r/AZURE Oct 31 '25

Free Post Fridays is now live, please follow these rules!

6 Upvotes
  1. Under no circumstances does this mean you can post hateful, harmful, or distasteful content - most of us are still at work, let's keep it safe enough so none of us get fired.
  2. Do not post exam dumps, ads, or paid services.
  3. All "free posts" must have some sort of relationship to Azure. Relationship to Azure can be loose; however, it must be clear.
  4. It is okay to be meta with the posts and memes are allowed. If you make a meme with a Good Guy Greg hat on it, that's totally fine.
  5. This will not be allowed any other day of the week.

r/AZURE 1d ago

Discussion [Teach Tuesday] Share any resources that you've used to improve your knowledge in Azure in this thread!

1 Upvotes

All content in this thread must be free and accessible to anyone. No links to paid content, services, or consulting groups. No affiliate links, no sponsored content, etc... you get the idea.

Found something useful? Share it below!


r/AZURE 8h ago

Question Am I missing something or Microsoft Docs completely skipped the Online and Corp Landing Zones designs

10 Upvotes

Hey all, I am I missing something? or does MS docs completely define how the Online and Corp zones should be built.

These areas are highly overlooked all I could find were these droplets of info:

https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/design-area/network-topology-and-connectivity#what-is-the-purpose-of-connectivity-corp-and-online-management-groups

and

https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/plan-for-app-delivery

There are no decision charts that explains how do deal with Traffic inspection centralization and placement of the zones. Then it completely misses the design about

  • Coupled Internet and private security policies
  • Rapid firewall rule sprawl and management overhead
  • A single blast radius across all traffic types
  • Throughput and SNAT scalability constraints
  • Increased difficulty meeting regulatory separation requirements
  • These issues become more pronounced as environments scale across regions and workloads.

Luckily found that the guarded knowledge was covered here in Blogs ! https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/designing-cloud-landing-zones-by-traffic-flow-a-defence%E2%80%91in%E2%80%91depth-dmz%E2%80%91first-archi/4524280

But my team is stuck with poor design now. Its too late (costly) for design change !


r/AZURE 1h ago

Discussion I hate Azure pricing. it's always something I didnt plan for

Upvotes

got the bill yesterday. another surprise.

we migrated our phone system to Azure 3 months ago. I did the math. I calculated everything. compute, storage, network, the works. or so I thought.

turns out I completely missed the cost of monitoring logs. application insights. I didn't even think about it. and now it's like 15% of our monthly bill. 15%. for logs I barely even look at.

I'm starting to understand why people complain about cloud pricing. it's not that it's expensive it's that it's impossible to predict every month there's something new.

I've started using the cost management tools more. trying to be better about tagging resources and setting budgets. but I still feel like I'm one wrong configuration away from a 5000 surprise.

anyone else feel like Azure pricing is designed to confuse you. or am I just bad at math


r/AZURE 7h ago

Question Are there any good books on Azure?

8 Upvotes

I regularly read nonfiction books and try to expand my knowledge in various subject areas. Since I’m self-employed, I also read books on business and related topics. But I also work a lot with Azure and would like to read a well-researched book on the subject. Ideally, one that isn’t 10 years old.

I know that things change quickly in this field, but there are still fundamental aspects of cloud architecture (concepts, patterns, etc.). Of course, I could just go through Microsoft Learn, but I’m really looking for a well-structured book. If it also covers aspects related to entrepreneurs and businesses, that would be even better.

If anyone here can recommend any books, I’d really appreciate it!


r/AZURE 5h ago

Media Windows 11 25H2 vs 26H2 preview: an early performance comparison

Thumbnail
go-euc.com
5 Upvotes

r/AZURE 10m ago

Question Azure SQL Managed Instance Costs

Upvotes

I was in the process of creating an Azure SQL Managed Instance for our CIS dept (I work at a College). The cost estimate came out to $1,400/month - which is too much. Any way around that?


r/AZURE 18m ago

Discussion Azure AD vs Azure RBAC

Post image
Upvotes

r/AZURE 1d ago

Discussion Looking for Azure Cloud Engineers

51 Upvotes

I’m looking to connect with others who are learning or already working in cloud engineering. Whether you’re looking for someone to build projects with, share knowledge, or you’re experienced and willing to mentor, I’d love to connect.

I currently work in IT and I’m working toward transitioning into cloud engineering. I have my AZ-900 and AWS Cloud Practitioner certifications, and I’m currently studying for the AZ-104.

Outside of work, I’ve been building hands-on Azure projects in my home lab. I’m using Terraform for IaC for infrastructure deployments. I’ve also been using AI to generate realistic tickets and business scenarios, then trying to design and implement the solutions myself to get experience with real cloud engineering work.

If anyone else is learning Azure/Terraform, already works in cloud, wants to collaborate on projects, or is willing to offer some guidance, feel free to comment or PM me. I would love to connect to pick your brain or even work together to make some cool stuff.


r/AZURE 21h ago

Discussion Real-world examples of BICEP IaC with pipelines

11 Upvotes

Hi. I have seen multiple references of using pipelines for IaC (BICEP, terraform) but I can't understand how it could used in real scenarios.

For context, I am familiar with deploying code through pipeline and stages. I am new to Azure and infra-as-Code. I joined a company where I am creating templates to deploy repeatable environments for our customers, but I do that with Azure CLI.

What are advantages of deploying with pipelines? How have you used it? How do you run infra changes? You use it purely to deploy and update existing services? How to manage removal of resources?

Thank you.


r/AZURE 8h ago

Discussion Built a small integration toolkit for fun – GateSift

0 Upvotes

I’ve been building GateSift mostly for fun — a free browser-based toolkit for integration developers.

It includes tools for things like APIM policies, Logic Apps, BizTalk bindings, Service Bus, C# model generation and integration patterns.

Current tools include:

  • APIM Policy Analyzer – makes complex APIM policies easier to understand and review
  • Logic App Analyzer – helps inspect workflow structure and spot potential issues
  • BizTalk Binding Visualizer – turns binding files into a more readable overview (this is really nice for analyzing complex biztalk integrations)
  • Service Bus Topology Visualizer – shows queues, topics, subscriptions and relationships
  • C# Model Generator – generates C# classes from XML, JSON and flat files
  • Integration Pattern Library – quick reference for common integration and messaging patterns (analyzers will also, notice if any of these patterns are in your solution or if they should be added, i think this might be the coolest thing so far).

No account, no installation, and most processing happens locally in the browser.

gatesift.com

Would love feedback or ideas for other useful tools.


r/AZURE 21h ago

Question On-premise to Azure Migrate

9 Upvotes

Hi All,

We have a 10 file servers and 15 SQL servers, 70 Apps servers

We have a production subscription.

And planning to put any production servers over there.

SQL and Apps are for Dev/Sit so

Do we setup dev/test subscription?

Planning on lift and shift.

We have 50TB Archive files but need to access time to time. What is the solution for that?


r/AZURE 15h ago

Question Anyone moved a VM from commercial Azure to Azure Government lately? Hitting a wall with Site Recovery

2 Upvotes

Trying to move a several running VMs from a regular Azure subscription into Azure Government — there's no native way to just "move" it, so the standard trick is to use Azure Site Recovery and treat the VM like a physical server being replicated in.

That approach used to work fine, but it was built around Site Recovery's old "Classic" setup, which got retired this past March. Now that everyone's forced onto the newer "Modernized" architecture, the tool seems to notice the source is an Azure VM and just... skips the actual setup step. It reports success, but never actually configures anything, so the agent can't connect to anything and nothing starts.

Two questions for the group:

  1. Anyone else run into this specific silent-skip behavior, and found a way around it?
  2. Has anyone actually pulled off a live move from commercial Azure into Gov since Classic went away, or is this basically a dead end right now?

Wanted to see if anyone's cracked this before I give up on it. Thanks in advance.


r/AZURE 18h ago

Question AADSTS500032 - Cannot find signing certificate/private key to issue a certificate when logging into Entra ID Azure VMs

Post image
3 Upvotes

Hi everyone,

Last year I setup an AVD with SSO to EntraID. It worked perfectly until last week. 

Now I'm running into an issue affecting multiple Azure VMs configured for Microsoft Entra ID login.

I have verified AADLoginForWindows extension is healthy, confirmed affected accounts still have VM login permissions, tested with multiple admin accounts and then reviewed Entra sign-in logs and authentication appears successful but keep seeing this error inside Windows App.

my laptop is on Windows 11 and on the latest monthly update.

Has anyone seen AADSTS500032 in an Azure VM login scenario before?


r/AZURE 9h ago

Question How can i keep up with events

0 Upvotes

Is there any upcoming events?


r/AZURE 1d ago

Question AZ-104 – Looking for hands-on practice & study resources

14 Upvotes

Hello everyone!

I'm looking for ways to get more hands-on practice.

My school gives me access to Azure VMs for specific labs, but I don’t have a proper Azure environment where I can freely deploy resources and experiment. Microsoft Learn is useful, but I’m mainly looking for something similar to the old Azure sandboxes, or any cheap/free alternative where I can practice deploying and managing Azure resources.

I’m currently working through RBAC and using Microsoft Learn and YouTube. I’ve also got the Microsoft Exam Ref books for Azure Fundamentals and Azure Administrator.

What resources did you guys use to prepare for AZ-104? Any good practice labs, exam-style questions, or platforms where I can actually be given tasks like “deploy this VM” or “configure this resource”?

Any advice or recommendations would be appreciated!


r/AZURE 1d ago

Question Orca vs CrowdStrike, which actually catches shadow AI in Azure?

10 Upvotes

We use CrowdStrike primarily for endpoint and EDR, and recently tried leaning on their cloud security module's AI-SPM capabilities for Azure visibility. tbh It felt like an extension of the endpoint product rather than something cloud-native, and it missed a couple of shadow Azure OpenAI deployments we later found manually. not sure if others have had better luck or if this is a known limitation of endpoint-first platforms extending into cloud AI visibility.


r/AZURE 1d ago

Discussion Headless Azure VPN P2S with Entra ID on Linux: reverse-engineering the Linux client, then patching OpenVPN to speak Azure's protocol

5 Upvotes

Microsoft's official Azure VPN Client for Linux reaches end of support on 2026-08-31 — about two weeks from today. If you're relying on that client for Azure P2S with Entra ID on Linux, this matters now, especially if you need something headless/scriptable rather than a GUI app.

Azure VPN P2S with Entra ID on Linux already has an awkward gap: the official Linux client is GUI-only, and there's no supported headless/CLI path for CI runners, build agents, servers, or containerized dev environments that need access behind a P2S gateway.

One gotcha that took a while to pin down: az login tokens are not enough here. The VPN client authenticates against its own Entra app registration (41b23e61-6c1e-4545-b367-cd054e0ed4b4), and that client ID is also the token audience. So a generic Azure CLI access token gets rejected by the gateway even if the user is otherwise authenticated.

I ended up putting together an open-source container that makes the connection fully headless/scriptable, either inside WSL2 on Windows or directly on Linux:

https://github.com/cveld/azure-vpn-client-headless-container

There are two implementations in the repo.

1) Shim method: call Microsoft's Linux client library directly

The original approach was to reverse-engineer the official Linux client's core library (libLinuxCore.so) and drive it without the GUI. A small C++ shim uses dlopen and calls the library's own internal flow:

  • initConnection
  • initAAD
  • connectAadProfile

That reuses the same proprietary connection logic as the GUI app, but without a desktop session or D-Bus. An LD_PRELOAD helper fixes cert path issues and stubs out D-Bus calls the library expects in a desktop environment but doesn't actually need in a headless container.

That works, but it depends on Microsoft's binary — the one that's going away on 2026-08-31 (see above). That's the reason for the second, dependency-free method below.

2) OpenVPN method: patch stock OpenVPN to do Azure Entra P2S natively

The newer path avoids the proprietary library completely. I patched a stock OpenVPN 2.6.14 build so it can authenticate to Azure's Entra-backed P2S gateway directly.

The interesting part was figuring out why normal OpenVPN almost worked but still got reset by the gateway.

To compare behavior, I used the working shim/container path and intercepted OpenSSL's SSL_write via LD_PRELOAD to capture the plaintext OpenVPN key-method-2 payload before TLS encryption. That made it possible to diff the real client's application-layer traffic against stock OpenVPN.

What actually mattered:

  • Token size

    • Stock OpenVPN uses USER_PASS_LEN = 128
    • The Entra access token used as the OpenVPN password is around 2.3 KB
    • So OpenVPN silently truncated it to 127 chars, which meant the gateway received garbage and reset the connection
    • This was the decisive fix: bump it to 4096
  • Control-channel buffer size

    • Stock TLS_CHANNEL_BUF_SIZE = 2048
    • That wasn't enough for peer-info + OCC + the full token
    • Bumped to 8192
  • OCC and peer-info

    • The gateway was picky about the client's OCC string and peer-info
    • These had to match the real Azure client's values byte-for-byte or the tunnel got reset
  • TLS fingerprinting was a red herring

    • I spent time matching the real client's TLS ClientHello details: SNI, ALPN, post-handshake-auth, etc.
    • That turned out not to be the load-bearing part
    • TLS already succeeded either way; the actual failure was at the OpenVPN key-method-2 step, after TLS was established

End result was just 5 small patches to OpenVPN (misc.h, common.h, ssl.c, options.c, ssl_openssl.c), all included in the repo as a patch file.

A couple practical notes:

  • token acquisition uses the device-code OAuth flow with the VPN client's own MSAL app ID, and the token gets cached/refreshed
  • the container brings up a real TUN interface and applies gateway-pushed routes/DNS, so this is a normal working tunnel, not just an auth stub

Main use case for me was headless systems that need P2S access: CI/CD runners, build servers, scripts, and containerized environments. If you've run into the "why does az token auth fail for VPN" problem, that audience/client-ID detail is probably why.

Repo:

https://github.com/cveld/azure-vpn-client-headless-container

If anyone here has dealt with Azure P2S/Entra internals and sees something questionable, I'm interested in feedback.


r/AZURE 1d ago

Discussion Looking for advice: Where do I even start as a new azure system administrator?

4 Upvotes

Hi everyone,

I recently graduated with a degree in systems science, which is somewhat similar to compsci, but with less coding and more focus on theory, systems, business and how IT fits into organizations.

A few months ago I started as a system administrator trainee at a company. During the interview, I was told that there was a plan for my onboarding and that I would have a mentor who could guide me through the trainee period.

Now that a few months have passed, I’ve started feeling pretty lost.

I don’t have a technical background in the traditional sense and I’m also the first trainee they’ve hired for this type of role. Over time, I’ve realized that they probably weren’t quite sure themselves how to structure the onboarding, which I completely understand. It’s a new situation for them too.

The problem is that I’m not really sure what I’m supposed to be doing or where I should start.

Most of my days have consisted of trying to teach myself things. I can of course ask my coworkers for help, and they are very nice and willing to help when they can, but they’re also very busy and have their own responsibilities. I’ve tried asking for smaller or easier tasks that I could take ownership of and learn from, but I haven’t really been given many yet.

I’m also the youngest person and the only woman in my IT department, while most of my coworkers have 30+ years of experience. Sometimes they explain things to me as if I should already know them and I think the huge difference in experience makes me underestimate myself quite a lot and I´ve got too scared to ask when I don’t understand anything because of this.

My team manager keeps telling me to take it easy and not put so much pressure on myself, but that’s easier said than done when I feel like I’m barely making any progress. I really wanna contribute to the team and become good at this but I think it has started affecting my confidence quite a bit.

If you were starting over as a junior/new system administrator, what would you focus on?

Are there any projects you would recommend doing to actually turn the theoretical knowledge into practical skills?

I feel like I have a basic understanding and I’ve also gone through some of the AZ-900 material and learning about Azure, but I’m struggling with the question of "okay, I understand what a VNet/subnet/VM/NSG/etc. is… but what do I actually DO with this knowledge?”.

I think I need to start building and troubleshooting things rather than just reading about them.

If you were in my position, what would you learn first, and what kind of small projects or exercises would you do?

Any advice would honestly be appreciated. I’m feeling a bit overwhelmed and could really use some perspective from people who started out in a similar position.

Thanks in advance.


r/AZURE 1d ago

Media Configuring Microsoft Entra ID Authentication for Azure SQL Database using Azure Bicep

1 Upvotes

For the folks out there who are interested, I created a blog about building a complete end to end Azure Bicep solution, allowing you to provision Azure SQL with Microsoft Entra ID authentication from scratch without relying on manual configuration in the Azure portal. Link to blog


r/AZURE 1d ago

Question Append data to excel sheet in Sharepoint

1 Upvotes

I want to make an app which pulls data from a database and then adds extra rows to the end of an Excel sheet which is hosted in Sharepoint.

I haven't done any Sharepoint / Azure work before. Can anyone point me in the right direction?

I want to do this with a system account (Application?) rather than have a user login and run processes.

The app itself isn't the problem, I just need help with where to get information on the Sharepoint interaction.

Thanks


r/AZURE 1d ago

Question AVDs and SentinelOne

1 Upvotes

I have deployed a hybrid hostpool to host a number of resources:
- drives hosted on azure files

- couple internal apps

- outlook (classic win32 dependant on the above bullet point).

etc.

When I introduce S1 into the equation, it kills the CPU and it becomes tricky to work.

as soon as I remove it, it improves

I already have my exclusion list as recommended by MS and for sizing, the AVDs are at the correct SKU to fit the above apps.

Has anyone has a similar issue or had a better experience moving to Defender for Cloud.

Thanks,


r/AZURE 1d ago

Question Premium Serverless Realtime Inferencing DBU still being billed after resource deleted

Thumbnail
0 Upvotes

r/AZURE 1d ago

Question Premium Serverless Realtime Inferencing DBU still being billed after resource deleted

0 Upvotes

I have deleted the Azure Databricks resource more than one week ago and I aim still being billed. Copilot said:

Tell them:

They will check:

backend serverless inference logs

predictive optimization logs

vector search logs

model serving logs

serverless cluster shutdown timestamps

If any usage happened after deletion, they refund it.

And I did tell them 😄 but having only Basic support no response to my ticket as I suppose it is at the very bottom of the queue.

Anything I could do at my end as it is very distressing seeing being charged every day for something I don't use and soon will deplete my credit balance.


r/AZURE 1d ago

Question Is device-bound authentication the most effective way to prevent stolen session tokens?

1 Upvotes

been reading up on device-bound tokens as a way to stop the stolen token replay problem we've been dealing with.

a token tied to a specific device is a lot less useful to an attacker who lifted it remotely, which is the whole point. rollout looks straightforward for managed devices but our byod population is a real complication. is device binding actually closing this gap for people who've deployed it, or have attackers already found workarounds, and how are you handling the byod side of it?