Quantcast
Channel: TechNet Blogs
Viewing all 36188 articles
Browse latest View live

Send encrypted emails to anyone using Office 365!

$
0
0

Have you ever needed to send an email to someone, but didn't want them to forward the email nor copy sensitive text out of the attachment or email? You probably only want the intended recipient to view the email, and not accessible to anyone else. In other words, you probably want that email to be encrypted. If you are an Office 365 subscriber – you have this capability today: Office 365 Message Encryption (OME)! Would this be useful in your environment? If so, read on…

OME enables only the intended recipient to open the message using their identity: Azure AD, Office 365, Microsoft Account, Gmail, or a One Time Passcode (OTP). Once accessed, they can read the email but based on your policy they cannot forward the email – and they have read only of the attachments (and cannot download the attachments).

Let's take a look at the user experience and what OME is all about!

IMPORTANT: For the full technical documentation on how to setup and the IT Admin configuration that is required see: Office 365 Message Encryption and Set up new Office 365 Message Encryption capabilities for more information.

Sending the email:

I am going to send an email to a Gmail account. Office 365 Message Encryption in my environment is configured using a Mail Flow rule in Exchange Online to apply encryption to any email leaving my organization that has the key words of Sales Quote. I am also going to send the same email to a Outlook.com account. I'll explain later why the two accounts.

The message will now be received at Gmail and Outlook.com. Note the experience (subject line and body of message) in Gmail:

The email is encrypted. To view its contents I am going to click "Read the message". A new browser window will appear asking me to authenticate. From here I can use my Gmail (Google) credentials to view the email– or a One Time Passcode emailed to me:

For purposes of this demo I am going to click Or,sign in with a one-time passcode. The OTP will be emailed to me:

 

Next, I am going to type in the OTP to gain access to the encrypted email:

Once I have authenticated using the OTP, I can now view the contents of the encrypted email. Notice how the Forward button is grayed out and the email is only viewable in the browser. Even right click functionality is disabled!

 

If I try to open the attached document, I can download it, but once opened I can view the text but cannot cut/copy text out of the document (it is protected). Also, notice how I cannot take a screen shot – it's blacked out!

Pretty cool huh? Remember I also sent the same email to an Outlook.com address.
IMPORTANT:
Outlook.com and Azure AD (Office 365) subscribers, will never have to authenticate using a OTP or have a secure browser session – pass thru authentication will enable the recipient to view the email within the email application. Here's what this looks like in Outlook.com without having to take any additional action to read the encrypted email (note the forward button is also grayed out)

Conclusion:

Depending on you business scenario Office 365 Message Encryption may help you to stay compliant and ensure that only intended recipient can view your email, and stay confident the information in the email will be protected. Enjoy!


SPO Tidbit – Released SMPT PowerShell

$
0
0

Hello All, 

I have previously mentioned the SharePoint Migration Tool (SPMT) and it’s capabilities, so I won’t go into how the tool works but read here for detailed info.  But what I want to provide you with is the fact that they have released PowerShell Cmdlet’s to help with the management.

  1. Register-SPMTMigration:  This cmdlet will create a SPMT migration session and initialization. The initialization includes configuring migration settings at session level and connecting to SPO. If no specific setting parameters are defined, default settings will be used.  After a session is registered, the Administrator can add a migration task to the SPMT session and start migration.
  2. Add-SPMTTask: Add a new migration task to the registered migration session. Currently you can add three types of tasks;File share task, SharePoint task and JSON defined task.
  3. Remove-SPMTTask: Remove an existing migration task from the registered migration.
  4. Start-SPMTMigration: This cmdlet will start the registered SPMT migration.
  5. Get-SPMTMigration: Return object of current session. It includes information regarding to current tasks and current settings.
  6. Stop-SPMTMigration: Cancel the current migration session.
  7. Show-SPMTMigration: If the admin starts the migration in NoShow mode, running the ‘Show-SPMTMigration’ cmdlet will display the task ID, data source location, target location and migration status in the console.
  8. Unregister-SPMTMigration: Remove the SPMT migration session created.

For more information on the cmdlets and there configuration see here.

To help you understand how long a migration could take please see this article.

Pax

2018 年 9 月のセミナーの開催予定のご案内

$
0
0

マイクロソフトでは、様々な支援ができるよう多数のセミナー(オンラインでのウェビナーおよび実際にスクール形式で行うオンサイトセミナー)を開催しております。遠方や当日都合が悪くてもオンラインでご参加いただける形式のオンラインセミナーも多数実施しております。是非ご参加いただき、お役立て下さい。(事前のお申込みが必要になります)

「登録サイトが公開され次第、順次アップデートいたします。」

なお、終了したウェビナーの閲覧は Azureサイトの歩き方ページより、[学習] ― [過去の Web/動画セミナー (2018 年 1 月以降)] から参照いただけます

 

Index

ライセンス
AI/BI
IoT
DevOps
モバイル/Web
データベース
インフラ

セッションレベルの説明
  • L100…マイクロソフトの製品群やテクノロジ群の方向性を説明し、ビジネス判断のためにテーマを理解できることを目指したレベル
  • L200…受講いただいた方がテーマの製品やテクノロジの全貌や備わった機能を把握し、開発/提案ができるようになることを目指したレベル
  • L300…受講いただいた方が自ら関わっているプロジェクトでプロトタイピングや PoC などを通じて採用判断/開発判断ができることを目指したレベル

 


[ウェビナー]

 
ライセンス

2018/9/25 (L100)

[ウェビナー] 初めての Azure ~購入方法~

 

AI/BI

2018/9/18 (L100) (登録サイト準備中)

[ウェビナー] スマートスピーカのビジネス活用 音声認識 AI がもたらすワークスタイル変革

 

IoT

2018/9/21 (L100)

[ウェビナー] IoT がビジネスを変える! -マイクロソフトの IoT 戦略と最新事例-

 

DevOps
-

 

モバイル/Web
-

 

データベース

2018/9/14 (L100)

[ウェビナー] Databricks で始める Spark。構築から活用までの第一歩

 

インフラ系

2018/9/12 (L100)

[ウェビナー] Azure へのお引越しシリーズ(全 6 回)第 5 回 これまでの AD と Azure AD は何が違うの?

2018/9/12 (L100)

[ウェビナー] Azure はじめの一歩(全 6 回)第 5 回 Azure で運用管理ってどうするの?

2018/9/19 (L200)

[ウェビナー] Azure へのお引越しシリーズ(全 6 回)第 6 回 Azure って安心して使えるの?

2018/9/19 (L100)

[ウェビナー] Azure はじめの一歩(全 6 回)第 6 回 Azure でコストを下げることはできるの?

 
 

[オンサイト]

2018/9/11 (L200)

[オンサイト] データセンターのクラウド移行検討

2018/9/18 (L200)

[オンサイト] <SQL Server Day> SQL Server 丸わかり 1 日セミナー

2018/9/25 (L200) (登録サイト準備中)

[オンサイト] Microsoft Azure + Power BI で始めるビッグ データ分析の第一歩~ Microsoft が提供する AI と機械学習~

 

Bluetooth を搭載し、Windows 10 搭載 PC にもワイヤレス接続が可能な『Xbox ワイヤレス コントローラー (スポーツ ホワイト)』 を数量限定で発売

$
0
0

日本マイクロソフト株式会社 (本社: 東京都港区) は、清潔感のあるホワイトの本体に、シルバー、ミント グリーンをアクセントに採用した『Xbox ワイヤレス コントローラー (スポーツ ホワイト)』を 2018 年 8 月 23 日 (木) より 6,980 円 (税抜参考価格)*1 で全国のゲーム販売店にて数量限定で発売します。

『Xbox ワイヤレス コントローラー (スポーツ ホワイト)』は、特徴的な本体デザインに加え、グリップ部分には滑りにくく操作しやすいラバー加工を施したダイアモンド グリップを採用しています。また、Windows 10 搭載 PC やタブレットとワイヤレス接続が可能な Bluetooth を搭載しています。*2

ゲームの臨場感を表現するリアル トリガー*3、高い操作性を実現したスティックと方向パッドを操作しやすい位置に配置。お持ちのヘッドセット*4 などを直接接続できる 3.5mm ステレオ ヘッドセット ジャックを搭載したワイヤレス コントローラーです。

製品基本情報

製品名
Xbox ワイヤレス コントローラー (スポーツ ホワイト)
日本語カナ読み
エックスボックス ワイヤレス コントローラー スポーツ ホワイト
国内販売元
日本マイクロソフト株式会社
発売予定日
2018 年 8 月 23 日 (木)
SKU番号
WL3-00094
JAN コード
4549576096681
参考価格
6,980 円 (税抜)*1
主な特徴
  • 清潔感のあるホワイトの本体に、シルバー、ミント グリーンをアクセントに採用
  • Windows 10 搭載 PC やタブレットとワイヤレス接続が可能な Bluetooth を搭載 *2
  • グリップ部分には滑りにくく操作しやすいラバー加工を施したダイアモンド グリップを採用
  • 臨場感を表現する「リアル トリガー」*3
    • 振動モーターを Xbox ワイヤレス コントローラーの左右グリップとコントローラー上部の左右トリガーに合計 4 つ搭載。銃を撃った時のダイナミックな振動や人間の鼓動といった繊細な振動まで、幅広い表現を実現します
  • ゲーム体験を広げる機能
    • Micro USB 端子に USB ケーブルを接続すれば、無線が自動的にオフになり、有線コントローラーとして使用可能
    • 同時に 8 つの Xbox ワイヤレス コントローラーを接続可能
    • 単 3 形アルカリ乾電池 2 本で動作
    • 最大 10 m の距離からプレイが可能
お持ちのヘッドセットなどを直接接続できる 3.5mm ステレオ オーディオ ジャックを搭載 *4
主な同梱物
  • Xbox ワイヤレス コントローラー (スポーツ ホワイト) 本体
  • 単 3 形乾電池 (試供品)
外形寸法
  • 153 x 102 x 61 mm
重量
約 280 g
電源
単 3 形乾電池 x 2, リチウムイオン リチャージブル バッテリーパック (別売), Micro USB 端子 (USB ケーブルは別売りです)
ボタン
Xbox ボタン、左/右トリガー、L/R ボタン、ビュー ボタン、メニュー ボタン、A ボタン、B ボタン、X ボタン、Y ボタン、左/右スティック、方向パッド
端子
Micro USB 端子
拡張端子 (デジタル インターフェース)
3.5 mm ステレオ オーディオ ジャック
コピーライト

*1 お客様の購入価格は、販売店により決定されますので、販売店にお問い合わせ下さい。
*2 Windows 10 搭載デバイスとの Bluetooth 接続には Windows 10 Anniversary Update の適用が必要です。また、コントローラー本体のファームウェアをアップデートする必要な場合があります。Windows 10 で Xbox ワイヤレス コントローラーを更新する方法については 「Windows 10 で Xbox One コントローラーを更新する方法」 を参照してください。Windows 7、8.1、または 10 で Bluetooth を使わずに使用する場合は、USB ケーブル (別売) が必要です。
*3 リアル トリガーは対応したゲームのみ有効です。
*4 ヘッドセットの互換性に関する詳細は 「互換性のあるヘッドセットを接続する | Xbox One」 をご参照ください

.none{display:none;}
.valign {
position: relative;
}
.valign .vtest {
position: absolute;
top: 50%;
left: 50%;
margin-right: -50%;
-webkit-transform: translate(-50%, -50%); /* Safari用 */
-ms-transform: translate(-50%, -50%);
transform: translate(-50%, -50%);
}
.entry-title {font-size: 36px;}
.row-eq-height {display: flex; flex-wrap: wrap;}
.info .row {margin: 0; border-right: 1px solid #ddd;}
.info .row .col-sm-3, .info .row .col-sm-9 {padding: 6px 15px 6px 15px; border-top: 1px solid #ddd; border-left: 1px solid #ddd;}
.info .row-end {border-bottom: 1px solid #ddd}
.info .row .col-sm-3 {background-color: #eee; text-align: center; font-weight: 500;}
.sup-link {margin-bottom: 20px;}
.copyright{font-size: .75em;}
.br3:after {content: "A"; white-space: pre;}
ul {margin: 3px 0 3px -10px;}

@media screen and (max-width:768px) {
.valign {
position: static;
}
.valign .vtest {
position: static;
top: 0;
left: 0;
margin: 0;
-webkit-transform: translate(0%, 0%); /* Safari用 */
-ms-transform: translate(0%, 0%);
transform: translate(0%, 0%);
}
.entry-title {font-size: 21px;}
.info .row {font-size: calc(12px + 1vw);}
.info .row .col-sm-3 {text-align: center;}
.br1:after {content: "A"; white-space: pre;}
.br3:after {content: " "; white-space: pre;}
ul {margin: 3px 0 3px -15px;}
}

@media screen and (max-width:420px) {
.br2:after {content: "A"; white-space: pre;}
}

Microsoft Premier Workshop: System Center Configuration Manager: Troubleshooting Infrastructure

$
0
0

Beschreibung

Der dreitägigen Workshop System Center Configuration Manager: Troubleshooting Infrastructure vermittelt den Teilnehmer die Fähigkeiten, die benötigt werden, um die gängigsten System Center Configuration Manager Infrastructure Probleme zu analysieren. Dies erfolgt anhand von praktischen Übungen, in denen die Tools und Ressourcen genutzt werden, um diese Probleme zu lösen. Der Workshop besteht aus Wissensvermittlung anhand der praktischen Erfahrungen unserer Trainer in Form von Präsentationen, Demonstrationen, Diskussionen und Hands-on Labs. Teilnehmer erhalten einen Einblick in die Techniken und den Prozess der Problembehandlung des Configuration Manager.

Zielgruppe
Dieser Workshop richtet sich in erster Linie an IT Mitarbeiter die bereits mit bestehenden Installationen von System Center Configuration Manager arbeiten und über ein fortgeschrittenes Know-How verfügen.  Ein Basis Know-how von Windows Server 2016 und Windows 8.1 oder spätere Versionen sollte vorhanden sein.

Level 300
(Level Skala: 100= Strategisch/ 200= technischer Überblick/ 300=tiefe Fachkenntnisse/  400= technisches Expertenwissen)

Agenda
Module 1: Troubleshooting Tools and Resources
Module 2: Management Point
Module 3: Updating and Servicing Configuration Manager
Module 4: Database Replication
Module 5: Content Distribution
Module 6: Performance Considerations
Module 7: Backup and Recovery

Sprache
Dieser Workshop wird in deutscher Sprache gehalten. Es werden hauptsächlich Englisch sprachige Kursunterlagen verwendet.

Anmeldung
Zur Anmeldung wenden Sie sich bitte direkt an Ihren Microsoft Technical Account Manager oder besuchen Sie uns im Web auf Microsoft Premier Education. Dort finden Sie eine Gesamtübersicht aller offenen Workshops, für die Sie sich dort auch gleich anmelden können.

Airband Grant Fund de Microsoft invierte en 8 startups que entregan soluciones conectadas a internet a comunidades rurales alrededor del mundo

$
0
0

Por: Shelley McKinley, jefa de tecnología y responsabilidad corporativa en Microsoft.

ColdHubs es uno de los ocho receptores del Microsoft Airband Grant Fund que utiliza los espacios blancos de TV y otras tecnologías para expandir el acceso a soluciones habilitadas por internet. Foto cortesía de ColdHubs.

En la actualidad, el acceso a internet es tan esencial como la electricidad. Impulsa a emprendedores para comenzar y crecer pequeños negocios, a los agricultores para implementar agricultura de precisión, a los doctores a mejorar la salud de la comunidad y a los estudiantes para tener un mejor rendimiento en la escuela. Pero casi la mitad de la población del mundo aún no está conectada, de manera frecuente debido a que viven en áreas marginadas, y debido a esto pierden oportunidades para aprovechar y ser parte de la economía digital. Como una empresa global de tecnología, creemos que tenemos una responsabilidad y una gran oportunidad de cerrar esta brecha.

Es por eso que estamos emocionados por anunciar a las ocho compañías en etapa temprana que fueron seleccionadas para nuestro tercer Airband Grant Fund anual. Estas startups han superado barreras para brindar acceso asequible a internet a comunidades marginadas y sin conexión a comunidades en los Estados Unidos, África y Asia a través de espacios blancos de TV (TVWS, por sus siglas en inglés) y otras prometedoras tecnologías de acceso de última milla. Nuestro fondo de subvención brindará financiamiento, tecnología, mentoría, oportunidades de crear conexiones y otras formas de soporte para ayudar a escalar estas nuevas e innovadoras tecnologías, servicios y modelos de negocio de estas startups. Airband Grant Fund es parte de Microsoft Airband Initiative, lanzada en 2017 para extender el acceso de banda ancha a través de los Estados Unidos, y por último, conectividad alrededor del mundo.

Estamos emocionados por asociarnos con este grupo de beneficiaros de Airband, que incluye a:

Estas compañías mejoran la vida de algunas de las comunidades más marginadas en Estados Unidos y alrededor del mundo. Por ejemplo, cerca del 35 por ciento de la gente que vive en tierras tribales en los Estados Unidos carecen de acceso a banda ancha. Tribal Digital Village quiere cambia resto. Con el soporte de nuestro Airband Grant Fund, utilizarán TVWS (espectro vacante de transmisión que habilita conexiones de internet en terreno rural desafiante) y otras tecnologías para desplegar banda ancha en hogares tribales en 20 reservaciones aisladas en el sur de California. “Nos dimos cuenta que sin acceso a internet, los estudiantes tribales no iban a tener acceso a oportunidades avanzadas que en su lugar otros niños sí tendrán”, comentó Matt Rantanen, director de tecnología para Tribal Digital Village. “Pero no había infraestructura en tierras tribales y ninguna compañía de telecomunicaciones quería trabajar con nosotros para construir una. Así que tuvimos que construirla por nuestra cuenta”.

ColdHubs es otra organización que ha encontrado maneras innovadoras de abordar el reto del acceso a la banda ancha. En Owerri, Nigeria, ColdHubs transforma sus espacios refrigerados de almacenamiento de cosechas en hot spots de Wi-Fi a través de tecnología TVWS. La compañía busca impulsar a los pequeños agricultores con la capacidad de conseguir un mejor sustento. Sus instalaciones de almacenamiento de cosechas con energía solar ayudan a reducir el deterioro de los alimentos, lo que causa que 470 millones de pequeños agricultores pierdan 25 por ciento de sus ingresos anuales. Los agricultores que utilizan ColdHubs pueden extender la frescura de sus frutas y vegetales de dos a cerca de 21 días, lo que reduce la pérdida posterior a la cosecha en un 80 por ciento. Al convertir estas instalaciones en “Farm Connect Centers” de Wi-Fi, ColdHubs permitirá a los agricultores estar en línea y acceder a entrenamiento en agricultura, recursos para mejorar los campos de cultivo y entrenamiento en mercadotecnia y habilidades digitales.

Ya sea en Estados Unidos o alrededor del mundo, creemos en fomentar soluciones innovadoras al dar apoyo a compañías y emprendedores locales. Estamos ansiosos por trabajar de cerca con estos receptores de Airband Grant Fund el siguiente año para refinar y expandir el alcance de sus soluciones. Y en los meses por venir, tendremos más por compartir sobre el increíble progreso que hemos conseguido en nuestra Iniciativa Airband, y nuestra meta de entregar acceso a banda ancha a 2 millones de estadounidenses rurales para 2022, además de extender la conectividad a comunidades marginadas alrededor del mundo. conozcan más sobre los acreedores al Airband Grant Fund aquí.

August 2018 Non-Security Office Update Release

$
0
0

Listed below are the non-security updates we released on the Download Center and Microsoft Update. See the linked KB articles for more information.

 

Office 2013

Update for Microsoft Office 2013 (KB3172506)

Update for Microsoft Office 2013 (KB4011155)

Update for Microsoft Office 2013 (KB4022212)

Update for Microsoft OneDrive for Business (KB4022226)

Update for Microsoft PowerPoint 2013 (KB4018374)

Update for Skype for Business 2015 (KB4032250)

 

Office 2016

Update for Microsoft Office 2016 (KB4032234)

Update for Microsoft Office 2016 Language Interface Pack (KB4032232)

Update for Microsoft OneNote 2016 (KB4022216)

Update for Microsoft PowerPoint 2016 (KB4018368)

Update for Microsoft Project 2016 (KB4032238)

Update for Microsoft Word 2016 (KB4032258)

Update for Skype for Business 2016 (KB4032255)

Update for Microsoft OneDrive for Business (KB4022219)

 

 

Support Tip: Intune Support for Android P

$
0
0

Google just announced release of Android P, or Android 9 Pie. Our Intune App Protection Policy (APP and also known as mobile app management or MAM) team and our Android Mobile Device Management (MDM) team have been testing each preview and wanted to keep you posted on what we’ve been finding. So far, through our testing with each beta release, all existing Intune MDM and Intune APP scenarios are compatible with this latest version of Android.

There's are a few things you’ll want to know:

  1. If you are an app developer who has taken a previous version of the Intune SDK for Android, you must adopt the recently published Intune APP SDK in order to ensure that Intune functionality within your app continues to work smoothly on Android P. In order to both facilitate Android P support and to provide a smoother integration experience, this new SDK provides a required build plugin which performs most SDK replacements, such as inheriting from MAMActivity instead of Activity, automatically as a build step. Existing integrated code will not need to be rewritten. More details are provided in the documentation with the SDK release.
  2. If you are an app developer/IT admin that has taken a previous version of the Intune App Wrapping Tool, the Intune product team will be releasing an update in calendar year Q3 that all LOB apps must use in order to work with Android P.
  3. Encourage your end users to update to Intune's latest version of the Company Portal, Intune Managed Browser, and other APP-supported apps. The latest version is required to work with Android P.
  4. App icon branding: if you are using the old badging style for Intune, we recommend you use the briefcase icon. The Intune app partner web page will reflect these changes from your new icon. Our branding details are in this GitHub repository.

For customers using Intune MDM:

  1. Company Access Setup may not complete successfully on a device running Android P Preview builds. We are addressing this issue in the August production update of the Intune web portal.
  2. There's a slight branding change around app icon badging with Work Profiles in Android P. The Company Portal for Android uses this icon at the end of the workflow for enrolling with a Work Profile. Newer updates of the Company Portal will now show Google’s new design with a blue briefcase. There is no change in behavior or functionality. New icon (left), old icon (right).

As with other major platform updates, check mobile app compatibility with your app providers to confirm your users' apps work with Android P. You’ll see a “What’s New for the app” in the Play Store or in-app details on an application’s website. Some apps provide Day 0 support, while others update over time. Ensure your users' managed apps that are deployed through Intune have been updated to a version that supports Android P. If you run into anything else in your testing, do let us know!


Azure File-Sync

$
0
0

Azure File Sync ya fue liberado a producción.

 

Hola.

Con mucha frecuencia escuchamos la necesidad de migrar el almacenamiento de los servidores de archivos hacia la nube, conservando los permisos de accesos, ahora esto ya es posible con Azure File Sync que ya esta liberado y en producción.

Azure File Sync replica los archivos de su servidor Windows en sitio hacia un área de datos compartidos en Azure (Azure File Share). Ya no necesitamos escoger entre los beneficios del almacenamiento en la nube y los del servidor en sitio, podemos tener ambos.

Sabemos que los servidores de archivos se utilizan para todas las áreas de la empresa, con Azure Files, nos enfocamos en crear carpetas compartidas que puedan reemplazar o complementar los servidores de archivos y las NAS de su empresa.

Azure File Sync replica los archivos de su servidor Windows en sitio hacia una carpeta compartida de Azure de la misma manera que lo haría DFS-R para replicar entre servidores locales. Una vez que se tiene la copia de sus datos en Azure, habilitamos la capa en la nube (Cloud tiering) que es la verdadera magia de Azure File Sync, almacenamos únicamente la información de acceso mas reciente en sitio, y ya que la nube tiene una copia completa de sus datos, puede conectar cuantos servidores necesite a su área de datos en Azure, permitiéndole establecer “caches” de su información donde quiera que los necesite. Como mencionamos, en términos sencillos, Azure File Sync habilita la centralización de su servicio de archivos en Azure manteniendo los permisos de acceso a los mismos.

 

Al tener una copia de sus datos en la nube, usted tiene ilimitadas posibilidades, por ejemplo, si un servidor se daña, se puede recuperar rápidamente, no importa lo que le pase al servidor, una actualización, disco dañado, etc., estamos tranquilos sabiendo que la nube tiene la información, simplemente conectamos un servidor Windows nuevo al grupo existente de sincronización, y el espacio será reconocido y listo para usar.

 

La liberación de Azure File Sync es solo el comienzo de las innovaciones, durante el verano y otoño se agregarán una nueva serie de mejoras, ¡incluyendo soporte para una mejor integración con Windows Server 2019!

 

 

Para la documentación completa de implementación, favor de ir al enlace:

Planning for an Azure File Sync deployment

https://docs.microsoft.com/en-us/azure/storage/files/storage-sync-files-planning

 

 

Gracias y esperamos que sea de su agrado.

Saludos

Mariano Carro

Enviar correo a latampts

 

 

PowerShell and DNS Reverse Lookup Zones

$
0
0

Welcome back! I know you've missed me

Today, I wanted to talk about PowerShell and DNS. I have a customer who is looking to clean up records which have grown out of control over the years. This customer has many reverse lookup zones, like any company which has various offices throughout the world. They were looking for a way to use PowerShell to pull all the old records, so they could verify them before going in and deleting the records.

Oh, and before we get too much further into this, there is some code being used in this project, so…

*DISCLAIMER*

This Sample Code is provided for illustration purposes only and is not intended to be used in a production environment. THIS SAMPLE CODE AND ANY RELATED INFORMATION ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND/OR FITNESS FOR A PARTICULAR PURPOSE. We grant You a nonexclusive, royalty-free right to use and modify the Sample Code and to reproduce and distribute the object code form of the Sample Code, provided that You agree: (i) to not use Our name, logo, or trademarks to market Your software product in which the Sample Code is embedded; (ii) to include a valid copyright notice on Your software product in which the Sample Code is embedded; and (iii) to indemnify, hold harmless, and defend Us and Our suppliers from and against any claims or lawsuits, including attorneys' fees, that arise or result from the use or distribution of the Sample Code.

Moving on!

This customer did not have scavenging turned on, which is not uncommon, but would have prevented the need to clean up mismatching and old records from happening. Scavenging is a setting on Windows DNS servers which will clean out records if the servers have not checked in after a specific length of time. Here's a blog on how to configure it through the GUI. That blog is a little old, so here's the setting on a Windows Server 2012 R2, being set at the zone level:

 

But that's not the point of this post! The point is, we needed to get a list of all the records, exported in a way that would be easy for us to understand and manipulate.

I found this article in the Microsoft scriptcenter, which was a great starting point, and did almost everything the customer needed. My first step was to get the data where we could read it. This script did that, and pretty much nothing else ;p

A few quick notes:

  • all the DNS PowerShell commands require an Administrator PowerShell prompt. Failure to do so will get you a Permission Denied error.
  • You must have the DnsServer module loaded to get these commands to work
  • I've been using PowerShell version 4 on Windows Server 2012 R2

 

#Get all the records

$records
=
Get-DnsServerResourceRecord
-ZoneName
contoso.com
-RRtype
A

 

#Filter out dynamic records

$records
=
$records
|
where
Timestamp
-ne
$null

 

#Filter out records with Timestamp newer than 1/1/2018

$records
=
$records
|
where
Timestamp
-le
1/1/2018
|
Out-GridView

 

#Get reverse zone

$reverse
=
Get-DnsServerResourceRecord
-ZoneName
10.168.192.in-addr.arpa
-RRtype
PTR

 

#Filter out dynamic records

$reverse
=
$reverse
|
where
Timestamp
-ne
$null

 

#Filter out records with Timestamp newer than 1/1/2018

$reverse= $reverse
|
where
Timestamp
-le
1/1/2018
|
Out-GridView

 

 

After taking a short break, we decided that what we really needed was to get all the reverse lookup zones, without having to call them one by one. That should be easy, we should just be able to pull all the zones into a variable and then a foreach loop and export it out. Easy peasy!

Should is such a great word.

First objective was to get just the reverse lookup zones. I knew I was going to need to use the Get-DnsServerZone cmdlet, but exactly how was I going to get just the reverse zones, and all of them?

A little poking around and a little trial and error bought me to pull this command, putting all the reverse lookup zones into a variable ($revZones):

$revZones
= (Get-DnsServerZone
|
Where-Object {$_.isReverseLookupZone -eq $true}).ZoneName

 

Test lab output:

That's exactly what I want to see. Now, I only need to throw this into a foreach loop and we'll be golden. Here's my first try at a loop:

foreach ($zone
in
$revZones){


$records
=
Get-DnsServerResourceRecord
-ZoneName
$zone


$list
+=
$records

 

}

That's full of a lot of stuff I'm not interested in, so a small adjustment of adding -RRType
Ptr

will get me just the records I want.

Much better output:

Now I'm going to just send it all to Out-GridView and we should be good. I chose Out-GridView because I wanted a quick view of my output in something that I could manipulate and export if I wanted to. Eventually we'll push the data to a .csv file.

 

foreach ($zone
in
$revZones){


$records
=
Get-DnsServerResourceRecord
-ZoneName
$zone
-RRType
Ptr


$list
+=
$records

}

$list
|
Out-GridView

 

Output:

Almost what I'm looking for. That HostName is not enough information though. You can see several of my servers have the same HostName, but are clearly not the same server. What's missing here is the rest of the address. As they're all in different reverse lookup zones, I need to be able to see that here, or the data is useless. In addition to not having all the information I need, it's got more than I care for as well. I filter on PTR records, so I don't need the record type, and for my purposes now I don't really need TimeToLive either.

So, I do a select
*
and pull up all the possible data that I can choose from.

It looks like I want DistinguishedName to pull the full IP address, but now I see something else weird.

Look at the two RecordData columns. What just happened?

That's definitely not what I'm looking for. I need my server names! Since they showed up there once, I know they're in there somewhere, I just need to find them. Let's take a look at all RecordData has to offer.

Sounds like PSComputerName might be what we're looking for. Let's grab that value, and just the few other things we want for our final output and see what we get.

 

Nope! RecordData is blank! Time to try again. Perhaps the PtrDomainName will give us the information we're looking for.

There we go! Just what I was looking for!

Last thing to be done is to export it to a .csv file and we're all set. For my testing I use -NoTypeInformation
and
-Force
to remove the first line of type information from the file and to overwrite the file. I tend to run lots of tests before I'm finally happy with my results and changing the name each time or getting an error because the file already exists from my previous testing, and that annoys me. When I'm satisfied with the result, I won't want to overwrite the file, but for testing I prefer to blast through files as needed.

Here's the final script and a sample of the .csv file.

$list
=
$null

 

# retrieve all Reverse Lookup Zones

$revZones
= (Get-DnsServerZone
|
Where-Object {$_.isReverseLookupZone -eq $true}).ZoneName

 

# retrieve all PTR records from zones

foreach ($zone
in
$revZones){


$records
=
Get-DnsServerResourceRecord
-ZoneName
$zone
-RRType
Ptr
|
Select
DistinguishedName, Timestamp,@{name='RecordData';Expression={$_.RecordData.PtrDomainName}}


$list
+=
$records

 

}

 

# Export the compiled list

$list
|
Out-GridView

$list
|
Export-Csv
-Path
"C:userstestadminDesktopzones.csv"
-NoTypeInformation

 

 

Output:

 

That's it for now! I'll be working to refine this more, cleaning up the data a little, and doing a compare against forward lookup zones. That one will take a bit longer, but I'm it will be an adventure!

 

 

 

SharePoint: SAML Authentication – Nested Groups and Role Claims

$
0
0

I came across this topic troubleshooting a support case where users were getting Access Denied to a site using Trusted Provider (SAML) authentication.

The Issue:

Users were given permission to the site using a group that had other groups nested in it. The users were not direct members of the group being used for permission. For example:

ContosoLevel1 – Users are direct members of this group.

ContosoLevel2 – No users in this group, only the "Level1" group and some other groups. This is the group used in SharePoint site permissions.

So we got a Fiddler trace of the user logging in via SAML auth and found that their SAML assertion only contained Role claims for the "Level1" group, and not the "Level2" groups. If your SAML assertion does not contain a certain group, then SharePoint does not believe you are a member of that group, and you will not get any permission that has been assigned to that group within SharePoint.

Research:

In my research, I wasn't finding any definitive answers about whether or not nested groups should typically be part of a users Role claims, so I tested it. Short answer: it depends on which attribute you have mapped to your Role claim in your Relying Party Trust.

Testing:

I tested this in my lab with Active Directory Federation Services (AD FS) as my Trusted Provider, and found that as long as I was using the standard "Token-Groups" attributes mapped to "Role" in my claim rules, all groups, including nested groups showed in my SAML assertion.

Upon further investigation, I found that in my customers case, they were not using ADFS. They were using a 3rd-party trusted provider that was using the "MemberOf" Active Directory attribute to map to the Role claim. The problem with that is the MemberOf AD attribute only contains groups the user is a direct member of.

 

The Fix:

Either change the claims mappings for Role to use the Token-Groups attribute, or only use groups in site permissions that users are direct members of.

Streamline business management with the NEW Business Central technical journey

$
0
0

How can you make smarter business decisions? By leveraging Dynamics 365 Business Central – the all-in-one business management solution that connects finance, operations, customer service, supply chain and project management into one end-to-end view. Start building your Dynamics 365 Business Central practice today by leveraging the new interactive technical webinars and one-to-one technical consultations now available!

New webinars & consultations:

Adopting Dynamics 365 Business Central Feature Update Series (no cost for MPN partners; L200)  

  • Upcoming webinars (English):
  • Key outcomes: Learn about the latest features and updates that have been released for Dynamics 365 Business Central and dive deeper into specific technical capabilities. This webinar will build upon the information presented during “What is New in Business Applications” and focus exclusively on Dynamics 365 Business Central topics.

Dynamics 365 Business Central Starter Kit Consultation (cost 5 partner advisory hours; L100)

  • Key outcomes: Understand the capabilities and advantages of Dynamics 365 Business Central from a Microsoft Partner Technical Consultant, helping you sell and deploy solutions more effectively. Designed for partners who are new to Dynamics 365 Business Central, this consultation will help you to expand your technical skillset by covering topics such as licensing, feature overviews, product demos, and integration.

 

Explore the full Business Central technical journey, to leverage the entire suite of webinars and consultations available at aka.ms/BusinessCentralTechJourney.    

SQL Tip: Multi Server queries

$
0
0

My coworkers ask me from time to time to "do that magical thing you do" and then ask me to share with them how to do it. I have showed it several times...so now I'm going to blog it for reference. 🙂

That "magical" thing I do is pretty simple and stems from me being lazy. If I want to get some information from multiple servers rather than connect to each server and run the query separately, I use multi server queries to query all of them at the same time. I have some reports that use linked servers to accomplish similar functionality but if I'm just issuing a query from SSMS then building the linked server query is more work than it's worth. Again, I'm lazy and that sounds like too much work. So how do you run a multi server query? It's really simple and easy - you need to use "Registered Servers". (You could use a "Central Management Server" but let's assume that you're not the DBA who can make that happen). And, even if you're not going to use multi server queries, if you're not using Registered Servers hopefully this tip will help you start using it - it's a great feature of SSMS.

This isn't intended to be a 'how-to' on Registered Servers, but in case you're not aware of it I'll get a couple basics out there to help you be able to follow along with the real point of this post. If you don't already see "Registered Servers" when you open SSMS, go to the "View" menu and choose "Registered Servers". Now that you have it you can dock it wherever you like - I personally like to have it docked with "Object Explorer" so that they are tabs. That's it; now you're up to speed. 🙂 Here's a link to a quick summary of "Registered Servers". Basically, it's a great way to manage all your server connections. Do it.

Now, if you haven't already done so, you'll need to create some server groups and/or registrations. It's pretty simple to add these via the UI, or...you can use a PowerShell script I wrote that will create groups and servers from txt or csv files (if you want to be able to do it really quickly). I wrote another blog on this script here.

Once you have at least one group created with more than one server, you can simply right click on the group and choose "New Query". This will open a query window that will connect to each server in the group, and you can query each server in one shot! You'll also notice that the status bar for the query window will be a different color. You can determine the color in "Tools"-->"Options"-->"Text Editor"-->"Editor Tab and Status Bar"-->"Group connections". You can also manage the multi server query results in "Tools"-->"Options"-->"Query Results"-->"SQL Server"-->"Multiserver Results". I like to set "Merge results" and "Add server name to the results" to "True".

Something I haven't mentioned yet is that you're only going to see the databases that exist in all server instances you are connected to (i.e., if you try to change your database via the drop down):

So, if you're trying to query all your ConfigMgr (SCCM) databases, which have a different database name for each site, you're either going to have to make your query dynamic (to run against the correct database name) or be smarter about creating your server registrations. The easiest way to do this is to define the SCCM servers to connect to the CM database as the default database. If you do this, then when you choose "New Query" on the group you'll see "Multiple" in the name of the database you're connected to. That's exactly what you want:

You do that by specifying the "Connect to database" option under the "New Server Registration" "Connection Properties":

Let's say that I wanted to know what each SCCM site's "site range" was. I could open a new query against my "CM Virtual Names - CMDB" group (which connects to the specific CM database for each site) and run/get the following:

Or, let's say I have a group for all my SQL Servers and I wanted to know the compatibility level of the CM database (if there is one). I'd do this:

Whew, they're all the same except for the secondary sites. Oh, and running that example also reminded me that before you run your query you'll be able to see if you were able to connect to all the servers in the group. Sometimes you can't connect to all of them for some reason. You'll see this in the status bar:

And when you run your query you'll get some "errors" in the messages window:

Pretty sick right? I actually use this more often than you might think. Want to know the exact version of SQL running on your servers? Want to know a particular setting on each server? Create a group named "All SQL Servers" and you're able to do that really quickly and easily!

Creating Registered Servers in SSMS via PowerShell

$
0
0

I wrote a script that creates a "Registered Server" group and then a "Server Registration" for each of the servers found in a text or csv file. This comes in handy when you want to create lots of registrations (groups and/or servers).

Basically, to use the script, you create a file (txt or csv) for each group you want to add in "Registered Servers". The script can be run against a folder or a file, so if you want to create all groups at one time you can put all the files in one folder and the script will process each file in the folder. The name of the file is the name of the group you'll create, i.e., if I wanted to create a group named "ConfigMgr SQL Servers" I'd create a file named "ConfigMgr SQL Servers.txt" or "ConfigMgr SQL Servers.csv". Within this file I'd add a line for each server I want to add in the group, and then I could run the PowerShell script which would create the group and all the servers that were in the file.

In addition to the comments and examples in the script, let me try to explain the CSV file formats that are accepted by the script. The txt or csv file(s) must have at least a "SQL Server Name" in order for the script to work correctly. But, it can have additional properties as well as long as they follow this format: ServerName,DatabaseName,DisplayName,ConnectionString (or Connection String Options to add to the connection string). Perhaps the best way to do this is to show examples; here I created a csv file with some fake servers and named the file "Example Group For Blog.csv":

Next, I'll run the following command (notice that I'm using the "HasHeaderRow" flag because I do have a header row in the csv file):
& 'C:LocationWhereTheScriptIsStoredCreateSqlServerRegistrationsInSSMS.ps1' -Path "F:Example Group For Blog.csv" -HasHeaderRow

And, when I look in SSMS's "Registered Servers" I see:

You can see that each of the servers listed in the csv file was created within the group. And, to show the properties from the UI for each of the registered servers to help make sense of how the properties were used:

DisplayName: "My Azure Datawarehouse"

DisplayName: "MySqlServer1"

DisplayName: "MySqlServer2"

DisplayName: "MySqlServer4"

DisplayName: "The New XYZ Server"

Does that help explain without words? Hopefully. The rest of the functionality should be fairly well documented in the script comments itself, so please make sure to read those.

The blog platform seems to strip out the help comments when I try to paste the code directly in this blog using 'code' blocks so here is a OneDrive link to the script. And, here's a link to the OneDrive folder which contains the script as well as the example csv for reference.

If you find any issues or have some improvements please let me know (and share the updated script!) :).

Wiki Life: Are you aware about TechNet Guru Awards

$
0
0

Dear All,

Welcome to TechNet Wiki Life.

TechNet Guru Awards

In this blog post we will see in detail about what is TechNet Guru Awards and why an author should know about TechNet Guru Awards.

What is TechNet Guru Awards?

Each month the TechNet Wiki looks to recognize and celebrate the best of the best!

Is that you? Do you consider yourself an expert, or authority in the technology of your choice?

You don't actually have to be an expert of your chosen technology.  All you need is one subject or a technique which may be interesting/useful.

It could be a solution to a particularly tricky problem or an interesting answer to a forum's tricky question or anything worth writing an article about.

It could be a set of techniques solving one problem or one technique which can be used in a number of different scenarios. It should be something original and interesting.

Whatever it is, check up on how a TechNet Wiki is expected to be written and formatted and craft your masterpiece.

This is an official Microsoft TechNet recognition program, where people such as yourself can get the recognition they deserve for the time given to the community.

If you spend any amount of time crafting an awesome answer to a forum question, then why not get the most back for your efforts by posting it to the TechNet Wiki?

Become MICROSOFT TECHNOLOGY GURU OF THE MONTH!

To know more about what is What is Competition is About read from here TechNet Guru Monthly Article Competitions

Why an author should know about TechNet Guru Awards

Authors can nominate their article by categories. For example, if an author has published an article related to C# for the current month, then the author himself nominate his/her article to the category Visual C#.

Each month Winners will be selected by category and awarded with

  • Gold Medal
  • Silver Medal
  • Bronze Medal

 The List of Technology available for adding monthly Guru Awards

  • ASP.NET
  • Microsoft Azure
  • BizTalk
  • Forefront Identity Manager
  • SharePoint 2010 / 2013
  • Small Basic
  • SQL BI & Power BI
  • SQL Server General & Database Engine
  • System Center
  • Transact-SQL
  • Universal Windows Apps
  • Visual Basic
  • Visual C#
  • Windows PowerShell
  • Windows Presentation Foundation (WPF)
  • Windows Server
  • Wiki and Portals
  • Miscellaneous

Note: If your Technology is not listed here means then you can add your article entry under Miscellaneous category. Hope you all know as in TechNet Wiki we can publish only Microsoft related technologies. Only current month article can be added for the competition.

Every month authors need to add their published article entry by them self to the competition. If you didn’t add your article entry for the TechNet Wiki Guru competition then you might lose the monthly awards.

Another important part of the winners are comments made by the judges. Yes, set of Microsoft employee or the Microsoft MVP’s per each category will review all the article entered for the competition and the judges will select the article for gold/silver and bronze award based on the article quality, articles which fulfill the TechNet Wiki rules and format. TechNet Wiki judges are best of best as all of them are Microsoft employee or the Microsoft MVP’s and they will give very valuable feedback and golden words to encourage the entire winning author. If required judges also guide the authors on how to improve their article quality and format to make more better for the community.

Simple steps to add your article to TechNet competition

Every month authors by themselves need to add their article entry to the competition. many friends have asked me as from where they can find each month article competition page to add their article entry.

The best and simple way to find the monthly Guru Awards competition page is

Go to the TechNet Wiki home page

At the bottom of right side menu under Engage you can find the link as TechNet Guru Awards click on that link to open the TechNet Guru Awards 

In the TechNet Guru Awards page, we can see both the Past and Current month competition page as well the past month Winners announcement pages.

Past and Present Month Competition.

Each month first day, TechNet wiki Council members will update this page with Current month competition page. Click on the current month to add your article entry on your favorite Microsoft Technology. For example, here we can see as I have added my article entry for August 2018 month under ASP.NET Category. We can add our article entry by adding our article link along with our MSDN profile link.

Once we add our article entry to the monthly competition our part of work will be completed and the next part will be by the Judges as they will pick the best article and announce the winners in TechNet Wiki Ninja blogs website

Past Month Winners page link.

We can also find all the past month winners announcement page links from the TechNet Guru Awards  page. Each month end the winners will be announced per category by the TechNet Wiki council members.

For example, we can see my article won the Gold medal under ASP.Net Category for June 2018 month.

We can see all the golden words used by the judges ,by adding our article to the TechNet Wiki competitions we not only get the awards also we will  mark our article in history as the winners page will be published each month in TechNet Wiki Ninja blogs website ,even our grandson can see this link in future and proudly tell to their friends as my grandfather was TechNet Wiki Guru and he has won several Gold/Silver and Bronze awards in TechNet Wiki monthly competition’s .If you didn’t add your article entry to TechNet Wiki Guru then its time to start adding your article in competition page’s.

See you all soon in another blog post.


Thank you all.

tnwlogo_3

Yours,
Syed Shanu
MSDN Profile | MVP Profile | Facebook | Twitter |
TechNet Wiki the community where we all join hands to share Microsoft-related information.


Azure ポータルで Managed Disks への移行が可能に

$
0
0

執筆者: Kay Singh (Senior Program Manager, Azure Compute)

このポストは、2018 8 2 日に投稿された Managed Disks migration now available in the Azure Portal の翻訳です。

 

Azure ポータルで Unmanaged Disks VM Managed Disks に変換する機能をリリースいたしました。これにより、PowerShell CLI スクリプトを使用しなくても、ワンクリックで移行できるようになります。

Azure Managed Disks は、リリース以来高い評価を得ており、既に多くのお客様に導入いただいています。まだ使用されたことのないお客様のために、すべての機能をまとめてご紹介します。ぜひご検討ください。

  • ストレージ アカウントの制限を気にせずにアプリケーションをスケーリング
  • 障害ドメインの整合性により、コンピューティングおよびストレージ リソース全体の高可用性を実現
  • 最大 1,000 個のインスタンスを含む VM Scale Sets を作成
  • ディスク、スナップショット、イメージを優先リソースとしてアーキテクチャに統合
  • Azure RBAC (ロールベースのアクセス制御) によってディスク、スナップショット、イメージを保護

Managed Disks のさらなるメリットについては、「Azure Managed Disks の概要」をご覧ください。

 

Azure ポータルでの Managed Disks への移行

Azure ポータル内での移行は非常に簡単です。手順は以下のとおりです。

Unmanaged Disks VM を使用している場合は、VM の概要ブレードに情報バナーが表示されます。

vm1

バナーをクリックすると、移行ブレードが起動します。

vm2

: VM が可用性セットに含まれている場合は、先に可用性セットを移行するように促すメッセージが表示されます。

移行が開始されると、以下のスクリーンショットのように、移行ステータスを確認することができます。

vm3a

[Resource Group] ビューに戻ると、追加の Disk リソースが表示されます。VM にアタッチされた OS およびデータ ディスクごとに 1 つのディスクが表示されます。

vm4

サイド バーの [Disks] をクリックして、VM のディスクの詳細を表示することもできます。

vm5

 

移行の自動化

マネージド ディスクへの移行を自動化する場合は、以下の手順をご確認ください。

 

Azure Reserved Virtual Machine Instances のインスタンス サイズの柔軟性の一般提供

$
0
0

執筆者: Manish Shukla (Program Manager, Microsoft Azure)

このポストは、2018 年 8 月 3 日に投稿された General availability of instance size flexibility for Azure Reserved Virtual Machine Instances の翻訳です。

 

今回のブログ記事は、Microsoft Azure の主任エンジニアリング マネージャーを務める Arabinda Mohapatra と共同で執筆しました。

このたび、Azure Reserved Virtual Machine Instances のインスタンス サイズの柔軟性をご利用いただけるようになりました。これは、Reserved Instances (RI) の購入と管理を簡素化する新しい機能で、同じ VM グループ (英語) 内の他のサイズの VM に RI 割引を適用することができます。

この機能を利用すると、同じ VM グループ内の他の VM サイズに RI 割引を適用できるため、Azure RI のメリットを得るために、わざわざ同じサイズの VM をデプロイする必要はありません。

たとえば、以下のような VM グループで利用することができます。

VM VM グループ 比率
Standard_D2s_v3 DSv3 Series 1
Standard_D4s_v3 DSv3 Series 2
Standard_D8s_v3 DSv3 Series 4
Standard_D16s_v3 DSv3 Series 8
Standard_D32s_v3 DSv3 Series 16
Standard_D64s_v3 DSv3 Series 32

D2s_v3 VM の Azure Reserved Instances を 1 つ購入した場合、同一リージョン内の VM Instances には、以下の比率で RI の割引を適用することができます。

  1. 1 Standard_D2S_v3
  2. 1/2 Standard_D4s_v3
  3. 1/4 Standard_D8s_v3
  4. 1/8 Standard_D16s_v3
  5. 1/16 Standard_D32s_v3
  6. 1/32 Standard_D64s_v3

Azure Reserved Instances のシンプルさにインスタンス サイズの柔軟性が加わることで、Windows Server、Linux、RHEL などのオペレーティング システムに関係なく、VM のインフラストラクチャ コストと Azure Reserved Instances の両方のメリットを得られるようになります。VM で追加のソフトウェアを実行している場合、ソフトウェアの料金のみが請求されます。

既存の Azure Reserved Instances のスコープが共有になっている場合、インスタンス サイズの柔軟性は既定で有効になります。単一のスコープを設定している場合は、RI の設定からインスタンス サイズの柔軟性を有効にします。Azure Reserved Instances のスコープを変更する方法については、こちらのドキュメントをご覧ください。

次のステップ

ご利用を開始する際には、まずこちらのドキュメント (英語) をお読みいただき、単一スコープの Reserved Instances のインスタンス サイズの柔軟性オプションを切り替える方法をご確認ください。

 

Active Directory サーバーでシステム状態のバックアップに失敗する

$
0
0

こんにちは。日本マイクロソフト株式会社 高谷 です。

最近、Active Directory サーバーにおいて、Windows Server バックアップで “システム状態” のバックアップをとろうとすると失敗する、というお問い合わせを複数のお客様からいただきましたが、多くのケースで vsock.sys (VMWare製)ドライバーの ImagePath が不正な値になっていることが原因であることが確認できました。

この事例に当てはまる場合、ユーザー様にて比較的簡単に修復ができますので、原因と対処方法についてご紹介したいと思います。
この事例に当てはまるかご確認いただき、当てはまる場合は修復方法をお試し下さい。
.

■ 事象の確認ポイント

.
確認ポイント (1)  環境の確認

お客様の環境は以下に当てはまりますか?

.....・VMWare 環境である。(物理サーバーおよび Hyper-V 仮想環境では事象は確認されておりません。)

.....・OS は Windows Server 2012 R2もしくは Windows Server 2016 である。

.....・Active Directory の役割を担っている。

.
確認ポイント (2)  バックアップのログの確認

エラーのログが以下のパスに作成されていますか?

.....パス:C:WindowsLogsWindowsServerBackupBackup_Error-dd-mm-yyyy_xx-xx-xx.log

▽ Backup ログに記録されるエラーの内容
----------------------------------------------------------------------------------------------
C:windows\systemroot のバックアップで列挙中にエラーが発生しました: エラー [0x8007007b]
ファイル名、ディレクトリ名、またはボリューム ラベルの構文が間違っています。
----------------------------------------------------------------------------------------------

.
確認ポイント (3)  イベント ログの確認

アプリケーションのイベント ログには、以下のログが記録されていますか?

▽ アプリケーションのイベント ログに記録されるエラーのイベント
----------------------------------------------------------------------------------------------
レベル:エラー
イベントソース:Backup
イベント ID:517
メッセージ:'‎YYYY‎-‎MM‎-‎DDT09:00:43.533016300Z' に開始したバックアップ操作は、次のエラー コード '0x80780049' (バックアップに含まれるいずれの項目もバックアップされませんでした。) のため失敗しました。
イベントの詳細で解決策を確認し、問題の解決後にバックアップ操作を再実行してください。
----------------------------------------------------------------------------------------------

上記 3 点が全て当てはまる場合、この事例に合致する可能性が高いですので、次の項の修復方法をお試しください。
.

■ 修復方法

.
vsock.sys ドライバーの ImagePath のパス情報の SystemRoot を削除することで改善します。

// 修正手順

  1. [スタート] > [ファイル名を指定して実行] > regedit と入力してレジストリ エディターを起動します。
  2. 以下のパスの階層を展開します。

..........HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Services > vsock

  1. ImagePath の値を右クリック > 修正 をクリックし以下のように変更します。

..........---------------------------------------------------------------------
..........変更前:
..........SystemRootsystem32DRIVERSvsock.sys

..........変更後:
..........system32DRIVERSvsock.sys
..........---------------------------------------------------------------------

..........※ 変更内容は SystemRoot を削除するのみです。

  1. レジストリ エディターを終了し再起動を実施します。

..........以上で作業は完了です。

なお、上記のレジストリの変更作業が、Active Directory の機能も含めてシステムへ影響を与えた報告はございませんので、ご安心ください。
.

■ 原因

.
バックアップ取得の要求が発生すると、まず静止点の確保のために、各種 VSS Writer がそれぞれの管轄するモジュールの列挙を行います。列挙が正常に完了して初めて静止点の確保が行われ、バックアップが取得される流れとなります。

今回の事象は、VSS Writer の一つである System Writer が、自身が管轄するモジュールの一つである vsock.sysの列挙に失敗したことで、バックアップ取得に失敗しています。

さらに、vsock.sys の列挙に失敗した理由としては、vsock.sys の ImagePath の情報が正しくないことが原因です。

通常、各ドライバーの情報は、ドライバーのインストール時にレジストリに保存されており、この情報の一つである ImagePath に正しくない値が入力されていることにより、列挙に失敗します。

そのため、ImagePath の値を正しい値に修正すれば今回の事象は改善します。

▽ vsock.sys の ImagePath の情報
---------------------------------------------------------------------
誤:SystemRootsystem32DRIVERSvsock.sys

正:system32DRIVERSvsock.sys
---------------------------------------------------------------------

(参考) vsock.sys とは?
vscok.sys は VMWare 様の提供する VMWare Tools のドライバーです。
以下に VMWare 様の公開情報ページを掲載します。

.
VMWare 様 公開情報)
“VMware Tools デバイス ドライバ”
https://pubs.vmware.com/vsphere-50/index.jsp?topic=%2Fcom.vmware.vmtools.install.doc%2FGUID-6994A5F9-B62B-4BF1-99D8-E325874A4C7A.html

なお、VMWare 様の公開質問ページにて、この事象が取り上げられておりました。

.
VMWare 様公開情報)
“Unable to backup Windows AD Server with VMware Tools installed”
https://communities.vmware.com/thread/565599

いかがでしたでしょうか。
本ブログが少しでも皆様のお役に立てますと幸いです。

Key takeaways from Microsoft Inspire 2018

$
0
0

Microsoft Inspire 2018 provided an unprecedented opportunity for partners to make meaningful connections with even more of the Microsoft community. As we kicked off our fiscal year together, it was more apparent than ever that partnership is the key to staking a claim on $1.7 trillion of digital transformation opportunity in the U.S.

Speakers included partners, business leaders, and Microsoft executives like Gavriella Schuster, Brad Smith, Ron Markezich, and CEO Satya Nadella. Our partner ecosystem is strong and growing, having built more than 28,000 applications, services, and solutions with partners in the last year. With that success and momentum in mind, here are some of the key takeaways from Microsoft Inspire 2018:

Leaning into marketplaces and growing capabilities

We were proud to announce efforts to enhance AppSource by making even more resources available to partners, customers, and our sales team. Azure Marketplace is your one place for everything from finished apps and partner-to-partner bundles to managed services. This online store can be used to increase discoverability and app usage, drive more leads, and promote your solutions. MPN Partners have access to a Microsoft Marketplaces consultation at no cost from now through December 21, 2018.

Enhancing Go-to-Market benefits

Go-to-Market connects what we build with how we sell—together—and we’re not only expanding core benefits but offering more flexible benefits packages. New benefits will guide partners through building their marketing practice and support them in generating leads, improving lead velocity, and boosting close rates. Partners can also choose the benefits package that aligns to your business focus, whether that’s Modern Workplace, Biz Apps, Data & AI, or Apps & Infrastructure. Stay tuned for more details at partner.microsoft.com or through our upcoming MPN 101 calls, to review benefits in-depth.

Supporting partner development

Differentiating your offerings is key to partner success, which is why we’re launching the Microsoft Azure Expert MSP initiative as well as offering new areas of specializations and competencies. The Microsoft Azure Expert MSP qualification gives customers confidence when selecting a partner to help them on their digital transformation journey by vouching for your highest degrees of capability. In FY19, we’ll be launching advanced areas of specialization beyond Microsoft Gold competency, including: Modern Workplace (GDPR, Teams), Biz Apps with Dynamics 365, Azure Stack, Cloud Migration, and Data & AI (machine learning, cognitive services). To improve the resources available to our partners, there are also 4 new Digital Transformation eBooks and 2 Cloud Practice Playbooks upcoming.

For more in-depth info and highlights from Microsoft Inspire, watch our recap on-demand. Then, head over to our MPN page to get plugged in, and follow @msuspartner for the latest updates.

For more info and ways to stay connected, check out our additional resources below:

Breaking Into Windows Server 2019: Network Features: Software Defined Networking (SDN)

$
0
0

Happy Wednesday to all of our great readers! Brandon Wilson here once again to give yet another pointer to some more outstanding content/information from the Windows Core Networking team on the Top 10 networking features in Windows Server 2019. This time around, they are covering some of the new Software Defined Networking (SDN) capabilities in Windows Server 2019, and its an excellent read in my humble opinion, but don't take my word for it! Here is some initial information straight from the product group:

"This week, the Windows Core Networking team continues their Top 10 Networking features in Windows Server 2019 blog series with: #7 - SDN Goes Mainstream

Each blog contains a "Try it out" section so be sure to grab the latest Insider's build and give them some feedback!

Here's an Excerpt:

If you've ever deployed Software Defined Networking (SDN), you know it provides great power but is historically difficult to deploy. Now, with Windows Server 2019, it's easy to deploy and manage through a new deployment UI and Windows Admin Center extension that will enable anyone to harness the power of SDN.  Even better, these improvements also apply to SDN in Windows Server 2016!

"

As always, if you have comments or questions on the post, your most direct path for questions will be in the link above.

Thanks for reading, and we'll see you again soon!

Brandon Wilson

Viewing all 36188 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>