Provisioning for true zero-touch secure identity management for IoT

When you’re on a mission to deliver an awesome, complex IoT experience, the last thing you want to be doing is babysitting device identities at any stage of your solution. If you’re building a smart vehicle experience, you want to be thinking fleets, services, operational telemetry and not how to transfer vehicle identities between owners, renters, insurance companies, and service providers. If you’re developing for a mobile factory experience like a cruise ship or an airline, you want to be thinking geography optimal predictive maintenance, and not about cloud connection points and sovereign cloud specific requirements. How you provision your IoT devices makes a world of a difference with operational efficiency. Provisioning for true zero-touch secure identity management is the promise to minimize operational burden and maximize focus on the experience.

Until now, most claims for zero-touch provisioning have been about giving devices identities to connect to a cloud. What happens thereafter has largely been a mystery relegated to the IoT solutions developer. Developers of complex solutions are often left with no choice but to hack custom accommodations for their backends or manually manage hand-off of device identities in operations. Both options are costly, burdensome, and most of all, detracts focus from envisioned experience. Shouldn’t secure device identity and complete lifecycle management be a scalable building block in the IoT solution developer’s toolbox, so they can focus on just IoT experience?

Well, we believe it should. Microsoft has been building towards answering this very question, and in the past few months, collaborated with partners to make this a reality. The solution originates with anchoring trust in secure silicon, from which standards are used to derive device unique certificate identities that are ingested, authenticated, and lifecycle managed at scale by Azure Device Provisioning Service (DPS).

Earlier this year, as part of Microsoft’s commitment to IoT security, we announced adoption of Trusted Computing Group’s DICE standard and new HSM partners committed to availing DICE hardware. We now extend this announcement to welcome Microchip into the fold. Microchip has made availability of DICE hardware a reality through its CEC1702 family of secure silicon chips and evaluation kit offering. You may also learn about this offering from the Azure IoT Catalog and purchase directly from the Microchip Website. Designed for security and trust from the ground up, CEC1702 roots trust in secure silicon hardware and implements the DICE standard to generate device unique certificate identities that are trusted by any cloud service including Azure DPS.

Azure DPS takes it from here to fully realize provisioning for a truly zero-touch secure identity management for the lifecycle of IoT devices. DPS extends trust from the secure silicon hardware into the cloud domain where it creates registries to facilitate managed identity services to include location, mapping, aging, and retirement. This wealth of capability is exposed to the IoT solutions developers as simple routing rules to keep their full attention on the IoT experience they are creating. They only need to add a DPS compliant secure hardware like CEC1702 into their IoT devices.

IoT has evolved to the stage where connecting to a cloud is no longer a novelty. Secured and lifecycle-managed device identity should just be another component of the IoT developers standard toolbox. Microsoft in collaboration with secure silicon partners is making this a reality. To learn more about Azure Device Provisioning Service, please visit our tutorial documentation. 
Quelle: Azure

Announcing general availability of the new App Service Premium Plan

Today, we’re excited to announce the general availability of the new Premium plan from Azure App Service that runs on Dv2-series VMs. 

Azure App Service allows you to quickly build, deploy, and scale enterprise-grade web, mobile, and API apps running on any platform. Applications and services running on App Service can meet rigorous performance, scalability, security, and compliance requirements while leveraging a fully-managed platform to take care of infrastructure maintenance. This update brings additional horsepower to your applications.  

Two months ago, we announced the preview of the new Premium tier for Azure App Service featuring Dv2-series VMs with faster processors, SSD storage, and doubled memory-to-core ratio when compared to the previous instances. Today, the new Premium plan is generally available. 

It puts more application performance at your disposal. You can use it to build mission-critical applications faster, taking advantage of App Service’s enterprise grade capabilities including high availability with geo-distributed deployments, securing apps with Azure Active Directory (AAD) integration, and built-in SSL support. It runs on a cloud platform that complies with ISO information security standards, SOC2 accounting standards, and PCI security standards, just to name a few.

Getting started with the new Premium tier is easy. You can leverage Azure Resource Manager (ARM) templates, Azure Command Line Interface (CLI) scripts, or the Azure Portal user interface to configure a performant, scalable, and reliable environment in seconds.

We are excited about the addition of the newer, faster hardware underpinning the new Premium tier. To learn more, check out the documentation for the new App Service Premium tier. You can also provide your feedback in the App Service feedback forum.
Quelle: Azure

End-to-end monitoring solutions in Azure for Apps and Infrastructure

Today at the Ignite 2017 conference in Florida, we announced a range of new monitoring and analytics capabilities in Azure bringing together application and infrastructure monitoring in a unified curated overview in Azure Monitor. We are significantly optimizing your experience with the new log analytics, metrics exploration, application performance monitoring and failure investigations. We also announced integration of Azure alerts with IT Service Management tools and new solutions for Container Monitoring.

Bringing together monitoring services in Azure Monitor

From Azure Monitor you can now get at-a-glance reporting on the health and performance of all your cloud resources, from virtual machines to applications to individual lines of codes in the applications. Azure Monitor will now offer in public preview a unified overview as a starting point for navigation and on-boarding to various monitoring services in Azure. Customers will be able to see notable issues across applications & infrastructure in a single place and navigate to them in context.

Azure Monitor will now provide near real-time alerting in public preview for platform metrics from Azure services such as Virtual Machines, Networking, ServiceBus, EventHubs, etc. A complete list of all resources supported by near real-time alerting can be found here in our documentation. Azure Monitor is also enabling new metrics and logs to be surfaced from many services such as, Networking, Storage, Traffic Manager, Network Interfaces, Express Routes, Load Balancers, Data Lake Store, Data Lake Analytics, etc. A complete list of all the resources and their metrics available via Azure Monitor can be found here in our documentation.

Also released for Azure Monitor is a public preview of a completely revised metrics exploration experience that now supports rendering charts for both multi-dimensional and basic metrics. You can plot charts overlaying metrics from different resources and simultaneously view multiple charts to visually correlate trends, spikes and dips in metrics values. For the resources that support multi-dimensional metrics (e.g. Application Insights or Storage), you can apply filters on the desired dimension/value combinations, and/or add grouping to see a line for each dimension value.

 

Azure Monitor is enabling integration with your IT Service Management (ITSM) tool of choice (System Center Service Manager, Service Now, Provance or Cherwell) through the new ITSM action in Action groups. The ITSM action enables users to automatically create work items (incidents, events or alerts) in their ITSM tool when an Azure alert fires. This ITSM action is built on top of ITSM Connector Solution in Azure Log Analytics. Through the solution, customers can combine the power of help desk data (such as incidents and change requests) and log data (such as activity and diagnostic logs, performance and configuration changes) to mitigate incidents quickly.

New Log Analytics & Container Monitoring Solutions

Azure Application Insights and Azure Log Analytics are offering a public preview of cross-resource querying, which will allow users to query across multiple Application Insights applications or multiple Log Analytics workspaces. This will enable querying across multi-tiered or geo-distributed applications as well as across multiple logical infrastructure groups. The new and improved Log Analytics, whose upgrade rollout was launched a month ago, is now providing REST APIs for the new query language.

Container Monitoring Solution is now supported for Windows Kubernetes Environment providing container monitoring for performance, logs, events, and inventory as well as Kubernetes events. Helm, a package manager which helps, share, and use software built for Kubernetes, is getting the solution integrated, enabling customers to easily find and deploy Container Monitoring onto their Linux Kubernetes environment. With the GA of Service Fabric on Linux as a container orchestrator, Log Analytics will be capturing container monitoring information with the Azure Monitoring Agent.

Revamped user experience in Azure Application Insights

Application Insights has completely refreshed the user experience for Performance Monitoring and Failure Diagnostics (in public preview) to provide an interactive experience and show contextual insights. Customers can now quickly triage which specific end-user experiences are slow in production and visualize a duration distribution to get a holistic statistical view of both the good and the bad user experiences. Effective transitions to code level visibility (profiler) and diagnostic information on slow dependencies are only a click away.

With the new failure investigation experience, you can quickly identify and fix your top failing operations, exception types, failing dependencies behind their failures and see how end users are impacted.

Visual Studio Mobile Center announced that their users can now connect to Application Insights and continuously export a copy of all their usage telemetry events. From there, they can query and analyze their Mobile Center data with the richer set of capabilities that Application Insights provides around ad-hoc querying, filtering, segmentation, and richer usage analytics.

Get started today

Azure monitoring and analytics services help you to gain greater visibility into your environment with advanced data analysis and visualization, and make it easy to turn insights into action. Learn more about the capabilities of our Monitoring Solutions, and how they can help you reduce complexity for a hybrid cloud environment.
Quelle: Azure

The next generation of Azure IoT Suite accelerates IoT solutions

Two years ago, we announced the availability of Azure IoT Suite, a set of preconfigured solutions that deploy in minutes and help customers get started quickly and is customized to meet their needs. Since then, customers including The Hershey Company, Schneider Electric, Rolls Royce, and Sandvik have selected Azure IoT Suite to accelerate their business transformation through their IoT initiatives.

Today, we are excited to announce a new version of Azure IoT Suite’s Remote Monitoring preconfigured solution. Incorporating learnings from customers and partners, this new version is a fully operational IoT solution right out of the box. New features include:

Advanced scalability & extensibility: Listening to customers and partners, we’ve introduced a new scalable Microservices architecture that dramatically simplifies the ability to customize the solution to meet your needs.
Lower cost: We now provide two deployment options to match different needs:

Basic option to get started at a low cost
Standard version for production ready IoT solutions

Best of all, the basic option can be updated to Standard when needed.

New UI: A complete redesign of the user interface helps you visualize the capabilities of a production ready solution.
Flexible language support: We now support both Java and .NET programming languages.

The updated Remote Monitoring preconfigured solution also leverages the best of the existing preconfigured solutions including the ability to provision directly into your subscription within minutes, open source availability, and functionally comprehensive from device to business application.

Our redesigned user interface enables operators to perform the following tasks:

Visualize data on a rich dashboard for deep insights and solution status.
Configure rules and alarms over live IoT device telemetry.
Schedule device management jobs, including updates to software and configuration.
Provision your own custom physical or simulated devices.
Troubleshoot and remediate issues within your IoT device groups.

More options for developers and partners

Remote Monitoring is the first of our preconfigured solutions to leverage a microservices architecture available in both .NET and Java. Microservices have emerged as a prevalent pattern to achieve scale and flexibility, without compromising development speed. Microservices compartmentalize the code and provide well defined interfaces making the solution easier to understand and less monolithic. It also further expands options for partners that want to extend our current preconfigured solutions to build finished solutions that can be monetized.

Learn more

The Remote Monitoring solution is richly supplemented with how-to, tutorial, and GitHub developer documentation detailing the building, extending, and deploying of your changes.

View an interactive demo of the remote monitoring solution.
Provision the updated Remote Monitoring solution at www.azureiotsuite.com.

Quelle: Azure

Introducing SQL Vulnerability Assessment for Azure SQL Database and on-premises SQL Server!

I am delighted to announce the public preview of our latest security development from the Microsoft SQL product team, the new SQL Vulnerability Assessment (VA). SQL Vulnerability Assessment is your one-stop-shop to discover, track, and remediate potential database vulnerabilities. The VA preview is now available for Azure SQL Database and for on-premises SQL Server, offering you a virtual database security expert at your fingertips.

What is VA?

SQL Vulnerability Assessment (VA) is a new service that provides you with visibility into your security state, and includes actionable steps to investigate, manage, and resolve security issues and enhance your database fortifications. It is designed to be usable for non-security-experts. Getting started and seeing an initial actionable report takes only a few seconds.

Vulnerability Assessment report in the Azure portal.

This service truly enables you to focus your attention on the highest impact actions you can take to proactively improve your database security stature! In addition, if you have data privacy requirements, or need to comply with data protection regulations like the EU GDPR, then VA is your built-in solution to simplify these processes and monitor your database protection status. For dynamic database environments where changes are frequent and hard to track, VA is invaluable in detecting the settings that can leave your database vulnerable to attack.

VA offers a scanning service built into the Azure SQL Database service itself, and is also available via SQL Server Management Studio (SSMS) for scanning SQL Server databases. The service employs a knowledge base of rules that flag security vulnerabilities and deviations from best practices, such as misconfigurations, excessive permissions, and exposed sensitive data. The rule base is founded on intelligence accrued from analyzing millions of databases, and extracting the security issues that present the biggest risks to your database and its valuable data. These rules also represent a set of requirements from various regulatory bodies to meet their compliance standards, which can contribute to compliance efforts. The rule base grows and evolves over time, to reflect the latest security best practices recommended by Microsoft.

Results of the assessment include actionable steps to resolve each issue and provide customized remediation scripts where applicable. An assessment report can be customized for each customer environment and tailored to specific requirements. This process is managed by defining a security baseline for the assessment results, such that only deviations from the custom baseline are reported.

How does VA work?

We designed VA with simplicity in mind. All you need to do is to run a scan, which will scan your database for vulnerabilities. The scan is lightweight and safe. It takes a few seconds to run, and is entirely read-only. It does not make any changes to your database!

When your scan is complete, your scan report will be automatically displayed in the Azure Portal or in the SSMS pane:

Vulnerability Assessment report in SSMS. Currently available in limited preview.

The scan results include an overview of your security state, and details about each security issue found. You will find warnings on deviations from security best practices, as well as a snapshot of your security-related settings, such as database principals and roles, and their associated permissions. In addition, scan results provide a map of sensitive data discovered in your database with recommendations of the built-in methods available to protect it.

For all the issues found, you can view details on the impact of the finding, and you will find actionable remediation information to directly resolve the issue. VA will focus your attention on security issues relevant to you, as your security baseline ensures that you are seeing relevant results customized to your environment. See “Getting Started with Vulnerability Assessment” for more details.

You can now use VA to monitor that your database maintains a high level of security at all times, and that your organizational policies are met. In addition, if your organization needs to meet regulatory requirements, VA reports can be helpful to facilitate the compliance process.

Get started today!

We encourage you to try out Vulnerability Assessment today, and start proactively improving your database security stature. Track and monitor your database security settings, so that you never again lose visibility and control of potential risks to the safety of your data.

Check out “Getting Started with Vulnerability Assessment” for more details on how to run and manage your assessment.

Try it out, and let us know what you think!
Quelle: Azure

Azure Data Factory – announcing new capabilities in public preview

This week at Ignite, we announced new capabilities in Azure Data Factory (ADF) service available in public preview for customers. Azure user preview terms of use can be found here. These new capabilities in ADF will enable you to build hybrid data integration at scale. Now you can create, schedule, and orchestrate your ETL/ELT workflows, wherever your data lives, in the cloud or on any self-hosted network. Meet security and compliance needs while taking advantage of extensive capabilities and paying only for what you use. Accelerate your data integration with multiple data source connectors natively available in-service. SQL Server Integration Services (SSIS) customers will benefit from easily lifting their SSIS packages into the cloud using new managed SSIS hosting capabilities in Data Factory.

We have taken the first steps to separate Control Flow and Data Flow within ADF to provide greater control over complex orchestrations that now facilitate looping, branching, and conditional structures within Control Flow. We have added new flexibility to scheduling by enabling triggering with wall-clock timers or on-demand via event generation. Parameters can now be defined and passed while invoking pipelines to enable incremental data loads.

Full details of the release and features can be found on the Azure Data Factory service page. We encourage you to try these new capabilities, available at public preview pricing.
Quelle: Azure

Announcing the public preview for Azure File Sync

Extend your on-premises file servers to Azure Files with Azure File Sync

Since Azure Files became generally available, we’ve consistently heard from our customers that they want to embrace the power and flexibility of the cloud without giving up the locality of their on-premises file server. Today, we are excited to announce the preview of a great new feature in Azure Files that enables you to get the best of both the cloud and on-premises worlds: Azure File Sync.

Azure File Sync keeps your Azure File share in-sync with your on-premises Window Servers. The real magic of Azure File Sync is the ability to tier files between your on-premises file server and Azure Files. This enables you to keep only the newest and most recently accessed files locally without sacrificing the ability to see and access the entire namespace through seamless cloud recall. With Azure File Sync, you can effectively transform your Windows File Server into an on-premises tier of Azure Files.

Since Azure File Sync is a multi-master sync solution, it makes it easy to solve global access problems introduced by having a single point of access on-premises, or in Azure by replicating data between Azure File shares and servers anywhere in the world. With Azure File Sync, we’ve introduced a very simple concept, the Sync Group, to help you manage the locations that should be kept in sync with each other. Every Sync Group has one cloud endpoint, which represents an Azure File share, and one or more server endpoints, which represents a path on a Windows Server. That’s it! Everything within a Sync Group will be automatically kept in sync!

Azure File Sync also helps you leverage Azure to get control over your on-premises data. Since cloud tiering moves old and infrequently accessed files to Azure, it effectively helps you make unpredictable storage growth predictable. When disasters strike, Azure File Sync can help. Simply set up a new Windows Server, install Azure File Sync, and the namespace is nearly instantly synced down as your cache is rebuilt.

Azure File Sync will be available, as a preview offering, this week (week of 9/25) – try it out! Please see our documentation for additional information about how to setup and configure Azure File Sync. If you are attending Ignite, come to our great sessions on Azure Files and Azure File Sync:

 

Session
Time
Place

BRK2286: Microsoft Azure File Sync – seamlessly extend file services across servers and cloud

Tuesday, September 26, 2017

10:45 AM – 12:00 PM ET

Hyatt Regency Windermere X

BRK2161: Maximize storage efficiency and conquer distributed file access with Windows Server and Azure Files

Tuesday, September 26, 2017

12:30 PM – 1:45 PM ET

OCCC West Hall F2

BRK2158: Windows Server Fall Release technical foundation

Wednesday, September 27th

10:45 AM – 12:00 PM ET

OCCC West Hall E1

THR2015: Microsoft Azure File Sync – setup, configuration, and management

Wednesday, September 27th

5:35 PM – 5:55 PM ET

TBD

Quelle: Azure

Azure DDoS Protection Service preview

This blog post was co-authored by JR Mayberr,y Principal PM Manager & Anupam Vij, Senior Program Manager, Azure Networking.

Distributed Denial of Service (DDoS) attacks are one of the top availability and security concerns voiced by customers moving their applications to the cloud. These concerns are justified as the number of documented DDoS attacks grew 380% in Q1 2017 over Q1 2016 according to data from Nexusguard. In October 2016, a number of popular websites were impacted by a massive cyberattack consisting of multiple denial of service attacks. It’s estimated that up to one third of all Internet downtime incidents are related to DDoS attacks.

As the types and sophistication of network attacks increases, Azure is committed to providing our customers with solutions that continue to protect the security and availability of applications on Azure. Security and availability in the cloud is a shared responsibility. Azure provides platform level capabilities and design best practices for customers to adopting and apply into application designs meeting their business objectives.

Today we're excited to announce the preview of Azure DDoS Protection Standard. This service is integrated with Virtual Networks and provides protection for Azure applications from the impacts of DDoS attacks.  It enables additional application specific tuning, alerting and telemetry features beyond the basic DDoS Protection which is included automatically in the Azure platform.  

Azure DDoS Protection Service offerings

Azure DDoS Protection Basic service

Basic protection is integrated into the Azure platform by default and at no additional cost. The full scale and capacity of Azure’s globally deployed network provides defense against common network layer attacks through always on traffic monitoring and real-time mitigation. No user configuration or application changes are required to enable DDoS Protection Basic.

Azure DDoS Protection Standard service

Azure DDoS Protection Standard is a new offering which provides additional DDoS mitigation capabilities and is automatically tuned to protect your specific Azure resources. Protection is simple to enable on any new or existing Virtual Network and requires no application or resource changes. Standard utilizes dedicated monitoring and machine learning to configure DDoS protection policies tuned to your Virtual Network. This additional protection is achieved by profiling your application’s normal traffic patterns, intelligently detecting malicious traffic and mitigating attacks as soon as they are detected. DDoS Protection Standard provides attack telemetry views through Azure Monitor, enabling alerting when your application is under attack. Integrated Layer 7 application protection can be provided by Application Gateway WAF.

Azure DDoS Protection Standard service features

Native Platform Integration

Azure DDoS Protection is natively integrated into Azure and includes configuration through the Azure Portal and PowerShell when you enable it on a Virtual Network (VNet).

Turn Key Protection

Simplified provisioning immediately protects all resources in a Virtual Network with no additional application changes required.

Always on monitoring

When DDoS Protection is enabled, your application traffic patterns are continuously monitored for indicators of attacks.

Adaptive tuning

DDoS protection understands your resources and resource configuration and customizes the DDoS Protection policy to your Virtual Network. Machine Learning algorithms set and adjust protection policies as traffic patterns change over time. Protection policies define protection limits, and mitigation is performed when actual network traffic exceeds the policies threshold.

L3 to L7 Protection with Application Gateway

Azure DDoS Protection service in combination with Application Gateway Web application firewall provides DDoS Protection for common web vulnerabilities and attacks.

Request rate-limiting
HTTP Protocol Violations
HTTP Protocol Anomalies
SQL Injection
Cross site scripting

DDoS Protection telemetry, monitoring & alerting

Rich telemetry is exposed via Azure Monitor including detailed metrics during the duration of a DDoS attack. Alerting can be configured for any of the Azure Monitor metrics exposed by DDoS Protection. Logging can be further integrated with Splunk (Azure Event Hubs), OMS Log Analytics and Azure Storage for advanced analysis via the Azure Monitor Diagnostics interface. 
  

Cost protection

When the DDoS Protection services goes GA, Cost Protection will provide resource credits for scale out during a documented attack.

Azure DDoS Protection Standard service availability

Azure DDoS Protection service is available now in East U.S., West U.S. and West Central U.S.

How do I get started?

DDoS Protection is in preview and there is no cost for the service during preview. Azure customers may register for the Azure DDoS Protection service here.

To learn more about the service, please see the Azure DDoS Protection service documentation.

We would love to hear your feedback, questions, comments through our regular channels including Forums, StackOverFlow, or Uservoice.
Quelle: Azure

New advancements in Azure for IT digital transformation

I'm at Ignite this week, where more than 20,000 of us are talking about how we can drive our businesses forward in a climate of constant technology change. We are in a time where technology is one of the core ways companies can better serve customers and differentiate versus competitors. It is an awesome responsibility. The pace of change is fast, and constant – but with that comes great opportunity for innovation, and true business transformation.

Here at Microsoft, our mission is to empower every person and every organization on the planet to achieve more. I believe that mission has a special meaning for the IT audience, particularly in the era of cloud computing. Collectively we are working with each of you to take advantage of new possibilities in this exciting time. That's the reason we are building Azure – for all of you. The trusted scale and resiliency of our Azure infrastructure, the productivity of our Azure services for building and delivering modern applications, and our unmatched hybrid capabilities, are the foundation that can help propel your business forward. With 42 regions announced around the world and an expansive network spanning more than 4,500 points of presence– we’re the backbone for your business.

Core Infrastructure

Cloud usage goes far beyond the development and test workloads people originally started with. Enterprises are driving a second wave of cloud adoption, including putting their most mission-critical, demanding systems in the cloud. We are the preferred cloud for the enterprise, with more than 90% of the Fortune 500 choosing the Microsoft cloud. Today at Ignite, we’re making several announcements about advancements in Azure infrastructure:

New VM sizes. We continue to expand our compute options at a rapid rate. In my general session, I will demonstrate SAP HANA running on both M-series and purpose-built infrastructure, the largest of their kind in the cloud. I will discuss the preview of the B-series VM for burstable workloads, and announce the upcoming Fv2-, NCv2-, ND-series which offer the innovation of new processor types like Intel’s Scalable Xeon and NVIDIA’s Tesla P100 and P40 GPUs.
The preview of Azure File Sync, offering secure, centralized file share management in the cloud. This new service provides more redundancy and removes complexity when it comes to sharing files, eliminating the need for special configuration or code changes.
A new enterprise NFS service, powered by NetApp. Building on the partnership with NetApp announced in June, Microsoft will deliver a first-party, native NFS v3/v4 service based on NetApp’s proven ONTAP® and other hybrid cloud data services, with preview available in early 2018. This service will deliver enterprise-grade data storage, management, security, and protection for customers moving to Microsoft Azure. We will also enable this service to advance hybrid cloud scenarios, providing visibility and control across Azure, on-premises and hosted NFS workloads. 
The preview of a new Azure networking service called Azure DDoS Protection, which helps protect publicly accessible endpoints from distributed denial of service (DDoS) attacks. Azure DDoS Protection learns an application’s normal traffic patterns and automatically applies traffic scrubbing when attacks are detected to ensure only legitimate traffic reaches the service.
The introduction of two new cloud governance services – Azure Cost Management and Azure Policy – to help you monitor and optimize cloud spend and cloud compliance. We are making Azure Cost Management free for Azure customers, and you can sign up now for a preview of Azure Policy. 
Integration of the native security and management experience. New updates in the Azure portal simplify the process of backing up, monitoring, and configuring diaster recovery for virtual machines. We are also announcing update management will now be free for Azure customers.
A preview of the new Azure Migrate service, which helps discover and migrate virtual machines and servers. The new service captures all on-premises applications, workloads, and data, and helps map migration dependencies over to Azure, making IT’s jobs immensely easier. Azure Migrate also integrates with the Database Migration Services we released today.
A preview of the new Azure Data Box, which provides a secure way to transfer very large datasets to Azure. This integrates seamlessly with Azure services like Backup and Site Recovery as well as partner solutions from CommVault, Netapp, Veritas, Veeam, and others.

Building on the news from last week about the preview of Azure Availability Zones, later today I will also talk about the unique measures we are taking in Azure to help customers ensure business continuity. As the only cloud provider with single VM SLAs, 21 announced region pairs for disaster recovery, Azure offers differentiated rich high availability and disaster recovery capabilities. This means you have the best support, resiliency, and availability for your mission-critical workloads.

Modern Applications

Applications are central to every digital transformation strategy. One of the compelling and more recent technologies that is helping in the modernization of applications is containers. Having received more attention from developers to date, containers are now accelerating application deployment and streamlining the way IT operations and development teams collaborate to deliver applications. Today we are announcing even more exciting advancements in this space:

Windows Server containers were introduced with Windows Server 2016. The first Semi-Annual Channel release of Windows Server, version 1709, introduces further advances in container technology, including an optimized Nano Server Container image (80% smaller!), new support for Linux containers on Hyper-V, and the ability to run native Linux tools with the Windows Subsystem for Linux (aka Bash for Windows).
Azure supports containers broadly, offering many options to deploy, from simple infrastructure to richly managed. Azure Container Instances (ACI) provide the simplest way to create and deploy new containers in the cloud with just a few simple clicks, and today I’m announcing Azure Container Instances now support Windows Server in addition to Linux.
Azure Service Fabric offers a generalized hosting and container orchestration platform designed for highly scalable applications, and today we are announcing the general availability of Linux support.

Hybrid Cloud

Nearly 85 percent of organizations tell us they have a cloud strategy that is hybrid, and even more – 91 percent – say they believe that hybrid cloud will be a long-term approach. Hybrid cloud capabilities help you adopt the cloud faster. What is unique about Microsoft’s hybrid cloud approach is that we build consistency between on-premises and the cloud. Consistency helps take the complexity of hybrid cloud out because it means you don’t need two different systems for everything. We build that consistency across identity, data, development, and security and management. Today we’re advancing our hybrid cloud leadership even further via the following developments:

Azure Stack is now shipping from our partners Dell EMC, Hewlett Packard Enterprise (HPE) and Lenovo. You can see all of these integrated systems on the show floor at Ignite. As an extension of Azure, Azure Stack brings the agility and fast-paced innovation of cloud computing to on-premises environments. Only Azure Stack lets you deliver Azure services from your organization’s datacenter, while balancing the right amount of flexibility and control – for truly-consistent hybrid cloud deployments.
Our fully managed Azure SQL Database service now has 100 percent SQL Server compatibility for no code changes via Managed Instance. And today, we are introducing a new Azure Database Migration Service that enables a near-zero downtime migration. Now customers can migrate all of their data to Azure without hassle or high cost.
Azure Security Center can now be used to secure workloads running on-premises and in other clouds. We’re also releasing today new capabilities to better defend against threats and respond quickly, including Just in Time (JIT) access, dynamic app whitelisting, and being able to drill down into an attack end to end with interactive investigation paths and mapping.

Beyond all of the product innovation above, one of the areas I’m proud of is the work we’re doing to save customers money. For example, the Azure Hybrid Benefit for Windows Server and the newly announced Azure Hybrid Benefit for SQL Server allow customers to use their existing licenses to get discounts in Azure, making Azure the most economical choice and path to the cloud for these customers. Together with the new Azure Reserved VM Instances we just announced, customers will be able to save up to 82 percent on Windows Server VMs. The free Azure Cost Management capabilities I mentioned above help customers save money by optimizing how they run things in Azure. And we are now offering the new Azure free account which introduces the free use of many popular services for 12 months, in addition to the $200 free credit we provide.

It’s an exciting time for IT, and we’re equally excited that you are our trusted partners in this era of digital transformation. I look forward to hearing your questions or feedback so that we can further your trust in us and empower each of you to achieve more.
Quelle: Azure

Your future cloud is hybrid, and so is Azure

When we talk to our customers about their cloud strategy, it comes through loud and clear: they need choice and flexibility in where to run their workloads and applications. There’s no question companies are rapidly turning to the cloud and seizing the opportunities it brings – increased agility, faster innovation, just to name a few. The conversation is rarely “all cloud or nothing.” In fact, for most enterprises, or highly regulated industries, it’s a hybrid approach to cloud that makes the most sense.

Customers choose hybrid to future-proof their cloud strategies

Hybrid cloud made a great deal of sense to our customers like CarMax, who needed to reduce latency between their corporate data center and store locations. It made sense to Willis Towers Watson, who leveraged an on-premises data warehouse together with Azure to perform compute intensive analysis. It made sense to AVID, an Emmy Award-winning entertainment and media solutions company, who built an innovative media processing solution for global broadcasting corporations using a hybrid cloud approach for fast processing in local newsrooms.

The conversation around hybrid cloud continues to evolve. Hybrid is essential in a world of AI and IoT as we move towards an Intelligent Cloud and Intelligent Edge working together. A distributed hybrid cloud enables a future-proof, long-term approach – which is exactly why we see it playing a central role in cloud strategies for the foreseeable future. We asked 2,500 IT professionals about their approach to cloud, and 91 percent of these IT workers believe hybrid cloud will remain the approach for their organizations five years from now.
 
Recently, other major cloud players have finally started listening to customers and admitted the need to offer hybrid solutions. Azure has always been hybrid by design, based on our decades of enterprise experience. We stand alone in offering a hybrid cloud experience that is consistent across on-premises and the cloud. Meanwhile, cobbled-together partnerships like AWS and VMWare (and others) fundamentally miss the ability of hybrid to meet customer needs, and the great value of this model to customers.

Let’s talk about what hybrid is, and isn’t

Hybrid is the future of cloud. One of the most promising things about cloud is the application innovation that new approaches like containers, microservices, serverless, and platform-as-a-service enable. The arrival of Azure Stack, just one of our many solutions to help advance hybrid scenarios, is an absolute game-changer. It enables a consistent development experience for cloud-native and traditional applications, with the flexibility to deploy in the cloud, on-premises, or at the edge.

Microsoft has set the bar in terms of hybrid – we’re proud of it. The consistency of our hybrid approach is exactly why customers find it appealing. When we say consistency, we do mean consistency across data, management, identity, and security. Customers must secure and manage their data and users across both the cloud and on-premises, and not having multiple systems helps reduce complexity.

True hybrid cloud helps address customer requirements around industry regulations, connectivity and latency. Regulation might evolve, but it won’t go away. The speed of light won’t get faster. And, geopolitical environments will always be dynamic. Our customers tell us a hybrid approach to cloud also lets them use existing on-premises technology as an asset in digital transformation as opposed to treating them as purely legacy investments.

Hybrid is not taking the virtualization customers have historically done and putting it into someone else’s data center. That’s why the AWS and VMWare offer as hybrid fails to address the real reason hybrid cloud is attractive to customers – and customers are left with the complexity of two vendors, two platforms, two portals and so on.

New customer-focused hybrid solutions at Ignite 2017

This week at Ignite we’re excited to continue the conversation about hybrid cloud with many of you. We’ll showcase our hybrid capabilities and announce new updates. You’ll hear about Azure Stack shipping, the extension of Azure Security Center to hybrid environments, and a new fully-automated Database Migration Service, and the GA of SQL Server 2017 – the first born in the cloud database that’s also available on-premises on Linux, Windows Server and Docker containers.

At Microsoft, we’ve always been passionate about the value of hybrid cloud. Our enterprise roots run deep and we look forward to continuing to bring you game-changing hybrid solutions as you transform your business.
Quelle: Azure