Azure News - 2026-07-24

2026-07-24
最終更新: 2026-08-27 21:13:49 JST

Azure Updates

[In preview] Public Preview: Azure DDoS Protection custom policy

Azure DDoS Protection custom policy is now in public preview. This capability provides per-resource control over DDoS mitigation thresholds for protected Standard Load Balancer frontend IP configurations. Customers can configure fixed inbound detection th

Azure Blog

AT&T and Microsoft scale trillion-token workloads with Microsoft Foundry and AMD

AT&T processed approximately one trillion tokens while developing OTel2.0 using Microsoft Foundry Managed Compute, open AI models, and AMD and NVIDIA GPU infrastructure. Discover how flexible model choice and scalable infrastructure are enabling production-scale telecom AI.

The post AT&T and Microsoft scale trillion-token workloads with Microsoft Foundry and AMD appeared first on Microsoft Azure Blog.

Azure Networking Blog

Announcing public preview of Azure DDoS Protection custom policy

詳細を表示

We are excited to announce the public preview of Azure DDoS Protection custom policy, a new capability that gives customers more granular control over how Azure DDoS Protection detects and mitigates attacks against protected workloads.

Azure DDoS Protection has always focused on delivering automatic, adaptive protection at scale. With custom policy, customers can now fine-tune mitigation behaviour for supported resources and configure protocol-specific detection thresholds. This allows customers to better align protection settings with any planned or projected changes in their application traffic patterns upfront, while giving them additional control over supported protocol thresholds.

 

Azure DDoS Protection custom policy is currently in preview. See the Supplemental Terms of Use for Microsoft Azure Previews for legal terms that apply to Azure features that are in beta, preview, or otherwise not yet generally available.

Why customers asked for more control 

Azure DDoS Protection automatically analyses traffic patterns and applies adaptive mitigation during attacks. While this approach works well for most workloads, some organizations require additional flexibility to support unique traffic characteristics, operational environments, or changes around big releases and events. 

Customers running latency-sensitive applications, high-throughput services, gaming platforms, or workloads with predictable traffic spikes often want the ability to customize mitigation trigger behavior for specific protocols. 

Example scenarios include: 

  • Applications with known peak traffic periods 
  • Workloads that experience sustained high packet-per-second rates 
  • Services requiring protocol-specific tuning 
  • Organizations that need separate mitigation policies across environments or applications 

Custom policy allows organizations to align DDoS protection behaviour with their operational traffic baselines while still leveraging Azure’s global-scale mitigation infrastructure. 

Key benefits: 

  1. Granular, protocol-level controlConfigure custom detection thresholds for TCP, UDP, and TCP SYN traffic, so mitigation triggers reflect how your application behaves rather than generic baselines.  
  2. Predictable protection during planned events: Align mitigation behaviour with anticipated traffic changes product launches, seasonal peaks, gaming events, so legitimate traffic surges aren't mistaken for attacks.  
  3. Flexibility without sacrificing scale: Fine-tune triggers for specific workloads while still benefiting from Azure's global-scale mitigation infrastructure and adaptive protection everywhere else.  
  4. Per-resource policy management: Apply separate policies across environments or applications, giving teams the ability to tune protection independently for dev, test, and production workloads.  
  5. Full operational visibility: Existing Azure Monitor and DDoS Protection telemetry continue to work with custom policies, so you can validate threshold changes and monitor mitigation activity end to end. 

Public preview walkthrough 

Customers can deploy and manage DDoS custom policies directly from the Azure portal. 

To create a new policy: 

  1. Open the Azure portal. 
  2. Search for DDoS custom policies. 
  3. Select Create. 
  4. Choose the subscription, resource group, and region. 
  5. Select a supported frontend IP configuration. 
  6. Configure protocol detection rules. 
  7. Review and deploy. 

Once deployed, the custom policy can be associated with supported frontend IP resources to apply protocol-specific mitigation settings. 

 

 

 

 

 

 

Current public preview scope 

During public preview, Azure DDoS Protection custom policy supports: 

  • Standard Load Balancer frontend IP configurations 
  • TCP, UDP, and TCP SYN threshold customization 
  • Azure portal management 
  • ARM and REST API deployment 

Current limitations include: 

  • Support is currently limited to Standard Load Balancer frontend IPs and no Power Shell support 

As with all preview features, functionality and supported scenarios may evolve before general availability. 

Important considerations 

When a customer configures a custom threshold for a protocol, Azure disables autotuning triggers for that protocol and uses the configured static value. 

Customers should: 

  • Use anticipated traffic baselines to guide threshold selection 
  • Start with conservative tuning changes 
  • Validate behaviour in lower environments before broad deployment 
  • Monitor mitigation telemetry after configuration changes 

Azure Monitor and existing Azure DDoS Protection telemetry continue to provide visibility into mitigation activity and operational behavior. 

Looking ahead 

Azure DDoS Protection continues to evolve to support modern application architectures, large-scale internet exposure, and advanced operational requirements. 

Custom policy extends Azure DDoS Protection's automatic, adaptive baseline with optional per-resource control, without changing the turnkey default that protects every workload out of the box. Autotuning stays on everywhere a custom threshold is not explicitly configured. 

We want customers to know that Azure DDoS continues to be a hands-off fully automated service, and that policy customization is not a new operational model, but rather an optional override-on-top automated/adaptive engine. 

Get started 

Customers can begin using Azure DDoS Protection custom policy today through the public preview experience. 

To learn more: 

  • Review the Azure REST API documentation for DDoS Custom Policies here 
  • Deploy a test policy in a supported subscription 
  • Explore the Azure portal experience for policy management 
  • Evaluate protocol-specific threshold tuning for your applications 

We look forward to hearing your feedback.