How Microsoft’s Physical Security Engineering Team scaled hybrid operations with Azure Arc and Azure Virtual Desktop

When a physical security operator begins a shift supporting Microsoft’s global datacenter operations, they depend on a collection of applications and systems that help monitor access activity, review video feeds, investigate alerts, and coordinate physical security operations across a complex global environment. Those tools must be available, responsive, and reliable from the moment a shift begins.

As Azure datacenters expanded to support growing demand for cloud and AI services, maintaining that experience became increasingly important. Critical security systems were distributed across hundreds of locations worldwide, while the infrastructure supporting them spanned both on-premises and cloud environments. The challenge wasn’t responding to a specific incident or operational failure but ensuring that as Azure’s physical footprint continued to grow, the systems supporting those operations remained secure, manageable, observable, and consistent at a global scale.

See how Azure Arc unifies hybrid operations

Meeting that goal required more than simply keeping systems online. The team needed a way to manage infrastructure across hybrid environments, standardize operations, automate routine tasks, improve visibility into system health, and provide operators with consistent application experiences regardless of location. By combining Azure Arc, Azure Virtual Desktop, Azure Monitor, and other Azure management services, Microsoft built a more unified operational foundation designed to support the evolving needs of its global physical security environment.

Building a unified management layer across hybrid infrastructure

As Azure datacenters expanded, so did the infrastructure supporting their physical security operations. Critical systems were deployed close to the environments they served and operated within highly segmented networks designed to prioritize resiliency, security, compliance, and local autonomy. That architecture solved one challenge but created another.

The physical security organization was responsible for deploying and managing thousands of servers distributed across Microsoft’s global datacenter footprint in alignment with established protocols. While each deployment met baseline operational requirements, rapid growth and increasing scale made it increasingly difficult to guarantee consistency.

The team needed a way to bring these distributed systems under a common management framework without changing where the workloads ran or weakening the security boundaries that protected them.

Why Azure Arc

The objective wasn’t to move these workloads into Azure. Many of the systems supporting physical security operations needed to remain close to the environments they served and continue functioning independently when required by local operational or resiliency needs. Instead, the team was looking for a way to extend the operational benefits of Azure to on-premises infrastructure.

Azure Arc was designed to address exactly this type of challenge. At its core, Azure Arc extends Azure’s management and governance capabilities to servers and resources running outside Azure. Rather than treating on-premises systems as separate operational islands with their own tools and processes, Azure Arc allows organizations to manage those resources through Azure’s control plane. This makes it possible to apply, at scale, many of the same monitoring, policy, automation, security, and update-management workflows used in Azure to infrastructure running elsewhere.

For Microsoft’s physical security organization, Azure Arc made it possible to manage servers across its global datacenter footprint through a common operational model, regardless of where they were physically located.

More importantly, Azure Arc allowed the team to preserve the resiliency and security characteristics of their existing deployments while gaining centralized visibility, governance, and automation capabilities.

Establishing a consistent operational foundation

Once onboarded to Azure Arc, the team began extending familiar Azure management capabilities to infrastructure running outside Azure. Using Azure Update Manager, patching activities that had historically required significant coordination across distributed environments could be scheduled, tracked, and governed through a centralized framework. According to the team, this automation now saves thousands of hours annually while enabling a relatively small operations team to support a growing infrastructure footprint.

At the same time, Azure Policy, Guest Configuration, Azure Monitor, Azure Monitor Agent, and Log Analytics helped create a common framework for governance, compliance monitoring, and observability. The team could continuously assess critical security configurations, identify drift, monitor system health, and surface operational telemetry through centralized dashboards, alerts, and reporting workflows regardless of where infrastructure was deployed.

Security remained a primary consideration throughout the design. Managed Identities and Azure role-based access control (RBAC) helped reduce reliance on stored credentials while providing more granular control over access to operational resources. Azure Automation further reduced manual effort by standardizing remediation, maintenance, and configuration-management activities through reusable runbooks. Together, these capabilities helped establish a more consistent operating model across the environment while improving visibility, strengthening governance, and reducing the operational overhead associated with managing a globally distributed infrastructure.

Delivering a consistent operator experience with Azure Virtual Desktop

Unified management solved one part of the challenge. The next was ensuring that operators interacting with those systems received the same level of consistency, performance, and visibility.

The team’s objective extended beyond providing remote access. They needed a way to improve application performance, simplify lifecycle management, and gain better insight into the end-user experience. Azure Virtual Desktop provided a flexible platform for delivering applications closer to the infrastructure they depended on, while also enabling centralized image management and integration with Azure monitoring services. This allowed the team to maintain consistent host configurations, simplify updates, and incorporate user-session telemetry into existing operational workflows.

To improve the operator experience, the team relocated the application environment closer to the infrastructure it supported and delivered access through Azure Virtual Desktop sessions. The impact was immediate: application launch times improved by approximately 12x, helping operators access critical tools more quickly and consistently.

The team also adopted a centralized image-management strategy and automated host refresh process. Instead of maintaining individual systems over time, hosts could be rebuilt from approved images and deployed consistently across the environment. This approach accelerated release cycles by ~6x, reduced configuration drift, and allowed updates that once required weeks or months of coordination to be completed in hours.

Equally important was the visibility Azure Virtual Desktop unlocked. By integrating Azure Virtual Desktop with Azure Monitor, Azure Monitor Agent, Log Analytics, and Azure Virtual Desktop Insights, the team gained access to telemetry on session health, round-trip time, bandwidth usage, and client-side application behavior. Engineers could better understand how applications performed from the operator’s perspective, identify trends earlier, and shift from reactive troubleshooting to a more proactive, data-informed approach.

Key lessons for managing hybrid environments at scale

As Azure’s global datacenter footprint continued to grow, Microsoft’s physical security organization needed a management and delivery model that could scale alongside it. By combining Azure Arc and Azure Virtual Desktop, the team established a more consistent approach to managing infrastructure, delivering applications, and monitoring operational health across a complex hybrid environment.

The result wasn’t a single breakthrough technology, but a unified operating model that improved visibility, reduced operational overhead, and helped ensure critical systems remained resilient, manageable, and ready to support future growth.

Learn more

Azure Arc

Azure Virtual Desktop

Azure Monitor

Bring consistency and control to hybrid operations

See how Azure Arc helps organizations extend Azure management and governance capabilities across distributed infrastructure, enabling centralized visibility, automation, compliance, and operational consistency without changing where workloads run.

Explore Azure Arc

The post How Microsoft’s Physical Security Engineering Team scaled hybrid operations with Azure Arc and Azure Virtual Desktop appeared first on Microsoft Azure Blog.
Quelle: Azure

GPT-6 Astra: Frontier intelligence for work, now available in Microsoft Foundry

The next era of enterprise AI will not be defined by chat experiences. It will be defined by how well a model can work for and with you. GPT-6 Astra, OpenAI’s newest frontier model, begins rolling out today through the Microsoft Foundry Limited Access Program, with availability expanding to participating customers over the coming days. It is designed to help organizations make decisions for complex work and execute across the applications and systems where your business operates.

We are investing to make it easier for customers to use advanced technology like Astra. AI initiatives often slow down on identity, networking, governance, data handling, evaluation, and compliance. Microsoft Foundry brings these fundamentals together in Azure, helping teams move from experimentation to production with speed and trust.

Turn open-ended goals into action

Astra is built to take an open-ended challenge, reason through it in multiple steps, create a plan, and produce a polished result. It can weigh trade-offs, incorporate new direction as work progresses, and use tools across applications and systems. 

For enterprises, this shifts AI from conversational assistance toward delivering more substantial units of work:

Deliberate planning and decision support. Astra can break a challenge into steps, evaluate options, communicate its recommendation, and identify the next actions for review.

Polished, purposeful output. Astra can apply context, templates, and quality standards throughout a workflow, helping produce documents, spreadsheets, presentations, and analyses that are ready for review.

Execution across applications. With advanced tool use and computer use, Astra can interact with software on a person’s behalf, move between apps, and complete multi-step tasks with appropriate human oversight.

At Replit, our mission is making useful intelligence accessible to everyone. GPT-6 Astra available through Microsoft Foundry unlocks a new level of agentic capability that goes beyond code generation to active software creation and more. We’re excited about the opportunities created for developers and entrepreneurs to build more ambitious applications with an intelligent software-building partner.
—Luis Hector Chavez, CTO, Replit

Computer use across applications

Astra’s computer-use capabilities are designed to work across familiar applications, including workflows without dedicated APIs. It can interpret on-screen information and interact with approved interfaces to support tasks such as updating records, navigating development tools, testing software, and assembling results into reports. OpenAI reports state-of-the-art results on selected computer-use evaluations; performance varies by task, tools, configuration, and safeguards.

Capability this direct demands containment. Content displayed in an application may be incomplete, misleading, or designed to influence an agent’s behavior. Foundry helps customers define access, approvals, and monitoring, and design workflows with scoped credentials, approved resources, human checkpoints for consequential actions, and activity records aligned to their risk requirements.

Enterprise scenarios we’re seeing

Software engineering: Astra can reproduce complex bugs, investigate likely causes, propose fixes, and prepare changes for developer testing and review.

Business intelligence: Astra can build and refine dashboards in Power BI, helping analysts compare data, identify trade-offs, and prepare insights to share.

Professional work: Astra can produce documents, spreadsheets, and presentations that follow existing templates and business standards, creating polished artifacts for expert review.

Application workflows: Astra can support tasks such as updating customer records, processing forms, testing websites, and working through approved interfaces where dedicated APIs are limited. 

Enterprise controls for agentic work

OpenAI describes Astra as its most aligned model to date and plans to publish supporting alignment, safety, and computer-use evaluations in its supporting launch materials. Foundry complements that model-level work with enterprise security, safety, and compliance capabilities, including Microsoft Entra identity and access management, encryption in transit and at rest, private networking options, role-based access controls, content filtering, safety evaluations, monitoring, and governance tools.

Prompts and outputs are not used to train the models. These capabilities help customers configure safeguards and maintain oversight, but do not eliminate risk or replace each organization’s responsibility to select and configure controls appropriate to its scenarios and regulatory obligations.

At Albertsons Companies, we believe the real advantage in frontier AI is the ability to evolve as quickly as the technology does, without compromising enterprise discipline. That means creating an environment where we can evaluate new capabilities, put the right ones to work quickly and maintain consistent security, governance and operational controls as we scale. Azure OpenAI on Microsoft Foundry helps us create that balance of speed and control, so our teams can stay focused on delivering meaningful outcomes for our customers, associates and the business.
—Anirban Nandi, VP, Data and AI, Albertsons Companies

Global scale with service level to match

GPT-6 Astra will be available through Standard deployments including Global and U.S. Data Zone. Customers can choose the right deployment based on workload requirements.

This consumption-based model lets teams begin building without committing to reserved capacity. Astra is also designed for token efficiency on complex work, helping customers manage consumption as they scale. Actual usage and costs will vary by workload and configuration.

GPT-6 Astra pricing

DeploymentPricing (USD $/million tokens)InputCached InputCached WritesOutputStandard Global (Short context)$10.00$1.00$12.50$50.00Standard Global (Long context)$20.00$2.00$25.00$75.00Standard Data Zone (US) (Short context)$11.00$1.10$13.75$55.00Standard Data Zone (US) (Long context)$22.00$2.20$27.50$82.50

Get started today

Explore the model: Try GPT-6 Astra in Foundry Models to see its advanced capabilities firsthand.

Build agentic workflows: Start with the Foundry Agent Service to bring cross-application task execution to your workflows.

Try GPT-6 Astra today

Explore the model and start building agentic workflows.

Learn more

The post GPT-6 Astra: Frontier intelligence for work, now available in Microsoft Foundry appeared first on Microsoft Azure Blog.
Quelle: Azure

Enterprise AI transformation relies on the end-to-end platform: Azure was built for this moment

Summary
The recognition for Microsoft over the past couple of weeks comes down to models, infrastructure, data, applications, and developer tools working as one system when AI moves into production.

Enterprise AI is moving into production, and our customers are becoming multi-model. Organizations will use frontier models where capability matters, and smaller, specialized, and open-weight models where economics and finer controls matter. But the value does not come from any model in isolation. It comes from the system around it: infrastructure, data, applications, agents, security, and operations working together. That compounding value is what Microsoft Azure is built to deliver.

A system built from silicon to agent

That integration extends into the infrastructure underneath the model. Customers want the flexibility to choose across models and infrastructure without having to stitch together and tune every layer themselves. Microsoft has drawn on decades of running mission-critical systems and operating some of the world’s most demanding AI services at global scale. We believe that breadth and integration across the platform, extending through developer tools and AI applications is a key reason why Microsoft has been named a Leader in both the 2026 Gartner® Magic Quadrant™ for Strategic Cloud Platform Services and The Forrester Wave™: Public Cloud Platforms, Q3 2026.

We appreciate the recognition. What matters more is that customers choosing a platform today are shaping their infrastructure for years, and that choice rests on system-level capability. A cloud platform now must do more than provide individual services. It must give customers choice across models and infrastructure while helping them build faster, run reliably, manage risk, control cost, and improve outcomes. For an enterprise building the next generation of AI applications, how the layers work together matters more than any single feature.

Discover trusted cloud solutions on Microsoft Azure

Microsoft’s Leader placement in the 2026 Gartner® Magic Quadrant™ for Strategic Cloud Platform Services follows Leader placements in the 2025, 2024, and 2023 editions. We believe that what matters for customers, is whether the platform can translate technology into real impact: better performance, greater cost efficiency, faster delivery, and the ability to scale critical systems with confidence.

Microsoft was also named a Leader in The Forrester Wave™: Public Cloud Platforms, Q3 2026. Forrester’s evaluation looks at both the strength of the current offering and the strategy behind it. This recognition provides another independent view of how Azure is evolving as customers move from isolated AI projects to production systems.

Forrester describes Microsoft’s direction as a vision of Azure as a single, vertically integrated system.

Choice without complexity

A multi-model strategy does not mean every model should run the same way. The platform must support those choices across heterogeneous compute while applying consistent security, identity, governance, reliability, and operations.

Microsoft Foundry is central to this approach. It gives developers broad model choice and the tools to evaluate, secure, monitor, and operate AI systems, with Azure infrastructure underneath. This is not about forcing every workload into one model. It is about using reducing the seams between layers so teams can make workload-specific choices while operating consistently across cloud, on-premises, edge, and third-party environments.

Data gives AI its business value

Model choice will keep changing, but the data and business context that make AI useful endure. Customers want to work with data where it already resides, without creating more copies or losing governance along the way. As Forrester puts it: “Models come and go; data has gravity.”

Microsoft Fabric brings analytics and data together, and Microsoft Purview applies governance across that estate. The Azure databases, including Azure SQL and Azure Cosmos DB, connect AI to current operational data. On top of that foundation, Microsoft IQ provides the unified enterprise intelligence layer, giving apps and agents consistent business context across work, data, and knowledge. Together, these capabilities let organizations change models without rebuilding the data, governance, and business context around every application.

UNC Health illustrates why that foundation matters. By modernizing its analytics, the organization is creating a governed data environment that supports care, operations, and research within the requirements of a highly regulated industry. It is the kind of foundation organizations need before AI can be applied responsibly at scale.

Modernization is the catalyst to AI

The applications running a business today contain years of business logic, data, and operating knowledge. They need a modern home where they can continue to support proven processes and connect to new AI experiences. Modernization is therefore part of the AI work, not a separate project. Customers need to decide workload by workload whether to move it, update it, use a managed service, expose it to agents through secure interfaces, or rebuild the parts where there is a clear business reason.

Levi Strauss & Co. shows how modernization and AI become part of the same journey. The company modernized its legacy infrastructure on Azure to build a more resilient foundation, then used Microsoft Foundry to introduce agents that simplify work and accelerate decision-making. A heritage company did not have to leave its existing business behind to adopt AI; it modernized that foundation and built forward from it.

Agents can help teams assess applications, plan upgrades, refactor code, test changes, and support migration while developers and IT teams retain control of architecture and business decisions. GitHub Copilot agentic modernization supports .NET and Java applications, and the work connects across the software lifecycle. This is where the analyst feedback is especially relevant: Gartner highlights Microsoft’s pragmatic approach to application modernization and its integrated, end-to-end software developer lifecycle, while the Forrester report notes our customers’ appreciation for Microsoft’s migration and modernization expertise. The goal is straightforward: help customers modernize the applications they already rely on and so they are ready for the next generation of AI.

Power every AI ambition

As customers run more AI in production, the platform must be more efficient, more reliable, and easier to operate. Customers need the freedom to choose the models and infrastructure that best fit each workload, while the platform reduces the complexity of bringing those choices together.

We’re proud to be recognized as a Leader by Gartner and Forrester, and even more excited by what these evaluations reflect about where the industry is heading. We believe the next generation of cloud will be defined by how well the platform brings infrastructure, data, models, applications, and developer tools together while preserving the choice customers need as each layer continues to evolve.

That’s the direction we’re building toward with Azure, and we’re excited to keep shaping what comes next alongside our customers and partners.

Review the 2026 Gartner® Magic Quadrant™ for Strategic Cloud Platform Services. Read the report.

Review The Forrester Wave™: Public Cloud Platforms, Q3 2026. Read the report.

Gartner® Magic Quadrant™ for Strategic Cloud Platform Services, 2026. By Alessandro Galimberti, Carolin Zhou, Douglas Toombs, Dennis Smith, Ed Anderson, Tobi Bet, Chuck Lawton, 1 September 2026.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Gartner and Magic Quadrant are trademarks of Gartner, Inc., and/or its affiliates.

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request here.

Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here.
The post Enterprise AI transformation relies on the end-to-end platform: Azure was built for this moment appeared first on Microsoft Azure Blog.
Quelle: Azure

Amazon ECS introduces Early Success Criteria for service deployments

Amazon Elastic Container Service (Amazon ECS) now supports Early Success Criteria for rolling service deployments, giving you the flexibility to define when a deployment is considered successful based on your confidence level and the operational needs of your workload. This can help you complete deployments sooner and unblock subsequent deployments, CI/CD pipelines, and other dependent operations.
With Early Success Criteria, you configure the healthy percent – the proportion of desired tasks that must be running and healthy on the target service revision before the deployment is marked successful. For example, with a desired count of 100 and a healthy percent of 90%, Amazon ECS marks the deployment successful after 90 tasks are healthy and continues launching the remaining tasks through regular service scaling, outside the deployment lifecycle. This can benefit workloads running on specialized or constrained capacity, such as GPU-accelerated inference workloads, where hardware availability can extend task launch times. Early Success Criteria also gives you more control over how long deployment rollback monitoring applies, allowing it to protect the deployment until your configured success criteria are met while subsequent scale-out continues through regular service scaling. You can also choose how Amazon ECS handles source service revision cleanup using BLOCKING or DEFERRED. With BLOCKING, Amazon ECS completes source revision cleanup before declaring success. With DEFERRED, Amazon ECS declares success when the criteria are met and drains source revision tasks asynchronously outside the deployment. This benefits services with active long-lived connections or task scale-in protection, where source revision tasks may need to remain running without holding the deployment open.
The feature is available with the rolling deployment strategy in all AWS Commercial and AWS GovCloud (US) Regions. You can configure Early Success Criteria for new and existing Amazon ECS services using the AWS Management Console, AWS CLI, AWS SDKs, and infrastructure as code (IaC) tools. To learn more, see our documentation.
Quelle: aws.amazon.com

Amazon EC2 now supports specifying compatible instance types on AMIs

Amazon EC2 now enables AMI owners to define which instance types are compatible with their AMIs. Owners can specify supported instance types, unsupported instance types, or both — and any launch attempt on a non-permitted instance type is automatically blocked.
AMI owners now have a built-in way to prevent launches on instances that are not compatible with their AMIs. This reduces the risk of failed launches due to incompatible instance-AMI pairings. By default, an AMI can be launched on any instance type, so existing workflows remain unaffected until restrictions are explicitly applied.
This feature is available in all AWS Regions at no additional cost. To learn more, please visit the documentation.
Quelle: aws.amazon.com