AzBluePrint · Waitlist

Move off Azure Blueprints before Oct 31 — know what to export and how your locks map to Deployment Stacks

  1. Definitions frozen. No new assignments.

  2. Existing assignments frozen.

  3. Retired: API stops, un-exported definitions/versions/assignments deleted, blueprint locks stop working. Resources stay.

Dates per Microsoft Learn "Azure Blueprints retirement". New definitions and versions have been blocked since July 31, 2026.

Answer 5 quick questions — do you still have blueprint definitions or assignments, do you rely on Read Only / Do Not Delete locks, has Azure Advisor flagged you, have you exported JSON, and are you targeting Deployment Stacks, template specs, or Git. Get your deadline risk, export steps, a Blueprints-to-Stacks/Template Specs map (including locks to deny settings), and a regression checklist. Not an Azure connector — never paste credentials, secrets, tenant or subscription IDs, or templates.

Independent tool. Not affiliated with or endorsed by Microsoft. · Market-validation page · Free waitlist · No Azure connection

Problem

Three dates: Oct 31 · Dec 31 · Jan 31

Per Microsoft Learn, Azure Blueprints (Preview) is retiring in phases. On Oct 31, 2026 existing definitions can no longer be modified and new assignments can no longer be created; on Dec 31, 2026 existing assignments can no longer be modified; on Jan 31, 2027 the service retires — un-exported definitions, versions, and assignments are automatically and permanently deleted, and blueprint locks (Do Not Delete, Read Only) stop working. Blueprint locks are Azure RBAC deny assignments that even subscription Owners can't override; when they are removed, resources inherit parent RBAC and any protection that depended on them is gone. The official guidance is complete, but it is spread across the retirement, FAQ, migrate, deployment stacks, and resource-locking pages.

Before

  • Jump between retirement, FAQ, migrate, deployment stacks, and resource-locking docs
  • Discover after Oct 31 that new subscriptions can't get a blueprint assignment
  • Find out in Feb 2027 that definitions are gone and Read Only protection vanished

After — with AzBluePrint

  • Answer 5 questions → only the gates, exports, and mappings that apply to you
  • "Still need new assignments" flagged as an Oct 31 hard deadline up front
  • Per-version export list + Read Only → DenyWriteAndDelete stack + staging test

Official phased timeline (Microsoft Learn)

DateStatusWhat changes
Jul 31, 2026Already in effectNew blueprint definitions and versions can no longer be created.
Oct 31, 2026Definitions frozenExisting blueprint definitions can no longer be modified; new blueprint assignments can no longer be created.
Dec 31, 2026Assignments frozenExisting blueprint assignments can no longer be modified.
Jan 31, 2027RetiredAPI no longer responds; Az CLI and Azure PowerShell commands stop functioning; removed from the portal; un-exported definitions, versions, and assignments are automatically and permanently deleted; blueprint locks (Do Not Delete, Read Only) stop functioning. Resources created through blueprints remain.

Microsoft's retirement FAQ notes that about 30 days before retirement the service phases down to read + delete only. Separately, the Azure CLI az blueprint command group is deprecated and expected to be removed in Azure CLI 2.92.0 (scheduled Nov 2026) — earlier than Jan 31, 2027.

Solution

What AzBluePrint does

A Blueprints → Deployment Stacks retirement-readiness decision layer for platform and governance teams still on Azure Blueprints: your usage × locks × export status × target → gate risk + exports + mappings + regression checklist. Not a replacement for Microsoft Learn, not an Azure connector, and not affiliated with Microsoft.

WHO

Cloud platform engineers, security / governance owners, and cloud architects whose tenants still use Azure Blueprints (Preview) definitions, versions, or assignments — including Do Not Delete or Read Only locks — and have not yet exported and migrated to Azure Deployment Stacks / template specs.

PROBLEM

Oct 31, 2026: definitions frozen, no new assignments. Dec 31, 2026: existing assignments frozen. Jan 31, 2027: API stops, un-exported definitions / versions / assignments are deleted with no recovery, and blueprint locks stop working — resources stay, but effective permissions widen once the deny assignments are gone. Microsoft recommends Azure Deployment Stacks with template specs or Git.

SOLUTION

Tick 5 questions → personalized deadline risk (which gate hits you first), export steps, a Blueprints → Stacks / Template Specs map including locks → DenySettingsMode, and a regression checklist. Never asks for Azure credentials, service principal secrets, tenant / subscription IDs, or template source.

RESULT

Before the Oct 31 freeze, know what you can still do (last new assignments, last definition edits); before Jan 31, have every definition and assignment detail exported and your locks replaced by Deployment Stacks deny settings — instead of finding out in Feb 2027 that definitions are gone and protection has vanished.

Blueprints → Deployment Stacks / Template Specs map

BlueprintsMaps to
Blueprint definition + versionsTemplate spec + versions, or a Git template folder
Blueprint assignmentAzure Deployment Stack (resource group / subscription / management group scope)
Policy assignment artifactPolicy assignment in ARM / Bicep (policyDefinitions can be embedded)
Role assignment artifactRole assignment in ARM / Bicep
ARM template artifactMain template + Bicep modules / nested templates / template links (can be stored as template specs)
Resource group artifactResource group resource in a subscription-scope template
Assignment at management group (so subscription Owners can't remove it)Place the stack at a parent scope (Microsoft: "Store stacks at parent scope")

Based on Microsoft Learn "Migrate blueprints to deployment stacks". Template specs are not required to use Deployment Stacks.

Blueprint locks → Deployment Stacks deny settings Closest equivalent — verify in staging

Closest equivalent — verify in staging
Blueprint lockClosest Deployment Stack setting
Don't Lock (None)DenySettingsMode = None
Do Not Delete (AllResourcesDoNotDelete)DenyDelete
Read Only (AllResourcesReadOnly)DenyWriteAndDelete
excludedPrincipals (max 5)DenySettingsExcludedPrincipal / --deny-settings-excluded-principals (max 5; Microsoft suggests Entra groups instead)
excludedActions (wildcards allowed)DenySettingsExcludedAction / --deny-settings-excluded-actions (max 200)

Not an official mapping. Microsoft only says DenySettingsMode is "similar to Blueprint locks" and publishes no one-to-one table; we compiled these closest equivalents from the resource-locking and deployment-stacks docs — test every row in staging. Known differences: a Blueprint Read Only lock on a resource group still allows tag changes and adding unlocked resources; stack deny settings apply to the control plane only and protect only resources explicitly created in the template (child scopes need DenySettingsApplyToChildScopes); non-None deny settings require the Azure Deployment Stack Owner role (Contributor can't create or delete deny assignments). Deployment Stacks need Azure PowerShell 12.0.0+ or Azure CLI 2.61.0+.

Features

Features

Marketing points from the product hypothesis — for demand validation, not a formal spec promise.

Phase-gate risk timeline

Need new assignments? Oct 31. Need to change assignments? Dec 31. Not exported? Jan 31. Days left for each, plus a reminder that the service is read + delete only about 30 days before retirement.

Export steps

Export-AzBlueprintWithArtifact (PowerShell) or az blueprint export per definition and version, plus saved assignment details; note that the az blueprint command group is slated for removal in Azure CLI 2.92.0 (Nov 2026).

Blueprints → Stacks / Template Specs map

Definitions → template specs or Git; assignments → Deployment Stacks; policy, role, template, and resource group artifacts → ARM / Bicep.

Locks → DenySettingsMode map

Do Not Delete → DenyDelete, Read Only → DenyWriteAndDelete, excluded principals and actions — closest equivalents with caveats to test.

Regression checklist

Deploy the stack in staging, prove deletes/edits are denied, verify policy and roles, then remove the blueprint assignment.

Export steps — PowerShell route and Azure CLI route

Export every definition and every version, save assignment details, and commit everything to Git. Placeholders only — this page never accepts any ID, credential, or template.

PowerShell (Az.Blueprint module)

  1. Get-AzBlueprintFind each blueprint definition; add -Version to pick a specific version.
  2. Export-AzBlueprintWithArtifact -Blueprint … -OutputPath …Writes blueprint.json plus an artifacts/ folder — repeat for every version.
  3. Get-AzBlueprintAssignmentSave assignment details (scope, parameters, lock mode, excludedPrincipals).

Azure CLI

The az blueprint command group is deprecated and expected to be removed in Azure CLI 2.92.0 (scheduled Nov 2026). Export early, pin your CLI version, or use the PowerShell route.

  1. az blueprint export --name … --output-path …Exports a definition with its artifacts.
  2. az blueprint assignment showSave each assignment's details.

The documented export tools cover definitions + artifacts; no dedicated assignment-export command is documented, so keep the assignment output next to the definition exports. Repeat per version and commit to Git.

Join Waitlist

How it works

How it works

Three steps. No Azure connection, no credentials.

  1. 1

    Answer 5 questions

    Still have definitions or assignments? Rely on locks? Flagged by Azure Advisor? Already exported? Targeting Deployment Stacks, template specs, or Git?

  2. 2

    See which gate hits you first

    Personalized Oct 31 / Dec 31 / Jan 31 risk plus an export list — every definition, every version, every assignment's parameters and lock settings — each linked to Microsoft Learn.

  3. 3

    Map, migrate, retest

    Blueprints-to-Stacks/Template Specs map, locks-to-DenySettingsMode map, and a staging regression checklist — never paste credentials, secrets, IDs, or templates.

Use cases

Who it's for

If these situations sound familiar, join the waitlist to help us validate.

Landing-zone baseline assigned to many subscriptions

New subscriptions get their baseline through "one more assignment" — not possible after Oct 31. Move new subscriptions to a Deployment Stack now and queue the existing ones for migration.

Hub network resource group behind a Read Only lock

On Jan 31 locks are removed automatically and Owners can delete or change those resources. You need a DenyWriteAndDelete stack with excluded principals (CI, break-glass groups), verified in staging first.

Azure Advisor flagged you, but the scope is unclear

You need an inventory (Advisor recommendation + the Azure Blueprints blade in the portal) and what to export first for each assignment.

Compliance baseline that needs version history

Auditors want definition versions kept: export version by version and publish them as template spec versions or Git tags.

Pipelines still call az blueprint

The CLI command group is expected to be removed in 2.92.0 (Nov 2026): export first, pin your tooling version or switch to PowerShell export, then move deployments to az stack.

Tenant scheduled for decommissioning

Microsoft's FAQ allows a limited "export + standard Azure resource locks" approach for tenants on near-term decommissioning — know whether you qualify and the minimum you must do.

FAQ

FAQ

Is AzBluePrint an official Microsoft tool?

No. AzBluePrint is independent and not affiliated with or endorsed by Microsoft. Everything cites Microsoft Learn with links.

How is it different from Microsoft Learn?

Microsoft Learn covers every case across several pages. We filter to your usage, locks, export status, and target, and output gate risk, exports, mappings, and a regression checklist.

How is it different from Azure Advisor?

Advisor tells you where Blueprints is in use. We tell you what to do next, and in what order.

Will my resources be deleted at retirement?

Per Microsoft Learn, resources created through blueprints remain. Un-exported definitions, versions, and assignments are deleted, and blueprint locks are removed.

How do I keep lock protection?

Microsoft's FAQ recommends managing the resources in a Deployment Stack with deny settings. We give closest equivalents (Do Not Delete → DenyDelete, Read Only → DenyWriteAndDelete) and a test list — there's no official one-to-one table, so verify in staging.

Can I still change assignments after Oct 31?

Per the official timeline, after Oct 31 definitions can't be modified and new assignments can't be created; existing assignments can still be modified until Dec 31.

Will you ask for credentials, secrets, tenant/subscription IDs, or templates?

No. Never asked, never held, never stored. We don't connect to your Azure tenant.

Do you export, convert to Bicep, or deploy for me?

No. The MVP is a static questionnaire + lists + mappings + checklist + waitlist.

When is early access?

Waitlist invites go out in batches by email. No fake launch date.

AzBluePrint is an independent tool, not affiliated with or endorsed by Microsoft. Microsoft and Azure are trademarks of the Microsoft group of companies.

Join Waitlist

Waitlist

Join the waitlist

Leave your work email for AzBluePrint early access and launch notes. Email plus optional checkboxes and dropdowns only — there is no free-text field anywhere on this form.

Blueprints usage (optional)
Lock modes in use (optional)

Used only for waitlist, early access, and launch emails. Never paste Azure credentials, service principal secrets, tenant or subscription IDs, blueprint JSON, or templates. Unsubscribe anytime.