Friday, July 14, 2017

Microsoft EMS support for your journey to EU GDPR compliance

Most of the you are already aware about the new European privacy law, the General Data Protection Regulation (GDPR). GDPR is due to take effect from May 2018. The GDPR imposes new rules on companies, government agencies, non-profits, and other organisations that offer goods and services to people in the European Union (EU), or that collect and analyse data tied to EU residents. The GDPR applies no matter where you are located.


Microsoft provides you with right set of products and features that you can adopt to make your Organization compliant with GDPR, Access the below Microsoft Trust Center page to know more

Access here: https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/default.aspx

Be sure to review all  resources including Webinar, Products and  Services, whitepapers, Blog posts etc. and also take the Assessment to check your Organization readiness for GDPR.

This whereto post is written to point you on Microsoft Enterprise Mobility + Security (EMS), which has the right set of products, components and features that effectively supports your GDPR Compliance Journey.



Download the Whitepaper to know more: Supporting Your EU GDPR Compliance Journey With Enterprise Mobility + Security

Also review the Blog post series from Enterprise Mobility and Security Blog, with more detailed updates.

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 1

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 2

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 3

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 4

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 5

How Microsoft EMS can support you in your journey to EU GDPR compliance – Part 6

Update:

Access the below Microsoft Ignite 2017 Sessions on demand related to this topic.

Learn how Microsoft Enterprise Mobility + Security supports your GDPR compliance journey

GDPR and Office 365

Related Microsoft Mechanics video below

Understanding GDPR and the tools in Office 365 and beyond to help meet its requirements

Update:

Access the latest blog post how Microsoft 365 provides an Information Protection strategy to help with the GDPR Compliance.

Microsoft 365 provides an information protection strategy to help with the GDPR

Update:

Access the On-demand Webinar to know how Microsoft 365 uses first-rate security tools to help you easily protect and manage your vast data sets on the path to GDPR compliance


Access here: Streamline your path to GDPR compliance

Stay tuned for more updates...

Tuesday, July 11, 2017

Microsoft Workplace Analytics now Available !

Every Organisation's success rely on its Employees productivity for its success, Making your employees productive is not just something that is easily achievable, you need to enable them with the right tools to perform their work effectively, setup a collaboration platform that can make them engage more with one another to effectively deliver the results.


Microsoft Office 365 provides the right platform to achieve the fore said productivity for your employees by giving them the right tools and one such great tool for employees to know their personal productivity is "My Analytics" .

My Analytics helps your users understand how they collaborate with colleagues and spend their time at work. The dashboard gives them the tools that  help them to prioritize their work and spend time more effectively. Only your Employees have access to their MyAnalytics dashboard. MyAnalytics does not include any settings that provide anyone else in your organization access to the Employee's My analytics dashboard.

MyAnalytics is available as a part of Office 365 Enterprise E5 license or it can be purchased as an add-on with select Plans.

Get to know more here: Microsoft MyAnalytics personal dashboard

Its fine that you enable your employees to know and manage their Productivity, How your business leadership team know the productivity at an Enterprise level, to address this need, you now have the latest add-on for Office 365 "Microsoft Workplace Analytics"  .

Workplace Analytics leverages Office 365 collaboration data to deliver powerful new insights for enterprise productivity. It helps your business leaders understand collaboration patterns across organisations that influence productivity and employee engagement.

Workplace analytics is an add-on that can be purchased separately with any Office 365 Enterprise plan.

Access the Official Blog post here: Transform your organization with Microsoft Workplace Analytics


Get to know the Metrics for Workplace Analytics here: Metric descriptions and glossary for Workplace Analytics

Be sure to know the latest updates in the "Workplace Analytics" space in Microsoft Tech Community.

Having both My Analytics for Employees personal productivity tracking and Workplace analytics for enterprise productivity tracking , empowers your Organization to become more productive and one step a head in driving towards your Organisational goals.

Stay tuned for more updates...

Sunday, July 09, 2017

Windows AutoPilot now Available !

Microsoft team announced the availability of Windows AutoPilot a suite of capabilities designed to simplify and modernize the deployment and management of new Windows 10 PCs.


With Windows AutoPilot, IT professionals can customize the Out of Box Experience (OOBE) for Windows 10 PCs and enable end users to take a brand-new Windows 10 device and—with just a few clicks—have a fully-configured device ready for business use. There are no images to deploy, no drivers to inject, and no infrastructure to manage. Most importantly, users can go through the process independently, without making any decisions and without needing to involve IT.

Windows AutoPilot allows you to:

  • Automatically join devices to Azure Active Directory
  • Auto-enroll devices into MDM services, such as Intune (Requires an Azure AD Premium subscription)
  • Restrict the Administrator account creation
  • Create and auto-assign devices to configuration groups based on the devices' profile
  • Customize OOBE content specific to the organization

Prerequisites

  • Devices must be registered to the organization
  • Devices have to be pre-installed with Windows 10, version 1703 or later
  • Devices must have access to the internet
  • Azure AD premium P1 or P2
  • Microsoft Intune or other MDM services to manage your devices

Access the Official Announcement here: Delivering the Modern IT promise with Windows 10

Review this Blog post to know more on this feature: Modernizing Windows deployment with Windows AutoPilot

Access the documentation here: Overview of Windows AutoPilot

Be sure to review the Microsoft Mechanics video here: Introducing Windows AutoPilot deployment
To know more and get real time answers, Attend the Ask Microsoft Anything' (AMA) about Windows 10 management!  event on  Tuesday, July 25th, 2017 from 9:00 AM to 10:00 AM Pacific Time in the  Microsoft Tech Community -Windows 10 management space

Access the related Microsoft Ignite 2017 Sessions on demand to know more.

Update:

Watch the below Microsoft Mechanics session to know more on Windows AutoPilot from Sidd Mantri MSFT

The truth about Windows AutoPilot: The service components and how it works

Also the below  Ask Me Anything session with Michael Niehaus MSFT


Update:

New Troubleshooting articles published for Windows AutoPilot.

Troubleshooting Windows AutoPilot (level 100/200)

Troubleshooting Windows AutoPilot (level 300/400)

Update:

A new guidance documentation is now available to demo the Windows AutoPilot Deployment Program on a Virtual Machine

Demo the Windows AutoPilot Deployment Program on a Virtual Machine

Stay tuned for more updates...

Wednesday, July 05, 2017

What's new in Active Directory Federation Services 2016

Organizations using Active Directory Federation Services (AD FS) to provide Single Sign-on benefits to variety of Applications both On premises and Cloud with s secure and seamless end user experience, now with AD FS 2016 with Windows Server 2016 you have more new features added that would simplify your existing Infrastructure to provide additional Security requirements like Sign-in with Azure MFA, and advanced Access Control features like Conditional Access etc. to provide enhanced secure access to your resources with rich end user experience.



To know more on the latest features review the documentation here: What's new in Active Directory Federation Services for Windows Server 2016

Organizations already using Azure MFA server On premises once successfully moved to ADFS 2016 can directly consume Azure MFA using the in-built Azure MFA Adapter and remove the On premise MFA servers. Device based Conditional access Policies are also made available for On premises using which you can apply more granular controls in providing application access.

Take a look at the related documentation articles on Requirements, Design, Deployment guidance etc.to know more in detail and plan for your New deployment or upgrade.

If you are environment is already setup with AD FS Windows Server 2012 R2 then upgrading to AD FS 2016 with Windows server 2016 is much simplified and once your environment meets the requirement to raise the "Farm Behaviour level (FBL)" to 2016, you can take full advantage of the AD FS 2016 features.

To more on this in action review the below Microsoft Ignite 2016 session



View here: Discover whats new in Active Directory Federation and domain services in Windows Server 2016

Also read this excellent Blog post from Sam here : Choosing the right sign-in option to connect to Azure AD & Office 365

Update:

Access the latest Microsoft Ignite 2017 Session below on this topic.



View here: What's new and upcoming in AD FS to securely sign-in your users to Office 365 and other applications

Update:

Access the latest best practices guidance for Azure AD and ADFS to defend against the latest password spray attack.

Azure AD and ADFS best practices: Defending against password spray attacks

Stay tuned for more updates...

MVA Learning: Exchange Hybrid Deep Dive

Planning for migrating your On Premises Exchange Environment to Office 365 using Hybrid deployment model, now you have different options available and you can select the best one for your migration.



To know more on this you can review the latest Microsoft Virtual Academy Advanced course on 'Exchange Hybrid deep dive"  to explore full hybrid, minimal hybrid, and Express Migration to see which is the best option for your migration. Also learn about common migration myths, best practices, and deployment blockers. Plus, see what’s coming in the future of hybrid.

Access the course here: Exchange Hybrid Deep Dive



Monday, July 03, 2017

Vulnerability in Azure AD Connect !!!

After the End of Support for DirSync and Azure AD Sync this April and having a tight deadline that Azure AD will stop accepting connections from DirSync and Azure AD Sync after December 31, 2017. Most Organisations already upgraded to Azure AD Connect.


If your Organization is upgraded to AzureAD Connect you get more enhanced features bundled with the product, and if you are customer using "Password WriteBack" feature you need to aware about the new Security vulnerability identified recently and fix it promptly before your environment gets impacted.

Microsoft released the new security advisory to inform customers that a new version of Azure Active Directory (AD) Connect is available that addresses an Important security vulnerability.

The update addresses a vulnerability that could allow elevation of privilege if Azure AD Connect Password writeback is misconfigured during enablement. An attacker who successfully exploited this vulnerability could reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts.

The issue is addressed in the latest version (1.1.553.0) of Azure AD Connect by not allowing arbitrary password reset to on-premises AD privileged user accounts.

More information is available in the Security Advisory Article : Microsoft Security Advisory 4033453 - Vulnerability in Azure AD Connect Could Allow Elevation of Privilege

Review the article and validate whether your environment is impacted and perform the Remediation steps promptly, Even if your Organization is not impacted Microsoft recommends Organisations to use the latest version of Azure AD Connect.

If you cannot perform the upgrade right now, follow the Mitigation steps provided in the article to fix the issue.

If you are planning for an upgrade to the latest version (1.1.553.0) of Azure AD Connect, and you are using OU-based filtering be sure to review the below release history article and perform the outlined steps as the upgrade does not carry forward OU filtering settings if not set correctly during the upgrade process.

Review here: Azure AD Connect: Version release history - 1.1.553.0

Update: 

A New version of Azure AD Connect (1.1.557.0) is now released, Review the documentation below

Review here: Azure AD Connect: Version release history - 1.1.557.0

Note: This build is not available to customers through the Azure AD Connect Auto Upgrade feature.So you need to perform a manual install.

To know more about Auto Upgrade feature review the below Excellent Blog post from MVP Jeff Guillet

Understanding Auto-Upgrade Options in Azure AD Connect

Update:

A New version of Azure AD Connect (1.1.614.0) is now released with some great features that includes support for a new installation mode called Use Existing Database. This installation mode allows customers to install Azure AD Connect that specifies an existing ADSync database

Review here: Install Azure AD Connect using an existing ADSync database

Update:

Microsoft team released AAD Connect build 1.1.654.0 (Security related Hotfix) which addresses a new security vulnerability with AAD Connect through which elevated privileges can be obtained by resetting the password for the AD DS directory synchronization account (MSOL). To address this issue you can upgrade to the new version. Microsoft also use the PowerShell Script which configures the new recommended permissions on the MSOL account and tighten the permission if you cant upgrade to the new version immediately.

Access the Release history here to know more: Azure AD Connect: Version release history - 1.1.654.0

Access the PowerShell Script here: Prepare Active Directory Forest and Domains for Azure AD Connect Sync

Also review the Excellent write-up on this topic from MVP Jeff Guillet here: Secure AAD Connect! New build 1.1.654.0 and AdSyncConfig.psm1 module is available

Stay tuned for more updates...

FastTrack for Azure Preview

Microsoft FastTrack service currently providing support for Office 365, Windows 10, EnterPrise Mobility + Security,  Dynamics 365 and now its extended to include Microsoft Azure.


Starting August 1st, 2017 FastTrack Service will include Microsoft Azure as a preview in US, Canada, and Australia. Over the coming months, Microsoft will be reviewing the results of this preview to determine how this can be roll out to other countries in the future.

Below is the extract from the Official Announcement,

FastTrack for Azure Preview

FastTrack for Azure helps customers build solutions quickly and confidently in the cloud. Our engineers work side by side with partners to guide customers, from setup, configuration, and development to production.

Starting August 1st 2017, FastTrack for Azure will provide the following solutions:

  • Backup and Archive
  • Disaster Recovery
  • Development and test
  • Internal Line of Business Applications (Database Migration, App Modernization, App Lift & Shift)

As the program evolves, we will continue to expand to the solution offerings.

During preview, FastTrack for Azure is available through Microsoft-field nomination to customers that are:

  • Located in the United States, Canada, or Australia (English-only).
  • Have an Azure project of USD $60,000 or more per year or equivalent in local currency.
  • Not supported by a Microsoft Cloud Solution Architect.
  • Aim to deploy a supported solution.
Access the FastTrack website here to begin: https://fasttrack.microsoft.com/azure

stay tuned for more updates..

Sunday, July 02, 2017

Protecting your Office 365 Global Administrator accounts

Office 365 is now globally adopted to drive productivity across the Organization. As more and more features are added to the service, managing each of them requires different level of Admin access and handled by different teams across the IT Organization. Global Administrator Account is the Prime account that has the ability to manage your entire tenant and requires enhanced security.



In today's world Phishing attacks and Security breaches occurs every minute causing drastic impact to business, Having a safe environment without compromising Information Security and data protection is the priority for all Organisations. 

This post is written to point you to the Microsoft support article available that outlines the guidelines for Protecting your Office 365 Global Administrator accounts effectively.

To better protect your Office 365 subscription from attack, you must do the following right now:
  • Create dedicated Office 365 global administrator accounts and use them only when necessary.
  • Configure multi-factor authentication for your dedicated Office 365 global administrator accounts and use the strongest form of secondary authentication.
  • Enable and configure Advanced Security Management to monitor for suspicious global administrator account activity.

As  a best practice always limit the Number of Admin accounts in your tenant, not just limited to Global Admins, and also having your Admin users use their Admin Role access only when required limits the Risk. Keep track of your Admin accounts and ensure that proper Life cycle management is in place to review the usage of Admin roles.


If your Organization has already adopted Microsoft Enterprise Mobility and Security ( EMS E5) or Azure AD premium (Premium P2) you can take the advantage of "Azure AD Privileged Identity Management" to take care of the fore said best practices at ease.

You can review more information here: Start using Azure AD Privileged Identity Management

Having Just in time Admin access , Central Administration of managing Admin Roles and usage reporting etc. ensures your  Office 365 Admin accounts are more secure.

Additionally review the Security Best practices for Office 365 support article to keep your Office 365 Organization more secure for your users.

Wednesday, June 21, 2017

Public preview of the Office 365 adoption content pack in Power BI

Microsoft team recently announced the Public preview of Office 365 adoption content pack that combines the intelligence of the usage reports with the interactive analysis capabilities of Power BI, providing rich usage and adoption insights.


Now this new content pack gives you a cross-product view of how users communicate and collaborate to help IT admins provide more targeted user communication. When you better understand how employees use the various services within Office 365, it is easy to decide where to prioritize training and communication efforts.

The content pack lets admins further visualize and analyze their Office 365 usage data, create custom reports, share insights and understand how specific regions or departments use Office 365.

Access the Official Blog post here: Announcing the public preview of the Office 365 adoption content pack in Power BI

Make sure your review the Office Mechanics Video and resources provided under the Learn more section on the blog post to know more.

Add-on Read

Use the Power BI Content Pack for Azure Active Directory to understand how your users adopt and use Azure Active Directory features in your Organization.

Review here : How to use the Azure Active Directory Power BI Content Pack

Enterprise Mobility Assessment

Microsoft Enterprise Mobility Assessment will help you evaluate your mobility landscape and determine how well your strategy addresses the foundational principles of enterprise mobility:


  • Mobile device and application management
  • Identity and access management
  • Advanced security
  • Information protection

Spend 5-10 minutes to identify your strengths and uncover hidden gaps and potential vulnerabilities. At the end of the assessment you’ll receive a summary report of how your practices compare to today’s most advanced enterprise mobility solutions. You will also have access to in-depth resources that can help you plan next steps and how to address your specific needs.

For current Enterprise Mobility + Security (EMS) customers, the assessment tool can help you identify opportunities to maximize the value of your investment.

Access the Assessment here: Enterprise Mobility Assessment

Official Blog post here: How do your enterprise mobility and security solutions stack up?

You can check out FastTrack program that connects you to experts and resources to help you build your mobility and security strategy.

Thursday, June 15, 2017

SharePoint and OneDrive Innovations to know

During last month SharePoint Virtual Summit  Microsoft team unveiled the latest innovations for SharePoint and OneDrive, including powerful integrations across Office 365, Windows and Azure.




Watch the SharePoint Virtual Summit on-demand here : https://resources.office.com/ww-landing-sharepoint-virtual-summit-2017

To know the latest innovations in action watch the below Office Mechanics videos.




Experience the latest innovations available now, and more to come in the upcoming days, Stay tuned...


Sunday, June 11, 2017

Windows Server 2016: Run Workloads for Any Platform

Windows Server 2016 is designed to run both traditional and cloud-native workloads equally well on-premises or in the cloud, and can help resolve many of the issues that come with deploying workloads in hybrid and cloud environments.


Download the Whitepaper here to know more: Windows Server 2016: Run your applications on any platform

Access the Official Blog here: Windows Server 2016: Run your applications on any platform


Thursday, June 01, 2017

Protect your data at the front door with conditional access

Microsoft Enterprise Mobility Security provides Organization with enhanced conditional access controls powered by Azure Active Directory Premium.


Conditional access has evolved in the recent days and the latest documentation can be found here : Conditional access in Azure Active Directory

Access the below Whitepaper to Learn how to use conditional access to keep corporate data secure while still enabling people to do their best work from any device.

Protect your data at the front door: Enterprise Mobility + Security conditional access can help you:

  • Set parameters to restrict access based on application, user, location, or risk
  • Enforce device compliance on managed or unmanaged employee devices
  • Identify and classify vulnerable access scenarios based on risk

Download here: Protect your data at the front door with conditional access

Update:

After the General Availability of Azure AD Admin console few more new announcements were made for Conditional Access recently as below

The New Intune and Conditional Access Admin Consoles are GA

Ping Access for Azure AD is now Generally Available (GA)!

Azure AD Conditional Access now supports Microsoft Teams & the Azure Portal

Update:

Access the blog post below to know more on how EMS benefits today's Organization need for digital transformation and the new EMS experience after the availability of  the Unified Admin experience in Azure Portal,  that is essential for every IT Pro to increase their productivity.

Access here: Enabling a more strategic role for IT with Microsoft Enterprise Mobility + Security


Be sure to review the Microsoft Mechanics video: New unified EnterPrise Mobility + Security Management experience in the Azure Portal

Update: 

Read the below documentation to get to know how Conditional Access can be applied for Azure AD B2B users.

Read here:  Conditional access for B2B collaboration users

Update:

Access the latest Microsoft Inspire 2017 video session on the  benefits of new Conditional Access: Identity-driven security through conditional access

Update:

Beginning August 9, accessing the authenticated Office 365 home page (either through https://portal.office.com or https://www.office.com) will require that your users satisfy the Azure Active Directory Premium Conditional Access policies that you have applied to either Exchange Online or SharePoint Online.

Read here to know more: Changes to authentication requirements for the Office 365 home page Conversation Options

Microsoft team has changed the dates for the Roll-out plan of the above changes and now its planned for August 24th  as per the Official Announcement made in the Enterprise Mobility and Security Blog.

Access the Official Announcement here: An update to Azure AD Conditional Access for Office.com

Update:

Azure Active Directory Conditional Access support now available for macOS in Public Preview

With the public preview of macOS device-based conditional access, you’ll be able to:
  • Enroll and manage macOS devices using Intune
  • Ensure macOS devices adhere to your organization’s compliance policies
  • Restrict access to applications in Azure AD to only compliant macOS devices
Access the Official announcement here: Azure AD and Intune now support macOS in conditional access!

Get to know the current issue exist with macOS Conditional Access Preview here: Support Tip: Known issue in macOS Conditional Access Preview

Be sure to follow the Microsoft Intune Support Team Blog blog for latest updates.

Update:

Learn how to use Conditional Access in Azure Active Directory (Azure AD) to restrict how Microsoft Teams is accessed by your users.

Microsoft Teams: Restrict Usage with Azure AD Conditional Access

Update:

Before you implement Conditional access Policies in your environment, you can now use the new  "What If " tool understand the impact of the policies on a user sign-in, under conditions you specify

Public preview: “What If” tool for Azure AD Conditional Access policies

Update:

Frequent questions about using Conditional Access to secure remote access

Stay tuned for more updates...

Tuesday, May 30, 2017

Azure AD Admin Console is GA!

Azure Active Directory Admin Console (in the new Azure portal) is now Generally Available


Access http://aad.portal.azure.com for the new experience.

Microsoft team already Migrated the Admin console from the classic portal to the new Azure Portal, and now this new portal presents information about your Organization with a better view and ease of navigation.

Most importantly, The new portal does not require an Azure subscription, which streamlines access, especially for Office 365 admins, whose lives will be made easier with the new group-based licensing functionality.

Access the below Official Blog post to know more: The new Azure AD Admin Console is GA!

Share your feedback in for further improvements.


Monday, May 01, 2017

Ultimate Guide to Windows Server 2016 e-Book

As most of the Organizations today are moving towards the Hybrid Cloud, and if you are in the process of evaluating a hybrid environment, a great place to start is Windows Server 2016. It takes all of the learnings from Microsoft Azure and builds it into your on-premises datacenter operating system. It provides added layers of security and new, streamlined deployments options. It also perfectly sets you up for a transition to hybrid cloud when you are ready.


Access the e-book here to know more :  Ultimate Guide to Windows Server 2016

Read the Hybrid Cloud Blog regularly and stay updated.