Episode 357 – Community galleries for Azure Compute Gallery
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Oct 26, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 357 of the Microsoft Cloud IT Pro podcast recorded live on October 16th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and how it relates to you today. Ben and Scott run through the recently announced community gallery capability that has been added to the Azure Compute Gallery service. We also spend a little time talking about the table level RAC read access control for log analytics workspace. Scott, you've had questions for me in the past. I have a question for you this morning. It kind of ties into. Tables are turning. I'm. Okay. Tables are turning. We were talking before we started recording and you made a comment about you need to find more time to use your green egg in your Blackstone to grill .And it tied into an article I saw this morning about a survey of workers that would take pay cuts for these top tier perks and the biggest perks. I'm curious what you think about these. This survey found that most workers would take some kind of a pay cut for a four day work week consisting of four eight hour days pay cut of 16 to 20%. So essentially you're giving up a day's salary, right? 20% for four days of work. Large number of workers would also take a pay cut from our vacation time. Same thing. 16 20% doesn't say how much more vacation time And then fully remote workers was obviously one of the top ones. 61% of people saying they would take a pay cut for remote work. I think those were the big three more vacation, four hour workday remote work. I'm curious, some people were like, I would know that wasn't a pay cut one. Curious your thoughts. Would you take a pay cut for any of those? Not that your employee could listen or should do it for. More vacation? No, I think generally the thing to do is like when you're walking into a new position is know your worth and negotiate for it. Right? That's my thought. Even. Companies with very fixed policies, I think there's ways to come to agreement there. Like you might land in a band say with two weeks of vacation, but really you need like, you need three and that's what you're used to and what you've had in the past. And I've run into that from some places like having worked overseas where you just end up naturally with more in a vacation time. Another interesting one is I've worked at a bunch of law firms and law firms tend to have pretty generous vacation policies, like three to four weeks. Interesting. For all employees regardless of level. So I got used to that pretty early on in my career by doing some of that stuff. Like working with law firms where I was like, Ooh, I just need three weeks .And now at Microsoft we do the DTO thing, discretionary time off, which is effectively unlimited time off but you know, you have to get, still get your manager's approval and things like that. So no, I I don't think vacation time is one that would be worth taking it for remote work. Yeah, absolutely. What you do, if you are, if you think about it, if you're grinding away for say like half an hour to an hour of commute one way each day, that's gonna be your eight hours right there anyway . So,so just take the, take the pay cut and do it. You were already putting the time in. It is what it is. And generally you do come out ahead in those deals just with the savings on mileage wear and tear gas. You might up some more things at home. You might find that you go absolutely crazy and end up with like microphones and fancy webcams, and all the other stuff. But I,I think it all course fills the gap pretty decently. The 40 workweek one is interesting. I would not want to do 32 hours I think for a 20% pay cut. I would rather do 40 hours like we tend to do a standard in in the United States, but just let me do my 40 hours in four days in four days and then I'm done. I can still do the same things and I'll arguably have the same if not more output. So just let me, let me do that and float through. Right. Especially I can see the four and 40, especially if you're combining that with the remote work because if you're doing eight to five and you're just doing a quick lunch that's already nine hours. Lunch. What's lunch .Exactly. I. Don't, I don't get lunches anyway so it it, yeah it's. The snacks sitting on my desk here. So I have mixed feelings about remote work and if that should be a pay cut. So I've always had this theory too if you're going into the office, how much money is the company actually spending for you to be in the office because they're paying for the real estate, the electricity, the office supplies. There may be a lot of office supplies that you actually get if you're in the office in terms of chairs and desks and all of that. Should you actually be getting a pay cut if you're working remotely or should the company actually be investing some of that money back into you for you to provide some of that stuff as you're working remotely? Pick. The company. ,there's lots of companies even today with the whole rigmarole about returned office RRTO and all that stuff that are carrying large chunks of their books in commercial real estate. I think it's hard to make that flip. If you went to a company today and that company didn't have offices and they said, oh, but we pay 20% less, that smells a little fishy. But if they have a bunch of offices other places and they go, well we let some people come into the office and they make this much and they let some people stay from home, like there's trade-offs there. I think that's a negotiation that you can potentially like rationalize your way through as a remote work from home employee. I would take that trail. I don't know that I could go back to an office, let's put it that way. If somebody came and said you have to go back to an office or take a 20% pay cut, I would take a 20% pay cut, I think. Take the pay cut and stay at home. I'm not gonna sell my house and move someplace else and do all those things. And I also get what you're saying about long commutes. Like if, to your point, if you're driving an hour a day spending X number of dollars on gas and oil changes and maintenance on your car or whatever those additional expenses are that do come with commuting, just even from a time perspective, there is something to be said for that too. But I'm with you. I don't know that I could ever go into an office. I. Don't, I don't know that people always think about it that way. like and you have to have, I I think it helps.Like I've worked places where I've had to do the long commute thing. Like when I lived in outside Washington DC when I had to go down into the district for customers, Uhhuh ,that was a two hour one way commute. There were some days where it was taking me three hours to go one way just because of traffic timing for things like I lived 35 miles outside of dc which meant that for me to get down into the district, like you can't drive on the hve lanes as a single driver in the morning. So you had to find it potentially a different way to get in, but you didn't want to drive in all the way to the district and have to deal with the traffic actually down there. So I would drive my car to a park and ride. I would go from the park and ride to the train and then I would take the train to where I need to be and maybe catch another bus, right? If there wasn't a train that got you within a walkable distance of the place that you were going. So it was a little ridiculous sometimes. And I would get home at eight at night , what did I do?. Yeah.So in cases like that, it's a totally worthwhile trade off and it's not a trade off that everybody can make, but if you can make it, I think it's, yeah, it's worthwhile doing. Like it is a quality of life thing. It. Was interesting, there was just an interesting survey and I'd say we'd post a link to it but it was on the Jacksonville Business Journal and it's a paid link so if we post a link you can't really get to it anyways. ,it was interesting just to see what some of those top things were. That and the four, I'm with you, the four day, eight hours a day surprised me. It was like, so people just wanna work 32 hours instead of 40 hours. There. Are people that do that. So I've definitely worked in organizations and and come across folks that do those kinds of things. Uh, we did a, I attended maybe last year and a half ago a seminar that was put on by one of our more junior employees who decided to take that trade off like totally negotiated down and said you are gonna do 32 hours a week and that's it. And for a whole bunch of reasons, right? They're just like work life balance, mental health, this is a better model for me kind of thing. Uhhuh, and there's a lot of that in there.Like everybody is situationally different. Like not everybody is built to do 40 hours of continuous context switching the entire time. So I can I get that respect it, know what you want, go for it and grab it if it's an option. That was my question for the day outside of, and I also saw an article in there about mansions for sale in Jacksonville, but we don't need to talk about $25 million mansions in Jacksonville .No. No, no we don't. So news, there's a few news things. We were just talking before this too. News feels like it's slowed down, but Ignite is now one month away I think ish give. Or take. Yes. From one we're recording this. We're about, we're we're about a month and a week away, so maybe just about five. Weeks. By the time people hear this it'll be like two, two and a half weeks away. But. Something like that. Yeah. As a result Microsoft has said we announce news as it comes up now and we've definitely seen a lot more news come out, but it is also very apparent that once you would get within a month of ignite, the news kinda slows down and Microsoft is definitely holding some stuff back to announce that Ignite in a month. So there's a few things that have trickled out that we figured we'd talk about today. So do you wanna take the first? Yeah, what do you wanna start with? I don't know. You have a tab highlighted here in the browser. Do you wanna start with the, the one you're on? This was an interesting one that I did not see. Let's start with sharing images using community galleries like. Pictures, right? ., yeah sort of I guess maybe if we consider A-V-H-D-A picture,do we consider V HD's pictures? A vhd is a picture of a virtual machine. They certainly tell a story. No. So in Azure there has been this thing kicking around for a while now, which is the Azure Compute Gallery. So for a long time you've been able to take a virtual machine in Azure or even potentially like a virtual machine from your, from another environment. Not the best idea. But typically we'd start with an Azure one just for the best experience. But you can take those images and you can customize them. So say it's like a Windows image and you want to cis prep that image, take it back to an out of the box experience for running it through. You maybe wanna lay down your own bits on top of it just to give you an accelerator, like whatever it is. So you've had the ability for a long time to take those images and let start it out as oh just grab AVHD, then you would create like an image your next VM from that VHD that's a pain. And then they introduce this thing called a commute gallery. So effectively take your images and have your images with things like versioning associated with them. So okay great. I've got my golden image for Windows server 2022, I've got my golden image for my Ubuntu 20.0 0.4 LTS version that I run in my environment, Myre, whatever it happens to be. Take those and then be able to like version them as you patch them, update your applications, all those kinds of things. Compute galleries have traditionally been private. So there's been like the Azure marketplace, hey go out to the marketplace from an official publisher, be it Microsoft or one of the other vendors that's in the marketplace that's been vetted by Microsoft and grab your VDS from there or your images that you spin up. So a third party example would be something like Kemp, like you wanna spin up a load balancer from Kemp, you need like a NetScaler, that kind of thing. Great, you can go spin those up and those are vendor supported images from those companies And now there's a new flavor that's kicking around which within the community gallery now you can or so within the compute gallery, Azure Compute Gallery, you can now have private galleries which is traditionally what you've had. And you can also have a community gallery and community galleries are interesting. So private galleries as they've existed you could do rback sharing within your tenant. You could also do a what was known as a direct shared gallery potentially over to other users within your tenancy, other subscriptions, things like that. But generally like your tenant, your Azure ad intra ID tenant was a boundary for you for identity. So you couldn't really share those things publicly with other Azure users if you wanted to do that. Let's say you didn't, I don't know, you didn't meet the bar to go into the public marketplace, you just didn't even know it was the thing. You didn't wanna deal with it. Like you could just spin up one of these community galleries Now because what community galleries allow you to do is you can still do rback. So you can still do things like your share your images using world based access control to a service principle, anything like that. People, groups, whatever it happens to be. But it's not locked down to a specific tenant. So a community gallery lets you break the boundary of a single tenant and get out there to more of the marketplace or you can just share things publicly. You can say hey I've got this community image and I want to push it out for everyone out there to be able to see and get hands on with. So it's another mechanism or another way for publishers to share things potentially outside of the Azure marketplace. And that's got like pros and cons to it. I think as consumers of images, like we need to be pretty careful there 'cause now there's maybe some additional vetting or things that you'll want to have in place. 'cause like marketplace images are certified, they go through a certification process both for Microsoft images and like Microsoft as the vendor who's publishing them or you know Kemp, Citrix NetScaler, all those kinds of things. Those all go through a certification process. They're all good. Vetted, verify, run 'em with your production workloads. You can do that with confidence, they'll be supported. There's a slew of first party, third party images, like all the, all that stuff just is there. But I think the biggest thing is they are supported. is probably the biggest thing. Uh, for marketplace images,community images, there's a certain degree of trust that you're going to have with the publisher. 'cause like you or I could just go create a community gallery today and spin up an image and put it out there. So you're trusting that A, we know what we're doing when we build that image. B we are licensed to build and distribute that image. Like there could be software licensing or other things that come into play there. So this is really good for open source stuff potentially depending on the license associated with that. I don't know how well or how much it gets used for commercial stuff. It's also great for testing. Like I could see like a bunch of marketplace vendors potentially using this as a path to test their images and get them out there. There's no like billing model, anything like that. Community images are just free. So it really is like a, I think like an apple like test flight kind of thing. Like it is very test kind of thing. And then that support angle is a rough one I think in that images published through a community gallery are supported by the owner of the image. So who's the person who made the image that is who is ultimately responsible for support on top of that thing. And Microsoft calls this out in the documentation. Okay, like this is potentially an area you could be interested in, but if you are a consumer of community gallery images, like you're not just a publisher but you're also using them in your environment. Like you should exercise a degree of caution there becauseyou really do have more work to do. Like you have to go verify the source again, there's no like certification scanning, anything like that that happens on the way. Like there could be malware in these things. Like it's really on you to go and figure it out and, and there's mechanisms for folks to report nefarious images to Microsoft. Like all that stuff's in place but it doesn't stop it from getting out there as quickly the way it might do in something like the regular Azure marketplace. Yeah. I was just looking through it. So if you go out to Azure and you browse for resources, you can go look up and I'm, I think these are all community galleries. You can go look for the community images in Azure and just start browsing through them. So in community images right now there are 4,600 images and you're right, you don't know what any of them are. So one of them in here is from some guy named Pete and the gallery is Pete Specialized and it's a Windows 11 and they have AURLfor the publisher's website, which just goes to his public blog. It's Peter and it's a software engineer's log book. But to your point, it's what is actually in this Windows 11 specialized image. Because one thing I don't see on any of these is for all of these community images, they have a name location, architecture publisher, but there's no description on any of these. I don't even see a description field where someone could go in and specify what this image actually is or what's contained in it or why I might want to use it. And I'm wondering if. It's a little rough. So if you go look at the way to deploy from a community image today, uh, lots of the examples like they, they start right off with CLI and and and rest even over the, the portal deployment experience. But if, if you dig down in and you go, okay, hey let's look and see how you deploy this in the CLI, it's effectively do discovery, go out and list the images that are available, list the community images that are available. Funny enough, not a global resource, right? This is still a a regional service. So go out and list the community images that exist in this region. Show me all the community images in east US in North Europe, like whatever happens to be where you're deploying. Once you have that, the resource ID to that image. So,so effectively the string, here's the gallery name and the GUI associated with that image. All that stuff all the way down to the version that becomes like what you pass into a VM creed command to get things, get things spun up and get them running. So yeah, it's new thing that's out there. I, I'd be interested to see what the uptick on it is and if you do see like MSRC reports on these over time of, I, I could totally see a vendor coming in and doing something like a, a bad actor vendors maybe a bad choice word. A bad actor comes in and you know, slams a bunch of images into 60 regions or you've gotta play like whack-a-mole trying to figure out like which region which bad actor is in and and where they've published in images, things like that. There's more vetting for you to do as a customer here. Like you really do have to trust where these things come from because say you're using like a virtual machine scale set and we're doing like VMSS and we're scaling things out. The way you're gonna do this is community images aren't just like a, it's like a docker image in that it's got like a version associated with it. So yeah like if the docker image, you might always do like docker on image name and then a tag of latest like always give me the latest one every time I run this. You can do the same kinds of things and you'll see that if you dig into the resource U MRIs and the image definition ur urs in that you're actually pointing down to version and version could just be like latest it could be a tag and the next VMSS instance that you bring up could potentially be running something different than the rest of it. There could have been something bad that happened along the way. Whatever ear mileage may vary. Yes, I'm having fun going through here and just going, HP has some stuff out here. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft cloud technology, visit them at intelligent.com/podcast. That's I-N-T-E-L-L-I-G-I-N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So there's some good stuff. There's some an HP HPE ES morale software documentation. So they have an image out there for their ESM morale. I don't even know what it is but they have some images out there for that. It looks like it's primarily different vendors that have built their services, bundled them into a VM and pushed 'em out there. But then you do have these random ones like Pete's specialized VM image, huh. It will be interesting to see the uptake too. And I feel like at some point in time you need better sorting or maybe you don't necessarily go to the community image to find it but if you have a specific vendor that you buy software from that you're using it from, it gives them an option to put it out there and maybe trust them to point you to the right image. It's an interesting model of how do you figure out if there's something out there you wanna use. I would almost wanna see it where you could browse by publisher and that's a little hard to do maybe today like it, it'd even be nice if you could just maybe browse by like publisher URI. So there's a couple extra fields if you load one of these up. Say you push the community image out there and and you sort of see the metadata associated with it. So there's name of the resource that makes sense, what location does it live in? What's its architecture X 86, X 64, that kind of thing. But there's also a publisher URI and a legal agreement URL. So if you go look today, like there's a bunch of stuff even that appears to be published by Microsoft where like they've just skipped those fields. and publishing URI is ww www.example.comkind of thing. If you go out and browse it, I don't know if you were noticed but like all the by default it's sorted by the public gallery name. Yep. So a bunch of stuff that shows up there is for actual like Microsoft services, there's a ton of AKS images that just fill up the first couple of screens, like different versions of Ubuntu running different versions of container DA FIPs compliant container D and then they have all like the permutations of that. So you see each image like published globally. So okay there's one image but rather than being in one one region it's in 60 regions .Yes And just pushed all over the place to prevent egress charges from eating up too much and things like that. But there's tons of just variants of different things out there. Yeah, you'd have to go through the list and see and I imagine most of this would be like very much like a test flight ish kind of thing. Like a vendor comes to you and says hey here's the image definition URI so that you don't have to go searching for it this way. Yeah because even like the way it is today, like grouping by like the public gallery name and things like that, like it's a messy way to get in there and view things a. Hundred percent. So definitely has potential I I agree it needs some work to be able to sort filter, make it usable. If you wanna start in community images versus a vendor telling you hey we have all these community images out here. Here's our public gallery name or here's the link like you said directly to that image we have published for you. If you want, if you're up in the portal. So something you can do is in the upper right if you're in the list view, go click on the list view and change over to the summary view and then do something like summarize by location. We'll show you a map and the number of deployed images out at out at each location. But you can then go in, there's a summary view for a gallery name and you can just say hey show me like the top 10 publishers in the gallery. Things like that. Hey. Scott, did you try clicking on the summary view by location and then actually clicking on a location? I did not click on a location. I mean they came up Oh yeah. , they're, they're still working on that. They're.Broken some underlying APII think. Yeah that was my first one. I'm like oh it's deployed in East US two and I got an error. So it's not just me , that's a, it's interesting.Maybe we should create a podcast gallery Scott of all of our VMs of nothing 'cause I don't have that many customized ones. I've done a few for like dev box and AVD where I've done some gold images but nothing that I don't know that I'm pushing any public galleries anytime soon. I'd be super scared to publish most stuff. Like I think you'd have to be a little bit of illegal eagle to get some of that out there, right? Like I would not want to publish a Windows 11 image. Lemme put it that way for Pete's special image gallery over there. That doesn't seem . Something could be off there. Well.But you'd still have to license it, right? So it's not on you to necessarily license the OSS or from a legally standpoint in terms of somebody doing something on your image and it somehow coming back on you. You. Just don't know. So in my mind, let's put it this way, like given the choice between going and getting like an Ubuntu image from the marketplace, Azure marketplace, okay that that certified scanned publicly verifiable thing versus a community gallery. I'm either gonna go to the marketplace or I'm gonna build my own. That's it. I'm not gonna go to the community gallery and deal with deal with that kind of thing. Especially for a base image in my head it would be like, ooh, base images marketplace, great, we can get those And then if whatever you need in a base image isn't there in a base image like what's my overhead to add it and maintain it, I bet that's gonna be like right in line if not lower than dealing with something from a community gallery. Yeah. And then I, I would think a lot of the community gallery over time turns into probably what it looks like the AKS team is doing where there are a bunch of like test images and variants and things like that that you can go out and run with. So if I'm Citrix and I'm publishing NetScalers out, I might have my marketplace images for NetScalers and then maybe I have an entire test bed set of images that I can let customers get on like early days for a new release to go vet something. Yeah, I think that's where I'd see a lot of benefits to it 'cause looking through it, I did see a couple, let's see if these come back up. Yeah there's some here that you have nightly builds net service who are these by edgeless systems has something out there. I don't know what they do. Any cloud always encrypted open source solutions for confidential computing. But if you go look for like nightly you will see some of these images where there's nightly builds of stuff or dev builds or beta builds and I agree with you there where if you have some of those production workloads and you do wanna have give customers the option to go test on a nightly build or a lab build or something like that, this could be a good place for it. But again I think then you're coming through the vendor's website. You're not necessarily out here browsing for edgeless systems nightly builds because. .I don't know why. Yeah. So fascinating. More services see where it goes. But with that I have meetings coming up Scott we have some more topics. Yeah we have more topics but we might have to punt those for next week unless you had another quick one you wanted to talk through. So we're talking galleries and rback and sharing and things like that. So one that crossed my radar, we've talked a bunch about log analytics and custo and things like that in the past table level AC in custo clusters. Have you seen this one out there and kicking about. You sent this one to me a few weeks ago 'cause we were talking about it from a sentinel deployment perspective of what if I want to have a log analytics workspace and layer sentinel on it but I don't necessarily want everybody to have access to everything in my log analytics where maybe those users using Sentinel doing it for those SIM workloads need access to the entire log analytics workspace. But my app developers only need access to certain data in there like the app services they're working on where they're using it for app insights or something like that. And it was how do you secure your logs if you're using a single instance of log analytics for these different workloads? And you sent this to me when we were talking about that 'cause up in before I had not seen this one. Yeah. So this is a capability that is in preview uh, as far as being able to use like Azure R back in this manner. Yep. TLDR is you end up with a log analytics workspace where you're gonna create some some new roles around that log analytics workspace. So you're gonna have a new role at the workspace level like all up here's my deployed resource and all the tables within it and what that role does, it's a kinda limited permission role that has access to read workspace details and it has the ability to run a query but it does not have the ability to read any data from any tables in there. So that kind of gives you the ability to go in and see hey what's out there But then if you actually wanna run against it, you need additional permissions to get at it And then you have a table level role which effectively becomes a reader role and those are just scoped down at the table level to let folks in on that side. So in combination like when you have both the roles and they both line up the right way, then you get this magical super set where not only can you see the table and you have the ability to run queries but now you have the additional grant and additional permission to be able to execute a query, uh I guess execute a query, read data out of the table. Yeah. It's. Weird because the permission is like workspaces slash query slash read and it's really, it should be like WordSpace slash query slash execute and read or whatever it happens to be, something like that.But because these are are back rolls, you can do things like action have a not action. So you could say like for this user they're not allowed to do this thing on this table, anything like that up and down. So it's pretty familiar once you know what the roles are that are out there. So that customer role that you created at the top and then the reader role for each table, it's just going ahead and applying RAC at that point to get it out there. So I've been having to play around with it like it's pretty seamless like I mean it's, it really does just bring your scope for RAC down to a lower level down to that table level within a log analytics resource. So there still might be some weird things in there like you mentioned like Sentinel is one of those things that really should have access to all the tables that are out there. So you need to think your way through that one and what that looks like and maybe even like where users execute queries from, do they execute them from Sentinel which is running on say like a managed identity and it has access to everything or do you give them access to the log analytics workspace where then they're coming in as their user principle and all that kind of stuff to get to where they need to be. And it. Also looks like you talked about permissions but it also has a couple different access control modes. Going back to kind of the example that I had talked about where you can set workspace permissions where it doesn't allow granular RAC and you essentially have access to everything but they also have a user or a user resource or workspace permissions where it's not even going and it looks like and setting it up the table. But if you use that control mode you can do granular RAC granted based on the resource they can view versus just a let's go set it on this table or this table and going down that route. This. Will be the new mode going forward. I I like my sense is once this GA is that the old way of table level access and the reason I say it's probably gonna go away is 'cause they started calling it the legacy method of setting table levelread. That's usually a good hint. That's my hint that at some point like when this capability GA's they'll get away from the old way of doing it. 'cause the old way of doing it was still Azure identity driven but you were doing a ton with custom roles at the end in in that one and you really had to get like super granular in your definitions of those roles to get them to where they needed to be and really get 'em like dialed in. So this is potentially a little bit easier there. There might be trade-offs in granularity or things like that. Like we'll see if they even introduce like additional additional levels in there. Do you get to the point where there is say like a query versus a read versus an update kind of RAC thing that you can push in at a table level? You know, who knows? We'll see if it gets there. Got it. So that table level, I'm reading this article more, the access control mode is that differentiation has been around for a couple years now. Since 2019. It's just the table level RAC stuff that's in preview that's brand new. I. Think it's confusing though 'cause technically like when I go look at the old stuff, the old table level of access was also RAC. Like it was all based on on it. Was still got it Azure. Roles and application of those roles to an identity, those kinds of things. So I think this is bringing more clarity to what are the permissions within those roles and potentially like rationalizing, make that management a little bit easier. Yeah, I found it. This is the one disadvantaged to shared tab. Scott, I can't see where you are. The set table level read access versus the legacy set table read access in this article. Huh? It's a confusing one but kicking out there in preview. It's been in preview for I think like a month or two now, like a little hot minute. So hopefully not too much longer. And then that one GA's sounds. Good. I need to go look at this one some more too. This one's on my list, Scott, my never ending list. This one makes it there. There we go. Added to the list. All right, success. Sounds good. Well I have a meeting now in three minutes. So with that we will wrap it up on this Monday morning and get to our work week a meeting and then we have to go renew some Azure certs because they're expiring. Yep, sounds like a plan. Alright. . Well thanks Scott.Enjoy the rest of your day week and I'm sure we will talk to you a little later this week. All. Right, thanks Ben. Yep. bye-Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 357 – Community galleries for Azure Compute Gallery
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 36:56 — 25.4MB)
Subscribe: Spotify | Amazon Music | Pandora | iHeartRadio | Email | RSS
In Episode 357, Ben and Scott run through the recently announced Community gallery capability that has been added to the Azure Compute Gallery service. They also take a few minutes to discuss the public preview of table-level RBAC read-access controls for your Log Analytics workspaces.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 351 – Rock me like a hurricane… or Python in Excel
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Sep 14, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 351 of the Microsoft Cloud IT Pro podcast recorded live on August 30th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss the topic where recent news and how it relates to you. It's hurricane time or Python time, or maybe the hurricane is bringing pythons. This week, Scott and Ben catch up on some of the latest news around power automate Microsoft Enterra and Microsoft Excel while they look out their windows. Watching Hurricane Adalia whipping the tree branches around. Was a dark and stormy morning. Yeah, we're back to hurricane season. Yeah. Which means we get to sit here and record and watch the trees gently swaying in the breeze. Yeah. I keep turning around like this. It's 'cause it's gusting. We're like, whoosh. You're looking whoosh. See, I have mine right out here. Coming through the backyard, so we'll see how it goes. I don't have to completely look that way. I just look out my window here right now. It's really still. But yes, I'm the same way watching the gusts. Every once in a while the trees start madly dancing in the wind. Oh, look at you. You, you've been playing with chat G b T and poetry haven't you? Yeah, no, I should . I should have Ja chat.G p t write a poetry script for the podcast. Yeah, I dunno. We have not, I don't know about you. We haven't gotten much rain. It's supposed to be windy later today as it gets a little closer to us, we're supposed to get 60 mile an hour winds, but really no rain, which I'm disappointed in because I'm cheap and I don't wanna pay for water to fill up the pool and we're not getting enough rain to fill the pool back up. Yeah, well. It's a hard life, but. Yeah. Yeah. We'll see how this one's going. Folks on the Gulf Coast are getting it like they're, we're we're into, we're into landfall time right now, so I I was watching the news before we hopped on, but once again Jacksonville gets cleared out so. You know who didn't though? This was interesting. I was talking to somebody and they were like, I don't know if this has ever happened before, that Valdosta, Georgia has a hurricane warning because of where it was coming in through the armpit of Florida. There there's like very little land between the ocean and Georgia. So it was like just blowing right through Florida and it was still gonna be a hurricane when it got up into Georgia. Yeah. Yeah. It, it, it happens. It was something climate change is real Y'all like maybe when your insurance company has started upping the prices, we should have all gotten the gotten the idea. We're.Just dropping you because they didn't want to insure your zip code anymore. There. There's that too. Not that ever happened to me and I'm bitter about it. Yeah, I need coffee. It was a long ways away. .Okay then. All right, you got coffee? I've got coffee. Let's go ahead. You've. Got news. Get into it. Where do you wanna start today? Where do you wanna I I don't have my articles up. Just a minute. Browser. I was getting my coffee. Where should we start today? I can guide you in or you go ahead and pick one. No, you're all set. It's your show. Pick one. Oh, let's pick one. Let's pick the integration of power automate telemetry data with Azure application insights. You. Went the other way. I didn't think you were gonna go that. Way. You didn't think I was gonna go this way? This one's your exciting one, huh? I don't know if this was exciting. This one's a little older. How's that? This one is like a week old at this point in time. Yeah. Sorry I messed y'all up. I'm jumping all over the place today. I don't think there's not a ton with this one. This one an announcement back last Thursday on August 24th that you can now go into your power automate and go set up certain data to come out of power automate into application insights. So this can some things like cloud or cloud flow runs and power automate. I still think they need to call 'em automation since they name changed the name of it. Because anyways triggers action level data from an environment to app Insights and it's really just like a click, click Next you go through export to application insights, select what you wanna export and then power automate. And it's really those three categories and it just shoves it all into insights for you into log analytics so you can go look through it. You can also take multiple environments into a single instance. So I know I have some companies that have multiple instances. It'll be interesting to see how much data eventually gets added. Like one of my peeves with Power Automate is I will get, I've built some very complex flows for certain customers and when something goes wrong or something errors out, it says failed in the run history. But if you have these flows that are running like a hundred, 200, 300 times a day and they only load 10 instances or 20, I can't remember how many it is, but it's like the last 20 runs in the UI and then you have to scroll and it's like the whole continuous scroll. Then you wait for the next 20 to load and then you scroll and wait for the next 20 to load. It's not very easy to dive through. Power automate runs to view things like which actions are flowing and when they flow and try to dive through the details of what actually happened or even going and looking at a historical one that may be completed but didn't do what it was supposed to because that happens too where it doesn't actually air out but it doesn't work correctly. Having some additional data to be able to pull out of these power automate flows and really analyze the data and analyze these different actions and what happened with them would be very helpful. I don't know that this is there yet, but hopefully this is a step in ingesting those logs into someplace where it's a little bit easier to query them, dig through them, see what's going on within your power automate environment. Yeah. So nifty a little bit maybe limiting in its first iteration, but that's okay. It's in preview. I should have called that out just to reiterate like preview not for production, blah blah blah. So maybe it gets better. So there's probably some things for folks to watch out here. Four if they've never done done App insights before. So App Insights is like you mentioned, it's its own little service that sits on its side and takes a pretty heavy dependency on yield log analytics and log analytics workspaces. I think Aveta like a wrapper layer on top of log analytics that gives you ultimately a way to interact with the data in the background in your app. Insights in the same way that you would with the log analytics workspace. It's our old friend Custo, again sitting there ready to go. But I, I think a couple of cool things that happen along the way here, like even with the limitations, like you mentioned, there's only a couple different types of telemetry you can catch. It's not like you can put like a custom event in your power app that's then writing to that login analytics workspace. Unless you wanna wire that all up yourself. There's no built in nicety for that. But once it's all there, now you've got all of the requests for your cloud flow runs and then all of your cloud flow triggers and cloud flow actions that you mentioned. Uh, they also land in a dedicated table as well for dependencies. So once all this stuff is sitting there and it's ready to go, then you can start getting nifty with it because there's other things that you can start to do. What if you wanted to create a an an alert through App Insights and Azure Monitor that goes and looks at a particular flow and actually alerts any time it fails, hey now you can just spin that up and do it. So that's all nicety and and ready to go. You mentioned multiple environments. There is a note in the documentation, not in the blog post shockingly that calls out when this feature goes from preview to ga, it is only going to be available for managed environments. So you're going to have premium usage rights for users on those power apps and I don't know why they're allowing you to do it in without premium use rights and without managed environments in the preview. That seems. Yeah, that's odd. It's like a bait and switch ish. A little bit. I call it out because some folks don't always go and read the documentation before they spin this stuff up. Yeah, like me, were you referring to me there Scott . But yes,I agree to give it to. I was ringing to us there to.To give it to everybody and then pull it away. That one is a little odd. We should probably go talk about premium or managed environments at some point in time too. I don't know that we've talked about those much add. Add it to your list. Yeah. Your other thing about K Q L too is nice 'cause I also have some flows that fail once because of illegitimate failure. Uh, so whatever triggered it didn't get passed in, it failed. So maybe even my alerts for a single failure are different versus maybe I wanna go see if this fails like 10 times in a row or fails 10 times in a certain time period. I want to be alerted of multiple sequential failures or multiple failure failures in a certain timeframe that maybe indicate it wasn't something with just that whatever happened to trigger that flow that particular time, but something more indicative of a more significant issue with my flow. Like a service account getting disabled that now causes all my connections to stop working or something like that. Never happens. That no never. Or it was tied to a user instead of a service account and said user left the company and their account get disabled. That never happens either. .Yeah, all those little things. We might have to come back and revisit this one once it GA's and see how things change with it along the way. But I'm a big fan of App Insights so I would take having this data in there over not having it in there. The other thing that you have to watch out for when you spin these up is it can create an app Insights resource for you or you can go down the path of saying I already have one. So in your case, maybe you have a couple apps and they're even across environments or things like that and you wanna tie 'em all together in the same app, insights, workspace, you can do all that. You just have to be mindful in the setup that you're going down that path and not letting Power Automate make some decisions for you. Ooh, app insights for everybody kind of thing. Absolutely. Another. Governance thing to watch out for. Yes, there's a lot of governance stuff with the power platform as a whole. It's a, it's a unique service within the platform from a governance perspective. Platform is a unique service. There you go. Good way to sum it up. What's next Scott? Which one are you gonna jump to? What. I'm gonna keep us in? Platforms. Platforms. Did you see, I know you're always excited about this stuff as as our Mac OSS reporter platform, SS s o for Mac OSS is coming to intra ID tenants near you as a deployable, extensible agent on Mac OS clients. I think this one's kind of cool. This one is cool and you're right. I am excited for this one because up until now we did have the Microsoft Enterprise S SS O plugin for Apple devices. So this essentially allowed you to set up S ss o once you were logged in so that you could SS s o into various applications on your Mac OSS device. Now it is coming to Mac OSS as a whole. So this is taking that SS s O plugin bringing it up to the next level where now you can have your platform credentials for Mac oss Go Passwordless using Touch id unlocking the devices and be signed into intra ID under the hood. So essentially now you go log into your macros device and you're signing into intra ID as well using and they go into all the, it's the device bound, cryptographic key phishing resistant credentials based on the windows Hello tech and some of the Apple hardware that's already there. So this is gonna be cool. It's not quite Azure AD joining your device as a whole, but it's bringing it closer to that where now you're again signing into your device, signing into enter ID at the same time. So this is enabling all the SS s o for all your applications. You can also with this now synchronize your local account password and the enterra ID password. So your user account password on Mac OSS is also your enterra ID password. It doesn't sound like it's necessarily the same account or even the same user id, but at least the passwords on the backend are going to be the same. So you don't have to remember two passwords if you even use a password for anything anymore. Most of mine is all touch, ID watch, ID passwordless, all of that type of stuff. This is an upcoming public preview of platform SS s O for Mac oss and it'll work with Intune. It is coming to other M D M providers soon. I would say the timing for this is interesting. So it does say your Mac OSS requirements, I saw it in here somewhere, venture and hire, but it was also announced the same day that Apple announced their September event for Mac, which is usually also when the next version of MAC OSS comes out. So it'll be interesting to see. At first I thought maybe this was going to be a Sonoma specific functionality that Apple did something, but with the requirement of enterra, maybe there's some updates coming to ventra as well or just Microsoft finally was able to incorporate this into enterra a nice improvement for MAC users that are using intra id formerly known as Azure ad. Yeah. So the way I ran into this one, uh, you probably ran into it through the R S SS feeds that that we kinda automate and bring in. I ran into this one over on, I think it was Mastodon. Somebody was chatting about it and it it was one of the PMs in Azure AD and the way he framed it is like, hey, we're finally doing this. You can finally bring your C T o, your security leads and your devs on board . I was like,that is so true. Like I, I remember I I worked for for a logistics company here in Jacksonville and our C E O was the only user in the organization with a Mac . That was it.He liked a Mac the rest of us like we bought Lenovo's stuff like it was free candy but the C E O wanted his Mac and that was like the pain point for all of us to live with. And then I was thinking about it where I was like, oh and our chief security officer used to be on a Mac too. Yeah that that made life more difficult back then like it's so true. Bring folks into the fold and get 'em where they need to be. I'd be interested in seeing how this one works there. There's other components of Intune and the whole M D M stack on a Mac that maybe don't integrate the nicest. So one area for me would be say you impose like FileVault restrictions, which is basically like encryption on the MAC side. Yep. You might have BitLocker on Windows kinds of things. Does that extend all the way down to FileVault? Do you still need a local password for FileVault? What does that look like? How does it come through? 'cause when you do things like BitLock or like you get your recovery keys stored Azure ad your help desk can work with you. Some of those constructs don't necessarily exist. Like they're not the same on Mac OSS Ventura to all the way up to the upcoming Sonoma. We shall, we shall see. Yeah. It's. Always interesting when stuff like this comes out because I think sometimes from a marketing public perception side of things, it's like Microsoft and Apple are bid rivals and they can't stand each other in all of this. But then you see stuff like this and it's, you wonder how much, and I suspect there's a lot more collaboration between the two companies, especially when it comes to stuff like this or I know even some of the stuff with OneDrive files on demand. I think one of the sessions I saw there was some partnership in working between 'EM but from getting their systems to work together. When it comes to things like the SS s o when certain features that Microsoft maybe rolls out, I get the feeling maybe there's a little bit more partnership together behind the scenes than maybe public perception always gives to .Give you some of this stuff 'cause it is important. Like you said, you want your C-level guys to guys girls to be brought into the fold and your devs and your security people. Oh you also forgot Scott. Marketing Graphics, multimedia. Those people are also usually all on their Macs. They are indeed right here. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I N T E L L I G I k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. Alright, so yeah platform SS s O for Mac, OSS nifty stuff. Why don't we keep talking about intra ID since we're over here. There's another interesting announcement that came out this week-ish. Uh this week. Yeah. Any, anyway, it'll have come out by some week by the time somebody listens to this. But that is that there is the ability now to do a p I driven provisioning within your intra ID tenant. So rather than having maybe some outside service that does some wonky synchronization or something else that comes in along the way, you can just go ahead and actually take your system of record. I don't know, let's say I've got like SS A P or SuccessFactors or something like that. I can take the data out of there and as long as I can extract it and get it out, you can then push those changes like when they occur in that system of record over to this new A P i which sits within the uh, entra provisioning service and then that goes ahead and pushes that data out to where it needs to be. And the cool thing is it's not only like cloud provisioning 'cause now you've got, because we we've got the whole like intro cloud sync thing and and you do have hybrid like you mentioned putting all those things together. So now you can push into a single A p I endpoint and then say it's something that needs to affect change in your on-premises active directory. Great. That change can flow straight down from the provisioning a P I and the provisioning service down into what's yet another local agent runningbehind your firewall and ready to go in the form of the provisioning agent. And that can do things like push users and push changes into your on-premises active directory and then if you have synchronization configured between that and your intra ID tenant cloud sync kicks in, connect sync, click whatever you happen to be doing a along the way to get you there. So I think that's a super powerful one. Kind of seemed to go out under the radar. I didn't see a bunch of fanfare about it but I think it's super powerful, super cool and a long time coming. Yes. I agree and I have some customers that this might be beneficial for. Like I've done some weird stuff, I'm not gonna lie, it gets a little hacky at times but like one customer. That's janky, janky. Janky, it's not hacky, it's janky. What about convoluted? Convoluted is a good one too. I've done things for customers like their system again, they have a different system of record that they need everything to go into Azure AD four and it's things like C SS V files getting emailed out of this system because they can act do like regular export email reports and then we pull the said C S V out of the email attachment, dump it into blob storage, which triggers another flow that runs a runbook to go parse the C SS V, find all the changes and synchronize them up to Azure Active directory. Just being able to tie straight into an A P I if you can go straight from that system of record instead of all the secret sauce in between them, this would be very nice And I was talking to another customer that was in the same type of boat, different system of record, wanted to just shove everything straight into N I D and this is going to be a good solution. So this is one that is absolutely on my list and I'm excited to play about play with because I do have some customers in this scenario where we might be able to simplify some things for them. One of the other things to call out in here is you can give it a try and the a p i driven provisioning, this is another one of those preview features. Don't use it in production, yada yada yada. You can start using it if you have Microsoft enterra ID P one. So premium P one license for Azure ad enterra but then it also says licensing's terms will be released at general availability. So if you are a brave soul that wants to try this in preview, it doesn't sound like they are necessarily committed to this only being or remaining just a P one feature that this similar to the log analytics one we talked about or the app insights could change once it hits GA from that licensing perspective and what's required. Again, I know they want people to try it, right? That would be my guess as to why they're doing this is we have this license now but we don't know what it's gonna be when it comes out in general availability. And they've done that before too with other stuff or it's, it's free now. It's not gonna be free once it comes out. I wish they would just release the licensing terms right away so that people would know is this even worth playing with because I could play with it but there's no way I'm gonna be able to upgrade everybody to premium P two or pay an extra $5 per user a month to have a p I driven provisioning because it's just not feasible for their budget. So I don't know. It'd be nice to see what the licensing terms are gonna be once it hits general availability. Even if you have different ones in preview. In preview, you can use it here once it, it's a general availability, it's going to be this. It just helps from a planning perspective in my opinion. Yeah. So there's some other interesting things I think about the provisioning service as a service kind of thing and the way it's been implemented. So lots of the identity management world, like if you think about common, so directory tooling, so stuff like, I know SailPoint does this, I think Okta does this well off the top of my head but there there's a bunch of them that kind of interoperate based on a standard called Skimm. So the system for cross domain identity management I I believe that is. But Skimm is basically it's an open standard and it allows you to automate user provisioning end to end across all these various systems that also implements Skimm. One of the things that comes along with Skimm is bound schemas to work with in different scenarios and the a p i provisioning service supports both of those. So it gives you the ability to map from the Skimm core user schema and the enterprise user extension all the way back to the attributes in Azure ad. I think an interesting thing here is even though the payload to talk to the A P I provisioning service is skimm content, like it's actually a specific content type that gets fired into the A P I. So like the content type header on these requests gets set to application slash skim plus json it. It is not a Skimm compliant endpoint. So even though skim is the glue that's potentially holding things together, Microsoft is not fully coming into that ecosystem. So it's a one-way inbound endpoint. This is inbound provisioning, it's not outbound provisioning and full right back to these systems as well. So I think that's important to call out and you do have to consume a custom a p I here it's not, hey let's go ahead and just fire this up into existing product stacks that natively integrate with Skimm. Like you've gotta do some work to get it going. It is not a standard Skimm endpoint by any definition of the record. It's also very different from I think graph. If folks are looking at it and they're saying like, oh why wouldn't you use the graph to do this? Fundamentally different things like just the way the APIs are built out and what they're made to do. Like graph as being very o data centric, single user, not very bulky. This is all just bulk upload, bulk provisioning, get it into this schema, get it into this format, do some mapping for us and we'll make the rest of the magic happen in the in the background. Which I think it's very good to see it. I wonder how that changes over time too though if it does need to be become something that plays nicer in the ecosystem to get folks to latch onto it or if they just go, oh my gosh, I've been waiting for this so long that I'm going to take it and run with it kind of thing. Yeah, they have a big explanation of why it's not a standardized skim endpoint. There's a lot of good information about this in the F A Q that we threw it in the discord chat, but if you're listening to this after the fact, it is also will be in all the show notes. If you are thinking about implementing this, definitely go read through these frequently asked questions about the a p I driven inbound provisioning because it's not just a, there's a lot of information we'll leave it at that. There's a bunch of information in this few frequently asked questions about more details on how it's all working, why it's all working the way it does, all of that type of stuff. Indeed. All right, what else? We we we have time for one more, for one more. You wanna talk about, you wanna talk about Python? We. Can talk about Python. You were doing such a good job with your flow from one to the next and then we just completely band all that and said let's talk about Python ,but let's talk about Python. I. Ran outta things so , this'll be our, this'll be our last one. There.Was my G P O one. We can do that one next time though. We'll do Python. We'll. Save that one in the list. So Python used all loaf for the place in data science land. It's available in your favorite products of choice. Like maybe you've spun up Databricks and you're like Ooh, I'm gonna run a notebook over here and get things going and start playing with some pandas data frames and things like that. If you've ever done that on that side and you're like, huh, I really wish I could do this in Excel now you can dopandas data frames and pandas extensions and all the things that come along with that ecosystem within Excel except you're not really doing it in Excel. And I think this is cool the way they set this one up and get it ready to go. So if you hop over to the latest insider builds of office within Excel in public preview, now there is Python functionality. So rather than having a standard Excel function, you can come over and you can run Python functions which are just using pandas, which is super cool because there's tons of plugins and other things for like charting and visualization and all that stuff or running specific types of algorithms on top of your data. Like all that stuff exists in conduct. Super easy to pull in. Like that's all supported over here. So if you're a data analyst and you've been pining to have access to data manipulation and working with data frames inside of Excel, I think this is a super cool thing. Just like not only on the data manipulation but also the visualization front. There's all sorts of other things that go into predictive analytics, modeling, statistics modeling, forecasting, all those kinds of things that now you can also go ahead and run through this engine and if you're already in the ecosystem, like it should be super easy to come over like it's all pandas, it's all Conda, Anaconda and that stack. It should all just work, which is cool. The even cooler thing I think is how it all just works, huh? Like how did they do all this and how did they bring this functionality down to a local, a local Excel client and make it consistent? And the interesting thing is they didn't bring Python down to the client. They brought the data from the client up to the cloud specifically in the form of a container. So Microsoft is hosting Azure container instances that are using pre-built packages from Anaconda that then you can go ahead like I said and and absolutely bring in and inject your own packages into that container. But effectively Microsoft is running like compute as a service in the cloud in the form of these Python containers that are all stood up and ready to go that your Excel client can talk to. So it can pass data to that container that gets sent out via this specific Python function that's now available in Excel. Like it's the Excel function. So Excel, open paren and then close paren and it can just return that data in the form of a data frame that can then talk locally inside of Excel. I think all sorts of interesting kind of things to follow up on here, but I'm excited about the Python part of it. Anytime I don't have to go and and open a notebook and hop over to a specific workspace or anything like that is really nice. I wonder how much customers will latch onto it once they realize that the units of compute that are running things are actually container instances and sitting out there in a hosted on behalf of managed on behalf of environment within Microsoft land. There is a little bit of an article out about this functionality, I'll put a link in the show notes. It's called Data Security and Python in Excel but it talks specifically about what these Azure container instances are, where code runs and what your Python code has access to and does not have access to. So I think it's important to go and read through that because effectively like now your Excel client is punching out to random place on the internet to go ahead and put data in and out of your Excel notebooks. Yeah it is interesting that it's doing it all in Azure. So I have a question. I've not done a bunch with Python, I don't do much data science, this is not on my list to go play with but just from understanding it, is it that the amount of data in the amount of compute that Python would use to crunch this is that it needs something like a container in Azure? Like why build this to run an an A C I instead of building this to run locally? Or is it just that there would be so many more requirements on how you'd have to set it up locally because, and this came out, I actually had a, a friend of mine that asked this question because in preview it's gonna be included but this is another one that after preview some fun, some functionality they don't specify what will be restricted without a paid license. And he was like, I don't wanna go learn all of this and set all this up but while it's in preview only to lose this functionality because I'm not gonna get my company to go buy a paid license for me to do it once it comes out of preview. Why isn't there some way that I can still use Python and Excel but run it like using my local compute instead of having this dependency on a C i or maybe you can already do this all locally if you go set everything up. That was just one of those I was curious about not having done a ton with it. I didn't necessarily have a good answer. I think. Part of it is the ephemeral nature of data science. So if you think about these massive lakehouse and data lakes and other things that kind of sit out there today, right? Uh, there might be some form of like centralized governance that sits on top of that. But quite often you have like disparate communities that are actually working with the data. Like you might have one set of data scientists working with say say do the medallion architecture, right? You're running everything through like bronze, like raw data, refining the silver, getting it out to gold, blah blah blah. Like all that data is meant for different audiences and for different types of analysis. So quite often while you maintain like the centralized data source, the lakehouse, now let's imagine like your Excel file is the centralized data source. Yep. The people who consume that data are different audiences and they're gonna go about it in different ways with potentially different tools. So you might spin up like like a Databricks cluster to do some one-off analysis on an already refined dataset 'cause you wanna go and look at it in a different way or there's a different like statistical model you wanna run against it, something like that. So you'll spin that up, you'll create it, you'll do it all, you'll crunch all the numbers, you'll run through it all and then you'll spin it down 'cause you got the result kind of thing and and I think that ethos of ephemeral analysis that potentially doesn't always need to stick around plus the ephemeral nature of maybe you are doing one type of analysis and I'm doing it another and we're gonna approach that in different ways with a different set of plugins. All those kinds of different things actually makes a ton of sense with something like container instances which are also quite ephemeral in their nature, right? Spin 'em up, spin 'em down, only use the compute when you need it and then hey the rest of the time I don't need the compute, let's just ditch it out the side and get rid of it. So I imagine like that's a big component of it is the very nature of some of this stuff is ephemeral works end to end if you think about it that way. The other one is consistency and availability of these things. Like containers make a great way to spin up packaged environments that are the same for everybody at the beginning and then they can deviate as needed but whenever they deviate too far like they can just reset and come back to baseline and start again. That kind of thing. I think it all comes together and works. It's an interesting way to solve the problem and I think it opens up the ecosystem to a bunch of new folks. So if you're thinking about it from the context of oh my gosh my company is not gonna pay for a license for me to do this in Excel, is your company paying for you to have access to Databricks or Synapse or Snowflake or like one of these other. One of those other ones. Analytics platforms? 'cause if they are, I'm gonna bet that the cost bakes out to be a lot less to run a container instance to run on top of your Excel workbook than it is to spin up an entire unit of compute around even like a single node Databricks cluster. Got it. That makes sense. And I guess the other aspect of it, I was going through the article here too is they do talk about that it's built for teams so you can also like store these workbooks in SharePoint. You can put them in Microsoft Teams, which is still putting them in SharePoint, send them via Outlook, which you shouldn't be emailing files via Outlook anyways, but it still has all the comments, the mentions and then as different people maybe go grab these notebooks, to your point, your Excel workbook is your source of data and maybe different people have different worksheets, all of that or other people are working with you on the data, they'll be able to open it and not all of a sudden run into, my machine isn't set up the same way your machine is from a Python perspective so it's not working. You just open the workbook and it sounds like it's there. I'm guessing it just as soon as someone opens it, it maybe spins up a new a c I instants in the background to be able to do anything with it. They say sensitivity labels work with all of this for protection policies but this also probably better facilitates the portability of an Excel workbook. I guess they would be curious, does it only call out when it re renders data? Let's say you have the license for this, you go do a bunch of data analytics around the podcast in Excel, you send it over to me or share it with me and I don't have a license, is it just not gonna work for me? It'll be interesting to see how that works too if you share these with people that are licensed differently for Python and Excel. T B D, we'll see, I haven't seen that one yet. There's a really good video out there. There's this awesome person out there, Layla Ani, she's an office M V P like she's great. She's got a YouTube channel. If you go in you watch like John Savile videos for Azure stuff like just go watch her videos for office stuff. Ooh Excel word one like stuff like I'm not excited about all the time but she has an awesome video that walks through this feature I think in a really great way. Like it takes you through like the baby steps of okay, let's bring in our first data frame. Let's see how a data frame plays over here. Talks a little bit about what data frames and what they are and let's leave the whole a c I thing and like the technology and the background out of it. Like just here's what Python and Excel potentially means for you with a nice simple dataset. I think rather than folks like getting on their jump to conclusions Matt and trying to worry about licensing and how it all works in the background. Like maybe just go see if the functionality works for you and the functionality works for you and the values there. It's a lot easier to have that conversation about like downstream, R O I on on licensing and all those kinds of things because if you get like analysis paralysis in the beginning, I think for something like this, like you're potentially missing out what could be a really cool tool in your toolbox. Right? I wonder if it'll end up being even like a pay as you go type license or you can buy like credits thinking back to the whole spin up a container as units of compute. We've seen more of this pay as you go type stuff coming in through some of the syntax stuff that we talked about earlier too. Like I could see this one even being a pay as you go type model based on usage of those instances. So we shall see, but I do. We'll see it is compute somewhere, right? Like let's be clear like it is compute that's running all the other compute things. Like you look at like dev boxes and cloud PCs and all this other stuff that runs in the background in Microsoft land. Like part of the reason that stuff costs money is because it costs Microsoft money to run it. Like you're literally firing up a server for some period of time. So keep that in mind too about licensing models and things like that. Sometimes underlying technical implementation has to drive some of that just to get those wonderful cogs back. Yep. But I do like to that point of the portability, it definitely is a better way to do this I think from a portability standpoint. So who knows what it will end up being, but definitely some cool features and functionality coming to Excel. And with that we should call it a day. The leaves are still gently waving outside my window with an occasional wild gust or two, but I also have clients pinging me that they have an urgent issue that I should probably go attend to. It. Happens. All right, cool. Go fire up Spotify. Start playing Rocky like a hurricane, like a little bit of scorpions in the morning to get you going and you'll be all set. Should I play it loud enough that I can go stand in the middle of the street with my flag and brave the hurricane? Be the Florida man . It was funny. One last story.I had a friend that totally did this the other day. I was on a conference call with him, he's down in Tampa and he was like, oh this is a good, a good squall coming in. I'm going outside. And he literally like left in the middle of the conference call to go run outside in the middle of the squall and he didn't come back for 20minutes. I was like, see outside, like hanging onto a stop sign, blowing sideways or, but I was like, this is, it's definitely Florida. Yeah. Yeah, definitely Florida. That's our new motto now. Definitely. Definitely Florida . Alright, thanks Scott.Enjoy the rest of your day. Hopefully you are able to maintain power throughout the day today and we will talk to you later. All right, thanks Ben. Yep. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 351 – Rock me like a hurricane… or Python in Excel
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 45:02 — 31.0MB)
In Episode 351, Ben and Scott catch up on some of the latest news around Power Automate, Microsoft Entra, and Microsoft Excel. First, they discuss the Public Preview of Application Insights integration with Power Automate for debugging your cloud flows. Next, they break down the still in Private Preview features of platform SSO for macOS clients. And then they close on some exciting announcements around the addition of Python functions to Microsoft Excel.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 340 – A little bit of DDoS in your life
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | Jun 29, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 340 of the Microsoft Cloud IT Pro Podcast. Recorded live on June 23rd, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users. Where we discuss the topic or recent news and how it relates to you, Microsoft has released a response to the denial of service attack that occurred in early June against Azure and some details about how you can protect yourself against similar attacks. We also discuss some Terraform news with the June updates as well as a new module to manage Azure AD with Terraform. Finally, we wrap up talking about copilot as the release gets closer and Microsoft has released guidance around preparing your Microsoft 365 tenant for its release and adding it to your environment. I feel like we should talk about news, but I don't know that I really wanna talk about news. . Fair enough?Yeah. Okay, so I have one for you Scott. I forgot to send you this. This was on my list and I have to find it now. I think I sent it to you in a text message. Remember how, okay. A couple weeks ago, I think it was a couple weeks ago or a week ago, we talked about that outage in Azure and Microsoft kind of did everything in that news article to not say denial of service. They just talked about a spike in traffic. Mm-hmm. , I do remember that one. They.Did come out now with the official response to that and it is Microsoft's response to a layer seven distributed denial of service attack. So they did come out and say that it was a denial of service attack. It was interesting, it started in early June. I don't know when that actual outage was, but it sounds like this was actually a denial of service attack that occurred across maybe multiple days that temporarily impacted availability. They did open an investigation tracking it to a threat actor that Microsoft tracks as storm 1359 .I wish I had a cool name like that. Yeah. Yeah. But they did dive into kind of what was going on. They did say no evidence of customer data being accessed or compromised. It was layer seven rather than layer three or four. And it was a combination of attacks, an htt P https, flood attack, a cash bypass and a slowloris. Is that how you pronounce it? Slowloris? Mm-hmm. . Yeah. Effectively a client that opens a, a connection.So think like, hey, I make, may I make an HTP request and so I've, I've got that TCP socket open and I'm ready to go and the client then just, it just sits there. Yep. Keeps it open, consumes resources. Yep. The other interesting thing about this, or nice thing though is Microsoft's also because it was against Azure and like Azure uses Azure, which is kind of odd to think about in and of itself ,but they talk about how you can use layer seven protections such as the web application firewall or the waf not to be confused with the well architected framework or the wife acceptance factor to help protect against those. So they also not only kinda said this is what happened, but also gave recommendations how even you as a customer hosting things in Azure could take advantage of the WAF to help prevent some of these layer seven DDO o s attacks. Yeah. It's another thing that's just happened over time, right? As web applications become more prevalent, stuff starts to move up the stack and I guess in this case the O S I stack and you know, you start to go from layer three, layer four and then you hit up to the application layer on layer seven and it starts to get more interesting where clients can do like really weird things like not just even like the, the slowloris kinds of things where you maybe open a connection and then you purposefully go slow with it. There are clients that misbehave even when they don't intend to, like sometimes they see storage customers that do weird things with like HDB connection, pooling like, like they don't understand the way like sockets are pooled inside of SDKs or inside of some of the frameworks that exist. So they start to do weird things like you know, occasionally I'll have a customer where they go, oh, you know, I thought I had enough of the data so I just stopped downloading it and then I start seeing all these network errors in my storage account. Why do we see network errors? It's like, well let's go read our documentation. A, a network error is when a client suddenly disconnects and we're still sending data so we don't know if the client ever got it and they look at us andthey go, oh well we got all the data so we walked away. It's like, but you didn't walk away in the right way. You know, like sometimes I have customers who do things like they send us like RSTs and we're like, no, you shouldn't do that. We should send you the R S T cuz we're done and it's just weird. So I think the more of that like just underlying implementation stuff that's been abstracted away from developers, sometimes it's a little easier to lose sight of how this stuff works now and and how it comes together and and what that all looks like. I was actually, I was same kind of vein of like weird client behaviors and maybe you don't understand or think enough it's that people don't understand. I think it's just that they don't kind of think end to end about how it comes together. Yep. Is we were working with a customer on easy copy. So easy copy client tool, it copies data from on-prem service to service, like all those kinds of things. So it's a multi-threaded application and it also has concurrency built into it. So within these threads you can spin off kind of n HTP connections because you have to fire off HTP requests to the storage service to be able to do your copies. And we were working with a customer and they're like, Hey, we're getting this weird air on Linux where we're running out of sockets. And it was like, huh, you really shouldn't like ever run out of sockets cuz we purposefully limit the number of threads that can go up. So that doesn't happen cuz like most Linux clients, like a default installation on like a modern Linux kernel. You've probably got something from like 20,000 to 40,000 ephemeral sockets to work with locally and it's like wow, that's a lot for you to run out of. Like what are you doing? Oh well we're running multiple instances of AZ copy on the same server and then each one of those instances has this concurrency setting and it's doing this thing and we're like, oh we never really intended for you to run multiple instances of AZ copy on the same server .You can certainly run multiple instances but you should kind of like fan that out, right? Maybe you have this one, go look at this directory, this one, go look at this directory. And the response we got back, which I kind of went like fair enough, but was, well your documentation doesn't say that we shouldn't run multiple instances on the same server. So I was like, okay, fair enough. Right? Like I'll, I'll go update the documentation so that that doesn't happen so that, you know, future customers can take that into consideration. Yeah. But it was a weird one to me like I, like I hadn't even thought about ephemeral T c p port exhaustion on Linux clients in like a long time. It's like something that's been so far abstracted and so far outside of my head like, like why would that be top of mind for me or anybody else? Un until you run into a weird edge case, right? So things like this do happen. I think in the case of like the DDoS attack that that you pulled up and some of the things in there, like you do have to think about kind of multi-layered mitigation and how you're gonna mitigate risk there for yourself. So you can't really protect at just layer four or layer three. Like you, you probably do need some things at the application level as well and you know, that often comes at the expense of operational overhead and money as well. Like sometimes these advanced security solutions do cost you more to pick up those things like web application firewalls and, and all that kind of stuff. But I think it's worth it for customers to consider and kind of do that like, you know, risk reward kind of thing, right? Like put it on the scales, see where it balances out and what makes sense for your business, your workload, all that good kind of stuff. Absolutely. I'm still this, this whole running multiple copies of AZ copy on the same server still has me going, huh? I don't know that I ever would've even tried that or thought to try that. Uh. Yeah, I I mean you can certainly do that. Uh, there's no. Limitation. And it, it was never explicitly not recommended. Now it's not recommended cause we we updated the docs and,and put that fair enough there. But should, should you wanna find a way to exhaust tens of thousands of ephemeral ports on your client very quickly. Yeah.Just spin up a couple copies of AZ copy, I mean, and tell it to copy a couple hundred thousand objects at the same time. I was. Gonna say they must have also set the concurrency really high. Yes. I would assume. concurrency high plus number of objects really high.So one of the interesting things about like easy copy as a client tool and and I sometimes forget about this, like I tend to view it as a, and not to sell it short but like it should be used more for I think more manageable migrations and data movement scenarios, right? Especially if you're doing like an on-premises client to the cloud for a whole bunch of reasons and you know, over time like the maturity of that tooling, like it's good today. Like you can throw 50 million o object, you know, job at easy copy and it'll churn through it and do it like that. But just because you can do 50 million objects in a single job, does that mean you should well initial, well again, we're back to like weigh the risk reward thing. Like how big's my client? Uh, you know, what's my network throughput? What what's my CPU and and all these other things that you've gotta kind of put together on the client side and just think about a little bit, right? It's not that it can't be done, it's that you have to like think through it end to end and rationalize it and you know, we're all moving so fast that you know, you just kind of go, go, go, go, go. And sometimes you don't know that you've haven't like passed a point of no return but that you've passed a point that you maybe could have caughtsooner and come back to. So I always think it's very, very interesting to go work on those kinds of things and I am 100% happy to be putting more prescriptive guidance like you know, yes you should do this. Yes, you shouldn't do this right into documentation and things like that. I think that moves everybody forward. Oh absolutely. I wish everybody did that with documentation. And again, I think it just like that's what they ran out of first. To your point, I've never thought about doing that because I always feel like you'd choke out your throughput whether it's the nick going through the switch or the CPU or the memory or the IOPS on the hard drive, but to choke out the available connections and the available sockets before you hit any of that other stuff. Cuz that's why I've always run AZ copy or other SharePoint migration tools when I've done something similar, probably not this amount of data, you spread it out for that, right? I think. Any tool that does this, right? Like I not to not to single out easy copy, but anything that's gonna open an h e p connection call an API and orchestrate this type of movement. Like ultimately bits like when you're doing an on-premises to like cloud, cloud integration scenario, right? That stuff needs to move over the wire and it's going to consume resources, it's gonna be cpu, it's gonna be memory like say you wanna like hash objects before you send them with like, you know, I don't know, an MD five or a Shaw hash or something like that. Like guess what? You've gotta do all that someplace. So that takes CPU and then you know, potentially increases the size of your responses even minimally because it's gotta go in headers and be stored in a service, blah blah blah. So it's one of those things like nobody should have to think about it. But then when you get into those kind of edge cases you go like, yeah okay, .Right? Yeah for sure. Huh, interesting. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I N T E L L I G I N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. All right, so with that, what else do we have? Which one of these do you wanna go? There were a couple of interesting ones. I've got two interesting ones. I would like to chat about something that you brought to my attention. So why don't we do Terraform and Azure AD Azure ad cause I didn't even, I didn't even know this was possible through a, through like an HCF F script. Well I don't think this was possible up until very recently and I don't even know, I'll be fair, I don't know where this came from in my R ss feed I have some searches that just pull random stuff into my RSS feed. I may have seen this on Twitter but yet this was an article from June 20th so just three days ago about Azure AD with Terraform examples and I agree I didn't know this was possible. So I've done some with Terraform and I've looked at Terraform, I've written some Terraform, we've talked about Terraform and Bicep on the podcast before but it's always been in like provisioning resources, whether it's managing VMs or app services or firewalls and the whole infrastructure is code type of thing. And then I saw Azure ad intro with Terraform and I was like huh, this is gonna be interesting because I never, I never thought about this before and I wasn't quite sure what this even was. And then you start reading through the article and it is even more interesting. So it, the article kind of starts out with your Terraform set up for Azure ad kind of what you need to do, what providers you need to specify how you would go in and set this up with a client id, client secrets, tenants ID subscription IDs. And then the next thing is managing users in Azure ad. So it's all about how you can create and manage users with Terraform. I don't even know where do you wanna start with this? Like it goes through again, it just kind of caught me off guard.Yeah with you can go through and set these user properties. So I think it's an interesting idea. A couple of things just from like looking at the article and I guess the way the kind of provider operates, it's all fairly straightforward. It's an official kind of thing looks like supported on the HashiCorp side. So they've got kind of their own Azure ID provider just to plug into you pump in a tenant id. So pretty easy to figure all that out. And as far as how the provider interacts with Azure ad, it looks like it's all just a service principle. So uh, you know you go create a new service principle grant that service principle contributor rights over to your Azure active directory and then you end up, you know, with a client ID, client secret, all that good kind of stuff which can just be exported out, you know just environment variables that sit on the client side and then get it running management look pretty rich like it doesn't look too bad to get started with, you know, you can create users, you can assign roles, it even works with administrative units. , that was kind of good.Yeah like uh, I didn't even know like most people read the documentation and and knew those existed group membership applications licensing, which I think is really cool devices as well. So if you're thinking about devices and groups and dynamic security groups that's all in here and all good and ready to go I think like it seems like it has a good surface area. The really interesting thing to me would be, hey this is Terraform so it can do things like state management. So can it start to manage state of group memberships inside of my Terraform scripts? I think that could be a little bit interesting like as you start to extend your scripts like maybe application deployment now. Like here's a cool one, right? Like cuz now you have the ability to create users and all these kinds of things. You could go ahead and say like when you're deploying, say your new web app and your web app has a specific set of maybe security groups that are already in your Azure ED that are gonna be associated with some r a roles on the resources in Azure that are spun up now you can go ahead and kind of apply that user security, that R a C and kind of do all the identity and access management things as part of your native Terraform script and not have to reach out and run like a separate BA script or a power shell script on the side. So, and then you get all the state management across, you know all those resources within there and I think that's pretty nifty. I'm gonna have to go play around with this one. Yeah, I was looking at it, I don't see much about state management here, but I think that was my first thought that I had with this as well. Like I mean you could use dynamic groups, right? If you have dynamic groups and you are managing users and their group membership that way technically based on user attributes, it would automatically undo and redo things but then people could change attributes. You could still manually create security groups but if you could kinda lock down your Azure ad environment by forcing state management of security groups, I guess I see pros and cons to this too because you start thinking through, if I'm managing group membership users and groups with Terraform and managing their state. I'm thinking like Terraform State. So you know when you spin up a Terraform script you can create a plan and then you can apply that plan. So if this works the way other Terraform modules do, I should be able to do something like create a security group in Terraform and then populate group membership in that group and I run it the first time like let me do a plan and apply it and then when I come back and run it again, if there's no changes it's just gonna skip it, it knows I don't need to do it right? Or if I run it again and I've changed it, say like I've gone and added a user like hey we hired Ben, he's onboarded ready to go. You just put that in it and that's the only change that fires off against the environment. So, but not so much like Azure D State but actual like be the ability to retain state like group memberships within the plan on the Terraform side. But what if you're creating other groups like I'm gonna assume this is only security groups maybe. Oh no there's Microsoft 365 groups too, but you might not necessarily want it to main state maintain state of Microsoft 365 groups or if you were using that, what would happen as you create new teams? I mean you'd really have to think through how you would do all of that .Cause you wouldn't want it deleting teams because it wasn't in your terraform. Welcome to everybody's big problem with Terraform or, or the thing that they run into, right? Like Terraform only knows what Terraform knows, right? And the things that it doesn't know so, so the more you manage outside of your Terraform scripts, the less iept they become over time or I think kind kind of you lose some of that power. So should you go down a path like this, quite often you are getting to the point where you're making the decision of saying like, Hey I'm gonna use Terraform as a management tool and really with the management plane of these services that I work with to go ahead and affect change within them. It's the same kind of thing. Like if you think about Terraform and maybe there's an update to a service or a new service in Azure and that isn't available in Terraform yet, the answer is usually well hey if there's not a provider for Terraform for the, to the resource provider in Azure, just go ahead and fire off an arm template. Well the problem is when you fire off an ARM template, all Terraform does is it knows it ran an arm template, it doesn't know like what was in the template and what resources were created within it. So you lost like that state management piece, which I, I think is why people become a little kind of like zealots around like oh my gosh like I need native Terraform support for these kinds of things. Which again, you know like makes sense if, if you kind of walk it end to end like you can understand the desire and why you would want it to be that way. So I view this as like this is probably pretty cool for standing up new stuff and then kind of maintaining it going forward. The stuff that's there, it's gonna be a little bit harder, right? Cuz Terraforms not gonna have any idea that it ever existed in the first place. But all about having like new providers that are integrated into the ecosystem, they work really well without having to do things like arm templates or kind of sideways machinations like that so that you can maintain like TF State and all those kinds of things. Like that's goodness. Yeah and this, it does force you to do a password too. So they also include in this article a random password generator from Terraform. So you can use that in combination with it. I think the other place I thought this could be useful too is I've done things before with different solutions where you have a service account and you need to create a service account, you need to have a password, maybe that service account needs to maintain certain permissions. I've had issues before where you create a service account, you give it permissions, it's doing something and some overzealous administrator comes in and sees that said service account has permissions and maybe they don't know why and they take 'em away and it breaks stuff. never happens.No. If you can maintain, maybe you're not doing all your user management, but if you build a solution that requires a service account and requires the service account to be a member of certain groups or have certain permissions being able to both create and then kinda your point manage the state so that if somebody comes in and does alter certain settings, permissions groups, whatever on the service account, Terraform goes in and says or redoes it the next time you run it. There could be some benefits there. I I could see with this as well. Yeah, it's an interesting idea. While we're talking Terraform real quick, I'll put a link in the chat and show notes for everybody as well. If you go out on tech community, the Terraform is HashiCorp and Yep. You know they,they write the things they write and then there's also Microsoft which contributes back to HashiCorp and in some cases holistically maintains some of those Terraform modules and kind of the, the management of how those map back to the resource providers in Azure and all that kind of stuff. So if you're into Terraform, there is an Azure tools blog, you might want to go follow that blog on tech community, like throw it into an RSS reader like we've talked about in the past or you know, however you choose to consume that. But they do monthly updates for what's come out in Terraform. But I don't know if you've been paying attention to some of the things but like they've been pushing new updates to the export tools. So being able to go back between native concepts of uh, Terraform and Azure can be a little bit hard sometimes in this kind of clouds scenario that's out there. They also host community calls, I believe they do those monthly or B or bimonthly, I forget the exact cadence for them, but folks can go out and register for those community calls. It's like aka ms slash Azure Terraform, you can just register, join the community and uh, go ahead and do that and then they're always pushing out new quick starts, all that kind of thing. So super helpful for kind of keeping up with what's going on on the Microsoft side of Terraform, which is potentially different than the HashiCorp side of Terraform and, and what it's doing as like HashiCorp uh, as a whole. Yeah, I saw this too. I haven't read through what was new in June but excellent call out, good resources. Export tool and yeah some, some new documentation and and quick starts and things like that, which is probably one of like the other big asks that I see a lot. It's like, hey how do you do this? It's like, it's not documented yet. Okay, we should go fix that. Yeah and. The LA the last community call that's mentioned in here was yesterday on June 22nd, it looks like it's maybe like every other month. They had one on April 6th. Doesn't look like they had one in May and then they had one on June 22nd. So if you're interested like use the sketch, just go sign up and watch for notifications and emails about those community calls because they don't look to be particularly consistent. You can also be a speaker if you're interested. Fill out a form at a K M S A Z, uh T F C C speakers and we'll reach out if you like your topic, if you want to co-present on a community call. So if you don't wanna just observe but you wanna participate and have something interesting to talk about. I know from running user groups in the past with you Scott, that people are always looking for speakers that are interested in speaking. Yes. Uh, what they are hard to find. So I have one more Scott that is not Azure related or Terraform related but is one I have been anxiously waiting for is there was an article published this past week about how to prepare for Microsoft 365 co-pilot. This is not an announcement about co-pilots being out there or getting public preview access to it. It is still in the early access program. There's a link to it if you want to go apply and find out more about that. But the fact that they are now publicly talking about what you need to do to prepare to me means that maybe, hopefully this is right around the corner and I can go give Microsoft some more money for yet another license. . Oh yeah.I always love things like this. You're like huh, what do I really need to prepare for? Right? Like I already, if you're a Microsoft 365 Office 365 customer, you would think like you already have a lot of the groundwork in place but you might not, the licensing is probably gonna be a big one upfront. Like do you have the right types of licenses? So copilot is like as far as what they've said so far for Microsoft 365, you're gonna need either an M 365, E three or E five license. Yep. You need the Azure ID account. Like that all makes sense. And then all those apps and services that co-pilot is going to work with like Word, Excel, PowerPoint, OneDrive, all that kind of stuff. Turns out you're gonna need that. And I, I think that's probably one of the more interesting things like having done the M 365 office 365 administrator thing for multi-thousand person orgs. You have clients who are kind of multi-thousand, it gets like weird sometimes, right? With some of those organizational requirements or just things they've put in place like oh yeah, you know we, we let this business group run this thing but we don't do this over here, we haven't deployed this yet or turn this on. And I think for like co-pilot to work across the stack, you're back to one of these inflection points where you kind of gotta like get ready to turn everything on and live with it. , right? And they did so they did say too further down,there's a footnote all the way down and I saw it in the comments for SMB Business standard and Business Premium are also eligible base licenses. So this was not called out in the initial technical requirements but is a footnote that if you're an SMB you can also use either of those. I'm curious about this Scott, from the preparing for it with the word Excel, PowerPoint, OneDrive, outlook loop and more, it says you need access to the Microsoft 365 apps and services. Is this going to be that you need the desktop license of those apps or do you think it'll just be like if you have just the online version of Word Excel, PowerPoint, is that gonna be an enough? That's not specifically clear in here from a licensing perspective. It also does say you need to be on current channel or monthly enterprise channel for Microsoft 365 apps to have access to copilot. Yeah. So doesn't the channel thing for apps apply to the web desktop clients? I think it's desktop and web. And and web. Yeah. Yeah. So I would speculate it would work on the web particularly because a lot of these features do tend to come to the web before the desktop. I'd have to dig it out. I thought there was an announcement the other day that like when the new version of Outlook drops, like you know that new like web-based version of Outlook at that point like Outlook is basically like a glorified PWI glorified. Yeah and I, I'm way over simplifying it but like I guess I'm allowed to do that. You. Can absolutely do that. So those are some of the technical requirements. It also talks about permissions. There's some stuff in here about security, privacy, data residency that it's gonna follow Microsoft's principles around those. I think that's gonna be super interesting with GDPR and some of the things that are going on in the EU around ai. Like are you going to be able to do this organizationally let alone like can you configure the stat, can you light everything up? Like are you okay with that organizationally, just like the broader question of like, is machine learning things like this kind of hate that we're calling 'em ai, but are AI things like this allowed in your country or in your geography is gonna be another big question for folks. And then what do you do like if you're a global organization, like how are you gonna handle this and what's that gonna look like and how is Microsoft gonna handle it? I think those are gonna be super gnarly kind of questions to dig into. So this whole thing is interesting. I saw an article about this and I can't find the one I saw recently, but it did pull up one bag from April where there was a leak at Samsung where Samsung employees entered sensitive information into chat G P T. And depending on where this data goes from co-pilot and from, I mean even chat G P T is the bigger one because it's just open public is you're giving these models confidential information that they then turn around and get trained on and could technically leak out to a competitor who uses it to look for the same information. Um, which kind of ties into this whole data residency security privacy as when I start having all these internal documents presentations that's learning from the graph and it's generating these models and learning, making sure that data does stay secure and private. So my understanding for copilot and, and I could be off, I've, I've gotta go watch some of this stuff about the indexing service for it. Mm-hmm . So the base model,like the foundational model was not trained and will not be trained on customer. Data. Customer data, yes. So you're effectively, like Microsoft Mechanics had a pretty good video on it, I think that kind of laid it out. I'll try and dig up a link to it, but you're kind of running through this series of like meta prompts. So it's a meta prompt that builds on a meta prompt that builds on a response and another meta prompt from there and then is augmented with kind of security controls in Azure AD and making sure they've got the guardrails and and ring fencing and things there. So if you think about it for like large language model to say summarize this meeting for you for it to be able to respond to that, really it's gotta go back to the transcript of the meeting. It's not training on that data, but it is eventually running that data like through one of the meta prompts so that it can feed in that document or whatever it needs to do and go summarize. But how it learned to summarize and what it thought a good summarization was like that's all in the foundational model and and none of that was trained on customer data. So we shall see. Yeah, and it does get into that in that security privacy and data residency. It says copilot does not use customer data or user prompts train the foundation. Copilot does not use open AIS publicly available services. It uses Azure open a AI services only the L L M calls are routed to the closest data centers but can go into other regions where capacity is available. No customer data is written outside the user's home region. Starting in July, the early access program for Microsoft 365 copilot will align with our commitments under the EU data boundary. So they do have a bunch of that type of information in here. If you're curious about it, it's interesting that starting in July, the early access program will adhere to that. Is that an EU thing or is that a hint at that maybe we'll see this in July because they're getting ready for public preview and wanna make sure it aligns with all that when it hits public preview? I have no idea. Me reading between the lines. I don't know, I haven't, I haven't been paying attention to some of like more deeply some of the stuff that's going on over in the eu. I know there was the initial hubbub with, you know, Italy banning some of those things, which they've kind of dialed back a little bit and walk back some of that. But we'll see. I don't think you'll know like the fallout until all of this is broadly available. People can kind of see what it does and understand where it's going. And then I would imagine that given the kind of, you know,government tour that some of the CEOs of, of these companies like Sam Altman and OpenAI, like they, they're going around and kind of visiting with governments now I'd imagine this stuff is just gonna be litigated for a while as well once it launches and gets ready to go. But I imagine also a number of organizations will be kind of hampered by that in the beginning, especially cuz there's gonna be lack of clarity there. I just don't know how they'd get to like a 100% locked in kind of prescriptive set of guidance around that. Like I, I haven't seen it done yet. It'd be interesting if it could get done for this. Yeah. And then the last big thing I would say is the license management. We already talked about you need a base license. Needing a base license implies that this is not in included in a base license, that it is an add-on. But then yes, further down they also say co-pilot license management as with other apps and services admins will be able to manage Microsoft 365 co-pilot licenses using the admin center, blah blah blah blah blah. That very much implies as well that there is a Microsoft 365 co-pilot license that you will have to buy. So for all of you hoping that this was going to be just a free addition to maybe even the E five plan, kind of reading between the lines here where it talks about base licenses and then it also talks about Microsoft 365 licenses. Very much my expectation is, is that this is absolutely going to be a paid add-on to all of the existing license plans that you may have. This is not coming, well I won't say an add-on to any of them. An add-on to the base licenses. There are not gonna be licenses that automatically include this. You're gonna have to go spend money to get copilot is how I would interpret everything in this article. Yeah, you ready for an E six or an E seven or an E 42? Like, like whatever the answer is. I mentioned that to somebody the other day. I was like, I would actually love an E seven or an E nine that just includes everything. I get it. It's going to be an expensive license if it's $97 or a $125 per user per month. For me, I am getting tired of trying to manage, I'm gonna license everything for my job, for what I have to do. I am going to have at least one license of everything for myself so that I can adequately talk about it, test it out, validate it, that type of stuff. I am getting so tired of adding on add-ons to my license that even if it's the same price I would pay for an E seven or an E nine that includes everything. Just to simplify my management, to align everything together. Just to have one big product to know exactly how much it is. I mean maybe Microsoft, if they bundled everything, they'd be able to knock off a few bucks. I'm just tired of add-ons. I want one license that includes it all. .I don't miss my days of having to worry about those kinds of things and I've mostly forgotten about it. Right? Like with my current employer, it's like stuff is just there and I just use it and consume it and it's fine. , there's really not, you don't have.To think about it. Microsoft gives you your licenses for their products. Uh, they, they give me that and a lot of early release broken software. Yes. That makes it so like I have to reboot multiple times a day. Yeah, that's that's pretty much how I live my life. .Yeah, sorry but kind of not. You kind of signed up for it when you took the job, Scott. I mean just saying little bit. All right with that, I don't know that I have anything too exciting in terms of news. There's even more Viva stuff. I'm doing some stuff on Viva. We might have to do a circle back around to Viva. There are new Viva products that didn't even know existed that have been announced. .Viva the one that sneaks up on you. Yes, I, I've been playing around with Viva goals a little bit lately so there is some stuff out there. How. About Viva Amplify, have you heard about Viva Amplify? No idea what it is. See exactly. I'm gonna put it right up there with like syntax indexes and syntax repositories and like all the crazy stuff you hear about like later about these products as they come together. So I don't know. We'll see if you wanna talk about Viva sometime, we can talk about Viva. We. Would just need to catch up. There was amplifying. There was one other one that was out there that I just ran across the other day that I was like, huh, who knew? Apparently some of this came from Glint. Microsoft acquired a company Glint. Mm-hmm and some of these new Viva stuff came from Glint andthere's gonna be a Viva glint now as well. Microsoft, Viva and Glint. Yeah, Microsoft, Viva and Glint I saw somewhere. Microsoft. Yeah, Microsoft. Microsoft, Viva Glint, Microsoft Adoption. like Viva's like a bunny.It just keeps having babies or something like that. Anyways, we do not need to talk about Viva anymore, but there's more Viva stuff we can talk about if we decide to talk about Viva. Done and done, we'll get that sorted. Too. And with that, I'll let you go enjoy your weekend. I'm gonna go work this weekend because I have end of the month deadlines that I need to make some progress on. Yeah. Got I got some. We're in the middle of a semester, so yeah, ,I gotta get all my like retros done and mid-semester reviews and all that stuff. So. Have fun with those. The. Work never stops. Yeah, the beatings will continue until morale improves. Let's just put it. That way. All right, well thanks Scott. Enjoy your weekend. Don't work too hard. Hopefully we'll get some non rainy weather and we will talk to you next week. As it's been getting darker and darker behind me. As I'm sitting here, I'm like, should I turn up my key light? Should I have to, my lights on .We just had a thunderstorm roll through here. Maybe it's coming your way. All right. . All good. Thanks guys. All right.Appreciate it. Thanks Scott. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 340 - A little bit of DDoS in your life
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 41:34 — 28.6MB)
In Episode 340, Ben and Scott talk about some of the takeaways from the recent DDoS attacks on the Azure Portal, a (new to them) Terraform module for working with Azure AD, and how to start preparing your Microsoft 365 tenant for Microsoft Copilot.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 334 – Converged Authentication Methods in Azure AD
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | May 18, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 334 of the Microsoft Cloud IT Pro Podcast recorded live on May 12th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and how it relates to you. Today is all about security, home security cameras, Azure AD or intra converged authentication with multifactor authentication and self-service password reset, new M FFA fraud alerts and iOS web enrollment for tune. I have absolutely nothing random or exciting to kick off with today. ,except Twitter's getting a new c e o I don't know that. That's exciting. They finally announced one. I can't say that that one is necessarily exciting either. Let me see. Um, I have been playing around with some, uh, new stuff here on the home automation front. Like I found some more ways to goof around and make my life a little bit, probably harder while like the goal is making it easier like it and it'll get easier and better. So do you have security cameras at your house, like wifi cameras or POE cameras, anything like that? Do I have them or do I have them set up? These are two different questions. I have a doorbell camera. Do you have them and are, are they wired up and like maybe you can view them in like an M V R or a web interface or something like that? So. I had not had them previously to my Unify thing. I have a unified doorbell which has a camera on it and I actually do have a Unify p OE camera that I have been meaning to set up. However, where my wife would like it and where cables will get too easily for a POE camera are not one in the same. I thought she wanted it one spot and now she wants it in a different spot and I keep looking at it and I will think, huh, and it's sitting here waiting to install. So all my stuff is unify, which makes it completely different. With the home automation side of things, do. You just do straight Unify Protect and that's kind of the only app or do you use Home Assistant with like a Unify integration and and pulling your cameras for home assistant? I use Home Assistant with a Unify integration primarily for the doorbell. I will say it's really nice because when someone knocks at the door or rings the doorbell, the kids know to go run and look at the tablet on the wall to see who's at the door because it's just a live stream of the doorbell on the tablets in the house. Are you familiar or have you ever heard of scripted. Of scripted? It rings the bell, but I couldn't tell you why or how or from. What. I'll put a link in Discord and, and the show notes. So scripted is a video integration platform and it's specifically for home video devices and security devices. Like cameras be they a P OE camera could be something like a doorbell, maybe like a Unify doorbell, it could be Ring Doorbell, could be Nest Camera, could be an Arlo camera. Like you know how there's all these manufacturers and they're not exactly the same in standards or what they support when it comes to like home automation ecosystems. So I was bringing everything into Home Assistant, but then I was having some things where I'm like, you know, it'd be really nice to have the same camera view, not only in Home Assistant but also maybe in something like Home Kit or I've been see watching the Google announcements for the new Google Home tablet, like the, the tablet that docks and then becomes a Nest hub and that all looks really cool. So it's like, oh well, like maybe I wanna do Goo some Google Home stuff in the future. So I've been playing around with that a a little bit as well. So scripted is this platform that kind of sits between the camera and then whatever else it needs to talk to. So rather than integrating your camera into Home Assistant and then into Home Kit and then into Google Home, you just integrate it into scripted once you set it up. And then scripted is the thing that integrates into all these other places. But the cool thing is, is that once your cameras are inscripted, you can do things like individual home kit pairings, individual Google home pairings per camera. You can control the quality of a stream coming out of it. Like you might find like you want like a, a medium R T S P stream for this camera over here. You might want a low one over here for performance or whatever it happens to be, but it just lets you mix and match all this stuff. So I have a just picked up a new Unify router dream machine, like the little round one and yeah, the the trash can like. The trash can like the one that kinda looks like a Mac Pro Old Mac Pro. Yep. And that one came with a deal for a discounted unify camera. So I've never played around with Unify cameras. So I picked up one of their wifi unify cameras cuz it was cheap and I was like Ah, I'll find a use for this around the house. I also have a ring doorbell at my front door and then I have some Arlo cameras spread throughout the house in various areas, you know, like looking out from the garage in the backyard and and things like that. So it was getting kind of annoying to go in and say like, okay, I can do some of this in home assistant, I can do some of this in home kit. Oh I can't do this thing over in Google Home, blah blah blah, whatever. So I pulled all the cameras into scripted, took all the time to kind of strip it back out of every place else. And now anytime I need to pull a camera in, I just pull it into scripted first and then that handles getting it out to the rest of the ecosystem in a sane way. So now like on the home assistant side, I'm not running an Arlo plugin and a Unify plugin and like all these integrations that are potentially putting overhead on home assistant cause I'm just running it in a pretty low-key Docker container. Instead I put everything in scripted and then like Home Assistant has a generic camera integration available into it. So you can just give it an R T S P I and it just pulls it out locally from like the local R T S P feed that scripted is pumping out. And I've got it all in home kit and I've got it all in Google Home. And it's kind of cool cuz I didn't have to go out and buy a bunch of like home kits, secure video certified cameras or things like that. I was able to just kind of put it all into one place and then I can still use things like motion detection sensors or like the doorbell sensor, things like that in home assisting if I want to without pulling in the overhead of the actual camera device. And then scripted becomes this kind of dedicated thing out there to do it all. Nice. I might have to go play with it but I don't have quite the camera, uh, the wide variety of cameras that you do. So I don't know, I mean I, I guess I would use it more to try to pull it into other places if I wanted to do that. I'm. Kind of a fan of this model where you can centralize like a function like hey put all my home video stuff over here and then it's just kind of one throat to choke when it comes to an issue. Or if you have to go debug something you're not dealing with like okay, well I had this integration turned on in home assistant, I was using this plugin and HomeBridge and I was using this thing over here and blah blah blah. Uh, it just gets really confusing and probably too much to deal with. Yes, fair enough. So I have, since we're talking about security, I'm, I'm gonna stretch here for transition. There's some security stuff in Office 365 some news and this is not one we talked about beforehand. We threw a couple ideas around and I just thought of this one while we were sitting here. Remember, I don't know, it was maybe two or three weeks ago we talked about how Office 365, Microsoft 365 Admin Center, when you click on Azure, ID now takes you over to the intro portal. Mm-hmm but like aad.portal.azure.com and going to Azureand clicking on active directory still took you to like that Azure portal for Azure Active directory. Yeah. To the the old place to. The old, right? So I noticed the other day I started typing, I tend to just go aad.portal.azure.com when I need to get to Azure ad I don't tend to go through the admin center. aad.portal.azure.com now also redirects you to intra and on top of all that I noticed now if you're in the Azure portal and you go to portal.azure.com and click on Azure active directory, it still takes you to the old Azure active directory. But we have a new little announcement bar, title bar at the top that says Microsoft Intra has a simpler integrated experience for managing all your identity and access management needs. Try the new Microsoft intra admin center. Which makes me think how long do you think it will be before the old Azure active directory as we know it in the Azure portal? Cuz really this is the last place, the old one is left, it'll be just intra for everything. I don't think it's long. Like it's certainly the way things are going that writing's on the wall like we know intra as a brand it has, I I think everybody's been pretty clear about that, that it's gonna be the thing and the place to go. Yep. And the reason I say not long is like we're into like as you get into the second half of the calendar year here, like May is build and then you've got Ignite at the end of the year. Like we're almost into like this weird six month marketing cycle. So marketers gonna market and if you're gonna make a push for it, why not do it between marketing season, like get it out there and be done with it. I would agree and I think I'm actually okay with this because I think we've also talked about this before where Azure active directory is technically a service in the Azure portal but it's not technically a service in Azure, right? Like everything else in Azure you have a resource that you create in a subscription and resource groups, all of that where Azure ID is the identity for all things Microsoft Cloud and you can have multiple subscriptions under Azure Active Directory. You only have one Azure active directory instance for all your subscriptions for Office 365. So can it taking it out and setting it on its side and say here's intra, here's the identity platform for all things Microsoft Cloud, for all your Azure subscriptions for Office 365, Microsoft 365, whatever term you want to use for that naming mass. I kinda like that concept of okay here's intra here's you're still gonna maybe have Azure active directory in intra, but it kind of separates it out from those two services in a way that really does make sense to me at least the way it's all architected. People. Get really hung up on the Azure, in Azure active directory and it makes it confusing and naming things ishard and hindsight being 2020, Azure active directory isn't like the right way to name that service. It is an identity and access management service that is independent of Azure but then it happens to have all these hooks into Azure and M 365 and and a whole bunch of a whole bunch of other things. The forefront name was taken for other stuff and who knows that that might not made the most sense for identity either . But yeah,I think the best thing you can do is like as you're thinking about this stuff like like don't get so hung up on the name Azure Active Directory, then just think like this is my global identity and access management solution for identity across the Microsoft cloud and the Microsoft cloud being inclusive of all things Microsoft 365, office 365, Azure dynamics, like just all this stuff. I think it's a easier to wrap your head around and B like sets the right expectation that when you go to something like intra Intra as like an Uber suite for identity, like it kind of makes sense that hey my identity and access management solution is presented to me here as well. It's just another pain of class within kind of that bigger suite of functionality. Yeah. I don't know if there's any, if they would do this for any reason but I feel like it also gives them the ability to tweak stuff intra, whether it's the UI or settings or navigation, all of that without having to live within the Azure constraints. I don't know if that would be a real reason to do it, but you do kinda get that feeling a little bit when you go over enter is that they kind of refreshed the UI a little bit to like this at an org. Azure easier to find stuff. Yeah, if you're not used to it but if you're used to where it used to be in Azure, it's a little harder to find stuff because there's this thing called muscle memory and I just knew where stuff was. Yeah, now I don't. But I think someone brand new it does some of how they're organizing it, laying it out, all of that makes sense. But it definitely does not adhere to maybe the traditional Azure branding that you used to seeing. Yeah. I think it's a good way to think about it. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates on the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees, they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I N T E L L I G I N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So this was another article from a couple days ago May nine. There was a modernizing authentication management since we're talking about authentication and there have been two updates around authentication in intra Azure active, now I'm gonna have to say intra slash Azure active directory, like I say, office 365 slash Microsoft 365. This is not going down a good path. But the general availability of converged authentication methods was one announcement in this is one, I think we talked about it in preview before too. Converged authentication methods is simply combining MFA and self-service password reset methods. So MFA, you could do text messages, authenticator app, Fido keys, all of that. And then self-service password reset actually could have a different set of values for some of those things like if you're using a secondary email address, they've kind of combined those. And now both of these are managed in one policy alongside all your passwordless methods like 5 0 2, security keys, s, cba, newly added methods, SMS voice calls, third party. So they're kind of taking all the MFA stuff, the self-service password reset stuff, cramming it all together, that's the converged authentication. And then they also announced the public preview of modern MFA fraud alert bringing configuration into the authentication methods policy, integrating user reported signal of suspicious MFA prompts with identity protection. So some stuff there around in this article, I haven't read it fully ,I just saw your message and now you got me like I'm on. Johnny on the spot. Let's go. Yes. So updating some of that suspicious activity report risk detections when it comes to authentication M FFA reporting suspicious activity functions and parallel with the legacy M F A Fraud alerts. Fraud alerts. So during preview you can have both of these in place. I can post a link to this. What is going on? You're sending me messages, stuff is crashing, my wife is calling. All of the things are happening at once. Uh. You know there's a glitch in the matrix. Yes. So a couple a preview to play with in terms of mfa. It looks like in January the legacy MFA authentication, self-service password reset policies are gonna be deprecated and you'll manage everything together in this converged method. And then yeah, the suspicious MFA prompts because this is getting to be a thing. I know there's a lot of people that still use push notifications because I still authenticate to a lot of tenants that still use push notifications and the whole mm-hmm , it's not,I'm trying to think of the proper term but essentially prompt exhaustion where people will hammer when you have that method and hammer it over and over and over again until someone just finally hits approved cuz they want it to go away. So there is absolutely something to be said for watching risk detections for MFA prompts and security risks with M FFA prompts. This is not related to the article but go to the whole number matching passwordless thing or use Fido keys M FFA and just the whole push notification. Approver net doesn't seem to be maybe as secure as it did a couple years ago before people were tired of all the notifications. .I will say I've always really liked the risk reports that come out of Azure AD for suspicious sign ends and things like that. Like anything that builds on that is really good. You know I, it was always just hard to swallow the licensing fees for like P one and P two to actually get access to those reports and you know kind of get things to where they need to be or where you would want them to be. Like it makes for really cool demoware and then all of a sudden you have to justify the pricing for it and it's like uh, it could be a little bit harder to do for you know, an organization of a lot of people unless you've got some decent pricing or some kind of break somewhere. They. Didn't say anything about licensing here. I'm assuming a lot of this is still gonna be all Azure DP two it appears. So yeah we'll put this link out there if you wanna go check out these reports, start thinking about MFA and SS self-service sspr and your converged authentication methods. A couple things to dive into. Yes and. I think it's important that you look at those just you know, because the legacy stuff is going to be deprecated at some point. Like you just need to move away from SMS and voice and get on board the authenticator 5 0 2 train. Like however you choose to approach that. But I think that's another place that Microsoft has been pretty clear about, like very heavily like hinting that you should think about getting away from these things cuz they're not gonna be there forever. So drive behavior change now. Well you can. Yes, absolutely. What else do we have? I feel like we had some other, oh I had another security one. I'm gonna keep going with the whole security authentication stuff. Keep 'em coming. Keep 'em going. This is one that showed up on the roadmap today Scott. This is feature ID 1 0 9 5 5 9 Microsoft 365 roadmap. We have talked at length about the importance of following that. We have an episode where we talked about an RSS feed you can follow it on but this is around Microsoft Intune and iOS web enrollment, not iOS company portal enrollment and it just showed up today. It's still in development. Oh no, this says release phases, general availability. So on the announcement it says release phases general availability in the actual categorization it shows it's in development and it says the rollout will start July, 2023. So I think this is technically still in development but this is changing Apple's device enrollment for B Y O I always saw thought it was B Y O D for bringing your own device. Apparently it's just the form of enrollment for bring your own ,bring your own something. But in the past it's always relied on the company portal app and I've seen this like pushing it out. It always adds the extra prompts, app downloads extra steps of go download the portal and type in usernames and passwords and all that. Web enrollment is gonna be the new streamlined B Y O enrollment. Bring your own enrollment flow. Can we do B Y O D? We can go with B y. Yeah I'm gonna go with somebody. Character. Yeah we can, it's your show. We can do whatever you want. Our new. Streamline B Y O D enrollment flow. So JIT registration, web enrollment, again I haven't seen this previewed demoed anywhere. Just reading between the lines it sounds like you're just gonna be able to use your browser. Maybe it's gonna force you to at least use Safari for this because Safari has all its hooks into iOS in ways that other browsers don't. But it does sound like you're gonna be able to enroll your own device in Intune using the browser and the company portal will no longer be required to enroll an iOS device with Intune, which would be very nice. Nice if you don't need the company portal but I still think there's a lot of organizations out there that probably do need it or they want it right just to push kind of bespoke apps or you know, internal whatever that that you want to get out the door. The other nice thing that I actually use the company portal for a lot is it's a much nicer experience when you're managing multiple in-tune enrolled devices. So like in my case I have my phone mdmd, I have you know several like work PCs that are mdmd, I have a personal PC that's mdmd over to my employer. So like if I ever want to take like my personal PC out and actually like purge the record and get it out all the way, like I found sometimes it's not enough just to like unenroll from the device. Like you gotta go into the company portal and kick things around and it's just easier to use than the website or find like where your devices are on the website and how that stuff comes together. So I I, I don't know the company portal like isn't that bad as long as you structure it the right way and you explain the flow and kind of like hey these are the steps you're gonna go through to do you know A, B and C and, and that gets you where you need to be. I haven't seen the company portal being a big blocker. Like it's certainly a nice city like hey make it easier for everybody but don't throw the baby out with the bath water on that one. Like there might be other things that necessitate you bringing the company portal back later or still encouraging users to install it post enrollment, you know, however that goes for you. Yeah I can see that. I agree. Like there's absolutely some nice features in there. You can use it to remotely wipe your devices if you have those multiple device enrollments and do some remote maintenance security type stuff in those remote devices. I am kind of cur like I wonder if the company portal will end up being more of company owned devices. I guess for me I think of company portal when you're doing the B Y O D scenario, it's like you can get pushback from users on why do I have to install this corporate app on my personal device for I'll bring my own device type scenario. And I think it's similar like because. You've already mdmd it and given it over to your employer anyway. Like bring your own device is your device that you just made your employers good job everybody. Uh, like that's why. But what about like ma'am, if you're doing like the application management and some of the stuff where you're not fully handing over your device, you're just handing over the the application management and it's still gonna force you. Like there's some of that with enrollment. I don't know, I guess there's always that a little bit of pushback from users sometimes or from some users. Every. User wants their employer to buy them a device if they're expected to use it for work, right? Like I, I would very much like my employer to buy me a device. They don't, right? Like the reality is like they give me a method to bring my own and right, it doesn't taste very good and that medicine doesn't go down smoothly but it's like what am I gonna do not bring it? Like I, I can't not be mobile and there's still things that I need to participate in. So it's a real catch 22, right? Like ideal world your employer would provide all the things that you need to do for your job. Unfortunately we don't live in an ideal world because all the people who do things like device enrollment bent over backwards to make it so that as an employer they don't need to give their employees devices. This could be a whole interesting conversation on its own. I have this mixed feeling too because like if my company, if I was working for a company, my company does buy my device but my company's me. So .In your case, yes. I'm a little different but let's say I was working for Microsoft, there's a part of me that's like yes absolutely I want them to buy me a device but I don't necessarily always wanna carry around two devices. Like do I really wanna walk around with two phones in my pocket? I did have, I don't know, 12, 13 years ago a company that they bought me a device and I was very much in that boat where I had two phones everywhere I went I was like I don't really want two phones, I don't want to give up my personal phone number cuz I have actually had the same cell phone number for like 20 or 23 years now and I didn't wanna give it up but I also got tired of carrying around two phones. But then there's also that other part of me, one, I don't want my personal device to be controlled by my employer where they can wipe out all my pictures or block my camera or dictate what apps I installed. But I also don't wanna just have a company device where they can say, well you can't use your device for this. So it it is, it's definitely that interesting scenario of two devices or one device but then who owns it and what can or can't be done on that device based on the ownership or the control. I grant out of necessity. It's interesting. If you can solve this dilemma for the rest of the world, like you might be right up there with like some of the, some of the greats. Like you could be the person, like the very, the only next thing you could do that would be better would be like leading us all to world peace. I have no aspirations to do any of those. I think from my perspective the application management in Intune is the closest that I've come like let me bring my own device only make me do application management and I don't care if you control email or the data in teams or some of that in on a personally owned device but I don't want to hand over for full control. Well of all of a sudden you kill my camera block my camera, block me from taking pictures, all of that type of stuff. So yes, I don't know. That's my opinion. I still am a big fan of ma'am over full device management. Same like when I've been in those roles and the ones who's making the decision, I have bent over backwards to say we are not going to do U MDM for personal devices. Like we'll go down the MAM path and do it that way. Like we want to control data at the application level and like devices are devices, it is what it is and if somebody is at the point where like we think third device needs to be secured in that way, then yeah we should really think about like allocating that and getting it done the right way. So. I concur. And with that Scott, we can wrap up our podcast on security and security cameras done. So. Next. Week go and do your weekend. Maybe we'll. See next week. Alright, we'll come up with some Azure stuff for next week and we need, we'll we'll figure out some recordings. We're not gonna be live some of these cuz we've got some vacations coming up. But we will continue to make sure we get a podcast out every week regardless of vacations. Just not consistent in when we record them, so. Fair enough. All right, cool. Well. Enjoy your weekend. Yeah. As always. Thanks Ben, appreciate it. All. Right, thanks. We'll talk to you later Scott, if you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more IT pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 334 - Converged Authentication Methods in Azure AD
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 29:44 — 20.4MB)
In Episode 334, Ben and Scott take a detour into automating your home video devices/security cameras with Scrypted and then get back on track with some enhancements in Azure AD authentication methods and Microsoft Intune.
Like what you hear and want to support the show? Check out our membership options. (more…)
Episode 333 – Azure AD and LAPS in Preview
by [Scott](/content/author/scottmsclouditpro/ "Posts by Scott"/index.html) | May 11, 2023 | Podcast
Blubrry Player
|
Auto Scroll
Welcome to episode 333 of the Microsoft Cloud IT Pro podcast recorded live on May 5th, 2023. This is a show about Microsoft 365 and Azure from the perspective of it pros and end users where we discuss a topic or recent news and hub it relates to you Today we start out by giving our opinions on Teams and Outlook, opening links in Microsoft Edge and talk a little bit about some other browsers before diving into Azure AD News. In this last week there have been a few announcements around Azure AD with the preview release of Windows lapses for in-tune and Azure AD as well as Azure AD certificate based authentication or CBA on mobile Now being generally available. I'm curious what you think about this. I've seen the headlines, I think I understand what's going on with this, but I don't know that there's any demos out. It was more of a announcement in the message center and I've seen a few people ranting and raving about this is Microsoft Teams plans to make users open links and Edge and apparently this is both Microsoft Teams and Outlook that when there's a link in one of those two programs, that's gonna force you to open it and Edge and everybody is up in arms that Microsoft is now forcing edge on people. However, based on how I'm reading this, it sounds like it's doing it like Edge within Outlook and Teams cuz it talks about opening, like say you get a link in a message, I email you a link or I send you a link in teams and you click on it to open it instead of popping up like a brand new browser window. It sounds like from this announcement that it's popping it up within Teams or an. Outlook. It's not. It's popping it up. It's not in edge. It's in edge and it's showing cuz it talks about showing things side by side. So it's popping it up in edge and then showing teams and the link side by side. You know the new office browser bar that's on like the right side and edge. So it pops open with the email, say I clicked a link from an email, it has that email and Outlook web view and then the link rendered on the left. Yeah. Browser. Bar. Yes. So the page is in the main area and then the team's conversation or the outlook is in that little toolbar thingy on the right? Yes. Okay. Then they're probably justified that that's stupid. Yeah, it's not a good way to to do it. Yeah and I, again, I didn't look, I kind of skimmed through the articles and I was, yeah, I couldn't tell from the articles and what I had seen if it was popping it in the client or popping it in the browser itself. I would agree this should not pop it in the browser. You should have an option. Okay, we can be done with that one now, but it's, I'm surprised they're trying this cuz I feel like they always get in trouble with their browsers and trying to force their browsers on everybody and then the EU goes in, slaps 'em on the wrist and they have to go undo it all and then they go try to redo it again like a few years later. ,I like a lot of Microsoft stuff but I've heard what is it, the definition of Insanity is doing the same thing over and over again. Ye. Yes. And not learning from your, it's something like that and not learning from it. I. Just don't know sometimes about these things. You know like last week we chatted about the marketing messages for conferences showing up in teams and SharePoint and all these various applications and this is very much in the same vein kind of thing. Like don't give me marketing for your own stuff or like it's great, it's fine if you wanna be helpful, be helpful, but as soon as I turn it off, don't come and try and be helpful again and again and again and again behind me kind of thing. Like stop forcing it down my throat. It's like Edge is for the most part, it's like a decent browser but becomes a really degraded experience when all of a sudden hey here's the new office bar, you know? You know on the right side of edge when maybe you're not an office user, like not everybody is, maybe you don't need that. Maybe you don't want the big Bing button there. By default maybe in the enterprise version of Edge, like you don't want to have Bing shopping bot following you around and offering you coupon suggestions. Like , it's kind of a hodgepodge thing, right?Like and it's very like micro softian that it's one of those everything in the kitchen sink kinds of products. I think it's really unfortunate that they do that at the expense of user experience. Like you know, if you wanna be a viable replacement for Chrome, you gotta be less creepy than Chrome. Not more creepy and it's all going the other way, which isn't the best way. Yeah, I was hoping Edge was gonna be nice. Although I will be honest Scott, I have been using Arc. Have you played around with the ARC browser at all? I have played around with Arc a little bit, so you sent me an invite to it. So Arc today is a Mac os Mac only. Mac only. Yeah. Web browser and it's gonna come to other platforms at some point. I don't know if you saw this, so. Yes and there was a tweet today about it hinting that it was gonna come to Windows like in the relatively near future. I will put a link to a a, a Reddit thread on arc. So Arc as a browser is interesting. If anybody wants an invite hit hit up Ben on on all the socials and he'll help you out. Or I guess I have a couple invites now as well that I'm probably not gonna use for anything. Yeah, you have some now too, but either of us. It's an interesting browser. It's an interesting take on the concept of a browser and having spaces within a browser and bringing, I think like PWAs kind of in line into a browser. It's kind of interesting like the way you interact with your mail versus YouTube versus a set of web pages that are in like a tab group, which is a space, things like that. One of the cool things the ARC team is doing is, or they're gonna try and do, I have no idea if they'll be successful on this . So for Arc on Windows,they're basically going to build their own custom like bundled version of Swift and bring that over to Windows. So it's kind of this um, this this very ambitious thing that they want to,to go ahead and do. So they want to build a swift tool chain for Windows and sometime in 2023, the timing isn't exact but basically what they want to do is they want to build their own custom compiler and debugger for Swift on Windows. They also want to build a native vs code integration and build a bridge layer to do swift fi, swift bindings over to the built-in WIN app s stk. And then they, once they have all that in place, right, like they, they can port their code over, they can compile, debug, all those kinds of things. They will actually be ready to port Arc over to Windows. So basically what they're looking to do is design, build and ship a tool chain to develop cross-platform Mac and Windows apps that are programmed in Swift using Visual Studio Code. The ARC team, which is the underlying organization that runs, it's called the Browser Company. It's not a big company , it seems like a very,a very large endeavor to go ahead and push through, but uh, we shall yeah, see how it goes and where it lands. I mean I wish I'm y you know, best of luck. It's always cool to see new technology come through like that. I imagine there's a whole host of wonkiness that comes along the way with that. For sure and I've been using it for two weeks now. I've been really liking it. I won't lie, I said it to my default browser, I'm like okay, I'm gonna dive into this for two weeks and try it. I've actually been a big fan of it and I have no intention at this point in time of switching back. We'll have to see. It's been a good experience for me to this point in time. I have a guest on the podcast with me today, black eyed Jack, Jack, he tried to catch a swing with his face. It did not work out so well. .For those of you that can see. I see the lock on your door is working really well too. It. Worked well. I didn't lie it so I'm, it's just me and him home for a couple days while the rest of the family's out and I didn't wanna lock him outta my office since there's no one else here. Security through obscurity. I got it. Yes. Let us know about the ARC browser. So I was going to mention this, I'm, I want to go back to the edge thing and then we'll dive into our Azure ad topic. So how come Microsoft gets into all this trouble for it and Apple got away with like forcing Safari on you on all their devices for so much longer and even the iPhone, I mean you can switch it now right on the iPhone iPad it sort of lets you switch your default browser and you still see all this stuff about opening Safari and then it opens in the default browser. But to be fair, apple forced Safari on mobile devices for a really long time and never really got this type of blowback I guess from the community that Microsoft does when they try to force edge. I don't think either one is right. I don't think Apple should do it, I don't think Microsoft should do it. I want to be able to pick what I want, but that aspect of it has always befuddled me. They're. Very different things, very different ecosystems and different units of scale when you measure them. So I guess for Apple, when you say they used to force people into Safari, they still do. So WebKit is the underlying rendering engine on iOS. If you're a third party browser maker, like say you're Microsoft building Edge for mobile and Google building Chrome. Chrome for for iOS you still have to use Apple's WebKit rendering engine in the background. So you're basically a shell on top of Safari On's top and that's the state of affairs today. So until Apple builds in side loading or something else, like you really can't bring your own rendering engine like Google couldn't bring Chrome over with Blink or something like that. I, I think some of it is you and I live in the United States where it's very much like an Apple bubble. Like iOS is a popular thing here. Like everybody I know who has a phone has an Apple device like and but I mean I've got 'em all over my, like I got an Android phone sitting next to me but I only have it sitting on the desk for like testing and playing around. I don't use it day to day. Like my daily driver is an iPhone and I've got iPads and all those kinds of things. As soon as you get outside of the United States, that's not the case at all. Like, like. It's all Android. Yeah, from a pure like hey let's take a look at the global market and kind of economies of scale and things that are going on out there. Android is magnitudes larger than iOS, it's it absolutely it's the right thing to do to say like hey, like why is it this way? But saying why is it this way? Cuz like Apple's got a monopoly isn't really, I don't know that it's the best lens to look at it through. That. It's that cuz there's such a small market share compared to the people using teams and Outlook and Edge getting forced on 'em. And I guess to your point, a lot of this stuff ends up coming down from the eu, not anything in the US and if Androids are Apples not that big over in the eu, they probably aren't caring that much about it. I just real quick kind of Googled around for a quick one here. So mobile operating systems share worldwide in Q1 2023 was Android at 71.65% of the global market and iOS at 27.71. I guess that makes sense sort of, although I still think it should be if one gets in trouble, the other one should too. But any who, we don't need to spend our entire time talking about browsers. browsers are fun, they're not a bad thing to talk about and.They're very quickly turning into the center of everything we do. Like I look at the amount of time I spend in the browser and even the amount of time I could spend in the browser, if I didn't care about desktop outlook or office apps, I could probably legitimately spend like 95% of my day just in a browser and do all of my work right in the browser and websites and all of that. Which is why I need like 16 gigs of RAM dedicated just for my browser. .It's an interesting thing so I, I don't know if you've noticed this in just kind of the change in the way you collaborate with people. I was doing something Uhhuh earlier this week. We were talking about Power BI and they, okay, they wanted some help putting together some Power BI reports like they've never done Power bi. I know where this is going. I was like, okay cool. Like happy to show you and you know, let's set up some time, put some time on my calendar, like we'll go through it and do it all. And we were kind of talking about prerequisites like what are the things that you should have in place ahead of time to make sure that this is a useful session for us. So you know that Excel notebook that has the tabular data, make sure you have that available, put it in a shared location on SharePoint or your OneDrive. Make sure you bring your Gusto queries, your SQL queries, like all those things like bring those to the conversation. Yep. And oh by the way bring Power BI as well Windows. And when you say that to somebody and they're living in a web first world, like it was a little bit of a, the first question I got wasn't like, do I need the desktop app? It's like can I, it was, can I start from the web? I'm like no, let's not do that. Like let's go get the desktop app here. There's a 64 bit version of it, have fun, please. Like go grab that thing. Yeah and it's a different way to think about it. Like in the world of PWAs, all these kind of mobile first things like I guess I always, I come from a place where I'm apt first for everything. Like I don't want, I do everything I can not to use a website first and I'm slowly recognizing that there's this whole other universe of folks out there back to Android versus iOS, right? People approach things in different ways that right? Yeah. Like that it's a not a desktop first world, it's a mobile and specifically like online, like web-based world first. That's a big pivot point for me in my head, right? And and it's something I really have to like try and wrap my head around and and be able to grasp. So. I would be fascinated if we can find somebody that has some insight into Power bi, why it has actually reverted unless you know why it's reverted to a Windows app first. Because I remember when Power BI first came out, I was able to do a lot more in the browser then than I am today in terms of like setting up data connections and creating those initial dashboards and the power query and all of that. I re like I distinctly remember doing all of that in the browser and one day I went in to do it and I was like wait a minute, it's all gone in the browser. I actually have to start the desktop app now for 99% of what you do in Power bi, you absolutely need Windows. Do you need to go download the desktop app and Windows 10, windows 11, do everything there, publish it up to Power BI and then you can make minor tweaks in the browser. But I feel like that's one app that has actually gone backwards from the functionality available, at least from the creation authoring standpoint and what was available on the web to having to be more desktop first. I don't know if maybe it is, it's a, the massive amount of data or the processing. I'm curious if you know or if anybody knows that is listening. I don't know. I would bet a couple of things. So there's actually a pretty decent comparison on the differences between Power BI desktop and Power bi, the service kind of like the website that you would go to if you were going to be web first. So one of the things that really stands out to me there is being able to not only transform your data but also shape and model it. And I think that's gonna be better suited to desktop apps, especially the way Power BI does it today, right? Like where you might have a backend view for your data sources and then you actually have your modeling view and you have this kind of relationship structure that can be changed on the fly and sometimes it can be one-to-one, one to many, many to many. You can have bidirectional things like honestly like that's not something I want to mess around with at a Microsoft interface for doing like data modeling on the web. Like I've already tried VIO on the web and that's horrible. Like for things like that I don't even want to do it with a live connection. Having to tie things together. I think another big part of it is probably just performance and uh, kind of Perth and scale. So when you're doing things like you're say creating a new DAX measure or you're creating calculated columns, you are really kind of asking the local client to do a whole lot on the fly. Like usually when I'm working with Power BI reports, I'm working with data sets with at least a million rows if not tens of millions sometimes. So it's not an inconsequential amount of data to have to churn through and kind of figure out, like I, I wouldn't wanna have the overhead of waiting for my web browser to render something like it's bad enough having to wait for the uh, power BI desktop app to catch up with you. And then the the, the final one that stands out to me is data sources. And there's always been this disparity between Microsoft tooling and the, and the ability to bring in data sources. So things like well take like Excel on the Mac versus Excel on Windows and what you can do with being able to do a link data source and like pull in acoustic connection or connect to another notebook and and bring in data, things like that. Like it's a varied experience there and it's really limited by the client and what it can connect to. So I'm willing to bet that you can just write a whole ton of different connectors on desktop and iterate on top of them much quicker on the desktop side than you can on the service side. And then on the service side, like you don't need the authoring connector experience, you really just need to support like the gateway or connectivity piece. Like you're almost down to like ports and protocols at that time over the actual like engine to do all the stuff. So. Right. And then I guess from the data refresh standpoint, if you're doing scheduled refreshes or manual refreshes, you're not as worried about it refreshing quite as quick cuz you're not trying to actively work with the data live to formulate it. It's just go refresh all the data re-render and if you're doing a daily refresh at 5:00 AM or 11:00 PM who cares if it takes 15 or 20 minutes to do a day to refresh? Exactly. I guess that I can see that. And yeah, I wonder if it, if that was part of the web stuff is it just was too slow, it was taking too many resources on the back end and they said let's just author it all the desktop top. . I don't know if you've noticed but uh, you know,for all the web apps that Microsoft pushes on us, they're not always the most performant things. Like given the choice of working in like, sorry, Google Sheets versus Excel .I would wanna work in Google Sheets every day. Does it do everything Excel does? No. Does it work fast and consistently? Yes. Can I say the same about Excel on the web? I cannot, same thing for like Gmail and Outlook teams versus Slack. Like all all these things, right? Like they, they're tools for the masses that have known rough edges and you just kind of live with 'em and plot along. Yeah, well and I think some of the difference there, I'm going to assume between Excel on the web outlook, I mean Microsoft came from a server first on-premises non-web application first scenario and kind of has molded all their applications to work on the web versus all these newcomer, I mean newcomers, Google's been around for a while, but even them G Suite, slack, all of those kind of started with internet first browser, first web first mindsets I would say very much so where Microsoft has evolved from desktop to web. Do you feel overwhelmed by trying to manage your Office 365 environment? Are you facing unexpected issues that disrupt your company's productivity? Intelligent is here to help much like you take your car to the mechanic that has specialized knowledge on how to best keep your car running Intelligent helps you with your Microsoft cloud environment because that's their expertise. Intelligent keeps up with the latest updates in the Microsoft cloud to help keep your business running smoothly and ahead of the curve. Whether you are a small organization with just a few users up to an organization of several thousand employees they want to partner with you to implement and administer your Microsoft Cloud technology, visit them at intelligent.com/podcast. That's I N T E L L I G I N k.com/podcast for more information or to schedule a 30 minute call to get started with them today. Remember intelligent focuses on the Microsoft cloud so you can focus on your business. So all that being said, that was a good. Ramp for you. . That was a good rant. Do you wanna talk about Azure AD today too? Yeah.We can probably fit in some Azure AD stuff. Now fit in some Azure AD stuff. So this is one Scott, this was end of April really I guess only a week ago. And this is an interesting one because I've actually had a couple of clients come to me and directly ask for this. They came from the on-premises windows management world, GPO servers, ad domain connected to computers, all of that and asked for, they're like what's Microsoft's alternative if you're gonna do Azure AD for lapse or this local administrator password management and setting all that up. And there wasn't a good story. I've come up with workarounds where you could do like a request with a user account that had its password recycled nightly and was a device admin and Azure ad. But then really you're sharing the same account among all your devices. So it's not really local. It's like if you actually knew what was going on, you'd be able to use that administrator password on any machine, not just your own. But within the last week, windows has now rolled out Windows lapse feature into public preview for Intune and support for hybrid Azure AD or Azure AD joined. So if you're looking for this local administrator password feature and being able to roll this out, again not GA yet, but in preview you can now do this natively within Azure AD and they have a good article, we'll post it out here pretty straightforward in terms of going in and setting up your device settings and Azure active directory going under account protection and setting up a lapse windows lapse local admin password solution within one of your endpoint security profiles. And then going in and setting up some of the basic information around password complexity, administrator account name, password lengths, post authentication actions. So there's a quite a few configuration options you get right out of the gate. How long password age days are in there backing up the password where you wanna back up the password to Azure 80 only or I'm gonna guess active directory is another option in here. But this article does a good job at kind of walking through how you would set all of this up within Intune. I will say it is Intune so you are gonna need Azure ad premium. This is not one you're just gonna get for free out of the gate. Interestingly enough you can do it without in tune. Can you? You can. I did not see that in the article. I missed it. It's a long article. It's not in the article but it is in the official documentation like. The learned documentation. Yeah, so a couple of things. So client support for this. If you're going down and you mentioned preview status, which usually implies you've got some kind of subset of clients out there that it's gonna work with. You do need to be on specific versions of Windows clients. So Windows 10 you have to be on the April, 2023 update April 11th, 2023. Same for Windows 11, both 21 H two and 22 H two. There were also updates released on April 11 for those. And then you need to be on Windows server 22, uh 2022 rather or Windows server 2019. So as long as you meet those kinds of things, you're okay. So the the actual article for getting started with this, it has a call out in there if your devices are Azure active directory joined but you are not using Microsoft Intune, you can still deploy Windows laps for Azure active directory in this scenario you must deploy policy manually for example, either by using direct registry modification or by using local computer group policy. And that's about it. So yeah you can do it without in tune, it's just gonna take more on your side to get it done more. Work. Well and that is an interesting note cuz if you're looking at the very top under the prerequisites for laps, it is an in-tune subscription as a prerequisite but apparently that's like an optional prerequisite then based on how you wanna push it out. And then Azure active directory free which is the free version which makes sense. And I guess here it does kind of say it under there too with Azure ad free, you can still use all the features of labs but it's more like you said then buried further down. It's the automatic policy deployment aspect of it that you would get within Tune. Yes. Your experience is going to be different when it comes to policy management, policy creation, all those kinds of things. But uh, if you are not in tune inclined and you're like ooh this is interesting, there is a path forward there. Well. And I guess the nice thing about that path forward is you could test it out. Like if you have a couple devices, you wanna see how this works, test it all out without having to use Intune to push out the policy, go test it on your device, set up laps, see how this works, set it up on a test device if you really like it and you don't wanna manually push it out to all your clients. Go look at. I'm curious, so not trying to skirt licensing requirements, what would happen if you'd go get the in-tune trial because you wanted lapse for all your devices, pushed it out to all your devices and then let your trial subs subscription expire. Like technically the policy's still there, right? Obviously new devices if you don't have in tune it wouldn't push 'em out to new devices. Yes. But I don't know that it has to continually call back. That's. A good question. I don't know what policy peel back looks like when a trial ends. Does the service reach out right before? I don't know. It's a good question. Ends somebody test that out because I'm not about to test that out anywhere cuz I don't wanna blow up a bunch of devices unless they're standing one up and just try it. Shoot. Your shot. I'm trying to think if I've had some, I don't think it actually peels it back because I think it's a lot like gpo. I mean GPOs stay applied, you wouldn't get any new updates to it but once you push out those settings and update cuz really it's updating the registry, right? It's not like it's reading it live, it's updating the registry. The registry's gonna stay set until it says don't update the registry anymore. Correct. Yep. Yeah but like you said, once your in tune's gone, any new devices, any changes to it, if you ever wanted to pull it back you'd be outta luck. But this was a nice one to see come again especially cause I've had a couple clients come and ask for this directly. They're like we're all Azure AD joined, we use labs on-prem, we don't have on-prem anymore. What's our solution? It was, it's hacky, you can make some stuff work but it's definitely not anywhere near that functionality that you would normally get with lap. Yeah so I I I can think of like beyond just base deployment, the other nicety that you would get out of having Intune licensing here is going to be reporting both at the device level. So hey did this like individual device have this thing pushed to it and how is it configured? What's at stake? Yep. But there's a uh, effectively like a workbook I guess it's a dedicated workbook inside of your endpoint management in Intune for Windows lapse management as well. So not only can you see at the individual device level and report there and see what's happening, but you can also get the all up aggregate view of your kind of device posture and how that deployment has gone for you. Which is probably more than a little annoying to do in any kind of like at scale way, you know if you've got more than a handful of clients. Yeah. Well and the other thing within Tune is you get all the other in-tune features, right? You can go take advantage of conditional access and all your other policies and all that. Yes. None lapse related. Absolutely there's a lot of benefits to Intune. And did you also see Scott, this is one of the first times I think I've seen this, that this is also supported for G C C high like day one it came out to the public cloud and GCC High at the same time. that is Cindy one. I don't think I've seen that too much. No.It is, I'm guessing it's because I don't know that there's actually much new here. I mean Windows lapses has been there forever. You've been able to do with G P O and it's really just bringing that policy and then there are a couple features that came like the password retrieval is within Azure ad, but I think a lot of times with GCC Hyatts because they have to get certifications for new features or new code or some of that. And I'm wondering if this was straightforward enough that there was not many hoops to jump through for approval for gcc or maybe GCC is the one that's always been asking for this. So they just did it for everybody at once. Because I can also imagine that this would be a feature that a lot of those GCC high gov clouds, all of those different types of higher security tenants would actually really want or be interested in. Where did. You see the note about GCC High? I don't see it in any of the, at least the doc that you had shared. It is not in the doc I shared it's in another doc. Uh, let me, I will send you this one. It's in the, is that the documentation? It's in the learn documentation. Oh it's. Under You search specifically under under Intune support. Yeah, it, I see it there. GCC high right there. So, so what else has come to Azure 80 Scott? There's been a few more. G CCC high not G C high below. There's been a few more Azure AD things that have come out in the last few days. Do you wanna do one more? Sure. We can do one more. I I think there's a bunch. So, so uh, I'll put a link in the show notes. There's actually an article that was published about a whole bunch of Azure ADSS slash intro features that came out. One of the more interesting ones that kind of came across was the ability to do certificate based authentication with mobile devices. This is something that was at least uh, certificate based authentication or, or CBA was announced back at Ignite 2022. So it's been kicking around for a while now but now it is also generally available on mobile. So the cool thing here is it supports not only on device certificates but you can also do external security keys. So that could be like your N F C U B key, your iOS or your Android device, all that good kind of stuff. So I think for B Y O D customers like bring your own device, this is a really nifty capability to have. Yeah, I had missed, I saw the headline, I had not had a chance to read this article yet before today cuz it came out yesterday. But yeah, the Azure AD CBA and iOS mobile with the u b key CBA on Android with the UB key. I'm gonna have to go play with this in a little bit and test it out but this is another one. I do have clients that use cba, especially mobile devices being able to push out CERT based off or and they do it for a lot of their email being able to push email config out to manage devices using cert based off. So this is one we're gonna have to look at trying to start rolling out and playing with there. I always like giving you a new task. Add your sticky note list. To go play my sticky note list. That never gets any shorter because you add them quicker than I can get them done. That's the one. Yeah, that is a good one. And now Scott, it's time to go automate our podcast synopsis with Azure Open AI G P T .This was another article that came out, I haven't read it. It's a whole article from Microsoft and how you can do pod abstracts with Azure Cognitive Services and open ai. We should try this. We can get Synopsis, you don't need to write our two sentence pod descriptions anymore. You can let open AI do it for you .You can let open AI do it for you. You can do, I've seen folks do this with Whisper, I don't know if you've played around with Whisper at all yet. I've not played with Whisper yet. So Whisper. Is an AI juice transcription engine for audio. So you take like a Wave file and you pump it into Whisper and it runs the model on top of it and it spits out SRTs TXTs. Uh, you know, like if we wanted to caption our YouTube videos for this podcast, we should really just slam 'em through Whisper and let 'em go and do its thing and it'll do a better job than like auto captioning in YouTube or anything like that. So yeah, you can totally just take the output from something like Whisper and pump it into chat G P T and then come back with a summary for you. It's kind of interesting, I don't know if you've been paying attention to like one last quick digression here. We talked about Home Assistant a couple weeks back and all the home assistant updates that have been coming out lately are focused on really like voice improvements, which I think is kind of interesting. So they've started to add all these kind of base layers and plugins to Home Assistant for being able to do voice integrations in multiple ways. So one is, you know, like if you're talking to your little device in the other room, you wanna say like, Hey device do this. So your device basically needs to do voice transcription and bring that back and pull it back. So the way the home assistant folks are doing it is they're using some of these open source models and transcription engines like Whisper to actually do that translation , which is, which is kind of cool.So like the latest versions of Home Assistant basically have whisper built in. So that's when you're talking say to your mobile device and you're signed into the app and you're saying like, Hey do this, do this, do this. It's actually taking that and it's recording that audio in real time, passing it through whisper, getting an output back. And then they're using large language models to take your request. Like hey Dingus, turn on the lights in the living room and Uhhuh, run it through an l m to have it output a common command.So if I say, Hey Dingus, turn on the lights in the living room and you say, Hey Dingus, turn on the living room lights. Those ultimately mean like the same thing, but there's probably just one common shortened command to push them through. So they're doing it both ways. They're taking, they're taking human voice and they're transcribing it and then they're taking the transcriptions and they're passing them into AI models and they're having the AI models distill down to common commands that then can be executed within like home assisted as an engine. Which is actually like totally, it was kind of like, I was like, oh yeah, like that's how all these things ultimately work at the end of the day. But it was kind of cool to see it just spelled out that way. So I, I'll have to see, I saw some good videos on YouTube about the latest update. I'll see if I can pop one in the show notes for for you. All. Right. It'll be interesting to look at that and see how that continues to change over the coming months and years. So the captions, speaking of captions, I've been doing them in YouTube, Scott and I need to go look Da Vinci Resolve is what I use to do the editing of our YouTube videos and in their latest version they came out with 8.5 beta one, they added right in there generating captions from the audio and I don't know if they're using Whisper or something else in the backend, but I can go edit all our podcast, edit the podcast together and then say go make captions for me from the audio tracks in it adds a caption track in there and then when I export it I can export the caption track as a V T T and they have like four or five different caption file types that you can generate. So I've been doing it, but I just do it right alongside editing the video cuz even these video editing tools are starting to build that language transcription right in, I. Forget which model they use in Da Vinci but it's, they kind of made it like the serviced script if anybody has ever played around with that. Yeah, I didn't look, I just saw it showed up in there so I was like, ah, it should, good. Try. I don't think they're using descript in the background but it's, it's totally something descript ish. So the Da Vinci stuff I've seen, I haven't played with it in person, like you've probably got more hands on with it than me, but from what I've seen of it, it's, it's basically doing the same kind of thing. Take the audio, translate it through, put it into the text. But then the really cool thing like the the nifty thing about something like descript as an engine, so descript is basically an audio really like kind of spoken word, very like podcast focused thing, but it lets you just in real time edit text and then it does like the underlying clip edits for you on the other side. So if you wanted to, you know, strike an entire sentence out, you just strike the sentence in descript and then it strikes all that audio automatically clips it and shortens it up and and does all that stuff and Da Vinci's doing for something very similar. Yeah it. Is, it's kind of nifty. They haven't gotten to the point yet in 8.5 where they let you edit the audio based on editing the subtitles and I just looked and I don't know that it's only been within the last two weeks that they came out with this update and I don't know if they even said what they're using in the background to do it, but I have seen some of those tools that let you edit your audio by editing the text and it is pretty nice cuz then you can just search the text for all the times you went. Um mm-hmm and delete 'em all and quickly removethat from your audio. Yep. But, but that's Scott, I should probably let you go. I have a feeling my son is trying to lock me in my office because he shut the door and I hear things being tied on the doorknob. All. Good stuff. So I'll let you go to it. As always, thanks for the time Ben, I appreciate it. All. Right, thanks gal. We'll talk to you again next week. Yep. Bye. If you enjoyed the podcast, go leave us a five star rating in iTunes. It helps to get the word out so more it pros can learn about Office 365 and Azure. If you have any questions you want us to address on the show or feedback about the show, feel free to reach out via our website, Twitter, or Facebook. Thanks again for listening and have a great day.
Donate
Share
Apps
Menu
Microsoft Cloud IT Pro Podcast
Open in new window Display Menu
Episode 333 - Azure AD and LAPS in Preview
|
Back 15 seconds Forward 15 seconds Play Speed CC
Podcast: Play in new window | Download (Duration: 40:42 — 28.0MB)
In Episode 333, Ben and Scott talk about some more strange choices coming from the Microsoft Edge team before they discuss the new preview of Azure AD LAPS (with and without Intune).
Like what you hear and want to support the show? Check out our membership options. (more…)
Buy us a Coffee
Name
FirstLast
Product Name
Small - $2.00Medium - $3.50Large - $5.00
Total
Payment Method
PayPal CheckoutCredit Card
MasterCard
Visa
Supported Credit Cards: MasterCard, Visa
Credit Card Number
expiration-monthexpiration-yearcvv
Card Number Expiration Date
Expiration Date CVV
Security CodeCardholder Name
×
Contact Us
Contact Us
Contact Form
This field is for validation purposes and should be left unchanged.
First Name
Question or Comment
Add me to the mailing list
Signup to be notified when new podcasts are published, participate in listener surveys and give input into future episodes!
Sign me up!!
This field is hidden when viewing the form
Tags
Checking your Browser…
Verify you are human
Verifying...
Stuck? Troubleshoot
Success!
Verification failed
Verification expired
Verification expired
×
Microsoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM Wikis
Microsoft Cloud IT Pro PodcastMicrosoft Cloud IT Pro Podcast
Episode 429: Getting started with LLM WikisEpisode 429: Getting started with LLM Wikis
More
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
More
more
Speed: 50%Speed: 75%Speed: NormalSpeed: 125%Speed: 150%Speed: 175%Speed: DoubleSpeed: Triple
Back 15 seconds
Forward 60 seconds
Currently Playing
More
Notifications
PayPal