Azure Product Updates Digest

Azure product updates grouped by product category, sourced from the official Microsoft Azure Updates feed.

# Azure product updates - 2026-09-02

**9 new update(s)** — first seen in this run. The last 7 day(s) are rescanned every time so late or backdated announcements are not missed. Grouped by Azure product category.

Source: [Azure Updates](https://azure.microsoft.com/en-us/updates)

## Summary by category

| Category | Updates | GA | Preview | Top products |
| --- | ---: | ---: | ---: | --- |
| [Compute](#compute) | 3 | 3 | - | Azure Kubernetes Service (AKS) |
| [DevOps](#devops) | 3 | 3 | - | Azure Monitor, Azure Copilot |
| [Containers](#containers) | 1 | 1 | - | Azure Container Apps |
| [Networking](#networking) | 1 | 1 | - | Azure Firewall |
| [Other](#other) | 1 | 1 | - |  |

## Compute

### [Generally Available: Windows Server 2025 on AKS](https://azure.microsoft.com/en-us/updates?id=570090)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Kubernetes Service (AKS) | **Tags:** Features

Azure Kubernetes Service (AKS) now generally supports Windows Server 2025 for Windows node pools, offering enhanced security, performance, and modern container runtime features to help organizations modernize Windows-based workloads.

- Windows Server 2025 support in AKS is generally available, featuring Stable ABI, Generation 2 VM default, containerd 2.0, and FIPS enabled by default.
- Windows Server 2025 is the recommended OS for Windows node pools, improving security and performance for containerized Windows workloads.
- AKS Windows node pools require Azure Container Networking Interface (Azure CNI) networking, with Azure CNI Overlay recommended for scalability and simplified management.
- Windows Exporter is installed on Windows nodes in certain regions, enabling enhanced observability via Managed Prometheus and Grafana dashboards.

Documentation: [Best Practices for Windows Containers on Azure Kubernetes Service (AKS) - Azure Kubernetes Service](https://learn.microsoft.com/en-us/azure/aks/windows-best-practices)

### [Generally Available: Artifact Streaming on AKS](https://azure.microsoft.com/en-us/updates?id=570095)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Kubernetes Service (AKS) | **Tags:** Feature

Artifact Streaming on Azure Kubernetes Service (AKS) with Azure Container Registry (ACR) is now generally available, enabling faster pod startup and improved scaling by allowing pods to start before full container images are downloaded.

- Accelerates containerized workloads by reducing time to pod readiness, especially for large images.
- Supports large-scale deployments by minimizing startup delays during pod creation or scaling.
- Optimizes initialization for workloads that do not require all image layers immediately, such as stateful applications.
- Available for specific repositories or tags in new or existing ACRs, with both original and streaming artifacts accessible even after disabling streaming.

Documentation: [Overview of Artifact Streaming on Azure Kubernetes Service (AKS) - Azure Kubernetes Service](https://learn.microsoft.com/en-us/azure/aks/artifact-streaming-overview)

### [Generally Available: Confidential VMs for Azure Linux](https://azure.microsoft.com/en-us/updates?id=570100)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Kubernetes Service (AKS) | **Tags:** Feature

Confidential Virtual Machines (CVM) for Azure Linux in AKS are now generally available, enabling secure migration of sensitive container workloads without code changes.

- CVM node pools support Azure Linux 3 and Ubuntu (defaulting to supported versions like Ubuntu 20.04) with customized images configured for confidentiality.
- CVMs provide hardware-based isolation, customizable attestation, VM encryption key management, secure key release, dedicated virtual TPM, and secure boot for enhanced security.
- Currently, only AMD SEV-SNP based CVMs are supported in AKS; Intel TDX-based CVMs are not supported.
- Limitations include no support for FIPS, ARM64, Trusted Launch, Pod Sandboxing, and no in-place node pool upgrades to CVM sizes; migration requires resizing node pools.

Documentation: [Use Confidential Virtual Machines (CVMs) in Azure Kubernetes Service (AKS) - Azure Kubernetes Service](https://learn.microsoft.com/en-us/azure/aks/use-cvm)

## DevOps

### [Generally Available: Azure Copilot Observability Agent supports Basic and Auxiliary table plans](https://azure.microsoft.com/en-us/updates?id=570250)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Monitor, Azure Copilot | **Tags:** Feature

Azure Copilot Observability Agent now supports Basic and Auxiliary table plans in Log Analytics, enabling cost-effective analysis of high-volume telemetry data without additional configuration, which is crucial for efficient Kubernetes operations.

- Supports Basic and Auxiliary table plans for Log Analytics data during interactive analysis and deep investigations.
- Enables moving high-volume telemetry like container logs and audit trails to lower-cost table plans while keeping data accessible to the agent.
- No additional user configuration needed if eligible tables already use Basic or Auxiliary plans.
- Particularly beneficial for Kubernetes telemetry such as ContainerLogV2, AKS audit logs, and control-plane logs.

Documentation: [Query Data in a Basic and Auxiliary Table in Azure Monitor Logs - Azure Monitor](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/basic-logs-query)

### [Generally Available: Azure Monitor Auxiliary Logs Plan in Azure Government and China regions](https://azure.microsoft.com/en-us/updates?id=569899)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Monitor | **Tags:** Features

Azure Monitor Auxiliary Logs plan is now generally available in Azure Government and China regions, enabling cost-effective ingestion and retention of verbose logs with new features like Azure table support and in-place plan switching, enhancing flexibility and compliance for sovereign cloud customers.

- Auxiliary Logs plan supports Azure tables and allows in-place switching between Analytics and Auxiliary plans without data loss or disruption.
- General availability extends to sovereign clouds: Azure Government (Fairfax) and Azure operated by 21Vianet (China).
- Standard tables can now be configured on Auxiliary plan, preserving schema and integrations while reducing costs for high-volume, low-touch data.
- Plan switching flexibility enables customers to optimize cost and query performance as table usage evolves, benefiting public-sector and regulated workloads.

Documentation: [Azure Monitor Auxiliary Logs expands with Azure tables support, plan switching, and sovereign clouds | Microsoft Community Hub](https://techcommunity.microsoft.com/blog/azureobservabilityblog/azure-monitor-auxiliary-logs-expands-with-azure-tables-support-plan-switching-an/4525206)

### [Generally Available: Azure Monitor Auxiliary Logs Plan support for Azure tables and plan switching](https://azure.microsoft.com/en-us/updates?id=569904)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Monitor | **Tags:** Features

Azure Monitor Logs Auxiliary table plan now supports a subset of standard Azure tables and allows in-place switching between Analytics and Auxiliary plans, improving cost efficiency and flexibility for high-volume, low-touch log data retention.

- Auxiliary plan now supports certain standard Azure tables, preserving original table names, schema, and queries without requiring custom pipelines.
- Users can switch tables between Analytics and Auxiliary plans in-place, retaining history, schema, and integrations with a fully reversible process.
- Auxiliary Logs is generally available in sovereign clouds (Azure Government Fairfax and Azure operated by 21Vianet Mooncake) for DCR-based custom tables, with Azure tables and plan switching coming after stabilization.
- These enhancements reduce engineering overhead, enable cost-effective retention of verbose logs for compliance, and provide flexibility to adjust table plans as workload patterns evolve.

Documentation: [Azure Monitor Auxiliary Logs expands with Azure tables support, plan switching, and sovereign clouds | Microsoft Community Hub](https://techcommunity.microsoft.com/blog/azureobservabilityblog/azure-monitor-auxiliary-logs-expands-with-azure-tables-support-plan-switching-an/4525206)

## Containers

### [Generally Available: Microsoft Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)](https://azure.microsoft.com/en-us/updates?id=570282)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Container Apps | **Tags:** Feature

Microsoft Defender for Cloud now generally supports Azure Container Apps in its Serverless Containers Posture, enabling unified security posture management and risk assessment across container environments.

- Capability: Integration of Azure Container Apps into Defender for Cloud's Serverless Containers Posture for enhanced visibility and risk assessment.
- Scope: Available generally for customers using Azure Container Apps, extending posture management to serverless container environments.
- Customer impact: Simplifies security operations by unifying container security posture, reducing manual effort, and enabling faster identification of potential exposures via attack path analysis.
- Security features: Supports managed identities, secrets management, and Azure Key Vault integration to enforce least privilege and secure configuration handling.

Documentation: [Security overview in Azure Container Apps](https://learn.microsoft.com/en-us/azure/container-apps/security#microsoft-defender-for-cloud-serverless-containers-posture-preview)

## Networking

### [Generally Available: Azure Firewall auto-learn SNAT routes](https://azure.microsoft.com/en-us/updates?id=570474)

**Status:** Launched | **Published:** 2026-09-01 | **Products:** Azure Firewall | **Tags:** Features, Security

Azure Firewall's auto-learn SNAT routes feature is now generally available, enabling automatic detection and application of registered and private destination prefixes as No-SNAT ranges to preserve original source IPs and simplify SNAT management.

- Automatically learns registered and private IP address ranges periodically and applies them as No-SNAT ranges to avoid source IP translation.
- Supports configuration via Azure PowerShell, Azure CLI (classic rules), ARM templates, and Azure portal, with firewall policies requiring SNAT range specification in the policy.
- Improves network traffic management by preserving original source IPs for internal destinations, aiding in accurate traffic inspection and logging.
- Available for Azure Firewalls using classic rules and those associated with firewall policies starting with API version 2020-11-01.

Documentation: [Azure Firewall SNAT private IP address ranges](https://learn.microsoft.com/en-us/azure/firewall/snat-private-range?tabs=powershell)

## Other

### [Generally Available: Purchase order mapping available in Microsoft Marketplace](https://azure.microsoft.com/en-us/updates?id=569700)

**Status:** Launched | **Published:** 2026-09-01 | **Tags:** Feature

Microsoft Marketplace now supports purchase order mapping, enabling organizations to align Marketplace purchases with their accounting and budgeting processes for improved spend reconciliation.

- Purchase order mapping allows allocation of Microsoft Marketplace and Azure purchases separately or by software company/product to match internal budgets and reporting.
- Available through the Azure portal under Cost Management + Billing for customers with appropriate billing permissions (MCA-E billing admins, EA enterprise admins).
- Supports remapping of spend up to three months after invoicing, providing flexibility to adapt allocations as organizational needs evolve.
- Purchase order records aid internal accounting and reconciliation without affecting invoice amounts or payment terms.

Documentation: [Align cloud investments to your purchase orders for Microsoft Marketplace - Marketplace customer documentation](https://learn.microsoft.com/en-us/marketplace/purchase-orders)

---

_Generated automatically on 2026-09-02 00:55 UTC._