[Launched] Generally Available: Next hop IP support for Virtual WAN
April 30, 2025Partner Case Study | Biztech grows revenue by 150% with Microsoft Marketplace Rewards
April 30, 2025In the face of AI-driven digital growth and a threat landscape that never sleeps, Azure continues to raise the bar on Zero Trust-ready, “secure-by-default” networking. Today we’re excited to announce five innovations that make it even easier to protect your cloud workloads while keeping developers productive:
Innovation | What it is | Why it matters |
Next generation of Azure Intel® TDX Confidential VMs (Private Preview) | Azure’s next generation of Confidential Virtual Machines now powered by the 5th Gen Intel® Xeon® processors (code-named Emerald Rapids) with Intel® Trust Domain Extensions (Intel® TDX). | Enables organizations to bring confidential workloads to the cloud without code changes to applications. The supported VMs include the general-purpose families DCesv6-series and the memory optimized families ECesv6-series. |
CAPTCHA support for Azure WAF (Public Preview) | A new WAF action that presents a visual / audio CAPTCHA when traffic matches custom or Bot Manager rules. | Stops sophisticated, human-mimicking bots while letting legitimate users through with minimal friction. Microsoft Learn |
Azure Bastion Developer (New Regions, simplified secure-by-default UX) | A free, lightweight Bastion offering surfaced directly in the VM Connect blade. One-click, private RDP/SSH to a single VM—no subnet planning, no public IP. | Gives dev/test teams instant, hardened access without extra cost, jump servers, or NSGs. Azure |
Azure Virtual Network TAP (Public Preview) | Native agentless packet mirroring available for all VM SKUs with zero impact to VM performance and network throughput. | Deep visibility for threat-hunting, performance, and compliance—now cloud-native. Microsoft Learn |
Azure Firewall integration in Security Copilot (GA) | Native agentless packet mirroring available for all VM SKUs with zero impact to VM performance and network throughput. | Threat hunt across Firewalls using natural language questions instead of manually scouring through logs and threat databases. Microsoft Learn |
1. Next generation of Azure Intel® TDX Confidential VMs (Private Preview)
We are excited to announce the preview of Azure’s next generation of Confidential Virtual Machines powered by the 5th Gen Intel® Xeon® processors (code-named Emerald Rapids) with Intel® Trust Domain Extensions (Intel® TDX). This will help to enable organizations to bring confidential workloads to the cloud without code changes to applications. The supported VMs include the general-purpose families DCesv6-series and the memory optimized families ECesv6-series.
Azure’s next generation of confidential VMs will bring improvements and new features compared to our previous generation. These VMs are our first offering to utilize our open-source paravisor, OpenHCL. This innovation allows us to enhance transparency with our customers, reinforcing our commitment to the “trust but verify” model.
Additionally, our new confidential VMs support Azure Boost, enabling up to 205k IOPS and 4 GB/s throughput of remote storage along with 54 GBps VM network bandwidth. We are expanding the capabilities of our Intel® TDX powered confidential VMs by incorporating features from our general purpose and other confidential VMs. These enhancements include Guest Attestation support, and support of Intel® Tiber™ Trust Authority for enterprises seeking operator independent attestation.
The DCesv6-series and ECesv6-series preview is available now in the East US, West US, West US 3, and West Europe regions. Supported OS images include Windows Server 2025, Windows Server 2022, Ubuntu 22.04, and Ubuntu 24.04. Please sign up at aka.ms/acc/v6preview and we will reach out to you.
2. Smarter Bot Defense with WAF + CAPTCHA
Modern web applications face an ever-growing array of automated threats, including bots, web scrapers, and brute-force attacks. Many of these attacks evade common security measures such as IP blocking, geo-restrictions, and rate limiting, which struggle to differentiate between legitimate users and automated traffic. As cyber threats become more sophisticated, businesses require stronger, more adaptive security solutions.
Azure Front Door’s Web Application Firewall (WAF) now introduces CAPTCHA in public preview—an interactive mechanism designed to verify human users and block malicious automated traffic in real time. By requiring suspicious traffic to successfully complete a CAPTCHA challenge, WAF ensures that only legitimate users can access applications while keeping bots at bay. This capability is particularly valuable for common login and sign-up workflows, mitigating the risk of account takeovers, credential stuffing attacks, and brute-force intrusions that threaten sensitive user data.
Key Benefits of CAPTCHA on Azure Front Door WAF
- Prevent Automated Attacks – Blocks bots from accessing login pages, forms, and other critical website elements.
- Secure User Accounts – Mitigates credential stuffing and brute-force attempts to protect sensitive user information.
- Reduce Spam & Fraud – Ensures only real users can submit comments, register accounts, or complete transactions.
- Easy Deployment and Management – Requires minimal configuration, reducing operational overhead while maintaining a robust security posture.
How CAPTCHA Works
When a client request matches a WAF rule configured for CAPTCHA enforcement, the user is presented with an interactive CAPTCHA challenge to confirm they are human. Upon successful completion, Azure WAF validates the request and allows access to the application. Requests that fail the challenge are blocked, preventing bots from proceeding further.
Getting Started
CAPTCHA is now available in public preview for Azure WAF. Administrators can configure this feature within their WAF policy settings to strengthen bot mitigation strategies and improve security posture effortlessly. To learn more and start protecting your applications today, visit our Azure WAF documentation.
3. Azure Bastion Developer—Secure VM Access at Zero Cost
Azure Bastion Developer is a lightweight, free offering of the Azure Bastion service designed for Dev/Test users who need secure connections to their Virtual Machines (VMs) without requiring additional features or scalability. It simplifies secure access to VMs, addressing common issues related to usability and cost. To get started, users can sign in to the Azure portal and follow the setup instructions for connecting to their VMs. This service is particularly beneficial for developers looking for a cost-effective solution for secure connectivity.
It’s now available in 36 regions with a new portal secure by default user experience.
Key takeaways
- Instant enablement from the VM Connect tab.
- One concurrent session, ideal for dev/test and PoC environments.
- No public IPs, agents, or client software required.
4. Deep Packet Visibility with Virtual Network TAP
Azure virtual network terminal access point enables customers to mirror virtual machine traffic to packet collectors or analytics tools without having to deploy agents or impact virtual machine network throughput, allowing you to mirror 100% of your production traffic. By configuring virtual network TAP on a virtual machine’s network interface, organizations can stream inbound and outbound traffic to destinations within the same or peered virtual network for real-time monitoring for various uses cases, including:
- Enhanced security and threat detection:
Security teams can inspect full packet data in real-time to detect and respond to potential threats.
- Performance monitoring and troubleshooting:
Operations teams can analyze live traffic patterns to identify bottlenecks, troubleshoot latency issues, and optimize application performance.
- Regulatory compliance:
Organizations subject to compliance frameworks such as Health Insurance Portability and Accountability Act (HIPAA), and General Data Protection Regulation (GDPR) can use virtual network TAP to capture network activity for auditing and forensic investigations.
Virtual network TAP supports all Azure VM SKU and integrates seamlessly with validated partner solutions, offering extended visibility and security capabilities. For a list of partner solutions that are validated to work with virtual network TAP, see partner solutions.
5. Protect networks at machine speed with Generative AI
Azure Firewall intercepts and blocks malicious traffic using the intrusion detection and prevention system (IDPS) today. It processes huge volumes of packets, analyzes signals from numerous network resources, and generates vast amounts of logs. To reason over all this data and cut through the noise to analyze threats, analysts spend several hours if not days performing manual tasks. The Azure Firewall integration in Security Copilot helps analysts perform these investigations with the speed and scale of AI. An example of a security analyst processing the threats their Firewall stopped can be seen below:
Analysts spend hours writing custom queries or navigating several manual steps to retrieve threat information and gather additional contextual information such as geographical location of IPs, threat rating of a fully qualified domain name (FQDN), details of common vulnerabilities and exposures (CVEs) associated with an IDPS signature, and more. Copilot pulls information from the relevant sources to enrich your threat data in a fraction of the time and can do this not just for a single threat/Firewall but for all threats across your entire Firewall fleet. It can also correlate information with other security products to understand how attackers are targeting your entire infrastructure.
To learn more about the user journey and value that Copilot can deliver, see the Azure blog from our preview announcement at RSA last year. To see these capabilities in action, take a look at this Tech Community blog, and to get started, see the documentation.
Looking Forward
Azure is committed to delivering secure, reliable, and high-performance connectivity so you can focus on building what’s next. Our team is dedicated to creating innovative, resilient, and secure solutions that empower businesses to leverage AI and the cloud to their fullest potential. Our approach of providing layered defense in depth via our security solutions like Confidential Compute, Azure DDoS Protection, Azure Firewall, Azure WAF, Azure virtual network TAP, network security perimeter will continue with more enhancements and features upcoming. We can’t wait to see how you’ll use these new security capabilities and will be keen to hear your feedback.