Saturday, 7 May 2022

Azure Health Data Services: Engineering product for partners

Azure Health Data Services, Azure Exam Prep, Azure Certification, Azure Tutoria and Material, Azure Career, Azure Skills, Azure Jobs

The healthcare industry has come a long way from putting pen to paper on a pharmacy script or clinical SOAP note to now, being able to deliver primary care in the emerging hospital at home. My career in the healthcare and life sciences (HLS) industry has spanned different roles including: a military clinician, life science entrepreneur, clinical research application scientist, and business leader. Currently, I head the Partner Alliances team for Microsoft’s global health and Life sciences Cloud and Data engineering and product group. Today, I consider myself an HLS generalist bridging the gap between engineering and the application of it in the wild. I look forward to continuing to listen to the needs, implement solutions, and partner with others to bring forward meaningful change in healthcare.

Last month, we launched Azure Health Data Services, a platform as a service (PaaS) offering designed exclusively to support Protected Health Information (PHI) in the cloud, built on the global open standards Fast Healthcare Interoperability Resources (FHIR)® and Digital Imaging Communications in Medicine (DICOM). Watching the team work to develop this product, I feel compelled to share how intentional our product team is at building healthcare technologies for an industry that is currently experiencing historically unprecedented transformation. We are deploying technology that can ingest, transform, and persist data, allowing our customers to use their data to span workflows from discovery research to clinical end points. The underlying technology enables our customers to engage in activities ranging from novel biomarker identification to virtual clinical decision support. For example, today our customers can combine cellular assay data, pathology data, molecular imaging, genomics, handwritten, voice, and text derived notes. With so much data, the goal is to enable our customers to derive insights from a single system of record, so that they can optimize the user experience for patient,  research and clinical workflows so that adherence to treatment increases, scientists gain faster contextual evidence to support their early discoveries and clinicians can spend more time focused on delivering healthcare without experiencing burnout and information overload. The bottom line is, when you can bring these data sets together in a meaningful way, you inherently increase your signal to noise ratio since you are no longer looking for a needle in a haystack; you are looking for a book in a library.

Five years ago, under the leadership of Peter Lee, Microsoft made a purposeful decision that enabled us to lead the way in cloud, data, AI, and innovation. In 2020, Microsoft won the Frost and Sullivan Best Practice Award for our commitment to global AI for healthcare IT growth, and our innovation and leadership in the industry. The Microsoft executive health leadership team realized that we needed a common standards-based platform for healthcare and life sciences data and a secure compliant environment for the industry to build on. To accomplish this, we would need to contribute to the interoperability momentum for FHIR® standard. We also knew we had to lead with partners that know the space better than we do.  We are now focused on building the most trusted, health data platform designed with security and compliance in mind, that is ready to ingest a variety of data types and standards, workflow accelerators, and scenario-specific features. Our hope is that this will enable our ecosystem of partners to push the last mile of innovation for our shared customers in provider, pharmaceutical, payor, and life sciences.

With our partners as the foundation of our business, we will maintain competitive velocity in such transformational times.

Our approach to building Azure Health Data Services has been to support our partners by building and managing the underlying cloud technology so they can remain focused on the front-line industry scenarios. We appreciate the intimate business propriety required to remain innovative and competitive. For this model to work, we must begin and end with the question “are we going to build, buy, or partner for this given product, feature, or capability?” These decisions are rigorous and informed by key industry opinion leaders, the partner ecosystem, and our leadership teams.

Taking inspiration from industry leaders

To support this thesis, we built Health Data Services Partner Alliances team. Our charter is to listen to industry leaders like Tom Arneman at EPAM, BJ Moore at Providence, and the broader trusted advisors across the Microsoft health and life sciences partnership ecosystem. This industry driven feedback challenged us to deliver interoperable, FHIR enabled services and partner led solutions. Partners like Redox, Onyx, 3Cloud, EPAM, SAS, Efferent, Teladoc and ZS Services have been instrumental in providing direct user feedback.

These solutions are coming to life with our mutual customers across the provider, payer and pharma industries. Together we are delivering diversified solutions across the HLS continuum that includes users like translational oncology clinical trial coordinators to care providers remotely accessing their patients. We have worked closely to evolve features with early movers that have deep expertise in multi-modal interoperability deployments, FHIR resource creation, MedTech eventing features for remote patient monitoring, and DICOM for imaging. Now we are scaling these managed services with global partners, their large enterprise HLS practices and industry leading ISV solutions. We are deploying a breadth motion and application toolset that will make it simpler for our partners to build new transactional and analytic SMART on FHIR and other applications on top of Azure Health Data Services.

These partners are the cornerstone of building solutions for the greatest challenges we see today and foresee in years to come. At Microsoft we focus on aligning with them on a defined customer and business opportunity, we then commit resources and appropriate enablement to deliver timely and measurable business value. When we execute in this way, our likelihood of optimized collaboration, product; market fit, market adoption, and long-term partnership is much greater.

Azure Health Data Services is built with the goal of enabling our customers to be able to do more with their health data. We want our partners to be able to provide them solutions to do so—solutions optimized for Azure, Microsoft Cloud for Healthcare and Azure Health Data Services which can help them transform patient experience, discover new insights, and accelerate innovation.

Source: microsoft.com

Tuesday, 3 May 2022

Announcing new investments to help accelerate your move to Azure

Azure Exam Prep, Azure Tutorial and Materials, Azure Preparation, Azure Career, Azure Skills, Azure Preparation Exam

As businesses adapt to new ways of operating, IT leaders are presented with increasing challenges to achieving sustainable growth. Ensuring your business continues to run without interruptions while adapting and transforming can be paramount. If your company is looking for options to migrate your server estate to the cloud, we have news for you.

Outstanding offers

Extended Security Updates and Azure Migration and Modernization Program support to larger migration projects.

Microsoft has great offers for Windows Server and SQL Server customers looking to move to the cloud. Azure offers free Extended Security Updates for SQL Server 2012 and Windows Server 2012/2012 R2, giving you more time to modernize supported applications for three additional years beyond the 10 years granted by Microsoft Support. Microsoft also allows customers to save significantly when running their workloads in Azure Virtual Machines with Azure Hybrid Benefit, which combined with reserved instances can enable up to 85 percent savings when compared to other cloud services.

To help support your migration and modernization to the cloud, mitigating potential unforeseen risks and costs, Microsoft is expanding the Azure Migration and Modernization Program (AMMP). In the past years, AMMP has helped thousands of customers like Jotun unlock the value of the cloud, bringing together the right mix of resources and best practices at every stage of their journey. We’re now investing significantly more to support your largest Windows/SQL Server migration and modernization projects—up to 2.5 times larger based on project eligibility. This investment will help with your migration in two ways: partner assistance with planning and moving your workloads, and Azure credits that offset transition costs during your move to Azure SQL Managed Instance and Azure SQL Database.

Unparalleled innovation

Unlock your SQL Server and Windows Server’s greatest potential in Azure, with unique capabilities and more options for true hybrid cloud flexibility. With Microsoft you can choose the option that aligns best to your business needs, migrating and modernizing servers with solutions like Windows Server and SQL Server running in virtual machines (VMs), Azure SQL managed databases, and hybrid management through Azure Arc.

When you have your VMs in Azure, management becomes simplified with dedicated solutions such as Azure Automanage and Windows Admin Center in the Azure portal. Azure SQL allows you to spend more time innovating and less time patching, updating, and backing up your databases, as Azure is the only cloud with evergreen SQL that automatically applies the latest updates and patches so that your databases are always up to date, eliminating end-of-support hassles. Azure SQL also features built-in AI that automatically tunes databases ensuring peak performance for every database, delivering leading price-performance.

Unmatched security

Security is foundational for Azure. If your company is running SQL Server 2012 and Windows Server 2012/2012 R2, this is the time to consider assessing those environments as they reach the end of support on July 12, 2022 and October 10, 2023 respectively. Not having support means the end of security updates, which may leave your business exposed to security risks and compliance concerns. Azure offers three years of extended security updates.

Multilayered security is provided across physical datacenters, infrastructure, and operations with cyber security experts actively monitoring to protect your Windows Server and SQL Server, including in hybrid deployments with Azure Arc. Microsoft has more than 3,500 cybersecurity professionals and spends $1 billion annually on security to help protect, detect, and respond to threats, so you can grow a safe and secure business. The Azure platform is a leader in compliance coverage with 90 plus compliance offers that allow you to proactively safeguard your data and streamline compliance. Our commitment to privacy is uncompromising. Our core privacy principle is, you own your data. We will never use it for marketing or advertising purposes, in turn providing you confidence around data storage and security. 

Source: microsoft.com

Sunday, 1 May 2022

Meet PCI compliance with credit card tokenization

In building and running a business, the safety and security of your and your customers' sensitive information and data is a top priority, especially when storing financial information and processing payments are concerned. The Payment Card Industry Data Security Standard (PCI DSS) defines a set of regulations put forth by the largest credit card companies to help reduce costly consumer and bank data breaches.

Azure PCI DSS, Microsoft Exam Prep, Microsoft Certification, Microsoft Career, Microsoft Skills, Microsoft Jobs, Microsoft Preparation

In this context, PCI compliance refers to meeting the PCI DSS’ requirements for organizations and sellers to help safely and securely accept, store, process, and transmit cardholder data during credit card transactions, to prevent fraud and theft.

Towards confidential computing

In June 2021, the Monetary Authority of Singapore (MAS) issued an advisory circular on addressing the technology and cyber security risks associated with public cloud adoption. The paper describes a set of risk management principles and best practice standards to guide financial institutions in implementing appropriate data security measures to help protect the confidentiality and integrity of sensitive data in the public cloud, taking into consideration data-at-rest, data-in-motion, and data-in-use where applicable. Specifically, at section 21, reported below, for data that is being used or processed in the public cloud, financial institutes (FIs) may implement confidential computing solutions if available from the cloud service provider. Confidential computing solutions protect data by isolating sensitive data in a protected, hardware-based computing enclave.

Data security and cryptographic key management

FIs should implement appropriate data security measures to protect the confidentiality and integrity of sensitive data in the public cloud, taking into consideration data-at-rest, data-in-motion and data-in-use where applicable.

◉ For data-at-rest, that is, data in cloud storage, FIs may implement additional measures e.g. data object encryption, file encryption or tokenization in addition to the encryption provided at the platform level.

◉ For data-in-motion, that is, data that traverses to and from, and within the public cloud, FIs may implement session encryption or data object encryption in addition to the encryption provided at the platform level.

◉ For data-in-use, that is, data that is being used or processed in the public cloud, FIs may implement confidential computing solutions if available from the CSPs. Confidential computing solutions protect data by isolating sensitive data in a protected, hardware-based computing enclave during processing.

Confidential virtual machines

On these premises, FIs can leverage Azure confidential computing for building an end-to-end data and code protection solution on the latest technology for hardware-based memory encryption. The solution presented in this article for processing credit card payments makes use of confidential virtual machines (CVMs) running on AMD Secure Encrypted Virtualization (SEV)—Secure Nested Paging (SNP) technology.

AMD introduced SEV to isolate virtual machines from the hypervisor. Hypervisors are typically considered trusted components in the virtualization security model, and many customers have requested a VM trust model which reduces the exposure to vulnerabilities in the infrastructure. With SEV, individual VMs are assigned a unique encryption key wired in the CPU, used for automatically encrypting the memory allocated by the hypervisor to run a VM.

The latest generation of SEV technology includes SNP capability. SNP adds new hardware-based security by providing strong memory integrity protection from potential attacks to the hypervisor, including data replay and memory re-mapping.

Azure confidential computing offers confidential VMs based on AMD processors with SEV-SNP technology. Confidential VMs are for tenants with high security and confidentiality requirements. You can use confidential VMs for migrations without making changes to your code, with the platform help protect your VM’s state from being read or modified. Benefits of confidential VMs include:

◉ Robust hardware-based isolation between virtual machines, hypervisor, and host management code.

◉ Attestation policies to ensure the host’s compliance before deployment.

◉ Cloud-based full-disk encryption before the first boot.

◉ VM encryption keys that the platform or the customer (optionally) owns and manages.

◉ Secure key release with cryptographic binding between the platform’s successful attestation and the VM’s encryption keys.

◉ Dedicated virtual Trusted Platform Module (TPM) instance for attestation and protection of keys and secrets in the virtual machine.

The provisioning of a confidential VM in Azure is as simple as any other regular virtual machine, using your preferred tool, either manually via the Azure Portal, or by scripting with Azure command-line interface (CLI). Figure 2 shows the process of creating a virtual machine in the Azure Portal, with specific attention to the “Security type” attribute. For provisioning a confidential VM based on AMD SEV-SNP technology, you have to select that specific entry in the dropdown list. At the time of writing (March 2022), confidential VMs are in preview in Azure, and thus limited in availability across regions. As this service enters general availability, more regions will be available for deployment.

Azure PCI DSS, Microsoft Exam Prep, Microsoft Certification, Microsoft Career, Microsoft Skills, Microsoft Jobs, Microsoft Preparation
Figure 1: Confidential Virtual Machine in Azure Portal.

Credit card tokenization


In the scenario above in Figure 2, the process of tokenization is a random oracle, which is a process that, given an input, generates a non-predictable output. The random output always varies even if the same input is provided. For example, when a customer makes a second payment using the same credit card used in a previous transaction, the token generated will be different. Lastly, when providing that random output back to the service, the tokenization interface fetches the original input.

Not by coincidence that I used the term “interface” for describing this tokenization service. Indeed, the technical implementation of such random generator is a Web API running in the .NET 6 runtime. Figure 3 describes the reference architecture for the solution.

Azure PCI DSS, Microsoft Exam Prep, Microsoft Certification, Microsoft Career, Microsoft Skills, Microsoft Jobs, Microsoft Preparation
Figure 2: Credit card tokenization architecture reference.

1. A payment transaction is initiated by the customer and payment data is transferred to the .NET Web API. This API is running on a confidential VM.

2. The random token is generated by the API based on the input data. Tokenization includes also encryption of such data, with a symmetric cryptographic algorithm (AES specifically).

3. The encryption key is stored in Azure Key Vault running on a managed Hardware Secure Module (HSM). This is a critical component of the confidential solution, as the encryption key is preserved inside the HSM. The HSM helps protecting keys from the cloud provider or any other rogue administrator. Only the Web API app is authorized to access the secret key.

The following code snippets show the implementation of the key retrieval from AKV inside the Get method of the Web API.

[HttpGet(Name = "GetToken")]
public async Task<TokenTuple> Get(CreditCard card)
{
        // Retrieve the AES encryption key from AKV
        string akvName = Environment.GetEnvironmentVariable("KEY_VAULT_NAME");
        var akvUri = $"https://{akvName}.vault.azure.net";
        var akvClient = new SecretClient(new Uri(akvUri), new Azure.Identity.DefaultAzureCredential());
        var secret = await akvClient.GetSecretAsync("AesEncryptionKey");
        EncryptionKey key = JsonSerializer.Deserialize<EncryptionKey>(secret.Value.Value);

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant, standards-compliant cloud service that enables you to safeguard cryptographic keys for your cloud applications, using FIPS 140-2 Level 3 validated HSMs.

The service is highly available and zone resilient (where availability zones are supported): Each HSM cluster consists of multiple HSM partitions that span across at least two availability zones. If the hardware fails, member partitions for your HSM cluster will be automatically migrated to healthy nodes.

Each Managed HSM instance is dedicated to a single customer and consists of a cluster of multiple HSM partitions. Each HSM cluster uses a separate customer-specific security domain that cryptographically isolates each customer's HSM cluster.

The HSM is FIPS 140-2 Level 3 validated, which means that it meets compliance requirements with Federal Information Protection Standard 140-2 Level 3.

AKV Managed Hardware Security Module (MHSM) also assists with data residency as it doesn't store and process customer data outside the region the customer deploys the HSM instance in.

Lastly, with AKV MHSM, customers can generate HSM-protected keys in their own on-premises HSM and import them securely into Azure.

4. The obtained encryption key is then used to encrypt the payment data with a symmetric cipher. The encrypted value is associated with a newly generated token and added as a message to the queue. In the code snippet below, the pair token and encrypted data is stored in a tuple object and then enqueued.

// Encrypt the credit card information
string json = JsonSerializer.Serialize(card);
string encrypted = SymmetricCipher.EncryptToString(json, key);

// Generate token
Token token = Token.CreateNew();

// Add the token tuple to the queue
TokenTuple tuple = new (token, encrypted);
QueueManager.Instance.Enqueue(tuple);

5. The generated token is added to an in-memory queue. There is no persistence of data in the solution. The token expires after a configurable amount of time, typically a few seconds, that allows the payment gateway to process the payment information from the queue. The combination of running this solution on a confidential infrastructure, as well as the volatility of data in the queue, helps customers make their system PCI compliant: no sensitive payment data is stored and processed in clear text.

6. The queue mechanism can be implemented with any highly reliable queue engine, such as RabbitMQ. By running in a confidential VM, confidentiality of data in the queue is retained also during in-memory processing utilizing a third-party application such as RabbitMQ or similar with no code changes.

7. The payment gateway implements the Publish-Subscribe pattern (Pub-Sub) for retrieving messages from the queue, using a webhook for registering the endpoint to invoke and de-queue a message.

[HttpGet(Name = "ResolveToken")]
        public async Task Post(string subscriberUri)
        {
            TokenTuple tuple = QueueManager.Instance.Dequeue();
            await HttpClientFactory.PostAsync(subscriberUri, tuple);
        }

Source: microsoft.com

Saturday, 30 April 2022

Unlock cloud savings on the fly with autoscale on Azure

Azure Exam Prep, Azure Certification, Azure Tutorial and Material, Azure Career, Azure Skills, Azure Job

Unused cloud resources can put an unnecessary drain on your computing budget, and unlike legacy on-premises architectures, there is no need to over-provision compute resources for times of heavy usage.

Autoscaling is one of the value levers that can help unlock cost savings for your Azure workloads by automatically scaling up and down the resources in use to better align capacity to demand. This practice can greatly reduce wasted spend for those dynamic workloads with inherently “peaky” demand.

In some cases, workloads with occasionally high peak demand have extremely low average utilization, making them ill-suited for other cost optimization practices, such as rightsizing and reservations.

For periods when an app puts a heavier demand on cloud resources, autoscaling adds resources to handle the load and satisfy service-level agreements for performance and availability. And for those times when the load demand decreases (nights, weekends, holidays), autoscaling can remove idle resources to reduce costs. Autoscaling automatically scales between the minimum and maximum number of instances and will run, add, or remove VMs automatically based on a set of rules.

Azure Exam Prep, Azure Certification, Azure Tutorial and Material, Azure Career, Azure Skills, Azure Job

Autoscaling is near real-time cost optimization. Think of it this way: Rather than build an addition to your house with extra bedrooms that will go unused most of the year, you have an agreement with a nearby hotel. Your guests can check-in, at any time and at the last minute, and the hotel will automatically charge you for the days when they visit.

Not only does it utilize cloud elasticity by paying for capacity only when you need it, you can also reduce the need for an operator to continually monitor the performance of a system and make decisions about adding or removing resources.

What services can you autoscale?


Azure provides built-in autoscaling using Azure Monitor autoscale for most compute options, including:

◉ Azure Virtual Machines Scale Sets

◉ Service Fabric

◉ Azure App Service

◉ Azure Cloud Services has built-in autoscaling at the role level. 

Azure Functions differs from the previous compute options because you don't need to configure any autoscale rules. The hosting plan you choose dictates how your function app is scaled:

◉ With a consumption plan, your functions app will scale automatically, and you will only pay for compute resources when your functions are running.

◉ With a premium plan, your app will automatically scale based on demand using pre-warmed workers that run applications with no delay after being idle.

◉ With a dedicated plan, you will run your functions within an App Service plan at regular App Service plan rates.

Azure Monitor autoscale provides a common set of autoscaling functionality for virtual machine scale sets, Azure App Service, and Azure Cloud Service. Scaling can be performed on a schedule, or based on a runtime metric, such as CPU or memory usage.

Use the built-in autoscaling features of the platform if they meet your requirements. If not, carefully consider whether you really need more complex scaling features. Examples of additional requirements may include more granularity of control, different ways to detect trigger events for scaling, scaling across subscriptions, and scaling other types of resources.

Note that application design can impact how that app handles scale as a load increases. To review design considerations for scalable applications, including choosing the right data storage and VM size, and more, check out Design scalable Azure applications—Microsoft Azure Well-Architected Framework.

Also know that, in general, it is better to scale up than to scale down. Scaling down usually involves deprovisioning or downtime. So, choose smaller instances when a workload is highly variable and scale out to get the required level of performance.

You can set up autoscale in the Azure portal, PowerShell, Azure CLI, or Azure Monitor REST API.

Source: microsoft.com

Friday, 29 April 2022

Study Resources for Microsoft AZ-400 Exam Preparation


The AZ-400
Microsoft Azure DevOps Solutions certification exam measures and confirms an applicant's skill as a DevOps Professional around utilizing Microsoft Azure technologies for designing and executing DevOps practices. This exam is a part of the required exams required to achieve the more comprehensive Microsoft Certified: Azure DevOps Engineer Expert certification.

Microsoft AZ-400 Certification Overview

The AZ-400 Microsoft Azure DevOps Solutions certification exam is designed for DevOps Professionals who link people, processes, and tools to constantly provide value to fulfill users' needs and business goals. These applicants simplify delivery by improving practices, enhancing communication and collaboration, and generating automation. They design and enforce app code and infrastructure tactics that enable continuous integration, testing, delivery, and constant observation and feedback.

Exam takers are expected to be experts in Agile practices, must be acquainted with both Azure Administration and Azure Development, and should be masters in one of these areas. They must be capable of designing and executing DevOps practices for version control, infrastructure as code (IaC), compliance, build, configuration management, release, and testing by utilizing Microsoft Azure technologies.

AZ-400 Exam Objectives

  • Develop an instrumentation strategy (5-10%)
  • Develop a Site Reliability Engineering (SRE) strategy (5-10%)
  • Develop a security and compliance plan (10-15%)
  • Manage source control (10-15%)
  • Facilitate communication and collaboration (10-15%)
  • Define and implement continuous integration (20-25%)
  • Define and implement continuous delivery and release management strategy (10-15%)

AZ-400 Microsoft DevOps Solutions Exam Structure

  • Certification Name: Microsoft Certified: Azure DevOps Engineer Expert
  • Question Type: Multiple-choice, Multiple-answer, Sequence type, Case studies based questions
  • Exam Cost: USD 165.00
  • Total Questions: 40 – 60 Questions
  • Exam Duration: 150 Minutes
  • Languages: English, Japanese, Chinese (Simplified), Korean, Spanish, German, and French

Is the Microsoft Azure AZ-400 Exam Difficult to Pass?

Achieving a Microsoft Certification is every professional's dream, and it helps them make higher salaries and fill the gap in their dream job. But the most crucial question is how difficult is the Microsoft Azure AZ-400 exam? Well, one thing is sure this exam is not impossible to crack. The pass ratio is low, but if you have the appropriate preparation plan. Furthermore, if you have former knowledge and a thorough understanding of the field of Azure, then the exam is not difficult to crack. On the contrary, if this is your first Microsoft Azure exam, in the first place, you must concentrate on the AZ-400 syllabus topics. Line up your preparation with the exam course and concepts.

However, it is not easy to pass the certification exam, as discussed, and it demands a lot of preparation and practice. So to smoothen your preparations, read the next section!

Study Resources for Microsoft DevOps Engineer AZ-400 Exam Preparation

The study resources you prefer explain how well you will be performing in the exam. But with the lots of options available for Microsoft exam preparation, it usually becomes challenging to select the right resources. Here is a list of a few resources that will boost your learning. Furthermore, they will help you take your preparations to the next level.

1. Make Most Out of Microsoft Documentation

Microsoft provides Microsoft documentation that includes various learning pages, and Microsoft documentation aids you in understanding various scales of different Azure services in a much more thorough manner. This will assure that you are working by the clock and understanding so many new azure technologies offered by industry professionals straight to you.

2. Take Up Instructor-Led Training Course

Microsoft offers online and instructor-led training courses that are on-demand classroom lectures that you can smoothly arrange anywhere and anytime. Furthermore, these training courses help you understand the AZ-400 exam syllabus in-depth. The course for the AZ-400 exam is:

Designing and Implementing Microsoft DevOps solutions

3. Obtain the Appropriate Books

Books have been a traditional and vital element for any exam preparation. They equip you with a profound understanding of the AZ-400 syllabus. Also, books provide real-life scenarios that help you qualify for a practical exam.

4. Gauge Your Preparation Level with AZ-400 Practice Test

Mistakes are unavoidable, but certainly, they can be restricted. When it comes to Microsoft exams, practice tests help in reducing errors. Moreover, readying the brain is vital. Practice tests offer that simulation in which the brain requires to get used to the real exam. Hence after studying the complete syllabus, you need to perform AZ-400 practice tests to assess your performance. This will help you out find your strong and weak areas. Moreover, attempting numerous AZ-400 practice tests will enhance your confidence. Try improving yourself with each subsequent exam.

Why Earn Microsoft AZ-400 Certification?

  • AZ-400 opens the door to career-changing opportunities for those individuals who are bound to use Cloud operations and surpass in the Cloud Computing field.
  • Earning this Microsoft certification will improve your knowledge of technical DevOps.
  • Applicants get the right idea of how to enforce techniques for continuous delivery and integration.
  • Applicants are qualified to formulate the security plans of an organization's applications and services on Azure Cloud. Therefore, it assists them in solving the credibility problems to operate all business operations seamlessly.
  • A large number of enterprises are progressively moving to DevOps and are executing related practices. With AZ-400 certification, applicants can outshine the crowd and open various lucrative job opportunities.
  • Because the competition is mounting among the organizations and Cloud implementations, different enterprises will prefer to hire Certified engineers over non-certified professionals.
  • The DevOps engineers holding Microsoft AZ-400 certification hold the skills working with Agile practices, and they are skilled in how to deliver secure and fast outcomes. Thus, AZ-400 certified Microsoft DevOps Engineers are among the IT field's highest-paying professionals.

Summary

In the present IT field, the AZ-400 exam is sought-after and one of the high-paid certifications. Those organizations working in Cloud always prioritize hiring Microsoft Azure DevOps Engineers who have passed Microsoft exam AZ-400. If you are determined to pursue the examination, you have to execute a lot of effort and have the perseverance to prepare for the same entirely. Following the tips and recommendations discussed above helps applicants pass the AZ-400 exam on the first try.

Thursday, 28 April 2022

Optimize your cloud investment with Azure Reservations

Azure Reservations, Azure Exam Prep, Azure Exam Prep, Azure Learning, Azure Career, Azure Skills, Azure Jobs, Azure Preparation

Continuous cost optimization can take place at all stages of an Azure workload’s lifecycle, but your Azure subscription provides a very effective benefit to further optimize your investment when you are ready to deploy that workload.

For cloud workloads with consistent resource usage, you can buy reserved instances at a significant discount and reduce your workload costs by up to 72 percent compared to pay-as-you-go prices. Azure Reservations can be obtained by committing to one-year or three-year plans for virtual machines, Azure Blob storage or Azure Data Lake Storage Gen2, SQL Database compute capacity, Azure Cosmos DB throughput, and other Azure resources.

When you can predict and commit to needed capacity, it gives us visibility into your resource requirements in advance, allowing us to be more efficient in our operations. We can then pass the savings on to you. This benefit applies to both Windows and Linux virtual machines (VMs).

In addition, you now can combine the cost savings of reserved instances with the added Azure Hybrid Benefit when running on-premises and Azure workloads to save up to 80 percent over pay-as-you-go pricing.

How to get your reservation

A reservation discount only applies to resources associated with Enterprise Agreement, Microsoft Customer Agreement, Cloud Solution Provider (CSP), or subscriptions with pay-as-you-go rates. These are billing discounts (paid upfront or monthly) and do not affect the runtime state of your resources. And do not worry, you will not pay any extra fees when you choose to pay monthly.

To determine which reservation to purchase, analyze your usage data in the Azure portal, or use reservation recommendations available in Azure Advisor (VMs only), the Cost Manage Power BI app, or the Reservation Recommendations REST API.

Reservation purchase recommendations are calculated by analyzing your hourly usage data over the last seven, 30, and 60 days.

Simple and flexible

You can purchase Azure Reserved VM Instances in three easy steps—just specify your Azure region, virtual machine type, and term (one year or three years)—that's it.

Here is how it works: Discounts are generally applied to the resource usage matching the attributes you select when you buy the reservation. Attributes include the scope where the matching VMs, SQL databases, Azure Cosmos DB, or other resources run. Attributes include the SKU, regions (where applicable), and scope. Reservation scope selects where the reservation savings apply. You can scope a reservation to a subscription or resource group. When you scope the reservation to a resource group, reservation discounts apply only to the resource group—not the entire subscription.

You can manage reservations for Azure resources including updating the scope to apply reservations to a different subscription, changing who can manage the reservation, splitting a reservation into smaller parts, or changing instance size. Enhanced data for reservation costs and usage is available for Enterprise Agreement (EA) and Microsoft Customer Agreement (MCA) usage in Azure Cost Management and Billing. Those same customers can view amortized cost data for reservations and use that data to chargeback the monetary value for a subscription, resource group, or resource.

Capacity on demand

The ability for you to access compute capacity with service-level agreements, and ahead of actual VM deployments, is important to ensure the availability of mission-critical applications running on Azure. On-demand capacity reservations, now in preview, enable you to reserve compute capacity for one or more virtual machine size(s) in an Azure region or availability zone for any length of time. You can create and cancel an on-demand capacity reservation at any time, no commitment is required.

You also can exchange a reservation for another reservation of the same type or refund a reservation, up to $50,000 USD in a 12-month rolling window if you no longer need it, or cancel a reserved instance at any time and return the remaining months to Microsoft.

Source: microsoft.com

Tuesday, 26 April 2022

Enhance your classroom experience with Azure Lab Services—April 2022 update

Azure Lab Services, Microsoft Exam Prep, Microsoft Career, Microsoft Skills, Microsoft Jobs, Microsoft Preparation, Microsoft Skills, Microsoft Jobs

Azure Lab Services offers classroom labs for higher education, K-12 institutions, and commercial organizations that don't want to use the on-premises hardware but rather want to harness the power of the cloud to host labs for students or users. We are excited to announce major updates to Azure Lab Services including enhanced lab creation and improved backend reliability, access performance, extended virtual network support, easier labs administration via new roles, improved cost tracking via Azure Cost Management service, availability of PowerShell module, and .NET API SDK for advanced automation and customization, and integration with Canvas learning management system. Learn more about the new update and how to use it.

Along with making significant reliability enhancements to the backend, labs creation, and access performance improvements, this major update is bringing a whole slew of additional features for the IT departments and administrators, educators, and the students, who are the three key personas that use this service.

IT and administrators

For the IT and administrators, we have now introduced the concept of a lab plan instead of a lab account to provide more control over the creation, configuration, and management of the labs. For ease of administration of the lab, new roles have been created to provide granular control for different people managing labs for a large organization.

Creating a large number of labs with many virtual machines requires additional vCPUs which you have to request from us. With this new update, there is an improved vCPU capacity management for your subscription and you don't share the vCPU capacity with others using the service. We have also now made it easier for you to track costs for your lab resources in Azure Cost Management. We have replaced virtual network peering with virtual network injection. With Virtual Network Injection you have more control over the network for lab virtual machines. In your own subscription, create a virtual network in the same region as the lab, delegate a subnet to Azure Lab Services, and you’re off and running.

For advanced automation, deployment, configuration, and management we have the PowerShell module and .NET API SDK. The Azure Lab Services PowerShell will now be integrated with the Azure PowerShell module and will release early February. In alignment with all the global compliance and regulatory laws around data residency, we are also saving the customer data in the regions where the labs are set up.

Educators

For all the educators and instructors using the service, we have added new functionality to improve their experience. Azure Lab Services can now be integrated within Canvas, a popular learning management system. Educators can use Canvas to create and configure labs for the students. Students can connect to the virtual machine from inside their course in Canvas. We have improved the auto-shutdown feature of the virtual machine. Auto-shutdown settings are now available for all operating systems. In addition, we have improved idle detection based on resource usage. For more flexibility, an instructor or IT Administrator can choose to skip the virtual machine template creation process if they already have an image ready to use or want to quickly deploy virtual machines for their lab.

Students

Student experiences have also improved. Students can now redeploy their virtual machine without losing data if they are having issues accessing or using the virtual machine. If the lab is set up to use AAD group sync, there is no longer a need to send an invitation email so students can access their virtual machine—one is assigned to the student automatically.

Source: microsoft.com