Sunday, 21 November 2021
Discover what’s new to Microsoft database services—recap from Microsoft Ignite
Saturday, 20 November 2021
Microsoft and AT&T are accelerating the enterprise customer’s journey to the edge with 5G
Today, we find ourselves at a pivotal moment that’s impacting many enterprise customers’ digital transformation needs. In this place where cloud meets the edge, compute meets mobile, and 5G trends continue to drive innovation—customer demand for advanced network capabilities is surging. For customers, the promise of all these converging technologies is still the ability to create and use innovative solutions and experiences to keep pace with a rapidly evolving digital landscape.
As a result, enterprises are migrating mission-critical workloads to the cloud to better serve their customers. The technologies that are involved are complex, and companies are looking to providers to not merely sell them products, but to help them deliver innovation while developing ever-greater capabilities. With new use cases and connected devices becoming ubiquitous, those enterprises are requiring new edge application solutions close to the end users to help them build innovative solutions within industries as diverse as gaming, automotive, healthcare, manufacturing, and more.
Sign up for the Azure Edge Zones with AT&T private preview today.
Journey to the mobile network edge
Thursday, 18 November 2021
Bringing commercial innovations in chip design to national security
Semiconductors and microelectronics are some of the most important components in building cutting-edge capabilities for our national security and defense technologies, from satellites and radar to vehicles and communications equipment. Ensuring these components are developed with the utmost regard for security is a critical, yet challenging task. Historically, the security requirements associated with developing microelectronics have limited the U.S. Department of Defense’s (DoD) ability to leverage the latest innovations.
Through a recent DoD-sponsored project, Rapid Assured Microelectronics Prototypes (RAMP) using Advanced Commercial Capabilities, the goal is to leverage commercial best practices to help accelerate the development process and bring reliable, secure state-of-the-art microelectronic design and manufacturing to national security and defense applications. The DoD recently announced it has selected Microsoft to support the second phase of this project.
This project builds on a 40-year history of collaboration between Microsoft and the U.S. DoD, to bring commercial innovation to the national security community. Microsoft previously led a coalition of partners in collaborating with the DoD on the first phase of this initiative: to develop design capabilities that achieve the department’s mission priorities. In this second phase, Microsoft and our partners will build on these successful designs and begin to develop custom integrated chips and System on a Chip (SoC) designs using a secure, collaborative design flow that provides access to advanced manufacturing processes. These new designs will achieve lower power consumption, improved performance, reduced physical size, and improved reliability for application in DoD systems.
Microsoft has engaged microelectronics industry leaders across the commercial and defense industrial base (DIB) to develop this phase of the RAMP project, collaborators include Ansys, Applied Materials, Inc., BAE Systems, Battelle Memorial Institute, Cadence Design Systems, Cliosoft, Inc., Flex Logix, GlobalFoundries, Intel Federal, Raytheon Intelligence and Space, Siemens EDA, Synopsys, Inc., Tortuga Logic, and Zero ASIC Corporation.
The RAMP solution will provide an advanced microelectronics development platform for mission-critical applications, with cloud, AI, and machine learning-enabled automation, security, and quantifiable assurance. This solution will be hosted in Azure Government, offering the broadest range of commercial innovation for governments with services available across all U.S. data classifications.
RAMP is a critical initiative that will enable the DoD to leverage a secure, scalable microelectronic supply chain, while also ensuring the design and manufacturing meets its stringent security and compliance requirements. By leveraging cloud-based secure design capabilities, RAMP will expand the number of foundries available to DoD, enhance resiliency, and foster growth of the domestic semiconductor supply chain. The success of RAMP will also enable the department to be more agile with technology developments, quickly adapt to evolving needs, and adopt the latest technological capabilities. We look forward to continuing our work with the DoD and our industry partners to deliver groundbreaking, transformative solutions to secure the microelectronic supply chain.
Source: microsoft.com
Tuesday, 16 November 2021
Learn how Microsoft Azure is accelerating hardware innovations for a sustainable future
This year’s theme for OCP Global Summit is Open Possibilities, and in the Microsoft Azure team, we wholeheartedly agree—we have been part of tremendous creativity and resiliency as the community continued to collaborate, despite the challenges posed by the pandemic. This year, we are excited to showcase some of our projects and technology at OCP Global Summit and share our learnings on the path of building a more reliable, trusted, and sustainable cloud alongside industry partners and the open source hardware ecosystem.
Accelerating open source innovation over the years
As OCP celebrates its 10-year anniversary, Microsoft is proud to have been one of the major contributors in the journey of reimaging datacenter designs and technology with the vibrant open source hardware community. We joined OCP in 2014, and over the years have shared the designs of our very own datacenters that powered Microsoft Azure (Open Cloud Server, OCS). We continue to be inspired by the innovations and technology advancement made possible by industry partners and developers coming together as a community. We are glad to see Project Olympus, our open-sourced modular server architecture that was announced in 2016, achieving industry adoption and serving as the standard hardware design for over 60 datacenters regions around the world. In collaboration with the OCP community, Project Cerberus was introduced as the new industry standard for platform security in 2017, to equip datacenter designs with the critical components for robust security, firmware integrity, and hardware root of trust—deployed in Microsoft’s datacenters today. In 2020 we leaned in to innovate further by building upon datacenter foundations, and announced the Modular Building Block Architecture (MBA) initiative that provides interoperability for security, AI, and more.
Liquid cooling—from standards to production deployment to better chip performance
From early discussions on standardization in cold plates and liquid immersion cooling with OCP and partners, Microsoft achieved a milestone of deploying the world’s first two-phase liquid immersion cooling in a production public cloud environment in early 2021. We are excited to share from our latest research, that liquid cooling accentuates the benefits of overclocking, in which the chip components are operated beyond their pre-defined voltage, thermal, and power design limits to further improve performance. Our tests showed that with liquid cooling, the performance of some chipsets can increase by up to 20 percent. As liquid cooling unleashes new possibilities with fewer constraints and resources required for chip, server, and datacenter architecture, we look forward to engaging with the industry to not only further the cooling technology but also ensure safe and ergonomic operations of the immersion tanks.
Sustainably and responsibly meeting the computing demands of the future
Increasing demands for cloud computing leads to increasing demands for physical datacenters. It’s critical that Microsoft develop and operate the sites sustainably. As Microsoft committed to being carbon negative, water positive, and zero waste by 2030, we’ve created first-of-their-kind Microsoft Circular Centers, that will help us extend the lifecycle of servers and reuse them to reduce waste. We’re also working with the OCP community to collaborate on data gathering templates and contribute guidance on Life Cycle Assessments (LCA) as a method to understand and evaluate the environmental impact from our server hardware. As we expand the use of LCA and desire to apply it to assess impacts of bleeding edge technology, it is important to align on relevant metrics for measurement and accompanying supplier considerations across every stage of the hardware value chain. Microsoft will continue to actively work with the OCP community to define and further the sustainability agenda for the future of datacenters and to preserve our only planet.
Continuing to evolve and deliver cloud hardware innovation for scale
We continue to believe that collaboration through open source, community engagement, and industry partnership makes technology advancement more rigorous, faster, and better for the world. Together with OCP, we enable innovation, efficiency, scalability, and sustainability for the datacenter infrastructures of the future. We invite you to come visit Microsoft’s booth at OCP Global Summit 2021 and check out the Datacenter-ready Secure Control Module (DC-SCM) for modular server management, security, and control, as well as our two-phase liquid immersion cooling tank, and the newest addition to Project Olympus, a Modular 3U Chassis, designed for higher power devices and flexible connectivity. At OCP Global Summit’s Experience Center, you will also find us showcasing the latest 15mm E1.s form factor, which was led by Microsoft and developed in partnership with key industry players, for high-performance, high-density SSDs for next-generation servers and storage platforms.Source: microsoft.com
Monday, 15 November 2021
Complement your Microsoft AZ-104 Exam Prep with Practice Test
When you achieve this certification, you will manage to become an Azure Administrator who has a distinct role in any organization across the globe. Otherwise stated, such a professional will be responsible for deploying and managing an organization’s cloud infrastructure. Professional will work with a team of proficient professionals and engineers who perceive how to utilize cloud computing services to better business processes and boost their performance.
AZ-104 Exam Information
Let’s dive into the AZ-104 exam details. If you want to get through the Microsoft AZ-104 exam, you should have very clear in your mind which prerequisites for this exam are and what skills this exam evaluates. What affects the requirements for being qualified for AZ-104? Your possibilities to pass it from the first attempt will improve significantly if you have at least six months of practical experience using cloud technologies. So, you will learn the new concepts thoroughly and will enhance your odds to pass the AZ-104 exam. In general, this Microsoft exam helps applicants acquire the following skills:
- Learn Azure governance and identities and perceive how to manage them;
- Manage and execute various storage solutions;
- Deploy Azure compute resources and understand how to manage them;
- Configure virtual networking solutions and manage them appropriately;
Microsoft Azure Administrator AZ-104 Exam: Preparation Journey
Microsoft supports you pass its exams by equipping you with a complete preparation guide and other study resources. Here is a look at some of the means that you can use to prepare:
1. Enroll in an online training
Several online platforms offer Microsoft AZ-104 training. A mere Google search can disclose most of them. Make sure that you analyze each website’s content before enrolling in a training course. The best option is to enroll in a training course offered by Microsoft itself.
2. Use Study Guides
The busy applicants can get the Microsoft AZ-104 study guides from trustworthy publishers. Its significance is that they can always read it whenever you get time.
For example, you can choose to spend a few minutes of your lunch break reading the AZ-104 study guide rather than chatting with others.
3. Engage in Online Communities
Find out Microsoft online study communities and actively participate in them. Even though these forums may not have organized learning, they can give you beneficial information and lead you to an accurate path.
4. Take AZ-104 Practice Tests
Just studying is not enough. You need to take some practice tests to get an idea of what Microsoft AZ-104 looks like. Exam dumps can also help you with that.
What Are the Benefits of Passing the Microsoft AZ-104 Certification Exam?
Now that you know all the essential information of the Microsoft AZ-104 exam, you might want to know how this Microsoft certification exam can benefit your career. There are a lot of benefits that this qualifying exam may deliver to you, and here are a few of them:
1. It Proves Your Knowledge and Skills
The Microsoft AZ-104 exam works as a solid proof of your skills, which many organizations trusts. Once you pass the certification exam, you can prove to your current and potential organizations that you have solid expertise in Microsoft Teams application and proficiency to better business processes using its latest tools.
2. Improve Your Career Development
Passing the Microsoft AZ-104 exam will improve your odds of being hired many times. This is because the Microsoft Certified - Azure Administrator Associate certification is greatly respected by the hiring managers as it is proof of more productivity and dedication to development.
3. Microsoft is an Internationally Accepted Vendor
The reputation of Microsoft is popular in the job market. Both the hiring managers and professionals know that not everyone manages to crack the Microsoft AZ-104 exam. So, passing this exam will allow you to excel in the crowd of non-certified peers and make you a preferred applicant during your job interview.
4. Passing AZ-104 Exam Keeps You Acquainted With the Industry Latest Trends
The Microsoft AZ-104 certification exam covers modern concepts that you will be able to perform right away after finishing your preparation process. Thus, you will become a worthy member of your team.
Conclusion
Passing the Microsoft AZ-104 exam is the best way to follow if you want to learn more about Microsoft Teams. Other than opening the doors of international organizations, it will help you get more confidence in your skills and become more productive while performing your everyday tasks.
Tuesday, 9 November 2021
Protect workloads with inline DDoS protection from Gateway Load Balancer partners
DDoS attacks are rapidly evolving in complexity and frequency. As we highlighted in our 2021 Q1 and Q2 DDoS attack trends review, we see that attacks in Azure have been trending toward shorter durations, mostly short-burst attacks. Workloads that are highly sensitive to latency, such as those in the multiplayer online gaming industry, cannot tolerate such short burst DDoS attacks, which can cause outages ranging from two to 10 seconds that result in availability disruption.
Today, we are announcing the preview of inline DDoS protection which will be offered through partner network virtual appliances (NVAs) that are deployed with Azure Gateway Load Balancer and integrated with Azure DDoS Protection Standard in all Azure regions. Inline DDoS protection mitigates even short-burst low-volume DDoS attacks instantaneously without impacting the availability or performance of highly latency-sensitive applications.
Azure DDoS Protection Standard is the recommended product to protect your resources against L3/4 attacks in Azure. Third-party inline L7 DDoS protection, combined with Azure DDoS Protection Standard, provides comprehensive L3 to L7 protection against volumetric as well as low-volume DDoS attacks. Azure customers using third-party DDoS protection services for inline mitigation now have the option to use the marketplace offering along with Azure DDoS Protection Standard. This solution enables comprehensive inline L7 DDoS protection for high performance and high availability scenarios using different providers.
Gateway Load Balancer enables the protection of such workloads by ensuring the relevant NVAs are injected into the ingress path of the internet traffic. Once chained to a Standard Public Load Balancer frontend or IP configuration on a virtual machine, no additional configuration is needed to ensure traffic to and from the application endpoint is sent to the Gateway Load Balancer.
Easily deploy inline DDoS protection with partner network virtual appliances
Deployment of inline DDoS NVA can be done in a few easy steps:
1. Find your virtual appliance in Azure Marketplace.
2. Deploy the NVA instances.
3. Create a Gateway Load Balancer and place the NVA instances in the backend pool.
4. Chain the Gateway Load Balancer to your public IP or Standard Load Balance frontend.
Gateway Load Balancer provides transparent flow (bump in the wire) using an overlay network with low latency, preserving the health of the host as well as the NVAs during the DDoS attacks.
Inbound traffic is always inspected with the NVAs in the path and the clean traffic is returned to the backend infrastructure (gamer servers).
Traffic flows from the consumer virtual network to the provider virtual network and then returns to the consumer virtual network. The consumer virtual network and provider virtual network can be in different subscriptions, tenants, or regions enabling greater flexibility and ease of management.
Sunday, 7 November 2021
Key foundations for protecting your data with Azure confidential computing
The exponential growth of datasets has resulted in growing scrutiny of how data is exposed—both from a consumer data privacy and compliance perspective. In this context, confidential computing becomes an important tool to help organizations meet their privacy and security needs surrounding business and consumer data.
Confidential computing technology encrypts data in memory and only processes it once the cloud environment is verified, preventing data access from cloud operators, malicious admins, and privileged software such as the hypervisor. It helps keep data protected throughout its lifecycle—in addition to existing solutions of protecting data at rest and in transit, data is now protected while in use.
Thanks to confidential computing, organizations across the world can now unlock opportunities that were not possible before. For example, they can now benefit from multi-party data analytics and machine learning that combine datasets from parties that would have been unwilling or unable to share them, keeping data private across participants. In fact, RBC created a platform for privacy-preserving analytics for customers to opt-in for more optimized discounts. The platform generates insights into consumer purchasing preferences by confidentially combining RBC’s credit and debit card transactions with retailer data of what specific items consumers purchased.
Industry leadership and standardization
Microsoft has long been a thought leader in the field of confidential computing. Azure introduced “confidential computing” in the cloud when we became the first cloud provider to offer confidential computing virtual machines and confidential containers support in Kubernetes for customers to run their most sensitive workloads inside Trusted Execution Environments (TEEs). Microsoft is also a founding member of the Confidential Computing Consortium (CCC), a group that brings together hardware manufacturers, cloud providers, and solution vendors to jointly work on ways to improve and standardize data protection across the tech industry.
Confidential computing foundations
Our bar for confidentiality aligns and extends the bar set by the CCC to provide a comprehensive foundation for confidential computing. We strive to provide customers the technical controls to isolate data from Microsoft operators, their own operators, or both. In Azure, we have confidential computing offerings that go beyond hypervisor isolation between customer tenants to help protect customer data from access by Microsoft operators. We also have confidential computing with secure enclaves to additionally help prevent access from customer operators.
Our foundation for confidential computing includes:
◉ Hardware root-of-trust to ensure data is protected and anchored into the silicon. Trust is rooted to the hardware manufacturer, so even Microsoft operators cannot modify the hardware configurations.
◉ Remote attestation for customers to directly verify the integrity of the environment. Customers can verify that both the hardware and software on which their workloads run are approved versions and secured before allowing them to access data.
◉ Trusted launch is the mechanism that ensures virtual machines boot with authorized software and that uses remote attestation so that customers can verify. It’s available for all VMs including confidential VMs, bringing Secure Boot and vTPMs, to add defense against rootkits, bootkits, and malicious firmware.
◉ Memory isolation and encryption to ensure data is protected while processing. Azure offers memory isolation by VM, container, or application to meet the various needs of customers, and hardware-based encryption to prevent unauthorized viewing of data, even with physical access in the datacenter.
◉ Secure key management to ensure that keys stay encrypted during their lifecycle and release only to the authorized code.
The above components together form the foundations for what we consider to be confidential computing. And today, Azure has more confidential compute options spanning hardware and software than any other cloud vendor.
Innovative new hardware
Our new Intel-based DCsv3 confidential VMs include Intel SGX that implement hardware-protected application enclaves. Developers can use SGX enclaves to reduce the amount of code that has access to sensitive data to a minimum. Additionally, we will enable Total Memory Encryption-Multi-Key (TME-MK) so that each VM can be secured with a unique hardware key.
Our new AMD-based DCasv5/ECasv5 confidential VMs available provide Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) to provide hardware-isolated virtual machines that protect data from other virtual machines, the hypervisor, and host management code. Customers can lift and shift existing virtual machines without changing code and optionally leverage enhanced disk encryption with keys they manage or that Microsoft manages.
To support containerized workloads, we are making all of our confidential VMs available in Azure Kubernetes Service (AKS) as a worker node option. Customers can now protect their containers with Intel SGX or AMD SEV-SNP technologies.
Azure’s memory encryption and isolation options provide stronger and more comprehensive protections for customer data than any other cloud.
Customer successes across industries
Many organizations are already leveraging the great data privacy and security benefits of Azure confidential computing.
Secure AI Labs have been using a private preview of our AMD-based virtual machines to create a platform where healthcare researchers can more easily collaborate with healthcare providers to advance research. Luis Huapaya, VP of Engineering at Secure AI Labs Inc, mentions, “Because of Azure confidential computing, Secure AI Labs can realize all of the benefits of running in Azure without ever sacrificing on security. One could argue that running a virtual payload within Azure confidential computing might be more secure than running in a private server on-premise. It also offers remote attestation, a pivotal security feature because it provides a virtual payload the ability to give cryptographic proof of its identity and verify its running inside an enclave. Azure confidential computing with AMD SEV-SNP makes our job a lot easier.”
While regulated industries have been the early adopters due to compliance needs and highly sensitive data, we are seeing growing interest across industries, from manufacturing to retail and energy, for example.
Signal Messenger, a worldwide messaging app known for high security and privacy, leverages Azure confidential computing with Intel SGX to protect customer data, such as contact info. Jim O’Leary, VP of Engineering at Signal says, “To meet the security and privacy expectations of millions of people every day, we utilize Azure confidential computing to provide scalable, secure environments for our services. Signal puts users first, and Azure helps us stay at the forefront of data protection with confidential computing.”
We are excited to see organizations bring more workloads to Azure with confidence in the data protection of Azure confidential computing to meet the privacy needs of their customers.
Azure confidential cloud
Azure is the world’s computer from cloud to edge. Customers of all sizes, across all industries, want to innovate, build, and securely operate their applications across multi-cloud, on-premises, and edge. Just as HTTPS has become pervasive for protecting data during internet web browsing, here at Azure, we believe that confidential computing will be a necessary ingredient for all computing infrastructure.
Our vision is to transform the Azure cloud into the Azure confidential cloud, moving from computing in the clear to computing confidentially across the cloud and edge. We want to empower customers to achieve the highest levels of privacy and security for all their workloads.
Alongside our $20 billion investment over the next five years in advancing our security solutions, we will partner with hardware vendors and innovate within Microsoft to bring the highest levels of data security and privacy to our customers. In our journey to become the world’s leading confidential cloud, we will drive confidential computing innovations horizontally across our Azure infrastructure and vertically through all the Microsoft services that run on Azure.
Source: microsoft.com











