
Principal Cloud Solutions Architect
In a concise weekly update, John Savill's [MVP] walks viewers through a broad set of changes to Azure services announced on 19 September 2025. The video combines quick chaptered highlights with short explanations, and it reflects the present pace of platform change that many cloud teams now face. Notably, the creator also warns that channel growth prevents him from answering viewer questions directly, and he suggests community forums for follow-up, which underscores the practical limits of one-to-many guidance in fast-moving cloud environments.
One of the most impactful items covered is the new requirement for managed identities on Azure Virtual Desktop host pools created through the Azure portal, effective immediately for new deployments. This move replaces service principal patterns with per-host pool identities, improving security by granting narrower permissions and enabling automated permission assignment for resources like Key Vault. Consequently, organizations can restrict public access to secrets and still allow secure host pool operations, while also supporting cross-subscription images within the same tenant.
However, the change introduces tradeoffs and operational friction that Savill highlights, since existing host pools will face staged enforcement in October and November 2025 that prevents session host configuration updates without adding a managed identity. Teams must therefore weigh the security gains against the effort to modify automation, update templates, and validate role assignments. In practice, this shift accelerates a move toward zero-trust principles, but it also requires coordination across identity, security, and platform engineering teams to avoid disruption during the rollout.
Savill explains that Microsoft plans to retire default outbound internet access for new virtual machines using shared and dynamic public IPs as of 30 September 2025, meaning new VMs must use explicit outbound methods such as NAT Gateway, load balancer rules, or assigned public IPs. The change aims to increase control and security by forcing operators to design explicit egress paths rather than relying on an implicit shared route that can hide exposure. Existing VMs will keep the old behavior temporarily, but organizations should plan to migrate configurations to avoid future surprises and to maintain compliance with internal network policies.
The tradeoffs involve cost, complexity, and manageability: choosing NAT Gateway or assigning public IPs will raise operational costs and may require updates to infrastructure-as-code, while load balancer rules can preserve some cost-efficiency but add configuration overhead. Furthermore, teams must test egress rules thoroughly, because misconfigurations can break outbound connectivity for patching, telemetry, or service interactions. Ultimately, the security benefits are significant, but they demand investment in planning, testing, and governance to balance budget and reliability concerns.
Beyond identity and networking, the video touches many smaller but meaningful platform updates that cloud teams should track, including lifecycle notes for AKS variants, VM generation changes such as HBv5 and DCa/ECa v6, retirement timelines for services like AKS on VMware and Azure Databricks Standard, and feature news for Azure Functions and Durable Functions. Savill also flags enhancements to the App Gateway v2 backend TLS controls and dedicated backend connections, which affect application delivery security and performance. These updates together show Microsoft emphasizing secure defaults, platform consolidation, and tighter control over runtime and networking surfaces.
He also highlights Storage, Monitoring, and AI-adjacent features, including a new major version for Azure Container Storage, region expansions for file services, licensing changes for cloud VMware solutions, and preview capabilities such as video-to-video transformation around the Sora family. While each item may not demand immediate action, collectively they require teams to maintain inventories of used services and to watch retirement dates, compatibility notes, and any breaking changes that could interrupt deployments.
Practically, Savill urges teams to start with an inventory and impact assessment, mapping which host pools, VMs, and services will be affected by managed identity mandates and outbound egress retirement. Next, organizations should update templates and pipelines to inject managed identities, adopt explicit egress architectures, and test service interactions in staging to reduce the risk of outages. These steps help reconcile the improved security posture with the increased operational work that comes with more explicit control.
In addition, teams must balance cost and complexity when choosing solutions; for example, a NAT Gateway delivers predictable security and scale but increases spend, whereas load balancer solutions might lower costs yet require more operational oversight. Ultimately, the video reinforces that stronger defaults and more granular identity models improve long-term resilience, but they also shift effort onto DevOps and security teams who must plan, automate, and monitor the transition carefully to preserve uptime and control budgets.
John Savill's update synthesizes a busy set of Azure changes into actionable observations, and it stresses that the platform is moving toward tighter governance and explicit control by design. Therefore, organizations should treat these announcements as prompts to review identity models, egress designs, and lifecycle exposure across the estate, while coordinating cross-team work to avoid surprises. In short, the video offers a practical roadmap: adopt managed identities, plan outbound migration, and maintain service inventories to align security goals with operational realities.
Azure update September 2025, Azure September 19 2025 release, Azure new features 2025, Azure service updates Sep 2025, Azure security updates September 2025, Azure AI updates September 2025, Azure pricing changes 2025, Azure Kubernetes updates Sep 2025