Episode 380 – The future of AD FS is cloudy
by [Ben](/content/author/benmsclouditpro/ "Posts by Ben"/index.html) | Jul 18, 2024 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 380 of the Microsoft It pro podcast recorded live on 07/12/2024. This is a show about Microsoft 3 65 in Azure from the spec to of It pros and end users, where we discuss the topic or recent news and how it relates to you. With the recent news about the At and T data breach or data league we start, top off talking a bit about security identity protection into recent security alert in Ben's Microsoft 3 65 tenant. Then staying along the lines of security, we discussed the recently released Ad ass migration tool in some of our thoughts around migrating from Ad fast to Microsoft Enter Id. Wow. It's a Friday. Scott. It is... Run the right microphones phones for recording, I'm using the right camera, And if you're on At and T your data has been stolen. If you're on any United States carrier, date has been stolen and at some point. Heck, if you live in the Us, actually, I think if you live anywhere in the world at this point, your data has been stolen. Yeah. I saw 1 the other day it was, like, the largest credential dump is floating around, like the Dark web and it's, like billions of records. Have you had this issue? I've had this issue in Teams. Then we'll go back to At and T where it just randomly switches to a different audio source while you're using Teams. Is that what just happened? I don't know. Like, my speaker went from my ding to my speakers. Which was weird. Got it. Anyways, Okay. So back to At and T, Yeah. I can't remember if we talked about this or at this somewhere where realistically, you should operate on the assumption that your data has been stolen versus that you're trying to protect your data at this point in time. So there is another article this week. I'll pop a link in the the chat and Show notes for everybody. So the largest password database leak was also this week. So that was 9 point 948 million unique plain text passwords. Wow. Released by the threat actor dubbed Obamacare as part of the ro 20 24 dot TXT file. Can't make that stuff up. So creative. It's wild. This 1. I don't know did you see this At and T 1. Apparently it came from snowflake. So I'm curious to see more too if this was, like, At and T cr that were compromised to get into snowflake kinda like did they go through At and T to get to snowflake? Or was there a breach in snowflake? Because there been a bunch of stolen records that have come out of Snowflake. This article talked about... Who was it ticket master lending tree and some others that have all data stolen from snowflake specifically. So it's, like, was there issue. Snowflake. I don't know. It doesn't it doesn't really say, but a hundred and 10000000 At and T customers and it was, like, not just their information, but who they texted in who they called. So it was records of who called who who texted who didn't contain time date or the data of those, but still being able to draw a bunch of connections between different people based on who they're calling and texting. This is not an insignificant breach. No. It's not. So snowflake had a breach over the summer. And, like okay I guess, we're still in summer so. So this summer. It's snowflake kinda a breach. There there were, like, a hundred plus customers that were potentially leaked out in that breach, and, if I'm remembering great, it was actually, like, an ex campaign that kinda brought it all to bear. But you'll be happy to know that as of this week, what we're July 12. What is? Today's July July 12 So as of July eleventh, Snowflake has decided to enable and enforce Mfa. Ironic that that came out the day before this did. Yeah. The, you know, the the the hits just keep on coming. I think it's a good lesson that none of us are actually in control of a lot of the data about our lives once it gets out there, you said, you kinda think about ways to mitigate that and kinda work through it. So I don't know how it works outside the Us, typically with a lot of these breaches in the Us like... And I imagine this will happen in the case of At and T, like, as a major provider with hundred million plus customers. Usually, they'll reach out, offer you some form of monitoring. So, like, for a credit card beat preach that could come in the form of credit monitoring for things like your credit score and maybe through, like Trans, or Ex ex or or some of the companies that monitor and watch that stuff could be other protections that are out there, like, I don't know. I've had, like, free ex experience and Trans, whatever premium monitoring for what feels like, the past, like, 5 years. Just because there's always another breach, and I just keep upping it for free. That makes sense. I've done identity theft insurance. So I actually went and bought identity theft insurance for, like, the entire family, and it's relatively inexpensive. I wanna say I pay, like, a hundred and 40 bucks a year or something. It's like 12 bucks a month. And they will monitor a bunch of that stuff as well so that if I didn't actually have free which. I'm like, you. I feel like, I've had free forever. But then if there is a case where, like, me or 1 of the kids or my wife or we have identity stolen, they are also will help resolve it, take care of any issues, get identities back, all of that. And again, kinda operating on the assumption that it's out there. And if it happens, it's a relatively small price to pay. Because everything I've heard that if your identity does get stolen, it can be a nightmare to get everything un entangled by yourself. Yeah. So I've never done identity theft in insurance. So last time I looked into it, and again, this could be Us specific. The insurance was very, like specific in the legal east in that they would provide you coverage, but the coverage around costs was related to the recovery process. After you've become a victim of Vice theft, it's not the recovery of funds prior, we which is a little bit weird. So say somebody spending money on a credit card for illegally for, like, the past year, and they've rung up, like, 50 k and in fraudulent purchases. The 50 k in pro fraudulent purchases isn't what's covered. What's covered is the time and the money to get that fixed. So you're still on the hook for the fraudulent service or you still need to go and work that out with your financial provider. And I couldn't find any... So so maybe you and I left to chat offline. Maybe you found a better option or maybe you found 1 that did kinda, like, work through this. But it seems to be a pretty big loophole in coverage in that, like, you're effectively still on the hook for the fraudulent purchases. It's more about, like, recovery afterwards. Which in my mind, I'm like, hey, recovery. Wouldn't does that mean covering the fraudulent purchases? It does not... I'd have to look at when this starts. The 1 I have is up to 2000000 dollars for stolen funds and expenses. So again, when that starts if it, like, is retroactive to when it was originally started or once they discover the fraud, if it's only stolen funds and expenses after you discover it, but, yeah, we can talk more about this 1. And maybe throw some links in the show notes if other people are interested. So 1 other security topic, unless you wanna talk more about identity theft and data breaches I had an interesting 1 in my Microsoft 3 65 tenant today. Actually. Are you spam again? I am still absolutely getting spam Although I finally got the first 1 to go to quarantine, I've had a crazy spam problem coming from a dot on Microsoft dot com account Neither here nor there, but this is 1, I got an alert Microsoft defender, and I'm not gonna share this 1 because of information that's in it, but essentially, I got an alert this morning that 1 of my guests users in my tenant that I had shared something with that Truth told it was like 5 or 6 years ago. So this is a lesson learned. 5 or 6 years ago that I shared I invited them to a team channel. The team channel has long. The team has gone, I think the team has gone or archived. The channels got her archived, It was for some training stuff so nothing in there, but I got an alert that I had a user account in my tenant, accessing my tenant from tour Ip address. And when it it looked in, I will say defender did a good job, like it picked it up pretty quick based on all the audit logs, like, within seconds of the first activity. And actually went in and deleted the guest user. Just remove them from my tenant cleaned it all up. I didn't even recognize the username. So first I was like, oh, who is this guest username my tenant? I did some searching figured out when I had interacted with them when I had invited them, good thing is again, It didn't have any access to anything in the tenant because everything is long since come gone. But It appears because this credential was also used like, 4 different times, and this is part of why I got picked up to 4 different times in the course of a few seconds, to access my tenant as a guest, and it looks like it was probably in teams from, like, 4 different countries. Welcome to the fund that is be being on AAA tour. Right? And Right. The layers of the onion and and how all that comes together. It's an interesting thing. So so it's funny you bring this up. We do annual security training. And part of... Well, I mean, we do it more manually. But part of the latest round of security training. Actually had a section in there that talked about guest users. And actions that we as employees need to take when we're dealing with guest users and things like teams. So it's a very manual process. Right? Like, if you finished a project, like, you said, you've done all the things. You've archived the team, you've archived the channel. Like, it turns out you actually do have to go and, like, explicitly revoke access from those users to kinda clean it all up. Feels like a great space for, like, an Is or somebody to step in. Just have, like, the tenant monitoring blah blah blah. I'm surprised Microsoft doesn't have it and, like, some kind like, built in life cycle management for guests, but a lot of the onus is still on individuals who are spinning these things up. Have the context. Like, I get why it's hard automate. You don't know. Like a guess Google dormant for 2 months, and it turns out maybe they're needed later kinda thing, whatever. Yeah. Well it's a hard problem. It feels like a sol 1 as well. May maybe an Ai could solve it for us who knows. Yep. And I haven't not done this in mind. Maybe we should do a podcast on this. They have, like, their life cycle workflows in their identity governance, and the access reviews, which I would say get close. I don't know that you could build a full life cycle workflow. Because life cycle workflows are usually more onboarding new hires group membership changes, off boarding employees, off boarding employee, off boarding employee. It doesn't look like And I've looked at these some, you can do it for guest users. Access reviews, I know you can set up for guest users that are guests of teams and groups. Where it would, like, every 3 months that essentially goes through a team in or a Microsoft 3 65 group, re really? Because that's the identity structure under the team. And you can set those up for guests and say, every so often looks roll my teams with guests and send notifications to the owners, Does this guest delete access to this team group? If not, like, by default, delete them or by default, leave them or after the owner hasn't set it for so long or responded for so long, escalated it to somebody else, but it isn't necessarily I think it falls a little short, and then it doesn't have that ability to necessarily delete the guest from your tenant. Kinda like mine was. The team was gone. An access review could cleaned them up from the team, and I think I may even manually cleaned them up from the team, but they're still stuck in intra, and even you like At Microsoft, you're not gonna have the ability to go into entrant and delete remove users. So it does have to fall to an admin. Yeah. You really need like, holistic. You almost want like all the life cycle management components to come together. So, like, life cycle for my team, life cycle for the data and the That exist in there. Life cycle for the users, all the way back down to the identity store, be it And and Id or or whatever kind of thing. Especially for like, these more, like, project driven workflows, like you really would wanna. I think, like, you know, it'd be an interesting world where you come in and you say, hey, I'm spending up a new project and that thing automatically creates a team, and it has some metadata that's says here's the start date. Here's the end date. And then once you hit the end date, if you haven't extended it, then it goes and kinda runs the machine and does all the other stuff behind it, but it says humans are bad at managing information. I've learned that very well over the course of my career, myself included. You know, sometimes you need, like, the state machine to come and kick things and move it forward and get it going. So... Tl, these things are gonna continue to happen. They'll continue to be an issue, be vigilant even in your own tenants. Yes. And I will give props to defender. It did a good job. It caught it. It deleted it, and then right from within the incident that it generated. I was able to go, I reviewed all my logs. I'm like, okay. Did this user... Is there data? This guest account accessible. It was in there? Was there data that was still shared with this guest account. Like everything came back, like, there was nothing there. For all I knew it was still the user that happened to be on a to network with his company account, and opened up teams and hit my tenant because once you're a guest, you have, like, a gazillion different teams, in your tenancy and all it does is just taking it opening up, trying to re in teams to. Yep, pop that up. But yes, Looks like have a safe, but it... It's a new 1 for me. I had not ever seen that before. So like you said, be wary with guest accounts. And their life cycle and how you manage them? Be beware with your own user accounts too. No Limited it to guests. That as well. Be wary with all the accounts. Yeah. I think people forget about guest accounts. An easy 1 to slip your mind especially when you just shared an document with 1 and didn't, like, that whole process of now they're guest accounts. I do like the 1 time passcode stuff from that perspective where there is some sharing now you can do where it doesn't create a guest account. It's just like a 1 time Act. Cisco code, you get it and that also can help with some of that. So with that, 20 minutes later, good conversation. Should we jump into our topic that we had planned for today? Jump into this 1 a little bit? You put all this work into planning. We should get to it. We should get to it. And it's still kinda released. To this. Do you feel overwhelmed by trying to manage your office 3 65 environments are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge, how to best keep your car running, intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization several thousand employees. They want to partner with you to implement and administer your Microsoft cloud technology of Visit them at intelligent dot com slash podcast that's INTELLIGINK dot com slash podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent jake focuses on the Microsoft cloud, so you can focus on your business. So this was an article, take from Tech nut that popped up, and it brought up an interesting conversation. It was from June 26. So this was few weeks ago now, but it's moved to the cloud or move to cloud authentication with the the Ad or active directory Federation services, migration tool. So this was an announcement that the migration tool for Ad fast, to move their apps to Microsoft Enter. Id is now generally available. They can update identity management, they announced the Efs application migration moving to public freebie back in November, all of that. We can talk about the tool, But what I think is interesting about this, Scott. And we talked about this a little bit is further down in this article, they have a diagram with Ad efs, and enter Id in highlighting limitations of not transforming to and try Id and benefits moving to Id, but then they also label Ad is the old way in try Id as the new way, and this spurred a very immediate comment on the article. Given this new tool, the age complexity, security limitations of ad fast and improve technology being available, Do you consider a road map on Ad s d fabrication? And we started talking a little bit? Or 1 about this tool but too about Ad efs and try, comparing them as 2 different ways of authentication, especially in old way in a new way, And I would say even more so that in my head, this triggers eye old way new way, but it's also... Is Microsoft saying on prem is the old way cloud is the new way versus some of these where it's... They're still providing an on prem solution. This is almost starting to say, and I think where this comment is coming from is, is the on prem identity for something like Ad efs or a lot going away and interest going to be the only way forward or there's a lot of questions, I think. Around just the way some of this was labeled. And I still have customers on Ad s 2, which makes me think about it. I don't think this is too different than what everybody's been hearing for years now. In that there's a focus on the cloud and cloud services. And, you know, it's kind of a a funny list if you go and and look at their they're framing for old way in new way, like, you could apply just about any of these benefits to any cloud solution. Over to, like, remove Ad fast from it. Right and so, like, they talk about, like the new way and the benefits. So benefits, more agile than responsive Ai future ready. Whatever. We'll throw the Ai thing out the window for a second, but more agile and responsive, sure. Like, if there's an evergreen service that's constantly being updated in the cloud, that's gonna be more responsive. That could be ent, that could be exchange that could be your toaster fridge in the corner and it's firmware, like, like, whatever it is. Right? Like, like those things. If they're running and somebody else responsible for running them in their data center. Like, they're gonna be more agile more up to date. Reduce costs and operational complexity. Again, that's not Ad efs specific. It's you're just removing the costs and the Capex and Op associated with running on prem kit. So, hey, I don't need to lease new servers. I don't need to worry about getting the latest version of that load balance or or whatever it happens to be those kinds of things. Requirements around where data is home. So you know, if you think about, like, try versus on prem. Well, on prem. Everything's gotta be an active directory. And then you go, well, Great Scott, Like, everything's gotta be an intro Id in in in the cloud. Isn't it the same. Yeah, kinda sorta of not really though because entry Id is more than 80 domain accounts. It's devices. It's this whole other world of like, constructs and personas and and types of things that exist out there. And then in the last benefit they had was eliminating vulnerable assets. I kinda put that back under the hidden costs of maintenance of on prem things. Benefit you're moving at a different pace. Somebody else is responsible for the the security and all the other things around it. So in Ad s Land, like, you're like, well, Microsoft is still responsible for the security either way, whether it's Ad efs or whether it's enter in the cloud. Yes and no. Like, they're responsible for the software, but you're responsible for deploying the software. You're responsible for deploying all the, surrounding kit on those things. Right? Because it's not just an Ad f server. It's usually multiple Ad f servers. Usually those sit behind a load balance. There's probably also, like, firewalls and Ips, Ids, things like that in in line in there that all need to be updated and configured as well. How I think it was interesting just to kinda see the framing of this. But clearly, there's a desire to, you know, shift customers away. From on prem. And then the reality is, like, once you're in enter in the cloud, like, you're probably not going back the other way either. I would agree on those benefits and how they framed it It's an interesting comparison to make and. I have started having these conversations with some of my customers that are like, we wanna start getting off of Ed efs. But I've also had conversations. I don't know that I have any customers that I've had it with that I have Ad fest today, but there is... Also still a few feature gaps. I would say between Ad ass and and try d. I don't know what all of them are because I don't do a ton with Ad ass, most of my customers that have it. I know it's there and we've done some work with it. But I do know 1 that. This is an interesting 1 that comes up over and over and over again is customers limiting the time that people can log in to a service. Like these employees are only allowed to log in between 8AM and 5PM. And there's been various requirements that make valid sense for that. It actually makes sense from a security perspective. Right? Like, some of my workers that are maybe scheduled to work a particular shift or work certain hours and should not be accessing company data outside of those hours, Some of that I've heard around need to pay them over time if they're accessing company data outside of work hours. Some of it could be a security thing. If they're on the clock, they can access data, but I don't want them logging in anywhere else when they're not at work. You could argue well you can do device join and some of that. But that's 1 that has come up a lot. And I'm like, yeah. There isn't the way to sell that right now and enter. And I do know that can be solved with Ad s. Because that's been the answer for a long time. So... Again, maybe some of these will start coming to Intro. If anybody's listening on the enter team and wants to add a new feature to Enter, you need something to add in this next fiscal year. Time bound logins to enter would be on a list of things that I've been asked about. That's an interesting 1. So you're 1 of the few people who I've actually heard frame it as a business problem versus a security problem. So, like, if you go out and you'd look, We talked about this like, last week when we we're going it. So III was kinda looking around. I was like, you know, it's like, it makes sense. Like, why isn't it there? I can see it, like, based on the way you framed it. And everything that I saw, every time somebody asks about this, they often frame it in context of security. Where they're like, oh, this person not being able to log in at this time is more secure, or I only want admins to be able to log in into these times. Like, And from that lens, it's like, well, no. Not really. It's more like security through obscurity. Right? Because once you're in with the access rates you have, it doesn't matter if you're doing that at 12AM or 12PM, like, in is in kind of thing. Right. So from a security lens, like, yeah. It probably doesn't make a ton of sense Like, I'm I'm sure there's somebody out there who can rationalize the way into it. But, like, it's just soft to cough, Like, doesn't make a ton of sense from a security perspective. Like, it's more a a piece of business functionality. And then that actually makes it I think harder to prioritize in today's world, So, like, you know, we opened with the whole credential theft thing. So with And Microsoft being the provider of that service. Do you want them to spend time on a user nice, like, time based to access control? Or do you want them to focus on better audit logs and better restrictions and being able to catch people on to networks or the traffic from China or rogue actor, things like that. Like, most people are gonna say, like, no. I actually wanna focus on the security stuff. So that's where the time, like, continues to go and lean into. Maybe this manifests in other ways. Like, I I don't know if it ever becomes, like, a core intra thing. Maybe it shows up as you know, something inside of conditional access. Like, they used to have the configure... What were they, like, the adaptive session lifetimes and things like that. So they've had kind of ish features like this, but they're like, all almost not quite kinds of things. We'll see. And I think to thing for you to do as customers to, like, frame that out and think about it too is what's the Roi? Am I getting it out of it. You know, you're using Ad efs for this thing today, is the writing on the wall that eventually Ad efs goes away. I don't know. But Ad efs also isn't getting meaningful improvements. So at some point you're gonna kinda be left behind. And this same thing has happened with, like, Sharepoint, with exchange, with all these other things. You're just seeing it on kind of a a different timeline and potentially a different scale depending on your organization and and kinda your applications you host in your company and and the way you do business. So we'll see where it bake out. I don't know. Maybe somebody will step in at some point, like, even if Ad f goes away. I don't think the ability for ent intro to be a modern identity provider and support things like Sam off and replying parties. Like, I don't think that goes away. So maybe there's an opportunity where even like, another 1 of, like, the cloud vendors picks it up, like, say, like, an O or something like that. So if you maybe fed through O, Oracle Id, maybe, you know, say there's a theoretical world where Ad goes away. Does that mean, everybody goes to oracle Id or sale pointers. Something. I don't know. You know, we'll see. It's interesting And does that mean... I mean, I feel like almost every organization has something in the cloud But does it also mean for, like, companies that have been purely on prem if this goes away and stops being supported, something like an authentication server, You shouldn't run any software out of support for security reasons. I feel like authentication servers or maybe on another level? Kind of a important. Right. Is it gonna start pushing some companies? Dan. Like, are they gonna get some kickback? I know at 1 point in time, there was, like, this is the last version of Sharepoint on prem ever. And then there were a bunch of customers that said, can we rethink that? And low and behold we had Sharepoint. Subscription edition, I can't remember if there was even like a Sharepoint 20 19 and then Sharepoint subscription edition after that, how the timing of that worked, But I would imagine that. And again, this is not... Don't interpret this as Ad s is going away because there has been no announcements about it. But it definitely feels like it's Microsoft trying to push everybody to the cloud for authentication, which good or bad. I mean, space at Microsoft was also in the news for security stuff over the course of the last 6 months. So I don't know. Definitely an interesting discussion and I say especially if you do have an ad f server. And again, I've had these conversations already with my clients is, do you need to start thinking about... Let's enter in replacing Ad s with Ent. And they're all already in the cloud. This has already been conversations that have come up for that reason because as they've migrated work workloads to the cloud, and there are challenges that have also come up with Ad aws from their perspective where their like it probably is smart, for us to look at getting rid of our Ad f servers and migrate to given that we're already in the cloud already doing a bunch of stuff for Azure well, Azure ad with Id, all of that. But I will say, well we have a few more minutes, this also led us to this tool, I gotta find it. And I was trying to remember if I've seen this website before Scott. It is set up dot cloud dot Microsoft. And then in this tool, there is a migrate from Ad to my Microsoft and Id for identity management, and this is the website. And the sub site within the website that this blog post redirected us to where it's like a it's an interesting tool We'll put it at that. It's not necessarily a click through and go connect to my tenant, like, maybe I anticipated it was, but it's a guide where, like, on the first page, it's for all types of migrations. The following Ad scenarios can't be migrated to end. So it does start right off with certain cases and it gives you a bullet list there of, these can't be migrated to Ad s and then some stuff are on staged rollout. And if the too select to none of the scenarios apply to my org and I'm ready to move forward, then you can go to the next page, which then walks you through. It's almost like a questionnaire of, then what types of apps are using. They're using office apps, non Microsoft apps Based on those it's an conditional checkbox of Is your Ad efs implementation integrated with Microsoft Enter multi factor authentication server, which has been d by the way. And based on what you select there. So it's it's like a walk through of getting you ready for it. And then I believe once you get far enough we found it, does provide, like, some scripts you can run links out to different documentation to begin your... Some actual migration. And, again, not necessarily the tool I was thinking where it's gonna, like, do a bunch of migrations of apps for you and grab all the metadata, and copy it from your Ad f server maybe into entrance and start creating applications there and automate the migration, but walks you through I would say better than maybe the Microsoft learn documentation does around some of the steps and what you need to think about to actually manage this migration and go forward with that. Migration. I think it abstracts away just like, on the front, like some of the complexities of thinking about, like, sam assertion, Ad what are the potential, like, claim rules that need to be augmented? Like, how do I swing things? How do I roll back? Like, it's not the most. Like un complicated scenario to swing your identity from 1 side to the other and get it to where it needs to be. So it's know I think it depends on the kind of admin you are, like, hopefully, if you're maintaining Ad fast infrastructure, like, you know all this stuff and you know how to go in and like, augment claims roll with your eyes closed. If you don't, then, you know, wizards like this are kind of nice for you to keep you there. Like, maybe somebody else set it up, and it's just, like a piece of infrastructure to your portfolio. You need to go back and maintain it and get it to where it needs to be. So I kinda go both ways with it. Like, 1, it's nice to have to wizard, but the other... The reality is, like, you're gonna end up in those deep dive docks anyway. At the end of the day to get to get where you need to be. This site, the the whole setup dot cloud dot Microsoft dot thing. Set up dot cloud dot Microsoft was interesting me. Like, I never really... I mean, maybe at some point, like they announced this thing or somebody knew existed. I couldn't remember it existed or that it was out there but there's just all sorts of different kind of migration guides. They're they're all in these, like, wizard driven interfaces, right. And so it's like, weird stuff, like, configuring high mode for Microsoft edge. There's a 0 trust setup guide. You can do things by categories. So you can go in and look at like, hey. I wanna look at, like a guide for identity, which would be things like Ad cleanup, so wanna do security. You mentioned defender, like, kudos to defender, Like, hey, Guess what? There... There's a guy. There's a scenario guide in here. For defender for identity, for defender for Office 3 65, defender for cloud apps. There's a bunch of intune stuff with Md. There's per stuff for compliance. There's team stuff for collaboration and voice Right? So, like, how do you configure teams for a frontline workforce? As a guide that they they have in here. They have a bunch of employee experience stuff? Like, don't think I've ever seen engage insights goals, like, Fifa engage, insights, v insights, Vivo goals, all that stuff, like wrap together in 1 place like this, product driven guides it's a really kind of a weird site, and then it replicates some other functionality as well and potentially strange ways. So, like, 1 of the ones you and I were talking about when where we're really looking at this previously was when you do office deployments with the office deployment tool in O t, you have to create some xml to pump into your Ot t file that Xml defines configuration for your office client. Like, what are the things that I'm saw? I'm oh, I'm only gonna saw, excel and word here? And I'm gonna have this turned on. I want a 32 bit. 64 bit architecture, blah all those things. So usually, the way you would do that is there's actually an entire, like, setup and provisioning engine. That's part of the admin center, the interesting thing about the 1 that sits over here is this 1 sits outside the admin center, and you can do it all una a authenticated. Right? Just come in and spin up the Xml and get it out the other side. But then it not only gives you the Xml. It gives you a whole other set of, like, powershell scripts that are bespoke, for you to actually go and do the Odd deployment, it's really kind of a weird du thing. I don't know. But if nobody's seen it I did like, like, the wizard driven interface, the next next next, like, hey, Explain it to me as I go kind of thing, like some of that was nice. Again, It felt like... Even though it duplicated it it puts some of that in, I would say more logical order if you're brand new to it. To your point if you've been doing this for a while, I don't know. Like you and I how beneficial this really is because it does... I would say it tends to focus on a little bit more of the basic stuff. Deployed the Microsoft 3 65 apps, I didn't know look what was in there like for defender. Set up your 0 Trust security model. That 1 be interesting to walk through to see how detailed that 1 gets. Deploying configure defender for endpoint, defender for Office 3 65, analyze security posture. And like you said, some of the stuff that's in here, then you have that mixed in with die mode for edge. I don't I don't know, Scott. You know, you gotta sprinkle the legacy in there with the new stuff. It's it's it's 5. To play and configure edge with a step by step experience. Microsoft search setup guide is somehow under edge. Don't know that I would consider Microsoft search setup up got under edge, but we'll go with it. Yeah. I would say worth exploring. There's... 61 different guides in here, so it is not gonna be all inclusive. Tell me everything I need to know about deploying Microsoft 36C5? There might be couple in here that you find interesting. Preview security are the big ones, V. Yeah. There's 9 of them for Viva. C There was a bunch of. Is it insights goals, engaged that they were all there. There's 1 for Am 2 Scott, which technically isn't even a product anymore. Just in case. I mean, just in case someone's still using the upper. Yes. Which has steve engage. Just think we've engaged. Let's just rec categorize it. Yeah. So nifty tools. If you are still any D ass, you're looking to migrate. There's a click through to maybe help you, I would say to help you think through it. But given some of these, I would also say if you're on Ad ass, and especially if you're already using Ent for identity, this is probably something you wanna start thinking about doing. Or even start to think about, like, how you scope those things down and segment them to? I think... Some folks view, identity is, like, an all or nothing scenario. And, you know, so, like, all my users are in the con domain. Therefore everyone has to authenticate through 3 D efs? Well, maybe maybe not. Right? Like, you might want more security for, like, your admins and your admin accounts and maybe that actually requires, like, a different tenant with a different configuration and maybe the that stuff does go through Ad efs or it goes through some other security token service. Right? That can just sit out there as a relying party and and do what it needs to do. I live in that world for sure. I have multiple Pcs for my employer. Like, I have basically, like my prod identity. And then I have another, like, admin identity, and that's the thing that gets me into the admin stuff. But the admin stuff actually happens on, like, at this point, a dedicated machine. It flows through its own dedicated identity provider, like, all, all these different things. Like, it is truly, like, segmented. And I think that's kinda funny too. Like, that very much reminds me of, like, the old school worlds. We're like, hey, we used to have separate, like, user Ids and admin Ids and then for a while, we've... Floated back. And we said, well, why do you really need an admin id when you can just pi in and you can do all this other stuff. Right? And it turns out that III now live in a world where I still have separate Ids floated I still have to pi in, but when I pi in, I'm not only logged into my admin account, but then I'm still pi or doing, like, just in time, request or things like that. Even on that admin account for the additional layer that goes in there. It's all just very cyclical. Right? We always come back around. Yes. And then you set up different authentication or different Mfa options for your admin account that to make Mfa more secure for admin versus normal user and there's all. Kinds of things. And I've started doing some of that too. I've seen some of the security stuff, and I now have 2 accounts, my end and 1 has Pam it requires strong Mfa. My normal 1, not quite as. Not quite the same level of Mfa requirements. It's a thing. So, like, separate identities, separate devices. I saw the other day that it looks like Microsoft is position for, like, employees in China that they can only use iphones due to security threat. I saw that. So it's even coming down to potentially that point as well. Not only, like, do you have to use this identity in this thing? You also have to potentially use this device from this manufacturer, which is kind of funny as well, like, not like, funny sad, but more like, funny, like, That was come all the way back around to, like, you can use any device to access anything, and now we're into, like, oh, you must use this device kinda thing. Yeah. This was I've mean, here's a news article for it. I'm sure there's a better 1 out here because I think this came from somewhere else. But Msn... Yeah. Microsoft employees in China. Now have to use authentication apps installed exclusively on iphone devices. Part of Microsoft secure future initiative announced last year. We'll that 95 Mac reports. 9 to 5 Mac has some... It's interesting what shows up on 9 to 5 Max sometimes go with that. So interesting. Lots more always always something new to talk about with security and authentication. You know, it's... Just keep on coming. With that, I have meetings, I actually have a presentation coming up. Ironically enough. I have a presentation like 2 hours today, Scott. On Ad... Id. No. Id best practices or security best practices an Id. That is some I have to spit into like, Step 1 do Ad efs? What what which which way you lean in? No. My... Slide 1 is turn on Mfa. Slide 2 is turn on Mfa. Slide 3 is... Turn on... No. Sounds about right. Yeah. No. Mfa, secure off, or anti phishing Mfa because I have also seen a lot of... Articles recently and how actually scar easily it is to bypass, certain M mfa methods. Oh, yeah. With the can't... It's it's not it's not called man in the middle, but it's essentially a man in the middle and stealing the session token and the need for the anti phishing Mfa. So I'm dying some about anti phishing Mfa, the guest access thing I talked about reviewing guests, how long they've been in there who has access. So Can't remember. And pull up my slides. We can turn this into a future podcast topic. Maybe, adjusting authentication methods. Yeah. Limits me your admin roles, some of the Pi stuff we talked about auditing and alerting. I might bring up, like, I'm borderline, like some of the global secure access stuff, senior best practice, maybe borderline, but beneficial from a security perspective, probably. So I have way more slides that I'm gonna cover so I may kinda just pick and choose through my slides as well as I. So that's the rest of my Friday. And with that, I'll let you go enjoy your Friday. Sam like a plan. Thank you, Ben. Alright. Thank you, and we will talk to you again soon. If you enjoyed the podcast, runs go leave us a 5 star rating in itunes. It helps to get the word out so more It pros can learn about Office 3 65 in Azure. If you have any questions you want us to address on the show, or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day. On
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 380 – The future of AD FS is cloudy
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 42:04 — 28.9MB)
Subscribe: Spotify | Amazon Music | Pandora | iHeartRadio | Email | RSS
Welcome to Episode 380 of the Microsoft Cloud IT Pro Podcast. In this episode we discuss some of the latest security breaches that you should be on the lookout for and then we get into AD FS migrations and if you should consider it.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 375 – Securing Your Digital World: An Intro to Global Secure Access
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Apr 25, 2024 | Podcast
Blubrry Player
|
Auto Scroll
- Welcome to episode 375 of the Microsoft Cloud IT Pro Podcast recorded live on April 19th, 2024. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss the topic or recent news and how it relates to you. This week we'll be discussing global secure access as part of the Microsoft Security Service Edge and how Global Secure Access brings identity network and endpoint access. Together. Under one service, we'll discuss some of the services that includes, that may seem familiar to you as it relates to Defender for cloud apps and App Proxy. We'll also talk about some of the key features around internet access and private access, as well as the global secure access clients for Windows and Android and the upcoming ones to the Mac OS and iOS. We'll also talk about the benefits provided by these services, taking advantage of the Microsoft Global wan. Join us as we take a deep dive into the world of digital security and learn how global secure access can help you secure your digital world. Here we go. Scott, what is Global Secure access in preview? That's our topic for today. Global Secure Access. .This was, have you played with global security access? Oh, Todd's been putting out fires all day. He said, why not come put out more fires at my house. . Alright, good to know. Todd .Okay, what is Global Secure Access Squirrel. Scott Squirrel. Yeah, global - Secure Access. Yeah. So let's see. This is all about securing your digital world, right? That's what I thought. So - It's secure access globally is what Global secure access is. . Yeah. So this is a new feature.This one was announced actually, was it Ignite? When did they change the name of Azure? Adida - Entra. That was back around the Ignite. I - Think that was Ignite. - And this was also the introduction of not just global Secure Access, this was also the introduction of the introduction, a little bit of the rebrand and and pushing out of the concept of Security Service Edge or SSE. - Yeah. And that was all announced in kinda since then. This is, I would say it's been a slow role of various services within, whether you call it various services within the Secure edge or even just global secure access in general has kind of been a slow rollout and there's a, I would say a halfway decent image in this overview of what it is. But essentially at a high level global secure access goes and takes all of your endpoints, identities, endpoints, even remote networks. So think of identifying traffic based on the network it's on, routes it all through this security service edge through global secure access so that all of your traffic is routing through this global secure access, which is a service sitting out in the Microsoft cloud before it goes to any number of things. It could be before it goes out to Microsoft 365 could be before it goes out to the internet, before it goes on premises to your on premises applications or even going out to another cloud service, whether it's AWS Google Cloud going out to Azure. But it's a way to essentially securely route all of that traffic wherever it goes and route it through this service between your end points or devices and wherever they're trying to go. - That's a good encapsulation. I think one thing that's missing in this picture is some of the buckets should be a little bit bigger and maybe have sub components within them. For example, take Microsoft 365 and some of the things that are part of Microsoft 365 ish slash intra idea ish at this point. Like conditional access. So how do you extend, you mentioned like on premises clients, so how do you extend conditional access to on-premises clients? You need to bring those, those clients both the on-prem client and maybe the on-prem application within the purview and the overarching boundary of entra and things like Microsoft 365 and that whole stack to put it together. 'cause ultimately what we're doing with this service suite of services again, right? If we think about Security Service Edge or SSE, it's really comprised of we're back to bundles and suites of things. It's combining this set of capabilities for both internet and intranet bound network traffic and making that all play nicely together. Not just across the network but bringing in things like conditional access. So you have an identity layer and an identity boundary plus a network boundary plus an endpoint boundary on your clients themselves. And we'll talk about what some of those clients are that are out there and what's capable for things today. So if somebody looks at this and they're like, haven't I seen this game before? This sounds a lot like defender for cloud apps and maybe CASB, right? For access to AWS and GCP and these external SaaS services like Slack and Dropbox, that sounds unique to me. Intimately familiar, like how we've been down that path before. You're talking about things like proxying connections and having, having connectivity through a network layer back to on-premises resources, but being able to inject an identity boundary through conditional access that sounds a lot like app proxy connector, and,and some of the things that go into that. So if you've been in this space a while, you're like, yeah, something doesn't smell right here. You're absolutely right. Like this is still under the hood. The things that you understood and and the way you understood them to be with things like defender for Cloud x Defender for cloud apps rather that whole CASB solution, sorry cloud access security broker and putting all that together. Things like app proxy support through Azure AD and app proxy connectors that guess what that's been here and and it's brought up to snuff under this suite of products with slightly different names. But I think if you look at the underlying architecture and the way those things compose all the same, it's just kind of new names and potentially bringing all these things together as a suite of services under one banner that you can go ahead and just live a certain kind of life through depending on what kind of life you wanna live, right? Do you want to do things like monitor traffic externally? Do you wanna monitor traffic internally? Do you want to have uh, those additional operational and access controls on top of things? So if you're looking in your, hey in my environment I already do the network thing. Like I have forwarding proxies and I have all the things in place I need that protect me across the various OSI layers on premises and my outbound traffic and things like that. Maybe not the solution for you, but if you're looking for more than what you get out of maybe your traditional on-premises solutions and tight integration across the Microsoft stack and I'm, and I'm intentional there when I say across the Microsoft stack because it's not just SaaS services in the Microsoft stack like M 365 or Dynamics. It's things like Azure and access to Azure and some of these other internet connected suites of things that that exist out there in that stack it, it marries all of those together. Puts them in a nice little bundle or bucket for you both from a functionality perspective and from an administration perspective. - And I would say like you mentioned the app proxy stuff, right? And the CS B stuff. I think this is not, I would go a step back from what you said where it's like bundling those in my impression of this and from the playing I've done, it's like an entirely new process. Instead of bundling those together, I would almost, I wanna be careful saying this because I don't want somebody to go out and say Ben and Scott said this was V two, this is almost, it appears to be, we'll say the appearance from everything I've seen like a V two of app proxy and of CASB where my understanding of CASB and some of the uh, cloud app protection and the stuff that's there today relied on like the defender endpoint, right? Because somehow the existing cloud app security stuff had to reach into your machine and see what, what the traffic is, where are you going, what are you visiting all of that where instead of still using defender for endpoint for global secure access and you said we'll talk about this, there's actually a new agent that you install on your device for these where it's instead of like defender sitting there monitoring it, this is almost like setting up and it may even be doing similar in the background setting up A VPN on your client devices and I feel like Defender Endpoint was sitting off to the side watching what you were doing and sending some of that back. This is literally routing all of your traffic through a secure VPN or secure connection through this global secure access to do things like, and it's probably similar to that proxy but I think more of the CASB stuff, I don't know that I wanna say more invasive but it's watching a lot more of that network traffic because it's routing it all through this global secure access endpoint. So - The CASB stuff was invasive as well, right? It was a local agent. Your traffic absolutely passed through that thing for monitoring. I think the big difference here is it is much more VP nish at the end of the day, right? Like you are doing a virtual private network effectively. Yep. And the connectivity for that VPN if you think about performance of A VPN and having to tunnel and connects through an endpoint where those endpoints sit has a big, no pun intended like network effect and knock on effect to customer experience and client latency. And I think those were potential issues with some of the kind of traditional CASB approach and there was also just the general, hey like what do I get out of doing this solution? So like that CASB approach was really good for routing and monitoring for external SaaS solutions. It wasn't good for the app proxy thing 'cause you still needed the app proxy thing on the side. What this does with global secure access and the client, what it lets you do is it lets you basically say, hey now that all this stuff is under one suite of services, let me have a singular client and then I can take that client and I can affect change in client behavior by pushing traffic profiles so I can have a traffic profile from Microsoft 365, I can have a traffic profile for my internal applications, that kind of thing. And then it all passes through that one agent, that VPN connection, right? Which is giving you a tunnel back to what's effectively the Microsoft wan. So this is another like kind of thing, right? As as when I talk about like limitations of the old stuff versus the new stuff, now you're given connectivity just straight up back to the MS WAN N which is really interesting because Microsoft, for folks who go out and look at the side or like their networking geeks has a massive WAN like massive network, tons of dark fiber. If you think about the way like Azure regions and Microsoft 365 regions are all connected together. Like there's a ton of bandwidth and a ton of capabilities there just within the core network, let alone all the segments for that network and where they push out to, especially on the edge with pops and and things like that. So you're basically talking about like A VPN that's smart enough to locally route to the closest edge site And an edge site could be a region, it could be a pop, but you're looking at all up 140 ish regions. So that lets you know that it's more than just Azure, right? Because Azure has give or take - 60 ish, right? - I can never remember the exact number because there's all sorts of like canaries and E UAPs and things like that. Yeah, it's on the order of 60 ish, 60 to 70, something like that. But way more regions here plus all the pops that exist out there or all the edge sites for that wan. So 140 plus regions, 190 plus pops all ready to go kind of sitting there. So hopefully, and from what I've seen of this uh and experienced with it, like the knock on effects of things like client latency, they're vastly diminished in this solution versus what I used to encounter in the CASB world. But the cool thing is even for app proxy connections, things like that because now you have the VPN tunnel between your client and that edge site that can broker everything up. It can pass it through the WAN for evaluation by being passed through the WAN for evaluation. And this is where I was saying that graphic maybe it wasn't the greatest thing 'cause really you wanted like there wanted there to be like a big circle around the whole thing. Yep. Which included stuff like conditional access in it. So hey, how, how do I take and put conditional access in front of an on-premises app? Have you been able to do that in the past? Absolutely. Did it require additional functionality and was it rolled up into a singular solution? No, not so much, right? That that, that was the friction and things that came along with it. You're picking that piece up here. This new client effectively gives you VPN plus a traffic filter that can monitor both for internal and external bound traffic based on profiles that you can configure. And then based on the destination of that traffic, then you get all the other operational things on top of it that you might want like identity and conditional access. - This is where like when you go in and do some of those profiles, we were looking at this the other day, now I'm gonna have to remember where all my profile settings are. You do have those different profiles so you can go create those profiles for your internet traffic and for your Microsoft 365 traffic. And one of the interesting things that I saw in here when you're going and setting up some of those profiles is that it starts giving you some additional functionality and now I'm losing all my connectors traffic forwarding. I think that's where my profiles are. Yes. Like you can go into your Microsoft 365 profile and set up different policies within it too that let you go in and set up like what exchange traffic is going. It gives you all the fully qualified domain names, the IP subnets of your Outlook traffic and SharePoint and OneDrive and some of your common office applications. But this is also now because of running through this VPN, there's options to even go in and enable a lot more logging of your Microsoft 365 traffic. And this is one thing that's still slowly rolling out where you can go in and get like enhanced logging and we've talked about some of the logs that are available. It's 'cause you enhanced logging I think of exchange and SharePoint like teams is still coming. I'd imagine there's a bunch of other stuff still coming as well. And then for internet access web content filtering has been there for a while in Microsoft 365 and this is another one that gets rolled in. But now with your internet access profile, you can go into and do things like web content filtering policies where if you wanna go in and create a policy to block certain websites or to block different categories of websites you can go, it brings in that web traffic filtering that you, it's buried down within defender I think in the security center. But it brings that into here too. So you can go start filtering that web content. And this is another one I've had clients ask about, especially over the last few years when everybody's starting to work remotely. A lot of this used to be done at the firewall level, right? People would've devices, DNS, custom, DNS, all kinds of things to filter traffic. If you were internal to the network with everybody working from home three or four years ago, the number of calls I had about help, we overloaded our VPN because we're still requiring everybody to go to VPN for some of this functionality and it just couldn't support 6,000 people all working from home over VPN. This goes in and takes care of a lot of that because now instead of to your point Scott, instead of relying on your VPN or your teeny tiny WAN setup, respective to what Microsoft's network is, you can get a lot of that performance without having to rely on premises VPNs or on premises networks to do a lot of this web content filtering, advanced logging, all of that is a lot of that type of functionality begins to roll out and come to this global secure access. The - Scale component is interesting that call out to 140 plus regions and 190 edge sites, that's not just about things like client latency, it's also about capacity of the Microsoft WAN in, I don't know many folks who are running, running around even in their local environments with petabytes per second of capacity. , right? like we're not talking gigabits asecond year, we're not talking megabits a second, we're talking like PETA bit scale like petabits a second and the contention issues and all the other things that can come into play there do go away, right? Like your constraint effectively becomes like the client and does my client have internet access? And that's a problem that you've had to solve the entire way along anyway. So that constraint really hasn't moved around for you in a meaningful way. Some of this stuff's a little weird to be honest with you. I don't understand why log enrichment is tied to this client because if you look at the logs and what event enrichment actually means ,it's things for SharePoint online having an event for say SharePoint for file deleted, you should already have a file deleted event for teams. It's about having app installed for exchange. It's about new inbox rule, new transport rule things. There's no magic sauce there that couldn't be enabled in the SaaS service anyway. Like it's a weird gatekeeping kind of thing to me. But I don't know, - I want go in and look at more I encountered, this is another episode. They - Published the schema for what they enrich and watch the what they push out there. And if you look at the enrichment schema, it's, - Oh look at - This. It's not a very special thing. Like, like you, you will not be enthralled when you see that list. - Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So I'm wondering though Scott, like looking through this like you said for SharePoint, for OneDrive, file deleted file downloaded, file recycled, those are absolutely already logged. Does this somehow give you, and this article doesn't have it, - Why would it be documented and tell you that - Idea? Oh lemme talk about documentation, how I feel about it right now. Does it give you additional details about it from the perspective of a new inbox rule is created right now. You can see the endpoint that it's created from. Maybe you can see the client, but does it give you not so much, these are new activities that are logged but it's additional information about these activities that they're able to log because it's watching the network traffic. I don't, again, it doesn't say because to your point, why would it be documented? But it talks about enrichment of these logs, not necessarily new logging activities. I wonder what are those additional details that you're getting when these are enrich when these logs or these operations are enriched with data from global secure access. If - I'm remembering right, it's been a hot minute side looks so yeah it is additional details about the clients and things like that. It's also a little weird the way you pump these out and this has been a moving target as they shift around the way audit logs in general are, are manifested within the admin center. But this brings it under the same banner as things like your regular audit logs sign-in logs, things like that where you can pump it out to log analytics or send it to event hubs and very much like the Azure ish diagnostic setting kind of thing. If you think about like configuring a diagnostic setting, it's also a little bit weird and I haven't had a chance to play around with it in a mixed environment. But if you go and configure this and look to light it up, so if you went into your tenancy, you should see this within your tenant, you should have diagnostic logs someplace in there. I - Don't see it. Dashboards see and this is, - It's under identity. So go under the identity admin center. It's like monitoring and health diagnostics, something like that. - Uh, monitoring and health diagnostic settings. - This looks a lot like Azure all of a sudden- It is. I mean this is your diagnostic logs from Yep, this looks like diagnostic logs essentially Diagnostic sign-in - Logs, that's Sentinel. Yep. So go ahead and click add diagnostic setting there. So in this experience now you have your audit logs, you have your sign-in logs. If you scroll down towards the bottom you have a separate log category for the enriched logs. Yeah. So with this kind of flexibility, like you could even do things like maybe take your enrich logs versus your sign-in logs and send those off to different log analytics workspaces. Maybe you wanna evaluate in another one in another place like Splunk or something like that. Hey, I'm gonna send my sign-in logs over here to this event hub and eventually route 'em through to Splunk with my custom connector. I'm going to pump my enrich logs over to this log analytics workspace. I'm gonna send these things over to a storage account just for archiving whatever it happens to be. You can do all those on that side. I don't know, diagnostics in M 365 continue to be confusing to me. I don't understand why they're gate kept behind additional licensing and additional features and functionality. Frankly, observability and logging should be free , right?Like I get it costs money to store text someplace, but folks should figure, figure that out, right? If it's a, if it's a true value add thing, okay, if it's got enriched in it and it actually enriches the experience, sure give that to me. But if it's out of the box, like just give it to me out of the box, right? It should be there for me ready to go. - I have a whole nother topic we could talk about on another podcast around this that came up with a client around auditing exchange activities. This one was fascinating that I did not realize, but it's absolutely going down a different rabbit hole that has nothing to do with global - Secure access. Write that down. All right, we'll take a note, we'll take a note on that, put that in the parking lot, we'll come back to it later. So anyways, so these clients, right? It is an application that gets installed that effectively deploys its capability to do a VPN tunnel. It is Windows and Android only today. So all this stuff's in preview like moving target preview is not production, blah blah blah. All that good stuff. For disclaimers, I think Windows clients are probably the most interesting, the most turnkey for M 365 subscribers, right? Who are probably de deploying things like office onto their desktops and and wanting to track and monitor all that. So Windows, windows clients 64 bit only. If you're operating in a mode with, you've got mixed mode like enterra joined, hybrid joined devices, registered devices, all those kinds of things. Registered devices don't qualify today for that. And the deployment of the client requires enter ID P ones, which is another important one to call out. So there is, it's not just hey like I need to deploy the client. Cool thing is you can deploy the client through things like we talked about Intune for what seems like three months and in one of those Intune reviews that we did, we talked about things like app deployments. So you could totally push out this through Intune and have it come down and then it gets its configuration based on cloud service and things like that. Fairly flexible, super easy to set up. Oh, one last note on setup here. Weird one but really not that weird. It requires admin, admin access to install on Windows clients at least. And it makes sense, right? You're deploying a new VPN, you're deploying a new network filter on top of it. So keep that in mind. So client deployment is actually super lightweight. I think it's just lack of support in places, right? 64 bit only doesn't support arms. 64 - Doesn't support multi-session. This is another interesting one. If you do an A VD, it doesn't support multi-session and it doesn't support multiple user sessions on the same device from RDP. - It's another limitation that's out there. It does support Windows 365 dev box. There's no explicit callouts for supportive things like dev box or anything like that. I imagine that it works over there. I, I'd have to spin up a dev box to try it out. Like I, I can't think of any restriction that would be there other than maybe a supportability but it's all preview today so support's gonna be a a weird one for you anyway. - And I'm running this like I'm running it on my Windows 365 cloud PC because that's technically a single session A VD and I think dev box would fall into that same boat dev box for all practical purposes is a single session a VD environment. So it should work on those. I would say you mentioned Windows and Mac or Windows and Android, Mac and iOS is coming, it is in private preview yet. So you have to like I imagine Mac and iOS, they're maybe running into the whole test flight limitations when you're doing stuff in private preview for those that Apple can sometimes cap how many people you can have in a beta test environment. So those are coming, I'm surprised they're still in private preview. I would hope they would come out soon 'cause I want to try it on my Mac so it is, yeah, like you said, the client's super easy to deploy. I deployed it and then once it's deployed you just log in with your M 365 account. So I logged my account the other day and then I went and logged in and like I had global secure access popup and I had to go re-authenticate with my user account , which I guessthat one's an interesting one too Scott, because I have not tested this. Part of the point of this is to monitor all that web traffic, but if I can sign out of global secure access, can I essentially bypass it by signing out of my account for global secure access or are there ways, and I haven't looked at this yet, to like block internet traffic if you're signed out of your global secure access client, - I've not seen a way to block it. I had a very similar question. It's weird, it's early days for this one. I, I think it is definitely one of those like preview, not for production but play around with IT kinds of things. It's a little weird. It's a little strange. I do think and and the reason we're covering it, I think it's worth getting hands on with - Absolutely. - It's going to be I think a pretty turnkey capability for a segment to, or a subset of organizations that sit out there. It's also another great example of hey, let's take the disparate pieces and parts and pull them together and put them into one place. Like for you in in your screen share. Let's go back to the traffic forwarding stuff - That was tr not traffic logs. Traffic forwarding was the connections. Yep, yep. - So like you take a look at that like you turn on your M 365 profiles. So let's take that one as example. Go in and and and view that one there and view my traffic. So you have these policies and the policies that you've enabled. So these are all canned, right? This was brought in just by saying hey I'm gonna bring in M 365. There was nothing you couldn't have done here on your own other than Microsoft bundled it all together for you. Which is nice because tracking the IP subnets for M 365 as a service right, isn't something you want to do uh, on your own, but there's a ton of flexibility here in the way that like this manifests and comes together. So you could take like SharePoint for example, say you wanna drive your exchange traffic through the tunnel so you're set to forward now for all of those things over TCP. But if you take like your first FQDN role like star sharepoint.com, that that wild card and bring down the dropdown, you can actually bypass just for the FQDN, you can bypass by IP subnet, things like that. So you can get like super granular within these and then you have the same set of controls for your internet bound access as well, internet and both your internet and your private access. So it's super helpful to see like the way like Microsoft composed the rules for M 365 and how that stuff came together and then you can think about potentially modeling that into your own stuff. There's also the ability, if you go back yeah, - No though for internet, yeah. That they give you, so they give you that option for Microsoft 365. I don't think, and this is to your preview point that you can go in and tweak your internet access profile yet. I don't, this is tr security policies. - I wouldn't be surprised to see it in the future. I imagine a lot of it is is scaling things, right? Let's say you might wanna, you might wanna forward for, I don't know, pick a website you might wanna forward for stuff to, to Reddit for evaluation but you might wanna bypass for Bing, right? Just for your online searches. Like I, I think that capability will come and probably is the scale component. The other thing I should mention with traffic forwarding, if you go back to traffic forwarding again and like the M 365 1, so you've got that linked conditional access policies. So you can link conditional access policies to each profile as well, which is super flexible again, like it's basically making a lot of this stuff like as much as like conditional access policies were next exercise, this is just next .- Yeah. - And done it, it simplifies that deployment model even further. - Yep. And one of the things that they've brought up, we haven't talked about it yet, we could probably talk about this more, is you like with conditional access and another thing that Microsoft is working towards with this and this can help with is, and I've seen this come up more and more lately in different things that Meryl, we had him on the podcast, he created a video on it is token stealing, right? Like people creating sessions, you get the whole man in the middle attacks that are stealing session tokens by routing all of your traffic this way too. That can, this also goes a long ways with helping with token stealing because you're now essentially going through this end-to-end encrypted tunnel from your device over that VPN connection in an encrypted manner. And I think, I can't remember all the conditional access policies where you can essentially say if somebody's going to connect to my Microsoft 365 applications in those conditional access policies, they are going to have to come through global secure access so that I know they're coming into my environment in an encrypted manner and that traffic and that interaction is be gonna be secure. I think that's a conditional access policy. I'm not a hundred percent sure, but that is another, I would say benefit of this. 'cause we talked about a lot of the logging the profiles, but a, there's that security aspect of this as well. Yeah, - I wanna do it as like the old, like Steve Jobs strip ,like when he introduced the iPhone, oh it's the internet plus video and, and all those kinda things. No, it's identity, it's networking ,it's, what is it? Identity networking. Yeah, it's networking, it's endpoint access, right? Like you put these three things together and you have uh, global secure access, which is part of this security service Edge S-S-S-S-S-E suite kind of thing. So it's a mouthful on the front. I would encourage folks if you're listening to this, like just go like pop up in a web browser and check it out. Even if you go look at the docs or you just browse through like your admin center and M 365. This is by far one of the easier like security solutions to configure out there. Like it, it, it really is fairly self-explanatory in what it's trying to do and, and what's happening and there's not a ton of machination going on. So it's super easy to wrap your head around and then once you can do that, I think like it does like just bring value. Like it's one of those like self-inflicting value kind of services. - Yep. And you will encounter stuff that, yeah, it's preview, I think my audit logs I go click on like audit logs and it says we're hard at work developing this feature. Be patient - We'll see in the future - .Yeah there's some IT teases functionality because the menu items are there and as you click through it you'll get, oh we're still developing this or we're still developing that. But to your point, it's what absolutely worth playing with. Clicking on a few of the check boxes, some of the profiles set up a couple of your test clients to route traffic through it and it's fascinating. Traffic logs is one thing that is there. This does not go through my production machine, but it has 28,000 connections and seven and a half thousand accesses to Microsoft 365 20,000 times I've access to the internet. And it gives you like even endpoints within Microsoft that you're connecting to where I can see connections to East US or to like edge.microsoft.com. It's interesting to just go look through it. Here's a Grammarly where I connected a Grammarly endpoint from my Windows device. So it has got absolutely worth turning this on and starting to play with it for certain clients and see if it's something that, it's something I would keep an eye on and really consider rolling out in certain cases as it comes outta preview for sure. - So I think that takes us through our whirlwind tour of Global Secure Access coming to an M three, no coming to an enterra ID tenant near you. - . Yeah. 'cause I guess technically you don't needto do M 365 if you're just doing Enterra and Azure. You could go get Enterra ad premium plan one and use this for, if - You're just doing enterra as an identity store and AWS you could do this, right? I I I think it's about where you find the value in it without having to be a wholesale consumer of all Microsoft Services. That being said, if you're doing M 365, this is a kind of like a big natural fit kind of thing, especially for those customers who, and I imagine this is still the case. This used to be the case when I was doing a lot of Office 365 and M 365 and customer deployments in my consulting days. Everybody wanted a private version of SharePoint online. Yep. . So this kind of gives you that click stop and,and that next FU piece of like warm fuzzies about your connectivity for your organization and your clients and there's a whole lot of what's in it for me there versus what's in it for Microsoft, which is nice to see. Yeah, it really does further that. Alright, - Thanks Scott. That was a good one. Yeah, now it is time for the weekend after a couple more meetings. - . It's getting there slowly but- Surely we'll get there eventually. - I got two more to go and then it's off for Margaritas and CES tonight, so I'm looking forward to that. All right, - Go enjoy your weekend and we will talk to you again soon. All - Right, thanks Ben. - Thanks Scott. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 375 – Securing Your Digital World: An Intro to Global Secure Access
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 37:54 — 26.1MB)
Welcome to Episode 375 of the Microsoft Cloud IT Pro Podcast, where we discuss Microsoft’s Global Secure Access offering. We explain how Global Secure Access brings identity, network, and endpoint access together under one service and how it combines with Defender for Cloud Apps and is built around the capacity of the Microsoft WAN. Join us as we take a deep dive into the world of digital security and learn how Global Secure Access can help you secure your digital world.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 366 – Old Man Yells At Cloud
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Dec 28, 2023 | Podcast
Blubrry Player
|
Auto Scroll
- Welcome to episode 366 of the Microsoft Cloud IT Pro Podcast recorded live on December 8th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and how it relates to you. In this episode, we discuss some changes to where to find us on social media. Then we dive into our technical discussion around conditional access and break glass accounts and managing these security aspects of Microsoft Entra. We conclude the episode discussing native apps versus progressive web apps or PWAs and some of our recent frustrations with this trend toward those PWAs. You know, what was a mistake? - I can tell you what my mistake was this week. You - Could, I don't know what my mistake was. I could tell you what Elon Musk's mistake was. That's a long list. , we don't have time for that.Okay, what was your mistake this week? - Hold on, I gotta do this joke. So Elon pulled the go f yourself thing at that conference last week to all advertisers, like called out Bob Iger everybody, - And then told him he should resign, right? Yes. - . So there's, I am, I'm done with Twitter.I don't, I don't go on Twitter. Like I didn't delete my account, but I deleted all the apps, blah, blah, blah. I, I, I made you, oh, - I didn't know you haven't deleted it. You talked about deleting it. You have not though. - I deleted the apps and all that stuff. Okay. But I figured like the handles there, like they'll take it away someday. I, I don't, I don't care. Whatever. And then I made you go through and update, you know, like I just want it to be my threads handle and, and MAs it on and things like that. And neither here nor there. So I get all my Twitter news through threads these days. So apparently there's an account, it's called uh, fab Bit Fun. I don't know, it's some service that's out there. I don't know what this thing is, but they ran a Twitter campaign and they called out that they are pledging an additional a hundred thousand of X advertising in support of its free speech ideals. And to all of you looking for a free perfect gift this holiday, we're also giving away a free 300 plus dollars gift with your first box for new annual X users use code. Go f yourself. Except they spelled out F which apparently led to a slew of people discontinuing the service like actually saying like, Hey, um,that might not have been a good idea to use uh, a profanity in your like professional account kind of thing. But yeah, so they did that out. They ran that campaign. And much like Elon losing advertisers 'cause hey, uh, he might not be the stable genius we all thought he was, they are also bleeding customers from this subscription product that they have. So I thought that was kind of hilarious. There's gonna be some great case studies and great movies someday about how you can literally light $40 billion on fire, 44 billion and just put a match to it. Yeah. Destroy people's lives. Like people who work for that company destroy a company itself. Like all that kinda stuff. Like they're, they're gonna be talking about this crap in business school like 20 years from now . There- Are a few documentaries I'm waiting for that's gonna be one of them. The other one is going to be everything that went down with. Sorry, I just saw a message that distracted me and I don't know what it was about but we'll come back to that later. I should put do not disturb on the other one I wanna see a documentary on is everything that happened with AI and coming and leaving and going and coming back and firing people and all of that. There are going to be some fabulous documentaries coming out of these last two or three months or six months about Twitter and about open ai.And then when the bots take over the world, - We haven't talked about the whole OpenAI thing, but for those that are interested, I'll put some links in the show notes. There's an a couple of excellent other podcasts out there that have covered it very well. Like they, they covered it on the Vergecast and also, uh, Casey Newton and his partner in crime in the Hard Hard Fork podcast. They did a really good job kind of covering things. And then Casey Newton has a interview with Sam Alton, uh, Sam Altman rather before and after , which is kind of awkward and kind of fun.- I have not watched that. I should go look up that. I'll add that to my list. That one I will add to my list and I will go do .- Yeah, that's the one that'll get you - There. Yep. That one will get me there. I'm from documentaries news. I have an interesting one. Scott, I'm curious what you think about this. I have some thoughts about this one. I have some questions about this one. And this is has, I mean I guess that has a little bit to do with admins if you wanna enable this in your tenant. But there is a much awaited calendaring feature coming to Outlook. The capability of keeping events you decline on your calendar. So this, yeah, this does not look like, so it's not even an admin, it's not enabled by default. You can go into Outlook on the web or the new outlook for Windows. I don't see this for Mac oss yet. And in the settings, calendars, events and invitations, you can go toggle an option, click a checkbox to save declined events and then once it's enabled you can decline events and they'll still be preserved on your calendar. Thoughts. Is this something you'll use and yeah, what do you think about this one Scott? So - I'm gonna use this one all the time and, and for a couple different reasons. So as a remote employee and somebody who theoretically is responsible for a whole bunch of stuff in an what, what is an ever-growing a massive platform, I get invited to a lot of meetings and many of those meetings can be, they end up being more passive meetings I guess. Like I know they're gonna be passive in that I need to be there to get the information, but I'm not an active contributor. Like I'm not driving the conversation nor am I responsible for ultimate success, right? Like I'm part of an outcome downstream in there and I kind of recognize that walking into it and that being the case. I have a lot of meetings today where I take them and I put them on my calendar and I mark myself as a maybe and I do that very specifically so that the meeting stays on my calendar for search history. Like I'm always going into my calendar and searching like I remember like the title or the person I like. I wanna go back and look at it because I wanna refer to the metadata from that meeting. Like quite often people include, you know, agendas and attachments and things like that. But the other part of it and the other side of it is when that meeting's on your calendar, as long as you don't dump it all the way off by saying no, you'll actually end up with the chat in teams. And we record so many of our meetings that it's hugely beneficial to me. Like you know, as a remote employee who is time zone, time zone disconnected from many of my teams, I can't actually participate live even if I wanted to. Like there is like a mission critical meeting every week on Thursdays at 8:00 PM Sorry, that's like prime time eight 8:00 PM local for me. Yep. So sorry like that's prime time for me to be with my family not prioritizing work. So I don't attend that meeting. I attended it once just to see how it went and then I was like, uh, yeah you know, I really should be here but I'm not gonna be here because it's me time. But I am a ravenous consumer because that happens on Thursdays of just picking it up Friday morning. Fridays tend to be slow days for me. It's a good time to actually catch up on meetings and figure out what's going on. So I do that religiously like week over week. Great Thursday meeting it runs at 8:00 PM it's only supposed to be a half hour meeting, it often goes over an hour. like they just keep going.So I catch up on that recording. I wouldn't be able to do that if I didn't have myself marked as tentative on that meeting. But what this capability lets you do is it lets me decline the meeting like a clear signal to the organizer and attendees and the people that are in that meeting that I ain't gonna be there. Like this is not the forum where you're gonna find Scott, but I get all those other additive benefits in that I can still search for it on my calendar, I can still refer back to the chat, I can refer to meeting recordings, all those good kinds of things. Like in my mind the way this composes is it actually lets me be a shadow consumer and follower of those meetings all while setting the tone that like, yeah, sorry I'm not an active participant if you need me I I'm around but you just gotta catch me my time, not your time. Right? - So do you think this will still preserve those team chats and stuff? I guess it's one thing that's like not called out I would assume because you still have the event, you could still like open it up and get to the join link to go find it in teams after the fact or see the recording for - Meetings that you still have on your calendar. Like because this persists across Outlook and teams like, you know, you have like the calendar tab in teams, you just go click on the event and then the chat tabs there and then once you're in the chat tab you can see all the other tabs like meeting recaps and all those other kinds of things. Which let me tell you like the meeting recap stuff getting way, way, way better to the point where like I record and transcribe all my meetings now because I'm kind of becoming dependent on the AI summarization of the transcriptions. Like that stuff works really, really, really well. I think - That's one area where AI, from my perspective, not to go too far down it is the AI path again, but AI is getting really good is that some of that summarization stuff it, I'm still not sold on it coming up with net new. But I agree some of the summarization stuff is getting good and I need to remember to record more of my meetings. I am still not like that's a habit I need to develop of always. First thing, hey, do you mind if we record this meeting, click record so I can have all of that stuff. Aside from that, I'm really curious to try this declined events too. I'm sort of in the same boat as you of some of these. I want to go back and see later or see the chat for, but I actually have a bunch, so I get a bunch of meetings related to like MVP stuff that pop up on my calendar and I'm the same as you. I always click tentative 'cause I'm like I don't know what's going on. I don't know if I'm gonna be there or not. Some of 'em are all just random time zones but maybe I want to go catch up on stuff later. All of that. So I have a gazillion like tentative meetings on my calendar. But for me, my problem that I, I just realized this recently, I use Savvy Cal, it's very similar to Calendly for people to schedule meetings with me and it looks at all of my different calendars including my work one, a few other ones where I contract and it gives people my availability. Tentative meetings still show me as busy and end up blocking off my time on these other services on Savvy Caller Calendly. So I'm similar to you is that I'm hoping declined in. 'cause now I manually go through and I'm like flip it to free so that if someone wants to meet with me at that time, 'cause they're more important. That's - Another part of it. Yeah, is like free busy management, right? - Like I'm hoping Declined shows me as free and not as busy even though it still shows on my calendar. So I think that's where I might use declined more is a lot of these, again these types of meetings, it's more FYI if you wanna show up, this is what we're gonna talk about today. So whether I decline or tentative or accept, nobody really cares. 99% of these, they don't even have the auto responses turned on. So it's not even like people are getting emails about what you did about it. So I think that's where I'm looking forward to it is just decline 'em, decline 'em, decline 'em. So my calendar shows free but I can still see 'em there and go attend them if I want to. I - Guess just a point of clarification, some folks in the chat are kinda saying like, hey why can't there maybe another status like declined but keep informed or declined and kept on calendar or something like that. Just, just to be clear with kind of the way this one manifests, it's you're declining the meeting so this organizer is getting a decline. You're picking whether it stays on your calendar or not. So it's a meeting by meeting kind of thing. Like all meetings you decline don't have to stay on your calendar in this kind of model as it manifests for itself. It's kind of disappointing to me that it requires the outlook on the web or the new Monarch client I have you played around with the new Monarch client yet? - No, I sit in a Mac all day. I think I do have a VM where I turned it on, but I honestly can't remember. I don't spend enough time in Outlook on Windows that I, I won't lie, I don't pay that close of attention to Outlook on Windows. - I live in the Monarch line on Windows day in day out. It's pretty much trash . I don't like it.Like I'm, I'm like old man get off my lawn kind of thing when it comes to it. It's got some really weird behaviors. So when I ran into today, I seem to run into like some weird new education Monarch every day. Uhhuh . It's very opinionated about being aquote unquote like cloud product. Like it knows it's a web app and it knows it's a glorified web app on the desktop too. I, I hadn't run into this one yet because so many of the things I do like we share like links to artifacts like Word documents, anything, PDFs, stuff like that. They all come out of like OneDrive or a SharePoint site. And I was doing something with somebody yesterday and they sent me, uh, for the first time in a long time I got an actual attachment, like not a cloud attachment but an attachment attachment, okay. And it came through in the Monarch client. And so I said I wanna double click that and open it up. It was a Word document. Simple, right? Like, 'cause when you're in Outlook and you double click on an attachment, it just opens locally on your desktop. Like it goes to attempt, download, location, blah blah blah. Opens up no friction, Uhuh not in Monarch. 'cause Monarch doesn't even know that it has separate windows, right? So it pops up the little pop-up window, the word doc doesn't render and then it says open, but it doesn't say open locally, it says open in OneDrive. So then what it does is you click open, it pops up another window and now that window is basically a web browser at that point, right? 'cause it's all just a view into a web browser. So then you know how if you have, you know, like Chrome Edge whatever it is not configured to automatically go to a website, it pops up the little dialogue and says, you know, are you sure you wanna open this on the web? Yeah blah blah blah. So all I get is that little dialogue in a blank white window. And I'm like how is it even opening it in OneDrive? Like what's it doing? It's taking the attachment and it's storing it random location in my OneDrive and then it's opening there in Word on the web and it's like it did all the things that I did not want it to do. All I wanted to do was double click an attachment and have it open in my desktop client and it did every single thing it could to ingest that data into OneDrive, which I did not want, nor did I need. 'cause now I gotta go find it and clean it up later. And also everything it can do not to open that document in a local browser, which is like the very first setting that I set in all my office clients. is open everything on the desktop.Like I'm not a fan of the web experiences. Like there's 99% of the time I'm using functionality that doesn't comport with the web experience. So I'm like adamant that you should open on the desktop. Like just such a broken, frustrating, like horrible thing And ooh boy is it slow? Like you can tell it is a glorified PWA wrapped in a desktop app. You know, like somebody cancels a meeting and you and you know you get the remove button that pops up just in the Outlook thing when you click remove you can sit there and you can pull out your watch and you can count the seconds until that item like disappears out of the list inside of Monarch. And then my third complaint from Monarch for the day is, oh my gosh the UI is really, really, really bad. So by default when you open new items, say you're like replying to an email. So you know you send me an email and I just click the reply button in line even though it looks like I'm typing in the same window, it's actually created, I am typing the same window but it actually creates a new little sub tab down on the bottom of the window. So now when I like sometimes I go into my email client, I just kind of like glance like bottom up as I'm reading my email and I'll have a whole list of tabs, tabs along the bottom of the reading panand it's just all these like previous emails that I've looked at other stuff like there are no rhyme or reason to the way this thing works or how it comes together. I would rather have the version of Outlook or the version, uh, from iOS or Android like take the Nont tablet, tablet version from Android and it would be a thousand percent better than what Monarch is today. . It's absolutely crazy.So I see people on Reddit always going through and like worrying that it's gonna get turned on and all those kinds of things and I can't blame them at all. It is a suboptimal experience for email. 'cause email should be quick, right? Like triage in out and go - And it does. I mean it's a PWA 'cause I just looked, I thought I had seen that. Like you can see the whole tap experience if you go look at Outlook on the web, if you just go mail.office 360 five.com and start opening emails and responding to 'em, you get the exact same thing where you get all those silly tabs across the bottom of your, it's essentially across the bottom of the reading pain. It's bad - like I get you have to drive new change.Yeah and new behavior and there's a desire to do that but like it is such a big bang approach that like who it, it's gonna be a rough one. So for those organizations that are out there where you're like, we don't like to train our users and we're very adamant we're against that. Like when this is shoved down your throats and it will be shoved down your throats, it's kinda like one of those like prepare yourselves for like the IT help desk Apocalypse because it's not gonna be fun. - Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft Cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft Cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. I get why Microsoft is doing this and a lot of other companies for that matter. I guess from a development perspective where everything is now just a glorified PWA but I get so annoyed with it as well from your perspective, whether it's that or whether it's silly things like I was in the Yammer slash Veeva engage today for whatever reason. We don't need to go into the reason of why I'd even go in there .But like I get this popup of oh we've released a new desktop client for Veeva Engage. And I'm like oh sweet, let's just add it so I don't have to keep my browser up all the time. Mm-hmm it just creates a pwa That's not the point. And I think some of my annoyance is that everybody now thinks PWAs are actually desktop applications and I'm like no, not really because I'll even do silly things like I'm having an issue with Outlook or Outlook needs an update and I'm like okay go restart Outlook. And I forget and I'm like ah shoot, there goes my five PWAs that I was thinking or forgetting they weren't desktop apps or I go to open a PWA and like 10 browser windows pop open because that's what I had open last time. I had my browser open in this dependency on all my PWAs now to have the browser open and I can't just have an app open, I have to have my browser open and browser updates affect my PWAs and all that. It's like just gimme a silly desktop app that's independent of my browser because that's the whole point of a desktop app. Otherwise I might as well just go buy a Chromebook, right? And just run a browser for everything. - Yeah and there seems to be like while we're on this like little ranty thing, so have you, you know what A PWA is, right? A progressive web app like I think most of us do sometimes I feel like there's just this cognitive dissonance when it comes from like the way these things are positioned and pushed out to customers. So I, I don't know if you saw this one, I'll put it in the chat here on Discord and over in the show notes - You mentioned this one, I haven't read it. - Yeah, we didn't talk about it but no so this is the Windows Forms app. So Microsoft Forms the new Yes, - The Microsoft the New Forms app, it's here based on the title of the article. Yes. - So published in the Microsoft store the most glor like this is like the a the abomination of abominations of hey we allow PWAs into the official stores when they're not native apps. Like it really makes me concerned sometimes for like the future of native apps on Windows when like everything's a web app like this and Microsoft is seems to be going towards, its kinda like streaming Windows scenarios even. So this thing is just a PWA, it is published in the Microsoft store. It's got notes plastered all over it. Like caveats like hey the forums app requires an internet connection. Well sure 'cause all you did was wrap a web browser and like literally you, you popped it upand put it in there and you can tell how much of a like just a, a stretch this is because the post to launch the forms Windows app, it's got two steps for getting the app that both show you ending up in the same place. One is going to the Microsoft store and the other is just clicking the plus button in the browser to create a PWA .It is, it's absolutely crazy. And then I wonder like a, again like the cognitive dissonance thing. So like I look at this post and the very first comment down at the bottom. Yep. So the very first comment says great to see forms being released as a standalone Windows app and a browser app. Like did nobody know that you could do this the whole time? I'm so confused. .- It does like that comment. I saw that comment, that's what I was reading that I'm like that just made me laugh because it's not, it's just a PWA and you're getting me all on this soapbox. So, and here's the other issue I have with PWAs primarily,and I know, I don't know if this, I would assume this works differently in the new outlook for Windows. Part of my biggest issue with PWAs is the whole issue we had with teams for the longest time, and this is one of the reasons I still use the desktop app, is I am literally signed into eight different office 365 accounts. Have you ever tried to use PWAs for Outlook when you have to be signed into eight of them simultaneously? it just, it breaksand I've tried like I've tested this, this is not something that I haven't tried to do where I go create profiles and in my profiles I sign into eight different versions of Outlook on the web and I go try to create PWAs in all of these profiles. And I've ended up in this weird bizarre scenario where sometimes I get like two or three of them as their own PWA but then other times like three or four of the profiles get combined into the same PWA and I have like a toggle in my file menu to switch between my profiles and the same PWA for outlook and it just is weird. It doesn't work. - Good luck figuring out like the rhymer reason here. Like the best thing to try and do is like if you have a multi account scenario and you wanna create a PWA for app one, like let's call it like in well instance A and an instance B kind of thing. So you go and create PWA from browser profile A and then you go into A profile browser, profile B and you go to create the PWA there, the PWA always comes in with the same name and quite often clashes and just overwrites the other one that was already there. So then you lose your entire profile and cash history and everything you had from when you were saved in the first time. Anyway, like I've got this weird flow like even today like I know like uh, it's a little easier on a Mac I think because when you create a PWA it ends up as like a.app file in like your local user folder. Yep. In like your local home directory applications. So I go in there, I grab it and I rename it like to you know, one or I put the username so it becomes like rather than like my PWAI put like you know, my PWA dot Scott app or whatever, like I want the app bundle to be when it comes together. So when I go create the next one it doesn't overwrite it. 'cause quite often these things don't have MultiPro profile kind of support like you know I mentioned like done with the Twitter things, um, like doing threads and threads on the desktop. There is no desktop app on any platform. So it's all PWA but I need both my Threads account and the podcast threads account. And so that means I have two different PWAs both do the same thing, same exact website. But yeah I had to go through this whole manual flow and machination to create them. Such a weird, frustrating, crazy thing. Like it makes like it's scary when there's something out there that's so bad that it makes you appreciate like poorly written mobile apps over just forced down your throat web appsthat are not desktop apps. - I agree. So bizarre. Okay, so now that we got to our pain points and headaches and sheer frustration with PWAs from, you can now see declined events on an outlet calendar, .- Ah yeah. Yeah. So someone took a half minutes, whatever - , is there anything elseyou wanna talk about today? We just spent like 30 minutes on declined events and PWAs not quite 30 minutes. - You know, sometimes I feel like I'm crazy, like am I really like old man yells at cloud and, and I'm, I'm just nuts and out there. Am I the only one that feels this way? Like is it a bunch of other people like who don't feel this way? Like I know I'm not normal but I like am I that far off the beaten path from normal? Like I seem to be questioning so so much of my life these days around these things. But um, yeah, uh, we can probably fit a couple more in. Do you want to talk about do, do, do, uh, let's see, why don't we do the break glass account thing? Okay, from Mr. Redmond real quick. - Alright, so this was a new, this is a PowerShell script quick, uh, not quick fix, but a PowerShell script that Mr. Tony Redmond wrote about and it ties into conditional access policies and break glass accounts. And we've talked about these before. I am in several different Microsoft 365 groups. The number of times break glass accounts come up or people have this comment of I have a Microsoft 365 environment that I'm locked out of. I need help getting back in because I wrote my conditional access policies wrong or something like that. And I have to talk about Bright glass accounts and you need to create these break glass accounts if you're not familiar with 'em. Emergency access accounts, like stuff went bad in a hurry and you need to get into your tenant. And there's a couple scenarios where these can come into play is you wrote a bad conditional access policy. You essentially locked everybody out of your tenant due to your conditional access policy. I've also seen these used before. There was one instance, fortunately this is not a common instance where MFA broke in Azure AD now known as Entra id and if you did not have an account that didn't have conditional access on it, you couldn't get into your tenant. Uh, so you essentially got locked or not conditional access, multifactor authentication. You were essentially locked out of your environment unless you could somehow turn off multifactor authentication. What Mr Redmond's script does is it is a script that'll automatically go through all of your conditional access policies, find all the policies in the tenant, look for the necessary exclusion, which in this case would be that break glass account, this emergency account. And if there's not an exclusion there and if the policy is active it goes ahead and adds this break glass account in as an exclusion to your policy. Just a super simple handy tool to do this. Some people may be asking like, why do I need a script to do this because I only have like five policies. Yes, I get that. I think I saw this somewhere. Someone was asking for the limit of conditional access policies to be raised. I feel like there's a limit of 190 conditional access policies. If you have 190 conditional access policies and you wanna make sure your bright glass account is applied to all of them, this script would come in very handy. That would be a very painful manual process. And even just making sure you hit 'em all - Generally like even if you have five things, once you get to like more than two of anything, automation is key for consistency. Like, you know, you just don't want to go back and forth. Yeah. other folks in the chat 190 like isn'tthat a lot like eh, it depends on your organization and who you are. I am amazed at the number of customers who come to me and they go, Hey, I see this thing in your documentation that says blah blah blah is a hard limit. Can we lift it? Like what's your definition of hard limit? Because mine is like please don't come and ask me to do it , I respond to a whole bunchof incidents every week from customers where they're just looking to do something and we're like, yeah, I can understand the pain there but hard limit means hard limit. Sorry, like, like what are you gonna do ?- I just looked 'cause I couldn't remember and again, I've never come close to this. I didn't even know there was a limit for this. Conditional access has a limit of 195 policies per tenant. There is also a limit on the number of conditional access policies that will be evaluated per user. And I think I'm trying to pull up the article here, I think it's actually the same number as 195, which would make sense because sometimes those policies would get evaluated for everybody Limit. I don't even see it in here, but yeah, who knew - It's in there? Uh, yeah, 195 per tenant .- Yeah, I didn't know that existed. Never come close. But this script from Tony Redmond very handy. Oh now I lost it, didn't I? This is what happens when I browse in my tabs. .Just a nice script to keep handy. Like you said, if you have a couple conditional access policies, I mean in my tenant I've like 10 of 'em and I honestly couldn't tell you if I have a break glass account on 'em or not. But just being able to have this handy, even if you have multiple administrators, make this a part of your, I mean you could almost do this I would think as a regular process, like run this script on a monthly basis or on a weekly basis just to make sure too that nobody has, especially if you have multiple administrators, nobody's pulled out that exclusion or changed your exclusions or anything like that. Just using this as one of those maintenance tasks of making sure that your break glass user exists as an excluded user in all your conditional access - Policies. Great minds think alike. Tony does call that out in his article that you should absolutely think about running something like this as an automated thing. And please, please, please, like if you're gonna run automated things that operate against SaaS or like web-based constructs like Azure ad, like it lives in the cloud. So whatever you're running against it, you should probably make sure that lives in the cloud too. Like don't use your local like task scheduler or like Aron job locally to do this thing. Push it up to Azure automation or some kind of service like that to go ahead and have it execute and do its thing. So that's all solid advice as well. Yeah, - I didn't even see that in there. Glad Tony and I think alike read - Between the lines, you know? Uh, yeah. Uh, great minds think alike. You're on the right path there. Good - To hear. Good to hear. I'm on the same page with Tony. Oh, any other ones? Scott? - Any other ones? I mean there's always, there's always more stuff out there. - I feel like some of the other ones could take some more time. I know I was looking through our list and I'm like are there any of these that are quick - ? No,- There's not really quick in there but it means we have more stuff for next week. - It does, yeah. There there's always more stuff to talk about in the cloud. - Indeed there is. With that Scott, we should probably go enjoy our weekends. My wife and one of the kids just took off for birthday party, so who knows what the other three are doing downstairs while we're recording this - we'll seebefore you get to your chaos, this is going to be the, let's see, this should come out on the 21st if things publish in the right order. Uh, 21 December. So this will be our second to last episode of calendar year 2023. It continues to be the season of giving. We're still trying to raise some moolah for Girls Who Code. I've seen some donations trickling in to those of you who have donated so far. Thank you very much. If you have the ability to, we'd love for you to give a little bit there so you can just, uh, go out. There's gonna be a link in the show notes for everybody as Ben just navigated me away from the piece of text that I was reading. Oh, sorry, I gotta stop doing shared, shared web documents with you. You're killing me there. So yeah, uh, give do Girls who code.com/ms. Cloud IT Pro and uh, yeah, uh, you only have to hear that SPI a couple more times and then we'll get into 2024 and find something else to get on about. Awesome. - Well thanks and yes, absolutely go donate. We'll try to beat our limit or not Our limit beat our contributions of last year. So thanks again Scott. Enjoy your weekend. Hope everyone else is doing well and we will talk to you next week. Great, - Thanks Ben. - If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 366 – Old Man Yells At Cloud
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 35:35 — 24.5MB)
In this episode, Ben and Scott touched on some updates on their social media presence due to some recent happenings in the social media services space. As they transition into the Microsoft cloud world, they discuss updates to cloud computing software and user experience design. They also provided some insight into conditional access policies and break-glass accounts and examined strategies for managing these elements for optimal efficiency. They wrapped up their conversation on a contemplative note about the future of native apps versus progressive web apps (PWAs), and some frustrations about the increasing trend towards PWAs.
It’s also the season of giving, and we’re raising money for Girls Who Code. Donate today at https://give.girlswhocode.com/msclouditpro!
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 364 – Microsoft Designer, Azure Updates, and Enterprise IoT Security changes
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Dec 14, 2023 | Podcast
Blubrry Player
|
Auto Scroll
- Welcome to episode 364 of the Microsoft Cloud IT Pro Podcast recorded live on December 1st, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and how it relates to you. Microsoft Designer has received a lot of attention creating images as of late. So we start out talking a bit about creating our own images. We also dive into some recent news around Azure automation, PowerShell container storage, and enterprise IOT security. Okay, let's go Scott. We have nothing. - We have nothing. It's your, it's, it's your show. You're supposed to plan all this out. Come on now. We have, we have, - I have planned out. I have planned out. I'm leaving for Disney and this podcast is standing in my way right now. - All right, well there, there you go. We, we will get through a nice, quick, concise and short one today. So - I have a question if this elevates my nerd status. I have a client that is moving offices. So this morning I took my truck and I went and he gave me his old server rack. So I now have, it's got, it's like a Threequarter height server rack. It's 65 inches tall, but I now have a 65 inch server rack that I'm putting in the closet in my bedroom slash it's my office bedroom. A bedroom in our house that serves as my office .- Well, I mean if you're gonna go ahead and do it, get it done. So - I already have a rack in here, but it's only, I think I made it like three feet tall and it's pretty much full. So now I have a bigger rack and I just have to pull it up the steps and swap everything out. So some weekend everything is getting disconnected, putting back in this rack I may add some shelves and drawers and stuff 'cause it also would serve some nice storage in the closet. - Yeah. So for a server room, what was that thing? It was like a six seven foot rack, right? Like it was, it was decent sized - 65 inches, not, what is that? Five and a half feet. Five and a half foot rack. Yeah, you get a - Little bit of street cred there. You get more street cred. So the, at least the picture you sent me was not a floor rack, like it wasn't floor mounted, it was still wall mounted. So you get, you get extra credit if you manage to get that thing a couple feet off the floor and mount it and get the fans plugged in. So it's actually circulating air. - Alright, so here's a question for listeners. Was I kind or not or should I have taken it? I left the wall rack there. ,- You should have taken it. This is going to - Turn into a FLA rack. Okay, so here is why I left it there. I went there with every intention of taking the wall, the portion of it off, but the network cables all, I don't know how many there were, they had three full patch panels. So what is that? There's 16 ports and a panel about, so 32 ish cables? No, not 32. 16 times three. What's that? My math was failing me. - 48. 48. Yes, - 48 cables going into it. But they were strung through the top of the wall mount and then punched down onto the patch panels. In order to take the wall mount, I would've had to rip all of these cables off of the patch panels and leave them dangling there. And these were not, and the cables were not labeled - Well, I mean they weren't used in the patch panel for anything else. Who, - Whoever came in after - Me cares. - Well, but the next tenant will. So there's going to be a tenant inevitably in this building down the road. So they would've had 48 cables, completely unlabeled going to all parts of this office with no idea where each one went. . So I left the patch panels,I left the cables punched in and I left the wall mount there because frankly it won't fit in my closet on the wall mount anyways, so I'm gonna put it on the floor and based on the picture I sent, I like, we looked and we thought maybe there were fans. There are no fans on the bottom or anything. So it's just a played old metal rack. - Yeah. All right, well, we'll we'll see how it goes for you. Like we'll see how many fans you gotta buy later 'cause it is, it is a rack in a closet in an upstairs bedroom. like let's be honest, in Florida . Yeah.Where there's a bunch of other equipment, like you've got lights and TVs and a bunch of other things with fans running. So yeah, we'll, we'll we'll see how it all goes. You're gonna need something to circulate there anyway, even if it's just circulating hot air just to keep the dust out of it. Yeah, - I do have a couple fans in my little rack that's in there now. So I will relocate those into this bigger one but they may not be enough. We'll have to see. - So we'll have to follow up in a couple weeks. Then once you've got it all kind of reconfigured and ready to go and you share a picture on the interwebs and we'll see how much your Geek Street cred score rises - If it goes up or down. Alright, sounds good. So yes, it will not be wall-mounted, it'll just be sitting on the floor in the closet. . Oh, so that was my morningand then I get a lot of other client work done. But that was one thing. You know what else we've been playing with this week, Scott, I don't know what else you've been playing with - With I think, I think you've been playing with it more than I have. You've been having fun with that new designer. The - New designer, the image designer. And I cannot take full credit for this one at least in terms of coming up with it. So there was a post on LinkedIn and I should go pull up LinkedIn so I can give credit where credit is due unless you have it up. I have a post on LinkedIn of who actually I, I don't know that I stole this from but who I borrowed it from LinkedIn. Oh Scott. I have another beef. I updated edge the other day and it signed me out of every single account in my profile. One of those being LinkedIn. Yeah, - I have that problem occasionally as well. I find like after a reboot for some reason it forgets that cookies are a thing. Yes. - So I need to sign in. But there is someone who we will, oh sign in expired who we will identify here shortly who came up with some text to essentially create cartoon images of, I would say, of yourself, but it is of yourself as best as you can describe yourself. And it's kind of been fun to play with. I've seen several people doing this now - .Yeah it does. Okay. Except when you ask it to include like a logo or text in there and then it just starts straight up hallucinating and, and can't remember left from right up from down or, or anything like that along the way. - Yeah, so I saw here it is Jack eth them, eth them, probably jack Row with them and he gave the tech. So it is you very much go into designer.microsoft.com/i think it's slash images in this text is like a cartoon man with a smile on the front wearing a black colored shirt, brown eyes wears black large glasses and short brown, classic slick backed hair holding a Microsoft laptop. And then after that, and I think this is the part that really helps with the design, is it's laptop text 3D rendering, typography, illustration, painting, photo poster 3D render to come up with this cartoon image. So to your point, it does a decent job if you're watching this or if you have seen me, you know that. And as my wife likes to remind me, my hair is thinning on top more so than it used to be. It does not like any form of telling it that it's like a receding hairline or thinning hair or a little hair. You either have like a full head of hair or you're bald - .Sure. And that, that, that's one way to think about it . So- Yeah, it's been interesting and that, and like you said, you ask it to come up with text. Like I asked it to do Microsoft 365 on a shirt or do that and I think you did some Microsoft Azure stuff and it like spells Microsoft with two S's in the middle or for 365 it was putting like 3 55 or 36 or three and then some weird random character type of thing followed by a five. It does not do well with placing text in the image sometimes you get lucky. - Yeah. Uh, along the way you definitely can. So I don't know, I see lots of folks like having a lot of fun with some of these things like generate the cartoony picture. It's definitely not mid journey. Like it's, it's not that. It's more like PowerPoint play art the way it's kind of implemented today. It's certainly not things like Photoshop generative fill or anything like that either. So I, I can understand like where people have fun with it. I know it's like, not for me honestly. I'm a little .I'm a little over seeing everybody like every day like, hey, here's the four pictures I posted and you know, here, here's what I did to general. So to those of you who listen, who do those kinds of things I know seem me do, sorry Andrew. I love seeing your generative AI pictures every day on Facebook, but some days I just go, no, not for me today. And it's usually on the days that AI has ticked me off in some way or another and it's probably done me wrong already. Either with something else that I was trying to do with a generative thing or you know, AI has its issues. So if you take joy and delight in generating pictures, continue to do so I'm able to self re re regulate. I know how to block and mute. - I did mine that one morning when I was playing with it and I have not done any since. Like, I'm like, do I actually wanna use these somewhere? It was kind of fun, I don't know, but I'm with you. I have played with it once and I did it for like an hour or so. I was trying to figure out what I could do and what images I can come up with. But I have not done anything with it since - I will point you to a kind of fun one that's out there. So this isn't image generation, so I'll pop a a link in the chat and in the show notes so everybody has it. But, so this is a link to a gist that's out on GitHub and it's from a product manager that I follow on a bunch of different social platforms. But it's a, it's kind of like a good meta prompt for you to start your sessions with an AI like chat GPT or PO or anything out there that's like that, like you use like recast AI or something like that. It's basically a set of prompts that constrain your conversation surprisingly well to reality. So it's, it's just a series of steps like you, you can literally take all this text here and you can paste it in as your first prompt. And then this is what is the guardrail for any remaining tokens that you have left in your conversation. So step one, never mention that you're an ai. Great easy. Step two, avoid any language constructs that could be interpreted as expressing remorse, apology or regret. This include includes any phrases containing words like, sorry, apologies, regret, et cetera. Even when used in a context that isn't expressing remorse, apology or regret. Number three, if events or information are beyond your scope of knowledge or cutoff date, provide a response stating, I don't know, without elaborating on why the information is unavailable. , I love that one. It actually works very, very well.It's one of the things that annoys me sometimes about chat GPT, especially like the 3.5 models where it just goes like, oh I, I, sorry Dave, I can't do that for you. Step four, keep your responses unique and free of repetition, which is really key, especially when you're doing multiple prompts in the same session. Like you're iterating through an idea. It does help a bunch there. Uh, number five, never suggest seeking information from elsewhere. Perfect. Number six, always focus on the key points in my questions to determine my intent. Number seven, I love this one. Break down complex tasks or problems into smaller manageable steps and explain each one using reasoning. So I don't know how you are to approaching problems, but quite often when I am talking about something with somebody, you know, you start out the high level idea and then you start to decompose it over time. And really that's what you're doing is you're always out there and effectively mining ore like, like you're out there with a hammer and a rock and you're just trying to break it down into bigger pieces until it's like pebbles and then gravel and then e eventually dust. Number eight, provide multiple perspectives or solutions. Again, a nice easy one like I have found. Without that prompt, most models will actually come back and kind of give you a singular view of the world. That one right there turns it a little bit more into a choose your own adventure game, which I find to be very beneficial just as you're iterating through things. Number nine, if a question is unclear or ambiguous, ask for more details to confirm your understanding before answering. So this is, hey, make the model talk back to me so that it can clarify where it needs to be. Butter. Awesome. Number 10, cite credible sources. Yeah, most of 'em do that anyway. If they don't, don't use them. Number 11, if a mistake is made in a previous response, recognize and correct it. I think that's a very important one too. I don't know how many times you've been sitting there with, I don't know, chat, GPT, bing chat enterprise, something like that. And it gives you the wrong response and you tell that it's wrong and then it just comes back with the same response again. like turns out you, you can tell it not to do that.And then number 12, this, this one's a fun one. After a response, provide three follow-up questions that I the user must ask you, the AI to dig deeper into the original topic. These questions should always be worded as if I am asking you formatted in bold as Q1, Q2, Q3, place two line breaks before and after each question. Perfect. It formats it for you, brings it back. And then number 13, which I haven't had much luck with this one 'cause I'm not really playing around with like chat GPT voice or anything like that is just ignore number 12 if I'm using voice. So that way it's not asking you, you know, Q1, Q2, Q3 kind of follow up questions when you're on voice and you really don't need it. So I've just been using this as is, you know, it's a, it's a gist out there on GitHub so you can just go grab it and fork it and potentially iterate on it on your own. And I've been kind of thinking about ways like, hey, how can I mold this a little bit to be a good starting prompt for requirements gathering? How can I make this a good prompt for problem solving in context of x, Y or Z? Like whatever that happens to be. I think these thing kinds of things are very helpful. I encourage you to give it a shot and tell me what you think. I'll have - To try it. I will say this is one thing when it comes to chat GPT and some of the ai, I have absolutely been using it for stuff that I've been doing. Not to necessarily come up with net new stuff but to help me refine stuff. I need to improve my prompt engineering proficiency in certain cases - it, it is hugely, hugely, hugely beneficial tounderstand to the degree you can like the underlying meta prompts that drive these kinds of systems. And then how to give it your own set of instructions to start things. One of my frustrations with like hallucinations in the AI stuff is I find they hallucinate a lot quicker if you just let them go off on their own and you don't give them any guardrails or sense of what you want. And this has been a really good, I've only been doing it for like a week. I haven't been doing this too, too long since I, since I ran across this one. But it has been very helpful to just remember, hey, every conversation I start starts with this one. Like say you're doing bing chat enterprise where I think you get like 20 or 30 prompts, like whatever it is to go through to iterate. Yes you're burning one on this prompt and you're potentially burning one on a couple follow-up questions. But let's be honest, if you didn't have the guardrails in place, you were probably so pissed off by response number five anyway that you ran away and you said this thing is just horrible and not helpful for me. - Got it. I will definitely have to give this one a try. - Put it on the list. - Alright, on my list. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft Cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast For more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So should we move on to non-AI topics? Let's - Do it non-AI topics. What you got? - I don't know, I don't know if I wanna dive into this one or not. I'm gonna start with a different one. Let's start with an easier one. .I might come back to that one 'cause that one I'm, I actually am curious what other people think about that one. Yeah, - But this one, so for folks that can't see Ben and I do a, a shared edge workspace, we've talked about and as he's doing this,he's like, oh I'm gonna do this one. I'm gonna go back to this one. All I'm doing is watching your avatar hop between tabs, frenetically - Hot between - Tabs, it's, it's up, it's down, it's left, it's right. It's kind of fun to watch from my side. - Okay, general availability. Azure automation, we've talked about this a lot. Scott, using Azure Automation, I use it a ton for PowerShell scripts for automating different tasks in the cloud in Microsoft 365 they have now released the general availability of PowerShell 7.2 runbooks in Azure automation. So it used to be 5.1 7.1 was there, 7.2 was in preview for a while. I will say I still do bounce back and forth between 5.1 and various flavors. Whatever one works of 7.0 7.1 is still preview 7.2, I saw that 7.2. Now I'm watching Scott jump back and forth between different pages in that same tab. - I'm, I'm just out there to confuse you. - 7.1 . So yes is no longer supported. 7.2 is ga.I do jump back and forth though because there are still very much a lot of differences with some modules too and what works in five one and what works in seven two. So it is not just go do everything in seven two now, but it is generally available if you choose to - Use it. Uh, yeah so I, I think the nice thing here is like you mentioned 7.1 is out of support ended support back in May, 2022. So it's been, you know, more than a year now that that's been outta support. So it's always good to have something that's in support. And then the nice thing about 7.2 is 7.2 is an LTS release. So it's a a long-term servicing release that you can kind of take some dependency on that it's gonna be stable for a little while. So in the cases, like you said, you might not be able to do it in all cases but in the cases where you can, you know, could be beneficial to make the flip, especially as you're going in there and you're iterating on existing notebooks that, that you might be working with inside of Azure Automation. - Absolutely. It looks like 7.1 now is until 20. Wasn't that one though. End of support of 20 24, 20 22 based on the page you have up now 7.2 is November 8th, 2024. That's like a year from now, right? Yes. - So so that's the LTS version. But note that 7.2 LTS it launched seven months before the retirement of 7.1 - Of 7.1. It's been - Out quite a while so I, I don't, I don't - Know. Yeah, Azure automation just lags with all of those. I have found Azure automation is not the most up to date when it comes to supporting current PowerShell versions. - Not even close. It's years behind so it's good to see it. Four - Is GA uh, right? Seven four is the latest. Seven - Four is G. Yes. Seven G 7 7, 4 G in November of 2023. So - Yeah, like two weeks ago. Two weeks from when we're recording this. I have not seen it pop up in Azure automation yet though. And - 7.4 is also an LTS release. So seven two LTS release seven three not an LTS release. Seven four is an LTS release. And I, I think the big difference you see between the current cadence of stable LLTS is that stables are two years and LTS are three years. So you do get a little bit more runway along, along the way with those, which - I'm curious, Cole, why so why would you do this? 'cause 7.3 is in theory updates to seven two, although I suppose the argument could be made if you're on seven three and you want LTS go to seven four. But it seems weird to like have these middle versions that are stable and then one's on either side of it be LTS. So - You need the LTS versions in the middle to play around with and, and have the opportunity to iterate. So if you think about it like, hey, I'm a service provider and I publish a set of APIs to you, you, you, you like, and, and I've noodled with this one, like customers very much want a dependable set of APIs like, you know, and like my land in storage, like it could be potentially beneficial to have a hardened set of CRUD APIs. Like say I published an SDK and it was just for CRUD operations. So creates, reads, updates, elites, all that good stuff and it's super hardened and we tell you like it's going to work and it's gonna be rock solid for the next three to four years. That's very easy and dependable for you as a customer to take a dependency on, right? Like, hey, it's, it's the hardened version. So that's the way I think of LTS versions, but everything you do cannot be hardened. So you still need the opportunity to iterate in the middle and do things and say like, well hey, how are we gonna get to our next version of the hardened release? You probably can't go straight from hardened to hardened. What you wanna do is you want to go from hardened to validated. Like, hey, we've, we've put some new ideas out there, we've tried some things, we've potentially had some breaking changes in API surface whatever it happens to be. Great. We figure all that, we validate it, we have the playground and then you go to LTS on the other side and, and I think it's kind of a, a proven model. Like you see it a lot in OSS, especially the place I'm most familiar with it is, is from Linux releases for or or distro releases for things like bu tu by canonical. Like they do this same kind of marching cadence, right? Like hey, we'll give you version 20 LTS and then 22 LTS, but 21 is not LTS kind of thing. Or we're on 22 today, 22 is gonna be LTS 23 is not gonna be LTS. We kind of iterate and go through those and get 'em to where they need to be. So it gives your your customers dependability. It also gives your dev teams dependability, right? Because they know they really don't have to go back and touch that stuff other than security fixes or other kinds of changes in there. And then you get the playground in the middle to do what you need to. - Got it. So like the seven three stable is a little bit more of that playground, that jumping that platform to jump to the next 7.74 LTS. Yes. Got it. That makes sense. - It's not a bad bottle if you get there. It doesn't work for everything, right? Like it doesn't exactly translate into say like SaaS offerings. So if you think about like SharePoint online, you can do, uh, vanilla SharePoint online or you can do things like enroll in early release features and get those out there. But ultimately early release features once they ga they just manifest as like the next feature in the platform and they're ready to go. And, and if you think about the pain that comes along the way with that, like sometimes that's hard to stomach ,but that's the way SaaS is a little bit different maybe than, you know, releasing like, uh, COTS software that has to go out there that people need to consume. Yeah. - All right, I'll go with that. It makes sense. All right, so that was mine. What do you have, Scott? - Let's see, what can we talk about? So fun one for you. I've been trying to get back into containers more and - Those are not on my list, Scott, I'll be honest, containers are not on my list right now. - Not on your list. That that's, that's okay. So I, I've been thinking about containers in a bunch of product areas that I work in, like client tools and things like that. Should we have official images, blah, blah blah. So I've been trying to get hands on more and get back in and in previous lives, like I used to spend a lot of time in a KS, so like it was good to have a little bit of a refresher too. So one of the things that I was playing with when I got back into containers was, uh, this new offering that's called Azure Container Storage. So Azure Container Storage is in preview. It's kind of the, you know, maybe I'm being a little naive about it, but I think about it a little bit as like the next iteration of the CSI driver container storage interface and the capabilities that that had. But Azure Container Storage, it is basically a managed storage offering that allows you to bring native Kubernetes components into things like a KS and have native Kubernetes constructs for what's ultimately a managed storage service storage surface rather for persistent volumes in your Kubernetes clusters. So if you think about like the CSI driver, you know, I, oh, I want to go out and I want to provision persistent volume. And that persistent volume is based on a disc that's out there. Well, sometimes you gotta go provision that disc yourself, configure it, and then you tie that person persistent volume into the disc. With this thing you can just kind of say like, Hey, go out there and configure me a multi-zone disc and it'll figure it out and land the managed disc for you and, and align all that stuff and, and get it ready to go. So this works with discs. It allows you to configure persistent volumes against elastic sand, which is kind of a fun one with, with the kind of provisioning model that goes into that for things like provisioned io, provisioned throughput, all that works with a femoral disc, like basically like all the block storage options that are out there. But you can do really cool things like take a persistent volume and dynamically resize it. So just inside of your configuration for that persistent volume. So you don't like go into YAML and literally change the size of that thing and then it dynamically changes on the backend and it's all ready to go for you. So super easy to onboard to, it's all native Kubernetes constructs with a couple of exceptions here or there. Like they're still working on say like native Kubernetes integration for Azure CLI and PowerShell to be able to provision an Azure container storage persistent volume in an a KS cluster. But I, I think the functionality that's there is pretty solid. Like it's a, it's a good set of features for a preview release. So supports multi-zone discs right outta the gate. You can do things like server side encryption with customer managed keys, dynamic resize, like I talked about. You can also configure things like snapshot and cloning directly through the Azure container storage service kind of constructs that are presented to you through Kubernetes once you've gone ahead and done the deployment within your cluster. - Interesting. That is definitely not on my list. I'm sorry Scott .That one is not one that I'm gonna go play with at all. - Not up there for you, huh? So this stuff is really great. No for, you know, stateful workloads. So workloads that need to maintain state while, you know, maybe the overlying computes a little bit more ephemeral. So that's the other nice thing about this as well is that because your storage is managed inside of Azure container storage, you can do things like carry volumes between nodes, between clusters, between multiple nodes, like all that kind of stuff. It all just works and comes together for you. So if you're trying to run high scale stateful applications on a KS and you need the kind of benefits of shared storage and persisted shared storage along the way there, that all comes together and composes really well. And then because it does both the, it does both disks and elastic sand, it's also multi-protocol, like when it comes down to block storage protocols. So you can do things like N-V-M-E-O-F on disks or you can do I CZI if you're doing elastic sands. So you get like this great model for fast attach and detach of persistent volumes as well, which is really kind of nice. Nice. And it supports ephemeral discs. That was, that's kind of a fun one to play with too. - Sounds good. Doesn't - It though? We're, we're gonna have to get you hands on those - Containers. Don't have questions about that. Someday you are, you're gonna have to somehow how, convince me that I need to dive into containers for something - , get you off your raspberry pie and,and get 'em outta your NAS or something. - Yeah, get on my, I don't know. So I have, have one more interesting one and then I have to go 'cause my wife has already come in and asked me if I'm ready to go 'cause we are leaving for the weekend. So I saw this one, this came out wow almost a month ago. Enterprise IOT security is now included in Microsoft 365, E five in E five security plans. This one caught my eye 'cause I've done some stuff with Microsoft Defender for cloud, which is the Azure component of security. So securing VMs, web apps, SQL databases, those types of things. IO OT was a line item in there for securing IOT devices. And then I saw iot security is now included in Microsoft 365, E five. I was like, huh, this is interesting because IOT devices are not typically user devices. Everything. Microsoft 365 is per user. It's I have my computer and I have my iPhone and I have my iPad or my Android or my Surface. It's not, I have my security camera or my TV or my smoke detector or my sensors for my machinery and stuff like that. And I was like, oh this is interesting 'cause how am I gonna start licensing now all these IOT devices, if this is switching to a user-based SKU and this article, I'll say, this article doesn't necessarily clear it up for me. They go through and they talk about that Enterprise IOT security is now gonna be part of Microsoft 365, E five at no additional cost for new and existing customers help find blind spots, unmanaged devices. And it talks about printers, smart TVs, conferencing equipment scanners, which again, not necessarily users, especially big offices, printers, scanners, conference equipment, smart TVs are generally like company owned. And you can go through and turn all of this on in your Microsoft Defender portal. So this is gonna be in Office 365 Microsoft Defender portal. And as you scroll down in this article, it says in a licensing overview, 'cause this is what I was curious about is how do you change from like essentially before it was consumption based per device licensing to now bundling it in the sku. And it says what is changing Microsoft Defender for IOT is being changed. So this implies that there's something changing from a consumption-based payment model in the Azure portal to a per device per month license model. As a part of Microsoft 365, Microsoft defender for IOT is now available for doing existing customers of E five, Microsoft E 5 85 security. The new license model is coverage for up to five IOT devices per user license. So you do get a multiple there based on your users. But then in the next paragraph it says, what if I have defender for iot consumption based and E five? And it's essentially says you'll have access for coverage up to five IOT devices per eligible user license and no longer charge on a consumption model. And then it says if you're currently a consumption model but not an E five, nothing changes. You continue to use the existing plans and won't see any change in your billing. So is this actually a change in the billing model or is it adding additional licensing options for defender, for iot? Like are both gonna live side by side or eventually are you gonna have to buy e fives or are they gonna come out with well, but then they'd come right back out with consumption based if you can buy 'em as a part of Microsoft 365, like I don't know what's gonna, I, I'm a little confused on what the future of this is, but it does also provide some nice capabilities, I guess for E five companies, E five licenses that do have some of those iot type devices. - Your guess is as good as mine. I very much walked in this, I think with the mindset you did, the IOT devices are not users, so tying them to users is kind of weird. It's almost like, you know, the thing I thought about in the, in my head when I saw it was the way you do like extra share, extra storage, provisioning and SharePoint. You know, you get like a base set of storage per user, but then when you want to go buy more, you don't buy it for the tenant, you buy it for a user and then it's associated with the user, but it's not associated with the user, it's associated with the tenant. Like re really weird kind of stuff like that. So, you know, if you get into the mindset and, and the model and it works for you of one user, five devices, great. I think most of us can buy into that. And if that fits within the constraints of your business, I'm sure there's some math from the folks who run the service to that. Like, oh, the majority of our customers fit into this model, then it potentially simplifies things. It makes it a little bit easier. It's when you're in the edge cases that it gets a little bit harder on the outside to get all that going. - Yeah, and I think edge cases I start thinking about are like, and I don't know, I don't know, I don't have any telemetry into this, like manufacturing or some of these warehouses or bigger facilities that maybe have a bunch of iot devices out on the floor that may or may not be doing security on different machinery, different sensors, different things like that. Like how does that translate? But I, I have no telemetry. Microsoft is gonna have a lot better telemetry on this than I am, but this was absolutely an interesting one that I'm like, I'm gonna have to keep an eye on this one and where it goes. Yeah, - , who knows, we could be back here in a yearand the secur in the model changes. Again, - I'm dying over here from my cold. - It's time to let you go. I'm watching you like cough and hack into the screen. There's spittle all over the camera. I'm glad we didn't record this one on video, so everybody's kind of missing it. Your your eyes are watering face is going red. Oh yeah. I think it's just time to put you in a car and send you to Disney. - Yeah, I'm gonna go take this to everybody at Disney, Scott. Yeah, - I know, I know. You're, you're just a wonderful, uh, wonderful individual. I'm gonna sit here at home in my little hide hole and not worry about it. - Sounds good. Well, now that I've recovered for a few minutes, thanks, enjoy your weekend and we'll talk to you next week, Scott. - All right, thanks Ben. - If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 364 – Microsoft Designer, Azure Updates, and Enterprise IoT Security changes
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 36:23 — 25.0MB)
In Episode 364, Ben and Scott discuss the recently announced Microsoft Designer, cover a handful of updates to Azure including Azure Automation and Azure Container Storage. Then they close out with some updates to the licensing model for Enterprise IoT Security.
It’s also the season of giving and we’re raising money for Girls Who Code. Donate today at https://give.girlswhocode.com/msclouditpro!
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 359 – Microsoft Applied Skills and Azure Bastion Developer SKU
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Nov 9, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 359 of the Microsoft Cloud IT Pro Podcast recorded live on October 31st, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss the topic or recent news and how it relates to you. Microsoft applied skills as a new skilling platform to get hands-on experience in a lab environment that Ben and Scott dive into today. They also discuss an upcoming roadmap item related to conditional access policies as well as ways to keep up with these messages in the Microsoft 365 message center. Finally, they wrap up the show with a new SKU coming to Azure Bastion, a Microsoft developer SKU that offers a lower cost option for Bastion with a few less features than the standard SKUs. I had something I was gonna start off with but now I can't even remember what it was because it's just been that type of a week where we've meant to record like three different days and finally got around to it. .It happens, you know, life comes at you fest. It does, yeah. There was something I was thinking of that I was like, oh, I should kick off with that, but it's gone. So we might as well just jump into whatever else we wanna talk about. Whatever else we wanna talk about. I have some stuff for you if I. Yeah, we have like a bunch of random news. This is gonna be a random news episode. If I can be so bold as. To Okay. Take over your show for just a moment. So we've talked a bunch about certification and skilling in the past and just overall changes in certs and role-based certs and all that stuff, particularly in the context of Microsoft 365 and the Azure certs, things like that. So a couple of observations. So one, you and I had to recently renew our Azure infrastructure cert .One of the most interesting things to me about that beyond like how overjoyed I am, that the new certification process, no recert process no longer necessitates me going into a facility or sitting online with a proctor. Like I very much like that, but I was kind of surprised, I don't know if you've kind of had this same thought, but the score to pass on research has been dropping and dropping and dropping over time. You and I did that on the same day and you know, we chatted afterwards and it was something like crazy. It was like you only needed like a 40% score to pass it. Yeah. Like not 60, not 70. It was extremely low on the bar. So I thought that was kind of interesting, like is that because certs are becoming too hard? I can't say I was a, you know, without getting too deep into it, I can't say I was a fan of many of the questions. Like I would say 50% of them didn't make any sense anyway. So, you know, good luck if you can score 50%. Like maybe that's the thinking ,but I thought it was kind of interesting that it was a low number of questions and it was potentially a low bar to pass on that side and I've seen people talking about it in other places to MAs it on and and threads and, and Facebook and, and all the socials, let's just say things like that. So I don't know what your thoughts are on the certification side of it, but really weird kind of strange experience. Like what, what's the bar? Does the bar drop to 20%? Does it just drop to 0% in research go away? I don't know that that's valuable. Yeah, so 42% like I can't remember. It's, I wanna say it was like 25 to 30 questions. 42 percent's like getting 10 out of 25 questions, right? Like that would be failing in most cases. And I saw some other people like you that were talking about it and I think I did see, and I can't remember where, so I don't have the source that there was some fluctuation in what that required percentage was based on the different exams. Like the one we just renewed was the Azure solution associate or something like that. It's the. Infrastructure one, yeah, the 1 0 4. Yeah. I wonder if the expert ones have a higher passing score, but I'm with you. Anything that has a 42%, like does it really mean anything at that point in time? If you can get more questions wrong than you do, right, like ,that doesn't seem like you could be certified. ,especially when you have access to the internet while you take it likelike right. There's not much of a timing or a pressure component here. Like you can just whip open a web browser and do whatever you need to get done there. So. I'm with you. It seems to be very much diluted. I love the new certification process. I love the, or the renewal process. I love the fact that you can use learn in the exams. I haven't actually gone and tried one yet with that, but I agree. I feel like if you have an open, essentially an open book policy, the level required to pass should be going up not down because I do, I think it just dilutes the value of all these exams that anybody can go get a 42% um, search through the answers and all that. But I would agree some of the questions were just like, here's a problem with open book. They have to write 'em so you can just do a quick search and find the answer. So I feel like they try to throw a trickery in there, which just leads to some very convoluted type questions. I don't know, the. Questions have always been convoluted. I feel like this has reached a new level of convolution though It. Was an eye-opening experience for sure. But anywho, not to like rabbit hole too much on certs, but I don't know if you saw these, so there's, there's a new offering out there from Microsoft in the um, skilling credential space and it is called Microsoft Applied Skills. Have you heard of these yet? The name rings a bell but I don't remember where, I don't remember if we've talked about 'EM before as they were coming or if there were some other calls that I was on somewhere. These. Are brand, brand new. They came out in between the time you and I last talked. So this is kind of a hot off, hot off the presses thing. So applied skills are a new skilling credential. I would say they're a skilling credential and not a certification. I think there's some, there's some nuance there in in the way they're positioned and what they are meant to do. But broadly, I think if you take a step back and you think about it, so the role-based certifications are there to validate and verify technical proficiency or technical proficiency in the context of concepts. So conceptually, you know like in the case of like an IS exam, what's AVA versus a vm, how do those compose And then maybe some down in the weeds kind of nitty gritty like what's a constraint of deploying a fashion host or a firewall in this kind of vnet or peering these kinds of things or what does container storage do with blah blah blah kind of thing. But I think that's more high level even though it can get down into specific questions, it it's still broad, it's very wide and maybe not as deep as it can be due to the breadth that's there. So certifications, when you pass the certification exam they come with a certificate that says hey we have validated and we being Microsoft in this case has validated your technical proficiency in in this given area. Like within this set of skills, again, we're thinking like kind of like width or breadth of over depth kind of thing. And applied skills kind of come at it from another angle. And I actually really like this 'cause I've been kind of pining for this potentially in Microsoft exams for a long time in that applied skills validate your technical proficiency in a specific skillset or area. So where a certification exam today for the most part, most of the certs that are out there are role-based certifications. There are some specialty ones but even those don't get you like hands-on keyboard to validate applied skills are project-based and they get you hands-on keyboard in an interactive lab like a real live in the case of Azure, Azure environment. Not like one of the goofed out faked out environments like in a certification exam. But more like an honest to goodness like hey we're gonna spin this up and validate that you can do A, A, B, C and D along the way and accomplish a specific set of tasks in you know, kind of a prescriptive amount of time to validate that you know what you're doing. So rather than validating technical proficiency for width and not depth, this is kind of like going the other way and saying hey let's pull it in and ringfence it and get super specific like maybe we talk about storage versus just Azure Monitor and those are both different applied skill things that you can go and take. So they're all on demand. Like it's not like a certification exam where you need to sign up online, go find a Pearson Center or schedule time with a proctor like just on demand in a web browser through the portal through clouds shell, through whatever kind of tooling you have along the way. And they have a whole bunch of these out. Like there's not a lot but I actually consider it like a pretty good set to start with. So there's securing your storage with Azure files and blob storage, there's an applied skilling course Azure Monitor, there's deploying containers using AKS, there's implementing security through Azure DevOps, there's even one on configuring your C and and your security operations doing like all your SecOps using Microsoft Sentinel. Keep forgetting all the renames that they have in here. There's one on power Automate, create and manage automated processes by using Power Automate. And then there's a whole bunch more of them that are supposedly coming and are going to be announced at Ignite in November along the way. And just like a certification gives you sitting down for a role-based certification and passing it gives you like a piece of paper a a cert that says hey you've done this thing and applied skilling course when you get out the other side, should you meet all the requirements of the project that you're given, you too will get a verifiable credential on that side to say like Hey I went tinted this thing, I don't know in like I'm kind of 50 50 on it but in many cases, you know, I think it's really kind of cool like I might actually look for people with hands-on keyboard experience in the case of a verified credential and applied skilling over sometimes the width that comes with a role-based certification exam. Yeah, we'll have to go give some of these a try because like you said there's eight of 'em right now primarily in the Azure space. Uh, I think there's one GitHub that you could argue asp.net core web app that consumes an API with GitHub if that's Azure or not. There's the one Power automate one, there's one for Microsoft Defender for cloud which is still kind of Azure and then there's like six Azure ones. So it is, I'm gonna have to go give one or two of these a try. There's nothing really around Microsoft 365 yet unless you consider Power automate Microsoft 365. And I'm wondering if that's just a harder environment to create one of these in. I feel like standing up an Azure resource or doing some stuff with Azure networking or core web apps, that's a lot easier to spin up like a hands-on keyboard skilling environment with that than like a brand new Microsoft 365 tenant with the right data and stuff to actually do anything meaningful. A couple of things to watch for with this one. I would encourage folks to go and take some of them. I think Microsoft has been overly ambitious maybe in theircategorization of some of these and maybe I'm, I'm, maybe I'm too close to some of it. Like I will fully admit that. So like I went and took the the blob and files one and it's tagged as an intermediate and it's really more like level 100 like hey beginner. Yeah getting hands on with these kinds of things. So that's okay. I think, you know, that gets figured out over time. One of the other kind of thoughts that I had and I saw it pop up a lot in the comments on the tech community post about this one as well was does this dilute the value of certifications like those role-based certs in some way? 'cause you're gonna see folks that are gonna go out much like they do with certifications today where they take like 10 certs. You're gonna see somebody go out and take like 50 applied skilling things and just bang, bang, bang, bang, bang, bang bang, like do them all and all of a sudden you're gonna walk out the other side with having a hundred Microsoft credentials insideof a inside of a week kind of thing. And I've actually seen some of that on LinkedIn already, like a whole bunch of like, hey I did this, I did this, I did this. Like yeah, I, okay, you took a hands-on lab, I got it . Right, all good.Glad that you did it kind of thing. Glad you did it in general. I I like kind of the, the diversity that comes from this like you know, for the folks that need it, I would also potentially look at it as a way for people who are looking at the certifications. Like if you're looking for other ways to get hands-on and validate before you take a cert, potentially good for that as well because I think that's one of the things that often misses in certification land, particularly in like the weird era we're in now where brain dumps and things are accessible and people do do those kinds of things right? Like you know, maybe you have less motivation to do that if you can just go get hands-on in what is today a free way to do it. Like they're free for now I have to imagine these cost money at some point because they are running up services and compute just to get them done. Like you're, you're in a real Azure environment when you're doing it. One last kind of thing to watch for with these is certification still, and I think you're mindful of this, still count towards things like partner requirements and meeting the bar to be in the, the partner network or one of the ISV programs at Microsoft and these credentials from Applied Skilling currently do not apply to things like the partner program. So if you're in say like the cloud partner program and and you're an ISV in there or you're doing kind of the legacy MPN thing and haven't fully rolled over to one of the new partner programs yet, these do not count for, they do not count for that. Well and I don't know if you mentioned this, I didn't realize when you were saying to the assessments that these are also still timed. So if you go in to sign up for one of these assessments. Yeah they are. Yeah it gives you a learning path similar to the certification like for the sim for Sentinel, they have a learning path through Microsoft to learn that they recommend you go through for Sentinel and then the assessment it does say you will have two hours to complete it. So it's not like you can just go in and take this assessment and take your time working your way through it and looking for all the answers and how you do stuff. And again, I haven't taken one yet so I don't fully know what the experience is, but you do have a time limit in order to complete it and I can imagine one, it's maybe to validate that you do know it but to your point also is that they're spinning up resources, they just don't want a bunch of these running for 5, 6, 7 hours if you take a day to complete it. They wanna be able to spin up resources and spin them back down to save on their backend cost for. These over time. I imagine these almost have to cost money and and I think that's even weirder when you try to position them like now where do they sit in the world of, well I already have an Azure environment, like maybe I'm like a visual studio subscriber or I get access to Azure through my employer or M 365, like wherever these things end up baking out. Like if you have access to power automate licensing, like is the credential the important thing or is the hands-on time with it important? I have seen some things, you know on the socials as well about them potentially being a little bit buggy and like timing out kicking you out of the environment and you can't get back in for a couple days so your mileage may vary. Yeah, it's relatively new like this totally came across as kind of like a pre-announcement like hey here's a little bit that we have going on just to give you a tease and you know there should be some more about it at Ignite. Huh? We'll have to watch Ignite and see what comes out. But that is interesting. I'm gonna have to go take at least one of these and see what it's like. You should. Do the power automate one, do one that like you're familiar with, like I said, I I did the blob one, do the power automate one just to see, just to see what you think about the way it's frame framed up or if there's another one in there. I know you've been spending a bunch of time on Sentinel and a couple other things. Yeah I might do Sentinel too. Yeah. But go go in blind like definitely take it blind and see how it goes.Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. Alright Scott, so I have another question for you. Yeah. Have you ever wanted, I don't know if I wanna do that roadmap item, let's do this roadmap item, that roadmap item's a little ranty. This one is a little interesting and I think something that people should be aware of is I saw this one come across and I'm curious to see how it comes to fruition and how it gets rolled out because this is, it's almost going back to something Microsoft used to did used to do. So this was added to the roadmap back on October 24 and starting in November. So I mean it could start already tomorrow from when we're recording, we're recording on the 31st. By the time people hear us this may be well underway. Microsoft is gonna start automatically protecting customers with Microsoft managed conditional access policies. So what it sounds like Microsoft is doing, and we just spent a little time digging through this and looking through what we could find, I cannot find any docs on it like un learned@microsoft.com or any official announcement in tech community or any of that. But Microsoft is going to create and enable a and this, I found this on Twitter, you told me to get off Twitter but I'm still on it and this is where I found it. They're gonna create a Microsoft managed and MFA for admin portals. So forcing MFA for accessing all your admin portals, MFA for per user MFA users. So I think this may be in kind of advance of maybe trying to get away from the per user MFA that's considered legacy at this point in time. And then MFA for high risk sign-ins, which high risk sign-ins is a Azure ADP two feature. Mm-Hmm . So I'm assuming that.It is. They're also gonna look at a. Little bit of upsell in there, right? I'm assuming like maybe they look at your licensing if you don't have any Azure AD premium, maybe they're still doing security defaults and if you have P one you'll get like the first two admin portals and per user MFA and if you have PE two maybe they'll add and enable the MFA for high risk sign-ins. But if you aren't paying attention and someday you randomly go in and you have all these new Microsoft managed conditional access policies or M FFA starts behaving differently in your tenant, this could be what's happening And they do say in the Microsoft 365 roadmap that all eligible tenants will be notified prior to this rollout. So you should get a notification. The other thing I have not seen anything about is like I already have some of these policies or policies that meet this criteria enabled in my tenant. So if you already have these, will Microsoft just not add them? Will they kind of intelligently look at, oh they already have an MFA policy that covers admin portals so we're not going to deploy it. Will they still push it out there but not enable it? If you disable one of these, will they automatically get re-enabled? There's a lot of interesting things because of the effects conditional access can have on your tenant as to how this will actually function going forward. TBD, so there's some, there's some weird language in the roadmap side of things. So it says all eligible tenants will be notified. I'm imagining that like in the back of my head I'm thinking great, you're gonna have to go and watch the message center. Like that's how you're gonna be notified if you are eligible, right? So hopefully they are looking at those licensing components like and figuring that out like the whole ADP one versus P two and and kind of how that manifests. So like makes sense, right? I think they that they should do that but really, really weird. Like what are they gonna consider eligibility here? Is it going to be based on your licensing? Is it gonna be based on some kind of like minimum threshold for licensing? Like not a ton of clarity in how that one, how that one manifests itself. So yeah, especially with kind of the broad coverage right between MFA for admin portal MFA for per user MFA and then like you said the MFA for high risk sign-ins as well. Yeah. And the fact that it technically could start hitting tenants tomorrow and there's no, again, there's no documentation that I could find. The only thing I've found from Microsoft official is the roadmap item. To. Be fair, the roadmap does, item does say you'll be notified, right? I speculatively think that hey, that means you're gonna get a message in the admin center. My concern there is, and and I've seen this time and time again as Microsoft rolls out these new things is people don't read the admin center no matter how many times they've sent you the message, you don't see it there. So I get that's not Microsoft's fault that you know, we as customers aren't following along and that they're doing everything they can to enter into this world of kind of secure by default posture. Like hey really can't fault anybody for that. It would be great to see them do more messaging about how to and more kind of prescriptive guidance about how to stay up to date with these things. Like I would love to see, you know, like a targeted campaign going out to M 365 subscribers, particularly tenant uh, admins or service admins, uh, who are also potentially gonna be going in and looking at those things or the folks who are responsible for change management in an organization just to get them up to speed and help them understand things like best practices for cadence to check the message center. Where do those emails come from to make sure that you know, they're, they're not being black hole someplace in your spam filter or something else. Like, you know, I think Microsoft is really good about telling you like, uh, hey we run this service under these ipss or you know, these are the FQ DNS that you need to potentially whitelist in your firewall for outbound communication. Like you need to be able to go for like M 365 to like this blob storage account to be able to download this thing. They give you all that knowledge in the docs but they don't necessarily give you the other side of it, which is like what should I as a customer be looking out for and how often should I be doing it and what's the right cadence for me to be doing it? All right, so like should I be looking at the message center daily, weekly, monthly, what are the email addresses these come from and how do I make sure that they're not sent into the black hole abyss of a spam filter? Heck, what's the email address you send it to? Like we've talked in the past about like the whole like Azure thing with admins versus COAD admins and how like, you know, service alerts and resource health alerts and things like that come out. Like it's a bit ambiguous about who gets emailed when these things happen and whether the folks getting emailed even have like valid mailboxes, . So,and I'd love to see Microsoft just do a little bit more on that side. Yeah. And the message center in Microsoft 365 since we're talking about this, has gotten a little bit better in terms of email. Like if you go into the preferences you can go customize your view and choose which messages you wanna show or which services you wanna show messages for. And then they do have an email tab where you can receive email notifications to the primary email and it'll tell you which one it is or other email addresses and then choose which emails you want to get emails for major updates. But. You have to go in and do that stuff. But you do have to go in and do it if. Nobody ever tells you to do it, how do you know to do it True? Like it's a, it's a little bit of a chicken egg problem there and over time, like as they've adjusted the message center and they've kind of opened it up to you know, restricting certain admin roles from having access to it and then opening up like specific roles that have access to it for like folks in your change management organization or things like that. Like I don't always know that that next click stop happens of actually communicating like, great, I gave you access now here's what I expect you to do with that access. Yeah. So that everything goes down the happy path. There's also something I've played with this before, I don't use it because it's really just me, but another interesting feature that they do have in the Microsoft 365 message center is planner syncing. So if you do use planner, you have like an IT team that you want watching all of these, while they may not have access to the message center, you can set up planner syncing so that you can sync tasks into planner based on these updates to the message center, assign people, handle them, archive them off, know that somebody's seen them, et cetera, et cetera. Yeah. Then you need to use planer. .That's tough that that's a tough hill to climb. .Is. True. I'd never seen that one that that one's actually, that one's interesting. Yeah. I tried it and again for me it was just too much because I'm the only one that caress about 'em. For me it's just as easy to go into my message center but to your point about how often I don't do it as often as I should. If you are running Microsoft 365, you should absolutely be doing it daily. There's usually at least a handful per day. And then other days, I was just flipping through mine October 26th, they must have gone through and updated a bunch of items. There were 27 updates or messages to the message center on October 26th. It looks like it was maybe seven or eight of the new messages and then they updated like 20 of 'em. Which could be timelines, it could be usually it's just timelines updated. Yeah, a lot of these are just, we updated the rollout timeline of when it's gonna happen. It's going slower than we thought, faster than we thought, et cetera. But absolutely Microsoft 365 message center. If you're not doing it daily, you should be doing it daily if you care or if you just wanna live on the edge, just wait until something random pops up. .Wait until one day you log into your tenant and purple is green and it's all just upside down. Exactly. One other news, Scott, I have another roadmap item but I might get ranty on that one. .Depends. On if you want me to rant. Sure. If. You you wanna rant, you can rant. Or do you wanna actually do news? What are you highlighting over here? We. Can go back to Agile land for a little bit if you want. Let's go back to this one 'cause this one intrigues me and I hadn't seen this one yet. Deploy Bastion. Yes. So, so we've talked about Bastion in the past. I think one of the, one of the friction points with a lot of Azure SKUs is pricing. Like how do you get hands-on with these things with like minimal experience? What's the right way for you to get in and not spend the absolute most money possible upfront? And some services like Bastion can do that they can, they can run away from you a little bit. Like, you know, you've got a bunch of different things going on there. So one of the new things that happened with Bastion is they recently announced a new developer SKU that's available. So it's, it's out in preview, you know, preview comes with restrictions. So it's only in a couple end user acceptance regions that are out there. North central us, west Central us, west Europe and North Europe to kind of go ahead and get started with it. But I didn't see pricing published with it. But it's called out in the doc like the pricing page on like azure.com hasn't been updated with the new SC U yet, but all the docs are out there on Microsoft Docs. So TBD what the cost is but it's gonna be lower cost than anything else that's out there for bastion today. So it's a dku, it's missing a couple things, particularly like scaling, like you're not gonna have any kind of scale out operations in there. You're not gonna have any kind of advanced security features, anything like that. You absolutely are still going to need, you know, bastions for accessing your virtual machines in a vnet. So you still need V nets and virtual machines and the right roles and the right ports and protocols and just all those kinds of things set up and ready to go for you. So I think the big differences with the developer SKU and there's some really interesting differences in here. the developer SKU can't RDP to a Linux machine.But then again neither can the basic SKU of Bastion, which honestly I never realized this and explains a whole lot about the last couple times I've deployed Bastion and have not been able to RDP to my Linux host .Like that makes a whole lot of sense now and it's never told me that in the portal it will not do SSH again or does the basic sku. There's no customization around things like ports. So customizing, import, customizing, inbound ports, anything like that. Funny enough from an authentication side, like we, we should talk in the future about how Microsoft has been doing a bunch of messaging around to like the future of NTLM versus BERROS and things like that. But even though you can only connect to Windows hosts, you can't do any type of curb off end to that. So I, I thought that was kind of interesting. You also don't have the ability to do some of like the advanced security controls like disabling copy paste, anything like that along the way. And then I think I called it out but no scaling either. You can't also connect to VMs that are across peered fee nets. So you can do that with both the basic and standard SKUs. So like I said, uh, TBD to see where pricing falls for this one. But in general like I really do like to see these kinds of things come up because the less friction and less cost you put in place of getting hands-on with these types of services, ultimately the broader deployment you can kind of drive downstream. I think it is a really nice like carrot to hang out there and get customers comfortable with it and say they just get comfortable with it through the portal or whatever and then they're ready to move on to you know, PowerShell for deployment or arm templates, things like that because it's just a skew of bastion. It's not like a whole net new resource provider or anything like that. Like it's kind of immaterial and and trivial to go ahead and do things like move from the portal to a deployment script using PowerShell or the CLI bicep arm templates, any kinds of those, any kinds of those things. Interesting enough you can also upgrade from the developer SKU to the basic or standard tiers. So that's very nice to see as well. Like you can start, you can get started with it, maybe you find there's some friction or a limitation there and now that you're comfortable with the service you just want to go ahead and upgrade and get yourself to where you need to be. But it's really just bastion with a lower cost and a lower set of features that are associated with, like I said like all the other prerequisites, they all stay the same. Like need to make sure you have enough address space, need to make sure you've got a vnet with uh, a subnet with enough address space for that bastion host. You know you gotta be using standard port, standard protocols, all those kinds of things. Yes, I like this one as well 'cause I think you talk about getting familiar with it but I also see this as a way for you to better secure your infrastructure. It helps maybe Microsoft from a security standpoint because if you ever wanna have some fun turn on a VM you don't care about, you're too cheap or you don't want to deploy Bastion. So you just leave port 33 89 open to the internet and don't bother like limiting it to just your IP address or something and watch how long it takes for that server to start getting uh, hammered with people trying to log into it remotely. It's incredible. So by turning on something like Bastion two, you reduce that risk, make it a little bit more secure from that remote access standpoint. And a lot of these already servers are already ping into, tend to be kind of in line with the developer skew. They tend to be to be developers that need ARDP into a server to deploy something, to set something up. So having a lower cost skew to just get Bastion going and have some additional security around that remote access to VMs for your developers is going to be a nice option because Bastion does add up quickly. It's one of those services that you look at the pricing and you don't think it's a big deal, right? It's 19 cents per hour for the basic 29 cents for standard, but then you start reading all the fine print that it is billed hourly from the moment it's deployed until the is deleted. So if you're turning this on for unlimited access to your vm, it's 19 cents an hour per hour every day you're paying $4 and 50 cents a day times what? 30 ish days? It adds up to $135 a month or so for Bastion unless you're actually going in and creating it and deleting it every time you need to access the server. I wanna see where the pricing lands for this one because even the developer sku, at least from the documentation side, is still gonna be priced at the, that per hour price. That way per hour. Pricing. So you know, if it comes in at 15 cents versus 19 cents, I don't think that's a material thing that's gonna move, move the needle. We'll see how low it can go given it doesn't have any needs for auto scale or anything like that. If I was to guess, even looking at like standard basic, it's a 10 cents per hour. If they could get it down to like nine or 10 cents per hour, kind of half the cost or literally move it down, I would love to see that where it's in the ballpark of like 60, $65 per month. I wonder if I go deploy one and just crank it up like I see if it shows up in cost management or something. Who knows if the meters are rolled out yet. We'll see. , I like that one. I'm going to maybe go turn that on too.'cause I have used Standard, I've used that quite a bit for different VMs that I deploy. I use Bash in a bunch of places and I feel like every time I use it, like I'm compelled to tear it down because of the price. 'cause lots of the things I'm doing are dev test scenarios. I get that automation's there. But realistically like if I'm doing something to play around for a couple weeks, like it's way easier for me to just keep it on and just pay the cost of it and it would be way nicer if that cost was less. You do better than me. I'm even cheaper. I just don't deploy it and I go modify my NSG to only allow RDP access from my IP address. There are places that I have to deploy it like I'm compelled by policy. You must. Fair enough. Alright, well that maybe does it for the news for today. I think I've got stuff to go do that is Halloween today and I have pork to pull for dinner and stuff to set up outside because we are in Florida and we just hang out outside all evening ,unlike those northerners that I talked to up in Chicago in Michigan today where it just snowing up there. It's. Gonna be another balmy 80 degree Thanksgiving here in Jacksonville, Florida. So. Halloween Thanksgiving's a few weeks away. Yeah. Halloween, Thanksgiving, they, they all, they all blend together after a while. One of those holidays, the fall holidays turns. Out they're both events where uh, people get dressed up and just eat a bunch of candy in the United States. So it's. True. I would argue though the Thanksgiving food is way better in the us It. Is. I'm in it for all the pies for dessert. Oh yes, absolutely. I need to go see which houses have good candy that I need to go trick or treating with my kids and grab some or bribe them to get me some extra. Yours are still young enough to do it. All right, well I'll let you go. Enjoy your Halloween. Thanks and we'll chat again. Alright. Enjoy your uh, Halloween as well and we'll talk again soon. Thanks. Ben. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 359 – Microsoft Applied Skills and Azure Bastion Developer SKU
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 39:46 — 27.3MB)
In Episode 359, Ben and Scott discuss Microsoft Applied Skills – a new skilling platform for Microsoft customers to get hands-on in a live, on-demand lab environment to validate their skills in a specific area and how Applied Skills compares to the existing role-based certification exams. Next up, it’s a quick review of an upcoming roadmap item that impacts Microsoft-managed conditional access policies and how to monitor and keep up to date with Message Center messages that are applicable to your tenant. Then it’s time to wrap up with a Developer SKU that was recently launched for Azure Bastion, offering lower cost to Bastion at the expense of some of the bells and whistles in the Basic and Standard SKUs.
Like what you hear and want to support the show? Check out our membership options. (more…)
Buy us a Coffee
Name
FirstLast
Product Name
Small - $2.00Medium - $3.50Large - $5.00
Total
Payment Method
PayPal CheckoutCredit Card
MasterCard
Visa
Supported Credit Cards: MasterCard, Visa
Credit Card Number
expiration-monthexpiration-yearcvv
Card Number Expiration Date
Expiration Date CVV
Security CodeCardholder Name
×
Contact Us
Contact Us
Contact Form
Name
This field is for validation purposes and should be left unchanged.
First Name
Question or Comment
Add me to the mailing list
Signup to be notified when new podcasts are published, participate in listener surveys and give input into future episodes!
Sign me up!!
This field is hidden when viewing the form
Tags
Checking your Browser…
Verify you are human
Verifying...
Stuck? Troubleshoot
Success!
Verification failed
Verification expired
Verification expired
×
Microsoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM Wikis
Microsoft Cloud IT Pro PodcastMicrosoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM WikisEpisode 429: Getting started with LLM Wikis
More
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
More
more
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
Currently Playing
More
Notifications
PayPal