Amazon WorkSpaces adds new security features to manage which client devices can access WorkSpaces

Amazon WorkSpaces now provides you additional options to manage which client devices can access your WorkSpaces. This new feature allows you to limit WorkSpaces access to trusted devices only. You can manage access to your WorkSpaces from macOS and Microsoft Windows PCs using your digital certificates. You can also allow or block access for iOS, Android, Chrome OS, and zero clients, as well as the WorkSpaces Web Access client. With these new capabilities, you can further improve your security posture.
Quelle: aws.amazon.com

A Mobile Billboard Is Driving Around Seattle Urging Amazon To Cut Ad Ties With Breitbart

Starting today, a mobile billboard bearing the words “Amazon, Stop Funding Bigotry. Please Pull Your Ads From Breitbart” will begin driving around Amazon's Seattle headquarters in an effort to get the e-commerce giant to join an online ad boycott of the pro-Trump news site.

The ad campaign is funded by the anonymous marketing collective Sleeping Giants. Since the 2016 election, the group has been waging a campaign against Breitbart on Facebook and Twitter. The group's main concern centers around the programmatic advertising market , which uses software and algorithms, not humans, to purchase digital ads. Sleeping Giants believes this makes it easy for companies to advertise on controversial sites without knowing it. So far, Sleeping Giants has convinced 2,250 companies to sever their ad relationship with Breitbart — the advocacy campaign has been largely credited as the reason for a reported 90% drop in brands advertising on Breitbart's website. A viral petition on the activism site sumofus.org titled “Amazon: Stop Investing in Hate” also amassed over 589,000 signatures this spring.

But despite this pressure, Sleeping Giants has one big hold-out: Amazon. “We haven't heard from anybody in eight months of calls and emails,” an anonymous Sleeping Giants founder told BuzzFeed News. “We've even spoken to people who have shows on Amazon's streaming service and they've approached people at the Amazon about the Breitbart situation and still we've heard nothing.”

The pressure is also coming from inside Amazon. In April, BuzzFeed News reported that a petition opposing Amazon's continued advertising on Breitbart had amassed 564 employee signatures. Attached were testimonials from concerned employees about the company running ads on a company that “regularly publishes hateful and bigoted content.” The petition was met with mostly silence from Amazon, though SVP Jeff Blackburn told employees at a March all-hands meeting that “we have our eyes on it.” While Amazon doesn’t have a direct relationship with Breitbart, the company does select the exchanges through which it buys ads, and presumably has some say in how they are targeted.

Sleeping Giants said that Amazon's silence is the reason for the billboards. “The crux of the problem is that they're so unresponsive,” the Sleeping Giants founder said. “If they aren't going to pull them it is their choice but they owe customers a reason.”

Though Sleeping Giants understands that convincing the commerce giant to pull ads is an uphill battle, the group feels the billboards will raise more awareness for people who don't spend most of their time online.

“This is a first for us — taking the cause onto the actual streets,” a Sleeping Giants member said. “It's one thing to hammer away at things on Twitter and Facebook but it's another to get it out into the real world and let them know the problem we have.”

Quelle: <a href="A Mobile Billboard Is Driving Around Seattle Urging Amazon To Cut Ad Ties With Breitbart“>BuzzFeed

Managing updates for your Azure VM

In this blog post, I will talk about how to use Update Management solution to manage updates for your Azure VMs. Right from within your Azure VM you can quickly assess the status of available updates, initiate the process of installing required updates, and review deployment results to verify that updates were applied successfully to the VM.

This feature is currently in private preview. If you’re interested in giving it a try, please sign up!

Enabling Update Management

From your VM, you can select “Manage Updates” on the virtual machines blade, under Automation + Control. After selecting it, validation is performed to determine if the Update Management solution is enabled for this VM. If it is not enabled, you will have the option to enable the solution.

The solution enablement process can take up to 15 minutes, and during this time you should not close the browser window. Once the solution is enabled and log data starts to flow to the workspace, it can take more than 30 minutes for data to be available for analysis in the dashboard described in the next section. We expect this timing to significantly improve in the future.

Review update assessment

From the Manage Updates dashboard, you can review the update compliance state of the VM from the Missing updates by severity tile, which displays a count and graphical representation of the number of updates missing on the VM. The table below shows how the tile categorizes the updates missing by update classification.

To create an update deployment and bring the VM into compliance, you configure a deployment that follows your release schedule and service window. This entails what update types to include in the deployment, such as only critical or security updates, or if you want to exclude certain updates.

Create a new Update Deployment for the VM by clicking the “Schedule deployment for this VM” button at the top of the blade and specify the required values. 

After you have completed configuring the schedule, click the “OK” button and you return to the status dashboard. You will notice that the Scheduled table shows the deployment schedule you just created.

View update deployment state

When the scheduled deployment executes, you see the status appear for that deployment under the Completed and in-progress table. Double-clicking the completed update deployment takes you to the detailed deployment status page.

To review all detailed activities performed as part of the update deployment, select “All Logs and Output tiles”. This will show the job stream of the runbook responsible for managing the update deployment on the target VM.

OS support

Windows: Windows 2012 and above
Linux: RedHat Linux 6 & 7, Ubuntu Server 12.04 LTS, 14.04 LTS, 15.10, and 16.04

New to OMS Update Management

If you are new to OMS Update Management, you can view the current capabilities which include Update Insights across Windows and Linux, and the ability to deploy updates, as well as documentation.

In future posts, I’ll talk about how to manage updates for multiple VMs in your subscription and how to orchestrate the update deployments including running pre/post steps, sequencing, and much more!
Quelle: Azure

New Filtering Options and Linked Account Access in AWS Budgets

AWS Budgets lets you set custom AWS cost and usage budgets and receive notifications if your budget thresholds are breached. You can set budgets to monitor your total monthly costs or use the available filtering dimensions to track the costs associated with a specific linked account, usage associated with an AWS service, costs by one or more tagged groups, and more. Starting today, your linked accounts will also have access to AWS Budgets. 
Quelle: aws.amazon.com

Enable client side monitoring in Azure with Application Insights

With the Application Insights JavaScript SDK you can collect and investigate the performance and usage of your web page or app. Historically we have offered onboarding through manually adding a script to your application and redeploying. Manually adding the script is still supported, but recently we have added the ability to add client-side monitoring from the Azure portal in a few clicks as well.

Enablement

If you have enabled Application Insights in Azure, you can add page view and user telemetry. You can learn how to switch on server-side monitoring in our documentation.

     1. Select Settings -> Application Settings

     2. Under App Settings, add a new key value pair:

Key: APPINSIGHTS_JAVASCRIPT_ENABLED

Value: true

 

     3. Save the settings and Restart your app in the Overview tab.

 

The Application Insights JavaScript SDK is now injected into each web page.

Feedback

If you have any questions or experiencing any problems with the JavaScript SDK, feel free to open an issue on GitHub.
Quelle: Azure

OpenShift Commons Briefing #76: Security Practices in OpenShift Container Platform at Amadeus

In this webcast, Nenad Bogojevic of Amadeus and Diogenes Rettori from Red Hat talk about security mechanisms and protections related to Red Hat OpenShift Container Platform and Amadeus’ experiences deploying and using OpenShift, including security mechanisms, such as user and network access control and policies in OpenShift and underlying Openstack, the audit trail of administrative actions, ways to use and protect Kubernetes secrets as well as some best practices for Docker containers. They also present some possibilities to address technical limitations or potentially unknown vectors of attack using compensating controls via auditd, monitoring, and alerting.
Quelle: OpenShift

GDPR Questions? Azure has answers.

Microsoft is here to help

Please have a look at our white paper How Microsoft Azure Can Help Organizations Become Compliant with the EU General Data Protection Regulation to gain an understanding of how your organization can use currently available features in Azure to optimize your preparation for GDPR compliance. We are here to help you with your compliance efforts in the face of the coming EU law.

May 25, 2018: a new era begins for data privacy

On this date in a little less than a year, the new European Union (EU) data protection law will be implemented, replacing the old Data Protection Directive, which has been in effect since 1995. The new law, known as the General Data Protection Regulation (GDPR), gives individuals greater control over their personal data and imposes many new obligations on organizations that collect, handle, or analyze personal data.

This is what we do

Azure has developed a tradition of compliance which gives our customers the tools they need to comply with complex regulations. Our attention to, and preparation for the impact of GDPR continues to show how we equally prioritize the best cloud technology with the best compliance offerings.

Additional information about how Microsoft helps you to fulfill specific GDPR requirements are available at the GDPR section of our Microsoft Trust Center.
Quelle: Azure

Azure Site Recovery now supports managed disks

Azure Site Recovery (ASR) now supports managed disks. This follows the announcement of Azure’s support for managed disks in February. With the integration of managed disks into ASR, you can attach managed disks to your machines during a failover or migration to Azure. 

Managed disks provide the following advantages:

Simplified disk management for Azure IaaS VMs by removing the hassle of managing storage accounts for your machines after failover to Azure.
Improved reliability for Availability Sets by ensuring that the disks of the failed over VMs are automatically placed in different storage scale units (stamps) to avoid single points of failure.

To attach managed disks to your machine on a failover, set “Use managed disks” to “Yes” in the Compute and Network settings for the virtual machine as shown below.

 

Below are a few considerations to keep in mind when using this feature: 

Managed disks can be created only for virtual machines deployed using the Resource manager deployment model.  
Virtual machines with managed disks can only be part of availability sets with "Use managed disks" property set to "Yes". Learn more about managed disks and availability sets.
If the storage account used for replication was encrypted with Storage Service Encryption (SSE) at any point in time, creation of managed disks during failover will fail. In such a scenario, you can either set "Use managed disks" to "No" in the Compute and Network settings for the virtual machine and retry failover or disable protection for the virtual machine and protect it to a storage account which did not have Storage service encryption enabled at any point in time. Learn more about managed disks and Storage service encryption.
For Hyper-V VM’s managed by/not under the management of System Center VMM, set the option to use managed disks only if you intend to migrate your machine to Azure. This is because failback from Azure to on-premises Hyper-V environment is not currently supported for machines with managed disks.
Data from on-premises VMs replicates to a target storage account in Azure, as is with the experience today. Managed disks are created and attached to your machine only on a failover to Azure.
Disaster Recovery of Azure IaaS machines with managed disks is not supported currently and will be made available in the future.

The latest Deployment Planner tool, version 1.3, supports managed disks. You can download the tool from the ASR Deployment Planner doc. For a complete understanding of how managed disks works, please refer to the detailed Managed disks documentation.

Ready to start using ASR?

Check out additional product information to start replicating your workloads to Microsoft Azure using Azure Site Recovery today. You can use the powerful replication capabilities of Site Recovery for 31 days at no charge for every new physical server or virtual machine that you replicate. Visit the Azure Site Recovery forum on MSDN for additional information and to engage with other customers. You can also use the ASR UserVoice to let us know what features you want us to enable next.

Azure Site Recovery, as part of Microsoft Operations Management Suite, enables you to gain control and manage your workloads no matter where they run, including Azure, AWS, Windows Server, Linux, VMware, or OpenStack, with a cost-effective, all-in-one cloud IT management solution. Existing System Center customers can take advantage of the Microsoft Operations Management Suite add-on, empowering them to do more by leveraging their current investments. Get access to all the new services that OMS offers, with a convenient step-up price for all existing System Center customers. You can also access only the IT management services that you need, enabling you to on-board quickly and have immediate value, paying only for the features that you use.
Quelle: Azure