Tag Archives: Security

Azure Germany services URLs and IP addresses for firewall or proxy whitelisting

When you are working with Azure Germany sometimes you have to whitelist specific IP address ranges or URLs in your corporate firewall or proxy to access all Azure services you are using or trying to use. Some information like the datacenter IP ranges and some of the URLs are easy to find. Other things are more complicated to find like calling IP addresses of specific Azure services or specific URLs. The Read more [...]

Using MFA in Azure Germany

Using multi-factor authentication as an additional security layer for your accounts in Azure Germany is very easy. Just login to the Azure Germany portal (https://portal.microsoftazure.de) with a Global Administrator account and jump to the Azure Active Directory blade. Next, click on Multi-Factor Authentication in the overview pane to access the MFA portal. There you can activate MFA for a single Read more [...]

Azure services URLs and IP addresses for firewall or proxy whitelisting

When you are working with Azure sometimes you have to whitelist specific IP address ranges or URLs in your corporate firewall or proxy to access all Azure services you are using or trying to use. Some information like the datacenter IP ranges and some of the URLs are easy to find. Other things are more complicated to find like calling IP addresses of specific Azure services or specific URLs. The Read more [...]

Microsoft Azure Network Security Group effective security rules evaluation

Ever faced the problem that you had defined rules in your Network Security Groups, attached one to the virtual subnet and the other one to the VM’s NIC and finally lost the view which rules of which NSG are applied to the VM? If you can answer the question with yes, then Azure provides the solution for it. A hidden gem: the effective security rules. The effective security rules evaluation can Read more [...]

Automated patching for Azure IaaS VMs with OMS update management

During my time at a Microsoft Partner before joining Microsoft and now at Microsoft, customers are asking me, if Microsoft does the patching of Azure IaaS VMs. The answer is no. But with the latest updates to the Update Management solution in the Operations Management Suite, you can now configure an automated patching schedule for your Azure IaaS VMs. -> https://azure.microsoft.com/en-us/documentation/articles/oms-solution-update-management/#installing-updates When Read more [...]

Review Cloud and Datacenter Conference Germany

On May 12th I had the honor to speak at the first Cloud and Datacenter Conference Germany about one of my favorite topics Azure IaaS especially the security part. The one day conference was an awesome event with a set of top international speakers from Microsoft Corp and the MVP community. Thanks to Kerstin and Carsten Rachfahl for such an awesome event. If you have missed to be on-site at CDC Germany, Read more [...]

Azure Disk Encryption is available for Windows VMs

Just in time before the weekend Microsoft announced the general availability of Azure Disk Encryption for Windows VMs in all Azure regions that are public available. -> https://blogs.msdn.microsoft.com/azuresecurity/2016/05/20/azure-disk-encryption-for-windows-virtual-machines-reaches-general-availability/ This is a huge milestone for keeping your data secure. All you need is an Azure Key Vault Read more [...]

Azure Security Center – keep your Azure VMs up to date

Actually the Azure Security Center is in public preview, but nevertheless it is a very useful extension to the existing Azure services. -> https://azure.microsoft.com/en-us/blog/azure-security-center-now-available/ First of all you have to define the security policy for your subscription. Afterwards the Azure Security Center will install the data collection agents on your Azure VMs. Now you have Read more [...]

Attestation failed with a transient error – System Center 2016 TP3 VMM

At the moment I am testing and working in my lab on the Shielded VM and Guarded Fabric scenario. Due to the fact that my Hyper-V hosts in my lab are not having any TPM chip, I am forced to use the AD-based attestation. After a business trip I started my lab again and ran into this error message under the status tab in the properties of my Hyper-V hosts. Error (20588) Attestation failed on HV-02.neumanndaniel.local Read more [...]

Virtual Machine Manager – Error 12711

Vor zwei Wochen trat ein sehr interessantes VMM Problem auf und zwar lies sich nach einem VM Deployment die VM über den VMM nicht starten. Stattdessen erschien die Meldung Error 12711. Error (12711) VMM cannot complete the WMI operation on the server (hyperv.domain.tld) because of an error: [MSCluster_Resource.Name="VMName"] The group or resource is not in the correct state to Read more [...]