Skip to content

Commit a4c927b

Browse files
authored
Merge branch 'main' into defender-exclusions
2 parents 8acfa1d + 06ec108 commit a4c927b

15 files changed

+290
-265
lines changed

AKS-Arc/aks-hci-network-system-requirements.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: AKS enabled by Azure Arc network requirements
33
description: Learn about AKS network prerequisites.
44
ms.topic: overview
5-
ms.date: 11/19/2024
5+
ms.date: 04/23/2025
66
author: sethmanheim
77
ms.author: sethm
88
ms.reviewer: abha
@@ -64,6 +64,9 @@ Regardless of the option you choose, you must ensure that the IP addresses alloc
6464

6565
Proxy settings in AKS are inherited from the underlying infrastructure system. The functionality to set individual proxy settings for Kubernetes clusters and change proxy settings isn't supported yet. For more information on how to set proxy correctly, see [proxy requirements for Azure Local](/azure/azure-local/manage/configure-proxy-settings-23h2).
6666

67+
> [!WARNING]
68+
> You cannot update incorrect proxy settings after you deploy Azure Local. If the proxy is misconfigured, you must redeploy Azure Local.
69+
6770
## Firewall URL exceptions
6871

6972
Firewall requirements for AKS have been consolidated with Azure Local firewall requirements. See [Azure Local firewall requirements](/azure/azure-local/concepts/firewall-requirements) for list of URLs that need to be allowed to successfully deploy AKS.

azure-local/concepts/compare-windows-server.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.topic: conceptual
55
author: alkohli
66
ms.author: alkohli
77
ms.service: azure-local
8-
ms.date: 03/28/2025
8+
ms.date: 04/08/2025
99
---
1010

1111
# Compare Azure Local to Windows Server
@@ -18,7 +18,7 @@ When replacing a datacenter primarily running VMware, Azure Local is typically n
1818

1919
## When to use Azure Local
2020

21-
Azure Local is Microsoft's premier hyperconverged infrastructure platform for running VMs or virtual desktops on-premises with connections to Azure hybrid services. Azure Local can help to modernize and secure your datacenters and branch offices, and achieve industry-best performance with low latency and data sovereignty.
21+
Azure Local is Microsoft's premier hyperconverged infrastructure platform for running virtual machines (VMs) or virtual desktops on-premises with connections to Azure hybrid services. Azure Local can help to modernize and secure your datacenters and branch offices, and achieve industry-best performance with low latency and data sovereignty.
2222

2323
:::image type="content" source="media/compare-windows-server/hci-scenarios.png" alt-text="When to use Azure Local over Windows Server 2019" border="false" lightbox="media/compare-windows-server/hci-scenarios.png":::
2424

@@ -41,7 +41,7 @@ Windows Server is a highly versatile, multi-purpose operating system with dozens
4141

4242
Use Windows Server for:
4343

44-
- A guest operating system inside of virtual machines (VMs) or containers
44+
- A guest operating system inside of VMs or containers
4545
- As the runtime server for a Windows application
4646
- To use one or more of the built-in server roles such as Active Directory, file services, DNS, DHCP, or Internet Information Services (IIS)
4747
- As a traditional server, such as a bare-metal domain controller or SQL Server installation
@@ -119,7 +119,7 @@ The following table compares the management options for Azure Local and Windows
119119
| Azure portal > Windows Admin Center integration (preview) | Yes | Azure VMs only <sup>1</sup>|
120120
| Azure portal > Multi-cluster monitoring for Azure Local | Yes | No |
121121
| Azure portal > Azure Resource Manager integration for clusters | Yes | No |
122-
| Azure portal > Arc VM management | Yes | No |
122+
| Azure portal > Management of Azure Local VMs enabled by Arc | Yes | No |
123123
| Desktop experience | No | Yes |
124124

125125
<sup>1</sup> Requires manually installing the Arc-git statusConnected Machine agent on every machine.

azure-local/concepts/firewall-requirements.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,25 @@ For a consolidated list of endpoints for Japan East that includes Azure Local, A
6565
For a consolidated list of endpoints for South Central US that includes Azure Local, Arc-enabled servers, ARB, and AKS, use:
6666
- [Required endpoints in South Central US for Azure Local](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/SouthCentralUSEndpoints/southcentralus-hci-endpoints.md)
6767

68+
## Firewall requirements for OEMs
69+
70+
Depending on the OEM you are using for Azure Local you may need to open additional endpoints in your firewall.
71+
72+
DataON required endpoints for Azure Local deployments
73+
- [DataOn required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/DataOn/DataOnAzureLocalEndpoints.md)
74+
75+
Dell required endpoints for Azure Local deployments
76+
- [Dell required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Dell/DellAzureLocalEndpoints.md)
77+
78+
HPE required endpoints for Azure Local deployments
79+
- [HPE required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/HPE/HPEAzureLocalEndpoints.md)
80+
81+
Hitachi required endpoints for Azure Local deployments
82+
- [Hitachi required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Hitachi/HitachiAzureLocalEndpoints.md)
83+
84+
Lenovo required endpoints for Azure Local deployments
85+
- [Lenovo required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Lenovo/LenovoAzureLocalEndpoints.md)
86+
6887
## Firewall requirements for additional Azure services
6988

7089
Depending on additional Azure services you enable for Azure Local, you may need to make additional firewall configuration changes. Refer to the following links for information on firewall requirements for each Azure service:

azure-local/deploy/deployment-azure-arc-gateway-overview.md

Lines changed: 28 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Overview of Azure Arc gateway for Azure Local, version 23H2 (preview)
33
description: Learn what is Azure Arc gateway for Azure Local, version 23H2 (preview).
44
author: alkohli
55
ms.topic: how-to
6-
ms.date: 04/10/2025
6+
ms.date: 04/23/2025
77
ms.author: alkohli
88
ms.service: azure-local
99
---
@@ -89,37 +89,36 @@ Unsupported scenarios for Azure Local include:
8989

9090
## Azure Local endpoints not redirected
9191

92-
As part of the Azure Local version 2411.1 preview update, the endpoints from the table are required and must be allowlisted in your proxy or firewall to deploy the Azure Local instance. These version 2408 and 2411 endpoints are not redirected via the Arc gateway:
92+
The endpoints from the table are required and must be allowlisted in your proxy or firewall to deploy the Azure Local instance:
9393

9494
| Endpoint # | Required endpoint | Component |
9595
| -- | -- | -- |
96-
| 1 | `http://go.microsoft.com:443` | Arc registration |
97-
| 2 | `http://login.microsoftonline.com:443` | Arc registration |
98-
| 3 | `http://<region>.login.microsoft.com:443` | Arc registration |
99-
| 4 | `http://download.microsoft.com:443` | Arc registration |
100-
| 5 | `http://management.azure.com:443` | Arc registration |
101-
| 6 | `http://gbl.his.arc.azure.com:443` | Arc registration |
102-
| 7 | `http://<region>.his.arc.azure.com:443` | Arc registration |
103-
| 8 | `http://dc.services.visualstudio.com:443` | Arc registration |
104-
| 9 | `https://<region>.obo.arc.azure.com:8084` | AKS extensions |
105-
| 10 | `http://<yourarcgatewayId>.gw.arc.azure.com:443` | Arc gateway |
106-
| 11 | `http://<yourkeyvaultname>.vault.azure.net:443` | Azure Key Vault |
107-
| 12 | `http://<yourblobstorageforcloudwitnessname>.blob.core.windows.net:443` | Cloud Witness Storage Account |
108-
| 13 | `http://files.pythonhosted.org:443` | Microsoft On-premises Cloud/ARB/AKS |
109-
| 14 | `http://pypi.org:443` | Microsoft On-premises Cloud/ARB/AKS |
110-
| 15 | `http://raw.githubusercontent.com:443` | Microsoft On-premises Cloud/ARB/AKS |
111-
| 16 | `http://pythonhosted.org:443` | Microsoft On-premises Cloud/ARB/AKS |
112-
| 17 | `http://ocsp.digicert.com` | Certificate Revocation List for Arc extensions |
113-
| 18 | `http://s.symcd.com` | Certificate Revocation List for Arc extensions |
114-
| 19 | `http://ts-ocsp.ws.symantec.com` | Certificate Revocation List for Arc extensions |
115-
| 20 | `http://ocsp.globalsign.com` | Certificate Revocation List for Arc extensions |
116-
| 21 | `http://ocsp2.globalsign.com` | Certificate Revocation List for Arc extensions |
117-
| 22 | `http://oneocsp.microsoft.com` | Certificate Revocation List for Arc extensions |
118-
| 23 | `http://dl.delivery.mp.microsoft.com` | Windows Update |
119-
| 24 | `http://*.tlu.dl.delivery.mp.microsoft.com` | Windows Update |
120-
| 25 | `http://*.windowsupdate.com` | Windows Update |
121-
| 26 | `http://*.windowsupdate.microsoft.com` | Windows Update |
122-
| 27 | `http://*.update.microsoft.com` | Windows Update |
96+
| 1 | `http://login.microsoftonline.com:443` | Arc registration |
97+
| 2 | `http://<region>.login.microsoft.com:443` | Arc registration |
98+
| 3 | `http://management.azure.com:443` | Arc registration |
99+
| 4 | `http://gbl.his.arc.azure.com:443` | Arc registration |
100+
| 5 | `http://<region>.his.arc.azure.com:443` | Arc registration |
101+
| 6 | `http://dc.services.visualstudio.com:443` | Arc registration |
102+
| 7 | `https://<region>.obo.arc.azure.com:8084` | AKS extensions |
103+
| 8 | `http://<yourarcgatewayId>.gw.arc.azure.com:443` | Arc gateway |
104+
| 9 | `http://<yourkeyvaultname>.vault.azure.net:443` | Azure Key Vault |
105+
| 10 | `http://<yourblobstorageforcloudwitnessname>.blob.core.windows.net:443` | Cloud Witness Storage Account |
106+
| 11 | `http://files.pythonhosted.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
107+
| 12 | `http://pypi.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
108+
| 13 | `http://raw.githubusercontent.com:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
109+
| 14 | `http://pythonhosted.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
110+
| 15 | `http://ocsp.digicert.com` | Certificate Revocation List for Arc extensions |
111+
| 16 | `http://s.symcd.com` | Certificate Revocation List for Arc extensions |
112+
| 17 | `http://ts-ocsp.ws.symantec.com` | Certificate Revocation List for Arc extensions |
113+
| 18 | `http://ocsp.globalsign.com` | Certificate Revocation List for Arc extensions |
114+
| 19 | `http://ocsp2.globalsign.com` | Certificate Revocation List for Arc extensions |
115+
| 20 | `http://oneocsp.microsoft.com` | Certificate Revocation List for Arc extensions |
116+
| 21 | `http://crl.microsoft.com/pkiinfra` | Certificate Revocation List for Arc extensions |
117+
| 22 | `http://dl.delivery.mp.microsoft.com` | Windows Update |
118+
| 23 | `http://*.tlu.dl.delivery.mp.microsoft.com` | Windows Update |
119+
| 24 | `http://*.windowsupdate.com` | Windows Update |
120+
| 25 | `http://*.windowsupdate.microsoft.com` | Windows Update |
121+
| 26 | `http://*.update.microsoft.com` | Windows Update |
123122

124123
## Restrictions and limitations
125124

azure-local/deploy/download-23h2-software.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@ author: alkohli
55
ms.author: alkohli
66
ms.topic: how-to
77
ms.service: azure-local
8-
ms.date: 04/21/2025
8+
ms.date: 04/23/2025
99
---
1010

11-
# Download version 23H2 operating system for Azure Local deployment
11+
# Download operating system for Azure Local deployment
1212

1313
[!INCLUDE [hci-applies-to-23h2](../includes/hci-applies-to-23h2.md)]
1414

@@ -27,6 +27,7 @@ Before you begin the download of the software from Azure portal, ensure that you
2727
- [Pay-as-you-go](https://azure.microsoft.com/pricing/purchase-options/pay-as-you-go/) subscription with credit card.
2828
- Subscription obtained through an Enterprise Agreement (EA).
2929
- Subscription obtained through the Cloud Solution Provider (CSP) program.
30+
- At a minimum, you'll need **Reader** access at the subscription level.
3031

3132
- Register the Microsoft Azure Stack HCI resource provider. For more information, see [Register your machines and assign permissions for Azure Local deployment](deployment-arc-register-server-permissions.md).
3233

azure-local/faq.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
author: cosmosdarwin
77
ms.author: cosdar
88
ms.service: azure-local
9-
ms.date: 02/03/2025
9+
ms.date: 04/08/2025
1010
title: Azure Local FAQ
1111
summary: The Azure Local FAQ provides information about Azure Local connectivity with the cloud, and how Azure Local relates to Windows Server.
1212

@@ -54,7 +54,7 @@ sections:
5454
answer: |
5555
While your connection is down, all host infrastructure and VMs continue to run normally, and you can use edge-local tools for management. However, you wouldn't be able to use features that directly rely on cloud services. Information in the Azure portal may also become out-of-date until Azure Local is able to sync again.
5656
57-
Configuration changes made to Arc VMs using edge-local tools won't automatically sync with Azure.
57+
Configuration changes made to Azure Local VMs enabled by Arc using edge-local tools won't automatically sync with Azure.
5858
5959
- question: How long can Azure Local run with the connection down?
6060
answer: |

azure-local/includes/hci-download-vhdx.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ author: alkohli
33
ms.author: alkohli
44
ms.service: azure-local
55
ms.topic: include
6-
ms.date: 10/11/2024
6+
ms.date: 04/22/2025
77
---
88

99

@@ -12,9 +12,9 @@ SDN uses a VHDX file containing either the Azure Stack HCI or Windows Server ope
1212
> [!NOTE]
1313
> The version of the OS in your VHDX must match the version used by the Azure Local Hyper-V machines. This VHDX file is used by all SDN infrastructure components.
1414
15-
To download an English-language version of the VHDX file, see [Download the operating system from the Azure portal](../deploy/download-23h2-software.md). Make sure to select **English VHDX** from the **Choose language** dropdown list.
15+
[Download an English-language version of the VHDX file](https://aka.ms/PVvxVBVCVVC).
1616

17-
Currently, a non-English VHDX file isn't available for download. If you require a non-English version, download the corresponding ISO file and convert it to VHDX using the `Convert-WindowsImage` cmdlet. You must run this script from a Windows client computer. You'll probably need to run this script as Administrator and modify the execution policy for scripts using the `Set-ExecutionPolicy` command.
17+
Currently, a non-English VHDX file isn't available for download. If you require a non-English version, [download the corresponding ISO file](../deploy/download-23h2-software.md) and convert it to VHDX using the `Convert-WindowsImage` cmdlet. You must run this script from a Windows client computer. You'll probably need to run this script as Administrator and modify the execution policy for scripts using the `Set-ExecutionPolicy` command.
1818

1919
The following syntax shows an example of using `Convert-WindowsImage`:
2020

0 commit comments

Comments
 (0)