Edit

Reliability recommendations

Azure Advisor helps you ensure and improve the continuity of your business-critical applications. You can get reliability recommendations on the Reliability tab on the Advisor dashboard.

  1. Sign in to the Azure portal.

  2. Search for and select Advisor from any page.

  3. On the Advisor dashboard, select the Reliability tab.

API Management

Review hostname certificate for errors

The API Management service failing to refresh the hostname certificate from the Key Vault can lead to the service using a stale certificate and runtime API traffic being blocked. Ensure that the certificate exists in the Key Vault, and the API Management service identity is granted secret read access.

Potential benefits: Ensure service availability

Impact: High

For more information, see Configure custom domain name for Azure API Management instance - Azure API Management

ResourceType: microsoft.apimanagement/service
Recommendation ID: 8962964c-a6d6-4c3d-918a-2777f7fbdca7
Subcategory: Other

Dependency network status check failed

Azure API Management service dependency not available. Please, check virtual network configuration.

Potential benefits: Improve service stability

Impact: High

For more information, see Deploy Azure API Management instance to external VNet

ResourceType: microsoft.apimanagement/service
Recommendation ID: 53fd1359-ace2-4712-911c-1fc420dd23e8
Subcategory: Other

Deploy your Azure API Management instance to multiple Azure regions to increase service availability

Azure API Management supports multi-region deployment, which enables you to add regional API gateways to your existing API Management instance. Multi-region deployment helps reduce request latency for geographically distributed API consumers and improves service availability.

Potential benefits: Increase service resilience and availability across regions.

Impact: High

For more information, see Deploy an Azure API Management Instance to Multiple Azure Regions - Azure API Management

ResourceType: microsoft.apimanagement/service
Recommendation ID: 2e4d65a3-1e77-4759-bcaa-13009484a97e

Enable and configure autoscale for API Management instance on production workloads.

API Management instance in production service tiers can be scaled by adding and removing units. The autoscaling feature can dynamically adjust the units of an API Management instance to accommodate a change in load without manual intervention.

Potential benefits: Increase scalability and optimize cost.

Impact: High

For more information, see Configure autoscale of an Azure API Management instance

ResourceType: microsoft.apimanagement/service
Recommendation ID: f4c48f42-74f2-41bf-bf99-14e2f9ea9ac9
Subcategory: Scalability

Migrate to TLS 1.2 or above for API Management

Support for TLS 1.0 and 1.1 on API Management is retiring. Update the TLS policy to the latest version.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.apimanagement/service
Recommendation ID: 18d79d0b-6a10-49f7-a0e4-f6b3b6f9c9b1

Built-in Analytics (API Management) is retiring

The analytics dashboards that are built in to Azure API Management are retiring. You need to transition to using the new Azure Monitor based dashboards that use Log Analytics workbooks.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.apimanagement/service
Recommendation ID: 4d793750-3bdf-42e0-aab0-7883c5e296ee

App Service Certificates

Domain verification required to issue your App Service Certificate

You have an App Service Certificate that's currently in a Pending Issuance status and requires domain verification. Failure to validate domain ownership will result in an unsuccessful certificate issuance. Domain verification isn't automated for App Service Certificates and will require action.

Potential benefits: Ensure successful issuance of App Service Certificate.

Impact: High

ResourceType: microsoft.certificateregistration/certificateorders
Recommendation ID: a2385343-200c-4eba-bbe2-9252d3f1d6ea

App Service

Verify contact information for App Service Domain

Verify the accuracy of the contact information for your App Service Domain immediately to avoid domain suspension.

Potential benefits: Prevent domain suspension.

Impact: High

For more information, see Buy a custom domain - Azure App Service

ResourceType: microsoft.domainregistration/domains
Recommendation ID: b9b84818-1e7c-45af-8918-a0d280911ca6
Subcategory: Other

Check your app's service health issues

We have a recommendation related to your app's service health. Open the Azure portal, go to the app, and select Diagnose and solve to see more details.

Potential benefits: Keep your app healthy

Impact: High

For more information, see Best practices for Azure App Service - Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: a85f5f1c-c01f-4926-84ec-700b7624af8c
Subcategory: Other

Fix application code, a worker process crashed due to an unhandled exception

A worker process in your application crashed due to an unhandled exception. To identify the root cause, collect memory dumps and call stack information at the time of the crash.

Potential benefits: Keep your app healthy and highly available

Impact: High

For more information, see Crash Monitoring in Azure App Service - Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: 3e35f804-52cb-4ebf-84d5-d15b3ab85dfc
Subcategory: Other

Consider changing your application architecture to 64-bit

Your App Service is configured as 32-bit, and its memory consumption is approaching the limit of 2 GB. If your application supports, consider recompiling your application and changing the App Service configuration to 64-bit instead.

Potential benefits: Improve your application reliability

Impact: Medium

For more information, see Application performance FAQs - Azure

ResourceType: microsoft.web/sites
Recommendation ID: 8be322ab-e38b-4391-a5f3-421f2270d825
Subcategory: Scalability

Consider upgrading the hosting plan of the Static Web App(s) in this subscription to Standard SKU.

The combined bandwidth used by all the Free SKU Static Web Apps in this subscription is exceeding the monthly limit of 100GB. Consider upgrading these applications to Standard SKU to avoid throttling.

Potential benefits: Higher availability for the apps by avoiding throttling.

Impact: High

For more information, see Pricing – Static Web Apps

ResourceType: microsoft.web/staticsites
Recommendation ID: dc3edeee-f0ab-44ae-b612-605a0a739612

Use Standard or Premium tier

Choose Standard or Premium Azure App Service Plan for robust apps with advanced scaling, high availability, better performance, and multiple slots, ensuring resilience and continuous operation.

Potential benefits: Enhanced scaling and reliability

Impact: High

For more information, see Resiliency checklist for services - Azure Architecture Center

ResourceType: microsoft.web/sites
Recommendation ID: dc298556-8232-4aa8-bfe0-5204c5017be0
Subcategory: HighAvailability

Set minimum instance count for App Service to 2

App Service should be configured with a minimum of two instances for production workloads. If apps have a longer warm-up time, a minimum of three instances should be used.

Potential benefits: Improve app performance

Impact: High

For more information, see Reliability in Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: e987dcce-fd2c-4683-8abf-f1a34bbad737
Subcategory: Scalability

Enable Health check for App Service

Use health check for production workloads. Health check increases the availability of the application by rerouting requests away from unhealthy instances and replacing instances if the instances remain unhealthy. The health check path should check critical components of the application.

Potential benefits: Enhanced reliability via automation

Impact: High

For more information, see Monitor the health of App Service instances - Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: 72063b96-92fa-4b74-9457-b84b662155f9
Subcategory: MonitoringAndAlerting

Migrate to zone-supported App Service Environment

Enable zoneRedundant in App Service Environment settings

Potential benefits: Increases uptime for App Service Environments

Impact: High

For more information, see App Service Environment Overview - Azure App Service Environment

ResourceType: microsoft.web/hostingenvironments
Recommendation ID: 96d638d0-3d41-418f-bf21-a75f193c2f6e
Subcategory: HighAvailability

Use zone-supported App Service Plan

Deploy App Service Plan with zoneRedundant set to true

Potential benefits: Keeps web apps running across zones

Impact: High

For more information, see Azure App Service Plans - Azure App Service

ResourceType: microsoft.web/serverfarms
Recommendation ID: fac3022a-eda5-44b9-b54d-cb500d1d01dd
Subcategory: HighAvailability

App Service Managed Certificates: trafficmanager.net domains are no longer supported

To meet updated compliance standards, DigiCert applies multi-perspective issuance corroboration for certificate validation. As a result, you cannot issue or renew App Service Managed Certificates for trafficmanager.net domains.

Potential benefits: Maintain HTTPS support under new validation rules.

Impact: High

For more information, see App Service Managed Certificate (ASMC) Changes – July 28, 2025 - Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: 7ca9b77c-53ea-402a-a1c9-085efd569ef4

Upgrade PHP to a newer, supported version

Extended support for PHP 8.1 is ending. Apps hosted on App Service continue to run. Future security updates aren't available. The platform no longer provides customer service for PHP 8.1.

Potential benefits: Continued support for applications on Azure App Service

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 42702f7a-06af-4cca-80b6-6b058e22b12f

Store configuration as app settings for Web Sites

Use app settings for configuration and define them in Resource Manager templates or via PowerShell to facilitate part of an automated deployment/update process for improved reliability.

Potential benefits: Enhanced reliability via automation

Impact: Medium

For more information, see Configure an App Service App - Azure App Service

ResourceType: microsoft.web/sites
Recommendation ID: b5666e83-63e6-420d-acd2-c1924f1f060e

Migrate to Flex Consumption

Migrate all workloads from Linux Consumption to Flex Consumption to maintain access to new features and avoid service disruptions.

Potential benefits: Avoid service disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 6f2c6ba6-3fd4-4786-af01-d10b127ee031

Upgrade Node.js for Azure Functions apps to version 22 or later

To avoid potential security vulnerabilities, reduce performance risks, and ensure Azure Functions apps take advantage of the newest features; upgrade Node.js to version 22 or later.

Potential benefits: Avoid potential security vulnerabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 81c8903e-2d50-4e57-9c3b-7049b5a9d0e8

Upgrade apps to Python 3.10

Extended support for Python 3.9 is retiring. Apps that are hosted on App Service will continue to run, but security updates and customer support will no longer be available

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 14f2b661-8b62-4e1e-9020-6ae63ce9e354

Durable Functions support for Netherite is ending

Opening new support cases that seek assistance for Netherite-enabled apps is blocked.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 3d5765c2-e25e-47ca-988a-cf11535a592d
Subcategory: ServiceUpgradeAndRetirement

Transition to native backup and restore tools

Azure App Service custom backup feature doesn't back up linked databases configured as part of the Azure App Service custom backup feature. Transition to native backup and restore tools available with the respective databases.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 271b07b4-c9f6-450a-ac0b-68124c0faa63

Upgrade Azure Functions apps to Python 3.13

In alignment with the end of community support, support for Python 3.10 in Azure Functions will end. Apps that are hosted on Functions will continue to run, but security updates and performance optimizations will no longer be available and we'll no longer provide customer service for Python 3.10.

Potential benefits: Avoid service interruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: b5ff4db4-4032-4380-a0fb-2db4f37b4027

Extended support for .NET 9 (STS) is ending

Applications hosted on App Service continue to run. Future security updates and customer service for .NET 9 (STS) aren't available.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 970c8068-7d7d-470f-93f1-0840d6f63ba2
Subcategory: ServiceUpgradeAndRetirement

Support for Python 3.9 is ending

Applications hosted on Azure Functions continue to run. Future security updates and performance optimizations are no longer available for Python 3.9.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: c62d7787-7595-4539-a837-9f9bcffac205
Subcategory: ServiceUpgradeAndRetirement

Migrate Python applications to Linux

Python applications hosted on Azure App Service on Windows and Azure Functions on Windows will no longer run. To avoid service disruption, migrate Python applications to Linux.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 7d26ab34-5f6a-495e-91e3-781a1c578c3f

Migrate apps to .NET 10 (LTS)

Support for .NET 8 (LTS) is ending. Apps that are hosted on App Service will continue to run, but security updates will no longer be available. To avoid potential security vulnerabilities and minimize risk for App Service apps, upgrade apps to .NET 10 (LTS).

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 55a560ff-1039-4a49-b6da-6f272dc52db6

Upgrade PHP 8.2 app to newer version

Extended support for PHP 8.2 is ending. Apps hosted on App Service continue to run. Future security updates are no longer available. The platform no longer provides customer service for PHP 8.2.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 18745007-438b-4c68-bfa3-b6576d85a831

Community support for Node 20 LTS is ending, so the platform is retiring support on App Service

Extended support for Node 20 LTS is ending. The apps hosted on App Service continue to run, but security updates are no longer available and the platform no longer provides customer service for Node 20 LTS.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: dcf3c6e4-27b3-44d4-9b70-bb9e18a7184a

Extended support for Node 18 LTS is ending

Extended support for Node 18 LTS is ending. Apps hosted on App Service continue to run. Future security updates are no longer available. The platform no longer provides customer service for Node 18 LTS.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 060218a1-bf04-43a9-a967-2a507b69904b

In-process model is being retired

The platform no longer supports the in-process model for .NET apps in Azure Functions. To ensure that your apps that use this model continue being supported, you need to transition to the isolated worker model by that date.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 154820bc-8d6f-44c8-b9ad-c214f16968ad

Migrate to Static Web Apps Standard pricing plan or to Azure Container Apps

The Static Web Apps Dedicated pricing plan is retiring. Migrate deployments that use the Dedicated pricing plan to the Static Web Apps Standard pricing plan or to Azure Container Apps.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure Static Web Apps hosting plans

ResourceType: microsoft.web/staticsites
Recommendation ID: 92b2f593-b118-4655-9dcb-20137b13f790

Migrate to TLS 1.2 or later for App Service

App Service will no longer accept connections using TLS 1.0 or TLS 1.1. Any client, application, or service that continues to use these legacy TLS versions will be unable to connect to these services. Migrate to TLS 1.2 or later.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 4bf50b72-9c8d-48cb-b78a-b9bc8acdaba7

Migrate to TLS 1.2 or later for Functions

Functions will no longer accept connections using TLS 1.0 or TLS 1.1. Any client, application, or service that continues to use these legacy TLS versions will be unable to connect to these services. Migrate to TLS 1.2 or later.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: de15ab5e-80bd-405f-a709-47cb3e8c7819

Migrate to TLS 1.2 or later for Logic Apps

Logic Apps will no longer accept connections using TLS 1.0 or TLS 1.1. Any client, application, or service that continues to use these legacy TLS versions will be unable to connect to these services. Migrate to TLS 1.2 or later.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 969227e6-d5c5-40db-9f4c-44f526a1cf26

Upgrade App Service apps to Python 3.11

Extended support for Python 3.10 is retiring. Apps that are hosted on App Service will continue to run, but security updates and customer support won't be available.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: bf624ee9-0fd3-4802-b7fa-99b171d2898e

Version 1.x runtime is retiring

Support for version 1.x of the Azure Functions runtime is ending.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.web/sites
Recommendation ID: 6e427a59-6f55-474a-8104-0ef6fe48059c

Application Gateway

Change subnet of V1 gateway as the current subnet contains a NAT gateway

Your Application Gateway may be deleted after October 2024 due to a failed internal upgrade. This is because it lacks a dedicated subnet and contains a NAT Gateway. To resolve, either change the subnet, remove the NAT Gateway, or migrate to V2. Allow a day for the message to disappear once fixed

Potential benefits: Avoid disruption in management of Application Gateway V1 resource

Impact: High

For more information, see Frequently asked questions about Application Gateway

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 511a9f7b-7b5e-4713-b18d-0b7464a84d1f

Update VNet permission of Application Gateway users

To improve security and provide a more consistent experience across Azure, all users must pass a permission check to create or update an Application Gateway in a Virtual Network. The users or service principals minimum permission required is Microsoft.Network/virtualNetworks/subnets/join/action.

Potential benefits: Ensure access to Application Gateway V1 resource management.

Impact: High

For more information, see Azure Application Gateway infrastructure configuration

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 6cc8be07-8c03-4bd7-ad9b-c2985b261e01

Change subnet of V1 gateway named GatewaySubnet as it's reserved for VPN/Express Route

Your Application Gateway is at risk of deletion after October 2024 due to a failed internal upgrade. This is due to subnet named Gatewaysubnet, which is reserved for VPN/ExpressRoute. To resolve, please change the subnet or migrate to V2. Allow a day for the message to disappear once fixed

Potential benefits: Ensure access to Application Gateway V1 resource management.

Impact: High

For more information, see Frequently asked questions about Application Gateway

ResourceType: microsoft.network/applicationgateways
Recommendation ID: df989782-82d1-420d-b354-71956bd9379c

Use managed TLS certificates

When Front Door manages your TLS certificates, it reduces your operational costs, and helps you to avoid costly outages caused by forgetting to renew a certificate. Front Door automatically issues and rotates the managed TLS certificates.

Potential benefits: Ensure service availability by having Front Door manage and rotate your certificates

Impact: Medium

For more information, see Azure Front Door - Best practices

ResourceType: microsoft.network/frontdoors
Recommendation ID: 5185d64e-46fd-4ed2-8633-6d81f5e3ca59
Subcategory: Other

Consider having at least two origins

Multiple origins support redundancy by distributing traffic across multiple instances of the application. If one instance is unavailable, then other backend origins can still receive traffic.

Potential benefits: Increase your workload resiliency

Impact: High

For more information, see Azure Well-Architected Framework perspective on Azure Front Door - Microsoft Azure Well-Architected Framework

ResourceType: microsoft.network/frontdoors
Recommendation ID: 589ab0b0-1362-44fd-8551-0e7847767600
Subcategory: HighAvailability

Use the same domain name on Front Door and your origin

When you rewrite the Host header, request cookies and URL redirections might break. When you use platforms like Azure App Service, features like session affinity and authentication and authorization might not work correctly. Make sure to validate whether your application is going to work correctly.

Potential benefits: Ensure application integrity by preserving original host name

Impact: Medium

For more information, see Azure Front Door - Best practices

ResourceType: microsoft.network/frontdoors
Recommendation ID: 79f543f9-60e6-4ef6-ae42-2095f6149cba
Subcategory: Other

Avoid placing Traffic Manager behind Front Door

Using Traffic Manager as one of the origins for Front Door isn't recommended, as this can lead to routing issues. If you need both services in a high availability architecture, always place Traffic Manager in front of Azure Front Door.

Potential benefits: Increase your workload resiliency

Impact: Medium

For more information, see Best practices for Front Door

Resolve issues for private endpoint not in succeeded state

Private Endpoint not in a succeeded state potentially influences application availability and reliability. Healthy state of connectivity over private endpoints is crucial to reliably and securely access resources. Troubleshoot and resolve issues that cause a failed state.

Potential benefits: Resume private connectivity and availability of application

Impact: Medium

For more information, see Troubleshoot Azure Private Link Service connectivity problems

ResourceType: microsoft.network/privateendpoints
Recommendation ID: 5db013ba-e657-4b80-93f7-8c5b5f9e780a
Subcategory: BusinessContinuity

Add endpoint

Profiles need more than one endpoint to ensure availability if one of the endpoints fails. We also recommend that endpoints be in different regions.

Potential benefits: Improve resiliency by allowing failover

Impact: Medium

For more information, see Traffic Manager Endpoint Types

ResourceType: microsoft.network/trafficmanagerprofiles
Recommendation ID: 6cd70072-c45c-4716-bf7b-b35c18e46e72

Add endpoint

For geographic routing, traffic is routed to endpoints in defined regions. When a region fails, there is no pre-defined failover. Having an endpoint where the Regional Grouping is configured to All (World) for geographic profiles avoids traffic black holing and guarantees service availability.

Potential benefits: Improve resiliency by avoiding traffic black holes

Impact: High

For more information, see Manage endpoints in Azure Traffic Manager

ResourceType: microsoft.network/trafficmanagerprofiles
Recommendation ID: 0bbe0a49-3c63-49d3-ab4a-aa24198f03f7

ExpressRoute IP routes nearing specified limit

Your ExpressRoute circuit is close to reaching its IP route limits. Exceeding these limits will disrupt the connectivity. Connectivity will restore once routes are within limit. Suggestions: Regularly monitor route counts. Explore Virtual WAN RouteMap to reduce advertised IP routes.

Potential benefits: Prevent connectivity issues and ensure stability

Impact: High

For more information, see Azure Virtual WAN FAQ

ResourceType: microsoft.network/virtualhubs
Recommendation ID: e3489565-d891-406e-91d1-44f476563850

Enable Active-Active gateways for redundancy

In active-active configuration, both instances of the VPN gateway establish site-to-site (S2S) VPN tunnels to your on-premise VPN device. When a planned maintenance or unplanned event happens to one gateway instance, traffic is automatically switched over to the other active IPsec tunnel.

Potential benefits: Ensure business continuity through connection resilience

Impact: Medium

For more information, see Design highly available gateway connectivity - Azure VPN Gateway

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: c249dc0e-9a17-423e-838a-d72719e8c5dd
Subcategory: BusinessContinuity

Implement Site Resiliency for ExpressRoute

To ensure maximum resiliency, the platform recommends connecting to two ExpressRoute circuits in two peering locations. The goal of maximum resiliency is to enhance availability and ensure the highest level of resilience for critical workloads.

Potential benefits: Improve ExpressRoute uptime with Site Resilient Connectivity

Impact: High

For more information, see Design and architect Azure ExpressRoute for resiliency

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: 8d61a7d4-5405-4f43-81e3-8c6239b844a6
Subcategory: HighAvailability

Implement Zone Redundant ExpressRoute Gateways

Implement zone-redundant Virtual Network Gateway in Azure Availability Zones. This brings resiliency, scalability, and higher availability to your Virtual Network Gateways.

Potential benefits: Provides zonal resiliency and redundancy for ExpressRoute

Impact: High

For more information, see Create a zone-redundant virtual network gateway in Azure availability zones - Azure VPN Gateway

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: c9af1ef6-55bc-48af-bfe4-2c80490159f8

Use NAT gateway for outbound connectivity

Prevent outbound connectivity failures due to source network address translation (SNAT) port exhaustion by using a zone‑redundant Standard V2 NAT gateway. Standard V2 NAT gateway scales dynamically, offers native zone redundancy, and improved reliability for outbound internet traffic.

Potential benefits: Prevent outbound connection failures with NAT gateway

Impact: Medium

For more information, see What Is Azure NAT Gateway?

ResourceType: microsoft.network/virtualnetworks
Recommendation ID: 56f0c458-521d-4b8b-a704-c0a099483d19

Use a health probe for monitoring the health of servers

Use an Application Gateway health probe to monitor backend pool server health. Application Gateway health probes prevent traffic being sent to unhealthy servers.

Potential benefits: Prevent sending traffic to unhealthy server.

Impact: High

For more information, see Health monitoring overview for Azure Application Gateway

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 01c0dcd3-d6f7-4d50-a98b-4e15f9486a32

Deploying zone-redundant virtual network gateways across availability zones ensures zone-resiliency, improving access to mission-critical, scalable services on Azure.

Potential benefits: Improved availability and reliability

Impact: High

For more information, see About zone-redundant virtual network gateway in Azure availability zones - Azure VPN Gateway

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: 1afa00b3-bb4c-496d-99e5-b7bda59a057c
Subcategory: HighAvailability

Deploy Azure Firewall across multiple availability zones

Azure Firewall SLAs vary by deployment type such as single or multiple availability zones to improve reliability and performance.

Potential benefits: Enhanced SLA and reliability

Impact: High

For more information, see Deploy Azure Firewall with Availability Zones using PowerShell

ResourceType: microsoft.network/azurefirewalls
Recommendation ID: e82f5b61-b0f8-48e7-8e18-5aa1f57bff81
Subcategory: HighAvailability

Standard Load Balancers and related resources configured to use availability zones offer resilience to zone faults. Assigning a zone-redundant frontend IP to a Standard Load Balancer ensures continuous traffic distribution even if one availability zone fails.

Potential benefits: Improved availability and reliability

Impact: High

For more information, see Reliability in Azure Load Balancer

ResourceType: microsoft.network/loadbalancers
Recommendation ID: 796b9be0-487d-4daa-8771-f08e4d7c9c0c
Subcategory: HighAvailability

Ensure backend pools contain at least two instances

Deploying Azure Load Balancer backend pools with at least two instances prevents a single point of failure. Pairing with Virtual Machine Scale Sets can provide additional scalability.

Potential benefits: Enhanced reliability and scalability

Impact: High

For more information, see Resiliency checklist for services - Azure Architecture Center

ResourceType: microsoft.network/loadbalancers
Recommendation ID: 5b132ebc-bd86-46fc-b2ee-95bc3e2d3017
Subcategory: HighAvailability

Standard Public IP addresses and related resources configured to use availability zones offer resilience to zone faults. Zone-aligned resources, or resources all in the same zone, offer isolation protection from faults in other zones.

Potential benefits: Improved uptime and application availability.

Impact: High

For more information, see Public IP addresses in Azure - Azure Virtual Network

ResourceType: microsoft.network/publicipaddresses
Recommendation ID: bc45d55d-3902-4505-8e34-ef8777bc6177
Subcategory: HighAvailability

Configure a maintenance configuration

Configure a maintenance configuration to avoid upgrades during important service hours.

Potential benefits: Improve reliability during important service hours.

Impact: Low

For more information, see Configure customer-controlled maintenance for your virtual network gateway - ExpressRoute

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: b4af9e04-3570-41f1-b4cf-b7af07224799
Subcategory: BusinessContinuity

Use Standard SKU with zone-redundant IP addresses

Use Standard SKU and deploy across three or more zones.

Potential benefits: Ensures IP availability during zone failures

Impact: High

For more information, see Azure Public IP address prefix - Azure Virtual Network

ResourceType: microsoft.network/publicipprefixes
Recommendation ID: cdf6b706-a12c-4b65-96b6-00cb125b7c26
Subcategory: HighAvailability

Traffic Manager monitor status should be online

Monitor status should be online to ensure failover for application workload. If Traffic Manager's health shows degraded, one or more endpoints may also be degraded.

Potential benefits: Ensures failover functionality

Impact: High

For more information, see Azure Traffic Manager endpoint monitoring

ResourceType: microsoft.network/trafficmanagerprofiles
Recommendation ID: 20f2ff6a-3940-4cc9-8f14-909466c4ddd0

Monitor health for Virtual WAN point-to-site VPN gateways

Configure monitoring and alerts for point-to-site VPN gateways. Create alert rule to ensure prompt response for critical events including gateway over utilization, connection count limits, and user VPN route limits. Mission Critical workloads should use dual express routes instead of VPN.

Potential benefits: Proactively detect and mitigate disruptions

Impact: High

For more information, see Monitor Azure Virtual WAN

ResourceType: microsoft.network/p2svpngateways
Recommendation ID: 80415aba-c979-4199-b093-873d3a31fec0

Use version-less Key Vault secret identifier to reference the certificates

To allow your application gateway resource to automatically retrieve a new certificate version, we strongly recommend using a version-less secret identifier, whenever available. For example: https://myvault.vault.azure.net/secrets/mysecret/

Potential benefits: Ensure auto-rotation for new certificate versions

Impact: High

For more information, see TLS termination with Azure Key Vault certificates

ResourceType: microsoft.network/applicationgateways
Recommendation ID: c7b5d99f-9759-4a04-9e86-ff6a41e0902f

Standard and High-Performance VPN Gateway SKUs are being retired

Basic SKU public IP addresses are retiring. The Standard and High-Performance SKUs that only accept Basic SKU public IP addresses are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: 96e232d0-9b01-4e96-8c24-f9160ba3535a

Monitor changes in Route Tables with Azure Monitor

Create Alerts with Azure Monitor for operations like Create or Update Route Table to spot unauthorized and undesired changes in production resources. This setup aids in identifying improper routing changes, including efforts to evade firewalls or access resources from outside.

Potential benefits: Enhanced security and change detection

Impact: Medium

For more information, see Azure Monitor activity log - Azure Monitor

ResourceType: microsoft.network/routetables
Recommendation ID: 830e326a-d280-4d4e-887a-884d7d8994ce

Migrate to TLS 1.2 or above for Application Gateway

Support for TLS 1.0 and 1.1 on Azure Application Gateway is retiring. Update the TLS policy for Application Gateway to the latest version.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.network/applicationgateways
Recommendation ID: a7ecaaaa-dc86-444b-8aad-e0773d5c2324

Migrate to virtual network flow logs

Network security group (NSG) flow logs in Azure Network Watcher is retiring. As part of this retirement, customers will no longer be able to create new NSG flow logs. Migrate to virtual network flow logs in Network Watcher.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.network/networkwatchers/flowlogs
Recommendation ID: 954daefb-e247-4e27-85c6-a212f9df5a53

Deploy Application Gateway in a zone-redundant configuration

Deploy Application Gateway in a zone-redundant configuration to ensure continued customer access to services. If a specific zone goes offline, services in other zones remain available.

Potential benefits: Enhanced uptime and customer access.

Impact: High

For more information, see Architecture Best Practices for Azure Application Gateway v2 - Microsoft Azure Well-Architected Framework

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 6012b4f4-b19a-4d6e-ae25-4289c228428e

Use Zone-Redundant NAT Gateway configuration to reduce outages

Deploy a zone-redundant StandardV2 NAT Gateway configuration

Potential benefits: Outbound traffic remains operational even if one zone fails

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.network/natgateways
Recommendation ID: 374b21de-e7ec-409a-9961-93e789e27536

Migrate Inbound NAT Pools to Inbound NAT rules v2 on Load Balancer

Inbound NAT Pools on Azure Load Balancer are retiring on September 30, 2027. Migrate to Inbound NAT Rules v2 to ensure continued port forwarding functionality, simplified management, and seamless scaling for virtual machine scale sets.

Potential benefits: Avoid service disruption from NAT Pool retirement

Impact: Medium

For more information, see Migrate from Inbound NAT rules version 1 to version 2

ResourceType: microsoft.network/loadbalancers
Recommendation ID: 1e97d137-7812-474d-af09-6d5b3e2a1508

Application Gateway V1 is being retired.

The platform encourages you to switch to Application Gateway V2 to avoid potential disruptions.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.network/applicationgateways
Recommendation ID: a62f1141-8da0-4e23-a953-eaaa7b8bc475

Application Gateway Web Application Firewall v2 configuration is retiring

To continue using the service, migrate to Application Gateway WAF v2 Policy before the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: Medium

For more information, see Upgrade to Azure Application Gateway WAF Policy

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 13d4b9e9-e144-4fa6-8d03-38b1c9f2b4a3

Azure Basic Load Balancer is retiring

To keep the workloads appropriately distributed, upgrade to Standard Load Balancer.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.network/loadbalancers
Recommendation ID: 332e07de-da0d-4ee7-b1c4-ca9016005e1d

Basic SKU retirement

If you have any Basic SKU public IP addresses deployed in Azure Cloud Services (extended support), those deployments aren't affected by this retirement and you don't need to take any action for them.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.network/publicipaddresses
Recommendation ID: 557fc33a-46a3-4688-9f09-0aa6ae3d38d7

Classic (Azure Front Door) is being retired

Classic (Azure Front Door) is being retired. Migrate to Front Door Standard or Premium.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.network/frontdoorwebapplicationfirewallpolicies
Recommendation ID: f0d2449d-99ce-4037-86b4-a1e1ace2a6ff

Manual VPN clients for point-to-site connections with Microsoft Entra ID authentication are retiring

To improve security, the platform only supports Microsoft-registered VPN clients for point-to-site connections with Microsoft Entra ID authentication.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: 666322e5-95e9-4ac4-8c5d-9323f0052b18

VpnGw1-5 (non-availability zone SKUs) is retiring

Due to the lack of redundancy, lower availability, and potential higher costs associated with other failover solution; the platform is transitioning all SKUs without availability zones to SKUs with availability zones.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: 4d9ee0c5-6fbd-41d3-864f-b9251c92eebc

Automation

Best Practices (Azure Automanage) are being retired

Best Practices (Azure Automanage) are being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.automation/automationaccounts
Recommendation ID: d63e646e-752a-40c0-aa76-b744a6b6949a

Migrate to a supported language and runtime version from Python 2.7 and 3.8, and PowerShell 7.1 and 7.2.

Language support for Python 2.7 and 3.8, and PowerShell 7.1 and 7.2 is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Language runtime support and retirement policy for Azure Automation

ResourceType: microsoft.automation/automationaccounts
Recommendation ID: 8f80e730-c8be-4636-907a-24eb220befed

State Configuration (DSC) retirement

Azure Automation State Configuration is retiring. Transition to Azure Machine Configuration.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.automation/automationaccounts
Recommendation ID: 3a7dee11-21b2-42fc-abab-63225f751033

Create a Standard search service (2GB)

When you exceed your storage quota, indexing operations stop working. You're close to exceeding your storage quota of 2GB. If you need more storage, create a Standard search service or add extra partitions.

Potential benefits: capability to handle more data

Impact: Medium

For more information, see Service limits for tiers and skus - Azure AI Search

ResourceType: microsoft.search/searchservices
Recommendation ID: 97b38421-f88c-4db0-b397-b2d81eff6630
Subcategory: Scalability

Create a Standard search service (50MB)

When you exceed your storage quota, indexing operations stop working. You're close to exceeding your storage quota of 50MB. To maintain operations, create a Basic or Standard search service.

Potential benefits: capability to handle more data

Impact: Medium

For more information, see Service limits for tiers and skus - Azure AI Search

ResourceType: microsoft.search/searchservices
Recommendation ID: 8d31f25f-31a9-4267-b817-20ee44f88069
Subcategory: Scalability

Avoid exceeding your available storage quota by adding more partitions

When you exceed your storage quota, you can still query, but indexing operations stop working. You're close to exceeding your available storage quota. If you need more storage, add extra partitions.

Potential benefits: Able to index additional data

Impact: Medium

For more information, see Service limits for tiers and skus - Azure AI Search

ResourceType: microsoft.search/searchservices
Recommendation ID: b3efb46f-6d30-4201-98de-6492c1f8f10d
Subcategory: Scalability

Upgrade to the newest version of the listQueryKeys request

Upgrade to the newest version of the Search/searchServices/mysearchservice/listQueryKeys request. The platform identified resources under the subscription using an outdated version of the Search/searchServices/mysearchservice/listQueryKeys request.

Potential benefits: Improved security.

Impact: Medium

For more information, see Query Keys - List By Search Service - REST API (Azure Search Management)

ResourceType: microsoft.search/searchservices
Recommendation ID: e24f566a-0ea9-4a6b-94c5-be0a73f251c8
Subcategory: ServiceUpgradeAndRetirement

Add a replica for Azure AI Search. Instance of Azure AI Search isn't covered by service-level agreement. In Azure AI Search, a replica is a copy of the index. Adding replicas allows Azure AI Search to do machine reboots and maintenance against one replica, while a query runs on another replica.

Potential benefits: Improve reliability of Azure AI Search instance.

Impact: Medium

For more information, see Reliability in Azure AI Search - Azure AI Search

ResourceType: microsoft.search/searchservices
Recommendation ID: 98acf571-d0a4-4111-993c-829f91b8c71b
Subcategory: HighAvailability

Azure Arc-enabled Kubernetes Configuration

Upcoming Breaking Changes for Microsoft Flux Extension

The Microsoft Flux extension frequently receives updates for security and stability. The upcoming update, in line with the OSS Flux Project, modifies the HelmRelease and HelmChart APIs by removing deprecated fields. To avoid disruption to workloads, necessary action is needed.

Potential benefits: Improved stability, security, and new functionality

Impact: High

For more information, see Available extensions for Azure Arc-enabled Kubernetes clusters - Azure Arc

ResourceType: microsoft.kubernetesconfiguration/extensions
Recommendation ID: 79cfad72-9b6d-4215-922d-7df77e1ea3bb

Migrate to Azure Container Apps on Arc-enabled Kubernetes

Azure App Service on Azure Arc-enabled Kubernetes is retiring. Installation of the Application Services extension is no longer available.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.kubernetesconfiguration/extensions
Recommendation ID: 51b9ef93-332d-4438-b1ba-851a6eae2e67

Azure Arc-enabled Kubernetes

Upgrade to the latest agent version of Azure Arc-enabled Kubernetes

For the best Azure Arc enabled Kubernetes experience, improved stability and new functionality, upgrade to the latest agent version.

Potential benefits: Arc-enabled K8s latest agent version

Impact: Medium

For more information, see Upgrade Azure Arc-enabled Kubernetes agents - Azure Arc

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: 6d55ea5b-6e80-4313-9b80-83d384667eaa
Subcategory: ServiceUpgradeAndRetirement

Migrate to Azure Kubernetes Service on Azure Local

Migrate to Azure Kubernetes Service on Azure Local for enhanced capabilities. The platform recommends migrating to Azure Kubernetes Service on Azure Local for improved features.

Potential benefits: Avoid service disruptions and loss of support

Impact: High

For more information, see Azure updates

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: 7e161911-fa97-4d8c-88a0-d7c4b9432eb0

Upgrade to a supported version of Windows Server

Windows Server 2022 image support is retiring, upgrade to the latest version to take advantage of the fixes, improvements, and new functionality.

Potential benefits: Take advantage of fixes, improvements, and new functionality

Impact: High

For more information, see Azure updates

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: 988cb7a5-1439-41f5-a07a-a71de67827b5

Migrate to Azure Kubernetes Service on Azure Local v23H2

Azure Kubernetes Service's current architecture on Windows Server 2019 and Windows Server 2022 is retiring. Replace existing Azure Kubernetes Service clusters on Windows Server 2019, Windows Server 2022 or Azure Local, version 22H2 with Azure Kubernetes Service on Azure Local, version 23H2 or later.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: ee99b379-18e9-467c-9b91-2bc8925fa45b

Azure Kubernetes Service on Windows Server 2019 and Windows Server 2022 is retiring

You can't deploy, upgrade, or scale Azure Kubernetes Service on Windows Server 2019 and Windows Server 2022.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: 21cd3357-484c-40e7-9714-ec74661c96c5

Open Service Mesh (Azure Kubernetes Service) add-on is being retired

Open Service Mesh (Azure Kubernetes Service) add-on is being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: eca2a85b-2fe3-4b16-b5f5-35acebb15830

Windows Server 2019 on AKS hybrid is being retired

Windows Server 2019 on AKS hybrid is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Announcing the 3-year retirement of Windows Server 2019 on AKS and AKS hybrid

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: a61b0026-fe7a-49d9-8dbb-91fec640dee6

Azure Arc-enabled servers

Upgrade the Azure Connected Machine agent

The Azure Connected Machine agent is updated regularly with bug fixes, stability enhancements, and new functionality. For the best Azure Arc experience, upgrade your agent to the latest version.

Potential benefits: Improved stability and new functionality

Impact: Medium

For more information, see Managing the Azure Connected Machine agent - Azure Arc

ResourceType: microsoft.hybridcompute/machines
Recommendation ID: 9d5717d2-4708-4e3f-bdda-93b3e6f1715b
Subcategory: Other

Migrate from Dependency Agent and VM Insights Map

Dependency Agent and VM Insights Map are retiring. To continue collecting data about processes running on virtual machines and external process dependencies, consider a replacement solution from the Azure Marketplace.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see VM Insights Map and Dependency Agent retirement guidance - Azure Monitor

ResourceType: microsoft.hybridcompute/machines
Recommendation ID: a8ffbd6c-08e0-4a66-b1d5-249719ab9899

Azure Cache for Redis

Increase fragmentation memory reservation

Fragmentation and memory pressure can cause availability incidents. To help in reduce cache failures when running under high memory pressure, increase reservation of memory for fragmentation through the maxfragmentationmemory-reserved setting available in the Advanced Settings options.

Potential benefits: Avoid availability incidents when your cache has high memory fragmentation

Impact: Medium

For more information, see How to configure Azure Cache for Redis - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: 7c380315-6ad9-4fb2-8930-a8aeb1d6241b
Subcategory: Other

Configure geo-replication for Cache for Redis instances to increase durability of applications

Geo-Replication enables disaster recovery for cached data, even in the unlikely event of a widespread regional failure. This can be essential for mission-critical applications. We recommend that you configure passive geo-replication for Premium Azure Cache for Redis instances.

Potential benefits: Geo-Replication enables disaster recovery for cached data.

Impact: High

For more information, see Configure passive geo-replication for Premium Azure Cache for Redis instances - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: c9e4a27c-79e6-4e4c-904f-b6612b6cd892

Enable zone redundancy for Redis

Enable multi-node replication configuration across Availability Zones, with automatic failover

Potential benefits: Reduces outage risk; 99.9% uptime for Premium cache

Impact: High

For more information, see What is Azure Cache for Redis? - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: 1a0a309c-54f0-4cb0-a839-2cee5912ba62
Subcategory: HighAvailability

Use Enterprise SKU with zone redundancy

Select Zone Redundancy in portal or ARM template

Potential benefits: Reduces outage risk; 99.9% uptime for Enterprise cache

Impact: High

For more information, see What is Azure Cache for Redis? - Azure Cache for Redis

ResourceType: microsoft.cache/redisenterprise
Recommendation ID: 08cff11d-aa10-44a1-a92f-a76a19e63f7d
Subcategory: HighAvailability

Migrate to Azure Managed Redis from Azure Cache for Redis

To avoid service disruptions, migrate workloads to Azure Managed Redis before the retirement date.

Potential benefits: Avoid service disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cache/redis
Recommendation ID: f3aded79-f9ff-4ce4-99e3-2ffcf11161a4

Migrate to Azure Managed Redis from Azure Cache for Redis Enterprise

To avoid service disruptions, migrate workloads to Azure Managed Redis before the retirement date.

Potential benefits: Avoid service disruptions and ensure continued support

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cache/redisenterprise
Recommendation ID: b498df1b-749b-4fdb-a7a1-28551cef6a82

Azure Communication Services

Prepare for Azure Communication Services breaking changes and service retirement by September 30, 2028

Your resources are using services that will be retired or experience breaking changes effective September 30, 2028. Services with breaking changes will require integration with Microsoft Teams aligned services for continued support. Retired services will be completely removed from availability.

Potential benefits: Action is required before September 30, 2028, to avoid disruption.

Impact: Medium

For more information, see Retirement and breaking changes guide for Azure Communication Services.

ResourceType: microsoft.communication/communicationservices
Recommendation ID: 71c92f71-e32f-40c1-abe5-deb2dbfc2c45

Azure Container Apps

Renew custom domain certificate

The custom domain certificate you uploaded is near expiration. To prevent possible service downtime, renew your certificate and upload the new certificate for your container apps.

Potential benefits: Your service wont fail because of expired certificate.

Impact: Medium

For more information, see Custom domain names and certificates in Azure Container Apps

ResourceType: microsoft.app/containerapps
Recommendation ID: b9ce2d2e-554b-4391-8ebc-91c570602b04
Subcategory: Other

An issue has been detected that is preventing the renewal of your Managed Certificate.

The managed certificate used by the Container App didn't renew automatically. Check the DNS settings for your custom domain to ensure they're correct.

Potential benefits: Avoid downtime due to an expired certificate.

Impact: High

For more information, see Custom domain names and free managed certificates in Azure Container Apps

ResourceType: microsoft.app/containerapps
Recommendation ID: fa6c0880-da2e-42fd-9cb3-e1267ec5b5c2
Subcategory: Other

Increase the minimal replica count for your containerized application

The minimal replica count set for your Azure Container App containerized application might be too low, which can cause resilience, scalability, and load balancing issues. For better availability, consider increasing the minimal replica count.

Potential benefits: Better availability for your container app.

Impact: Medium

For more information, see Scaling in Azure Container Apps

ResourceType: microsoft.app/containerapps
Recommendation ID: 9be5f344-6fa5-4abc-a1f2-61ae6192a075
Subcategory: HighAvailability

Re-create your your Container Apps environment to avoid DNS issues

There's a potential networking issue with your Container Apps environments that might cause DNS issues. We recommend that you create a new Container Apps environment, re-create your Container Apps in the new environment, and delete the old Container Apps environment.

Potential benefits: Avoid DNS failures in your Container Apps Environment.

Impact: High

For more information, see Quickstart: Deploy your first container app using the Azure portal

ResourceType: microsoft.app/managedenvironments
Recommendation ID: c692e862-953b-49fe-9c51-e5d2792c1cc1
Subcategory: Other

Enable zone redundancy for the managed environment

To maximize high availability, deploy application replicas across multiple zones within the region. Traffic is automatically distributed among these zones. For optimal resiliency, configure at least three application replicas and ensure the workload profile node count is at least three.

Potential benefits: Protect apps & data from data center failures

Impact: High

ResourceType: microsoft.app/managedenvironments
Recommendation ID: b7e00078-7703-4a0a-afac-1b403803ba62
Subcategory: HighAvailability

Migrate away from Service Connector (preview) on Azure Container Apps

Support for Service Connector (preview) on Azure Container Apps is ending. Creation of new service connections using Service Connector (preview) through any interface is blocked.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.app/containerapps
Recommendation ID: ce97546e-2d8f-4534-99dd-c5bbb584d568

The public preview add-ons feature in Container Apps are being retired

Container Apps running add-ons are going to be deleted along with associated application data. Transition to Azure-managed services, such as Azure Cache for Redis or Azure Database for PostgreSQL if you're ready to use a production-level service.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.app/containerapps
Recommendation ID: 632a1d5b-bce5-46d7-a059-f4476b40f932
Subcategory: ServiceUpgradeAndRetirement

Transition to Azure managed services or open-source quick starts

The public preview add-ons feature in Azure Container Apps is retiring. Move to Azure managed services (for example, Azure Cache for Redis, Azure Database for PostgreSQL) or use open-source quickstarts for dev/test purposes.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.app/containerapps
Recommendation ID: ea0bf0e5-dc1b-446f-a1e8-eff1b913eb31

Azure Cosmos DB

Configure Azure Cosmos DB containers with a partition key

The Cosmos DB nonpartitioned collections are approaching the provisioned storage quota and might lose the ability to add data. Migrate to new collections that use a partition key definition, so the service automatically scales out the collections.

Potential benefits: Scale your containers seamlessly with increase in storage or request rates without running into any limits

Impact: High

For more information, see Partitioning and horizontal scaling - Azure Cosmos DB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 5e4e9f04-9201-4fd9-8af6-a9539d13d8ec
Subcategory: Scalability

Use static Cosmos DB client instances in your code and cache the names of databases and collections

A high number of metadata operations on an account can result in rate limiting. Metadata operations have a system-reserved request unit (RU) limit. Avoid rate limiting from metadata operations by using static Cosmos DB client instances in your code and caching the names of databases and collections.

Potential benefits: Optimize your RU usage and avoid rate limiting

Impact: Medium

For more information, see Performance Tips for .NET SDK V2 - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: bdb595a4-e148-41f9-98e8-68ec92d1932e

Your Cosmos DB account can't access its linked Azure Key Vault that hosts your encryption key

When an Azure Cosmos DB account can't access its linked Azure Key Vault hosting the encyrption key, data access and security issues might happen. Your Azure Key Vault's configuration is preventing your Cosmos DB account from contacting the key vault to access your managed encryption keys. If you recently performed a key rotation, ensure that the previous key, or key version, remains enabled and available until Cosmos DB completes the rotation. The previous key or key version can be disabled after 24 hours, or after the Azure Key Vault audit logs don't show any activity from Azure Cosmos DB on that key or key version.

Potential benefits: Update your configurations to continue using customer-managed keys and access your data

Impact: Medium

For more information, see Configure customer-managed keys - Azure Cosmos DB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 44a0a07f-23a2-49df-b8dc-a1b14c7c6a9d
Subcategory: Other

Consider Consistent indexing mode on Azure Cosmos DB containers

Azure Cosmos containers configured with the Lazy indexing mode update asynchronously, which improves write performance, but can impact query freshness. Your container is configured with the Lazy indexing mode. If query freshness is critical, use Consistent Indexing Mode for immediate index updates.

Potential benefits: Improve query result consistency and reliability

Impact: Medium

For more information, see Manage indexing policies in Azure Cosmos DB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 213974c8-ed9c-459f-9398-7cdaa3c28856
Subcategory: Other

Update Azure Cosmos DB Java SDK v2 to version 2.6.14 or migrate to Azure Cosmos DB Java SDK v4

Migrate to Azure Cosmos DB Java SDK v4. As a hotflix, update Azure Cosmos DB Java SDK v2 to version 2.6.14. A critical bug in Azure Cosmos DB Async Java SDK v2 version 2.6.13 and earlier causes errors when a Global logical sequence number (LSN) is greater than the Max Integer value.

Potential benefits: Without action, operations fail with NumberFormatException

Impact: High

For more information, see SQL Async Java API, SDK and Resources - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: bc9e5110-a220-4ab9-8bc9-53f92d3eef70

A critical bug affects Azure Cosmos DB Java SDK v4 versions 4.15 and earlier. When the Global Logical Sequence Number (LSN) exceeds the maximum integer value—something that can occur transparently after a large volume of transactions over a container’s lifetime—the SDK may start returning errors. To

Potential benefits: All CRUD operations may fail with NumberFormatException

Impact: High

For more information, see Java SDK V4 for API for Nosql Release Notes and Resources - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 38942ae5-3154-4e0b-98d9-23aa061c334b

Use the new 3.6+ endpoint to connect to your upgraded Azure Cosmos DB's API for MongoDB account

Some of your applications are connecting to your upgraded Azure Cosmos DB's API for MongoDB account using the legacy 3.2 endpoint - [accountname].documents.azure.com. Use the new endpoint - [accountname].mongo.cosmos.azure.com (or its equivalent in sovereign, government, or restricted clouds).

Potential benefits: Take advantage of the latest features in version 3.6+ of Azure Cosmos DB's API for MongoDB

Impact: Medium

For more information, see 4.0 server version supported features and syntax in Azure Cosmos DB for MongoDB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 123039b5-0fda-4744-9a17-d6b5d5d122b2
Subcategory: ServiceUpgradeAndRetirement

Upgrade your Azure Cosmos DB API for MongoDB account to v4.2 to save on query/storage costs and utilize new features

Your Azure Cosmos DB API for MongoDB account is eligible to upgrade to version 4.2. Upgrading to v4.2 can reduce your storage costs by up to 55% and your query costs by up to 45% by leveraging a new storage format. Numerous additional features such as multi-document transactions are also included in v4.2.

Potential benefits: Improved reliability, query/storage efficiency, performance, and new feature capabilities

Impact: Medium

For more information, see Upgrade the Mongo version - Azure Cosmos DB for MongoDB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 0da795d9-26d2-4f02-a019-0ec383363c88
Subcategory: Other

Enable Server Side Retry (SSR) on your Azure Cosmos DB's API for MongoDB account

When an account is throwing a TooManyRequests error with the 16500 error code, enabling Server Side Retry (SSR) can help mitigate the issue.

Potential benefits: Prevent throttling and improve your query reliability and performance

Impact: High

For more information, see Prevent rate-limiting errors for Azure Cosmos DB for MongoDB operations. - Azure Cosmos DB for MongoDB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: ec6fe20c-08d6-43da-ac18-84ac83756a88

Add a second region to your production workloads on Azure Cosmos DB

Production workloads on Azure Cosmos DB run in a single region might have availability issues, this appears to be the case with some of your Cosmos DB accounts. Increase their availability by configuring them to span at least two Azure regions. NOTE: Additional regions incur additional costs.

Potential benefits: Improve the availability of your production workloads

Impact: Medium

For more information, see High availability (Reliability) in Azure Cosmos DB for NoSQL.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: b57f7a29-dcc8-43de-86fa-18d3f9d3764d
Subcategory: BusinessContinuity

Upgrade your old Azure Cosmos DB SDK to the latest version

An Azure Cosmos DB account using an old version of the SDK lacks the latest fixes and improvements. Your Azure Cosmos DB account is using an old version of the SDK. For the latest fixes, performance improvements, and new feature capabilities, upgrade to the latest version.

Potential benefits: Improved reliability, performance, and new feature capabilities

Impact: Medium

For more information, see Azure Cosmos DB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 51a4e6bd-5a95-4a41-8309-40f5640fdb8b
Subcategory: Other

Upgrade outdated Azure Cosmos DB SDK to the latest version

An Azure Cosmos DB account using an old version of the SDK lacks the latest fixes and improvements. Your Azure Cosmos DB account is using an outdated version of the SDK. We recommend upgrading to the latest version for the latest fixes, performance improvements, and new feature capabilities.

Potential benefits: Improved reliability, performance, and new capabilities

Impact: High

For more information, see Azure Cosmos DB documentation - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 60a55165-9ccd-4536-81f6-e8dc6246d3d2

Enable service managed failover for Cosmos DB account

Enable service managed failover for Cosmos DB account to ensure high availability of the account. Service managed failover automatically switches the write region to the secondary region in case of a primary region outage. This ensures that the application continues to function without any downtime.

Potential benefits: Azure's Service-Managed Failover feature enhances system availability by automating failover processes, reducing downtime, and improving resilience.

Impact: Medium

For more information, see High availability (Reliability) in Azure Cosmos DB for NoSQL.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 5de9f2e6-087e-40da-863a-34b7943beed4
Subcategory: Other

Add at least one data center in another Azure region

Your Azure Managed Instance for Apache Cassandra cluster is designated as a production cluster but is currently deployed in a single Azure region. For production clusters, we recommend adding at least one more data center in another Azure region to guard against disaster recovery scenarios.

Potential benefits: Ensure applications have another region in case of disaster recovery

Impact: Medium

For more information, see Building resilient applications - Azure Managed Instance for Apache Cassandra.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 92056ca3-8fab-43d1-bebf-f9c377ef20e9
Subcategory: DisasterRecovery

Avoid being rate limited for Control Plane operation

We found high number of Control Plane operations on your account through resource provider. Request that exceeds the documented limits at sustained levels over consecutive 5-minute periods may experience request being throttling as well failed or incomplete operation on Azure Cosmos DB resources.

Potential benefits: Optimize control plane operation and avoid operation failure due to rate limiting

Impact: Medium

For more information, see Service quotas and default limits - Azure Cosmos DB.

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: a030f8ab-4dd4-4751-822b-f231a0df5f5a
Subcategory: Scalability

Improve resiliency by migrating your Azure Cosmos DB accounts to continuous backup

Your Azure Cosmos DB accounts use periodic backup. Continuous backup with point-in-time restore is now available - restore data to any moment in the past 30 days. It may also be more cost-effective, retaining only a single copy of your data.

Potential benefits: Improve the resiliency of your Azure Cosmos DB workloads

Impact: Medium

For more information, see Continuous Backup with Point-in-Time Restore - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 52fef986-5897-4359-8b92-0f22749f0d73
Subcategory: BusinessContinuity

Evaluate multi-region write capability in Azure Cosmos DB

Multi-region writes enable high availability but require careful consistency and conflict resolution. Using Bounded Staleness is an anti-pattern, as replication lag increases latency and coordination overhead. This setup undermines scalability, impacting performance and availability.

Potential benefits: Enhances high availability

Impact: High

For more information, see Configure Multi-Region Writes

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: a2002089-9dd1-46b6-881c-d0f349515230

Enable zone redundancy for multi-region Cosmos DB accounts

Enabling zone redundancy for multi-region Cosmos DB accounts to improve high availability and reduce the risk of data loss in case of a regional outage.

Potential benefits: Improved availability and reliability

Impact: High

For more information, see High Availability (Reliability) in Azure Cosmos DB for NoSQL

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 687f83d3-db01-4ab1-a77b-b31e99f16d33

Improve Resiliency with Per‑Partition Automatic Failover

PPAF is a new Azure Cosmos DB preview feature that boosts availability for single‑write region accounts by failing over at the partition level instead of the entire account, reducing downtime and enabling faster recovery during regional outages.

Potential benefits: Enhances single‑region availability

Impact: Medium

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 36b07167-9b19-4725-81bc-54e8e0510a0c

Configure protection for Cosmos DB

Vaulted backup helps in achieving cyber resiliency goals and long-term retention of backups helps in meeting compliance needs. The platform recommends configuring protection for Cosmos DB.

Potential benefits: Achieve cyber resiliency goals and meet compliance needs

Impact: Medium

For more information, see About Azure Cosmos DB backup - Azure Backup

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 649fd0b8-0bf0-43fe-bfa1-c408f6d33200

Azure Cosmos DB requires using TLS 1.2 or later

All Cosmos DB database accounts must use Transport Layer Security (TLS) 1.2 or higher.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Self-Serve Minimum TLS Version Enforcement - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 3086bd6c-a257-4577-9401-fa9d1e0ce48a

Azure Synapse Link for Azure Cosmos DB NoSQL will be retired on March 31, 2029. Customers using this feature should migrate analytical workloads to Cosmos DB mirroring in Microsoft Fabric, the recommended replacement solution, before the retirement date to avoid service disruption and potential loss.

Potential benefits: Prevent disruption to Cosmos DB analytics workloads.

Impact: Medium

For more information, see Migrate from Azure Synapse Link to Azure Cosmos DB mirroring in Microsoft Fabric - Microsoft Fabric

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 0082c3b0-5b9c-4157-bb43-29307b6f882e

Azure Data Explorer

Resolve virtual network issues

Service failed to install or resume due to virtual network (VNet) issues. To resolve this issue, follow the steps in the troubleshooting guide.

Potential benefits: Fix connectivity problems for private endpoints.

Impact: High

For more information, see Troubleshoot access, ingestion, and operation of your Azure Data Explorer cluster in your virtual network - Azure Data Explorer

ResourceType: microsoft.kusto/clusters
Recommendation ID: fa2649e9-e1a5-4d07-9b26-51c080d9a9ba
Subcategory: Other

Azure Database for MariaDB

Azure Database for MariaDB is retiring.

The platform encourages you to transition to Azure Database for MySQL Flexible Server before the retirement date to experience the new capabilities of Azure Database for MySQL Flexible Server.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.dbformariadb/servers
Recommendation ID: 97c5d103-0ef7-4463-80a9-23413d01101c

Azure Database for MySQL

High Availability - Add primary key to the table that currently doesn't have one.

Significant replication lag is detected on the high availability standby server. The lag is caused by the standby server replaying relay logs on a table with no primary key. To address the issue, add primary keys to all tables, disable high availability, and then re-enable high availability.

Potential benefits: Reduced failover times and maintained business continuity

Impact: High

For more information, see Troubleshoot Replication Latency - Azure Database for MySQL - Flexible Server

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: cf388b0c-2847-4ba9-8b07-54c6b23f60fb

Replication - Add a primary key to the table that currently doesn't have one

Significant replication lag is detected on the replica server. The lag is caused by the replica server replaying relay logs on a table with no primary key. To address the issue, add primary keys to the tables in the primary server and recreate the replica server.

Potential benefits: Increase synchronization with the primary server

Impact: High

For more information, see Troubleshoot Replication Latency - Azure Database for MySQL - Flexible Server

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: fb41cc05-7ac3-4b0e-a773-a39b5c1ca9e4

Scale the SKU of the replica server to match or exceed the SKU of the source server

The replica server is experiencing replication lag. This is due to the replica server's SKU being smaller than the source server SKU. To ensure smooth replication, we recommend scaling up the SKU of your replica server.

Potential benefits: Tracks and reduces replication lag

Impact: High

For more information, see Service Tiers - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: 91fd3a33-3b2f-48bb-81db-a2a54cfa2d76

Upgrade to Transport Layer Security (TLS) 1.2

Upgrade to Transport Layer Security (TLS) 1.2 from TLS 1.0 or TLS 1.1 for the application. TLS 1.0 and TLS 1.1 were deprecated in March 2021.

Potential benefits: Improved security. Compliance with newest standards.

Impact: High

For more information, see Networking Overview - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: f259e897-9924-45db-a1ea-788f768548da

Globally set the value of the innodb_strict_mode server parameter to OFF

Globally set the value of the innodb_strict_mode server parameter to OFF. The platform identified a critical issue with the High Availability server. The platform isn't able to process data from the source server due to an error: Table Row Size Too Large.

Potential benefits: Uninterrupted replication. Improved data consistency

Impact: High

For more information, see Server Parameters in Azure Database for MySQL - Flexible Server - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: f51c5bce-c771-42c0-97c8-5c6676bad17c

Enable HA with zone redundancy

Set highAvailability.mode to ZoneRedundant

Potential benefits: Maintains DB access during zone failures

Impact: High

For more information, see Azure Database for MySQL - Flexible Server Overview - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: 5dd0cbbb-61a6-497c-a498-50fe19c7f5d1
Subcategory: HighAvailability

Enable geo-backup on MySQL server for improved disaster recovery and regional resilience

Our monitoring shows geo-backup isn't enabled on your Azure Database for MySQL server. Without it, you cannot restore data in a different region during a regional outage. Enable geo-backup to meet disaster recovery best practices and ensure business continuity.

Potential benefits: Improves disaster recovery and regional resilience

Impact: Medium

For more information, see Backup and Restore - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: c317d906-e24a-4f6d-8cd7-389bd6bc602c

MySQL v5.7 is being retired

MySQL v5.7 is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Version support policy - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: 99565ce4-6382-4ab9-a3ae-48b7df76fdb3

Azure Database for PostgreSQL

Configure geo redundant backup storage

Configure GRS to ensure that your database meets its availability and durability targets even in the face of failures or disasters.

Potential benefits: Ensures recovery from regional failure or disaster.

Impact: Medium

For more information, see Backup and restore - Azure Database for PostgreSQL

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: 5295ed8a-f7a1-48d3-b4a9-e5e472cf1685
Subcategory: DisasterRecovery

Create a read replica from the Azure Database for PostgreSQL flexible server

Create a cross region read replica to protect the database from regional failures. A read replica is a read-only replica that asynchronously updates from an Azure Database for PostgreSQL flexible server instance using physical replication technology. A read replica lags the primary server.

Potential benefits: Recover from a regional failure, disaster, or both.

Impact: High

For more information, see Geo-disaster recovery

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: 7d2149f5-94f7-458d-8171-92cf66832cb2
Subcategory: DisasterRecovery

Enable high availability with zone redundancy

Enable high availability with zone redundancy on flexible server instances to deploy a standby replica in a different zone, offering automatic failover capability for improved reliability and disaster recovery.

Potential benefits: Enhanced uptime and data protection

Impact: High

For more information, see Reliability and high availability in PostgreSQL - Flexible Server - Azure Database for PostgreSQL - Flexible Server

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: 80b4e93c-4500-4fbd-bd6f-3ec245f72be9
Subcategory: HighAvailability

Turn on backup for PostgreSQL flexible server

Backup helps protect data from accidental or malicious deletion. The platform recommends configuring the PostgreSQL flexible server to turn on backup.

Potential benefits: Protect data from accidental or malicious deletion.

Impact: Medium

For more information, see About Azure Database for PostgreSQL Flexible server backup - Azure Backup

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: d1f667d3-b945-4c67-98e2-84a1df2c30ca
Subcategory: DisasterRecovery

Review the server for storage auto grow

The server has utilized 80 percent of the storage and storage auto growth isn't enabled. Storage auto grow can help ensure that your server always has enough free space available and doesn't become read-only.

Potential benefits: Storage autogrow ensures your server has enough free space

Impact: High

For more information, see Storage options - Azure Database for PostgreSQL

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: 2de25da6-5d44-4c0d-8a37-b61f8a65babe

Migrate to Azure Database for PostgreSQL Elastic Cluster

Azure Cosmos DB for PostgreSQL is retiring. Migrate to Azure Database for PostgreSQL Elastic Cluster.

Potential benefits: Avoid service disruption

Impact: Medium

ResourceType: microsoft.dbforpostgresql/servergroupsv2
Recommendation ID: bbce2e96-97d6-406e-bb16-07fda2759879

Azure Database for PostgreSQL Single Server is retiring.

Use the migration tool to migrate to Azure Database for PostgreSQL Flexible Server.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.dbforpostgresql/servers
Recommendation ID: aeab15f5-b474-46f5-892e-8d60f874d769

PostgreSQL 11 on Azure Database for PostgreSQL flexible server instances is retiring

Upgrade Azure Database for PostgreSQL flexible server instances to PostgreSQL version 13 or later.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Version Policy - Azure Database for PostgreSQL

ResourceType: microsoft.dbforpostgresql/flexibleservers
Recommendation ID: 49b73d1f-caf4-47ca-899e-5214af89827c

Azure Databricks

Upgrade to Premium tier workspace for Azure Databricks

Standard tier workspaces are retiring. Upgrade to Premium tier prior to retirement date. The Standard tier workspace is automatically upgraded to Premium tier after the retirement date.

Potential benefits: Access to enhanced capabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.databricks/workspaces
Recommendation ID: 99db65bb-fdb3-4bc8-b015-341fba99865c

Azure Health Data Services

Azure API for FHIR is retiring.

To avoid potential disruptions, migrate to Azure Health Data Services.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.healthcareapis/services
Recommendation ID: 61f4820a-997b-4690-a323-8c7df26271c8

In your FHIR service, SMART on FHIR proxy feature is retiring.

To maintain feature continuity, follow the instructions in SMART on FHIR - Azure Health Data Services to migrate to the replacement option by September 21, 2026.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.healthcareapis/workspaces/fhirservices
Recommendation ID: d649a10e-87a5-4f0d-b9f8-eb21f8b17064

Azure HPC Cache

Azure HPC Cache is retiring.

Modify your existing workflows to remove Azure HPC Cache.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.storagecache/caches
Recommendation ID: 8e0d3259-067c-4f95-8559-95654a4d3eff

Azure IoT Hub

Upgrade Device Client SDK for IoT Hub

When devices use an outdated SDK, performance degradation can occur. Some or all of your devices are using an outdated SDK. We recommend you upgrade to a supported SDK version.

Potential benefits: Ensure business continuity with supported SDK for your devices

Impact: Medium

For more information, see Azure IoT Hub device and service SDKs

ResourceType: microsoft.devices/iothubs
Recommendation ID: d448c687-b808-4143-bbdc-02c35478198a
Subcategory: ServiceUpgradeAndRetirement

IoT Hub Potential Device Storm Detected

This is when two or more devices are trying to connect to the IoT Hub using the same device ID credentials. When the second device (B) connects, it causes the first one (A) to become disconnected. Then (A) attempts to reconnect again, which causes (B) to get disconnected.

Potential benefits: Improve connectivity of your devices

Impact: Medium

For more information, see Troubleshooting Azure IoT Hub error codes

ResourceType: microsoft.devices/iothubs
Recommendation ID: 8d7efd88-c891-46be-9287-0aec2fabd51c
Subcategory: Other

Add IoT Hub units or increase SKU level

When an IoT Hub exceeds its daily message quota, operation and cost problems might occur. To ensure smooth operation in the future, add units or increase the SKU level.

Potential benefits: The IoT Hub can receive messages again.

Impact: High

For more information, see Troubleshoot Azure IoT Hub Error Codes

ResourceType: microsoft.devices/iothubs
Recommendation ID: e4bda6ac-032c-44e0-9b40-e0522796a6d2

Upgrade the Azure Device Update for IoT Hub SDK to the latest version

When a Device Update for IoT Hub instance calls the service by using an outdated SDK version, it misses fixes, features, and support for current API versions. Outdated SDK versions are supported only until the API versions they use retire. Upgrade to the recommended version to stay supported.

Potential benefits: Stay supported and avoid disruption when older SDKs retire.

Impact: Medium

For more information, see Introduction to Device Update for Azure IoT Hub

ResourceType: microsoft.devices/iothubs
Recommendation ID: 63f181a7-95a9-42be-9443-34ea8a5b4d3e
Subcategory: ServiceUpgradeAndRetirement

Azure Lab Services

Azure Lab Services is retiring.

After the retirement date, Azure Lab Services isn't supported. You won't have access to the lab accounts, lab plans, or labs.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.labservices/labplans
Recommendation ID: 6127d183-2109-4234-87bf-3518eb8a460e

Azure Lab Services is retiring.

After the retirement date, Azure Lab Services isn't supported. You won't have access to the lab accounts, lab plans, or labs.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.labservices/labaccounts
Recommendation ID: 703bd88a-fe4b-4e74-ba7b-f328121ad1ca

Azure Lab Services is retiring.

After the retirement date, Azure Lab Services isn't supported. You won't have access to the lab accounts, lab plans, or labs.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.labservices/labs
Recommendation ID: c363fcbf-28df-417b-a5e9-cf71fa037515

Azure Kubernetes Service (AKS)

Use AKS Backup for a cluster with persistent volumes

Azure Kubernetes Service (AKS) backup is a cloud-native solution for backing up and restoring containerized apps and data in an AKS cluster. AKS Backup supports scheduled backups for cluster state and persistent volumes. AKS Backup offers granular control over a namespace or an entire cluster.

Potential benefits: Backups for cluster state and persistent volumes

Impact: Medium

For more information, see What is Azure Kubernetes Service (AKS) backup? - Azure Backup

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 29f2eea3-b0d8-4934-a0f8-171dbd70ba13
Subcategory: DisasterRecovery

Enable Autoscaling for your system node pools

To ensure your system pods are scheduled even during times of high load, enable autoscaling on your system node pool.

Potential benefits: Autoscaler improves system pod uptime

Impact: High

For more information, see Use the cluster autoscaler in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 70829b1a-272b-4728-b418-8f1a56432d33

Have at least 2 nodes in your system node pool

Ensure your system node pools have at least 2 nodes for reliability of your system pods. With a single node, your cluster can fail in the event of a node or hardware failure.

Potential benefits: Having 2 nodes ensures resiliency against node failures.

Impact: High

For more information, see Use system node pools in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: a9228ae7-4386-41be-b527-acd59fad3c79

Create a dedicated system node pool

Your cluster doesn't have a dedicated system node pool. It's recommended to dedicate system node pools to only serve critical system pods. This prevents resource starvation between system and competing user pods. Enforce this behavior with the CriticalAddonsOnly=true:NoSchedule taint on the pool.

Potential benefits: Prevents resource scarcity for core system pods

Impact: High

For more information, see Use system node pools in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: f31832f1-7e87-499d-a52a-120f610aba98

Clusters with node pools using nonrecommended B-series

When a cluster has one or more node pools that use a nonrecommended burstable VM SKU, the cluster doesn't guarantee full vCPU capability at 100%. Ensure B-series VMs aren't used in production environments.

Potential benefits: Best practice for consistent performance

Impact: Medium

For more information, see Bv1 size series - Azure Virtual Machines

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: fac2ad84-1421-4dd3-8477-9d6e605392b4
Subcategory: HighAvailability

The availability zones in Azure regions ensure high availability by offering independent locations. An availability zone is equipped with independent power, cooling, and networking to ensure applications and data are protected from datacenter-level failures.

Potential benefits: Improved availability and reliability

Impact: High

For more information, see Availability Zones in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 9f3263db-b9c0-43bb-8523-6800f9f50793
Subcategory: HighAvailability

Ubuntu 20.04 on Azure Kubernetes Service is retiring

To avoid service disruptions, scaling restrictions, and remain supported; upgrade to a supported Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 863d09bd-e767-472b-9980-f32709414ade

Migrate to Container insights managed identity authentication

Migrate to Container insights managed identity authentication before the retirement date to maintain access and retain functionality.

Potential benefits: Avoid service disruption and gain enhanced features

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: b005ecf0-23e2-4279-9ca2-718d1518c9fb

Use Fleet Manager auto-upgrade profiles to regularly update clusters

Use Azure Kubernetes Fleet Manager to safely update multiple clusters using update runs, auto-upgrade profiles and strategies.

Potential benefits: Safe and predictable updates of multiple clusters

Impact: Medium

For more information, see Automate upgrades of Kubernetes and node images across multiple clusters using Azure Kubernetes Fleet Manager

ResourceType: microsoft.containerservice/fleets
Recommendation ID: 8aad9adb-cb6a-4ddc-b659-12d1c6ca186a

Migrate from NPM for Windows on AKS

Customers should explore alternative options for restricting traffic access on Windows clusters, such as: Network Security Groups (NSGs) at the node level or Open-source tools like Project Calico. Microsoft encourages identifying the best approach for your environment before the retirement date.

Potential benefits: Ensure secure traffic control on Windows-based AKS clusters

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: ec938125-62ef-4dc5-b7b1-257eb8d006d9

Migrate to Cilium Network Policy

Azure Network Policy Manager for Azure Kubernetes Service clusters running Linux nodes is retiring. Migrate to Cilium Network Policy using Azure Container Networking Interface powered by Cilium before the retirement date.

Potential benefits: Avoid service disruptions and unsupported configurations

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 0e15044d-e326-4281-bbe1-1e35b32308ec

Migrate to Azure Linux 3.0

Transition to Azure Linux 3.0 before the retirement date to receive future kernel updates, receive future security improvements, and avoid scaling failures.

Potential benefits: Avoid service disruptions and unsupported configurations

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 91594754-953c-4eda-ac71-7b8e2e9b0e74

Migrate from NGINX Ingress with Application Routing Add On

Managed NGINX Ingress via the AKS Application Routing add-on is retiring. Plan migrations to alternative solutions like Application Gateway for Containers (AGC) or Istio-based service mesh.

Potential benefits: Avoid service interruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 40985a2e-6876-4a4c-902e-c85d06272935

Azure Kubernetes Support for HC-series is being retired

Standard_HC44rs, Standard_HC44-16rs, and Standard_HC44-32rs virtual machine sizes will be retired. Transition to one of the current-generation Azure HPC VM families, HBv5-series, or HX-series VMs.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Migrate your HC-series virtual machines by May 31, 2027 - Azure Virtual Machines

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: c7507a57-0abf-47af-81bb-819a675bc956

Azure Kubernetes Support for HBv2-series is being retired

Standard_HB120rs_v2, Standard_HB120-96rs_v2, Standard_HB120-64rs_v2, Standard_HB120-32rs_v2, and Standard_HB120-16rs_v2 virtual machine sizes will be retired. Transition to the HBv5-series VMs.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Migrate your HBv2-series virtual machines by May 31, 2027 - Azure Virtual Machines

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 10378caa-f4fe-48f3-9893-6bdec79687b2

Migrate to Ubuntu 24.04 or later versions

Azure Kubernetes Service support for Ubuntu 22.04 is retiring, transition to Ubuntu 24.04+ or a supported alternative.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 00dbcc9d-50d4-44ef-bc21-c15785cddf42

Azure Kubernetes Service support for NP-series is being retired

Standard_NP10s, Standard_NP20s, and Standard_NP40s virtual machine sizes are being retired. Transition to NC-series or ND-series VMs.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Migrate your NP-series virtual machines by May 31, 2027 - Azure Virtual Machines

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 1f0dbe45-11b2-44e5-a6e6-676f599f786f

Kubenet networking for Azure Kubernetes Service (AKS) is retiring

After the retirement date, workloads running on kubenet networking for AKS aren't supported.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 4686c4de-4652-475b-95a5-08f6518424a9

Kubernetes workloads is stopping support of Windows Server 2019

Windows Server 2019 retires when Kubernetes 1.32 reaches the end of platform support. On Kubernetes 1.33 and later, creation of new Windows Server 2019 node pools is blocked.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Upgrade the Operating System (OS) Version for your Azure Kubernetes Service (AKS) Windows Workloads - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 73d80d39-3c2c-4baa-908c-82d76027ab14

Migrate Windows Server 2022 to a supported version for Kubernetes workloads

Windows Server 2022 retires when Kubernetes 1.34 reaches the end of platform support. On Kubernetes 1.35 and later, creation of new Windows Server 2022 node pools is blocked.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Upgrade the Operating System (OS) Version for your Azure Kubernetes Service (AKS) Windows Workloads - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 2c717abc-d6b0-4588-aa10-8ecaec0a33b4

Ubuntu 18.04 on Azure Kubernetes Service is being retired

To avoid service disruptions, scaling restrictions, and remain supported, upgrade to a supported Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 66e6be23-79fa-464a-b1b6-dfce922075c3

Ubuntu 20.04 LTS support is being retired

Ubuntu 20.04 LTS support is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 7c4f5f17-03a6-4bc7-b59d-4e565f8dba87

Upgrade your AKS cluster from 1.31 LTS Kubernetes version

Azure Kubernetes Service retires 1.31 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.31 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: b85966b5-4c36-475f-b230-d8a6e31c1375

Upgrade your AKS cluster from 1.32 Kubernetes Official version

Azure Kubernetes Service retires 1.32 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.32 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 7dcef62e-792c-49dc-b36a-1938829c449c

Upgrade your AKS cluster from 1.32 LTS Kubernetes version

Azure Kubernetes Service retires 1.32 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.32 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: Medium For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 11112bf2-7226-486c-94b3-cff3ea6b59e2

Upgrade your AKS cluster from 1.33 Kubernetes Official version

Azure Kubernetes Service retires 1.33 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.33 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: cf2add1a-e133-4562-92a0-4bd39b2f659b

Upgrade your AKS cluster from 1.33 LTS Kubernetes version

Azure Kubernetes Service retires 1.33 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.33 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 56b606bb-1363-4fc0-91ef-b26127579d38

Upgrade your AKS cluster from 1.34 Kubernetes Official version

Azure Kubernetes Service retires 1.34 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.34 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 0b1bf3f1-eb3e-4855-b9a5-06cde224c60d

Upgrade your AKS cluster from 1.34 LTS Kubernetes version

Azure Kubernetes Service retires 1.34 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.34 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 997ec7aa-2f8d-4268-9ac0-4e8147cbe9d7

Upgrade your AKS cluster from 1.35 Kubernetes Official version

Azure Kubernetes Service retires 1.35 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.35 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: Medium For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: e228c486-197f-415c-8b93-5e2b07458c17

Upgrade your AKS cluster from 1.35 LTS Kubernetes version

Azure Kubernetes Service retires 1.35 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.35 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: af3198f6-7691-4d61-8e30-da79088eb579

Upgrade your AKS cluster from 1.36 Kubernetes Official version

Azure Kubernetes Service retires 1.36 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.36 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: e828d5b8-b7bd-47b8-ac15-30e825ccdcfe

Upgrade your AKS cluster from 1.37 Kubernetes Official version

Azure Kubernetes Service retires 1.37 Kubernetes Official version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.37 Kubernetes Official version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: c540fc0a-d78a-4b6a-84df-c97dae512b2d

Upgrade your AKS cluster from 1.37 LTS Kubernetes version

Azure Kubernetes Service retires 1.37 LTS Kubernetes version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.37 LTS Kubernetes version.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: cc60a05a-1e40-403f-9790-28f310d54249

Upgrade your AKS cluster to a supported long-term support (LTS) version

Azure Kubernetes Service retires 1.30 LTS version. To stay within supported versions and service-level agreements (SLA), upgrade to a supported version within 30 days after Azure removes version 1.30 LTS.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Supported Kubernetes Versions in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 3afd0e0e-36bd-444b-97d7-d1e85d44066d

Azure Machine Learning

Migrate external data imports to Microsoft Fabric

Import data from external sources – S3, Snowflake, Azure SQL Db along with external Data Connections in Azure Machine Learning are being retired. To avoid any disruptions to ML pipelines, migrate external data imports to Microsoft Fabric and use AzureML datastores.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 8027dfbe-6af9-427c-8078-6e907d6a7ce1

Migrate away from retiring Azure Machine Learning preview features

The preview features for Azure Machine Learning are retiring. Preview features include grouping multiple steps for better organization of complex pipeline jobs to debug failures or unexpected issues. Create a plan for removing dependencies on the preview features.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 262c35d4-83fe-457f-afa7-cac774c371d8

Migrate to third-party data labeling providers

Azure Machine data labeling is retiring. Migrate to third-party data labeling providers.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 45d99071-d74a-49ed-8535-de77290017a5

Migrate to dedicated virtual machine for compute clusters

The ability to allocate Azure Low Priority Virtual Machines in Batch pools is retiring. Azure Low Priority Virtual Machine instances aren't provisionable or supported in new clusters.

Potential benefits: Ensure continued support and avoid disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 38b0a494-d5f6-4855-83e4-4e5f5ed9b987

Transition from Batch Endpoints preview APIs

Azure Machine Learning Batch Endpoints preview APIs will be retired. Move to alternative solutions for batch inferencing to ensure continuity and leverage newer capabilities.

Potential benefits: Ensure service continuity

Impact: High

For more information, see What are batch endpoints? - Azure Machine Learning

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 08a4b7ad-b2b8-41b4-bc80-a733da095979

Upgrade to Azure Machine Learning SDK v2

Migrate to Azure Machine Learning SDK v2 to avoid service disruptions.

Potential benefits: Ensure continued support and avoid disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.machinelearningservices/workspaces
Recommendation ID: 6effe055-73b3-4dd2-bcbf-bbdcd11b4161

Azure Managed Workspace for Grafana

Use Managed Grafana in zone-redundant regions to ensure dashboards remain available during outage

Deploy Grafana instances in multiple zones or use the zone-redundant SKU (if available). For critical dashboards, configure paired-region failover.

Potential benefits: Dashboard availability during zone outages

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.dashboard/grafana
Recommendation ID: b76a9063-460e-437f-b939-da4f322293da

Upgrade to X2 for more memory and reliable performance

Grafana workspaces under high load can encounter out‑of‑memory (OOM) issues, which might cause service instability. Scaling to the X2 size increases memory resources, enabling workspaces to sustain peak usage while delivering more consistent performance and higher availability.

Potential benefits: Enhance reliability by scaling to X2, which has higher memory.

Impact: Medium

For more information, see What is Azure Managed Grafana?

ResourceType: microsoft.dashboard/grafana
Recommendation ID: 83357e9d-cc5b-46c3-ac81-6709cf07965e

Azure Maps

Azure Maps Traffic APIs version 1.0 is being retired

Azure Maps Traffic APIs version 1.0 isn't supported and API calls fail. Transition to Azure Maps Traffic Incident API version 2025-01-01, Azure Maps Get Map Tile API version 2024-04-01, or both.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.maps/accounts
Recommendation ID: 32c9c955-d054-4648-b6f8-a02ff805efe6
Subcategory: ServiceUpgradeAndRetirement

Azure Maps Gen1 (Standard S0 and Standard S1) price tier is retiring

To avoid deployment disruptions, use the Gen2 price tier for new Azure Maps accounts that you create through Azure Resource Manager templates.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.maps/accounts
Recommendation ID: 2b3d5fa8-7583-4203-be7d-53f8598ae47a

Azure Maps Render V1 APIs are retiring

Azure Maps Render V1 APIs are retiring. Transition to Azure Maps Render V2 APIs.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.maps/accounts
Recommendation ID: 535d4280-cfc2-4dad-a8ab-2beef1473cb9

Azure Maps Route APIs version 1.0 is retiring

Azure Maps Route APIs version 1.0 isn't supported, and API requests fail.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.maps/accounts
Recommendation ID: 6801eb05-04b6-4b81-ae58-c16e764dcfc2

Data Registry 2023-06-01 is being retired

Azure Maps Data Registry APIs V 06-01-2023 is retiring. To avoid service disruptions, stop using Azure Maps Data Registry API V 2023-06-01.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.maps/accounts
Recommendation ID: 97089a37-e512-4a1e-aea2-76b232080c54

Spatial API V1 & 2022-08-01 is being retired

Azure Maps Spatial APIs V1 & 2022-08-01 is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.maps/accounts
Recommendation ID: f983a0ec-874c-499f-8364-fd1ffc5e917a

Web SDK Map Controls v1.xx is being retired

Azure Maps Web SDK Map Controls Version 1.xx is retiring. Transition to Azure Maps Web SDK Map Controls Version 3.xx.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.maps/accounts
Recommendation ID: c5a9f2fd-3672-4912-9c48-0295e2a608b1

Azure Monitor pipeline

Migrate to direct Prometheus

Azure Monitor is deprecating the sidecar for remote-write of Prometheus metrics to Azure Monitor Workspace. Configure self-hosted Prometheus or Prometheus Operator to remote-write directly to Azure Monitor Workspace.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.monitor/accounts
Recommendation ID: fe21e589-8398-4fae-be74-6364137782eb

Azure Monitor Workspace

Transition from ContainerLog table

Azure Monitor ContainerLog table will be retired. Customers should migrate to the new table or supported alternatives to maintain observability and leverage enhanced capabilities.

Potential benefits: Maintain observability

Impact: High

For more information, see Configure the ContainerLogV2 schema for Container Insights - Azure Monitor

ResourceType: microsoft.monitor/accounts
Recommendation ID: 8c051878-a1ba-42e3-88b7-3533772f295e

Migrate to Diagnostic Settings

Azure Activity Logs Legacy solution will be retired and replaced by Diagnostic Settings. Automation using the Legacy API will not be supported; recreate automation using the new API.

Potential benefits: Ensure automation continuity

Impact: High

For more information, see Azure updates

ResourceType: microsoft.monitor/accounts
Recommendation ID: 68da57f8-4582-4d1c-b5a2-4a114a3b2f1a

Azure Monitor

Update Data Collection Rules

Preview feature Send virtual machine client data to Event Hubs and Storage is retiring. Switch to alternatives to continue using AMA or other Azure solutions that provide more reliable, scalable and performant solutions to send data.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.insights/actiongroups
Recommendation ID: bc89d51f-df67-4814-ae1f-f36116d34218

Classic Application Insights is being retired

Classic Application Insights is being retired, migrate to workspace-based Application Insights resources.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.insights/components
Recommendation ID: c40a2c46-1da0-4205-be9d-c7d3d8688272

API keys for querying are retiring

API keys used to query Application Insights are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.insights/components
Recommendation ID: 12cd603f-7c81-4edc-bba8-f67cbaff3981

Alerts - GetAlertSummary API is retiring

Alerts - GetAlertSummary API is retiring. You need to migrate to Azure Resource Graph query, which provides all of the functionality of GetAlertSummary API plus new ones.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.insights/activitylogalerts
Recommendation ID: 1f72b1d9-0b0d-41ec-84b5-6d1f535b4e63

Monitoring Support (AKS-Engine) is retiring

AKS-Engine is retiring. With this retirement, Azure Monitor users will no longer have access to the UX support, portal experience, or monitoring agent for any applications hosted on AKS-Engine.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.insights/components
Recommendation ID: affb5d76-a7fb-4b4c-a67d-c32dc5be1cc4

The URL ping test capability of the application insights feature for Azure Monitor is retired.

To ensure you can continue to run single-step availability tests in your application insights resources, transition to standard tests. Ping tests are removed from your resources.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.insights/webtests
Recommendation ID: e877d6d4-e952-4f8a-a4c4-5f90e5ac1da9

Azure NetApp Files

Review SAP configuration for timeout values used with Azure NetApp Files

High availability of SAP while used with Azure NetApp Files relies on setting proper timeout values to prevent disruption to your application. Review the 'Learn more' link to ensure your configuration meets the timeout values as noted in the documentation.

Potential benefits: Improve resiliency of SAP Application on ANF

Impact: High

For more information, see Get started with SAP on Azure VMs

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 8754f0ed-c82a-497e-be31-c9d701c976e1

Configure a snapshot for the Azure NetApp Files volume

Configure a snapshot for the Azure NetApp Files volume. Restore a snapshot to a new volume, restore a single file using a client, or revert an existing volume using a snapshot.

Potential benefits: Add data protection for the Azure NetApp Files volume.

Impact: High

For more information, see Understand Azure NetApp Files snapshot-based data protection

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: cda11061-35a8-4ca3-aa03-b242dcdf7319

Enable SMB volume for Azure Netapp Files to enable Continuous Availability

For Continuous Availability, the platform recommends enabling Server Message Block (SMB) volume for Azure Netapp Files.

Potential benefits: Prevent application disruptions for SMB volumes

Impact: High

For more information, see Enable Continuous Availability on existing Azure NetApp Files SMB volumes

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: e4bebd74-387a-4a74-b757-475d2d1b4e3e

Configure a backup for the Azure NetApp Files volume

Configure a backup for the Azure NetApp Files volume. An Azure NetApp Files backup provides a fully managed backup solution for long-term recovery, archiving, and compliance. An Azure NetApp Files backup expands the data protection provided by Azure NetApp Files volume.

Potential benefits: Add data protection for the Azure NetApp Files volume.

Impact: Medium

For more information, see Configure policy-based backups for Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts
Recommendation ID: c70fc854-2814-4b03-9b93-8ad7b918bfcf

Create a cross-region replication relationship from the Azure NetApp Files volume to another volume

Create a cross-region replication relationship from the Azure NetApp Files volume to an Azure NetApp Files volume in another region. Azure NetApp Files cross-region feature provides data protection between volumes in different regions.

Potential benefits: Protect data for volumes in different regions.

Impact: Medium

For more information, see Cross-region replication of Azure NetApp Files volumes

ResourceType: microsoft.netapp/netappaccounts
Recommendation ID: 26f91380-cb68-4642-bb6f-1bce3c64c55e
Subcategory: DisasterRecovery

Create a cross-zone replication relationship from the Azure NetApp Files volume to another volume

Create a cross-zone replication relationship from the Azure NetApp Files volume to an Azure NetApp Files volume in another availability zone. The Azure NetApp Files cross-zone replication feature provides data protection between volumes in different availability zones.

Potential benefits: Protect data for volumes in different availability zones.

Impact: Medium

For more information, see Cross-zone replication of Azure NetApp Files volumes

ResourceType: microsoft.netapp/netappaccounts
Recommendation ID: 7a48f43e-8615-4ce0-8039-83b9d24f945a
Subcategory: DisasterRecovery

New volume creation with Standard networking only

From May 31, all Azure NetApp Files volumes will be created using Standard Networking. Basic network feature will no longer be an option. Existing volumes are unaffected and no customer action is required.

Potential benefits: Increases the number of IP addresses.

Impact: High

For more information, see Guidelines for Azure NetApp Files network planning

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 64936c6e-8236-4875-8234-109ab34576fe
Subcategory: ServiceUpgradeAndRetirement

Configure backup policy for Azure NetApp Files volume

Configure a backup policy to enable scheduled backup protection. Azure NetApp File volumes have no scheduled backups by default, increasing risk of data loss and longer recovery. Using this feature will incur additional backup charges.

Potential benefits: Add data protection for the Azure NetApp Files volume.

Impact: Medium

For more information, see Manage backup policies for Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 2c3230cf-e6a3-4479-8a82-b8031b991b24

Azure Relay

Migrate Azure Relay templates and automation to ARM API version 2021-11-01 or later

Using ARM API version 2021-11-01 or later for Azure Relay keeps your deployments compatible with current Azure Resource Manager capabilities. This approach supports consistent provisioning and management across templates, scripts, and tools.

Potential benefits: Ensure supported Azure Relay management

Impact: High

For more information, see Steps to upgrade control plane API references for Azure Service Bus, Event Hubs, and Relay

ResourceType: microsoft.relay/namespaces
Recommendation ID: 98ac83b7-1944-4a73-b6ed-4cfc6bc610b9

Azure SignalR Service

Deploy Azure Web PubSub in a zone-redundant configuration

Deploying Azure Web PubSub in a zone-redundant configuration by using the Premium Tier improves service availability by distributing the service across multiple availability zones, reducing the impact of zone-level failures

Potential benefits: Improved availability and resiliency

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.signalrservice/webpubsub
Recommendation ID: b2bab712-303b-486c-b9fc-3588fa47c00d

Azure Site Recovery

Enable soft delete for your Recovery Services vaults

Soft delete helps you retain your backup data in the Recovery Services vault for an additional duration after deletion, giving you an opportunity to retrieve it before it's permanently deleted.

Potential benefits: Helps recovery of backup data in cases of accidental deletion

Impact: Medium

For more information, see Soft delete for Azure Backup - Azure Backup

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 3ebfaf53-4d8c-4e67-a948-017bbbf59de6
Subcategory: DisasterRecovery

Enable Cross Region Restore for your recovery Services Vault

Cross Region Restore (CRR) allows you to restore Azure VMs in a secondary region (an Azure paired region), helping with disaster recovery.

Potential benefits: As one of the restore options, Cross Region Restore (CRR) allows you to restore Azure VMs in a secondary region, which is an Azure paired region.

Impact: Medium

For more information, see Restore VMs by using the Azure portal using Azure Backup - Azure Backup

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 9b1308f1-4c25-4347-a061-7cc5cd6a44ab
Subcategory: DisasterRecovery

Enable Zone Redundant Storage (ZRS) for vault storage to protect backups from zone failures

Create vaults in regions that support zone-redundant storage (ZRS) for backup data.

Potential benefits: ZRS backups survive zone-level failures

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 21ac578c-0fb9-42eb-9c58-69716f87e7fb

Classic Alerts (Azure Site Recovery) is retiring

Classic Alerts (Azure Site Recovery) is retiring. Move to Azure Monitor alerts.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 42818b36-2faf-467c-af96-57a37a4ab2ab

Classic VMware protection is being retired

Classic VMware protection is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 67354030-fcfb-481b-8b6f-02279264493b

Classic alerts for Recovery Services vaults are being retired

Recovery Services vaults in Azure Backup are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: cd54a1da-c8ee-4a90-b1ca-5cdb822d32a1

Migrate from classic alerts to built-in Azure Monitor alerts for Azure Recovery Services Vaults

Classic alerts for Recovery Services vaults in Azure Backup will be retired on 31 March 2026.

Potential benefits: Enhanced, scalable, and consistent alerting.

Impact: Medium

For more information, see Backup Classic Alerts using Azure Backup - Azure Backup

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: e7b53f49-3639-4673-aed9-beed581d4535

Azure Sphere

Azure Sphere is being retired

Azure Sphere OS and cloud services are being retired, including the first generation MT3620 microcontroller based platform. Migrate to a new hardware and connectivity stack.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Retirement - Azure Sphere

ResourceType: microsoft.azuresphere/catalogs
Recommendation ID: ee60d00e-823e-439d-971f-644fce1f1cb4

Public API (Azure Sphere) is retiring

Azure Sphere Legacy service interfaces, including the Azure Sphere (Legacy) API (also known as PAPI), and the Azure Sphere (Legacy) CLI (also known as azsphere), are retiring.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.azuresphere/catalogs
Recommendation ID: d76f2201-475e-4397-a654-43390f545dd4

Azure Spring Apps

Upgrade Application Configuration Service to Gen 2

We notice you are still using Application Configuration Service Gen1 which will be end of support by April 2024. Application Configuration Service Gen2 provides better performance compared to Gen1 and the upgrade from Gen1 to Gen2 is zero downtime so we recommend to upgrade as soon as possible.

Potential benefits: Higher stability and availability

Impact: Medium

For more information, see Use Application Configuration Service for Tanzu - Azure Spring Apps Enterprise plan

ResourceType: microsoft.appplatform/spring
Recommendation ID: 39d862c8-445c-40c6-ba59-0e86134df606
Subcategory: Other

Azure Spring Apps, including Basic, Standard and Enterprise plans, are being retired.

Azure Spring Apps is retiring, and you can no longer access Azure Spring Apps instances.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates.

ResourceType: microsoft.appplatform/spring
Recommendation ID: bc36b547-2461-4f0d-8063-c9a6a2b19dfc

Azure SQL Database

Enable cross region disaster recovery for SQL Database

Enable cross region disaster recovery for Azure SQL Database for business continuity in the event of regional outage.

Potential benefits: Enable database recovery after a regional failure.

Impact: High

For more information, see Cloud Business Continuity - Disaster Recovery - Azure SQL Database

ResourceType: microsoft.sql/servers/databases
Recommendation ID: 2ea11bcb-dfd0-48dc-96f0-beba578b989a

Enable cross region disaster recovery for SQL Managed Instance

Consider deploying a failover group for the SQL Managed Instance to allow business continuity in different Azure regions to deal with a regional outage.

Potential benefits: Ensure business continuity through regional redundancy.

Impact: High

For more information, see Failover Groups Overview & Best Practices - Azure SQL Managed Instance

ResourceType: microsoft.sql/managedinstances
Recommendation ID: e1967ca0-c0c3-4ae2-b69b-13d5676a4b18
Subcategory: DisasterRecovery

Enable zone redundancy for Azure SQL Managed Instance to improve high availability and resiliency

Azure SQL Managed Instance offers built-in availability by deploying multiple replicas in the same zone. For higher availability, use a zone-redundant configuration that spreads replicas across three Azure availability zones, each with independent power, cooling, and networking.

Potential benefits: Enhanced availability with minimal latency impact

Impact: High

For more information, see Availability through local and zone redundancy - Azure SQL Managed Instance

ResourceType: microsoft.sql/managedinstances
Recommendation ID: 9b7e559c-2f7a-41ea-9b8f-43a53a12c273
Subcategory: HighAvailability

Migrate Azure Monitor SCOM Managed Instance to System Center Operations Manager or Azure Monitor

Migrate monitoring workloads using Azure Monitor SCOM Managed Instance to supported alternatives based on environment type.

Potential benefits: Avoid loss of access and service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.sql/managedinstances
Recommendation ID: cdbef351-5bba-4639-abcd-34b594310b97

Migrate to TLS 1.2 or above for SQL databases

Support for TLS 1.0 and 1.1 on Azure SQL db is retiring. Update the TLS policy to the latest version

Potential benefits: Avoid service disruption

Impact: High

For more information, see Connectivity Settings - Azure SQL Database and SQL database in Fabric

ResourceType: microsoft.sql/servers
Recommendation ID: 8eff5550-a532-452b-88dd-f4032156da2f

Fsv2-series hardware configuration is being retired

We recommend transitioning to the Hyperscale premium-series or General-purpose standard-series (Gen5) service tier to maintain comparable performance levels.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.sql/servers/databases
Recommendation ID: 78a8bb04-6f10-4112-8b1e-ac0fd88c67a2

Migrate from Elastic query using Shard_Map_Manager mode

Elastic query using Shard_Map_Manager external data source type reaches end of support. Existing workloads can continue to run using Azure SQL Elastic query - Shard_Map_Manager mode but will no longer receive updates or support from Microsoft.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.sql/servers
Recommendation ID: 7bd8494e-7c51-456b-86a1-0cab4fe0516b

Enable zone redundancy for Azure SQL Database to achieve high availability and resiliency

By default, Azure SQL Database Premium tier creates multiple replicas in the same region for high availability. To protect against zone-level failures, enable zone redundancy to spread replicas across availability zones within the region.

Potential benefits: Improved availability and reliability.

Impact: High

For more information, see Availability Through Local and Zone Redundancy - Azure SQL Database

ResourceType: microsoft.sql/servers/databases
Recommendation ID: fe62c79b-21e2-43fe-82b7-f7ec3b76c2aa

Enable zone redundancy for SQL Managed Instance databases

Enabling zone redundancy for SQL Managed Instance databases improves availability by ensuring database replicas are distributed across multiple availability zones, reducing the impact of zone-level failures.

Potential benefits: Improved database availability

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.sql/managedinstances
Recommendation ID: 4c400f75-46b6-42a5-9c18-b80602a44531

Enable zone redundancy for Azure SQL Elastic Pools

Enabling zone redundancy for Azure SQL Elastic Pools improves database availability by distributing pool compute across availability zones and minimizing the impact of zone-level failures.

Potential benefits: Improved availability

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.sql/servers/elasticpools
Recommendation ID: 46cc1fcd-f1eb-4558-a7fb-22ba33f9e8e9

Data Sync (Azure SQL) is being retired

Data Sync (Azure SQL) is being retired. Consider migrating to alternative data replication or synchronization solutions.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.sql/servers/databases
Recommendation ID: f3d3e057-d647-40e4-9905-f085e4a70ff7

Microsoft.SQL 2014-04-01 stable APIs are retiring

Microsoft.SQL 2014-04-01 stable APIs are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure SQL Database REST API 2014-04-01 Retirement Notice

ResourceType: microsoft.sql/servers
Recommendation ID: 9d190e63-71f2-4732-994f-bb6074b91e5d

Support for TLS 1.0 and TLS 1.1 in Azure SQL Managed Instance is ending

Upgrade TLS to the latest version. Support for TLS 1.0 and TLS 1.1 in Azure SQL Managed Instance is ending.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Configure Minimal TLS Version - SQL Managed Instance - Azure SQL Managed Instance

ResourceType: microsoft.sql/managedinstances
Recommendation ID: 2ed2b058-8bf0-459d-9674-6fdf8e39e11a

Azure Stack HCI

Upgrade to the latest version of AKS enabled by Arc

Upgrade to the latest version of API/SDK of AKS enabled by Azure Arc for new functionality and improved stability.

Potential benefits: AKS enabled by Azure Arc has improved stability.

Impact: High

For more information, see Azure SDK Releases

ResourceType: microsoft.azurestackhci/clusters
Recommendation ID: 09e56b5a-9a00-47a7-82dd-9bd9569eb6ed
Subcategory: ServiceUpgradeAndRetirement

Upgrade to the latest version of AKS enabled by Arc

Upgrade to the latest version of API/SDK of AKS enabled by Azure Arc for new functionality and improved stability.

Potential benefits: The latest version of AKS enabled by Azure Arc with new functionality and improved stability.

Impact: Low

For more information, see Azure SDK Releases

ResourceType: microsoft.azurestackhci/clusters
Recommendation ID: 2ac72093-309f-41ec-bf9d-55e9fc490563
Subcategory: ServiceUpgradeAndRetirement

Azure Synapse Analytics

Azure Synapse runtime for Apache Spark 3.4 is being retired.

Azure Synapse runtime for Apache Spark 3.4 is being retired and disabled.

Potential benefits: Avoid potential disruptions for the applications

Impact: High

For more information, see Azure updates

ResourceType: microsoft.synapse/workspaces/bigdatapools
Recommendation ID: 5202f09f-6886-4daf-a2e2-21fea2672973

Azure Synapse runtime for Apache Spark 3.3 is being retired.

Azure Synapse runtime for Apache Spark 3.3 is retired and disabled.

Potential benefits: Avoid potential disruptions for the applications

Impact: High

For more information, see Azure updates

ResourceType: microsoft.synapse/workspaces/bigdatapools
Recommendation ID: 90fc2705-3d75-44f8-87c2-052e331df519

Migrate to Eventhouse in Microsoft Fabric

Synapse Data Explorer (Preview) is retiring. Migrate to Eventhouse in Real-Time Intelligence, part of Microsoft Fabric.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.synapse/workspaces/kustopools
Recommendation ID: 439a275e-50fd-412d-8167-8297b32ee12d

Synapse Data Explorer (Preview) will be retired

Workloads running on Synapse Data Explorer will be deleted, and the associated application data will be lost.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.synapse/workspaces/kustopools
Recommendation ID: 8c05b9dd-60b1-4637-a6c3-5efac13ede7c

Azure VMware Solution

Migrate AV36P nodes to a new Azure VMware Solution node type

AV36P node type is retiring. Migrate from AV36P nodes to a new Azure VMware Solution node type before the end of current AV36P reserved instance term.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.avs/privateclouds
Recommendation ID: 42be4c34-135c-4ec7-b3a6-dd3b8ed7b049

Migrate AV36 nodes to a new Azure VMware Solution node type

The AV36 node type is retiring. Migrate from AV36 nodes to a new Azure VMware Solution node type before the end of the current AV36 reserved instance term.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.avs/privateclouds
Recommendation ID: 0601549e-0144-4144-9a25-a2644fdf5f22

Migrate AV52 nodes to a new Azure VMware Solution node type

The AV52 node type is retiring. Migrate from AV52 nodes to a new Azure VMware Solution node type before the end of the current AV52 reserved instance term.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.avs/privateclouds
Recommendation ID: afa137b9-4f71-42bb-92f9-e24a1e3d42df

Batch

Migrate Azure Batch Pools from Av2, F, Fs, Fsv2, G, Gs, Lsv2

Av2-series, F-series, Fs-series, Fsv2-series, G-series, Gs-series, and Lsv2-series Virtual Machines for Azure Batch pools are being retired. Need to migrate to Dsv5/Ddsv5/Dasv5 (general purpose/compute); Lsv3/Lasv3 (storage/memory optimized); Dlsv6/Falsv6 (compute optimized).

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: bdc11098-207d-4e5f-9d00-ec506a407464

Migrate Azure Batch Pools from D, Ds, Dv2, Dsv2, Ls Virtual Machines

Dsv2-series, and Ls-series Virtual Machines for Azure Batch pools are being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Retired VM Sizes Migration Guide - Azure Virtual Machines

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: c081d84e-3811-478b-b083-c8bb09b99ed7

Migrate Azure Batch Pools to VMs that support encryption at host

Azure Disk Encryption (ADE) for Azure Virtual Machines and Virtual Machine Scale Sets are being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Migrate from Azure Disk Encryption to encryption at host - Azure Virtual Machines

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: 6c4cd580-41fb-4f20-977b-3be3cbead46e

Availability in select regions is retiring

Azure Batch is retiring in the following regions: India West, China North 1, China East 1, USDoD East, and USDoD Central. Azure Batch isn't retiring in any other regions. This notification is strictly for the regions mentioned.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: 5c23301a-1a3c-46c5-b4e5-c0bb2b91b36c

Classic compute node communication model is retiring

The classic compute node communication model is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: 2a857ec5-3fa1-4e25-8959-05147ffaa66a

Migrate batch pools from HBv2 to newer virtual machine SKUs

HBv2-series virtual machine sizes are retiring. To ensure continuity and improved performance, transition to one of the current‑generation Azure HPC VM families, Azure HBv5‑series or Azure HX‑series.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: bdb3cf17-47a1-4727-ab02-98856925e50f

Migrate batch pools from HCv1 to newer virtual machine SKUs

HC-series virtual machine (VM) sizes are retiring. To ensure continuity and improved performance, transition to one of the current‑generation Azure HPC VM families, Azure HBv5‑series or Azure HX‑series.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: 0e613505-c557-41b8-90fd-2946528db0f2

Migrate workload to a supported Windows Server image

Azure Batch is retiring support for Windows Server 2016. Migrate workload to a supported Windows Server image.

Potential benefits: Avoid service disruption.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: df47adb1-1b61-4091-911a-d776f85ae81c

NP, HC, and HBv2-series VM family retirement in Azure Batch pools

NP-series, HC-series, and HBv2-series virtual machines are retiring. Migrate Batch pools to a newer VM series before the retirement date.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Update pool properties - Azure Batch

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: 3e7bb96a-9aa8-494c-8e43-fc1108a35a9d

Classic deployment model storage

Action required: Migrate classic storage accounts by 8/30/2024

Migrate your classic storage accounts to Azure Resource Manager to ensure business continuity. Azure Resource Manager will provide all of the same functionality plus a consistent management layer, resource grouping, and access to new features and updates.

Potential benefits: Maintain the ability to manage your data

Impact: High

For more information, see We're retiring classic storage accounts on August 31, 2024 - Azure Storage

ResourceType: microsoft.classicstorage/storageaccounts
Recommendation ID: fd04ff97-d3b3-470a-9544-dfea3a5708db

The legacy version of the Azure Storage Data Movement Library (v2) is retiring

The modern version of the Azure Storage Data Movement Library offers important upgrades including checkpointing, shared infrastructure with Azure Storage v12 client libraries, and provides improved performance and reliability.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.classicstorage/storageaccounts
Recommendation ID: 3b56a230-55c4-410f-89e6-d8d596f78593
Subcategory: ServiceUpgradeAndRetirement

Classic deployment model virtual machine

Cloud Services (classic) is retiring. Migrate before 31 Aug 2024

Cloud Services (classic) is retiring. To avoid any loss of data or business continuity, migrate off before 31 Aug 2024.

Potential benefits: Continuity of your service

Impact: Medium

For more information, see Migrate Azure Cloud Services (classic) to Azure Cloud Services (extended support)

ResourceType: microsoft.classiccompute/domainnames
Recommendation ID: 13ff4efb-6c84-4684-8838-52c123e3e3a2
Subcategory: ServiceUpgradeAndRetirement

Cognitive Services

Upgrade your application to use the latest API version from Azure OpenAI

An Azure OpenAI resource with an older API version lacks the latest features and functionalities. We recommend that you use the latest REST API version.

Potential benefits: Our new API versions contain the latest and greatest features and capabilities.

Impact: Medium

For more information, see Azure OpenAI Service REST API reference - Azure OpenAI

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 13fed411-54aa-4923-b830-23b51539d79d
Subcategory: ServiceUpgradeAndRetirement

Quota exceeded for this resource

If the quota for your resource is exceeded your resource becomes blocked. You can wait for the quota to automatically get replenished soon, or, to use the resource again now, upgrade it to a paid SKU.

Potential benefits: If you upgrade to a paid SKU you can use the resource again today.

Impact: Medium

For more information, see Plan and manage costs for Microsoft Foundry - Foundry

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 3f83aee8-222d-445c-9a46-2af5fe5b4777
Subcategory: Scalability

Migrate to named entity recognition

Entity linking in Azure AI Language is retiring. Consider a replacement solution such as named entity recognition in Azure AI Language that supports entities but doesn't provide a link to a public page.

Potential benefits: Maintain entity identification capabilities

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 41853861-bc9a-42b9-8ffc-f34dbaf07c00

Migrate away from Azure Custom Vision

Azure Custom Vision is retiring. Plan for migration to alternative solutions.

Potential benefits: Ensure business continuity and minimize disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: d5da3480-071a-49d8-b4ce-06a196d844c9

Migrate away from Azure AI Vision - Image Analysis API

The Azure AI Vision - Image Analysis API is retiring. Full support for all existing Image Analysis customers continues until retirement. To ensure business continuity and minimize disruption, customers should plan for migration to alternative solutions.

Potential benefits: Avoid service disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 85c750a4-a0cb-4610-a2df-074a5e775ddc

Migrate away from Azure AI Health Insights service

Azure AI Health Insights, Clinical Trials Matcher model, and Radiology Insights model are retiring. Azure AI Health Insights, Clinical Trials Matcher model, and Radiology Insights model are no longer available for use or integration.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 35c12ad3-0e52-45cd-bf53-16777b0f6a34

Migrate to conversational language understanding

Language Understanding (LUIS) is retiring. Migrate to conversational language understanding, a capability of Azure AI Service for Language.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 2b8347d8-bd08-4046-892d-8844f741b8b2

Migrate from Custom Commands to new Speech Services

Cognitive Services Custom Commands feature is being retired. Azure Cognitive Services is restructuring Speech Services to leverage next-generation dialog orchestration models for improved performance and accuracy.

Potential benefits: Ensure continuity and improved accuracy

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 8523d119-bfd8-4f91-b17d-13d6b34338c4

Migrate Computer Vision workloads to Computer Vision 3.2 API

Computer Vision v1.0, v2.0, v2.1, v3.0, and v3.1 APIs are retiring. You need to migrate your Azure Computer Vision workloads to Computer Vision 3.2 API.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 4d9bed4d-22e3-4dae-8eb3-ceb1bdd8c577

AI Services Anomaly Detector is being retired.

Until the retirement date, continue use of AI Services Anomaly Detector resources.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: e0e84b83-8be3-48d6-91bf-730d1d5fd745

AI Services Metrics Advisor is being retired.

After the retirement date, you can no longer use AI Services Metrics Advisor with the applications.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 8dca8881-92ae-480a-aa8c-0933efdf9e02

AI Services Personalizer is being retired.

You can no longer use AI Services Personalizer with the applications after the retirement date.

Potential benefits: Avoid potential disruptions for the applications

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: d4f522ba-0646-4c73-8ca6-7636f7ad119c

Azure Content Moderator is being retired.

The platform encourages users to explore our new offering Azure AI Content Safety that offers both new and updated capabilities to meet various content moderation needs.

Potential benefits: Avoid potential disruptions and use new capabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: e30a6464-0e05-4d48-b604-741074db3aa3

Transition some Azure AI Language features to Foundry-based models

Key Phrase Extraction, Sentiment Analysis & Opinion Mining, Custom Text Classification, Conversational Language Understanding (CLU), Custom Question Answering (CQA), Orchestration Workflow, Summarization, and Entity Linking are being retired.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 46a2ac77-9b96-4741-a036-76155cc3616c

Azure Document Intelligence v3.0 2022-08-31 API is being retired

Azure Document Intelligence v3.0 2022-08-31 API is being retired. Migrate to v4.0 2024-11-30 API.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 134edfc1-8479-4792-b19b-b47ac18a58ac

Azure QnAMaker is being retired.

Beginning October 1, 2022, you aren't be able to create new QnA Maker resources or knowledge bases. All QnA Maker resources and knowledge bases created before that date are supported until the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 5046219d-e79f-46bf-a68f-0ccb5166f5fd

Long audio API is being retired

The Long Audio API of Azure AI Speech is being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 7e42bc25-4cf7-47fc-a125-ef619cf7c6aa

S2, S3, and S4 price instances are being retired

Azure AI Translator S2-S4 billing instances are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 627cfbef-2bd0-4f15-8394-65b1f720ba78

Speech-to-text REST preview API v3.1-preview.1 is being retired

Speech-to-text REST preview API v3.1-preview.1 is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: ed76767e-3113-4540-872e-0e80fcd3f8d9

Studio v2.1 (Azure Document Intelligence) is being retired

The Document Intelligence GA API v2.1 is being retired and you need to migrate to a newer GA API version of Document Intelligence.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: b7c8556a-5977-49f2-8db0-b3a0e4252f5c

Transition to Azure AI Document Intelligence v3.1 API

Azure AI Document Intelligence v2.0 API is retiring. Transition to Azure AI Document Intelligence v3.1 API.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cognitiveservices/accounts
Recommendation ID: 28eea5a8-16a5-4e1a-94ef-3c967983e932

Container Registry

Use Premium tier for critical production workloads

Premium registries provide the highest amount of included storage, concurrent operations and network bandwidth, enabling high-volume scenarios. The Premium tier also adds features such as geo-replication, availability zone support, content-trust, customer-managed keys and private endpoints.

Potential benefits: Premium tier provides maximum performance and resiliency

Impact: High

For more information, see Azure Container Registry SKU Features and Limits - Azure Container Registry

ResourceType: microsoft.containerregistry/registries
Recommendation ID: af0cdbce-c610-499b-9bd7-b169cdb1bb2e
Subcategory: HighAvailability

Ensure Geo-replication is enabled for resilience

Geo-replication lets your registry serve image pulls from multiple regions. Without it, a regional outage can disrupt pulls and deployments. Enabling this reduces single-region risk, improves region-local pull performance, and strengthens failover resilience. Available in the Premium service tier.

Potential benefits: Reduced outage risk and faster region-local pulls.

Impact: High

For more information, see Geo-replication in Azure Container Registry - Azure Container Registry

ResourceType: microsoft.containerregistry/registries
Recommendation ID: dcfa2602-227e-4b6c-a60d-7b1f6514e690

2017-01-01-(GA) API (Azure Container Registry) is being retired

The 2017-01-01-(GA) API (Azure Container Registry) is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.containerregistry/registries
Recommendation ID: a5c46a88-2122-498c-a3c6-00d333698e2c

Docker Content Trust (DCT) is retiring and no longer available in Container Registry

Docker Content Trust (DCT) no longer meets the requirements of modern supply chain security for containers. As a result, DCT is retiring and is no longer available in Container Registry.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.containerregistry/registries
Recommendation ID: 1ce751c6-35b8-4468-ac4b-d3052a1ae511

Content Delivery Network

Renew the expired Azure Front Door customer certificate to avoid service disruption

When customer certificates for Azure Front Door Standard and Premium profiles expire, you might have service disruptions. To avoid service disruption, renew the certificate before it expires.

Potential benefits: Ensure service availability.

Impact: High

For more information, see Configure HTTPS for your custom domain - Azure Front Door

ResourceType: microsoft.cdn/profiles
Recommendation ID: 4e1c2077-7c73-4ace-b4aa-f11b36c28290

Re-validate domain ownership for the Azure Front Door managed certificate renewal

Azure Front Door cannot automatically renew the managed certificate because the domain isn't CNAME mapped to the AFD endpoint. To automatically renew the managed certificate, revalidate domain ownership.

Potential benefits: Ensure service availability.

Impact: High

For more information, see How to add a custom domain - Azure Front Door

ResourceType: microsoft.cdn/profiles
Recommendation ID: bfe85fd2-ee53-4c35-8781-7790da2107e1

Switch Secret version to 'Latest' for the Azure Front Door customer certificate

Configure the Azure Front Door (AFD) customer certificate secret to 'Latest' for the AFD to refer to the latest secret version in Azure Key Vault, allowing the secret can be automatically rotated.

Potential benefits: Latest version can be automatically rotated.

Impact: Medium

For more information, see Configure HTTPS for your custom domain - Azure Front Door

ResourceType: microsoft.cdn/profiles
Recommendation ID: 2c057605-4707-4d3e-bbb0-a7fe9b6a626b
Subcategory: Other

Validate domain ownership by adding DNS TXT record to DNS provider

Validate domain ownership by adding the DNS TXT record to your DNS provider. Validating domain ownership through TXT records enhances security and ensures proper control over your domain.

Potential benefits: Ensure service availability.

Impact: High

For more information, see How to add a custom domain - Azure Front Door

ResourceType: microsoft.cdn/profiles
Recommendation ID: 9411bc9f-d181-497c-b519-4154ae04fb00

Avoid placing Traffic Manager behind Front Door

Using Traffic Manager as one of the origins for Front Door isn't recommended, as this can lead to routing issues. If you need both services in a high availability architecture, always place Traffic Manager in front of Azure Front Door.

Potential benefits: Increase your workload resiliency

Impact: Medium

For more information, see Azure Front Door - Best practices

ResourceType: microsoft.cdn/profiles
Recommendation ID: 825ff735-ed9a-4335-b132-321df86b0e81
Subcategory: Other

Consider having at least two origins

Multiple origins support redundancy by distributing traffic across multiple instances of the application. If one instance is unavailable, then other backend origins can still receive traffic.

Potential benefits: Increase your workload resiliency

Impact: High

For more information, see Architecture Best Practices for Azure Front Door - Microsoft Azure Well-Architected Framework

ResourceType: microsoft.cdn/profiles
Recommendation ID: 589ab0b0-1362-44fd-8551-0e7847767600
Subcategory: HighAvailability

Use the same domain name on Front Door and your origin

When you rewrite the Host header, request cookies and URL redirections might break. When you use platforms like Azure App Service, features like session affinity and authentication and authorization might not work correctly. Make sure to validate whether your application is going to work correctly.

Potential benefits: Ensure application integrity by preserving original host name

Impact: Medium

For more information, see Azure Front Door - Best practices

ResourceType: microsoft.cdn/profiles
Recommendation ID: 79f543f9-60e6-4ef6-ae42-2095f6149cba
Subcategory: Other

Use managed TLS certificates

When Front Door manages your TLS certificates, it reduces your operational costs, and helps you to avoid costly outages caused by forgetting to renew a certificate. Front Door automatically issues and rotates the managed TLS certificates.

Potential benefits: Ensure service availability by having Front Door manage and rotate your certificates

Impact: Medium

For more information, see Azure Front Door - Best practices

ResourceType: microsoft.cdn/profiles
Recommendation ID: 5185d64e-46fd-4ed2-8633-6d81f5e3ca59
Subcategory: Other

Switch from managed certificates to BYOC by August 15, 2025 or migrate to AFD Standard/Premium

Starting 15 August 2025, Azure CDN will no longer support - new domain onboarding, new profile creation or Switching from BYOC to managed certificates. Existing managed certificates will auto-renew by 15 August 2025, valid until April 14, 2026, after which managed certs will no longer be supported.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.cdn/profiles
Recommendation ID: 600a3187-48dd-495b-a9e8-320f83571b01

Azure CDN Standard from Microsoft (classic) is retiring

To avoid service disruptions, migrate to Azure Front Door Standard or Premium.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.cdn/profiles
Recommendation ID: 52ff3019-62b0-4905-b016-da35fa6bbddc

Azure Data Factory

Enable Modern trusted service access for Azure Data Factory to strengthen network security

Azure Data Factory Modern trusted service setting isn’t enabled for secure access to Azure Storage and Azure Key Vault. Enable it to simplify secure connectivity to protected resources and align your factory with current security standards.

Potential benefits: Improve Azure Data Factory security, availability, and support.

Impact: High

For more information, see Modern mode for trusted service firewall bypass in Azure Data Factory - Azure Data Factory

ResourceType: microsoft.datafactory/factories
Recommendation ID: a8a24eaf-864b-406d-b894-c9cfd55154f5

Memory Optimized Data Flows is being retired

Azure Data Factory Memory Optimized Data Flows is being retired. Going forward, all Azure Data Factory Data Flows will use the General Purpose SKU that will provide performance that is superior to current Memory Optimized and at the General Purpose price.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.datafactory/factories
Recommendation ID: 8df0d8ad-a3c9-49d0-bf72-f6a3d4793e0a

Entra Domain Services

Azure Managed Grafana Essential is being retired

Essential SKU workspaces are disabled and dashboards do no longer render. Migrate to Azure Monitor Dashboards with Grafana or upgrade to the Azure Managed Grafana Standard SKU.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.aad/domainservices
Recommendation ID: 5605b630-3f2f-4787-a600-1f3b5042a996

Migrate to TLS 1.2 or above for Entra domain services

Support for TLS 1.0 and 1.1 on Entra domain services is retiring. Update the TLS policy to the latest version.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.aad/domainservices
Recommendation ID: e756137a-ce78-4586-a777-1059cb9d14c5

Transition from FXT Edge Filer

Azure FXT Edge Filer is retiring. Plan the migration to avoid service disruption.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.aad/domainservices
Recommendation ID: a36da88c-c25b-47d1-b3da-e3647a52c6bf

Transition to Azure RBAC roles

Azure classic administrator roles (Co-Administrator, Service Admin) retire on 31 August 2024. All Azure classic resources and Azure Service Manager also retire. Starting 3 April 2024, adding new Co-Administrator roles is disabled.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.aad/domainservices
Recommendation ID: 54594c92-883e-4256-a6b5-e43a70fcac2b

Upgrade to latest Price Sheet API

Older versions of the EA Azure Price Sheet – Download by Billing Account API retire soon. Transition to version 2023-11-01 to leverage enhancements like RI pricing, market price, base price, and improved metadata.

Potential benefits: Access enhanced pricing data

Impact: High

For more information, see Azure updates

ResourceType: microsoft.aad/domainservices
Recommendation ID: e5dbad94-0be4-4bb4-948a-ccbf2fd87050

Event Grid

Event Grid requires using TLS 1.2 or later

Support for TLS 1.0 and TLS 1.1 ends on the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.eventgrid/namespaces
Recommendation ID: 64f39d77-dca5-479a-b2d8-916d24fe9a61

Event Grid requires using TLS 1.2 or later

Support for TLS 1.0 and TLS 1.1 ends on the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.eventgrid/partnernamespaces
Recommendation ID: b91050c5-907e-4ab7-8216-70bb36dc4360

Event Grid requires using TLS 1.2 or later

Support for TLS 1.0 and TLS 1.1 ends on the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.eventgrid/topics
Recommendation ID: ef89da0a-b5d9-4f20-adfb-defbb7f6c1a4

Event Grid requires using TLS 1.2 or later

Support for TLS 1.0 and TLS 1.1 ends on the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates

ResourceType: microsoft.eventgrid/domains
Recommendation ID: 2cbab16d-94e4-47ea-b91e-5e8ad06e007e

Event Hubs

Set up Geo-replication for Event Hubs namespace

Set up Geo-replication on Event Hubs namespaces with Premium or Dedicated SKUs to ensure high availability and regional failover. This new feature replicates both metadata and data, helping protect against outages and disasters for mission-critical workloads.

Potential benefits: Ensures high availability and regional failover

Impact: High

For more information, see Azure Event Hubs geo-replication - Azure Event Hubs

ResourceType: microsoft.eventhub/namespaces
Recommendation ID: 36901a23-7263-44cb-9986-d60513ad97af
Subcategory: DisasterRecovery

Enable auto-inflate on Event Hubs Standard tier

Enable auto-inflate on Event Hubs Standard tier namespaces to automatically scale up throughput units (TUs), meeting usage needs and preventing data ingress or egress throttle scenarios by adjusting to allowed rates.

Potential benefits: Prevents throttling by autoscaling TUs

Impact: High

For more information, see Automatically scale up throughput units in Azure Event Hubs - Azure Event Hubs

ResourceType: microsoft.eventhub/namespaces
Recommendation ID: e1e0d94e-4805-42e6-b6b4-3bbcb4909c78
Subcategory: Scalability

Enable zone redundancy in supported regions

Enable zone redundancy in cluster configuration for supported regions.

Potential benefits: Maintain event streaming active during outages

Impact: High

For more information, see Azure Event Hubs: Data streaming platform with Kafka support - Azure Event Hubs

ResourceType: microsoft.eventhub/clusters
Recommendation ID: 508f935c-bd6c-4bd0-a788-78f2c611fa44

Migrate Azure Event Hubs deployments to ARM API version 2021-11-01 or later

Using ARM API version 2021-11-01 or later for Azure Event Hubs improves deployment compatibility and reliability, and provides access to current platform capabilities. Update templates, scripts, and SDKs to standardize deployments across environments.

Potential benefits: Ensures reliable Event Hubs deployments

Impact: High

For more information, see Steps to upgrade control plane API references for Azure Service Bus, Event Hubs, and Relay

ResourceType: microsoft.eventhub/namespaces
Recommendation ID: bee1c54b-36cb-4409-bf42-f5dd57ef3406

Fluid Relay

Upgrade your Azure Fluid Relay client library

If you invoke the Azure Fluid Relay service by using an old client library, it might cause application problems. To keep your application running, upgrade your Azure Fluid Relay client library to the latest version. Upgrading gives you the most up-to-date functionality, and improvements in performance and stability.

Potential benefits: Improved reliability

Impact: Medium

For more information, see Version compatibility with Fluid Framework releases - Azure Fluid Relay

ResourceType: microsoft.fluidrelay/fluidrelayservers
Recommendation ID: a5e8a0f8-2c84-407a-b3d8-f371d684363b
Subcategory: ServiceUpgradeAndRetirement

HDInsight

Drop and recreate the HDInsight clusters (certificate rotation round 2) to apply critical updates

The HDInsight service attempted to apply a critical certificate update on your running clusters. However, due to some custom configuration changes, we're unable to apply the updates on all clusters. To prevent those clusters from becoming unhealthy and unusable, drop and recreate your clusters.

Potential benefits: Ensure cluster health and stability

Impact: High

For more information, see Set up clusters in HDInsight with Apache Hadoop, Apache Spark, Apache Kafka, and more

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 69740e3e-5b96-4b0e-b9b8-4d7573e3611c
Subcategory: Other

Restart brokers on your Kafka Cluster Disks

When data disks used by Kafka brokers in HDInsight clusters are almost full, the Apache Kafka broker process can't start and fails. To mitigate, find the retention time for every topic, back up the files that are older, and restart the brokers.

Potential benefits: Avoid Kafka broker issues

Impact: High

For more information, see Broker fails to start due to a full disk in Azure HDInsight

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 35e3a19f-16e7-4bb1-a7b8-49e02a35af2e

Upgrade the cluster to the latest HDInsight image

A cluster doesn't have the latest image upgrades. The cluster was created 1 year ago. The platform recommends using the latest HDInsight images for the best open source updates, Azure updates, and security fixes. The recommended maximum duration for cluster upgrades is six months or less.

Potential benefits: Get the latest fixes and features

Impact: High

For more information, see Before you start with Azure HDInsight

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 8f163c95-0029-4139-952a-42bd0d773b93

VM agent is 9.9.9.9. Upgrade the cluster.

Our records indicate that one or more of your clusters are using images dated February 2022 or older (image versions 2202xxxxxx or older). There is a potential reliability issue on HDInsight clusters that use images dated February 2022 or older. Consider rebuilding your clusters with newest image.

Potential benefits: Improved Reliability in Scaling and Network connectivity

Impact: High

For more information, see Migrate cluster to a newer version - Azure HDInsight

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: e4635832-0ab1-48b1-a386-c791197189e6

HDInsight 4.0 is being retired

Customers running HDInsight 4.0 no longer receive support and no new clusters can be created after the retirement date.

Potential benefits: Avoid potential disruptions and use new capabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 32b83a78-f586-425a-afd2-52accec61d65

HDInsight 5.0 is being retired

Customers running HDInsight 5.0 no longer receive support.

Potential benefits: Avoid potential disruptions and use new capabilities

Impact: High

For more information, see Azure updates

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: f0466e91-184d-4a0d-8e18-25c1cf7a4c1c

Deploy nodes across zones or multi-cluster to keep analytics running

Deploy HDInsight clusters in a zone-aware configuration or use multiple clusters pinned to different zones.

Potential benefits: Continuous analytics during zone failures

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 66bfeb4c-1351-4672-b410-3ecea872b17d

Key Vault

Azure Key Vault API versions prior to 2026-02-01 are being retired

Transition to API version 2026-02-01. Azure role-based access control (RBAC) will be the default access control model for all newly created vaults. Existing key vaults will continue using their current access control model.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Prepare for Key Vault API version 2026-02-01 and later - Azure RBAC as default

ResourceType: microsoft.keyvault/vaults
Recommendation ID: 7ff06874-39e9-41be-9552-fa1ae2a83c88

Enable diagnostic logs in Key Vault

Enable logs, set up alerts, and adhere to retention requirements for improved monitoring and security of Key Vault access. The logs detail the frequency and identity of users.

Potential benefits: Enhanced monitoring and security compliance

Impact: Low

For more information, see Azure Key Vault logging

ResourceType: microsoft.keyvault/vaults
Recommendation ID: 2ee11d3b-0e4c-48ae-84a9-ca3bdf998fd2

Enable purge protection on key vaults

Purge protection secures against malicious deletions by enforcing a retention period for soft deleted key vaults. No one, not even insiders or Microsoft, can purge your key vaults during this period. This protection prevents permanent data loss.

Potential benefits: Protects from insider attacks, avoids data loss

Impact: Medium

For more information, see Azure Key Vault soft-delete

ResourceType: microsoft.keyvault/vaults
Recommendation ID: ffb6883e-a7c2-470b-91fc-aa3a21f9ed59

Migrate to HSM Platform 2 Keys

To keep your operations secure and working properly, transition to HSM Platform 2 keys as soon as possible.

Potential benefits: Avoid service disruptions and maintain secure operations.

Impact: Medium

For more information, see Azure updates.

ResourceType: microsoft.keyvault/managedhsms
Recommendation ID: a6d218b1-a826-4183-8cc8-4b111371e47b

Log Analytics

HTTP Data Collector API is retiring

The HTTP Data Collector API is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Migrate From the HTTP Data Collector API to the Logs Ingestion API - Azure Monitor

ResourceType: microsoft.operationalinsights/workspaces
Recommendation ID: e0f4abac-5cd4-4d57-9474-0e86d520b465

Log Analytics Alert API is retiring

The Log Analytics Alert API is retiring. Transition to using the Scheduled Query Rules API for log search alerts.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Upgrade Legacy Rules Management to the Current Azure Monitor Scheduled Query Rules API - Azure Monitor

ResourceType: microsoft.operationalinsights/workspaces
Recommendation ID: ac4c2c10-1af3-4224-a316-aff895f4f308

Migrate from Dependency Agent and VM Insights Map

Dependency Agent and VM Insights Map are retiring. To continue collecting data about processes running on virtual machines and external process dependencies, consider a replacement solution from the Azure Marketplace.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see VM Insights Map and Dependency Agent retirement guidance - Azure Monitor

ResourceType: microsoft.operationalinsights/workspaces
Recommendation ID: 3055fad1-ed7f-4858-aaee-b198749ea3b8

The batch API in Azure Monitor Log Analytics is retiring

The batch API in Azure Monitor Log Analytics is retiring. To avoid disruptions, switch to the standard API request. Update workloads by splitting batch queries into single queries and using the new request and response formats for Azure Monitor Log Analytics data access.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Migrate from Logs Query API Batch and Beta to Latest Version - Azure Monitor.

ResourceType: microsoft.operationalinsights/workspaces
Recommendation ID: fb7993fe-daa7-443c-8c20-f6edcda21ac3

Media Services

MICROSOFT.FILESHARES

Enable Vault Backup on your Azure file shares

Secure your data by enabling vault backups for your azure file shares.

Potential benefits: Protection for your Azure File Shares

Impact: Medium

For more information, see Manage Azure Files backups - Azure Backup

ResourceType: microsoft.fileshares/fileshares
Recommendation ID: b263dad8-02a1-4546-a496-3dc5361c3f0c

Microsoft Sentinel

Alert-trigger playbooks -Microsoft Sentinel is retiring

Alert-trigger playbooks -Microsoft Sentinel is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.sentinelplatformservices/sentinelplatformservices
Recommendation ID: aa6d0dad-580f-4ec6-8f73-db67c1ee26d6

Playwright Testing

Migrate to Azure App Testing

To avoid service disruptions, users should migrate existing Playwright workloads to Playwright Workspaces in Azure App Testing.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.azureplaywrightservice/accounts
Recommendation ID: 2c1fc2d7-3e01-4bce-b306-5d506c4d7f2a

RecommendationsService

Azure Intelligent Recommendations Service is retiring

Due to strategy changes, Azure Intelligent Recommendations service is retiring. On the retirement date, workloads running Intelligent Recommendations and the Intelligent Recommendations Machine Learning models are deleted. The platform encourages investigation of other options.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.recommendationsservice/accounts
Recommendation ID: aba0b711-0b25-40d8-9cad-ea3786245252

Service Bus

Use Service Bus premium tier for improved resilience

When running critical applications, the Service Bus premium tier offers better resource isolation at the CPU and memory level, enhancing availability. It also supports geo-replication feature enabling full recovery from regional disasters.

Potential benefits: Stronger resiliency with CPU isolation and geo-replication

Impact: Low

For more information, see Azure Service Bus premium messaging tier - Azure Service Bus

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 29765e2c-5286-4039-963f-f8231e56cc3e
Subcategory: HighAvailability

Use Service Bus autoscaling feature in the premium tier for improved resilience

When running critical applications, enabling the auto scale feature allows you to have enough capacity to handle the load on your application. Having the right amount of resources running can reduce throttling and provide a better user experience.

Potential benefits: Enabling autoscale prevents users from capacity constraints

Impact: High

For more information, see Azure Service Bus - Automatically update messaging units - Azure Service Bus

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 68e62f5c-4ed1-4b78-a2a0-4d9a4cebf106

Set up Geo-replication for Service Bus namespace

Set up Geo-replication on Premium Service Bus namespaces to ensure high availability and regional failover. This new feature replicates both metadata and data, helping protect against outages and disasters for mission-critical workloads.

Potential benefits: Ensures high availability and regional failover

Impact: High

For more information, see Azure Service Bus Geo-Replication - Azure Service Bus

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 15a7e73b-943e-4cf5-847d-f54ed39c33f1
Subcategory: DisasterRecovery

Migrate to latest Azure SDK libraries

Older Azure Service Bus SDK libraries (WindowsAzure.ServiceBus, Microsoft.Azure.ServiceBus, com.microsoft.azure.servicebus) will be retired. Move to the latest Azure SDK libraries for security updates and improved capabilities.

Potential benefits: Maintain security & performance

Impact: High

For more information, see Azure updates

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 55bd2c8e-da67-4e38-9af7-eb2123b0ca5e

Use ARM API version 2021-11-01 or later for Azure Service Bus namespaces

Azure Resource Manager (ARM) API versions 2014-09-01, 2015-08-01, and 2016-07-01 for Azure Service Bus retire on 30 September 2026. After that date, requests that use those versions fail and namespace management breaks. Move templates, scripts, and SDKs to API version 2021-11-01 or later.

Potential benefits: Ensure reliable Service Bus namespace management

Impact: High

For more information, see Steps to upgrade control plane API references for Azure Service Bus, Event Hubs, and Relay

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 15ac3f22-d7eb-4d19-b5bc-7e4a2e4eeefe

Service Fabric

Migrate to the Semantic Python SDK

The Spark native connector for Semantic Link is retiring. The Semantic Python SDK offers comparable functionality and enhanced support.

Potential benefits: Ensure continued support and improved security

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.servicefabric/clusters
Recommendation ID: 0523982f-9aef-4211-8466-3330121f34c8

Distribute node types across zones to maintain quorum during faults

Create node types with placement across multiple zones. Ensure durability level is set to Silver or Gold for quorum-based fault tolerance across zones.

Potential benefits: Maintains quorum across zone failures

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.servicefabric/clusters
Recommendation ID: c26fdcea-6dc5-4d41-874b-5bc2462834a7

Enable a zone-aware managed cluster that automatically recovers from zone failures

Create node types with placement across multiple zones. Ensure durability level is set to Silver or Gold for quorum-based fault tolerance across zones.

Potential benefits: Automated zone-aware cluster resilience

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.servicefabric/managedclusters
Recommendation ID: 09bbb8ce-4e21-4cd6-99b8-41e2ded05d95

Service groups

Assign resilience goal to service group

Assign resilience goals to your service group to enable Azure to monitor adherence to key resilience targets and proactively identify areas that require attention.

Potential benefits: Improve service and application resilience

Impact: Medium

For more information, see How to Assign Goals to Your Service Group.

ResourceType: microsoft.management/servicegroups
Recommendation ID: 9ae3e2dd-c71a-45b8-a074-d95268d6c730

Create a zonal recovery plan for your service groups

Create a zonal recovery plan to seamlessly recover during a zone outage.

Potential benefits: Improved outage readiness

Impact: Medium

For more information, see How to Assign Goals to Your Service Group.

ResourceType: microsoft.management/servicegroups
Recommendation ID: cec2d45b-e50d-4b7f-9d1d-3d51f901b68c

Create an Availability Zone Down drill for your service groups

Create an Availability Zone Down drill template to validate the resilience of the application via a simulated outage.

Potential benefits: Improved outage readiness

Impact: Medium

For more information, see How to Assign Goals to Your Service Group.

ResourceType: microsoft.management/servicegroups
Recommendation ID: be4ce46f-2a88-4aae-b7e9-10c4efefb695

Execute the zone down drill for your service group

Execute an Availability Zone Down drill template to validate the resilience of the application via a simulated outage.

Potential benefits: Improved outage readiness

Impact: Medium

For more information, see How to Assign Goals to Your Service Group.

ResourceType: microsoft.management/servicegroups
Recommendation ID: caa221ac-931a-4145-a674-ac7395ab1a72

Fix the zone recovery plan for your service groups

Fix the zone recovery plan to successfully recover during a zone outage.

Potential benefits: Improved outage readiness

Impact: Medium

For more information, see How to Assign Goals to Your Service Group.

ResourceType: microsoft.management/servicegroups
Recommendation ID: 74bd8b9d-7d66-4f84-95ce-046cccbc6016

Service Map

Migrate to Azure Monitor VM insights when Service Map is retired.

To monitor connections between servers, processes, inbound and outbound connection latency, and ports across any TCP-connected architecture, migrate to Azure Monitor VM insights.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.operationsmanagement/solutions
Recommendation ID: 5da9649e-147b-4762-a5a5-0abea68e0e9b

SQL Server on Azure Virtual Machines

Enable Azure backup for SQL on your virtual machines

For the benefits of zero-infrastructure backup, point-in-time restore, and central management with SQL AG integration, enable backups for SQL databases on your virtual machines using Azure backup.

Potential benefits: SQL aware backups with no-infra for backup, centralized management, AG integration and point-in-time restore

Impact: Medium

For more information, see Back up SQL Server databases to Azure - Azure Backup

ResourceType: microsoft.sqlvirtualmachine/sqlvirtualmachines
Recommendation ID: 77f01e65-e57f-40ee-a0e9-e18c007d4d4c
Subcategory: DisasterRecovery

Migrate to Azure Update Manager

Automated Patching for SQL Server on Azure VMs will be retired and replaced with Azure Update Manager. The new solution offers centralized update management, custom schedules, and compliance reporting for better efficiency.

Potential benefits: Streamlined update management

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.sqlvirtualmachine/sqlvirtualmachines
Recommendation ID: e44bbf9e-55e0-4f18-9ec3-812b10b93fc2

Deploy SQL Virtual Machines across availability zones

Deploying SQL Virtual Machines across availability zones improves resiliency by reducing the impact of zone-level failures when combined with supported high availability configurations.

Potential benefits: Improved resiliency

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.sqlvirtualmachine/sqlvirtualmachines
Recommendation ID: cb5f37e8-2ce6-4f50-baa0-a2a8c25a2293

Storage

Enable zone redundancy for storage accounts to improve high availability and resiliency

By default, data in a storage account is replicated three times within a single data center. If the application must be highly available, convert the data to Zone Redundant Storage (ZRS). ZRS takes advantage of Azure availability zones to replicate data across three separate data centers.

Potential benefits: Achieve higher availability for the application.

Impact: High

For more information, see Data redundancy - Azure Storage

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 4c10f447-fc3d-48b5-931d-23cea8486023
Subcategory: HighAvailability

Configure backup and enable soft delete for Azure Files to provide data protection

Configure backup and enable soft delete to store data on a schedule and make the backup available to restore as needed.

Potential benefits: Protect data against accidental loss or corruption

Impact: Medium

For more information, see Accidental Delete Protection for Azure Files - Azure Backup

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: f39dc18e-4830-4027-962b-e27cb9bb1458

Migrate to geo-redundant storage for standard files replicated using locally redundant storage

Migrate storage accounts with standard files to geo-redundant storage to replicate data across Azure regions, ensure durability, and protect against regional failures.

Potential benefits: Increase data durability and availability across regions.

Impact: High

For more information, see Change how a storage account is replicated - Azure Storage

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: b18744b9-2718-4617-9cdd-f6fad6cbc0cf

Configure backup for Azure Files to provide data protection

Configure backup to store data on a schedule and make the backup available to restore as needed.

Potential benefits: Protect data against accidental loss or corruption

Impact: Medium

For more information, see Back up Azure Files in the Azure portal - Azure Backup

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: ebe76d14-0f9e-4fd2-b453-f04f8852dc8f

Upgrade general-purpose v1 storage accounts

Migrate to general-purpose v2 storage account or specialized alternatives based on workload requirements, such as BlockBlobStorage or FileStorage.

Potential benefits: Avoid service disruptions and gain improved performance

Impact: High

For more information, see Azure updates

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 1d70919c-1a4a-4f79-8300-bb576c291e9d

Enable Soft Delete

Soft Delete puts deleted data into a soft deleted state instead of permanently deleted. When data is overwritten, a soft deleted snapshot is generated to save the state of the overwritten data. You can configure the amount of time soft deleted data is recoverable before it permanently expires.

Potential benefits: Restore blobs or snapshots after overwrite or deletion

Impact: Medium

For more information, see Soft delete for blobs - Azure Storage

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 42dbf883-9e4b-4f84-9da4-232b87c4b5e9

Migrate BlobFuse to version 2

Migrate BlobFuse to BlobFuse2. All future enhancements and innovations related to Azure Blob Storage file system access exclusively focuses on BlobFuse2.

Potential benefits: Enhancements to Azure Blob Storage file system access

Impact: High

For more information, see Azure updates

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 26cbb942-7c43-4f4b-af10-116f5b107acc

Support for TLS 1.0 and TLS 1.1 in Azure storage accounts is ending

Upgrade TLS to latest version. Support for TLS 1.0 and TLS 1.1 in Azure storage accounts is ending.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see TLS 1.0 and 1.1 support will be removed for new & existing Azure storage accounts starting Feb 2026

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: ced5fa9f-b5bf-4982-9f25-8190fb36dfca

Migrate to Standard endpoints for blob storage account

AzureDnsZone endpoints (preview) for Azure Blob storage accounts is retiring. Transition to Standard endpoints for all new and existing blob storage account deployments.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 7be41487-135c-4bee-901f-b4e8cd5e9180

Upgrade to AES-256 to avoid losing Azure Files access.

RC4 encryption in Azure Files Storage Accounts and Active Directory Objects is being retired

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Troubleshoot Encryption Changes Affecting Azure Files - Azure

ResourceType: microsoft.storage/storageaccounts
Recommendation ID: 6015a8e7-c899-4724-b39d-4281ddcc2551

Subscriptions

Support for TLS 1.0 and TLS 1.1 in Azure Monitor is ending

Upgrade TLS to latest version. Support for TLS 1.0 and TLS 1.1 in Azure Monitor is ending.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Secure your Azure Monitor deployment - Azure Monitor

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: badb6a09-d33e-4e2a-82d8-8ed668db0aad

Best Practices (Azure Automanage) are being retired

Best Practices (Azure Automanage) are being retired.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: d63e646e-752a-40c0-aa76-b744a6b6949a

Azure Sphere is being retired

Azure Sphere OS and cloud services are being retired, including the first generation MT3620 microcontroller based platform. Migrate to a new hardware and connectivity stack.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Retirement - Azure Sphere

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: ee60d00e-823e-439d-971f-644fce1f1cb4

Set a minimum node count greater than zero on Microsoft Discovery Supercomputer nodepools

When a nodepool's minNodeCount is 0, the autoscaler can scale it to zero. Workloads dispatched while no nodes exist face cold-start delays or failures. Setting a minimum of at least 1 keeps baseline capacity available, reducing job latency and preventing timeouts for time-sensitive workflows.

Potential benefits: Prevent timeouts for time-sensitive scientific workflows

Impact: High

For more information, see Manage Supercomputer and Nodepools in Microsoft Discovery

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: 2d6324ac-055e-4657-a42c-a7ef571d4aad

Automatically grow and shrink HPC Pack cluster resources

Deploy Azure burst nodes (both Windows and Linux) in your HPC Pack cluster or create the HPC Pack cluster in Azure. The resources in the cluster can automatically grow or shrink, such as nodes or cores adjusting to the workload on the cluster.

Potential benefits: Efficient, uninterrupted execution

Impact: Medium

For more information, see HPC Pack cluster auto scale

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: d76068ef-16d9-423f-9cb1-e7df7191bad1

Classic (Azure Virtual Desktop) is retiring

Classic (Azure Virtual Desktop) is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure Virtual Desktop (classic) retirement - Azure

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: dbf205b2-84ad-4b5b-a69f-008bfb644c32

Conditional Access policies that use only the Require Approved Client App grant are retiring

Conditional Access policies that use only the Require Approved Client App grant are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Migrate approved client app to application protection policy in Conditional Access - Microsoft Entra ID

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: f0a802ce-63fa-4343-a7e4-d2f09becb999

HPC Pack 2016 is being retired

HPC Pack 2016 is being retired.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: 48960682-e549-4989-b6f8-c785a19b70e2

Proxy support - Azure Functions is being retired

Azure Functions Proxies are a limited subset of these capabilities that are no longer funded in to avoid duplication of functionality. Azure Functions Proxies will continue to remain in maintenance mode until 30 September 2025 after which they will no longer be supported.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: d369a4ab-978b-428f-97a7-ba8441ad8f87

Remove unwanted location constraints from Linux Pacemaker clusters

Use the migrate command in a Linux Pacemaker cluster to create a temporary prefer location constraint, moving a resource to a specified node for maintenance or testing. This constraint is temporary and should be removed after the task to revert to the original cluster configuration.

Potential benefits: Enhanced maintenance and failover handling

Impact: High

For more information, see Set up Pacemaker on RHEL in Azure

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: 05a63caf-3461-44bf-98a7-2f5d7f7f2a1e

SQL Server scenarios are being retired

Azure Database Migration Service (classic) - SQL Server scenarios are retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: b9dad077-2c94-436e-80c5-ed0e1ecd083a

Virtual Machines

Improve data reliability using Managed Disks

VMs in an Availability Set sharing storage accounts or scale units risk downtime from single-unit failures. Use Azure Managed Disks to isolate VM disks across units and eliminate single points of failure.

Potential benefits: Ensure business continuity through data resilience

Impact: High

For more information, see Overview of Azure Disk Storage - Azure Virtual Machines

ResourceType: microsoft.compute/availabilitysets
Recommendation ID: 02cfb5ef-a0c1-4633-9854-031fbda09946
Subcategory: HighAvailability

Ensure Azure Disks are in the same zone as your VM for higher resiliency and availability

Azure VMs can be regional or zonal. For higher resilience, use a zonal VM with the disk in the same zone to be isolated from zonal failures without disruptions to applications. For higher even resiliency and availability, migrate disks from LRS to ZRS.

Potential benefits: Improved availability and reliability.

Impact: High

For more information, see Best practices for high availability with Azure VMs and managed disks - Azure Virtual Machines

ResourceType: microsoft.compute/disks
Recommendation ID: d4102c0f-ebe3-4b22-8fe0-e488866a87af

Enable virtual machine replication to protect applications from regional outage

Virtual machines are resilient to regional outages when replication to another region is enabled. To reduce adverse business effect during an Azure region outage, the platform recommends enabling replication of all business-critical virtual machines.

Potential benefits: Ensure business continuity during an Azure region outage.

Impact: High

For more information, see Set up Azure VM disaster recovery to a secondary region with Azure Site Recovery - Azure Site Recovery

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: ed651749-cd37-4fd5-9897-01b416926745

Upgrade your deprecated Virtual Machine image to a newer image

Virtual Machines (VMs) in your subscription are running on images scheduled for deprecation. Once the image is deprecated, new VMs can't be created from the deprecated image. To prevent disruption to your workloads, upgrade to a newer image. (VMRunningDeprecatedImage)

Potential benefits: Minimize any potential disruptions to your VM workloads

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 11f04d70-5bb3-4065-b717-1f11b2e050a8
Subcategory: ServiceUpgradeAndRetirement

Upgrade to a newer offer of Virtual Machine image

Virtual Machines (VMs) in your subscription are running on images scheduled for deprecation. Once the image is deprecated, new VMs can't be created from the deprecated image. To prevent disruption to your workloads, upgrade to a newer image. (VMRunningDeprecatedOfferLevelImage)

Potential benefits: Minimize any potential disruptions to your VM workloads

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 937d85a4-11b2-4e13-a6b5-9e15e3d74d7b
Subcategory: ServiceUpgradeAndRetirement

Upgrade to a newer SKU of Virtual Machine image

Virtual Machines (VMs) in your subscription are running on images scheduled for deprecation. Once the image is deprecated, new VMs can't be created from the deprecated image. To prevent disruption to your workloads, upgrade to a newer image.

Potential benefits: Minimize any potential disruptions to your VM workloads

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 681acf17-11c3-4bdd-8f71-da563c79094c
Subcategory: ServiceUpgradeAndRetirement

Provide access to mandatory URLs missing for your Azure Virtual Desktop environment

For a session host to deploy and register to Windows Virtual Desktop (WVD) properly, you need a set of URLs in the 'allowed list' in case your VM runs in a restricted environment. For specific URLs missing from your allowed list, search your application event log for event 3702.

Potential benefits: Ensure successful deployment and session host functionality when using Windows Virtual Desktop service

Impact: Medium

For more information, see Required FQDNs and endpoints for Azure Virtual Desktop

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 53e0a3cb-3569-474a-8d7b-7fd06a8ec227
Subcategory: Other

Use Availability zones for better resiliency and availability

Availability Zones (AZ) in Azure help protect your applications and data from datacenter failures. Each AZ is made up of one or more datacenters equipped with independent power, cooling, and networking. By designing solutions to use zonal VMs, you can isolate your VMs from failure in any other zone.

Potential benefits: Zonal VMs protect your apps from zonal outage in other zones

Impact: High

For more information, see Move Azure single-instance virtual machines from regional to zonal availability - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 066a047a-9ace-45f4-ac50-6325840a6b00

Convert Standard to Premium disk for higher uptime

Use a Premium SSD managed disk in a Single Instance virtual machine for the highest uptime. Conversion is allowed from a Standard managed disk to a Premium managed disk.

Potential benefits: Enhanced performance, configurability, and uptime

Impact: Low

For more information, see Best practices for high availability with Azure VMs and managed disks - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 2b5cf6e5-2792-49b2-9ec0-0e901be6488b
Subcategory: BusinessContinuity

Enable Backups on your Virtual Machines

Secure your data by enabling backups for your virtual machines.

Potential benefits: Protection of your Virtual Machines

Impact: Medium

For more information, see What is Azure Backup? - Azure Backup

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 651c7925-17a3-42e5-85cd-73bd095cf27f
Subcategory: DisasterRecovery

Add additional VM or use Premium disks for higher uptime

Add a second instance VM to Availability Set or upgrade to Premium SSD managed disks for highest uptime.

Potential benefits: Enhanced performance, configurability, and uptime

Impact: Medium

For more information, see Best practices for high availability with Azure VMs and managed disks - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: e5e707f2-f41f-4aa6-bccf-3fb9748e5b66
Subcategory: BusinessContinuity

Upgrade your VMSS to alternative image version

VMSS in your subscription are running on images that are scheduled for deprecation. When the image is deprecated, your VMSS workloads stop scaling out. Upgrade to a newer version of the image to prevent disruption to your workload.

Potential benefits: Minimize any potential disruptions to your VMSS workloads.

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 3b739bd1-c193-4bb6-a953-1362ee3b03b2

Upgrade your VMSS to alternative image offer

VMSS in your subscription are running on images that are scheduled for deprecation. When the image is deprecated, your VMSS workloads stop scaling out. To prevent disruption to your workload, upgrade to a newer offer of the image.

Potential benefits: Minimize any potential disruptions to your VMSS workloads.

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 3d18d7cd-bdec-4c68-9160-16a677d0f86a
Subcategory: ServiceUpgradeAndRetirement

Upgrade your VMSS to alternative image SKU

VMSS in your subscription are running on images that are scheduled for deprecation. When the image is deprecated, your VMSS workloads stop scaling out. To prevent disruption to your workload, upgrade to a newer SKU of the image.

Potential benefits: Minimize any potential disruptions to your VMSS workloads.

Impact: High

For more information, see Deprecated Azure Marketplace images - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 44abb62e-7789-4f2f-8001-fa9624cb3eb3
Subcategory: ServiceUpgradeAndRetirement

Enable Automatic Repair Policy on Azure Virtual Machine Scale Sets

Enabling automatic instance repairs helps achieve high availability by maintaining a set of healthy instances. If an unhealthy instance is found by the Application Health extension or load balancer health probe, automatic instance repairs attempt to recover the instance by triggering repair actions.

Potential benefits: Increase resiliency by automating repair of failed instances

Impact: High

For more information, see Automatic instance repairs with Azure Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: b4d988a9-85e6-4179-b69c-549bdd8a55bb
Subcategory: BusinessContinuity

Upgrade to Standard SSD OS disk

HDD operating system (OS) disks are being retired in September 2028. Upgrade the OS disk from Standard HDD to Standard SSD for increased uptime of single-instance virtual machine and improved input/output operations and throughput.

Potential benefits: Boost single-instance VM uptime from 95% to 99.5%.

Impact: Medium

For more information, see Migrate Standard HDD OS disks by September 08, 2028 - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 3c03549b-9c0a-4c13-bed4-def3c7e34ddd

Migrate workload on A-series or B-series virtual machine (VM) to D-series or better VM

Migrate production workload from A-series or B-series virtual machine (VM) to D-series or better VM. A-series and B-series VMs are designed for entry-level workloads.

Potential benefits: Full CPU performance for heavy workload in production

Impact: High

For more information, see Virtual machine sizes overview - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 7f71b153-c0b7-4e99-a23e-db8179183ec9

Migrate workload to Virtual Machine Scale Sets Flex

Migrate production workload on stand-alone virtual machine (VM) to multiple VMs grouped in a Virtual Machine Scale Sets Flex to intelligently distribute across the platform.

Potential benefits: Enhanced resilience to platform faults and updates.

Impact: Medium

For more information, see Orchestration modes for Virtual Machine Scale Sets in Azure - Azure Virtual Machine Scale Sets

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 5f2613df-629f-4b07-9425-2a47ea0dfad3
Subcategory: HighAvailability

Migrate virtual machine using availability sets to Virtual Machine Scale Sets Flex

Migrate workloads from virtual machine (VM) to Virtual Machine Scale Sets Flex for deployment across zones or within the same zone across different fault domains.

Potential benefits: Availability across zones or across different fault domains.

Impact: Medium

For more information, see Migrate deployments and resources to Virtual Machine Scale Sets in Flexible orchestration - Azure Virtual Machine Scale Sets

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 39fb2718-a2ae-4662-a8c9-cd8df23f01eb
Subcategory: HighAvailability

Enable application health monitoring for Virtual Machine Scale Sets (VMSS)

Configure VM scale set application health monitoring using the Application Health extension or load balancer probes so Azure can detect unhealthy instances, trigger repairs, and enable safer upgrades to improve application resiliency.

Potential benefits: App-health detection during upgrade and auto-repair

Impact: Medium

For more information, see Use Application Health extension with Azure Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 3b587048-b04b-4f81-aaed-e43793652b0f

Validate Virtual Machine reliability with a Site Recovery test failover

Perform a test failover to validate Business Continuity and Disaster Recovery strategy and ensure that the applications are functioning correctly in the target region without impacting production environment.

Potential benefits: Ensure business continuity. Verify disaster recovery plan.

Impact: High

For more information, see Tutorial to run an Azure VM disaster recovery drill with Azure Site Recovery - Azure Site Recovery

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 01c715f6-426a-47d3-87be-9f26e2ab2d8e

Configure and deploy Azure Virtual Machine Scale Sets in a more resilient and balanced configuration

Use Virtual Machine Scale Sets to deploy VMs across availability zones, fault domains, and have a balanced distribution. Balanced distribution provides a protection measure for the applications and data against the rare event of datacenter failure.

Potential benefits: Increased application uptime.

Impact: High

For more information, see Azure Virtual Machine Scale Sets overview - Azure Virtual Machine Scale Sets

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 4175946b-cd53-4a37-9e9a-0f8a418ef6ac
Subcategory: HighAvailability

Align location of resource and resource group

Move virtual machines to the same region as the related resource group. This way, Azure Resource Manager stores metadata related to all resources within the group in one region. By co-locating, you reduce the chance of being affected by region unavailability.

Potential benefits: Reduce the impact of regional outages

Impact: Medium

For more information, see What is Azure Resource Manager? - Azure Resource Manager

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 00e4ac6c-afa3-4578-a021-5f15e18850a2
Subcategory: HighAvailability

Migrate to zonal aware deployment model

Migrate to zonal aware deployment model such as Virtual Machine Scale Sets, Azure Kubernetes Service (AKS), or App Service for zone redundant benefit.

Potential benefits: Zone failover reduces service disruption

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.compute/cloudservices
Recommendation ID: 71c69a25-0953-41d6-bf3a-1db323cd70b0

Spread dedicated hosts across zones for isolation of hardware failures

Create host groups with hosts distributed across multiple zones. Assign virtual machine instances to hosts in different zones for isolation of faults.

Potential benefits: Host isolation across zones for durability

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.compute/hostgroups
Recommendation ID: 61bd0aa3-f2b0-485f-8e5e-95d02ac3483a

Use zone-scoped Proximity Placement Groups and duplicate across zones

Use zone-scoped proximity placement groups and deploy dependent resources in the same zone for low latency. Ensure multiple proximity placement groups exist across zones for redundancy.

Potential benefits: Low latency plus zone-level fault isolation

Impact: High

For more information, see Enable Zone Resiliency for Azure Workloads

ResourceType: microsoft.compute/proximityplacementgroups
Recommendation ID: 3742247e-ea02-4202-bfef-a8a6be51fa4c

Review and migrate virtual machine workloads

Azure Virtual Machine (VM) series F, Fs, Fsv2, Lsv2, G, Gs, Av2, and B are retiring. The VM series are no longer available for use or purchase. Applications and workloads currently operating on VM types must be migrated to newer VM series.

Potential benefits: Avoid service disruptions by proactively migrating workloads

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 13cea0f1-c3f7-4c66-8b3b-9928a0f07cea

Resize or migrate NVv3-series virtual machines

To avoid service disruptions, migrate workloads to the Azure NVadsA10_v5-series VMs. Azure NVadsA10_v5-series VMs include increased GPU memory bandwidth per GPU, Small AI workloads and GPU accelerated graphics applications, virtual desktops, and visualizations.

Potential benefits: Avoid service disruptions and loss of functionality

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 0e68ab45-c2c8-4d1f-9873-908dc5828252

Resize or migrate NVv4-series virtual machines

To avoid service disruptions, migrate workloads to Azure NVads_V710_v5-series virtual machines. NVads_V710_v5-series virtual machines provide greater GPU memory bandwidth per GPU for small AI workloads and GPU accelerated graphics applications, virtual desktops, and visualizations.

Potential benefits: Avoid service disruptions and loss of functionality

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: cfeba225-ca14-48fe-83ba-50d24f60f84e

Migrate to encryption at host

Azure Disk Encryption is retiring. Migrate to encryption at host before the retirement date to ensure continued security, functionality, and performance.

Potential benefits: Ensure continued security, functionality, and performance

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: d7d26cea-dca8-4033-9e7f-d8e8a7a08cf1

Migrate D, Ds, Dv2, Dsv2, and Ls series VM instances to latest series VMs

Migrate D, Ds, Dv2, Dsv2, and Ls series VM instances to newer VM generation instances. D, Ds, Dv2, Dsv2, and Ls series VMs in Azure Virtual Machines are retiring.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 779dbd8a-6102-47d0-b36c-75eb070b86d6

Migrate to the newer VM series in the same NC product line

Standard_NC24rs_v3 virtual machine size in NCv3-series virtual machines is retiring. Upgrade to the newer VM series in the same NC product line.

Potential benefits: Avoid service disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 81076cd9-e656-4b1a-862b-63f2f40caa87

Migrate to Windows Server 2022

Kubernetes workloads will no longer be supported with Windows Server 2019 when Kubernetes version 1.32 reaches End of Life (EOL).

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 98680ff0-2723-4c8b-9af4-54ce8a3a82d1

Migrate Standard HDD OS Disks to SSD

To improve customer experience and align with current disk usage patterns, Standard HDD OS Disks are retiring. Customers should stop using Standard HDD OS Disks for new virtual machines and migrate existing OS disk workloads to Standard SSD or Premium SSD.

Potential benefits: Avoid potential service disruption after retirement

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/disks
Recommendation ID: 6885dc91-c4d1-4695-be6f-f64be575769f

Migrate from Dependency Agent and VM Insights Map

Dependency Agent and VM Insights Map is retiring. We recommend considering a replacement solution from the Azure Marketplace to continue collecting data about processes running on virtual machines and external process dependencies.

Potential benefits: Avoid Service Disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: f49d7356-7251-4e15-a577-a3398527f3fd

Cloud Services (extended support) is being retired

Migrating to Virtual Machine Scale Sets with Flexible orchestration enhances the scalability, flexibility, and reliability of the Azure deployments. After the retirement date, workloads running Cloud Services (extended support) are deleted and associated application data is lost.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/cloudservices
Recommendation ID: 69e994b4-9b84-4581-930b-edcf9cc81582
Subcategory: ServiceUpgradeAndRetirement

Migrate HBv2 to latest HPC Virtual machine families

Microsoft is retiring following HBv2-series virtual machine (VMs) sizes: Standard_HB120rs_v2, Standard_HB120-96rs_v2, Standard_HB120-64rs_v2, Standard_HB120-32rs_v2, and Standard_HB120-16rs_v2. To ensure continuity and improved performance, transition to current generation Azure HPC VM families.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 851ac46b-6ac2-4074-9ba2-447bb8754cb6

Migrate HCv1 to latest HPC Virtual machine families

HC-series virtual machine sizes are retiring. To ensure continuity and improved performance, transition to one of the current‑generation Azure HPC VM families, Azure HBv5‑series or Azure HX‑series.

Potential benefits: Avoid service disruption

Impact: Medium

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: c6199b8a-db76-4a4f-b45b-ef5e9d2be09c

NP-series virtual machines are retiring

NP-series virtual machines are retiring. To ensure continuity and optimal performance, transition to latest GPU VM families. e.g. NDv2 VMs, NDv2 VMs, NCasT4_v3.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: ac992ddf-2bbf-4049-b142-a30d6236291e

Service Fabric support for Windows Server 2022 is ending

Service Fabric support for Windows Server 2022 is retiring. To remain supported, upgrade all Service Fabric clusters to Windows Server 2025.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: b131ddbe-5439-4c87-95bc-6999b0648252

Service Fabric support for Windows Server 2019 is retiring

Service Fabric support for Windows Server 2019 is retiring. To remain supported, upgrade all Service Fabric clusters to Windows Server 2025.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 2ae93784-84f0-4f3a-8a9c-4ee4f8549cd4

Add and enable the LegacyVMNVA tag for NVA virtual machines

The workload uses a VM series that is eligible to be deployed on MANA-capable hardware. If the workload isn't MANA ready, apply and enable the 'LegacyVMNVA' tag on affected VMs to temporarily avoid deployment on MANA-capable hardware until 5/31/2027. Migrate to a supported OS or VM series by then.

Potential benefits: Reduce network performance risk due to MANA incompatibility.

Impact: High

For more information, see MANA support for Network Virtual Appliances (NVAs) - Microsoft Azure Network Adapter

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 40df4452-9b9f-47d7-921c-638e6cac6333

Enable LegacyVMNVA tag for NVA virtual machines

The workload uses a VM series that is eligible to be deployed on MANA-capable hardware. The workload has the LegacyVMNVA tag but the tag needs to be enabled. Enabling the tag will temporarily avoid deployment on MANA-capable hardware until 5/31/2027. Migrate to a supported OS or VM series by then.

Potential benefits: Reduce network performance risk due to MANA incompatibility.

Impact: High

For more information, see MANA support for Network Virtual Appliances (NVAs) - Microsoft Azure Network Adapter

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 53f3eb12-bd32-4e63-8241-234ae2b58615

Add and enable LegacyVMNVA tag on VM Scale Set with NVAs

The VMs in VMSS use a VM series that is eligible to be deployed on MANA-capable hardware. If the VMs are not MANA ready, apply and enable the 'LegacyVMNVA' tag on the VMSS to temporarily avoid deployment on MANA-capable hardware until 5/31/2027. Migrate to a MANA supported OS or VM series by then.

Potential benefits: Reduce network performance risk due to MANA incompatibility.

Impact: High

For more information, see MANA support for Network Virtual Appliances (NVAs) - Microsoft Azure Network Adapter

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 2a126a9d-b0ec-4352-bb39-863cb8fafdcf

Enable LegacyVMNVA tag for VM Scale Set Uniform

The VMs in VMSS use a VM series that is eligible to be deployed on MANA-capable hardware. If the VMs are not MANA ready, enable the 'LegacyVMNVA' tag on the VMSS to temporarily avoid deployment on MANA-capable hardware until 5/31/2027. Migrate to a MANA supported OS or VM series by then.

Potential benefits: Reduce network performance risk due to MANA incompatibility.

Impact: High

For more information, see MANA support for Network Virtual Appliances (NVAs) - Microsoft Azure Network Adapter

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: b70fccd9-37c8-435a-8868-7b5b2ec759f7

Enable LegacyVMNVA tag for NVAs in VM Scale Set Uniform

The VM uses a VM series that is eligible to be deployed on MANA-capable hardware. The VMSS has the LegacyVMNVA tag but the tag needs to be enabled for the VM. Enabling the tag will temporarily avoid deployment on MANA-capable hardware until 5/31/2027. Migrate to a supported OS or VM series by then.

Potential benefits: Reduce network performance risk due to MANA incompatibility.

Impact: High

For more information, see MANA support for Network Virtual Appliances (NVAs) - Microsoft Azure Network Adapter

ResourceType: microsoft.compute/virtualmachinescalesets/virtualmachines
Recommendation ID: dcca165d-ffec-43e4-a21d-bc41b7812e09

Migrate from Dependency Agent and VM Insights Map

Dependency Agent and VM Insights Map is retiring. We recommend considering a replacement solution from the Azure Marketplace to continue collecting data about processes running on virtual machines and external process dependencies.

Potential benefits: Avoid Service Disruption

Impact: Medium

For more information, see VM Insights Map and Dependency Agent retirement guidance - Azure Monitor

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 5d4bb790-d34a-4b45-81d7-4dd060e59853

Azure Diagnostic Extensions are retiring

Microsoft is retiring Azure Diagnostic Extensions for Windows and Linux (WAD/LAD) and will no longer support them. This retirement also includes the collection of diagnostic extension data from Azure Storage accounts imported into Log Analytics workspaces.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 8db086d4-6f1e-4459-86c1-7e83e4c436a9

Azure Virtual Machines DCsv2-series are retiring

You can't use Virtual Machines DCsv2-series anymore. Review changes to the VMs billing after changing SKUs.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: ad6df2a0-827c-493f-8307-d9d553bb5531

Azure unmanaged disks are being retired

Migrate your data from Azure unmanaged disk storage to managed disks.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Unmanaged disks have been retired - Azure Virtual Machines.

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 2d1f43c1-9d8d-46be-873c-6ddda75636ee

Configure your node pool worker virtual machines across availability zones to improve availability.

Your Azure Red Hat OpenShift node pool runs worker virtual machines in a single availability zone. Create node pools across availability zones to improve availability for your applications.

Potential benefits: Improve application availability across availability zones.

Impact: High

For more information, see What are Azure Availability Zones?

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 990f7204-592d-49e4-8ddf-251a056dada0

Default outbound access connectivity for virtual machines in Azure is retiring.

Default outbound access connectivity for virtual machines in Azure is retiring.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: e3a21ba5-e34b-4614-a718-131670d51e3f

Desired State Configuration Extension for Azure Virtual Machines is retiring

After the retirement date, Azure won't support the Desired State Configuration Extension for Azure Virtual Machines.

Potential benefits: Avoid potential disruptions

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: beae2503-c504-47b1-8ca4-d0e708559af9

Migrate ccV5 to general purpose virtual machines

The cc_v5 confidential VM series is retiring, and DCas_cc_v5, DCads_cc_v5, ECas_cc_v5, and ECads_cc_v5 are no longer available for use or purchase. Migrate your workloads to general-purpose VM series.

Potential benefits: Avoid service disruption

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 8e73c079-f841-49c6-9fca-cd552930efb8

NCv3 VM Family Support - Azure Batch is being retired

Microsoft Azure is retiring support for NCv3-series VMs, including Standard_NC24rs_v3, Standard_NC6s_v3, Standard_NC12s_v3, and Standard_NC24s_v3. Azure Batch follows Microsoft Azure support retirement dates for NCv3-series VM support in Batch pools.

Potential benefits: Avoid potential disruptions

Impact: High

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 475ee3a1-e973-4a80-9f41-7f5fafc48e93

Standard_M192idms_v2 is being retired.

Workloads running Standard_M192idms_v2 are deleted and associated application data is lost.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: e1c591d0-5ccb-4aca-91d7-b41b6924da8c

Standard_M192ids_v2 is being retired

Workloads running Standard_M192ids_v2 are deleted and associated application data is lost.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 06e322e4-61bd-4399-8074-09eef9272950

Standard_M192ims_v2 is being retired.

Workloads running Standard_M192ims_v2 are deleted and associated application data is lost.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 321a6b2e-ff3a-4319-95a2-312953015781

Standard_M192is_v2 is being retired.

Workloads running Standard_M192is_v2 are deleted and associated application data is lost.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: Medium

For more information, see Azure updates

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 046927b3-bbf7-460d-86fc-d2b10f7f5f00

Test Azure Virtual Machine Scale Sets Resiliency with a Chaos Experiment

Run an S3 Compute Zone Down chaos experiment to validate zonal resiliency of your VMSS Scale Sets. Chaos experiments inject failures and might affect targeted resources. Start with non-production environments and use approved maintenance windows for production workloads.

Potential benefits: Improve outage readiness and validate zone resilience.

Impact: High

For more information, see Scenarios and outage templates for Chaos Studio Workspaces - Azure Chaos Studio

ResourceType: microsoft.compute/virtualmachinescalesets
Recommendation ID: 604fb48f-017f-4239-9a9c-e46d6c48132e

Virtual machines in NCv3-series are retiring

To avoid any disruption to your service, change the VM sizing for your workloads from the current NCv3-series VMs to the newer VM series in the same NC product line.

Potential benefits: Avoid potential disruptions and use new capabilities.

Impact: High

For more information, see Azure updates.

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 1c5fb9ab-77aa-4298-9caf-2a38f9feecdb

Migrate from DCsv3, DCdsv3 series to DCesv6, ECesv6 virtual machines

DCsv3 and DCdsv3-series virtual machines are retiring. Migrate to DCesv6, ECesv6 virtual machines.

Potential benefits: Avoid service disruption

Impact: Medium

For more information, see DCsv3-series and DCdsv3-series retirement - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 3455290f-894b-45cf-b441-f28861424c5e

Workloads

Ensure high availability for production SAP app server

Verify high availability configuration for SAP application server of production SAP workloads.

Potential benefits: Minimize downtime to enhance system availability

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 90a86c8e-efab-47a1-bb4d-63f231b15292
Subcategory: HighAvailability

Ensure high availability across zones for SAP app server

Verify high availability configuration across multiple availability zones within the same region for SAP application servers of production workloads.

Potential benefits: Minimize downtime to enhance system availability

Impact: High

For more information, see SAP workload configurations with Azure Availability Zones

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: b914567c-cfc4-42a5-8d16-939b77b6b4d0
Subcategory: HighAvailability

Use Premium or Ultra Disk for single app server VM

Use Premium Storage or Ultra Disks for SAP application server.

Potential benefits: Maximize the Azure single VM SLA

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: a7202ec4-8a6e-45ef-9b6e-df2486bcaa86
Subcategory: HighAvailability

Set the Idle timeout in Azure Load Balancer to 30 minutes for ASCS HA setup in SAP workloads

To prevent load balancer timeout, make sure that all Azure Load Balancing Rules have: 'Idle timeout (minutes)' set to the maximum value of 30 minutes. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable the setting.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 45c2994f-a01d-4024-843e-a2a84dae48b4
Subcategory: HighAvailability

Enable Floating IP in the Azure Load balancer for ASCS HA setup in SAP workloads

For port resuse and better high availability, enable floating IP in the load balancing rules for the Azure Load Balancer for HA set up of ASCS instance in SAP workloads. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: aec9b9fb-145f-4af8-94f3-7fdc69762b72
Subcategory: HighAvailability

Enable HA ports in the Azure Load Balancer for ASCS HA setup in SAP workloads

For port resuse and better high availability, enable HA ports in the load balancing rules for HA set up of ASCS instance in SAP workloads. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: c3811f93-a1a5-4a84-8fba-dd700043cc42
Subcategory: HighAvailability

Disable TCP timestamps on VMs placed behind Azure Load Balancer in ASCS HA setup in SAP workloads

Disable TCP timestamps on VMs placed behind AzurEnabling TCP timestamps will cause the health probes to fail due to TCP packets being dropped by the VM's guest OS TCP stack causing the load balancer to mark the endpoint as down

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 27899d14-ac62-41f4-a65d-e6c2a5af101b
Subcategory: Other

Ensure that stonith is enabled for the Pacemaker configuration in ASCS HA setup in SAP workloads

In a Pacemaker cluster, the implementation of node level fencing is done using a STONITH (Shoot The Other Node in the Head) resource. To help manage failed nodes, ensure that 'stonith-enable' is set to 'true' in the HA cluster configuration.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 28a00e1e-d0ad-452f-ad58-95e6c584e594
Subcategory: HighAvailability

Set the corosync token in Pacemaker cluster to 30000 for ASCS HA setup in SAP workloads (RHEL)

The corosync token setting determines the timeout that is used directly, or as a base, for real token timeout calculation in HA clusters. To allow memory-preserving maintenance, set the corosync token to 30000 for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: deede7ea-68c5-4fb9-8f08-5e706f88ac67
Subcategory: Other

Set expected-votes parameter to 2 for pacemaker cluster in ASCS HA setup in RHEL for SAP workloads

For a two node HA cluster, set the quorum 'expected-votes' parameter to '2' as recommended for SAP on Azure to ensure a proper quorum, resilience, and data consistency.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 35ef8bba-923e-44f3-8f06-691deb679468
Subcategory: HighAvailability

Enable concurrent-fencing parameter for pacemaker cluster in ASCS HA setup in RHEL for SAP workloads

Concurrent fencing enables the fencing operations to be performed in parallel, which enhances high availability (HA), prevents split-brain scenarios, and contributes to a robust SAP deployment. Set this parameter to 'true' in the Pacemaker cluster configuration for ASCS HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 0fffcdb4-87db-44f2-956f-dc9638248659
Subcategory: Other

Ensure that stonith is enabled for the cluster configuration in ASCS HA setup in SAP workloads

In a Pacemaker cluster, the implementation of node level fencing is done using a STONITH (Shoot The Other Node in the Head) resource. To help manage failed nodes, ensure that 'stonith-enable' is set to 'true' in the HA cluster configuration.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 6921340e-baa1-424f-80d5-c07bbac3cf7c
Subcategory: HighAvailability

Set the stonith timeout to 144 for the cluster configuration in ASCS HA setup in SAP workloads

The stonith-timeout specifies how long the cluster waits for a STONITH action to complete. Setting it to '144' seconds allows more time for fencing actions to complete. We recommend this setting for HA clusters for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 4eb10096-942e-402d-b4a6-e4e271c87a02
Subcategory: Other

Set the corosync token in Pacemaker cluster to 30000 for ASCS HA setup in SAP workloads (SUSE)

The corosync token setting determines the timeout that is used directly, or as a base, for real token timeout calculation in HA clusters. To allow memory-preserving maintenance, set the corosync token to '30000' for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 9f30eb2b-6a6f-4fa8-89dc-85a395c31233
Subcategory: Other

Set 'token_retransmits_before_loss_const' to 10 in Pacemaker cluster in ASCS HA setup in SAP workloads

The corosync token_retransmits_before_loss_const determines how many token retransmits are attempted before timeout in HA clusters. For stability and reliability, set the 'totem.token_retransmits_before_loss_const' to '10' for ASCS HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: f32b8f89-fb3c-4030-bd4a-0a16247db408
Subcategory: Other

Set the corosync join in Pacemaker cluster to 60 for ASCS HA setup in SAP workloads

The corosync join timeout specifies in milliseconds how long to wait for join messages in the membership protocol. Set it to 60 in the Pacemaker cluster configuration for ASCS HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: fed84141-4942-49b3-8b0c-73a8b352f754
Subcategory: Other

Set the 'corosync consensus' in Pacemaker cluster to '36000' for ASCS HA setup in SAP workloads

The corosync 'consensus' parameter specifies in milliseconds how long to wait for consensus before starting a round of membership in the cluster configuration. Set 'consensus' in the Pacemaker cluster configuration for ASCS HA setup to 1.2 times the corosync token for reliable failover behavior.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 73227428-640d-4410-aec4-bac229a2b7bd
Subcategory: Other

Set the 'corosync max_messages' in Pacemaker cluster to '20' for ASCS HA setup in SAP workloads

The corosync 'max_messages' constant specifies the maximum number of messages that one processor can send on receipt of the token. Set it to 20 times the corosync token parameter in the Pacemaker cluster configuration to allow efficient communication without overwhelming the network.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 14a889a6-374f-4bd4-8add-f644e3fe277d
Subcategory: Other

Set 'expected votes' to '2' in the cluster configuration in ASCS HA setup in SAP workloads (SUSE)

For a two node HA cluster, set the quorum 'expected_votes' parameter to 2 as recommended for SAP on Azure to ensure a proper quorum, resilience, and data consistency.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 89a9ddd9-f9bf-47e4-b5f7-a0a4edfa0cdb
Subcategory: HighAvailability

Set the two_node parameter to 1 in the cluster cofiguration in ASCS HA setup in SAP workloads

For a two node HA cluster, set the quorum parameter 'two_node' to 1 as recommended for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 2030a15b-ff0b-47c3-b934-60072ccda75e
Subcategory: HighAvailability

Enable 'concurrent-fencing' in Pacemaker ASCS HA setup in SAP workloads (ConcurrentFencingHAASCSSLE)

Concurrent fencing enables the fencing operations to be performed in parallel, which enhances HA, prevents split-brain scenarios, and contributes to a robust SAP deployment. Set this parameter to 'true' in the Pacemaker cluster configuration for ASCS HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: dc19b2c9-0770-4929-8f63-81c07fe7b6f3
Subcategory: Other

Ensure the number of 'fence_azure_arm' instances is one in Pacemaker in HA enabled SAP workloads

If you're using Azure fence agent for fencing with either managed identity or service principal, ensure that there's one instance of fence_azure_arm (an I/O fencing agent for Azure Resource Manager) in the Pacemaker configuration for ASCS HA setup for high availability.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: cb56170a-0ecb-420a-b2c9-5c4878a0132a
Subcategory: HighAvailability

Set stonith-timeout to 900 in Pacemaker configuration with Azure fence agent for ASCS HA setup

For reliable function of the Pacemaker for ASCS HA set the 'stonith-timeout' to 900. This setting is applicable if you're using the Azure fence agent for fencing with either managed identity or service principal.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 05747c68-715f-4c8f-b027-f57a931cc07a
Subcategory: HighAvailability

Create the softdog config file in Pacemaker configuration for ASCS HA setup in SAP workloads

The softdog timer is loaded as a kernel module in linux OS. This timer triggers a system reset if it detects that the system has hung. Ensure that the softdog configuation file is created in the Pacemaker cluster forASCS HA set up

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 88261a1a-6a32-4fb6-8bbd-fcd60fdfcab6
Subcategory: HighAvailability

Ensure the softdog module is loaded in for Pacemaler in ASCS HA setup in SAP workloads

The softdog timer is loaded as a kernel module in linux OS. This timer triggers a system reset if it detects that the system has hung. First ensure that you created the softdog configuration file, then load the softdog module in the Pacemaker configuration for ASCS HA setup

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 3730bc11-c81c-43eb-896a-8fce0bac139d
Subcategory: HighAvailability

Ensure high availability for production SAP central service

Verify high availability configuration for SAP central services instance of production SAP workloads.

Potential benefits: Minimize downtime to enhance system availability

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: d2c08f71-906b-4915-a08e-c56215913fb2
Subcategory: HighAvailability

Ensure high availability of the SAP Central Services by leveraging availability zones

Verify high availability configuration across multiple availability zones within the same region for SAP central services of production workloads.

Potential benefits: Minimize downtime to enhance availability

Impact: High

For more information, see SAP workload configurations with Azure Availability Zones

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 9db6dd7f-af0e-45aa-89df-d35062baaefb
Subcategory: HighAvailability

Use Premium or Ultra Disk for SAP central service VM

Use Premium Storage or Ultra Disks for the SAP central services instance.

Potential benefits: Maximize the Azure single VM SLA

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: bbdfaf94-719f-4cb2-897a-9e237007328a
Subcategory: HighAvailability

Set the Idle timeout in Azure Load Balancer to 30 minutes for HANA DB HA setup in SAP workloads

To prevent load balancer timeout, ensure that all Azure Load Balancing Rules 'Idle timeout (minutes)' parameter is set to the maximum value of 30 minutes. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable the recommended settings.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 1c1deb1c-ae1b-49a7-88d3-201285ad63b6
Subcategory: HighAvailability

Enable Floating IP in the Azure Load balancer for HANA DB HA setup in SAP workloads

For more flexible routing, enable floating IP in the load balancing rules for the Azure Load Balancer for HA set up of HANA DB instance in SAP workloads. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable the recommended settings.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: cca36756-d938-4f3a-aebf-75358c7c0622
Subcategory: HighAvailability

Enable HA ports in the Azure Load Balancer for HANA DB HA setup in SAP workloads

For enhanced scalability, enable HA ports in the Load balancing rules for HA set up of HANA DB instance in SAP workloads. Open the load balancer, select 'load balancing rules' and add or edit the rule to enable the recommended settings.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: a5ac35c2-a299-4864-bfeb-09d2348bda68
Subcategory: HighAvailability

Disable TCP timestamps on VMs placed behind Azure Load Balancer in high-availability SAP workloads

Disable TCP timestamps on VMs placed behind Azure Load Balancer. Enabling TCP timestamps causes the health probes to fail due to TCP packets dropped by the VM's guest OS TCP stack causing the load balancer to mark the endpoint as down.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see Azure Load Balancer health probes

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 760ba688-69ea-431b-afeb-13683a03f0c2
Subcategory: Other

Ensure high availability for production SAP database

Ensure high availability configuration for SAP database instance of production SAP workloads

Potential benefits: Minimize downtime to enhance system availability

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: c16626fe-2b55-4e01-9ddf-7d25f694f2ef
Subcategory: HighAvailability

Ensure high availability across zones of SAP database

Verify high availability configuration across multiple availability zones within the same region for SAP database instance of production workloads

Potential benefits: Minimize downtime to enhance system availability

Impact: High

For more information, see SAP workload configurations with Azure Availability Zones

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: ab3fc753-4f6e-481f-a42a-7d9a85c56b43
Subcategory: HighAvailability

Use Premium or Ultra Disk for prod system of database VM

Use Premium Storage or Ultra Disks for the SAP database instance

Potential benefits: Maximize the Azure single VM SLA

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 4a047f75-39f1-4ec7-a5e7-2261d1741b0c
Subcategory: HighAvailability

Set PREFER_SITE_TAKEOVER parameter to 'true' in the Pacemaker configuration for HANA DB HA setup

The PREFER_SITE_TAKEOVER parameter in SAP HANA defines if the HANA system replication (SR) resource agent prefers to takeover the secondary instance instead of restarting the failed primary locally. For reliable function of HANA DB high availability (HA) setup, set PREFER_SITE_TAKEOVER to 'true'.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 255e9f7b-db3a-4a67-b87e-6fdc36ea070d
Subcategory: HighAvailability

Enable stonith in the cluster cofiguration in HA enabled SAP workloads for VMs with Redhat OS

In a Pacemaker cluster, the implementation of node level fencing is done using STONITH (Shoot The Other Node in the Head) resource. To help manage failed nodes, ensure that 'stonith-enable' is set to 'true' in the HA cluster configuration of your SAP workload.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 4594198b-b114-4865-8ed8-be06db945408
Subcategory: HighAvailability

Set the corosync token in Pacemaker cluster to 30000 for HA enabled HANA DB for VM with RHEL OS

The corosync token setting determines the timeout that is used directly, or as a base, for real token timeout calculation in HA clusters. To allow memory-preserving maintenance, set the corosync token to 30000 for SAP on Azure with Redhat OS.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 604f3822-6a28-47db-b31c-4b0dbe317625
Subcategory: Other

Set the expected votes parameter to '2' in HA enabled SAP workloads (RHEL)

For a two node HA cluster, set the quorum votes to '2' as recommended for SAP on Azure to ensure a proper quorum, resilience, and data consistency.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 937a1997-fc2d-4a3a-a9f6-e858a80921fd
Subcategory: HighAvailability

Enable the 'concurrent-fencing' parameter in the Pacemaker cofiguration for HANA DB HA setup

Concurrent fencing enables the fencing operations to be performed in parallel, which enhances high availability (HA), prevents split-brain scenarios, and contributes to a robust SAP deployment. Set this parameter to 'true' in the Pacemaker cluster configuration for HANA DB HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 6cc63594-c89f-4535-b878-cdd13659cfc5
Subcategory: Other

Set parameter PREFER_SITE_TAKEOVER to 'true' in the cluster cofiguration in HA enabled SAP workloads

The PREFER_SITE_TAKEOVER parameter in SAP HANA topology defines if the HANA SR resource agent prefers to takeover the secondary instance instead of restarting the failed primary locally. For reliable function of HANA DB HA setup, set it to 'true'.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 230fddab-0864-4c5e-bb27-037bec7c46c6
Subcategory: HighAvailability

Enable stonith in the cluster configuration in HA enabled SAP workloads for VMs with SUSE OS

In a Pacemaker cluster, the implementation of node level fencing is done using STONITH (Shoot The Other Node in the Head) resource. To help manage failed nodes, ensure that 'stonith-enable' is set to 'true' in the HA cluster configuration.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 210d0895-074c-4cc7-88de-b0a9e00820c6
Subcategory: HighAvailability

Set the stonith timeout to 144 for the cluster configuration in HA enabled SAP workloads

The 'stonith-timeout' specifies how long the cluster waits for a STONITH action to complete. Setting it to '144' seconds allows more time for fencing actions to complete. We recommend this setting for HA clusters for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 64e5e17e-640e-430f-987a-721f133dbd5c
Subcategory: HighAvailability

Set the corosync token in Pacemaker cluster to 30000 for HA enabled HANA DB for VM with SUSE OS

The corosync token setting determines the timeout that is used directly, or as a base, for real token timeout calculation in HA clusters. To allow memory-preserving maintenance, set the corosync token to 30000 for HA enabled HANA DB for VM with SUSE OS.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: a563e3ad-b6b5-4ec2-a444-c4e30800b8cf
Subcategory: Other

Set 'token_retransmits_before_loss_const' to 10 in Pacemaker cluster in HA enabled SAP workloads

The corosync token_retransmits_before_loss_const determines how many token retransmits are attempted before timeout in HA clusters. Set the totem.token_retransmits_before_loss_const to 10 as recommended for HANA DB HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 99681175-0124-44de-93ae-edc08f9dc0a8
Subcategory: Other

Set the 'corosync join' in Pacemaker cluster to 60 for HA enabled HANA DB in SAP workloads

The 'corosync join' timeout specifies in milliseconds how long to wait for join messages in the membership protocol so when a new node joins the cluster, it has time to synchronize its state with existing nodes. Set to '60' in Pacemaker cluster configuration for HANA DB HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: b8ac170f-433e-4d9c-8b75-f7070a2a5c92
Subcategory: Other

Set the 'corosync consensus' in Pacemaker cluster to 36000 for HA enabled HANA DB in SAP workloads

The corosync 'consensus' parameter specifies in milliseconds how long to wait for consensus before starting a new round of membership in the cluster. For reliable failover behavior, set 'consensus' in the Pacemaker cluster configuration for HANA DB HA setup to 1.2 times the corosync token.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 63e27ad9-1804-405a-97eb-d784686ffbe3
Subcategory: Other

Set the 'corosync max_messages' in Pacemaker cluster to 20 for HA enabled HANA DB in SAP workloads

The corosync 'max_messages' constant specifies the maximum number of messages that one processor can send on receipt of the token. To allow efficient communication without overwhelming the network, set it to 20 times the corosync token parameter in the Pacemaker cluster configuration.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 7ce9ff70-f684-47a2-b26f-781f80b1bccc
Subcategory: Other

Set the expected votes parameter to 2 in HA enabled SAP workloads (SUSE)

Set the expected votes parameter to '2' in the cluster configuration in HA enabled SAP workloads to ensure a proper quorum, resilience, and data consistency.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 37240e75-9493-433a-8671-2e2582584875
Subcategory: HighAvailability

Set the two_node parameter to 1 in the cluster configuration in HA enabled SAP workloads

For a two node HA cluster, set the quorum parameter 'two_node' to 1 as recommended for SAP on Azure.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 41cd63e2-69a4-4a4f-bb69-1d3f832001f9
Subcategory: HighAvailability

Enable the 'concurrent-fencing' parameter in the cluster configuration in HA enabled SAP workloads

Concurrent fencing enables the fencing operations to be performed in parallel, which enhances HA, prevents split-brain scenarios, and contributes to a robust SAP deployment. Set this parameter to 'true' in HA enabled SAP workloads.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: d763b894-7641-4c5d-9bc3-6f2515a6eb67
Subcategory: Other

Ensure there is one instance of fence_azure_arm in the Pacemaker configuration for HANA DB HA setup

If you're using Azure fence agent for fencing with either managed identity or service principal, ensure that one instance of fence_azure_arm (an I/O fencing agent for Azure Resource Manager) is in the Pacemaker configuration for HANA DB HA setup for high availability.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 1f4b5e87-69e9-470a-8245-f337fd0d5528
Subcategory: HighAvailability

Set stonith-timeout to 900 in Pacemaker configuration with Azure fence agent for HANA DB HA setup

If you're using the Azure fence agent for fencing with either managed identity or service principal, ensure reliable function of the Pacemaker for HANA DB HA setup, by setting the 'stonith-timeout' to 900.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 943f7572-1884-4120-808d-ac2a3e70e33a
Subcategory: HighAvailability

Ensure that the softdog config file is in the Pacemaker configuration for HANA DB in SAP workloads

The softdog timer is loaded as a kernel module in Linux OS. This timer triggers a system reset if it detects that the system is hung. Ensure that the softdog configuration file is created in the Pacemaker cluster for HANA DB HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 63233341-73a2-4180-b57f-6f83395161b9
Subcategory: HighAvailability

Ensure the softdog module is loaded in Pacemaker in ASCS HA setup in SAP workloads

The softdog timer is loaded as a kernel module in Linux OS. This timer triggers a system reset if it detects that the system is hung. First ensure that you created the softdog configuration file, then load the softdog module in the Pacemaker configuration for HANA DB HA setup.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: b27248cd-67dc-4824-b162-4563adaa6d70
Subcategory: HighAvailability

Deploy your Electronic Health Record (EHR) workload components across Availability Zones.

Deploy the virtual machines that support your Electronic Health Record (EHR) workload across Availability Zones to improve availability and isolate faults across physically separate data centers in your region.

Potential benefits: High availability and fault isolation within the region.

Impact: High

For more information, see Availability options for Azure Virtual Machines - Azure Virtual Machines

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 38ac2342-ae5f-4086-b152-3d2044ae891a

Disable TCP Reset in Azure Load Balancer for high availability (HA) setup in SAP workloads

Disabling TCP Reset on Azure Load Balancer for high availability (HA) setup ensures no TCP reset packets are sent to instances, maintaining stable connections during failover scenarios.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 230678ae-6682-4972-b3da-0854156e3ddc

Enable Floating IP in Azure Load Balancer for HA in SAP workloads

To ensure port reuse and improved high availability, enable Floating IP in the load balancing rules of your Azure Load Balancer for SAP HA setups. In the Azure portal, go to your load balancer, select Load balancing rules, and add or edit a rule to enable Floating IP.

Potential benefits: Enhances reliability and failover for SAP HA workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 866884c7-ede2-40e2-a09b-eb58ba3d35fd

Enable high availability (HA) ports in Azure Load Balancer for HA setup in SAP workloads

For port reuse and improved high availability, enable high availability (HA) ports in the load balancing rules for your SAP workloads. This setting ensures traffic is distributed across all configured ports for better fault tolerance.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: c3ccd660-1e0c-4c7b-bac2-8b33f12d077e

Ensure PREFER_SITE_TAKEOVER is set to true for high availability (HA) SAP on RHEL

The PREFER_SITE_TAKEOVER parameter in SAP HANA defines if the HANA system replication (SR) resource agent prefers to take over the secondary instance instead of restarting the failed primary locally. For reliable function of HANA DB high availability (HA) setup, set PREFER_SITE_TAKEOVER to true.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 600720f1-fe59-48eb-9d29-0c261bb44ac3

Ensure STONITH is enabled in the high availability (HA) configuration for SAP on RHEL

In a Pacemaker cluster, the implementation of node level fencing is done using STONITH (Shoot The Other Node in the Head) resource. To help manage failed nodes, ensure that 'stonith-enable' is set to 'true' in the high availability (HA) cluster configuration of your SAP workload.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 98dd295e-59d5-40f7-a0aa-5cbedfe627b0

Ensure corosync join is set to 60 for high availability (HA) SAP workloads on SUSE

The corosync join timeout specifies how long to wait for join messages when a new node joins the cluster. Set this value to 60 in the Pacemaker cluster configuration for high availability (HA) SAP on SUSE.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 74b5f9b6-5297-4ead-b50e-e520efc5bb70

Ensure corosync max_messages is set to 20 for high availability (HA) SAP on SUSE

The corosync max_messages setting specifies the maximum number of messages a processor can send when it receives a token. Set it to 20 for efficient communication in high availability (HA) SAP clusters on SUSE.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: High

For more information, see High availability for SAP HANA on Azure VMs on SLES.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 8a866318-ccb6-41da-a742-4553d0a68c92

Ensure corosync token is set to 30000 for high availability (HA) SAP on RHEL

The corosync token setting determines the timeout that the system uses directly, or as a base, for real token timeout calculation in high availability (HA) clusters. To allow memory-preserving maintenance, set the corosync token to 30000 for SAP on Azure with RHEL.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 106abf77-dab9-4e01-b0e5-31779e982030

Ensure expected votes is set to 2 for high availability (HA) SAP workloads on RHEL

For a two-node high availability (HA) cluster, set the quorum votes to 2 as recommended for SAP on Azure to ensure a proper quorum, resilience, and data consistency.

Potential benefits: Reliability of high availability (HA) setup in SAP workloads

Impact: High

For more information, see High availability of SAP HANA on Azure VMs on RHEL.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 0ebd80ff-24c6-47f1-8e8a-2a0a368259b2

Ensure high availability for SAP by distributing VMs across availability zones

Ensure that each production workload has high availability (HA) with compute instances spread across multiple availability zones (VMs) within the same region to minimize the risk of a single point of failure by distributing VMs across different zones.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: High

For more information, see SAP workload configurations with Azure Availability Zones.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 938e467d-cdf4-40d2-9ef2-1e359abdd185

Monitor your Oracle Database@Azure Exadata Infrastructure lifecycle state to keep it available.

Your Oracle Database@Azure Exadata Infrastructure includes a lifecycle state property, such as provisioning, updating, maintenance, failing, and terminating.

Potential benefits: You improve the reliability of your database operations.

Impact: High

For more information, see Manage Exadata Cloud Infrastructure

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: f8681e63-15d2-4e50-8bc4-2443c1713052

Set Health Probe Threshold to recommended value so the load balancer marks backend instances unhealthy after two consecutive failures, enabling quick identification and isolation of unhealthy instances.

Potential benefits: Reliability of HA setup in SAP workloads

Impact: Medium

For more information, see High availability for SAP HANA on Azure VMs on SLES

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: a96a02ff-a80d-4b16-a166-1e4236b8ec4e

Spread Azure Virtual Machines of the same stock-keeping unit (SKU) across availability zones.

Spread your Azure Virtual Machines of the same stock-keeping unit (SKU) across multiple availability zones in a high-availability setup to improve the resilience and fault tolerance of your SAP workloads.

Potential benefits: Reliability of HA setup in SAP workloads.

Impact: High

For more information, see Move Azure single-instance virtual machines from regional to zonal availability - Azure Virtual Machines

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: b428f425-5a24-4fb5-bb1d-c6f31c770869

Use Premium or Ultra Disk for single server VM to maximize Azure's single VM SLA in SAP roles

For single-instance VMs in SAP workload roles, use Premium Storage or Ultra Disks to achieve the highest Azure single VM SLA. This configuration ensures optimal performance and availability for critical SAP systems without HA configuration, providing better uptime guarantees.

Potential benefits: Maximize the Azure single VM SLA

Impact: High

For more information, see Azure VMs HA architecture and scenarios for SAP NetWeaver.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 262d0cbf-2054-4091-a003-09b42525bcde

Use ZRS for SAP shared file systems to ensure high availability

SAP shared file systems such as /sapmnt, /usr/sap/trans, and interface directories should use Zone-Redundant Storage (ZRS) or Geo-Zone-Redundant Storage (GZRS) for high availability across availability zones.

Potential benefits: Higher availability and resilience for SAP shared storage

Impact: High

For more information, see Data Redundancy in Azure Files

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 182c769e-d361-4f85-a905-a468451e13fd

Use rolling patching mode for your Oracle Database@Azure Exadata Infrastructure.

Oracle Database on Azure Exadata Infrastructure supports rolling and non-rolling patching modes. Use rolling patching mode to maintain availability during automatic maintenance.

Potential benefits: Maintain availability during patching.

Impact: Medium

For more information, see Configure Oracle-Managed Infrastructure

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 2b3c3748-77ef-49ea-85d4-bb81e251d7bd

Next steps

Learn more about Reliability - Microsoft Azure Well Architected Framework