Businesses today are comparing ChatGPT vs. Copilot, especially Microsoft 365 Copilot and ChatGPT Enterprise, not just by features but by strategic value. This blog breaks down where each platform excels and why users consistently feel ChatGPT “just responds better.”
Microsoft 365 Copilot has been built on top of OpenAI’s large language models since its inception in November 2023.
Their strategic partnership has allowed millions of secured business prompts using the paid version of Copilot, and recently, through the free Copilot Chat.
In parallel, OpenAI is investing in ChatGPT Enterprise to compete with AI lab rivals Anthropic (Claude) and Google (Gemini), and to some extent, Microsoft itself.
As the frenemies plan the next seven years of their alliance, a substantive debate continues to surface: which service is better for businesses?
I’ve discussed with several IT leaders, and include the prevailing sentiment below.
This was validated by one particular CIO, who is one of the few that provides his organization with the option to use either ChatGPT Enterprise or Copilot (and in addition, Claude or Gemini).
What follows are the drivers that we agreed on.
Why Businesses Are Adopting Microsoft 365 CopilotWhen comparing ChatGPT Enterprise and Microsoft’s paid version of Copilot, five of the key differences highlight Copilot’s strengths, while one reflects a perceived advantage for ChatGPT.
There are five positives for Copilot:
Where Users Perceive ChatGPT Has An EdgeThat leaves the sixth difference as a subjective advantage in ChatGPT’s favor:
Said the CIO, who kindly confirmed these exact points, “I think you have summarized this pretty well. Really, what it comes down to is ChatGPT’s responses just seem to be a lot better than Copilot.”
Dissecting ChatGPT’s Subjective AdvantageWhy does ChatGPT “seem” to provide better responses? I put ChatGPT and Microsoft 365 Copilot head-to-head using three (3) basic business prompts.
Rather than subjectively comparing and rating their responses myself, I had a third LLM (Gemini) evaluate the outputs for objectivity.
Test Methodology Three of the exact same prompts were requested of both models:
After generating the six outputs, I copied them and removed any identifying details. I then submitted the anonymized outputs to a neutral third-party AI (Gemini) for scoring. Gemini applied a four-part, 1-to-5 scoring rubric to each output, allowing for a maximum of 20 points per test and 60 points total.
Test ResultsAs do many humans, Gemini observed clear differences in how each system produced its responses. It scored ChatGPT at 60/60 and Microsoft 365 Copilot at 54/60. Both are high scores, and the six-point gap reflects differences in how the two systems interpret and apply instructions, not differences in underlying intelligence.
These nuances matter for understanding output quality, but they represent only one dimension of evaluating enterprise AI. To understand why the scores differed and why many organizations still prefer Copilot for productivity, security, and governance, we looked more closely at how each system approached the prompts.
Why the Scores DivergedThe most significant functional difference was ChatGPT’s ability to perfectly adhere to all rules simultaneously.
Marketing Prompt: Completeness vs. UtilityIn the marketing prompt, I asked both systems to create an invitation to a webinar provided by financial advisors for prospective clients.
Copilot’s marketing email scored lower (17/20) because its response failed to explicitly mention one of the important services in the prompt (estate planning).
On the other hand, Gemini gave ChatGPT full marks since it seemed to treat the prompt as a non-negotiable set of rules. ChatGPT’s response was longer, but more complete.
Copilot, while excellent, demonstrates a tendency to prioritize high-level utility over flawless execution of every specific constraint, which, in at least one test, led to incomplete final content.
Strategic Analysis Prompt: Extra Customization WinsIn the strategic analysis test, both systems were pointed to a blog and asked to provide novel, high-value strategy tips. Copilot scored 19/20, and ChatGPT received Gemini’s full marks.
The final point difference was in the application of that strategy.
M365 Copilot “Provided excellent strategic concepts and an actionable checklist. This highlights its power in grounded analysis and structured business frameworks.”
Meanwhile, ChatGPT “Achieved the final point by including an ‘Implications for Your Context’ section, which proactively connected the strategic takeaways to the user’s specific consulting business.”
ChatGPT not only analyzed the blog, gave insights, but also gave additional insights to me (the user), which again made the response much longer, but provided a surprising final layer of customized value.
Job Description Prompt: Strategic AlignmentFinally, I uploaded a job description into both systems and asked them to interpret and improve the document.
Both AIs fulfilled the rules, but ChatGPT’s output was strategically more valuable, yielding 20/20.
Copilot’s 17/20 score reflects that its metrics for the job role focused on process-oriented measures (e.g., SOW count), whereas ChatGPT’s metrics aligned strategically with the ultimate business goal (e.g., revenue generated and win rate).
Gemini interpreted the difference:
“This suggests ChatGPT is better tuned for strategic extrapolation, interpreting the job’s context to propose high-value edits that directly relate to executive performance metrics, making its output immediately more useful for senior HR/Recruiting teams.”
When you look across all three tests, the strengths and limitations become clearer; and that’s where broader business considerations enter the picture.
Final Takeaways on ChatGPT vs CopilotContent and extrapolation aren’t the only decision criteria for businesses. Clearly, Copilot’s integrations and security are top of mind for many CIOs (and especially CISOs).
Yet users often have the final word, and often make their decisions in the shadows, so IT leaders would do well set clear guidelines for adoption:
ChatGPT is best for:
Choose M365 Copilot for:
But no matter which GenAI platform(s) you endorse, it is most vital to pick one (or more), fund it for authorized users, and clearly set expectations about not using public AI for work data.
Empower Your Organization with the Right AI StrategyChoosing the right GenAI platform is a strategic decision. eGroup can help ensure your team is using tools that drive productivity, security, and real business outcomes.
Explore AI & Copilot ServicesTalk to an AI ExpertThe post ChatGPT vs. Copilot: What Businesses Need To Know appeared first on eGroup US.
SharePoint is evolving fast with AI, automation, and smarter governance shaping the modern workplace. Learn how eGroup and Microsoft experts unlock new features to streamline collaboration and reduce costs.
SharePoint (and OneDrive) have quietly powered collaboration for years, sometimes so quietly we forget to dig deep– but in our Fall roadshow, I teamed up with Jesus Shelby, Director of Cloud & Microsoft 365 Services, to unpack what’s new, what’s next, and how to get the most from modern SharePoint. You can also hit play on the recording here.
Recent Directions SharePoint’s recent advancements are foundational for how organizations manage content, reduce administrative overhead, and prepare for an AI-driven future.
The latest possibilities we focused on include:
Let’s dive into the key themes and actionable takeaways.
Key Advancements and Upcoming Improvements SharePoint Advanced Management’s (SAM) and the Content Management Assessment (CMA) Dashboard * Automates governance tasks and prepares sites for Copilot activation * Provides a unified dashboard to evaluate site health, permissions, and lifecycle readiness * Helps identify over-permissioned sites and remediate security risks efficiently
“If you have Copilot– even one license– you’ll have access to a subset of the SAM controls.
They’re really the most important parts for getting more information around your SharePoint sites, your permissioning, who’s accessing what, and how things are being shared.”
— Jesus Shelby, Director of Cloud & M365 Services
SharePoint Backup and Archive Service * Automates backup, integrates with Microsoft 365, and reduces manual effort * Quickly restores sites and files to minimize risk and impact of data loss * Moves inactive sites to cheaper storage, but still supports retention policies and compliance * Controls costs tightly with its (upcoming) file-level archive capability
“Backup covers Exchange and content, whereas archive is really only content– your files, your SharePoint sites. Archive and backup are different; they serve different purposes.”
— Jesus Shelby, Director of Cloud & M365 Services
Intelligent Versioning * Automatically tracks document changes and flags significant updates * Minimizes storage needs by preventing redundant file copies * Enables easy retrieval and comparison of older versions, supporting better teamwork and rapid decisions * Can save up to 70% of storage consumption on sites
“Most people aren’t even aware of how much storage these things are actually taking up. To clean them up manually is pretty onerous. Having this built into the platform is extremely helpful.”
— Jesus Shelby, Director of Cloud & M365 Services
AI File Actions and Knowledge Agents * Users can summarize, compare, generate FAQs, and create audio summaries from documents using AI * With knowledge agents, Metadata tagging is automated, improving search accuracy and enabling advanced workflows * AI features are enabled via the ‘AI Actions’ button (for Copilot-licensed users)
Copilot-Connected Enterprise Image Libraries * PowerPoint users can pull branded images from SharePoint Organizational Asset Library or Templafy, maintaining brand consistency
* Libraries are registered using PowerShell with CopilotSearchable flag
Copilot-Powered Page Sections * AI-generated sections help authors create content faster with relevant contextual formatting * Improves productivity and consistency in SharePoint page development
SharePoint Agents * Smart assistants answer natural language questions using SharePoint site content * Deployed via Teams integration (or accessible via the SPO page itself) and configured with domain-specific content scopes
Free for Microsoft 365 Copilot users or pay as you go for unlicensed users
Hero Links for Secure Sharing (Future) * Generates a unique secure link per file with automatic permission settings * Simplifies sharing and reduces errors related to file permissions * Feature is enabled by default for convenience
“Microsoft’s going to start releasing this early next year. It should simplify how people are sharing, remove confusion, and make it easier when links are going around.”
— Jesus Shelby, Director of Cloud & M365 Services
What Technologies You Need to Know * Purview – Data governance and compliance management, including sensitivity labels * Advanced Management (SAM/CMA) – Unified dashboards and controls for site health, permissions, and lifecycle * Knowledge Agents – Automate metadata tagging, FAQ generation, and document summarization * Hero Links – Simplified, secure sharing links for files and sites * Intelligent Versioning – Automated version control and storage optimization
Best Practices, Lessons Learned, and Recommendations * For SAM/CMA, start with a full export of your sites and configurations to assess exposure and permissions. Then, use group-based access controls to rein in unfettered access and simplify management. Leverage CMA and SAM dashboards for visibility and targeted remediation on an ongoing basis. * Educate users on sharing behaviors and monitor activity to maintain security * Enable knowledge agents to automate metadata and improve search accuracy * Plan for storage optimization with intelligent versioning and upcoming file-level archiving * Apply sensitivity labels and configure Purview for file-level protection * Test new features in preview and stay abreast of roadmap updates via the Message Center
Conclusion SharePoint is accelerating behind the scenes, with AI, automation, resiliency, and cost controls at the forefront. Staying abreast of these new capabilities can reduce administrative burden, save costs, and empower employees with more secure collaboration tools.
Turn SharePoint Insights Into ActionTake the next step in your Microsoft 365 journey. Our experts help you map out a strategic roadmap that modernizes collaboration, governance, and AI readiness.
Explore the M365 Roadmap OfferConnect with a Microsoft ExpertThe post Enabling AI-Ready Collaboration: SharePoint News to Put to Use appeared first on eGroup US.
Third-party vendors and partners are essential, but granting them access to sensitive systems introduces significant risk. Traditional remote access solutions like VPNs are often cumbersome, over-permissive, and a management nightmare for IT teams.
Giving access to third-party vendors is both a necessity and a risk. Common scenarios of developers needing access and specialized tooling, third-party service providers/consultants, or external users often need access to sensitive systems and data, and traditional VPN is cumbersome to both use and manage. Providing that access comes the potential for misconfiguration, over-permissioning, and increased exposure to threats.
Here is the challenge:
How do you enable secure, scalable, and auditable access for vendors without compromising your organization’s security posture or operational efficiency?
Microsoft’s cloud ecosystem offers a suite of solutions purpose-built for this challenge. In this post, we’ll explore three key options: Azure Bastion, Azure Virtual Desktop, and Microsoft Entra Private Access. Will discuss how each can be used to build a modern, secure, vendor access strategy that is tailored to the users’ needs and is efficient to manage for your technology team.
Azure Bastion: Secure Remote — Managed Access Without Public ExposureTraditional remote access often relies on exposing resources (virtual machines, networks & data) to the internet via public IPs and RDP/SSH ports. This approach is inherently risky, opening the door to a variety of threats and potential lateral movement once inside the environment. Azure Bastion offers a different approach by providing secure, seamless RDP and SSH connectivity to Virtual Machines directly through the Azure portal. Doing so without exposing those VMs to the public internet.
How this helps support secure vendor access:
Primary Remote Use Case: A vendor needs occasional access to a production VM for troubleshooting. With Bastion, you can grant time-bound access to just that VM, without opening firewall ports or provisioning VPN credentials.
Azure Virtual Desktop: Flexible and Efficient Workspaces for External UsersSecure vendor access isn’t always as simple as providing access to a specific resource. Sometimes, a full desktop experience or access to multiple internal resources across development, production, secure networks, etc. are required. Azure Virtual Desktop (AVD) offers a secure, scalable solution. AVD provides a virtualized Windows experience that is hosted in Azure but allows vendors to work within a controlled environment that is suited to their needs– scoped only to access the resources they require, and can be fully managed by your IT team.
Why It Works for Vendor Access
Primary Use Case: A partner needs access to work inside your environment to support building or modifying a variety of resources in the cloud or on-prem. AVD allows them to work in a secure space without exposing your environment to theirs or the outside world.
Microsoft Entra Private Access: Zero Trust for Internal AppsVPNs have been a necessary evil for a long time in the secure remote access space, but they’re increasingly being seen as over-permissive against today’s threats. They tend to grant broad network access with limited visibility or control. Some of that is due to improper configuration (I’ll get to locking that down tomorrow), and some is a limitation of the technology. Microsoft Entra Private Access offers a modern alternative as part of the overall Secure Access Service Edge (SASE) strategy. It enables secure, identity-centric access to internal apps without requiring full network connectivity.
How does this help?
Use Case: A third-party service provider (or remote employee) needs access to an internal web app. Entra Private Access allows secure, browser-based access with full audit trails. Doing this without opening the network up for additional risks.
Final ThoughtsEach of these technologies presents a different value proposition depending on the use case. The right mix depends on your specific needs across the users themselves, alongside security, compliance, and management efficiency.
Looking for a place to start?
The key is to move beyond one-size-fits-all solutions, put the users’ needs at the forefront, while ensuring the access itself is secured with Microsoft Entra ID Conditional Access, Privileged Identity Management, etc.
Next Steps: Let’s Build Your PlanI’d love to hear more about your secure remote access use cases. From there, we can develop a plan with the right mix of technology and security to deliver modern, secure, and efficient access to your critical business partners.
Ready to Secure Your Vendor Access?Implementing a modern, Zero Trust strategy for external partners requires careful planning and the right mix of Azure tools. Stop relying on outdated VPNs and start controlling access with identity-driven security.
Explore Azure Solutions TodayTalk to an Azure ExpertThe post Securing Vendor Access in a Remote World: Microsoft Azure Strategies for Enterprise IT appeared first on eGroup US.
Microsoft Sentinel is entering a new era defined by AI-driven security operations and agentic intelligence. Learn how these updates transform detection, response, and cost optimization across your Microsoft ecosystem.
The Evolution of Microsoft SentinelMicrosoft Sentinel has been a foundational tool for building cloud-native security operations. It started with leading the cloud-native SIEM charge, but the September 2025 announcements lay out how Sentinel will function and where it fits within Microsoft’s broader security strategy going forward.
This isn’t just a product update, this evolution matters because it redefines how security teams will detect, respond, and adapt to threats today and in the future.
Understanding the Agentic EraThe concept of the “agentic era” refers to a transition from traditional automation to intelligent agents that can reason, act, and adapt. In short, we have and want agents that can not only alert but take actions. In Sentinel, this means the introduction of AI copilots, natural language interaction, and context-aware recommendations. These features are designed to reduce the burden on analysts, improve detection accuracy, and accelerate response times. Think of it this way, instead of complex queries to correlate events and data we can simply say, “what was the issue and what areas were impacted”. Now, that doesn’t mean we don’t need security teams, but it does allow those security teams (or agents they create) to identify, react, and respond faster.
This shift also introduces new architectural considerations. Organizations will need to rethink how they structure their data, workflows, and integrations to support these capabilities. Sentinel is no longer just a log collector. It is becoming a decision-making partner. Sentinel Graphmaps all entities and uses orchestration capabilities to help AI agents understand the relationships between assets, identities, and activities. The Model Context Protocol (MCP) provides a structured way for AI and human analysts to query security data contextually. Following a similar foundation to Microsoft Copilot.
A simple example of this would be the creation of an agent that is solely focused on phishing attempts. Taking actions to notify the user that phishing attempts have been detected against their mailbox and warning for extra caution. However, these agents go beyond alerting. They can perform a wide range of actions to separate false positives to focus in on the real threats.
As Chris Stegh, CTO of eGroup Enabling Technologies, explains:
“The most relevant AI Agents in SecOps are the Security Copilots. Clients with large enough SOC teams can optimize the time of those valuable professionals by providing natural-language interfaces to information that can simply reduce risk faster. Due to the cost and people involved, smaller SecOps teams might still benefit from having a managed security partner.”
Sentinel’s Migration to the Microsoft Defender PortalOne of the most visible changes that have been announced is the migration of Sentinel into the Microsoft Defender portal. This move consolidates Microsoft’s security tools into a single interface, making it easier to correlate signals across endpoints, identities, cloud workloads, and more. This simplifies visibility for security teams by pulling together disparate tools into one central location.
For organizations already using Defender for Endpoint, Identity, or Cloud, this integration simplifies operations. The migration to the Defender portal is not automatic. Organizations will need to create a plan for the migration as well as replace any legacy capabilities that will not be making the move to the new, consolidated, platform. Businesses should plan on completing the migration by March 31st, 2026.
Sentinel Data Lake: Preparing for AI WorkloadsMicrosoft also introduced the Sentinel Data Lake, a new storage layer that separates compute from storage. The primary benefit organizations will see is reduced costs for storage, something that is a BIG benefit.
In addition to cost savings, it will allow organizations to retain data for longer periods at that lower cost, while also enabling advanced analytics and machine learning. The result? Significant cost reduction as well as less administrative time fine tuning storage retention.
It’s not just about cost savings. The Data Lake is important for making those agentic AI scenarios a reality. Agents require historical context to make informed decisions. By storing years of data efficiently, organizations can support forensic investigations, compliance audits, and proactive threat hunting without overwhelming their budgets.
Cost Optimization: New Pricing ModelsMicrosoft introduced new Sentinel pricing tiers designed for flThe cost savings don’t stop with optimizing storage with Sentinel Data Lake, Microsoft rolled out new pricing options for Sentinel. These include a new 50GB daily ingestion commitment tier and pre-purchase plans that offer predictable billing and volume discounts.
For organizations scaling up their Sentinel usage, these models provide more flexibility and better cost control. For most organizations, this presents a clear opportunity to reduce costs. Allowing for savings of 5-45% based on the tier.
For our ThreatDefender clients, these changes allow us to offer more competitive packages by reducing your Sentinel costs in storing data. After all, our platform is built on you owning your data without vendor lock-in. Optimizing that cost makes managed and co-managed security even more affordable. Whether clients are building their own SOC or partnering with a provider, understanding these pricing options is key to maximizing value.
ThreatDefender: Accelerate Your Sentinel JourneyAs a Microsoft Verified MSSP, we’ve built our ThreatDefender solution to help clients operationalize Sentinel quickly and effectively. For some, the best approach is to build their own environment with our guidance. For others, a co-managed or fully managed model delivers faster results and lower overhead.
We offer Sentinel Optimization Workshops to assess readiness, design future-state architectures, and support migration efforts. Our managed detection and response services are built around Microsoft security with Microsoft best practices in mind. Enabling you to own your data and access security experts to extend your team or act as your team. e extending your security team with Microsoft-certified experts.
Final ThoughtsAgentic AI is a powerful tool in the evolution of threat detection and response. It doesn’t replace your security team; it makes them better (and faster) at securing your business. The evolution of Sentinel from a technical standpoint as well as timely cost optimizations is making this capability an affordable reality.
Whether you are building your own Sentinel environment or evaluating a managed solution, we can help. ThreatDefender is designed to deliver 24×7 security with Microsoft Sentinel at its core. Let’s talk about how we can support your security journey and stay out in front of the evolution of these platforms.
Secure Your Organization in the Agentic EraModernize your Microsoft Sentinel environment with AI-driven visibility, automation, and cost control.
Whether you’re building your own SOC or exploring managed options, our experts can help you stay ahead of evolving threats.
Learn More About ThreatDefenderTalk to a Security ExpertThe post Microsoft Sentinel in the Agentic Era: What’s Changing and Why it Matters appeared first on eGroup US.
Day 3 of the Fall Microsoft Virtual Roadshow explored how organizations can strengthen productivity, security, and AI readiness with Microsoft 365 and security solutions. From Copilot governance to Entra ID automation, learn how to simplify operations, secure data, and prepare your people for AI.
On October 16, 2025, we hosted Day 3 of the Fall Microsoft Virtual Roadshow, focused on Microsoft 365 productivity and security.
If you missed it, the recording is available in our Events OnDemand Library– feel free to share with your teams and watch segments on demand.
This recap summarizes hours of content into compact sections, clear recommendations, and actionable takeaways. We emphasized several cross-cutting themes: reducing administrative burden, preparing employees and technology to be AI-ready, strengthening security and compliance, and elevating the employee experience.
1. Make Every Employee & System AI-ReadyWe explored how Copilot is evolving from a single assistant to an ecosystem of agents– retrieval, task, and autonomous—plus practical paths to build them with Copilot Studio and Azure AI.
Topics included Copilot Memory & Custom Instructions, license/consumption options, and the Copilot Control Center for governing lifecycle, metering, and permissions.
We also reviewed how to enable enterprise brand images for PowerPoint Copilot to keep presentations on brand.
Key Takeaways
2. Secure Data for AI with Purview, DSPM, & Adaptive ControlsWe covered Microsoft’s integrated approach to Data Security, including Information Protection, DLP, Insider Risk Management, Data Security Investigations, and Data Security Posture Management (DSPM) to continually harden protections as AI usage expands.
For rollouts to stick, start from Microsoft’s deployment patterns and blueprints, and use eGroup’s eQIP model. Two resources to explore:
Key Takeaways
3. SharePoint Governance, AI-Assisted Content, & Resilient BackupWe demonstrated practical ways to prepare your tenant for Copilot and content growth using Content Management Assessment (CMA) dashboards to surface site health and over-permissioned areas; AI Actions in document libraries; Copilot-powered page sections; and enterprise image libraries for compliant AI-generated content.
We also compared Microsoft 365 Backup (first-party backup for SharePoint, OneDrive, Exchange) with third-party options.
Microsoft 365 Backup is consumption-based ($0.15/GB/month), supports rapid restore, and offers point-in-time rollback.
See: Microsoft 365 Backup Overview and Microsoft 365 Backup Pricing.
Key Takeaways
4. Employee Experience at Scale — Teams Phone and Teams RoomsWe examined how consolidating calling and meetings in Microsoft Teams reduces complexity and costs while improving user satisfaction.
Key updates included the Teams Phone Queues app and why Teams Rooms (MTR) remain a force multiplier for hybrid collaboration.
For planning, we recommended these resources:
Key Takeaways
5. Operational Excellence: Identity Lifecycle Automation and Unified SecOpsWe highlighted how Microsoft Entra ID Governance automates joiner/mover/leaver processes with Lifecycle Workflows, access reviews, and just-in-time controls—reducing tickets and access risk while giving employees day-one productivity.
See: Create Lifecycle Workflows and Understand Lifecycle Workflows.
We also discussed the Sentinel → Microsoft Defender portal transition, which unifies SIEM and XDR operations.
New workspaces are onboarding directly to Defender, and the Azure portal view will retire on July 1, 2026.
Key Takeaways
What’s Next?Day 3 underscored a simple pattern: prepare people and platforms for AI, secure the data that powers it, simplify the estate, and automate what used to be manual.
If you’d like a deeper dive or help with sequencing these steps, evaluating Copilot use cases, deploying Purview controls, modernizing Teams Phone and Rooms, or automating JML with Entra– eGroup is here to help you stay ahead and get the most from Microsoft’s latest innovation.
*Build Your Microsoft 365 Roadmap for AI, Security, & ProductivityReady to turn these insights into action? Our Microsoft 365 Roadmap* engagement helps you assess your current environment, define priorities across collaboration, security, and AI, and chart a clear path forward. Transform what you learned from the Roadshow into a modernized, AI-ready strategy tailored to your organization.
Start Your Microsoft 365 RoadmapTalk to a Microsoft ExpertThe post Fall Microsoft Virtual Roadshow | Day 3: Microsoft 365 + Security appeared first on eGroup US.
With VMware’s rising costs and licensing changes under Broadcom, IT leaders are evaluating Nutanix AHV as a powerful alternative. Learn how three organizations navigated their VMware to Nutanix AHV migration journey to unlock cost savings, simplicity, and performance.
Welcome to a deep dive into one of the most pressing topics in IT infrastructure today: migrating from VMware to Nutanix AHV.
If you’re reading this, you’re probably wrestling with the same questions our panel tackled recently. What’s next for VMware under Broadcom, how do you manage rising costs, and is Nutanix AHV really a viable alternative?
This post is a direct reflection of our August 2025 virtual panel discussion, where I had the privilege of moderating a candid conversation with three IT leaders who’ve lived through the migration journey. We skipped the slides and got straight to the real talk of what worked, what didn’t, and what you need to know if you’re considering a similar move.
Setting the Stage: Why This Discussion MattersLet’s be honest – uncertainty around VMware’s future has been a cloud over the industry for two years. Licensing changes, price hikes, and shifting product features have forced organizations to rethink their virtualization strategies.
As mentioned at the start of the panel, “What is Broadcom doing with VMware? Prices are going up, licensing is changing, and product features and functionality are shifting.” The result? IT leaders are searching for alternatives that offer cost savings, simplicity, and agility.
Our goal for this session was simple: share practical advice and real-world insights from organizations that have already made the move to Nutanix AHV, or are actively evaluating it. No bashing, just realism about the state of the industry and what’s possible.
Meet the PanelistsI was joined by three customers from diverse industries, each with a unique perspective:
Each panelist brought hands-on experience with Nutanix AHV and different stages of adoption; some fully migrated, some running mixed environments, all with valuable lessons to share.
Decision-Making: Why Move to Nutanix AHV?Cost Savings and SimplicityCody kicked things off with the core reason for their migration:
“The biggest point was the renewal costs. We were seeing where Broadcom was going, and what the renewal costs were coming in as. What we really liked was the demo of Nutanix AHV, not only the cost savings, but also the overall management and simplicity. It still provided the same functional services we were doing.”
Devin echoed this, highlighting the licensing model:
“With Nutanix, you get AHV basically for free. We were already running Nutanix hardware, so it wasn’t an issue. Why not take advantage of that and save a little bit of money?”
Overcoming HesitancyMigrating critical services, especially in public safety, comes with risks. Cody admitted, “We were concerned about the sustainability and how well it would continue to operate in the event of a disaster or outage. But it was very simple to deploy. We had it up in a matter of hours and were building out the new environment. It was far easier than operating with VMware.”
Devin added, “There was really nothing that we can’t do in AHV that we weren’t already doing in VMware. So why not move forward?”
Risk Management and PlanningScott’s firm faced not only VMware costs but also hardware renewal. “Our PowerEdge servers were long in the tooth, about six years old, and starting to show their age. We needed to expand, and were running out of memory. Migrating to AHV meant we could consolidate and simplify,” Scott shared.
The migration was carefully planned to minimize downtime. “From the user’s perspective, there was never any downtime. We migrated 120 VMs, and the staged rollout was pretty painless. I expected it to be a lot worse,” Scott said. He credited the Nutanix Move tool and expert support for the smooth transition.
Devin and Cody both emphasized the importance of disaster recovery (DR) and business continuity. Nutanix’s native DR functionality allowed for live disaster testing and seamless failover, critical for organizations that operate 24/7.
Day Two: Life After MigrationPerformance and StabilityOne of the most immediate benefits was improved performance. Scott reported, “Citrix logins went from 30 seconds to under 20 seconds internally, which is crazy. We’ve never had that fast before. External users saw similar improvements, and nothing changed on the network side.”
Devin agreed, “End users expressed how much faster it was and how much quicker it responded. It was a game-changer. When end users say, ‘Hey, this is working fast,’ you know you’re doing something right.”
Operational EfficiencyPatch and firmware lifecycle management became dramatically simpler. Cody described, “It has saved hours upon hours of my life. Now I just go into Prism Element or Prism Central, run my updates, and it does everything autonomously. I don’t have to do each individual host one at a time. It handles it all. It has saved hundreds of hours.”
Devin added, “We do a lot of it during the day. We don’t have to schedule time after hours. We get so many man hours back in our day.”
Disaster Recovery and Data ProtectionCody shared his experience moving from Zerto to Nutanix DR services. “I had a lot of challenges with Zerto. When I built DR into Nutanix, it was very straightforward. It gives you the ability to test a failover without actually performing a failover and tells you why it’s failing without causing any impact. Everything remained operational throughout that time period.”
Network mapping and IP changes were handled smoothly, with Nutanix offering both manual and automatic options. “You tell it what VLAN or subnet you want, and it will move it there and automatically assign as long as you have those features in place,” Cody explained.
Regarding Recovery Point Objective (RPO) and Recovery Time Objective (RTO), Cody found Nutanix competitive. “We didn’t notice any significant changes. Nutanix DR can go down to one-minute RPOs, and there are three different types of DR strategies—async, near sync, and metro sync—so you can craft it to what you need.”
Unified Storage and InfrastructureScott’s firm moved away from NetApp to Nutanix Unified Storage. “Sometimes it felt like you needed a PhD to operate NetApp. We didn’t need high IO for files, so why spend tons of money on NetApp when we can get what we need and still get good performance out of Nutanix?”
The migration resulted in significant savings in rack space and power. “We saved about 14U in rack space. It’s crazy how much space is in our rack now. We were looking at having to upgrade our PDU because we had too much stuff, and now we can stick with what we’ve got,” Scott said.
Cloud Integration and Future PlansDevin’s organization is leveraging Azure VMware Solution (AVS) as a DR target, with plans to expand cloud integration. “We’re on the East Coast of North Carolina, affected by hurricanes. AVS seemed like a good fit. We can have our secondary systems up and running in the cloud environment, alleviating downtime. We have outage management systems that have to be up 24/7, 365,” Devin explained.
Scott mentioned their use of Nutanix Files today and is interested in extending those capabilities into Azure. With Nutanix Files now running natively in Azure, he can seamlessly replicate file data from his on-premises Nutanix Files deployment to Nutanix Files in Azure. This provides a consistent management experience across environments and supports scenarios such as cloud-based disaster recovery, data mobility, and long-term workload modernization.
Key Takeaways and AdviceAs we wrapped up, I summarized the common themes:
Each panelist shared their next steps:
ConclusionMigrating from VMware to Nutanix AHV is not just a technical shift, it’s a strategic move that can deliver cost savings, operational simplicity, and future-proof flexibility. The experiences shared by Cody, Scott, and Devin demonstrate that with careful planning, expert support, and the right tools, organizations can navigate the migration with minimal disruption and maximum benefit.
Whether you’re facing rising VMware costs, seeking to simplify your environment, or planning for cloud integration and disaster recovery, Nutanix AHV offers a compelling alternative. As I concluded, “Not every workload is made for Nutanix, just like not every workload is made for the cloud. The key is understanding your environment, evaluating your options, and crafting a migration strategy that fits your needs.”
If you’re considering a migration, hands-on workshops and modernization assessments can help you understand what makes sense for your organization. The journey may be complex, but with the right partners and insights, it can be transformative.
Ready to Explore Your VMware to Nutanix AHV Migration?Discover how eGroup can help you simplify infrastructure, reduce costs, and modernize your virtualization strategy with confidence.
Schedule a Modernization AssessmentTalk to a Nutanix ExpertThe post Migrating from VMware to Nutanix AHV: Real Insights from IT Leaders appeared first on eGroup US.
AI transformation isn’t just about technology, it’s about people, strategy, and measurable outcomes. During our 2025 Microsoft Virtual Roadshow Day 2: Data & AI, eGroup and Microsoft experts shared how organizations can align data modernization, governance, and change management to drive real business value.
During our Fall Microsoft Virtual Roadshow, we spent several hours diving into the realities of Data & AI transformation. Our six-part discussion focused on practical strategies, real-world challenges, and most importantly, the people side of transformation.
If you missed the live sessions, the recordings are available– and if you want a summary of what we discussed, then read on and learn how you can take the next step in your AI journey.
Part 1: AI Today– Moving From Learning to Action We kicked off the afternoon by acknowledging a simple truth: AI is no longer just hype, it’s here to stay, but the “magic” is evolving. Organizations are moving from curiosity to experimentation, and the real value comes when technology is grounded in business process improvement, not just deployed for its own sake.
What We Discussed:
Key Takeaways:
How eGroup Can Help:We offer AI education, strategy workshops, and hands-on training to help you move from learning to action. Let’s map your AI journey together and align technology to your business goals.
Part 2: AI Strategy & Enablement With the landscape set, we shifted to what it takes to make AI work for your organization. Leadership sponsorship, pragmatic governance, and a clear strategy are critical.
What We Discussed:
Key Takeaways:
How eGroup Can Help:We’ll help you establish your AI charter, build a Center of Excellence, and deploy Copilot Chat to drive safe, effective adoption. Our team supports strategy, governance, and user enablement for long-term results.
Part 3: AI Readiness & Organizational Change No technology succeeds without people. This session, led by our OCM practice leader, Hayley Meese-Cherry, focused on the human journey, addressing excitement, skepticism, and the need for ongoing enablement. Change management isn’t just training; it’s about nurturing employees through the transition and reinforcing new behaviors.
What We Discussed:
Key Takeaways:
How eGroup Can Help:Our Organizational Change Management team helps you assess readiness, build champion networks, and design reinforcement programs for lasting AI adoption. We guide your people through every step of change.
Part 4: Security, Compliance & Trust in the AI Era Security remains top of mind as organizations embrace AI. We explored practical steps to secure data, retrain users, and deploy solutions without waiting for perfection. The message was clear: bad data leads to bad AI, and security demands ongoing attention, not a one-time fix.
What We Discussed:
Key Takeaways:
How eGroup Can Help:We’ll help you implement Purview, secure your Microsoft 365 environment, and deploy Copilot Chat and custom agents safely. Our security assessments and user training build trust and compliance.
Part 5: Capturing Data Intelligence Next, we turned to Microsoft Fabric, a unified platform for data modernization, analytics, and AI. The focus was on iterative, process-centric approaches that deliver business value quickly and avoid the pitfalls of massive, stalled projects.
What We Discussed:
Key Takeaways:
How eGroup Can Help:Let us guide your data modernization journey: design, implement, and govern your Fabric environment for rapid, measurable business impact.
Part 6: Modern AI Solution Architectures We wrapped up the day by looking at the evolving world of AI solution architectures. The takeaway? There’s no one-size-fits-all. Organizations need to mix and match technologies (Copilot, custom agents, automation, and Azure AI services) based on their unique business needs.
What We Discussed:
Key Takeaways:
How eGroup Can Help:Ready to build your AI recipe? We offer consultative sessions to help you discover use cases, design solution architectures, and implement the right mix of AI and automation for your organization.
Turning Insight into ActionThe 2025 Fall Microsoft Virtual Roadshow Day 2: Data & AI brought together leaders, technologists, and change champions united by one goal: to turn innovation into impact. Across every session, one theme echoed: AI transformation succeeds when data, people, and strategy move together.
From foundational readiness to modern solution architectures, eGroup and Microsoft continue to help organizations harness the full power of AI through secure, scalable, and human-centered approaches.
Ready to move from insight to execution?Whether you’re just starting your AI journey or looking to accelerate adoption, eGroup is here to help. From strategy and governance to technical implementation and change management, our team brings the expertise and practical experience to guide you every step of the way.
Explore AI Opportunities TodayTalk to a Data & AI ExpertThe post Fall Microsoft Roadshow | Day 2: Data & AI Transformation appeared first on eGroup US.
Four essential Azure conversations that matter for IT leaders. From cost management to cloud security and governance– discover what’s next. Missed the sessions? Catch up on the insights and start your Azure journey.
We recently hosted a four-part virtual roadshow focused on helping IT leaders build, secure, and modernize their Microsoft Azure environments. The goal wasn’t to just showcase every new feature, it was to have meaningful conversations about what works, what’s changing, and what’s next.
Each session tackled a different challenge, but they all shared a common theme: strategies that work. Whether you’re just getting started with Azure or refining a mature deployment, these are the conversations that matter.
If you missed the live sessions, the recordings are available. Below is a recap of each part, along with key takeaways and an opportunity for continuing the conversation.
Part 1: Azure Cost Management: Beyond the Billing Dashboard We opened the roadshow with a foundational session on how to architect Azure environments for long-term success. This wasn’t about lift-and-shift, it was about aligning platform choices with business outcomes.
We walked through:
Key Takeaways:
Part 2: Azure Innovation: Building What’s Next In part two, Kai Andrews led a deep dive into Microsoft Fabric: a single platform for data ingestion, transformation, storage, analytics, and AI. For organizations drowning in spreadsheets and disconnected reporting tools, Fabric offers a way out.
We covered:
Key Takeaways:
Part 3: Azure Security: What CISOs Actually Care About Security was the third topic and is arguably the most urgent. We focused on how to move beyond disparate, somewhat connected, solutions and how we can adopt a platform to build a proactive, integrated-by-default, security solution by leveraging the expertise of a Microsoft Validated Security Solution Partner (ThreatDefender).
Highlights included:
Key Takeaways:
Compliance isn’t just about checkboxes; it’s about confidence.
Part 4: Azure Governance: From Chaos to Clarity We wrapped Day 1 of the Roadshow with a session on modern desktops; specifically, an ongoing trend towards changing strategies between managed endpoints and virtual desktop infrastructure (VDI). Azure Virtual Desktop (AVD), Windows 365, and Intune all provide viable options. However, the conversation centers around successful flexibility, cost, and user experience.
We explored:
Key Takeaways:
Final Thoughts The Azure platform is broad, but full of opportunity. These four conversations (building for success, data, security, and endpoints) are where most organizations find challenges with evaluating their posture, upskilling their teams, and making meaningful progress. If any of these topics struck a chord, let’s have a conversation that centers around your goals.
Whether you’re planning a migration, launching a new initiative, or just trying to clean up what’s already there, we’re here to help.
Watch the Roadshow RecordingsStart the ConversationThe post Fall Microsoft Roadshow | Day 1: Azure Insights That Matter appeared first on eGroup US.
Even the best IT teams can’t go it alone during a cyber incident. Learn why a coordinated, well-practiced response plan is essential, and how to build one before it’s too late.
Our CIO advisory practice has helped many IT teams with Incident Response (IR) Planning and Tabletop Exercises, where we help evaluate the IR team and the IR plan by walking them through several types of realistic incidents.
From ransomware attacks to account or data security compromises, every decision during an incident matters. The difference between a few days of disruption and a full-blown business continuity crisis comes down to preparing carefully so you know how to respond, who you involve, and when you engage them.
The Risks of Handling IR Yourself (or worse, figuring it out as you go)For many small and mid-sized IT organizations, the first instinct after discovering a potential breach is to lock things down and start triaging internally. That’s understandable– your team knows your systems best.
But this DIY approach can quickly create blind spots:
Even the most capable IT teams are rarely equipped to manage the full scope (legal, technical, regulatory, and reputational) that comes with a serious incident.
Have a Real Incident Response PlanHaving a solid Incident Response Plan (IRP) is the most important step you can take to avoid the risks of improvising. Yet, many times organizations either lack a plan or have a document that hasn’t been meaningfully updated or tested recently. A modern IRP needs to be a living, operational playbook. It should define:
What to Do NowYou can’t prevent every incident, but you can significantly strengthen your response capabilities by taking these steps before you need to respond to an attack:
Don’t Wait to Find Out the Hard WayIf there is one message to take away from all this, it is that incident response is not a time for improvisation. The pressure, complexity, and risk are simply too high. Every organization, especially mid-sized enterprises without dedicated IR staff, needs a well-defined plan, trusted partners, and the discipline to follow it.
Your IT team’s expertise is invaluable, but it shouldn’t stand alone. Surround it with the right ecosystem of internal and external partners, and you will be in a much better position to bring speed, confidence, and expertise to bear when it matters most.
Be Ready Before It HappensEnsure your organization can respond confidently under pressure. Strengthen your team’s readiness with an Incident Response Tabletop Exercise or speak directly with our cybersecurity experts to build your plan.
Explore Incident Response Tabletop ExerciseTalk to an IR ExpertThe post Please Don’t DIY Your Security Incident Response appeared first on eGroup US.
Intentional C-suite leadership, not tools alone, determines GenAI ROI. Focus on culture, business alignment, technology choices, data readiness, and governance to scale value.
Shaping Your AI Future: C-Suite Leadership Can Drive Sustainable Value While the promise of AI is significant, realizing its potential requires more than technology. Success depends on intentional leadership across five key facets of AI. By getting in front of these factors, C-level leaders can shape how AI affects their future, not just react to it.
The Five Pillars of GenAI Maturity To guide your organization through successful GenAI adoption, consider five interconnected pillars that define AI maturity:
Each of these areas presents unique challenges and opportunities, and the C-suite’s role in shaping them is irreplaceable.
Leadership and employee opinions of AI are mismatched. Democratizing access to AI tools helps lower fear and resistance among staff. Upskilling initiatives, led by HR and supported by leadership, empower a workforce ready to embrace AI.
Start with internal use cases that deliver immediate value—such as AI assistants to reduce helpdesk volume or automated report generation to save analyst time. These “quick wins” build organizational confidence and buy-in, creating momentum for more complex projects. And when results fall short of expectations, treat them as learning opportunities, not failures, to encourage continued innovation and engagement.
Said VP of IT Rich Mitton at Mathis Home, of his first AI investment, a sales chatbot, “I’m glad we started; it’s important to take a step forward so that you can learn from that. It’s given us the opportunity to really believe bigger, probably even more than we did when we started the process.” Their full case study is here AI-Powered Sales Copilot Transforms Mathis Home’s Retail Process
Start with sanctioned, enterprise-ready tools to reduce risk and shadow IT, and invest in building in-house expertise. As your organization’s maturity grows, consider AI agents that support your evolving business strategy. Prepare for frequent change—the AI landscape is advancing rapidly, and adaptability is key.
Said CIO Sujan Turlapaty from Verdantas, “We are trying to balance the rapid advancements happening in AI. It’s sometimes overwhelming, but it’s also exciting because it provides new opportunities.”
Remember, not all data needs to be perfect; focus first on the data that powers your highest-value AI use cases to accelerate time-to-value. Use AI agents to focus on specific, curated data, instead of relying on broad Copilot searches covering the entire Microsoft 365 data estate.
Promote awareness of data literacy and risk management throughout the organization. Effective governance will allow you to harness AI’s benefits while minimizing unintended consequences, helping to build trust both internally and externally.
Practical Steps for the C-Suite 1. Lead by Example – CxO engagement sets the tone for the entire organization. Be a visible champion. Promote a culture of experimentation. Treat setbacks as learning opportunities and celebrate successes to build momentum. 2. Democratize AI– Offer GenAI tools to all to unlock value and spark ideas. 3. Develop a Roadmap – Move from ad-hoc pilots to a strategic plan. Define your vision, prioritize use cases, and align resources. 4. Invest in Data – Make data readiness a top priority. Assign data stewards, build catalogs, and curate the data that drives high-impact AI initiatives. 5. Strengthen Governance – Start with guidelines, evolve to enforcement. Involve business leaders in governance structures to ensure alignment and accountability.
Conclusion – The Future Is Yours to Shape The most crucial step is the first one. Just getting started can yield insights and value, helping your team learn and adapt as AI evolves.
The journey may be complex, but with intentional leadership, your organization can realize the promise of AI. By focusing on culture, alignment, technology, data, and governance, you can ensure that GenAI becomes a source of sustainable value and competitive advantage.
AI will change the world—but C-level executives have a unique opportunity to shape how it supports their mission.
Ready to Lead Your AI Journey?Empower your leadership team to move from AI experimentation to enterprise-scale success.
Partner with eGroup to build your GenAI roadmap– aligned with business value, data readiness, and governance maturity.
Explore AI ServicesSchedule a Strategy SessionThe post How C-Suite Leaders Can Drive GenAI Success Across Five Pillars appeared first on eGroup US.
Cloud environments bring enterprises unparalleled flexibility and power, but they also introduce increased complexity and new security requirements.
Identity context has become essential to both prevention and detection. Your identities serve as gatekeepers to your cloud environment—failing to secure them would be like leaving its drawbridge unguarded, inviting attackers inside.
Hybrid EnvironmentsHybrid work environments present security teams with unique challenges due to the wide array of tools, technologies and devices employees utilize. Therefore, in order to safeguard a hybrid network successfully it requires adopting a zero trust methodology which verifies users across diverse environments as well as any devices used within those environments.
At the core of all these measures lies a robust identity and access management (IAM) solution capable of supporting multi-cloud. To simplify cloud management and protection efforts as they develop over time, having one IAM platform for all cloud and on-premises apps managed by one team reduces management complexity significantly.
Implementing a zero trust architecture begins by cataloguing all non-human identities – known as machine identities or digital workers – who have permissions to access cloud applications and infrastructure, such as service accounts, robotic process automation bots, scripts or any other digital workers that access cloud services or infrastructure. It’s essential to take an inclusive approach since these non-human identities can cause more damage than human ones; an attack using social engineering on an automated bot could easily gain entry to sensitive data quickly while remaining within your system for extended periods of time if compromised phishing attacks become successful against humans versus machine workers.
Secure IAM solutions allow for the assigning of permissions based on individual identities’ roles in an organization, for instance: an IT administrator will have different privileges than, say, software developers or finance managers. Finally, these solutions help keep these permissions up-to-date as people change roles or leave.
Cloud Identity and Access Management solutions may offer multiple-factor authentication (MFA), which enables employees to securely log-in to on-premises systems using the same credentials used for cloud apps and services. They may also include device management that automatically configures devices – such as Wi-Fi settings – with appropriate security policies; in addition to centralizing administration.
Hybrid work environments present security teams with unique challenges due to the wide array of tools, technologies, and devices employees utilize. To effectively safeguard a hybrid network, organizations must adopt a Zero Trust methodology, which:
Verifies users across diverse environments.
Secures devices used within those environments.
At the core of this security approach lies a robust Identity and Access Management (IAM) solution capable of supporting multi-cloud environments. A single IAM platform for all cloud and on-premises apps, managed by one team, significantly reduces management complexity.
Key Steps to Implementing Zero Trust for Hybrid Environments:Catalog all non-human identities (machine identities/digital workers)
Assign permissions based on role
Enable Multi-Factor Authentication (MFA) and Device Management
Modernize On-Premises Apps at Your Own Pace
Recap:Hybrid environments require a strong IAM solution, machine identity cataloging, and Zero Trust security to reduce attack surfaces and maintain compliance.
Remote WorkAllowing employees to work remotely is a valuable business advantage, yet it comes with unique security challenges that must be managed carefully. Remote employees typically access sensitive company data through unmanaged personal devices that have access to this data – potentially leaving these vulnerable to malware attacks or attackers taking advantage of misconfiguration of access controls.
Companies must adopt a zero trust approach when managing remote work risk. Modern identity and device access management (IDAM) tools offer solutions that offer increased protection while simultaneously reducing administrative overhead and complexity.
Cloud solutions provide the infrastructure for secure remote work, offering several key benefits including reduced hardware expenses, software patches and updates being handled easily without extra space requirements, and reduced VPN setup expenses. Cloud solutions also offer user-friendly access tailored specifically for each device and employee with multi-factor authentication (MFA) via hardwired security keys, push notifications from mobile devices, voice calls or SMS services and more – as well as providing flexible multi-factor authentication (MFA) options like hard-wired security keys for hardening security keys to multi-factor authentication (MFA), multi-factor authentication (MFA), voice calls or SMS services and more allowing secure remote working arrangements between multiple sites and employees.
Cloud services also provide the ability to access multiple applications, networks, and devices quickly without creating individual accounts for each resource. This is an immense improvement over legacy systems which often necessitate setting up access control lists for every new application or device requiring access.
Cloud solutions can also make budgeting for IT easier by offering an easy subscription model, making it simpler for IT to justify purchasing or leasing less costly hardware and software, freeing up funds for other priorities.
Zero Trust has become the go-to security architecture for remote work due to these improvements, boasting five primary components that include secure centralized access to applications and cloud environments; user and entity authentication to grant granular permissions; unified security infrastructure protecting cloud environments from threats; monitoring logs forensics which detect potential security issues – not only does this approach provide resilience against attacks but it can help organizations comply with regulations like GDPR or HIPAA as well as industry frameworks for managing security risks.
Allowing employees to work remotely offers flexibility and productivity gains, but it also introduces new security risks.
Key Risks of Remote Work: Employees accessing sensitive data from unmanaged personal devices. * Malware infections due to misconfigured access controls. * Unauthorized access* from compromised credentials.
How to Secure Remote Work with Zero Trust Adopt Modern Identity and Device Access Management (IDAM) – Increases protection while reducing administrative overhead. * Leverage Cloud Solutions for Secure Work – Reduces hardware expenses, streamlines software updates, and eliminates VPN complexity. * Utilize Flexible Multi-Factor Authentication (MFA) Methods – Options include security keys, push notifications, voice calls, and SMS authentication. * Improve Access Management – Employees gain quick, secure access to multiple applications and devices without managing separate accounts. * Enable Subscription-Based IT Models* – Budget-friendly IT spending by shifting to cloud-based licensing rather than upfront infrastructure purchases.
Recap:Zero Trust enables secure remote work by using advanced identity verification, cloud-based security models, and flexible authentication methods to reduce risks and administrative burden.
Contractor AccessAs more organizations rely on cloud services for applications and data delivery, the need for comprehensive identity security increases significantly. While cloud adoption offers cost savings, efficiency, scalability, and reduced risks from cyberattacks – it could expose your organization to severe risks should anything go awry.
Zero trust methods of cloud access can protect against many common threats to identity and access management (IAM), by creating secure tunnels between agency-owned infrastructure and vendor-controlled services hosting these services. Zero trust acts as an excellent defense against even the most persistent security issues related to IAM or cloud security; deployment can occur alongside existing network infrastructures.
Identity authentication, which verifies users are who they claim they are, and authorization, which regulates what authenticated users can do once granted access. Role- and attribute-based access control are often employed to enforce more granular permissions that reduce the risk of any unauthorized activity by authenticated users.
Cloud-native apps and automation tools have resulted in the explosion of machine identities, now outnumbering human ones by 45:1. As these machine identities do not fall under human policies and processes, their attack surfaces are much higher; agile development teams typically set broad permissions so new software can reach market faster; this misconfiguration can then be exploited by hackers to launch attacks of different sorts.
An effective cloud identity security initiative relies heavily on having an effective plan that includes goals, an approach and quantifiable metrics. Furthermore, this strategy should incorporate an ongoing monitoring and assessment process designed to detect issues.
As businesses rely more on third-party vendors and contractors, securing identity and access management (IAM) becomes critical.
Why Contractor Access Poses a Risk Third-party access increases the attack surface. * Vendors may have broad permissions, leading to over-permissioning risks. * Machine identities outnumber human ones by 45:1*, increasing potential vulnerabilities.
How Zero Trust Secures Contractor AccessImplement Role- & Attribute-Based Access Control (RBAC & ABAC)
Monitor and Authenticate All Identities
Reduce Over-Permissioning Risks
Regularly Audit Machine Identities
Recap:Contractors introduce additional security risks, but Zero Trust IAM models ensure strict authentication, authorization, and continuous monitoring.
Business-to-Business CollaborationWith today’s rapidly-paced business environment, teams often collaborate across geographical regions or multiple cloud environments. This often results in an increasing number of identities and permissions being created as teams work together – this makes securing the cloud especially challenging as attackers may use these identities to move laterally through systems and gain access to sensitive data or systems containing sensitive information. Today’s most frequent attacks utilize compromised credentials; therefore protecting identities in the cloud is paramount in protecting against these threats.
Cloud IAM solutions provide organizations with a scalable and unified set of tools for automating access control. Their security surpasses traditional solutions by including features such as continual authentication and context-aware access. In addition, cloud IAM solutions enable companies to streamline user onboarding, deprovisioning, monitoring, role-based access controls (RBAC) as well as password management.
A typical cloud environment boasts thousands of system users that attackers can exploit as attack vectors, including both human and machine identities. Most are unsynchronized or over-permissioned accounts created without adequate oversight, creating an endless source of risk. One study found that an individual could create up to 20 unsynchronized cloud accounts with various levels of privilege in just a single day!
Over-permissioning leaves an organization vulnerable to security risks, including privilege escalation vulnerabilities that lead to breaches and can cause considerable business disruption. Attackers can exploit over-permissioned accounts to gain entry to all parts of the system causing severe business disruption.
Zero trust methodologies offer an effective solution to this problem, which will prevent attackers from gaining entry to your critical infrastructure. Zero trust can be implemented using an identity service integrated with your enterprise security ecosystem that has the ability to identify and verify users before applying an authorization policy based on roles and policies established by your security team – thus limiting system access and decreasing attacks.
In today’s digital economy, teams collaborate across multiple cloud environments, increasing identity security risks. Attackers often exploit compromised credentials to move laterally through systems and gain access to sensitive data.
Key Risks of B2B Collaboration Increasing number of identities and permissions makes it harder to track security gaps.
Lack of synchronization between identity systems leads to security blind spots.
Over-permissioned accounts expose organizations to unnecessary risks.
How Cloud IAM Solutions Secure CollaborationContinuous Authentication & Context-Aware Access
Automated User Onboarding & Deprovisioning
Role-Based Access Controls (RBAC) & Password Management
Example: The Impact of Over-PermissioningA study found that one employee could create 20 unsynchronized cloud accounts in just one day. These accounts increase attack vectors and introduce privilege escalation risks.
| Risk | Impact | | --- | --- | | Over-Permissioning | Attackers can escalate privileges and gain unauthorized access. | | Unsynchronized Identities | Harder to track user access, increasing security blind spots. | | Lack of Role-Based Controls | Increases risk of lateral movement attacks. |
Recap:Zero Trust IAM solutions ensure secure collaboration by enforcing continuous authentication, automated access control, and role-based permissions.
Final Thoughts: The Future of Cloud Identity SecurityCloud environments continue to evolve rapidly, introducing both opportunities and security challenges. Whether securing hybrid environments, remote workforces, contractors, or B2B collaborations, organizations must adopt:
Zero Trust Architectures for strict identity verification.
Cloud IAM Solutions to manage identities efficiently.
Continuous Monitoring & Authentication to prevent security gaps.
By implementing robust identity security strategies, businesses can protect sensitive data, prevent unauthorized access, and enhance operational efficiency.
Want to strengthen your cloud security posture? Reach out to learn how a Zero Trust approach can safeguard your enterprise.
eGroup Enabling Technologies helps businesses secure cloud identities, implement IAM solutions, and adopt zero trust security for hybrid environments. Contact us today to safeguard your cloud infrastructure and protect against cyber threats.
The post Cloud Identities and Security appeared first on eGroup US.
The Big News in February: Broadcom’s 2025 VMware Licensing Changes As we step into 2025, VMware customers are once again facing significant (some good, some bad) changes. Notably, Broadcom has ended the sale of the Essentials Plus Kit, a cornerstone for many smaller VMware deployments, while reintroducing the Enterprise Plus licensing SKU. These changes bring both opportunities and challenges, especially for smaller organizations. Dive into the details to find out what this means for your environment.
To catch up on all things VMware, check out these helpful resources:
OnDemand Webinar: VMware Renewals – Evaluating Your Options to Make Informed Decisions
Blog Post: Navigating the VMware License Increase – Rethink and Consider Azure VMware Solution
Blog Post: How to Handle Hypervisor Disruption
Blog Post: Azure VMware Solutions vs Data Center/Azure Native
Case Study: JOEMC Turns the Lights out on VMware and Turns to Nutanix for Improved ROI and Reliability
What’s New in the Hybrid Data Center?Leading vendors are redefining cloud storage, security, and virtualization with breakthrough innovations in risk assessment, AI-powered security, and automation.
Pure StoragePure1® storage enhances security with AI-powered anomaly detection, proactively monitoring admin activities and mass deletions to flag unusual patterns. By providing early warnings of potential threats or errors, organizations can quickly respond before disruptions occur.
Pure1’s enhanced Self-Service Upgrade (SSU) streamlines operations by intelligently managing expired packages—automatically re-downloading bundles without disrupting workflows. Enterprises benefit from unlimited bulk upgrades, eliminating the previous 10-operation limit for true enterprise-scale efficiency. Additionally, SSU now supports Purity//FA non-encrypted deployments, ensuring a consistent upgrade experience across diverse storage environments.
NutanixNot a huge feature release, but a few bug fixes related to API Infrastructure and Data Replication!
Cohesity LTS Release Update:
Updated to 7.1.2 Update 3* (as of January 16th).
Omnissa (formerly Horizon VDI)If you’ve been tracking at home, you know that the Horizon VDI solution is now part of the Omnissa family. The rebranding of Horizon to Omnissa Horizon is now complete, and Omnissa has extended the End of Life (EOL) for Horizon 8 2212.x by six months, giving customers additional time to plan their upgrade.
The Latest release of Horizon 8 has dropped with build 2412. There are some enhancements and feature additions, but what caught our eye was some focus on the UAG, with security tightening and provisioning enhancements!
RubrikWith the latest CDM release, Rubrik has added guidance for deployed versions. Customers requiring the latest product enhancements and features should upgrade to CDM 9.3 (released 1/28/25), or a minimum 9.2 to proactively mitigate any known issues with older CDM releases. All versions of Rubrik CDM 8.1 or earlier have reached end of support.
To enhance the security posture of customers and partners in response to the constantly evolving threat landscape, the following are the security best practices for enabling RSC features.
Rubrik recommends that customers who configured SSO in RSC prior to May 20, 2024, update the existing SSO identity provider (IdP) configuration to use the native SSO SP prior to July 31. After 7/31/25, SSO authentication attempts using the legacy configuration will fail. Knowledge article
What’s New in Microsoft?Discover the latest innovations and updates from Microsoft, designed to enhance security, collaboration, and productivity across Azure, Microsoft 365, Teams, and more.
AzureIf you have resources that interact with Azure services, transition them to TLS 1.2 or later by February 28th.
Microsoft is updating Azure SQL Database APIs for performance and security and retiring all version 2014-04-01 APIs on October 31. Update your resources to use a newer API version by then.
Microsoft 365 Microsoft 365 License Price Increase:
Starting April 1, prices for annual commitments paid monthly will increase by 5%*.
CopilotCopilot EnhancementsContext IQ Enhancements: Smarter Prompts in ChatBy late February, users will be able to leverage Context IQ in chat, making it easier than ever to search for and select specific SharePoint sites to ground prompts with relevant data. This enhancement ensures that Copilot can provide more precise and context-aware responses, improving the overall experience.
Data Visualization Made EasyAlso, coming by the end of February, chat will support chart, graph, and data analysis generation directly from prompts. Whether you need quick insights or detailed reports, this feature will make data-driven decision-making more intuitive and efficient.
Lockbox for GenAI: Enhanced Data Security for Copilot StudioStarting February 28th, Microsoft will introduce Lockbox for GenAI in Copilot Studio. This new security feature provides an extra layer of transparency and control, allowing customers to review and approve or reject data access requests when a Microsoft engineer needs access—such as during a support request.
Copilot Visual Creator Meets ClipchampFor those looking to create dynamic video content, Copilot Visual Creator is integrating with Clipchamp by mid-March. This update will allow users to generate videos simply by typing a prompt, pulling from Microsoft 365’s extensive stock media library. The resulting videos will be automatically saved in OneDrive, with full editing capabilities available in Clipchamp for further customization.
M365 Copilot Chat Expands to Teams and OutlookBig changes are coming to Microsoft 365 Copilot Chat (formerly Microsoft Copilot). By late February, it will be available directly in Teams and Outlook for Entra account users. Licensed users will see it automatically pinned, while others can manually pin it or add it from the Store. Admins will retain full control over pinning settings, ensuring a smooth rollout across organizations.
New AI Administrator Role for Copilot ManagementTo help organizations better manage Copilot settings, Microsoft is introducing a dedicated AI Administrator role within the Microsoft 365 Admin Center. This role will give authorized users direct control over Copilot configurations, making it easier to optimize AI-powered workflows.
With these updates, Microsoft Copilot is becoming an even more powerful tool for businesses and individuals alike. Stay tuned as these features roll out, and get ready to experience the next wave of AI-driven productivity.
Copilot Enhancements – Recap: Context IQ Integration:
Search and select specific SharePoint sites to “ground” prompts when writing in the chat box.
* Data Visualizations:
Users can create charts, graphs, and data analysis using prompts by late February.
* Support Lockbox for GenAI:
Available on February 28th, providing a customer interface to review and approve data access requests.
* Clipchamp Integration:
Generate videos from prompts using Copilot Visual Creator*. Available mid-March.
Defender for Office 365 Third-Party Reporting Integration:
Defender can automatically analyze messages reported through third-party tools like Knowbe4 or Proofpoint.
* Threat Classification for Emails*:
Enhanced detection and response capabilities.
Microsoft Entra IDFIDO2 Passkeys on SmartphonesMicrosoft is extending FIDO2 support to smartphones running the Authenticator app, turning them into secure, device-bound passkeys—just like a key fob. Organizations with the FIDO2 authentication policy enabled (no key restrictions) will have this feature enabled automatically.
New Auditing Features in Entra ConnectVersion 2.4.129.0 of Microsoft Entra Connect now logs admin changes in the Sync Wizard and PowerShell, improving transparency. For details, see: Auditing Administrator Events in Entra Connect Sync (Public Preview).
Customers will be auto-upgraded starting February 2025 where supported. For customers who wish to be auto-upgraded, ensure that you have auto-upgrade configured.
Real-Time Password Spray ProtectionMicrosoft’s Entra ID Protection now detects and interrupts password spray attacks in real-time, reducing remediation from hours to seconds. This feature is included in the Entra P2 (Microsoft 365 E5) license.
These updates showcase Microsoft’s commitment to stronger security and streamlined management.
Entra ID Updates – Recap: FIDO2 Passkeys:
Expands support for device-bound passkeys via the Authenticator app.
* Password Spray Detection:
Entra ID Protection now detects and interrupts password spray attacks in real-time.
* New Entra Connect Version (2.4.129.0)*:
Supports logging administrator changes and allows auto-upgrades for February 2025.
Exchange OnlineAn External Recipient Rate Limit (ERRL) will be enforced in phases starting January, with a limit of 2000 external recipients in 24 hours. The rollout for existing tenants is delayed until October, with full enforcement by April 2026.
IntuneSupport Assistant is now available in Intune. It leverages AI to enhance your help and support experience, and is currently in preview.
Microsoft TeamsTeams Chat and ChannelsStay in control of how your files open across Microsoft Teams and other Microsoft 365 apps.
Teams MeetingsMicrosoft Teams meetings are getting smarter and more customizable for participants and organizers.
Teams PhoneTeams Phone is enhancing communication capabilities with SMS support and new location-sharing options.
Teams AdminAdmins can now perform updates and configurations on Teams Android devices without disrupting active use.
Teams PremiumTeams Premium now provides real-time insights to optimize queue staffing and improve service levels.
Purview Information ProtectionPurview Data Lifecycle Management will allow separate retention policies for Teams chats and Copilot interactions, and separate retention policies for Copilot and AI apps. Rollout begins mid-February.
Data Lifecycle Management now integrates with Adaptive protection, automatically preserving items deleted by high-risk users for restoration if needed. Rollout is in mid-March.
Look for a new graph in Microsoft Purview Data Security Posture Management for AI that displays the departments of users interacting with AI apps. The department data is from a user’s profile in Entra.
The Microsoft Purview Data Loss Prevention now includes Policy Insights in Microsoft 365 Copilot for Security, allowing admins to understand and align DLP policies effectively.
Purview Updates – Recap: Separate Retention Policies for Teams and Copilot:
Purview now supports separate retention policies for Teams chats and Copilot interactions. Rollout begins in mid-February.
* Adaptive Protection Integration:
Automatically preserves items deleted by high-risk users for restoration if needed. Rolling out in mid-March.
* Department-Level Insights for AI Apps:
New graphs in Microsoft Purview Data Security Posture Management display departments interacting with AI apps, using Entra profile data.
* Policy Insights in DLP (Data Loss Prevention):
Admins can align and adjust DLP policies* using insights provided by Microsoft 365 Copilot for Security.
SharePoint Approvals in Document Libraries:
SharePoint will soon allow users to configure and manage approvals directly in document libraries and Teams. Rollout completes by March.
* Retirement of SharePoint Add-Ins and Workflows:
+ SharePoint Add-Ins and 2013 workflows will be retired by April 2, 2026.
+ Organizations should migrate to modern workflows before the deadline.
* Copilot Queries for SharePoint Agents:
Organizations with 50 or more Microsoft 365 Copilot licenses will receive 10,000 additional queries per month for SharePoint agents until June 30, 2025*.
OutlookOutlook (Classic) End of Support for Legacy Mac Versions:
After October 2025*, Microsoft 365 subscriptions will no longer support legacy Outlook for Mac.
Outlook (Mobile) Improved Reporting Buttons:
+ Users can report emails as phishing, junk, or not junk.
+ Admins can customize reporting behavior through Defender for Office 365.
* Email Attachments in Compose Window:
Users will soon be able to attach emails directly in the compose window*.
Outlook (New) Org Explorer: + Visualizes company structures. + Available without a Viva premium license after January 2025. * S/MIME for Encrypted Emails: + Rolling out for sending and reading signed and encrypted emails* in Outlook for Windows.
WindowsJanuary 2025 Security UpdateMicrosoft has released the January security update to ensure all supported versions of Windows remain protected.
Full Enforcement Mode for CertificatesWindows is enhancing certificate authentication to meet modern security standards.
Key TakeawaysHere are some of the top highlights you need to know from the latest updates:
Stay ahead of the curve with these cutting-edge tools and features that redefine the hybrid data center and modern workplace.
The post What’s New in the Hybrid Data Center & Microsoft Cloud | February 2025 appeared first on eGroup US.
Creating an Identity Zero Trust StrategyEstablishing an Identity Zero Trust strategy ensures that security measures align with business priorities.
Create an Identity Zero Trust strategy from the outset to ensure your organization’s security measures align with business priorities. Outlining goals and expected results can help gain buy-in from key stakeholders along the way.
Integrate Identity Zero Trust principles into your policies and procedures, such as least privilege access and strong authentication. Train employees on these principles so they understand how their actions impact security at your organization.
Key Actions for a Strong Identity Zero Trust Foundation Define clear goals and expected results to gain stakeholder buy-in. * Integrate Zero Trust principles into policies and procedures, such as: + Least privilege access (users only get necessary permissions). + Strong authentication (multi-factor authentication and risk-based access). * Educate employees* on security best practices and their impact on cybersecurity.
Modern Access Controls and the Focus on Identity ArchitectureModern access control systems are designed to safeguard digital and physical assets in an integrated fashion, including protecting sensitive areas within buildings from unauthorize physical access and shielding data from hacking or phishing attacks which originate either inside or outside network perimeter.
Newer access control technologies offer a far superior user experience to older ones; rather than using isolated local servers that required on-site management teams for administration and remote monitoring capabilities, modern access control technologies are centralized cloud-based solutions with multiple methods of authentication to make it harder for hackers to breach security systems.
Mastering Identity Architecture (IAM) best practices is no simple task. IAM covers various disciplines within its discipline such as authentication, privileged identity management, authorization and access control and identity federation. Furthermore, Identity Architecture also encompasses identity lifecycle management such as user onboarding/offboarding processes, permission management processes and resource provision.
Building an IAM infrastructure, one key best practice should be having one authoritative source of user data. Decisions regarding access revocation and grant rely on this data, so its collection and maintenance by trusted parties must remain continuous; its accuracy must also be validated regularly and stored safely in one central repository.
Automating access provision and deprovision based on identity lifecycle events is also a best practice that should be adopted, since this minimizes manual user credential tracking while making it easier to detect potential compromises quickly when they arise.
Security leaders need to trust the identity data they are using in order to make accurate access decisions at the appropriate times. This requires regularly collecting and validating identity data, storing it securely in a central repository accessible by all components in an IAM infrastructure and creating policies which govern access privileges for all identities ranging from employees, third-party suppliers, customers, application users and system administrative users – key steps towards realizing zero trust by placing identity first.
Modern access control systems safeguard both digital and physical assets, ensuring:
Traditional vs. Modern Access Control Technologies
| Traditional Access Control | Modern Access Control | | --- | --- | | On-premise, isolated servers | Cloud-based, centralized security | | Manual access administration | Automated, real-time access control | | Single-factor authentication (passwords) | Multi-factor authentication (MFA), biometrics | | No remote monitoring | AI-driven anomaly detection and risk assessment |
Cloud-based solutions enhance user experience by offering centralized security, multiple authentication methods, and stronger protection.
Mastering Identity Architecture (IAM) Best PracticesZero trust may be an emerging security trend, but mastering it is no simple matter. Zero trust requires more than products or solutions; rather it involves changing one’s mindset around security for all aspects of an organization’s network – from devices to data. To successfully implement zero trust into an infrastructure environment it’s vital that full knowledge be had regarding all current users, endpoint devices, and any third-party services within it as well as any third-party relationships which might impact implementation success.
An effective Identity and Access Management solution is vital to identifying a potential attack surface and determining the level of risk required for accessing critical resources. A robust IDAM solution should include multi-factor authentication (MFA), where users provide their username/password combination plus another factor such as SMS code sent directly to their phone or biometric scans as part of the authentication process.
Once this infrastructure is in place, an organization can implement zero trust policies tailored to its unique requirements. This should include using security policies to implement micro-segmentation to safeguard data and continuously verifying identity, devices and context – it is recommended to assume breach situations exist and always authenticate, authorize, and verify on all available data points such as device location service data source workload etc.
By employing Zero Trust practices in this way, organizations are able to limit lateral movement of attacks by reducing attack surface area and protecting their most essential assets. Furthermore, Zero Trust implementation helps organizations limit breach impacts by limiting “blast radius” of compromised devices or systems.
Implementing zero trust architecture can be complex, particularly when combined with legacy systems and workflows. Implementation involves significant investments in new technology, changes to how people work and the ability to alter business processes – something which must be handled carefully or risk causing significant productivity disruptions. With proper tools and guidance from experienced providers however, the advantages of zero trust architecture can become apparent quickly.
IAM is a critical pillar of Zero Trust, covering several key disciplines:
Key IAM Components Authentication – Verifying user identity before granting access. * Privileged Identity Management (PIM) – Restricting administrative access to high-risk systems. * Authorization & Access Control – Assigning role-based permissions. * Identity Federation – Enabling secure access across multiple applications. * Lifecycle Management* – Automating user onboarding, offboarding, and permission changes.
Best Practices for IAM Implementation1. Maintain a single authoritative source of user data. 2. Automate access provisioning and deprovisioning. 3. Store identity data securely in a centralized repository. 4. Continuously validate identity data for accuracy and security. Mastering the Best Practices Around Zero TrustZero Trust is more than just technology—it’s a security mindset shift.
Essential Components of Zero Trust Implementation Understand all users, endpoint devices, and third-party relationships.Use a robust IAM solution, including: + Multi-factor authentication (MFA) + Context-based access (device, location, risk score) + Privileged identity controls * Apply micro-segmentation to restrict unauthorized movement. * Continuously verify identity and context* for every access attempt.
Implementing Zero Trust in Enterprise SecurityHow Zero Trust Strengthens Security Reduces attack surface by verifying every access request. * Prevents lateral movement of threats using segmentation and least privilege access. * Assumes a breach scenario*, enforcing authentication at multiple levels. Security Policies for Implementing Zero Trust
| Security Control | Purpose | | --- | --- | | Micro-Segmentation | Isolate networks to prevent lateral movement. | | Continuous Authentication | Ensure ongoing verification of users and devices. | | Least Privilege Access | Restrict user permissions to only necessary access. | | Zero Trust Policies | Define security rules based on risk levels and behavior analytics. |
Putting Identity First in Zero Trust SecurityAs cybersecurity threats grow, organizations must ensure identity remains the foundation of Zero Trust.
What Zero Trust Authentication Requires Verifying all users, devices, and applications before granting access. * Preventing unauthorized access through strict authentication policies. * Using behavioral analytics and risk-based scoring* to detect anomalies. As threats become increasingly complex, Zero Trust security becomes an essential element of enterprise infrastructure protection. But as organizations focus on it too exclusively, there’s a real risk that they become so fixated on it that they neglect other essential elements of an effective security architecture.
Zero Trust was pioneered by former Forrester Research analyst John Kindervag and takes a “never trust, always verify” approach to cybersecurity. By authenticating all users, devices and applications prior to being granted entry into the network, Zero Trust ensures that any suspicious activities and threats can be quickly detected and eliminated before becoming breaches.
Many CISOs are beginning to recognize the value in adopting Zero Trust as part of their enterprise security plan, and how important it is that users have access to applications and functions in the most secure environments possible. Unfortunately, not every organization has put in place all of the controls needed for an effective implementation of this strategy.
Identity authentication should never be seen as an alternative to other core processes like continuous monitoring and authentication, micro-segmentation, advanced encryption or behavioral analytics. While following best practices for identity access control is crucial, this should not serve as a replacement.
One common misperception about zero trust is that it only involves human identities. However, zero trust involves machine identities as well (applications, workloads and devices). This fact should be remembered because one compromised user using one compromised device could do great damage.
To counter this threat, zero trust requires taking an in-depth inventory of all devices and users connected to a network – both BYODs and third-party ones – which connect with it. Furthermore, each identity should be managed responsibly with only what privilege is necessary to complete its task effectively.
Ensuring each device and user are being handled securely will make preventing cyber breaches, which could cost organizations millions, much simpler. In order to accomplish this, organizations should implement Zero Trust security protocols while prioritizing both human identities as well as machine identities within their operations.
Addressing Common Zero Trust Misconceptions
| Misconception | Reality | | --- | --- | | Zero Trust only applies to human identities | Includes machine identities (applications, workloads, devices). | | MFA alone is enough for Zero Trust | Requires continuous monitoring and policy enforcement. | | Zero Trust is a one-time implementation | Needs ongoing updates and security assessments. |
Mastering Your User Identity LandscapeZero Trust approaches place identity at the core of their security strategies, verifying every access attempt by thoroughly vetting each individual human or machine (or combination) that attempts to access a network, API server or application they’re seeking to reach. This provides organizations with granular access control, adheres to least privilege principles, reduces attack surfaces by eliminating vulnerabilities, and ensures security is an enabler of business innovation.
Authentication and authorization should be ongoing and should include multiple data points, such as device, user, location, service provider, workload and classification of data. This contextual analysis ensures a system of constant verification which works alongside the principle of least privilege to ensure users only gain access to resources necessary for performing legitimate business functions.
Zero Trust architectures provide protection from a variety of threats, such as cyber-attacks, insider threats and other risks. But it’s important to note that this model alone is no guarantee against attacks; even with all of the right infrastructure in place you still must remain proactive against these attacks – for instance by regularly adding new technologies and following best practices to strengthen your infrastructure further.
Zero Trust solutions have evolved significantly over time to protect against previously insurmountable threats such as credential thefts and man-in-the-middle attacks, providing visibility into user, application, and device behavior as a continuous verification system detects such attacks as they happen.
As cybersecurity evolves, traditional perimeter approaches to network security no longer suffice. More organizations are turning towards Zero Trust security which can address all these evolving threats while giving businesses confidence in adopting new applications, implementing AI systems, expanding into new markets or encouraging hybrid work arrangements. However, in order to be effective, it requires proper infrastructure as well as following all eight best practice elements of Zero Trust security.
How Zero Trust Enhances Identity Security Every access request is vetted (human and machine identities). * Access follows least privilege principles to reduce risk. * Granular access control is enforced* across all network layers.
Zero Trust Authentication & Authorization Factors1. User Identity Verification 2. Device Health Assessment 3. Location-Based Contextual Access 4. Behavioral Analytics & Risk Scoring 5. AI-Driven Continuous Authentication Cybersecurity Specialists Working in TeamConclusion: The Future of Zero Trust SecurityKey Takeaways Zero Trust is a continuous process, not a one-time solution. * Identity-first security ensures authentication at every stage. * IAM best practices reduce access risks* and strengthen cybersecurity.
Next Steps Evaluate current identity security measures. * Implement Zero Trust in phases across high-risk areas. * Stay tuned for Part 2: Implementing Zero Trust for Cloud Security*.
The post Zero Trust and Putting Identity First appeared first on eGroup US.
A Cybersecurity Close Call:How We Detected and Contained the ThreatAntone AndradeSecurity Engineer - MSSP
In the early hours one morning, the quiet rhythm of our team’s 24/7 operations was interrupted by an urgent alert. Our automated monitoring systems flagged a series of high-severity events tied to a known ransomware group. These alerts, seamlessly aggregated into Microsoft Sentinel, generated incident tickets in real-time, allowing us to jump into action immediately. For our team—working remotely across multiple shifts to provide round-the-clock protection for clients—this was just another day in the life of a Managed Security Services Provider (MSSP).
The First Signs of TroubleThe initial red flag came from a compromised shared account within the client’s environment. This account, which had additional privileges, was executing unauthorized delete actions and initiating suspicious connections to a Windows domain. Our team quickly began piecing together the details. Registry keys were being deleted, and file paths manipulated—classic signs of an attacker attempting to erase their tracks.
Using our team chat channels, the response came together seamlessly. One analyst shared a VirusTotal report that spotlighted a suspicious file: clip.dll. The file was swiftly identified as malicious, linked directly to the ransomware group. The attackers weren’t amateurs—they employed advanced techniques like scheduled tasks, Kerberoasting attempts, and targeted PowerShell commands, revealing a well-coordinated attack.
Locking it DownContainment became the priority. We cataloged every device and account the attackers had touched, mapping their lateral movement across the client’s network. The likely entry points were internal servers and the Remote Desktop Web environment. Without delay, we disabled compromised accounts, shut down the Remote Desktop Web Server, and heightened monitoring across the client’s systems to detect any further anomalies. Additionally, we detected and removed a backdoor MFA option that the attackers had added in case the tokens were cleared.
Given the sophistication of the attack, we advised the client to engage their Forensic Incident Response Team (IRT) to lead the in-depth investigation and provide expert analysis. This collaboration allowed us to validate our containment measures, identify additional threats, and implement enhanced security protocols. Together, we worked to ensure the environment was secure and all risks were mitigated.
A Close Call with RansomwareThe forensic analysis confirmed the severity of the incident. This was a highly coordinated ransomware group, known for its precision. The good news? We stopped them before they could encrypt any data.
“By the time we’re usually involved, data encryption has already occurred, and ransom negotiations are underway. The fact that you stopped this attack in its tracks is extraordinary.”
Forensic Lead on the Incident
Cleaning Up and Moving ForwardNeutralizing the immediate threat was only the beginning. Over the following weeks, we worked closely with the client and the IRT to ensure the attack was thoroughly eradicated. Logs were analyzed in granular detail, affected devices were remediated, and additional defenses were implemented to fortify the client’s environment. Every ticket—whether tied to unusual sign-ins, Kerberoast activity, or registry anomalies—was resolved with precision.
A Seamless Team EffortThis victory wasn’t achieved by any single person, but by a team that performed with absolute professionalism and precision. Across time zones and shifts, our team members handed off responsibilities seamlessly—from the overnight shift that first detected the threat to the day shift that continued the containment and cleanup efforts. Everyone played a crucial role in ensuring a smooth and effective response, demonstrating the strength of collaboration and trust in a global, remote operation.
By the end of the ordeal, every ticket was closed, the client’s systems were secure, and the team had gained valuable insights for future incidents. What could have been a devastating ransomware attack became a success story, thanks to the power of preparation, coordination, and expertise.
We Can Help!If you have questions about cybersecurity or how to protect your organization with expert-managed security services that detect, respond, and prevent cyber threats 24/7, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousBroadcom’s 2025 VMware Licensing Changes: What You Need to KnowNextZero Trust and Putting Identity FirstNextNeed Assistance with Cybersecurity?Contact our team of experts today!
The post A Cybersecurity Close Call: How We Detected and Contained the Threat appeared first on eGroup US.
Broadcom's 2025 VMware Licensing Changes: What You Need to KnowMike DentField CTO - Hybrid Data Center
Essentials Plus—you will be missed! Working with customers over the last decade, Essentials Plus has been ideal as either a starter kit, small install use case, or disaster recovery strategy to limit the overall cost of VMware licensing. But that’s last year’s news… as we step into 2025, VMware customers are once again facing significant (some good, some bad) changes. Notably, Broadcom has ended the sale of the Essentials Plus Kit, a cornerstone for many smaller VMware deployments, while reintroducing the Enterprise Plus licensing SKU. These changes bring both opportunities and challenges, especially for smaller organizations.
Let’s dive into the details and what this means for your environment.
Essentials Plus Kit: A Trusted Solution for Smaller DeploymentsThe Essentials Plus Kit has been a go-to choice for smaller environments, providing:
Enterprise Plus: The Powerhouse ReturnsBroadcom’s decision to reintroduce the Enterprise Plus licensing SKU is a nod to larger organizations needing advanced features. Key benefits of Enterprise Plus include:
Licensing Basics: Per-Core Model with a Minimum Core CountAll VMware licensing SKUs, including Essentials Plus, Standard, Enterprise Plus, VVF, and VCF, are based on a per-core model. Each CPU requires licensing for a minimum of 16 cores, regardless of the actual core count. This means that for servers with 8, 10, 12, or 14 core CPUs, you will still be licensing at 16 cores per CPU. For Essentials Plus, the licensing applies to up to three hosts with a maximum of 96 cores, making it a cost-effective option for smaller environments.
Comparing Licensing Tiers: Essentials Plus, Standard, Enterprise Plus, VVF, and VCFTo understand the impact of these changes, it is helpful to compare the features offered by each currently available licensing model:
| Feature | vSphere Standard | Enterprise Plus | vSphere Foundation (VVF) | VMware Cloud Foundation (VCF) | | Hosts Supported | Unlimited (up to vCenter limits) | Unlimited (up to vCenter limits) | Unlimited (up to vCenter limits) | Unlimited (up to vCenter limits) | | High Availability (HA) | Yes | Yes | Yes | Yes | | vMotion | Yes | Yes | Yes | Yes | | Distributed Resource Scheduler (DRS) | No | Yes | Yes | Yes | | Distributed Switching | No | Yes | Yes | Yes | | vSAN | No | No | Yes | Yes | | Enhanced Security | No | Yes | Yes | Yes | | Cloud Integration | Limited | Limited | Yes | Extensive | | vSAN Capacity per Core | N/A | N/A | 0.25 TiB | 1TiB | | Core Licensing Model | Per-core (16/core min) | Per-core (16/core min) | Per-core (16/core min) | Per-core (16/core min) |
VMware Cloud Foundation (VCF): An all-in-one solution integrating vSphere, vSAN, NSX, Aria Operations and Automation and SDDC Manager for hybrid and cloud-native environments. VCF continues to offer 1 TiB of vSAN capacity per core, providing significant scalability for larger deployments. Impact on Smaller CustomersFor smaller organizations, the discontinuation of Essentials Plus Kit creates a dilemma. Enterprise Plus, with its higher cost and expansive feature set, is often impractical for these environments. However, the availability of vSphere Standard presents a middle ground:
vSphere Standard: While more expensive than Essentials Plus, it offers core features like vMotion and HA without the cost of advanced enterprise features. For many smaller customers, this is a reasonable compromise to maintain virtualization capabilities without significant budget strain. What’s Next for Smaller Customers?With the Essentials Plus Kit being phased out, smaller businesses should consider:
Evaluating Needs: Determine if features like DRS and advanced security are necessary. If not, vSphere Standard might suffice.
We Can Help!If you have questions or need guidance, reach out to discuss the best path forward. Contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousJanuary 2025 NewsletterNextA Cybersecurity Close Call: How We Detected and Contained the ThreatNextNeed Assistance with Licensing Changes?Contact our team of experts today!
The post Broadcom’s 2025 VMware Licensing Changes: What You Need to Know appeared first on eGroup US.
January 2025 NewsletterTable of ContentsNew Year, New Technology Goals for Your BusinessAs we step into 2025, businesses are setting ambitious technology goals to stay competitive. This year, trends such as AI-driven automation, advanced data analytics, and the rise of edge computing are at the forefront of innovation. Learn more about these technologies in our ondemand webinar, Future Forward: Insights Into 2025 Business Technology.
AI continues to play a pivotal role by enabling smarter decision-making, enhancing customer experiences, and optimizing operations across industries. AI-powered tools like generative models and predictive analytics are empowering organizations to uncover new opportunities and adapt to market demands more effectively. As businesses align their strategies with these trends, the focus on leveraging AI responsibly and securely will be a key driver of success in 2025 and beyond.
Check out our blog post, Top 3 Reasons to Include AI in Your New Year’s Resolutions.
We want you to succeed in 2025 and beyond with technology that propels your organization forward. eGroup Enabling Technologies offers AI services and virtual events to empower your organization with advanced AI tools that drive innovation, enhance decision-making, and accelerate growth.
What’s New in the Hybrid Data Center?Cisco With data generation expected to grow annually by 40.5% through 2027, we often forget the bandwidth requirements. Read how Cisco is developing 400G and 800G connections to support data growth. * Cisco’s recent release of Secure Workload 3.10 introduces significant enhancements in micro-segmentation and workload protection. Key features include Integration of Generative AI (GenAI) to identify and recommend corrections for unused or overly broad policies, eBPF data collection methods, improving accuracy and reducing agent resource consumption by over 10%, and Identity Connector for diverse identity sources such as Active Directory, Open LDAP, Entra ID, ISE, and AnyConnect, enabling user identity-based segmentation for greater granularity. Cohesity Cohesity has added a new Microsoft 365 Backup Storage Usagereport to Data Protect-as-a-Service that provides an overview of the amount of the Cohesity-managed cloud storage consumed by backups of the Microsoft 365 environment. It’s useful to see opportunities to optimize storage consumption. Nutanix Nutanix has announced Database Service version 2.7, introducing features that enhance support for AI workloads, bolster security, and multi-cloud capabilities. The integration of the pgvector extension enables PostgreSQL databases to efficiently store and search vector data, facilitating AI and machine learning applications. Security is strengthened through automated patching and support for custom SSL certificates. Additionally, the service now offers improved multi-cloud database management. * One of the cornerstone features of Nutanix is Data Locality. A quick read shows how Nutanix provides the performance and scalability to support all workloads. * Nutanix’s Zero Compute Deployment for MST-Powered Disaster Recovery (DR) offers a cost-effective and efficient solution by eliminating the need for pre-provisioned standby compute resources. This approach allows organizations to maintain minimal infrastructure during normal operations, activating additional compute resources only during a DR event. Rubrik Rubrik Turbo Threat Hunting is designed to accelerate cyber recovery operations by identifying clean backups within just seconds to quickly begin the recovery process. Using pre-computed hash values within Rubrik snapshot metadata, Turbo can scan up to 75,000 files within less than 60 seconds across the backups housed on one or more Cloud Data Management (CDM) clusters. Turbo is integrated with the Rubrik Security Cloud management platform and will be available to customers with Enterprise Edition licensing this month. VMware VMware ESX’s latest version is ESXi 8.0 Update 3c, released on December 12th with patches and improvements, such as enhanced security features and bug fixes. Additionally, ESXi 7.0 Update 3r was also released on the same date to address issues with vSphere vMotion tasks and other fixes to improve stability and performance. Zerto Zerto released Update 6 for v10, bringing a huge shift in how Zerto integrates with VMware. Zerto now supports leveraging vSphere APIs for I/O filtering (VAIO), helping vSphere replication and recovery workflows. This doesn’t change Zerto’s journal protection, however, it does change the way Zerto can be deployed and managed. Read more here. As our team has gone through VAIO deployments, we have helped customers make configuration decisions, like here, here, and here. * Customers on Azure VMware solution using Zerto for DR protection, the upcoming upgrade to vSphere 8 may impact your Zerto installation. Once Microsoft notifies you that the cluster will be upgraded, contact us or Zerto support for troubleshooting. What’s New at Microsoft?Azure Microsoft Cost Management, an integral part of Azure FinOps, saw enhancements in flexibility and visibility in optimizing reserved instances ranging from AI usage to Azure Kubernetes Service (AKS). * Looking to modernize applications within Microsoft Azure? Forrester puts out a great guidance document and checklist on what true continuous modernization looks like. * Enable seamless hybrid cloud mobility (the ability to move workloads between data centers, clouds, and hypervisors) with Zerto Virtual Replication. New to Zerto, catch up on how they enable migration to Azure, Azure VMware Solution, or region-to-region Azure recovery in this Microsoft Ignite recap. * Got 40 minutes to spare? Take the Microsoft Azure FinOps assessmentand receive personalized guidance on how your organization can improve in specific areas of the cloud adoption framework. Use your scores as a baseline for continuous improvement. * No time like the beginning of the year to assess your plan and position for 2025. * Check out other Azure self-assessments you can use below. If you have any questions, feel free to reach out to our experts, * + Azure Well-Architected Review * + Azure Landing Zone Review * + Data Services Well-Architected Review * + Azure VMware Solution Review * + Azure Virtual Desktop Well-Architected Review * + Azure AI Well-Architected Review Defender for Office 365 Administrators and security operators who are using third-party report message solutions in Microsoft Outlook to allow their users to report suspicious messages (for example, Knowbe4, Hoxhunt, Cofense, Proofpoint add-ins, and so on) can now configure Defender for Office 365 to automatically send these messages to Microsoft for analysis. * Defender for Office 365 introduced tooltips and pointers in the Quarantine portal to assist admins. * Defender for Office introduced a “Threat Classification” feature for emails, utilizing advanced techniques for accurate threat intent analysis. * Outlook for iOS/Android is getting new reporting buttons, allowing users to report emails as phishing, junk, or not junk. Admins can customize button behavior through the Microsoft 365 Defender portal. Defender XDR As part of the convergence of Defender for Identity and Defender for Cloud Apps into Defender XDR services, Microsoft will gradually retire Defender for Identity’s Active Directory and alerts data from Defender for Cloud Apps, moving the data and functionality in the Defender XDR unified experiences. * Microsoft Secure Score will contain new Microsoft Defender for Identity recommendations to better reflect security posture, specifically for Entra Connect accounts, starting in mid-February. Edge for Business Microsoft Search in Bing, the work search experience available on Bing.com, will be deprecated on March 31. Edge for Business’s address bar and Windows search box will still support work search, as will the core Microsoft Search experience through Office.com, SharePoint Online, and Microsoft365.com. Entra ID As announced in Microsoft Entra change announcements and in the Microsoft Entra Blog, the MSOnline and Microsoft Azure AD PowerShell modules (for Microsoft Entra ID) retired on March 30th, 2024. * Users can now update their profile photos directly from their MyAccount portal. * Privileged Identity Management (PIM) capabilities are now integrated into the Azure Role-Based Access Control (Azure RBAC) UI. Just-in-time access and timebound access, functionalities supported by PIM, are now brought into the Azure RBAC UI for customers with either a P2, or Identity Governance license. * Intune now supports Ubuntu 24.04 LTS for Linux management. * Customers can automatically provision “custom security attributes” in Entra ID from authoritative HR sources, like Workday, SAP SuccessFactors, and any HR system integrated using API-driven provisioning. Exchange Online Public Preview of the new “Message trace” feature in Microsoft Exchange Online is rolling out, with extended query range, subject and delivery status filters, customizable columns, and cmdlet changes. Intune You can now create up to 25 policies that customize the Company Portal and Intune app experience. The previous maximum number of customization policies was 10. * Microsoft continues to expand the power of cloud-native management as it is being harnessed by more organizations. The recently announced Windows 365 Link device has enabled new solutions for hardware buyers and created new scenarios for Windows 365 Cloud PCs. Enhanced device inventory capabilities for Windows devices (and soon across platforms) are extending the versatility and utility of Intune. Hardware-backed device attestation helps IT teams ensure that only genuine and uncompromised devices can access company resources. * Intune for macOS is ready for enterprises with new enhancements and updates that greatly improve the management and security of macOS. These include Platform SSO, Universal Print, Certificate Management in the user keychain in addition to the device keychain, Automated Certificate Management Environment (ACME) protocol support, andIntune Remote Help. Microsoft 365 * Until April 1st, 2025, a limited number of Microsoft 365 E5 licenses can be purchased for a 15% discount. Connect with us to learn more about the promotion. Microsoft 365 Copilot You can review a list of Microsoft 365 Copilot changes including new features, product updates, and improvements within the Copilot release notes. * Microsoft is making several changes to Copilot, including UI and naming conventions, and how the free version is different from the paid version. See Copilot for all: Introducing Microsoft 365 Copilot Chat. * Microsoft Copilot is now available for B2B members in multi-tenant organizations, with a new Teams policy for IT admin control. * OneNote is rolling out the ability for users to gather and create notes using natural language based on users’ M365 content on Notebook pages that are personal and non-shared with other users. * Copilot for OneNote on Mac and iPad rolled out, allowing simple natural language commands to help understand, summarize, and rewrite notes. * Quick Actions with Copilot (i.e., Take Notes, Summarize Page, Create a Task List, Rewrite Page) are now generally available directly on the OneNote desktop app canvas. * With Copilot in Excel, users can now clean data with just one click. Clean Data detects and offers solutions for text inconsistencies, number format issues, and extra spaces. * Users can add images to their chat using Copilot in Word and PowerPoint. Users can upload handwritten notes, ask questions about images, get a description of a chart, translate, or generate alt text. * You can get AI-generated summaries for more types of meetings, even when they are not scheduled in advance. Intelligent meeting recap will be available for impromptu calls and meetings, like those started from ‘Meet Now’ and calls started from chat. * Microsoft is updating how Data Loss Prevention (DLP) policies are enforced in Copilot Studio. Currently, enforcing DLP policies is a two-step process. In February, the default mode for all tenants will be changed to Enabled, and all new/updated bots will be subject to DLP policies as defined within your tenant. * The free/web version of Copilot can be pinned within Teams and Outlook, even for unlicensed users. See Microsoft Copilot extending to Teams and Outlook. * M365 Copilot will soon display file sensitivity labels in Business Chat and enterprise data protection chat, consistent with other Microsoft 365 products. Microsoft 365 Apps Admin Center Starting February 3rd, Microsoft will mandate MFA for all M365 admin center users. Users and global admins must set up MFA, verify methods, or apply to postpone the enforcement date. * The retirement for MSOnline PowerShell module starts in early April and ends in late May. You must take action by March 30th, to avoid impact after the retirement by migrating any use of MSOnline to Microsoft Graph PowerShell SDK or Microsoft Entra PowerShell (Preview). OneDrive OneDrive policies are going live for Microsoft 365 Commercial tenants. OneDrive sites that have not had a licensed user attached for more than 93 days will be moved to site collection recycle bin unless they are under retention policy. OneDrive sites covered by retention policies will be Archived, which will cost you if unmanaged. See our Director of Cloud and Microsoft 365 Services- Jesus Shelby’s post. Outlook (New) The new Outlook for Windows will soon support managing emails in PST files, including moving, copying, deleting, and categorizing, with general availability by March. PST support will be default, but can be managed with OutlookDataFile mailbox policy. Users will be able move (drag and drop) emails from an Outlook Data File (.pst or Personal Storage Table file) to a mailbox and vice versa. Future releases of new Outlook for Windows will expand the support for .pst file capabilities. * Delegates in the new Outlook for Windows and web will be able to create and manage categories in the account owner’s Calendar, by mid-February. * Outlook is introducing a new feature called Microsoft 365 Copilot, which provides personalized meeting summaries. It will be available in Outlook for Windows and web, with a Copilot license, by mid-February. * The new Outlook will be pre-installed on Windows 10 devices with the 1/28/25 and 2/11/25 updates. It will exist alongside classic Outlook without altering configurations or defaults. * New Outlook for Windows is rolling out S/MIME support to send and read signed and encrypted emails. Power Automate Microsoft will introduce AI-powered natural language scripting for Power Automate, which simplifies the process of generating code, starting January 31st. * Via the integration between a hosted machine group and your own virtual network (VNet), you can execute RPA jobs that require access to on-premises networks. By leveraging your own VNet, you can ensure secure and reliable connectivity between the hosted machine groups and the on-prem networks. * Copilot can analyze automation activity in Power Automate, allowing users to use natural language to ask about past flow runs, machines, and related data. It will provide advanced operational visibility, without the need to build and deploy custom, predefined reports. * The streamlined workflow creation with the next best action feature for Power Automate for desktop will provide you with the next best action for your workflow creation by continually analyzing your workflow. Purview Purview is introducing a Data Loss Prevention feature for Mac endpoints, protecting sensitive data on network shares and mapped drives. Public Preview starts early February, with General Availability in early March. Organizations can configure DLP policies and exclusions via Microsoft Purview. * Dynamic watermarking, a new sensitivity label setting, has been added to Microsoft Word, Excel, and PowerPoint, embedding the user’s information onto files. * Microsoft Purview’s Adaptive Protection feature, which allows configuring HR resignation dates as a condition for risk levels, will be generally available in mid-January. * Purview introduces a new feature for data governance administrators to permanently delete sensitive content from Exchange mailboxes, bypassing legal holds and retention policies, after multiple approvals and auditing for security. * Communication Compliance now flags potential workplace safety issues in user-reported Teams messages, displaying severity and classifier name. * The Purview eDiscovery experience is modernized in the new Purview portal, unifying Content Search, eDiscovery Standard, and Premium features. New features like Advanced Data Source Mapping and Statistics will be introduced in February. * Information Protection’s OCR capabilities will be enhanced to scan embedded images in files for sensitive content in Exchange Online, with a rollout in mid-February. * Public Preview has begun for Purview’s integration with ChatGPT Enterprise. Organizations can use Purview solutions to manage sensitive information within these interactions. SharePoint SharePoint Online introduces a Carousel layout for the Hero web part, enhancing pages and news with a slideshow, new styles, and a call to action. Rollout begins mid-February 2025 for General Availability. * SharePoint introduces a new pay-as-you-go billing model for Agents, enabling payment through an Azure subscription based on usage. Rollout begins in mid-February for general availability. Admins must set up billing in the Microsoft 365 admin center to activate this service. Teams Users will be able to reduce the main Teams window, the chat window, and the meeting stage to 360px wide or 502px wide (smaller than current dimensions), with no loss of functionality. Also, users can adjust the width of Teams side panels as desired. This applies to Teams on Windows and Mac desktop. Teams Chat and Channels Teams introduced a block user feature allowing admins to prevent malicious users from contacting the organization again. * By mid-February, Teams will allow forwarding Loop components in chats and channels using the ‘more actions’ menu. * Teams will allow forwarding of posts and reply messages to and from channels. This feature is for Teams on Windows and Mac, with rollouts starting in January, and can be controlled with sensitivity labels. * Teams will soon allow users to add Microsoft 365 Copilot agents to group chats, without needing a Copilot license. It will be enabled by default but can be disabled if desired. * Teams introduced a feature to schedule messages in channels, enhancing communication etiquette. * Teams will soon allow users to personalize the placement of notifications on their screens. Users will be able to choose from four options: bottom right, top right, bottom left, or top left on Windows desktops. * Teams will allow users to record video clips directly in Teams channels. This feature, previously only available in chat, enables recording of self, screen, or audio to post or reply in channels, by late January. * Teams will allow adding a Loop workspace tab to standard channels for real-time collaboration by late February. Teams Meetings Meeting participants will be able to share a link to the Meeting Recap from the meeting thumbnail in chat and the Recap tab, making it easier to reference and share Meeting Recap insights with others. Users who don’t have access to the recording or transcript must request access. * Participants using the Teams web app can now use the “take control” function to request control while another person is screen-sharing. * Meeting moderators can privately reply to attendee questions during events, enhancing privacy. * By late February, users can pop out Notes, Chat, and Copilot (if licensed) panes during meetings. * Teams will soon automate the association of peripherals to BYOD rooms using meeting room invite data, enabling features like auto-selection of audio/video devices and shared display mode. It’s recommended to review room inventory and encourage users to book rooms and plug in peripherals. * New transcription policies for Microsoft Teams town halls and webinars will allow finer control and won’t follow the current Teams meeting transcription policies. * Teams is introducing DVR capabilities for town halls on desktop and web, rolling out by early March. Teams Admin A new csTeamsAIPolicy policy for Teams (available via PowerShell in mid-February) will give IT admins more control over voice and face enrollment settings, allowing organizations to manage these features based on their needs. After rollout, voice and face profile enrollment will be enabled by default, and users can benefit from voice isolation, speaker recognition, and attribution in meeting rooms, resulting in smarter meeting recaps and Copilot functionality in meetings. * The Microsoft Teams admin center will introduce options to disable chat before and after meetings, with rollout beginning in March. Admins will have new ‘in-meeting only’ controls for meeting chats. * The Microsoft Teams admin center introduces a feature for Android-based Teams devices to perform updates and configurations only when devices are idle, preventing disruptions during active use. This will start rolling out in late February and requires updates to the Teams app and admin agent app. * There are important changes coming to a few Teams PowerShell cmdlets. Starting in January, Microsoft is deprecating Get-CsDialPlan cmdlet. We will also be deprecating DialPlan attribute from Get-CsOnlineUser and LocationProfile attribute from Get-CsUserPolicyAssignment cmdlet. If you are using DialPlan or LocationProfile attribute found in these cmdlets, please stop using them. * Look for the ‘Best Practice Configurations’ dashboard in the Teams admin center, which helps monitor tenant conformance to Microsoft’s best practices, with automatic updates for administrators. Teams Premium For contact centers using the Queues app, Microsoft will include “Service level” in the real-time metrics. Authorized users will be able to review the Service level metrics and adjust staffing accordingly. * Meeting organizers with Teams Premium licenses can prevent participants from copying chat, captions, transcripts, and insights from meeting recaps. Windows Starting in May 2025, certificate-based authentication on Windows domain controllers (DCs) started to go through a series of changes to enhance security, following a planned timeline of Enablement Phases. After you install the Windows security updates released in February 2025, authentication for certificates that do not meet the expected mapping requirements will be denied. This change is known as Full Enforcement mode. However, you can move back to Compatibility mode until September 2025. For full details, see KB5014754. ConclusionIf any of these updates or changes pose a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousAchieving Successful Data Governance Is More Organizational Than TechnicalNextBroadcom’s 2025 VMware Licensing Changes: What You Need to KnowNextNeed Assistance with These Updates?Contact our team today to get help with any of the updates mentioned above!
The post January 2025 Newsletter appeared first on eGroup US.
Achieving Successful Data Governance is More Organizational Than Technical###### Tom Papahronis
CIO Advisor
Many of our clients are trying to get a data governance program off the ground, typically in response to either compliance requirements or a desire to mitigate risk that Copilot and other AI tools may introduce as they make data easier to use or search.
Their first instinct is usually to jump right into deploying a tool to help with this, such as Microsoft Purview. While piloting Purview is a good idea, a widespread rollout can be premature if the organization does not already have the required organizational components in place first.
Like any other initiative, executive buy-in, written policy guidance, and resources need to be secured before the adoption of a data governance program and related controls can be successful. Here are the key roles that we recommend from a RACI standpoint so that the organization can be positioned to successfully launch a data governance effort.
Executive SponsorshipA successful data governance program needs strong sponsorship from executives, typically from the Legal, Compliance, Privacy, GRC, or Risk Management groups. These sponsors best understand the data risks that the organization has and the authority to define and enforce data governance requirements across the organization. Their responsibilities typically include:
Metrics and KPIs: Define and track specific metrics or key performance indicators (KPIs) that they need to track and measure the success of the data governance program. This could include compliance scores, remediation costs, or reduction in data breach incidents overall. Data Governance Program OwnershipThe GRC lead, Chief Information Security Officer (CISO), Data Privacy Officer, or Chief Information Officer (CIO) typically own the data governance program. Their role involves:
Developing written data governance policies: These policies should include data classification, retention, acceptable data use, and data sharing requirements. (Focused on the “how.”) They must be comprehensive and clear to ensure employees can understand their own data governance and security responsibilities.
Metrics and KPIs: Define and track metrics or KPIs related to policy adherence and controls, such as DLP policy violations, Insider Risk alerts, sharing metrics, and shadow IT detection. Application OwnershipThe person or team responsible for configuring and administering Purview typically reports up to the technology group, security, or GRC teams. They need to be knowledgeable about both Microsoft 365 and governance/compliance requirements. Their tasks include:
Configuring Purview policies and settings: This involves setting up data classification labels, sensitivity labels, and Data Loss Prevention (DLP) policies. The configuration should align with the organization’s data governance policies.
Maintaining Technical Skills and Certifications: Ensure the application owner or team develops and maintains technical skills to operate Purview effectively. This should include certifications like the Microsoft SC-400 (Information Protection and Compliance Administrator) and keeping up with ongoing Purview feature release documentation and training. Line of Business Impact OwnershipThis role involves liaising with data owners across different business groups to understand the uses of sensitive data and the impact of new controls like Data Loss Prevention (DLP) or sensitivity labeling on business processes. Often, this is a business or technical analyst who is familiar with company processes and data usage. Finding a balance between effective data governance controls and business processes is key to the success of any data governance program. In some cases, business processes or data governance policies may need to be modified to mutually satisfy the needs of both. Typical responsibilities include:
Understanding business needs: The LOB impact owner must work closely with business leaders to understand how sensitive data is used in daily operations and the potential impact of new data governance controls.
Facilitating change management: Implementing new data governance controls can be met with resistance. The impact owner should facilitate change management by helping to communicate the benefits of the controls and providing support during the transition. Data Literacy and Purview Policy Training Effective data governance requires comprehensive training communication and training. A dedicated training program should focus on:
Data literacy: This training should educate employees on the types of sensitive data used, why they need to protect it, and the specific actions they need to take to comply with data governance policies.
Implementing Microsoft Purview for data governance is a multi-faceted process that should have the needed organizational support and expertise in place before the deployment of the technical controls. Establishing the organizational roles is often more time-consuming than the technical deployment, but by ensuring these roles and responsibilities are clearly defined and supported, it really does help ensure success of the overall data governance effort and for effective data security controls to be put in place.
We Can Help!If you have questions about data governance or Microsoft Purview, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousNavigating Uncomfortable Change During Tenant MigrationsNextJanuary 2025 NewsletterNextNeed Assistance with Data Governance?Contact our team of experts today!
The post Achieving Successful Data Governance Is More Organizational Than Technical appeared first on eGroup US.
Navigating Uncomfortable ChangeDuring Tenant Migrations###### Andrew Willis
Senior Project Manager
Have you ever hopped in a rental car and things just felt “off?” You have to spend time adjusting the seats (was Danny DeVito sitting in here?) getting the mirrors just right, figuring out how to connect your phone to the Bluetooth, etc. God forbid it’s raining and you have to turn every knob in the car to get the wipers working properly while simultaneously navigating through airport traffic. It takes time for your brain to adjust to operating a vehicle that is not your own.
This is something that we all recognize on some level. No matter how seemingly small and innocuous—change is uncomfortable.
This is an important principle for organizations to keep in mind while planning for a tenant migration. Your users are going to experience change and will need support mitigating their initial discomfort. While there are numerous change management elements to consider, the key factors in ensuring a smooth transition are communication, training, and post-migration support.
These may seem like obvious points, yet they are often the most overlooked components when organizations are going through migrations. There is a tendency to focus solely on the technical details of the migration; leaving these critical aspects on the backburner. Do not let your team fall into the same trap. Take the time to thoroughly plan through the items below.
CommunicationEffective communication is the cornerstone of any successful tenant migration. It goes beyond simply informing users of the upcoming change; it’s about building trust, managing expectations, and ensuring everyone feels heard and supported throughout the process. Miscommunication or lack of clarity can lead to confusion, frustration, and resistance, while a well-thought-out communication strategy can ease the transition and foster a positive reception.
Develop a Communication Plan and Timeline TrainingEffective training is essential to help users navigate a new system or process with confidence. It’s not just about giving them the tools they need, but also about making them feel comfortable using them. A well-structured training plan should empower users to adapt quickly and reduce the anxiety associated with change
Create FAQs: Identify common questions and concerns that might arise from the change
ConclusionOur passion is bridging the gap between technology and those who use it, while equipping individuals to successfully navigate and adopt any change. To thrive in the technology landscape, you need a nimble and proactive approach to change management. eGroup Enabling Technologies’ team of experts can be your trusted guide, empowering you to navigate the complexities of digital transformation with confidence.
Learn More About Our Azure and Microsoft 365 Migration Services
Leverage our Microsoft Migration Services to successfully migrate Microsoft Azure and Microsoft 365 for Exchange Online, OneDrive, Teams, and SharePoint Online Services.
Learn More About Our Organizational Change Management Services
Our Change Management Consultants can help your organization through migrations when you find yourself short on availability, resources, and expertise.
We Can Help!If you have questions about Tenant Migrations or Organizational Change Management, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousImplementing CISA’s SCuBA Project In Your CloudNextAchieving Successful Data Governance Is More Organizational Than TechnicalNextNeed Assistance with Tenant Migrations?Contact our team of experts today!
The post Navigating Uncomfortable Change During Tenant Migrations appeared first on eGroup US.
Implementing CISA's SCuBA ProjectIn Your Cloud###### Micah Linehan
CTO - Cybersecurity
As more federal civilian agencies migrate their business applications to the cloud, it’s critical that they take an aggressive stance toward managing security configuration baselines proactively in order to ensure data remains secure while adhering to Cybersecurity and Infrastructure Security Agency (CISA) guidance.
CISA has published two Microsoft configuration baseline documents and developed an automated assessment tool called ScubaGear to analyze GWS tenant configurations against these baselines.
Microsoft 365Federal efforts to avoid another SolarWinds-like breach are becoming more centralized in one agency: the Cybersecurity and Infrastructure Security Agency (CISA). CISA is spearheading a national cybersecurity agenda intended to extend into private industry environments amid mounting geopolitical tension; one high-profile initiative being SCuBA.
SCuBA stands for Secure Cloud Business Applications. It is a project that seeks to assist federal agencies with protecting their business application environments and safeguarding federal information created, accessed, shared, or stored within those apps. In addition, visibility gaps that impeded federal civilian executive branch (FCEB) efforts at managing cybersecurity risks for their IT enterprises, as well as detecting or responding to cyber threats, are addressed through SCuBA.
SCuBA will not only establish baselines for critical business applications, but will also ensure FCEBs are configured and integrated correctly into existing enterprise systems. It aims to standardize security configurations across widely used cloud business apps while mandating agencies share relevant telemetry with CISA in order to facilitate threat analysis, incident response, and risk-mitigation activities.
The initial release of resources under SCuBA includes two documents—the Technical Reference Architecture (TRA) document and an Extensible Visibility Reference Framework (eVRF) guidebook. The TRA document establishes a model of “shared responsibility,” where agencies are accountable for configuring business applications securely while vendors must ensure the integrity of SaaS platforms underlying those applications; CISA then is accountable for outlining baseline security requirements.
The eVRF guidebook will enable organizations to identify the visibility data necessary for threat detection and response, assess their ability to collect and leverage this telemetry, as well as any gaps in their product offerings. Both documents will eventually be accompanied by an assessment tool to assess compliance of an organization’s Microsoft 365 environment with new security baselines.
Hybrid Identity GuidanceThe Cybersecurity and Infrastructure Security Agency (CISA) recently issued new identity management guidelines that address transitioning identity management capabilities to the cloud. Entitled “SCuBA Hybrid Identity Solutions Architecture,” these guidelines seek to inform agencies on their options for migrating identity management functions to the SaaS model, also known as IDaaS (Identity as a Service).
CISA provides guidance that details various hybrid identity architectures, outlining their advantages and disadvantages to assist agencies in choosing one that best meets their unique needs and risk tolerances. Key factors considered when making their selection include time, existing infrastructure complexity, and implementation cost compared to each alternative option.
Provisioning and synchronizing identity data across both on-premises Active Directory (AD) and Entra ID are crucial steps in creating hybrid identities, as it ensures all identity data in both directories remain consistent. There are various methods to do this; PIM solutions offer one such means.
Other practices recommended in this guidance are federated authentication, pass-through authentication, password hash synchronization, and cloud primary authentication. Furthermore, two-factor authentication should be required when providing outbound guest access to resources within another tenant, and activation duration should not exceed one hour for privileged accounts, significantly decreasing an attacker’s window of opportunity.
The SCuBA project aims to assist federal civilian executive branch (FCEB) agencies secure their Microsoft 365 and Google Workspace environments by offering baseline configurations that ensure federal information created, accessed, shared, or stored within these environments remains intact. Furthermore, its primary goal is to strengthen FCEB cybersecurity postures against continuously-evolved threat actors.
Technical Reference Architecture (TRA)CISA’s SCuBA Project provides federal civilian agencies with much-needed guidance for securing SaaS applications, to address visibility gaps that impede our understanding and managing of cyber risk across our entire federal network.
The SCuBA project released two guidance documents —Technical Reference Architecture (TRA) and Extensible Visibility Reference Framework (eVRF). Both guides outline a technical architecture and framework for protecting SaaS applications; with TRA outlining a layered, scalable approach for protecting common business applications while the latter provides advice for overseeing security in multi-cloud environments.
eVRF provides an architecture to enable the identification of visibility data for specific applications and identify gaps that might exist between visibility data and actual application use. Furthermore, its flexible framework can easily accommodate changes to technologies or capabilities to enable security integration into business processes as well as managing overall security posture.
One of the more comprehensive sections of TRA is its Shared Services Layer, which details cloud-service models, FedRAMP roles and responsibilities, and application authorization boundaries. Organizations should closely consider this section when planning for cloud security-layered approaches.
Extensible Visibility Reference Framework (eVRF)CISA recently unveiled its inaugural series of security guidance resources under its SCuBA project—Technical Reference Architecture (TRA) and an Extensible Visibility Reference Framework (eVRF). CISA actively solicited input for these documents in order to make sure our guidance allows for rapid technological evolution while continuing to protect federal enterprises.
These two documents assist agencies with creating secure implementation architectures for Microsoft 365 and Google Workspace cloud business apps, providing guidance around their deployment as well as tips and recommendations on how best to configure them to comply with Federal Risk and Authorization Management Program requirements.
Additionally, the eVRF provides agencies with capabilities they can use to identify and mitigate threats that could threaten business application environments. This enables agencies to gain visibility into their cloud services as well as detect anomalous behavior or activities that may indicate an attack attempt.
CISA will continue its leadership of various identity and visibility projects, while strengthening our cloud capabilities, such as publishing an official guidance document on recommended cybersecurity configuration baselines for selected products that should become available soon.
We Can Help!If you have questions about securing your cloud infrastructure or any of the concepts discussed in this article, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousTop 3 Reasons to Include AI in Your 2025 ResolutionsNextNavigating Uncomfortable Change During Tenant MigrationsNextNeed Assistance with Cybersecurity?Contact our team of experts today!
The post Implementing CISA’s SCuBA Project In Your Cloud appeared first on eGroup US.
Top 3 Reasons to Include AIin Your 2025 Resolutions###### Kai Andrews
Data / AI / Power Platform Practice Leader
Well, here we are. We’ve crossed that magical line that represents the start of a “new” year and along with this milestone, comes the idea of fresh beginnings and maybe even a resolution or two. Many organizations spent 2024 pondering the value of AI and how to possibly integrate it into their business processes. I should know, I spoke with many of you! Others sat back and played the waiting game, wanting to see whether AI was here to stay. To all of you who have not taken that first step, may I recommend that you use the start of a new calendar year to plan and execute with intent.
Why now? Maybe the better question is, why not now? Here are three reasons why you should move forward with an AI initiative in 2025:
The Copilot capabilities have evolved greatly. Both out-of-box Microsoft 365 Copilot and declarative and/or custom agents built using Copilot Studio or the Azure AI Foundry are much more capable and full-featured than what was available a year ago at launch. If you were on the fence about previously dismissed these tools, it is worth revisiting these products and mapping out functionality to your business needs.
Other times, there is an over-reliance on less-than-optimal tools (email for approval routing, anyone?) to get the work done. Eliminating or optimizing these work processes through the application of AI has immediate and valuable outcomes. Work is done faster. Capacity to do the work is increased, resulting in better utilized employees and less need to hire more people. Quality is improved by removing mundane steps from human hands. New insights are to be had through improved data analysis. And both employee and customer experience can be improved by providing faster and smarter interactions. You can measure these changes. You can observe these changes. And we can help you find them!
And pragmatism does not end with managing a project’s cost. The technology used also comes into play. While AI is still the shiny and new toy, our architects and engineers will always let you know if AI is right for you. We won’t over-engineer a solution and will suggest other automation and process improvement approaches if they are the better fit. Now, you may elect to embrace AI regardless in order to prove out its worth, but at least you will possess all of the information you need to make the right decision for your business.
Meeting You Where You AreSo, where do we find you on your 2025 journey? We have a variety of offerings that will “meet you where you are.” All our offerings are grounded in the principles of safety, security, and responsible AI and we never forget about the human impact of adopting AI, incorporating robust change management practices to ensure that your workforce appreciates how AI can be a benefit and thereby adopts the new technology and ways of working.
If you need to build an AI strategy and roadmap, our AI Action Acceleratorwill help you find and prioritize AI opportunities in your business. Or maybe you have already identified your AI initiative and now need to design and build the solution. Our Design Sprint and AI Solution Implementation offerings will turn your vision into reality. And if all of these still seem too ambitious—simply reach out and set up a free consultative session to talk and learn more about AI in 2025. Here’s to an exciting year where we learn, explore and build, together.
We Can Help!If you have questions about implementing AI in your organization or any of the concepts discussed in this article, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousUnderstanding DNS Changes in Nutanix DR Recovery PlansNextImplementing CISA’s SCuBA Project In Your CloudNextNeed Assistance with Artificial Intelligence?Contact our team of experts today!
The post Top 3 Reasons to Include AI in Your 2025 Resolutions appeared first on eGroup US.
Zerto Virtual Replication Deployments:A Comparison###### Mike Dent
Field CTO - Hybrid Data Center
With the first post in the Zerto series, I ran through the history of Zerto and some features that Zerto Virtual Replication provides. Continuing the series on Zerto with the second post, we’ll cover the typical Zerto Virtual Replication deployment requirements and compare a Windows-based deployment versus the newer Linux-based deployment. While this post will focus more specifically on VMware deployments, the terminology and concepts will mostly hold true across the different environments Zerto may be deployed within. At the core, the functionality of the Zerto product is not that much different between the Windows-based and Linux-based installations, however the direction for Zerto to move to the Linux-based appliance allowed them to accelerate features while also enhancing security within the product.
Zerto TopologyLet’s take a quick look at the topology of a Zerto deployment. With Zerto, the typical deployment will have a mirrored configuration on each of the sites, which will include a Zerto Virtual Manager (“ZVM”) server, as well as one or more Virtual Replication Appliances (“VRA”). While there is only a single ZVM per site, there will be potentially multiple VRA’s per site based on the number of Hosts that Zerto will be protecting virtual machines from.
For the VRA’s, they are deployed and pinned directly to the host they are installed on, which allows Zerto to enable replication at a Per-VM level, and pick up all changes to that VM within the I/O path on that host.
Deployment RequirementsWhile the ZVM role was historically Windows-based and the VRA’s Linux-based, starting with the release of 9.5 a Linux-based ZVM appliance was made available. While the early releases of the Linux-based ZVM will sometimes be tricky to deploy, it got much better through 9.7 as it related to feature parity with the Windows-based ZVM. Finally, with the release of v10, Zerto released only a Linux-based ZVM appliance, and the Windows-based ZVM installation was fully removed. This has also allowed Zerto to move from a monolithic application to a container-based application, giving them flexibility for development and scalability.
I’ve posted in the past about the Linux-based ZVM, but let’s take a look at why the transition from a Windows-based installer for the Zerto Virtual Manager (ZVM) to a Linux-based appliance brings several key benefits that address both operational efficiency and performance improvements. Here’s a quick breakdown of the advantages of moving to the Linux-based ZVM:
Improved Resource Efficiency
Enhanced Performance and Scalability
Faster Performance: Linux is known for being lightweight and more efficient in handling background services and processes. This results in better overall performance for large-scale Zerto deployments with many virtual machines or complex replication setups.
Simplified Security and Maintenance
Less Frequent Patch Requirements: Linux environments generally require fewer frequent patches compared to Windows, which has a regular update cadence and more critical security patches. This reduces downtime due to patch management.
Greater Flexibility and Customization
More Control Over the Environment: Linux offers greater flexibility for administrators who are comfortable working in a Linux shell. This allows for more granular control of the environment, including network settings, logging, and security hardening.
Streamlined Deployment and Management
Appliance-Based Deployment: The Linux ZVM is typically deployed as an appliance, simplifying the installation process. This reduces the complexity associated with provisioning a full Windows Server instance and installing the ZVM manually.
Compatibility and Support
Long-Term Support: With the growing adoption of Linux, Zerto’s move to a Linux-based ZVM ensures that the platform remains modern and well-supported for the foreseeable future, avoiding the potential pitfalls of legacy Windows-based installations. I want to say that the Windows-based ZVM was stable, and I rarely ran across many issues with it through deployments in the last 10 years. However, as we’re seeing more and more management functions moving to an appliance-based model, continuing to manage Windows and then the Zerto software updates, as well as a heightened security focus and simplifying the architecture—the move to Linux for the ZVM role made sense.
In this next section, we’ll do a quick comparison of the Windows and Linux-based ZVM deployments, as well as the differences between them.
Windows-Based ZVM (Pre-v10) Hardware Requirements + Processor: 4 vCPUs minimum (6-8 recommended for larger environments) + Memory: 8 GB minimum (16 GB or more for environments with higher VM counts) + Storage: 40 GB of disk space for the ZVM installation (ensure enough space for ZVM logs and potential growth) * Network: + ZVM requires access to the vCenter Server, ESXi hosts, and Zerto components over the network. + A static IP address is recommended for the ZVM server. + Ensure firewall ports are opened between the ZVM, vCenter, and ESXi hosts (e.g., TCP 443 for vCenter, TCP 4006 for communication between ZVM and Zerto Virtual Replication Appliances). * Software Requirements + Operating System: - Windows Server 2016, 2019, or 2022 supported. - Ensure the latest Windows updates are installed. + .NET Framework: Version 4.8 or higher is required. + VMware vCenter*: - ZVM is compatible with vCenter Server 6.5 and above. - Administrator privileges on the vCenter Server are required to deploy Zerto Virtual Replication Appliances (VRAs). ZVM Deployment StepsLet’s quickly review the installation steps for the deployment of Zerto prior to version 10.
Download the Zerto Virtual Replication (ZVR) installer from the Zerto website.
Download the latest ZVM appliance OVF template.
Connect to the management interface of the ZVM appliance (https://
Zerto AuthenticationAuthentication for Zerto with the Windows-based ZVM was done through vCenter rather than using any direct authentication by Zerto. This allowed Zerto to natively integrate with any authentication providers that vCenter was using, whether it be local accounts within the vsphere.local SSO domain or an external provider, such as LDAP or AD Authentication that was currently in use. While this was easy, it did not allow for easy additional security functions, such as MFA or identity sources not directly supported by vCenter. It’s also required that vCenter was available to be able to log into the Zerto GUI.
With the appliance deployment, Zerto removed the reliance on tying into vCenter for authentication and instead moved to a centralized authentication method using the open-source identity and access management solution, Keycloak. Keycloak now provides the authentication to Zerto, allowing organizations to create locally significant roles and users, configuring LDAP and/or Kerberos authentication and leveraging the built-in Keycloak MFA provider to add additional layers of security.
Upgrading ZertoFinally, let’s talk about the process of upgrading Zerto. With the legacy Windows-based deployment, administrators would patch Windows through normal mechanisms (Windows Update, WSUS, Admin Center, etc.), and then download and install the Zerto software separately. With this version, while there was a notice in the Zerto console about version upgrades, there was no automated upgraded process for the ZVM role, and thus required manual intervention. This did not have any sort of online requirement, so it was very easy to work within a dark site if required.
With the appliance-based deployment, we now have a fully automated upgrade process from the Zerto Management Console. This upgrade process not only handles the updates for the Zerto software, but also handles the Debian OS updates to keep the appliance secure and up to date. Due to the nature of the container deployment, this also provides a rollback function, which is really helpful. I still recommend taking a snapshot before the upgrade though!
With initial versions of the Linux appliance, working in a dark site or offline mode was not possible. Starting with version 10 update 2, Zerto now allows for the ability to work within a dark site and download the bits ahead of time, and manually upload.
Wrap-UpIn the second part of this series, we briefly looked at the deployment and some nuances between the Windows and Linux-based deployments. While the result is the same awesome Virtual Replication for Disaster Recovery, the latest releases and the Linux-based appliance deployments provide a much simpler and arguably more secure topology.
In the next part of the series, I’ll describe the process of migrating an existing Windows-based deployment to a Linux-based deployment using the Zerto Migration tool.
We Can Help!If you have questions about Virtual Replication for Disaster Recovery, or Zerto Windows and Linux-based deployments, contact our team at info@eGroup-us.com or complete the form below.
PrevPreviousNovember 2024 NewsletterNeed Assistance with Virtual Replication for Disaster Recovery?Contact our team today to get help with any of the updates mentioned above!
The post Zerto Virtual Replication Deployments: A Comparison appeared first on eGroup Enabling Technologies.
November 2024 NewsletterTable of ContentsWe’re Grateful for YOU This Thanksgiving SeasonAs we celebrate this Thanksgiving season, we want to express our heartfelt gratitude to you, our clients! This year has been filled with growth, challenges, innovation, achievements, and accolades—and we know none of it would be possible without your trust and partnership.
Your partnership has allowed us to reach new milestones and receive recognitions that truly honor the work we do together. We are thankful for the opportunity to work alongside you and for the confidence you’ve placed in us to empower your organization by leveraging technology to drive business success.
From all of us at eGroup Enabling Technologies, thank you for letting us be a part of your journey.
#TogetherWeMakeIThappen
What’s New in the Hybrid Data Center?Cisco ThousandEyes Enterprise Agents now have native support on Cisco Meraki MX devices, enhancing visibility into SaaS performance and network health, allowing for proactive network management beyond their own domain without needing extra hardware. * Cisco has introduced new AI-native features in ThousandEyes focused on Digital Experience Assurance. These advancements use comprehensive telemetry data and AI to enhance IT operations, enabling customers to move from reactive to proactive management for improved digital resilience. * Cisco Wireless: + Cisco has introduced AI-native innovations across its networking portfolio, including wireless solutions. These enhancements leverage AI to provide proactive insights and automated actions, enhancing the performance and reliability of wireless networks. Cohesity Cohesity has shifted the Long-Term Support version from 6.8.x up to 7.1. Version 7.1 provides some additional features for database protection, WORM support for Cloud Archives, and many other features! * Cohesity Data Protect-as-a-Service now includes a Microsoft 365 Backup Status Overview report, detailing the success of M365 backup operations. This report offers quick insights and supports various filters like M365 object types (e.g., Mailbox, OneDrive). Currently, this feature is in Private Preview and can be activated with Cohesity’s help. Nutanix If you’re a customer currently running VSAN-ready Nodes and have been looking to move away from VMware, Nutanix is doubling down on supporting the migration of VSAN-ready nodes, providing a flexible way to adopt the Nutanix ecosystem. * Nutanix continues to drive value to unstructured data on-premises, and with the latest Gartner report for File and Object storage, Nutanix Unified Storage (NUS) provides that value. Whether it’s SMB, NFS, or S3 storage, NUS provides performance, security, and scalability all within an easy-to-use hybrid platform. * A repeat message for November—now’s the time to start planning your migration to the latest LTS release of AOS, 6.10. Performance enhancements, additional Disaster Recovery features, and Flow Network Security enhancements make this a release to jump on NOW! Note that version 6.10 has a very specific Prism Central release, so make sure you check your version compatibility matrix prior to upgrading! Rubrik Rubrik Cloud Vault, which uses Microsoft Azure storage services, now offers Zone-Redundant Storage (ZRS) and Geographically Redundant Storage (GRS) protection options. These new options surpass the existing Locally-Redundant Storage (LRS) by protecting against single or multiple data center failures in the Rubrik Cloud Vault region. It’s strongly advised to use ZRS or GRS for data stored in Rubrik Cloud Vault. * Rubrik NAS Cloud Direct, a SaaS backup tool for NAS platforms, now supports backup, recovery, and archiving of Nutanix Files. These backups can be stored in various repositories like Rubrik Cloud Vault, customer-managed Azure, and AWS S3, as well as NFS and S3 storage systems. Pure Storage Pure has launched a fully-managed Cloud Block Store on Azure to enhance Azure VMware Solution storage with Pure Storage Cloud. This complements the existing customer-managed Cloud Block Store, which continues to offer cost savings by reducing the necessary footprint for AVS. What’s New with Microsoft?Azure Get the latest on how you can effectively manage Azure Virtual Desktop with 5 Tips for Effective AVD Management from our partners at Nerdio. * Struggling to contain costs in Azure? Let us introduce you to the Azure FinOps Library (Unlocking Azure Savings) and the latest iteration of What is New in the FinOps Toolkit 0.6. * Azure VMware Solution has another option for the “right fit” between Compute/Memory and Storage with the addition of Elastic SAN for AVS. Above you can see how Pure Storage is an alternative for meeting your storage needs. Elastic SAN provides yet another option. * Gain better data privacy and less latency with the general availability of ExpressRoute Metro services. * Business Continuity and Disaster Recovery (BCDR) is a primary use of Azure Infrastructure. For those looking to enhance the management of their BCDR capabilities, take a look at the public preview of the Azure Business Continuity Center (ABCC). The 5-part series details the evolution of BCDR in the cloud and how you can enhance your control and management. * With a new Azure Backup public preview, you can now enable Immutable WORM storage for your backups when you lock immutability on the Recovery Services Vault. Defender for Office 365 Outlook for Mac introduced new reporting buttons for phishing, junk, and not junk emails, controllable by admins via the Microsoft 365 Defender portal. * Microsoft’s Secure Score recommendation for Spam confidence level (SCL) in Microsoft Defender for Office 365 will be updated. The recommendation will only trigger if a transport rule explicitly sets SCL to -1. The rollout will complete by December, and may increase the Secure Score. Defender XDR The “Alert notifications” feature in Microsoft Defender for Identity will retire, replaced by Incident email notifications in Microsoft Defender XDR. Existing settings must be transferred to avoid disruption. * Defender for Endpoint will update the InitiatingProcessFolderPath to include file names, affecting all Advanced Hunting tables. Organizations should adjust custom detection rules and queries accordingly. The change applies only to Windows activity. Entra ID Get all of the details on the new Microsoft Entra Suite and the problems it solves for your organization with our blog and webinar recording! * Starting mid-January 2025, organizations with enabled passkey (FIDO2) policy and no key restrictions will have passkeys in the Microsoft Authenticator app. Users can add this via aka.ms/MySecurityInfo, and it’s enforced by Conditional Access policy. Organizations can opt out with key restrictions. * B2C update: SMS is now generally available as an MFA method for external accounts. This supports enhanced methods for MFA for your external account authentication.Read more here. Exchange Online Exchange is enhancing bulk email filtering with recalibrated bulk sender distribution across different bulk complaint levels (BCL). New BCL recommendations are 7 for default/standard, and 5 for strict policies. Admins should adjust BCL settings accordingly. Forms Forms is getting a new, modern experience with an updated portal page, form creation, and response analysis. Look for organized templates, a selection of styles, and results analysis with charts and graphs. * Forms will introduce a new data sync to Excel for the web, replacing the older version by January 13, 2025. Users must manually update to the new solution before this date. Intune Intune will end support for Android device administrator on devices with Google Mobile Services access by December 31, 2024. Users should stop enrolling devices with this method and migrate to alternative management methods. Intune will not update or support these devices after the end date. * In April 2025, Intune will stop supporting custom profiles for Android Enterprise personally-owned work profile devices. Admins should transition to equivalent settings in the Intune admin center. * Pain point fixed: Latency when adding an Enterprise App to the catalog is reduced by adding a direct link rather than duplicating app binaries. Read more here. * GCC and GCC HIGH update: Defender for Endpoint settings support is now generally available. You can use Intune now to manage Defender for Endpoint in the Gov Cloud. * The Windows Autopatch experience is now available, with update management moved to a new section and Autopatch groups relocated. The service unifies Autopatch and Windows Update for Business. Loop Loop will allow guest sharing for all tenants, including those with sensitivity labels, after a rollout in December. Admins can configure policies for B2B guest sharing in SharePoint, and users can share Loop components with external guests, respecting existing OneDrive and SharePoint settings. * Microsoft Loop will introduce container-level sensitivity labels by December, enhancing security features for organizations using Microsoft Information Protection. Microsoft 365 Copilot Declarative Agents will be available by late November in Word and PowerPoint Web, allowing users to customize Copilot. Users can install and interact with these agents via Teams or the Microsoft 365 Admin Center. No admin action is required before rollout. * Copilot Pages should now be available for users with an Entra account and SharePoint license to allow for collaborative and persistent workspaces in Copilot chat. * Microsoft 365 Copilot will soon allow users to share BizChat prompts via a link, starting in late November. Licensed users can share prompts on the Copilot Lab website, and admins can export these prompts. * Web mode is being released for Copilot in Teams and Outlook, with full rollout by late November. Users can switch between Web and Work modes like in BizChat, with no admin action needed for the update. * The Microsoft Graph API will soon include Copilot usage metrics, enabling customized reporting and analytics. The rollout begins in September for Public Preview and March for General Availability. * By mid-January, Copilot retention policies can be separated from Teams chats, allowing admins to create distinct retention policies for Copilot interactions. * OneNote for Win32 introduces Copilot quick actions on the canvas, including Rewrite, Summarize, and Todo. Rolling out by mid-December. * There’s an early preview of new Graph connectors, including GitHub, Google Drive, and others. Sign-ups for the preview are open via a form or email. These connectors allow indexing of third-party content, enhancing search capabilities across Microsoft Search clients. * The Copilot Dashboard update allows global admins to manage access using Microsoft Entra ID Groups. Tenants with certain license counts will have full or limited dashboard features. * Microsoft 365 Copilot now integrates with SharePoint organization asset libraries, allowing direct access to brand assets in PowerPoint and Word. * By default, people can prompt Copilot about “sentiment of the meeting” and other inferences. Admins can now turn off that capability so that only facts are reported. See the roadmap for more info. * Copilot in Edge will reintroduce page summarization and contextual prompt suggestions for users signed in with a Microsoft Entra account or using Copilot in web mode. Admins can configure the feature. * Themes by Copilot will be available in Microsoft Outlook, allowing users to create themes inspired by global locations or their current surroundings. * Copilot now auto-generates a document summary when opening a file in Word. Users can hide it. * Look for the “Allow Web Search in Copilot” policy, enabling separate management of Bing searches in Copilot from other optional connected experiences. This can be configured at the user/group level. * Microsoft 365 Copilot Business Chat will enable chart, graph, and data analysis creation via prompts, via Python code. Outlook (New) Outlook is updating the My Day pane to allow users to view and edit work hours and location. * Users can now create events by dragging emails into the Calendar icon. Outlook Mobile Microsoft Outlook on iOS and Android now opens standalone Microsoft Office apps instead the Microsoft 365 app for opening document files. * Outlook for iOS and Android will soon support choosing fonts while composing and improve font support for reading emails, with rollout completion by early December. * Outlook’s handling of PDFs with Purview Information Protection labels on iOS/Android is updated. Users will be prompted to open such PDFs in the Microsoft 365 app. Users should be advised. Places The Microsoft Places app will be enabled by default starting in December, helping people coordinate in-office days with colleagues. It’s accessible via web, Teams, Outlook, and Microsoft 365 app, with added features for Teams Premium users. Power Platform Look for the Security page in the Power Platform admin center. It is a centralized location for managing security recommendations, evaluating your security score, and implementing policies. * Customers can use their own encryption key for encrypting data at-rest for existing environments with flows in Power Automate, helping meet data and privacy policy guidelines. * The prevent data exfiltration by securing app access feature is available. This will allow admins and makers to protect against data exfiltration by controlling what apps can be run in your Dataverse environment, and help to prevent malicious users from creating or using unapproved apps to export. Purview A Purview DLP analytics feature is available, providing weekly recommendations to enhance data protection. Users can turn on analytics, which spotlight risks and fine-tuning policies. * Public Preview has begun for Communication Compliance’s enhanced policy alerts. Expect improved capabilities and customization options, allowing admins to adjust alert frequency and recipients. * Purview Information Protection will soon integrate Advanced Message Encryption with Message Recall in Outlook, allowing licensed users to recall encrypted emails. * Purview’s compliance portal is being updated to introduce a new schema to track Power Apps and Power Platform Connector activities, logged under the PowerPlatformAdministratorActivity activity type. * Microsoft Purview Insider Risk Management will soon support bulk upload for priority user groups. * The rollout of default sensitivity labels and policies enhancements for Microsoft Purview Information Protection now includes meetings, in addition to files and email. SharePoint SharePoint will enable approvals for document libraries by December 2024. Users can configure approvals in the Automate menu, with in-progress approvals viewable in Teams. * SharePoint is introducing coauthoring for Pages and News, allowing multiple authors to edit simultaneously with real-time changes. * Design Ideas are now available in Microsoft SharePoint, allowing page authors to enhance sections with new layouts and formatting. * The SharePoint SendEmail API will be retired on October 31, 2025. Update any components using this API with alternatives like Microsoft Graph or Power Automate’s Outlook connector for email. * SharePoint list and library rules’ automated emails will now be sent from no-reply@sharepointonline.com with the display name “SharePoint Online.” Teams Chat and Channels A new chat and channels experience is coming between mid-November 2024 and late April 2025, streamlining conversations and management across different locations. This update excludes Education tenants. * Teams will add skin tone settings and reactions to personalize emojis and reactions by late November. * A block-user feature will allow admins to prevent malicious users from contacting the organization again, by mid-December. Admins need to turn on and configure the block list in external access settings. * Teams has a new onboarding process for teams and channels, where team owners can recommend channels, and team members will initially see only the ‘General’ channel upon joining a team. Teams Meetings The new Microsoft Teams policy, ‘csTeamsAIPolicy,‘ will default to enabling voice and face enrollment, and replace the ‘csTeamsMeetingPolicy’ in mid-January. Admins should configure settings before then. * Teams on the web will soon allow users to take control during screensharing, a feature already available on the desktop version. Look for rollout by mid-January 2025. * Teams is introducing CAPTCHA verification for anonymous meeting participants, with rollout by mid-November. Tenant Admins must enable this feature in the Teams Admin Center. * Teams is introducing a new ‘Event chat’ feature for Premium town halls, allowing all participants to chat during the event. It supports a large number of users and messages. Organizers can disable this feature. * Teams is increasing meeting passcodes from 6 to 8 characters for enhanced security, by late November, with no admin action required. External users joining with a Meeting ID and passcode will be affected. Teams Phone The Quality of Experience Report v5.0 for Teams Call Quality Dashboard in Power BI is now generally available, featuring new intelligent media quality classifiers and an updated design. * Survivable Branch Appliances are being updated to extend their certificate expiration lifetime to 7 days, meaning if an outage occurred 23 hours after the last refresh, the SBA would continue to function for another six days, one hour (as opposed to just one hour). It’s a mandatory patch for AudioCodes SBAs. Teams Premium Meeting organizers with Teams Premium licenses will be able to prevent participants from copying chat, captions, transcripts, and AI-generated insights by early 2025. No admin action is required. * An Intelligent recap for ad-hoc meetings and calls, allowing users to access AI-generated notes, tasks, and mentions post-meeting, will roll out by January 2025. Windows 2025 Windows Server 2025 is generally available, offering advanced security, improved performance, and cloud agility. Deploy for apps in any environment, whether on premises, hybrid environments, or cloud. Conclusion*If any of these updates or changes pose as a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousAccelerating Redaction and Enhancing Compliance: How AI is Transforming Document Management in Higher EducationNeed Assistance with These Updates?Contact our team today to get help with any of the updates mentioned above!
The post November 2024 Newsletter appeared first on eGroup Enabling Technologies.
Accelerating Redaction and Enhancing Compliance: How AI is Transforming Document Management in Higher Education###### Mehran Basiratmand, PhD
CIO Strategic Advisor
Recently, the case study Harnessing Custom-Built AI to Accelerate Redaction and Drive Efficiency for the University of Pittsburgh articulated the successful use of AI to accelerate artifact redaction. The opportunity to implement a similar solution in various other support units within higher education institutions is worth further consideration given the importance of redacting various documents that pertain to FERPA and HIPAA-related requirements.
There are ongoing efforts to streamline workflows and document management processes across organizations. Specifically, in higher education, the organic nature of technology consumption and solution adoption in various support units lends itself to departments being technology-rich while others operate in a technology debt. One of the promising tools that could pave the way for a more consistent and balanced use of technology is AI. While in the early stages of development, expectations and understanding of its potential are forging.
Custom-Built AI Tools in Higher EducationA great example is the case at the University of Pittsburgh. Their custom-built AI tool accelerates the artifact redaction process, introduces automations, enhances their security posture, and establishes a consistent mechanism for document management. Other institutions have been interested in implementing the same technology, which is a unique solution in the marketplace.
UPitt’s initial focus was to use AI to redact documents in the Division of Research; however, its application and processes could be easily duplicated within other higher education departments including, but not limited to the: Office of Admissions, Registrar, Financial Aid, Student Services (including Health Clinics), Libraries, Legal, Housing, Compliance, Academic Departments and Colleges, University-Hospital, Foundations, Information Technology, Teaching and Learning, Technology Transfer (IP), Academic Affairs, Financial Services, and Athletics.
Each of the aforementioned departments generally utilize SIS and ERP systems, as well as other secondary or specialized systems (CRM, Housing, Legal, Foundations, and more). There are manual processes that exist to extract Personally Identifiable Information delivered via emails, forms, shared drives, and external systems. These documents are required to be placed into one of the systems outlined above for processing as well as archiving to address record retention schedules.
In most cases, the document remains in the original system and gets incorporated into thousands of other documents and emails that are part of the employees’ file system.
This poses three levels of potential exposure:
The process of applying redaction will reduce the potential harm of exposing any sensitive information. For the departments with the highest need and the lowest level of automation, this AI redaction tool diminishes the threat of overexposing sensitive information. Furthermore, this brings each department closer to meeting the compliancy and protection requirements outlined by reaffirming or modifying departmental document retention schedules, artifact sensitivity management, and preparing departments for larger scale AI adoption.
This AI redacting tool is developed in tandem with artifacts inside a Microsoft tenant, notwithstanding the current licensing tier. There are some Azure cloud consumption costs associated with this solution.
We Can Help!If you have questions about implementing a similar solution within your higher education institution, contact us at info@eGroup-us.com or complete the form below.
PrevPreviousNonprofit Response to a Ransomware Incident: Tabletop Exercise ResultsNextNovember 2024 NewsletterNextNeed Assistance with Custom-Built AI Tools in Your Institution?Contact our team today to get help with any of the updates mentioned above!
The post Accelerating Redaction and Enhancing Compliance: How AI is Transforming Document Management in Higher Education appeared first on eGroup Enabling Technologies.
Nonprofit Response to a Ransomware Incident:Tabletop Exercise Results###### Chris Stegh
CTO & VP of Strategy
Interested in comparing your ability to respond to cyber incidents to other nonprofits?
This blog provides details of the results from a crowdsourced tabletop exercise led by our Strategic Advisory team. We asked nonprofits from around the globe questions about how they’d handle a ransomware incident. We then analyzed their responses.
Here, you’ll find poll results and discussion about the good, the bad, and the gaps.
Why are we sharing this data? In many nonprofits, incident response plans either don’t exist, are lacking, or don’t often get stress tested—in spite of the fact thatthe Ponemon Institute found that lost business costs due to data breaches averaged $1.42 million in 2022.
This article also gives some insights into how a tabletop exercise works. Read on if you’re curious about how your cyber incident response measures up.
Scenario 1: RansomwareWe posed the first question to replicate an all-too familiar incident.
“At 4:30pm on the Friday of a holiday weekend, the service desk receives several calls with users reporting that they have a skull and crossbones message mentioning bitcoin on their screens. System access is disrupted for all employees, including the phone system. The attacker’s instructions include a $1 million ransom demand for the decryption tool. They have given you 48 hours to pay before the data on your systems is destroyed.”
Question 1.1: Would You Know Something is Wrong?In this case, tools matter. That’s why 84% of participants with a Security Information Event Management (SIEM) and User and Entity Behavior Analysis (UEBA) tool believe they’d have a chance of detecting the incident.
But 48% (16+32) of respondents are right not to be too sure.
Why?
Unless alerts and automated remediations are in place to shut down the first signs of compromise (i.e., escalating privileges) without human intervention, encryption may be applied swiftly and silently.
It’s a safer approach to assume breach and be prepared to recover.
Question 1.2: What Would You Do First?Now that responders are aware of an issue, they responded in the following way:
Those that would disconnect the affected devices right away would be wise to get approval in advance from business leadership before isolating a critical system. That’s a key aspect of the most common answer, e.
Question 1.3: Do You Have a Tool to Analyze the Logs?Tabletop leaders would then ask some logical steps about the expected process….
Question 1.4: What Do You Do Next?B (segmenting the network) is easier said than done, so in a real tabletop, the next questions would include, “Who,” “How,” and “With whose authorization?”
E is an excellent answer, but a breach coach won’t engage quickly without a preexisting incident response contract.
Question 1.5: Do You Have a Way to Roll Back/Restore the Systems Before the Compromise?Solid answer!
In an actual tabletop exercise, the next step would again be exactly “who” and “how” would reinstate the systems, but as importantly, “when?” Business leaders will want to reinstate service as soon as possible, but it’s critical for the incident response team to ensure that the intruder is no longer in the environment (and that backups themselves are not affected).
The importance of ensuring that backups are not compromised and testing them regularly cannot be overstated. It’s the best insurance policy.
Question 1.6: Do You Have a Way to Pay the Ransom?The answer was interesting in that as many people are ready to potentially pay the ransom as those who never would. In either case, cyber insurance providers will expect you to open a claim prior to paying for a ransom (and they will not pay with their own bitcoin).
Question 1.7: The Process for Responding to This Incident is…No matter how the previous questions have gone, our final question for any incident is to see how repeatable and rapid it would be.
Props go to the 43% of participants that take ransomware seriously enough to document a playbook! Even more applause to the 12% who have tested the recovery!
More than we’d like to admit, we hear that incident responders store their plans “in their heads.” They’re not in a binder or offline soft copy. They’re neither known nor accessible by their peers or successors. We trust that those folks now have some proof to management that investing time and resources in such efforts is necessary.
For those well-prepared organizations, a good tabletop coordinator would typically inject a curveball, an unforeseen and potentially bizarre situation. In this case, had our collective audience passed the previous tests, we’d ask, “Question 1.8. The ransomware compromise is publicized on Facebook by an employee who brags that they’ve gotten the day off due to the computers being down. What’s next?”
Question 1.8: What Did You Learn?At the end of each scenario, it helps to ask all participants to share their thoughts. Some of our respondents obliged when we asked the crowd. Assembled in a word cloud are their responses.
I’d like to point out one comment, “Lots of work.” While yes, that will make an optimal response possible, starting with incremental improvements (especially backups and restoration processes) is not an option. Perfect shouldn’t be the enemy of good.
SummaryFEMA, NIST, CISA, and the White House are imploring organizations to practice their response to ransomware. Some cyber insurance carriers are starting to require it.
The media and legal communities love to highlight those that don’t.
It’s impossible to understate the importance of practicing and adapting to different scenarios in disaster response. Here are some takeaways…
Dos and Don’ts:
– Do practice and identify gaps in your response plan.
– Do communicate effectively with your teammates.
– Do share your thoughts and lessons learned after each tabletop scenario.
– Don’t let perfect be the enemy of good. Get started in some way today!
– Don’t rely solely on documentation or protocols. Teamwork and practice are key.
– Don’t ignore the feedback from the line of business participants. They own this too!
We Can Help!If you find yourself without the time or authority to execute an internal tabletop exercise or make progress closing your gaps, our Strategic Advisory team is at your disposal. Contact us at info@eGroup-us.com or complete the form below.
PrevPreviousInc. Names eGroup Enabling Technologies as a 2024 Power Partner Award WinnerNextAccelerating Redaction and Enhancing Compliance: How AI is Transforming Document Management in Higher EducationNextNeed Assistance with Tabletop Exercises for Your Nonprofit?Contact our team today to get help with any of the updates mentioned above!
The post Nonprofit Response to a Ransomware Incident: Tabletop Exercise Results appeared first on eGroup Enabling Technologies.
Inc. Names eGroup Enabling Technologies as a 2024 Power Partner Award Winner
The annual list recognizes the country’s leading B2B companies that have proven track records of supporting entrepreneurs and helping companies grow.
Charleston, South Carolina, October 22, 2024 — Inc., the leading media brand and playbook for the entrepreneurs and business leaders shaping our future, today announced its third annual Power Partner Awards.
The prestigious list honors B2B organizations across the country that have proven track records supporting entrepreneurs and helping businesses grow. This year’s list recognizes eGroup Enabling Technologies among 359 companies in technology, marketing and advertising, health and wellness, financial services, legal, logistics, public relations, and productivity, as well as other critical areas of business.
Every company on the Inc. Power Partner award list received top marks from clients for being instrumental in helping leadership navigate the dynamic world of startups. These B2B partners support entrepreneurs across various facets of the business, including hiring, compliance, infrastructure development, cloud migration, fundraising, etc., allowing founders to focus on their core missions. “This is our definitive listing of vendors and suppliers who have demonstrated excellence in serving small- and midsize customers,” says Inc. Editor-In-Chief Mike Hofman.
"As part of the vetting process, our team of editors, researchers and reporters gathered information on companies’ products and services, assessed their reputation as captured in online comments and forums, and collected customer testimonials to ensure that the sales pitch matches the actual client experience. In every case, we spoke to founders like you who were happy to attest to a vendor’s genuine commitment to a mutually beneficial business partnership. We’re happy to be the conduit for that positive word of mouth.”"
– Mike Hofman, Inc. Editor-In-Chief
"We are honored to be recognized with multiple prestigious accolades so far this year, including the Channel Futures Next Gen List, CRN MSP 500, CRN SP 500, CRN Tech Elite 250, The Software Reports Top 25 Cloud Computing Companies of 2024, Channel Insider’s Hybrid Solution Provider 250, the Inc. 5000, and now the Inc. Power Partner Award!
These achievements highlight our unwavering commitment to delivering innovative, impactful technology solutions and the exceptional level of service we provide to our clients. Our clients' success is at the forefront of everything we do and we're grateful to work with a lot of amazing businesses and individuals across the nation."
– Carly Picciuto, Director of Marketing- eGroup Enabling Technologies
Each award underscores the breadth of their expertise, from managed services and hybrid infrastructure to cloud computing and digital transformation. These recognitions are a testament to the team’s dedication to staying ahead of industry trends, fostering strategic partnerships, and delivering tailored solutions that empower organizations to achieve more.
Organizations seeking a trusted partner should look to these accolades as a reflection of a proven track record. Partnering with eGroup Enabling Technologies means gaining access to the industry’s top talent, cutting-edge technologies, and a team that is as invested in your success as you are. These recognitions not only celebrate their achievements but also inspire them to continue raising the bar in service excellence and innovation.
About eGroup Enabling TechnologieseGroup Enabling Technologies is a leading provider of IT solutions and an award-winning MSP specializing in empowering organizations to leverage technology for business success. With a team of experts and a customer-centric approach, their team offers a wide range of services, including cloud, hybrid data center, security, data and AI, collaboration, and managed services.
Partner with their team to streamline your IT operations, reduce costs, and focus on what you do best—growing your business– Transform your IT into a strategic advantage.
About Inc.Inc. is the leading media brand and playbook for the entrepreneurs and business leaders shaping our future. Through its journalism, Inc. aims to inform, educate, and elevate the profile of our community: the risk-takers, the innovators, and the ultra-driven go-getters who are creating our future. Inc.’s award-winning work achieves a monthly brand footprint of more than 40 million across a variety of channels, including events, digital, print, video, podcasts, newsletters, and social media. Its proprietary Inc. 5000 list, produced every year since its launch as the Inc. 100 in 1982, analyzes company data to rank the fastest-growing privately held businesses in the United States. The recognition that comes with inclusion on this and other prestigious Inc. lists, such as Female Founders and Power Partners, gives the founders of top businesses the opportunity to engage with an exclusive community of their peers, and credibility that helps them drive sales and recruit talent. For more information, visit www.inc.com.
To view the complete list, go to: https://www.inc.com/power-partner-awards/2024
Contact Our Team!Looking to team up with experts who have 30+ years of experience delivering successful outcomes in areas such as cloud migrations, productivity and collaboration, security, consulting, data and AI, and organizational change management?
Fill out the contact form and our team will be in touch shortly!
The post Inc. Names eGroup Enabling Technologies as a 2024 Power Partner Award Winner appeared first on eGroup Enabling Technologies.
Enhance Your Security with the New Microsoft Entra SuiteMicrosoft Entra has introduced a new tier of capabilities within its identity management and security tools. This new tier focuses on enhancing advanced access management, security, and identity to support Zero Trust principles, while also addressing integration gaps that pose risks for businesses. I speculate that it is likely that an E7 tier licensing bundle will be available soon to accommodate the ongoing expansion and flexibility of the Microsoft 365 Productivity, Security, and Compliance platform.
In this blog post, I’ll briefly touch on what each of these new capabilities are and the benefits of each in simple terms.
Core Capabilities of the Microsoft Entra Suite Private Access – Works with your conditional access policy to provide secure access to on-premises applications. This is done by an agent on the endpoint device in coordination with a connector on the private network that allows on-demand secure access with outbound connections only. * Internet Access – Prevents access to unsafe content through Microsoft and admin-specified web content filtering rules. This extends your conditional access policies to internet content with things like device location, behavior patterns, and other conditional access policies to continuously evaluate the security threat. * ID Protection – Builds upon traditional Entra ID controls, such as multi-factor authentication, leveraging signals from endpoint management for device compliance, and other risk-based controls. ID Protection extends that with ML-based adaptive controls and user risk assessments to develop usage trends that continuously analyze risk for anomalies. * ID Governance – Supports identity and user lifecycle management with automation capabilities to ensure you implement least privilege access to individuals by managing their employment lifecycle from onboarding and job changes to offboarding. * Face Check with Verified ID – Leverages facial biometrics to ensure the person presenting a government-issued ID is who they say they are. How Are These Features Beneficial to My Business? Private Access – Flexible access from private/public and known/unknown networks without legacy VPNs. * Internet Access – Secure web gateway capabilities allow for conditional access settings to internet sites, ensuring that users can only access to approved sites when on trusted devices and locations. * ID Protection – Advanced machine learning provides insight into real-time threats that allow for rapid response. * ID Governance – Automated workflows integrated with HR platforms, device lifecycle, etc. to assign users permissions to applications based on their employee attributes with automated revocation of access during offboarding. * Face Check with Verified ID – Enhanced capability to identify people are who they say they are locally or remotely without compromising their personal information and meet compliance standards. How Does Entra Suite Vary from Entra ID (Plan 1 and Plan 2)?**Entra ID Plan 1 and Plan 2 are included in Microsoft 365 bundles and available separately. Entra Suite, only offered as a standalone product, costs $12 per user per month and requires a Microsoft P1 license. Discounts are offered for users with Entra ID P2.
Choosing the Right Microsoft 365 Packages and Solutions For Your BusinessAs you’ve heard me say in prior blog posts, “It depends” is the honest answer anyone should give you at the start of the conversation. Building on our Microsoft 365 E5 post, including Entra Suite must be evaluated based on the needs of the business, current solutions in place, and ability to implement new technology once procured. It should be part of a planning and roadmap exercise to ensure the successful implementation of zero trust across the full Microsoft security platform and any third-party solutions you have in place.
Don’t Leave Incentives on the TableThere are incentives in the form of discounts, implementation support, educational workshops, and concierge guidance available for businesses of all sizes. Include those in your planning and ensure you get the maximum value out of your planned investments.
The Microsoft 365 Productivity, Security & Compliance RoadmapThe Microsoft 365 Roadmap is an active workshop designed to support a business looking to understand how an investment in Microsoft 365 solutions can increase productivity, security, and management time for their end users. It’s perfect for those looking to get the right fit for their Microsoft licensing, while also ensuring they get the greatest return on capabilities procured.
The outcomes of the Microsoft 365 Roadmap are:
Where does Entra Suite fit my business?
We Can Help!If you have any questions about the new Entra Suite or are looking for assistance with enhancing advanced access management, security, and identity, please reach out toinfo@eGroup-us.comor complete the form below.
Looking to learn more? Check out our recent Halloween webinar, Nightmare on Cyber Street: Protecting Devices and Identities, where we covered the details of the new Entra Suite and Intune Suite.
PrevPreviousExecutive Considerations for Data Governance with Microsoft PurviewNextInc. Names eGroup Enabling Technologies as a 2024 Power Partner Award WinnerNextInterested in Learning More about the New Entra or Intune Suites?Contact our team today to learn more about the new Entra Suite or to Sign Up for a Microsoft 365 Productivity, Security, & Compliance Roadmap!
The post Enhance Your Security with the New Microsoft Entra Suite appeared first on eGroup Enabling Technologies.
Executive Considerations for Data Governance with Microsoft PurviewImplementing Microsoft Purview to help govern your data is a strategic decision that requires thoughtful scoping and planning. Purview implementations look quite different from company to company, and the balance between security, usability, policy, and automation will be unique. I would like to share some important considerations that technology and business leaders need to keep in mind when determining when and how to sponsor a data governance initiative in their organization. Your reasons for undertaking the effort and what resources you must commit to it are critical to both the decision and a successful outcome.
Why Sponsor Or Support A Data Governance Project?External Drivers Compliance Regulations: Government-mandated industry compliance frameworks such as CMMC, GDPR, HIPAA, FINRA, or CJIS all have data governance requirements, most often for enforced retention and data classification policies. * Breach Disclosure Laws: Most countries and almost every US state have breach disclosure laws that require notification to those impacted by a breach of their personal information. * Cyber Insurance Requirements: More and more cyber insurance carriers are recommending customers have basic data governance controls like encryption and data loss prevention in place to help qualify for coverage. * Customer Requirements: Increasingly, corporate and government vendor management and purchasing teams have started asking (and sometimes requiring) their vendors to have information security and data governance controls in place in order to be awarded business. This is happening across both regulated and non-regulated industries. Mitigate Data Risks Stale and Over-Retained Data: If old, unneeded, or unvalued sensitive data is exfiltrated, it still requires a disclosure. Retention and disposal policies are often incompletely implemented, and Purview can help automate the enforcement of your policies. * Over-Permissioned Data: Similar to stale data, over-permissioned or over-shared data presents risks over time. Data classification controls and right-sized sharing policies can help reduce the chance that data is inappropriately accessed by accident or intentionally. * Unencrypted Data: Data labels can protect files and email with encryption that restricts who can access a file, even if it has been shared or sent outside the company. In some cases, exfiltrated data can even be rendered unusable to an attacker. * Data Loss Prevention: Data leakage can occur through simple errors or insecure business processes. Real-time scanning, labeling, and restrictions on data can stop leakage while allowing legitimate use and sharing. (The cost of one mistake can be significant.) Modernize and Secure Collaboration Tools Traditional Access Control Lists Are Not Enough: Modern collaboration tools rely on co-authoring, versioning, and sharing. This makes traditional access control lists difficult to manage, often leading to multiple, overshared copies. Protecting SharePoint, OneDrive, Exchange, and Teams content with integrated Purview labels and policies allows individual files and messages to be protected and retained, regardless of location. * File Server Limitations: Backing up, retaining, and auditing data use on file servers is at best onerous. Moving files to tenant services allows easier collaboration, increases visibility, and provides more protection options. * Modern AI Tool Access: Copilot can only access and consider corporate data if it resides in the Microsoft 365 tenant– and speaking of AI… Copilot and Other AI Tool Enablement and Visibility Provide Certainty That Data Is Secured: Often the biggest worry that prevents widespread AI and Copilot usage is not having confidence that Copilot may expose inadvertently over-permissioned information. Purview can help mitigate that risk by helping control the content that employees, and therefore Copilot, can access. * Dated, Redundant Data Gives Inaccurate Results: Proper retention of active data and removal of stale data increases the accuracy of Copilot responses. * AI Visibility: The Purview AI Hub and Copilot-specific policies help provide visibility into AI usage and can block sensitive data from being shared with external AI tools. What Do You Need To Commit To?Improve Data Policies and Usage Guidelines Acceptable use, data classification, and retention policies that define how to use labels, how to share data, and what not to do with data need to be updated and clarified. * Coordinate with legal, compliance, and business processes owners to ensure new policies and acceptable use guidelines align with their requirements. * To the extent you can, keep policies simple so they are easy to understand and follow. Complexity and usability need to be balanced. Provide Resources and Time Purview will require an “owner” with time to create and manage the data governance program along with an understanding of how the organization uses data. Adding this to an already overburdened technology group is usually not the answer. * Data owners and business unit teams will need to help define what sensitive data they have, how they use it, and commit to improving processes that handle data insecurely. (This is often more difficult than establishing the technical controls.) * Realistic expectations will need to be set. A full Purview rollout takes time to complete, and there are few shortcuts. Sensitive information policies will need to be tuned, improvements will be required as the deployment progresses, and employees will need time to be trained and brought along on the journey. Adoption and Training Data governance and Purview will impact most employees to some extent. The need for a comprehensive and thoughtful communication and training effort cannot be understated. Business processes may also need to change, and that can also take time. * Find the groups in the organization that inherently see the value of data governance and start with them. Ask them to be your data governance success stories and evangelists. Human Resources, Payroll, Finance, and Legal are often more aware of risks and regulations, and therefore often look for better ways to protect their data. Next Steps A Pilot: A good way to kickstart data governance with Purview is to execute a pilot initiative to help understand the Purview toolset and make policy configurations to audit and protect common sensitive data types. Understand what is possible and how it aligns with your organization’s needs. * Define Success: What would a successful data governance program look like in your organization? What data is impacted? Who is impacted How do you balance usability and governance? The answer will be unique to your organization and its culture. * Start to get to know more about how business units use data, what their processes are, and what you need to do to start reducing data risks. We Can Help!My colleagues and I help organizations with pilot efforts, Purview configurations, policy reviews, and other data governance initiatives all the time. We also have an award-winning Organization Change Management** team to help lessen the fear and burden of change for end users. Let us know if we can help you get started!
PrevPreviousOctober 2024 NewsletterNextEnhance Your Security with the New Microsoft Entra SuiteNextNeed Assistance with Data Governance?Contact our team today to get help with any of the updates mentioned above!
The post Executive Considerations for Data Governance with Microsoft Purview appeared first on eGroup Enabling Technologies.
October 2024 NewsletterTable of ContentsWhat’s the Buzz at eGroup Enabling Technologies?October is Cybersecurity Awareness Month!Cybersecurity Awareness Month is an international initiative that empowers individuals and businesses to protect their data from cybercrime. Even amidst large-scale data breaches and cyberattacks, Cybersecurity Awareness Month reminds everyone that there are simple, effective ways to keep yourself safe online, protect your personal data, and ultimately help secure our world.
Check out these helpful resources to learn how to protect your business effectively:
Register to attend our Nightmare on Cyber Street: Protecting Your Devices and Identities Webinar, happening on Thursday, October 31st at 2PM EST. Discover how the Intune and Entra Suite value-packed bundles can protect your devices and identities from the ghouls and goblins of the digital world.
Download our Mapping NIST CSF 2.0 to Microsoft Security Services eGuide, built for those who value tools that work together, rather than managing separate platforms.
Check out our blog post, Securing What Really Matters. We believe in taking a proactive approach to protecting, detecting, and responding to incidents for our customers, and this article shares some of those practices.
Learn how Microsoft Security Workshops can provide insight into security and protection services that fit the needs of your organization.
What’s New in the Hybrid Data Center?Cisco Cisco continues to expand its AI-native security solution, Hypershield. This architecture integrates security directly into network and compute fabrics, offering autonomous segmentation and protection from emerging threats. By leveraging hardware accelerators like DPUs, Hypershield enhances security across data centers, cloud, and edge environments.
* Cisco released the 1200 Series of SD-WAN-enabled firewalls, which provide up to three times the performance of traditional solutions, combining routing, switching, and security functionalities. This update also includes new features in Cisco’s Firewall Threat Defense (FTD) 7.6, offering advanced protection for AI applications and zero-day threats.
* Cisco expanded its AI collaboration with NVIDIA through the Nexus HyperFabric AI Clusters, specifically targeting generative AI workloads. This simplifies AI deployment and management across hybrid cloud environments, making it more accessible for enterprise data centers.
* Cisco rolled out enhanced observability features in its ThousandEyes platform and across its networking portfolio, enabling AI-powered insights that improve operational efficiency and security.
Cisco Meraki Meraki released the MX18.2 firmware for its MX security and SD-WAN appliances. This update improves throughput for branch networks and strengthens your security posture by offering enhanced real-time steering capabilities and better resilience and scalability.
* Meraki’s Secure Connect platform now integrates with Cisco’s Secure Access, a cloud-based security service. This integration helps organizations implement zero-trust models more effectively, offering advanced security for remote workforces across hybrid environments.
* Meraki has incorporated AI-driven features in its networking solutions to improve visibility and automated issue resolution. Tools like Cisco ThousandEyes provide comprehensive digital experience assurance across networks, making it easier to manage owned and unowned parts of a network.
Cohesity Cohesity 7.1.2 U2 released! While 6.8.2 U1 is still the LTS release, 7.1.2 U2 provides fixes, as well as Security updates, and is supported through March 2025.
Nutanix *New Long Term Support Release drops!* As Nutanix has been bringing some fantastic features to the platform, recently most of them have been in the Short-Term Support (“STS”) and Extended Short-Term Support (“eSTS”) releases. On October 7th, Nutanix dropped the latest Long-Term Support (“LTS”) release with AOS 6.10 and AHV 20230302.102001 being released. The 6.5 release for AOS has been around for a while, and it’s great to see the features from the 6.8 releases make their way into the LTS release.
* Nutanix recently announced a promotion for customers using VMC on AWS. With Broadcom’s announcement of VMC on AWS and the inability to purchase directly from AWS, Nutanix is helping those customers with a migration path/promotion to Nutanix Cloud Clusters (NC2). Nutanix is providing a one-time promotion for licensing, and will run from September 2024 through July 2025.
* Prism Central 2023.4.0.2 released! While mostly a bug-fix release, Nutanix continues to focus on stability and scalability for Prism Central as a cornerstone of the Nutanix Cloud Infrastructure.
* Nutanix Move 5.4.1 released! Easily one of the most powerful tools in the Nutanix toolbox, Move continues to be enhanced with some helpful features.
+ Move now supports the automatic installation of NGT on migrated VMs.
* + Move now supports configuring Nutanix Self-Service runbooks for execution post VM migration.
* + Move now supports the automatic target share creation for Files Migrations.
+ Move now supports the scanning of shares, and shows progress of migration for Files 5.0.0+.
VMware The rocky relationship between Broadcom and its customer base continues with an AT&T lawsuit. 1050% is an extreme case, but we’re consistently seeing 200-400% cost increases. We’re a Broadcom partner and can provide options and ballpark pricing before your renewal.
Zerto ZVR remains a vital tool for IT teams seeking to protect their critical data and applications. Whether using VMware vSphere, Microsoft Hyper-V, or exploring the cloud for DR or Lift and Shift opportunities, Zerto ensures your business is always prepared for the unexpected. Read our blog on the latest!
What’s New with Microsoft?Azure Evaluating your next move from VMware? Microsoft has released incentives and opportunities to explore cloud native, Azure VMware Solution, and alternative hypervisors in Azure. Read more to dig deeper into how you can get information as well as pros and cons.
* The new capabilities of Azure Cost Management give more precise and predictive cost estimations from your Azure investments.
* Mandatory MFA is here for Microsoft Azure. Be prepared and get ahead of the gradual enforcement over the coming months and early 2025 by reading here and acting.
* One of the most valuable uses of Azure is still to provide disaster recovery for on-premises resources. Mike Dent tackles the capabilities of not only Zerto Virtual Replication to on-premises but also for VMware environments to Azure in his latest blog post.
* Available in public preview, Azure Business Continuity (ABC) Center is the new, streamlined replacement Azure Backup Center that centralizes management of Azure Backup and Azure Site Recovery BU/DR policies and operations.
* Automated Patching is being deprecated on 9/15/2027, replaced by Azure Update Manager.
* Between now and 3/31/25, MSFT is offering an additional 15% discount on 1-year Azure Reserved Virtual Machine Instance rates for the latest Linux VMs.
* Azure Application Gateway support for TLS 1.0 and TLS 1.1 will end by 31 August 2025.
* Risk and safety evaluations for protected material (text) are now available in public preview, accessible through Azure AI Studio UI and SDK experiences.
* Start using the Azure Machine Learning model monitoring instead of the Azure Machine Learning data drift detection before September 1st, 2025.
Defender for Office 365 Beginning now and through late October, admins can start blocking or allowing IPv6 addresses without prior submissions.
Defender XDR Microsoft is consolidating ‘Microsoft 365 Defender for Cloud Apps’ communications under ‘Microsoft Defender XDR’ in Service health and Message center.
* The Files page in Microsoft Defender for Cloud Apps will be retired on October 28, 2024. Users can manage Information Protection policies and explore malware files via the Policy Management page.
* Stay up to date on the security enhancements in Microsoft Defender XDR with the monthly blog. Drill into the details of things like improved resilience against QR code phishingand the critical role of identities in attack disruption.
Delve Delve retires December 16, 2024.
Entra ID A new Conditional Access template requiring device compliance is now available in Public Preview. This template restricts access to company resources exclusively to devices enrolled in mobile device management (MDM) and compliant with company policy.
* Beginning with version 6.2408.5807, Authenticator for Android is compliant with Federal Information Processing Standard (FIPS 140-3) for all Microsoft Entra authentications, including phishing-resistant device-bound passkeys, push MFA, passwordless phone sign-in, and time-based one-time passcodes.
* Follow our blog and events page for an opportunity to learn more and join our webinar about the all-new Microsoft Entra Suite, the top tier in Microsoft Identity Security solutions. In the meantime, read more about the capabilities of Private Access, Internet Security, and ID protections & governance.
Exchange Online Microsoft is now gradually enabling IPv6 for all customer Accepted Domains that use Exchange Online for inbound mail. To take advantage of IPv6 connectivity, please make sure that your network allow-lists allow Exchange Online IPv6 endpoints in the same way it allow-lists IPv4.
* Starting October 15th, Exchange Online will reject emails with multiple From addresses without a Sender header, to comply with RFC 5322. Organizations should ensure a single address in the Sender header to avoid non-delivery reports (NDRs) with error code 550 5.1.20.
Forms Microsoft Forms introduces a new, more reliable data sync to Excel for the web, replacing the older version on January 13, 2025. Migration support begins late September. Users must manually update to the new solution after October 20, to continue syncing data from Forms to Excel.
Intune Intune ends support for Android device administrator on Google Mobile Service devices after 12/31/24. Users should stop enrolling devices using GMS and migrate to newer management methods.
* Working time settings allow you to enforce policies that limit access to apps and mute message notifications received from apps during non-working time for Teams and Edge apps.
* Enterprise App Management is enhanced to allow you to update an Enterprise App Catalog app, with a wizard that allows you to add a new application and use supersedence to update the previous app.
* Samsung has deprecated many important Samsung Knox APIs (opens Samsung’s web site) configuration settings on Android device administrator managed (DA) devices.
* You can now use the new Personal Data Encryption (PDE) template that is available through endpoint security disk encryption policy. PDE differs from BitLocker in that it encrypts files instead of whole volumes and disks. PDE occurs in addition to other encryption methods such as BitLocker.
* *Since Apple ended support for profile-based user enrollment, Intune has ended support forprofile-based user enrollment with Company Portal.* This method was their privacy-focused BYOD enrollment flow using managed Apple IDs.
* While cloud-native endpoint management has been a trend for quite a while, there are lots of questions on what it truly takes to get there. This blog aims to tackle that question with common changes to the vision and process required to make the jump.
Microsoft 365 Admin Center Enable multifactor authentication (MFA) for your tenant by October 15, 2024, to access Microsoft Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. Postponement is possible, but without MFA, admin sign-in will prompt MFA registration.
Microsoft 365 Copilot Wave 2 of Copilot was launched on 9/16.
Improvements include:
+ Pages for Microsoft 365 Copilot, enabling collaborative AI interactions and multiuser prompting. The feature is automatically enabled but comes with admin controls for customization. Copilot agents to automate business processes.
* Microsoft changed how it handles detailed usage metrics. Previously, admins had to enable optional diagnostic data. Now, this data is reclassified as required service data, meaning you no longer need to enable optional diagnostic data to see active usage metrics.
* Self-service purchase settings for Microsoft 365 Copilot will be generally available for global admins or billing admins. The option to self-purchase can be deactivated.
* Microsoft 365 Copilot now connects to SharePoint organization libraries for brand-approved images and other assets. Admins must prepare by uploading brand content and using a new cmdlet for consent.
* Microsoft 365 Copilot will automatically offer to summarize a document when opened in Word.
OneNote OneNote for Windows 10 will end support on October 14, 2025. OneNote for Windows is the future.
Outlook (New) More options for work location sharing are available in late October, including not sharing any information. Users and admins can configure these settings in Outlook or with PowerShell.
* Soon, when users want to share a Word, Excel, or PowerPoint file that is saved to their device (not stored in OneDrive), the user can right-click the file name in File Explorer, select Share, and select new Outlook for Windows to email the file.
* Outlook is updating to automatically hide duplicate contacts, with rollouts ending mid-October. This affects Outlook on the web and new Outlook for Windows, while other versions will show all contacts.
Places* Microsoft Places, an AI-powered app to efficiently find meeting locations that suit participants’ needs, will be available in Q4 CY24 with core and premium service plans. Existing O365 subscribers receive the core service plan, with basic workplace coordination. Teams Premium users get enhanced features.
Planner The new Planner for the web integrates features from Microsoft To Do, Planner, Project, and Copilot for a comprehensive task management solution. Expect availability by late January 2025. Some features will be unavailable at launch but will return by early 2025. A Microsoft 365 license is required.
Power Platform Coming to public preview today, admins and makers can protect against data exfiltration by controlling what apps can be run in the Dataverse environment. This feature will help to prevent malicious users from creating or using unapproved apps to export data.
* The ‘create a flow on a file’ in Teams feature for Power Automate allows users to set up and use Workflows in Teams on files on 10/31. It will not be available via Power Automate Desktop.
Purview* Diagnostics for Microsoft Information Protection and Data Loss Prevention will soon be available in the Microsoft Purview compliance portal, with a public preview in late October and GA in early January.
* Endpoint DLP is introducing seven new conditions for Mac endpoints in December to bring capabilities closer to parity with Windows.
* Purview Insider Risk Management will roll out a feature allowing HR resignation date to be used as a condition for risk level in Adaptive Protection.
SharePoint SharePoint is introducing coauthoring for Pages and News, allowing multiple authors to edit simultaneously with real-time changes.
Teams Chat and Channels Teams will eventually stop working on old/unsupported Operating Systems. Beginning October 15th, the Teams desktop client may present a banner notifying users that they are on an unsupported OS version with a link instructing people to update to Windows 10 version 10.0.19041 or higher.
* Teams Workflows will allow users to describe the automation they need and have a workflow created by late October. The feature is in the Workflows app in Teams chat and channel overflow.
* Teams introduces a way to add a location to your presence signal, viewable from profile cards, one-on-one, and group chats. This will roll out in early to mid-November. Review the Places deployment guide.
* Teams is introducing a block user feature to prevent malicious users from contacting an organization again. Admins can block users, preventing 1:1 and group chats with them. It’s off by default.
* ICYMI: Teams now offers real-time Calendar notifications in the Activity Feed. Notifications include meeting invites, updates, cancellations, and forwards. If these notifications create noise for you, turn them off at “…/Settings/Notifications and activity/Calendar/New invites, updates, and cancellations.”
Teams Meetings* Meeting passcodes are increasing from 6 to 8 characters for enhanced security. This won’t affect internal usage, only external users joining with a Meeting ID will need to use longer passcodes.
* Teams is introducing a new policy that gives IT admins enhanced flexibility with distinct settings for voice and face enrollment. Voice and face biometric enrollment will be enabled by default, enabling voice isolation and speaker recognition in meeting rooms and enhancing intelligent meeting recaps and Microsoft Copilot for meetings (link to LinkedIn).
* The UDP signaling ports for Calling and Meetings are changing in need to be updated in firewalls. The source ports will change from 49152-65535 to 50070-50089, with the destination UDP port remaining at 3478. Rollout begins early October 2024.
* The new Microsoft Teams on Windows now allows users to mute and unmute using the mic icon in the Windows taskbar or a keyboard shortcut.
* New interaction improvements for multi-room Mesh events will be available, allowing attendees to see reactions across rooms and hosts to move between rooms.
* By early November, presenters can join events via mobile. No admin action needed, but inform users.
* If using older Teams Room systems on Android, see the note immediately below.
Teams Phone Automatic updates for Teams Android Devices to Company Portal version 5.0.6152.0 are planned, now through late December. Devices running older versions may be unstable after July 1, 2025. Organizations should ensure devices are updated and check Teams Admin Center for current firmware and application versions. Accelerated updates will occur outside business hours, overriding normal update timelines and maintenance windows. Devices no longer supported will not receive updates.
Teams Admin Teams is currently updating its app installation process to be more and user-friendly. No changes to policies needed.
* New Teams apps and Copilot extensions will provide admins with security and certification information for compliance assessment. This feature, available in the Teams and Microsoft 365 admin centers, will include Microsoft 365 certification outcomes and ISV-submitted data.
Windows* October 1st’s Windows 11 2024 Update contains new features, including enhanced battery saver, Bluetooth LE Audio, HDR background support, and support for Wi-Fi 7. Admins need to configure Windows Update for Business, Intune, or other solution to deploy this full operating system swap.
* The functionality formerly known as Windows Update for Business deployment service has been woven into Windows Autopatch. A dashboard in the Intune admin center now has four main sections: update policies, update groups, update status, and update reports.
Conclusion**If any of these updates or changes pose as a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviouseGroup Enabling Technologies Ranked Among Elite Managed Service Providers on Channel Futures 2024 Next Generation ListNextExecutive Considerations for Data Governance with Microsoft PurviewNextNeed Assistance with These Updates?Contact our team today to get help with any of the updates mentioned above!
The post October 2024 Newsletter appeared first on eGroup Enabling Technologies.
eGroup Enabling Technologies Ranked Among Elite Managed Service Providers on Channel Futures 2024 Next Generation List
Charleston, South Carolina, September 23, 2024 — eGroup Enabling Technologies has been named as one of the world’s premier managed service providers on the prestigious 2024 Next Generation rankings.
The Next Generation list, affiliated with the MSP 501, honors industry-leading managed service and technology providers who drive a new wave of growth and innovation for the tech channel via ground-breaking solutions delivered to their customers. Many of these MSPs generate recurring revenue from cloud, security, unified communications, and other solutions to clients of all sizes. Due to their growth, drive, and innovation, these MSPs represent the future of the technology channel and IT industry.
Channel Futures is pleased to name eGroup Enabling Technologies to the 2024 Next Generation.
“We are honored to be recognized among the top innovators in the tech industry! This acknowledgment underscores our team's dedication to delivering cutting-edge services and solutions that drive growth and efficiency for our clients. Our commitment to forward-thinking innovations and customer service excellence continue to propel our journey in shaping the future of IT services.”
– Christa Anderson, VP of Alliances, Marketing, and Sales Development
At the heart of eGroup Enabling Technologies’ success lies its team of highly skilled professionals, who possess a deep understanding of business technology and strategies. Their expertise allows them to offer a comprehensive suite of services, including cloud, hybrid data center, cybersecurity, data and AI, consulting, organizational change management, and managed services.
Channel Futures recognizes the channel partner communities for their innovation and contributions to the IT industry. The Next Generation represents that effort.
“Constant innovation is the lifeblood of the tech industry. These MSPs drive that innovation and build sales and marketing strategies around them. I enjoy watching these companies grow and develop and expect many of them will become among the biggest managed service providers in the industry if they’re not already there.”
- Dave Raffo, Manager of the MSP 501 and Next Generation Programs
The data collected by the annual Next Generation and MSP 501 lists drive Channel Futures’ market intelligence insights. Channel Futures uses these robust data sets and data-based trend reports to support editorial coverage, event programming, community and networking strategies and educational offerings.
“These companies are providing innovative approaches to customer solutions and partner engagement never seen before,” said Robert DeMarzo, Vice President of Content for Informa Tech Channels. “They drive the future growth of the channel.”
About eGroup Enabling TechnologieseGroup Enabling Technologies provides IT solutions and Managed Services that empower organizations to achieve their business objectives. They specialize in helping their clients harness the power of technology to drive innovation, enhance security, and optimize operations.
About Channel FuturesChannel Futures is a media and events destination for the information and communication technologies (ICT) channel community. We provide information, perspective, and connection for the entire channel ecosystem, including solution providers (SPs), managed service providers (MSPs), managed security service providers (MSSPs), cloud service providers (CSPs), value-added resellers (VARs) and distributors, technology solutions brokerages, subagent and agents, as well as leading technology vendor partners and communication providers.
Contact Our Team!Looking to team up with experts who have 30+ years of experience delivering successful outcomes in areas such as cloud migrations, productivity and collaboration, security, consulting, data and AI, and organizational change management?
Fill out the contact form and our team will be in touch shortly!
The post eGroup Enabling Technologies Ranked Among Elite Managed Service Providers on Channel Futures 2024 Next Generation List appeared first on eGroup Enabling Technologies.
Maximize the Value of Your Microsoft 365 Investments at Renewal Time###### Jason Webster
Field CTO, Microsoft 365 & Azure
Whether you have an upcoming renewal or are looking to expand your capabilities with Microsoft productivity and security, you want to get the most out of your investments.
Maximizing value means addressing several things:
Deciding on the Right License Option
Answers to the licensing topics below are based on observations from working with numerous clients on how to sift through licensing options to make the right decision for their business.
– How Do You Choose the M365 Package That’s Right For You?
“It depends” is the honest answer anyone should give you at the start of the conversation. You must evaluate it based on the needs of the business, current solutions in place, and ability to implement new technology once procured. The most common outcome we see is a mix of M365 E3, F3, E5, F5, or the Security and Compliance E5 bundles.
– When is It Beneficial to Go Full E5?
I categorize Microsoft 365 E5 features into three groups: Productivity (Power Platform, Phones, etc.), Security (Defender Platform), and Compliance (Purview Platform). Financially, using an E5 bundle is sensible if you need two or more capabilities from these areas. From a capability standpoint, consolidating platforms simplifies management and reduces long-term costs, requiring less specialized vendor expertise.
It’s also common that an organization has compliance or security needs, but they already have investments elsewhere in one or the other. Procuring E5 allows vendor consolidation and streamlined management of both areas to reduce complexity and cost.
– Consolidating Existing Solutions After the Purchase
Developing a solution to service map (or GAP/Overlap analysis) that includes which solutions currently address the needs of the business, while documenting product costs, renewal dates, and dependencies allows you to build an effective timeline. Some Microsoft 365 benefits can be realized immediately. However, others can take time to effectively, plan, test, and execute in production. Developing a baseline for decision-making and a timeline for implementation is critical to the decision process.
– Do You Need the Advanced Security Features in E5?
If your organization deals with sensitive data or operates in a regulated industry, the advanced security features in E5 (like Microsoft Defender, Entra ID (fka Azure AD) Premium P2, and Advanced Threat Protection) can help reduce risk by protecting against cyber threats. Additionally, they can streamline compliance reporting and decrease risk through effective management tools.
If your business isn’t obligated to meet specific regulatory compliance, we still advise you to adopt and adhere to an appropriate industry standard to guide security decisions that adapt over time. The specific features you need can be easily identified through a GAP analysis.
– The End-User Impact is the Difference Between Success and Failure
With any technology change, success depends on effective utilization AFTER the change.
There are three core milestones to achieving success:
– Don’t Leave Incentives on the Table
There are incentives in the form of discounts, implementation support, educational workshops, and concierge guidance available for businesses of all sizes. Include those in your planning and ensure you get the maximum value out of your planned investments.
– The Microsoft 365 Roadmap
The Microsoft 365 Roadmap is an active workshop designed to support a business looking to understand how an investment in Microsoft 365 solutions can increase productivity, security, and management time for their end users. Those looking to get the right fit for their Microsoft licensing while also ensuring they get the greatest return on capabilities procured.
The outcomes of the Microsoft 365 Roadmap are:
We Can Help!
If you have any questions about Microsoft 365 or are looking for assistance withmaximizing your Microsoft 365 investment, please reach out toinfo@eGroup-us.comor complete the form below.
PrevPreviousSeptember 2024 NewsletterNexteGroup Enabling Technologies Ranked Among Elite Managed Service Providers on Channel Futures 2024 Next Generation ListNext###### Have Questions or Need Help with Microsoft 365 or Maximizing Your Investment?
Contact our team of experts today!
The post Maximize the Value of Your Microsoft 365 Investments at Renewal Time appeared first on eGroup Enabling Technologies.
September 2024 NewsletterTable of ContentsWhat’s the Buzz at eGroup Enabling Technologies? eGroup Enabling Technologies Recognized on the 2024 Inc. 5000
“We are extremely excited to be named one of the Inc. 5000 fastest-growing private companies. This honor results from our team’s incredible work and the solutions we provide for our valued customers. Our dedication to bringing outcomes to our customers that allow technology to work for them, and make them better, is what continues to drive us forward. We are excited for what the future holds and how we’ll continue to grow together.” – Ben Gaddy, Principal, Operations
Teams Phone Major Updates
This year, Microsoft has made two major changes to Teams Native phones: 1. The operating system on the phones will be upgraded to Android 12, and, 2. Management of Native Teams phones in Intune will switch to the Android Open Source Project (AOSP) from the Android Device Administrator. The solution? Check out this article on configuring Intune and AOSP to support these updated phones, and view our recent webinar, What’s New in Microsoft Teams?
ThreatHunter Prevents a “Save Your Bacon” Client Incident
Daryl Breneman, CISO of Becket & Lee, shares a specific incident where ThreatHunter saved the firm from a potential breach. A work-from-home device was misconfigured and did not have Windows Firewall turned on. The device was also plugged directly into the ISP modem, exposing it to the internet. Read more HERE to find out how ThreatHunter and eGroup Enabling Technologies saved the day!
What’s New in the Hybrid Data Center?Cisco Cisco announced the Nexus HyperFabric AI Clusters in partnership with NVIDIA. This AI-driven data center solution combines Cisco’s networking expertise with NVIDIA’s AI software and hardware to provide simplified cloud management for AI deployments across data centers and edge sites. * Cisco continues to enhance its Intersight platform for hybrid cloud management. New features allow seamless integration with public cloud services, enabling customers to manage both on-premises and cloud-based workloads through a single interface. Intersight also offers AI-driven predictive analytics and anomaly detection for proactive issue resolution. * Cisco has expanded its UCS X-Series hybrid-cloud systems with accelerated computing capabilities and high-performance networking, including GPU integration for AI and machine learning workloads. This system now supports hybrid and multi-cloud environments, simplifying hybrid data center operations. Cohesity To ensure future supportability, Cohesity has transitioned to the host operating system from CentOS to Red Hat Enterprise Linux (RHEL) 7.9 in response to the end of maintenance support for CentOS 7.9. Cohesity maintains a Red Hat Enterprise Linux Extended Life Cycle Support Subscription for RHEL 7.9, which permits support to be extended until June 30, 2028. * Cohesity Data Protect-as-a-Service adds support for protecting virtual machines (VMs) that reside on Azure VMware Solution (AVS). Check out this documentation for more information on configuring AVS backup. Nutanix Nutanix and Dell announced the latest OEM platform refresh, XC Plus. * Have you wanted to try out Nutanix without buying new hardware? Nutanix released Community Edition 2.1,which is based on the latest AOS/AHV release. Whether it’s for a lab or your garage, Nutanix is giving you that hands on! * Nutanix Kubernetes Platform (NKP) has gone GA! If you’re struggling with managing a Kubernetes deployment, NKP can help simplify and manage that lifecycle! Rubrik Rubrik integration with Microsoft Sentinel ensures that visibility to threats leads to direct action of Rubrik Workflows from within Sentinel for threat hunting and orchestrated recovery. VMware VMware Explore has wrapped up—and what better way to call out the announcements and information shared than all of the on-demand sessionsand a special session from our friends at Microsoft, Best Practices for Migration and Security with Azure VMware Solution. Windows Server DNS glue records must be validated after installing the Windows update released on or after August 13, 2024. Make sure glue records registered on a parent domain match the data that is provided by the authoritative name servers. Remove or update stale glue records (outdated, inactive, or invalid IP addresses) to prevent unexpected results, starting with external domains then internal domains. What’s New with Microsoft?Azure Microsoft will enforce mandatory MFA for all Azure sign-in attempts on October 15th. Prepare today! * Remove any outstanding dependencies on TLS 1.0 and 1.1 before October 31st. * Vaulted backup for Azure Blob Storage is now generally available to help protect against data loss. Also, lifecycle management rules in Azure Blob Storage and Azure Data Lake Storage* now provide more control over returning rehydrated objects back to archive tier. * Developers and IT pros can preview ways to optimize the carbon footprint from cloud usage. * The development process is simplified with Dev Container templates for Azure SQL Database, now generally available. * Azure Backup now supports performing Cross-Region Restore of SQL and HANA backups from a vault which has Private Endpoints enabled. * Many PostGreSQL announcements were made, as were updates about NetApp Files on Azure. * The ability to attach and detach Virtual Machines on Virtual Machine Scale Sets with a fault domain count of 1 is now generally available. Microsoft 365 Copilot The Microsoft Copilot Dashboard will be available to all Microsoft 365 Copilot customers without extra cost, accessible via the Viva Insights app in Teams or a web app. * Copilot in OneDrive allows users to ask questions, summarize files, and create FAQs without opening the source file. * Microsoft 365 Copilot in PowerPoint and Word is now able to search, download, and insert brand-approved images, logos, icons, and illustrations directly from the chat experience. This enables a new creative content source beyond the licensed stock images already available today. * The Microsoft 365 Usage report will include a ‘Suggested Candidate for Copilot’ column to aid admins in licensing decisions. This feature identifies users likely to benefit from Copilot based on their app usage. Defender for Office 365 Microsoft is making improvements to email remediation capabilities with new “sender’s copy clean-up” features. Before this rollout, admins did not have a way to remove harmful emails from a sender’s Sent items. This will streamline the process for admins who use Soft delete and Move to Inbox actions. * Look for Bulk Senders Insight, a tool to optimize bulk email management. It helps admins fine-tune bulk email policies by simulating the optimal bulk complaint level and identifying potential issues. Defender XDR Microsoft Defender XDR will soon enable SecOps to restore quarantined emails directly from various interfaces, including Threat Explorer and Microsoft Graph API. Entra ID Enable MFA by October 15th to access the Azure portal, Entra admin center, and Intune admin center. Set up MFA or apply to postpone the enforcement date. Without MFA, admin access will be restricted. * The Attacker in the Middle detection feature is generally available in Entra ID Protection (P2), enhancing security by identifying compromised user accounts. Such users are elevated to High risk. * Entra ID is previewing FIDO2 provisioning via API, allowing organizations to pre-provision security keys (passkeys) for users. These new APIs can simplify user onboarding, and provide seamless phishing-resistant authentication on day one for employees. * Four Entra ID Governance workflow capabilities went GA. Fabric Microsoft Fabric introduces new settings for short-lived user-delegated Shared Access Signature tokens, enhancing security for applications using Microsoft OneLake. Intune Users on Red Hat Enterprise Linux 8.x and 9.x (LTS) can now register their devices with Entra ID, enroll into Intune, and securely access corporate resources using device-based Conditional Access policies. * Windows Autopatch is unifying with Windows Update for Business deployment service in mid-September, simplifying update management within Intune. This change organizes update capabilities into three categories and maintains existing licensing rights for customers. * Intune will soon require iOS/iPadOS 16 or higher after the release of iOS/iPadOS 18. If managing iOS/iPadOS devices, check Intune reports for affected devices and users, and use Intune to update OS. * With Apple’s release of macOS 15 Sequoia, Intune, the Company Portal app, and the Intune MDM agent will now require macOS 13 (Ventura) and later. * Intune now supports account-driven Apple User Enrollment, the new, and improved version of Apple User Enrollment, for devices running iOS/iPadOS 15 and later. This new enrollment method utilizes just-in-time registration, removing the Company Portal app for iOS as an enrollment requirement. * Managed Home Screen (MHS) is now supported on Android Enterprise Fully Managed devices. It’s an Intune app that allows you to configure the home screen on the device. It only shows the apps that users access and the device settings that admins need to manage. * Managing Intune-enrolled devices with Android Enterprise management options previously required you to connect your Intune tenant to your managed Google Play account using an enterprise Gmail account. Now you can use a corporate Microsoft Entra account to establish the connection. This change is happening in new tenants, and doesn’t affect tenants that have already established a connection. Microsoft 365 Apps Admin Center ActiveX will be disabled by default, affecting Word, Excel, PowerPoint, and Visio. This change occurs in October 2024 for Office 2024 and begins in April 2025 for Microsoft 365 apps. Users can re-enable ActiveX by adjusting Trust Center Settings, the registry, or group policy settings. * User and License admins will soon manage self-service license requests in the Microsoft 365 admin center, a role previously limited to global admins. * The Microsoft 365 admin center will implement continuous access evaluation (CAE) this month, enabling near real-time session termination or reauthentication and enforcing policy changes without waiting for token expiration. OneDrive OneDrive users will now *access shared folders via the People view in their own OneDrive, organized by the sharer. There’s no admin action, but users should be informed. Outlook (Classic) While you have until 2029 to use it, admins can start using an ‘Admin-Controlled Migration to New Outlook’ policy, involving three steps, with prompts and messages guiding users through the process. The policy includes settings for re-initiating migration if users revert to classic Outlook. Outlook (New) Outlook and Teams are introducing a new meeting response called ‘Follow’ for attendees who can’t attend but want to stay informed. It’s initially in the new Outlook (Windows) and web, not Mac or mobile. Organizers are notified of ‘Follow’ responses, and users are marked as “free” but get updates. * The new Outlook for Windows update allows users to open attachments directly in desktop apps by double-clicking. Rollout begins early September 2024, completing early October 2024. The feature streamlines opening attachments, and no admin action is required for the update. * Outlook for Windows will soon allow sharing of Word, Excel, and PowerPoint files stored locally on devices via email. Users can right-click a file and select new Outlook to share it. Outlook Mobile Outlook for iOS and Android has a new setting for automatically advancing to the next email after actions like delete or archive, instead of going back to the message list. Users must enable this feature in Settings/Mail/Email Auto-Advance. * Admins can alter which browser pops up on mobile devices when the “OpenLinks” app configuration keys on Android/iOS are updated. Power Automate The create and edit expressions with Copilot feature for Power Automate allow makers to create, edit, and fix their Power Automate expressions by invoking natural language prompts using Copilot. Purview * Microsoft is separating policy tips and email notification for Data Loss Prevention for SharePoint and OneDrive. General Availability is in late December. Admins can use PowerShell or Purview to configure. * Purview Information Protection will enhance default sensitivity labels and policies to include files, email, and meetings for eligible customers. Rollout will compete by late October. No admin action required, but updating documentation is advised. * By late October, when users select a PDF with Purview Information Protection sensitivity labels in Outlook for iOS or Android, they will be presented with a button suggesting they open the file in the Microsoft 365 app if it is installed, or to install the Microsoft 365 app from the store if it is not installed. * Purview Information Protection will soon integrate Advanced Message Encryption with Message Recall for emails in Outlook, enabling licensed users to recall encrypted emails. * M365 E5 Compliance features: + New message popups are coming in Outlook Win32, introducing ‘Message contains’ and ‘Attachment contains’ warnings. + Insider Risk Management will soon support bulk upload for priority user groups. The Public Preview is set for mid-August 2024, with General Availability in early February. This update allows admins to upload multiple UPNs via CSV, simplifying user group management. + Purview Insider Risk Management has a new feature to detect exfiltration of sensitive data to free public domain emails. The update enhances email insight alerts and adds new domain detection for better security incident prevention. + Purview Communication Compliance introduces advanced classifiers for detecting workplace safety violations in over 100 languages. + Purview Endpoint DLP will scan, classify, and protect sensitive content on Windows endpoint devices for ~100 supported file types, bringing Endpoint DLP into parity with M365 apps. November’s update will detect labels from protected files (pfiles), identify sensitive content within file metadata, recognize information in PDF form fields, and in files embedded inside office files (i.e., a .txt file inside .pptx file).53. + The Purview AI Hub will display prompts and responses from Copilot for Microsoft 365 in Activity explorer, with full rollout in November. Users need the Content Explorer Content Viewer role to access this feature. Preparation involves role assignment and reviewing documentation. SharePoint SharePoint introduces custom fonts and themes for sites and experiences, through the SharePoint Brand center, allowing organizations to express their brand creatively on sites and pages. * SharePoint will allow approvals in any list. Users can configure approvals via the Automate dropdown and action them in Teams. Teams Chat and Channels Teams will soon allow in-tenant users to request to join a shared channel using a link. * Teams has now expanded search options for 1:1 chats allowing users to search content related to a person across Teams. This feature is available on Windows, Mac, and the Web. Teams Meetings Teams introduces a new meeting option allowing organizers to control who can admit participants from the lobby. This update provides two choices: only organizers and co-organizers or including presenters. The feature will roll out in September, with no specific action required for implementation. * Teams will soon allow meeting participants to select their own breakout rooms. * Users can now control how they receive notifications in meeting chats. Declining a meeting will result in no notifications, while accepting a meeting will result in notifications for all new messages. It will be available on Desktop, Mobile, and Web. Users can select which meetings to receive updates from. * Teams is introducing CAPTCHA verification for anonymous participants, rolling out in October 2024. This feature is off by default and enabled by Tenant Admins in the TAC to provide additional security. * After a town hall ends, organizers can download the Q&A questions as a .CSV file. Teams Phone Common area Teams 911 calls will go straight to the relevant Public Safety Access Point (PSAP) without being screened by a national call center first. No admin action is needed. * Teams phone devices will soon allow non-touch phone users to customize speed dial using line keys and sidecars by late December. Teams Admin Administrators will now need Microsoft 365 admin roles with user creation permissions to create and manage Teams Phone Resource Accounts. * Shadow IT alert! Teams will soon allow the purchase of third-party app subscriptions directly from the Teams Admin Center and Teams app store, aiming to simplify the subscription process. Teams Premium The Queues app is rolling out in early October for Teams Premium users. It offers real-time statistics, historical reporting, agent opt-in/out, collaborative call handling, outbound calls, and management tools. Preparation steps include reviewing app setup policies and configuring users. * Premium users will soon be able to set sensitivity labels for town halls and webinars. Windows On October 8th, Windows 11, version 21H2 (Enterprise, Education, and IoT Enterprise editions) and Windows 11, version 22H2 (Home and Pro editions) will reach end of servicing. October 8th’s security update will be the last update available, and devices running these editions vulnerable. * The August 2024 security update is now available for all supported versions of Windows. Microsoft recommends that you install these updates promptly. ConclusionIf any of these updates or changes pose as a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousUsing AI for Transcription in Public SafetyNextMaximize the Value of Your Microsoft 365 Investments at Renewal TimeNextNeed Assistance with These Updates?Contact our team today to get help with any of the updates mentioned above!
The post September 2024 Newsletter appeared first on eGroup Enabling Technologies.
Using AI for Transcription in Public Safety###### Keith Singleton
Architecture Team Support Leader
Public Safety requires meticulous documentation, processes, and record keeping. Everything is under scrutiny and can/should be considered public record. Law enforcement often requires summaries of reports, interviews, and even body camera conversations to be transcribed into readable documentation for use in court proceedings and investigations.
How much time does a typical agency spend transcribing video and audio into written documentation?Research shows that for every hour of recorded audio (i.e. dictated police reports), transcribing each file’s contents takes a minimum of 4 hours, up to 10 hours.
To give you some context on my background in this area, I have spent 20 years in law enforcement and in public safety technology. My tenure was with the Columbus, Ohio Division of Police. And yes, that makes me long in the tooth. Back in my day, (early 90s) we would take suspects into an interview room, start the tape recorder, and begin the interview.
Once the interview was complete, we would label the tapes and drop them into the evidence check in. The transcription pool (mainly typists with Wang integrated word processors—using 8” floppy disks), would load the tapes from the interviews into a tape player and use a foot switch to start and stop the interview. The interview conversations would be meticulously typed word for word. The summaries would end up in the case file and used for court proceedings as needed. My department was large enough to have dedicated personnel for this purpose. Many agencies outsource transcription services and pay a hefty annual fee. The average cost researched is between $1.50-$5.00 per audio minute. Imagine the number of hours consumed by the interview and transcription process!
Fast forward a few decades—where are we now? We still require the transcription of key conversations and suspect interaction, except now it is more available. Audio recordings are digital now, so we are managing files rather than physical media. Body cameras, radio log recorders, interviews, and interrogations all contribute to data files needing to be transcribed. But now we also have technology to help speed up and automate the process of transcription.
Artificial Intelligence (AI) has received a lot of attention recently through ChatGPT, Microsoft 365 Copilot, and other “bots” that can provide extensive information in record time. We are scratching the surface of what is possible. Could AI be used to intelligently transcribe interviews, interactions, and even public meetings that require documentation? Yes. The AI team at eGroup Enabling Technologies has been working to decode what AI can do for the real world and how it can save time and money, or just make life easier.
The first step in understanding what you can do to help your agency is to learn what capabilities exist today and how those capabilities may be applied to your operations. Our AI team recently published an AI Maturity Model eGuide to benchmark where you currently are versus where you would like to be. This would be a good starting point.
Some considerations for AI use within law enforcement include:
Please reach out directly to further the conversation, learn more about us or just chat about what you see is on the horizon for AI within your agency. Our team is hard at work putting down early lessons learned on paper, as evidenced by a book written by our CTO, Chris Stegh—Elevate the Enterprise Using Microsoft 365 Copilot: A Guide for Power Users, CxOs, and IT Pros.
ConclusionTranscription of key interviews and public interactions (like body cameras) requires significant time, effort, and cost. AI, while still a developing technology, has incredible potential for Public Safety and Law Enforcement. Hundreds to thousands of hours could be recovered each year by allowing AI to transcribe public meetings, interviews, field reports, and even body camera summaries for use in internal and court investigations. To learn more about AI and how it can be used within your agency (but still meet CJIS requirements), feel free to reach out.
We Can Help!If you have any questions or are looking for assistance with determining use cases and ROI for potential AI initiatives or need help launching Microsoft 365 Copilot in your environment,please reach out toinfo@eGroup-us.comor complete the form below.
About the AuthorKeith Singleton works as the Support Leader for the Solution Architecture Team at eGroup Enabling Technologies. During his time in law enforcement and business, Keith was issued an ORI from CJIS to provide agencies with direct access to NCIC data through his company.
You may connect with Keith on LinkedIn or email directly at Keith.Singleton@eGroup-us.com
PrevPreviousPurview’s New AI Hub: Reduce AI Risks, Improve AI VisibilityNextSeptember 2024 NewsletterNext###### Unsure of where to start with AI?
Contact our team of experts today!
The post Using AI for Transcription in Public Safety appeared first on eGroup Enabling Technologies.
Purview’s New AI Hub: Reduce AI Risks and Improve AI Visibility###### Tom Papahronis
CIO Advisor
I have written extensively about getting data governance programs off the ground and the fundamentals of Purview Compliance. Today, though, I would like to address the AI concerns in organizations that already have mature Purview implementations, including advanced E5 features like Endpoint DLP, Insider Risk Management, and Communication Compliance. Their AI compliance challenges are evolving from LLM data overexposure toward how to ensure people are responsibly using the AI tools they now have broad access to—including preventing sensitive data from being used outside the M365 tenant trust boundary. To help with this, Microsoft has released a new set of controls into Purview called the AI Hub (in preview as I write this). It is a one-stop location for managing Purview policies and reporting relevant to the organization’s AI usage.
This discussion applies to those who, in addition to having an E5 license or E5 Compliance add-on, have also completed the following:
New DLP PoliciesDiscover Sensitive Prompts for AI AssistantsUsing the Endpoint DLP functionality and the Microsoft Purview browser extension, this policy detects if any of 90+ sensitive data types are uploaded or pasted into a Generative AI site. (Microsoft maintains a pre-populated list of these sites called ”Generative AI Websites” that include the domains listed here.) Like other Endpoint DLP policies, the actions that can be taken upon detection are Audit, Block with Override, and Block.
Adaptive Prediction in AI AssistantsA parameter has been added to the DLP engine that can recognize the Adaptive Risk levels from Insider Risk Management as a condition. This new default policy detects a user with an elevated adaptive risk level using a Generative AI Website and audits the activity. Again, like other Endpoint DLP policies, the actions that can be taken upon detection are Audit, Block w/ Override, and Block:
The same notifications, alerts, and other threshold capabilities available in other types of DLP policies are also available for these new AI detection policies. These AI Hub DLP policies can be used to log or prevent sensitive data from being shared outside of the Microsoft 365 tenant/Copilot trust boundary to third-party AI tools.
New Insider Risk Management PolicyBrowsing in AI AssistantsThis is a new IRM policy that is part of the Risky Browser Usage policy template. It uses the “Browsed to generative AI websites” trigger event (again, using the same Microsoft-maintained list here) that detects a user browsing a generative AI website. A threshold can be set to fire an Insider Risk alert (the default is 10 instances daily):
Like other insider risk management policies, this looks at audit log data to detect risky behaviors and score users accordingly, leading to both Alerts and in determining Adaptive Risk levels. This policy can be used to audit or alert on excessive use of external AI websites if they are discouraged but not blocked.
New Communication Compliance PolicyBrowsing in AI AssistantsThis policy reviews Copilot interactions for unethical prompts matching one of the following nine trainable classifiers, then creates a Communication Compliance alert:
New AI Risk AnalyticsThe AI Hub created these policies as examples to help gather baseline metrics and provide something to build from so you can track and control both Copilot and third-party generative AI usage. Real-world use cases will usually be more complex, nuanced, and reflect the specific needs of the organization. Much of the success of these AI policies will rely on other existing configurations in Purview, such as custom data classifiers or sensitivity label restrictions.
Over time, the AI Hub builds an analytics dashboard like the one below to give you a detailed overview of AI usage and risks:
Purview and AI Hub information give you the tools and metrics needed to enforce internal AI governance charters and policies while also reinforcing good stewardship of sensitive data overall. Keep an eye on these new features and capabilities. AI Hub is in preview now and will only improve as it moves into General Availability at some point soon.
We Can Help!If you have any questions or are looking for assistance withAI compliance challenges in your organization, or helps with the new AI Hub in Microsoft Purview, please reach out toinfo@eGroup-us.comor complete the form below.
PrevPreviousZerto Virtual Replication: History and CapabilitiesNextUsing AI for Transcription in Public SafetyNext###### Have Questions or Need Help with AI Compliance or Microsoft Purview?
Contact our team of experts today!
The post Purview’s New AI Hub: Reduce AI Risks, Improve AI Visibility appeared first on eGroup Enabling Technologies.
Zerto Virtual Replication:History and Capabilities###### Mike Dent
Field CTO - Hybrid Data Center
This is the first part of a series about Zerto Virtual Replication, starting with some history and capabilities of Zerto. Additional posts will follow and dive deeper into the full Zerto suite.
A Deep Dive into Zerto Virtual Replication: History, vSphere, Hyper-V, and Cloud CapabilitiesIn the world of disaster recovery and data protection, Zerto Virtual Replication (ZVR) has established itself as a leading solution, providing seamless business continuity and disaster recovery (BCDR) for businesses of all sizes. Let’s explore the evolution of ZVR, compare its functionality in VMware vSphere and Microsoft Hyper-V environments, and examine its powerful cloud features.
The Evolution of Zerto Virtual ReplicationZerto was founded in 2009 to simplify disaster recovery through a hypervisor-based replication approach. This innovative method revolutionized the industry by eliminating the complexity and limitations of traditional storage-based replication solutions.
The company’s flagship product, Zerto Virtual Replication, was launched in 2011. Since then, ZVR has evolved significantly, continuously enhancing its capabilities to support a broader range of environments and integrate with various cloud platforms. Today, ZVR is critical to many organization’s disaster recovery strategies, offering unparalleled flexibility and scalability.
Comparing vSphere and Hyper-V EnvironmentsZerto Virtual Replication supports VMware vCenter and Microsoft Hyper-V environments, providing a unified solution for multi-hypervisor environments. Let’s briefly compare how ZVR operates in these two popular platforms:
ZVR in VMware vCenter Hypervisor-Level Replication: ZVR leverages vSphere APIs for Data Protection (VADP) to perform agentless replication at the hypervisor level, ensuring minimal impact on VM performance. * Consistency Groups: ZVR allows you to group related VMs into consistency groups, ensuring application consistency during failovers and testing. * Granular Recovery: With VMware vSphere, ZVR provides recovery point objectives (RPOs) as low as seconds and offers point-in-time recovery options. ZVR in Microsoft Hyper-V Integration with SCVMM: ZVR integrates with System Center Virtual Machine Manager (SCVMM) to provide centralized management and monitoring of replication processes. * Agentless Replication: Similar to its vCenter implementation, ZVR offers agentless replication in Hyper-V environments, reducing complexity and overhead. * Cross-Platform Mobility: ZVR facilitates seamless migration between Hyper-V and VMware environments, enabling hybrid cloud strategies. Zerto Virtual Replication Cloud FeaturesZVR extends its capabilities to the cloud, empowering organizations to leverage cloud resources for disaster recovery and business continuity. Here are some of the standout cloud features of ZVR:
Multi-Cloud SupportZVR supports a wide range of cloud providers, including Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and IBM Cloud. This flexibility allows organizations to choose the best cloud provider for their needs or implement a multi-cloud strategy.
Cloud Disaster Recovery-as-a-Service (DRaaS)ZVR enables organizations to implement Disaster Recovery-as-a-Service (DRaaS) by replicating data to a cloud provider. This approach reduces the need for secondary data centers, lowers costs, and simplifies disaster recovery operations.
Hybrid Cloud ArchitectureZVR supports hybrid cloud architectures, allowing businesses to maintain on-premises environments while leveraging the scalability and cost-effectiveness of the cloud for disaster recovery and backup solutions.
Automated Failover and FailbackZVR provides automated failover and failback processes in the cloud, minimizing downtime and ensuring quick recovery times. This automation ensures business continuity and reduces the risk of human error during critical recovery operations.
Long-Term Retention and StatisticsWith ZVR’s cloud capabilities, organizations can store long-term retention copies in the cloud for compliance and audit purposes. Additionally, Zerto Analytics provides comprehensive insights into data protection operations, helping businesses optimize their disaster recovery strategies.
Quick ComparisonThe table below compares Zerto’s flexibility and robustness across different platforms, making it a versatile solution for organizations looking to implement comprehensive disaster recovery and business continuity strategies.
| Feature | VMware vSphere | Microsoft Hyper-V | Cloud Environments | | --- | --- | --- | --- | | Replication Method | Agentless, hypervisor-level using VADP | Agentless, hypervisor-level integration with SCVMM | Cloud-native integration with supported providers | | RPO | Seconds | Seconds | Seconds | | RTO | Minutes | Minutes | Minutes | | Consistency Groups | Supported | Supported | Supported | | Cross-Hypervisor Mobility | vSphere to Hyper-V and vice versa | Hyper-V to vSphere and vice versa | Cross-cloud and on-premises to cloud | | Automated Failover/Failback | Yes | Yes | Yes | | Point-in-Time Recovery | Yes | Yes | Yes | | Offsite Backups | Yes | Yes | Yes | | Multi-Site Support | Yes | Yes | Yes | | Cloud DRaaS | Via cloud integration | Via cloud integration | Native | | Long-Term Retention | Yes | Yes | Yes | | Zerto Analytics | Yes | Yes | Yes | | Integration with Management Tools | VMware vCenter and vSphere Client | SCVMM and Hyper-V Manager | Cloud provider consoles and Zerto Cloud Manager | | Testing and Sandbox Environments | Yes | Yes | Yes | | Hybrid Cloud Support | Yes | Yes | Yes | | Compliance and Audit | Supports compliance with retention policies | Supports compliance with retention policies | Supports compliance with cloud provider standards |
Key Points Replication Method: Both VMware and Hyper-V use agentless, hypervisor-level replication, while cloud environments use native integration with cloud providers. * Cross-Hypervisor Mobility: Zerto allows for seamless migration and replication between hypervisor environments and on-premises and cloud environments. * Automated Failover/Failback: Automated processes are available across all environments, ensuring minimal downtime and quick recovery. * Cloud DRaaS: Zerto provides robust disaster recovery as a service (DRaaS) capabilities, utilizing cloud resources to eliminate the need for a secondary data center. * Integration and Management: Zerto integrates with native management tools for each environment, facilitating centralized control and monitoring. * Ransomware Detection:* Zerto utilizes its Analytics platform to provide anomaly detection capabilities across all environments. This feature helps identify unusual patterns in replication and backup activities that could indicate potential ransomware attacks. Zerto Analytics provides insights into changes in data size, throughput, and replication frequency to detect possible threats early. This comparison highlights Zerto’s flexibility and strength across different platforms, making it a versatile solution for organizations looking to implement comprehensive disaster recovery and business continuity strategies.
Wrap UpZerto Virtual Replication has transformed how organizations approach disaster recovery and business continuity. With its history of innovation, cross-platform capabilities, and powerful cloud features, ZVR remains a vital tool for IT teams seeking to protect their critical data and applications. Whether using VMware vSphere, Microsoft Hyper-V, or exploring the cloud for DR or Lift and Shift opportunities, Zerto provides the flexibility and reliability to ensure your business is always prepared for the unexpected.
Stay tuned for upcoming posts in the Zerto series!
We Can Help!If you have any questions or are looking for assistance with Zerto Virtual Replication, or Disaster Recovery and Data Protection for your business, please reach out toinfo@eGroup-us.comor complete the form below.
PrevPreviousEnhancing Disaster Recovery with Nutanix Hybrid Cloud and Nutanix Cloud Clusters on AzureNextPurview’s New AI Hub: Reduce AI Risks, Improve AI VisibilityNext###### Have Questions or Need Help with Zerto Virtual Replication?
Contact our team of experts today!
The post Zerto Virtual Replication: History and Capabilities appeared first on eGroup Enabling Technologies.
Enhancing Disaster Recovery with Nutanix Hybrid Cloud and Nutanix Cloud Clusters on Azure###### Mike Dent
Field CTO, Hybrid Data Center
In today’s digital world, where downtime can translate to significant financial loss and damage, having an extensive Disaster Recovery (DR) strategy is no longer optional—it’s essential. Organizations have many DR options at their disposal, each with its own advantages and considerations.
Traditionally, on-premises DR has been a go-to for many, offering full control over data and infrastructure, and providing a sense of security. However, it often requires significant investment in hardware, software, and maintenance. Colo-based DR, where organizations utilize a colocation facility to house their backup infrastructure, presents a middle ground. It alleviates some of the overhead of on-premises solutions while offering a high degree of control and customization.
However, as cloud computing evolves, cloud-based DR strategies have become increasingly attractive. These strategies offer unparalleled flexibility, scalability, and cost efficiency, allowing organizations to leverage public or hybrid cloud environments to protect critical workloads. Among these options, Nutanix Cloud Clusters (NC2) is a powerful solution, providing seamless integration between on-premises and cloud environments for a resilient, secure, and efficient Disaster Recovery framework.
In this blog, I’ll explore how Nutanix Cloud Clusters on Azure can be effectively utilized as a DR target, along with how it compares to traditional on-premises and Colo DR strategies.
The Challenges of Traditional Disaster RecoveryTraditional DR solutions often involve complex, costly, rigid setups requiring significant capital expenditure and ongoing management overhead. These environments typically involve dedicated DR sites, expensive hardware, and intricate network configurations, which can be difficult to scale or adapt to changing business needs. Additionally, ensuring the security and compliance of DR environments can be a significant challenge, especially in industries with stringent regulatory requirements.
Enter Nutanix Hybrid Cloud and Nutanix Cloud Clusters (NC2) on AzureNutanix Hybrid Cloud combines the best on-premises and cloud environment features, offering unparalleled flexibility, scalability, and simplicity. NC2 on Azure extends Nutanix’s hyper-converged infrastructure (HCI) to the public cloud, enabling organizations to seamlessly deploy and manage workloads across on-premises and cloud environments.
With NC2 on Azure, organizations can:
| Aspect | Nutanix DR with NC2 on Azure | Nutanix DR with On-Premises/Colo-based Nutanix Cluster | | --- | --- | --- | | Infrastructure Requirements | No dedicated DR site or hardware required; utilizes Azure’s infrastructure. | Requires a dedicated on-premises DR site with Nutanix hardware. | | Scalability | Highly scalable; resources can be scaled up or down based on demand within Azure. | Limited by on-premises hardware capacity; scaling may require additional hardware investment. | | Deployment Speed | Rapid deployment in hours using Azure’s cloud infrastructure. | Longer deployment time due to physical hardware setup and configuration. | | Cost Model | Pay-as-you-go model; operational expenses with flexible scaling. | High upfront capital expenses for hardware; ongoing operational expenses for maintenance. | | Workload Mobility | Seamless mobility between on-premises and Azure NC2 environments. | Mobility restricted to on-premises infrastructure; requires WAN replication. | | Disaster Recovery Site Location | Cloud-based; Azure’s global footprint allows for wide geographic distribution. | Limited to the physical location of the on-premises DR site. Could be customer’s facility, or Colo, or both. | | Security and Compliance | Enhanced security with Azure’s compliance certifications and Nutanix’s built-in security features. | Managed within the organization’s security parameters, but compliance depends on Colo provider. | | Flexibility | High flexibility with quick adaptation to changing business needs. | Less flexible; changes often require physical hardware modifications. | | Operational Complexity | Reduced complexity; Azure’s infrastructure abstracts much of the operational burden. | Higher complexity due to the need to manage and maintain physical infrastructure. | | Resiliency | Leverages Azure’s global infrastructure for high resiliency and redundancy. | Resiliency is dependent on the on-premises infrastructure setup and redundancy plans. | | Data Residency | Data can be stored in specific Azure regions to meet compliance requirements. | Depending on facility location, it may require multiple sites for compliance with data residency laws. |
ConclusionLeveraging Nutanix Hybrid Cloud with NC2 on Azure for Disaster Recovery offers a compelling solution for organizations seeking a resilient, secure, cost-effective DR strategy. By combining the power of Nutanix’s HCI with the flexibility and scale of Azure, businesses can ensure that they are prepared for any eventuality without the complexities and costs associated with traditional DR solutions.
If your organization is looking to modernize its disaster recovery approach, consider Nutanix Hybrid Cloud with NC2 on Azure—a solution that meets today’s demands and is also ready for tomorrow’s challenges.
We Can Help!If you have any questions or are looking for assistance in choosing the right Nutanix option for your business, please reach out toinfo@eGroup-us.comor complete the form below.
PrevPreviousAnswering Your Top AI Questions… Without Using AI – Part Two###### Need Help With Your Disaster Recovery Strategy?
Contact our team of experts today!
The post Enhancing Disaster Recovery with Nutanix Hybrid Cloud and Nutanix Cloud Clusters on Azure appeared first on eGroup Enabling Technologies.
Answering Your Top AI Questions... Without Using AI PART TWO###### Kai Andrews
Data/AI/Power Platform Practice Leader
IntroductionIn my last post, we tackled some BIG questions around AI—what it is and how it works, along with potential dangers and benefits. Pretty heady stuff! This time, let’s shift gears and dive deeper into how to implement AI successfully. As I mentioned before, as a consulting team, we are presented with many questions around AI and these questions vary greatly depending on where the person/organization is on their journey to implement AI. The questions in this post are asked most often by those about to start an AI implementation, and they want to gain clarity as to what the design/build/deploy experience is like. Are you curious? Read on!
Part 2: Focusing on ImplementationQuestion 1: Are there limits as to what can be developed using AI?Modern AI capabilities seem nothing short of astounding, and with enough time and money, almost anything can be possible. Does that sound familiar? It should if you have ever taken on a custom development project. AI projects are no different. They too should focus on building functionality that solves a well-defined business problem—they just employ novel technology to do so– Because the technology is so new (and frequently evolving), there is increased uncertainty around project duration, cost, and effectiveness. In order to manage that uncertainty, and the risks that come with it, we highly recommend going through a process called a “Design Sprint” before committing to any kind of development effort.
A Design Sprint is a 2-3 week undertaking (typically), during which the initiative stakeholders (from both IT and the business team(s)) get together to identify the problem, understand the challenges, map out the underlying business process, and outline the desired solution outcomes. The technologists on the team can then outline possible technical solutions and begin to develop a level of effort to realize the desired solution. It is important to note that a Design Sprint isn’t going to provide you with exact and comprehensive cost and effort numbers. This is custom development after all, and it is foolish to believe that you can accurately predict what will happen during the implementation phase. However, now you are armed with much more detail and understanding than you were when the original problem statement was introduced.
Question 2: Waterfall or Agile – Which methodology is best for developing AI solutions?The short answer to this question is to use whatever methodology your team is familiar and comfortable with. It is unwise to force a new way of working on a team unless you are willing to invest the time needed to teach a new approach. The longer answer starts with a counterpoint—does the official methodology even matter, or is it more important how you approach the phasing of the work? What the heck does that mean?
Follow along for a second…
Waterfall implementation has been scoffed at over the years as being less effective in getting results quickly and helping an implementation team navigate changing requirements as users begin to use a product. This attitude stems from multi-month/year projects where all requirements were gathered and a team then sequestered themselves until they believed that the solution has been adequately developed and was ready for its big reveal… a reveal that often missed the mark since there was little user feedback incorporated into the development process.
So, what if we moved away from this literal “all or nothing” waterfall approach and adopted an iterative mindset? We could still gather all the requirements, but then, instead of developing the entire tool, requirements were broken down into phases and even levels of detail. The team could then develop parts of the solution and showcase the features, gather feedback, and refine the requirements. This is not as “scary” or challenging as adopting a full-blown Agile methodology may feel like to those who have not practiced it before. Key in on the concept of iterations and your AI project will move forward with a greater likelihood of success.
Question 3: What is an MVP?Nope, it’s not your Most Valuable Player on the team, though they are just as important and celebrated loudly and often. MVP, with regards to AI solution development, refers to a Minimum Viable Product. It represents a solution that is deployed to users that is functional and begins to address their overall needs. It will not incorporate every feature. It will likely still require additional user interface tweaks, and it may not provide the full promised ROI on the project. But it works—and it gives users the opportunity to provide feedback, and builds confidence in the team and stakeholders that progress is being made and a better future is possible.
Defining the MVP is more art than science. Stakeholder negotiations will prioritize feature sets and align everyone on what this important milestone represents. Use time to force a decision on which features are in or out for a given solution. Ideally, MVP status can be reached in 4 to 6 weeks. Use that constraint as a negotiating tactic. It will be uncomfortable at first, but in the long run, users will appreciate the process and the fact that they are getting value over time.
Question 4: How do I estimate an AI project’s total cost? Are you reading these answers and finding yourself yelling at the screen, “Stop with the iterations and MVPs already. How much is this going to cost me?!” I’m going to stick to my comments above and point out again that coming up with THE pricing estimate is a fool’s errand. However, if you embrace an iterative mindset and adopt the MVP approach, then you have all you need to provide a relatively firm estimate for the first release.
Do this…
First, form your team: a project manager, change manager, solution owner, tester(s), architects/engineers, and so forth. You can assign a weekly cost to each of these resources. Then, with the iterative approach, estimate how long it would take to get to MVP. Again, ideally you can reach this state with two to three 2-week sprints. Now you can do the math and come up with a total cost. OK, there are some nuances that I’m glossing over, but this is a logical and defensible way to create a project estimate. Given the uncertainty of custom development, it is the best you can do. If your sponsoring stakeholders do not have the appetite for uncertainty and the idea that there will be additional costs, maybe it’s time to explore purchasing a solution instead of building one.
Question 5: Why do I have to pay for a project manager and change management? Hoo boy, there are books written on this one.–So let me just point out that custom development, especially with new tools like AI, is a complex venture. If you’ve read my answers above, you know this to be true. Without a dedicated project manager leading the charge, who will negotiate the MVP scope? Who will manage the iterative sprint cycles? Who will communicate the updates? Who will coordinate testing and launch? There is no acceptable answer to these questions other than the project manager.
As for change management, let me ask this question—if we are taking an MVP approach, who will manage user expectations, provide training, and quell the mass hysteria surrounding the idea that, “AI is coming for my job?” The project manager and change management roles are non-negotiable. Not paying for them will lead to a project incurring multiples of the avoided cost in time overruns and unnecessary churn. 25 years of implementing solutions gives me the right to say just trust me on this one.
Question 6: When is my AI project done?Never. Not if you want to embrace all that AI has to offer. The technology will continue to evolve, and your business processes should be continuously evaluated for new efficiency improvements. Set up a Center of Excellence so that you can vet new developments and prioritize which initiative to tackle next. With a robust ROI evaluation model and strong development practices, your projects can fund themselves. Go explore!
We Can Help!If you have any questions or you’re looking for assistance with implementing AI , please reach out to info@eGroup-us.com or complete the form below.
PrevPreviousAnswering Your Top AI Questions… Without Using AI – Part OneNextEnhancing Disaster Recovery with Nutanix Hybrid Cloud and Nutanix Cloud Clusters on AzureNextNeed Assistance with Artificial Intelligence?Contact our team today to schedule a call with one of our experts.
The post Answering Your Top AI Questions… Without Using AI – Part Two appeared first on eGroup Enabling Technologies.
Answering Your Top AI Questions... Without Using AI PART ONE###### Kai Andrews
Data/AI/Power Platform Practice Leader
Part One of a Two-Part Series: Big Questions with Not-So-Big (But Still Really Good) AnswersAs eGroup Enabling Technologies’ Data & AI Practice Director, I get the privilege (seriously!) of meeting with individuals and organizations every day, and together, explore how to integrate modern data and AI capabilities into their business functions. For each conversation, we want to “meet folks where they are on their journey.” That’s just simple code for saying that some conversations are educational in nature, only discussing basic AI capabilities, while other meetings dive deep into specific functionality and project needs. Regardless of the type of conversation, some topics and questions come up over and over again. So I figured—why not compile these questions and answers in a couple of blog posts so that we all can benefit from these insights?
Before we begin, I am a proponent of giving credit where credit is due, and therefore I want to send a shout out to my talented team of architects and engineers. These individuals have contributed most of the learnings that make up the answers below. Our team collaboration highlights that the rapidly evolving data and AI space is too big for one person to embrace alone. It requires a team of passionate researchers and developers sharing knowledge and assisting one another on a regular basis. As such, the answers below are not “my” answers, but rather represent the learnings and perspectives from a broad team of contributors. Now, let’s get to those questions and answers, shall we?
Question 1: What Is Artificial Intelligence? (AI)Entire books have been written on this topic, so I’m not sure how to use a simple blog post to even begin tackling that subject. So let me refer to another question that I was asked recently to help narrow my answer. A customer challenged me to define AI without using the words ‘artificial’ or ‘intelligence.’ I love a challenge! Simply put, we see AI as “smart automation.” I don’t want to downplay the power of these new technologies and advances, but if we want to break these capabilities down to their basics, they are just automation routines. Mind you, the processing power, models, and adaptability of these new tools are truly revolutionary and allow us to leap way beyond simple process automation.
Systems can now decipher documents and images. They can generate new content and aggregate and distill large amounts of data. They can be easily integrated into many daily activities, freeing up time for more valuable activities (more on that point in a different Q&A pair). Finally, these new technologies are approachable. There are low-code development environments, and even the pro-code tools allow for relatively rapid proof-of-concept development. So, there you have it. AI is indeed the evolution of automation… or dare we say—revolution.
Question 2: How Does AI Work?Hey, what’s with all the hard questions? How am I supposed to use a paragraph to address how all the different AI capabilities work? Now don’t laugh, I do have a relatively concise answer here, and like my answer to Question 1 above, I’m going to use a two-word answer, “learning models.” Just like humans, AI needs to be taught and ultimately use those teachings to evolve its knowledge without additional human intervention—the very definition of artificial intelligence. AI is presented with “models” that allow it to learn and evolve. AI that interprets pictures is fed a large library of images (the model) to learn from. Document intelligence services are fed sample documents (the model) and taught how the document content and structure interrelate. Generative AI uses large language “models” that, in turn, allow the AI to respond to our questions and prompts.
For example, Copilot for Microsoft 365 builds a model, called a semantic index (actually, it builds two if you are counting) from all of your emails, shared content, texts, and relationships. It is then able to use this model, combined with a large language model, to “read” your prompts and generate answers based on the relationships. The more it learns about you and your associations, the better it will be able to respond. The last part in making AI act effectively and “work,” is providing context. Each AI solution is provided with guidance as to its purpose and the desired output. An AI system designed to detect cancer in patient images is given context as to what cancer is and what it does (and does not) look like. Copilot for Microsoft 365 understands the professional work environment that it is deciphering. This context keeps the AI aligned to its tasks and should keep it from hallucinating. There you have it… AI works through learning models.
Question 3: What Is The World’s Largest Artificial Intelligence?This is a fun one! I can sum up my answer by simply quoting one mythical green Jedi Master; “Size matters not!” Seriously, though, the effectiveness of AI is not necessarily based on the size of the model being used to teach the AI. Sure, feeding an AI more examples allows for improved accuracy, but it is not necessary to employ the “world’s largest” AI to get effective results. For example, we recently designed a document intelligence solution that read through complex PDFs to find and extract certain data elements. We only needed to feed the system three sample documents before we started to see the AI function with an 80%+ success rate. Your mileage will surely differ, but it will come down to your use case/need and not necessarily the size of your training model.
Another proof point that size doesn’t necessarily matter, is the fact that AI vendors are publishing more and more small models that are designed to address specific functions. Instead of having to use one of the largest natural language models (like OpenAI), there are smaller, more efficient, and more affordable models are available for use. Now, you are probably wondering, “Is he going to answer the actual question?” Well, that would be difficult to do because I’m not sure how to define and measure “size.” Are we talking large language models or some other AI tech? I’ll let OpenAI, Meta, Amazon, IBM, and others battle it out and keep innovating, providing us with the “right” models, but maybe not the largest.
Question 4: Is AI Dangerous?To answer this one, I’m going to employ what many of you see as an annoying consultant trait—answering a question by asking another question.
How do you define dangerous? And from whose perspective?
Yes, AI can be dangerous. It is, after all, a form of automation (see my answer to Question 1 above). Automate the wrong task, or put too much decision making and trust into faulty AI logic, then bad results could follow.
What if an AI model was tasked with identifying outdated information and given the ability to delete said content based off defined retention logic? What if that AI was not trained well enough to understand exceptions, deleting critical messages and documents that put the firm at risk in legal proceedings, for example? That is dangerous in its own right. This is where the concepts embodied in “responsible AI” come into play. Every AI solution needs to be evaluated on an ethical basis and designed with human checks and balances, reviewing output and logic on a regular basis to mitigate the dangers.
What if we redefined “danger” altogether and take the perspective of someone whose job is at risk of being eliminated by AI? In that case, even the most effective AI tool is a threat. Once again, responsible AI practices can help mitigate this situation. Organizations can evaluate job impacts and elect to retrain employees. Not only should AI systems be transparent in their logic and intent, but so should organizational leadership. Publishing AI charters can go a long way in warding off fear and uncertainty posed by “dangerous” or “threatening” AI. I have no intention of downplaying the impacts, good or bad, that AI can have on our future. I simply want to highlight that humans are the orchestrators of our future and bear the responsibility to proactively address these concerns.
Question 5: What Are The Benefits of AI?We believe that AI-produced benefits can be visualized as a hierarchy of benefits. If we start at the top of this hierarchical pyramid, AI benefits can be summed up with two words: “efficiency” and “quality.” AI, at its core, is a modern and advanced form of automation (again, see my answer to Question 1 above). Automation should, by its very nature, produce outcomes more quickly due to process steps being removed or optimized. These same automations can improve the quality of the output due to computerized processes being more consistent and predictable. These outcomes are dependent on the AI solutions being both well-designed, as well as checked by responsible AI principles.
Each of these core benefits now expands into sub-benefits. Efficiency, for example, can lead to improved work/life balance, which leads to happier employees, which results in higher retention rates. Another benefit trail leads us from higher-quality customer experiences to an improved marketplace reputation, and ultimately to higher sales. There are many dependencies to realize these cascading benefits. I already mentioned the need for responsible AI and good design. Other requirements include a defined vision, adequate funding, long-term commitment, a willingness to experiment and possibly fail, and most importantly, transparency and communications across the organization. But, all of these dependencies are best tackled in a different answer…
Hop on over to PART TWO of this blog post to find out!
We Can Help!If you’re unsure where to begin with AI, or need help planning, designing, and/or implementing your vision, visit our Artificial Intelligence page or reach out to info@eGroup-us.com.
PrevPreviousDive Into Business Processes to Improve Data Governance and AI EffortsNextAnswering Your Top AI Questions… Without Using AI – Part TwoNextNeed Assistance Implementing AI?Contact our team today to schedule a call with one of our experts.
The post Answering Your Top AI Questions… Without Using AI – Part One appeared first on eGroup Enabling Technologies.
Dive Into Business Processes to Improve Data Governance and AI Efforts###### Tom Papahronis
CIO Advisor
We engage with a lot of small- to mid-sized organizations that are in different phases of planning or implementing data governance, compliance, or AI initiatives. I have noticed that there is a common circumstance that can slow down or frustrate these projects: The people tasked with getting a data governance program off the ground (often the technology team) lack a meaningful understanding of how and why the critical business processes that use confidential data actually work.
Larger organizations often have business analysts or they can bring in external help to map and document the data and processes, but small businesses almost never do. At most, there is some tribal knowledge about them, but never enough information to be able to help guide the organization through a true data governance effort that identifies sensitive data, its locations, and the processes that rely on it. As a result, the organization struggles to implement governance policies to address compliance and risks, including AI tools that can expose over-permissioned information.
Much of the time there is a cultural gap here too—whose job is it to know about these processes across the organization? This responsibility has typically not been formalized (or everyone assumes someone else is doing it).
Historically, the focus of IT teams has been on keeping systems secure, available, and performant. I am now seeing that cloud SaaS, data, and AI tools are starting to develop their own gravity and have started to pull that same IT team into needing more data and process expertise as well. The Technology group is uniquely positioned to add significant value here. They already have a global understanding of what platforms, applications, and storage locations are in use, along with responsibility for security. Working with the business units to document what sensitive data they use can be an almost natural extension of those responsibilities.
Here are some tactics that I have used in past organizations to start understanding where confidential data is used and why.
Completing discovery and documentation of processes for the base cases discussed above, you can rinse and repeat the methodology as you review all areas that handle sensitive information to form the overall governance policies and controls.
We Can Help!If you’re interested in learning more, Download our Microsoft Purview eGuide discussing the Four Feature Realms that Purview has to offer. If you have any questions or you’re looking for assistance with Data Governance, please reach out to info@eGroup-us.com or complete the form below.
PrevPreviousDelegating Teams Administration with Administrative UnitsNeed Assistance with Data Governance?Contact our team today to schedule a call with one of our experts.
The post Dive Into Business Processes to Improve Data Governance and AI Efforts appeared first on eGroup Enabling Technologies.
Delegating Teams Administration with Administrative Units ###### Chris Stegh
CTO & VP of Strategy
Background and Problem Statement In large organizations such as state governments, university systems, or multinational corporations, managing communication systems across diverse regions and departments is complex. Traditionally, phone systems were managed locally to allow for tailored decisions about local telecom providers and budgets. Regional or campus teams managed their own specific systems.
In a shared Microsoft 365 tenant environment, Teams Phone settings have been managed tenant-wide. This often meant that administrators had to be granted control over all regions, subsidiaries, or departments, leading to potential control and security concerns.
Imagine a large corporation where the phone systems in EMEA (Europe, Middle East, and Africa) are managed by a different team than those in APAC (Asia-Pacific) or the Americas. Similarly, consider a state government where the Department of Transportation’s phone services are managed separately from those of the State Legislature office. These scenarios highlight the need for a more granular and flexible administrative approach.
Expanding Administrative Units (AUs) To address this challenge, Microsoft has been slowly improving the use of Administrative Units (AUs). Now, global administrators can delegate administration to specific subsets of users based on attributes such as department, location, or business unit. This capability enhances management flexibility and security by ensuring that administrators only have control over their designated areas.
Use Cases and Value The introduction of AUs brings several valuable use cases and benefits:
| Role | Capabilities | | --- | --- | | - Teams Administrator | Full control over Teams settings and policies within the AU. | | - Teams Device Administrator | Manage Teams devices (phones and room video systems), including configuration and updates. | | -Teams Communication Administrator | Oversee communication settings, including messaging and meetings. | | -Teams Communication Support Engineer | Provide advanced support for communication issues, including troubleshooting and diagnostics. | | -Teams Communication Support Specialist | Offer basic support for communication issues, focusing on user assistance. | | -Teams Telephony Administrator | Manage telephony settings, including PSTN (Public Switched Telephone Network) configurations and call quality. |
Preparing to Employ AUs This capability will appear automatically in September, with no admin action required beforehand to enable it.
However, there is much planning to consider about who should get which controls. Generally, Zero Trust calls for least privileged access, and considering all the options even within an AU, there are decisions for large, siloed organizations to make.
The table summarizes the main considerations and actions:
| Consideration | Action | | --- | --- | | - Which attributes to use to group admins into AUs? | You can use any Entra ID attribute or extension attribute to create AUs. For example, you can use department, location, business unit, etc. Choose the attributes that best reflect your organization’s structure and management needs. For instance, admins of Campus #1 should be assigned to users in the AU associated with Campus #1 (likely determined by an Entra attribute such as Location). | | - How many AUs do you need and what are their names? | Each AU must have a unique name and a description. You can use descriptive names that indicate the scope and purpose of each AU. There are limits to the number of AUs in a tenant. | | -Who are the admins for each AU and what are their roles? | You can assign one or more admins to each AU and grant them specific roles. There are limits to the number of AUs a person can join. | | -What are the Teams settings and policies for each AU? | You can apply different Teams settings and policies to each AU to control the features and capabilities of Teams for the users in that AU. For example, you can enable or disable chat, calling, meetings, phones or room systems, and access settings and policies for each AU. | | -How will you monitor and audit the activities of each AU? | You can use the Teams admin center and PowerShell cmdlets to view and manage the AUs in your tenant. You can also use the Microsoft 365 audit log to track the actions performed by the admins and users in each AU. |
Summary Large organizations who have different administrators handling different locations, campuses, or departments have wondered “Should I give administrator A in campus A access to controls over campus B-Z as well?” Now, decentralized organizations can divide/conquer administrative duties, without having to overprovision their admins.
Imagine a phone expert in Asia having control over phone updates and the telecom connectivity settings for South America. Or more concerning, a person in the Department of Transportation having control over settings in the Department of Finance.
The expansion of Administrative Units in Microsoft Teams represents a significant enhancement in the way large organizations can manage their communication systems. By providing more granular control and tailored management options, AUs will help break down an important barrier to Teams adoption.
PrevPreviousTeams Phones Major Updates Have Begun###### Have Questions or Need Help with Microsoft Teams?
Contact our team of experts today!
The post Delegating Teams Administration with Administrative Units appeared first on eGroup Enabling Technologies.
Teams Phones Major Updates Have Begun###### John Miller
Cloud Solutions Architect
IntroductionThis is a follow up to our earlier article about the major upgrades to native Teams phones taking place this year:
Microsoft recently published Migrating Teams Android Devices to AOSP Device Management from Device Administrator. This article describes:
Some organizations have added enrollment, compliance and conditional access policies to Intune to manage native Teams phones. This article tells you what to do to prepare to move these managed phones from the Android Device Administrator platform to the AOSP platform. This must be setup before upgrading these managed devices to Android 12. If You Currently Manage Native Teams Phones in Intune – READ THIS!Two (2) years ago I summarized the information from Microsoft about how to enroll native Teams phones in Intune:
Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 1)
Native Teams phones running the Android 9 operating system have run under the Android Device Administrator (ADA) platform. Intune is ending support for ADA beginning December 31, 2024.
If you have setup Intune to enroll and manage native Teams phones based on the ADA platform, you must prepare your organization before the support ends.
You should complete these steps before upgrading any enrolled phones to the Android 12 operating system. If the AOSP enrollment policy is implemented in Intune, Microsoft states that when you upgrade an enrolled native Teams phone, Intune will automatically re-enroll the phone using the AOSP enrollment.
The steps to setup AOSP managed native Teams phones are very similar to those in the original articles, mentioned previously. Rather than completely reproduce those blogs, I will just provide the required changes here.
Create an AOSP Enrollment Profile
Click “Create profile.”
Type in a name for the profile.
Click the “Next” button.
Click the “Create” button on the next screen.
Create an AOSP Management Configuration Policy
Click the “Create” button.
Provide a name for the policy.
Click the “Next” button.
Click on “General.”
Click the “Next” button.
Click the “+ Add all devices” button.
Click “Edit filter.”
Click on the “Include filtered devices in assignment” button.
Click the “Select” button.
Click the “Next” button.
Click the “Create” button.
Create a Device Compliance Policy for the Teams Phones Follow the steps in the first blog article. At step “3”, choose “Android (AOSP)” instead of “Android Device Administrator”. * Provide a new unique name for the policy and add a description as needed. * The Intune Compliance Policy Options for the Teams phones from September 14, 2022, remain the same. Exclude Android Device Administrator Devices From App Protection Policies When you look at the settings for this that you previously made, you should see that Android AOSP devices have been added to the “Device Types” section. Firmware Upgrade Notes *Do not upgrade phones enrolled in Intune until you have prepared Intune to enroll and manage these upgraded phones. Please see the information above. * The current certified firmware versions for Native Teams Phones, Android Rooms, Displays and Panels can be found on the Microsoft Teams certified Android Devices Web page. AudioCodes The current firmware release from AudioCodes is 2.3.423. * The firmware can be installed through the Teams Admin center or the AudioCodes OVOC management platform. * AudioCodes C448s and C450s phones cannot be upgraded to Android 12. + AudioCodes has provided a few methods for converting these phones to function through the Teams SIP Gateway: - They can be switched through the OVOC platform’s Device Manager module. - The change can be made through the phone’s web interface. - Upgrading through the Teams Admin Center If your phones are not currently running version 2.3.423, they can be upgraded through the Teams Admin Center (TAC). Please refer to the Update Microsoft Team devices remotely Microsoft article. * Upgrades through the Teams Admin Center are made incrementally. For example, if you have a phone that is running version 1.17.561, you will probably have to run through a few intermediate upgrades before the TAC finally installs version 2.3.423. - Upgrading through the AudioCodes One Voice Operations Center (OVOC) AudioCodes native Teams phones can also be upgraded through the Device Manager module of the OVOC management platform. * You must own Device Manager licenses to be able to use the module to manage and update your phones. * The Device Manager will let you install specific versions of the firmware to your devices. * Before installing version 2.3.423, phones should be running version 1.19.642. * Upgrading phones running earlier versions to 2.3.423 is not recommended. HP | Poly The current firmware release from HP | Poly for the native Teams phones is 9.0.0.10315. * It does not appear that this release is available through the Teams Admin Center as of August 9, 2024. · It can be installed using the Poly LENS platform. * If a phone is running a firmware version older than 8.1.4, the upgrade to 9.0.0.10315 will automatically install version 8.1.4 as part of the upgrade process. Yealink* The MP54, 56 and 58 have been certified by Microsoft through October 4, 2026, running version 122.15.0.135. * The CP965 is certified through the same date running 143.15.0.48. * The MP52 is not in the list. This suggests that this model cannot be upgraded to Android 12. Please check with Yealink if you have any of these phones. * Available versions:
+ **145.15.0.83:** for the MP52 released on January 18,2024. This version appears to run under the Android 9 operating system.
+ **91.15.0.136:** for the VP50 released on the same date.
+ **122.15.0.142:** for the MP54, 56 and 58 released on October 9, 2023. This version appears to be based on Android 12.
SummaryThe changes for Native Teams Phones have begun updating them to run under the Android 12 operating system and replacing the Android Management platform in Microsoft Intune. Organizations should follow the guidance and upgrade their phones before Microsoft starts to deprecate the Android Device Administrator platform at the end of the year. While Microsoft has not provided specifics, it should be inferred that phones currently managed in Intune on the Android Device Administrator will cease to be managed when this platform is sun downed in Intune. We are working with Microsoft to determine how to continue to enroll and manage these devices in Intune.
Stay tuned to the eGroup Enabling Technologies news page for updates! eGroup Enabling Technologies is available and ready to answer any questions that you might have about Microsoft Teams, Teams Phone, and Teams Devices. If you need help with implementing or migrating to Microsoft Teams or Teams Phone or upgrading your devices, please contact us at info@eGroup-us.com.
Links Intune ending support for Android Device Administrator on devices with GMS in December 2024. * Microsoft Teams certified Android Devices * AudioCodes Product Notice #0506 * Poly Voice Software 9.0 | Poly Lens Help * Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 1) – eGroup Enabling Technologies (egroup-us.com) * Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 2) – eGroup Enabling Technologies (egroup-us.com) PrevPrevious5 Common Objections to Azure VMware Solution – AnsweredNextDelegating Teams Administration with Administrative UnitsNextNeed Assistance with Microsoft Intune?*Contact our team today to schedule a call with one of our experts.
The post Teams Phones Major Updates Have Begun appeared first on eGroup Enabling Technologies.
5 Common Objections to Azure VMware Solution – Answered###### Jason Webster
Field CTO, Microsoft 365 & Azure
When discussing Azure VMware Solution, I often receive one of a handful of reactions ranging from real or perceived technical and financial challenges. Today, I’ll touch on a few of those common obstacles I most commonly receive.
“Azure VMware Solution costs more than my infrastructure”While this is a true statement, it doesn’t reflect an apples-to-apples comparison of what you are purchasing with AVS. With AVS, as depicted below, you are not only buying servers and storage, but you are also buying facilities, services, and maintenance that allow you to focus your team on tasks that create value for your business, not maintenance.
It’s a tough sell but I particularly enjoyed the perspective of our friends at the State of Alaska, “Migrating to Azure has empowered us to focus on the data and the meaningful changes that we can start making” (read more). Niel Smith (Deputy CIO), makes the case that most organizations really struggle in understanding the true and total cost of ownership for their data centers. Something I couldn’t agree with more. We can solve this through sizing and migration planning exercises to clarify what your operational costs of running in AVS would be. From there, we can compare that to the total costs of everything in the yellow and orange sections above.
“I have a storage heavy environment and the amount of AVS nodes I would need to purchase to meet my needs is cost prohibitive.”This is a great objection. It is rooted in the fact that AVS nodes are fixed to a limited set of options and if you are “storage heavy”, meaning, you have a lot of need for storage with relatively low needs for compute and memory, you could be in a situation where you are “wasting hosts” to meet the storage requirement. This makes AVS untenable from a pricing perspective with compute costs so high. Answer: Our partners at Pure Storage offer external block storage that allows you to separate storage from AVS to find the correct balance. With Pure Cloud Block Store, you can get the right fit for your data heavy workloads.
“When using AVS for Disaster Recovery, it’s going to cost money to have the nodes I need when declaring a disaster. It’s also going to take time to add those nodes.”In this scenario, all the points are correct. However, I’d argue that this is a strength of the solution vs. a weakness.
Mainly because:
The considerations you need to think about in this scenario are essentially the time it takes Microsoft to provision nodes to your environment. Planning your minimal size (minimum nodes at the ready) for rapid recovery operations (sub 1-hour RTOs) and additional nodes for those +1/+4 hour Recovery Time Objectives (RTOs). Effectively balancing your steady state costs and cost savings for your desired RTO.
“Our applications require us to be on-premises”The frequent concern is well-founded. Current research indicates that approximately 50-55% of operations for businesses will continue to be on-premises in the coming years. Not all processes are fit for the cloud owing to security, availability, and network needs, which highlights the advantage of bare metal as a service (BMaaS) options such as AVS, compared to Infrastructure as a Service (IaaS) models.
AVS is managed in the same way as on-premises ESXi. VMware management can “see” AVS as another datacenter/cluster and allows mobility of applications between on-premises and the cloud. This provides several benefits:
AVS isn’t a blocker to on-premises requirements. In fact, it’s a strength in allowing flexible options so applications can run where they are best suited with a consistent management experience for IT teams.
“When we go to cloud, our preference is to modernize applications, not lift and shift”Like the previous concern, AVS aids in modernization by offering conventional infrastructure options that integrate seamlessly with Azure platform services on high-performance, low latency, networks. This helps app and infrastructure teams avoid challenging interdependency issues during modernization efforts. It’s possible to update applications, data, and storage layers separately without compromising on efficiency. This results in quicker and more effective team modernization.
Conclusion:Hopefully you found this helpful. I would love to hear other challenges and objections for BMaaS solutions you have. I am a firm believer that the goal of technology is to provide applications and data to people that allow them (or their businesses) to be more productive. We have a range of technical tools available to us to be effective, we just need to understand the goals to choose the right one. If you are interested in digging in, reach out for a discussion or a Technology Strategy Review today.
PrevPreviousCrowdsourced Incident Response Plan Tabletop Exercise Results###### Schedule a Technology Strategy Review
Contact us to discuss further how your team could benefit from a Technology Strategy Review with our team of experts.
The post 5 Common Objections to Azure VMware Solution – Answered appeared first on eGroup Enabling Technologies.
Crowdsourced Incident Response Plan Tabletop Exercise Results ###### Chris Stegh
CTO and VP of Strategy
Table of ContentsInterested In Comparing Your Ability To Respond To Cyber Incidents To Others'?This blog provides details of a noteworthy cyber incident, and data about how a variety of organizations would manage it. This information comes from a crowdsourced tabletop exercise led by our Strategic Advisory team. You’ll find poll results and discussions about the good, bad, and gaps.
Why are we sharing this data?
In many small/medium businesses, incident response plans either don’t exist, are lacking, or don’t often get stress tested. This, in spite of the fact that the Ponemon Institute found that lost business costs due to data breaches averaged $1.42 million in 2022.
This article also provides some insights on how an Incident Response Tabletop Exercise works. Read on if you’re curious about how your cyber incident response measures up.
Scenario 1: Supply Chain Compromise We posed the first question to replicate a trending incident.
“You apply a routine, vendor-provided update to your Enterprise Resource Planning (ERP) application. Things seem to be working as expected immediately after the change. The system is put back into production and is processing transactions.
Several days later, you are notified by the vendor that they were compromised and that this recent patch contains exploit code….”
We know this is an unfair but all too common situation. Ever since SolarWinds, adversaries have purposefully infiltrated the systems, that when weaponized, impact the most downstream organizations. Very recently, well-meaning vendors have created their own problems.
Question 1: Would You Know Something Is Wrong? Less than 25% of respondents felt they would get early warning about the incident.
In this case, tools matter. That’s why 25% of participants with a Security Information Event Management (SIEM) and User and Entity Behavior Analysis (UEBA) believe they’d have a chance of detecting the incident.
75% of respondents are right not to be overconfident.
Why?
In the infamous SolarWinds incident, the first people to ID the issue wasn’t SolarWinds. It was discovered by the SecOps engineers at the cyber monitoring firm FireEye (now part of Google). As SolarWinds users, they only found the breach after exhausting every other lead. They’d looked everywhere else before finally decompiling SolarWinds’ code (18000 files, 3500 executable files, and 1M lines of assembly code) to find the implant.
After thousands of hours of looking at every other place, FireEye’s CEO described the implant as “The last place, not the first place, you’d look” to ID the benign looking traffic. This was months after they started looking, after picking up a stealthy IP session to an unknown server on the Internet, posing as a SolarWinds server.
In other words, if it took cyber pros months to detect the issue, your SIEM and UEBA need to be uber-aware to notice such stealthy changes. It’s a safer approach to assume breach every time you patch your servers and applications.
Question 2: What Would You Do First? Now that responders are aware of an issue, they responded in the following way:
Those that disconnect the server right away would be wise to at least ask for business leadership’s approval for isolating a critical system. One participant wisely asked, “Where is the option to “Initiate the Incident Response Plan?”
In a real tabletop exercise, subsequent follow up questions would be asked:
Tabletop leaders would then ask some logical steps about the expected process….
The questions posed by the tabletop leader can (and should) become harder. They should weave between people, process, and technology/tools. All parts of the incident response should be covered, including business impacts, stakeholder communication, and potentially restoration (to a known/good version).
Which led to question 4…..
Question 4: Do You Have A Way To Roll Back The Change Back To Before The Compromise And Re-Run All The Transactions That Were Using The Compromised Code?43% of respondents said they do, meaning 57% have a crucial decision to make:
a. Leave the server running on a known/compromised version
or
b. Continue to leave it in a disconnected state, with severe business impact
We couldn’t see the faces of our participants, but we’d envision a few discomforted looks! That’s OK! It’s better to know (and communicate) to management so that you can get resources to close such gaps, or at least set proper expectations.
Question 5: Where Does The Process For Responding To This Incident Exist: No matter how the previous questions have gone, our final question for any incident is asking where the process for responding is documented.
Props go to the participants that take their ERP seriously enough to document a playbook!
Even more applause to those who have tested the recovery!
For those well-prepared organizations, a good tabletop coordinator would typically inject a curveball, an unforeseen and potentially bizarre situation. In this case, had our collective audience passed the previous tests, we’d ask a 6th question: “The ERP compromise is reported on the national news the next day, and your #1 Salesperson is asked by your #1 customer how you are handling it. What’s next?”
More than we’d like to admit, we hear that incident responders store their plans “in their heads.” They’re not in a binder or offline soft copy. They’re neither known nor accessible by their peers or successors. We trust that those folks now have some proof to management that investing time and resources in such efforts is necessary.
Bonus Question: What Did You Learn? At the end of each scenario, it helps to ask all participants to share their thoughts. Some of our respondents obliged when we asked the crowd. Assembled in a word cloud are their responses.
I’d like to point out one comment, “perfect documentation.” While yes, that will make an optimal response possible, documentation is not as valuable as practicing, continually identifying gaps, and being able to count on one another to think on the fly.
Don’t let perfect be the enemy of good.
Summary: FEMA, NIST, CISA, and the White House often implore organizations to practice their response to cyber disasters. Some cyber insurance carriers are starting to require it.
The media and legal communities love to highlight those that don’t have an efficient IRP in place.
It’s impossible to understate the importance of practicing and adapting to different scenarios in disaster response.
Here are some takeaways:
Dos and Don’ts:
– Do practice and identify gaps in your response plan.
– Do communicate effectively with your teammates.
– Do share your thoughts and lessons learned after each tabletop scenario.
– Don’t let perfect be the enemy of good. Get started in some way today!
– Don’t rely solely on documentation or protocols. Teamwork and practice are key.
– Don’t ignore the feedback from the line of business participants. They own this too!
If you find yourself without the time or authority to execute an internal tabletop exercise or make progress closing your gaps, our Strategic Advisory team is at your disposal.
Editor’s note: We did run a second simulation – about an executive losing their mobile device out of the country on a Saturday while working on an M&A docket. Contact us if you’d like to benchmark how you’d handle that one!
If you have questions or would like assistance with your Incident Response strategy, please reach out to info@eGroup-us.com or complete the form below.
PrevPreviouseGroup Enabling Technologies Recognized on the 2024 Inc 5000Looking for Guidance or Assistance with your Incident Response Strategy?Contact our team today to learn how we can help.
The post Crowdsourced Incident Response Plan Tabletop Exercise Results appeared first on eGroup Enabling Technologies.
eGroup Enabling Technologies Recognized on the 2024 Inc. 5000
Charleston, South Carolina, August 13th, 2024 — Inc. revealed today that eGroup Enabling Technologies was recognized on the 2024 Inc. 5000, its annual list of the fastest-growing private companies in America. The prestigious ranking provides a data-driven look at the most successful companies within the economy’s most dynamic segment—its independent, entrepreneurial businesses. Microsoft, Meta, Chobani, Under Armour, Timberland, Oracle, Patagonia, and many household-name brands gained their first national exposure as honorees on the Inc. 5000.
“We are extremely excited to be named one of the Inc. 5000 fastest-growing private companies. This honor results from our team's incredible work and the solutions we provide for our valued customers. Our dedication to bringing outcomes to our customers that allow technology to work for them, and make them better, is what continues to drive us forward. We are excited for what the future holds and how we’ll continue to grow together.”
– Ben Gaddy, Principal, Operations
The Inc. 5000 class of 2024 represents companies that have driven rapid revenue growth while navigating inflationary pressure, the rising costs of capital, and seemingly intractable hiring challenges. Among this year’s top 500 companies, the average median three-year revenue growth rate is 1,637 percent. In all, this year’s Inc. 5000 companies have added 874,458 jobs to the economy in the last three years.
“One of the greatest joys of my job is going through the Inc. 5000 list,” says Mike Hofman, who recently joined Inc. as Editor-In-Chief. “To see the intriguing and surprising ways that companies are transforming sectors, from healthcare and AI to apparel and pet food, is fascinating for me as a journalist and storyteller. Congratulations to this year’s honorees for growing their businesses fast despite the economic disruption we all faced in the last three years, from supply chain woes to inflation to changes in the workforce.”
- Mike Hofman, Inc. Editor-In-Chief
eGroup Enabling Technologies is a leading IT solutions service provider known for its commitment to innovation, reliability, and client-centric approach. Focused on empowering organizations nationwide, eGroup Enabling Technologies specializes in delivering tailored solutions that drive efficiency, productivity, and growth.
At the heart of eGroup Enabling Technologies’ success lies its team of highly skilled professionals, who possess a deep understanding of business technology and strategies. Their expertise allows them to offer a comprehensive suite of services, including cloud, hybrid data center, cybersecurity, data and AI, consulting, organizational change management, and managed services.
About eGroup Enabling TechnologieseGroup Enabling Technologies provides IT solutions and Managed Services that empower organizations to achieve their business objectives. They specialize in helping their clients harness the power of technology to drive innovation, enhance security, and optimize operations.
About Inc.Inc. Business Media is the leading multimedia brand for entrepreneurs. Through its journalism, Inc. aims to inform, educate, and elevate the profile of our community: the risk-takers, the innovators, and the ultra-driven go-getters who are creating our future.
For results of the Inc. 5000, go to www.inc.com/inc5000.
Contact Our Team!Looking to team up with experts who have 30+ years of experience delivering successful outcomes in areas such as cloud migrations, productivity and collaboration, security, consulting, data and AI, and organizational change management?
Fill out the contact form and our team will be in touch shortly!
The post eGroup Enabling Technologies Recognized on the 2024 Inc 5000 appeared first on eGroup Enabling Technologies.
Incident Response Plans: What Are They and Why Do They Matter to Your Organization?###### Jenn Johnson
eGroup Enabling Technologies
Consider These FactsHuman error accounts for a whopping 95% of cybersecurity breaches—and contrary to common belief, cybercriminals and hackers tend to exploit vulnerabilities outside of the IT department, capitalizing on the weakest links within your company.
A mere 38% of organizations worldwide assert that they are ready and prepared to tackle sophisticated cyberattacks, while about 54% report experiencing one or more attacks within the past 12 months.
While the staggering statistics above are disheartening, organizations can be prepared for the worst-case scenario to protect their digital assets in the event of a cyber attack by implementing an Incident Response Plan.
What’s an Incident Response Plan?An Incident Response Plan (IRP) is a structured approach designed to handle and manage the aftermath of a security breach or cyberattack. The goal of an IRP is to identify, respond to, and recover from incidents in a way that limits damage, reduces recovery time and costs, and mitigates future risks.
What are Incident Response Plan Tabletop Exercises?Every IT organization should have an incident response plan. It is intended as a guide for IT staff to use in the event that the organization suffers any disaster described in the plan.
Putting it plainly, tabletop exercises are a test of your organization’s response to real-world threat scenarios to find out if your organization is adequately prepared. Putting your plan to the test.
Tabletop exercises include a test run to find out whether your incident response plan sufficiently addresses likely threats to business continuity with the goal being to increase the team’s ability to detect, mitigate, and recover from cyberattacks effectively, thereby improving the overall cybersecurity posture and resilience.
By understanding how to respond to such incidents, you can mitigate their impact, empowering your organization to develop proactive strategies that minimize risks and prevent future occurrences, thereby safeguarding your digital assets.
Are Incident Response Plan Tabletop Exercises Worth the Cost?Calculating the Return on Investment (ROI) of incident response plan tabletop exercises involves assessing the cost of the exercise and time investment of the team against the potential benefits and cost savings that result from improved incident response capabilities. Improved response capabilities contribute to overall risk reduction and business continuity, helping your organization avoid costly disruptions and maintain operations during security incidents. It’s important to assess the value of risk mitigation and business resilience in relation to the costs of potential disruptions. The potential benefits aren’t always immediately recognized because they are preventative measures being taken to achieve most of these benefits.
Who Should be Involved in Incident Response Plan Tabletop Exercises? Incident response plan tabletop exercises typically involve professionals from various job roles to ensure comprehensive coverage of incident detection, analysis, and response. Some key job roles that should be involved include: Cybersecurity Analysts, Incident Response Coordinators, Digital Forensic Analysts, Network Security Engineers, Security Operations Center (SOC) Analysts, IT Administrators, Legal and Compliance Experts, Communication and PR Specialists, Operational Staff, and Executive Leadership.
By involving professionals from diverse job roles within your organization, these exercises ensure comprehensive coverage of all critical aspects, including identifying potential threats, understanding their impact on the business from various perspectives, and coordinating an effective, unified response. This holistic approach ultimately strengthens your organization’s security posture and positions your team for an effective response effort.
When is the Best Time to Conduct an Incident Response Tabletop Exercise? Yesterday! It’s crucial to proactively train employees on incident response procedures before a security incident occurs. By conducting tabletop exercises in advance, your organization can better prepare your team to prevent, understand, and respond to incidents effectively, reducing the impact of potential breaches or prolonged repercussions.
It’s also common to incorporate incident response plan tabletop exercises into annual training or onboarding, before implementing new technologies or applications, or after security incidents and breaches.
Ultimately, the best time to conduct an incident response plan tabletop exercise is when it aligns with your organization’s strategic objectives, operational priorities, and compliance obligations. Regularly scheduled tabletop exercises not only help ensure that employees are adequately prepared to respond to cybersecurity incidents effectively, but can also help you meet your cyber insurance requirements.
What’s the Next Step? Choosing the right provider to conduct an incident response plan tabletop exercise for your business is crucial to ensuring its effectiveness and relevance to your organization’s needs. With over 30 years of experience, eGroup Enabling Technologies’ team of security experts can help you put your incident response plan to the test. Gain visibility into real-world threat scenarios, along with clarity into best practices to strengthen your threat response and security posture for the long term.
We Can Help!Interested in testing your team’s Incident Response Plan? Schedule an Incident Response Tabletop Exercise with our experts by reaching out to our team at info@eGroup-us.com or completing the form below.
"Working with eGroup Enabling Technologies on developing tabletop exercises for our top threats was an integral part of upgrading our information security risk management plan. It was a great experience and helped us identify and fill critical gaps in our own internal procedures. These documented exercises are serving as a training tool for all IT staff as well."
—Erica Feldkamp, VP of Information Technology and Security at Internews Tweet
PrevPreviousAugust 2024 NewsletterNexteGroup Enabling Technologies Recognized on the 2024 Inc 5000NextNeed Assistance With Your Incident Response Plan?Contact our team today to schedule a call with one of our experts.
The post Incident Response Plans: What Are They and Why Do They Matter to Your Organization? appeared first on eGroup Enabling Technologies.
August 2024 NewsletterTable of ContentsWhat’s the Buzz at eGroup Enabling Technologies?Following the Broadcom acquisition, VMware transitioned from perpetual licensing to a subscription model in December 2023. Since then, we have seen some customer’s renewals increase 2-3 times the amount of their last renewal. Check out the following resources to better understand your options and help you choose the best path forward for your organization:
On-Demand Webinar:
– VMware Renewals – Evaluating Options to Make Informed Decisions
Blog Posts:
– How to Handle Hypervisor Disruption
– Navigating the VMware License Increase
– Cloud-First vs On-Premises Computing: Contrasting Views
– Azure VMware (AVS) vs Data Center/Azure Native
What’s New in the Hybrid Data Center?Cisco The recommended code for NX-OS has been updated, with 10.3(5) becoming the current recommended maintenance release.
* Cisco Umbrella for Government achieves FedRAMP “Authority to Operate,” bringing DNS threat intelligence and Protective DNS to customers requiring FedRAMP.
Cohesity Maintenance and Security patches were recently released for both 6.8.2 and 7.1.2 U1, including both Security/CVE and product patches.
+ On-Prem customers:
Customers running 6.8.1_u4 and earlier software versions MUST upgrade to 6.8.1_u7 software version prior to 6.8.1_p17/6.8.1_p17s1 and later patch application
+ Oracle Adapter Customers:
Oracle Adapter customers with Replication configured are advised not to apply patch 6.8.2_u1p20240709 to your cluster at this time. Please await the release of the next patch for the 6.8.2 branch.
* Check out this solid article from Cohesity on their approach to backing up EPIC systems, with a multi-faceted approach to the different modules, focusing on Cache, Clarity and Caboodle, and other EPIC sources. Cohesity’s ability to backup the EPIC Cache database using MegaFile helps dramatically decrease backup times and speed up recovery!
Nerdio Making its inaugural appearance in the Hybrid Data Center newsletter is Nerdio! A must-have addition to any AVD deployment, don’t miss Nerdio’s great features to extend and optimize AVD.
* Starting with release 6.2.1, Nerdio now supports downgrading the FSLogix agent, which wasn’t previously possible, extending the feature released in 6.2.0, which allowed for FSLogix version management, giving administrators the ability to select the desired version.
* In preview now with 6.3.0, Nerdio is bringing AVD Mult Entra ID Support, allowing the ability to link multiple Entra ID tenants to an AVD host pool, as well as an offline mode and greater insights into auto-scale and capacity reservations.
Nutanix Customers with G9 (and some G8) nodes should be aware that LCM has a bug that does not show any available updates for Redfish modules. This will be fixed in an upcoming release of LCM, but for now, follow KB-15172 to upgrade the BMC and BIOS to recommended versions manually.
* Nutanix Files 5.0.0.2 was also released; while only a maintenance release, it does remediate issues that have impacted performance on certain workloads.
* It’s great to see Nutanix really diving into the AI world, leveraging NC2 and Nutanix Files to integrate with Azure OpenAI. Check out the video showing Nutanix Files and Data Factory in Azure here.
Pure Storage Security incidents always hold a dark cloud over operations, and ensuring organizations have disaster recovery capabilities available in their time of need, Pure continues to expand on the Pure Protect / DRaaS capabilities with clean room and isolated environments—bringing confidence to secured data!
* Over the last few weeks, many organizations have suffered from outages that had widespread impacts, from Microsoft Azure and M365 outages, to CrowdStrike to highlight the big ones. While measuring downtime in dollars lost to the organization is important, Pure highlights some of the hidden costs of downtime and disruption—don’t miss this read!
VMware Still in Technical preview, vSphere 8.0 U3 now allows for NVMe tiering to leverage onboard NVMe devices as tiered memory. This now helps extend the performance of nodes by using NVMe devices to add additional memory to a host.
* With lots of questions about Broadcom’s direction, Azure VMware Solution (AVS) is getting traction. Check out info from Microsoft, including licensing portability and locked-in pricing. Our Field CTOs wrote a recent blog post about the options as well.
Windows Server Starting October 15, 2024, the Enforced by Default phase of Kerberos PAC signature validation mitigation begins. Updates released on or after this date will move all Windows domain controllers and clients in the environment to Enforced mode, enforcing the secure behavior by default. Note that during this phase, the Enforced by Default settings can be reverted to Compatibility mode by an Administrator.
* Windows Server 2025 preview is now available, providing advanced security, performance increases, and modernized experiences.
Zerto Hot off the press is Zerto 10.0 U5, which brings some nice enhancements to both on-premises and Azure/AWS deployments to simplify deployments using code. With U5, site settings are now configurable as code and via the Management Console REST API, allowing for consistent settings and maintaining configuration drift.
* Also, new with U5 is the addition of the Linux-based ZVM to Azure VMware Solution deployments, which now have consistent deployments across all environments!
What’s New with Microsoft?Azure The existing Azure Support offer has been discontinued. Customers who do not already have a paid support plan (eGroup Enabling Technologies’ Managed Services, Microsoft Unified, ProDirect support, etc.) will need to purchase a support plan if they wish to maintain technical support coverage.
* Lifecycle management rules in Blob Storage and Data Lake Storage now provide more control over returning rehydrated objects back to archive tier with support for daysAfterLastTierChangeGreaterThan.
* Vaulted backup for Azure Blob Storage, now generally available, can help you comprehensively protect your data in Azure Blob Storage against data loss.
* A new VM disk capability, Azure Premium SSD V2 feature allows you to change your existing Standard SSD/HDD, or Premium SSD V1 disks to PV2 disks in a few clicks. This avoids disk destruction, eliminates the need to use snapshots as a staging resource, and doesn’t require background data copying.
* Azure Monitor Basic Logs plan now extends the included interactive retention period from 8 days to 30 days, and allows full KQL on a single table and lookup of additional data in Analytics tables.
* Azure Monitor now supports three plans—Analytics, Basic, and the new Auxiliary plan. Auxiliary Logs are verbose logs that can be stored inexpensively. All logs can be retained in one place, cost effectively.
* EDU Customers: Azure Lab Services will be retired on June 28, 2027.
* ExpressRoute Traffic Collector can now be enabled on ExpressRoute provider circuits, and support is now available for ExpressRoute FastPath V-net peering and User Defined Routes (UDR) connectivity.
* Azure Virtual Network Manager mesh and direct connectivity enables a group of virtual networks to directly communicate to each other without an additional hop, reducing latency and management.
* Azure Cost Management will provide more details in estimations and in visualizing actuals. See details.
Copilot for Microsoft 365 Outlook mobile will include Copilot features by default for users with a Copilot license, by early September. The Copilot button will appear next to Mail and Calendar, or in the Apps section.
* A ‘scheduled prompts’ feature for Copilot in M365 automates Copilot prompts at set times. It requires a Copilot license and a Standard Power Automate license by October 2024. Admins manage via the Optional Connected Experiences admin setting.
Defender XDR If you’re burdened with independently managing permissions of different security tools, Unified RBAC for Defender is going to be a relief! See Microsoft Defender XDR Unified role-based access control (RBAC).
* Defender for Identity will introduce new recommendations to Microsoft Secure Score. These recommendations include Azure SSO account configurations and actions for Entra Connect accounts.
* Look for an enhanced session control app onboarding experience for Defender for Cloud Apps, with GA in mid-August. This update automates the application of session and access policies, eliminating manual onboarding and allowing direct selection from the Entra catalog.
* Classic Outlook for Windows will integrate new reporting buttons, allowing users to report emails as phishing, junk, or not junk. Admins can customize these buttons and actions via the Defender portal.
Edge for Business Edge will change its hardware requirements, no longer supporting devices without SSE3 starting from version 128. By the end of August 2024, devices need to be upgraded to continue receiving updates.
Entra ID Microsoft Entra Suite, the industry’s most comprehensive secure access solution for the workforce is available, as is Microsoft Sentinel within the Microsoft Unified security operations platform, which delivers unified threat protection and posture management.
* The Insider Risk condition, in Conditional Access, is a new feature using signals from Purview’s Adaptive Protection capability. If Purview detects unusual activity from a user, Conditional Access can enforce extra security measures such as requiring MFA or blocking access. This is an Entra P2 feature.
* The Attacker in the Middle detection is now GA for users in Identity Protection (P2 feature). This high precision detection will be triggered on a user account that has been compromised by an adversary that has intercepted the user’s credentials. It’ll include tokens that were issued to the user. The High risk will trigger the configured Conditional Access policy.
Excel Python in Excel will be generally available by October, offering Python formulas in Excel for Windows users. It includes standard compute and a self-purchase option for premium compute.
Exchange Online Starting October 1, 2024, Microsoft will enable IPv6 for Accepted Domains in Exchange Online for security and performance. Organizations should update network allow-lists to include Exchange Online IPv6 endpoints. Opt-out details will be provided in September for those needing to remain IPv4-Only.
* Exchange is updating to support inbound SMTP DANE with DNSSEC by late October. This will be off by default and can be enabled using Exchange PowerShell. There are specific supported and unsupported domain configurations to consider. Read more about it here.
* Exchange admin center has new troubleshooting workflows to help resolve common issues. Admins will be able to access the new Troubleshoot option on the left navigation of the Exchange admin center. The new workflows gather logs and data to provide relevant information.
Intune Cloud-managed devices are getting a boost with features in the areas of AI, automation, and reach. Adopting a “growth mindset” on how routine maintenance will continue to be automated is critical for future success. Leverage a pilot today to incrementally roll out these capabilities. Read more here.
* Admins can offer MacOS users downloads of unmanaged applications (in PKG and DMG format) via the Intune Company Portal app. More info at unmanaged PKG apps and LOB DMG apps.
* Now in public preview, administrators can ask Copilot for device data. If the question can be answered with device query, Copilot will generate a KQL string that can be pasted into Intune Advanced Analytics to get the answer without admins needing knowledge of KQL.
* In October, Intune will only support Android 10 and later for user-based management methods. Devices on Android 9 or earlier will not receive technical support, bug fixes, or guaranteed feature functionality.
Microsoft 365 Apps Admin Center Planner Starting August 30, 2024, the ‘Send Password in Email’ feature will be retired from the Microsoft 365 admin center. Admins should use the ‘Print’ option to securely share user account details.
* Microsoft Teams’ Office 365 Connectors are retiring, with new connector creation blocked. Existing connectors will function until December 2025, but require a URL update by December 31, 2024. Users are advised to migrate to alternatives like Power Automate or Microsoft Graph.
* Microsoft 365 admins will receive notifications for self-service purchases made by users. This feature provides awareness, actionable insights, and is on by default. Admins can manage or cancel subscriptions and should familiarize themselves with the self-service purchase FAQ and policy.
OneDrive OneDrive will update storage policies for unlicensed (business and enterprise) accounts in early 2025. Unlicensed accounts over 90 days will be archived and inaccessible to users but visible to admins. Actions include archiving, deletion, or renewal. Education tenants are currently exempt.
Outlook (New) The new Microsoft Outlook for Windows went GA on August 1st for commercial accounts.
Outlook Mobile Heads up to ensure iPhones continue to work with Outlook Mobile. Once iOS 18 (in beta) is released to GA, Apple will stop supporting iOS 16, and Outlook for iOS app will require iOS 17 at minimum.
* Outlook mobile apps will soon allow sign-in via QR code, rolling out by mid-November. This feature will be on by default but can be disabled by admins.
* The Dictation feature in Microsoft Outlook for iOS and Android will be retired in September.
Power Apps A public preview of coauthoring within Canvas Designer is coming, allowing multiple makers the ability to author and edit the same canvas app in real time. GA is end of 2024.
* You can undo and redo while you build cloud flows in the designer feature. You can now build flows with Copilot, or otherwise experiment, knowing that you can undo any of your actions.
Purview Information Protection Data Loss Prevention for Mac devices will now include OCR to detect sensitive content in images. Users with specific roles can configure OCR settings in the Purview portal. Charges apply for OCR usage.
* By October 2024, there will be a tenant-wide Hold Report in eDiscovery (Premium) to provide information on all hold policies for eDiscovery cases. Access it under the ‘Reports’ tab.
* Purview DLP on Windows devices will support over 100 file types by November, including sensitive content in metadata, PDF form fields, and files within Office files. No existing policy changes needed.
* Four new Purview DLP predicates for Exchange are introduced, enabling detection of unlabeled messages and attachments, and content containing specific sensitive information types or labels.
* By late October, Purview (Communication Compliance) will release a feature enabling Viva Engage (Yammer) users to report policy-violating posts and comments.
* New roles for accessing Purview AI Hub will be available for Microsoft E5 or Compliance E5 license holders. The Purview Compliance Administrator and Purview Security Reader roles will come in November.
SharePoint The Lists app will soon introduce a drag and drop feature to reorder list items, with rollout phases starting in August 2024. This feature will be on by default and requires no admin action prior to rollout.
* Copilot is being integrated into SharePoint’s Rich Text Editor, enabling content authoring assistance.
Stream By late September, people can record and insert Stream video recordings in Outlook on the web and the new Outlook. If the policy is enabled or not configured, users can record themselves and/or their screen. If the policy is disabled, users can’t record videos within supported M365 applications.
Teams Teams will soon bring Power Automate Workflows for files shared in Teams chat or channels to the 3-dot menu. Users select the 3-dot menu on such files, then choose Workflows to configure and run.
* A new ‘Workflow builder’ feature will allow users to describe the automation they need, which will then generate a matching workflow. The rollout will be completed by mid-October.
* Classic Microsoft Teams for Mac will be automatically removed in early August and will occur after users update to the latest version of new Teams. No admin action is required for the uninstallation.
Teams Chat and Channels Team owners can rename the General channel by late September.
* The “Files” tab in Teams Chat will be renamed to “Shared” and will include files, links, and upcoming features like image previews and keyword search. Rollout will complete by late September 2024.
Teams Meetings Town Hall events will soon allow organizers, presenters, and external presenters to engage in private chats before, during, and after their virtual events.
* Teams will require explicit consent from participants for transcription during meetings if admins turn on the ‘get recording and transcription consent’ policy. If it is, participants who do not consent cannot unmute, turn on their camera, or share content during the meeting. Roadmap ID 389368.
Teams Phone By September 30, 2024, call queues will be switched from Transfer to Conference mode for faster connections. Organizations should update their Call queues in the Teams admin center to use these improvements.
* Teams app update 1449/1.0.94.2024071104 offers new features like explicit consent for recording, rich call history, enhanced call transfer, simplified contact management, and a private line feature. Update!
Teams Admin Global admins will be able to assign several roles to Administrative Units, allowing delegates to manage only the users and groups assigned to the specific AU.
* Updates for Android-based Microsoft Teams devices will be more flexible, allowing for stand-alone app updates. Rollouts start in August and will enable updates via the Teams admin center for individual components like Microsoft Intune and Authenticator, with automatic updates for certain apps.
Teams Premium The new Queues app for Microsoft Teams will complete by late October. Teams Premium users can access real-time statistics, historical reporting, and improved call handling features.
* For people with Premium (or Copilot) licenses, Outlook will integrate AI-Powered Intelligent Recap feature from Microsoft Teams, allowing users to access AI-generated meeting notes and tasks directly from the Outlook calendar.
* The Teams Premium feature usage report will be available in the Teams admin center, providing insights into user benefits and feature utilization. It will roll out in August.
Viva Viva Engage will soon introduce a new community to support the adoption of Copilot for Microsoft 365, offering features like one-click community creation and a setup checklist.
* Viva Connections is now available on the web with the same functionalities as in Teams.
* Starting September 1st, Microsoft will retire the Feed for Viva Connections web part and Video news link.
Windows On October 8, 2024, Windows 11, version 21H2 (Enterprise, Education, and IoT Enterprise will go out of service.
ConclusionIf any of these updates or changes pose as a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousAzure VMware Solution (AVS) vs. Data Center/Azure NativeNextIncident Response Plans: What Are They and Why Do They Matter to Your Organization?NextNeed Assistance with These Updates?Contact our team today to get help with any of the changes mentioned above!
The post August 2024 Newsletter appeared first on eGroup Enabling Technologies.
Azure VMware (AVS) vs Data Center/Azure Native ###### Mike Dent
Field CTO, Hybrid Data Center
Field CTO, Microsoft 365 & Azure
OverviewAzure VMware Solution (AVS) offers an advantageous path to extend VMware environments into Azure, enhancing interoperability with established VMware infrastructures and various Azure functionalities. This post is part of a series where we assess the pros and cons of various cloud solutions, highlighting the importance of choosing the right platform(s) for your business’s success. The best option varies depending on the specific needs and goals of your organization.
In this edition, we’ll explore the strengths of AVS when examined alongside a hybrid setup that incorporates conventional on-premises data centers and/or native Azure infrastructure approaches. Our analysis will cover several aspects, including strategic advantages, migration ease, disaster recovery/data protection strategies, staffing implications, and the financial impact.
Azure VMware Solution (AVS) is optimal for organizations looking to enhance their VMware-based operations via hybrid cloud. It suits those aiming to update their IT infrastructure partially or fully, with minimal interruption, using familiar tools and set expenses.
Common scenarios include:
| Azure VMware Solution (AVS) | Data Center / Azure Native | | --- | --- | | Seamless Integration: AVS provides the same, familiar tools your organization leverages on-premises—allowing a like-for-like hybrid cloud configuration and a rapid migration or extension to/from the cloud. Extended Capabilities: AVS extends on-premises VMware workloads to Azure, providing both VMware-based services, but also seamless connectivity into Azure IaaS, PaaS, and services that allow for flexible modernization efforts. | Hybrid Complexity: Managing a hybrid cloud with VMware and Azure Native (IaaS) requires conversion of virtual machines between VMware (VMDK) and Azure IaaS (VHD) with 3rd party products, adding complexity. Limited Flexibility: Traditional data centers often fall short in flexibility and scalability compared to cloud solutions, resulting in longer service delivery times and higher long-term capital expenditures (CapEx). |
Migration Benefits
| Azure VMware Solution (AVS) | Data Center / Azure Native | | --- | --- | | Ease of Migration: AVS supports lift-and-shift migrations with minimal reconfiguration (IP Addresses for example), reducing downtime and risk during migration. Migrating to and from Azure is point-and-click with VMware HCX and the ability to extend the network. Compatibility: AVS maintains compatibility with existing VMware tools and processes, simplifying the migration process. | Re-Architecting Required: Migrating to Azure Native often requires re-architecting applications to take full advantage of cloud-native features, adding an extra layer of complexity for workload mobility. Network extensibility between an on-premises data center and Azure introduces complexity. Potential Disruption: Migration to a new environment in Azure or the Data Center requires extensive planning, configuration, testing, and procurement efforts, including disaster recovery and backup solutions. |
Disaster Recovery and Backup Benefits
| Azure VMware Solution (AVS) | Data Center / Azure Native | | --- | --- | | Integrated DR Solutions: AVS is supported by traditional VMware-based disaster recovery and data protection solutions, allowing for less change in tooling and processes. Additionally, AVS integrates with Azure’s native disaster recovery and backup solutions, providing a cloud alternative to reduce data resilience cost and complexity. Automated DR and Backups: Azure Site Recovery (ASR) and Azure Backup solutions, as well as third-party (with a little more configuration) can be easily integrated with AVS, ensuring data is protected and recoverable without managing the infrastructure to do so. | Traditional DR Challenges: Procuring, configuring, and maintaining secondary data centers that you hope you never have to use is costly and oftentimes under-powered. Testing to ensure readiness can be disruptive and time intensive to business operations. Complexity and Maintenance: On-premises solutions rely on additional infrastructure, manual processes, and additional resources to support underlying systems to maintain. |
Technology Team Benefits
| Azure VMware Solution (AVS) | Data Center / Azure Native | | --- | --- | | Familiar Environment: AVS allows IT teams to continue using familiar VMware tools and interfaces, reducing the learning curve and allowing for a smoother transition to cloud native skills. Focused on Value: AVS takes 7 of the 10 core management tasks from your technology team and shifts them to a Microsoft-managed service, allowing your technology team to focus more time on value-creation activities vs. lower-value maintenance. Unified Management: AVS provides a unified management platform for both on-premises and cloud resources, simplifying operations. | New Skill Sets Required: Moving to Azure Native requires IT teams to acquire new skills and knowledge, which can be time-consuming and costly. Keeping the Lights On: With data center-based virtualization, your technology team is focused on managing, maintaining, and “keeping the lights on" activities versus creating new value for your users. Separate Management: Managing on-premises and cloud resources separately can increase complexity and overhead for technology teams, without adding in additional costly and complex tools. |
Cost Benefits
| Azure VMware Solution (AVS) | Data Center / Azure Native | | --- | --- | | Operational Cost Savings: AVS can support your migration to operational costs models that provide more consistent billing and lower cost growth overtime. Cost Reductions: 1YR, 3YR, and 5YR reserved-instance availability allows for significant reduction in overall costs. Transferability of reserved instances allows for flexibility in migration to IaaS/PaaS Azure services over time without lock-in. Scalability: AVS offers scalable resources that can be adjusted based on demand one node at a time, optimizing costs and allowing you to scale up in hours versus months for scenarios, such as disaster recovery. | CapEx Investments: Traditional data centers require significant capital expenditures for hardware, facilities, and maintenance. Cost Difference: Total Cost of Ownership (TCO) in the data center is elusive to most organizations. Cost of infrastructure is most often compared to cost of cloud services. Cost of facilities, power, cooling, maintenance, personnel, and other “softer” costs must be considered for effective comparison. Fixed Capacity: Data centers have fixed capacity, which can lead to underutilization or the need for unpredictable and costly maintenance/upgrades. |
ConclusionUtilizing Azure VMware Solution can provide benefits like improved integration, easier migration, better disaster recovery, increased team efficiency, and cost savings when properly implemented, according to specific requirements. Companies aiming to upgrade their IT infrastructures without interrupting their current VMware setups may find AVS to be an attractive option. We advise enterprises considering their infrastructure strategy for the next two to five years to undertake a planning process that prioritizes their distinct business needs before aligning technology solutions to those requirements. AVS constitutes just one of many alternatives, and determining its suitability for your organization depends on a variety of considerations.
We Can Help!Interested in exploring how Azure VMware Solution and other solutions can benefit your organization? Contact us today at info@eGroup-us.com or complete the form below to for an introduction and start your hybrid cloud infrastructure roadmap journey.
For more information, view our recent webinar VMware Renewals: Evaluating Your Options for Making Informed Decisions
PrevPreviousWeekly Tech Tip: Check Your FEC!NextAugust 2024 NewsletterNext###### Have Questions or Need Help with Azure VMware Solution?
Contact our team of experts today!
The post Azure VMware Solution (AVS) vs. Data Center/Azure Native appeared first on eGroup Enabling Technologies.
Weekly Tech Tip: Check Your FEC!###### Mike Dent
Field CTO, Hybrid Data Center
Connectivity Issues Between Cohesity C5016 Nodes and Nexus 93180YC-FX3H SwitchesVery recently, I was deploying a new Cohesity C5016 appliance with 25Gb NICs, connecting up to a pair of Nexus 93180YC-FX3H switches. When using the 9K’s in a VPC pair, my personal preference is to configure the Cohesity nodes with LACP to get the most bandwidth possible (regardless if it’s 10Gb or 25Gb connectivity). Nothing super creative there, and I’ve done this dozens of times in the past with no issue, on both the Cohesity appliances and Nexus 9k’s. But this time, it was different…
A Little Background…This deployment included a pair of Nexus 93180YC-FX3H switches (I love this model, and if you didn’t know what the H stands for, it stands for Half—go figure). The FX3 switch is a 48 1/10/25Gbe and 8 100Gbe port switch with a fantastic set of features– But in some cases, we just don’t need the full 48 ports on each switch, so to help with the overall cost, we use the FX3H model, which is the same switch but only 24 of the ports are licensed. In my specific scenario, we were performing a refresh for a past customer from a 3-tier environment to a pair of new 9k’s, Nutanix nodes for hyperconverged storage and compute, and Cohesity for the backup solution. A perfect trifecta if I say so myself…
When bringing up the C5016 nodes with 25Gb NICs connected redundantly to the Nexus 93180YC-FX3H switches running 10.3.4a code, even though I had visible light on the fiber, I wasn’t getting any connectivity. So I moved forward with normal troubleshooting. Checked the SFP modules (and swapped them out), checked the fiber (and swapped that out as well). Rebooted the nodes, rebooted the switches, nothing. But go figure, the Nutanix nodes using the same 25Gb modules and the same switches (even the same ports) worked just fine.
Forward Error CorrectionForward Error Correction (FEC) is a method used in data communication and storage systems to detect and correct a limited number of errors in data without the need for retransmission. It works by adding redundancy to the original data so that errors can be detected and corrected on the receiver’s end. This is particularly useful in high-speed networking environments where retransmissions can be costly, in terms of time and bandwidth.
Impact of FEC on 25Gb Connectivity on Nexus Switches Error Correction: FEC enables error detection and correction, which is crucial for maintaining data integrity, especially at higher speeds like 25Gbps. This helps in reducing the bit error rate (BER) and ensures more reliable data transmission. * Compatibility: Different FEC modes (such as RS-FEC and FC-FEC) may be required, depending on the transceivers and cables used. Ensuring the correct FEC mode is enabled is vital for establishing a stable link. * Latency: While FEC improves data integrity, it can introduce a slight increase in latency due to the time required for error correction processes. However, this latency is typically minimal and outweighed by the benefits of reduced errors. * Interoperability: For 25Gb links, both ends of the connection (transmitter and receiver) must support and be configured for the same FEC mode. Mismatched FEC configurations can result in link failures or degraded performance. * Configuration: On Nexus switches, FEC settings can be configured to match the requirements of the connected devices. Incorrect FEC settings can lead to connectivity issues or suboptimal performance. * Performance:* With the correct FEC settings, 25Gb links can achieve optimal performance, ensuring high throughput and low error rates. This is critical for applications requiring high bandwidth and low latency. Now, I’ve had this issue in the past when connecting a pair of Cisco Catalyst 9200/9300’s switches using 25Gb uplinks to the Nexus 93180, and had to tune the FEC parameters, but it just didn’t click that this might be the same issue.
Enter Random Cohesity KB ArticleDoing some searching on the Cohesity support site, I stumbled upon a KB article addressing a similar issue with Arista switches. So why not, let’s check it out.
A quick synopsis of the KB article:
SymptomThe links on the nodes do not come up after upgrading the switch.
CauseThe issue might stem from a mismatch in the Forward Error Correction (FEC) mode between the NICs/SFPs and the switch configuration. The specific problem noted in the Cohesity article was related to Arista switches allowing FEC Mode RS to be set, which needed to match the NIC/SFP configuration.
ResolutionThe FEC mode supported is determined by the SFP and switch configuration. Cohesity devices default to negotiating FEC automatically using RS encoding. You might need to force RS encoding on the Nexus switch ports connected to the C5016 series NICs.
Here’s an example of checking and setting the FEC mode:
Set the FEC mode on the Nexus switch:
The exact commands to force RS encoding will vary based on your switch model and IOS version. However, a typical approach involves configuring the interface settings:
Ensure that the interface matches the one connected to your C5016 NICs. You might need to adjust these commands based on the specific syntax for your Nexus switch and IOS version.
Upgrade Switch Software if Necessary:
If the issue persists, it might be worth checking if an upgrade to a newer software version on the Nexus switch is available and recommended by the vendor. Software upgrades can often resolve compatibility issues and introduce enhancements that improve overall performance and stability.
Additional Steps and Considerations Validate Fiber Connections:* Double-check the physical connections, ensuring that the fibers are clean and properly seated.
ConclusionQuite often, I use blogging to help remind me of situations I have previously encountered—call it my personal knowledgebase. As higher bandwidth connections continue to be the norm, running into this on 25Gb and higher connections will remind me to check the FEC!
Thanks for reading, I hope you found this valuable if you ran into a similar situation!
We Can Help!If you have any questions or you’re looking for assistance with Cohesity, please reach out to info@eGroup-us.com or complete the form below.
PrevPreviousCloud-First vs On-Premises Computing: Contrasting ViewsNextAzure VMware Solution (AVS) vs. Data Center/Azure NativeNextNeed Assistance with Cohesity?Contact our team today to schedule a call with one of our experts.
The post Weekly Tech Tip: Check Your FEC! appeared first on eGroup Enabling Technologies.
Cloud-First vs On-Premises Computing: Contrasting Views###### Chris Stegh
CTO & VP of Strategy
CIO Advisor
CIO Advisor
Cloud-First Versus On-Premises Computing: A ComparisonBroadcom’s acquisition of VMWare and subsequent price increases are an inflection point for many IT organizations. Even mature organizations with large VMware environments are facing substantial price increases.
Fortunately, organizations have choices to proceed. Our prior blog outlines several of them.
This blog provides the perspectives of two IT Executives and Strategic Advisors. Tom Papahronis’s comments can be found in the left column of each table from a Cloud-First perspective, while Mehran Basiratmand, PhD‘s thoughts can be found in the right columns from a Cloud-Smart perspective.
Without further ado, onto the debate!
Tom’s Cloud-First Perspective:
I would argue that many affected teams would better serve their organizations by migrating to native to Azure and cloud services. Further, it is time that we start changing our default thinking about cloud services in general. I see many clients still looking for justification to move to the cloud, but the real question is what is the justification for staying on-prem? While a look at an alternative virtualization platform is certainly an option, I often challenge Mehran if our customers need an on-prem/colocation virtualization environment at all.
Mehran’s Cloud-Smart Perspective:
While my esteemed colleague, Tom, articulates an argument to migrate to a cloud-native environment given the latest changes to VMWare, there are however instances where cloud migration in a near term is not on the cards. It is equally imperative to recognize these scenarios and to provide alternative strategies to maintain the current services with minimal disruption.
The inhibitors to migrating to cloud-based solutions are generally caused by organizational factors including contractual agreements, existing hardware investments, executive mindsets, or other pressing IT priorities. From a technical perspective, barriers include skillsets, technical debt, and timing. Below the IT execs weigh in, with Tom’s cloud-first philosophy in column 1 and Mehran’s Cloud-Smart points of view in column 2. When addressing the challenges of individual organizations, we’ve found these to be most consistent.
Strategic Considerations
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Focus staff time and skills on initiatives that are strategically important to the organization, rather than servers, hardware, and networking, and other commoditized functions. - Services instead of servers. Preconfigured SaaS or IaaS services can simply eliminate a lot of patching, firmware changes, OS builds, and other maintenance that requires downtime for many types of applications. - Scale up or down, no strings attached. Cloud services are modular with much less planning and assembly required. This shortens planning horizons and project risks significantly. -What would a greenfield look like? If you had to build your current environment from scratch today, what would you use? Would it be on-premises? Do you have specific use cases that will only work on-premises? | - Meet highly specific legal, compliance, or other specific organizational requirements for systems hosting. Some organizations have business or security concerns that cannot be met by cloud services or facilities. - Support For Highly Customized Architectures. If applications require specific hardware, firmware, or networking protocols, these may not be able to be met by mainstream cloud services. - Support For Legacy Applications. Some applications may still require non-Ethernet or non-TCP/IP-based networking, custom operating systems, or hardware drivers. - High Computational Intensity Support. Applications that rely on extremely fast network, processor, or storage resources may not be economically feasible in the cloud. |
Risk Reduction
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Use the cloud to reduce vendor risks by consolidating point solutions and unpredictable software licensing costs. - Reduce colocation risk – Azure and other cloud services use Tier 1 data centers with state-of-the-art physical security and multiple redundancies. Is your data center that well protected? - High availability and failover are checkboxes, not complex configurations that need to be maintained. - Reduce surprise financial risks – With some planning effort, everything is operational expense and has pricing known ahead of time. | - Less Reliance On Public Internet Connectivity And Reliability. Public internet connectivity is required for many cloud-based services. There is inherently some risk in relying on this, and on-premises VMs or dedicated servers may reduce that specific risk. - Cloud Outages Do Happen. While they are typically short-lived, there is often little an individual customer can do to mitigate this risk. - Non-Compliance Risks. Organizationally, some compliance controls or other policy requirements may not be as easy to meet with infrastructure in the public cloud. |
Cost Management
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Cost Predictability – Run rates and operational expenses can be planned in advance and much more easily tied to specific initiatives or teams. - Facility, colocation, and hardware costs can be significantly reduced. - CapEx cycles & leases can be simplified. Less to manage, less to plan for, less unused capacity. - Pay only for what you need today. No more overbuilt environments or capacity hoarding. | - Contractual Agreements with Data Center Providers. Organizations that have heavy on-premises footprints generally have negotiated multi-year contracts with data center providers. As such, “lifting and shifting” applications such as VMware to the cloud requires thoughtful planning to incrementally reduce their on-prem rack space; therefore, any hasty move would not necessarily yield financial benefits. - Capital Expenditure and Hardware Investment. Given server refresh cycles of most orgs, there is a possibility that an organization has recently refreshed their servers; therefore, abandoning their investment for the sake of migrating to a cloud solution without fully amortizing their servers or exhausting their capabilities would be splurge behavior. - Low Cost of Data Center Operations. There are organizations where the cost of data center maintenance, cooling and power are embedded in the general (non-IT) operating budget. In these circumstances, developing a justification for a full cloud migration is more challenging, since calculating the full cost of operating the current environment is an arduous task. Instead, the rationale for any cloud migration should be shifted to high-availability, reduction of DR cost and ease of provisioning based on consumption. |
IT Team Benefits
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Relieve the already overtaxed IT team with more automation and standardized services. - Have that IT team focus on value-add projects rather than task to simply “keep the lights on.” Focus them on organizational goals, not just IT goals. - Build relevant and forward-looking skill sets. - Easily find qualified third parties for expertise and assistance when needed. - Reduce common service configurations to checking boxes and running scripts rather than complex product integrations. | - Adoption of Cloud Culture. Each organization is in a different stage of their cloud journey. The process of adopting a new service/application in the cloud experiences a different vetting process. If the organizational culture is averse to cloud, it is imperative to continue hosting VMWare on-prem for a couple of years or until the cultural challenges stemming from cyber security concerns, perceived loss of control, skill-set deficiencies and cost management are appropriately addressed. Negotiating to maintain on-prem is a viable option while assessing the cloud offerings. - Technical Skillset. It takes time to develop or recruit individuals with the necessary skillset to fully support any cloud environment. In the case of organizations that have excellent resources to support their on-perm VMware environment, those skillsets do not necessarily translate to a quick migration and subsequent maintenance the cloud with the same degree of efficiencies. In these situations, it is prudent to maintain the current environment while gradually building the cloud skillset by deploying sandboxes and backup/recovery environments. |
Security Improvements
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Secure the environment at cloud scale. Cloud services can capture every event, every login, etc. easily and without physical on-premises disk and throughput limitations. - Reduce or eliminate siloes between cloud and on-premises solutions. One place to monitor, one identity provider, one SIEM, and one set of governance controls. - Vendor security investments and product development efforts are heavily skewed to securing data and assets in the cloud. Take advantage of that. - Expanded security capabilities vs on-premises. Buying and running the same protection that M365 and Azure offer in an on-premises environment would cost orders of magnitude more than an existing cloud solution that you connect to. | - Support Many Specific, Point-Based Security Solutions. If the organization requires using a portfolio of point-specific security solutions, it can be challenging to extend those to the cloud. Cloud services often lend themselves to using integrated security suites that are designed for cloud use. - Meet “Airgap” Requirements. If the organization truly has systems that do not (or cannot) be accessed using the public internet, then the cloud is not the answer. - Physical Security Requirements. Cloud providers have robust physical data security controls, but if the organization’s requirements exceed those, then an on-site or specialized colocation facility may be required. |
Disaster Recovery and Business Continuity Simplification
| Cloud-First Approach | Cloud-Smart Approach | | --- | --- | | - Reduce physical facilities overall and leverage cloud facility redundancies already in place. - Unlimited backup capacity without physical infrastructure limitations. - Service, server, and application redundancies are easy to configure and test. - Increased (or decreased) RPO and RTO targets can be directly tied to operational expense. - Reduced DR complexity overall, and easy to build runbooks with automation. | - Risk, security, and cost limitations outlined above will preclude using the cloud for disaster recovery. - Specific Control Over Recovery Environment. Legacy systems, legacy hardware, proprietary connectivity, or even specific data residency requirements may not be able to be replicated by cloud services. |
Incremental Approach and Hybrid InfrastructureWhile two different perspectives of adopting cloud-native and maintaining on-prem environments for VMWare were outlined, an alternative is to adopt a best of breed approach of a hybrid environment. You can read through one of the hybrid options in a recent blog: Navigating the VMware License Increase: RETHINK IT & Consider Azure VMware Solution.
Migrating to a native cloud has significant benefits; however, it is a good practice to bounce your ideas off of those who are engaged in this process on a regular basis. It is always a sound idea to evaluate these options from your lens and to assess the pros and cons of each scenario based on the viewpoints presented.
It is a significant undertaking to move to the cloud. (Not unlike changing the tires on the truck as it speeds down the highway.) Recent market changes with VMware have changed this decision calculus quite a bit. Our team is ready to help chart the right course, or to just lend a sympathetic shoulder to cry on.
We Can Help! If you have any questions or are looking for assistance in choosing the right VMware Renewal option for your business, please reach out toinfo@eGroup-us.comor complete the form below.
For more information, view our recent webinar VMware Renewals: Evaluating Your Options for Making Informed Decisions.
PrevPreviousMicrosoft Intune Multi-Admin ApprovalNextWeekly Tech Tip: Check Your FEC!Next###### Have Questions or Need Help with Your VMware Renewal?
Contact our team of experts today!
The post Cloud-First vs On-Premises Computing: Contrasting Views appeared first on eGroup Enabling Technologies.
Microsoft Intune Multi-Admin Approval###### David Bergquist
Senior Cloud Solutions Architect
Microsoft Intune is a cloud-based device management service that allows you to manage and secure your organization’s devices, apps, and data. As an Intune Administrator, you can configure Microsoft Intune settings, such as creating policies, applications, compliance, and assigning roles. However, some of these changes may have a significant impact on your organization’s security and productivity and may require approval from multiple admins before they can be applied.
Multi-Admin Approval is a feature in Intune that institutes an approval process requiring one or more admins to consent before changes are made. This feature can help you to prevent unauthorized or accidental changes and maintain an audit trail of changes and approvals. Multi-Admin approval is available for the following Intune service settings:
In this blog post, you will learn about the prerequisites and process for enabling multi-admin approval in Intune, along with sharing my experiences from both an administrator and approver perspective.
PrerequisitesBefore you can enable multi-admin approval in Intune, you need to meet the following prerequisites:
You must be assigned the Intune Administrator or Global Administrator role in Entra ID to create an access policy. ProcessThe process for enabling and using multi-admin approval in Microsoft Intune consists of the following steps:
Plan for and create an “Intune Multi-Admin Approval” group in Entra ID that consists of Intune approvers.
Once approved, the administrator can complete the application push request. Configure a Multi-Admin Approvers GroupTo enable multi-admin approval in the tenant settings, follow these steps:
Sign in to the Microsoft Intune admin center.
Sign in to the Microsoft Intune admin center.
Sign in to the Microsoft Intune admin center.
You will see a notification that your change request has been submitted for approval. Application Approval Process in Microsoft IntuneOnce the application has been submitted for approval, an approver can view the request and approve, cancel, or reject the request.
As an approver, sign in to the Microsoft Intune admin center.
This change will also have to be approved. Once approved, the application (in this case) will be pushed to the intended users. SummaryMicrosoft Intune Multi-Admin Approvals can help IT Administrators achieve the following benefits:
It can prevent unauthorized or accidental changes to the app configurations and scripts that affect end users and devices.
PrevPreviousJuly 2024 NewsletterNeed Assistance with Microsoft Intune?Contact our team today to schedule a call with one of our experts.
The post Microsoft Intune Multi-Admin Approval appeared first on eGroup Enabling Technologies.
July 2024 NewsletterTable of ContentsWhat’s New at eGroup Enabling Technologies?eGroup Enabling Technologies has been recognized as #1 in the U.S. for both Microsoft Cybersecurity Incentives Program (CSI) Workshops and the Copilot Adoption Factory Program. These achievements highlight our dedication to providing industry-leading solutions and exceptional service to our clients.
#1 in the U.S. for Microsoft CSI Workshops: Our top ranking reflects our expertise in delivering comprehensive security workshops that empower organizations to fortify their defenses and stay ahead of evolving cyber threats. Learn more about how our Microsoft Security Workshops can enhance your security posture.
#1 in the U.S. for Copilot Adoption Factory Program: We’re leading the way in helping businesses seamlessly integrate Copilot for Microsoft 365, driving productivity and collaboration across teams. Discover the transformative power of Copilot for Microsoft 365 and how it can revolutionize your work environment.
Thank you for your continued trust and partnership. We look forward to supporting your success with these industry-leading solutions!
What’s New in the Hybrid Data Center?Cisco Cisco has announced a new feature within Cisco Networking Cloud called Workflows, aimed at simplifying network automation. This service allows organizations to easily automate configuration tasks across various domains, using a low- to no-code interface.
* Benefits of Workflows:
+ Efficiency: Streamlines complex automation processes.
+ Integration: Seamlessly connects with hybrid cloud environments.
+ Security: Ensures secure operations across public and private assets.
* Key Features:
+ Low- to No-Code Customization: Offers drag-and-drop API tasks and data transformation.
+ Real-Time Updates: Provides updates on workflow execution and audit logs.
* Cisco ISE 3.4 Update: Streamlining Network Security
+ The latest Cisco ISE 3.4 release introduces Common Policy, a unified strategy for consistent security policy enforcement across network domains. Cisco ISE acts as a central hub, integrating network and security domains with identity context to distribute policies effectively.
* Key Advantages:
+ Uniform Policies: Ensures consistent access across all network areas.
+ Simplified Management: Allows PAC-less communication, reducing administrative tasks.
Cohesity It’s Epic, or EPYC! Cohesity is bringing even more options to the Cohesity DataCloud, enabling the AMD EPYC CPU-based all-flash and hybrid servers from Dell, HPE and Lenovo. (Commence the Faith No More music in the background… )
* Make sure you catchthis preview video from Cohesity on using DataProtectaaS with the Microsoft 365 Backup Storage Service.
Nutanix Chalk this up to a repeat update: with the very recent End of Support for CentOS 7 (June 30th, 2024), Red Hat and Nutanix announced a collaboration to bring AOS (and presumably AHV and other Nutanix platforms) to Red Hat Enterprise Linux.
While the initial message was a repeat, this one is not. Since CentOS 7 is now EOL, upgrading AOS to 6.8 and Prism Central to 2024.1 resolves the support issues, as they are both based on Rocky Linux 8 (el8).
* From the Desk of Keep an Eye Out:
+ Field Advisory for Prism Central Resource Contention
+ Field Advisory for Protection Domain-based DR
+ Security Advisory – Intel Processor Vulnerability
Pure Storage An exciting announcement from Pure coming this month is the Secure Application Workspaces, or SAW. SAW enhances multitenancy by logically dividing storage to align with application demands, improving the performance and availability of SLAs, and isolating tenants to prevent noisy neighbor issues. A few key highlights:
+ Multitenancy Concept: This concept aligns with the application-focused, containerized approach, providing tenant isolation, faster service, and improved resource management.
+ Realms: Logical constructs for managing storage objects, ensuring isolation and QOS, controlled by array admins.
+ Use Case: Facilitates production and Test/Dev operations concurrently, mitigating resource constraints with QOS.
+ Implementation: Available via Purity updates, simplifying configurations with 75% fewer parameters and better visibility.
* Pure wrapped up its Pure Accelerate 2024 conference last week, and with it came some exciting new announcements about the Evergreen program, AI, Security, and Hybrid Cloud.
+ Pure announced a new certification with NVIDIA, the Super Pod! The new NVIDIA DGX SuperPOD will combine the NVIDIA AIRI DGX BasePOD and Pure’s FlashStack for AI solutions to create a large-scale AI training inference platform.
+ Pure continues to enhance its Evergreen//One capabilities, with new SLA’s designed to simplify and enhance storage management through AI-powered security assessments and enhanced anomaly detection. Read more about the Cyber Recovery and Resilience SLA features on Evergreen//One here.
+ Don’t miss all the updates from Accelerate here!
* But what excited our Field CTO for Hybrid Data Center, Mike Dent, and Director of Sales and Delivery Operations, Jeff Thomas, was the announcement that Rivian Automotive won the Cloud Champion award for their cloud strategy with the Pure Platform. As Jeff and Mike are both Rivian EV Truck owners, this one was a big internal hoorah! Read more about Rivian’s use of Pure Storage’s various platforms here.
VMware VMware recently announced 8.0 Update 3, which brought about a few exciting enhancements.
+ ESXi Live Patching now allows patching to the virtual machine execution environment, aka VMX, on hosts without the need to reboot or evaluate the host. This seems to be the second coming of the ESXi Quick Boot capabilities and is available to more than just specific HW vendors. The host enters a partial maintenance mode, and VMs are fast-suspend-resumed, which is non-disruptive to the VMs. This can be a big win for organizations that need help maintaining their lifecycle due to capacity or patch management!
+ While still fairly new to the masses, with Update 3 VMware announced dual-DPU support to enhance security and resiliency of the environment within the VMware Distributed Services Engine.
- If you’re not familiar with the VMware Distributed Services Engine, it was released in vSphere 8.0 allowing customers to take advantage of DPUs. Read about it here.
- And if you’re not familiar with DPU’s and how it will change and enhance the landscape of virtualization and other environments, read up on it here.
What’s New with Microsoft?Azure Windows Server 2025 preview is now available. Advanced security, performance increases, and modernized experience are in this newest version of Windows Server.
* The Azure Standard support offer ended on June 30, 2024. Customers without another paid support plan that need technical coverage should purchase support or discuss CSP with eGroup Enabling Technologies.
* Azure Site Recovery now supports Azure Trusted Launch VMs (for Windows OS).
* Azure ExpressRoute is rolling out several enhancements to help customers improve their multi-site and zonal resiliency posture with ExpressRoute deployments.
Copilot for Microsoft 365 Restricted SharePoint Search for Copilot for M365 is available, allowing admins to limit search to selected SharePoint sites. The feature is off by default and requires admin roles to enable. Users can access content from allowed sites and personal files.
* Microsoft 365 admin center introduces a new people experiences category in Adoption Score to track the overall adoption of Copilot for Microsoft 365. The AI assistance category includes a score on a 100-point scale.
* Copilot is being integrated into SharePoint’s Rich Text Editor, enabling content authoring assistance. It’ll be to Copilot licensees, rolling out in early August. Admins can disable this feature.
* In Teams, watch for a ‘Catch up’ tab, which provides updates and action prompts. This is rolling out from early July to early August 2024, with no admin action needed.
* Now, in addition to referencing Word and PowerPoint files when using Copilot in Word, users can reference PDFs and specific emails and meetings.
* Users are no longer limited to using Copilot in Excel only in Excel tables, because Copilot in Excel now works on data ranges resembling tables with a single row of headers on top.
* PowerPoint and Word users can create the perfect AI-generated image with a simple prompt, or pull in an ideal stock photo. Prompt DALL-E 3 to “create an image” to “find an image” from Microsoft’s stock. When in PowerPoint, Designer will automatically add the image into a compelling slide design.
Defender for Office 365 The new Take Action wizard in Threat Explorer allows multiple response actions simultaneously. This enhancement aids in efficient threat remediation, supporting actions like email purging, inline submissions, and tenant-level block actions for up to 100 messages. Rollout is complete, but admins need the Search and Purge role to perform email purge actions.
Edge for Business Admins can customize organizational branding assets onto Edge for Business through the Microsoft Edge management service. This branding can help users differentiate between multiple profiles and browser windows. Admins can control, preview, and customize the organization name, accent color, and logo. Default branding can be enabled through policies by admins via the Edge management service.
Intune A new Windows 11 feature is available to help you manage company policies using mobile device management (MDM). Starting with the May 2024 non-security update, you can now use Config Refresh to configure policy refresh timing to be as short as 30 minutes or as long as 24 hours. This helps improve security and compliance so that settings don’t drift from your intent.
* Intune will end support for Android device administrator on devices with GMS access on December 31, 2024. Users should stop enrolling devices with this method and migrate to alternative management methods. Intune will not update or support these devices after the end date.
* Intune will require iOS/iPadOS 16 and higher after the release of iOS/iPadOS 18 later this year.
* Intune will support macOS 13 and higher later this year, coinciding with the release of macOS 15 Sequoia. Devices on macOS 12.x or below will remain enrolled but won’t enroll new devices.
* Intune now supports corporate device identifiers for devices running Windows 11, version 22H2 and later so that you can identify corporate machines ahead of enrollment. When a device that matches the model, manufacturer, and serial number criteria enrolls, Intune will mark it as a corporate device and enable the appropriate management capabilities.
* End users can view the BitLocker recovery key for an enrolled Windows device and the FileVault recovery key for an enrolled Mac in the Company Portal app for iOS and Company Portal app for macOS. This capability will reduce helpdesk calls when they’re locked out of their corporate machines.
* Microsoft is replacing the role-based access control (RBAC) rights to endpoint security policies that are granted by the Security baselines permission with more granular permissions for specific tasks. This change can help assign the specific rights that Intune admins require to do specific jobs instead of relying on either the built-in Endpoint Security Manager role or a custom role. New roles include App Control for Business, Attack surface reduction, and Endpoint detection and response.
* Intune Suite’s Endpoint Privilege Management (EPM) elevation rules now support the elevation of Windows Installer and PowerShell files in addition to executable files that were previously supported. The new file extensions that EPM supports include msi and ps1 files.
* The Remove apps and configuration (RAC) feature will solve the problem where removing settings involved excluding devices from policy assignments or removing users from groups, and then waiting for devices to check in. RAC allows Real-time monitoring of which policies and apps are removed/restored, and selective restore of individual apps and policies.
OneDrive For Business Microsoft OneDrive is updating its shared folder experience. Users will now access shared folders via the People view in their own OneDrive, organized by the sharer, starting late July.
Outlook (Classic) Legacy Outlook clients are retiring, affecting users with outdated versions on iOS, Android, Mac, and Windows Mail and Calendar applications. Starting in mid-August, outdated browsers will receive an error on Outlook web. Users must update to the latest versions for continued support.
Outlook (New) The new Outlook for Windows will open web links in Microsoft Edge side-by-side with the email. This feature will be rolled out through late September and applies to links from Entra ID and MSA accounts. Admins can configure this behavior using the Cloud Policy service or Administrative Templates for Microsoft 365 Apps. Users will be notified of this change and can manage preferences in settings.
Planner eDiscovery support for Microsoft Planner, including search and legal holds, will be generally available in early July 2024. This feature allows admins to search and hold Planner tasks, comments, and attachments in Purview, but only for tenants created before October 2022.
* The new Microsoft Planner app in Teams is rolling out, including Copilot for Microsoft 365 for premium users to manage plan data via language prompts. Users can access Copilot features without a specific license and admins will have a control to disable it.
Power Apps Microsoft is switching the tenant setting “disableShareWithEveryone” that was previously set to “off” by default, to now be “on” by default. This means that makers will not be able to share their canvas apps with the “Everyone” group without changing this setting.
Power BI Power BI is retiring support for older browsers on September 1st. Users should upgrade their browsers by August 31, 2024, to avoid any disruptions.
Purview The new Purview Portal is entering General Availability with a unified experience for data security, governance, and compliance, and will replace the classic portal by the end of 2024.
* The new Microsoft Purview portal will come with a modernized eDiscovery experience, unifying Content Search, eDiscovery Standard, and eDiscovery Premium with enhanced features for efficiency and data management.
* Microsoft Entra’s Insider Risk condition in Conditional Access is now generally available. Organizations with an Entra ID P2 license can set up Conditional Access policies using insider risk signals from Adaptive Protection to enforce actions based on user risk levels, after admins enable Adaptive Protection.
* By September, the Purview portal will introduce an enhanced global Search feature, allowing users to search for organizational profiles, including names, email addresses, role groups, and admin units.
* Purview’s Data Lifecycle Management integrates with Adaptive protection to automatically preserve items deleted by users at elevated risk levels. Public preview begins late June 2024, GA in December.
SharePoint SharePoint Online has a feedback button for users to submit compliments, problems, or suggestions about features and functionality. Collection is on by default, but can be turned off using the Cloud Policy service for Microsoft 365 in the admin center.
* A new content pane will appear for Pages and News, enhancing tools for authors with features like distribution channel selection and audience selection.
* The SharePoint News connector in Microsoft Teams will retire on July 22nd. Users should transition to alternatives like Viva Connections News notifications, Viva Amplify, or Teams Workflow.
* SharePoint eSignature is now integrated into the Teams Approvals app, allowing users to view, track, and sign requests.
Teams The classic Teams for VDI will reach end of support on October 1, 2024, and end of availability on July 1, 2025. For more information, see: End of availability for classic Teams client.
* Teams is releasing a new VDI solution that offers enhanced performance, reliability, security, and streamlined support. The release applies to Windows endpoints connecting to Azure Virtual Desktops, Windows 365, and Citrix VDI environments only, and requires the new Microsoft Teams client and the client-side plugin component.
Teams Chats and Channels The “Files” tab in Teams Chat will be renamed to “Shared” and will include files, links, and upcoming features like image previews and keyword search.
* To stay focused, you can now adjust the sound on notifications. Assign different sounds to different kinds of notifications, such as urgent messages, or mute notification sounds when busy.
* When you join a new team, you can see which channels the team owner recommends and choose to only see the channels relevant to you.
* If you have a link to a shared channel in your organization, you can request to join that channel. Channel owners will be able to view and respond to your request.
* Keep up with the latest in your channel with the new channels experience. Create and view new posts at the top of your page and switch to conversation view for more focused discussions. Pin important posts and see important channel details, like members and notifications, in the new info pane.
Teams Meetings Now, transcript owners can download or delete a transcript file while participants can only view the transcript. Owners can also manage which participants can download, view, and edit the transcript.
* All Teams transcripts are now stored in OneDrive for Business. Anytime you open a transcript in Teams, you’ll see the OneDrive transcript copy. Meeting transcripts will no longer be saved in Exchange Online.
* Intelligent recap is now supported after transcribed meetings that weren’t recorded (as part of the Copilot for Microsoft 365 license or Teams Premium). If your meeting was only transcribed, you’ll have access to name mentions and AI-generated meeting notes and tasks. Intelligent recap features are available as part of the Copilot for M365 license. To learn more, see Meeting recap in Microsoft Teams.
* Breakout rooms are now supported on Teams VDI. Use breakout rooms to split larger meetings into small groups for more focused discussions. To learn more, see Use Breakout Rooms in Teams Meetings.
* Live captions, which automatically create real-time subtitles from your meeting participants’ dialogue, can now be edited to remove profanity. To turn it on, go to Captions and transcripts in your Teams settings and turn the Filter profane words in meeting captions toggle on.
* Zoom in, zoom out, and restore the original size of content that you’re viewing in a Teams meeting. Just look for the button controls at the lower left of the meeting window when content is being shared.
* Speaker recognition is available on all Teams Rooms on Windows devices. Speakers can be recognized in Teams meetings transcripts even when joining from a meeting room. To be recognized, set up your voice profile in Teams.
* Teams will soon allow viewing of file attachments from Outlook meeting invitations directly in the Teams calendar for Desktop and Mac.
Teams Phone Microsoft Teams Android devices will migrate to the Android AOSP management platform in December. Eligible devices will receive a manual firmware update, others may stop working unless they’re reconfigured. IT admins need to create new policies in Intune to support the migration.
* On Windows devices, you can mute and unmute Teams audio by clicking the mic icon on the taskbar.
* Manage your business hours greeting, add on-hold music, and more by managing your call queue and auto attendant greetings in Teams settings. To make changes to your organization’s call queue and/or auto attendant, your IT admin must designate you as an authorized user and your org must have calling functionality set up. Then go to Settings > Calls > Call queue or auto attendant in Teams to make changes.
* If you’ve chosen a delegate to answer your Teams calls, you can now allow them to switch phone lines, join active calls, and view other delegates’ call history. To change delegate settings, go to Settings and More, then at the top of Teams, select Settings > General, and then select Manage delegates.
Teams Admin The Teams admin center will introduce app centric management and changes to app permission policies. Admins can control who can install Teams apps and manage access to the app individually.
* Admins can use the New-CsTeamsUpdateManagementPolicy command to control certain in-product messages in Teams, such as “What’s New” updates and training opportunities.
* Starting August 15th, Microsoft is retiring the Office 365 connectors feature from Teams. Power Automate workflows are the new solution to relay information into and out of Teams in a scalable, secure way.
Teams Premium Organizers with Teams Premium can now select the 10 translated caption languages from over 40 options for town hall meetings.
* The Queues app is now part of Teams Premium, enabling efficient call handling within Teams.
Windows Microsoft Defender Antivirus on Windows 10 and Windows 11 will be shipping with a new service called Microsoft Defender Core service. To prepare, users need to update the Platform Update to the latest version and allow specific URLs. If using an Application Control application or running a 3rd party AV and/or EDR, add the Microsoft Defender Core Service process to the allowed list.
* Windows 365 Cloud PCs will now have port 3389 closed by default to enhance security. Organizations are advised to keep it closed but can manage access via Windows 365 Security Baselines or Intune custom Firewall rules if necessary. Reprovisioning will close open port 3389 on existing Cloud PCs.
Conclusion*If any of these updates or changes pose as a challenge for your team, please don’t hesitate to reach out to us! We will be happy to work with you to navigate these changes. Feel free to fill out the form below to get in contact with our team.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousHow to Deploy Microsoft Intune Endpoint Privilege ManagementNeed Assistance with These Updates?Contact our team today to get help with any of the changes mentioned above!
The post July 2024 Newsletter appeared first on eGroup Enabling Technologies.
How to Deploy Microsoft IntuneEndpoint Privilege Management###### David Bergquist
Senior Cloud Solutions Architect
Endpoint Privilege Management is a crucial aspect of IT security and compliance. It involves granting the minimum level of permissions and privileges necessary for devices and users to perform their tasks, while preventing unauthorized or malicious actions. Endpoint Privilege Management can help reduce the risk of data breaches, malware infections, ransomware attacks, and other cyber threats.
The purpose of this article is to show you how to deploy and manage Microsoft Intune Endpoint Privilege Management (EPM) for standard users, along with showing the end user and administrator experiences throughout the process for a single application. As a user needs to install an application, they will be required to request elevated access. Once an administrator approves, they will be notified that the application is available to install with elevated privileges. I will also demonstrate how to see if the user installed the application using Microsoft Intune device query. Microsoft Intune EPM and Device Query are part of the Microsoft Intune Suite add-on licensing.
PrerequisitesTo deploy Microsoft Intune EPM, you will need the following:
Obtain the certificate of the application by right clicking the application and selecting “Properties.”
An End-User ExperienceAn end user can request access to install the Microsoft Remote Desktop application by right clicking the file and selecting the “Run with elevated access” option.
Before Microsoft Intune EPM is applied: Access should be denied for standard users until approval has been given.
After Microsoft Intune EPM is applied: Will allow the user to request access and install once an administrator approves. The end user will get a Windows toast notification once approved. This could take 15 minutes, give or take.
Business Justification: Once the end user runs the application with elevated access, they will be required to provide a business justification.
User Notification: Once the administrator approves the request, the user will receive a Windows toast notification that they can now run the application with elevated access.
Administrator ExperienceAdministrators must use the “Elevation Requests” tab to view pending requests. Currently, they do not get notified by any other means.
View elevation requests: Via the Microsoft Intune Administration portal, the administrator can go to: Endpoint Security -> Endpoint Privilege Management -> Elevation Requests:
Approve, Deny, Revoke: An administrator can select the app and either approve or deny the initial request. You can also revoke access post approval.
Device Query: An administrator can check to see if the application has been installed on the device using Microsoft Intune device query. In this example, we will check to see if the exact file is installed in the expected directory:
As you can see, the Microsoft Remote Desktop executable was discovered showing the application was installed.
Benefits of Microsoft Intune Endpoint Privilege ManagementBy using Microsoft Intune Endpoint Privilege Management, IT administrators can achieve the following benefits:
We Can Help!If you have any questions or are looking for assistance in creating a Modern Endpoint Management strategy or deploying Microsoft Intune Endpoint Privilege Management as part of your device management solution, please reach out to info@eGroup-us.comor complete the form below.
PrevPreviousCatch up with Copilot for Microsoft 365, Your Post-PTO Productivity PartnerNeed Assistance with Endpoint Management?Contact our team today to schedule a call with one of our experts.
The post How to Deploy Microsoft Intune Endpoint Privilege Management appeared first on eGroup Enabling Technologies.
Catch Up with Copilot for Microsoft 365, Your Post-PTO Productivity Partner###### Chris Stegh
CTO and VP of Strategy
I’ve always wanted to write a travel blog, but instead of a diary of my family’s recent road trip to the coast of North Carolina, this article outlines how Copilot for Microsoft 365 can be used to catch up from the week off.
You’ll learn some prompts (in bold) that can keep you informed about important things while you’re out of the office, and prompts to get caught up when you’re back.
Before You Go On PTOTo use Copilot while out of the office, you can use it on your mobile device. It should already appear within Teams as an app, as long as you have previously added Copilot to your Teams desktop. If it’s doesn’t appear under “Chats” as shown below, add it by installing or updating the Microsoft 365 mobile app. Then, you may need to activate the button by going into Settings/General/Copilot, which pins the Copilot button to the top of Chats as shown.
While Out of the OfficeRather than scrolling through a myriad of emails and Teams messages, skip right to the important things by asking Copilot!
After tapping the Copilot button above, you’ll be able to ask it to summarize emails, Teams messages, and meetings. You can get a readout of those items all at once, or with some specificity. “Summarize all important emails, Teams messages, and meetings from Tuesday” (or “from Wednesday and Thursday”). This provides a verbose list organized by items you received in Outlook, Teams chats you received, and from calendar activities. Specifying dates keeps Copilot from giving too much and less relevant information.
When Back in the OfficeTo leverage the capabilities listed below, use Copilot for Microsoft 365 within your desktop version of Teams or click here.
Catch Up with VIPsIt often makes sense to catch up on activities from certain people (i.e., supervisors, project managers, or other top collaborators). “Summarize all important emails and chats sent by /manager from last week.” Repeat with different / references for whomever you’re concerned with catching up with first.
Get Synced on a Specific TopicYou can catch up on an important project, customer, or thread. Type the command, “Summarize all activities about
Focus on Pending Action ItemsTo broaden your scope, ask, “Did I receive any action items last week?” That will bring up summaries from the meeting transcripts (if available) that mentioned you. You can also ask, “Was I mentioned in any meetings last week?” Finally, ask, “What happened in the
Get a Broad OverviewOnce you’ve reviewed specific topics from specific people, take a bigger picture view of everything that may have happened. “Summarize all my emails, Teams messages, channel messages from the past work week.”
If desired, Copilot can provide ideas about how you should handle your follow ups. For a more advanced and possibly helpful interaction, write a prompt with additional queries. “Summarize my emails, Teams messages, and channel messages from the past work week. List action items in a dedicated column. Suggest follow-ups (if applicable) in another column. The table should follow this format: Type (Mail/Teams/Channel) | Topic | Summary | Action item | Follow-up.”
Again, Copilot works better when you separate meetings from messages. To catch up on all meetings, use the prompt, “Summarize all meetings from the past work week.” If you found the table above helpful, you can repeat the formatting to view follow ups and action items in columns by adding, “List action items in a dedicated column. Suggest follow-ups (if applicable) in another column. The table should follow this format: Type (Mail/Teams/Channel) | Topic | Summary | Action item | Follow-up.”
Respond to EmailsInbox swamped? You can find more details and process email messages by heading over to Copilot Chat or Outlook (where you can click the Copilot button at the top). Use the prompt, “Summarize all important emails from the last work week,” or “Summarize emails about
To give it a more professional flare, make your drafts sound more like you. Create a personal sound fileand reference the file when asking Copilot for a draft.
Review Long Emails, Documents, or DecksTo get a summary of all the documents, presentations, and emails you received, ask Copilot to, “Explain this
Move OnFinally, to see if you’ve missed anything (or if you’re completely swamped), you may find Copilot’s response to, “What should I do first to get back on track this week?” to be useful.
Plan Your Next VacationNow that you’ve saved all that time on re-entry into the office, you can use Copilot (Web) to ask questions, describe your preferences, set your budgets, get suggestions for where to go, and get links for where to stay and what to do next time. Check out this video to start looking forward to your next round of R&R!
Hope you had/have a nice break!
We Can Help!If you have any questions or you’re looking for assistance in deploying Copilot for Microsoft 365, please reach out to info@enablingtechcorp.com or complete the form below.
PrevPreviousConfigure Location Services via Intune: Microsoft TeamsNeed Assistance with Copilot for Microsoft 365?Contact our team today to schedule a call with one of our experts.
The post Catch up with Copilot for Microsoft 365, Your Post-PTO Productivity Partner appeared first on eGroup Enabling Technologies.
Configure Location Services via Intune: Microsoft Teams###### Dave Berquist
Senior Cloud Solutions Architect
When working with Microsoft Teams and Public Switched Telephone Network (PSTN) calling, you are likely required to provide emergency location information for your users. If it’s an emergency and a user dials 911, the location information would be provided to the Public Safety Answering Point (PSAP). This information can be added manually by the user, or it can be discovered through Windows Location Services and used in Microsoft Teams PSTN calling.
If you want to ensure that the user’s location services are enabled, restrict them from disabling it in addition to forcing location access to Microsoft Teams. You can create a Microsoft Intune configuration profile to manage this and assign it to your users.
You can start by getting the Microsoft Teams “PackageFamilyName” via PowerShell, then run the “Get-AppPackage -Name MsTeams” command. What you’re looking for is “MSTeams_8wekyb3d8bbwe.” This is the corporate Microsoft 365 version of Teams—not to be confused with the personal (or consumer) version of Teams, which is named “Microsoft Teams.” In that case, “PackageFamilyName” is “MicrosoftTeams_8wekyb3d8bbwe.”
Now that we have the Microsoft Teams “PackageFamilyName,” we can proceed to Microsoft Intune to create a policy that enables location services, stops users from disabling, and ensures it’s enabled for Microsoft Teams.
In Microsoft Intune, navigate to Devices -> Windows -> Configuration Profiles -> Create New Policy:
We Can Help!If you have any questions or you’re looking for assistance in deploying this as part of your device management solution, please reach out to info@enablingtechcorp.com or complete the form below.
PrevPreviousTeams Governance Settings: Balance Collaboration and RiskNeed Assistance with Configuring Location Services?Contact our team today to schedule a call with one of our experts.
The post Configure Location Services via Intune: Microsoft Teams appeared first on eGroup Enabling Technologies.
Teams Governance Settings: Balance Collaboration and Risk###### Tom Papahronis
CIO Advisor
Microsoft Teams is an incredibly powerful tool that enables efficient collaboration and information access across an organization. That said, a remarkable number of customers that we work with struggle to manage and secure it the way that they would like to.
Much of the time, Teams was enabled during the pandemic to try to help employees work more effectively remotely, but it was deployed without much planning or training. As a result, Teams access is often over-permissioned while also being under-adopted and under-governed. Features like guest access and third-party app access are often unrestricted, and the usage of Teams and channels is inconsistent. Conversely, Teams loses a lot of value if it is over-restricted, so finding a balance that is right for your organization is critical.
Teams governance overall is a huge topic. Organizations need to establish some norms and policies regarding how Teams should be used, and there are hundreds of settings in the application. In this blog, I’ll address seven of the most common recommendations we give to customers to help them start getting Teams back on track. These settings will help to address common risks from Teams sprawl and overprovisioned access while allowing most of the collaboration features to be available to employees.
7 Most Common Recommendations Limit Who Can Create a TeamLimiting who can create a Team helps prevent Teams sprawl and allows those who are authorized to help ensure Teams and Channels are being used appropriately, and standards can be followed regarding Teams naming and ownership.
Restricting Team creation also restricts Office 365 group creation, so make sure to identify any other group creation workflows before applying this restriction. For more information, check out Manage who can create Microsoft 365 Groups. Create and Publish a Teams Naming StandardHaving a naming standard helps to set some organizational norms and makes it easier for employees to understand what to expect and how to interpret Team names.
Although limited, Microsoft provides a facility for automatically enforcing a naming standard based on either Entra ID attributes or user provided strings. Learn more here: Microsoft 365 Groups and Microsoft Teams naming policy.
In many cases, however, Microsoft’s Group Naming Policy is not as robust as one might want. If it is too limiting, the organization should still deploy a naming standard. Standard prefixes or suffixes can make it easier to determine the type of Team and its use. Create and Enforce a Standard Taxonomy for Teams and ChannelsEstablishing a standard taxonomy will help make Teams easier to navigate and encourage employees to use Teams and Channels in a similar way across business units and departments. Have a bias toward Channels. Only create a Team if a Channel in an existing Team won’t do the job. A Team is mostly just a group of Channels, so fewer Teams and more Channels is usually the right approach.
Public vs Private Teams: Most Teams are Private, meaning that members need to be invited by the owner, and the onus is on the owner to ensure that only the right staff (or guests) have access. Public Teams can be seen and joined by anyone in the organization, so they are good for employee engagement and other purposes where confidentiality is not a concern.
Here is a sample taxonomy that you can build on:
If any user is active in the Team (i.e., posts a message, accesses a file, etc.) the renewal cycle is restarted from the beginning. The owners of frequently used Teams will never see anything regarding expiration.
Expiration policies can be set globally or on a per Team basis. For more information, check out Microsoft 365 group expiration policy. Establish a Team Decommissioning or Archival ProcessFor Teams that have reached the end of their lifecycle, it is a good idea to have a process established to either archive or delete the Team. Often an organization will want to save documents related to a project, but not chat content or other transient information captured in Teams. This archival and deletion can be an administrative process, or you can allow the Team owner to archive a Team themselves.
Consider adding a Teams decommission or archival step to your project close-out process.
Archival renders the Team read-only but deleting does delete associated files. Often, organizations will archive files somewhere, but delete the Team. Learn more here: Archive or delete a team in Microsoft Teams. Restrict Third-Party Teams AppsTeams apps are a great way to extend the Teams client as the one-stop-shop for processes and information access, but it is important to vet the third-party (non-Microsoft) apps available in Teams before allowing their use. All Teams apps are available to users by default, so I often advise customers to restrict access to only the Microsoft apps, and then vet and publish the third-party apps as needed to either everyone or just the user groups that will use them.
Third-party apps and Microsoft apps can be enabled or disabled separately. Find out more here: Manage your apps in the Microsoft Teams admin center. Review and Update Teams Guest Access SettingsGuest access in Teams can be a bit complex, as guest capabilities are determined by the result of several policies working together across Entra ID, Microsoft 365 groups, SharePoint, and Teams. This combination gives you a lot of flexibility but can also introduce unintended consequences.
It is important to create a Teams guest access document that defines what guests are allowed (or not allowed) to do. That should be used as a guide to configure the various policies and settings to provide that level of access.
We Can Help!We help our clients with Teams Governance and Security all the time! Click Here if you’re interested in learning more about our Teams Governance Workshop. If you have questions or would like some help with Teams governance in general, please reach out to info@enablingtechcorp.com or complete the form below.
PrevPreviousSecuring What Really MattersNeed Assistance with Teams Governance?Contact our team today to schedule a call with one of our experts.
The post Teams Governance Settings: Balance Collaboration and Risk appeared first on eGroup Enabling Technologies.
Securing What Really Matters###### Chris Stegh
CTO and VP of Strategy
The Problem is the Perp, Not the VictimWhen a hospital is victimized by ransomware, patients whose care is disrupted due to postponed or relocated appointments have a right to be angry. When the prices of gas or meat spike because of a cyber incident, consumers are right to demand action. When a government agency or school system loses the data of its citizens or students, they’re justified in asking, “Why!?” (If they’re polite in their choice of words.)
These incidents are not only illegal, but also immoral, and unjust. They’re initiated by nation-states, their proxies, or criminals who attack from all corners of the globe. Occasionally, they target specific victims, but mostly, adversaries indiscriminately search and attack any vulnerable victim.
It’s like planting a garden to feed a community in need, only to have someone constantly uproot the seeds before they can grow. Imagine that in the physical world—no one would stand for it! We shouldn’t stand for it in the cyberwar arena, either.
Step One: Hire Motivated PeopleSome of us are so irked that we direct our energy for 50+ hours a week to cybersecurity. Dedicated cyber pros won’t stand by while innocent people are affected. Protecting and hunting valuable systems and the people that count on them is why we do what we do.
At eGroup Enabling Technologies, we believe in taking a proactive approach to protecting, detecting, and responding to incidents for our customers, and this article shares some of those practices.
Step Two: Be Clear About ResponsibilitiesIn organizations with large security teams, the concept of a RACI chart is needed. Often, different priorities and unclear roles between CISO organizations and IT operations slow the time to respond to new threats or implement new protections. This excerpt of the RACI chart below shows the groups involved, and which groups are Responsible, Accountable, Consulted, and Informed for the planning and the decision-making of the security lifecycle. Additional pages cover implementation, monitoring, red team exercises, and the like.
For smaller security teams, especially where security and IT are managed by the same people, internal RACIs are less necessary. Clearly, those teams need more external assistance to manage and hunt for threats.
Gartner Group predicts that by 2026, 60% of organizations will employ the services of a Managed Security Service Provider, up from 30% today. Gartner recommends that organizations with less than 8 full-time personnel seek out co-managed security services (from “Market Guide for Co-Managed Security Monitoring Services”).
Chances are, if you’re reading this, you are either proactively or reactively exploring such services. Gartner and others are coining the term, “Co-Managed Security Services,” where a partner, “Provides remote maintenance and monitoring of client-owned threat detection, investigation, and response capable products.”
eGroup Enabling Technologies takes a co-managed approach, yielding architectures that resemble the following:
Clients own and co-manage the devices, software, and systems in the left-hand side, and when contracting for ThreatHunter services, benefit from the added layer of proactive monitoring added in green. This architecture is specified as the way all Microsoft Intelligent Security Association members and Microsoft Verified Managed eXtended Detection and Response partners must connect to clients.
Customers have responded positively. Marcus Ienaro from NYC law firm, Herrick said, “Oftentimes, Managed Security Providers require you to put in their own technology. That was one of those things we’re trying to avoid, not just from a cost perspective, but also from an integration perspective. We had the license and the tool set, we just needed someone to monitor alerts. That’s when we turned to eGroup Enabling Technologies.”
While internal RACIs are less necessary for small IT and security teams, having a RACI with service providers is critical. In co-managed environments, eGroup Enabling Technologies generally works with customers in the construct outlined below. The outer nomenclature refers to the functions within NIST 800-61, Cybersecurity Framework. If you’re unfamiliar with the NIST Cybersecurity Framework, click here to download our eGuide.
Step Three: Get ProactiveRegardless of either self-managing or co-managing the security environment, frequent updates are required for two primary reasons:
In both cases, many SMBs don’t have the time to stay in front.
Some MSSPs simply configure agents and wait for the incidents to come in. ThreatHunters do that too, but to minimize the number of incidents that occur, the systems need to be periodically tuned for improvements. As result, our ThreatHunters regularly engage to:
Executives with small security organizations know how challenging it can be to protect assets from the latest cyber threats. With limited resources, time, and expertise in the latest threats, it’s difficult to manage risk.
The CFO of new ThreatHunter customer Carolina Eastern stated, “We were not trying to get hacked. We thought we were doing fine, but we didn’t know. We were hacked, and it was a lot of pain. After partnering with eGroup Enabling Technologies, our outlook now is ‘We are trying not to get hacked.’”
Together we can raise the cost of criminal activity and cease cyberattacks from harming innocent patients, consumers, and citizens from malicious, unfounded, and illegal attacks.
We Can Help!Does your organization lack the time and bandwidth or specialized skills to deploy and keep security systems updated? We can help! If you have questions or would like some guidance on cybersecurity, please reach out to info@enablingtechcorp.com or complete the form below.
PrevPreviousJune 2024 NewsletterLooking for Guidance or Assistance with Cybersecurity?Contact our team today to learn how we can help.
The post Securing What Really Matters appeared first on eGroup Enabling Technologies.
June 2024 NewsletterTable of ContentsWhat’s New at eGroup Enabling Technologies?eGroup Enabling Technologies Earns Spot on CRN’s 2024 Solution Provider 500 List for the 12th Consecutive Year!
CRN’s annual Solution Provider 500 list recognizes North America’s largest solution providers by revenue, and serves as a prominent benchmark for many of the channel’s most successful companies. This year’s list of companies represents a combined revenue of more than $501.2 billion, and the honorees are among the top influencers driving momentum in the IT industry and the global technology supply chain.
“We’re proud to accept the CRN SP500 award for the 12th year in a row! This recognition underscores our commitment to innovation, client satisfaction, and industry leadership. It’s a testament to the hard work and dedication of our team, whose persistent pursuit of excellence continues to drive our success. This accolade inspires us to push boundaries further and set new standards in technology solutions, ensuring our clients thrive in the digital landscape.” Christa Anderson – VP of Alliance, Marketing, and Sales Development
What’s New in the Hybrid Data Center?CentOS The end-of-life date for CentOS Linux 7 is quickly approaching on June 30th, 2024, just a few weeks away. If you’re unfamiliar with this announcement, the CentOS project announced in 2020 that it was shifting upstream of Red Hat Enterprise Linux (RHEL) rather than remaining binary compatible with RHEL. This one is coming fast, and with so many platforms being built using CentOS, we’re seeing a flurry of vendors quickly migrating away from CentOS to RHEL, Rocky Linux, or a variety of other distributions. Cisco Secure Firewall now integrates into Azure Virtual WAN (vWAN)! Starting with the 7.4.1 update, Secure Firewall Virtual (fka FTDv) now integrates with Azure vWAN to simplify firewall deployment in Azure. Key benefits include built-in availability and resiliency, quick provisioning, simplified routing, and integrated support. This integration enhances security and consistent policy enforcement across hybrid cloud environments, thus elevating the cloud security posture for Azure customers.
Bookmark Recommendation: Always looking for the latest recommended releases for Cisco Nexus 9K or Catalyst 9K’s? Bookmark these!
+ **NX-OS** for Nexus 9K Platforms
+ **IOS-XE for Cat 9k Platforms**
Cohesity Have you upgraded to 6.8.2 yet? With CentOS reaching its end of life on June 30th, 2024, Cohesity is migrating the baseOS platform from CentOS 7.9 to RHEL 7.9. This upgrade is low-risk, since CentOS 7.9 and RHEL 7.9 are binary compatible. Update Cohesity clusters to remain supported!
Nutanix Nutanix and Red Hat have announced greater collaboration. Nutanix is moving to leverage RHEL as the operating system of choice for the Nutanix Cloud Platform, moving away from CentOS as the base. This is welcome, as the EOL announcement for CentOS, the Nutanix platform, is mostly built on CentOS.
* A new release branch calledExtended Short Term Support(eSTS) complements the existing Long Term Support (LTS) and Short Term Support (STS). The eSTS release is meant for customers interested in adopting new features, but not upgrading multiple times a year. It is also only applicable to AOS, not AHV.
+ LTS Release: 6.5.5.7
+ STS Release: 6.7.1.8
+ eSTS Release: 6.8.0.1
* Nutanix held their annual .NEXT conference 2 weeks ago in Barcelona, and as usual with these conferences, we saw a lot of great announcements. Don’t miss our webinar recapping What’s New from .NEXT? on June 13th, but here’s a quick recap below on some of the major announcements!
* Nutanix and NVIDIA Collaborate to Accelerate Enterprise AI Adoption
PDF Version
The integration will bring together Nutanix’s automated and secure enterprise AI platform with NVIDIA NIM inference microservices for accelerated inference of state-of-the-art AI models.
* Nutanix Accelerates Hypervisor Innovation to Drive Enterprise Modernization
PDF Version
New AHV features and deployment options ideally suited for large-scale enterprise environments.
* Nutanix and Dell Technologies Collaborate on New Joint Solutions for Hybrid Multi-Cloud
PDF Version
Companies announce products and go to-market collaboration to give customers choices for traditional and modern workloads.
* Nutanix Simplifies Management and Operations of Kubernetes Clusters Anywhere to Speed Innovation
PDF Version
Nutanix Kubernetes® Platform enterprise-ready cloud-native stack helps customers run containerized applications across hybrid multi-cloud environments.
* Nutanix Accelerates Enterprise Adoption of Generative AI
PDF Version
The company delivers an Enterprise AI foundation in collaboration with NVIDIA, Hugging Face, and an ecosystem of partners to speed time to value for on-premises use cases.
Pure Storage Self-Service upgrades for FlashArray, sign us up! Pure Storage has announced that customers now have access to self-service upgrades for their FlashArray through the Pure1 portal. Previously, customers would open a ticket with Pure Support to have the upgrades performed requiring schedule alignment between Customers and Pure engineers. This new method is more user-friendly, involving automated health checks, downloading the necessary upgrade packages, and executing the upgrade once the array is onboarded through Pure1 and the new Edge Service. Don’t fret; support-led upgrades are still available.
Rubrik In a recent blog post, Rubrik discusses how their system engineers ensure software reliability and customer confidence. Key elements include high-quality observability, maintaining stable infrastructure, shifting left in the development process, and providing tailored solutions. They emphasize robust monitoring, stress testing, and proactive issue resolution. The post highlights the importance of reliability, scale, stress handling, resiliency, and longevity in their systems, using a detailed case study to illustrate these principles in action.
VMware It’s great to see VMware and Microsoft’s relationship continue to foster as it relates to Azure VMware Solution. This week’s joint announcement now allows customers with eligible VMware Cloud Foundation (“VCF”) entitlements to enable mobility to and from on-premises environments to Azure VMware Solution. This flexibility, on top of the VMware Rapid Migration Plan, allows customers to take advantage of flexible licensing AND reduce the cost and time it takes to migrate to Azure VMware Solution.
What’s New with Microsoft?Microsoft Build took place in late May. You can find a short recap HERE* from our VP of Solutions and Success, Christine Dillard.**
Azure Save on Azure compute charges with the Azure Savings Plan. Designed for businesses that need flexibility in terms of where and what consumes their hourly compute across regions. * ICYMI: Information about Migration Incentives, Bring Your Own Licensing (BYOL), discounts, and Azure Credits to support your migration to Azure VMware Solution. ClipChamp ClipChamp’s new AI feature, silence removal, automatically deletes pauses over 3 seconds in videos and is free in preview. Rollout is by late July. Copilot for Microsoft 365 Users will be able to use Draft with Copilot in Microsoft Word with the on-canvas Copilot menu when selecting text, a list, or a table to generate new content starting in August. Today those formats are unable to be processed. * Users can select a language of choice during a Teams meeting even without activating transcripts or captions. This feature, available when ‘Allow Copilot’ is set to ‘Only During the Meeting,’ will ensure responses are in the chosen language. Rollout begins mid-June. * Relevance Tuning for Graph connectors for Microsoft Search and Copilot for Microsoft 365 will let admins apply importance weights to properties of Graph connections. The ranking model will consider the property weight when finding relevant content, prioritizing the properties that are most important for the organization and ensure that relevant content is returned for the given query. Defender for Cloud Apps Organizations will automatically be added to the Microsoft Defender for Cloud Apps public preview on July 7, 2024, unless they update their preview features settings by July 1, 2024. Failure to act implies consent to the changes. Defender for Office 365 A new feature will automatically remove allow list entries 45 days after their last use, starting late June. This applies to customers with Microsoft Exchange Online Protection and Defender for Office 365 Plan 1 or 2. Users are advised to update their allow entries to utilize this new feature. * New details on who or what is responsible for releasing a message from quarantine will be available. The Release by field will be propagated with the email address of the user or admin responsible for the release. This will be available in the email summary flyout panel accessible from the Quarantine page. * New details are coming about who or what is responsible for releasing a message from quarantine. The “Release by Feld” will be propagated with the email address of the user or admin responsible for the release and be available in July. Entra ID Improve authentication strength by using passkeys stored on devices. Users will see new registration options in My Security Info. The rollout will complete by early August. * Users can now sign in with their phone without a password for multiple accounts in the Authenticator App on any Android device that supports it. They can add several accounts in Microsoft Entra to Microsoft Authenticator and use phone sign-in for all of them from one Android device. The Microsoft Entra accounts can belong to the same or different tenants. * Platform SSO for macOS is available in public preview. Platform SSO is an enhancement to the Microsoft Enterprise SSO plug-in for Apple Devices that makes usage and management of Mac devices more seamless and secure. At the start of public preview, Platform SSO works with Microsoft Intune. * External authentication methods enable you to use your preferred MFA solution with Entra ID. Exchange Online Beginning January 2025, Exchange Online will enforce a new External Recipient Rate limit of 2000 recipients per 24 hours, introduced in two phases for new and existing tenants. * The classic Exchange admin center is retired, and the “View Another Mailbox” feature is now in the modern EAC, which admins can access. Fabric Contributors will be able to deploy workspace content between stages using Microsoft Fabric Deployment Pipelines starting late July 2024. The update will be completed by early August 2024, and admins should review roles to comply with organizational policies. Intune Starting now, Intune MAM service updates will require the latest versions of iOS wrapped apps, iOS SDK integrated apps, and the Company Portal for Android. Users will be blocked from launching outdated apps. iOS LOB apps must be on Intune Wrapper/SDK version 17.7.0 or later. Microsoft 365 Struggling to keep up to date with the latest features and bundles with Microsoft 365? Use this interactive click-through to compare and learn the various capabilities you can unlock at each licensing level. * Delve Web will retire on December 16, 2024. Most features are available in other Microsoft 365 experiences, with Profile Cards being the main alternative. * Microsoft 365 is reducing support for Natural Language-Based Search in favor of keyword-based searches, starting early July. Affected products include Outlook, Teams, SharePoint, OneDrive, and Microsoft Search on Bing and office.com. Microsoft Copilot “Catch up” is a new feature in Microsoft Copilot, that requires a license and provides updates and action prompts on a tab, rolling out from late June to July. * Connection statistics for admins in Microsoft Graph Connector will provide insights into crawled and indexed items, and will be available in Public Preview along with General Availability by early July. * The Microsoft Copilot app will be available in classic Outlook for Windows by mid-June. * Microsoft Copilot introduced the ability to create PowerPoint presentations from PDF files. OneDrive OneDrive for Business is simplifying web URLs for easier navigation, rolling out mid-June to mid-July 2024. The new format is “tenant-my.sharepoint.com” with no impact on existing scenarios. Old URLs will redirect, and no preparation is needed from users. Automation and scripts remain unaffected. * OneDrive has a feature for annotating PDFs with text boxes, rolling out by late June. Users can edit PDFs in OneDrive and SharePoint by opening the file and using the ‘Edit’ and ‘Add Text’ commands. * OneDrive for Web will soon enable “Offline Mode” for Windows and macOS devices running the OneDrive sync app, allowing users to continue working with OneDrive even when offline. * Users can edit PDFs in OneDrive and SharePoint by opening the file and using the ‘Edit’ and ‘Add Text’ commands. Outlook CLASSIC: Users with a Copilot license will see a new Copilot icon, providing access to various Copilot for Microsoft 365 features in classic Outlook for Windows. Copilot chat experience in Outlook is expected to finish by late June. Summarize by Copilot and Coaching by Copilot are already available, as is draft by Copilot. * NEW: Outlook will introduce a split view in month view for multiple calendars, by early July. Users should be informed of the change. * Outlook and Teams are introducing a new meeting response called ‘Follow’ for attendees who can’t attend but want to stay informed. It will roll out around mid-July, initially in the new Outlook for Windows and the web, not on Mac or mobile. Organizers will be notified of ‘Follow’ responses, and users will be marked as free but kept in the loop. Power Apps The tenant setting “disableShareWithEveryone” that was previously set to “off” by default, will now be set to “on” by default. This means that makers will not be able to share their canvas apps with the “Everyone” group without changing this setting. This aligns with Microsoft’s recent security recommendations of being “Secure by Default.” Preventing sharing with this group aligns with this security posture due to the overexposure of data. * Starting in early June, a new feature allows end users to sort, filter, and search their canvas app galleries with Copilot. When working with a gallery, users will be able to quickly filter, sort, and search for the items in the gallery using natural language. This is a net-new functionality, as the current gallery does not support filtering unless the maker manually implements the capability. Purview Information Protection Microsoft Purview Data Loss Prevention (DLP) on Windows devices will soon support over 100 file types, detect sensitive content in metadata, PDF form fields, and files within Office files. The update will roll out from late June to late October. * Microsoft Purview’s Adaptive Protection feature allows the HR resignation date to be used as a condition for risk level. Rollout begins late June 2024 and completes by late July 2024. * Purview’s compliance portal will soon allow users to restrict unintentional sharing of sensitive items to unallowed cloud apps and monitor sensitive activities in macOS environments. No action is required to prepare for this rollout. The rollout began in late April 2024 for preview and August 2024 worldwide. * Members of a mail-enabled security group will be able to view and respond to encrypted mail in a shared mailbox using Outlook for Windows. Rollout begins late June, with general availability expected by late October. Users need Outlook for Windows Version 2402 or higher. * Starting now, Microsoft Purview DLP will be separated from Microsoft Defender for Endpoint on Windows devices. This backend change will not affect the deployment process. Customers will see two distinct processes for DLP and Defender instead of one, improving stability and performance. * A tenant-wide hold report in eDiscovery (Premium) will rollout by early July. This report will provide information on all hold policies for eDiscovery cases, and can be accessed under the ‘Reports’ tab. * Privacy control in Endpoint DLP improves by limiting access to PII in Activity Explorer to admins with the ‘Data Classification Content Viewer’ role. It will roll out by late June. Admins without this role will lose certain access rights. * Public preview of Microsoft Purview Generative AI Hub has begun, and will finish around November. The AI Hub helps organizations secure data in AI applications, offering insights, data protection policies, and compliance controls. * A new feature, Protection Policy, provides label-based protection on Azure SQL, Data Lake Gen 2, Blob Storage, and Amazon S3. General availability starts early November, with a free public preview phase. * Purview is enhancing the user experience for opening locked records in Office applications by making them read only. This prevents editing errors and is expected by late August. Stream Stream (Classic) retired on April 15, 2024, with all content being deleted on August 20, 2024. * New video page templates are coming to SharePoint Online and Stream, with a rollout in June. Users will be able to create video pages and news posts directly from the Stream web app. SharePoint Restricted SharePoint Search for Copilot will allow admins to limit search to selected SharePoint sites. Rollout will complete by late June. The feature is off by default and requires admin roles to enable. Users can access content from allowed sites and personal files. * Videos uploaded to SharePoint Online, Yammer, and Office.com will soon have automatic transcriptions. The feature is enabled by default but can be disabled via PowerShell. No preparation is needed, but informing users is suggested. Teams Chat and Channels Teams desktop client must be updated to comply with the Modern Lifecycle Policy. Unsupported versions will receive notifications or blocking pages starting June 19th, 2024. Ensure regular updates for service reliability and feature compatibility. * The “Notify When Available” feature in Microsoft Teams informs users when a colleague is available. It can be activated via the chat list or the “People” section in settings. No admin action is required. Users can manage or unsubscribe from notifications in settings. * Custom emojis and reactions will allow users to upload images or GIFs. Each tenant can add up to 5,000 custom emojis. The feature will be available by default, with rollout starting late June 2024. Admins can manage this feature through the Teams Admin Center. * Custom avatars for group chats are available, allowing users to upload their own images or select from built-in images or emojis. * Teams for Mac will change its name from “Microsoft Teams (work or school)” to “Microsoft Teams.” Tenant admins should be aware of the implications of these changes, which include a change in the MacOS .app file name. MDM systems that check whether Teams is installed on a given Mac device may need to update their .app name check to prevent duplicate versions of the app. * People will be able to create avatars from photos by late June. It requires a quad-core processor, 4 GB RAM. Users can create up to three avatars and need Teams 2.1 or newer on Windows PC or Mac. To prepare, enable Mesh Avatars in the Teams Admin Center. * Multi-Tenant Organization (MTO) capabilities in Microsoft Teams for GCC, GCC High, and DoD clouds will complete by late June. Admins can activate these features to enable seamless collaboration across tenant boundaries. Users must update their client machines and Teams clients to specific versions. * Later this summer, create stunning images right from a Teams chat thanks to the new Microsoft Designer integration. Simply type ‘@Designer’ in the chat box, describe the image you envision, and everyone in the group chat can see the suggestions and collaborate on refining them using additional prompts. * Channel cards will provide an overview of a channel, including description, activity, team name, and membership, and appear on desktop and web by hovering over channel names. Rollout is expected to be complete by late July 2024. Teams MeetingsThe support for Microsoft Teams Live Events has been extended beyond the initial retirement date of September 30th, 2024. Customers can continue using it and upgrade to town hall, the new event solution, at their convenience.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousHow Microsoft Copilot in Fabric Boosts ProductivityNeed Assistance with These Updates?Contact our team today to get help with any of the changes mentioned above!
The post June 2024 Newsletter appeared first on eGroup Enabling Technologies.
How Microsoft Copilot in Fabric Boosts Productivity###### Joseph Lindahl
Business Insights Data Architect
How I’m using Copilot in Fabric: Data Factory, Data Science – Spark Notebooks, Power BI Desktop – DAX Query View, and Visuals Creation.
As a BI Engineer/Data Analyst, I often work with different tools and platforms to collect, process, analyze, and visualize data. However, sometimes I face challenges such as writing complex code, creating effective measures, or designing engaging visuals. That’s why I was excited to try Microsoft Copilot, a new AI-powered assistant that helps me write code faster and create better content more quickly in Fabric. In this blog post, I will share my experience using Copilot with four tools: Data Factory, Data Science – Spark Notebooks and DAX Query View, and Visuals Creation in Power BI Desktop. I will also highlight the benefits and features of Copilot that impressed me the most.
Data FactoryData Factory is a tool in Fabric that allows me to create data pipelines and orchestrate data movement and transformation. One of the tasks that I often do in Data Factory is clean and transform data, such as removing duplicate and bad rows of data, using the first row as column headers, and removing or adding columns. Copilot was very helpful in this task, as it suggested code snippets and expressions that could be used to perform these operations. You could ask Copilot to do things like create new queries, add steps to existing queries, or describe an existing query or step. For example, below is a screenshot of asking Copilot in Data Factory to remove duplicate data rows based off the Customer field. I am not sure that this could be made any easier.
Data Science – Spark NotebooksSpark notebooks are one of the Data Science tools of Fabric that allows me to write and run code in an interactive environment and use Spark to process large-scale data. I was not remarkably familiar with Spark or Notebooks as I have not traditionally held a role as a Data Scientist. However, Microsoft continues to flatten the learning curve, as Copilot was a major help in this tool. Copilot suggested code snippets and comments that I could use to write Spark SQL queries, create data frames, perform aggregations, join tables, and inspect and visualize data. This helped me get up and running quickly as I am familiar with writing traditional SQL queries. For example, I asked Copilot the command below, and what it came back with was almost perfect—the problem was me not providing enough context, not Copilot. I should also mention this is on some gnarly group policy text data from a bunch of spreadsheets… we can’t make it too easy!
PROMPT: “Please create code to load a data frame with a join of tables from all the branches based on Policy_Group_or_Registry_Key and Policy Setting fields.” The results were amazing! With a couple button clicks I can easily add this code cell and run it, then further inspect from there or chart my data with ease (screenshot below).
Power BI Desktop – DAX Query View
DAX Query View is another tool in Fabric, but found in Power BI Desktop; that allows me to write and run DAX queries, and create measures and calculations based on my data model. DAX is a powerful and expressive language, but it can also be complex and tricky to master. Copilot was amazing in this tool, as it helped me write and test DAX queries, and create measures, upon measures, upon measures in moments!
For example, the default out-of-the-box “suggest measures” is actually the following prompt: “Define and evaluate measures not in my model and add a comment that explains what each measure does.” Either run this as-is or refine it to your liking. Copilot will typically come back with around four new measures for you to examine/analyze and add to your model if you desire. Simply click the “Keep Query” button, which will then add a nifty “Update Model: Add New Measure” hyperlink above each of the suggested measures. Now just decide which ones you want to keep, then rinse and repeat. I can now easily run and test these DAX queries in the query view and see the results in a table all in one place. Having written DAX measures for several years as a professional, I can’t put into words the amount of time and effort this single Copilot tool saves alone!
Visuals Creation
Visuals Creation is a tool that allows me to create and design visuals and reports in Power BI Desktop and share them with others. Visuals are a great way to communicate and present data, but they can also be challenging to create and format, especially when starting from scratch. Copilot was very helpful in this tool, as it helped me create and suggest content for my report and customize and enhance my visuals. For example, I could simply ask Copilot to “Suggest content for this report” and it would analyze my data and then come back with four different options that I could easily add to my report with a single button click!
For the best performance I found these few tips extremely helpful:
After learning these tips, I was able to hand the reins over to Copilot and let it go to work creating rich and robust visuals for my report in a matter of seconds.
ConclusionIn this blog post, I shared my experience using Microsoft Copilot in Fabric, and how it helped me with various tools such as Data Factory, Data Science – Spark Notebooks, DAX Query View, and Visuals Creation in Power BI Desktop. Copilot is a great assistant that helped me write better code and create better content, along with helping me learn and improve my skills. Copilot was easy to use, fast, and accurate, and it offered me suggestions and explanations that I could work with. Copilot greatly boosted my productivity, confidence, and satisfaction in my work, and I highly recommend it to anyone who works in Business Intelligence. Whether it be ingesting and transforming data, performing data discovery, analysis, or modeling, creating measures or even creating end-user reports; Copilot in Fabric is an amazing tool and a real game changer!
We Can Help!Our experts are ready to help you boost your productivity using Microsoft tools. Interested in signing up for a Microsoft Fabric Educational Workshop? Click Here to Learn More, or complete the form below.
PrevPreviousIntune Windows Autopilot Device Preparation###### Interested in Signing Up for a Microsoft Fabric Educational Workshop?
Complete this form to schedule time with one of our experts.
The post How Microsoft Copilot in Fabric Boosts Productivity appeared first on eGroup Enabling Technologies.
Intune Windows Autopilot Device Preparation###### David Bergquist
Senior Cloud Solutions Architect
New Announcement!There is a new Intune Windows Autopilot in town!
Welcome Intune Windows Autopilot device preparation to general availability for Entra ID joined devices! Windows Autopilot device preparation should simplify and expedite the process, reducing the time it takes to run devices through Autopilot—plus near real-time deployment status, monitoring capabilities, and improved troubleshooting.
Currently, Autopilot device registration requires software version:
Microsoft Entra ID joined is the only supported method. So, if you require hybrid Entra ID join, you can still use Windows Autopilot in parallel.
Windows Autopilot device preparation only supports user-driven mode, and it does not require device registration (like Windows Autopilot). In addition, Windows Autopilot device preparation supports line-of-business and Win32 applications in the same deployment, whereas Windows Autopilot does not.
With these enhancements, device preparation is more efficient and versatile, making it an invaluable tool for your organization’s deployment needs. Embrace the future of device management with Intune Autopilot and experience seamless, real-time deployment like never before!
We Can Help!If you are excited as I am about Intune Windows Autopilot device preparation and need assistance deploying this as part of your device management solution, please contact us at info@enablingtechcorp.com or complete the form below and we can assist!
PrevPreviousNavigating the Post-Xi Leap Landscape: Top Alternatives for Disaster Recovery###### Need Help with Windows Autopilot Device Preparation?
Contact our team to schedule a call with one of our experts.
The post Intune Windows Autopilot Device Preparation appeared first on eGroup Enabling Technologies.
Navigating the Post-Xi Leap Landscape: Top Alternatives for Disaster Recovery###### Mike Dent
Field CTO, Hybrid Data Center
2024 has been a struggle for many organizations with the Broadcom acquisition of VMware, from increased costs for renewals to uncertainty in the EUC world with Horizon View. The concern from customers regarding what their alternatives are is definitely keeping me busy throughout the week– helping our customers navigate the waters and the journey of what comes next.
Another unexpected, and somewhat disappointing discussion we’re having now, is the decision by Nutanix to discontinue Xi Leap in April of 2025. While maybe not surprising in the wake of the capabilities and extensibility of Nutanix Cloud Clusters (NC2) for initially AWS and now Azure, many businesses are left wondering about their next steps for Disaster Recovery (DR) with Nutanix—and specifically with AHV.
Xi Leap provided a very simple and robust method for Nutanix customers to gain access to Disaster Recovery-as-a-Service (“DRaaS”), without needing to invest in new skills (such as AWS or Azure), or in infrastructure for a secondary cluster. Yes, there were and are other Colo and Service Providers out there offering Nutanix DRaaS, but many customers enjoyed the single point of contact with Nutanix for both on-premises and DR.
As we consider alternatives to Xi Leap, now is also the perfect time to consider the Four R’s of cloud migrations to see if it’s time to modernize the application architecture landscape.
DRaaS AlternativesLet’s take a brief look at some current alternatives to Nutanix Xi Leap—both within the Nutanix ecosystem and outside.
Nutanix Clusters (NC2) on AWS or AzureBenefits:
Considerations:
Workloads: Consider where you land your workloads.
-Do you replicate everything? If so, you need to understand the requirements during failover to expand the NC2 cluster to ensure you optimize costs.
-Or, do you run Test/Dev in NC2 to validate connectivity and operations, and during failover, just expand the cluster? Options are there, but careful planning can ensure you don’t have cost overruns!
Migrating to a Public CloudBenefits:
Native Tools and Services: Utilize the native tools and services offered by public cloud providers like AWS, Azure, or Google Cloud for DR. These platforms offer robust solutions tailored for various DR scenarios.
Considerations:
Cost Management: Keep an eye on costs, as they can spiral if not managed correctly. Deploying a Second Nutanix Cloud Cluster for Disaster RecoveryBenefits:
Familiar Environment: Stay within the Nutanix ecosystem, ensuring a familiar environment for your IT team.
Considerations:
Management: Requires ongoing management and maintenance of the additional cluster. Leveraging a DRaaS ProviderBenefits:
Expertise: DRaaS providers bring specialized knowledge and experience, ensuring best practices are followed.
Considerations:
Happy exploring, and may your DR strategy be ever resilient!
We Can Help!Stay tuned to the eGroup Enabling Technologies news page for updates. Our experts are ready to answer any questions that you might have about these changes. If you need help with vetting or implementing the options above, please contact us at info@enablingtechcorp.com or complete the form below.
PrevPreviousCRN’s Solution Provider 500 for the 12th Consecutive Year###### Need Help Navigating Changes in Disaster Recovery?
Contact our team to schedule a call with one of our experts.
The post Navigating the Post-Xi Leap Landscape: Top Alternatives for Disaster Recovery appeared first on eGroup Enabling Technologies.
eGroup Enabling Technologies Earns Spot on
CRN’s 2024 Solution Provider 500 List
CHARLESTON, SC, May 29, 2024 — CRN®, a brand of The Channel Company, announced that eGroup Enabling Technologies has been recognized on its 2024 Solution Provider 500 list for the 12th consecutive year!
“Ranking on CRN’s 2024 Solution Provider 500 recognizes the service innovations and market responsiveness of the list’s leading technology integrators, managed service providers, and IT consulting firms.”
Jennifer Follett, VP, U.S. Content, and Executive Editor, CRN, The Channel Company
CRN’s annual Solution Provider 500 list recognizes North America’s largest solution providers by revenue, and serves as a prominent benchmark for many of the channel’s most successful companies. This year’s list of companies represents a combined revenue of more than $501.2 billion, and the honorees are among the top influencers driving momentum in the IT industry and the global technology supply chain.
“eGroup Enabling Technologies is proud to accept the CRN SP500 award for the 12th year in a row! This recognition underscores our commitment to innovation, client satisfaction, and industry leadership. It's a testament to the hard work and dedication of our entire team, whose persistent pursuit of excellence continues to drive our success. This accolade inspires us to push boundaries further and set new standards in technology solutions, ensuring our clients thrive in an ever-evolving digital landscape.”
Christa Anderson - VP of Alliance, Marketing, and Sales Development at eGroup Enabling Technologies
eGroup Enabling Technologies stands as a leading IT solutions service provider known for its commitment to innovation, reliability, and client-centric approach. With a focus on empowering organizations nationwide, eGroup Enabling Technologies specializes in delivering tailored solutions that drive efficiency, productivity, and growth.
At the heart of eGroup Enabling Technologies’ success lies its team of highly skilled professionals, who possess a deep understanding of business technology and strategies. Their expertise allows their team to offer a comprehensive suite of services, including cloud solutions, datacenter modernization, cybersecurity, data and AI, consulting, and managed services.
“These companies have shown an unflagging commitment to business agility, continued growth, and future success through a period of rapid IT channel change, including the expansion of Everything as a Service and GenAI disruption. Our congratulations go to each company named to this year’s Solution Provider 500!”
Jennifer Follett, VP, U.S. Content, and Executive Editor, CRN, The Channel Company
CRN’s 2024 Solution Provider 500 list will be available online at www.CRN.com/SP500, and a sampling of the list will be featured in the June issue of CRN Magazine.
ABOUT eGROUP ENABLING TECHNOLOGIES
eGroup Enabling Technologies is a leading provider of IT solutions and Managed Services that empower organizations to achieve their business objectives. With a focus on Cybersecurity, Cloud, Data and AI, and Collaboration, eGroup Enabling Technologies helps clients harness the power of technology to drive innovation, enhance security, and optimize operations.
ABOUT THE CHANNEL COMPANY
The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers, and end users. Backed by more than 40 years of unequaled channel experience, we draw from our deep knowledge to envision innovative solutions for ever-evolving challenges in the technology marketplace. www.thechannelcompany.com
Contact our team of experts today to get started on your journey to a more productive and secure organization!
The post CRN’s Solution Provider 500 for the 12th Consecutive Year appeared first on eGroup Enabling Technologies.
Generative AI: Where Does It Fit In & What Myths Need to Be Debunked? ###### Kai Andrews
Azure AI, Data, & Power Platform Technology Practice Leader
In recent years, the rise of ChatGPT and other AI-powered chatbots has propelled artificial intelligence into the spotlight of mainstream attention. With their ability to generate responses to a myriad of questions, AI platforms have fostered a perception that they possess boundless capabilities. This perception has led many to believe that AI can tackle virtually any challenge, prompting business leaders to eagerly embrace the idea that generative AI holds the key to solving a wide array of business problems.
Custom Copilots Are Good For:1. Generating New Content Based on a Library or Pool of Similar Content
Do you have a library full of similar documents that you wish you could summarize and reuse? For example, many organizations have contracts or service agreements; these documents contain a wealth of information around how, where, when, and with whom work has been done. These contracts typically include assumptions and prerequisites, many of which will be rewritten repeatedly because it is too difficult to remember where certain language was used in the past. Generative AI can excel at “reading” these documents and uncovering relevant content needed for future documents. This is arguably the most powerful advantage of using generative AI—overcoming the challenge of the “blank page.” Let Generative AI jump-start your creativity with a few draft paragraphs that you can manipulate into your desired final output.
2. Qualitative Content Comparisons
Product-centric organizations publish vast catalogs of their offerings. Most of the time, this content is published in descriptive text instead of structured tables with rows and columns. Written prose is great for a consumer who wants to read about a particular product, but the same verbose text is not ideal when the same consumer wants to pivot and compare two or more products. Instead of having to maintain both descriptive text as well as a table of features, Generative AI can extract the comparisons from unstructured text sources and provide the consumer with the desired comparisons. While this may not be suitable for a detailed, technical product comparison, this does allow for natural language comparisons of form and function.
3. Q & A Based on Curated Unstructured Content
Too many hours are spent designing and building intranet pages that users must navigate to ultimately offer up an HR or IT policy, or other standard operating procedures. Some users will hope to find the information they need by searching for it, or entering search keyword combinations that they hope will retrieve the desired document. Generative AI is ideally positioned to transform this legacy experience. Users can ask natural questions and the AI will return the favor by providing users with the information they seek. The only thing the content author needs to do is ensure that the source documentation is up to date.
4. Repeatable Calculations Based on User-Provided Data Input
Generative AI doing math? Sure! If users can provide the AI with the needed input parameters, a chatbot can easily pass this information to a workflow that calculates the output based on structured rules. For example, if a worker wants to know their prorated commission, they could provide the bot with a date range and projected hours/sales, and the system can use inherent data such as the user’s location and role to calculate the commission amount. While not exactly “generative” in the sense that the bot is creating net new content, this is a use case where users would have had to historically interact with a separate app or system and can now have a seamless integration with a bot.
5. Data Searches (Lookup) Where Users Provide Specific Parameters
This last one also skirts the concept of “generative” AI. The convenience of being able to do quick data lookups from a central chat interface cannot be dismissed. Like the repeatable calculations above, the bot would ask the user for input parameters but then, instead of performing a calculation, the bot would pass the parameters to a lookup function that filters a data table and returns the desired result. This works best when the input parameters are unique numbers or text that are not prone to misspellings. For example, entering a SKU or product ID is less error-prone than typing in someone’s last name. Ideal scenarios for data lookups could include finding shipping rates based on product IDs and zip codes or warranty information based on a product number. What doesn’t work as well are broad, undefined data searches… more on that below.
Custom Copilots Are NOT Good For:1. Data Analysis Where You Expect Precise Numeric Answers
Many believe that a custom copilot can be pointed to a library of structured data sources (insert your favorite Excel spreadsheet here) and have it return with data-centric answers. What do we mean by “data-centric?” We are referring to answers that are precise and repetitive. This means that the answers are accurate and identical when asked multiple times. For example, having the AI ingest a product catalog and then asking it, “How many red widgets do we sell?” will likely result in less-than-ideal answers such as, “We sell a variety of red widgets, some of which include the square widget and the round widget.” The user was hoping for, “We sell 174 red widgets.” The answer is not wrong, per se, it is just not of the quality that the user is hoping for. The user/AI interaction can be improved by providing more information to the copilot as outlined in item #5 above. Just remember that a custom copilot is not a data summarization or extraction tool. Do note that there are other copilots, such as the one built into the Fabric platform, that excel at this type of data querying… it’s just not our custom copilots, which are the main topic of this article.
2. Random Comprehensive Content Extraction and/or Manipulation
Like the case above, if a user wants to extract or identify all occurrences of specific text in a document, then a custom copilot is likely not the right solution. Note that we underlined the term “all.” This is an important distinction. A Generative AI tool will reply well to a prompt such as, “Show me assumptions that were made when delivering our product overseas,” however, it will likely fail when prompted to, “Show me all of the assumptions made when making an international sale.” It will surely list some, but a user will not get a reliably consistent and comprehensive answer. Generative AI, at least today, will struggle with absolute expectations.
3. Content Associations Based on Company or Industry-Specific Vernacular
The large language models that are available when building a custom copilot continue to improve. However, today, they do struggle with identifying contextual relationships if all that they can refer to is company-specific or industry-specific information. Let’s walk through an example. Let’s assume that there are metal and wooden bed frames in a product catalog. The metal ones are referred to as “Luxor,” while the wooden frames are referred to as “Rustic.” These names are unique to the company selling these products and are simply known to sellers as brand identifiers. The same company may have a document that outlines the pros and cons of metal and wooden frames, but that document does not use the “Luxor” and “Rustic” identifiers. Unless this name-to-type association exists somewhere else that the copilot has access to, users asking to compare the “Luxor” and “Rustic” frame with regards to durability will likely get the dreaded, “I cannot help you with that” response. It is certainly possible to create the contextual relationship using other AI mechanisms but to expect an out-of-box association will likely lead to a disappointing experience.
4. Content Generation in the Absence of Historical Context
While this last scenario appears self-evident, it does need to be included in the list. There is a certain perceived “magic” surrounding many of the AI experiences today. It seems that we can ask any question and receive an answer. But this illusion is a result of incredible investments in teaching and grounding the AI in a vast amount of information. It is necessary to remember that many organizations have proprietary data and information, and that this information must be provided to the custom copilot for it to learn and generate new answers. Depending on where and how an organization has historically stored information, it may require a focused effort to migrate and secure the content in a cloud-based repository. While not a trivial exercise, a pragmatic and iterative approach can yield quick and evolving experiences. Return on investment should be calculated for such initiatives… but that is another story for another day.
We Can Help!Custom copilots are a revolutionary tool that extends the benefits of Generative AI and natural language interaction to any organization. Let us help you explore when and where these benefits can be employed for your workforce and customers.
Sign up for an Action Accelerator Workshop to learn the best use cases and benefits that Custom Copilots can provide to your organization.
Contact us at info@eGroup-us.com or complete the form below!
PrevPreviousLicensing Optimization: Lessons Learned###### Need Help Navigating Custom Copilots?
Contact our team to schedule a call with one of our Copilot experts.
The post Generative AI: Where Does It Fit In & What Myths Need to Be Debunked? appeared first on eGroup Enabling Technologies.
Licensing Optimization: Lessons Learned###### Tom Papahronis
CIO Advisor
At some point in almost every Microsoft 365 engagement I have with customers, we talk about licensing. Even if the project has absolutely nothing to do with licensing, and no one planned for it to come up, and we all pinky-swear that we won’t talk about it, it inevitably still comes up. There are two lessons that I would like to share today about that:
Many times, customers do not realize that they can accomplish their goals with what they already own, or they assume that what they want to do with Microsoft 365 will cost far more than it actually will. I have provided some insight, resources, and examples below.
Understand What You HaveIt goes without saying that Microsoft 365 E5 provides a robust, comprehensive set of productivity, collaboration, systems management, compliance, and security tools. If you can make this investment and implement all that comes along with it, you should.
That said, do not assume you need E5 to get significant value out of the Microsoft 365 platform. The E3 license levels (especially Microsoft 365 E3) offer a ton of features and functionality, and I recommend that you maximize what you can out of those features before looking at add-ons or upgrading. M365 E3 includes most of Office 365, Intune, Windows Enterprise, and strong identity protection. If you have frontline workers, the F3 license complements the E3 license well.
If you need more features, make sure to consider the add-ons that are available for Teams Voice, the Defender security functions, or Purview data governance and compliance. Keep in mind though, that the cost of adding a couple of add-ons may require nearly as much spending as a full E5 license. It may end up making more sense to move to E5—in this case, to simplify license administration and take advantage of the full E5 feature set.
Also, the common thread that the E5 suite or add-on SKUs provide is automation on top of the E3 functionality. Automated security response features, email hygiene, identity protection, and data labeling are prominent, and the time savings that the automation brings to both end users and the technology or security teams can be a reason to move to E5.
(The links above reference a great resource at M365maps.com that can help you understand how Microsoft 365 licenses are structured, and showing which features are part of each bundle. This site provides color-coded diagrams of the Microsoft 365 features, along with a wealth of other information. In particular, this diagram shows what is included in each bundle and add-on as it relates to Office 365 and Microsoft 365 E3 and E5, including a breakdown of the add-ons you can purchase separately.)
Maximize the Value—Leverage the Ecosystem!I am still surprised at how many organizations don’t know what they are licensed for and still have not implemented features that could help them achieve their goals related to identity, security, compliance, and device management. They made the decision to invest in the integrated Microsoft 365 ecosystem, but then did not implement the integrated tools it provides. Not only are they often paying for redundant solutions, but in many cases, they can easily address gaps that do not require much effort to deploy. A few of the more common scenarios:
If the last time the IT team really considered some of these features was more than a year ago, I would encourage a second look now. Microsoft is continually adding features, and often customers find that the current feature sets in Microsoft 365 do provide features that may have been missing the last time they were reviewed. This is especially true when it comes to identity, security, and data governance toolsets.
Lastly, Look Towards the FutureCustomers that do a good job deploying the Microsoft 365 integrated services I’ve discussed, also give themselves a leg up when it comes to other cloud adoption initiatives. Implementing additional services like Copilot for Microsoft 365 or migrating infrastructure and applications to Azure is easier if the Microsoft 365 services are already in place as the foundation. All these components are designed to integrate and complement each other.
We Can Help!eGroup Enabling Technologies works with customers all the time to help with licensing evaluations and alignment with technical and business initiatives. Let us know if you would like to have a licensing discussion or need some help making sense of it all.
Learn more about our Licensing Optimization Workshop here.
PrevPreviousTeams Phones Major Updates: Chicken or Egg?###### Need Help Navigating Microsoft Licensing?
Contact our team to schedule a Licensing Optimization Workshop.
The post Licensing Optimization: Lessons Learned appeared first on eGroup Enabling Technologies.
Teams Phones Major Updates: Chicken or Egg?###### John Miller
Cloud Solutions Architect
IntroductionThis year, Microsoft will be making two (2) major changes to Teams Native phones:
So where does the chicken and the egg fit into this? Native Teams Phones must be running Android 12 to be managed in Intune with AOSP. Teams administrators need to get ready to update their phones to Android 12 before the switchover to AOSP in Intune. Later this year we will publish a follow-up article on configuring Intune and AOSP to support these updated phones, and as events warrant, we will publish updates as we get them from the Native Teams Phones manufacturers.
Firmware Updates Current State as of May 8, 2024 The current firmware versions for Native Teams Phones, Android Rooms, Displays, and Panels can be found on the Microsoft Teams certified Android Devices web page. AudioCodes The certification is for version 2.1.87 which is based on Android 12. This version of the firmware is not currently available. The certification for the phones is valid until October 4, 2026. * Available versions: + 19.705: released on February 19, 2024: This is the current firmware version available for all the AudioCodes Teams phones. * AudioCodes issued Product Notice #0506 on July 26, 2023. There were several important points in this document: + Software Version 2.1 will be made available for all models on September 30, 2023… this did not happen! + To upgrade the phones to version 2.1, they need to have been previously upgraded to version 1.19.516 or later. + AudioCodes strongly recommends that all native Teams devices be upgraded to version 1.19.516 or later. + The notice only applies to these models: - TEAMS-C455HD - TEAMS-C455HD-DBW - TEAMS-C470HD - TEAMS-C470HD-DBW - TEAMS-C435HD-R * In the “Certified Teams Phones” section towards the top of the web page you will notice that the AudioCodes C448HD and C450HD phones are not listed. These phones cannot be upgraded to Android 12. More on this below. Crestron None of their phones are currently certified. * Available versions: + 1.0.6.20 released on April 20, 2023. HP | Poly The certification for many Poly CCX and Trio devices is good through October 31, 2024. The web page indicates that these phones run on Android 9. * Available versions: + 1.6.1006: This was released for the CCXs on April 12, 2024. + 1.6.1005: This was released for the Trio C60 on the same date. * On April 17, 2024, HP | Poly announced the availability of Poly Voice Software (PVOS) 9.0 “in about a month” for the Poly CCX phones and the Poly Trio C60 Conference Phone. They are expecting to have these phones certified by Microsoft with PVOS 9.0 before the firmware is released. Yealink The MP54, 56, and 58 are certified through October 4, 2026, running version 122.15.0.135. * The CP965 is certified through the same date running 143.15.0.48. * The MP52 is not in the list. This suggests that this model cannot be upgraded to Android 12. Please check with Yealink if you have any of these phones. * Available versions: + 15.0.83: for the MP52 released on January 18,2024. This version appears to run under the Android 9 operating system. + 15.0.136: for the VP50 released on the same date. + 15.0.142: for the MP54, 56 and 58 released on October 9, 2023. This version appears to be based on the Android 12. What Do You Need to Do As of Now?AudioCodes Follow the provided guidance and get your C435s, C455s and C470s upgraded to at least version 1.19.516 as soon as possible! * The C448s and C450s cannot be upgraded to Android 12. AudioCodes has provided a method for converting these phones to function through the Teams SIP Gateway. A One Voice Operations Center (OVOC) server is the only current way to convert these phones. We will provide updates on this when provided by AudioCodes. Crestron Contact Crestron or your reseller about their plans regarding running firmware based on Android 12 on these devices. * eGroup Enabling Technologies was not able to find any information about this from Crestron. HP | Poly PVOS 9.0 should be available some time after May 17, 2024. * We will provide updates when available from HP | Poly. Yealink If you haven’t already done so, upgrade your MP54s, MP56s, and MP58s to a minimum firmware version of 122.15.0.142. * You should do this as soon as you can! Management Platform Conversion from Android Device Administrator to AOSP Stay tuned! As soon as we get the information and try it out, we’ll post our guidance. SummaryThere are some significant changes happening this year for Native Teams Phones—updating them to run under the Android 12 operating system and replacing the Android Management platform in Microsoft Intune. The availability of the updates and guidance from the manufacturers varies. Organizations should follow the guidance and upgrade their phones before Microsoft starts to deprecate the Android Device Administrator platform at the end of August 2024.
Stay tuned to the eGroup Enabling Technologies news page for updates. Our experts are ready to answer any questions that you might have about Microsoft Teams, Teams Voice, and Teams Devices. If you need help with implementing or migrating to Microsoft Teams or Teams Voice or upgrading your devices, please contact us at info@enablingtechcorp.com or complete the form below.
PrevPreviousNavigating the VMware License Increase: RETHINK IT & Consider Azure VMware SolutionNeed Assistance with These Updates?Contact our team today to get help with any of the changes mentioned above!
The post Teams Phones Major Updates: Chicken or Egg? appeared first on eGroup Enabling Technologies.
Navigating the VMware License Increase: RETHINK IT & Consider Azure VMware Solution###### Jason Webster
Field CTO,
Azure & Microsoft 365
With Broadcom’s recent acquisition of VMware, many organizations face increases in licensing costs under the new subscription model due to how the subscriptions are calculated. Azure VMware Solution (AVS) presents a compelling alternative to not only help accelerate an organization’s cloud strategy, but also to avoid additional VMware-centric costs. Below are four key benefits of migrating to AVS that could help your business avoid these increased costs and gain additional advantages:
Cost Predictability and Cloud FlexibilityAzure VMware Solution offers a more predictable cost structure, which is essential for budgeting and financial planning. AVS pricing when optimized with reserved instance incentives offers a consistent and predictable monthly/annual total cost of ownership (TCO). This predictability helps businesses avoid unexpected increases in licensing fees while offering flexibility to migrate to Azure Native Infrastructure (IaaS) and Platform (PaaS) services over time.
Seamless Integration and MigrationYou already have the VMware skills to be successful today. AVS allows you to migrate your existing VMware workloads to Azure without the need to refactor applications. This seamless integration not only saves time and resources, but also minimizes the risk of migration errors. By leveraging familiar VMware tools and skills, existing IT teams can ensure a smooth transition and support, enhancing business continuity and reducing training costs.
Reduce the Impact: Leverage Azure VMware Solution for Disaster RecoveryYou don’t have to make the decision to migrate everything at once. You can still reduce the licensing impact of the transition to subscription pricing by re-targeting secondary data centers to AVS for disaster recovery. The ability to minimally size and scale rapidly as needed allows you to save and consume resources on an as-needed basis.
Cloud Migration: Avoiding “Lock-In”When adopting Azure VMware Solution. Microsoft Azure PaaS and IaaS solutions are easier to adopt. With the ability to connect AVS and Azure Native solutions leveraging the Azure backplane, your organization can modernize your server and serverless solutions overtime with less disruption. With flexible conversion options for reserved instances between AVS and Azure Native, you can ensure you can optimize your costs now—and in the future as well.
ConclusionMigrating to Azure VMware Solution is not just a tactical move to avoid potential licensing cost increases; it’s also an opportunity to enhance your organization’s agility and operational efficiency by accelerating your cloud journey. By choosing AVS, you gain the capabilities of the full VMware platform with the operational efficiency of the cloud.
Learn More: Check out our Events OnDemand for a deeper overview of Azure VMware Solution or join us for an upcoming event live.
Interested in seeing how Azure VMware Solution can benefit your business? Sign up for our 30-Day Azure VMware Solution Pilot to experience firsthand the ease of migration and the advantages it brings. Don’t let licensing costs dictate your infrastructure choices—explore a more flexible and cost-effective solution today.
PrevPreviousMay 2024 NewsletterNextTeams Phones Major Updates: Chicken or Egg?Next###### Need Help Considering Your VMware Options?
Contact our team to schedule a 30-Day Azure VMware Solution Pilot.
The post Navigating the VMware License Increase: RETHINK IT & Consider Azure VMware Solution appeared first on eGroup Enabling Technologies.
May 2024 NewsletterWhat’s New at eGroup Enabling Technologies?eGroup Enabling Technologies Recognized with the Microsoft Verified Managed XDR Solution Status
eGroup Enabling Technologies has achieved Microsoft Verified Managed Extended Detection and Response (MXDR) solution status. By achieving this status, our team has proven our robust MXDR services including a Security Operation Center (SOC) with 24/7/365 proactive hunting, monitoring, and response capabilities all built on tight integrations with the Microsoft Security platform.
“Being Microsoft Verified for our MXDR solution is not just a badge of honor; it’s a testament to our commitment to excellence in cybersecurity. Being among the ~70 MXDR verified solutions validates our hunters’ dedication to protecting our customers from threats using the best available security platform.” -Chris Stegh, CTO and VP of Strategy at eGroup Enabling Technologies
What’s New in the Hybrid Data Center?Cisco Cisco recently patched two critical zero-day vulnerabilities in their firewall products, discovered after probable nation-state actors targeted them in a campaign dubbed “ArcaneDoor.” These vulnerabilities and their patches for devices running ASA and FTD software are summarized in our recent blog. * Cisco joined Microsoft and IBM in signing a Vatican-sponsored pledge to ensure the ethical use and development of artificial intelligence. This pledge advocates for AI to be developed and regulated with transparency, inclusion, responsibility, impartiality, and security. * Cisco’s cloud-based version of its Meraki/Azure security and SD-WAN appliance (virtual MX) had a mid-April update. The vMX connects physical MX gear to Azure through the same Meraki dashboard. A vMX can act as your Cisco Meraki SD-WAN and Auto VPN node to link your network with your Azure services. Nutanix Nutanix Move, a cross-hypervisor mobility solution to move VMs with minimal downtime, has an updated release 5.2.0. Move now supports the customization of target VM IP configurations. It supports TLS 1.3, resolves file migration issues, and is available in the following migrations:
+ ESXi to AHV on Ubuntu 20.04, 22.04
+ ESXi to ESXi on Nutanix on Ubuntu 22.04, RHEL 9.
Company Portal Update: Users must update to the minimum Company Portal app versions by July 10, 2024, to maintain access. Automatic updates will handle this for most users; others must update manually. Classic Conditional Access policies need migration. Users should be notified to prepare.
We Want to Hear From You!Like any good partner, we’re listening! Since the latest advancements and announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see more of!
Click Here To Tell Us What You'd Like To See In The NewsletterPrevPreviousWhere, Oh Where, Should I Start With AI? Need Assistance with These Updates?Contact our team today to get help with any of the changes mentioned above!
The post May 2024 Newsletter appeared first on eGroup Enabling Technologies.
Where, Oh Where, Should I Start With AI? ###### Kai Andrews
Azure AI, Data & Power Platform Technology Practice Leader at eGroup Enabling Technologies
AI is everywhere. It is one of those rare technologies that have fascinated so many people in such a short time. When it comes to deciding whether to adopt AI in their organization, business and technology leaders are divided into three groups. There is the vanguard, those pioneers who already have AI-enabled solutions up and running. Then there are the experimenters, trying out the new functionality in a test environment or, perhaps, launching a simple pilot or proof-of-concept to see what it can do. Then we have the majority of leaders—aware that they need to enable AI in their organization but unsure how to begin—and wondering how to identify the ideal use case for testing AI. Do you belong to this third group? Well, then keep reading, this article is for you.
Finding opportunity for AI in an organization does not have to be hard or daunting. It all comes down to how individuals embrace creative brainstorming. Once again, the rule of three applies because at eGroup Enabling Technologies, we approach discovery using three different approaches. Let’s explore each in turn…
Watch & LearnMany individuals possess the ability to apply one situation to another; to connect the dots, so to speak. If you are capable of easily making associations, then the best path forward might be to simply absorb stories of how others are applying AI. Watch a video that explains AI capabilities or browse a website and learn what a product set can do. Many websites also contain use cases, or stories, about how organizations have deployed AI to solve problems. If you need someone to brainstorm with, reach out to your favorite consultant and have them discuss what they are seeing out in the wild. As you learn, consider how your discoveries relate to challenges that you have seen in your organization.
**Findings & Indicators**An alternate approach is to look inside your organization and engage with leaders and individual contributors to understand where they are experiencing pain points in their various daily activities. What should you be looking for?
Here are the top indicators that can lead you to find your AI opportunities:
Finally, if all else fails, what is the “one thing” that you wish could be solved tomorrow? What issue has been a thorn in your side for too long? Examine those problems and see if AI can provide a feasible solution to your wish. Artificial Intelligence isn’t necessarily magical pixie dust that solves all your needs, but if you want to see how you can possibly apply AI in your business, use one or more of the approaches above to analyze your business and we are confident that you will find your starting point. Happy hunting!
PrevPreviousPurview Insider Risk Management: How to Capture Forensic Evidence on Intune Enrolled Devices###### Need Help Idenitfying Use-Cases for AI?
Contact our team to schedule an AI-Action Accelerator workshop.
The post Where, Oh Where, Should I Start With AI? appeared first on eGroup Enabling Technologies.
Purview Insider Risk Management: How to Capture Forensic Evidence on Intune Enrolled Devices###### David R. Bergquist II
Senior Cloud Solutions Architect
Insider risks are a growing threat to organizations, especially in the era of remote work and cloud-based services. Insider risks can be caused by malicious actors who intentionally steal or leak sensitive data, sabotage systems, or compromise accounts. They can also be caused by negligent or compromised users who accidentally or unknowingly expose data, violate policies, or fall victim to phishing or malware attacks.
To effectively manage insider risks, organizations need to have a comprehensive solution that can monitor user activity, detect anomalous behavior, alert security teams, and respond to incidents. Moreover, they need to have a reliable way to collect and preserve forensic evidence that can support investigations and legal actions.
In this blog post, I will show you how to configure Purview Insider Risk Management to collect forensic evidence on managed devices enrolled in Intune. I will demonstrate how to use Microsoft Intune to install the agent required to capture forensic evidence on enrolled Windows devices.
Table of ContentsWhat is Purview Insider Risk Management?Purview Insider Risk Management (IRM) is a cloud-based compliance solution designed to help organizations detect, investigate, and act on malicious and inadvertent activities that pose insider risks. It correlates various signals to identify potential risks such as intellectual property theft, data leakage, and security violations. IRM leverages advanced analytics, machine learning, and user and entity behavior analytics (UEBA) to monitor user activity across various data sources, such as Microsoft 365, Azure, SharePoint, OneDrive, Teams, Exchange, and more.
IRM Forensic Evidence provides security teams with visual insights into potential insider data security incidents. It includes customizable event triggers and built-in user privacy protection controls, providing a thorough investigation path to insider data risks, such as unauthorized data exfiltration of sensitive information.
Purview Insider Risk Management can help you:
In addition to the capabilities outlined above, adding Forensic Evidence to IRM can provide additional visual context to security teams aiding their investigations. Activities such as printing files, creating, or copying files to USB, creating, or transferring files to a network share, and even using a browser to upload files to the web.
PrequisitesLicensing:
Supported Platforms:
Physical Devices:
| Hardware | Minimum Requirement | | RAM | Minimum of 8 GB (at least 2 GB should be available for client usage) | | CPU | Intel i5 or above and AMD Ryzen 5 or above | | Graphics | Compatible with DirectX 11 or later, with a WDDM 1.0 driver or later (currently only integrated graphics cards supported) | | Disk | Minimum of 10 GB of disk storage | | Display | Minimum screen resolution of 1920 x 1080 |
Virtual Devices:
| Hardware | Minimum Requirement | | RAM | Minimum of 16 GB (at least 2 GB should be available for client usage) | | CPU | Minimum of eight vCPU processors or equivalent | | Disk | Minimum of 10 GB of disk storage | | Display | Minimum screen resolution of 1920 x 1080 |
Permissions/Role Groups required for viewing, submitting, and approving forensic evidence. To assign these roles to users or groups, you need to use the Purview portal. To learn more about how to assign roles and manage permissions in Purview Insider, see the documentation here.
| Purview Role Group | Capability | | Insider Risk Management | Configure and view everything inside IRM. | | Insider Risk Management Admins | Configure polices, access analytics insights and submit forensic capturing requests. | | Insider Risk Management Investigators | Access and investigate cases, alerts, and forensic evidence captures. | | Insider Risk Management Auditors | View & export audit logs. | | Insider Risk Management Approvers | Only review, approve, or reject forensic collection requests. |
How Do You Capture Forensic Evidence on Microsoft Intune Enrolled Devices?You must onboard devices to the Purview compliance portal and install the Purview agent to devices to start capturing content. For the purposes of this article, we will onboard devices via the Purview compliance portal and use Microsoft Intune to push out and install the Purview Forensic client. We will download the Purview client, wrap it with the Microsoft Win32 Content Prep Tool (Intunewin), and push the packaged client out to the intended devices. The client will be used to onboard and capture activity on approved users’ Windows devices.
Onboarding DevicesOnboard device via the Purview Portal: Settings -> Device onboarding -> Devices and onboard your devices. It may take a couple of hours before devices show up.
Installing the AgentDownload the Purview Forensic client.
We hope you found this blog post helpful and informative. If you have any questions, feedback, or require assistance, please contact us here or complete the form below. Thank you for reading!
PrevPreviousZero Day Threat – Cisco Remote Access on ASA/FTDNextWhere, Oh Where, Should I Start With AI? Next###### Interested in learning more about preventing Insider Risks?
Contact our team of experts today to discuss how to better secure your data!
The post Purview Insider Risk Management: How to Capture Forensic Evidence on Intune Enrolled Devices appeared first on eGroup Enabling Technologies.
Zero Day Threat – Cisco Remote Access on ASA/FTD**###### Mike Dent
Field CTO- Hybrid Data Center: eGroup Enabling Technologies****Cisco recently patched two critical vulnerabilities in their firewall products, discovered after probable nation-state actors targeted them in a campaign dubbed “Arcane Door”. These zero-day vulnerabilities, found in devices running ASA and FTD software, were exploited to implant malware and possibly steal data. Cisco released three patches and has tracked the hacking group under UAT4356 and STORM-1849 by Microsoft. These flaws, involving HTTP header parsing and a legacy VPN client preloading capability, allowed attackers root-level access, emphasizing the need for immediate patching and security upgrades.
The Talos blog post and more details from Cisco can be found here and here. Thanks to Jarad for the heads up!**
Understanding the ArcaneDoor Espionage Campaign: Implications and DefensesBackgroundThe ArcaneDoor campaign represents a sophisticated espionage effort aimed at exploiting perimeter network devices across various organizations, including critical infrastructure sectors. By targeting devices such as Cisco Adaptive Security Appliances, attackers, identified as UAT4356, leverage custom malware (like “Line Runner” and “Line Dancer”) to modify configurations, capture network traffic, and potentially move laterally within networks. This campaign underscores the vulnerabilities in network devices and the strategic approaches taken by state-sponsored actors to compromise such essential assets.
*Fixes Available*Cisco has released fixes for the ASA and FTD platforms (thankfully, FMC doesn’t have any known impact), as workarounds are unavailable for two of the three posted vulnerabilities. CVE-2024-20353 is the most critical, while the other 2 warrant close inspection.
| Cisco Security Advisory | CVE ID | Security Impact Rating | CVSS Base Score | | --- | --- | --- | --- | | Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability | CVE-2024-20353 | High | 8.6 | | Cisco Adaptive Security Appliance and Firepower Threat Defense Software Persistent Local Code Execution Vulnerability | CVE-2024-20359 | High | 6.0 | | Cisco Adaptive Security Appliance and Firepower Threat Defense Software Command Injection Vulnerability | CVE-2024-20358 | Medium | 6.0 |
If you’re running ASA or FTD code I’d say, based on the severity of these vulnerabilities they are important enough to get them to the front of the urgent request line, if you’re currently using AnyConnect (SSL or IKEv2) for remote access.
**Unfortunately, the fixes are not part of the gold code release for ASA or FTD, with FTD release 7.2.6 being dropped just a little over a month ago. However it’s important enough to get your devices patched!
Complete the form below if you have additional questions or would like to request assistance from our team.**
PrevPreviouseGroup Enabling Technologies Recognized with Microsoft Verified Managed XDR Solution Status###### Need Help?
Contact our team of experts with any questions you may have regarding these vulnerabilities and how to address them.
The post Zero Day Threat – Cisco Remote Access on ASA/FTD appeared first on eGroup Enabling Technologies.
eGroup Enabling Technologies Recognized with the Microsoft Verified Managed XDR Solution Status
eGroup Enabling Technologies announced today that they have achieved Microsoft Verified Managed Extended Detection and Response (MXDR) solution status. By achieving this status, eGroup Enabling Technologies has proven its robust MXDR services including a Security Operation Center (SOC) with 24/7/365 proactive hunting, monitoring, and response capabilities all built on tight integrations with the Microsoft Security platform. This solution combines expert-trained technology with human-led services and has been verified by Microsoft engineers.
"Being Microsoft Verified for our MXDR solution is not just a badge of honor; it's a testament to our commitment to excellence in cybersecurity. Being among the ~70 MXDR verified solutions validates our hunters' dedication to protecting our customers from threats using the best available security platform."
Chris Stegh, CTO and VP of Strategy at eGroup Enabling Technologies
eGroup Enabling Technologies, a 9x Microsoft Partner of the Year Award winner, provides ThreatHunter: consulting, configuration, and training services to help organizations protect, detect, and respond to risks. As a Microsoft Managed Security Service Provider (MSSP), they provide security services to organizations that wish to have ongoing support and monitoring of Intune, the Microsoft 365 E5 security stack, and Sentinel. Their MSSP team has 24/7 security analysts who monitor, investigate, triage and work with clients to resolve incidents within the environment. Their approach of combining managed Intune along with Managed Extended Detection & Response (MXDR) and Sentinel, provides Complete Endpoint Protection.
"With malicious attacks on the rise, we understand security is front and center for our customers. That is why I am excited to congratulate eGroup Enabling Technologies on achieving Microsoft Verified: Managed Extended Detection and Response solution status. Their solution closely integrates with Microsoft 365 Defender and Microsoft Sentinel and has been verified by Microsoft Security engineering to ensure that it provides comprehensive service coverage across the Microsoft Security portfolio."
Rob Lefferts, CVP, Modern Protection and SOC, Microsoft
eGroup Enabling Technologies is part of the Microsoft Intelligent Security Association (MISA). “The Microsoft Intelligent Security Association is comprised of some of the most reliable and trusted security companies across the globe,” said Maria Thomson, Microsoft Intelligent Security Association Lead. “Our members share Microsoft’s commitment to collaboration within the cybersecurity community to improve our customers’ ability to predict, detect, and respond to security threats faster. We’re thrilled to recognize and welcome eGroup Enabling Technologies’ MXDR solution to the MISA portfolio.
ABOUT eGROUP ENABLING TECHNOLOGIES
eGroup Enabling Technologies is a leading provider of IT solutions and Managed Services that empower organizations to achieve their business objectives. With a focus on Cybersecurity, Cloud, Data and AI and Collaboration, eGroup Enabling Technologies helps clients harness the power of technology to drive innovation, enhance security, and optimize operations.
For additional information
Carly Picciuto, Marketing Director, carly.picciuto@eGroup-us.com, 877-347-6871
Contact our team of experts today to get started on your journey to a more secure organization!
The post eGroup Enabling Technologies Recognized with Microsoft Verified Managed XDR Solution Status appeared first on eGroup Enabling Technologies.
AI Program Management: Lessons from Infosec****###### Tom Papahronis
Strategic Advisor - eGroup Enabling Technologies*The eGroup Enabling Technologies team has been spending a lot of time in the last few months helping clients preparing and deploying Copilot for Microsoft 365 and other AI tools. Through this work, it has become clear that to successfully adopt and maximize the value of these tools, it will require a new program management area that owns the strategy and operations of these technologies.***
*Interestingly, a great approach to designing an AI program’s requirements already exists in your organization—your information security program. The parallels are numerous, and I’ll try to articulate that comparison here so you can start to leverage structures and lessons learned in security to not only jumpstart an AI program, but also as an example of the level of effort (and budget) required to fully realize the value of AI tools to the organization.*
*Table of Contents*Policies and Compliance*This is the starting point for both programs. The “Rules of the Road.” Policies define acceptable use, operational requirements, audit requirements, and include regulatory or other compliance requirements like NIST, HIPAA, CIS, etc.*
**Organizational Oversight*Leaders need to define what they want from both programs. In the case of security, that means reducing risk to an acceptable level while supporting organizational initiatives. For AI, that means developing business cases that support the organization and driving the ROI. Senior management’s support and ongoing involvement is critical for either of these programs to succeed. Establishing Centers of Excellence or other groups to define success and drive adoption from the top is key.***
**Budget*This one should be obvious, but often it’s more of a struggle than it should be. There are no silver bullets or shortcuts in security, and the same is true for AI. Dollars and time need to be allocated for expertise, tools, oversight, and holding people accountable to results. Security products and practices are far more developed in this regard today, but AI will need the same level of attention to be successful. The CFO needs to be included early and often to get AI off the ground.***
**Ownership*Just like security, AI will need an owner who is accountable for the program’s success. Leaving this to an existing (and already overextended) IT group is a mistake. Again, like security, staff with dedicated time will be needed to develop expertise, implement tools, and manage their use (and risks). CISOs exist for a reason. Technical depth will be required to bring well-managed AI solutions to life as well.***
**Configuration Management*Both programs will need controls and capabilities that are aligned with policies and business needs, including following standard practices that are auditable and flexible. Additionally, both program areas are constantly in a state of flux, so keeping up with changes and the state of the industry is paramount.***
**Data Governance*This topic is often the thorn in both programs’ sides. From a security standpoint, Data Loss Prevention (DLP) prevents unwanted disclosure, retention policies reduce the amount of data at risk, and encryption protects the data you have. For AI, retention policies help reduce data to what is relevant, encryption protects data from surfacing when it shouldn’t, and DLP again helps prevent disclosure through unexpected AI behavior or exfiltration attacks.***
**Ownership*For security, I hope this one is obvious by now. Similarly, AI also needs to be monitored. It is still a nascent technology, and the results aren’t always predictable or consistent. It’s critical to ensure organizational awareness of its strengths and weaknesses to both guide its use and develop a constant improvement methodology. Deploying and managing AI tools that can alter their behavior is both an art and a science, so staying a few steps ahead is important.***
*Hopefully this comparison gives you some insight and ideas into how to use existing security program framework to help direct the enthusiasm for AI tools into actionable steps to onboard and scale up their usage in an intentional way. The management team may not be thrilled to hear that additional structure might be needed to manage something that isn’t very tangible yet, but they will be glad when that structure is in place to absorb and scale the new benefits and challenges that AI brings. As the ROIs for these tools become apparent, this will allow you to move faster and be more responsive to the organization.*
*If you’re looking to learn more about incorporating artificial intelligence into your organization, see our AI services here: *www.eGroup-us.com/ai/.****
*PrevPreviousNamed Top 25 Cloud Computing Companies of 2024*NexteGroup Enabling Technologies Recognized with Microsoft Verified Managed XDR Solution StatusNext*Learn More About AI*Interested in learning how to become more efficient with and manage an AI program? Contact our team today to learn more.**
*The post AI Program Management: Lessons Learned from Infosec appeared first on eGroup Enabling Technologies.*
eGroup Enabling Technologies Listed on Top 25 Cloud Computing Companies of 2024 List
The Software Report announced that eGroup Enabling Technologies has been recognized on its Top 25 Cloud Computing Companies of 2024 list.
The rapid pace of cloud computing innovation and the abundance of new tools can be daunting for business leaders. However, it also presents exciting opportunities for exploration and growth. This year’s winners excel across all facets of cloud computing. They offer groundbreaking solutions, spanning from revolutionary cloud-based security and compliance tools to managed cloud services and Infrastructure as a Service (IaaS). Their innovative offerings are empowering businesses globally with cutting-edge solutions.
These cloud service providers stand out not only for their innovative technology but also for their strategic guidance, enhancing revenue and reducing costs. They support customers with tailored solutions for their specific needs. To identify top performers in cloud computing, companies were assessed on market impact and revenue growth, product reliability and performance, strategic vision and leadership, and efforts towards sustainability, such as energy-efficient data centers.
The eGroup Enabling Technologies team has 30+ years of experience with a portfolio of partners comprised of best-of-breed technologies. The team provides top-tier solutions and services creating joint-success with clients across the nation. Their team of experts holds advanced competencies across their partner technology portfolio including Microsoft Partner Designations in Data and AI, Digital & App Innovation, Infrastructure, Modern Work, and Security. They provide services from education and consulting to managing entire environments, offering their clients peace of mind by ensuring they have a trusted partner with them throughout their digital transformation journey. This enables their clients to focus their time and efforts on initiatives that drive innovation for their business.
Coverage of the Top 25 Cloud Computing Companies of 2024 list can be found here: https://www.thesoftwarereport.com/top-25-cloud-computing-companies-of-2024/.
ABOUT eGROUP ENABLING TECHNOLOGIES
eGroup Enabling Technologies, a leading provider of IT solutions and an award-winning MSP, specializes in empowering organizations to leverage technology for business success. With a team of experts and a customer-centric approach, their team offers a wide range of services, including cloud solutions, cybersecurity, collaboration, and managed services.
ABOUT THE SOFTWARE REPORT
The Software Report is a comprehensive source for market research and insights, business news, investment activity and corporate actions related to the software sector. Based in New York City, the firm is run by a seasoned team of editors, writers and media professionals highly knowledgeable on software and the various companies, executives and investors that make up the sector.
www.thesoftwarereport.com
Contact our team of experts today to get started on your journey to a more secure organization!
The post Named Top 25 Cloud Computing Companies of 2024 appeared first on eGroup Enabling Technologies.
April 2024 NewsletterWe're back with our monthly roundup!Like any good partner, we’re listening! Since Microsoft announcements are coming in quickly, we’ve separated the list into subcategories below. Let us know what you’d like to see improved!
Click Here To Tell Us What You'd Like To See In The NewsletterWhat’s New in the Hybrid Data Center?Azure On August 31, 2024, Azure classic administrator roles will be retired. Active Co-Administrator or Service Admin roles need to transition to using Azure RBAC roles by then. Starting April 3, 2024, you’ll no longer be able to add new Co-Administrator roles. Cisco For those of you running Nexus and Catalyst switches—you know about the Recommended Code pages, right? NX-OS on supported devices is now up to 10.3(4a), and you can find the Catalyst recommendations here. * Cisco is leveraging generative AI for network observability and automation in this series. Cohesity* AI continues to be an integral component that organizations consume at an amazing pace. In 2023, Cohesity released Turing for customer support, and they are now releasing Gaia, which allows organizations to utilize retrieval-augmented generation (RAG) AI and large-language models (LLMs) to provide greater visibility into backup content, compliance, and eDiscovery. * Cohesity’s Cloud Services (“CCS”) continues to evolve, and while not immediately new, CCS now supports* the backup and recovery of Azure Virtual Machines (VMs), and Azure SQL databases, in addition to the existing support for Microsoft 365 data. This is great news for hybrid cloud customers with Azure and also consuming CCS for M365 backups; they can now backup Azure Native VMs and SQL databases from the same interface (Helios). Nutanix Nutanix has recently announced the End-of-Life for its legacy software portfolio, which includes the following products: + AOS CBL, AOS NBL, Flow + Prism Pro, Prism Ultimate, Calm + Files, Objects, Mine + Era + AOS VDI + AOS RoBo * If you’re still consuming these licensing models, understand that you will need to migrate to the new software portfolio licensing models. Reach out to your eGroup Enabling Technologies Account Executive to understand what your options are. * Nutanix released several important Field Advisories over the last few weeks:
+ **Prism Central performance and resource contention**
+ **Deprecation of upgrades outside of LCM starting with AOS 6.5** – Nutanix has made amazing progress with LCM, and our team welcomes this!
+ If you’re a Nutanix Objects consumer, check out this **FA** about data unavailability.
The following new solutions will be added to the Intune Suite:
The Teams Join Launcher web page can now show the brand logo and brand image uploaded for branded meetings. Windows Server Microsoft released Out-of-Band (OOB) updates for some versions of Windows on March 22, 2024, to address an issue related to a memory leak in the Local Security Authority Subsystem Service (LSASS). If your organization uses the affected server platforms as DCs and you haven’t deployed the March 2024 security updated yet, Microsoft recommends you apply an OOB update instead.* For more information and instructions on how to install this update on your device, consult the below resources for your version of Windows:
Windows Server 2022: KB5037422
PrevPreviousBlock Top-Level Domains with Intune and Windows Firewall PolicyNextNamed Top 25 Cloud Computing Companies of 2024NextNeed Assistance with these Updates?Contact our team today to get help with any of the changes mentioned above!
The post April 2024 Newsletter appeared first on eGroup Enabling Technologies.
Block Top-Level Domains with Intune and Windows Firewall Policy****###### David Bergquist
Senior Cloud Solutions Architect - eGroup Enabling Technologies*In this blog post, I will show you how to create Intune Endpoint Security Windows Firewall Policy and Firewall Rules to block outbound traffic using reusable group settings. This is a useful scenario for organizations that want to restrict the network access of their devices to specific top-level domains. By using Intune, you can manage the firewall settings of your devices remotely and apply them to different groups of devices based on your needs.***
*Table of Contents*What are Endpoint Security Windows Firewall Policy and Firewall Rules?*Endpoint Security Windows Firewall Policy is a feature of Intune that allows you to configure the Windows Defender Firewall settings of your devices. You can create policies that define the firewall profile, the default action, and the notifications for inbound and outbound traffic. You can also create Firewall Rules that specify the conditions and actions for allowing or blocking specific traffic based on the protocol, port, application, or IP address.*
*By using Endpoint Security Windows Firewall Policy and Firewall Rules, you can control the network access of your devices and protect them from unwanted or malicious traffic. You can also create different policies and rules for different groups of devices based on their roles, locations, or security requirements.*
**Deployment*In Microsoft Intune, we will first create an Endpoint Security Firewall Reusable group. Then we will create a standard Firewall policy, and create Firewall rules to block top-level domains using the reusable group. I highly recommend testing this with a test device before rolling out to pilot groups and production.***
**How to Create Reusable Settings for Endpoint Security*One of the benefits of using Intune to manage your firewall settings is that you can create reusable settings. Reusable settings are a collection of settings that you can apply to multiple policies or rules without having to configure them individually. For example, you can create a reusable settings group that defines the IP addresses of your trusted network and apply it to multiple firewall rules that allow traffic from those addresses. In this article, we will use a reusable settings group to block top-level domains.***
*To create a reusable settings group for Endpoint Security Windows Firewall, follow these steps:*
*On the device, Firewall Advanced, you will see a blocked rule under Monitoring -> Firewall.*
**Conclusion*In this blog post, we have shown you how to use Microsoft Intune to create an Endpoint Security Windows Firewall Policy and Firewall Rules to block top-level domain access using reusable settings groups. This is a useful way to manage the network access of your devices and prevent data leakage or unauthorized connections. By using Intune, you can create and apply different firewall settings to different groups of devices based on your needs.***
*We hope you found this blog post helpful and informative. If you have any questions, feedback, or require assistance, please contact us *here or complete the form below. To learn more about our Microsoft Intune services, and how we help our clients with their Modern Endpoint Management strategy read more here.****
*Thank you for reading!*
*PrevPreviousDeploying Intune LAPS with a Remediation Script and Protection Policy*NextApril 2024 NewsletterNext*Learn More About Microsoft Intune*Contact our team today to get started with Microsoft Intune or get your questions answered by our experts!**
*The post Block Top-Level Domains with Intune and Windows Firewall Policy appeared first on eGroup Enabling Technologies.*
Deploying Intune LAPS with a Remediation Script and Protection Policy****###### David Bergquist
Senior Cloud Solutions Architect - eGroup Enabling Technologies*Microsoft Intune LAPS (Local Administrator Password Solution) is a feature that allows you to manage the local administrator passwords of your Windows devices enrolled in Intune. It helps you prevent unauthorized access, pass-the-hash attacks, and lateral movement by generating random, complex, and unique passwords for each device. You can also set expiration policies and view the passwords in the Azure portal.***
*However, Intune LAPS requires that your devices have the LAPS agent installed and configured, which can be a challenge for some scenarios. For example, if you have devices that are not domain-joined, or if you have devices that have existing local administrator accounts with custom names or passwords, you may need to perform some additional steps to ensure that Intune LAPS works properly.*
*In this document, we will show you how to deploy Intune LAPS using a remediation script that can handle these scenarios. We will also show you how to use an endpoint security protection policy that leverages app protection to prevent unauthorized access to the LAPS passwords.*
*Table of Contents*Prerequisites* *A Microsoft Intune subscription. * Admin account that has global administrator or Intune administrator permissions. * Windows 10/11 devices enrolled in Intune (Entra ID or hybrid Entra ID joined devices). * A remediation script that can detect and remediate (example provided). + Use of remediations requires Windows license verification to be enabled. Additional info can be found *here.* * An app protection policy that can enforce LAPS passwords (example provided). Steps1. In the Intune Admin Portal, ensure Windows license verification is enabled. To enable Windows license verification, your tenant must have E3/A3 or above licenses. You must be a Global Administrator or an Intune Administrator. * + To enable Windows licenses verification via the Intune Admin portal: - Tenant administration -> Connectors and tokens -> Windows data -> Windows licenses verification: On 2.* Create a remediation script(s) that can detect the existence of the local admin account, and if not, create the account and add it to the local administrators group. The following are examples you can use to detect and remediate:**
**Detect: * $userName = “ADM_ServiceDesk”
$userExists = (Get-LocalUser).Name -Contains $userName
if ($userExists) {
Write-Host “$userName exists”
Exit 0
}
Else {
Write-Host “$userName does not exist.”
Exit 1
}* - *Remediate * $localUser = “ADM_ServiceDesk”
$userExists = (Get-LocalUser).Name -Contains $localUser
if($userExists -eq $false) {
try{
New-LocalUser -Name $localUser -Description “ADM_ServiceDesk Admin Account” -NoPassword
Add-LocalGroupMember -Group “Administrators” -Member $localUser
Exit 0
}
Catch {
Write-error $_
Exit 1
}
}* 3.* Create the Intune remediation script package as follows: (NOTE: I recommend you test this package with some test users and devices prior to rolling out to the masses.)**
*From the Intune Admin portal, go to Endpoint Security -> Manage -> Account Protection:*
*Assign the scope tag(s) if required, then assign the LAPS policy to a group, and save the policy: *5. Verify the deployment and view the passwords. (NOTE: This will take some time for the remediation script to run and the LAPS policy to assign to the device.)****
*PrevPreviousShaping the Future of Technology: Women in IT*NextBlock Top-Level Domains with Intune and Windows Firewall PolicyNext*Learn More About Microsoft Intune*Contact our team today to get started with Microsoft Intune or get your questions answered by our experts!**
*The post Deploying Intune LAPS with a Remediation Script and Protection Policy appeared first on eGroup Enabling Technologies.*
Shaping the Future of Technology: Women in IT****###### Jenn Johnson
Marketing Coordinator - eGroup Enabling Technologies*This March, as we honor the exploration, recognition, and celebrations surrounding the indispensable contributions of women in American history during Women’s History Month, we can’t help but reflect on the role and growth of women in technology.***
**What Does It Mean To Be A “Woman In Technology”?*Currently, about 26% of the technology workforce is made up of women. However, being a woman in tech isn’t simply a woman working in the industry. It entails bridging the gender divide in the technology workforce, dismantling gender-related stereotypes, and fostering innovation within the sector. Despite having a different perspective, a workforce that is more inclusive of gender diversity is advantageous for businesses—particularly in IT.***
*"For me, being a woman in technology goes beyond shattering stereotypes; it's about rewriting the script to make space for everyone. As a practitioner of intentional transformation in the OCM and technology field, I find purpose in creating inclusive environments where diverse voices propel our innovations forward. In this fabulously dynamic and fast-paced industry, we're not just driving progress; we're sparking that 'wow' moment for the next generation."*
*Vallorie Weires - Director of Organizational Change Management*
**Why Is There Such A Big Gender Gap in Technology?*The gender gap in the tech industry begins early—even before women choose their college paths or receive guidance in high school. A mere 16% of women are encouraged to pursue careers in science, technology, engineering, and math (STEM) a stark contrast to the 33% of men receiving similar suggestions. This disparity underscores the urgent need to address the lack of representation, which is important for forming perceptions about identity. Closing this gap necessitates initiatives aimed at cultivating women’s interest in tech or presenting it as a viable career option from the outset of their educational journeys.***
*“Women in technology are breaking through traditional barriers and challenging societal norms. The women in this field contribute to diverse perspectives, nurture both creativity and innovation, and prove that gender should never limit one's ability to thrive. Being a woman in technology extends beyond personal success for me, and I welcome the opportunities and responsibility of knowing that I am also an influential role model for aspiring individuals. At its core, navigating the tech industry as a woman is inspiring because it involves overcoming challenges, contributing unique perspectives, enabling oneself and others, and playing a crucial role in shaping the future of technology.”*
*Christa Anderson - VP of Alliances, Marketing, and Sales Development*
**How Is Gender Diversity In The Tech Industry an Advantage in Business?*Gender diversity breeds innovation by bringing together people with different perspectives, experiences, and problem-solving approaches. This diversity fosters creativity and leads to the development of more effective solutions and products. Not to mention, promoting gender diversity allows companies to access a broader talent pool, enabling the recruitment of the best candidates for positions and thus raising expertise and performance levels.***
*It’s interesting to note that gender-diverse teams tend to make better decisions. Research has shown that diverse groups are more likely to consider a wider range of viewpoints and perspectives, leading to more thoughtful and comprehensive decision-making processes—a feat that is incredibly valuable in the tech world, where complex decisions and strategy shape business outcomes.*
*Embracing gender diversity also contributes to the creation of an inclusive and supportive company culture. When employees feel valued and respected for their unique contributions and perspectives, it results in higher levels of job satisfaction, retention, and overall morale.*
*Businesses generally consider their bottom line first, but as it turns out, companies with diverse workforces tend to be more profitable. Studies show that organizations with higher levels of diversity outperform their less diverse counterparts financially. Gender diversity in the tech industry is not only a matter of equality but also a strategic advantage that can drive innovation, improve decision-making, and ultimately contribute to the success and profitability of companies in the sector.*
*At eGroup Enabling Technologies, we encourage and value a diverse workforce, with people from all backgrounds and cultures. We’re in the business of helping others succeed, and always looking for creative individuals to round out our team of stellar go-getters.*
*What better way to grasp the significance of being a Woman in Technology and its critical role in the field than by hearing from our very own women in technology:*
*"Embracing diversity in a male-dominated industry isn't just about leveling the playing field, it's about recognizing the invaluable contribution of diverse perspectives. In a world where innovation thrives on the convergence of varied viewpoints, fostering an environment where women and all minorities are celebrated and empowered to participate, not only drives progress, but unlocks a whole new spectrum of creativity and innovation that propels industries forward with unparalleled momentum."*
*Carly Picciuto - Director of Marketing*
**What Does The Future Hold For Women In Technology?****
*"Being a woman in tech is about defying stereotypes, not just by showing up, but by speaking up. Our voices matter, not just for us, but for the women we’ll inspire. When women innovate, we don’t just add lines of code or trouble-shoot problems, we elevate what’s possible. Our unique perspectives are shaped by diverse experiences which allow us to see what others might miss. We’re the bridge for a more inclusive culture. Whether it’s in boardrooms or design studios, our presence matters. We’re not just here to fill a quota; we’re here to shape strategy. So, my message to every woman considering a career in technology: You belong here. Your voice matters. Your ideas are essential. Embrace the challenges, celebrate the victories, and know that you’re igniting a more equitable future."*
*Christine Esterling - VP of Solutions and Success*
*In the technology landscape, strategy shapes decisions and action for solutions and desired outcomes. Similarly, we can apply strategy to increasing women’s involvement in the tech industry:*
*By implementing these strategies, we can create more inclusive and diverse industries that harness the full potential of women’s talent and creativity.*
*PrevPreviousListed on CRN’s Tech Elite 250 List*NextDeploying Intune LAPS with a Remediation Script and Protection PolicyNext*Join the Team That Is Shaping The Future of Tech* Interested in joining a team that values inclusive and diverse talent? Fill out the form today!**
*The post Shaping the Future of Technology: Women in IT appeared first on eGroup Enabling Technologies.*
eGroup Enabling Technologies Listed on CRN’s 2024 Tech Elite 250 List
CHARLESTON, SC, March 18, 2024 — Today CRN®, a brand of The Channel Company, announced that eGroup Enabling Technologies has been recognized on its 2024 Tech Elite 250 list.
"CRN’s Tech Elite 250 highlights leading-edge solution providers within the IT landscape, distinguished by their comprehensive technical proficiency, expertise, and commitment to achieving top-level certifications in critical technology areas. These solution providers persistently strengthen their capabilities to bring the advanced IT solutions to market that customers need."
Jennifer Follett - VP of U.S. Content and Executive Editor of CRN at The Channel Company
This yearly compilation showcases solution providers based in the U.S. and Canada that have distinguished themselves by attaining top-tier certifications and specializations from leading technology vendors in the areas of infrastructure, cloud, and security.
To help customers navigate today’s IT complexities and harness the advantages of state-of-the-art solutions, solution providers—ranging from strategic service providers and systems integrators to managed service providers and value-added resellers—strive to uphold rigorous levels of training and certification from strategic IT vendors, often aiming for the pinnacle tiers within these vendors’ partner programs.
The eGroup Enabling Technologies team has 30+ years of experience, and with a portfolio of partners comprised of best-of-breed technologies, their team is able to provide top-tier solutions and services creating joint-success with clients across the nation. Their team of experts holds advanced competencies across their partner technology portfolio including Microsoft Partner Designations in Data and AI, Digital & App Innovation, Infrastructure, Modern Work, and Security. The team holds advanced competency levels with other big-hitters such as Cisco for Networking, and Nutanix for Hyperconverged Infrastructure. Nutanix also releases a prestigious annual list of less than 100 worldwide Nutanix Technology Champions…
"This powerhouse of IT pros is a melting pot of brilliance, spanning every cloud, application and tech realm. Their diverse backgrounds and mastery are the driving force behind innovative solutions that are shaping the hybrid multicloud landscape. These champions aren't just tech wizards, they're mentors, motivators, and community builders."
The eGroup Enabling Technologies team boasts not one, but TWO of these 82 worldwide recipients for 2024!
eGroup Enabling Technologies proudly acknowledges the large number of individuals on the team who hold their own advanced certifications, and individual partner recognitions for going above and beyond, making them a well-rounded group of experts. What sets them apart is their commitment to not only providing the latest technology on the market but also offering comprehensive support and expertise every step of the way. From initial consultation to implementation and ongoing support, eGroup Enabling Technologies’ team of experienced professionals ensures a seamless transition to new IT solutions, making them a true contender as both a trusted and “Tech Elite” partner.
"We are honored to be acknowledged for the 14th consecutive year on CRN's Tech Elite 250 list. This recognition underscores our unwavering commitment to excellence in technology and reaffirms our dedication to innovation, expertise, and our determined quest to deliver best-of-breed solutions to our clients nationwide. We extend our gratitude to CRN for this prestigious acknowledgment and remain steady in our mission to push the boundaries of technological excellence."
Christa Anderson - VP of Alliance, Marketing, and Sales Development at eGroup Enabling Technologies
Coverage of the Tech Elite 250 list will be featured in the April issue of CRN Magazine and online at www.CRN.com/techelite250.
ABOUT eGROUP ENABLING TECHNOLOGIES
eGroup Enabling Technologies, a leading provider of IT solutions and an award-winning MSP, specializes in empowering organizations to leverage technology for business success. With a team of experts and a customer-centric approach, their team offers a wide range of services, including cloud solutions, cybersecurity, collaboration, and managed services.
ABOUT THE CHANNEL COMPANY
The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers, and end users. Backed by more than 40 years of unequaled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. www.thechannelcompany.com
Follow The Channel Company: Twitter, LinkedIn, and Facebook.
© 2024 The Channel Company LLC. CRN is a registered trademark of The Channel Company, LLC. All rights reserved.
The Channel Company Contact:
Kristin DaSilva
The Channel Company
kdasilva@thechannelcompany.com
–List of 2024 Nutanix Technology Champions
Contact our team of experts today to get started on your journey to a more secure organization!
The post Listed on CRN’s Tech Elite 250 List appeared first on eGroup Enabling Technologies.
New Advanced Data, AI, Apps, and Automation Services*eGroup Enabling Technologies, a leading provider of innovative IT solutions and an award-winning Managed Services Provider, announces the launch of its new suite of Data, AI, Apps, and Automation Services. This comprehensive portfolio of offerings has been thoughtfully designed to empower organizations with the tools and technologies needed to accelerate their digital transformation journey and achieve unparalleled efficiency and agility.*
*Today’s business solutions now rely on applications that seamlessly combine trustworthy and ethical AI with robust data infrastructure. As a result, organizations are seeking ways to harness the power of data, artificial intelligence (AI), modern applications, and automation to drive business outcomes and gain a competitive edge. eGroup Enabling Technologies’ new suite of services addresses these needs by delivering advanced solutions tailored to meet organizations where they are with their data and AI initiatives, while also meeting the demands of modern enterprises.*
*Our goal is to empower organizations; by harnessing the power of modern resources and strategic insights to revolutionize business practices and ignite innovation. With our newly launched Data, AI, Apps, and Automation Services, we equip businesses with the essential tools and expert guidance to unleash their data’s full potential, leverage AI-driven insights, modernize applications, and streamline repetitive tasks. Together, we drive efficiency, success, and transformation."*
*Christine Esterling, VP of Solutions & Success*
*Their “EASY” Methodology offers a comprehensive approach to navigating today’s technology landscape:*
**Yielding Results Through Implementations: Transform your designs into reality over tailored sprints, building and deploying a solution to drive efficiency and innovation.* Key components of eGroup Enabling Technologies’ Data, AI, Apps, and Automation Services include:***
**Data Management and Analytics: Unlock valuable insights from your data and make informed decisions with advanced data management and analytics solutions.****
*For more information about eGroup Enabling Technologies’ Data, AI, Apps, and Automation Services, visit *https://www.egroup-us.com/data-ai-apps-automation/****
*PrevPreviousThe Case for Tabletop Exercises in Incident Response Planning*NextListed on CRN’s Tech Elite 250 ListNext*Connect with an expert.*Complete this form to schedule time with our team of experts.**
*The post New* Advanced Data, AI, Apps, & Automation Services appeared first on eGroup Enabling Technologies.**
Improve Your Tenant’s Compliance with Microsoft Purview Compliance Manager The features of Purview that we’ve discussed so far in this series — Content Explorer, Search, Data Loss Prevention, Sensitivity Labeling, and Data Retention—are all foundational tools to help better secure and govern data in your Microsoft 365 tenant. Today, we are going to look at...
The post Improve Your Tenant’s Compliance with Purview Compliance Manager appeared first on eGroup | Enabling Technologies.
Microsoft Disrupts UCaaS Market
Microsoft recently released Pay-As-You-Go Calling Plans for US-based customers. This is a BIG DEAL for organizations whose users don’t make a lot of phone calls.
Pay-As-You-Go plans for Microsoft Teams calling has introduced a new level of flexibility and cost-efficiency. This blog outlines the concept and benefits of these plans.
Overview
The trend towards lower-priced calling plans has been underway for years, with mobile operators setting the bar by offering unlimited calling. However, until now, business plans (whether SIP Trunking or Unified Communications-as-a-Service (UCaaS) pricing) have had a higher bar for minimum monthly spend. Pay-As You-Go plans take a further chunk out of that base expense.
Now, people can be assigned a $3 Per User Per Month (PUPM) calling plan, and then pay $0.03 per minute for every outbound call. For people who make less than 200 minutes (3.33 hours) of calls per month, this is likely a better deal than other MSFT cloud calling options.
Why Pay-As-You-Go?
Until now, Microsoft’s US Calling Plan customers were provided a fixed number of minutes for a fixed monthly fee (i.e. $12 PUPM for 3000 minutes). However, this approach lacked flexibility and failed to cater to users with low call volumes. Large customers would just negotiate big discounts as a result. Pay-As-You-Go plans disrupt this model by allowing all businesses to pay only for the minutes they actually use.
One of the key tenets of cloud services is to pay for what you use. This pricing model ensures that businesses pay for consumption, eliminating overpayment for unused minutes. Pay-As-You-Go plans come with dynamic pricing that considers factors like call destination (local or international), call type (landline or mobile), and the originating country.
Unlimited incoming minutes are still included. In Pay-As-You-Go, no outgoing minutes are included. The outbound rate from US numbers to call US numbers is $0.03 / minute. Calling from US to international numbers varies according to a metered rate card.
To see that rate card, navigate to Microsoft Teams Audio Conferencing | Microsoft Teams and toward the bottom, configure the drop downs as follows (US customers should select US in Step 1). Clicking “Download rates” will provide a .xls which shows the per minute rates.
That rate card shows the origin and the cost to call other destinations. In a pertinent screen shot below, calling from the US to all US prefixes (1+area codes) costs $0.03/minute, while a call from the US to Uruguay would be $1.43/minute.
For people making lots of calls to Uruguay (and the like), selecting a fixed fee plan and adding an international calling plan is a better option.
There are two options for organizations to compensate Microsoft for Pay-as-You-Go.
Communication Credits serve as a virtual calling card from which calling minutes are deducted. This empowers businesses to have full control over their expenses, maintaining a budget that aligns with their communication needs.
Licenses and calling plans are assigned to users based on needs and MSFT 365 ID.
Microsoft provides a Teams PSTN usage report to track recent fees. Reports provide call durations, destinations, and associated costs. This transparency enables organizations to analyze their calling patterns and make informed decisions about their calling plan choices. For instance, if a particular user is consistently over $3/month in Pay-As-You-Go costs, they could be moved to a fixed plan with more minutes.
Ring Central has no such low-entry point, and Zoom advertises Pay-As-You-Go only as a way to pay for services used in excess of the base plans.
Adding Pay-As-You-Go
In the M365 tenant, under billing, Teams Communications Administrators are able to assign users to the Pay-As-You-Go calling plans.
Note the $3 PUPM reference above.
Other Factors
Pay-As-You-Go is but one of many options for making calls to the Public Telephone Network from Microsoft Teams. An organization can mix/match licenses and assign them to different users in the organization.
While it’s likely the best option for people making very few calls per month, there are other factors, including flexibility, ease and consistency of support, and disaster recovery.
The other options are outlined in detail in our past blog, and summarized in the following table.
| Characteristics | Pay-As-You-Go | Direct Routing | Operator Connect | Microsoft Calling Plans | | --- | --- | --- | --- | --- | | Cost | $3 PUPM + per minute usage | Varies based on Telecom Provider | Varies based on Operator (~$6) | Fixed monthly fee (~$12 for 3000 minutes) | | Administrative Overhead | Low | Moderate to High | Low to Moderate | Low | | On-Premises Equipment | None required | Required (to integrate to on-premises systems) | Not required but supported | Not required | | Interop Flexibility | Low | High | Moderate to High | Low | | Disaster Recovery / Resilience | Reliant on Microsoft Cloud | Many options, including Survivable Branch Appliances | Calls can be routed independently of Microsoft Cloud | Reliant on Microsoft Cloud |
Conclusion
eGroup | Enabling Technologies has recently heard from customers who are polling their users and finding in some cases that ~50% of their population do not want or need a business phone number. They’re finding most people are on scheduled conference calls and not making outbound calls.
The introduction of Pay-As-You-Go plans in the USA for Microsoft Teams calling supports this trend. By offering a flexible approach to communication expenses, these plans empower organizations to tailor their communication strategies to their specific needs. Microsoft is leading the way with adaptable, cloud-first solutions.
With Pay-As-You-Go, businesses can now embrace a model that aligns expenses with actual usage, promoting efficiency and control. As remote work, online meetings, and cell phones continue to reshape the way we work, the flexibility and transparency of Pay-As-You-Go plans position Microsoft Teams as a leader in the future of business communication.
Chris SteghCTO and VP of Strategy - eGroup | Enabling Technologies
Learn more about Microsoft Teams Calling OptionsInterested in learning how to migrate your current communications to Microsoft Teams?
Contact our team of experts to get started on the journey of saving time and money!
The post Microsoft Disrupts UCaaS Market appeared first on eGroup | Enabling Technologies.
Purview Data Lifecycle Management: Use Data Retention to Reduce Risk In the past few months, I have discussed the first three foundational elements of Microsoft Purview Compliance: Use Purview Content Explorer searches to identify where sensitive data exists in your tenant, Use Purview Data Loss Prevention (DLP) policies to prevent sensitive data from being shared...
The post Use Data Retention to Reduce Risk appeared first on eGroup | Enabling Technologies.
Summary of Announcements from Redmond A flurry of pricing info, new product innovations, and name changes have been announced in the past two weeks. Here’s a summary and some resources for your research and planning. Microsoft 365 Copilot Commercial pricing for Microsoft 365 Copilot was announced at $30/user/month. No release date information yet. Microsoft joined...
The post Summary of Announcements from Redmond appeared first on eGroup | Enabling Technologies.
A Critical Step to Securing Confidential Data Previously, I have discussed data governance using Microsoft Purview and how Content Explorer and Data Loss Prevention (DLP) are key components to identifying and protecting sensitive data. In this installment, we will review Purview’s Information Protection features, also referred to as Sensitivity Labels. Referring to the diagram below, Information...
The post A Critical Step to Securing Confidential Data appeared first on eGroup | Enabling Technologies.
Preparing for Microsoft 365 Copilot Even if you can’t preview Copilot yet, it’s not too early to start preparing. Microsoft’s “Get started with Microsoft 365 Copilot” blog scratches the surface about what should be done in advance to ensure a successful rollout…. Here, we outline the four main steps that help your initiative be effective...
The post Preparing for Microsoft 365 Copilot appeared first on eGroup | Enabling Technologies.
eGroup | Enabling Technologies Recognized on Channel Futures 2023 MSP 501 List The Tech Industry’s Most Prestigious List of Managed Service Providers Worldwide The Annual MSP 501 List Identifies the Industry’s Best-in-Class Businesses Growing Via Recurring Revenue and Innovation JUNE 30, 2023: eGroup | Enabling Technologies has been named as one of the world’s premier managed...
The post eGroup | Enabling Technologies Recognized on Channel Futures 2023 MSP 501 List appeared first on eGroup | Enabling Technologies.
Easily Collaborate with External Microsoft 365 Users Remember what a nightmare it was for the Griswolds when Cousin Eddie came for a visit? Azure Active Directory (AAD) administrators might feel the same way with the options and headaches that come with managing external identities. The Griswolds were gracious hosts– Directory and data managers can also...
The post Easily Collaborate with External M365 Users appeared first on eGroup | Enabling Technologies.
Purview Data Loss Prevention: The First Step to Data Governance As I discussed in my previous blog, data governance is top of mind in most organizations, as it probably is in yours too. Today I am going to continue covering Purview features that can help you get started with data governance. In this installment: Data...
The post Purview Data Loss Prevention: The First Step to Data Governance appeared first on eGroup | Enabling Technologies.
eGroup | Enabling Technologies Recognized by CRN’s 2023 SP 500 List Charleston, South Carolina, June 14th, 2023 — Today, eGroup | Enabling Technologies announces that CRN®, a brand of The Channel Company, has named eGroup | Enabling to its 2023 Solution Provider 500 list for the ELEVENTH year in a row. CRN’s annual Solution Provider...
The post eGroup | Enabling Technologies Recognized by CRN’s 2023 SP 500 List appeared first on eGroup | Enabling Technologies.
Common FAQs about Microsoft 365 Copilot Greetings, curious AI reader! We hope you find your answer here, but if not, feel free to reach out to us at info@eGroup-us.com and we’ll be happy to share what we know. When will Microsoft 365 Copilot be available? At this writing, Copilot in Microsoft 365 apps like Word...
The post Common FAQs About Microsoft 365 Copilot appeared first on eGroup | Enabling Technologies.
Get To Know Your Data with
Purview Content Explorer
The Challenge
Many organizations have data governance on their minds to some degree. Some are actively working on initiatives to apply retention, data loss prevention, and other controls on the data in their tenant. More often, though, IT organizations struggle with where to start, and how to get their arms around data that is owned by everyone in the organization but them. This is often exacerbated by the lack of effective organizational policies around retention and sensitive data protection.
Even if your organization is not a regulated industry like banking, government, or healthcare, you are almost always going to be subject to some kind of state regulation and disclosure requirements in the event of a breach. Often, you may also be subject to another state or country’s regulations if you do business or have customers there. Data governance challenges apply to every organization that has sensitive data stored somewhere.
To help manage the risk and provide protection, enter Microsoft 365 Purview. This is a great data governance tool, and it has a huge and often overwhelming set of features that will require many blog posts to cover. Today, I am going to focus on how Microsoft Purview Content Explorer can be used to help identify where sensitive data is in your tenant (stored in Exchange Online, SharePoint Online, OneDrive for Business, or Microsoft Teams) and how that information can be used to help provide a starting point to build momentum for a data governance initiative.
Knowing Your Data
Here is one of Microsoft’s diagrams that I like to reference when talking about Purview and what it does. The Know Your Data step is often the most difficult to achieve, since so many data owners exist in most companies.
Content Explorer makes it easy to start to get to know your data and is included as part of E3 and E5 licensing, so you can probably start using it today to see where some kinds of sensitive data are located. It identifies common types of sensitive data automatically based on hundreds of built-in data patterns like Social Security Numbers, bank account information, or driver’s license numbers. Content Explorer also shows you where these data types are located, and you can even drill down to the file or email message that contains it.
By the way, not just anyone can go to your tenant Admin portal and start browsing confidential data. There are specific Azure Active Directory (AAD) and Purview roles that you must explicitly be made a member of to see any actual data beyond the aggregated metrics shown above. Remember that it isn’t always an “IT” person that needs to do this. Access can be delegated to legal, HR or compliance staff to maintain confidentiality.
Most of the time, organizations find that sensitive data is just…well….everywhere. Both where they expect it, like HR files, and where they don’t, like the marketing manager that has 500 social security numbers in a hidden tab in an email attachment about last year’s employee holiday gifts. (Yes, this happens.)
Using What You Discover
Using the out-of-the-box sensitive data types is a great way to start a data governance conversation with management. It shows that there is indeed a lot of sensitive data out there and the organization is at risk of both bad actors or employees being able to exfiltrate data that would require disclosure, incident response costs, and cause a public relations nightmare.
Even in companies where there is no CISO, there is usually a group that worries about business risks and often they can be a good advocate for information security risks as well. It is critical to engage them (often finance, legal, or HR) to be partners in a data governance effort. If it is only led by the technology team it can be very challenging to get people to listen and act.
Following the start of the conversation, the governance team should drive toward the following:
Many of the controls and actions I discuss above are other features of Purview that I will explore in more detail in future blogs. Also, I provide a high-level description of some of those features and how they complement your traditional security controls here.
Using Content Explorer to see what common sensitive data types are detected does provide a great starting point, but it is often just the tip of the iceberg. Purview provides robust searching and customization functionality, in addition to all the pre-configured options. Stay tuned for more discussion on this topic in the coming weeks. In the meantime, if you want to learn more, my colleagues and I help clients with Purview and data governance planning, design, and governance programs all the time. Please reach out if you need some help!
Tom Papahronis Strategic Advisor - eGroup | Enabling Technologies
Learn more about Microsoft PurviewInterested in learning about the features included with Microsoft Purview and how they can simplify your compliance and data governance efforts?
Contact our team of experts today!
The post Get To Know Your Data with Purview Content Explorer appeared first on eGroup | Enabling Technologies.
5 Benefits of Choosing Azure VMware Solution
and Zerto for Disaster Recovery
Disaster recovery is a critical aspect of any organization’s IT infrastructure. Companies that experience unplanned downtime risk significant financial loss, loss of productivity, and damage to their reputation. To ensure business continuity, many organizations use disaster recovery solutions to protect their data and applications in the event of a disaster.
One such solution is the Azure VMware Solution (AVS), which provides an integrated environment for running VMware workloads on Azure. AVS provides you the compute, networking, and storage to be able to supply you with a fully managed Disaster Recovery (DR) site. In addition to AVS, many clients elect to pursue Zerto in addition to AVS. Zerto is a leading replication technology for disaster recovery that simplifies management and reduces complexity in the configuration. In this blog, we will explore the value of combining AVS and Zerto as a disaster recovery environment for an on-premises data center.
What is Azure VMware Solution (AVS)?
Azure VMware Solution (AVS) is a fully managed service that enables organizations to run VMware workloads natively on Azure. With AVS, organizations can use their existing VMware tools and processes to manage and run their applications in Azure. AVS provides a consistent infrastructure across on-premises and cloud environments, making it easier to migrate workloads between the two.
What is Zerto?
Zerto is a leading replication technology for disaster recovery. Zerto replicates data and applications in real-time to a secondary site, enabling organizations to failover quickly in the event of a disaster. Zerto’s continuous data protection ensures that organizations can recover data to the point of failure, minimizing data loss and downtime.
Value of AVS and Zerto for Disaster Recovery
Combining AVS and Zerto provides several benefits as a disaster recovery environment for on-premises data centers:
When implementing Azure VMware Solution and Zerto, eGroup | Enabling Technologies offers professional services to help you implement the solution with speed and certainty. Some of the common pitfalls we help our clients overcome are ensuring we have a shared understanding of the Disaster Recovery need. Beyond that, clients often state the following are their largest challenges for implementing the solution – this is where eGroup | Enabling Technologies can help upskill and deliver success for your team.
eGroup | Enabling Technologies partners with Microsoft and VMware to provide an effective Disaster Recovery Proof of Concept leveraging trial AVS solutions, and Microsoft funded services for qualified customers. Reach out and learn more:
Ensure your business is ready to recover when needed with effective 24×7 managed services for your Azure, Data Center, and DR replication. Including change configuration, monitoring, and managed failover events to ensure your critical applications are up and running when you need them the most.
Combining Azure VMware Solution (AVS) and Zerto as a disaster recovery environment for on-premises data centers provides a valuable solution that simplifies configuration, is scalable and cost-effective, improves RPOs and RTOs, and helps organizations maintain regulatory compliance. With AVS and Zerto, organizations can have peace of mind knowing that their critical applications and services are protected in the event of a disaster. With eGroup | Enabling Technologies, you can have confidence in knowing you have a team of experts available to implement, manage, and support your disaster recovery readiness.
Jason WebsterPrincipal, Mid-Atlantic - eGroup | Enabling Technologies
Learn more about AVS and Zerto for Disaster RecoveryPrepare your environment BEFORE disaster strikes.
Contact our team of experts to get started with AVS and Zerto today!
The post 5 Benefits of Choosing AVS and Zerto for Disaster Recovery appeared first on eGroup | Enabling Technologies.
Migrating from Google Workspace to Exchange Online
Introduction
Google Workspace and Microsoft Exchange Online are two popular productivity suites used by companies worldwide. Both offer a range of collaboration and communication tools, including email, calendars, document editing, and file storage. However, some organizations may choose to migrate from Google Workspace to Exchange Online. In this article I will discuss the reasons why a company might make this move, and some considerations companies should make before migrating. I’ll also talk about some of the different migration tools a company can use and migration velocity.
Reasons to Migrate
There are several reasons why a company may choose to migrate from Google Workspace to Exchange Online. Here are some of the most common reasons:
Migrating from Google Workspace to Exchange Online can provide several benefits. Organizations should carefully evaluate their needs and consider these factors when deciding whether to migrate. It is important to plan the migration carefully and seek expert assistance from a Microsoft partner like eGroup | Enabling Technologies to ensure a successful migration.
Considerations Before Migrating
A large migration from Google Workspaces to Exchange Online can be a complex process that requires careful planning and consideration. Here are some key factors that a company should consider before, during and after a migration:
Migrating to Exchange Online requires careful consideration of several factors, including migration strategy, data security, migration tools, user training, network bandwidth, post-migration support, and budget. By taking these factors into account, companies can ensure a successful migration that meets their organization’s needs and minimizes disruption. It is important to plan the migration carefully and seek expert assistance if necessary.
Migration Tools
Migrating from Google Workspace to Exchange Online can be a complex process, but there are several tools and methods available to help make the transition as smooth as possible. Here are some of the tools commonly used to migrate from Google Workspace to Exchange Online:
Organizations should carefully evaluate their migration needs and choose the tools and methods that best suit their requirements. Whether using free Microsoft tools or third-party solutions, a well-planned migration can ensure a smooth transition to Exchange Online.
Migration Velocity
The speed at which mailboxes can be migrated from Google Workspace to Exchange Online depends on several factors, including the size of the mailbox, the migration method used, and the network bandwidth available. Here are some factors that can affect the speed of mailbox migration:
The speed at which mailboxes can be migrated from Google Workspace to Exchange Online can vary depending on several factors. While some factors, such as the size of the mailbox, may be out of the organization’s control, other factors such as the migration method used and network bandwidth can be optimized to achieve faster migration times. It is important to carefully evaluate the migration tools and methods available and choose the ones that best suit the organization’s needs in terms of speed, complexity, and data security.
Issues To Look Out For
The migration process for the most part is straightforward, however there are things companies need to be aware of when migrating:
While Google Workspace and Exchange Online both offer a range of productivity and collaboration tools, there are several reasons why a company might choose to migrate from Google Workspace to Exchange Online. These reasons include integration with Microsoft products, advanced security features, improved collaboration features, familiarity with Microsoft products, and cost. Ultimately, the decision to switch from one platform to another will depend on the unique needs of the organization and its users.
Carl CarterCloud Solution Architect - eGroup | Enabling Technologies
Learn more about Exchange OnlineInterested in learning how to improve your productivity and collaboration?
Contact our team of experts to get started with Exchange Online!
The post Migrating from Google Workspace to Exchange Online appeared first on eGroup | Enabling Technologies.
Why You Should Back Up Microsoft 365
Before I was a consultant, I spent 20+ years managing all manner of technology groups and functions. Backup was always core to any system decision or implementation just like networking, security, or storage. Most of the time I made sure there was a backup plan before there was an implementation plan. While the technology and media may have changed (and yes, I’m looking at you, DDS-4…), backup was a common requirement that transitioned to virtual machines hosted on-premises in a colocation facility, and servers hosted on Infrastructure-As-A-Service (IaaS) virtualization services like Azure and AWS.
For whatever reason, though, this mindset didn’t seem to follow the data that moved to Software-As-A-Service (SaaS) platforms like Microsoft 365, Salesforce, or Google Workspace. Many organizations moved their data to these platforms and never gave backup a second thought (including yours truly, up until a few years ago). When you consider that the “crown jewels” of most organizations include their files and email, this is simply astonishing.
The reality is that many SaaS providers have fairly limited backup features embedded in their products, and those features are typically focused on short term retrieval of a small amount of data. You may argue that the extent of their infrastructure and internal redundancies make failures that cause data loss extremely rare, and that is true most of the time. However, to have full control of backups and be able to retain and restore backups in the various ways that organizational or compliance requirements dictate, you really do need a backup solution for your Microsoft 365 data. Microsoft 365 and other SaaS platforms typically offer APIs for data backup systems to connect to and use. Also, have a look at the terms of service you agreed to – they usually recommend that you use a third-party backup method. Listed below are some of the many reasons you need a backup solution.
Long-term Backup Retention
M365 Functions: The document versioning, retention and legal hold functions in Microsoft 365 are powerful and useful features, but they aren’t intended to replace the need to back up data. Robust Incident Recovery Capabilities
Cyber insurance policies often require data to be backed up in an immutable format in case of a malware attack. Microsoft 365 does not offer this kind of protection.
Consider Your Requirements
Personally, I have seen third party cloud SaaS backup platforms save the day more than once. A couple of examples:
Neither of the situations above were overall business-threatening incidents, but they would have been costly. The point is that most of the time you will be using a SaaS backup to resolve common issues and help everyone save some angst, time, and money.
I always recommend to clients now that they include Microsoft 365 backup in their disaster recovery plans. It fills a gap and also provides another tool set for the technology team to be able to leverage for daily tasks at a fairly reasonable cost. (And it is most certainly better than DDS-4.)
Tom Papahronis Strategic Advisor - eGroup | Enabling Technologies
Ask the Experts!Interested in discussing your M365 backup plan or your strategy for disaster recovery?
Contact our team of experts to get started!
The post Why You Should Back Up Microsoft 365 appeared first on eGroup | Enabling Technologies.
Improving 911 Calling for Remote Workers
Introduction
The goal of the RAY BAUM Act is to automatically route 911 calls to the appropriate Public Safety Answering Point (PSAP). This requires that the telephone system handling the 911 call be able to determine or ascertain the caller’s accurate current location. Microsoft Teams will determine if a 911 caller’s location includes a valid address, and that the caller has verified the accuracy of that address.
The address provided when a call is made from an on-premises network location always consists of a valid and verified address. Until recently, most locations provided in 911 remote workers calls did not have validated addresses but had verified addresses. Calls with unvalidated and verified addresses will always be pre-screened by a live agent at a clearinghouse before being routed to the appropriate PSAP. This pre-screening increases the amount of time it takes to identify the location appropriate for first responders.
A recent enhancement, referred to as “map search”, to the Teams Windows Desktop client increases the number of locations with valid and verified locations during 911 calls made by Remote Workers. This results in more 911 calls being directly routed to the PSAP rather than being routed through the clearinghouse process and reducing the amount of time it takes to start the first responder’s response.
Background
eGroup | Enabling Technologies has written a whitepaper on Teams Dynamic 911. In this document, the process Microsoft Teams uses to determine the valid and accurate current location of a 911 caller has been explained. It covers how the location is derived for both on-premises and remote Teams users.
When a Teams user dials 911 the call is routed to an Emergency Response Service Provider (ERSP). Microsoft is the ERSP for Calling Plan clients, the vendor, such as NuWave, is the ERSP for Operator Connect customers and Direct Routing clients will have engaged with a 3rd party ERSP, such as Intrado, or will receive the functionality through their SIP trunk provider. The ERSP will route 911 calls directly to the PSAP or to their internal clearinghouse. Microsoft refers to this clearinghouse as the Emergency Call Center (ECC) while the Operator Connect and Direct Routing providers may refer to it as the Emergency Call Response Center (ECRC). If the 911 caller’s provided current location contains a valid address and has been verified for accuracy by the caller, the ERSP’s will route the call directly to the PSAP appropriate for the provided location. In all other cases, the call is routed to the ECC/ECRC.
Calls routed to the ECC/ECRC are answered by a live agent. The agent will confirm that the address provided with the 911 call is the current address of the caller. The agent will use this address to determine the appropriate PSAP. The agent will then do a consultative transfer to the PSAP and hand off the 911 caller. The PSAP will gather additional information from the caller to determine the correct first responders (police, fire, ambulance) to be alerted. The amount of time it takes between when the call is placed and when the first responders are dispatched is longer when the 911 call must be handled by an ECC/ECRC. The implied objective of the RAY BAUM Act is to get the 911 caller to the PSAP as quickly as possible.
Deciding on Routing 911 Calls to the PSAP or the ECC/ECRC
The ERSPs decide on how 911 calls are routed based on two factors:
Once you click the “Save” button, the Emergency Address will be added to the Teams inventory and treated as a “Validated” address. If the automatic address finder cannot find the address, you can turn the “Input address manually” switch and directly add the address. In manual mode you will always have to provide the location’s longitude and latitude. Even when you save a manually input record, it will also be treated as a “Validated” Emergency Address. There is much more detail about creating Emergency Addresses in the whitepaper. Once you have created your organizational Emergency Addresses, their underlying locations can be associated with Location Information System (LIS) objects. Following this logic, the addresses of all locations provided for on-premises 911 callers will always have a validated address.
The current address of a Remote Worker can also be validated. When the Teams client of a remote worker is started, the client will quickly determine that the device is not on an on-premises network. The client will ask the device’s operating system for its current location information. This will usually be provided to the Teams client in the form of a latitude and longitude. The Teams client will pass this information on to Teams and Teams will attempt to provide a valid address. The suggested address will be passed back to the Teams client. The user can confirm that the suggestion is correct, or they can correct it. If they confirm it, the valid address will have been verified by the user. 911 calls from the user will be routed directly to the PSAP. If the user does not confirm the suggestion or corrects it, the suggested address is treated as an unvalidated address. 911 calls would first be routed to the ECC/ECRC.
Address correction form:
Address VerificationFor on-premises users, address verification is implied. The Teams client should always be able to determine the user’s on-premises location. Since Teams automatically provides the current location, the caller’s current location is verified. Calls made from validated and verified locations are always routed directly to the PSAP. Again, tracing the logic: all on-premises locations are both validated and verified therefore, all 911 calls from on-premises locations will be directly routed to the PSAP.
Remote Workers must always verify their current location. They must either confirm a suggested address or correct it. In either case, the caller’s current location is verified. If the caller had confirmed the suggested address, it is both validated and verified. If they neither confirm or correct the suggested address, the user’s current location is neither valid nor verified. Remote Workers should always confirm or correct their current location when starting up their Teams Desktop client.
What Problem Does the New Feature Resolve?
Firstly, the new feature has no impact on the current location of on-premises users. The new “map search” feature addresses the validation of Remote Workers corrected addresses. Prior to its release, corrected Remote Workers current locations could not be determined to be valid. As invalid addresses, 911 calls using these locations would always result in their being routed to the ERSP’s ECC/ECRC.
eGroup | Enabling Technologies personnel are predominantly Remote Workers. There are very few hybrid workers and no full-time on-premises personnel. Based on our own internal analysis, we have found that our Remote Workers get an accurate suggested address for our home office locations from Teams less than 1% of the time. Teams 911 calls from our personnel working from home will almost never go directly to the PSAP. We have noticed that the accuracy of the suggested locations is better when our personnel are working from public locations such as airports, restaurants, client sites, etc.
The new “map search” feature is designed to increase the frequency of validated addresses when a Remote Worker corrects a suggested address. The “map search” feature works very much like the automatic address matching for the Emergency Addresses. As you type in an address, the Teams client will try to match what you typed to valid entries in Azure Maps. When you click on the “Edit” button from the address drop-down in the Teams client, you will see the new input form. You can start to type your correct current address into the “Address” field:
As you type, the client will try to find and suggest possible validated matching addresses:
If the client finds your address, you can click on it then click on the “Confirm” button. Your Teams current location will now have an address that is both validated and verified. The Teams 911 calls of your Remote Workers will now be routed directly to the PSAP. At eGroup | Enabling Technologies with this new feature, we expect that 99% of our Remote Workers current locations will be both valid and verified and that 99% of the time their 911 calls will be routed directly to the PSAP.
Users can still manually enter their address if Teams cannot find a match. Their current locations will have invalid but verified addresses. Their Teams 911 calls will be routed to the ECC/ECRC before delivery to the appropriate PSAP. We already know of a few of our personnel whose home addresses fall into this category.
The Who, What, When, and Where’s of the New “Map Search” Feature
Who? The feature is being rolled out to commercial Microsoft 365 tenants. * Organizations should alert their users to this new feature and amend their Teams training accordingly. What? When a Teams hybrid user or Remote Worker is adding or editing their correct current location, there is a new “map search” box. * As the user types their address into the box, the Teams client will try to suggest a valid address to the user based on Azure Maps. * If the correct address is suggested, the user should select it and confirm the address. * This will result in the Teams user’s 911 calls being routed directly to the PSAP and reducing the overall response time of the first responders. When? The feature appeared in our tenant at the end of March 2023. * It has not appeared in one of our GCC High client’s tenants. Where? Information on which Teams clients are supported is not currently available. It is probably supported on both the Teams Windows and Teams Mac clients. This article will be updated as information becomes available. * Support for the feature is unclear for the Teams Mobile clients and Teams Phones that are not on-premises. * It is not applicable to the Teams clients that do not currently support Teams Dynamic 911: + Teams Web Client. + Teams 3PIP Gateway attached devices. + Teams SIP Gateway attached devices. How?* No how! The feature is automatically enabled for all users who have been assigned an Emergency Calling Policy with the “External location lookup mode” option turned on. Summary
eGroup | Enabling Technologies is available and ready to help with the design, deployment, and configuration of Teams Dynamic 911. If you need help with your Microsoft Teams deployment, please contact us at info@eGroup-us.com.
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
Learn more about Microsoft Teams Dynamics 911Interested in learning how to ensure first responders arrive quickly when making an emergency call?
Contact our team of experts to get started with Teams Dynamics 911 and protect your team from any unnecessary delays!
The post Improving 911 Calling for Remote Workers appeared first on eGroup | Enabling Technologies.
File Sharing: Why You Need To Do It Now!
In today’s digital age, one of the most popular tools for document management is Microsoft SharePoint, a collaborative platform that allows organizations to store, share, and manage their documents in a secure and centralized location. I’d like to discuss the benefits of using SharePoint document libraries over traditional file server shared drives and describe how businesses can derive more value and reduce costs by migrating from file servers to SharePoint document libraries. It’s also worth noting that Microsoft Teams has this capability and might be a good alternative. Choosing between Teams, SharePoint, and even OneDrive will be a different discussion. For now, let’s focus on SharePoint as a direct replacement for file server file shares. Here are several benefits.
You can choose whether you like to use the web interface or sync them to your computer. When syncing to your computer, several more features are easily available. For example, when SharePoint files are synchronized to your computer, you can use Windows Explorer the same way you would for File Server Shares. This familiar experience ensures adoption will be straightforward. An additional benefit to syncing to your computer is that for most users, performance is faster because it’s local.
SharePoint document libraries use version control. When you save a document to a SharePoint library, the system automatically creates a new version of the document each time it is edited or revised. This means that you can always access previous versions of a document, which can be helpful if you need to roll back to an earlier version or compare different versions side by side.
In contrast, traditional file server shared drives typically rely on backup systems to recover lost or deleted files. While backups can be helpful in some cases, they are not as efficient as version control. With backups, you may lose data or changes made between the backup intervals, whereas with version control, you have access to all changes made to the document.
For example, let’s say that your team is working on a document in a SharePoint document library. If a team member accidentally deletes a section of the document, they can easily restore the deleted content by accessing a previous version of the document. This can save time and prevent frustration by eliminating the need to recreate lost work or restore data from a backup.
Additionally, the restore method typically requires a ticket to the help desk and a technology team member to recover the file. This can take much more time than expected. Hours at best, days at worst. This is not the case with SharePoint versioning. By simply right clicking on the file, the authors can select the version they want instantly.
SharePoint document libraries do not require a VPN connection to access documents from anywhere. This is because SharePoint is a web-based platform that can be accessed from any device with an internet connection. This makes it easier for employees to access their documents from anywhere, without having to worry about VPN connections or security issues. This is even easier if you are synchronizing the documents down to your computer.
Imagine that you are on a business trip and need to access an important document from your hotel room. Since the document is already synchronized on your computer, you can edit it as needed with or without a basic internet connection. If you are disconnected, once you reestablish your connections, all your changes will automatically be synchronized back to the SharePoint library. This can save time and increase productivity by allowing you to access your documents from anywhere without having to worry about network limitations.
If you are still using file servers, you can only access your shared files remotely when connected over some type of VPN or virtual desktop. This can be inconvenient if you need to work from a location without a connection – like on an airplane or in a secured location.
Another benefit of SharePoint document libraries is the ability to share documents with a group of people, without having to email the document to each person individually. When you share a document through SharePoint, you can set permissions to control who can view or edit the document, and you can also track who has accessed the document and when.
For example, imagine that you are working on a project with a team of coworkers. Instead of emailing the project plan to your team members, you can simply email the file as a link rather than attachment. Each person can edit the single document at their convenience. All the changes are captured in the original document directly by each person. This also avoids the work and confusion needed by the old way when coworkers emailing you back various versions and you try to consolidate those edits back into the original document. Consider if you must do this more than once! This can be a version control nightmare.
Autosave is a feature in SharePoint that automatically saves changes made to a document in real-time. This means that you don’t have to worry about manually saving your work, and you can be sure that all changes are saved and up to date. Autosave also ensures that you won’t lose any work due to unexpected system crashes or power outages.
For example, imagine that you are working on a document using SharePoint and your computer suddenly shuts down due to a power outage. With autosave, you can be confident that all your changes will be saved and that you won’t lose any work. This can save time and prevent frustration by eliminating the need to recreate lost work. This is even further enhanced if you lose your connection while working on a synchronized SharePoint document. As far as the document goes, you can continue to make edits and once you reconnect, all the changes are saved back to SharePoint.
In contrast, traditional file server shared drives typically require you to manually save your work, which can be time-consuming and can lead to lost work if you forget to save before a system crash, power outage, or disconnection.
Co-authoring is a powerful feature of SharePoint that allows multiple people to work on the same document at the same time. With co-authoring, you can see who else is working on a document and can view their changes in real-time. This can be especially helpful for collaborative projects or documents that require input from multiple people.
For example, imagine that you are working on a project proposal in a SharePoint document library with a team of coworkers. With co-authoring, you can all work on the same document simultaneously and see each other’s changes in real-time. This can save time and increase productivity by allowing you to collaborate more efficiently and avoid version control issues.
Here’s a real-world example. The organization I was working for experienced a significant system outage. A message needed to go out to staff to inform them of what happened and what could be done to work around the problem. I asked several people on my team including engineers and others skilled in messaging to help draft this message. We coauthored a document in real time in just a few minutes. Once it was drafted, I was able to easily copy it into a message and help staff avoid any loss of productivity.
Traditional file server shared drives typically require you to work on a document one person at a time, which can be time-consuming and can lead to version control issues if multiple people need to work on a document. Others must wait until the current editor is finished and closes the document.
SharePoint document libraries are already included in most Microsoft licensing packages, making it an affordable and accessible option for businesses of all sizes. This means that you do not have to purchase any additional software or licenses to use SharePoint, which can save your business money in the long run.
Finally, SharePoint Online infrastructure is included in the cost of most licenses. If you are still using file servers shared drives, you typically need file servers or storage units to provide the capability. Consider the cost of those solutions including initial deployments, upgrades, updates, datacenter space, heating and cooling, and administrative overhead. All these costs can be eliminated by using SharePoint Online.
In conclusion, SharePoint document libraries offer several benefits over traditional file server shared drives, including version control, document syncing, remote access without VPN, easy document sharing, and affordability. If your business is looking for a secure and efficient way to manage its documents, SharePoint is definitely worth considering.
Connect with Us!
If you are a Microsoft 365 customer and you are not aware of these capabilities, eGroup | Enabling Technologies welcomes the opportunity to have a conversation with you to enlighten you regarding Microsoft 365 capabilities and how these capabilities can help you ensure you have implemented CIS Critical Security Controls and document proof of compliance.
Contact our experts at info@eGroup-us.com to learn more today!
John BerarStrategic Advisor - eGroup | Enabling Technologies
The post File Sharing: Why You Need To Do It Now! appeared first on eGroup | Enabling Technologies.
CIS Security Controls and Compliance
Cybersecurity is a persistent worry for CIO’s, CISO’s, Board of Directors and organizational leaders. CIO’s and CISO’s specifically are expected to provide leadership and direction to their IT staff and their broader organization to strengthen cybersecurity postures.
Where To Begin
One question I have been asked by clients is, “where do I start?” Many organizations must comply with specific regulations such as PII (Personal Identifiable Information), HIPAA, etc. There are numerous standards and frameworks publicly available to demonstrate good security hygiene practices, data protection and general data governance. Some of the best known are NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) and ISO (International Organization for Standardization), as well as from FedRAMP (Federal Risk and Authorization Management Program) and more recently, GDPR (General Data Protection Regulation of the European Union) and CMMC.
I recommend organizations should begin their improvements by adopting the Center for Internet Security (CIS) Critical Security Controls. If the organization has no specific business mandate to meet one or more of the above regulations, then it’s unlikely that the IT team will realistically attain and maintain such stringent standards. Such organizations not having specific requirements and mandates will find a happy medium in the CIS Critical Security Controls. The CIS Controls are a simplified set of best practices developed collaboratively by a global community of thousands of cybersecurity practitioners.
The Benefit of CIS Controls
There are many reasons and benefits to incentivize organizations to adopt the CIS Controls. Most importantly, is improving one’s security posture based on the experience of the community of cybersecurity experts. Beyond this primary benefit, CIS Controls provides an objective way to track progress and to identify current risks. The documentation on your organization’s progress will be valuable to assist with internal and external audit procedures. Having the ability to provide this level of documentation to Cyber Insurance underwriters could potentially result in lowering insurance premiums.
CIS Controls are not a replacement for other frameworks. The CIS Controls map to most major compliance frameworks such as the NIST Cybersecurity Framework, NIST 800-53, ISO 27000 series and regulations such as PCI DSS, HIPAA, NERC CIP, and FISMA. Mappings from the CIS Controls have been defined from these other frameworks to give a starting point for action. More specifically, CIS Controls has been recognized as a comprehensive onramp for complying with NIST cybersecurity standards. The CIS provides an amazing tool (CIS Critical Security Controls Navigator) that cross-references the CIS Controls to twenty-seven other frameworks and regulations. The Navigator easily demonstrates where the CIS Controls maps to one of the other frameworks and regulations controls.
The 153 Critical Security Controls Safeguards are prioritized and are a very prescriptive set of actions. These actions are a great starting point for organizations on a mission to improve their cyber defenses. CIS has organized these controls into three (3) Implementation Groups (IGs).
I recommend organizations should begin their improvements by adopting the Center for Internet Security Critical Security Controls. It is my opinion that CIO’s and CISO’s should strongly focus on and comply with at least IG1 and IG2 of the CIS Critical Security Controls to ensure they are protecting their organizations with best practices security hygiene and controls.
All organizations absolutely should implement the 56 IG1 safeguards. These are the fundamentals for good cyber prevention. After getting these basics done, most organizations should venture to review and implement the additional 74 safeguards included in IG2.
How To Document Compliance with Controls
Documenting controls and regulations compliance is painstaking. I have seen organizations utilize spreadsheets and documents to track and demonstrate their compliance. It works, but this methodology is difficult to maintain. My organization has experience utilizing Microsoft Purview – Compliance Manager to perform compliance assessments. A recent example, eGroup | Enabling Technologies was engaged by a large university hospital system. We were tasked to assist them to ensure their large Microsoft 365 tenant was HIPAA compliant. Rather than manual efforts and typical risk assessment time and research, our consultant utilized Compliance Manager within their tenant and checked for specific gaps utilizing the HIPPA assessment template offered by Microsoft. Compliance Manager provided a comprehensive report of “Improvement Actions” which was used by the customer to guide them towards resolution with a prioritized list.
Compliance Manager provides great value to perform regulatory and compliance assessments. Organizations which have M365 subscriptions have access to Compliance Manager. Those that have E5/A5 subscriptions have access to the full suite of Purview capabilities. Compliance Manager is a source of documenting organizations’ compliance and assigning responsibilities for specific safeguards and controls.
Connect with Us!
If you are a M365 customer and you are not aware of these capabilities, eGroup | Enabling Technologies welcomes the opportunity to have a conversation with you to enlighten you regarding Microsoft Purview – Compliance Manager capabilities and how it can aid you to ensure you have implemented CIS Critical Security Controls and document proof of compliance. Contact our experts at info@eGroup-us.com to learn more today!
Bill SmithStrategic Advisor - eGroup | Enabling Technologies
The post CIS Security Controls and Compliance appeared first on eGroup | Enabling Technologies.
eGroup | Enabling Technologies Recognized by
CRN’s Tech Elite 250 List for 13th Year
eGroup | Enabling Technologies Honored on the 2023 CRN’s Tech Elite 250 List
"CRN’s Tech Elite 250 list features the leading solution providers in the IT channel with the most in-depth technical knowledge, expertise, and certifications for providing the highest level of service for their customers. These solution providers have continued to extend their aptitudes and abilities across various technologies and IT practices, demonstrating their commitment and value to their customers."
Blaine Raddon - CEO of The Channel Company
March 23rd, 2023 —
eGroup | Enabling Technologies announces that CRN, a brand of The Channel Company, has honored eGroup | Enabling on its 2023 Tech Elite 250 list.
This annual list features solution providers of all sizes across the U.S and Canada that have differentiated themselves by achieving the highest level and largest breadth of certifications and specializations from key technology vendors in the infrastructure, cloud, and security spaces.
Businesses rely on solution providers to maintain the highest levels of technical prowess across critical products and services to help them meet today’s IT challenges and take advantage of the benefits of cutting-edge solutions. To meet these demands, solution providers such as strategic service providers, systems integrators, managed service providers and value-added resellers strive to maintain high levels of training and certification from IT vendors and achieve the highest tiers within those vendors’ partner programs.
eGroup | Enabling Technologies delivers speed and certainty to clients, enhancing the digital transformation journey.
Signing up for Cloud Services can be simple, but securing, managing, and ensuring adoption can be hard.
eGroup | Enabling Technologies has helped organizations optimize their IT investments for over 20 years. Their expertise is in improving workflow, modernizing data centers, and meeting customers where they are with hybrid cloud solutions, consulting, and managed services.
Their team of experts will make your cloud journey more productive, more secure, and as simple as it should be.
"eGroup | Enabling Technologies is excited to be recognized once again as part of the CRN Tech Elite 250 list. Providing speed and certainty for our customers with their technology initiatives has allowed us to quickly and accurately support them in achieving their desired outcomes. We partner with key vendors such as Microsoft, Nutanix, and Cisco to produce innovative solutions that are driving us and our customers into the future."
Ben Gaddy - Principal, Operations at eGroup | Enabling Technologies
ABOUT eGROUP | ENABLING TECHNOLOGIES
With over 20 years of experience and a comprehensive cloud and data center solutions portfolio, eGroup | Enabling Technologies delivers outstanding results for customers across the nation. eGroup | Enabling takes pride in delivering white-glove service to all clients and is proud to showcase that in a YoY 100% Customer Satisfaction Score. By aligning client needs with exceptional solutions, services, and support, eGroup | Enabling makes businesses more productive, efficient, and competitive.
ABOUT THE CHANNEL COMPANY
The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers, and end users. Backed by more than 40 years of unequalled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. www.thechannelcompany.com
Follow The Channel Company: Twitter, LinkedIn, and Facebook.
© 2023 The Channel Company LLC. CRN is a registered trademark of The Channel Company, LLC. All rights reserved.
The post eGroup Awarded CRN’s Tech Elite 250 For 13th Year appeared first on eGroup | Enabling Technologies.
Copilot Coming to Microsoft 365
By now you’ve seen the previews of Microsoft’s unique capabilities using large language models within Microsoft 365 Apps like PowerPoint and Excel. Known as Copilot, it’s generating a lot of buzz amongst fans and critics. This blog summarizes some of the more subtle advantages of the technology, timelines of when you might see the capabilities, how it works, and how you can thoughtfully prepare to take prudent advantage of it.
When Can You Try It?
Unless you were fortunate to be one of the handful of private preview invitees, you’ll have to wait several months for this technology to be in your tenant. Typical Microsoft timelines vary but three to six months would be a minimum for this to start to go into broader private preview, followed by public preview, where the masses will start to see it. Make sure your tenant admins are part of the Office Insider program. There are also admin capabilities that control preview features for users. For instance, in Teams, it’s now more foolproof to enable users for Microsoft Teams Public Preview before new versions roll out to the rest of the company. There, Microsoft is adding a new value named ‘Forced’ for this to move users to Public Preview without them having users opt-in.
Licensing and pricing are not being disclosed at this time, but from experience, anytime Microsoft augments existing tooling with AI/automation, it will require an incremental investment.
At this time, there is no plan of record for Copilot within education or government tenants.
Unique Capabilities Draw from Multiple Apps
It would be simple enough to say Copilot will bring ChatGPT type capabilities to Office, reducing writer’s block by allowing users to ask to “Draft a proposal” or “Start a presentation” about certain topics. However, its real strength appears to be in connecting and extracting data from existing apps and data within M365.
For instance, Copilot can connect to customer notes from OneNote and other internal documents, drawing data out of these documents to create a first draft. See how the “create based on” calls upon a customer OneNote. This is a major time saver to create a draft without copying/pasting.
Then, to quickly ensure consistency, you can ask Copilot to reformat the draft into a document template that you’ve used in prior documents.
The time savings of both steps are immense productivity enhancements.
As another example, a PowerPoint presentation can be drafted from a Word document! Writing once, reusing everywhere without copying/pasting will be a major productivity boost.
Then, drawing on some advancements in the existing “Design Ideas” feature, you can simply tell Copilot to add animations, additional slides (i.e. “Add a slide about cost/benefits”) and even speaker notes.
For those of us who are using 1% of the features of Excel, there are some solid Copilot capabilities that can help. Using common language, you can ask Copilot to create graphs that help visualize trends, apply colors to the tables to highlight certain data, and model future projections.
Since important decisions may be made from this data, the output should be well understood. You can ask Copilot for an explanation of how it derived some of its inferences, and it will provide a breakdown.
There are several Outlook / email enhancements too, like highlighting and summarizing the most important emails, and allowing you to draft emails with connected data from OneDrive and Excel, etc. You can even change the tone of the email language.
Power Apps Copilot is previewing, purporting to enable some natural language control to “build an app, including the data behind it, just by describing what you need through multiple steps of conversation.” Based on past experience, this will take much more time to mature.
Finally, Copilot in Teams can help in real-time, as shown below. In this case, a participant arrives late to the meeting. The transcript is humming along in real-time, allowing the participant to recap key points so far, and then dive deeper into the points that they’ve missed. You can ask Copilot what a good question to ask would be (and of whom), check for sentiment of comments, and list action items.
Overall, you’ll start to see helpful tools that you can use natural language to control throughout the M365 experience. The connected fabric of files, notes, and messaging services within Microsoft 365, combined with the ChatGPT learning model, makes it extremely powerful.
How Does It Work?
The Copilot System is made of three components:
Users initiate the process while within the M365 App they’re using, as shown on the top left. The Copilot Systems pre-processes that request and then relays it to the Graph to “ground” it.
“Grounding” is an important step to produce relevant output. Grounding happens automatically and improves the quality of the prompt before it’s sent to the LLM. That allows the LLM to provide answers that are more relevant and actionable.
Now, the LLM can now draw on real-time sources of relevant data and provide better output as a result. Think of ChatGPT drawing data not just from its own data sources, but from your OneDrive, or your company’s data. Contextual, relevant content will expedite the completion of your tasks.
Copilot takes the response from the LLM and “post-processes” it, where it does additional grounding in conjunction with the graph. It’s here where security, compliance, privacy, and “responsible AI” reviews will be conducted. Here’s where you can expect to employ individual organizational controls (i.e. see below about Data Loss Prevention).
Finally, Copilot sends the response to the user and commands back to the apps (i.e. pulling in data from a Word doc from the graph and creates a new PowerPoint based on that doc).
Preparing for AI Within Microsoft 365
While it appears these capabilities are coming out of nowhere, the tooling won’t appear in your tenant without your knowing it. Admins (and licensing) can stand in the way of the tools showing up for users. Here are some important steps to take in advance. For instance, the Power Apps Copilot can be disabled.
-Start EducatingWorkers will be skeptical and scared – and legitimately so. It’s been said “At work, you will be telling a machine what to do, or a machine will be telling you what to do” (Alec Ross, The Raging 2000s). Help them understand that these tools can be a competitive advantage, if used wisely. They’re used to enhance or speed up, and not replace creativity.
-Set ExpectationsPeople need to know that AI models can be wrong and should be countered with human reasoning. This should be our behavior for many years, and for many, forever.
Note the use of the word “Draft” several times above. It should be expected that the information drawn from the Graph may be off-base (see the “Keep It” and “Regenerate” options below the PowerPoint slide in a previous image shared above). In its launch, Microsoft’s CVP Jared Spataro said AI “can be usefully wrong.”
-Protect Your DataThe data in your tenant stays within your tenant and isn’t sent or shared with the LLM for training, for others to use or see. Early FAQs like that are answered here: Administration of Microsoft 365 in the new era of AI .
However, it will become more crucial to protect confidential and proprietary information within your Microsoft 365 ecosystem from unexpected (internal exposure). In the future, without the employee needing to even look around for data they need, Copilot may just search SharePoint and offer to import or use key data. This may end up overexposing confidential data. Ensure your privileges are managed well and your data is protected using Microsoft Purview. This is not a trivial investment of time and effort, so take steps to define, inventory, and protect confidential data now, before the AI crawlers become even easier to expose this data.
Summary
The velocity at which Microsoft is embedding AI and LLM into products and services is a testament to how useful the technology is, and also how quickly it is being improved. Seeing a few NDA demos, it’s not vaporware. The sky’s the limit with how this can help an organization, and it’ll happen soon.
One can debate how well Microsoft’s Responsible AI principles will counter the competitive benefits this technology may provide them. However, one shouldn’t debate the importance of protecting confidential information, and educating users. The workforce needs to be prepared to effectively use the technology for competitive advantage, helping them understand how to move their career forward, rather than be threatened, in the presence of such game-changing tools.
Contact our team of experts with any questions you may have about these changes coming to Microsoft 365 by emailing info@eGroup-us.com.
Chris SteghCTO & VP of Strategy - eGroup | Enabling Technologies
The post Copilot Coming to Microsoft 365 appeared first on eGroup | Enabling Technologies.
How Government Institutions Can
Manage Cyber Insurance Increases
Growing trends and recent news have shocked the cyber insurance system. With cost and coverage changes, government institutions are simply seeking to attain reasonably affordable cyber insurance. This blog summarizes a spirited debate amongst subject matter experts on the topic in January 2023. Contributors include a former .gov insurance negotiator, Mehran Basiratmand, a cyber insurer, Doug Schulkin, and cyber security expert David Branscome.
The trends and shocks include:
Each topic is explored by our experts in turn below.
Managing Rising Rates
Cyber insurance rates increased 28% in Q4 2022 and 48% in Q3 in the USA (Marsh). While some correction is expected as new entrants to the market increase capacity, insurers will continue to hike rates until attacks subside and organizations adequately improve defense and detection.
To keep rates in check, experts advise to
Insurance industry executive Schulkin advises to communicate early and often, first during broker negotiations and then, once the policy is active. “Cyber insurance is not a lot like other insurance,” Doug began. “There’s high incentive to report all the time,” which defies the stigma of a demerit system where customers opening too many claims are dropped or see rates spike. “In fact, it’s quite the opposite,” he continued. “Good underwriters and carriers look at that situation and say, ‘OK, these people are very cognizant, they’re very aware of their data risk management,’ and note in their file to make sure that they don’t lose them as a customer.”
Basiratmand agrees that strong communication with a broker is part of a four pronged approach, with a strong internal team (or Managed Security Services Provider) handling Extended Detection and Response (XDR) as the second leg. Continuous improvement, often involving a third-party health check of security posture, is a third pillar. “Your staff are wonderful,” he said, “but they are only going to report what they can report, so getting a third-party company to come in that basically has no skin in the game has been extremely valuable.” Finally, the insurance broker itself rounds out the four important aspects.
Speaking of health checks, Branscome asserts that Microsoft tools embedded in Microsoft 365 and Azure Secure Score will call out much of what a cyber insurer will look at. “It’s going to look at MFA, it’s going to look at privileged access management, things like that, so you can use these free tools and start on that journey before you decide about cyber insurance.”
Doug stressed David’s point for organizations make a plan to inform the financial decision about insurance. “The first step in this process is to make yourself safe, with good cyber hygiene,” he began. He advises using the resources of insurance brokers, cyber lawyers, and technical companies to help. “Then, once you assess how vulnerable you are,” Doug continued, “you can compare the risk you’re willing to take against your budget.” Making an insurance purchase without knowing your relative risk is backwards.
Managing Stricter Requirements
As risks evolve, so do insurers’ requirements. Schulkin debunked a major myth. “MFA isn’t the silver bullet everyone thinks it is. It is still a very good mitigation tool and a great benchmark for insurance carriers to see how safe you are.” To that end, some carriers are asking questions about MFA in very specific situations, rather than a single catchall question of ‘Do you use MFA?’
Doug continued to explain the thought process and importance of the cyber insurance questionnaire. “Insurers evaluate single question quite carefully and they go into an equation. It’s mostly science, a little bit of art, on the part of insurance carriers.” He stresses that “When you fill these out and C-level signs off, you are saying ‘If we ever have to go to court, I’m promising that these things are in place.’ Insurance carriers have every right to deny payment if it’s wrong.’”
He admits, “That sounds bad, but it’s not, if you just take the time with your insurance broker and take the questions seriously.” He also advises to be honest about your gaps. “People feel they need to be perfect, but there’s no such thing as perfect, and at some point you have to take a risk.”
Factoring Nation State Risks
Lloyd’s of London is the most public cyber insurer to begin “excluding liability for losses arising from any state-backed cyber-attack.” Assessing the likely ramifications requires a look back before looking forward.
Think back to the SolarWinds supply chain attack, attributed to Russia after many months of deliberation. Would the recoveries of the approximately 18,000 affected public and private sector customers have been covered? Add to that Russia’s creation and widespread damage of NotPetya in 2017, the largest cyber incident in history at $10B in damages. Would NotPetya’s drive-by victims outside of Ukraine (like Maersk, Merck, state hospitals, etc.) have been covered?
Looking forward, the litigation around this blurred line is likely to be thick. Attribution to state actors has been slow if nonexistent. Insurers who are asked to make payments immediately may delay payments and require further proof.
As a result, some organizations are electing to self-insure. According to Branscome, “There has been a push by some cyber insurers to get people to self-insure to a certain degree. In other words, they’ll pay out, but only up to a certain level, which would help reduce the premiums that customers must pay.”
A recent government CIO told the author that if his organization were to take the necessary actions to comply with the insurer’s requirements, it’d take millions of dollars, and yet their rate would still increase $1M/year, with a $2M deductible. Putting away a multimillion-dollar slush fund for a safety net is becoming more a palatable alternative for some.
Big Data Illustrates Trending Vectors
What’s likely to happen next? While at a macro level, phishing and identity compromise are still the number one vector, a few trends are on the rise of note. The charts that follow are from metadata from Chubb’s Cyber Claims in the past three years, couple with commentary from the experts.
This first visual shows what instigated most of Chubb’s claims in the last three years (ending in 2022).
You can see the “people problem” is growing, with social engineering at 30% and a 5% growth. This is more than just Nigerian Prince phishing campaigns. Last year there were a few employees of, in some cases, large notable IT organizations, who were recruited on social media and eventually willingly gave up their credentials for money. In some cases, they even approved the MFA prompt when the malicious actor logged in.
Such LAPSUS$ extortion campaigns clearly bypassed existing edge or front-end technologies like MFA. This reinforced the necessity of a defense in depth strategy, including a focus on insider threats and monitoring end user behavior.
The idea of enforcing MFA with conditional access adds another layer to a well-protected environment. If logins are only permitted to legitimate credentials coming from legitimate, trusted machines, they could be provided with trusted access. Then, even if a willing employee approved a bad actor’s MFA prompt, unless the actor also had the willing employee’s machine, the login would’ve been blocked.
Conditional Access with device compliance similarly solves the rising “Adversary in the Middle Attack,” noted in a prior blog.
Chubb’s next pie chart shows what kind of actors were the source of their claims, and of note here is a growth in partner attacks.
In part, this rise comes from supply chain software attacks like SolarWinds, Kaseya, and ManageEngine. But it also comes from adversaries hopping from managed services’ provider networks into their downstream customers. That is because providers with access to multiple downstream customers’ systems are bigger targets.
In the wrong way, the average hacker isn’t going after mom and pop anymore. They’re going after the sources of many other downstream victims.
Branscome pointed out that “Gartner predicts that by 2025, 45% of organizations worldwide will have experienced attacks on their software supply chains” (a three-fold increase from 2021). He followed by advising that organizations factor in their vendors’ security practices during the IT procurement stages.
Finally, Chubb reported on the assets that are most often targeted in incidents. Servers are way up at 5% here, the network is up a bit at 2%, and the people are the target in some cases.
Basiratmand predicted that servers attacked by human-operated ransomware attacks will grow because “There’s still a large number of organizations that have not improved their security posture to the level that is required. It’s surprising to see how many organizations truly have not fully taken advantage of the tool set that is readily available at their disposal. Sometimes it’s funding, sometimes it’s the staffing. Attacks will continue because the bad actor doesn’t have to have a high level of his skill set to deploy ransomware, and there’s a large number of organizations that are still truly vulnerable.”
Schulkin agreed and noted that “The movement towards individuals (people) is interesting. I kind of view those as catastrophic. If an adversary is going do something like that, that person isn’t going to be a low-value target, and that attack isn’t going to be a little one.”
Tips for Making a Risk-based Decision:
eGroup | Enabling Technologies has a set of services that can help organizations prepare for, react to, and remediate cyber insurance and technical initiatives, including MSSP and professional cybersecurity services. Contact our team of award-winning experts today to get started on your MSSP journey or check out our website to learn more about how we can manage your environment from end to end.
Chris SteghCTO & VP of Strategy - eGroup | Enabling Technologies
The post How Government Institutions Can Manage Cyber Insurance Increases appeared first on eGroup | Enabling Technologies.
Managed Security Services Improve Security & Your Team’s Value
The Power of MSSPs
When I was leading technology organizations, one of the most critical and valuable partner vendor relationships was with our managed security service provider (MSSP). They served in three capacities:
Our internal team always remained the point of escalation, but 95% of the time alerts and incidents were primaily handled and closed by the MSSP team.
While this certainly helped us sleep better at night, the MSSP also provided a wealth of knowledge and operational clarity to our ongoing security practices. They would monitor changes to our Microsoft 365 and Azure secure scores, proactively hunt for threat indicators within our environment, and be a resource for us in all things security, including advice on how to best onboard and secure new services or technologies.
The fact is that small and medium-sized businesses (less than a few thousand employees) are almost never in a position to afford a dedicated, experienced, around-the-clock security team. Using an existing team member or tacking security on as a secondary responsibility for existing staff is not a realistic or effective approach for something this important.
After engaging an MSSP, the business and the technology team saw benefits in a few areas:
Risk Reduction You benefit from using a third party that has other clients. An MSSP will have a far larger set of diverse experiences and develop better practices than an internal team. They are able to leverage what they learn from all their clients to the benefit of all the others. An in-house team will only see much narrower field of attacks, so their perspective can be limited. * The vendor had time to do proactive threat hunting. An internal team may struggle to prioritize this, and similar to the point above, they may not be as effective at it without a diversity of experience. * The vendor had time and expertise to tune rule sets and automation. Security response isn’t just about buying some licensing and acting on alerts. Calendar time is needed to configure tools, tune, and effectively continue building security service maturity. * The vendor produced regular reporting, metrics, and provided a structured review process. It made it easier for the internal team to understand what was happening so we could make better decisions. * You have a partner to identify trends, alternatives, and approaches as threats evolve or internal systems change. That also applies to all the improvements and changes that vendors like Microsoft make to their security products and services so you can take advantage of them more quickly. Financial Efficiency The people with the specialized knowledge and experience required to effectively secure and monitor the computing environment are expensive and hard to find. * Hiring and managing for active 24×7 monitoring increases the already high staffing costs by 3-4 times. * Cyberinsurance rates are far easier to keep in check with an MSSP as part of the information security program. * The MSSP had predictable costs and drove continuous risk reduction. That allowed us to avoid the bursts of reactive panic or incident response spending that would be required if we didn’t have a vendor with time dedicated to helping keep us secure. * The MSSP vendor was flexible and able to pivot their services as our needs changed. That is far more difficult and expensive (and time consuming) to do internally. Sometimes staffing changes or advanced training need to be executed on quickly. The vendor had designed themselves to be able to do that. Improved Internal Team Focus Our MSSP offloaded and filtered the security noise from the internal team. Internal staff could then focus on serving the company’s goals and initiatives more fully. Completing projects and service delivery were much improved because the only time spent on security was for true (and fairly rare) event escalations. I can’t overstate how much of a positive impact this made in the internal team’s effectiveness. * Employee satisfaction was improved.* The people in IT operations, networking, service desk, and other disciplines were no longer dragged into security tasks that they did not have expertise in, but felt like they needed to own anyway. Prior to engaging an MSSP, staff (myself included) always felt obligated to jump on security issues first, which would make all the other work overdue. This definitely caused anxiety and increased stress. Advice and Other Considerations
The reality is that many Technology groups (and their budgets) are going to have a difficult time effectively self-managing their security. I found that using a third-party MSSP is more affordable, more effective, and more scalable. Given the current prevalence of malware, ransomware, data exfiltration, and other malicious activity, security management is far too important to be lost in the shuffle in a busy person’s inbox. Security incidents and ongoing monitoring require immediate response and mitigation. Anything less puts your organization at significant risk, and there are readily available services to not only take much of the burden off the technology team’s shoulders but also more effectively prevent incidents in the first place.
Contact our team of award-winning experts today to get started on your MSSP journey or check out our website to learn more about how we can manage your environment from end to end.
Tom Papahronis Strategic Advisor - eGroup | Enabling Technologies
The post Managed Security Services Improve Security & Your Team’s Value appeared first on eGroup | Enabling Technologies.
eGroup Recognized by
CRN’s MSP 500 List for 7th Year
eGroup Recognized on CRN’s 2023 MSP 500 List
"Managed services offer a path for businesses of all sizes to remain efficient and flexible as they grow. The solution providers on our 2023 MSP 500 list are bringing innovative managed services portfolios to market, helping their customers win by doing more with the IT budgets they have and freeing up resources to focus on mission-critical activities to drive future success."
Blaine Raddon - CEO of The Channel Company
eGroup announces that CRN® a brand of The Channel Company, has named eGroup to its Managed Service Provider (MSP) 500 list in the Pioneer 250 category for 2023. CRN’s annual MSP 500 list identifies the leading service providers in North America whose forward-thinking approaches to managed services are changing the landscape of the IT channel, helping end-users increase efficiency and simplify IT solutions while maximizing their return on investment.
With many customers still recovering from the impact of the ongoing pandemic, MSPs have become a vital part of the success of businesses worldwide. MSPs not only empower organizations to leverage intricate technologies but also help them keep a strict focus on their core business goals without straining their budgets.
The annual MSP 500 list is divided into three sections: the MSP Pioneer 250, recognizing companies with business models weighted toward managed services and largely focused on the SMB market; the MSP Elite 150, recognizing large, data center-focused MSPs with a strong mix of on- and off-premises services; and the Managed Security 100, recognizing MSPs focused primarily on off-premises and cloud-based security services.
The MSP 500 list was featured in the February 2023 issue of CRN and online at www.crn.com/msp500.
eGroup delivers speed and certainty to clients, enhancing the digital transformation journey.
"For the seventh consecutive year, eGroup has been recognized on the MSP 500 list, a continued testament to the success of the company. In addition to providing core services to clients, we are dedicated to helping our clients grow their businesses through the integration of new technologies and services, ensuring they remain competitive, relevant, and secure in their respective markets. We are strengthening our partnerships with key vendors like Microsoft, Nutanix, Rubrik, and Cisco to provide clients with solutions in critical areas such as Digital Transformation, Zero Trust architectures, and Hybrid Cloud. Our investment in these areas today will have significant returns and long-lasting impact for the future."
Jesus J. Shelby - Director of Cloud and Managed Services at eGroup
ABOUT eGROUP
With over 20 years of experience and a comprehensive cloud and data center solutions portfolio, eGroup delivers outstanding results for customers across the nation. eGroup takes pride in delivering white-glove service to all clients and is proud to showcase that in a YoY 100% Customer Satisfaction Score. By aligning client needs with exceptional solutions, services, and support, eGroup makes businesses more productive, efficient, and competitive.
ABOUT THE CHANNEL COMPANY
The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers and end-users. Backed by more than 30 years of unequaled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. www.thechannelco.com
Follow The Channel Company: Twitter, LinkedIn, and Facebook.
© 2023 The Channel Company LLC. CRN is a registered trademark of The Channel Company, LLC. All rights reserved.
The post eGroup Awarded CRN’s MSP 500 List For 7th Year appeared first on eGroup | Enabling Technologies.
Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 2)
Introduction
This is the second article in this series. In the first part, we discussed the need to properly configure your Intune settings and policies for Teams Android devices. Here we will go over a few more items related to settings in Intune. We will also go over configuring Conditional Access Policies for these devices. Finally, we will talk about Teams Configuration profiles and testing your devices.
Detailed Configuration Steps (Continued)###### Check the Intune and Azure Active Directory Device Limits
Click on “Device settings.”
Note the number of devices in the “Maximum number of devices per user.
Switch back to the “Microsoft Endpoint Manager” and click on “Devices.”
Click on “Enroll devices.”
Click “Enrollment device limit restrictions.”
Click on the name of the Device Limit Restriction Policy.
If the device limit is less than that of the Azure Active Directory devices, click on “Properties.”
Click the “Edit” button.
Change the value of the “Device limit” to something that matches or exceeds the Azure Active Directory device limit or the maximum, 15, whichever is greater.
Click the “Review + save” button.
Click the “Save” button.
Click the “Edit” button for the “Apps” section.
Set the “Target to apps on all device types” switch to “No.”
Click the “Review + save” button.
Click the “Save” button. Repeat for the rest of the policies written for the Android platform.
Click on the first policy in the list. (The policies used in the examples were created from the templates provided by Microsoft and are in “Report only” mode. The “Terms of Use” Policy was manually created.)
In the “Cloud apps or actions” section, if the value is “All cloud apps,” this section of the policy is not compatible with Teams Phones. The example policy, therefore, is not compatible with Teams Phones. You do not need to perform the additional checks for this policy.
If the value is “1 app included” check to see if it is “Office 365.” If not, the policy is not compatible.
The “Conditions” section of the sample policy indicates that there are “0 conditions selected.” The settings in this section are compatible with Teams Phones. Continue checking the other sections of the policy:
If “Client apps” are configured, the Conditional Access Policy is not compatible.
The “Require multi-factor authentication” control in the “Grant” section of the policy is selected. The settings in this section are compatible. Continue checking the other sections of the policy.
If one of the documented unsupported controls or a “Terms
The “Session” section of the sample policy indicates that there are “0 controls selected.” The settings in this section are compatible with Teams Phones.
If “Use Conditional Access Apps Control” had been selected, the “Session” section would not be compatible.
This policy has one section that is incompatible. Select and copy the query you used to create the “Teams Phone” filter in step 1 above from the open “Notepad” session. (I told you we would need this later!).
Click the “0 conditions selected” button in the “Conditions” section.
Click the “Not configured” button in the “Filter for devices” condition
Set the “Configure” option to “Yes.”
Click “Exclude filtered devices from policy” in the “Devices matching the rule” section.
Click the “Edit” button above the “Rule syntax” box.
Paste the query into the “Rule syntax” box.
Click the “Apply” button above the “Rule Syntax” box.
Click the “Done” button.
Click the policy’s “Save” button. Continue checking the rest of the Conditional Access Policies.
Click “All user” beneath the “Include” tab.
Click the “Exclude” tab.
Click “No cloud apps, actions, or authentication contexts selected” in the “Cloud apps or actions” section.
Click “Select apps” beneath the “Include” tab.
Click the checkbox next to “Office 365.” You could instead choose these applications:
Microsoft Teams
Office 365 SharePoint Online
Click the “Select” button.
Click “0 conditions selected” in the “Conditions” section.
Click the “Not configured” button in the “Device platforms” section.
Click the “Not configured” button in the “Locations”
Set the “Configure” option to “Yes.”
Click the “Not configured” button under the “Filter for devices” section
Set the “Configure” option to “Yes.”
Click the “Edit” button to the right above the “Rule syntax” box.
Paste the query from before into the “Rule Syntax” box.
Click the “Done” button.
Click the “Grant access” option.
Click the checkbox for “Require device to be marked as compliant.” Select these options as required by your implementation. Make sure to avoid the unsupported options and Terms of Use requirements.
Click the “Select” button.
Verify that the settings in the profile are working as configured on the phone. Summary
Integrating your Teams Phones with the Microsoft Security and Compliance suite of products is possible. Special handling is required for several of the components:
eGroup | Enabling Technologies is available and ready to help you with the integration of your Teams devices into your organizational security and compliance plan. Excluding them from your security and compliance deployment is not advisable. If you need help with your Teams devices or in implementing your overall security infrastructure, please contact us today!
References
The post Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 2) appeared first on eGroup.
Teams Android OS Devices
Peacefully Coexisting (and Actually Working!) with
Microsoft Security and Compliance Policies (Part 1)
Introduction
At eGroup | Enabling Technologies, we define as a best practice the implementation of Microsoft Intune to provide device management used by authenticated users in Microsoft 365 tenants. The Intune component enrolls these devices and applies device compliance policies. We also define the configuration and use of Azure Active Directory (AAD) conditional access policies as a critical best practice for applying access controls during user authentication. This guidance is based on our recommendation that our clients adopt the Zero Trust security model for their organization. The broad definition of the model that we use is “Trust no one and harden everything.”
When configuring Intune profiles/policies and AAD conditional access policies, care must be taken to prevent problems for Teams (Android OS) phone and Teams Rooms on Android devices (“Teams devices” herein). Organizations usually configure these profiles/policies to control, protect, and manage their desktops, and both company and personally owned mobile devices. While documentation exists on how to treat Teams devices when creating these policies, it can be easily missed. If the policies are not correctly “tweaked” they will cause significant problems when they are applied to Teams devices; and they usually do end up getting applied automatically!
Teams devices can experience various problems with incorrectly configured policies:* Not being able to sign in * Randomly signing out + For a user, this would be annoying + Teams devices can and are used to place emergency calls. Emergency calls can be made from powered up and signed on Teams devices, even if the screen lock has been activated. From a health and safety perspective, deployed phones should almost never be in a signed-out state. * Freezing/crashing * Sign-in loops In this two-part series (Part 2 found here), we will describe how to configure these policies to peacefully coexist with your Teams devices. In this first part we will cover how to configure the Intune components and policies. In the second part , we will go over two additional Intune tasks and configuring your conditional access policies to prevent problems with your Teams devices. We will also touch on testing and Teams configuration profiles. This guidance should fix or prevent these problems from occurring on your Teams devices while not compromising the objective of Zero Trust.
What are the Policies Used For?
This article is not going to dive deeply into Intune Enrollment, Device Compliance, Configuration Profiles, Application Protection Policies and Azure Active Directory Conditional Access Policies. All five of these are components of Microsoft Intune; Conditional Access Policies really fall under Azure Active Directory, but they can be accessed from Intune. These topics are covered extensively by Microsoft and other parties. A user must have an Intune license to have their device enrolled into Intune.
All five policies fall under the heading of Device Management. They collectively allow an organization to manage the devices that their users sign into their tenant with. These are a critical component for the implementation of a Zero Trust security model for an organization. Devices fall into two major categories:
A Conditional Access Policy could be configured to block access to resources for a device marked as non-compliant. Android Device Platforms
There are two different Intune Device Platforms for Android devices:
High-Level Steps1. Create an Intune filter for Teams Phones. 2. Verify that the Android Device Administrator management method is enabled. 3. Configure the Android Enrollment Device Platform Restrictions. 4. Add the serial numbers of the Teams Phones as Corporate Device Identifiers. 5. Configure the Compliance Policy Settings. 6. Create a Device Compliance Policy for the Teams Phones. 7. Add an exclusion for the “Teams Phones” filter to existing Device Compliance Policies. 8. Add the “Teams Phones” filter as an exclusion to all Configuration Profiles created for the “Android Device Administrator” platform. 9. Check the Intune and Azure Active Directory Device limits. 10. Exclude Android Device Administrator devices from App Protection Policies for the Android Platform. 11. Add the Teams Phones exclusion query as a “Filter for devices” condition on existing Conditional Access Policies including Terms of Use Policies that have unsupported Teams Phones Settings. 12. Create a Teams Phones Conditional Access Policy. 13. Test the Teams Phones. 14. Create and apply a Teams Configuration Profile. 15. Test the Teams Phones with the applied Teams Configuration Profile. General Notes and Recommendations* Microsoft recommends using the “All Users” and “All Devices” Intune virtual-user groups. + These groups are available in all Intune tenants and do not require any management overhead. + They are highly scalable and optimized. * Re-use groups as much as possible. + It is more efficient to target a particular group with ten (10) policies than it is to create ten (10) groups with the same membership and assign ten (10) policies. * Make incremental group changes. + Large group membership changes in Azure AD can cause Intune’s targeting of assignments to policies to slow down significantly. Put another way, do not add 180,000 devices or users to the group all at once. Or don’t add three (3) child groups of 60,000 devices or users each to a parent group all at once. + Whether it’s a single group or the child-groups of a parent, plan to add no more than 30,000 users or devices to a group per day. * Use filters to include and exclude. + As a support statement, Microsoft does not recommend or support creating assignments to user groups and excluding a device group from the assignment or vice-versa. + The recommendation is to assign user groups to policies and use filters to include or exclude the appropriate devices. Detailed Configuration Steps###### Create an Intune filter for Teams Phones.
Type a name for the rule in the “Filter name” field.
Select “Android Device Administrator” from the “Platform” drop-down menu.
Click the “Next” button.
Add rules for the manufacturers of your Teams Phones. Use the “Contains” operator, the “Equal” operator can give unexpected results. You can expand these rules to include criteria for specific phone models.
Highlight and copy the rule in the “Rule Syntax” box. Create a text file and paste in the rule; you will use it later.
Click the “Next” button.
Click the “Create” button.
Click on “Android enrollment.”
Scroll down to the “Android Device Administrator” section.
Click on “Personal and corporate-owned devices with device administrator privileges.”
Make sure the checkbox next to “Use device administrator to manage devices….” is checked.
If it is, click the “X” to close the window.
If not, check the box and click the “OK” button.
Click “Enrollment device platform restrictions.”
Click the “Android restrictions” tab.
Click on “All User” in the “Default” Policy.
Click “Properties.”
Click the “Edit” button in the “Platform settings” section.
Click the “Allow” button in the “Platform” column of the “Android Device Administrator” row.
Click the “Block” button in the “Personally owned” column.
Click the “Review + save” button.
Click the “Save” button.
Click “Corporate device identifiers.”
Click the drop-down arrow next to “+ Add.”
Click “Enter manually.”
Choose “Serial number” (or IMEI as required) from the “Select identifier type” drop-down box.
Type in the serial number or IMEI in the “Identifier” text box.
Enter information in the “Details” text box.
Add additional rows as needed then click the “Add” button. Corporate Identifiers in a comma-separated value (.csv) files can also be imported.
Click “Compliance policy settings.”
Set “Mark devices with no compliance policy assigned as” to “Compliant.” This is a temporary setting. Switch it back to “Not-compliant” once all policies have been defined and tested.
Click the “Save” button.
Type a name for the policy in the “Name” field.
Add a description in the “Description” field.
Click the “Next” button.
Based on the current Compliance Policy supportability for Android Device Administrator, expand each of the policy subjects and follow the guidance below. The guidance is based on the information on the previously mentioned web page published on September 14, 2022.
Microsoft Defender for Endpoint
All Android devices
Click the “Next” button once you’ve completed your settings.
On the line with the “Mark device noncompliant” action type a “1” into the “Schedule (days after noncompliance) column. If a device is not compliant, it will be allowed to be signed into and function for one (1) day. This allows time for administrators to remediate the device to bring it into compliance. If you are applying this policy to a large number of devices, increase the length of this “grace” period.
Click the “Next” button.
Click “Add all devices.”
Click “Edit filter.”
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Next” button.
Click the “Save” button.
Click the “Create” button.
Click on the first policy that is not based on the “Android Device Administrator” platform. In this example, “IOS.”
Click on “Properties.”
Scroll down to “Included groups.”
If the groups are device groups or appear to be device groups, click the “Edit” button adjacent to the “Assignments” label.
If the groups are user groups, click the “X” in the upper right-hand corner and proceed to the next policy.
Click the “Edit filter” button.
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Review + Save” button.
Click the “Save” button.
Repeat these steps for the rest of the device Compliance Policies.
Scroll down until you can see the “Assignments” label in the Profile’s properties.
Click the “Edit” button.
Click on “Edit filter”
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Review + Save” button.
Wrap Up
In this first article, we have covered how to configure most of the settings in Intune and its policies to accommodate Teams devices. In the second part, we will finish up the Intune configuration and dive into the setup of Conditional Access policies that will provide security and prevent problems for your Teams devices.
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
The post Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 1) appeared first on eGroup.
Use Classification Rules (Instead of Proxy Sets) on AudioCodes SBCs
Introduction
Admittedly, this title is misleading, but it did get you to look at this article! This is part of our series on securing AudioCodes SBCs based on eGroup | Enabling Technologies’ security mantra of “Trust No One, Harden Everything” and guidance provided by AudioCodes.
A “basic” class on configuring an AudioCodes SBC shows how to populate Proxy Sets with the IP addresses or Fully Qualified Domain Names (FQDNs) of a SIP service’s endpoints that need to communicate with an SBC, or which an SBC needs to communicate with. If a SIP Trunk vendor provided you with two (2) SIP signaling IP addresses, you would add them to the SIP Trunk Proxy Set on your SBC. The Proxy Set would have been paired with a SIP Interface on your SBC and associated with an IP Group. The problem with this configuration is that it allows traffic to enter your SBC based only on two (2) criteria:
If you have a SIP Trunk running “over the internet,” bad actors can spoof their source IP address with one of these addresses and gain access to your SBC.
AudioCodes recommends the use of strict Classification rules to manage the ingress of traffic into SBCs. This guidance for using Classification rules can be found in their security guidelines documents for SBCs and Gateways, referenced at the end of this article.
Classification rules are not a replacement for Proxy Sets, they are an addition that increases the security footing of the SBC. In most cases, you will still have to populate Proxy Sets with the provided IP addresses or FQDNs of the SIP service provider. Besides associating incoming traffic to an IP Group, the addresses in the Proxy Set are used to route traffic from the SBC to the SIP service provider. The Classification rules replace the Proxy Sets function of mapping incoming traffic to IP Groups.
How an SBC Manages Inbound Traffic
The SBC will try to Classify inbound traffic. Classification determines:
Before the SBC begins the Classification process, the traffic must get past the SBC’s first line of defense, the firewall rules. Once the traffic is permitted, the “Network Interface” it arrived on and the appropriate “SIP Interface” is determined. The SBC can then begin the Classification process:
By default, the SBC will associate the SIP INVITE with the first IP Group in the IP Groups table and the traffic will be allowed to come into the SBC.
Cloud platforms are always up to date and there is always constant improvement to these platforms. No more risky (and expensive) stair-step upgrades. The cloud provides predictable costing for both licensing and the effort required to manage and maintain the platform. Depending on the need, cloud-based virtual desktops can even eliminate much of the capital expenditures for workstations, plus they add some security and manageability features.
Speaking of security (I know, there it is again), modern and cloud-driven security platforms are a match for the threats that exist today, and these platforms are constantly improving. Beyond endpoint protection and automated response, platforms like Azure Active Directory, Defender for Cloud Apps, and Sentinel allow you to continually monitor and maintain a vastly improved security posture.
Your compliance program gets easier, too. Microsoft Purview provides robust compliance features like retention, data labeling, DLP, and insider risk detection. Purview also evolves as the rest of the Microsoft 365 cloud solutions do and can replace third-party products point solutions that require upgrades, maintenance and separate alerting and management processes.
The legacy PBX can be replaced by Teams Voice, and Teams is natively connected into the security stack and Purview to provide a one-stop shop for collaboration and interoperability with SharePoint, OneDrive, and third-party SaaS systems. Plus, storage stops requiring so much separate effort since it is included and managed alongside the cloud services.
Automation and development with Power Apps are also available and can help get those manual processes that live in people’s heads (and 7 linked spreadsheets) documented and implemented as applications that people can simply use, and not manage.
Proxy Set Call Flow — Classification by Proxy Set
SIP service providers will let you know the IP addresses or FQDNS you should use to reach their service. It is usually one or the other. Microsoft Teams is the best-known example of a SIP service that provides both addresses and FQDNs.
The Golden Rules1. Use Classification rules if you are given IP addresses by the service provider. If you are only given FQDNs, you cannot use Classification rules and must use “Classify by Proxy Set” for the SIP service. If you are given both, you should use Classification rules. 2. Configure the SBC to reject unclassified calls. 3. Apply strict criteria to Classification rules. The criteria should be as strict and specific as possible. Avoid using wildcards or “Any” values in the criteria. 4. The order of the rules in the table is significant. Configuring Classification RulesRules must be assigned to an SRD. From the previous articles, we know that SBCs with only a default SRD are most common. When you create a new rule, the “defaultSRD” will already be populated in the “SRD” field.
Matching CriteriaEach rule has a “Match” and “Action” component. The “Match” side specifies the criteria for the rule and the “Action” side has what should happen if the rule is matched.
There are nine (9) types of criteria that can be matched:
Rule ActionsThere are six (6) fields on the “Action” side of the rule. Only three (3) are commonly used.
IP Group SettingsChange the configuration of the IP Groups (Setup > Signaling & Media > Core Entities > IP Groups) that will use Classification Rules. The “Validate Source IP” parameter should be available in the Long-Term Support release of the 7.40 firmware for the AudioCodes SBCs.
Set “Validate Source IP” to “Enable.” SBC General SettingsThis setting rejects inbound SIP INVITES that cannot be Classified. This replaces the default behavior of routing the unclassified calls to the first IP Group on the SBC.
Click on “Setup.”
The rules for DOD and GCC High tenants can be found in a previous blog post UPDATE! AudioCodes SBC Configuration Update for Teams Direct Routing.
Classification Rules for SIP Services that use Sub-netted IP Address Ranges
The Teams Direct Routing documentation from Microsoft for Microsoft 365, Office 365 and GCC environments states that there are three (3) FQDNs that a Teams Direct Routing SBC needs to communicate with:
These FQDNs will resolve to IP addresses in these ranges:
As mentioned earlier, the Classification rules do not provide a way for a subnet mask to be applied to the Source IP address in the rule. The Source IP does permit the use of wildcards for one or more of the address’s octets. If we were to create two (2) Classification rules with 52.112.. and 52.120.. as the Source IP addresses, the rules would match traffic coming from these IP address ranges:
These ranges do not match those specified by Microsoft. To cover the Microsoft ranges, we need to create individual rules for each of the subnets in 52.112.0.0/14 and 52.120.0.0/14. It is important to note this in case you need to create Classification rules for other SIP services that use similar IP addressing.
Explanation of the Supported Classification Rules for Teams Direct RoutingThe rules provided by AudioCodes use four (4) of the matching rules to create the criteria for matching inbound traffic from Microsoft Teams.
A match will happen if an inbound SIP INVITE:
On a match, the “Action” configured for the rule will be executed. In this case, the SIP INVITE will be marked as having a Source IP Group of “Teams” for the duration of the call.
Message Condition RulesYou can create up to 1,200 Message Condition rules on an SBC. The rules define special criteria for incoming SIP messages. They use the same syntax as Message Manipulation rules. Each Classification rule allows you to associate a single Message Condition rule. If you want to match multiple criteria, you can use the “and” and “or” constructs in the rule. You can also create separate Message Condition rules and associate them with separate identical Classification rules, except for the Message Condition rule.
The “Teams-Contact” Message Condition rule will be matched if an incoming SIP INVITE has ‘pstnhub.microsoft.com’ in the host part of the “contact” field URL in the header.
To create the rule:
Before changing the Teams Classification rule on an SBC, keep in mind that the configuration of these rules has been set out by AudioCodes. It can be implied that these settings reflect the AudioCodes supported configuration of the SBC. Changing these rules may adversely affect the ability of the SBC to route inbound SIP INVITEs from Microsoft Teams. Keeping this in mind, there is room to carefully add additional criteria to these rules.
Following are suggested additional criteria that can be added to the Teams Classification rules:
There is another way to configure your Classification rules to match multiple different DID ranges that you might have. This involves using Dial Plans, Tags and Call Setup rules. Details for this are beyond the scope of this article. Please contact us if you are interested in using your DID ranges as a criterion in your Classification rules.
Final Notes
Some tips for SIP Trunk Classification rules:
AudioCodes’ SBC security guidance recommends that Classification rules be used to control the admittance of inbound traffic to the SBC.
eGroup | Enabling Technologies is available and ready to answer any questions that you might have about SBC hardening and security as well as overall security for your enterprise. If you need help in implementing a security infrastructure for your organization, please contact us!
Bibliography
AudioCodes has written two (2) documents addressing security on their Session Border Controllers and Gateways. There are separate versions for the 7.2 and 7.4:
The AudioCodes Teams Direct Routing Configuration guides contain the configuration steps for interfacing an AudioCodes SBC to Teams Direct Routing. These guides apply to both firmware versions 7.2 and 7.4:
The AudioCodes SBC hardware installation and user manuals can also be found in the Library section of the AudioCodes website.
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
The post Use Classification Rules (Instead of Proxy Sets) on AudioCodes SBCs appeared first on eGroup.
Defuse the Technical Debt Time Bomb
While it has certainly been in the news more often lately, technical debt has been a challenge for organizations since the days of vacuum tubes. Other than the recent air travel examples in the last few months, there is a constant stream of articles about health care providers, colocation services, public utilities, and other companies falling victim to their lack of investment in modern technology platforms and solutions.
The Tech Debt Time Bomb
Failed endpoint hardware. Overextended file servers. Corrupted email servers. Storage arrays beyond their end of life. Legacy Private Branch eXchange (PBX) systems. Uninterruptible Power Supply (UPS) batteries. That router that could die any day. Shall I go on? (Notice I haven’t even mentioned security yet….)
Most organizations have at least a few systems that are either too expensive to upgrade or are not deemed enough of a priority to replace. When those systems fail, though, there are almost always unforeseen consequences, dependencies, or costs that could have been easily avoided. These are usually the systems that someone also decided not to build redundancy into when they were designing the solution years ago.
Even newer challenges like using ungoverned shadow IT to run critical processes can worsen technical debt, since these stopgaps provide a bandage that hides the weak system underneath that it relies on.
Oh yeah, and security – Legacy security solutions are really no match for the sophistication of the threats and attackers that exist today, so every week you hear about organizations that are devastated by ransomware, or notifying their customers that they have had a breach.
There is a light at the end of this tunnel, though….
Cloud Solutions to the Rescue
Cloud technology provides a path out of this mess for many of the impending system failures I have called out above. Platforms like Microsoft 365 and Azure provide better versions of all those services and the barrier to switching is fairly low, considering there is really no large capital expense required to make the switch. Plus, imagine how much time the IT team gets back if they no longer need to babysit those legacy systems.
Cloud platforms are always up to date and there is always constant improvement to these platforms. No more risky (and expensive) stairstep upgrades. The cloud provides predictable cost for both licensing and the effort required to manage and maintain the platform. Depending on the need, cloud-based virtual desktops can even eliminate much of the capital expenditures for workstations, plus they add some security and manageability features.
Speaking of security (I know, there it is again), modern and cloud-driven security platforms are a match for the threats that exist today, and these platforms are constantly improving. Beyond endpoint protection and automated response, platforms like Azure Active Directory, Defender for Cloud Apps, and Sentinel allow you to continually monitor and maintain a vastly improved security posture.
Your compliance program gets easier, too. Microsoft Purview provides robust compliance features like retention, data labeling, Data Loss Prevention (DLP), and insider risk detection. Purview also evolves as the rest of the Microsoft 365 cloud solutions do and can replace third-party product point solutions that require upgrades, maintenance, and separate alerting and management processes.
The legacy PBX can be replaced by Teams Voice, and Teams is natively connected into the security stack and Purview to provide a one-stop shop for collaboration and interoperability with SharePoint, OneDrive, and third-party SaaS systems. Plus, storage stops requiring so much separate effort since it is included and managed alongside the cloud services.
Automation and development with Power Apps are also available and can help get those manual processes that live in people’s heads (and 7 linked spreadsheets) documented and implemented as applications that people can simply use, and not manage.
Staying Up to Speed
While all the benefits I describe here are real and extremely impactful, there are some changes that the IT team will have to get used to. The constant changes can be challenging to keep up with, but they are also the reason technical debt is a thing of the past. You do need to pay attention to the published product roadmaps and announcements, plus have established ways to communicate these improvements to your organization.
Staying current on supported Windows releases, Office versions, and endpoint compliance becomes very important, but again, also stops you from falling behind. Good thing you now have far better tools to manage those endpoints with, like Intune.
The Bottom Line
Cloud solutions really do help resolve technical debt once and for all across a significant number of systems. It may not meet the requirements for every need and scenario but using these new platforms will significantly reduce the time and money required. The IT group can now focus more effort and capital expense on systems that do require more care and feeding, and that allows you to get more done with less, reduce risks, and give people better tools all at the same time.
Tom Papahronis Strategic Advisor - eGroup | Enabling Technologies
The post Defuse the Technical Debt Time Bomb appeared first on eGroup.
The Pros and Cons of Threat Hunting
Assuming Breach
Stealthy supply chain attacks like Solorigate and Log4j have shined a light on the importance of assuming breach. When these attacks hit the news, vendors and analysts often suggest to “hunt for Indicators of Compromise.” IT and security pros spend nights and weekends determining the extent of the risk within their organization, then come up with a plan to isolate, patch, or otherwise remediate the issue. That’s easier said than done, especially for small security teams. It’s even harder to keep up with the near-constant, less-publicized threats, like the one that CISA advised to hunt for last week.
This blog outlines what it really means to be a threat hunter, provides realistic advice for organizations with limited means to do so, and highlights how the automation of Microsoft’s security suite makes threat hunting more scalable.
What Does Threat Hunting Entail?
Threat hunters discover unknown or stealthy attacks that might have bypassed existing security measures. Threat hunting is especially crucial in supply chain attacks, which evade traditional detection systems because their patterns appear “normal” and don’t trigger an alarm.
Threat hunting is a Security Operations Center (SOC) function. It’s rare that an IT Pro or individual security pro has time to proactively search for, analyze, and identify potential security threats, especially in hybrid cloud environments.
Hunting starts with a hypothesis. A hunter may generate a hypothesis based on internal (i.e. one VIP Is breached, so they’ll check on others) or external information (such as threat reports, blogs, and databases of Indicators of Compromise (IOCs)).
Like with log4j, the security community is the best source for what to hunt for. Vendors, industry, and researchers (eventually) publish IOCs. CISA’s article includes IOCs for threat hunters to follow up on. Separately, a SANS analyst advised that “You should be checking for installations of any remote management software.”
Hunting tools and techniques involve the analysis of logs, network traffic, and security alerts to identify patterns of behavior that may indicate a security breach or attack. The goal is to detect, prevent and respond to security incidents before they result in a breach or significant damage.
Microsoft’s Threat Hunting Tools
The key tool in Microsoft’s threat hunting arsenal is Sentinel, the Magic Quadrant-leading Security Information and Event Management (SIEM). Sentinel provides the most robust way to scan for threats across the broadest set of IT systems. The Defender suite also has hunting capabilities along with Kusto Query Language (KQL) capability, if it’s not possible to use Sentinel.
SANS survey in 2022 confirmed that most (83.4%) hunters are using SIEM technology to hunt.
Sentinel can be integrated with threat intelligence from various sources, including Microsoft Threat Protection and third-party STIX/TAXII systems feeds. STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Indicator Information) are open standards for exchanging cyber threat intelligence. Leading examples include AlienVault and PickupSTIX. Integration with STIX/TAXII systems allows Microsoft Sentinel to receive threat intelligence from a variety of sources, including internal threat intelligence platforms, third-party threat intelligence providers, and community-based threat intelligence feeds. This information can be used by hunters in a more automated way, rather than them having to import and custom-create their own hunting code every time (using KQL).
Pros of Threat Hunting
Threat hunting enables:
In SANS 2022 Threat Hunting survey, improvements from hunting are well above 25%.
Challenges of Threat Hunting
So why doesn’t everyone take the CISA directions, and act? There are many factors on why it’s difficult.
Finally, threat hunting can be a rabbit hole. CISA’s recent advisory suggests that “The authoring organizations strongly encourage network defenders to review the Indicators of Compromise (IOCs) and Mitigations sections in this CSA.” The CISA post included a list of five (observed) Malicious Domains and IP addresses observed by CISA, but not how to check if an environment has been exposed by said domains. They also link to a more thorough blog from security researchers, which included a much lengthier list of IP addresses and phishing domains. Which list should be used, practically? How does a SOC decide, and ensure that a thorough check is completed?
For all of those reasons, only 15.6% of SOCs surveyed by SANS had personnel dedicated to a “very mature” hunting process.
It’s frustrating for a security pro to know what to look for, but not how– and equally so for a CISO who’s invested in a SOC, who’s not sure if the investment is paying off.
What Can a Short-Handed Team Do?
Organizations without a dedicated Security Operations Center (SOC) and limited personnel can still be proactive by:
Having limited personnel can make it challenging to hunt threats effectively, and organizations may still need to consider using outside resources or outsourcing some of their security operations. For those looking to build in-house hunting capability, SANS has a nice outline.
How eGroup | Enabling Technologies Hunts for Threats
For organizations who find value in threat hunting but lack the time or resources, eGroup | Enabling Technologies can be a resource. Our team has experience with the processes, tools, attack vectors, and remediating steps of threat hunting.
As an example of the automation and proactivity of the ThreatHunter team, I sought to understand how our team was responding 24 hours after the CISA alert.
The team monitors IOCs in several ways, including:
Either by direct feeds or manual inspection, the IOCs (be they IP, URL, File hash, or process) are entered into a gold list of IOCs in Microsoft Sentinel. The IOCs act as a sort of watchlist for a set of analytic rules.
That gold list of IOC’s gets synchronized to all of our ThreatHunter Managed Security Service (MSSP) clients via a LogicApp, which is monitored for any failed runs. If any of the IOCs (of which there are thousands at this point) are seen in customer environments we’re monitoring, the automated analytic rules will catch them and report an incident, prompting our hunters to investigate deeper to validate or resolve. Often the resolution can be automated (i.e. a phishing email from an offending domain can be deleted by Defender for Office Automated Investigation and Response), but if necessary, manual intervention and remediation are provided.
Summary
Hunting for threats is an important aspect of an organization’s security posture, especially to counter the growing trend of stealthy supply chain attacks. Organizations can hunt for threats on their own by utilizing various tools and technologies, including SIEMs like Sentinel, threat intelligence platforms like AlienVault and PickupSTIX, and extended defense and response solutions like Defender. Organizations with the staff have a unique advantage – they can combine the tools, knowledge of in-house systems, and awareness of their business to analyze data and identify potential security incidents.
Meanwhile, organizations without the resources, including personnel and technology, to effectively hunt for threats, can consider using eGroup | Enabling Technologies MSSP. Built on Microsoft technology, we provide the necessary tools and expertise to effectively detect and respond to security incidents, automate the threat hunting process, reduce the time and effort required to detect and respond to security incidents, and allow your organization to focus on its core business operations.
Chris SteghCTO & VP of Strategy - eGroup | Enabling Technologies
The post The Pros and Cons of Threat Hunting appeared first on eGroup.
Evolve Your Cloud Vendor Management Program
Having an active and intentional vendor management program has always been important for a technology team. With the introduction of cloud, SaaS, laaS, and all the other flavors of “as a Service” offerings, this program has become even more critical. While the cloud offers significant benefits and provides a far more robust set of functions and features, the technology companies that were once simply vendors have morphed into critical partners that are now running fundamental technology services for you. They are hosting and securing your most sensitive information in data stores that are often no longer directly accessible or manageable with legacy methods. The impact of a vendor outage, breach, or other failure is now far more significant and should be planned for and responded to differently.
Before cloud solutions were available, vendor management programs were typically focused on feature comparisons, pricing, and a large up-front capital expenditure. You owned the software, hosted it, and your destiny was completely in your hands. Post-purchase, the vendor was only there for upgrades or support. It was up to you to provide redundancy and decide how to respond to and recover from an outage event. You were on your own to provide an SLA and fix things when they went down. Outage windows were needed for maintenance. The underlying (and complex) networking, storage, and server/hypervisor management all needed significant staff attention. All of this required money, people and time that were often stretched thin or (at best) at a premium.
This dynamic has changed quite a bit with cloud technologies since you no longer own the environment. Your vendor management processes now need to evolve accordingly. While the capabilities, benefits, and cost advantages of cloud technologies are a huge step forward, the cloud provider is in a very different role than a traditional vendor.
Many clients I work with are using more cloud solutions and incurring different risks than they actively realize. The technology and risk management teams need to get ahead of this so that the feature improvements and changes in risk profiles are well understood, balanced, and actively managed.
I’ve outlined some key considerations below to help illustrate some of the different vendor management approaches and decisions that need to be made:
Sourcing Considerations
Understand the Service Level Agreements (SLAs) – Cloud provider SLAs are complex and it is critical that they are well understood. They are often non-negotiable and calculated by individual service. Failures are specifically defined and often the only remedy for an outage is a future credit on the service. Cloud services like Microsoft’s have a great track record and almost always exceed their SLAs. I have never seen the SLA be a barrier to a purchase decision, but if there is an outage it is best if no one is surprised at the remedy. Financial Considerations
Perform a financial assessment – A detailed financial assessment of the vendor is key. Public cloud providers like Microsoft publish their financial statements, uptime statistics, and other critical information, so this process is much easier than trying to vet a private company. The CFO should be asking whether the organization would invest in that cloud provider, because in many ways you will be.
Stop paying for unapproved cloud services – Shadow IT presents risks and is often redundant to some of the solutions the business may already be paying for today. Financial controls should be used to ensure that cloud vendors that have not been vetted are not being paid for. Legal and Insurance Considerations
Review the cloud provider’s agreements – Have the legal team review cloud provider agreements to ensure they are understood, and so any specific business risks can be called out. Again, try to avoid any surprises.
Understand who carries liability – The cloud vendor does not carry all the liability for their service. Clearly understanding what each party is liable for is critical, along with any indemnification clauses. (These may require the vendor to defend you, or you to defend the vendor in specific cases.) Risk & Compliance Considerations
Perform a risk analysis – As mentioned above, implementing cloud solutions will change the organization’s risks and this needs to be evaluated. Many existing risks can be mitigated by cloud solutions, but those that remain should be cataloged and addressed. The increased dependency on the cloud vendor may be new to the organization.
Backup, recovery, and replication – The methods available to backup and recover data will change in a cloud environment, plus new data replication options may be available to enhance redundancy. That said, you still need to periodically test recovery, service restoration, and incident response. Those processes will be different and require your existing recovery playbooks to be updated. Ongoing Vendor Management Tasks
Periodic review of services – At least annually, develop a process to review vendor performance. Would you purchase the services again knowing what you know now? Provide feedback to the vendor if there are services that could be improved. Make sure your team keeps up to date on the vendor’s product roadmap as well.
I’ve listed a lot of things to watch out for here, but much of this is required to manage any type of vendor. The bottom line is that cloud offerings significantly improve the functionality, security, and availability of your technology systems. (I wrote about all the risks you can avoid with cloud technologies here.) Just like with on-premises systems, you do need to be thoughtful and prudent when both selecting solutions and maintaining an ongoing program to manage the vendor. If it is done right, you can maintain positive and responsive vendor relationships that will allow you to continue to drive even more value out of their platforms and provide ongoing positive outcomes for everyone.
Tom Papahronis Strategic Advisor - eGroup | Enabling Technologies
The post Evolve Your Cloud Vendor Management Program appeared first on eGroup.
Nonprofit IT Executives Talking Azure
In a recent case study about his organization’s journey to the Microsoft cloud, a nonprofit leader stated, “Technology can be the great equalizer.”That evidence was again on display in a recent panel hosted by Microsoft and eGroup | Enabling. Panelists included IT leaders representing four non-profit organizations, with topics ranging from cost justification to global agility.
Read on for some terrific tales from the trenches!
About the Panelists
Our panel included:
Michael Mazza, Head of IT Solution Services from FHI 360. Michael has the “great fortune” of working at FHI 360, where we focus on the “360 degrees of human development.” Their strongest business unit is in health. “We receive a lot of funding to fight HIV,” explained Mazza. “We have received significant funding to establish a COVID prevention network around the world. We also have a large educational business unit.” He added that “If any of you are in corporate America, you might think about your second career being at a not-for-profit. It’s been very rewarding!”
Matt Birnie, Enterprise Architect at Trans World Radio. Matt took that path after spending years in IT for Wall Street broker dealers, banks, and credit card processors. Now he supports Trans World Radio, a “Christian media and broadcast company in around 200 countries or so, broadcasting in about 300 languages.” With a worldwide presence, Birnie’s job is to “keep all that going on the shoestring budget.”
JoJo Almario, Senior IT manager at IntraHealth International. JoJo is the Senior Manager of IT at IntraHealth International. “We’re an international and profit NGO,” Almario explained, “building capacity for health workers in low bandwidth areas.” With presence mainly in sub-Saharan African, Central America, and Asia, “We deal with areas like HIV interventions and disease prevalence,” he said.
and
John Berar, CIO Emeritus and current Strategic Advisor. John is currently a Strategic Advisor with eGroup | Enabling Technologies. Most relevant to the conversation was his prior role as CIO for an international, not-for-profit operating in about 20 countries, including Africa, South America and the U.S.
The Business Case for Action
The panelists described some of the reasons they took the plunge in Azure at the pace they did.
FHI 360For Michael Mazza, the cloud is about “Doing things faster.” He opened by telling a story of the inefficiencies of IT before the cloud, compared to the efficiency of using the cloud today.
In 2011, when South Sudan became a country, “FHI 360 was awarded $30 million over three years to strengthen the health systems there,” Mazza explained. “I spent $500,000 on information technology to set up an office with Cisco VoIP, a satellite, WAN optimization, and an e-mail server.” After spending all that money, “FHI struggled to find enough local people to hire for the program, so the funding was greatly reduced. We had to shut down the office and the technology we had implemented. The money that was spent for equipment, network contracts, staff time, etc. was gone.”
Sensitive to the US taxpayer dollars being spent, Mazza declared “We’ve got to come up with a faster way.”
Now, with the cloud, “We can work literally anywhere in the world,” Michael claimed. “I don’t even have to send a laptop. All our critical systems are in the cloud.” That velocity enables us to get projects up quicker and thus provides faster results for our funders like the US government or Gates Foundation. “With cloud-based systems FHI can begin work immediately after receiving the award and we can have people on the ground working on day one. FHI does not need to worry about setting up all this infrastructure. Microsoft makes it easy to get things up and running.”
Trans World RadioTrans World started by using Azure as a backup for their data centers to improve availability. “Since then, we’ve moved all our critical workloads are in Azure,” Matt Birnie explained. TWR still has data centers around the world, but “Critical workloads, finance and things that we need operational 24 hours a day run in Azure.” That includes SQL servers, Windows servers and terminal servers, which have now been “rolled into the Microsoft’s VDI environment, which has worked really well.”
TWR is also improving identity security. “We utilize the Azure AD app proxy to provide single sign-on for all sorts of internal applications that we want to make available to vendors, or to people without the need of a VPN,” Matt articulated. “That’s been really nice, because MFA is probably the most important security solution that you should implement right away.”
IntraHealth InternationalLike Birnie, Jojo Almario agreed that “The cloud helps IntraHealth in our security strategy.” IntraHealth moved services more rapidly into Azure. “We emptied out our data center around 2017,” he said. “We now have about 15 virtual machines, some app services, platform services, and a couple of Azure SQL databases.” With a large data set of donor and research data, “We also have an implementation of a data factory as our data warehouse which is also coupled with some databases. We’re using Power BI dashboards for reporting about our programmatic efforts.”
Disasters Catalyze Some Migrations
Trans World’s journey into Azure began with a Disaster Recovery plan. “Our main data center was in Cary, NC, which once in a while experiences a hurricane,” he started. “It was quite an ordeal to move all of our services to another site, so we set up an Azure tenant and started with a traditional Active Directory server and our hybrid Exchange Server.” Once seeing the operational efficiency, and considering future needs of the global organization. “We made the decision that we were going to move all our critical workloads into Azure over one really scary weekend,” recalled Matt. “We went all in pretty quickly and we really have been served very well with it. As time goes on, we utilize Azure more and more.”
At IntraHealth, Almario had even more urgency. “Before we started working with eGroup and FastTrack on Azure Site Recovery, we had two ransomware attacks within a year– about six months apart.” Legacy storage technology could do little to protect against such disasters. “Our backup storage area was iSCSI connected. That means that if the bad actors attacked our servers, they also had access to our backups– so they chewed through all that and we were down for a whole week.” Azure Site Recovery not only provides Disaster Recovery (DR) as-a-Service, but also provided IntraHealth a low-risk way to transition from running a backup in the cloud to running production services. That’s the state that IntraHealth is in now, putting Almario in a (relatively) safer position. “Now that we’re in Azure, and in Office 365, I understand there are other vulnerabilities that can do us in. But with the resources we have in Azure, it’s easier to have an immutable backup. We have multiple versions of data because storage is elastic. I don’t have to worry about my backup hard drives getting full and having to budget for more. You just click a button and expand your storage. That ease gives us so much more time to concentrate on the security of many more things.”
Mazza summarized FHI 360’s journey by starting with some critical services in Azure, determining that it worked, and then choosing not to build a data center when they moved offices. “We just have a couple of network closets (onsite), and we have not looked back since,” Michael stated.
Berar echoed common themes as he described his organization’s first move into Azure. “All of us here around the table have to be very careful of dollars, need to move quickly, and we’re all global companies.” He too got started by using Azure as a disaster recovery site. After moving domain controllers and IT ticketing systems, “That’s when we went from having a data center in one of our offices to doing a collocated data center, to moving 100% to Azure.” Berar shared his low-risk approach to migration. “We moved development environments first, then production environments. The easiest migration we ever had was shifting our data center to Azure, in terms of downtime. Then instead of worrying if a disc failed or if there’s not enough memory in a server, we could really help support the business initiatives.”
Domain Controller Consolidation
“I think this is one of the lowest hanging fruits,” asserted Berar. “We had twelve domain controllers scattered across the globe. We ended up moving two domain controllers into Azure and then a third in one of our offices in case something happened in Azure. Then, we’re not worrying about connectivity across the globe to get to a domain controller that ‘tomb-stoned’ and can’t be reached anymore.”
Trans World’s Birnie agreed. “We’ve decommissioned most of our domain controllers,” Matt started,
“and where we have them, we usually have one domain controller instead of two.” Taking a proactive, ‘cloud-first’ philosophy, “Our new computers aren’t joined to Active Directory anymore,” continued Birnie. “They’re all joined to Azure Active Directory only, and as all the old devices that were hybrid joined are replaced, we really won’t have the need for domain controllers.”
A prior blog outlines more detail, including the approximate cost of a domain controller in Azure.
Finances Pan Out For All
On limited budgets, our nonprofit panelists had to make the leap to an operational expense model and make commitments to Microsoft about cloud expenses. They shared their experiences in justifying the expense, along with some unexpected benefits.
IntraHealth’s Almario started by saying “Overall, there was a downtrend in spending, but most gains came in our level of effort. In other words, where we were spending our time. We aren’t spending our time as much on setting up offices, setting up services in our field offices.” That saves time not only in setup but also operationally. “Anytime anything goes down or fails, it’s not easy to get something drop-shipped there. So you paid your budget, you get as many spares as you can at that office but then things happen, and wait a while before we can get a spare there. Now, that just doesn’t happen. Any issues with drives or memory or expanding storage, it just kind of happens on the fly.”
That tangible time and expense savings is additive with a ‘softer’ improvement. “There’s also a perception of less downtime,” said Almario. “There are no e-mails saying, ‘We have to work on this, or please stand by while we update something.’ Our stakeholders see less of that now and actually perceive ‘Oh you guys are up all the time because there’s been no warning’ That’s helped us show how valuable the IT department is and how we spend our time. We are able to spend more time looking at things like security and expanding services for our stakeholders and our users.”
Berar took a hard look at the total cost of ownership (TCO) of cloud services, and found advantages that offset the Azure invoice. “We used to have infrastructure in our country offices,” John explained. “If we go to set up an office it may take months, but now we ship an air card and simple network gear to connect to the Internet. We’re up and running in minutes, hours, days versus many months. Part of it is the speed, and what’s the benefit of that speed? What’s the cost of the less administrative overhead of even tracking those assets? So that’s how we did it… by looking at the total cost of ownership and how can we better serve the organization.”
Mazza said that it was due to FHI’s “Very supportive leadership team” that “We never really had to cost justify it. If we don’t have people managing storage, managing servers, we can instead have business analysts supporting the business and information security people keeping us safe.”
Trans World Radio dove deep into cost analysis of Azure, and still came out in the black. “We were at the end of life of our HyperV environment and had to replace a pretty big SAN in our main data center,” explained Matt Birnie. “Originally the plan was to replace that with a new SAN or hyperconverged infrastructure.” During initial conversations with eGroup, Azure was discussed and “We were very surprised at the price point.” After spending days comparing the Azure calculations versus buying new hardware, Matt found that “Honestly, Azure was going to be cheaper for us, plus have all the future-proofing and benefits that we’ve been talking about.” Reallocating the budget for replacement hardware into an operational expense for Azure “Wound up saving us a fair amount of money as well as significantly upgrading our service availability.”
Advantages and Challenges
For Trans World, the advantage right away was high availability. Birnie quipped, “If a hurricane comes, it’s Microsoft’s problem, not mine.” Yet he recognized that maintaining new services and the security thereof as an ongoing challenge. “You can give people whatever control you want and have a huge amount of granularity in roles and in giving people rights to do only exactly what they need to, so that’s an advantage. But that’s then another thing that to manage and that’s another level of complexity. So I would say that the security options available is one of the greatest advantages, but also a disadvantage.”
For FHI 360, the advantage of distributing control to his global community is also a risk. Mazza explained, “We were a global organization operating in dozens of countries. We operate 24 hours a day.” Instead of waiting for people in the U.S. to make changes, FHI distributes the power to people across the world to spin up Azure servers, add storage space and the like. “All of them are great stewards of the organization’s money, but occasionally we have to sort through that and optimize our spend.” But overall, “The idea that you can get on and off really quickly makes Azure very powerful for us,” Mazza said.
For IntraHealth, global reach is a primary advantage. “When I had a physical server in South Sudan or Ethiopia,” said Almario, “it’s a prayer to get remote desktop protocol (RDP) access, and even more if I try and run it through an encrypted tunnel. Using an Azure bastion to any of my virtual machines is great. It’s so easy. I can protect it with MFA and it’s just like I’m right there in the data center.” This frees global organizations like his from a past problem: shipping equipment. “I don’t have to worry about things getting smashed or lost or held ransom at customs, and I don’t have to send somebody there to set it up.” As for a challenge, Jojo quipped, “It’s a bit addictive. It’s not only quick, but it’s very easy to set up VM’s and most Azure services.”
Berar summed up the group’s sentiment by saying “The speed at which you can operate is the advantage. The challenge that I found was the rate of change that things changed within Azure, whether it’s movement around a functions in the portal or new capability. Just keeping up with that was a bit of a challenge.”
Big Data: A Growing Theme
When asked what their next steps were in Azure, the panel shared some of their plans.
IntraHealth is continuing on the path with Platform-as-a-Service and more app services. “We’re looking at Docker containerization and utilizing more Azure databases. I’d like to reduce the need for domain controllers in any of our offices–so just further into the cloud and cloud services.”
“We’re actually starting a Microsoft engagement for Azure Synapse for data analytics and warehousing,” said Trans World’s Birnie.
For FHI, Mazza is looking to “Put computing power closest to our users, with local development in country (using Azure Virtual Desktop). If we can enable that through Microsoft, that’s a win all the way around.”
Conclusion
Global NGOs and other nonprofits are realizing the operational and financial advantages of Azure. They’re experiencing business improvements including quicker time to market in global regions, more reliable and highly available in-country services, and better overall security. Yet keeping up with the security options and tracking everchanging capabilities have been a challenge.
All of that is netting out to better returns for donors and more focus on stakeholders.
A common time to get started is when there’s a compelling event, like a disaster recovery plan, an impending renewal, or purchase of equipment.
Getting started typically involves a call with Microsoft or an Azure partner like eGroup | Enabling Technologies for a discovery session to uncover needs, constraints, and requirements. After some rough calculations to prove a financial case, a workshop and/or Planning and Design service will outline the detailed designs, roadmap for action, prerequisites, and specific investments needed. The current state typically defines the deployment and migration path, with services like Azure Site Recovery providing a smooth way to first use the cloud as a backup target, and eventually transitioning to production.
Connect with your eGroup | Enabling Technologies resource for more information on how to succeed in Azure!
Chris SteghCTO & VP of Strategy - eGroup | Enabling Technologies
The post Nonprofit IT Executives Talking Azure appeared first on eGroup.
Using Regular Expressions to Build a Microsoft Purview Custom Sensitive Information Type
Introduction
A colleague of mine needed to create a Microsoft Purview custom Sensitive Information Type (SIT) for a client– The client wanted to use this SIT as part of their implementation of Microsoft Purview. The client needed the SIT to match on occurrences of an organizational identifier that met specific criteria. There is a library of available SITs, but none of them were applicable. SITs are leveraged by several components in the Purview product family and in other areas of the Microsoft compliance universe.
This article will show how you can use Regular Expressions (RegEx) to help create a matching pattern in the “Primary Element” of a custom SIT. We will not be discussing how to configure the other three (3) components of the pattern in the SIT. We will begin with what a SIT is and how they are used in the Microsoft Purview solution suite to protect organizations and their priceless information assets. Microsoft Purview is a cornerstone solution that eGroup | Enabling Technologies uses to help our customers implement and maintain our overriding information security and compliance philosophy:
Sensitive Information Types
Sensitive Information Types (SITs) are used to identify and classify sensitive “items” that are in your organization’s data inventory. There are four (4) types of SIT:
Microsoft Purview Data Loss Prevention Policies
Sensitivity labels
Retention Labels
Insider Risk Management
Communication Compliance
Auto-Labelling Policies
Microsoft Priva
SITs are used to detect sensitive information in an organization’s documents, files, emails, chats, etc. Policies can be created to take an action if the SIT gets a match. For example, a policy:
Detect and manage the transfer of an employee’s personal data within the organization as required by the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA) and other similar regulations Every SIT has a Name, Description, and a Pattern. The Pattern is the definition of what the SIT is looking for. It is composed of four (4) components:
Primary Element: This is what is being looked for. It can be a RegEx, keyword list, keyword dictionary or a function.
What are Regular Expressions (RegEx)?
Regular Expressions (RegEx) have been around since 1951. The concept was originated by mathematician Stephen Cole Kleene. It is a syntax that can be used to search for a pattern in text. They can be used in “find” or “find and replace” operations. They first came into popular use in Unix text-processing utilities. RegEx has been incorporated into most common programming languages including:
If you aren’t confused at this point, the SITs have some additional RegEx validation rules that you need to be aware of. Believe me, if you violate any of these rules, Microsoft 365 will let you know!
At eGroup | Enabling Technologies, we have been using RegEx for over a decade. RegEx has been the required syntax when creating telephone number Normalization Rules in Dial Plans from the days of Live Communications Server 2005 through Lync, Skype for Business, and Microsoft Teams. Some Session Border Controllers also use RegEx in their manipulation engines. The most common Dial Plan Normalization Rules translate four (4) digit telephone extensions (5100) dialed by a user into twelve (12) digit e.164 phone numbers (+14436255100).
There are many sources and resources available on the web as well as those old-fashioned things called books! RegEx is supported in many programming languages. If you want to learn RegEx in general, avoid using a resource specific to a programming language, you won’t get the full picture. Creating the Custom Sensitive Information Type
You can create a custom SIT in the Microsoft Purview Compliance Portal. They can also be created offline in an XML file called a rule package. A colleague of ours wrote about this a few years ago, How to Create Data Loss Prevention Custom Sensitive Information Types.
Client Criteria and Initial RegEx RuleThe client asked us to create a SIT that would produce a match if a number in a document, e-mail, chat, etc. matched the definition of an organizational identifier with these criteria:
Digits can be repeated sequentially up to three (3) times Here are examples of numeric strings that meet the criteria:
1234567891
1112211122 And non-matching numeric strings:
0234567891
Creating the Custom SIT1. Sign in and navigate to the Microsoft Purview Compliance Portal, https://compliance.microsoft.com/homepage 2. Click on “Data classification” 3. Click on “Sensitive info types”
Click “Create sensitive info type”
Type in a name in the “Name” field for the SIT
Add a description to the “Description” field. Descriptions are required.
Click the “Next” button
Click “Create pattern”
Click the “+ Add primary element” drop-down
Click on “Regular Expression”
In the “ID” field, type in a name for the Regular Expression
Paste the RegEx into the Regular Expression field. Obviously, even though the rule’s syntax was fine in the tool we used to create it, Microsoft 365 didn’t like the syntax. We’ll discuss this below.
Select “String Match”. A match will occur even if the matched number is contained within preceding and/or ending text. The rule would match for “ID:1234567891Number”. If you select “Word Match”, the rule will only match instances of the string that “stand” by themselves. The example string would not match if you had selected “Word Match”.
After fixing the syntax, the errors will clear
Click the “Done” button
Change the “Character proximity” as needed
Add “Supporting Elements”
Click the “Create” button
Click the “Next” button
Select a Confidence level
Click the “Next” button
Click the “Create” button
Wait for the SIT to be created then click the “Done” button
Testing the Custom SIT1. Click in the “Search” box and type in part of the name of the new rule 2. Double-click on the name of the rule 3. Click the “Test” button
Click “Upload file”
Select the test file.
Click the “Open” button.
Click the “Test” button.
Wait for the test to complete, review the results.
Click the “Finish” button.
Correct the SIT as needed.
The Primary Element’s RegEx Rule of the SIT
(?!\d{0,6}(0{4}|1{4}|2{4}|3{4}|4{4}|5{4}|6{4}|7{4}|8{4}|9{4})\d{0,6})(?!(0))\d{9}(?!(0))\d
All these risk reductions are real, they are valuable, and they should be a part of any discussion about moving systems or applications to the cloud. This isn’t to minimize the shared responsibility model that we all need to follow (see Microsoft’s diagram of this below), but up to half (half!!) of the boxes below are Microsoft’s responsibility, depending on the system. Oh, except for on-premises. You have to manage that. All on your own….
High-Level Breakdown of the RegEx Rule1. Look for a string of numbers that begins with zero (0) to six (6) digits and ends in zero (0) to six (6) digits. 2. If this group of numbers contains any digit that has repeated four (4) times, the match fails. 3. If the match is still possible, check to see if the first digit is a zero (0), if it is, the match fails. 4. If the match is still possible, match on a string of numbers, nine (9) digits long. If there are fewer than nine (9) digits, the rule fails. 5. If the match is still possible, check if there is a tenth digit. If there isn’t, the match fails. 6. If the match is still possible, check to see if the tenth digit is a zero (0), if so, the match fails. 7. The match succeeds with the string of numbers matching the criteria for the organizational identifier. First Matching Section Detail(?!\d{0,6}(0{4}|1{4}|2{4}|3{4}|4{4}|5{4}|6{4}|7{4}|8{4}|9{4})\d{0,6})
The entire section is enclosed with (?!……). This construct says that if there is a match based on the RegEx that appears between the “?!” and the “)”, the entire RegEx expression fails. If this first construct fails, don’t even bother trying the rest of the constructs, the rule fails and does not match the submitted numeric string. Second Matching Section Detail(?!(0))
Having passed the first test, this section asks if the first digit in the numeric string is a zero (0).
If it is, this construct fails, don’t bother testing the rest of the rule and fail the match. Third Matching Section Detail\d{9}
This section looks for any nine (9) digits. These can be any digit between zero (0) and nine (9).
If there are fewer than nine (9) digits, the construct and the rule will fail. Fourth Matching Section Detail(?!(0))\d
If we’ve made it this far, we have matched nine (9) digits where:
This rule checks to make sure the tenth digit is not a zero (0). If it is, the construct and the rule will fail to make a match. Summary
Sensitive Information Types (SIT) are fundamental elements in an organization’s implementation of the Microsoft Security and Compliance suite of products.
eGroup | Enabling Technologies is available and ready to help you harden and protect your organization and its information assets. SITs and custom SITs are basic components used by many of the security and compliance tools in the Microsoft product family. Determining which SITs you need to leverage or create is not always straightforward.
We have been writing RegEx rules for the Microsoft Unified Communications products and using them in various programming projects, PowerShell scripts, etc. for over fifteen (15) years. The need to use RegEx when creating custom SITs is something we are very comfortable with and ready to assist our customers in their implementation.
This series is part of our effort to help our customers implement a “Trust No One and Harden Everything” security infrastructure. If you need help in planning and implementing your organizational security infrastructure, please contact us!
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
The post Using Regular Expressions to Build a Microsoft Purview Custom Sensitive Information Type appeared first on eGroup.
Configuring Internet Firewall Rules for Microsoft Teams Direct Routing
Introduction
This is the fourth in a series of articles on hardening AudioCodes Session Border Controllers (SBCs). The series is mostly following the guidance provided by AudioCodes. These configuration notes are referenced at the end of this article. These articles are components of eGroup | Enabling Technologies’ security mantra:
We are going to look at the rules that need to be added to an organization’s internet-facing firewall to provide connectivity between Microsoft Teams and AudioCodes SBCs configured to support Teams Direct Routing:
In the previous article in this series, Separation of Un-trusted Network Traffic on AudioCodes SBCs, we talked about the concept of trusted and untrusted interfaces on an AudioCodes SBC. Most SBCs will have:
It is a well-accepted and understood practice to deploy a firewall solution between the internet and an organization’s DMZ and trusted networks. The main purpose of a firewall is to block all inbound traffic from the internet while only allowing permitted bidirectional traffic to be routed to the organization’s DMZ and trusted networks.
Dedicated circuits or direct connections between an organization and a vendor usually bypass the organization’s internet firewall. Most SIP Trunk vendors when implementing a dedicated SIP Trunk circuit will install their own SBC(s) or SBC/firewall combination on the organization’s premises. The vendor SBCs are then cross-connected to an untrusted interface on an AudioCodes SBC over a small, dedicated network with between two (2) and four (4) endpoints. Hardening the SBC protects it from unwanted traffic coming from the vendor’s equipment much like the organization’s own internet firewall.
Microsoft Teams Direct Routing Firewall Requirements
The firewall requirements for the different Microsoft and Office 365 tenants can be found on the Plan Direct Routingweb page. For each type of tenant, the web page provides the:
***These are not the firewall requirements for Microsoft Teams traffic. These can be found on the Office 365 URLs and IP address ranges web page.
On Windows Servers running the Azure Monitor Agent, use data collection rules to define the data to collect from each agent. Besides for the predefined sets of events that you can select to ingest, such as All events, Minimal, or Common, data collection rules enable you to build custom filters and select specific events to ingest. The Azure Monitor Agent uses these rules to filter the data at the source, and then ingest only the events you’ve selected, while leaving everything else behind.
Microsoft 365, Office 365, and Office 365 GCC Tenants
Microsoft Office 365 DOD Tenants
Microsoft Office 365 GCC High Tenants
Teams Media Port Ranges and Media Realms on the SBC
In a previous article in this series, Separation of Un-trusted Network Traffic on AudioCodes SBCs, the physical and logical separation of the SIP traffic traversing the SBC was discussed. On the logical side, we talked about each SIP service (Teams, SIP Trunks, ERSPs, etc.) having its own set of defined parameters. Each SIP service on the SBC should have its own:
SIP signaling traffic is usually configured on ports in the 5060 to 5075 range. To avoid these ports, the default starting port for SIP media on an AudioCodes SBC is 6,000 with the available ports extending to 65,535. When defining a Media Realm port range, you need to specify the starting port and number of media session legs. The ending port is calculated based on these inputs. We are not going to dive deeper into the nuances of configuring Media Realms in this document. Typical practice is to separate the starting ports of the ranges by 1,000 and configure 100 media session legs. Each of these ranges would have 1,000 ports and no overlapping. This is assuming that the “UDPPortSpacing” parameter on the SBC is set to ten (10).
On a new SBC, the Media Realm for the LAN (trusted) interface would usually start at port 6,000 and extend to 6,999. If Teams is the first SIP service added to the SBC, the ports in its realm should be from 7,000 to 7,999. It is this range that is referred to as the “SBC Media Realm Range for Teams” in the tables above. In the tables, 7,000-7,999 can be inserted in the cells that currently say, “SBC Media Realm Range for Teams”.
The next SIP service added to the SBC will have its Media Realm setup for ports 8,000 through 8,999.
Teams Media Bypass and Teams Local Media Optimization (LMO)
Teams Media Bypass and Teams Local Media Optimization (LMO) are optional features that can be enabled on Direct Routing SBCs. Both reduce the number of hops and improve performance for SIP Media traffic between Teams endpoints and the Session Border Controller. Enabling Media Bypass requires the addition of several more firewall rules. LMO requires the same set of rules on the organization’s internet firewall. If there is a firewall between the internal endpoints and the trusted interface of the SBC, additional rules may need to be added to this firewall.
Microsoft Office 365 DOD Tenants
Microsoft Office 365 GCC High Tenants
Firewall Rules for SIP Trunks, ERSPs and other SIP Entities
Here is some generic guidance on configuring these rules for over the internet connections to a SIP Service provider:
SIP Signaling rules
The first layer of defense for the untrusted interfaces of a Teams Direct Routing SBC is the organizations internet facing firewall.
eGroup | Enabling Technologies is available and ready to answer any questions that you might have about defining the required organizational internet firewall rules for Teams Direct Routing. While we did not go into Media Bypass and Local Media Optimization in depth, we are ready to show you how these features can improve the performance of SIP media for your Direct Routing users.
This series is part of our effort to help our customers implement a “Trust No One and Harden Everything” security infrastructure. If you need help in implementing Teams Direct Routing or a security infrastructure for your organization, please contact us!
Bibliography
AudioCodes has written documents addressing security on their Session Border Controllers and Gateways. There are versions for the 7.2 and 7.4 firmware in which they discuss the importance of setting up the SBC’s firewall rules:
The AudioCodes SBC user manuals can also be found in the Library section of the AudioCodes website.
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
The post Configuring Internet Facing Firewall Rules for Microsoft Teams Direct Routing appeared first on eGroup.
How to Save on Sentinel’s Recurring Costs
While Microsoft Sentinel is a powerful tool to identify and resolve sophisticated cyber attacks, organizations who pilot without taking preliminary steps to minimize costs might experience some sticker shock. This blog outlines some of the more obvious and subtle optimizations that are often missed.
Don’t Go with Pay-As-You-Go
Organizations who plan on ingesting a significant amount of data from third party sources like firewalls, servers, and third party services will pay nearly twice as much on a pay–as–you–go plan than when selecting a “commitment tier.” This is a committed payment whether it’s used or not, so it’s rare that pilots are set up with a commitment, especially since ingesting logs from (most) Microsoft 365 services are free. But when you get started on pay-as-you-go and extrapolate the first costs to the potential worst case, remember it’s not a linear equation. As you approach the bare minimum for a commitment tier (100GB/day), remember to change it. The more logs ingested/committed, the cheaper the per GB.
Pay-as-you-go costs ~$4.76/GB, making the minimum savings of a commitment tier ~38%.
Create a Separate Log Analytics Workspace
Sentinel is Microsoft’s AI-enabled Security Information and Event Management (SIEM) service, while Log Analytics is the repository storing the logs that Sentinel analyzes. Isolating the security logs in their own Log Analytics workspace keeps Sentinel analyzing only relevant data and keeps costs down. Store any other log in its own workspace.
Ingestion Costs Don’t Have to Cause Indegestion
Whether on pay-as-you-go or a commitment tier, ingesting pointless data to Sentinel is wasteful. You can filter incoming data before it’s stored in the Log Analytics workspace where it would start costing money.
There are two types of logs that you can opt to ingest. To get the full value of Sentinel as an early warning system, Analytics Logs are the standard.
The easy yet debatable way to reduce ingestion is by using Basic Logs. Basic logs are best for data with low detection value, but good for forensics. Netflow, TLS certificate monitoring, and cloud storage access logs are good examples. They aren’t going to be the first triggers of an incident but could identify breadcrumbs as you do forensics on a suspected breach. There’s an extra fee to search/analyze basic logs.
In a nutshell, Basic Logs are an option appropriate for budget-conscious organizations who don’t plan to actively use the SIEM for proactive detection and resolution– but who may need to check a box to have a SIEM for a compliance requirement. SIEM expert Rod Trent wrote a good blog about When to Use and When NOT to Use Basic Logs with Microsoft Sentinel
Now, back to the standard Analytics Logs. What can be done to manage their costs? A somewhat sophisticated way to streamline ingested data is to ‘transform’ the logs before they hit the Log Analytics workspace. Log Analytics’ custom data ingestion process gives you a high level of control over the data that gets ingested. Transforming could mean removing redundancies (i.e. two firewalls in an HA pair sending similar logs) or truncating logs from the device. For instance, there Syslog has eight levels of severity, ranging from Emergency to Debug. Customers rarely need all eight. You can configure the device itself to send a specific level of logs, and you can use Log Analytics’ Data Collection Rules to filter unwanted logs.
On Windows Servers running the Azure Monitor Agent, use data collection rules to define the data to collect from each agent. Besides for the predefined sets of events that you can select to ingest, such as All events, Minimal, or Common, data collection rules enable you to build custom filters and select specific events to ingest. The Azure Monitor Agent uses these rules to filter the data at the source, and then ingest only the events you’ve selected, while leaving everything else behind.
Retention Rules Help Retain Budget
After their eight days of normal life, basic logs can be archived to store the data for longer. Standard logs can also be archived, after their 90 days of free storage. Instead of leaving logs in standard storage at full cost, organizations can archive data for up to seven years at a lower cost, shown below. When needed for an audit or review, extracting the data again comes with a fee/GB.
Other Means to Get Lean and Mean
There are several other techniques that can Reduce costs for Microsoft Sentinel beyond the major savers above.
While Sentinel is generally cheaper than Splunk and other SIEMs, it can seem expensive if left with its defaults. These techniques will be helpful in reducing costs, but should be carefully set up so as to not miss an important incident.
Chris SteghCTO & VP of Strategy - eGroup | Enabling Technologies
The post How to Save on Sentinel’s Recurring Costs appeared first on eGroup.
Risk Reductions – The Cloud Benefit We Don’t Talk About
Most cloud decisions that I have been a part of in the past, or help clients with today, are typically dominated by budget, security, functionality, and adoption considerations. While these are all extremely important, risk reductions outside the security space often go unrecognized. These other risk reductions are the unsung benefits of the cloud, and they don’t receive the attention they should– They are also compelling reasons to start making the shift.
I am sure there are plenty more examples than the ones I outline below, but these are the risks I have personally been able to help organizations avoid with cloud solutions.
Facility and Environmental Risks
These are the most obvious, but also the most common. Whether you are hosting your infrastructure yourself or at a colocation facility, these are all tough (and costly) to mitigate.
On-premises systems often evolve over time and end up more complex, and not nearly as “standards-driven” as cloud deployments typically are.
Vendors can always present risk and require attention. That being said, large enterprise public cloud providers present less risk to an organization than smaller development, hosting, and colocation companies.
As I have mentioned in previous posts, compliance is really an extension of security technologies in many ways. One of the easiest ways to simplify compliance efforts is to reduce what you have to manage and keep compliant yourself.
Despite everyone’s best efforts, disruptions and data loss can still occur. If they do, being able to recover quickly and reliably is much easier in the cloud. Geographic diversity and the sheer scale of the cloud environment opens up entirely new opportunities to improve recovery capabilities without enormous investments of time and money.
Tom PapahronisStrategic Advisor - eGroup | Enabling Technologies
The post Risk Reductions – The Cloud Benefit We Don’t Talk About appeared first on eGroup.
Virtual CISO – An Appealing Alternative to CISO
The cybersecurity market is in a state of influx as it matures into a more mainstream information technology service. As the number of cyber-attacks from e-mail phishing to sophisticated data farming are exponentially growing, there are not enough cyber security experts to keep up with the demand.
Job Demand
According to a report from Emsi Burning Glass Market Research firm (now Lightcast), there are well over 700,000 cyber security positions yet to be filled, and existing cyber security engineers are in-high demand. There are several reasons for this massive gap in the marketplace, including the growing number of cyber incidents (i.e. ransomware), regulatory requirements demanding qualified cyber security specialists at both the federal and state levels, a lack of adequately educated and experienced cyber security professionals to address these challenges, and cyber insurance providers demanding investments by their insurer to harden their security posture.
Supply has not kept up with the demand and it has become increasingly challenging to recruit and retain qualified professionals, not to mention the continual increase of their wages. It is also important to note that in many cases, it is difficult to justify the cost or need for a full-time CISO-Level employee. Given this growing trend, most small to midsize organizations as well as various public sectors and non-profit organizations are faced with a crucial decision of meeting their cybersecurity needs while struggling to justify the growing expenditure. To address this gap and to provide organizations with qualified cyber security professionals at a much lower expense, a growing market trend is emerging. The concept is to recruit an information security officer from a reputable firm on a part-time basis with a time-limited contract to assist the organization in meeting its cyber security goals. They are referred to as a Virtual Chief Information Security Officer (vCISO). While there are ample individuals and firms that offer cyber security services, the key differentiators are the quality, experience, expertise, and access to other cybersecurity resources.
The Power of a vCISO
The latest report from CSO magazine argues that vCISOs are estimated to cost between 30% to 40% of a full-time CISO, and they are available on-demand with no training requirements. Therefore, they are able to deliver results in a short timeframe. Given that their role is a time-limited engagement they will remain objective, and their primary focus is getting a satisfactory result on an on-going basis, based on the pre-defined/pre-negotiated key performance indicators (KPIs).
Several large consulting firms have adopted the philosophy of over-hiring cyber security engineers with the understanding that most will not make it past the first few months and the field will correct itself by weeding out some of these individuals. The idea is to show clients that they have resources and strength in numbers. Unfortunately, this approach is short-sighted, and these underqualified experts could potentially cause more damage and create bigger issues for their clients down the road. It is imperative that organizations seeking a vCISO do their due diligence and work with a reputable firm. It is never the size of a firm that dictates their quality, but instead their reputation, work ethics, expertise, and most importantly their experience and positive client relationships. Many smaller IT delivery firms have a much better story to tell when it comes to engaging in the process of drafting a vCISO as a service.
There are a number of organizations that have opted to assign a member of their cyber security team to fulfill the role of an information security officer in addition to maintaining their daily assignments. This is challenging since these individuals will inevitably suffer fatigue due to the on-going volume of activities, and they might become a flight risk as well. Furthermore, most of these cyber security engineers favor their technical interest over their newly added assignments that includes—but is not limited to—policy review and development, security planning, security awareness programs, incident response planning and simulation, budgeting processes, staff assessment, management and mentorship, and engagement with cyber insurance negotiations. To avoid this potential adverse effect, it would be more practical to augment the team by commissioning an external vCISO. In addition to managing daily activities, these individuals could play a pivotal role in assessing the organization’s overall security posture and making objective recommendations.
Finding an Impactful vCISO
One area where a vCISO could provide an immediate impact is evaluation and implementation of a few key programs to reduce or to sustain the cyber insurance premium adjustments. The cyber insurance market is expected to grow from seven billion dollars to twenty billion dollars in the next four years, based on a study by Fortune Business Insights. While the number of claims has grown by 100% during the past three years, naturally, these providers will continue to pass the increase of their liabilities on to their clients. A stark contrast in a report published in netdiligence.com points out that in 2021, 99% of claims involved small to mid-size enterprises (SME) organizations (below two billion dollars in revenue), while only 1% of claims involved enterprise-class organizations. SMEs that have difficulties hiring or rationalizing a full-time CISO are poised to take advantage of vCISO services.
An organization embarking on the journey of selecting a firm for vCISO services should consider the following seven guiding principles:
There are two famous quotes that come to mind with enormous relevancy in the process of evaluating and ultimately selecting a vCISO firm: first is an African proverb– “Tomorrow belongs to people that plan today.” Second, is George Patton’s statement, “A good plan today is better than a perfect plan for tomorrow.” While keeping these in mind, it is prudent to start the discussion about the merits of using a vCISO sooner than later, given the attention that a cyber security area requires on an on-going basis. Anticipate that there will be adjustments to the statement of work. The outside view of the vCISO will surely bring new perspectives and areas of consideration to the organization. To facilitate thoughtful planning, below is a list of services that should be expected or examined as part of the initial phase of engaging with a vCISO firm.
Responsibilities of a vCISO
vCISO services include but are not limited to:
eGroup | Enabling Technologies security experts and vCISO teams have extensive experience in various aspects of information security architecture. These C-level executives replicate the job function of a Chief Information Security Officer. They are positioned to provide guidance, develop policy, assess organizational security readiness, engage in evaluation of risk mitigation, deliver security gap analysis, and participate in auditing and compliancy processes while keeping an eye on the day-to-day activities.
Mehran BasiratmandCIO Strategic Advisor - eGroup | Enabling Technologies
The post Virtual CISO – An appealing alternative to CISO appeared first on eGroup.
Separation of Untrusted Network Traffic on AudioCodes SBCs Introduction This is the third in a series of articles on hardening AudioCodes Session Border Controllers (SBCs). The series is mostly following the guidance provided by AudioCodes. These articles are listed at the end of this article. AudioCodes recommends untrusted network traffic be both physically and logically separated...
The post Separation of Untrusted Network Traffic on AudioCodes SBCs appeared first on eGroup.
The Journey to Zero Trust The Zero Trust concept has been around for a while now, and the rise of remote work related to COVID lockdowns supercharged the Zero Trust conversation. Many organizations had to scramble to enable employees to work remotely but did not have technology environments that were prepared for it. As a...
The post The Journey to Zero Trust appeared first on eGroup.
Improving Cloud Security Policies Our Strategic Advisors find a consistent gap when reviewing our customers’ security policies: a lack of focus on cloud computing. Even in organizations with many traditional policy documents, there’s a lag in updating them for cloud technologies like Microsoft 365. Additionally, the gap widens when it comes to documenting the standard...
The post Improving Cloud Security Policies appeared first on eGroup.
The Value of the Roadmap Since making the transition to consulting from technology leadership roles, I am constantly surprised at how many organizations have not documented and agreed upon a technology roadmap, yet have spent enormous amounts of money and time purchasing licensing, hardware, and applications. This usually leads to an environment with overlapping products,...
The post The Value of the Roadmap appeared first on eGroup.
UPDATE! AudioCodes SBC Configuration Update for Teams Direct Routing Introductions On October 26, 2022, AudioCodes published 0483 Product Notice – SBC Security Configuration update for Microsoft Teams Direct Routing. The article provides configuration information to mitigate a recently discovered vulnerability in the Session Border Controller (SBC) configuration for Teams Direct Routing that had been previously...
The post AudioCodes SBC Configuration Update for Teams Direct Routing appeared first on eGroup.
5 Ways to Help Remote Workers Be More Effective As we continue to dissect the trends in remote work, we reflect on how to optimize this new work/life style for our users. Prior to the pandemic, less than 20% of U.S. employees reported working from home 5 days or more per week. Fast forward to...
The post 5 Ways to Help Remote Workers Be More Effective appeared first on eGroup.
Compliance as Security Technology One of my favorite security analogies is that enterprise information security is like an onion. Each layer of the onion represents a different control that secures the data at the center. Common layers are endpoint protection, mobile device management, MFA, firewalls, encryption, security policies, and staff training. All of these (and...
The post Compliance as Security Technology appeared first on eGroup.
New Microsoft Defender Security Tools: MDEASM and MDTI Cybersecurity is ever-changing. New attacks and techniques are practically created every day. Organizations are getting more complex with multi-cloud environments. Data is exponentially growing and we are losing visibility into our assets due to poor governance. Last week, Microsoft announced two new Defender solutions as a result...
The post New Microsoft Defender Security Tools: MDEASM and MDTI appeared first on eGroup.
How to Implement Zero Trust Without Being Tarred and Feathered “Zero What?” So what does Zero Trust mean? Zero Trust has been a term that has been around a long time. Remember the X Files? Agent Molder would always tell his colleagues – “Trust no one”. That pretty much sums it up. You don’t trust...
The post How to Fearlessly Implement Your Zero Trust Strategy appeared first on eGroup.
New Microsoft Usage Workshops Many Microsoft cloud customers have taken advantage of incentive programs like workshops and deployment funds. Microsoft’s thinking is that by reducing the fees normally charged by qualified partners, customers pay less for a smooth onboarding of new tools and processes. To kickoff cybersecurity month, Microsoft is giving qualified customers a chance...
The post New Microsoft Usage Workshops appeared first on eGroup.
Cyber Insurance Requiring MFA Everywhere Cyber insurance providers are tightening their requirements for Multifactor Authentication. For starters, they are being more verbose about the systems and services on which MFA is enabled. They’re making what had been a very broad question into a set of discrete questions. Essentially, what was “Do you have MFA enabled?”...
The post Cyber Insurance Requiring MFA Everywhere appeared first on eGroup.
Microsoft Teams Direct Routing and Mutual TLS Authentication Introduction Microsoft Teams Direct Routing AudioCodes Session Border Controllers (SBCs) have usually been setup using one-way TLS (Transaction Layer Security) authentication. Enabling mutual TLS authentication has always been an option. Enabling Technologies (a division of eGroup) has two (2) primary mantras when it comes to application and...
The post Microsoft Teams Direct Routing and Mutual TLS Authentication appeared first on eGroup.
InSite Moves from Skype to Microsoft Teams Voice Competing in the commercial real estate market takes constant communication and 24×7 availability. For InSite Real Estate, L.L.C., Microsoft Teams is providing reliable phone and collaboration services from the cloud. As a leading commercial real estate and industrial developer, InSite buys, custom-develops, and then operates income-producing real estate. InSite owns...
The post InSite Moves from Skype to Microsoft Teams Voice appeared first on eGroup.
Zerto Linux- Zerto Virtual Manager is finally here! -Mike Dent’s take on the latest release of ZVM- Finally, Zerto has released a Linux based appliance for the Zerto Virtual Manager (ZVM) role! Now to be clear, I don’t mean to use the term “finally” in a negative sense with Zerto, more of a sense of happiness...
The post Zerto Linux Zerto Virtual Manager – Finally! appeared first on eGroup.
10 Consecutive Years!eGroup Recognized by CRN’s 2022 SP 500 List Charleston, South Carolina, June 1st, 2022 — Today eGroup announces that CRN®, a brand of The Channel Company, has named eGroup to its 2022 Solution Provider 500 list for the TENTH year in a row. CRN’s annual Solution Provider 500 ranks North America’s largest solution...
The post 10 Consecutive Years! eGroup Recognized by CRN’s 2022 SP 500 List appeared first on eGroup.
Charleston ENT & Allergy enlists eGroup for a Technology Portfolio Optimization Assessment (TPOA) Since 1997, Charleston ENT & Allergy’s mission has been to serve the people and families of South Carolina with superior, comprehensive, and convenient care. Their commitment to these core values has allowed Charleston ENT & Allergy to expand from one to seventeen...
The post Charleston ENT & Allergy enlists eGroup for a Technology Portfolio Optimization Assessment (TPOA) appeared first on eGroup.
eGroup Acquires Enabling Technologies Corp CHARLESTON, SC, May 2, 2022 /PRNewswire/ — eGroup Holding Company, LLC (eGroup), a leading IT solutions and managed services provider, announced that it has acquired Florida-based Enabling Technologies Corp (Enabling). The acquisition—which closed on April 29, 2022, will expand eGroup’s reach nationally in the U.S. and dramatically expand its Microsoft 365, Azure, Security & Compliance, and...
The post eGroup Acquires Enabling Technologies Corp appeared first on eGroup.
For the 6th Consecutive Year- eGroup Recognized by CRN’s 2022 MSP 500 List eGroup Recognized on CRN’s 2022 MSP 500 List eGroup announces today that CRN® a brand of The Channel Company, has named eGroup to its Managed Service Provider (MSP) 500 list in the Pioneer 250 category for 2022. CRN’s annual MSP 500 list identifies...
The post For the 6th Consecutive Year- eGroup Recognized by CRN’s 2022 MSP 500 List appeared first on eGroup.
eGroup Announces Christa Anderson as Director of Alliances eGroup is thrilled to announce the addition of Christa Anderson as Director of Alliances. In this role, Christa will join the executive leadership team at eGroup and be responsible for the management and development of all partner alliance activities – working across all eGroup business units to...
The post eGroup Announces Christa Anderson as Director of Alliances appeared first on eGroup.
eGroup Founder Mike Carter recognized as 50 Most Influential by Charleston Business Magazine eGroup Founder Mike Carter was recognized as one of the 50 Most Influential by Charleston Business Magazine. eGroup is thrilled to announce that Founder and Principal, Mike Carter has been named to Charleston Business Magazine’s 50 Most Influential for the second consecutive...
The post eGroup Founder Mike Carter recognized as 50 Most Influential by Charleston Business Magazine appeared first on eGroup.
Evolute Capital, along with Hunt Technology Ventures, Make Strategic and Substantial Investment in eGroup Evolute Capital, along with Hunt Technology Ventures, Make Strategic and Substantial Investment in eGroup [Charleston, SC – October 13, 2021] eGroup is excited to announce that they have received a substantial investment from Evolute Capital, a Dallas, Texas-based middle-market private equity investment...
The post Evolute Capital, along with Hunt Technology Ventures, Make Strategic and Substantial Investment in eGroup appeared first on eGroup.