github Azure/azure-powershell v16.4.0-October2026
Az 16.4.0

5 days ago

Gallery Module for Azure PowerShell: https://www.powershellgallery.com/packages/Az/16.4.0

To install Az from the PowerShell Gallery, run the following command:


Install-Module -Name Az -Repository PSGallery -Force

To update from an older version of Az, run the following command:


Update-Module -Name Az

Docker images

  • mcr.microsoft.com/azure-powershell:latest
  • mcr.microsoft.com/azure-powershell:alpine-3.23
  • mcr.microsoft.com/azure-powershell:16.4.0-alpine-3.23
  • mcr.microsoft.com/azure-powershell:debian-12
  • mcr.microsoft.com/azure-powershell:16.4.0-debian-12
  • mcr.microsoft.com/azure-powershell:azurelinux-3.0
  • mcr.microsoft.com/azure-powershell:16.4.0-azurelinux-3.0
  • mcr.microsoft.com/azure-powershell:azurelinux-3.0-arm64
  • mcr.microsoft.com/azure-powershell:16.4.0-azurelinux-3.0-arm64
  • mcr.microsoft.com/azure-powershell:ubuntu-24.04
  • mcr.microsoft.com/azure-powershell:16.4.0-ubuntu-24.04

Release Notes

Az.Compute 11.10.0

  • Added '-ScheduleProfileStart' and '-MinimumCommitmentDayCount' parameters to 'New-AzCapacityReservation' to create Future Capacity Reservations, and surfaced the read-only 'ScheduleProfile' (including 'ModifiableUntil') and instance view 'ReservationStateInfo' on 'Get-AzCapacityReservation' output.
  • Added 'SpotPlus' as a supported value for the '-Priority' parameter of 'New-AzVM', 'New-AzVMConfig', 'New-AzVmss', and 'New-AzVmssConfig'.
    • 'SpotPlus' is the next generation of Azure Spot for VM (Virtual Machine) and VMSS (Virtual Machine Scale Set) deployments, and offers higher reliability and longer running time than 'Spot'.
    • '-EvictionPolicy' and '-MaxPrice' behave the same way as they do for 'Spot'.
    • Requires the 'Microsoft.Compute/SpotPlus' subscription feature to be registered, and a region where the feature is enabled.
  • For 'New-AzVM': If the extension-version catalogue lookup fails, the cmdlet uses the default BGInfo (Background Information) extension version, and installation failures now emit a warning rather than terminating the cmdlet.
  • Added cmdlets and parameters to configure first-party service tags for implicit public IP addresses on VMs (Virtual Machines) and VMSS (Virtual Machine Scale Sets).
  • Added extension release metadata support to 'Get-AzVMExtensionImage'.

Az.ContainerInstance 5.1.0

  • Added Change Safety support.

Az.ContainerRegistry 5.2.0

  • Added Change Safety support for additional cmdlets.

Az.DataFactory 1.20.2

  • Updated the 'Update-AzDataFactoryV2IntegrationRuntime' example output to use a public service URL.

Az.DataProtection 3.1.0

  • Upgraded the DataProtection API version to '2026-06-01' (general availability), which natively models the Azure Elastic SAN (Storage Area Network) backup and restore types
  • Added 'AzureElasticSAN' datasource support for backup and restore
    • Added '-ResourceSelector' parameter to 'New-AzDataProtectionBackupConfigurationClientObject' for selecting the volume to back up (the service currently supports one volume per backup instance)
    • Added '-ResourceIdentifier' and '-ResourceNameOverride' parameters to 'New-AzDataProtectionRestoreConfigurationClientObject' for selecting and optionally renaming the volume to restore
    • Enabled 'AzureElasticSAN' in 'Initialize-AzDataProtectionRestoreRequest' and 'Set-AzDataProtectionMSIPermission'
  • Added cost management granularity support to backup vault creation and update cmdlets
    • Added '-CostManagementGranularity' parameter to 'New-AzDataProtectionBackupVault' and 'Update-AzDataProtectionBackupVault'
    • Allowed values are 'VaultLevel', 'ProtectedItemLevel', 'ProtectedItemWithParentTag'

Az.Discovery 1.0.0

  • General availability for module Az.Discovery

Az.EventGrid 2.3.0

  • Added Change Safety support.

Az.EventHub 5.7.0

  • Added Change Safety support for additional cmdlets.
  • Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.

Az.Kusto 3.1.0

  • Added Change Safety support.

Az.Maintenance 1.7.1

  • Changed scheduled event approval failures to terminating PowerShell errors displaying the HTTP status and service error JSON. HTTP 200 and list HTTP 207 responses remain normal output.
  • Updated 'Approve-AzScheduledEventList' to return multi-status results through 'Error.Details' with target IDs supplied by the service.

Az.ManagedServiceIdentity 2.1.0

  • Added Change Safety support.

Az.Migrate 3.1.0

  • Updated Azure Data Replication API version from 2024-09-01 to 2026-05-01
  • Added 'MigrateAsArcVM' parameter to 'New-AzMigrateLocalServerReplication' to support migrating VMs as Azure Arc-enabled VMs

Az.Mission 1.0.0

  • General availability release for module Az.Mission targeting the stable Microsoft.Mission API version 2026-04-01

Az.Monitor 8.1.0

  • Added Change Safety support for data collection rule cmdlets.

Az.Network 8.3.0

  • Fixed Change Safety parameter forwarding in custom read-before-write cmdlets.
  • Added provider-led ExpressRoute cross-connection migration commands.
  • Added First Party Service Tag association support to IP tags used by 'New-AzPublicIpPrefix'.
  • Added support for provisioning an ExpressRoute circuit on an 'ExpressRouteLag' resource (Microsoft.Network 2026-01-01 API).
  • Added 'MigrateGatewayForPointToSiteProfile' as a supported value for the '-MigrationType' parameter of 'New-AzVirtualNetworkGatewayMigrationParameter', and fixed the cmdlet to honor the user-provided '-MigrationType' value.
  • Added Application Gateway advanced routing support.
  • Added 'AdvancedRouting' as a supported value for '-RuleType' on 'New-AzApplicationGatewayRequestRoutingRule', 'Add-AzApplicationGatewayRequestRoutingRule', and 'Set-AzApplicationGatewayRequestRoutingRule'.
  • Added '-VerifyClientAuthMode' to 'New-AzApplicationGatewayClientAuthConfiguration' and 'Set-AzApplicationGatewayClientAuthConfiguration' to select the frontend mutual TLS (mTLS) client certificate verification mode.
  • Upgraded Network SDK to API version '2026-01-01'.
  • Fixed '-EnableOnlyIpv6Peering' on 'New-AzVirtualHubVnetConnection' so that the 'Enabled' and 'Disabled' values are correctly translated to the boolean 'enableOnlyIPv6Peering' property expected by the service.
  • Added minimum and maximum allocation size bounds to IPAM pool creation, update, and output.
  • Added 'Get-AzExpressRouteCircuitAuthorizationKey' and 'Get-AzExpressRoutePortAuthorizationKey' to retrieve the authorization key for an ExpressRoute circuit or port authorization (Microsoft.Network 2026-01-01 API).
  • Added WAF (Web Application Firewall) managed rule set display name and managed rule paranoia level to Application Gateway WAF cmdlet output.
  • Added 'SourceGeoLocation' and 'DestinationGeoLocation' filters to 'New-AzFirewallPolicyNetworkRule'.
  • Removed client-side validation of the '-FormatVersion' parameter for 'New-AzNetworkWatcherFlowLog' and 'Set-AzNetworkWatcherFlowLog'.
  • Added Change Safety support for additional cmdlets.
  • Added the 'CAPTCHA' action to Application Gateway WAF policies.

Az.RecoveryServices 7.15.0

  • Moved Instant Item Recovery (ILR) mount script retrieval to the dedicated 'listInstantItemRecoveryOperationResult' action (api-version '2026-08-01'); 'Get-AzRecoveryServicesBackupRPMountScript' no longer reads iSCSI CHAP connection details from the broad ILR operation-status response (MSRC-114273).
  • Added Managed Identity (MI) based authentication support for Azure File Share backup:
    • Supports identity-based registration and restore for Azure File Share backup, including Cross Subscription Restore.
  • Fixed 'New-AzRecoveryServicesVault' and 'Update-AzRecoveryServicesVault' to use the AsPerPolicy configuration by default when enabling vault immutability.
  • Fixed cross-subscription Azure VM protection for virtual machines with user-assigned managed identities.
  • Added Microsoft Defender for Cloud Source Scan configuration for Recovery Services vaults and Azure Virtual Machine backup items.
    • Supports vault and protected-item configuration and exposes Source Scan and threat details in backup output.

Az.Resources 10.2.1

  • Aligned deployment stack WhatIfResult tag preservation with deployment stack cmdlets when '-Tag' is omitted or explicitly given a null value.

Az.ServiceBus 4.4.0

  • Added Change Safety support for additional cmdlets.
  • Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.

Az.Sql 7.2.0

  • Exposed the backup storage redundancy type in the output of 'Get-AzSqlInstanceDatabaseLongTermRetentionBackup'.
  • Fixed 'Restore-AzSqlDatabase' to omit the high availability (HA) replica count when the parameter is not specified.
  • Added selective-fields support to Azure SQL auditing
    • Added the optional 'RequiredFields' parameter to 'Set-AzSqlServerAudit' and 'Set-AzSqlDatabaseAudit'
    • Added 'RequiredFields' to the output of 'Get-AzSqlServerAudit' and 'Get-AzSqlDatabaseAudit'
    • Updated blob auditing operations to API version '2026-08-01-preview'

Az.StorageSync 2.7.0

  • Improved help for the 'ChangeEnumerationIntervalDay' parameter
  • Fixed 'Set-AzStorageSyncServer' to retrieve the registered server using the validated server ID
  • Added 'ChangeEnumerationIntervalDay' parameter to 'New-AzStorageSyncCloudEndpoint' cmdlet
    • Allows customers to configure the interval in days between change enumeration operations for cloud endpoints
    • Optional parameter that provides control over change detection frequency
    • Valid range: 1 to 20 days
  • Added 'Set-AzStorageSyncCloudEndpoint' cmdlet
    • Allows customers to update the 'ChangeEnumerationIntervalDay' property of an existing cloud endpoint
    • Valid range: 1 to 20 days

Az.Websites 4.2.0

  • Upgraded the Microsoft.Web API version from 2021-01-15 to 2025-05-01. Microsoft.CertificateRegistration and Microsoft.DomainRegistration remain on 2021-01-15.

SHA256 Hashes of the release artifacts

  • Az-Cmdlets-16.4.0.41245.tar.gz
    • 8DDFF52ADB99EABAE532C81C7E0C4E0447025151731803AC7535911128C3244D

Don't miss a new azure-powershell release

NewReleases is sending notifications on new releases.