In This Post
- The week in one paragraph
- The licensing lever hiding in a compute announcement
- Networking: a ceiling raised and a protocol arrives
- Data and migration
- The retirement that needs a purchase order
- Security advisories
- Beyond the announcements
- What I would act on
- Complete inventory β all 14
- Official Azure references
The week in one paragraph
Fourteen announcements across five days and no new services among them. What arrived divides cleanly into three groups: cost levers for people running licensed software on virtual machines, two long-awaited networking capabilities, and a steady stream of SQL tooling. Alongside them came nineteen Azure security advisories, most landing on Thursday, and one retirement notice that is not a technical migration at all β it is a purchasing decision with a date on it.
The item most likely to change a design this week looks like a footnote about route advertisement.
The licensing lever hiding in a compute announcement
VM vCore Customization reached general availability with two capabilities: disabling simultaneous multithreading, and configurable constrained cores. Microsoft frames it as optimising performance while reducing software licensing costs, and the second half is where the money is.
Any workload licensed per core β commercial database engines being the obvious case β pays for the vCPUs the virtual machine presents, not the ones it uses. Constraining cores lets a VM keep its memory, storage throughput and network capacity while presenting fewer licensable cores. Disabling multithreading gives a workload exclusive access to physical cores, which matters both for licence arithmetic and for workloads where hyperthreading hurts rather than helps.
This reads as a minor compute knob and belongs in a FinOps conversation. If you run per-core licensed software on Azure virtual machines, the ratio of memory to licensable cores is now something you set deliberately.
Networking: a ceiling raised and a protocol arrives
Summarized advertised gateway prefixes reached general availability, and it removes a real scaling limit. A gateway can now advertise aggregated prefixes to on-premises networks instead of advertising every individual virtual network address space. It works on both ExpressRoute Gateway and VPN Gateway, and covers IPv4 and IPv6.
Microsoft names the problem precisely: large hub-and-spoke deployments often approach the advertised-prefix limits of ExpressRoute and VPN Gateway as spokes are added. That is a ceiling reached by success β every new spoke consumes budget in a limit most teams never think about until a spoke fails to connect. Summarisation turns linear growth into a design choice, and it is one more argument for the disciplined address planning that makes summarisation possible at all.
Azure Firewall added IPv6 support in public preview: dual-stack Firewall and Firewall Policy, native IPv6 network-rule filtering, and DNS Proxy support. For organisations that have been holding a dual-stack migration because the firewall could not follow, this is the piece that was missing.
Data and migration
Zone redundancy for Azure SQL Managed Instance Next-gen General Purpose entered public preview, distributing compute and data across availability zones for up to 99.995% uptime without changing application architecture. That last clause is the interesting part: zone resilience arriving as a property of the tier rather than as a rearchitecture, and on General Purpose rather than only the premium tier.
Managed Instance on Azure App Service reached general availability. It targets web applications that cannot be modernised cheaply β those depending on Windows services, third-party libraries and custom runtimes β and moves them into managed PaaS with minimal configuration and no code changes.
Azure Databricks Lakebase became generally available in four additional regions, and Azure Linux on WSL entered public preview in beta, putting the same Microsoft-supported Linux on the developer workstation as in production.
The retirement that needs a purchase order
The Azure VMware Solution license-included service will be retired on 30 August 2027. The cause is not Azure: Broadcom changed VMware licensing across all hyperscaler platforms to require customers to bring their own portable VMware Cloud Foundation licence.
What that means concretely is that customers on license-included Reserved Instance SKUs must purchase portable Broadcom VCF licences and move to an AVS VCF bring-your-own-licence SKU β or leave AVS. There is no technical migration path that avoids the commercial one, and the deadline is a year out precisely because procurement of that kind takes longer than an engineering change.
A year sounds generous. It is one budget cycle, and the decision belongs to whoever owns the licence relationship rather than to the platform team who will be asked about it.
Security advisories
Nineteen distinct Azure and Entra advisories, the bulk of them published on Thursday. Grouped by what they touch:
- Identity β CVE-2026-69836 Microsoft Entra ID remote code execution, and CVE-2026-69851 Entra ID elevation of privilege. A remote code execution advisory against the identity plane is the one to read first this week.
- Data β four Azure SQL Database elevation of privilege advisories (68789, 66309, 68782, 69502), two Azure Data Factory (62834, 66800), two Microsoft Fabric (63509, 56642), and CVE-2026-65770 against Azure Managed Instance for Apache Cassandra.
- Hybrid and infrastructure β two Azure Arc elevation of privilege advisories (65816, 69555), CVE-2026-47632 against the Azure Connected Machine Agent, CVE-2026-69543 against Azure Virtual Machines, and CVE-2026-69519 against Azure Stack HCI, the product now called Azure Local.
- Application and agents β CVE-2026-69400 Azure Logic Apps, CVE-2026-69419 Azure Data Manager for Energy, and CVE-2026-69855 Microsoft Copilot in Azure.
The Arc and Connected Machine Agent pair deserve a second look for anyone with a large hybrid estate: those agents run on servers you own, at privilege, and they are patched on your schedule rather than Microsoft's.
Beyond the announcements
Three items from Microsoft's blogs that carry more than the announcement feed did:
- What-If for Azure Deployment Stacks is generally available β preview of what a stack deployment would change, including what it would delete. For a construct whose whole point is managing resource lifecycle, seeing the deletions before committing is the feature that makes it usable in production.
- Azure DNS introduces Traffic Manager linked records in public preview β linking a DNS record to a Traffic Manager profile rather than maintaining the indirection by hand.
- What it really takes to run GitHub Actions runners on AKS β the operational detail behind a pattern that is usually described as a five-minute setup.
Also this week: Entra ID tightened the security of branded sign-ins, and the Terraform AzureRM provider shipped a release.
What I would act on
- Start the Azure VMware Solution licence conversation now. 30 August 2027 is one budget cycle away, the resolution is a Broadcom purchase rather than an Azure configuration, and the people who decide it are not the people who will notice the deadline.
- Check your advertised prefix count if you run hub-and-spoke at scale. Microsoft has explicitly named approaching gateway prefix limits as a common condition. Summarisation is now GA on both gateway types, so the ceiling is optional β if your addressing plan is clean enough to summarise.
- Model the licence saving from constrained cores on any per-core licensed workload. This is the rare compute feature whose benefit shows up on a software invoice rather than an Azure one.
- Patch the Arc and Connected Machine Agent advisories deliberately. Unlike the platform-side CVEs, these run on your servers and wait for you.
- If you are on SQL Managed Instance General Purpose, read the zone redundancy preview. Up to 99.995% uptime without an architecture change is a rare shape of upgrade, though it is preview and should be treated as such.
Complete inventory β all 14
Every announcement published to Azure Updates between Monday 17 and Friday 21 August 2026.
| Date | Announcement | Status |
|---|---|---|
| 20 Aug | Azure Copilot introduces direct access to agents | Change |
| 20 Aug | Summarized advertised gateway prefixes for route advertisement | GA |
| 19 Aug | vCore Customization: disable multithreading and configurable constrained cores | GA |
| 19 Aug | Azure SQL updates for mid-August 2026 | GA |
| 19 Aug | SQL Formatter in MSSQL extension | Preview |
| 19 Aug | Azure SQL Database provisioning in MSSQL extension | GA |
| 19 Aug | Bring Your Own NIC in Azure Site Recovery | GA |
| 19 Aug | Azure Databricks Lakebase in four additional regions | GA |
| 18 Aug | Managed Instance on Azure App Service | GA |
| 18 Aug | IPv6 support in Azure Firewall | Preview |
| 18 Aug | Retirement: Azure VMware Solution license-included service, 30 August 2027 | Retirement |
| 17 Aug | Dragon Copilot physician apps and agents on Microsoft Marketplace | GA |
| 17 Aug | Zone redundancy for Azure SQL Managed Instance Next-gen General Purpose | Preview |
| 17 Aug | Azure Linux on WSL | Preview |
Official Azure references
- Summarized advertised gateway prefixes for route advertisement
- vCore Customization: disable multithreading and configurable constrained cores
- IPv6 support in Azure Firewall
- Zone redundancy for Azure SQL Managed Instance Next-gen General Purpose
- Managed Instance on Azure App Service
- Retirement: Azure VMware Solution license-included service
- Azure Linux on WSL
- Azure Databricks Lakebase in four additional regions
Comments