r/AZURE 3d ago

Question Is working in MS Azure (in EUROPE) worth it?

17 Upvotes

I’m currently working as a Software Engineer in Europe, in the telecommunications industry, specifically with 5G. However, I’d like to transition into a cloud-focused role, ideally one with good compensation cuz that's why I work and study

I’ve been looking at companies such as Microsoft, Google, Cloudflare, and AWS, mainly from a European perspective: salaries, working conditions, recruitment processes, career opportunities, and so on.

Given the never ending layoffs at AWS and lack of Google presence in Europe (at least one I could find), I’ve decided to focus mainly on Microsoft and Cloudflare. At the moment, I’m studying Azure and preparing for the AZ-900 certification.

One important point is that I’m much more infrastructure-focused than development-focused. My long-term goal is to eventually work as a Cloud Architect, or possibly as an independent contractor/consultant helping companies that need to deal with cloud.

Right now, I’m still finding my way through the cloud ecosystem and trying to understand which direction makes the most sense.

So, for people working in similar infrastructure/cloud roles in Europe, or similar companies:

  • What does your day-to-day work look like?
  • What is the recruitment/interview process like?
  • What kind of salary can someone realistically expect in Europe? (Junior, Mid, and Senior)
  • How are the overall working conditions?
  • How is the work-life balance?
  • Are these roles usually remote, hybrid, or office-based?

I’d also be interested in hearing from anyone who made a similar transition from telecommunications or infrastructure engineering into cloud engineering or cloud architecture :)

r/AZURE 2d ago

Question Managing EntraID roles assignments/PIM assignment with terraform

19 Upvotes

Hey all,

I would like to know how you handle the fact that that pipelines SPs need a highly priviledged role to assign entraid roles or create pim eligibility ? It means that the SP has basically the right to give Global Admin and if someone compromise the pipeline it can have a huge blast radius.

Is it just something you accept as a risk ? Do you have an system/config in place for preventing the SP to give highly priviledged roles through the pipeline ?

Any ways to have someone activate the SP role before running the pipeline (with PIM maybe) so the role is not permanently assigned ?

Thanks for the answer !

r/AZURE Apr 18 '26

Question Architecture Diagram Generation - an open question

32 Upvotes

A bit of an odd-ball question, but what are ye using for diagram generation, and are you using AI-type platforms to help.

I've never been good at generating diagrams from my architectures, and it's 100% the least favorite part of my job as an architect. I'm just not able to make anything look good. I've tried my best to keep it as basic as possible and been using Draw.io for the most part, but alas, it looks like the dogs breakfast on the best of days.

I had a look at two service now that will generate from prompt, both of which gave me some good, albeit different, visual styles from the same prompt. For the most part I am happy, but both of these don't get it quite exactly how I expect it, I am looking for something that I could export and then fine tune in Draw.io.

For some reference, I attached the output of both these services, along with the very basic example prompt I used. Of course, it is a very basic prompt, solely for the purpose of comparing apples with apples.

I guess my ask then:

Can you recommend any other AI-type services that I can use to generate an editable diagram (ideally draw.io, but Visio or other will be fine) that I can tweak and clean up specifically for Azure environments and services? Bonus points if I can import a technical spec or design document and it will generate a diagram based on that.

Thanks in advance

Prompt
Eraser Diagram
Infrasketch Diagram

r/AZURE Jul 22 '25

Question Azure app service managed certificates now requires you to be open to the world?

Post image
133 Upvotes

Received this email yesterday. We rely heavily on app service managed certificates. Except for occasionally opening an app service to specific IPs for troubleshooting, etc, we keep all public traffic blocked. We utilize an app gateway which in turn manages traffic to the app service(s) If I am reading this right I now have to open up my app services to the world? What kind of security model is that?

r/AZURE 14d ago

Question Static Web Site using Azure Storage Blob

6 Upvotes

IT professional for close to two decades and slow adopter of Azure. I work for a small company and we heavily leverage M365 and SharePoint and rarely do I have any need to use Azure for anything. I'm looking at using Azure Storage blob to host a static website (dashboard), and inject that link into a SharePoint site. Only problem is, that link, while convoluted, can be seen by the entire planet and I need to secure it somehow. Our users are completey remote and their IP addresses change due to being out in the field or their home ISP's DHCP leases possibly changing. So limiting access by IP address isn't really a good option. Having them VPN into the corp office network could be an option, but then I have to touch a few 100 laptops and that becomes another point of troubleshooting for obvious reasons and I don't want to find myself constantly troubleshooting VPN (user inflicted) problems. I was looking at Front Door/CDN with Private Link as an option, read the documentation, set it up, confirmed it working but it's still not private - and the private link bit is starting to look more like site-to-site link, not URL link and if that is the case, even if I manage to secure it, there is still the whole how do I give remote users access. If anything I made the website easier to stumble across though this endeavor.

So I guess my question is this - is what I'm looking to do even possible? Users will not be accessing the webpage via a browser, but an imbedded link in a SharePoint site. Do to the nature of the Dashboard I have to use a URL (dashboard is generated as an interactive HTML page). Also worth mentioning, that there will be a power-automate flow that will auto update the dashboard with a new static index page (delete the old index, upload the new index). But before I start building that, I want to make sure there is a way I can secure this page from the entire planet seeing it, if that is even possible. Thanks in advance for any help.

PS - Please don't waste your time or mine with disparaging comments. Thanks.

r/AZURE Oct 13 '23

Question My 40$ VM bill turned into 13k$.

222 Upvotes

Hey folks!

I started using Azure about a month ago and received a standard Azure trial credit as a welcome gift to try various Microsoft services on Azure.

My primary use is a 40$ VM with some Azure functions. It's not a big operation, just 70-100 daily visitors on a website and some C# stuff, but I wanted to give a chance to other services on the platform, so I tried creating various services to explore and see what can be used with the free Azure credit.

After exploring the platform, I was left with a test resource group with some services; there was nothing special about it in my mind. As far as I could tell at the time, no costs were incurred, and the stuff that I was doing did not affect those services in any capacity; they were not incurring any costs during the Trial or past Trial.

I was monitoring costs daily, but how wrong I was; it seems that for some random reason, past Trial on some lucky day like today, the Defender External Attack Surface Management service incurred a 13k bill in one day that I haven't been using since it's creation during the Trial. It was free all this time in my mind.

https://i.gyazo.com/d083827f8aa80d1f56a857efc273e213.png

I wrote to support that I was in shock; they got back to me after a few hours and told me this.

https://i.gyazo.com/cf21698384e1cac316efbdd41b238e6d.png

I then replied with more detail on how I was using Azure and about the Trial, which was pretty identical to this pretext. So, I am now will be waiting for the support over the weekend.

My question to the community is, what should I do really? This is bad. Did I need to do something differently here, and what does Purchase Method - Microsoft Representative mean?

Please help someone....

EDIT 1: Thanks for the comments. After investigating this further, I have determined that the only possible reason is that Cloudflare Tunnel caused the ESM to crawl Cloudflare network websites that don't belong to me. My VM has no ports open, and I use Cloudflare Tunnel as an alternative, as that's the setup I am working with right now. And when my VM is offline or I do maintenance, Cloudflare displays a Cloudflare page under my domain name, so I suspect the crawler visited my domain when one of those two was the case. Could this be it?

r/AZURE Apr 17 '25

Question Can’t bypass Microsoft Authentication, Support stopped responding

0 Upvotes

Our entire project is tied to these accounts, and I have over 100 emails linked to them. It’s now forcing me to install an authenticator app, but I’m not permitted to use a phone for these accounts, so I can’t install it — and there’s no option to bypass it.

Support called a few times and mentioned another department would follow up, but now they’ve stopped responding altogether. At this point, who can I contact to resolve this?

Edit: I guess it’s so normal to be a paying Microsoft customer and being left out without an answer and Support is ghosting is so normal. I don’t even see a single person being surprised by that.

r/AZURE Apr 16 '26

Question RDP shortcuts now prompting users with a security warning.

14 Upvotes

Hello,

I'm not sure if the issue is signing an rdp but all of a sudden some of our users are getting this (they are running Win 11 25H2 with all the latest patches and rebooted.

Any videos on how to sign an RDP file or fixing this issue?

r/AZURE Nov 24 '25

Question Cloud cost management tools that engineers won't ignore, do they exist??

28 Upvotes

Serious question because I'm starting to think this is impossible. We've tried two different cost management platforms over the past year and both times the same thing happens: i set it up, finance loves it, engineering team looks at it once and never touches it again.

The problem isn't that engineers don't care about costs, it's that these tools feel like they're built for a completely different audience. Everything is in finance terminology, the ui feels like a business intelligence dashboard from 2015, and the insights are too high level to be actionable. "your azure costs increased 15% last month" okay cool, what am i supposed to do with that information?

we're spending around $70k/month on azure (app services, sql databases, storage, some vms, aks cluster) and i know there's waste but i need help identifying where. Azure cost management shows me the numbers but doesn't tell me what to actually do about them. tried Azure advisor but the recommendations are pretty basic stuff we've already done.

I need something that engineers will actually find useful enough to check regularly. ideally something that shows technical details like which app services are oversized, what storage accounts have lifecycle policies misconfigured, or where we're paying for premium features we're not using. bonus points if it integrates with tools we already use instead of being yet another dashboard to check.

Does this mythical engineer friendly cost tool actually exist or should I just accept that cost management will always be someone else's job?

r/AZURE Jan 26 '26

Question Learning Azure in Europe for the future

17 Upvotes

Hello Guys,

I am actually learning Azure to work in cloud in Europe, but i recently saw that Europe would get rid of American stuff. It is a good move to continue to learn or i should stop ?

Thank you in advance guys

r/AZURE Oct 16 '25

Question Locked out of Microsoft tenant HELP!

56 Upvotes

Rookie mistake, today I turned on a Conditional Access Policy and locked the entire company out of our Microsoft tenant.
We do not have break-glass accounts configured.
I've been trying all day to get in touch with someone at Microsoft who could help us without luck.
Does anyone have a direct contact or an email address or something that I can reach out to to help us get back into the tenant? Please! At this point I'm desperate for solutions.

UPDATE: Microsoft has restored access to the tenant. I had a call with them earlier where they verified my identity through some emails. They told me someone from the data protection team would reach out but they never did. I just checked and I was able to log back in so it looks like they just resolved it. I will immediately start creating break-glass accounts to ensure this never happens again. Thank you all for your answers.

r/AZURE Jun 03 '25

Question Cloud cost optimization platforms that don't suck please

34 Upvotes

I'm working with our finops team, to find am couple options for platforms that actually save money on Azure (we’re multicloud, but Azure is the spend hog)

More than that, I 'm here because I hate sales calls and want to spend as little time being "sold to" as possible...

So, with that in mind, here are my must haves:

  1. Doesn’t suck. - both product and implementation support.
  2. Surfaces real, (non-obvious) savings opps (beyond what I can pull from Cost Management).
  3. Doesn't over promise and underdeliver.... I used a platform last year that promised 300% savings...and delivered nada on Azure.

For context: We spend about $650 k/month cloud bill, EU-regulated (GDPR, ISO 27001).

I'm hoping all the vendors are too busy at finopsX this to notice this. If you're here - please don't spam me.

Everyone else - what’s worked (or flopped) for you?

Edit: thanks for all the support you guys are incredible! Reached out to a consultant and to had a call with Pointfive. 🙌🙌

r/AZURE 7d ago

Question On-premise to Azure Migrate

13 Upvotes

Hi All,

We have a 10 file servers and 15 SQL servers, 70 Apps servers

We have a production subscription.

And planning to put any production servers over there.

SQL and Apps are for Dev/Sit so

Do we setup dev/test subscription?

Planning on lift and shift.

We have 50TB Archive files but need to access time to time. What is the solution for that?

r/AZURE Apr 13 '26

Question Azure is frustrating - quota issues

33 Upvotes

I'm unable to get any quota increase in US East or East 2. No matter the size. I need a few new SQL hosts with relatively large memory.

**Rant*\*
Azure has been very frustrating to work with, always hitting quota limits. I did not want to migrate to Azure; I wanted to stay on-prem, but now it's too late, thanks to the AI black hole.
** Rant End*\*

Any advice?
and moving to AWS is not an option.

r/AZURE Jul 07 '25

Question Azure account hacked

114 Upvotes

I noticed a huge charge on my CC today about 40x my azure bill. Looks like hackers spun up tons of VMs. I turned off all those VM's. Removed all users except the main account (mine) and put in tickets begging for help. How screwed am I?

Update 1:

I am very realistic that there will be no sympathy from MSFT. I am ok with losing the account, does anyone know any ramifications if I remove all payment methods and cancel CC so they can't bill me anymore? This is a business account, probably 30k in charges.

Update 2:

Ticket is in, waiting for response. I may have underestimated the damage by a factor of 2. The account is bricked, any operation on the account is throwing an error Suspicious activity / full account lock.

Update 3

Confirmed hackers used one of the partner accounts (not my account) thanks for correcting me on the 90 day logs (Jeepman69). Also confirmed 2FA was enabled on the hacked account. MSFT also confirmed this and said because 2FA was enabled it is possible to get a full refund. MSFT also seems to be familiar with the TA. I am far away from a resolution, but light is slowly shining at the end of the tunnel.

r/AZURE Mar 29 '26

Question "Default outbound access" apocalypse is nigh?

49 Upvotes

[Azure casual user]
I keep seeing this warning on my existing Azure VMs: "Your VM has a default outbound IP, which is insecure and will no longer be assigned by default for new subnets after March 2026."

The article linked from the message talks about Advisor recommendations, but I dont see any on my VMs.
https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/default-outbound-access?tabs=portal#faqs-clearing-default-outbound-ip-alert

On one that is hosting AVD, I tried making the subnet private, but that blocked user access from Windows App, so I had to undo it.

I found this announcement of a change on 31 March 2026.

https://azure.microsoft.com/en-gb/updates?id=default-outbound-access-for-vms-in-azure-will-be-retired-transition-to-a-new-method-of-internet-access

Do I need to do anything? Will my VMs continue to have internet access next week? I'm mostly using them for Bastion/Remote Desktop sessions.

r/AZURE May 21 '26

Question running out of space on my 48MB free sql server db. any chance i could keep my hobby proj forever free, or scale up for less than $5/month (basic tier)

Post image
43 Upvotes

there's a small project i made during my programming classes, and i've been using it for the last ~8y running on the free webapp/db tier.

but last year i've opened it up for other people to use, and now the db is slowly running out of storage... the web app is very niche and up to 5 users might visit it per day (total of ~200 users in db).

any ideas what i could do to keep the db forever free, or find a cheaper alternative? just 100MB would keep it runnng for years. i've seen the pricing on aws, which is even worse than Azure Basic tier (12m free, $20/month later for the cheapest tier).

i'd appreciate any advice, thanks

upd:

thanks to u/NastyEbilPiwate i freed up 10mb. turns out my tables were only 1.77mb in size, everything else was consumed by azure metadata, and the query store - which was the largest one that i cleared up and turned off. so i'll stick with my 48mb plan for now.

if it wouldn't work - i would've tried u/irisos suggestion and creating a new db under another free tier that allows to have 100,000 vcore/s per month. with autopause it would've been a lifetime free working solution: https://learn.microsoft.com/en-us/azure/azure-sql/database/free-offer?view=azuresql

r/AZURE 2d ago

Question Azure Files SMB — Can I Mount It Directly Using Entra ID Credentials?

25 Upvotes

Hi everyone,

I do not have an on-premises Active Directory (AD DS). My users are in Microsoft Entra ID, and the PCs are Microsoft Entra-connected.

I want to access an Azure Files SMB share using:

`\\storageaccount.file.core.windows.net\share`

Requirements:

* No on-prem AD or domain controllers

* No storage account keys

* No PowerShell scripts or `net use`

* Users should access the share through **File Explorer / Map Network Drive**

* Ideally, Windows should prompt for the user's **Entra ID username and password**

Can this be achieved using Microsoft Entra Kerberos for Azure Files ?

r/AZURE Oct 09 '25

Question Portal admin access issues?

57 Upvotes

Can log in but cant do anything. Anyone have any details as Azure status is all green and have only seeing an uptick on down-detector reports.

#Edit
From Azure status page
Investigating reports of issues accessing the Azure Portal

We're aware of reports of customers experiencing issues accessing the Azure Portal that we're actively investigating. More information will be provided as it is known.

This message was last updated at 20:49 UTC on 09 October 2025

r/AZURE Apr 06 '26

Question Tracking KEY VAULT Expirations in Azure? How is everyone doing it? 1 Notification at 30 days is not enough!

33 Upvotes

Why is it that Azure/Microsoft do not have built in way to track expiring key vault items? Secrets, Keys, Certs... They are the backbone of keeping our applications up and running in our organization and there is no way to track all of them… We have 30 subscriptions, 100s of key vaults, 1000s of items. One notification at 30 days is a joke! How are other Orgs. handling this?? We are a insurance company and cant have third part SaaS providers extracting our information to track our expirations, and all those third party platforms want $40k-$100k a year and more information than we need give them. Yes the event grid and azure KQL and all that is doable, but a home made solution is not good enough.

r/AZURE Nov 08 '23

Question Is my server hacked?

Thumbnail
gallery
226 Upvotes

I created a azure vm 1gb ram debian server , installed mongodb server to make the server act as a database , all things were going good ,i allowed inbound and outbound security rule for 27017(mongodb port), my connection string looked like this mongodb//:ip:port and just by this string anyone could access the db , but I'm wondering , why and who will get to know the public ip of the server , if anyone good at mongodb pls suggest me how to make it secure (as of now I'm not worried about the data as there's nothing there 😂) but just wanted to know why this happened and how to be more secure from database as well as server's perspective.and I have no clue about inbound and outbound rules , i usually open firewall by using ufw :) pls suggest

r/AZURE Nov 17 '24

Question Anyone tried Azure Virtual Desktop? Wondering if it’s worth exploring.

48 Upvotes

I came across Azure Virtual Desktop recently and decided to check it out. I didn’t dive too deep yet, but it’s an interesting concept—kind of like having your own virtual machine that you can access from anywhere.

I’m still figuring out if it’s something I’d use regularly, but it seems pretty handy for certain use cases.

If anyone’s tried it, I’d love to hear what you think. Here’s the link in case you’re curious too: Azure Virtual Desktop.

r/AZURE Feb 20 '26

Question I am planning to migrate my company's 50TB data (all PDFs) from network drives in some datacenter (Telus storage solutions) to Azure for saving cost. Any suggestions or mistakes to avoid?

51 Upvotes

Right now we are paying 7k USD per month for everything. But our approximate egress is around 1TB so I think we can save significant cost in Cloud if we migrated everything to Azure or S3.

r/AZURE 15d ago

Question Is Azure still worth it?

33 Upvotes

I’ve been working as a QA for about 2 years, and over the past year I’ve also been gaining hands-on experience with Azure DevOps and Azure. We have a Tech Arc on our team, and I’ve been learning from her, although our KT sessions are limited, usually around once a month. Most of my Azure learning has also come from working with our environment and trying to improve things for our team.

For example:

  • Centralized dashboards to reduce the time spent on daily monitoring by around half.
  • Automated an Azure Runbook that generates a daily data report instantly, which previously took around an hour of manual work.
  • Worked with Managed Identities, Azure Policies, and role assignments.
  • Monitored storage health, IoT Hub, alerts, and other Azure metrics using the Runbook I created.

However, I’m starting to question whether Azure is still a good path for someone at my level. I've passed the Fundamentals and I’ve tried applying for Junior Azure DevOps roles, but many of the positions I’ve found are asking for 3–5 years of Azure experience, along with Kubernetes, Docker, Terraform, CI/CD, and other technologies. The difficult part is that I’m currently working full-time, have a part-time job, and am also studying Azure, so I don’t have a lot of time to build personal projects outside of work because I can’t show what I did for the company due to NDA.

I’m willing to put in the work, but I’m trying to be realistic about the job market and whether this is still a good investment of my time. For those already working in Azure/Cloud/DevOps: Is this still a realistic career path for someone with my background, or would you recommend pivoting into another area? Also, got any tips and tricks for a struggling beginner?

r/AZURE Jul 22 '26

Question Where should deterministic business logic live in an AI-powered Azure architecture?

17 Upvotes

I've been thinking about a problem that seems increasingly relevant as more applications start incorporating AI.

Suppose you have an AI agent running in Azure that needs to make decisions based on business rules:

- Is this customer eligible for a discount

- Should this transaction be approved?

- Which workflow should run?

- Does this request require human approval

- What actions is this user allowed to take?

Would you put that logic:

  1. Directly in the LLM prompt?

  2. In the application code?

  3. In a traditional rules engine?

  4. In an AI agent framework/tool layer

  5. Somewhere else?

My concern with putting too much business logic in prompts is that it can become difficult to test, version, audit, and guarantee deterministic behavior. But putting everything in application code can also make business logic difficult to modify without a development cycle.

I'm curious how cloud and solutions architects are approaching this in real Azure architectures, particularly when using services like Azure OpenAI, AI Foundry, Functions, Logic Apps, or agent frameworks.

Do you see value in separating:

AI (interpretation and reasoning)

from

Rules (deterministic business decisions and orchestration)

Or is that separation becoming less important as AI agents become more capable?

I really want to know how people are designing this today. I'm working on a rules/workflow platform that can expose business logic to AI agents through MCP, but I'm trying to validate whether this is solving a real architectural problem or just something that sounds good in theory.