Changelog

What's new in Locally

What's in each release of Locally - new features, improvements and fixes.

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

v2026.09.02

This release contains:

Bug Fixes

  • Event Hubs: improving behavioural consistency (fixing compatibility with the Azure SDK for Python, and returning the right errors when a management request names a missing event hub or partition).
  • Event Hubs: fixing an issue where deleting and then recreating an event hub would leave the old content around.
  • Function Apps: ensuring that Function Apps linked to an Application Insights component have the connection string set.
  • Function Apps: diagnostic settings now send Function App and authentication logs.
  • Logging: replaying a request now sends it to the same host as the original, so data-plane requests such as Storage reach the right account.
  • Managed HSM: fixing an issue where Terraform couldn't create local role assignments.
  • Managed HSM: allowing the rotation of the wrapping keys for an activated HSM's security domain.
  • Service Bus: improving behavioural consistency (fixing compatibility with the Azure SDKs for Python and .NET, and only accepting supported api-version values on the management API).
  • Service Bus: fixing a bug where disabling local authentication wasn't fully propagated, allowing SAS keys to continue authenticating.
  • Service Bus: fixing an issue where deleting and then recreating a queue, topic or subscription would leave the old content around.
  • Virtual Machines: fixing an issue where the Custom Script extension required files to download before it could run a script or command.
  • Web Apps: ensuring that Web Apps linked to an Application Insights component have the connection string set.
  • Web Apps: diagnostic settings now send HTTP, platform and authentication logs, not just console output.

v2026.09.01

This release contains:

Improvements

  • App Configuration: Improving behavioural consistency of key and label filters, snapshots and feature flags.
  • App Service Authentication: Now enforced for Web Apps, Function Apps and Container Apps, including Microsoft Entra sign-in, access tokens sent from code and the legacy authentication settings.
  • Application Insights: Telemetry can now be sent using a Microsoft Entra token.
  • Azure Cache for Redis: Surfacing the correct permissions when authenticating using a Microsoft Entra token.
  • Azure Monitor: Alerts now fire and resolve on their own schedule and cover many more services. Diagnostic settings can send to Storage and Event Hubs, and KQL supports many more operators and functions.
  • Container Apps: Authentication and CORS settings are now enforced.
  • Container Registry: az acr build and az acr run now build and push images. Improving behavioural consistency of scope maps and locked images.
  • Cosmos DB: Support for vector, full-text and hybrid search, transactional batches and bulk operations from the .NET SDK, and point-in-time restore. Items are now deleted when their time-to-live passes.
  • Event Grid: Event subscriptions on a resource, resource group or subscription now receive events, and Key Vault, Container Registry, IoT Hub, App Service and Service Bus now raise theirs. The MQTT broker now supports MQTT v5 and more ways to authenticate.
  • Event Hubs: Retention, compaction and a hub's status are now honoured, and consumers can start from a point in time.
  • Functions: Support for route templates, binding expressions, custom handlers (such as Go or Rust), remote builds, PowerShell, Java and poison queues.
  • IoT Hub: Devices on MQTT now receive cloud-to-device messages. Improving behavioural consistency of message expiry and dead-lettering.
  • Key Vault: Roles can now be assigned on a single secret, key or certificate, and deleted items are purged on their scheduled date. Managed HSM supports backup and restore.
  • Locally CI: Team runbooks can now be applied in CI by setting LOCALLY_CI_APPLY_RUNBOOKS=true.
  • locally run curl: Now sends the right token for the API being called, including Microsoft Graph, Storage and Key Vault.
  • Microsoft Entra: Applications can now sign in with a certificate or federated credential, so GitHub Actions, workload identity and Terraform's OIDC support work. Tokens now match those issued by Microsoft Entra ID more closely.
  • Microsoft Graph: Support for directory extensions, and for token lifetime, token issuance, home realm discovery and activity timeout policies.
  • Role-based Access Control: Custom roles can now be created at resource group scope.
  • Service Bus: Improving behavioural consistency of sessions, rules, entity status and size limits.
  • Storage: Supporting pagination when listing blobs, queues, files and tables.
  • Virtual Machines: The Custom Script extension, Run Commands and cloud-init (customData) now run inside the container Locally launches for each VM, so they need Docker or Podman.
  • Web Apps and Function Apps: Configuration changes, connection strings and CORS now take effect in the running app, stopping an app stops it, and WebJobs are supported.

Bug Fixes

  • App Service Authentication: /.auth/me now returns the signed-in user's tokens when the token store is enabled.
  • App Service Authentication: improving behavioural consistency of redirects after sign-in and sign-out, which are now limited to the app itself and its allowed external redirect URLs.
  • ARM Templates and Bicep: deployment().name now returns the deployment's name, so Bicep modules deployed from different parent deployments no longer overwrite each other, and What-If previews the same names the deployment uses.
  • Assigning a role to a managed identity created in the same template no longer fails on the first run.
  • Azure Policy External Evaluation policies now resolve type-qualified aliases.
  • Closing Locally now removes all of its containers when using Podman.
  • Container Apps: az containerapp ingress no longer removes the app's existing ingress and secrets.
  • Directory Emulator: improving behavioural consistency when validating authorization codes and on-behalf-of requests.
  • Directory Emulator: support for v1.0 access tokens, and respecting the claims requested by the app registration.
  • Ensuring permissions are applied consistently in Container Registry, Cosmos DB, Event Grid, Event Hubs, IoT Hub, Service Bus and Storage.
  • Event Grid: improving behavioural consistency when publishing to a custom topic, domain or partner namespace, which now checks its credentials. MQTT clients now connect using the namespace's hostname.
  • Event Grid: updating a topic, domain or partner namespace now applies every change, not just tags.
  • Fixes a crash when provisioning many resources at once.
  • Key Vault: reading a missing secret or key now returns 404 rather than 500, which fixes azapi_resource. Purging a vault now removes all of its contents.
  • locally ci now releases its CI lease when it exits with an error.
  • locally ci: removed the unused LOCALLY_ANALYTICS_ENABLED and LOCALLY_CRASH_REPORTING_ENABLED environment variables.
  • locally deploy no longer leaves temporary files behind after deploying a Bicep file, and shows resource names and durations more clearly.
  • locally mcp install copilot-vscode now installs into VS Code's user profile, so Locally is available in every workspace.
  • locally setup now links to the same Terms and Conditions page as other places.
  • Microsoft Graph: improving behavioural consistency by checking the application's Graph permissions on each call. The Azure CLI, Azure PowerShell and VS Code are pre-consented.
  • MySQL and PostgreSQL Flexible Servers: changing the administrator password now changes it on the server, and MySQL server parameters are now applied.
  • Resource Groups: every API version Azure lists is now accepted.
  • Role-based Access Control: az role definition delete no longer reports an error after deleting a custom role.
  • Web Apps: a deployment whose build crashes on Apple Silicon now fails straight away and explains how to deploy without a build, rather than hanging.
  • Web Apps: custom containers are now reached on port 80 by default.
  • Web Apps: improving behavioural consistency of ZIP deploys, which now only run a build when SCM_DO_BUILD_DURING_DEPLOYMENT is true.

v2026.09

Initial Release

This is the initial release of Locally, which contains:

New Components

  • Locally Control Plane: provides a Resource Manager compatible API with support for provisioning Resources via Plugins. Find out more.
  • Locally Dashboard: a dashboard for Resource Manager-related functionality. Find out more.
  • MCP Server: gives AI assistants like Claude Code and Cursor a set of tools to explore and manage the resources in your Locally instance. Find out more.

Data Plane Emulators

Key Features

  • Automatic Configuration of common tooling, like the Azure CLI, HashiCorp Terraform, OpenTofu, PowerShell and Pulumi. Applications built using the Azure SDKs can also be connected to Locally, but require a few lines of changes at this time. Find out more.
  • Support for both ARM and Bicep Templates: these can be natively deployed to Locally.
  • Real Subscriptions and Credentials: Locally gives you multiple, real Subscriptions, with real credentials (Service Principals, Entra Users/Groups and Managed Identities) and real role-based access control (RBAC). The Default Identity has full permissions for ease of development (e.g. Global Administrator), but you can assign any Role to any Enterprise Application/Entra User/Group at any scope.

Features

  • Architecture Diagrams: View and export a live architecture diagram of your deployed infrastructure. Find out more.
  • Chaos Engineering: Support for testing how your application behaves when things go wrong. Find out more.
  • Containers: Support for launching containers in both Docker and Podman.
  • Cost Estimation: Shows a ballpark estimate of how much your application would cost to run in Azure. Find out more.
  • Directory Emulator: Work with Users, Groups, Applications, Service Principals and more. Test your applications using single-sign-on, SAML support and conditional access. Find out more.
  • Locally Directory: Shows you who in your team is most familiar with, and has most recently worked with, each Azure Service. Find out more.
  • Locally Runbooks: Define common infrastructure (Resource Groups, Resources, DB scripts and Entra users) for your team and have them available within Locally, optionally provisioning automatically at launch. Find out more.
  • Locally Teams: Build infrastructure together using common Runbooks, the Locally Directory and CI configuration at a Team level. Find out more.
  • Minimum Necessary Permissions: Run your application/deployments against Locally and see a Role Definition with the minimum permissions needed to run the deployment. Find out more.
  • Observability: Dig deep into your application by inspecting the HTTP(S) requests and responses being made, and by running KQL queries against the Application Insights and Log Analytics emulators.
  • Regions: Locally uses its own set of Regions to differentiate it from Azure (so you can be sure when you're targeting Locally or Azure). Support for using the Azure Regions is available as a preview feature. Find out more.
  • Themes: Locally ships with 9 themes: Dark, Forest, HardHacker, Light, Neon, Parchment, Retro, Sunset, Solarized.

Other

  • Support for launching containers via Docker and Podman. Both of these are auto-detected at launch.
  • Support for connecting to both Virtual Machines and Bastion instances over both Remote Desktop (for Windows VMs) and SSH.
    This allows you to validate whether the Virtual Machine in question has access to the route you're expecting it to.
  • Support for exploring the Control Plane API in a browser without authentication, which makes this more explorable during local development.
    This is enabled by default, but can be turned off in Settings -> Feature Flags within the Dashboard.
  • Support for disabling the Beta API in the Directory Emulator. Find out more.
    Beta API Versions are enabled by default, but can be turned off in Settings -> Feature Flags within the Dashboard.
  • Support for disabling Deprecated API Versions in the Control Plane API. Find out more.
    Deprecated API Versions are enabled by default, but can be turned off in Settings -> Feature Flags within the Dashboard.
  • Support for disabling Preview API Versions in the Control Plane API. Find out more.
    Preview API Versions are enabled by default, but can be turned off in Settings -> Feature Flags within the Dashboard.
  • Support for Purge Protection on resources that support it within the Resource Manager API.
    This is off by default but can be turned on in Settings -> Feature Flags within the Dashboard.

Preview Features

Preview Features are features that we're still working on, and may contain bugs or other issues.

  • Compliance: Validate your infrastructure's compliance with regulatory policies, including seeing a breakdown of which resources do/do not comply, and how to bring them into compliance. Find out more.
  • Custom Regions: support for using the regions from an Azure Environment (Azure Public, Azure China or Azure US Government). This feature flag can be turned on in Settings -> Feature Flags. Find out more.
  • Locally Policies: Define your team's policies centrally and allow your team to validate that their deployments comply with them, without blocking their day-to-day work. Find out more.
  • Policies: Deploy Azure Policies to your Subscriptions. Find out more.
  • Translation: Locally is available in 16 languages (with 14 translations in Beta, translated via AI), including Chinese (Simplified), Dutch, English (UK/US), French, German, Hindi, Italian, Japanese, Korean, Norwegian (Bokmål), Polish, Portuguese (Brazil), Russian, Spanish and Ukrainian.

Have your first local subscription running in under a minute.

Runs entirely on your machine, with the tools you already use.

Install Locally →

Or read more: Pricing · Documentation