Saturday, 4 November 2023

Introducing Azure Bastion Developer: Secure and cost-effective access to your Azure Virtual Machines

Microsoft Azure is constantly evolving to meet the needs of its growing user base. In response to the feedback and requirements of developers, we have announced a new SKU for Azure Bastion: Bastion Developer. This service, now in public preview, will be a game-changer for developers seeking secure, cost-effective, and hassle-free connectivity to their Azure Virtual Machines. In this blog post, we’ll explore what Azure Bastion Developer is, the problems this new SKU addresses, and why it’s a must-try solution for developers.

What is Azure Bastion Developer?


Azure Bastion Developer is a new low-cost, zero-configuration, always-on SKU of the Azure Bastion service. Its primary mission is to provide secure-by-default Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to Azure Virtual Machines, allowing users to establish secure connections to a single Virtual Machine at a time without the need for additional network configurations or public IP addresses on Virtual Machines. This service is designed to simplify and enhance the process of accessing your Azure Virtual Machines by eliminating the complexities, high costs, and security concerns often associated with alternative methods.

Addressing developer pain points


Azure Bastion Developer has been developed with the aim of addressing three common issues that developers encounter when connecting to Azure Virtual Machines:

1. Discovery

When developers create standalone Virtual Machines, they may not actively seek out Azure Bastion, and it might not be readily apparent during the Virtual Machine creation process. While IT professionals are familiar with the concept of a bastion host or jump-box server, the average Azure user may not be. This could lead to the use of less secure public IP-based access methods. Azure Bastion Developer solves this problem by providing secure and seamless access directly in the Virtual Machine blade. In the coming months, Bastion Developer will populate as the recommended connectivity option in the Virtual Machine connect experience for available regions.

2. Usability

Setting up Azure Bastion has traditionally required users to deploy a new resource and follow a series of configuration steps, including the creation of a dedicated subnet. While these steps might be manageable for technically savvy users, they can be complex and time-consuming for many. Azure Bastion Developer simplifies the process by offering an easy-to-use, zero-configuration solution. Users can opt-in to use it during Virtual Machine connection, making secure access a breeze.

3. Cost

Azure Bastion Basic, while a powerful tool, may be a potentially expensive choice for developers who spend a few hundred dollars or less in Azure each month, leading them to connect with less secure public IP based options. Azure Bastion Developer addresses this concern by providing an option that comes at a more affordable price point than public IP. This cost-effective pricing will make Azure Bastion Developer the default private connectivity option in Azure, enabling developers to enjoy secure access without breaking the bank. The public preview of Bastion Developer will be free with more details on pricing when generally available.

Connectivity Options with Azure Bastion Developer


1. Portal-based access (public preview). Bastion Developer will offer support for RDP connections for Windows Virtual Machines and SSH connections for Linux Virtual Machines in the Azure portal.

2. Native client-based access for SSH (roadmap). Bastion Developer will offer support for SSH connections for Linux Virtual Machines via Azure Command Line Interface (CLI) in the coming months.

Feature comparison of Azure Bastion offerings


Bastion Developer will be a lightweight SKU of the Bastion service, allowing a single connection per user directly through the Virtual Machines connect experience. Bastion Developer is ideal for Dev/Test users who want to securely connect to their Virtual Machines without the need for additional features or scaling. The feature matrix below outlines the differences between Bastion Developer and Bastion Basic and Standard SKUs.

Features Developer  Basic  Standard 
Private connectivity to Virtual Machines Yes Yes  Yes 
Dedicated host agent  No Yes  Yes 
Support for multiple connections per user  No  Yes Yes 
Linux Virtual Machine private key in AKV   No  Yes  Yes 
Support for Network Security Groups   No  Yes Yes 
Audit logging   No  Yes  Yes 
Kerberos support   No  Yes  Yes 
VNET peering support   No  Yes  Yes
Host scaling (2-50 instances)   No  No  Yes
Custom port and protocol No  No  Yes 
Native SSH support via Azure CLI   Roadmap Roadmap  Yes 
Native RDP support via Azure CLI   No  No  Yes 
Azure Active Directory login for RDP/SSH via native client  No  No  Yes 
IP-based connection   No  No  Yes 
Shareable links   No  No  Yes 

How to get started


We invite you to preview Azure Bastion Developer in your cloud environment.

1. Navigate to the Azure portal.
2. Deploy a Windows or Linux Virtual Machine in one of the regions below. Note that Bastion Developer is currently only available in the following regions:
  1. Central United States EUAP
  2. East United States 2 EUAP
  3. West Central United States
  4. North Central United States
  5. West United States
  6. North Europe
3. Navigate to the Bastion tab in the Virtual Machine blade and click Deploy Bastion Developer. (Bastion Basic and Standard deployments will be moved under “Dedicated Deployment Options”).
4. Once your Bastion Developer resource is deployed, enter your Virtual Machine username and password and select Connect to securely connect to your Virtual Machine in the browser.

Introducing Azure Bastion Developer: Secure and cost-effective access to your Azure Virtual Machines

Introducing Azure Bastion Developer: Secure and cost-effective access to your Azure Virtual Machines

Thursday, 2 November 2023

Protect your web apps from modern threats with Microsoft Defender for Cloud

Protect your web apps from modern threats with Microsoft Defender for Cloud

In this era of AI-driven competition, enterprises of all sizes have prioritized the value of migrating their app development from on-premises to the cloud. As developers rapidly publish new cloud applications, bad actors are equally relentless in seeking new ways to exploit misconfigured resources. One question that comes up for enterprise cloud architects is, how can you best protect your cloud deployments from attacks? More importantly, how do you incorporate security practices for cloud systems that may be different from on-premises systems and different between cloud service providers?

That’s where the power of a managed platform as a service (PaaS) with integrated cloud security comes in. Azure App Service provides native security integration with Defender for App Service in Microsoft Defender for Cloud to help protect multicloud and hybrid environments with comprehensive security across the full lifecycle, from development to runtime. In this blog, we will explore another well-kept secret: how seamless and worry-free it can be to safeguard your web applications using the integration with Defender for App Service.

Protect your web apps from modern threats with Microsoft Defender for Cloud

Native security integration with a Zero Trust approach


Defender for App Service is a Microsoft first-party solution that uses the scale of the cloud to identify attacks targeting applications running in Azure App Service, providing more robust security when you migrate from your on-premises web apps. With this migration to App Service, you receive automatic platform maintenance and security patching so you’re always running the latest versions of the operating system, language frameworks, and runtime software.  

By enabling Defender for App Service, you get an extra layer of protection for your App Service plan that assesses the resources and generates security recommendations based on its findings. Since it seamlessly integrates with Azure App Service, it minimizes the need for deployment and onboarding overhead on your end and requires no alterations to your apps to detect threats.  

Attackers routinely probe web applications to find and exploit weaknesses. Before being routed to specific environments, requests to applications running in Azure go through several gateways, where they’re inspected and logged. Our Zero Trust approach collects signals from your organization’s cloud app usage without any reconfiguration, with Azure Web Application Firewall optionally safeguarding data transmission between your environment and these applications. Defender for App Service then works to detect harmful exploits and malicious behavioral patterns in web apps and web app runtime activity. 

You can use the detailed instructions in these recommendations to harden your App Service resources, meaning your team will also have complete behind-the-scenes visibility into potential threats and misconfiguration. With Defender for App Service integrated with your Azure App Service deployment and managed by Microsoft, your web apps are assured of the latest security protection without necessarily requiring you to first become a hands-on Zero Trust expert.

Enhanced detection and response capabilities at scale 


Security in the cloud provides scalable defenses that are constantly updated and expertly managed. By enabling Defender for App Service in Defender for Cloud, you can implement robust security practices early in the software development process, secure code management environments, and gain valuable insights into your development environment’s security posture.  

Defender for Cloud provides a centralized view of security alerts across all your Azure resources, including App Service. It generates cloud-centric security recommendations after assessing these resources, based on the Microsoft cloud security benchmark. You can then use the detailed instructions in these recommendations to harden your App Service resources. 

Our customers have found that using security benchmarks can help you quickly secure cloud deployments. A comprehensive security best practice framework from cloud service providers can give you a starting point for selecting specific security configuration settings in your cloud environment, across multiple service providers and allow you to monitor these configurations using a single pane of glass.  

These recommendations include two key aspects: 
 
◉ Security controls: These recommendations are generally applicable across your cloud workloads. Each recommendation identifies a list of stakeholders that are typically involved in the planning, approval, or implementation of the benchmark. 
◉ Service baselines: These apply the controls to individual cloud services to provide recommendations on that specific service’s security configuration.  

Defender for App Service provides tools to help you investigate and respond to security incidents, and because it is natively integrated with Azure App Service, it’s easy to enable with just a few clicks. By utilizing the two services together, Your IT team will be able to quickly identify and fix the root cause of an attack, so that your apps can be brought back online as quickly as possible. 

A playbook for staying ahead of digital threats 


Defender for App Service maps threats according to the MITRE ATT&CK framework. The MITRE ATT&CK framework is a comprehensive list of ways that cyber attackers can try to break into and exploit computer systems. The framework helps cybersecurity experts understand and defend against these attacks by giving them a clear idea of what tactics and techniques bad actors might use.  

Defender for Cloud can also detect ongoing attacks, even if it is deployed after a web app has been exploited. This is because it can analyze log data and infrastructure data together to identify suspicious activity, such as new attacks circulating in the wild or compromises in customer applications. 

Improve the security posture of your web apps running on App Service 


Migrating apps to Azure App Service can help improve security posture in several ways. To recap some of the benefits: 

  • A secure and hardened platform: Actively monitored and updated by Microsoft, you don’t have to worry about managing the underlying infrastructure, network, or software components. 
  • HTTPS and TLS encryption: Supported for all communication, both inbound and outbound. You can also enforce HTTPS and disable outdated protocols to prevent unencrypted or insecure connections. 
  • Restricted app access based on IP addresses, client certificates, or user identities: You can also use the App Service authentication feature to integrate with various identity providers, such as Microsoft Entra ID (formerly Azure Active Directory), Facebook, Google, or OpenID Connect providers. 
  • Managed identities: Securely access other Azure resources, such as SQL Database or Storage, without storing any secrets in your code or configuration files. You can also store sensitive app settings and connection strings as secrets in Azure Key Vault, and then monitor your Key Vault using Defender for Key Vault. 
  • Integrated with additional security products: App Service works with industry-leading features and tools that can help you detect and mitigate threats, such as web application firewall (WAF), Microsoft Defender for Cloud, and Azure Sentinel. 

Enable Defender for App Service in your App Service plan today 


Defender for App Service provides continuous security assessment and recommendations to help you harden your Azure App Service resources and improve your secure score. It detects and alerts you of various attacks, such as user-agent injection, web shell activity, and dangling DNS. You can also view the attack details and mitigation steps in the Azure portal or use Azure Sentinel to investigate and respond to incidents. 

Since Defender for App Service is natively integrated with App Service, you don’t have to install or configure anything. Simply enable it on your App Service subscription and refer to the pricing options to customize your plan.

Source: microsoft.com

Tuesday, 31 October 2023

FOCUS: A new specification for cloud cost transparency

FOCUS: A new specification for cloud cost transparency

When it comes to FinOps, the data is of the upmost importance. Data is the key to understanding your cloud cost and usage patterns, and pivotal to making smart decisions about your cloud strategy and operations. This is why Microsoft is proud to be a founding member of the FinOps Open Cost and Usage Specification (FOCUS) project and why we’re excited to add support in Cost Management after FOCUS 1.0 is available later this year. In the meantime, start preparing for FOCUS by familiarizing yourself with the current specification, joining the FOCUS community, and providing feedback on your use cases and needs.

What is FOCUS?

FOCUS is a groundbreaking initiative to define a common format for billing data that empowers organizations to better understand cost and usage patterns and optimize spending and performance across multiple cloud, SaaS, and even on-premises service offerings.

FOCUS will provide organizations with a consistent, clear, and accessible view of their cost data explicitly designed for FinOps needs such as allocation, analytics, monitoring, and optimization. As the new “language” of FinOps, FOCUS will enable practitioners to collaborate more efficiently and effectively with peers throughout the organization and even maximize transferability and onboarding for new team members, getting people up and running quicker. Paired with the FinOps Framework, practitioners will be armed with the tools needed to build a streamlined FinOps practice that maximizes the value of the cloud.

Why organizations need FOCUS

The variety and flexibility of Microsoft cloud services allows you to build amazing things while only paying for what you need, when you need it. And with this flexibility comes varying operational models where services are billed and can be tuned differently based on a variety of factors. When services are billed differently, their cost and usage data tends to differ as well, making it challenging to allocate, analyze, monitor, and optimize consistently. Of course, this goes beyond just Microsoft’s cloud services. Organizations often rely on software as a service (SaaS) products, licensed software, on-premises infrastructure, or even other clouds, exacerbating the problem with each provider sharing data in proprietary formats.

FOCUS solves this problem by establishing a provider and service agnostic data specification that addresses some of the biggest challenges organizations face in managing the value of their cloud investments—understanding and quantifying the business value of their spending. FOCUS will enable organizations to spend more time driving value and less struggling to understand data caused by inconsistencies between and unfamiliarity with different services and providers.

“At Walmart, we spend a lot of our time not only normalizing data across different clouds, but we’re also constantly reacting to changing SKUs and services in areas like Storage, Compute, and AI/ML. One of the most significant outcomes of FOCUS isn’t just that we’re aiming to simplify and standardize on a common specification, it’s the conversations that are starting on best practices – How should we all think about amortization for committed and reserved instances? What are our standard values for service categories?

It’s much more than just a conversation about a few fields. It’s a discussion that will help define best practices and standards for a cloud computing market that continues to expand into new areas like SaaS, IoT, and Gen AI. We’re discussing standards today that will be the foundation of how we talk about cost decades from now. It’s exciting.“—Tim O’Brien, Senior Director of Engineering, Cloud Cost Management at Walmart Global Tech.

Why Microsoft believes in FOCUS

But why would Microsoft want to join other cloud providers and SaaS vendors to promote a common billing data specification? Because consistent cloud billing promotes the innovation and experimentation that Azure is built to provide. Building and optimizing applications in Azure in an iterative way using modern architectures is easier when you clearly understand how you’re billed and can weigh cost equally amongst other business priorities in building those systems. Better collaboration between business, technical, and finance teams will make your organization more productive overall, which maps back to our core mission to empower every person and every organization on the planet to achieve more.

“At FinOps X 2022, when Udam Dewaraja first introduced the idea of the FinOps community and service providers joining forces to establish an open billing data specification, I was hooked but also somewhat skeptical about whether major cloud providers would be willing to engage and adopt this upcoming specification (and natively support the new dimensions and metrics). However, during the very first FOCUS meeting, Microsoft’s Cost Management team proved me wrong, and my skepticism quickly faded away!”—Irena Jurica, Solution Architect at CloudVane, Neos.

Widespread adoption of FOCUS will make allocating, analyzing, monitoring, and optimizing costs across providers as easy as using a single provider, enabling you to do more with less. FinOps skills become more portable than ever, and practitioners, vendors, and consultants will become more efficient and effective when moving to an organization that uses different clouds or SaaS products. Without having to spend time learning proprietary data formats, organizations can focus on value-added FinOps capabilities that help deliver real value.

Our adoption of FOCUS removes a barrier to cloud adoption and helps organizations make better data-driven decisions about their cloud use that translates to business value on top of the Microsoft cloud.

Getting started with FOCUS

The FOCUS 0.5 release was announced in June 2023 and introduced a standardized way to describe fundamental concepts which apply to any provider.

Resources are identified by a ResourceId and ResourceName and organized into their respective ServiceName and ServiceCategory. ServiceCategory enables you to organize your costs into a top-level set of categories consistent across cloud providers, which makes it especially interesting. You can also see additional details, like the Region a resource was deployed to, the PublisherName of the company who developed the service, and the ProviderName of the cloud where the service was used.

All charges include a ChargeType to describe what kind of charge it is (such as usage or purchase), the ChargePeriodStart and ChargePeriodEnd dates the charge applied to, and the applicable BilledCost and AmortizedCost amounts. This is one big deviation from the current Cost Management experiences: instead of pulling cost from separate actual (billed) and amortized cost datasets, with FOCUS, you can query all your data at once, which should speed up processing times and reduce storage size for anyone currently exporting both datasets.

All charges have BillingPeriodStart and BillingPeriodEnd dates, a BillingAccountId and BillingAccountName that links to the scope at which your invoices are generated, a SubAccountId and SubAccountName that indicates the lower-level subscription account where resources are managed, and an InvoiceIssuerName that indicates what organization you receive invoices from (such as Microsoft or a Microsoft partner). For anyone using Microsoft Customer Agreement, you may notice that the BillingAccountId is linked to your billing profile, since that’s where the invoice is generated. This will be an important distinction for Microsoft Cloud customers, given the different terminology. Similarly, SubAccountId is linked to your subscription, which will be a new cross-cloud term to familiarize yourself with for cost allocation and chargeback needs.

Of course, reading about FOCUS isn’t as good as working with the data. If you’d like to give FOCUS a test run, you can download a FOCUS sample Power BI report as part of the FinOps toolkit, an open source collection of reusable solutions to help you jump start your FinOps efforts.

FOCUS: A new specification for cloud cost transparency

You can also connect this report to your own data through the Cost Management connector for Power BI or by deploying a FinOps hub data pipeline.

For those interested in the data, you can also explore a small sample dataset along with a few other open datasets that can be used as part of your own data ingestion and cleanup efforts.

And lastly, if you’re interested in converting your own data in FOCUS, you can also leverage either the Invoke-FinOpsSchemaTransform or ConvertTo-FinOpsSchema command from the FinOps toolkit PowerShell module. These commands allow you to convert small datasets to FOCUS using a familiar command line interface.

Looking forward to FOCUS 1.0


But this was only the beginning. We’re incredibly excited to be a part of the FinOps community and help lead the way forward as FOCUS nears the 1.0 milestone. The FOCUS 1.0 specification is being driven forward by squads of project members, working backwards from the perspective of FinOps practitioners’ use cases. Practitioners are defining the columns they need to perform consistent cost allocation, to manage commitment-based discounts effectively, define consistent unit cost metrics and key performance indicators (KPIs), and more. Squads are building out the specification based on their needs to define consistent usage, pricing, and cost metrics, as well as for consistent inclusion of credits, discounts, and prepaid cost elements.

FOCUS is an important step for our industry, and for the adoption of FinOps in organizations around the world. Microsoft is proud to serve on the FOCUS Steering Committee, and on the Governing Board and Technical Advisory Council of the FinOps Foundation. Join us to help make FOCUS a standard worldwide!

Source: microsoft.com

Saturday, 28 October 2023

The new AI imperative: Unlock repeatable value for your organization with LLMOps

The new AI imperative: Unlock repeatable value for your organization with LLMOps

Time and again, we have seen how AI helps companies accelerate what’s possible by streamlining operations, personalizing customer interactions, and bringing new products and experiences to market. The shifts in the last year around generative AI and foundation models are accelerating the adoption of AI within organizations as companies see what technologies like Azure OpenAI Service can do. They’ve also pointed out the need for new tools and processes, as well as a fundamental shift in how technical and non-technical teams should collaborate to manage their AI practices at scale.  

This shift is often referred to as LLMOps (large language model operations). Even before the term LLMOps came into use, Azure AI had many tools to support healthy LLMOps already, building on its foundations as an MLOps (machine learning operations) platform. But during our Build event last spring, we introduced a new capability in Azure AI called prompt flow, which sets a new bar for what LLMOps can look like, and last month we released the public preview of prompt flow’s code-first experience in the Azure AI Software Development Kit, Command Line Interface, and VS Code extension.  

Today, we want to go into a little more detail about LLMOps generally, and LLMOps in Azure AI specifically. To share our learnings with the industry, we decided to launch this new blog series dedicated to LLMOps for foundation models, diving deeper into what it means for organizations around the globe. The series will examine what makes generative AI so unique and how it can meet current business challenges, as well as how it drives new forms of collaboration between teams working to build the next generation of apps and services. The series will also ground organizations in responsible AI approaches and best practices, as well as data governance considerations as companies innovate now and towards the future.  

From MLOps to LLMOps

While the latest foundation model is often the headline conversation, there are a lot of intricacies involved in building systems that use LLMs: selecting just the right models, designing architecture, orchestrating prompts, embedding them into applications, checking them for groundedness, and monitoring them using responsible AI toolchains. For customers that had started on their MLOps journey already, they’ll see that the techniques used in MLOps pave the way for LLMOps.  

Unlike the traditional ML models which often have more predictable output, the LLMs can be non-deterministic, which forces us to adopt a different way to work with them. A data scientist today might be used to control the training and testing data, setting weights, using tools like the responsible AI dashboard in Azure Machine Learning to identify biases, and monitoring the model in production.  

Most of these techniques still apply to modern LLM-based systems, but you add to them: prompt engineering, evaluation, data grounding, vector search configuration, chunking, embedding, safety systems, and testing/evaluation become cornerstones of the best practices.  

Like MLOps, LLMOps is also more than technology or product adoption. It’s a confluence of the people engaged in the problem space, the process you use, and the products to implement them. Companies deploying LLMs to production often involve multidisciplinary teams across data science, user experience design, and engineering, and often include engagement from compliance or legal teams and subject matter experts. As the system grows, the team needs to be ready to think through often complex questions about topics such as how to deal with the variance you might see in model output, or how best to tackle a safety issue.

Overcoming LLM-Powered application development challenges

Creating an application system based around an LLM has three phases:

  • Startup or initialization—During this phase, you select your business use case and often work to get a proof of concept up and running quickly. Selecting the user experience you want, the data you want to pull into the experience (e.g. through retrieval augmented generation), and answering the business questions about the impact you expect are part of this phase. In Azure AI, you might create an Azure AI Search index on data and use the user interface to add your data to a model like GPT 4 to create an endpoint to get started.
  • Evaluation and Refinement—Once the Proof of Concept exists, the work turns to refinement—experimenting with different meta prompts, different ways to index the data, and different models are part of this phase. Using prompt flow you’d be able to create these flows and experiments, run the flow against sample data, evaluate the prompt’s performance, and iterate on the flow if necessary. Assess the flow’s performance by running it against a larger dataset, evaluate the prompt’s effectiveness, and refine it as needed. Proceed to the next stage if the results meet the desired criteria.
  • Production—Once the system behaves as you expect in evaluation, you deploy it using your standard DevOps practices, and you’d use Azure AI to monitor its performance in a production environment, and gather usage data and feedback. This information is part of the set you then use to improve the flow and contribute to earlier stages for further iterations.

Microsoft is committed to continuously improving the reliability, privacy, security, inclusiveness, and accuracy of Azure. Our focus on identifying, quantifying, and mitigating potential generative AI harms is unwavering. With sophisticated natural language processing (NLP) content and code generation capabilities through (LLMs) like Llama 2 and GPT-4, we have designed custom mitigations to ensure responsible solutions. By mitigating potential issues before application production, we streamline LLMOps and help refine operational readiness plans.

As part of your responsible AI practices, it’s essential to monitor the results for biases, misleading or false information, and address data groundedness concerns throughout the process. The tools in Azure AI are designed to help, including prompt flow and Azure AI Content Safety, but much responsibility sits with the application developer and data science team.

By adopting a design-test-revise approach during production, you can strengthen your application and achieve better outcomes.

How Azure helps companies accelerate innovation 

Over the last decade, Microsoft has invested heavily in understanding the way people across organizations interact with developer and data scientist toolchains to build and create applications and models at scale. More recently, our work with customers and the work we ourselves have gone through to create our Copilots have taught us much and we have gained a better understanding of the model lifecycle and created tools in the Azure AI portfolio to help streamline the process for LLMOps.  

Pivotal to LLMOps is an orchestration layer that bridges user inputs with underlying models, ensuring precise, context-aware responses.  

A standout capability of LLMOps on Azure is the introduction of prompt flow. This facilitates unparalleled scalability and orchestration of LLMs, adeptly managing multiple prompt patterns with precision. It ensures robust version control, seamless continuous integration, and continuous delivery integration, as well as continuous monitoring of LLM assets. These attributes significantly enhance the reproducibility of LLM pipelines and foster collaboration among machine learning engineers, app developers, and prompt engineers. It helps developers achieve consistent experiment results and performance. 

In addition, data processing forms a crucial facet of LLMOps. Azure AI is engineered to seamlessly integrate with any data source and is optimized to work with Azure data sources, from vector indices such as Azure AI Search, as well as databases such as Microsoft Fabric, Azure Data Lake Storage Gen2, and Azure Blob Storage. This integration empowers developers with the ease of accessing data, which can be leveraged to augment the LLMs or fine-tune them to align with specific requirements. 

And while we talk a lot about the OpenAI frontier models like GPT-4 and DALL-E that run as Azure AI services, Azure AI also includes a robust model catalog of foundation models including Meta’s Llama 2, Falcon, and Stable Diffusion. By using pre-trained models through the model catalog, customers can reduce development time and computation costs to get started quickly and easily with minimal friction. The broad selection of models lets developers customize, evaluate, and deploy commercial applications confidently with Azure’s end-to-end built-in security and unequaled scalability. 

LLMOps now and future 

Microsoft offers a wealth of resources to support your success with Azure, including certification courses, tutorials, and training material. Our courses on application development, cloud migration, generative AI, and LLMOps are constantly expanding to meet the latest innovations in prompt engineering, fine-tuning, and LLM app development.  

But the innovation doesn’t stop there. Recently, Microsoft unveiled Vision Models in our Azure AI model catalog. With this, Azure’s already expansive catalog now includes a diverse array of curated models available to the community. Vision includes image classification, object segmentation, and object detection models, thoroughly evaluated across varying architectures and packaged with default hyperparameters ensuring solid performance right out of the box. 

Source: microsoft.com

Thursday, 26 October 2023

Prompts are key in 2023: Twenty-five tips to help you unlock the potential of generative AI

Prompts are key in 2023: Twenty-five tips to help you unlock the potential of generative AI

In the last few years, generative AI has seen exponential growth. Language models like GPT-3.5-Turbo and GPT-4 on Azure OpenAI Service can automate content generation and conversational experiences, making it easier and more efficient to communicate with customers and end users.

AI input prompts defined


A prompt, in the context of AI, particularly in large language models, refers to the input or instruction given by users to elicit a specific type of response. To get the most out of large language models like GPT-4, it’s imperative to craft prompts that yield effective results. The challenge lies in choosing the best combination of words, expressions, symbols, and structures to steer the model toward producing accurate and pertinent content.

Why prompts matter


Just like when communicating in real life, how you ask for what you want can limit—or expand—the type of information you receive.

Prompts help specify the user’s intent and expectation from AI, hence more precise prompts lead to more accurate and relevant results. They allow users to obtain a wide variety of responses, from answering questions, creating stories in the tone of your favorite author, generating poetry, and even performing code-related tasks.

Similar prompts can lead to varying responses based on the underlying model, its training data, or even subtle variations in how you phrase your request.

Following you’ll find prompt tips to help you create the kind of content you need, whether at work or play.

Get started! Twenty-five prompt tips for your best content creation to date


  • Know what you want
    • Clearly outline the problem or need you’re trying to address. For instance, “I need fresh ideas for a marketing campaign geared toward our latest app.”
  • Start with a simple question
    • Begin with a simple question to check the model’s understanding, then build into more complex queries.
  • Ask open-ended questions
    • Generative models work best when they’re free to roam. Instead of asking, “Should I use social media for marketing?” ask, “What are some innovative ways to grab attention across my social media platforms.” You can even specify the specific platform you plan to use (X, LinkedIn, etc.).
  • Iterate and refine
    • Use the feedback you get from initial prompts then build on it. Like an idea about a general content marketing strategy? Follow up with, “How can I implement a content marketing strategy for a tech product designed to monitor how happy my pet is while I’m away from home?”
  • Provide context
    • The more context you provide, the better AI can tailor its response to your unique situation. For example, “I just released an app to track sleep patterns and am looking for low-cost marketing strategies that appeal to businesses concerned with their employee’s well-being.”
  • State your boundaries
    • Mention any constraints (e.g., budget, timeline, resources) upfront. “What are marketing strategies for a new product that can be executed within a 5,000 USD budget and within a two-week period?”
  • Go big (then small)
    • Break down big questions into smaller ones for more actionable insights. Instead of asking “How can I improve my business?” ask “How can I increase online sales?” Then, followed up with “What social media platforms are best for advertising beanbags?”
  • Opposites attract: Marry creative and analytical requests
    • AIs can handle both creative brainstorming and analytical tasks. But divide and conquer for the best results. Brainstorm marketing strategies, then follow up with “What are the pros and cons of influencer marketing?”
  • Strengths, Weaknesses, Opportunities, Threats (SWOT)
    • A SWOT analysis can help get your business on the right path. Ask AI to perform a SWOT analysis using specifics about your business for immediately actionable items you can get started on ASAP.
  • Ask for examples
    • Grasping a concept is easier with an example on hand. Ask for an example then use it as a potential model. You’ll discover what does—and doesn’t—work for your specific case. For example, “Can you provide a case study of a successful influencer marketing campaign?”
  • Specify the format
    • Want answers in bullet points, a paragraph, or a list? Make mention of that and see your wishes take literal form.
  • Define tech terms
    • If there’s a term or acronym specific to your industry, use a prompt to define it, or ensure the model understands the context in which it’s being used.
  • Rephrase for precision
    • If the initial answer isn’t satisfactory, rephrase your question. Not only will you get your creative communicative juices, but you’ll also find that answers to your questions can prompt new directions in your thinking.
  • In-depth versus short-form
    • Want a summary in a single paragraph or a pages-long academic deep dive? Make mention of your preferences in your prompt.
  • Use negative instructions for a positive effect
    • If you know what you don’t want, specify that. E.g., “Provide marketing strategies excluding online advertisements.”
  • Multiple answers
    • Ask for multiple answers or perspectives to a single question for a more comprehensive and nuanced understanding of your topic.
  • Request sources
    • While most models don’t browse the web in real-time, asking it to base its answer on known sources up to its last training data can provide greater credibility.
  • Limit bias
    • Explicitly ask the model to give an unbiased answer or to consider multiple perspectives.
  • Context is key
    • Ask for compliance requirements for specific industries. “What are the current trends in generative AI?” “What compliance requirements should I keep in mind for healthcare related topics?
  • Power in numbers
    • Quantify whenever possible: Need numbers or percentages? Metrics, distances, or speed? Include this request in your prompt.
  • Avoid leading questions
    • Ensure your question doesn’t steer the model towards a specific answer—unless that’s your intention.
  • Tone it down (or up)
    • If you need fun, out-of-the-box content versus a more academic tone, mention that. E.g., “Provide a fun creative tagline for a green energy campaign.”
  • Provide real-world implications
    • Explain why you need the answer or how it’ll be used for more context. We’re launching a new cookie testing app next month. How should we position it against competitor x?”
  • Safety and accuracy
    • Cross-reference critical information provided by the model with trusted external sources, especially if decisions based on the model’s answer have significant business implications.
  • Refine over time
    • If you’re using the model regularly, note down what types of prompts give you the best results and refine them accordingly.

Think of generative AI prompts as a multifunctional tool built for the digital age, adept at both enhancing business strategies and enriching our home lives. 

The goal is to use generative AI as a tool in your broader decision-making and brainstorming process. Combining AI’s suggestions with your expertise and knowledge of your business and market will yield the best results. By integrating these AI insights, we’re not merely keeping up with the times; we’re pioneering a future where efficiency meets innovation.

Our commitment to responsible AI


With Responsible AI tools in Azure, Microsoft is empowering organizations to build the next generation of AI apps safely and responsibly. Microsoft has announced the general availability of Azure AI Content Safety, a state-of-the art AI system that helps organizations keep AI-generated content safe and create better online experiences for everyone. Customers—from startup to enterprise – are applying the capabilities of Azure AI Content Safety to social media, education and employee engagement scenarios to help construct AI systems that operationalize fairness, privacy, security, and other responsible AI principles.

Source: microsoft.com

Thursday, 19 October 2023

The Microsoft Azure Incubations Team launches Radius, a new open application platform for the cloud

The Microsoft Azure Incubations team is excited to announce Radius, a cloud-native application platform that enables developers and platform engineers who support them to collaborate on delivering and managing cloud-native applications that follow corporate best practices for cost, operations, and security by default. Radius is an open-source project that supports deploying applications across private cloud, Microsoft Azure, and Amazon Web Services, with more cloud providers to come. 

Microsoft innovating via open source software


Microsoft is a major contributor to open-source projects across the industry and its Azure Incubations team is focused specifically on open-source innovation that enables everyone to accelerate their journey to the cloud. In addition to Radius, the team has launched multiple popular open source projects including Dapr, KEDA, and Copacetic, all available at github.com via the Cloud Native Compute Foundation (CNCF). 

The evolution of cloud computing has increased the speed of innovation for many companies, whether they are building second and third-tier applications or complex microservice-based applications. Cloud native technologies like Kubernetes have made building applications that can run anywhere easier. At the same time, many applications have become more complex, and managing them in the cloud is increasingly difficult, as companies build cloud-native applications composed of interconnected services and deploy them to multiple public clouds and their private infrastructure. While Kubernetes is a key enabler, we see many customers building abstractions over Kubernetes, usually focused on compute, to work around its limitations: Kubernetes has no formal definition of an application, it mingles infrastructure and application concepts and it is overwhelmingly complex. Developers also inevitably realize their applications require much more than Kubernetes, including support for dependencies like application programming interface (API) front ends, key-value stores, caches, and observability systems. Amidst these challenges for developers, their corporate IT counterparts also must enforce an ever-growing matrix of corporate standards, compliance, and security requirements, while still enabling rapid application innovation. 

Introducing Radius


Radius was designed to address these distinct but related challenges that arise across development and operations as companies continue their journey to the cloud. Radius meets application teams where they are by supporting proven technologies like Kubernetes, existing infrastructure tools including Terraform and Bicep, and by integrating with existing continuous integration and continuous delivery (CI/CD) systems like GitHub Actions. Radius supports multi-tier web-plus-data to complex microservice applications like eShop a popular cloud reference application from Microsoft.

The Microsoft Azure Incubations Team launches Radius, a new open application platform for the cloud

Radius enables developers to understand their applications and it knows your application is more than just Kubernetes. Radius helps developers see all the components that comprise their application, and when they add new components, Radius automatically connects those components to their application by taking care of permissions, connection strings, and more.

Radius also ensures the cloud infrastructure used by applications meets cost, operations, and security requirements. These requirements are captured in recipes, which are defined by the IT operators, platform engineers, and/or security engineers that support cloud native developers. Radius binds an application to its dependent infrastructure, which enables Radius to provide an application graph that shows precisely how the application and infrastructure are interconnected. This graph enables team members to view and intuitively understand what makes up an application.

Many enterprises are multi-cloud and want solutions that work well not on just Azure, but on other clouds, as well as on-premises. So, Radius is open-source and multi-cloud from the start. Companies like Microsoft, BlackRock, Comcast, and Millenium BCP have worked together to ensure applications defined and managed with Radius can run on any cloud. Anyone in the open-source community can contribute to Radius, ensuring Radius evolves along with the broader cloud native community. Initial observations from these companies include:

“In today’s landscape of ever-evolving cloud complexities, there’s an imperative need to streamline the application development lifecycle. It’s essential that our internal developers can rapidly access the infrastructure they require, all while adhering to compliance standards and requirements. We see Radius as a promising enabler in this context. Through its unique offering of Radius recipes, the platform empowers developers to tap into vital cloud resources like Kubernetes and storage solutions, without the necessity to grasp the intricate details of these underlying systems. Our engagement with Radius stems from our advocacy for open-source solutions within our own technology platform, Aladdin, and we believe this approach holds significant potential to resonate with the cloud-native community.“ Mike Bowen, Senior Principal Engineer and OSPO Director, BlackRock.

“Radius is strongly aligned with our platform engineering vision to enable Comcast engineers to innovate at the speed of thought. We are prototyping on Radius to understand how Comcast might both consume and contribute to this promising open-source project.” Paul Roach, VP of Developer Experience, Comcast 

“At Millennium bcp our focus on security, compliance, best practices, and agility is paramount, and we must ensure these requirements are continuously met. To align expectations and lifecycles across multiple teams and technologies we are working to make common Application definitions and lifecycles first-class citizens in our IT landscape, while abstracting custom internal IT patterns and service contracts. We find this same vision in Radius. Our infrastructure can be handled exclusively by internal infra product teams, exposing only the Recipe to our developers to abstract complexity and ensure design decisions are made by the right people. Developers can focus on identifying what is relevant for their Applications, leveraging the correct Recipes without having to go into implementation concerns. This common contract correctly refocuses teams: developers focus exclusively on evolving the Application while infrastructure teams now manage infrastructure with a clear understanding of Application dependencies.” Nuno Guedes, Cloud Compute Lead, Millennium BCP

With Dapr, the Microsoft Azure Incubations Team helped developers write microservices with best practices, abstraction, portability, and separation from infrastructure. Now, we are doing the same for defining an application’s architecture. The two technologies strongly complement each other: Radius works with Dapr, simplifying Dapr configuration. Together, they enable, not just portable code, but portable applications.

Source: microsoft.com

Tuesday, 17 October 2023

Azure Secrets Revealed: Boosting Business with Cloud Magic

Azure Secrets Revealed, Cloud Magic, Azure Exam, Azure Exam Prep, Azure Tutorial and Materials, Azure Certification

In the digital age, businesses are constantly seeking innovative solutions to stay ahead of the curve. The advent of cloud computing has revolutionized the way organizations operate, with Microsoft Azure emerging as a game-changer. In this article, we will unlock the secrets of Azure, revealing how it can elevate your business to new heights.

Azure: Unveiling the Power of the Cloud


What Is Azure?

Azure is Microsoft's cloud computing platform, designed to provide a wide range of services for building, deploying, and managing applications through Microsoft-managed data centers. It offers an extensive suite of services, including virtual machines, databases, AI, IoT, and more.

Scalability Beyond Imagination

One of the secrets of Azure's success is its incredible scalability. Whether you're a startup or an enterprise, Azure adapts to your needs. You can scale up or down effortlessly, ensuring that your resources are always aligned with your business requirements. This elasticity is a true game-changer, allowing you to pay only for what you use.

Unparalleled Reliability

Azure's global network of data centers guarantees unmatched reliability. With multiple data centers worldwide, your data is safe, and your applications are always available. This is essential for businesses that cannot afford downtime.

Cutting-Edge Security

Security is a paramount concern in the digital world, and Azure takes it seriously. With Azure, your data is protected by a fortress of security measures, including advanced threat detection and encryption. Azure's security protocols are second to none.

Transforming Business with Azure


Streamlined Operations

Azure streamlines your business operations by providing you with tools and services that make management and deployment a breeze. From DevOps to automation, Azure simplifies complex processes, allowing you to focus on what matters most—your business.

Data-Driven Decisions

Data is the lifeblood of the modern enterprise. Azure offers a range of data services, including Azure SQL Database, Azure Cosmos DB, and Azure Synapse Analytics, that allow you to collect, store, and analyze data effectively. This data-driven approach empowers you to make informed decisions, driving your business forward.

AI and IoT Integration

Azure isn't just about infrastructure; it's about innovation. It offers robust AI and IoT capabilities, enabling you to build smart, connected solutions. Harness the power of Azure to create intelligent applications that learn and adapt, opening new doors for your business.

Azure Case Studies: Real-World Success


Toyota: Driving Innovation with Azure

Toyota, the world-renowned automotive manufacturer, embraced Azure for its cloud needs. By doing so, they optimized their production processes, improved supply chain management, and enhanced customer experiences. Azure became their secret weapon for innovation.

Johnson & Johnson: Healing with Azure

The healthcare giant, Johnson & Johnson, turned to Azure to accelerate drug discovery. By leveraging Azure's advanced data analytics capabilities, they significantly reduced research time, making the world a healthier place.

How to Get Started with Azure


Step 1: Assess Your Needs

Before diving into Azure, it's essential to assess your business needs. Consider your current infrastructure, goals, and budget. Azure offers a variety of pricing models to suit different scenarios.

Step 2: Create an Azure Account

To get started, you'll need to create an Azure account. You can choose from various subscription plans, including a free trial with a credit of $200 to explore Azure's services.

Step 3: Explore Azure Services

Once you have your account, start exploring Azure's services. Familiarize yourself with its vast catalog and choose the ones that align with your business goals.

Step 4: Implement Azure Solutions

Whether you need to migrate existing applications, build new ones, or enhance your business with AI, Azure has the tools to make it happen. Leverage the expertise of Azure professionals to ensure a seamless transition.