Quantcast
Channel: TechNet Blogs
Viewing all 34890 articles
Browse latest View live

無線 LAN プロファイルをグループ ポリシー利用して配布する手順について

$
0
0

皆様、こんにちは。Windows プラットフォーム サポート担当の永谷です。

 

今回は "無線 LAN プロファイル  (接続するための設定) をグループ ポリシー (以後 : GPOと表記) を利用して

ドメイン クライアントへ配布する手順" を紹介します。

これまで手動で端末ごとに無線 LAN プロファイルを設定頂いていた方も、

これを機に GPO のご利用についても併せてご検討ください。

 

- 対象の環境

・ 無線 LAN 接続に、Windows 標準の無線 LAN サプリカントを利用している

・ ドメイン に参加しており GPO の適用が可能な無線 LAN クライアント

 

- Blog 内で設定する内容

認証方式に EAP-TLS を利用しコンピューターのクライアント証明書を利用して RADIUS 認証を実施する設定を実施。

 

★ 具体的な設定は下記の通りです。

-----------------------------

ポリシー名 : wlan

プロファイル名 : testssid

接続先 SSID : testssid

 

自動接続 : はい

ステルス SSID を利用 : いいえ

認証 : WPA2-エンタープライズ

暗号化 : AES

ネットワークの認証方法 : EAP-TLS

認証モード : コンピューターの認証

-----------------------------

 

上記の設定をご利用いただく場合、事前にクライアントに EAP の要件を満たした

コンピューター証明書をインポートしておく必要がございます。

 

タイトル : PEAP および EAP の証明書の要件

URL : https://technet.microsoft.com/ja-jp/library/cc731363(v=ws.11).aspx

 

===============================

設定方法 (Windows Server 2012 R2 を利用した場合)

===============================

 

ドメイン クライアントに対して無線 LAN プロファイル する場合はグループポリシーを利用した方法を使用し、設定を行う事が可能です。

 

1. ドメイン コントローラーでグループポリシーの管理を起動します

2. グループ ポリシーを適用したい任意の OU 等を右クリックし、[このドメインに GPO を作成し、このコンテナにリンクする] を選択します。

3. 任意の GPO 名を入力し OK をクリックします。

4. 作成された GPO を右クリックし、編集 をクリックします。

5. 以下のパスを展開し、[Windows Vista 以降のリリース用の新しいワイヤレス ネットワーク ポリシーの作成] をクリックします。

 

コンピュータの構成

  ポリシー

      Windows の設定

         セキュリティの設定

             ワイヤレス ネットワーク (IEEE 802.1) ポリシー

 

6. [以下のプロファイルの順序で利用できるネットワークに接続します" 下部の [追加] をクリックします。

7. プロファイル名を入力します。

8. ネットワーク名 (SSID) を入力し、右の [追加] をクリックください。

この時点で以下のように表示されている事をご確認ください。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

9. 続けて [セキュリティ] タブをクリックします。

10. [ネットワークの認証方法の選択] にて "Microsoft : スマート カードまたはその他証明書" を選択します。

11. 続けて [認証モード] より "コンピューター認証" を選択します。

この時点で以下のように表示されている事をご確認ください。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

12. 設定に間違いがなければ [OK] をクリックします。

13. "ネットワークのアクセス許可" タブを開きます。

以下のように構成されていれば特に変更頂く必要はございません。

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

14. [OK] ボタンをクリックし、プロパティ画面を閉じます。

15. Windows のドメイン クライアントを再起動するか、

管理者ユーザーで起動したコマンド プロンプトにて gpupdate /force を実行し、グループ ポリシーを適用します。

 

★ 次回は無線 LAN クライアントを特定の SSID にしか繋げさせない場合の設定方法をご案内予定です。

 

特記事項

本情報の内容(添付文書、リンク先などを含む)は、作成日時点でのものであり、予告なく変更される場合があります。

 


Office 365 Weekly Digest | April 22 – 28, 2018

$
0
0

Welcome to the April 22 - 28, 2018 edition of the Office 365 Weekly Digest.

Only a few additions to the Office 365 Roadmap from last week, including public anonymous external video sharing coming to Microsoft Stream in Q4 CY2018, as well as naming conventions in Office 365 targeted for release in May 2018. There was also one cancellation – In product messaging in the Service Health dashboard.

In addition to the ongoing customer online immersion experience events, there are a couple of new events including a free educator-focused webinar for Microsoft Teams and a webcast on safeguarding individual privacy rights with the Microsoft Cloud..

Lots of content in the Blog Roundup including posts on new and upcoming capabilities in Microsoft 365, improvements to the Planner tab in Microsoft Teams, an increase in SharePoint Online storage, updates to the Office Customization Tool for Click-to-Run, new sharing and collaboration features for OneDrive on Mac, iOS and Android. In addition, MyAnalytics has added new features and resources and Microsoft Forms is now enterprise ready.

Wrapping up the post are noteworthy items on recent updates to Office for Windows, Mac and iOS, a white paper on Office 365 Encryption options, an increase of the public folder limit in Exchange Online to 500,000 folders and a new date for discontinuation of support for Session Boder Controllers in Exchange Online Unified Messaging.

 

OFFICE 365 ROADMAP

 

Below are the items added to the Office 365 Roadmap last week:

 

Feature ID

Title Description

Status

Added

Estimated Release

More Info

27728

Microsoft Stream: Public anonymous external video sharing Allow individual videos in Microsoft Stream to be marked for external public access allowing the video to be embeded in a public website. Anyone in the world can view these external videos without a login. Stream admins will be able to control if this feature is enabled and who within the organization can make videos publicly available.

In development

04/26/2018

Q4 CY2018

n / a

27740

SharePoint web part: Weather Site owners and members will now be able to show the current weather on their site home page, within subpages and/or within a news article on team sites, communication sites and hub sites. Simply add the web part to your page or news, add a location and select from Fahrenheit or Celsius (°F or °C). The web part pulls up-to-date information from MSN Weather.

In development

04/26/2018

May CY2018

n / a

27769

Naming conventions in Office 365 Admins will have the ability to set up rules around how an Office 365 group is named and will be able to block certain types of words from being included in a group name.

In development

04/27/2018

May CY2018

n / a

15064

Service Health Dashboard Update: in product messaging We're adding enhancements to the Service Health Dashboard in the Office 365 admin center:  In product messaging —The new Service health dashboard will enable you to make your end users aware of service incidents and inform them about possible workaround solutions through optional in product notifications.

Cancelled

06/13/2017

Q4 CY2018

Announcing a new Service Health dashboard

 

 

UPCOMING EVENTS

 

Microsoft Learning Consultants: 6 Steps for building a collaborative classroom with Microsoft Teams

When: Tuesday, May 1, 2018 at 5pm ET | This free webinar is hosted by educators and tailored for educators. In this webinar learn how Office 365 tools like Teams can help you facilitate content creation, collaborative classrooms, and personalized learning in a digital hub experience. Be sure to check out our additional free spring webinars in May and June.

 

Productivity Hacks to Save Time & Simplify Workflows

When: Wednesday, May 2, 2018 and Wednesday, May 9, 2018 at 1pm ET | This 90-minute hands-on experience will give you the opportunity to test drive Windows 10, Office 365 and Dynamics 365. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Discover how you can keep your information more secure without inhibiting your workflow, (2) Learn how to visualize and analyze complex data, quickly zeroing in on the insights you need, (3) See how multiple team members can access, edit and review documents simultaneously, and (4) Gain skills that will save you time and simplify your workflow immediately. Each session is limited to 12 participants, reserve your seat now.

 

Transforming your business to meet the changing market and needs of your customers

When: Thursday, May 3, 2018 at 12pm and 3pm ET | This 2-hour hands-on experience will give you the opportunity to test drive Windows 10, Office 365 and Dynamics 365. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Use digital intelligence to build personalized experiences across all customer touchpoints, (2) Improve customer service through a single, unified experience that delivers end-to-end service across every channel, (3) Increase customer satisfaction with intelligent scheduling, native mobile support, and remote asset monitoring to help you get the job done right the first time, and (4) Run your project-based business more productively by bringing people, processes, and automation technology together through a unified experience. Each session is limited to 12 participants, reserve your seat now.

 

Visualizing, Analyzing & Sharing Your Data Without Having to be a BI Expert

When: Tuesday, May 8, 2018 and Tuesday, May 29, 2018 at 12pm ET | This 2-hour hands-on experience will give you the opportunity to test drive the latest business analytics tools. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they can work throughout your organization. During this interactive session, you will explore how to: (1) Locate and organize large amounts of data from multiple sources, (2) Visualize complex data and identify trends quickly without having to be a BI expert, (3) Find and collaborate with company experts on the fly, even if they work in another part of the country, and (4) Gather colleague's opinions easily and eliminate communication and process bottlenecks. Each session is limited to 12 participants, reserve your seat now.

 

Hands-on with security in a cloud-first, mobile-first world

When: Thursday, May 10, 2018 at 12pm and 3pm ET | This 2-hour hands-on session will give you the opportunity to try Microsoft technology that secures your digital transformation with a comprehensive platform, unique intelligence, and partnerships. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will: (1) Detect and protect against external threats by monitoring, reporting and analyzing activity to react promptly to provide organization security, (2) Protect your information and reduce the risk of data loss, (3) Provide peace of mind with controls and visibility for industry-verified conformity with global standards in compliance, (4) Protect your users and their accounts, and (5) Support your organization with enhanced privacy and compliance to meet the General Data Protection Regulation. Each session is limited to 12 participants, reserve your seat now.

 

Connecting, Organizing & Collaborating with Your Team

When: Tuesday, May 15, 2018 and Tuesday, May 22, 2018 at 12pm ET | During this session, you will have the opportunity to experience Windows 10, Office 365 and Microsoft's newest collaboration tool: Microsoft Teams. A trained facilitator will guide you as you apply these tools to your own business scenarios and see how they work for you. During this interactive session, you will explore how to use Microsoft Teams and Office 365 to: (1) Create a hub for team work that works together with your other Office 365 apps, (2) Build customized options for each team, (3) Keep everyone on your team engaged, (4) Coauthor and share content quickly, and (5) Gain skills that will save you time and simplify your workflow immediately. Each session is limited to 12 participants, reserve your seat now.

 

Safeguarding individual privacy rights with the Microsoft Cloud

When: Friday, May 25, 2018 from 3:00pm – 5:00pm ET | Join Alym Rayani, Director of Microsoft 365, for our May 25 webcast where he will: (1) Show how you can use GDPR fundamentals to assess and manage your compliance risk, (2) Discuss how you can help protect your customers' data with built-in, intelligent security capabilities, and (3) Cover how you can meet your own compliance obligations by streamlining your processes.

 

BLOG ROUNDUP

 

Making IT simpler with a modern workplace

There is a simple way to explain one of the biggest threats to any organization's infrastructure. It's just one word: complexity. Complexity is the absolute enemy of security and productivity. The simpler you can make your productivity and security solutions, the easier it will be for IT to manage and secure—making the user experience that much more elegant and useful. We've learned from building and running over 200 global cloud services that a truly modern and truly secure service is a simple one. Microsoft 365 is built to help you solve this problem of complexity so that you can simplify. But let me be clear, simpler doesn't mean less robust or less capable. From thousands of conversations with customers, we heard clearly how important it is for IT to simplify the way it enables users across PCs, mobile devices, cloud services, and on-premises apps. Microsoft 365 provides that all with an integrated solution that's simpler, yet also more powerful and intelligent. Because the way you work and do business is so important to us, our work will never be done—we will constantly innovate, improve, and discover new and better ways to help your organization do more. We are excited to announce some new capabilities and updates coming soon to Microsoft 365, including: (1) A modern desktop, (2) Solutions for Firstline Workers, (3) Streamlined device management with lower costs, (4) Integrated administration experience, and (5) Built-in compliance. Each of these new capabilities will allow you to simplify your modern workplace, which means delighting and empowering your users, while enabling IT to protect and secure the corporate assets.

 

Planner tab in Microsoft Teams now includes the Schedule view and Charts view

When we released the first version of the Planner tab in Teams, we noted that our goal was to support the same feature set in Teams as we do in the Planner web app. We recently took another step towards our goal and have completed the roll out of a few more popular features from the web: (1) Schedule view - get an overview of upcoming tasks and drag and drop them to set dates, (2) Charts view - stay up to date on the status of your plans, and (3) Filter and Group by options - focus on key tasks and group by Assigned To, Progress, Due Date, and Labels. For more information about using Planner in Teams, check out this article.

 

Increase in SharePoint Online storage allocation

Global digital transformation is driving growth across Microsoft 365 and SharePoint as organizations invest in technology to empower employees to do their best work. More than 350,000 organizations now have SharePoint and the data they are storing over doubled last year alone. We're hearing customers want to put even more content into SharePoint to take advantage of new team collaboration and enterprise content management experiences, while moving off on-premise servers, file shares, and 3rd party cloud offerings. We are announcing a 20x increase in the SharePoint Online per user license storage allocation. This will increase to 1 TB plus 10 GB per user license purchased, up from 1 TB plus .5 GB per user license purchased. Note this does not include SharePoint Online kiosk plans including Office 365 F1 and Microsoft 365 F1. All Office 365 services that use SharePoint for content services, including Microsoft Teams and Office 365 Groups, will benefit from this substantial storage increase. This change will start rolling out on July 1, 2018 and will be completed by the end of August 2018. Once complete, you'll see this increased storage in your SharePoint Online admin center. If you are currently paying for additional storage you can decrease this as needed after this change is reflected in your tenant. | Resource: SharePoint and OneDrive Security and Compliance Resource Center

 

Setting preferences for Office 365 ProPlus using the Office Customization Tool for Click-to-Run

We are announcing a preview update to the Office Customization Tool for Click-to-Run, which provides desktop admins with a simple user interface to customize their deployment of Office. With this update, you can now customize Office application settings as part of your configuration file, which means you can build a single configuration file that installs Office and configures preferences for Office applications. You can search for Office application settings based on Office application, category, and title to quickly find the settings you're interested in. For this preview release, we've provided a limited set of Office application settings to choose from. We plan to include the full set of application settings later this summer. In addition to application settings, we have been listening to your feedback and since we introduced the Office Customization Tool for Click-to-Run we have made a few changes to the preview experience; adding Organization Name as a setting that is included as part of the deployment configuration, an update to the language selection experience, and an update to the Automatically accept the EULA option. In our next update we plan to add many additional enhancements including: an update to the product selection experience to allow you to have more control over the products you can select from and the apps that you exclude, an update to the language selection experience including support for MatchOS, AllowCdnFallback, Proofing Tools and more. As always, make sure you download the latest version of the Office Deployment Tool (ODT) to enable this new feature during deployment.

 

OneDrive Brings New Sharing and Collaboration Features to Mac, iOS and Android

Over the past year, we have worked hard to bring new sharing features to OneDrive and SharePoint, including real-time collaboration for Office for Mac as well as to iOS and Android. We have several announcements that reinforce our commitment to deliver a first-class experience to our Mac, iOS and Android users. We consistently hear that users are more confident and comfortable sharing files when given a simple, consistent experience across their devices. Over the past year, we've focused on delivering that with a unified sharing experience to Office, OneDrive, and SharePoint across desktop and web. Now, we take our next step in that journey by bringing the same, successful sharing experience that you currently see in our other clients to our OneDrive app for iOS and Android. This feature is available now for Android users and is currently rolling out for iOS users so, make sure to keep your OneDrive app updated to the latest version when prompted. There are also new updates for Mac Office users. The OneDrive client for Mac will now be part of the Office 2016 for Mac Click-to-Run installer. This means that the OneDrive standalone client will be automatically installed as part of your Office installations rather than having to install it separately. For customers currently running the Mac App Store version, OneDrive will now automatically migrate your settings to the standalone version. Finally, this update will also bring requested functionality to the Mac OneDrive client: Office for Mac will work with OneDrive to intelligently open your files locally if it has already synced the file rather than download a new copy, so your files will open much more quickly. We will announce more features and functionality coming to our customers in May at the SharePoint Conference North America.

 

New in MyAnalytics: manager 1:1 insights, adoption resources, and shortened onboarding time

As the demands on our time at work grow, MyAnalytics helps people get back in control and build better work habits. This month, we're excited to announce the following updates and releases: (1) Manager 1:1 insights, (2) New user adoption resources, and (3) Shortened onboarding time. Manager 1:1 insights will surface in the MyAnalytics personal dashboard when you've gone 3 or more weeks since your last 1:1 with your manager, with a friendly tip to book a 30-minute check-in. If you're a manager, you'll also see a similar insight if you've gone 3+ weeks without booking a 1:1 with one of your direct reports. Managerial relationships are determined using Azure Active Directory. Our new adoption resources will help map out a path in advance and include resources for individuals and teams. The MyAnalytics onboarding process is now faster than ever. Within 3 days of being assigned a MyAnalytics license by their Office 365 Administrator, users will receive a "Welcome to MyAnalytics" email and have access to their personal dashboard and Outlook add-in. The personal dashboard will populate 80 days retroactively, assuming the user has been active on Exchange Online for that duration. Users will receive a weekly email digest starting on the first Monday after the Welcome email sends.

 

Microsoft Forms is Enterprise Ready now!

We are excited to announce that Microsoft Forms, a simple app for creating surveys, quizzes, and polls, is generally available to all Office 365 commercial customers. Used by more than 3 million users in education, Forms was brought to commercial preview by customer demand last year. Thanks to more than 50,000 companies participating in the Preview program, Microsoft Forms is now enterprise ready, and, hence, we are removing the "Preview" label. With Microsoft Forms, your employees can easily solicit client input, measure customer satisfaction, and organize team events, within minutes. The app is simple to use and works on any web browser, so it can be accessed from anywhere, anytime. With real time responses and automatic charts built in, Microsoft Forms makes it easy to understand the data right away. And for companies that want to custom brand their surveys, Forms supports the addition of themes, logo, and images. We also know that many users work in teams, so users can collaborate on a single form. Forms can be used within applications you know and love, such as Excel, SharePoint, Teams, Flow, and Sway. Most recently, Microsoft Forms added many features that enterprises requested, such as SOC compliance, ability for IT admins to manage user licenses, and controls to enable sharing of Forms outside of their organization. For more complex surveys, we also added support question branching and Likert scales, plus an ability to collect 50,000 survey responses per form.

 

NOTEWORTHY

 

Office 365 for Windows Desktop – April 2018 Release details

On April 25th, 2018, Microsoft released Office for Windows Desktop version 1804 (Build 9226.xxxx). Our Office International team translated this update into 44 languages. Here are a few of the new features that are included in this release: (1) In PowerPoint convert your ink to text or shapes, (2) Listen to your emails in Outlook, (3) Encrypt option in Outlook using Office 365 Message Encryption, (4) Task board filtering in Project, and (5) Find and fix proofing issues in your language in Word. More information and help content on this release can be found in the What's New in Office 365 page.

 

Office for MAC 2016 - April 2018 Release details

On April 11th, 2018, Microsoft released Office 2016 for Mac Version 16.12 (Build 180410) in 27 languages. Our Office International team was responsible for translating this release. There are several new features in Outlook including a more actionable calendar and the ability for delegates to schedule Skype for Business Online meetings on behalf of principals using principals' email addresses. Also, in most client applications including Excel, Outlook, PowerPoint and Word you can now insert and edit Scalable Vector Graphics. In addition, locally synced OneDrive documents open directly from the cloud, allowing users to AutoSave, share, and collaborate easily. More information and help content on this release can be found in the MAC section of the What's New in Office 365 page.

 

Office 365 for iPad & iPhone - April 2018 release details

On April 9th, 2018, Microsoft released an updated version of Office for iPad & iPhone to Office 365 subscribers - Version 2.12 (18040200) in 35 languages. Our Office International team translated this release. Here are some of the new features included this month in Excel, PowerPoint and Word: (1) Rotate, resize, and add color to SVG images in your documents, worksheets, and presentations to better convey your ideas, (2) Perform common calculations in Excel on a selected range of data using functions, and (3) In Excel, have quick access to contextual commands like expand selection, sort, filter, and more! More information and help content on this release can be found in the iOS section of the What's New in Office 365 page.

 

Using encryption in Office 365 to help protect data and meet your compliance needs

With digital data growing exponentially, and threats becoming more advanced, laws and regulations are evolving to protect individuals and their personal information. Encryption is one method that can be used to help ensure the confidentiality of certain sensitive information, reduce the risk of data compromise and help you meet your compliance needs. When organizations use Office 365, they can expect customer data to be encrypted both in transit and at rest by default. Additional encryption capabilities can be added for increased protection. Encryption technologies available in Office 365 to help protect your data include: (1) TLS, (2) BitLocker, (3) Service Encryption, and (4) Office 365 Message Encryption. For customers who have data security or privacy requirements that are driven by compliance, Office 365 offers flexible encryption key management options to further help organizations meet their compliance needs as they move to the cloud. You can read more about these options in our white paper.

 

Announcing the increase of the Public Folder limit in Exchange Online from 250,000 to 500,000 folders

In September 2017, we officially announced the increase of the supported limit of Public Folders in Exchange Online from 100,000 to 250,000. In line with our efforts to scale Public Folders even further, we are glad to announce that Exchange Online now officially supports public folder hierarchies of up to 500K public folders in the cloud – double the previously supported limit of 250K public folders! All existing customers using Exchange Online who are currently constrained by the limit of 250K public folders, can now expand their Exchange Online public folder hierarchy up to 500K folders. Note about migrations: Exchange 2013/2016 customers can still only migrate up to 100K public folders to Exchange Online, and Exchange 2010 customers can only migrate up to 250K public folders to Exchange Online. However, once folders are migrated to Exchange Online, you can expand the hierarchy up to 500K public folders. We are working to resolve these limitations in the future.

 

New date for discontinuation of support for Session Border Controllers in Exchange Online Unified Messaging

In July 2017, we announced that support for Session Border Controllers (SBC) that connect 3rd Party PBX systems to Exchange Online Unified Messaging (UM) would be discontinued as of July 2018. After feedback from customers and partners concerned about this change, we are announcing additional time for customers to prepare. The new date for discontinuation will be April 30, 2019. Customers with existing deployments remain fully supported until this date. However, Microsoft strongly advises all customers to begin their voicemail transition now. There are different alternatives (outlined in this post) for customers currently using an on-premises PBX system that connects to Exchange Online. We recognize that customers may also choose a combination of these options for their organization. We know these changes can be challenging in the near-term. But we believe that continuing to identify areas where we can evolve the service we provide while taking full advantage of the cloud is the right answer. We will continue to evaluate emerging needs as customers make the transition from legacy dedicated voice to Microsoft's Intelligent Communications solutions. | Microsoft Tech Community Announcement


KI ist überall, Microsoft auch

$
0
0

Logbucheintrag: 190430


Wer hätte das gedacht? Vor gut einem Jahr war künstliche Intelligenz noch ein Randthema, das lediglich große Organisationen mit hohem Automatisierungsbedarf interessierte. Sprachassistenten wurden zwar auf dem Smartphone intensiv genutzt. Aber den wenigsten war dabei bewusst, dass sie einen KI-Service in Anspruch nehmen, wenn sie Cortana nach dem Weg fragen oder über Bing ausgefeilte Suchalgorithmen nutzen. Jetzt steht künstliche Intelligenz ganz oben auf der Liste der Topthemen in den Unternehmen – hinter Cloud Computing, IT-Security- und IT-Service-Management und noch vor Digitalisierung und Big Data.

Das jedenfalls ergab eine Umfrage von IDG Research unter Entscheidern in europäischen Unternehmen. Und dabei gilt: Je größer die Organisation, desto weiter sind die IT-Fachleute mit der Einführung von KI-Lösungen und Machine Learning. 60 Prozent der Befragten, deren IT-Abteilungen mehr als 500 Mitarbeiter beschäftigen, haben künstliche Intelligenz schon im Einsatz – zum Teil sogar in „einer ganzen Reihe“ von Einsatzszenarien. Nicht viel anders sieht es bei Organisationen mit mehr als 100 IT-Mitarbeitern aus: Hier sind es 56 Prozent, die KI heute bereits nutzen. Erst darunter, also dort, wo kleine IT-Abteilungen die Geschäftsprozesse und IT-Ausrüstung managen, sinkt die Zahl signifikant ab: hier ist erst jeder Dritte konkret mit KI befasst.

Damit zielen wir mit der Microsoft Azure-Plattform exakt auf die Topthemen unserer Kunden. Denn von Cloud Computing über (KI-gestützte) Security-Features bis zu KI-Services aus der Cloud und schließlich unseren IoT-Angeboten Azure Central und Azure Sphere bieten wir komplette Lösungen für die digitale Agenda der CIOs. Dabei ist die Azure-Plattform voll skalierbar, so dass sowohl kleine Organisationen als auch globale Konzerne ihre maßgeschneiderten Lösungen vorfinden. Dazu tragen vor allem auch unsere weltweit 64.000 Partner bei, die sich mit eigenen Aktivitäten ein Cloud-basiertes Business aufgebaut haben und jetzt durch KI weiter ausbauen.

Es ist schon faszinierend, wie Satya Nadella Microsoft in kürzester Zeit zur wahrscheinlich relevantesten IT-Company für Unternehmen und Privatpersonen gewandelt hat. Mit der Strategie „Intelligent Cloud und Intelligent Edge“ stehen wir ganz vorne als Technologieführer und Marktführer in wichtigen Wachstumsmärkten. Nach besten Bewertungen an den Aktienmärkten wird auch unser viertes Quartal noch einmal zeigen, dass wir vor dem Wind fahren – sozusagen im Konvoi mit unseren Kunden und Partnern.

Dabei müssen wir damit leben, dass es einen erheblichen Mangel an KI-Experten gibt. Zwar beschäftigt Microsoft derzeit bereits mehr als 3000 Entwickler mit Aufgaben rund um KI-Produkte, aber wir könnten weit mehr Data Scientists, KI-Entwickler und Machine Learning-Experten gebrauchen. Das gleiche gilt für unsere Kunden und Partner. Der Mangel an Fachkräften mit diesen neuen Wissensprofilen und Spezialgebieten verhindert die rasche Einführung und Weiterentwicklung von Künstlicher Intelligenz. Zwar sagen 45 Prozent der von IDG befragten Manager, dass ihre Organisation bereits über die nötige technische Infrastruktur für KI verfügt. Doch nur 24 Prozent bestätigen zugleich, dass ihre Mitarbeiter über das nötige Expertenwissen verfügen.

Hier entsteht ein gigantischer Weiterbildungsbedarf. Denn die KI-Experten sollen nicht im Elfenbein-Turm arbeiten, sondern möglichst über kombinierte Wissensgebiete verfügen. So wollen 44 Prozent der Organisationen mit Hilfe von Machine Learning ihre internen und externen Prozesse optimieren und automatisieren. Dabei sollen vor allem Routinetätigkeiten durch KI übernommen werden. Deshalb sind KI-gestützte Assistenzsysteme und Planungswerkzeuge mit einem Einsatzgrad von jeweils 30 Prozent die wichtigsten Technologien. Dabei erwartet mehr als die Hälfte der Befragten, dass die eingesetzten KI-Systeme die Prozesse nicht nur effektiver machen, sondern disruptiv neu gestalten werden.

Und immerhin jeder vierte befürchtet, dass KI-Systeme auch dazu genutzt werden, smarte und kaum wahrnehmbare Cyber-Angriffe zu starten. Microsoft hat sich auch auf dieses Thema längst eingestellt. Azure bietet eine Vielzahl von KI-gestützten Security- und Monitoring-Funktionen, die die Cloud-Landschaft ebenso wie Hybride Strukturen sicherer und stabiler machen.

Spätestens auf der Microsoft-Entwicklerkonferenz Inspire im kommenden Juli wird es an allen KI-Fronten neue Ankündigungen geben. Denn KI ist überall. Und Microsoft ist überall vorne dabei.

Microsoft lleva la traducción impulsada por IA a usuarios finales y desarrolladores sin importar si están conectados o no

$
0
0

Microsoft Translator ha agregado nuevas capacidades que permiten a los usuarios y desarrolladores recibir traducciones impulsadas por inteligencia artificial sin importar si tienen conexión a internet o no.

Las nuevas capacidades permiten tanto a los usuarios finales como a los desarrolladores de aplicaciones de terceros, contar con el beneficio de la tecnología de traducción neural sin importar si el dispositivo está conectado o desconectado de la nube.

Al usar la aplicación de Microsoft Translator, los usuarios finales ahora pueden descargar de manera gratuita los paquetes impulsados por AI para usar sin conexión. Además, a través de la nueva característica local en versión previa de la app Translator, los desarrolladores de Android podrán integrar de manera sencilla y rápida, traducciones de texto con AI integrada, con conexión o sin ella en sus aplicaciones.

Nuevos paquetes de lenguaje sin conexión impulsados por AI para las aplicaciones de Translator para Android, iOS y Amazon Fire

El desarrollo viene después de dos años de trabajo, y complementa los esfuerzos generales de Microsoft para asegurar que los desarrolladores y usuarios puedan tener acceso a las herramientas impulsadas por IA, justo donde están sus datos, sin importar si los manejan desde la nube o en un dispositivo. Esta capacidad, a la cual los expertos se refieren como el cómputo en el entorno, surge mientras los expertos descubren maneras para correr poderosos algoritmos de AI sin el poder masivo del cómputo en la nube.

Microsoft Translator lanzó la traducción en línea de máquina neural impulsada por AI (NMT) en 2016. Debido a que el cómputo en la nube necesitaba correr estos modelos de traducción de alta calidad, esta capacidad sólo estaba disponible en línea. A finales del 2017, esta capacidad se volvió disponible en teléfonos específicos Android equipados con un chip especializado de IA. Esto permitió que sus usuarios pudieran recibir traducciones de calidad sin conexión con la misma calidad que las traducciones neurales con conexión.

Basado en este trabajo inicial, el equipo de Translator pudo optimizar aún más estos algoritmos, y permitirles funcionar directo en el CPU de cualquier dispositivo moderno sin la necesidad de tener chips especializados de IA. Estas nuevas aplicaciones de Translator llevan las NMT al entorno de la nube para todos los dispositivos Android, iOS y Amazon Fire. El soporte para los dispositivos Windows llegará pronto.

Estos nuevos paquetes de NMT producen traducciones de mayor calidad, que son hasta un 23 por ciento mejores, y son un 50 por ciento más pequeñas que los paquetes no neurales anteriores de idiomas sin conexión. Estos paquetes de NMT están disponibles en los idiomas más populares de Translator, y los nuevos lenguajes del NMT serán agregados de manera regular. Para poder tener la lista completa actualizada, por favor revisen https://translator.microsoft.com/help/articles/languages.

Nueva característica local de prueba para Translator en Android

Para los desarrolladores de Android, la aplicación de Translator ahora también ofrece una versión de prueba de la nueva característica local, la cual permite que los desarrolladores agreguen traducción de texto de una manera más rápida y sencilla a cualquier aplicación de Android que se beneficie de las capacidades de traducción.

Además, gracias a estos paquetes de NMT sin conexión, los desarrolladores de Android pueden agregar por primera vez NMT sin conexión a sus aplicaciones, los cuales permiten que sus usuarios puedan tener acceso a contenido traducido por parte del NMT sin la necesidad de una conexión a internet.

Para integrar traducción a sus aplicaciones, los desarrolladores sólo tendrán que agregar un código simple que utilizarán la tecnología de servicio vinculado de Android, a través de una interfaz AIDL para activar la aplicación de Translator de manera silenciosa. La aplicación hará el resto. Si el dispositivo está conectado a internet, la aplicación recuperará el texto traducido desde el servicio de Microsoft Translator en Azure. Si la conectividad a internet no está disponible, la aplicación de Microsoft Translator utilizará los paquetes locales de NMT de idiomas sin conexión, para proveer el texto traducido de regreso a su aplicación.

Se espera que la característica pase de versión previa a disponibilidad general, dentro de los 90 días después del lanzamiento de la versión prueba.

Cuando el dispositivo está conectado, las traducciones también pueden aprovechar los modelos de traducción personalizados que coincidan con la terminología* única de la compañía y de la aplicación.

Sin importar si la aplicación recibe traducciones con conexión o sin ella, la característica local factura la suscripción de Translator Text API* de desarrollador a través de Microsoft Cognitive Services. No hay necesidad de crear una nueva y, si la API de nube es activada de manera directa, los requerimientos no serán registrados para las traducciones con o sin conexión.

Pueden aprender más sobre cómo trabaja la característica local de prueba en nuestra documentación de GitHub y aplicación de prueba.

*Durante la prueba, algunas características pueden no estar disponibles, o pueden estar disponibles sin ningún costo. Por favor consulten las notas sobre el lanzamiento de la documentación para recibir más información.

Is Dynamics 365 in your Future?

$
0
0

Over the last several weeks, lots of announcements have been made about the products that comprise Dynamics 365, specifically around Dynamics 365 Business Central. And I know we’ve been promoting this product line to you over the last several years. Your question: “Is it time that I look at what Dynamics 365 has to offer my infrastructure business?”

In a word: “YES!”

I see the pieces coming together: appropriate products and roadmap, competitive pricing, and easy availability.

One of my co-workers, Craig Crescas, is about to start a three city roadshow (San Diego, Chicago, New York) (https://blogs.technet.microsoft.com/uspartner_ts2team/2018/04/17/attend-one-of-the-upcoming-microsoft-dynamics-365-business-central-roadshows/)

and he just finished a four part webcast (https://msuspartner.eventbuilder.com/?landingpageid=u200VK)

And today, we are letting you know about another, upcoming, webcast series:

image

As a Microsoft Partner, adding Microsoft Dynamics 365 solutions to your current offerings can help turn your customer relationships into increased revenue and profitability. Join us in this three-part series where the Partner Technology Strategists and Architects will provide sophisticated demos of Dynamics 365 Sales, Customer Service, and Marketing. These demos will go in-depth on new product functionality, customer based scenarios, and steps on how to prepare a demo environment.

REGISTER NOW!

By adding Dynamics 365 to your portfolio you will also have the opportunity to earn customers for life with your ability to add your managed services and future Dynamics 365 modules to your customer offerings. Join us to see the potential Dynamics 365 can bring to your business.

In addition, they will show you demo tools and resources available to support your organization’s go to market strategy while reducing your cost of sale.

We look forward to have you join us for all three events!

Trying to attend all of these events is a HUGE investment of time, but attending one of these events is an appropriate investment in your future.

SDeming 2017  Steve

Tip of the Day: Windows 10 April 2018 Update

Tip of the Day: Features Removed or Planned for Replacement starting with Windows 10, version 1803

$
0
0

Today's tip...

Each release of Windows 10 adds new features and functionality; we also occasionally remove features and functionality, usually because we've added a better option. Here are the details about the features and functionalities that we removed in Windows 10, version 1803 (also called Windows 10 April 2018 Update).

Reference: “Features removed or planned for replacement starting with Windows 10, version 1803” - https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-1803-removed-features

Tip of the Day: Help me choose

$
0
0

Today's tip...

Here’s a great tool that anyone can use to:

  • Shop for a new Windows 10 PC - Let’s you pick you devices based on what you plan to use it for and any special features you want to use.
  • Get Windows 10 – Let’s you pick between Home, School/Education, and Business versions. Also recommends new devices if yours is getting up there in age.
  • Check for Windows 10 updates – Quickly lets you know if you are up to date or if you need a bit of patching.
  • Learn more about Windows 10 Features – Currently showing you all of the cool features in the Windows 10 April 2018 Update.

Check it out and forward this along to your friends and family!

Reference: “Help me choose” - https://www.microsoft.com/en-us/windows/get-windows-10


Il Cloud (Microsoft) quale acceleratore della compliance GDPR – 2a parte

$
0
0

Nello scorso blog post vi avevo lasciato con una domanda che qui riprendo:

dal momento che il contratto cloud di Microsoft include già le tutele contrattuali necessarie, posso dire quindi di aver già soddisfatto tutti i requisiti di conformità GDPR nell'utilizzo di tali servizi ?

Per comprendere in quale misura le tutele contrattuali siano in grado di coprire i requisiti di conformità GDPR nel caso di servizi cloud è necessario rifarsi allo schema classico del NIST che descrive le varie tipologie di cloud pubblico possibili:


In questo schema, valorizzato in alto nel contesto delle soluzioni Microsoft, si potrà riconoscere come varia il livello di corresponsabilità operativa quando ci si sposta da uno scenario puro on-premise a sinistra (dove tutto è gestito dal cliente), via via verso modelli di cloud che fanno aumentare l'ambito operativo in carico al Cloud Service Provider (CSP), dove il modello di tipo Software as a Service (SaaS) a destra è quello più estremo in cui potrà apparire che sia quasi tutto in carico al CSP, e quindi Microsoft.

Se ci riflettete, questo modello di corresponsabilità operativa che varia in base al tipo di servizio cloud, si può leggere anche per chiarire come variano le tutele contrattuali che un CSP è in grado di fornire: maggiore è la responsabilità operativa, maggiore la responsabilità anche ai fini compliance (vedi riquadro rosso nella figura che segue):


Ma è bene aver chiaro che (attenzione, questo è il punto cruciale di questa spiegazione!) questo ambito di cui stiamo parlando è solo il primo dei possibili livelli su cui è necessario introdurre dei controlli di sicurezza per garantire una adeguata protezione del dato quando si considera l'utilizzo di servizi in cloud (come ricorda la nota "(1)-Cloud Security Level" che ho riportato in basso a destra nell'immagine che ho appena riportato).

Quali sono gli altri livelli? Ecco, schematizzando una interazione tra un endpoint (un PC, un tablet, uno smartphone, un dispositivo IoT, etc..) ed un servizio applicativo in cloud, questo di seguito potrebbe essere un modello che vi fa apprezzare quanti altri livelli di sicurezza vanno considerati:


Il primo livello di cui detto è solo quello relativo all'infrastruttura cloud realizzata per offrire l'applicazione considerata: per questo livello vale quanto già detto, ossia più il tipo di cloud è verso il SaaS, maggiore è la responsabilità operativa (e di compliance) in carico al CSP.

E' però fondamentale riconoscere che esiste un ambito intermedio che permette l'interazione tra l'endpoint e l'applicazione cloud che va considerato come ulteriore anello da mettere in sicurezza.

Nel contesto delle soluzioni Microsoft ho ritenuto utile distinguere questo ambito intermedio in due livelli:

  • Livello 2: sono le funzionalità di sicurezza native della stessa applicazione cloud di interesse. Disponibili come parte della stessa applicazione, ma con attivazione e gestione ancora a carico del cliente.
  • Livello 3: sono soluzioni di sicurezza di infrastruttura, offerte come soluzioni aggiuntive che sta al cliente valutare, ed eventualmente acquisire ed attivare.

Ultimo, ma non meno importante, bisogna ricordare che non si può tralasciare di rafforzare la sicurezza dell'endpoint.

Facciamo un esempio pratico per farvi ritrovare con applicazioni e soluzioni reali: supponiamo che la "Cloud Application" sia Exchange Online come parte della suite Microsoft Office 365.

Il Livello 1 è l'infrastruttura cloud Microsoft per offrirvi la soluzione di posta in cloud, su cui – in quanto SaaS – la quasi totalità della gestione operativa e quindi delle tutele compliance è di Microsoft. Sta a Microsoft documentare quanto bene si operi la gestione di tale livello per garantire un trattamento a norma.

Il Livello 2 è rappresentato dalle funzionalità di sicurezza (Identity Protection, Information Protection, Threat Protection, etc) incluse nativamente in Office 365/Exchange Online. In ambito clienti medio-grandi, queste variano in base ai piani di licenza Enterprise: maggiore il livello di licenza/piano Enterprise, maggiori le funzionalità incluse.

Prendiamo in esame la funzionalità di autenticazione per accedere alla casella di posta: normalmente i clienti realizzano una federazione di identità per riutilizzare l'identità e le credenziali on-premise di Active Directory per accedere in Single Sign-On (SSO) alla casella ospitata sul cloud.

In questo caso la robustezza dell'accesso alla casella di posta è legata a quanto sia protetta l'identità on-premise e quanto sia robusta la relativa password: il governo di questo anello della catena di sicurezza è ancora in carico al cliente nonostante la casella sia ospitata sul cloud Microsoft!!

Continuando con l'esempio, se il cliente disponesse di piani di licenza Office 365 E3, avrebbe a disposizione delle funzionalità di Multi-Factor Authentication (MFA) per rendere più robusto l'accesso alla posta (tramite l'uso di un cellulare che può ricevere il secondo fattore di autenticazione, come quando accediamo al conto corrente bancario online): decidere se usare questa funzionalità ed attivarla, è ancora una prerogativa in carico al cliente! (quindi ancora una sua responsabilità in ottica compliance/GDPR)

Le funzionalità MFA incluse in Office 365 E3 permettono di essere applicate come singolo interruttore ON/OFF per tutti gli utenti e per tutte le applicazioni della suite (Exchange, Sharepoint, Onedrive for Business, Skype for Business, etc…) senza possibilità granulare di attivazione per singolo utente/gruppo o per singola applicazione: è solo con l'utilizzo di una soluzione di livello 3, Azure MFA (acquisibile singolarmente o come parte della suite di soluzioni di sicurezza denominata Enterprise Mobility & Security (EMS)), che è possibile guadagnare la massima capacità funzionale e in particolare la granularità di poter abilitare l'MFA solo per alcuni utenti/gruppi o solo per alcune applicazioni.

Decidere se adottare tale soluzione per rispondere al meglio ad alcuni requisiti compliance/GDPR è ancora una prerogativa del cliente!!

Come lo è anche decidere le soluzioni di sicurezza da implementare a livello di endpoint: cosa dite, ai fini compliance/GDPR è la stessa cosa decidere di mantenere i client su Windows XP (ormai non più supportato e quindi non più protetto dagli aggiornamenti di sicurezza), o evolvere verso il recente e quindi più robusto/aggiornato Windows 10??

Se quindi applicassimo il modello di sicurezza che vi ho appena proposto (in presenza di una applicazione cloud) allo scenario di esempio della produttività personale con soluzioni Microsoft, questo sarebbe il risultato corrispondente:


La suite di soluzioni Microsoft 365 (che racchiude licenze e relative funzionalità di Windows, EMS ed Office 365) è in grado quindi di offrire sia le tutele contrattuali dovute in quanto soluzioni cloud (livello 1) sia di offrire le soluzioni tecnologiche necessarie per mettere in sicurezza il trattamento del dato sugli ulteriori livelli (Livello 2, livello 3, livello Endpoint) che serve comunque indirizzare per un adeguata gestione del rischio.

Vi lascio con una considerazione per permettervi di fare un confronto con le altre soluzioni cloud sul mercato: tutti i Cloud Service Provider dovranno offrirvi (entro il 25 maggio) le tutele contrattuali GDPR per il livello 1, ma quanti sono in grado di offrirvi anche un insieme di soluzioni di sicurezza che si integrino tra di loro nel modo migliore possibile e verso le soluzioni on-premise per mettere in sicurezza gli altri livelli??

E per il confronto con le soluzioni totalmente on-premise? Nel caso di scenario puro on-premise tutta la catena di controlli e quindi di tutele tecnico-organizzative è solo in carico al cliente con tutto quello che ne consegue in termini di costi e tempi… mentre le soluzioni cloud, che – ripeto – devono essere contrattualmente conformi alla GDPR, permettono sia di "trasferire" una parte della gestione e quindi del rischio e di realizzare soluzioni di protezione in modo significativamente più rapido ed efficace di quanto si possa fare on-premise.

Ecco perché il Cloud, e solo quello Microsoft (per la capacità distintiva di offrirvi anche soluzioni di sicurezza di infrastruttura integrate tra loro), è a tutti gli effetti considerabile quale acceleratore della compliance (sia in generale che quella GDPR, nello specifico di questo momento storico), e questa a sua volta in grado di poter agire da acceleratore per la trasformazione digitale tanto necessaria e finora spesso frenata proprio dalle perplessità sul cloud nei confronti della conformità normativa.

Ai prossimi post il compito di illustrarvi questo insieme davvero ricco di funzionalità di sicurezza incluse in Microsoft 365.

 

P.S. ricordo il post che agirà da sommario di tutti i miei post a tema GDPR:

A presto!

 Feliciano

@felicianointini
(mostly in Italian – technical & non technical tweets)


@NonSoloSecurity
(English only – technical only)


 

The May Partner Insider call is this Wednesday!

$
0
0

Todd Sweetser

The May Partner Insider call is this Wednesday!

Join the Microsoft US team for the Partner Insider call this Wednesday, May 2, 2018 where you’ll get valuable, actionable information to help your Microsoft business grow.

May Agenda:

  • Insider Scoop | Melody Chen, Partner Channel Marketing Manager will cover events, training, offers in market and more
  • Office 365 Business Apps | Jimmy Ward, Senior Product Marketing Manager will walk you through the Business apps for SMBs, give a demo and talk about the partner opportunity
  • Solution Areas Plays | Jose Gomez Cueto Director, One Commercial Partner, Go to Market, will share new resources to help your customers achieve digital transformation

STAY IN THE KNOW

We look forward to you joining us on the May 2 Partner Insider call!

Tip of the Day: How to get the Windows 10 April 2018 Update

Support-Info: (PCNS): PCNS is not sending passwords to the Synchronization Service Engine

$
0
0

 

PRODUCTS / COMPONENTS INVOLVED

  • Microsoft Identity Manager 2016 Service Pack 1
    • Password Change Notification Service (PCNS)

PROBLEM SCENARIO DESCRIPTION

  • Passwords are not being replicated to the Target Domain

NOTE

If passwords are not making it from the Source Domain Controller to the Synchronization Service Manager GUI, enable verbose logging and see if you are getting an Event ID 6025 in the Application Event Log.

PCNS: Troubleshooting Event ID 6025: https://social.technet.microsoft.com/wiki/contents/articles/4159.pcns-troubleshooting-event-id-6025.aspx

CAUSE

  • Password Synchronization was not enabled in the Synchronization Service Manager GUI
    • Enable Password Synchronization  in Tools > Options was not enabled (checked)
  • Source and Target Management Agents were not setup

Source - Configure Directory Partitions

  • Target - Configure Extensions

RESOLUTION

  • Enable the Enable Password Synchronization option in Tools > Options
  • Enable the Source Management Agent on Configure Directory Partitions
  • Enable the Target Management Agent on Configure Extensions

  ADDITIONAL INFORMATION

Support-Info: (GROUP MANAGEMENT): Group information is not being synchronized to/from Active Directory

$
0
0

PRODUCTS / SOLUTIONS / FEATURES INVOLVED

  • Microsoft Identity Manager 2016 Service Pack 1
    • Group Management

PROBLEM SCENARIO DESCRIPTION

  • This issue centered around Group Management.  We were not seeing Security and/or Distribution Groups be synchronized correctly through the Synchronization Engine.

CAUSE

From Portal to Active Directory

  • We noticed that the Provisioning Synchronization Rules for Security Groups were not being applied.
  • In review of the Outbound Synchronization Rule, the Scope was set to "GroupType" instead of "Type"

From Active Directory to Portal

  • FIM Service Management Agent was missing Export Attribute Flow (EAF) for member

RESOLUTION - FROM PORTAL TO ACTIVE DIRECTORY

  1. Update the Scope on the Group Outbound Synchronization Rule
    1. Set the Scope to reference the Metaverse Attribute "Type"
    2. Updated the DN on the Outbound Attribute Flow tab to ensure that it referenced an OU that exists in Active Directory and is in Scope for the Active Directory Management Agent.
  2. Import and Sync the update to the Synchronization Rule into the Synchronization Service Engine (FIM Service Management Agent Connector Space and Metaverse)
  3. Test the Synchronization Process through the use of the Preview Feature

RESOLUTION - FROM ACTIVE DIRECTORY TO PORTAL

  1. Added Export Attribute Flow for the attribute Member on the Group to Group branch under Configure Attribute Flow

ADDITIONAL INFORMATION

 

Tip of the Day: What’s new in the Windows 10 April 2018 Update

Security baseline for Windows 10 “April 2018 Update” (v1803) – FINAL

$
0
0

Microsoft is pleased to announce the final release of the security configuration baseline settings for Windows 10 “April 2018 Update,” also known as version 1803, “Redstone 4,” or RS4.

Download the content here: Windows-10-RS4-Security-Baseline-FINAL

The downloadable attachment to this blog post (which will be incorporated into the Security Compliance Toolkit shortly) includes importable GPOs, scripts for applying the GPOs to local policy, custom ADMX files for Group Policy settings, all the recommended settings in spreadsheet form and as a Policy Analyzer file (MSFT-Win10-v1803-RS4-FINAL.PolicyRules), and a Policy Analyzer-generated spreadsheet showing the differences from the RS3/v1709 baseline.

The only change from the draft version of this baseline is that after discussion we have removed the recommendation to configure the “Microsoft network server: Amount of idle time required before suspending session” security option. Enforcing that setting does not mitigate a contemporary security threat.

The differences between this baseline package and that for Windows 10 v1709 (a.k.a., “Fall Creators Update,” “Redstone 3”, RS3) include:

  • Two scripts to apply settings to local policy: one for domain-joined systems and a separate one that removes the prohibitions on remote access for local accounts, which is particularly helpful for non-domain-joined systems, and for remote administration using LAPS-managed accounts.
  • Increased alignment with the Advanced Auditing recommendations in the Windows 10 and Windows Server 2016 security auditing and monitoring reference document (also reflected here).
  • Updated Windows Defender Exploit Guard Exploit Protection settings (separate EP.xml file).
  • New Windows Defender Exploit Guard Attack Surface Reduction (ASR) mitigations.
  • Removed numerous settings that were determined no longer to provide mitigations against contemporary security threats. The GPO differences are listed in the “Delta RS3 to RS4 baseline.xlsx” spreadsheet in the package’s Documentation folder. (Since the draft release of the RS4 baseline, we removed one more setting: “Microsoft network server: Amount of idle time required before suspending session.”)

After the draft baseline was released, Windows added another GPO setting that we considered adding to the baseline but ultimately decided not to configure at this time. The GPO path is Computer ConfigurationAdministrative TemplatesSystemCredentials DelegationEncryption Oracle Remediation. You can read information about the setting here and here. (Note that the term “Oracle” here refers to a cryptographic concept and not to anything having to do with Oracle Corporation or its products.) While we recommend patching systems and incorporating this setting as soon as possible, we opted not to include it in the baseline for broad use in the short term because if all servers and clients aren’t patched in a timely fashion the setting will block remote desktop connections. We anticipate incorporating this setting in the next baseline that we publish.

When we published the draft baseline for RS4, we requested feedback about replacing the firewall’s logging facility with Advanced Auditing, such as by auditing failure events for Filtering Platform Connection. At this time, we’re going to keep the baseline as it is rather than introduce more changes. But remember that the baseline is just that: a starting point. If monitoring security events works better for you than monitoring firewall logs, do so. Or if you want to use both, do so.

Windows 10 v1803 (RS4) has greatly expanded its manageability using Mobile Device Management (MDM). However, our mapping from the baseline’s GPO settings to MDM is not ready to publish at this time. We will publish the baseline in MDM form as soon as it is ready.


Integrated Security Configuration for your Azure VM

$
0
0

Last week I wrote about the new Azure Security Center Network Map, today I want to talk about the new integrated security configuration experience for Azure VMs, which was also something that we announced at RSA Conference. With this new experience, you can see all recommendations for a particular VM, directly from the VM's properties in the Azure Portal, under the Security settings as shown below:

With this new integration, you can quickly visualize VM's recommendations as you go through the process of reviewing the VM's settings. In this blade you can also identify in which workspace this VM is located, and the Security Center tier. This interface also allows you to quickly navigate from this blade to Security Center dashboard.

Can I export these recommendations?

Since this is a common question, I decided to add it here, and the answer is: you can, but not from this blade. The best way to export Azure Security Center recommendations is via Azure Advisor dashboard. As you can see below, the Security tile is basically a list of recommendations coming from Azure Security Center:

From this dashboard, you can download the recommendations as PDF or CSV format.

 

 

[無料ダウンロード]4 つの産業革命: デジタルへ変革へのロードマップ(e-book)【5/1更新】

$
0
0

デジタルファーストのビジネスの力

 

デジタル変革の先行企業は、通常の営業利益に加え、平均で毎年 1 億ドル以上の利益を得ています。– Keystone Strategy による聞き取り調査 (2016)によると、

50% の従業員が、2020 年までに「デジタル ネイティブ」になり、24 時間 365 日ネットワークに接続し、働き方を自由に選べるようになります。

– Mind the gaps、The 2015 Deloitte Millennial Survey (2016)。

 

私たちは今、第 4 次産業革命時代のさなかにいます。テクノロジーによって生活や仕事の様式は根本的な変容を遂げました。そして最終的には、ビジネスの拡大や変革のあり方も、これからのテクノロジーによって決まります。この変化に対し、企業はデジタルトランスフォーメーションの急激な過渡期にあり、デジタルファーストモデルを優先するようになっています。

デジタル ファーストビジネスへ向けてのロードマップでは、Microsoft のリーダーたちが集まり、デジタルファーストの世界へと参入し、検討を重ねて適応する方法について有意義な会話を展開しています。

この e-Book で、以下の内容をデジタルトランスフォーメーションにより実現する方法をご確認ください。

• 顧客エンゲージメントを深める
•  社員にパワーを
• 業務を最適化する
• 製品を変革する

 

 

「4 つの産業革命: デジタルへ変革へのロードマップ」のダウンロードはこちらから

 

 

Azure Security Center 和 Microsoft Web 應用程序防火牆集成

$
0
0

撰 /Senior Program Manager

Web 應用程序越來越成為諸如跨站點腳本、SQL 注入和應用程序 DDoS 等攻擊的目標。儘管OWASP 提供了編寫應用程序的指導,使其能夠更好地抵禦此類攻擊,但它需要在多層應用程序拓撲中進行嚴格的維護和修補。 Microsoft Web 應用程序防火牆(WAF)Azure 安全中心(ASC)可幫助保護 Web 應用程序免受此類漏洞的攻擊。

Microsoft WAF 是 Azure 應用程序網關(第 7 層負載均衡器)的一項功能,可使用 OWASP 核心規則集保護 Web 應用程序免受常見 Web 漏洞攻擊。 Azure 安全中心會針對漏洞掃描 Azure 資源,並針對這些問題推薦緩解措施。一個這樣的漏洞是存在不受 WAF 保護的 Web 應用程序。目前,Azure 安全中心建議對面向公眾的 IP 進行 WAF 部署,這些 IP 具有關聯的網絡安全組並具有開放的入站 Web 端口(80和443)。 Azure 安全中心提供應用程序網關 WAF 到現有 Azure 資源的供應,並向現有 Web 應用程序防火牆添加新資源。通過與 WAF 集成,Azure 安全中心可以分析其日誌並顯示重要的安全警報。

在某些情況下,安全管理員可能沒有資源權限從 Azure 安全中心提供 WAF,或者應用程序所有者已將 WAF 配置為應用程序部署的一部分。為了適應這些情況,我們很高興地宣布,安全中心很快會自動發現預訂中未使用安全中心進行配置的 WAF 實例。以前供應的 WAF 實例將顯示在安全管理中心可以將其與 Azure 安全中心集成的已發現解決方案下的安全中心安全解決方案窗格中。連接現有的微軟 WAF 部署將允許客戶利用安全中心檢測的優勢,而不管 WAF 是如何配置的。其他配置設置(如自定義防火牆規則集)可在直接從安全中心鏈接的 WAF 控制台中使用。這篇關於配置 Microsoft WAF 的文章可以提供關於配置過程的更多指導。

 

新元号への対応に向けた検証とテスト ケースについて

$
0
0

皆さまこんにちは。弊社サポート部門では、来年 5 月に控えた改元に向け、さまざまなお客様からお問い合わせを頂戴することが増えてまいりました。

現時点では、改元に対する Microsoft の対応方針、それに基づいた Windows API や OS に含まれるコンポーネント、影響を受ける製品群一覧や改元の対応対象製品等についてお伝えすることは難しい状況でございます。
しかしながら、弊社では、以前の投稿でもお伝えしております通り、弊社製品の対応方針や具体的に対応を行う製品の検討等を急ピッチで進めております。情報の公開まで今しばらくお待ちくださいますようお願い致します。

また、去る 4 月 20 日には、弊社オフィスへパートナー様にお越しいただき改元に向けた説明会を開催させていただきました。大変ご好評をいただきましたため、今後の追加開催を検討しております。こちらは別途ご案内をさせていただきます。

なお、上述の情報公開を待たずとも、ユーザー様、開発者様におかれましては、今すぐにでも、改元の影響を受ける可能性のあるシステムやアプリケーションの棚卸しを開始していただくことが可能です。
今回は、改元の影響を受ける可能性のあるシステムやアプリケーションの棚卸しをご実施いただく際、一般的にまずご確認をいただきたいテスト項目についてお伝えいたします。

大きく分けて、検証を行うべき項目としては下記の 2 点がございます。

・ 日付関連
・ フォント (合字) 関連

上記を踏まえ、アプリケーションごとの主なチェック項目としては下記のようなものが挙げられます。

・ 日付関連
- 日付の表記を和暦に設定できる、または Windows OS の表示形式設定を参照し、和暦が設定されている場合にはアプリケーション上も和暦表記になる
- 和暦を選択できる機能がある
- カレンダーやスケジュール機能がある
- 祝日や六曜といった表記がある
- 日付を挿入できる (当日の日付、カレンダーから選択等)
- 日付で並べ替え、フィルターができる
- レポート、グラフ機能がある
- 西暦 ⇔ 和暦変換ができる
- 他システムや他アプリケーションと和暦でデータ交換を行っている

・ フォント (合字) 関連
- 合字の入力、表示を確認する
- 合字の正規化を行っている

まず、日付の処理に関連した部分から詳細にご説明いたします。

Windows OS の既定の設定では、日本語版をご利用いただいていても和暦を表示することはありません。また、Windows OS としては和暦を使用するよう設定いただく項目は下記以外にございません。

下記の設定をご実施いただくことにより OS が日付を表示する際に使用される既定の表示形式が和暦に変更されます。
Windows 7 / Windows Server 2008 R2 以降の Windows では、この際使用される元号名や日付の範囲は、先日の記事にてご紹介いたしましたレジストリ値が使用されます。

[コントロール パネル]
- [時計、言語、および地域]
- [地域と言語]
- [形式] タブ
- [追加の設定] ボタン
- [日付」タブ
- [カレンダーの種類]
- "和暦"

このような表示形式の設定は、API を使用しアプリケーションから取得することができます。そのため、OS の言語設定や表示形式に従い既定の表示を変えているアプリケーションが少なからず存在いたします。

一方、Microsoft Excel のように OS の設定とは無関係に和暦を使用できるアプリケーションも存在します。例えば、セルの書式設定や連続データを自動的に入力するオートフィル機能がそれに該当します。お使いのアプリケーションが和暦に対応しているか、または OS の言語設定に従い和暦を表示する機能があるか、ご確認ください。

次に、Microsoft Outlook のようにカレンダー、スケジュール機能を持つアプリケーションでは、改元以降の祝日や六曜の表示や、うるう年等、特殊な日付が正しく表示できるかご確認いただくことをお勧めいたします。また、MonthCalendar コントロールのようにカレンダー形式で UI を表示する場合も、元号の切り替わりの表示等にご注意ください。

最後に、和暦 ⇔ 西暦変換を行う場合の動作のご確認についてお伝えいたします。例として、MS IME では "きょう" や "2018ねん" 等を予測変換した場合、候補として和暦が表示されます。現時点では、ここで使用される元号名は前述いたしましたレジストリ値と連動しません。このように、和暦 ⇔ 西暦変換のロジックがどのように実装されているか、また Windows が提供する方法を使用しているのか独自に実装いただいているのかをご確認いただくことが必要と想定されます。

それでは、フォント (合字) 関連についてもご説明してまいります。

MS IME では、"へいせい" を変換した際 "平成" と "㍻" が候補として表示されます。後者の 1 文字分のコードで元号を表現しているものを合字と呼びます。
現時点で新元号は発表されておりませんが、新元号に対しても合字を用意すべく、弊社では Unicode コンソーシアムや日本政府、業界団体とともに Unicode 上の文字コードの確保や新しい字形の作成、フォントの更新について準備を進めております。

新しい合字のコード ポイント等については未確定の状況でございますが、今一度、下記のような合字の表示、入力に問題がないかご確認ください。また新元号の発表後に追加される合字を正しく表示するためにはフォントの更新 (合字のグリフの追加) が必要となりますため、アプリケーションにてご使用のフォントについても確認が必要と想定されま
す。

- ㍻ (U+337B)
- ㍼ (U+337C)
- ㍽ (U+337D)
- ㍾ (U+337E)

また、合字を含めた検索や並べ替えについては、少々考慮が必要です。弊社の Web 検索 "Bing" では、"㍻" を検索した際 ”㍻” と ”平成” の両方が検索されます。一方、Word では "㍻" の検索の際には "㍻" のみが検索されます。検索や並べ替えの動作についても正規化処理の状況によって異なる結果となることが予想されますため、ご確認をいただく
ことをお勧めいたします。

TNWiki Article Spotlight – Unity3d and Language Understanding Intelligent Service (LUIS)

$
0
0
Dear All,

Welcome to the TechNet Wiki Tuesday – TNWiki Article Spotlight.

In today's blog post we are going to see about  Unity3d - Using LUIS for voice activated commands  by Chilberto

This article explains about how to call Language Understanding Intelligent Service (LUIS) from Unity3d. The reason why I have selected this article is as this article talks about Unity3d with the combination of Language Understanding Intelligent Service (LUIS). There are very articles which explains about Unity3d and this article is special as this article also describing about how to call the LUIS from Unity3d.

Language Understanding (LUIS) allows your application to understand what a person wants in their own words. LUIS uses machine learning to allow developers to build applications that can receive user input in natural language and extract meaning from it.

Chilberto also explained in this article as this post is continues of his previous post Azure Cognitive Services - Bing Speech API and Language Understanding Intelligent Service (LUIS)  and in that article he has explained about using Azure Cognitive Services using LUIS with  Speech API. In this article he extends to call the LUIS from Unity3d game application.

Unity is the ultimate 2D and 3D game development platform. We can deploy the Unity in mobile, desktop, VR/AR, consoles or the Web and etc. Unity supports javascript and C# as development languages but an important fact to emphasize is the engine uses the C# compiler Mono to build the game.

In this article we can learn

  • Unity Project
  • Asset Store
  • Setting up the scene
  • Visual stimuli
  • Star Cruiser
  • Capturing Voice
  • Converting to .wav format
  • Convert to Text
  • Translating from Text to Command

The important point to be note here is we can download the source code from the download part of the article.

Chilberto completed this article with the conclusion as below

Combining AI with gaming has been happening for a while now and using hosted services makes a lot of sense for scalability, global coverage, and the simplicity in getting up and running for both indie devs and professional studios.  The example shown here is simple and, in all likelihood, controlling the movement of a ship would be easier to be done with an arrow or WASD keys.
But imagine a more complex scenario.  For example, Lock phasers on target alpha, strength to stun or All ahead full to Alpha Centauri in the Gamma Quadrant.  It is a guess that many players of loot grabbing games on consoles would have loved a voice-controlled inventory system: Sell to a merchant, all ammo where the inventory is over 10 and not used by any of my guns.

I believe this article will be a great feast for all who is looking to work with Unity3d and Cognitive Services  ,don't miss to read this article from here  Unity3d - Using LUIS for voice activated commands  by Chilberto . I hope you all enjoy reading his article.

See you all soon in another blog post.

PS: Today’s banners come from MandarDharmadhikari.

Thank you all.

tnwlogo_3

Yours,
Syed Shanu
MSDN Profile | MVP Profile | Facebook | Twitter |
TechNet Wiki the community where we all join hands to share Microsoft-related information.

Viewing all 34890 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>