You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: azure-local/security-update/security-update.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ This section applies to existing deployments of 2504 running OS build **25398.15
33
33
34
34
## Improvements
35
35
36
-
This security update includes quality improvements. Below is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change.
36
+
This security update includes quality improvements. Here is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change.
37
37
38
38
-**[Daylight saving time (DST)]** Update for the Aysen region in Chile to support the government DST change order in 2025. For more info about DST changes, see the [Daylight Saving Time & Time Zone Blog](https://techcommunity.microsoft.com/category/windows/blog/dstblog).
39
39
@@ -47,15 +47,15 @@ The following is a known issue with this update.
47
47
48
48
Devices that have certain Citrix components installed might be unable to complete installation of the January 2025 Windows security update. This issue was observed on devices with [Citrix Session Recording Agent (SRA)](https://docs.citrix.com/en-us/session-recording/current-release/install-upgrade-uninstall.html), version 2411. The 2411 version of this application was released in December 2024.
49
49
50
-
Affected devices might initially download and apply the January 2025 Windows security update correctly, such as via the Windows Update page in Settings. However, when restarting the device to complete the update installation, an error message with text similar to "*Something didn’t go as planned. No need to worry – undoing changes*" appears. The device will then revert to the Windows updates previously present on the device.
50
+
Affected devices might initially download and apply the January 2025 Windows security update correctly, such as via the Windows Update page in Settings. However, when restarting the device to complete the update installation, an error message with text similar to "*Something didn’t go as planned. No need to worry – undoing changes*" appears. The device then reverts to the Windows updates previously present on the device.
51
51
52
-
This issue likely affects a limited number of organizations as version 2411 of the SRA application is a new version. Home users are not expected to be affected by this issue.
52
+
This issue likely affects a limited number of organizations as version 2411 of the SRA application is a new version. Home users aren't expected to be affected by this issue.
53
53
54
54
**Workaround**
55
55
56
56
Citrix has documented this issue, including a workaround, which can be performed prior to installing the January 2025 Windows security update. For details, see [Citrix support documentation](https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US).
57
57
58
-
Microsoft is working with Citrix to address this issue and will update this documentation once a resolution is available.
58
+
Microsoft is working with Citrix to address this issue and update this documentation once a resolution is available.
59
59
60
60
## To install
61
61
@@ -74,9 +74,9 @@ This section applies to new deployments of 2504 running OS build **26100.3775**.
74
74
75
75
## Improvements
76
76
77
-
This security update includes quality improvements. Below is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change.
77
+
This security update includes quality improvements. Here is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change.
78
78
79
-
-**[Authentication]** This update addresses an issue affecting machine password rotation in the Identity Update Manager certificate/Pre-Bootstrapping Key Initialization path. This issue occurred particularly when Kerberos was used and Credential Guard was enabled, potentially causing user authentication problems. The feature **Machine Accounts in Credential Guard**, which is dependent on password rotation via Kerberos, has also been disabled until a permanent fix is made available.
79
+
-**[Authentication]** This update addresses an issue affecting machine password rotation in the Identity Update Manager certificate/Pre-Bootstrapping Key Initialization path. This issue occurred particularly when Kerberos was used and Credential Guard was enabled, potentially causing user authentication problems. The feature **Machine Accounts in Credential Guard**, which is dependent on password rotation via Kerberos, is disabled until a permanent fix is made available.
80
80
81
81
-**[Daylight Saving Time (DST)]** This update is for the Aysen region in Chile to support the government DST change order in 2025. For more info about DST changes, see the [Daylight Saving Time & Time Zone Blog](https://techcommunity.microsoft.com/category/windows/blog/dstblog).
82
82
@@ -86,15 +86,15 @@ For more information about security vulnerabilities, see the [Security Update Gu
86
86
87
87
## Known issues
88
88
89
-
The following is a known issue with this update.
89
+
This update has the following known issues:
90
90
91
91
**Symptom**
92
92
93
93
Devices that have certain Citrix components installed might be unable to complete installation of the January 2025 Windows security update. This issue was observed on devices with [Citrix Session Recording Agent (SRA) version 2411](https://docs.citrix.com/en-us/session-recording/current-release/install-upgrade-uninstall.html). The version 2411 version of this application was released in December 2024.
94
94
95
95
Affected devices might initially download and apply the January 2025 Windows security update correctly, such as via the Windows Update page in Settings. However, when restarting the device to complete the update installation, an error message with text similar to *"Something didn’t go as planned. No need to worry – undoing changes"* appears. The device will then revert to the Windows updates previously present on the device.
96
96
97
-
This issue likely affects a limited number of organizations as version 2411 of the SRA application is a new version. Home users are not expected to be affected by this issue.
97
+
This issue likely affects a limited number of organizations as version 2411 of the SRA application is a new version. Home users aren't expected to be affected by this issue.
98
98
99
99
**Workaround**
100
100
@@ -129,11 +129,11 @@ This security update includes quality improvements. Below is a summary of the ke
129
129
130
130
-**[Daylight saving time (DST)]** This update supports (DST) changes in Paraguay.
131
131
132
-
-**[Open Secure Shell (OpenSSH) (known issue)]** Fixed: The service fails to start, which stops SSH connections. There is no detailed logging, and you must run the sshd.exe process manually.
132
+
-**[Open Secure Shell (OpenSSH) (known issue)]** Fixed: The service fails to start, which stops SSH connections. There's no detailed logging, and you must run the sshd.exe process manually.
133
133
134
134
-**[GB18030-2022]** This update adds support for this amendment.
135
135
136
-
-**[Azure Virtual Network]** Fixed: You can turn off the VNET metering feature with the following registry key:
136
+
-**[Azure Virtual Network]** Fixed: You can turn off the virtual network metering feature with the following registry key:
This article lists the various features and improvements that are available in Azure Local. The latest version of Azure Local solution focuses on cloud-based deployment and updates, cloud-based monitoring, new and simplified experience for Azure Local VM management, security, and more.
17
+
This article lists the various features and improvements that are available in Azure Local. The latest version of Azure Local solution focuses on cloud-based deployment and updates, cloud-based monitoring, new and simplified experience for Azure Local virtual machine (VM) management, security, and more.
18
18
19
19
::: moniker range="=azloc-2504"
20
20
21
-
Starting with 2504 release, Microsoft has introduced a new versioning schema. There are two 2504 releases for April. Here are the details of each release:
21
+
Starting with 2504 release, Microsoft introduced a new versioning schema. There are two 2504 releases for April. Here are the details of each release:
22
22
23
23
24
24
|Solution version |OS version |Deployment |
@@ -32,7 +32,7 @@ For more information, see [Release information summary](./release-information-23
32
32
33
33
This release has the following features and improvements:
34
34
35
-
-**OS version changes**: Starting 2504, all new Azure Local deployments will use a new operating system (OS) version **261000.3775**. Existing deployments will continue to use the OS version **23598.1551**. For more information, see [Release information summary](./release-information-23h2.md).
35
+
-**OS version changes**: Starting 2504, all new Azure Local deployments use a new operating system (OS) version **261000.3775**. Existing deployments continue to use the OS version **23598.1551**. For more information, see [Release information summary](./release-information-23h2.md).
36
36
37
37
-**.NET update installations improvements**:
38
38
- Increased reliability of .NET security update installations.
@@ -61,9 +61,9 @@ This release has the following features and improvements:
61
61
- Improved reliability of copying solution extension content locally to each machine.
62
62
- Added specification of plug-in name in the solution extension.
63
63
64
-
-**Billing changes**: For any new deployments running solution version 12.2504.1001.20 and later, the usage record originates from the Azure Local resource in the Azure directly. For mre information, see [Billing](./concepts/billing.md#billing-changes-for-122504100120-and-later).
64
+
-**Billing changes**: For any new deployments running solution version 12.2504.1001.20 and later, the usage record originates from the Azure Local resource in Azure directly. For more information, see [Billing](./concepts/billing.md#billing-changes-for-122504100120-and-later).
65
65
66
-
-**Archival of Azure Local, version 22H2 documentation**: The documentation for version 22H2 will be archived by May 31, 2025 and will be available in the [Azure previous versions documentation](/previous-versions/azure/) for reference. The archived documentation won't be updated and is not supported.
66
+
-**Archival of Azure Local, version 22H2 documentation**: The documentation for version 22H2 will be archived by May 31, 2025 and will be available in the [Azure previous versions documentation](/previous-versions/azure/) for reference. The archived documentation isn't updated and isn't supported.
67
67
68
68
::: moniker-end
69
69
@@ -72,11 +72,11 @@ This release has the following features and improvements:
72
72
## Features and improvements in 2503
73
73
74
74
75
-
This is a baseline release with the following features and improvements:
75
+
This release has the following features and improvements:
76
76
77
77
-**Preview availability of Azure Government cloud** - Azure Local is now available in the US Government regions in preview. Download the latest Azure Stack HCI OS image for Azure Government from [OS image](https://aka.ms/hcireleaseimage). For more information on where Azure Government is supported, see [Azure Local supported regions](./concepts/system-requirements-23h2.md#azure-requirements).
78
78
79
-
The following preview features are not supported for Azure Local in Azure Government cloud:
79
+
The following preview features aren't supported for Azure Local in Azure Government cloud:
-[Deploy using local identity with Key Vault](./deploy/deployment-local-identity-with-key-vault.md).
@@ -99,11 +99,11 @@ This is a baseline release with the following features and improvements:
99
99
- Environment checker validates PowerShell modules as per the validated solution recipe in the Pre-Update checks.
100
100
101
101
-**Updates and upgrade improvements**
102
-
- The Solution Builder Extension update now supports both supported and non-supported SKUs for a given model.
103
-
- A tag has been added to indicate whether an update is the latest or has been superseded.
102
+
- The Solution Builder Extension update now supports both supported and nonsupported SKUs for a given model.
103
+
- A tag is added to indicate whether an update is the latest or is superseded.
104
104
- HTTP content is now downloaded using a more resilient service (Download Service).
105
105
- OS content is packaged with the release, rather than determining applicable content on the device at runtime. This change is aimed to minimize failure points and support [Importing content](update/update-via-powershell-23h2.md#step-3-import-and-rediscover-updates).
106
-
- OS content will be installed using the CAU plug-ins that are shipped with OS.
106
+
- OS content is installed using the CAU plug-ins that are shipped with OS.
107
107
- Azure Local rebranding changes were made for this update.
108
108
109
109
-**Azure Local VM changes**: You can now connect to an Azure Local VM using the SSH/RDP protocol without the need for line of sight (inside the host network). For more information, see [Connect to an Azure Local VM using SSH](./manage/connect-arc-vm-using-ssh.md).
@@ -119,7 +119,7 @@ This is a baseline release with the following features and improvements:
119
119
120
120
## Features and improvements in 2411.3
121
121
122
-
This is a baseline release with the following features and improvements:
122
+
This release has the following features and improvements:
123
123
124
124
-**Quality updates** - This build contains the latest quality updates and is based off the Operating system version 25398.1425.
125
125
-**Updated .NET version** - This build has an updated .NET version 8.0.13.
@@ -148,7 +148,7 @@ For more information on improvements in this release, see the [Fixed issues in 2
148
148
149
149
## Features and improvements in 2411.1
150
150
151
-
This is a baseline release with the following features and improvements:
151
+
This release has the following features and improvements:
152
152
153
153
-**Azure Local VMs** - Starting this release, the deletion for attached resources (network interface, disk) is blocked while the associated Azure Local VM is in creation. For more information, see [Delete a network interface](./manage/manage-arc-virtual-machine-resources.md#delete-a-network-interface) and [Delete a data disk](./manage/manage-arc-virtual-machine-resources.md#delete-a-data-disk).
154
154
@@ -164,9 +164,9 @@ For more information on improvements in this release, see the [Fixed issues in 2
164
164
165
165
## Features and improvements in 2411
166
166
167
-
This is a baseline release with the following features and improvements:
167
+
This release has the following features and improvements:
168
168
169
-
-**Renaming of Azure Stack HCI to Azure Local** - Azure Stack HCI is now a part of Azure Local. Microsoft has renamed Azure Stack HCI to Azure Local to communicate a single brand that unifies the entire distributed infrastructure portfolio.
169
+
-**Renaming of Azure Stack HCI to Azure Local** - Azure Stack HCI is now a part of Azure Local. Microsoft renamed Azure Stack HCI to Azure Local to communicate a single brand that unifies the entire distributed infrastructure portfolio.
170
170
171
171
For more information, see [Renaming Azure Stack HCI to Azure Local](./rename-to-azure-local.md).
172
172
-**Azure Local for Small Form Factor (Preview)**- Beginning this release, Azure Local supports a new class of *small* devices with reduced hardware requirements. These low cost devices are suitable for edge scenarios across the industry horizontals. The devices must meet the Windows Server certification requirements and relaxed requirements from Software Defined Data Center (SDDC) and Windows Server Software-Defined (WSSD) program.
@@ -215,9 +215,9 @@ This is a baseline release with the following features and improvements:
215
215
216
216
## Features and improvements in 2408.2
217
217
218
-
This is a baseline release with the following features and improvements:
218
+
This release has the following features and improvements:
219
219
220
-
-**Azure Local VM management improvements**: Starting this release, following improvements were made to the Azure Local VM management experience:
220
+
-**Azure Local VM management improvements**: Starting with this release, following improvements were made to the Azure Local VM management experience:
221
221
222
222
- You can set a proxy configuration for Azure VMs on the Portal.
223
223
- You can set a SQL Server configuration for Azure VMs on Portal.
@@ -226,7 +226,7 @@ This is a baseline release with the following features and improvements:
226
226
227
227
## Features and improvements in 2408.1
228
228
229
-
This is a baseline release with the following features and improvements:
229
+
This release has the following features and improvements:
230
230
231
231
-**Environment checker improvements**: Starting in this release, a new validator was added in the environment checker that checks all storage adapters in each of the nodes.
232
232
-**Install module version numbers**: Starting in this release, the install module version numbers for *Az.Accounts*, *Az. Resources*, and *Az.ConnectedMachine* were changed. For more information, see [Register machines with Azure Arc](./deploy/deployment-arc-register-server-permissions.md#register-machines-with-azure-arc).
0 commit comments