infrastructure (azure)
18 TopicsComing soon: the Frontier Partner specialization
One of two Frontier-focused offerings in the Microsoft AI Cloud Partner Program, the Frontier Partner specialization validates partners who can design, build, deploy, govern, and secure AI agents across the Microsoft tech stack, including Microsoft 365 Copilot, Azure AI Foundry, GitHub Copilot, Microsoft Defender, Entra, and Purview. Partners who earn this specialization signal their deep expertise to customers—and get access to badging, priority search, and skill-aligned benefits such as: Eligibility for Frontier-aligned co-sell opportunities Microsoft Agent prepurchase plan credits and Microsoft 365 E7 licensing Packaged go-to-market resources including marketing campaigns and case study opportunities Microsoft AI Cloud Partner Program Concierge support through the qualification process The specialization will be open for enrollment later in FY27, but you can start preparing now. Requirements across three components must be met simultaneously under the same Partner Global Account: Specializations: Partners must hold the following four prerequisite specializations: Microsoft 365 Copilot, AI Apps on Microsoft Azure OR AI Platform on Microsoft Azure, Data Security, and Identity and Access Management. Skilling: Five individuals from your organization must complete the Frontier Transformation Engineer badge; three individuals must earn the Fabric Analytics Engineer Associate (DP-600) certification. The people who hold the badge and the certification can be the same or different. Audit: You must get a third-party audit validating delivery capability across design, build, deploy, govern, secure, and operate. There is a two-year audit cadence. Review the walking deck for more details on this exciting opportunity.418Views0likes0CommentsIt's now easier to attain the Microsoft Azure VMware Solution specialization
To expand the specialization opportunity to more partners, Microsoft has removed the Azure VMware Solution (AVS) technical assessment requirement from the Microsoft AVS specialization. This change makes both attaining and renewing the specialization significantly easier for partners. VMware is a leading provider of on-premises virtualization. As more organizations evaluate moving parts of their server-virtualization workloads to the cloud, this creates a meaningful opportunity for partners to guide migration plans aligned to security best practices and relevant regulatory requirements. The Microsoft AVS specialization showcases your authority in helping customers migrate on-premises VMware workloads to Azure. If you do not yet hold the Microsoft AVS specialization, we encourage you to pursue it now. Partners approaching their renewal window can also begin the renewal process today. Visit Partner Center to review the status of the Microsoft Azure VMware Solution specialization.309Views0likes0CommentsStand out as an authority on cloud sovereignty with the Digital Sovereignty specialization
The Digital Sovereignty specialization is designed to drive meaningful business outcomes. It differentiates your organization as a sovereign cloud leader, building trust with customers in compliance-heavy regions. It also opens access to high-value projects in regulated industries such as government, defense, banking, and healthcare. The Digital Sovereignty specialization supports business growth by highlighting value-added services capabilities with higher margins in digital sovereignty. Finally, it signals proven delivery capability on sensitive cloud deployments, fostering strong client relationships. To enroll, meet the five specialization prerequisite requirements across Security, Azure, and Modern Work. Once eligible, respond to Microsoft outreach and schedule a third-party audit, demonstrating recent sovereign cloud projects. Then, maintain the specialization by continuing to meet prerequisites annually and passing the audit every two years. Don't miss this opportunity to tap into incredible business value and access exciting opportunities based on the capabilities and knowledge you already have.396Views0likes0CommentsUpdated requirements for the SAP on Microsoft Azure specialization
The SAP on Microsoft Azure specialization is a credential that validates your deep expertise in planning, migrating, and operating SAP (Systems, Applications, and Products in Data Processing) workloads on Microsoft Azure. Microsoft is updating this specialization to make it more accessible for a broader range of partners. These changes are designed to expand opportunity—making it possible for more organizations to demonstrate SAP on Azure expertise, earn official Microsoft recognition, and unlock exclusive go-to-market advantages that strengthen differentiation in a competitive market. What's changed Lower ACR threshold: Beginning in January 2026, the Azure consumed revenue (ACR) requirement decreased from $30,000 to $7,500,* totaled over three months, significantly reducing the barrier to entry while maintaining a high standard of technical capability. Streamlined skilling validation: Partners can validate required Microsoft learning coursework directly within Partner Center, removing the need to do so in the third-party audit for this specialization. Skilling requirements may be met through either: The Azure for SAP Workloads Specialty certification. Completion of the Run SAP on the Microsoft Cloud learning path. This simplified approach accelerates the path to earning the specialization. Next actions Visit Partner Center to review the updated SAP on Microsoft Azure specialization requirements and apply or renew. *Throughout this document, $ refers to US dollar (USD).416Views0likes0CommentsUpdated requirements for Microsoft Azure VMware Solution specialization
Updated requirements for the Microsoft Azure VMware Solution (AVS) specialization make it simpler to obtain—offering a path to showcase your unique capabilities and technical expertise. What's changed We removed the requirement to pass the outdated AVS technical assessment to earn the specialization. We also removed the Broadcom certification requirements, which were previously checked as a portion of the audit. Highlights of the specialization Show customers you're uniquely qualified to migrate VMware workloads to Azure with the AVS specialization. Highlights include: Verified expertise badge. Priority listing in Microsoft directories. Access to incentives and co-sell programs. Visit Partner Center to verify that you meet the new AVS specialization requirements, then apply or renew today.273Views0likes0CommentsBuild Your Microsoft Ignite Schedule: Top Sessions for Solution Architects
Get Ready for Microsoft Ignite Welcome back to our Azure Tech Community Microsoft Ignite 2025 series! If you joined us for Your Guide to Azure Community Activations at Microsoft Ignite 2025, you already know that Microsoft Ignite isn’t just about product updates, it’s where ideas, innovation, and community come together. With hundreds of sessions to choose from, it can be hard to know where to focus. That is why we have curated a list of sessions tailored specifically for Solution Architects to help you plan your week, strengthen your technical design strategy, and stay ahead of the latest advancements in Azure. Use the Microsoft Ignite session scheduler feature in the session catalog to personalize your agenda, save your favorites, and organize your time at Microsoft Ignite. Make Every Minute Count: Top Recommended Sessions for Solution Architects Microsoft Ignite moves fast, so it pays to plan your path before you arrive. By organizing your schedule around your interests and goals, you’ll be able to maximize learning opportunities, connect with peers, and leave with actionable insights. The recommendations below highlight our top picks for architects who want to design scalable, secure, and future-ready cloud environments. From start to scale: Realize agentic AI value (BRKSP464) Learn how to plan and scale intelligent systems built on Microsoft’s Agentic AI framework, combining performance, governance, and responsible design principles. Unleashing SAP Databricks on Azure: Modernize, analyze, and innovate (BRK136) Explore how Azure and Databricks integrate with SAP to deliver a high-performance data architecture for enterprises. Migrate and Modernize Windows and SQL Server Workloads to Azure (LAB506-R1) See how Azure’s modernization framework enables secure, scalable, and cost-efficient migration for enterprise systems. Innovation Session: Security in the Agentic Era – the Core Primitive (BRK1712) Gain a forward-looking perspective on how the rise of Agentic AI will reshape the security landscape for IT operations and enterprise systems. Microsoft Purview Compliance Manager: AI Compliance & Resilience (THR750) Learn how Microsoft Purview leverages AI to simplify compliance management, automate risk assessments, and streamline audits for hybrid and multi-cloud environments. Before diving into your developer sessions, make time for these essential moments that set the stage for everything happening at Microsoft Ignite. Opening Keynote (KEY01) Hear from Microsoft leaders as they unveil the latest innovations shaping the future of AI, cloud, and the developer ecosystem. This is the session that sets the tone for the entire event. Innovation Session: Scale Smarter: Infrastructure for the Agentic Era (BRK1704) Dive into what’s new in Azure Infrastructure—from compute and networking to hybrid management and scalability. Hear from Azure engineering experts on best practices and innovations for modern cloud operations. Innovation Session: Microsoft Fabric and Azure Databases - the data estate for AI (BRK1702) See how Azure Data services—spanning databases, analytics, and governance—empower organizations to unify data, build intelligent apps, and unlock insight-driven decision-making at scale. Plan Smarter with the Session Scheduler With the “add to schedule” feature in the session catalog you’ll be able to: Browse and filter all Microsoft Ignite sessions by topic, product, or persona. Save your favorite sessions to build a personalized schedule. Set reminders and block time for networking, community booths, and demos. Stay Connected with the Azure Tech Community Your Microsoft Ignite journey doesn’t stop when the sessions end, the conversation continues across the Azure Tech Community.Share the sessions you are most excited about using #MSIgnite and #AzureTechCommunity, tag azure, and connect with other architects exploring the future of cloud design and intelligent infrastructure. Follow the Azure Tech Community for real-time updates, photos, and highlights throughout Microsoft Ignite. See You at Microsoft Ignite 2025 With the right plan in place, every session becomes an opportunity to learn, grow, and connect. Explore these recommendations, save your favorites, and get ready for an unforgettable Microsoft Ignite 2025 experience.1.2KViews1like0CommentsShowcase your deep sovereignty expertise with the new Digital Sovereignty specialization
As announced on November 6 during our AI Tour, we're excited to introduce the Digital Sovereignty specialization. We designed this specialization so partners can capitalize on rising demand for sovereign cloud solutions as governments and critical industries seek data sovereignty and security in response to global uncertainty. This is a key growth opportunity as market demand for data, application, and infrastructure sovereignty increases. Starting in early 2026, partners who meet certain criteria can attain the Digital Sovereignty specialization. Here's what to know: This specialization signals to customers your deep technical expertise in designing, implementing, and managing sovereign cloud environments, including data operations, technical, and AI sovereignty. Attainment gives you access to benefits aligned to the specialization, including incentives, specialized badging, and increased discoverability. Microsoft will prioritize your organization for sovereign cloud opportunities. Partners who are interested in attaining this specialization must complete audit requirements and enroll via Partner Center. For more details, review the Digital Sovereignty specialization deck. Learn more652Views0likes0CommentsBuild Your Microsoft Ignite Schedule: Top Sessions for IT Pros
Get Ready for Microsoft Ignite Welcome back to our Azure Tech Community Microsoft Ignite 2025 series! If you joined us for Your Guide to Azure Community Activations at Microsoft Ignite 2025, you already know that Microsoft Ignite isn’t just about product updates, it’s where ideas, innovation, and community come together. With hundreds of sessions across every area of Azure, it can be hard to know where to focus. That’s why we’ve curated a list of sessions tailored specifically for IT Pros to help you make the most of your time, strengthen your technical strategy, and get inspired for the year ahead. Use the Microsoft Ignite session scheduler feature in the session catalog to personalize your agenda, save your favorites, and organize your time at Ignite. Make Every Minute Count: Top Recommended Sessions for IT Pros Microsoft Ignite moves fast, so it pays to plan your path before you arrive. By organizing your schedule around your interests and goals, you’ll be able to maximize learning opportunities, connect with peers, and leave with actionable insights. The recommendations below highlight our top picks for IT Pros looking to streamline operations, strengthen security, and stay ahead in an evolving cloud landscape. End-to-End migration of applications with AI Agents to IaaS and PaaS (BRK140) See how Azure’s new AI-powered migration agents can simplify and accelerate every stage of your migration journey—from assessment to deployment. Architecting for resiliency on Azure Infrastructure (BRK178) Discover how to build resilient cloud solutions on Azure by leveraging availability zones, multi-region deployments, and fungible products. This session explores architectural patterns, platform capabilities, and best practices. Migrate and Modernize Windows and SQL Server Workloads with Azure (LAB506-R1) Get hands-on with practical approaches to moving core enterprise workloads to Azure, improving reliability, and optimizing costs. Govern your estate using PowerShell and the CLI with AI (BRK170) Discover how you can use AI for PowerShell and Azure CLI to boost automation and simplify complex commands. Turning Compliance Burden into Competitive Advantage with RegScale (THR820) Explore how to use Microsoft’s compliance and governance frameworks to drive efficiency and differentiation. Before diving into your targeted sessions, make time for these essential moments that set the stage for everything happening at Microsoft Ignite. Opening Keynote (KEY01) Hear from Microsoft leaders as they unveil the latest innovations shaping the future of AI, cloud, and the developer ecosystem. This is the session that sets the tone for the entire event. Innovation Session: Security in the Agentic Era – the Core Primitive (BRK1712) Gain a forward-looking perspective on how the rise of Agentic AI will reshape the security landscape for IT operations and enterprise systems. Innovation Session: Scale Smarter: Infrastructure for the Agentic Era (BRK1704) Dive into what’s new in Azure Infrastructure—from compute and networking to hybrid management and scalability. Hear from Azure engineering experts on best practices and innovations for modern cloud operations. Plan Smarter with the Session Scheduler With the “add to schedule” feature in the session catalog you’ll be able to: Browse and filter all Microsoft Ignite sessions by topic, product, or persona. Save your favorite sessions to build a personalized schedule. Set reminders and block time for networking, community booths, and demos. Stay Connected with the Azure Tech Community Your Microsoft Ignite journey doesn’t stop when the sessions end, the conversation continues across the Azure Tech Community. Share the sessions you’re most excited about using #MSIgnite #AzureTechCommunity, tag azure, and connect with other IT Pros exploring the future of cloud management and security. Follow the Azure Tech Community for real-time updates, announcements, and product news throughout Ignite. See You at Microsoft Ignite 2025 With the right plan in place, every session becomes an opportunity to learn, grow, and connect. Explore these recommendations, save your favorites, and get ready for an unforgettable Microsoft Ignite 2025 experience.619Views1like0CommentsStrengthening Azure File Sync security with Managed Identities
Hello Folks, As IT pros, we’re always looking for ways to reduce complexity and improve security in our infrastructure. One area that’s often overlooked is how our services authenticate with each other. Especially when it comes to Azure File Sync. In this post, I’ll walk you through how Managed Identities can simplify and secure your Azure File Sync deployments, based on my recent conversation with Grace Kim, Program Manager on the Azure Files and File Sync team. Why Managed Identities Matter Traditionally, Azure File Sync servers authenticate to the Storage Sync service using server certificates or shared access keys. While functional, these methods introduce operational overhead and potential security risks. Certificates expire, keys get misplaced, and rotating credentials can be a pain. Managed Identities solve this by allowing your server to authenticate securely without storing or managing credentials. Once enabled, the server uses its identity to access Azure resources, and permissions are managed through Azure Role-Based Access Control (RBAC). Using Azure File Sync with Managed Identities provides significant security enhancements and simpler credential management for enterprises. Instead of relying on storage account keys or SAS tokens, Azure File Sync authenticates using a system-assigned Managed Identity from Microsoft Entra ID (Azure AD). This keyless approach greatly improves security by removing long-lived secrets and reducing the attack surface. Access can be controlled via fine-grained Azure role-based access control (RBAC) rather than a broadly privileged key, enforcing least-privileged permissions on file shares. I believe that Azure AD RBAC is far more secure than managing storage account keys or SAS credentials. The result is a secure-by-default setup that minimizes the risk of credential leaks while streamlining authentication management. Managed Identities also improve integration with other Azure services and support enterprise-scale deployments. Because authentication is unified under Azure AD, Azure File Sync’s components (the Storage Sync Service and each registered server) seamlessly obtain tokens to access Azure Files and the sync service without any embedded secrets. This design fits into common Azure security frameworks and encourages consistent identity and access policies across services. In practice, the File Sync managed identity can be granted appropriate Azure roles to interact with related services (for example, allowing Azure Backup or Azure Monitor to access file share data) without sharing separate credentials. At scale, organizations benefit from easier administration. New servers can be onboarded by simply enabling a managed identity (on an Azure VM or an Azure Arc–connected server) and assigning the proper role, avoiding complex key management for each endpoint. Azure’s logging and monitoring tools also recognize these identities, so actions taken by Azure File Sync are transparently auditable in Azure AD activity logs and storage access logs. Given these advantages, new Azure File Sync deployments now enable Managed Identity by default, underscoring a shift toward identity-based security as the standard practice for enterprise file synchronization. This approach ensures that large, distributed file sync environments remain secure, manageable, and well-integrated with the rest of the Azure ecosystem. How It Works When you enable Managed Identity on your Azure VM or Arc-enabled server, Azure automatically provisions an identity for that server. This identity is then used by the Storage Sync service to authenticate and communicate securely. Here’s what happens under the hood: The server receives a system-assigned Managed Identity. Azure File Sync uses this identity to access the storage account. No certificates or access keys are required. Permissions are controlled via RBAC, allowing fine-grained access control. Enabling Managed Identity: Two Scenarios Azure VM If your server is an Azure VM: Go to the VM settings in the Azure portal. Enable System Assigned Managed Identity. Install Azure File Sync. Register the server with the Storage Sync service. Enable Managed Identity in the Storage Sync blade. Once enabled, Azure handles the identity provisioning and permissions setup in the background. Non-Azure VM (Arc-enabled) If your server is on-prem or in another cloud: First, make the server Arc-enabled. Enable System Assigned Managed Identity via Azure Arc. Follow the same steps as above to install and register Azure File Sync. This approach brings parity to hybrid environments, allowing you to use Managed Identities even outside Azure. Next Steps If you’re managing Azure File Sync in your environment, I highly recommend transitioning to Managed Identities. It’s a cleaner, more secure approach that aligns with modern identity practices. ✅ Resources 📚 https://learn.microsoft.com/azure/storage/files/storage-sync-files-planning 🔐 https://learn.microsoft.com/azure/active-directory/managed-identities-azure-resources/overview ⚙️ https://learn.microsoft.com/azure/azure-arc/servers/overview 🎯 https://learn.microsoft.com/azure/role-based-access-control/overview 🛠️ Action Items Audit your current Azure File Sync deployments. Identify servers using certificates or access keys. Enable Managed Identity on eligible servers. Use RBAC to assign appropriate permissions. Let me know how your transition to Managed Identities goes. If you run into any snags or have questions, drop a comment. Cheers! Pierre569Views0likes0Comments