Azure Local (formerly Azure Stack HCI) Design and Deployment
IT Partner designs and deploys Azure Local — the platform Microsoft renamed from Azure Stack HCI at Ignite in November 2024 — for mid-size and enterprise organizations that need compute to stay on their own premises for latency, data sovereignty or regulation, but want it run from the Azure control plane. The engagement covers capacity sizing and the selection of validated hardware from the Azure Local catalog (you buy it from your OEM), network and storage design, Active Directory or local-identity preparation, Azure Arc registration and the cloud deployment from the Azure portal, Azure Local VM management through Arc, optional Azure Virtual Desktop and AKS, migration of your Hyper-V or VMware virtual machines into the new instance, and an operations handover your team runs the platform from. Projects are quoted per estate — one written fixed price per instance and site after a scoping call, starting from $9,500 — and a single-instance deployment typically runs about six weeks once the hardware is racked, managed by Roman Sotnik. The hardware, Microsoft's per-physical-core Azure Local subscription and any Azure services you attach are your own purchases, billed by your OEM and by Microsoft, and are not part of our fee.
What this engagement is
Three kinds of estates arrive at this page. The first is a Hyper-V cluster on Windows Server 2016 hosts — extended support ends on 12 January 2027 per Microsoft's product lifecycle, and the 2012 R2 hosts still behind it lose Extended Security Updates on 13 October 2026 — where the hardware is due anyway and nobody wants to hand-build another failover cluster. The second is a VMware estate facing a renewal after Broadcom's licensing changes, with a board asking why the hypervisor bill climbed for software that runs Windows VMs. The third was never a cloud candidate: a plant floor or clinical system that cannot tolerate WAN latency, a data set that regulation keeps on the premises, a site with thin or intermittent connectivity, or an estate whose auditors want the data on one side of a sovereignty line and the control plane on the other. All three want the same thing — Microsoft's hypervisor, storage and networking stack on hardware they own, managed from the Azure portal like everything else — and that is what Azure Local is. Azure Local is Microsoft's Azure Arc-enabled infrastructure platform: Hyper-V, Storage Spaces Direct (or, in a disaggregated design, an external SAN), software-defined networking, and an Azure-delivered operating system that Microsoft updates as one solution on a monthly release train — release 2608 is current at the time of writing, and since release 2504 every new deployment runs the 26100 build line, the same OS generation as Windows Server 2025. The instance registers with Azure Arc, so its VMs, Kubernetes clusters, updates, monitoring and policy live in Azure Resource Manager alongside your cloud subscriptions. Microsoft bills it per physical core per month to your Azure subscription, and supports it only on hardware in the Azure Local catalog — validated nodes, integrated systems and Premier Solutions from Dell, HPE, Lenovo and other OEMs — which you buy from the OEM against the bill of materials we specify. We start with an honest platform decision, because Azure Local is not the answer for every estate. If the workloads can simply move to Azure, we say so and route you to the migration pages. If you hold Windows Server Datacenter licences with Software Assurance and have no appetite for a cloud control plane, a Windows Server 2025 failover cluster is a legitimate alternative and we scope that instead. If the driver is a VMware renewal, the design document sets out per workload whether Azure Local, Azure or retirement is the cheaper home. Once Azure Local is the answer, the design covers the things that are expensive to change after the first VM lands: capacity in cores, memory and usable storage after resiliency overhead; machine count and topology — a single machine, a two-machine switchless instance with a cloud witness, a three- or four-machine switchless instance, or a switched hyperconverged instance of up to sixteen machines, with rack-aware and disaggregated SAN designs for larger footprints; the Network ATC intents for management, compute and storage, with RDMA storage networking at 10 GbE minimum and 25 GbE or better recommended, two storage VLANs, jumbo frames and a management subnet with the contiguous addresses the deployment needs; identity — the Active Directory organizational unit and deployment account the instance is joined with, or the local identity with Azure Key Vault option Microsoft made generally available in release 2604 for sites that do not want a domain-joined platform; the Azure side — subscription, region, resource group, the Key Vault that holds deployment secrets, the witness storage account and the roles the deployment identity needs; outbound connectivity, with Azure Arc gateway to shorten the list of endpoints your firewall must allow; and the security posture the platform applies by default — TPM 2.0, Secure Boot, BitLocker and Microsoft's hardened baseline — with the exceptions your applications force written down rather than assumed. Then we deploy: the operating system installed on each machine, every machine registered with Azure Arc, Microsoft's environment checker run until it is clean, and the instance created from the Azure portal or an ARM template and validated against the design before the first workload arrives. Post-deployment we stand up Azure Local VM management through Arc — custom location, logical networks, an image library, VMs created from the portal, CLI or templates — connect Azure Update Manager for solution updates, wire Azure Monitor Insights and alerting, and enable Defender for Cloud where the design calls for it. The migration wave moves your VMs in: Microsoft's Azure Migrate path for VMware sources is generally available, Azure Migrate for Hyper-V sources is in preview at the time of writing, and we choose per VM between Azure Migrate, a controlled export-and-import of virtual disks, or a rebuild — with test migrations, a cutover runbook and rollback for each wave. Optional Azure Virtual Desktop session hosts and AKS clusters on the instance are designed and deployed as scoped add-ons. We hand over with an as-built document, an operations runbook and a recorded walkthrough that your team — or our managed service — runs the platform from. Hardware procurement is yours, ongoing operations after handover are a separate engagement, and moving workloads to the public cloud is its own page.
Success criteria
What you receive
How the work unfolds
Inventory of hosts, VMs, cores, memory, storage and network from your Hyper-V or vCenter environment; workload requirements — latency, residency, attached hardware, licensing anchors; your Windows Server licensing position; and the connectivity and Azure foundation you already have. Output is the design outline with the honest recommendation per workload: Azure Local, Azure, a Windows Server 2025 cluster, or retirement.
The design document — capacity, machine count and topology, network intents and VLANs, identity, Azure resources, security exceptions, cost model and migration waves — which you approve in writing, and the bill-of-materials brief you take to your OEM. OEM lead time runs from here and sits outside the six weeks; the deployment weeks below start when the machines are racked and powered.
Switch configuration to the design validated with your network team, Active Directory organizational unit and deployment account (or local identity with Key Vault), DNS entries, firewall rules or Azure Arc gateway, and the Azure side — subscription placement, resource group, Key Vault, witness storage account and role assignments.
Operating system installed on every machine, each machine registered with Azure Arc, Microsoft's environment checker run and every finding closed, the instance deployed from the Azure portal or an ARM template, and post-deployment validation — storage pool, networks, witness, update readiness — recorded against the design.
Azure Local VM management stood up — custom location, logical networks, image library, VM templates, guest management — with Azure Update Manager, Azure Monitor Insights and alerting, Defender for Cloud where agreed, the backup configuration in the design, and Windows Server guest licensing under your chosen option. Optional Azure Virtual Desktop or AKS add-ons are built here when in scope.
A pilot wave first — a handful of low-risk VMs through Azure Migrate or disk export-and-import, test-migrated, cut over, validated by their owners — then production waves on the agreed schedule, each with a cutover runbook, rollback and a per-VM validation record. Source VMs are retained for the agreed period before deletion.
As-built document and operations runbook delivered, recorded walkthrough for your platform team, open items closed, temporary access removed, and acceptance signed. Ongoing operations continue with your team from the runbook or under a separate managed-service engagement.
Prerequisites
Who does what
IT Partner
- Lead discovery, make the platform recommendation honestly, and produce the design document, cost model and bill-of-materials brief.
- Prepare the Azure side, validate site readiness, and deploy the instance to the approved design from the Azure portal or an ARM template.
- Stand up VM management, solution updates, monitoring, and the agreed security and backup configuration.
- Plan and execute the migration waves with test migrations, cutover runbooks and rollback, and record per-VM validation.
- Deliver the as-built document, runbook and recorded handover; raise risks, scope changes and platform constraints as soon as they are found; and remove any temporary access we were granted.
Your team
- Procure the hardware from your OEM against the brief, and provide rack, power, cooling and switch configuration to the design.
- Provide Azure, Active Directory, network and source-hypervisor access, and make design decisions when options are presented.
- Own Microsoft's charges: the Azure Local per-core subscription, Windows Server guest licensing, Extended Security Updates where Microsoft charges for them, and any attached Azure services.
- Supply application owners to test each migrated VM, and approve each cutover window.
- Operate the platform after handover from the runbook, or contract managed operations separately.
What's not included
Limitations & technical notes
Frequently asked questions
What is Azure Local, and what happened to Azure Stack HCI?
Azure Local is the name Microsoft gave Azure Stack HCI at Ignite in November 2024. It is the same product line — Hyper-V, Storage Spaces Direct, software-defined networking and an Azure-delivered operating system on validated hardware you own — now positioned as Microsoft's Azure Arc-enabled infrastructure for on-premises and edge sites. Existing Azure Stack HCI 23H2 instances updated into Azure Local; since release 2504 new deployments run the 26100 build line, the same generation as Windows Server 2025, and the OEM licence formerly called the Azure Stack HCI OEM licence is now the OEM licence for Azure Local. If you are still searching for 'Azure Stack HCI', this is the page.
Azure Local versus Hyper-V on Windows Server — which should we run?
Both use Hyper-V. A Windows Server 2025 Datacenter failover cluster with Storage Spaces Direct is a perpetual licence you patch and operate yourself, managed with Windows Admin Center, Failover Cluster Manager or System Center — a good answer for teams that want no cloud dependency and already own Datacenter licences with Software Assurance. Azure Local is a per-core subscription billed through Azure, with an operating system Microsoft delivers and updates as one solution, VMs and updates managed from the Azure portal through Arc, and platform features a Windows Server cluster does not get — Azure Virtual Desktop session hosts, AKS enabled by Arc, Azure Policy and Defender integration, and the Azure benefits for guest VMs. Choose Azure Local when Azure is already your management plane and you want one way of working across cloud and premises; choose a Windows Server cluster when the site must run with no Azure relationship at all. The design document states the recommendation per estate, and we are comfortable recommending either.
Can Azure Local replace VMware?
For Windows and Linux virtual-machine estates, yes: the hypervisor becomes Hyper-V, vSAN's role is taken by Storage Spaces Direct or an external SAN, NSX-style network virtualization maps to Azure Local's software-defined networking, and Microsoft's Azure Migrate path for VMware sources into Azure Local is generally available — agentless replication with test migrations before cutover. What does not translate one-for-one is the surrounding ecosystem: backup products, monitoring agents, automation and third-party appliances need Hyper-V and Azure Local support, and VMs with hardware pass-through or vendor appliances delivered as OVAs are checked individually. The design document lists every VM with its disposition — migrate, rebuild, move to Azure, or retire — before you sign anything.
Do our Windows Server 2016 and 2012 R2 VMs get Extended Security Updates at no charge on Azure Local?
Only partly, and the difference matters. Per Microsoft's Azure Local documentation, ESUs for editions that left support before 1 April 2026 — Windows Server 2012 and 2012 R2 among them — remain available at no additional charge on Azure Local through Azure verification for VMs; that benefit runs until Windows Server 2012 R2 ESU itself ends on 13 October 2026 per Microsoft's product lifecycle. ESUs released after 1 April 2026, including Windows Server 2016 when its extended support ends on 12 January 2027, fall under Microsoft's standardized ESU pricing, so a 2016 VM on Azure Local is not automatically covered at no charge. Azure Local gives those VMs a supported, current platform to live on while you upgrade or retire them; it is not a way around the 2016 ESU bill, and we confirm the terms in force for your estate during design.
What does Azure Local cost to run once it is deployed?
Three lines, all Microsoft's or your OEM's rather than ours. The Azure Local service itself is billed by Microsoft per physical core per month to your Azure subscription at Microsoft's published rate. Windows Server inside the VMs is licensed either through Azure Hybrid Benefit — Windows Server Datacenter licences with active Software Assurance assigned to the machines, which under Microsoft's current terms can also waive the Azure Local host fee — or through the Windows Server subscription add-on billed per core per month; the design document models both against your licence position. Attached services — Defender for Cloud plans, log ingestion, Azure Virtual Desktop, AKS, Azure Migrate — are metered as they are anywhere in Azure. We deliberately print none of Microsoft's numbers on this page because Microsoft revises them; the cost model in the design carries the current ones.
Which hardware do we need, and can we buy it from you?
Hardware must come from the Azure Local catalog — validated nodes, integrated systems, or Premier Solutions with the OEM's deeper integration — from Dell, HPE, Lenovo and other listed OEMs, and every machine in an instance must match in model, processor, adapters and drive layout. We produce the bill-of-materials brief and check competing OEM quotes against it; you buy from the OEM, and the warranty and firmware support stay with them. Reusing existing servers is possible only if the exact configuration is in the catalog, which we check before you plan on it.
How many machines does an instance need?
One machine is supported and suits an edge site that accepts no host-level resilience. Two machines with a cloud witness in Azure give you host failover in a switchless design. Three or four machines still run switchless storage; beyond that the storage network goes through switches, and a hyperconverged instance scales to sixteen machines at the time of writing, with rack-aware, disaggregated SAN and multi-rack designs for larger footprints. The design sizes the count from your capacity, the resilience you want, and the storage overhead of the mirroring that resilience costs — usable capacity is a fraction of raw, and the model shows exactly which fraction.
Does the site need Active Directory?
Traditionally yes: Azure Local is deployed with an Active Directory organizational unit and a deployment account, and most estates with existing domain controllers deploy that way. Since release 2604 Microsoft also supports local identity with Azure Key Vault as a generally available option, so a site that does not want a domain-joined platform can deploy without Active Directory. We recommend one or the other in the design based on what already runs on the site and what the migrated VMs expect.
Does Azure Local need an internet connection, and can it run air-gapped?
A standard instance needs outbound HTTPS to Azure — directly, through a proxy, or through Azure Arc gateway, which shortens the endpoint list your firewall must allow — to deploy, report billing and receive updates; it keeps running through connectivity gaps within Microsoft's sync grace period. Fully disconnected operation is a distinct Microsoft configuration: it runs on Premier Solutions hardware with a dedicated management cluster that hosts a local Azure control plane, and it is designed and quoted as its own project rather than folded into this page.
How do our existing VMs get onto Azure Local?
Through waves. For VMware sources, Microsoft's Azure Migrate path into Azure Local is generally available: a source appliance on VMware and a target appliance on the instance replicate VMs without agents, and each VM is test-migrated before its cutover. For Hyper-V sources, Azure Migrate is in preview at the time of writing, so the design states per VM whether we use it, export the virtual disks and re-create the VM through Azure Local VM management, or rebuild. Every wave has a cutover runbook, a rollback path and a validation record signed by the application owner, and source VMs stay for the agreed period before deletion.
Can we run Azure Virtual Desktop and AKS on it?
Yes, both are scoped add-ons. Azure Virtual Desktop session hosts can run on Azure Local so users get desktops from the site with the AVD control plane in Azure — useful where the applications or data must stay on the premises; our Azure Virtual Desktop Implementation page describes the host-pool design we bring to it. AKS enabled by Azure Arc runs Kubernetes clusters on the instance, managed from Azure like any other Arc-connected cluster. Each is quoted in the same estate quote when you want it.
Why is the project quoted per estate rather than a fixed price?
Because a two-machine branch instance with ten VMs and a sixteen-machine datacenter consolidation with three hundred VMs, AVD and an AKS cluster are not the same project, and one price would be wrong for both. The scoping call captures machine count, sites, VM count and mix, add-ons, and what foundation already exists; the quote that follows is one written fixed price per instance and site — from $9,500 for the smallest designs — and per our standard terms you pay after you approve delivery.
How long does it take?
About six weeks for a single instance from design through the last migration wave and handover, once the hardware is racked: discovery and design in weeks one to two, site and Azure preparation in parallel with the OEM's lead time, deployment in weeks three to four, platform services in week four, migration waves in weeks four to six, and handover in week six. What stretches it is hardware lead time, a switch change that waits on a change board, or migration waves with many application owners to schedule.
What happens after handover?
Your team runs the platform from the runbook — monthly solution updates, monitoring triage, VM lifecycle, capacity — or we do under Azure Resource Monitoring and Maintenance as a separate engagement. Organizations that buy their Microsoft licensing through IT Partner get unlimited break-fix support during business hours at no extra charge; platform operations are a managed service, not break-fix, and 24/7 coverage is a paid agreement.
Is Azure Local right for a small office?
Usually not. This page is written for mid-size and enterprise estates — sites with dozens to hundreds of VMs, a real reason to keep them on the premises, and an OEM budget for catalog hardware. A ten-person office with a single aging server is nearly always better served by moving its workloads to Azure or Microsoft 365, and we will say so on the scoping call rather than sell you a platform you do not need.