Azure Just-in-Time VM Access

Azure Security Center provides several threat prevention mechanisms to help you reduce surface areas susceptible to attack. One of those mechanisms is Just-in-Time (JIT) VM Access. Today Microsoft announced the general availability of Just-in-Time VM Access, which reduces your exposure to network volumetric attacks by enabling you to deny persistent access while providing controlled access to VMs when needed. When you enable JIT for your VMs, you can create a policy that determines the ports to be protected, how long ports remain open, and approved IP addresses from where these ports can be accessed. The policy helps you stay in…
Read More

Nested Virtualization in Azure

Today Microsoft announced that you can now enable nested virtualisation using the Dv3 and Ev3 VM sizes. Microsoft will continue to expand support to more VM sizes in the coming months. For software and hardware prerequisites, configuration steps and limitations for nested virtualisation please see the document here. In this blog Microsoft discuss a couple of interesting use cases and provide a short video demo for enabling a nested VM. Now not only you can create a Hyper-V container with Docker (see instructions here), but also by running nested virtualisation, you can create a VM inside a VM. Such nested environment provides…
Read More

Azure VPN Gateways New SKU

A VPN gateway is a type of virtual network gateway that sends encrypted traffic across a public connection to an on-premises location. You can also use VPN gateways to send encrypted traffic between Azure virtual networks over the Microsoft network.  To send encrypted network traffic between your Azure virtual network and your on-premises site, you must create a VPN gateway for your virtual network. Microsoft have recently released a new set of gateway SKU's which provides an increase in aggregate throughput, you can see the increase in throughput and new SKU below. If you haven't got the luxury of Express…
Read More

Azure ASR for IaaS virtual machines

Microsoft this week announced the public preview of disaster recovery for Azure IaaS virtual machines (VMs) using Azure Site Recovery (ASR). You can now easily replicate and protect IaaS based applications running on Azure to a different Azure region of your choice within a geographical cluster without deploying any additional infrastructure components or software appliances in your subscription. This new capability, along with Azure Backup for IaaS virtual machines, allows you to create a comprehensive business continuity and disaster recovery strategy for all your IaaS based applications running on Azure. As you move production applications to the cloud, Azure natively…
Read More

Azure IaaS Virtual Machines Temporary Drives

I’ve seen many posts on forums asking for more detail on the temporary disks assigned to Azure IaaS Windows and Linux VMs so here is a quick post explaining what they are. When you create a VM either in the portal or command line utilities (i.e. PowerShell) you automatically receive an additional drive or mount point which is available for you to use at no additional cost for storage or transactions.  The primarily use case is to provide faster storage (IOPS and Latency) but although this sounds great it isn’t to be used for any data that you wish to…
Read More

Azure IP address 168.63.129.16

Have you ever wondered what this IP address is?  Well 168.63.129.16 is a virtual public IP address that is used to facilitate a communication channel to internal platform resources for the bring-your-own IP Virtual Network scenario.  Because the Azure platform allow customers to define any private or customer address space, this resource must be a unique public IP address.  It cannot be a private IP address as the address cannot be a duplicate of address space the customer defines.  This virtual public IP address facilitates the following things: Enables the VM Agent to communicating with the platform to signal it…
Read More

Microsoft Azure Security

As we all know in this day and age our workloads are more likely to migrate to the cloud which I'm sure you all know has it's benefits and it's inherent downsides.  One discussion point on everyone's mind is always security (so it should be), just how secure is the cloud. One thing to bear in mind is that your time and approach to defining security principles should be no different to that of on-premises.  Having worked with Azure for a number years I just wanted to share some pertinent information around the security model specifically with Azure. The following…
Read More

Microsoft Azure Backup Certificate Not Available

If you are running your server backups using Microsoft Azure Backup you may now receive the following error message in Azure Backup since 21st August:- Following error occurred during Microsoft Azure Backup SnapIn Operation. Error Details: A server registration certificate was not available to authenticate this server with the backup service. Ensure that you signed in with an administrator account and try again. If the issue persists, register the server again. The reason for this issue is Microsoft have recently released a new Azure Backup agent which is a mandatory update. Download the Azure Backup agent update now The version…
Read More

Outlook fails to send emails after Windows 10 upgrade

I have recently upgraded a number of machines to Windows 10 Home and Windows 10 Pro editions and noticed that for some strange reason Outlook 2010/2013 stops sending emails instead they are just held in the Outbox folder and never get sent.  After doing some troubleshooting I found the answer.  It looks like a system file has become corrupt and by running an SFC /SCANNOW resolves this issue. Click on the search icon, search on cmd when you find the application (Command Prompt) run as administrator (i.e. right click it and click run as administrator). You will then see a…
Read More

The DRA server is already registered” ERROR of Azure Site Recovery Provider Setup

I have recently been running a POC of Hyper-V 2012 R2 experimenting replicating several VM's to Windows Azure (Site Replication) in the East Asia region. During the POC I was receiving connection issues from the Hyper-V host so I decided to remove the Azure Site Recovery Provider agent from the Hyper-V host and the configuration settings from within Azure so that I could start again. Once I configured the Azure settings I then re-installed the agent but on this occasion I received the following error which I'd not seen before Upon going through various troubleshooting steps I found that the uninstall had not…
Read More