Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms 

Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms, which we believe recognizes the platforms organizations rely on to build, deploy, and operate cloud-native applications at scale. This is our third consecutive year positioned as a Leader in this report.

Read the report

We are proud of this recognition. More importantly, we believe it reflects a shift we see across industries. Cloud-native application platforms are no longer where organizations build and run modern applications. They are becoming the foundation for AI transformation.

The challenge is not a shortage of AI ideas. It is turning those ideas into production systems that can connect to existing applications and data, perform reliably at global scale, and meet the security and governance standards the business already expects. That requires more than a collection of application services. It requires a platform that brings application modernization, AI innovation, operations, and security together.

Microsoft’s cloud-native application platform is designed around that reality. Azure App Service provides a managed foundation for enterprise web applications and modernization. Container Apps runs cloud-native applications, APIs, AI inferencing, and agents without requiring teams to manage infrastructure. Azure Functions provides event-driven execution and integration, while API Management governs APIs, models, and agent tools through a consistent policy layer. Together with Microsoft Foundry, GitHub Copilot, and the shared Azure foundation for identity, networking, observability, and security, these capabilities give organizations one platform for what they already run and what they build next.

Gartner® Magic Quadrant™ graphic for Cloud-Native Applications Platform 2026

Build AI apps and agents faster

Microsoft brings the application runtime and AI toolchain together so developers can build with the model, framework, and architecture that fits the job. Microsoft Foundry provides the models, agent tooling, evaluation, tracing, and safety capabilities needed to take AI systems into production. GitHub Copilot helps developers move faster across the development lifecycle. Azure’s application platform provides the managed runtime, event-driven execution, integration, and API capabilities to turn those systems into applications people can rely on.

This is where platform capabilities matter. Developers can deploy a container directly to a production endpoint with Azure Container Apps Express, and use Azure Functions to expose existing business logic through the Model Context Protocol. More than 1,400 connectors help agents act across enterprise systems without requiring developers to rebuild authentication, retries, and integration logic for every connection.

Azure Container Apps Sandboxes provide the isolated compute that agent platforms run on. The same primitive runs the agent itself, hosts its tools and MCP servers, and executes the code it generates, each in its own microVM, hardware-isolated boundary, with state that survives when the agent pauses. It is the compute layer behind Foundry Agent Service and is available to customers building and operating their own agent platforms on Azure.

The result is a shorter path from an AI idea to a governed application or agent that can deliver on your business goals.

Modernize applications regardless of architecture

AI transformation starts with the application estate organizations already have, not a blank slate. Azure gives teams a practical path to modernize at their own pace. They can move established applications to fully managed Platform as a Service (PaaS) services, containerize where it makes sense, adopt event-driven patterns incrementally, and extend existing business logic so it can participate in AI-powered experiences. App Service Managed Instance helps organizations move complex Windows and .NET applications without requiring a rewrite, while GitHub Copilot app modernization accelerates assessment and remediation. Once modernized, those applications can connect to the same data, AI services, APIs, identity controls, and operational practices as new cloud-native applications.

This flexibility protects the value already in the application estate while creating a foundation for continuous innovation. Organizations do not have to choose between modernizing the core and building for the AI era. The platform makes those efforts part of the same strategy.

Secure, govern, and simplify operations

AI applications raise the operational bar. Agents can call APIs, execute generated code, and interact with sensitive systems at a speed and volume that traditional controls were not designed to manage. Security, governance, and observability cannot be added after deployment. They need to be part of the platform.

Azure provides shared identity, networking, policy, and security controls across the application estate. Azure API Management extends that consistency to APIs, MCP servers, and model endpoints. Its AI gateway capabilities help teams authenticate access, enforce token limits and quotas, balance traffic across models, apply semantic caching, and monitor how AI services are consumed. Azure Container Apps Sandboxes add hardware-level isolation for agent-generated or untrusted code, while confidential computing and Microsoft Defender strengthen protection for sensitive workloads.

Operations also need to keep pace with development. Azure combines global reach with managed scaling across web apps, containers, functions, and APIs. Built-in load balancing, zone redundancy, deployment controls, and integrated observability help teams maintain performance as usage grows. Azure Monitor and Application Insights give teams end-to-end visibility across applications and AI workloads. Azure SRE Agent brings agentic operations into that environment by helping teams investigate incidents, identify root causes, and take auditable remediation actions. Together with GitHub Copilot, these capabilities create a secure and reliable path across the application lifecycle, from development to production operations.

Customer momentum across the platform

Across banking, retail, healthcare, manufacturing, IT, and other industries, organizations are running their most critical applications and their newest AI workloads on the same Azure foundation.

A clean cloud architecture is a prerequisite for AI. You can’t build on top of a weak foundation.
Mike Gibson, Chief Technology Officer, Planet DDS

Planet DDS built that foundation on Azure. It modernized its platform on Azure App Service and cut provisioning time from six weeks to one day, which gives its teams room to invest in the product rather than the plumbing. Replit and Microsoft Azure now put enterprise software building in reach of every Hexaware employee, extending development beyond the people who write code for a living.

That same platform is already running AI in production. Commerzbank runs its agentic AI architecture on Azure Container Apps, where its Ava assistant handles more than 30,000 customer conversations each month and resolves 75% of them autonomously. Ghassan Aboud Group built its Ragin AI platform on Azure Container Apps to deliver agentic customer experiences across its businesses. Levi Strauss and Co. uses Microsoft Foundry to simplify everyday work and accelerate decision-making. These are not experiments running alongside the business. They are AI systems operating inside it.

Taken together, these stories describe one platform doing several jobs at once. It carries existing applications forward, runs new AI and agentic workloads in production, and gives organizations a common foundation to operate both with confidence.

We believe the next generation of applications will be cloud-native, AI-powered, and deeply connected to the systems organizations already rely on. In our view, Microsoft’s position as a Leader for the third consecutive year reinforces our commitment to giving every organization one secure, scalable platform to modernize what it has and build what comes next.

Get started

Wherever you are in your journey, there is a place to begin today.

Building AI apps and agents. Start on Azure Container Apps to build your agentic applications with built-in enterprise security and ultra-fast scale.

Modernizing existing applications. Bring Windows and .NET workloads forward with App Service Managed Instance, and use GitHub Copilot app modernization to accelerate assessment and remediation.

Running event-driven and API-centric workloads. Build with Azure Functions and manage your APIs, MCP servers, and model endpoints through Azure API Management.

Operating with confidence. Add Azure SRE Agent and Azure Monitor to bring agentic operations and end-to-end observability to what you already run.

Microsoft Named a Leader by Gartner®

Learn why Microsoft earned Leader recognition in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms.

Read the report

Gartner ® Magic Quadrant™ for Cloud-Native Application Platforms, Mukul Saha, Alex Coqueiro, Prasanna Lakshmi Narasimha, Richard Watson, August 3, 2026. 

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose. 

Gartner and Magic Quadrant are trademarks of Gartner, Inc., and/or its affiliates. 

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from here. 
The post Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms  appeared first on Microsoft Azure Blog.
Quelle: Azure

The Economics of Agent Optimization: From pilots to measurable returns

This blog post is the first of a four-part series called The Economics of Agent Optimization which shares the strategies, capabilities, and proof points to help you optimize agent costs and run AI as a managed investment system on Microsoft Foundry.

The AI conversation in most enterprises has moved from the whiteboard to the budget review. Two years ago, the question was whether AI could work. The question leaders are asking now is sharper and less comfortable: is it paying for itself?

For the teams now in production—including more than 100,000 organizations building on Microsoft Foundry that question has become urgent. Tokens have become the new unit of technology spend, and financial discipline (not model choice) is what decides whether a promising pilot ever scales. The money is already moving in: in a Microsoft-commissioned IDC study of more than 4,000 business leaders, 71% said they plan to increase AI budgets, funded from IT and non-IT sources alike. The budgets are growing. The question is whether the discipline grows with them. 

71% of business leaders plan to increase their AI budgets2025 IDC survey

The teams pulling ahead did not go looking for a cheaper model. They stopped running AI as a string of one-off pilots and started running it as a managed investment system: every request sized to its job, every agent improved as it runs, and every dollar bounded and accounted for. That shift, from buying intelligence to managing it, is the whole game. This series is about how the system works and why Microsoft Foundry is built to run it.

Start building on Microsoft Foundry

Understand your AI costs and spending

Before you can manage AI spend, you need to understand what creates it. Cost is not determined only by the model you choose. It is also shaped by the application or agent built around that model.

Every request includes input tokens, such as system prompts, conversation history, tool definitions, and retrieved content, as well as output tokens generated by the model. Because models are stateless, the full context is sent with every request. Costs can increase over time even when the user asks only a simple follow-up question.

Agents introduce another layer of complexity. Instead of following a single path, an agent may evaluate options, retry actions, or call multiple tools before producing a response. A single user request can generate many model calls, making workflow design as important as model selection.

Improve AI cost visibility across teams

AI spend is difficult to manage when it appears as a single aggregate number. Teams need visibility into costs by application, agent, workflow, and model to understand what is driving usage and where optimization opportunities exist.

Without that level of attribution, it becomes difficult to explain costs, prioritize improvements, or measure the impact of optimization efforts.

Control and optimize spend

Visibility alone is not enough. AI workloads can scale quickly, and unexpected behavior can increase consumption in a short period of time. Organizations need controls that help manage spend before costs become a surprise.

Optimization also requires more than selecting a lower-cost model. Most AI workloads contain a mix of requests with different requirements. Better outcomes come from matching requests to the right models, reducing unnecessary context, limiting unneeded tool use, and improving agent workflows so they operate more efficiently.

Why Microsoft is the platform for AI FinOps

FinOps began as the discipline of bringing financial accountability to variable cloud spend, a shared operating model that puts engineering, finance, and product on one set of numbers. FinOps for AI comes down to four commitments:

Make AI predictable to fund

Efficient by design

Optimized at scale

Proven in value 

Microsoft’s answer is a single, first-party approach to FinOps for AI that spans the entire lifecycle—plan, build, manage, and measure. Cost visibility and control are built into the products teams already use: Microsoft Foundry and GitHub where agents are built and run, Microsoft Cost Management for allocation and chargeback, Azure pricing offers for commitment-based savings, and Azure API Management as the gateway that meters and governs AI traffic. Microsoft Agent 365 extends the same discipline to the tenant—unifying agent cost management across Microsoft and third-party platforms with spending policies, budget caps, and departmental chargeback in one place. Together they give organizations something no point tool can: comprehensive, best-in-class cost management across the whole AI estate, from the first prompt to the board-level ROI number.

Foundry is where that approach gets specific, because it’s where agents are run and optimized. It runs AI as a managed investment system across one closed loop: optimize each request at runtime, optimize each agent workflow over time, and govern the spend continuously.

AI cost optimization starts with visibility

A managed investment system makes three decisions, each at a different speed. You optimize the request in the moment it runs. You optimize the agent workflow over days and weeks, as you learn what works. And you govern the spend continuously, with limits and budgets that never sleep. Foundry is built to make all three. Each move has its own set of Foundry capabilities, and the map below shows how they fit together. 

The decisionWhat Foundry gives youOptimize the request, at runtimeRight-size every call so simple work never pays frontier prices.Model router for Microsoft Foundry routes each prompt across cost, quality, and balanced modes, so simple requests don’t pay frontier-model prices.Deployment and pricing options match each workload to its cost and latency needs, spanning Global, Data Zone, and Regional deployments and the Standard, Priority, Provisioned Throughput, and Batch processing modes.Prompt and semantic caching reuse repeated context instead of paying to recompute it.Fine-tuning lets a smaller tuned model match a larger one on your task, lowering the per-token rate and shortening prompts.Microsoft IQ provides a shared enterprise intelligence layer across how people work, how the business operates, institutional knowledge, and the web. Within that layer, Foundry IQ gives agents reusable, permission-aware knowledge bases and uses agentic retrieval to select only the most relevant context. This improves grounding while reducing unnecessary input tokens.Optimize the workflow, over timeMake each agent cheaper as it learns what works. Agent optimizer tests prompts, models, tools, and skills against your own evaluators and promotes the best configuration, often holding quality on a smaller, cheaper model. Toolboxes send only the tools a request needs instead of every definition. Memory (procedural, user, and session memory) carries context across turns without resending the full history. Govern the spend, continuously Set limits and budgets that hold, so no agent can run away with the bill. Azure API Management’s AI Gateway can be deployed in front of your Foundry endpoints as a separate AI Gateway layer, applying token rate limits, quotas, and caching for teams that already standardize on Azure API Management. We are working to deliver more seamless and integrated AI Gateway functionalities in Foundry.Foundry in-platform budgets and enforcement will be available soon to bring spending limits and enforcement natively into Foundry, closer to where agents run. Foundry gives you model- and deployment-level cost reporting today, with Azure Cost Management as the system of record for budgets, alerts, and billed costs. Richer attribution, down to the individual agent and session, is on the roadmap.

Agent 365 will extend governance to the tenant, unifying cost management across Microsoft and third-party agents with spending policies, budget caps, and departmental chargeback. 

You can watch the runtime levers work live in our new Microsoft Mechanics episode on token economics.

The four questions AI leaders should be asking

If you take one thing from this post, take these four questions into your next AI or budget review. Each has a concrete answer in Foundry. If you cannot answer one today, that is where to start.

Do we know what we’re paying for?Spend should be visible by model, agent, and workflow, not hidden in a single invoice line. Foundry’s metering and traces make it easier to understand where costs originate.

Are we paying the right amount for each request?Most requests do not need a frontier model. Model router, deployment and pricing options, caching, fine-tuning, and Foundry IQ help match each request to the capability it needs.

Are our agents operating efficiently?Agent costs should improve over time as workflows become more effective. Agent optimizer and memory in Foundry Agent Service and Toolboxes in Foundry help reduce unnecessary token usage and improve execution quality.

Do our limits hold when usage spikes?Usage that expands rapidly needs controls that hold. Today, many teams put Azure API Management in front of their AI endpoints to enforce token rate limits and quotas at the AI Gateway layer. Native budgets and enforcement inside Foundry, plus tenant-wide controls through Agent 365, are where we are headed next.

The first question is about understanding AI spend. The next three are the areas this series explores in more detail: matching requests to the right models, improving agent efficiency, and applying governance controls to manage cost at scale.

Get started

This series will continue over the coming weeks, going one level deeper on each subsequent move: how to optimize the request at runtime, how to build agents that use tokens efficiently, and how to govern the spend as you scale. Each post pairs the thinking with the Foundry capabilities that make it real.

You don’t have to wait to start. The capabilities behind this framework are live in Microsoft Foundry today:

Learn more about the ways to optimize model cost and performance in Microsoft Foundry.

Watch the token economics episode on Microsoft Mechanics for a hands-on look at the levers in action.

Follow along as the series unfolds and bring the four questions to your next review.

Build an AI investment strategy that scales

Foundry is the enterprise AI platform to build, ground, and govern AI apps and agents at scale.

Start building today

The post The Economics of Agent Optimization: From pilots to measurable returns appeared first on Microsoft Azure Blog.
Quelle: Azure

Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for AI-Augmented Code Modernization Tools

In this article

Cloud-native modernizationThe problem we set out to solveHow it worksWhere we believe we stand apartThe results that make it realThis is the starting line

Microsoft has been named a Leader in the inaugural 2026 Gartner® Magic Quadrant™ for AI-Augmented Code Modernization Tools, which recognizes software solutions that use specialized AI agents, generative AI, and deterministic analysis to accelerate the transformation of legacy systems. We are proud of our placement as a Leader in this first edition of the report.

Cloud-native modernization

Microsoft’s conviction from the start has been that modernization should become one of the fastest, most trusted, and most predictable workflows organizations undertake, and agentic AI is what finally makes that possible. For years, modernization and innovation competed for the same budget, and modernization usually lost. Now the math has changed: modernization is no longer the tax teams pay before they can innovate, it is the fastest path to it, and the gateway to AI. Eliminating decades of technical debt is what lets teams embed intelligence directly into the proven, high-value systems that already run their business. This modern foundation turns the assets they depend on most into the platform for what comes next.

Read the report

None of this is on the horizon; it is happening now. Modernization is shifting from a multi-year program into something teams finish in days or weeks.

Today, organizations are not just moving to the cloud or reducing technical debt, they are fundamentally rethinking their applications, their data, and their infrastructure because they know the decisions they make today will determine whether they are AI-ready tomorrow. Every modernization decision is now an AI decision.

Microsoft Azure was built for this moment. It provides the agentic foundation and engine for modernization and AI transformation, along with the governance and trust enterprises require, so modernization lowers security, data, and operational risk as much as it accelerates AI readiness. With agentic tooling and an end-to-end modernization solution powered by GitHub Copilot and Azure Copilot, Microsoft is accelerating the shift, not just leading it.

The problem we set out to solve

Every enterprise carries code it cannot afford to rewrite and cannot afford to ignore. Legacy .NET Framework applications, Java runtimes, aging dependencies, and accumulated security debt power critical business processes while also limiting an organization’s ability to move forward. For decades, modernization meant large teams, months of manual effort, and a real risk of breaking what already works. As a result, it got deferred, repeatedly, while technical debt compounded and the distance to the cloud grew.

We feel Gartner frames the opportunity perfectly: software engineering leaders can meaningfully reduce the time, effort, and risk of modernization by using AI-powered tools rather than manual approaches. That distance, between the cost of standing still and the cost of moving, is exactly where we put our focus. The goal was never to help teams modernize a little faster. It was to fundamentally change the economics of modernization.

How it works

The engine behind this is GitHub Copilot modernization, an agentic, end-to-end approach that helps teams assess, upgrade, and migrate applications to Azure, with AI handling repetitive tasks while developers remain firmly in control.

We deliver it through two layers that work together. The modernization agent, available through the Modernize CLI, enables architects and application owners to orchestrate assessment, planning, and framework-upgrade automation across many applications at once, then delivers robust application-specific plans to developers. Inside the IDE, developers use GitHub Copilot to execute those plans: upgrading runtimes and frameworks, migrating dependencies to Azure services, generating infrastructure-as-code, and deploying to production. Assessment, planning, transformation, validation, and deployment become one continuous, guided journey rather than a dozen disconnected steps.

What we chose not to automate matters just as much, and that is human judgment. Every recommendation is transparent, every change is reviewable, and every step is validated against your own tests and pipelines. This is modernization at machine speed, with the accountability enterprises require.

Where we believe we stand apart

Breadth: Github Copilot modernization spans the languages that actually run the enterprise—.NET, Java, C++, and Python—rather than a single stack, so platform teams can standardize on one approach.

Repeatable expertise: Predefined tasks capture best practices for common migration patterns, such as adopting managed identities, Azure Key Vault, Blob and File storage, or Microsoft Entra ID. Then custom skills let teams turn their own proven code changes into reusable patterns, applying them consistently across projects and ensuring institutional knowledge stays within the organization.

Trust built in: Security is part of the workflow, not a phase bolted on at the end. Copilot validates builds, migrates unit tests, scans for CVEs after upgrades, and applies fixes in agent mode—strengthening your security posture as you modernize, not after.

Enterprise readiness: Modernizing one application is a project; modernizing an entire estate is a business imperative. What makes the difference at scale is consistency: the patterns that work become reusable tasks and skills any team can apply again, so a proven approach spreads across the portfolio instead of being reinvented app by app. It is what turns modernization from a string of one-off wins into a repeatable, governable practice.

The destination, not just the journey: Modernization is continuous. Applications land on Azure—Azure App Service, Azure Container Apps, Azure Kubernetes Service—and become ready to tap into the full system from silicon to software. This includes Microsoft Foundry’s catalog of more than 11,000 models and Microsoft IQ, the enterprise intelligence layer that grounds AI agents in your organization’s own data and knowledge. Teams don’t just retire technical debt; they unlock what’s next.

The results that make it real

The numbers coming back from teams already doing this work are what change the conversation. Customers using GitHub Copilot modernization capabilities report up to 70% less time spent on migration efforts and 50% less effort to upgrade applications. Some have moved more than 500,000 lines of code in a matter of weeks, work that once would have consumed quarters. Adoption tracks the same story: more than 1.4 million developers have already installed the experience.

GitHub Copilot’s modernization agent significantly saved time on our Java modernization effort from days down to mere hours at SAP Labs. It runs seamlessly at scale, significantly reducing manual complications for our developers. The modernization agent is now an essential pillar of our modernization effort.
—Dr Richard Cai, Managing Director, SAP Labs China

This is the starting line

Being named a Leader in this Magic Quadrant is an honor for us, and candidly it is an obligation. The teams that adopt AI-powered modernization now will spend the next decade building on modern, secure foundations, in the cloud or hybrid, while others are still untangling the past. We intend to keep widening that gap with deeper language and framework coverage, richer agentic automation, and an ever-shorter path from legacy code to production on Azure.

To every customer and partner who has modernized alongside us, thank you. You shaped this, and you are the reason for the recognition.

If you are ready to see what is possible, explore agentic modernization and start with a single application this week. You can also read a complimentary copy of the report to see why Microsoft was named a Leader.

Microsoft named a Leader

Learn more about the 2026 Gartner® Magic Quadrant™ for AI-Augmented Code Modernization Tools

Read the report

Gartner ® Magic Quadrant™ for AI-Augmented Code Modernization Tools, Prasanna Lakshmi Narasimha, Erin Khoo, Deacon D.K Wan, Wei Jin, 3 August 2026

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Gartner and Magic Quadrant are trademarks of Gartner, Inc., and/or its affiliates.

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from: https://www.gartner.com/reprints/?id=00ThR000008k1rGUAQ&ct=260804&st=sb
The post Microsoft named a Leader in the 2026 Gartner® Magic Quadrant™ for AI-Augmented Code Modernization Tools appeared first on Microsoft Azure Blog.
Quelle: Azure

What customers value most in Microsoft Databases—from reliability to AI readiness

In this article

What customers consistently value Turning customer feedback into innovation Thank you to our customers and community

Every day, customers trust Microsoft Databases to power their most critical applications, business processes, and AI-powered experiences. Continuous customer feedback provides valuable insights into how these technologies perform in production and where we should continue investing.

I’m honored to share that Microsoft Databases have received multiple 2026 PeerSpot Customer Choice / Tech Leader recognitions based on feedback from real practitioners using these technologies in production environments.

This year, PeerSpot recognized:

SQL Server as a Tech Leader in Database Management Systems (DBMS) (#1) and Relational Database Tools (#1)

Azure SQL Database as a Tech Leader in Database as a Service (DBaaS) (#2)

Azure Database for PostgreSQL as a Tech Leader in Open Source Databases (#1)

Azure Cosmos DB as a Tech Leader in Managed NoSQL Databases (#1), NoSQL Databases (#1), and Vector Databases (#1)

Learn more about our PeerSpot awards

Customer feedback across Microsoft Databases consistently highlights five themes: reliability, scalability, operational simplicity, developer productivity, and AI readiness. These are the same priorities shaping our investments across SQL Server, Azure SQL Database, Azure Cosmos DB, and Azure Database for PostgreSQL. The PeerSpot recognition reinforces that customers see value not only in the performance of our databases today, but also in how they are helping organizations prepare for the next generation of AI-powered applications.

What customers consistently value

SQL Server: Trusted reliability for mission-critical workloads

For SQL Server customers, reliability, stability, and long-term data stewardship remain foundational requirements. Organizations continue to rely on SQL Server to support business-critical applications, analytics, and increasingly AI-enabled workflows.

Hemanth Reddy Vakiti, a data engineer at Cognizant, wrote that “The backup and recovery allow us to easily access previous 10 to 15 years of data”, citing SQL Server’s ability to handle large datasets and support secure role-based access.

Another SQL Server reviewer, Isseo Martinez from eGlobal, called out availability and stability, saying “We never have concerns about the database.” For many organizations, that confidence is the foundation for business-critical applications and long-term modernization strategies. 

Explore SQL Server 2025

Azure SQL Database: Simplifying modernization with cloud-scale SQL

Customers regularly tell us they want the reliability and familiarity of SQL Server with the operational simplicity of a fully managed cloud service. Azure SQL Database helps organizations modernize applications, reduce infrastructure management, and scale with confidence.

Fredrick Weinshenk, a cloud engineer at healthcare IT firm Med Tech Solutions, wrote that “The ease of deployment and scalability are significant reasons we push our larger clients to Azure,” and described the platform as “reliable” and “solid.”

That feedback reflects a recurring need we hear from customers: modernize infrastructure, reduce operational burden, and retain the SQL skills, tools, and application patterns their teams already trust.

Explore Azure SQL Database

Azure Database for PostgreSQL: Open-source flexibility with enterprise reliability

Customers choose Azure Database for PostgreSQL because it combines the innovation of the PostgreSQL ecosystem with the operational benefits of a managed service.

Wesley Haakman, a principal architect at IT service provider Intercept, using the service across hundreds of customer scenarios, shared that “[the] organization’s database uptime has improved” and highlighted the ease of integration with other Azure services.

Sathish Palanisamy, data engineer at a large transportation company, said “We’ve used Azure Database for PostgreSQL for four years, benefiting from its performance, scalability, ease of integration, and support, especially during migration from Oracle, while also reducing costs and enabling faster, secure, AI-driven innovation in our airline operations.”

These reviews highlight the value customers place on flexibility, modernization, and a clear path to AI-powered innovation.

Explore Azure Database for PostgreSQL

Azure Cosmos DB: Global scale and performance for modern applications

Customers building modern cloud-native and AI-powered applications consistently point to Azure Cosmos DB’s combination of low latency, elastic scalability, flexible data models, and search performance.

Kunal Mukerjee, former vice president of technology strategy at Docusign, said “Cosmos DB has improved search result quality, throughput, and query latency. There are trade-offs to finding the sweet spot among all of these. Having a NoSQL solution that can do that in a 100 percent Azure shop is the best fit we could want.”

Another customer, Yoni Nijs, CTO of Zero Friction, described using Azure Cosmos DB serverless for a highly unpredictable consumer portal and provisioned throughput with autoscale for a back-office application, noting that the configuration was “… very scalable and still cost-effective.”

These are exactly the patterns AI applications demand: responsive global systems that can adapt to changing demand without sacrificing performance or cost efficiency.

Explore Azure Cosmos DB

Taken together, these reviews reinforce a clear message: organizations want databases that are not only secure and scalable, but also ready for the next generation of intelligent applications.

Turning customer feedback into innovation

The themes customers highlighted are the same themes guiding our investments across the Microsoft Databases portfolio. Our goal is not simply to add new features, but to help customers solve real challenges: modernizing existing applications, building AI-powered experiences, reducing operational complexity, and scaling with confidence.

SQL Server

Relational databases continue to power many of the world’s most critical applications. With SQL Server 2025, we’re helping customers extend those applications into the AI era without changing the platforms, skills, or tools they already trust. Native vector support, in-database embedding generation, semantic search, and retrieval-augmented generation (RAG) capabilities make it easier to build intelligent applications while keeping data secure, governed, and close to operational workloads.

Azure SQL Database

With Azure SQL Database, customers get a fully managed cloud-native SQL solution for modernizing and building AI applications. Azure SQL Database Hyperscale helps applications scale with demand and grow as needs evolve, while automatic tuning and elastic resource management improve performance and cost efficiency. Customers can build AI-powered experiences on operational data with AI retrieval and secure agent connectivity, with integrations across key AI and analytics solutions like Microsoft Foundry and Microsoft Fabric. 

This helps their organization build a direct path from business-critical data to intelligent applications, without compromising the security, governance, and performance they expect from Microsoft’s SQL platforms. 

Azure Database for PostgreSQL

For PostgreSQL on Azure, our investments focus on helping customers modernize faster, accelerate AI development, and run mission-critical workloads with greater confidence. Highlights include the public preview of Azure HorizonDB, bringing AI-native capabilities such as integrated vector search, AI functions, AI pipelines, and model management to PostgreSQL; new migration and upgrade innovations including AI-assisted Oracle-to-PostgreSQL migration tooling; and performance improvements such as Premium SSD v2, cascading read replicas, and new high-performance infrastructure options for Azure Database for PostgreSQL. These innovations are helping organizations adopt AI capabilities while continuing to benefit from PostgreSQL’s open-source ecosystem.

Azure Cosmos DB

For customers building AI-native applications, Azure Cosmos DB investments focus on helping developers move faster while simplifying operations at scale. Recent innovations include enhanced vector and hybrid search, semantic reranking, agent-focused development tools, Global Secondary Indexes, per-partition automatic failover, richer change feed capabilities, and improvements to local development through the Linux Emulator. Together, these investments help developers build responsive, AI-powered applications faster while maintaining performance, resilience, and operational efficiency.

Across the portfolio, our goal is consistent: help customers build applications faster, operate them more efficiently, and prepare for a future where AI is deeply integrated into every application experience.

Thank you to our customers and community

These PeerSpot recognitions belong first and foremost to our customers and community.

Every review, product suggestion, support interaction, preview program discussion, and customer conversation helps shape the direction of Microsoft Databases. Your feedback helps other technology leaders make informed decisions, and it helps our teams build better products.

On behalf of everyone across the Microsoft Databases organization, thank you for your trust, your partnership, and your willingness to share your experiences.

I encourage you to read what your peers are saying, and, if Microsoft Databases are helping your organization innovate, consider sharing your own review.

Microsoft Databases

Modernize or build AI-ready apps with intelligent cloud databases.

Get started

The post What customers value most in Microsoft Databases—from reliability to AI readiness appeared first on Microsoft Azure Blog.
Quelle: Azure

GPT-5.6 now available in Microsoft Foundry 

What’s new todayGPT‑5.6 is generally available in Microsoft Foundry, alongside the Asia-Pacific Data Zone, and hosted agents in Foundry Agent Service. See GPT-5.6 pricing.

AI only creates value when it shows up in real systems—systems that are reliable, observable, and aligned to business outcomes. More than 100,000 organizations are already building on Microsoft Foundry, and companies like Adobe, Telefónica, and Tata Consultancy Services are running agents in production today.

At Microsoft Build, we laid out a simple promise for the agentic era: developers should be able to build an agent where they already work, run it on infrastructure they can trust, and put it in front of the people who need it— without stitching together disconnected platforms. Today, that vision moves from roadmap to reality with three sets of updates now generally available in Microsoft Foundry:

OpenAI’s latest frontier model series: GPT-5.6 Sol, GPT-5.6 Terra, and GPT-5.6—each tuned to a different workload, available in Standard Global and Standard Data Zones.

Asia-Pacific Data Zone, giving APAC customers a regional option to run frontier OpenAI models while keeping data processing within the region.

Production agents in Foundry Agent Service, with hosted agents, toolboxes, and publishing to Microsoft 365 Copilot and Microsoft Teams.

Together, these capabilities bring frontier models, production agent runtime, enterprise-grade identity, security, and compliance controls, and distribution across Microsoft 365 into a single platform—helping organizations move from experimentation to production without assembling disconnected tools and services.

Why Foundry is the best agent platform

Microsoft Foundry is Microsoft’s end-to-end platform for building, running, governing, and distributing AI agents. Foundry brings together the capabilities organizations need to move agents into production across three pillars:

Build: Open and flexible across models and frameworks.

Generate: Connected to enterprise data, tools, and users.

Govern: Secured, managed, and optimized for long-term value.

These pillars come together in the latest Foundry updates, helping organizations build, run, and scale production agents on a single platform.

const currentTheme =
localStorage.getItem(‘blogInABoxCurrentTheme’) ||
(window.matchMedia(‘(prefers-color-scheme: dark)’).matches ? ‘dark’ : ‘light’);

// Modify player theme based on localStorage value.
let options = {“autoplay”:false,”hideControls”:null,”language”:”en-us”,”loop”:false,”partnerName”:”cloud-blogs”,”poster”:”https://cdn-dynmedia-1.microsoft.com/is/image/microsoftcorp/1117654-HostedAgent_tbmnl_en-us?wid=1280″,”title”:””,”sources”:[{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x1080-6439k”,”type”:”video/mp4″,”quality”:”HQ”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x720-3266k”,”type”:”video/mp4″,”quality”:”HD”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x540-2160k”,”type”:”video/mp4″,”quality”:”SD”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x360-958k”,”type”:”video/mp4″,”quality”:”LO”}],”ccFiles”:[{“url”:”https://azure.microsoft.com/en-us/blog/wp-json/bloginabox/v1/get-captions?url=https%3A%2F%2Fwww.microsoft.com%2Fcontent%2Fdam%2Fmicrosoft%2Fbade%2Fvideos%2Fproducts-and-services%2Fen-us%2Fazure%2F1117654-hostedagent%2F1117654-HostedAgent_cc_en-us.ttml”,”locale”:”en-us”,”ccType”:”TTML”}],”downloadableFiles”:[{“url”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent_transcript_en-us”,”locale”:”en-us”,”mediaType”:”transcript”}]};

if (currentTheme) {
options.playButtonTheme = currentTheme;
}

document.addEventListener(‘DOMContentLoaded’, () => {
ump(“ump-6a66f875d3428″, options);
});

Build with any framework and model on the industry’s end-to-end AI platform

Agent development starts where developers already work—in GitHub Copilot and Microsoft Visual Studio (VS) Code—with the Foundry Toolkit for VS Code and the Foundry skill handling deployment to Foundry. Whether teams build with Microsoft Agent Framework, GitHub Copilot SDK (generally available), or Claude Agent SDK, Foundry is the production destination—and it all starts with the right model.

Start with the right model for the right job

An agent is only as capable as the model reasoning behind it. Microsoft Foundry gives organizations access to industry-leading frontier, open-source, and task-specific models through a single platform, allowing teams to choose the right model for every workload.

Today, we’re making OpenAI’s GPT-5.6 series generally available in Microsoft Foundry Models and Microsoft Foundry Agent Service:

GPT-5.6 Sol delivers the most advanced reasoning capabilities yet, supporting extended reasoning, agentic workflows, and code-focused scenarios, for the most demanding enterprise workloads.

GPT-5.6 Terra is a balanced model for everyday work, delivering performance competitive with GPT-5.5 at a lower cost, making it ideal for scaling intelligent applications across the enterprise.

GPT-5.6 Luna is the fastest and most affordable model in the family, making it well suited to high-volume, latency-sensitive workloads.

Together, the GPT-5.6 series gives organizations the flexibility to match model capability, cost, and performance requirements to specific business scenarios, rather than forcing every workload onto a single model.

Customers consistently tell us that access to new models matters as much as model quality. That’s why we are making GPT-5.6—the latest model—available through Global Standard and Global Priority Processing for all the existing 28 global regions, Data Zones Standard, and Global Provisioned from day one. This enables customers to adopt the latest frontier AI innovations where they have already built, deployed, and scaled their applications.

GPT-5.6 pricing for Sol, Terra, and Luna

The following table outlines GPT-5.6 pricing for Sol, Terra, and Luna in Microsoft Foundry. Use this pricing information to compare model options and plan deployment costs:

Model Deployment Pricing (USD $/million tokens) Input Output GPT-5.6 Sol Standard Global 5.00 30.00 GPT-5.6 Terra Standard Global 2.50 15.00 GPT-5.6 Luna Standard Global 1.00 6.00

Run frontier AI where your business operates

More models, in more regions, are only half of what platform expansion means. The other half is more places to run them compliantly. This is exactly what the Asia-Pacific Data Zone delivers. Today we’re also announcing the general availability of the Asia-Pacific (APAC) Data Zone for Microsoft Foundry, enabling APAC customers to run frontier OpenAI models while keeping data processing within the Asia-Pacific regions, with no separate environment to stitch together and no waiting for capability to catch up.

With Global, Data Zone, and Regional deployment options available in Foundry, organizations can align AI adoption with their sovereignty, compliance, performance, and scale requirements while maintaining a consistent development and operations experience across environments.

As financial institutions adopt AI, responsible data handling becomes foundational to trust. Microsoft Foundry’s APAC Data Zone allows us to keep data processing regionally anchored while accessing advanced AI models at scale. This gives us the confidence to accelerate AI innovation responsibly and reinforces our ambition to be a leading AI-powered financial platform in Asia.
—Hongsoo Kim, Chief Data and AI Officer (CDAO), Viva Republica (Toss)

Generate impact with action-oriented, context aware agents

A capable model is only the starting point. To put one to work in production, an agent also needs somewhere to run, knowledge of your business, governed access to its tools, memory that carries across interactions and acts on real-world events, and a path to the people who use it. Foundry provides each of these as a built-in capability, designed to work together.

Where it lives: Hosted agents in Foundry Agent Service is now generally available, giving developers one production runtime for agents built with any framework and harness—Microsoft Agent Framework, GitHub Copilot SDK, LangGraph, OpenClaw, Hermes, and others. It’s enterprise-ready on day one: Network isolation with Microsoft Azure Virtual Network (VNet) integration keeps agent traffic inside your security boundary. For long-running workloads, the new resilient task support in hosted agents (private preview) makes it easier to build agents that survive failures. The platform provides primitives to keep the sandbox running, your harness provides checkpointing, and together they allow an agent to resume when it restarts. The result: multi-turn conversations, reasoning loops, and human-in-the-loop approvals can pick up where they left off, without developers having to build their own recovery, retry, and state-management.

How it talks: Hosted agents with Voice Live is now generally available. Developers can add real-time voice experiences to the agents they built with the frameworks they prefer, using the Azure VoiceLive SDK. 

What it knows: Foundry gives agents access to enterprise knowledge without requiring developers to build a complex retrieval pipeline from scratch. Microsoft IQ brings together Work IQ for real-time awareness of your Microsoft 365 environment, Fabric IQ for your structured data, and Web IQ for low-latency live web grounding—all unified behind Foundry IQ, now generally available as the SLA-backed knowledge layer behind every Foundry agent. 

How it reaches its tools: Toolboxes in Foundry is generally available. Instead of shipping every tool definition on every request, a toolbox dynamically selects the right tool for the job—giving agents governed, curated access while dramatically reducing the token overhead of large tool sets. 

How it remembers and responds to the world: Memory and routines in Foundry Agent Service are in public preview. Memory (procedural, user, and session) lets agents carry context across interactions. Routines run any agent on a recurring schedule or timer so it acts without a user prompt; new event-based triggers, powered by the connector gateway, now let the same agent wake up the moment an upstream system signals a change—a ticket filed, a file landing in storage, a workflow completing. 

How it reaches users: Publishing to Microsoft Teams and Microsoft 365 Copilot is generally available next week. The agents your developers build land in the applications where hundreds of millions of people already do their work with identity, permissions, and policy flowing through automatically. And it works even for network-isolated agents: when a project runs behind a private endpoint, you publish through a documented flow rather than the one-click button. The agent stays on your private network while Microsoft’s channel adapters reach it through your own firewall and reverse proxy.

Govern and optimize the full AI lifecycle with observability and controls

An agent you can’t see, improve, or secure is an agent you can’t put in production—so Foundry treats trust as a platform priority, not a developer responsibility. What’s new in this release closes the loop around everything that happens after you build: seeing what an agent did, making it better, and proving it’s worth running.

How you see what it did—tracing and evaluation for hosted agents, generally available. See exactly what an agent did, why, and where it went wrong, and evaluate behavior systematically before and after you ship.

How it gets better and cheaper—agent optimizer in Foundry Agent Service, in public preview. It tests your prompts, skills, models, and tools together and automatically identifies better configurations—often letting you hold quality while moving to a smaller, cheaper model.

How you prove its value—ROI for agents in Microsoft Foundry, in private preview. It connects an agent’s traces, business-value evaluations, and operating cost into a single view—surfacing KPIs like net value, total cost, and current ROI in the dashboard, so customers can see whether a production agent is creating more value than it costs to run, and drill into traces when it isn’t. 

As agents scale from pilots to thousands of runs a day, Foundry gives teams the levers to keep spend predictable without leaving the platform.

That starts with choice.

Choose how you deploy. Foundry offers Global, Data Zone, and Regional deployments, so you can align AI to your sovereignty, compliance, and performance requirements, running frontier models while keeping data processing in-region.

Choose how you pay for model inference. A full spectrum of offers—Standard, Priority Processing, Provisioned Throughput, and Batch—lets you optimize for agility, latency, throughput, and cost on one platform.

On top of that foundation, model router matches each request to the right model, prompt caching cuts redundant computation, and PTU spillover and quota optimization preserve service continuity through usage spikes. For agents, toolboxes in Foundry send only the tools each request needs, and agent optimizer tunes prompts, skills, tools, and model choice against your own evaluators.

And spend is only half the equation. ROI for agents in Foundry connects business value, usage, and cost in one view—so teams can see whether a production agent is creating more value than it costs to run, and where cost is outpacing value.

For a hands-on walkthrough, watch our new Microsoft Mechanics episode on token economics for agents.

In production: What teams are building on Foundry  

The organizations building on Foundry aren’t experimenting; they’re shipping, from digital natives to the world’s largest enterprises.

Adobe is building with GitHub, Foundry Agent Service, and Azure Functions, deploying agents for their applications and saving time and work getting to production.

Telefónica has adopted Microsoft Foundry as the core of their corporate agentic platform, with the first wave of agents tackling network operations—a telco’s most complex, strategic domain—across Microsoft Agent Framework, hosted agents, AI Gateway, and Azure Logic Apps.

Tata Consultancy Services is using agent optimizer in Foundry Agent Service to improve agent performance with a more structured approach to prompt tuning, helping teams reduce manual effort while measuring gains in task adherence and execution efficiency.

The pattern is consistent: teams that once spent weeks integrating, securing, and deploying agents are now doing it in days, on infrastructure that meets their compliance bar, reaching users through tools they already trust.

Get started

Everything in this post is live in Microsoft Foundry.

Follow the documentation and Microsoft Learn courses. Developers can get started in minutes by following the Quickstart, which walks through setting up, testing, and deploying a production-ready hosted agent end to end.

Check out AI Agents for Beginners for a 12-lesson curriculum, then go deeper with guided labs: Develop AI Agents in Azure, Hosted Agents Workshop (.NET), the Foundry Toolkit for VS Code and hosted agents workshop, and the ZavaShop Supply Chain Workshop. To put your agents on a solid quality footing, read Evaluating AI Agents: A Practical Guide with Microsoft Foundry. 

Watch: Foundry Agent Service + Microsoft Agent Framework Explained—Jeff Hollan walks through how to operationalize AI agents from deployment to real-world impact.

Start building on Foundry

The end-to-end platform for building, running, governing, and distributing AI agents.

Visit Foundry

The post GPT-5.6 now available in Microsoft Foundry  appeared first on Microsoft Azure Blog.
Quelle: Azure

AT&T and Microsoft scale trillion-token workloads with Microsoft Foundry and AMD

First-of-its-kind telecom AI deployment

Telecommunications organizations are increasingly looking to AI to help teams navigate highly specialized domains, but generic models often lack the industry-specific knowledge needed to understand telecom networks, standards, and operations. To address that gap, AT&T created their Open Telco (OTel) models, the next generation of telecom-focused AI designed to bring deeper telecommunications expertise into AI systems. Building OTel2.0 required more than training a large language model, it reflected a broader issue many organizations face: how to build domain-specific AI systems at scale while balancing cost, performance, and operational complexity. Cost management quickly became a key consideration. To continue advancing telecom-focused AI, AT&T needed a platform capable of supporting OTel2.0 development at an entirely new scale.

Where teams previously had to own and manage deployments, infrastructure, and the associated operational overhead, Foundry Managed Compute provided a more streamlined way to access dedicated graphics processing unit (GPU) capacity. This transformation requires more than powerful models; it requires the ability to scale without compromising cost, flexibility, or performance.

Learn how OTel2.0 scales telecom AI

Using Microsoft Foundry Managed Compute, AT&T was able to experiment across multiple open models, optimize workloads across different GPU architectures, and process massive volumes of telecom data all within a unified platform. The result was an AI development environment capable of supporting trillions of tokens while giving teams the flexibility to iterate, optimize, and innovate faster.

Model choice meets infrastructure flexibility

Building OTel2.0 required flexibility across both models and infrastructure. Rather than standardizing on a single model, AT&T adopted a multi open-model strategy. Open models were central to AT&T’s approach because they provided the flexibility to work with approved telecom data, tailor the workflow for domain-specific model development, and support large-scale experimentation with greater control over cost and deployment strategy. Through Microsoft Foundry, the team deployed several models from the Hugging Face collection, including Phi-4, OSS-120B, and Gemma-4, to support different stages of development, from synthetic data generation and data preparation to reasoning-intensive workloads and broader model development efforts. Phi-4 played a significant role in this process, processing more than 700 billion tokens a month as part of the broader data preparation and training workflow for OTel2.0.

Every company in the world needs to build its own AI, and that is only possible with open models and open source. AT&T is championing this vision, building on open models like Phi-4 and Gemma, and giving OTel back to the community as a telecom AI foundation others can build upon. Microsoft Foundry makes this practical at scale, bringing the latest open models from the Hugging Face collection together with AMD and NVIDIA GPUs in one place, so teams can pick the right model and the right hardware, then deploy in hours instead of weeks.
—Jeff Boudier, Vice President of Product, Hugging Face

Developing OTel2.0 also required infrastructure capable of operating at telecom scale. AT&T used approximately 530 GPUs through Microsoft Foundry Managed Compute spanning multiple GPU architectures including 430 AMD Instinct™ MI300X GPUs. This heterogenous approach gave AT&T more flexibility in how models were deployed and optimized as requirements evolved.

ModelExample workloadPhi-4Around 700B tokens a month for data preparation and synthetic data generationOSS 120BHigher-reasoning workloads Gemma 4OTel2.0 development workflowsTable 1: Explains what open source models were used and how

This flexibility illustrates a broader trend across AI development. Organizations increasingly need platforms that allow them to choose the right model for the job, optimize for cost and performance, and scale workloads without rebuilding operational environments. Microsoft Foundry brings model choice, infrastructure flexibility, governance, and operational scale together in a unified platform that supports those requirements.

Start building with Microsoft Foundry

Beyond flexibility and cost, deployment speed is a critical factor for many AI initiatives. As workloads expand and new models are evaluated, the ability to access GPU capacity quickly enables teams to move from experimentation to execution faster without lengthy provisioning cycles. With Foundry Managed Compute, AT&T could deploy and scale models in days rather than waiting weeks for infrastructure to become available, helping accelerate development timelines and maintain momentum across OTel2.0 development.

Optimizing cost without limiting innovation

As AI workloads grow, economics become as important as model performance. For AT&T, one of the primary objectives was to lower AI model consumption costs while continuing to drive meaningful business value through AI-powered innovation. By using open models on Microsoft Foundry Managed Compute, AT&T was able to support large-scale data preparation and model development using a different economic model built around dedicated GPU infrastructure and open-model flexibility.

The impact became clear at scale. In support of OTel2.0, AT&T processed approximately 1T tokens, consisting of raw documents from GSMA supplemented by synthetic data generated. Generating the data using open-source models like Phi-4, served by Microsoft’s Foundry Managed Compute, saved tens of millions of dollars versus using frontier models. This allowed teams to invest in larger-scale experimentation and development while maintaining a focus on business value and operational efficiency.

MetricValueOTel 1.0 DownloadsOver 25MGPUs Used Through Foundry Managed ComputeAbout 530Tokens Processed for OTel2.0About 1TTokens Trained for OTel2.0About 400 BModels used to train OTelPhi-4, OSS 120B, Gemma 4Table 2: Quick facts about the OTel model family and metrics around what was used to build OTel2.0 

When you are processing hundreds of billions of tokens, infrastructure becomes part of the problem you solve. Foundry Managed Compute gave us access to GPU capacity at scale so our teams could focus on advancing OTel2.0 instead of managing infrastructure.
—Mark Austin, Vice President, Data Science and AI at AT&T

At this scale, infrastructure is no longer simply a deployment consideration. It becomes a strategic component of AI development.

Accelerating the next wave of production-scale AI

OTel 2.0 demonstrates how organizations can combine open models, scalable infrastructure, and domain expertise to build production-ready AI systems. By matching different models to different workloads and optimizing infrastructure for cost and performance, AT&T was able to process trillions of tokens while maintaining operational efficiency. 

As organizations move from AI experimentation to production deployment, they increasingly need the flexibility to choose the right models, optimize infrastructure, and scale efficiently. Microsoft Foundry and Foundry Managed Compute help support that transition by bringing those capabilities together in a unified platform.

Learn more

Read Scott Guthrie’s blog about Azure AI and HPC infrastructure.

Learn more about OTel2.0.

Explore session topics from AMD’s Advancing AI:

From GPUs to CPUs: Optimizing Every AI Workload with Azure and AMD

What’s Next for AI Infrastructure in the Cloud?

Powering the Future of AI on Azure

Discover how Microsoft and AMD are expanding Azure AI and HPC infrastructure.

Read more

The post AT&T and Microsoft scale trillion-token workloads with Microsoft Foundry and AMD appeared first on Microsoft Azure Blog.
Quelle: Azure

Azure Databricks delivers proven business value

Microsoft Azure Databricks delivers the first-party advantage of Databricks on Microsoft—and for customers, that advantage shows up as real, measurable value. It is the same Databricks platform your teams already know, co-engineered with Microsoft and delivered as a native Azure service, so it fits naturally into the Microsoft tools, identity, and governance your organization already runs.

Discover Azure Databricks

The advantage is built-in, not bolted on. Microsoft and Databricks co-engineer the service, share one integration roadmap across the Microsoft data and AI stack, and align go-to-market so you get one motion, one bill, and one support path. For technical teams, that means deeper native integration and stronger performance. For the business, it means lower cost, less risk, and faster time to value.

The strategic partnership drives an accelerated integration roadmap and continuous optimization for improved performance; however, decision-makers constantly ask about what business value all of this translates to. To address this key question, Microsoft commissioned a Forrester Total Economic Impact™ study of Azure Databricks. It found that a composite organization based on interviewed customers realized a three-year 331% return on investment, $58.1 million in net present value, and recovered its investment in less than six months.

331%Return on investment $58.1MNet present value< 6 monthsPayback period

Commissioned study conducted by Forrester Consulting on behalf of Microsoft, June 2026. Results are over three years and represent a composite organization based on interviewed customers and may not be typical; actual results will vary.

What the study found

Forrester interviewed Azure Databricks customers and built a composite organization to model the impact: a $6 billion company in a regulated industry, running about 10 petabytes of data.

Before Azure Databricks, its data estate was fragmented and expensive. It was unreliable at scale and hard to govern. Afterward, the results were clear: $75.6 million in benefits against $17.5 million in cost over three years translating to $58.1 million in net present value.

The value came from four places:

$39.0 million—data and analytics teams’ productivity. Teams handled more work without adding people, with measured gains of 15% to 25%. As a Vice President of data services at a healthcare organization put it: “…we’re doing more work with the same size of the team.”

$19.9 million—lower infrastructure costs. Elastic, pay-as-you-go compute replaced overprovisioned hardware.

$11.4 million—better data platform resiliency. Managed operations meant fewer outages and no custom disaster recovery to build.

$5.4 million—retired legacy software and redeployed DBAs. Consolidating databases and Extract, Load, Transform (ETL) tools eliminated third-party licenses, and managed operations freed database administrators for higher-value work.

Forrester listed more benefits it didn’t put a price on: native Azure services integration, faster insights, wider access to data, and governance through Unity Catalog. That’s where the return starts.

Model your own numbers with the Azure Databricks ROI estimator

Where the value comes from

Those returns come down to one thing. Azure Databricks is a true first-party Azure service, co-engineered by Microsoft and Databricks, it plugs into the tools your teams already use. That removes the extra data copies, tooling, and integration work that raise costs elsewhere.

A great example is the Azure Databricks Genie integration with Microsoft Copilot Cowork. You can add context of your business and build on that intelligence into the tools your teams already use with this integration. Genie lets anyone question the lakehouse in plain language—now inside Microsoft Teams, Microsoft 365 Copilot, and more recently in Copilot Cowork, where it grounds tasks in trusted data through Genie Ontology. Every answer is scoped by Unity Catalog to exactly what each user is permitted to see, so intelligence reaches the flow of work without loosening governance.

The same depth runs across the rest of the platform:

Identity and governance: Automatic Identity Management for Entra ID syncs users into Azure Databricks. Unity Catalog and Microsoft Purview govern the rest. 

Microsoft Power BI and Microsoft 365: Power BI reads your data directly and now writes back to it. A new Excel add-in brings governed data into spreadsheets; a SharePoint connector streams files into Delta tables, and Teams notifications deliver alerts where teams work. Metric views keep business logic consistent across all of them. 

AI and agents: Beyond chatting with your data, Genie connects to Copilot Studio and Microsoft Foundry, and a single Model Context Protocol (MCP) connection lets Copilot Studio and GitHub Copilot agents reason over an entire Azure Databricks workspace. Azure Database Lakebase gives agents a serverless Postgres engine, and serverless workspaces get them started fast. 

Microsoft OneLake: OneLake catalog federation lets Azure Databricks query OneLake data directly, with no pipelines or copies. You can also store Unity Catalog tables in OneLake, alongside Azure Data Lake Storage.

Customer data: CustomerLake, a new Agentic Customer Data platform, builds Customer 360 profiles and runs campaigns inside the lakehouse where the data and governance already live. 

Enterprise systems: SAP Business Data Cloud Connect brings SAP data into the lakehouse. It’s the same model helping industries like industries like telecom turn AI into returns. 

These are the integrations that Forrester valued but didn’t price separately however, they are critical factors driving productivity and cost benefits that were quantified.

Backed by independent benchmarks

Value also depends on speed, and that’s been tested. Principled Technologies, an independent firm, ran an industry-standard, TPC-DS-like decision-support benchmark on a 10-terabyte dataset. Azure Databricks completed a single query stream in up to 21.1% less time than Databricks on AWS (with autoscale disabled) and ran four concurrent query streams more than nine minutes faster.

What it means for you

Choosing a data and AI platform is a long-term decision, and with Azure Databricks the pieces reinforce each other. The integration drives the savings Forrester measured. The performance keeps those gains steady as usage grows. And it all rests on one foundation: a first-party partnership that puts Microsoft and Databricks engineering, roadmap, and support behind your data estate. The value isn’t a claim, it’s been measured: a three-year 331% return, with payback in under six months. It’s why so many teams choose to run their lakehouse on Azure Databricks.

Get started with Azure Databricks

Explore further

The full Forrester TEI study, plus the ROI calculator to model your own numbers.

The Principled Technologies benchmark.

Azure Databricks at Data + AI Summit 2026, and how it uses OneLake as a shared data foundation.

Build AI apps and agents with Azure Databricks, Copilot Studio, and GitHub Copilot.

Stay current on the Azure Databricks Tech Community blog and the official release notes.

Related blog posts: Differentiated synergy and Databricks runs best on Azure.

For the full set of Databricks Data + AI Summit 2026 announcements, see Azure Databricks at Data + AI Summit 2026.

Learn more about Azure Databricks

Build Intelligent Solutions with Azure Databricks

Empower teams to develop AI-powered applications and gain deeper insights with a unified data and AI platform.

Learn More

The post Azure Databricks delivers proven business value appeared first on Microsoft Azure Blog.
Quelle: Azure

Frontier models and production agents: Advancing Microsoft Foundry for the agentic era

What’s new todayGPT‑5.6 is generally available in Microsoft Foundry, alongside the Asia-Pacific Data Zone, and hosted agents in Foundry Agent Service.

AI only creates value when it shows up in real systems—systems that are reliable, observable, and aligned to business outcomes. More than 100,000 organizations are already building on Microsoft Foundry, and companies like Adobe, Telefónica, and Tata Consultancy Services are running agents in production today.

At Microsoft Build, we laid out a simple promise for the agentic era: developers should be able to build an agent where they already work, run it on infrastructure they can trust, and put it in front of the people who need it— without stitching together disconnected platforms. Today, that vision moves from roadmap to reality with three sets of updates now generally available in Microsoft Foundry:

OpenAI’s latest frontier model series: GPT-5.6 Sol, GPT-5.6 Terra, and GPT-5.6—each tuned to a different workload, available in Standard Global and Standard Data Zones.

Asia-Pacific Data Zone, giving APAC customers a regional option to run frontier OpenAI models while keeping data processing within the region.

Production agents in Foundry Agent Service, with hosted agents, toolboxes, and publishing to Microsoft 365 Copilot and Microsoft Teams.

Together, these capabilities bring frontier models, production agent runtime, enterprise-grade identity, security, and compliance controls, and distribution across Microsoft 365 into a single platform—helping organizations move from experimentation to production without assembling disconnected tools and services.

Why Foundry is the best agent platform

Microsoft Foundry is Microsoft’s end-to-end platform for building, running, governing, and distributing AI agents. Foundry brings together the capabilities organizations need to move agents into production across three pillars:

Build: Open and flexible across models and frameworks.

Generate: Connected to enterprise data, tools, and users.

Govern: Secured, managed, and optimized for long-term value.

These pillars come together in the latest Foundry updates, helping organizations build, run, and scale production agents on a single platform.

const currentTheme =
localStorage.getItem(‘blogInABoxCurrentTheme’) ||
(window.matchMedia(‘(prefers-color-scheme: dark)’).matches ? ‘dark’ : ‘light’);

// Modify player theme based on localStorage value.
let options = {“autoplay”:false,”hideControls”:null,”language”:”en-us”,”loop”:false,”partnerName”:”cloud-blogs”,”poster”:”https://cdn-dynmedia-1.microsoft.com/is/image/microsoftcorp/1117654-HostedAgent_tbmnl_en-us?wid=1280″,”title”:””,”sources”:[{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x1080-6439k”,”type”:”video/mp4″,”quality”:”HQ”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x720-3266k”,”type”:”video/mp4″,”quality”:”HD”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x540-2160k”,”type”:”video/mp4″,”quality”:”SD”},{“src”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent-0x360-958k”,”type”:”video/mp4″,”quality”:”LO”}],”ccFiles”:[{“url”:”https://azure.microsoft.com/en-us/blog/wp-json/bloginabox/v1/get-captions?url=https%3A%2F%2Fwww.microsoft.com%2Fcontent%2Fdam%2Fmicrosoft%2Fbade%2Fvideos%2Fproducts-and-services%2Fen-us%2Fazure%2F1117654-hostedagent%2F1117654-HostedAgent_cc_en-us.ttml”,”locale”:”en-us”,”ccType”:”TTML”}],”downloadableFiles”:[{“url”:”https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/1117654-HostedAgent_transcript_en-us”,”locale”:”en-us”,”mediaType”:”transcript”}]};

if (currentTheme) {
options.playButtonTheme = currentTheme;
}

document.addEventListener(‘DOMContentLoaded’, () => {
ump(“ump-6a554d882f554″, options);
});

Build with any framework and model on the industry’s end-to-end AI platform

Agent development starts where developers already work—in GitHub Copilot and Microsoft Visual Studio (VS) Code—with the Foundry Toolkit for VS Code and the Foundry skill handling deployment to Foundry. Whether teams build with Microsoft Agent Framework, GitHub Copilot SDK (generally available), or Claude Agent SDK, Foundry is the production destination—and it all starts with the right model.

Start with the right model for the right job

An agent is only as capable as the model reasoning behind it. Microsoft Foundry gives organizations access to industry-leading frontier, open-source, and task-specific models through a single platform, allowing teams to choose the right model for every workload.

Today, we’re making OpenAI’s GPT-5.6 series generally available in Microsoft Foundry Models and Microsoft Foundry Agent Service:

GPT-5.6 Sol delivers the most advanced reasoning capabilities yet, supporting extended reasoning, agentic workflows, and code-focused scenarios, for the most demanding enterprise workloads.

GPT-5.6 Terra is a balanced model for everyday work, delivering performance competitive with GPT-5.5 at a lower cost, making it ideal for scaling intelligent applications across the enterprise.

GPT-5.6 Luna is the fastest and most affordable model in the family, making it well suited to high-volume, latency-sensitive workloads.

Together, the GPT-5.6 series gives organizations the flexibility to match model capability, cost, and performance requirements to specific business scenarios, rather than forcing every workload onto a single model.

Customers consistently tell us that access to new models matters as much as model quality. That’s why we are making GPT-5.6 available through Global Standard and Global Priority Processing for all the existing 28 global regions, Data Zones Standard, and Global Provisioned from day one. This enables customers to adopt the latest frontier AI innovations where they have already built, deployed, and scaled their applications.

GPT 5.6 pricing

Model Deployment Pricing (USD $/million tokens) Input Output GPT-5.6 Sol Standard Global 5.00 30.00 GPT-5.6 Terra Standard Global 2.50 15.00 GPT-5.6 Luna Standard Global 1.00 6.00

Run frontier AI where your business operates

More models, in more regions, are only half of what platform expansion means. The other half is more places to run them compliantly. This is exactly what the Asia-Pacific Data Zone delivers. Today we’re also announcing the general availability of the Asia-Pacific (APAC) Data Zone for Microsoft Foundry, enabling APAC customers to run frontier OpenAI models while keeping data processing within the Asia-Pacific regions, with no separate environment to stitch together and no waiting for capability to catch up.

With Global, Data Zone, and Regional deployment options available in Foundry, organizations can align AI adoption with their sovereignty, compliance, performance, and scale requirements while maintaining a consistent development and operations experience across environments.

As financial institutions adopt AI, responsible data handling becomes foundational to trust. Microsoft Foundry’s APAC Data Zone allows us to keep data processing regionally anchored while accessing advanced AI models at scale. This gives us the confidence to accelerate AI innovation responsibly and reinforces our ambition to be a leading AI-powered financial platform in Asia.
—Hongsoo Kim, Chief Data and AI Officer (CDAO), Viva Republica (Toss)

Generate impact with action-oriented, context aware agents

A capable model is only the starting point. To put one to work in production, an agent also needs somewhere to run, knowledge of your business, governed access to its tools, memory that carries across interactions and acts on real-world events, and a path to the people who use it. Foundry provides each of these as a built-in capability, designed to work together.

Where it lives: Hosted agents in Foundry Agent Service is now generally available, giving developers one production runtime for agents built with any framework and harness—Microsoft Agent Framework, GitHub Copilot SDK, LangGraph, OpenClaw, Hermes, and others. It’s enterprise-ready on day one: Network isolation with Microsoft Azure Virtual Network (VNet) integration keeps agent traffic inside your security boundary. For long-running workloads, the new resilient task support in hosted agents (private preview) makes it easier to build agents that survive failures. The platform provides primitives to keep the sandbox running, your harness provides checkpointing, and together they allow an agent to resume when it restarts. The result: multi-turn conversations, reasoning loops, and human-in-the-loop approvals can pick up where they left off, without developers having to build their own recovery, retry, and state-management.

How it talks: Hosted agents with Voice Live is now generally available. Developers can add real-time voice experiences to the agents they built with the frameworks they prefer, using the Azure VoiceLive SDK. 

What it knows: Foundry gives agents access to enterprise knowledge without requiring developers to build a complex retrieval pipeline from scratch. Microsoft IQ brings together Work IQ for real-time awareness of your Microsoft 365 environment, Fabric IQ for your structured data, and Web IQ for low-latency live web grounding—all unified behind Foundry IQ, now generally available as the SLA-backed knowledge layer behind every Foundry agent. 

How it reaches its tools: Toolboxes in Foundry is generally available. Instead of shipping every tool definition on every request, a toolbox dynamically selects the right tool for the job—giving agents governed, curated access while dramatically reducing the token overhead of large tool sets. 

How it remembers and responds to the world: Memory and routines in Foundry Agent Service are in public preview. Memory (procedural, user, and session) lets agents carry context across interactions. Routines run any agent on a recurring schedule or timer so it acts without a user prompt; new event-based triggers, powered by the connector gateway, now let the same agent wake up the moment an upstream system signals a change—a ticket filed, a file landing in storage, a workflow completing. 

How it reaches users: Publishing to Microsoft Teams and Microsoft 365 Copilot is generally available next week. The agents your developers build land in the applications where hundreds of millions of people already do their work with identity, permissions, and policy flowing through automatically. And it works even for network-isolated agents: when a project runs behind a private endpoint, you publish through a documented flow rather than the one-click button. The agent stays on your private network while Microsoft’s channel adapters reach it through your own firewall and reverse proxy.

Govern and optimize the full AI lifecycle with observability and controls

An agent you can’t see, improve, or secure is an agent you can’t put in production—so Foundry treats trust as a platform priority, not a developer responsibility. What’s new in this release closes the loop around everything that happens after you build: seeing what an agent did, making it better, and proving it’s worth running.

How you see what it did—tracing and evaluation for hosted agents, generally available. See exactly what an agent did, why, and where it went wrong, and evaluate behavior systematically before and after you ship.

How it gets better and cheaper—agent optimizer in Foundry Agent Service, in public preview. It tests your prompts, skills, models, and tools together and automatically identifies better configurations—often letting you hold quality while moving to a smaller, cheaper model.

How you prove its value—ROI for agents in Microsoft Foundry, in private preview. It connects an agent’s traces, business-value evaluations, and operating cost into a single view—surfacing KPIs like net value, total cost, and current ROI in the dashboard, so customers can see whether a production agent is creating more value than it costs to run, and drill into traces when it isn’t. 

As agents scale from pilots to thousands of runs a day, Foundry gives teams the levers to keep spend predictable without leaving the platform.

That starts with choice.

Choose how you deploy. Foundry offers Global, Data Zone, and Regional deployments, so you can align AI to your sovereignty, compliance, and performance requirements, running frontier models while keeping data processing in-region.

Choose how you pay for model inference. A full spectrum of offers—Standard, Priority Processing, Provisioned Throughput, and Batch—lets you optimize for agility, latency, throughput, and cost on one platform.

On top of that foundation, model router matches each request to the right model, prompt caching cuts redundant computation, and PTU spillover and quota optimization preserve service continuity through usage spikes. For agents, toolboxes in Foundry send only the tools each request needs, and agent optimizer tunes prompts, skills, tools, and model choice against your own evaluators.

And spend is only half the equation. ROI for agents in Foundry connects business value, usage, and cost in one view—so teams can see whether a production agent is creating more value than it costs to run, and where cost is outpacing value.

For a hands-on walkthrough, watch our new Microsoft Mechanics episode on token economics for agents.

In production: What teams are building on Foundry  

The organizations building on Foundry aren’t experimenting; they’re shipping, from digital natives to the world’s largest enterprises.

Adobe is building with GitHub, Foundry Agent Service, and Azure Functions, deploying agents for their applications and saving time and work getting to production.

Telefónica has adopted Microsoft Foundry as the core of their corporate agentic platform, with the first wave of agents tackling network operations—a telco’s most complex, strategic domain—across Microsoft Agent Framework, hosted agents, AI Gateway, and Azure Logic Apps.

Tata Consultancy Services is using agent optimizer in Foundry Agent Service to improve agent performance with a more structured approach to prompt tuning, helping teams reduce manual effort while measuring gains in task adherence and execution efficiency.

The pattern is consistent: teams that once spent weeks integrating, securing, and deploying agents are now doing it in days, on infrastructure that meets their compliance bar, reaching users through tools they already trust.

Get started

Everything in this post is live in Microsoft Foundry.

Follow the documentation and Microsoft Learn courses. Developers can get started in minutes by following the Quickstart, which walks through setting up, testing, and deploying a production-ready hosted agent end to end.

Check out AI Agents for Beginners for a 12-lesson curriculum, then go deeper with guided labs: Develop AI Agents in Azure, Hosted Agents Workshop (.NET), the Foundry Toolkit for VS Code and hosted agents workshop, and the ZavaShop Supply Chain Workshop. To put your agents on a solid quality footing, read Evaluating AI Agents: A Practical Guide with Microsoft Foundry. 

Watch: Foundry Agent Service + Microsoft Agent Framework Explained—Jeff Hollan walks through how to operationalize AI agents from deployment to real-world impact.

Start building on Foundry

The end-to-end platform for building, running, governing, and distributing AI agents.

Visit Foundry

The post Frontier models and production agents: Advancing Microsoft Foundry for the agentic era appeared first on Microsoft Azure Blog.
Quelle: Azure

External key management for Azure Managed HSM is now in public preview

Azure Key Vault Managed Hardware Security Module (HSM) provides strong sovereignty over your encryption keys. Keys are generated and stored in a single-tenant, FIPS 140-3 Level 3 HSM that only you control: Microsoft has no access to your key material, and you govern who can use each key. For most organizations, including those with stringent regulatory requirements, this level of control is sufficient.

Some organizations have a further requirement: the hardware that holds their key must reside physically outside Azure datacenters. External key management for Azure Key Vault Managed HSM is now in public preview to address that requirement, delivering on a commitment made a year ago.

Try External key management for Azure Key Vault Managed HSM

How Managed HSM delivers sovereignty today

Before looking at external key management, it’s worth being precise about the sovereignty Managed HSM already provides. Managed HSM is a single-tenant service: each instance is a dedicated cluster of FIPS 140-3 Level 3 validated HSM partitions for each customer—built on Marvell LiquidSecurity adapters. Keys are generated inside that hardware and never leave it in plaintext, making the keys inaccessible to Microsoft operators.

Control rests with you, not Microsoft:

Customer-specific security domain. Each HSM cluster is cryptographically isolated by a security domain that you generate and own. Microsoft can’t decrypt your key material or recover your HSM cluster without it. You are in full control of the security domain as it’s protection and safeguarding is outside of Microsoft.

Multiperson control. The security domain is protected by a quorum of RSA key pairs that you hold offline. Recovery requires your quorum, so no single person—and no Microsoft operator—can act alone.

Local role-based access control (RBAC). A data-plane authorization model, independent of Azure RBAC, governs who can perform each cryptographic operation.

Key attestation. You can obtain cryptographic proof that a key was generated and is used within the FIPS 140-3 Level 3 hardware boundary.

Managed HSM is built on FIPS 140-3 Level 3 HSMs and confidential computing technology based on Intel SGX, so request handling, access control, and key material are isolated in hardware enclaves and HSMs that no Microsoft operator—even one with administrative or physical access to the host—can read. Managed HSM provides redundancy, isolation, and protection—giving organizations the sovereignty assurances they need without compromising on key security, operational overhead or availability.

What external key management adds

Managed HSM already provides full customer control over your keys, with enterprise-grade availability, security, and operational simplicity. External key management adds one capability: the option to keep your key material on an HSM that you own and operate, either on-premises or with a trusted third party, completely outside Microsoft infrastructure.

External key management is designed for scenarios where regulation or contractual obligations mandate the cryptographic keys must reside outside the cloud provider’s environment. These requirements are sometimes found in highly regulated sectors such as government, financial services, and critical infrastructure, and in jurisdictions with strict data-sovereignty rules. External key management ensures the root of trust and key material remain on hardware you own and operate, outside Microsoft infrastructure, and under your direct physical control.

However, this model should only be adopted deliberately and only when required. For most workloads, Managed HSM keys remain the recommended approach, delivering higher native availability, reduced operational complexity, and a security posture that meets or exceeds sovereignty requirements without introducing additional risk or overhead. External key management is about meeting specific regulatory constraints, not increasing baseline security. When those constraints do not apply, Managed HSM provides a stronger, more reliable, and more operationally efficient solution.

How it works

External key management extends Managed HSM through a dedicated API endpoint that connects directly to the HSM you control. It allows cryptographic operations in Azure to invoke external key material without changing how applications interact with the service. The external key never resides in or passes through Microsoft infrastructure; only your hardware uses it. Because you control that hardware, you can disconnect it at any time to halt all cryptographic operations.

Integration is transparent to applications. Applications continue to use Managed HSM and the Azure Key Vault API with the customer-managed key envelope encryption pattern unchanged. When an data access requires your external key to decrypt local data encryption keys, Managed HSM forwards it to your hardware and returns the result.

You choose the hardware and partner. Because the external key management API is an open specification, you decide how to implement it. Your hardware, your partner, or your implementation.

All connections are mutually authenticated and encrypted. Traffic between Azure and your hardware is secured with mutual TLS, ensuring a secure and trusted connection between Azure and your HSM.

HSM ecosystem

A growing ecosystem of HSM vendors support integration with the Managed HSM external key management API, as many providers are actively enabling compatibility for their platforms.

Microsoft doesn’t build or operate the connecting integration proxy itself. Instead, you benefit from an open model: you can use a vendor provided implementation, reply on a partner to operate it, or build your own.

Responsibilities and tradeoffs

External key management deliberately shifts a portion of operational responsibility to you. This is the direct consequence of extending the trust boundary beyond Azure: you gain control over the root of trust, and with it, ownership of the systems that enforce it.

Availability of your hardware. The Managed HSM SLA applies up to the point Managed HSM calls your external HSM proxy. Availability of your proxy and HSM is your responsibility. Any disruption on your side directly impacts cryptographic operations and Azure service data accessibility.

Scope of operations. External key management focuses on the operations used to protect data at rest. It does not expose the full set of key operations available with Managed HSM keys, reflecting a deliberate trade-off between control and functionality.

Hardware operations. Provisioning, securing, scaling, monitoring, and recovery of your proxy and HSM become your responsibility, whether operated directly or through a partner.

Error transparency. Failures originating on your side of the connection are surfaced in Managed HSM logs, but remain your responsibility to diagnose and resolve.

This is the core trade-off: more control means more responsibility.

Public preview scope

Availability: all Azure public regions at preview launch.

Access: gated. Your Microsoft account team enables external key management on your Managed HSM—contact them to request it.

Use case: protecting data at rest for Azure services that support customer-managed keys with Managed HSM.

Pricing: standard Managed HSM pricing, with no additional Microsoft surcharge. You cover the cost of your own hardware and any partner licensing.

Get started

Start with: What is Managed HSM external key management?

Review the SLA and shared-responsibility model

Try the Azure CLI quickstart

External key management is the latest step in giving customers granular control over how and where their keys are protected. During public preview, your feedback will directly shape the feature on its path to general availability — including the operational guidance, vendor integrations, and scenarios we prioritize next.

Take control of your encryption keys

Explore external key management for Managed HSM and keep your key material outside Azure while maintaining secure, scalable operations.

Get started

The post External key management for Azure Managed HSM is now in public preview appeared first on Microsoft Azure Blog.
Quelle: Azure

Built to bounce back: How Azure resiliency evolved

In this article

Resiliency as a shared responsibility, not a handoffPlatform foundations that reflect reality: zones, regions, and sovereigntyAzure features and capabilities strengthen resiliency outcomesBridging intent to execution through experiences on AzureHow you can build Resilience in AzureAzure Essentials

Resiliency in the cloud is often described in terms of availability, such as how quickly a system fails over, how many replicas exist, or what a service-level agreement guarantees. But for most organizations today, especially those operating in regulated, sovereign, or geopolitically sensitive environments, resiliency is something far more fundamental. It is the ability to continue operating under pressure, protect what matters most, and recover safely when the unexpected happens.

A useful way to think about this is not a system problem, but a city problem. A modern city does not depend on a single power source, a single road, or a single control system. It is designed to withstand disruptions, whether from infrastructure failures, natural events, or security incidents. It has redundancy—but more importantly—it has governance, control, and recovery mechanisms that reflect local realities. Cloud resiliency operates in much the same way. It is not just about avoiding outages; it is about ensuring systems can adapt, recover, and keep functioning within real-world constraints.

Get started with Resiliency in Azure

On Azure, resiliency is not something Microsoft delivers to customers. It is something Microsoft builds with them. The platform provides deeply resilient infrastructure and increasingly intelligent capabilities, but resiliency outcomes only emerge when those are intentionally designed, aligned with sovereignty constraints, and continuously validated against real-world conditions. Last year, we explained how at its core, Azure approaches resiliency across three interconnected pillars: infrastructure resiliency, data resiliency, and cyber recovery.

Infrastructure resiliency: ensuring applications remain available through failure conditions.

Data resiliency: ensuring data remains protected, durable, and recoverable.

Cyber recovery: ensuring organizations can recover safely from compromised states.

Together, they ensure not only that systems remain available, but that they remain recoverable and trustworthy—even when failure modes are unpredictable. These pillars are operationalized through a lifecycle approach that helps organizations design, improve, and continuously validate their resiliency posture.

What differentiates Azure is how these elements come together. Azure provides not just resilient infrastructure, but a unified approach that spans platform capabilities, observability, validation, and intelligent remediation, allowing organizations to move from designing for resiliency to continuously operating and improving it.

Resiliency as a shared responsibility, not a handoff

In any city, infrastructure providers ensure that roads, utilities, and foundational systems are reliable. But how buildings are designed, how emergency plans are executed, and how critical services are protected; those remain the responsibility of the city and its operators.

Azure’s shared responsibility model follows the same principle. Microsoft is responsible for delivering a resilient cloud platform foundation like regions, physical datacenters, networking, isolation boundaries, and engineering systems that reduce blast radius and improve durability at scale. This includes capabilities such as Availability Zones, regional isolation, and services like Azure Backup and Azure Site Recovery. Customers then build on Azure enabled experiences to configure the right capabilities and achieve their desired resiliency outcomes. This includes how applications are architected, how dependencies are managed, how recovery objectives are defined, and how backup and disaster recovery are configured and tested. In sovereign and regulated environments, this responsibility becomes even more critical where customers explicitly define where data resides, how it moves, and how recovery aligns with compliance and jurisdictional requirements.

Platform foundations that reflect reality: zones, regions, and sovereignty

Modern Azure resiliency starts with a zone-first design approach, where applications are built to tolerate the loss of an entire Availability Zone. This significantly reduces the likelihood of localized infrastructure failures impacting application availability.

However, resilience does not stop at zones. Regions themselves are not uniform, and assuming uniformity is one of the most common causes of design fragility.

Some Azure regions are paired, with predefined recovery regions aligned for disaster recovery.

Others are non-paired, often due to sovereignty, regulatory, or geographic constraints.

This distinction fundamentally shapes resiliency architecture.

Paired region scenario (predictable recovery): Azure provides a spectrum of durability options from locally redundant storage (LRS) to zone redundant (ZRS) and geo‑redundant storage (GRS), enabling customers to align data protection strategies with their availability, compliance, and data sovereignty requirements. For example, a financial services application deployed in West Europe can leverage its paired region (North Europe) for disaster recovery. Using Azure Site Recovery (ASR), workloads are continuously replicated and orchestrated to enable application-level continuity during a regional disruption.

The predefined region pairing offers predictable failover behavior, along with well-understood Recovery Point Objective (RPO) and Recovery Time Objective (RTO) trade-offs. However, modern Azure resiliency guidance has evolved beyond strict reliance on region pairs. As outlined in the Modern Azure Resilience with Mark Russinovich blog, customers are increasingly adopting flexible multi-region architectures, including non-paired region strategies based on factors such as service availability, capacity, latency, and data residency requirements. These patterns emphasize that disaster recovery is no longer bound to predefined pairs, but instead is a design choice aligned to workload-specific needs.

In such scenarios, Azure Site Recovery plays a critical role by providing consistent, application-aware replication and failover orchestration across any chosen region, paired or not. This allows customers to standardize their recovery strategy while retaining the flexibility to meet evolving business, regulatory, and scale considerations.

Non-paired region scenario (sovereign constraint): a government workload operates in a sovereign region with no predefined pair. Cross-region recovery is restricted. The architecture prioritizes zonal high availability and restore-based recovery using backup to region of choice, ensuring data remains within jurisdictional boundaries. Recovery is slower but fully compliant.

Asymmetric recovery scenario (regulated enterprise): a multinational enterprise deploys in a constrained geography where only subsets of data can leave the region. For example, Azure Site Recovery enables failover for critical services, while sensitive data relies on Azure Backup for in-boundary recovery. The result is an intentionally asymmetric resiliency model, balancing compliance with business continuity.

The result is a shift from one-size-fits-all architectures to workload-driven resiliency design, where recovery strategies are intentionally aligned to business, regulatory, and operational constraints.

Azure features and capabilities strengthen resiliency outcomes

Resiliency in Azure is not delivered by a single service, but it is achieved through a set of capabilities and services. These capabilities work together to ensure applications remain available, data remains protected, and systems can recover even under infrastructure failures, regional disruptions, or cyber-attacks. It begins with zone-resilient foundations that reduce exposure to localized failures, and extends through autoscaling, load balancing, and health-aware traffic management that keeps applications responsive under stress.

For broader infrastructure or regional disruptions, Azure Site Recovery enables continuity through replication and failover orchestration. Equally important, Azure Backup addresses a different class of risk like corruption, accidental deletion, compliance retention, and cyber compromise by enabling recovery to a trusted point in time when failover is not enough. These capabilities are most effective when paired with strong observability and rehydration-friendly design, where systems can detect issues early, recover automatically, and rebuild quickly. The result is a more complete view of resiliency: not just maintaining uptime but sustaining trust and recoverability under real-world failure conditions.

Bridging intent to execution through experiences on Azure

Customers had tools but lacked a unified way to measure and improve their resiliency posture. Introduced at Microsoft Build 2026 and available in public preview, Azure Infrastructure Resiliency Manager addresses this challenge. It provides an application-centric and resource-centric view of resiliency, bringing together Resiliency in Azure, Azure Advisor, Azure Chaos Studio, and Azure Monitor into a single, cohesive experience.

A key starting point is zonal resiliency posture. It helps customers understand whether their workloads are truly zone-resilient, identify hidden dependencies, and pinpoint gaps between intended architecture and actual deployment.

It introduces a lifecycle approach to resiliency:

Start resilient: design workloads with the right foundational posture.

Get resilient: identify and close gaps in existing systems.

Stay resilient: continuously validate and improve through drills and monitoring.

At the core of Azure Infrastructure Resiliency Manager is the Resiliency Agent, which brings intelligence and automation into the lifecycle. The agent evaluates workloads holistically and identifies risks, surfaces misconfigurations, and explains trade-offs across cost, availability, and compliance. But its role extends beyond analysis. This represents a shift from reactive guidance to proactive and increasingly autonomous resiliency management.

In addition to guiding remediation, the Resiliency Agent can generate Infrastructure-as-Code (IaC) templates, enabling teams to directly implement recommended changes in their deployment pipelines. This is a fundamental shift: resiliency moves from being advisory to executable. It becomes embedded in DevOps workflows; codified, repeatable, and consistently applied.

In addition to this, with the Azure Backup MCP Server, these capabilities become programmable. Organizations can integrate backup posture validation, recovery readiness checks, and policy-driven restore workflows into automated systems while maintaining full control within sovereignty boundaries.

How you can build Resilience in Azure

On Azure, this evolution reflects a shift from predefined constructs to intentional architectures, from fragmented tools to unified experiences, and from guidance to execution. As organizations navigate increasing complexity, regulatory constraints, and unpredictable failure modes, the path forward is clear: build resilience into the foundation, validate it continuously, and automate it wherever possible. With Azure’s platform capabilities, application-centric experiences, and intelligent agents, resiliency is not just achievable but operationalized to deliver with confidence.

Explore Azure Essentials to get started with a unified resiliency experience across your applications and infrastructure. Azure Essentials, Microsoft Unified, and Azure Accelerate help organizations move from resiliency design to operational execution across every stage of the lifecycle.

Azure Essentials

Create secure, resilient, and cost-efficient projects.

Get started

Related resources

Announcing Azure Infrastructure Resiliency Manager Public Preview

Resiliency documentation

Modern Azure Resilience with Mark Russinovich

Reliability guides for Azure services

Cloud Resiliency

Proving application resilience on Azure with Chaos Studio

The post Built to bounce back: How Azure resiliency evolved appeared first on Microsoft Azure Blog.
Quelle: Azure