Have you tagged your Azure firewalls yet? From 1 August 2026, Microsoft will expand the roll out MANA-capable hardware across Azure VM SKUs. MANA improves Azure networking, but older FortiGate and Palo Alto VM-Series builds may not support the new MANA datapath. When that happens, the appliance can silently fall back to the synthetic network path, cutting throughput by 50% or more.
The good news: there is a simple stopgap you can apply today, and a clean way to manage the real migration on your own terms.
What MANA changes for your NVAs
MANA, the Microsoft Azure Network Adapter, is Azure’s next-generation NIC and part of Azure Boost. It is rolling out across existing VM series, and it is standard on newer SKUs, including the new Fv7 series that we favour for its higher CPU-to-NIC ratio for high-availability NVA clusters.
Here is the catch: FortiGate and Palo Alto VM-Series push traffic through a high-speed DPDK dataplane. On a build that does not support MANA, the appliance drops back to the synthetic path, and Palo Alto’s own advisory puts the impact at a 50% or greater cut in maximum throughput. The same fallback can hit any VM that is stop-deallocated, restarted, or redeployed onto MANA hardware.
The stopgap: apply the LegacyVMNVA tag before 1 August
Microsoft’s opt-out is the LegacyVMNVA tag. It keeps tagged NVA VMs and scale sets on non-MANA hardware while you migrate, and it is honoured until 31 May 2027. Apply it through the built-in LegacyVMNVA Azure Policy so it scopes automatically to known NVA publishers and product IDs, then run a reapply (or a stop-deallocate and start) so existing VMs pick it up.
- 1 August 2026: the date impacted Intel v1 to v4 series can start landing on MANA hardware unless they are tagged (some v5 and Cobalt 100 series were earlier, on 26 May 2026).
- 31 May 2027: the tag stops being honoured, so treat it as a bridge, not a destination.
- Reapply to enable: new deployments in scope get the tag automatically; existing VMs need the tag plus a reapply or a stop-deallocate and start.
Check whether you are exposed
- Inventory your NVAs: list every FortiGate and Palo Alto VM-Series instance with its firmware or OS version.
- Check the minimum versions: FortiOS below 7.6.1 and PAN-OS below 12.1.5 lack the MANA drivers and fall back to the synthetic path.
- Confirm Accelerated Networking: the risk and the tag only apply where Accelerated Networking is enabled, which is your firewall data interfaces.
- Watch for the Azure Advisory: Microsoft flags impacted VMs directly in the portal, as shown above.
Plan your move: tag now, migrate on your terms
- Tag production today: apply the LegacyVMNVA tag to your production firewalls now to hold them on compatible hardware and take the 1 August pressure off.
- Migrate through test and CAB: schedule the FortiOS 7.6.1 or PAN-OS 12.1.5 upgrades through your test environments and change advisory board, on your timeline rather than Azure’s.
- Mind the newer SKUs: if you want the Fv7 series for its CPU to NIC ratio, plan to be on a MANA-ready build first, because those SKUs are built for MANA.
- Reapply in a window: enabling the tag needs a reapply or stop-deallocate, which is a brief interruption, so use a maintenance window.
MANA-ready versus legacy, at a glance
| Aspect | MANA-ready build | Legacy build on MANA hardware |
| Dataplane | Accelerated via the MANA Virtual Function | Drops to the synthetic path |
| Throughput | Full line rate | Cut by 50% or more |
| Redeploy or servicing | Stays on the fast path | Falls back with no warning |
| Minimum version | FortiOS 7.6.1 / PAN-OS 12.1.5 | Below those versions |
Final Thoughts
MANA is a genuine step forward for Azure networking, but for NVAs it is a hard dependency on the right build and the right hardware. Tag your production firewalls before 1 August, then move FortiOS and PAN-OS up to a MANA-ready version through your normal test and change process.
At Codify, our managed firewall service handles exactly this: platform changes like the MANA transition, firewall version upgrades, and posture management of your Azure routing so traffic flows through predictable paths. We also police the anti-patterns that quietly bypass your network edge, like stray public IPs and route table changes.
Want a hand getting your firewalls tagged and MANA-ready? Get in touch for an obligation-free chat.

