แก้ไข

Operational Excellence recommendations

Operational excellence recommendations in Azure Advisor can help you with:

  • Process and workflow efficiency.
  • Resource manageability.
  • Deployment best practices.

You can get these recommendations on the Operational Excellence tab of the Advisor dashboard.

  1. Sign in to the Azure portal.

  2. Search for and select Advisor from any page.

  3. On the Advisor dashboard, select the Operational Excellence tab.

API Management

Tracing functionality should be used for debugging purposes only

Traces generated by Azure API Management service may contain sensitive information that is intended for service owner and should not be exposed to clients using the service. Using tracing enabled subscription keys in production or automated scenarios creates a risk of sensitive information exposure if client making call to the service requests a trace.

Potential benefits: Avoiding the use of tracing enabled subscriptions in production scenarios minimizes the risk of inadvertent sensitive information exposure including, but not limited to keys, access tokens, passwords, internal hostnames, and IP addresses.

Impact: High

For more information, see Tutorial - Debug APIs in Azure API Management using request tracing

ResourceType: microsoft.apimanagement/service
Recommendation ID: bb3bb94d-c2f1-4f8b-97b3-7025e1a11f03

Self-hosted gateway instance(s) were identified that use gateway tokens that will expire soon

At least one deployed self-hosted gateway instance was identified that uses a gateway token that will expire in the next 7 days. To ensure that it can connect to the control-plane, generate a new gateway token and update your deployed self-hosted gateway(s). This does not impact data-plane traffic.

Potential benefits: Ensure deployed gateway(s) use the latest configuration.

Impact: High

For more information, see Self-Hosted Gateway Overview

ResourceType: microsoft.apimanagement/service
Recommendation ID: b677ed4b-1eed-45c7-b268-4280be5839f8

Use Azure AD-based authentication with self-hosted gateway

You can use Azure AD-based authentication, instead of gateway tokens, which allows you to use standard procedures to create, assign and manage permissions and control expiry times. Additionally, you gain fine-grained control across gateway deployments and easily revoke access in case of a breach.

Potential benefits: Run gateway(s) more securely with simplified management

Impact: Medium

For more information, see Azure API Management Self-Hosted Gateway - Microsoft Entra Authentication

ResourceType: microsoft.apimanagement/service
Recommendation ID: b226053d-8d25-4de4-9e26-fa30df1a4379

Use api-versions newer than 2021-08-01

Update your existing templates, tools, scripts, and programs used to configure Azure API Management to 2021-08-01 or later for our latest capabilities and support.

Potential benefits: Our newer API versions make your infrastructure more secure, reliable, and offers more functionality.

Impact: Medium

For more information, see Azure API Management - API version retirements (June 2024)

ResourceType: microsoft.apimanagement/service
Recommendation ID: 6c154595-3c5c-49d3-ac57-f122a8e1adb9

Use stronger security keys for JWT validation

Validate JWT policy is being used with security keys that have insecure key size for validating Json Web Token (JWT). We recommend using longer key sizes to improve security for JWT-based authentication & authorization.

Potential benefits: Improved security of JWT-based authentication & authorization with more robust JWT validation.

Impact: Medium

ResourceType: microsoft.apimanagement/service
Recommendation ID: 580a50ee-8300-4678-9a16-a946c948778b

Disable trusted service connectivity in API Management

Your API Management service may rely on trusted service connectivity to access other Azure services. To prevent service disruption following the retirement of this feature in March 2026, update your networking configuration and disable trusted connectivity in API Management.

Potential benefits: Prevent runtime outage of APIs in API Management

Impact: High

For more information, see Azure API Management - Trusted service connectivity retirement (March 2026)

ResourceType: microsoft.apimanagement/service
Recommendation ID: d6c54614-97fe-4f55-85cf-adb49ca7ccd3

Validate JSON Web Token (JWT) issued by Microsoft Entra ID using validate-azure-ad-token policy

The new validate-azure-ad-token policy provides a simplified configuration experience for validating JSON Web Token (JWT) issued by Microsoft Entra ID. In the future, the validate-azure-ad-token policy more tightly integrates with Microsoft Entra features.

Potential benefits: Simplified JWT validation policy for Microsoft Entra ID.

Impact: Low

For more information, see Introducing a better way to integrate Azure AD with API Management.

ResourceType: microsoft.apimanagement/service
Recommendation ID: 3b94bf03-9715-47c0-b8d4-556f5122aa6c

Use Azure Service Tag to restrict inbound connectivity for Developer and Premium VNet support

Your API Management instance uses virtual network (VNet) integration in the Developer or Premium SKU, but inbound access isn’t restricted by the Azure service tag ApiManagement. Use this service tag to limit inbound traffic and simplify network rules.

Potential benefits: Prevent outage when managing configuration.

Impact: High

For more information, see VNet configuration settings

ResourceType: microsoft.apimanagement/service
Recommendation ID: dd689461-5ae0-42f0-9cfa-1756b1712e04

App Service

Update Service Connector API Version

We have identified API calls from outdated Service Connector API for resources under this subscription. We recommend switching to the latest Service Connector API version. You need to update your existing code or tools to use the latest API version.

Potential benefits: The latest version contains fixes and improvements.

Impact: Low

For more information, see Service Connector documentation

ResourceType: microsoft.web/sites
Recommendation ID: 511c0f88-60dd-4178-9c48-36e9d61f6c85

Update Service Connector SDK to the latest version

We have identified API calls from an outdated Service Connector SDK. We recommend upgrading to the latest version for the latest fixes, performance improvements, and new feature capabilities.

Potential benefits: Improve reliability, performance, and feature availability.

Impact: Low

For more information, see Service Connector documentation

ResourceType: microsoft.web/sites
Recommendation ID: abe69199-cad8-4eb8-a915-15bcf58ff369

Application Gateway for Containers

Application Gateway

Resolve Azure Key Vault issue for your Application Gateway

We detected that one or more of your Application Gateways is unable to obtain a certificate due to misconfigured Key Vault. You should fix this configuration immediately to avoid operational issues with your gateway.

Potential benefits: Resolve control plane failures and data plane downtime

Impact: High

For more information, see Common key vault errors in Application Gateway - Azure Application Gateway

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 3467464b-955a-4caf-95e5-547344ba0281

Upgrade your legacy WAF configuration to WAF policies

WAF policies offer a richer set of advanced features: newer managed rule sets, custom rules, per rule exclusions, bot protection, and the next generation of WAF engine. Policies provide higher scale and better performance. It can be defined once and shared across gateways, listeners, and URL paths.

Potential benefits: Richer feature set, improved performance and scalability

Impact: High

For more information, see Upgrade to Azure Application Gateway WAF policy

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 47ee7abd-4f5e-45d7-9d9f-d0329616fef9

Fix DNS configuration causing resolution failures

One or more of the Application Gateways are facing DNS resolution failures due to misconfiguration in the DNS configuration.

Potential benefits: Prevents PUT failures or datapath issues within a Gateway.

Impact: High

For more information, see Azure Virtual Network Name Resolution Guide

ResourceType: microsoft.network/applicationgateways
Recommendation ID: 884975b5-12b5-433d-a633-904d8db75c5f

Remove the conflicting private frontend IP configuration

The update operations on the gateway are failing due to conflicts with static private IP addresses. To resolve the issue, remove the conflicting frontend IP configuration. Allow a day for the message to disappear after fixed.

Potential benefits: Avoid disruption in management of Application Gateway V1

Impact: High

For more information, see Remove-AzApplicationGatewayFrontendIPConfig (Az.Network)

ResourceType: microsoft.network/applicationgateways
Recommendation ID: ea000e01-b053-4076-a61b-e4cc58e9db07

Upgrade to the latest DRS rule set in Application Gateway WAF

WAF rule sets are constantly updated to guard against new attacks. Upgrading to the latest DRS version provides enhanced engine performance, improved protection, and reduced false positives. CRS rule sets are legacy versions, older than DRS; it is recommended to use the latest DRS version (DRS 2.2).

Potential benefits: Ensure increased efficiency and better protection

Impact: High

For more information, see CRS and DRS rule groups and rules - Azure Web Application Firewall

ResourceType: microsoft.network/applicationgatewaywebapplicationfirewallpolicies
Recommendation ID: 7aaefe5a-5b88-4790-9a3d-5106722f7c34

Upgrade from legacy CRS 2.2.9 rule set to the latest DRS version

Usage of CRS 2.2.9 is no longer supported for new WAF policies. We recommend you upgrade to the latest DRS version. Upgrading to DRS 2.1 or later will migrate WAF to a newer engine with larger scale limits, enhanced performance, better protection and fewer false positive.

Potential benefits: CRS 2.2.9 is no longer supported for new WAF policies

Impact: High

For more information, see CRS and DRS rule groups and rules - Azure Web Application Firewall

ResourceType: microsoft.network/applicationgatewaywebapplicationfirewallpolicies
Recommendation ID: aa60b18a-feab-4857-8d9a-e4f6a8d3ef0e

Upgrade to the latest bot protection rule set in Application Gateway WAF

Bot protection in Web Application Firewall (WAF) will protect you application against malicious bots, crawlers and scanners. Using the latest version of bot Protection rule set will ensure the WAF engine will apply the latest rules.

Potential benefits: Ensure increased efficiency and protection against bots

Impact: Medium

For more information, see What is Azure Web Application Firewall on Azure Application Gateway?

ResourceType: microsoft.network/applicationgatewaywebapplicationfirewallpolicies
Recommendation ID: fd86a3fc-2048-46a7-8ea1-d859cecf54ef

Configure Connection Monitor for ExpressRoute

Connection Monitor is part of Azure Monitor logs. The extension also lets you monitor network connectivity for your private and Microsoft peering connections. When you configure Connection Monitor for ExpressRoute, you can detect network issues to identify and eliminate.

Potential benefits: Provides monitoring of your ExpressRoute circuits for latency, point in time issues, and performance.

Impact: Medium

For more information, see Configure Connection Monitor for Azure ExpressRoute

ResourceType: microsoft.network/expressroutecircuits
Recommendation ID: 8cf57fc1-66ee-4089-a92f-29b9fdb27ea7

Migrate Azure Front Door (classic) to Standard/Premium tier

In March 2027, Azure Front Door (classic) will be retired, and you’ll need to migrate to Front Door Standard or Premium by that date. It combines the capabilities of static/dynamic content delivery with turnkey security, enhanced DevOps experiences, simplified pricing, and better Azure integrations.

Potential benefits: Avoid potential disruptions and leverage new capabilities

Impact: Medium

For more information, see Migrate Azure Front Door (classic) to Standard or Premium tier

ResourceType: microsoft.network/frontdoors
Recommendation ID: 14368063-38db-4dd6-a755-9c49ff123a5e

Upgrade to the latest DRS rule set in Front Door WAF

WAF rule sets are constantly updated to guard against new attacks. Upgrading to the latest DRS version will provide enhanced engine performance, better protection, and a reduction in false positives. It is recommended to use the latest DRS rule set version.

Potential benefits: Ensure increased efficiency and better protection

Impact: High

ResourceType: microsoft.network/frontdoorwebapplicationfirewallpolicies
Recommendation ID: a1ad465b-8218-40d6-a6ce-4bfff566a6cd

Add explicit outbound method to disable default outbound

Use an explicit connectivity method such as NAT gateway or a Public IP. After March 31, 2026, new virtual networks will default to creation of private subnets, which are intentionally designed to block default outbound access connectivity.

Potential benefits: Secure and explicit outbound access for new subnets.

Impact: Medium

For more information, see Default Outbound Access in Azure - Azure Virtual Network

ResourceType: microsoft.network/networkinterfaces
Recommendation ID: c7a883a4-fda2-4bcd-9f78-dad70c19429f

Upgrade from network security group flow log to Virtual Network flow log

Upgrade from Network Security Group flow log to powerful Virtual Network Flow Logs to capture IP Traffic across Virtual networks including gateways where NSG’s are unavailable.

Potential benefits: Broader network coverage with enhanced traffic visibility.

Impact: High

For more information, see Virtual Network Flow Logs - Azure Network Watcher

ResourceType: microsoft.network/networkwatchers/flowlogs
Recommendation ID: 6f087e7e-afdf-4a3d-a1de-41d70404b9cb

Configure Connection Monitor for ExpressRoute Gateway

Connection Monitor is part of Azure Monitor logs. The extension also lets you monitor network connectivity for your private and Microsoft peering connections. When you configure Connection Monitor for ExpressRoute, you can detect network issues to identify and eliminate.

Potential benefits: Identify and resolve network issues

Impact: Medium

For more information, see Configure Connection Monitor for Azure ExpressRoute

ResourceType: microsoft.network/virtualnetworkgateways
Recommendation ID: dedaaba3-b5aa-4e91-a12e-6886ba0b2f6d

VNet with more than 5 peerings should be managed using AVNM connectivity configuration

VNet with more than 5 peerings should be managed using Azure Virtual Network Manager (AVNM) connectivity configuration. Azure Virtual Network Manager is a management service that enables you to group, configure, deploy, and manage virtual networks globally across subscriptions.

Potential benefits: Operational excellence will be increased and more reliable.

Impact: Medium

ResourceType: microsoft.network/virtualnetworks
Recommendation ID: f8d4da72-3b27-4dd7-839c-bd69b9b95111

Monitor Azure Firewall Metrics

Monitor Azure Firewall for overall health, processed throughput, and outbound SNAT port usage. Get alerted before limits affect services. Consider NAT gateway integration with zonal deployments; Take into account limitations with zone redundant Firewalls and Secure Virtual Hub Networks.

Potential benefits: Improve health and performance monitoring.

Impact: High

For more information, see Azure Monitor supported metrics by resource type - Azure Monitor

ResourceType: microsoft.network/azurefirewalls
Recommendation ID: 8a885111-34c0-4fd6-bb77-dbbb844ad7e5

Monitor health for virtual hubs

Configure monitoring and alerts for virtual hubs. Create alert rule to ensure prompt response to changes in BGP status and data processed by virtual hubs.

Potential benefits: Detect and mitigate issues to avoid disruptions.

Impact: Medium

For more information, see Monitor Azure Virtual WAN

ResourceType: microsoft.network/virtualhubs
Recommendation ID: 8abe4b22-d8ad-4bff-babe-38b9267e46b7

Migrate from Basic to Standard Virtual WAN

Basic tier isn't recommended for critical workloads. Standard tier provides important features including Inter-hub and VNet-to-VNet transiting through the virtual hub, ExpressRoute, VPN and Point-to-Site Gateways, ability to deploy Azure Firewalls and NVAs.

Potential benefits: Full Mesh communication and resiliency

Impact: High

For more information, see Upgrade Virtual WAN - Basic SKU type to Standard - Azure Virtual WAN

ResourceType: microsoft.network/virtualhubs
Recommendation ID: 37652095-cbe3-4132-9c62-526eeb6f4d75

In Azure ExpressRoute Direct, the Admin State specifies the administrative status of the layer 1 link as Enabled or Disabled. The Admin State is the same as turning the physical port on or off. Billing begins when Admin State for either link is set to Enabled.

Potential benefits: Ensure optimal connectivity

Impact: High

For more information, see Configure Azure ExpressRoute Direct

ResourceType: microsoft.network/expressrouteports
Recommendation ID: 88ecf03e-51dc-4aa4-9a4d-2ee48c407f56

Automation

Azure AI Search Storage is 80% full. Add partition to increase capacity.

Azure AI Search storage is 80% full. Add a new partition to increase capacity. If the maximum number of allowed partitions is reached, upgrade the service tier to a higher level.

Potential benefits: Increase the total storage capacity.

Impact: Medium

For more information, see Estimate capacity for query and index workloads - Azure AI Search

ResourceType: microsoft.search/searchservices
Recommendation ID: 20c2eb91-7c3b-4744-8bd3-44820f563ce1

Azure Arc-enabled Kubernetes

Enable container monitoring for Azure Kubernetes Service (AKS) clusters

The Azure Kubernetes Service (AKS) cluster doesn't have container monitoring enabled. Enable monitoring to collect logs and Prometheus metrics in Azure Monitor for better visibility about pod health, performance, and cluster issues.

Potential benefits: Improve visibility and performance insights

Impact: Medium

For more information, see Kubernetes monitoring in Azure Monitor - Azure Monitor

ResourceType: microsoft.kubernetes/connectedclusters
Recommendation ID: bfa9dd65-27ca-4d93-8634-a909b1132277

Azure Arc-enabled servers

Restore connectivity for Arc-enabled servers disconnected for more than 30 days

Azure Arc didn't receive a heartbeat from your machine for more than 30 days. Restore connectivity to maintain management access and ensure your managed identity certificate stays current.

Potential benefits: Restore connectivity early to avoid service disruption.

Impact: Medium

For more information, see Resolve Azure Advisor recommendations for Azure Arc-enabled servers - Azure Arc

ResourceType: microsoft.hybridcompute/machines
Recommendation ID: 18700d61-0b5a-4807-86a1-b7d669475335

Azure Cache for Redis

Migrate to the Enterprise tier of Azure Cache for Redis to access more powerful features

The Azure Cache for Redis instance is using more than six shards, geo-replication, zone-redundancy, or persistence. Migrate to the Enterprise tier cache to improve availability, performance, and access more powerful features like active geo-replication.

Potential benefits: Improve performance, availability, and additional features

Impact: High

For more information, see Azure Cache for Redis Enterprise GA

ResourceType: microsoft.cache/redis
Recommendation ID: f160c11d-9aab-4d41-979f-d119dec02392

Enable Persistence

Redis persistence allows you to persist data stored in Redis. You can also take snapshots and back up the data. If there's a hardware failure, the persisted data is automatically loaded in your cache instance. Data loss is possible if a failure occurs where Cache nodes are down.

Potential benefits: Avoid data loss due to hardware failure or Cache node failure

Impact: Medium

For more information, see Configure data persistence - Premium Azure Cache for Redis - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: e387838a-4fbc-47d5-9a3d-9d1aaa218345

Check to see if Soft Delete is enabled

Check to see if your storage account has soft delete enabled before using the data persistence feature. Using data persistence with soft delete causes very high storage costs. For more information, see Check to see if soft delete is enabled on my storage account

Potential benefits: Avoid high storage costs due to soft delete

Impact: Medium

For more information, see Configure data persistence - Premium Azure Cache for Redis - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: 77204a4e-03ed-4db5-b059-3c3a26145b43

Injecting a cache into a virtual network (VNet) imposes complex requirements on your network configuration. It's difficult to configure the network accurately and avoid affecting cache functionality. It's easy to break the cache accidentally while making configuration changes for other network resources. This is a common source of incidents affecting customer applications

Potential benefits: Avoid affecting cache functionality.

Impact: Medium

For more information, see Migrate from VNet injection caches to Private Link caches - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: dc33091b-a748-4418-b4b0-d3d97466efe4

Migrate to Azure Managed Redis

Azure Cache for Redis will be retired on September 30, 2028. New cache creation will be blocked in phases - starting April 1, 2026 for new customers and starting October 1, 2026 for existing customers. Proactively migrate workloads to Azure Managed Redis to avoid service disruption.

Potential benefits: AMR offers low-latency, cost-effective data storage

Impact: High

For more information, see Frequently asked questions (FAQ) on the retirement of Azure Cache for Redis - Azure Cache for Redis

ResourceType: microsoft.cache/redis
Recommendation ID: 2bb28cf0-969d-43a3-baf8-51328ac497fc

Azure Container Apps

The API version you use for Microsoft.App is deprecated, please use latest API version

The API version you use for Microsoft.App is deprecated, please use latest API version

Potential benefits: More stable API experience

Impact: Low

For more information, see Azure Resource Manager template reference for Microsoft.App - Bicep, ARM template & Terraform AzAPI reference

ResourceType: microsoft.app/containerapps
Recommendation ID: A0C6DF20-B77A-4215-A877-A8EE03CEB156

Enable Java Stack to unleash the power of Java

Enable the Java Stack configuration to enhance the performance, diagnostics, and manageability of Java applications on Azure Container Apps. Benefit from features like automatic memory fitting, JVM metrics, diagnostics, various deployment options, and native compatibility with Spring applications.

Potential benefits: Built-in Java support for better performance and management

Impact: Medium

For more information, see How to turn on Java features in Azure Container Apps

ResourceType: microsoft.app/containerapps
Recommendation ID: 135f09ad-9dbb-433d-8854-da272e05f435

Azure Cosmos DB

Migrate Azure Cosmos DB attachments to Azure Blob Storage

We noticed that your Azure Cosmos collection is using the legacy attachments feature. We recommend migrating attachments to Azure Blob Storage to improve the resiliency and scalability of your blob data.

Potential benefits: Improve attachment blob resiliency and scalability

Impact: Medium

For more information, see Attachments - Azure Cosmos DB for NoSQL

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 061dcd4a-2090-4ec0-b4e0-ec9eaae5cf80

Enable partition merge to configure an optimal database partition layout

Your account has collections that could benefit from enabling partition merge. Minimizing the number of partitions will reduce rate limiting and resolve storage fragmentation problems. Containers are likely to benefit from this if the RU/s per physical partition is < 3000 RUs and storage is < 20 GB.

Potential benefits: Improve performance and lower the chance of rate-limiting

Impact: High

For more information, see Merge partitions (preview) - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: bf161e78-ce57-4198-82e8-a34522045518

Enable near real-time analytics or reporting on your Azure Cosmos DB data

Mirroring Azure Cosmos DB in Microsoft Fabric is now available in preview for NoSQL API. If you are considering enabling near real-time analytics or reporting on your Azure Cosmos DB data, we recommend that you try mirroring to assess overall fit for your organization.

Potential benefits: Better analytical performance

Impact: Low

For more information, see Microsoft Fabric Mirrored Databases From Azure Cosmos DB (Preview) - Microsoft Fabric

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 54537590-fff7-4680-bdf8-5e37b5cf0c12

Monitor Azure Cosmos DB data by using resource-specific diagnostic settings.

Save costs by switching to resource-specific diagnostic settings for Azure Cosmos DB to get more granular control over the logs and metrics that are collected for your resources.

Potential benefits: Improve monitoring and troubleshooting of Azure Cosmos DB resources.

Impact: Medium

For more information, see Monitor data using diagnostic settings - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: a850ac78-dcea-485d-9c86-17a5f2cf56c4

Upgrade the Azure Cosmos DB account to TLS 1.2 or later

Azure Cosmos database users must use secure connections using Transport Layer Security (TLS) 1.2 or later to provide optimal reliability, security, and performance.

Potential benefits: Enhanced security and reliability for data transmissions.

Impact: High

For more information, see Self-Serve Minimum TLS Version Enforcement - Azure Cosmos DB

ResourceType: microsoft.documentdb/databaseaccounts
Recommendation ID: 5c48d9ec-397c-4f11-a342-929a1208c375

Azure Data Explorer

Reduce the cache in the cache policy

Based on usage over the past month, update the cache policy to reduce the hot cache for the table. The number of instances in the cluster is determined using CPU and ingestion load, rather than the amount of data in the hot cache, and varies based on your usage. Given the current usage, simply changing the cache isn't sufficient to reduce the number of instances. The platform recommends other optimizations like reducing CPU load, changing the SKU, and enabling autoscale to efficiently scale in.

Potential benefits: Cache reduction

Impact: Medium

For more information, see Caching policy (hot and cold cache) - Kusto

ResourceType: microsoft.kusto/clusters
Recommendation ID: 9a3ea211-a282-4ab6-a63b-81024975b796

Azure Database for MySQL

Enable storage autogrow for MySQL Flexible Server

Storage auto-growth prevents a server from running out of storage and becoming read-only.

Potential benefits: Prevent servers from going read-only due to low storage

Impact: High

For more information, see Service Tiers - Azure Database for MySQL

ResourceType: microsoft.dbformysql/flexibleservers
Recommendation ID: 43b6411e-c197-4e3d-9295-af1b84e552cf

Azure Dedicated HSM

Update Cloud HSM SDK Version

Update to Microsoft Azure Cloud HSM SDK version 1.0.0.0 for bug fixes and improvements.

Potential benefits: New features and bug fixes.

Impact: Medium

For more information, see GitHub - microsoft/MicrosoftAzureCloudHSM: Azure Cloud HSM SDK (Private Preview)

ResourceType: microsoft.hardwaresecuritymodules/cloudhsmclusters
Recommendation ID: 5def6158-6b43-44af-9744-681ce65b0248

Azure IoT Hub

IoT Hub Fallback Route Disabled

We have detected that the Fallback Route on your IoT Hub has been disabled. When the Fallback Route is disabled messages will stop flowing to the default endpoint. If you are no longer able to ingest telemetry downstream consider re-enabling the Fallback Route.

Potential benefits: Downstream can consume messages

Impact: Low

For more information, see Understand Azure IoT Hub message routing - Azure IoT Hub

ResourceType: microsoft.devices/iothubs
Recommendation ID: 31e5d980-53b5-4475-855e-b6d71b70c2af

Azure Kubernetes Service (AKS)

Use the Standard Load Balancer

Your cluster is currently using a basic load balancer. This will be retired on September 30, 2025 and will not be supported. Moving to Standard Load Balancer will help you achieve high performance and low latency management of network traffic both within and across regions and availability zones.

Potential benefits: Provides high performance for traffic across regions and AZs

Impact: Medium

For more information, see Azure Load Balancer SKUs

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 0b341a36-99c1-41be-b9fb-71efd8029d31

Deprecated Kubernetes APIs are found. Avoid using deprecated API.

The cluster has been detected using deprecated Kubernetes APIs. Using these APIs can cause operations failures such as cluster upgrade, resulting in performance issues. Please follow the Kubernetes deprecated API migration guide to remove these APIs.

Potential benefits: Best practice for consistent performance

Impact: High

For more information, see Deprecated API Migration Guide

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 37a054b6-21dc-4f5c-bdfe-360c0827205f

Use the latest generation VM series such as Ddv5 series

Use latest generation of Azure VMs such as Ddv5 series for better performance and higher availability during host maintenance events. These VM series run the latest generation of hardware in our data centers to help optimize your cluster performance.

Potential benefits: Ensure high performance and lower impact of maintenance events by using the latest generation of Azure hardware

Impact: Low

For more information, see Dpsv5 size series - Azure Virtual Machines

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: deb97441-d830-49f6-b9a5-9d04306abde9

Use Uptime SLA

The cluster uses the Free tier and has more than 10 nodes. The Kubernetes Control Plane on the Free tier comes with limited resources and isn't intended for production use or any cluster with 10 or more nodes. To avoid performance issues, upgrade to the Standard tier.

Potential benefits: High Availability for cluster

Impact: High

For more information, see Azure Kubernetes Service (AKS) Free, Standard, and Premium Pricing Tiers - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: e32c5e70-515f-45aa-90e7-94fb4fdb1b6c

Configure the Cluster Autoscaler

The cluster autoscaler isn't configured in the cluster. The cluster can't automatically adapt to changing load conditions unless it is scaling another way.

Potential benefits: Optimized scaling for cost and performance

Impact: Low

For more information, see Use the cluster autoscaler in Azure Kubernetes Service (AKS) - Azure Kubernetes Service

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: c2f34a5d-2742-4c3d-9247-e0a8b85c3e51

Use Ephemeral OS disk

This cluster is not using ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades

Potential benefits: Faster scaling, upgrades & I/O

Impact: Low

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 79dd48e7-cd34-4f35-a8be-a7d483353c1c

Enable container monitoring for Azure Kubernetes Service (AKS) clusters

The Azure Kubernetes Service (AKS) cluster doesn't have container monitoring enabled. Enable monitoring to collect logs and Prometheus metrics in Azure Monitor for better visibility about pod health, performance, and cluster issues.

Potential benefits: Improve visibility and performance insights

Impact: Medium

For more information, see Kubernetes monitoring in Azure Monitor - Azure Monitor

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: d1e9f4a0-926e-4480-a4e4-3ea94877370c

Simplify multi-cluster management with Azure Kubernetes Fleet Manager

Use Azure Kubernetes Fleet Manager to simplify management of Kubernetes clusters in any Azure region or subscription.

Potential benefits: Simplified multi-cluster management

Impact: Medium

For more information, see Azure Kubernetes Fleet Manager

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: cc62fec4-24e5-4fc4-bf99-2b83d0702549

Use Fleet Manager auto-upgrade profiles to replace cluster auto-upgrades

Use Azure Kubernetes Fleet Manager auto-upgrade profiles to safely update multiple member clusters in a defined order.

Potential benefits: Safely automate the update of multiple clusters

Impact: Medium

For more information, see Automate Upgrades of Kubernetes and Node Images Across Multiple Clusters using Azure Kubernetes Fleet Manager

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 89e238d9-56e5-4f05-bd9a-295ebd55711d

Outdated Azure OS SKUs found for Azure Linux (Mariner)

Found outdated Azure Linux (Mariner) OS SKUs. The CBL-Mariner SKU isn't supported. The Mariner SKU is equivalent to AzureLinux, but it's advisable to switch to AzureLinux SKU for future updates and support, as AzureLinux is the generally available version.

Potential benefits: Avoid using deprecated Azure Linux OS SKU

Impact: Medium

For more information, see Troubleshoot common issues for Azure Linux Container Host for AKS - Azure

ResourceType: microsoft.containerservice/managedclusters
Recommendation ID: 478c34be-baee-415c-b0a0-b2210f1bf400

Azure Managed Workspace for Grafana

Update Azure Managed Grafana SDK Version

We have identified that an older SDK version has been used to manage or access your Grafana workspace. To get access to all the latest functionality, it is recommended that you switch to use the latest SDK version.

Potential benefits: Latest Azure Managed Grafana SDK contains latest fixes and feature capabilities.

Impact: Medium

For more information, see What is Azure Managed Grafana?

ResourceType: microsoft.dashboard/grafana
Recommendation ID: c324c9de-e88a-4074-9727-c775a0b169b2

Azure Monitor

Azure NetApp Files

Configure standard networking for the Azure NetApp Files volume

Convert the basic volume to standard with no downtime. The setting allows higher IP limits and standard virtual network features, such as network security groups and routes defined by user on delegated subnets.

Potential benefits: Improve network routing.

Impact: Medium

For more information, see Configure network features for an Azure NetApp Files volume

ResourceType: microsoft.netapp/netappaccounts
Recommendation ID: d35fd191-4fa0-4949-8517-50750bd9672e

Backup Vault Migration

All backups in the volume need to be migrated to Backup Vault. This recommendation automatically disappears 24 hours after all volumes in your subscription are migrated.

Potential benefits: Helps in managing Backups better

Impact: Medium

For more information, see Manage backup policies for Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts
Recommendation ID: f1a7425d-69fa-463e-a2b0-f1d37cb995cf

Avoid mounting issue by specifying NFSv4.1 mount options

To avoid any issues with clients mounting NFSv4.2 and to comply with supportability, ensure the NFSv4.1 version is specified in mount options or the client’s NFS client configuration is set to cap the NFS version at NFSv4.1.

Potential benefits: Avoid Mounting Issues

Impact: Medium

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 464a7366-ddae-4d74-9187-386bfc45e4f5

Configure the network topology and the domain controllers

Configure the network topology and the domain controller to match the requirements of Azure NetApp Files. The platform detected that the domain controller configured in the Azure NetApp Files Active Directory Connector isn't available and results in application disruption.

Potential benefits: Normalized access to volume.

Impact: Medium

For more information, see Understand guidelines for Active Directory Domain Services site design and planning

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: db4ccef4-d6aa-40a8-8d3c-b42ffc20a9a0

Avoid volume availability issues with Azure NetApp Files

Avoid volume availability issues by specifying your preference for the volume. Contact your Account Representative with your desired volume's state.

Potential benefits: Sustained Volume Availability

Impact: High

For more information, see Service levels for Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 95c1a2fb-ee2f-40bf-b3b4-ee8fc3fd94dd

Azure NetApp Files SDK Upgrade Recommendation

Upgrade to the latest Azure NetApp Files SDK version to begin using new capabilities and improvements.

Potential benefits: Compatibility with latest API

Impact: Medium

For more information, see What's new in Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 36851155-3579-47fc-afc6-8334fe9eb26a

Azure NetApp Files end of support for RC4 defaults to AES256 encryption

Azure NetApp Files supports only AES encryption for Active Directory authentication. This support applies to SMB, dual-protocol, and NFSv4.1 Kerberos scenarios that use an Active Directory connection. RC4 encryption isn't supported. AES-256 and AES-128 are supported, with AES-256 recommended.

Potential benefits: Improved encryption

Impact: High

For more information, see Understand AES in Azure NetApp Files

ResourceType: microsoft.netapp/netappaccounts/capacitypools/volumes
Recommendation ID: 5a81adcd-918b-43c2-a9d0-f1fd9f94e1ba

Azure Orbital Ground Station

Deprecated Microsoft Planetary Computer ARM API version detected

Deprecated Microsoft Planetary Computer ARM API preview version detected. Using this version may lead to operation failures. Upgrade to the latest API version 2026-04-15 to ensure reliability and support.

Potential benefits: Avoid potential failures and support issues

Impact: High

For more information, see GeoCatalogs - REST API (Azure Planetary Computer)

ResourceType: microsoft.orbital/geocatalogs
Recommendation ID: cfdd653f-53d8-498d-8310-16da6d1b95b1

Deprecated Microsoft Planetary Computer API version detected.

Deprecated Microsoft Planetary Computer API preview version detected. Using this version may lead to operation failures. Upgrade to the latest API version 2026-04-15 to ensure reliability and support.

Potential benefits: Avoid potential failures and support issues

Impact: High

For more information, see Data Plane

ResourceType: microsoft.orbital/geocatalogs
Recommendation ID: b7e3affb-e367-4b6b-ada0-ad40197a9ad3

Azure Site Recovery

Switch to Azure Monitor based alerts for backup

Switch to Azure Monitor based alerts for backup to leverage various benefits, such as - standardized, at-scale alert management experiences offered by Azure, ability to route alerts to different notification channels of choice, and greater flexibility in alert configuration.

Potential benefits: Richer alert management capabilities

Impact: Medium

For more information, see Backup Classic Alerts using Azure Backup - Azure Backup

ResourceType: microsoft.recoveryservices/vaults
Recommendation ID: 06578866-1877-41e6-9d22-3ea5122e8048

Azure Spring Apps

Azure Virtual Desktop

Azure VMware Solution

New HCX version is available for upgrade

Your HCX version is not latest. New HCX version is available for upgrade. Updating a VMware HCX system installs the latest features, problem fixes, and security patches.

Potential benefits: Get latest features, problem fixes, and security patches

Impact: High

For more information, see TechDocs

ResourceType: microsoft.avs/privateclouds
Recommendation ID: 78785b91-c41b-4d86-9a8f-37705c13c2a6

Resolve Azure VMware Solution host blockers to enable successful host maintenance

Review affected hosts and apply the recommended actions to support successful maintenance operations and help keep your environment up to date. No cost involved, but Private Cloud goes out of SLA.

Potential benefits: Reduce maintenance failures, delays, and operational risk.

Impact: High

For more information, see Private Cloud Maintenance - Azure VMware Solution.

ResourceType: microsoft.avs/privateclouds
Recommendation ID: 67fa3f81-5b79-4cf5-bb60-d437c3950375

Batch

Recreate your pool with a new image

Your pool is using an image with an imminent expiration date. Please recreate the pool with a new image to avoid potential interruptions. A list of newer images is available via the ListSupportedImages API.

Potential benefits: Avoid potential interruptions

Impact: High

For more information, see Choose VM sizes and images for pools - Azure Batch

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: a37462ed-d4d7-4c42-bf88-f16a60e2f8b6

Upgrade to the latest API version to ensure your Batch account remains operational.

In the past 14 days, you have invoked a Batch management or service API version that is scheduled for deprecation. Upgrade to the latest API version to ensure your Batch account remains operational.

Potential benefits: Improved functionality and stability

Impact: High

For more information, see Azure Batch API Life Cycle and Deprecation

ResourceType: microsoft.batch/batchaccounts
Recommendation ID: bbc3f0f1-85b7-4bcb-b474-0e02571eb5fa

Content Delivery Network

Migrate Azure CDN Standard from Microsoft (Classic) to Azure Front Door Standard/Premium tier

Azure CDN Standard from Microsoft (classic) is scheduled for retirement on 30 September 2027. We encourage you to use the zero downtime migration tool to transition to Front Door Standard and Premium SKUs. These options offer not only feature parity but also additional features and enhanced security

Potential benefits: Avoid potential disruptions and leverage new capabilities

Impact: Medium

For more information, see About Azure CDN from Microsoft (classic) to Azure Front Door migration

ResourceType: microsoft.cdn/profiles
Recommendation ID: 062d41f2-0dfa-48e0-a9b8-fb40fa5b001f

Event Hubs

Avoid using explicit key versions for customer-managed keys in Event Hubs namespace

Avoid using explicit key versions for Key Vault used for customer-managed keys in Event Hubs namespaces to enable seamless key rotation, reduce operational overhead, and prevent outages caused by expired or deleted key versions.

Potential benefits: Enables seamless key rotation and reduces outages

Impact: High

For more information, see Configure your own key for encrypting Azure Event Hubs data at rest - Azure Event Hubs

ResourceType: microsoft.eventhub/namespaces
Recommendation ID: 927abfcb-1a85-4411-bc49-7c8a2d9fb098

HDInsight

Upgrade your HDInsight cluster images

Your HDInsight cluster runs an older image, so it misses the latest open-source or other security updates, and Azure updates. Upgrade to the latest HDInsight image to keep features current. New images release every 90 days.

Potential benefits: Get the latest fixes and features.

Impact: High

For more information, see Before you start with Azure HDInsight.

ResourceType: microsoft.hdinsight/clusters
Recommendation ID: 97355d8e-59ae-43ff-9214-d4acf728467a

Key Vault

Create a backup of HSM

Create a periodic HSM backup to prevent data loss and have ability to recover the HSM in case of a disaster.

Potential benefits: Improve data loss prevention

Impact: Medium

For more information, see Best practices for securing Azure Key Vault Managed HSM

ResourceType: microsoft.keyvault/managedhsms
Recommendation ID: 12278831-341f-4933-85e6-40560e4a3405

MICROSOFT.APICENTER

Enable API specification static analysis

Enable linting and analysis of API definitions in your API center to detect and report violations of rules in your organization's API style guide. Rules can enforce API syntax, style, best practices, or company-specific guidelines.

Potential benefits: Improve consistency and compliance of API definitions.

Impact: Medium

For more information, see Perform API linting and analysis - Azure API Center

ResourceType: microsoft.apicenter/services
Recommendation ID: b64191e1-69b1-4977-be74-284a0b1ff535

MICROSOFT.KUBERNETESRUNTIME

Service Bus

Avoid using explicit key versions for customer-managed keys in Service Bus namespace

Avoid using explicit key versions for Key Vault used for customer-managed keys in Service Bus namespaces to enable seamless key rotation, reduce operational overhead, and prevent outages caused by expired or deleted key versions.

Potential benefits: Enables seamless key rotation and reduces outages

Impact: High

For more information, see Configure your own key for encrypting Azure Service Bus data at rest - Azure Service Bus

ResourceType: microsoft.servicebus/namespaces
Recommendation ID: 8849acb8-a958-41f3-af98-dab43f85bf3c

Service Fabric

Enable Standard SKU for Service Fabric Managed Clusters

Basic SKU clusters are intended to be used for testing and pre-production environments with support for minimal configuration change. A Standard SKU cluster allows users to configure the cluster to specifically meet their needs.

Potential benefits: Only Standard SKU is recommended for Production work loads

Impact: Low

For more information, see Service Fabric managed clusters FAQ

ResourceType: microsoft.servicefabric/managedclusters
Recommendation ID: 70825f31-3f42-4070-ae1c-757da5872db3

SQL Server on Azure Virtual Machines

Install SQL best practices assessment on your SQL VM

SQL best practices assessment provides a mechanism to evaluate the configuration of your Azure SQL VM for best practices like indexes, deprecated features, trace flag usage, statistics, etc. Assessment results are uploaded to your Log Analytics workspace using Azure Monitoring Agent (AMA).

Potential benefits: Check your server config for best practices and increased excellence

Impact: Medium

For more information, see SQL best practices assessment - SQL Server on Azure VMs

ResourceType: microsoft.sqlvirtualmachine/sqlvirtualmachines
Recommendation ID: 9e0a4a67-45b6-408b-b766-6c4822fca2ec

Storage

Update Azure File Sync agent to latest version

Update the Azure File Sync agent to ensure security and access to newest features.

Potential benefits: Performance improvements and security patches

Impact: High

For more information, see Release Notes for Azure File Sync

ResourceType: microsoft.storagesync/storagesyncservices
Recommendation ID: fa28a694-3881-4aae-9a77-86ff2f6105aa

Subscriptions

Subscription with more than 10 VNets should be managed using AVNM

Subscription with more than 10 VNets should be managed using AVNM. Azure Virtual Network Manager is a management service that enables you to group, configure, deploy, and manage virtual networks globally across subscriptions.

Potential benefits: Operational excellence will be increased and more reliable.

Impact: Medium

For more information, see Azure Virtual Network Manager documentation

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: a58fd47f-d7b9-49dc-b763-c511d8774639

Upgrade to latest version of carbon optimization API

Upgrade the carbon optimization API version to 2025-04-01 for updated features and access to a more scalable API. The newer version improves performance and efficiency while managing carbon optimization tasks.

Potential benefits: Access to new features and a more scalable API.

Impact: Low

For more information, see Azure Carbon Optimization REST APIs (Preview)

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: f52ed1b8-9d60-469c-b1d8-b671043fe264

Create an Azure Service Health alert

Create Azure Service Health alerts to stay informed about service issues, planned maintenance, security advisories, and health advisories. Personalize alerts to notify you about disruptions or potential impacts to your selected Azure regions and services.

Potential benefits: Get alerts on service, security, and health issues.

Impact: High

For more information, see Create Service Health alerts for Azure service notifications in Azure portal - Azure Service Health

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: 242639fd-cd73-4be2-8f55-70478db8d1a5

Retirement notice: migrate from Azure Blueprints by January 31, 2027

Take the required steps before the phased retirement date, and complete them by January 31, 2027, to maintain service continuity. Migrate to Azure deployment stacks for resource grouping, lifecycle management, and deny assignment enforcement.

Potential benefits: Migration helps you transition your blueprint artifacts.

Impact: Medium

For more information, see Azure Blueprints retirement - Azure Blueprints

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: 5de787df-6f37-4425-bf23-820b2126517b

Upgrade Microsoft Discovery resources to latest and stable API version

Your Microsoft Discovery resources currently use a preview API version (2025-07-01-preview or 2026-02-01-preview). Preview APIs are retiring soon and might cause operational failures. Upgrade to the latest API version (2026-06-01) to ensure long-term reliability and support.

Potential benefits: Improved reliability and support with the stable API version.

Impact: High

For more information, see Microsoft Discovery Overview

ResourceType: microsoft.subscriptions/subscriptions
Recommendation ID: fc34f295-bb2a-4d01-82ef-0479295da942

Virtual Machines

In-Place Upgrade to Ubuntu Pro with zero downtime for Extended Security

Given Ubuntu 18.04 LTS is out of standard support, customers are required to upgrade to Ubuntu Pro enable Extended Security Maintenance until 2028. Ubuntu Pro is a premium image delivering the most comprehensive open source security while expanding the package coverage to over 23,000 packages.

Potential benefits: Ubuntu Pro enables Extended Security Maintenance until 2028.

Impact: High

For more information, see In-place upgrade to Ubuntu Pro Linux images on Azure - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 4b25fc0f-b045-423b-a85a-241978696e36

Enable Trusted Launch foundational excellence, and modern security for Existing Generation 2 VM(s)

Trusted Launch (TL) offers a modern and operational technologies for Azure virtual machines, using Secure Boot, virtual TPM, and guest attestation. This Generation 2 VM(s) have an opportunity to upgrade to Trusted Launch. Ensure this VM(s) has both an image and VM size that it is TL compatible.

Potential benefits: Boost Gen2 VM security by protecting against rootkits

Impact: High

For more information, see Trusted Launch for Azure VMs - Azure Virtual Machines

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: de7ddac0-29e6-4bff-a812-519d18184982

Add explicit outbound method to disable default outbound for Virtual Machine Scale Sets

Use an explicit connectivity method such as NAT gateway or a Public IP. After March 31, 2026, new virtual networks will default to creation of private subnets, which are intentionally designed to block default outbound access connectivity.

Potential benefits: Secure and explicit outbound access for new subnets

Impact: Medium

For more information, see Default Outbound Access in Azure - Azure Virtual Network

ResourceType: microsoft.compute/virtualmachinescalesets/virtualmachines/networkinterfaces
Recommendation ID: acc30c87-0979-4a35-b4c4-918869897844

Enable VM Insights for virtual machines

Your virtual machines don’t have VM Insights enabled. Turn it on to collect performance and dependency data for better troubleshooting, right-sizing, and health monitoring in Azure Monitor.

Potential benefits: Gain performance and dependency visibility

Impact: Medium

For more information, see Enable VM Insights - Azure Monitor

ResourceType: microsoft.compute/virtualmachines
Recommendation ID: 2881ca3a-070d-40fb-9471-83783ff487c0

Workloads

Set the parameter net.ipv4.tcp_keepalive_time to '300' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_keepalive_time = 300. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: aafa012d-9696-4f5b-8f72-ffa083d7040d

Set the parameter net.ipv4.tcp_retries2 to '15' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_retries2 = 15. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see NFS file system hangs. New mount attempts hang also.

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 797ce8ea-e16e-4b87-84da-fe3f3e872875

Set the parameter net.ipv4.tcp_keepalive_intvl to '75' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_keepalive_intvl = 75. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see Cluster SAP ASCS/SCS instance on WSFC using shared disk in Azure

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: c7af38cf-0f55-4843-9b53-66d929a621ae

See the parameter net.ipv4.tcp_keepalive_probes to '9' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_keepalive_probes = 9. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see Cluster SAP ASCS/SCS instance on WSFC using shared disk in Azure

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 2fc002b9-ad07-40f0-8418-a6f3ef928499

Set the parameter net.ipv4.tcp_tw_recycle to '0' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_tw_recycle = 0. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see NFS file system hangs. New mount attempts hang also.

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 9e273e91-2876-4999-a7cf-7281bf7be031

Set the parameter net.ipv4.tcp_tw_reuse to '0' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_tw_reuse = 0. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see NFS file system hangs. New mount attempts hang also.

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 528d066a-8652-479e-8eec-92d41174210f

Set the parameter net.ipv4.tcp_retries1 to '3' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_retries1 = 3. This is recommended for all Application VM OS in SAP workloads in order to enable faster reconnection after an ASCS failover

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover

Impact: Medium

For more information, see NFS file system hangs. New mount attempts hang also.

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 1a778001-f50a-4e08-a03d-ed2e40f4cc15

Ensure the Operating system in App VM is supported in combination with DB type in your SAP workload

Operating system in the VMs in your SAP workload need to be supported for the DB type selected. Please see SAP note 1928533 for the correct OS-DB combinations for the ASCS, Database and Application VMs. This will help ensure better performance and support for your SAP systems

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: 15ab1e61-048c-47e0-9e10-fa55762efd49

Disable fstrim in SLES OS to avoid XFS metadata corruption in SAP workloads

fstrim scans the filesystem and sends 'UNMAP' commands for each unused block it finds; useful in thin-provisioned system if the system is over-provisioned. Running SAP HANA on an over-provisioned storage array is not recommended. Active fstrim can cause XFS metadata corruption See SAP note: 2205917

Potential benefits: Ensure high reliability of file system in SAP workloads

Impact: High

For more information, see Disabling fstrim - under which conditions?

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: cbb610fd-5caf-445e-943b-8175c77f1118

Ensure Accelerated Networking is enabled on all NICs for improved performance of SAP workloads

Network latency between App VMs and DB VMs for SAP workloads is required to be 0.7ms or less. If accelerated networking is not enabled, network latency can increase beyond the threshold of 0.7ms

Potential benefits: Low network latency and improved performance in SAP workload

Impact: High

For more information, see SAP workload planning and deployment checklist

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: fad6ef33-8ee0-4b11-b6b9-27c927a6d06d

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/applicationinstances
Recommendation ID: a0609b82-7756-11ec-8827-7c50798c1d82

Ensure the Operating system in ASCS VM is supported in combination with DB type in your SAP workload

Operating system in the VMs in your SAP workload need to be supported for the DB type selected. Please see SAP note 1928533 for the correct OS-DB combinations for the ASCS, Database and Application VMs. This will help ensure better performance and support for your SAP systems

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: b07e6fcd-1741-477a-b8f0-0bf90c1aef10

Disable fstrim in SLES OS to avoid XFS metadata corruption in SAP workloads

fstrim scans the filesystem and sends 'UNMAP' commands for each unused block it finds; useful in thin-provisioned system if the system is over-provisioned. Running SAP HANA on an over-provisioned storage array is not recommended. Active fstrim can cause XFS metadata corruption See SAP note: 2205917

Potential benefits: Ensure high reliability of file system in SAP workloads

Impact: High

For more information, see Disabling fstrim - under which conditions?

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 4c3cfb18-c43f-42e5-8814-552b86bac6ff

Ensure Accelerated Networking is enabled on all NICs for improved performance of SAP workloads

Network latency between App VMs and DB VMs for SAP workloads is required to be 0.7ms or less. If accelerated networking is not enabled, network latency can increase beyond the threshold of 0.7ms

Potential benefits: Low network latency and improved performance in SAP workload

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 7f921999-e9e3-4193-8b77-10382beb4dc9

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/centralinstances
Recommendation ID: 2435ce38-ad73-4d5e-ab40-8e508f915796

Adjust Linux kernel semaphore settings for better performance and reliability of SAP

Linux kernel parameters have to be adjusted to meet the requirements of SAP software. Semaphore settings should be as per IBM note

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see Kernel parameter requirements (Linux)

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 78a6427a-8307-4077-9503-50258fc03798

Adjust VM swappiness linux kernel parameter for better reliability of SAP with DB2 database

Adjust VM swapiness kernel parameter for better performance and reliability of SAP with DB2 database

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see Kernel parameter requirements (Linux)

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 0fa90566-e286-44d4-9dad-9c0cad0cf8ee

Adjust VM overcommit memory linux kernel parameter for better reliability of SAP with DB2 database

Adjust VM overcommit memory linux kernel parameter for better performance and reliability of SAP with DB2 database

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see Kernel parameter requirements (Linux)

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 7fa5b5cb-1839-4d0f-9ac6-b6e45959c3a6

Adjust randomize VA space linux kernel parameter for better security of SAP on DB2 database

Adjust randomize VA space linux kernel parameter for better security of SAP on DB2 database

Potential benefits: Improved security for SAP workloads

Impact: Medium

For more information, see Minimum suggested kernel-parameter values on Linux

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: f632b889-88b5-4bf6-adb0-c1c65bd4ba55

Adjust Linux kernel semaphore settings for better performance and reliability of SAP

Linux kernel parameters have to be adjusted to meet the requirements of SAP software. Semaphore settings should be as per SAP Note 2936683

Potential benefits: Reliability of SAP on Oracle Linux

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 13a8f39c-7d65-4008-8be2-3e8520f0ac2b

Ensure the HANA DB VM type supports the HANA scenario in your SAP workload

Correct VM type needs to be selected for the specific HANA Scenario. The HANA scenarios can be 'OLAP', 'OLTP', 'OLAP: Scaleout' and 'OLTP: Scaleout'. Please see SAP note 1928533 for the correct VM type for your SAP workload. This will help ensure better performance and support for your SAP systems

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: cd3d9525-7315-42af-a005-a61aea23d20c

Ensure the Operating system in DB VM is supported for the DB type in your SAP workload

Operating system in the VMs in your SAP workload need to be supported for the DB type selected. Please see SAP note 1928533 for the correct OS-DB combinations for the ASCS, Database and Application VMs. This will help ensure better performance and support for your SAP systems

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 083322ac-d997-414e-a6bd-f01187204ab6

Disable fstrim in SLES OS to avoid XFS metadata corruption in SAP workloads

fstrim scans the filesystem and sends 'UNMAP' commands for each unused block it finds; useful in thin-provisioned system if the system is over-provisioned. Running SAP HANA on an over-provisioned storage array is not recommended. Active fstrim can cause XFS metadata corruption See SAP note: 2205917

Potential benefits: Ensure high reliability of file system in SAP workloads

Impact: High

For more information, see Disabling fstrim - under which conditions?

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: c61597cf-c7b2-4f9c-bbd0-49fb4762278c

For better performance and support, ensure HANA data filesystem type is supported for HANA DB

For different volumes of SAP HANA, where asynchronous I/O is used, SAP only supports filesystems validated as part of a SAP HANA appliance certification. Using an unsupported filesystem may lead to various operational issues, e.g. hanging recovery and indexserver crashes. See SAP note 2972496.

Potential benefits: Better performance and support for HANA DB in SAP workloads

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 63d8c4d5-b717-44d9-88e1-ca8082e12a1c

For better performance and support, ensure HANA log filesystem type is supported for HANA DB

For different volumes of SAP HANA, where asynchronous I/O is used, SAP only supports filesystems validated as part of a SAP HANA appliance certification. Using an unsupported filesystem may lead to various operational issues, e.g. hanging recovery and indexserver crashes. See SAP note 2972496.

Potential benefits: Better performance and support for HANA DB in SAP workloads

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 70cec929-4e06-4334-ab73-15c48fb4dc6f

For better performance and support, ensure HANA shared filesystem type is supported for HANA DB

For different volumes of SAP HANA, where asynchronous I/O is used, SAP only supports filesystems validated as part of a SAP HANA appliance certification. Using an unsupported filesystem may lead to various operational issues, e.g. hanging recovery and indexserver crashes. See SAP note 2972496.

Potential benefits: Better performance and support for HANA DB in SAP workloads

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: f8fece56-6392-4ee9-b9c1-9bafd056037f

Optimize network configuration for improved internal HANA communication in SAP workloads

Ensure that as many client ports are available as possible for HANA internal communication. You also need to ensure that you explicitly exclude the ports used by processes and applications which bind to specific ports by adjusting parameter net.ipv4.ip_local_reserved_ports with a range 9000-64999

Potential benefits: Improved internal HANA communication

Impact: Low

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: b081afb7-0106-4b69-8bc6-9f9ea1e57728

To avoid performance regressions, swap space on HANA systems should be 2GB in SAP workloads

Configure a small swap space, 2 GB for SLES/RHEL to avoid performance regressions at times of high memory utilization in OS. It is usually better if activities terminate with out of memory errors. This makes sure that the overall system is still usable and only certain requests are terminated

Potential benefits: Avoid performance regressions at time of high utilisation

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: 416eefce-4efb-4219-8876-c11f51e81365

Ensure Accelerated Networking is enabled on all NICs for improved performance of SAP workloads

Network latency between App VMs and DB VMs for SAP workloads is required to be 0.7ms or less. If accelerated networking is not enabled, network latency can increase beyond the threshold of 0.7ms

Potential benefits: Low network latency and improved performance in SAP workload

Impact: High

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: a742dd2f-a022-45a2-8948-6741b460c461

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

VM not certified! For better performance and support, ensure that VM is Certified for SAP on Azure

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

ResourceType: microsoft.workloads/sapvirtualinstances/databaseinstances
Recommendation ID: a07aa063-45a8-4538-9bd5-41f4a8abff4b

Set the net.ipv4.tcp_retries2 parameter to 15 on your SAP application virtual machine

On your application virtual machine (VM) operating system (OS), edit /etc/sysctl.conf and add net.ipv4.tcp_retries2 = 15. Apply this setting to all application VM OS instances in your SAP workload to reconnect faster after an SAP Central Services (ASCS) failover.

Potential benefits: Optimize application VMs to reconnect faster after failover.

Impact: Medium

For more information, see NFS file system hangs. New mount attempts hang also.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 120fda4b-ad0b-4a39-bfe2-5bf5c90ee128

Ensure TCP time-wait reuse is set to 0 on SAP workload Application VMs

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_tw_reuse = 0. Set this value for all Application VM OS in SAP workloads to enable faster reconnection after an ASCS failover.

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover.

Impact: Medium

For more information, see Cluster SAP ASCS/SCS instance on WSFC using shared disk in Azure.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 18bdc0e6-aaaf-43ef-84a3-d820cf801580

Disable fstrim in SLES OS to avoid XFS metadata corruption in SAP workloads

Running SAP HANA on over-provisioned storage isn't recommended. Active fstrim can cause XFS metadata corruption. Disable fstrim in SLES to avoid filesystem issues and ensure reliability of SAP workloads. See SAP note 2205917 for details.

Potential benefits: Ensure high reliability of the file system in SAP workloads.

Impact: High

For more information, see Disabling fstrim - under which conditions?

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 1c0de4ee-f89a-473b-a057-b90f0e4127a1

Ensure SELinux is set to Permissive mode for SAP with DB2 or Oracle on Linux

Run SELinux in permissive mode, which means it logs policy violations but doesn't enforce them. This setting prevents several components of the SAP server system from breaking.

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see SAP Note 2936683

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 2b1d5151-0f65-433d-84e0-783b18589139

To avoid performance regressions, swap space on HANA systems should be 2 GB in SAP workloads

Configure a small swap space of 2 GB for SLES and RHEL to avoid performance regressions during high memory utilization. This configuration ensures the overall system remains usable and only certain requests are terminated without memory errors.

Potential benefits: Avoid performance regressions during high memory utilization.

Impact: High

For more information, see SAP Note 1999997

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 3127f497-59f1-4c4b-a31f-1ec81f1969fc

Ensure VM swappiness kernel parameter is configured for SAP with DB2

Adjust VM swappiness kernel parameter for better performance and reliability of SAP with DB2 database.

Potential benefits: Improved performance and support for SAP DB2 workloads

Impact: Medium

For more information, see Kernel parameter requirements (Linux)

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 3a856750-59f5-49a3-9392-5f1aafad9af8

Tag your Electronic Health Record (EHR) workload resources

Tag your Electronic Health Record (EHR) workload resources with contextual metadata to enable advanced filtering, reporting, governance, and cost management.

Potential benefits: Use tags to improve governance and reporting.

Impact: Medium

For more information, see Use tags to organize your Azure resources and management hierarchy - Azure Resource Manager.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 4b9e9b3d-4d73-44f4-ad67-b87857c00eca

Enable boot diagnostics from Azure portal, PowerShell, or CLI

Boot diagnostics is a debugging feature for Azure virtual machines (VM) that helps diagnose VM boot failures. By using boot diagnostics, you can see the state of your VM as it boots up through serial log information and screenshots.

Potential benefits: Diagnose VM boot failures.

Impact: Medium

For more information, see Azure boot diagnostics - Azure Virtual Machines.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 569e45d1-cfd0-4e6f-ab7f-15e876cd139c

Configure the number of unanswered TCP keepalive probes based on your workload needs

Configure the number of unanswered TCP keepalive probes (keepalive checks) to detect unresponsive connections quickly. Use your workload needs to choose the recommended value.

Potential benefits: Optimize application servers to reconnect after failover.

Impact: Medium

For more information, see Maintenance and updates - Azure Virtual Machines.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 5db444f4-42ba-4123-985a-5fa143e47112

Ensure your Linux kernel semaphore settings support SAP workloads that use DB2 or Oracle databases

Adjust your Linux kernel settings to meet the requirements for SAP software that uses DB2 or Oracle databases.

Potential benefits: Improve performance and reliability of SAP workloads.

Impact: Medium

For more information, see IBM Db2 Azure Virtual Machines DBMS deployment for SAP workload

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: 8ad2ccab-5b5e-4f1f-a9ef-254ff39febba

Deploy each electronic health record (EHR) component to an independent resource group

Deploy each electronic health record (EHR) workload component to an independent resource group in each environment and region to improve governance and isolation.

Potential benefits: Improve governance and operational isolation.

Impact: Low

For more information, see Use the Azure portal and Azure Resource Manager to Manage Resource Groups - Azure Resource Manager

ResourceType: microsoft.workloads/virtualinstances
Recommendation ID: 9ceb1fd6-faae-40a4-80f3-f1693153439e

Ensure the VM SKU is certified for the HANA scenario in your workload

Select a VM SKU that is certified for your specific SAP HANA scenario (OLAP, OLTP, OLAP scale-out, or OLTP scale-out). For supported VM SKUs, see SAP Note 1928533. Using a certified SKU helps improve performance and ensures SAP supportability.

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see SAP Note 1928533

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: a7f3c891-2e54-4d86-b9c1-5f8e2a4d6b73

Ensure TCP retries1 is set to 3 on SAP workload Application VMs

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_retries1 = 3. Set this value for all Application VM OS in SAP workloads to enable faster reconnection after an ASCS failover.

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover.

Impact: Medium

For more information, see Cluster SAP ASCS/SCS instance on WSFC using shared disk in Azure.

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: b4234934-34ab-4a36-91ca-7c9f5cf3dc85

Ensure all NICs of workload VMs are attached to the same virtual network

Connect all network interfaces (NICs) associated with virtual machines in your workload to the same virtual network (VNet). This setup ensures consistent network connectivity, simplified management, and optimal performance for your workloads.

Potential benefits: Improved network reliability and management.

Impact: High

For more information, see What is Azure Virtual Network?

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: c9d4e7a2-8f15-4b63-a1c6-3e5d9b2f7a84

Ensure the VM operating system is supported as per your workload recommendation

The operating system on your workload VMs must be compatible with your workload requirements. Using supported OS configurations ensures optimal performance, reliability, and vendor support.

Potential benefits: Improved performance and support for SAP workloads

Impact: Medium

For more information, see SAP Note 1928533

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: d4c7e8a2-5f19-4b63-9e81-2a6d3c5f7b90

Use SAP-certified VM SKUs for SAP workloads

SAP workloads require VM SKUs certified by SAP for optimal performance, reliability, and full support from SAP and Microsoft.

Potential benefits: Improved performance and supportability for SAP workloads.

Impact: Medium

For more information, see SAP Note 1928533

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: d4e5f6a7-b8c9-4d1e-a2f3-c5b6d7e8f9a0

Ensure TCP keepalive interval is set to 75 seconds in the Application VMs of SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_keepalive_intvl = 75. Set this value for all Application VM OS in SAP workloads to enable faster reconnection after an ASCS failover.

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover.

Impact: Medium

For more information, see SAP Note 1410736

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: dffd35a2-c840-4e39-bb45-8f6859f361b9

Set the parameter net.ipv4.tcp_keepalive_time to '300' in the Application VM OS in SAP workloads

In the Application VM OS, edit the /etc/sysctl.conf file and add net.ipv4.tcp_keepalive_time = 300. Add this setting to all Application VM OS in SAP workloads to enable faster reconnection after an ASCS failover.

Potential benefits: Optimize SAP App VMs to reconnect faster after ASCS failover.

Impact: Medium

For more information, see SAP Note 1410736

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: f4a7c2d8-9e15-4b63-8a91-2c5d7e3f6b18

Ensure randomize VA space kernel parameter is configured for SAP with DB2

Adjust the randomize VA space kernel parameter for better security of SAP with DB2 database.

Potential benefits: Improved security for SAP workloads.

Impact: Medium

For more information, see Linux: suggested minimum values

ResourceType: microsoft.workloads/virtualinstances/components
Recommendation ID: fd3f5c0e-4ced-4c43-a16b-24b35c612eae

Next steps

Learn more about Operational Excellence - Microsoft Azure Well Architected Framework