VS Code Browser Agent Tools

πŸ”Ή Feature: VS Code Browser Agent Tools πŸ”Ή What It Does: Browser agent tools let GitHub Copilot in VS Code drive the integrated browser autonomously β€” open pages, click buttons, type into fields, take screenshots, run Playwright code, and read console errors. The agent builds your app, opens it in the browser, tests every interaction, discovers bugs, fixes them, and verifies the fix. A complete closed development loop, no human in the test driver’s seat. πŸŒπŸ€– What Is It Giving You: βœ… Full Closed-Loop Dev Cycle: Build β†’ run β†’ test β†’ identify issues β†’ fix β†’ verify, all by the agent. You watch instead of click. βœ… Real Browser Automation: openBrowserPage, navigatePage, clickElement, hoverElement, dragElement, typeInPage, handleDialog, screenshotPage, readPage β€” plus runPlaywrightCode for any custom interaction you can write. βœ… Visual + Console Debugging: Agent inspects rendered pages, reads console errors, and analyzes screenshots β€” catches bugs that unit tests miss. βœ… Isolated Sessions by Default: Pages opened by the agent run in private, in-memory browser sessions β€” no cookies or storage shared with your normal browsing. Sandboxed by design. βœ… Share a Real Page When Needed: β€œShare with Agent” lets you hand the agent a logged-in browser tab … VS Code Browser Agent ToolsRead more

Azure Migrate for VMware β†’ Azure Local

πŸ”Ή Feature: Azure Migrate for VMware β†’ Azure Local β€” Move Off VMware Without Going All-In on Public Cloud πŸ”Ή What It Does: Migrate VMware VMs directly to your on-premises Azure Local instance using the same Azure Migrate hub you’d use for cloud migrations β€” orchestrated entirely from the Azure portal. Source disks and data stay on-prem the whole time (only metadata and replication state touch Azure Storage), no agents on the source VMs, and minimal downtime. The pragmatic exit from Broadcom-era VMware licensing β€” stay on Microsoft-supported hyperconverged infrastructure, keep your data where it is. πŸ”„πŸ–₯️ What Is It Giving You: βœ… Agentless Source Discovery: No agents to install on each VMware VM before migration. Deploy a source appliance to the VMware cluster β€” it discovers everything for you. βœ… Azure Portal as Single Control Plane: Start, run, and track the entire migration from the Azure Migrate project in the portal. One place to see status across hundreds of VMs. βœ… Data Stays Local β€” Truly: VM disks and data flow directly from on-prem VMware to on-prem Azure Local. Azure Storage only holds metadata and replication state. Big for regulated workloads where bulk data exiting the data center is … Azure Migrate for VMware β†’ Azure LocalRead more

GitHub Sandboxes

πŸ”Ή Feature: GitHub Sandboxes πŸ”Ή What It Does: GitHub Sandbox provides fast, cheap, isolated, and resumable cloud microVM environments so Copilot can safely run, test, and iterate on code beyond the developer’s local machine. Available alongside local sandboxes β€” together, they give Copilot a safe place to execute commands, interact with your code and tools, and run agentic workflows without ever touching your host. What Is It Giving You: βœ… MicroVM-Level Isolation in the Cloud: Each Copilot session gets its own ephemeral cloud microVM with hypervisor-grade boundaries. Agentic workflows can install packages, modify files, build containers, and run services β€” host machine and other sessions stay untouched. βœ… Fast & Cheap to Spin Up: Lightweight microVMs start in seconds, so agentic loops aren’t bottlenecked by environment setup. Pay only for what you use. βœ… Resumable Sessions: Pause an agent run, come back later β€” the sandbox picks up where it left off. Long-running or interrupted tasks don’t restart from zero. βœ… Local Sandbox Companion: Standard Copilot seat includes a local sandbox built on Microsoft MXC technology β€” consistent isolation across macOS, Linux, and Windows. Enable with /sandbox enable in any Copilot session. βœ… Built-In Identity, Governance & Policy: Consistent enterprise … GitHub SandboxesRead more

Generative AI for Beginners .NET β€” Free Microsoft Course

πŸ”Ή Feature: Generative AI for Beginners .NET β€” Free Microsoft Course πŸ”Ή What It Does: Five hands-on lessons from Microsoft teaching .NET developers how to actually build Generative AI applications β€” not just read theory. Short videos, fully working C# code samples, GitHub Codespaces-ready setup, and coverage from your first chat completion to multi-agent systems with the Microsoft Agent Framework. Free, MIT-licensed, 2.5k+ stars and counting. What Is It Giving You: βœ… Practical, Not Theoretical: Short 5–10 minute videos, complete runnable .NET code, step-by-step guidance. Live coding over slides. βœ… Multi-Backend Setup: Azure OpenAI / Microsoft Foundry for production-grade samples, OR Ollama for local model hosting on your own hardware. βœ… Microsoft Agent Framework Samples (RC): 25+ samples covering console apps, web chat, multi-agent workflows, and Foundry integration. Plus dedicated Claude (Haiku/Sonnet/Opus) integration samples via Microsoft Foundry β€” including Blazor web chat. web chat. βœ… Zero Friction Setup: One PowerShell script (./setup.ps1) deploys Azure OpenAI + embeddings, configures .NET User Secrets, and you’re coding. Cleanup script included. βœ… Available in 8 Languages: Chinese (Simplified & Traditional), Japanese, Korean, Spanish, German, French, Portuguese β€” plus English. For every .NET dev tired of generic “what is an LLM” posts and ready to … Generative AI for Beginners .NET β€” Free Microsoft CourseRead more

Microsoft Foundry Toolboxes β€” Bundle AI Agent Tools Once, Use Them Everywhere

πŸ”Ή Feature: Microsoft Foundry Toolboxes β€” Bundle AI Agent Tools Once, Use Them Everywhere πŸ”Ή What It Does: Stop wiring every agent to every tool. A Toolbox is a named, reusable bundle of tools β€” defined once in Microsoft Foundry, centrally configured for authentication, and exposed through a single MCP-compatible endpoint any agent runtime can consume. What It Is Giving You: βœ… Bundle Once, Consume Everywhere: Web Search, Code Interpreter, File Search, Azure AI Search, MCP servers, A2A, and OpenAPI β€” all published as a single reusable Toolbox. βœ… One MCP Endpoint Per Toolbox: Agents connect once and dynamically discover all tools. No per-tool wiring, no custom SDKs, no five different auth models. βœ… Centralized Auth: OAuth identity passthrough and Microsoft Entra managed identity configured in Foundry β€” individual agents never handle credentials. βœ… Foundry-Homed, Not Foundry-Bound: Use Toolboxes from Microsoft Agent Framework, LangGraph, Copilot SDK, GitHub Copilot, Claude Code, MCP-enabled IDEs, or your own code. No lock-in. βœ… Versioning Built In: Promote a tested version to β€œdefault,” keep iterating β€” consumers don’t change a line of code when you ship updates. πŸš€ The Layer That Makes Agentic AI Scale Across an Enterprise. 🌐 https://devblogs.microsoft.com/foundry/introducing-toolboxes-in-foundry/

Power Pages β€” The Fastest Way to Build Secure, Scalable External Business Portals on Microsoft’s Cloud

πŸ”Ή Feature: Microsoft Power Pages β€” The Fastest Way to Build Secure, Scalable External Business Portals on Microsoft’s Cloud πŸ”Ή What It Does: Enterprise-grade, low-code SaaS for external-facing portals on Microsoft’s cloud. Customer self-service, partner hubs, supplier onboarding, community portals β€” built in days, not quarters. Direct Dataverse connection, Entra ID for external identities, WAF and DAST built in. Drag-and-drop where you need speed; full pro-code (HTML/CSS/JS/Liquid + Web APIs) when you need power. What Is It Giving You: βœ… Fastest Path to Live: Start from a template (FAQ, scheduling, registration, partner support, community), customize themes, publish in days. AI-driven site creation generates pages, forms, and layouts that fit Power Pages architecture out of the box. βœ… Sit Directly on Operational Data: Native Dataverse connection β€” no middleware, no sync scripts. Customers, partners, and internal apps share the SAME tables. Single source of truth. βœ… Enterprise-Grade Security Built In: Microsoft Entra ID + External Identities, web roles + table permissions, Power Pages Web Application Firewall, built-in DAST (XSS, injection), IP restrictions, DLP rules, maintenance mode. βœ… Native Microsoft Cloud Integration: Power Automate, Power BI, Entra, Azure Functions / Logic Apps / Storage β€” no bespoke PaaS stitching. βœ… Low-Code AND … Power Pages β€” The Fastest Way to Build Secure, Scalable External Business Portals on Microsoft’s CloudRead more

Agent Governance Toolkit (AGT) β€” Govern Your AI Agents

πŸ”Ή Feature: Microsoft Agent Governance Toolkit (AGT) β€” Govern Your AI Agents πŸ”Ή What It Does: Open-source MIT-licensed toolkit for runtime governance of autonomous AI agents. Enforces policy, zero-trust identity, sandboxing, and tamper-evident auditing β€” before any tool call leaves your app. Covers all 10 OWASP Agentic AI risks. πŸ›‘οΈπŸ€– βœ… Govern Any Tool Fast: safe_tool = govern(my_tool, policy=”policy.yaml”) β€” every call is evaluated, logged, and enforced. βœ… Five Modular Layers: Policy engine, zero-trust identity, sandboxing, SRE (SLOs, chaos, kill switch), and tamper-evident audit. Start with policy + audit, add more later. βœ… MCP Security Gateway: Detects tool poisoning, drift, typosquatting, and hidden-instruction attacks in MCP servers. βœ… Shadow AI Discovery: Finds unregistered agents in your environment β€” solves AI sprawl at audit time. βœ… Polyglot SDKs: Python, TypeScript, .NET, Rust, Go β€” with native adapters for Copilot CLI, Claude Code, and popular agent frameworks. For banks, regulators, and any team shipping agents to production: governance isn’t optional. Use the toolkit that already covers the OWASP Agentic Top 10. πŸš€ 🌐 https://github.com/microsoft/agent-governance-toolkit 🌐 Docs: https://microsoft.github.io/agent-governance-toolkit

Microsoft Entra Tenant Governance – Tenant As Code

πŸ”Ή Feature: Microsoft Entra Tenant Governance πŸ”Ή What It Does: Tenant as Code, Drift Detection, Multi-Tenant Admin. What Is It Giving You: βœ… Tenant As Code (Configuration Baselines): Author a JSON baseline that expresses the desired state of tenant resources β€” your “tenant blueprint.” 200+ resource types supported across six services: Entra, Intune, Exchange Online, Teams, Purview, and Defender. Source-control it, peer-review it, version it. βœ… Snapshot a Known-Good Tenant: Take a configuration snapshot of an existing “golden” tenant to jumpstart your baseline authoring. Snapshots also satisfy audit requirements as point-in-time evidence. βœ… Continuous Drift Detection: Configuration monitors run every 6 hours and compare each tenant’s actual state to your JSON baseline. View aggregated drift across all monitors or drill into individual properties that diverged from the desired state. βœ… Multi-Tenant Administration via Governance Relationships: Set up cross-tenant administrative access between your governing tenant and the tenants you need to govern β€” using invitation/request/approval workflows. Least-privilege cross-tenant admin (configuration management included) β€” no more bouncing through guest accounts or shared admin creds. βœ… Streamlined App Injection: Provision and maintain permissions for your custom apps across multiple governed tenants in one workflow. Reusable governance policy templates mean you ask for the … Microsoft Entra Tenant Governance – Tenant As CodeRead more

Create SharePoint Pages With Copilot β€” Just Prompt It

πŸ”Ή Feature: Create SharePoint Pages With Copilot β€” Just Prompt It πŸ”Ή What It Does: Generate a full SharePoint page from a natural-language prompt and your own source documents. What Is It Giving You: βœ… Two Ways to Start: Open prompt for a from-scratch draft (“Announce the new hybrid work policy”), OR pick a template (Newsletter, Event, Status Update, Process) and personalize via prompts. βœ… Up to 5 Source Files Per Page: First file = primary content source. The rest are supporting documents. Rename a section to “Release Plan” and Copilot intelligently pulls from the matching attachment to populate it. βœ… Auto-Suggested Subject & Layout: Copilot suggests the page title from your sources and applies Design Ideas to choose layout, sections, and imagery β€” no manual web-part wiring. βœ… Permission-Aware by Design: Grounded in Microsoft Graph with your existing tenant permissions β€” Copilot only references documents you can already see. Compliance posture stays intact. βœ… Save as Private Draft by Default: Prevents accidental oversharing β€” publish only when you’re ready. βœ… Refine in the Rich Text Editor: Highlight text β†’ “Suggest improvements,” “Add a table summarizing these points,” or change tone (concise / enthusiastic / etc.). Speed up the first … Create SharePoint Pages With Copilot β€” Just Prompt ItRead more

SharePointe Page Template Gallery β€” Centralized, One Place for ALL Templates (GA)

πŸ”Ή Feature: SharePointe Page Template Gallery β€” Centralized, One Place for ALL Templates (GA) πŸ”Ή What It Does: SharePoint finally has one centralized Template Gallery β€” a single hub to browse, preview, and apply every available page template. Custom templates saved on the site, full-page apps, AND 50+ professionally designed Microsoft templates, all in one consistent experience. Now generally available worldwide for commercial customers (including GCC, GCC High, DoD). What Is It Giving You: βœ… One Gallery to Rule Them All: Saved on this site, Full-page apps, and From Microsoft templates β€” all in one unified view. No more digging through menus. βœ… 50+ Professionally Designed OOB Templates: A growing Microsoft library covering HR, status updates, event announcements, team intros, product news β€” stop reinventing for common scenarios. βœ… Custom Templates Front and Center: Your site-specific templates show prominently at the top of the gallery. Brand consistency without the search hunt. βœ… Pages vs News Posts, Separated: Tailored template options for each use case β€” right template, right job, automatically. βœ… Theme-Aware by Default: Templates auto-adapt to match site theme and branding when applied. βœ… Designate a Default Template Per Site: Drive instant design consistency for new content across the … SharePointe Page Template Gallery β€” Centralized, One Place for ALL Templates (GA)Read more

Apps Inside Microsoft 365 Copilot Chat β€” The New, Easier Way (Easier Than Building an MCP Server)

πŸ”Ή Feature: Apps Inside Microsoft 365 Copilot Chat β€” The New, Easier Way (Easier Than Building an MCP Server) πŸ”Ή What It Does: Until now, the route for an app to deeply integrate with Copilot was building an MCP server β€” useful, but a real engineering effort. Now apps can render their own interactive experience directly inside Copilot chat. The seller logs a Dynamics 365 Sales opportunity, the manager approves a Power Apps form, the marketer edits a flyer in Adobe Express β€” all without leaving the conversation. The catalog is small today, but the standard is open and the trajectory is clear. 🧩 What Is It Giving You: βœ… Real Interactive App UI Inside Copilot: This isn’t “Copilot calls an API and pastes a string back.” Agents bring the app’s actual interactive widgets and forms into the chat surface β€” users complete real work in-app without ever switching tabs. βœ… Concrete Workflows On Day One: Schedule meetings in Outlook (GA), log opportunities in Dynamics 365 Sales (public preview), handle cases in Dynamics 365 Customer Service (public preview), and run any line-of-business workflow built on Microsoft Power Apps (public preview). βœ… Curated Partner Apps: Adobe Express, Adobe Acrobat, Base44, Box, … Apps Inside Microsoft 365 Copilot Chat β€” The New, Easier Way (Easier Than Building an MCP Server)Read more

Transfer User Source of Authority (SOA) From On-Prem AD to Microsoft Entra ID

πŸ”Ή Feature: Transfer User Source of Authority (SOA) From On-Prem AD to Microsoft Entra ID πŸ”Ή What It Does: For decades, a synced hybrid user has been READ-ONLY in the cloud β€” every change had to flow through on-prem Active Directory. Microsoft Entra ID now lets you flip the script per user. Transfer that user’s Source of Authority to the cloud, and Entra ID becomes the master: changes happen in the cloud, on-prem AD changes no longer flow back. The cloud-first migration step the hybrid identity world was waiting for. β˜οΈπŸ”„ What Is It Giving You: βœ… Per-User, Granular SoA Transfer: Flip individual users from “AD-mastered” to “cloud-mastered” with a single Microsoft Graph PATCH β€” isCloudManaged=true. No big-bang cutover, no domain controller decommission required. Migrate one user, one team, or one department at a time. βœ… Bidirectional and Reversible: Rolled back just as easily β€” set isCloudManaged=false and Connect Sync takes the object back over on its next cycle. Safety net included. βœ… Sync Engine Stays Aware: Once SoA is in the cloud, the Microsoft Entra connector sets blockOnPremisesSync=true on that object. AD changes for that user are recognized but not flowed (Event ID 6956 logged). No drift, no surprise … Transfer User Source of Authority (SOA) From On-Prem AD to Microsoft Entra IDRead more

Post-Quantum Cryptography (PQC) in Active Directory Certificate Services

πŸ”Ή Feature: Post-Quantum Cryptography (PQC) in Active Directory Certificate Services πŸ”Ή What It Does: Windows Server 2025 AD CS can now issue and manage certificates using NIST-standardized post-quantum algorithms β€” designed to survive attacks from future quantum computers. Your root CA, code signing certs, TLS, and domain auth get a quantum-safe path before hackers with quantum hardware arrive. ⚠️ Why this matters NOW (before quantum is here): πŸ”Έ Harvest now, decrypt later: Attackers are already capturing encrypted traffic today, planning to decrypt it once a sufficiently powerful quantum computer exists. Anything encrypted in 2026 must still protect data in 203X. πŸ”Έ Long-lived trust: Root CAs and code-signing certs issued today need to remain trustworthy for 10–20+ years. Once quantum breaks RSA/ECDSA, every signature made with them is forgeable retroactively. Migration starts before the headlines. What Is It Giving You: βœ… ML-DSA Today (Phase 1): NIST FIPS 204 β€” quantum-safe digital signatures, available now in Windows Server 2025 AD CS with the May 2026 security update. βœ… ML-KEM + Composite Algorithms Next (Phase 2): FIPS 203 key encapsulation and composite certs (classical + PQ) where both signatures must validate β€” attacker must break both algorithms. βœ… Pure or Composite Certificates: Pure … Post-Quantum Cryptography (PQC) in Active Directory Certificate ServicesRead more

Identity Risk Management Agent in Microsoft Entra ID Protection

πŸ”Ή Feature: Identity Risk Management Agent in Microsoft Entra ID Protection πŸ”Ή What It Does: An AI agent backed by Security Copilot that protects your identities automatically β€” but on your terms. It investigates every risky user in your tenant, correlates sign-in logs, risk detections, and audit signals, then generates a clear risk summary and a recommended remediation action for each one. What Is It Giving You: βœ… Autonomous Investigation, Per Risky User: The agent picks up users in “At risk” state, digs into their risky sign-ins and risk detections, and produces a thorough risk summary explaining exactly why this account is suspicious β€” and what to do about it. βœ… Clear, Actionable Recommendations: For each investigated user, the agent suggests the right remediation (reset password, require MFA, block sign-in, confirm safe, etc.) backed by the evidence it found. No more guessing why an alert fired. βœ… Chat With the Agent: Ask follow-up questions about any risky user or summary. The agent answers in natural language so you understand the reasoning before acting. βœ… Agent Memory for Your Org’s Preferences: Give the agent custom instructions (“for finance team users, always recommend X first”) and it remembers them for future runs … Identity Risk Management Agent in Microsoft Entra ID ProtectionRead more

The GitHub Copilot App β€” A Modern Desktop GUI for Agent-Driven Development

πŸ”Ή Feature: The GitHub Copilot App β€” A Modern Desktop GUI for Agent-Driven Development πŸ”Ή What It Does: Love GitHub Copilot CLI but want more than a terminal? The GitHub Copilot app is a cross-platform desktop application built ON TOP of Copilot CLI β€” giving you a modern, interactive UI to direct multiple AI agents across parallel workstreams, work with issues and PRs, and manage the full dev lifecycle in one window. Same engine, far more interactive. No more living entirely in the console. πŸ–₯️ What Is It Giving You: βœ… Built on Copilot CLI β€” Same Power, Visual Shell: The app runs the exact agentic core from GitHub Copilot CLI, wrapped in a real desktop experience. You keep the capability of the CLI and gain a modern interface around it. βœ… Run Multiple Agents in Parallel: Direct several AI agents across parallel workstreams at once. You shift from doing all the work to directing it β€” kick off tasks, monitor progress, and keep multiple threads moving simultaneously. βœ… One Place, Zero Context-Switching: Issues, pull requests, branches, and the full development lifecycle live in a single app β€” no bouncing between terminal, IDE, and a dozen browser tabs. Stay focused … The GitHub Copilot App β€” A Modern Desktop GUI for Agent-Driven DevelopmentRead more

FSLogix Profile Containers for Cloud-Only & External Identities (Azure Virtual Desktop)

πŸ”Ή Feature: FSLogix Profile Containers for Cloud-Only & External Identities (Azure Virtual Desktop) πŸ”Ή What It Does: You can now store FSLogix profile containers on Azure Files using Microsoft Entra Kerberos β€” for cloud-only and external identities. That means full Azure Virtual Desktop with roaming profiles, with zero Active Directory. No domain controller, no AD DS, no Entra Domain Services, and no line-of-sight to a DC from your session hosts. Pure cloud identity, the way AVD should have always worked. β˜οΈπŸ” What Is It Giving You: βœ… Truly AD-Free AVD: Entra ID itself issues the Kerberos tickets needed to access the SMB file share. Session hosts don’t need any network line-of-sight to a domain controller. Perfect for greenfield, cloud-native, or M&A scenarios with no on-prem AD. βœ… Cloud-Only AND External Identities: Previously required hybrid identities synced from on-prem AD. Now, cloud-only Entra ID accounts β€” and external identities β€” are supported (Azure public cloud). Ideal for contractors, B2B guests, and born-in-cloud orgs. βœ… Simplified β€œManage Access” Permissions: With Entra Kerberos enabled, the Azure file share exposes a Manage access tab to assign permissions directly to Entra users, groups, or SIDs β€” no more icacls gymnastics over a DC connection. βœ… … FSLogix Profile Containers for Cloud-Only & External Identities (Azure Virtual Desktop)Read more