惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Latest news
Latest news
T
Troy Hunt's Blog
V
Vulnerabilities – Threatpost
L
LINUX DO - 热门话题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
V
V2EX
博客园 - 司徒正美
B
Blog RSS Feed
AWS News Blog
AWS News Blog
MyScale Blog
MyScale Blog
Scott Helme
Scott Helme
Cisco Talos Blog
Cisco Talos Blog
Last Week in AI
Last Week in AI
NISL@THU
NISL@THU
博客园 - Franky
P
Proofpoint News Feed
博客园_首页
C
CERT Recently Published Vulnerability Notes
雷峰网
雷峰网
S
Schneier on Security
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
G
GRAHAM CLULEY
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
WordPress大学
WordPress大学
The Hacker News
The Hacker News
T
Threatpost
阮一峰的网络日志
阮一峰的网络日志
A
Arctic Wolf
Microsoft Azure Blog
Microsoft Azure Blog
T
The Exploit Database - CXSecurity.com
Engineering at Meta
Engineering at Meta
罗磊的独立博客
T
The Blog of Author Tim Ferriss
D
Darknet – Hacking Tools, Hacker News & Cyber Security
I
Intezer
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
K
Kaspersky official blog
SecWiki News
SecWiki News
云风的 BLOG
云风的 BLOG
美团技术团队
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Security Latest
Security Latest
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog
S
Security Affairs

The Register - Special Features: Datacenter Networking Nexus

How Broadcom is quietly invading AI infrastructure Cisco punts network-security integration as key for agentic A trip through vintage datacenter networking The network is indeed trying to become the computer Cisco fixes two critical make-me-root bugs AI could finally see DPUs take off in enterprise networks An introduction to rack-scale networking HPE Aruba touts new AI agents and network orchestrator Same suspected Chinese spies again attacking Ivanti bugs Human error and power glitches to blame for most outages Hyperconverged infrastructure now needs liquid cooling Asia reaches 50 percent IPv6 capability Rising demand for datacenter capacity sees prefabs sprout The No-Nvidia networking club delivers first spec Nvidia punts silicon photonic switches to keep GPUs fed Chinese snoops spotted on end-of-life Juniper routers
Microsoft to retire default outbound access for VMs in Azure
Richard Speed Richard Speed · 2025-06-24 · via The Register - Special Features: Datacenter Networking Nexus

INTERVIEW In September, Microsoft will retire default outbound access for VMs in Azure. "It's not quite a Y2K moment," says Aviatrix CPO Chris McHenry, "but things will break."

Deploying applications in the cloud usually requires some form of internet access. Sure, a company might create an Azure Virtual Network (vnet) to roll out their applications, but at some point, access to public services will be needed.

"So to make that easy for developers - because developers don't typically understand networking - Azure's model has been if you deploy an app, by default, it has internet access," says McHenry, "You don't have to do anything."

Simple, right? Wrong.

The problem is security. While the security team could inspect and control internet traffic when applications were deployed on-prem, if a developer deployed to Azure and accepted the defaults, "the security team no longer has any visibility, and they no longer have any control."

By going for the defaults, Microsoft takes care of all the networking stuff and assigns an IP address. "So you don't know what your IP address is," says McHenry. "You don't really have the ability to control it."

"In September of this year, that will change."

"The thing that the developer was doing beforehand, where they deploy this virtual machine, now they try to deploy another one, or they try to scale that virtual machine out – like horizontal scalability, they want to increase the performance of their application – it won't work because they're retiring that behavior of default outbound internet access."

The upshot is that developers will need to know a bit more about networking, rather than blithely clicking through the defaults.

"Microsoft is doing the right thing," says McHenry. "Anything that is existing and already deployed, if it doesn't change, it will continue to work as it does right now."

"But as soon as the developer or the application owner wants to deploy something new or change the deployment that they have in their current environment, it will no longer get that outbound internet access."

"So [it] really has a chance to break a decent amount of pipelines."

As a company, Aviatrix is all about secure cloud networking. So McHenry and his team have been keeping a close eye and discussing the implications of Microsoft's change with customers.

"There are three kinds of perspectives on this," he says. "One is 'I wasn't aware of that, this is crazy, I almost don't believe you, I'm going to have to validate this myself.' That's a very, very common perspective."

"The second one is 'We're aware of it. This is scary, but I don't believe Microsoft is going to hold to their date so we're just gonna risk it.'"

"And then the third one is 'We're really freaking out and we're actively negotiating with Microsoft to see if they can kick that date down the road."

There is, of course, a fourth response to the change, which comes from organizations with mature architectures and a good handle on their network security. They might not be affected at all.

The problem is relatively unique to Microsoft. "GCP and AWS make you do some explicit setup to make these things work," explains McHenry.

"In AWS, you have to explicitly say, 'I want a gateway to the internet, and I want a route pointing to that gateway.' In Microsoft, the lack of any configuration indicates that you have internet access. So it's like you're going back and reversing a lot of config."

Microsoft has several recommendations for affected users. One is that old standby, the fixed public IP address. "When I mentioned that at Ignite," recalls McHenry, "there was a literal groan from the audience, because it actually moves your security posture backwards."

Or you could put a fixed public IP address on a NAT gateway on the vnet, so any workloads in the vnet can access the internet via the gateway. "Now, the problem with that model is that it still doesn't solve the visibility or control problem," says McHenry. "It's really not anything different than the existing behavior."

"And again, it costs money."

There's also an approach using Azure Load Balancers. Users could even opt for Microsoft's Firewall product. "I was very surprised in all of this that they aren't recommending their firewall offering," says McHenry, "because if the intent behind this is security, you would think that that would be one of their explicit options."

"My guess for the reason they're not doing that is because it's significantly more expensive."

"So they're making this global change, and they're saying things are gonna break, like, you have to do something, and the only options you have are to add cost."

Still, although working out how severe an enterprise's exposure might be – and simply freezing a company's network configuration in a dynamic cloud world is not particularly viable – McHenry sees opportunities for administrators. "This change," he says, "is an opportunity for organizations to reassess what their security posture looks like."

The change comes after September 30. Administrators running Azure workloads, unsure of what their developers clicked during self-service, could have a busy summer ahead. ®