Insights

The Azure trial that starts charging when the reminder disappears

Azure SRE Agent’s 30-day trial reached general availability on 26 August 2026, waiving the always-on charge. Microsoft’s own pricing page sets that charge at 4 Azure Agent Units per agent-hour, running from creation until the agent is deleted. Stopping the agent does not stop it. On day 31 always-on billing starts automatically unless the agent has been deleted, and the portal banner that counts the trial down disappears at that moment.

What changed

Microsoft announced on 26 August 2026 that the Azure SRE Agent 30-day trial is generally available, stating that customers can explore the service “without baseline always-on charges” and pay “only for Azure Agent Units (AAUs) consumed when agents perform work”. On the same day it announced that SRE Agent VNet Integration reached general availability, which Microsoft states lets the agent “securely access private resources, including services behind private endpoints, during incident investigation and remediation without requiring changes to your network boundary”. The evaluation page, updated 25 August 2026, sets out the trial terms: eligibility is “Azure customers without an SRE Agent as of Aug 25, 2026”; the allowance is “Three agents per customer, including deleted agents”; each agent carries its own 30-day window from its own creation; and “Thirty days after you create the agent, the always-on billing starts automatically unless you delete the agent”. The pricing page, updated the same day, states the always-on rate as 4 AAUs per agent-hour and that “Always-on billing continues from agent creation until the agent is deleted”.

The operational risk is easy to miss because the service can continue to look healthy. The control becomes visible only when a capacity request fails, an unsupported runtime is removed, or an extension blocks an enforced ERP update. Waiting for that moment transfers a planned decision into an incident.

What the term means in plain language

Azure SRE Agent is an agentic service that connects to monitoring, incident and source-control systems, investigates alerts and proposes mitigations. Microsoft states that “The agent proposes changes and your team approves. No change deploys without human sign-off.” An Azure Agent Unit, or AAU, is Microsoft’s standardised measure of agentic processing, used across its prebuilt Azure agents. Microsoft bills two kinds of AAU consumption: an always-on flow for keeping an agent provisioned and available, and an active flow for the work it actually does.

This distinction matters because product status is not the same as business readiness. Availability, support and compatibility are separate questions. A service can be available but unsupported, supported but capacity-constrained, or technically updated while a customer-specific process has stopped working.

Why this matters to a South African organisation

South African teams often operate with tight specialist capacity, rand-sensitive budgets and business processes that cannot be paused while a replacement is sourced. Localisation, regional cloud capacity and long procurement lead times can narrow the recovery options. The practical response is to use the available test window before it becomes an emergency window.

The consequence belongs to the business process, not only the technology team. Finance month-end, customer transactions, data pipelines and ERP extensions all cross technical and operational ownership. A change should therefore be accepted only when the service owner and the business owner can see the same evidence.

The hidden exposure

Azure SRE Agent’s 30-day trial reached general availability on 26 August 2026, waiving the always-on charge. Microsoft’s own pricing page sets that charge at 4 Azure Agent Units per agent-hour, running from creation until the agent is deleted. Stopping the agent does not stop it. On day 31 always-on billing starts automatically unless the agent has been deleted, and the portal banner that counts the trial down disappears at that moment.

Normal operation is weak evidence. It proves only that yesterday’s combination of platform, configuration and workload completed. It does not prove that the next capacity allocation, lifecycle enforcement or major release will preserve the same result. An owner needs an inventory, a representative test and a dated decision.

Decision path

The announcement is accurate and the pricing page is not hiding anything. They simply answer different questions, and the one that matters after the demo is over is only answered on the second page. Three things there are worth knowing before an agent is created rather than after. Stopping is not deleting: Microsoft’s own billing table shows a stopped agent halting active flow while always-on remains “Still billed”, and states plainly that to stop all billing you delete the agent. A monthly spend limit does not contain this either, because when the active flow limit is reached the agent becomes unavailable for chat and actions while “Always-on charges continue for the rest of the month”, and a reduction to the allocation only takes effect the following month. And the reminder is the part that reads oddly on the page: Microsoft states the trial countdown banner “disappears when always-on billing begins on the 31st day of the agent’s existence”. The signal that the meter has started is the removal of the thing that was warning you about it. Braintree’s arithmetic on Microsoft’s own two tables, not Microsoft’s claim: 4 AAUs per agent-hour is 96 AAUs across a day, while the pricing page’s own worked example puts a full “Diagnose and fix the failing deployment” at about 86.5 AAUs on Claude Opus 4.6. An idle agent left running for a day therefore costs more than one complete remediation. We give this in AAUs rather than in rands deliberately, because Microsoft publishes the rate structure in AAUs and directs customers to the regional pricing calculator for currency; converting it here would be inventing a figure. None of this argues against the evaluation, which is genuinely free of the fixed charge for thirty days and has no feature limitations. It argues for the delete-by date being written down by a person on day one.

Record the alternatives that were rejected and why. That prevents the next reviewer from reopening the entire question without context. Where the preferred path cannot be completed inside seven days, approve a time-bound exception with a responsible owner, expiry date and compensating control.

Technical test plan

Plan the evaluation before creating the agent, because the clock starts at creation and not at first use. Microsoft’s own suggested uses give a reasonable shape: run a root cause investigation across alerts, logs, metrics and recent deployments; point the agent at failed pipelines; trigger an investigation from Azure Monitor, PagerDuty or ServiceNow; and run scheduled health checks. Decide which of those the evaluation must answer, and give each a date inside the window. Track consumption as you go under Settings then Agent consumption, which shows the monthly AAU limit, total and daily active flow consumption, and a per-thread table. A monthly active flow limit can be set from Change AAU allocation, with a minimum of 500 and a maximum of 1,000,000 AAUs, but understand what it does and does not do before relying on it: it caps active flow only, increases take effect immediately while decreases take effect next month, and always-on charges continue regardless. Two governance points belong in the same decision. Creating an agent also creates an Application Insights resource, a Log Analytics workspace and a managed identity in the subscription, so the agent is not the only thing that appears. And on what the agent may do, read Microsoft’s two statements together rather than separately: the note that “SRE Agent proposes mitigations but doesn’t apply them without human approval”, and the description of the permission gate as a layer where “Operators can require human approval, enforce policy rules, or block disallowed operations”. Alongside those sits the statement that any Azure CLI operation can be automated through runbooks, subagents and agent hooks. Establish the gate’s configuration and the managed identity’s role assignments explicitly during the evaluation, and route the audit telemetry to your own Application Insights instance, which Microsoft supports. Microsoft’s own caution is worth keeping in view: “As with any AI system, SRE Agent might occasionally produce incorrect conclusions or propose mitigations that don’t apply to your environment. Always review proposed actions before approving.”

Use production-representative conditions without exposing production data unnecessarily. Capture the starting configuration, exact version, time of test and expected result. A pass requires evidence from the real workflow, not only a successful login or an unchanged dashboard.

Primary owner

Primary owner: Whoever is accountable for the Azure subscription’s spend, jointly with the operations or platform lead who would run the evaluation.

The named owner coordinates platform, application, commercial and business-process decisions. Contributors may perform the work, but accountability cannot be distributed across a meeting invite. The owner closes the test, exception and evidence record.

Action within seven days

Action within seven days: If anyone starts an SRE Agent trial this week, record the delete-by date the same day, in a calendar with an owner rather than in a portal banner. Decide in advance what the evaluation has to prove in thirty days, and know before you begin that stopping the agent is not the same as deleting it. If the evaluation is inconclusive at day 29, the default is deletion, because the trial allowance is three agents per customer including deleted ones.

Start with the highest-consequence workload. Assign the people, date and pass criteria before the test begins. If the first test fails, record the failure as evidence and open remediation with a deadline rather than hiding it behind a general project status.

Evidence to retain

Evidence to retain: The dated record of each agent created, with its creation date, its calculated day-31 date, the named owner of that date, and the disposition at the end of the evaluation. Retain the AAU consumption report from Settings then Agent consumption for the trial period, and the Azure Cost Management view for the subscription covering the month after it.

Store the evidence with the platform or change record. Include source exports and machine-readable results where possible. The next reviewer should be able to reproduce the conclusion without rebuilding it from email, chat or memory.

Frequently asked questions

What is actually free during the trial?

The always-on charge. Microsoft states the 30-day trial waives baseline always-on AAU costs, while consumption charges still apply for the work the agent does. There are no feature limitations during the trial period.

What happens on day 31?

Microsoft states that thirty days after you create the agent, always-on billing starts automatically unless you delete the agent. The portal banner showing the time remaining disappears when that billing begins.

Can I just stop the agent instead of deleting it?

No, not for billing purposes. Microsoft’s billing table shows that stopping an agent halts active flow while always-on continues to be billed, and states that to stop all billing entirely you delete the agent.

Will a spending limit protect me?

Only partly. The limit applies to active flow. Microsoft states that when the limit is reached the agent becomes unavailable for chat and actions while always-on charges continue for the rest of the month, and that decreases to the allocation take effect the following month.

How much is an AAU in rands?

Microsoft publishes the AAU rate structure but directs customers to the Azure pricing calculator for pricing in their region, so we do not quote a currency figure here. What can be stated from Microsoft’s tables is the relationship: the always-on rate is 4 AAUs per agent-hour, which is 96 AAUs a day, against Microsoft’s own worked example of about 86.5 AAUs for a full diagnose-and-fix task on Claude Opus 4.6. That comparison is our arithmetic on their figures.

Who is eligible, and for how many agents?

Microsoft states eligibility is Azure customers without an SRE Agent as of 25 August 2026, and the allowance is three agents per customer, including deleted agents. Each agent has its own 30-day window from its own creation.

What did VNet integration change?

It reached general availability on the same day. Microsoft states it lets the agent operate within existing network controls and securely access private resources, including services behind private endpoints, during investigation and remediation, without requiring changes to the network boundary.

Can the agent change things by itself?

Microsoft states that the agent proposes changes and a human approves, and that no change deploys without human sign-off. It also describes a permission gate that operators configure, and states that any Azure CLI operation can be automated through runbooks, subagents and hooks. The practical step is to confirm how that gate is configured and what the agent’s managed identity is scoped to, rather than to assume either.

The Braintree view

Microsoft’s announcement supplies the platform fact. The customer control begins after that fact: identify the exposed process, name the owner, test the real dependency and retain a decision that can survive audit or staff turnover. Braintree can help structure the inventory, build the representative test and translate the result into a controlled implementation plan.

Use the seven-day action as the entry point. Do not wait for a renewal, support refusal or enforced update to reveal work that can be measured now.

 

Download your copy of the Insights

Related Posts

Azure Firewall auto-learn SNAT routes reached general availability...
On 1 September 2026 Microsoft made two Azure...
Microsoft Threat Intelligence published research on 1 September...