Cloud and Datacenter Management Blog

Microsoft Hybrid Cloud blogsite about Management


Leave a comment

My Highlights Day 3 of Microsoft Ignite 2024

Mark Russinovich and Scott Hanselman on Stage talking about Copilot, ChatGPT and AI

Scott and Mark learn responsible AI

Always check the output of AI πŸ˜‰

Microsoft Azure LocalΒ 

NEW Microsoft Introducing disconnected Operations (Preview) βœ…

Azure Local with disconnected Operations
Awesome!

NSG with Azure Local βœ…πŸš€

Security in Azure Local video

 

Defender for Cloud

Get Started Today πŸš€

Azure Linux 3.0 on AKS kubernetes in Preview

QuickStart

AKS Automatic
Dynamic System Node pool in Preview

More Buit-in policies for AKS

Auto-Instrumentation with Application Insights
Preview in January 2025

Enhanced Risk & Attack Path Analysis for Containers

Microsoft Azure Container Registry – Image Auto Patching in Private Preview
Security on Vulnerabilities

Network Isolated Cluster in Public Preview
Here you findΒ Best practices for cluster isolation in Azure Kubernetes Service (AKS)

Microsoft Container Vulnerabilities Management

Container Vulnerabilities Assessment throughout the software development lifecycle.

Defender for Cloud Container Security
Continuously reduce risks.

Attack path and remediation on your AKS Kubernetes Cluster Inside overview

Container Security posture from Code to runtime is important! βœ…

Microsoft Azure Kubernetes Fleet Manager Auto-Upgrade

Microsoft AKS Static Egress Gateway for Pod-level Access Control.

Block pod access to the Azure Instance Metadata Service (IMDS) endpoint (preview)

Trusted launch for Azure Kubernetes Service (AKS)

Seccomp Default Public Preview

Node Auto Provisioning GA January 2025

Comprehensive Security Controls overview

Experience Security Copilot Today βœ…πŸš€

My Conclusion

Always start small with New innovative features like Azure Copilot or making your Adaptive Cloud first in a test environment.
Do your own experiences, testing and make your Secure architecture designs for your production. Keep it simple because it can be quick complex with a lot of dependencies. Microsoft works hard to make your life more easy in this changing IT landscape πŸ‘
I like to thank all the people who supported the Microsoft Ignite 2024 event, it was Awesome with a lot of Great News. πŸš€

Here you find the Microsoft Ignite 2024 Book of News.

 


Leave a comment

My highlights Day 2 of Microsoft Ignite 2024

Microsoft Azure Adaptive Cloud approach enabled by Azure Arc.

Adaptive Cloud approach Key Services and Products.

Operate everywhere with AI-enhanced management and security

AI-enhanced Central Management & Security

Get Started with Azure Arc Jumpstart here

Welcome to the heart of our mission at Azure Arc Jumpstart, where we strive to transform your learning experience into a smooth and empowering journey. Our commitment is rooted in the principles that drive us forward:

  1. Enabling immediate engagement:Β Arc Jumpstart is designed to offer a seamless “zero to hero” experience. We understand the value of your time, and our goal is to enable you to dive right into Azure Arc, eliminating barriers and complexities.

  2. Comprehensive guidance:Β We provide more than just guides; we offer comprehensive, step-by-step instructions tailored for various independent Azure Arc scenarios. Our content is meticulously detailed, incorporating extensive automation, vivid screenshots, and insightful code samples. This ensures that your learning journey is not just informative but also visually enriching and deeply engaging.

  3. Unparalleled user experience:Β Our dedication lies in delivering a rich and immersive experience. We go beyond the basics, curating a user-centric environment that resonates with both beginners and seasoned professionals. Whether you’re setting up your environment on-premises or in the cloud, our guides empower you to focus on Azure Arc’s core values without being bogged down by technical intricacies.

  4. Embracing platform flexibility:Β We recognize the diversity of your infrastructure, and our mission is to provide a platform-agnostic approach. Arc Jumpstart accommodates your infrastructure, whether it resides on-premises or in the cloud. Our focus is to ensure that regardless of your setup, you can harness the true potential of the Azure Arc platform effortlessly.

Investments to further the Adaptive Cloud Approach πŸš€

Introducing Microsoft Azure Local enabled by Azure Arc

Scott Hanselman about Visual Studio and Copilot

More AI development in Visual Studio or VSCode

Microsoft Windows 365 Link

This is Awesome, my next question is:
How fast will this solution be on Mobile?

Windows Hotpatch will be Available Spring 2025
for Windows 11 and Windows 365.

Windows Resilient Security Platform

Quick Machine Recovery in Insider program early 2025.

Microsoft working together with Cybersecurity & Infrastructure Security Agency

Smart App Control only Verified apps are allowed.

Windows Hello for Business Update with support for passkey.

Administrator Protection.

Personal Data Encryption to Windows Enterprise
Only decrypted via Windows Hello

Microsoft 365 in File Explorer

Windows Search is Cool 😎
Coming in 2025

My Conclusion

Make your own test environment and become a Windows Insider to be one of the first to test these Awesome New features!
You can make this of course in Microsoft Azure Cloud or in your own Azure Local environment πŸš€
There are so much possibilities, to keep yourself up-to-date with this changing IT landscape.

 

 


Leave a comment

Day 2 of Microsoft Ignite 2024 with Azure CTO Mark Russinovich

Mark Russinovich Microsoft Azure CTO Starting and Running 10.000 Containers in Azure in just 90 seconds!
That is unbelievable 😎

Here you find my screenshots and links of the Microsoft Ignite 2024 session with Mark Russinovich.
First a quick introduction about Microsoft Azure Boost in this video.

Microsoft Azure Boost more IOPS and Throughput

Before and After Azure Boost Local Storage improvements.

Can you believe it, these are no typo’s 6.6 M IOPS ! 😎

Azure Boost Networking

Network driver Update in Azure Boost.

Software Defined Networking (SDN) Today

SDN Accelerating offloads with DPU

 

Secure 1.6 Tbps+ to storage over WAN
Can you believe it 😎

Microsoft announcing Azure Container Instances NGroups (Preview)

Cloud Native Apps are more than just Kubernetes

Radius in the Cloud

New Azure Container Solutions

Security Trusted Execution Environments (TEE)

When you missed Mark Russinovich at Ignite 2024 session, you can watch it on-demand here

My Conclusion

Not only with Microsoft Copilot, Azure AI or Open-AI is the IT landscape changing, but the Adaptive Cloud is evolving very quick and hardware, Software Defined is getting faster and faster but also scaling in Datacenters.

This Jeremy Winter Talking about Power-efficient Datacenter Infrastructure.

Power-efficient datacenter infrastructure is very important for Microsoft, and what I see is More Software solutions with less hardware.
Software defined and AI solutions are changing the IT Cloud Landscape also in a Hybrid way with On-premises Datacenters.
10 years ago IT workloads was 80% on-premises datacenters and 20% in the Cloud, Today this is Changed to maybe 30% on-premises and 70% in the Cloud of companies IT solutions.Β  Here you can Learn more at Microsoft Learn Ignite 2024


Leave a comment

Update Windows 11 Insider Dev Preview Build 26120.1330 with Azure Windows Admin Center

Windows 11 Insider Preview Dev Build Update 26120.1330 in Microsoft Azure WAC.

The Microsoft Windows Insider Program Team released Windows 11 Insider Preview Dev Build Update 26120.1330

JOIN the Windows Insider Program, It’s a community of millions of Windows’ biggest fans who get to preview Windows features. While previewing Windows, Insiders can provide feedback and engage directly with Microsoft engineers to help shape the future of Windows.

Here I manage Windows 11 Insider Build in my MVP LAB with Microsoft Azure Windows Admin Center.

Since June 2024 Microsoft Azure Windows Admin Center supports Windows 10 / 11 in the Cloud.

Update Done via Azure WAC πŸ˜‰


Leave a comment

Microsoft Azure Copilot Preview in the Cloud to Support you

Azure Copilot

Microsoft Copilot in Azure (preview) is an AI-powered tool to help you do more with Azure. With Microsoft Copilot in Azure, you can gain new insights, discover more benefits of the cloud, and orchestrate across both cloud and edge. Copilot leverages Large Language Models (LLMs), the Azure control plane, and insights about your Azure environment to help you work more efficiently.

You can try Copilot now in the Microsoft Azure portal in Preview !

Click on Copilot and click on Next.

Give your feedback.

Click on Try Copilot.

Now you can use Azure Copilot Preview.

for example, show me all running Virtual Machines.

Here you find the Microsoft Azure Copilot capabilities

Prompt engineering is the process of designing prompts that elicit the best and most accurate responses from large language models (LLMs) like Microsoft Copilot in Azure (preview). As these models become more sophisticated, understanding how to create effective prompts becomes even more essential. Read here more aboutΒ Write effective prompts for Microsoft Copilot in Azure

Conclusion

Microsoft Azure Copilot preview can be very handy to support you with deployments, troubleshooting in Azure Cloud services and
Hybrid with Azure Arc. Time to market and going live in production can be quicker because you don’t have to search yourself for the right command or scripts. Copilot will be smarter and more efficient, and you can learn from Copilot approaches. You are still in control because you have to check it if Copilot advise is the right thing to do. Try it yourself and experience the Azure Copilot Preview version πŸ˜‰

Join the Azure Copilot and Microsoft Security Copilot LinkedIn Community Group

 

 

 


Leave a comment

Keep your Azure Connected Machine Agent Version Up-to-Date and your Extensions too

Windows Server 2025 Insider Preview Azure Arc enabled Server

The Azure Connected Machine agent receives improvements on an ongoing basis. To stay up to date with the most recent developments, this article provides you with information about:

  • The latest releases
  • Known issues
  • Bug fixes

Here you find more information about each new release of the Azure Connected Machine Agent

Further more, keep also your Azure Arc enabled Extensions up-to-date for your Azure Hybrid Services.

Automatic extension upgrade supports the following extensions at this moment:

  • Azure Monitor agent – Linux and Windows
  • Log Analytics agent (OMS agent) – Linux only
  • Dependency agent – Linux and Windows
  • Azure Security agent – Linux and Windows
  • Key Vault Extension – Linux only
  • Azure Update Manager – Linux and Windows
  • Azure Automation Hybrid Runbook Worker – Linux and Windows
  • Azure extension for SQL Server – Linux and Windows

More extensions will be added over time. Extensions that do not support automatic extension upgrade today are still configured to enable automatic upgrades by default. This setting will have no effect until the extension publisher chooses to support automatic upgrades. So have a look at your manual upgrade extensions too!

Here you find more information about Azure Arc extensions for your Servers.

Update your Azure Arc enabled Server Extensions.

Some are not Automatic Upgraded by Default!

Updating the Azure Arc enabled Server Extensions.
Important Message:

Don’t forget Migrate to Azure Monitor Agent from Log Analytics agent

Updating the Azure Arc enabled Server Extensions Succeeded.

Keep your Azure components Up-to-date πŸ˜‰


Leave a comment

Happy Holidays

I wish you all a Merry Christmas and a Happy & Healthy New Year 2024!
Thank you for all your support in the Community.

Join these Free LinkedIn Community Groups during the Holidays and keep up-to-date πŸ˜‰

Microsoft Azure Monitor & Security for Hybrid IT

Azure Hybrid Community

Windows Admin Center Community

Azure DevOps Community

Containers in the Cloud

Azure Copilot and Security Copilot (NEW)


Leave a comment

Adding Windows Server 2022 to Azure Arc Services #AzureHybrid #HybridIT #Azure

Azure Arc Enabled Server

With Microsoft Azure Arc Machine agent you can connect your Windows Server 2022 with Microsoft Azure Arc Services.
Microsoft Azure Arc-enabled servers lets you manage Windows and Linux physical servers and virtual machines hosted outside of Azure, on your corporate network, or other cloud provider. in October 2023 Microsoft released via Windows Update Center the setup of Azure Arc Machine agent. In the following steps I will install Azure Arc via the Windows Server Manager:

Click on Disabled

Click on Next

Azure Connected Machine Agent is installing.

Click on Configure

Click on Next

Sign into your Azure Subscription

Click on Next

Select your Azure Active Directory Tenant.
Select Subscription
Select the Resource Group
Select the Azure Region
Select Network Connectivity.
Click on Next

 

Your done, your Windows Server is now connected with Azure Arc
Click on Finish

Here is our Azure Arc enabled Windows Server 2022 in the Microsoft Azure Portal.

 

From here you have all the Azure Arc Services available for your on-prem Server.

When you connect your machine to Azure Arc-enabled servers, you can perform many operational functions, just as you would with native Azure virtual machines. Below are some of the key supported actions for connected machines.

  • Govern:
  • Protect:
    • Protect non-Azure servers withΒ Microsoft Defender for Endpoint, included throughΒ Microsoft Defender for Cloud, for threat detection, for vulnerability management, and to proactively monitor for potential security threats. Microsoft Defender for Cloud presents the alerts and remediation suggestions from the threats detected.
    • UseΒ Microsoft SentinelΒ to collect security-related events and correlate them with other data sources.
  • Configure:
  • Monitor:
    • Monitor operating system performance and discover application components to monitor processes and dependencies with other resources usingΒ VM insights.
    • Collect other log data, such as performance data and events, from the operating system or workloads running on the machine with theΒ Log Analytics agent. This data is stored in aΒ Log Analytics workspace.

This is handy to install a couple of Servers manually but when you have to do more, you can generate a script for multiple
Servers installation:

From the Azure Portal
Click on Generate Script

Here you can make a Basic script or for Configuration Manager,
or a script for a Group Policy or via Ansible.

Important:

Before you begin with making your Windows Server Azure Hybrid with the Arc Connected Machine Agent, you have to think about Security by Design. with Identity Access Management (IAM) you can manage who will get access to your Arc enabled Servers.
Wo may use Windows Admin Center for example in the Azure portal?

Access Control on Azure Arc enabled Server.

With Microsoft Azure policy you can set your governance and policies for the organization. There are a lot of pre-defined policies, but you can also make your own Azure policies for your Arc enabled Servers.

Conclusion

Make your datacenter(s) securely Hybrid with Microsoft Azure Arc Services is easy to do and gives you a lot of Azure Hybrid benefits.
Start with your test environment and make your own Azure Arc enabled solutions and when the experience is good you can do it in production πŸ˜‰

Β Here you find more about Azure Arc enabled Services:

Join the Azure Hybrid Community on LinkedIn for Free


Leave a comment

Whats new with Azure Connected Machine agent and More CLI #AzureArc #AzureHybrid

Azure Connected Machine Agent

Microsoft is continuously improving and fixing issues on the Azure Connected Machine agent for Azure Arc Enabled Servers.

Before you make your Servers in your datacenter Hybrid with Azure Arc Connected Machine Agent, you can have a look at Security first when you want to be in Controle of the Azure Arc extensions. For example, who can install Azure Arc Extensions? and which Extensions should be installed and which not. Or in the latest Azure Connected Machine Agent Version 1.35 of October 2023 No Extensions allowed to install on this Server.

With Azure Arc Connected Machine Agent version 1.35 you can configure the extension manager to run, without allowing any extensions to be installed, by configuring the allowlist to “Allow/None”.Β  This supports Windows Server 2012 ESU scenarios where the extension manager is required for billing purposes but doesn’t need to allow any extensions to be installed.

Users and applications grantedΒ contributorΒ or administrator role access to the resource can make changes to the resource, including deploying or deletingΒ extensionsΒ on the machine. Extensions can include arbitrary scripts that run in a privileged context, so consider any contributor on the Azure resource to be an indirect administrator of the server.

TheΒ Azure Connected Machine Onboarding role is available for at-scale onboarding and is only able to read or create new Azure Arc-enabled servers in Azure. It cannot be used to delete servers already registered or manage extensions. As a best practice, we recommend only assigning this role to the Microsoft Entra service principal used to onboard machines at scale.

Users as a member of theΒ Azure Connected Machine Resource Administrator role can read, modify, re-onboard, and delete a machine. This role is designed to support management of Azure Arc-enabled servers, but not other resources in the resource group or subscription.

Identity and Access Management (IAM) in Azure to Configure Roles.

Azure Arc Portal Agent version.

With AZCMAGENT CLIΒ command, you can see more information from the Arc enabled Server and is handy for
the Administrator to know:

azcmagent check

azcmagentΒ Config get config.mode

azcmagentΒ show

azcmagentΒ logs

in ProgramData you will find the Azure Arc Connected Machine Agent Logs

Guest config logs of Azure Arc extensions

The Azure Connected Machine agent command line tool, azcmagent, helps you configure, manage, and troubleshoot a server’s connection with Azure Arc. I just showed you some azcmagent commands I use for troubleshooting or to just get the right information.
Here you find the complete Azure Connected Machine Agent Command line reference

Hope this information is useful for you and keep your azcmagent up-to-date for fixes and new innovated features!

Join the Azure Hybrid Community on LinkedIn Group

 


Leave a comment

Windows Server Insider Preview Build 25967 with Azure Arc in Taskbar

You can Download Windows Server Insider Preview Build 25967 here

New in Windows Server Insider Preview Build 25967 is Microsoft Azure Arc in your taskbar system tray Icon.

Currently, Azure Arc allows you to manage the following resource types hosted outside of Azure:

  • Servers: Manage Windows and Linux physical servers and virtual machines hosted outside of Azure.
  • Kubernetes clusters: Attach and configure Kubernetes clusters running anywhere, with multiple supported distributions.
  • Azure data services: Run Azure data services on-premises, at the edge, and in public clouds using Kubernetes and the infrastructure of your choice. SQL Managed Instance and PostgreSQL (preview) services are currently available.
  • SQL Server: Extend Azure services to SQL Server instances hosted outside of Azure.
  • Virtual machines (preview): Provision, resize, delete and manage virtual machines based onΒ VMware vSphereΒ orΒ Azure Stack HCIΒ and enable VM self-service through role-based access.

Here you find the Azure Arc system tray icon.

Here you can see the Microsoft Azure Arc Status
and
You can connect to the Azure Arc enabled virtual machine in the Cloud.

Azure Arc enabled virtual machine in the Cloud.

Windows Admin Center via Azure Arc enabled Server.

Azure Arc Management in Server Manager!

Here you find more information about Windows Server Insider Preview Build 25967 on Microsoft Tech Community.

JOIN Microsoft Azure Arc Hybrid Community on LinkedIn