Slider 1 mini Slider 2 mini

Thursday, 23 July 2026

Filled under:

 

These items can be added to the release notes in the same format:

Platform Work Category Feature Key Value
Azure Cosmos DB Enabler Enhanced provisioning and governance controls Enhanced provisioning and governance controls have been implemented for serverless deployments, public endpoints, administrative access, resource tagging, and seven-day continuous backup configurations. These controls strengthen compliance and ensure that resources are provisioned according to approved platform standards.
Azure Managed Redis Enabler Policy update to enable Redis provisioning The Deny-Redis-Create policy effect has been changed from Deny to Audit. This enables users to provision Azure Managed Redis instances while retaining visibility and governance through policy compliance monitoring.
MongoDB vCore Enabler Automated role assignment and TPAC enablement in Red Zone Automated role assignment has been enhanced through the Red Zone Function App, enabling TPAC access for MongoDB vCore in the Red Zone. This provides authorized users with controlled and compliant access through the automated provisioning process.

For the first row, Azure Cosmos DB appears to be the applicable platform based on the serverless and continuous-backup controls.

Posted By Nikhil01:19

Wednesday, 22 July 2026

Filled under:

 

Database Scanning – Account Creation

Created a dedicated six-month sub-epic to design a secure and scalable database-access approach for increased scanning volumes across Emerging DB platforms. The work will assess the feasibility of a read-only scanning account and review the existing account-ordering process to improve reliability while maintaining ACS compliance.

Posted By Nikhil22:00
Filled under:

 

Database Product Adoption – Emerging DB

  • Completed MongoBleed vulnerability remediation across all supported native MongoDB DBaaS instances.
  • Completed the native MongoDB version-upgrade assessment and successfully tested patching in the development environment. Further rollout is pending application feedback on decommission plans.
  • Conducted enablement sessions for MongoDB users covering cost, platform overview, the Cyclops case study and practical comparisons between native MongoDB and Azure Cosmos DB for MongoDB (vCore).
  • Completed the initial Azure Managed Redis adoption analysis and progressed cost comparisons to identify potential savings and support migration from Redis before its planned retirement.
  • Conducted targeted one-to-one sessions with application teams to explain the cost and operational benefits of moving to Azure Cosmos DB for MongoDB (vCore).

Q3 focus: Finalize the native MongoDB decommission and patching approach, progress Azure Managed Redis migration opportunities, and continue application-specific adoption discussions for Azure Cosmos DB for MongoDB (vCore).

Posted By Nikhil21:53
Filled under:

 

Database Risk Engineering & Control Framework – Emerging DB

  • Strengthened security and compliance controls across Cosmos DB, Redis/AMR and DocumentDB through TLS 1.2 enforcement, Entra ID-based access, access-key restrictions and audit-to-deny policy updates.
  • Updated Cosmos DB ICC evidence and progressed privileged-access controls for controlled and monitored database access through CyberArk.
  • Introduced lower-environment governance policies covering autoscale restrictions, low-cost AMR SKUs and HA configuration auditing to support risk reduction and cost optimisation.
  • Rolled over to Q3: BigID scanning remediation, remaining HA audit-policy coverage for Redis, Cosmos DB and DocumentDB, and completion of the Azure Redis Cache deny-policy readiness checks.
  • The central CMK Key Vault removal and Cosmos NoSQL MIM-group enablement were initiated toward the end of Q2 and completed in early Q3.

Note: Unlike Q3, Q2 did not have a dedicated Cost Optimisation epic. Cost-related policy items were therefore included and tracked under the Risk Engineering & Control Framework epic from the outset.

Posted By Nikhil21:25
Filled under:

 

Based on this context, the summary should focus on the completed decommissioning and closure, rather than only the application engagement activities.

MongoDB Migration/Decommission – UBS Estate

  • Completed the exit of the Database crew-managed native MongoDB estate from the CS environment, in coordination with application and business stakeholders.
  • Created all required RFCs and completed the agreed closure activities, including the retirement of MongoDB-related tooling and supporting utilities.
  • The decommissioning removed the remaining infrastructure and tooling footprint, reducing associated operational and licensing costs.

The epic was closed in Q2 and is not carried over to Q3.

Posted By Nikhil07:32
Filled under:

 

Database Product Enhancement – Emerging DB

  • Enhanced the Azure Function invocation pipeline with asynchronous processing and separate agent pools, enabling parallel execution, reducing wait time and balancing workload across the pipelines.
  • Delivered same-account restore capability for Cosmos DB RU, allowing users to restore databases without creating an additional account.
  • Improved operational traceability by enabling Azure Function audit logs to be stored for activity and response tracking.
  • Progressed migration capabilities through RiotX validation for Redis-to-Azure Managed Redis migration and updates to the Cosmos RU-to-vCore migration pipeline using Entra ID.
  • Optimized the Cosmos metadata export process to support region-specific execution instead of processing all instances.
  • Rolled over to Q3: Completion of secure cross-tenant Cosmos RU-to-vCore migration validation without using a public endpoint.

I have treated the cross-tenant migration without a public endpoint as the rolled-over item, since it appears both in the main list and under “Rolled over to Q3.”

Posted By Nikhil04:26
Filled under:

 

Epic: [Epic Name]

Q2 delivery:
Completed [brief description of the features, controls, validations, automation, or documentation delivered]. This enabled/improved [business or technical outcome].

Closed child items:

  • [Completed item 1]
  • [Completed item 2]
  • [Completed item 3]

Rolled over to Q3:

  • [Item] — rolled over due to [dependency, pending vendor feature, application readiness, resource constraint, or change timeline].

Q3 focus:
Complete the remaining activities related to [brief next step].

Posted By Nikhil03:55