Quantcast
Channel: TechNet Blogs
Viewing all 36188 articles
Browse latest View live

Office365 Groups Going Private By Default

$
0
0

365Groups.jpg

For some readers, this will be an obscure 'technical post' on something that they never have to worry about in the course of their work. For those who read this and have Office365 administrative responsibilities then they may well exclaim "at last!" and rejoice over their morning coffee!

The ability to set Office365 groups created in Outlook as "private" by default was the third highest user request on UserVoice and the team have responded:

Based on your feedback, we are updating the default privacy setting for groups created across all five Outlook endpoints (web, PC, iOS, Android, and Mac) to be private by default where only approved members can see what’s inside the group. For customers that want to continue with the existing behavior of public by default (where anyone in your organization can see what’s inside) we are providing an Exchange Online PowerShell cmdlet to define the default value. This update will gradually rollout to all Outlook endpoints in the coming months starting with Outlook on the web.

There is a more detailed breakdown of this change from Tony Redmond that I encourage you to read:

Click here to read Tony's thoughts on O365 Groups going private

Tony rightly points out that sometimes it is Education customers that drive the need for change:

Microsoft is doing well with Groups and Teams in the education market, especially in the U.S., and it is unsurprising to see them respond to these customers by making groups private by default.

Having worked in schools and now supporting them with their O365 setups, I've heard of more than one story where teachers have created a group to share "teacher only" content, only to learn it was public and students were able to see it. This default setting change is going to go some way towards preventing this from happening and bring O365 Groups more in line with MS Teams default settings which are private (with Team members needing to be explicitly invited to see content).

This link is a good resource from Microsoft giving the current status of private vs public for the various O365 services and will be updated regularly. Right now, it looks like the following:

O365 Groups

The above will change regularly. Click here for latest details

For those that don't like change, there is of course the option to stick with the status quo and use PowerShell to keep groups public at an organisational / Tenant level:

How to change the default setting of Office 365 Groups for Outlook to Public or Private

If your organization wants Office 365 Groups for Outlook to be created as Public by default (or Private), use this PowerShell cmdlet syntax:

Set-OrganizationConfig -DefaultGroupAccessType Public

To set to Private:

Set-OrganizationConfig -DefaultGroupAccessType Private

To verify the setting:

Get-OrganizationConfig | ft DefaultGroupAccessType


Office 365 Weekly Digest | April 22 – 28, 2018

$
0
0

Welcome to the April 22 - 28, 2018 edition of the Office 365 Weekly Digest.

Only a few additions to the Office 365 Roadmap from last week, including public anonymous external video sharing coming to Microsoft Stream in Q4 CY2018, as well as naming conventions in Office 365 targeted for release in May 2018. There was also one cancellation – In product messaging in the Service Health dashboard.

In addition to the ongoing customer online immersion experience events, there are a couple of new events including a free educator-focused webinar for Microsoft Teams and a webcast on safeguarding individual privacy rights with the Microsoft Cloud..

Lots of content in the Blog Roundup including posts on new and upcoming capabilities in Microsoft 365, improvements to the Planner tab in Microsoft Teams, an increase in SharePoint Online storage, updates to the Office Customization Tool for Click-to-Run, new sharing and collaboration features for OneDrive on Mac, iOS and Android. In addition, MyAnalytics has added new features and resources and Microsoft Forms is now enterprise ready.

Wrapping up the post are noteworthy items on recent updates to Office for Windows, Mac and iOS, a white paper on Office 365 Encryption options, an increase of the public folder limit in Exchange Online to 500,000 folders and a new date for discontinuation of support for Session Boder Controllers in Exchange Online Unified Messaging.

 

OFFICE 365 ROADMAP

 

Below are the items added to the Office 365 Roadmap last week:

 

Feature ID

Title Description

Status

Added

Estimated Release

More Info

27728

Microsoft Stream: Public anonymous external video sharing Allow individual videos in Microsoft Stream to be marked for external public access allowing the video to be embeded in a public website. Anyone in the world can view these external videos without a login. Stream admins will be able to control if this feature is enabled and who within the organization can make videos publicly available.

In development

04/26/2018

Q4 CY2018

n / a

27740

SharePoint web part: Weather Site owners and members will now be able to show the current weather on their site home page, within subpages and/or within a news article on team sites, communication sites and hub sites. Simply add the web part to your page or news, add a location and select from Fahrenheit or Celsius (°F or °C). The web part pulls up-to-date information from MSN Weather.

In development

04/26/2018

May CY2018

n / a

27769

Naming conventions in Office 365 Admins will have the ability to set up rules around how an Office 365 group is named and will be able to block certain types of words from being included in a group name.

In development

04/27/2018

May CY2018

n / a

15064

Service Health Dashboard Update: in product messaging We're adding enhancements to the Service Health Dashboard in the Office 365 admin center:  In product messaging —The new Service health dashboard will enable you to make your end users aware of service incidents and inform them about possible workaround solutions through optional in product notifications.

Cancelled

06/13/2017

Q4 CY2018

Announcing a new Service Health dashboard

 

 

UPCOMING EVENTS

 

Microsoft Learning Consultants: 6 Steps for building a collaborative classroom with Microsoft Teams

When: Tuesday, May 1, 2018 at 5pm ET | This free webinar is hosted by educators and tailored for educators. In this webinar learn how Office 365 tools like Teams can help you facilitate content creation, collaborative classrooms, and personalized learning in a digital hub experience. Be sure to check out our additional free spring webinars in May and June.

 

Productivity Hacks to Save Time & Simplify Workflows

When: Wednesday, May 2, 2018 and Wednesday, May 9, 2018 at 1pm ET | This 90-minute hands-on experience will give you the opportunity to test drive Windows 10, Office 365 and Dynamics 365. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Discover how you can keep your information more secure without inhibiting your workflow, (2) Learn how to visualize and analyze complex data, quickly zeroing in on the insights you need, (3) See how multiple team members can access, edit and review documents simultaneously, and (4) Gain skills that will save you time and simplify your workflow immediately. Each session is limited to 12 participants, reserve your seat now.

 

Transforming your business to meet the changing market and needs of your customers

When: Thursday, May 3, 2018 at 12pm and 3pm ET | This 2-hour hands-on experience will give you the opportunity to test drive Windows 10, Office 365 and Dynamics 365. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Use digital intelligence to build personalized experiences across all customer touchpoints, (2) Improve customer service through a single, unified experience that delivers end-to-end service across every channel, (3) Increase customer satisfaction with intelligent scheduling, native mobile support, and remote asset monitoring to help you get the job done right the first time, and (4) Run your project-based business more productively by bringing people, processes, and automation technology together through a unified experience. Each session is limited to 12 participants, reserve your seat now.

 

Visualizing, Analyzing & Sharing Your Data Without Having to be a BI Expert

When: Tuesday, May 8, 2018 and Tuesday, May 29, 2018 at 12pm ET | This 2-hour hands-on experience will give you the opportunity to test drive the latest business analytics tools. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they can work throughout your organization. During this interactive session, you will explore how to: (1) Locate and organize large amounts of data from multiple sources, (2) Visualize complex data and identify trends quickly without having to be a BI expert, (3) Find and collaborate with company experts on the fly, even if they work in another part of the country, and (4) Gather colleague's opinions easily and eliminate communication and process bottlenecks. Each session is limited to 12 participants, reserve your seat now.

 

Hands-on with security in a cloud-first, mobile-first world

When: Thursday, May 10, 2018 at 12pm and 3pm ET | This 2-hour hands-on session will give you the opportunity to try Microsoft technology that secures your digital transformation with a comprehensive platform, unique intelligence, and partnerships. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Detect and protect against external threats by monitoring, reporting and analyzing activity to react promptly to provide organization security, (2) Protect your information and reduce the risk of data loss, (3) Provide peace of mind with controls and visibility for industry-verified conformity with global standards in compliance, (4) Protect your users and their accounts, and (5) Support your organization with enhanced privacy and compliance to meet the General Data Protection Regulation. Each session is limited to 12 participants, reserve your seat now.

 

Connecting, Organizing & Collaborating with Your Team

When: Tuesday, May 15, 2018 and Tuesday, May 22, 2018 at 12pm ET | During this session, you will have the opportunity to experience Windows 10, Office 365 and Microsoft's newest collaboration tool: Microsoft Teams. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will explore how to use Microsoft Teams and Office 365 to: (1) Create a hub for team work that works together with your other Office 365 apps, (2) Build customized options for each team, (3) Keep everyone on your team engaged, (4) Coauthor and share content quickly, and (5) Gain skills that will save you time and simplify your workflow immediately. Each session is limited to 12 participants, reserve your seat now.

 

Safeguarding individual privacy rights with the Microsoft Cloud

When: Friday, May 25, 2018 from 3:00pm – 5:00pm ET | Join Alym Rayani, Director of Microsoft 365, for our May 25 webcast where he will: (1) Show how you can use GDPR fundamentals to assess and manage your compliance risk, (2) Discuss how you can help protect your customers' data with built-in, intelligent security capabilities, and (3) Cover how you can meet your own compliance obligations by streamlining your processes.

 

BLOG ROUNDUP

 

Making IT simpler with a modern workplace

There is a simple way to explain one of the biggest threats to any organization's infrastructure. It's just one word: complexity. Complexity is the absolute enemy of security and productivity. The simpler you can make your productivity and security solutions, the easier it will be for IT to manage and secure—making the user experience that much more elegant and useful. We've learned from building and running over 200 global cloud services that a truly modern and truly secure service is a simple one. Microsoft 365 is built to help you solve this problem of complexity so that you can simplify. But let me be clear, simpler doesn't mean less robust or less capable. From thousands of conversations with customers, we heard clearly how important it is for IT to simplify the way it enables users across PCs, mobile devices, cloud services, and on-premises apps. Microsoft 365 provides that all with an integrated solution that's simpler, yet also more powerful and intelligent. Because the way you work and do business is so important to us, our work will never be done—we will constantly innovate, improve, and discover new and better ways to help your organization do more. We are excited to announce some new capabilities and updates coming soon to Microsoft 365, including: (1) A modern desktop, (2) Solutions for Firstline Workers, (3) Streamlined device management with lower costs, (4) Integrated administration experience, and (5) Built-in compliance. Each of these new capabilities will allow you to simplify your modern workplace, which means delighting and empowering your users, while enabling IT to protect and secure the corporate assets.

 

Planner tab in Microsoft Teams now includes the Schedule view and Charts view

When we released the first version of the Planner tab in Teams, we noted that our goal was to support the same feature set in Teams as we do in the Planner web app. We recently took another step towards our goal and have completed the roll out of a few more popular features from the web: (1) Schedule view - get an overview of upcoming tasks and drag and drop them to set dates, (2) Charts view - stay up to date on the status of your plans, and (3) Filter and Group by options - focus on key tasks and group by Assigned To, Progress, Due Date, and Labels. For more information about using Planner in Teams, check out this article.

 

Increase in SharePoint Online storage allocation

Global digital transformation is driving growth across Microsoft 365 and SharePoint as organizations invest in technology to empower employees to do their best work. More than 350,000 organizations now have SharePoint and the data they are storing over doubled last year alone. We're hearing customers want to put even more content into SharePoint to take advantage of new team collaboration and enterprise content management experiences, while moving off on-premise servers, file shares, and 3rd party cloud offerings. We are announcing a 20x increase in the SharePoint Online per user license storage allocation. This will increase to 1 TB plus 10 GB per user license purchased, up from 1 TB plus .5 GB per user license purchased. Note this does not include SharePoint Online kiosk plans including Office 365 F1 and Microsoft 365 F1. All Office 365 services that use SharePoint for content services, including Microsoft Teams and Office 365 Groups, will benefit from this substantial storage increase. This change will start rolling out on July 1, 2018 and will be completed by the end of August 2018. Once complete, you'll see this increased storage in your SharePoint Online admin center. If you are currently paying for additional storage you can decrease this as needed after this change is reflected in your tenant. | Resource: SharePoint and OneDrive Security and Compliance Resource Center

 

Setting preferences for Office 365 ProPlus using the Office Customization Tool for Click-to-Run

We are announcing a preview update to the Office Customization Tool for Click-to-Run, which provides desktop admins with a simple user interface to customize their deployment of Office. With this update, you can now customize Office application settings as part of your configuration file, which means you can build a single configuration file that installs Office and configures preferences for Office applications. You can search for Office application settings based on Office application, category, and title to quickly find the settings you're interested in. For this preview release, we've provided a limited set of Office application settings to choose from. We plan to include the full set of application settings later this summer. In addition to application settings, we have been listening to your feedback and since we introduced the Office Customization Tool for Click-to-Run we have made a few changes to the preview experience; adding Organization Name as a setting that is included as part of the deployment configuration, an update to the language selection experience, and an update to the Automatically accept the EULA option. In our next update we plan to add many additional enhancements including: an update to the product selection experience to allow you to have more control over the products you can select from and the apps that you exclude, an update to the language selection experience including support for MatchOS, AllowCdnFallback, Proofing Tools and more. As always, make sure you download the latest version of the Office Deployment Tool (ODT) to enable this new feature during deployment.

 

OneDrive Brings New Sharing and Collaboration Features to Mac, iOS and Android

Over the past year, we have worked hard to bring new sharing features to OneDrive and SharePoint, including real-time collaboration for Office for Mac as well as to iOS and Android. We have several announcements that reinforce our commitment to deliver a first-class experience to our Mac, iOS and Android users. We consistently hear that users are more confident and comfortable sharing files when given a simple, consistent experience across their devices. Over the past year, we've focused on delivering that with a unified sharing experience to Office, OneDrive, and SharePoint across desktop and web. Now, we take our next step in that journey by bringing the same, successful sharing experience that you currently see in our other clients to our OneDrive app for iOS and Android. This feature is available now for Android users and is currently rolling out for iOS users so, make sure to keep your OneDrive app updated to the latest version when prompted. There are also new updates for Mac Office users. The OneDrive client for Mac will now be part of the Office 2016 for Mac Click-to-Run installer. This means that the OneDrive standalone client will be automatically installed as part of your Office installations rather than having to install it separately. For customers currently running the Mac App Store version, OneDrive will now automatically migrate your settings to the standalone version. Finally, this update will also bring requested functionality to the Mac OneDrive client: Office for Mac will work with OneDrive to intelligently open your files locally if it has already synced the file rather than download a new copy, so your files will open much more quickly. We will announce more features and functionality coming to our customers in May at the SharePoint Conference North America.

 

New in MyAnalytics: manager 1:1 insights, adoption resources, and shortened onboarding time

As the demands on our time at work grow, MyAnalytics helps people get back in control and build better work habits. This month, we're excited to announce the following updates and releases: (1) Manager 1:1 insights, (2) New user adoption resources, and (3) Shortened onboarding time. Manager 1:1 insights will surface in the MyAnalytics personal dashboard when you've gone 3 or more weeks since your last 1:1 with your manager, with a friendly tip to book a 30-minute check-in. If you're a manager, you'll also see a similar insight if you've gone 3+ weeks without booking a 1:1 with one of your direct reports. Managerial relationships are determined using Azure Active Directory. Our new adoption resources will help map out a path in advance and include resources for individuals and teams. The MyAnalytics onboarding process is now faster than ever. Within 3 days of being assigned a MyAnalytics license by their Office 365 Administrator, users will receive a "Welcome to MyAnalytics" email and have access to their personal dashboard and Outlook add-in. The personal dashboard will populate 80 days retroactively, assuming the user has been active on Exchange Online for that duration. Users will receive a weekly email digest starting on the first Monday after the Welcome email sends.

 

Microsoft Forms is Enterprise Ready now!

We are excited to announce that Microsoft Forms, a simple app for creating surveys, quizzes, and polls, is generally available to all Office 365 commercial customers. Used by more than 3 million users in education, Forms was brought to commercial preview by customer demand last year. Thanks to more than 50,000 companies participating in the Preview program, Microsoft Forms is now enterprise ready, and, hence, we are removing the "Preview" label. With Microsoft Forms, your employees can easily solicit client input, measure customer satisfaction, and organize team events, within minutes. The app is simple to use and works on any web browser, so it can be accessed from anywhere, anytime. With real time responses and automatic charts built in, Microsoft Forms makes it easy to understand the data right away. And for companies that want to custom brand their surveys, Forms supports the addition of themes, logo, and images. We also know that many users work in teams, so users can collaborate on a single form. Forms can be used within applications you know and love, such as Excel, SharePoint, Teams, Flow, and Sway. Most recently, Microsoft Forms added many features that enterprises requested, such as SOC compliance, ability for IT admins to manage user licenses, and controls to enable sharing of Forms outside of their organization. For more complex surveys, we also added support question branching and Likert scales, plus an ability to collect 50,000 survey responses per form.

 

NOTEWORTHY

 

Office 365 for Windows Desktop – April 2018 Release details

On April 25th, 2018, Microsoft released Office for Windows Desktop version 1804 (Build 9226.xxxx). Our Office International team translated this update into 44 languages. Here are a few of the new features that are included in this release: (1) In PowerPoint convert your ink to text or shapes, (2) Listen to your emails in Outlook, (3) Encrypt option in Outlook using Office 365 Message Encryption, (4) Task board filtering in Project, and (5) Find and fix proofing issues in your language in Word. More information and help content on this release can be found in the What's New in Office 365 page.

 

Office for MAC 2016 - April 2018 Release details

On April 11th, 2018, Microsoft released Office 2016 for Mac Version 16.12 (Build 180410) in 27 languages. Our Office International team was responsible for translating this release. There are several new features in Outlook including a more actionable calendar and the ability for delegates to schedule Skype for Business Online meetings on behalf of principals using principals' email addresses. Also, in most client applications including Excel, Outlook, PowerPoint and Word you can now insert and edit Scalable Vector Graphics. In addition, locally synced OneDrive documents open directly from the cloud, allowing users to AutoSave, share, and collaborate easily. More information and help content on this release can be found in the MAC section of the What's New in Office 365 page.

 

Office 365 for iPad & iPhone - April 2018 release details

On April 9th, 2018, Microsoft released an updated version of Office for iPad & iPhone to Office 365 subscribers - Version 2.12 (18040200) in 35 languages. Our Office International team translated this release. Here are some of the new features included this month in Excel, PowerPoint and Word: (1) Rotate, resize, and add color to SVG images in your documents, worksheets, and presentations to better convey your ideas, (2) Perform common calculations in Excel on a selected range of data using functions, and (3) In Excel, have quick access to contextual commands like expand selection, sort, filter, and more! More information and help content on this release can be found in the iOS section of the What's New in Office 365 page.

 

Using encryption in Office 365 to help protect data and meet your compliance needs

With digital data growing exponentially, and threats becoming more advanced, laws and regulations are evolving to protect individuals and their personal information. Encryption is one method that can be used to help ensure the confidentiality of certain sensitive information, reduce the risk of data compromise and help you meet your compliance needs. When organizations use Office 365, they can expect customer data to be encrypted both in transit and at rest by default. Additional encryption capabilities can be added for increased protection. Encryption technologies available in Office 365 to help protect your data include: (1) TLS, (2) BitLocker, (3) Service Encryption, and (4) Office 365 Message Encryption. For customers who have data security or privacy requirements that are driven by compliance, Office 365 offers flexible encryption key management options to further help organizations meet their compliance needs as they move to the cloud. You can read more about these options in our white paper.

 

Announcing the increase of the Public Folder limit in Exchange Online from 250,000 to 500,000 folders

In September 2017, we officially announced the increase of the supported limit of Public Folders in Exchange Online from 100,000 to 250,000. In line with our efforts to scale Public Folders even further, we are glad to announce that Exchange Online now officially supports public folder hierarchies of up to 500K public folders in the cloud – double the previously supported limit of 250K public folders! All existing customers using Exchange Online who are currently constrained by the limit of 250K public folders, can now expand their Exchange Online public folder hierarchy up to 500K folders. Note about migrations: Exchange 2013/2016 customers can still only migrate up to 100K public folders to Exchange Online, and Exchange 2010 customers can only migrate up to 250K public folders to Exchange Online. However, once folders are migrated to Exchange Online, you can expand the hierarchy up to 500K public folders. We are working to resolve these limitations in the future.

 

New date for discontinuation of support for Session Border Controllers in Exchange Online Unified Messaging

In July 2017, we announced that support for Session Border Controllers (SBC) that connect 3rd Party PBX systems to Exchange Online Unified Messaging (UM) would be discontinued as of July 2018. After feedback from customers and partners concerned about this change, we are announcing additional time for customers to prepare. The new date for discontinuation will be April 30, 2019. Customers with existing deployments remain fully supported until this date. However, Microsoft strongly advises all customers to begin their voicemail transition now. There are different alternatives (outlined in this post) for customers currently using an on-premises PBX system that connects to Exchange Online. We recognize that customers may also choose a combination of these options for their organization. We know these changes can be challenging in the near-term. But we believe that continuing to identify areas where we can evolve the service we provide while taking full advantage of the cloud is the right answer. We will continue to evaluate emerging needs as customers make the transition from legacy dedicated voice to Microsoft's Intelligent Communications solutions. | Microsoft Tech Community Announcement


Fill Factor and Data Compression

$
0
0

Another post by our excellent US PFE Susan Van Eyck goes though Fill Factor and Data Compression!

 

I got a pair of interesting questions from a colleague this week:

  1. If you’re using fill factor then enable data compression, is the fill factor still enforced?
  2. If you aren’t using fill factor and enable data compression does it create free space on the original pages?

The answer to #2 is “No” because to enable compression (row or page) you rebuild an index, and that involves writing the data out to a new set of data (or index) pages then dropping the original index.  Note the page numbers in the illustration below (bonus points if you can explain the funky numbering in the original index).  Since this index was rebuilt without a fill factor, each page was filled to capacity.  Only the last page might have room for more data (represented here by the lighter colors):

image

 

As for question #1, I did a bit of research and found a helpful blog post from Sunil Agarwal (one of the SQL Server Program Managers) confirming that the 2 features are compatible.  I wrote a demo script based on Sunil’s, and thought it would be interesting to share with you – along with a few notes about data compression.

To start, we’ll create a table in tempdb then fill it with a lot of repetitive data:

USE tempdb;

CREATE TABLE dbo.BogusData (

BogusDataId INT IDENTITY,

WideColumn CHAR(100) DEFAULT REPLICATE( 'A', 50 )

);

INSERT INTO dbo.BogusData ( WideColumn ) DEFAULT VALUES;

GO 10000

That CHAR(100) column is a good target for Row Compression since we’re using only half the reserved space with strings 50 characters in length.  You can think of Row Compression as smooshing out leftover space from columns.  Here are some examples of where it will be useful:

image

 

 

And all that repetitive data is a good target for Page Compression which stores 1 copy of a repeated column values in the page header then substitutes a smaller placeholder in the body of the page (dictionary compression).  My index is bit wonky, and the compression process is a bit more involved, but you get the idea – a lot more wombats per page read.

image

 

The impact of data compression will depend greatly on both your data types and your data.  For instance, a CHAR(10) column that always contains 10 characters won’t benefit from row-compression.  Neither will a VARCHAR(n) column doesn’t have extra space to eliminate.  A unique index on a column like SocialSecurityNumber won’t benefit from either row or page compression (assuming you’ve chosen the data type and width wisely).  And repetitive data can only page-compressed if the repeated values occur on the same data page.  Imagine an index on EmployeeId that includes LastName.  If there are 2000 Smiths are scattered across 10,000 data pages, dictionary compression won’t be of much use.  Onto our demonstration!

In the demos below we’ll start by adding a clustered index to our table, then we’ll look at the impact of adding a fill factor, row compression and finally page compression (which includes row compression).  We’ll check the index’s size and space usage after each step (although the query to get those values is only printed once).  Let’s see what happens to those values across our 4 test cases.

  1. Add a Clustered Index

CREATE CLUSTERED INDEX ci_BogusDataId ON dbo.BogusData ( BogusDataId );

SELECT page_count, avg_page_space_used_in_percent

FROM sys.dm_db_index_physical_stats( DB_ID(), OBJECT_ID( 'dbo.BogusData' ), NULL, NULL, 'DETAILED' )

WHERE index_level = 0;

image

 

Note that our data pages are packed full.  This helps keep the cost of I/O down since we get more data rows per page read.

[Note:  We’re using DETAILED mode in the query to return the avg_page_space_used_in_percent value, but this requires that all the index’s data pages be read.  Be very cautious using this mode in a production  environment.]

  1. Add a Fill Factor

ALTER INDEX ci_BogusDataId ON dbo.BogusData REBUILD WITH ( FILLFACTOR = 80 );

image

 

We’ve now got about 20% free space on each data page – good for delaying page splits, but we’ve also made the index 20% larger which will negatively impact queries involving index scans as there are now fewer row per page.  Keep this trade-off in mind when implementing fill factors.

  1. Add Row Compression (the specified fill factor will persist through the rebuild)

ALTER INDEX ci_BogusDataId ON dbo.BogusData REBUILD WITH ( DATA_COMPRESSION = ROW );

image

 

This is a move in the right direction!  We’ve still got free space for new data, and “smooshing” out the empty spaces has dropped the index size by more than 40%.  We might have expected a 50% drop since we’re only using half of the column’s 100 character width, but some page space is now is being used to store information about the uncompressed state of the column.

  1. Add Page Compression (includes Row Compression which will be applied first)

ALTER INDEX ci_BogusDataId ON dbo.BogusData REBUILD WITH ( DATA_COMPRESSION = PAGE );

image

 

Once again, the fill factor persists, and due to the very bogus, super-repetitive nature of our data the index is down to a mere 18 pages!  Note that you’re unlikely to see such amazing gains with real-world data.

Remember to drop the demo table when you’re done:

DROP TABLE dbo.BogusData;

If you’re thinking about using either fill factor or data compression, here’s some additional reading that covers some of the factors you’ll want to take into consideration:

Specify Fill Factor for an Index

Data Compression

And lastly,  I’ve attached a script that has the full set of demo scripts to save you a little copy/paste effort!

20180404_FillFactorAndDataCompression

 

Happy Exploring!

 

 

Windows Server 2019 – Storage Migration Service

$
0
0

Windows Server 2019 Preview Builds

Back in late March Microsoft announced the first preview build of Windows Server 2019.  In this announcement were many new and improved features. Just a few listed below.

Extending your Clusters with Cluster Sets

Windows Defender Advanced Threat Protection 

Windows Defender ATP Exploit Guard

Failover Cluster removing use of NTLM authentication

Shielded virtual machines: Offline mode, Alternate HGS, VMConnect and Shielded Linux support

Encrypted Network in SDN

Performance history for Storage Spaces Direct

All of the above will be covered in future posts, but the one new feature missing from the announcement was the all new Storage Migration Service.

Storage Migration Service

In the middle of April, Ned Pyle the head honcho for Storage Replica announced this brand new feature. So, what is it? Who is it aimed at? What does it do?

What is it?

The Storage Migration Service will assist you to migrate data on legacy servers without ANY application or user configuration changes. You can migrate to a modern (Windows Server 2019 Preview) Server from and Windows Server all the way back to 2003. (The pan is to support migrating to and Windows Server but not yet).

The service provides fast, consistent, scalable migration managing the complexity and providing a graphical workflow. The data migrated can be unstructured and can be migrated either to Azure or on-premises Windows Server targets.

Who is it aimed at?

This service will be available in both Standard and Datacenter editions of Windows Server 2019 so it is aimed at any size of business that wants to migrate data off legacy devices without having to worry about infrastructure or network changes.

What does it do?

Quite simply it allows a new server to take the place of an old server without the manual tasks normally required, as listed below.

Transfer all data, shares, configurations and security for file system and shares. Transfer all files that are currently in use as well as those files your operator privileges do not allow you access to. Transfer all local users and groups and files that have changed since you last transferred them. Network addresses, computer naming and network resolution such as DNS must be transferred. Finally all data security and other attributes must transfer.

A pretty long list of tedious configuration just to move some files.

So the Storage Migration Service (I am not going to shorten it to SMS, for obvious reasons) is a three stage process. Take a look at the graphic from Ned's initial blog post.

The service has an orchestrator (a Windows Server 2019 Preview server) which manages the whole migration and maintains a database of all results.

Stage 1 - Inventory

Nodes to be migrated are selected and the orchestrator gathers the data required.

Stage 2 - Transfer

Having identified all possible data to move the admin then pairs source devices with target devices and chooses the data. The migration is then performed.

Stage 3 - Cutover (in development)

In this stage the new devices supplant the sources in the network and place the old servers in a maintenance state. In this state users and applications cannot see these devices.

Ned give a useful list of pre requisites to test this great new service, the best thing for me is that is is managed using the Windows Admin Center the first example of a brand new service where the admin center is the primary tool for management.

Also in Ned's blog is a full walkthrough, I can thoroughly recommend giving it a go.

Watch this space for more great enhancements to the service.

Tip of the Day: Say Hello to FIDO Devices

$
0
0

Today's tip...

The FIDO (Fast Identity Online) alliance is a collection of companies including Microsoft, Google, PayPal, and hundreds of others, all working together to solve the shortcomings of passwords. Motivations driving this work include:

  • Weak or stolen passwords account for approximately 76% of all network intrusions.
  • In surveys, 81% of respondents reported using the same password across multiple endpoints.
  • Data surveys show approximately 50% of enterprise help desk calls are for password resets.

The alliance has introduced the FIDO 2.0 open standard to transition users from proving their identity with something they know (passwords) to using something they have such as a physical security key. These physical FIDO 2.0 security keys come in a variety of form factors, whether that be a card, fingerprint protected USB dongle, phone, etc. The device need only implement the FIDO 2.0 standard and the underlying CTAP (Client To Authenticator Protocol) transport protocol to work with the FIDO 2.0 authentication scheme on accommodating platforms such as the Windows client operating system.

Extending the capabilities of Windows Hello

How to find out which image was used for the deployment of an existing Azure VM

$
0
0

You may have deployed a VM in Azure using a marketplace image. Or it was deployed a long time ago. Now you might wonder which exact image was used? Either for documentation purposes – or because you need the details for an automation / PowerShell script or you are just curious if you are using the latest template.

This is how I once found out using PowerShell:

Login-AzureRmAccount
$VM = Get-AzureRmVM -ResourceGroupName
MyRG -VMName TheVMName
$VM.StorageProfile.ImageReference

 

Result could look like e.g.:

Publisher : veeam
Offer     : veeam-backup-replication
Sku       : veeam-backup-replication-95
Version   : latest
Id        :

KI ist überall, Microsoft auch

$
0
0

Logbucheintrag: 190430


Wer hätte das gedacht? Vor gut einem Jahr war künstliche Intelligenz noch ein Randthema, das lediglich große Organisationen mit hohem Automatisierungsbedarf interessierte. Sprachassistenten wurden zwar auf dem Smartphone intensiv genutzt. Aber den wenigsten war dabei bewusst, dass sie einen KI-Service in Anspruch nehmen, wenn sie Cortana nach dem Weg fragen oder über Bing ausgefeilte Suchalgorithmen nutzen. Jetzt steht künstliche Intelligenz ganz oben auf der Liste der Topthemen in den Unternehmen – hinter Cloud Computing, IT-Security- und IT-Service-Management und noch vor Digitalisierung und Big Data.

Das jedenfalls ergab eine Umfrage von IDG Research unter Entscheidern in europäischen Unternehmen. Und dabei gilt: Je größer die Organisation, desto weiter sind die IT-Fachleute mit der Einführung von KI-Lösungen und Machine Learning. 60 Prozent der Befragten, deren IT-Abteilungen mehr als 500 Mitarbeiter beschäftigen, haben künstliche Intelligenz schon im Einsatz – zum Teil sogar in „einer ganzen Reihe“ von Einsatzszenarien. Nicht viel anders sieht es bei Organisationen mit mehr als 100 IT-Mitarbeitern aus: Hier sind es 56 Prozent, die KI heute bereits nutzen. Erst darunter, also dort, wo kleine IT-Abteilungen die Geschäftsprozesse und IT-Ausrüstung managen, sinkt die Zahl signifikant ab: hier ist erst jeder Dritte konkret mit KI befasst.

Damit zielen wir mit der Microsoft Azure-Plattform exakt auf die Topthemen unserer Kunden. Denn von Cloud Computing über (KI-gestützte) Security-Features bis zu KI-Services aus der Cloud und schließlich unseren IoT-Angeboten Azure Central und Azure Sphere bieten wir komplette Lösungen für die digitale Agenda der CIOs. Dabei ist die Azure-Plattform voll skalierbar, so dass sowohl kleine Organisationen als auch globale Konzerne ihre maßgeschneiderten Lösungen vorfinden. Dazu tragen vor allem auch unsere weltweit 64.000 Partner bei, die sich mit eigenen Aktivitäten ein Cloud-basiertes Business aufgebaut haben und jetzt durch KI weiter ausbauen.

Es ist schon faszinierend, wie Satya Nadella Microsoft in kürzester Zeit zur wahrscheinlich relevantesten IT-Company für Unternehmen und Privatpersonen gewandelt hat. Mit der Strategie „Intelligent Cloud und Intelligent Edge“ stehen wir ganz vorne als Technologieführer und Marktführer in wichtigen Wachstumsmärkten. Nach besten Bewertungen an den Aktienmärkten wird auch unser viertes Quartal noch einmal zeigen, dass wir vor dem Wind fahren – sozusagen im Konvoi mit unseren Kunden und Partnern.

Dabei müssen wir damit leben, dass es einen erheblichen Mangel an KI-Experten gibt. Zwar beschäftigt Microsoft derzeit bereits mehr als 3000 Entwickler mit Aufgaben rund um KI-Produkte, aber wir könnten weit mehr Data Scientists, KI-Entwickler und Machine Learning-Experten gebrauchen. Das gleiche gilt für unsere Kunden und Partner. Der Mangel an Fachkräften mit diesen neuen Wissensprofilen und Spezialgebieten verhindert die rasche Einführung und Weiterentwicklung von Künstlicher Intelligenz. Zwar sagen 45 Prozent der von IDG befragten Manager, dass ihre Organisation bereits über die nötige technische Infrastruktur für KI verfügt. Doch nur 24 Prozent bestätigen zugleich, dass ihre Mitarbeiter über das nötige Expertenwissen verfügen.

Hier entsteht ein gigantischer Weiterbildungsbedarf. Denn die KI-Experten sollen nicht im Elfenbein-Turm arbeiten, sondern möglichst über kombinierte Wissensgebiete verfügen. So wollen 44 Prozent der Organisationen mit Hilfe von Machine Learning ihre internen und externen Prozesse optimieren und automatisieren. Dabei sollen vor allem Routinetätigkeiten durch KI übernommen werden. Deshalb sind KI-gestützte Assistenzsysteme und Planungswerkzeuge mit einem Einsatzgrad von jeweils 30 Prozent die wichtigsten Technologien. Dabei erwartet mehr als die Hälfte der Befragten, dass die eingesetzten KI-Systeme die Prozesse nicht nur effektiver machen, sondern disruptiv neu gestalten werden.

Und immerhin jeder vierte befürchtet, dass KI-Systeme auch dazu genutzt werden, smarte und kaum wahrnehmbare Cyber-Angriffe zu starten. Microsoft hat sich auch auf dieses Thema längst eingestellt. Azure bietet eine Vielzahl von KI-gestützten Security- und Monitoring-Funktionen, die die Cloud-Landschaft ebenso wie Hybride Strukturen sicherer und stabiler machen.

Spätestens auf der Microsoft-Entwicklerkonferenz Inspire im kommenden Juli wird es an allen KI-Fronten neue Ankündigungen geben. Denn KI ist überall. Und Microsoft ist überall vorne dabei.

無線 LAN プロファイルをグループ ポリシー利用して配布する手順について

$
0
0

皆様、こんにちは。Windows プラットフォーム サポート担当の永谷です。

 

今回は "無線 LAN プロファイル  (接続するための設定) をグループ ポリシー (以後 : GPOと表記) を利用して

ドメイン クライアントへ配布する手順" を紹介します。

これまで手動で端末ごとに無線 LAN プロファイルを設定頂いていた方も、

これを機に GPO のご利用についても併せてご検討ください。

 

- 対象の環境

・ 無線 LAN 接続に、Windows 標準の無線 LAN サプリカントを利用している

・ ドメイン に参加しており GPO の適用が可能な無線 LAN クライアント

 

- Blog 内で設定する内容

認証方式に EAP-TLS を利用しコンピューターのクライアント証明書を利用して RADIUS 認証を実施する設定を実施。

 

★ 具体的な設定は下記の通りです。

-----------------------------

ポリシー名 : wlan

プロファイル名 : testssid

接続先 SSID : testssid

 

自動接続 : はい

ステルス SSID を利用 : いいえ

認証 : WPA2-エンタープライズ

暗号化 : AES

ネットワークの認証方法 : EAP-TLS

認証モード : コンピューターの認証

-----------------------------

 

上記の設定をご利用いただく場合、事前にクライアントに EAP の要件を満たした

コンピューター証明書をインポートしておく必要がございます。

 

タイトル : PEAP および EAP の証明書の要件

URL : https://technet.microsoft.com/ja-jp/library/cc731363(v=ws.11).aspx

 

===============================

設定方法 (Windows Server 2012 R2 を利用した場合)

===============================

 

ドメイン クライアントに対して無線 LAN プロファイル する場合はグループポリシーを利用した方法を使用し、設定を行う事が可能です。

 

1. ドメイン コントローラーでグループポリシーの管理を起動します

2. グループ ポリシーを適用したい任意の OU 等を右クリックし、[このドメインに GPO を作成し、このコンテナにリンクする] を選択します。

3. 任意の GPO 名を入力し OK をクリックします。

4. 作成された GPO を右クリックし、編集 をクリックします。

5. 以下のパスを展開し、[Windows Vista 以降のリリース用の新しいワイヤレス ネットワーク ポリシーの作成] をクリックします。

 

コンピュータの構成

  ポリシー

      Windows の設定

         セキュリティの設定

             ワイヤレス ネットワーク (IEEE 802.1) ポリシー

 

6. [以下のプロファイルの順序で利用できるネットワークに接続します" 下部の [追加] をクリックします。

7. プロファイル名を入力します。

8. ネットワーク名 (SSID) を入力し、右の [追加] をクリックください。

この時点で以下のように表示されている事をご確認ください。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

9. 続けて [セキュリティ] タブをクリックします。

10. [ネットワークの認証方法の選択] にて "Microsoft : スマート カードまたはその他証明書" を選択します。

11. 続けて [認証モード] より "コンピューター認証" を選択します。

この時点で以下のように表示されている事をご確認ください。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

12. 設定に間違いがなければ [OK] をクリックします。

13. "ネットワークのアクセス許可" タブを開きます。

以下のように構成されていれば特に変更頂く必要はございません。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

14. [OK] ボタンをクリックし、プロパティ画面を閉じます。

15. Windows のドメイン クライアントを再起動するか、

管理者ユーザーで起動したコマンド プロンプトにて gpupdate /force を実行し、グループ ポリシーを適用します。

 

★ 次回は無線 LAN クライアントを特定の SSID にしか繋げさせない場合の設定方法をご案内予定です。

 

特記事項

本情報の内容(添付文書、リンク先などを含む)は、作成日時点でのものであり、予告なく変更される場合があります。

 


Microsoft lleva la traducción impulsada por IA a usuarios finales y desarrolladores sin importar si están conectados o no

$
0
0

Microsoft Translator ha agregado nuevas capacidades que permiten a los usuarios y desarrolladores recibir traducciones impulsadas por inteligencia artificial sin importar si tienen conexión a internet o no.

Las nuevas capacidades permiten tanto a los usuarios finales como a los desarrolladores de aplicaciones de terceros, contar con el beneficio de la tecnología de traducción neural sin importar si el dispositivo está conectado o desconectado de la nube.

Al usar la aplicación de Microsoft Translator, los usuarios finales ahora pueden descargar de manera gratuita los paquetes impulsados por AI para usar sin conexión. Además, a través de la nueva característica local en versión previa de la app Translator, los desarrolladores de Android podrán integrar de manera sencilla y rápida, traducciones de texto con AI integrada, con conexión o sin ella en sus aplicaciones.

Nuevos paquetes de lenguaje sin conexión impulsados por AI para las aplicaciones de Translator para Android, iOS y Amazon Fire

El desarrollo viene después de dos años de trabajo, y complementa los esfuerzos generales de Microsoft para asegurar que los desarrolladores y usuarios puedan tener acceso a las herramientas impulsadas por IA, justo donde están sus datos, sin importar si los manejan desde la nube o en un dispositivo. Esta capacidad, a la cual los expertos se refieren como el cómputo en el entorno, surge mientras los expertos descubren maneras para correr poderosos algoritmos de AI sin el poder masivo del cómputo en la nube.

Microsoft Translator lanzó la traducción en línea de máquina neural impulsada por AI (NMT) en 2016. Debido a que el cómputo en la nube necesitaba correr estos modelos de traducción de alta calidad, esta capacidad sólo estaba disponible en línea. A finales del 2017, esta capacidad se volvió disponible en teléfonos específicos Android equipados con un chip especializado de IA. Esto permitió que sus usuarios pudieran recibir traducciones de calidad sin conexión con la misma calidad que las traducciones neurales con conexión.

Basado en este trabajo inicial, el equipo de Translator pudo optimizar aún más estos algoritmos, y permitirles funcionar directo en el CPU de cualquier dispositivo moderno sin la necesidad de tener chips especializados de IA. Estas nuevas aplicaciones de Translator llevan las NMT al entorno de la nube para todos los dispositivos Android, iOS y Amazon Fire. El soporte para los dispositivos Windows llegará pronto.

Estos nuevos paquetes de NMT producen traducciones de mayor calidad, que son hasta un 23 por ciento mejores, y son un 50 por ciento más pequeñas que los paquetes no neurales anteriores de idiomas sin conexión. Estos paquetes de NMT están disponibles en los idiomas más populares de Translator, y los nuevos lenguajes del NMT serán agregados de manera regular. Para poder tener la lista completa actualizada, por favor revisen https://translator.microsoft.com/help/articles/languages.

Nueva característica local de prueba para Translator en Android

Para los desarrolladores de Android, la aplicación de Translator ahora también ofrece una versión de prueba de la nueva característica local, la cual permite que los desarrolladores agreguen traducción de texto de una manera más rápida y sencilla a cualquier aplicación de Android que se beneficie de las capacidades de traducción.

Además, gracias a estos paquetes de NMT sin conexión, los desarrolladores de Android pueden agregar por primera vez NMT sin conexión a sus aplicaciones, los cuales permiten que sus usuarios puedan tener acceso a contenido traducido por parte del NMT sin la necesidad de una conexión a internet.

Para integrar traducción a sus aplicaciones, los desarrolladores sólo tendrán que agregar un código simple que utilizarán la tecnología de servicio vinculado de Android, a través de una interfaz AIDL para activar la aplicación de Translator de manera silenciosa. La aplicación hará el resto. Si el dispositivo está conectado a internet, la aplicación recuperará el texto traducido desde el servicio de Microsoft Translator en Azure. Si la conectividad a internet no está disponible, la aplicación de Microsoft Translator utilizará los paquetes locales de NMT de idiomas sin conexión, para proveer el texto traducido de regreso a su aplicación.

Se espera que la característica pase de versión previa a disponibilidad general, dentro de los 90 días después del lanzamiento de la versión prueba.

Cuando el dispositivo está conectado, las traducciones también pueden aprovechar los modelos de traducción personalizados que coincidan con la terminología* única de la compañía y de la aplicación.

Sin importar si la aplicación recibe traducciones con conexión o sin ella, la característica local factura la suscripción de Translator Text API* de desarrollador a través de Microsoft Cognitive Services. No hay necesidad de crear una nueva y, si la API de nube es activada de manera directa, los requerimientos no serán registrados para las traducciones con o sin conexión.

Pueden aprender más sobre cómo trabaja la característica local de prueba en nuestra documentación de GitHub y aplicación de prueba.

*Durante la prueba, algunas características pueden no estar disponibles, o pueden estar disponibles sin ningún costo. Por favor consulten las notas sobre el lanzamiento de la documentación para recibir más información.

Is Dynamics 365 in your Future?

$
0
0

Over the last several weeks, lots of announcements have been made about the products that comprise Dynamics 365, specifically around Dynamics 365 Business Central. And I know we’ve been promoting this product line to you over the last several years. Your question: “Is it time that I look at what Dynamics 365 has to offer my infrastructure business?”

In a word: “YES!”

I see the pieces coming together: appropriate products and roadmap, competitive pricing, and easy availability.

One of my co-workers, Craig Crescas, is about to start a three city roadshow (San Diego, Chicago, New York) (https://blogs.technet.microsoft.com/uspartner_ts2team/2018/04/17/attend-one-of-the-upcoming-microsoft-dynamics-365-business-central-roadshows/)

and he just finished a four part webcast (https://msuspartner.eventbuilder.com/?landingpageid=u200VK)

And today, we are letting you know about another, upcoming, webcast series:

image

As a Microsoft Partner, adding Microsoft Dynamics 365 solutions to your current offerings can help turn your customer relationships into increased revenue and profitability. Join us in this three-part series where the Partner Technology Strategists and Architects will provide sophisticated demos of Dynamics 365 Sales, Customer Service, and Marketing. These demos will go in-depth on new product functionality, customer based scenarios, and steps on how to prepare a demo environment.

REGISTER NOW!

By adding Dynamics 365 to your portfolio you will also have the opportunity to earn customers for life with your ability to add your managed services and future Dynamics 365 modules to your customer offerings. Join us to see the potential Dynamics 365 can bring to your business.

In addition, they will show you demo tools and resources available to support your organization’s go to market strategy while reducing your cost of sale.

We look forward to have you join us for all three events!

Trying to attend all of these events is a HUGE investment of time, but attending one of these events is an appropriate investment in your future.

SDeming 2017  Steve

Tip of the Day: Windows 10 April 2018 Update

Tip of the Day: Features Removed or Planned for Replacement starting with Windows 10, version 1803

$
0
0

Today's tip...

Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1803 (also called Windows 10 April 2018 Update).

Reference: “Features removed or planned for replacement starting with Windows 10, version 1803” - https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-1803-removed-features

Tip of the Day: Help me choose

$
0
0

Today's tip...

Here’s a great tool that anyone can use to:

  • Shop for a new Windows 10 PC - Let’s you pick you devices based on what you plan to use it for and any special features you want to use.
  • Get Windows 10 – Let’s you pick between Home, School/Education, and Business versions. Also recommends new devices if yours is getting up there in age.
  • Check for Windows 10 updates – Quickly lets you know if you are up to date or if you need a bit of patching.
  • Learn more about Windows 10 Features – Currently showing you all of the cool features in the Windows 10 April 2018 Update.

Check it out and forward this along to your friends and family!

Reference: “Help me choose” - https://www.microsoft.com/en-us/windows/get-windows-10

Il Cloud (Microsoft) quale acceleratore della compliance GDPR – 2a parte

$
0
0

Nello scorso blog post vi avevo lasciato con una domanda che qui riprendo:

dal momento che il contratto cloud di Microsoft include già le tutele contrattuali necessarie, posso dire quindi di aver già soddisfatto tutti i requisiti di conformità GDPR nell'utilizzo di tali servizi ?

Per comprendere in quale misura le tutele contrattuali siano in grado di coprire i requisiti di conformità GDPR nel caso di servizi cloud è necessario rifarsi allo schema classico del NIST che descrive le varie tipologie di cloud pubblico possibili:


In questo schema, valorizzato in alto nel contesto delle soluzioni Microsoft, si potrà riconoscere come varia il livello di corresponsabilità operativa quando ci si sposta da uno scenario puro on-premise a sinistra (dove tutto è gestito dal cliente), via via verso modelli di cloud che fanno aumentare l'ambito operativo in carico al Cloud Service Provider (CSP), dove il modello di tipo Software as a Service (SaaS) a destra è quello più estremo in cui potrà apparire che sia quasi tutto in carico al CSP, e quindi Microsoft.

Se ci riflettete, questo modello di corresponsabilità operativa che varia in base al tipo di servizio cloud, si può leggere anche per chiarire come variano le tutele contrattuali che un CSP è in grado di fornire: maggiore è la responsabilità operativa, maggiore la responsabilità anche ai fini compliance (vedi riquadro rosso nella figura che segue):


Ma è bene aver chiaro che (attenzione, questo è il punto cruciale di questa spiegazione!) questo ambito di cui stiamo parlando è solo il primo dei possibili livelli su cui è necessario introdurre dei controlli di sicurezza per garantire una adeguata protezione del dato quando si considera l'utilizzo di servizi in cloud (come ricorda la nota "(1)-Cloud Security Level" che ho riportato in basso a destra nell'immagine che ho appena riportato).

Quali sono gli altri livelli? Ecco, schematizzando una interazione tra un endpoint (un PC, un tablet, uno smartphone, un dispositivo IoT, etc..) ed un servizio applicativo in cloud, questo di seguito potrebbe essere un modello che vi fa apprezzare quanti altri livelli di sicurezza vanno considerati:


Il primo livello di cui detto è solo quello relativo all'infrastruttura cloud realizzata per offrire l'applicazione considerata: per questo livello vale quanto già detto, ossia più il tipo di cloud è verso il SaaS, maggiore è la responsabilità operativa (e di compliance) in carico al CSP.

E' però fondamentale riconoscere che esiste un ambito intermedio che permette l'interazione tra l'endpoint e l'applicazione cloud che va considerato come ulteriore anello da mettere in sicurezza.

Nel contesto delle soluzioni Microsoft ho ritenuto utile distinguere questo ambito intermedio in due livelli:

  • Livello 2: sono le funzionalità di sicurezza native della stessa applicazione cloud di interesse. Disponibili come parte della stessa applicazione, ma con attivazione e gestione ancora a carico del cliente.
  • Livello 3: sono soluzioni di sicurezza di infrastruttura, offerte come soluzioni aggiuntive che sta al cliente valutare, ed eventualmente acquisire ed attivare.

Ultimo, ma non meno importante, bisogna ricordare che non si può tralasciare di rafforzare la sicurezza dell'endpoint.

Facciamo un esempio pratico per farvi ritrovare con applicazioni e soluzioni reali: supponiamo che la "Cloud Application" sia Exchange Online come parte della suite Microsoft Office 365.

Il Livello 1 è l'infrastruttura cloud Microsoft per offrirvi la soluzione di posta in cloud, su cui – in quanto SaaS – la quasi totalità della gestione operativa e quindi delle tutele compliance è di Microsoft. Sta a Microsoft documentare quanto bene si operi la gestione di tale livello per garantire un trattamento a norma.

Il Livello 2 è rappresentato dalle funzionalità di sicurezza (Identity Protection, Information Protection, Threat Protection, etc) incluse nativamente in Office 365/Exchange Online. In ambito clienti medio-grandi, queste variano in base ai piani di licenza Enterprise: maggiore il livello di licenza/piano Enterprise, maggiori le funzionalità incluse.

Prendiamo in esame la funzionalità di autenticazione per accedere alla casella di posta: normalmente i clienti realizzano una federazione di identità per riutilizzare l'identità e le credenziali on-premise di Active Directory per accedere in Single Sign-On (SSO) alla casella ospitata sul cloud.

In questo caso la robustezza dell'accesso alla casella di posta è legata a quanto sia protetta l'identità on-premise e quanto sia robusta la relativa password: il governo di questo anello della catena di sicurezza è ancora in carico al cliente nonostante la casella sia ospitata sul cloud Microsoft!!

Continuando con l'esempio, se il cliente disponesse di piani di licenza Office 365 E3, avrebbe a disposizione delle funzionalità di Multi-Factor Authentication (MFA) per rendere più robusto l'accesso alla posta (tramite l'uso di un cellulare che può ricevere il secondo fattore di autenticazione, come quando accediamo al conto corrente bancario online): decidere se usare questa funzionalità ed attivarla, è ancora una prerogativa in carico al cliente! (quindi ancora una sua responsabilità in ottica compliance/GDPR)

Le funzionalità MFA incluse in Office 365 E3 permettono di essere applicate come singolo interruttore ON/OFF per tutti gli utenti e per tutte le applicazioni della suite (Exchange, Sharepoint, Onedrive for Business, Skype for Business, etc…) senza possibilità granulare di attivazione per singolo utente/gruppo o per singola applicazione: è solo con l'utilizzo di una soluzione di livello 3, Azure MFA (acquisibile singolarmente o come parte della suite di soluzioni di sicurezza denominata Enterprise Mobility & Security (EMS)), che è possibile guadagnare la massima capacità funzionale e in particolare la granularità di poter abilitare l'MFA solo per alcuni utenti/gruppi o solo per alcune applicazioni.

Decidere se adottare tale soluzione per rispondere al meglio ad alcuni requisiti compliance/GDPR è ancora una prerogativa del cliente!!

Come lo è anche decidere le soluzioni di sicurezza da implementare a livello di endpoint: cosa dite, ai fini compliance/GDPR è la stessa cosa decidere di mantenere i client su Windows XP (ormai non più supportato e quindi non più protetto dagli aggiornamenti di sicurezza), o evolvere verso il recente e quindi più robusto/aggiornato Windows 10??

Se quindi applicassimo il modello di sicurezza che vi ho appena proposto (in presenza di una applicazione cloud) allo scenario di esempio della produttività personale con soluzioni Microsoft, questo sarebbe il risultato corrispondente:


La suite di soluzioni Microsoft 365 (che racchiude licenze e relative funzionalità di Windows, EMS ed Office 365) è in grado quindi di offrire sia le tutele contrattuali dovute in quanto soluzioni cloud (livello 1) sia di offrire le soluzioni tecnologiche necessarie per mettere in sicurezza il trattamento del dato sugli ulteriori livelli (Livello 2, livello 3, livello Endpoint) che serve comunque indirizzare per un adeguata gestione del rischio.

Vi lascio con una considerazione per permettervi di fare un confronto con le altre soluzioni cloud sul mercato: tutti i Cloud Service Provider dovranno offrirvi (entro il 25 maggio) le tutele contrattuali GDPR per il livello 1, ma quanti sono in grado di offrirvi anche un insieme di soluzioni di sicurezza che si integrino tra di loro nel modo migliore possibile e verso le soluzioni on-premise per mettere in sicurezza gli altri livelli??

E per il confronto con le soluzioni totalmente on-premise? Nel caso di scenario puro on-premise tutta la catena di controlli e quindi di tutele tecnico-organizzative è solo in carico al cliente con tutto quello che ne consegue in termini di costi e tempi… mentre le soluzioni cloud, che – ripeto – devono essere contrattualmente conformi alla GDPR, permettono sia di "trasferire" una parte della gestione e quindi del rischio e di realizzare soluzioni di protezione in modo significativamente più rapido ed efficace di quanto si possa fare on-premise.

Ecco perché il Cloud, e solo quello Microsoft (per la capacità distintiva di offrirvi anche soluzioni di sicurezza di infrastruttura integrate tra loro), è a tutti gli effetti considerabile quale acceleratore della compliance (sia in generale che quella GDPR, nello specifico di questo momento storico), e questa a sua volta in grado di poter agire da acceleratore per la trasformazione digitale tanto necessaria e finora spesso frenata proprio dalle perplessità sul cloud nei confronti della conformità normativa.

Ai prossimi post il compito di illustrarvi questo insieme davvero ricco di funzionalità di sicurezza incluse in Microsoft 365.

 

P.S. ricordo il post che agirà da sommario di tutti i miei post a tema GDPR:

A presto!

 Feliciano

@felicianointini
(mostly in Italian – technical & non technical tweets)


@NonSoloSecurity
(English only – technical only)


 

The May Partner Insider call is this Wednesday!

$
0
0

Todd Sweetser

The May Partner Insider call is this Wednesday!

Join the Microsoft US team for the Partner Insider call this Wednesday, May 2, 2018 where you’ll get valuable, actionable information to help your Microsoft business grow.

May Agenda:

  • Insider Scoop | Melody Chen, Partner Channel Marketing Manager will cover events, training, offers in market and more
  • Office 365 Business Apps | Jimmy Ward, Senior Product Marketing Manager will walk you through the Business apps for SMBs, give a demo and talk about the partner opportunity
  • Solution Areas Plays | Jose Gomez Cueto Director, One Commercial Partner, Go to Market, will share new resources to help your customers achieve digital transformation

STAY IN THE KNOW

We look forward to you joining us on the May 2 Partner Insider call!


Tip of the Day: How to get the Windows 10 April 2018 Update

Support-Info: (PCNS): PCNS is not sending passwords to the Synchronization Service Engine

$
0
0

 

PRODUCTS / COMPONENTS INVOLVED

  • Microsoft Identity Manager 2016 Service Pack 1
    • Password Change Notification Service (PCNS)

PROBLEM SCENARIO DESCRIPTION

  • Passwords are not being replicated to the Target Domain

NOTE

If passwords are not making it from the Source Domain Controller to the Synchronization Service Manager GUI, enable verbose logging and see if you are getting an Event ID 6025 in the Application Event Log.

PCNS: Troubleshooting Event ID 6025: https://social.technet.microsoft.com/wiki/contents/articles/4159.pcns-troubleshooting-event-id-6025.aspx

CAUSE

  • Password Synchronization was not enabled in the Synchronization Service Manager GUI
    • Enable Password Synchronization  in Tools > Options was not enabled (checked)
  • Source and Target Management Agents were not setup

Source - Configure Directory Partitions

  • Target - Configure Extensions

RESOLUTION

  • Enable the Enable Password Synchronization option in Tools > Options
  • Enable the Source Management Agent on Configure Directory Partitions
  • Enable the Target Management Agent on Configure Extensions

  ADDITIONAL INFORMATION

Support-Info: (GROUP MANAGEMENT): Group information is not being synchronized to/from Active Directory

$
0
0

PRODUCTS / SOLUTIONS / FEATURES INVOLVED

  • Microsoft Identity Manager 2016 Service Pack 1
    • Group Management

PROBLEM SCENARIO DESCRIPTION

  • This issue centered around Group Management.  We were not seeing Security and/or Distribution Groups be synchronized correctly through the Synchronization Engine.

CAUSE

From Portal to Active Directory

  • We noticed that the Provisioning Synchronization Rules for Security Groups were not being applied.
  • In review of the Outbound Synchronization Rule, the Scope was set to "GroupType" instead of "Type"

From Active Directory to Portal

  • FIM Service Management Agent was missing Export Attribute Flow (EAF) for member

RESOLUTION - FROM PORTAL TO ACTIVE DIRECTORY

  1. Update the Scope on the Group Outbound Synchronization Rule
    1. Set the Scope to reference the Metaverse Attribute "Type"
    2. Updated the DN on the Outbound Attribute Flow tab to ensure that it referenced an OU that exists in Active Directory and is in Scope for the Active Directory Management Agent.
  2. Import and Sync the update to the Synchronization Rule into the Synchronization Service Engine (FIM Service Management Agent Connector Space and Metaverse)
  3. Test the Synchronization Process through the use of the Preview Feature

RESOLUTION - FROM ACTIVE DIRECTORY TO PORTAL

  1. Added Export Attribute Flow for the attribute Member on the Group to Group branch under Configure Attribute Flow

ADDITIONAL INFORMATION

 

Tip of the Day: What’s new in the Windows 10 April 2018 Update

Integrated Security Configuration for your Azure VM

$
0
0

Last week I wrote about the new Azure Security Center Network Map, today I want to talk about the new integrated security configuration experience for Azure VMs, which was also something that we announced at RSA Conference. With this new experience, you can see all recommendations for a particular VM, directly from the VM's properties in the Azure Portal, under the Security settings as shown below:

With this new integration, you can quickly visualize VM's recommendations as you go through the process of reviewing the VM's settings. In this blade you can also identify in which workspace this VM is located, and the Security Center tier. This interface also allows you to quickly navigate from this blade to Security Center dashboard.

Can I export these recommendations?

Since this is a common question, I decided to add it here, and the answer is: you can, but not from this blade. The best way to export Azure Security Center recommendations is via Azure Advisor dashboard. As you can see below, the Security tile is basically a list of recommendations coming from Azure Security Center:

From this dashboard, you can download the recommendations as PDF or CSV format.

 

 

Viewing all 36188 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>