Azure Product Updates Digest

Azure product updates grouped by product category, sourced from the official Microsoft Azure Updates feed.

# Azure product updates - 2026-08-10

**13 update(s)** published in the last 7 day(s), grouped by Azure product category.

Source: [Azure Updates](https://azure.microsoft.com/en-us/updates)

## Summary by category

| Category | Updates | GA | Preview | Top products |
| --- | ---: | ---: | ---: | --- |
| [Networking](#networking) | 5 | 2 | 3 | Azure Private Link, Azure Firewall, Azure DNS |
| [AI + machine learning](#ai-machine-learning) | 3 | 2 | - | Azure Databricks |
| [Compute](#compute) | 2 | 1 | - | Virtual Machines, Virtual Machine Scale Sets |
| [Databases](#databases) | 1 | 1 | - | Azure SQL Database, Azure SQL Managed Instance |
| [Hybrid + multicloud](#hybrid-multicloud) | 1 | - | 1 | Azure ExpressRoute |
| [Migration](#migration) | 1 | - | 1 | Azure Storage Mover |

## Networking

### [Generally Available: Explicit proxy in Azure Firewall](https://azure.microsoft.com/en-us/updates?id=568825)

**Status:** Launched | **Published:** 2026-08-05 | **Products:** Azure Firewall | **Tags:** Security, Feature

Azure Firewall explicit proxy is now generally available.

- Explicit proxy enables customers to configure applications and browsers to send HTTP and HTTPS traffic directly to Azure Firewall using proxy settings, providing an alternative to route-based traffic steering and enabling more granular control over outbound…
- The GA release builds on extensive customer validation during public preview, where explicit proxy was enabled across 300+ Azure subscriptions and adopted by approximately 40 S500 customers.
- Customer feedback gathered during preview directly influenced several key enhancements delivered as part of GA, including support for serving both HTTP and HTTPS destinations through a single proxy endpoint, Managed Identity-based PAC file retrieval, and an…
- Organizations can use Azure Firewall as a forward proxy for Arc-enabled servers, enabling secure connectivity to required Microsoft services while maintaining centralized outbound access controls.

Documentation: [Azure Firewall explicit proxy](https://learn.microsoft.com/en-us/azure/firewall/explicit-proxy?tabs=portal)

### [Public Preview: Perimeter link feature in network security perimeter](https://azure.microsoft.com/en-us/updates?id=568837)

**Status:** In preview | **Published:** 2026-08-04 | **Products:** Azure Private Link | **Tags:** Security, Feature

Perimeter link (cross-perimeter connectivity) is a network security perimeter capability that allows trusted resources in two different network security perimeters to securely communicate with each other using Managed Identity (MSI), without requiring…

- Reduces operational complexity by automatically creating required Network security perimeter rules.
- To configure a perimeter link, see Configure a perimeter link between network security perimeters .
- It preserves Zero Trust boundaries while enabling controlled service-to-service access across perimeters Learn more.
- When you create a perimeter link, Azure automatically generates the required inbound and outbound rules on both perimeters, so you don't need to create manual access rules.

Documentation: [Perimeter link feature in Network Security Perimeter (Preview) - Azure Private Link](https://learn.microsoft.com/en-us/azure/private-link/perimeter-links-overview)

### [Public Preview: Azure Private Link support over IPv6](https://azure.microsoft.com/en-us/updates?id=568842)

**Status:** In preview | **Published:** 2026-08-04 | **Products:** Azure Private Link | **Tags:** Features

You can now use IPv6 private endpoints to connect from IPv6 clients in an Azure virtual network or from on-premises networks over ExpressRoute.

- Azure Private Link over IPv6 enables you to privately access Azure PaaS services, such as Azure Storage and Azure SQL Database, over IPv6-based connectivity.
- Your subscription must be registered for the Private Link over IPv6 preview.
- A dual-stack (IPv4 and IPv6) virtual network.
- On-premises connectivity : On-premises IPv6 clients access IPv6 private endpoints over ExpressRoute through a Virtual Network Routing Appliance.

Documentation: [Configure Azure Private Link over IPv6 (Preview) - Azure Private Link](https://learn.microsoft.com/en-us/azure/private-link/private-link-ipv6)

### [Public Preview: Azure DNS enables DNS-based load balancing through Traffic Manager integration](https://azure.microsoft.com/en-us/updates?id=565214)

**Status:** In preview | **Published:** 2026-08-04 | **Products:** Azure DNS, Traffic Manager | **Tags:** Services, Feature

This improves lookup latency by eliminating a CNAME hop and enables DNSSEC compatibility for load balanced records by removing unsigned trafficmanager.net domain from CNAME lookup chain.Learn more.

- Azure DNS now offers a seamless way to integrate with Azure Traffic Manager for DNS-based traffic routing.
- You can use Traffic Manager at contoso.com directly.
- Customers can now directly associate Azure DNS record set with Traffic Manager profiles without creating CNAME record for trafficmanager.net domain.
- Traffic Manager Linked Records support the following DNS record types: The record type you choose determines the endpoint type Traffic Manager must use.

Documentation: [Traffic Manager Linked Records overview - Azure DNS](https://learn.microsoft.com/en-us/azure/dns/dns-traffic-manager-linked-records)

### [Generally Available: Azure Virtual Network routing appliance](https://azure.microsoft.com/en-us/updates?id=568605)

**Status:** Launched | **Published:** 2026-08-04 | **Products:** Virtual Network | **Tags:** Management, Services, Feature

Azure Virtual Network routing appliance is now generally available.

- A routing appliance supports global and cross-region private endpoints.
- A routing appliance emits throughput and flow metrics to Azure Monitor by default.
- A routing appliance provides built-in high availability and is resilient to availability zones by default.
- It delivers private connectivity across virtual networks, using specialized hardware for low latency, high throughput, and better performance than virtual machines.

Documentation: [Overview of Routing Appliances - Azure Virtual Network](https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-routing-appliance-overview)

## AI + machine learning

### [Announcing:  Azure Databricks Genie One and Genie Agents Free Usage extended through January 31, 2027](https://azure.microsoft.com/en-us/updates?id=568964)

**Status:** Effective | **Published:** 2026-08-06 | **Products:** Azure Databricks | **Tags:** Announcement

Free usage of Genie One and Genie Agents in Azure Databricks is now extended through January 31, 2027, from the previous end date of July 31, 2026.

- August 2026 release notes for new Azure Databricks features and improvements.
- The promotion covers usage by users only - service principals are excluded, and their Genie One and Genie Agents usage continues to be billed.
- Budget controls do not apply to these products during the promotional period.
- The managed PagerDuty connector in Lakeflow Connect is now available in Beta.

Documentation: [August 2026 - Azure Databricks](https://learn.microsoft.com/en-us/azure/databricks/release-notes/product/2026/august#genie-one-and-genie-agents-free-usage-extended-through-january-31-2027)

### [Generally Available: SharePoint Connector for Azure Databricks](https://azure.microsoft.com/en-us/updates?id=568905)

**Status:** Launched | **Published:** 2026-08-05 | **Products:** Azure Databricks | **Tags:** Feature

The SharePoint connector for Azure Databricks is now generally available.

- The connector supports incremental ingestion, Unity Catalog governance, and multiple authentication methods for enterprise-scale deployments.
- August 2026 release notes for new Azure Databricks features and improvements.
- Organizations can use Lakeflow Connect to ingest files from SharePoint into Azure Databricks, helping unify enterprise content with data and AI workflows on Azure.
- The managed PagerDuty connector in Lakeflow Connect is now available in Beta.

Documentation: [August 2026 - Azure Databricks](https://learn.microsoft.com/en-us/azure/databricks/release-notes/product/2026/august#sharepoint-connector-ga)

### [Generally Available: Unity AI Gateway on Azure Databricks](https://azure.microsoft.com/en-us/updates?id=568910)

**Status:** Launched | **Published:** 2026-08-05 | **Products:** Azure Databricks | **Tags:** Feature

Unity AI Gateway is now generally available on Azure Databricks.

- Unity AI Gateway provides centralized governance for AI models, agents, tools, and MCP services, helping organizations monitor usage, manage costs, apply guardrails, and enforce access controls across AI workloads.
- Built on Unity Catalog, it extends governance capabilities across both Azure Databricks and external AI services.
- Unity AI Gateway and Unity Catalog asset governance are generally available and do not require a preview.
- Unity Catalog is the foundation for AI governance on Azure Databricks.

Documentation: [AI governance guide - Azure Databricks](https://learn.microsoft.com/en-us/azure/databricks/ai-gateway/ai-governance)

## Compute

### [Retirement: Nested confidential (cc_v5) VMs will be retired on September 1, 2026](https://azure.microsoft.com/en-us/updates?id=568661)

**Status:** Retirement | **Published:** 2026-08-05 | **Products:** Virtual Machines | **Tags:** Retirements

On September 1, 2026, the cc_v5 confidential VM series will be retired and will no longer be available for use or purchase.

- The impacted VM sizes that will be retired are: DCas_cc_v5, DCads_cc_v5, ECas_cc_v5, and ECads_cc_v5.
- Any affected VM that has not been resized before that date will deallocated.

### [Generally Available: Trusted Launch as Default](https://azure.microsoft.com/en-us/updates?id=568600)

**Status:** Launched | **Published:** 2026-08-03 | **Products:** Virtual Machine Scale Sets, Virtual Machines | **Tags:** Features, Pricing & Offerings, Security

TLaD automatically enables Secure Boot and vTPM for supported deployments, helping customers establish a stronger security baseline for workloads at no additional cost.New Gen2 VMs deployed through Azure Portal, Azure CLI, and Azure PowerShell automatically…

- Trusted Launch as Default (TLaD) is now generally available for new Azure Gen2 virtual machines and virtual machine scale sets.
- We are excited to announce that Trusted Launch as Default (TLaD) is now Generally Available for new Azure Generation 2 (Gen2) virtual machines...
- When you use Microsoft.Compute API version 2025-11-01 or higher , the absence of a securityProfile element in your deployment enables Trusted Launch by default for a new VM or scale set—provided all of the following are true: The source Marketplace OS image…
- Here's how the default applies across the tools you already use: New Gen2 VMs and scale sets default to Trusted Launch automatically —no registration required.

Documentation: [Secure by default: Trusted Launch as Default is now Generally Available | Microsoft Community Hub](https://techcommunity.microsoft.com/blog/microsoft-security-blog/secure-by-default-trusted-launch-as-default-is-now-generally-available/4541672)

## Databases

### [Generally Available: Immutability to the most recent seven days of backups on Azure SQL Database and Azure SQL Managed Instance](https://azure.microsoft.com/en-us/updates?id=568339)

**Status:** Launched | **Published:** 2026-08-03 | **Products:** Azure SQL Database, Azure SQL Managed Instance | **Tags:** Feature

This capability is enabled by default for all databases, regardless of the configured point-in-time restore retention period.

- No action or configuration is required.Note: Support for Azure SQL Hyperscale backups is coming in a future release.
- To enhance backup protection, Azure SQL Database and Azure SQL Managed Instance now automatically apply immutability to the most recent seven days of backups.
- All supported Azure SQL Database and Azure SQL Managed Instance databases have protection enabled by default.
- This protection is especially important in the following scenarios: Ransomware or malicious activity that targets backup data By preserving recent restore points, organizations can improve confidence in recovery operations during incidents.

Documentation: [Automatic backup immutability - Azure SQL Database & Azure SQL Managed Instance](https://learn.microsoft.com/en-us/azure/azure-sql/automatic-backup-immutability?view=azuresql)

## Hybrid + multicloud

### [Public Preview: Azure ExpressRoute resiliency guard](https://azure.microsoft.com/en-us/updates?id=568666)

**Status:** In preview | **Published:** 2026-08-07 | **Products:** Azure ExpressRoute | **Tags:** Feature

Azure ExpressRoute resiliency guard is now available in public preview for ExpressRoute virtual network gateways.

- The new resiliency model property lets you specify whether a gateway is intended for a single-homed or multi-homed configuration, helping align your deployment with the resiliency requirements of your workloads.
- Portal guidance and configuration safeguards help identify incomplete setups and reduce the risk of changes that could weaken gateway resiliency.
- For multi-homed gateways, resiliency guard guides you to connect either two ExpressRoute circuits in different peering locations or an ExpressRoute Metro circuit.
- The portal displays your connectivity status once you connect all required circuits: You can change your gateway's resiliency model at any time on the Configuration tab in the Azure portal.

Documentation: [ExpressRoute Resiliency Guard (Preview) - ExpressRoute](https://learn.microsoft.com/en-us/azure/expressroute/resiliency-model)

## Migration

### [Public Preview: Migrate from AWS FSx for Windows File Server to Azure Files with Azure Storage Mover](https://azure.microsoft.com/en-us/updates?id=567979)

**Status:** In preview | **Published:** 2026-08-06 | **Products:** Azure Storage Mover | **Tags:** Feature

Azure Storage Mover now supports agentless, cloud-to-cloud migration from AWS FSx for Windows File Server (SMB) to Azure Files (SMB), in preview.

- You can move your Windows file shares off FSx and into Azure Files without deploying or managing a migration agent — the service handles the transfer for you.
- File data is copied directly from FSx to your Azure file share over a private connection between Azure and your AWS network.
- Review these limits and behaviors before production use: Each migration job supports up to 500 million objects .
- After adding all required values, select Create to save your changes and create a new source endpoint resource.

Documentation: [Migrate data from AWS FSx for Windows File Server to Azure Files with Azure Storage Mover](https://learn.microsoft.com/en-us/azure/storage-mover/amazon-files-azure-files-migration?tabs=portal)

---

_Generated automatically on 2026-08-10 05:28 UTC._