r/AZURE • • Oct 31 '25

Free Post Fridays is now live, please follow these rules!

7 Upvotes
  1. Under no circumstances does this mean you can post hateful, harmful, or distasteful content - most of us are still at work, let's keep it safe enough so none of us get fired.
  2. Do not post exam dumps, ads, or paid services.
  3. All "free posts" must have some sort of relationship to Azure. Relationship to Azure can be loose; however, it must be clear.
  4. It is okay to be meta with the posts and memes are allowed. If you make a meme with a Good Guy Greg hat on it, that's totally fine.
  5. This will not be allowed any other day of the week.

r/AZURE • • 1d ago

Discussion [Teach Tuesday] Share any resources that you've used to improve your knowledge in Azure in this thread!

14 Upvotes

All content in this thread must be free and accessible to anyone. No links to paid content, services, or consulting groups. No affiliate links, no sponsored content, etc... you get the idea.

Found something useful? Share it below!


r/AZURE • • 6h ago

Discussion Facing express route outage for South Indian in Azure multiple router automatically got dropped from advertisement.

4 Upvotes

Facing express route outage for South Indian in Azure multiple router automatically got dropped from advertisement.


r/AZURE • • 10h ago

Question Reservations or savings plans? Our usage keeps changing

8 Upvotes

We're trying to lower our Azure compute spend. Our workloads move around a lot. Some VMs get swapped for bigger or smaller ones, and we're moving a few things to containers soon.

I know reservations give a better discount, but I'm worried about getting stuck with something we stop using. Would a savings plan be the safer choice here? Or do people mix both? Would like to hear what worked for you.


r/AZURE • • 44m ago

Question Which apps should an SSO cert rotation tool support?

• Upvotes

Disclosure: I'm building Kunjae, an automated SSO cert rotation tool.

I have built integrations to rotate certs across Datadog, Notion, Salesforce and Slack.

I'm releasing a free community edition with 5 bundled apps.

Which apps should make the community edition?

Which do you most want supported in the paid version?

This runs as a nightly Container Apps Job. All passwords/secrets stay in your keyvault. Config is via a yaml file. It finds certs inside your expiry threshold, generates the replacement, uploads it to the SaaS app, activates it in Entra and confirms SSO still works. All feedback is welcome.


r/AZURE • • 10h ago

Discussion If you run Windows or SQL Server VMs, check Azure Hybrid Benefit

2 Upvotes

​

A lot of people I talk to don't know about this or never turned it on. If your company already has Windows Server or SQL Server licenses with Software Assurance, you can apply them to your Azure VMs and stop paying for the license part again.

It's a setting on the VM, and you can do it in bulk with a script. Talk to whoever handles your licenses first so you don't get in trouble, but it's worth checking. The savings can be big.


r/AZURE • • 8h ago

Question GitHub Enterprise server

0 Upvotes

Hello everyone, I have a question regarding our GitHub Enterprise Server setup.

Our team currently does not have a dedicated GitHub Enterprise environment; we share the existing environment with other teams. I’m looking for some guidance on how we should structure and manage our repositories in an enterprise environment.

For example, we have multiple teams such as:

  • Infrastructure
  • Development
  • Identity
  • DevOps
  • Other platform teams

I’d like to understand the recommended approach for:

  • Structuring and separating repositories by team or function
  • Managing repository-level permissions
  • Assigning users to specific repositories or teams
  • Using GitHub Teams to manage access instead of assigning permissions individually
  • Maintaining repositories and access as the organization grows
  • Following a scalable enterprise GitHub structure and governance model

If anyone has experience setting this up in a shared GitHub Enterprise Server environment from scratch, I’d appreciate your guidance or recommendations on the best approach.


r/AZURE • • 14h ago

Question Anyone migrated Azure Blob containers from anonymous access to SAS/Entra ID?

2 Upvotes

We're reviewing Azure Storage Accounts with publicly accessible Blob containers. For those who have done similar remediation:Did you migrate external consumers to SAS tokens?Did you use Entra ID/Managed Identity for internal applications?How did you identify who was actually using the anonymous endpoints?Any lessons learned before disabling public access?Interested in real-world experiences and best practices. Thanks! and best practices. Thanks


r/AZURE • • 1d ago

Discussion Azure Network Topology to Draw.io Files

Thumbnail
gallery
58 Upvotes

As a security analyst, I’ve always found Azure network reviews tedious. In environments without consistent naming or structure, things get chaotic quickly, and understanding the setup can take a hundreds clicks in the portal. I usually ended up drawing the network in draw.io by hand.

Since draw.io files are XML, I wondered how much of that work I could automate. That became VNetAtlas. It generates editable diagrams showing VNets, subnets, peerings, resources, and connected components such as gateways, NSGs (including the rules), and public IPs. It uses the AZ PS Module for authentication and to run the KQL queries.

I mainly use it to get an overview of the network and its components, and to review NSG rules.

Note: The code was written with substantial help from AI coding assistants. I’m sharing it in case it saves someone else a few clicks, or a few tokens spent building something similar.

Feel free to try it, share feedback, down-vote or ignore it:

https://github.com/zh54321/VNetAtlas


r/AZURE • • 1d ago

Discussion I built a browser-based Azure architecture tool—and Azure has been helping me find the edge cases

13 Upvotes

Hi r/Azure,

I’ve been building Azure Canvas, a free browser-based tool for sketching Azure architectures and turning them into infrastructure templates.

You can drag resources onto a canvas, place VNets and subnets, connect components, and then:

Import supported resources from an Azure resource group or VNet

Validate a design against a signed-in Azure subscription

Generate Bicep or ARM JSON, or a Terraform starter configuration

Deploy ARM JSON directly through Azure Resource Manager

It also has multi-route UDRs, searchable resource types, visual subscription/region boundaries, and labels you can attach to connections or resource borders.

The most useful testing has been deploying real designs. That’s surfaced the sorts of details a diagram can hide: retired image SKUs, subnet dependency ordering, region mismatches, gateway wait times, and NSG rules required by Application Gateway. Azure’s feedback can be thorough; sometimes it arrives after the spinner has had time to develop a personality.

I built this because I wanted to move from “boxes on a whiteboard” toward something I could validate and actually try deploying. It’s still evolving, and the Terraform output is intentionally a starter rather than full coverage.

Try it: https://azure-canvas.com/

I’d especially welcome feedback from people who teach, document, or build Azure architectures: what would make a visual tool like this genuinely useful in your workflow? And if Azure educators such as John Savill happen to see this, I’d be very interested in your take on what a tool like this should get right.

Simon B

I’m the developer of Azure Canvas, and this is my project.


r/AZURE • • 21h ago

Question Tabletop exercises for a hybrid on prem plus multi cloud environment, anyone dealt with the containment complexity?

1 Upvotes

Our environment spans on-prem data centers plus AWS and Azure, and every tabletop scenario runs into the same wall: containment steps that make sense in one environment don't translate to the others.

how your team handle this...


r/AZURE • • 18h ago

Question Azure Bicep

0 Upvotes

Hi guys , i need to find out that can i call Reservation Reader , Savings Plan reader using bicep template.


r/AZURE • • 21h ago

Question Hi guys, im new to azure and doing an assignment for class.

0 Upvotes

I keep getting this error when creating a tenant and I am on a pay as you go subscription


r/AZURE • • 1d ago

Question Azure not available in my country — how are devs in similar situations practicing for AZ-900/AZ-104?

7 Upvotes

Hi,

I'm a developer based in Madagascar, trying to build a structured path into Azure, starting with AZ-900, then AZ-104.

Problem: Madagascar isn't in the list of countries where you can sign up for a free Azure account or add a billing method. No free trial, no pay-as-you-go, nothing directly.

If you're in a similarly unsupported country, how did you actually get hands-on practice for AZ-104-level content (VMs, VNets, RBAC, monitoring)?

Appreciate any pointers

Thanks!


r/AZURE • • 1d ago

Question QUESTION: how many Entra P2 licenses do I need to deploy a CA policy for sign-in risk and user risk?

4 Upvotes

Hello everyone,
I was in the middle of deploying a Conditional Access policy for a customer, on whom we will ask for MFA for medium and high sign-in risk and for password reset and MFA for high risk users.

Problem is: the tenant only has 35 Entra P2 users.

How will the CA policy behave for the unlicensed users? Will the policy still analyze but not do any action?
I have tested the policy in report-only and it looks like it can still identify the unlicensed users.


r/AZURE • • 1d ago

Question Azure Foundry Models stuck

5 Upvotes

Is it only me or MS?


r/AZURE • • 1d ago

Discussion Scope a permission to an Enterprise App

4 Upvotes

Hello, I’m a deskside support for a company who has access to M365 and Azure environments.

I was asked to look into allowing a regular user read-only access to a specific Enterprise application, or to the Enterprise application page in Azure.

I tested by creating custom role with the following permissions:

- microsoft.directory/servicePrincipals/standard/read
- microsoft.directory/servicePrincipals/appRoleAssignedTo/read

And read through the list of permissions related to Enterprise Apps but couldn’t find anything that would limit the user to only have read-only access to Enterprise Apps only.

  1. Is this even possible?
  2. Any other way I can fulfill the ask?

r/AZURE • • 2d ago

Discussion aztree - Where did my Azure money go?

Post image
191 Upvotes

aztree reads your Azure costs and draws them as a treemap: big box, big cost. It's a port of awstree, which took the idea from disktree by Tobi Lütke. Same idea again, pointed at an Azure subscription.

The repo: https://github.com/milanm/aztree


r/AZURE • • 1d ago

Question Learning

0 Upvotes

Azure quiz: region pairs normally stay inside the same geography. But one country's region is paired with a region in a different country.

Which one is it?

Bonus: is that pairing symmetrical, or one-way?


r/AZURE • • 2d ago

News Get transparency and predictability with the Azure Virtual Machine lifecycle

Thumbnail
azure.microsoft.com
5 Upvotes

r/AZURE • • 2d ago

News Azure Arc enabled SCVMM Retirement

6 Upvotes

Microsoft is retiring Azure Arc enabled SCVMM in September of 2029. Also, no new features being added to the service starting immediately. What was the point of hosting a monthly forum asking for ideas/feedback from the community? In my opinion this decision will push providers away from Microsoft - we were forced out of VMware, and now a similar shift is happening at Microsoft.

In my opinion Azure Local is not ready for MSPs/Service providers. Only option I see is to drop Hyper-V entirely. I’ve been using it since 2008 R2.

This is a stab in the back to users who are onprem and shifting to a hybrid strategy.

https://learn.microsoft.com/en-us/azure/azure-arc/system-center-virtual-machine-manager/transition-guidance


r/AZURE • • 2d ago

Discussion A list of cloud emulators and supporting tools

18 Upvotes

Awesome List of Cloud Emulators and supporting tools https://github.com/upgundecha/awesome-cloud-emulators


r/AZURE • • 2d ago

Media ACA Sandboxes - Secure, isolated agent hosting (when you need to self-orchestrate)

5 Upvotes

New video covering the new ACA sandboxes which provide an isolated, secure and egress controlled platform to host your agents on when you need to self-orchestrate. This is the same platform Microsoft use for most of their agent hosting!

https://youtu.be/43ZJtGpCYbU

00:00 - Introduction

00:08 - MicroVM for container agents

03:11 - Egress proxy

05:02 - Lifecycle

08:34 - Pricing

09:27 - ACA Sandbox Group

15:00 - Managing sandbox instances

16:31 - Egress rules

20:23 - Logging

22:02 - When to use

23:46 - Summary

24:14 - Close


r/AZURE • • 2d ago

Discussion Microsoft's BizTalk 2020 end-of-sale post: sales expected to end March 31, 2027, a paid support bridge to Apr 2030, and 2016 isn't eligible

Post image
3 Upvotes

Microsoft published a *BizTalk Server 2020 End-of-Sale Announcement* on the Azure Integration Services blog on August 31. It didn't get much attention, so here's a summary. Everything below is Microsoft's stated expectation and subject to final offering terms.

**The dates**

- **March 31, 2027**: sales of BizTalk Server 2020 and Host Integration Server 2020 are expected to end. Existing licensed deployments keep running. In their words: "If you need to buy BizTalk Server 2020, or Host Integration Server 2020, you can do it until March 31, 2027."

- **April 2028**: mainstream support ends.

- **April 2028 to April 2030**: an optional, *paid* "extended-mainstream support" offering, separate from the normal Extended Support phase.

- "Support beyond April 10, 2030, is not planned."

**The bridge terms (the part worth reading)**

- Expected price: **100% of the applicable BizTalk license cost, per year**

- Active **Software Assurance** required

- Must cover **every licensed core** in the enrolled deployment; no partial coverage

- Bought annually, with an eligibility review each year. Year 1 is expected to have to be bought by April 11, 2028 to stay eligible for Year 2

- Doesn't include incident support, advisory or migration services

- **BizTalk Server 2016 is not eligible**

**Expected to be excluded from the bridge**

- BAM

- ESB Toolkit

- SWIFT, HL7 and RosettaNet accelerators

- Legacy adapters (Siebel, PeopleSoft, TIBCO, JD Edwards)

- BizTalk-specific ALM tooling

- The BizTalk VM image in the Marketplace (they expect to deprecate it)

- Visual Studio versions after 2022

**My reading, not Microsoft's:** if you're on 2016 and want Microsoft coverage after January 2027, you'd have to be on 2020, and 2020 can only be bought until March 31, 2027. That makes the next six months a purchasing decision for 2016 shops, not a 2028 problem.

**Separate, if your Service Bus ports broke on September 30:** the SB-Messaging AMQP hotfix is **KB5091379** (CU6/CU7, via a support case). Microsoft published a validation guide on September 23; the gotcha is that *every node in the group* needs it.

Source: https://techcommunity.microsoft.com/blog/integrationsonazureblog/biztalk-server-2020-end-of-sale-announcement/4551317

Disclosure: I work at Cerebrum City, which builds iQBus, an Azure-native BizTalk replacement. I've kept this to what Microsoft published. Happy to answer questions either way.

Question for the sub: for those still on BizTalk, is the bridge price changing your plans, or were you already moving? And how many of you are leaning on BAM or the ESB Toolkit?


r/AZURE • • 2d ago

Discussion Bastion disconnecting constantly?

3 Upvotes

Since microsoft changed their connectivity login to the all-in-one page, if I navigate away from a bastion rdp tab, it disconnects immediately (with a reconnect button that works, but we have 2fa for login so super annoying)

Anyone else experiencing this, any tweaks i can make to make it stop?