3 key cloud adoption trends in migrating and modernizing workloads

In the past few years, organizations have weathered unprecedented change as they have had to adapt to macro-economic, political, and societal challenges. These challenges are not going away—the business outlook remains uncertain with ongoing concerns, including inflation, supply chain disruptions, and rising energy prices.

Microsoft believes the best way to prepare for this uncertainty is for organizations to do more with less—less complexity and cost, with more agility, resilience, and innovation. This means applying digital capabilities to extend what organizations can achieve amidst today’s constraints.

Moving workloads to the cloud provides more flexibility for organizations to align their IT investments with business needs while benefiting from cloud economies of scale. Modern infrastructure and cloud capabilities can also free up an organization’s IT workforce to focus on workloads and applications that are most meaningful to their customers.

To get a deeper understanding of the challenges faced by our customers and their plans around cloud adoption, Microsoft commissioned a global survey with more than 1200 IT decision makers.

The study revealed three key cloud adoption trends:

1. Cloud adoption plans remain integral to strategies in uncertain business climates

The survey found 62 percent of organizations have a migration and modernization strategy in place, showing the increasing importance of cloud adoption in IT transformation. Their top motivators are reducing total business costs, future proofing business strategy, and driving revenue growth. The survey also showed security, business continuity (BC), disaster recovery (DR), and scalability as top benefits desired from cloud migrations. That said, we expect that returns on investment (ROI) considerations will remain top of mind in the near term as customers prioritize cloud initiatives for implementation—be it optimizing their existing cloud workloads or moving additional workloads. This increased attention on cost optimization and the rise of financial operations teams (FinOps) is also echoed in the Flexera state of the cloud 2022 report, where for the sixth year in a row, optimizing the existing use of cloud (cost savings) was the top initiative, followed by migrating more workloads to the cloud.

Organizations are considering cloud adoption plans holistically across their entire IT infrastructure to better prepare for what’s next. Of the organizations we surveyed, the number who have more than half of their workloads in the cloud will grow from 27 percent to 47 percent over the next 18 months with investments spanning both business-critical and non-business critical workloads. Furthermore, the survey found organizations with a cloud migration and modernization strategy are 58 percent more likely to be ‘cloud-only’ (all or almost all applications and workloads running in the cloud) three years from now.

2. Modernization is a key focus for digital transformation

82 percent of surveyed organizations said migrating to the cloud is a steppingstone towards digital transformation. Migration is about getting workloads to the cloud—and modernization is about refactoring existing applications and workloads to take full advantage of cloud-native technologies like Platform-as-a-Service (PaaS) or containers. Those surveyed told us 74 percent of workloads that have already migrated are candidates for modernization—modernizing workloads helps opens the door to digital transformation whether it’s speeding up product innovation cycles or personalized end-user experiences.

3. Hybrid and multicloud interoperability and integration are expected

Organizations continue to embrace multicloud and are looking for cross-cloud management and interoperability from their cloud providers. Underscoring our recent research on hybrid and multicloud earlier this year, customers surveyed want to retain investment flexibility along with best-of-breed cloud capabilities with 71 percent to continue implementing a hybrid or multi-cloud strategy.

Complexities of cloud-to-cloud integration, refactoring existing applications, and integration with legacy backends are a few of the barriers that can slow down cloud adoption. So, it’s no surprise that support from a dedicated migration and modernization team was ranked highest in surveyed customers’ wish list from cloud vendors. Post migration support, access to engineering resources, and help with technical skilling were other key areas that emerged from the survey.  These findings present significant implications for cloud providers as they define programs and investments to assist customers during uncertain times.

How Microsoft Azure can help customers with cloud migration and modernization efficiently

We have been on our own digital transformation journey since Microsoft began migrating on-premises workloads to the cloud in 2014. We have been transforming our IT footprint using built-in tools and data insights that Azure provides to optimize costs (such as Azure Advisor, Azure Cost Management and Billing, and Azure Monitor) and reinvesting in modernization for business growth. Today more than 95 percent of our workloads run on the cloud, and while our yearly budget for Azure has remained constant since 2014, Microsoft has grown by more than 20 percent. Our own journey and learnings inform how we can empower customers to best meet their current and future technology needs.

Our customers choose Azure as their platform of choice to meet their goals today and to build for the future tomorrow.

Fiserv, a global fintech and payment company, improved their payment processing infrastructure to simplify operations bringing benefits such as risk reduction and cost savings. Perrigo, a worldwide producer and supplier of consumer self-care products for businesses, unlocked agility and flexibility through streamlined finance workloads to build a single source of truth for finance. The Bank of Angola became the first bank in Angola to embrace digitization by moving to the cloud to innovate and improve processes and infrastructure. O2 Czech Republic, the leading telecommunications company in the Czech Republic, saw a 30 percent total cost of ownership (TCO) savings for every workload they moved while enhancing security and scaling their entertainment business.

We continue to invest deeply in helping our customers do more with less and get the most out of their Azure investments with our solutions.

Today we’re announcing a new total cost of ownership (TCO) or business case capability to help customers estimate how much they can save by migrating their Windows Server and SQL Server estate to Azure. This will be available within Azure Migrate, our free self-service migration tool that allows organizations to plan and execute their move to Azure. Try out this new capability and share your feedback.
Customers can optimize their cloud investments with our unique offers and pricing benefits. With unique offers like the Azure Hybrid Benefit (save costs by reusing software assurance enabled Windows, Server SQL Server, Red Hat Enterprise Linux, and SUSE Linux licenses on Azure) and Extended Security Updates (free only on Azure), it’s up to 80 percent less expensive to run Windows Server and SQL Server VMs on Azure than it is with our main competitor. With Azure savings plan for compute, customers can significantly reduce resource costs by up to 65 percent compared to pay-as-you-go prices.
The Azure Migration and Modernization Program (AMMP) offers customers the right mix of expert help to reduce migration costs and accelerate their move—including technical skilling, engineering resources, specialized partners, and cost-effective incentives so customers are holistically set up for success.

At Microsoft, we are committed to helping our customers be successful, drive strong business outcomes and get the most out of their cloud investments, especially in challenging environments like today’s.

Learn more about some of our updates and other key cloud trends in my fireside chat with Dave McCarthy, Research Vice President, Cloud and Edge Infrastructure Services at IDC, where we discussed industry trends around cloud adoption, and the whitepaper on “The Business value of Migrating and Modernizing with Microsoft Azure."

Dive deeper into our global survey findings and methodology by downloading the full report here.

Sources: Flexera 2022 State of the Cloud Report: Cloud Migration Stats—2022 Flexera State of the Cloud Report IDC.

The Business Value of Migrating and Modernizing with Azure, sponsored by Microsoft Azure, #US49665122 Published: 9/24/2022.
Quelle: Azure

Microsoft Azure's defense in depth approach to cloud vulnerabilities

Our digital world is changing, with more persistent, sophisticated, and driven cybercriminals. As risks increase and threats compound, trust is more important than ever. Customers need to be able to trust in the technology platforms they invest in to build and run their organizations. As one of the largest cloud service providers, we build trust by helping our customers be secure from the start and do more with the security of our cloud platforms that’s built in, embedded, and out of the box.

Our security approach focuses on defense in depth, with layers of protection built throughout all phases of design, development, and deployment of our platforms and technologies. We also focus on transparency, making sure customers are aware of how we’re constantly working to learn and improve our offerings to help mitigate the cyberthreats of today and prepare for the cyberthreats of tomorrow.

In this blog, we highlight the extensive security commitments from our past, present, and into the future, as well as where we see opportunities for continued learning and growth. This piece kicks off a 4-part Azure Built-In Security series intended to share lessons we’ve learned from recent cloud vulnerabilities and how we're applying these learnings to ensure our technologies and processes are secure for customers. Transparently sharing our learnings and changes is part of our commitment to building trust with our customers, and we hope it encourages other cloud providers to do the same.

Past, present, and future of our security commitments 

For decades Microsoft has been, and continues to be, deeply focused on customer security and improving the security of our platforms. This commitment is evident in our long history of leading security best practices from our on-premises and software days to today’s cloud-first environments. A shining example of this is when in 2004, we pioneered the Security Development Lifecycle (SDL), a framework for how to build security into applications and services from the ground up whose influence has been far reaching. SDL is currently used as the basis for built-in security in key initiatives including international application security standrards (ISO/IEC 27034-1) and the White House’s Executive Order on Cyber Security.

As security leaders and practitioners know though, security’s job is never done. Constant vigilance is vital. This is why Microsoft currently invests heavily in internal security research as well as a comprehensive bug bounty program. Internally, Microsoft boasts more than 8,500 security experts constantly focused on vulnerability discovery, understanding attack trends and addressing patterns of security issues. Our world-class security research and threat intelligence helps protect customers, Microsoft, open-source software, and our industry partners alike.

We also invest in one of the industry’s most proactive Bug Bounty Programs. In 2021 alone, Microsoft awarded $13.7 million in bug bounties across a broad range of technologies. An emerging trend over the last year has been an uptick in externally reported vulnerabilities impacting several cloud providers, including Azure. While vulnerabilities are not uncommon across the industry, as a leading cloud provider and the number one security vendor, Microsoft is of greater interest to researchers and security competitors alike. This is why our public bounty program was the first to include cloud services, beginning in 2014, and in 2021 we further expanded the program to include higher rewards for cross-tenant bug reports. As anticipated, this clearly drew even more external security researcher interest in Azure, culminating in multiple cross-tenant bug bounties being awarded. Regardless of the reasons, these findings helped further secure specific Azure services and our customers.

Finally, we firmly believe that security is a team sport, and our focus on collaboration is evidenced in our contributions to the security ecosystem, such as our involvement in the NIST Secure Software Development Framework (SSDF), and improving the security posture of Open Source Software (OSS) through our $5 million investment in the OpenSSF Alpha-Omega project.

Our commitment to security is unwavering, as seen in our decades-long leadership of SDL to present day vulnerability discovery, bug bounty programs, collaboration contributions, and continues well into the future with our commitment of investing more than $20 billion over five years in cybersecurity. While building-in security from the start is not new at Microsoft, we understand the security landscape is continually changing and evolving, and with it so should our learnings.

Our latest learnings and improvements for a more secure cloud

At Microsoft, a core part of our culture is a growth mindset. Findings from internal and external security researchers are critical to our ability to further secure all our platforms and products. For each report of a vulnerability in Azure, we perform in-depth root cause analysis and post-incident reviews whether discovered internally or externally. These reviews help us reflect and apply lessons learned, at all levels of the organization, and are paramount to ensuring that we constantly evolve and build in security at Microsoft.

Based on the insights we’ve gained from recent Azure vulnerability reports, we are improving in three key dimensions. These developments enhance our response process, extend our internal security research, and continually improve how we secure multitenant services.

1. Integrated response

Several lessons from the past year focused our attention in areas we recognize the need to improve, such as accelerating response timelines. We are addressing this throughout our Integrated Response processes and unifying internal and external response mechanisms. We started by increasing both the frequency and scope of our Security LiveSite Reviews at the executive level and below. We are also improving the integration of our external security case management and our internal incident communication and management systems. These changes reduce mean time to engagement and remediation of reported vulnerabilities, further refining our rapid response. 

2. Cloud Variant Hunting

In response to cloud security trends, we have expanded our variant hunting program to include a global and dedicated Cloud Variant Hunting function. Variant hunting identifies additional and similar vulnerabilities in the impacted service, as well as identify similar vulnerabilities across other services, to ensure discovery and remediation is more thorough. This also leads to a deeper understanding of vulnerability patterns and subsequently drives holistic mitigations and fixes. Below are a few highlights from our Cloud Variant Hunting efforts:

In Azure Automation we identified variants and fixed more than two dozen unique issues.
In Azure Data Factory/Synapse we identified significant design improvements that further harden the service and address variants. We also worked with our supplier, and other cloud providers, to ensure that risks were addressed more broadly.
In Azure Open Management Infrastructure we identified multiple variants, our researchers published CVE-2022-29149, and we drove the creation of Automatic Extension Upgrade capabilities to reduce time to remediate for customers. Our Automatic Extension Upgrade feature is already benefiting Azure Log Analytics, Azure Diagnostics, and Azure Desired State Configuration customers.

Additionally, Cloud Variant Hunting proactively identifies and fixes potential issues across all our services. This includes many known as well as novel classes of vulnerabilities, and in the coming months we will share more details of our research to benefit our customers and the community at large

3. Secure multitenancy

Based on learnings from all our security intelligence sources, we continue to evolve our Secure Multitenancy requirements as well as the automation we use at Microsoft to provide early detection and remediation of potential security risk. As we analyzed Azure and other cloud security cases over the last couple of years, both our internal and external security researchers have found unique ways to break through some isolation barriers. Microsoft invests heavily in proactive security measures to prevent this, so these new findings helped determine the most common causes and ensure we were committed to addressing them within Azure through a small number of highly leveraged changes.

We are also doubling down on our defense in depth approach by requiring and applying even more stringent standards for Compute, Network, and Credential isolation across all Azure services, especially when consuming third-party or OSS components. We are continuing to collaborate with the OSS community, such as PostgreSQL, as well as other cloud providers, on features which are highly desirable in multitenant cloud environments. 

This work has already resulted in dozens of distinct findings and fixes with the majority (86 percent) attributed to our specific improvements in Compute, Network, or Credential isolation. Among our automation improvements, we are extending internal Dynamic Application Security Tests (DAST) to include more checks for validating Compute and Network isolation as well as adding net new runtime Credential isolation check capabilities. In parallel, our security experts continue to scrutinize our cloud services, validate they meet our standards, and innovate new automated controls for the benefit of our customers and Microsoft.

From the cloud security’s shared responsibility model, we recommend our customers use the Microsoft cloud security benchmark to improve their cloud security posture. We are developing a set of new recommendations focusing on multi-tenancy security best practices and will publish that in our next release.

In short, while Microsoft has a long and continued commitment to security, we are continually growing and evolving our learnings as the security landscape also evolves and shifts. In this spirit of constant learning, Microsoft is addressing recent Azure cloud security issues by enhancing secure multitenancy standards, expanding our cloud variant hunting capacity, and developing integrated response mechanisms. Our enhancements, and the scale of our security efforts, further demonstrate our leadership and decades-long commitment to continual improvement of our security programs and raising the bar for security industry-wide. We continue to be committed to integrating security into every phase of design, development, and operations so that our customers, and the world, can build on our cloud with confidence.

Learn more

Follow the Microsoft Security Response Center blog for our latest security research findings.
Learn more about how Microsoft Azure can help strengthen your security posture.
To learn more about our responses to cloud security updates, read our blogs: the Anatomy of a Cloud-Service Security Update and Anatomy of a Security Update.

Quelle: Azure

Fähigkeiten von Elastic Load Balancing für die Verfügbarkeit von Anwendungen

Wir freuen uns, vier neue Fähigkeiten von Elastic Load Balancing bekannt zu geben, die die Verfügbarkeit Ihrer Anwendungen weiter verbessern werden. AWS bietet mehrere Bausteine, wie Regionen und Availability Zones, damit Sie Ihre Anwendungen so entwerfen können, dass sie von verschiedenen Arten von Ausfällen isoliert sind. Ab heute bieten wir zusätzliche Funktionen an, mit denen Sie definieren können, wie sich Ihre Anwendungen im Fall von Ausfällen verhalten sollen, sowie eine Funktion, die zu einer schnelleren Wiederherstellung beiträgt. Diese neuen Funktionen umfassen:
Quelle: aws.amazon.com

Ankündigung von Funktionen in AWS Lambda SnapStart für Java

AWS Lambda SnapStart für Java liefert ohne Zusatzkosten bis zu zehnmal schnellere Startzeiten für Funktionen. Lambda SnapStart ist eine Leistungsoptimierung, mit der Sie ganz einfach reaktionsschnelle und skalierbare Java-Anwendungen mit AWS Lambda erstellen, ohne Ressourcen bereitstellen oder Zeit und Personal für die Implementierung komplexer Leistungsoptimierungen aufwenden zu müssen. 
Quelle: aws.amazon.com

Amazon FSx für NetApp ONTAP vereinfacht den Zugriff auf Multi-AZ-Dateisysteme aus On-Premises- und über Peering verbundenen Netzwerken

Amazon FSx für NetApp ONTAP verkündet eine neue Funktion, die den Zugriff auf Multi-AZ-Dateisysteme von anderen Netzwerken aus (On-Premises-Netzwerke und über Peering verbundene Netzwerke in AWS) weiter vereinfacht. Ab heute können Sie Multi-AZ-Dateisysteme erstellen, auf die Sie über AWS Transit Gateway von anderen Netzwerken aus zugreifen können, ohne zusätzliche Routing-Konfigurationen durchführen zu müssen. Dadurch wird der Einstieg noch schneller und einfacher.
Quelle: aws.amazon.com

Ankündigung von netzwerkoptimierten Instances M6in, M6idn, R6in und R6idn in Amazon EC2

AWS gibt die allgemeine Verfügbarkeit von M6in- und M6idn-Instances und R6in- und R6idn-Instances von Amazon EC2 bekannt. Diese netzwerkoptimierten Instances der sechsten Generation werden von skalierbaren Intel-Xeon-Prozessoren der 3. Generation mit einer All-Core-Turbofrequenz von 3,5 GHz angetrieben. Sie sind die ersten x86-basierten allgemeinen und speicheroptimierten Instances, die bis zu 200 Gbit/s Netzwerkbandbreite bieten. Diese Instances liefern bis zu zweimal mehr Netzwerkbandbreite und bis zu doppelt so hohe Paketverarbeitungsleistung wie vergleichbare Instances der fünften Generation. Die Instances basieren auf dem AWS Nitro System, einer Kombination aus dedizierter Hardware und schlankem Hypervisor, der praktisch alle Rechen- und Speicherressourcen der Host-Hardware für die Instances bereitstellt und so für eine bessere Gesamtleistung und Sicherheit sorgt. Sie können die Leistung von Anwendungen wie SQL- und NoSQL-Datenbanken, In-Memory-Datenbanken (SAP HANA), Telco-Anwendungen (5G User Plane Function (UPF)), leistungsstarke Dateisysteme, verteilte In-Memory-Caches für die Webebene und Big-Data-Analyse in Echtzeit skalieren.
Quelle: aws.amazon.com

Amazon QuickSight kündigt paginierte Berichte an

Amazon QuickSight unterstützt jetzt paginierte Berichte, die die Erfassung detaillierter Betriebsdaten in benutzerdefinierten Formaten ermöglichen, um kritische und tägliche Geschäftsprozesse zu erleichtern. Sie können beispielsweise einen wöchentlichen Snapshot von Betriebsmetriken im Tabellenformat erhalten, der von den Geschäftsteams kritisch geprüft wird.
Quelle: aws.amazon.com