Browse Security Community (165)

Rafia Aqil outlines how to enable Azure Databricks’ Compliance Security Profile (CSP) for HIPAA workloads, including the September 1, 2026 deadline, required prerequisites like Azure VNet encryption and supported VM series, and a rollout approach to validate cluster startup and end-to-end connectivity before production.
stevenbucher introduces a new Compliance Substate property for Azure Policy exemptions, making it possible to see whether exempt resources would be compliant or non-compliant if the exemption were removed. The post shows where to enable the column in the Azure portal and how to query the field at scale using Azure Resource Graph.
vladvino announces the public preview of the AI Gateway tier for Azure API Management, focused on publishing and governing AI models and MCP servers. The post explains the new portal experience, policy-card governance (rate limits, quotas, Content Safety, fallback), and OpenTelemetry token metrics to destinations like Application Insights.
Lee Stott explains why the Model Context Protocol (MCP) is becoming the standard way AI agents connect to tools and data, then shows minimal runnable MCP server examples in Python and TypeScript plus practical guidance for VS Code hosting, security, and production operations.
stevenbucher explains how Azure Policy for Kubernetes can now enforce policies using Kubernetes Validating Admission Policy (VAP) with CEL, via Gatekeeper’s integration. The post contrasts the older webhook/Rego flow with in-process validation, then walks through packaging a CEL constraint template into an Azure Policy definition and rolling it out across AKS clusters.
OfirSarfaty announces a public preview feature for Azure DDoS Protection: custom policies that let teams set protocol-specific detection thresholds and manage per-resource mitigation behavior, while keeping existing Azure Monitor visibility and DDoS telemetry.
brauerblogs shares a reminder to register for Microsoft’s “Path to Production for Agents” webinar series (July 27–28), focused on taking AI agent solutions from experimentation to secure, scalable production with guidance on governance, platform design, AgentOps, and multi-agent architecture patterns.
Kalaivanan explains how to use Azure API Management (APIM) as a control plane for Model Context Protocol (MCP) servers, focusing on enterprise-ready authentication, access control, observability, and governance. The post lays out practical patterns for putting APIM in front of MCP endpoints and using Entra ID, OAuth flows, and API Center for discovery.
Ricardo Duncan describes how CDK Global migrated a business-critical automotive CRM platform to Azure SQL Managed Instance, including the architecture choices, migration approach, and operational practices used to move more than 1,000 databases with minimal downtime.
richpaw describes a reference architecture for running Microsoft Discovery on a Windows VM in Azure and connecting it to an Azure CycleCloud HPC cluster via Azure NetApp Files (NFS) and SSH, so agentic workflows can submit Slurm jobs, read/write POSIX files, and stay inside a private network boundary.
Lee Stott invites AI engineers to a Microsoft Foundry Discord round table on using the Browser Automation Tool (BAT) to let agents drive real browser workflows via Playwright Workspaces, with a focus on setup basics, practical use cases, and the guardrails needed for responsible, auditable automation.
Jordan Selig explains how Microsoft Foundry’s new AI Gateway control plane lets platform teams create or associate an Azure API Management (APIM) gateway from the Foundry admin console, while keeping the runtime on Azure App Service. The post breaks down what Foundry now governs, what still belongs in APIM, and how to adapt an existing App Service agent sample.
VimalVerma outlines Hypervelocity Engineering (HVE) as an operating model for building and continuously evolving Azure AI Landing Zones, with a focus on platform engineering, Infrastructure as Code, Policy as Code, and security-by-design so enterprise AI platforms can scale without losing governance.
Lee Stott invites AI engineers to a Microsoft Foundry Discord round table on scaling agent apps beyond demos, focusing on how Foundry Toolbox, Skills, and Tool Search reduce tool sprawl, prompt bloat, and auth plumbing by centralizing tools behind a governed MCP endpoint with runtime discovery.
jordanselig explains the new stable Enterprise-Managed Authorization (EMA) extension for MCP and how it differs from a centrally governed OAuth setup using Microsoft Entra ID and Azure App Service Authentication. The post includes a working sample, a local EMA lab, and practical security details for deploying an Entra-governed MCP endpoint.
Suma SaganeGowda explains how Microsoft 365 built COSMIC, an internal platform layer on Azure Kubernetes Service (AKS), to standardize provisioning, deployments, security/compliance guardrails, and observability across globally distributed services so product teams can ship faster without taking on Kubernetes operational overhead.
Manasa Ramalinga lays out a practical reference map for governing enterprise AI and autonomous agents, focusing on how to turn responsible AI policy into enforceable controls, runtime visibility, and audit-ready proof using Microsoft’s governance, security, and observability services.
jordanselig shares a reference implementation for giving an AI agent both short-term conversation history and durable, user-scoped memory on Azure App Service, using Redis for bounded session history and Cosmos DB vector search for recall, with keyless auth via managed identity and a one-command azd + Bicep deployment.
akhilkarmalkar announces Azure Front Door edge actions (public preview), a way to run lightweight JavaScript during request processing at Microsoft’s global edge. The post explains where edge actions run in the Front Door pipeline, what scenarios they enable (routing, headers, auth checks), and how Hyperlight micro-VM isolation is used to keep execution secure.
jisunchoi explains how to replace “multi-model chaos” with a governed AI gateway on Azure using Azure API Management, covering cost controls (token quotas and budget-based model downgrades), security hardening (managed identity + private endpoints), observability with Application Insights, and a Terraform-based deployment you can integrate with GitHub Copilot.
abhimittal shows how to use Azure API Management (APIM) as an AI gateway in front of Azure AI Foundry to capture per-model token usage for governance. The post walks through an inbound policy that authenticates with managed identity, emits token metrics to Azure Monitor/Application Insights, and adds edge protection with Azure Front Door + WAF.
kinfey shares a reference implementation for running long-lived autonomous coding agents from Microsoft Teams, using MCP as the control plane and Azure Container Apps dynamic sessions as a Hyper-V-isolated sandbox. The post focuses on multi-agent orchestration, deployment reliability under platform timeouts, and practical security guardrails like auth, allowlists, private ingress, and managed identities.
supriyas lays out a practical, end-to-end lifecycle for building enterprise AI agents, using a banking “loan agent” example to show how to design guardrails, build with safety controls, test with evaluations and red teaming, deploy gradually, and continuously monitor and iterate using Microsoft Foundry and Azure services.
Nir Mashkowski shares customer examples of how Azure SRE Agent is being used to reduce incident triage and investigation time by having an AI-powered agent gather evidence, classify issues, and recommend next steps, with an emphasis on governance controls and operational “memory” for teams running production on Azure.

Golden Paths Are a Product. Treat Them Like One.

KishoreKumarPattabiraman explains why “golden paths” in platform engineering need to be treated as long-lived products, not one-off projects. Using examples like an AKS migration and identity modernization, the post lays out an operating canvas for ownership, guardrails, adoption strategy, and measurable feedback loops that keep paved paths trusted over time.
Sunita_AZ0708 documents a validated reference architecture for running Siemens Teamcenter on Azure Virtual Machines while using Oracle Exadata Database Service (Oracle Database@Azure) for the database tier, including identity integration, private cross-cloud networking, backup/recovery validation, and performance test results.
EldertGrootenboer explains how to secure Azure Service Bus namespaces using layered controls—firewall rules, service endpoints, private endpoints, and Network Security Perimeter—then ties the network layer to identity with Entra ID and managed identities, including practical notes on geo-replication and DNS.
daisami walks through adding production-grade auditing and telemetry to AI agents using Microsoft’s Agent Governance Toolkit (AGT) in a .NET (C#) sample. It shows how to append governance events to Azure Blob Storage, export OpenTelemetry metrics/traces to Application Insights, and apply default-deny policies with practical security guidance for log sanitization.
aakarshdhawan walks through how to enable Microsoft Entra ID B2B guest access for Power Apps (Canvas and Model-driven) that use Microsoft Dataverse, including the tenant invitation flow, environment access, licensing requirements, and Dataverse security roles needed to validate least-privilege access for external users.
pallakatos introduces kars, a Kubernetes-native runtime for running AI agents on Azure with a “treat agents as untrusted code” security model: per-agent sandboxes, policy enforced via CRDs, zero credentials in the agent process, and an end-to-end encrypted inter-agent mesh designed for governance at scale on AKS.
wmarkley announces GA support for client-side, end-to-end data integrity in Azure Blob Storage using CRC64-NVME in the latest Azure Blob SDKs. The post explains how checksum validation works on upload/download, why CRC64-NVME is preferred over MD5, performance considerations, and the minimum SDK versions needed to enable it.

My Journey with Azure SRE Agent

jometzg walks through building an autonomous PIM elevation audit workflow using Azure SRE Agent, including how to move from interactive chat exploration to a headless scheduled subagent that queries Log Analytics and emails a daily alignment report to stakeholders.
Lee Stott explains the Model Context Protocol (MCP) and why it’s becoming a practical standard for connecting LLM apps to tools and data. The post highlights recent updates to Microsoft’s MCP for Beginners curriculum, including spec alignment, validated SDK samples, and a security-focused refresh with concrete fixes and audits.
RajyaLaxmiYellajosyula announces the Oracle AI Database@Azure AI adoption playbook and outlines the main blueprint patterns for building AI experiences on Oracle data using Microsoft services, with a strong emphasis on security, governance, and regulated-industry requirements.
ssaroiu explains how Microsoft built a production-oriented Rowhammer defense into the Azure Cobalt 200 SoC, focusing on practical cloud-scale constraints like performance overhead, configurability across DRAM quality, and operating the protection safely with privacy-preserving telemetry in confidential computing environments.
VikasBhatia summarizes how Azure Confidential Computing is maturing for sovereign and regulated workloads, highlighting recent GA and preview milestones across confidential VMs, hardware-rooted security, key protection, and operational capabilities like confidential live migration, plus how these controls fit into broader governance and compliance requirements.
bexelbie explains what the Microsoft UEFI CA 2011 expiration in June 2026 means for Linux systems using UEFI Secure Boot, why expiration isn’t the same as revocation, and what can actually cause boot failures when vendors move to 2023-only signed shims.
vzisiadis walks through how to put Azure API Management (APIM) in front of MCP servers to handle authentication and authorization, from basic Entra ID token validation to interactive OAuth sign-in from VS Code, app-role based access control, and governing external MCP servers like GitHub via passthrough and tool-level blocking.
jordanselig explains why most Model Context Protocol (MCP) servers are being deployed without real authentication, then walks through a defense-in-depth reference architecture on Azure App Service using Entra ID OAuth, managed identity, Key Vault, private networking, API Management, and monitoring to reduce common MCP attack paths.

Azure Firewall explicit proxy Migration Guide

devanshirastogi explains upcoming changes to Azure Firewall explicit proxy and provides a migration walkthrough for PAC file–based setups, including moving PAC retrieval to customer-managed Azure Storage and using Managed Identity with the right RBAC roles. The guide includes portal steps plus PowerShell and Azure CLI examples for configuring Firewall Policy.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.