Quantcast
Channel: TechNet Blogs
Viewing all 36188 articles
Browse latest View live

Azure Storage Explorer で AzCopy のサポートのパブリック プレビューを開始

$
0
0

執筆者: Catherine Wang (Visual Studio 担当プログラム マネージャー)

このポストは、2019 3 12 日に投稿された AzCopy support in Azure Storage Explorer now available in public preview の翻訳です。

 

Azure Storage Explorer で AzCopy のパブリック プレビューが開始されました。AzCopy は、ストレージ アカウントとのデータ転送のパフォーマンスを向上させる人気の高いコマンドライン ユーティリティです。AzCopy の新しいバージョンでは、マシンの論理コアの数に応じて同時実行をスケールアップするスケーラブルな設計によって、パフォーマンスと信頼性がさらに強化されました。ツールの回復性も、再試行を繰り返すことによって向上しています。

Azure Storage Explorer では、さまざまなストレージ タスクに対応する UI インターフェイスが提供されています。今回、AzCopy を転送エンジンとして使用して、Azure Storage とのファイル転送のスループットを最大限に高められるようになりました。この機能は現在、Azure Storage Explorer でプレビューとしてご利用いただけます。

BLOB のアップロード/ダウンロードに対して AzCopy を有効化

データ転送のパフォーマンスが非常に重要であると、これまで多くのお客様からご指摘いただいてきました。Azure にファイルが転送されるまで待っているのは、はっきり言って時間の無駄です。Azure Storage Explorer AzCopy を使用すれば、その時間を有効活用できます。

AzCopy のプレビューを使用すると、BLOB 操作がこれまでよりも高速になります。このオプションを有効にするには、[Preview] メニューで [Use AzCopy for improved Blob Upload and Download] を選択します。

現在、Azure Files BLOB の一括削除のサポートに取り組んでいます。他にもサポートしてほしい機能がありましたら、GitHub リポジトリ (英語) からご要望をお聞かせください。

 

Enable AzCopy in Azure Storage Explorer

1: Azure Storage Explorer での AzCopy の有効化

実際の速度

自社環境で簡単なテストを実施したところ、Azure Storage Explorer AzCopy を使用すると、ファイルのアップロード時間が大幅に短縮されました。ただし、この時間はマシンによって異なります。

Storage Explorer Storage Explorer + AzCopy 10 向上率
100 KB ファイル x 10,000 1 時間 36 59 秒 98.9 %
100 MB ファイル x 100 5 分 12 1 分 35 69.5 %
10 GB ファイル x 1 3 分 41 1 分 40 54.7 %

2: BLOB のアップロード/ダウンロードの転送エンジンとして AzCopy を使用した場合のパフォーマンス向上率

 

AzCopy uploads and downloads blobs efficiently 1 x 10GB files

3: AzCopy による BLOB の効率的なアップロード/ダウンロード (10 GB ファイル x 1)

 

 

AzCopy uploads and downloads blobs efficiently 10,000 x 10KB files

4: AzCopy による BLOB の効率的なアップロード/ダウンロード (10 KB ファイル x 10,000)

次のステップ

ぜひ Azure Storage Explorer AzCopy 機能のプレビューをお試しください。皆様からのフィードバックをお待ちしています。問題を発見した場合や、機能に関するご提案がある場合は、GitHub リポジトリ (英語) Issue を作成してください。


医療業界での Microsoft AI 事例: データと AI を活用し、がんと闘うヨーロッパの臨床医と患者

$
0
0

マイクロソフトレポーター

2019 年 月 

 

将来有望な俳優、ファビアン・ボリンが白血病に罹ったことがわかったのは、彼がちょうど 28 歳のときでした。がんの診断結果が彼の将来を暗くさせ、彼は何もやる気がおきませんでした。

 

このような気持ちは、多くのがん患者に共通しています。

 

毎年、ヨーロッパでは推定 370 万の新しいがんの症例が発見され、190 万人ががんによって死亡しています。世界保健機関によると、ヨーロッパの人口は全世界の 8 分の 1 しかないにもかかわらず、世界のがん患者の 1/4 を占めています。実際には、がんは心血管系副作用を含めると死因の第 2 位になっています。

 

ヨーロッパは世界最高の、最も確立された医療システムを有していますが、がんは未だに手ごわい相手のままです。現在、大手医療機関や組織は、人工知能 (AI) などの技術を活用して患者への関与とサポートを行い、医師と協力して研究を促進させています。病気を管理し克服するために、一歩ずつ前進しているのです。

 

患者に力を取り戻す

ファビアンが最初にがんと診断されたとき、自分の無力を感じソーシャルメディアで自身の経験を共有し始めました。周囲からの反応は非常によく、がん患者やその親類のためのソーシャルネットワーク WarOnCancer を立ち上げることになりました。


左から: ファビアン・ボリン (WarOnCancer)、マティアス・エクマン(Microsoft)、ノラ・ バベイ (UNITECH)、セバスチャン・ハームリン(WarOnCancer)

40 種類のがんに対して 150 人の強力なブログコミュニティで構成された、オリジナルのプラットフォームが、ほとんどのがん患者は自尊心が低くなり、うつ病に苦しむという事実を明らかにしました。この洞察をもとに、WarOnCancer は、製薬および幅広いライフサイエンス業界の 6 つのパートナーと協業して、がん患者のためのグローバルなソーシャルネットワークを目指しながら新しいモバイルアプリを開発/テストしています。

 

2019 年中にリリース予定のこのアプリは、会員が自分のデータを共有し、業界が研究のためにどのようにこのデータを使用しているかを確認することができます。Microsoft Azure の機能を通じて、WarOnCancer はデータを分析して、患者のさまざまなグループが経験する問題点や利点を、どこで、どのように扱われているか分かるようになっています。

 

「私の治療中に専門家と話していたとき、治験の基準を満たす患者を見つけることが難しいために、腫瘍学の臨床試験のほぼ半数が遅延していることがわかり、驚きました」と、ファビアンは語ります。「患者の大半が、臨床試験のためにデータを共有することを望んでいるにもかかわらず、多くの人は、これらが行われていることを知らないか、データがどのように使用されるかきちんと知らされません。これは文字通り、救命処置を見つけることができるかどうか、という違いになります」

 

共同創設者兼 WarOnCancer 業界パートナーシップ代表であるセバスチャン・ハームリンは、「長期的な目標は、臨床試験と患者のための マッチングタイプのサービスを構築することです。これは成功した臨床試験の数を増加させ、 医薬品の研究開発の促進やがん患者のニーズに合わせた治療スケジュールや薬のカスタマイズだけでなく、最終的には患者の命を救うことになります」と続けました。

 

診察時の早期発見及び精度と正確性の向上をサポート

がんの早期発見の利点は、高い生存率をもたらすだけでなく、治療の副作用を最小限に抑えることができます。そのプロセスは、国によって異なりますが、標準的な乳がんスクリーニングは、通常 2 年ごとに検診をし、特定の年齢層では、マンモグラフィ検査を伴います。

 

しかし、乳腺組織が多く存在している乳腺濃度が高い乳房に対しては、マンモグラフィ検査の有効性が劇的に低下します。この課題に対処するために、Veneto Institute of Oncology (IOV) は、何百万もの人々を助ける可能性を秘めた Volpara 社の新しい乳房濃度評価ツールを使用しています。従来のマンモグラムの限界を越えたクラウドベースのソリューションが、患者の乳房組織のイメージを分析し乳腺濃度を検診します。


Volpara の新しいクラウドベースのツールは、患者の乳房組織の画像を評価して密度を計算します

 

Volpara 社の新しいクラウドベースツールは、その密度を計算するために患者の乳房組織の画像を評価します。「X 線では、密な乳房組織と腫瘍の両方が白くみえるため、乳腺濃度が高い胸を持つ女性のがんを検出することは困難です。さらに、乳房の密度が高い女性が、乳房の密度が低い女性と比較して乳がんを発症するリスクが高いことが証明されています」とベネチア腫瘍学研究所の医学物理学者、ジセラ・ジェンナーロは言います。「しかし現在、高度な画像解析により、女性の乳腺濃度を自動的かつ客観的に評価することができるようになり、そのシステムは乳がんの発病リスクを見積もることにも使われています。乳房密度に隠れているがんを見つけるイベントで超音波を使用するなどして、個別の画像解析による試験実施計画書を提供可能です」

 

「高度な画像解析技術なしでは、このような高速で精度の高い解析を実現することは不可能です。今後 5 年間で、1 万人以上の女性を調査する予定です。がんの検出率の増加、中間期がんの減少、そして持続可能な検査費用。これらは本当に高精度医療への第一歩です」と、ベネチア腫瘍学研究所の乳房放射線科のディレクター、フランチェスカ・カウモは語ります。

 

ストックホルムでは、ファビアンと彼のチームが、がんの影響を受けるすべての人の生活を改善するという使命を果たし続けています。彼の最初の診断から 4 年ほどが経ち、この取り組みは非常に有益なものとなりました。最先端の治療と家族のサポートと並んで、データもまた、わずかばかりの手助けになったことが証明されました。

 

研究者や臨床医、患者やすべての人にとって、クラウドコンピューティングと AI とともにあれば、人類の癌との闘いは決して壮絶なものではなくなるでしょう。

臨床医、研究者、患者が医療をより効率的にするためにデータと AI がどのように役立っているかについては、ここをクリックしてください。

 


New in AI では、マイクロソフト AI の世界各地の事例を紹介しています。
バックナンバーはこちら

小売業界の AI 戦略 (5/6) データを駆使してオペレーションを最適化

$
0
0

データを駆使してオペレーションを最適化

小売業界では、常にお客様を中心とした事業を展開しています。しかしお客様の好みはすぐに変化してしまうもの。変化するニーズを確実に捉えることは困難ですが、AI による知見を駆使した統合データフレームワークを利用することで、情報ベースの意志決定ができるようになり、オペレーションの最適化も進みます。


オペレーションの最適化を推進するAIトレンド 3 選

・ 適応力の高いアダプティブ R&D

・ オペレーションの最適化

・ 需要予測


複数店舗をAIで管理、オペレーションの最適化を実現

ここで具体的な利用シーンを紹介しましょう。食料品店を 3 店舗経営するスズキさんは、店舗のリソースやプロセスの最適化に向け、運用システムに AI を導入しました。同システムは、各店舗から収集したデータを統合することで、市場トレンドや競合の一歩先を行く運用を実現しています。

システムの CRM 機能では、お客様のオンラインでの購買履歴や店舗での履歴を確認。店舗内の IoT センサーからもデータを収集し、お客様が興味を示した商品やショッピングにかけた時間を把握します。ダッシュボードからは行列モニターセンサーによるレジのサービスレベルが確認でき、状況に合わせてスタッフの人数が調整できます。

また、データ分析により、多くのお客様が 3 店舗のうち 2 店舗以上で定期的に買い物をしていることを把握したスズキさんは、機械学習モデルで各店舗の在庫を最適化。会話インターフェースも活用し、地元のイベントなどお客様の購買行動が変化する状況に合わせて在庫を調整し、利益率を高めています。

さらに、ピックアップサービスや自宅配送サービスを利用するお客様にも対応できるよう、システム側で日々の注文を分析し、消費期限や在庫状況によってそれぞれの店舗に商品を移動させることも可能となりました。

もちろん、物流オペレーションでも AI が生かされています。配達の効率化に向けて事前に道順を計画するなど、ダイナミックに管理されるようになりました。


デジタルトランスフォーメーションへの道

・異なる店舗からのデータを相互参照し、全店舗の運用フレームワークに組み込むことで、一貫したサービスとオペレーションが実現します。

・行動検知センサーを導入すれば、お客様の移動経路を把握することも可能です。その行動データを分析し、新たな知見を導き出しましょう。

・天気やイベントなどによっても需要は変化します。背景となる要素を分析し、需要計画を向上させましょう。

・ パーソナライゼーションやレコメンデーションエンジンなど、学習によって改善を続ける技術を活用し、消費者の体験を向上させ変革させましょう。


イノベーション事例

自動販売機およびドリンク機器メーカーの Mars Drinks は、Neal Analytics と共同で Microsoft のコグニティブ サービスとデータテクノロジを自動販売機に導入しました。Mars Drinks は、Cortana Intelligence Suite や Microsoft Azure IoT Suite、Power BI などの技術を採用。リモートセンサーと予測コンピューティングを駆使して在庫レベルをより正確に管理し、お客様とのインタラクションをより深く理解すると共に、休日や天気といった状況による需要の変化が把握できるようになりました。

 

【New in AI: 2019/03/13】AI と交通安全 : 高速道路を監視する新たな目

$
0
0

"New in AI" では、ビジネスや社会の変革に向けて、マイクロソフト AI を活用いただいている世界各地の事例を紹介します。

AI と交通安全 : 高速道路を監視する新たな目

190313_new_in_ai

タイでは、交通事故で 1 日に約 66 人もの人が亡くなります。そして、その交通事故の多くが、混雑している高速道路で無謀な運転をするドライバーや疲れによって引き起こされたものです。タイ国内最大手の石油化学会社 GC は、その中でも危険なルートを毎年 8,000 回以上従業員に往復させています。4,000 人以上のスタッフやほかの道路利用者の安全を保つため、GC は Microsoft と提携して「AI for Road Safety」ソリューションを開発しました。このソリューションは、人工知能を使用して運転者の行動を監視し、眠気や気を散らすような状況に陥った際に警告します。管理者は必要に応じて、救援ドライバーを派遣することもできます。

この記事を読む(リンク先のページは英語です)
この動画を見る(リンク先のページは英語です)


New in AI

AI 変革を導く、STEM を学んだ女性たち

スリランカでは何百人もの女性が、キャリアコーチと新しいスキルを用いて国際女性デーを祝っています。スリランカ首相官邸で開催された DigiGirlz イベントでは、参加者が女性のロールモデルに出会い、キャリアの選択肢を探り、新しいスキルを身に付けました。AI のような新しい技術が、世界中の人々の生活、仕事、遊びの方法を変えていこうとしています。アジア太平洋地域においては、STEM (科学、技術、工学、数学) を学んだ女性たちが中心となってこの変化を実現していくでしょう。

この記事を読む(リンク先のページは英語です)


New in AI

若い女性たちが社会問題に AI 活用で挑む

3 月 8 日は国際女性デーです。将来を見据えた新たな取り組みの多くは、若い女性に科学、技術、工学、数学(STEM)教育とキャリア追求を奨励することによって、男女間のスキルギャップを解消することを目的としています。その新たな取り組みの一つが、Soweto での AI ブートキャンプでした。このキャンプにおいて、Soweto の 50 人の女子生徒は、創造的思考と AI で社会問題に取り組むことに挑戦しました。勝利したチームは、追加のスキル開発と AI トレーニング、そしてテクノロジーとビジネスにおけるリーダーとつながりを持ち、指導を受ける機会を獲得しました。

この記事を読む(リンク先のページは英語です)


AI side notes :

(リンク先のページは英語です)


本ページのすべての内容は、作成日時点でのものであり、予告なく変更される場合があります。正式な社内承認や各社との契約締結が必要な場合は、それまでは確定されるものではありません。また、様々な事由・背景により、一部または全部が変更、キャンセル、実現困難となる場合があります。予めご了承下さい。

バックナンバーはこちら

 

Partner Skills Initiative

$
0
0

How to attract and retain talent with the Partner Skills Initiative

By Liz Penning, UK Partner Skills Lead

As Partner Skills Lead, working closely with partners, one of the things I realise we have in common is our passion to ensure employees have the skills to drive business goals and to help our customers succeed.

It’s also one of the biggest challenges we face today. Attracting and retaining the best talent is the top emerging risk organisations face globally, according to Gartner.

We need to support both new and current employees in both re-skilling and up-skilling their digital skills. To do this successfully we need to work together to create a culture of continuous learning. This can include such things as an effective learning plan built with your HR function, empowering your employees to build learning time into their working hours or creating a learning rewards programme. By creating a positive learning culture within your business you’ll be supporting your current employees to maintain and improve, as well as attract and hire top talent.

Because I’m so passionate about all our partners succeeding in this, I’m excited to share our Partner Skills Initiative. We want to help you create new talent for the future, as well as retain and re-skill your current employees. We want to give you the opportunity to stay at the forefront of cloud and new technologies to help inspire our joint customers.

The programme aims to give you best practices, tools, and learning options, as well as ongoing support to ensure you futureproof your organisation. It covers the full Microsoft stack of products as well as readying for different job roles. The programme focuses on three areas; assess, learn, and grow.

Assess

Where are you on your digital transformation journey?

The first step is to assess. It’s important to know where you are in your digital transformation – both from a business and technical perspective and to know your starting point and benchmark.

The Partner Transformation Readiness Assessment was created to help you do exactly this. It only takes about 25 minutes to complete, and at the end it gives you recommendations and resources you can use to advance your organisation. If you have been working with your Partner Team on the Partner Transformation Index, then please continue to do so and create your plan for moving forward together.

Learn

Learn new skills for the future

Included in the Partner Skills Initiative is an online training centre designed to aid in the re-skilling and up-skilling of your employees. They can use this to learn new skills in new technology areas and by new job roles, for example a sales person moving into a technical role.

Our online partner training centre offers ongoing role-based learning pathways and training recommendations based on the job role, skill level, and technology.

Grow

Embrace a culture of continuous learning

Just as your organisation will grow with your new culture of continuous learning, our initiative will too. We’ll provide continuous updates to the learning resources, in-person and virtual live events, and best practices to support you.

Also, to help grow your business and talent, we have created a new Partner Talent Playbook to help partners understand how to recruit, hire, develop and retain talent.

Coupled with the Microsoft Apprenticeships Programme, these are great resources and programmes for the UK to fill the digital skills gap and for businesses to build their talent pipeline and invest in the future of their workforce. Apprenticeships are a great opportunity for young people to develop the skills they need to succeed in the future of work through hands-on learning. They’re good for businesses and the UK economy too. With an ever-growing digital skills gap, there’s never been a better time to invest in the workforce of the future.

Business leaders

Often business leaders’ learning requirements are overlooked and so I am pleased to also announce the AI Business School. The business school complements the Partner Skills Initiative but is focused purely on AI and is commercially designed to get executives ready to lead their organisation on a journey of AI transformation.

The school is a deep dive into how to develop a strategy and identify blockers before they happen as you implement AI in your organisation. Mitra Azizirad, Corporate Vice President for AI Marketing at Microsoft explains: “Developing a strategy for AI extends beyond the business issues. It goes all the way to the leadership, behaviours, and capabilities required to instil an AI-ready culture in your organisation.”

On the road to developing a strategy, executives and other business leaders are often stalled by questions about how and where to begin implementing AI across their companies. They ponder the cultural changes that AI requires companies to make, and how to build and use AI in ways that are responsible, protect privacy and security, and comply with government rules and regulations.

Launching Microsoft’s AI Business School will help business leaders navigate these questions. The free online courses, built in partnership with INSEAD, is a masterclass series that aims to empower leaders to advance with confidence in the age of AI.

Helping you futureproof your organisation

I believe the best way to move into this tech-driven future is by equipping your workforce with the skills needed to drive innovation, knowledge, and empowerment.

That is why I’m proud to be able to share these initiatives with you. The Partner Skills Initiative and AI Business School are part of our plan to help equip the UK partner ecosystem with the skills to succeed in the future.

You can also show that you share this vision by signing our Partner Pledge. This is where partners can reaffirm their commitment to helping the UK build the skills we need for our digital future.

Explore our resources:

Readiness Assessment

Online Partner Training Centre

Partner Talent Playbook

Microsoft Apprenticeship Programme

AI Business School

Partner Pledge

 

About the author

Liz Penning is our Partner Skills Lead, within Partner Business and Development in One Commercial Partner UK. Her role is focused on setting the UK strategy for partner learning and executing on this. This can be anything from working on training events such as workshops, hacks and hands-on labs, all the way to landing new programmes, such as the Partner Skills Initiative, and working on plans with our partners to help grow a continuous learning culture. Liz also leads the Apply section of our Digital Skills Programme, which focuses on Apprenticeships for partners and customers.

Having been at Microsoft for nine years, she has lots of experience working with our network of partners. Over that time, there has been one consistent message, which is the lack of skills within the market. Skills have a direct correlation to the growth of our partners’ and customers’ businesses and if we can help provide them with the right resources and programmes to engage in learning and new talent, we will get that one step closer to closing the skills gap together. Liz is extremely passionate about Early in Career and diversity – there are many young people who need that extra help to realise their potential, regardless of their background or situation.

Installing SCVMM 2019 with a Group Managed Service Account

$
0
0

___________________________________________________________________________________________________________________________
IMPORTANT ANNOUNCEMENT FOR OUR READERS!

AskPFEPlat is in the process of a transformation to the new Core Infrastructure and Security TechCommunity, and will be moving by the end of March 2019 to our new home at https://aka.ms/CISTechComm (hosted at https://techcommunity.microsoft.com). Please bear with us while we are still under construction!

We will continue bringing you the same great content, from the same great contributors, on our new platform. Until then, you can access our new content on either https://aka.ms/askpfeplat as you do today, or at our new site https://aka.ms/CISTechComm. Please feel free to update your bookmarks accordingly!

Why are we doing this? Simple really; we are looking to expand our team internally in order to provide you even more great content, as well as take on a more proactive role in the future with our readers (more to come on that later)! Since our team encompasses many more roles than Premier Field Engineers these days, we felt it was also time we reflected that initial expansion.

If you have never visited the TechCommunity site, it can be found at https://techcommunity.microsoft.com. On the TechCommunity site, you will find numerous technical communities across many topics, which include discussion areas, along with blog content.

NOTE: In addition to the AskPFEPlat-to-Core Infrastructure and Security transformation, Premier Field Engineers from all technology areas will be working together to expand the TechCommunity site even further, joining together in the technology agnostic Premier Field Engineering TechCommunity (along with Core Infrastructure and Security), which can be found at https://aka.ms/PFETechComm!

As always, thank you for continuing to read the Core Infrastructure and Security (AskPFEPlat) blog, and we look forward to providing you more great content well into the future!

__________________________________________________________________________________________________________________________

This content also resides in the Core Infrastructure and Security TechCommunity blog @ https://techcommunity.microsoft.com/t5/Core-Infrastructure-and-Security/Installing-SCVMM-2019-with-a-Group-Managed-Service-Account/ba-p/370186

Hello SCVMM Users, Michael Godfrey here again, Premier Field Engineer specializing in all things Private and Public Cloud including the Software Defined Datacenter.

It's here, It's here. The time has come for a new Long-Term Servicing Channel (LTSC) release of System Center 2019. I know first-hand that the Product Group behind Virtual Machine Manager has been hard at work bringing new features to make VMM a stellar part of your Private & Hybrid Cloud Deployment and I wanted to talk about one of my favorite new features before you begin the path to install VMM 2019.

In the past, VMM has had a requirement for a Service Account, this is the account that all VMM requests to the Hosts and Infrastructure components of VMM are made through. This has traditionally been a standard user account, that you or your Active Directory Administrator would create, set the password to a random string, and set the password to never expire. This was not a great idea in a modern infrastructure, especially when it came to security. This account has a lot of permissions, including local administrator rights on all of your hosts.

A wise manager once told me, "It's not a problem, unless you have a solution." So, in Windows Server 2012 a concept known as Group Managed Service Accounts was introduced, and these accounts are essentially a managed service account that provides automatic password management, provided by Active Directory. You can read more about them here.

What I am so excited to share with you today is after years of Microsoft products adopting GMSA's, the time has finally come for System Center 2019. Now, as you prepare to install VMM 2019, you will have the option to supply a Service Account, a Local Account or a Group Managed Service Account. In this post, I want to share with you, exactly how you go about creating a GMSA and then use it to install VMM 2019. Here we go….

There are some prerequisites to creating a GMSA, there are great directions from our friends at Docs.Microsoft.Com; the link is here. The short end of it is, your AD Administrator will need to use PowerShell to create the Managed Service Account, you will need to provide the name of the account, and the "PrincipalsAllowedToRetriveManagedPassword." This is quite simply the Computer Accounts that will be authorized to retrieve the password from Active Directory on an ongoing basis. In the instance of installing VMM, you will need to use all Servers that the VMM Server is installed on, so in a Stand-Alone environment, one machine. If you deployed VMM in a Highly Available Capacity, then all the nodes in the Cluster and the Cluster Computer Account Name itself will be included in this list. Here is an example command in PowerShell that can help you build the account on a domain controller.


New-ADServiceAccount SCVMMSVC -DNSHostName SCVMMSVC.Contoso.com -PrincipalsAllowedToRetrieveManagedPassword SCVMMCL, SCVMMNode1, SCVMMNode2 -KerberosEncryptionType RC4, AES128, AES256

Once you have the Managed Service Account Created and verified, you can use it for the install. When you get to the "Configure Service Account and Distributed Key Management" Page in the SCVMM 2019 Install Wizard, simply select the radio button; "Group Managed Service Account," and enter the name of the service account. Please note this must be in the "FQDNService Account Name," format, and be sure to include the dollar sign, $, at the end of the account name, as it is considered a computer account.

That's it! Now continue through the wizard like normal and you will have set SCVMM 2019 with one of the newest features, GMSA. Now, the VMM Server will request the password from AD on a consistent basis and update the SCVMMService with the new Service Account password, all in the background, allowing you and your security team peace of mind that the Service account password is reset regularly and unknown to any humans.

I hope this helps and stay tuned for more blogs about new features in SCVMM 2019, as I will be posting new content on things like Storage Optimization, Azure Update Integration with VMM and Encrypting SDN VMNetworks in the future.

As always feel free to comment and reach out with any questions. Thanks again!

Join Microsoft Security Response at the Product Security Operations forum at LocoMocoSec!

$
0
0

The MSRC is more than managing vulnerability reports, publishing Microsoft security updates, and defending the cloud. The MSRC is passionate about helping everyone improve internal engineering practices and supporting the defender community, and are excited to partner with Blackberry to host a Product Security Operations Forum at LocoMocoSec on April 18, 2019.

Featuring exceptional speakers from across the industry, the Product Security Operations Forum will share what industry practitioners have learned about problems (and solutions!) of secure development and managing vulnerability response. We’ll have hands-on practitioners from, npm, Adobe, Microsoft, GitHub, and elsewhere discussing the operational programs and processes they are using to tackle real-world challenges. Since no single person has all the answers, we also hope that everyone attending will take advantage of the event format to meet and share knowledge with each other about the approaches they’ve taken—and then continue the conversation at the luau event in the evening.

And if that’s not enough, LocoMocoSec has loads of other great content and workshops scheduled. Interested? The conference schedule is online and the advance purchase discount deadline is March 26.

We look forward to seeing you there!

 

Christa Anderson,

Senior Security Program Manager

MSRC

 

The Microsoft Security Response Center (MSRC) is part of the defender community and on the front line of security response evolution. For more than twenty years, we have been engaged with security researchers working to protect customers and the global online community. For more information, please visit our website at www.microsoft.com/msrc and follow our Twitter page at @msftsecresponse.

Top Contributors Awards! Upgrading to SCOM 2019 Step-By-Step and many more!

$
0
0

Welcome back for another analysis of contributions to TechNet Wiki over the last week.

First up, the weekly leader board snapshot...

 

As always, here are the results of another weekly crawl over the updated articles feed.

 

Ninja Award Most Revisions Award
Who has made the most individual revisions

 

#1 Emre Ozan Memis with 42 revisions.

 

#2 Peter Geelen with 34 revisions.

 

#3 Hamid Sadeghpour Saleh with 28 revisions.

 

Just behind the winners but also worth a mention are:

 

#4 Somdip Dey - MSP Alumnus with 26 revisions.

 

#5 karimSP with 25 revisions.

 

#6 Leon Laude with 22 revisions.

 

#7 Jayendran arumugam with 18 revisions.

 

#8 Av111 with 17 revisions.

 

#9 Dave Rendón with 15 revisions.

 

#10 Santhosh Sivarajan- with 12 revisions.

 

 

Ninja Award Most Articles Updated Award
Who has updated the most articles

 

#1 karimSP with 23 articles.

 

#2 Somdip Dey - MSP Alumnus with 21 articles.

 

#3 Hamid Sadeghpour Saleh with 15 articles.

 

Just behind the winners but also worth a mention are:

 

#4 Emre Ozan Memis with 12 articles.

 

#5 Peter Geelen with 8 articles.

 

#6 Av111 with 7 articles.

 

#7 Santhosh Sivarajan- with 6 articles.

 

#8 Dave Rendón with 4 articles.

 

#9 Carsten Siemens with 3 articles.

 

#10 Richard Mueller with 3 articles.

 

 

Ninja Award Most Updated Article Award
Largest amount of updated content in a single article

 

The article to have the most change this week was SCCM troubleshooting: Content Location Request for <Package ID> failed. (Code 0x80040102), by Kiodos

This week's reviser was Peter Geelen

 

Ninja Award Longest Article Award
Biggest article updated this week

 

This week's largest document to get some attention is Upgrading to SCOM 2019 Step-By-Step, by Leon Laude

This week's revisers were Carsten Siemens & Leon Laude

 

Ninja Award Most Revised Article Award
Article with the most revisions in a week

 

This week's most fiddled with article is PowerBI: Tracking Location using Google Location Data , by Jayendran arumugam. It was revised 16 times last week.

This week's reviser was Jayendran arumugam

 

Ninja Award Most Popular Article Award
Collaboration is the name of the game!

 

The article to be updated by the most people this week is Active Directory Firewall Ports, by Hamid Sadeghpour Saleh

This week's revisers were Hamid Sadeghpour Saleh, Carsten Siemens & Emre Ozan Memis

 

Ninja Award Ninja Edit Award
A ninja needs lightning fast reactions!

 

Below is a list of this week's fastest ninja edits. That's an edit to an article after another person

 

Ninja Award Winner Summary
Let's celebrate our winners!

 

Below are a few statistics on this week's award winners.

Most Revisions Award Winner
The reviser is the winner of this category.

Emre Ozan Memis

Emre Ozan Memis has won 2 previous Top Contributor Awards:

Emre Ozan Memis has not yet had any interviews, featured articles or TechNet Guru medals (see below)

Emre Ozan Memis's profile page

Most Articles Award Winner
The reviser is the winner of this category.

karimSP

karimSP has won 17 previous Top Contributor Awards. Most recent five shown below:

karimSP has not yet had any interviews, featured articles or TechNet Guru medals (see below)

karimSP's profile page

Most Updated Article Award Winner
The author is the winner, as it is their article that has had the changes.

Kiodos

This is the first Top Contributors award for Kiodos on TechNet Wiki! Congratulations Kiodos!

Kiodos has not yet had any interviews, featured articles or TechNet Guru medals (see below)

Kiodos's profile page

Longest Article Award Winner
The author is the winner, as it is their article that is so long!

Leon Laude

Leon Laude has been interviewed on TechNet Wiki!

Leon Laude has won 3 previous Top Contributor Awards:

Leon Laude has TechNet Guru medals, for the following articles:

Leon Laude has not yet had any featured articles (see below)

Leon Laude's profile page

Most Revised Article Winner
The author is the winner, as it is their article that has ben changed the most

Jayendran arumugam

Jayendran arumugam has been interviewed on TechNet Wiki!

Jayendran arumugam has won 6 previous Top Contributor Awards. Most recent five shown below:

Jayendran arumugam has TechNet Guru medals, for the following articles:

Jayendran arumugam has not yet had any featured articles (see below)

Jayendran arumugam's profile page

Most Popular Article Winner
The author is the winner, as it is their article that has had the most attention.

Hamid Sadeghpour Saleh

Hamid Sadeghpour Saleh has won 3 previous Top Contributor Awards:

Hamid Sadeghpour Saleh has not yet had any interviews, featured articles or TechNet Guru medals (see below)

Hamid Sadeghpour Saleh's profile page

Ninja Edit Award Winner
The author is the reviser, for it is their hand that is quickest!

Emre Ozan Memis

Emre Ozan Memis is mentioned above.

 

 Says: Another great week from all in our community! Thank you all for so much great literature for us to read this week!

Please keep reading and contributing, because Sharing is caring..!!

 

Best regards,

 


Talend とマイクロソフトがより強力なクラウド スケールの分析を実現

$
0
0

執筆者: Ewan Dalton (Sr. Partner Development Manager)

このポストは、2019 3 13 日に投稿された Spinning up cloud-scale analytics is even more compelling with Talend and Microsoft の翻訳です。

 

このブログ記事の執筆にご協力いただいた Lee Schlesinger 氏と Talend チームに感謝の意を表します。

2019 年 2 月に、Azure Data Warehouse が費用対効果の面で業界をリードし続けている (英語) というレポートが発表されました。それに続くように、Talend Stitch Data Loader (英語) Azure SQL Data Warehouse をサポートするということが発表されました。Stitch Data Loader は最近 Talend のポートフォリオに追加された中堅中小企業向けの製品であり、これを使用すると Azure SQL Data Warehouse 1 サブスクリプションあたり月間 500 万行まで無料で読み込めるほか、スケールアップも無制限に行えます。

クラウドへの移行が業界全体で急激に進んでいる今、高速で柔軟で安全なクラウド データ ウェアハウスを使用することは、その取り組みに欠かせない重要な一歩です。Microsoft Azure SQL Data Warehouse Stitch Data Loader を組み合わせれば、クラウドへの移行をいち早く開始できます。市場に出回っている他のオプションに比べて、Azure SQL Data Warehouse は最大 14 倍も高速で、コストも 94% 削減 (英語) できるため、あらゆる規模のお客様がクラウド スケールの分析機能をすばやく導入できます。

Stitch Data Loader でクラウドへのパイプラインを構築

Stitch チームは、マイクロソフトのエンジニアの協力の下、Azure SQL Data Warehouse を統合しました。このソリューションでは、Azure Blob Storage PolyBase を使用して Azure クラウドにデータを取得し、最終的には SQL Data Warehouse に読み込みます。移行元と移行先の間でのデータ型変換、スキーマ変更、一括読み込みに関する問題には、すべてマイクロソフトが対応しました。

データの移行を開始するときは、ホスト アドレスとデータベース名を指定して認証資格情報を入力します。たったこれだけで、Stitch があらゆるソースから数分のうちにデータを読み込みます。

Stitch Data Loader を使用すると、Azure SQL Data Warehouse ユーザーはデータベース、SaaS ツール、ネットワークなどの 90 種類以上のデータ ソースのデータを分析できます。マイクロソフトはオープン ソース ETL Singer (英語) プロジェクトにも出資して統合を行っているため、さらに豊富なデータ ソースやカスタムのデータ ソースから Azure SQL Data Warehouse に簡単に読み込むことが可能です。

既存の Stitch ユーザーは、Stitch 転送先切り替え (英語) 機能を使用することで、既に統合されているソースから Azure SQL Data Warehouse に直接簡単にデータを読み込めます。

Talend Cloud と Azure SQL Data Warehouse の高度な使い方

データ ウェアハウスをスケールアウトし、データ変換、プロファイリング、品質の問題に対処する準備が完了したら、次のステップに進みましょう。Talend Cloud (英語) では、さらに広範なソースがサポートされていることに加え、Azure SQL Data Warehouse Azure Platform で使用可能な最新のデータ処理機能と品質管理機能が提供されます。900 種類を超えるコネクタが用意されており、形式やソースによらずあらゆるデータを移行できます。データ準備機能や高度なセキュリティ機能が組み込まれているため、すぐに Azure で使用できます。

ここで Uniper の事例 (英語) をご紹介します。同社では Azure Talend Cloud を使用してクラウド ベースのデータ分析プラットフォームを構築し、さまざまな外部ソースや内部ソースから温度や IoT センサーなどの 100 以上のデータ ソースを統合しました。市場分析から契約、資産管理、契約後までのビジネス トランザクションのフロー全体を構築し、同時にデータ ガバナンスとセルフサービスを可能にした結果、統合コストの 80% 削減と 6 か月間での投資回収に成功しました。

次のステップ

  • Stitch の無料試用版 (英語) を今すぐお試しください。Azure SQL Data Warehouse に数分程度でデータを読み込むことができます。
  • こちらのページ Azure SQL Data Warehouse の高い費用対効果をとマイクロソフトのレポートをご確認ください。

Managed Disks が VMware と物理サーバーに対応し、ディザスター リカバリーが容易に

$
0
0

執筆者: Mayuri Gupta (Program Manager II, R&D Compute MDR IDC (Hyd))

このポストは、2019 3 13 日に投稿された Simplify disaster recovery with Managed Disks for VMware and physical servers の翻訳です。

 

Azure Site Recovery (ASR) で VMware 仮想マシンと物理サーバーから Managed Disks に直接レプリケーションできるようになり、ディザスター リカバリーがサポートされました。2019 3 月以降に新しく保護されたマシンでは、これらの機能をすべて Azure Portal から使用できます。今後は、マシンのレプリケーションを有効にするためにストレージ アカウントを作成する必要はなく、レプリケーション データを Managed Disks に直接書き込めます。Managed Disks の種類は、データの変更量に応じて Standard HDDStandard SSDPremium SSD からお選びいただけます

VMware and physical - Write to Managed Disks

なお、既に保護されているマシンには今回の変更が適用されず、引き続きストレージ アカウントがレプリケーション先となりますのでご注意ください。ただし、[Compute and Network] ブレードの設定を変更するとフェールオーバー時に Managed Disks を使用することができます。

書き込み先を Managed Disks に設定すると、以下のようなメリットがあります。

  • Microsoft Azure のキャパシティ管理が不要: レプリケーション先のストレージ アカウントをいくつも追跡、管理する必要がありません。レプリケーションが有効化されると、ASR でレプリカ ディスクが作成されます。Azure Managed Disks はオンプレミスの仮想マシン (VM) ディスク 1 台につき 1 台作成され、Azure で管理されます。
  • 異なる種類の Managed Disks にシームレスに移行可能: 保護を有効化した後にソース ディスクのデータの変更量や変更パターンが変化しても、Managed Disks のレプリケーションの無効化や有効化を行う必要はありません。変化後のデータ変更量に応じて Managed Disks の種類を切り替えるだけです。ただし、Managed Disks の種類を変更した後にフェールオーバー テストやフェールオーバー後のアクティビティのテストを実施する場合は、新しい復旧ポイントが生成されるまで待機してください。

ASR 用レプリケーション アーキテクチャは、最初に Azure のキャッシュ ストレージ アカウントにアップロードされたレプリケーション ログに従って調整されます。このログは ASR で処理され、その後レプリカ用の Azure Managed Disks にプッシュされます。レプリケーションを有効化した時点のレプリケーション ポリシーに従って、一定間隔で Managed Disks のスナップショットが作成されます。レプリケーションされたアイテムの [Disks] ブレードに、レプリカの名前とレプリケーション先の Managed Disks が表示されます。フェールオーバー時には、ユーザーがレプリカの Managed Disks のいずれかの復旧ポイントを選択できます。この復旧ポイントは、レプリケーション先の Azure Managed Disks を作成する際に使用されます。これは、VM 起動時にその VM にアタッチされたものです。

キャッシュ ストレージではレプリケーション オプションとして LRS を使用することをお勧めします。キャッシュ アカウントは Standard Storage であり、一時データのみを格納するため、1 つの Recovery Services コンテナーに複数のキャッシュ ストレージ アカウントを用意する必要はありません。

今すぐ ASR をお試しくださいManaged Disks への書き込みは、すべての Azure リージョンでサポートされています。また、ナショナルクラウドでも近いうちにサポートされる予定です。

関連資料

 

イベント開催のご案内 | 2019/3/18 号

$
0
0

マイクロソフトでは、様々な支援ができるよう多数のセミナー(ウェビナーおよび各地でスクール形式行われるセミナー)を開催しております。

遠方で参加が難しい方や当日都合が悪くなった方には、オンラインでご参加いただける形式のセミナーも多数実施しておりますので、お気軽にご参加いただき、お役立て下さい。(参加には事前のお申込みが必要になります)

なお、過去のウェビナーは Azure サイトの歩き方ページより、
[学習する] ― [過去の Web / 動画セミナー (2018 年 1 月以降)] から参照いただけます。

※このエントリーは、期間内のイベントに限り、登録サイトが公開され次第順次アップデートされます。

セミナー

2019 年 4 月 16 日(火) 13:00-17:30(12:45 開場)

[東京開催] SQL Server の達人になる!丸わかり 1 日セミナー
SQL Server 2019 とデータベースマイグレーションの最新情報をお届け!

今回の SQL Server 丸わかり 1 日セミナーでは、前半は、新しいバージョンの SQL Server となる SQL Server 2019 の最新のプレビュー版の情報 / SQL Server と高い互換性を持つ PaaS 型のマネージド データベースである SQL Database Managed Instance の解説 / SQL Server への移行、SQL Server のバージョンアップ、クラウドの SQL Server へのマイグレーションを効率的に実施するために活用できるツールなどの最新情報をご紹介いたします。

後半は、既存データ資産を生かしたデータベースの最新化についてご説明いたします。

参加のご登録はこちら >

Azure のイベント からもイベントの一覧をご覧いただけます。

現在提供されているのは、Azure DevOps Server 2019

$
0
0

9 月の Azure DevOps の発表に続き、Azure DevOps Server 2019 の正式リリースを発表します。Team Foundation Server (TFS) は Azure DevOps Server 2019 に名称が変更され、お客様の専用の環境で Azure DevOps の機能をご利用いただけるようになりました。

https://azure.microsoft.com/ja-jp/blog/now-available-azure-devops-server-2019/

※このポストは、2019 年 3 月 5 日に投稿された Now available: Azure DevOps Server 2019

Azure の Announcements 一覧は https://azure.microsoft.com/ja-jp/blog/topics/announcements/ よりご覧いただけます。

Azure Databricks – VNet インジェクション、DevOps バージョン コントロール、および Delta の利用可能性

$
0
0

Azure Databricks は、高速かつ簡単でコラボレーションに対応した Apache® Spark™ ベースの分析プラットフォームを提供することで、ビジネスを推進するビッグ データと AI のソリューションを構築するプロセスを高速で簡単なものにします。すべてが業界最高の SLA によって裏付けられています。

https://azure.microsoft.com/ja-jp/blog/azure-databricks-vnet-injection-devops-version-control-and-delta-availability/

※このポストは、2019 年 3 月 13 日に投稿された Azure Databricks – VNet injection, DevOps Version Control and Delta availability

Azure の Announcements 一覧は https://azure.microsoft.com/ja-jp/blog/topics/announcements/ よりご覧いただけます。

PowerApps Tidbit – Various links for PowerApps and Environments

$
0
0

Hello All,

Built this list for a customer after having a discussion around management of PowerApps (And how to build PowerApps), thought you might find it useful.

Building a PowerApps

PowerApps formulas - https://powerapps.microsoft.com/en-us/tutorials/formula-reference/

New Best Practices Community Galleries! - https://powerapps.microsoft.com/en-us/blog/new-best-practices-community-forums-and-app-gallery/

Understand delegation in a canvas app - https://docs.microsoft.com/en-us/powerapps/maker/canvas-apps/delegation-overview

Custom connectors for canvas apps - https://docs.microsoft.com/en-us/powerapps/maker/canvas-apps/register-custom-api

Overview of creating apps in PowerApps - https://docs.microsoft.com/en-us/powerapps/maker/

What are canvas apps in PowerApps? - https://docs.microsoft.com/en-us/powerapps/maker/canvas-apps/getting-started

What are model-driven apps in PowerApps? - https://docs.microsoft.com/en-us/powerapps/maker/model-driven-apps/model-driven-app-overview

Environments (CDS for Apps)

Predefined Security Roles https://docs.microsoft.com/en-us/common-data-service/upgradecds/introduction-upgrade-cds

Managing environments for your organization https://docs.microsoft.com/en-us/power-platform/admin/environments-overview#managing-environments-for-your-organization

Data loss prevention (DLP) policies - https://docs.microsoft.com/en-us/power-platform/admin/create-dlp-policy

What is Common Data Service for Apps? - https://docs.microsoft.com/en-us/powerapps/maker/common-data-service/data-platform-intro

Manage environments in PowerApps - https://docs.microsoft.com/en-us/power-platform/admin/environments-administration

Manage Common Data Service for Apps settings - https://docs.microsoft.com/en-us/power-platform/admin/admin-settings

Administer PowerApps

Administer PowerApps - https://docs.microsoft.com/en-us/power-platform/admin/admin-guide

What's the role of a PowerApps administrator? - https://docs.microsoft.com/en-us/power-platform/admin/overview-role-powerapps-admin

Management and monitoring - https://docs.microsoft.com/en-us/power-platform/admin/wp-management-monitoring

PowerApps Preview Program - https://docs.microsoft.com/en-us/power-platform/admin/preview-environments

Application Lifecycle Management - https://docs.microsoft.com/en-us/power-platform/admin/wp-application-lifecycle-management

Licensing

PowerApps standalone Plan 1 and Plan 2 https://docs.microsoft.com/en-us/power-platform/admin/pricing-billing-skus

Pax

Enhanced Audit Status Message Queries

$
0
0

Hello everyone!  My name is Brandon McMillan and I am a System Center Configuration Manager (ConfigMgr) PFE.  I have found that Status Message Queries can be one of the more underappreciated features of ConfigMgr.  The information you can gather in a quick and easy query can be very powerful in helping you determine the root cause analysis of an issue.  I hope this blog will provide additional Status Message Queries and how you can quickly export/import some examples into your environment.

First let’s break down the different Status Message Types:

 

ID Status Message Type Description
256 Milestones  

Use this type at the end of an operation to indicate the operation's success or failure. If the operation was successful, use the Milestone type in an informational message. If the operation failed, use a milestone message type in a warning or error message.

512 Details  

Use this type to illustrate the steps in a complex operation. Often, detail messages are meaningful only within the context of the sequence of status messages representing a complex operation.

768 Audits  

Use this type for informational messages that provides a trail of actions taken by the Configuration Manager administrator. An audit message also depicts an operation that results in objects being added, modified, or deleted. You do not need to create audit messages; the provider automatically generates these messages for you.

1024 NT Events

 

Reference: SMS_StatusMessage WMI Class

Enumerating Status Message Strings

How can we obtain a full listing of Status Message ID’s?  If you are unsure what Status Message ID’s to use to create a specific Status Message Query, you can export all the Status Messages ConfigMgr provides by using a PowerShell script provided by a previous article by SaudM.  The script and an example of an excel output from a previous ConfigMgr 2012 R2 environment can be found here: Enumerate Status Messages.

Here’s an example of how you can leverage the script and export the Status Messages based on type: Client, Provider, or Server Messages:

Client Messages
.Export-StatusMessages.ps1 -stringPathToDLL "<InstallDrive>:Program FilesMicrosoft Configuration ManagerbinX64system32smsmsgsclimsgs.dll" -stringOutputCSV ExportClientMsgs.csv
Provider Messages
.Export-StatusMessages.ps1 -stringPathToDLL "<InstallDrive>:Program FilesMicrosoft Configuration ManagerbinX64system32smsmsgsprovmsgs.dll" -stringOutputCSV ExportProviderMsgs.csv
Server Messages
.Export-StatusMessages.ps1 -stringPathToDLL "<InstallDrive>:Program FilesMicrosoft Configuration ManagerbinX64system32smsmsgssrvmsgs.dll" -stringOutputCSV ExportServerMsgs.csv

Default Status Message Queries

We provide many out of box queries that are delivered with the product; however, there are many Message ID’s that you can leverage which could help you build your own specific queries for your environment. Here is a list of Status Message Queries that are delivered with ConfigMgr:

  1. All Audit Status Messages for a Specific User
    • Message Type: 768
    • Message Attribute ID: 403
  2. All Audit Status Messages from a Specific Site
    • Message Type: 768
  3. Boundaries Created, Modified, or Deleted
    • Message IDs: 40600-40602
  4. Client Component Configuration Changes
    • Message IDs: 30042-30047
  5. Collections Created, Modified, or Deleted
    • Message IDs: 30015-30017
  6. Collection Member Resources Manually Deleted
    • Message IDs: 30066-30067
  7. Deployments Created, Modified, or Deleted
    • Message IDs: 30006-30008
  8. Packages Created, Modified, or Deleted
    • Includes Package Conversion Status
    • Message IDs: 30000-30002
  9. Programs Created, Modified, or Deleted
    • Includes Package Conversion Status
    • Message IDs: 30003-30005
  10. Queries Created, Modified, or Deleted
    • Message IDs: 30063-30065
  11. Remote Control Activity at a Specific Site, User, or System (4 Total)
    • Message IDs: 30069-30087
  12. Security Scopes Created, Modified, Deleted, or Imported
    • Message IDs: 31200-31202 / 31220-31222 / 31207
  13. Server Component Configuration Changes
    • Message IDs: 30033-30035 / 30039-30041
    • Site Control Changes
  14. Site Addresses Created, Modified, or Deleted
    • Message IDs: 30018-30020

Enhanced Audit Status Message Queries

Now what if you need something more specific?  The following list may help you quickly determine what specific activities are occurring within your environment.  A direct link to TechNet gallery of the exported Status Message Queries is located here: “Enhanced Audit Status Message Queries”.

  1. Audit - All Alert Actions
    • Includes DRS Alerts
    • Message IDs: 30240-30244
  2. Audit - All Application Actions
    • Message IDs: 30226-30228 / 49003-49005 / 52300
  3. Audit - All Application Catalog Actions
    • Message IDs: 30800-30805 / 50000-50004
  4. Audit - All Asset Intelligence Actions
    • Message IDs: 30208-30209 / 31001
  5. Audit - All Azure and Co-Management Actions
    • Message IDs: 53001-53005 / 53401-53403 / 53501-53503
  6. Audit - All Boundary Group Actions
    • Message IDs: 40500-40505
  7. Audit - All Client Configuration Requests (CCRs)
    • Client Push actions.
    • Message IDs: 30106-30111
  8. Audit - All Client Operations Actions
    • Includes “Right Click” actions.
    • Message IDs: 40800-40804
  9. Audit - All Client Settings Actions
    • Includes Antimalware Policies.
    • Message IDs: 40300-40305
  10. Audit - All Client and Collection Miscellaneous Actions
    • Includes Update Membership, Device Imports, Clear PXE Deployments
    • Message IDs: 30104 / 30213 / 42021
  11. Audit - All CMPivot and Script Actions
    • Message IDs: 40805-40806 / 52500-52505
  12. Audit - All Conditional Access Actions
    • Includes Exchange Online, SharePoint Online, and On-Prem Exchange actions.
    • Message IDs: 30340-30341
  13. Audit - All ConfigMgr Actions in Console
    • Checks components: Microsoft.ConfigurationManagement.exe / AdminUI.PS.Provider.dll
  14. Audit - All Configuration Baseline Actions
    • Message IDs: 30168 / 30193-30198
  15. Audit - All Configuration Items
    • Configuration Items Created, Modified, and Deleted. Includes Applications, Operating Systems, Drivers, Compliance Settings, and Endpoint Protection actions.
      • Compliance Settings
        • Configuration Items, Configuration Baselines, User Data and Profiles, Remote Connection Profiles, Compliance Policies, Company and Resource Access: Certificate Profiles, Email Profiles, VPN Profiles, Wi-Fi Profiles, Windows Hello for Business Profiles, Terms and Conditions, Microsoft Edge Browser Profiles, Windows 10 Edition Upgrade
      • Endpoint Protection
        • Windows Defender Firewall Policies, Windows Defender ATP Policies, Windows Defender Exploit Guard, Windows Defender Application Guard, Windows Defender Application Control
      • Message IDs: 30152-30167
  16. Audit - All Content Library Actions
    • Includes Content Library changes
  17. Message IDs: 30080 / 30189-30191
    • Audit - All Distribution Point Actions
  18. Message IDs: 30009-30011 / 30068 / 30109 / 30125 / 30500-30503 / 40409-40410
    • Audit - All Distribution Point Changes
    • Message IDs: 40400-40409 / 40506
  19. Audit - All Folder Actions
    • Message IDs: 30113-30117
  20. Audit - All Messages
  21. Audit - All Messages (Specified Message ID)
  22. Audit - All Messages (Specified Timeline)
  23. Audit - All Migration Actions
    • Message IDs: 30900-30907
  24. Audit - All Mobile Device Management Actions
    • Message IDs: 40200-40206 / 45000-45004 / 47000-47002 / 48000-48003 / 49003-49005 / 51000-51006 / 52000-52020
  25. Audit - All Phased Deployment Actions
    • Message IDs: 53601-53603
  26. Audit - All Query Actions
    • Message IDs: 30063-30065 / 30302-30303
  27. Audit - All Report Actions
    • Message IDs: 30091-30093 / 31000-31002
  28. Audit - All Search Folder Actions
    • Message IDs: 30700-30702
  29. Audit - All Secondary Site Actions
    • Message IDs: 30012-30014 / 30021-30023
  30. Audit - All Site Server Boundary Actions
    • Message IDs: 30054-30056
  31. Audit - All Site Server Definition Actions
    • Message IDs: 30030-30032
  32. Audit - All Site Server Property Actions
    • Message IDs: 30024-30029
  33. Audit - All Site Server Role Actions
    • Message IDs: 30036-30038
  34. Audit - All Site Server Security Actions
    • Message IDs: 30057-30062 / 30210-30212 / 31200-31242 / 31203-31249
  35. Audit - All Site Server SQL Actions
    • Includes Site Maintenance Tasks
    • Message IDs: 30048-30053
  36. Audit - All Software Update Actions
    • Message IDs: 30112 / 30118-30124 / 30135-30137 / 30172 / 30183-30188 / 30196-30198 / 30219-30221 / 30229-30231 / 30506-30507 / 42031-42033 / 4900-49002
  37. Audit - All Software Metering Rules Actions
    • Message IDs: 30094-30095 / 30105
  38. Audit - All User Object Actions
    • Message IDs: 30600-30606

Script to Import Status Message Queries

param(  
    [Parameter(Mandatory=$True)]  
    [string]$XMLPath  
)  
  
# Imports ConfigMgr Module 
Import-Module "$env:SMS_ADMIN_UI_PATH..ConfigurationManager.psd1" 
 
# Get SiteCode 
$SiteCode = Get-PSDrive -PSProvider CMSITE 
Set-location $SiteCode":" 
 
# Imports XML 
Try { 
    $CMStatusMsgs = Import-Clixml $XMLPath 
} 
Catch { 
    Write-Host -ForegroundColor Red "Invalid file path or file type.  Please try again." 
    Exit 
} 
 
foreach ($Query in $CMStatusMsgs) { 
      Try {   
           $StatusQuery = @{ 
                Name = $Query.Name 
                Expression = $Query.Expression 
                Comments = $Query.Comments   
            } 
            New-CMStatusMessageQuery @StatusQuery 
            Write-Host -ForegroundColor Green $Query.Name "was created successfully." 
      }  
      Catch { 
            Write-Host -ForegroundColor Red $Query.Name "already exists." 
      }       
}

Export Status Message Queries to XML

What if you wish to export your own Status Message Queries to another environment?  You can leverage the ConfigMgr PowerShell cmdlets: Get-CMStatusMessageQuery and Export-Clixml.

NOTE: Requires the ConfigMgr PowerShell Module

Export all Queries

Get-CMStatusMessageQuery | Export-Clixml <path>StatusMsgQueries.xml

Export only Queries beginning with the name “Audit”

Get-CMStatusMessageQuery -Name Audit* | Export-Clixml <path>Audit_StatusMsgQueries.xml

References: Get-CMStatusMessageQuery, Export-Clixml

I hope this information will help you in becoming a true detective within your environment.  Very special thanks for SaudM on the “Enumerating Status Message Strings” script along with Kevin Kasalonis on his assistance with the content of this blog.

Thank you again for reading!

Brandon McMillan, Premier Field Engineer

Disclaimer: The information on this site is provided “AS IS” with no warranties, confers no rights, and is not supported by the authors or Microsoft Corporation. Use of any included script samples are subject to the terms specified in the Terms of Use.


Office 365 Weekly Digest | March 10 – 16, 2019

$
0
0

Welcome to the March 10 - 16, 2019 edition of the Office 365 Weekly Digest.

There were twelve additions to the Office 365 Roadmap last week, including multiple updates for Office 365 Groups, OneDrive, and Stream. Also of note, is the updated Microsoft 365 admin center with several enhancements. The updated Microsoft 365 admin center is currently rolling out to tenants with Targeted Release enabled.

New events for this week's post include another Outlook Mobile webinar, and another "prenote" SharePoint session. Most of the Customer Immersion Experience sessions have been filled, but there are still opportunities for Teams and Azure Active Directory webinars over the next couple of weeks.

Blog posts in last week's roundup include lots of Teams-related posts, a look at enhancements for SharePoint News in March, the ability to add flagged emails in Microsoft To-Do, the ability to copy a plan in Planner, and the latest installment (Step 6) in the "Top 10 actions to secure your environment" series.

Noteworthy item highlights include new ways to access Microsoft Forms from the suite header of Office.com, a Microsoft IT Showcase video on data and telemetry strategy related to security, and information on how to discover and block legacy authentication in Azure Active Directory.

 

OFFICE 365 ROADMAP

 

Below are the items added to the Office 365 Roadmap last week…

 

Feature ID

App / Service

Title Description

Status

Added

Estimated Release

More Info

49376

Stream

General availability of live events in Microsoft Stream Deliver more engaging communications and training to 10,000 attendees with live events in Microsoft Stream.

In development

03/12/2019

March CY2019

n / a

48534

Office Online

OneDrive

SharePoint

Share and coauthor documents with LinkedIn connections directly from OneDrive, SharePoint, Word, Excel, and PowerPoint Online With this update, users will be able to find many of their first-degree LinkedIn connections as people suggestions when sharing files or folders from the OneDrive and SharePoint websites, or from Word, Excel, and PowerPoint Online. This makes it easier for employees in your organization to collaborate with people outside your organization without needing to know their email addresses.

Rolling out

03/12/2019

March CY2019

n / a

48624

Planner

To-Do

Planner: Integration with Microsoft To-Do Manage Planner tasks assigned to you within Microsoft To-Do. Users can view, edit, and complete Planner tasks from Microsoft To-Do. Add Planner tasks to To-Do's My Day to focus on what's most important to get done.

In development

03/13/2019

April CY2019

n / a

49094

OneDrive

OneDrive: Recommended View on web Leveraging Office's new intelligent services, we're pleased to introduce the new "Recommended View". This view will help you get you to your files faster by recommending files to you based on how you work and how you collaborate with others. It also brings attention to important files relevant to you, that you may not want to miss.

In development

03/13/2019

April CY2019

n / a

49413

Office 365 Groups

SharePoint

Multi-Geo in SharePoint and Office 365 Groups Multi-Geo in SharePoint and Groups enables global businesses control the country or region where shared resources like SharePoint Team Sites, Office 365 Groups content (associated SharePoint Sites and Groups mailboxes) are stored at-rest.

In development

03/13/2019

April CY2019

n / a

49422

OneDrive

Filters in OneDrive Mobile app When you capture a photo, you will now have options to select relevant filters (like b/w) for image correction.

In development

03/13/2019

April CY2019

n / a

49424

OneDrive

OneDrive: Per machine install of sync client Today, the OneDrive sync client installs per-user, meaning OneDrive.exe is installed for every user account on the machine under %localappdata%. With the new per-machine install, admins will be able to install OneDrive under the Program Files (x86) directory. Other than where the sync client is installed, everything else stays the same. The per-machine client will be helpful especially for multi-user machines (kiosks, schools, VDI etc.) and in cases where admins do not want exe files running from the user profile. Over time, we plan to migrate more and more of our install base to per-machine.

In development

03/13/2019

Q3 CY2019

n / a

49375

Stream

Stream: New mobile app features Upload videos to Stream from your mobile device, or record new ones using the Microsoft Stream mobile app. Plus, use channels and groups on to help manage your videos, and interact with Microsoft Forms quizzes in Stream videos – all directly from your mobile device.

In development

03/13/2019

Q4 CY2019

n / a

49423

OneDrive

OneDrive: Time to Read and Inside Look to files You can get deeper information like Key Points from documents and the average time to read. This information can help you make quick decisions about which content to read and how to best prioritize your day.

In development

03/13/2019

Q4 CY2019

n / a

48639

Office 365 Admin

Updated Microsoft 365 admin center The Microsoft 365 admin center, available at admin.microsoft.com, is the common entry point for managing all your Microsoft 365 services. We'll begin rolling out an updated version with new features and functionality in April. During this time, admins will still have access to the old version. All IT admin tasks that can be completed in the admin center today will be supported.
With the change, there is a simplified admin experience with enhancements made in the following areas:
  • Improved user, groups, and settings management to make common, everyday tasks more efficient
  • Targeted, intelligent recommendations and actionable insights to help your org get the most out of your Microsoft 365
  • Tailored admin center experiences for your organization and admin role to provide a focused environment

If you'd like to experience it before general availability, join Targeted Release or click on the toggle in the upper right corner of the admin center dashboard to access the preview.

In development

03/14/2019

March CY2019

n / a

49515

Office 365 Groups

Support the ability for Administrators to update Exchange properties on Office 365 Groups without requiring an Exchange license Administrators who manage Office 365 Groups will now have the ability to modify Exchange properties without requiring an Exchange license. Previously, any attempt to modify an Exchange property would require an Exchange license be assigned to the user attempting to make the change. Administrators without an Exchange license can now update Exchange properties through the Microsoft Admin Center as well as API calls using Microsoft Graph.

In development

03/15/2019

Q4 CY2019

n / a

49537

Office 365 Exchange

Enhancements to URL views in Explorer We have been working on enhancing the email phishing and All-email views in Explorer by adding new functionalities to include additional details on URLs for our ATP P2/ E5 customers helping them drill down for a deeper investigation.  The enhancements include:
  • URLs included in messages
  • Filtering based on URL information
  • Display of URL information in the graph/pivot
  • Safe Links time-of-click data on allowed/blocked clicks from messages

Every time a potentially malicious URL click is detected by change in URL's reputation post-detonation or overridden URL click, an alert is fired with linked details for the admin to take necessary action. This strengthens the loop by enabling analysis on URLs for delivered mail, supporting security analysis for missed phish, data loss, and other security investigations. Since the URL features will be in preview, URL data will be available for days as indicated in the user interface. This will extend as we go GA. We have also enriched phish detection events in the Office 365 management API. The schema will now include email phish and URL click events. We believe these enhanced views are critical to powering security investigation and remediation scenarios across advanced phishing attack vectors.

In development

03/16/2019

March CY2019

n / a

 

 

 

UPCOMING EVENTS

 

Manage Your Enterprise Applications with Azure AD

When: Tuesday, March 19, 2019 at 7am PT | Learn the different ways Azure AD can help you achieve single-sign-on to your enterprise SaaS applications as well as best practices for controlling access for these applications.

 

Manage Your Enterprise Applications with Azure AD

When: Tuesday, March 19, 2019 at 11am PT | Learn the different ways Azure AD can help you achieve single-sign-on to your enterprise SaaS applications as well as best practices for controlling access for these applications.

 

Accelerate productivity with effective search & knowledge across content and people

When: Wednesday, March 20, 2019 at 8am PT | Effective search and discovery needs to know what information is relevant to you, your colleagues, the work you do, and your context right now. Find out how insights assist you across Microsoft 365 to create such a personalized search experience. Add to this organizational knowledge – structured and unstructured help break down knowledge barriers and connect people in new ways by surfacing content and expertise at the right time, in the right context. This prenote will showcase the art of the possible today – so you know the now and are ready for the SharePoint Conference North America in Vegas.

 

Getting Started with Microsoft Teams

When: Wednesday, March 20, 2019 at 10am PT | This 60-minute session introduces you to the key activities needed to get started with Microsoft Teams today. From setting your profile, to running a meeting, users will leave this session with the foundation needed to use Teams with confidence. Check here for sessions in different time zones and other dates. The session is also available on demand at https://aka.ms/teamsgettingstartedondemand.

 

Streamlining Password management Using Azure AD

When: Thursday, March 21, 2019 at 7am PT | Learn how to utilize Azure AD to achieve self-service password management (reset/change) for users and the different ways you can roll it out. This session covers advanced configurations such as on-premises synched passwords and federated authentication.

 

Getting Started with Microsoft Teams

When: Thursday, March 21, 2019 at 8am PT | This 60-minute session introduces you to the key activities needed to get started with Microsoft Teams today. From setting your profile, to running a meeting, users will leave this session with the foundation needed to use Teams with confidence. Check here for sessions in different time zones and other dates. The session is also available on demand at https://aka.ms/teamsgettingstartedondemand.

 

Streamlining Password management Using Azure AD

When: Thursday, March 21, 2019 at 11am PT | Learn how to utilize Azure AD to achieve self-service password management (reset/change) for users and the different ways you can roll it out. This session covers advanced configurations such as on-premises synched passwords and federated authentication.

 

Customer Immersion Experience: Securely managing apps and data on iOS, Android and Windows

When: Friday, March 22, 2019 at 7am PT and 11am PT | Join us for this online, facilitator-led learning experience, built in an Azure environment. This event is designed to allow you to experience real-world solutions that will secure your employees' mobile devices and applications with Microsoft Enterprise Mobility + Security (EMS). During this online experience exploring Microsoft Managed Mobile Productivity solutions, you will learn how implementing Microsoft Intune can provide your employees with access to corporate applications, data, and resources from virtually anywhere on almost any device, while keeping essential corporate data secure. During this interactive session, you will explore how to: (1) Keep corporate data secure, and (2) Utilize Microsoft Intune to provide your employees with access to corporate applications, data, and resources from virtually anywhere on almost any device. Each session is limited to 12 participants, reserve your seat now.

 

Getting Started with Microsoft Teams

When: Tuesday, March 26, 2019 at 8am PT | This 60-minute session introduces you to the key activities needed to get started with Microsoft Teams today. From setting your profile, to running a meeting, users will leave this session with the foundation needed to use Teams with confidence. Check here for sessions in different time zones and other dates. The session is also available on demand at https://aka.ms/teamsgettingstartedondemand.

 

Customer Immersion Experience: Productivity Hacks to Save Time & Simplify Workflows

When: Wednesday, March 27, 2019 at 9am PT and 12pm PT | This 2-hour hands-on session will give you the opportunity to try Microsoft technology that secures your digital transformation with a comprehensive platform, unique intelligence, and partnerships. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Detect and protect against external threats by monitoring, reporting and analyzing activity to react promptly to provide organization security, (2) Protect your information and reduce the risk of data loss, (3) Provide peace of mind with controls and visibility for industry-verified conformity with global standards in compliance, (4) Protect your users and their accounts, and (5) Support your organization with enhanced privacy and compliance to meet the General Data Protection Regulation. Each session is limited to 12 participants, reserve your seat now.

 

10 time saving tips and tricks with Outlook mobile

When: Thursday, March 28, 2019 at 8am PT | Outlook mobile brings together your email, calendar, contacts, documents and more in one fast, fluid experience so you can accomplish the most important tasks in just a few seconds. All backed by enterprise-grade security you can trust. Join the Outlook mobile team for a webinar that will highlight cool tips and tricks that save you time and spark joy. You also get to ask any questions and share feedback with the team directly. In this webinar, you will learn: (1) Why Outlook mobile is the right choice for you, (2) Best practices for getting started, (3) Cool tips and tricks that spark joy and let you accomplish the most important tasks in just a few seconds, and (4) Ask questions or share your feedback directly with the Outlook team.

 

Getting Started with Microsoft Teams

When: Thursday, March 28, 2019 at 10am PT | This 60-minute session introduces you to the key activities needed to get started with Microsoft Teams today. From setting your profile, to running a meeting, users will leave this session with the foundation needed to use Teams with confidence. Check here for sessions in different time zones and other dates. The session is also available on demand at https://aka.ms/teamsgettingstartedondemand.

 

Make the switch from Skype for Business to Microsoft Teams: End User Guidance

When: Friday, March 29, 2019 at 10am PT | Designed specifically for Skype for Business end users, this course offers everything you need to help make the transition to Microsoft Teams. We'll focus on the core communication capabilities you use today, chat and meetings, as well as provide an orientation to additional collaboration functionality Teams has to offer. Check here for sessions in different time zones and other dates. The session is also available on demand at https://aka.ms/fromskypetoteamsondemand.

 

BLOG ROUNDUP

 

What's new in Microsoft Teams – March round up

Microsoft Teams continues to evolve to be the hub for teamwork for workers in all roles and across industries. Recent enhancements include: (1) the ability to work together with up to 5,000 people in the same team, (2) new capabilities to help firstline Workers and healthcare organizations, (3) new features to help transform the classroom, (4) Unified presence, interoperability and Planner integration for Office 365 Government GCC customers. Additionally, new updates to the Microsoft Graph Lifecycles enables you to automate processes and provide familiar experiences to your users. Keep reading to learn more...

Related:

 

SharePoint News Enhancements – March 2019

SharePoint news is a content distribution system that works across personal, team and organizational news. News articles and links can be composed on browser or mobile platforms, and are easily surfaced in portals, Microsoft Teams, email, Microsoft Search and more. Rich new capabilities will empower communicators to keep groups, departments, and divisions up to date easily. New features include: (1) News - organize, (2) Authoritative news, (3) News notifications from followed sites, and (4) Page templates.

 

Flagged emails come to Microsoft To-Do

Microsoft To-Do is always here to help you plan your day, but sometimes an inbox full of urgent emails can get in the way of careful planning. Don't worry, with our latest update, you won't have to juggle your emails and your task list—you can now add your flagged emails to To-Do (for work and school accounts), giving you one unified view of what you need to accomplish today. It's time to get to work ticking off that list. Click on the flagged email task and you'll find a preview of the email and a button to take you to the Outlook website, or your mobile app, where you can see the full email and reply to it. Not ready to reply to it just yet? Jot down some ideas in the notes section or break down your task into Steps. If you are halfway through writing an email and get pulled away to a meeting, flag the draft email and it will also show up in To-Do, reminding you that it still needs to get ticked off when you get back to your desk.

 

Planner's new copy plan feature helps streamline work management

We are pleased to share that we've added the ability to copy plans to Microsoft Planner. We built this feature as the first step to address your feedback that you'd like to reuse project plans and repeat business processes. With copy plan, you can now easily duplicate plans and get organized quickly. It takes a lot of time to build the perfect work management plan. This is especially true when a plan includes a lot of tasks or are part of a repeated process. Manually recreating plans can be tedious and takes time away from actually doing the work. That's where copy plan comes in. With this feature, you can now create a new plan by duplicating an existing one.

 

Top 10 actions to secure your environment: Step 6 - Manage mobile apps

The "Top 10 actions to secure your environment" series outlines fundamental steps you can take with your investment in Microsoft 365 security solutions. In this post, you'll learn how to complete your Unified Endpoint Management (UEM) strategy by using Microsoft Intune Mobile Application Management (MAM). In Step 5, we introduced ContosoCars to illustrate the journey of implementing Intune as part of your UEM strategy. We continue their story to demonstrate how you can enhance endpoint security by managing mobile apps and tracking the deployment.

 

NOTEWORTHY

 

Start Forms journey from office.com

We are thrilled to announce 100% integration of Office.com and Microsoft Forms for our commercial and consumer customers! This means multiple ways for you to create a new form, find an existing form, or search for a form in the suite header of Office.com.

 

Microsoft IT Showcase: Speaking of security - Data and telemetry

Format: Video (54 minutes) | The best tool in a security professional's toolbox for detecting, protecting, and—most importantly—responding to incidents, is intelligence. As the amount of data that we have at our fingertips increases, so does the accuracy of our insights and answers. But there are risks associated with big data as well, including a greater incentive for malicious parties. During this webinar we discuss Microsoft's data and telemetry strategy and share insights and recommendations that you can use.

 

Global Admin Pro Tip: Learn how to build video analytics reporting using Office 365 audit logs

In Microsoft Stream, you can see analytics that show you the popularity of a video based on view, comment, and like counts. If you are a global administrator for Office 365, now you can set up a workflow to pull deeper analytics. This post shares a way to access video engagement analytics by leveraging Office 365 Audit Logs, along with SharePoint and Microsoft Flow, to deliver reports in Power BI. In this training we will cover the following: (1) The data – Unified Audit Logs, (2) Setting up the SharePoint list as the data source, (3) Getting the data, (4) Pulling the data into Power BI, (5) Building a basic report, and (6) Refreshing the data.

 

Azure AD Mailbag: Discovering and blocking legacy authentication

Andres Canello, from the Azure AD Get-to-Production team, is very passionate about helping customers prevent password-based attacks and it is a major topic of concern from customers. Legacy authentication is a key part of these conversations because these protocols and clients are commonly used to perform brute-force or password spray attacks. In this post, Andres will talk about the challenges with legacy authentication and how you can use Azure AD and Microsoft Exchange Online to get better access control. Generally speaking, legacy authentication refers to protocols that use basic authentication (Basic Auth); they only require a single factor authentication of username and password and typically cannot enforce a second factor as part of the authentication flow. On the other hand, modern authentication (Modern Auth) can require second factor authentication, usually the app or service will pop up a browser frame so the user can perform whatever is required as a second factor. This can be entering a one-time code, approving a push notification on the phone, or answering a phone call.

 

Field Notes: The case of Active Directory Diagnostics – Data Collector Set Fails to Start

$
0
0

Performance Monitor is a great tool for collecting and analyzing performance data in Windows and Windows Server.  There are many counters available that one can look at to help understand how the system is performing.  Unfortunately analysis of performance data may not always be straightforward for some system administrators.  Luckily, there is the built-in Data Collector Set for Active Directory Diagnostics in Windows Server once the Active Directory Domain Services role is installed on a machine.  This feature makes the life of an Active Directory administrator easy as most of the analysis is automated.

In this blog post, I briefly explain how the Active Directory Diagnostics works.  I also take you through what I see in some environments where this feature does not work due to inadequate user rights.

The Active Directory Diagnostics Report

Say you are already familiar with the Active Directory (AD) Diagnostics Data Collector Set (DCS) in Performance Monitor, or you have read this blog post and are interested in a report similar to the one below created by the default AD DCS.  In the example, we see that there is a warning indicating that the system is experiencing excessive paging.  The cause here is that available memory on the system is low.  The report also suggests that we upgrade the physical memory or reduce system load.  This report allows us to drill into desired areas of interest such as Active Directory, CPU, network, disk, memory, etc.

 Diagnostics Results

The Data Collector Set Fails to Start

Unfortunately the AD DCS may fail to start in some instances due to inadequate user rights, which I see often in the field.  Instead of starting up and visually indicating with the green play icon as depicted below, there would not even be a pop-up dialog box with a warning or error indicating that there is a problem – the DCS just does not start!

Running Data Collector Set

Attempting to kick of the DCS via command line also does not help:

 Logman Start "SystemActive Directory Diagnostics" –ets 

Behind The Scenes

Before we get into what exactly the issue is and how we would go about resolving it, let us briefly take a look at how this feature works. 

Working environment

The Active Directory Diagnostics DCS leverages the Windows Task Scheduler in order to complete what it is requested to perform.  I grabbed a screenshot from the Task Scheduler to help paint a picture:

Scheduled Task History

Following the sequence of events that took place (reading from bottom to top), we get an idea on what happens behind the scenes when the play button is pressed in Performance Monitor.  Here are a few informational events that stand out:

  • Event ID 100 – Task Started
  • Event ID 200 – Action Started
  • Event ID 201 – Action Completed
  • Event ID 102 – Task Completed


Broken environment

Looking at the task where the Data Collector Set fails to launch, we see the following:

Scheduled Task History

From the image above, we can see Event ID 101.  This event means the Task Scheduler failed to start the AD Diagnostics task for the currently logged on user.

Note: These tasks are created under Microsoft | Windows | PLA |System

Taking a look in the Event Viewer (Microsoft-Windows-TaskScheduler | Operational), there is also an Event ID 104 logged indicating that the task scheduler failed to logon…

Event 104

Required Rights

How do we proceed with this background information?  Taking a look back at the scheduled task, we see the following under general options.  The specified account is the currently logged on user (which is also reflected in Event ID 101):

Task User Account

You may begin to wonder at this stage as you are currently logged on to the DC with an account that is in the Domain Admins group.  What permissions/rights are missing?  The log on as a batch job user right assignment, which determines which accounts can log on by using a batch-queue tool such as the Task Scheduler service. 

Default Behavior

In Windows Server 2012 R2, this setting is set to “Not Configured” in the Default Domain Controllers Policy.  Domain Controllers would then assume the default behavior, which assigns this user right to the following security groups:

  • Administrators
  • Backup Operators

Common Case

If you look at the policy setting (where the DCS fails to start), you would see that user accounts or groups have explicitly been granted the right.  This unfortunately overrides the default behavior – only the accounts and/or security groups listed here have this right (the explain tab lists the default groups):

User Rights Assignment

I observed something interesting when I tested on a few Windows Server 2016 machines in my lab.   Default groups are pre-populated when you modify this setting, therefore, chances of accidentally hurting yourself are lower.

The Fix is Very Easy

Administrators and Backup Operators would have to been added over and above the IDRSfw-service account (in this example) if you still want them to have this user right, as depicted below:

User Rights Assignment

After adding the Administrators group back to the list of security principles allowed to log on as a batch job, the DCS successfully starts:

 Logman Query “SystemActive Directory Diagnostics” – ets 

 

Running Data Collector Set (command-line)

Closure

Be careful when modifying policy settings such as User Rights Assignments as you could end up seeing unexpected results if they are not properly configured.  In this instance, the Administrators and Backup Operators groups would have to be explicitly added with the IDRSfw-service account in order not to negatively impact the default behavior.  Be sure check tools such as the Policy Analyzer and the Security Compliance Manager for guidance on what the recommendations are.  This is one example and there are others, such as the inability to add a new DC to an existing domain due to lack inadequate rights!

Till next time…

Školenie “Docker, Managed Kubernetes a PaaS služby v cloude formou CI/CD” 17.4.2019, Bratislava

$
0
0

Zveme vás na jednodenní technické školení formou praktického workshopu:

Docker, Managed Kubernetes a distribuované PaaS služby v globálním cloudovém prostředí formou CI/CD

  • Školení bude v češtině formou workshopu optimálně s vlastním notebookem
  • Je určeno zejména pro OSS, Linux, Java, Python, .NET Core, JavaScript, … architekty, vývojáře, DevOps leady
  • Kombinace „Dev“ a „Ops“ problematiky, není však třeba znalosti programování.
  • Je dobré znát alespoň základní principy Gitu a ideálně mít free account na GitHubu
  • Prakticky vše bude prováděno v příkazové řádce, v shellech nebo v browseru.
  • Bude probíhat s využitím cloudu Microsoft Azure, není třeba kreditní karty na Azure trial.
  • Netřeba jakákoli znalosti Microsoft technologií, není třeba Windows počítač.
  • Není určeno pro úplné začátečníky (Bez základních znalosti principů kontejnerizace a principů DevOps  budete mít složité " vše stíhat":)
  • Je vhodné si vzít vlastní notebook a všechny technologie zkoušet live, není to však nutné, můžete jen pozorovat jako na přednášce
  • Účast pouze pro registrované, školení je placené - viz níže.
  • Organizuje společnost Gopas ve spolupráci s Microsoft s.r.o.
  • 17.4. 2019, 9:00 - 16:00  (registrace od 8:30),

 

Program:

  • Úvod a běžící Docker aplikace v cloudu
    • Úvod, představení infrastruktury a architektury, prakticky vše na Linuxu
    • Uděláme Spring Boot apku (REST API), kterou zaDockerujeme
    • Vytvoříme si PostgreSQL nebo MongoDB službu
    • Naklikáme vlastní privátní Container Registry kam pushneme Docker Image
    • Rozjedeme vše live v Azure Container Instances
  • Managed Kubernetes
    • Managed Kubernetes jako služba
    • Lehký úvod do Azure Kubernetes Services (AKS)
    • Deployneme Docker image do AKS, pohrajeme si jak live běží a škáluje co s tím můžeme dělat
  • Microservices a Kubernetes prakticky 
    • Microservices prakticky provozované v Managed Kubernetes
    • SPA + REST API s PostgresSQL  + REST API s MongoDB jako službu
    • Deployment celého řešení do AKS včetně ingress controleru
  • Azure Kubernetes Services do hloubky
    • Deep dive do Azure Kubernetes Services
    • Networking
    • Management
    • Security
    • Škálovaní
  •  Jak na CI/CD a další ukázky  
    • Jenkins, Azure DevOps, GitHub, … to je vlastně v Azure jedno
    • Ukázka Build a Release pilelines , parametrizace (rozlišeni produkce, dev, test prostředí)
    • Helm, Env. variables
    • Config mapy a sekrety,  KeyVault a další vychytávky
  • Závěr, Q&A, Podpora vašich projektů

Kdo bude přednášet?

Placené školení, sleva z 100 EUR na 20 EUR sponzorským kódem

Kdy a Kde?

  • 17.4. 2019, (registrace od 8.30) 9:00 - 16:00
  • Přednáškové prostory společnosti Microsoft Slovakia, Apollo II. E/3p, Prievozská 4D, 821 09 Bratislava-Ružinov, Slovensko
  • Občerstvení zajištěno a v ceně kurzu

Registrace

 

 

Těšíme se na viděnou,
Jiří Burian, Microsoft

Nueva Dirección

$
0
0

Tenemos Nueva Dirección.

Estimados Socios Microsoft.

 

En un esfuerzo por brindarles un mejor servicio, estamos migrando nuestro blog de socios a una nueva ubicación.

 

Ahora vamos a formar parte del portal de Socios Microsoft en la sección de blogs para adherirnos a los estándares para los socios.

 

La nueva ubicación de Blog para socios LATAM es:

https://blogs.partner.microsoft.com/mpn-latam/

 

Nuestra dirección corta http://aka.ms/latampts va a continuar trabajando direccionando a la nueva ubicación.

 

 

Vamos a estar publicando nuevamente los artículos que mas consulta tienen para sus futuras referencias.

 

Esten al pendiente, y si tienen alguna publicación que vean se expiro en esta version, avísennos para publicarla en la nueva direccion.

 

Saludos

 

Mariano Carro

Enviar correo a latampts

 

BYOL Microsoft Server license to the Cloud: Azure Hybrid Benefit vs License Mobility. What is the difference?

$
0
0

When an organization deploys a solution built on Microsoft platform to the Cloud there are 2 primary options how Microsoft Server products can be licensed. First, the organization can acquire Microsoft product subscription along with other cloud services such as virtual machines from the Cloud provider, another option is to bring your own license (BYOL) to the Cloud. Second option in most of the cases provides significantly better TCO.

For example, by bringing SQL Server, Windows Server licenses to Azure organizations can realize significant savings in Azure.

Here is an example for SQL Server Enterprise comparing Bring Your Own License to Azure scenario vs buying SQL Server Enterprise license as a part of Azure subscription (please find the detailed view here):

SQLblog1

The rules of BYOL are different for Microsoft Cloud (Azure) and other Clouds. The BYOL programs for Azure and other cloud providers also have different names. For other cloud providers program name is License Mobility because it actually allows moving licenses between on premises datacenter and the cloud provider. For Azure the BYOL program name is Azure Hybrid Benefit (AHB), and it is an extension of License Mobility offer.

Key requirement to leverage AHB or License mobility offers is an active Software Assurance for the server product or an active server product subscription.

The tables below summarize the key difference between AHB and Licenses Mobility for SQL Server and Windows Server.


SQL Server

Cloud type:

Microsoft Azure

Other Clouds (GCP, AWS, other hosting providers)

Offer name:

Azure Hybrid Benefit

License Mobility

IAAS scenario:

BYOL to a Virtual Machine (VM) in the Cloud

1 SQL Server ENT/STD Core license provides the rights to run 1vCore in the Cloud VM

Each VM in the Cloud should have at least 4 SQL Server Core Licenses assigned.

For example, if you have only 2 vCore VM you still need to assign 4 SQL Server Core licenses to this VM.

1 SQL Server ENT/STD Core license provides the rights to run 1vCore in the Cloud VM

Each VM in the Cloud should have at least 4 SQL Server Core Licenses assigned.

For example, if you have only 2 vCore VM you still need to assign 4 SQL Server Core licenses to this VM.

PAAS scenario:

BYOL to a SQL Server Managed Service (shared infrastructure)

Yes, organization can bring SQL Server licenses with active SA to Azure SQL Managed Instance.

If you have Enterprise Edition per core licenses, you can get 4 vCores in the Azure SQL Managed Instance General-Purpose Tier for every SQL license core you own on-premises. This is a unique benefit available only on Azure.

If you have Standard Edition per core licenses with Software Assurance, you can get one vCore in the general-purpose tier for every SQL Server license core you own on-premises.

No, BYOL SQL Server license scenario is not available for Managed services such as AWS RDS and others.

Can we use our SQL Server license on-premises AND in the cloud simultaneously?

No, your SQL Server licenses must be used either on-premises OR in Azure;

however, you have a 180-day grace period during which you can use licenses both on-premises and in the cloud to facilitate migration

No, your SQL Server licenses must be used either on-premises OR in the cloud;


Windows Server

Cloud type:

Microsoft Azure

Other Clouds (GCP, AWS, …)

Offer name:

Azure Hybrid Benefit

License Mobility

IAAS scenario: BYOL to a Virtual Machine in the Cloud

Azure Hybrid benefit is available for Windows Server.

For virtual machines running 24x7 this option provides significant savings compared with buying SQL Server subscription from the cloud provider

No BYOL for Windows Server. The Windows Server license subscription can be acquired along with VM from the cloud provider.

Can our Windows Server license be used on premises AND in the cloud simultaneously?

The Azure Hybrid Benefit for

Windows Server Standard Edition licenses can only be used once either on-premises OR in Azure.

Windows Server Datacenter Edition benefits allow for simultaneous usage both on-premises AND in Azure.

Each 2-processor license or each set of 16-core licenses are entitled to two instances of up to 8 cores, or one instance of up to 16 cores.

No BYOL

The differences between Azure Hybrid benefits and License Mobility listed above are one of the reasons why Azure is the most cost-effective cloud for Windows Server and SQL Server.

clip_image005[7]

If you are interested to learn more about SQL Server licensing please watch this webinar: Demystifying SQL Server 2017 and How to Buy.

I want to say Big Thank you to Jai Dhir, Microsoft Licensing Manager for reviewing the blogpost and providing valuable feedback.

Please let us know if you have any comments, questions of feedback by sending email to CanadaDataPlatform@microsoft.com

This blogpost is for information purposes only, for the official Microsoft documentation on Azure Hybrid Benefit and License Mobility please check these links:

Viewing all 36188 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>