azure arc
307 TopicsEpisode 2: Reduce restarts with Hotpatch for Windows Server 2025 | The Azure Arc Check-In
Once a month, the Azure Arc team releases an episode covering a new hybrid and multicloud management scenario. To request a topic or view additional episodes, visit aka.ms/the-azure-arc-check-in. Scenario: Your infrastructure team needs to apply monthly security updates across hybrid Windows servers, but every restart creates another maintenance window and potential workload interruption. Hotpatch can reduce that restart-driven effort while helping you keep eligible servers protected. Try now in Azure aka.ms/aaci-episode2 Why Hotpatch matters Security updates are essential, but coordinating restarts across a distributed server estate takes time and can disrupt workloads. Hotpatch updates Windows security code in memory, allowing eligible security updates to take effect without requiring a restart. For Azure Arc-enabled Windows Server 2025 machines, enabling and using Hotpatch is available at no additional charge. Hotpatch reduces restart frequency, but it does not eliminate every restart. Baseline updates and updates outside the Hotpatch program can still require one. Confirm that your server is eligible Before enabling Hotpatch, confirm that the machine meets the operating system, Azure Arc, and security prerequisites. The server must: Run Windows Server 2025 Standard or Datacenter, build 26100.1742 or later. Run a generally available release. Preview and Windows Server Insider builds are not supported. Meet the Azure Connected Machine agent prerequisites and be connected to Azure Arc. Support virtualization-based security and Virtual Secure Mode. Use Unified Extensible Firmware Interface (UEFI) with Secure Boot enabled. Be a Generation 2 virtual machine when hosted on Hyper-V. Windows Server 2025 Datacenter: Azure Edition follows a different path because Hotpatch is enabled by default and does not require Azure Arc connectivity. For the latest requirements, see Enable Hotpatch for Azure Arc-enabled servers. Verify Virtual Secure Mode Run the following PowerShell command on the server to check its Virtual Secure Mode status: Get-CimInstance -Namespace 'root/Microsoft/Windows/DeviceGuard' -ClassName 'win32_deviceGuard' | Select-Object -ExpandProperty 'VirtualizationBasedSecurityStatus' A result of 2 means Virtual Secure Mode is configured and running. If the result is not 2, resolve the prerequisite before enrolling the machine in Hotpatch. Enabling Virtual Secure Mode requires a server restart, so make that change during a planned maintenance window. Enable Hotpatch through Azure Arc After confirming the prerequisites, enroll the server from the Azure portal: Open Azure Arc, then select Machines. Select the eligible server. Select Hotpatch. Review the confirmation, then select Confirm. Allow about ten minutes for the changes to apply. Verify that enrollment completes and the status is no longer pending. The portal enrollment is intentionally short. Most of the work is making sure the server meets the prerequisites before you begin. Choose how to manage updates Hotpatch enrollment and update installation are separate. After enrollment, continue to manage available updates according to your organization's patch policy and change-control process. Supported options for Arc-connected machines include: Windows Update Azure Update Manager Group Policy SConfig Supported non-Microsoft patch-management solutions Choose the method that fits your existing operations model. Enrolling a server in Hotpatch does not, by itself, install every available update automatically. Plan for the restart cadence Hotpatch changes the monthly update rhythm, but restart planning still matters. Every three months, Microsoft releases a planned baseline with the latest cumulative update. Installing a baseline requires a restart. Hotpatch releases normally follow during the next two months, allowing eligible security updates to be applied without a restart. An unplanned baseline can replace a scheduled Hotpatch release when necessary and will also require a restart. Updates outside the Hotpatch program can require restarts as well, including: Nonsecurity Windows updates .NET updates Drivers Firmware Other non-Windows updates The practical operating model is fewer restart-driven maintenance windows, not a server that never needs to restart. FAQs 1. Does Hotpatch mean I never need to restart the server? No. Planned baselines arrive every three months and require a restart. Unplanned baselines and updates outside the Hotpatch program can also require restarts. Hotpatch reduces restart frequency for eligible security updates; it does not eliminate restart planning. See Hotpatch for Windows Server. 2. Is Hotpatch an extra-cost service for Azure Arc-enabled Windows Server 2025? Enabling and using Hotpatch on eligible Azure Arc-enabled Windows Server 2025 machines is available at no additional charge. Optional Azure management services may have separate pricing. 3. Does enrolling in Hotpatch install every update automatically? No. Enrollment makes the machine eligible to receive Hotpatch updates. Continue using Windows Update or a supported patch-management tool, such as Azure Update Manager, Group Policy, SConfig, or a non-Microsoft solution, to manage available updates according to your patch policy. 4. Can I use Hotpatch with Windows Server Core? Yes. Both Server Core and Server with Desktop Experience are supported when the machine meets all other Hotpatch prerequisites. 5. What does a Virtual Secure Mode status of 2 mean? For the documented Device Guard PowerShell query, a result of 2 means Virtual Secure Mode is configured and running. If you receive another result, resolve the prerequisite before attempting enrollment. Review the current Hotpatch enablement guidance and Hotpatch concepts and update cadence, then visit The Azure Arc Check-in for more episodes.171Views2likes0CommentsAzure Local Storage: Choose the Architecture That Fits Your Business
Organizations modernize infrastructure in different ways. Some prioritize a simple, integrated platform; others need to preserve SAN investments, scale storage independently, or support workloads with different storage requirements. In this post, we'll explore the storage options available in Azure Local, when to use each one, and the business benefits they unlock. One Platform, Multiple Storage Architectures Azure Local brings multiple storage choices into a consistent, cloud-connected platform experience. Hyperconverged Infrastructure (Storage Spaces Direct) Storage Spaces Direct (S2D) provides a hyperconverged architecture where compute and storage are integrated into the same cluster. This model is ideal for customers looking for streamlined deployment experience, with infrastructure managed as a single platform and fewer organizational dependencies. Disaggregated Architecture (SAN Only) Azure Local supports validated external storage arrays connected through Fibre Channel or iSCSI. This architecture enables organizations to leverage existing storage investments and advanced storage services while independently scaling compute to support higher-capacity requirements. This gives customers the flexibility to work with supported storage vendors—including Dell, HPE, Hitachi, Lenovo, NetApp, and Everpure—while using the Fibre Channel or iSCSI connectivity already supported by Azure Local. Hybrid Architecture (Storage Spaces Direct + SAN) Customers can also combine Storage Spaces Direct and external storage to support different workload requirements within the same environment. This approach offers maximum flexibility, allowing organizations to align storage choices with application needs. Which Storage Option Should You Choose? If your goal is... Consider Simple integrated infrastructure Hyperconverged Expand an existing Azure Local cluster storage capacity Hybrid Reuse existing storage investments Hybrid or Disaggregated Independent compute and storage scaling Disaggregated Consolidate storage across workloads Disaggregated Advanced storage efficiency capabilities Disaggregated Flexible workload placement Hybrid Traditional three-tier architecture modernization Disaggregated Minimize infrastructure replacement Disaggregated Higher-scale compute clusters with more than 16 nodes Disaggregated Ready to size your solution? Use ODIN for Azure Local to translate workload, resiliency, growth, compute, and storage requirements into an example solution design. Use ODIN as a planning aid and validate the proposed configuration against official Azure Local documentation and with your preferred hardware and storage partners. Before finalizing your design, review External storage support for Azure Local for supported architectures and protocols, and Supported SAN solutions on Azure Local for validated storage partners and configurations. Use the comparison above to identify the most suitable architecture, then use ODIN, official Azure Local documentation, and partner guidance to validate workload sizing, supported configurations, and operational requirements. Modern Infrastructure Demands More Storage Flexibility Storage architecture decisions increasingly depend on more than capacity and performance. Organizations must also account for operational processes, maintenance planning, existing infrastructure, efficiency services, resiliency, and expected growth. These priorities influence whether an organization chooses an integrated, disaggregated, or hybrid architecture—and which benefits matter most in its environment. The following benefits explain where external storage can add value within that decision. Benefits of External Storage with Azure Local Protect Existing Investments Many organizations already operate enterprise storage platforms that support critical business applications. Azure Local enables customers to modernize compute infrastructure while continuing to leverage existing storage investments, operational expertise, backup strategies, and storage management processes. Get More Value from Every Terabyte Storage efficiency is becoming increasingly important as organizations scale virtualized environments, desktop infrastructure, databases, and application workloads. Many enterprise storage platforms offer advanced services such as compression, deduplication, thin provisioning, and capacity optimization. Organizations can leverage these capabilities while maintaining consistent Azure Local management experience. Spend Less Time Maintaining Infrastructure Operational efficiency is often just as important as infrastructure capabilities. Because compute and storage are separated in SAN-based architectures, organizations can independently manage storage and compute infrastructure. This can help simplify maintenance planning and reduce storage-related operational activities during maintenance events. Customers frequently cite more predictable maintenance windows, simplified update planning, mature storage monitoring practices, and reduced operational complexity. Scale on Your Terms One of the primary reasons organizations adopt external storage is flexibility. In hyperconverged environments, compute and storage typically scale together. With disaggregated storage, organizations can expand storage capacity independently from compute resources. This can be particularly valuable when storage growth outpaces CPU or memory requirements. Designed for Enterprise Resiliency Azure Local pairs cloud-connected infrastructure with the storage maturity Windows Server has refined over many generations. For external storage, that means working with the same well-understood technologies you already rely on—Fibre Channel and iSCSI connectivity, MPIO, dual fabrics, redundant controllers, and Cluster Shared Volumes—applied to the Azure Local platform. Because these are proven, standard building blocks, you have the flexibility to design highly available storage that fits your existing SAN investments and operational practices, rather than adapt to an unfamiliar model. For implementation requirements and configuration steps—including Fibre Channel, iSCSI, MPIO, array-side configuration, and presenting SAN-backed volumes as Cluster Shared Volumes see : Connect an external storage array to Azure Local. Real-World Scenarios Streamlined Infrastructure for Distributed Locations Retail stores, branch offices, and back-office environments can use a hyperconverged architecture to run applications on an integrated compute and storage platform. This approach simplifies deployment and day-to-day operations for locations that need consistent infrastructure without dedicated storage teams. Flexible Workload Placement Manufacturing and healthcare organizations can use a hybrid architecture when some workloads are best served by integrated Storage Spaces Direct and others require external SAN capacity or established storage services. This allows application teams to place workloads on the storage option that best meets their performance, resiliency, and operational requirements. Modernizing while Preserving SAN Investments A manufacturing organization, financial institution, or enterprise datacenter with established SAN platforms and processes can use a disaggregated architecture to modernize compute without redesigning storage operations, retraining teams, or immediately replacing proven infrastructure. Scaling Storage as Data Needs Grow Data-intensive environments—including manufacturing, fintech, and enterprise datacenters—may find that storage capacity grows faster than compute demand. A disaggregated architecture allows them to scale storage and compute independently, helping optimize infrastructure investments over time. Cost and Licensing Considerations Azure Local uses a monthly service fee based on the deployment configuration: Hyperconverged deployments (S2D only): Compute and storage are integrated in the same cluster using Storage Spaces Direct, with no external SAN storage. A monthly service fee of $10 per physical core/month applies. Disaggregated (SAN only), and hybrid storage configurations (S2D with SAN): Disaggregated deployments use external SAN storage instead of Storage Spaces Direct, while hybrid deployments with external storage combine Storage Spaces Direct with external SAN storage. Using external SAN storage has a monthly service fee of $20.1 per physical core/month applies. Prices are subjected to change. For current pricing details and applicable terms, visit Azure Local Pricing | Microsoft Azure. Choosing the Right Fit for Your Business Start with the operating model and workload requirements you need to support, then choose the architecture that best fits them. Azure Local provides a consistent platform experience across hyperconverged, disaggregated, and hybrid deployments. That consistency lets organizations modernize without treating storage architecture as a one-time, irreversible choice. The right storage strategy is the one that fits your workloads, operations, and growth plans. Learn more: Storage Spaces Direct overview; External storage support for Azure Local; Supported SAN solutions on Azure Local; Connect an external storage array to Azure Local; Azure Local pricing; and Azure Hybrid Benefit for Azure Local.464Views2likes3CommentsMicrosoft Industrial AI Partner Guide: Choosing the Right Data Expertise for Every Stage
As organizations scale Industrial AI, the challenge shifts from technology selection to deciding who should lead which part of the journey -- and when. Which partners should establish secure connectivity? Who enables production grade, AI ready industrial data? When do systems integrators step in to scale globally? This Partner Guide helps customers navigate these decisions with clarity and confidence: Identify which partners align to their current digital transformation and Industrial AI scenarios leveraging Azure IoT and Azure IoT Operations Confidently combine partners over time as they evolve from connectivity to intelligence to autonomous operations This guide focuses on the Industrial AI data plane – the partners and capabilities that extract, contextualize, and operationalize industrial data so it can reliably power AI at scale. It does not attempt to catalog or prescribe end‑to‑end Industrial AI applications or cloud‑hosted AI solutions. Instead, it helps customers understand how industrial partners create the trusted, contextualized data foundation upon which AI solutions can be built. Common Customer Journey Steps 1. Modernize Connectivity & Edge Foundations The industrial transformation journey starts with securely accessing operational data without touching deterministic control loops. Customers connect automation systems to a scalable, standards-based data foundation that modernizes operations while preserving safety, uptime and control. Outcomes customers realize Standardized OT data access across plants and sites Faster onboarding of legacy and new assets Clear OT–IT boundaries that protect safety and uptime Partner strengths at this stage Industrial hardware and edge infrastructure providers Protocol translation and OT connectivity Automation and edge platforms aligned with Azure IoT Operations 2. Accelerate Insights with Industrial AI With a consistent edge-to-cloud data plane in place, customers move beyond dashboards to repeatable, production-grade Industrial AI use cases. Customers rely on expert partners to turn standardized operational data into AI‑ready signals that can be consumed by analytics and AI solutions at scale across assets, lines, and sites. Outcomes customers realize Improved Operational efficiency and performance Adaptive facilities and production quality intelligence Energy, safety, and defect detection at scale Partner strengths at this stage Industrial data services that contextualize and standardize OT signals for AI consumption Domain-specific acceleration for common Industrial AI scenarios Data pipelines integrated with Azure IoT Operations and Microsoft Fabric 3. Prepare for Autonomous Operations As organizations advance toward closed‑loop optimization, the focus shifts to safe, scalable autonomy. Customers depend on partners to align data, infrastructure, and operational interfaces, while ensuring ongoing monitoring, governance, and lifecycle management across the full operational estate. Outcomes customers realize Proven reference architectures deployed across plants AI‑ready data foundations that adapt as operations scale Coordinated interaction between OT systems, AI models, and cloud intelligence Partner strengths at this stage Industrial automation leadership and control system expertise Edge infrastructure optimized and ready for Industrial AI scale Systems integrators enabling end‑to‑end implementation and repeatability Data Intelligence Plane of Industrial AI - Partner Matrix This matrix highlights which partners have the deepest expertise in accessing, contextualizing, and operationalizing industrial data so it can reliably power AI at scale. The matrix is not a catalog of end‑to‑end Industrial AI applications; it shows how specialized partners contribute data, infrastructure, and integration capabilities on a shared Azure foundation as organizations progress from connectivity to insight to autonomous operations. How to use this matrix: Start with your scenario → identify primary partner types → layer complementary partners as you scale. Partner Type Adaptive Cloud Primary Solution Example Scenarios Geography Advantech Industrial Hardware, Industrial Connectivity LoRaWAN gateway integration + Azure IoT Operations Industrial edge platforms with built in connectivity, industrial compute, LoRaWAN, sensor networks Global Accenture GSI Industrial AI, Digital Transformation, Modernization OEE, predictive maintenance, real-time defect detection, optimize supply chains, intelligent automation and robotics, energy efficiency Global Avanade GSI Factory Agents and Analytics based on Manufacturing Data Solutions Yield / Quality optimization, OEE, Agentic Root Cause Analysis and process optimization; Unified ISA-95 Manufacturing Data estate on MS Fabric Global Belden Industrial Connectivity, Networking, Security Belden Horizon Data Operations (BHDO) + LioN-X with Azure IoT Operations OT-IT convergence, network orchestration and monitoring, ruggedized ethernet and switching, industrial WiFi, multi-vendor protocol connectivity, OT security, OPC UA Global Capgemini GSI The new AI imperative in manufacturing OEE, maintenance, defect detection, energy, robotics Global DXC GSI Intelligent Boost AI and IoT Analytics Platform 5G Industrial Connectivity, Defect detection, OEE, safety, energy monitoring Global Innominds SI Intelligent Connected Edge Platform Predictive maintenance, AI on edge, asset tracking North America, EMEA Litmus Automation Industrial Connectivity, Industrial Data Ops Litmus Edge + Azure IoT Operations Edge Data, Smart manufacturing, IIoT deployments at scale Global, North America Mesh Systems GSI & ISV Azure IoT & Azure IoT Operations implementation services and solutions (including Azure IoT Operations-aligned connector patterns) Device connectivity and management, data platforms, visualization, AI agents, and security North America, EMEA Nortal GSI Data-driven Industry Solutions IT/OT Connectivity, Unified Namespace, Digital Twins, Optimization, Edge, Industrial Data, Real‑Time Analytics & AI EMEA, North America & LATAM NVIDIA Technology Partner Accelerated AI Infrastructure; Open libraries, models, frameworks, and blueprints for AI development and deployment. Cross industry digitalization and AI development and deployment: Generative AI, Agentic AI, Physical AI, Robotics Global Oracle ISV Oracle Fusion Cloud SCM + Azure IoT Operations Real-time manufacturing Intelligence, AI powered insights, and automated production workflows Global Rockwell Automation Industrial Automation FactoryTalk Optix + Azure IoT Operations Factory modernization, visualization, edge orchestration, DataOps with connectivity context at scale, AI ops and services, physical equipment, MES Global Schneider Electric Industrial Automation Industrial Edge Physical equipment, Device modernization, energy, grid Global Siemens Industrial Automation & Software Industrial Edge + Azure IoT Operations reference architecture Industrial edge infrastructure at scale, OT/IT convergence, DataOps, Industrial AI suite, virtualized automation. Global Sight Machine ISV Integrated Industrial AI Stack Industrial AI, bottling, process optimization Global Softing Industrial Industrial Connectivity edgeConnector + Azure IoT Operations OT connectivity, multi-vendor PLC- and machine data integration, OPC UA information model deployment EMEA, Global TCS GSI Sensor to cloud intelligence Operations optimization, healthcare digital twin experiences, supply chain monitoring Global This Ecosystem Model enables Industrial AI solutions to scale through clear roles, respected boundaries and composable systems: Control systems continue to be driven by automation leaders Safety‑critical, deterministic control stays with industrial automation partners who manage real‑time operations and plant safety. Customers modernize analytics and AI while preserving uptime, reliability, and operational integrity. Data, AI, and analytics scale independently A consistent edge to cloud data plane supports cloud scale analytics and AI, accelerating insight delivery without entangling control systems or slowing operational change. This separation allows customers and software providers to build AI solutions on top of a stable, industrial‑grade data foundation without redefining control system responsibilities. Specialized partners align solutions across the estate Partners contribute focused expertise across connectivity, analytics, security, and operations, assembling solutions that reduce integration risk, shorten deployment cycles, and speed time to value across the operational estate. From vision to production Industrial AI at scale depends on turning operational data into trusted, contextualized intelligence safely, repeatably, and across the enterprise. This guide shows how industrial partners, aligned on a shared Azure foundation, create the data plane that enables AI solutions to succeed in production. When data is ready, intelligence scales. Call to action: Use this guide to identify the partners and capabilities that best align to your current Industrial AI needs and take the next step toward production‑ready outcomes on Azure.2KViews4likes0CommentsWorkload Orchestration in the Azure portal is now available: Deploy in minutes, scale with ease
Edge deployments rarely stay simple for long. What begins as an application running on a single Kubernetes cluster can quickly expand across stores, factories, branches, or other distributed locations, each having different configuration needs. That is exactly where workload orchestration for Azure Arc comes in. Workload orchestration helps teams manage that complexity by providing a centralized approach to consistently define, configure, and deploy applications across distributed cloud, on-premises, and edge environments, all while catering to custom configuration needs of individual sites and deployment targets. See the experience in action Evaluating a new deployment approach often starts slowly: study the documentation, package an application, complete the setup, and only then decide whether it fits. The Azure portal reverses that order with its jumpstart onboarding experience. Bring your Azure Arc-enabled Kubernetes cluster and deploy a pre-packaged application in minutes. Whether you are validating a proof of concept or introducing the product to your broader team, the new portal onboarding experience turns the end-to-end workflow into something you can quickly try on your own cluster. Scale from first deployment to production Once you have validated the first deployment, you can evolve the same approach for production. Onboard your infrastructure into workload orchestration, organize your deployment sites into hierarchies, and define shared configurations for all deployments – all without leaving the portal. This lets you expand from one cluster to a distributed fleet while retaining centralized governance, repeatability, and site-level flexibility. Ready to try it? Try now by deploying your first application with workload orchestration in the Azure portal. Explore the product documentation for the complete set of capabilities.403Views0likes0CommentsScaling Industrial AI at the Edge with Helin and Azure IoT
Remote industrial sites generate operational data continuously, but the ability to act on that data in near real time can be challenging. Bandwidth is often limited; connectivity is inconsistent, and the analysis needed to turn raw signals into insight typically depends on cloud connection. When worker safety is on the line, that gap matters even more, since a person entering a hazardous zone has to be detected and flagged on site independent of a cloud connection. Meeting those conditions calls for a secure, repeatable foundation, one that trains models in the cloud, runs inference locally, governs distributed edge devices, and turns the right signals into insight. Helin Data built that foundation: an edge-to-cloud platform that combines local inference, industrial data collection, and fleet observability on Azure. RedZone, Helin's vision AI application for hazardous-zone monitoring, is the first proof point of this platform. It uses the CCTV cameras already installed on a rig to detect when a person enters a defined danger zone around active equipment, triggering a local alert through an on-site interface and status lights, and logging the event for later safety and operational analysis. Because inference runs at the edge, RedZone can detect and alert without waiting on a connection to the cloud, while Azure handles centralized management, analysis, and model lifecycle activities. What sets this solution apart Designed for constrained environments – Inference runs directly on the edge box, so RedZone keeps detecting and alerting even through network outages, with no dependence on the cloud at runtime. Only priority events and metadata detected by RedZone sync to Azure, which keeps bandwidth use low on a constrained connection such as satellite connectivity used at some offshore sites. Secure, scalable fleet governance – Devices onboard automatically through Device Provisioning Service (DPS) with per-device X.509 certificates. Every device is listed in Azure Device Registry (in preview) and projected as native ARM resources, so updates and configuration changes can be targeted, governed, and audited using standard Azure tooling. Helin adds multi-level security, including public key infrastructure (PKI), data encryption, and industry-trusted authentication, protecting data as it moves from the rig to the cloud. Helin's observability layer spans device health, firmware updates, application status, and the data pipeline, so organizations can promptly identify and investigate potential issues across the edge-to-cloud pipeline. A closed edge-to-cloud AI loop – Models are trained and versioned in Azure Machine Learning, then deployed to the edge for local inference. Detections stream back into Microsoft Fabric, where the data can inform model evaluation and future model versions, closing the loop between the field and the cloud. A reusable application foundation – RedZone runs on the same platform and loop that can be adapted for additional customer scenarios. A different hazard, a different zone, or a different operational question can become its own application. Delivering a governed device fleet Azure IoT Hub and DPS provide secure device connectivity, messaging, and automated provisioning. The Azure IoT Hub integration with Azure Device Registry, currently in public preview, represents devices as Azure resources, providing a foundation for Azure-native fleet inventory and governance. Together, these services help Helin onboard, connect, and manage distributed edge deployments. Azure Device Registry (public preview with Azure IoT Hub): Provides the management plane, representing each device as an Azure Resource Manager resource so it can be governed with the same patterns used for other Azure resources including role-based access control, resource groups, tags, and resource-level management, with namespaces acting as the organizational and security boundary. Azure Device Registry integration with Azure IoT Hub and Microsoft-backed X.509 certificate management is in public preview and is not recommended for production workloads. Azure IoT Hub and DPS: Deliver secure onboarding and bidirectional messaging between the devices and the cloud. Helin Data Edge Inference and Data Collector: Runs vision AI inference at the edge and connects into the industrial control systems already on site, so each detection carries operational context. Industrial data is collected, contextualized, buffered, and filtered locally before important signals are sent to Azure. Microsoft Fabric: Ingests telemetry and turns it into an operational model for analysis and reporting, giving organizations clearer insight into their operations. Customer Impact This solution is already proven in a demanding industrial environment. When Helin Data implemented RedZone on Noble’s Maersk Discoverer rig, RedZone detected a person entering a hazardous zone and raised an alert in roughly 150 milliseconds. Processing the detection locally is particularly important offshore, where limited connectivity makes a cloud-dependent response impractical. Helin’s broader edge platform is already supporting Noble across its operations. The offshore drilling contractor, which operates a fleet of more than 40 rigs, uses Helin’s Remote CCTV Manager to provide authorized personnel with live video from more than 20 rigs. Reduced resolution streams sync to Noble’s secure Azure environment for viewing while full resolution recordings stay at the rig to reduce bandwidth use. Together, these examples demonstrate the broader platform pattern: process high-volume data locally, transmit the signals that matter, and centrally manage applications deployed across a distributed industrial fleet. Closing RedZone shows what becomes possible when Azure IoT Hub is used as more than a device-connectivity service. Combined with secure provisioning, Azure-native device governance, edge inference, model lifecycle management, and Microsoft Fabric, it becomes part of a repeatable platform for building and operating industrial AI applications at scale. For customers, the value extends beyond a single safety scenario. The same foundation can support new applications across worker safety, operational visibility, process improvement, and other industrial use cases, without rebuilding the underlying device and data infrastructure each time. Helin brings the industrial application expertise; Azure provides the scalable foundation on which those applications can be deployed, governed, and continuously improved. Take the next step Read the customer case study, Improving safety across a fleet of drilling rigs Learn more about RedZone in Seeing the Human Layer: Helin Brings Edge Vision AI to Industrial Operations on Azure. Explore Helin’s Intelligent Edge Application Platform is now available in Azure Marketplace Resources Deploy Azure IoT Hub with Device Registry integration and certificate management (preview) Azure IoT Hub Documentation Product documentation | Helin Documentation516Views0likes1CommentHow Mesh Systems Builds on Azure IoT Hub and Azure IoT Operations to Accelerate Industrial AI
Manufacturers generate vast amounts of operational data, yet its complexity and fragmentation across historians, Operational Technology (OT) systems, and cloud platforms can slow AI adoption at scale. As organizations invest in AI to enhance productivity, quality, and decision making, the ability to connect and contextualize operational data becomes critical. Azure IoT Hub, Azure IoT Operations, and Mesh address this challenge together, spanning the full path from device connectivity to actionable AI-powered insights. Mesh brings deep Azure IoT platform experience and a practical path to industrial AI, with MeshCloud built on Azure IoT Hub, an open-source .NET Akri framework for Azure IoT Operations, and MeshInsights delivering generative AI-powered operational intelligence. This expertise is backed by a long history with Azure; Mesh launched its first IoT solution on Azure in private preview in 2009 and remained an early adopter of every major Azure IoT service since. Together, Azure IoT Hub, Azure IoT Operations, and Mesh give manufacturers a streamlined way to unify operational data and apply AI where it matters most. Unlocking legacy data with Mesh's Akri Connector Industrial organizations often struggle to modernize operations because critical operational data sits isolated inside historians and legacy Operational Technology (OT) systems. Many manufacturers are also wary of integrations that create new dependencies and limit future flexibility. Azure IoT Operations addresses this through an open architecture built around Akri, connecting industrial data sources while preserving interoperability across hardware and software environments. Mesh built on this foundation with its Akri Historian Connector, bringing historian and legacy operational data into Azure IoT Operations through prebuilt connectivity rather than source-by-source integration work. The result is faster access to operational data ready for analytics, AI, and industrial automation. The key features of this connector include: Restart-safe data continuity: Manufacturers can trust that operational data keeps flowing even through outages or restarts, with no data loss and no time spent recovering or reprocessing data. Secure, flexible authentication: Modern and legacy industrial systems connect under one security model, meeting enterprise-grade authentication standards without restructuring existing infrastructure. A foundation other connectors can be built on: The underlying framework handles the heavy lifting, so teams only need to build what's unique to each new OT data source. This means faster time to value for every new data source. Built in alignment with Azure IoT Operations roadmap: The connector stays up to date automatically, as new Azure IoT Operations features become available. This means manufacturers have access to the latest capabilities as the platform evolves. Together, Mesh and Azure IoT Operations give organizations a production-ready path from the shop floor into Azure IoT Operations and onward to Microsoft Fabric. Delivering Scalable Connected Products with Azure IoT Hub and MeshCloud MeshCloud helps manufacturers move from connected product pilots to fleet scale deployments faster by providing a platform build on Azure IoT Hub and other Azure native services. Azure IoT Hub provides per-device identity, support for MQTT, AMQP, and HTTPS, and built-in capabilities like device twins, direct methods, and rules-based message routing. Azure Device Provisioning Service (DPS) extends this foundation with zero-touch, just-in-time onboarding using X.509, TPM, or symmetric key attestation. Mesh operates as one cohesive engineering practice across the full connected product lifecycle, delivering hardware, firmware, wireless, edge, and cloud integration natively for Azure IoT Hub and Azure IoT Operations. That end-to-end scope is what MeshCloud, their Azure-native connected product platform, brings together. MeshCloud embeds Azure IoT Hub and DPS into an Azure-native connected product platform, giving organizations a faster path to connected product delivery without sacrificing control, scale, or solution ownership. The platform comes together across four layers: Edge to cloud: Connected devices, from MCU controllers to tablets and phones, register and authenticate through DPS and connect securely to IoT Hub, giving organizations a direct, secure line from shop floor to enterprise systems. Messaging and command: Event Hubs and Container Apps move telemetry and commands between devices and the cloud, with asset and ontology data exposed for digital twin management and device control. IT and operations: Azure Monitor, OpenTelemetry, Microsoft Entra, and Application Gateway bring platform observability, identity management, and secure ingress together, equipping IT and operations teams with a unified way to manage and secure the environment. Analytics and visualization: Telemetry flows into Azure Data Explorer and Microsoft Fabric for processing and storage, with Grafana, Power BI, and a Device Health UI giving teams fleet-wide visibility. This architecture enables organizations to move from pilot projects to fleet-scale deployments using Azure-native services, while maintaining interoperability across devices, connectivity protocols, and analytics platforms. For manufacturers, this means less time integrating infrastructure and more time delivering operational insights, connected services, and AI-powered workflows. Advancing Industrial Intelligence with MeshInsights As organizations connect more assets and operational systems, the next challenge becomes turning information into consistent actions and decisions. Microsoft Azure provides the cloud, data, and AI foundation for intelligent operational workflows, while giving organizations control over their data and business processes. Mesh extends this foundation through MeshInsights. MeshInsights is Mesh's AI agent offering for connected-product manufacturers. Mesh works with organizations to define a specific operational decision worth automating, such as classifying an alert or determining the right service response, and builds an evaluation standard from real telemetry, service history, and expert-validated examples. AI agents are then developed and measured against that standard, acting automatically on high-confidence cases and routing the rest to the organization's own experts. This extends connected systems beyond monitoring and reporting into trusted, auditable operational decisions. By combining Azure IoT platform services with MeshInsights, Mesh helps organizations move from connected infrastructure to autonomous, AI-driven action without changing where their data lives or who owns the architecture. Why This Matters Industrial transformation increasingly depends on strong collaboration between hyperscale cloud platforms and ecosystem partners who bring operational expertise, deployment acceleration, and industry-specific engineering capabilities. Mesh Systems demonstrates how partners can build differentiated value on top of Azure IoT platform services while helping organizations accelerate deployment timelines, standardize industrial data architectures, and operationalize AI across connected environments. Organizations are already putting this value to work in everyday operations. BUNN's cloud-connected coffee machines now give technicians a head start before every service call. As Kurt Powell, Executive Vice President at BUNN, put it: "With this solution, we know exactly which component to fix before we get there." WLS Lighting Systems has turned that same visibility into measurable savings at scale. Built on MeshCloud and Azure IoT, WLS's netLiNK gives property owners remote monitoring and control over individual light fixtures. Kevin Fletcher, President National Accounts at WLS, shared that the company has saved customers a little over $50 million in electrical costs since bringing netLiNK to market. Together, Azure IoT Hub, Azure IoT Operations, and Mesh Systems help manufacturers reduce integration complexity and operationalize industrial data, creating a foundation for AI driven operations spanning plant, edge, and cloud. The result: manufacturers spend less time on integration and more time improving productivity, resiliency, and decision making across their operations. Learn More Explore Mesh Systems solutions on Azure Marketplace: https://marketplace.microsoft.com/en-us/product/saas/mesh-systems.cloud?tab=Overview Read customer success stories: https://meshsystems.com/case-study-eaton-1/ Learn more about Azure IoT Operations: https://azure.microsoft.com/products/iot-operations/534Views1like0CommentsGenerally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing
Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program by specifying their Volume Licensing entitlements (Invoice Ids) in provisioning new Azure Arc WS2012/R2 ESU licenses. Extended Security Updates afford customers with critical security patches for end of support Windows Server 2012/R2 machines.6.2KViews3likes4CommentsFive Key Updates on WS2012 ESUs enabled by Azure Arc
We’re excited to announce the public preview of the Azure Arc ESU Usage View and Transition Scenario from Year 1 Volume Licensing. Additionally, we have made a breadth of improvements to pre-requisites, billing service, and included capabilities.4.2KViews4likes3Comments