Quantcast
Channel: TechNet Blogs
Viewing all 36188 articles
Browse latest View live

FieldNote: Scanned firewall, found TCP ports open: 25, 80, 443

$
0
0

One time, I had a phone call from the ISP for the company I was working at and they said they did a firewall scan without notifying us. Ok, thanks for that, but next time, be honest and let us know when you are going to perform a penetration test and we’ll be happy to work with them.

They told me that the firewall was extraordinarily strong and only allowed three ports access to two specific IP addresses using the follow TCP ports: 25, 80, and 443. They mentioned it would be wise to consider closing those ports to not allow access for a more secure environment. I then thought, if I block the Exchange server from using TCP’s 25, 80/443, then no need for mail flow nor OWA. And the TCP 80/443 ports on the web server, wouldn’t need to host up any web pages for the customers. Thus, no need to pay the ISP for any bandwidth usage and save money and they would lose out on our money. Sigh…thanks for the information.


(RDS) Tip of the Day: Azure Marketplace new offers

$
0
0

Today's tip...

We continue to expand the Azure Marketplace ecosystem. From May 1 to 15, 28 new offers successfully met the onboarding criteria and went live.

See details of the new offers below:

Altova Server Platform: This free Azure virtual machine template makes it easier and more convenient to use Altova server software in the cloud. The VM template installs the complete line of Altova server software products, including the free LicenseServer, on the VM you specify in Azure.
Apptimized Test: Apptimized Test takes away the pain from constant retesting against the Windows platform. Using our unique Azure-based solution, test all your products against every Insider Release of every Microsoft Windows change well before that change moves into production.
Apptimized Catalogue: Get instant access to latest versions of the world’s most commonly packaged applications, already packaged to Apptimized’s high quality standards. No longer pay each time an application needs to be repackaged; simply log in and download the latest version.
Apptimized Packaging Service: We package applications for all formats, against any platform, without you needing to invest a penny in hardware, software, or expensive resources. Built on over 15 years delivering specialist packaging services to hundreds of customers of all sizes across all sectors.
Apptimized Packaging Tool: The Apptimized Packaging Tool is a scalable, low-cost alternative to the traditional thick client toolsets. For a low monthly fee, access everything needed to discover, package, remediate, test, and store as many applications and application packages as you like.
Apptimized Monitor: Apptimized Monitor continually analyzes multiple sources of industry data, so we can let you know instantly when any one of 250 applications in your portfolio has been updated by its vendor. We monitor 250 products, keeping your applications estate current.
CentOS for Azure Batch container pools: Use this CentOS image to create Azure Batch pools to run container applications. These images should only be used with Azure Batch service to create pools that run container applications. The images have the container runtime pre-installed.
CentOS (with RDMA) for Azure Batch container pools: Use this image (with RDMA driver) to create Azure Batch pools to run container applications. Only use these images with Azure Batch service to create pools that run container applications. The images have the container runtime pre-installed.
CloudEndure Disaster Recovery - Tier-2: CloudEndure utilizes Azure to provide an affordable enterprise-grade disaster recovery solution for any source workload – physical, virtual, or cloud-based. Recover workloads into Azure, launching an identical copy of your source machines.
FastCollect from Archive360: FastCollect is a powerful data onboarding platform that is based on a legally compliant data validation engine. Onboard 80+ data types to Azure at high speed while maintaining 100% data fidelity and chain of custody. Meets all required compliance regulations.
hive - Azure Self Service Portal: hive removes bottlenecks, eliminates human errors, and reduces VM request time from 1 week to 1 hour. Our workflows include: list all VMs in Azure IaaS; email requestor and approver; empower users to schedule start and stop of VMs; and more.
PHP 5.6 - Zend Server: Zend Server on Azure is designed for both development and production. Create higher-performing applications and run mission-critical PHP applications in the cloud. Zend Server is an application server designed to scale applications seamlessly across cloud resources.
PlateSpin Migrate: PlateSpin Migrate is a powerful workload portability solution that automates the process of moving workloads over the network between physical servers, virtual hosts, and enterprise cloud platforms – all from a single point of control. Test, migrate, and rebalance workloads.
Rapid Recovery Core VM: Rapid Recovery advanced data protection unifies backup, replication, and recovery in one easy-to-use software solution. The Rapid Recovery Core Virtual Machine for Azure leverages the Microsoft cloud for snapshot backups and all the features of Rapid Recovery.
Solar inCode: Solar inCode seamlessly plugs into each stage of the software development lifecycle (SDLC), thus allowing your developers to run security scans with ease and focus on building applications. Control the security of applications, provided to you by third-party developers.
STAR-CCM+ v12: The STAR-CCM+ v12 integrated engineering simulation software on Microsoft Azure gives you the additional compute power you need to solve your complex simulations. With one click you can run STAR-CCM+ on your Azure instance of choice with STAR-CCM+ pre-installed.
Stratusphere UX: Stratusphere UX provides complete Microsoft Windows desktop monitoring, diagnostics, performance validation, and optimization. The solution supports all Microsoft Windows-based delivery approaches, including virtual and mixed platform desktop environments.
Ubuntu server OS for Azure Batch container pools: Use this Ubuntu server OS image to create Azure Batch container pools. These images should only be used with Azure Batch service to create pools that run container applications. The images have the container runtime pre-installed.
Ubuntu (with RDMA) for Azure Batch container pools: Use this Ubuntu server OS image to create Azure Batch container pools. These images should only be used with Azure Batch service to create pools that run container applications. The images have the container runtime pre-installed.
Microsoft Azure Applications
Alchemi Intelligent Data Management Stack: Alchemi is a solution that sits above all file data, creating a unified virtual view that describes the universe of content, yet leaves the physical data where it sits. It creates a near-real-time, central metadata index representing all environments it sees.
AppGate SDP: AppGate SDP for Azure supports fine-grained, dynamic access control to Azure resources. Using a Software-Defined Perimeter approach for granular security control, it makes your Azure resources inaccessible and invisible. It then delivers access to authorized Azure resources only.
Azure Blockchain Workbench: The Azure Blockchain Workbench is the fastest way to get started with blockchain on Microsoft Azure. This tool allows developers to deploy a blockchain ledger along with a set of relevant Microsoft Azure services most often used to build a blockchain-based application.
Haivision Media Gateway 1.5: Haivision Media Gateway on Microsoft Azure is used for efficiently transporting high-quality, low-latency live HD video via the open-source SRT protocol to multiple locations around the world, making it ideal for broadcast distribution and enterprise events.
Haivision Media Gateway 1.6.2: Haivision Media Gateway on Microsoft Azure is used for efficiently transporting high-quality, low-latency live HD video via the open-source SRT protocol to multiple locations around the world, making it ideal for broadcast distribution and enterprise events.
Infrastructure for SAP Netweaver and SAP HANA: Get the most from your SAP HANA and SAP business application software with decreased downtime, greater efficiency, and accelerated innovation with the reliability, availability, and service ability of SUSE Linux Enterprise Server for SAP.
Paxata Self-Service Data Preparation: Paxata Self-Service Data Preparation is a solution for business analysts and data professionals to discover, ingest, explore, transform, and export data, creating clean and contextual information from raw data. This fuels data exploration, discovery and analytics.
TeamCity: TeamCity is a continuous integration and continuous delivery server from JetBrains. It takes moments to set up, shows your build results on the fly, and works out of the box. TeamCity will make sure your software gets built, tested, and deployed, and will notify you on that the way you choose.
Unraveldata: Unravel Data is the Application Performance Management platform for big data that is full-stack and intelligent. Unravel Data guarantees the reliability and performance of apps, maximizes cost savings, and more. The Unraveldata app for HDInsight is prepared for Azure HDInsight clusters.

Reference: Azure Marketplace new offers: May 1–15 - https://azure.microsoft.com/en-us/blog/azure-marketplace-new-offers-for-may-1-15/

Configuring a PowerShell DSC Web Pull Server to use SQL Database

$
0
0

Introduction

Hi! Thank you for visiting this blog to find out more about how you can configure a PowerShell DSC Web Pull Server to use an SQL database instead of the "Devices.edb" solution we currently use.

Since you made it his far I assume that you're already familiar with PowerShell and PowerShell Desired State Configuration but if not, I encourage you to read more about PowerShell and PowerShell Desired State Configuration.

Either way, you are probably ready to experiment with Desired State Configuration or ready to implement a Desired State Configuration architecture within your environment (perhaps even production).

I wrote this blog post to show you how you can implement an example Desired State Configuration environment where the Secure Pull Web Server uses a SQL database to store all data.

About me

Before I do so I will tell you a little bit about myself.

My name is Serge Zuidinga and I'm a Dutch Premier Field Engineer with System Center Operations Manager as my core technology.

I started working at Microsoft in September 2014 focusing on supporting customers with their Operations Manager environment(s) and, among other things, the integration with automation products like System Center Orchestrator.

I always had a passion for scripting and application development so this was the ideal situation for me since I could use my passion for PowerShell in combination with Operations Manager and Orchestrator.

I've been seriously working with PowerShell ever since and am currently involved with not only System Center Operations Manager and Orchestrator but with Azure in general and Azure Automation, OMS, EMS, Operations Manager Management Pack Authoring, Visual Studio, Visual Studio Team Foundation Server, PowerShell and PowerShell Desired State Configuration in particular.

I currently also support customer in designing and building a Continuous Integration and Continuous Deployment pipeline with Desired State Configuration and Visual Studio Team Foundation Server besides Operations Manager, Orchestrator and Operations Management Suite.

Let's get started

Glad to see you made it through the introduction.

So, this is the plan:

  • Step 1: the prerequisites
  • Step 2: implement our example environment
  • Step 3: watch it work
  • Step 4: enjoy our accomplishments

Prerequisites

Windows Server 2019 Technical Preview

To be able to leverage the ability to use an SQL database with our pull server, we need to deploy a Windows Server 2019 Technical Preview server which holds the version of WMF 5.1 that includes the ability to connect to SQL server.

We should make sure that we have the latest version of Windows Server 2019 Technical Preview installed since, at least up until build 17639, the MUI file could be missing required elements to support SQL server.

Note: there is currently no support for SQL with DSC on Windows Server 2016 (or previous Windows Server versions) even though WMF 5.1 is available for Windows Server 2016!

If you want, you can read all about the supported database systems for WMF versions 4.0 and higher at Desired State Configuration Pull Service ("Supported database systems"-section) and please check out this great post by Raimund Andrée on how to use a SQL server 2016 as the backend database for a Desired State Pull Server.

We also need to make sure that we have version 8.2.0.0 (or higher) of the "xPSDesiredStateConfiguration"-module installed on our Windows Server 2019 Technical Preview server.

Hint: Find-Module -Name xPSDesiredStateConfiguration | Install-Module

Note: version 8.3.0.0 is the latest version of the "xPSDesiredStateConfiguration"-module at the time this blog post was written

A certificate for enabling a HTTPS binding within IIS is also required for our example environment to work so please make sure you have a web server certificate installed on your Windows Server 2019 Technical Preview server along with the "xPSDesiredStateConfiguration"-module.

Finally, access to any SQL server instance to host our database.

From a firewall perspective, we only need access to the TCP port the SQL server instance is listening on from our pull server.

There's no need to create a database upfront since this will be taken care of by our pull server (our database will always be created with "DSC" as the name for our database) and both SQL and Windows Authentication is supported.

Note: you can use a Domain User account instead of the "Local System"-account the IIS AppPool is configured with by default.

If you want to use a Domain User account, you only need to make sure that it has "dbcreator"-permissions configured for the SQL Server instance that will host the "DSC"-database

Let's get cracking!

Implement a Secure Web Pull Server

Step 1

Install the PowerShell Desired State Configuration by using "Add Roles and features" available through Server Manager or from PowerShell: Add-WindowsFeature -Name DSC-Service

Step 2

Get the thumbprint of our web server certificate we are going to use for our HTTPS binding: Get-ChildItem -Path Cert:LocalMachineMy -SSLServerAuthentication

Get a unique GUID that we are going to use as a registration key: (New-Guid).Guid

Get the SQL connection string that will allow our pull server to connect to the appropriate SQL server instance or modify and use one of the following examples:

  • Windows Authentication: Provider=SQLOLEDB.1;Integrated Security=SSPI;Persist Security Info=False;Initial Catalog=master;Data Source=SQLDSC
  • SQL authentication: Provider=SQLOLEDB.1;Password="password";Persist Security Info=True;User ID=user;Initial Catalog=master;Data Source=SQLDSC

Note: you can leave Initial Catalog=master as is because we'll create and use a specific database (called "DSC") for use with our pull server.

Step 3

Create a MOF file that we will use to configure our pull server. You can modify and use this example:

# === Arguments ================================================ #
# We got these from step 2 #
$Thumbprint = "BF6E5EFC44A15FE238CDE2A77D9A12B07B0BA200"
$Guid = "5fd98d96-7864-4006-b60d-0a907a676c6a"
# === Arguments ================================================ #
# === Section Secure Web Pull Server with SQL database ========= #
Configuration SecureWebPullServerWithSQLDatabase {
Param([string]$NodeName"localhost",
[string$Thumbprint = "$(Throw "Provide a valid certificate thumbprint to continue")",
[string]$Guid"$(Throw "Provide a valid GUID to continue")")

Import-DscResource -ModuleName PSDesiredStateConfiguration
Import-DSCResource -ModuleName xPSDesiredStateConfiguration

Node $NodeName {
Windowsfeature DSCServiceFeature {
Ensure = "Present"
Name "DSC-Service"
}

xDscWebService SecureWebPullServer {
Ensure = "Present"
EndpointName "SecureWebPullServer"
Port 443
PhysicalPath "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerWebsite"
CertificateThumbPrint $Thumbprint
ModulePath "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerModules"
ConfigurationPath "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerConfiguration"
State "Started"
DependsOn "[WindowsFeature]DSCServiceFeature"
RegistrationKeyPath "C:Program FilesWindowsPowerShellDscService"
AcceptSelfSignedCertificates $true
UseSecurityBestPractices $true
SqlProvider $true
SqlConnectionString "Provider=SQLOLEDB.1;Integrated Security=SSPI;Persist Security Info=False;Initial Catalog=master;Data Source=PUT_DMZ_SQL_SERVER_INSTANCE_HERE"
}

Windowsfeature IISMGMTConsole {
Ensure "Present"
Name "Web-Mgmt-Console"
DependsOn = "[xDscWebService]SecureWebPullServer"
}

File RegistrationKeyFile {
Ensure "Present"
Type "File"
DestinationPath "C:Program FilesWindowsPowerShellDscServiceRegistrationKeys.txt"
Contents $Guid
DependsOn "[xDscWebService]SecureWebPullServer"
}
}
}

# === Section Secure Web Pull Server with SQL database ========= #
SecureWebPullServerWithSQLDatabase -NodeName PUT_SERVER_FQDN_HERE -Thumbprint $Thumbprint -Guid $Guid -OutputPath C:WindowsTemp -Verbose

Just open it in Windows PowerShell ISE (I use Visual Studio Code but you can use any editor of your preference) and make the necessary modifications (at least the thumbprint and registration key).

Assuming the previous steps went well, we should now have a MOF file in C:WindowsTemp on our Windows Server 2019 Technical Preview server.

Let's get our pull server configured by consuming the MOF file we just created: Start-DscConfiguration -Path C:WindowsTemp -Wait -Verbose

Our pull server has now been configured and we are ready to host (partial) configurations and have clients connect to consume the appropriate configurations.

We will create such a partial configuration as an example so that we can serve any connected clients.

So, like what we just did we can create a configuration and MOF file that our client(s) will consume. You can modify and use this example:

Configuration TelnetClient {
Import-DscResource -ModuleName PSDesiredStateConfiguration

Node TelnetClient {
Windowsfeature TelnetClient {
Name 'Telnet-Client'
Ensure 'Present'
}
}
}

TelnetClient -OutputPath "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerConfiguration" -Verbose

New-DscChecksum -Path "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerConfiguration" -OutPath "C:Program FilesWindowsPowerShellDscServiceSecureWebPullServerConfiguration" -Verbose

We are now ready to connect one or more clients to our pull server. You can modify and use the following example on a Windows Server (for this example you should not use your pull server) that you want to connect to our pull server:

[DscLocalConfigurationManager()]
Configuration PartialConfig {
Param([string]$NodeName = 'localhost')
Node $NodeName {
Settings {
RefreshFrequencyMins = 30;
RefreshMode = "PULL";
ConfigurationMode = "ApplyAndAutocorrect";
AllowModuleOverwrite = $true;
RebootNodeIfNeeded = $true;
ConfigurationModeFrequencyMins = 60;
}


ConfigurationRepositoryWeb PullServer {
ServerURL = "https://FQDN_SECURE_WEB_PULL_SERVER/PSDSCPullServer.svc/"
RegistrationKey = "5fd98d96-7864-4006-b60d-0a907a676c6a"
ConfigurationNames = @("TelnetClient")
#ConfigurationNames = @("TelnetClient","Web-Mgmt-Console") # Multiple partial configurations
}

ReportServerWeb PullServer {
ServerURL = "https://FQDN_SECURE_WEB_PULL_SERVER/PSDSCPullServer.svc/"
RegistrationKey = "5fd98d96-7864-4006-b60d-0a907a676c6a"
}

PartialConfiguration TelnetClient {
Description = "Installs the Telnet Client"
ConfigurationSource = @("[ConfigurationRepositoryWeb]PullServer")
}
}
}

PartialConfig -OutputPath C:WindowsTemp -Verbose

Assuming the previous steps went well, we should now have a Meta MOF file in C:WindowsTemp on our Windows Server 2019 Technical Preview server that allows for configuring the Local Configuration Manager.

To configure the LCM to actually connect to and retrieve (a) configuration(s) from our pull server, we just need to execute: Set-DscLocalConfigurationManager -Path C:WindowsTemp -Verbose

Step 4

Congratulations on implementing your pull server with a SQL database! Sit back and enjoy your newly installed and configured PowerShell DSC Secure Web Pull server with a SQL database!

Stay tuned for the next post were I will tell you more on how you can pull reports.

Excel Online – External Users cannot refresh data connections

$
0
0

Scenario:

You're using an Excel file that contains a Excel Power Pivot Model with external data connections and currently the data refresh in Excel Online is working without any issues for the internal users of the organization tenant.

When this file is shared with external users of the tenant, this users are not able to refresh the file from the Excel Online. They receive an error message like:

"An error occurred while working on the data model in the workbook. Try again.
One or more data connections in this workbook can not be refreshed."

Or

"An error occurred while working with the data model in the book. Try again.
Failed to update the data connections in this book.
The failure occurred when the following connections were updated:"

Cause:

Currently, the data refresh operation in Excel Online doesn’t support external users of the tenant.

As workaround, the user can possibly open the file into the Excel client application and refresh the data source from there.

 

 

BlogMS Microsoft Team Blogs – June 2018 Roll-up

ReadReceipt on Active Sync Device

$
0
0

Starting from Exchange 2016, now you can disable Read Receipt Feature on Active Sync Device through cmdlet.

Default Output would be:

Get-CASMailbox <User> | fl ActiveSyncSuppressReadReceipt
ActiveSyncSuppressReadReceipt : False

You can set it $Ture and it will change following option in Outlook Web Access as well.

Set-CASMailbox <User> -ActiveSyncSuppressReadReceipt $True

 

 

July 2018 Office 365 Update video, survey, resources and transcript now available

OSD with Configuration Manager Video Tutorial Series Overview

$
0
0

Over the next few weeks we will be publishing another video tutorial series on our YouTube channel focused on Operating System Deployment (OSD) with Configuration Manager. These videos have been prepared by Steven Rachui, a Principal Premier Field Engineer focused on manageability technologies.

This series will be divided into 4 main sections, each consisting of multiple tutorials.

  •  OSD - Introductory Sessions for those who are new to OSD. Using Config Manager 2012 to demonstrate, Steve covers all the foundational topics including image capture, task sequencing, driver management and PXE.
  • OSD - A Deeper Dive will get into task sequence variables, USMT and MDT integration, Pre-staged media and nested task sequences in Configuration Manager current branch.
  •  OSD - Advanced Concepts includes optimizing task sequences, UEFI, custom boot images, DaRT, troubleshooting and automation.
  • OSD and Windows 10 discusses servicing options and the imaging options available for Windows 10 in Configuration Manager.

Posts in the OSD Introductory Sessions 

  • Part I - Introduction and Basics
  • Part II - Obtain and Import the Image
  • Part III - Task Sequencing
  • Part IV - Image Deployment
  • Part V - The Logical Task Sequence
  • Part VII - Driver Management
  • Part VIII - Understanding PXE
  • Part IX - Standalone USMT

Go straight to the playlist

We hope you enjoy.


OSD Video Tutorial: Part I – Introduction and Basics

$
0
0

This is the first session of a series that will detail the Operating System Deployment feature of ConfigMgr 2012. The session provides base knowledge that answers the questions - what is OSD?  Why OSD? The session also provides a quick look at the ConfigMgr 2012 console showing and describing the various elements relevant to OSD.

The video linked below was prepared by Steven Rachui, a Principal Premier Field Engineer focused on manageability technologies. 

Next in the series, Steven will discuss the process of image capture.

Posts in OSD Introduction Sessions

  • Operating System Deployment - Part I - Introduction and Basics (this post)
  • Operating System Deployment - Part II - Obtain and Import the Image
  • Operating System Deployment - Part III - Task Sequencing
  •  Operating System Deployment - Part IV - Image Deployment
  •  Operating System Deployment - Part V - The Logical Task Sequence
  •  Operating System Deployment - Part VII - Driver Management
  • Operating System Deployment - Part VIII - Understanding PXE
  • Operating System Deployment - Part IX - Standalone USMT

Go straight to the playlist

OSD Video Tutorial Overview

Top stories for US partners the week of July 9

$
0
0

Find resources that help you build and sustain a profitable cloud business, connect with customers and prospects, and differentiate your business. Read previous issues of the newsletter and get real-time updates about partner-related news and information on our US Partner Community Twitter channel.

Subscribe to receive posts from this blog in your email inbox or as an RSS feed.

Looking for partner training courses, community calls, and information about technical certifications? Refer to the Hot Sheet training schedule for a six-week outlook that’s updated regularly as we learn about new offerings. To stay in touch with us and connect with other partners and Microsoft sales, marketing, and product experts, join our US Partner Community on Yammer.

Microsoft Inspire 2018

New posts on the US Partner Community blog

New videos on the US Partner YouTube channel

MPN news

Upcoming events

US Partner Community call schedule

Community calls and a regularly updated, comprehensive schedule of partner training courses are listed on the Hot Sheet

デジタル トランスフォーメーションの道筋を示すガイドブック【7/10更新】

$
0
0

(この記事は2018年5月1日にMicrosoft Partner Network blog に掲載された記事 Guidebooks for your digital journey  の翻訳です。最新情報についてはリンク元のページをご参照ください。)

 

 

 

デジタル トランスフォーメーションの道筋を示すガイドブック

デジタル トランスフォーメーションは、もはや単なる将来のビジョンではありません。今日、かつてないほどの成長を実現するためには、クラウドを避けて通ることはできず、インテリジェントなテクノロジを活用して、お客様のイノベーションを主導する必要があることは明白です。

お客様は既に、業界で生じている破壊的変革を目の当たりにしています。変革を加速し続けるには、お客様との適切な対話を重ね、最新のテクノロジに合わせてビジネス戦略を立てる必要があります。

 

マイクロソフト デジタル トランスフォーメーション シリーズ

そこで、このたび『Microsoft Digital Transformation Series (マイクロソフト デジタル トランスフォーメーション シリーズ)』という電子ブックを制作しました。この電子ブックでは、パートナー様がデジタル トランスフォーメーションを加速し、テクノロジ リーダーとなるためのビジネス チャンスについて、概略を説明しています。International Data Corporation (IDC) と共同で制作した全 5 冊の電子ブックをお読みいただき、デジタル トランスフォーメーションを加速すると共に、お客様の業界で生じている変革の様相について理解を深めてください。

この電子ブックでは、量的調査 (世界各地のパートナー様 639 社を対象とした IDC による調査) と質的調査 (パートナー様へのインタビュー) の両方を実施し、パートナー様が現在のビジネス チャンスを活用するにあたって、どのような立ち位置にいるかを解説しています。

今はまさしくチャンスの時です。IDC の予測によると、2019 年末までに、新たなビジネス モデル、製品、業務効率化の施策、カスタマー エクスペリエンスの構築への投資額は、全世界で 1.7 兆ドルに達する見込みです。また、2021 年までには、クラウド テクノロジやクラウド サービスへの支出が 2 倍以上に拡大し、2022 年までにはデジタル トランスフォーメーションのビジネス チャンスが 20 億ドルを超えると予測されています。

 

 

調査結果からは、デジタル トランスフォーメーションが今や経営幹部にとっての重要課題となっていることが見て取れます。2020 年までには、デジタル戦略を導入している企業の割合は 60% 以上に達します。今後、パートナー様はサービスの提供を通じて、お客様が最新テクノロジの導入と企業文化の変革を実現していくうえで、主導的な役割を果たすようになるでしょう。

現在、デジタル戦略を展開しているパートナー様は 84% になりますが、その大半はまだスタートを切ったばかりの段階です。パートナー様が専門性の高いソリューションを提供していくことで、お客様が業界に破壊的変革を起こせるよう、迅速に支援できます。

 

このシリーズの第 1 弾となる『The Digital Transformation Opportunity (デジタル トランスフォーメーションのビジネス チャンス、英語)』では、市場機会とお客様のデジタル トランスフォーメーションに対する成熟度について、深く掘り下げて説明しています。デジタル トランスフォーメーションを成功させるうえで企業に求められる特性について解説しているほか、クラウド テクノロジ (AI やブロックチェーンなど) に合わせたビジネス戦略によって業務の改善と収益化を図る方法を紹介します。IDC の予測によると、2019 年までに、AI、ビッグ データ、IoT を活用しているデジタル事業の割合は 40% に達する見込みです。

また、IDC は、マイクロソフトのデジタル トランスフォーメーションの柱が、お客様のニーズに対応するためのロードマップとなることも確かめています。今後公開予定の電子ブックでは、デジタル トランスフォーメーションに対する成熟度の高いパートナー様が、収益を拡大するために、次の 4 つの柱にどのように重点を置いているかについて取り上げます。

 

  • お客様との関係の強化
  • 従業員の支援
  • 業務の最適化
  • 製品の変革

 

デジタル トランスフォーメーションは、マイクロソフト パートナー様の収益率を何倍にも高める中核的な役割を果しています。2017 年には、マイクロソフトの収益 1 ドルにつき、パートナー様が獲得した収益は 9.64 ドルになりました。これは 2022 年まで変わらない見通しです。

この収益率の高さは、パートナー様の製品やサービスの豊富さによるものです。パートナー様が自社の価値、なかでも知的財産 (IP) を拡張することで、お客様のデジタル トランスフォーメーションの成功を今後も加速していくことにつながります。さらに、IP はパートナー様のデジタル トランスフォーメーションに対する成熟度と直結しています。IDC の調査によると、IP 関連サービスを提供しているパートナー様の利益率が最も高く、70% を超えています。

デジタル経済をリードするには、革新的なサービスの提供に専念する方向へ、従業員のトレーニングをシフトさせる必要があります。IDC の予測によると、2020 年までには、新規採用者の 85% に分析スキルや AI のスキルが求められるようになるほか、Forbes Global 2000 企業の  25% でデジタル トレーニング プログラムが実施され、デジタルな協働体制が敷かれるようになります。

 

状況は急を要します。IDC の予測によると、2020 年には Global 2000 企業の半数で、情報ベースの製品やサービスの収益成長率が平均的なポートフォリオの 2 倍になる見込みです。

投資家はデジタル ビジネスを異なる角度から見ており、デジタル企業として認知されているかどうかが企業評価に影響を及ぼします。IDC の予測によると、2020 年には、プラットフォームへの参画、データの価値、カスタマー エンゲージメントといった基準が企業評価の 75% 以上を占めるようになります。

デジタル トランスフォーメーションにおいて、課題とビジネス チャンスは同義語です。このシリーズでは今後、パートナー様の効果的な戦略や、自社のデジタル トランスフォーメーションの要件に関する有用な情報をお届けします。引き続きご注目ください。

 

皆様のデジタル トランスフォーメーションについて、ぜひこちらのマイクロソフト パートナー コミュニティ (英語) でお聞かせください。

 

 

 

 

 

Behind the design: Meet the new Surface Go

$
0
0

Today we are excited to launch Surface Go, our brand new 10-inch ultra-light device, which gives you a highly portable form factor for mobile experiences at a lower price point. Importantly, for mobile workers and students, the good news is that great value does not come at a compromise. The Surface Go team crafted the device to be versatile enough to function as a tablet or laptop. Combined with Windows 10 Pro, it’s powerful enough for Firstline Workers and students to run full desktop applications.

As Surface engineer, Cindy Martinez, explains on today’s episode of Microsoft Mechanics, ensuring that we could fit everything needed into this vastly reduced form factor, while maintaining the modern, iconic, Surface design, was our top engineering challenge.

Compact mobility

The first thing you’ll notice when you see the Surface Go, is it looks like a Surface Pro just much smaller. Its weight starts at just 18.4 ounces. At the back of the device you’ll see a number of familiar features such as the 8MP Camera. The full friction kickstand is capable of lowering to 165º to give you an optimal angle for writing and drawing. A microSD card slot nested behind the kickstand, allows you to add additional mobile storage.

An interesting feature added to support mobile use, is the Surface Go’s near field sensor, this can be used to read RFID tags to track inventory or even to launch specific applications for an appliance-like experience.

Further, the LTE Advanced option, available later this year, will come with a SIM tray for 4G LTE connectivity using a Qualcomm® Snapdragon™ X16 LTE Modem. This is the same modem found in the full-sized Surface Pro with LTE Advanced.

At the front of the device, Surface Go comes equipped with a 5MP front facing camera for video conferencing, and an infrared camera for facial recognition with Windows Hello.

The screen is a compact 10”, 3 by 2 optically-bonded Pixel Sense™ display. It has 217 PPI and the optical bonding gives you a full 180 degree viewing angle.

Each screen is individually color-calibrated at the factory for color accuracy and supports the same 10-point touch as on other Surface devices. Used with the Surface Pen you get a full inking experience, and tilt support for shading.

Power and performance

We chose to stay with an Intel architecture for predictable performance whether you're using modern apps or full desktop software.

Surface Go comes with an Intel® Pentium® Gold Processor 4415Y with Intel HD 615 GPU and is available in several memory and storage configurations, supporting up to 8 GB of RAM and up to a 256 GB NVMe SSD.

Intelligent charging means that you can fully charge Surface Go from 0 to 100% capacity, in just 2 hours, and you can get up to 9 hours of use, based on normal video playback.

Device portability also extends how we help you charge Surface Go. The Surface Connect charger is smaller too, at just 5 ounces it’s about half the size of a regular Surface charger and if you prefer can the USB-C port to charge the device.

Further, as you use Surface Go, it’s noticeably fanless. The device disperses heat using passive cooling which not only helps reduce weight and size of the device but also reduces noise levels. The absence of air vents by design, also makes it easier to use Surface Go in high particulate environments like factory floors or mines.

Ports and Peripherals

Surface Go comes with an array of ports including a headphone jack, Surface Connect for charging and connecting to Surface Dock, as well as a full functioning USB-C port that supports power, video and data. Surface Go can also be used with Surface Dock.

Accompanying the Surface Go is an ultra-compact optional Type Cover. Here the challenge was to engineer a smaller yet comfortable, premium quality typing experience.

Adjustments were made to the pitch between keys, while ensuring a vertical travel of 1mm. Despite being smaller, the Type Cover comprises a mechanical, backlit keyset.

This in combination with the Alcantara fabric, makes the Type Cover comfortable to use despite its smaller size compared to the Surface Pro Type Cover.

And to add to comfort, while everything else on the Type Cover was carefully remodeled, we made the trackpad slightly bigger allowing precise movements as well as multi-touch gestures.

Durability on the go

We expect Surface Go to be used outside of an office environment. For example, in schools, in healthcare and in the field.

Like all Surface devices, we've put Surface Go through a battery of stringent use case tests. We’ve also worked with top accessory manufacturers worldwide to produce ruggedized cases and screen protectors, including some to MIL standard specs, available soon.

To learn more about the design of Surface Go, watch today's Microsoft Mechanics  episode with engineer Cindy Martinez. Please also visit our Surface Go website and keep current on the design and management of Surface devices, by checking out our Microsoft Mechanics playlist.

 

特許庁の機械翻訳システムに、Microsoft Azure が基盤として採用

$
0
0

執筆者:クラウド & エンタープライズビジネス本部 本部長 浅野 智

 

特許戦略のグローバル化に伴い、特許文献を翻訳する頻度・件数は急激に増えています。従来の人手による翻訳作業は、時間がかかる、コストが高い、大量の翻訳は難しいなどの課題がありました。近年、機械翻訳技術の進展に伴い、機械翻訳の活用が進んでいますが、翻訳品質の高まりと比例して、莫大な計算能力が不可欠となっています。今回、東芝デジタルソリューションズ株式会社様(本社:神奈川県川崎市、取締役社長:錦織弘信、以下 東芝デジタルソリューションズ)は特許庁様から、特許審査官、企業や研究機関などが使う「機械翻訳システム」を受注、国立研究開発法人情報通信研究機構の開発した最新のニューラル機械翻訳エンジンを組み合わせたそのシステムのクラウド基盤として、日本マイクロソフトのクラウドプラットフォーム Microsoft Azure が採用されました。

「機械翻訳システム」では、ニューラル機械翻訳エンジンの処理性能を発揮させるための高速 GPU インスタンスを始め、他の複数の翻訳インスタンスを並列的に動作させ必要に応じた柔軟なサーバリソース、 Security Center など各種セキュリティサービスや、構造化が難しい大量の翻訳データやログを低レイテンシーで適切に保管・分析・復元する COSMOS DB 等、システムの基盤部分として Microsoft Azure の多岐にわたる機能・サービスが活用される予定です。

Microsoft Azure はクラウドセキュリティゴールドマークの取得や、日本に寄り添った契約形態(円建てでの支払いや日本の法律の準拠)など特許庁様が求める各種基準に準拠したクラウドプラットフォームであっただけでなく、今回大量の特許文献に対して高速に翻訳処理を行うにあたり、すでに 280 台のマシーンによる同時並行処理において期待に応えるパフォーマンスと安定稼働を実現した実績を有しており、高く評価されました。さらに日本マイクロソフトは、高速・同時・大量な処理が可能なこの機械翻訳システム全体のアーキテクチャー設計支援、導入検討時のサポート体制の構築等、細やかなコンサルテーションを行うことで、今回の導入検討を支援してまいりました。  日本マイクロソフトは今後とも、高品質の機械翻訳ソリューションの開発・改良を続ける東芝デジタルソリューションズ様をアーキテクチャー設計支援と強力な技術サポート体制の両面で支援するとともに、特許庁様を含めた官公庁におけるクラウド化を積極的にサポート・推進してまいります。

 

関連情報
東芝デジタルソリューションズ株式会社 ニュースリリース
URL  https://www.toshiba-sol.co.jp/news/detail/20180710.htm
 
 

Encrypting Emails from Anywhere!

$
0
0

The Situation:

So, you recently purchased Microsoft 365 E3/E5 (or EMS E3/E5) and have started rolling out your pilot of Azure Information Protection.  Everything is going great until one of your executives approaches you and wants to know how to protect emails from their phone/tablet while they are relaxing on the beach.  You could always just hand them a shiny new Surface Pro with Office 365 Pro Plus, but they mentioned that sometimes they send emails while they are in the water (hey, I do that too!) and Surface Pro's aren't super tiny and waterproof (yet).  So, you need a different solution that will quickly enable said executive to classify and protect their emails right from their portable device.

The Solution:

The solution to this conundrum comes in the form of the new Office 365 Encrypt functionality and Exchange Online Mail Flow Rules (the feature formerly known as Exchange Transport Rules or ETRs).  By setting up a label in the Azure Information Protection portal called Encrypt, you can allow your executives (and everyone else) to automatically encrypt emails and supported attachments by simply adding a keyword like #Encrypt to the bottom of their message.  I will walk you through this process in the rest of this post.

The Label

The way that I typically recommend that customers set up their label is as a sub-label of a Confidential and/or Highly Confidential top level label.  In the portal it would look like the image below.

 

If you need assistance creating a label, please see my previous post on the subject at http://blogs.technet.microsoft.com/kemckinn/2018/05/17/creating-labels-for-azure-information-protection/. However, as TL;DR, I will walk you through the simple steps of setting up this sub-label.

  1. Log into https://portal.azure.com as an O365 Global Admin or Security Admin with rights to the AIP Portal
  2. In the search bar at the top of the portal, type Inform and click on Azure Information Protection
  3. In the AIP Portal, you should see the list of labels similar to the image above.  If you do not, under Classifications on the left, select Labels
  4. Assuming you have a top level label similar to Confidential, click the ... on the right and click Add a sub-label
  5. In the new Sub-label, give it the name Encrypt and the description This message is encrypted. Recipients can't remove encryption. and Save.  We are using this specific name and description because it mirrors the native Encrypt protection verbiage. Do not add any protection to this label (we will do that with the mail flow rule).
  6. You should now have an unprotected sub-label that looks similar to the image at the beginning.

The Mail Flow Rules

Now that you have the label, you can set up your mail flow rules.  We will set up 2 seperate mail flow rules, one for the label, and one for the keyword.  Follow the steps below to set up your mail flow rules.

  1. In the AIP Portal, click on the Encrypt label and scroll to the bottom where the label ID is shown
  2. Copy this Label ID into a new notepad document and add the words MSIP_Label_ and _Enabled=True around the Label ID. In my case, I have MSIP_Label_18acc54a-e84e-4add-9fe5-36781d02b550_Enabled=True.
  3. Next, log into https://outlook.office365.com/ecp/ as either a Office 365 Global Admin or Exchange Admin
  4. On the left side, click mail flow
  5. This will default to the rules pane
  6. In the rules pane, click the  and click Create a new rule...
  7. In the new rule pane, name the rule Encrypt and click the More options... link
  8. After clicking More options..., select the drop-down under *Apply this rule if... and hover over A message header... and click includes any of these words
  9. Click on the *Enter text... link and type msip_labels in the specify header name box and click OK
  10. Next, click on the Enter words... link and copy/paste the label information you have stored in the notepad document and click the  then click OK

  11. Click the drop-down below the *Do the following... and hover over Modify the message security... and click Apply Office 365 Message Encryption and rights protection
  12. In the select RMS template dialog, click the drop-down below RMS template: and select Encrypt and click OK
  13. The completed rule should look like the image below. Click Save to finish creating the first mail flow rule.
  14. To create the second rule, highlight the Encrypt rule and click the  button
  15. This will create a copy of the first rule named Copy of Encrypt and open it for editing
  16. Rename the rule to #Encrypt then click the drop-down under *Apply this rule if... and hover over The subject or body... and select subject or body includes any of these words
  17. In the specify words or phrases dialog, add #Encrypt (and optionally #ENC) and press then OK once finished
  18. The completed second rule should look like the image below.  Click Save to complete creation of the rule.
  19. You should now have two rules that can be used to apply the Encrypt protection to messages and supported attachments.

The Added Bonus

Ok, so you may have noticed that your really didn't need the label itself to use the #Encrypt function of the Mail Flow Rule.  That is true, but what you have now is a label that gives you the same functionality as the brand new Encrypt feature (that is in Office 365 ProPlus 2016 version 1804+) that you can use with any version of office that supports the AIP Client (that's all the supported versions of Office). So I might have added more functionality than you necessarily needed, but it was totally worth it. 😉

Another fun bonus, is the #Encrypt tag can be used to encrypt emails from Mac Office clients where there is no AIP Client currently (that is coming later this year), so for all of you out there that use Office for Mac, this gives you that additional functionality too!

Hopefully this is helpful to get you set up to use the new Encrypt functionality.  Let me know in the comments if there is anything you didn't understand.

 

Azure – PowerShell Azure locations with zones

$
0
0

#Requires -module AzureRM

#find regions that support Zones and what VM SKus are supported

function Get-AzureRMlocationZones {
PARAM ($location,$ComputeResourceSku)

$sku=Get-AzureRmComputeResourceSku | Where-Object {$_.ResourceType -eq 'virtualMachines' -and $_.LOcationInfo.Zones }

if ($location) {
$sku = $sku | Where-Object {$_.Locations -eq $location}
}

if ($ComputeResourceSku) {
$sku = $sku | Where-Object {$_.Name -eq $ComputeResourceSku}
}

$sku
}

#Get-AzureRMlocationZones -Location FranceCentral -Name Standard_D12_v2
Get-AzureRMlocationZones -ComputeResourceSku Standard_D12_v2


SPO Tidbit – SharePoint Online Page diagnostics

$
0
0

Hello All,

I’ve been asked on multiple occasions if we have any tools to insure that best practices are being followed in SPO.  And we do have something that can look at your pages in Classic Teams and Publishing sites, it will analyze the page and provide feedback based on rules in the tool.

You can get the Tool for Chrome then follow this article to run the tool

Pax

Tip of the Day: Windows Server Storage Migration Service

$
0
0

Today's tip...

Windows Server 2019 Preview contains an entirely new feature!

The Storage Migration Service helps you migrate servers and their data without reconfiguring applications or users.

  • Migrates unstructured data from anywhere into Azure & modern Windows Servers
  • It’s fast, consistent, and scalable
  • It takes care of complexity
  • It provides an easily-learned graphical workflow

Check out the blog post for more information and check back for updates!

References:

Microsoft PremCast: Einhaltung der Anforderungen der DSGVO mit der Microsoft SQL Plattform

$
0
0

Beschreibung
Ab Mai 2018 gilt die EU-Datenschutz-Grundverordnung (DSGVO), eine Verordnung der EU zum Schutz personenbezogener Daten. Die Datenschutz-Grundverordnung beinhaltet neue Regeln für Unternehmen, Behörden, gemeinnützige und andere Organisationen, die Waren und Dienstleistungen für Menschen in der EU anbieten oder Daten im Zusammenhang mit EU-Bürgern erfassen und analysieren.

Erfahren Sie in diesem PREMCast mehr darüber, wie unsere Datenbankprodukte Sie bei der DSGVO-Compliance unterstützen und Ihnen den Einstieg erleichtern.

Zielgruppe
IT Manager, Architekten, Entwickler, Projekt Manager

Level 200
(Level Skala: 100= Strategisch/ 200= technischer Überblick/ 300=tiefe Fachkenntnisse/ 400= technisches Expertenwissen)

Sprache
Dieser Workshop wird in deutscher Sprache gehalten.
Wir bieten Ihnen diese Webcasts als Online-Meeting über Microsoft Skype for Business an. Die Referentin erläutert das Thema anhand von Microsoft PowerPoint Slides, die Sie zum Webcast erhalten.

Anmeldung
Zur Anmeldung wenden Sie sich bitte direkt an Ihren Microsoft Technical Account Manager. Besuchen Sie uns auf Microsoft Premier Education. Dort finden Sie eine Gesamtübersicht aller verfügbaren Webcasts, Workshops und Events.

Microsoft PremCast: Big Data Analytics mit Azure Data Lake

$
0
0

Beschreibung
Azure Data Lake umfasst alle erforderlichen Funktionen, die Entwickler, Data Scientists und Analysten benötigen, um Daten problemlos speichern zu können – und zwar unabhängig von der Größe, vom Format und von der Geschwindigkeit der Daten. Mit Data Lake gehört die Komplexität beim Erfassen und Speichern von Daten der Vergangenheit an, und mit Batch-, Streaming- und interaktiven Analysen können Sie Ihre Analysen jetzt noch schneller ausführen.

Erfahren Sie in diesem PREMCast mehr darüber, was Data Lake Store und Data Lake Analytics sind, und wie sie sich von anderen Big Data Produkten unterscheiden.

Zielgruppe
IT Manager, Architekten, Entwickler, Data Scientists

Level 100-200
(Level Skala: 100= Strategisch/ 200= technischer Überblick/ 300=tiefe Fachkenntnisse/ 400= technisches Expertenwissen)

Sprache
Dieser Workshop wird in deutscher Sprache gehalten.
Wir bieten Ihnen diese Webcasts als Online-Meeting über Microsoft Skype for Business an. Die Referentin erläutert das Thema anhand von Microsoft PowerPoint Slides, die Sie zum Webcast erhalten.

Anmeldung
Zur Anmeldung wenden Sie sich bitte direkt an Ihren Microsoft Technical Account Manager. Besuchen Sie uns auf Microsoft Premier Education. Dort finden Sie eine Gesamtübersicht aller verfügbaren Webcasts, Workshops und Events.

 

グループ ポリシー [ロック画面を表示しない] の動作につきまして

$
0
0

みなさん、こんにちは。
Windows プラットホーム サポートの山﨑です。
今回は、Windows 10における、ロック画面をユーザーに表示するかどうかを制御する
以下ポリシーの動作につきましてご紹介いたします。

パス   : [コンピューターの構成] - [管理用テンプレート] - [コントロール パネル] - [個人用設定]
ポリシー名: [ロック画面を表示しない]

本ポリシーにつきましては、グループ ポリシー エディターの説明には「 注意: この設定は、Enterprise SKU、
Education SKU、Server SKU にのみ適用されます。」と記載されておりますが、以下のWindows 10 Professional 
エディションにおきましても、適用されるポリシーであることをお伝えいたします。

   ● Windows 10 Professional ビルド1511 (TH2) 以前
   ● 2017 年 4 月 26 日 リリースの更新プログラム KB4016240 適用済みの Windows 10 Professional ビルド1703 (RS2) 以降 
   ● Windows 10 Professional ビルド1709 (RS3)
   ● Windows 10 Professional ビルド1803 (RS4)


一部のOSバージョンでは適用されない理由につきまして


本ポリシーは、本来 Windows 10 Enterprise や Windows 10 Education にのみ適用されるグループ ポリシーでございましたが、
Windows 10 Professional ビルド 1703 (RS2) 以降のOSでは 2017 年 4 月 26 日 リリースの更新プログラム KB4016240 における
修正により、Professional エディションにおきましても、正式な動作として適用されるようになっております。

なお、Windows 10 Professional ビルド 1511 (TH2) 以前でも本ポリシーは適用されておりましたが、この動作は
本来 Windows 10 Enterprise や Windows 10 Education にのみ適用されるグループ ポリシーが誤って適用されてしまう
という既知の問題によるものでした。
この問題を受け、Windows 10 Professional ビルド1607 (RS1) 以降で適用されないように動作変更されている経緯がございますため、
Windows 10 Professional ビルド1607 (RS1) および 2017 年 4 月 26 日 リリースの更新プログラム KB4016240 適用以前の
Windows 10 Professional ビルド1703 (RS2) では適用されません。

参考情報:2017 年 4 月 26 日 — KB4016240 (OS ビルド 15063.250)
https://support.microsoft.com/ja-jp/help/4016240/windows-10-update-kb4016240
※ Professional SKU でグループ ポリシーを使用しているときに、ロック画面を無効にすることができない問題を修正しました。

参考情報:Windows 10 Professional ビルド 1607 (RS1) 以降では適用されなくなったグループ ポリシーについて
https://blogs.technet.microsoft.com/jpntsblog/2017/08/10/windows-10-professional-%E3%83%93%E3%83%AB%E3%83%89-1607-rs1-%E4%BB%A5%E9%99%8D%E3%81%A7%E3%81%AF%E9%81%A9%E7%94%A8%E3%81%95%E3%82%8C%E3%81%AA%E3%81%8F%E3%81%AA%E3%81%A3%E3%81%9F%E3%82%B0%E3%83%AB/

本 Blog が少しでも皆様のお役に立てれば幸いです。


山﨑 智子 (ヤマザキ トモコ)
Windows プラットフォームサポート担当
日本マイクロソフト株式会社

Viewing all 36188 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>