Azure Update - 19th September 2025
Azure Weekly Update
19. Sept 2025 15:57

Azure Update - 19th September 2025

von HubSite 365 über John Savill's [MVP]

Principal Cloud Solutions Architect

Azure update: AKS App Service changes, Azure Functions .NET support, App Gateway TLS, Databricks retire, PostgreSQL

Key insights

  • Azure Virtual Desktop now requires Managed identities for new host pools created in the Azure Portal (effective 19 Sep 2025).
    This replaces service principal use with per-host-pool permissions to improve security and simplify automated permission assignment.
  • Default outbound internet access for new Azure VMs is retired (effective 30 Sep 2025).
    Admins must configure explicit outbound methods such as NAT Gateway, load balancer outbound rules, or assigned public IPs to maintain internet connectivity.
  • Migration timeline: existing AVD host pools and VMs get phased updates after these dates (host pools follow in Oct–Nov 2025).
    Session host configuration updates and new session host creation will be blocked unless a managed identity is added, so plan changes now to avoid outages.
  • Zero-trust and granular permissions are the goal: replacing broad service principals with scoped identities reduces attack surface.
    The change also enables secure access to Key Vaults with restricted public access and supports using cross-subscription images within the same tenant.
  • Notable service updates in this release include AKS lifecycle changes, App Service JBoss EAP BYOL, Azure Functions .NET 10 support, Distributed tracing for Durable Functions, App Gateway v2 TLS/backend controls, Azure Container Storage v2, Databricks and database platform updates, and new region expansions for storage and Data Box services.
    Review vendor-specific retirement notices and feature changes that may affect your workloads.
  • Action items for cloud teams: adopt managed identities for new AVD deployments, schedule outbound connectivity migration for VMs, test changes in staging, update runbooks and IAM processes, and prioritize fixes for any breaking changes flagged in the release.
    Communicate timelines to stakeholders and validate backups and monitoring before applying updates.

Video Overview and Context

In a concise weekly update, John Savill's [MVP] walks viewers through a broad set of changes to Azure services announced on 19 September 2025. The video combines quick chaptered highlights with short explanations, and it reflects the present pace of platform change that many cloud teams now face. Notably, the creator also warns that channel growth prevents him from answering viewer questions directly, and he suggests community forums for follow-up, which underscores the practical limits of one-to-many guidance in fast-moving cloud environments.

Identity Changes: Azure Virtual Desktop Requires Managed Identities

One of the most impactful items covered is the new requirement for managed identities on Azure Virtual Desktop host pools created through the Azure portal, effective immediately for new deployments. This move replaces service principal patterns with per-host pool identities, improving security by granting narrower permissions and enabling automated permission assignment for resources like Key Vault. Consequently, organizations can restrict public access to secrets and still allow secure host pool operations, while also supporting cross-subscription images within the same tenant.

However, the change introduces tradeoffs and operational friction that Savill highlights, since existing host pools will face staged enforcement in October and November 2025 that prevents session host configuration updates without adding a managed identity. Teams must therefore weigh the security gains against the effort to modify automation, update templates, and validate role assignments. In practice, this shift accelerates a move toward zero-trust principles, but it also requires coordination across identity, security, and platform engineering teams to avoid disruption during the rollout.

Networking Shift: Retirement of Default Outbound Internet for New VMs

Savill explains that Microsoft plans to retire default outbound internet access for new virtual machines using shared and dynamic public IPs as of 30 September 2025, meaning new VMs must use explicit outbound methods such as NAT Gateway, load balancer rules, or assigned public IPs. The change aims to increase control and security by forcing operators to design explicit egress paths rather than relying on an implicit shared route that can hide exposure. Existing VMs will keep the old behavior temporarily, but organizations should plan to migrate configurations to avoid future surprises and to maintain compliance with internal network policies.

The tradeoffs involve cost, complexity, and manageability: choosing NAT Gateway or assigning public IPs will raise operational costs and may require updates to infrastructure-as-code, while load balancer rules can preserve some cost-efficiency but add configuration overhead. Furthermore, teams must test egress rules thoroughly, because misconfigurations can break outbound connectivity for patching, telemetry, or service interactions. Ultimately, the security benefits are significant, but they demand investment in planning, testing, and governance to balance budget and reliability concerns.

Other Notable Platform Updates

Beyond identity and networking, the video touches many smaller but meaningful platform updates that cloud teams should track, including lifecycle notes for AKS variants, VM generation changes such as HBv5 and DCa/ECa v6, retirement timelines for services like AKS on VMware and Azure Databricks Standard, and feature news for Azure Functions and Durable Functions. Savill also flags enhancements to the App Gateway v2 backend TLS controls and dedicated backend connections, which affect application delivery security and performance. These updates together show Microsoft emphasizing secure defaults, platform consolidation, and tighter control over runtime and networking surfaces.

He also highlights Storage, Monitoring, and AI-adjacent features, including a new major version for Azure Container Storage, region expansions for file services, licensing changes for cloud VMware solutions, and preview capabilities such as video-to-video transformation around the Sora family. While each item may not demand immediate action, collectively they require teams to maintain inventories of used services and to watch retirement dates, compatibility notes, and any breaking changes that could interrupt deployments.

Operational Implications and Recommended Actions

Practically, Savill urges teams to start with an inventory and impact assessment, mapping which host pools, VMs, and services will be affected by managed identity mandates and outbound egress retirement. Next, organizations should update templates and pipelines to inject managed identities, adopt explicit egress architectures, and test service interactions in staging to reduce the risk of outages. These steps help reconcile the improved security posture with the increased operational work that comes with more explicit control.

In addition, teams must balance cost and complexity when choosing solutions; for example, a NAT Gateway delivers predictable security and scale but increases spend, whereas load balancer solutions might lower costs yet require more operational oversight. Ultimately, the video reinforces that stronger defaults and more granular identity models improve long-term resilience, but they also shift effort onto DevOps and security teams who must plan, automate, and monitor the transition carefully to preserve uptime and control budgets.

Conclusion

John Savill's update synthesizes a busy set of Azure changes into actionable observations, and it stresses that the platform is moving toward tighter governance and explicit control by design. Therefore, organizations should treat these announcements as prompts to review identity models, egress designs, and lifecycle exposure across the estate, while coordinating cross-team work to avoid surprises. In short, the video offers a practical roadmap: adopt managed identities, plan outbound migration, and maintain service inventories to align security goals with operational realities.

Azure Weekly Update - Azure: New Features & Fixes — Sep 19

Keywords

Azure update September 2025, Azure September 19 2025 release, Azure new features 2025, Azure service updates Sep 2025, Azure security updates September 2025, Azure AI updates September 2025, Azure pricing changes 2025, Azure Kubernetes updates Sep 2025