Category Archives: Cloud

Azure IaaS and Azure Stack: announcements and updates (November 2019 – Weeks: 45 and 46)

This series of blog posts includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft in the last two weeks.

In this dedicated post you can find the most important announcements and major updates officialized last week during Microsoft Ignite 2019 conference.

Azure

Save more on Azure usage: reservations for six more services

With reserved capacity, you get significant discounts over your on-demand costs by committing to long-term usage of a service. Microsoft is pleased to share reserved capacity offerings for the following additional services:

  • Blob Storage (GPv2) and Azure Data Lake Storage (Gen2).
  • Azure Database for MySQL.
  • Azure Database for PostgreSQL.
  • Azure Database for MariaDB.
  • Azure Data Explorer.
  • Premium SSD Managed Disks.

With the addition of these services, Microsoft supports reservations for 16 services, giving you more options to save and get better cost predictability across more workloads.

Azure Key Vault Virtual Machine extension generally available

The Azure Key Vault Virtual Machine extension makes it easier for apps running on virtual machines to use certificates from a key vault, by abstracting the common tasks as well as best practices.

Azure Disk Encryption

Azure Disk Encryption enables you to encrypt your Azure Virtual Machine disks with your keys safeguarded in Azure Key Vault. Previously this capability was available through PowerShell and CLI, now this capability is also available in the Azure portal, which makes it very easy to use. Microsoft has also added support for the latest versions of the common Linux distros on Azure, including Red Hat Enterprise Linux 7.6 and 7.7 as well as CentOS Linux 7.6 and 7.7.

HB and HC Virtual Machines in additional regions

The HB-series VMs are optimized for HPC applications driven by memory bandwidth, such as fluid dynamics, explicit finite element analysis, and weather modeling. The HB-Series VM is now available in East US. HC-series VMs are optimized for HPC applications driven by intensive computation, such as implicit finite element analysis, reservoir simulation, and computational chemistry. The HC-Series VM is now available in Japan East. 

Azure IaaS and Azure Stack: announcements and updates (Microsoft Ignite 2019 – Special Edition)

This special edition includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft this week during Microsoft Ignite 2019 conference. Microsoft announced several important additions to its Azure infrastructure as a service (IaaS) portfolio and the Microsoft infrastructure services continue to evolve to optimize the experience of running business-critical workloads.

Azure

Azure Arc: Extended Azure management and security to any infrastructure

Azure Arc enables Azure services anywhere and extends Azure management to any infrastructure for unified management, governance and control across clouds, datacenters and edge. They look and feel just like Azure resources, and they provide unified auditing, compliance, and role based access control across multiple environments and at scale.
As a result, customers can modernize any infrastructure with cloud management and security protection. With cloud practices that work anywhere, Microsoft is delivering these resources, from cloud to datacenter to edge, and enabling cloud security anywhere.
With Azure Arc, customers can now take advantage of Azure’s robust cloud management experience for their own servers (Linux and Windows Server) and Kubernetes clusters by extending Azure management across environments.
Customers can seamlessly inventory, organize, and govern their own resources at scale through a consistent and unified experience through the Azure Portal.

Virtual Machines

Azure generation 2 virtual machines generally available

Generation 2 virtual machines are now generally available on Azure. Generation 2 VMs provide support for Intel Software Guard Extensions (Intel SGX), UEFI boot architecture, and the ability to provision large VMs (up to 12TB) and OS Disks sizes that exceed 2TB. 

Proximity placement groups generally available

A proximity placement group is a logical grouping capability for Azure Virtual Machines that you can use to decrease the network latency between a set of virtual machines. When you assign your virtual machines to a proximity placement group, their placement is optimized to deliver lower latency for your latency-sensitive workloads. Now this feature is generally available in most Azure regions.

Azure VMware Solutions available in West Europe

Azure VMware Solutions are available in the West Europe Azure region. Azure VMware Solutions delivers the ability to run your VMware environment natively on Azure. This gives you the option to leverage your existing VMware skills and investments while taking full advantage of the scale and automation Azure offers. Azure VMware Solutions is now supported in East US, West US, and West Europe regions.

Azure Spot VMs

Azure Spot Virtual Machines, give you access to unused Azure compute capacity at deep discounts, will be available soon (we expect to preview this by early 2020). Spot Virtual Machines will be ideal for workloads that can be interrupted, providing scalability while reducing costs. You will be able to take advantage of Spot Virtual Machine pricing for Azure Virtual Machines or Virtual Machine Scale Sets (VMSS) to deploy opportunistic workloads of all sizes.

New virtual machine scale sets capabilities in preview

New virtual machine scale sets features simplify the management of virtual machines while improving their runtime and performance capabilities.

Vulnerability assessment in Azure Security Center

Applications that are installed in virtual machines could often have vulnerabilities that could lead to a breach of the virtual machine. Microsoft announced that the Security Center Standard tier includes built-in vulnerability assessment for virtual machines for no additional fee.

Advanced data security for SQL servers on Azure Virtual Machines

Azure Security Center’s support for threat protection and vulnerability assessment for SQL DBs running on IaaS virtual machines (VMs) is in preview.

New Azure Dav4-series and Eav4-series virtual machines

New Azure Dav4-series and Eav4-series virtual machines (VMs) based on AMD EPYC™ are available. They are ideal for general purpose (Dav4-series) and memory intensive workloads (Eav4-series).

New NVv4 series Azure Virtual Machines in preview

NVv4 (currently in preview) offers, for Windows Virtual Desktops and high-performance computing (HPC) workloads, enhanced GPU resourcing flexibility, giving customers more choice by offering partitioned GPUs built using industry-standard SR-IOV technology. Customers can select the right size of GPU Virtual Machines with as little as 2GB of dedicated GPU frame buffer for an entry-level desktop in the cloud, and up to the whole GPU with 16GB of frame buffer to provide powerful engineering workstations.

Updated NDv2 Azure Virtual Machines preview

The NDv2-series Virtual Machines, currently in preview, are the latest, fastest, and most powerful addition to the GPU family, specifically designed for the cutting edge demands of distributed HPC, AI, and machine learning workloads.

HBv2 Azure Virtual Machines for HPC workloads coming soon

HBv2 VMs are designed to deliver supercomputer-class performance, message passing interface (MPI) scalability, and cost efficiency for a variety of real-world HPC workloads. HBv2 Virtual Machines support up to 80,000 cores for single MPI jobs to deliver performance that rivals some of the world’s largest and most powerful bare metal supercomputers.

Networking

Azure Bastion is generally available

Microsoft announced the general availability (GA) of Azure Bastion, a fully managed platform as a service (PaaS) service that provides more secure and seamless RDP and SSH access to virtual machines directly through the Azure portal.

Azure Firewall Manager is now in preview

Azure Firewall Manager Preview is a security management service that provides central security policy and route management for cloud-based security perimeters. It works with Azure Virtual WAN Hub, a Microsoft-managed resource that lets you easily create hub and spoke architectures. When security and routing policies are associated with such a hub, it is referred to as a Secured Virtual Hub.

Native Azure Active Directory authentication support in point-to-site VPN

Native Azure Active Directory (Azure AD) authentication support for OpenVPN protocol, and Azure VPN Client for Windows are now available. Native Azure AD authentication support was widely requested by enterprise customers because Azure AD integration enables user-based policies, conditional access, and multi-factor authentication (MFA) for P2S VPN. Native Azure AD authentication requires both Azure VPN gateway integration and a new Azure VPN Client to obtain and validate an Azure AD token.

Azure Private Link is now available in all regions

Azure Private Link, which provides private connectivity to Azure services, is now available in all regions.

Azure Peering Service in managed preview

Azure Peering Service is a partnership with service providers to provide highly reliable and optimized internet connectivity to Microsoft services. It also provides internet latency telemetry and route monitoring with alerting against hijacks, leaks, and any other BGP mal configurations.  Azure Peering Service is targeting customers with an internet-first network strategy for accessing Azure and SaaS services such as Office 365. Through partnering with internet service providers, customers are able to take advantage of optimized routing of their internet traffic to the Microsoft cloud.

Enhancements to Azure Virtual WAN

Significant enhancements include the preview of hub-to-hub and any-to-any connectivity. Virtual WAN users can connect multiple hubs for full mesh connectivity to further simplify their network architecture. Additionally, ExpressRoute and Point to Site are now Generally Available with Virtual WAN.

IPv6 for Azure Virtual Network is generally available

IPv6 support within the virtual network and to the internet enables you to expand into the growing mobile and IoT markets with Azure-based applications and to address IPv4 depletion in your own corporate networks.

Azure ExpressRoute for satellites is available

ExpressRoute, with one of the largest networking ecosystems in the public cloud, now includes satellite connectivity partners, bringing new options and coverage.

Storage

Azure Data Share is available

Azure Data Share enables organizations to easily and securely share data with other organizations to expand analytics datasets for enhanced insights.

Azure Stack

Azure Stack, the extension of Azure that brings the innovation of cloud computing to build and deploy hybrid applications anywhere, is being renamed “Azure Stack Hub“. Also, Azure Data Box Edge, the Microsoft data-transfer devices, is being renamed as “Azure Stack Edge“.

So, Azure Stack will expand to include a portfolio of products consisting of:

  • Azure Stack HCI
  • Azure Stack Hub (previously Azure Stack)
  • Azure Stack Edge (previously Azure Data Box Edge):
    • It is an Azure managed appliance that brings the compute, storage, and intelligence of Azure to the edge.
    • It is a first party Microsoft appliance, delivered to customers’ sites to run Azure services with no upfront costs (you pay monthly in your Azure bill).
    • Customers can use the Azure portal to order and provision Azure Stack Edge; Azure management tools are used for monitoring and running updates.

Azure Stack Hub

Microsoft is sharing some new updates for Azure Stack Hub roadmap, including N-Series virtual machines enabled by NVIDIA V100 GPUs. It’s also announcing the general availability of Kubernetes on Azure Stack Hub. You can now easily provision Kubernetes clusters on Azure Stack Hub using Azure Kubernetes Service (AKS) engine to automate the creation, update, and scaling of Kubernetes clusters. In the first half of 2020, Event Hubs and Azure Stream Analytics will also be available for public preview.

Azure Stack Edge

Azure Stack Edge will soon support new compute and AI capabilities including virtual machines, Kubernetes clusters, NVIDIA GPU support and high-availability support. With these capabilities, Azure Stack Edge is quickly evolving to the forefront of edge computing in the market. Microsoft is also enabling private cellular networks as a service by adding the tech preview of multi-access edge compute (MEC) on Azure Stack Edge.

Azure Stack portfolio and Azure Arc

Azure Arc and Azure Stack portfolio are complementary, so you can combine the benefits of Azure Arc with Azure Stack portfolio, where Azure Arc can manage virtual machines, containers, and run Azure Data Services on Azure Stack portfolio of validated and integrated systems while leveraging the compute and cloud capabilities of Azure Stack.

Conclusions

The most important announcement from Microsoft Ignite 2019 for me is Azure Arc, the Microsoft’s new approach to hybrid. Enterprises rely on a hybrid technology approach to take advantage of their on-premises investment and, at the same time, utilize cloud innovation. As more business operations and applications expand to include edge devices and multiple clouds, hybrid capabilities must enable apps to run seamlessly across on-premises, multi-cloud, and edge devices, while providing consistent management and security across all distributed locations. Hybrid cloud capabilities in Microsoft is evolving to enable innovation anywhere, while providing a seamless development, deployment and ongoing management experience.

Azure IaaS and Azure Stack: announcements and updates (November 2019 – Weeks: 43 and 44)

This series of blog posts includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft in the last two weeks.

Azure

New Cost Management features

Here are the Cost Management features that are generally available as of October 2019.

Azure Mv2-series VMs with 12TB memory now GA in new regions

Azure Mv2-series Virtual Machines with 12TB memory are generally available for the US West 2, US East, US East 2, Southeast Asia, EU West and EU North regions. Azure Mv2-series virtual machines are hyper-threaded and feature Intel® Xeon® Platinum 8180M 2.5GHz (Skylake) processors, offering up to 416 vCPU in 3TB, 6 TB and 12 TB memory configurations. This is by far the largest-memory virtual machine offered on Azure. Mv2-series virtual machines provide unparalleled computational performance to support large in-memory databases and workloads such as SAP HANA and SQL Hekaton.

Azure Monitor’s Service Map is available in new regions

The Service Map feature of Azure Monitor is now available in South Central US, West US, Central US, North Central US, East Asia, and Central India.  Around the world is it available in eighteen public regions. Service map automatically discovers application components on Windows and Linux systems and maps the communication between services. With service map, you can view your servers in the way that you think of them—as interconnected systems that deliver critical services. Service map shows connections between servers, processes, inbound and outbound connection latency, and ports across any TCP-connected architecture, with no configuration required other than the installation of an agent.

Server-side encryption with customer-managed keys for Azure Managed Disks (preview)

The preview for server-side encryption (SSE) with customer-managed keys (CMK) for Azure Managed Disks is available. Azure customers already benefit from server-side encryption with platform managed keys (PMK) for Azure Managed Disks enabled by default. Customers also benefit from Azure disk encryption (ADE) that leverages the BitLocker feature of Windows and the DM-Crypt feature of Linux to encrypt Managed Disks with customer managed keys within the guest virtual machine. Server-side encryption with customer-managed keys improves on platform managed keys by giving you control of the encryption keys to meet your compliance needs. It improves on Azure disk encryption by enabling you to use any OS types and images for your virtual machines by encrypting data in the storage service. Server-side encryption with customer-managed keys is integrated with Azure Key Vault (AKV) that provides highly available and scalable, secure storage for RSA cryptographic keys backed by hardware security modules (HSMs). You can either import your RSA keys to Azure Key Vault or generate new RSA keys in Azure Key Vault.

Azure File Sync is available in new regions

Azure File Sync is available in South Africa and UAE regions. To get the latest list of supported regions, see this document.

Azure File Sync agent v8 release

Azure File Sync is now on Microsoft Update and Microsoft Download Center. Improvements and issues that are fixed:

  • Restore performance improvements
    • Faster recovery times for recovery done through Azure Backup.Restored files will sync back down to Azure File Sync servers much faster.
  • Improved cloud tiering portal experience
    • If you have tiered files that are failing to recall, you can now view the recall errors in the server endpoint properties. Also, the server endpoint health will now show an error and mitigation steps if the cloud tiering filter driver is not loaded on the server.
  • Simpler agent installation
    • The Az\AzureRM PowerShell module is no longer required to register the server making installation simpler and fast.
  • Miscellaneous performance and reliability improvements

More information about this release:

  • This update is available for Windows Server 2012 R2, Windows Server 2016 and Windows Server 2019 installations that have Azure File Sync agent version 4.0.1.0 or later installed.
  • The agent version of this update rollup is 8.0.0.0.
  • A restart may be required if files are in use during the update rollup installation.
  • Installation instructions are documented in KB4511224.

Azure management services and System Center: What's New in October 2019

In October were announced, by Microsoft, a considerable number of news regarding the Azure management services and System Center. Our community, through these articles that are released on a monthly basis, want to provide an overview of the main news of the month, in order to stay up to date on these arguments and have the necessary references for further information.

Azure Log Analytics

Availability in new regions

Azure Log Analytics is now available in the new regions “Switzerland North, Switzerland”, to allow you to collect log and perform related trend analysis on the use of resources.

New option for the pricing model

For Azure Monitor Log Analytics is available from November 1 2019 a new pricing model, allowing you to pay a fixed fee for data ingestion, based on the capacity of the selected tier. The tier start at 100 GB per day and allow you to get a saving of up to 25%, compared to the Pay-As-You-Go cost.

New version of the agent for Linux systems

This month the new agent version of Log Analytics introduces enhancements for Linux systems in particular concerning the installation process and performance. For more information about this, you can access theGitHub official page.

Retention configurable by data type

Azure Monitor Log Analytics introduces the ability to configure data retention, that is, the retention period of the data, for each type of data, instead of having a single retention setting for the entire workspace. The configuration at the time must be made through ARM commands. This new possibility allows for greater flexibility and savings in retention costs from the collated data from October (release date of this functionality). For more details please visit the Microsoft's official documentation.

Changing the saving of data in Service Map in Log Analytics

Data for Service Map, until now saved in custom log tables ServiceMapComputer_CL and ServiceMapProcess_CL will be moved to specific Log Analytics data types. These new tables will be called VMComputer and VMProcess, Inl.

Azure Site Recovery

New Update Rollup

For Azure Site Recovery was released theUpdate Rollup 41 that solves several issues and introduces some improvements. The details and the procedure to follow for the installation can be found in the specific KB.

Update for Windows servicing stack and SHA-2

For the Azure Site Recovery Mobility agent was issued a specific update required to enable Windows servicing stack and SHA-2 support.

Availability in new regions

Azure Site Recovery is now available in “Norway East, North Dakota” and “Norway West, North Dakota”. To check the availability of the service in all the Azure regions you can consult this document.

Azure Backup

Support for disks up to 32 TB

Support for large Managed disks has been announced for Azure Backup, up to 32 TB. For further information you can consultthis article.

System Center Configuration Manager

New releases for the Technical Preview Branch

For Configuration Manager was released the update 1910 that one of the main innovations is the ability to deploy and manage Microsoft Edge. With this integration, you can also easily manage the deployment of new versions of Microsoft Edge from the beta channel (updated every 6 weeks) and the Dev channel (updated weekly).

To check the details of what's included in these updates, you can see this document.

Please note that the Technical Preview Branch releases help you to evaluate new features of SCCM and it is recommended to apply these updates only in test environments.

Evaluation of Azure and System Center

To test and evaluate free of charge the service offered by Azure you can access this page, while to try out the various components of System Center you must Access to theEvaluation Center and, after registering, you can start the trial period.

Azure IaaS and Azure Stack: announcements and updates (October 2019 – Weeks: 41 and 42)

This series of blog posts includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft in the last two weeks.

Azure

Azure DNS private zones is now generally available

Azure DNS private zones is now production ready and backed by Azure DNS SLA. Azure DNS private zones provide reliable, secure DNS service to host, resolve and manage domain names from a virtual network without the need to add a custom DNS solution.  Azure DNS private zones enables you to effortlessly tailor your DNS namespace design to best suit your organization’s needs without having to worry about scalability, security and performance issues that arise from operating a custom DNS solution. Unlike public DNS zone, private DNS zones are not accessible over internet. DNS queries made against a private DNS zones can be resolved only from the virtual networks linked to the zone.

Customer Provided Keys with Azure Storage Service Encryption

Microsoft presents enhancement to storage service encryption to support granular encryption settings on storage account with keys hosted in any key store. Customer provided keys (CPK) enables you to store and manage keys in on-premises or key stores other than Azure Key Vault to meet corporate, contractual, and regulatory compliance requirements for data security.

New Azure Active Directory roles to reduce the number of Global administrators

Microsoft introduces 16 new roles in Azure AD designed to help you reduce the number of Global administrators by delegating administration tasks and assigning lower-privileged roles.

New Azure Resource Graph functionality

An update to Azure Resource Graph API now allows you to see further details about the changes to your Azure resources. For each change record, an overall changeType is returned indicating if the overall change to the resource was a Create, Update, or Delete action. When you set the fetchPropertyChanges flag to true in your request, the response body will contain a new section called propertyChanges that contains the list of property changes made, including the property name, the before value, the after value, and the change type for that property change (Insert, Update, or Remove).

Large file shares (100 TiB) for Azure Files standard tier

Microsoft announces the general availability of larger, more powerful files shares (100TiB) for Azure Files on standard tier. Large file shares on standard shares significantly improves customers’ experience on standard shares by increasing not only the capacity limits to 100 TiB (20x increase), but also the performance limits up to 10,000 IOPS (10x increase) and 300 MiB/s (5x increase). Large file shares for standard tier is now live in 13 Azure regions with support to enable large file shares on existing accounts.

SR-IOV availability schedule on NCv3 Virtual Machines SKU

As part of Azure’s ongoing commitment to providing industry-leading performance, Microsoft is enabling support for all MPI types and versions, and RDMA verbs for InfiniBand-equipped virtual machines, beginning with NCv3 coming in early November 2019.

Azure Monitor updates

  • Azure Monitor for VMs is available in South Central US, West US, Central US, North Central US, East Asia, and Central India. It’s available around the world in eighteen public regions.
  • In April 2019 Microsoft added support for Azure Kubernetes Services (AKS) in China regions. As part of this support, multi-cluster view is now available in the table of contents so you can monitor multiple clusters at once. Also, AKS-Engine is now supported for China regions. 
  • Azure Monitor for containers has updated the agent to support pod annotation settings. This supports Prometheus metrics scrapping per namespace configurations via config map. Also supports descriptive error outputs to troubleshoot scrape settings.
  • Grafana dashboard template is now available for out-of-the-box metrics collected by Azure Monitor for containers.

How to address the end of lifecycle for Windows Server 2008\2008 R2

The end of Microsoft support for Windows Server 2008 and Windows Server 2008 R2 is imminent and planned for 14 January 2020. As of this date, Microsoft will no longer release free security updates for these platforms in an on-premises environment. Unfortunately, there are still many systems in production that adopt these operating system versions. This article discusses the approaches you can take to address this situation, avoiding exposing your infrastructure to security issues caused by the unavailability of the necessary updates.

The end of the extended support for these platforms implies that Microsoft, unless certain actions are taken, will no longer release its security updates. Under these conditions the exposure to security attacks is considerable and would result in the state of non-compliance with respect to specific regulations, such as the General Data Protection Regulation (GDPR). This condition, certainly not very pleasant for those who find themselves to face it now, given the limited time, it can also be seen as an important opportunity for renewal and innovation of the infrastructure.

To continue receiving security updates for Windows Server 20082008 R2 hosted on on-premises environment, the only possibility is to join to the program Extended Security Update (ESU). The fee program is only available for customers in Software Assurance and ensures the provision of Security Update classified as "critical" and "important" for a further three years, from 14 January 2020.

If the ESU program is not appropriate to their needs you can be assessed two totally different upgrade paths.

Upgrade on-premises

This path provides for the transition to a new version of Windows Server environment on-premises. The advice in this case is to approach at least Windows Server 2016 and not to proceed, whenever possible, with upgrade in place of the operating system, but to manage migration in side-by-side. This method usually requires the involvement of the application provider, to ensure software compatibility with the new version of the operating system. Since the software is not recent, often it require the adoption of updated versions of the same, which may comprise architecture adjustment and an in-depth phase of testing for the new release . By adopting this upgrade process, the time and effort are considerable, but the result you get is critical to complying with the technological renewal.

Migrating to Azure

Migrating Windows Server Systems 2008 and Windows Server 2008 R2 on-premises in Azure environment will continue to receive security updates for another three years, classified as critical and important, without having to join the ESU program. This scenario is not only useful to ensure compliance with its systems, but it opens the way towards hybrid architectures where you can get the cloud advantages. In this regard, Microsoft offers a great solution that can provide a large set of tools needed to best deal with the most common migration scenarios: Azure Migrate,  that structure the migration process in different phase (discovery, assessment, and migration). This approach may be more immediate than upgrading systems and gives you more time to deal with software renewal. In this regard, the cloud allows you to have excellent flexibility and agility in testing applications in parallel environments. Before starting the migration path towards Azure is fundamental to structure the hybrid networking environment in a timely manner and evaluate the iterations with the other infrastructure components, to see whether the application can also work well in the cloud.

Regardless of the upgrade path you decide to take the advice is to make a detailed assessment, so you can categorize workloads by type, criticality, complexity and risk. In this way it is possible to prioritize, and proceed with a structured migration plan.

Conclusions

For all those who, inside their own datacenter have Windows Server 2008 or Windows Server 2008 R2 is appropriate to manage the condition that Microsoft will not release more security updates, free of charge, exposing systems to potential security issues. At the same time there are various possibilities offered by Microsoft to address this situation in the best possible ways. The migration path to Azure is definitely a very interesting option to start the journey to expand your datacenter into the Microsoft public cloud.

Azure IaaS and Azure Stack: announcements and updates (October 2019 – Weeks: 39 and 40)

This series of blog posts includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft in the last two weeks.

Azure

Large file shares (100 TiB) Azure FIles standard preview available in new regions

Azure Files standard large file shares (LFS) preview in available in two more regions: North Europe and East Asia. Please see the full region list at this page.

New version of Azure Storage Explorer

This month Microsoft released a new version of Azure Storage Explorer, 1.10.0. This latest version of Storage Explorer introduces several new features and delivers significant updates to existing functionality. These features and changes are all designed to make users more efficient and productive when working with Azure Storage, CosmosDB, ADLS Gen2, and, starting with 1.10.0, managed disks. You can download Storage Explorer 1.10.0 to take advantage of all of these new features.

Increment snapshots of Azure managed disks in preview

The preview of incremental snapshots of Azure managed disks is now available. Incremental snapshots are a cost-effective point-in-time backup of managed disks. Unlike current snapshots, which are billed for the full size, incremental snapshots are billed for the delta changes to disks since the last snapshot. They are always stored on the most cost-effective storage i.e., standard HDD irrespective of the storage type of the parent disks. Additionally, for increased reliability, they are stored on Zone redundant storage (ZRS) by default in regions that support ZRS. They cannot be stored on premium storage. 

Windows Virtual Desktop is generally available

Windows Virtual Desktop is generally available worldwide. It is the only service that delivers simplified management, a multi-session Windows 10 experience, optimizations for Office 365 ProPlus, and support for Windows Server Remote Desktop Services (RDS) desktops and apps. With Windows Virtual Desktop, you can deploy and scale your Windows desktops and apps on Azure in minutes. It is available in all geographies, customers will be able to deploy scalable Azure-based virtualization solutions with a number of operating systems, including Windows 10 multi-session, Windows Server, and Windows 7 desktops with free Extended Security Updates for up to three years for customers still completing their move to Windows 10.

Azure Lab Service Updates

Azure Lab Services added this new features:

  • Adjust quota per user, enabling instructors to give additional hours to students as needed.
  • An option to install GPU drivers automatically if a GPU size is picked. 
  • An updated and improved UI experience.

Private Link for Azure SQL Database and Data Warehouse is in preview

Private Link enables you to connect to Azure SQL Database and Data Warehouse via a private endpoint. Use it to establish cross-premises access to the private endpoint using ExpressRoute, private peering, or VPN tunneling, or you can choose to disable all access via public endpoint.

Preview of direct-upload to Azure managed disks

You can directly upload your VHD do Azure Managed disks without converting them. The direct-upload is in preview.

Azure File Sync agent version 4.x will expire

On November 5, 2019, Azure File Sync agent version 4.x will be expired and stop syncing. If you have servers with agent version 4.x, update to a supported agent version (5.x or later). If you don’t update your servers before November 5, 2019, they will stop syncing. To resume syncing, the agent must be updated to a support version.

Azure management services and System Center: What's New in September 2019

Even in September it was announced by Microsoft news regarding the Azure management services and System Center. Our community publishes this summary monthly to provide an overview of these new features. In this way you can stay up-to-date on these topics and have the necessary references to conduct further investigations.

Azure Site Recovery

New Update Rollup

For Azure Site Recovery was released theUpdate Rollup 40 that solves several issues and introduces some improvements. The details and the procedure to follow for the installation can be found in the specific KB.

Azure Backup

Support for disks up to 30 TB

For Azure Backup has been announced the support in public preview for large Managed disks, up to 30TB. For further information you can consultthis article.

System Center

New Update Rollup for System Center 2016

Microsoft has released the Update Rollup 8 (UR8) for System Center 2016. This is the second update rollup of the year and includes updates for the following products, mainly aimed at solving problems:

System Center Configuration Manager

New releases for the Technical Preview Branch

For Configuration Manager was released the update 1909 one of the main innovations is the creation of orchestration groups, to better control the deployment of software updates. The Orchestration Groups are designed to give you more flexibility when upgrading devices, including the ability to run PowerShell scripts before and after the update deployment phase.

To check the details of what's included in these updates, you can see this document.

Please note that the Technical Preview Branch releases help you to evaluate new features of SCCM and it is recommended to apply these updates only in test environments.

Evaluation of Azure and System Center

To test and evaluate free of charge the service offered by Azure you can access this page, while to try out the various components of System Center you must Access to theEvaluation Center and, after registering, you can start the trial period.

Azure Migrate: introduction to the solution

The migration of workloads hosted in on-premises datacenter toward Azure is a challenger process that is more and more frequently required to exploit the benefits of cloud. To best address the migration path and achieve the desired results, it is appropriate to carry out a careful preliminary analysis and use appropriate tools. Azure Migrate is the service in Azure that includes a large portfolio of tools that you can use, through a guided experience, to address effectively the most common migration scenarios. This article describes the main features of Azure Migrate and the changes that have recently affected this solution.

Azure Migrate structure the process of migration in different phase: discovery, assessment, and migration. This approach provides an integrated experience that provides continuity and provides an overall view of the migration process.

The solution is currently able to cover the following scenarios of migrating to Azure:

  • Virtual Machines, in a VMware environment, Hyper-V or other public clouds (AWS, Google) and physical machines.
  • SQL Server Database to Azure SQL Database or Azure SQL Database Managed Instance.
  • Web App using .NET or PHP to Azure App Service, its Azure Platform-as-a-Service.
    • In this case, you are directed directly to the page App Service Migration, that providing the public URL it scans and provides a detailed report of the technologies that are used, to determine if they can be hosted by App Service. If so, you can start the migration process by using the Migration Assistant installed locally.
  • Large amounts of data via the offline Data Box service.
    • Directly from the portal you can order a Azure Data Box, monitor the shipping status and its data copy process towards Azure.

By accessing Azure Migrate from Azure portal is immediately directed, according to the migration scenario that you want to perform, the most appropriate tools to use.

Figure 1 – Overview of Azure Migrate

To proceed with the use of the tool you need to create a new project. This project is used to save metadata from discovery activities, assessment and migration in the on-premises environment. Metadata is retained in an Azure datacenter in the selected region. However, you can use a project in any region to perform migrations to any Azure region.

Figure 2 – Creating the migration project

Each of these steps is done through solutions provided directly by Microsoft or through tools provided by third-party vendors. At the moment in Azure Migrate are integrated the following third-party tools: Carbonite, Cloudamize, Corent, Device42, Turbonomic, and UnifyCloud.

Figure 4 - Migration Tools Available

The Microsoft tool that allows the assessment of the servers, called "Azure Migrate: Server Assessment", has been enhanced with the following features:

  • It can discover and assess VMware environments that host up to 35000 virtual machines. The limit in the previous version was 1500 VMs.
  • You have the option to profile Hyper-V environments that host up to 10000 VMs.
  • The inventory data from VMware and Hyper-V environments can flow within the same Azure Migrate project.
  • It provides guidance on sizing systems, performs analysis to identify application dependencies and provide a cost estimate.

All of the discovery process and the assessment with the tool Server Assessment occurs without installing any agent. This is a totally free tool for all Azure customers and will soon be enhanced to cover also the support of physical systems.

Also with regard to the migration process Microsoft provides its own tool called "Azure Migrate: Server Migration", that allows you to migrate virtual systems in VMware environments, Hyper-V, Amazon Web Services (AWS), e Google Cloud Platform (GCP) and physical servers. This tool has recently been enhanced with the following features:

  • Ability to migrate VMs in VMware environment in agentless mode. By adopting this mode of migration without agent, you can use the same appliance for the discovery, the assessment and the migration. This ensures that you have operating system-independent support, that allows you to migrate any OS client or server, if supported on Azure.
  • Ability to migrate without agent virtual machines in Hyper-V environments.
  • Agent-based Migration to VMs and physical servers running on Amazon Web Services or Google Cloud Platform.
  • A new simplified user experience has been introduced, making the process similar to creating a virtual machine in Azure.
  • Ability to perform the migration test without giving any impact, allowing in this way to better plan the migration. In addition, the migration process allows to obtain a loss of data equal to zero when moving applications in Azure .

Also "Azure Migrate: Server Migration" is a tool you can be uses for free for all Azure customers. Obviously the costs are to be considered for computational resources and storage used in Azure subscription after the successful migration. In this regard it is also possible to estimate in advance the possible cost savings that can be achieved by migrating workloads in Azure. The instrument Total Cost of Ownership (TCO) Calculator allows you to define the characteristics of your workloads that you want to migrate and, after arranging different parameters specific to each reality, you get an estimate of the potential savings over the 5 years.

Figure 5 – Chart of an estimate of savings, migrando in Azure, effettuata tramite TCO Calculator

Conclusions

Azure Migrate, thanks to the new features recently released , is an excellent solution that can provide a broad set of tools needed to better address the most common migration scenarios. Azure Migrate is now a real reference point for moving workloads to Azure through integrated and centralized management and a transversal approach, able to deal with different migration paths.

Azure IaaS and Azure Stack: announcements and updates (September 2019 – Weeks: 37 and 38)

This series of blog posts includes the most important announcements and major updates regarding Azure infrastructure as a service (IaaS) and Azure Stack, officialized by Microsoft in the last two weeks.

Azure

New cloud regions in Germany

Microsoft Azure is available from new cloud regions in Germany. Azure is available in new cloud datacenter regions in Germany, Germany West Central (located in Frankfurt) and Germany North (located in Berlin), to provide greater flexibility, the latest intelligent cloud services, full connectivity to the global cloud network, and data residency within Germany. The new regions with German-specific compliance, including Cloud Computing Compliance Controls Catalogue (C5) attestation, and will remove barriers so in-country companies can benefit from the latest solutions such as containers, IoT, and AI.

Azure Firewall is ISO compliant

Azure Firewall is Payment Card Industry (PCI), Service Organization Controls (SOC), and International Organization for Standardization (ISO) compliant. It currently supports SOC 1 Type 2, SOC 2 Type 2, SOC 3, PCI DSS, and ISO 27001, 27018, 20000-1, 22301, 9001, 27017. For more information, see the Microsoft Compliance Guide.

New Azure ExpressRoute sites

The following new ExpressRoute meet-me sites are now live:

  • Copenhagen
  • Stockholm
  • Munich

Azure Private Link in preview

Private Link simplifies the network architecture and secures the connection between endpoints in Azure by keeping data on the Azure network, thus eliminating exposure to the internet. Private Link also enables you to create and render your own services on Azure. During public preview, Private Link supports Azure Storage, Azure Data Lake Storage Gen 2, Azure SQL Database, Azure SQL Data Warehouse, and customer-owned services.

Monitor bandwidth for all peered Azure virtual networks with ExpressRoute

Azure network monitoring solutions including Network Performance Monitor and Network Watcher help monitor your networks in the cloud and in hybrid environments. ExpressRoute Monitoring enables you to monitor network performance over ExpressRoute circuits that are configured to use private peering or Microsoft peering.

Azure Monitor for Azure Virtual Machines is available in additional regions

Monitor for Virtual Machines monitors and analyzes the performance and health of your Windows and Linux virtual machines hosted in Azure, on-premises, or with another cloud provider. Azure Monitor for Azure Virtual Machines is now available in Japan East, North Europe, and East US2.

Service Map feature of Azure Monitor is available in additional regions

Service Map automatically discovers application components on Windows and Linux systems and maps communication between services. The feature enables you to view your servers, processes, inbound and outbound connection latency, and ports as interconnected systems. The Service Map feature of Azure Monitor is available in Japan East, North Europe, and East US2.

Zone Redundant Storage (ZRS) for Azure Files premium tier

Zone Redundant Storage (ZRS) is available for Azure Files premium tier. The ZRS replication provides customers a choice of performant Azure Files services with higher availability. With the release of ZRS support, Azure Files premium tier now offers two durability options:

  • Zone redundant storage (ZRS) for data protection against entire zonal outage.
  • Locally-redundant storage (LRS) for lower cost-effective storage for data protection against hardware failure.

Currently, ZRS option is available in West Europe and we plan to gradually expand the regional coverage.

Azure Lab Services supports new GPU Virtual Machine sizes

Azure Lab Services supports two new 6-core GPU Virtual Machine sizes:

  • Small GPU (Compute): 6 cores, 56 GB RAM, 139 Lab units.
    • Available in US, North Europe, and West Europe regions
    • Best-suited for compute-intensive and network-intensive applications such as Artificial Intelligence and Deep Learning
  • Small GPU (Visualization): 6 cores, 56 GB RAM, 160 Lab units.
    • Available in US, North Europe, West Europe, and Australia regions
    • Best-suited for remote visualization, streaming, gaming, and encoding using frameworks such as OpenGL and DirectX.

M-series virtual machines (VMs) are available in new regions

Azure M-series VMs are now available in: Germany West, Germany North, Switzerland West and Switzerland North. M-series VMs offer configurations with memory from 192 GB to 3.8 TiB (4 TB) RAM and are certified for SAP HANA.