Azure Blueprint takes takes on DoD Level 4

I am pleased to announce the release of the Azure Blueprint for the Department of Defense (DoD). Azure Blueprint recently released documentation to streamline the path for Azure Government customers working with the Federal Risk and Authorization Management Program (FedRAMP) Moderate Baseline to attain Authorizations to Operate (ATO).

Azure Blueprint has expanded to support our DoD customers working in Azure Government to document their customer security responsibilities. The Azure Blueprint Customer Responsibilities Matrix (CRM) and System Security Plan (SSP) template can now be used by DoD mission owners and third-party providers building systems on behalf of DoD customers.

The DoD migration to the cloud has been guided by the Department of Defense Security Requirements Guide (SRG) Version 1 Release 2. All cloud systems must meet the security standards outlined in the SRG for use by DoD customers. The Cloud Computing SRG breaks down requirements into impact levels, covering specific data classifications that are adequately protected at each level.

As announced on June 23, 2016, Azure Government has been granted a provisional authorization (PA) at the DoD Impact Level 4 for processing of controlled unclassified information (CUI) and mission critical data. This includes export controlled data, protected health information, privacy information, and others (e.g. FOUO, SBU, etc.). Since that announcement, we have been working with DoD customers to help them understand the Azure Government security protections and work through their security responsibilities. Azure Blueprint now provides these DoD customers with a simplified way to understand the scope of their security responsibilities when architecting solutions in Azure.

We look forward to providing DoD L5 Azure Blueprints once we attain our Impact Level 5 PA for the Microsoft Azure Government DoD Regions and expanding our footprint as the most trusted cloud.

For any questions and to access to these documents, please e-mail AzureBlueprint@microsoft.com.

We welcome your comments and suggestions to help us continually improve your Azure Government experience. To stay up to date on all things Azure Government, be sure to subscribe to our RSS feed and to receive emails, click “Subscribe by Email!” on the Azure Government Blog. To experience the power of Azure Government for your organization, sign up for an Azure Government Trial.
Quelle: Azure

Azure Blueprint takes ATO processes to the next level

I am pleased to announce the release of the Azure Blueprint for the Department of Defense (DoD). Azure Blueprint recently released documentation to streamline the path for Azure Government customers working with the Federal Risk and Authorization Management Program (FedRAMP) Moderate Baseline to attain Authorizations to Operate (ATO).

Azure Blueprint has expanded to support our DoD customers working in Azure Government to document their customer security responsibilities. The Azure Blueprint Customer Responsibilities Matrix (CRM) and System Security Plan (SSP) template can now be used by DoD mission owners and third-party providers building systems on behalf of DoD customers.

The DoD migration to the cloud has been guided by the Department of Defense Security Requirements Guide (SRG) Version 1 Release 2. All cloud systems must meet the security standards outlined in the SRG for use by DoD customers. The Cloud Computing SRG breaks down requirements into impact levels, covering specific data classifications that are adequately protected at each level.

As announced on June 23, 2016, Azure Government has been granted a provisional authorization (PA) at the DoD Impact Level 4 for processing of controlled unclassified information (CUI) and mission critical data. This includes export controlled data, protected health information, privacy information, and others (e.g. FOUO, SBU, etc.). Since that announcement, we have been working with DoD customers to help them understand the Azure Government security protections and work through their security responsibilities. Azure Blueprint now provides these DoD customers with a simplified way to understand the scope of their security responsibilities when architecting solutions in Azure.

We look forward to providing DoD L5 Azure Blueprints once we attain our Impact Level 5 PA for the Microsoft Azure Government DoD Regions and expanding our footprint as the most trusted cloud.

For any questions and to access to these documents, please e-mail AzureBlueprint@microsoft.com.

We welcome your comments and suggestions to help us continually improve your Azure Government experience. To stay up to date on all things Azure Government, be sure to subscribe to our RSS feed and to receive emails, click “Subscribe by Email!” on the Azure Government Blog. To experience the power of Azure Government for your organization, sign up for an Azure Government Trial.
Quelle: Azure

Project Bletchley – Blockchain comes to Azure Marketplace

Only a couple weeks after our most recent update, I am pleased to be back to announce more great additions to our blockchain offering on Azure, in addition to new partner solutions.  We continue to expand on our blockchain infrastructural work to improve the services, tools, and best practices needed to design, build out, and manage complex consortium networks to develop new business applications.

This week we are excited to expand support of Bletchley v1 into the Azure Marketplace.  As you may recall, with the first phase of blockchain support on Azure, you can quickly and easily deploy a many-node consortium blockchain network.  With this release, you have all the same great functionality as with the original release in the Azure Quickstart templates, but with a more robust user experience directly integrated into the Azure portal.

Since we try to never release without new functionality, we have also added support for:

Dozen Consortium Members: You can now deploy a blockchain network that has a dozen consortium members.
Premium storage: To support low latency and high throughput applications, you can configure the nodes within the consortium network to leverage premium storage backed virtual machines.
Password or SSH key: To secure the nodes within your network, you can now specify an SSH key instead of a password.

For more information about the solution, you can visit our detailed walkthrough.

In addition to our solutions, we continue to grow our blockchain ecosystem on Azure.  We are excited to welcome many new exciting partner blockchain solutions in the Azure Marketplace, including:

​Chain: As announced last week, you can now deploy Chain&;s distributed ledger technology, Chain Core, on Azure.
Ethereum Studio: You can quickly set up ether.camp&039;s Ethereum stack, a full stack developer sandbox to develop and test Ethereum solutions, on Azure.

Try out all the latest blockchain releases and let us know if you have any question, feedback, or additional requests.  We are excited to continue on this journey with you.
Quelle: Azure

General availability: Azure cool blob storage in additional regions

Azure Blob storage accounts with hot and cool storage tiers are generally available in six new regions: US East, US West, Germany Central, Germany Northeast, Australia Southeast and Brazil South. You can find the updated list of available regions on the Azure services by region page.

Blob storage accounts are specialized storage accounts for storing your unstructured data as blobs (objects) in Azure Storage. With Blob storage accounts, you can choose between hot and cool storage tiers to store your less frequently accessed (cool) data at a lower storage cost, and store more frequently accessed (hot) data at a lower access cost.

Customers in the new regions can take advantage of the cost benefits of the cool storage tier for storing backup data, media content, scientific data, active archival data—and in general, any data that is less frequently accessed. For details on how to start using this feature, please see our getting-started documentation.

For details on regional pricing, see the Azure Storage pricing page.
Quelle: Azure

Azure Backup supports encrypted Azure virtual machines using Portal and PowerShell

Azure Backup already supports backup and restore of Classic and Resource Manager virtual machines and also premium storage VMs. Today, we are announcing support for backup and restore of encrypted Azure virtual machines using portal as well as PowerShell, available for VMs encrypted using Azure Disk Encryption.

Azure Disk Encryption solution helps protect customer data to meet their security and compliance commitments through a range of advanced technologies to encrypt, control and manage encryption keys, and audit access of data. Additionally various security requirements like key rollover and re-encryption of VMs make it more complex to maintain keys and secrets of these VMs. Azure Backup supports backup of encrypted VMs across all of these scenarios seamlessly and maintains security, privacy and sovereignty of enterprise data throughout the backup lifecycle.

Value Proposition

This feature provides:

Enhanced security: Since the keys and secrets of encrypted VMs are backed up in encrypted form, unauthorized users cannot read or use these backed up keys and secrets. Only users with right level of permissions can backup and restore encrypted VMs as well as keys and secrets.
Improved restores: Besides backing up and restoring encrypted VMs, latest keys and secrets associated with the VM are also backed up. So even if VM is restored after years and the keys are lost, the backed up version can be used to retrieve the VM. Learn more about how to restore keys and secrets using Azure Backup.
Simplified experience: With this capability, you can seamlessly backup and restore your encrypted VMs through a familiar and consistent experience.

Features

With this release, Azure Backup provides:

Backup of encrypted VMs using Key Encryption Key: The current capability supports backup of VMs encrypted using BitLocker Encryption Key (BEK) and Key Encryption Key (KEK) both. The BEK and KEK backed up will be stored in encrypted form so they can be read and used only when restored back to key vault by the right user.
Restore lost keys and secrets: Since KEK and BEK are backed up as well, users with right set of permissions will be able to restore keys and secrets, in case they are lost, back to the key vault and bring up the encrypted VM.
PowerShell: Customers can leverage Azure PowerShell to automate and perform backup and restore operations at scale.

Getting Started

To get started with backup of encrypted Azure VMs:

Create a recovery services vault, if it doesn’t exist. Open the recovery services vault.
Click on +Backup to start backing up encrypted VMs – Refer Backup and Restore of encrypted VMs documentation for more details.

To restore encrypted Azure VMs:

To restore encrypted VMs, use the steps mentioned in restore virtual machines in Azure portal documentation for more details.
To restore keys and secrets of encrypted VMs, use the steps mentioned in how to restore keys and secrets using Azure Backup for more details.

Related Links and Additional Content

Learn more about how to backup and restore encrypted Azure VMs
Getting started with Recovery Services vault
Learn more about Azure Backup
Want more details? Check out Azure Backup Documentation
Need help? Reach out to Azure Backup forum for support
Tell us how we can improve Azure Backup by contributing new ideas and voting up existing ones
Follow us on Twitter @AzureBackup for latest news and updates

Quelle: Azure

Azure Relay – cross-platform, open-protocol connections

The Azure Relay service was amongst the initial core set of services available on Azure, and is a fundamental hybrid cloud integration tool for many current solutions running on Azure. The Relay allows for secure and seamless communication bridging between cloud and on-premises assets, or even between different sites using the cloud as a matchmaker. The Relay operates at the application-level, allowing for traversal of network address translation (NAT) boundaries and firewalls and for endpoint discovery completely without requiring any intrusive changes to the networking environment.

The first great news we have for you today is that the Relay service, which is developed and maintained by the same team that brings you Event Hubs and Service Bus Messaging, is now (finally!) available for management and monitoring in the modern Azure Portal, and as a standalone service as Relay.

But we have even greater news.

Until today, the Azure Relay’s capabilities have required using a particular runtime and platform: the full .NET Framework running on Windows. Building relayed services required using the WCF communication framework. Over the years, we’ve done a lot of (often invisible) work to make these capabilities robust on the client and in the service, and we will continue to offer them under the WCF Relay feature name. If you’re using the Relay features today with WCF, nothing changes.

If you are building apps on platforms other than Windows and/or using you own choice of languages, runtimes, or frameworks – everything changes.

Today, we’re announcing and making available the public preview of the next generation cross-platform and open-protocol Azure Relay capabilities, named Hybrid Connections.

Hybrid Connections

Hybrid Connections evolution of the Relay is completely based on HTTPS and WebSockets, allowing you to securely connect resources and services residing behind a firewall in your on-premises setup with services in the cloud or other assets anywhere.

Being based on the WebSockets protocol and thus providing a secure, bi-directional, and binary communications channel unencumbered by particularities of specific frameworks, allows easy integration with many existing and modern RPC frameworks such as Apache Thrift, Apache Avro, Microsoft Bond, and many others. It is also a great foundation for stream communication bridges that allows relaying database, remote desktop or shell connections, to name just some examples.

Hybrid Connections leverages the robust security model of the Relay service, and provides the proven load balancing and failover capabilities that Relay solutions rely on today.

The initial set of samples and the client code is available for C# and JavaScript (Node) today on GitHub and we will provide more language bindings as we work towards general commercial availability. The C# samples already demonstrate integration with Thrift and Avro, and we’re inviting contributions and further RPC framework bindings with wide open arms. The full protocol documentation to make that possible is now available on Azure Documentation Center.

Hybrid Connections and BizTalk Services

It is also important to note that this Hybrid Connections feature is a newer, but separate version from the Hybrid Connections feature brought to you by BizTalk Services. That particular feature will continue to run as it does today with no change in billing and how you use it.
Quelle: Azure

Azure SQL Database: Now supporting up to 10 years of Backup Retention (Public Preview)

Does your application have compliance requirements to retain data for a long period of time? Or do you need to extend the built-in backup retention for oops recovery past 35 days? Now, with just a few clicks, you can easily enable your databases to have long-term retention. Azure SQL Database now supports backups stored in your own Azure Backup Service Vault. This allows you easily extend the built-it retention period from 35 days to up to 10 years.

Now supporting your data retention requirements is much simpler. Today Azure SQL Database automatically creates a full backup every week for each of your databases. Once you add the LTR policy to a database using Azure Portal or API, these weekly backups will be automatically copied to your own Azure Backup Service Vault. If your databases are encrypted with TDE, that&;s no problem — the backups are automatically encrypted at rest. The Services Vault will automatically delete your expired backups based on their timestamp, so there&039;s no need to to manage the backup schedule or worry about the cleanup of the old files. The following diagram shows how to add LTR policy in the Portal.

Get started with the Azure SQL Database long-term backup retention preview by simply selecting Azure Backup Service Vault for your SQL server in the Azure Portal and creating a retention policy for your database. The database backups will show up in the vault within seven days.

Learn more about Azure SQL Database backups
Quelle: Azure

New Azure Government Documentation

We are happy to announce Azure Government documentation! This documentation provides guidance that is tailored to our Azure Government customers. We highlight common solutions and guidance on building government specific implementations, as well as information that you need to know about using services, Marketplace, Portal and PowerShell in Azure Government. This is just the start! Many more updates are planned as we continually expand our offerings for Azure Government. As new services come online, we will update the corresponding documentation. Over the coming months we will add additional content on how to build solutions and onboard successfully. We encourage and welcome feedback and documentation requests you have. Please comment on this blog post with any questions, recommendations, or comments in relation to our new documentation site. Accessing the Documentation The content can be accessed via three easy ways: Navigate to the new Azure Government Landing Page through the secondary navigation bar.      2. Access the page directly at Azure Government documentation.      3. Select “Azure Government” from the Microsoft Documentation Articles cloud filter drop down menu. To stay up to date on all things Azure Government, be sure to subscribe to our RSS feed or receive emails by clicking “Subscribe by Email!” on the Azure Government Blog.
Quelle: Azure

Automated notifications from Azure Monitor for Atlassian JIRA

The public preview of Azure Monitor was recently announced at Ignite. This new platform service builds on some of the existing monitoring capabilities to provide a consolidated and inbuilt monitoring experience to all Azure users.

From within the Azure portal, you can use Azure Monitor to query across Activity Logs, Metrics and Diagnostic Logs. If you need the advanced monitoring and analytics tools like Application Insights, Azure Log Analytics and Operations Management Suite (OMS), the Azure Monitor blade contains quick links. You can also leverage the dashboard experience in the portal to visualize your monitoring data and share it with others in your team.

The consolidated Azure Monitor blade in the portal allows you to quickly and centrally manage alerts from the following sources:

Metrics
Events (eg. Autoscale events)
Locations (Application Insights Web Tests)
Proactive diagnostics (Application Insights)

These alerts can be configured to send an email and also in the case of the Metrics and Web Tests POST to a webhook. This allows for easy integration with external platforms.

Integrating Azure Monitor with Atlassian JIRA

Atlassian JIRA is a familiar solution to many IT, software and business teams. It&;s an ideal candidate for connecting to the Azure Monitor service via the webhook mechanism in order to create JIRA Issues from Metric and Web Test Alerts.

"Azure Notifications with JIRA marries critical operational events with JIRA issues to help teams stay on top of app performance, move faster, and streamline their DevOps processes," said Bryant Lee, head of product partnerships and integrations at Atlassian.

Add-ons can be built for JIRA, Confluence, HipChat and BitBucket to extend their capabilities. In order to make the process of deploying the add-on as easy as possible, we&039;ve built this Azure Notifications add-on to be deployed and hosted on an Azure Web App which is connected to your JIRA instance via the Manage add-ons functionality in the JIRA Administration screen. The add-on establishes a secret, key exchange and other private details with JIRA that is used to secure, sign and verify all future communication between the two. All of this security information is stored in Azure Key Vault.

The add-on exposes token secured endpoints that can be configured in Azure Monitor against the webhooks exposed for various alerting mechanisms. Alerts will flow from Azure Monitor into the token secured endpoints. The add-on will then transform the payloads from the Azure Monitor alerts and securely create the appropriate Issue in JIRA.

Relevant information is extracted from the Azure Monitor alerts and highlighted in the Issue. The full Azure Monitor alert payload is included for reference.

Deploying the add-on

The Azure Notifications for Atlassian JIRA add-on is available today in Bitbucket for you to deploy and connect your JIRA instance and Azure Monitor alerts. The overview section of the add-on&039;s repository provides documentation on the add-on and how to install it and all its associated infrastructure in Azure.

Once installed, the add-on will appear in your add-ons list in JIRA. You can then configure your Azure Monitor Alerts to send alerts to the add-on.

If you have resources deployed in Azure and are using JIRA, then this add-on has just made it really simple for you to start creating issues from your Azure Monitor alerts today!

For more information

Announcing the public preview of Azure Monitor
Get Started with Azure Monitor
Operations Management Suite (OMS)
Azure Log Analytics
Application Insights
JIRA REST API Documentation
JIRA REST API Reference

Quelle: Azure

Microsoft reimagines open source cloud hardware

Tomorrow, I’ll be speaking at Zettastructure: The European Digital Infrastructure Summit hosted by Datacenter Dynamics in London. In collaboration with the Open Compute Project (OCP), we are introducing Project Olympus – our next generation hyperscale cloud hardware design and a new model for open source hardware development with the OCP community. This is a significant moment as we usher in a new era of open source hardware development at cloud speed.

Microsoft has been a significant and growing contributor to open source projects for the past decade, particularly with Microsoft Azure. In 2014, we began reimagining our Azure hardware through the lens of open source innovation and joined OCP. Our initial contributions were server and datacenter designs that power the Azure hyperscale cloud. We’ve also contributed technologies that showcase the software-defined networking (SDN) principles of speed and scale-out that serve as Azure’s backbone.

We’ve learned a tremendous amount from our deep collaboration with the OCP Foundation and the open source community over the past few years. An important realization is that open source hardware development is currently not as agile and iterative as open source software. The current process for open hardware development is to contribute designs that are production-ready. At that stage, the design is essentially finalized – almost 100% complete – and this late contribution delays the development of derivative designs, limits interactive community engagement and adoption, and slows down overall delivery.

To address these challenges, we’ve set out in collaboration with the OCP to introduce a new hardware development model for community based open collaboration. Project Olympus applies a model of open source collaboration that has been embraced for software but has historically been at odds with the physical demands of developing hardware. We’re taking a very different approach by contributing our next generation cloud hardware designs when they are approx. 50% complete – much earlier in the cycle than any previous OCP project. By sharing designs that are actively in development, Project Olympus will allow the community to contribute to the ecosystem by downloading, modifying, and forking the hardware design just like open source software.

“Microsoft is opening the door to a new era of open source hardware development. Project Olympus, the re-imagined collaboration model and the way they’re bringing it to market, is unprecedented in the history of OCP and open source datacenter hardware,” said Bill Carter, Chief Technology Officer, Open Compute Project Foundation.

The community can play a significant role in expanding the Project Olympus ecosystem by taking advantage of the early access and contributing additional building blocks to enable a new common hardware design portfolio. OCP Solution Providers will benefit by being able to rapidly assemble hardware solutions specific to product offerings, and the broader community benefits from proven base hardware designs on which they can build value added services. This should decrease the time to market for new product offerings and lower investment costs. The net result will be increased productivity in the industry and faster delivery of new capabilities via the cloud.

Over the past several years, we’ve also learned from deploying OCP hardware at scale in our datacenters – over 90% of the servers we currently purchase are based on OCP contributed specifications. As we look to the future, we know we need to keep pace with tremendous growth in the cloud, support a broad spectrum of workloads including emerging cloud services, and enable easy scaling across global datacenter regions.

The building blocks that Project Olympus will contribute consist of a new universal motherboard, high-availability power supply with included batteries, 1U/2U server chassis, high-density storage expansion, a new universal rack power distribution unit (PDU) for global datacenter interoperability, and a standards compliant rack management card. To enable customer choice and flexibility, these modular building blocks can be used independently to meet specific customer datacenter configurations. We believe Project Olympus is the most modular and flexible cloud hardware design in the datacenter industry. We intend for it to become the foundation for a broad ecosystem of compliant hardware products developed by the OCP community.

We have already released the server chassis interfaces (mechanical and power) and the universal motherboard and PDU specifications on the OCP GitHub branch, and in the coming weeks, we’ll also open source the entire rack system as well.

Over the next two days at Datacenter Dynamics: Zettastructure in London, we’ll share more about Project Olympus through a keynote, OCP workshop and in the Microsoft booth where we’ll have the hardware on display. The team and I are looking forward to working with the OCP community to establish the next generation of open source cloud hardware.
Quelle: Azure