Governance

Azure Blueprints retires on 31 January 2027: dates, impact and how to migrate

The phased shutdown has already started. Here are the four dates that matter, what happens to your resources and locks, and how to move to Deployment Stacks.

By Vikas Garg · 7 min read · Updated 8 October 2026

Azure Blueprints (Preview) is being retired, and this time the shutdown is phased. The first restriction is already live, and the next one lands on 31 October 2026. If your landing zones or subscription baselines were built with Blueprints, the time to plan the move is now.

The four dates that matter

Microsoft first announced the retirement on 14 September 2023 with an end date of 11 July 2026. That was extended to 31 January 2027, with restrictions switching on in stages. (Microsoft Learn)

DateWhat changes
31 July 2026 (already in effect)You can no longer create new blueprint definitions or versions.
31 October 2026Existing definitions can no longer be modified, and you can no longer create new blueprint assignments.
31 December 2026Existing blueprint assignments can no longer be modified.
31 January 2027Blueprints is retired. The API stops responding, Azure CLI and PowerShell commands stop working, and Blueprints is removed from the portal.

What happens on 31 January 2027

The lock change is the one that bites. If a production resource group is protected only by a blueprint lock, it becomes unprotected on retirement day, with no warning in the portal. Replace those locks before then.

Find out where you use Blueprints

What replaces it

Blueprints did two jobs. Microsoft has split them across two generally available features that you use together. (Microsoft Learn)

Blueprints conceptReplacement
Blueprint definition (stored, versioned artifacts)Template specs, or Bicep/ARM files in a Git repository
Blueprint assignment (deploy and manage as a unit)Azure Deployment Stacks (recommended)
Blueprint locksDeployment stack deny settings
Policy and role assignment artifactsPolicy and role assignment resources written in Bicep or ARM
Scope: subscription or management groupStacks work at resource group, subscription and management group scope

A migration checklist

  1. Inventory now. List every definition and assignment, its scope, and who owns it. Do this before 31 October, while you can still change things.
  2. Export everything you want to keep. Unexported definitions are deleted at retirement.
  3. Convert the artifacts to Bicep or ARM templates: policy assignments, role assignments and resource templates. Microsoft's migration guide walks through it.
  4. Store them as template specs, or in Git if you already review infrastructure changes through pull requests.
  5. Deploy them as deployment stacks at the same scope, with deny settings that match your old locks.
  6. Test in a non-production subscription first, then compare the result with the blueprint assignment it replaces.
  7. Update pipelines and runbooks that call az blueprint or Blueprint cmdlets.
  8. Remove the old assignments once the stacks are in place and verified. Do it before 31 December, when assignments freeze.

Need a hand?

Moving governance baselines safely is part of my Azure architecture consulting. If you'd rather learn it yourself, my upcoming short course Azure Policy & Governance in Practice covers policy, deny settings and deployment stacks.

Sources