clip_image002Microsoft is very excited to announce an “Azure Serverless & Azure Function” Ask Microsoft Anything (AMA) on October 29!  The AMA will take place on Thursday, October 29, 2020 from 9:00 a.m. to 10:00 a.m. PT in the Azure AMA space.   Add the event to your calendar and view in your time zone here.

An “Ask Microsoft Anything” (AMA) is a live online event similar to a “YamJam” on Yammer or an “Ask Me Anything” on Reddit. This AMA gives you the opportunity to connect with cloud solution architects who will be on hand to answer your questions and listen to feedback.

Upcoming dates/events are below:

  • November 5 – App Services & Standard Web Apps

clip_image002Join this webinar to learn about built-in security capabilities of Windows Virtual Desktop. You’ll also find out how to improve your security posture by integrating your desktop environment with other Azure and Microsoft offerings.  Get technical guidance to help you:

  • Understand the security controls available in Windows Virtual Desktop.
  • Use multifactor authentication and conditional access to help keep your users safe.
  • Configure security tools such as Azure Security Center and Microsoft Endpoint Manager to help protect your infrastructure.

Register now at:

Yay!

Windows Virtual Desktop is now Generally Available in Azure US Government regions, along with the Azure portal integration. With the Azure portal integration, you get a simple interface to deploy and manage apps and virtual desktops. Host pool, workspace, and all other objects you create are Azure Resource Manager objects and are managed the same way as other Azure resources. You can provide fine-grained access to Windows Virtual Desktop resources using role-based access control, publish remote apps and desktops to AAD groups instead of individual users, and troubleshoot issues faster with Azure Monitor.

Reference:
https://azure.microsoft.com/en-us/updates/windows-virtual-desktop-is-now-generally-available-in-the-azure-government-cloud/

We have a session from some of the security principals of our Support Services organization coming up specifically on directing your organization to “Zero Trust”.

imageNever trust, always verify. Once, before the pandemic, you may have found Zero Trust interesting. Yet you didn’t rush to implement it. And you’re not the only one. We found that only 10% used multi-factor authentication, let alone all the tenets of Zero Trust.

Then Covid-19 forced businesses to send their workforce home. Many of our customers turned to Zero Trust to enable and secure remote work. You may have elevated it from yellow-light optional to green-light imperative overnight.

Microsoft Support Services can help you navigate the challenges of a larger attack surface. Join our webinar on October 22 to find out how to create strict boundaries around data. We’ll talk about the balance between access and productivity. We’ll share info about workshops, assessments, and engagements to help you reach Zero Trust.

Register below:

Posted by: kurtsh | October 18, 2020

INFO: Microsoft Edge (Chromium) Add-ons

Here are a few useful add-ons for Microsoft Edge Chromium: (This is mainly a reference for myself)

  • imageARCHIVE PAGE
    Adds a button to the Microsoft Edge toolbar. When clicked, it sends the URL of the current tab to archive.today to preserve a snapshot of the page, and opens the result in a new tab. Also includes Link context menu to Archive or Search, Page context menu to Search. Archive URL can be bookmarked for future reference, shared, whatever. Uses HTTPS for security.
    (For similar functionality on Android, check out Share2Archive in the Play Store.)

    archive.today is a time capsule for web pages. It takes a ‘snapshot’ of a webpage that will always be online even if the original page disappears. It saves a text and a graphical copy of the page for better accuracy and provides a short and reliable link to an unalterable record of the web page

    https://microsoftedge.microsoft.com/addons/detail/archive-page/llldbgankiiaiobhnjpbllpijlidinaf

  • imageTAMPERMONKEY
    Tampermonkey is the most popular userscript manager, with over 10 million weekly users. It’s available for Microsoft Edge, Chrome, Safari, Opera Next, and Firefox.

    Tampermonkey makes it very easy to manage your userscripts and provides features like a clear overview over the running scripts, a built-in editor, ZIP-based import and export (Google Drive, Dropbox, OneDrive, WebDAV), automatic update checks and also browser and cloud storage based synchronization. And finally it’s compatible to Greasemonkey up to version 3.x.

    https://microsoftedge.microsoft.com/addons/detail/tampermonkey/iikmkjmpaadaobahmlepeloendndfphd

  • imageI DON’T CARE ABOUT COOKIES
    Get rid of cookie warnings from almost all websites!

    https://microsoftedge.microsoft.com/addons/detail/i-dont-care-about-cookie/oholpbloipjbbhlhohaebmieiiieioal

  • imageDISABLE HTML5 AUTOPLAY
    “Disable HTML5 Autoplay” disables HTML5 audio and video autoplaying.

    Now any video is blocked until you click the agreement button.

    In addition to removing the HTML autoplay attribute from media elements, “Disable HTML5 Autoplay” also hooks into the media’s JavaScript API. This allows for restrictions on media control and simulation of expected behavior to ensure that all pages behave normally. Main and most requested feature: this blocker has a customizable white list, so you may add your favorite sites to exclude from blocking autoplay. To deactivate a function, simply uncheck the related item from toolbar-panel. With this extension you will never have to worry about videos auto playing in the background. In addition, the video will be automatically buffered if necessary.

    https://microsoftedge.microsoft.com/addons/detail/disable-html5-autoplay/angamhlikfokpbmfppadnnbmflollmnc

imageI was asked to do some research around the “costs associated with storage for software distribution & update packages for Modern/Managed Desktop” configurations.

In that vein, I thought I’d share a couple things for folks looking to manage desktops on the Internet without VPN, but to summarize what I understand:

  1. SCCM CMG/CDP configurations will have Azure Storage, outbound Azure Networking, & Azure VM Compute costs for software distribution
  2. Microsoft Intune has no additional cost for software distribution storage and networking

SCCM CLOUD MANAGEMENT GATEWAY/CLOUD DISTRIBUTION POINTS

SCCM Cloud Management Gateways or CMGs have a cost associated with their operation – mostly Azure Compute.  The rough estimate for this is ~$150/gateway/month where each gateway can sustain a rough maximum 3000 devices, with a recommended limit of 1000 devices/gateway and obvious redundancy for each gateway. (Those with Premier Services will want to speak to a Premier engineering resource for more guidance)

SCCM CMGs require the use of “Cloud Distribution Points” or CDPs for distributing software – these may be on the same VMs as the SCCM CMGs or on separate VMs but you’ll want to discuss architecture & configurations with a Premier subject matter expert or a Professional Services Architect. (From Microsoft Consulting Services or a Microsoft certified partner) CDP costs for software distribution include Azure Storage & Azure Networking costs along with the VM/compute costs.

Per the documentation, there are 5 potential costs:

  1. CMG VM costs
  2. CMG Outbound data transfer costs
  3. CDP VM costs
  4. CDP Outbound data transfer costs
  5. CDP Storage costs

For more details, visit:

MICROSOFT INTUNE
Microsoft Intune, when licensed for all endpoints being distributed to, does not have any additional cost associated with software package storage & distribution. 

  1. There’s no limit on the amount of storage; storage comes with the purchase of a Microsoft Intune license.
  2. There is a 8GB maximum file size limit on any individual desktop file uploaded.

Taken from the Microsoft Intune documentation:

All apps that you create by using the software installer installation type (for example, a line-of-business app) are packaged and uploaded to Intune cloud storage. A trial subscription of Intune includes 2 gigabytes (GB) of cloud-based storage that is used to store managed apps and updates. A full subscription does not limit the total amount of storage space.

For more information, read the following:

imageWe have 4 1-hour trainings coming up for Windows Virtual Desktop that are free and no cost to you:

  1. Windows Virtual Desktop Overview and Architecture
  2. Windows Virtual Desktop Deployment, Profile management, Identity, and Security
  3. Windows Virtual Desktop Infrastructure Management
  4. Windows Virtual Desktop Assessment, Migration and Optimization

Here’s the details & the registration links:

  • Windows Virtual Desktop Overview and Architecture
    26-Oct-2020 – 9:30AM-10:30AM PT
    In this online course, you will learn about deploying and managing Windows Virtual Desktop. Windows Virtual Desktop on Microsoft Azure is a desktop and app virtualization service that runs on the cloud. Windows Virtual Desktop works across devices – including Windows, Mac, iOS, and Android – with full-featured apps that you can use to access remote desktops and apps. You will learn about its pre-requisites, architecture and deployment during this course. This course is suitable for Cloud infrastructure administrators and Remote Desktop engineers.
    https://note.microsoft.com/CO-NOGEP-WBNR-FY21-10Oct-26-ImplementingWindowsVirtualDesktopWindowsVirtualDesktopOverviewandArchitecture-SRDEM41583-01_Registration.html
  • Windows Virtual Desktop Deployment, Profile management, Identity, and Security
    27-Oct-2020 – 9:30AM-10:30AM PT
    In this online course, you will learn about deploying and managing Windows Virtual Desktop. Windows Virtual Desktop on Microsoft Azure is a desktop and app virtualization service that runs on the cloud. Windows Virtual Desktop works across devices – including Windows, Mac, iOS, and Android – with full-featured apps that you can use to access remote desktops and apps. You will learn about its pre-requisites, architecture and deployment during this course. This course is suitable for Cloud infrastructure administrators and Remote Desktop engineers.
    https://note.microsoft.com/US-NOGEP-WBNR-FY21-10Oct-27-ImplementingWindowsVirtualDesktopWVDAssessmentMigrationandOptimization-SRDEM41583-02_Registration.html
  • Windows Virtual Desktop Infrastructure Management
    28-Oct-2020 – 9:30AM-10:30AM
    In this online course, you will learn about deploying and managing Windows Virtual Desktop. Windows Virtual Desktop on Microsoft Azure is a desktop and app virtualization service that runs on the cloud. Windows Virtual Desktop works across devices – including Windows, Mac, iOS, and Android – with full-featured apps that you can use to access remote desktops and apps. You will learn about its pre-requisites, architecture and deployment during this course. This course is suitable for Cloud infrastructure administrators and Remote Desktop engineers.
    https://note.microsoft.com/US-NOGEP-WBNR-FY21-10Oct-28-ImplementingWindowsVirtualDesktopWVDDeploymentProfilemanagementIdentityandSecurity-SRDEM41583-03_Registration.html
  • Windows Virtual Desktop Assessment, Migration and Optimization
    29-Oct-2020 – 9:30AM-10:30AM
    In this online course, you will learn about deploying and managing Windows Virtual Desktop. Windows Virtual Desktop on Microsoft Azure is a desktop and app virtualization service that runs on the cloud. Windows Virtual Desktop works across devices – including Windows, Mac, iOS, and Android – with full-featured apps that you can use to access remote desktops and apps. You will learn about its pre-requisites, architecture and deployment during this course. This course is suitable for Cloud infrastructure administrators and Remote Desktop engineers.
    https://note.microsoft.com/US-NOGEP-WBNR-FY21-10Oct-29-ImplementingWindowsVirtualDesktopWVDInfrastructureManagement-SRDEM41583-04_Registration.html

image

As you move toward bringing employees back, give your teams the tools to help them stay safe and productive on the job with solutions from Microsoft.

Reopen and manage physical locations

Open and operate your locations responsibly to provide employees with a safer environment, while ensuring your organization can quickly respond to—and communicate—changing circumstances.

Return while supporting employee safety and wellbeing

Protect your employees with new safety protocols and intelligently monitor the health of your entire organization to help make data-driven decisions about who should work where.

Engage your teams—remotely and onsite

Support the flow of work wherever it happens—remotely, onsite, or a combination of both. Help everyone stay connected, productive, and secure.

Read more at Microsoft’s Resilience site about returning to the workplace:

image

The following 4 podcasts focus on Security from Microsoft’s best and brightest security minds.

—————–

Uncovering Hidden Risks Podcast

Introducing our new podcast series: Uncovering Hidden Risks! Join us to learn how organizations handle insider risk and implement best-in-class technology and processes.

imageWe’ll take you through a journey on insider risks to uncover some of the hidden security threats that Microsoft and organizations across the world are facing.  We will bring to surface some best-in-class technology and processes to help you protect your organization and employees from risks from trusted insiders.  All in an open discussion with topnotch industry experts!

Learn all about Microsoft M365 Compliance solutions here. Stay up to date by following our Insider Risk blog here.

Subscribe here:

Security Unlocked

imageSecurity Unlocked explores the technology and people powering Microsoft’s Security solutions. In each episode, Microsoft Security evangelists Nic Fillingham and Natalia Godyla take a closer look at the latest innovations in threat intelligence, security research, and data science, with a special focus on demystifying artificial intelligence and machine learning. Be sure to listen in and subscribe!

Afternoon Cyber Tea

imageAnn Johnson, Corporate Vice President, Business Development, Security, Compliance & Identity at Microsoft, talks with cybersecurity thought leaders and influential industry experts about the trends shaping the cyber landscape and what should be top-of-mind for the C-suite and other key decision makers. Ann and her guests explore the risk and promise of tools and systems powered by AI, IoT, machine learning, and other emerging technology, as well as the impact on how humans work, communicate, consume information, and live in this era of digital transformation. Please note, the opinions expressed by guests on this podcast are their own and are not endorsed by, nor do they necessarily reflect opinions of, Microsoft or Ann Johnson.

Azure Security Podcast

Join our experts twice a month for the Azure Security Podcast, dedicated to #security, privacy, compliance and reliability on the Microsoft Cloud Platform.

imageA twice-monthly podcast dedicated to Security, Privacy, Compliance and Reliability on the Microsoft Cloud Platform. Hosted by Microsoft security experts Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos. Meet the team.

imageIf you’re interested in downloading some or all of the session video recordings and PowerPoint decks from Microsoft Ignite 2020, you’re in luck:  There’s a PowerShell script available to do just that!

It’s called the “Microsoft Ignite Resource Downloader” script and is a small .ZIP file that contains a README doc for instructions and command line parameterized to limit what sessions you want to download.

Download the script here:

« Newer Posts - Older Posts »

Categories