Anzeige: 13-mal das gleiche Passwort

Sichere Passwörter sind die Basis für den Schutz vor Kriminalität im Internet. Dennoch haben Unternehmen bei Passwort- und Identitätsmanagement große Lücken. Welche das sind, zeigt der globale Passwort-Sicherheitsreport von LastPass 2019. (Passwort, Datensicherheit)
Quelle: Golem

Cloud innovation enhances fan experience

Hate standing in queues? Me too. In fact, I’ll avoid them even if there’s no alternative. This is how Nicco was born. I was at a sports bar, and the queue for drinks was so long that I refused to get in line. Over three hours, I had one drink and one snack and walked away feeling like my friends and I would have enjoyed ourselves more at home.
Consider this:

Approximately 81 percent of companies believe they provide great experiences. Only 8 percent of clients agree. [Source:2018 Gartner Customer Experience in Marketing Survey]
86 percent of customers who received a great customer experience were likely to repurchase from the same company. [Source: Temkin Experience Ratings, 2018]

This got me thinking … How much does a seamless in-venue experience impact customer loyalty, and by extension, income?
Two core functions of modern venue experiences
1. Everyone enjoys live entertainment. No one enjoys queues.
We needed a solution designed to reduce queues and wait times — in bars, restaurants, stadiums or events — by allowing users to order and pay from their seats. If users can spend more time enjoying the action, they’ll be more likely to return. Select, order, collect. Simple.
2. Businesses are going in blind. Which products are being consumed? Where, and by whom?
We needed to create a customer engagement solution that would help businesses better understand buyer behaviour and create personalised customer experiences. We knew that a mobile app would be the perfect user interface to achieve both objectives and gain access to previously unseen data.
The story of Nicco: From iteration(s) to reality
Having no technical employees, we saw value in the IBM Garage when we gained access to a team of experienced architects, developers and designers that were ready to bring our idea to life. And so our journey began …
1. The importance of framing an idea.
During an Initial Framing Session, we looked at different business themes and screened benchmarks, determining that we needed to narrow our focus to stadium experience. While our dream was bigger, success means perfecting one use case before expanding to others, balancing the need for data collection capabilities with user experience.
2. Design thinking: Solving the problem through ideation.
During a two-day IBM Enterprise Design Thinking Workshop, we worked with the IBM Garage team to look at stadium experiences from the customer’s perspective. What would add the most value to an attendee’s experience? We did everything from persona creation and scenario mapping to wireframing. Here’s a full list of what goes into the process.
We agreed that the food and beverage purchasing process could be modernised and expedited with concepts such as mobile ordering and in-seat delivery. We talked through details such as building payment systems; creating iPhone, Android and vendor apps; and designing an analytics dashboard.
3. Build, test, iterate.
After a brief cloud innovation architecture workshop, we decided to focus on building an MVP (minimum viable product) for iOS users. Initially, we built a clickable wireframe prototype, which was helpful during discussions with investors.
We then completed the first Nicco MVP, an iOS app that allows a user to choose a merchant located within the stadium, view its menu, order, pay and receive a notification when the order is ready for pickup.
As of October 2019, we have completed three pilots at Lottoland Stadium, primarily to test functionality and interest. Through constant iteration, we determined the need for integration with a point of sale (POS) management system and an administration dashboard. Somewhat unexpectedly, the app also enhanced safety due to fewer people in queues blocking aisles and doors.
4. Building our stack.
We built our production solution on IBM Cloud, which gave us flexibility, openness, reliability, scale and speed. We leveraged technology from the IBM Cloud Catalog, including IBM Cloud Kubernetes Service for the application microservices, IBM Cloud App ID for user authentication, IBM API Connect for API management, IBM Cloud Object Storage for image storage, IBM Cloud Monitoring and IBM Cloud Log Analysis for application health and performance monitoring, and MongoDB for application data management.
What’s next for Nicco?
Over time, we plan to use Nicco’s detailed transaction data and IBM Watson to interpret customer profile data with AI. We will continue to iterate our application with IBM Garage based on user feedback, architectural inquiry, venue demand and new research that becomes available.
The IBM Garage team is our Nicco team. They’re engaged and passionate and provide us with a perspective that has been invaluable during this build. Frankly, we could have hired an offshore team to do this at a lower cost, but if we did that, we wouldn’t have had the confidence to tell large enterprises, stadiums and investors that the technology in our solution works. Whether you’re a startup or large enterprise, tapping into IBM Garage expertise and methodologies is a competitive advantage.
We’ll be back with updates soon. For now, I’ve got to run – Nicco just alerted me that my order is ready.
To learn about Nicco and our solution, check out this video. Want to experience the IBM Garage for yourself? Schedule a complimentary visit to the IBM Garage to get started.
The post Cloud innovation enhances fan experience appeared first on Cloud computing news.
Quelle: Thoughts on Cloud

Why Use Containers, Kubernetes, and OpenShift for AI/ML Workloads?

Containers and Kubernetes are proving to be very valuable in helping accelerate Artificial Intelligence (AI) and Machine Learning (ML) lifecycle for organizations worldwide. ExxonMobil, BMW, Volkswagen, Discover Financial Services, Ministry of Defense (Israel), Boston Children’s Hospital, are some organizations have operationalized Red Hat OpenShift, industry leading Kubernetes-based container platform, to accelerate data science workflows, and build intelligent applications. These intelligent applications are helping achieve key business goals and providing competitive differentiation.
In a recent blog, I explained how these emerging cloud-native technologies are playing a vital role in helping solve ML Lifecycle execution challenges, and accelerate the delivery of intelligent applications. You may be thinking…”ok, so where do we start to learn about this topic?”
To help you get started on this journey, we have developed a short video that explains in under three minutes how containers, Kubernetes, and OpenShift can accelerate AI/ML initiatives for your organization. Whether you are working at your desk, driving, riding on a train, walking, or something else, this quick video will do the job for you! As always, feedback is highly appreciated.
 

The post Why Use Containers, Kubernetes, and OpenShift for AI/ML Workloads? appeared first on Red Hat OpenShift Blog.
Quelle: OpenShift

Azure Cognitive Services for building enterprise ready scalable AI solutions

This post is co-authored by Tina Coll, Senior Product Marketing Manager, Azure Cognitive Services and Anny Dow, Product Marketing Manager, Azure Cognitive Services.

Azure Cognitive Services brings artificial intelligence (AI) within reach of every developer without requiring machine learning expertise. All it takes is an API call to embed the ability to see, hear, speak, understand, and accelerate decision-making into your apps. Enterprises have taken these pre-built and custom AI capabilities to deliver more engaging and personalized intelligent experiences. We’re continuing the momentum from Microsoft Build 2019 by making Personalizer generally available, and introducing additional advanced capabilities in Vision, Speech, and Language categories. With many advancements to share, let’s dive right in.

Personalizer: Powering rich user experiences

Winner of this year’s ‘Most Innovative Product’ award at O’Reilly’s Strata Conference, Personalizer is the only AI service on the market that makes reinforcement learning available at-scale through easy-to-use APIs. Personalizer is powered by reinforcement learning and provides developers a way to create rich, personalized experiences for users, even if they do not necessarily have deep machine learning expertise.

Giving customers what they want at any given moment is one of the biggest challenges faced by retail, media, and e-commerce businesses today. Whether it’s applying randomized A/B tests or supervised machine learning, businesses struggle to keep up with delivering unique and relevant experiences to each user. This is where Personalizer comes in, exploring new options to stay atop of previously unencountered influences on user behavior through a cutting-edge machine learning technique known as reinforcement learning. This technique allows Personalizer to learn from what’s happening in the world in real-time and update the underlying algorithm as frequently as every few minutes. The result is a significant improvement to your app usability and user satisfaction. When XBOX implemented Personalizer on their homepage, they saw a 40 percent lift in user engagement.

Form Recognizer: Increase efficiency with automated text extraction and feedback loop

Businesses often rely on a variety of documents that can be hard to read; these documents are not always cleanly printed, and many include handwritten text. Businesses including Chevron use Form Recognizer to accelerate document processing through automatic information extraction from printed forms. This frees their employees to focus on more challenging and higher-value tasks.

Form Recognizer extracts key-value pairs, tables, and text from documents including W2 tax statements, oil and gas drilling well reports, completion reports, invoices, and purchase orders. Today we are announcing feedback loop support to enable even more accurate data extraction. Users will be able to provide labeled examples of the specific values they want extracted. This feature enables Form Recognizer to support any type of form including values without keys, keys under values, tilted forms, photos of forms, and more. Starting with just 10 forms, users can train a model tailored to their use case with high-quality results. A new user experience gets you started quickly, selects values of interest, labels, and trains your custom model.

In addition, Form Recognizer can now train a single model without labels for all the different types of forms, and supports training on large datasets and analyzing large documents with the new AsyncAPI. This benefit enables customers to train a single model for the different types of invoices, purchase orders, and more without the need to classify the documents in advance.

We have also enhanced our pre-built receipts capabilities with accuracy improvements, additional new fields for tips, receipt types (itemized, credit card slip, gas, parking, other), and line item extraction detailing all the different items in the receipt. Finally, we have also improved the accuracy of our text recognition enabling extraction of high-quality text from the forms and our table extraction.

Sogeti, part of Capgemeni, is harnessing these new Form Recognizer capabilities. As Arun Kumar Sahu, the Manager of AI ML for Sogeti notes:

“We are working on a document classification and predictive solution for one of the largest automobile auction companies in the US, and needed an efficient way to extract information from various automobile related documents (PDF or image). Form Recognizer was quick and easy to train and host, was cost effective, handled different document formats, and the output was amazing. The new labelling features made it very effective to customize key value pair extraction.”

Speech: Enable more natural interactions and accelerate productivity with advanced speech capabilities

Businesses want to be able to modernize and enable more seamless, natural interactions with their customers. Our latest advancements in speech allow customers to do just that.

At Microsoft Ignite 2018, we introduced our neural text-to-speech capability, which uses deep neural networks to enable natural-sounding speech and reduces listening fatigue for users interacting with AI systems. Neural text-to-speech can be used to make interactions with chatbots and virtual assistants more natural and engaging, convert digital texts such as e-books into audiobooks, and enhance in-car navigation systems. We’re excited to build upon these advancements with the Custom Neural Voice capability, which enables customers to build a unique brand voice, starting from just a few minutes of training audio. The Custom Neural Voice capability can enable scenarios such as customer support provided by a company’s branded character, interactive lesson plans or guided museum tours, and voice assistive technologies. The capability also supports generating long-form content, including audiobooks.

The Beijing Hongdandan Education and Culture Exchange Center is dedicated to using audio to create accessible products for those with visual impairments and improving the lives of the visually impaired by providing aids such as audiobooks. Hongdandan is using the Custom Neural Voice capability to produce audiobooks based on the voice of Lina, who lost her sight at the age of 10. Lina is now a trainer at the Hongdandan Service Center, using her voice to teach others who are visually impaired to communicate well.

With the rapid pace at which business is moving today, remembering all the details from your last important meeting and tracking next steps and key deadlines can be a real challenge. Quickly and accurately transcribing calls can help various stakeholders stay on the same page by capturing critical details and making it easy to search and review topics you discussed. In customer support scenarios, being able to hear and understand your customers and keep an accurate record of information is critical for tracking customer requirements and enabling broader analysis.

However, accurately transcribing organization-specific terms like product names, technical terms, and people's names pose another barrier. With Custom Speech, you can tailor speech recognition models based on your own data so that your unique terms are accurately captured. Simply upload your audio to train a custom model. Now, you can also optimize speech recognition on your organization-specific terms by automatically generating custom models using your Office 365 data in a secure and compliant fashion. With this opt-in feature, organizations using Office 365 can more accurately transcribe company terminology, whether in internal meetings or on customer calls. The organization-wide language model is built only using conversations and documents from public groups that everyone in the organization can access.

Additional new features such as Custom Commands, Custom Speech and Voice containers, Speech Translation with automatic language identification, and Direct Line Speech channel integration with Bot Framework are making it easier to quickly embed advanced speech capabilities into your apps. For more information, visit the Azure Speech Services page.

Language: Extract deeper insights from customer feedback and text documents

There are a multitude of valuable customer insights captured today—whether in social media, customer reviews, or discussion forums. The challenge is being able to extract insights from that data, so businesses can act fast to improve customer service and meet the needs of the market. With the Text Analytics Sentiment Analysis capability, businesses can easily detect positive, neutral, negative, and mixed sentiment in content, enabling them to keep an ongoing pulse on customer satisfaction, better engage their customers, and build customer loyalty. The latest release of the Sentiment Analysis capability offers greater accuracy in sentiment scoring, as well as the ability to detect sentiment for both an entire document as well as individual sentences.

Another challenge of extracting information from your data is being able to take unstructured natural language text and identify occurrences of entities such as people, locations, organizations, and more. Text Analytics is expanding entity type support to more than 100 named entity types, making it easier than ever to extract meaningful information and analyze relationships from raw text and between terms. Additionally, customers will now be able to detect and extract more than 80 kinds of personally identifiable information in English language text documents.

We are also adding several new capabilities to Language Understanding Intelligent Service (LUIS) that enable developers to build sophisticated models that are conversational. The new capabilities provide the ability to handle more complex requests from users (as an example, if you want to allow customers to truly use natural language, they might order ‘Two Burgers with no onions and replace buns with lettuce wraps’). This provides customers with the advanced ability for hierarchical entities and model decomposition, to build more sophisticated language models that reflect the way humans speak. In addition, we are adding more regions and further enhancing the existing human languages supported in LUIS with the addition of Hindi and Arabic.

Enterprise Ready: Azure Virtual Network for enhanced data security

One of the most important considerations when choosing an AI service is security and regulatory compliance. Can you trust that the AI is being processed with the high standards and safeguards that you come to expect with hardened, durable software systems? Azure Cognitive Services offers over 70 certifications. Today we are offering Virtual Network support as part of Cognitive Services to ensure maximum security for sensitive data. This service also is being made available in a container that can run in a customer’s Azure subscription or on-premises.

Get started today

We are continuing to enable new powerful and intelligent scenarios for our customers that improve their productivity and user experiences. The incredible breadth of services available through Azure Cognitive Services enables you to extract insights from all your data. Using these new announcements, you can accurately extract text from forms using Form Recognizer, analyze and understand this text using Text Analytics and LUIS, and finally, provide these insights to your users through a spoken, conversational interface with our speech services.

These milestones illustrate our commitment to make the Azure AI platform suitable for every business scenario, with enterprise-grade tools that simplify application development and industry-leading security and compliance for protecting customers’ data.

Get started today by building your first intelligent application using an Azure free account and learn more about Cognitive Services.

Azure. Invent with purpose.
Quelle: Azure

Depend on Docker for Kubeflow

Run Kubeflow natively on Docker Desktop for Mac or Windows
This is a guest post by Alex Iankoulski, Docker Captain and full stack software and infrastructure architect at Shell New Energies. The views expressed here are his own and are neither opposed or endorsed by Shell or Docker. 
In this blog, I will show you how to use Docker Desktop for Mac or Windows to run Kubeflow. To make this easier, I used my Depend on Docker project, which you can find on Github.
Rationale
Even though we are experiencing a tectonic shift of development workflows in the cloud era towards hosted and remote environments, a substantial amount of work and experimentation still happens on developer’s local machines. The ability to scale down allows us to mimic a cloud deployment locally and enables us to play, learn quickly, and make changes in a safe, isolated environment. A good example of this rationale is provided by Kubeflow and MiniKF.
Overview
Since Kubeflow was first released by Google in 2018, adoption has increased significantly, particularly in the data science world for orchestration of machine learning pipelines. There are various ways to deploy Kubeflow both on desktops and servers as described in its Getting Started guide. However, the desktop deployments for Mac and Windows rely on running virtual machines using Vagrant and VirtualBox. If you do not wish to install Vagrant and VirtualBox on your Mac or PC but would still like to run Kubeflow, then you can simply depend on Docker! This article will show you how to deploy Kubeflow natively on Docker Desktop. 
Setup
Prerequisites
Kubeflow has a hard dependency on Kubernetes and the Docker runtime. The easiest way to satisfy both of these requirements on Mac or Windows is to install Docker Desktop (version 2.1.x.x or higher). In the settings of Docker Desktop, navigate to the Kubernetes tab and check “Enable Kubernetes”:
Fig. 1 – Kubernetes Settings in Docker Desktop
Enabling the Kubernetes feature in Docker Desktop creates a single node Kubernetes cluster on your local machine.
This article offers a detailed walkthrough of setting up Kubeflow on Docker Desktop for Mac. Deploying Kubeflow on Docker Desktop for Windows using Linux containers requires two additional prerequisites: 

Linux shell – to run the bash commands from the Kubeflow installation instructions 
Kfctl and kubectl CLI – to initialize, generate, and apply the Kubeflow deployment

The easiest way to satisfy both of these dependencies is to run a Linux container that has the kfctl and kubectl utilities. A Depend on Docker project was created for this purpose. To start a bash shell with the two CLI’s available, just execute:
docker run -it –rm -v <kube_config_folder_path>:/root/.kube iankoulski/kfctl bash
The remaining setup steps for both Mac and Windows are the same.
Resource Requirements
The instructions for deployment of Kubeflow on a pre-existing Kubernetes cluster specify the following resource requirements:

4 vCPUs
50 GB storage
12 GB memory

The settings in Docker Desktop need to be adjusted to accommodate these requirements as shown below.
Fig. 2 – CPU and Memory settings in Docker Desktop
Fig. 3 – Disk image size setting in Docker Desktop
Note that the settings are adjusted to more than the minimum required resources to accommodate system containers and other applications that may be running on the local machine.
Deployment
We will follow instructions for the kfctl_k8s_istio configuration.

Download your preferred version from the release archive:curl -L -o kfctl_v0.6.2_darwin.tar.gz https://github.com/kubeflow/kubeflow/releases/download/v0.6.2/kfctl_
Extract the archive:tar -xvf kfctl_v0.6.2_darwin.tar.gz
Set environment variables:export PATH=$PATH:$(pwd)export KFAPP=localkfexport CONFIG= https://raw.githubusercontent.com/kubeflow/kubeflow/v0.6-branch/bootstrap/config/kfctl_k8s_istio.0.6.2.yaml
Initialize deployment:kfctl init ${KFAPP} –config=${CONFIG}cd ${KFAPP}kfctl generate all -V

Note: The above instructions are for Kubeflow release 0.6.2 and are meant to use as an example. Other releases would have slightly different archive filename, environment variable names and values, and kfctl commands. Those would be available in the release-specific deployment instructions.

Pre-pull container images (optional)

To facilitate the deployment of Kubeflow locally, we can pre-pull all required Docker images. When the container images are already present on the machine, the memory usage of Docker Desktop stays low. Pulling all images at the time of deployment may cause large spikes in memory utilization and can cause Docker Daemon to run out of resources. Pre-pulling images is especially helpful when running Kubeflow on a 16GB laptop.
To pre-pull all container images, execute the following one-line script in your $KFAPP/kustomize folder:
for i in $(grep -R image: . | cut -d ‘:’ -f 3,4 | uniq | sed -e ‘s/ //’ -e ‘s/^”//’ -e ‘s/”$//’); do echo “Pulling $i”; docker pull $i; done;
Fig. 4 – Pre-pulling Kubeflow container images
Depending on your Internet connection, this could take several minutes to complete. Even if Docker Desktop runs out of resources, restarting it and running the script again will resume pulling the remaining images from where you left off. 
If you are using the kfctl container on Windows, you may wish to modify the one-line script above so it saves the docker pull commands to a file and then execute them from your preferred Docker shell.

Apply Kubeflow deployment to Kubernetes:

cd ${KFAPP}kfctl apply all -V
Fig. 5 – Deployment output and Kubeflow pods – found by executing ‘kubectl get pods –all-namespaces’ – running in Docker Desktop.
Note: An existing deployment can be removed by executing “kfctl delete all -V”

Determine the Kubeflow entrypoint

To determine the endpoint, list all services in the istio-system namespace:kubectl get svc -n istio-system
Fig. 6 – Istio Ingress Gateway service.
The Kubeflow end-point service is through the ingress-gateway service on the NodePort connected with the default HTTP port (80). The Node Port number is 31380. To access Kubeflow use: http://127.0.0.1:31380
Using Kubeflow
The Kubeflow central dashboard is now accessible:
Fig. 7 – Kubeflow dashboard
We can run one of the sample pipelines that is included in Kubeflow. Select Pipelines, then Experiments, and choose Conditional expression (or just click the [Sample] Basic – Conditional expression link on the dashboard screen). 
Fig. 8 – Conditional execution pipeline
Next, click the +Create run button, enter a name (e.g. conditional-execution-test), choose an experiment, and then click Start to initiate the run. Navigate to your pipeline by selecting it from the list of runs.
 Fig. 9 – Conditional execution pipeline run
The completed pipeline run looks similar to Fig. 9 above. Due to the random nature of the coin flip in this pipeline, your actual output is likely to be different. Select a node in the graph to review various assets associated with that node, including its logs.
Conclusion
Docker Desktop enables you to easily run container applications on your local machine, including ones that require a Kubernetes cluster. Kubeflow is a deployment that typically targets larger clusters either in cloud or on-prem environments. In this article we’ve demonstrated how to deploy and use Kubeflow locally on your Docker Desktop. 
References

Docker Desktop
About Kubeflow
MiniKF Rationale
MiniKF
Kubernetes
Kubeflow Getting Started
Vagrant
Virtual Box
Kubeflow deployment instructions
Depend on Docker project
Kfctl container image

Credits
I’d like to thank the following people for their help with this post and related topics:

Yannis Zarkadas, Arrikto 
Constantinos Venetsanopoulos, Arrikto
Josh Bottum, Arrikto
Fabio Nonato de Paula, Shell
Jenny Burcio, Docker
David Aronchick, Microsoft
Stephen Turner, Docker
David Friedlander, Docker

To learn more about Docker Desktop and running Kubernetes with Docker:

Learn about designing your first application in Kubernetes.
Try Play with Kubernetes, powered by Docker.
Learn more about Docker Desktop and the new Docker Desktop Enterprise

How to run #Kubeflow on #DockerDesktop by #DockerCaptain Alex IankoulskiClick To Tweet

The post Depend on Docker for Kubeflow appeared first on Docker Blog.
Quelle: https://blog.docker.com/feed/

Secure and compliant APIs for a hybrid and multi-cloud world

APIs are everywhere. The broad proliferation of applications throughout enterprises often results in large silos of opaque processes and services, making it hard for IT to manage and govern APIs in a systematic way, and for development teams to gain visibility into and make use of APIs that already exist.

Entire industries, such as financial services, are embracing APIs as a means to become more open, for example with open banking initiatives. Open banking is an API-first approach to creating more open, rich ecosystems that encourage third-party participation and usage of the services financial institutions have previously kept behind the scenes.

Products, such as Azure API Management, were created to address these issues. By letting you manage all APIs in a single, centralized location, you are able to impose authentication, authorization, throttling, and transformation policies and easily monitor the usage of the APIs associated with your applications, giving you the much-needed visibility into your application portfolio(s) at a macro-level.

To succeed in an increasingly connected world, it is key to adopt an API-first approach that lets you:

Embrace innovation by creating vibrant API ecosystems.
Secure and manage APIs seamlessly in a hybrid world.

APIs can be a bridge to the uncertain future and help you safely traverse over turbulent waters.

Embrace innovation by creating vibrant API ecosystems

Microsoft offers all of the tools to be able to immediately capitalize on new opportunities as they emerge in the business landscape. Our infrastructure technologies, such as Kubernetes and serverless computing, accelerate development velocity and help developers move faster than ever before. Our API technologies, such as API management, accelerate the speed at which new opportunities can be acted upon, by immediately providing channels for partners, developers, customers, and other third-parties to leverage new technology which is created. These types of activities are often done with tools such as an API developer portal.

Azure API Management’s developer portal lets you easily grant access (and control) to APIs. The developer portal provides documentation on how to use the APIs and creates a simple, easy way for people to get started. A developer portal is an integral part of any API-first approach, which is why we’re announcing the general availability of our greatly improved developer portal experience.

You can now easily customize the developer portal with a visual user interface, helping create a branded experience. The developer portal is open-source and built with extensibility in mind. You can easily fork our exacting repository and customize it to meet your needs. It was created using contemporary JAMstack technologies that significantly reduce page load times, to make it as frictionless of user experience as possible.

You can learn more about this announcement by reading our Azure Update on the release.

Secure and manage APIs seamlessly in a hybrid world

Today’s most popular API management solutions run in public clouds. And while having a purely cloud-based API management service can work for pretty much all scenarios, it’s not always the best choice. Perhaps compliance requirements mandate that information must stay on the corporate network, or maybe accessing the cloud is prohibited by company policy. Whatever the reason, scenarios like this can’t use an API management service running in any public cloud; the service must run on-premises.

To meet your hybrid requirements, we’re announcing the preview of Azure Arc enabled API Management, a self-hosted API gateway. The new self-hosted API gateway doesn’t replace the primary cloud-based API management service. Instead, it augments this service by providing the essential aspects of API management in software that organizations can run wherever they choose.

It adds a containerized version of the Azure API Management gateway you can host on-premises or another environment that supports the deployment of Docker containers. It enables more efficient call patterns for internal-only and internal and external APIs and is managed from a cloud-based Azure API Management instance. Azure Arc enabled API Management enables you to run the self-hosted API management gateway in your own on-premises datacenter or run the self-hosted API management gateway in another cloud.

Read the whitepaper we’ve released, API management in a hybrid and multi-cloud world, which goes into further detail technical detail on Azure Arc enabled API Management, as well as the strategic benefits you receive when adopting this approach.

Or, you can start a free trial of Microsoft Azure and check out API Management for yourself.

Heading into the future

APIs are the way that businesses will continue to communicate. The growth of APIs has continued to increase, and the rise of the API product is happening right now. Many different companies now offer API-first products and are a powerful reminder that a well thought out API strategy is going to be key to any business' strategy moving forward.

To learn more about what APIs and API Management can do for you, you can visit API Management on Azure.

Azure. Invent with purpose.
Quelle: Azure

New Azure Security Center and Azure platform security capabilities

At Microsoft Ignite we're sharing the many new capabilities our teams have built to improve security with Azure Security Center and the Azure Platform. We have a long list of new innovations, and this blog provides our general direction and summarizes some of our favorite new features. For more information, you can read all the details in our Azure Security Center Community post.

Turn on the protection you need with Azure Security Center

Azure Security Center provides unified infrastructure security management that strengthens security posture and provides advanced threat protection across your workloads running in Azure, on-premises, and in other clouds. It enables continuous assessment of security posture, protects against cyberattacks using Microsoft’s vast threat intelligence, and helps implement security faster with integrated controls.

With Security Center, you can monitor the security of machines, networks, and Azure services using hundreds of built-in security assessments or create your own in a central dashboard.

Extending Azure Security Center’s coverage with a platform for community and partners

A constantly evolving threat landscape requires new approaches to protection, cloud security posture, enterprise-scale deployment, and automation. Through partnering with members of the Microsoft Intelligent Security Association, Microsoft is able to leverage a vast knowledge pool to defend against a world of increasing cybersecurity threats.

Leverage all of Security Center's capabilities against built-in and partner recommendations. Azure Security Center's simple onboarding flow connects existing solutions, including Check Point CloudGuard, CyberArk, and Tenable, enabling you to view all security posture recommendations in a single place. Run unified reports and export Security Center’s recommendations for connected partner products.

We invite users to contribute and help improve policies and configurations used in Security Center through the Azure Security Center community menu for additional scripts, content, and community resources.

Enhanced threat protection for cloud resources

Threat protection detects and prevents attacks across a wide variety of services, from infrastructure as a service (IaaS) layer to platform as a service (PaaS) resources in Azure, including Azure IoT and Azure App Service, and on-premises virtual machines.

Stream threat detection findings to Azure Sentinel for investigation, threat hunting, correlation with signals from other security solutions, and security operations center (SOC) level management.

The latest threat protection capabilities include:

Threat protection and vulnerability assessment support for SQL Server hosted on an Azure Virtual Machine.
Vulnerability assessment capabilities for VMs is part of our virtual machine protection offering (powered by Qualys) at no additional cost. Security Center collects the vulnerabilities and displays them as part of the secure score.
Threat protection suite for containers focusing on Azure Kubernetes Service (AKS) includes scanning of container images for vulnerabilities, secure configuration of the AKS cluster, and threat detection on the Kubernetes runtime activities.
Threat protection for Azure Key Vault is in preview in North America regions. This provides an additional layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit your encryption keys, certificates, and secrets in Azure Key Vault.

Threat protection for Azure Storage offers new detections powered by Microsoft Threat Intelligence for detecting malware uploads to Azure Storage using hash reputation analysis and suspicious access from an active Tor exit node (an anonymizing proxy.) You can now view detected malware across storage accounts using Azure Security Center.

Cloud security posture management enhancements

Misconfiguration is the most common cause of security breaches for cloud workloads. Security Center provides a bird’s eye security posture view across your Azure environment, enabling you to continuously monitor and improve your security posture using the Azure secure score. Security Center helps manage and enforce your security policies to identify and fix misconfigurations across different resources and maintain compliance.

New capabilities:

Secure score simplified: Use the updated, percentage based secure score to get better visibility into the secure score controls and provide a more reliable method for calculating the score.

Address misconfigurations faster with new quick-fix capabilities.

Add custom assessments, created in Azure Policy, into the secure score and monitor their compliance state in Security Center.

Automatically assess compliance state against a new set of regulatory standards, including NIST SP 800-53 R4, SWIFT CSP CSCF v2020, Canada Federal PBMM, and UK Official together with UK NHS.

Misconfigurations are the leading source of attacks and improving your secure score can make a remarkable difference in your overall security posture.

Implement security faster with Azure Security Center

To enable large organizations to leverage Security Center’s findings in enterprise-scale, Azure Security Center continues to provide clear APIs, automation, and management capabilities that can help customers connect Security Center to workflows, processes, and tools used across the organization.

A new capability in Security Center enables the creation of rich workflows using Azure Logic Apps and policies trigger based on a recommendation or alert. Configure a logic app to perform a custom action supported by the vast community of Logic App connectors, or use one of the templates provided, including to send an email or open a service ticket.

Security from the ground up

In addition to Azure Security Center updates, we have several additional enhancements for Azure platform security. To empower you to do more, we are continuously enhancing the platform services to improve existing offerings and address your feedback.

Here are some of the exciting updates coming to the platform. 

Extension of Customer Lockbox for Microsoft Azure beyond virtual machines

Customer Lockbox provides customers the capability to control Azure support engineers' access to workloads that contain customer data This expanded support now provides customers control over access to their data for a larger set of Azure offerings.

New services and scenarios, available in preview:

Azure Storage
Azure SQL Database
Azure Data Explorer
Memory dumps and managed disks for Azure Virtual Machines
Transferring Azure subscriptions

Release of Microsoft Secure Code Analysis toolkit to help you build secure code

With the Microsoft Security Code Analysis extension, you can infuse security analysis tools including Credential Scanner, BinSkim, and others into your Azure DevOps continuous integration and delivery (CI/CD) pipelines. Increase developer productivity and simplify security through easily configurable build tasks that abstract away the complexities (installing, updating, maintaining, and running) from analysis tools without relinquishing control over them. 

This product is now available via Unified Support. Customers can sign up using their existing credit or paying the service fee. To learn more please visit the Microsoft Secure Code Analysis documentation page.

Azure Disk Encryption in more places, and more services offering customer-managed keys

Azure Disk Encryption enables you to encrypt your Azure Virtual Machine disks with your keys safeguarded in Azure Key Vault. Previously this capability was available through PowerShell and CLI. We have now added this capability to the Azure portal, which makes it very easy to use. We have also added support for the latest versions of the common Linux distros on Azure, including Red Hat Enterprise Linux 7.6 and 7.7 as well as CentOS Linux 7.6 and 7.7.

Try it yourself using Quickstart for Windows or Quickstart for Linux now.

The following services recently announced preview for customer-managed keys for encryption at rest.

Azure Event Hubs
Azure Managed Disks
Power BI

For a full list of services offering encryption with customer-managed keys, see the Azure Data Encryption-at-Rest documentation page.

New Azure policies to manage certificates across your organization, currently in preview

Large organizations have thousands of certificates in key vaults distributed across thousands of applications and subscriptions. If you are responsible for security and compliance across the organization, you need a simple way to set rules across all these certificates, prove that those rules were followed, and flag violations. Azure policy helps with this. We have added new policies in preview for certificates in Azure Key Vault.

Issuer Policy: Flag certificates that are (or are not) issued by a particular issuer.
Key Type Policy: Flag certificates that are (or are not) protected by a RSA or ECC key pairs.
Key Size Policy: Flag certificates that are (or are not protected) by a key of a certain size.
Expiry Policy: Flag certificates that are (or are not) renewed within “X” number of days of their expiry date.
Validity Lifespan Policy: Flag certificates that have (or do not have) Validity Lifespan that is less than, or more than, or equal to "X" number of years.

For more information see the documentation for Azure Key Vault governance policies.

Azure Key Vault Virtual Machine extension now generally available

The Azure Key Vault Virtual Machine extension makes it easier for apps running on virtual machines to use certificates from a key vault, by abstracting the common tasks as well as best practices—authenticate, handle common network errors, cache, periodically refresh the certificate from the key vault, and bind the certificate for Transport Layer Security (TLS).

This extension is now generally available for Windows and Linux.

Free Azure managed certificates for your domains on Azure

We want to make sure there are no reasons not to use TLS in your Azure applications. Azure now provides TLS certificates at no cost to you for your custom domains hosted on the following services. Azure renews these certificates automatically.

Azure CDN managed certificates (generally available.)
Azure Front Door managed certificates (generally available.)
Azure App Service managed certificates for both web apps and functions (currently in preview.)

We will expand this to other Azure PaaS services in the future.

Note that this is just one of your options. If you have a need to use certificates from a different certificate authority (CA), then you have the option to configure these Azure services to use a certificate you manage in your key vault.

Learn more

With these additions, Azure continues to provide a secure foundation and gives you built-in security tools and intelligent insights to help you rapidly improve your security posture in the cloud. Azure Security Center strengthens its role as the unified security management and advanced threat protection solution for your hybrid cloud.

For Azure app developers:

Use the Microsoft Secure Code Analysis toolkit to inspect your code for security issues.
Enable TLS for your Azure CDN, Front Door, and App Service (web app and function) resources.
Evaluate the new Azure Virtual Machine extension for Azure Key Vault to simplify how your app uses certificates from Azure Key Vault (for Windows and Linux).

For users responsible for security across their organizations:

Evaluate Azure Policy, including the new Key Vault policies, to ensure developers across your organization follow the rules you set for security and compliance.

Security can’t wait. Get started with Azure Security Center today and visit Azure Security Center Tech Community, where you can engage with other security-minded users like yourselves.

Azure. Invent with purpose.
Quelle: Azure