Azure Marketplace new offers – Volume 81

Azure Marketplace new offers – Volume 81

This article is contributed. See the original author and article here.

We continue to expand the Azure Marketplace ecosystem. For this volume, 111 new offers successfully met the onboarding criteria and went live. See details of the new offers below:

Applications

ALFRED - AI Health Claims Automation.png

ALFRED – AI Health Claims Automation: ALFRED on Microsoft Azure is an automated, end-to-end health and medical claims platform for cashless (planned or emergency) and post-discharge (reimbursement) claims processing with payout in less than 15 minutes.

Amelia.png

Amelia: Amelia is a comprehensive conversational AI agent that listens and interacts with people to solve problems. Able to take on a wide variety of business and engineering tasks, Amelia reads natural language, understands context, applies logic, infers implications, and learns through experience.

Application Access Governance for Dynamics 365.png

Application Access Governance for Dynamics 365: Saviynt’s application access governance solution for Microsoft Dynamics 365 provides segregation of duty (SoD) management and continuous compliance monitoring with intelligent lifecycle management and risk-based access reviews to ensure users have access to the right data at the right time.

AUSIS - AI Underwriting Platform.png

AUSIS – AI Underwriting Platform: Artivatic Data Labs’ AUSIS is an AI-based underwriting automation and instant-decision platform that enables insurance businesses to perform real-time assessment for policyholders for risk, pricing, and policy decisions.

backdrop Powered by Miri.png

Backdrop Powered by Miri: Use Backdrop CMS to create websites ranging from a single administrator’s personal blog to a complex, multi-role e-commerce platform. Backdrop is easily expandable with add-ins, modules, and themes to ensure your website fits your needs.

Bot Foundry in Azure (SaaS).png

Botfoundry in Azure (SaaS): Hosted on Microsoft Azure and powered by Azure Bot Service and Language Understanding (LUIS), Botfoundry enables you to build bots tailored to individual users and global organizations.

CareFlow Vitals - electronic observations system.png

CareFlow Vitals – electronic observations system: CareFlow Vitals is an observation and decision-support system designed to improve patient safety and outcomes. It calculates early warning scores, monitors and analyzes patient vital signs to identify deteriorating conditions, and provides risk scores to trigger escalation pathways.

CARSURE-Auto & Vehicle Damage Assessment & Claims.png

CARSURE – Auto & Vehicle Damage Assessment & Claims: Available on-premises or in the cloud, CARSURE is an AI-based platform for vehicle damage estimation and for assessment and claims automation. It eliminates the need for physical inspection by detecting damage using photos, video, or guided mobile tools.

Cloud PAM for Azure, Azure AD and Microsoft 365.png

Cloud PAM for Azure, Azure AD, and Microsoft 365: Saviynt’s Cloud Privileged Access Management (Cloud PAM) solution provides privileged access to Microsoft Azure consoles and workloads and Azure Active Directory, along with tenant administration for Microsoft 365 applications, Azure services, and more.

Conversational AI for Healthcare.png

Conversational AI for Healthcare: Hyro’s conversational AI for healthcare seamlessly transforms troves of data into conversational interfaces powered by natural language understanding (NLU), simplifying the patient journey across channels such as websites, applications, and call centers.

Conversational Analytics.png

Conversational Analytics: Data Semantics Pvt. Ltd.’s Conversational Analytics platform on Microsoft Azure enables voice assistants and chat messengers to report real-time key performance indicators (KPIs) from business intelligence dashboards, CRM, ERP, and IT service management applications.

Covid_19_Assessment.png

COVID-19_Assessment: By providing a patient-centric care team model, dClinic’s private healthcare blockchain (PHB) and COVID-19 assessment platform help break down the traditional barriers of one-on-one interactions and data silos in healthcare.

Delair ai - Visual Intelligence for Infrastructure.png

Delair.ai – Visual Intelligence for Infrastructure: The delair.ai platform rapidly and repeatedly analyzes imagery of enterprise assets to help improve reliability, manage projects, and lower operating costs. The AI-powered solution enables companies to manage, view, analyze, and collaborate around digital twins of assets.

Delphix Masking for Azure (3TB).png

Delphix Masking for Azure (3TB): Delphix masking for Microsoft Azure enables you to find, mask, and govern up to 3 terabytes of sensitive data to maintain compliance in non-production environments. Secure relational databases, cloud-native data sources, and files for use by development and test teams.

Desk To Go.png

Desk To Go: Accessible via any device, Desk To Go is a virtual desktop solution hosted on Microsoft Azure. Work from anywhere with access to all your files as if you were right in front of your computer. This app is available in Portuguese, Spanish, and English.

DgSecure.png

DgSecure: DgSecure data provisioning monitors access to elements containing raw, sensitive data; provides thorough identity inventory and classification of sensitive data; and delivers back-end automation of data subject requests for privacy standards, such as CCPA and GDPR.

DNS Server (IaaS) for Ubuntu 18.04 LTS.png

DNS Server (IaaS) for Ubuntu 18.04 LTS: Tidal Media offers an Ubuntu 18.04 LTS image configured with DNS Server (IaaS), providing security-, performance-, and operations-related insights into the DNS infrastructure of your organization by collecting, analyzing, and correlating analytic and audit logs and other related data from DNS servers.

Dotclear CMS powered by MIRI.png

Dotclear CMS powered by MIRI: Written in PHP, the Dotclear content management system on Microsoft Azure respects web standards based on open-source solutions with multilingual interface and publishing capabilities.

EcoStruxure for Healthcare.png

EcoStruxure for Healthcare: EcoStruxure for Healthcare is an IoT-based platform designed to help healthcare facilities of all sizes improve operational efficiency and patient safety and satisfaction through modernized infrastructure management.

eDiscoveryPro - Prosecution Innovation Software.png

eDiscoveryPro – Prosecution Innovation Software: Data Vision Group LLC’s eDiscoveryPro is a scalable, highly secure application that complies with the FBI’s Criminal Justice Information Services. eDiscoveryPro enables district attorney’s offices to facilitate the transformation of paper-based workflows to digital processes.

ESPOCRM powered by MIRI.png

EspoCRM powered by MIRI: EspoCRM on Microsoft Azure provides companies and organizations with actionable insights that can help them enhance products and services, build and maintain fruitful relationships with customers, boost revenue, and drive business growth.

ExpectID.png

ExpectID: IDology’s ExpectID enables you to find and approve legitimate identities while also deterring fraud. It completes identity verification with as little as a name and an address, allowing you to quickly validate customer identity to drive revenue and perform appropriate due diligence.

ExponentCMS powered by MIRI.png

ExponentCMS powered by MIRI: Exponent CMS is an open-source content management system written in PHP and designed to help site owners develop and easily manage dynamic websites without having to code web pages or manage site navigation.

Fathym Low-Code Framework.png

Fathym Low-Code Framework: The Fathym Low-Code Framework enables developers to host, manage, and deploy data-driven applications that are tool-, platform-, and cloud-agnostic. It reduces development time by applying best-practice workflows for cloud infrastructure automation and app orchestration.

Firebird SQL RDBMS on Windows Server 2016.png

Firebird SQL RDBMS on Windows Server 2016: Cloud Infrastructure Services offers this image of Firebird, an open-source SQL relational database management system, configured on Windows Server 2016. Firebird offers ANSI-standard SQL features, concurrency, high performance, and powerful language support for stored procedures and triggers.

Firebird SQL RDBMS on Windows Server 2019.png

Firebird SQL RDBMS on Windows Server 2019: Cloud Infrastructure Services offers this image of Firebird, an open-source SQL relational database management system, configured on Windows Server 2019. Firebird offers ANSI-standard SQL features, concurrency, high performance, and powerful language support for stored procedures and triggers.

FreePBX 15 supporting commercial add-on modules.png

FreePBX 15 supporting commercial add-on modules: Build a cloud phone system, a call center, a traditional PBX with desk phones, or a fully software-based experience using WebRTC or softphones with FreePBX on Microsoft Azure. FreePBX includes a strong core-feature set and a large ecosystem of add-on modules.

Frogmi Store Operations.png

Frogmi Store Operations: Frogmi is a task management solution for retail that enables store managers, supervisors, and quality control personnel to perform store audits that automatically trigger tasks to support areas and then track the resolution of those tasks.

FrontAccounting powered by MIRI.png

FrontAccounting powered by MIRI: FrontAccounting on Microsoft Azure is a web-based accounting system for the entire ERP chain written in PHP and using MySQL. It enables users to submit purchase orders, maintain supplier accounts, send payments, and generate financial reports.

Gender Fitness.png

Gender Fitness: Gender Fitness helps raise awareness of the gender balance in your meetings and delivers valuable insight into inclusion and participation. The application links to your organization’s Office 365 calendars and provides a simple two-question survey to attendees for each meeting.

Geolog.png

Geolog: Based on the Epos data management infrastructure, Geolog on Microsoft Azure offers petrophysical and geological analysis tools, well data management, and robust data integration.

GetSimpleCMS powered by MIRI.png

GetSimpleCMS powered by MIRI: Designed for small organizations and individuals who need a small-to-midsize website, GetSimpleCMS makes content management adaptable to users’ needs by creating suitable designs for tablets, desktops, smartphones, and other devices.

Gitea - Git Server for Ubuntu 18.04.png

Gitea – Git Server for Ubuntu 18.04: Gitea is a powerful and easy-to-maintain self-hosted Git service. It supports Git revision control and provides other collaborative features, including bug/issue tracking, development wiki pages, and code review.

Graphnet CareCentric - shared care record.png

Graphnet CareCentric – shared care record: CareCentric integrates detailed information from acute hospitals, mental health and community organizations, general practices, and social care into a single digital care record available to clinicians and care professionals.

Helpdesk.png

Helpdesk: SteadyPoint Solutions’ Helpdesk is an IT service management system for assisting service desks with IT and non-IT trouble tickets. Designed to help small and medium-sized enterprises take their office experience to the next level, Helpdesk makes collaboration simple with the familiar Office 365 look and feel.

Hexator.png

Hexator: Intended for software developers, web coders, and administrators, Hexator is an online tool for hexadecimal encoding and decoding. Hexator encodes and decodes data from binary or text format to hexadecimal via copy and paste or file upload.

I&D PORTAL.png

I&D PORTAL: The I&D Portal platform for the financial sector streamlines business processes to help companies embrace digital transformation and reduce the costs, time, and resources associated with maintaining security control and compliance.

InMobi Telco AdCloud-in-a-box.png

InMobi Telco AdCloud-in-a-box: InMobi offers end-to-end cloud-based ad operations for global telecommunications companies (telcos) and mobile OEMs. Telcos can set up an internally managed ad operation to monetize devices, users, and data, while mobile OEMs can utilize a device monetization suite run by InMobi.

Insignia Gatekeeper.png

Insignia Gatekeeper: Gatekeeper from Insignia Medical Systems automatically copies your picture archiving and communication system (PACS) and radiology information system (RIS) medical images to your Microsoft Azure environment, protecting against local disasters and malicious attacks with secure, write-once Azure storage.

KALE LOGISTICS UPLIFT PORT COMMUNITY SYSTEM.png

KALE LOGISTICS UPLIFT PORT COMMUNITY SYSTEM: Port Community Systems (PCS) from Kale Logistics Solutions enables secure information exchange between public and private stakeholders, improving the efficiency of seaports and airports. PCS optimizes, manages, and automates port processes by connecting transport and logistics chains.

KeePass Password Safe on Windows Server 2016.png

KeePass Password Safe on Windows Server 2016: Cloud Infrastructure Services offers this image configured with the open-source KeePass software. KeePass encrypts passwords and other sensitive information, such as documents, ATM PINs, and credit card numbers, using a master password or key file to secure the KeePass database.

Managed Backup Services.png

Managed Backup Services: Integrity Partners offers a managed service of dedicated backups for Office 365, including Microsoft Exchange Online, OneDrive for Business, SharePoint Online, and Microsoft Teams. Manage and monitor backups via web or mobile.

Mantis powered by MIRI.png

Mantis powered by MIRI: Miri Infotech offers a version of Mantis Bug Tracker, an open-source bug-tracking system, preconfigured for running on Microsoft Azure. Features include tracking issues through a simple web-based interface; custom notifications; project management graphs; and time tracking.

MedDream.png

MedDream: DICOM Viewer by MedDream, a Softneta company, is a vendor-neutral medical image application that can be installed on Azure. The app integrates with patient portals, telemedicine systems, electronic health records, and any picture archiving system (PACS), including MedDream PACS, Orthanc, and more.

MediaWiki - Wikipedia Server on Ubuntu 18.04 LTS.png

MediaWiki – Wikipedia Server on Ubuntu 18.04 LTS: Tidal Media offers an Ubuntu server image configured with MediaWiki, a free and open-source wiki server. MediaWiki is a powerful, scalable software package and a feature-rich wiki implementation that uses PHP to process and display data stored in a database, such as MySQL.

Medium Sentinel Services Scope.png

Medium Sentinel Services Scope: Integrity Partners Sp. z o.o. will deploy Microsoft Azure Sentinel in your environment so you can implement it in your security operations center (SOC). Receive cloud-native SIEM, enhanced security visibility across cloud and on-premises environments, and more.

Microsoft SQL Server Developer for Ubuntu 18-04.png

Microsoft SQL Server 2019 Developer for Ubuntu:18-04: Ntegral’s database container image contains Microsoft SQL Server 2019 Developer Edition on Ubuntu 18.04. It includes all the functionality of Enterprise Edition but is licensed for use as a development and test system, not as a production server.

Microsoft SQL Server Enterprise for Ubuntu18-04.png

Microsoft SQL Server 2019 Enterprise for Ubuntu:18-04: Ntegral’s database container image contains a bring-your-own-license version of Microsoft SQL Server 2019 Enterprise Edition on Ubuntu 18.04. Enterprise Edition is ideal for apps requiring mission-critical in-memory performance, security, and high availability.

Microsoft SQL Server Express for Ubuntu 18-04.png

Microsoft SQL Server 2019 Express for Ubuntu:18-04: Ntegral’s database container image contains Microsoft SQL Server 2019 Express Edition on Ubuntu 18.04. Express Edition is freely downloadable and distributable.

Microsoft SQL Server Standard for Ubuntu 18-04.png

Microsoft SQL Server 2019 Standard for Ubuntu:18-04: Ntegral’s database container image contains a bring-your-own-license version of Microsoft SQL Server 2019 Standard Edition on Ubuntu 18.04. Ntegral packages applications following industry standards and monitors all components and libraries for vulnerabilities and updates.

Minimum Sentinel Services Scope.png

Minimum Sentinel Services Scope: Integrity Partners Sp. z o.o. will perform a minimal deployment of Microsoft Azure Sentinel in your environment, performing remote monitoring and optional threat hunting. Receive cloud-native SIEM, enhanced security visibility across cloud and on-premises environments, and more.

MiO - PoS, Agent Sales & Video Branches.png

MiO – PoS, Agent Sales & Video Branches: MiO from Artivatic Data Labs is an integrated, video-based insurance platform designed to support digital branch applications for insurance policies, brokers, point-of-sale connections to customers, lead generation, and policy distribution.

MistServer Streaming Media Toolkit for Ubuntu.png

MistServer Streaming Media Toolkit for Ubuntu: Tidal Media offers an Ubuntu server image configured with MistServer, an open-source streaming-media toolkit for over-the-top (OTT) internet streaming. MistServer allows you to take any media from any location using any method, and deliver it to anyone, anywhere, in any format.

Mix.png

Mix: Nuance’s Mix is a platform for creating advanced conversational experiences for chatbots and interactive voice response systems. With one tooling platform across the full software development lifecycle, enterprises gain greater control, accelerated development time, and increased business agility.

Nuvepro Cloud Labs.png

Nuvepro Cloud Labs: Cloud Labs from Nuvepro Technologies Pvt. Ltd. is a marketplace and software-as-a-service platform that provides hands-on labs for fast and effective learning. Use the self-service portal to rapidly deploy and access a sandbox environment configured with a technology stack and compute power on a cloud of your choice.

NVIDIA Image for AI - Optimized for PyTorch.png

NVIDIA Image for AI – Optimized for PyTorch: Deploy on Microsoft Azure a virtual machine configured with NVIDIA’s PyTorch distribution, certified for maximum performance on NVIDIA GPUs and easy access to NVIDIA NGC. NGC is a hub for GPU-optimized software for deep learning, machine learning, and high-performance computing.

NVIDIA Image for AI - Optimized for TensorFlow.png

NVIDIA Image for AI – Optimized for TensorFlow: NVIDIA’s GPU-optimized TensorFlow container included in this image will fast-track your end-to-end AI deployment and development process. Supported Azure virtual machine instances are NCv2, NCv3, and ND series.

NVIDIA Image for AI using GPUs.png

NVIDIA Image for AI using GPUs: NVIDIA NGC is a hub for GPU-optimized software for deep learning, machine learning, and high-performance computing. Containers from NGC require this image, and the supported Microsoft Azure virtual machine instances are the NCv2, NCv3, and ND series.

October CMS powered by MIRI.png

October CMS powered by MIRI: This offer from Miri Infotech contains a hardened image of October CMS, a content management system designed to make website creation, design, and editing faster and more intuitive. October CMS is based on the PHP programming language and the Laravel web application framework.

Omeka powered by MIRI.png

Omeka powered by MIRI: This offer from Miri Infotech contains a hardened image of Omeka, an open-source content management system for cultural institutions such as libraries and museums. Omeka is written in PHP and uses the Zend web application framework.

Opensource Social Network (OSSN) on Ubuntu 18.04.png

Opensource Social Network (OSSN) on Ubuntu 18.04: This ready-to-run software offered by Tidal Media allows you to create a social networking website. The quick-deployment image will launch Open Source Social Network (OSSN) on Ubuntu 18.04.

pivotx Powered by Miri.png

pivotx Powered by Miri: This virtual machine offered by Miri Infotech contains PivotX CMS, open-source software used for maintaining blogs, online journals, and other frequently updated websites. PivotX CMS is written in PHP and uses MySQL or flat files as a database.

Python escaper.png

Python escaper: PythonEscaper by Glueo is an online tool for software developers and administrators who need to update a string in Python code and want to avoid the tedious work of doing it manually. PythonEscaper supports escaping and unescaping string literals.

Quick Decisions, SAP Business One en Power BI.png

Quick Decisions, SAP Business One in Power BI: Streamline your SAP Business One decision-making with Innovación Orientada al Cliente’s pre-built dashboards in Microsoft Power BI. Dashboard categories cover sales, sales details, purchases, inventory, and accounts receivable. This offer is available only in Spanish.

RiskCenter360.png

RiskCenter360: RiskCenter360 from Evertec enhances risk-management and fraud-prevention strategies with intuitive analytical tools, robust rules, and an analyst-friendly environment console for addressing alerts. This app is available in Spanish, Portuguese, and English.

RiskMaster Creatio.png

RiskMaster Creatio: RiskMaster Creatio makes risk-registration and risk-management processes easy and transparent. It can be used to manage a particular risk type, such as customer complaints, or a group of risks, such as operational risks. English and Russian software interfaces are available.

Seenic AI Platform.png

Seenic AI Platform: Seenic AI, a proprietary visual AI platform from Everseen, blends AI and computer vision to aid retail stores. Seenic AI scans data and video of processes performed by humans, creates a digital blueprint of those processes, and shapes them for better outcomes.

Seequent Central.png

Seequent Central: Seequent Central, a geoscience model management solution, helps geologists and geophysicists visualize, track, integrate, and manage data from a centralized environment hosted on Microsoft Azure.

SentryOne SQL Sentry.png

SentryOne SQL Sentry: SQL Sentry from SentryOne is a scalable solution for database performance monitoring and for migrating and optimizing Microsoft SQL Server workloads on Microsoft Azure. SQL Sentry includes an intuitive environmental health dashboard, flexible alerting, and more.

SepiaCMS.png

SepiaCMS: SepiaCMS by Sepia Solutions serves as a multi-site marketing platform with multilingual support and integrated modules for portal management. Customers can design with drag-and-drop tools and manage an unlimited number of domains in one place.

Serendipity Powered by Miri.png

Serendipity Powered by Miri: This virtual machine offered by Miri Infotech contains Serendipity, a PHP-powered blog engine. Although the default package is designed for the casual blogger, Serendipity offers an expandable framework and can be used with professional applications.

Servian VisualCortex.png

Servian VisualCortex: With its intuitive self-serve interface and AI toolbox, VisualCortex from Servian harvests data from your cameras or video archive to provide insights on safety and security. Configure VisualCortex over your CCTV arrays or any combination of cloud or edge-compute setups.

Skolsynk for Microsoft.png

Skolsynk for Microsoft: Skolsynk for Microsoft is a collaboration between several Swedish teaching aid suppliers. It syncs schools, students, teachers, and groups from Microsoft 365 with teaching material providers. This app is available only in Swedish.

SLM Cost Take-Out.png

SLM Cost Take-Out: SoftwareONE’s SLM Cost Take-Out aims to save your organization money by focusing on increasing operational effectiveness through analyzing software consumption.

Solar Hand Sanitizer Simple.png

Solar Hand Sanitizer Simple: SIMPLE is a solar hand sanitizer for disinfection in public places. Its weather resistance makes it suitable for outdoor conditions as well as indoor spaces. Each dispenser can be powered by a photovoltaic panel and is fully autonomous.

Solteq DataShovel.png Solteq DataShovel: Solteq Oyj’s DataShovel is a next-generation data warehouse automation tool. DataShovel creates a visual model of the data warehouse, making customers’ workflows more agile and efficient.
Subrion CMS powered by MIRI.png

Subrion CMS powered by MIRI: This ready-to-launch virtual machine offered by Miri Infotech contains Subrion CMS, an open-source content management system based on PHP and MySQL. Subrion CMS is used to build websites and is suitable for small projects as well as high-load portals.

Temperature Detector API, Thermoquaesitor.png

Temperature Detector API, Thermoquaesitor: Thermoquaesitor, a cross-browser REST API for apps that use thermal imaging, detects the temperatures of people’s faces based on photos. For one photo, the API may return multiple predictions with different probability scores of detected temperatures.

Think ChatBot with Autotask.png

Think ChatBot with Autotask: Think ChatBot from Think AI Consulting Corporation can engage with customers and reduce email volume at your business. Customers can get their ticket status and schedule assignments with the Autotask platform.

Thycotic Secret Server Privileged Access Mgmt.png

Thycotic Secret Server Privileged Access Mgmt.: Thycotic’s flagship privileged access management (PAM) and least-privilege endpoint security offerings are hosted on Microsoft Azure and include Secret Server Cloud, Privilege Manager, and Account Lifecycle Manager.

Tiki Wiki- Content Managenet Groupware.png

Tiki Wiki: Content Management Groupware: This offer from Miri Infotech contains a pre-configured one-click deployment of Tiki Wiki CMS, a free and open-source Wiki-based content management system.

Verisium.png Verisium: Verisium is a marketing IoT platform that connects retail brands with customers through products, regardless of sales channels and geography, by embedding NFC chips and QR codes into products.
Webmin - Easy GUI SysAdmin Server for Ubuntu.png

Webmin – Easy GUI SysAdmin Server for Ubuntu: This ready-to-run Ubuntu image from Tidal Media contains Webmin, a web-based interface for Unix system administration. Webmin removes the need to manually edit Unix configuration files and lets you manage a system remotely or from the console.

Webmin - Easy GUI SysAdmin Server on LINUX Centos.png

Webmin – Easy GUI SysAdmin Server on LINUX Centos: This offer from Tidal Media contains Webmin on the CentOS Linux platform. Webmin is a web-based interface for Unix system administration. Using any modern web browser, you can set up user accounts, Apache, DNS, file sharing, and more.

Consulting services

Azure Data Analytics Foundation- 4-Wk PoC.png

Azure Data Analytics Foundation: 4-Wk PoC: In this proof of concept, Data-Driven AI will conduct discovery workshops with stakeholders and deliver a modern data platform on Microsoft Azure that’s ready for advanced analytics, machine learning, and big data transformations.

Azure Data Analytics Optimization 5-Day Assessment.png

Azure Data Analytics Optimization 5-Day Assessment: Let Enimbos help you optimize data collected from your Microsoft Azure infrastructure. Enimbos bases its approach on four areas: ingestion and data preparation, data management and quality, machine learning and AI, and data visualization and reporting.

Azure Kubernetes Service- 2- Week Workshop.png

Azure Kubernetes Service: 2- Week Workshop: In this workshop, Applied Cloud Systems will teach the fundamentals of Docker and Kubernetes and enable capabilities for deploying, scaling, and updating applications on Microsoft Azure Kubernetes Service.

Azure Machine Learning- 2-Week Proof of Concept.png

Azure Machine Learning: 2-Week Proof of Concept: In this proof of concept, Softcrylic will work with your team to scope and implement a predictive analytics business use case using your data in a private and secure Microsoft Azure virtual network. The outcome will be operational machine learning models that meet your expectations.

Azure Sentinel Workshop and Deployment (Free).png Azure Sentinel Workshop & Deployment (Free): In this free engagement, Hydra Security will help your organization get started with Microsoft Azure Sentinel and security analytics by deploying and configuring an Azure Sentinel instance and integrating up to three supported log sources.
Azure Virtual WAN plus Fortinet- 2 weeks assessment.png

Azure Virtual WAN + Fortinet: 2 weeks assessment: Microsoft Azure Virtual WAN can provide low-latency secure routing and help your business reduce costs and complexity. In this offer, ANS Group Limited will deliver Azure Virtual WAN along with Fortinet SD-WAN capability.

CAF Ready Transformation- 10-Week Implementation.png

CAF Ready Transformation: 10-Week Implementation: Contino will provide the customer with a self-service, Microsoft Cloud Adoption Framework-aligned Microsoft Azure landing zone. Contino will upskill the customer’s engineering employees so they can take over at the conclusion of the engagement.

Cloud and DC Transformation Advisory 1 Hour Briefing.png

Cloud & DC Transformation Advisory 1 Hour Briefing: Insight Direct (UK) Limited will provide an overview of its services and how you can benefit from them. These include discovery workshops, a hybrid cloud assessment, and proof-of-concept and migration services. This offer is available in Swedish.

Comprehensive Azure Review 1 Week Assessment.png

Comprehensive Azure Review 1 Week Assessment: IFI Techsolutions will analyze your Microsoft Azure environment, evaluate your resources, and help you adopt best practices to ensure that you get the most value out of your cloud investment.

Comprehensive Azure Review 2 Week Implementation.png

Comprehensive Azure Review 2 Week Implementation: Consultants from IFI Techsolutions will conduct a 360-degree review of your Microsoft Azure environment, analyzing it for cost savings, resource optimization, end-to-end security, and high availability so you can get the best value out of your Azure investment.

Data Estate Modernisation- 10 weeks implementation.png

Data Estate Modernization: 10 weeks implementation: In this engagement, Nordcloud’s experts will define a data operating model and implement an initial data platform for ingesting, managing, and analyzing data on Microsoft Azure.

Development Project- Marketing, Sales, and Service.png Development Project: Marketing, Sales, and Service: Iterbi Consulting provides companies with a marketing, sales, and service digital transformation strategy tailored to their needs. It offers seamless personalized communication with clients to influence their decision-making and drive quicker transactions.
Digital Connectivity Check- 2 Week Assessment.png

Digital Connectivity Check: 2 Week Assessment: Before you can reap the benefits of the cloud, you need to know whether your network can handle the traffic. A solution architect from ANS Group Limited will conduct an assessment and detail any required changes to your network architecture.

ExpressRoute and connectivity- 2 week Assessment.png

ExpressRoute & connectivity: 2 week Assessment: In this assessment, an ANS Group Limited solutions architect will help you validate your current network and determine what changes are required for you to be able to deliver Microsoft Azure ExpressRoute connectivity.

GreenPages Cloud Xcelerator Program.png GreenPages Cloud Xcelerator Program: GreenPages’ Cloud Xcelerator Program is a series of three workshops paired with a reference architecture implementation that includes a cloud opportunity assessment, a cloud readiness assessment, and a minimum viable cloud proof of concept that leverages the Cloud Xcelerator Platform.
HPE Accelerator Workshop for Cloud - SAP, 2 Days.png

HPE Accelerator Workshop for Cloud – SAP, 2 Days: Hewlett Packard Enterprise’s workshop will define a strategy and a timeline for your SAP-to-Azure migration. Topics will include economic modeling, SAP consolidation priorities, and key SAP operating requirements for Microsoft Azure.

Implementation Project.png Implementation Project: Iterbi Consulting provides a marketing, sales, and service digital transformation tailored to your needs. Learn how to deliver a personalized, omnichannel customer experience while driving successful digital transformation in your organization.
ISV-SaaS Consulting Offer - 1 Week Workshop.png

ISV/SaaS Consulting Offer – 1 Week Workshop: Whether you want to migrate and modernize an app in the cloud or transfer workloads between clouds, LANcom Technology’s DevOps team will review your product and provide recommendations using industry best practices.

ISV-SaaS Consulting Offer - Free 4 hour Assessment.png

ISV/SaaS Consulting Offer – Free 4 hour Assessment: Book a call with LANcom Technology in this free four-hour assessment. LANcom Technology’s DevOps team will carry out an initial assessment of your software and empower you with a high-level overview on the benefits of migrating your development to the cloud.

Managed Services & Enablement.png Managed Services & Enablement: Iterbi Consulting’s managed services and marketing, sales, and service enablement provide mass content production to achieve your goals. Outsourcing with Iterbi enables your team to focus on essential tasks to hit performance targets. This offering is available in English and Russian.
Modern App With Kubernetes 1 Week Proof Of Concept.png

Modern App with Kubernetes 1 Week Proof Of Concept: In this proof of concept, IFI Techsolutions consultants and architects will work closely with you to modernize, monitor, and scale your application using Microsoft Azure Kubernetes Services.

Nordcloud - Data Enablement- 3 days workshop.png

Nordcloud – Data Enablement: 3 days workshop: Nordcloud’s workshop will allow business and technical stakeholders to understand the opportunity of building a data platform on Microsoft Azure. Nordcloud will define an operating model and select initial use cases for the implementation.

Nordcloud's CAF - 3 Days Workshop.png

Nordcloud’s CAF – 3 Days Workshop: In this workshop, Nordcloud will define an operating model to enable secure, agile, and cost-efficient use of Microsoft Azure across your organization. Nordcloud’s workshop is aligned with the Microsoft Cloud Adoption Framework roadmap.

Public Sector ExpressRoute- 2 Weeks Assessment.png

Public Sector ExpressRoute: 2 Weeks Assessment: ANS Group Limited will deliver Microsoft Azure ExpressRoute along with Fortinet SD-WAN capability so organizations can attain secure connectivity to the cloud while having access to public-sector networks such as PSN and HSCN.

SAP on Azure Assessment - 6 week.png

SAP on Azure Assessment – 6 week: Fast-track your journey to SAP S/4HANA on Microsoft Azure with this assessment from Fujitsu. The assessment will provide you with application and architecture recommendations, a migration plan, a business case, and more.

Windows Virtual Desktop- 3 Week Implementation.png

Windows Virtual Desktop: 3 Week Implementation: In this engagement, Applied Cloud Systems will establish a pilot implementation of Windows Virtual Desktop for up to 50 users in preparation for production deployment. This engagement will allow for a work-from-home experience similar to being in the office.

Whats new: Azure Sentinel and Microsoft Defender ATP improved alert integration

Whats new: Azure Sentinel and Microsoft Defender ATP improved alert integration

This article is contributed. See the original author and article here.

In the past few months, we have worked on an improved integration of Microsoft Defender ATP alerts into Azure Sentinel. After an initial evaluation period, we are now ready to gradually roll out the new solution to all customers. The new integration will replace the current integration of MDATP alerts which is now in public preview (see details below). The changes will occur automatically on 3/8/2020 and require no configuration from customers.

 

Improved alert details and context

The new integration has significant advantages in improved details and context, which are meant to facilitate and expedite triage and investigation of Microsoft Defender ATP incidents in Azure Sentinel. The integration will provide a more detailed view of each alert and is designed to capture changes on alert status over time. The upgrades include increased visibility into investigation and response information from MDATP as well as a link to provide an easy pivot to see the alert in the source portal. Finally, more information on entities is provided in a more concise format so analysts can have a broader picture of the involved entities.

 

It is important to note that the new integration does make minor changes to the structure of alerts from Microsoft Defender ATP. A summary of the changes is presented below (table 1), and a full description of the changes, together with a sample alert, can be found in the attached file. Any scheduled rules that use one of the changed fields might be affected.

 

A new MDATP API

The integration is based on the newly released MDATP Alerts API. Details on the new API can be found here.

 

Improved discoverability of the Sentinel integration in MDATP

The Sentinel integration is now exposed in the Partner application section in Microsoft Defender ATP.

 

Ely_Abramovitch_0-1596446387513.png

 

Additional Resources

Connecting Microsoft Defender ATP alerts to Sentinel – https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protection

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/get-alerts

 

Table 1 – summary of the alert schema changes

This table details the changes in the representation of MDATP alerts in the SecurityAlert table in Azure. The changes are in comparison to how MDATP alerts are now represented in Sentinel. Full description of the alert can be found in the attached file.

 

Description of Change

Sample Alert Data

Added: ExtendedProperties field. This field is an object containing the following details from MDATP:

– MDATP category
– Investigation ID
– Investigation state
– Incident ID
– Detection source
– Assigned to
– Determination
– Classification
– Action

{
“MicrosoftDefenderAtp.Category”: “SuspiciousActivity”,
“MicrosoftDefenderAtp.InvestigationId”: “10505”,
“MicrosoftDefenderAtp.InvestigationState”: “Running”,
“LastUpdated”: “05/25/2020 08:09:17”,
“IncidentId”: “135722”,
“DetectionSource”: “CustomerTI”,
“AssignedTo”: null,
“Determination”: null,
“Classification”: null,
“Action”: “zavidor was here”
}

Replaced: ExtendedLinks field – The new AlertLink column displays a link to the MDATP portal for each alert.

https://securitycenter.microsoft.com/alert/
da637259909307309588_-1180694960 

Repurposed: AlertType field – shows the detection source (instead of a GUID of the alert in MDATP)

Before: 360fdb3b-18a9-471b-9ad0-ad80a4cbcb00
After: CustomerTI

Expanded: Entity field – More information on entities is surfaced.
For example, the host entity now holds the following details:
– HostName
– OSFamily
– OSVersion
– Type
– MdatpDeviceId
– FQDN
– AadDeviceId
– RiskScore
– HealthStatus
– LastSeen
– LastExternalIpAddress
– LastIpAddress

{
“$id”: “3”,
“HostName”: “real-e2etest-re”,
“OSFamily”: “Windows”,
“OSVersion”: “1809”,
“Type”: “host”,
“MdatpDeviceId”: “e84e634c8c5c2ca10db696cac544ea9ec41e784c”,
“FQDN”: “real-e2etest-re”,
“AadDeviceId”: null,
“RiskScore”: “Medium”,
“HealthStatus”: “ActiveDefault”,
“LastSeen”: “2020-05-
25T08:06:28.5181093Z”,
“LastExternalIpAddress”:
“20.185.104.143”,
“LastIpAddress”: “172.17.53.241”
},

 

 

 

 

 

 

 

 

 

 

Whats new: Azure Sentinel and Microsoft Defender ATP improved alert integration

What’s new: Azure Sentinel and Microsoft Defender ATP improved alert integration

This article is contributed. See the original author and article here.

In the past few months, we have worked on an improved integration of Microsoft Defender ATP alerts into Azure Sentinel. After an initial evaluation period, we are now ready to gradually roll out the new solution to all customers. The new integration will replace the current integration of MDATP alerts which is now in public preview (see details below). The changes will occur automatically on the 3rd of August and require no configuration from customers.

 

Improved alert details and context

The new integration has significant advantages in improved details and context, which are meant to facilitate and expedite triage and investigation of Microsoft Defender ATP incidents in Azure Sentinel. The integration will provide a more detailed view of each alert and is designed to capture changes on alert status over time. The upgrades include increased visibility into investigation and response information from MDATP as well as a link to provide an easy pivot to see the alert in the source portal. Finally, more information on entities is provided in a more concise format so analysts can have a broader picture of the involved entities.

 

It is important to note that the new integration does make minor changes to the structure of alerts from Microsoft Defender ATP. A summary of the changes is presented below (table 1), and a full description of the changes, together with a sample alert, can be found in the attached file. Any scheduled rules that use one of the changed fields might be affected.

 

A new MDATP API

The integration is based on the newly released MDATP Alerts API. Details on the new API can be found here.

 

Improved discoverability of the Sentinel integration in MDATP

The Sentinel integration is now exposed in the Partner application section in Microsoft Defender ATP.

 

Ely_Abramovitch_0-1596446387513.png

 

Additional Resources

Connecting Microsoft Defender ATP alerts to Sentinel – https://docs.microsoft.com/en-us/azure/sentinel/connect-microsoft-defender-advanced-threat-protection

MDATP API – https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/get-alerts

 

Table 1 – summary of the alert schema changes

This table details the changes in the representation of MDATP alerts in the SecurityAlert table in Azure. The changes are in comparison to how MDATP alerts are now represented in Sentinel. Full description of the alert can be found in the attached file.

 

Description of Change

Sample Alert Data

Added: ExtendedProperties field. This field is an object containing the following details from MDATP:

– MDATP category
– Investigation ID
– Investigation state
– Incident ID
– Detection source
– Assigned to
– Determination
– Classification
– Action

{
“MicrosoftDefenderAtp.Category”: “SuspiciousActivity”,
“MicrosoftDefenderAtp.InvestigationId”: “10505”,
“MicrosoftDefenderAtp.InvestigationState”: “Running”,
“LastUpdated”: “05/25/2020 08:09:17”,
“IncidentId”: “135722”,
“DetectionSource”: “CustomerTI”,
“AssignedTo”: null,
“Determination”: null,
“Classification”: null,
“Action”: “zavidor was here”
}

Replaced: ExtendedLinks field – The new AlertLink column displays a link to the MDATP portal for each alert.

https://securitycenter.microsoft.com/alert/
da637259909307309588_-1180694960 

Repurposed: AlertType field – shows the detection source (instead of a GUID of the alert in MDATP)

Before: 360fdb3b-18a9-471b-9ad0-ad80a4cbcb00
After: CustomerTI

Expanded: Entity field – More information on entities is surfaced.
For example, the host entity now holds the following details:
– HostName
– OSFamily
– OSVersion
– Type
– MdatpDeviceId
– FQDN
– AadDeviceId
– RiskScore
– HealthStatus
– LastSeen
– LastExternalIpAddress
– LastIpAddress

{
“$id”: “3”,
“HostName”: “real-e2etest-re”,
“OSFamily”: “Windows”,
“OSVersion”: “1809”,
“Type”: “host”,
“MdatpDeviceId”: “e84e634c8c5c2ca10db696cac544ea9ec41e784c”,
“FQDN”: “real-e2etest-re”,
“AadDeviceId”: null,
“RiskScore”: “Medium”,
“HealthStatus”: “ActiveDefault”,
“LastSeen”: “2020-05-
25T08:06:28.5181093Z”,
“LastExternalIpAddress”:
“20.185.104.143”,
“LastIpAddress”: “172.17.53.241”
},

 

 

 

 

 

 

 

 

 

 

Usage of Custom RBAC roles in Azure API Management

Usage of Custom RBAC roles in Azure API Management

This article is contributed. See the original author and article here.

 

Overview of Built-In RBAC roles in Azure API Management

 

Azure API Management relies on Azure Role-Based Access Control (RBAC) to enable fine-grained access management for API Management services and entities (for example, APIs and policies).

 

Reference Article: https://docs.microsoft.com/en-us/azure/api-management/api-management-role-based-access-control

 

As highlighted in the above article, Azure APIM provides a set of built-in RBAC roles for managing access to APIM services. These roles can be assigned at different scopes, which includes

  • Subscription Level
  • Resource Group Level
  • Individual APIM service level

 

The following table provides a brief description of the built-in roles currently offered by Azure APIM. These roles can be assigned via Azure portal or other tools, including Azure PowerShellAzure CLI, and REST API

 

APIM Built InRoles.PNG

 

 

 

Custom RBAC roles in Azure APIM

 

If the default built-in roles do not meet specific user requirements, you can create custom RBAC roles for providing a more granular access to either APIM services or any of their sub-components.

Custom Roles in Azure RBAC: https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles

 

While creating a custom RBAC role, it is easier to follow the below approach in order to avoid complexities or discrepancies:

  • Start with one of the built-in roles.
  • Edit the attributes to add Actions, NotActions, or AssignableScopes.
  • Save the changes as a new role.
  • Assign the new role to the APIM services or APIM components (such as APIs, policies, et cetera).

 

The ARM (Azure Resource Manager) Resource Provider Operations article contains the list of permissions that can be granted on APIM level.

https://docs.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftapimanagement

 

Let us consider a few scenarios where we envision the usage of custom RBAC roles to enable fine-tuned access to APIM services or their components.

 

 

Scenario 1: Deny users from deleting APIM services

 

RBAC roles that enable having complete write access to APIM services (such as API Management Service Contributor role) have provision for performing all management operations on an APIM service.

To avoid intentional/unintentional deletion of APIM services by any user having write access other than the APIM Administrator, you can create the below custom RBAC role for denying the operation Microsoft.ApiManagement/service/delete to users.

 

In this example, let us use the Azure Portal for modifying the built-in RBAC role Contributor and create a custom role for denying APIM service deletion action for all services under a particular Azure subscription. This custom role would allow users to perform all default owner operations except deleting APIM services in the subscription.

 

Step 1:

Maneuver to the Access Control (IAM) blade of a sample APIM service on the Azure Portal and click on the Roles tab. This would display the list of roles that are available for assignment.

 

ss1.PNG

 

Step 2:

Search for the role you wish to clone (APIM Service Contributor in this case). At the end of the row, click the ellipsis () and then click Clone

 

ss2.PNG

 

Step 3: Configure the Basics section as follows

 

ss3.PNG

 

 

Step 4: Configure the Permissions section.

 

Retain the default permissions listed for this role.

Click on +Exclude Permissions and search for Microsoft API Management

 

ss4.PNG

 

 

Under Not Actions, select the permission ‘Delete: Delete API Management Service instance’ under Microsoft.ApiManagement/service on the succeeding Permissions page and click the Add button.

 

ss5.PNG

 

 

ss6.PNG

 

 

Step 5: Configure the Assignable Scopes section.

 

Delete the existing resource level scope. Click on +Add Assignable Scopes and set the scope to Subscription level. Click Add.

 

ss7.PNG

 

 

NOTE:

  • Each Azure Active Directory can only have a maximum of 5000 custom roles. 

Hence, for a custom role where the assignable scope is configured to be at resource level, you could consider replacing it with a subscription or resource group level scope to prevent exhausting your custom role limit.

Constraints associated with custom roles can be found documented in the below article:

https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles#custom-role-limits

 

 

Step 6: In the JSON section, you could also Download your custom RBAC role in JSON format for future usage or reference.

 

remove sub.png

 

 

Step 7: Review the custom RBAC role details in the Review + Create section and click on Create.

It may take a few minutes for the custom role to be created and displayed under the list of available roles.

 

In this scenario, the newly created custom role would be available for assignment under the Roles section on the subscription’s Access Control (IAM) blade since the assignable scope was set at subscription level during creation.

 

 

NOTE:

  • Post creation, custom roles appear on the Azure portal with an orange resource icon (Built-in roles appear with blue icons).
  • Custom Roles would be available for assignment at the respective subscription, resource group or resource access control blade based on the assignable scope that has been configured during creation of the role.

 

Step 8: Assign this custom role to a user. Any user having this role would be able to perform all the operations that are offered by default by the APIM Service Contributor role except deleting APIM services in the subscription.

 

assign.PNG

 

 

 

Scenario 2: Deny users having Reader access from reading Product subscription keys

 

Let us consider the built-in APIM RBAC role ‘API Management Service Reader’ role for this scenario.

Users often have a misconception that only the APIM Administrators would be able to view the Product subscription keys on the Azure Portal. However, that is not the case.

The ability to read subscription keys from products (an action which is defined as Microsoft.ApiManagement/service/products/subscriptions/read) is allowed by default for users having the ‘API Management Service Reader Role’. Same is the case for navigating to the keys via APIs/subscriptions.

Hence, as a workaround, you can create a custom RBAC role in order to block the subscription keys – read action.

 

NOTE:

The action Microsoft.ApiManagement/service/users/keys/read does not correspond to reading subscription keys. The 2 actions are completely different.

Every user has two “secrets”, a primary and a secondary. These secrets are used to generate an encrypted SSO token that users can use to access the developer portal. These keys are not related to the subscription keys that users use to call the APIs. The /service/users/keys/read permission corresponds to the ability to read the user secrets, whereas the /service/products/subscriptions/read permission corresponds to reading subscription keys under products, which is allowed by default under the ‘API Management Service Reader’ role.

Additionally, the Microsoft.ApiManagement/service/users/subscriptions/read permission corresponds to the ability to read subscriptions associated with users via the “Users” blade on the Portal, which is also allowed by default under this role.

 

Here, we are creating and assigning a custom RBAC role using PowerShell for denying users having Read access over the APIM service from reading the subscription keys. Basically, this role denies users from performing the operation Microsoft.ApiManagement/service/products/subscriptions/read

 

The sample PowerShell script is as below:

 

$role = Get-AzRoleDefinition "API Management Service Reader Role"
$role.Id = $null
$role.Name = 'Deny reading subscription keys'
$role.Description = 'Denies users from reading product subscription keys'
$role.NotActions.Clear()
$role.NotActions.Add('Microsoft.ApiManagement/service/products/subscriptions/read')
$role.AssignableScopes.Clear()
$role.AssignableScopes.Add('/subscriptions/<subscription ID>/resourceGroups/<resource group name>/providers/Microsoft.ApiManagement/service/<service name>')
New-AzRoleDefinition -Role $role
New-AzRoleAssignment -ObjectId <object ID of the user account> -RoleDefinitionName 'Deny reading subscription keys' -Scope '/subscriptions/<subscription ID>/resourceGroups/<resource group name>/providers/Microsoft.ApiManagement/service/<service name>' 

 

 

 

Known Limitations

 

  • Current design does not allow RBAC permissions to be controlled at Product level for API creation/deletion.

For example, consider a scenario where users on the Azure Portal should have read and write access only over APIs that are associated with a particular Product. For this, you can configure an RBAC role where the assignable scope has been set at “Product” level and add the desired Actions and NotActions.

 

Now, even if you add the permission “Microsoft.ApiManagement/service/apis/*” at product scope, when the user who is assigned this role attempts creating a new API inside this Product, the operation would still fail.

If a user needs to create a new API in the service (irrespective of whether it is inside the same Product), they should be able to read all APIs in the service and have write permissions granted at the APIM service scope instead of Product scope.

 

This is because, when a user attempts to create a new API or add a new version/revision for an existing API, there is a validation check that happens in the background to verify if there is any other API in the service which is using the same path that the user is attempting to create. If the user performing this operation does not have permissions to read all APIs in the service, the operation would fail.

Hence, you would have to grant the user the permission to read all APIs in the service (granted at the service scope).

 

 

  • Permissions to view APIM Diagnostics Logs cannot be configured at APIM scope.

For example, if user has configured streaming of APIM Diagnostic Logs to a Log Analytics Workspace and wishes to create a custom RBAC role only for viewing these diagnostic logs, it wouldn’t be possible to configure this role at the APIM scope. Since the log destination is Log Analytics, the permission has to be configured at the Log Analytics scope.

 

The APIM ARM operation “Microsoft.ApiManagement/service/apis/diagnostics/read” only controls access to the diagnostic configuration for the APIM service and not to the diagnostic telemetry that APIM streams to external resources such as Log Analytics/Application Insights, et cetera.

 

 

  • Preventing users from accessing the Test Console for APIs on the Azure Portal cannot be achieved with a straight-forward approach.

This is because there are no APIM ARM operations that support actions corresponding to “Microsoft.ApiManagement/service/apis/operations/test”.

However, this limitation can be overcome if the API is protected by a subscription key. When the permission “Microsoft.ApiManagement/service/subscriptions/read” is denied to a user, the user cannot test an API protected by a subscription key since they wouldn’t be able to retrieve the subscription key required for testing the API operation.

 

A JSON sample for creating this custom role can be found attached below:

 

{
  "properties": {
    "roleName": "Deny Testing APIs",
    "description": "Deny Testing APIs",
    "assignableScopes": [
      "/subscriptions/<subscription ID>/resourceGroups/<resource group name>/providers/Microsoft.ApiManagement/service/<service name>"
    ],
    "permissions": [
      {
        "actions": [],
        "notActions": [
          "Microsoft.ApiManagement/service/subscriptions/read"
        ],
        "dataActions": [],
        "notDataActions": []
      }
    ]
  }
}

 

 

 

APPENDIX

 

 

 

 

  • Tutorials for Creating Custom RBAC Roles:

a) Azure Portal Tutorial – https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles-portal

b) PowerShell Tutorial – https://docs.microsoft.com/en-us/azure/role-based-access-control/tutorial-custom-role-powershell#create-a-custom-role

c) Azure CLI Tutorial – https://docs.microsoft.com/en-us/azure/role-based-access-control/tutorial-custom-role-cli

d) REST API Tutorial – https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles-rest

e) ARM Template Tutorial and Sample – https://docs.microsoft.com/en-us/azure/role-based-access-control/custom-roles-template

 

 

 

Azure Advocates Weekly Roundup dotnetConf – Microservices & Create:Frontend

Azure Advocates Weekly Roundup dotnetConf – Microservices & Create:Frontend

This article is contributed. See the original author and article here.

bit_community.png

 

What an action packed week with TWO great live conferences!
 
Create:Frontend A one of a kind live event from Microsoft about all things frontend.
 
.NET Conf: Focus on Microservices a free, livestream event that features speakers from the community and .NET teams that are working on designing and building microservice-based applications, tools and frameworks.
 
Content Round Up
 

How to Manage SharePoint via PowerShell – Part 1
Anthony Bartolo

In this 2-part series, we’re going to look at how we can manage SharePoint using PowerShell. This is highly focused on SharePoint Online, but if the cmdlets are available, it also applies to SharePoint on-premises. We’ll start with the basics, and then get some real-world scenarios scripts in part 2 to get you started with your daily management tasks. I’ll also you give some tips along the way to make your life easier.

 

How to Manage SharePoint via PowerShell – Part 2
Anthony Bartolo

In this 2-part series, we’re going to look at how we can manage SharePoint using PowerShell. This is highly focused on SharePoint Online, but if the cmdlets are available, it also applies to SharePoint on-premises. We’ll start with the basics, and then get some real-world scenarios scripts in part 2 to get you started with your daily management tasks. I’ll also you give some tips along the way to make your life easier.

 

ITOpsTalk: Traditional Failover Clustering in Azure
Pierre Roman

Review of announcements and their impact on running traditional Clusters in Azure

 

LearnTV: 92 & Pike w/ Jen Looper!
Chloe Condon

On this episode we chat with Jen Looper! 👩🏼?:school: Jen is a Cloud Advocate Lead on the Academic Team at Microsoft where she helps create curriculum, content, and experiences for educators, students, new learners looking to upskill in tech. We chat with Jen about Maya Mystery.

 

Abhishek Gupta

Welcome to part four of this blog series! So far, we have a Kafka single-node cluster with TLS encryption on top of which we configured different authentication modes (TLS and SASL SCRAM-SHA-512), defined users with the User Operator, connected to the cluster using CLI and Go clients and saw how easy it is to manage Kafka topics with the Topic Operator. 

 

Using Graph Explorer Sample Data via REST
Todd Anglin

If you need a quick and easy way to access sample Graph data, you case use Graph Explorer via REST with the small “hack” discussed in this article.

 

React For Beginners workshop
Aaron Powell

React is a JavaScript library for creating high-performing, maintainable JavaScript applications and brings a fresh approach to thinking into the JavaScript community.

Being a declarative user interface library that is un-opinionated about the rest of your application it is easy to reason about it is simpler to learn and master the basics than a full application framework like Angular. Also thanks to the simple nature of React, the patterns and lessons you will learn are transferable to other libraries and frameworks.

 

A Guide to Running a Virtual Workshop
Aaron Powell

In this article I share my experience in delivering an online workshop as part of NDC Melbourne, what works (and what didn’t), the tech side of things and what is useful to know for anyone looking to run their own online workshop.

 

Demystifying ARM Templates – Variables
Frank Boucher

Variables are very useful in all king of scenarios to simplify things. Azure Resource Manager (ARM) templates aren’t an exception and the variable will offer great flexibility. In this chapter, we will explain how you can use variables inside your template to make them easier to read, or to use.

 

Learning-ARM tutorials
Frank Boucher

In this repository you will find a series of tutorial paired with videos to guide you through learning the best practice about Azure Resource manager (ARM) template.

Each video is featured in the same page as the content. The videos are part of Azure DevOps – DevOps Lab show.

 

How to use Azure Go SDK to manage Azure Data Explorer clusters
Abhishek Gupta

Getting started with Azure Data Explorer using the Go SDK covered how to use the Azure Data Explorer Go SDK to ingest and query data from azure data explorer to ingest and query data. In this blog you will the Azure Go SDK to manage Azure Data Explorer clusters and databases.

 

Azure AD Mailbag: Identity protection

Azure AD Mailbag: Identity protection

This article is contributed. See the original author and article here.

Greetings!

 

We’re back with another mailbag, this time focusing on your common questions regarding Azure AD Identity Protection. Security is always top of mind and Identity Protection helps you strike a balance between the usability required for end users to be productive while protecting access to resources. We’ve got some really great questions from folks looking to improve the effectiveness of their alerts and to increase their overall security posture. We even have a sample script for you! I’ll let Sarah, Rohini and Mark take it away.

 

—–

 

Hey y’all, Mark back again for another mailbag. You’ve been asking some really great questions around Azure AD Identity Protection. So good, in fact, I’ve kept putting this off for an embarrassingly long time. Then I called in for some help from some excellent feature PMs Sarah Handler and Rohini Goyal.

 

Question 1: I want to bulk dismiss a lot of Users that have risk. How can I do this?

Make sure that before you bulk dismiss users, you’ve already remediated them or determined that they’re not at risk. Then we have a GraphAPI call you can make to dismiss the user risk. We’ve put together a little sample script to help you with doing bulk dismissal.

 

We’ve provided a sample PowerShell script and examples to enumerate risky users, filter the results, and dismiss the risk for the collection.

 

mailbag731.png

 

Question 2: How do we detect TOR or anonymous VPN? Is it based off exit node or are there ways to bypass this?

We detect anonymizers in a few ways. For Tor, we continually update the list of Tor exit nodes. For VPNs, we use various third-party intelligence to determine whether an anonymizer has been used.

 

Question 3: How should we handle false positives?

There are two ways to address false positives: giving feedback on false positive detections that occur and reducing the number of false positives that get generated. If while investigating risky sign-ins you find a detection to be a false positive, you should mark “confirm safe” on the risky sign-in. There are two ways to prevent false positives in Identity Protection. The first is to enable sign-in risk policies for your users. When a user is prompted for a sign-in risk policy with MFA and passes the MFA prompt, it gives feedback to the system that the legitimate user signed in and helps to familiarize the sign-in properties for future ones. The second is to mark common locations that you trust as trusted locations in Azure AD.

 

Question 4: What is the best practice for whitelisting known locations?

First, you want to make sure you’re putting in your public egress end points. This helps with our detection algorithms. We’ve recently increased the named locations to 195 named locations with 2,000 IP ranges per location. You can read more in our docs.

 

But we know that many times networking teams make changes and don’t notify the Azure AD Admins. It’s good to have a process to work through the Sign-In logs and look for IP ranges that are not part of your named locations and add those as well as remove IPs that no longer are your egress point.

 

Question 5: Does AAD Leaked credentials connect to Troy Hunt’s Have I been Pwned API? Do I need to supplement with other scans?

Leaked credentials detection does not connect to Troy Hunt’s “Have I been Pwned”. Troy does an excellent job with his service correlating and collecting public dumps. Leaked credentials alerts take into account those public dumps as well as non-public dumps we call out in our docs, more info here. If you want to supplement the Azure AD leaked credentials alerting with other feeds, that is entirely up to you.

 

Question 6: When I turn on Password Hash Sync does the leaked credential alert on existing ones or only on leaks going forward?

Leaked credentials will only detect on leaks going forward. When we find clear text username and passwords pairs, we don’t keep them. We process them through and delete them. We’ve updated our documentation to call this out and provided more info.

 

We hope you’ve found this post and this series to be helpful. For any questions you can reach us at AskAzureADBlog@microsoft.com , the Microsoft Forums and on Twitter @AzureAD @MarkMorow, @Sue_Bohn, and @Alex_A_Simons

 

-Rohini Goyal, Sarah Handler and Mark Morowczynski