未经同意请勿转载适用版本Azure Local 12.2602.1002.5012602 → 12.2606.1003.2052606文档来源Whats new in Azure Local / Release information / Known issues / AzureStackHCI-Supportability维护版本v1.1 · 2026-07-21 · ACP 评审修订版TL;DR2602 直跳 2606 在微软 6 个月支持窗口内完全合规但中间会一次性带入 2604 那一波 GA 项升级前必须做兼容性评估特别是 AKS Arc node pool / OEM SBE / 外部 SAN。Azure Stack HCI 23H2 OSOS Build 25398.xxxx已进入生命周期末期Azure Local 24H2OS Build 26100.xxxx与 Windows Server 2025 24H2 系列 Build Number 一致成为当前主支持版本——任何仍在 23H2 的客户应当把升 24H2 当作当下最重要的版本任务。升级路径不是线性的必须先升到上一个 Cumulative Build再升 Feature Build跳过中间的 Cumulative 直接升 Feature 是微软不推荐的做法。本篇给出可直接执行的实战清单升级前的 7 项检查、升级中的 5 步顺序、升级后的 4 项验证以及一份按场景分类的升级决策树。一、升级路径全景图1.1 微软的硬性升级路径规则来自 Release informationTo keep your Azure Local solution in a supported state, you have up to six months to install updates. However, before installing the feature update, make sure to install the last released cumulative update.Before you can update to the 2511 release, you must first apply the 12.2510 update. The 12.2510 (24H2) update becomes automatically available once you apply 11.2510.也就是说维度规则Feature Build 升级前必须先装上一个 Feature Build 的最后一个 Cumulative Build从 23H2 升 24H2必须先升 11.2510再升 12.2510才能进 24H2 主线跳过中间 Cumulative微软不推荐可能触发 SBE manifest 校验失败6 个月支持窗口超过 6 个月未更新 不受支持1.2 两条主线的推荐升级路径A. 仍在 23H211.xxxx 系列OS 25398.xxxx的客户推荐路径合规且最稳 11.2503 → 11.2504 → 11.2505 → 11.2506 → 11.2507 → 11.2508 → 11.2509 → 11.2510 ↓ └→ 12.2510 → 12.2511 → 12.2512 → 12.2601 → 12.2602 → ... → 12.2606 ↑ 注意23H2 已进入生命周期末期必须尽快迁到 24H2紧急路径生产已被 23H2 EOL 风险暴露但仍想保留 HCI 形态 直接升 11.2510 → 12.2510 → ... → 12.2606。微软允许从 23H2 的最终 Cumulative Build11.2510.1002.93跨到 12.x但必须先升到 11.2510。B. 已在 24H212.xxxx 系列OS 26100.xxxx的客户推荐路径以 2602 为例 12.2602 → 12.2602.x最后 Cumulative→ 12.2603 → 12.2603.x → ... → 12.2606 更精简的合规直跳路径仍在 6 个月窗口内 12.2602 → 12.2603 → 12.2604 → 12.2605 → 12.2606 中间 Cumulative 由 Update Wizard 自动应用**前提是 OEM SBE 允许**1.3 容易踩的坑坑说明跳过中间的 Cumulative 直接装 Feature可能触发 SBE manifest 校验失败已知 warning 级 error SBE manifest endpoint not reported by Get-SolutionDiscoveryDiagnosticInfo使用被召回的 11.2510.1002.87 / 12.2510.1002.88 镜像add node / repair node 会失败必须先升到 .93 / .94Azure Arc resource bridge 超 1 年未升级证书失效、Azure Local VM 功能异常Defender for Endpoint 启用了 Restrict App ExecutionUpdate / Repair 失败Defender ASR 规则阻止 PSExec WMISolution Update 失败二、升级前必须检查的 7 件事2.1 OEM Solution Builder ExtensionSBE状态If your cluster supports Solution Builder Extension software updates, you receive feature release updates after your hardware vendor completes their validation and confirms the release is ready. This process typically takes a few weeks following the Microsoft release and varies by hardware vendor.为什么这件事排在第一微软每个月 release 后OEM 还要做 SBE 适配验证验证完成前 SBE 不会推送。客户在 Azure Update Manager 里看不到 2606 不代表集群落后可能是 OEM 还在验证。检查方式Azure Update Manager → Cluster → Readiness checks / Available updates与 OEM Support 确认 2606 SBE 适配时间表2.2 AKS Arc 集群的 K8s 版本与 node pool OS检查项要求K8s 版本在 1.31.12 ~ 1.33.5 之间2606 支持矩阵WS2019 node pool必须在升级前迁移到 WS2022 / WS2025——WS2019 SKU 在 2603 已完全 EOLKMS 配置评估是否要迁到 KMS v2v1 弃用倒计时关键原则升 Azure Local 之前先把 AKS Arc 升到受支持的 K8s 受支持的 node pool OS。否则升 Azure Local 后 AKS Arc 会进入不可用状态。2.3 集群当前 Solution 版本与 OS Build确认起点如果在 2601 / 2602需要注意 MOC 误删 VM 漏洞——升级前应用 Remediation Support Tool如果在 11.xxxx23H2需要先升 11.2510 再跨 12.x如果在 10.xxxx旧 23H2 终端需要先升 11.x2.4 外部存储SAN依赖检查项说明是否使用 FC SAN2604 GAiSCSI 仍在 preview存储 vendor 是否在 Azure Local 支持矩阵微软只认证特定 vendoriSCSI 流量隔离网络iSCSI SAN 需要独立网络2.5 GPU 部署计划检查项说明现有 GPU 型号在 OEM SKU 认证列表内RTX PRO 6000 Blackwell 是 2603 起支持计划用 DDA 还是 GPU-P决策影响 GPU 切分策略、监控告警设置Day-2 热操作是否需要2604 起支持热挂 / 热卸载2.6 Local Identity with Key Vault仅限气隙 / 弱连接客户检查项说明客户是否已部署 Key VaultKey Vault 必须可访问轮换策略已就绪Rack-aware 集群是否计划用 Local Identity2604 起支持 Rack-aware Local Identity 组合哪些 Azure 服务还依赖 Azure AD参考 Generally available or supported services2.7 Defender for Endpoint / Defender ASR 配置检查项说明Restrict App Execution是否启用必须禁用否则 Update / Repair 失败Block Process Creations originating from PSExec WMI不能 Block否则 Solution Update 失败参考 TSG三、升级中5 步推荐顺序3.1 第一步备份与快照虽然 Azure Local 升级是 in-place但强烈建议做以下备份配置备份通过 Azure portal 或 PowerShell 导出集群配置关键 VM 快照Azure Local VM 在升级前不需要关机in-place但仍建议对关键业务 VM 做快照OEM iDRAC 配置导出便于回滚3.2 第二步安装上一个 Feature Build 的最后 CumulativeBefore installing the feature update, make sure to install the last released cumulative update.举例从 2602 升 2603 之前先确认已装 12.2602.1002.5012602 最后 Cumulative。判断方法Get-SolutionUpdate | Where-Object { $_.State -eq Installed } | Select Version, State3.3 第三步解决 readiness check 的同名重复问题When you view the readiness check results for an Azure Local instance via the Azure Update Manager, there might be multiple readiness checks with the same name. Theres no known workaround in this release.2606 仍没有 fix这个 UI 问题。处理方式不被同名检查项困扰点 View details 看具体内容不要因为看到多个同名 Failed就判定升级失败——具体看每个 View details 的失败原因3.4 第四步在 Azure Update Manager 中执行 Feature Update操作步骤Azure Portal → Azure Arc → Azure Local → 集群Updates → 检查 2606 是否 available若未 available等 OEM SBE 适配完成Readiness check 全 Pass 后点击 Install不要在更新过程中同时跑其他工作流add node / repair node / new VM deploy3.5 第五步升级后验证见第四节四、升级后必须验证的 4 件事4.1 验证 Solution 版本与 OS BuildGet-SolutionUpdate | Where-Object { $_.State -eq Installed } | Select Version, State # 期望12.2606.1003.205 # 在每个节点上 Get-ComputerInfo | Select WindowsProductName, WindowsVersion, OsBuildNumber # 期望26100.329954.2 验证 .NET RuntimeGet-ChildItem C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Select Name # 期望看到 8.0.28 10.0.94.3 验证已知修复验证项操作期望NIC 创建/删除 tenant logical network IP pool 重叠创建 IP pool 与 infra logical network 重叠的 tenant logical network不再被阻断startup memory / vCPU 外部修改回滚在 Azure 外部修改 VM startup memory 后看 sync 行为不再回滚到旧配置4.4 验证 Update workflowAzure Portal → Azure Local → Updates检查 2606 显示为 Installed如果 Portal 显示 Failed to update / In progress 但实际已完成# 远程 PowerShell 连接到集群 $Update Get-SolutionUpdate | Where-Object { $_.Version -eq 12.2606.1003.205 } $Update.State # 期望Installed # 强制 Portal 刷新在其中一个节点上 Stop-ClusterGroup Cloud Management Start-ClusterGroup Cloud ManagementIf the update status is Installed, no further action is required. The Azure portal refreshes the status correctly within 24 hours.五、按场景分类的升级决策树5.1 场景 A当前 23H2OS 25398.xxxx当前11.xxxxOS 25398.xxxx ↓ Q: 11.2510.1002.93 或 12.2510.1002.94 是否已装 ├─ 是 → 直接跳 12.2606 └─ 否 → 必须先升到 11.2510.1002.93 → 12.2510 → 12.2511 → 12.2512 → 12.2601 → 12.2602 → ... → 12.26065.2 场景 B当前 24H2 早期2601 / 2602当前12.2601.x / 12.2602.x ↓ Q: AKS Arc 是否用 WS2019 node pool ├─ 是 → 先升 AKS Arc 到 WS2022/WS2025 node pool │ ↓ │ 再升 Azure Local 到 12.2606 └─ 否 → 直接升 12.2606中间 2603/2604/2605 由 Update Wizard 自动应用5.3 场景 C当前 2603 / 2604 / 2605当前12.2603.x / 12.2604.x / 12.2605.x ↓ Q: 是否在新功能使用上已经用上 2604 的 GA 项 ├─ 是 → 评估 2606 是否带来兼容性问题一般没有升到 2606 └─ 否 → 评估是否需要 2606 的修复NIC IP pool 重叠、startup memory sync ├─ 是 → 升到 2606 └─ 否 → 可走正常 Update cadence不必立即升5.4 场景 D使用 GPU-P / DDAQ: 现有 GPU 是否在 OEM 认证列表 ├─ 否 → 不要升 2606先解决硬件认证 └─ 是 → 升 2606 后用 GPU-P 指标监控验证2605 起 Azure Monitor 收录5.5 场景 E使用 Local Identity with Key VaultQ: 当前是否在 Local Identity KV 部署 ├─ 否 → 不影响 2606 升级2604 已经 GA └─ 是 → 升级后验证 Key Vault 访问策略未变轮换策略仍生效六、回滚策略与边界6.1 升级可以回滚吗Azure Local 升级是单向的 in-place 操作没有撤销按钮。可回滚的边界配置变更可由备份恢复VM 数据可由 VM 快照恢复升级前做的快照集群拓扑升级后不可降级到 23H26.2 如果升级失败怎么办来自 Known issues失败场景微软建议更新状态 Portal 显示 Failed用 PowerShell 验证$Update.State重启 Cloud Management 集群组强制刷新Readiness check 失败不要直接放弃——先看具体 View details可能是 Defendder ASR / Mochostagent 卡死Mochostagent 卡死restart-service mochostagentDefender Restrict App Execution 导致失败禁用该设置 rebootDefender ASR 阻止 PSExec WMI参考 TSGARC registration exitcode: 42参考 TSG6.3 OEM Support 的回滚路径如果升级触发 OEM SBE 兼容问题联系 OEM Support 提供 Solution Builder Extension logsOEM 可能推送 SBE hotfix在 Solution Update 之外的独立补丁极端情况OEM 可能建议保持上一版 Solution Update 不动直到 hotfix 发布七、2606 仍未解决的已知 / 预期行为这部分是客户做架构决策时必须知道的已知系统行为不是 Bug但会影响运营Feature行为影响Operating System使用RegBack恢复 registry不支持——会移除 LCM 与 MOC 设置损坏方案绝对不要用 RegBack 做 Azure Local 的 registry 备份恢复来自 Known and expected behaviorsRestoring the registry by using RegBack isnt supported on Azure Local. This operation can remove the Lifecycle Manager (LCM) and Microsoft On-premises Cloud (MOC) settings on your Azure Local instance, which can corrupt the solution.八、推荐升级窗口基于微软 6 个月规则起点 Release直跳 2606 的最迟合规日期计算方式12.2602首次发布 2026-02-172026-08-17起点 6 个月12.2603首次发布 2026-03-172026-09-17起点 6 个月12.2604首次发布 2026-04-222026-10-22起点 6 个月12.2605首次发布 2026-05-282026-11-28起点 6 个月11.2510首次发布 2025-10-2423H2 终版2026-04 进入生命周期末期23H2 整条线进入末期强烈建议不要等到最迟日期才升级。预留 2~4 周的测试窗口在预生产集群上验证避免生产环境踩坑。关于23H2 已 EOL 的措辞本文严格采用微软官方原文reached end of support in April 2026的措辞Solution 支持层面避免在公开文章里写23H2 OS 已完全终止支持——后者容易在客户支持对话中引发争议且与 Azure Local Solution Support Lifecycle 与 Windows Server OS Servicing Lifecycle 两个独立但相互关联的体系不完全等价。九、本篇核心 takeaway2602 直跳 2606 在 6 个月窗口内合规——2026-08-17 是硬截止日。Azure Stack HCI 23H2 OSOS Build 25398.xxxx已进入生命周期末期24H2OS Build 26100.xxxx与 Windows Server 2025 24H2 系列 Build Number 一致成为当前主支持版本——仍在 23H2 的客户必须启动 24H2 迁移。升级前必须做 7 项检查特别关注 OEM SBE、AKS Arc WS2019 EOL、SAN 依赖、Defender 配置。升级中按 5 步顺序执行关键是先装上一个 Cumulative Build、再升 Feature。升级后用 PowerShell 验证 Solution 版本与 OS BuildPortal 状态可能滞后 24 小时。Azure Local 升级不可回滚——做好升级前快照但集群拓扑不可降级。附录 C · 升级检查清单可打印升级前7 项 [ ] 1. OEM SBE 适配状态2606 是否在 OEM 支持矩阵 [ ] 2. AKS Arc K8s 版本 node pool OS不能是 WS2019 [ ] 3. 当前 Solution 版本 OS Build [ ] 4. 外部 SAN 依赖FC / iSCSI [ ] 5. GPU 部署计划DDA / GPU-P / 型号 [ ] 6. Local Identity with KV如适用 [ ] 7. Defender 配置Restrict App Execution / ASR PSExec WMI 规则 升级中5 步 [ ] 1. 备份 VM 快照 iDRAC 配置导出 [ ] 2. 装上一个 Feature Build 的最后 Cumulative [ ] 3. 解决 readiness check 同名重复问题 [ ] 4. Azure Update Manager 执行 Feature Update [ ] 5. 升级后验证 升级后4 项 [ ] 1. Get-SolutionUpdate 验证 12.2606.1003.205 Installed [ ] 2. Get-ComputerInfo 验证 OS 26100.32995 [ ] 3. .NET 8.0.28 10.0.9 路径验证 [ ] 4. 已知修复验证NIC IP pool / startup memory sync 升级后已知未修复持续监控 [ ] Mochostagent 卡死一个月未更新日志→ restart-service [ ] Update 状态 Portal 误报 → 用 PowerShell 验证实际状态 [ ] WAC Cluster Manager 扩展 5.2.6 → 升级到 2511 build 2.6.6.18 [ ] Defender Restrict App Execution → 禁用 reboot [ ] Defender ASR Block PSExec WMI → 配置例外附录 D · 参考链接类别链接Whats new 2606Whats new in Hyperconverged Deployments of Azure Local latest release - Azure Local | Microsoft LearnRelease informationAzure Local release information - Azure Local | Microsoft LearnKnown issuesRelease notes with fixed and known issues in Azure Local - Azure Local | Microsoft LearnOverviewWhat Is Azure Local? Overview and Key Benefits - Azure Local | Microsoft LearnAzure Local Supportabilityhttps://github.com/Azure/AzureStackHCI-SupportabilityAzure Local CatalogOEM 认证https://aka.ms/AzureStackHCICatalogDisaggregated deploymentOverview of Disaggregated Deployments for Azure Local - Azure Local | Microsoft LearnSAN storageEnable External Storage on Azure Local - Azure Local | Microsoft LearnLocal identity with Key VaultDeploy Azure Local Using Local Identity with Azure Key Vault - Azure Local | Microsoft LearnDrift detectionDrift Detection for Azure Local - Azure Local | Microsoft LearnGPU preparationPrepare GPUs for Azure Local instance - Azure Local | Microsoft LearnGPU metricshttps://learn.microsoft.com/en-us/azure/azure-local/manage/monitor-cluster-with-metrics#metrics-for-gpuSecure Boot updatesManage Secure Boot Updates - Azure Local | Microsoft LearnSimplified machine provisioninghttps://learn.microsoft.com/en-us/azure/azure-local/deploy/simplified-machine-provisioningSecurity baselinehttps://learn.microsoft.com/en-us/azure/azure-local/manage/manage-secure-baseline文档维护本文以微软 Learn 当前版本azloc-2606为准。请以官方页面为最终事实。
Azure Local 2606 Release 解读(2602→2606 演进与升级价值·下篇):升级路径与实战清单
未经同意请勿转载适用版本Azure Local 12.2602.1002.5012602 → 12.2606.1003.2052606文档来源Whats new in Azure Local / Release information / Known issues / AzureStackHCI-Supportability维护版本v1.1 · 2026-07-21 · ACP 评审修订版TL;DR2602 直跳 2606 在微软 6 个月支持窗口内完全合规但中间会一次性带入 2604 那一波 GA 项升级前必须做兼容性评估特别是 AKS Arc node pool / OEM SBE / 外部 SAN。Azure Stack HCI 23H2 OSOS Build 25398.xxxx已进入生命周期末期Azure Local 24H2OS Build 26100.xxxx与 Windows Server 2025 24H2 系列 Build Number 一致成为当前主支持版本——任何仍在 23H2 的客户应当把升 24H2 当作当下最重要的版本任务。升级路径不是线性的必须先升到上一个 Cumulative Build再升 Feature Build跳过中间的 Cumulative 直接升 Feature 是微软不推荐的做法。本篇给出可直接执行的实战清单升级前的 7 项检查、升级中的 5 步顺序、升级后的 4 项验证以及一份按场景分类的升级决策树。一、升级路径全景图1.1 微软的硬性升级路径规则来自 Release informationTo keep your Azure Local solution in a supported state, you have up to six months to install updates. However, before installing the feature update, make sure to install the last released cumulative update.Before you can update to the 2511 release, you must first apply the 12.2510 update. The 12.2510 (24H2) update becomes automatically available once you apply 11.2510.也就是说维度规则Feature Build 升级前必须先装上一个 Feature Build 的最后一个 Cumulative Build从 23H2 升 24H2必须先升 11.2510再升 12.2510才能进 24H2 主线跳过中间 Cumulative微软不推荐可能触发 SBE manifest 校验失败6 个月支持窗口超过 6 个月未更新 不受支持1.2 两条主线的推荐升级路径A. 仍在 23H211.xxxx 系列OS 25398.xxxx的客户推荐路径合规且最稳 11.2503 → 11.2504 → 11.2505 → 11.2506 → 11.2507 → 11.2508 → 11.2509 → 11.2510 ↓ └→ 12.2510 → 12.2511 → 12.2512 → 12.2601 → 12.2602 → ... → 12.2606 ↑ 注意23H2 已进入生命周期末期必须尽快迁到 24H2紧急路径生产已被 23H2 EOL 风险暴露但仍想保留 HCI 形态 直接升 11.2510 → 12.2510 → ... → 12.2606。微软允许从 23H2 的最终 Cumulative Build11.2510.1002.93跨到 12.x但必须先升到 11.2510。B. 已在 24H212.xxxx 系列OS 26100.xxxx的客户推荐路径以 2602 为例 12.2602 → 12.2602.x最后 Cumulative→ 12.2603 → 12.2603.x → ... → 12.2606 更精简的合规直跳路径仍在 6 个月窗口内 12.2602 → 12.2603 → 12.2604 → 12.2605 → 12.2606 中间 Cumulative 由 Update Wizard 自动应用**前提是 OEM SBE 允许**1.3 容易踩的坑坑说明跳过中间的 Cumulative 直接装 Feature可能触发 SBE manifest 校验失败已知 warning 级 error SBE manifest endpoint not reported by Get-SolutionDiscoveryDiagnosticInfo使用被召回的 11.2510.1002.87 / 12.2510.1002.88 镜像add node / repair node 会失败必须先升到 .93 / .94Azure Arc resource bridge 超 1 年未升级证书失效、Azure Local VM 功能异常Defender for Endpoint 启用了 Restrict App ExecutionUpdate / Repair 失败Defender ASR 规则阻止 PSExec WMISolution Update 失败二、升级前必须检查的 7 件事2.1 OEM Solution Builder ExtensionSBE状态If your cluster supports Solution Builder Extension software updates, you receive feature release updates after your hardware vendor completes their validation and confirms the release is ready. This process typically takes a few weeks following the Microsoft release and varies by hardware vendor.为什么这件事排在第一微软每个月 release 后OEM 还要做 SBE 适配验证验证完成前 SBE 不会推送。客户在 Azure Update Manager 里看不到 2606 不代表集群落后可能是 OEM 还在验证。检查方式Azure Update Manager → Cluster → Readiness checks / Available updates与 OEM Support 确认 2606 SBE 适配时间表2.2 AKS Arc 集群的 K8s 版本与 node pool OS检查项要求K8s 版本在 1.31.12 ~ 1.33.5 之间2606 支持矩阵WS2019 node pool必须在升级前迁移到 WS2022 / WS2025——WS2019 SKU 在 2603 已完全 EOLKMS 配置评估是否要迁到 KMS v2v1 弃用倒计时关键原则升 Azure Local 之前先把 AKS Arc 升到受支持的 K8s 受支持的 node pool OS。否则升 Azure Local 后 AKS Arc 会进入不可用状态。2.3 集群当前 Solution 版本与 OS Build确认起点如果在 2601 / 2602需要注意 MOC 误删 VM 漏洞——升级前应用 Remediation Support Tool如果在 11.xxxx23H2需要先升 11.2510 再跨 12.x如果在 10.xxxx旧 23H2 终端需要先升 11.x2.4 外部存储SAN依赖检查项说明是否使用 FC SAN2604 GAiSCSI 仍在 preview存储 vendor 是否在 Azure Local 支持矩阵微软只认证特定 vendoriSCSI 流量隔离网络iSCSI SAN 需要独立网络2.5 GPU 部署计划检查项说明现有 GPU 型号在 OEM SKU 认证列表内RTX PRO 6000 Blackwell 是 2603 起支持计划用 DDA 还是 GPU-P决策影响 GPU 切分策略、监控告警设置Day-2 热操作是否需要2604 起支持热挂 / 热卸载2.6 Local Identity with Key Vault仅限气隙 / 弱连接客户检查项说明客户是否已部署 Key VaultKey Vault 必须可访问轮换策略已就绪Rack-aware 集群是否计划用 Local Identity2604 起支持 Rack-aware Local Identity 组合哪些 Azure 服务还依赖 Azure AD参考 Generally available or supported services2.7 Defender for Endpoint / Defender ASR 配置检查项说明Restrict App Execution是否启用必须禁用否则 Update / Repair 失败Block Process Creations originating from PSExec WMI不能 Block否则 Solution Update 失败参考 TSG三、升级中5 步推荐顺序3.1 第一步备份与快照虽然 Azure Local 升级是 in-place但强烈建议做以下备份配置备份通过 Azure portal 或 PowerShell 导出集群配置关键 VM 快照Azure Local VM 在升级前不需要关机in-place但仍建议对关键业务 VM 做快照OEM iDRAC 配置导出便于回滚3.2 第二步安装上一个 Feature Build 的最后 CumulativeBefore installing the feature update, make sure to install the last released cumulative update.举例从 2602 升 2603 之前先确认已装 12.2602.1002.5012602 最后 Cumulative。判断方法Get-SolutionUpdate | Where-Object { $_.State -eq Installed } | Select Version, State3.3 第三步解决 readiness check 的同名重复问题When you view the readiness check results for an Azure Local instance via the Azure Update Manager, there might be multiple readiness checks with the same name. Theres no known workaround in this release.2606 仍没有 fix这个 UI 问题。处理方式不被同名检查项困扰点 View details 看具体内容不要因为看到多个同名 Failed就判定升级失败——具体看每个 View details 的失败原因3.4 第四步在 Azure Update Manager 中执行 Feature Update操作步骤Azure Portal → Azure Arc → Azure Local → 集群Updates → 检查 2606 是否 available若未 available等 OEM SBE 适配完成Readiness check 全 Pass 后点击 Install不要在更新过程中同时跑其他工作流add node / repair node / new VM deploy3.5 第五步升级后验证见第四节四、升级后必须验证的 4 件事4.1 验证 Solution 版本与 OS BuildGet-SolutionUpdate | Where-Object { $_.State -eq Installed } | Select Version, State # 期望12.2606.1003.205 # 在每个节点上 Get-ComputerInfo | Select WindowsProductName, WindowsVersion, OsBuildNumber # 期望26100.329954.2 验证 .NET RuntimeGet-ChildItem C:\Program Files\dotnet\shared\Microsoft.NETCore.App | Select Name # 期望看到 8.0.28 10.0.94.3 验证已知修复验证项操作期望NIC 创建/删除 tenant logical network IP pool 重叠创建 IP pool 与 infra logical network 重叠的 tenant logical network不再被阻断startup memory / vCPU 外部修改回滚在 Azure 外部修改 VM startup memory 后看 sync 行为不再回滚到旧配置4.4 验证 Update workflowAzure Portal → Azure Local → Updates检查 2606 显示为 Installed如果 Portal 显示 Failed to update / In progress 但实际已完成# 远程 PowerShell 连接到集群 $Update Get-SolutionUpdate | Where-Object { $_.Version -eq 12.2606.1003.205 } $Update.State # 期望Installed # 强制 Portal 刷新在其中一个节点上 Stop-ClusterGroup Cloud Management Start-ClusterGroup Cloud ManagementIf the update status is Installed, no further action is required. The Azure portal refreshes the status correctly within 24 hours.五、按场景分类的升级决策树5.1 场景 A当前 23H2OS 25398.xxxx当前11.xxxxOS 25398.xxxx ↓ Q: 11.2510.1002.93 或 12.2510.1002.94 是否已装 ├─ 是 → 直接跳 12.2606 └─ 否 → 必须先升到 11.2510.1002.93 → 12.2510 → 12.2511 → 12.2512 → 12.2601 → 12.2602 → ... → 12.26065.2 场景 B当前 24H2 早期2601 / 2602当前12.2601.x / 12.2602.x ↓ Q: AKS Arc 是否用 WS2019 node pool ├─ 是 → 先升 AKS Arc 到 WS2022/WS2025 node pool │ ↓ │ 再升 Azure Local 到 12.2606 └─ 否 → 直接升 12.2606中间 2603/2604/2605 由 Update Wizard 自动应用5.3 场景 C当前 2603 / 2604 / 2605当前12.2603.x / 12.2604.x / 12.2605.x ↓ Q: 是否在新功能使用上已经用上 2604 的 GA 项 ├─ 是 → 评估 2606 是否带来兼容性问题一般没有升到 2606 └─ 否 → 评估是否需要 2606 的修复NIC IP pool 重叠、startup memory sync ├─ 是 → 升到 2606 └─ 否 → 可走正常 Update cadence不必立即升5.4 场景 D使用 GPU-P / DDAQ: 现有 GPU 是否在 OEM 认证列表 ├─ 否 → 不要升 2606先解决硬件认证 └─ 是 → 升 2606 后用 GPU-P 指标监控验证2605 起 Azure Monitor 收录5.5 场景 E使用 Local Identity with Key VaultQ: 当前是否在 Local Identity KV 部署 ├─ 否 → 不影响 2606 升级2604 已经 GA └─ 是 → 升级后验证 Key Vault 访问策略未变轮换策略仍生效六、回滚策略与边界6.1 升级可以回滚吗Azure Local 升级是单向的 in-place 操作没有撤销按钮。可回滚的边界配置变更可由备份恢复VM 数据可由 VM 快照恢复升级前做的快照集群拓扑升级后不可降级到 23H26.2 如果升级失败怎么办来自 Known issues失败场景微软建议更新状态 Portal 显示 Failed用 PowerShell 验证$Update.State重启 Cloud Management 集群组强制刷新Readiness check 失败不要直接放弃——先看具体 View details可能是 Defendder ASR / Mochostagent 卡死Mochostagent 卡死restart-service mochostagentDefender Restrict App Execution 导致失败禁用该设置 rebootDefender ASR 阻止 PSExec WMI参考 TSGARC registration exitcode: 42参考 TSG6.3 OEM Support 的回滚路径如果升级触发 OEM SBE 兼容问题联系 OEM Support 提供 Solution Builder Extension logsOEM 可能推送 SBE hotfix在 Solution Update 之外的独立补丁极端情况OEM 可能建议保持上一版 Solution Update 不动直到 hotfix 发布七、2606 仍未解决的已知 / 预期行为这部分是客户做架构决策时必须知道的已知系统行为不是 Bug但会影响运营Feature行为影响Operating System使用RegBack恢复 registry不支持——会移除 LCM 与 MOC 设置损坏方案绝对不要用 RegBack 做 Azure Local 的 registry 备份恢复来自 Known and expected behaviorsRestoring the registry by using RegBack isnt supported on Azure Local. This operation can remove the Lifecycle Manager (LCM) and Microsoft On-premises Cloud (MOC) settings on your Azure Local instance, which can corrupt the solution.八、推荐升级窗口基于微软 6 个月规则起点 Release直跳 2606 的最迟合规日期计算方式12.2602首次发布 2026-02-172026-08-17起点 6 个月12.2603首次发布 2026-03-172026-09-17起点 6 个月12.2604首次发布 2026-04-222026-10-22起点 6 个月12.2605首次发布 2026-05-282026-11-28起点 6 个月11.2510首次发布 2025-10-2423H2 终版2026-04 进入生命周期末期23H2 整条线进入末期强烈建议不要等到最迟日期才升级。预留 2~4 周的测试窗口在预生产集群上验证避免生产环境踩坑。关于23H2 已 EOL 的措辞本文严格采用微软官方原文reached end of support in April 2026的措辞Solution 支持层面避免在公开文章里写23H2 OS 已完全终止支持——后者容易在客户支持对话中引发争议且与 Azure Local Solution Support Lifecycle 与 Windows Server OS Servicing Lifecycle 两个独立但相互关联的体系不完全等价。九、本篇核心 takeaway2602 直跳 2606 在 6 个月窗口内合规——2026-08-17 是硬截止日。Azure Stack HCI 23H2 OSOS Build 25398.xxxx已进入生命周期末期24H2OS Build 26100.xxxx与 Windows Server 2025 24H2 系列 Build Number 一致成为当前主支持版本——仍在 23H2 的客户必须启动 24H2 迁移。升级前必须做 7 项检查特别关注 OEM SBE、AKS Arc WS2019 EOL、SAN 依赖、Defender 配置。升级中按 5 步顺序执行关键是先装上一个 Cumulative Build、再升 Feature。升级后用 PowerShell 验证 Solution 版本与 OS BuildPortal 状态可能滞后 24 小时。Azure Local 升级不可回滚——做好升级前快照但集群拓扑不可降级。附录 C · 升级检查清单可打印升级前7 项 [ ] 1. OEM SBE 适配状态2606 是否在 OEM 支持矩阵 [ ] 2. AKS Arc K8s 版本 node pool OS不能是 WS2019 [ ] 3. 当前 Solution 版本 OS Build [ ] 4. 外部 SAN 依赖FC / iSCSI [ ] 5. GPU 部署计划DDA / GPU-P / 型号 [ ] 6. Local Identity with KV如适用 [ ] 7. Defender 配置Restrict App Execution / ASR PSExec WMI 规则 升级中5 步 [ ] 1. 备份 VM 快照 iDRAC 配置导出 [ ] 2. 装上一个 Feature Build 的最后 Cumulative [ ] 3. 解决 readiness check 同名重复问题 [ ] 4. Azure Update Manager 执行 Feature Update [ ] 5. 升级后验证 升级后4 项 [ ] 1. Get-SolutionUpdate 验证 12.2606.1003.205 Installed [ ] 2. Get-ComputerInfo 验证 OS 26100.32995 [ ] 3. .NET 8.0.28 10.0.9 路径验证 [ ] 4. 已知修复验证NIC IP pool / startup memory sync 升级后已知未修复持续监控 [ ] Mochostagent 卡死一个月未更新日志→ restart-service [ ] Update 状态 Portal 误报 → 用 PowerShell 验证实际状态 [ ] WAC Cluster Manager 扩展 5.2.6 → 升级到 2511 build 2.6.6.18 [ ] Defender Restrict App Execution → 禁用 reboot [ ] Defender ASR Block PSExec WMI → 配置例外附录 D · 参考链接类别链接Whats new 2606Whats new in Hyperconverged Deployments of Azure Local latest release - Azure Local | Microsoft LearnRelease informationAzure Local release information - Azure Local | Microsoft LearnKnown issuesRelease notes with fixed and known issues in Azure Local - Azure Local | Microsoft LearnOverviewWhat Is Azure Local? Overview and Key Benefits - Azure Local | Microsoft LearnAzure Local Supportabilityhttps://github.com/Azure/AzureStackHCI-SupportabilityAzure Local CatalogOEM 认证https://aka.ms/AzureStackHCICatalogDisaggregated deploymentOverview of Disaggregated Deployments for Azure Local - Azure Local | Microsoft LearnSAN storageEnable External Storage on Azure Local - Azure Local | Microsoft LearnLocal identity with Key VaultDeploy Azure Local Using Local Identity with Azure Key Vault - Azure Local | Microsoft LearnDrift detectionDrift Detection for Azure Local - Azure Local | Microsoft LearnGPU preparationPrepare GPUs for Azure Local instance - Azure Local | Microsoft LearnGPU metricshttps://learn.microsoft.com/en-us/azure/azure-local/manage/monitor-cluster-with-metrics#metrics-for-gpuSecure Boot updatesManage Secure Boot Updates - Azure Local | Microsoft LearnSimplified machine provisioninghttps://learn.microsoft.com/en-us/azure/azure-local/deploy/simplified-machine-provisioningSecurity baselinehttps://learn.microsoft.com/en-us/azure/azure-local/manage/manage-secure-baseline文档维护本文以微软 Learn 当前版本azloc-2606为准。请以官方页面为最终事实。