<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Azure Local on Mike Hacker</title>
        <link>https://blog.mikehacker.net/categories/azure-local/</link>
        <description>Recent content in Azure Local on Mike Hacker</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en-us</language>
        <lastBuildDate>Fri, 03 Apr 2026 12:10:04 +0000</lastBuildDate><atom:link href="https://blog.mikehacker.net/categories/azure-local/index.xml" rel="self" type="application/rss+xml" /><item>
            <title>Azure Local and Sovereign AI at the Edge: Bringing Secure Cloud Infrastructure to Disconnected Government Environments</title>
            <link>https://blog.mikehacker.net/p/azure-local-and-sovereign-ai-at-the-edge-bringing-secure-cloud-infrastructure-to-disconnected-government-environments/</link>
            <pubDate>Fri, 03 Apr 2026 12:10:04 +0000</pubDate>
            <guid>https://blog.mikehacker.net/p/azure-local-and-sovereign-ai-at-the-edge-bringing-secure-cloud-infrastructure-to-disconnected-government-environments/</guid>
            <description>&lt;img src=&#34;https://blog.mikehacker.net/&#34; alt=&#34;Featured image of post Azure Local and Sovereign AI at the Edge: Bringing Secure Cloud Infrastructure to Disconnected Government Environments&#34; /&gt;&lt;p&gt;Government agencies face a growing tension: the pressure to adopt AI and cloud-native technologies is accelerating, yet the regulatory and security requirements governing public-sector data have never been more demanding. Many agencies operate in environments where continuous cloud connectivity is not feasible, whether due to security classification requirements, data residency mandates, or simply the realities of deploying infrastructure in remote or austere locations.&lt;/p&gt;&#xA;&lt;p&gt;Microsoft is addressing this challenge head-on with &lt;strong&gt;Azure Local&lt;/strong&gt; and its &lt;strong&gt;disconnected operations&lt;/strong&gt; capability, forming the foundation of what Microsoft calls the &lt;strong&gt;Sovereign Private Cloud&lt;/strong&gt;. Together, these technologies enable government organizations to deploy Azure services, run AI workloads, and manage infrastructure in fully disconnected or air-gapped environments, all while maintaining a consistent Azure management experience.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-is-azure-local&#34;&gt;What Is Azure Local?&#xA;&lt;/h2&gt;&lt;p&gt;Azure Local is Microsoft&amp;rsquo;s distributed infrastructure solution that extends Azure capabilities to customer-owned environments. It replaces and evolves the former Azure Stack HCI platform, providing a hyperconverged infrastructure that can run virtual machines, containers, and select Azure PaaS services on hardware you control, in locations you choose.&lt;/p&gt;&#xA;&lt;p&gt;At its core, Azure Local uses &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-arc/overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Arc&lt;/a&gt; as the unifying control plane. This means that whether you are managing a cluster in a government datacenter, a remote field office, or a mobile command post, you get the same Azure portal, Azure CLI, and Azure Resource Manager (ARM) template experience you already know.&lt;/p&gt;&#xA;&lt;p&gt;Key capabilities of Azure Local include:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Local VMs&lt;/strong&gt; for running Windows and Linux workloads with Trusted Launch security&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Kubernetes Service (AKS)&lt;/strong&gt; enabled by Azure Arc for containerized applications&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Virtual Desktop&lt;/strong&gt; for secure remote workspace delivery&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;GPU-accelerated compute&lt;/strong&gt; with support for NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Integration with Microsoft Defender for Cloud&lt;/strong&gt;, Azure Policy, and Azure Monitor&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Validated hardware&lt;/strong&gt; from over a dozen OEM partners including Dell, HPE, and Lenovo&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For more details, see the &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-local/overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Local overview on Microsoft Learn&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;disconnected-operations-cloud-without-the-cloud-connection&#34;&gt;Disconnected Operations: Cloud Without the Cloud Connection&#xA;&lt;/h2&gt;&lt;p&gt;The most significant development for government agencies is &lt;strong&gt;disconnected operations for Azure Local&lt;/strong&gt;. Currently available in preview for pre-qualified customers, disconnected operations allow organizations to deploy and manage Azure Local instances without any connection to the Azure public cloud.&lt;/p&gt;&#xA;&lt;p&gt;Disconnected operations deliver a local instance of the Azure control plane as a virtual appliance, providing:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure portal and CLI experience&lt;/strong&gt; running entirely on-premises&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Resource Manager&lt;/strong&gt; for managing subscriptions, resource groups, and templates&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Role-based access control (RBAC)&lt;/strong&gt; for granular permissions management&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Local VMs&lt;/strong&gt; with flexible sizing, custom images, and high availability&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Kubernetes Service (AKS)&lt;/strong&gt; for containerized AI and application workloads&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Container Registry&lt;/strong&gt; for storing and managing container images locally&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Key Vault&lt;/strong&gt; for secrets management&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Policy&lt;/strong&gt; for governance enforcement on new resources&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Offline updates&lt;/strong&gt; with monthly packages covering the appliance, OS, AKS, and service agents&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;This means a government agency can stand up a fully functional Azure environment in an air-gapped network, deploy AI containers, manage Kubernetes clusters, and enforce security policies, all without a single packet leaving the local network.&lt;/p&gt;&#xA;&lt;p&gt;For the full details, see &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Disconnected operations for Azure Local overview&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sovereign-ai-at-the-edge-with-edge-rag&#34;&gt;Sovereign AI at the Edge with Edge RAG&#xA;&lt;/h2&gt;&lt;p&gt;One of the most compelling workloads for disconnected Azure Local deployments is &lt;strong&gt;Azure Edge RAG (Retrieval Augmented Generation)&lt;/strong&gt;, an Azure Arc-enabled Kubernetes extension that brings generative AI capabilities to on-premises data.&lt;/p&gt;&#xA;&lt;p&gt;Edge RAG is a turnkey solution that packages everything needed to build custom AI chat assistants that derive insights from private, locally stored data. It includes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Generative AI language models&lt;/strong&gt; running locally with support for both CPU and GPU hardware&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;A complete data ingestion and RAG pipeline&lt;/strong&gt; that keeps all data local with Azure RBAC controls&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Prompt engineering and evaluation tools&lt;/strong&gt; for building, testing, and deploying chat solutions&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure-equivalent APIs&lt;/strong&gt; for integration with business applications&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Critically, Edge RAG sends only system metadata to Microsoft. All customer content stays within the on-premises infrastructure, within network boundaries defined by the customer. This is specifically validated for &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-arc/edge-rag/overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;disconnected operations on Azure Local&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For a government agency, this means you could deploy an AI assistant that helps staff search and synthesize sensitive policy documents, incident reports, or case files, all running on local hardware with zero data leaving the building.&lt;/p&gt;&#xA;&lt;h2 id=&#34;scaling-up-multi-rack-and-modular-deployments&#34;&gt;Scaling Up: Multi-Rack and Modular Deployments&#xA;&lt;/h2&gt;&lt;p&gt;Azure Local is no longer limited to small-scale edge deployments. Microsoft has introduced several capabilities that dramatically increase the scale and flexibility of on-premises infrastructure:&lt;/p&gt;&#xA;&lt;h3 id=&#34;multi-rack-deployments&#34;&gt;Multi-Rack Deployments&#xA;&lt;/h3&gt;&lt;p&gt;Now in preview, &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-local/multi-rack/multi-rack-overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;multi-rack deployments&lt;/a&gt; support hundreds of servers across multiple preintegrated racks, each containing compute, SAN storage, and managed networking. This enables large government agencies to build substantial on-premises cloud environments with the same Azure management experience.&lt;/p&gt;&#xA;&lt;h3 id=&#34;rack-aware-clustering&#34;&gt;Rack-Aware Clustering&#xA;&lt;/h3&gt;&lt;p&gt;Rack-aware clustering enables intelligent workload placement across multi-rack environments. Azure Local detects physical rack boundaries and distributes workloads accordingly, improving fault tolerance and minimizing the blast radius of localized hardware failures.&lt;/p&gt;&#xA;&lt;h3 id=&#34;external-san-storage-support&#34;&gt;External SAN Storage Support&#xA;&lt;/h3&gt;&lt;p&gt;Government agencies with existing investments in enterprise storage from Pure Storage, NetApp, Dell, HPE, or Hitachi can now integrate those systems directly with Azure Local clusters, protecting existing investments while modernizing management.&lt;/p&gt;&#xA;&lt;h3 id=&#34;azure-modular-datacenter&#34;&gt;Azure Modular Datacenter&#xA;&lt;/h3&gt;&lt;p&gt;For agencies that need portable, rapidly deployable compute in non-traditional locations, Microsoft also offers the &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure-stack/mdc/mdc-overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Modular Datacenter (MDC)&lt;/a&gt;, a ruggedized, self-contained datacenter unit built on Azure Stack Hub. The MDC is designed for operations in disconnected or contested communications environments, making it suitable for emergency response scenarios, temporary command posts, or locations without traditional datacenter facilities.&lt;/p&gt;&#xA;&lt;p&gt;When combined with Azure Local&amp;rsquo;s disconnected operations capabilities, these modular and scalable deployment options give government agencies a continuum of infrastructure choices, from a single server in a closet to hundreds of servers in portable or permanent facilities.&lt;/p&gt;&#xA;&lt;h2 id=&#34;security-built-in-not-bolted-on&#34;&gt;Security Built In, Not Bolted On&#xA;&lt;/h2&gt;&lt;p&gt;Azure Local is built with a secure-by-default posture that includes over 300 security settings providing a consistent security baseline with drift control. Additional security capabilities include:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Trusted Launch VMs&lt;/strong&gt; with secure boot and vTPM&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Microsoft Defender for Cloud&lt;/strong&gt; integration for threat assessment and security posture improvement&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Network Security Groups (NSGs)&lt;/strong&gt; for precise traffic filtering and isolation (generally available)&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Azure Policy enforcement&lt;/strong&gt; in both connected and disconnected scenarios&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Local identity with Azure Key Vault&lt;/strong&gt; (preview) for deployments that do not require Active Directory&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;why-this-matters-for-government&#34;&gt;Why This Matters for Government&#xA;&lt;/h2&gt;&lt;p&gt;State and local government agencies operate under a unique combination of constraints that make Azure Local with disconnected operations particularly relevant:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Data sovereignty and residency&lt;/strong&gt;: Criminal justice information, protected health information, and personally identifiable citizen data often cannot leave specific jurisdictional boundaries. Disconnected operations ensure data, operations, and control remain entirely within the organization&amp;rsquo;s physical and legal jurisdiction.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;CJIS and regulatory compliance&lt;/strong&gt;: Law enforcement and justice agencies subject to FBI CJIS Security Policy requirements need infrastructure that can demonstrate complete data isolation. An air-gapped Azure Local deployment with RBAC and Azure Policy enforcement provides a strong compliance posture.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Continuity of operations&lt;/strong&gt;: When natural disasters, network outages, or cyber incidents sever cloud connectivity, disconnected Azure Local instances continue operating without interruption. VMs keep running, Kubernetes clusters keep serving applications, and the local portal remains fully functional.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;AI without data exposure&lt;/strong&gt;: Government agencies want to leverage AI for document analysis, case management, constituent services, and decision support, but sending sensitive data to cloud-based AI endpoints may not be permissible. Edge RAG and disconnected AI containers solve this by running everything locally.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Familiar skills, lower risk&lt;/strong&gt;: Azure Local uses the same Azure portal, CLI, ARM templates, and RBAC model that IT teams already use for cloud workloads. This dramatically reduces the learning curve compared to standing up a completely separate on-premises platform.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Azure Government cloud support&lt;/strong&gt;: Azure Local can be deployed with Azure Government cloud as the control plane for connected scenarios, supporting both FedRAMP-compliant and commercially managed workloads.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;Migration from VMware&lt;/strong&gt;: With Azure Migrate from VMware to Azure Local now generally available, agencies currently running VMware can migrate workloads with an agentless, portal-driven experience that keeps data flows local.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h2 id=&#34;getting-started&#34;&gt;Getting Started&#xA;&lt;/h2&gt;&lt;p&gt;For agencies interested in exploring Azure Local with disconnected operations:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Review the documentation&lt;/strong&gt;: Start with the &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-local/overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Local overview&lt;/a&gt; and &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-local/manage/disconnected-operations-overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;disconnected operations overview&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check hardware options&lt;/strong&gt;: Browse the &lt;a class=&#34;link&#34; href=&#34;https://aka.ms/AzureStackHCICatalog&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Local Catalog&lt;/a&gt; for validated hardware from your preferred vendor&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Try it virtually&lt;/strong&gt;: Use &lt;a class=&#34;link&#34; href=&#34;https://jumpstart.azure.com/azure_jumpstart_localbox&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Azure Arc Jumpstart&lt;/a&gt; to spin up a sandbox environment with just an Azure subscription&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Pre-qualify for disconnected operations&lt;/strong&gt;: Submit the &lt;a class=&#34;link&#34; href=&#34;https://aka.ms/az-local-disconnected-operations-prequalify&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;pre-qualification form&lt;/a&gt; or contact your Microsoft account team&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Explore Edge RAG&lt;/strong&gt;: Review the &lt;a class=&#34;link&#34; href=&#34;https://learn.microsoft.com/en-us/azure/azure-arc/edge-rag/overview&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;&#xA;    &gt;Edge RAG overview&lt;/a&gt; to understand on-premises AI capabilities&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Azure Local represents a fundamental shift in how government agencies can consume cloud technology. It is no longer a question of cloud versus on-premises; it is Azure everywhere, managed consistently, secured by default, and deployed on your terms. For agencies navigating the intersection of AI innovation and regulatory compliance, this is the infrastructure platform to watch.&lt;/p&gt;&#xA;</description>
        </item></channel>
</rss>
