Posts

Five reasons to run SQL Server 2016 on Windows Server 2016

The Microsoft SQL Server team is publishing a five-part series on why to run SQL Server 2016 on Windows Server 2016.   Can you guess reason #1?   Yes, it's security.  We're going to see a much bigger push on the MS front addressing its commitment to a holistic security approach across the whole Microsoft stack, building and integrating security throughout its platforms, and product and service offerings.  Read on to see how SQL Server 2016 on Windows Server 2016 increase your security posture, using features such as Device Guard, Credential Guard, Control Flow Guard and Windows Defender on Windows Server 2016 and Always Encrypted protection, Row-Level Security and Dynamic Data Masking in SQL Server 2016. https://blogs.technet.microsoft.com/hybridcloud/2017/03/23/five-reasons-to-run-sql-server-2016-on-windows-server-2016-1-security/ The second part of the series focuses on the performance increases and cost savings that can be had with SQL Server 2016 on Windows...

Happy Birthday EMS: How cloud architecture and customer obsession is disrupting EMM

Read on for Brad Anderson's reflections on the disruptive nature of the cloud, on the three year anniversary of EMS. https://blogs.technet.microsoft.com/enterprisemobility/2017/03/27/happy-birthday-ems-how-cloud-architecture-and-customer-obsession-is-disrupting-emm/

Perspectives on the New Intune Console

Check out Brad Anderson's perspective on the new Intune console that is now part of the Azure admin portal. We're finally seeing the convergence of the various EMS offerings into one single glass of pane. https://blogs.technet.microsoft.com/enterprisemobility/2017/01/24/perspectives-on-the-new-intune-console/ Also, watch Brad go over the changes and how to use them in this video from Channel 9's Endpoint Zone: https://channel9.msdn.com/Series/Endpoint-Zone/The-Endpoint-Zone-with-Brad-Anderson-1701

Cyber Security Attackers Toolkit – What You Need to Know

For the security-interested, a more technical look at the tools attackers use during a cyber attack and how Advanced Threat Analytics plays a role in detecting these attacks and provides a higher level of visibility into them. https://blogs.technet.microsoft.com/enterprisemobility/2017/01/24/cyber-security-attackers-toolkit-what-you-need-to-know/

Eliminating Plaintext Passwords With Microsoft Advanced Threat Analytics Using LDAP

Happy New Year to everyone! To start off 2017 on an easy note, have a look at this article regarding the use of Microsoft Advanced Threat Analytics (ATA) to identify those applications and services that may still be sending passwords in plaintext in your network environment.  This is typically the result of simple LDAP binds being used for authentication purposes, which exposes your environment to attacks focused on privilege escalation. https://blogs.technet.microsoft.com/enterprisemobility/2017/01/09/eliminating-plaintext-passwords-with-microsoft-advanced-threat-analytics-using-ldap/

New survey shows hybrid is leading approach, security waning as blocker to cloud adoption

A posting by Julia White on the key findings from a survey of cloud use in 2016. Notably, hybrid deployments will continue to be the deployment model for years to come; vendor lock-in and privacy are moving up in terms of concerns; and security in the cloud remains a hot topic, but the nature of it has changed, with 50% of respondents seeing it as a benefit to cloud adoption, and the other half seeing it as a blocker. https://azure.microsoft.com/en-us/blog/new-survey-shows-hybrid-is-leading-approach-security-waning-as-blocker-to-cloud-adoption/

Risk-based Conditional Access now in the new Azure portal

Microsoft now allows you to apply risk-based conditional access policies at the Azure AD application level, providing you with real-time detection and automated protection that is fueled by the vast data in Microsoft’s Intelligent Security Graph. Today, several improvements to conditional access in have been published through the new Azure Portal: Risk-based access policies per application: Leverage machine learning on a massive scale to provide real-time detection and automated protection. Now you can use this data to build risk-based policies per application. Greater flexibility to protect applications: Set multiple policies per application or set and easily roll out global rules to protect all your applications with a single policy. All these capabilities are now available in a unified administrative experience on the Azure portal. This makes it even easier to create and manage holistic conditional access policies to all your applications. https://blogs.technet.microsoft....

Will Advanced Threat Analytics help me with all operating systems?

Short answer is yes, but there is a qualifier.  The activity still needs to hit Active Directory (AD), whether by connecting to the network via AD, querying the DNS servers, or authenticating with AD.  All that activity is inspected for anomalous activities, regardless of the operating system. https://blogs.technet.microsoft.com/enterprisemobility/2016/12/12/will-advanced-threat-analytics-help-me-with-non-windows-oss/

More enhancements to the Azure AD Admin experience in the new Azure Portal

Another public preview release of the Azure Portal is coming, with enhancements focused on enterprise app management. https://blogs.technet.microsoft.com/enterprisemobility/2016/12/09/more-enhancements-to-the-azuread-admin-experience-in-the-new-azure-portal/ https://docs.microsoft.com/en-us/azure/active-directory/active-directory-enterprise-apps-whats-new-azure-portal

Introducing Azure AD Pass-Through Authentication and Seamless Single Sign-on

Now in public preview, Azure AD Pass-Through Authentication is a 3rd alternative in the options for “single sign-on” between Active Directory and Azure AD.  Designed to remove the infrastructure requirements of AD Federation Services, it provides a more seamless SSO experience than the Password Hash Sync through AAD Connect.    With the use of AAD Connect and a simple connector, AAD PTA relies on secure outbound communication to validate username  and password credentials against your on-premises Active Directory.  No need to sync AD passwords to AAD, nor deploy AD FS! https://blogs.technet.microsoft.com/enterprisemobility/2016/12/07/introducing-azuread-pass-through-authentication-and-seamless-single-sign-on/ https://docs.microsoft.com/en-us/azure/active-directory/active-directory-aadconnect-pass-through-authentication

Microsoft Intune in the Azure portal Preview

Microsoft Intune is moving to the Azure portal and the public preview has started.  The initial release includes the following capabilities: Deploy and manage apps from a store to iOS, Android, and Windows devices Deploy and manage line of business (LOB) apps to iOS, Android, and Windows devices Deploy and manage volume-purchased apps to iOS, and Windows devices Deploy and manage web apps for Android, iOS, and Windows devices Volume-purchased apps for iOS (business and education) iOS managed app configuration profiles Configure app protection policies, and deploy LOB apps to devices that are not enrolled with Intune VPN profiles, per-app VPN, Wi-Fi, email, and certificate profiles Compliance policies Conditional access for Azure AD Conditional access for On-Premises Exchange Device enrollment Role-based access control https://docs.microsoft.com/en-us/intune-azure/introduction/what-is-microsoft-intune

An Introduction to Microsoft Azure Information Protection

As Azure Information Protection evolves from its Microsoft Rights Management Services roots, I’m sure we’ll start seeing a lot more uptake,  especially the auto-classification features baked into the Office suite .   Check it out! https://www.youtube.com/watch?v=N9Ip0m6d3G0

Azure AD Identity Protection and Azure AD Privileged Identity Management Subscription Requirements

With Azure AD Identity Protection and Azure AD Privileged Identity Management now generally available as part of AAD Premium P2, starting Monday December 5 2016 (TODAY!!), Microsoft is enabling license enforcement for existing tenants using Azure AD PIM.  Without an AAD P2 subscription or trial, tenants with AIP and PIM will see those capabilities disabled/removed. Azure AD PIM will no longer be available in your tenant if: Your organization was using Azure AD PIM when it was in preview and does not purchase Azure AD Premium P2 Your organization had an Azure AD Premium P2 trial that expired Your organization had a purchased subscription that expired When an Azure AD Premium P2 subscription expires, or an organization which was using Azure AD PIM does not obtain Azure AD Premium P2: Permanent role assignments to Azure AD roles will be unaffected. The Azure AD PIM extension in the Azure portal, as well as the Graph API Cmdlets and ...

Cloud Platform Roadmap

Microsoft's public Cloud Platform roadmap that provides high-level insights into what features were recently made generally available and what's in public preview and in development. It covers Cloud Infrastructure, Enterprise Mobility, Data Management and Analytics, Application Development and the Internet of Things: https://www.microsoft.com/en-us/cloud-platform/roadmap-public-preview?TabIndex=1&dropValue=AllProducts

EMS Scenario-Based Content

Microsoft has added scenario-based guidance to their Enterprise Mobility + Security (EMS) documentation,  to help clients understand how to use EMS services to deliver secure productivity.  The catalog of use cases is supposed to grow over the coming months. https://blogs.technet.microsoft.com/enterprisemobility/2016/12/02/a-new-destination-for-ems-scenario-based-content/

Real world Azure AD Connect: multi forest user and resource + user forest implementation

Insightful post about deploying AAD Connect in a truly multi-forest scenario and having to deal with precedence issues: http://www.clouduccino.com/2016/12/real-world-azure-ad-connect-multi-forest-user-and-resource-user-forest-implementation/

Disrupting the Cyber Kill Chain

Great blog describing the cyber kill chain ( how attackers infiltrate and compromised an organization’s networks and systems ) and how Microsoft Secure and Productive Enterprise (SPE) offerings can be used to disrupt the kill chain. http://blogs.microsoft.com/microsoftsecure/2016/11/28/disrupting-the-kill-chain/

Microsoft Teams: How to overcome challenges with Windows Information Protection & Conditional Access

Ronny De Jong, over at Modern Workplace , provides some great insight in how to deploy Microsoft Teams alongside Windows Information Protection and Conditional Access: https://ronnydejong.com/2016/11/30/microsoft-teams-how-to-overcome-challenges-with-windows-information-protection-conditional-access/

New to Office 365 in November—new collaboration capabilities and more

Collaboration and cloud are on the menu!  Updates this month include real-time co-authoring in PowerPoint, shared cloud documents in Outlook, and mobile notifications of changes to shared documents.  https://blogs.office.com/2016/11/29/new-to-office-365-in-november-new-collaboration-capabilities-and-more/

Application built on Hello.js with Azure ADB2C

Code sample showing how to build a web application using Hello.js that performs identity management with Azure AD B2C: https://github.com/Azure-Samples/active-directory-b2c-javascript-singlepageapp-dotnet-webapi