SlideShare une entreprise Scribd logo
1  sur  45
SECURE
Microsoft Azure
Azure Security Center
You need all three
High availability
When your applications
have a catastrophic failure,
run a second instance
Disaster recovery
When your applications have a
catastrophic failure, run them in
Azure or a secondary datacenter
Backup
When your data is corrupted,
deleted or lost you can restore it
Any OSWindows Linux
Site to Azure Site to Site
High availability mode
AvailabilitySetAvailabilitySetAvailabilitySet
 Multi-tiered with Availability Set
 Load balancers
 Public IP connectivity
 SQL Always On
AvailabilitySetAvailabilitySetAvailabilitySet
Enable Replication
App1 App2
Web1 Web2
Failover
AvailabilitySetAvailabilitySet
Desired State Configuration (DSC)
- Proactively respond to configuration
drift by defining a baseline for your
environment
- Deliver Infrastructure as code
- Flexible Delivery
• Apply and monitor
• Apply and autocorrect
- Detailed reporting and diagnostics at a
per resource level
- Available for both Windows & Linux
Change Tracking & Inventory
- Track changes made to your system
- Valuable for root-cause analysis
- Collect & search inventory and history
- Available for both Windows & Linux
- Windows
• Software
• Services
• Files
• Registry
- Linux
• Software (Packages)
• Daemons
• Files
Key Features
 Configure any cloud or on
premise machine
 Windows & Linux
 Desired State Configuration
 Change Tracking
 Inventory
On-
Premises
Datacenter
Azure
AWS &
Service
Providers
View snapshots for:
• Software
• Files
• Daemons/services
• Registry values
Key Features:
• Spans across Windows & Linux
• Use data to create computer
groups
• Browse historical data
View changes for:
• Software
• Files
• daemons/services
• registry values
• Azure activity log (New*)
Scenarios:
• Identify unauthorized changes
• Correlate configuration changes with
monitoring events
• Create an alert & remediate on change
• Reporting for package/software updates
• Browse historical changes for diagnosis and
forensics
Automated configuration management from the cloud
• Manage physical hosts and VMs in any cloud or on-premises
• Windows or Linux
• Configuration setting and reporting
• Easily attach Azure VMs from portal, ARM Template, or extension
Powered by PowerShell DSC
PowerShell (PS) DSC configuration, node configuration (MOF), node, and
resource management
• Import configurations & modules (from PS Gallery or custom)
• Author
• Compile
• Distribute to nodes
• View granular and high-level configuration compliance reports
• Easy node onboarding
Deploy, enforce, and monitor configuration compliance
standards-based
managed elements”
Configuration
(script)
DSC
Resources
Authoring
Azure VM Physical
server
On-prem
VM
MOF
MOF
Node
Configuration
(MOF)
Zip
Zip
Zip
Rest Endpoint
Staging
Reports
ARM Template
CloudFormation
synced with source control
imported compiled
Unified visibility and deploymentReliable, highly available, scalable
- Flexible scheduling options
- ConfigMgr
 Update Azure & non-Azure
 Windows & Linux
 Update Insights
 Update Deployments
Azure
Update
Management
AWS&
Service
Providers
Hyper-V
VMWare
OpenStack
On-Premises
omsagent
Omsconfig (DSC)
Linux
vendor
s
• Advanced reporting (classification, severity, CVE, bulletinURL etc)
• Consolidation of the package classification
2
1
Amazon Linux
• 2015.09 – 2017.09
Debian GNU/Linux
• 6 (x86/x64)
• 7 (x86/x64)
• 8 (x86/x64)
Oracle Linux
• 5 (x86/x64)
• 6 (x86/x64)
• 7 (x64)
Red Hat Ent. Linux
• 5 (x86/x64)
• 6 (x86/x64)
• 7 (x64)
SUSE Linux Enterprise Server
• 11 (x86/x64)
• 12 (x64)
Ubuntu Server
• 12.04 LTS (x86/x64)
• 14.04 LTS (x86/x64)
• 15.10 (x86/x64)
• 16.04 (x86/x64)
CentOS
• 5 (x86/x64)
• 6 (x86/x64)
• 7 (x64)
(Currently supported)
(future planned)
Legend
Monitoring and Logging
AZURE:
• Performs monitoring & alerting of security
events for the platform
• Enables security data collection via
Monitoring Agent or Windows Event
Forwarding
CUSTOMER:
• Configures monitoring
• Exports events to SQL Database,
HDInsight or a SIEM for analysis
• Monitors alerts & reports
• Responds to incidents
Azure
Storage
Customer
Admin
Guest VM Cloud Services
Customer VMs
Portal
Smart API
Guest VM
Enable Monitoring Agent
Events
Extract event information to SIEM or
other Reporting System
Event ID Computer Event Description Severity DateTime
1150 Machine1 Example security event
4 04/29/2014
2002 Machine2 Signature Updated Successfully
4 04/29/2014
5007 Machine3 Configuration Applied
4 04/29/2014
1116 Machine2 Example security event
1 04/29/2014
1117 Machine2 Access attempted
1 04/29/2014
SIEM Admin View
Alerting & reporting
HDInsight
Microsoft Azure
https://www.microsoft.com/en-us/trustcenter/security/auditingandlogging
Full Stack Monitoring & Analytics across Apps and Infra
Application Insights
Scenario Specific Monitoring – Customized Data Ingestion & Diagnostics
Log Analytics
Service Map Container Health
…Network Performance Monitor
Monitoring Fundamentals – Available out of the box with Azure Platform
Activity LogsDiagnostic Logs Service HealthMetrics
Dashboards Alerts Action Groups Autoscale
Unified pricing model
Only pay what you use
Data ingestion per GB
Detect
Triage
Diagnose
Operationalize
• Diagnosing across app stack is
hard unless various
perspectives connected
• New and powerful big data
query engine for all your app
telemetry and root-cause
analysis
• Ad-hoc queries and full-text
search helps answer tough
questions instantly
• Simple, powerful SQL like language
much easier for complex queries
• Filter, join and correlate data to gain
performance & usage insights
• Extract and extend your data to
create new calculated data fields
• Generate statistical aggregations
and powerful visualizations instantly
Visual Studio 2015 (Update 2)
Visual Studio Team Services
• Open Source SDKs to power
insights for any web app
• Continuously export data to
Azure Blob Storage or SQL
• Visualize data with Power BI
Content Pack
• Data access via REST APIs*
Azure Security and Management

Contenu connexe

Tendances

Microsoft Zero Trust
Microsoft Zero TrustMicrosoft Zero Trust
Microsoft Zero Trust
David J Rosenthal
 

Tendances (20)

[Azure Governance] Lesson 2 : Azure Locks
[Azure Governance] Lesson 2 : Azure Locks[Azure Governance] Lesson 2 : Azure Locks
[Azure Governance] Lesson 2 : Azure Locks
 
Azure governance v4.0
Azure governance v4.0Azure governance v4.0
Azure governance v4.0
 
Microsoft Azure Fundamentals
Microsoft Azure FundamentalsMicrosoft Azure Fundamentals
Microsoft Azure Fundamentals
 
Azure storage
Azure storageAzure storage
Azure storage
 
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
 
2 Modern Security - Microsoft Information Protection
2   Modern Security - Microsoft Information Protection2   Modern Security - Microsoft Information Protection
2 Modern Security - Microsoft Information Protection
 
Business Continuity & Disaster Recovery with Microsoft Azure
Business Continuity & Disaster Recovery with Microsoft AzureBusiness Continuity & Disaster Recovery with Microsoft Azure
Business Continuity & Disaster Recovery with Microsoft Azure
 
Azure Site Recovery - BC/DR - Migrations & assessments in 60 minutes!
Azure Site Recovery - BC/DR - Migrations & assessments in 60 minutes!Azure Site Recovery - BC/DR - Migrations & assessments in 60 minutes!
Azure Site Recovery - BC/DR - Migrations & assessments in 60 minutes!
 
Power of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure securityPower of the cloud - Introduction to azure security
Power of the cloud - Introduction to azure security
 
Azure fundamentals
Azure   fundamentalsAzure   fundamentals
Azure fundamentals
 
Azure Sentinel.pptx
Azure Sentinel.pptxAzure Sentinel.pptx
Azure Sentinel.pptx
 
Azure Monitoring Overview
Azure Monitoring OverviewAzure Monitoring Overview
Azure Monitoring Overview
 
Azure role based access control (rbac)
Azure role based access control (rbac)Azure role based access control (rbac)
Azure role based access control (rbac)
 
Building an Enterprise-Grade Azure Governance Model
Building an Enterprise-Grade Azure Governance ModelBuilding an Enterprise-Grade Azure Governance Model
Building an Enterprise-Grade Azure Governance Model
 
Windows Azure Virtual Machines
Windows Azure Virtual MachinesWindows Azure Virtual Machines
Windows Azure Virtual Machines
 
Microsoft Zero Trust
Microsoft Zero TrustMicrosoft Zero Trust
Microsoft Zero Trust
 
Azure 101
Azure 101Azure 101
Azure 101
 
Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and Compliance
 
Azure storage
Azure storageAzure storage
Azure storage
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to Azure
 

Similaire à Azure Security and Management

Similaire à Azure Security and Management (20)

Azure System Management
Azure System ManagementAzure System Management
Azure System Management
 
Azure F5 Solutions
Azure F5 SolutionsAzure F5 Solutions
Azure F5 Solutions
 
VMware vRealize Network Insight 3.4 whats new
VMware vRealize Network Insight 3.4 whats newVMware vRealize Network Insight 3.4 whats new
VMware vRealize Network Insight 3.4 whats new
 
Server update management optimization
Server update management optimizationServer update management optimization
Server update management optimization
 
Simplify and Scale Enterprise Spring Apps in the Cloud | March 23, 2023
Simplify and Scale Enterprise Spring Apps in the Cloud | March 23, 2023Simplify and Scale Enterprise Spring Apps in the Cloud | March 23, 2023
Simplify and Scale Enterprise Spring Apps in the Cloud | March 23, 2023
 
An Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the CloudAn Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the Cloud
 
Full stack monitoring across apps & infrastructure with Azure Monitor
Full stack monitoring across apps & infrastructure with Azure MonitorFull stack monitoring across apps & infrastructure with Azure Monitor
Full stack monitoring across apps & infrastructure with Azure Monitor
 
366864108 azure-security
366864108 azure-security366864108 azure-security
366864108 azure-security
 
Manage your enterprise with System Center
Manage your enterprise with System CenterManage your enterprise with System Center
Manage your enterprise with System Center
 
Cortana Analytics Workshop: Cortana Analytics -- Security, Privacy & Compliance
Cortana Analytics Workshop: Cortana Analytics -- Security, Privacy & ComplianceCortana Analytics Workshop: Cortana Analytics -- Security, Privacy & Compliance
Cortana Analytics Workshop: Cortana Analytics -- Security, Privacy & Compliance
 
Monitoring your data center with scom
Monitoring your data center with scomMonitoring your data center with scom
Monitoring your data center with scom
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
AWS Public Sector Symposium 2014 Canberra | Security as an Enabler: Improving...
 
Presentacion de solucion cloud de navegacion segura
Presentacion de solucion cloud de navegacion seguraPresentacion de solucion cloud de navegacion segura
Presentacion de solucion cloud de navegacion segura
 
Spirent CloudScore
Spirent CloudScoreSpirent CloudScore
Spirent CloudScore
 
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
Introducing Cisco HyperFlex Systems: The Next Generation in Complete Hypercon...
 
Un-clouding the cloud
Un-clouding the cloudUn-clouding the cloud
Un-clouding the cloud
 
Build modern and intelligent applications using Azure Database for PostgreSQL
Build modern and intelligent applications using Azure Database for PostgreSQLBuild modern and intelligent applications using Azure Database for PostgreSQL
Build modern and intelligent applications using Azure Database for PostgreSQL
 
AWS Security Architecture - Overview
AWS Security Architecture - OverviewAWS Security Architecture - Overview
AWS Security Architecture - Overview
 
What's New In Microsoft System Center 2016 & OMS
What's New In Microsoft System Center 2016 & OMSWhat's New In Microsoft System Center 2016 & OMS
What's New In Microsoft System Center 2016 & OMS
 

Dernier

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Dernier (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 

Azure Security and Management

  • 1.
  • 2.
  • 3.
  • 4.
  • 6.
  • 7.
  • 9.
  • 10.
  • 11.
  • 12.
  • 14.
  • 15.
  • 16. You need all three High availability When your applications have a catastrophic failure, run a second instance Disaster recovery When your applications have a catastrophic failure, run them in Azure or a secondary datacenter Backup When your data is corrupted, deleted or lost you can restore it
  • 17. Any OSWindows Linux Site to Azure Site to Site
  • 18. High availability mode AvailabilitySetAvailabilitySetAvailabilitySet  Multi-tiered with Availability Set  Load balancers  Public IP connectivity  SQL Always On
  • 20.
  • 21. Desired State Configuration (DSC) - Proactively respond to configuration drift by defining a baseline for your environment - Deliver Infrastructure as code - Flexible Delivery • Apply and monitor • Apply and autocorrect - Detailed reporting and diagnostics at a per resource level - Available for both Windows & Linux Change Tracking & Inventory - Track changes made to your system - Valuable for root-cause analysis - Collect & search inventory and history - Available for both Windows & Linux - Windows • Software • Services • Files • Registry - Linux • Software (Packages) • Daemons • Files Key Features  Configure any cloud or on premise machine  Windows & Linux  Desired State Configuration  Change Tracking  Inventory On- Premises Datacenter Azure AWS & Service Providers
  • 22. View snapshots for: • Software • Files • Daemons/services • Registry values Key Features: • Spans across Windows & Linux • Use data to create computer groups • Browse historical data
  • 23.
  • 24. View changes for: • Software • Files • daemons/services • registry values • Azure activity log (New*) Scenarios: • Identify unauthorized changes • Correlate configuration changes with monitoring events • Create an alert & remediate on change • Reporting for package/software updates • Browse historical changes for diagnosis and forensics
  • 25.
  • 26. Automated configuration management from the cloud • Manage physical hosts and VMs in any cloud or on-premises • Windows or Linux • Configuration setting and reporting • Easily attach Azure VMs from portal, ARM Template, or extension Powered by PowerShell DSC PowerShell (PS) DSC configuration, node configuration (MOF), node, and resource management • Import configurations & modules (from PS Gallery or custom) • Author • Compile • Distribute to nodes • View granular and high-level configuration compliance reports • Easy node onboarding Deploy, enforce, and monitor configuration compliance
  • 28.
  • 30.
  • 31. ARM Template CloudFormation synced with source control imported compiled
  • 32.
  • 33. Unified visibility and deploymentReliable, highly available, scalable - Flexible scheduling options - ConfigMgr  Update Azure & non-Azure  Windows & Linux  Update Insights  Update Deployments Azure Update Management AWS& Service Providers Hyper-V VMWare OpenStack On-Premises
  • 34.
  • 35. omsagent Omsconfig (DSC) Linux vendor s • Advanced reporting (classification, severity, CVE, bulletinURL etc) • Consolidation of the package classification 2 1
  • 36. Amazon Linux • 2015.09 – 2017.09 Debian GNU/Linux • 6 (x86/x64) • 7 (x86/x64) • 8 (x86/x64) Oracle Linux • 5 (x86/x64) • 6 (x86/x64) • 7 (x64) Red Hat Ent. Linux • 5 (x86/x64) • 6 (x86/x64) • 7 (x64) SUSE Linux Enterprise Server • 11 (x86/x64) • 12 (x64) Ubuntu Server • 12.04 LTS (x86/x64) • 14.04 LTS (x86/x64) • 15.10 (x86/x64) • 16.04 (x86/x64) CentOS • 5 (x86/x64) • 6 (x86/x64) • 7 (x64) (Currently supported) (future planned) Legend
  • 37.
  • 38. Monitoring and Logging AZURE: • Performs monitoring & alerting of security events for the platform • Enables security data collection via Monitoring Agent or Windows Event Forwarding CUSTOMER: • Configures monitoring • Exports events to SQL Database, HDInsight or a SIEM for analysis • Monitors alerts & reports • Responds to incidents Azure Storage Customer Admin Guest VM Cloud Services Customer VMs Portal Smart API Guest VM Enable Monitoring Agent Events Extract event information to SIEM or other Reporting System Event ID Computer Event Description Severity DateTime 1150 Machine1 Example security event 4 04/29/2014 2002 Machine2 Signature Updated Successfully 4 04/29/2014 5007 Machine3 Configuration Applied 4 04/29/2014 1116 Machine2 Example security event 1 04/29/2014 1117 Machine2 Access attempted 1 04/29/2014 SIEM Admin View Alerting & reporting HDInsight Microsoft Azure https://www.microsoft.com/en-us/trustcenter/security/auditingandlogging
  • 39. Full Stack Monitoring & Analytics across Apps and Infra Application Insights Scenario Specific Monitoring – Customized Data Ingestion & Diagnostics Log Analytics Service Map Container Health …Network Performance Monitor Monitoring Fundamentals – Available out of the box with Azure Platform Activity LogsDiagnostic Logs Service HealthMetrics Dashboards Alerts Action Groups Autoscale Unified pricing model Only pay what you use Data ingestion per GB
  • 41. • Diagnosing across app stack is hard unless various perspectives connected • New and powerful big data query engine for all your app telemetry and root-cause analysis • Ad-hoc queries and full-text search helps answer tough questions instantly
  • 42. • Simple, powerful SQL like language much easier for complex queries • Filter, join and correlate data to gain performance & usage insights • Extract and extend your data to create new calculated data fields • Generate statistical aggregations and powerful visualizations instantly
  • 43. Visual Studio 2015 (Update 2) Visual Studio Team Services
  • 44. • Open Source SDKs to power insights for any web app • Continuously export data to Azure Blob Storage or SQL • Visualize data with Power BI Content Pack • Data access via REST APIs*

Notes de l'éditeur

  1. 25% of VMs on Azure are already using Azure Backup. Only 10% are secure! Only 10% are monitored
  2. Azure can help by reducing the challenges of cost and complexity, while helping add coverage and compliance. Let’s drill into more details. Microsoft Azure provides customers peace of mind knowing their workloads are protected from any disaster without having to build and maintain a secondary datacenter or relying on backup. Azure delivers cloud services that extend to your datacenter to protect your infrastructure, transforming your business with a true hybrid solution. Reducing costs Customers do not have to pay for infrastructure, the power to run and cool machines, or IT personnel to manage machines, saving customers from paying to maintain a secondary data center Managing complexity Customers can leverage automation to enable the true power of recovery plans and allow you to failover your workloads with a click of a button, removing the guest work and stress involved in a disaster Ensuring compliance Disaster recovery is no longer constrained by geographical barriers. The disaster recovery site can be from any one of our Azure regions around the world. (Or asking for something like the quick restoration of workloads allows customers to gather necessary information to meet compliance deadlines) Scaling protection ASR provides rich capabilities to quickly replicate virtual and physical machines a customer’s own secondary on-premises site or Azure
  3. Azure can help by reducing the challenges of cost and complexity, while helping add coverage and compliance. Let’s drill into more details. Microsoft Azure provides customers peace of mind knowing their workloads are protected from any disaster without having to build and maintain a secondary datacenter or relying on backup. Azure delivers cloud services that extend to your datacenter to protect your infrastructure, transforming your business with a true hybrid solution. Reducing costs Customers do not have to pay for infrastructure, the power to run and cool machines, or IT personnel to manage machines, saving customers from paying to maintain a secondary data center Managing complexity Customers can leverage automation to enable the true power of recovery plans and allow you to failover your workloads with a click of a button, removing the guest work and stress involved in a disaster Ensuring compliance Disaster recovery is no longer constrained by geographical barriers. The disaster recovery site can be from any one of our Azure regions around the world. (Or asking for something like the quick restoration of workloads allows customers to gather necessary information to meet compliance deadlines) Scaling protection ASR provides rich capabilities to quickly replicate virtual and physical machines a customer’s own secondary on-premises site or Azure
  4. Gain visibility into health, performance and utilization of your platform, apps, and workloads, no matter where they reside and get time back to focus on the initiatives that matter the most to you and your organization. Azure provides monitoring and analytics as a SaaS offering, so you can get started quickly without any infrastructure overhead. It is designed to manage your development and IT operations workflows through a unified experience. It can connect to any data source and leverage your existing management tools, both on-premises and in the cloud. You will bridge the gap between app and infrastructure with the automated discovery and mapping of the dependencies across servers, processes, and 3rd party services. You can query at cloud scale and gain immediate insight by correlating and analyzing petabytes of machine data. With built-in solutions and machine learning algorithms baked into the service, you can detect and fix issues, before it impacts users - no matter what type of platform, or which public cloud service you use. Key benefits Collect and correlate data from multiple sources, enabling integrated monitoring and diagnostics of the cloud and on-premises environment, across multi-vendor solutions Discover application components and map their connections across servers, processes, and ports, for complete visibility of multi-tier services Visualize and alert on the health, performance and utilization of your resources, no matter where they reside and accelerate troubleshooting of issues Detect and respond to issues before they impact your users, with continuous monitoring across development and IT operations workflows. Learn, iterate, and improve the performance and usability of your apps and services using real-time insights with machine learning and ad-hoc analytics
  5. Talk through the investments of what MSFT/Azure sees as important for enterprise cloud management platform The combination together is powerful. Truly integrated capabilities SaaS management and security. To be successful in the Cloud era, enterprises must have visibility/metrics and controls on every component to pinpoint issues efficiently, optimize and scale effectively, while having the assurance the security, compliance and polices are in place to ensure the velocity. Native Security and Management in Azure Enterprise grade capabilities natively from the cloud provider Azure Integrated and interconnected across data and experiences Management capabilities included with the flexibility to increase or choose 3rd party Can make the point that for those familiar with OMS these were the foundation for what we now have natively within Azure. 5 main areas: Secure: While Azure is trusted and secure platform, you as a customer have your own security settings you need to manage. You also need to be able to protect your individual machines against threats and monitor the security posture of your system. Protect: Your VMs and applications in the cloud need to be backed up and protected in the event of data loss. With disaster recovery from on-prem to the cloud, or from one cloud to another, you can avoid downtime and keep your applications up and running. Monitor: Every operations manager and every developer needs to be able to see the health and performance of their applications, infrastructure, and network. And seeing insights across all three together in a single dashboard can save time and resources in troubleshooting and preventing issues in the future. Configure: For managing Azure and hybrid workloads at scale, automation and configuration capabilities help you create runbooks to automate tasks, manage the configuration settings and track changes, and monitor and deploy missing updates. Additionally in Azure you can use PowerShell and Cloud Shell for command line scripting. Govern: Many customers need a way to look across cloud resources to assess and enforce enterprise-wide standards and policy compliance for security and management. In addition, they need to manage and monitor costs for the cloud. We recently acquired Cloudyn, a multi-cloud cost management solution to help our customers with this challenge.
  6. Key investment themes
  7. Site Recovery Benefits: Automated VM level Replication RPO of seconds and RTO of minutes No impact DR Drills with Test Failover Planned and unplanned failover Orchestrated Recovery Plans for Disaster Recovery Failback support Migrate to Azure from anywhere Create on-demand test copies in Azure
  8. 39
  9. There are a bunch of interesting new capabilities so lets get started with the first area: Intelligent APM As modern app developers, we all know how crucial it is to detect, triage and diagnose problems before they start affecting our customers. With Application Insights you get all the tools to make your diagnostics experience smarter and find and fix problems before your customers know it! Detect: One of the most crucial things is to be able to detect issues as soon as they happen, and be alerted instantaneously. However, the issue with alerts is that it requires you to have a threshold and more often than not, you don’t have any idea. Moreover, in the complexity of modern app architecture, even an army of analysts sitting in front of a dashboard cannot detect all the different things that can go wrong. That is where proactive diagnostics come into play. With our Machine Learning based technology, you can be alerted on real time service disruptions and anomalous patterns in your app performance and behavior, with thresholds constantly evolving based on your app architecture and performance patterns. With dashboards you can pin all the charts and KPIs across your Azure resources at a single place and share with your colleagues. You can also take advantage of the new live stream metrics to see what is going on with your application metrics at this right very moment. Triage: Once you detect an issue, the next thing is to figure out its impact and whether it is priority enough to solve right now. With Application insights you can find out the real user impact of any exception and take decisions accordingly. With the new Application Map you can automatically detect your application topology across dependencies and client & server side components. You can find the impact assessment and click through to underlying Azure resources to find the right information. Diagnose: Once you decide to fix an issue, you need all the context to solve it, and with our out-of-the box telemetry collection, you will have all the data you need. What’s more, if you are developing Azure Cloud Services or App Services, you can get much deeper diagnostics information, covering some of the role lifecycle issues and other performance problems. Operationalize: Once you have been through the Detect, Triage & Diagnose cycle, you can set up your own custom alerts based on the thresholds you discovered and keep being on top of things!
  10. OK! So, lets get to our next area: Analytics As we mentioned in the beginning, Analytics is a new capability in Application Insights we just announced at Build. And, I should say it is one of my most favorites. In a modern app architecture with various tiers and components, it is often very difficult to diagnose problems or gaps across the entire app stack unless you can connect the various perspectives. With our new big data query engine, you can do that very easily and find all the answers to do the root-cause analyses. You can ask ad-hoc queries across your entire app telemetry and even do full text search to discover the right data sets.
  11. What powers the Analytics experience is a powerful query language we launched as well. Read through the points… And the best thing with Application Insights is that since we collect telemetry across your application stack, you can correlate data across your Service Performance, Business Metrics and Customer Experience and generate unique insights helping you answer tough questions almost instantly. To put it in perspective, some very high scale Microsoft services are using it today sending us Terabytes of data over which they can get answers to their queries in as little as a few seconds. E.g. internally the service ingests over 1 trillion events and 600TB a day of log data across hundreds of Microsoft cloud services.  Yes, 600TB a day – that’s many petabytes of retained log storage in just one month.
  12. Lets switch gears to our 3rd area: DevOps. As developers we would be using one or the other dev environment and have some DevOps workflows that we would be using! Having the diagnostics experience integrated with our existing practices makes it so very easy and useful! If you use Visual Studio or Visual Studio Team Services, there are a bunch of integration points that you can take advantage of.
  13. What also makes Application Insights powerful is how it is designed to be flexible and extensible to help you get insights suited to your particular needs.