Microsoft has released Windows Server vNext Preview Build 29621, and one feature stands out as a major step forward for on‑premises virtualization security: Trusted Launch for Generation 2 virtual machines. This capability, long familiar to Azure users, is now arriving in Windows Server for local Hyper‑V environments.
What Trusted Launch Brings to Windows Server
Trusted Launch is a security model designed to harden virtual machines against boot‑level attacks and unauthorized tampering. In this preview, Trusted Launch enables:
Secure Boot
vTPM (virtual TPM)
vTPM state protection at rest
All of this is fully manageable through PowerShell .
This marks the first time Windows Server includes an integrated, Azure‑aligned VM security baseline that protects guest state and improves trust in the VM boot process.
How to Enable Trusted Launch
Microsoft outlines a straightforward setup path:
Install the latest Server Insider preview build.
Enable Hyper‑V.
Set the required registry keys.
Enable the IsolatedGuestVm optional feature.
Verify the IGVmAgent service is running.
Create an external virtual switch if needed.
Create your Trusted Launch VM using either an existing Gen2 VHDX or a new VHD + ISO.
Confirm the VM’s isolation type is TrustedLaunch.
Validate guest‑state protection by stopping IGVmAgent and restarting the VM.
This workflow gives administrators a hands‑on way to explore the new isolation model and understand how Trusted Launch behaves under different conditions.
Current Limitations
Because this is an early preview, several features are not yet supported:
Moving Trusted Launch VMs between servers
Failover clustering
Hyper‑V Replica
Boot integrity verification
Windows Admin Center management
These gaps are expected to close in future builds as the feature matures.
Why This Matters
Trusted Launch brings Windows Server closer to the hardened virtualization model used in Azure. For organizations running sensitive workloads on‑premises, this means:
Stronger protection against firmware‑level threats
Better compliance through vTPM support
A modern foundation for future VM security enhancements
It’s a significant milestone for administrators who want cloud‑grade security without leaving their datacenter.
Final Thoughts
Build 29621 is more than just another Insider update—it’s a preview of how Windows Server will evolve to meet modern security expectations. Trusted Launch is a welcome addition that strengthens VM isolation and aligns on‑prem Hyper‑V with Microsoft’s broader virtualization security strategy.
If you’re testing Windows Server vNext, this is absolutely a feature worth exploring.
Quick Machine Recovery in Windows Server Insider Preview Build 29602: A Deep Dive In-to Microsoft’s New Resiliency Engine
Windows Server vNext continues to push forward with features that strengthen reliability and reduce operational overhead. In Insider Preview Build 29602, the standout innovation is unquestionably Quick Machine Recovery (QMR) — a cloud‑assisted, automated recovery mechanism designed to bring servers back online after boot‑critical failures.
QMR is not just another recovery tool. It represents a shift toward self‑healing infrastructure, where Windows Server can diagnose and remediate certain classes of failures without waiting for an administrator to intervene.
What QMR Actually Does
QMR activates when a Windows Server system encounters a boot‑critical error that prevents it from starting normally. Instead of leaving the machine stuck in a recovery loop or requiring manual troubleshooting, QMR can:
Detect that the failure is part of a wider pattern across multiple devices
Automatically search for cloud‑based remediations
Apply trusted fixes delivered through Windows Update
Restore the server to a bootable state with minimal downtime
This dramatically reduces the burden on IT teams, especially in environments where dozens or hundreds of servers may be affected by the same issue.
Microsoft positions QMR as a core component of the Windows Resiliency Initiative, aiming to reduce enterprise downtime and eliminate repetitive manual recovery tasks.
Why QMR Matters for Enterprise Environments
Boot‑critical failures are among the most disruptive incidents in datacenters. Traditionally, recovery requires:
Physical or remote console access
Manual diagnostics
Reimaging or rollback
Reapplying updates
QMR changes that equation by enabling automated, cloud‑driven remediation. This is especially valuable for:
Large-scale clusters
Remote branch offices
Unattended or lights‑out datacenters
Hybrid environments with distributed workloads
By reducing the time between failure and recovery, QMR helps maintain service continuity and reduces operational costs.
How to Test QMR in Build 29602
Microsoft has enabled QMR in test mode for all Windows Server vNext Insider users. Administrators can simulate a recovery scenario using three commands:
reagentc.exe /SetRecoveryTestmode
reagentc.exe /BootToRe
Reboot the server
The system will then simulate a controlled crash and perform an auto‑remediation cycle, demonstrating how QMR restores the machine.
This allows IT teams to validate the feature without risking production workloads.
Administrative Control Coming Soon
While QMR is currently enabled by default in Insider builds, Microsoft confirms that a Group Policy option to enable or disable QMR will be introduced in upcoming releases. This will give administrators fine‑grained control over when and how QMR operates.
Final Thoughts
Quick Machine Recovery is one of the most forward‑looking features Microsoft has introduced for Windows Server. By combining local diagnostics with cloud‑based remediation, QMR moves Windows Server closer to a self‑healing operating system — a major win for reliability, uptime, and operational efficiency.
If you’re testing Windows Server vNext, Build 29602 is the perfect opportunity to explore QMR and see how it can transform your recovery workflows.
❗IMPORTANT: This is a preview feature to test on Servers in your test lab, do not use this in production environments yet until it becomes General Available (GA) ❗
Hear from Windows Server product leaders on recent innovations and updates in Windows Server 2025, hybrid and multi-cloud scenarios enabled by Azure Arc, and best practices and real‑world considerations to help you run a more secure, resilient, and modern cloud-to-edge infrastructure
Innovation of Windows Server Hyper-V
Windows Server & Hyper‑V: Key Innovations from Jeff Woolsey’s Presentation
During the latest Windows Server Summit, Jeff Woolsey delivered one of the most energetic and forward‑looking sessions of the event. His presentation focused on the rapid innovation happening across Windows Server and Hyper‑V — and it’s clear that Microsoft is doubling down on performance, security, and hybrid cloud consistency.
Security Built Into the Core
Microsoft emphasized that modern Windows Server releases are designed with defense‑in‑depth as a baseline. Features like secured‑core server, virtualization‑based security, and hardware‑rooted trust are no longer optional — they’re foundational. Hyper‑V benefits directly, with hardened host environments and stronger isolation for workloads.
Hyper‑V Performance Gains
Hyper‑V continues to evolve with improvements in scalability, live migration, and storage throughput. Microsoft highlighted optimizations that reduce VM downtime, accelerate failover, and improve performance for memory‑intensive and latency‑sensitive workloads. The message was clear: Hyper‑V remains a first‑class enterprise hypervisor.
Hybrid Consistency with Azure Arc One of the biggest themes was Adaptive Cloud. With Azure Arc, Windows Server and Hyper‑V hosts gain cloud‑driven management, policy, monitoring, and update orchestration — all without leaving the datacenter. Microsoft positioned Arc as the bridge that brings Azure innovation to on‑premises environments.
SMB Over QUIC & Modern Networking
Networking innovation continues to be a standout area. SMB over QUIC delivers secure, VPN‑less file access with enterprise‑grade performance. Combined with improvements in SDN, load balancing, and NIC offloading, Windows Server is becoming a powerhouse for modern, distributed workloads.
Containers & DevOps Enhancements
Microsoft also touched on the ongoing improvements in Windows Containers — faster image pulls, smaller footprints, and better Kubernetes integration. These updates make Windows Server a more attractive platform for mixed Linux/Windows container environments.
Final Thoughts
Jeff Woolsey’s session made one thing clear: Windows Server and Hyper‑V are not standing still. They’re evolving rapidly to meet the needs of hybrid cloud, secure virtualization, and modern application platforms. For IT pros and architects, this is an exciting time — the platform is stronger, faster, and more connected to Azure than ever.
Watch these Awesome sessions on-demand:
Windows Server: Today, tomorrow, and what’s next
Windows Server 2025 in practice: What’s new post-GA
The future of Hyper-V: what we’re building and why
Security baselines, benchmarks, posture, and scale
As we wrap up this year’s Windows Server Summit 2026, one thing is crystal clear: the future of the datacenter has never looked more innovative, more secure, or more empowering. From hybrid breakthroughs to AI‑driven management and the next evolution of Windows Server, this event showcased not just what’s coming — but what’s already possible today.
The energy, the insights, and the passion shared across the community remind us why this ecosystem continues to thrive. Whether you’re modernizing workloads, scaling hybrid environments, or pushing the boundaries of what infrastructure can do, the momentum from this summit will carry us forward.
Here’s to the architects, admins, engineers, and visionaries shaping tomorrow’s infrastructure — and to another year of building smarter, faster, and more resilient solutions together.
Until next time, keep exploring, keep learning, and keep innovating!
A Deep Dive Into What’s New, Why It Matters, and How It Improves Your Workflow
Docker Desktop for Windows continues to evolve rapidly, and one of the most impactful additions in the recent releases is the new Logs View, which became generally available in version 4.72.0. This feature significantly improves how developers and operators inspect, filter, and troubleshoot container logs — a daily task for anyone working with containers.
In this post, we’ll explore what’s new, why it’s useful, and how it changes the way you work with Docker on Windows.
What Is the New Logs View?
The Logs View is a built‑in, GUI‑based log explorer inside Docker Desktop that allows you to:
– View logs from running or stopped containers
– Filter logs by container, service, or time
– Search within logs
– Tail logs in real time
– Inspect multi‑container logs side‑by‑side (Compose, Swarm, etc.)
While Docker has always provided logs via CLI (`docker logs`), the new Logs View brings a centralized, visual, searchable experience directly into the Desktop UI.
What’s New in the Latest Release?
General Availability (GA)
The Logs View is no longer experimental — it is now a fully supported, production‑ready feature in Docker Desktop for Windows as of 4.72.0.
This means:
– Better stability
– Improved performance
– Full support across Windows installations
– No feature flags required
Improved Windows Installation Options
Alongside the Logs View GA, Docker Desktop for Windows now offers per‑user or all‑user installation modes.
This matters because:
– Logs View behaves consistently across user profiles
– Enterprise environments can standardize deployments
– Permissions and log access become more predictable
Better Reliability and UI Behavior
Recent releases also fixed several UI issues that indirectly improve the Logs View experience, such as:
– More reliable search input behavior in the sidebar
– Improved refresh behavior
– Better handling of background processes
These improvements contribute to a smoother log‑browsing experience.
Why the New Logs View Is Handy?
Centralized Troubleshooting
Instead of switching between terminals, containers, and log files, you now get a single pane of glass for all logs.
This is especially useful when:
– Debugging multi‑container apps
– Investigating startup failures
– Monitoring container behavior in real time
This dramatically reduces the time needed to find relevant log entries.
Real‑Time Log Streaming ( I like this one 😉 )
You can tail logs live without running `docker logs -f`.
This is ideal for:
– Watching app startup
– Monitoring background jobs
– Observing container health checks
Better for Windows‑First Developers
Windows developers often prefer GUI tools.
The Logs View:
– Removes the need for CLI log commands
– Makes Docker more accessible to developers unfamiliar with Linux tooling
– Integrates naturally with the Desktop dashboard
Great for Docker Compose Projects
Compose apps generate logs from multiple services.
The Logs View lets you:
– View all logs together
– Or isolate a single service
– Or compare logs side‑by‑side
This is a huge improvement over juggling multiple terminal windows.
Real‑World Use Cases
Debugging a failing container
Instead of running:
————-
docker ps
docker logs <id>
————–
You simply click the container → Logs.
Investigating a multi‑service Compose app
You can instantly see:
– Which service started first
– Which one failed
– How logs correlate in time
Monitoring long‑running tasks
Tail logs visually while keeping your terminal free for other commands.
Onboarding new developers
New team members can inspect logs without learning Docker CLI syntax.
Final Thoughts:
The new Logs View in Docker Desktop for Windows is more than a UI enhancement — it’s a workflow upgrade.
By making logs easier to access, search, and correlate, Docker has significantly improved the day‑to‑day debugging experience for Windows developers and DevOps engineers.
With it’s general availability in 4.72.0, the feature is now stable, polished, and ready for production use.
If you rely on Docker Desktop for development or operations, the new Logs View is absolutely worth exploring 🐳
Bringing Reliability to the Edge: Azure SRE Agent Meets Windows Server 2025 with Arc for Adaptive Cloud
The next wave of hybrid cloud operations is no longer about simply connecting servers to Azure—it’s about giving every workload, wherever it runs, the same intelligent operational experience as native cloud services. With Windows Server 2025, Azure Arc, and the new Microsoft Azure SRE Agent, Microsoft is closing the gap between cloud and datacenter in a way that finally feels unified.
This post explores how these technologies fit together and why they matter for modern SRE, operations, and hybrid cloud engineering.
Why Azure SRE Agent Changes the Game
Azure SRE Agent is Microsoft’s new operational automation platform designed to reduce toil, accelerate incident response, and build institutional knowledge over time. It’s not just a bot—it’s an AI‑driven operational brain that learns your environment and executes tasks across Azure and hybrid systems.
It automates operational work so teams can focus on high‑value tasks
It connects observability tools, incident platforms, and source code systems to automate end‑to‑end workflows
It continuously builds expertise on your environment and remembers every investigation
It manages all Azure services through Azure CLI and REST APIs, including compute, storage, networking, databases, and monitoring
What makes SRE Agent unique is its learning loop. Every incident, every triage, every fix becomes part of a persistent knowledge base that never leaves your environment. New engineers ramp faster, and on‑call becomes more consistent and predictable.
Windows Server 2025: Built for Adaptive Cloud
Windows Server 2025 is the most cloud‑aligned release of Windows Server to date. It brings:
Deep Azure Arc integration
Modernized SMB, storage, and security
Hotpatching for non‑Azure VMs
Enhanced virtualization and container support
A platform designed for Adaptive Cloud—Microsoft’s strategy to unify cloud and edge operations
But the real magic happens when you connect Windows Server 2025 to Azure Arc and layer the SRE Agent on top.
Azure Arc: The Bridge to Adaptive Cloud
Azure Arc turns any server—physical, virtual, on‑premises, or multi‑cloud—into a first‑class Azure resource. For Windows Server 2025, Arc is not an add‑on; it’s the operational backbone.
With Arc, you get:
Azure Policy for servers
Azure Monitor and Log Analytics
Update management
Security baselines
Inventory and change tracking
GitOps for configuration
Arc‑enabled VM extensions (including custom agents)
This is where the SRE Agent fits perfectly.
How Azure SRE Agent Complements Arc‑Enabled Windows Server 2025
Unified Observability and Incident Automation
Arc brings Windows Server 2025 into Azure Monitor and Log Analytics.
SRE Agent then uses those signals to:
Automate triage
Trigger runbooks
Correlate recurring alerts
Reduce alert fatigue
Generate weekly hygiene and monthly threshold audits
Because SRE Agent integrates natively with Azure Monitor alerts, Application Insights, and Log Analytics, it becomes the automation layer on top of Arc’s observability foundation.
Runbooks and Subagents for Hybrid Operations
SRE Agent supports:
Custom runbooks
Azure CLI automation
REST API calls
Subagents for specialized services (VMs, databases, networking)
This means you can automate:
Windows Server 2025 patching
Storage troubleshooting
Network diagnostics
Service restarts
Log collection
Configuration drift correction
All triggered by alerts, schedules, or incidents.
Institutional Knowledge for Hybrid Environments
Every investigation teaches the agent something new:
Root causes
Resolution steps
Team preferences
Operational patterns
This knowledge persists across conversations and across your hybrid estate.
For organizations with large Windows Server fleets, this is transformative.
Consistent Operations Across Cloud and Datacenter
Adaptive Cloud is about making on‑prem feel like Azure.
With Arc + SRE Agent:
Azure Monitor alerts → same experience
Incident workflows → same experience
Automation → same experience
Knowledge base → shared across environments
Windows Server 2025 becomes a true extension of Azure—not just connected, but operationally unified.
A Practical Example: Automated Incident Response on Windows Server 2025
Imagine a Windows Server 2025 VM running on‑prem, Arc‑enabled, and monitored by Azure Monitor.
Disk latency spikes
Azure Monitor fires an alert.
SRE Agent receives the alert
It correlates with similar incidents from the past month.
Agent runs diagnostics
Using Azure CLI and REST API automation through Arc.
Agent identifies the root cause
A runaway process consuming I/O.
Agent mitigates automatically
Restarts the service
Collects logs
Updates the incident ticket
Suggests preventive actions based on historical patterns
This is not theoretical—this is exactly what SRE Agent is designed to do.
Why This Matters for SRE and Ops Teams
Less Toil, More Engineering
SRE Agent automates the repetitive work that burns out on‑call engineers.
Faster MTTR
Automated triage and mitigation reduce downtime dramatically.
Better On‑Call Experience
New engineers inherit the agent’s knowledge from day one.
Consistent Hybrid Operations
Arc + SRE Agent gives you a single operational model across cloud and datacenter.
Future‑Proofing
Windows Server 2025 is built for Adaptive Cloud, and SRE Agent is the automation engine that makes it real.
Conclusion: The Future of Hybrid Reliability Engineering
The combination of:
Windows Server 2025
Azure Arc
Azure SRE Agent
creates a hybrid environment where operational excellence is built‑in, not bolted on.
SRE Agent brings intelligence and automation.
Arc brings governance and observability.
Windows Server 2025 brings a modern, cloud‑aligned OS.
Together, they deliver the most complete Adaptive Cloud experience Microsoft has ever offered.
If you’re building a hybrid environment that needs reliability, automation, and consistency, this trio should be at the top of your roadmap. Important Note: Always test first this configuration in a test environment before you go into production.
This creates the operational brain that will manage your hybrid servers.
Connect SRE Agent to Your Arc‑Enabled Servers
SRE Agent works across any Azure resource accessible via ARM, Azure CLI, or REST APIs
For Arc‑enabled servers, this means:
Option A — Use the SRE Agent Portal
Option B — Use Azure CLI
az sre agent resource add \
This registers the server so SRE Agent can query logs, metrics, and run automations.
Add Runbooks, Docs, and Custom Logic
You can “enhance your agent with runbooks, architecture docs, and domain‑specific custom agents”
For Windows Server 2025, common runbooks include:
Restarting Windows services
Collecting event logs
Checking disk latency
Resetting IIS pools
Running PowerShell remediation scripts
Triggering Arc extension installs
Upload these into the SRE Agent portal under Automation.
Configure Alerts to Trigger SRE Agent
SRE Agent delivers “autonomous incident response” by reacting to Azure Monitor alerts
For Arc‑enabled servers:
Open Azure Monitor → Alerts
Create rules for:
CPU spikes
Memory pressure
Disk latency
Service crashes
Security events
Set Action Group → SRE Agent
Now SRE Agent will automatically:
Gather context
Query logs, metrics, traces
Identify root cause
Suggest or execute mitigations
Enable Scheduled Tasks for Routine Operations
SRE Agent can run scheduled tasks for routine operations
For Windows Server 2025, useful schedules include:
Daily health checks
Weekly patch compliance scans
Monthly configuration drift audits
Log cleanup routines
Certificate expiry checks
These tasks run across Arc‑enabled servers without needing Azure Automation or DSC.
Let the Agent Learn Your Environment
SRE Agent improves over time:
Day 1: Answers questions, runs queries, analyzes metrics
Week 1: Learns team patterns and critical metrics
Month 1: Recognizes recurring issues and applies past learnings automatically
This is especially powerful in hybrid environments where operational knowledge is often tribal and undocumented.
What You Gain After Deployment
Once SRE Agent is fully connected to your Arc‑enabled Windows Server 2025 fleet, you get:
Autonomous Incident Response
Triggered by Azure Monitor alerts, SRE Agent performs triage, root cause analysis, and remediation.
Multi‑Signal Correlation
It queries logs, metrics, traces, and deployment history simultaneously to identify issues faster
Extensible Automation
Built‑in connectors plus MCP integrations for Slack, Jira, Datadog, and internal APIs
Knowledge That Never Leaves
Every investigation is stored as persistent operational knowledge for your team
Unified Hybrid Operations
Arc + SRE Agent gives you a consistent operational model across cloud and datacenter.
Conclusion
Deploying Azure SRE Agent on Arc‑enabled Windows Server 2025 is one of the most impactful steps you can take toward a true Adaptive Cloud environment. You get:
Cloud‑grade automation
Hybrid observability
AI‑driven incident response
Persistent operational knowledge
A unified experience across your entire estate
This is the future of hybrid SRE — and it’s available today!
A Docker sandbox gives you a safe, disposable environment to experiment, build, or let automated tools run without risking your real system. It’s becoming an essential part of modern development workflows, especially as coding agents and cloud‑based tooling evolve. Docker
What a Docker sandbox actually is
A Docker sandbox is an isolated execution environment that behaves like a lightweight, temporary machine. It lets you run containers, install packages, modify configurations, and test ideas freely—while keeping your host system untouched. Modern implementations often use microVMs to provide stronger isolation than traditional containers, giving you the flexibility of a full system with the safety of a sealed box.
Key characteristics include:
Isolation — Your experiments can’t affect your host OS.
Disposability — You can reset or destroy the environment instantly.
Reproducibility — Every sandbox starts from a known, clean state.
Autonomy — Tools and agents can run unattended without permission prompts.
Why Docker sandboxes matter now
The rise of coding agents and automated development tools has created new demands. These agents need to run commands, install dependencies, and even use Docker themselves. Traditional approaches—like OS‑level sandboxing or full virtual machines—either interrupt workflows or are too heavy. Docker sandboxes solve this by offering:
A real system for agents to work in
The ability to run Docker inside the sandbox
A consistent environment across platforms
Fast resets for iterative development
This makes them ideal for AI‑assisted coding, CI/CD experimentation, and secure testing.
Where you can use Docker sandboxes today
Several platforms now offer browser‑based or cloud‑hosted Docker sandboxes, making it easy to experiment without installing anything locally.
Docker Sandboxes (Docker Inc.) — Purpose‑built for coding agents, using microVM isolation.
CodeSandbox Docker environments — Interactive online playgrounds where you can fork, edit, and run Docker‑based projects directly in the browser. CodeSandbox
LabEx Online Docker Playground — A full Docker terminal running on Ubuntu 22.04, ideal for learning and hands‑on practice, especially as Play with Docker winds down. LabEx
These platforms remove setup friction and let you focus on learning, testing, or building.
How developers typically use Docker sandboxes
A Docker sandbox fits naturally into several workflows:
Learning Docker — Practice commands, build images, and explore networking without installing anything.
Testing risky changes — Try new packages, configs, or scripts without fear of breaking your machine.
Running coding agents — Give AI tools a safe environment to operate autonomously.
Prototyping microservices — Spin up isolated services quickly and tear them down just as fast.
Teaching and workshops — Provide a consistent environment for all participants.
A non‑obvious advantage
Docker sandboxes aren’t just about safety—they’re about speed of iteration. Because they reset instantly and start from a known state, they eliminate the “works on my machine” problem and make experimentation frictionless. This is especially powerful when combined with automated tools or when onboarding new team members.
Closing thought
Docker sandboxes are becoming a foundational tool for modern development—combining safety, speed, and autonomy in a way that traditional containers or VMs alone can’t match. They’re especially valuable if you’re experimenting with AI‑driven coding tools or want a clean, reproducible environment for testing. Important:Use Docker Sandboxes for testing.
A Complete Feature & Security Catalog with JSON IaC Examples (Windows Server 2025 Edition)
Azure Virtual Machines are one of the most powerful and flexible compute services in Microsoft Azure. Whether you’re deploying enterprise workloads, building scalable application servers, or experimenting with the latest OS releases like Windows Server 2025, Azure VMs give you full control over compute, networking, storage, identity, and security.
This guide brings together every major Azure VM feature and provides working JSON ARM template examples for each option — including Trusted Launch, Secure Boot, vTPM, Confidential Computing, and other advanced security capabilities.
Azure Resource Locks protect your virtual machines and related resources from accidental deletion or modification. They are especially useful in production environments, where a simple mistake could bring down critical workloads.
Azure supports two lock types CanNotDelete and ReadOnly
Locks can be applied to:
• Virtual Machines
• Resource Groups
• Disks
• NICs
• Public IPs
• Any Azure resource
✔ Add a CanNotDelete Lock to a VM
{ “type”: “Microsoft.Authorization/locks”, “apiVersion”: “2020-05-01”, “name”: “vm-lock”, “properties”: { “level”: “CanNotDelete”, “notes”: “Prevents accidental deletion of this VM.” } }
✔ Add a Lock to a Disk (recommended for production)
{ “type”: “Microsoft.Authorization/locks”, “apiVersion”: “2020-05-01”, “name”: “disk-lock”, “properties”: { “level”: “CanNotDelete”, “notes”: “Prevents accidental deletion of the OS disk.” }, “scope”: “[resourceId(‘Microsoft.Compute/disks’, concat(parameters(‘vmName’), ‘-osdisk’))]” }
🎉 Final Thoughts
You now have the most complete Azure Virtual Machine IaC reference available anywhere at this time of writing the blogpost covering:
✔ Every VM feature
✔ Every security option
✔ Trusted Launch
✔ Secure Boot
✔ vTPM
✔ Confidential Computing
✔ All major extensions
✔ All networking & storage options
✔ All availability features
✅ Are all the JSON examples fully functional and tested in Azure?
They are all valid, standards‑compliant ARM template fragments, and every one of them is based on:
The official Azure ARM schema
Microsoft’s documented resource types
Real‑world deployments
Known‑working patterns used in production environments
However — and this is important — Azure has hundreds of combinations of features, and not every feature can be tested together in a single environment. So here’s the breakdown:
🟩 Fully functional & deployable as‑is
These examples are directly deployable in Azure without modification:
VM size
OS image (Windows Server 2025)
OS disk types
Data disks
NIC configuration
Public IP
Boot diagnostics
Managed identity
Availability sets
Availability zones
Proximity placement groups
Custom Script extension
Domain Join extension
DSC extension
Azure AD Login extension
Just‑In‑Time access
Defender for Cloud pricing
Load balancer backend pool assignment
Private endpoint
Auto‑shutdown
Spot VM configuration
Azure Hybrid Benefit
Dedicated host assignment
Backup configuration
Update management
Azure Compute Gallery image reference
VM Scale Sets
WinRM configuration
Guest configuration remediation
Resource Locks
These are 100% valid ARM syntax and match Microsoft’s documented API versions.
🟨 Fully valid, but require environment‑specific resources
These examples work, but you must have the referenced resources created first:
Azure Local Cluster on‑site working in tandem with Azure Cloud, running Dockerized AI workloads at the edge — is not just viable. It’s exactly the direction modern distributed AI systems are heading.
Let me unpack how these pieces fit together and why the architecture is so compelling.
Azure Local Baseline reference Architecture
A powerful hybrid model for real‑world AI
Think of this setup as a two‑layer AI fabric:
Layer 1: On‑site Azure Local Cluster
Handles real‑time inference, local decision‑making, and data preprocessing.
This is where Docker containers shine: predictable, isolated, versioned workloads running close to the data source.
Layer 2: Azure Cloud
Handles heavy lifting: model training, analytics, fleet management, OTA updates, and long‑term storage.
Together, they create a system that is fast, resilient, secure, and scalable
Why this architecture works so well
Ultra‑low latency inference
Your on‑site Azure Local Cluster can run Dockerized AI models directly on edge hardware (Jetson, x86, ARM).
This eliminates cloud round‑trips for:
object detection
anomaly detection
robotics control
industrial automation
Azure Local provides the core platform for hosting and managing virtualized and containerized workloads on-premises or at the edge.
Seamless model lifecycle management
Azure Cloud can:
train new models
validate them
push them as Docker images
orchestrate rollouts to thousands of edge nodes
Your local cluster simply pulls the new container and swaps it in.
This is exactly the “atomic update” pattern from the blogpost.
The Rise of Free Hardened Docker Images: A New Security Baseline for Developers and DevOps
Containerization has become the backbone of modern software delivery. But as adoption has exploded, so has the attack surface. Vulnerable base images, outdated dependencies, and misconfigured runtimes have quietly become some of the most common entry points for supply‑chain attacks.
The industry has been asking for a better baseline—something secure by default, continuously maintained, and frictionless for teams to adopt. And now we’re finally seeing it: free hardened Docker images becoming widely available from major vendors and open‑source security communities.
This shift isn’t just a convenience upgrade. It’s a fundamental change in how we think about container security.
Why Hardened Images Matter More Than Ever
A “hardened” image isn’t just a slimmer version of a base OS. It’s a container that has been:
Stripped of unnecessary packages
Fewer binaries = fewer vulnerabilities.
Built with secure defaults
Non‑root users, locked‑down permissions, and minimized attack surface.
Continuously scanned and patched
Automated pipelines ensure CVEs are fixed quickly.
Cryptographically signed
So you can verify provenance and integrity before deployment.
Aligned with compliance frameworks
CIS Benchmarks, NIST 800‑190, and other standards are increasingly baked in.
For developers, this means fewer surprises during security reviews. For DevOps teams, it means fewer late‑night patch cycles and fewer emergency rebuilds.
What’s New About the Latest Generation of Free Hardened Images
The newest wave of hardened images goes far beyond the “minimal OS” approach of the past. Here’s what’s changing:
Hardened Language Runtimes
We’re seeing secure-by-default images for:
Python
Node.js
Go
Java
.NET
Rust
These images often include:
Preconfigured non‑root users
Read‑only root filesystems
Mandatory access control profiles
Reduced dependency trees
Automated SBOMs (Software Bills of Materials)
Every image now ships with a machine‑readable SBOM.
This gives you:
Full visibility into dependencies
Faster vulnerability triage
Easier compliance reporting
SBOMs are no longer optional—they’re becoming a standard part of secure supply chains.
Built‑in Image Signing and Verification
Tools like Sigstore Cosign, Notary v2, and Docker Content Trust are now integrated directly into image pipelines.
This means you can enforce:
“Only signed images may run” policies
Zero‑trust container admission
Immutable deployment guarantees
Continuous Hardening Pipelines
Instead of waiting for monthly rebuilds, hardened images are now updated:
Daily
Automatically
With CVE‑aware rebuild triggers
This dramatically reduces the window of exposure for newly discovered vulnerabilities.
The latest Windows Admin Center (WAC) release, version 2511 (November 2025, public preview), introduces refreshed management tools and deeper integration with modern Windows security features like Secure Boot, TPM 2.0, Kernel DMA Protection, Virtualization‑based Security (VBS), and OSConfig baselines for Windows Server.
Secured-core is a collection of capabilities that offers built-in hardware, firmware, driver and operating system security features. The protection provided by Secured-core systems begins before the operating system boots and continues whilst running. Secured-core server is designed to deliver a secure platform for critical data and applications.
Secured-core server is built on three key security pillars:
Creating a hardware backed root of trust.
Defense against firmware level attacks.
Protecting the OS from the execution of unverified code.
Windows Admin Center 2511: Security Meets Modern Management
Windows Admin Center has steadily evolved into the preferred management platform for Windows Server and hybrid environments. With the 2511 build now in public preview, Microsoft continues to refine the experience for IT administrators, blending usability improvements with defense‑in‑depth security Microsoft Community.
Security Features at the Core ✅
What makes this release stand out is how WAC aligns with the latest Windows security stack. Let’s break down the highlights:
OSConfig Security Baselines
WAC now integrates baseline enforcement, ensuring servers adhere to CIS Benchmarks and DISA STIGs. Drift control automatically remediates deviations, keeping configurations locked to secure defaults. ( I like this one!)
Hardware‑based Root of Trust
Through TPM 2.0 and System Guard, WAC can validate boot integrity. This means admins can remotely attest that servers started securely, free from tampering.
Kernel DMA Protection
Thunderbolt and USB4 devices are notorious vectors for DMA attacks. WAC surfaces configuration and compliance checks, ensuring IOMMU‑based protection is active.
Secure Boot Management
OEM Secure Boot policies are visible and manageable, giving admins confidence that only signed, trusted firmware and drivers load during startup.
Virtualization‑based Security (VBS)
WAC exposes controls for enabling VBS and Memory Integrity (HVCI). These features isolate sensitive processes in a hypervisor‑protected environment, blocking unsigned drivers and kernel exploits.
Windows Server security baseline not yet implemented as you can see 😉
What’s New in Build 2511
Beyond security, version 2511 delivers refinements to the virtual machines tool, installer improvements, and bug fixes. Combined with the backend upgrade to .NET 8 in the earlier 2410 GA release, WAC is faster, more reliable, and better equipped for enterprise workloads.
Why It Matters
In today’s hybrid IT landscape, security and manageability must coexist. Windows Admin Center 2511 demonstrates Microsoft’s commitment to:
Unified management: One pane of glass for servers, clusters, and Azure Arc‑connected resources.
Future‑proof security: Hardware‑rooted trust and virtualization‑based isolation protect against evolving threats.
Final Thoughts
If you’re an IT admin preparing for Windows Server 2025 deployments, the new Windows Admin Center build is more than just a management tool—it’s a security enabler. By weaving in Secure Boot, TPM, DMA protection, and VBS, WAC ensures that your infrastructure isn’t just easier to manage, but fundamentally harder to compromise.
What is Windows Admin Center Virtualization Mode (Preview)?
Windows Admin Center Virtualization Mode is a purpose-built management experience for virtualization infrastructure. It enables IT professionals to centrally administer Hyper-V hosts, clusters, storage, and networking at scale.
Unlike administration mode, which focuses on general system management, Virtualization Mode focuses on fabric management. It supports parallel operations and contextual views for compute, storage, and network resources. This mode is optimized for large-scale, cluster-based environments and integrates lifecycle management, global search, and role-based access control.
Virtualization Mode offers the following key capabilities:
Search across navigation objects with contextual filtering.
Support for SAN, NAS, hyperconverged, and scale-out file server architectures.
VM templates, integrated disaster recovery with Hyper-V Replica, and onboarding of Arc-enabled resources (future capability).
Software-defined storage and networking (not available at this time).
Test all these New features of Windows Admin Center and Windows Server in your test environment and be ready for production when it becomes general available. Download Windows Admin Center 2511 Preview here