Gallery Module for Azure PowerShell: https://www.powershellgallery.com/packages/Az/16.4.0
To install Az from the PowerShell Gallery, run the following command:
Install-Module -Name Az -Repository PSGallery -Force
To update from an older version of Az, run the following command:
Update-Module -Name Az
Docker images
- mcr.microsoft.com/azure-powershell:latest
- mcr.microsoft.com/azure-powershell:alpine-3.23
- mcr.microsoft.com/azure-powershell:16.4.0-alpine-3.23
- mcr.microsoft.com/azure-powershell:debian-12
- mcr.microsoft.com/azure-powershell:16.4.0-debian-12
- mcr.microsoft.com/azure-powershell:azurelinux-3.0
- mcr.microsoft.com/azure-powershell:16.4.0-azurelinux-3.0
- mcr.microsoft.com/azure-powershell:azurelinux-3.0-arm64
- mcr.microsoft.com/azure-powershell:16.4.0-azurelinux-3.0-arm64
- mcr.microsoft.com/azure-powershell:ubuntu-24.04
- mcr.microsoft.com/azure-powershell:16.4.0-ubuntu-24.04
Release Notes
Az.Compute 11.10.0
- Added '-ScheduleProfileStart' and '-MinimumCommitmentDayCount' parameters to 'New-AzCapacityReservation' to create Future Capacity Reservations, and surfaced the read-only 'ScheduleProfile' (including 'ModifiableUntil') and instance view 'ReservationStateInfo' on 'Get-AzCapacityReservation' output.
- Added 'SpotPlus' as a supported value for the '-Priority' parameter of 'New-AzVM', 'New-AzVMConfig', 'New-AzVmss', and 'New-AzVmssConfig'.
- 'SpotPlus' is the next generation of Azure Spot for VM (Virtual Machine) and VMSS (Virtual Machine Scale Set) deployments, and offers higher reliability and longer running time than 'Spot'.
- '-EvictionPolicy' and '-MaxPrice' behave the same way as they do for 'Spot'.
- Requires the 'Microsoft.Compute/SpotPlus' subscription feature to be registered, and a region where the feature is enabled.
- For 'New-AzVM': If the extension-version catalogue lookup fails, the cmdlet uses the default BGInfo (Background Information) extension version, and installation failures now emit a warning rather than terminating the cmdlet.
- Added cmdlets and parameters to configure first-party service tags for implicit public IP addresses on VMs (Virtual Machines) and VMSS (Virtual Machine Scale Sets).
- Added extension release metadata support to 'Get-AzVMExtensionImage'.
- Use '-Expand Properties' when listing extension versions to include release category, urgency level, and run profile metadata. Azure/azure-powershell-cmdlet-review-pr#1571
Az.ContainerInstance 5.1.0
- Added Change Safety support.
Az.ContainerRegistry 5.2.0
- Added Change Safety support for additional cmdlets.
Az.DataFactory 1.20.2
- Updated the 'Update-AzDataFactoryV2IntegrationRuntime' example output to use a public service URL.
Az.DataProtection 3.1.0
- Upgraded the DataProtection API version to '2026-06-01' (general availability), which natively models the Azure Elastic SAN (Storage Area Network) backup and restore types
- Added 'AzureElasticSAN' datasource support for backup and restore
- Added '-ResourceSelector' parameter to 'New-AzDataProtectionBackupConfigurationClientObject' for selecting the volume to back up (the service currently supports one volume per backup instance)
- Added '-ResourceIdentifier' and '-ResourceNameOverride' parameters to 'New-AzDataProtectionRestoreConfigurationClientObject' for selecting and optionally renaming the volume to restore
- Enabled 'AzureElasticSAN' in 'Initialize-AzDataProtectionRestoreRequest' and 'Set-AzDataProtectionMSIPermission'
- Added cost management granularity support to backup vault creation and update cmdlets
- Added '-CostManagementGranularity' parameter to 'New-AzDataProtectionBackupVault' and 'Update-AzDataProtectionBackupVault'
- Allowed values are 'VaultLevel', 'ProtectedItemLevel', 'ProtectedItemWithParentTag'
Az.Discovery 1.0.0
- General availability for module Az.Discovery
Az.EventGrid 2.3.0
- Added Change Safety support.
Az.EventHub 5.7.0
- Added Change Safety support for additional cmdlets.
- Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.
Az.Kusto 3.1.0
- Added Change Safety support.
Az.Maintenance 1.7.1
- Changed scheduled event approval failures to terminating PowerShell errors displaying the HTTP status and service error JSON. HTTP 200 and list HTTP 207 responses remain normal output.
- Updated 'Approve-AzScheduledEventList' to return multi-status results through 'Error.Details' with target IDs supplied by the service.
Az.ManagedServiceIdentity 2.1.0
- Added Change Safety support.
Az.Migrate 3.1.0
- Updated Azure Data Replication API version from 2024-09-01 to 2026-05-01
- Added 'MigrateAsArcVM' parameter to 'New-AzMigrateLocalServerReplication' to support migrating VMs as Azure Arc-enabled VMs
Az.Mission 1.0.0
- General availability release for module Az.Mission targeting the stable Microsoft.Mission API version 2026-04-01
Az.Monitor 8.1.0
- Added Change Safety support for data collection rule cmdlets.
Az.Network 8.3.0
- Fixed Change Safety parameter forwarding in custom read-before-write cmdlets.
- Added provider-led ExpressRoute cross-connection migration commands.
- Added First Party Service Tag association support to IP tags used by 'New-AzPublicIpPrefix'.
- Added support for provisioning an ExpressRoute circuit on an 'ExpressRouteLag' resource (Microsoft.Network 2026-01-01 API).
- Added 'MigrateGatewayForPointToSiteProfile' as a supported value for the '-MigrationType' parameter of 'New-AzVirtualNetworkGatewayMigrationParameter', and fixed the cmdlet to honor the user-provided '-MigrationType' value.
- Added Application Gateway advanced routing support.
- Added 'AdvancedRouting' as a supported value for '-RuleType' on 'New-AzApplicationGatewayRequestRoutingRule', 'Add-AzApplicationGatewayRequestRoutingRule', and 'Set-AzApplicationGatewayRequestRoutingRule'.
- Added '-VerifyClientAuthMode' to 'New-AzApplicationGatewayClientAuthConfiguration' and 'Set-AzApplicationGatewayClientAuthConfiguration' to select the frontend mutual TLS (mTLS) client certificate verification mode.
- Upgraded Network SDK to API version '2026-01-01'.
- Fixed '-EnableOnlyIpv6Peering' on 'New-AzVirtualHubVnetConnection' so that the 'Enabled' and 'Disabled' values are correctly translated to the boolean 'enableOnlyIPv6Peering' property expected by the service.
- Added minimum and maximum allocation size bounds to IPAM pool creation, update, and output.
- Added 'Get-AzExpressRouteCircuitAuthorizationKey' and 'Get-AzExpressRoutePortAuthorizationKey' to retrieve the authorization key for an ExpressRoute circuit or port authorization (Microsoft.Network 2026-01-01 API).
- Added WAF (Web Application Firewall) managed rule set display name and managed rule paranoia level to Application Gateway WAF cmdlet output.
- Added 'SourceGeoLocation' and 'DestinationGeoLocation' filters to 'New-AzFirewallPolicyNetworkRule'.
- Removed client-side validation of the '-FormatVersion' parameter for 'New-AzNetworkWatcherFlowLog' and 'Set-AzNetworkWatcherFlowLog'.
- Added Change Safety support for additional cmdlets.
- Added the 'CAPTCHA' action to Application Gateway WAF policies.
Az.RecoveryServices 7.15.0
- Moved Instant Item Recovery (ILR) mount script retrieval to the dedicated 'listInstantItemRecoveryOperationResult' action (api-version '2026-08-01'); 'Get-AzRecoveryServicesBackupRPMountScript' no longer reads iSCSI CHAP connection details from the broad ILR operation-status response (MSRC-114273).
- Added Managed Identity (MI) based authentication support for Azure File Share backup:
- Supports identity-based registration and restore for Azure File Share backup, including Cross Subscription Restore.
- Fixed 'New-AzRecoveryServicesVault' and 'Update-AzRecoveryServicesVault' to use the AsPerPolicy configuration by default when enabling vault immutability.
- Fixed cross-subscription Azure VM protection for virtual machines with user-assigned managed identities.
- Added Microsoft Defender for Cloud Source Scan configuration for Recovery Services vaults and Azure Virtual Machine backup items.
- Supports vault and protected-item configuration and exposes Source Scan and threat details in backup output.
Az.Resources 10.2.1
- Aligned deployment stack WhatIfResult tag preservation with deployment stack cmdlets when '-Tag' is omitted or explicitly given a null value.
Az.ServiceBus 4.4.0
- Added Change Safety support for additional cmdlets.
- Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.
Az.Sql 7.2.0
- Exposed the backup storage redundancy type in the output of 'Get-AzSqlInstanceDatabaseLongTermRetentionBackup'.
- Fixed 'Restore-AzSqlDatabase' to omit the high availability (HA) replica count when the parameter is not specified.
- Added selective-fields support to Azure SQL auditing
- Added the optional 'RequiredFields' parameter to 'Set-AzSqlServerAudit' and 'Set-AzSqlDatabaseAudit'
- Added 'RequiredFields' to the output of 'Get-AzSqlServerAudit' and 'Get-AzSqlDatabaseAudit'
- Updated blob auditing operations to API version '2026-08-01-preview'
Az.StorageSync 2.7.0
- Improved help for the 'ChangeEnumerationIntervalDay' parameter
- Fixed 'Set-AzStorageSyncServer' to retrieve the registered server using the validated server ID
- Added 'ChangeEnumerationIntervalDay' parameter to 'New-AzStorageSyncCloudEndpoint' cmdlet
- Allows customers to configure the interval in days between change enumeration operations for cloud endpoints
- Optional parameter that provides control over change detection frequency
- Valid range: 1 to 20 days
- Added 'Set-AzStorageSyncCloudEndpoint' cmdlet
- Allows customers to update the 'ChangeEnumerationIntervalDay' property of an existing cloud endpoint
- Valid range: 1 to 20 days
Az.Websites 4.2.0
- Upgraded the Microsoft.Web API version from 2021-01-15 to 2025-05-01. Microsoft.CertificateRegistration and Microsoft.DomainRegistration remain on 2021-01-15.
SHA256 Hashes of the release artifacts
- Az-Cmdlets-16.4.0.41245.tar.gz
- 8DDFF52ADB99EABAE532C81C7E0C4E0447025151731803AC7535911128C3244D