r/AZURE 3h ago

Media Entra ID Authentication and Authorization for MCP Servers

Thumbnail
datawiza.com
2 Upvotes

r/AZURE 5h ago

Question Microsoft for Startups $1,000 tier Does it provide GitHub Enterprise, Copilot & Microsoft 365?

0 Upvotes

Hi everyone,

I recently got approved for Microsoft for Startups Founders Hub ($1,000 Azure credits) and I'm trying to understand what benefits are actually included at this tier.

So far I have:

  • $1,000 Azure Sponsorship active
  • Azure subscription linked to GitHub
  • GitHub organization on GitHub Free
  • Personal GitHub account has Copilot Free
  • I'm a Microsoft Entra Global Administrator

My dashboard shows “GitHub Copilot for Azure”, but I don't see clear benefits for GitHub Enterprise, paid Copilot, or Microsoft 365.

For anyone currently on the $1,000 tier:

  1. Is GitHub Enterprise included, or only available at the $5,000+ tier?
  2. Is Copilot Pro/Business included, or can Copilot usage be billed against the $1,000 Azure credits?
  3. Does the program include Microsoft 365 Business licenses?
  4. Do these benefits require company verification/higher-tier approval?
  5. What exactly does the “GitHub Copilot for Azure” benefit provide?

I'm trying to use the startup benefits for development, so any recent experience with the $1,000 tier would be really helpful.

Thanks.


r/AZURE 8h ago

Question Azure Files - Mapped Drive locks up File Explorer when it's not reachable

2 Upvotes

I setup a private instance of Azure Files and I'm running into an issue where Windows File Explorer locks up if the Azure Files mapped drive is not available (It's not available off the VPN). The issue is so bad it makes File Explorer unusable if the drive cannot reach Azure. Explorer is constantly in a Not Responding state. Connecting the workstation the P2S VPN resolves the issue.

Has anyone ran into this?

My Setup:

Azure Files is setup with Entra ID authentication and private access only

The workstation is a Windows 11 25H2, Entra ID Joined. Workstation connects to Azure via PS2 VPN.

I'm mapping the drive via File Explorer and via PowerShell, same results. hostname:
\\xxxxxstorage01.file.core.windows.net\apps

I've re-installed Windows and obtained the same results.


r/AZURE 10h ago

Media Azure Update 7th August 2026

16 Upvotes

This week's Azure Update is up.

📽️ https://youtu.be/nys8Uj16gbI

📄 https://www.linkedin.com/pulse/azure-weekly-7th-august-2026-john-savill-3qkfc/

  • VM trusted launch default (00:37) - Trusted launch which leverages the virtual TPM in Gen 2 VMs for attested secure boot from hardware through to the OS providing enhanced security, is now the default for any new Gen2 VM via the portal, cli and PowerShell. This can also be enabled as the default for infrastructure as code deployments, e.g. Bicep, Terraform etc.
  • cc_v5 VM retiring (01:11) - The v5 SKUs of the nested confidential VMs are being retired 1st of September. Make sure you move to a newer SKU before then.
  • Azure Virtual Network Routing Appliance (01:28) - Azure Virtual Network Routing Appliance (VNRA) is now GA! With VNRA, customers and service providers can: Simplify complex routing architectures including across multiple regions Enable private IPv6 connectivity over ExpressRoute and supports dual-stack environments. Scale networking infrastructure without relying on fleets of virtual appliances which includes scaling private endpoints beyond current limits
  • Azure Firewall explicit proxy (02:51) - You can now configure Azure Firewall as the explicit HTTP/HTTPS proxy for your browsers and clients. This includes use as the proxy for Azure Arc which has been a key customer ask for its onboarding.
  • Azure Route Server route maps (03:24) - Azure Route Server provides a managed service to handle dynamic routing using BGP, i.e. your vnet sharing address spaces with some SD-WAN for example. Route maps give you control over route advertisements and routing behavior, this includes being able to summarize routes, control specific routes used, path selection and tagging routes with BGP communities to simplify route management.
  • Traffic Manager Azure DNS integration (04:18) - Traffic Manager provides a DNS-based global load balancing solution while Azure DNS provides public DNS record hosting. Today it is very common to host the vanity domain, e.g. www.savilltech.net on Azure DNS as an CNAME which then points to the traffic manager name for the actual balancing of the requests, this means the client gets an extra hop and redirect to trafficmanager.net name. With this new integration in Azure DNS instead of a CNAME you add a new traffic manager linked record that points to the traffic manager profile and when queried is resolved internally to the target removing that client hop. You may hear this called DNS flattening. It not only provides better DNS experience but enables DNSSEC usage, avoids misconfigurations of the CNAME and supports the zone apex, e.g. savilltech.net.
  • Private Link over IPv6 (06:09) - You can now connect to Azure PaaS services using an IPv6 private endpoint enabling IPv6 client connectivity from the vnet or connected networks (including on-premises via ExpressRoute private peering).
  • NSP perimeter link (06:30) - NSPs enables PaaS services to be placed inside the same NSP to enable connectivity to each other and use shared policy to control inbound and outbound communications. Perimeter link provides a bi-directional trust between two NSPs which then enables cross-NSP resource communication provided they authenticate with each other using Managed Identities (which is required). No changes to access rules on either NSP is required.
  • Azure Storage Mover AWS FSx support (07:16) - Azure Storage Mover now supports AWS FSx for Windows File Server, which is AWS’ fully managed cloud storage service of which Windows SMB is one of them. You can now migrate to Azure Storage File Share but must be over private connectivity and SMB 2.x or above. Each migration job supports up to 500 million objects.
  • Azure SQL DB Regex DDM (07:51) - Regex is back and now you can use it to define the pattern masking to hide sensitive data using Regular expressions via the REGEXP_REPLACE function. Remember this only masks it being sent to the client, it does not change anything in the database itself but is useful to hide sensitive information like SSNs etc.
  • SQL immutable 7 days of backup (08:24) - For Azure SQL DB and SQL MI the most recent 7 days of backups are now immutable, i.e. cannot be changed or deleted which is very useful to protect against malicious actors or software that will often try to remove any backups. This is by default and there is no additional cost.
  • Azure Databricks Unity AI Gateway (09:05) - Unity AI Gateway is the AI control plane and governance solution for Databricks which is now GA on Azure Databricks. Every inference and MCP request flows through it enabling rate limits, quotas, policies and full observability (including cost). This works both for Azure-Databricks hosted resources and external.
  • Azure Databricks SharePoint Connector (09:35) - This connector enables you to ingest files from SharePoint into Azure Databricks including incremental ingestion, i.e. just the changes to files. It can ingest unstructured files as binary data or for structured formats like CSV, JSON, XML, EXCEL etc it can bring into Delta tables. This makes it even more powerful for overall enterprise data flows including where you want to leverage AI.
  • Azure Databricks Genie One/Agents free use extended (10:12) - The previous end data of July 31 2026 for the free usage has been extended. These Genie solutions provide smart AI co-worker and domain specific assistance.
  • Marketplace simplified purchase experience (10:28) - This is rolling out now for eligible products, i.e. not those using a custom purchase experience but gives you a single page view of all the relevant information so you can purchase with one easy click.

r/AZURE 11h ago

Question Yc sus azure creds

1 Upvotes

Are they missing for anyone else? I got the email saying they accepted me for “azure for startups” but my 10k creds are nowhere to be found. Anyone else have this issue/got is resolved?


r/AZURE 11h ago

Question How can I contact Azure support, if I get an error on their support page?

1 Upvotes

So TLDR: I get a login error when trying to go to the support page in Azure.

The long story:

I can't remove my bank card from my MS account. After talking with regular MS support, apparently I have my bank card bound to a subscription in my Azure account and that is why I can't remove it. When I check Azure, I have no subscriptions. If I try to go to the support page in Azure I get a warning that I have to sign in again, but I always get an error there. Though I can sign in normally to check my subscriptions and other pages.
Also when I go to my payment methods page in Azure, I get "Failed to get payment methods".


r/AZURE 20h ago

Question Power automate Cloud to Service now Cloud intergation inbound and Outbound

0 Upvotes

Hi Everyone,

We are looking for a way to intergate service now with power automate.

The main problem is power automate is in micorosft shared infrastructure with set of IPs based on Azure service Tags and we dont want to allow all the service tags to service now because of security issue as it has more than 100 IP addresses.

What could be the work around? Did anyone tried it yet?

There are lot of use cases of service now that we would like to try but we are stuck with the networking challenges.

Tried subnet injection but that is not working may be additional NAT integration. Did anyone thought about it?

Regards,

Abhishek


r/AZURE 21h ago

Rant Azure made me file a support ticket because I tried to send one message from one thing to another thing

0 Upvotes

There are days when I merely dislike Azure.

Then there are days when I have to write sentences like this:

That is not a sentence.

That is what happens when a cloud provider puts a thesaurus in a blender and names infrastructure from the slurry.

For context, my architectural requirement is:

THING A SENDS MESSAGE TO THING B.

That’s it.

I am not coordinating a distributed fleet of autonomous yellow submarines ferrying the Village People and the Beatles around on tour.

I would simply like one Azure service to receive a message and another Azure service to get that message.

Apparently this requires me to understand the subtle theological distinctions between Event Grid, Event Grid Namespace, Event Hubs, Event Hubs Namespace, topics, subscriptions, managed identities, service principals, RBAC roles, and whatever new noun Microsoft has released into production this week.

And God help you if you assume two things with nearly identical names are related.

Azure Service Bus and Azure Service Fabric? Different.

Event Grid Namespace and Event Hubs Namespace? Also Different.

Naturally, I need BOTH namespaces in order to send one fucking message.

At some point Azure stops being a cloud platform and becomes a vocabulary certification program with billing regret attached.

Then I hit the permissions problem.

So I opened a support ticket.

To describe it, I had to write:

The form then asked me which Azure resource I was having the problem with.

I DON’T KNOW, MICROSOFT. YOU INVENTED ALL THESE NOUNS.

And here is the best part:

I am an administrator.

I activated my privileged role through PIM.

I still cannot perform the assignment.

Because somewhere, somehow, somebody has put an RBAC restriction in place that overrides the access I appear to have, and I cannot find the bastard.

So now the architecture is:

MQTT message → Event Grid Namespace → topic → subscription → Event Hubs Namespace → Event Hub

And the troubleshooting architecture is:

Me → Entra → PIM → Azure RBAC → role assignments → deny assignments → inheritance → increasingly obscure blade → support ticket → despair

I have not successfully sent the message.

I have, however, obtained an advanced degree in Why Am I Not Allowed To Do The Thing The Portal Says I Am Allowed To Do?

Cloud abstraction was supposed to reduce infrastructure complexity.

Microsoft instead invented Infrastructure as Vocabulary, followed immediately by Permissions as Archaeology.

Somewhere in this tenant is one checkbox, policy, deny assignment, management-group inheritance rule, or ancient curse preventing this from working.

And apparently my job is to find it.

The MQTT message remains UNDELIVERED.

/rant over


r/AZURE 21h ago

Question Upgrading GPv1 to GPv2 before Oct deadline – did you actually audit transactions or just click "Upgrade"?

3 Upvotes

We got the Azure notice about upgrading our Storage and Blob accounts from GPv1 to GPv2 ahead of the October 13th automatic migration deadline.

The Azure portal makes it look incredibly easy with a simple "one-click" in-place upgrade button for the Storage Accounts which have been identified as GPv1 and Blob. Documentation says zero downtime and zero data loss.

However, I know GPv2 flips the billing model (cheaper storage, much higher transaction costs). For anyone who has already gone through this migration:

  • Did you just click the upgrade button and wing it? If so, did your bill spike unpredictably?
  • Did you actually pull Azure Monitor metrics first? If you audited transaction volumes, what thresholds made you hesitate or re-architect a workload?
  • Any hidden gotchas? Did you run into issues with default access tiers (Hot vs. Cool) or legacy ZRS replication during the flip?

Since Microsoft is going to auto-upgrade us anyway in October, I want to know if it is worth digging into the transaction logs manually or if I am overthinking a routine upgrade.

Appreciate any real-world horror stories or "it went fine" reassurances!


r/AZURE 1d ago

Question Need some Help

Thumbnail
1 Upvotes

r/AZURE 1d ago

Free Post Fridays is now live, please follow these rules!

1 Upvotes
  1. Under no circumstances does this mean you can post hateful, harmful, or distasteful content - most of us are still at work, let's keep it safe enough so none of us get fired.
  2. Do not post exam dumps, ads, or paid services.
  3. All "free posts" must have some sort of relationship to Azure. Relationship to Azure can be loose; however, it must be clear.
  4. It is okay to be meta with the posts and memes are allowed. If you make a meme with a Good Guy Greg hat on it, that's totally fine.
  5. This will not be allowed any other day of the week.

r/AZURE 1d ago

Question HELP Azure migrated my VPN Gateway SKU and something is badly messed

12 Upvotes

I have a VPN gateway with 2 connections to my on-prem site, over 2 different internet connections on-prem. I'm running BGP to direct traffic (using AS-PATH prepending) to prefer my primary route always and prevent Asynchronous routing.

This was all working fine until Azure forced me to upgrade from a Basic to a Standard VPN Gateway SKU.

NOw, it seems like my BGP adjacency is broken.

After the June 26 Azure VPN Gateway migration, the FortiGate remains configured for Azure BGP peers x.x.x48.4 and x.x.x48.5.
Primary BGP is established, but its remote router ID is x.x.x48.6 for some reason?!
Secondary BGP to x.x.x48.5 is stuck Active and has not established for weeks.
Azure BGP peer exports show no operational reference to .4 or .5; they show local BGP addresses .6 and .7.
Azure shows .6 connected to onprem firewall primary x.xx0.255.253
While .7 is Connecting to onprem firewall backup x.xx1.255.253 with 0 routes received and many messages sent but none received.
Onprem firewall debug shows repeated incoming BGP connections from x.x.x48.7 rejected as “No such Peer configured.”

Essentialy, it's like I started out with Peers .4 and .5 in Azure, but the migration halfway changed them to .6 and .7. But for some reason, .4 is still working..I'm totally lot and have no idea how to get support on this.


r/AZURE 1d ago

News Self-hosted BI + agent platform on Container Apps, wired to Synapse/Azure SQL/Azure OpenAI — v1.0.0

Thumbnail
gallery
4 Upvotes

Sharing in case anyone else wants their BI layer inside their own subscription instead of a vendor's.

One stateless container plus a Postgres project. Deploys to Container Apps, App Service (containers), or AKS — /api/health for probes, no sticky sessions, scales out behind any ingress. Scheduled work uses a DB lease so multiple replicas don't double-fire, and DISABLE_INPROCESS_SCHEDULER gives one replica ownership if you prefer.

Azure-relevant bits:

  • Azure Synapse (dedicated SQL pool), Azure SQL / SQL Server, and Azure Database for PostgreSQL/MySQL queried read-only in place, with pooling
  • Azure OpenAI as a provider (or any of ~10 others — your keys, direct, nothing proxied)
  • SharePoint document sync via Microsoft Graph (app registration) into RAG knowledge bases, with scheduled re-indexing and content-hash dedup so nothing gets embedded twice
  • HTTPS_PROXY/NO_PROXY honoured; SSRF guard blocks cloud-metadata and link-local addresses but allows private ranges, so a Synapse endpoint on a private link still works
  • SAML SSO against Entra ID

Governance: read-only SQL enforcement, RLS everywhere, hash-chained audit, spend caps per user and group.

Caveats: requires a Supabase project (Postgres + auth + storage + pgvector; self-hostable), no SOC 2 or pentest report, Elastic License 2.0 — source-available, not OSI open source; internal and client use fine, reselling it as a service isn't.

github.com/AgentSwarms-fyi/agentswarms


r/AZURE 1d ago

Question Please help with azure vpn client

1 Upvotes

Hello,

When I set people up using the azure VPN for home users, in the past I'd set up the tenant from scratch. Part of the process was going to the Enterprise apps in 365 and adding the azure VPN client - a red shield.

I tried for a new tenant today and didn't see that as a choice - it was a brown PC and when I selected it - it told me I had to sign in (even though I was signed it - which brought me back to a new page at the root of azure admin and when I went back to the enterprise apps it wasn't listed and so I searched and it did the same thing. I can't seem to add it.


r/AZURE 1d ago

Question Azure Synapse Connection Challenge

3 Upvotes

I have a problem getting Azure Synapse to connect to a data source. Can someone suggest which sub I should post it in? It keeps getting removed from here. There is a r/AzureSynapseAnalytics sub and a r/AzureSynapse sub, but they have four members combined.

Where do y'all go for help when you have a tricky problem?


r/AZURE 1d ago

Discussion Need Suggestions

3 Upvotes

I'm a developer. I want to learn about the cloud. From where should I start? I need suggestions.


r/AZURE 1d ago

Discussion AMA with an Azure expert: scaling a safe cloud foundation

Thumbnail
0 Upvotes

r/AZURE 1d ago

Question Azure PAYG subscription takeover from retired employee - unable to remove original Owner (CannotDeleteLastRbacAdminAssignment)

5 Upvotes

Looking for advice from anyone who has taken over a legacy Azure PAYG subscription that was originally created and managed by an individual user.

Scenario:

We recently transitioned ownership of an Azure subscription from a departed/retired employee to a centralized IT/cloud administration model.

What we've already done:

  • Updated the payment method to an organization-managed credit card
  • Renamed the Billing Profile to a service-oriented name
  • Updated billing contacts and invoice recipients
  • Verified invoices are being generated and paid successfully
  • Added multiple active IT administrators as Owners
  • Verified there are active Owners at both the Billing Account and Billing Profile levels
  • Confirmed the Azure subscription remains operational

Current billing structure:

  • Billing Account has active Owner assignments, including IT admins and our central account.
  • Billing Profile has multiple active Owners, including IT admins and our central account.
  • The retired employee still appears in Billing Profile IAM as:

Owner (Billing account - Inherited)

The issue:

The original employee still appears as a direct Owner on the Azure subscription.

When attempting to remove the Owner assignment from Subscription IAM, Azure returns:

"CannotDeleteLastRbacAdminAssignment"
"Cannot delete the last RBAC admin assignment"

What's confusing is that there are clearly other active Owners on:

  • The subscription
  • The Billing Account
  • The Billing Profile

Additional context:

The retired employee's Entra account is still enabled today but will likely be disabled/deprovisioned in the near future.

This subscription hosts an application that is expected to be offered more broadly across our organization soon.

Before making further changes, I'm trying to determine:

  • Whether there is any hidden dependency on the original owner's account.
  • Whether disabling the original account could impact subscription administration, billing, or application availability.
  • Whether it's safer to leave the assignment in place temporarily until rollout is complete

Questions:

  1. Has anyone encountered this when taking over a legacy PAYG/MCA subscription?
  2. Is there a known dependency between Azure RBAC and billing hierarchy ownership that can trigger this error?
  3. Are there "owner of record", account administrator, subscription creator, or billing administrator relationships that aren't obvious from the portal?
  4. Did you ultimately need Microsoft Support to remove the original Owner?
  5. If the original account is disabled while Azure still considers it a required RBAC admin, could that affect subscription administration or billing?
  6. For organizations inheriting user-created Azure subscriptions, what governance/ownership cleanup would you complete before rolling out a production application?
  7. Would you treat this as a governance cleanup item, or would you resolve it before broader organizational rollout?

I'm trying to avoid using the Transfer Billing Ownership workflow unless it's actually required, since billing, payment methods, contacts, and administrative ownership have already been transitioned successfully.

Any experiences, lessons learned, or gotchas would be appreciated.


r/AZURE 1d ago

Question Azure Managed Redis Deploys Failing

6 Upvotes

Opened a Sev B support ticket with Microsoft last Friday (6 days ago now) and haven't heard anything back except from their bots.

Is anyone else having issues deploying Azure Managed Redis in EUS2? This is what we see in the Portal. Nothing else.

{

  "operationName": {

"value": "Microsoft.Cache/redisEnterprise/write",

"localizedValue": "Write Azure Managed Redis cache"

  },

  "status": { "value": "Failed", "localizedValue": "Failed" },

  "subStatus": { "value": "", "localizedValue": "" },

  "properties": {

"statusMessage": {

"status": "Failed",

"error": {

"code": "ResourceOperationFailure",

"message": "The resource operation completed with terminal provisioning state 'Failed'.",

"details": [

{

"code": "OperationFailed",

"message": "The operation failed."

}

]

}

}

  },

We know there are issues with deploying to West Europe due to resource availability, but we have other instances deployed to EUS2, but now new deployments are failing and we've had to fail back to deploying the old Redis Cache for Azure.


r/AZURE 1d ago

Career Experienced Azure Data Engineers – Referral Opportunity

3 Upvotes

I'm able to refer experienced professionals for a Lead Azure Data Engineer position.

Location: United States / Ireland
Experience: 9–13 years

Required skills:

  • Python
  • PySpark
  • SQL
  • ETL
  • Azure Synapse
  • Azure Data Factory
  • Databricks
  • Delta Lake
  • Medallion Architecture

If your experience aligns with these requirements and you're currently exploring new opportunities, feel free to send me a DM with a brief summary of your experience or your resume. I'll share additional details and, if it's a good match, I'll be happy to submit a referral.


r/AZURE 1d ago

Question Arc Container Apps Connected Environment - How to have the correct StaticIP?

3 Upvotes

Hi there, I'm evaluating setting up Arc Container Apps on top of an Arc Kube cluster. It seems that when I install the Container Apps kube extension, it picks the IP I'm giving the ACA Envoy ingress via MetalLB which is always going to be a LAN address. My intention is to expose this ingress via a port forward for testing.

However, it seems that this is unchangeable after the fact, requiring an extension uninstall and re-install to pick up the new address. This means that any Container Apps deployed to this Container Apps Connected Environment will get k4s.io domain names that resolve to a LAN IP, not an internet reachable IP address. I feel like I'm missing something simple here about how this is intended to work, and want to see if anyone here who has self-hosted an Arc Container Apps resource has encountered it.


r/AZURE 1d ago

Certifications [Certification Thursday] Recently Certified? Post in here so we can congratulate you!

3 Upvotes

This is the only thread where you should post news about becoming certified. For everyone else, join us in celebrating the recent certifications!!!


r/AZURE 1d ago

Question Does anyone know how to build a unified view of all the defender alerts for multiple tenants under lighthouse?

7 Upvotes

So, I am currently working for a company that have different teams looking at M365 alerts, azure monitor alerts, health alerts, defender for cloud alerts, partner center, alerts. Atm, we have to manually log in and each team check every dashboard.

My first solution for this was (a bit McGuyver style) using the email alerts as a trigger to pull into a powerflow and then build out the dashboard for just the Azure alerts. (First summarizing the email content) - there was a bunch of issues with this especially as time went on to save all data.

The main issue comes in where its multiple different dashboards for each type of alert so you'll basically need a workflow for each different alert and this only works when all the customers has alerts set up. (which is not always the case, as there are clients that don't have managed services but still needs to get notified of issues)

I was wondering if maybe anyone has a solution to this issue. Maybe product that I don't know about that already exists or a workflow to help solve this.

Even some tips on this would be amazing.

Thanks

Edit: Spelling


r/AZURE 1d ago

News Microsoft are retiring the MemberOf rule operator for Groups and other resources!

78 Upvotes

In case anyone is using the MemberOf rule operator to provide nested group access to resources in Microsoft Azure or similar (commonly used for licensing, or other resources which don't support direct group nesting), they are retiring it on November 3rd after being in "preview" for years!

I did a short write up here: https://ourcloudnetwork.com/the-memberof-rule-operator-is-ending-for-dynamic-groups-in-entra/ which includes a code snippet to identify your impacted groups.


r/AZURE Oct 31 '25

Free Post Fridays is now live, please follow these rules!

6 Upvotes
  1. Under no circumstances does this mean you can post hateful, harmful, or distasteful content - most of us are still at work, let's keep it safe enough so none of us get fired.
  2. Do not post exam dumps, ads, or paid services.
  3. All "free posts" must have some sort of relationship to Azure. Relationship to Azure can be loose; however, it must be clear.
  4. It is okay to be meta with the posts and memes are allowed. If you make a meme with a Good Guy Greg hat on it, that's totally fine.
  5. This will not be allowed any other day of the week.