Content by TechHub (398)

This week's Security roundup centers on making security controls easier to apply at scale, from production-grade guardrails for AI agents to stricter, more automatable supply chain defaults. GitHub and npm updates push publishing toward identity-based workflows (OIDC) and improve coordinated remediation with innersource advisories, while CodeQL and secret scanning add clearer triage and coverage for AI-era risks like system prompt injection. On the Microsoft side, Secure Future Initiative updates show how continuous control validation and crypto readiness (including post-quantum planning) are becoming measurable engineering work, and Azure expands key custody options with external key management for Managed HSM.
Roundups
Welcome to this week's Weekly Azure Roundup, where the theme is getting agentic systems and cloud operations closer to production reality. Microsoft Foundry and Agent Framework both shipped concrete building blocks (hosted agents, orchestration patterns 1.0, skills packaging, tracing, and cost controls) while Azure also leaned into "agent-ready" design workflows with Diagram Builder generating WAF checks, pricing estimates, and Bicep. On the platform side, resiliency work showed up from edge routing improvements in Azure Front Door to new operational agents in Azure Monitor and GA for Azure SRE Agent, with security and integration updates rounding out the week (external key management for Managed HSM, Service Bus network posture guidance, and Logic Apps features for legacy formats and hybrid deployments).
Roundups
This week's DevOps roundup focuses on taking agents from experiments to production systems, with clearer governance, better telemetry, and practical cost controls. Microsoft Foundry and Azure operations updates push hosted agents, SRE workflows, and autonomous alert triage toward day-2 reliability, while resiliency guidance shifts from design-time checklists to continuous validation. On the developer platform side, GitHub shipped more structured workflow management (issue fields and PR dashboards), tighter policy controls (rulesets), and stronger supply-chain tooling (innersource advisories, secret scanning metadata, CodeQL updates, and npm v12 security changes). Across the board, the throughline is making automation auditable, repeatable, and predictable at scale.
Roundups
This week's AI roundup tracks a clear shift from demos to deployment: Microsoft Foundry and Azure shipped updates that treat agents like governed services, with tracing, evaluation, hosting, and regional data options built in. GitHub Copilot followed the same path, expanding app access and BYOK model switching while tightening enterprise controls for policy, telemetry (OpenTelemetry), and spend (budgets, cost centers, and billing UI). Across cloud operations and developer workflows, MCP keeps showing up as the bridge to real tools, and security teams are adapting with prompt-injection detection in CodeQL and Microsoft's multi-agent hardening work. We also round out the week with applied AI progress, including Aurora 1.5's ensemble weather forecasting and a practical case study on building safer real-time voice experiences.
Roundups
This week in machine learning, Microsoft pushed both ends of the stack toward more operational AI: Aurora 1.5 adds hourly resolution, 22 variables, and ensemble uncertainty so weather model output looks more like a forecast product. On the data platform side, Fabric and SQL updates focused on making AI workloads practical to run at scale, with GPU-accelerated warehouse queries, controlled Spark runtime release channels, and more direct hooks for embeddings and agent context via MCP. We also saw governance move closer to runtime behavior, including sensitivity labels that can guide agent actions and clearer patterns for shipping Fabric Apps into production.
Roundups
Welcome to this week's GitHub Copilot roundup, where the big theme is Copilot shifting from a single assistant into a platform you can govern. The Copilot desktop app is now available across all plans and adds Bring Your Own Key (BYOK), while the model picker expands with new OpenAI GPT-5.6 variants and Copilot's first open-weight option (Kimi K2.7 Code). On the admin side, managed settings via MDM, enterprise-managed OpenTelemetry export, and easier budgets in the billing UI make it more realistic to roll out agents at scale with clear policy, telemetry, and spend controls. Across IDEs and GitHub Mobile, agent workflows gain better status visibility, permissions, and repeatability, alongside engineering notes that show why benchmarking, A/B tests, and incident learnings matter when models and tools change.
Roundups
Welcome to this week's Weekly .NET Roundup, where the themes are clear: tighter security scanning and more practical, governed agent workflows. CodeQL 2.26.0 adds AI prompt injection detections and improves query accuracy across languages, which is relevant for .NET repos that mix C#, JavaScript/TypeScript, and GitHub Actions-heavy CI. On the productivity side, Copilot's new upgrade canvas, real-world cross-repo agent automation patterns, and Agent Framework updates (orchestration patterns and stable skills) show how teams are turning agents into repeatable workflows. We also cover VS Code Copilot governance details, Logic Apps Standard moving closer to Functions-style hosting for .NET, and the growing link between agent platforms (Foundry) and UI patterns in Blazor.
Roundups
Welcome to this week's Security roundup, where agent governance moved from design guidance to concrete tooling across Kubernetes, developer IDEs, and Microsoft Security. We look at kars and AGT patterns for isolating and auditing agent behavior, plus new mitigations for MCP risks like tool metadata poisoning and untrusted server connections. On the platform side, GitHub tightened CI and audit controls (read-only cache tokens, reduced PAT use, Copilot session streaming) and expanded secret scanning into a more operational model. We also cover integrity and egress controls in Azure and Fabric, and why resilience drills and a faster post-quantum timeline mean security planning needs to start earlier.
Roundups
Welcome to this week's GitHub Copilot roundup, where the story is equal parts model churn and operational control. New model options landed (Claude Sonnet 5 and Kimi K2.7 Code GA, Claude Opus 4.8 fast mode preview) while GitHub signaled upcoming removals for Gemini 2.5 Pro and Gemini 3 Flash, making policy audits and fallback planning a practical admin task. In the IDE, Copilot keeps pushing into agent workflows with vision attachments, browser tools in VS Code, and JetBrains support via ACP, backed by better session UX and usage visibility. On the governance side, managed-settings.json, cost-center budgets, session streaming, and CLI/SDK credit limits make it easier to enforce guardrails while still letting teams use agents in editors, CI, and tool-driven workflows.
Roundups
Welcome to this week's Weekly AI Roundup, where the common thread is taking agentic AI from demos to operations: more automation, more guardrails, and more ways to prove what happened. Azure pushed reliability toward standardized, automatable determinations with its internal "Brain" system and scenario-first Chaos Studio Workspaces that can plug into Copilot and MCP. GitHub Copilot news focused on enterprise governance and spend controls (managed-settings.json, credit pools, session limits, and audit-grade agent session streaming) alongside rapid model lineup changes and the approaching GitHub Models shutdown. Across MCP, Foundry, Fabric, and IDEs, the story is clear: tool use is expanding (browser automation, vision inputs, CI diagnostics), so security, provenance, and repeatable evaluation need to expand with it.
Roundups
Welcome to this week's Azure roundup, where reliability and agentic workloads got more concrete across the platform. Chaos Studio moved closer to repeatable resilience testing with Workspaces and scenario reports tied to Azure Monitor, while Azure Monitor added Dynamic Thresholds for Prometheus and OpenTelemetry to catch anomalies without constant retuning. On the agent side, updates ranged from the kars runtime on AKS and MCP tooling patterns on Azure Functions to new security guidance on tool description poisoning, with a consistent message: automation only works in production when identity, governance, and auditability come first.
Roundups
This week's ML roundup focuses on making Microsoft Fabric deployments more governable and production-ready, from delegated OneLake shortcuts that tighten zero-copy security across workspaces and tenants to new outbound access controls for Real-Time Intelligence (RTI). On the streaming side, Eventstream connectors picked up practical upgrades like private networking, Kafka and Service Bus support, and mTLS, while preview features point to broader CDC and IoT ingestion coverage. We also saw Fabric move further toward repeatable operations with a public data agent API, GA item recovery with REST restore, and an AI-assisted CLI path for migrating Synapse Spark and pipelines. Outside Fabric, SkillOpt and MCP-based SQL Server tooling both reinforce a shared lesson for agent builders: skills, tools, and permissions are the control plane that keeps agent behavior reliable and bounded.
Roundups
This week in DevOps, the common thread was making operational change more repeatable, reviewable, and safer. Azure Chaos Studio introduced scenario-based Workspaces with reports tied to Azure Monitor signals, while Azure Monitor added Dynamic Thresholds for Prometheus and OpenTelemetry metric alerts to cut noise without relying on static thresholds. On the CI and governance side, GitHub tightened least-privilege defaults (including read-only cache tokens for untrusted triggers), reduced secret sprawl by letting Copilot CLI use GITHUB_TOKEN in Actions, and expanded enterprise security controls across secret scanning, license compliance rulesets, and upcoming Dependabot alert retention changes.
Roundups
Welcome to this week's .NET Roundup. Microsoft set a clear planning deadline with .NET 8 and .NET 9 ending support on November 10, 2026, pushing teams to budget upgrade work toward .NET 10 and revisit TargetFramework and dependency constraints. On the AI tooling side, the focus shifted from chat-based demos to repeatable workflows: MCP-powered build diagnostics in GitHub Actions, practical auditing and OpenTelemetry for agent governance, and patterns for building tools (Functions, search) with safer data access. We also saw platform-focused updates like SkiaSharp 4 for .NET MAUI, a C# preview feature for closed class hierarchies, Azure Blob client-side integrity checks reaching GA, and a useful warning about ambiguous routes when inheriting ASP.NET Core controllers.
Roundups
Welcome to this week's Weekly Security Roundup, where the thread tying most stories together is control: tighter authorization for agent tooling, stronger defaults in developer ecosystems, and faster containment when accounts and tokens get hit. On the threat side, Microsoft detailed phishing-to-implant activity delivering a persistent Node.js payload, plus infostealer ecosystems (StealC and Amadey) built and sold as services, and a DART case study showing how two separate attackers can overlap in the same environment. On the defense side, MCP security moved from connectivity to governance with enterprise-managed authorization in VS Code, APIM-fronted authorization patterns, hardened App Service hosting guidance, and new warnings about persistent AI memory as an injection surface. The roundup closes with practical supply chain and identity hardening updates across npm, Dependabot, GitHub Enterprise incident response controls, Azure DevOps workload identity federation, and platform-leve
Roundups
This week's ML roundup connects two realities teams run into fast: scaling LLM training exposes bottlenecks beyond networking, and production AI depends on governed, reliable data access. We look at Azure's MLPerf Training deep dive on Llama 3.1 405B at 8,192 GPUs, then shift to Fabric updates that tighten Purview-based protections, improve ingestion patterns, and make Spark and Lakehouse operations more predictable. We also cover how vector search and embeddings are moving into the SQL core stack, plus research and applied ML stories that focus on closing the loop (testable explanations and automated genomic reanalysis).
Roundups
Welcome to this week's Weekly .NET Roundup, where the center of gravity kept shifting from chat-based assistance to agentic workflows you can host, secure, and observe in real apps. Azure Functions gained richer MCP building blocks (including Entra ID auth and structured responses), Blazor demos showed agents triggering UI actions through components, and Microsoft Agent Framework pushed the "agent harness" idea as a practical control plane for approvals and telemetry. On the platform side, .NET 11 preview 5 introduced StringBuilder.MoveChunks() to reduce allocations in hot text pipelines, while Azure tooling and IDE updates (azd, Azure SDK, VS Code, and Visual Studio) focused on tightening day-to-day loops for provisioning, AI-assisted development, and cost/usage visibility.
Roundups
This week's GitHub Copilot updates keep pushing Copilot beyond the IDE and into agent-first workflows you can run, review, and govern across tools. The Copilot desktop app reached general availability with isolated worktrees and an "agent merge" step, while BYOK and model pickers showed up across Desktop and other clients to make provider choice and cost control more practical. Copilot for Jira and the Copilot CLI's new terminal UI tightened the loop from issue to PR, and enterprise updates added stricter plugin sourcing controls plus reporting that ties adoption phases to merged pull requests. MCP work continued to mature with better security guidance, enterprise authorization patterns, and new benchmarking data focused on consistency and token efficiency across models.
Roundups
This week's AI roundup is about taking agents from experiments to everyday workflows, with GitHub Copilot expanding across a desktop app, GitHub Desktop worktrees, and a more capable Copilot CLI terminal UI. Teams also got more enterprise-ready controls, including new model options like MAI-Code-1-Flash, Jira integration with streaming agent progress, clearer code review depth defaults, and better adoption reporting. On the platform side, MCP matured with enterprise-managed authorization, stateless scaling changes, and hardened Azure deployment patterns that treat tool servers like production APIs. We close with agentic operations reaching GA in Azure Monitor, plus practical guidance on agent reliability, security risks like persistent-memory attacks, and the ongoing push toward efficient inference from edge NPUs to 8K+ GPU training runs.
Roundups
Welcome to this week's DevOps roundup, where the main thread is making AI-driven automation operational: more governed Copilot app and agent workflows, plus enterprise controls for MCP authentication and plugin marketplaces. GitHub Actions continued its shift toward platform-scale policy and performance with step-level parallelism, tighter hosted runner governance, and new RHEL images for larger runners. On the operations side, Azure shipped practical improvements for troubleshooting and incident investigation (including the Copilot Observability Agent GA), while supply chain updates from npm, Dependabot, and GitHub Enterprise focused on reducing blast radius and simplifying least-privilege automation.
Roundups
Welcome to this week's Weekly Azure Roundup, where the focus shifts from AI demos to operable systems. Azure Monitor's Copilot Observability Agent reached GA (with autonomous operations in preview), while MCP moved closer to production through Azure Functions tooling, a stateless protocol update for easier scale-out, and clearer security patterns using Entra ID and API Management. On the platform side, ACR added IPv6 dual-stack endpoints in preview and shared practical guidance on tuning image-pull performance, alongside updates across SQL and PostgreSQL tooling, confidential computing, and day-to-day ops improvements like azd and Kudu logging.
Roundups
This week in Security, AI agents and MCP-based tooling ran into familiar trust-boundary problems, especially when browser-like agents can be pushed from untrusted web content into localhost services and privileged tools. Microsoft Defender Security Research unpacked AutoJack, showing how a single page can drive an agent into an MCP WebSocket path that ends in host-side code execution, reinforcing the need for explicit mediation, authentication, and monitoring even on loopback. On the control side, teams shared concrete governance patterns like placing Azure API Management in front of MCP servers to enforce tool visibility, logging, and rate limits, alongside deterministic agent workflows in the ARM MCP Server that make infrastructure changes reviewable and repeatable. Rounding it out, enterprise reinforcement learning guidance emphasized that training loops need production-grade isolation too, using sandboxed environments and clear evaluation gates to keep experimentation contained.
Roundups
This week's Weekly .NET Roundup spans three practical threads: getting ready for platform changes, tightening security posture, and making AI-assisted development more repeatable. We cover the Logic Apps shift toward Azure Functions out-of-proc hosting on the road to .NET 10, plus .NET 11 Preview 5 and June 2026 servicing fixes you should roll into SDK mirrors, container images, and CI. On the tooling side, MCP shows up in build-log investigation and assistant skills, while agent middleware patterns and OpenAI-compatible endpoints point toward production-ready agent hosting. We also look at a real npm supply chain compromise that matters to polyglot .NET pipelines, and hands-on database guidance for Postgres performance, temporal modeling, and RAG at scale.
Roundups
This week's Azure roundup focuses on platform migrations where waiting can turn a routine change into a risky cutover. Logic Apps Standard is preparing to move from in-proc hosting to the Azure Functions out-of-proc model as part of the path to .NET 10, so teams should validate early and avoid depending on temporary redirect behavior. On the networking side, Azure Firewall explicit proxy shifts PAC retrieval to Azure Storage with SAS and identity-based access, while large hub-and-spoke topologies get a practical playbook for moving ExpressRoute MSEE hairpin routing to AVNM mesh without weakening segmentation or inspection.
Roundups
This week in DevOps, the common thread is making change safer: Azure platform migrations are getting clearer control points (from Logic Apps hosting redirects to large-scale networking cutovers), and GitHub Actions is tightening defaults and trigger policies to reduce workflow abuse. Security teams also got concrete lessons from an npm compromise, alongside steady improvements in secret scanning and more structured, production-focused AI scanning pipelines. On the automation and operations side, MCP servers are turning agent-driven work into repeatable, auditable tools, while Azure Monitor adds practical alerting options (dynamic thresholds and per-row alerts) and deeper guidance on evidence-backed investigations with the Copilot Observability Agent.
Roundups
This week's ML roundup connects three threads teams keep running into in production: how to improve agent behavior with measurable learning loops, how to query governed data across tools without copying, and how to keep AI-assisted operations safe. Microsoft outlined an enterprise reinforcement learning workflow with OpenEnv and Foundry that centers on controlled environments, rubric-based scoring, and managed post-training, while OneLake interoperability expanded across Databricks and ServiceNow through catalog federation and Iceberg-compatible table APIs. We also saw practical agent patterns in analytics and operations (MCP-based query agents, Spark diagnostics skills, Postgres guardrails), plus a look at extreme-scale training engineering from Azure and NVIDIA and a new open dataset for multilingual research.
Roundups
This week's Weekly AI Roundup is about AI moving from chat helpers to agent-driven workflows that ship real code and run inside everyday team processes. GitHub Copilot's new desktop app, stronger CLI and IDE agent modes, and GitHub-side changes (review shaping, PR attribution, issue triage) all point to agents becoming normal collaborators, with MCP as the connective tissue. At the same time, model routing, lifecycle changes, and per-user spend reporting are turning cost and policy into daily ops concerns. We also cover MCP's expanding tool ecosystem (from APIM gateways to MSBuild binlog analysis), the AutoJack security lesson on trust boundaries, and practical grounding patterns for RAG across Azure AI Search, file data via OneLake shortcuts, and Postgres-backed retrieval.
Roundups
This week, GitHub Copilot moved further into an agent-first workflow with the Copilot desktop app reaching general availability, tightening the loop from issue to merge with canvases, parallel sessions, and Git worktrees under the hood. At the same time, Copilot is getting more explicit about model operations: Auto mode is now available to everyone in Copilot Chat, token efficiency work is reducing long-session overhead, and teams need to plan for the Opus 4.6 (fast) deprecation with policy-aware replacements. On the governance side, new enterprise controls, richer usage and AI credit reporting, and better attribution for agent-opened pull requests make it easier to roll out agents responsibly. Rounding it out, MCP and agent discovery expanded into build diagnostics, database tooling, and cross-editor workflows (CLI, JetBrains, and SSMS), showing where Copilot integrations are heading next.
Roundups
This week's DevOps roundup is about tightening control without slowing delivery: GitHub Actions resumes minimum runner version enforcement, adds new hosted runner images, and expands approval gates for automation-driven pull requests. Agentic Workflows move into public preview with a Markdown-to-YAML authoring flow, new guardrails, and a shift from PATs to GITHUB_TOKEN for simpler permissions management. On the observability side, Azure Monitor pushes standardization with OpenTelemetry VM metrics, DCR-based metrics export and platform log collection, exemplar links between metrics and traces, and GA support for SLIs and SLOs. We also cover GHES 3.21, faster and broader CodeQL scanning, improved secret scanning signal quality, and updates that make reliability and cost allocation easier to track.
Roundups
This week in ML is a reminder that production reliability lives in the details: licensing and entitlements in Azure AI Foundry, VM and disk changes that can reshape workloads, and the day-to-day reality of cold starts, probe timeouts, and OOM kills. We also saw practical guidance for handling regional capacity limits in Azure Databricks and for standardizing failure logs across Fabric and Synapse pipelines with Azure Monitor and KQL. On the product side, Fabric added real-time dashboard improvements, governed sharing options (including OneLake shortcuts and cross-workspace role management), and more Copilot-driven authoring paths that fit into versioned, repeatable workflows.
Roundups
This week's AI roundup is about turning agents into something you can run, review, and govern. GitHub's Agentic Workflows moved into public preview with Actions-native controls, stronger sandboxing, and fewer operational footguns like PAT sprawl, while Copilot expanded enterprise configuration across code review, terminal workflows, and auditable agent sessions (including validation for third-party agents). On the platform side, Azure AI Foundry and Claude Fable 5 leaned into long-running agent patterns, and MCP kept emerging as the common layer for wiring tools with policy and authentication. We also saw practical guidance on evaluation and token discipline, plus concrete ops and security updates ranging from Azure Container Apps troubleshooting to reduced secret scanning alert fatigue.
Roundups
This week in GitHub Copilot, the story is less about new prompts and more about where agent work runs, how it gets reviewed, and how teams operate it safely. The Copilot desktop app expands in preview with canvases, voice input, isolated worktrees, and sandboxes, pushing agent workflows into a separate, reviewable workspace outside the editor. On the ops side, agentic workflows can now use GITHUB_TOKEN instead of PATs, Copilot Chat on the web surfaces cloud agent sessions and searchable history, and Copilot CLI and Code Review add configuration and governance controls (plus a new terminal security review command). We also saw Copilot features land deeper in Azure DevOps and Azure Repos, and model and platform news (Claude Fable 5 in Foundry) that reinforces how much governance, monitoring, and cost controls shape real agent adoption.
Roundups
This week in security, the focus shifted to tightening defaults and making controls easier to enforce across code, agents, and cloud boundaries. GitHub reduced credential sprawl and raised CI/CD gates with built-in tokens, bot PR workflow approvals, stronger validation for agent-generated PRs, and faster CodeQL scanning (including coverage for dormant repos). On the AI side, the story was operational guardrails: Foundry governance controls, ASSERT for turning specs into repeatable evals, and practical MCP patterns for exposing and scanning tools safely. Rounding out the week were concrete enterprise hardening moves like Azure Network Security Perimeter for Service Bus, IP allow lists for EMU namespaces, passkey adoption campaigns, centralized platform log collection, and LAPS policy enforcement for Azure Arc.
Roundups
This week in .NET, the Build 2026 recaps and session watchlists make one theme hard to miss: Microsoft is treating agentic workflows as something .NET teams should build, ship, and operate, not just demo. Alongside guidance for tracking .NET 11 and upcoming C# features, we saw practical patterns for grounded assistants ("golden repos" in ArchAngel) and a clear push toward multi-agent distributed apps with .NET Aspire and Microsoft Agent Framework. We also get a preview of where modernization is heading, with the .NET Day on Agentic Modernization connecting migrations to governed tool-calling flows through Copilot, Foundry services, and MCP-style integrations.
Roundups
This week's Azure roundup focuses on turning agentic AI from demos into production systems, with Microsoft Foundry and Azure AI Foundry leaning into orchestration, observability, governance, and clearer token-based cost controls. On the operations side, Azure Monitor expanded its OpenTelemetry and DCR toolbox with GA features for metrics export and platform SLI/SLOs, while App Service added MCP support and improved Linux startup diagnostics to shorten troubleshooting loops. We also saw practical guidance for running AI workloads on Azure Container Apps, plus new security guardrails like Network Security Perimeter for Service Bus and LAPS for Azure Arc to standardize controls across cloud and hybrid environments.
Roundups
This week's AI roundup focuses on Microsoft Foundry's shift from a model catalog to an end-to-end platform for building, operating, and distributing enterprise agents. Build 2026 updates centered on a repeatable operations loop (traces, evaluations, routing, and tuning), production-ready hosted agents with more reliable memory controls, and tool connectivity that scales through Toolboxes and managed MCP servers. On the grounding side, Foundry IQ expanded retrieval and connectors, while Teams and Microsoft 365 Copilot publishing (plus Entra ID-backed A2A endpoints) moved agent deployment closer to where work actually happens.
Roundups
This week in DevOps, agentic workflows moved from demos to platforms you can standardize, version, and roll out, with new GitHub Copilot and agent app surfaces, deeper PR-integrated review, and APIs that let other systems trigger governed agent tasks. Security teams also got a clearer warning label as prompt injection and a large npm campaign showed how agent tools and CI publishing flows can be abused, reinforcing least privilege, pinning, and explicit approval boundaries. On the operations side, direct OTLP ingestion into Azure Monitor reached GA and agent-focused observability views expanded, making trace-first debugging and cost visibility more practical as AI credits and usage-based billing become day-to-day concerns.
Roundups
This week, GitHub and Microsoft positioned Copilot as part of an enterprise agent platform, where identity, tool access, policy, observability, and eval loops matter as much as model output. Copilot also moved further into resource management, with model deprecations and replacements, optional Gemini models via admin policy, 1M-token context and reasoning controls, and fully live usage-based billing tied to GitHub AI Credits (plus new cost signals for code review and Actions). Inside GitHub, agentic workflows expanded with richer PR context for Copilot Chat, configurable code review tiers and MCP-backed skills, Azure Repos review previews, and Marketplace-installed agent apps. The rest of the updates fill in the execution and governance layer (CLI scheduling and rubber-duck review, sandboxes, a cloud agent tasks API, the Copilot SDK GA, and tighter enterprise controls across VS Code, JetBrains, Visual Studio, and Eclipse).
Roundups
This week in ML, Microsoft Fabric moved closer to an agent-ready analytics platform, with new ways to ship backends into Fabric, ground agents in governed context, and model relationships directly on OneLake. Rayfin positions Fabric as a default deployment target for data-powered apps, while Fabric IQ (now GA) and its ontology support aim to standardize how agents request context with permissions and auditability built in. Graph in Fabric (GA) adds GQL-based relationship querying, and the Fabric Operations agent plus Fabric Skills show how Microsoft wants teams to monitor, automate, and code against Fabric with guardrails instead of one-off scripts.
Roundups
This week's DevOps roundup connects three threads that show up everywhere in modern delivery: supply chain risk, agent-driven automation, and platform guardrails that actually enforce policy. Microsoft flagged new npm install-time attack campaigns, a reminder that lifecycle hooks inherit your CI and workstation permissions unless you tighten token scope and credential exposure. On the automation side, guidance and tooling updates pushed agents toward production discipline (tool contracts, grounding, eval gates, and auditability), while GitHub and Azure shipped governance knobs like Code Quality enablement APIs, CodeQL improvements, hard budget limits for GHAS, and security baselines as code for Windows and Azure Arc.
Roundups

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.