AKS on AzureStack HCI – now in Public Preview

AKS on AzureStack HCI – now in Public Preview

This article is contributed. See the original author and article here.

Hi Everyone,

This week we have announced the availability of the initial public preview of Azure Kubernetes Service (AKS) on Azure Stack HCI.

 

You can evaluate AKS on Azure Stack HCI by registering for the Public Preview here: https://aka.ms/AKS-HCI-Evaluate 

 

Azure Kubernetes Service on Azure Stack HCI takes our popular Azure Kubernetes Service (AKS) and makes it available to customers to run on-premises; delivering Azure consistency, a familiar Azure experience, ease of use and high security for their containerized applications. AKS on Azure Stack HCI enables developers and administrators to deploy and manage containerized apps on Azure Stack HCI. You can use AKS on Azure Stack HCI to develop applications on AKS and deploy them unchanged on-premises, run Arc enabled Data Services on a resilient platform and modernize Windows Server and Linux applications.

 

With AKS on Azure Stack HCI, Microsoft is delivering an Industry leading experience for modern application development and deployment in a hybrid cloud era. Microsoft is the only company that delivers technology that takes you from bare metal to a public cloud connected and consistent application and data platform in your datacenter.

image1.png

 

AKS on Azure Stack HCI can run Windows and Linux containers, all managed and supported by Microsoft. AKS on Azure Stack HCI leverages our experience with AKS, follows the AKS design patterns and best-practices, and uses code directly from AKS. This means that you can use AKS on Azure Stack HCI to develop applications on AKS and deploy them unchanged on-premises. It also means that any skills that you learn with AKS on Azure Stack HCI are transferable to AKS as well.

 

AKS on Azure Stack HCI uses Windows Admin Center and PowerShell to provide an easy to use and familiar deployment experience for any user of Azure Stack HCI. AKS on Azure Stack HCI simplifies the process of setting up Kubernetes on Azure Stack HCI and includes the necessary components to allow you to deploy multiple Kubernetes clusters in your environment.

image2.png

 

Which all means that you can focus on what matters most to you – your applications.

AKS on Azure Stack HCI is designed such that every layer is secure. Microsoft provides a secure baseline of all components in AKS on Azure Stack HCI and keeps them up to date. We will be adding mode security features and further hardening the platform over the course of the public preview.

AKS on Azure Stack HCI fully supports both Linux-based and Windows-based containers. When you create a Kubernetes cluster on Azure Stack HCI you can choose whether to create node pools (groups of identical virtual machine, like on AKS) to run Linux containers, Windows containers, or both. AKS on Azure Stack HCI creates and maintains these virtual machines so that you don’t have to directly manage operating systems.

 

If you have existing .NET applications that you want to modernize, and take advantage of the latest cloud development patterns, AKS on Azure Stack HCI is the platform for you. AKS on Azure Stack HCI provides an industry leading experience for Windows Containers on Kubernetes. We are also working on great tooling and documentation for the process of moving .NET applications from virtual machines to containers with AKS on Azure Stack HCI.

 

If you are building a new cloud native applications on AKS, AKS on Azure Stack HCI provides to easiest way for you to take those applications and run them in your datacenter. AKS on Azure Stack HCI shares a common code base with AKS, the user experience is consistent across both products, and Microsoft is investing to ensure that applications can move easily between these two environments.

 

If you are wanting to utilize new Microsoft technologies like Arc enabled Data Services in your datacenter, AKS on Azure Stack HCI delivers a complete solution from Microsoft. It is validated and supported by Microsoft, designed to deliver the best experience for these applications.

 

You can learn more about AKS on Azure Stack HCI by watching:

 

Working on this project has been a lot of fun for everyone involved, and we are excited to finally be able to share this with the world. I look forward to seeing what everyone is able to achieve with AKS on Azure Stack HCI!

 

Cheers,

Ben Armstrong

How to Secure Azure SQL Database by Setting Minimal TLS Version | Data Exposed

This article is contributed. See the original author and article here.

In this episode with Rohit Nayak, we will cover the Minimal TLS Version setting for SQL Database. Customers can use these features to enforce a TSL version at the logical server level to meet their compliance needs.

 

Watch on Data Exposed


Resources:

Minimal TLS version

Even more Networking videos

 

View/share our latest episodes on Channel 9 and YouTube!

Top 7 Microsoft Identity partnership announcements at Ignite 2020

Top 7 Microsoft Identity partnership announcements at Ignite 2020

This article is contributed. See the original author and article here.

In the past 6 months, I’ve spoken to customers around the world about the challenges associated with providing secure and seamless access for a remote workforce. Organizations need to maximize user productivity while safeguarding the business from cyber threats, but they also must reduce costs in light of today’s difficult economic conditions. To help you meet these goals, Microsoft announced several new product enhancements for Ignite 2020. But we can’t go at it alone. Partnerships play a key role in complementing our built-in capabilities. Today, I’d like to share 7 key ways solutions from partners working with Microsoft enable a secure, productive workforce.

 

Simplifying identity management and access to your apps

Software-as-a-service (SaaS) and cloud-based apps have been key enablers of user productivity—especially with so many people working from home. Out of the box, Azure AD integrates with leading SaaS apps, with more added every month. These integrations simplify user lifecycle management and app provisioning, allowing you to automatically create and update user identities and roles. Adobe and ServiceNow are two partners that we’ve developed integrations that can ensure employees have access to the right applications through their tenure at your organization.

 

Adobe announces support for SCIM-based provisioning. 

To streamline access and administration of its business-critical apps, Adobe has announced a SCIM standard-based app provisioning integration for its core Adobe Identity Management platform. Working with Microsoft IT as a customer to get insights, Adobe has built an updated admin experience, which will make it easier to manage user lifecycles across Adobe Creative Cloud, Adobe Document Cloud, and Adobe Experience Cloud. This integration will be available for limited preview in October and generally available for customers by the end of 2020.

 

Screenshot of updated Adobe Admin experience to enable SCIM provisioning with Azure AD. Experience subject to change.Screenshot of updated Adobe Admin experience to enable SCIM provisioning with Azure AD. Experience subject to change.

 

ServiceNow integrates with Azure AD to automate new hire onboarding

ServiceNow recently announced in their latest Now Platform Paris release new capabilities to automatically kick off the right onboarding workflows as soon as a new employee profile is created in Azure AD. IT and hiring managers can automatically provision application access for new hires through Azure AD, including from an HR system, increasing productivity for employees and support teams. This integration automates the whole onboarding workflow from case creation in ServiceNow HR Service Delivery, to role assignment by hiring manager, and application provisioning by IT based on the new hire’s role. Learn more about ServiceNow and Azure AD’s new employee onboarding capabilities.

 

Saviynt is partnering with Azure AD to provide advanced identity governance capabilities to customers

Saviynt is working with Microsoft and Azure AD to provide additional governance scenarios to customers. Saviynt Cloud Privileged Access Management (PAM) now integrates with Azure AD Privileged Identity Management and Identity Protection to create an identity led, Zero Trust security service to accelerate an enterprise’s digital transformation journey. Saviynt Cloud PAM has also extended their solution to provide privileged access for Microsoft Azure IaaS and expanded governance to Azure AD B2C customers (public preview coming soon). In the recent update to the Saviynt for Microsoft Teams governance, the solution now provides Microsoft Teams site succession management and support for Teams Private Channels. Learn more about the Azure AD and Saviynt partnership.

 

Enabling stronger security through passwordless, identity verification, and threat intelligence

With more employees working from home, we know that security is even more top of mind. This starts with securing identities. Azure AD capabilities like passwordless are designed to help protect identities with minimal impact to employees. Security operations (SecOps) teams also need greater visibility to enable them to take the right actions in remediating threats. Several recent partnerships have helped us advance these goals.

 

Illusive Networks integrates with Microsoft Security and Azure AD APIs

Illusive Networks enhances the visibility and monitoring of vulnerable privileged identities in Azure AD, such as redundant identities, identities with excessive privileges, risky practices (e.g. Azure MFA disabled), and unauthenticated identities. Learn more about Illusive Networks’ new integrations across Microsoft Security products.

 

Yubico enables the move to passwordless

Weak passwords are the most vulnerable attack vector, which is why we are such strong advocates of passwordless technologies. To help reduce the reliance on passwords, we’ve developed a limited time offer with Yubico where qualified services partners can nominate their customers to go passwordless. Learn more about the new program and ways we’re partnering with Yubico in the video below.

 

 

Enabling Identity Proofing and Verification capabilities to Azure AD B2C through partners

As more businesses move to online, they need to verify and onboard customers remotely. Jumio and Onfido now enable Azure AD B2C customers to perform identity card (passport or driver license) scanning, identity verification, and liveness detection during a user’s journey.

 

Protect legacy applications through new secure hybrid access partnerships

During the COVID-19 outbreak, our customers need to access all mission critical apps from home securely, including legacy applications. While Azure AD Application Proxy can provide remote access to your legacy apps, we know that some customers prefer to use their existing application delivery networks, VPNs, or Software Defined Perimeter solutions. That’s why we’re expanding our Secure Hybrid Access Partnerships to include new partners such as Kemp, Palo Alto Networks, Cisco AnyConnect, Fortinet and Strata and Ping Identity for Azure AD B2C customers.

 

All SHA Partners New and Existing.JPG

 

We hope all these announcements are welcome additions as you support the new realities of remote work. Please let us know any feedback you have, including any other partners you think we should be working with to improve the employee experience and security.

 

Join us virtually, on-demand for Identity Partner Sessions at Ignite 2020

While we wish we could have met in person this year at Microsoft Ignite 2020, we have a great line up of free, virtual sessions to share with you wherever you are in the world. Register for free here.

 

All the Microsoft Identity sessions, on-demand, can be found on this Microsoft Ignite playlist or the Video Hub. Here are my top sessions to attend that relate to our partner solutions:

  1. Azure Active Directory: our vision and roadmap to help you secure remote access and boost employee productivity
  2. Save money by securing access to all your apps with Azure Ac​tive Directory
  3. Bridge the gap between HR, IT and business with Azure Active Directory
  4. Build experiences that customers and partners will love with Azure Active Directory External Identities

 

Best regards,

Sue Bohn

Partner Director of Program Management

Microsoft Identity Division

 

Quickly Get Started with Samples in Azure Synapse Analytics

Quickly Get Started with Samples in Azure Synapse Analytics

This article is contributed. See the original author and article here.

To help users be even more productive with Azure Synapse Analytics, we are introducing the Knowledge center in the Azure Synapse Studio. You can now create or use existing Spark and SQL pools, connect to and query Azure Open Datasets, load sample scripts and notebooks, access pipeline templates, and tour the Azure Synapse Studio − all from one place!

 

The Knowledge center can be accessed through the Azure Synapse Studio via both “Useful links” in the bottom right of the Homepage on the main navigation and via the “?” icon in the header.

 

johnmac_MS_7-1600833954582.png

 

Use samples immediately

The Knowledge center offers several one-click tutorials that create everything you need to instantaneously explore and analyze data.

 

johnmac_MS_8-1600833954601.png

 

 

In the “Explore sample data with Spark” tutorial, you can easily use Apache Spark for Azure Synapse to ingest New York City (NYC) Yellow Taxi data and then use notebooks to analyze the data and customize visualizations.

 

johnmac_MS_9-1600833954612.png

 

 

In the “Query data with SQL” tutorial, you can query and analyze data from the NYC Yellow Taxi dataset with a serverless SQL pool, which allows you to use T-SQL for quick data lake exploration without provisioning any additional resources. The tutorial also enables you to quickly visualize results with one click.

 

 

 

johnmac_MS_10-1600833954628.png

 

 

The “Create external table with SQL” tutorial allows you to use either a serverless or dedicated SQL pool to create an external table.

 

johnmac_MS_11-1600833954646.png

 

 

Browse available samples

The new Knowledge center also contains numerous sample datasets, notebooks, scripts, and pipeline templates to allow you to quickly get started. Add and query sample data on COVID-19, public safety, transportation, economic indicators, and more. Regardless of whether you prefer to use PySpark, Scala, or Spark.NET C#, you can get started using a variety of sample notebooks. In addition to sample notebooks, there are samples for SQL scripts like “Analyze Azure Open Datasets using SQL On-demand,” “Generate your COPY Statement with Dynamic SQL,” and “Query CSV, JSON, or Parquet files” along with more than 30 templates for pipelines.

 

johnmac_MS_12-1600833954662.png

 

 

Tour Azure Synapse Studio

The Knowledge center offers a comprehensive tour of the Azure Synapse Studio to help familiarize you with key features so you can get started right away on your first project!

 

johnmac_MS_13-1600833954677.png

 

Try the Knowledge center today

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Save your spot at the Azure Data Explorer online event!

This article is contributed. See the original author and article here.

Join us to hear all about the great new features, announcements, and collaborations for Azure Data Explorer – Azure’s fast, fully- service for real-time analysis of telemetry big data streaming from apps, websites, IoT devices, and more.

 

 

One of Azure’s most used services and the foundation of Microsoft’s telemetry platform, Azure Data Explorer , combines broad data exploration and powerful analytical queries with lightning-fast interactivity.

 

Use Azure Data Explorer to:

  • Monitor mission-critical systems.
  • Analyze IoT data from thousands of devices.
  • Explore and identify trends and anomalies in your data.
  • Tune up customer experience.
  • And many more exciting capabilities!

Join us to learn how to harness the growing volume of telemetry data to drive business success while keeping costs at bay with the super cost-efficient Azure Data Explorer service.

 

Capacity is limited to make sure to save your spot today!

 

Register to our online event to learn about the latest groundbreaking innovations, new features, and exciting collaborations.

The event includes a keynote by Rohan Kumar, CVP, Azure Data and fascinating content by the product group team members, delivering sessions on various topics. See the full agenda below.

 

Win a brand-new Surface Duo

In every session, one participant will win the newest Surface Duo from Microsoft.
Register now for a chance to enter the contest and win! 

 

When: October 14th, 2020

Where: Wherever you are! The event will be streamed on Teams Live.

1st round: 09:00 BST (London Time)

2nd round: 09:00 PST (US Pacific Time)

 

Register Now

 

Agenda

Name

Description

Speakers

Duration (Min)

Opening Session

Opening words, brief overview of the agenda and service

Oded Sacher, Partner Group Manager

Uri Barash, Principal Group Program Manager

15

Re-imagine Telemetry Analytics, with Rohan Kumar

Join us to hear from Rohan Kumar, Corporate Vice President of Azure Data, about the exciting developments with Azure Data Explorer, Microsoft’s telemetry analytics platform that is powering Microsoft’s internal and external business

CVP, Azure Data, Rohan Kumar

30

       

What’s new with ADX

Updates on the latest and greatest in ADX ingestion, query, dashboards and more

Gabi Lehner, Program Manager
Tzvia Gitlin Troyna, Program Manager

30

Powering Engineering Excellence With Azure Data Explorer

Taboola on AzureDataExplorer “It’s magic, interactive & intuitive. My users are in love”

Ariel Pisetzky, VP Information Technology & Cyber at Taboola.

15

Start Fast and Accelerate! 

The next generation of the Kusto engine

 

Azure Data Explorer engine enhancements.

Evgeney Ryzhyk, Partner Software Engineer

Alexander Sloutsky, Principal Engineering Manager

Avner Aharoni, Principal Program Manager

 

 

30

 

 

 

 

Breakout Sessions– 30 minutes 11:30 – 12:00

All Breakout sessions are running in parallel at the end of Azure Data Explorer engine enhancements session

 

ADX overview

Azure Data Explorer is a big data interactive analytics platform for telemetry. Join this session to learn about ADX, where does it fit, when to use it, what are its key features, scenarios and customers

Uri Barash, Principal Group Program Manager

Minni Walia, Senior Program Manager

Enterprise Readiness

This session is about all the great features needed to run Azure Data Explorer at enterprise scale. We will cover security, business continuity, high availability CI/CD related details.

Henning Rauch, Senior Program Manager

Anagha Khanolkar, Principal Program Manager

 

ML, Time Series

Anomaly detection, forecasting, diagnostics & RCA for preventive maintenance in IIoT, cloud services and other markets. Training/scoring ML models in ADX using Python.

Adi Eldar, Principal Program Manager

Manoj Raheja, Principal Program Manager

Roy Ofer, Senior Data Scientist

Operating ADX optimally: Cost and performance

Choosing optimal SKU for your workload and utilizing auto-scale can significantly reduce your cluster cost. Join us for a deep dive session where we drill into the different cost reducing options.

Avner Aharoni, Principal Program Manager

Deepak Agrawal, Senior Program Manager

Guy Reginiano, Program Manager

Ingestion

In this session we will focus on ingestion methods, how to choose the right method to your customer scenario, and what are the available options

Vladik Branevich, Principal Engineering Manager
Tzvia Gitlin Troyna, Senior Program Manager

Visualizing big data

Overcoming scale and performance challenges when building dashboards solution in big data scenarios

Gabi Lehner, Principal Program Manager
Olga Goldenberg, Senior Program Manager

 

Please share and subscribe,

Azure Data Explorer

 

Security capabilities in Azure Kubernetes Service on Azure Stack HCI

Security capabilities in Azure Kubernetes Service on Azure Stack HCI

This article is contributed. See the original author and article here.

Azure Kubernetes Service on Azure Stack HCI (AKS-HCI) is an on-premises implementation of the popular Azure Kubernetes Service (AKS) orchestrator, which automates running containerized applications at scale. AKS on Azure Stack HCI enables developers and admins to deploy and manage Linux and Windows containerized apps on Azure Stack HCI.

 

With AKS-HCI, enterprises can take advantage of consistent AKS experience across cloud and on-premises environments, extend to Azure with hybrid capabilities, run apps with confidence through built-in security, and use familiar tools to modernize Windows apps. For a more detailed overview of AKS-HCI capabilities, refer to this blog.

 

One of the core strengths of AKS-HCI is using security-first approach. At Microsoft, we believe that leading with strong security posture is table stakes for an enterprise-grade offering. Our security roadmap is comprehensive, starting with a mindset of placing strong protection guardrails and bolstering that with industry-hardened threat detection, and remediation and recovery. The protection-related hardening is built into AKS-HCI. To bring threat detection and remediation, and we integrate with security management systems such as Azure Security Center.

 

rahulverma_0-1600903582089.png

Figure 1. Securing AKS-HCI Deployment

 

In this blog, we will describe the security capabilities in AKS-HCI. These security features are not available in the current public preview version, but these and more will be released in the lead-up to general availability.

 

Secure image baseline and container protection

 

Microsoft provides a secure baseline for Windows and Linux container host images and services the updates of those images to maintain consistency and standards.

 

rahulverma_1-1600903582114.png

 

Figure 2. AKS-HCI implemented with hypervisor isolation

 

AKS-HCI is designed such that every layer is secure. The container host is deployed as a virtual machine. Each tenant cluster runs on its dedicated set of container hosts and uses the same strong Hyper-V-based isolation used in Azure which provides the strong kernel isolation among the container hosts.  

 

In addition, AKS-HCI has multiple layers of protection built in. The first cluster to be bootstrapped is the management cluster, which is then used to bootstrap other tenant clusters. The container pods are run within Hyper-V virtual machines, enforcing strong isolation guarantees wherein the impact of a compromised container or pod is contained within the Hyper-V VM itself.

 

Identity and access management (IAM)

 

AKS-HCI integrates with Active Directory (AD), providing strong identity and facilitating seamless single sign-on (SSO) to manage the AKS-HCI environment and deploy the container workloads. Additionally, there is provision for Windows containerized application workloads to be bootstrapped with group Managed Service Account (gMSA) identity. gMSA is an AD-managed service account for which the passwords are automatically rotated.

 

Secure communication and secrets Management

 

Communication between the control plane components is protected by Transport Layer Security (TLS). AKS-HCI comes with zero-touch, out-of-the-box provisioning, and management of certificates for the infrastructure and Kubernetes built-in components. Additionally, the Kubernetes secrets are encrypted at rest using strong Advanced Encryption Standard (AES), with the ability to rotate the key encryption keys (KEK).

 

Integration with Azure security assets

 

AKS-HCI is integrated into the Microsoft security ecosystem, which allows extending Azure security constructs such as Azure Container Registry and Azure policies. In the future, integration with Azure assets like Azure Security Center will provide customers the ability to monitor for threats and offer pre- and post-runtime security assessments for both the infrastructure fabric and the Kubernetes cluster. This helps in monitoring for threats and keeping a strong security posture.

 

Join us in this journey

 

Security is a journey, not a destination. These are just some of the security features that we are working on and making generally available (GA) soon. AKS-HCI is going to be continually updated like a service. We will add more security features and continue to further harden the platform. Join us in this journey: we would love to hear feedback, experience, and insights on security. Be part of discussions in our Github repository.