Get insights into your Azure #CosmosDB: partition heatmaps, OMS, and more

Transparency is an important virtue of any cloud service. Azure Cosmos DB is the only cloud service that offers 99.99% SLAs on availability, throughput, consistency, and <10ms latency, and we transparently show you metrics on how we perform against this promise. Over the past year, we have made a number of investments to help you monitor and troubleshoot your Azure Cosmos DB workloads. Today we're announcing a few more metrics we added recently, as well as integration of our metrics with the Azure Monitor, OMS, and a preview of Diagnostics logs.

Elastic scale, partition key heatmaps, and "hot" partitions

Azure Cosmos DB offers limitless elastic scale. We don't ask you how many VMs or instances you want, etc. Instead, we just ask you how much throughput you need, and we transparently and elastically scale your collections as your data grows. To enable elastic scale, we ask you what partition key you would like us to use.

The latter is a very important piece of information. Our promise to you is: if you select a partition key that has data evenly distributed over the partition key value space, we will ensure that you're taking advantage of the entire provisioned throughput. However, if all your records come in with the same partition key value, say you forgot to set it, so the value is null, you will only get 1/Nth of the provisioned throughput, where N is the current number of physical partitions created for your collection. So, if you provisioned 10000 RU/s for your collection that has 10 physical partitions, did not choose the partition key wisely, you may end up with only 1000 RU/s provisioned throughput available for your requests.

How do you know if your partition key choice is good? We help you figure it out in three simple steps.

Check if your operations are getting throttled. Look at the "Requests exceeding capacity" chart on the throughput tab.
Check if consumed throughput exceeds the provisioned throughput on any of the physical partitions (partition key ranges), by looking at the "Max RU/second consumed per partition" metric.
Select the time where the maximum consumed throughput per partitions exceeded provisioned on the chart "Max consumed throughput by each partition" to investigate the per-partition distribution of the consumed throughput at that time.

Sometimes it’s also helpful to look at the data distribution across partitions. You can see this chart on the storage tab. You can click on individual partition key ranges and find out the dominant partition keys in that range. You can further select a key and click “Open in Data Explorer” to see the corresponding data.

Here is a quick Azure Friday video on this topic:

For more information on using the new metrics, see Monitoring and debugging with metrics in Azure Cosmos DB.

Database audit and OMS integration

We are excited to announce Diagnostics Logs for data plane operations, which enable you to get a full audit of who accessed your Azure Cosmos DB collections and when. In the Azure portal, navigate to the Diagnostics Log menu on the left navigation bar, select your Azure Cosmos DB account, and turn the diagnostics log on. You can also export these logs to an Azure Storage account, stream them to an Event Hub, or send them to Log Analytics and an Operations Management Suite. For instructions on turning on diagnostic logs, see Azure Cosmos DB diagnostic logging.

Azure Monitor

Today we also announced the availability of a subset of Azure Cosmos DB metrics via Azure Monitor API. Now you can use tools like Grafana to access your metrics, with Operations Management Suite integration coming soon.

Play with Azure Cosmos DB and let us know what you think

Azure Cosmos DB is the database of the future. It’s what we believe to be the next big thing in the world of massively scalable databases! It makes your data available close to where your users are, worldwide. It is a globally distributed, multi-model database service for building planet-scale apps with ease, using the API and data model of your choice. You can try Azure Cosmos DB for free today, no subscription or credit card required.

If you need any help or have questions or feedback, please reach out to us on the developer forums on Stack Overflow. Stay up-to-date on the latest Azure Cosmos DB news and features by following us on Twitter using #CosmosDB, or @AzureCosmosDB.

– Your friends at Azure Cosmos DB
Quelle: Azure

A new Planned Maintenance experience for your virtual machines

We’re excited to announce the availability of a new planned maintenance experience in Azure, providing you more control, better communication, and better visibility. While most planned maintenance is performed without any impact to your virtual machines using memory preserving maintenance, some do require a reboot to improve reliability, performance, and security.

What’s new?

More control: You now have the option to proactively initiate a redeploy of your VMs on your schedule within a pre-communicated window, ensuring that planned maintenance will be performed when it is most convenient for you.

Better communication: We added planned maintenance to the Azure Monitor experience where you can create log-based alerts. With Azure Monitor notifications, you can add multiple email recipients to maintenance alerts, receive SMS messages, and configure webhooks, which integrate with your third-party software, to alert you of upcoming maintenance.

Better visibility: We recently introduced Azure Service Health in the Azure Portal, which provides you planned maintenance information at the VM level. Additionally, we introduced Scheduled Events, which surfaces information, including upcoming planned maintenance, via REST API in the VM. You can use this capability as part of maintenance preparation. Lastly you can view upcoming maintenance information via PowerShell and CLI.

Why should I consider proactive-redeploy?

During a communicated window, customers can choose to start maintenance on their virtual machines. If you do not utilize the window, the virtual machines will be rebooted automatically during a scheduled maintenance window (which is visible to you). Starting the maintenance will result in the VM being redeployed to an already-updated host. While doing so, the content of the local (temporary) drive will be lost.

Native cloud applications running in a cloud service, availability set, or virtual machines scale set, are resilient to planned maintenance since only a single update domain is impacted at any given time.

You may want to use proactive-redeploy in the following cases:

Your application runs on a single virtual machine and you need to apply maintenance during off-hours.
You need to coordinate the time of the maintenance as part of your SLA.
You need more than 30 minutes between each VM restart even within an availability set.
You wish to take down the entire application (multiple tiers, multiple update domains) in order to complete the maintenance faster.

What should I do next?

Prior to the next planned maintenance in Azure:

Become familiar with how to proactively redeploy your VMs on Windows and Linux.

Create alerts and notifications in Azure Monitor.

Set up Scheduled Events for your Windows and Linux VMs.

For more information:

Watch Azure Friday on Planned Maintenance.

Watch Tuesdays with Corey on Planned Maintenance.

Quelle: Azure

Provisioning for true zero-touch secure identity management for IoT

When you’re on a mission to deliver an awesome, complex IoT experience, the last thing you want to be doing is babysitting device identities at any stage of your solution. If you’re building a smart vehicle experience, you want to be thinking fleets, services, operational telemetry and not how to transfer vehicle identities between owners, renters, insurance companies, and service providers. If you’re developing for a mobile factory experience like a cruise ship or an airline, you want to be thinking geography optimal predictive maintenance, and not about cloud connection points and sovereign cloud specific requirements. How you provision your IoT devices makes a world of a difference with operational efficiency. Provisioning for true zero-touch secure identity management is the promise to minimize operational burden and maximize focus on the experience.

Until now, most claims for zero-touch provisioning have been about giving devices identities to connect to a cloud. What happens thereafter has largely been a mystery relegated to the IoT solutions developer. Developers of complex solutions are often left with no choice but to hack custom accommodations for their backends or manually manage hand-off of device identities in operations. Both options are costly, burdensome, and most of all, detracts focus from envisioned experience. Shouldn’t secure device identity and complete lifecycle management be a scalable building block in the IoT solution developer’s toolbox, so they can focus on just IoT experience?

Well, we believe it should. Microsoft has been building towards answering this very question, and in the past few months, collaborated with partners to make this a reality. The solution originates with anchoring trust in secure silicon, from which standards are used to derive device unique certificate identities that are ingested, authenticated, and lifecycle managed at scale by Azure Device Provisioning Service (DPS).

Earlier this year, as part of Microsoft’s commitment to IoT security, we announced adoption of Trusted Computing Group’s DICE standard and new HSM partners committed to availing DICE hardware. We now extend this announcement to welcome Microchip into the fold. Microchip has made availability of DICE hardware a reality through its CEC1702 family of secure silicon chips and evaluation kit offering. You may also learn about this offering from the Azure IoT Catalog and purchase directly from the Microchip Website. Designed for security and trust from the ground up, CEC1702 roots trust in secure silicon hardware and implements the DICE standard to generate device unique certificate identities that are trusted by any cloud service including Azure DPS.

Azure DPS takes it from here to fully realize provisioning for a truly zero-touch secure identity management for the lifecycle of IoT devices. DPS extends trust from the secure silicon hardware into the cloud domain where it creates registries to facilitate managed identity services to include location, mapping, aging, and retirement. This wealth of capability is exposed to the IoT solutions developers as simple routing rules to keep their full attention on the IoT experience they are creating. They only need to add a DPS compliant secure hardware like CEC1702 into their IoT devices.

IoT has evolved to the stage where connecting to a cloud is no longer a novelty. Secured and lifecycle-managed device identity should just be another component of the IoT developers standard toolbox. Microsoft in collaboration with secure silicon partners is making this a reality. To learn more about Azure Device Provisioning Service, please visit our tutorial documentation. 
Quelle: Azure

Announcing general availability of the new App Service Premium Plan

Today, we’re excited to announce the general availability of the new Premium plan from Azure App Service that runs on Dv2-series VMs. 

Azure App Service allows you to quickly build, deploy, and scale enterprise-grade web, mobile, and API apps running on any platform. Applications and services running on App Service can meet rigorous performance, scalability, security, and compliance requirements while leveraging a fully-managed platform to take care of infrastructure maintenance. This update brings additional horsepower to your applications.  

Two months ago, we announced the preview of the new Premium tier for Azure App Service featuring Dv2-series VMs with faster processors, SSD storage, and doubled memory-to-core ratio when compared to the previous instances. Today, the new Premium plan is generally available. 

It puts more application performance at your disposal. You can use it to build mission-critical applications faster, taking advantage of App Service’s enterprise grade capabilities including high availability with geo-distributed deployments, securing apps with Azure Active Directory (AAD) integration, and built-in SSL support. It runs on a cloud platform that complies with ISO information security standards, SOC2 accounting standards, and PCI security standards, just to name a few.

Getting started with the new Premium tier is easy. You can leverage Azure Resource Manager (ARM) templates, Azure Command Line Interface (CLI) scripts, or the Azure Portal user interface to configure a performant, scalable, and reliable environment in seconds.

We are excited about the addition of the newer, faster hardware underpinning the new Premium tier. To learn more, check out the documentation for the new App Service Premium tier. You can also provide your feedback in the App Service feedback forum.
Quelle: Azure

End-to-end monitoring solutions in Azure for Apps and Infrastructure

Today at the Ignite 2017 conference in Florida, we announced a range of new monitoring and analytics capabilities in Azure bringing together application and infrastructure monitoring in a unified curated overview in Azure Monitor. We are significantly optimizing your experience with the new log analytics, metrics exploration, application performance monitoring and failure investigations. We also announced integration of Azure alerts with IT Service Management tools and new solutions for Container Monitoring.

Bringing together monitoring services in Azure Monitor

From Azure Monitor you can now get at-a-glance reporting on the health and performance of all your cloud resources, from virtual machines to applications to individual lines of codes in the applications. Azure Monitor will now offer in public preview a unified overview as a starting point for navigation and on-boarding to various monitoring services in Azure. Customers will be able to see notable issues across applications & infrastructure in a single place and navigate to them in context.

Azure Monitor will now provide near real-time alerting in public preview for platform metrics from Azure services such as Virtual Machines, Networking, ServiceBus, EventHubs, etc. A complete list of all resources supported by near real-time alerting can be found here in our documentation. Azure Monitor is also enabling new metrics and logs to be surfaced from many services such as, Networking, Storage, Traffic Manager, Network Interfaces, Express Routes, Load Balancers, Data Lake Store, Data Lake Analytics, etc. A complete list of all the resources and their metrics available via Azure Monitor can be found here in our documentation.

Also released for Azure Monitor is a public preview of a completely revised metrics exploration experience that now supports rendering charts for both multi-dimensional and basic metrics. You can plot charts overlaying metrics from different resources and simultaneously view multiple charts to visually correlate trends, spikes and dips in metrics values. For the resources that support multi-dimensional metrics (e.g. Application Insights or Storage), you can apply filters on the desired dimension/value combinations, and/or add grouping to see a line for each dimension value.

 

Azure Monitor is enabling integration with your IT Service Management (ITSM) tool of choice (System Center Service Manager, Service Now, Provance or Cherwell) through the new ITSM action in Action groups. The ITSM action enables users to automatically create work items (incidents, events or alerts) in their ITSM tool when an Azure alert fires. This ITSM action is built on top of ITSM Connector Solution in Azure Log Analytics. Through the solution, customers can combine the power of help desk data (such as incidents and change requests) and log data (such as activity and diagnostic logs, performance and configuration changes) to mitigate incidents quickly.

New Log Analytics & Container Monitoring Solutions

Azure Application Insights and Azure Log Analytics are offering a public preview of cross-resource querying, which will allow users to query across multiple Application Insights applications or multiple Log Analytics workspaces. This will enable querying across multi-tiered or geo-distributed applications as well as across multiple logical infrastructure groups. The new and improved Log Analytics, whose upgrade rollout was launched a month ago, is now providing REST APIs for the new query language.

Container Monitoring Solution is now supported for Windows Kubernetes Environment providing container monitoring for performance, logs, events, and inventory as well as Kubernetes events. Helm, a package manager which helps, share, and use software built for Kubernetes, is getting the solution integrated, enabling customers to easily find and deploy Container Monitoring onto their Linux Kubernetes environment. With the GA of Service Fabric on Linux as a container orchestrator, Log Analytics will be capturing container monitoring information with the Azure Monitoring Agent.

Revamped user experience in Azure Application Insights

Application Insights has completely refreshed the user experience for Performance Monitoring and Failure Diagnostics (in public preview) to provide an interactive experience and show contextual insights. Customers can now quickly triage which specific end-user experiences are slow in production and visualize a duration distribution to get a holistic statistical view of both the good and the bad user experiences. Effective transitions to code level visibility (profiler) and diagnostic information on slow dependencies are only a click away.

With the new failure investigation experience, you can quickly identify and fix your top failing operations, exception types, failing dependencies behind their failures and see how end users are impacted.

Visual Studio Mobile Center announced that their users can now connect to Application Insights and continuously export a copy of all their usage telemetry events. From there, they can query and analyze their Mobile Center data with the richer set of capabilities that Application Insights provides around ad-hoc querying, filtering, segmentation, and richer usage analytics.

Get started today

Azure monitoring and analytics services help you to gain greater visibility into your environment with advanced data analysis and visualization, and make it easy to turn insights into action. Learn more about the capabilities of our Monitoring Solutions, and how they can help you reduce complexity for a hybrid cloud environment.
Quelle: Azure

The next generation of Azure IoT Suite accelerates IoT solutions

Two years ago, we announced the availability of Azure IoT Suite, a set of preconfigured solutions that deploy in minutes and help customers get started quickly and is customized to meet their needs. Since then, customers including The Hershey Company, Schneider Electric, Rolls Royce, and Sandvik have selected Azure IoT Suite to accelerate their business transformation through their IoT initiatives.

Today, we are excited to announce a new version of Azure IoT Suite’s Remote Monitoring preconfigured solution. Incorporating learnings from customers and partners, this new version is a fully operational IoT solution right out of the box. New features include:

Advanced scalability & extensibility: Listening to customers and partners, we’ve introduced a new scalable Microservices architecture that dramatically simplifies the ability to customize the solution to meet your needs.
Lower cost: We now provide two deployment options to match different needs:

Basic option to get started at a low cost
Standard version for production ready IoT solutions

Best of all, the basic option can be updated to Standard when needed.

New UI: A complete redesign of the user interface helps you visualize the capabilities of a production ready solution.
Flexible language support: We now support both Java and .NET programming languages.

The updated Remote Monitoring preconfigured solution also leverages the best of the existing preconfigured solutions including the ability to provision directly into your subscription within minutes, open source availability, and functionally comprehensive from device to business application.

Our redesigned user interface enables operators to perform the following tasks:

Visualize data on a rich dashboard for deep insights and solution status.
Configure rules and alarms over live IoT device telemetry.
Schedule device management jobs, including updates to software and configuration.
Provision your own custom physical or simulated devices.
Troubleshoot and remediate issues within your IoT device groups.

More options for developers and partners

Remote Monitoring is the first of our preconfigured solutions to leverage a microservices architecture available in both .NET and Java. Microservices have emerged as a prevalent pattern to achieve scale and flexibility, without compromising development speed. Microservices compartmentalize the code and provide well defined interfaces making the solution easier to understand and less monolithic. It also further expands options for partners that want to extend our current preconfigured solutions to build finished solutions that can be monetized.

Learn more

The Remote Monitoring solution is richly supplemented with how-to, tutorial, and GitHub developer documentation detailing the building, extending, and deploying of your changes.

View an interactive demo of the remote monitoring solution.
Provision the updated Remote Monitoring solution at www.azureiotsuite.com.

Quelle: Azure

Introducing SQL Vulnerability Assessment for Azure SQL Database and on-premises SQL Server!

I am delighted to announce the public preview of our latest security development from the Microsoft SQL product team, the new SQL Vulnerability Assessment (VA). SQL Vulnerability Assessment is your one-stop-shop to discover, track, and remediate potential database vulnerabilities. The VA preview is now available for Azure SQL Database and for on-premises SQL Server, offering you a virtual database security expert at your fingertips.

What is VA?

SQL Vulnerability Assessment (VA) is a new service that provides you with visibility into your security state, and includes actionable steps to investigate, manage, and resolve security issues and enhance your database fortifications. It is designed to be usable for non-security-experts. Getting started and seeing an initial actionable report takes only a few seconds.

Vulnerability Assessment report in the Azure portal.

This service truly enables you to focus your attention on the highest impact actions you can take to proactively improve your database security stature! In addition, if you have data privacy requirements, or need to comply with data protection regulations like the EU GDPR, then VA is your built-in solution to simplify these processes and monitor your database protection status. For dynamic database environments where changes are frequent and hard to track, VA is invaluable in detecting the settings that can leave your database vulnerable to attack.

VA offers a scanning service built into the Azure SQL Database service itself, and is also available via SQL Server Management Studio (SSMS) for scanning SQL Server databases. The service employs a knowledge base of rules that flag security vulnerabilities and deviations from best practices, such as misconfigurations, excessive permissions, and exposed sensitive data. The rule base is founded on intelligence accrued from analyzing millions of databases, and extracting the security issues that present the biggest risks to your database and its valuable data. These rules also represent a set of requirements from various regulatory bodies to meet their compliance standards, which can contribute to compliance efforts. The rule base grows and evolves over time, to reflect the latest security best practices recommended by Microsoft.

Results of the assessment include actionable steps to resolve each issue and provide customized remediation scripts where applicable. An assessment report can be customized for each customer environment and tailored to specific requirements. This process is managed by defining a security baseline for the assessment results, such that only deviations from the custom baseline are reported.

How does VA work?

We designed VA with simplicity in mind. All you need to do is to run a scan, which will scan your database for vulnerabilities. The scan is lightweight and safe. It takes a few seconds to run, and is entirely read-only. It does not make any changes to your database!

When your scan is complete, your scan report will be automatically displayed in the Azure Portal or in the SSMS pane:

Vulnerability Assessment report in SSMS. Currently available in limited preview.

The scan results include an overview of your security state, and details about each security issue found. You will find warnings on deviations from security best practices, as well as a snapshot of your security-related settings, such as database principals and roles, and their associated permissions. In addition, scan results provide a map of sensitive data discovered in your database with recommendations of the built-in methods available to protect it.

For all the issues found, you can view details on the impact of the finding, and you will find actionable remediation information to directly resolve the issue. VA will focus your attention on security issues relevant to you, as your security baseline ensures that you are seeing relevant results customized to your environment. See “Getting Started with Vulnerability Assessment” for more details.

You can now use VA to monitor that your database maintains a high level of security at all times, and that your organizational policies are met. In addition, if your organization needs to meet regulatory requirements, VA reports can be helpful to facilitate the compliance process.

Get started today!

We encourage you to try out Vulnerability Assessment today, and start proactively improving your database security stature. Track and monitor your database security settings, so that you never again lose visibility and control of potential risks to the safety of your data.

Check out “Getting Started with Vulnerability Assessment” for more details on how to run and manage your assessment.

Try it out, and let us know what you think!
Quelle: Azure

Azure Data Factory – announcing new capabilities in public preview

This week at Ignite, we announced new capabilities in Azure Data Factory (ADF) service available in public preview for customers. Azure user preview terms of use can be found here. These new capabilities in ADF will enable you to build hybrid data integration at scale. Now you can create, schedule, and orchestrate your ETL/ELT workflows, wherever your data lives, in the cloud or on any self-hosted network. Meet security and compliance needs while taking advantage of extensive capabilities and paying only for what you use. Accelerate your data integration with multiple data source connectors natively available in-service. SQL Server Integration Services (SSIS) customers will benefit from easily lifting their SSIS packages into the cloud using new managed SSIS hosting capabilities in Data Factory.

We have taken the first steps to separate Control Flow and Data Flow within ADF to provide greater control over complex orchestrations that now facilitate looping, branching, and conditional structures within Control Flow. We have added new flexibility to scheduling by enabling triggering with wall-clock timers or on-demand via event generation. Parameters can now be defined and passed while invoking pipelines to enable incremental data loads.

Full details of the release and features can be found on the Azure Data Factory service page. We encourage you to try these new capabilities, available at public preview pricing.
Quelle: Azure

Announcing the public preview for Azure File Sync

Extend your on-premises file servers to Azure Files with Azure File Sync

Since Azure Files became generally available, we’ve consistently heard from our customers that they want to embrace the power and flexibility of the cloud without giving up the locality of their on-premises file server. Today, we are excited to announce the preview of a great new feature in Azure Files that enables you to get the best of both the cloud and on-premises worlds: Azure File Sync.

Azure File Sync keeps your Azure File share in-sync with your on-premises Window Servers. The real magic of Azure File Sync is the ability to tier files between your on-premises file server and Azure Files. This enables you to keep only the newest and most recently accessed files locally without sacrificing the ability to see and access the entire namespace through seamless cloud recall. With Azure File Sync, you can effectively transform your Windows File Server into an on-premises tier of Azure Files.

Since Azure File Sync is a multi-master sync solution, it makes it easy to solve global access problems introduced by having a single point of access on-premises, or in Azure by replicating data between Azure File shares and servers anywhere in the world. With Azure File Sync, we’ve introduced a very simple concept, the Sync Group, to help you manage the locations that should be kept in sync with each other. Every Sync Group has one cloud endpoint, which represents an Azure File share, and one or more server endpoints, which represents a path on a Windows Server. That’s it! Everything within a Sync Group will be automatically kept in sync!

Azure File Sync also helps you leverage Azure to get control over your on-premises data. Since cloud tiering moves old and infrequently accessed files to Azure, it effectively helps you make unpredictable storage growth predictable. When disasters strike, Azure File Sync can help. Simply set up a new Windows Server, install Azure File Sync, and the namespace is nearly instantly synced down as your cache is rebuilt.

Azure File Sync will be available, as a preview offering, this week (week of 9/25) – try it out! Please see our documentation for additional information about how to setup and configure Azure File Sync. If you are attending Ignite, come to our great sessions on Azure Files and Azure File Sync:

 

Session
Time
Place

BRK2286: Microsoft Azure File Sync – seamlessly extend file services across servers and cloud

Tuesday, September 26, 2017

10:45 AM – 12:00 PM ET

Hyatt Regency Windermere X

BRK2161: Maximize storage efficiency and conquer distributed file access with Windows Server and Azure Files

Tuesday, September 26, 2017

12:30 PM – 1:45 PM ET

OCCC West Hall F2

BRK2158: Windows Server Fall Release technical foundation

Wednesday, September 27th

10:45 AM – 12:00 PM ET

OCCC West Hall E1

THR2015: Microsoft Azure File Sync – setup, configuration, and management

Wednesday, September 27th

5:35 PM – 5:55 PM ET

TBD

Quelle: Azure

Azure DDoS Protection Service preview

This blog post was co-authored by JR Mayberr,y Principal PM Manager & Anupam Vij, Senior Program Manager, Azure Networking.

Distributed Denial of Service (DDoS) attacks are one of the top availability and security concerns voiced by customers moving their applications to the cloud. These concerns are justified as the number of documented DDoS attacks grew 380% in Q1 2017 over Q1 2016 according to data from Nexusguard. In October 2016, a number of popular websites were impacted by a massive cyberattack consisting of multiple denial of service attacks. It’s estimated that up to one third of all Internet downtime incidents are related to DDoS attacks.

As the types and sophistication of network attacks increases, Azure is committed to providing our customers with solutions that continue to protect the security and availability of applications on Azure. Security and availability in the cloud is a shared responsibility. Azure provides platform level capabilities and design best practices for customers to adopting and apply into application designs meeting their business objectives.

Today we're excited to announce the preview of Azure DDoS Protection Standard. This service is integrated with Virtual Networks and provides protection for Azure applications from the impacts of DDoS attacks.  It enables additional application specific tuning, alerting and telemetry features beyond the basic DDoS Protection which is included automatically in the Azure platform.  

Azure DDoS Protection Service offerings

Azure DDoS Protection Basic service

Basic protection is integrated into the Azure platform by default and at no additional cost. The full scale and capacity of Azure’s globally deployed network provides defense against common network layer attacks through always on traffic monitoring and real-time mitigation. No user configuration or application changes are required to enable DDoS Protection Basic.

Azure DDoS Protection Standard service

Azure DDoS Protection Standard is a new offering which provides additional DDoS mitigation capabilities and is automatically tuned to protect your specific Azure resources. Protection is simple to enable on any new or existing Virtual Network and requires no application or resource changes. Standard utilizes dedicated monitoring and machine learning to configure DDoS protection policies tuned to your Virtual Network. This additional protection is achieved by profiling your application’s normal traffic patterns, intelligently detecting malicious traffic and mitigating attacks as soon as they are detected. DDoS Protection Standard provides attack telemetry views through Azure Monitor, enabling alerting when your application is under attack. Integrated Layer 7 application protection can be provided by Application Gateway WAF.

Azure DDoS Protection Standard service features

Native Platform Integration

Azure DDoS Protection is natively integrated into Azure and includes configuration through the Azure Portal and PowerShell when you enable it on a Virtual Network (VNet).

Turn Key Protection

Simplified provisioning immediately protects all resources in a Virtual Network with no additional application changes required.

Always on monitoring

When DDoS Protection is enabled, your application traffic patterns are continuously monitored for indicators of attacks.

Adaptive tuning

DDoS protection understands your resources and resource configuration and customizes the DDoS Protection policy to your Virtual Network. Machine Learning algorithms set and adjust protection policies as traffic patterns change over time. Protection policies define protection limits, and mitigation is performed when actual network traffic exceeds the policies threshold.

L3 to L7 Protection with Application Gateway

Azure DDoS Protection service in combination with Application Gateway Web application firewall provides DDoS Protection for common web vulnerabilities and attacks.

Request rate-limiting
HTTP Protocol Violations
HTTP Protocol Anomalies
SQL Injection
Cross site scripting

DDoS Protection telemetry, monitoring & alerting

Rich telemetry is exposed via Azure Monitor including detailed metrics during the duration of a DDoS attack. Alerting can be configured for any of the Azure Monitor metrics exposed by DDoS Protection. Logging can be further integrated with Splunk (Azure Event Hubs), OMS Log Analytics and Azure Storage for advanced analysis via the Azure Monitor Diagnostics interface. 
  

Cost protection

When the DDoS Protection services goes GA, Cost Protection will provide resource credits for scale out during a documented attack.

Azure DDoS Protection Standard service availability

Azure DDoS Protection service is available now in East U.S., West U.S. and West Central U.S.

How do I get started?

DDoS Protection is in preview and there is no cost for the service during preview. Azure customers may register for the Azure DDoS Protection service here.

To learn more about the service, please see the Azure DDoS Protection service documentation.

We would love to hear your feedback, questions, comments through our regular channels including Forums, StackOverFlow, or Uservoice.
Quelle: Azure