Guardrails That Hold: RAI Filters & a Governed MCP Gateway
Part 2 of the governed AI platform: a custom RAI content filter with harm thresholds, plus an MCP gateway that tiers tool access.
Part 2 of the governed AI platform: a custom RAI content filter with harm thresholds, plus an MCP gateway that tiers tool access.
How I built an internal AI platform on Microsoft Foundry with governance first: data residency, secret-less identity, and central audit.
Azure CW32 2026: Trusted Launch on by default for new Gen2 VMs, the cc_v5 confidential VM retirement on September 1st, and Firewall explicit proxy GA.
Azure CW31 2026: AI Gateway in API Management, Azure Enclave preview, Key Vault symmetric keys, and reservation exchanges ending February 2027.
Azure CW30 2026: standard service endpoint preview, IPv6 on VPN Gateway GA, DDoS custom policies, and a protected table for generative AI telemetry.
Azure CW28 2026: Chaos Studio Workspaces preview, Site Recovery churn to 500 MB/s, Blob SFTP Entra ID GA, and Entra Backup GA.
Azure CW27 2026: Claude Sonnet 5 GA in Microsoft Foundry, and why its data residency still blocks regulated Swiss workloads.
Azure CW26 2026: file share-centric management GA, Confidential Live Migration for Intel TDX VMs, and the Azure Blueprints retirement.
Azure CW22 2026: VNet flow logs connector for Sentinel, Virtual Network Manager with Virtual WAN as hub, and Istio on AKS.
Azure CW13 2026: AKS application network mesh, blue-green agent pool upgrades, SQL DB automatic index compaction, and Entra external MFA.
Azure CW12 2026: Foundry Agent Service GA with native voice, Entra ID for Blob SFTP, WAF DRS 2.2, and standard HDD retirement announced.
Azure CW10 2026: Intel TDX confidential VMs GA, Azure Firewall draft-and-deploy, Databricks Lakebase, Arc Gateway down to 7 endpoints.
Azure CW9 2026: App Gateway WAF Insights preview, Entra-restricted blob SAS tokens, AI Search sensitivity labels, and GitHub Copilot CLI goes GA.
Practical guide to Azure PIM: Entra ID and Azure roles, activation workflows, approval configs, access reviews, and Terraform automation examples.
Build an Azure governance framework with management groups, policy assignments, compliance monitoring, and automated remediation that scales.
Azure CW5 2026: ExpressRoute scalable gateway goes GA with autoscaling, new Intel/AMD v7 VM SKUs, and automatic passkey rollout for all Entra tenants.
Post-quantum cryptography in Azure: NIST FIPS 203/204/205 standards, harvest-now-decrypt-later threats, and what Azure customers should do today.
PowerShell script to audit TLS versions across Azure subscriptions, scanning 13 service types and generating CSV and HTML compliance reports.
Practical guide to Azure cloud foundation: governance, connectivity, identity, security, and management done right from day one.