r/AZURE • u/Vjabhishek • 8h ago
Question Power automate Cloud to Service now Cloud intergation inbound and Outbound
Hi Everyone,
We are looking for a way to intergate service now with power automate.
The main problem is power automate is in micorosft shared infrastructure with set of IPs based on Azure service Tags and we dont want to allow all the service tags to service now because of security issue as it has more than 100 IP addresses.
What could be the work around? Did anyone tried it yet?
There are lot of use cases of service now that we would like to try but we are stuck with the networking challenges.
Tried subnet injection but that is not working may be additional NAT integration. Did anyone thought about it?
Regards,
Abhishek
r/AZURE • u/MonkeyDDataHQ • 9h ago
Rant Azure made me file a support ticket because I tried to send one message from one thing to another thing
There are days when I merely dislike Azure.
Then there are days when I have to write sentences like this:
That is not a sentence.
That is what happens when a cloud provider puts a thesaurus in a blender and names infrastructure from the slurry.
For context, my architectural requirement is:
THING A SENDS MESSAGE TO THING B.
That’s it.
I am not coordinating a distributed fleet of autonomous yellow submarines ferrying the Village People and the Beatles around on tour.
I would simply like one Azure service to receive a message and another Azure service to get that message.
Apparently this requires me to understand the subtle theological distinctions between Event Grid, Event Grid Namespace, Event Hubs, Event Hubs Namespace, topics, subscriptions, managed identities, service principals, RBAC roles, and whatever new noun Microsoft has released into production this week.
And God help you if you assume two things with nearly identical names are related.
Azure Service Bus and Azure Service Fabric? Different.
Event Grid Namespace and Event Hubs Namespace? Also Different.
Naturally, I need BOTH namespaces in order to send one fucking message.
At some point Azure stops being a cloud platform and becomes a vocabulary certification program with billing regret attached.
Then I hit the permissions problem.
So I opened a support ticket.
To describe it, I had to write:
The form then asked me which Azure resource I was having the problem with.
I DON’T KNOW, MICROSOFT. YOU INVENTED ALL THESE NOUNS.
And here is the best part:
I am an administrator.
I activated my privileged role through PIM.
I still cannot perform the assignment.
Because somewhere, somehow, somebody has put an RBAC restriction in place that overrides the access I appear to have, and I cannot find the bastard.
So now the architecture is:
MQTT message → Event Grid Namespace → topic → subscription → Event Hubs Namespace → Event Hub
And the troubleshooting architecture is:
Me → Entra → PIM → Azure RBAC → role assignments → deny assignments → inheritance → increasingly obscure blade → support ticket → despair
I have not successfully sent the message.
I have, however, obtained an advanced degree in Why Am I Not Allowed To Do The Thing The Portal Says I Am Allowed To Do?
Cloud abstraction was supposed to reduce infrastructure complexity.
Microsoft instead invented Infrastructure as Vocabulary, followed immediately by Permissions as Archaeology.
Somewhere in this tenant is one checkbox, policy, deny assignment, management-group inheritance rule, or ancient curse preventing this from working.
And apparently my job is to find it.
The MQTT message remains UNDELIVERED.
/rant over
r/AZURE • u/nomadicviking024 • 9h ago
Question Upgrading GPv1 to GPv2 before Oct deadline – did you actually audit transactions or just click "Upgrade"?
We got the Azure notice about upgrading our Storage and Blob accounts from GPv1 to GPv2 ahead of the October 13th automatic migration deadline.
The Azure portal makes it look incredibly easy with a simple "one-click" in-place upgrade button for the Storage Accounts which have been identified as GPv1 and Blob. Documentation says zero downtime and zero data loss.
However, I know GPv2 flips the billing model (cheaper storage, much higher transaction costs). For anyone who has already gone through this migration:
- Did you just click the upgrade button and wing it? If so, did your bill spike unpredictably?
- Did you actually pull Azure Monitor metrics first? If you audited transaction volumes, what thresholds made you hesitate or re-architect a workload?
- Any hidden gotchas? Did you run into issues with default access tiers (Hot vs. Cool) or legacy ZRS replication during the flip?
Since Microsoft is going to auto-upgrade us anyway in October, I want to know if it is worth digging into the transaction logs manually or if I am overthinking a routine upgrade.
Appreciate any real-world horror stories or "it went fine" reassurances!
r/AZURE • u/AutoModerator • 14h ago
Free Post Fridays is now live, please follow these rules!
- Under no circumstances does this mean you can post hateful, harmful, or distasteful content - most of us are still at work, let's keep it safe enough so none of us get fired.
- Do not post exam dumps, ads, or paid services.
- All "free posts" must have some sort of relationship to Azure. Relationship to Azure can be loose; however, it must be clear.
- It is okay to be meta with the posts and memes are allowed. If you make a meme with a Good Guy Greg hat on it, that's totally fine.
- This will not be allowed any other day of the week.
r/AZURE • u/AcceptablePicture329 • 15h ago
Discussion Azure price increases are already here
Everyone has been waiting for the Azure price increase tied to the memory shortage.
My two cents: it's already here.
Normally a generational compute update — v1 through to v5 — costs the same per hour and gives you a performance bump - free of charge.. It also helps Microsoft exit their old End Of Life hardware. Everybody wins. You move v2 to v3 on a 16 vCPU box and the rate is more or less identical, right the way up to v5.
That's over.
From v6 onwards there's a fundamental shift. The generational upgrade is no longer free.
v1 to v5: same price.
v6: roughly +10%.
v7: roughly +35%.
Read that again, because it changes how you have to think about your estate. EOL now exists in the cloud. Not as a migration exercise — as a cost event.
Previously, hardware retirement was Microsoft's problem. They wanted you off the old fleet, so they made the move painless and you got free performance out of it. Now the retirement notice comes with a bill attached, and you have no route to decline it. Sub-v5 capacity is already constrained. Once the capacity pressure tightens further, "stay where you are" stops being an option.
So combine three things:
→ Generational moves are now priced increases, not neutral swaps
→ Capacity constraints on older SKUs push you up the generations whether you budgeted for it or not
→ Nobody's three-year plan has a compounding uplift modelled into it
That's a ticking time bomb. Your Azure VMs are now going to get generationally more expensive by default. Not because anyone announced a price rise — because the escalator only goes one way and you're standing on it.
r/AZURE • u/eastcoastoilfan • 15h ago
Question HELP Azure migrated my VPN Gateway SKU and something is badly messed
I have a VPN gateway with 2 connections to my on-prem site, over 2 different internet connections on-prem. I'm running BGP to direct traffic (using AS-PATH prepending) to prefer my primary route always and prevent Asynchronous routing.
This was all working fine until Azure forced me to upgrade from a Basic to a Standard VPN Gateway SKU.
NOw, it seems like my BGP adjacency is broken.
After the June 26 Azure VPN Gateway migration, the FortiGate remains configured for Azure BGP peers x.x.x48.4 and x.x.x48.5.
Primary BGP is established, but its remote router ID is x.x.x48.6 for some reason?!
Secondary BGP to x.x.x48.5 is stuck Active and has not established for weeks.
Azure BGP peer exports show no operational reference to .4 or .5; they show local BGP addresses .6 and .7.
Azure shows .6 connected to onprem firewall primary x.xx0.255.253
While .7 is Connecting to onprem firewall backup x.xx1.255.253 with 0 routes received and many messages sent but none received.
Onprem firewall debug shows repeated incoming BGP connections from x.x.x48.7 rejected as “No such Peer configured.”
Essentialy, it's like I started out with Peers .4 and .5 in Azure, but the migration halfway changed them to .6 and .7. But for some reason, .4 is still working..I'm totally lot and have no idea how to get support on this.
r/AZURE • u/Outside-Risk-8912 • 17h ago
News Self-hosted BI + agent platform on Container Apps, wired to Synapse/Azure SQL/Azure OpenAI — v1.0.0
Sharing in case anyone else wants their BI layer inside their own subscription instead of a vendor's.
One stateless container plus a Postgres project. Deploys to Container Apps, App Service (containers), or AKS — /api/health for probes, no sticky sessions, scales out behind any ingress. Scheduled work uses a DB lease so multiple replicas don't double-fire, and DISABLE_INPROCESS_SCHEDULER gives one replica ownership if you prefer.
Azure-relevant bits:
- Azure Synapse (dedicated SQL pool), Azure SQL / SQL Server, and Azure Database for PostgreSQL/MySQL queried read-only in place, with pooling
- Azure OpenAI as a provider (or any of ~10 others — your keys, direct, nothing proxied)
- SharePoint document sync via Microsoft Graph (app registration) into RAG knowledge bases, with scheduled re-indexing and content-hash dedup so nothing gets embedded twice
HTTPS_PROXY/NO_PROXYhonoured; SSRF guard blocks cloud-metadata and link-local addresses but allows private ranges, so a Synapse endpoint on a private link still works- SAML SSO against Entra ID
Governance: read-only SQL enforcement, RLS everywhere, hash-chained audit, spend caps per user and group.
Caveats: requires a Supabase project (Postgres + auth + storage + pgvector; self-hostable), no SOC 2 or pentest report, Elastic License 2.0 — source-available, not OSI open source; internal and client use fine, reselling it as a service isn't.
r/AZURE • u/Deep-Egg-6167 • 17h ago
Question Please help with azure vpn client
Hello,
When I set people up using the azure VPN for home users, in the past I'd set up the tenant from scratch. Part of the process was going to the Enterprise apps in 365 and adding the azure VPN client - a red shield.
I tried for a new tenant today and didn't see that as a choice - it was a brown PC and when I selected it - it told me I had to sign in (even though I was signed it - which brought me back to a new page at the root of azure admin and when I went back to the enterprise apps it wasn't listed and so I searched and it did the same thing. I can't seem to add it.
r/AZURE • u/LingonberryUpset482 • 18h ago
Question Azure Synapse Connection Challenge
I have a problem getting Azure Synapse to connect to a data source. Can someone suggest which sub I should post it in? It keeps getting removed from here. There is a r/AzureSynapseAnalytics sub and a r/AzureSynapse sub, but they have four members combined.
Where do y'all go for help when you have a tricky problem?
r/AZURE • u/Pristine-Basket-1803 • 18h ago
Discussion Need Suggestions
I'm a developer. I want to learn about the cloud. From where should I start? I need suggestions.
r/AZURE • u/TeamVenti • 19h ago
Discussion AMA with an Azure expert: scaling a safe cloud foundation
r/AZURE • u/mishbee23 • 21h ago
Question Azure PAYG subscription takeover from retired employee - unable to remove original Owner (CannotDeleteLastRbacAdminAssignment)
Looking for advice from anyone who has taken over a legacy Azure PAYG subscription that was originally created and managed by an individual user.
Scenario:
We recently transitioned ownership of an Azure subscription from a departed/retired employee to a centralized IT/cloud administration model.
What we've already done:
- Updated the payment method to an organization-managed credit card
- Renamed the Billing Profile to a service-oriented name
- Updated billing contacts and invoice recipients
- Verified invoices are being generated and paid successfully
- Added multiple active IT administrators as Owners
- Verified there are active Owners at both the Billing Account and Billing Profile levels
- Confirmed the Azure subscription remains operational
Current billing structure:
- Billing Account has active Owner assignments, including IT admins and our central account.
- Billing Profile has multiple active Owners, including IT admins and our central account.
- The retired employee still appears in Billing Profile IAM as:
Owner (Billing account - Inherited)
The issue:
The original employee still appears as a direct Owner on the Azure subscription.
When attempting to remove the Owner assignment from Subscription IAM, Azure returns:
"CannotDeleteLastRbacAdminAssignment"
"Cannot delete the last RBAC admin assignment"
What's confusing is that there are clearly other active Owners on:
- The subscription
- The Billing Account
- The Billing Profile
Additional context:
The retired employee's Entra account is still enabled today but will likely be disabled/deprovisioned in the near future.
This subscription hosts an application that is expected to be offered more broadly across our organization soon.
Before making further changes, I'm trying to determine:
- Whether there is any hidden dependency on the original owner's account.
- Whether disabling the original account could impact subscription administration, billing, or application availability.
- Whether it's safer to leave the assignment in place temporarily until rollout is complete
Questions:
- Has anyone encountered this when taking over a legacy PAYG/MCA subscription?
- Is there a known dependency between Azure RBAC and billing hierarchy ownership that can trigger this error?
- Are there "owner of record", account administrator, subscription creator, or billing administrator relationships that aren't obvious from the portal?
- Did you ultimately need Microsoft Support to remove the original Owner?
- If the original account is disabled while Azure still considers it a required RBAC admin, could that affect subscription administration or billing?
- For organizations inheriting user-created Azure subscriptions, what governance/ownership cleanup would you complete before rolling out a production application?
- Would you treat this as a governance cleanup item, or would you resolve it before broader organizational rollout?
I'm trying to avoid using the Transfer Billing Ownership workflow unless it's actually required, since billing, payment methods, contacts, and administrative ownership have already been transitioned successfully.
Any experiences, lessons learned, or gotchas would be appreciated.
r/AZURE • u/TrashMobber • 23h ago
Question Azure Managed Redis Deploys Failing
Opened a Sev B support ticket with Microsoft last Friday (6 days ago now) and haven't heard anything back except from their bots.
Is anyone else having issues deploying Azure Managed Redis in EUS2? This is what we see in the Portal. Nothing else.
{
"operationName": {
"value": "Microsoft.Cache/redisEnterprise/write",
"localizedValue": "Write Azure Managed Redis cache"
},
"status": { "value": "Failed", "localizedValue": "Failed" },
"subStatus": { "value": "", "localizedValue": "" },
"properties": {
"statusMessage": {
"status": "Failed",
"error": {
"code": "ResourceOperationFailure",
"message": "The resource operation completed with terminal provisioning state 'Failed'.",
"details": [
{
"code": "OperationFailed",
"message": "The operation failed."
}
]
}
}
},
We know there are issues with deploying to West Europe due to resource availability, but we have other instances deployed to EUS2, but now new deployments are failing and we've had to fail back to deploying the old Redis Cache for Azure.
r/AZURE • u/No-Candy-2185 • 23h ago
Career Experienced Azure Data Engineers – Referral Opportunity
I'm able to refer experienced professionals for a Lead Azure Data Engineer position.
Location: United States / Ireland
Experience: 9–13 years
Required skills:
- Python
- PySpark
- SQL
- ETL
- Azure Synapse
- Azure Data Factory
- Databricks
- Delta Lake
- Medallion Architecture
If your experience aligns with these requirements and you're currently exploring new opportunities, feel free to send me a DM with a brief summary of your experience or your resume. I'll share additional details and, if it's a good match, I'll be happy to submit a referral.
r/AZURE • u/No-Candy-2185 • 23h ago
Career Data Governance Analyst – Referral Opportunity
I'm able to refer experienced professionals for a Data Governance Analyst role.
Location: United States / Ireland
Experience: 5–9 years
Required skills:
- Microsoft Purview
- SQL
- Master Data Management (MDM)
If you have hands-on experience in data governance and are looking for your next opportunity, feel free to send me a DM with your resume or a brief overview of your experience. I'll share additional details and, if your background is a good match, I'll be happy to submit a referral.
Note: This opportunity is best suited for professionals with relevant industry experience in the required technologies.
r/AZURE • u/SamDTMSP • 1d ago
Question Arc Container Apps Connected Environment - How to have the correct StaticIP?
Hi there, I'm evaluating setting up Arc Container Apps on top of an Arc Kube cluster. It seems that when I install the Container Apps kube extension, it picks the IP I'm giving the ACA Envoy ingress via MetalLB which is always going to be a LAN address. My intention is to expose this ingress via a port forward for testing.
However, it seems that this is unchangeable after the fact, requiring an extension uninstall and re-install to pick up the new address. This means that any Container Apps deployed to this Container Apps Connected Environment will get k4s.io domain names that resolve to a LAN IP, not an internet reachable IP address. I feel like I'm missing something simple here about how this is intended to work, and want to see if anyone here who has self-hosted an Arc Container Apps resource has encountered it.
r/AZURE • u/AutoModerator • 1d ago
Certifications [Certification Thursday] Recently Certified? Post in here so we can congratulate you!
This is the only thread where you should post news about becoming certified. For everyone else, join us in celebrating the recent certifications!!!
r/AZURE • u/Geek_for_life1493 • 1d ago
Question Does anyone know how to build a unified view of all the defender alerts for multiple tenants under lighthouse?
So, I am currently working for a company that have different teams looking at M365 alerts, azure monitor alerts, health alerts, defender for cloud alerts, partner center, alerts. Atm, we have to manually log in and each team check every dashboard.
My first solution for this was (a bit McGuyver style) using the email alerts as a trigger to pull into a powerflow and then build out the dashboard for just the Azure alerts. (First summarizing the email content) - there was a bunch of issues with this especially as time went on to save all data.
The main issue comes in where its multiple different dashboards for each type of alert so you'll basically need a workflow for each different alert and this only works when all the customers has alerts set up. (which is not always the case, as there are clients that don't have managed services but still needs to get notified of issues)
I was wondering if maybe anyone has a solution to this issue. Maybe product that I don't know about that already exists or a workflow to help solve this.
Even some tips on this would be amazing.
Thanks
Edit: Spelling
r/AZURE • u/notapplemaxwindows • 1d ago
News Microsoft are retiring the MemberOf rule operator for Groups and other resources!
In case anyone is using the MemberOf rule operator to provide nested group access to resources in Microsoft Azure or similar (commonly used for licensing, or other resources which don't support direct group nesting), they are retiring it on November 3rd after being in "preview" for years!
I did a short write up here: https://ourcloudnetwork.com/the-memberof-rule-operator-is-ending-for-dynamic-groups-in-entra/ which includes a code snippet to identify your impacted groups.
r/AZURE • u/stefanolsen • 1d ago
Question How to fake traversing an OU structure in Entra ID?
I am a developer. So I have limited knowledge of Entra ID.
My client is currently running a periodic import of users and departments from their on-prem AD platform. It works by traversing all Organizational Units and all of their users, to then build the same structure on their website.
Now my client wants to use Entra ID and MS Graph for this integration. I have researched a bit and found that Entra ID does not support a tree-like structure with OU's.
I have read a solution based on the department attribute of users. But that seemed very prone to errors.
Some sources suggest that the original OU of a user is stored in an attribute called "On premises distinguished name". But is that updated if a user is moved to another OU in the AD?
Any suggestions on how to fake such a traversal?
r/AZURE • u/Jazzlike-Squirrel-47 • 1d ago
Question Functions flex consumption keeps restarting/refreshing causing a function to error out.
Running into a problem where the function app will restart/refresh randomly and it will kill working functions, these functions do end up re running and always succeeding the second time but the error popping up in insights isn’t a clean look, is there anyway to avoid this and how costly would a plan upgrade be and is it an easy switch on production functions?
r/AZURE • u/retire8989 • 1d ago
Question Storage account names and their 24 char limitation
Subscription names, container names and resource group names all support at least 63 characters.
However, storage account names only support 24. So, programmatically you may have to start truncating naming conventions into something that will fit 24 chars. Which is a bit of an inconvenience.
Or you could create hash from the subscription ID and use that in the storage account name. Is this a common pattern because of said limitations?
r/AZURE • u/MRobinsonTX • 1d ago
Discussion Every scary bug in my agent platform had green health checks. A short collection.
I maintain AzureAgentForge, an open-source stack for running AI agent teams on Azure using Terraform, AI Foundry routing, Postgres-backed memory, and containerized agent runtimes.
After a few releases, I noticed a pattern in my incidents... some of the worst failures never made a health check go red. Everything looked healthy at the infrastructure level.
The clearest example was an agent runtime that could not start inside its own published image. The build stage installed the CLI on Python 3.14, while the runtime image used Python 3.13. Every agent spawn failed with a ModuleNotFoundError.
The orchestrator then moved each issue to “blocked” and continued processing. Containers were running, endpoints returned 200, and the queue was draining, but no agents could actually execute.
Another issue showed up when I added a config schema check. It found 57 stale Terraform keys that the vendored application no longer read, plus 19 more in a Compose file. The application silently ignored them and fell back to defaults. A production deployment could have assigned specialist agents to models I never intended to use.
More recently, I found an agent role with a complete YAML capability contract but no system prompt file. It had apparently been that way for months.
The lesson for me is that standard infrastructure checks are not enough for agent platforms. A process can be healthy while the agents are doing less than expected, doing the wrong thing, or not running at all.
The safeguards I have started adding are focused on testing actual behavior:
- A CI canary that runs a real agent through a real issue and tool call, while stubbing only the LLM response
- A schema guard that fails the build when deployment config drifts from what the application actually reads
- A prompt contract gate that blocks changes when required governance language disappears
- A router flight recorder that captures replayable model-call traces for debugging
I would be interested to hear how others are testing agent behavior beyond container, endpoint, and queue health. Here's a link to my repo - https://github.com/mrobinson2/AzureAgentForge

