Browse All Posts (145)
Microsoft Developer explains why an AI agent’s output quality depends on the context you can retrieve at runtime, and shows how Foundry IQ-style capabilities connect agents to enterprise data, ground responses, and enable actions across business workflows.
Mahmoud A. Atallah shows how he uses GitHub Copilot agents in VS Code to turn meeting transcripts and other customer inputs into structured requirements and execution-ready delivery artifacts, then enriches them with Azure guidance via MCP servers and the Well-Architected Framework.
Alex Weininger introduces the Canvas authoring plugin, which guides GitHub Copilot through the native create-canvas workflow to generate an Azure canvas app based on Microsoft Canvas Toolkit, including a read-only starter and patterns for safe, explicitly scoped Azure operations.
Drew Noakes explains how C# Dev Kit 11.0 (aligned with .NET 11) was rearchitected to dramatically reduce solution load times and memory usage in VS Code, while also speeding up incremental builds and improving MSBuild file editing with richer language features.
Freddy Dezeure and Sesha Mani explain how frontier AI models are changing vulnerability management, and what CISOs can do to keep patching both fast and correct. The post highlights Microsoft’s use of AI “harnesses” for scanning and triage, and points to Baseline Security Mode and secure-by-default controls to reduce blast radius when patches can’t land in time.
Ayush Shekhar introduces ScreenMind, an open source project that runs a single local AI model to understand what’s on your screen, transcribe audio (like meetings), and answer questions about what it has seen—aimed at running on a GPU with as little as 4GB of VRAM.
Emanuele Bartolesi shares a practical fix for high CPU/disk usage on Windows 11 when running Claude, Codex, and GitHub Copilot tooling: adding targeted Microsoft Defender Antivirus folder exclusions. The post also calls out the security tradeoff and walks through the exact Windows Security steps to apply exclusions safely.
GitHub explains how PR limits can reduce low-quality pull requests and automated spam (“AI slop”) by letting maintainers cap the number of open PRs from external contributors, with upcoming options like counting draft PRs and allowing trusted users to bypass limits.
Victoria Hall introduces Azure Functions Agent bindings (preview) for Python, showing how to add bounded agentic reasoning via Microsoft Agent Framework while keeping deterministic function code in control. The post walks through project structure, package setup, local settings, and examples for both direct HTTP calls and Durable Functions orchestrations.
Visual Studio Code shows how to use the Thunder Client extension to send API requests and view responses directly inside VS Code, keeping API testing alongside your code while you build and debug your app.
James Rempt explains how Azure credits included with eligible Visual Studio Subscriptions can be used as a personal Azure sandbox for learning and experimentation, including how the monthly credit works, what happens when you hit the spending limit, and key constraints around non-production use and service eligibility.
Allison announces an update to GitHub code scanning that adds visibility into AI Scan for pull requests enablement in the Security Overview coverage view, including enabled/not-enabled counts, per-repo effective status, filter queries, and a new CSV export column for tracking adoption across orgs and enterprises.
Andrew Lock shows how to shrink a .NET NativeAOT binary by using ILLink.Substitutions.xml to replace a runtime-only property with a compile-time constant, letting the linker remove an otherwise “reachable” dependency chain (including Azure.Identity and MSAL) and cutting output size by roughly 22–25%.
Waldek Mastykarz introduces Agent Experience (AX): how AI agents discover, choose, and correctly use your SDKs, APIs, and CLIs. He breaks AX down into propensity and efficacy, shows why you must measure both quality and task cost, and shares practical examples from GitHub Copilot Chat evaluations.
Samu Niemelä shares practical takeaways from FabCon 2026 on how Microsoft Fabric is maturing, from Fabric IQ grounding Copilot and agents in governed business semantics to new on-demand compute and stronger monitoring and governance features for running Fabric at scale.
Maria Jose Fernandez and Kyle Ikeda explain how Azure’s savings plan for databases helps teams reduce database spend with flexible, spend-based discounts that can follow workloads across services and regions, and how it compares to (and complements) Azure Reservations.
Allison announces new GitHub Secret Scanning detectors and a new partner integration, expanding the set of credentials GitHub can identify and help remediate when they’re committed to repositories.
Alex-wdy explains how the Azure AD Graph (graph.windows.net) retirement impacts older Azure CLI and Azure PowerShell versions, and what to check in developer machines, CI/CD agents, runbooks, and container images to avoid identity automation breaking during the phased shutdown after October 6, 2026.
Lily Ma introduces Azure Functions managed connectors (public preview) and shows how connector triggers and typed clients let functions react to events and call actions across services like SharePoint and Teams without hand-rolling webhook registration or OAuth token handling.
shobhitgarg announces the public preview of Azure Backup v2 for Azure Database for PostgreSQL flexible servers and elastic clusters, outlining the move to snapshot-based physical backups, daily incremental scheduling, long-term retention options, and a new “Restore as Server” flow for faster, more consistent recovery.
Amaury Levé explains how to run reliable UI-thread tests for UWP and WinUI 3 apps using MSTest 4.5 and Microsoft.Testing.Platform, including how packaged/unpackaged and AppContainer hosts change the test launch path and what to validate on CI agents.
Kerim Hanif announces the general availability of Azure Site Recovery for Azure Local, highlighting a new one-page Azure portal wizard for preparing infrastructure, plus key GA improvements like WDAC enforcement-mode support and built-in proxy configuration for regulated and locked-down network environments.
Michelle Zhou introduces ReviewBench, an open benchmark for evaluating AI code review agents using a representative set of GitHub pull requests, a multi-source ground truth process, and calibrated scoring. The post explains how to interpret grounded vs augmented metrics and how teams can submit their own agents to the public leaderboard.
John Edward covers Microsoft’s new self-service onboarding flow for publishing new applications to the Microsoft Entra App Gallery, including built-in validation for SSO and provisioning integrations, submission tracking, and the rollout timeline from public preview to general availability in late 2026.
NehaNellepalli outlines an architecture for building a reusable analytics layer around Odoo without modifying the ERP, using Azure Data Factory ingestion into ADLS Gen2, Databricks/Spark transformations, and Synapse/SQL modeling for governed Power BI reporting with row-level security.
This week's ML roundup centers on a practical shift toward governed, inspectable AI systems where semantics, permissions, and operational telemetry live close to the data. Microsoft Fabric doubled down on being the context and governance layer for Copilot and custom agents (via Fabric IQ, ontologies, OneLake controls, and scale tooling), while Azure SQL brought DiskANN-based vector indexing to GA to simplify retrieval next to transactional data. On the model side, Azure AI Foundry Model Router put measurable economics (quality, cost, latency) into routing decisions, and Azure Databricks highlighted unified pipelines, SQL-first AI decision patterns, and cost visibility. We also saw science-focused agent work (Microsoft Discovery and Research Quine) that treats reproducibility, tool traceability, and validation checkpoints as non-negotiable design requirements.
This week's Security roundup focuses on turning guidance into enforceable defaults across GitHub and Microsoft platforms. On the GitHub side, maintainers get practical hardening with gh-secure, a shift to stateless GitHub App installation tokens (plus a header deprecation deadline), and tighter vulnerability reporting and advisory collaboration APIs, alongside CI controls for Dependabot and quieter scheduled code scanning. We also look at real-world threat tradecraft (Zimbra command injection, RMM abuse, Azure DevOps pipeline pivots, and targeted malware) and the parallel push to secure action-taking AI agents with clear identity, policy enforcement, runtime isolation, and telemetry.
This week's DevOps roundup centers on turning agent-driven automation into something you can safely run in production, with reference architectures that emphasize shared inventory and identity, policy-enforced tool access, sandboxed execution, and measurable telemetry for safety and cost. On the CI/CD side, GitHub Actions changes will force practical maintenance work, including macOS 14 runner retirement brownouts, stricter minimum runner versions, and broader retention rules that now apply to checks and run metadata. Security and supply-chain updates focus on identity and trust boundaries, from stateless GitHub App tokens and TLS compatibility deadlines to more automatable vulnerability reporting and advisory workflows. We close with platform tooling updates that aim for predictable automation, including pay-as-you-go GitHub-hosted agents in Azure Pipelines, improved azd configuration layering, and an open source Azure Policy Linter built for CI.
This week's Weekly Azure Roundup focuses on what it takes to run action-taking AI agents like real production services: clear ownership, cross-tenant identity, and audit-ready controls. Microsoft shared concrete multitenant governance patterns (central visibility with federated control) and deeper guidance on sandboxing agent execution using AKS or Azure Container Apps, plus managed MCP tools like Playwright Workspaces with strong evidence capture. On the platform side, Azure AI Foundry expanded routing, tool management, and agent features, while data teams got practical updates across Azure SQL vector indexing, Fabric MCP servers and modernization paths, and Databricks governance for coding agents. The rest of the stack rounded things out with new VM SKUs, private AI connectivity via ExpressRoute, clearer VM lifecycle rules, and a steady stream of security, FinOps, and developer tooling improvements.
This week's .NET roundup centers on practical "agentic" app patterns, with experimental Blazor AI components in .NET 11 RC1 that treat tool calls, approvals, and streamed output as first-class UI building blocks. The IDE story keeps moving from chat help to task-driven workflows, as Visual Studio adds BYOM for Copilot agent mode, NuGet Audit fixes from the Error List, and MCP-enabled Git agent features, while VS Code improves multi-folder and session controls that matter for multi-repo .NET work. On the Azure side, connector-based triggers for .NET isolated-worker Functions and SDK updates (including stable Entra ID auth for PostgreSQL and AI Search preview APIs) aim to reduce glue code and make integrations feel native.
This week's Weekly GitHub Copilot Roundup is about Copilot growing up operationally: more models (GPT-6.1 Sol and Claude Sonnet 5.5), clearer routing with HydraFusion patterns, and more reasons to treat model choice as a governed dependency. Agents kept expanding beyond the IDE with dynamic workflows, scheduled automations, and a new "computer use" preview that brings desktop apps into scope (and into security reviews). Code review automation moved forward with API triggers and a new default effort level, while MCP-based extensibility matured with hosted skills, shared canvases, and managed automation patterns that emphasize evidence, auditability, and controlled execution.
This week's AI roundup tracks a clear shift from chat-based assistance to action-taking systems, with GitHub Copilot adding dynamic workflows, desktop "computer use", multi-model orchestration (HydraFusion), and more automation across code review and PR merge. In parallel, Microsoft and partners focused on the controls teams need when agents can execute real changes, including identity and policy across Entra tenants, runtime enforcement via gateways, and isolation with sandboxes and microVMs. On the data side, Fabric IQ and OneLake updates reinforced that agent-ready context depends on governed semantics and permissions, while Azure SQL Hyperscale pushed vector search deeper into mainstream databases. We close with practical guidance on measuring cost and quality (routing eval toolkits, FinOps controls) and the security work needed to keep agent-driven development reviewable and accountable.
Khalid Abuhakmeh breaks down three built-in ways to convert strings to integers in C#: int.TryParse, int.Parse, and Convert.ToInt32. He explains when each is appropriate, what exceptions to expect, and how culture and number formatting (like thousands separators) can make parsing fail.
Khalid Abuhakmeh maps familiar Ruby on Rails concepts (conventions, Action Pack, Hotwire, Active Record, Sidekiq, and the Rails CLI) to their closest ASP.NET Core and .NET equivalents, with practical guidance on choosing MVC vs Razor Pages vs Minimal APIs, EF Core patterns, and background job options.
John Savill recaps major Microsoft AI announcements from September 2026, focusing on Azure AI Foundry updates (models, routing, agent features, and controls), Copilot platform changes, and developer-facing items like GitHub Copilot and VS Code agent workflows, plus data/AI additions such as Azure SQL vector capabilities.
GitHub introduces gh-secure, a one-command tool from the GitHub Security Lab aimed at improving basic repository security hygiene by helping prevent secrets from being leaked into public code, with usage via the Copilot app, Copilot CLI, or GitHub CLI.
Microsoft Developer announces an October 8, 2026 webinar focused on getting started with Copilot Studio, including what to learn first and how Agent Academy can help build practical AI builder skills.
Allison announces that GitHub App installation tokens are now issued in a new stateless format by default, and outlines what developers should verify in their integrations to avoid breakages when handling longer tokens and updated validation behavior.
Daniel Roth and Jon Galloway introduce the new Blazor AI Components and show how they can be used to build agent-centric Blazor apps where AI participates in the UI, drives workflows, and takes actions beyond a simple chat experience.
Allison announces that GitHub Copilot code review can now be requested via the REST and GraphQL APIs, and explains the new default “Balanced” review effort level plus where to configure effort settings at the enterprise, organization, repository, and personal levels.