Browse All Posts (148)
Chu Lahlou and Cha Zhang explain why enterprise GenAI systems still need a dedicated content-extraction layer, even with stronger LLMs. They break down the operational gaps of “LLM-only” extraction and position Azure Document Intelligence and Azure Content Understanding as complementary tools for grounded, auditable, multimodal workflows.
Justin Bettencourt rounds up the September 2026 Azure SDK releases across .NET, Java, JavaScript/TypeScript, Python, Go, Rust, and C++, calling out notable updates like Azure AI Search preview API support, a stable Rust SAS crate, and new Entra ID authentication libraries for PostgreSQL.
Allison announces new repository-level controls for where Dependabot version and security update jobs run, including runner type selection plus optional custom labels and runner groups for self-hosted or larger GitHub-hosted runners.
Allison announces a public preview feature that lets enterprises sync repository business context from an external system of record into GitHub using external custom properties, keeping GitHub values read-only and continuously updated via APIs.
Matt Hernandez introduces Azure Canvases for GitHub Copilot, a shared workspace that pairs Copilot chat with interactive dashboards and guided workflows for common Azure tasks like deploying Functions, querying resources across subscriptions, and reviewing cost and governance signals.
Microsoft Developer shares an Azure Essentials Show conversation on estimating and controlling the cost of AI workloads on Azure, including what drives spend (models, compute, storage, and usage patterns) and how to use Azure pricing and governance tools to avoid surprises as you scale.
Allison announces that OpenAI’s GPT-6.1 Sol is generally available and rolling out in GitHub Copilot, highlighting improved multistep coding performance and more efficient token usage. The post also covers where the model can be selected, how admins can control access, and how it’s billed under usage-based pricing.
Fernando de Oliveira, Fernanda Lasmar, and Denise Mignoli explain how to package and distribute shared AI-assisted engineering workflows using GitHub Copilot plugins, so teams can reuse agent instructions, skills, and MCP tool connections while still keeping application-specific context and decisions inside each repo.
James Montemagno hosts a VS Code Live release recap with members of the VS Code and GitHub Copilot teams, highlighting recent feature updates and what they mean for day-to-day developer workflows in the editor.
sbaynes introduces Quine, a Microsoft Research system that combines a multimodal “world model” of biology with an interactive harness that connects models, scientific tools, literature, and wet-lab workflows to speed up biological discovery and hypothesis testing.
Mark Downie outlines the September Visual Studio update, including Bring Your Own Model (BYOM) for Copilot-powered agent mode, one-click fixes for NuGet Audit vulnerability warnings from the Error List, a Git agent for pull request exploration, improved C# debugging hints for compound if conditions, and Podman container attach support.
Microsoft Defender Experts Cybersecurity Incident Response (DART) breaks down how threat actor Storm-3068 used a compromised identity to pivot into Azure DevOps, tamper with trusted pipelines, and harvest Kubernetes credentials, plus practical steps to harden identity controls and DevOps pipelines against similar attacks.
Microsoft Threat Intelligence breaks down how Star Blizzard’s 2026 campaigns evolved toward higher-volume phishing and a new “RedFlick” delivery chain, including scheduled-task persistence, VHDX/LNK/MSI stages, and CosmicPulse backdoor deployment, plus concrete mitigations, Defender detections, hunting queries, and indicators of compromise.
Faisal Mohamood and Bogdan Crivat outline a guided modernization path from Azure Data Factory and Azure Synapse Analytics to Microsoft Fabric, covering the new “view in Fabric” upgrade experience, migration assessment and incremental upgrades, and migration assistants for Spark and dedicated SQL pools into Fabric Data Engineering and Fabric Data Warehouse.
Faisal Mohamood summarizes the FabCon/SQLCon Barcelona 2026 announcements for Fabric Data Factory, covering new mirroring sources, multicloud data distribution improvements, faster and more reusable transformations (Power Query, Dataflow Gen2, notebooks, dbt), richer monitoring, and MCP-based AI assistance across authoring and operations.
bogdanc summarizes the Fabric Analytics announcements from FabCon Europe 2026, covering Fabric IQ’s GA in Copilot experiences, new Power BI app-building capabilities, GPU-accelerated query execution for Fabric Data Warehouse, and expanded governance controls (labels, DLP, and Copilot restrictions) across the Fabric stack.
shireesht summarizes FabCon EU and SQLCon 2026 announcements across Microsoft Fabric and Microsoft SQL, including Fabric Apps for building governed data-backed apps, Database Hub for centralized estate management, and preview “database agents” plus Azure SQL updates like DiskANN vector indexing for RAG scenarios.
yitzhak outlines how Microsoft Fabric is positioning Real-Time Intelligence and Fabric IQ as the “live” data and semantic foundation for trusted AI in enterprises, then walks through new preview features like Observability Insights, Operations Agent/Investigator, Eventstreams improvements, ontology tooling, and governance capabilities.
sapatney announces major updates to Fabric Apps and the Rayfin framework, adding first-class backend capabilities (functions, storage, and databases), new Fabric data connectors (including semantic models with DAX), built-in app metrics, and a clearer enterprise access model based on Entra authentication and delegated identity.
diptiborkar announces new Planning capabilities in Microsoft Fabric IQ, focused on building budgets and forecasts directly on governed Fabric data and Power BI semantic models. The post covers tighter Fabric IQ integration, a new native planning engine, event-driven automation, embedding planning into org apps, and governance/billing controls.
Arun Ulag summarizes the FabCon and SQLCon Barcelona 2026 announcements across Microsoft Fabric and Azure SQL, focusing on how Fabric IQ, OneLake, and new agent experiences aim to provide governed business context for Copilot, analytics, and data/AI applications, plus new observability and database management capabilities.
kimani announces a set of Microsoft Fabric platform updates aimed at running Fabric estates at scale, covering new observability and monitoring experiences, repeatable delivery features (deployment plans, bulk definition APIs, Git enhancements), OneLake catalog discovery (including Copilot CLI), capacity controls and billing options, and expanded governance and security controls.
Dipti Borkar summarizes the FabCon and SQLCon Barcelona 2026 announcements for Microsoft OneLake, covering new ways to share governed context (IQ sharing), connect external platforms via shortcuts and mirroring, use Table APIs for Iceberg/Delta access, and strengthen governance with catalog, policies, and OneLake security.
murray-kp rounds up the September 2026 Microsoft Fabric release, covering major updates across governance, CI/CD and Git integration, OneLake catalog and APIs, data engineering and Spark runtime improvements, warehouse features, real-time intelligence (Eventstream/Eventhouse/Activator), and Fabric IQ/MCP capabilities for agent-driven workflows.
Allison announces an updated enforcement timeline for GitHub Actions self-hosted runner minimum versions on GitHub Enterprise Cloud, including what happens to runners below the required versions and how to avoid workflow disruption.
Kevin Stubbings explains how GitHub Security Lab’s open-source Taskflow Agent uses targeted LLM “taskflows” to audit Android apps, including how to run the workflows in a Codespace and what kinds of findings to expect. He also walks through two disclosed examples and where AI tends to produce false positives or misjudge severity.
Dan Wahlin introduces a free, open source “GitHub Copilot app for Beginners” course that teaches developers how to run and supervise AI coding agents in the Copilot desktop app, keep parallel work isolated with git worktrees, and validate changes with diffs, tests, previews, and PR checks.
Allison announces general availability of Claude Sonnet 5.5 in GitHub Copilot, including where you can select it (IDEs, Copilot CLI, coding agent, and GitHub clients), how it’s billed under usage-based pricing, and how Business/Enterprise admins can control access via model policy settings.
Elijah Newren reviews Git 2.56’s most practical changes for day-to-day workflows and large repo hosting, including safer conflict resolution staging, faster merge-base calculations, and server-friendly path-walk repacks that work with bitmaps and delta islands.
Daniel Roth introduces experimental Blazor AI components in .NET 11 RC1 for building “Agentic UI”: streamed agent output rendered as structured content blocks, tool calls, approvals, and shared state. The post walks through the AgenticUI sample architecture using Microsoft.Extensions.AI, AG-UI, Microsoft Agent Framework, ASP.NET Core, Foundry, and Aspire.
stevenbucher announces the Azure Policy Linter as an open-source CLI and .NET library, aimed at catching common Azure Policy definition mistakes before policies are assigned. The post explains how to install and run it, how rule sets and JSON output work, and highlights several high-impact rules from the catalog.
GitHub introduces how the GitHub Copilot app can stay involved after a pull request is opened, automatically fixing CI failures and addressing reviewer comments so changes can move toward merge with less manual back-and-forth.
The Microsoft Azure Team introduces an Azure Virtual Machine (VM) Lifecycle policy that standardizes how VM series move through lifecycle stages, what customers can expect at each stage, and how to plan workload transitions with clearer timelines, availability expectations, and purchasing options.
Microsoft Threat Intelligence breaks down NeedyMantis, a modular post-compromise malware family used in targeted intrusions, covering its loader chain, custom encrypted archives, C2 over HTTPS/WebSockets, and the key indicators and hunting queries defenders can use in Microsoft Defender XDR and Microsoft Sentinel.
John Savill explains Azure Container Apps (ACA) Sandboxes, focusing on how they provide isolated, secure hosting for agent workloads. He covers the MicroVM-based model, egress controls via proxy and rules, lifecycle and pricing considerations, how sandbox groups work, and operational topics like managing instances and logging.
John Savill gives a quick overview of the Azure Container Apps (ACA) Sandboxes capability and how it relates to Microsoft’s own agentic solutions.
Mark Russinovich explains what tends to fail inside large-scale Azure data centers and why “rare” hardware issues become routine at hyperscale, using concrete examples like power units and processor sockets to frame resilience and reliability thinking.
This week in security, the focus shifted from adding more automation to putting tighter boundaries around it, starting with stronger identity and session controls in GitHub and extending into agent governance across Microsoft Foundry. Updates also targeted the places teams tend to forget until something breaks, including SSH hardening, CodeQL packaging changes, and NuGet signing trust policies that can block CI if you do not update proactively. On the threat side, new reporting on compromised service principals and device code token theft reinforced an identity-first reality where attackers can automate destruction and persistence once they have the right tokens. Rounding things out, platform guidance and releases highlighted practical isolation and egress controls (microVM sandboxes, pod sandboxing, confidential containers) plus operational lessons like how Blob immutability can quietly prevent cleanup when you need it most.
This week in .NET centers on production readiness: Microsoft rotated its NuGet author-signing certificate (which can break locked-down restores), while agent building guidance moved from demos to deployable systems with AG-UI, memory, isolation, and secret redaction patterns. On the operations side, repeatable dump capture and Visual Studio analysis workflows showed how to diagnose real production hangs like thread pool saturation. We also saw steady momentum in platform hygiene, from .NET 11 preview security hardening (including experimental DBSC) to CodeQL improvements and Azure Functions expanding managed connector triggers in public preview.