Last 20 commits touching this section.
Update Azure landing zone terminology (#16867) * Initial plan * Update workload landing zone terminology Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com> * Enhance descriptions of Azure landing zones Clarified definitions of workload and platform landing zones, emphasizing the structure of environments within workload landing zones. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * PR review: Fix possessive form in design guide LAA report fix: Corrected the possessive form in the implementation's reference. --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Anna Huff <v-annahuff@microsoft.com>
Reassign articles after org changes (#16843) * switch to clayton * Switch priyanka
Align lightbox usage with 688px width threshold Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
PnP edit: IPv6 hub-spoke network topology (#16581) * Fix IPv6 support inaccuracies in IPv6 hub-spoke topology Azure Firewall does not support IPv6 and its subnet must be IPv4-only, and VPN Gateway carries IPv4 traffic only. The article routed IPv6 through both. - Remove IPv6 address space and IPv6 routes for the Azure Firewall subnet. - Route IPv6 internet egress to an IPv6-capable NVA instead of Azure Firewall. - Route cross-premises IPv6 to the ExpressRoute gateway instead of VPN Gateway. - Add an IPv6 support limitations section covering Azure Firewall, VPN Gateway, Virtual WAN, Route Server, Azure Bastion (preview, user-to-Bastion only), IPv6-only VMs, and NSG rules. - Replace the invalid hex prefix 2001:db8:efgh::/56 with 2001:db8:5678::/56. - Use valid UDR next hop types and a next hop address instead of prefixes. - Point ExpressRoute links at the canonical /azure/expressroute/expressroute-howto-add-ipv6 URL and drop the duplicate entry. - Replace azure-virtual-wan (IPv4 only) with azure-expressroute and azure-load-balancer in products. - Fix user-define/user-defined typos, a run-on sentence, and the contributor title. * Update docs/networking/guide/ipv6-architecture-content.md Co-authored-by: learn-build-service-prod-03[bot] <274428581+learn-build-service-prod-03[bot]@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Address review: fix invalid IPv6 UDR next hops, ExpressRoute gateway eligibility, and NAT64 prerequisites - Remove UDRs with a Virtual network gateway next hop for ExpressRoute; that next-hop type is supported only for VPN gateways. Describe BGP propagation and NVA inspection routes instead. - Remove the Azure Bastion UDR row; UDRs aren't supported on AzureBastionSubnet. - Note that NAT64 on a StandardV2 NAT gateway requires a third-party DNS64 solution, and that StandardV2 conflicts with Load Balancer outbound rules for IPv6. - Correct ExpressRoute IPv6 gateway eligibility: newly created gateways of any SKU, existing gateways only if zone-redundant. Add the on-premises CPE requirement and the /126 peering subnets. - Replace 'advertise IPv6 routes with UDRs' with accurate static-route wording. - Correct 'a route for each subnet' to route tables associated per subnet. - Add the IPv6 NVA to the workflow and components so the text matches the routing tables. * Reconcile VPN Gateway IPv6 statements with the autofix VPN Gateway supports IPv6 inner traffic in dual-stack deployments, so scope the IPv4-only statements in the workflow, components, address-space note, and UDR guidance to the ExpressRoute coexistence constraint that applies to this architecture. * Update ms.date for full freshness pass * Update architecture diagram to show the IPv6 NVA - Add the IPv6 NVA to the hub with its NSG and IPv6 UDR badges. - Remove the IPv6 UDR badges from Azure Bastion, Azure Firewall, and VPN Gateway, which don't carry IPv6 routes in this design. - Pin the SVG to color-scheme light with a white background. The draw.io export used 'color-scheme: light dark' with a transparent background, which rendered white text for readers whose OS is in dark mode. - Regenerate the browse thumbnail at 2645x1879. * Resolve redirecting links for the freshness pass - hub-spoke reference architecture moved to /networking/architecture; use a relative repo link. - Azure Monitor overview now lives under /fundamentals. - The PowerShell and CLI dual-stack articles were consolidated into the portal article as tabs; collapse the three links into one. - Remove the IPv6 for Azure Load Balancer entry from Next steps; it redirects to the IPv6 for Azure Virtual Network page already listed. * Minor changes before review * Apply suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Address review feedback: NVA high availability, diagram accuracy, accessibility Resolves the outstanding review threads on PR #16306. Single point of failure (Copilot, high severity): - Add "Deploy the IPv6 NVA pool for high availability" section. Every IPv6 UDR previously pointed at one appliance address, so the loss of that appliance severed all IPv6 internet and cross-premises connectivity. - Front the pool with an internal Standard Load Balancer using a dual-stack front end and an HA ports rule. UDRs now target the front-end address. - Document that IPv6 health probes require an NSG on the back-end subnet, so an NVA pool without one cannot detect an unhealthy instance. - Add a corresponding Azure Load Balancer row to the limitations table. Network interface correction (ckittel): - You add an IPv6 IP configuration to the existing network interface. You do not create a separate IPv6 interface. Corrected in the spoke procedure and in the Components section. Azure Bastion: - Disclose that dual stack must be enabled at creation time and that an existing IPv4-only host cannot be converted. Noted in the limitations table and beside the hub address plan. Diagram: - Remove IPv6 UDR badges from Azure Bastion and Azure Firewall, which the article states cannot carry IPv6 or support UDRs on their subnets. - Remove NSG badges from the Azure Firewall and gateway subnets, where NSGs are unsupported. - Label the internal load balancer, relabel the IPv6 path as "IPv6 Inspection Path", and normalize "IPv6 UDR" casing. Accessibility: - Convert the architecture diagram to a complex image with a long description. Update ms.date. * take over existing pr * convert to md only * links * edits, svg * edits * edits * edits * Address Copilot review findings on the IPv6 hub-spoke article Outbound IPv6 egress (High): - The NVA pool sits behind an internal load balancer, which provides no outbound connectivity, and subnets in virtual networks created with an API version released after March 31, 2026 are private by default. The pool therefore had no egress path. Attach a StandardV2 NAT gateway to the NVA subnet, the only NAT gateway SKU that supports IPv6, and add it to Components. Azure Firewall IPv6 (5 locations): - Dual-stack support is now in preview for network rules and DNS proxy, so the absolute "doesn't support IPv6" claim was stale. Keep the NVA as the production inspection path, but justify it by the preview's exclusions (application rules, DNAT, threat intelligence, IDPS, Explicit Proxy, IP Groups) rather than by absent support. Routing and terminology: - "Forced tunneling" described the spoke-to-firewall hop. That term means routing the firewall's own internet-bound traffic to on-premises. Describe the spoke subnet default route instead. - An IPv4 route can't be modified to carry IPv6, because each route has a single destination prefix. Tell readers to create separate IPv6 routes. Service behavior: - HA ports rules use protocol All and port 0, and cover all protocols including ICMP. ICMPv6 carries Neighbor Discovery and Path MTU Discovery, so this matters for IPv6. - ExpressRoute and VPN coexistence doesn't produce failover on its own. On-premises must prefer ExpressRoute routes. - Virtual Network Manager deploys configurations; it doesn't monitor network health. Metadata: - Restore products and categories that the Markdown conversion dropped. * edits * edits * edits * Correct Azure Bastion targets and align route propagation guidance Azure Bastion sits in the hub, but the workload virtual machines are in the spokes. The Components entry described remote access to virtual machines in the hub network, which names the wrong targets and contradicts the workflow. No diagram change is needed, because the diagram already places Bastion in the hub and the virtual machines in the spokes. The ExpressRoute step still said to confirm propagation on the gateway subnet, which contradicted the corrected passage in the hub routing section and omitted the NVA subnet that carries inspected traffic. Route propagation controls whether Azure injects gateway-learned prefixes into a subnet route table. It doesn't control whether the gateway learns them. * Apply suggestion from @v-albemi * Update diagram with NAT gateway and rewrite the long description Adds the NAT Gateway that gives the IPv6 NVA pool an egress path, relabels both traffic paths as IPv4 Inspection Path and IPv6 Inspection Path, and restores the IPv6 NVA Pool and Microsoft Azure labels that an earlier re-export dropped. Rewrites the long description to match: adds the NAT Gateway, removes the forced tunnel wording, and splits it into two paragraphs. 997 of 1000 characters. * edits * edits * image desc * image --------- Co-authored-by: Werner Rall <wernerrall@live.com> Co-authored-by: Werner Rall <weral@microsoft.com> Co-authored-by: learn-build-service-prod-03[bot] <274428581+learn-build-service-prod-03[bot]@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com>
Rename networking get-started page to match naming convention (#16423) * Initial plan * Rename networking get-started page and add redirect Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com> * Fix duplicate redirect document-id for networking get-started URL Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>
Add ai-usage: ai-assisted to category getting-started pages Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>
Point hub-spoke deployment links to GitHub repo folders Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>
Use Learn samples-catalog paths for new hub-spoke deployment repo Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>
Update hub-spoke deployment links to Azure-Samples/azure-hub-spoke repo Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>
PNP Edit: Hub-Spoke Network Topology using Azure Virtual WAN (#16296) * in progress * draft * copilot * touchups * peer review cx * touchups * Update docs/networking/architecture/hub-spoke-virtual-wan-architecture-content.md --------- Co-authored-by: Chad Kittel <chad.kittel@gmail.com>
PNP edit: 4 hybrid ARB articles (#16182) * 1st edit * 1st edit * updated diagram * ER edit * updates diagrams * added distinction between ER private peering and MS peering * update MS peering * updated diagrams * draft * major updates * security considerations updates * updated diagrams * considerations update * minor updates * minor updates * minor changes * renaming of the hybrid connectivity docs * ARB-Hybrid - Azure Networking Updates * 1st edit * 1st edit * updated diagram * ER edit * updates diagrams * added distinction between ER private peering and MS peering * update MS peering * updated diagrams * draft * major updates * security considerations updates * updated diagrams * considerations update * minor updates * minor updates * minor changes * renaming of the hybrid connectivity docs * ARB-Hybrid - Azure Networking Updates * fixing syntax error * fixing syntax error * fixing cross referencing * updated titles in TOC file * section title update * cross-references updates * cross-ref update for hybrid networking reference architectures * reference update * correct build warnings * minor build warnings * minor build warning * missing redirect * thumbnail updates to resolve remaining build warnings * acrolynx clarity and thumbnails * thumbnail error * Apply suggestions from formatting review * Update links and image syntax in documentation * Update image syntax and fix link formatting * Update ExpressRoute private peering documentation * Fix links and image formatting in hybrid connectivity options Updated links and image syntax for better clarity and consistency. * Refactor links and image syntax in VPN connectivity doc Updated links to use relative paths and modified image syntax for better compatibility. * Update docs/reference-architectures/hybrid-networking/hybrid-connectivity-options-content.md * acrolynx corrections * pandora: submit 62 annotation(s) for review * Pandora - content dev edits * edits to workflow * test * pandora: replace 3 annotation marker(s) with GitHub comment links * pandora: replace 3 annotation marker(s) with GitHub comment links * delete test file * test * test * test * Revise ExpressRoute and VPN failover documentation Updated the document to include metadata and improved title and description for clarity. * Delete docs/reference-architectures/hybrid-networking/expressroute-private-peering-connectivity.yml * Rename expressroute-vpn-failover-content.md to expressroute-vpn-failover.md * Clarify ExpressRoute and VPN failover details Updated the explanation of ExpressRoute and VPN failover architecture for clarity and accuracy. * Delete docs/reference-architectures/hybrid-networking/expressroute-vpn-failover.yml * Add ExpressRoute private peering connectivity YAML * Update hybrid-vpn-connectivity-content.md * Delete docs/reference-architectures/hybrid-networking/hybrid-connectivity-options.yml * Enhance hybrid connectivity options documentation Add metadata and introductory content for hybrid connectivity options. * Rename hybrid-connectivity-options-content.md to hybrid-connectivity-options.md * Revise VPN Gateway SLA and enhance VPN resiliency section Updated service-level agreement terminology and modified reference architecture links. Added strategies for improving VPN Gateway availability. * fix yml to md link references * fix link * fix link * Refine hybrid VPN connectivity documentation Removed placeholder questions and assumptions from the document, clarified architecture components, and ensured consistency in terminology. * Update ms.topic and ms.subservice in YAML file * Refactor ExpressRoute private peering documentation Updated the content to improve clarity and structure, including reformatting sections and enhancing descriptions of components. * Revise Azure VPN connectivity documentation for clarity Updated the document to clarify the structure and content regarding Azure VPN connectivity, including adjustments to assumptions, issues, and architectural alternatives. * Refine VPN connectivity documentation and remove assumptions Removed outdated assumptions and issues regarding VPN gateway configurations and clarified requirements for active-active mode. Updated descriptions for Azure VPN Gateway and related components. * Revise Azure VPN Gateway documentation for clarity Updated the documentation to clarify the requirements for public IP addresses and the deployment modes of Azure VPN Gateway. Removed outdated assumptions and issues regarding active-active mode and SKU requirements. * Update hub-spoke-content.md * Revise headings and enhance document structure Updated section headings and improved content organization for clarity. Added a note regarding the placement of diagrams in the document. * Update hybrid-vpn-connectivity-content.md * fix warnings * edits * updates * remove deploy this scenario section * change template * change template * content dev review * edits * edits * edits * images * images * edits * edits * edits * edits * edits * date * edits * edits * edits * edits * edits * edits * edits * links * edits * edits * edits * edits * edits * edits * revert mistake caused by merge conflict * delete unneded thumbnails * remove file accidentally added * redirect fixes * link * feedback * links * feedback --------- Co-authored-by: Cynthia Treger <ctreger@microsoft.com> Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> Co-authored-by: Anastasia Harris <61602255+anaharris-ms@users.noreply.github.com> Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com>
Delete sub tocs (#16176) * Flatten main TOC: inline AI-ML, Networking, Web Apps, SaaS sub-TOCs into docs/toc.yml - Replace single-line href references for AI + Machine Learning, Networking, Web applications, and Architecture for SaaS and multitenancy with full inline navigation trees in docs/toc.yml. - Adjust all relative hrefs to be docs/-relative (no sub-TOC context needed). - Rename sections to new model: Solution ideas / Architectures / Guides. - Sub-TOC files remain on disk but are no longer referenced from main navigation. * Remove sub-TOC files superseded by flattened main TOC Deletes the four workload sub-TOC files that are no longer referenced from main navigation after docs/toc.yml was flattened in the preceding PR: - docs/ai-ml/toc.yml - docs/networking/toc.yml - docs/web-apps/toc.yml - docs/guide/saas-multitenant-solution-architecture/toc.yml docs/_bread/toc.yml contains no references to these files and requires no changes. No redirects needed; these files are navigation metadata only and have no published URLs. * Commit 1: Remove Technology choices section from Application architecture fundamentals Delete the entire Technology choices section as all items have been distributed to their respective Azure categories: - Compute articles → Compute/Guides - Container articles → Containers/Guides - Storage articles → Storage/Guides - Data store and data movement articles → Databases and Integration Guides - Analytics articles → Analytics/Guides - AI service articles → AI + ML/Guides - Networking articles → Networking/Guides - Messaging articles → Integration/Guides - Hybrid articles → Hybrid + multicloud/Guides The 'Overview' article is deleted as it no longer serves a purpose once the section is removed. * Commit 2: Reposition Azure categories to position 3 in TOC Move the entire 'Azure categories' section from its original position (after Design patterns) to position 3, right after 'What's new'. New top-level order: 1. Browse all Architectures 2. What's new 3. Azure categories (MOVED) 4. Landing zones 5. Application architecture fundamentals 6. Design patterns 7. [other sections] 8. Microsoft Azure Well-Architected Framework 9. Cloud Adoption Framework for Azure This elevates the Azure workload categories in the navigation hierarchy, making them more prominent for users seeking technology-specific guidance. * Commit 3: Move Design patterns into Application architecture fundamentals Nest the 'Design patterns' section as a subordinate category under 'Application architecture fundamentals' rather than as a top-level TOC item. This consolidates application-focused content and creates a clearer hierarchy: Before: - Application architecture fundamentals - Design patterns After: - Application architecture fundamentals - ... [existing subsections] - Design patterns - Overview - Pattern implementations - [46 individual patterns] All 123 lines of Design patterns content are relocated with proper indentation, and the section is removed from the top-level navigation. * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Update docs/toc.yml Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * re-ordered to move Azure categories down * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fixed azure categories ordering * Fix Azure categories ordering regressions * Remove duplicate AI+ML parent link in TOC * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * minor fixes * minor fixes 2 * add Select a service sections for technology choices * add missing Select a service technology choices * fixing regressions * minor fixes 3 * normalize category redirects and update stale MongoDB links * Apply suggestions from code review Co-authored-by: Clayton Siemens <84867658+claytonsiemens77@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * add analytics service-choice links for data stores and stream processing * Apply suggestions from code review Co-authored-by: Clayton Siemens <84867658+claytonsiemens77@users.noreply.github.com> * redirect fixes * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * redirect-fix * reorder sap subsections in compute toc * normalize integration and kubernetes hosting toc order * fixing container guides * fixing container guides --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com>
Pipeline: Network Get Started (#15925) * draft * update * removed kal * removed kal * removed kal * Update index.md * edit * Fix capitalization and improve clarity in networking docs Corrected capitalization in the section title and rephrased sentences for clarity in the Azure networking documentation. @claytonsiemens77 This one is ready. * update image * update image * edits * link * edits * gitignore * template * edit * edits * Apply suggestions from code review Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> * file name * links * redirect * redirect * link * fix redirect file * remove learn section --------- Co-authored-by: Anastasia Harris <61602255+anaharris-ms@users.noreply.github.com> Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com>
Pipeline: Freshness review SDWAN integration (#15907) * Freshness review - 3/17/2026 * Apply suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Freshness review 3/19/2026 * Freshness review - 3/19/2026 * Resolved pending conversations * convert .md+.yml pair to .md file * edits * Apply suggestions from code review Co-authored-by: Mick Alberts <v-albemi@microsoft.com> * Apply suggestions from code review Co-authored-by: Mick Alberts <v-albemi@microsoft.com> Co-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com> * edits * test edit * rename files * file name changes * fix * Update hub-spoke-content.md * Apply suggestions from code review Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> * Apply suggestions from PR review Co-authored-by: Stacy Chambers <102548089+Stacyrch140@users.noreply.github.com> * revert suggestion --------- Co-authored-by: Federico Guerrini <fguerri@microsoft.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Mick Alberts <v-albemi@microsoft.com> Co-authored-by: Jodi Martis <v-jodimartis@microsoft.com> Co-authored-by: Stacy Chambers <102548089+Stacyrch140@users.noreply.github.com>
Network Virtual Appliance HA - Update diagrams and remove double negation (#15987) * Update diagrams Eliminate double negation (do not disable gateway route propagation) * Delete diagram * Delete file * Added fixed files Double negation removed, fixed GatewaySubnet (propagate gateway routes)