What changed in Azure, security and AI: week to 1 October 2026

Microsoft has pushed the retirement of Application Insights URL ping tests back to September 2028 and announced that Azure IoT Central retires in September 2029. Automatic zone placement for scale sets, and Microsoft Entra Kerberos for Azure NetApp Files, are now in preview.

By Tony Rough

  • what changed
  • retirements
  • AZ-305
  • AZ-104
  • SC-500

This is the first weekly round-up of what Microsoft changed in the areas the series covers, for the week from 24 September to 1 October 2026. This week there’s a retirement date that moved back, one new retirement and three previews worth knowing about. For each one we show where the books, the glossary and the study notes cover the subject.

The AZ-305 guide is free on Kindle from Friday 2 to Sunday 4 October. The details are here.

Retirements

Application Insights URL ping tests: retirement moved to 30 September 2028

URL ping tests in Application Insights were due to retire on 30 September 2026. Following customer feedback, Microsoft has extended this by 24 months to 30 September 2028, when any URL ping tests that remain are removed from your resources. Standard tests are still the replacement, so move to them before then. Microsoft Learn now has a procedure for finding your URL ping tests and creating matching standard tests. Note that standard tests are charged, and alert rules aren’t migrated for you.

Where we cover it: chapter 4, “Monitoring and observability”, of the AZ-305 guide; glossary: Availability tests, Application Insights.

We’ll reflect this in the next update of the AZ-305 guide.

Source: Azure Updates · Microsoft Learn: Application Insights availability tests

Azure IoT Central retires on 20 September 2029

Azure IoT Central will be retired on 20 September 2029. According to Microsoft Learn, you can no longer create new IoT Central applications from 23 September 2026, and existing applications keep working until 20 September 2029. Microsoft recommends Azure IoT Hub with the Device Provisioning Service (DPS) for connectivity, and Microsoft Fabric Real-Time Intelligence for dashboards and analytics. There’s a migration playbook for the move.

Where we cover it: chapter 8, “Data integration and analytics”, of the AZ-305 guide; glossary: IoT Central, IoT Hub, Microsoft Fabric.

Source: Azure Updates · Microsoft Learn: Azure IoT Central is evolving

In preview

Automatic zone placement for Virtual Machine Scale Sets

Announced on 29 September 2026 and now in public preview, automatic zone placement lets Azure choose the availability zones for a scale set. Instead of listing zones for each region, you state your placement rules and Azure picks zones based on capacity and SKU availability. By default it aims for an even spread across three zones, uses at least two, and puts no more than 50% of instances in any one zone. It works with both Uniform and Flexible orchestration, needs Compute API version 2026-03-01 or later and a preview feature registration, and only places new instances. It doesn’t move existing ones.

Where we cover it: chapter 8, “Virtual machines and scale sets”, of the AZ-104 guide and chapter 9, “Compute: virtual machines, App Service, Functions and HPC”, of the AZ-305 guide; study note: Availability sets vs availability zones; glossary: VM scale set, Availability zones.

Source: Azure Updates · Microsoft Learn: Configure automatic zone placement for a scale set (preview)

Auto-pause and auto-resume for Azure SQL Database Hyperscale serverless

Serverless Azure SQL Database Hyperscale databases can now pause automatically when idle and resume when activity returns. This is in public preview, announced on 29 September 2026. While a database is paused you pay for storage but not compute. In the preview the minimum auto-pause delay is 60 minutes (General Purpose allows 15), and named replicas aren’t supported. For generally available features, auto-pause is still a General Purpose feature, as the book says.

Where we cover it: chapter 6, “Relational databases: Azure SQL, MySQL and PostgreSQL”, of the AZ-305 guide; glossary: Serverless, Hyperscale.

Source: Azure Updates · Microsoft Learn: Auto-pause and auto-resume in the serverless compute tier

Microsoft Entra Kerberos for Azure NetApp Files SMB volumes

Azure NetApp Files SMB volumes can now use Microsoft Entra Kerberos authentication (public preview, announced 29 September 2026), for both hybrid and cloud-only identities. Clients no longer need network line of sight to AD DS domain controllers. Until now this was an Azure Files feature. It applies to SMB volumes only: NFS, dual-protocol and NFSv4.1 Kerberos volumes still need AD DS. A Standard NAT gateway is also required, so the service can reach Microsoft Graph.

Where we cover it: chapter 5, “Securing Azure Storage”, of the SC-500 guide and chapter 5, “Securing access to storage”, of the AZ-104 guide, both for Microsoft Entra Kerberos with Azure Files; chapter 5, “Azure Storage”, of the AZ-305 guide for Azure NetApp Files; glossary: Microsoft Entra Kerberos, Azure NetApp Files, SMB.

Source: Azure Updates · Microsoft Learn: Understand Microsoft Entra Kerberos with Azure NetApp Files (preview)

Every term above is explained in the series glossary. To get next week’s round-up, follow the RSS feed.

Tony Rough

The books in this post

More from the blog

All posts