scalable solutions using Azure Blob Storage, Azure Data Lake Storage, and others. They ensure controlled access, data protection, lifecycle management, and cost optimization, integrating with Azure services for backup, disaster recovery, and automation.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/heshamnouh.duc_bcdr_azure-f36d3c7a-449d-4b53-a6a2-2463d498ebb8/image3_DUCL.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/heshamnouh.duc_bcdr_azure" target="_blank" rel="noopener"&gt;Business Continuity and Disaster Recovery on Azure&lt;/A&gt;: Diyar United's Azure-based Business Continuity and Disaster Recovery service includes risk assessment, design, implementation, testing, and documentation. Using Azure Site Recovery and Azure Backup, this service protects critical workloads across environments, ensuring fast recovery, monitoring, and operational readiness.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/capgemini-group.mssovereigndataprotectioncyberdefence-dbcb3daa-bc59-4cde-bdcd-927685f0ceeb/image4_cg216logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/capgemini-group.mssovereigndataprotectioncyberdefence" target="_blank" rel="noopener"&gt;Capgemini Sovereign: Data Protection and Cyber Defense&lt;/A&gt;: Capgemini will deploy Microsoft Sovereign Key Management and Data Protection to secure sensitive data across Microsoft 365, Azure, SaaS, and hybrid environments. It offers data discovery, classification, encryption, key management, and monitoring, reducing risks like data loss and ransomware. Ideal for regulated enterprises, it ensures compliance, control, and audit readiness with scalable, integrated Microsoft security solutions.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/capgemini-group.mssovereignresilience-f3c19863-598a-41e4-bb6a-18b8e29d15d6/image3_cg216logo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/capgemini-group.mssovereignresilience" target="_blank" rel="noopener"&gt;Capgemini Sovereign: Microsoft Sovereign Resilience&lt;/A&gt;: Sovereign Resilience by Capgemini ensures critical workloads remain operational, compliant, and controlled amid regulatory or geopolitical constraints. It offers tailored strategies, multicloud architecture, identity continuity, and tested playbooks for lawful business continuity, making it ideal for regulated enterprises needing secure, resilient AI, data, and SaaS operations under evolving sovereignty conditions.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cps.cps_agentops-34c57477-9c12-4d50-8052-b7b7b8018784/image3_AgentOpslogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/cps.cps_agentops" target="_blank" rel="noopener"&gt;CPS AgentOps Agent Factory&lt;/A&gt;: CPS AgentOps is a managed service that helps organizations govern, scale, and optimize Microsoft AI agents like Microsoft 365 Copilot. It provides governance, lifecycle management, support, and continuous improvement to accelerate AI adoption, reduce risks, and maximize business value across industries, enabling scalable, secure, and measurable AI deployments.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cps.cps_agent_hr-a411d9bd-b6d3-427a-b1de-b6e4fd76a30f/image8_CPS.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/cps.cps_agent_hr" target="_blank" rel="noopener"&gt;CPS HR Agent – AI-Powered HR Support for Microsoft 365&lt;/A&gt;: The CPS HR Agent automates HR queries within Microsoft 365, providing instant, policy-compliant answers. It reduces HR workload, improves employee experience, ensures compliance, and offers analytics for better HR processes. Customizable and secure, it streamlines HR service delivery and supports strategic workforce initiatives.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cps.cps_agent_recruitment-9bdec906-3af3-4030-8c3e-ff1cd97e5413/image0_CPS.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/cps.cps_agent_recruitment" target="_blank" rel="noopener"&gt;CPS Recruitment CV Sifting Agent&lt;/A&gt;: The Recruitment CV Sifting Agent by CPS automates high-volume CV screening using Microsoft Copilot Studio, reducing screening time from days to minutes. It delivers unbiased, data-driven candidate rankings, saves money, improves recruiter focus, and enhances hiring efficiency.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/telekomdeutschlandgmbhbonn1632996783690.data_protection_envisioning_workshop-ae4e6d1c-14af-4e68-96c7-7e0e9645b50c/image2_Telekom.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/telekomdeutschlandgmbhbonn1632996783690.data_protection_envisioning_workshop" target="_blank" rel="noopener"&gt;Data Protection Envisioning Workshop&lt;/A&gt;: Telekom Deutschland's Data Protection Envisioning Workshop analyzes security and compliance risks in Microsoft 365, identifies sensitive data and insider threats, assesses the environment, develops measures with Microsoft Purview, and demonstrates solutions in a practical way. The target group is IT and security managers who want to improve governance, compliance, and AI security.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/1605098832294.microsoftdynamics365bclocalizationforspain-211c2eaa-14ec-4c84-b85e-6d5c74624774/image5_AwaraITLogo216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/1605098832294.microsoftdynamics365bclocalizationforspain" target="_blank" rel="noopener"&gt;Dynamics 365 Business Central Spain Localization&lt;/A&gt;: Awara IT's service configures Dynamics 365 Business Central for Spain, enabling local VAT reporting, electronic invoicing (FacturaE), and compliance with Spanish tax laws. It offers setup, training, and support for faster rollout, reducing manual finance tasks and ensuring smooth operations aligned with local requirements.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/naviona_4717541.erp_jumpstart_guided_implementation-69670783-e627-41d8-a26a-67bb8c86426f/image4_NavionaLogo216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/naviona_4717541.erp_jumpstart_guided_implementation" target="_blank" rel="noopener"&gt;ERP JumpStart Guided Service&lt;/A&gt;: ERP JumpStart Guided Service by Naviona offers small businesses a faster, lower-risk Dynamics 365 Business Central setup with expert support. It includes workshops, hands-on sessions, and 12 expert reviews, enabling quick go-live, reduced manual work with Microsoft Copilot, and scalable ERP tailored for growth.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/naviona_4717541.erp_jumpstart_self_serve_bc_implementation-234842ab-38dc-415a-9e09-cf76d47fad25/image1_NavionaLogo216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/naviona_4717541.erp_jumpstart_self_serve_bc_implementation" target="_blank" rel="noopener"&gt;ERP JumpStart Self-Service&lt;/A&gt;: ERP JumpStart Self-Service by Naviona offers small businesses a fast, ready-to-run Dynamics 365 Business Central ERP solution. It features guided self-setup with expert support, built-in training, and Microsoft Copilot integration. Designed for quick implementation, it replaces complex projects with a scalable, best-practice system to streamline operations and growth.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/folio3software.finance-for-dynamics365-finance-and-operations-6d65b5bf-c1d1-4cea-9910-3a36215c26d6/image1_216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/folio3software.finance-for-dynamics365-finance-and-operations" target="_blank" rel="noopener"&gt;Dynamics 365 Finance Implementation&lt;/A&gt;: Folio3 implements Microsoft Dynamics 365 Finance for fast, AI-driven financial close. It supports multi-entity, multi-currency consolidation, budgeting, and audit-ready reporting with Microsoft Copilot and AI agents. Integrated with Azure and Power BI, it ensures real-time analytics, lower costs, and global compliance from day one.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/incrementptyltd1637494276783.agent_365-a6e72d0c-e054-4322-a145-ae7c3cc88e37/image0_IncrementSquareLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/incrementptyltd1637494276783.agent_365" target="_blank" rel="noopener"&gt;Get Agent Ready with Microsoft Agent 365&lt;/A&gt;: Increment's Get Agent Ready with Microsoft Agent 365 helps organizations adopt AI agents securely and effectively. It addresses challenges like lack of AI strategy, governance gaps, undefined operating models, data security risks, licensing complexities, and agent sprawl, ensuring a scalable, compliant, and cost-efficient AI deployment.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/accigo1763389057334.integration_operations_hub-edf3957f-c1d6-4f29-8d31-e3d7886db0d5/image0_AccigoMSMarkeplace.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/accigo1763389057334.integration_operations_hub" target="_blank" rel="noopener"&gt;Integration Operations Hub: Centralized Monitoring and Recovery for Azure Integrations&lt;/A&gt;: Accigo's Integration Operations Hub centralizes Azure integration monitoring and recovery, reducing mean time to recovery and operational effort. It offers unified dashboards, automated telemetry ingestion, dead-letter queue management, and proactive alerts. Secure and scalable, it empowers support teams to resolve incidents without deep Azure expertise, improving reliability and SLA performance.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/tenant-ibmalliance-mpn-core-15608861579888451249.intelligent_contact_center_platform_iccp-0bba59e5-7d65-438e-9475-5666b8b97235/image8_ibmlogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/tenant-ibmalliance-mpn-core-15608861579888451249.intelligent_contact_center_platform_iccp" target="_blank" rel="noopener"&gt;Intelligent Contact Center Platform&lt;/A&gt;: IBM's Intelligent Contact Center Platform uses AI to enhance customer service by supporting live agents, automating tasks, and providing real-time guidance. Built on Azure, it improves efficiency, reduces handle time, and integrates with existing systems, enabling scalable, consistent, and high-quality support for modern contact centers.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/nexergroupab1652510841646.inventory_and_demand_intelligence_agent-e3995478-554c-4868-8edd-1f4ce44f65cc/image2_nexerlogolarge.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nexergroupab1652510841646.inventory_and_demand_intelligence_agent" target="_blank" rel="noopener"&gt;Inventory and Demand Intelligence Agent&lt;/A&gt;: Nexer’s Inventory and Demand Intelligence Agent integrates demand signals and supply data with Dynamics 365, enabling proactive identification of demand shifts, replenishment risks, and sales opportunities. It helps retail teams make data-driven decisions, improving responsiveness across stores, e-commerce, and suppliers while optimizing inventory and sourcing strategies.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/jascoconsultingptyltd1581981131653.copilot_adoption_program-63d0a528-2f49-48ab-8283-36e462455df2/image2_JascoLogo2.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/jascoconsultingptyltd1581981131653.copilot_adoption_program" target="_blank" rel="noopener"&gt;Jasco Copilot Advantage: Microsoft 365 Copilot Adoption Program&lt;/A&gt;: The Jasco Copilot Advantage ensures secure, effective Microsoft 365 Copilot adoption. It offers role-based training, change management, and continuous consulting to embed Copilot into workflows, delivering measurable productivity gains, strong AI governance, and a scalable adoption model for Australian organizations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/ltim.ltm_data_and_ai_deepcure-5a0913fa-9a8f-48ac-8622-919c547b8b1c/image1_LTM216X216px.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/ltim.ltm_data_and_ai_deepcure" target="_blank" rel="noopener"&gt;LTM Data and AI DeepCure&lt;/A&gt;: LTIMindtree's DeepCure AI, built on Azure, accelerates drug discovery by automating literature review, molecular screening, and analysis using AI agents and domain-specific data. It reduces research time, improves candidate selection, lowers manual effort, and integrates decision intelligence for faster, data-driven biomedical research workflows.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/folio3software.manufacturing-dynamics365-finance-and-operation-99a6c26d-aff8-4a5e-9255-3978b21c2cb2/image2_216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/folio3software.manufacturing-dynamics365-finance-and-operation" target="_blank" rel="noopener"&gt;Manufacturing for Dynamics 365&lt;/A&gt;: Folio3 enhances Dynamics 365 for manufacturers by unifying production, inventory, and finance in one system. Their solution offers real-time data, integrates via Burq iPaaS, and supports discrete and process manufacturing. Benefits include faster delivery, lower integration risk, scalable cloud deployment, and audit-ready financials.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/cloud-direct-1665588.microsoft_365_copilot_deployment-c7fb09e5-bd69-41c0-b1a4-f4f524718b13/image3_Eric216x216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/cloud-direct-1665588.microsoft_365_copilot_deployment" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot Deployment&lt;/A&gt;: Cloud Direct's service ensures secure, governed deployment of Microsoft 365 Copilot aligned with business priorities. It includes readiness assessment, phased rollout, compliance controls, and detailed documentation, enabling controlled AI adoption, improved productivity, reduced risk, and scalable implementation for responsible, efficient use of Microsoft 365 Copilot.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/avectrisag1600241865435.copilot_starter_workshop-ee99139d-e5b7-4184-abf8-4769f451443f/image0_starterworkshop2216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/avectrisag1600241865435.copilot_starter_workshop" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot Starter Workshop&lt;/A&gt;: Aveniq offers a workshop on Microsoft 365 Copilot, providing an overview, practical industry-specific use cases, and strategic rollout planning. Participants gain a clear understanding of the capabilities and limitations of Microsoft 365 Copilot. The workshop concludes with documented results, delivering a structured decision-making guide for successful implementation.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/avectrisag1600241865435.microsoft-copilot_studio-a43d9a07-a9eb-4ee7-b7e8-816f09e0ae41/image0_agentbuilder216.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/avectrisag1600241865435.microsoft-copilot_studio" target="_blank" rel="noopener"&gt;Microsoft Copilot Studio - Agent Builder&lt;/A&gt;: Aveniq offers tailored Microsoft Copilot Studio agent development, starting with process evaluation and security assessment for safe AI use. It includes detailed design, integration, and documentation, followed by deployment as a proof of concept or full solution. Ongoing support ensures stable operation, monitoring, and continuous optimization for business needs.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/signalalliance.sa_global_secure_access-475f3b34-423f-4502-95ee-d958944da314/image0_SignalAllianceLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/signalalliance.sa_global_secure_access" target="_blank" rel="noopener"&gt;Microsoft Entra - Global Secure Access Engagement&lt;/A&gt;: Signal Alliance Consulting enhances Microsoft 365 security with zero trust network access via Global Secure Access. They offer risk assessments, vulnerability audits, optimized traffic routing, and seamless VPN-less access. Their expert team provides tailored deployment, pilot testing, and training to secure remote workforces and protect cloud assets effectively.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/nebulan1597762163871.proposal-c-64861d27-e8d3-4f03-8585-f2832b06fba7/image2_partnercenter.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nebulan1597762163871.proposal-c" target="_blank" rel="noopener"&gt;Nebulan Commercial Proposal Agent&lt;/A&gt;: Nebulan's service automates the creation of business proposals using AI integrated into Microsoft 365 Copilot to reduce errors and improve the quality and consistency of documents. It supports multiple languages; integrates with CRM systems; and optimizes B2B sales teams, consultancies and agencies with templates and custom configurations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/scc.scc_cloud_security_pathfinder-93d4d5ab-dd7a-4bf4-9bbf-e732a4b0ed54/image1_SCC.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/scc.scc_cloud_security_pathfinder" target="_blank" rel="noopener"&gt;SCC Cloud Security Pathfinder&lt;/A&gt;: SCC’s Cloud Security Pathfinder engagement will assess and enhance your Azure security posture. Leveraging Microsoft Defender tools, it identifies risks, misconfigurations, and vulnerabilities across hybrid and multi-cloud environments, providing tailored recommendations and a clear roadmap to strengthen cloud security and compliance effectively.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/incrementptyltd1637494276783.secure_copilot_engagements-36c1d92d-588b-4274-9f43-68f3c53a85f9/image2_IncrementSquareLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/incrementptyltd1637494276783.secure_copilot_engagements" target="_blank" rel="noopener"&gt;Secure Microsoft 365 Copilot Engagements&lt;/A&gt;: Increment's Secure Microsoft 365 Copilot Engagements help organizations safely adopt Microsoft 365 Copilot and AI by addressing data security, governance, and sensitive information risks. They offer two paths: a five-week Readiness Assessment for strategic planning and a six-week Accelerated Controls service for rapid implementation of security measures and AI usage controls.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/telekomdeutschlandgmbhbonn1632996783690.threat_protection_envisioning_workshop-68330063-7780-4160-8789-59da7e5ed257/image2_Telekom.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/telekomdeutschlandgmbhbonn1632996783690.threat_protection_envisioning_workshop" target="_blank" rel="noopener"&gt;Threat Protection Envisioning Workshop&lt;/A&gt;: Telekom Deutschland's&amp;nbsp;Threat Protection Envisioning Workshop helps organizations detect, prioritize, and remediate threats across Microsoft cloud and on-premises environments. With Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Entra ID Protection, it provides visibility, actionable insights, prioritized recommendations, and a roadmap for modern security architectures.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/alescaproductividadsderldecv.transforma365-fc370ed8-fb5d-4ca3-9138-85a0978e327b/image1_350.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/alescaproductividadsderldecv.transforma365" target="_blank" rel="noopener"&gt;Transforma 365 - Strategic Adoption of Microsoft 365 and Copilot&lt;/A&gt;: Transforma 365 is an end-to-end service that drives strategic adoption of Microsoft 365 and Microsoft Copilot, improving productivity, collaboration, and automation. It offers continuous diagnostics, strategy, implementation, training, and measurement, helping organizations maximize technological value and move toward a work culture based on data and artificial intelligence.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/avtex_solutions.ttecdigital_cortentacx-931ec673-e873-4675-9a85-fb4e69f8ddca/image0_TTECDigitalBlackMSFTMarketplaceLogo.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/avtex_solutions.ttecdigital_cortentacx" target="_blank" rel="noopener"&gt;TTEC Digital CortentaCX&lt;/A&gt;: CortentaCX by TTEC Digital is an AI-powered Open CX platform that enhances customer experience by integrating with existing systems. Built on Azure, it offers unified intelligence, omnichannel support, and data privacy. It reduces costs, technical debt, and vendor dependency while providing scalable, customizable customer service solutions.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding: 15px;"&gt;&lt;IMG src="https://catalogartifact.azureedge.net/publicartifacts/accigo1763389057334.accigo_vibe_platform-32cd7c90-4184-4b37-becf-90c490b29041/image3_AccigoMSMarkeplace.png" alt="" width="100" height="100" /&gt;&lt;/td&gt;&lt;td style="padding: 15px;"&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/accigo1763389057334.accigo_vibe_platform" target="_blank" rel="noopener"&gt;Vibe Coding, Delivered Securely - From Idea to Azure in an Afternoon&lt;/A&gt;: Accigo’s Internal Developer Platform integrates GitHub Enterprise and Azure, enabling AI-assisted app development with automated security, testing, and deployment. It offers preconfigured templates, built-in authentication, secrets management, and full observability. This platform accelerates secure, production-ready app delivery, reduces operational costs, and ensures consistent quality and governance.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 15%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;&lt;EM&gt;Contact our partners&lt;/EM&gt;&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.applibra|AID.al_processing_charge|PAPPID.0e4793f4-e122-422f-a7f6-c2ba07d4c1f1" target="_blank" rel="noopener"&gt;AL Processing Charge&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/marketplace/apps/powerstackscorporation1641419080242.appstoreforintune" target="_blank" rel="noopener"&gt;App Store for Microsoft Intune&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/arysontechnologiesprivatelimited1738223813126.olm-to-csv-migrator" target="_blank" rel="noopener"&gt;Aryson OLM to CSV Migrator&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/arysontechnologiesprivatelimited1738223813126.zoho-to-office-365-migration-tool" target="_blank" rel="noopener"&gt;Aryson Zoho to Office 365 Migration Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/applied_systems-546667.asa-studio26" target="_blank" rel="noopener"&gt;aSa Studio 26&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/product/web-apps/PUBID.wsb_solutions|AID.auto_add_item_lines|PAPPID.0fe21e00-2ff6-40a5-9562-28443a5b7985" target="_blank" rel="noopener"&gt;Auto Add Item Lines&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/product/web-apps/sbs-group.axiointercompanytransactionsagent" target="_blank" rel="noopener"&gt;AXIO Intercompany Transactions Agent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/inbest_cloud.inbest-azure-migration-assessment" target="_blank" rel="noopener"&gt;Azure Migration Readiness Assessment&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/consultoreseingenierosconseinca1591899966939.sol_0011_vzla" target="_blank" rel="noopener"&gt;BanIA - From Chatbot to Intelligent Companion&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/leverxinc1667235792796.bi_modernization_microsoft_fabric" target="_blank" rel="noopener"&gt;BI Modernization on Microsoft Fabric: 1-Hour Readiness Assessment&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bitrecover.eml-attachment-extractor" target="_blank" rel="noopener"&gt;BitRecover EML Attachment Extractor Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bitrecover.incredimail-to-outlook-pst" target="_blank" rel="noopener"&gt;BitRecover IncrediMail to Outlook PST Converter Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bitrecover.incredimail-to-pdf" target="_blank" rel="noopener"&gt;BitRecover IncrediMail to PDF Converter Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bluevoyant1583844909747.azure-sentinel-solution-bv-claudecompliance" target="_blank" rel="noopener"&gt;BlueVoyant Anthropic Claude Compliance&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.insideaxgmbh1608541911558|AID.iax_bmd|PAPPID.8a54d91b-c276-45ef-811d-559d2afdc8c2" target="_blank" rel="noopener"&gt;BMD Interface&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/caputechinc1626377911079.capu-event-manager" target="_blank" rel="noopener"&gt;CapuWare Event Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/cigatisolutionspvtltd.cigati_godaddy_to_gmail_migration_tool" target="_blank" rel="noopener"&gt;Cigati GoDaddy to Gmail Migration Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/cigatisolutionspvtltd.godaddy_to_zoho_mail_migration" target="_blank" rel="noopener"&gt;Cigati GoDaddy to Zoho Mail Migration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/cigatisolutionspvtltd.cigati_hostgator_to_office_365_migration_tool" target="_blank" rel="noopener"&gt;Cigati HostGator to Office 365 Migration Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/cigatisolutionspvtltd.cigati_imap_to_google_workspace_migration_tool" target="_blank" rel="noopener"&gt;Cigati IMAP to Google Workspace Migration Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/product/web-apps/PUBID.randgroupllc1592867637727|AID.complyai|PAPPID.3393d8f1-30ce-4ccd-bc8c-ff97f0c3490a" target="_blank" rel="noopener"&gt;Compliance Sentinel&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.continia365|AID.continia-document-capture-fr|PAPPID.7dbb2ee2-8950-407b-9aa9-e9c865260ce8" target="_blank" rel="noopener"&gt;Continia Document Capture - French e-Invoicing&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.continia365|AID.continia-document-output-fr|PAPPID.8c1cb0a1-311a-430e-a55e-3b3c401bb2cf" target="_blank" rel="noopener"&gt;Continia Document Output - French e-Invoicing&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/bafflesoltechnologies1618950983678.customer_aging_dashboard" target="_blank" rel="noopener"&gt;Customer Aging Dashboard&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/datanovaconsultingfzco1776859374985.datanova_managedserv" target="_blank" rel="noopener"&gt;DataNova Managed Services&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/marketplace/apps/drssoftech.ost_to_imap_migration_tool" target="_blank" rel="noopener"&gt;DRS Softech OST to IMAP Migration Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/drssoftech.ost_to_thunderbird_converter" target="_blank" rel="noopener"&gt;DRS Softech OST to Thunderbird Converter&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/eleirisaioy1738146675982.id002" target="_blank" rel="noopener"&gt;Eleiris&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/misterkrabso.fanarex" target="_blank" rel="noopener"&gt;Fanarex - ERP for GCC Cleaning Companies&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/finifi.finifio2c" target="_blank" rel="noopener"&gt;Finifi AI for Order-to-Cash&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/ilogicdirodonofabrizio1775680349860.fpe_index" target="_blank" rel="noopener"&gt;FPE Index&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.fusion5|AID.f5_dyn365bc_businesshub|PAPPID.4c39fcd5-a965-45dd-9eea-d8063fbc7357" target="_blank" rel="noopener"&gt;Fusion5 Business Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.fusion5|AID.f5_dyn365bc_businesshub-aunz|PAPPID.2acfa4db-e8b9-4bc7-99f9-4f7994e4b2b6" target="_blank" rel="noopener"&gt;Fusion5 Business Hub for Australia/New Zealand&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/r3llc1765678745729.gcch_licensing" target="_blank" rel="noopener"&gt;GCC High Licensing: 1-Day Enablement&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/creosparkconsultingservicesinc.gcdocs_to_sharepoint_online_migration_assessment" target="_blank" rel="noopener"&gt;GCDocs to SharePoint Online Migration Assessment and Roadmap&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/insourceservicesinc1781712491520.insourcelighthouse" target="_blank" rel="noopener"&gt;Insource Services - Azure Managed Services&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/intility-csp.intility_landing_zone" target="_blank" rel="noopener"&gt;Intility Landing Zone&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/rishabhsoftwareprivatelimited1680521027497.rs-intranet-modernization-briefing" target="_blank" rel="noopener"&gt;Intranet Modernization with Microsoft 365: 1-Hour Briefing&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.builddynamicsptyltd1736891494025|AID.bd_licensemanagement|PAPPID.a3f6f58d-d09f-4b78-b200-3360659cf869" target="_blank" rel="noopener"&gt;License Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/litsservices1588138020299.lits_equipment_rental_system" target="_blank" rel="noopener"&gt;LITS Equipment Rental System&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.lookiesrl1652434820977|AID.lookie_close_as_invoice|PAPPID.2abf85a9-7d14-4a58-9a2e-71566fcc981d" target="_blank" rel="noopener"&gt;LOOKie Close as Invoice&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/marketplace/apps/macsonik.apple_mail_converter_tool" target="_blank" rel="noopener"&gt;MacSonik Apple Mail Converter Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/macsonik.gmail_to_google_workspace_migration_for_mac" target="_blank" rel="noopener"&gt;MacSonik Gmail to Google Workspace Migration for Mac&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.moore-insight-apps|AID.key-vault-link|PAPPID.96f7db86-c755-4819-b2c0-ff6e2f8ad214" target="_blank" rel="noopener"&gt;Key Vault Link&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/crowcanyonsystemsinc1772249801093.nitro_help_desk_for_it" target="_blank" rel="noopener"&gt;NITRO Help Desk for IT&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nordcloud-4356840.nc_azurelocal_pes" target="_blank" rel="noopener"&gt;Nordcloud's Managed Service for Azure Local&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/nordcloud-4356840.nc_entraid_pes" target="_blank" rel="noopener"&gt;Nordcloud's Managed Service for Microsoft Entra ID&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/product/web-apps/devsoftsolutions.onplana-migration-tool" target="_blank" rel="noopener"&gt;Onplana Migration Tool for Microsoft Project&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.powerblox1677140592963|AID.pbl-advanced-project-mgmt|PAPPID.14f69e86-222c-4be8-95b1-e13533618acb" target="_blank" rel="noopener"&gt;Powerblox Advanced Project Administration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/marketplace/apps/recoverytools.zimbra-to-pst" target="_blank" rel="noopener"&gt;RecoveryTools for Zimbra to PST Converter Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/recoverytools.zimbra-to-zoho-mail" target="_blank" rel="noopener"&gt;RecoveryTools for Zimbra to Zoho Mail Converter Tool&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/cloudsource1664978597240.cs-tech-7" target="_blank" rel="noopener"&gt;Regulate365: Casework&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/cloudsource1664978597240.cs-tech-6" target="_blank" rel="noopener"&gt;Regulate365: Inspections&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/cloudsource1664978597240.cs-tech-8" target="_blank" rel="noopener"&gt;Regulate365: Payments&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/cloudsource1664978597240.cs-tech-5" target="_blank" rel="noopener"&gt;Regulate365: Registrations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.blueridgeitfze|AID.re365propertylease|PAPPID.0d315d7e-99d5-4269-b1dd-4e1ba08706f2" target="_blank" rel="noopener"&gt;RidgeEstates 365 Property Lease Management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/agic_technology_1016574.risk_compliance_data_security" target="_blank" rel="noopener"&gt;Risk, Compliance &amp;amp; Data Security Assessment&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.rocket365|AID.rocket365_also_marketplace|PAPPID.63d6974b-e474-4b1c-a542-fcc56bfc9fd3" target="_blank" rel="noopener"&gt;rocket365 ALSO Marketplace&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://marketplace.microsoft.com/marketplace/apps/tialto.tialto_contact_me" target="_blank" rel="noopener"&gt;tialto&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/vosssolutions1620996719814.voss-rooms" target="_blank" rel="noopener"&gt;VOSS Automation and Analytics for Microsoft Teams Rooms&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/consulting-services/agic_technology_1016574.vapt" target="_blank" rel="noopener"&gt;Vulnerability Assessment &amp;amp; Penetration Test&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/TYPE.connect|PUBID.wiboo1757693543169|AID.dynamic_wiboo|PAPPID.8ec7eaaa-b829-4492-aedf-b00917df6ef5" target="_blank" rel="noopener"&gt;Wiboo CPQ for Microsoft Dynamics 365&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/xinu-tech.press_offer_id" target="_blank" rel="noopener"&gt;XINU Press&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/product/web-apps/PUBID.scapta1708358347670|AID.xpr365-rest-api-client|PAPPID.e63fa7b6-7a06-4680-9ace-e53acc9d1bb3" target="_blank" rel="noopener"&gt;XPR365 Rest API Client&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/zerofoxinc1695922129370.zerofox-threat-intel-sentinel-connector" target="_blank" rel="noopener"&gt;ZeroFox Threat Intelligence Connector&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://marketplace.microsoft.com/marketplace/apps/whizhacktechnologiespltd1665136436408.trace-v231" target="_blank" rel="noopener"&gt;ZeroHack TRACE Sensor&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;This content was generated by Microsoft Azure OpenAI, then revised by human editors.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 13:42:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/marketplace-blog/new-in-microsoft-marketplace-offers-published-june-23-24-2026/ba-p/4522363</guid>
      <dc:creator>Nikhil_Viswanathan</dc:creator>
      <dc:date>2026-07-23T13:42:11Z</dc:date>
    </item>
    <item>
      <title>Should You Use the New Microsoft Entra Tenant Governance or Azure Lighthouse? (part 3 of 3)</title>
      <link>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/should-you-use-the-new-microsoft-entra-tenant-governance-or/ba-p/4532297</link>
      <description>&lt;P&gt;In&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/implementing-azure-lighthouse-a-technical-guide-for-service-providers-and-enterp/4490592" target="_blank" rel="noopener"&gt;Part 1&lt;/A&gt;&amp;nbsp;we built Azure Lighthouse the technical way. In&amp;nbsp;Part 2,&amp;nbsp;&lt;EM&gt;"&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/azure-lighthouse-bring-your-partner-in-without-letting-their-identities-in-part-/4529852" target="_blank" rel="noopener" data-lia-auto-title="Bring Your Partner In, Without Letting Their Identities In" data-lia-auto-title-active="0"&gt;Bring Your Partner In, Without Letting Their Identities In&lt;/A&gt;,"&lt;/EM&gt; we made the security case for it: let a service provider operate a customer's Azure resources without creating any identity in the customer's tenant.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This third part introduces another, newly available delegation model&amp;nbsp;&lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;&amp;nbsp;and helps you to answer the question:&amp;nbsp;&lt;EM&gt;which one do I use, and when?&lt;/EM&gt;. If you already know Lighthouse, you have everything you need to follow along - If not, catch up on the previous two articles. While most of the focus will be on Microsoft Entra Tenant Governance, we will compare and contrast it with Azure Lighthouse.&lt;/P&gt;
&lt;P&gt;There's one idea that makes the whole comparison click:&amp;nbsp;&lt;STRONG&gt;the two models project access in opposite directions.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-One" class="lia-anchor"&gt;&lt;/a&gt;1. Azure Lighthouse, and its boundary&lt;/H2&gt;
&lt;P&gt;As a brief refresher, &lt;SPAN class="lia-text-color-21"&gt;Azure&lt;/SPAN&gt; Lighthouse lets a service provider manage a customer's Azure resources (subscriptions and resource groups) from the provider's own tenant. The provider's users never get an account in the customer's directory and never become guests there; instead, the customer's subscriptions and resource groups are &lt;EM&gt;delegated&lt;/EM&gt;&amp;nbsp;to the provider through Azure Resource Manager, and the provider operates them with their&amp;nbsp;home credentials&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/architecture" target="_blank" rel="noopener"&gt;Azure Lighthouse architecture&lt;/A&gt;). No identity sprawl, no extra license, no charge (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/overview" target="_blank" rel="noopener"&gt;Azure Lighthouse overview&lt;/A&gt;).&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Lighthouse is&amp;nbsp;scoped to the Azure Resource Manager control plane. It delegates&amp;nbsp;&lt;EM&gt;resources from subscriptions or resource groups such as&lt;/EM&gt; virtual machines, storage, networking, policy, and Sentinel workspaces. It does not grant Microsoft Entra directory roles, it does not reach resource data planes such as Storage blob data or Key Vault secrets, and it doesn't reach Microsoft 365 (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/cross-tenant-management-experience" target="_blank" rel="noopener"&gt;cross-tenant management experience&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;But it leaves a real question open. What happens when the partner (or an enterprise with multiple tenants) legitimately needs access to the directory, to read identity configuration, run security operations, administer users, or govern identities, and not just the resource estate? Lighthouse, by design, can't take you there. That's the gap the second model fills.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Two" class="lia-anchor"&gt;&lt;/a&gt;2. Two directions of projection&lt;/H2&gt;
&lt;P&gt;The easiest way to keep the two models straight is to consider the following:&lt;/P&gt;
&lt;img&gt;Fig 1 - Access delegation direction of trust&lt;/img&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Lighthouse projects the customer's&amp;nbsp;&lt;EM&gt;resources up&lt;/EM&gt;&amp;nbsp;into the provider's tenant.&lt;/STRONG&gt;&amp;nbsp;The provider manages those resources from its&amp;nbsp;own&amp;nbsp;context. The customer's subscription is, in effect, presented inside the provider's Azure portal.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra Tenant Governance projects the provider's&amp;nbsp;&lt;EM&gt;identity down&lt;/EM&gt;&amp;nbsp;into the customer's tenant.&lt;/STRONG&gt;&amp;nbsp;A principal from the provider tenant becomes usable&amp;nbsp;inside the customer, and a provider&amp;nbsp;user or service principal&amp;nbsp;uses it there to do the work.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each delegate cross-tenant access without local accounts, but the&amp;nbsp;&lt;EM&gt;thing that moves&lt;/EM&gt;&amp;nbsp;is opposite. And&amp;nbsp;who moves strongly shapes whose rules apply.&amp;nbsp;When the customer's resources come&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;&amp;nbsp;to the provider, the work happens in the provider's context. When the provider's identity goes&amp;nbsp;&lt;EM&gt;down&lt;/EM&gt;&amp;nbsp;to the customer, the work happens in the customer's context.&lt;/P&gt;
&lt;P&gt;Think of the word "projection" as a way to reason about&amp;nbsp;trust direction, not a literal claim that objects are copied between tenants. Lighthouse is delegated management&amp;nbsp;&lt;EM&gt;from the provider's context&lt;/EM&gt;; Tenant Governance creates&amp;nbsp;&lt;EM&gt;a governed principal in the customer's context&lt;/EM&gt; that can hold directory roles&amp;nbsp;and&amp;nbsp;Azure RBAC.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Three" class="lia-anchor"&gt;&lt;/a&gt;3. What is Microsoft Entra Tenant Governance?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra Tenant Governance&amp;nbsp;is the capability that lets one tenant securely administer another. The connection between a specific pair of tenants is called a&amp;nbsp;governance relationship: a&amp;nbsp;&lt;EM&gt;directional&lt;/EM&gt;&amp;nbsp;link in which one tenant, the&amp;nbsp;governing&amp;nbsp;tenant (the provider), administers another, the&amp;nbsp;governed&amp;nbsp;tenant (the customer) (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-set-up-governance-relationship" target="_blank" rel="noopener"&gt;set up a governance relationship&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;Throughout, this article is written from the&amp;nbsp;provider's&amp;nbsp;vantage point: when it says&amp;nbsp;&lt;EM&gt;you&lt;/EM&gt;, it means the provider (governing) side, and the other tenant is always referred to explicitly as&amp;nbsp;&lt;EM&gt;the customer&lt;/EM&gt;. The topics discussed here apply equally to Enterprises needing to manage many of their own tenants as well as Service Providers who manage many customer tenants.&lt;/P&gt;
&lt;P&gt;You set it up in two steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;policy template&lt;/STRONG&gt;&amp;nbsp;in the provider tenant that declares&amp;nbsp;&lt;EM&gt;which principal&lt;/EM&gt;&amp;nbsp;will be projected and&amp;nbsp;&lt;EM&gt;which Entra roles&lt;/EM&gt; it should receive. Note that RBAC assignments are not part of the governance relationship and must be completed by the customer in their tenant.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;handshake&lt;/STRONG&gt;&amp;nbsp;between the two tenants that establishes the trust boundary and provisions the access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Now let’s dive into the details:&amp;nbsp;&lt;EM&gt;what gets projected&lt;/EM&gt;, and&amp;nbsp;&lt;EM&gt;how it gets its powers&lt;/EM&gt;.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Four" class="lia-anchor"&gt;&lt;/a&gt;4. What actually gets projected: one proxy principal&lt;/H2&gt;
&lt;P&gt;In the provider tenant you start with something completely ordinary, a&amp;nbsp;security group&amp;nbsp;(say, your "Cloud Operators" group), or a custom&amp;nbsp;multitenant application. When you form the governance relationship, a&amp;nbsp;proxy of that principal is created in the customer tenant:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;security group&lt;/STRONG&gt;&amp;nbsp;is projected in as a&amp;nbsp;&lt;STRONG&gt;remote tenant group&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;An&amp;nbsp;&lt;STRONG&gt;application&lt;/STRONG&gt;&amp;nbsp;(a custom multitenant app) is projected in as a&amp;nbsp;service principal, when the relationship is established,&amp;nbsp;Tenant Governance automatically creates a service principal with the same permissions in the customer tenant&amp;nbsp;(no manual step on the customer's side):&amp;nbsp;&lt;EM&gt;"Tenant Governance creates a service principal with the same permissions in the governed tenant"&lt;/EM&gt; (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-SPOILER label="Note"&gt;
&lt;P&gt;Using a multitenant app registration with Tenant Governance requires an Entra ID Governance license.&lt;/P&gt;
&lt;/LI-SPOILER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 2 - Provider principal is projected into the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s important to keep two things straight, neither&amp;nbsp;is a local account or a guest:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;The proxy&lt;/STRONG&gt;, the remote tenant group (or, for an app, the service principal), is a&amp;nbsp;new principal created in the customer tenant by the relationship. It is&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a copy of the provider's group,&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a local group created in the customer, and&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;a guest. It exists only because the relationship projects it, and it is what the provider grants roles to.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The people and apps that use it&lt;/STRONG&gt;, the provider's&amp;nbsp;users and service principals, stay in the&amp;nbsp;provider&amp;nbsp;tenant. They never receive a member account or a guest invitation in the customer; they reach the customer&amp;nbsp;&lt;EM&gt;through&lt;/EM&gt;&amp;nbsp;the proxy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Here is what that provider&amp;nbsp;user or service principal&amp;nbsp;is and isn't, from the customer's point of view:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;The provider&amp;nbsp;user or service principal&amp;nbsp;is&amp;nbsp;NOT…&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;…it&amp;nbsp;IS…&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A local member account created in the customer's directory&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;An identity that stays in the&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;tenant and authenticates with&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;credentials&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A B2B guest invited into the customer&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Reachable only&amp;nbsp;&lt;STRONG&gt;through the projected proxy&lt;/STRONG&gt;, a signed-in user shows in the customer's logs as the provider tenant's name +&amp;nbsp;Technician&amp;nbsp;(e.g.&amp;nbsp;Contoso Technician)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A standing, permanent object listed among the customer's users&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Present only as a&amp;nbsp;&lt;STRONG&gt;governed session or principal&lt;/STRONG&gt;, scoped by the relationship and revocable by the customer&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;To work in the customer tenant, a provider user opens a supported admin portal (Entra or Azure) and&amp;nbsp;appends the customer's tenant ID, for example&amp;nbsp;https://entra.microsoft.com/{customer-tenant-id}, then&amp;nbsp;signs in with their provider-tenant credentials. The customer's logs then show them a directory display name of&amp;nbsp;user_{object-id}&amp;nbsp;(the provider object ID without dashes), and, in&amp;nbsp;sign-in and audit logs, the&amp;nbsp;provider tenant's name followed by&amp;nbsp;Technician, so for a provider tenant named Contoso the entry reads&amp;nbsp;Contoso Technician&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;). No local account, no guest object, the resource-plane property Lighthouse provides, now on the directory plane (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;A note on the two projection mechanics, because they differ in a way worth understanding. A&amp;nbsp;&lt;STRONG&gt;group&lt;/STRONG&gt;&amp;nbsp;projects as a&amp;nbsp;&lt;EM&gt;remote tenant group&lt;/EM&gt;, a cross-tenant reference back to the provider's group, with no new local membership stored in the customer. An&amp;nbsp;&lt;STRONG&gt;application&lt;/STRONG&gt;&amp;nbsp;projects as a&amp;nbsp;&lt;EM&gt;real service principal&lt;/EM&gt; that is actually created in the customer with the consented permissions. Same idea, a governed proxy of a provider principal, but a group is a reference, while an app is an instantiated object.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Five" class="lia-anchor"&gt;&lt;/a&gt;5. How the proxy gets its powers: roles attach to the one principal&lt;/H2&gt;
&lt;P&gt;The proxy is&amp;nbsp;one principal. You don't create separate identities for "directory access" and "resource access." Instead, you&amp;nbsp;grant roles to that single proxy, and the roles can come from&amp;nbsp;two different planes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory roles&lt;/STRONG&gt;&amp;nbsp;govern the customer's Microsoft Entra directory. Think of&amp;nbsp;well-known&amp;nbsp;ones such as&amp;nbsp;Global Reader&amp;nbsp;(read-only across the directory),&amp;nbsp;Global&lt;STRONG&gt; &lt;/STRONG&gt;Administrator, or&amp;nbsp;User Administrator, selected as built-in roles in the policy template (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure RBAC roles&lt;/STRONG&gt; govern the customer's Azure resources. Think of the familiar Reader, Contributor, or a service-specific roles like Virtual Machine Contributor, assigned to the remote tenant group at a subscription or resource-group scope. This is not done as part of the governance relationship as the Entra directory role is. This must be assigned after the relationship is established likely by a privileged customer admin.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The bridge from directory to resources is the remote tenant group itself: because the projected group can be referenced by Azure RBAC, the same proxy that holds&amp;nbsp;Global Reader&amp;nbsp;in the directory can&amp;nbsp;&lt;EM&gt;also&lt;/EM&gt; hold&amp;nbsp;Reader&amp;nbsp;or&amp;nbsp;Contributor&amp;nbsp;on a resource group. Critically, these are&amp;nbsp;not separate identities, they are both&amp;nbsp;roles held by the one remote tenant group, as the diagram above shows. And the directory role grants&amp;nbsp;no&amp;nbsp;Azure access on its own; the resource rights come entirely from the explicit RBAC assignment you choose.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That single design choice, &lt;EM&gt;roles branch off one proxy&lt;/EM&gt;, is what lets one projected principal span both planes: the same remote tenant group can hold a directory role&amp;nbsp;and&amp;nbsp;a separate, explicit Azure RBAC grant, without ever issuing a local account.&lt;/P&gt;
&lt;P&gt;What do these identities actually look like in the customer tenant? The only place you will see the security group is in the governance relationship. You will not find it among your other Entra groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 3 - Governance relationship shows the projected principal in the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 4 - The projected principal does not appear in the customer tenant security groups&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For RBAC purposes, you can find the proxy security group under resource Access Control (IAM) as a foreign group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 5 - The projected principal is available for RBAC assignments as a foreign group&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Six" class="lia-anchor"&gt;&lt;/a&gt;6. The building blocks, and how they depend on each other&lt;/H2&gt;
&lt;P&gt;Now that the concept is in place, here's the assembly order. Each block depends on the one before it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 6 - Sequence of creating a governance relationship&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;A role-assignable security group&lt;/STRONG&gt;&amp;nbsp;in the provider tenant, the principal you intend to project.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A policy template&lt;/STRONG&gt;&amp;nbsp;that selects which directory roles that group should receive when projected (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A governance relationship&lt;/STRONG&gt;, established by a&amp;nbsp;handshake. In the standard three-step flow the customer&amp;nbsp;&lt;EM&gt;invites&lt;/EM&gt;, the provider&amp;nbsp;&lt;EM&gt;requests&lt;/EM&gt;&amp;nbsp;(carrying the template), and the customer&amp;nbsp;&lt;EM&gt;accepts&lt;/EM&gt;; a streamlined&amp;nbsp;two-step&amp;nbsp;flow (request → accept) applies when the two tenants already share a qualifying signal, such as a billing relationship or an existing governance relationship. At acceptance, the role assignments are provisioned in the customer (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-set-up-governance-relationship" target="_blank" rel="noopener"&gt;set up a governance relationship&lt;/A&gt;). The template's role set is&amp;nbsp;projected&amp;nbsp;onto the relationship, so later template edits require a fresh request and re-approval, the customer always gets to review what changes.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The projected proxy plus its role assignments&lt;/STRONG&gt;&amp;nbsp;in the customer, the remote tenant group (or service principal), now holding the directory and/or Azure RBAC roles you granted.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Under the hood:&lt;/STRONG&gt;&amp;nbsp;this cross-tenant delegation is powered by&amp;nbsp;granular delegated admin privileges (GDAP), the same delegation technology behind Partner Center (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;). You don't configure it directly; the relationship and the template do it for you. That's all you need to know about the plumbing.&lt;/P&gt;
&lt;P&gt;The whole flow is also scriptable through the&amp;nbsp;Microsoft Graph&amp;nbsp;Tenant Governance APIs (&lt;A href="https://learn.microsoft.com/en-us/graph/api/resources/tenantgovernanceservices-tenantgovernance-overview?view=graph-rest-beta" target="_blank" rel="noopener"&gt;API overview&lt;/A&gt;), and a default template can bring&amp;nbsp;new add-on tenants&amp;nbsp;under governance automatically at creation (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/deployment-guide#configure-a-default-policy-template-optional" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;).&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Seven" class="lia-anchor"&gt;&lt;/a&gt;7. Key Features&lt;/H2&gt;
&lt;P&gt;Because the proxy can hold both directory roles and Azure RBAC, Tenant Governance unlocks delegated administration across the&amp;nbsp;&lt;EM&gt;entire&lt;/EM&gt;&amp;nbsp;surface a partner might legitimately need:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory administration&lt;/STRONG&gt;, read or manage the customer's Microsoft Entra directory with least-privileged built-in roles, using home credentials, no local accounts.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity governance&lt;/STRONG&gt;, run access reviews, entitlement management, and lifecycle workflows across many customer tenants from one place.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security operations&lt;/STRONG&gt;, operate security and compliance tooling centrally. Microsoft Defender XDR and Microsoft Sentinel multitenant management for MSSPs is&amp;nbsp;one&amp;nbsp;prominent example built on this model (&lt;A href="https://learn.microsoft.com/en-us/unified-secops/governance-relationships" target="_blank" rel="noopener"&gt;governance relationships for unified SecOps&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure resource management&lt;/STRONG&gt;, the remote tenant group can carry Azure RBAC for any Azure service, exactly the way a local group would. That covers the management (control) plane only; neither model delegates the resource data plane (for example, blob data or Key Vault secrets), so those operations still require an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Application management&lt;/STRONG&gt;, project a custom multitenant app as a service principal with consistent, least-privileged permissions across tenants (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/governance-policy-templates" target="_blank" rel="noopener"&gt;governance policy templates&lt;/A&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The provider's&amp;nbsp;users and service principals&amp;nbsp;use their&amp;nbsp;provider-tenant identities, and no local or B2B account is ever planted in the customer. The one object the customer does gain is in the&amp;nbsp;application&amp;nbsp;case, a governed&amp;nbsp;service principal&amp;nbsp;of the projected app, created and maintained through the relationship rather than as a standing local login.&lt;/P&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Eight" class="lia-anchor"&gt;&lt;/a&gt;8. Comparing Tenant Governance with Azure Lighthouse&lt;/H2&gt;
&lt;P&gt;Now that both models are understood, the comparison is straightforward. They operate on different planes and point in different directions.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Dimension&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Lighthouse&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Direction of projection&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;resources → provider&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Provider&amp;nbsp;&lt;STRONG&gt;identity → customer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Where the provider identity operates&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;From the&amp;nbsp;&lt;STRONG&gt;provider&lt;/STRONG&gt;&amp;nbsp;tenant (customer resources projected up; no customer sign-in)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;In the customer&lt;/STRONG&gt;&amp;nbsp;tenant, authenticated by the provider home tenant — as&amp;nbsp;{Provider} Technician&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Planes reached&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure resource (ARM) plane only&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Directory plane&amp;nbsp;&lt;EM&gt;and&lt;/EM&gt;&amp;nbsp;Azure resource plane&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Data-plane access (e.g., blob data, Key Vault secrets)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Not supported&lt;/STRONG&gt; (control/ARM plane only)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Not supported&lt;/STRONG&gt; (the proxy can hold a DataActions role, but cannot obtain a data-plane token)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Identity footprint in customer&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;None&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;A&amp;nbsp;&lt;STRONG&gt;projected proxy&lt;/STRONG&gt;&amp;nbsp;principal, no local or guest object&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Conditional Access&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Only the&amp;nbsp;&lt;STRONG&gt;provider's&lt;/STRONG&gt;&amp;nbsp;policies apply (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/recommended-security-practices" target="_blank" rel="noopener"&gt;security practices&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;customer's&lt;/STRONG&gt;&amp;nbsp;policies apply, the customer is the resource tenant for the technician's sign-in (&lt;EM&gt;lab-verified; see below&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Where the privileged assignment lives&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Provider&lt;/STRONG&gt;&amp;nbsp;tenant (JIT approvers in the provider) (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/create-eligible-authorizations" target="_blank" rel="noopener"&gt;eligible authorizations&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Customer&lt;/STRONG&gt;&amp;nbsp;tenant (the role assignment is owned customer-side)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Audit of provider actions&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;Activity Log&lt;/STRONG&gt;&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/view-service-provider-activity" target="_blank" rel="noopener"&gt;view activity&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Customer&amp;nbsp;&lt;STRONG&gt;audit log&lt;/STRONG&gt;&amp;nbsp;records the provider user’s&amp;nbsp;&lt;EM&gt;actions&lt;/EM&gt;; the&amp;nbsp;&lt;STRONG&gt;authentication sign-in is recorded provider-side,&lt;/STRONG&gt; it appears in the customer's sign-in log only when the customer's CA fires&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Role types&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure built-in roles only, &lt;STRONG&gt;no custom roles&lt;/STRONG&gt;;&amp;nbsp;&lt;STRONG&gt;Owner&lt;/STRONG&gt;&amp;nbsp;and roles with&amp;nbsp;&lt;STRONG&gt;DataActions&lt;/STRONG&gt;&amp;nbsp;excluded, and&amp;nbsp;Microsoft.Authorization/*&amp;nbsp;writes excluded except&amp;nbsp;&lt;STRONG&gt;User Access Administrator&lt;/STRONG&gt;&amp;nbsp;for managed-identity assignments (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/tenants-users-roles" target="_blank" rel="noopener"&gt;role rules&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Directory roles&amp;nbsp;and&amp;nbsp;Azure RBAC (including&amp;nbsp;&lt;STRONG&gt;custom&lt;/STRONG&gt;&amp;nbsp;RBAC) on the proxy&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Setup&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;ARM template / Marketplace offer (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/onboard-customer" target="_blank" rel="noopener"&gt;onboard&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Relationship handshake (invitation → request → acceptance)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Revocation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Remove the delegation, either party (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/remove-delegation" target="_blank" rel="noopener"&gt;remove&lt;/A&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Terminate the relationship, either party&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Operational view&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Single pane of glass&lt;/STRONG&gt;, every delegated customer's resources surface in the provider's&amp;nbsp;&lt;STRONG&gt;own&lt;/STRONG&gt;&amp;nbsp;portal&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Per-customer&lt;/STRONG&gt;, the admin signs in to each customer tenant individually&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Best for&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Scaled&amp;nbsp;&lt;STRONG&gt;Azure resource&lt;/STRONG&gt;&amp;nbsp;operations&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Directory / identity / security&lt;/STRONG&gt;&amp;nbsp;delegation&amp;nbsp;plus&amp;nbsp;resources&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;The sign-in, Conditional Access, footprint, and audit rows describe &lt;STRONG&gt;the&amp;nbsp;human delegated-administration&lt;/STRONG&gt;&amp;nbsp;path (a projected group). In the&amp;nbsp;application&amp;nbsp;case the customer instead gets a governed&amp;nbsp;service principal, so those rows read differently.&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Direction of projection, the root cause. &lt;/STRONG&gt;Everything else in the table is a consequence of this one row. Lighthouse brings the customer's&amp;nbsp;&lt;EM&gt;resources &lt;/EM&gt;up to the provider; Tenant Governance places a governed proxy of the&amp;nbsp;&lt;EM&gt;provider's identity&lt;/EM&gt;&amp;nbsp;down in the customer. Decide which direction your scenario actually needs, and the rest mostly answers itself.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Conditional Access, the cleanest inverse. &lt;/STRONG&gt;With Lighthouse, provider users authenticate&amp;nbsp;in their own tenant, so the customer's Conditional Access never reaches them, &lt;EM&gt;"Only policies set on the managing tenant apply"&lt;/EM&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/recommended-security-practices" target="_blank" rel="noopener"&gt;recommended security practices&lt;/A&gt;). With Tenant Governance the provider actually&amp;nbsp;signs in to the customer tenant&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;), which makes the customer the&amp;nbsp;resource tenant&amp;nbsp;that evaluates Conditional Access, so the&amp;nbsp;customer's&amp;nbsp;policies govern the inbound provider login, not the provider's policies.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Two nuances to keep in mind: When the provider logs into the customer tenant, the authentication still happens with the provider’s tenant, but the conditional access policy applied to the login is in the customer tenant.&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; Where privileged access lives. &lt;/STRONG&gt;Lighthouse offers just-in-time elevation through eligible authorizations, and the&amp;nbsp;approvers sit in the provider (managing) tenant, &lt;EM&gt;"up to 10 users or user groups in the managing tenant who can approve"&lt;/EM&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/create-eligible-authorizations" target="_blank" rel="noopener"&gt;create eligible authorizations&lt;/A&gt;). Tenant Governance inverts the ownership: the proxy's role assignment&amp;nbsp;lives in the customer tenant, so privileged-access governance over that assignment is anchored&amp;nbsp;customer-side. The useful contrast is simply&amp;nbsp;&lt;EM&gt;where the assignment lives and who governs it&lt;/EM&gt;, provider-side for Lighthouse, customer-side for Tenant Governance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Audit and identity footprint. &lt;/STRONG&gt;With Lighthouse, provider actions land in the customer's Azure Activity Log under a named user, with no customer sign-in and no directory object (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/how-to/view-service-provider-activity" target="_blank" rel="noopener"&gt;view provider activity&lt;/A&gt;). Tenant Governance is more subtle. The provider user's authentication is handled and logged in the provider (home) tenant, so the bare sign-in appears&amp;nbsp;&lt;EM&gt;there&lt;/EM&gt;, not in the customer tenant. What does get logged in the customer directory is the provider user’s actions, in its audit log, where the actor shows as the &amp;lt;provider tenant's name +&amp;nbsp;Technician&amp;gt;&amp;nbsp;(e.g.&amp;nbsp;Contoso Technician) (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/how-to-delegated-administration" target="_blank" rel="noopener"&gt;use cross-tenant delegated administration&lt;/A&gt;). A sign-in entry from the provider user only appears in the customer's logs when the customer's Conditional Access evaluates the session, for example, an MFA challenge. Without such a policy, that sign-in is only logged on the provider side. Either way, the customer keeps a full audit of what the technician does and gains no standing local or guest object (&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 7 - The providers activities on resources are logged in the customer's subscription activity log as "&amp;lt;provider name&amp;gt; Technician"&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 8 - When the provider logs into the customer tenant, their authentication is logged against the provider tenant while Conditional Access is logged against the customer tenant&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;STRONG&gt; One console vs. many: Operational reach. &lt;/STRONG&gt;Because Lighthouse projects the customer's resources&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;, the provider works from a&amp;nbsp;single pane of glass, every delegated customer's subscriptions appear in the provider's&amp;nbsp;own&amp;nbsp;Azure portal, and cross-tenant tooling, Azure Resource Graph, Microsoft Sentinel, Azure Policy, Azure Monitor, can span all of them at once. Tenant Governance points the other way: the provider's identity projects&amp;nbsp;&lt;EM&gt;down &lt;/EM&gt;into each customer, so day-to-day administration is&amp;nbsp;per-customer, the admin signs in to each customer tenant in turn. (Service consoles such as Microsoft Defender XDR add their own aggregated multitenant views on top, but the underlying delegated-admin model is per-tenant.) When operating&amp;nbsp;many&amp;nbsp;customers' Azure estates from one console is the priority, that single-pane reach is a distinct Lighthouse strength.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Nine" class="lia-anchor"&gt;&lt;/a&gt;9. Where the two models overlap&lt;/H2&gt;
&lt;P&gt;As is the case with other delegated access models, there is clear overlap between Azure Lighthouse and Tenant Governance:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Both eliminate local and B2B accounts&lt;/STRONG&gt;&amp;nbsp;in the customer. The partner's people stay in the provider tenant either way (&lt;A href="https://learn.microsoft.com/en-us/azure/lighthouse/concepts/architecture" target="_blank" rel="noopener"&gt;Lighthouse architecture&lt;/A&gt;,&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/cross-tenant-delegated-administration" target="_blank" rel="noopener"&gt;cross-tenant delegated administration&lt;/A&gt;).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both can ultimately place Azure RBAC on customer resources&lt;/STRONG&gt;, Lighthouse directly through the delegation, Tenant Governance via the remote tenant group.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both are limited to the control (management) plane&lt;/STRONG&gt;, neither delegates resource data-plane access (for example, blob data or Key Vault secrets); that still requires an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both keep the customer in control of the audit record&lt;/STRONG&gt;, provider actions are written to the customer's logs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Both are revocable by either party&lt;/STRONG&gt;, remove the delegation, or terminate the relationship.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Ten" class="lia-anchor"&gt;&lt;/a&gt;10. What is complimentary with the two models?&lt;/H2&gt;
&lt;P&gt;Because they sit on different planes and point in opposite directions, you can use one or both.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Fig 9 - Azure Lighthouse and Entra Tenant Governance compared&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deciding between the two delegated access models:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Need only to operate the customer's Azure resources, especially across many customers?&lt;/STRONG&gt;&amp;nbsp;Choose&amp;nbsp;Azure Lighthouse, no extra license or charge, a broad set of Azure built-in roles (Owner and custom roles excluded), just-in-time elevation with provider-side approval, zero directory footprint, and a&amp;nbsp;single pane of glass: because customer resources project&amp;nbsp;&lt;EM&gt;up&lt;/EM&gt;&amp;nbsp;into the provider's tenant, the provider manages&amp;nbsp;every&amp;nbsp;customer's estate from their&amp;nbsp;own&amp;nbsp;portal, with cross-tenant tooling spanning all of them at once.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Need directory, identity, or security reach, not just resources?&lt;/STRONG&gt;&amp;nbsp;Choose&amp;nbsp;Microsoft Entra Tenant Governance, directory roles and Azure RBAC on one projected principal, with the customer's own sign-in controls in the loop. Because the provider's identity projects&amp;nbsp;&lt;EM&gt;down&lt;/EM&gt;&amp;nbsp;into each customer, administration is&amp;nbsp;per-customer: the admin signs in to each customer tenant in turn rather than from one aggregated console.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Need both on the same tenant?&lt;/STRONG&gt;&amp;nbsp;Use both. They coexist because they operate on different planes, Lighthouse for the resource estate, Tenant Governance for directory and security.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Eleven" class="lia-anchor"&gt;&lt;/a&gt;11. Key points to remember about Entra Tenant Governance&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Least privilege.&lt;/STRONG&gt;&amp;nbsp;A directory role grants&amp;nbsp;&lt;EM&gt;no&lt;/EM&gt;&amp;nbsp;Azure access, and an Azure RBAC role grants&amp;nbsp;&lt;EM&gt;no&lt;/EM&gt;&amp;nbsp;directory access. Each plane is an&amp;nbsp;explicit grant&amp;nbsp;to the proxy, start with read-only (e.g.,&amp;nbsp;Global Reader&amp;nbsp;in the directory,&amp;nbsp;Reader&amp;nbsp;on resources) and add only what's needed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Directory ≠ resource.&lt;/STRONG&gt; The two planes are independent. If the partner needs to operate Azure resources, that comes from an explicit RBAC assignment on the remote tenant group, not from any directory role. That RBAC is control-plane only; neither Tenant Governance nor Lighthouse delegates the resource data plane (for example, blob data or Key Vault secrets), which still requires an identity native to the customer tenant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenant discovery is irreversible.&lt;/STRONG&gt;&amp;nbsp;Enabling related-tenant discovery is&amp;nbsp;permanent&amp;nbsp;(&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/deployment-guide#phase-1-enable-related-tenant-discovery" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;). For a controlled pilot, run the handshake&amp;nbsp;by&lt;STRONG&gt; &lt;/STRONG&gt;tenant ID&amp;nbsp;and skip discovery. Azure&amp;nbsp;Lighthouse, by contrast, coexists with a governance relationship on the same customer, different mechanism, different plane.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Conditional Access is the customer's to enforce.&lt;/STRONG&gt;&amp;nbsp;Because the provider signs in to the customer tenant, the&amp;nbsp;customer's&amp;nbsp;Conditional Access governs that access.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 class="lia-linked-item"&gt;&lt;a id="community--1-Twelve" class="lia-anchor"&gt;&lt;/a&gt;12. Summary&lt;/H2&gt;
&lt;P&gt;Azure Lighthouse and Microsoft Entra Tenant Governance are two delegation models pointing in opposite directions. Lighthouse brings the customer's&amp;nbsp;resources up&amp;nbsp;to the provider and keeps the provider's Azure access clean and identity-free. Tenant Governance places a&amp;nbsp;governed proxy of the provider down&amp;nbsp;in the customer, extending the very philosophy from Parts 1–2, &lt;EM&gt;govern the relationship, not the people&lt;/EM&gt;, from the resource plane all the way into the&amp;nbsp;directory.&lt;/P&gt;
&lt;P&gt;Choose by the direction the trust needs to flow: bring the resources to you (Azure Lighthouse), or place a governed proxy of yourself in the customer (Microsoft Entra Tenant Governance). When you need both, use both.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/should-you-use-the-new-microsoft-entra-tenant-governance-or/ba-p/4532297</guid>
      <dc:creator>Preston_Romney</dc:creator>
      <dc:date>2026-07-23T12:00:00Z</dc:date>
    </item>
    <item>
      <title>Lessons Learned #547:Some SQL DB Statistics Remain Outdated While Others Are Automatically Updated</title>
      <link>https://techcommunity.microsoft.com/t5/azure-database-support-blog/lessons-learned-547-some-sql-db-statistics-remain-outdated-while/ba-p/4540055</link>
      <description>&lt;P&gt;During the analysis of a SQL Server performance case, we observed an interesting statistics update pattern on a large table.&lt;/P&gt;
&lt;P&gt;Several statistics had recently been updated at different times, while a group of automatically created _WA_Sys_ statistics still showed:&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;STRONG&gt;An older last_updated date.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A high modification_counter.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A row count significantly lower than the current number of rows in the table.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;At first glance, this could suggest that &lt;STRONG&gt;AUTO_UPDATE_STATISTICS&lt;/STRONG&gt; was not working correctly. However, a closer review showed that this pattern can be completely consistent with the expected behavior of SQL Server.&lt;/P&gt;
&lt;H2&gt;1. Types of statistics in SQL Server&lt;/H2&gt;
&lt;P&gt;SQL Server can maintain several types of statistics.&lt;/P&gt;
&lt;H3&gt;Automatically created column statistics&lt;/H3&gt;
&lt;P&gt;When &lt;STRONG&gt;AUTO_CREATE_STATISTICS is enabled&lt;/STRONG&gt;, SQL Server can automatically create a &lt;STRONG&gt;single-column statistic&lt;/STRONG&gt; when the Query Optimizer needs cardinality information for a column used in a query predicate. These statistics normally use names such as: &lt;STRONG&gt;_WA_Sys_00000002_47A6D5E5&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The name can be interpreted as: &lt;STRONG&gt;_WA_Sys_&amp;lt;column_id in hexadecimal&amp;gt;&lt;/STRONG&gt;_&lt;STRONG&gt;&amp;lt;object_id in hexadecimal&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For example: &lt;STRONG&gt;00000002 &lt;/STRONG&gt;hexadecimal = &lt;STRONG&gt;column_id 2&lt;/STRONG&gt; &lt;STRONG&gt;47A6D5E5 hexadecimal&lt;/STRONG&gt; = table object_id&lt;/P&gt;
&lt;P&gt;The most reliable way to identify the associated column is not to decode the name manually, but to query the SQL Server catalog views:&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;DECLARE @TableName sysname = N'dbo.CustomerTransactions'; 
SELECT s.stats_id, s.name AS statistics_name, sc.stats_column_id, c.column_id, 
c.name AS column_name, s.auto_created, s.user_created, s.no_recompute 
FROM sys.stats AS s 
INNER JOIN sys.stats_columns AS sc ON sc.object_id = s.object_id AND sc.stats_id = s.stats_id 
INNER JOIN sys.columns AS c ON c.object_id = sc.object_id AND c.column_id = sc.column_id 
WHERE s.object_id = OBJECT_ID(@TableName) 
AND s.name = N'_WA_Sys_00000002_47A6D5E5' ORDER BY sc.stats_column_id;&lt;/LI-CODE&gt;
&lt;H3&gt;Statistics associated with indexes&lt;/H3&gt;
&lt;P&gt;When SQL Server creates an index, it also creates a statistics object associated with the index. For example: &lt;STRONG&gt;CREATE INDEX IX_CustomerTransactions_ClientId ON dbo.CustomerTransactions(ClientId) t&lt;/STRONG&gt;his creates an index statistics object normally named: &lt;STRONG&gt;IX_CustomerTransactions_ClientId&lt;/STRONG&gt; when a statistics object corresponds to an index, its stats_id matches the index's index_id.&lt;/P&gt;
&lt;H3&gt;User-created statistics&lt;/H3&gt;
&lt;P&gt;Statistics can also be created explicitly: &lt;STRONG&gt;CREATE STATISTICS ST_CustomerTransactions_ClientId_Status ON dbo.CustomerTransactions ( ClientId, StatusId ); &lt;/STRONG&gt;This object is identified in &lt;STRONG&gt;sys.stats&lt;/STRONG&gt; with: &lt;STRONG&gt;user_created = 1 auto_created = 0&lt;/STRONG&gt; and &lt;STRONG&gt;AUTO_UPDATE_STATISTICS&lt;/STRONG&gt; applies to index statistics, automatically created single-column statistics, manually created statistics and filtered statistics.&lt;/P&gt;
&lt;H2&gt;2. Statistics are not updated together&lt;/H2&gt;
&lt;P&gt;Assume that a table has these statistics:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;_WA_Sys_00000002_xxxxxxxx for ClientId&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;_WA_Sys_00000003_xxxxxxxx for StatusId&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IX_CustomerTransactions_CreatedDate for CreatedDate PK_CustomerTransactions and TransactionId&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After a large data load, several or all of them could become eligible for an automatic update. &lt;STRONG&gt;However, SQL Server does not immediately update all eligible statistics&lt;/STRONG&gt;. Before compiling a query, the Query Optimizer identifies the statistics that could be relevant to the query predicates and checks whether those statistics are outdated.&lt;/P&gt;
&lt;P&gt;Consider this query:&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;SELECT TransactionId, ClientId, Amount FROM dbo.CustomerTransactions WHERE ClientId = 100;&lt;/LI-CODE&gt;
&lt;P&gt;The optimizer might need a histogram on ClientId. If the corresponding statistics object is outdated and has crossed its update threshold, SQL Server may update that specific statistics object.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;It does not need to update unrelated statistics on&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;StatusId&lt;/LI&gt;
&lt;LI&gt;CreatedDate&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result, statistics on the &lt;STRONG&gt;same table can legitimately have different update times&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PK_CustomerTransactions 2026-07-22 10:53&lt;/LI&gt;
&lt;LI&gt;IX_CustomerTransactions_ClientId 2026-07-22 10:50&lt;/LI&gt;
&lt;LI&gt;IX_CustomerTransactions_CreatedDate 2026-07-22 10:13&lt;/LI&gt;
&lt;LI&gt;_WA_Sys_00000003_47A6D5E5 2026-07-19 10:00&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This pattern can be evidence of demand-driven automatic updates rather than evidence of a malfunction.&lt;/P&gt;
&lt;H2&gt;3. What does modification_counter represent?&lt;/H2&gt;
&lt;P&gt;The modification_counter returned by &lt;STRONG&gt;sys.dm_db_stats_properties&lt;/STRONG&gt; represents the number of modifications made to the leading statistics column since that statistics object was last updated. This definition is especially important for multicolumn statistics.&lt;/P&gt;
&lt;P&gt;For example: &lt;STRONG&gt;CREATE INDEX IX_CustomerTransactions_ClientId_Status ON dbo.CustomerTransactions ( ClientId, StatusId );&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The associated statistics object contains:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Histogram&lt;/STRONG&gt;: ClientId&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Density information:&lt;/STRONG&gt; ClientId ClientId, StatusId&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The histogram and modification_counter are based on the leading column, ClientId.&lt;/P&gt;
&lt;P&gt;If only StatusId is modified: &lt;STRONG&gt;UPDATE dbo.CustomerTransactions SET StatusId = 2 WHERE TransactionId = 100&lt;/STRONG&gt;; this does not have the same statistics impact as changing ClientId, because ClientId is the leading histogram column.&lt;/P&gt;
&lt;P&gt;SQL Server statistics contain only one histogram, built on the first key column. Multicolumn statistics additionally contain density information for column prefixes.&lt;/P&gt;
&lt;H2&gt;4. Why do multiple statistics sometimes have similar modification counters?&lt;/H2&gt;
&lt;P&gt;This commonly happens after an insert operation.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;INSERT INTO dbo.CustomerTransactions ( TransactionId, ClientId, StatusId, Amount, CreatedDate ) SELECT TransactionId, ClientId, StatusId, Amount, CreatedDate FROM dbo.StagingCustomerTransactions;&lt;/LI-CODE&gt;
&lt;P&gt;Each inserted row introduces a value for every populated column. Consequently, &lt;STRONG&gt;multiple single-column statistics may show similar increases&lt;/STRONG&gt; in their modification counters. This is particularly visible after a large ETL operation: &lt;STRONG&gt;Table rows before the load&lt;/STRONG&gt;: 487,673 &lt;STRONG&gt;Rows inserted by&lt;/STRONG&gt; the ETL: 515,244 &lt;STRONG&gt;Current approximate row count:&lt;/STRONG&gt; 1,002,917&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Several statistics could then show modification counters close to the number of inserted rows.&lt;/STRONG&gt; That does not mean SQL Server must update all those statistics immediately. They become candidates for updating, but an update is normally triggered when query optimization requires them.&lt;/P&gt;
&lt;H2&gt;5. Does automatic updating apply only to _WA_Sys_ statistics?&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;AUTO_UPDATE_STATISTICS applies to:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Automatically created _WA_Sys statistics&lt;/LI&gt;
&lt;LI&gt;Index statistics Primary-key index statistics&lt;/LI&gt;
&lt;LI&gt;User-created statistics&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Each statistics object is evaluated independently&lt;/STRONG&gt;. Therefore, &lt;STRONG&gt;SQL Server might update&lt;/STRONG&gt;: PK_CustomerTransactions &lt;STRONG&gt;while leaving this object&lt;/STRONG&gt; unchanged: _WA_Sys_00000003_47A6D5E5&lt;/P&gt;
&lt;P&gt;The reverse is also possible. The behavior depends on which statistics are considered relevant during compilation or cached-plan validation.&lt;/P&gt;
&lt;H2&gt;6. What happens when a _WA_Sys_ statistic and an index statistic cover the same column?&lt;/H2&gt;
&lt;P&gt;This is one of the most interesting scenarios. &lt;STRONG&gt;Assume SQL Server originally created:&lt;/STRONG&gt; _WA_Sys_00000002_xxxxxxxx for ClientId.&lt;/P&gt;
&lt;P&gt;Later, someone creates this index: &lt;STRONG&gt;CREATE INDEX IX_CustomerTransactions_ClientId ON dbo.CustomerTransactions(ClientId);&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The table now has two statistics objects with histograms on ClientId: &lt;STRONG&gt;_WA_Sys_00000002_xxxxxxxx and IX_CustomerTransactions_ClientId&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Conceptually: &lt;STRONG&gt;_WA_Sys statistic Histogram on ClientId Index statistic Histogram on ClientId&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For a query such as: &lt;STRONG&gt;SELECT * FROM dbo.CustomerTransactions WHERE ClientId = @ClientId&lt;/STRONG&gt;; the optimizer can have more than one potentially relevant statistics object. It may rely on the index statistics object rather than the older _WA_Sys_ object.&lt;/P&gt;
&lt;P&gt;In that case:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IX_CustomerTransactions_ClientId Updated recently &lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;_WA_Sys_00000002_xxxxxxxx&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Old last_updated value&lt;/LI&gt;
&lt;LI&gt;High modification_counter&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;This does not necessarily mean that automatic statistics updating has failed. It can mean that the _WA_Sys_ statistic has become redundant and has not been required by recent compilations. &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;However, this should be presented carefully: The Query Optimizer is not publicly documented as always preferring an index statistic over an equivalent _WA_Sys_ statistic.&lt;/P&gt;
&lt;P&gt;The statistics selected can depend on:&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;Query.&lt;/LI&gt;
&lt;LI&gt;Predicates.&lt;/LI&gt;
&lt;LI&gt;Available indexes.&lt;/LI&gt;
&lt;LI&gt;Filtered versus unfiltered statistics.&lt;/LI&gt;
&lt;LI&gt;Statistics freshness.&lt;/LI&gt;
&lt;LI&gt;Sampling quality.&lt;/LI&gt;
&lt;LI&gt;Multicolumn density information.&lt;/LI&gt;
&lt;LI&gt;Cardinality Estimator behavior.&lt;/LI&gt;
&lt;LI&gt;Existing cached plans.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The correct conclusion is that the scenario is possible and plausible, but the execution plan should be inspected before claiming that a specific statistics object was used.&lt;/P&gt;
&lt;P&gt;As we wrote down in multiple articles in our blog (below), identify redudant statistics is part of DBA work to avoid this situation, also, in other situations, I saw that the maintenance plan is taking too much time because we are updating statistics that we are not using or migth be duplicated. The following script identifies statistics whose leading columns overlap:&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;DECLARE @TableName sysname = N'dbo.CustomerTransactions'; 
;WITH LeadingStatisticsColumns AS ( SELECT s.object_id, s.stats_id, 
s.name AS statistics_name, 
s.auto_created, s.user_created, 
s.no_recompute, s.has_filter, s.filter_definition, sc.column_id, c.name AS leading_column, 
i.index_id, i.name AS index_name 
FROM sys.stats AS s 
INNER JOIN sys.stats_columns AS sc ON sc.object_id = s.object_id AND sc.stats_id = s.stats_id AND sc.stats_column_id = 1 
INNER JOIN sys.columns AS c ON c.object_id = sc.object_id AND c.column_id = sc.column_id 
LEFT JOIN sys.indexes AS i ON i.object_id = s.object_id AND i.index_id = s.stats_id 
WHERE s.object_id = OBJECT_ID(@TableName) ) 
SELECT leading_column, statistics_name, 
       CASE WHEN index_id IS NOT NULL THEN N'INDEX STATISTICS' WHEN auto_created = 1 THEN N'AUTO-CREATED _WA_SYS' 
	        WHEN user_created = 1 THEN N'USER-CREATED STATISTICS' ELSE N'OTHER' 
			END AS statistics_type, index_name, has_filter, filter_definition, no_recompute, COUNT(*) 
			OVER ( PARTITION BY column_id ) AS statistics_on_same_leading_column 
			FROM LeadingStatisticsColumns 
			ORDER BY leading_column, statistics_type, statistics_name;&lt;/LI-CODE&gt;
&lt;P&gt;This does not automatically mean that one object should be deleted. It only identifies an overlap.&lt;/P&gt;
&lt;H2&gt;7. Script&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;The following example demonstrates how an automatically created statistic can coexist with a later index statistic.&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;DROP TABLE IF EXISTS dbo.CustomerTransactions; 
GO 
CREATE TABLE dbo.CustomerTransactions 
( TransactionId int NOT NULL, ClientId int NOT NULL, StatusId tinyint NOT NULL, Amount decimal(12,2) NOT NULL, CreatedDate datetime2(0) NOT NULL, 
CONSTRAINT PK_CustomerTransactions PRIMARY KEY CLUSTERED (TransactionId) ); 
GO&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Insert sample data&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;;WITH Numbers AS 
( SELECT TOP (200000) ROW_NUMBER() OVER ( ORDER BY (SELECT NULL) ) AS n 
FROM sys.all_objects AS a 
CROSS JOIN sys.all_objects AS b ) 
INSERT INTO dbo.CustomerTransactions ( TransactionId, ClientId, StatusId, Amount, CreatedDate ) 
SELECT n, n % 5000, n % 5, CONVERT(decimal(12,2), n % 10000), DATEADD ( minute, -(n % 100000), SYSUTCDATETIME() ) 
FROM Numbers; 
GO&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Ensure that automatic statistics creation and updating are enable&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;ALTER DATABASE CURRENT SET AUTO_CREATE_STATISTICS ON; 
GO 
ALTER DATABASE CURRENT SET AUTO_UPDATE_STATISTICS ON; 
GO&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Trigger automatic statistics creation on ClientId&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;SELECT COUNT_BIG(*) 
FROM dbo.CustomerTransactions 
WHERE ClientId = 100 OPTION (RECOMPILE); 
GO&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Check the statistics created for ClientId&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;SELECT s.stats_id, s.name AS statistics_name, s.auto_created, s.user_created, 
c.name AS column_name 
FROM sys.stats AS s 
INNER JOIN sys.stats_columns AS sc ON sc.object_id = s.object_id AND sc.stats_id = s.stats_id 
INNER JOIN sys.columns AS c ON c.object_id = sc.object_id AND c.column_id = sc.column_id 
WHERE s.object_id = OBJECT_ID(N'dbo.CustomerTransactions') 
AND c.name = N'ClientId' 
ORDER BY s.stats_id;&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;PRE&gt;&lt;STRONG&gt;Create an index on the same column&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;LI-CODE lang="sql"&gt;CREATE INDEX IX_CustomerTransactions_ClientId ON dbo.CustomerTransactions(ClientId); 
&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;The table can now have:&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;PRE&gt;&lt;STRONG&gt;Modify the data significantly&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;LI-CODE lang="sql"&gt;UPDATE dbo.CustomerTransactions SET ClientId = ClientId + 10000 WHERE TransactionId &amp;lt;= 100000;&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Review the counters again&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;SELECT s.name AS statistics_name, sp.last_updated, sp.rows, sp.rows_sampled, sp.modification_counter 
FROM sys.stats AS s 
OUTER APPLY sys.dm_db_stats_properties ( s.object_id, s.stats_id ) AS sp 
WHERE s.object_id = OBJECT_ID(N'dbo.CustomerTransactions') ORDER BY s.stats_id&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Force a new compilation using ClientId&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="sql"&gt;SET STATISTICS XML ON; 
GO 
SELECT COUNT_BIG(*) FROM dbo.CustomerTransactions WHERE ClientId = 10100 OPTION (RECOMPILE); 
GO 
SET STATISTICS XML OFF; 
GO&lt;/LI-CODE&gt;&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;After the query, review:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;The &lt;STRONG&gt;actual execution plan XML.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;The &lt;STRONG&gt;StatisticsInfo elements.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;last_updated.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;modification_counter.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The exact object updated is an optimizer decision and can vary by SQL Server version, build, compatibility level and query shape. The test should therefore be used to observe the behavior rather than to assume a fixed preference.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Finally, as you could see SQL Server choose &lt;STRONG&gt;_WA_Sys_00000002_151102AD instead of IX_CustomerTransactions_ClientId to updat&lt;/STRONG&gt;e. In some situations, depending on execution plan, SQL Server might choose IX_CustomerTransactions_ClientId to update instead of _WA_Sys_00000002_151102AD and for this reason, doesn't mean that SQL Server is not updating the statistics it is depending that it is choosing one of them that the column is involved.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;My lessons learned, a statistic can be outdated without being relevant, and it can be relevant without being the only available source of cardinality information. Before interpreting an old last_updated value as an automatic statistics failure, identify the leading column, look for overlapping statistics, inspect the execution plan and determine whether there is a real estimation or performance problem.&lt;/P&gt;
&lt;H3&gt;Articles:&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuredbsupport/lesson-learned-482-identifying-potential-duplicate-statistics/4102435" target="_blank"&gt;Lesson Learned #482: Identifying Potential Duplicate Statistics | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuredbsupport/lesson-learned-324-query-recompilation-in-azure-sql/3737417" target="_blank"&gt;Lesson Learned #324: Query Recompilation in Azure SQL | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuredbsupport/lessons-learned-537-copilot-prompts-for-troubleshooting-on-azure-sql-database/4463038" target="_blank"&gt;Lessons Learned #537: Copilot Prompts for Troubleshooting on Azure SQL Database | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azuredbsupport/lesson-learned-498understanding-the-role-of-statman-in-sql-server-and-its-resour/4156891" target="_blank"&gt;Lesson Learned #498:Understanding the Role of STATMAN in SQL Server and Its Resource Consumption | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;Disclaimer:&lt;/H3&gt;
&lt;P&gt;The scripts included in this article are provided for demonstration and educational purposes only. They create a sample table, insert a significant number of rows, create indexes and statistics, modify data, and change automatic statistics settings in the current database.&lt;/P&gt;
&lt;P&gt;Run the complete demonstration only in a test or non-production environment. Review and adapt the database name, object names, row volume, and statements before execution.&lt;/P&gt;
&lt;P&gt;The results may vary depending on the SQL Server version, database compatibility level, existing configuration, data distribution, and workload. Always test the scripts in a representative environment before applying any conclusion or change to a production system.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 09:47:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-database-support-blog/lessons-learned-547-some-sql-db-statistics-remain-outdated-while/ba-p/4540055</guid>
      <dc:creator>Jose_Manuel_Jurado</dc:creator>
      <dc:date>2026-07-23T09:47:54Z</dc:date>
    </item>
    <item>
      <title>Design, test, and ship Foundry hosted agents from a canvas in GitHub Copilot App</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-developer-community/design-test-and-ship-foundry-hosted-agents-from-a-canvas-in/ba-p/4539921</link>
      <description>&lt;P&gt;Building a Microsoft Foundry hosted agent has historically meant juggling multiple surfaces — looking up a model deployment in the Foundry portal, wiring toolboxes and skills by hand, copying an endpoint into your editor, then dropping to the CLI to test and deploy. That context-switching adds friction at exactly the moment you want to be experimenting.&lt;/P&gt;
&lt;P&gt;Today we're changing that. &lt;STRONG&gt;The Foundry Agent Canvas is now in public preview.&lt;/STRONG&gt; With this release, the full hosted-agent workflow — discover, scaffold, configure, test, deploy — lives right beside the Copilot chat that's already writing your code.&lt;/P&gt;
&lt;P&gt;The Foundry Agent Canvas is a GitHub Copilot App extension that opens a visual canvas in the side panel. You make choices in the canvas, and it hands each step to Copilot with your Foundry project context already attached. Copilot writes the code and runs the commands; the canvas keeps the visual state and your workspace in sync. Here are a few things this unlocks for developers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;🧭 A project-aware canvas, one prompt away&lt;/H1&gt;
&lt;P&gt;Ask Copilot to create a Foundry hosted agent and the canvas opens automatically, connected to your project. It surfaces what's actually deployed — models, Foundry Toolboxes and their tools, project skills, and account guardrails — so you're choosing from real resources, not a static list.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To get started:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the GitHub Copilot App, ask Copilot: &lt;EM&gt;Create a Foundry hosted agent using the Foundry Agent Canvas.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Open the canvas project menu, sign in to Azure if you're prompted, and pick a subscription.&lt;/LI&gt;
&lt;LI&gt;Select a Foundry project. The canvas remembers your choice across reopens.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;✨ Scaffold and configure without leaving the panel&lt;/H1&gt;
&lt;P&gt;Start from a generated idea with &lt;STRONG&gt;Inspire me&lt;/STRONG&gt;, or begin from a &lt;STRONG&gt;Hello world&lt;/STRONG&gt; sample. From there, wire the agent to a deployed model and connect any toolboxes, skills, and guardrails. Every selection becomes a project-aware prompt to Copilot, which updates the agent code for you.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To build your agent:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Choose &lt;STRONG&gt;Inspire me&lt;/STRONG&gt; for a generated starting point, or the &lt;STRONG&gt;Hello world&lt;/STRONG&gt; sample prompt.&lt;/LI&gt;
&lt;LI&gt;Select a deployed model, then connect toolboxes, skills, and guardrails from your project.&lt;/LI&gt;
&lt;LI&gt;Let Copilot apply each change in your workspace as you go.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;🔍 Test locally with the embedded Agent Inspector&lt;/H1&gt;
&lt;P&gt;When you're ready to try it, &lt;STRONG&gt;Inspect Locally&lt;/STRONG&gt; runs the agent and embeds the Agent Inspector right in the canvas — no separate REST client, no extra tooling. Chat with the agent, and if something breaks, send the error straight back to Copilot as a fix request.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To test and deploy:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Inspect Locally&lt;/STRONG&gt; — the canvas runs the agent and opens the Agent Inspector on port 8088.&lt;/LI&gt;
&lt;LI&gt;Send a prompt such as &lt;EM&gt;Write a haiku about deploying cloud applications.&lt;/EM&gt; and iterate.&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Deploy to Foundry&lt;/STRONG&gt; to publish the agent to Foundry Agent Service.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because &lt;STRONG&gt;Inspect Locally&lt;/STRONG&gt; and &lt;STRONG&gt;Deploy to Foundry&lt;/STRONG&gt; run the underlying Azure Developer CLI (azd) commands, you're never boxed in — drop back to the terminal whenever you want.&lt;/P&gt;
&lt;P&gt;Hosted agents are one of the fastest-growing ways developers build on Microsoft Foundry — from internal copilots to task automation to customer-facing assistants. This release gives you a first-class, visual path to design and ship them faster, without giving up the code-first workflow you already know.&lt;/P&gt;
&lt;H1&gt;🚀 Get Started Today&lt;/H1&gt;
&lt;P&gt;Ready to build your first agent from the canvas? Here's how to jump in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the GitHub Copilot App, open &lt;STRONG&gt;Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Plugins&lt;/STRONG&gt;, search for foundry-agent-canvas, and select &lt;STRONG&gt;Install&lt;/STRONG&gt;. You can also install it from the &lt;A class="lia-external-url" href="https://awesome-copilot.github.com/extension/foundry-agent-canvas/" target="_blank"&gt;&lt;U&gt;awesome-copilot listing&lt;/U&gt;&lt;/A&gt; or ask Copilot to install it into user scope.&lt;/LI&gt;
&lt;LI&gt;Ask Copilot to create a Foundry hosted agent, then follow the canvas from project pick to deploy.&lt;/LI&gt;
&lt;LI&gt;Walk through it end to end with the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/foundry/agents/quickstarts/quickstart-hosted-agent?pivots=canvas" target="_blank"&gt;&lt;U&gt;Deploy your first hosted agent quickstart&lt;/U&gt;&lt;/A&gt;, and read the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/foundry/agents/concepts/foundry-agent-canvas" target="_blank"&gt;&lt;U&gt;Foundry Agent Canvas overview&lt;/U&gt;&lt;/A&gt; for the full picture.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We'd love to hear from you! Whether it's a feature request, a bug report, or feedback on your experience, join the conversation and contribute directly on our &lt;A class="lia-external-url" href="https://github.com/microsoft/foundry-toolkit" target="_blank"&gt;&lt;U&gt;GitHub repository&lt;/U&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Happy Coding!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 07:50:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-developer-community/design-test-and-ship-foundry-hosted-agents-from-a-canvas-in/ba-p/4539921</guid>
      <dc:creator>junjieli</dc:creator>
      <dc:date>2026-07-23T07:50:18Z</dc:date>
    </item>
    <item>
      <title>Azure Files, Reimagined: Top-Level Shares with Per-Share Networking, Billing, and Scale</title>
      <link>https://techcommunity.microsoft.com/t5/itops-talk-blog/azure-files-reimagined-top-level-shares-with-per-share/ba-p/4535079</link>
      <description>&lt;P&gt;Hello Folks!&lt;/P&gt;
&lt;P&gt;If you have ever wrestled with Azure Files inside a storage account, juggling shared RBAC, shared networking, and shared IOPS across a pile of shares that really should not live together, this session is going to address all that. During Microsoft Azure Infra Summit 2026, Vincent Du and Will Gries (both Product Managers on the Azure Files team) walked us through the new Microsoft.FileShares resource provider, a management model that promotes the file share itself to a top-level Azure resource.&lt;/P&gt;
&lt;P&gt;📺 &lt;STRONG&gt;Watch the session:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/IWktcxpru7c?si=STWrMOtHBHxWtFl3" width="100%" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" style="aspect-ratio: 16/9; height: auto;" sandbox="allow-scripts allow-same-origin allow-forms"&gt;
&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;H2&gt;Why IT Pros Should Care&lt;/H2&gt;
&lt;P&gt;For years, file shares lived inside a storage account, and that storage account dictated a lot of decisions for you. If one team needed a private endpoint and another needed a service endpoint, you either compromised or you created another storage account. If one share got hot and consumed all the IOPS, the other shares felt it too. Vincent and Will are on the team that built the new model to remove that compromise.&lt;/P&gt;
&lt;P&gt;Here is what changes for you as an IT pro:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Each file share is its own Azure resource with its own RBAC, networking, billing, IOPS, and throughput.&lt;/LI&gt;
&lt;LI&gt;Per-share cost shows up directly in Azure Cost Management’s per-resource view, no more Excel guesswork.&lt;/LI&gt;
&lt;LI&gt;Encryption in transit is on by default for NFS shares, at no extra cost.&lt;/LI&gt;
&lt;LI&gt;Provisioning is dramatically faster. In their head-to-head demo, 200 shares finished in about 50 seconds on the new model versus about 720 seconds with the classic flow.&lt;/LI&gt;
&lt;LI&gt;A new MCP server lets you create and manage shares from GitHub Copilot in VS Code with natural language.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In short, the new model trades the storage-account-as-gatekeeper pattern for something that feels a lot more like the rest of Azure (think VMs and disks, where the resource you care about is the resource you actually manage).&lt;/P&gt;
&lt;H2&gt;What Microsoft.FileShares Does, a Technical Overview&lt;/H2&gt;
&lt;P&gt;The new Microsoft.FileShares resource provider lets you deploy a file share without first standing up a storage account. When you go into the Azure portal, search for “File share,” and click create, you fill out a single create blade with the things that actually matter for that share: name, region, redundancy (LRS or ZRS), provisioned capacity, IOPS and throughput, networking, and tags. Microsoft Learn confirms the provisioned capacity range is 32 GiB to 262,144 GiB, and only LRS and ZRS redundancy are available at launch (see the Create a file share doc linked below).&lt;/P&gt;
&lt;P&gt;At GA, the new experience supports NFS 4.1 on the SSD media tier. SMB support, HDD support, customer-managed key encryption at rest, soft delete, and the AKS CSI driver integration are all on the roadmap and called out as the most-requested follow-ups. If you need those features today, the classic file share inside a storage account is still there for you.&lt;/P&gt;
&lt;P&gt;In the portal, Vincent showed off a small but meaningful detail: the icon color changed from blue (classic) to purple (new). It is a small thing, but when you are scanning a resource group, that visual cue saves you a click.&lt;/P&gt;
&lt;H2&gt;How It Works Under the Hood&lt;/H2&gt;
&lt;P&gt;The new model is built on the provisioned v2 billing structure. Microsoft Learn describes provisioned v2 as a billing model where you independently provision storage, IOPS, and throughput, and you pay for what you provision regardless of how much you actually use. This is a real shift from the older provisioned v1 model, where IOPS and throughput were a function of how much storage you provisioned.&lt;/P&gt;
&lt;P&gt;Will walked through the math. In his example, provisioning 14 TiB of storage on v1 gave 17,000 IOPS, about 1.5 GB/s throughput, and a bill of roughly $2,297. Moving to v2 with the exact same numbers was already noticeably cheaper. Then, because v2 lets you tune storage, IOPS, and throughput separately, he provisioned the exact storage he needed with slightly less IOPS and throughput, dropping the bill to roughly a third. For database-hot workloads you can dial IOPS up; for hot archive scenarios you can dial them down to the minimum. That kind of flexibility is genuinely useful.&lt;/P&gt;
&lt;P&gt;Encryption in transit deserves its own callout. The new shares default to encrypted NFS mounts using the AZNFS mount helper. Microsoft Learn explains that AZNFS wraps the NFS connection in a Stunnel-based TLS tunnel using AES-GCM, so you get TLS protection without needing Kerberos or external authentication. The helper installs cleanly on Ubuntu, RHEL, SUSE, Rocky, Oracle Linux, Alma Linux, and Azure Linux. If a workload genuinely cannot use the encrypted mount, you can uncheck the box and fall back to a traditional NFS mount.&lt;/P&gt;
&lt;P&gt;Networking is per share. You can attach a service endpoint or a private endpoint to each individual share, which means you can put a strict private-endpoint-only share next to a service-endpoint share for dev/test, all in the same resource group, without compromise.&lt;/P&gt;
&lt;P&gt;On the request side, classic shares throttle with a fixed window (you can burst, then you are locked out for the rest of the window). The new model uses a token-bucket algorithm (the same one Azure Resource Manager itself uses), which means you get a sustained refill rate. The team also gave you a separate delete bucket, so a big cleanup operation does not starve writes. That detail matters more than it sounds: batch cleanups against the classic model regularly crowd out new share creation.&lt;/P&gt;
&lt;H2&gt;Real-World Value&lt;/H2&gt;
&lt;P&gt;Where does this actually pay off? A few honest scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Mission-critical and regulated workloads.&lt;/STRONG&gt; A healthcare org with workloads at different sensitivity levels can put strict private-endpoint-only shares next to less sensitive service-endpoint shares without the storage-account ceiling.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Chargeback and showback.&lt;/STRONG&gt; With per-share resources, finance can pull a cost report that lines up to the team or project that owns each share. No more saying “we cannot itemize, the storage account is shared.”&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;High-density tenants.&lt;/STRONG&gt; The classic model effectively caps you at 34 file shares on an SSD provisioned v2 storage account (because of IOPS minimums) and 50 absolute. The new model goes up to 10,000 shares per subscription per region. That is a different game.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tuned database and analytics shares.&lt;/STRONG&gt; Provisioned v2 lets you right-size IOPS to the workload. As Will showed, that can drop the bill to roughly a third for the right shape of workload.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Faster deployment automation.&lt;/STRONG&gt; A 14x improvement on a 200-share deployment is not a micro-optimization. If you spin up environments for CI, training, or per-customer tenants, that adds up quickly.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The honest tradeoff: today, the new model is NFS-only on SSD. If you need SMB, HDD, customer-managed keys for NFS, or AKS CSI driver support, stay on the classic model for now. The team was upfront about that, and the GA-and-then-iterate roadmap is clear.&lt;/P&gt;
&lt;H2&gt;Getting Started&lt;/H2&gt;
&lt;P&gt;Here is the concrete path:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Register the Microsoft.FileShares and Microsoft.Storage resource providers on your subscription (Subscriptions, Resource providers, Register).&lt;/LI&gt;
&lt;LI&gt;From the Azure portal, search for “File share” in the marketplace and click Create. Pick LRS or ZRS, set the capacity between 32 GiB and 262 TiB, and either accept the recommended IOPS/throughput or set them manually.&lt;/LI&gt;
&lt;LI&gt;On the Advanced tab, leave “Require encryption in transit” enabled (it is on by default) and pick a custom mount name if you want one distinct from the resource name.&lt;/LI&gt;
&lt;LI&gt;On the Networking tab, attach a service endpoint or a private endpoint, per share.&lt;/LI&gt;
&lt;LI&gt;Mount it on your Linux VM with the AZNFS mount helper. The portal generates the exact command for your distribution.&lt;/LI&gt;
&lt;LI&gt;If you live in IaC land, the Microsoft.FileShares ARM and Bicep types are available, and Terraform support is coming.&lt;/LI&gt;
&lt;LI&gt;If you live in AI-assisted dev land, install the Azure MCP server and ask Copilot in VS Code to create a share for you, pointing at an existing VNet.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Resources&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/files/create-file-share" target="_blank"&gt;Create an Azure file share with Microsoft.FileShares&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/files/understanding-billing" target="_blank"&gt;Understand Azure Files billing (provisioned v1 and v2)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/files/encryption-in-transit-for-nfs-shares" target="_blank"&gt;Encryption in Transit for NFS Azure file shares&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/files/files-nfs-protocol" target="_blank"&gt;NFS file shares in Azure Files (protocol overview)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/files/" target="_blank"&gt;Azure Files documentation home&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Keep Learning at the Summit&lt;/H2&gt;
&lt;P&gt;Catch the full &lt;A class="lia-external-url" href="https://www.youtube.com/playlist?list=PLjt5SKzX1iI8con7FJDB56G6hHqxGm7ki" target="_blank"&gt;Microsoft Azure Infra Summit 2026 session playlist&lt;/A&gt; here.&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;
&lt;P&gt;Pierre Roman&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 07:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/itops-talk-blog/azure-files-reimagined-top-level-shares-with-per-share/ba-p/4535079</guid>
      <dc:creator>Pierre_Roman</dc:creator>
      <dc:date>2026-07-23T07:00:00Z</dc:date>
    </item>
    <item>
      <title>Regex-based dynamic data masking in Azure SQL Database (preview)</title>
      <link>https://techcommunity.microsoft.com/t5/azure-sql-blog/regex-based-dynamic-data-masking-in-azure-sql-database-preview/ba-p/4539938</link>
      <description>&lt;P&gt;Azure SQL Database introduces &lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-regex?view=azuresql" target="_blank"&gt;Regex-based dynamic data masking&lt;/A&gt;&lt;/STRONG&gt;, a new capability that enables flexible, pattern-driven masking for string-based columns using regular expressions through the T‑SQL&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/sql/t-sql/functions/regexp-replace-transact-sql?view=sql-server-ver17" target="_blank"&gt;REGEXP_REPLACE()&lt;/A&gt; function. This feature extends Dynamic Data Masking beyond built-in masking functions, giving you precise control over which portions of sensitive data are masked and which remain visible, helping preserve data utility while meeting business and compliance requirements.&lt;/P&gt;
&lt;P&gt;This capability is especially useful when working with structured data patterns—such as emails, phone numbers, or identifiers—where teams need to preserve specific visible segments while masking sensitive parts, and where built-in masks may be rigid for some business workflows.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why this matters&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-overview?view=azuresql" target="_blank"&gt;Dynamic Data Masking&lt;/A&gt; helps reduce accidental exposure of sensitive data by obfuscating values in query results for nonprivileged users, while keeping the original data intact in the database. However, existing built-in masking functions—such as default(), email(), random(), partial(), and datetime()—apply fixed patterns. These patterns cannot be customized, and may not be suitable for some of the real-world scenarios.&lt;/P&gt;
&lt;P&gt;For example, the built-in email() mask always transforms an address like alice.johnson@example.com into aXXX@XXXX.com, fully obscuring the domain name. In many operational scenarios, retaining the domain name is important for troubleshooting, routing, or business logic.&lt;/P&gt;
&lt;P&gt;Regex-based dynamic data masking addresses this gap by enabling precision masking without sacrificing usability.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s new with regex-based masking&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Regex-based DDM allows you to define &lt;STRONG&gt;custom, pattern-driven masking rules&lt;/STRONG&gt; using regular expressions. By leveraging the native &lt;A href="https://learn.microsoft.com/en-us/sql/t-sql/functions/regexp-replace-transact-sql?view=sql-server-ver17" target="_blank"&gt;REGEXP_REPLACE&lt;/A&gt; function in Azure SQL Database, you can precisely specify which parts of a string to mask and which to preserve—centrally enforced in the database layer.&lt;/P&gt;
&lt;P&gt;This approach supports variable-length and structured string data, enabling more precise and flexible data masking rules.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Practical scenarios&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Regex-based masking enables common customer scenarios that are difficult to address with fixed masks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Mask email usernames while preserving domains&lt;/STRONG&gt;&lt;BR /&gt;alice.johnson@example.com → &lt;A href="mailto:****@example.com" target="_blank"&gt;****@example.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Preserve country codes in phone numbers&lt;/STRONG&gt;&lt;BR /&gt;+1-4155552671 → +1-XXXXXXXXXX&lt;BR /&gt;+44-7911123456 → +44-XXXXXXXXXX&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Mask structured identifiers consistently&lt;/STRONG&gt;&lt;BR /&gt;Hide sensitive portions of national IDs or custom identifiers while keeping recognizable structure for support and auditing workflows.&amp;nbsp;For example: AB-1234-5678 → AB-****-5678&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The following example creates a table CustomerDetails with regex-based masking applied on Phone_Number and Email columns. The phone number mask preserves the country code and replaces the remaining digits with xxxx, and the email mask conceals the username while retaining the domain name.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table style="width: 94.1667%;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;-- Drop the CustomerDetails table if it exists&lt;/P&gt;
&lt;P&gt;DROP TABLE IF EXISTS Data.CustomerDetails;&lt;/P&gt;
&lt;P&gt;-- Create a CustomerDetails table under a schema&lt;/P&gt;
&lt;P&gt;CREATE TABLE Data.CustomerDetails (&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID INT IDENTITY(1,1) PRIMARY KEY,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name varchar(30),&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Phone_Number varchar(30) MASKED WITH (FUNCTION = 'REGEXP_REPLACE("(\+\d{1,3})(?:[ -.]?\d){7,14}","(\1)-xxxx")'),&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email varchar(255) MASKED WITH (FUNCTION = 'REGEXP_REPLACE("([a-zA-Z0-9._%+-]+)(@+)([a-zA-Z0-9.-]+)(\.)(\w)","*****\2\3\4\5")')&lt;/P&gt;
&lt;P&gt;);&lt;/P&gt;
&lt;P&gt;-- Insert some dummy records to CustomerDetails table&lt;/P&gt;
&lt;P&gt;INSERT INTO Data.CustomerDetails (Name, Phone_Number, Email) VALUES&lt;/P&gt;
&lt;P&gt;('Alice Johnson', '+1 202-555-0123', 'alice.johnson@example.com'),&lt;/P&gt;
&lt;P&gt;('Bob Smith', '+1 415-555-0198', 'bob.smith@contoso.com');&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-- Create a test user&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CREATE USER SupportEngineer WITHOUT LOGIN;&lt;/P&gt;
&lt;P&gt;-- Grant read permission on CustomerDetails to SupportEngineer&lt;/P&gt;
&lt;P&gt;GRANT SELECT ON Data.CustomerDetails TO SupportEngineer;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-- Query CustomerDetails table as SupportEngineer&lt;/P&gt;
&lt;P&gt;EXECUTE AS USER = 'SupportEngineer';&lt;/P&gt;
&lt;P&gt;SELECT * FROM Data.CustomerDetails;&lt;/P&gt;
&lt;P&gt;REVERT;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Public Preview notice&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;&lt;BR /&gt;Regex-based dynamic data masking is currently in Preview for Azure SQL Database. Preview features are provided for evaluation purposes and are subject to the &lt;A href="https://azure.microsoft.com/en-us/support/legal/preview-supplemental-terms/" target="_blank"&gt;Preview Terms Of Use | Microsoft Azure.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Azure SQL Database is the first SQL offering to receive this feature, with additional SQL platforms planned in the future.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to get started&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To learn more and access sample scripts, refer to the official documentation &lt;A href="https://learn.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-regex?view=azuresql" target="_blank"&gt;Regex-based dynamic data masking (preview) - Azure SQL Database | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Try Regex-based dynamic data masking in your dev or test environment and tell us what works—and what doesn’t!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Tell us what you need next in Data Masking&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Share your ideas through&amp;nbsp;&lt;A href="https://feedback.azure.com/d365community/forum/04fe6ee0-3b25-ec11-b6e6-000d3a4f0da0" target="_blank"&gt;Azure SQL feedback&lt;/A&gt; forum.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclaimer&lt;/STRONG&gt;: The examples in this article use fictional customer records created solely for demonstration and testing purposes. No real customer data is included.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 06:48:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-sql-blog/regex-based-dynamic-data-masking-in-azure-sql-database-preview/ba-p/4539938</guid>
      <dc:creator>MadhumitaTripathyMSFT</dc:creator>
      <dc:date>2026-07-23T06:48:35Z</dc:date>
    </item>
    <item>
      <title>Hybrid Logic Apps on RKE2: a self-managed cluster with MetalLB</title>
      <link>https://techcommunity.microsoft.com/t5/azure-integration-services-blog/hybrid-logic-apps-on-rke2-a-self-managed-cluster-with-metallb/ba-p/4539846</link>
      <description>&lt;P&gt;Azure Logic Apps Hybrid lets you run the Logic Apps runtime on your own Kubernetes cluster and still author, deploy, and monitor from Azure. The &lt;A href="https://techcommunity.microsoft.com/blog/integrationsonazureblog/hybrid-logic-apps-deployment-on-red-hat-openshift/4534828" target="_blank"&gt;previous post&lt;/A&gt; walked through Red Hat OpenShift. This one is RKE2. We spun up a single-node RKE2 cluster, gave the ingress an IP with MetalLB, connected it to Arc, and shipped a Hybrid Logic App end-to-end. A handful of things needed care along the way, and those are what this post is really about.&lt;/P&gt;
&lt;P&gt;If you've done Hybrid on AKS or K3s, the shape will look familiar. The &lt;A href="https://learn.microsoft.com/azure/logic-apps/set-up-standard-workflows-hybrid-deployment-requirements" target="_blank"&gt;official requirements doc&lt;/A&gt; covers the general flow. RKE2 is close enough to vanilla Kubernetes that most of it just works out of the box. Four things don't. Three of them are DNS. They're called out at the step they matter.&lt;/P&gt;
&lt;H2&gt;What makes RKE2 different?&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Area&lt;/th&gt;&lt;th&gt;What we found&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Ingress IP&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;RKE2 has an embedded cloud-controller-manager for node lifecycle, but no service load balancer. &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;type: LoadBalancer&lt;/CODE&gt; sits at &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;&amp;lt;pending&amp;gt;&lt;/CODE&gt; until you bring one. We used MetalLB (Step 2).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Pod security&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;No SCC dance like OpenShift; the extension pods schedule as-is. What we did hit was the node's &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;inotify&lt;/CODE&gt; limit. Enough runtime pods use it that the default runs out and about half the deployment crash-loops (Step 4).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;CoreDNS&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;RKE2 names its DNS objects &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;rke2-coredns-rke2-coredns&lt;/CODE&gt;, not &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;coredns&lt;/CODE&gt;/&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kube-dns&lt;/CODE&gt;. &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;az containerapp arc setup-core-dns&lt;/CODE&gt; doesn't have an RKE2 distro flag yet, so DNS is manual (Step 7).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Distribution flag&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;RKE2 is upstream Kubernetes. Don't copy the OpenShift install command; the &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;Azure.Cluster.Distribution=openshift&lt;/CODE&gt; and &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;coreDNSVersion&lt;/CODE&gt; overrides don't apply here and will bite you (Step 4).&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;A Linux host&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Anywhere RKE2 runs: bare metal, a VM, an edge appliance. We used a single Ubuntu 22.04 Azure VM (&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;Standard_D8as_v5&lt;/CODE&gt;) so everything was easy to nuke afterwards. 4 vCPU / 16 GB is the practical floor.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Azure subscription&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Rights to create Arc resources, custom locations, and connected environments.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Azure CLI&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Latest, with the &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;connectedk8s&lt;/CODE&gt;, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;k8s-extension&lt;/CODE&gt;, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;customlocation&lt;/CODE&gt;, and &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;containerapp&lt;/CODE&gt; extensions.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;An SMB file share&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Reachable from the cluster, for workflow artifacts.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;A spare IP range&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;A small unused range on your node's L2 network for MetalLB to hand out (Step 2).&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;az extension add --name connectedk8s
az extension add --name k8s-extension
az extension add --name customlocation
az extension add --name containerapp&lt;/PRE&gt;
&lt;H2&gt;Step 1: Stand up RKE2&lt;/H2&gt;
&lt;P&gt;One line and a couple of minutes:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;curl -sfL https://get.rke2.io | sudo sh -
sudo systemctl enable --now rke2-server.service

# kubectl + kubeconfig are dropped in place
export PATH=$PATH:/var/lib/rancher/rke2/bin
export KUBECONFIG=/etc/rancher/rke2/rke2.yaml
kubectl get nodes          # Ready in ~2-5 min after the first image pull&lt;/PRE&gt;
&lt;P&gt;RKE2 servers are schedulable by default, so this single node is your entire cluster. No taint to remove. If you want to run kubectl from your laptop, add the node's public IP or hostname to &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;tls-san&lt;/CODE&gt; in &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;/etc/rancher/rke2/config.yaml&lt;/CODE&gt; &lt;EM&gt;before&lt;/EM&gt; the first start, then copy &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;rke2.yaml&lt;/CODE&gt; out and swap &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;127.0.0.1&lt;/CODE&gt; for that address.&lt;/P&gt;
&lt;BLOCKQUOTE style="border-left: 4px solid #0067b8; background: #f0f7ff; margin: 20px 0; padding: 10px 16px; border-radius: 0 6px 6px 0;"&gt;
&lt;P&gt;&lt;STRONG&gt;Quick sanity check.&lt;/STRONG&gt; Expose a throwaway nginx as &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;LoadBalancer&lt;/CODE&gt;: &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kubectl create deploy nginx --image=nginx &amp;amp;&amp;amp; kubectl expose deploy nginx --port=80 --type=LoadBalancer&lt;/CODE&gt;. The &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;EXTERNAL-IP&lt;/CODE&gt; will sit at &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;&amp;lt;pending&amp;gt;&lt;/CODE&gt; forever. That's the gap MetalLB fills in the next step. Clean up the deployment and service when you're done looking.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Step 2: Give the ingress an IP with MetalLB&lt;/H2&gt;
&lt;P&gt;All the Logic Apps in this environment share a single Envoy ingress, and something has to give that service an IP. A cloud does it for you; on-prem, you pick one of two options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;In-cluster load balancer.&lt;/STRONG&gt; MetalLB (or Cilium, kube-vip, OpenELB) assigns an IP from a pool on your node network. Leave &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;envoy.serviceType=LoadBalancer&lt;/CODE&gt; in Step 4. This is what we did.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;External L4 load balancer in front of NodePort.&lt;/STRONG&gt; If you already run an F5, HAProxy, NetScaler, or an Azure Standard Load Balancer, keep using it. Set &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;envoy.serviceType=NodePort&lt;/CODE&gt; (plus &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;envoy.nodeHttpsPort&lt;/CODE&gt; / &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;envoy.nodeHttpPort&lt;/CODE&gt;) and point your LB at those NodePorts. Then pass the LB's VIP as &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;--static-ip&lt;/CODE&gt; in Step 6.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We went with MetalLB in L2 mode:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.14.9/config/manifests/metallb-native.yaml
kubectl wait --for=condition=Ready pods --all -n metallb-system --timeout=180s&lt;/PRE&gt;
&lt;P&gt;Then give it a pool from your node subnet and advertise it over L2:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
  name: hybrid-pool
  namespace: metallb-system
spec:
  addresses:
    - 192.168.1.240-192.168.1.250   # a spare range on your node network
---
apiVersion: metallb.io/v1beta1
kind: L2Advertisement
metadata:
  name: hybrid-l2
  namespace: metallb-system
spec:
  ipAddressPools:
    - hybrid-pool&lt;/PRE&gt;
&lt;P&gt;Two things to watch. The range should be free on your node subnet, and it must not collide with RKE2's cluster (&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;10.42.0.0/16&lt;/CODE&gt;) or service (&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;10.43.0.0/16&lt;/CODE&gt;) CIDRs. Re-run the throwaway &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;LoadBalancer&lt;/CODE&gt; test from Step 1; the &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;EXTERNAL-IP&lt;/CODE&gt; should now be one of your pool addresses.&lt;/P&gt;
&lt;BLOCKQUOTE style="border-left: 4px solid #0067b8; background: #f0f7ff; margin: 20px 0; padding: 10px 16px; border-radius: 0 6px 6px 0;"&gt;
&lt;P&gt;&lt;STRONG&gt;Running MetalLB on one cloud VM?&lt;/STRONG&gt; L2 mode ARPs the pool IPs on the node's network, but a cloud SDN won't route an unassigned IP to your NIC from the outside. It works fine for anything inside the cluster (kube-proxy programs the IP locally), but to hit envoy from outside the VM you'll need to &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;socat&lt;/CODE&gt;-forward the VM's public IP to the LB IP, or add the pool IP as a secondary ipconfig on the NIC. On real on-prem L2 you don't have to think about any of this.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Step 3: Connect the cluster to Azure Arc&lt;/H2&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;az connectedk8s connect --name &amp;lt;cluster&amp;gt; --resource-group &amp;lt;rg&amp;gt; --location &amp;lt;region&amp;gt;
kubectl get pods -n azure-arc      # all agents Running in a couple of minutes&lt;/PRE&gt;
&lt;BLOCKQUOTE style="border-left: 4px solid #0067b8; background: #f0f7ff; margin: 20px 0; padding: 10px 16px; border-radius: 0 6px 6px 0;"&gt;
&lt;P&gt;If your host is behind a strict egress policy, or in our case an internal MS VM with an inbound-deny NRMS policy, remember that Arc onboarding only needs &lt;EM&gt;outbound&lt;/EM&gt; connectivity and a &lt;EM&gt;local&lt;/EM&gt; kubeconfig. We ran the connect command on the VM itself using a system-assigned managed identity (&lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;az login --identity&lt;/CODE&gt;). No inbound port, no browser device-code prompt.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Step 4: Install the Container Apps extension&lt;/H2&gt;
&lt;P&gt;This is the extension that turns the cluster into a Logic Apps host. On RKE2 it's the plain command, with &lt;STRONG&gt;no&lt;/STRONG&gt; &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;Azure.Cluster.Distribution&lt;/CODE&gt; or &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;coreDNSVersion&lt;/CODE&gt; overrides. If you copy those from an OpenShift guide, the install will still succeed and then behave in mildly confusing ways.&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;az k8s-extension create \
  --resource-group &amp;lt;rg&amp;gt; --cluster-name &amp;lt;cluster&amp;gt; \
  --cluster-type connectedClusters --name logicapps-aca-extension \
  --extension-type Microsoft.App.Environment \
  --release-train stable --auto-upgrade-minor-version true --scope cluster \
  --release-namespace logicapps-aca-ns \
  --configuration-settings "Microsoft.CustomLocation.ServiceAccount=default" \
  --configuration-settings "appsNamespace=logicapps-aca-ns" \
  --configuration-settings "clusterName=&amp;lt;env-name&amp;gt;" \
  --configuration-settings "keda.enabled=true" \
  --configuration-settings "keda.logicAppsScaler.enabled=true" \
  --configuration-settings "keda.logicAppsScaler.replicaCount=1" \
  --configuration-settings "containerAppController.api.functionsServerEnabled=true" \
  --configuration-settings "functionsProxyApiConfig.enabled=true" \
  --configuration-settings "envoy.serviceType=LoadBalancer"&lt;/PRE&gt;
&lt;P&gt;Our first install came back "Succeeded", but half the pods were in &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;CrashLoopBackOff&lt;/CODE&gt;. &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;billing&lt;/CODE&gt;, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;containerapp-controller&lt;/CODE&gt;, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;keda-logicapps-scaler&lt;/CODE&gt;, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;mdm&lt;/CODE&gt;, and &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;log-processor&lt;/CODE&gt; all had the same line in their logs:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;The configured user limit (128) on the number of inotify instances has been reached&lt;/PRE&gt;
&lt;P&gt;These are .NET services with &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;FileSystemWatcher&lt;/CODE&gt; under the hood. The default &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;fs.inotify.max_user_instances=128&lt;/CODE&gt; on stock Ubuntu is comfortably below what the extension needs. Raise it on the node, delete the pods, done:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;sudo sysctl -w fs.inotify.max_user_instances=8192
sudo sysctl -w fs.inotify.max_user_watches=1048576
echo -e "fs.inotify.max_user_instances=8192\nfs.inotify.max_user_watches=1048576" | sudo tee /etc/sysctl.d/99-inotify.conf
kubectl delete pods --all -n logicapps-aca-ns&lt;/PRE&gt;
&lt;P&gt;After that everything came up green, and envoy grabbed a MetalLB address on its own. Confirm:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;az k8s-extension show -g &amp;lt;rg&amp;gt; --cluster-name &amp;lt;cluster&amp;gt; \
  --cluster-type connectedClusters --name logicapps-aca-extension \
  --query provisioningState -o tsv          # -&amp;gt; Succeeded
kubectl get svc microsoft-app-environment-k8se-envoy -n logicapps-aca-ns   # EXTERNAL-IP from your pool&lt;/PRE&gt;
&lt;H2&gt;Step 5: Create a custom location&lt;/H2&gt;
&lt;P&gt;Turn on the custom-locations feature, then create the location that ties the cluster, extension, and namespace together:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;az connectedk8s enable-features -n &amp;lt;cluster&amp;gt; -g &amp;lt;rg&amp;gt; \
  --features cluster-connect custom-locations \
  --custom-locations-oid $(az ad sp show --id bc313c14-388c-4e7d-a58e-70017303ee3b --query id -o tsv)

EXT_ID=$(az k8s-extension show -g &amp;lt;rg&amp;gt; --cluster-name &amp;lt;cluster&amp;gt; \
  --cluster-type connectedClusters --name logicapps-aca-extension --query id -o tsv)
CC_ID=$(az connectedk8s show -g &amp;lt;rg&amp;gt; -n &amp;lt;cluster&amp;gt; --query id -o tsv)

az customlocation create \
  --resource-group &amp;lt;rg&amp;gt; --name &amp;lt;custom-location&amp;gt; \
  --location &amp;lt;region&amp;gt; --host-resource-id $CC_ID \
  --namespace logicapps-aca-ns --cluster-extension-ids $EXT_ID&lt;/PRE&gt;
&lt;BLOCKQUOTE style="border-left: 4px solid #0067b8; background: #f0f7ff; margin: 20px 0; padding: 10px 16px; border-radius: 0 6px 6px 0;"&gt;
&lt;P&gt;One thing we tripped on: the extension type isn't offered in every Azure region. It's registered in &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;eastus&lt;/CODE&gt;, &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;westus&lt;/CODE&gt;, &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;westeurope&lt;/CODE&gt;, and a handful of others, but not &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;eastus2&lt;/CODE&gt; at the time of writing. The &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;connectedCluster&lt;/CODE&gt; resource's region is independent of where the node actually runs, so pick a supported one here.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Step 6: Create the connected environment&lt;/H2&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;CL_ID=$(az customlocation show -g &amp;lt;rg&amp;gt; -n &amp;lt;custom-location&amp;gt; --query id -o tsv)

az containerapp connected-env create \
  --resource-group &amp;lt;rg&amp;gt; --name &amp;lt;env-name&amp;gt; \
  --location &amp;lt;region&amp;gt; --custom-location $CL_ID&lt;/PRE&gt;
&lt;P&gt;Because MetalLB already put an &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;EXTERNAL-IP&lt;/CODE&gt; on the envoy &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;LoadBalancer&lt;/CODE&gt; service, the platform picks it up automatically. &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;--static-ip&lt;/CODE&gt; is only needed if you went the NodePort + external LB route in Step 2, in which case you pass your LB's VIP here.&lt;/P&gt;
&lt;H2&gt;Step 7: Configure cluster DNS&lt;/H2&gt;
&lt;P&gt;App hostnames like &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;*.&amp;lt;env&amp;gt;.&amp;lt;region&amp;gt;.k4apps.io&lt;/CODE&gt; need to resolve to the Envoy ingress &lt;EM&gt;from inside&lt;/EM&gt; the cluster. On AKS or OpenShift, &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;az containerapp arc setup-core-dns&lt;/CODE&gt; handles this. RKE2 isn't a supported distro on that command yet, so it's manual, but it's a small manual.&lt;/P&gt;
&lt;P&gt;The extension already writes the correct rewrite and forward rules into a &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;coredns-custom&lt;/CODE&gt; ConfigMap. What's missing is CoreDNS mounting that ConfigMap and importing it from the Corefile.&lt;/P&gt;
&lt;P&gt;We tried the direct route first: patch the Corefile ConfigMap, edit the Deployment to add the volume, restart. It works, right up until the next &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;rke2-server&lt;/CODE&gt; restart. RKE2's helm controller re-renders both objects from the chart and wipes your changes. The right way is a &lt;STRONG&gt;&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;HelmChartConfig&lt;/CODE&gt;&lt;/STRONG&gt;. The &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;rke2-coredns&lt;/CODE&gt; chart exposes &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;extraConfig&lt;/CODE&gt; (config outside the default zone block) and &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;extraVolumes&lt;/CODE&gt;/&lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;extraVolumeMounts&lt;/CODE&gt;, which is exactly what we need:&lt;/P&gt;
&lt;PRE style="background: #f6f8fa; border: 1px solid #d0d7de; border-radius: 6px; padding: 14px 16px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;# /var/lib/rancher/rke2/server/manifests/rke2-coredns-config.yaml
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: rke2-coredns
  namespace: kube-system
spec:
  valuesContent: |-
    extraConfig:
      import:
        parameters: /etc/coredns/custom/*.server
    extraVolumes:
      - name: custom-config-volume
        configMap:
          name: coredns-custom
          optional: true
    extraVolumeMounts:
      - name: custom-config-volume
        mountPath: /etc/coredns/custom&lt;/PRE&gt;
&lt;P&gt;Drop the file in &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;/var/lib/rancher/rke2/server/manifests/&lt;/CODE&gt;, or &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kubectl apply -f&lt;/CODE&gt; it (the helm controller watches both). Within a minute CoreDNS redeploys with the mount and the top-level &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;import&lt;/CODE&gt;. This time it survives restarts and RKE2 upgrades because the chart is now the source of truth.&lt;/P&gt;
&lt;P&gt;To verify, run &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;nslookup test.&amp;lt;env-domain&amp;gt;&lt;/CODE&gt; from a throwaway pod. You should get back the &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;microsoft-app-environment-k8se-envoy-internal&lt;/CODE&gt; ClusterIP.&lt;/P&gt;
&lt;BLOCKQUOTE style="border-left: 4px solid #0067b8; background: #f0f7ff; margin: 20px 0; padding: 10px 16px; border-radius: 0 6px 6px 0;"&gt;
&lt;P&gt;&lt;STRONG&gt;One last DNS thing: a &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kube-dns&lt;/CODE&gt; alias.&lt;/STRONG&gt; The Logic Apps platform locates cluster DNS by looking for a Service named &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kube-dns&lt;/CODE&gt; in &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kube-system&lt;/CODE&gt;. That's the convention on AKS, K3s, kubeadm, and most other distros. RKE2 uses &lt;CODE style="background: #e6eefc; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;rke2-coredns-rke2-coredns&lt;/CODE&gt; and doesn't ship the alias, so the platform can't find DNS. Symptom: revision calls come back as 502s. Fix: create the alias.&lt;/P&gt;
&lt;PRE style="background: #eef2f6; border: 1px solid #cdd7e1; border-radius: 6px; padding: 12px 14px; overflow: auto; font-family: Consolas,Menlo,'Courier New',monospace; font-size: 13px; line-height: 1.55; white-space: pre; color: #24292e;"&gt;apiVersion: v1
kind: Service
metadata: { name: kube-dns, namespace: kube-system, labels: { k8s-app: kube-dns } }
spec:
  selector: { k8s-app: kube-dns }
  ports:
    - { name: dns, port: 53, protocol: UDP, targetPort: 53 }
    - { name: dns-tcp, port: 53, protocol: TCP, targetPort: 53 }&lt;/PRE&gt;
&lt;P&gt;It's a plain Service. Nothing about it gets templated or overwritten, so it just stays put across reconciles and upgrades.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Step 8: Create and deploy a Logic App&lt;/H2&gt;
&lt;P&gt;Plumbing's out of the way. In the portal, create a new &lt;STRONG&gt;Logic App (Standard)&lt;/STRONG&gt; with the &lt;STRONG&gt;Hybrid&lt;/STRONG&gt; hosting option, point it at your connected environment, wire storage up to your SMB share, and create. Author the workflow the way you always would. The runs will execute on your RKE2 cluster instead of in Azure.&lt;/P&gt;
&lt;H2&gt;Troubleshooting: the RKE2 things we hit&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Symptom&lt;/th&gt;&lt;th&gt;Cause &amp;amp; fix&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Test &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;LoadBalancer&lt;/CODE&gt; / envoy stays &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;&amp;lt;pending&amp;gt;&lt;/CODE&gt;&lt;/td&gt;&lt;td&gt;No LB provider on the cluster. Install MetalLB (Step 2). RKE2 ships no ServiceLB.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Runtime pods &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;CrashLoopBackOff&lt;/CODE&gt; with &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;inotify instances ... reached&lt;/CODE&gt;&lt;/td&gt;&lt;td&gt;Node &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;fs.inotify.max_user_instances&lt;/CODE&gt; too low. Raise it to 8192 and restart the pods (Step 4).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Revision invoke returns &lt;STRONG&gt;502&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Platform can't find a &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kube-dns&lt;/CODE&gt; Service; RKE2's CoreDNS is under a different name. Add the alias (Step 7).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;App hostnames don't resolve inside the cluster&lt;/td&gt;&lt;td&gt;CoreDNS isn't loading &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;coredns-custom&lt;/CODE&gt;. Apply the &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;HelmChartConfig&lt;/CODE&gt; (Step 7).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Extension type "not registered in region"&lt;/td&gt;&lt;td&gt;The Arc cluster is in an unsupported region. Reconnect it in a supported one; it's independent of where the node runs (Step 5).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Cluster shows Arc &lt;STRONG&gt;Offline&lt;/STRONG&gt; after a reboot; &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;azure-arc&lt;/CODE&gt; pods &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;Unknown&lt;/CODE&gt;&lt;/td&gt;&lt;td&gt;Stale pods from an ungraceful stop. &lt;CODE style="background: #eff1f3; padding: 1px 5px; border-radius: 4px; font-family: Consolas,Menlo,'Courier New',monospace; font-size: .92em; color: #24292e;"&gt;kubectl delete pods --all -n azure-arc --force&lt;/CODE&gt; and they'll recreate and reconnect.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;References&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/azure/logic-apps/set-up-standard-workflows-hybrid-deployment-requirements" target="_blank"&gt;Set up Logic Apps Hybrid deployment&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/integrationsonazureblog/hybrid-logic-apps-deployment-on-red-hat-openshift/4534828" target="_blank"&gt;Hybrid Logic Apps on Red Hat OpenShift&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.rke2.io/" target="_blank"&gt;RKE2 documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://metallb.io/" target="_blank"&gt;MetalLB&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/azure/azure-arc/kubernetes/quickstart-connect-cluster" target="_blank"&gt;Connect a Kubernetes cluster to Azure Arc&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 23 Jul 2026 05:53:29 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-integration-services-blog/hybrid-logic-apps-on-rke2-a-self-managed-cluster-with-metallb/ba-p/4539846</guid>
      <dc:creator>anandgmenon</dc:creator>
      <dc:date>2026-07-23T05:53:29Z</dc:date>
    </item>
    <item>
      <title>Governance Is the New Bottleneck: What Agent 365 Means for Admins ?</title>
      <link>https://techcommunity.microsoft.com/t5/blog/governance-is-the-new-bottleneck-what-agent-365-means-for-admins/ba-p/4539884</link>
      <description>&lt;P&gt;Hi all , following up on my last post about token limits, I wanted to write about something that's been on my mind a lot lately: the sheer number of agents quietly showing up across our tenant. Not just the ones we built deliberately in Copilot Studio, but ones people spun up in Power Platform, ones connected through Teams, and a few I genuinely couldn't trace back to an owner when I went looking. That's the moment this topic stopped being theoretical for me.&lt;/P&gt;&lt;P&gt;For the last couple of years, the Microsoft AI conversation was mostly about capability -what can Copilot do, which model is better, how do I write a good prompt. That conversation hasn't gone away, but a second one has caught up to it fast: who's actually watching all of this. Microsoft's own 2026 Work Trend Index makes the shift explicit &amp;nbsp;this isn't about saving a few minutes in Outlook anymore, it's about organizations redesigning how work gets divided between people and agents. And the moment agents start acting semi-independently across your tenant, "how many do we have, and what are they allowed to touch" becomes a real operational question, not a hypothetical one.&lt;/P&gt;&lt;P&gt;That's exactly the gap Microsoft Agent 365 is built to close. It went generally available on May 1, 2026, alongside Microsoft 365 E7, and I think it's worth understanding properly especially if you're the one who ends up fielding the "wait, there's an agent doing what?" conversation.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;What Agent 365 Actually Is (and Isn't)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The first thing worth clearing up: Agent 365 doesn't build agents. That's still Copilot Studio's job, or Foundry, or whatever platform your team is using. Agent 365 is the layer that sits on top of all of that it's a control plane, not a construction tool. Think of it less like "another AI product" and more like the admin and security backbone that was honestly missing from the picture until now.&lt;/P&gt;&lt;P&gt;Microsoft frames it around three pillars: observe, govern, and secure. In practice, that means every agent in your tenant whether it was built in Copilot Studio, imported from AWS or Google Cloud, or even running locally on someone's Windows machine gets registered, gets its own identity through Microsoft Entra, and becomes something you can actually see and act on instead of just hoping it's behaving.&lt;/P&gt;&lt;P&gt;That identity piece is the part I think gets underrated. Each agent gets its own Entra Agent ID, the same way a human user would. That's a meaningful shift it means conditional access policies, auditing, and compliance tooling that already exist for people can now extend to agents instead of treating them as some invisible background process.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;Why This Matters Right Now&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Here's the honest version of what's been happening across a lot of organizations, including bits of what I've seen firsthand: agent creation has gotten easy. Almost too easy. Between Copilot Studio, Power Platform, and now agentic mode built directly into Word, Excel, and PowerPoint, it doesn't take much for someone in a business unit to spin up something that's technically an AI agent with access to real data without IT or security ever being looped in.&lt;/P&gt;&lt;P&gt;Microsoft has been fairly direct about this risk themselves, which I appreciated seeing in writing rather than just implied: the speed of agent development shows real value, but without guardrails, that pace turns into blind spots, lower ROI, and genuine security exposure. That's not vendor fear-mongering, that's just what happens when adoption outpaces oversight in any technology, and agents are no exception.&lt;/P&gt;&lt;P&gt;What makes this particular moment different from past "shadow IT" waves is that agents don't just store or move data they can act on it. An agent with the wrong scope isn't just a compliance footnote, it's something that could send an email, modify a file, or trigger a workflow on its own. That's a different risk category than an unsanctioned spreadsheet sitting in someone's OneDrive.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-15"&gt;What You Actually Get With Agent 365&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A few capabilities stood out to me as genuinely useful rather than just checkbox governance:&lt;/P&gt;&lt;P&gt;The overview dashboard gives you a real-time view of your entire agent fleet total registered agents, active users, connected platforms, runtime hours, and risk signals, all in one place. Before this, getting even a rough headcount of "how many agents exist in our tenant" was a manual, frustrating exercise.&lt;/P&gt;&lt;P&gt;Registry sync extends that visibility beyond Microsoft's own tools. It can pull in agents built on AWS Bedrock and Google Cloud, so you're not stuck with three different governance stories depending on where an agent happens to live. For organizations that are realistically never going to be 100% single-vendor, that matters.&lt;/P&gt;&lt;P&gt;Lifecycle actions install, publish, block, unblock, delete, reassign ownership are now available directly from the registry. That's a big deal operationally. Before, tracking down who owned a rogue or abandoned agent could turn into an actual investigation. Now it's a few clicks.&lt;/P&gt;&lt;P&gt;Local agent controls through Defender and Intune are rolling in too, extending management down to agents running on individual Windows endpoints, not just cloud-hosted ones. Given how much agent activity is starting to happen at the device level, this closes a gap that would've otherwise been a blind spot.&lt;/P&gt;&lt;P&gt;Conditional access for agents, through Entra, means you can apply the same kind of dynamic, granular access policies to agents that you'd apply to a human user which is really the whole philosophical shift Agent 365 represents: agents aren't a separate, ungoverned category anymore, they're first-class identities in your tenant.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;What This Means for Admins, Practically&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you're managing a tenant with any real Copilot or agent activity, here's where I'd actually start:&lt;/P&gt;&lt;P&gt;Don't wait for "full autonomy" to engage. It's tempting to think governance can wait until agents are doing something more dramatic than they are today. Microsoft's own guidance pushes against that &amp;nbsp;the advice is to establish visibility and guardrails early, while adoption is still accelerating, not after.&lt;/P&gt;&lt;P&gt;Get a real inventory first. Before writing new policies, it's worth just knowing what already exists. I'd genuinely bet most tenants have more agents running than the admin team could name off the top of their head. The overview dashboard is the fastest way to close that gap.&lt;/P&gt;&lt;P&gt;Loop in more than just IT. Agent 365 licensing and controls touch the M365 admin center, Entra, Defender, Purview, and Intune which means this isn't a single-team rollout. Security, compliance, and helpdesk all need to understand what's changing, especially the distinction between Frontier (preview, no production SLA) and GA (production-ready, supported).&lt;/P&gt;&lt;P&gt;Understand the licensing model before you scope a rollout. Agent 365 is licensed per human user — the person who manages, sponsors, or is served by an agent rather than per agent. It's available standalone at $15 per user per month, or bundled into Microsoft 365 E7. Worth mapping that against your actual agent-using population rather than assuming it's a flat cost per bot.&lt;/P&gt;&lt;P&gt;Treat this as incremental, not a one-time setup. Microsoft has said plainly that Agent 365's capabilities will keep evolving as adoption patterns and governance models mature. This isn't a project you finish and close out it's closer to how you'd think about identity and access management generally: ongoing, not a one-time rollout.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;The Bigger Shift Underneath All This&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What I find genuinely interesting about Agent 365 is what it signals about where Microsoft thinks this is all heading. They're not just selling a better Copilot anymore &amp;nbsp;they're positioning Microsoft 365 as the place where AI-driven work gets governed, regardless of which vendor's model or platform an agent actually runs on. Whether that's the right long-term answer for every organization is a fair thing to debate. But the underlying problem it's solving &amp;nbsp;that agents were multiplying faster than anyone's ability to see or control them &amp;nbsp;is real, and I don't think it's specific to Microsoft shops.&lt;/P&gt;&lt;P&gt;If your organization is building agents in Copilot Studio, experimenting with Foundry, or even just watching Copilot's agentic mode quietly take on more autonomous work in Word and Excel, this is worth getting ahead of. The teams that treat agent governance as a foundational layer now are going to have a much easier time scaling adoption later than the ones who bolt it on after something goes wrong.&lt;/P&gt;&lt;P&gt;Curious whether others are already rolling out Agent 365, or still in the "let's figure out how many agents we actually have" phase I suspect a lot of us are somewhere in between. Would love to hear how your organization is approaching this.&lt;/P&gt;&lt;P&gt;Cheers, and happy reading.&lt;/P&gt;&lt;P&gt;Surya Vennapusa-MCT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 01:48:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/blog/governance-is-the-new-bottleneck-what-agent-365-means-for-admins/ba-p/4539884</guid>
      <dc:creator>Surya_Narayana</dc:creator>
      <dc:date>2026-07-23T01:48:45Z</dc:date>
    </item>
    <item>
      <title>Reminder: Path to Production for Agents Webinar Series Starts Next Week</title>
      <link>https://techcommunity.microsoft.com/t5/azure-architecture-blog/reminder-path-to-production-for-agents-webinar-series-starts/ba-p/4539877</link>
      <description>&lt;P&gt;Next week, join Microsoft for the&amp;nbsp;&lt;STRONG&gt;Path to Production for Agents&lt;/STRONG&gt; webinar series—a free, six-session technical training designed to help organizations move from AI experimentation to secure, scalable, production-ready agent solutions. The series takes place &lt;STRONG&gt;July 27–28&lt;/STRONG&gt; and is aimed at architects, technical leaders, engineers, and AI practitioners looking to operationalize AI at enterprise scale.&lt;/P&gt;
&lt;P&gt;Across six expert-led sessions, you'll learn how to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Establish governance foundations for AI at scale&lt;/LI&gt;
&lt;LI&gt;Design production-ready AI platforms and landing zones&lt;/LI&gt;
&lt;LI&gt;Build reliable multi-agent architectures&lt;/LI&gt;
&lt;LI&gt;Implement AgentOps practices for deployment and observability&lt;/LI&gt;
&lt;LI&gt;Secure and govern AI systems&lt;/LI&gt;
&lt;LI&gt;Optimize performance, cost, and scalability&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each session includes proven Microsoft architecture patterns, real-world engineering guidance, and practical techniques you can apply immediately to accelerate your path from prototype to production.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Register today:&lt;/STRONG&gt; &lt;A href="https://aka.ms/AccelerateThePathToProduction" target="_blank"&gt;Path to Production for Agents Registration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Don't miss this opportunity to gain the knowledge and frameworks needed to confidently deploy production-grade AI agents at scale. We look forward to seeing you next week!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 00:15:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-architecture-blog/reminder-path-to-production-for-agents-webinar-series-starts/ba-p/4539877</guid>
      <dc:creator>brauerblogs</dc:creator>
      <dc:date>2026-07-23T00:15:07Z</dc:date>
    </item>
    <item>
      <title>Upcoming July 2026 Microsoft 365 Champion community call</title>
      <link>https://techcommunity.microsoft.com/t5/driving-adoption-blog/upcoming-july-2026-microsoft-365-champion-community-call/ba-p/4539865</link>
      <description>&lt;P&gt;Join our monthly calls to learn more about driving user enablement of Microsoft 365 services, including Microsoft 365 Copilot. All are welcome. Our next call is July 28, 2026, where we'll dive into Teams Meeting controls.&lt;/P&gt;
&lt;P&gt;Please note that our community calls are in the Teams webinar format, so&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;you must register&lt;/U&gt;&amp;nbsp;&lt;/STRONG&gt;to receive the link to join. The join link will be sent to you in email with your webinar registration confirmation.&amp;nbsp;The calls start at 5 minutes past the hour for both sessions (at 8:05 AM and 5:05 PM PT) and end at the top of the hour (9:00 AM and 6:00 PM PT, respectively).&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/M365ChampionCallAM" target="_blank"&gt;https://aka.ms/M365ChampionCallAM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/M365ChampionCallPM" target="_blank"&gt;https://aka.ms/M365ChampionCallPM&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The on-demand recording will be available on our&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/category/drivingadoption/events/drivingadoptionevents" data-lia-auto-title="Driving Adoption &amp;gt; Events pages" data-lia-auto-title-active="0" target="_blank"&gt;Driving Adoption &amp;gt; Events pages&lt;/A&gt;, as well as on our&amp;nbsp;&lt;A href="https://aka.ms/community/learning" target="_blank"&gt;Microsoft Community Learning&lt;/A&gt; YouTube channel. While our calls are open to everyone, you must be a member of the Microsoft 365 Champion Program in order to access the presentation materials - the access link is in the initial welcome email and the monthly newsletter emails sent the week before the community calls.&lt;/P&gt;
&lt;P&gt;If you have not yet joined our Champion community, &lt;A href="http://aka.ms/M365Champions" target="_blank"&gt;sign up here&lt;/A&gt; to get access to the monthly newsletters, calendar invites, and program assets (e.g., the presentations).&lt;/P&gt;
&lt;P&gt;Is there a topic you want us to bring? Share your feedback here: &lt;A class="lia-external-url" href="https://aka.ms/Microsoft365ChampionCallFeedback" target="_blank"&gt;https://aka.ms/Microsoft365ChampionCallFeedback&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;REMINDER:&lt;/STRONG&gt; Our community calls take a break in August and resume in September.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 22:43:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/driving-adoption-blog/upcoming-july-2026-microsoft-365-champion-community-call/ba-p/4539865</guid>
      <dc:creator>JessieHwang</dc:creator>
      <dc:date>2026-07-22T22:43:57Z</dc:date>
    </item>
    <item>
      <title>Azure Local expands SAN capabilities with iSCSI support</title>
      <link>https://techcommunity.microsoft.com/t5/azure-arc-blog/azure-local-expands-san-capabilities-with-iscsi-support/ba-p/4531999</link>
      <description>&lt;P&gt;As organizations modernize datacenters and accelerate migration from legacy virtualization platforms, flexibility in storage architecture has become a key requirement. Customers increasingly want to reuse existing storage investments, scale infrastructure independently, and choose the connectivity model that best fits their environment.&lt;/P&gt;
&lt;P&gt;Building on the general availability of Fibre Channel (FC) SAN support, Azure Local now introduces &lt;STRONG&gt;iSCSI SAN integration&lt;/STRONG&gt;, extending disaggregated architecture support to IP-based storage networks. With support for both Fibre Channel and iSCSI, Azure Local provides customers greater flexibility in how they modernize and scale their infrastructure while maintaining an Azure-consistent management experience.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Expanding disaggregated infrastructure&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;iSCSI support enables organizations to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Leverage existing IP-based storage networks&lt;/LI&gt;
&lt;LI&gt;Deploy cost-efficient disaggregated architectures without FC dependency&lt;/LI&gt;
&lt;LI&gt;Scale compute and storage independently&lt;/LI&gt;
&lt;LI&gt;Maintain an Azure-consistent management experience&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Architecture and deployment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Azure Local supports &lt;STRONG&gt;6-adapter configurations&lt;/STRONG&gt; to balance cost, performance, and resiliency:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;6 adapters&lt;/STRONG&gt;: enhanced performance and redundancy with dedicated iSCSI paths.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Today, iSCSI follows a &lt;STRONG&gt;manual configuration flow during deployment&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Local Deployment&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Azure Local supports two SAN deployment approaches:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Hybrid deployments (S2D + SAN)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Customers can attach external SAN storage to existing Azure Local deployments while continuing to use Storage Spaces Direct (S2D) for platform storage. This approach enables organizations to incrementally adopt SAN while reusing existing storage investments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disaggregated deployments (SAN-only)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Customers can also deploy Azure Local using external SAN storage as the primary storage platform for both infrastructure and workloads. This enables:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Independent scaling of compute and storage&lt;/LI&gt;
&lt;LI&gt;Fibre Channel or iSCSI connectivity&lt;/LI&gt;
&lt;LI&gt;Larger-scale infrastructure deployments&lt;/LI&gt;
&lt;LI&gt;Connected and disconnected deployment models&lt;/LI&gt;
&lt;LI&gt;Manage rising disk costs associated with hyperconverged architectures&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Additionally, customers can create local availability zones to align VM placement with physical infrastructure boundaries and support more granular workload placement. The deployment also validates connected SAN arrays against the supported vendor ecosystem, helping ensure a streamlined and fully supported experience.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Accelerating infrastructure modernization&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Azure Migrate now supports migration to Azure Local deployments that use external SAN storage, including NTFS-based volumes. This allows organizations to modernize compute infrastructure while preserving existing storage investments.&lt;/P&gt;
&lt;P&gt;Customers can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reuse existing SAN arrays and operational processes&lt;/LI&gt;
&lt;LI&gt;Minimize disruption during modernization projects&lt;/LI&gt;
&lt;LI&gt;Retain familiar storage architectures while adopting Azure Local&lt;/LI&gt;
&lt;LI&gt;Simplify migration from existing virtualization environments&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;What's next&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;iSCSI support represents another step in our broader vision for external storage on Azure Local. Our goal is to provide a comprehensive storage platform that spans deployment, operations, protection, and recovery.&lt;/P&gt;
&lt;P&gt;Looking ahead, we are investing in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Integration of iSCSI node configuration into cluster deployment to simplify the initial setup.&lt;/LI&gt;
&lt;LI&gt;Business Continuity and Disaster Recovery (BCDR) for SAN-backed workloads, including replication, failover, and failback capabilities between two external SAN attached or disaggregated Azure local clusters.&lt;/LI&gt;
&lt;LI&gt;Day-N storage management experiences that simplify monitoring, troubleshooting, and operational workflows.&lt;/LI&gt;
&lt;LI&gt;Replication management capabilities that provide visibility into recovery readiness, replication health, and workload mobility across environments.&lt;/LI&gt;
&lt;LI&gt;Expanding enterprise storage vendors ecosystem for Azure Local, helping customers adopt Azure Local while preserving their existing storage investments.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these investments will extend Azure Local beyond SAN connectivity and deployment to deliver a unified storage management experience across a broad ecosystem of enterprise storage solutions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;With iSCSI support, Azure Local now delivers a more complete SAN strategy—giving customers the flexibility to choose Fibre Channel or iSCSI, deploy hybrid or fully disaggregated architectures, and modernize infrastructure without abandoning existing storage investments.&lt;/P&gt;
&lt;P&gt;As we continue to invest in SAN management, replication, and disaster recovery, Azure Local is evolving into a comprehensive platform for enterprise storage and infrastructure modernization—from edge deployments to sovereign-scale datacenters.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 22:15:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-arc-blog/azure-local-expands-san-capabilities-with-iscsi-support/ba-p/4531999</guid>
      <dc:creator>saniya0307</dc:creator>
      <dc:date>2026-07-22T22:15:00Z</dc:date>
    </item>
  </channel>
</rss>

