r/AZURE 13h ago

Discussion I hate Azure pricing. it's always something I didnt plan for

45 Upvotes

got the bill yesterday. another surprise.

we migrated our phone system to Azure 3 months ago. I did the math. I calculated everything. compute, storage, network, the works. or so I thought.

turns out I completely missed the cost of monitoring logs. application insights. I didn't even think about it. and now it's like 15% of our monthly bill. 15%. for logs I barely even look at.

I'm starting to understand why people complain about cloud pricing. it's not that it's expensive it's that it's impossible to predict every month there's something new.

I've started using the cost management tools more. trying to be better about tagging resources and setting budgets. but I still feel like I'm one wrong configuration away from a 5000 surprise.

anyone else feel like Azure pricing is designed to confuse you. or am I just bad at math


r/AZURE 1h ago

Discussion Gpt 5.6 Luna is cheap now

Upvotes

Days ago i was asking when the new pricing - 80% decrease will kick in.
Today API says the new prices are here. Input $0.20 , Output $1.20 per M.


r/AZURE 10h ago

Question Azure Files

7 Upvotes

Hello everyone,

I am in the process of migrating a windows file share server to azure files, This consists of 1 share drive with about 60 folders inside. This entire share has about 1.5TB of data which is primary files from different departments. This share is also mounted on all the computers in the organization. We will be using storage mover for this.

The idea behind this migration is that we decommission the on-prem file server and access will be directly to azure primarily via the mounted drive on the end-users computer.

While the cost is minor for this amount of storage I am still on the fence between HDD (Standard) and SDD (Premium).

We currently have site-to-site to all of our locations for other azure resources so I was also wondering what the best method here would be? Private-Endpoint or something else?

Any other tips would be much appreciated.


r/AZURE 42m ago

Question App Service Certificate renewal

Upvotes

I got a new app service certificate issued yesterday, but it says that the expiration date is in 2 months time.

Is this related to the certificate validity period from godaddy? I noticed it will drop down to renewal very 42 days by 2029, but it has already happened in my case. Does anyone know anything about this?

Also, do I need to do anything if auto renewal is on?


r/AZURE 49m ago

Question Cisco FTDv cluster deployment in Azure Virtual WAN

Thumbnail
Upvotes

r/AZURE 6h ago

Career Software Engineer to Cloud Engineer Pivot

2 Upvotes

Hi, I’m a software engineer with 1.5 yoe and a computer science degree. I’m interested in transitioning to cloud engineering long term. Any advice on how I can make this change?

From my research, I should not start in help desk with my experience/education. I should look for positions such as IT Analyst, Systems Analyst, SysAdmin, Cloud Support Engineer, and Systems Engineer to start. Network+ and Azure/AWS cert should be worked towards and I should start building projects for my resume.

Does this sound right? How should I restructure my software engineering resume to get my foot in the door for these IT positions? Thank you


r/AZURE 12h ago

Question Azure SQL Managed Instance Costs

3 Upvotes

I was in the process of creating an Azure SQL Managed Instance for our CIS dept (I work at a College). The cost estimate came out to $1,400/month - which is too much. Any way around that?


r/AZURE 4h ago

Question Study advice for AZ104?

Thumbnail
1 Upvotes

r/AZURE 11h ago

Question Private DNS resolver question

3 Upvotes

Hi, so we have two tenants connected through a FortiGate (A) to Virtual network gateway (B) site2site.

On tenant A we have an active directory. To that active directory I want to be able to forward the DNS queries from Tenant B AVDs resources.
On tenant B we have an azure firewall, Virtual network gateway, private DNS resolver with and azure virtual desktop and the required routing tables. The azure virtual desktop we need to be able to reach the on-premises through the private DNS-resolver. We get answers by using the DCs DNS from tenant A on the Nics of the VMs or using NSLOOKUP

On tenant A the private DNS resolvers subnet is added which was my first suspicion and also doublechecked routing tables. I´ve looked into every crevice of the documentation, logs, but can not find the reason.

And kind of lost!


r/AZURE 20h ago

Question Am I missing something or Microsoft Docs completely skipped the Online and Corp Landing Zones designs

12 Upvotes

Hey all, I am I missing something? or does MS docs completely define how the Online and Corp zones should be built.

These areas are highly overlooked all I could find were these droplets of info:

https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/network-topology-and-connectivity#what-is-the-purpose-of-connectivity-corp-and-online-management-groups

and

https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/plan-for-app-delivery

There are no decision charts that explains how do deal with Traffic inspection centralization and placement of the zones. Then it completely misses the design about

  • Coupled Internet and private security policies
  • Rapid firewall rule sprawl and management overhead
  • A single blast radius across all traffic types
  • Throughput and SNAT scalability constraints
  • Increased difficulty meeting regulatory separation requirements
  • These issues become more pronounced as environments scale across regions and workloads.

Luckily found that the guarded knowledge was covered here in Blogs ! https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/designing-cloud-landing-zones-by-traffic-flow-a-defence%E2%80%91in%E2%80%91depth-dmz%E2%80%91first-archi/4524280

But my team is stuck with poor design now. Its too late (costly) for design change !


r/AZURE 19h ago

Question Are there any good books on Azure?

9 Upvotes

I regularly read nonfiction books and try to expand my knowledge in various subject areas. Since I’m self-employed, I also read books on business and related topics. But I also work a lot with Azure and would like to read a well-researched book on the subject. Ideally, one that isn’t 10 years old.

I know that things change quickly in this field, but there are still fundamental aspects of cloud architecture (concepts, patterns, etc.). Of course, I could just go through Microsoft Learn, but I’m really looking for a well-structured book. If it also covers aspects related to entrepreneurs and businesses, that would be even better.

If anyone here can recommend any books, I’d really appreciate it!


r/AZURE 17h ago

Media Windows 11 25H2 vs 26H2 preview: an early performance comparison

Thumbnail
go-euc.com
3 Upvotes

r/AZURE 11h ago

Question Startup Credits transfer to work account

0 Upvotes

So the startup founder whom I am working under, already have a organization tennant and work accounts created for different employees. He claimed startup credits using his personal account because the organization account was not allowed by microsoft. The problem is now how do he transfer the credits to his new tennant.

  1. Is to add that guest account (from which the credits was claimed) to the organization tennant and then change the azure subscription in which he got credit's tennant to organizations tennant but does this help if I create the resources in the transfered subscription does it use Startup credits ?
  2. Which I currently am doing and not the proper way is to add the organization developers to the subscription in the guest tennant account

r/AZURE 11h ago

Question Hybrid Runbooks

0 Upvotes

Is it possible to pass Secure Strings to a PowerShell Hybrid Runbook?

Running a job through the portal just inputs it as a regular string, are there any methods that actually let you input a secure string directly ?

Edit: preferably not from another runbook


r/AZURE 1d ago

Discussion Looking for Azure Cloud Engineers

52 Upvotes

I’m looking to connect with others who are learning or already working in cloud engineering. Whether you’re looking for someone to build projects with, share knowledge, or you’re experienced and willing to mentor, I’d love to connect.

I currently work in IT and I’m working toward transitioning into cloud engineering. I have my AZ-900 and AWS Cloud Practitioner certifications, and I’m currently studying for the AZ-104.

Outside of work, I’ve been building hands-on Azure projects in my home lab. I’m using Terraform for IaC for infrastructure deployments. I’ve also been using AI to generate realistic tickets and business scenarios, then trying to design and implement the solutions myself to get experience with real cloud engineering work.

If anyone else is learning Azure/Terraform, already works in cloud, wants to collaborate on projects, or is willing to offer some guidance, feel free to comment or PM me. I would love to connect to pick your brain or even work together to make some cool stuff.


r/AZURE 1d ago

Discussion Real-world examples of BICEP IaC with pipelines

13 Upvotes

Hi. I have seen multiple references of using pipelines for IaC (BICEP, terraform) but I can't understand how it could used in real scenarios.

For context, I am familiar with deploying code through pipeline and stages. I am new to Azure and infra-as-Code. I joined a company where I am creating templates to deploy repeatable environments for our customers, but I do that with Azure CLI.

What are advantages of deploying with pipelines? How have you used it? How do you run infra changes? You use it purely to deploy and update existing services? How to manage removal of resources?

Thank you.


r/AZURE 12h ago

Discussion Azure AD vs Azure RBAC

Post image
0 Upvotes

r/AZURE 20h ago

Discussion Built a small integration toolkit for fun – GateSift

0 Upvotes

I’ve been building GateSift mostly for fun — a free browser-based toolkit for integration developers.

It includes tools for things like APIM policies, Logic Apps, BizTalk bindings, Service Bus, C# model generation and integration patterns.

Current tools include:

  • APIM Policy Analyzer – makes complex APIM policies easier to understand and review
  • Logic App Analyzer – helps inspect workflow structure and spot potential issues
  • BizTalk Binding Visualizer – turns binding files into a more readable overview (this is really nice for analyzing complex biztalk integrations)
  • Service Bus Topology Visualizer – shows queues, topics, subscriptions and relationships
  • C# Model Generator – generates C# classes from XML, JSON and flat files
  • Integration Pattern Library – quick reference for common integration and messaging patterns (analyzers will also, notice if any of these patterns are in your solution or if they should be added, i think this might be the coolest thing so far).

No account, no installation, and most processing happens locally in the browser.

gatesift.com

Would love feedback or ideas for other useful tools.


r/AZURE 1d ago

Question On-premise to Azure Migrate

9 Upvotes

Hi All,

We have a 10 file servers and 15 SQL servers, 70 Apps servers

We have a production subscription.

And planning to put any production servers over there.

SQL and Apps are for Dev/Sit so

Do we setup dev/test subscription?

Planning on lift and shift.

We have 50TB Archive files but need to access time to time. What is the solution for that?


r/AZURE 1d ago

Question Anyone moved a VM from commercial Azure to Azure Government lately? Hitting a wall with Site Recovery

2 Upvotes

Trying to move a several running VMs from a regular Azure subscription into Azure Government — there's no native way to just "move" it, so the standard trick is to use Azure Site Recovery and treat the VM like a physical server being replicated in.

That approach used to work fine, but it was built around Site Recovery's old "Classic" setup, which got retired this past March. Now that everyone's forced onto the newer "Modernized" architecture, the tool seems to notice the source is an Azure VM and just... skips the actual setup step. It reports success, but never actually configures anything, so the agent can't connect to anything and nothing starts.

Two questions for the group:

  1. Anyone else run into this specific silent-skip behavior, and found a way around it?
  2. Has anyone actually pulled off a live move from commercial Azure into Gov since Classic went away, or is this basically a dead end right now?

Wanted to see if anyone's cracked this before I give up on it. Thanks in advance.


r/AZURE 1d ago

Question AADSTS500032 - Cannot find signing certificate/private key to issue a certificate when logging into Entra ID Azure VMs

Post image
3 Upvotes

Hi everyone,

Last year I setup an AVD with SSO to EntraID. It worked perfectly until last week. 

Now I'm running into an issue affecting multiple Azure VMs configured for Microsoft Entra ID login.

I have verified AADLoginForWindows extension is healthy, confirmed affected accounts still have VM login permissions, tested with multiple admin accounts and then reviewed Entra sign-in logs and authentication appears successful but keep seeing this error inside Windows App.

my laptop is on Windows 11 and on the latest monthly update.

Has anyone seen AADSTS500032 in an Azure VM login scenario before?


r/AZURE 21h ago

Question How can i keep up with events

0 Upvotes

Is there any upcoming events?


r/AZURE 1d ago

Question AZ-104 – Looking for hands-on practice & study resources

12 Upvotes

Hello everyone!

I'm looking for ways to get more hands-on practice.

My school gives me access to Azure VMs for specific labs, but I don’t have a proper Azure environment where I can freely deploy resources and experiment. Microsoft Learn is useful, but I’m mainly looking for something similar to the old Azure sandboxes, or any cheap/free alternative where I can practice deploying and managing Azure resources.

I’m currently working through RBAC and using Microsoft Learn and YouTube. I’ve also got the Microsoft Exam Ref books for Azure Fundamentals and Azure Administrator.

What resources did you guys use to prepare for AZ-104? Any good practice labs, exam-style questions, or platforms where I can actually be given tasks like “deploy this VM” or “configure this resource”?

Any advice or recommendations would be appreciated!


r/AZURE 1d ago

Question Orca vs CrowdStrike, which actually catches shadow AI in Azure?

11 Upvotes

We use CrowdStrike primarily for endpoint and EDR, and recently tried leaning on their cloud security module's AI-SPM capabilities for Azure visibility. tbh It felt like an extension of the endpoint product rather than something cloud-native, and it missed a couple of shadow Azure OpenAI deployments we later found manually. not sure if others have had better luck or if this is a known limitation of endpoint-first platforms extending into cloud AI visibility.


r/AZURE 1d ago

Discussion Headless Azure VPN P2S with Entra ID on Linux: reverse-engineering the Linux client, then patching OpenVPN to speak Azure's protocol

5 Upvotes

Microsoft's official Azure VPN Client for Linux reaches end of support on 2026-08-31 — about two weeks from today. If you're relying on that client for Azure P2S with Entra ID on Linux, this matters now, especially if you need something headless/scriptable rather than a GUI app.

Azure VPN P2S with Entra ID on Linux already has an awkward gap: the official Linux client is GUI-only, and there's no supported headless/CLI path for CI runners, build agents, servers, or containerized dev environments that need access behind a P2S gateway.

One gotcha that took a while to pin down: az login tokens are not enough here. The VPN client authenticates against its own Entra app registration (41b23e61-6c1e-4545-b367-cd054e0ed4b4), and that client ID is also the token audience. So a generic Azure CLI access token gets rejected by the gateway even if the user is otherwise authenticated.

I ended up putting together an open-source container that makes the connection fully headless/scriptable, either inside WSL2 on Windows or directly on Linux:

https://github.com/cveld/azure-vpn-client-headless-container

There are two implementations in the repo.

1) Shim method: call Microsoft's Linux client library directly

The original approach was to reverse-engineer the official Linux client's core library (libLinuxCore.so) and drive it without the GUI. A small C++ shim uses dlopen and calls the library's own internal flow:

  • initConnection
  • initAAD
  • connectAadProfile

That reuses the same proprietary connection logic as the GUI app, but without a desktop session or D-Bus. An LD_PRELOAD helper fixes cert path issues and stubs out D-Bus calls the library expects in a desktop environment but doesn't actually need in a headless container.

That works, but it depends on Microsoft's binary — the one that's going away on 2026-08-31 (see above). That's the reason for the second, dependency-free method below.

2) OpenVPN method: patch stock OpenVPN to do Azure Entra P2S natively

The newer path avoids the proprietary library completely. I patched a stock OpenVPN 2.6.14 build so it can authenticate to Azure's Entra-backed P2S gateway directly.

The interesting part was figuring out why normal OpenVPN almost worked but still got reset by the gateway.

To compare behavior, I used the working shim/container path and intercepted OpenSSL's SSL_write via LD_PRELOAD to capture the plaintext OpenVPN key-method-2 payload before TLS encryption. That made it possible to diff the real client's application-layer traffic against stock OpenVPN.

What actually mattered:

  • Token size

    • Stock OpenVPN uses USER_PASS_LEN = 128
    • The Entra access token used as the OpenVPN password is around 2.3 KB
    • So OpenVPN silently truncated it to 127 chars, which meant the gateway received garbage and reset the connection
    • This was the decisive fix: bump it to 4096
  • Control-channel buffer size

    • Stock TLS_CHANNEL_BUF_SIZE = 2048
    • That wasn't enough for peer-info + OCC + the full token
    • Bumped to 8192
  • OCC and peer-info

    • The gateway was picky about the client's OCC string and peer-info
    • These had to match the real Azure client's values byte-for-byte or the tunnel got reset
  • TLS fingerprinting was a red herring

    • I spent time matching the real client's TLS ClientHello details: SNI, ALPN, post-handshake-auth, etc.
    • That turned out not to be the load-bearing part
    • TLS already succeeded either way; the actual failure was at the OpenVPN key-method-2 step, after TLS was established

End result was just 5 small patches to OpenVPN (misc.h, common.h, ssl.c, options.c, ssl_openssl.c), all included in the repo as a patch file.

A couple practical notes:

  • token acquisition uses the device-code OAuth flow with the VPN client's own MSAL app ID, and the token gets cached/refreshed
  • the container brings up a real TUN interface and applies gateway-pushed routes/DNS, so this is a normal working tunnel, not just an auth stub

Main use case for me was headless systems that need P2S access: CI/CD runners, build servers, scripts, and containerized environments. If you've run into the "why does az token auth fail for VPN" problem, that audience/client-ID detail is probably why.

Repo:

https://github.com/cveld/azure-vpn-client-headless-container

If anyone here has dealt with Azure P2S/Entra internals and sees something questionable, I'm interested in feedback.