Blogs

Archive for the ‘Cloud’ Category

A quick look at the 4 Most Used Services on Microsoft Azure

Posted on May 4th, 2021 by admin@mismo2023

1. Azure Compute

Azure compute is an on-demand computing service for running cloud-based applications. Azure compute service can be divided broadly into three categories.

  • Infrastructure as a service

Virtual Machine: It is an IaaS service that allows us to deploy and manage VMs inside a virtual network (VNet). The most fundamental building block is the Azure virtual machine. We don’t need to buy any physical hardware and bear its maintenance cost. Using Azure virtual machine, we are able to deploy different services such as Windows, Linux within the Azure cloud. All this gets done within a few minutes. When we implement a virtual machine, every virtual machine will have an associated OS disk and data disk (if we want).

  • Platform as a service

App Service: It is a managed PaaS offering from Microsoft Azure for hosting web apps, mobile app back ends, etc. With this, we can simply upload our code and it deploys the application for us.

  • Serverless services

Infrastructure provisioning and management are invisible to the developer, hence the name serverless.

Azure Functions: With azure functions, we can run small pieces of code (“functions”) without worrying about the application infrastructure.

Azure logic apps: Azure logic apps are similar to azure functions, just that we don’t have to write code. With this, we can schedule, automate and orchestrate tasks, etc.

2. Azure Site Recovery

Azure Site Recovery is Azure’s built-in disaster recovery as a service (DRaaS).

What it does is when primary infrastructure goes down then it directs to the secondary infrastructure until it comes back again. It helps in business continuity.

As an organization, you need to adopt a business continuity and disaster recovery (BCDR) strategy that keeps your data safe when planned and unplanned outages occur.

Simple to deploy and manage:

We can set up Azure Site Recovery simply by replicating an Azure VM to a different Azure region directly from the Azure portal. Azure Site Recovery is automatically updated with new Azure features as they’re released.

Reduce infrastructure costs:

It reduces the cost of deploying, monitoring, patching, and maintaining on-premises disaster recovery infrastructure by eliminating the need for building or maintaining a costly secondary datacenter.

Testing without disruption:

 You can easily run disaster recovery drills, without affecting ongoing replication.

RTO and RPO targets:

The recovery time objectives (RTO) and recovery point objectives (RPO) are within organizational limits. Site Recovery provides continuous replication for Azure VMs and VMware VMs, and replication frequency as low as 30 seconds for Hyper-V.

3. Azure Content Delivery Network (CDN)

Azure CDN delivers high bandwidth content to users by caching their content at strategically placed nodes across the world. It lowers the latency to a great extent and reduces the file download time.

CDN stores the cached content on edge servers in POP (Point of Presence) locations that are close to end-users.

4. Azure Cost Management

 While the cloud made it easy to deploy and manage thousands of resources, it’s also important to manage the cost. Microsoft Azure Cost Management delivers cloud business management solutions to multi-cloud enterprises so that they can grow the cloud with confidence. It helps organizations effectively manage and optimize cloud spend across Azure and other clouds.

Azure Cost Management is a SaaS offering that helps organizations to monitor, allocate, and optimize cloud spend in a multi-cloud environment (Azure, AWS and Google Cloud Platform, etc.).

  • Service on by default
  • Set budgets, track, and get alerts.
  • Maximize cloud potential.
  • Free to manage azure costs.
  • Integrated with the azure advisor.
  • Optimize cloud spending.

Have questions? Let us know in the comments section below!

Cloud Security – A shared responsibility

Posted on May 1st, 2021 by admin@mismo2023

We see all businesses small or big, consuming cloud technology in one or another way. The pandemic has increased the adoption substantially and before that security was one of the drivers of moving to the cloud.

While we help businesses to realize the benefits of cloud technologies, we are concerned about their misunderstanding (especially small & medium) that moving to the cloud will take away their responsibility and everything is managed by cloud provider including security.

It is super important to have a clear understanding of everyone’s responsibility. Some examples below:

  • In case of SaaS services (e.g., Microsoft 365), you need to ensure that you are following the best practices to keep your account secure. Some of these are:
  • Implementing Multi Factor Authentication (MFA).
  • Disabling the services & accounts that are not required including legacy authentication.
  • Have right process & procedures (onboarding & offboarding).
  • Use Single Sign On/Single Identity to reduce the attack surface.
  • Use premium security offerings like Advanced Threat Protection (ATP), Azure AD Premium, Intune etc.
  • In case of Cloud platforms (IaaS & Pass):
  • Make sure that you have opened only the required network traffic.
  • Patching your servers regularly.
  • Using offerings like Web Application Firewalls, DDoS protection etc. to protect your workloads.
  • Protect database servers by isolating then in a different network.

Here is a diagram from Microsoft to help you understand the shared responsibility.

Another very important factor is to have regular monitoring & audit of the environment. This preventive approach helps you avoid security breaches and downtime. You can use the services of a Cloud Solutions Provider to do this for you.

It is the responsibility of cloud solution providers to share this information and making sure that customer is aware of this. To tackle this, we at Mismo Systems has decided that all of the customers will be managed. This will make it a little difficult for us to compete in the market due to the increased cost of adding managed services by default. However, we think it’s the only way and is in the best interest of our customers.

You can read about Mismo’s Managed Services here.

Let’s understand our responsibility and have safe cloud computing!

Breakout Rooms and Its Usage – Microsoft Teams

Posted on April 18th, 2021 by admin@mismo2023

In this blog, we are going to discuss a feature provided by Microsoft teams known as Breakout rooms. Also, we will focus on how we can create and manage it with a proper set of procedures. To be able for this feature to work seamlessly you must be the meeting organizer and use the Teams, desktop client, to access the breakout rooms option and to manage breakout rooms and participants.

If you want to use breakout rooms, you will either need to start a Meet Now meeting in a channel or calendar or schedule a private meeting with selected participants or a channel. Calls from chat interfaces do not support this feature as they are not considered meetings.

Context

  • Breakout Room Purpose and Need.
  • Using a Breakout Room

Breakout Room Purpose and Need:

Basically, a breakout room is a feature in Team meetings where a private room can be added inside the main meeting which the users can join and communicate. It allows a group of users to communicate with each other while the main meeting is ongoing.

This helps the group of users to save time and energy in creating another meeting and adding designated users in it and further joining back the main meeting back. The meeting organizer can create up to 50 breakout rooms and choose to assign participants automatically or manually into rooms.

An example that will simplify the concept of having this feature – let us say there is an organization that is inviting its different employee teams/groups for a meeting. In the meeting, they will discuss project ideas from different teams/groups.

Now traditionally if we implement this scenario, the solution to this will be first to create the main meeting room where all the tasks for each team must be discussed. Then these teams will start their own respective meeting to discuss project ideas. So, if there are 25 teams then 25 new meetings will be started which can result in mismanagement and more overload.

Now using breakout rooms in teams this can be done in few minutes and with barely any overload as well it is easily manageable. Admin can create 25 breakout rooms which will be there in the main meeting itself and the admin can monitor activities in the rooms easily including other features too.

 How to create and manage breakout rooms:

Let us start with the prerequisites, and it is quite simple. You need a private team in Microsoft Teams. Breakout rooms cannot be set up before a meeting and must be created after the meeting has started. 

Note: It is recommended NOT to invite participants until all the preparations are done. It can cause lots of calendar pop-ups for invitations in the meeting which would be a bit annoying for the participants.

 The breakout room icon is located on the meeting menu between the reactions control and the ellipsis that reveals additional actions.

  1. Join your meeting from the Teams desktop client.
  2. Once the meeting has started, select the breakout room icon.
  3. In the pop-up settings window, select the number of breakout rooms you want to create and how participants will be assigned:
    • Automatically – participants who have already joined the meeting will be assigned into equal-sized rooms. Participants who join the meeting after automatic allocation will need to be assigned manually.
    • Manually – allows you to assign participants to rooms as you choose.
  1. Select Create rooms button. A menu will appear to the right of your Teams meeting window displaying room management options, room titles, participants, and status of your breakout rooms and participants.
  1. To manually create additional rooms, select Add room.
  2. To assign/move a participant, select the closed room where the participant is currently assigned. Check the boxes next to the names of the participants you want to move. Select Assign and choose any room you want to place them in.

Note: The participants joining via a desk phone or Teams mobile app cannot be assigned and will remain in the main meeting.

  1. To edit the title of a room or delete it, hover over the status icon next to the room title:
  2. Rename room: Change the title of the selected room. It is recommended to create a specific title as the chat log remains accessible for participants after the meeting.
  3. Delete room: Remove the selected room. Any assigned participants will be moved to the list of unassigned participants. To open additional overarching room settings, select the ellipsis icon next to the Breakout rooms heading, and chose rooms settings while all rooms are closed:
  4. Automatically move people into opened rooms – select to move participants automatically in and out of their assigned rooms when you open or close the breakout rooms. Participants will receive a notification that they will be moved automatically with 10-second notice.
  5. Let people go back to the main meeting: select to allow participants to move between the main meeting and their assigned breakout room when the breakout rooms are open. If this option is not selected, participants will be able to move back into the main meeting by selecting Return, or back to the breakout room by selecting Join room.

Note: It is not possible for participants to switch between breakout rooms unless the meeting organizer has assigned them a new room.

  • Recreate rooms: delete all current rooms and settings to start from the beginning.
  • Make an Announcement: Organizers can send announcements to the breakout rooms and recall all participants back to the main meeting at any time.

When you are satisfied with the breakout rooms allocations and settings, you need to open the rooms to allow participants to access them.

  • To open all the rooms at once, select Start rooms. The status icon next to the rooms will change from Closed to Open.
  • To open individual rooms, hover over the Closed status icon of the room and select the ellipsis icon. Select Open.
  • When participants are in the breakout room, in meeting displays beside their name. If this status is not shown beside a name, you can prompt the participant to enter the breakout room by selecting their name and Ask to join.

You will be added to the breakout room and can interact with all features of the meeting.

  • While you are in a breakout room, you will be On Hold in the main meeting and will not be able to see if participants have entered the main meeting until you return to the main meeting.
  • Select the Leave button to leave the breakout room and return to the main meeting.

At the end of the meeting, you can either leave your breakout rooms open or closed.

  • Open: Allows participants to continue collaborating to the breakout room chat and re-open the breakout room meeting after the main meeting has ended. If the meeting is recurring, your breakout room settings and allocations are saved and maintained for subsequent meetings.
  • Closed: Breakout room chats become read-only for all participants after the meeting has ended and cannot be re-opened. Breakout room settings and allocations are not saved for subsequent meetings.

Have any questions? Let us know in the comments section below. Thanks for reading!

Is Cloud cheaper than On-premises Data Centres?

Posted on April 12th, 2021 by admin@mismo2023

Cloud has bloomed over the last decade, according to Goldman’s analysts almost 23% of IT workloads now live on Public clouds, and expected to reach 45% in the next 4 years, with the cloud service market reaching a valuation of $1 trillion.

What is the driving force behind this immense growth?

The major factors are Cost, Security, and Accessibility. Cost is the main factor that most of the enterprise consider before making any decision. IT workloads can either be on Cloud or on-prem Data Centres.

On-Prem Data Centres: On-premises data centres are a group of privately owned & controlled servers. It is based on Capex (Capital Expenditure) model which means the enterprise must require in-house server hardware, software licenses, integration capabilities, and an in-house IT team to control, administer and maintain the data centre and resolve potential issues that may arise. This does not even factor in the amount of maintenance that an enterprise is responsible for when something breaks or does not work. Enterprise with a huge growth potential must also factor in the cost of future upgrades, which are going to be needed with increased workloads.

Cloud: Cloud works on Opex (Operational expense) model which means a third-party provider owns the infrastructure which includes hardware & software and enterprises can subscribe to services and manage their account over the internet, this allows enterprises to pay on an As-Needed basis and effectively scale up or down depending upon overall usage and user requirements.

(Read More:- A quick look at the 4 Most Used Services on Microsoft Azure)

Following are some of the parameters to compare the cost of both:

Infrastructure: – Since the on-prem data centre is a Capex which means enterprise must spend a huge sum of money on hardware, software licensing, data backup, IT staff, and space for the housing data centre. In cloud computing a third-party CSP pays for all of these and enterprises can choose from monthly or annual subscriptions. So, on-prem have an enormous upfront cost and cloud computing has none.

Compliance: – Enterprises in the health and finance sectors must be compliant with HIPPA, CCPA, etc. Enterprises having on-prem data centres need to recruit staff with proper knowledge about regulations to take care of compliance-related matters. Servers need to be properly configured and maintained to stay compliant, if something went wrong then the whole burden falls on the enterprise itself. Unlike on-prem, Cloud providers (Amazon, Microsoft, Google) spend a huge sum of money to stay compliant. Although the responsibility will be yours if your CSP is not compliant, you can trust the word of big CSP’s like Microsoft, AWS, Google Cloud, etc

Backup: – Enterprises having on-prem data centres are more prone to data loss because data is stored in internal servers and backup as well. Many enterprises choose to use cloud services for data backup even after having on-prem data centres, which is an overhead for enterprises. Enterprises are offered various services to avoid data loss in the cloud such as redundancy (LRS, GRS, and ZRS), retention policy, snapshots, etc. Data is everything nowadays so losing data could be a huge cost for enterprises.

Deployment: – Deployment cost is something that must be born in both solutions. Although Cloud deployment costs can be lower by outsourcing the deployment service to a CSP partner which is specialized in doing so.

Scalability: – Scaling up or down according to your workloads in on-prem requires capital, time, and manpower, however, it can be done with just a few clicks and at a comparatively lesser cost.

Monthly Management: – When it comes to operating costs in on-prem, it is somewhat fixed. It includes rent for space, electricity cost, and in-house IT staff salaries. In Cloud, you can outsource the management of cloud servers to a CSP partner at a significantly less cost.

If you still have questions about whether cloud computing is a solution to your complex IT problems? Call Mismo Systems today!

Hosting with Transparency, Compliance, and Security

Posted on April 4th, 2021 by admin@mismo2023

We help customers host applications on the cloud, this includes accounting systems including Tally, ERP software including SAP, and Navision. We host workloads only with leading public cloud providers which are Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

We ensure that the solution is compliant from the licensing standpoint of both cloud providers (e.g., Microsoft) and business systems (e.g., Tally or NAV). We ensure that the system is secure and there’s no open access by implementing VPN and implementing backups.

All these services are fully managed. We perform regular monitoring of system performance, continuously evaluating the security posture, patching systems every month, and perform regular restore drills. And all this is proactive and there have been instances where we approached customers to reduce the server config (and hence reducing the cost) because of less load than expected. That is the beauty of Pay as You Go (PAYG).

I come across a question often from my team that our solution is costlier and also while discussing with customers that we are getting it at a much cheaper price than you are offering then why we should host with you. This bothered me and I decided to find out why our cost is higher than the so-called competition. I took help from one of the potential customers and spoke to the competition. And the following is what I found was making us costlier.

  • Competition is using a remote access solution that is not compliant as per cloud or license provider licensing terms. You ask them about it, and they will have no answer. Test it out!
  • They are not providing a VPN and the system is open from anywhere. They claim to have a firewall and antivirus but keeping your accounting system open to the whole world is a clear no-no from a business owner perspective.
  • They have got into a contract with a third-party data center provider and will give you a server. Your contract is with them and not with the datacenter. There’s no direct control or visibility and shifting to another provider will be a nightmare.
  • We enable you to host with major public cloud providers and the contract is between you and the cloud provider. You are the owner of the account. With the portal of Public Cloud, you can see your server and control it and even kick us out if we underperform and onboard another service provider. Think of the visibility and control you have. If I am a business owner, I cannot let my business systems under someone else’s control.
  • We provide proactive managed services, so your systems are always running and secure with a data backup which is tested regularly.
  • They give a fixed cost per user, our model is PAYG, so you can scale up or down easily.

I hope this gives us and our customers visibility of what you get when you host with us and what you lose when you host with a low-cost provider.

Future of Cloud Computing

Posted on April 4th, 2021 by admin@mismo2023

Cloud computing has established itself as the inevitable future when it comes to IT services. This picture becomes much clearer when we take a glimpse at some of the prominent cloud statistics such as, “one-third of companies’ total IT budget is allocated to cloud services” or Cisco’s statement saying that “94% of the world’s workload will be run on the cloud by 2021”.

If we take a brief look at the road that cloud computing has traveled so far, we can find that the concept first came into being in DARPA’s (the Defense Advanced Research Projects Agency) quest of developing a breakthrough technology that allows a “computer to be used by two or more people, simultaneously” in 1963.

As soon as the late 1990s came the years when Salesforce took a huge direction and giving rise to a whole new way of providing services to the globe i.e., SaaS (Software as a Service) when they made available their application to anybody with just an internet connection.

Since then, cloud computing has become a behemoth of a platform, far-reaching the imaginations of its progenitors, taking its modern form in 2006 when Amazon came up with AWS (Amazon web services) offering a fleet of VMs dubbed as EC2 (Elastic Cloud Computing).

At present, there is a multitude of major players in this segment starting from Microsoft Azure, Google Cloud Platform to IBM Bluemix and Alibaba. All having their unique specialty and benefits.

Now that we have covered the ground of the cloud’s existence so far, let’s get back to the future. SaaS seems to be the ultimate stop for any IT offering and the statistics solidifying this argument is the latest forecast from Gartner, which predicts the SaaS revenue to be $113 Billion and some change just for 2021, higher than any other form of cloud offering. This surge can be seen not only in SaaS but in IaaS and PaaS as well.

The trust in the cloud is so profound at the present and strengthening by the day so much so that organizations feel highly confident in moving all of the Infra to the cloud, making it the fastest-growing service with ‘Cumulative Annual Growth Rate (CAGR)’ of 33.7%.

With the cloud offering a highly agile and flexible landscape, organizations are making the best of various strategies while moving to the cloud. One of the most popular ones being the hybrid cloud, which is the best of both worlds – Private and Public Cloud with 84% of the enterprise making use of this strategy.

It’s clear, looking at the picture above that cloud will come with various innovations as we go along and how companies make use of it will be equally interesting to watch. The stage has been set for the unprecedented level of modernization across the globe. We all as earthlings are set to reap benefits from this technologically revolutionary and green campaign and once more we all get the opportunity to bear witness to the future unfolding right in front of us.

Read more blogs from Mismo Systems here.

AWS Security Features

Posted on April 4th, 2021 by admin@mismo2023

The Amazon Web Services (AWS) in terms of security follow a shared responsibility model. So, the security ‘of’ the cloud is on the shoulders of AWS, whereas you and your organization’s development team have to look after the security “in” the cloud. Hence, the protection of the infrastructure of the cloud, including hardware, software, and networking falls under the territory of AWS. All the other security objectives, including access to your AWS resources and the security of your application, is your responsibility. The following is an overview of four of the most common AWS security features you’ll need to keep your cloud secure.

1. S3 Security

S3 stands for Amazon’s Simple Storage Service, which is responsible for providing data storage with a high level of availability & durability. Just like all AWS services, the S3 by default denies access from most sources. Only the bucket and object owners (the AWS account owner) have read/write access by default. Hence, it becomes important to lock your S3 buckets so that no unauthorized users are able to view, upload, or delete your files. Contrary to other services, there are several ways of adding permissions to S3, like:

  • Firstly, by giving IAM roles to your hand-picked users within your AWS account. They can be used to specify what the users are allowed to do, and how many of them have access to it?
  • Usage of Bucket Policies to lock down a single bucket. There is an option of adding permissions to either the individual users or the entire AWS accounts. Bucket policies can be helpful if some files in your application are public and some are private.
  • Use of Access Control Lists (ACL) to gain access for AWS accounts & not the individual users. These become very helpful when your company is in possession of & uses several AWS accounts or if any other organization needs access to your files.

2. Identity Access Management (IAM)

The IAM is a free-of-cost element of the AWS that allows you to control & manage- ‘what users have access to what services and resources. By default, access to resources is generally denied, so you will have to grant users permissions in IAM. Permissions are incredibly comminuted and allow you to specify the particular file or resources that a user can access, what the things are that they can do with the file and the work conditions that have to be present for the permissions to get activated – like, using a specific IP address to access AWS. Here are some best practices you should consider with IAM:

  • Granting few privileges- Granting the users only the permissions they need to perform the tasks, and nothing more. This is very beneficial, as you can always grant more permissions, but you cannot obtain the databases that were deleted or removed because you made everyone an admin.
  • Creation of groups- A group can be defined as a lump or collection of users that allows you to specify the various permissions for the concerned users. Because of this, tracking who has what permissions becomes very easy, plus you can add permissions to several users at once. For example, a group called Mismo AWS could be given full control over the AWS, while the other group, i.e., AWS Developers, in this case, may only be given access to Lambda and S3.
  • Enable multi-factor authentication, or MFA, for all users. MFA means that, for a user to sign in, they will have to enter the passcode followed by an additional code that is sent to them through a secondary device, like a smartphone. This is very useful as, even if a user’s password is compromised, their account will not be accessible.

3. Cloud Trail

Your applications are not directly affected by CloudTrail, but it is essentially a tool used for tracking the activity of the users, compliance demonstration, and executing the security analysis. The review activity can also be searched through the logs created by CloudTrail. Overall, it is present by default, so you can view the logs as long as you have an AWS account. CloudTrail is very useful in determining whether your security configuration is sufficient or not? You can view the following from CloudTrail logs:

  • The various updates to AWS services.
  • The IP address source of the API calls.
  • Which account created, deleted, or even modified the different AWS resources.

You can monitor and protect your organization’s digital assets with the built-in features of AWS. You have the power to determine which security features to employ and who has access to them. Your data gets stored securely on the cloud, & your organization’s unique security requirements are still under your control.

4. Security Groups

Elastic Cloud Compute also called EC2, instances are the actual servers on which the applications are run. Each server operates from a Virtual Private Cloud (VPC), a virtual network that you have control over. These VPCs have. There are many security groups in VPCs, which may or may not allow the entry of traffic.

In these security groups, you get to choose the traffic that can enter both in and out of your VPC. Security groups, however, are stateful, so if you allowed ‘in’ a request, its response is allowed ‘out’. By default, traffic is denied, so everything gets rejected if it is not specifically allowed ‘in’. It is quite common for all the traffic to be allowed for Outbound traffic (because you are the one who is sending it), but it is important to cut down on the type of inbound traffic that you allow. You can also specify the types of requests (like HTTP, SSH, etc.), the port range, & the source of traffic through these security groups.

For more of such blogs click here.

Azure vs AWS

Posted on March 14th, 2021 by admin@mismo2023

It’s Azure vs AWS!! Read this blog to know the major differences between Azure & AWS.

What is Azure?

Microsoft Azure is a cloud computing service created by Microsoft for building, testing, deploying and managing applications and services through Microsoft-managed data centres. Founded in 2010, it can be operated on both Linux and Microsoft. Azure is a uniquely powerful offering because of its builder, Microsoft.

Azure offers Platform as a Service (PaaS) and an Infrastructure as a Service (IaaS)

What is AWS?

AWS is a subsidiary of Amazon providing on-demand cloud computing services and APIs to individuals, companies and government on a metered pay-as-you-go basis. Founded in 2006, Aws runs on Amazon Linux, which is a modified Linux operating system developed for their own use. The vast toolset of AWS is growing at an exponential rate. It’s been in the cloud computing market for more than 10 years, which means that AWS is the frontrunner and has been for some time.

AWS offering services are categorised as Platform as a Service (PaaS), Infrastructure as a Service (IaaS), and Software as a Service (Saas).

Features and Services

1.    Computing Power

  • AWS EC2 users can configure their own virtual machines (VMs), choose pre-configured machine images (MIs), or customize MIs. Users have the freedom to choose the size, power, memory capacity, and number of VMs they wish to use. 
  • Azure users, on the other hand, chose a virtual hard disk (VHD) to create a VM. This can be pre-configured by Microsoft, the user, or a separate third party. It relies on virtual scale sets for scalability purposes. 

2. Storage

  • AWS’s storage relies on machine instances, which are virtual machines hosted on AWS infrastructure. Temporary storage is allocated once per instance and destroyed when an instance is terminated. You can also get block storage attached to an instance, similar to a hard drive. AWS’s cloud object storage solution offers high availability and automatic replication across regions.
  • Azure offers temporary storage through D drive and block storage through Page Blobs for VMs, with Block Blobs and Files doubling as object storage. It supports relational databases, Big Data, and NoSQL through Azure Table and HDInsight. There are two classes of storage offered by Azure -Hot and Cool. Cool storage is comparatively less pricey than Hot, but one has to incur additional read and write costs.

3. Databases

AWS works perfectly with NoSQL and relational databases providing a mature cloud environment for big data. AWS’ core analytics offering EMR helps set up an EC2 cluster and provides integration with various AWS services. Amazon’s relational database service (RDS) supports six popular database engines: 

  1. Amazon Aurora
  2. MariaDB
  3. Microsoft SQL
  4. MySQL
  5. Oracle
  6. PostgreSQL

Azure’s SQL database, on the other hand, is based solely on Microsoft SQL.  Azure supports both NoSQL and relational databases and as well Big Data through Azure HDInsight and Azure table. Azure provides analytical products through its exclusive Cortana Intelligence Suite that comes with Hadoop, Spark, Storm, and HBase. 

4.  Network and Content Delivery

  • AWS uses a virtual private cloud (VPC) so that users can create isolated private networks within the cloud. From there, it uses API gateways for cross-premises connectivity. To ensure smooth operation, it uses elastic load balancing during networking. A user can create route tables, private IP address ranges, subnets, and network gateways within a VPC. 
  • Instead of a VPC, Azure uses a Virtual Network (VNET) that grants users the ability to create isolated networks, as well as subnets, private IP ranges, route tables, and network gateways. 
  • Both AWS and Azure offer firewall options and solutions to extend your on-premises data centre into the cloud without compromising your data. 

5.  Pricing

  • AWS provides a pay-as-you-go model and charges per hour. AWS can help you save more with increased usage- the more you use, the less you pay. AWS instances can be purchased based on one of the following models –
  • Reserved Instances – Paying an upfront cost based on the use, one can reserve an instance for 1 to 3 years.
  • On-demand Instances -Just pay for what you use without paying any upfront cost.
  • Spot Instances- Bid for extra capacity based on availability.
  • Azure charges per minute, offering a more exact pricing model than AWS. It also offers short-term commitments allowing you to choose between monthly or pre-paid charges

For more such blogs, visit here. Subscribe to our newsletter for the latest updates on Windows Virtual Desktop & Microsoft Teams.

Tags: ,

Azure Firewall

Posted on February 9th, 2021 by admin@mismo2023

Azure Firewall is a managed, cloud-based network security service that protects your Azure virtual network resources.

You can centrally create, enforce the network connectivity policies across subscriptions and virtual networks.

Firewall features

Built-in high availability: No additional load balancers are required because High availability is built-in so, you don’t need to configure anything.

Availability Zone:  Azure firewall can be configured during deployment to span multiple Availability Zones to increase the availability, availability Zones increases the availability up to 99.99% uptime.

There is no additional cost for a firewall deployed in the availability Zone, However, there are additional costs for inbound and outbound data transfer associated with availability Zones.

Unrestricted  Cloud Scalability:  Azure Firewall can scale up as much as you need to accommodate changing network traffic flows, so you don’t need to budget for your peak traffic.

Application FQDN  filtering rules:  you can limit outbound HTTP and HTTPS traffic or Azure  SQL traffic to a specified list of fully qualified Domain names (FQDN) including wild cards. This feature doesn’t require TLS terminations

Network traffic filtering rules: you can centrally create allow or deny network filtering rules by source and destination IP address, port, and protocol. The Azure Firewall is fully stateful, so it can distinguish legitimate packets for different types of connections.  Rules are enforced and logged across multiple subscriptions and virtual networks.

FQDN tags: make it easy for you to allow well–known Azure Service network traffic through your firewall. For example, say you want to allow windows to update the network through your firewall. You create an application rule and include the windows update tag. Now network traffic from windows update can flow through your firewall.

Service tags:  A service tag represents a group of IP address prefixes to help minimize complexity for security rule creation. You can’t create your own service tag, nor specify which IP address is included within a tag. Microsoft manages the address prefixes encompassed by the service tag, and automatically updates the service tag as addresses change.

Threat intelligence:  Threat intelligence-based filtering can be enabled for your firewall to alert and deny traffic from/known malicious IP addresses and domains. The IP Addresses and Domains are sourced from the Microsoft Threats intelligence feed.

Outbound SNAT support: All outbound virtual network traffic IP addresses are translated to the azure Firewall public IP (Source Network address translation). You can identify and allow traffic originating from your virtual network to remote internet destinations. Azure Firewalls doesn’t SNAT when the destination IP is a private IP range per IANA-RFC-1918. If your organization uses a public IP  address range of private network, Azure Firewall will SNAT  the traffic to one of the firewall private IP  addresses in AzureFirewallSubnet. You can configure Azure Firewall to not SNAT your public IP address range.

Inbound DNAT Support: Inbound internet network traffic to your firewall public IP address is translated (Destination Network address translation) and filtered to the private IP addresses on your virtual networks.

Multiple Public IP addresses:  You can associate multiple public Ip addresses (up to 250) with your firewall.

This enables the following scenarios:

DNAT – you can translate multiple standard port instances to your backend servers. For example, if you have two public IP addresses, you can translate TCP Port 3389 (RDP) for both IP Addresses

SNAT- Additional Ports are Available for outbound SNAT connections, reducing the potentials for SNAT port exhaustion. At this time, Azure Firewall randomly selects the source Public IP address associated with your firewall. Consider using a public IP address prefix.

Azure Monitor logging:  All events are integrated with Azure Monitor, allowing you to archive logs to a storage account, stream, events to your event hub, or send them to Azure Monitor logs.

Forced Tunnelling: you can Configure  Azure Firewall to route all internet–bound traffic to a designated next hop instead of going directly to the internet.

For more details, contact us!

Package Manager for Microsoft Intune Administrators – Part 1

Posted on February 3rd, 2021 by admin@mismo2023

Deploying applications to end-user Windows machines has never been easier if you are a Microsoft Intune administrator. Earlier what used to be a painstaking process of installing each application and its required dependencies one by one, has evolved into a professional solution where you can package all the applications along with their required dependencies into one complete “.intunewin” package for a simplified solution.

The concept of modern management or modern device management takes this a step further by providing IT administrators an even simpler way of installing, managing, updating & uninstalling applications using package managers.

Linux adopted early the practice of maintaining a centralized location where users could find and install the software.

What is a “Package Manager”?

A package manager or package management system is a collection of software tools that automates the process of installing, upgrading, configuring, and removing computer programs for a computer’s operating system in a consistent manner. It keeps track of what software is installed on the computer and allows us to easily install new software, upgrade the software to newer versions, or remove software that was previously installed.

As the name suggests, package managers deal with packages: collections of files that are bundled together and can be installed and removed as a group. Often, a package is just a particular program. A software package is an archive file containing a computer program as well as necessary metadata for its deployment. The computer program can be in source code that has to be compiled and built first. Package metadata includes package description, package version, and dependencies (other packages that need to be installed beforehand).

Package managers are charged with the task of finding, installing, maintaining, or uninstalling software packages upon the user’s command. Typical functions of a package management system include:

  • Working with file archivers to extract package archives
  • Ensuring the integrity of the package by verifying their checksums and digital certificates, respectively
  • Looking up, downloading, installing, or updating existing software from a software repository or app store
  • Grouping packages by function to reduce user confusion
  • Managing dependencies to ensure a package is installed with all packages required

Package Managers differ based on the packaging system as well as the operating systems for which they are used. For example, RPM-based Linux, Yum, and DNF are package managers. For DEB-based Linux, we have apt-get, aptitude command line-based package managers. For Windows, the two most used package managers are Winget & Chocolatey. Over the next couple of weeks, I am going to do a deep dive on how to leverage these platforms along with Microsoft Intune to make applications management easier.

In this part 1 of the 4-part series, we will investigate Chocolatey and what it does. In the next installment, I will walk you through steps to get it set up in your organization using Microsoft Intune and how you can use this to manage application installment & management. In parts 3 & 4 we will look into how the same can be achieved via Winget.

Chocolatey

Chocolatey is a machine-level, command-line package manager and installer for Windows software. It uses the NuGet packaging infrastructure and Windows PowerShell to simplify the process of downloading and installing software.

Some well known features of chocolatey:

  • Deploy Anywhere: chocolatey supports all Windows versions after Windows 7. It requires PowerShell v2+ and Microsoft .NET Framework 4.x. You can deploy on-prem, to Azure, AWS, or any cloud provider you might be looking at
  • Deploy with Everything. Anything that can manage endpoints or do remote deployments can either direct Chocolatey through commands, batches, or scripts. Full configuration management solutions like Ansible, Chef, PowerShell DSC, Puppet or Salt typically have providers/modules that allow you to work within their languages to manage both Chocolatey installation/configuration and software
  • Packages are Independent and Portable. When you deploy through multiple systems or want to migrate from one to another, you can take the work you have done with Chocolatey with you. How is that for some major time-savings
  • Completely Offline and Secure. You can step up your own local repositories and start using them without the need for an internet connection
  • Create Your Own Deployment Packages and use them internally
  • Manage Dependencies With Ease. You can build specific installation paths for your applications

One of the most time-consuming tasks with Microsoft Intune is the application portion, where you package applications up to deploy. Currently, if the application is bundled as an executable (exe), the steps are as follows:

  • Grab the installation executable
  • Find the install switches – most common one is the silent switch
  • Find the install directory or registry key to tell Microsoft Intune if it installed correctly or not
  • Find the uninstall executable and any switches it has as well
  • Wrap the executable in an ‘INTUNEWIN’ format
  • Import file into Microsoft Intune
  • Configure the application with the install and uninstall switches as well as the directory it creates to Microsoft Intune knows if it installed correctly or not

With Chocolatey, the process gets reduced and we only need to do the following:

  • Find any install switches
  • Grab the installation executable
  • Find the uninstall process and switches
  • Configure the application with any install switches, or uninstall switches within the Intune blade

Stay tuned for part 2, where we install Chocolatey as a Win32 app using Microsoft Intune and install subsequent software.

Read more blogs!