What changed in Azure, security and AI: week to 8 October 2026

Microsoft has confirmed that Always Encrypted with Intel SGX enclaves in Azure SQL Database retires on 31 October 2027, and that App Service support for Java 8, 11 and 17 ends on 1 September 2027. Defender for Storage can now scan individual blobs and containers on demand, and Application Gateway WAF inspects IPv6 traffic in preview.

By Tony Rough

  • what changed
  • retirements
  • SC-500
  • AZ-305
  • AZ-700
  • DP-800
  • AZ-104
  • DP-600

This is the round-up of what Microsoft changed in the areas the series covers for the week from 1 to 8 October 2026. There are two retirements to plan for, one feature now generally available, three previews and one change to Fabric search that administrators should look at before 15 October. For each one we show where the books, the glossary and the study notes cover the subject.

The AZ-104 guide is free on Kindle from Friday 9 to Sunday 11 October. The details are here.

Retirements

Always Encrypted with Intel SGX enclaves retires on 31 October 2027

Always Encrypted with Intel SGX enclaves in Azure SQL Database retires on 31 October 2027, as support for SGX-enabled DC-series hardware is phased out. Microsoft Learn says that after that date Azure automatically moves any database still on the DC-series compute tier to a supported standard-series (non-DC) tier and enables virtualisation-based security (VBS) enclaves. To move before then, migrate to a standard-series tier, enable VBS enclaves (which need no attestation), update client drivers and remove the SGX attestation settings from connection strings. Microsoft also suggests SQL Server on confidential VMs as an alternative.

Where we cover it: chapter 7, “Encryption, masking, row-level security and permissions”, of the DP-800 guide, which already gives the 31 October 2027 date, and chapter 6, “Securing Azure SQL and open-source databases”, of the SC-500 guide; study notes: Always Encrypted in SQL Server and Azure SQL, Always Encrypted, TDE and dynamic data masking compared; glossary: Always Encrypted, Intel SGX, VBS, Secure enclave.

Source: Azure Updates · Microsoft Learn: Always Encrypted with Intel SGX enclaves migration guide

App Service support for Java 8, 11 and 17 ends on 1 September 2027

On 1 September 2027, App Service stops supporting Java 8, 11 and 17. Apps on those versions keep running, but they no longer get security updates or customer support. Microsoft’s announcement says to upgrade to Java 25 before that date. Under App Service’s language support policy, an app on an unsupported language version has to be upgraded before it can get App Service support.

Where we cover it: chapter 9, “Compute: virtual machines, App Service, Functions and HPC”, of the AZ-305 guide, for running Java SE, Tomcat and JBoss EAP apps on App Service, and chapter 10, “Azure App Service”, of the AZ-104 guide; glossary: App Service, JBoss EAP.

Source: Azure Updates · Microsoft Learn: Language runtime support policy for Azure App Service

Now generally available

Defender for Storage: on-demand malware scans of specific blobs, containers and file shares

Generally available since 5 October 2026, on-demand malware scanning in Microsoft Defender for Storage no longer has to scan the whole storage account. You can scope a scan to a single blob or file, one container or file share, or every object that matches a path prefix, using filters in the REST API request body. With no filters, the scan covers the whole account, as before. Only data that is actually scanned is charged for malware scanning, so a targeted scan is the cheaper way to re-check one object after an alert or retry a failed scan.

Where we cover it: chapter 14, “Managing security posture with Microsoft Defender for Cloud”, of the SC-500 guide, in the section on Defender for Storage malware scanning and response; glossary: Microsoft Defender for Storage.

Source: Defender for Cloud release notes · Microsoft Learn: On-demand malware scanning

In preview

Application Gateway WAF inspects IPv6 traffic

Web Application Firewall on Application Gateway now inspects and enforces rules on IPv6 traffic, in public preview since 5 October 2026. Managed rule sets, custom rules and diagnostics all apply to IPv6, so dual-stack applications get the same protection on both protocols. Geo-based custom rules for IPv6 need the AllowAppGwWafIpv6Geo preview feature registered. The gateway must be a dual-stack v2 deployment: an existing IPv4-only gateway can’t be converted, and IPv6-only gateways aren’t supported. Some Application Gateway IPv6 pages on Microsoft Learn still list IPv6 custom rules as unsupported; the WAF pages describe the preview.

Where we cover it: chapter 15, “Web Application Firewall”, and chapter 10, “Azure Application Gateway”, of the AZ-700 guide; chapter 12, “Networking”, of the AZ-305 guide; study note: Choosing an Azure load-balancing service; glossary: Web Application Firewall, WAF policy, Dual-stack, IPv6. There’s more on choosing between the load balancers in Load Balancer vs Application Gateway vs Front Door vs Traffic Manager.

Source: Azure Updates · Microsoft Learn: IPv6 geo-based custom rules for Azure Web Application Firewall (preview)

Azure Backup for PostgreSQL flexible server and elastic clusters (v2)

A new version of Azure Backup for Azure Database for PostgreSQL flexible server went into public preview on 5 October 2026. It takes physical backups from managed disk snapshots instead of logical pg_dump backups, and stores them in a Backup vault. Compared with the generally available v1, it protects elastic clusters as well as flexible servers, handles servers up to 32 TB on Premium SSD v1 and 64 TB on Premium SSD v2 (v1 stops at 1 TB), supports daily as well as weekly backups, and restores directly to a target server rather than to files. Retention runs from 7 days to 10 years. The preview needs PostgreSQL 15 or later on the General Purpose or Memory Optimized tier.

Where we cover it: chapter 15, “Backup and disaster recovery”, of the AZ-104 guide, for Backup vaults; chapter 6, “Relational databases: Azure SQL, MySQL and PostgreSQL”, of the AZ-305 guide, for flexible server and elastic clusters; glossary: Backup vault, Azure Database for PostgreSQL flexible server, Azure Backup.

Source: Azure Updates · Microsoft Learn: About Azure PostgreSQL flexible server and elastic cluster vaulted backup (v2) (preview)

A single server security experience in the Defender portal

On 6 October 2026, Microsoft put a new Defender server security experience into public preview. It brings Microsoft Defender for Endpoint and Microsoft Defender for Servers data together in the Microsoft Defender portal: one asset page per server with its cloud and endpoint details, investigation across alerts, incidents and the attack graph, and access controlled by role-based access control, device groups and cloud scopes. In the Azure portal, turning off Defender for Servers for a subscription can now offboard eligible servers from Defender for Endpoint automatically. Servers that already run Defender for Endpoint keep their configuration and don’t need re-onboarding.

Where we cover it: chapter 10, “Securing servers and virtual machines”, of the SC-500 guide, for the Defender for Servers plans and the Defender for Endpoint integration; glossary: Microsoft Defender for Servers, Microsoft Defender for Endpoint, Microsoft Defender portal.

Source: Defender for Cloud release notes · Microsoft Learn: The new Defender server security experience

Other changes

Fabric search will find tables from 15 October 2026

From 15 October 2026, search in Microsoft Fabric returns tables from semantic models, lakehouses and mirrored databases as results in their own right. You can search by table name or description, or by an exact column name. This applies to global search, the OneLake catalog, the Search API, the Fabric CLI and Fabric’s MCP servers. Who can find a table depends on permissions on the parent item, not on data-level permissions on the table: anyone with Read on the item can discover all its tables, even ones they can’t query, although search doesn’t give access to the data. Tables in semantic models protected by object-level security are left out. The tenant setting “Users can find objects in search” is on by default; turn it off if your organisation isn’t ready for this.

Where we cover it: chapter 7, “Getting data into Fabric: connections, OneLake catalog, shortcuts and ingestion”, and chapter 4, “Governance: sensitivity labels, endorsement, lineage and impact analysis”, of the DP-600 guide; glossary: OneLake catalog, Tenant settings, Semantic model, Lakehouse.

Source: Azure Updates · Microsoft Learn: Tenant settings index

Every term above is explained in the series glossary. To get next week’s round-up, follow the RSS feed.

Tony Rough

The books in this post

Never miss a free Kindle weekend

An email when an Ultra Transcenders book is free on Kindle, and when a new book comes out. Sign up and you also get the free exam-day checklist: booking, ID, the online check-in and what to expect on the day.

We'll email you to confirm first. A few emails a month at most, no spam, unsubscribe any time. The list is run by Kit; see the privacy notice.

More from the blog

All posts