Cisco Live 2022: Cisco Catalyst Management is coming to the Meraki cloud

At Cisco Live 2022 this week, Cisco annouced that Catalyst is coming to the Meraki cloud which put simply means that organisations will now be able to manage their Catalyst switches and access points using the Cisco Meraki cloud dashboard, providing a centralised view of the network with real-time switch status and health.

Image (c) Cisco Meraki

Supported platforms

At time of launch, the Catalyst 9200, 9300 and 9500 switching platforms will be supported in the Meraki dashboard with two different options:

  • Cloud Monitoring (monitoring only)
  • Cloud Management (monitoring and config management)

Licensing

  • Monitored Catalyst switches needs only a Meraki license.
  • Fully managed Catalyst switches requires DNA Advantage (DNA-A) or DNA Essentials (DNA-E) licensing.

The main difference between the two switching licenses is that DNA-E will not include application visibility or client usage data.

Is this the end to DNA Center?

Put simply, No. What Cisco is doing is providing more flexibility and options to their customers. It will mean, however that organisations will need to make a choice as to where that want to manage their Cisco Catalyst infrastructure. In Meraki, in DNA Center, or standalone.

Once a Catalyst switch is fully managed by Meraki it will no longer be an IOS device and will instead run Cisco Meraki software. If the Catalyst switch is a monitored only switch though, it will still be accessible and manageable via the CLI.

New Catalyst Wireless Switches

Cisco also annouced that they are introducing three new Catalyst wireless access points that can be managed by their Meraki dashboard or a C9800 controller.

  • Catalyst CW9166
  • Catalyst CW9164
  • Catalyst CW9162

Feature Partity with DNA Center?

No.. Well not initially anyway.

Since this is the first iteration of Catalyst management within the Meraki Cloud dashboard, there will not be feature parity with what is possible with the CLI or DNA Center. Initially all the core basic basic monitoring and configuration will be available and Cisco have a said a feature list and roadmap will be published soon.

Why are Cisco taking this approach?

Cisco have traditionally been continuing to build on-premises software solutions, such as DNA Center, but with their increased focus of software subscriptions and cloud this is a logical move and something their competition have been doing for a while.

Since the aquisition of Meraki back in 2013, Cisco have continued to try to provided multiple options for their customers and this appears to eb a great move into that hybrid space, providing and option for scenarios where DNA Center maybe too much or complex, but a more simplistic cloud managed approach with a Meraki may well fit organisations who want cloud management with Meraki while still having the feature-rich capabilities of the Catalyst product set.

Getting Started…

Cisco advise their customers to speak to their account manager, work with their trusted a isco partner and / or to check out their get started guide. There’s no need to go full in and organisations can start their move cloud management for Catalyst at their own pace.


Read the full detail from Cisco

Microsoft Entra aims to secure access for the multicloud connected world

Microsoft has just announced “Entra“, which is the latest “family of products” and joins their other suites alongside Priva and Viva.

Entra brings together all of Microsoft’s identity and access products and services and includes Microsoft Azure Active Directory (Azure AD), as well as their Cloud Infrastructure Entitlement Management (CIEM) and decentralized identity services.

Identity is one of the biggest cornerstones for cybersecurity.

Microsoft Entra. Image (c) Microsoft

Microsoft Entra aims to help simply the way organisations approach and accomplish attack surface reduction in the multicloud, hyperconnected world by filling the biggest and most critical gaps. It does this by:

  • Protecting access to any application or resource for each and every user
  • Secure and verify every identity across hybrid and multicloud environments
  • Discovering and governing permissions in multicloud environments
  • Simplying the user experience with real-time intelligent access decisions.

Microsoft Entra embodies our vision for what modern secure access should be. Identity should be an entryway into a world of new possibilities, not a blockade restricting access, creating friction, and holding back innovation. We want people to explore, to collaborate, to experiment – not because they are reckless, but because they are fearless.

Microsoft.

Entra works with the majority of all cloud platforms, including Azure, AWS, Google Cloud, as well as other Microsoft apps and websites.


To find out more, visit the Microsoft Entra website to learn more about how Azure AD, Microsoft Entra Permissions Management, and Microsoft Entra Verified ID deliver secure access for our connected world.

Cisco becomes first SD-WAN vendor to leverage Microsoft Informed Networking Routing to optimise performance of Microsoft Teams and SharePoint

Cisco Cloud On-Ramp

Cisco has released an updated version of their SD-WAN software which now supports the optimal routing of Microsoft SaaS apps including Microsoft SharePoint, OneDrive, and Teams on their SD-WAN. Cisco’s Vipella SD-WAN solution is the first SD-WAN solution to be certified for this.

Note: At time of writing, this feature applies to Cisco’s Viptela SD-WAN solution and is not currently supported in the Cisco Meraki SD-WAN portfolio. This may change.

With this update to the Cloud OnRamp feature, Cisco SD-WAN “further integrates Cisco’s support for Microsoft’s Informed Network Routing technology that lets organisations share Microsoft 365 app feedback telemetry with networking vendors and to receive network link telemetry from them”, according to Jeevan Sharma, Manager, Product Management, Enterprise Cloud & SD-WAN group at Cisco in a blog about the enhancements.

Known as Cloud OnRamp for Microsoft 365, it uses “proactive and continuous link probing to assess the best performing path at any point in time. It also allows network admin to utilize Microsoft URL categories granularity for categorizing the Microsoft 365 apps into Optimize, Allow and Default categories, while active link probing makes sure that the best performing path is always selected”.

How it works

This latest update to Cisco’s SD-WAN software, which continually monitors and controls the connectivity, management, and services between data users (remote or office based) and cloud and data centre services, now includes support for more Microsoft SaaS applications specifically SharePoint (and OneDrive) and Microsoft Teams.

Cisco SD-WAN customers can leverage Cisco’s Cloud OnRamp to intelligently route Microsoft 365 traffic, to provide the fastest, most secure, and most reliable end-user experience. This is done by ensuring that all connectivity paths to Microsoft 365 from each WAN / Internet connection at the branch, office, regional hub and/or data center is monitored continuously for performance, and application traffic is then dynamically routed to the best-performing path without requiring human intervention. Cisco Cloud OnRamp also provides real-time and historical visibility into SaaS application performance.

“I am excited to announce that the integration between Cisco SD-WAN and Microsoft Informed Network Routing now includes support for Microsoft Teams and SharePoint app telemetry. This update will help us deliver an improved end-user experience through enhanced cloud connectivity. The partnership between Microsoft 365 and Cisco SD-WAN further enhances your Microsoft Teams and SharePoint experience by optimizing routing and path selection beyond traditional network telemetry probes”

Jeff Mealiffe | Principal Architect | Microsoft 365 Core Networking | Cisco

Microsoft and Cisco Partnership

Cisco SD-WAN is Microsoft Network Partner Program (NPP) certified and is also a Microsoft 365 networking partner. As part of this program, Cisco SD-WAN aligns with the Microsoft’s Connectivity Principles aimed at helping Microsoft 365 customers achieve optimal end-user experience.

What is SD-WAN?

SD-WAN technology is available from leading network and vendors such as Cisco, Palo Alto etc, and typically include routers and switches or virtualised customer-premises equipment (vCPE). They run together using a connected software stack that handles things like policy, security, networking functions, and other management and security functions.

Cisco SD-WAN technology enables enterprises to build a scalable and carrier-neutral WAN infrastructure, allowing them to reduce WAN transport costs and network operational expenses. Cisco SD-WAN enables IT to apply business-centric, application-aware, and differentiated routing policies – providing end users at the remote offices, branch direct connectivity to performance-intensive trusted app, such as Microsoft 365, while routing generic Internet traffic via SWGs, CASBs, or the customer’s VPN connected data center.

Microsoft’s new “Cyber Signals” gives vital insights into current cybersecurity threats

Microsoft has launched their first Cyber Signals, a new quarterly cyber intelligence brief that highlights the latest cyber security threats, tactics, and strategies and is aimed at Chief Information Security Officers, Chief Information Officers, Chief Privacy Officers and other senior security opps teams.

Microsoft Cyber Signals Report

The brief is built using Microsoft’s extensive threat and data and research which leverages insights from more than 24 million security signals as well as intelligence data mined from the monitoring of 40 nation-state groups and over 140 threat groups. Microsoft has focused the first edition specifically on identity, which they believes is “the battleground for security” and the biggest weakest link in most organisations security posture.

In the briefing, Microsoft state that “Our identities are made up of everything we say and do in our lives, recorded as data that spans across a sea of apps and services. While this delivers great utility, if we don’t maintain good security hygiene our identities are at risk. And over the last year, we have seen identity become the battleground for security.

Perhaps the biggest point raised in this Cyber Signals report is the worrying low adoption of strong identity authentication across organisations. This includes multifactor authentication (MFA) which are proven to reduce the risk of compromised identity by 99.9%.

Here are they key highlights from the report.

  • Only 22% of customers using Microsoft Azure Active Directory (Azure AD), Microsoft’s Cloud Identity Solution, have implemented strong identity authentication protection as of December 2021.
  • Microsoft Defender for Endpoint blocked more than 9.6 billion malware threats targetting enterprise and consumer customer devices
  • From January 2021 through December 2021, Microsoft blocked more than 25.6 billion Azure AD brute force authentication attacks and intercepted 35.7 billion phishing emails with Microsoft Defender for Office 365.

The full brief also examines how nation-states are using spear phishing attacks and targeted social engineering to obtain passwords and other sensitive data. It also details the latest Ransomware attack trends and how they are being along with guidance and recommendations for how to stop the attacks.

“Microsoft ended 2021 with 71 billion cyberattacks blocked.”

Microsoft Cyber Signals

Much of the research explained by leading security chiefs including Christopher Glyer – the principal threat intelligence lead at the Microsoft Threat Intelligence Center which employs nearly 4,000 security experts and threat hunters.

You can learn more about these trends and read the report on Microsoft’s Security Blog site….

… Oh and please let’s get MFA enabled for all corporate accounts and close that front door!

Use MFA

Defender for Endpoint now included within Microsoft 365 E3/A3

As of today (14th Jan 2022) Microsoft Defender for Endpoint Plan 1 is now included within Microsoft 365 E3/A3 licenses.

Microsoft Defender for Endpoint (Plan 1) extends Microsoft 365 security by including world class threat and attack prevention capabilities to help you deliver against your Zero Trust strategy, reduce cost (by negating the need for additional products) and simplifies security management.

Defender for Endpoint Plan 1 includes the following key features (among others).

  • Next generation, born in the cloud, antivirus, anti malware and anti ransomware protection that leverages all the intelligence of the Intelligent Security Graph to help keep users endpoints secure and protected.
  • World class attack surface reduction capabilities that harden the device, prevent zero day attacks, and provide granular control over access.
  • Device based conditional access which leverages Azure AD and the Intelligent Security Graph to provide additional layers of protection and breach protection and forms a key part of your Zero Trust Security architecture.

Microsoft Defender is a Top right Magic Quadrant leader for Endpoint Protection.

Gartner Magic Quadrant for Endpoint Protection

What’s included in Defender for Endpoint Plan 1

The following diagram from Microsoft illustrates the key services and features included within both Plan 1 (now part of Microsoft 365 E3 and A3) and Plan 2 (part of Microsoft 365 E5 and A5 or available as an add-on).

Defender for End Point Plan 1 vs Plan 2.

Microsoft Defender for Endpoint Plan 1 supports client endpoints running Windows 7 with Extended Security Updates, 8.1, 10, 11, macOS, Android, and iOS.

What about Plan 2?

Microsoft say that Plan one provides a strong baseline and leading edge protection against modern day, zero day and every advancing threats.

For the complete set of endpoint security capabilities, as shown above, Microsoft advise that organisations strongly consider Microsoft Defender for Endpoint Plan 2.

“Plan 2 builds on Plan 1 and provides a best in class EDR solution including automated investigation and remediation tools, advanced threat prevention and threat and vulnerability management (TVM), and hunting capabilities which which combined with the wider Microsoft Defender suite provides seemless, integrated and cross architecture protection”.


To find out more, please refer to the official Microsoft documentation.

https://aka.ms/MDEP1docs

Microsoft SIP gateway service let’s you use legacy SIP phones with Teams

Microsoft’s SIP gateway service was officially released as of today today. This means organisations can now repurpose a wide range of ‘old’ SIP phones and use them with #MicrosoftTeams helping to reduce TCO of Teams Voice Migrations and drive value out of legacy hardware.

The new SIP Gateway Service (which has been in private preview for a few months) is a solution that enables core Teams calling functionality on compatible SIP phones including many from Cisco, Poly, Yealink and AudioCodes.

Microsoft SIP gateway

Breathing life into legacy handsets

The SIP Gateway supports the following core Teams calling functionality:

  • Inbound and outbound calls
  • Call transfer
  • Meeting dial-in and dial-out
  • Device level based “do not disturb”
  • Voicemail with message waiting

The SIP Gateway Service is FREE

Microsoft are making the SIP Gateway service for free, and any user can use the SIP Gateway so long as they meet the following requirements.

  • Licensed for Teams Phone via Office 365 E5, Microsoft 365 E5 or a standalone license.
  • Enabled for PSTN, which means a phone number in Teams assigned via Calling Plan, a Direct Routing or Carrier Connect (calling via third party apps not supported)
  • Common Area devices licensed via Common Area Phone license.

For the best experiece Teams Phones are recommended

In the official Microsoft Teams blog, Microsoft reminds us that while their SIP Gateway and Skype for Business 3PIP Gateway services provide valuable flexibility for organisations wishing to sweat their legacy SIP phone investments, Teams phone devices provide the most complete Teams experience.

What devices are supported

These are the currently supported phones (at time of writing).

  • Cisco IP Phones (6821,7800 series, 8800 series)
  • Poly SIP Phones (VVX 100,200, 300, 400, 500, 600 etc.)
  • Yealink Phones (T20, T30 T40 and T50 series)
  • AudioCodes HD 400 series

Note: for Cisco, organisations need to license the MPP firmware for each SIP phone


You can read the full annoucement here:

https://techcommunity.microsoft.com/t5/microsoft-teams-blog/enable-core-microsoft-teams-calling-functionality-on-compatible/ba-p/3030196

Cisco’s new Enterprise Agreement is great for partners and customers

I feel I must congratulate Cisco on the annoucement of their new partner and customer centric Enterprise Agreement.

Simple and Inclusive

This looks and feels like one of the simplest yet powerful subscription based licensing programmes in the channel… at a time when “other” major vendors seem to be struggling to get a model right that is fair and offers value to both customer and partners regardless of size.

Consistent across their solution portfolio

When fully available in early 2022, Cisco will make their full portfolio of services available through a single agreement rather than the current multiple EAs with different terms, rules and portals they have today. Instead the EA will cover all five of Cisco’s solution areas – application infrastructure, networking infrastructure, collaboration, security and services.

Helps make it easy for customer to buy solutions across the stack

This new EA will dramatically simplify purchasing and selling as it creates one program and one experience for everything Cisco do and aligned to their product portfolio.

For example, Cisco has been beating the drum hard with the concept of “full stack observability”, which is growing in importance in this multi-cloud centric, highly mobile and hybrid world.

To make this a reality, customers, need to buy products across multiple technology and solution stacks, including services like AppDynamnics, ThousandEyes, Intersight etc., but this new should make it much easier for partners to sell and for customers to buy.

#cisco #collaboration #ciscopartner #security #partners #customers #subscription

Microsoft buys CloudKnox, the only multi-cloud, hybrid cloud permissions management platform

After their acquisition RiskIQ just last week and ReFirm the month before, Microsoft have just annouced they are now aquiring CloudKnox, a leader in Cloud Infrastructure Entitlement Management (CIEM).

Who are CloudKnox?

Founded in 2015, CloudKnox, are the only multi-cloud, hybrid cloud permissions management platform that provide granular visibility, automated remediation and continuous monitoring consistently enforcing least-privilege principles to reduce risk. CloudKnox works with Azure, as well as the AWS and Google public clouds as well with leading virtualisation and hybrid cloud vendors including VMware.

Image displaying key features of CloudKnox
CloudKnox

CloudKnox are the leaders in Cloud Infrastructure Entitlement Management (CIEM) space and offers complete visibility into privileged access within cloud services.

What Microsoft plans to do with the CloudKnox acquisition.

In Microsoft’s most recent security blog, Joy Chik (VP of Identity at Microsoft) said:

“Modern identity security needs to protect all users and resources consistently across multi-cloud and hybrid cloud environments….Today, Microsoft is taking a significant step toward this goal with the acquisition of CloudKnox Security, a leader in Cloud Infrastructure Entitlement Management (CIEM). CloudKnox offers complete visibility into privileged access. It helps organizations right-size permissions and consistently enforce least-privilege principles to reduce risk, and it employs continuous analytics to help prevent security breaches and ensure compliance. This strengthens our comprehensive approach to cloud security.”

Joy Chik, Corporate VP of Microsoft Identity

The post (which can be read here) summarises how Microsoft will leverage the CloudKnox technology to help Security Admins with tasks such as managing privileged access in multi-cloud and hybrid cloud environment through a set of comprehensive yet simple threat assessments and prevention methods as well as ensuring security enforcement and governance.

Finally Microsoft said that the acquisition of CloudKnox will allow Microsoft to further harden Azure Active Directory with more granular visibility, continuous monitoring and automated remediation for their hybrid and multi-cloud identities, access and permissions further solidifying their market leading position in Identity and Access Management.


Windows Server and SQL 2008 and 2012 – Extended Support Options

SQL and Windows Server 2008

Extended Security Updates were made available (at a cost) by Microsoft for both SQL Server and Windows Server versions 2008 and 2008 R2 since “official support” ended but these extended support update are also now coming to an end on:

  • SQL Server 2008: July 9th, 2022
  • Windows Server 2008/2008 R”: Jan 14th, 2023 respectively.

If your organisation is still running any of these older server products in Azure then you will be currently entitled to (and receiving) 3 years of free Extended Security Updates, and Microsoft have recently announced that one more year of Extended Security Updates will be available BUT ONLY if these workloads are running in Azure.

 

SQL Server and Windows 2012

Support for SQL Server 2012 and Windows Server 2012 / 2012 R2 is also coming to an end:

  • SQL Server 2012: July 12th, 2022
  • Windows Server 2012/2012 R2 on October 23rd 2023

As with version 2008, Microsoft will be making (again at a cost) 3 years of Extended Security Updates available from your licensing partner or Cloud Solution Provider (CSP) and, as before these will be free if these workloads are running (or moved into) Azure

If you are no planning on moving these into Azure, then you’ll need to buy licences for each server instance you need to cover.

Cost for ESU are

  • Year 1: 75% of the licence cost
  • Year 2: 100% of the licence cost
  • Year 3: 125% of the licence cost

What are my options?

If you are still on Windows Server 2008 or SQL 2008, you have 3 options:

  1. Migrate the VMs/Servers into Azure for  ONE MORE YEAR of free support
  2. Migrate or Rehost apps and workloads to Windows Server and SQL Server on Azure virtual machines
  3. Modernize with Azure services such as App Service and Azure SQL Managed Instance, and never have to patch or upgrade again.

If you are Windows or SQL Server 2012, you have 4 options:

  1. Pay for Extended Support for up to 3 years
  2. Upgrade the Servers to a supported version of SQL and Windows 
  3. Migrate or Rehost apps and workloads to Windows Server and SQL Server on Azure virtual machines
  4. Modernize with Azure services such as App Service and Azure SQL Managed Instance, and never have to patch or upgrade again.

 

Further Reading and References

You can find the formal announcement here, along with the data sheet which does into more detail, as well as a FAQ from Microsoft. 

#Windows365 is here as Microsoft announces Cloud PC at Inspire2021

Windows365 is a new service that will let users access their corporate ‘cloud’ PC from anywhere by streaming a version of Windows 10 (or Windows 11 when released) in a web browser. At initial launch, (2nd August 2021), organisations have two edition options – Windows 365 Business and Windows 365 Enterprise – with multiple Cloud PC configurations in each edition based on performance needs.

Designed for the disparate and agile workforce

Windows 365 allows organisations to equip distributed workforces, temporary and seasonal employees, contractors, and employees who have a need for specialised workloads in a flexible and highly secure manner – regardless of their location or device. Windows 365 will allow organisations to add and remove users with secure managed Cloud PCs according to the changing needs of the business and of the individual user, allowing them to scale for busy periods without the logistical challenges of issuing new hardware. Cloud PCs can be scoped, and scales based on the specification/power that best meets the user need and is paid for on a simple per user per month price.

Built on Azure Virtual Desktop – runs on anything

Windows 365 is built on Azure Virtual Desktop but simplifies the virtualization experience and licensing. Organisations that require greater customization and flexibility can of course still opt for Azure Virtual Desktop to modernize their VDI (Virtual Desktop Infrastructure) in the cloud or use a combination of both. 

Windows 365 offers a consistent Windows experience, across any device/operating system including Windows, Mac, Linux, iOS, or Android. It promises to support all your business apps such as Microsoft 365, Dynamics 365, Power Platform, line of business apps, and more as well as the Office 365 suite.

It provides an instant-on boot experience that enables users to stream all their personalized applications, tools, data, and settings from the cloud across any device and allow them to pick up right where they left off. The state of a user’s Cloud PC remains the same, even when they switch devices.

Feature Support for Windows 365
Windows 365 Device Support (July 2021)

Consistent Device Management

Microsoft Endpoint Manager is used to procure, deploy, and manage Cloud PCs for their organisation, since Windows 365 is consistent with how they manage physical devices with Microsoft End Point Manager. Cloud PCs are managed alongside physical devices and can apply management and security policies to them in the same way as they do on physical devices.  There is extensive monitoring too and IT can change on the fly the specification (processor, RAM, and disk) to adjust the performance of the Cloud PC to make sure the users are getting the best experience. There’s also built-in analytics and performance metrics to look at connection health across network to make sure the Cloud PC users can reach everything they need.

Build on Zero Trust Foundation

Windows 365 is built with a focus on a Zero Trust architecture. It stores information in the cloud, not on the device, and encryption is used everywhere as you’d expect with an Azure service. All managed disks running Cloud PCs are encrypted, stored data is encrypted at rest, and all network traffic to and from the Cloud PCs is also encrypted.

Licensing Information

Unlike other virtualisation services, Windows 365 is priced on a per-user price and are allocated via the Microsoft 365 admin centre portal in the same way as other Microsoft 365 E3/E5 licenses.

Windows 365 will initially come in two flavours – Business and Enterprise, and Microsoft will offer 12 different configurations for both the editions. The Cloud PCs can be configured with a single CPU, 2GB of RAM, and 64GB of storage at the low-end, all the way up to eight CPUs, 32GB of RAM, and 512GB of storage.

A full range of available configuration and example scenarios is available here.

Windows 365 will be officially available on August 2, 2021, and pricing will be announced on the same day, though rumours say we expect pricing to start from ~£25pupm

 

There are no clouds in space… But there is Azure!

I read an article recently about Stephen Kitay – the Former Deputy Assistant Secretary of Defense for Space Policy, who is now  Senior Director at Microsoft Azure Space. It got me thinking… Firstly.. what a cool job title…. and secondly… what is Azure Space..

It’s quite cool.. Tech and Space!

Microsoft says that “Azure Space was created to be the platform and ecosystem of choice for the mission needs of the space community” . It’s designed to make connectivity and compute increasingly attainable across industries including agriculture, energy, telecommunications, and government.”

Azure Space Overview

I loved researching and sharing some of what I read. What a great project to be part of… Imagine being asked what do you at a networking event and saying “supporting customers on their space missions off and on the planet, using the power of cloud and space technology to help business across industries re-imagine solutions to some of the world’s most challenging problems”

Taking cloud-powered innovation beyond Earth with “Azure Space”.

With the enormous challenges space presents, there also comes great opportunity. The space community is growing rapidly, and innovation is lowering the barriers of access for public and private sector organizations.

Microsoft is the first hyperscale cloud service provider to join the Space Information Sharing and Analysis Center (ISAC) as a member organization and they plan to share our unique global threat insights to protect critical infrastructure and strengthen cybersecurity expertise across the space community.

What is the purpose and applications for Azure Space?

Microsoft are diligently working to make Azure the platform of choice for the mission needs of the space community, bringing our unique global threats insights to protect critical infrastructure and strengthen cybersecurity expertise in the space industry“.

But…. Its not just about sticking Azure in space stations and shuttles.

Putting compute, data and AI into space makes connectivity and compute increasingly more attainable and accessible across the globe and has huge benefits across industries such as agriculture, energy, telecommunications as well as across the public sector and in particular in regions where traditional connectivity and access to compute is more sparse. Third and developing world nations will also hugely benefit. “ our ambition is to grow the entire world community, which is the basis for Azure Space.”

OK so what is Azure Space though?

Azure Space is basically a set of innovative service offerings, a new partner ecosystem and a global strategy focused on specific core areas to addresses never-before-seen security challenges. Azure Space is made up of 3 main things..

Azure Space Components Overview

Azure orbital

Azure Orbital is a Ground Station As-a-Service that provides communication and control of a satellite and enables satellite operators to communicate with and control their satellites, process data, and scale operations within Microsoft Azure.

Azure Orbital brings satellite data directly into Azure, where it can immediately be processed with market-leading data analytics, geospatial tools, machine learning, and Azure AI services.

In essence Azure Orbital will allow  organisations/providers of “space connected stuff”, to take full advantage of the Microsoft’s global network and services infrastructure to build new product offerings and services with the edge, 5G, SD-WAN, and AI.

Azure Modula Datacenter

 The Azure Modular Datacenter (MDC) is a complete, rugged datacenter solution for organisations/servjce providers that need cloud computing capabilities in hybrid, sparse or challenging environments like space.

Microsoft designed the MDC to support high-intensity, secure cloud computing in challenging environments, such as situations where critical prerequisites like power and building infrastructure are unreliable. Built on Azure Stack(r), it is a self-contained unit the provides the capability to deploy a complete datacenter to remote locations, or to complement existing infrastructure. The MDC runs primarily on terrestrial fiber, low-bandwidth networks, or be completely disconnected.

Azure Orbital Simulator

With space mow opening up to more commercial and government space organisation, the pace and demand of developing interconnected satellite networks increases exponentially.

To aid with this, Microsoft have created Azure Orbital Emulator, an emulation environment that conducts massive satellite constellation simulations with software and hardware in the loop. This allows satellite developers to evaluate and train AI algorithms and satellite networking before ever launching a single satellite reducing cost, time and money as well as human safety naturally. With Azure Orbital Emulator, Azure can emulate an entire satellite network including complex, real-time scene generation using pre-collected satellite imagery for direct processing by virtualized and actual satellite hardware.

“The Goal of Azure Orbital Emulator is to aid the preparation of space missions with the power of Azure.”

Azure Orbital Emulator is already being used Azure Government customers globally.

Credits and further reading

Some of the content here is referenced/quoted from the full comprehensive report. https://www.helpnetsecurity.com/2021/07/13/microsoft-azure-space and on twitter at @helpnetsecurity. Much of the information comes from Microsoft Azure blogs referenced below.

For further reading (it’s quite interesting) you can read Microsofts official blurb and ongoing updates here.

Registration open for ‘virtual’ Microsoft Inspire 2021 partner event.

Microsoft has opened registrations for this years Inspire 2021 virtual conference, which will be held on July 14th and 15th.

Microsoft Inspire is Microsoft’s largest (and global) annual partner event and as usual features several high-profile global execs including CEO Satya Nadella and EVP of Worldwide Commercial Business Judson Althoff.

What might we hear about?

Last year, there was huge news and updates around Azure,  Microsoft Teams, Microsoft Edge as you’d expect with also a focus on new services such as Microsoft Lists, and Power Automate Desktop.

This year we can expect to hear some new enhancements and updates and I expect to see a focus around the recently(ish) announced Microsoft Viva along with more updates around Windows (following the event on the 24th June) and probably some new things none of us are expecting… .

You can register for Microsoft Inspire 2021 on this page with your Microsoft account, Office 365, LinkedIn, or GitHub account.

See you there Microsoft partners…

Windows Virtual Desktop becomes Azure Virtual Desktop

Microsoft announced today that they are rebranding Windows Virtual Desktop (WVD) to Azure Virtual Desktop (AVD).

In the annoucement, Microsoft also said that a number of new enhancements (some of which have gone into public preview from today) are coming, which are part of the wider and longer term vision and the changing needs of customers. In the annoucement Microsoft said that the COVID19 pandemic has resulted in organisation moving rapidly to Windows Virtual Desktop for “secure, easy to manage, productive personal computing experience with Windows 10 from the cloud”.

Improved Azure AD Support

Azure Virtual Desktop will support the ability for users to domain join their virtual desktops directly to AAD using just their credentials. They are also fully removing the need for organisations to need Windows domain controller allowing Azure AD as the only or primary authoritive directory service.

Azure Virtual Desktop will also add further support for secure sign on and single sign on, bringing support for smart cards and FIDO2 keys

Another feature now out in public preview is the ability to enroll and manage Windows 10 Enterprise multi-sessions virtual machines through Endpoint Manager just like admins would for physical machines. This further improves the process of managing both physical and virtual desktops using the Endpoint Manager admin center.

Enhanced Endpoint Manager support.

Microsoft have said they are also adding support for IT to be able to automatically enroll these virtual machines using Microsoft Endpoint Manager (formerly Intune), bringing a much more “streamlined” deployment and management experience.

Also coming soon (and in public preview from today) is the ability to be able to enroll and manage Windows 10 Enterprise multi-sessions virtual machines through Microsoft Endpoint Manager in the same way that physical devices are managed today. This closes the management gap and streamlines the process of managing both physical and virtual desktops using the same Endpoint Manager experience.

New QuickStart Experience

Microsoft said that new deployment onboarding experience which will be available soon (in preview first naturally). This is designed to help organisations initiate fully automated deployments from the Azure portal using just a simple wizard style process.

New “per user” pricing model

Yes.. As it pricing and license wasn’t complicated enough, there are new pricing options coming for organisation to leverage Azure Virtual Desktop VDI and streamed applications in the form of a true SaaS based model.

To make this simpler, Microsoft have announced a new monthly per-user pricing

This new pricing will launch on January 1st, 2022, and will be $5.50 per user per month for apps, and $10 per user per month for apps plus desktops.

A launch promo will mean organisations will be able to use Azure Virtual Desktop for streaming first-party or third-party applications to external users at no cost from July 14, 2021, to December 31, 2021, after which they will need to keep paying for the underlying Azure infrastructure.

You can read about the pricing options here.

The biggest announcements from MSFT Ignite 2021

So, it wouldn’t be a Microsoft event (#MSIgnite) without a handful of “wow” demos, updates, and new products announcement both in preview and GA across Teams, the wider Microsoft 365 platform, Azure, Windows 10 and Power Platform, but without doubt the biggest “thing” to happen at Ignite this year was Mcirosoft Mesh.  Anyway, here’s my 

As in previous years), Microsoft have published their “encyclopaedia” if you like, of Ignite (the #BookOfIgnite ) which covers all the announcements in detail along with links to blogs and tech articles.

This post, on the other hand is a summary of my personal “top 3” announcements across each of the core solution areas. Of course, depending on your role, line of business and priorities, and interests, you will have your own favourites so feel free to let me know yours in the comments.

 

Microsoft Mesh

This stole the show from the moment the keynote started and was without question the biggest news of Ignite 2021. Much of the keynote and later sessions were available to watch live AltSpace VR in both Mixed and Virtual Reality. Mesh is Microsoft’s new Mixed Reality Platform which is designed to allow people who are in physically various locations to join collaborative and shared holographic experiences across many kinds of devices.

The business case for Mesh builds upon the success of HoloLens 2 and is designed (and was highlighted) for organisations to let their teams joined shared virtual spaces for collaborative meetings, where everyone will appear as virtual avatars (reminds me of the holograms in the StarWars). Microsoft say that their target audience is both enterprise and commercial customers. Microsoft Mesh can be accessed through an updated version of AltSpace VR, which is Microsoft’s VR platform. Microsoft Mesh will be coming to HoloLens via a dedicated app and solutions built through Mesh by developers will also be able to be tailored/supported to Windows Mixed Reality, PCs, Macs, Smart Phones, and headsets like Oculus.

Microsoft Teams

Teams Ignite Features
Highlight of new Teams Meeting Features

 

Always needing its very own category, my top 3 in this category are:

1. Improvements for Teams Meetings and Live Events.

    • Teams can now be used to create and run fully interactive webinars for up to 1,000 attendees and will also support webinars with up to 20,000 attendees from later this month. This will also be included for any customer with Office 365 E3 and more without any additional licenses or cost.
    • Dynamic View for Teams meetings will be released next month and is all about ensuring more inclusive and natural meetings for remote/hybrid meetings making them more engaging. Dynamic view uses AI to adjust elements of the meeting to allow for display different modes such as charts, chats, etc next to video feeds as well as an overlay of presenter video and presentation space.
    • Improved privacy and security in meetings – with meeting-only meeting controls and end-to-end encryption in one-to-one calls.
    • PowerPoint Live in Teams is available now. The much-requested feature combines slides, notes, and meeting chat in a single view to help make presentations easier for speakers and presenters and to make them more engaging for attendees.

2. Teams Connect

A new channel-sharing feature coming to Teams “later” this calendar year. This will enable users to share channels with anyone, internal or external. Unlike guest access, the shared channel will appear within a user’s primary Teams tenant, alongside other Teams channels meaning that “multiple organisations can share a single channel” that all members can then access from their own Teams environments. Channel sharing seems is great for scenarios where multiple organisations are collaborating on a specific project for example. Guest Access isn’t going anywhere and is still relevant as this is more suited to situations where an external organisation or person needs broad access to data, meetings, and information, beyond just a specific channel. This is currently in “private preview”.

3. Teams Calling Updates

  1. Direct Routing and Survivable Brach Appliances: With the explosion of customers enabling and migrating to PSTN calling in Teams from traditional IP PBXs, the use of Direct Routing grown 8-fold, Microsoft announced several new certified Session Border Controllers (SBC) for Direct Routing, with 6 new SBCs completing certification in just the past 3 months. Additionally, to add resiliency to the most critical locations, Survivable Branch Appliance (SBAs) are now generally available, enabling PSTN calling in the event an outage does not allow the Teams client to directly connect to Microsoft 365 global services.

  2. Operator Connect Conferencing brings an “operator-managed service” that provides “bring your own operator” for conferencing, meaning customers can keep their preferred operator contracts in place as they migrate their PSTN infrastructure to the cloud. This also allows additional geographic dial-in coverage, enhanced support, and reliability with locally agreed technical support and SLAs. This enters private preview from June, with the initial wave of qualified partners, including BT, Deutsche Telekom, Intrado, NTT, Orange Business Services, and Telenor.

  3. New Cloud Calling Plan Countries were also announced, with Microsoft native calling plans coming to 8 new markets from April 2021 including New Zealand, Singapore, Romania, Czech Republic, Hungary, Finland, Norway, and Slovakia, bringing native Microsoft Teams Calling Plans to 26 markets across the globe.

    Teams Calling Countries - April 2021

Identity, Security & Compliance

1. Identity

Focusing on helping organisations deliver on their Zero Trust strategy including, 

    1. Password-less authentication which is now “generally available” for cloud and hybrid environments meaning customers can move towards a truly password-less world leveraging multi-factor authentication and risk based conditional access to provide just in time, assume breach, challenge everything approach to identify and access management without the need for passwords.

    2. Azure AD Conditional Access now uses authentication context to enforce more granular policies based on user actions across the applications they are using or the sensitivity of data they’re trying to access.

    3. Azure AD verifiable credentials will be in public preview later this month. Verifiable credentials allow organisations to confirm information without collecting or storing personal data, improving security and privacy.

2. Security announcements

A wealth of announcements here as well, all of which will further strengthen, Microsoft’s commitment to deliver the absolute best security protection, detection, and response for all clouds and all platforms:

    1. Azure Sentinel now seamlessly integrates with Microsoft 365 Defender with shared incidents, schema, and user experiences to simplify investigations for a totally aligned view and remediation surface.
    2. Endpoint and Office 365 defender capabilities are now also integrated into the Microsoft 365 Defender portal.

    3. New Threat Analytics experience within the Microsoft 365 Defender portal provides a set of reports from expert Microsoft security researchers designed to help customers understand, prevent, and mitigate active threats, like the recent Solorigate / SolarWinds attacks.

    4. The Secure-core services that are now build into Surface devices (and other leading Windows 10 devices) is also coming to Windows Server and Azure edge devices to help minimise risk from firmware vulnerabilities, attacks, and advanced malware in IoT and hybrid cloud environments.

3. Compliance announcements

    1. Co-authoring of Microsoft Information Protection-protected documents will be available in “public preview” from this week. This in my experience the number one blocker of being able to properly deploy organisational wide information protect across SharePoint sites, Teams, and individual documents since currently (well, prior to this announcement) it was not possible to co-author docs that were encrypted which makes most of the power of Modern Office 365 and co-authoring useless. This feature helps significantly close the gap between security and productivity.

    2. Microsoft Azure Purview was announced in more detail. Purview provides new cross-platform support and deeper insight into data classification and protection across structured and un-structured data across on-premises, data bases, Microsoft Cloud and third-party services including Google and AWS – it’s Azure Information Protection on steroids!

    3. Microsoft 365 data loss prevention (DLP) now supports Google Chrome browsers and on-premises file shares and SharePoint Server as well as SharePoint Online and of course Microsoft’s Edge (Chromium based) browser.

    4. Microsoft 365 Insider Risk Management Analytics was released into public preview.

Power Platform

1. Power Automate Desktop was made free!

This is really really big news for any organisation that is looking, using, or intending to use Robotic Process Automation (RPA).  Power Automate Desktop is a an “attended Robotic Process Automation” solution which is a macro recorder on steroids. You can download it now if you want to try it. It will be available first for #WindowsInsiders to try (built into Windows 10), however it will eventually be rolled out to Windows 10 as a core product (most likely as an optional feature). Until now, a per user for month for the tool would cost about £12 a month. Power Automate currently has circa 400 actions to help build flows across different applications and the best part is that it enables you to build your own scripts to automate time consuming repetitive tasks which saves time and money. Microsoft’s goal here is to “democratise the development for everybody with Power Platform” by making no-code/low-code accessible to everyone not just developers.

2. PowerFX (a new low code programming language) was announced.

PowerFx is a low code programming language that is based on the foundation of the Microsoft Power Apps canvas. What’s great is that since Power Fx is based on Microsoft Excel, it will naturally be a great fit for a wide range of people since it will leverage skills, they “many” already know and becomes a common ground for business users and professional developers alike to express logic and solve problems. Microsoft also said they were planning make Power Fx, open source, making the language available for open contribution by the broader community on GitHub.

3. Dynamics 365 now seamlessly integrates with Microsoft Teams

This ensures conversations, calls, meetings, and chat will be available across dynamics 365 – within opportunities, sales, marketing, finance, and operations.

Windows 10

Windows 10 usually gets a backseat at Microsoft Ignite (as it typically focusses on cloud services and new things), but this year, there were some things which resonated.

1. Power Automate Desktop

As discussed above, Power Automate Desktop was announced and will be free for all Windows 10 users including Windows 10 Home and Pro and not just to Enterprise users. You can read more about this above.

2. Windows 10 in Cloud 

Simply put, cloud configuration is a Microsoft-recommended device configuration for Windows 10, cloud-optimised for users with specific workflow needs. IT admins use Microsoft Endpoint Manager to apply a standard, cloud-based, easy-to-manage configuration of Windows 10 to a selected set of new or existing devices. The configuration works on devices running Windows 10 Pro or Windows 10 Enterprise and may be appropriate for workers who only need a limited number of IT-curated and approved applications to meet their targeted workflow needs. User accounts are registered in Azure Active Directory and devices are enrolled for cloud management in Intune, so they are automatically updated with continuous product and security updates.

Microsoft announced that the newly announced Windows 10 in Cloud has now been integrated into Microsoft Endpoint Manager, which will make it even easier to provide a secure device configuration regardless of the type of worker. Microsoft also made a full “Windows 10 in cloud configuration overview and setup guide” available which is designed to help solution integrators, partners, and internal IT teams to apply a uniform, secure and easy-to-manage cloud-based configuration of Windows 10 Professional or Enterprise devices.

3. New version of Windows 10 Perhaps?

Well maybe! During a Fireside chat session at Ignite, Surface and Windows Lead, Panos Panay “teased” of some major updates and design changes coming to Windows. Windows 10 Insider LogoThese were very much hints and teases than any firm commitments but talked a lot about the fact that Microsoft has not “talked about the next generation of Windows for a while” and that he was “so pumped” for it – ending with “it’s going to be a massive year for Windows.”


Written: 05 March 2021

Microsoft announces “Cloud for Healthcare” at #MSBuild2020

As Microsofts’ annual dev conference Build opened today (May 19 2020), Microsoft announced the launch of the Microsoft Cloud For Healthcare, — a new Microsoft Industry Cloud solution.

Microsoft said that the solution aims to integrate Microsoft Cloud with an “industry-specific data model” “cross-cloud connectors,” and APIs to better help serve the global healthcare industry.

Global capabilities uniting the healthcare industry

The Microsoft Cloud for Healthcare wi bring together capabilities from across many Microsoft Cloud Services 365. This includes Microsoft 365, Dynamics 365, Power Platform, and if course Azure. This will be powered by a common data model which will allow the sharing of data across various applications to provide better analytics. Microsoft say that this will allow health providers globally to provide better services for patients, clinicians and doctors by helping make it easier to deploy resources to the needs of all hospital and care units.

For example, Cloud for Healthcare, will focus on what Microsoft has identified as important needs for the field, like engaging patients, facilitating health team collaboration and improving operational efficiency, all with strict security measures.

Sample Health App powered services


Of course, an important component of healthcare is aftercare, where medical professionals need to keep in touch with their patients to follow up on their recovery and any post opp treatment, tools available to do so are generally limited to follow-up phone calls and emails, which are not only tedious but can sometimes not meet security standards or provide the best care.

Microsoft’s Healthcare Bot Service will be available as part of this service, which Microsoft say is behind more than 1,500 instances of COVID-19-based bots that have gone live globally since March 2020. These bots can help alleviate the strain on emergency hotlines for public and provide health providers while addressing common questions that patients might have.

Availability

Microsoft has said that a public preview will be coming in coming days and will be free for 6 months for evaluation, with general availability bringing late this calendar year.

Microsoft has also said that although the healthcare industry will be “first served” with the solution, they also promised that more industry-specific clouds solutions will follow.

Thoughts..

What do you think.. Is industry specific Cloud solutions a good next step for Microsoft?