Petri IT Knowledgebase: Recent Episodes

None

Petri IT Knowledgebase is one of the most comprehensive IT related web sites. With hundreds of MS Windows Client and Server related tips, tricks and how-to articles, Petri.co.il has become one of the world's leading MCSE and IT related knowledge bases.

View Details

Key Takeaways:* Microsoft Teams will soon support custom emojis and reactions, a highly requested feature that will enhance user expression in chats. * New slash commands in the compose box enable users to perform various tasks quickly, such as adding code blocks, controlling presence indicators, and muting chats. * Microsoft Loop has added support for code blocks and Adaptive Card-based Loop components.

Microsoft detailed today several new features coming to Microsoft Teams and Loop to help users collaborate more effectively with colleagues. The company is adding support for custom emojis and reactions in public preview to Microsoft Teams chats next month.

Custom emojis and reactionsIn Microsoft Teams, custom emoji support is one of the top-requested features that rival collaboration platforms like Slack and Discord had for many years. This new capability will allow employees to better express themselves while collaborating in Microsoft Teams chats. Microsoft says that it will be up to the IT admins to give permission to users to create, delete, and disable custom emojis in Microsoft Teams.

Slash commands in the compose boxMicrosoft Teams has added support for slash (/) commands to the message compose box for both chats and channel conversations. It will allow users to add a code block or a loop component to their message, control their presence indicator, mute a chat, navigate to settings, and perform other frequent tasks. This feature is supported in the Microsoft Teams desktop, web, and mobile clients.

Unfurling permalinksWhen a developer shares a code snippet using a permalink in a Microsoft Teams chat, it automatically expands to display a detailed preview from Microsoft Azure DevOps. This feature allows the recipient to view the code directly in the source application.

Unfurling permalinks (Image Credits: Microsoft)Microsoft Loop-supported Code BlocksMicrosoft has started rolling out support for code blocks for its Loop app. This new feature allows users to insert code into a Loop component and convert a native Code Block to a Loop component. Users can share the Loop component in Microsoft Outlook as well as Microsoft Teams chats and channels.

Mermaid integration into Loop Code BlocksAdditionally, Microsoft has added new Mermaid integration to Loop Code Blocks. This new feature allows developers to collaborate with team members on technical discussions and documentation directly from a Loop page. Mermaid is a JavaScript-based diagramming and charting tool that lets users create complex diagrams and visualizations with a text-based syntax.

Adaptive Card-based Loop componentsLast but not least, Microsoft now lets users insert Adaptive Card-based Loop components from Confluence Cloud, Trello, Jira, Mural, Lucid Software, and Priority Matrix in Microsoft Teams chats and channels. The company plans to roll out this feature to Outlook users in the coming months.

In case you missed it, Microsoft announced today that Teams Premium is getting new AI-powered features and enhanced data protection features next month. We invite you to checkout our separate post for more details.

The post Build 2024: Microsoft Teams and Loop Add New Collaboration Features appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced AI-powered features and enhanced data protection for Microsoft Teams Premium customers. * Microsoft is also adding new admin controls to prevent content sharing in externally hosted meetings. * Microsoft has announced updates for custom app experiences in Teams, including sharing SharePoint files, PowerPoint Live support, and Live reactions.

Microsoft unveiled several updates for its Microsoft 365 suite of services at the annual Build developer conference. The company announced today several new AI-powered features and additional data protection capabilities for Microsoft Teams Premium customers.

Microsoft Teams will add intelligent recap support for meetings with only transcription enabled. It will allow meeting participants to access AI-generated tasks, meeting notes, and name mentions. Microsoft plans to make this new feature generally available in Teams Premium and Copilot for Microsoft 365 in June 2024.

Microsoft Teams Premium is getting a new feature that will enable organizers to control who can record and transcribe when scheduling meetings. Organizers will be able to select from two meeting options: organizers and co-organizers or organizers, co-organizers and presenters. This capability will be available for all Microsoft Teams Premium customers in June 2024.

Microsoft has introduced new admin controls that prevent attendees from sharing content in externally hosted meetings. This feature provides an additional layer of protection against potential data exfiltration from external participants.

Updates for custom app experiences connected to Microsoft TeamsIn addition to the new Premium capabilities, Microsoft announced new features for custom apps and website experiences connected to Microsoft Teams. It’s now possible to share SharePoint files in Teams chats with users joining from a custom app or web experience. Microsoft has introduced PowerPoint Live support to give both presenters and the audience an inclusive and engaging experience for Teams meetings.

With Live reactions, participants will be able to react with emojis on content (such as a desktop, window, PowerPoint deck, or whiteboard) shared in Teams meetings. Microsoft has also added noise suppression support to minimize disruptions during video calls and Teams meetings.

Lastly, the Call Diagnostics Center allows administrators to detect call quality and reliability issues, including poor internet connectivity and software compatibility issues. Other capabilities include support for real-time transcription via Azure AI Speech, closed captions, and picture-in-picture for iOS and Android.

The post Build 2024: Microsoft Teams Premium Gets New AI Features and Data Protection Capabilities appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft is expanding its Copilot AI assistant beyond personal use to support entire teams, departments, or companies. * Microsoft is enhancing Copilot Studio to allow developers to create custom copilots for automating business processes. * Microsoft says that all extensibility features for Copilot are being consolidated into Copilot extensions.

Microsoft continues to improve Copilot for Microsoft 365 which became generally available for commercial customers in November 2023. The company is getting ready to introduce new Team Copilot to help teams enhance collaboration and streamline project management.

“Team Copilot expands Copilot beyond a personal assistant to act on behalf of a team, a department, or
an entire company. And of course, you’re always in control – assigning tasks or responsibilities to Copilot
so the whole team can be more productive, collaborative, and creative, together,” explained Jared Spataro – CVP, AI at Work, Microsoft.

With this release, Team Copilot will be available for customers in Microsoft Teams, Loop, Planner, and other Microsoft 365 apps. The Copilot AI assistant will serve as a meeting facilitator by automatically managing the agenda and taking notes in Teams meetings.

Additionally, Copilot for Microsoft 365 will work as a group moderator in Microsoft Teams chats. Users will be able to use natural language commands to ask questions and summarize important information to catch up on lengthy conversations. In Microsoft Planner, the AI assistant will automatically create and assign tasks, track deadlines, as well as alerts team members when their input or action is required on a task.

Microsoft plans to release the new Team Copilot capabilities in public preview in the coming months. It will require a Copilot for Microsoft 365 license, which costs $30 per user per month for those businesses with 300 or fewer employees.

Agents: custom copilots Microsoft has introduced new features in Copilot Studio that will allow developers to create custom copilots that act as agents to automate common business processes (such as the end-to-end order fulfillment process). These new capabilities also enable users to reason over actions and user inputs, learn based on user feedback, use memory and knowledge for context, as well as record exception requests and ask for help. The new features, which are currently available in Early Access Program, will become generally available in the coming months.

Additionally, Microsoft now lets organizations create custom copilots in SharePoint. This feature enables employees to ask questions and find information in files and documents stored on SharePoint sites. This new capability is currently available for commercial customers enrolled in Early Access Program, and will be available in public preview by the end of this year.

Copilot Studio – Agent capabilities – Teaching (Image Credits: Microsoft)Copilot extensionsMicrosoft also announced today that it’s consolidating all extensibility concepts of Copilot for Microsoft 365 (such as plugins and connectors) into Copilot extensions. With Copilot extensions, users can tailor the productivity assistant’s actions and integrate it with various business systems. Microsoft says that developers can use Copilot Studio and Teams Toolkit for Visual Studio Code to build Copilot extensions.

Copilot for Microsoft 365 currently supports extensions in preview from Jira, Priority Matrix and Mural, and other popular apps. Enterprise administrators can control and manage access to Copilot extensions through the Microsoft 365 admin center. Microsoft is also adding support for connectors in Copilot Studio to help developers quickly create Copilot extensions.

Copilot Studio – Copilot connectors (Image Credits: Microsoft)Later this year, Microsoft plans to launch the Copilot Trust Platform in public preview for organizations. It should help to enhance the security, ethical standards, and efficiency of Microsoft Copilot for enterprise customers.

In related news, Microsoft has also announced new data protection capabilities for Microsoft Teams Premium customers at Build 2024. The company also detailed several new features for Microsoft Teams and Loop, and you can find more details in our separate post.

The post Build 2024: Microsoft Unveils New Team Copilot to Boost Productivity with Process Automation appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Fluid Framework 2.0 enables developers to easily add real-time collaboration features to new and existing applications. * The new Fluid Framework 2.0 supports Microsoft SharePoint Embedded, allowing developers to store collaboration data within Microsoft 365 tenants. * Microsoft expects to make Fluid Framework 2.0 generally available this summer.

Microsoft has announced a public preview of the new Fluid Framework 2.0 today at its Build 2024 conference. The latest update to the company’s open-source platform is designed to let developers quickly build real-time collaborative apps.

Microsoft’s Fluid Framework debuted back in 2019. It enables developers to build low-latency applications that support real-time collaboration across Office apps. Fluid Framework is designed to change the way people collaborate and update content in Office 365. The framework powers Microsoft Loop, Whiteboard, Microsoft Teams Live Share, and other Microsoft and third-party apps.

Fluid Framework 2.0 offers a schematized data model called a SharedTree Distributed Data Structure (DDS) to add collaboration capabilities to new and existing applications. This new model provides an intuitive programming interface for working with different data types, including arrays, objects, and maps.

“The SharedTree data model is defined by a schema, which enables developers to use Fluid data structures like other TypeScript/JavaScript data structures. This means developers can continue to follow the same programming paradigms for developing local-first apps, while getting the benefits of real-time collaboration through Fluid Framework,” Microsoft explained.

Fluid Framework (Image Credits: Microsoft)Fluid Framework 2.0 supports SharePoint EmbeddedIn addition to Azure Fluid Relay, Fluid Framework 2.0 introduces support for Microsoft SharePoint Embedded. It’s a cloud-based file and document management system that supports collaboration on content stored within a Microsoft 365 tenant. Microsoft highlighted that the new SharePoint Embedded support lets enterprise developers store collaboration data within the users’ Microsoft 365 tenant to comply with security and compliance requirements.

Overall, Fluid Framework 2.0 helps organizations to build collaborative, scalable, and cross-platform applications that enhance productivity and foster seamless teamwork. Microsoft expects to make it generally available this Summer. If you’re interested, you can learn more about how to get started with Fluid Framework 2.0 on the official website.

The post Build 2024: Microsoft Launches Fluid Framework 2.0 in Preview appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Edge for Business will add new screenshot prevention capabilities to protect against data leaks. * A new Edge management service will help IT admins track outdated browser instances to patch zero-day vulnerabilities. * Microsoft Edge will soon offer real-time video translation for popular websites like YouTube and LinkedIn.

At its Build conference this morning, Microsoft unveiled new security features coming to its Edge for Business experience that launched in August 2023. These new capabilities are designed to protect organizations against data leaks and security vulnerabilities.

Microsoft Edge for Business is a new dedicated work experience that allows users to better separate their better separate private browsing activities from work-related tasks. The feature is enabled by default for all commercial customers that use the Microsoft Entra ID service for signing into the browser. Microsoft Edge for Business offers AI-powered features, enterprise-grade security, productivity, and manageability capabilities.

Microsoft Edge for Business (Image Credits: Microsoft)Screenshot PreventionFirst off, Microsoft Edge for Business is getting new screenshot prevention capabilities to prevent data exfiltration in the browser. This security feature will block users from taking screenshots on select web pages that are labeled as protected or sensitive.

Microsoft says that IT admins will be able to configure screenshot prevention policies across Microsoft 365, Microsoft Intune Mobile Application Management, Microsoft Defender for Cloud Apps, and Microsoft Purview. The screenshot prevention feature will become generally available in the coming months.

Stay up to dateWith the Edge management service, IT admins will be able to track outdated managed browser instances. This capability should help organizations to patch zero-day security vulnerabilities that could lead to sophisticated cyberattacks. The service will let administrators perform mitigation activities like enabling enhanced security mode, automatic browser updates, and forcing a browser restart to install updates. Microsoft plans to roll out this feature in preview in the next few weeks.

Real-time video translation coming to Microsoft EdgeLastly, Microsoft announced today that new real-time video translation capabilities are coming soon to its Edge browser. This AI-powered feature will automatically translate video content across YouTube, LinkedIn, Coursera, Reuters, Bloomberg, CNBC News, and other popular websites.

At launch, Microsoft Edge will support video translations from English to Hindi, German, Italian, Spanish, and Russian as well as from Spanish to English. Microsoft also plans to add support for more languages and video platforms, though there is no ETA yet.

The post Build 2024: Microsoft Edge for Business Gets New Security Features to Prevent Data Leaks appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft announced the public preview of the Cobalt 100 Arm-based virtual machines. * The new Azure ND MI300X VM series is now generally available and is optimized for AI and high-performance computing workloads. * Microsoft introduced the Azure Compute Fleet in public preview, designed to streamline the provisioning and management of compute resources across various VM types and availability zones.

Microsoft announced this morning the public preview of the Cobalt 100 Arm-based virtual machine (VM). The company has also announced the general availability of the new Azure ND MI300X v5 VM series.

Microsoft first unveiled its Arm-powered chip Cobalt 100 chip for general-purpose and cloud-native workloads in November last year. The Azure Cobalt CPU is a 128-core processor that’s built on an Arm Neoverse CSS design. Microsoft has already tested its Cobalt 100 chip on workloads like Microsoft Teams and SQL server. The company claims that the Cobalt CPU has performed 40 percent better than Azure’s existing Arm-based chips.

The new Cobalt 100-based VMs should offer efficiency and performance improvements for workloads such as web apps, microservices, and open-source databases. Microsoft claims that users can expect up to 40 percent better performance compared to the previous generation of Arm-based VMs.

ND MI300X virtual machines now generally availableMicrosoft has also announced the general availability of the ND MI300X VM series. The company highlighted that these new VMs are optimized for demanding AI and high-performance computing workloads. For instance, users can build large models from scratch, run inference on pre-trained models, and fine-tune models for specific domains.

“It features an AMD Instinct MI300X AI accelerator, providing each VM with 1.5 TB of high bandwidth memory and 5.2 TB/s of memory bandwidth. These VMs are also connected by NVIDIA Quantum-2 CX7 InfiniBand, offering 3.2 TB/s of scale-out bandwidth per VM, which allows scaling up to thousands of VMs and tens of thousands of GPUs,” Microsoft explained.

Azure Compute Fleet launches in previewMicrosoft has launched a new Azure Compute Fleet in public preview for commercial customers. This new service is designed to make it easier for administrators to provision and manage compute resources in the cloud, across different VM types, availability zones, and pricing models. It helps customers to meet their requirements for scale, performance, and cost-effectiveness.

“Azure Compute Fleet will automatically find an optimal mix of VMs based on customer requirements while matching them to the available compute capacity and prioritizing speed of deployment, cost of operation or a balance of both,” Microsoft added.

Azure Compute Fleet lets administrators use a single API call to deploy and manage up to 10,000 virtual machines concurrently. This capability should be useful for enterprise customers with high computational demands or those requiring extensive parallel processing. The Azure Compute Fleet service also optimizes the use of Spot VMs, which leads to potential cost savings for organizations.

Lastly, Azure Compute Fleet provides users with flexible and automated ways to manage their virtual machine groups. It should help customers adapt to changing conditions like pricing, capacity availability, and Spot VM evictions. Azure Compute Fleet offers automation and simplification of the deployment, management, and cost optimization of large VM fleets.

The post Build 2024: Microsoft Announces New Azure Virtual Machines for AI and Cloud-Native Workloads appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft is expanding the preview of Microsoft Copilot for Azure to all customers. * Microsoft Copilot for Azure leverages natural language commands to help administrators troubleshoot issues, optimize IT environments, and streamline management tasks. * Copilot for Azure now supports additional features, including new skills for Azure Kubernetes Service and natural language to SQL conversion for Azure SQL databases.

Microsoft is broadening access to Copilot for Azure preview to all customers, promising enhanced cloud management capabilities. This expansion comes with a host of new features designed to streamline operations, optimize IT environments, and bolster security.

Microsoft Copilot for Azure enables customers to ask questions, write commands, and design and configure services. It leverages data from across Azure services to help administrators troubleshoot problems. Additionally, it provides recommendations for optimizing IT environments, particularly in terms of spending.

“We created Microsoft Copilot in Azure to act as an AI companion, helping your teams manage operations seamlessly across both cloud and edge environments. By using natural language, you can ask Copilot questions and receive personalized recommendations related to Azure services. Simply ask, “Why is my app slow?” or “How do I fix this error?” and Copilot will navigate a customer through potential causes and fixes,” explained Omar Khan, GM of Azure Infrastructure Marketing.

Microsoft Copilot for Azure (Image Credits: Microsoft)With this release, Microsoft will let administrators provide access to Copilot for Azure to all end users or select users or groups within a tenant. This capability should help IT admins to comply with the operational standards and security policies of their organization.

Microsoft has also announced new features and improvements for Copilot for Azure. The company has added several new skills for Azure Kubernetes Service (AKS) to Copilot for Azure. These new skills should help customers streamline common management tasks like configuring AKS backups, constructing kubectl commands, and locating YAML files.

Microsoft Copilot for Azure SQL streamlines database managementMicrosoft Copilot for Azure has added natural language to SQL conversion support for Azure SQL database-driven applications. The new Copilot experience converts natural language inquiries into T-SQL commands to help IT admins manage databases, track performance and mitigate issues. The Copilot AI assistant lets administrators use natural language commands to diagnose and resolve app issues.

Last but not least, Microsoft Copilot for Azure has introduced Defender for Cloud prompting capabilities to enhance risk exploration, remediation, and code fixes. Moreover, Microsoft Defender External Attack Surface Management (EASM) now leverages the Copilot AI assistant to identify security risks in order to protect customers against sophisticated cyberattacks.

The post Build 2024: Microsoft Expands Copilot for Azure Preview to All Customers appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced new Copilot+ PCs powered by Snapdragon X Elite and X Plus chips. * The new PCs include advanced AI features like Recall, Live Captions with translation, and advanced Windows Studio Effects. * Microsoft plans to start shipping its first Copilot+ PCs in June 2024.

Microsoft has just unveiled its new Copilot+ PCs, a new category of devices powered by Snapdragon X Elite and X Plus chips optimized for AI workloads. The company also announced several new AI-powered experiences set to debut with these Copilot+ PCs this summer.

“Copilot+ PCs are the fastest, most intelligent Windows PCs ever built,” said Yusuf Mehdi – Executive Vice President for Consumer Chief Marketing Officer. “With powerful new silicon capable of an incredible 40+ TOPS (trillion operations per second), all–day battery life and access to the most advanced AI models, Copilot+ PCs will enable you to do things you can’t on any other PC.”

Microsoft highlighted several new AI-powered features that will be available on the new Copilot+ PCs:

RecallThe new AI-powered Recall feature lets users scroll through their timeline to quickly find apps, documents, messages, web pages, images, and videos they previously accessed on the Copilot+ PCs. It also offers contextual suggestions based on what’s currently displayed on their screen.

Recall offers enhanced privacy controls to let users choose which information the feature can capture on the device. Moreover, IT admins can prevent the Recall from capturing any snapshots with Microsoft Intune. Microsoft also plans to introduce new policies that will let administrators filter specific apps and websites.

Recall (Image Credits: Microsoft)Live CaptionsMicrosoft also announced several enhancements to Live Captions on Copilot+ PCs. This feature can translate over 40 different languages into English from video calls, recordings, and streamed content. The real-time translation occurs directly on the device, without needing to connect to the cloud.

New Windows Studio EffectsMicrosoft announced new features for Windows Studio Effects to enhance the meeting experience on Copilot+ PCs. Windows Studio Effects already lets users reframe videos, blur backgrounds, adjust gaze, and more. With this release, users can now virtually improve lighting conditions and apply creative filters to their webcam video feed. These new features will be accessible in Quick Settings.

Windows Studio Effects (Image Credits: Microsoft)Updates for Copilot and CocreatorMicrosoft also detailed new AI-powered features coming to Copilot and Cocreator in Paint by Designer. The company highlighted that users will be able to generate images and text directly on Copilot+ devices. Additionally, the cocreator tool will collaborate with users in real time on drawing projects and provide artistic suggestions.

Microsoft plans to begin shipping the first Copilot+ PCs this summer. The company will launch the consumer versions of the Surface Pro 10 and Surface Laptop Pro 6 with Qualcomm’s X Series processors.

Microsoft also said that all popular OEMs (like Lenovo, Dell, Asus, HP, Samsung, and Acer) are expected to debut Copilot+ PCs next month. However, keep in mind that most of the new AI experiences will be available to customers later this year.

The post Microsoft’s New Copilot+ PCs Boast Advanced AI Experiences appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft will enforce MFA for all Azure customers in July 2024. * The rollout will begin with the Azure portal and extend to CLI, PowerShell, and Terraform, but won’t affect apps, websites, or services hosted on Azure. * Administrators can tailor MFA requirements using Entra ID Conditional Access policies, and monitor MFA adoption and status with dedicated reports and tools.

Microsoft is stepping up its security game for Azure customers by mandating multi-factor authentication (MFA) starting in July 2024. This move aims to bolster account protection by requiring users to verify their identity through multiple methods, significantly reducing the risk of unauthorized access and data breaches.

Multi-factor authentication (MFA) is a security feature that requires users to provide two or more verification methods to gain access to a system, application, or account. It adds an extra layer of security to make it difficult for attackers to compromise accounts and steal sensitive data. Multi-factor authentication helps to prevent unauthorized access due to credential stuffing, phishing, brute force, and password reuse attacks.

Starting in July, Microsoft will gradually introduce a new security setting that requires multi-factor authentication (MFA) for all users signing into the Azure portal. After this rollout is complete, the company will implement a similar enforcement policy for CLI, PowerShell, and Terraform. Microsoft plans to provide additional information about specific rollout dates through official emails and notifications.

“Students, guest users and other end-users will only be affected if they are signing into Azure portal, CLI, PowerShell or Terraform to administer Azure resources. This enforcement policy does not extend to apps, websites or services hosted on Azure. The authentication policy for those will still be controlled by the app, website or service owners,” Microsoft explained.

Microsoft Entra multi-factor authentication (Image Credits: Microsoft)Which MFA methods does Microsoft Entra ID support?Microsoft Entra ID supports various multi-factor authentication methods, including the Microsoft Authenticator app, Windows Hello for Business, SMS, voice calls, and hardware tokens. Admins can use Entra ID Conditional Access policies to customize when MFA is needed. These policies can be based on various signals, such as the user’s location, device, role, or current risk level.

Microsoft recommends that administrators enable MFA within their tenants using the MFA wizard for Microsoft Entra. They can track which users have registered for multi-factor authentication with the authentication methods registration report. Additionally, IT admins can use a PowerShell script to generate a report showing the MFA status for all end users.

The post Microsoft to Enforce MFA for All Azure Customers in July appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s upcoming Build developer conference starting next week, as well as the various Windows on ARM announcements from Microsoft and other PC manufacturers that are expected on Monday.

The use of React Native in Windows 11. Research shows how Microsoft is using React Native, a web technology created by Facebook, to build some of the new features in Windows 11, such as the recommended section in the Start menu. Microsoft controls the desktop version of React Native and is using it everywhere.

The challenges of modern app development on Windows. Paul and Brad discuss how Microsoft has failed to provide a consistent and easy framework for app development on Windows, and how they have to resort to different technologies such as WinUI, XAML Islands, and WPF. They speculate that Microsoft might move on from WinUI 3 and that WPF might make a comeback.

The trend of web-based technologies for cross-platform development. Paul and Brad compare the situation of Microsoft with that of Google, which is also using web-based technologies, such as Flutter and Dart, to create apps that run on multiple platforms. They suggest that web technologies are becoming the common way to get to the web, regardless of the language or framework used.

The post First Ring Daily: Building on the Road appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Cybercriminals are abusing Microsoft’s Quick Assist app to perform social engineering attacks, tricking users into granting remote access to their computers. * The financially motivated threat actor, Storm-1811, has been using this method to spread Black Basta ransomware since April 2024. * Microsoft advises administrators to uninstall or block Quick Assist if not in use and implement privilege access management solutions.

Microsoft has warned customers about a new wave of social engineering attacks where cybercriminals exploit its Quick Assist app. The company acknowledged that a financially motivated threat actor (tracked as Storm-1811) has been deploying Black Basta ransomware since mid-April, posing a significant threat to users.

Quick Assist is a remote assistance tool that helps to connect two PCs over the Internet. It allows IT support teams to remotely view and control another user’s computer to diagnose and fix technical issues. The Quick Assist app is installed by default on Windows 11, and it encrypts the connection between the two computers to maintain data privacy.

In a new threat intelligence report, Microsoft revealed that hackers are leveraging social engineering campaigns to trick victims into granting access to their computers via Quick Assist. The attackers pose as IT support to bombard targets with spam emails and flood their inboxes with subscribed content. They then use voice phishing (vishing) to convince victims to address the spam issue.

“During the call, the threat actor persuades the user to grant them access to their device through Quick Assist. The target user only needs to press CTRL + Windows + Q and enter the security code provided by the threat actor,” the Microsoft Threat Intelligence team explained. “After the target enters the security code, they receive a dialog box asking for permission to allow screen sharing. Selecting Allow shares the user’s screen with the actor.”

Quick Assist prompt to enter security code (Image Credits: Microsoft)Additionally, Microsoft observed that Storm-1811 is deploying various malware to escalate privileges and maintain control over compromised devices. This includes remote monitoring and management (RMM) tools like ScreenConnect and NetSupport Manager, as well as malicious payloads such as Qakbot and Cobalt Strike.

How to mitigate Quick Assist attacksMicrosoft advises administrators to uninstall or block Quick Assist and other management tools if they are not in use within their organizations. They also recommend implementing privilege access management solutions to prevent unauthorized access to sensitive information.

Additionally, Microsoft urges organizations to enable cloud-delivered protection, tamper protection, and network protection as well as invest in advanced anti-phishing solutions. IT admins should also conduct employee training sessions to educate staff about tech support scams and social engineering attacks.

The post Hackers Exploit Windows Quick Assist App to Deploy Black Basta Ransomware appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Teams users can now enjoy streamlined processes for creating and joining teams and channels. * The AI-powered Discover feed in Teams enhances content consumption by offering users a personalized hub to catch up on the most relevant channel updates. * Microsoft has introduced new admin controls to prevent users from finding private teams.

Microsoft has announced a slew of updates to streamline channel management in its Teams collaboration service. The company has reduced the number of steps that were previously required to create and join teams and channels in Microsoft Teams.

Microsoft mentioned that “create a team from scratch” is now the default experience in Microsoft Teams. Users will need to click “More create team options” to select a template from the template library. Microsoft has also introduced a new Create channel option in the menu for creating a new team.

Additionally, Microsoft Teams now allows users to find and join public and private teams. There are also new settings that let IT admins control whether users will be able to find a private team. Later this year, Microsoft Teams will enable users to choose to show only the channels that are relevant to them when joining a team.

Discover public and private teams (Image Credits: Microsoft)New Discover Feed enhances collaboration in Microsoft Teams channelsMicrosoft Teams has introduced a new AI-powered Discover feed that allows users to catch up on the most relevant content from channels. This new Discover feed helps to easily catch up on news as well as like/comment/share a post.

In Microsoft Teams, users can now share a link to the channel, a post, or a reply with their colleagues. Moreover, users can choose to hide the general channel of a team and mark all notifications as read with a single click in the activity feed.

Discover Feed (Image Credits: Microsoft)Archive channel is now generally availableFurthermore, Microsoft has released a new feature that lets channel owners and IT admins archive Teams channels. This capability should help to preserve channel content (such as messages, files, and tabs) when the collaboration in a project ends.

Archive channel (Image Credits: Microsoft)Later this year, Microsoft Teams is getting a new feature that will automatically hide inactive channels that haven’t been interacted with over the past 45 days. Additionally, it will be possible to rename the general channel in Microsoft Teams. Users will also be able to mute all notifications for a specific channel post and customize the sound of notifications.

The post Microsoft Teams Gets New Channel Management Capabilities appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* VMware has made its Workstation Pro and Fusion Pro desktop hypervisor products free for personal use. * VMware is also discontinuing its Workstation Player and Fusion Player solutions. * VMware has simplified its paid offerings to a single SKU called Desktop Hypervisor for commercial customers, priced at $120 per year.

VMware announced yesterday that its Workstation Pro and Fusion Pro desktop hypervisor products are now free for personal use. Starting this week, VMware will offer two license models for its Pro apps: a Free Personal Use or a Paid Commercial Use subscription for organizations.

According to VMware, customers should notice consistent functionality across both free and paid subscription models. However, the free version will display the message “This product is licensed for personal use only” on the screens.

VMware Workstation Pro and Fusion Pro are virtualization products that enable customers to create and operate virtual machines (VMs) on their computers. These services let users run multiple VMs to facilitate testing, development, and other virtualization tasks. VMware Workstation Pro is available for PCs running Windows and Linux, while VMware Fusion Pro is tailored for macOS.

“VMware Desktop Hypervisor products Fusion and Workstation are used by millions of people every day to run virtual machines on their Windows, Linux, and Mac computers,” VMware explained. “They give users the ability to quickly and easily build ‘local virtual’ environments to install other operating systems, learn about technology, build and test software, complex systems, browsers, apps, games, and more.”

VMware Workstation (Image Credits: VMware)How to download Workstation Pro and Fusion Pro 13 for free Go to the Broadcom’s Support website. * Click Register to create a new basic Broadcom account if you don’t already have one. * Once logged in, navigate to the Support Portal and select the “VMware Cloud Foundation division” from the dropdown menu. * Click the “My Downloads” option on the left and then search for either Fusion or Workstation. * Select VMware Fusion or VMware Workstation Pro from the list and choose version 17.5.2 or 13.5.2. * Finally, click the download and install* option.

VMware deprecates Workstation Player and Fusion Player VMware has announced its plans to phase out its Workstation Player and Fusion Player solutions. These products will no longer be available for purchase, and customers are encouraged to transition to the Pro versions at no additional cost. VMware assures that all virtual machines (VMs) utilized in the VMware Player products are compatible with Workstation Pro and Fusion Pro.

Lastly, Broadcom has simplified its paid offering into a single product for VMware commercial customers. This new subscription, called VMware Desktop Hypervisor, is priced at $120 per year and provides access to VMware Workstation Pro and Fusion Pro products. Commercial customers can purchase the new paid subscription through the new online store or an authorized Broadcom Advantage partner.

Overall, VMware’s decision to make Workstation Pro and Fusion Pro free for personal use marks a significant advancement in virtualization accessibility for IT professionals. This move not only promotes cost efficiency and flexibility but also facilitates skill development, collaboration, and career advancement within the IT community.

The post VMware Makes Workstation Pro and Fusion Pro Free for Personal Use appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft’s May 2024 Patch Tuesday updates address 59 vulnerabilities, including two zero-day flaws already being exploited by attackers. * Microsoft has fixed a high-severity security feature bypass vulnerability in the Windows MSHTML platform and an elevation of privilege flaw in Windows DWM Core Library. * Microsoft has introduced minor changes to Widgets icons on the taskbar and enhancements to lock screen widgets on Windows 11.

Microsoft has released the May 2024 Patch Tuesday updates for Windows 11 and Windows 10. This month, Microsoft fixed a total of 59 security vulnerabilities in Windows and other components, and there are two zero-day flaws that are already being exploited by attackers.

On the quality and experience updates front, Microsoft has released some changes to the Widgets icons on the taskbar and widgets cards on the lock screen on Windows 11. The latest update also fixes a known issue that was causing the Settings app to become unresponsive on Windows 11 PCs.

59 vulnerabilities fixed in the May 2024 Patch Tuesday updatesAs highlighted by the Zero Day Initiative, Microsoft’s May 2024 Patch Tuesday Updates include fixes for 59 vulnerabilities. Among these, only one is categorized as “Critical,” 57 are deemed “Important,” and one carries a “Moderate” severity rating.

  • CVE-2024-30040: This is a high-severity security feature bypass vulnerability in the Windows MSHTML platform that received an 8.8 CVSS score. The flaw could allow attackers to deceive users into opening a harmful file and then bypass OLE mitigations in Microsoft 365 and Microsoft Office to execute malicious code.
  • CVE-2024-30051: This elevation of privilege flaw in Windows DWM Core Library received a 7.8 CVSS score. The security vulnerability could let local attackers gain system privileges on the target system and take complete ownership of the device.
  • CVE-2024-30044: This is a remote code execution (RCE) vulnerability in SharePoint Server. It could let an unauthenticated hacker with site owner permissions inject and execute arbitrary code in the context of SharePoint Server.
  • CVE-2024-30033: This is an important rated elevation of privileges vulnerability in the Windows Search Service. An attacker could exploit this bug to system-level privileges and perform unauthorized actions.
  • CVE-2024-30018: This is another important-rated elevation of privileges vulnerability in the Windows Kernel with a 7.8 CVSS score. The security flaw enables hackers to bypass security protections and potentially take full control of the target system.

Here’s the complete list of resolved vulnerabilities in the May 2024 Patch Tuesday updates:

| Product | Impact | Max Severity | Article | Download | Details | | Microsoft Edge (Chromium-based) | Release Notes | Security Update | CVE-2024-4761 | | Windows 10 Version 1607 for 32-bit Systems | Security Feature Bypass | Important | 5037763 | Security Update | CVE-2024-30040 | | Windows 10 for x64-based Systems | Security Feature Bypass | Important | 5037788 | Security Update | CVE-2024-30040 | | Windows 10 for 32-bit Systems | Security Feature Bypass | Important | 5037788 | Security Update | CVE-2024-30040 | | Windows Server 2022, 23H2 Edition (Server Core installation) | Security Feature Bypass | Important | 5037781 | Security Update | CVE-2024-30040 | | Windows 11 Version 23H2 for x64-based Systems | Security Feature Bypass | Important | 5037771 | Security Update | CVE-2024-30040 | | Windows 11 Version 23H2 for ARM64-based Systems | Security Feature Bypass | Important | 5037771 | Security Update | CVE-2024-30040 | | Windows 10 Version 22H2 for 32-bit Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 10 Version 22H2 for ARM64-based Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 10 Version 22H2 for x64-based Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 11 Version 22H2 for x64-based Systems | Security Feature Bypass | Important | 5037771 | Security Update | CVE-2024-30040 | | Windows 11 Version 22H2 for ARM64-based Systems | Security Feature Bypass | Important | 5037771 | Security Update | CVE-2024-30040 | | Windows 10 Version 21H2 for x64-based Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 10 Version 21H2 for ARM64-based Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 10 Version 21H2 for 32-bit Systems | Security Feature Bypass | Important | 5037768 | Security Update | CVE-2024-30040 | | Windows 11 version 21H2 for ARM64-based Systems | Security Feature Bypass | Important | 5037770 | Security Update | CVE-2024-30040 | | Windows 11 version 21H2 for x64-based Systems | Security Feature Bypass | Important | 5037770 | Security Update | CVE-2024-30040 | | Windows Server 2022 (Server Core installation) | Security Feature Bypass | Important | 5037782 | Security Update | CVE-2024-30040 | | Windows Server 2022 (Server Core installation) | Security Feature Bypass | Important | 5037848 | SecurityHotpatchUpdate | CVE-2024-30040 | | Windows Server 2022 | Security Feature Bypass | Important | 5037782 | Security Update | CVE-2024-30040 | | Windows Server 2022 | Security Feature Bypass | Important | 5037848 | SecurityHotpatchUpdate | CVE-2024-30040 | | Windows Server 2019 (Server Core installation) | Security Feature Bypass | Important | 5037765 | Security Update | CVE-2024-30040 | | Windows Server 2019 | Security Feature Bypass | Important | 5037765 | Security Update | CVE-2024-30040 | | Windows 10 Version 1809 for ARM64-based Systems | Security Feature Bypass | Important | 5037765 | Security Update | CVE-2024-30040 | | Windows 10 Version 1809 for x64-based Systems | Security Feature Bypass | Important | 5037765 | Security Update | CVE-2024-30040 | | Windows 10 Version 1809 for 32-bit Systems | Security Feature Bypass | Important | 5037765 | Security Update | CVE-2024-30040 | | Windows Server 2012 R2 (Server Core installation) | Information Disclosure | Important | 5037823 | Monthly Rollup | CVE-2024-30039 | | Windows Server 2012 R2 | Information Disclosure | Important | 5037823 | Monthly Rollup | CVE-2024-30039 | | Windows Server 2012 (Server Core installation) | Information Disclosure | Important | 5037778 | Monthly Rollup | CVE-2024-30039 | | Windows Server 2012 | Information Disclosure | Important | 5037778 | Monthly Rollup | CVE-2024-30039 | | Windows Server 2016 (Server Core installation) | Elevation of Privilege | Important | 5037763 | Security Update | CVE-2024-30038 | | Windows Server 2016 | Elevation of Privilege | Important | 5037763 | Security Update | CVE-2024-30038 | | Windows 10 Version 1607 for x64-based Systems | Elevation of Privilege | Important | 5037763 | Security Update | CVE-2024-30038 | | PowerBI-client JS SDK | Information Disclosure | Important | Release Notes | Security Update | CVE-2024-30054 | | Microsoft Visual Studio 2022 version 17.8 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Microsoft Visual Studio 2022 version 17.6 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Microsoft Visual Studio 2022 version 17.4 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Microsoft Visual Studio 2022 version 17.9 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Microsoft Visual Studio 2019 version 16.11 (includes 16.0 – 16.10) | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Microsoft Visual Studio 2017 version 15.9 (includes 15.0 – 15.8) | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-32004 | | Dynamics 365 Customer Insights | Spoofing | Important | Release Notes | Security Update | CVE-2024-30048 | | .NET 7.0 | Remote Code Execution | Important | 5038351 | Security Update | CVE-2024-30045 | | .NET 8.0 | Remote Code Execution | Important | 5038352 | Security Update | CVE-2024-30045 | | Microsoft SharePoint Server Subscription Edition | Information Disclosure | Important | 5002599 | Security Update | CVE-2024-30043 | | Microsoft SharePoint Server 2019 | Information Disclosure | Important | 5002596 | Security Update | CVE-2024-30043 | | Microsoft Office 2019 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Microsoft Office 2019 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Office Online Server | Remote Code Execution | Important | 5002503 | Security Update | CVE-2024-30042 | | Microsoft Bing Search for iOS | Spoofing | Important | Release Notes | Security Update | CVE-2024-30041 | | Microsoft SharePoint Enterprise Server 2016 | Information Disclosure | Important | 5002598 | Security Update | CVE-2024-30043 | | Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002587 | Security Update | CVE-2024-30042 | | Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002587 | Security Update | CVE-2024-30042 | | Microsoft Office LTSC 2021 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Microsoft Office LTSC 2021 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Microsoft Office LTSC for Mac 2021 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2024-30042 | | Microsoft 365 Apps for Enterprise for 64-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Microsoft 365 Apps for Enterprise for 32-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2024-30042 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Elevation of Privilege | Important | 5037780 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Elevation of Privilege | Important | 5037803 | Security Only | CVE-2024-30049 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Elevation of Privilege | Important | 5037780 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Elevation of Privilege | Important | 5037803 | Security Only | CVE-2024-30049 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5037800 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5037836 | Security Only | CVE-2024-30049 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5037800 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Elevation of Privilege | Important | 5037836 | Security Only | CVE-2024-30049 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5037800 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Elevation of Privilege | Important | 5037836 | Security Only | CVE-2024-30049 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5037800 | Monthly Rollup | CVE-2024-30049 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Elevation of Privilege | Important | 5037836 | Security Only | CVE-2024-30049 | | Microsoft Intune Mobile Application Management for Android | Tampering | Important | Release Notes | Security Update | CVE-2024-30059 | | Azure Migrate | Spoofing | Important | Release Notes | Security Update | CVE-2024-30053 |

Quality and experience updatesIf you’re running Windows 11 versions 23H2 and 22H2, Microsoft has introduced new larger widget icons on the taskbar. The company has also added more customization options and visuals to improve the lock screen widgets for sports, weather, and finance news. Windows 11 users will also start seeing ads for some Microsoft Store apps and frequently used apps in the Recommended section of the Start menu.

For Windows 10, this month’s Patch Tuesday Update brings the same minor changes to widgets cards on the lock screen. The KB5037768 patch brings a new personalized app search experience and reliability improvements for Windows Search. Microsoft has also added support for account-related notifications for Microsoft accounts in Settings.

Microsoft has also addressed an issue that was previously causing VPN connections to fail on Windows 11 and Windows 10 devices. The company has also fixed Bluetooth connection problems with some wireless earbuds.

Windows Update testing and best practicesOrganizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.

The post Microsoft’s May 2024 Patch Tuesday Updates Fix Two Zero-Day Vulnerabilities appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Windows 10 version 21H2 will reach end of support in June 2024. * Microsoft recommends users to upgrade to Windows 10 version 22H2 for continued security patching. * Microsoft will automatically install Windows 10 version 22H2 on non-managed business PCs in the coming weeks to facilitate the transition.

Microsoft is warning customers still using Windows 10 version 21H2 that it will soon reach end of support. The consumer editions of Windows 10 version 21H2 already reached end of servicing last year, and June 2024 will mark the end of support for enterprise and education customers for the operating system.

Microsoft plans to release the last security update for enterprise, education, and IoT enterprise editions of Windows 10 version 21H2 on June 11. After this date, the company will no longer provide security patches and bug fixes for affected Windows 10 devices. However, Microsoft will continue to support Windows 10 Enterprise LTSC 2021 and Windows 10 IoT Enterprise LTSC 2021 until January 12, 2027.

Microsoft advises customers currently running Windows 10 version 21H2 to upgrade to version 22H2 to continue receiving security patches beyond June 2024. These security updates help to ensure protection against critical vulnerabilities on Windows 10 PCs. Microsoft will begin force-installing Windows 10 version 22H2 on non-managed business PCs in the next few weeks.

“To help keep you protected and productive, Windows Update will automatically initiate a feature update for Windows 10 business devices not managed by IT departments when these are nearing end of servicing. Moving to Windows 10, version 22H2 keeps your device supported and receiving monthly updates that are critical to security and ecosystem health,” Microsoft explained.

Microsoft urges upgrade to Windows 10 version 22H2Microsoft says that administrators will need to upgrade managed devices to Windows 10 version 22H2. Additionally, the company urges IT admins to consider migrating all eligible devices meeting the minimum hardware requirements to Windows 11.

Microsoft will officially end support for Windows 10 version 22H2 on October 14, 2025. The company will offer extended security updates for both businesses and enterprise customers for up to three years. The pricing starts at $61 for the first year and doubles to $122 and $244 in the second and third years, respectively.

The post PSA: Windows 10 version 21H2 Enterprise and Education Editions Set to Reach End of Support Next Month appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Places, a new AI-powered application, facilitates seamless coordination of in-office schedules by leveraging data from Microsoft Teams and Outlook. * The new Places app offers various features to help employees efficiently manage their in-office time and connect with colleagues. * The upcoming integration with Microsoft Copilot promises further optimization by enabling automatic booking of shared desks and meeting rooms.

Microsoft has announced the public preview of a new application called Microsoft Places. This new AI-powered app leverages insights from Microsoft Teams and Outlook to help employees synchronize their in-office time.

Microsoft first unveiled the new Places app during its Ignite conference in October 2022. With Microsoft Places, users can specify their office hours and locations, and coordinate schedules with colleagues seamlessly. This feature works like the “set your work location” functionality available in Google Calendar.

“AI innovation is already improving how you work; improving where you work is the next opportunity, “ said Jared Spataro, CVP for AI at Work. With Microsoft Places, an app that reimagines flexible work, AI can make coordinating in-office time and connecting with coworkers even easier. In addition to fostering improved coordination and connection, Places optimizes the effectiveness and engagement of the workplace.”

Microsoft Places location plan (Image Credits: Microsoft)Microsoft Places includes a location planning section that allows employees to set and monitor their own and their colleagues’ location schedules. Additionally, the team guidance feature lets managers designate priority days for in-office activities. All location information seamlessly syncs with Outlook calendars to help employees keep track of office events.

In Microsoft Teams group chats, users can easily view the location of their colleagues. Moreover, they can simply type “@nearby” to promptly inform coworkers of any updates or changes in meeting rooms. Microsoft notes that IT administrators have opt-in/opt-out controls to manage presence information, which specifically pertains to in-office locations.

Microsoft Places to get new Copilot integrationLater this year, Microsoft plans to integrate this new Places experience into Microsoft Copilot. This new feature will let users ask the AI assistant to automatically find and book shared desks and meeting rooms. This capability should help to reduce the administrative work in hybrid environments.

Copilot integration in Microsoft Places (Image Credits: Microsoft)It’s important to note that the new Places app will be available for commercial customers as a part of Microsoft Teams Premium. The subscription is priced at $10 per user per month, with a current promotional offer of $7 per month for new customers available until June 30, 2024.

The launch of Microsoft Places is a part of the company’s efforts aimed at helping organizations adapt to the new hybrid work era. The upcoming Copilot integration, slated for release in the second half of 2024, promises to enhance the app’s utility for businesses even further. Microsoft invites customers to enroll in the Microsoft Places Preview Program via this page.

The post Microsoft Places Uses AI to Enhance Workplace Coordination appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced that System Center 2025, the next LTSC release, arrives in Fall 2024. * Key improvements focus on modernizing infrastructure, managing heterogeneous environments, and enhancing security. * Microsoft will add support for TLS 1.3 for data transmission security and securely storing passphrases in Azure Key Vault.

System Center 2025, the next release of Long-Term Servicing Channel (LTSC) will be released in Fall 2024. Microsoft has announced that the latest versions of Center Operations Manager (SCOM), Virtual Machine Manager (VMM), Service Manager (SM), System Center Orchestrator (SCO), and Data Protection Manager (DPM) will be available later this year.

System Center is a suite of management tools that helps organizations to manage large-scale IT infrastructure. The service offers a comprehensive set of solutions to deploy, configure, manage, monitor, and automate datacenters, hybrid cloud infrastructures, and virtualized environments.

Microsoft highlights that System Center 2025 brings several improvements that should help organizations modernize infrastructure, manage heterogeneous infrastructure, and boost security. “By delivering System Center 2025 (VMM, DPM, SCOM, SM & SCO) together with Windows Server 2025, we are bringing you management support for the latest Windows Server version right from Day 0,” Microsoft explained.

Microsoft plans to add managing and monitoring support for Azure Stack HCI 23H2 clusters with VMM & SCOM 2025. This release should also make it easier for administrators to convert VMware VMs to Windows Server via VMM. Microsoft plans to introduce support for the latest versions of Linux distros when System Center Virtual Machine Manager (SCVMM) 2025 hits general availability.

Additionally, Data Protection Manager 2025 will enable IT admins to exclude specific disks from backups in Hyper-V environments. The service will also offer virtual TPM (vTPM) support for VMware and seamless integration with SharePoint Subscription Edition.

System Center 2025 to enhance storage & authentication mechanismsMicrosoft will introduce several security features to enhance the security and reliability of System Center products. The company has added support for Transport Layer Security (TLS) version 1.3 to ensure that the latest security standards protect all data transmission. Moreover, DPM 2025 lets administrators securely store passphrases in Azure Key Vault to prevent unauthorized access to sensitive information.

Last but not least, Microsoft has announced plans to discontinue support for the Azure Profiles feature in VMM and System Center Service Provider Foundation (SPF). The company mentioned that these built-in capabilities are already available in Arc-enabled VMM. Microsoft notes that administrators can sign up for a private preview of System Center 2025 on this page.

The post Microsoft to Launch System Center 2025 Later This Year appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Teams has introduced enhanced Presenter window features for improved meeting interaction. * Meeting notifications are now prominently displayed at the center of the screen. * Users have enhanced control and flexibility with the ability to manage meeting options directly from the Presenter window.

Microsoft Teams meetings are about to get a lot more interactive with the latest enhancements to the Presenter window. Now, users can effortlessly keep track of up to four participants, active speakers, raised hands, and shared content previews.

In Microsoft Teams, the extended Presenter window enables users to view meeting notifications at the center of the screen. This feature makes it easier for presenters to monitor the participants’ activity during Teams meetings.

“These enhancements help you stay aware of what’s happening in your meeting and make it easier to engage with other attendees while you’re screensharing. You can also manage actions in your meeting such as lowering raised hands and muting participants,” Microsoft explained.

Expanded Presenter window (Image Credits: Microsoft)How the new Presenter window works in Microsoft Teams Join a Microsoft Teams meeting and click Share > Screen or Window. * Microsoft Teams users will notice that the new Presenter window now shows up to 4 participants. This new Presenter window can be moved around on the screen as well as minimized or resized. * Users can click the arrow* button to expand the self-video title at the bottom of the Presenter window. * The self-video tile also allows users to change the presenter layout during the screen sharing session.

Microsoft is currently rolling out the new Presenter window experience to Targeted release customers and users enrolled in the Teams public preview program. It’s up to the IT admins to give access to select end users or the entire organization through the Microsoft 365 admin center.

As of this writing, this feature supports the new Teams client for Windows and macOS. The new Presenter window is expected to become generally available for all commercial customers in mid-June.

Last month, Microsoft announced the general availability of the new Planner experience in Teams. This new Planner app combines task management and planning tools, including Microsoft Planner, To Do, and the Project web app.

The post Microsoft Teams’ New Presenter Window Elevates Virtual Meetings appeared first on Petri IT Knowledgebase.

View Details

When it comes to cloud services and security technology, IT and systems administrators should seriously consider having SSO implemented for greater convenience and security.

What is single sign-on (SSO)?SSO is an authentication method that allows users to securely access multiple SaaS (Software-as-a-Service) applications, websites, and other digital resources with a single set of login credentials. As opposed to remembering and entering separate usernames and passwords for each service, SSO enables users to authenticate themselves once and then be granted access to all authorized systems and applications. Microsoft SSO, in particular, has become a pivotal centerpiece in its evolutionary, security- and AI-led approach across its entire ecosystem.

At its core, SSO establishes a trusted relationship between a user and one or more service providers (SPs). The user is responsible for providing the credentials, the service then creates an authentication token that validates the user as verified. This token is stored either in a browser or within the SSO vendor’s servers. The SSO vendor then passes the user’s token details to any apps on the server and the user is granted access without the need to enter their details again.

SSO plays a crucial role in securely managing access and authentication across geographically distributed teams and infrastructure. It allows organizations to manage user identities and access permissions from a centralized platform, simplifying the switching between various tools and services without the need to re-authenticate, fostering more efficient and streamlined workflows. Additionally, organizations can use SSO to validate users’ attempts to access and interact with mission-critical systems and enhance their DevOps operations, with CI/CD pipelines and cloud applications proving inherently more agile with this authentication method embedded.

How does single sign-on work?Firstly, however, it’s important to establish how SSO works in a business context. An SSO configuration setup can be viewed as a go-between that confirms whether a user’s login information matches their identity on a separately managed database. Most SSO services don’t manage databases themselves but can access them quickly to validate a login request.

Single sign-on powered by Microsoft Entra ID (Image Credit: Microsoft.com)The SSO process typically follows these steps:

  1. A user attempts to access a secure application or resource.
  2. The application redirects the user to the identity provider’s login page.
  3. The user provides their username and password to the application.
  4. The application establishes a secure session through identity verification.
  5. The resource generates an authentication token and returns it to the user’s browser.
  6. The user’s browser automatically includes the authentication token when accessing the original application or other connected services.
  7. The service provider validates the token and grants the user secure access to the requested resource(s).

Authentication tokens have specific communication standards to adhere to when confirming a request’s validity. The main token standard is known as Security Assertion Markup Language (SAML), but there are several common SSO configurations that organizations – of all sizes – can implement.

Types of SSO configurationsSAML-based SSOSAML is an XML standard for exchanging authentication and authorization data between users and service providers. SAML-based SSO involves communication between the user, the identity provider (IdP) that oversees a user directory or database, and the service provider.

Kerberos-based SSOKerberos is a network authentication protocol that authenticates secure service requests between trusted hosts across non-secure networks. In a Kerberos-based SSO setup, a user initially provides their credentials before a ticket-granting ticket (TGT) is issued, which obtains service tickets for other wanted resources without the need for re-entering information.

Smart Card-based SSOSmart card-based SSO utilizes a physical smart card or security token as the primary or initial authentication factor. Once the data from the card is used, the user does not have to re-enter their credentials, with the SSO vendor storing certificates or passwords after first entry.

Social SSOSome organizations allow users to validate their access requests if they log in using their social media account credentials. This can provide a convenient login experience but it also introduces potential security risks that users should consider carefully, given that it creates a single point of failure easily exploitable by attackers.

Enterprise SSOEnterprise single sign-on (eSSO) services usually comprise password managers with server and client components that align users and target applications with securely stored user-generated credentials.

Benefits of SSOThe enterprise SSO market is projected to reach an $11 billion valuation by 2036, expanding at a 14% CAGR from this year onwards. Given the current cyber threat landscape, it’s clear that enterprises are taking SSO seriously, and with good reason. Implementing a robust SSO solution can provide organizations with several advantages.

  1. Improved user experience: By removing the need for multiple login prompts and the need to remember separate passwords, SSO improves overall productivity and efficiency for users.
  2. Enhanced security: SSO can help IT teams strengthen security by enforcing stronger and specific password policies, multi-factor authentication (MFA), and the centralized management of user identities and access permissions.
  3. Reduced IT support costs: With the help of SSO, administrators spend less time implementing repeated password resets and can take advantage of a single place from which to initiate re-entry for internal applications. As such, business productivity improves and IT teams can dedicate more resources to higher-value work.
  4. Aiding in compliance: Many SSO solutions provide high-quality logging and reporting capabilities, which can help organizations meet regulations with greater oversight and less ambiguity.
  5. Scalability and flexibility: Third-party SSO platforms ‌can be seamlessly integrated with a wide range of on-premise and cloud-based applications, making them adaptable to the evolving needs of modern organizations.

Are there any security risks of SSO?While SSO offers several benefits, it’s important to be aware of potential security risks. If malicious actors gain access to a user’s credentials, resources connected through SSO can be potentially compromised through a single point of failure. Organizations must maintain strict controls and processes to reduce both password fatigue and an overreliance on service provider availability. To mitigate these risks, organizations should implement stringent identity and access management (IAM) practices, regular audits and 24/7 incident response.

Microsoft Entra ID SSO implementation Microsoft Entra ID, formerly known as Azure Active Directory (Azure AD) is Microsoft’s cloud-based identity and access management service. The Microsoft Entra SSO is an incumbent feature within the Entra platform and is the primary SSO solution that permits users to use one set of credentials to access multiple Microsoft applications.

Single sign-on in action in for a Microsoft work or school account (Image Credit: Microsoft Learning)The service offers extensive support for app integrations, passwordless and multi-factor authentication and a notable conditional access functionality which allows administrators to set specific conditions that grant users access to certain applications based on location, device, and other data. This is an agile and proactive workaround for users who have lost access to or forgotten logins, while giving administrators flexibility to ensure infrastructure stability and minimize risk.

Microsoft Entra also supports all OAuth 2.0 flows, which are connected to OpenID Connect (OIDC), a proven and reliable authorization layer.

Microsoft Entra ID additionally allows users to create an application identity that can connect to other resources using Entra authentication, with it recently permitting enterprise customers to convert external accounts to internal accounts with ease. Administrators can connect many Azure resources, for example, by supporting managed user identities with the help of Entra ID, including but not limited to Azure Virtual Machines, Azure SQL, Azure IoT Hub, and Azure Communication Services, to name just a few.

As such, administrators can create a robust, comprehensive security and regulatory compliance framework for their infrastructure and processes.


It’s clear that SSO is a powerful authentication solution that simplifies user access and identity management across an organization’s Microsoft infrastructure. Using SSO is a definitive way to enhance security and productivity across your estate, and by understanding the various configurations and benefits it can provide, as well as the potential security risks, IT administrators can implement the right enterprise-grade SSO solution that aligns with their unique business needs.

Enterprises have access to a user-friendly and established SSO tool within incumbent Microsoft setups, known as Entra ID, which can be leveraged to further streamline user authentication and access management across a range of cloud-based and on-premises applications. As organizations continue to scale with the help of DevOps, the role of SSO in securely managing user identities and access becomes increasingly vital.

As security becomes more of a hot topic among IT professionals, staying informed about SSO developments will help you make more informed choices about how best to implement a well-designed and reliable SSO solution.

The post What is Single Sign-On (SSO): Everything You Need to Know appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss the persisting feature gap between the new Outlook for Windows and the classic app, Microsoft having a bad week PR-wise, and the new iPad lineup Apple revealed earlier this week.

The post First Ring Daily: Outlook Frustrations and Microsoft’s PR Struggles appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Entra ID Protection has introduced streamlined deployment of risk policies and robust defense mechanisms against sophisticated security threats. * The new Identity Protection risk analysis workbook allows IT admins to comprehensively analyze the impact of activating risk-based Conditional Access Policies. * Microsoft Entra ID Protection offers improved prevention, investigation, and remediation capabilities, including on-premises password reset.

Microsoft has announced some important updates for its Entra ID Protection service. The new feature offers administrators streamlined deployment of risk policies, comprehensive impact analysis, and robust defense mechanisms against sophisticated security threats.

Last year, Microsoft announced its plans to enable Entra ID Conditional Access policies by default for select Microsoft 365 tenants. The company is gradually rolling out these Microsoft-managed policies, which are aimed at encouraging organizations to switch to using multifactor authentication.

Microsoft has just released a new Identity Protection risk analysis workbook to help administrators understand the implications of these changes on their environments. This workbook lets IT admins analyze the impact of activating risk-based Conditional Access Policies, which could potentially block user sign-ins, mandate multifactor authentication, or facilitate secure password changes.

To access the new workbook, users will need to sign in to the Microsoft Entra admin center as at least a Reports Reader. Navigate to Identity > Monitoring & health > Workbooks, and then choose the “Impact analysis of risk-based access policies workbook” option available under Identity Protection.

Microsoft Entra ID Protection dashboard is now generally availableMicrosoft has announced the general availability of a new Entra ID Protection dashboard that launched in public preview in July 2023. It provides key metrics, graphics, and recommended actions to help administrators understand the security posture of their organization. IT admins can now simply click on the “attack counts” option within the Attacks Graphic to access the Risk Detections report for more in-depth analysis. This report includes a newly added “Attack type” column detailing primary attack types.

Entra ID Protection dashboard (Image Credits: Microsoft)Improved Prevention, Investigation, and remediation capabilitiesMicrosoft has released a new feature that lets administrators enable on-premises password reset for resetting user risk within Identity Protection settings. This capability is generally available for commercial customers with Entra P1 and P2 subscriptions.

Microsoft Entra has added new User Risk Investigation skills within the standalone Copilot for Security experience, including User Details, Group Details, Sign-in Logs, Audit Logs, and Diagnostic Logs. These skills enable customers to gain insights into security incidents, while also addressing sign-in concerns and identity-related risks.

User Risk Investigation Copilot in public preview (Image Credits: Microsoft)Lastly, Microsoft Entra ID Protection has recently added new threat prevention and remediation capabilities to protect organizations against token theft, anomalous graph usage, attacker-in-the-middle (AitM) attacks, and other security threats. The service can now automatically adjust a user’s risk level if they are engaging in an unusually high volume of calls to MS Graph and AAD Graph. Microsoft also highlighted a real-time Anomalous Token Detection feature that leverages risk-based Conditional Access for sign-ins to disrupt token replay attacks.

Microsoft’s recent research study shows that its Entra ID service detects 11 token replay detections per 100,000 active users and 18,000 multifactor authentication (MFA) fatigue attacks per month. These new Entra ID Protection features should enable organizations to proactively manage security risks and protect their data and infrastructure more effectively.

The post Stay Ahead of Threats: Microsoft Entra ID Protection Enhances Security Capabilities appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Sentinel’s SOC optimization offers tailored recommendations to identify gaps in data utilization and detect diverse cyberattacks, enhancing organizational security. * This new feature aims to assist security teams in effectively managing risks without compromising operational efficiency. * IT admins can discover this SOC optimization feature in the new unified security operations platform and the Azure portal.

Microsoft announced yesterday a public preview of SOC optimization for Microsoft Sentinel customers. The feature provides actionable tailored recommendations, allowing organizations to pinpoint data utilization gaps and thwart various cyber threats.

Microsoft emphasized the importance of security teams optimizing both processes and outcomes. They should consistently adjust their security controls to adapt to evolving threat landscapes and business priorities. The new SOC optimization recommendations feature is designed to help security teams close coverage gaps against security threats without having to spend time on manual analysis and research.

“SOC optimizations are high-fidelity and actionable recommendations to help you identify areas where you can reduce costs, without affecting SOC needs or coverage, or where you can add security controls and data where its found to be missing. SOC optimizations are tailored to your environment and based on your current coverage and threat landscape,” Microsoft explained.

Currently, the SOC optimizations feature provides two types of recommendations: data value optimizations and threat-based optimizations. The data value optimizations feature allows security teams to gain deep insights into their data usage patterns. It provides actionable suggestions to maximize security value from ingested data or propose improvements to the data plan.

Additionally, SOC optimizations include threat-based recommendations for adding security controls to thwart a range of attacks, including Business Email Compromise and Human Operated Ransomware. Moreover, IT admins can click a link at the top of the page to check out all SOC optimization scenarios. From there, it’s also possible to get a quick look at an approximate score for each of those attacks.

Threat based recommendations – Azure portal (Image Credits: Microsoft)SOC optimizations empowers automation with an APIMicrosoft notes that organizations can also get access to SOC optimizations through the Azure REST API. For instance, the API can be used to get information about a specific recommendation or all existing ones. It also provides automation capabilities and seamless integration with existing processes and systems.

Microsoft notes that the new SOC optimization feature is currently available in the Azure portal and the unified security operations platform. Keep in mind that administrators must integrate Microsoft Sentinel with Microsoft Defender XDR to utilize SOC optimization within the Microsoft Defender Portal.

The post Microsoft Introduces New Sentinel SOC Optimization Feature for Enhanced Cybersecurity appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Teams will soon add slash commands support into the compose message box. * The integration of slash commands aims to enhance efficiency and simplify task completion within Microsoft Teams. * This feature will be available across all major platforms, including Windows, macOS, and the web.

Microsoft Teams is set to introduce support for slash commands directly within the compose message box. The company has announced on the Microsoft 365 Admin Center that this new feature will start rolling out to Teams users across Windows, macOS, and the web later this month.

In Microsoft Teams, slash commands are handy shortcuts designed to boost productivity. The feature helps users quickly initiate calls, access files, and navigate teams and channels. This capability is designed to streamline workflow and enhance efficiency, making tasks easier to accomplish.

Currently, the Microsoft Teams desktop client offers slash command support within the command box. Users will soon be able to type slash in Teams compose box and select a command in order to complete their tasks.

How to use slash commands in the Microsoft Teams compose boxOnce rolled out, Microsoft Teams users will simply need to enter a forward slash in the compose box to access a list of supported slash commands. Here are some common tasks that can be performed with slash commands:

  • /code: This command lets users add a code block to their message.
  • /loop: This command can be used to add a loop component to a message.
  • /away: This command allows users to set their presence indicator to away.
  • /setting: This command helps users navigate to settings.
  • /mute: This command can be used to mute a chat.

Slash commands in the Teams compose message box (Image Credits: Microsoft)Microsoft expects to roll out the new slash commands in the Teams compose box to targeted release customers later this month. This feature is expected to become generally available for all commercial customers worldwide in late June.

In related news, Microsoft has recently announced its plans to drop support for Classic Teams on July 1, 2024. Microsoft Teams users will begin seeing messages that the app is no longer supported. Microsoft will block users from accessing Classic Teams on Windows 7, 8, 8.1, and macOS Sierra (10.12) in October 2024.

The post Microsoft Teams Compose Box to Add Support for Slash Commands appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Exchange Server Subscription Edition (SE) is set to launch in Q3 2025, marking a shift towards subscription-based licensing for on-premises deployments. * Organizations will need subscription licenses for future Exchange Server releases to access updates, security patches, and technical support. * Microsoft plans to discontinue support for legacy perpetual server and Client Access Licenses (CALs) with Exchange Server SE.

Microsoft has revealed that Exchange Server Subscription Edition (SE) will debut in the third quarter of 2025. This upcoming on-premises release will require organizations to get subscription licenses for accessing product updates, security patches, and technical support.

According to Microsoft, Exchange Server SE will be “code equivalent” to Exchange Server 2019 CU15, but it would bring some minor changes. First of all, Microsoft plans to update the license agreement to reflect the new SKU. Additionally, the system name will be rebranded from Microsoft Exchange Server 2019 to Microsoft Exchange Server Subscription Edition. Microsoft will also update the build and version numbers.

Microsoft mentioned that Exchange Server SE will support two types of upgrades from previous versions. Customers will be able to perform an in-place upgrade from Exchange Server 2019 CU15. Microsoft says that this upgrade process would be identical to installing a cumulative update.

Exchange Server SE will also support legacy updates, which will require customers to build a new infrastructure and then migrate namespaces and mailboxes to the new infrastructure. Microsoft notes that customers still running Exchange Server 2016 will be required to perform a legacy upgrade to Exchange Server 2019 to prepare for the upcoming release.

Exchange Server SE CU1 to arrive in October 2025Going forward, Microsoft plans to release two cumulative updates annually for Exchange Server SE. The company expects to release the first CU for commercial customers in October 2025. It will include support for Kerberos for server-to-server communication instead of NTLMv2.

Additionally, Microsoft is phasing out Remote PowerShell (RPS) in favor of REST-based Admin APIs for Exchange Server. Furthermore, Exchange Server SE will discontinue support for Outlook Anywhere and co-existence with earlier versions.

“The RTM release of Exchange Server SE will not require any changes to Active Directory when upgrading from Exchange Server 2019. There are no Active Directory schema changes beyond those in Exchange Server 2019, and we will continue to support the Windows Server 2012 R2 forest functional level,” the Exchange team explained.

Exchange Server Subscription Edition LicensingMicrosoft has yet to reveal pricing details for Exchange Server SE. However, the company noted that customers will be able to download Exchange Server SE through the Microsoft 365 admin center. Just like the SharePoint Server Subscription Edition, it would require users to have either subscription licenses or licenses with active Software Assurance for both server and user licenses. Exchange Server SE doesn’t support legacy perpetual server and Client Access Licenses (CALs) used by Exchange 2019 or older versions.

Microsoft plans to release the final cumulative update (CU15) for Exchange Server 2019 customers in the second half of 2024. The upcoming update is expected to bring several new features and improvements, including Transport Layer Security (TLS) 1.5 and certificate management in the Exchange admin center (EAC).

It’s highly recommended that IT admins should get in touch with a Microsoft licensing specialist. It should help to understand how the new subscription-based licensing model will impact their organization.

The post Exchange Server Subscription Edition to Launch in Summer 2025 appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced that support for Copilot with Graph-grounded chat is now available in Outlook. * Copilot in Word now offers advanced capabilities such as refining specific document sections and summarizing selected text. * Copilot for Microsoft Excel introduces the ability to generate multiple formula columns simultaneously with a single prompt.

Microsoft has published a recap of all the new features and improvements added to Copilot for Microsoft 365 during the month of April 2024. The company highlighted several notable improvements tailored to enhance productivity and efficiency across desktop, mobile, and web platforms.

Later this month, Microsoft will add support for Graph-grounded Copilot chat to classic Outlook, the new Outlook for Windows client, and the Outlook web app. The AI assistant will allow users to find enterprise data (such as chats, meetings, emails, and documents) that are stored in the Microsoft cloud. Users will be able to ask questions and receive responses by clicking the Copilot icon at the top of the Outlook window.

Microsoft will also let Copilot for Microsoft 365 customers to ground Copilot chat in the local files stored on their computers. Users will also be able to easily share file links from OneDrive and SharePoint with Copilot for better conversations.

Copilot chat box in OutlookCopilot in WordMicrosoft has also announced several improvements for Copilot in Word. The Copilot AI assistant can use Graph-grounded data to answer questions, fine-tune specific sections of a document, and summarize selected text only. It’s also possible to use Draft with Copilot to reference files that are marked with sensitivity labels to create a new document draft. Later this month, users will also be able to copy/paste a link to a support file as a reference into Draft with Copilot.

Copilot in ExcelAdditionally, Copilot in Excel can now use a single prompt to generate multiple formula columns simultaneously. For instance, Microsoft Excel users can use a single prompt to extract both the first name and last name.

Microsoft Copilot mobile appMicrosoft says that commercial customers with eligible licenses can use a work account to sign in to the Copilot web app. Microsoft Copilot offers commercial data protection capabilities at no additional cost. IT admins can use Microsoft Intune to manage the Copilot mobile app within their tenants.

Notebook in Copilot Microsoft has also introduced a Notebook feature that allows users to create longer prompts that can be refined and fine-tuned over time. Users can access the Notebook feature at the top of the Copilot web app and Copilot in Bing.

Copilot chat box with a Notebook iconCopilot for Microsoft now supports new languagesMoreover, Copilot for Microsoft 365 has introduced support for 16 additional languages. Microsoft’s App Assure compatibility program has added support for Copilot for Microsoft 365 customers who use the monthly Microsoft 365 Apps channel. The company has also launched Restricted SharePoint Search in public preview, and it’s expected to be generally available in the next few weeks.

Lastly, Microsoft says that IT admins can manage Copilot availability and features in the Teams admin center. They can configure this setting to be on by default either just during the meeting or during and after the meeting.

The post Microsoft Outlook Gets Support for Copilot with Graph-Grounded Chat appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft’s new Purview AI Hub provides IT administrators with valuable insights into the usage of AI applications within their organization. * Microsoft has added AI compliance assessments and security posture management features to let organizations better safeguard their AI applications. * Microsoft’s unified security operations platform offers administrators valuable recommendations and suggestions to enhance the investigation and response process.

Microsoft has unveiled a host of new capabilities for its Microsoft Purview and Defender for Cloud solutions. The new features help IT administrators in efficiently managing, protecting, and governing AI applications within enterprise environments.

First off, Microsoft has launched a new Purview AI Hub in public preview. This new service enables IT admins to gain insight into how AI applications are being used within their organization. This capability helps to detect and mitigate data security and data compliance risks within their organization. Customers can access the new AI Hub through the Microsoft Purview portal or the Microsoft Purview compliance portal.

Microsoft Purview has also introduced new AI compliance assessments to help organizations govern AI usage to comply with regulatory policies. The four new Compliance Manager assessment templates are currently available in public preview for commercial customers.

Microsoft Defender for Cloud updatesMicrosoft has rolled out new AI security posture management capabilities for Defender for Cloud customers. This release enables customers to identify new AI attack surfaces, strengthen AI security posture, and protect AI apps against security threats. Microsoft says that AI security posture management capabilities are supported across different platforms, including Azure OpenAI Service, Azure Machine Learning, and Amazon Bedrock.

Microsoft has added new threat protection capabilities for AI workloads in Microsoft Defender for Cloud. This new feature offers integration with Azure OpenAI Service, Microsoft threat intelligence, and Azure AI Content Safety prompt shields to deliver real time contextual and actionable security alerts.

Microsoft Security (Image Credits: Microsoft)Microsoft’s unified security operations platform launches in previewMicrosoft has also announced the public preview of its new unified security operations platform experience. This new service provides recommendations and suggestions to help administrators speed up the investigation and response process.

Additionally, Microsoft has released a couple of new features for its Microsoft Sentinel and Defender XDR solutions, including automation rules, custom detections, and global search. Microsoft Defender XDR is getting new expanded attack disruption capabilities to protect customers against malicious OAuth apps.

Microsoft notes that native operational technology (OT) protection capabilities are now available for Microsoft Defender XDR customers. This new feature allows IT admins to detect and mitigate OT and industrial control system vulnerabilities.

Microsoft Copilot for Security now supports third-party pluginsLast but not least, Microsoft Copilot for Security is getting new integrations with various services, including Azure Firewall, Azure Web Application Firewall, and Microsoft Purview. Copilot for Security has also added support for various third-party plugins, including CIRCL.lu, Crowdsec, CyberArk, and Darktrace. Microsoft plans to add support for more plugins in the next few months.

The post Microsoft Purview and Defender for Cloud Add New Security Features to Protect AI Applications appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft is prioritizing security to protect its infrastructure and customers from cyber threats, expanding its Secure Future Initiative (SFI) to reinforce defenses. * Microsoft’s security approach encompasses six key pillars, including measures like multifactor authentication, network isolation, and enhanced threat detection, aiming to address vulnerabilities across its systems and processes. * Microsoft is instituting measures to hold senior leadership accountable for security goals.

Microsoft has announced plans to make security its top priority to better protect its infrastructure and customers against sophisticated cyberattacks. The company has recently detailed in a blog post that it’s expanding the Secure Future Initiative (SFI) to ensure robust protection measures.

Last year, Microsoft announced its Secure Future Initiative (SFI) to boost the built-in security of its products and services. It’s aimed at tackling software and vulnerability issues exploited by cybercriminals in recent high-profile security breaches.

As part of the SFI, Microsoft outlined several plans and changes to its security practices, with some already put into action. The company explained that this expanded SFI approach will be driven by three security principles: Secure by design, Secure by default, and Secure operations.

“Microsoft plays a central role in the world’s digital ecosystem, and this comes with a critical responsibility to earn and maintain trust,” said Charlie Bell, Executive Vice President for Microsoft Security. “We’re expanding the scope of SFI, integrating the recent recommendations from the CSRB as well as our learnings from Midnight Blizzard to ensure that our cybersecurity approach remains robust and adaptive to the evolving threat landscape.”

Microsoft’s Secure Future Initiative (Image Credits: Microsoft)Microsoft evolves its Secure Future Initiative approachMicrosoft detailed the following six actionable security pillars to address vulnerabilities in its systems and development processes:

  • Protect identities and secrets: Microsoft plans to use phishing-resistant multifactor authentication methods to protect 100 percent of user accounts, applications, and identity tokens against unauthorized access.
  • Isolate production systems: Microsoft will also implement strict controls aimed at isolating and safeguarding production environments in order to reduce the likelihood of security breaches.
  • Enhance network security: Microsoft will utilize isolation and micro-segmentation techniques to enhance the protection of production networks. This strategy will add an extra layer of security for both customer and Microsoft resources.
  • Secure engineering systems: Microsoft plans to strengthen the governance of software supply chains and engineering infrastructures via Zero Trust and least-privilege access policies.
  • Accelerate response and remediation: Microsoft will adopt the Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) industry standards to mitigate critical security vulnerabilities.
  • Enhanced detection and monitoring: Microsoft will use advanced threat detection and monitoring capabilities to quickly detect and respond to potential security incidents. The company also intends to retain all system security logs for at minimum two years, while customers will have access to six months of relevant logs.

Microsoft highlighted that it has already enabled automatic multifactor authentication by default in Microsoft Entra ID tenants. The company has also expanded its security logging and removed 730,000 insecure apps deployed across production and corporate tenants.

Lastly, Microsoft noted that the pay of its senior leadership will be directly tied to reaching the internal security plans and milestones. The company will also hold monthly and weekly meetings with engineering teams and senior leaders to review progress and ensure alignment with security objectives.

The post Microsoft Expands Secure Future Initiative to Counter Rising Cyber Threats appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Entra External ID will become generally available on May 15. * This new service provides customers with the ability to create secure sign-in interfaces for customer-facing web apps and pages. * Microsoft offers free access to Entra External ID features for commercial customers until July 1, 2024.

Microsoft Entra External ID, the new customer identity access management solution (CIAM) that the company announced last year, is set to officially launch on May 15. This new service allows organizations to create sign-in interfaces for customer-facing Web apps and pages.

Microsoft mentioned that it could be challenging for IT admins to manage external identities (such as customers, partners, and business clients) as well as their access protocols. The new Entra External ID capabilities enable employees to collaborate with business partners and guests seamlessly. This feature facilitates secure access for external identities to corporate apps and resources through either invitation or self-service sign-up.

“With External ID, you can consolidate all identity management under the security and reliability of Microsoft Entra. Microsoft Entra provides a unified and consistent experience for managing all identity types, simplifying identity management while reducing costs and complexity,” Microsoft explained.

Microsoft Entra External ID (Image Credits: Microsoft)Secure collaborationMicrosoft highlights that cross-tenant access settings let administrators manage external collaborators’ access to corporate resources. The ID Governance for External ID feature facilitates automatic review and revocation of access after periods of inactivity or project completion. This capability helps IT admins to ensure that only authorized external users have access to sensitive internal resources and data.

Moreover, Microsoft Entra External ID allows customers to natively integrate secure authentication capabilities into the sign-in experience of their web and mobile apps. They can use authentication options and verifiable credentials to streamline the sign-up/sign-in process for end users.

Microsoft Entra External ID pricingMicrosoft notes that commercial customers can enjoy free access to all Entra External ID capabilities until July 1, 2024. The company is offering access to these features for the 50,000 monthly active users (MAU) at no additional cost, with additional active users priced at $0.03 per MAU.

Furthermore, organizations can take advantage of the discounted price of $0.01625 per MAU until May 2025. If you are interested, you can learn more about External ID pricing on this FAQs page.

The post Microsoft Entra External ID Simplifies Customer Identity Access Management appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has added Copilot to the new Planner app in Teams to streamline project planning, management, and tracking. * The Copilot feature is rolling out gradually to commercial customers with Project Plan 3 or Project Plan 5 subscriptions. * Microsoft has announced the general availability of the new Planner experience in Teams.

Microsoft has started rolling out the Copilot AI assistant to the new Planner app in Teams. The new Copilot integration allows team members to plan, manage, and track projects directly within the Teams desktop and web apps.

Microsoft highlights that Copilot in Planner enables team members to use natural language commands to generate a plan, including goals, tasks and subtasks, and buckets. Users can also ask the digital assistant to create comprehensive plans for their upcoming projects.

With Copilot in Planner, customers can effectively manage their plans. The Copilot AI assistant can provide suggestions about tasks based on new goals. It can also help users add new goals to their plan and automatically generate tasks aimed at accomplishing those goals. The Copilot feature also lets users ask questions about the progress, priorities, and workload to stay informed on complex plans.

“With the power of generative AI, Copilot in Planner streamlines the planning, management, and execution of your work, keeping you informed as you achieve your goals. Copilot in Planner helps teams transform the way they work and collaborate on projects together,” Microsoft explained.

Copilot in new Planner (Image Credits: Microsoft)The new Copilot in Planner experience is rolling out gradually in public preview to commercial customers over the next few weeks. The new Copilot feature is available for organizations with a Project Plan 3 ($30 per month per user) or Project Plan 5 ($55 per month per user) subscription.

Microsoft is offering a free 30-day trial of Copilot in Planner for customers who don’t have a premium Project license. Users will need to click the “diamond” icon within the app to test the Copilot in the new Planner capabilities. Microsoft plans to reveal the final price of this feature when it becomes generally available for everyone.

New Microsoft Planner app in Teams is now generally availableMicrosoft has also announced the general availability of the new Planner experience in Teams that launched in preview earlier this year. This new Planner app includes several features and enhancements based on user feedback. It offers project timeline tracking and monitoring capabilities via a Gantt chart. Moreover, the task history feature provides detailed insights about a specific task. The new Planner app also allows users to break down complex tasks into smaller action items.

Microsoft plans to add a couple of top-requested features to the new Planner app in the coming weeks. These include an improved My Day and My Tasks experience and the ability to upgrade a basic plan to a premium plan.

The post New Microsoft Planner App in Teams Gets Copilot Integration to Streamline Collaboration appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Teams has added support for multi-turn conversations with Copilot, live translated captions for webinars, and custom profile pictures. * Microsoft Teams meetings are getting features like multi-account support, the ability to hide the general channel, and context-based file attach suggestions. * Microsoft Teams Phones now support AI voice isolation, call history sharing, and a busy on busy end user setting.

Microsoft has published a recap of all the new capabilities added to Teams during the month of April 2024. The company has enhanced the chat and meeting experience with multi-turn conversations with Copilot, live translated captions for webinars, custom profile pictures, and more.

Chat and collaboration featuresFor starters, Microsoft detailed a couple of enhancements to the chat and collaboration experience in Microsoft Teams. The Copilot AI assistant in Teams chats and channels has added support for multi-turn conversations. The feature allows users to ask follow-up questions to a Copilot response such as “Explain the second point in the summary.” Microsoft Teams has introduced multi-account support for government customers.

Microsoft Teams allows users to hide general channels in order to reduce clutter in the channel list. Moreover, users can set a custom profile picture for Teams group chats, making it easier to find a specific chat. Microsoft Teams now offers context-based file attach suggestions from OneDrive and SharePoint.

Multi-turn conversation with Copilot in chats and channels (Image Credits: Microsoft)Enhancements to Teams meetingsMicrosoft Teams has added a new feature that allows users to manage calendar notifications for upcoming meetings from their activity feed. The Teams admin center allows IT admins to control how people in their organization use the Copilot AI assistant for meetings and events.

Additionally, Microsoft Teams town halls now support live translated captions in up to six different languages. Microsoft says that organizers with a Teams Premium license can choose up to 10 languages. Microsoft Teams town halls indicate new notifications for questions or replies with a red dot beside the Q&A icon.

Calendar notifications in Microsoft Teams (Image Credits: Microsoft)Microsoft Teams Phones and other updatesMicrosoft Teams Phone customers can leverage AI-powered voice isolation capability to suppress background noise. Furthermore, Microsoft has added new incoming call setting options for Teams Phone mobile users. Users can also manage call forwarding settings through the home screen of the device. Other capabilities include shared call history for call delegation, busy on busy end user setting, as well as call on behalf of the call queue.

Voice isolation (Image Credits: Microsoft)Last month, Microsoft announced a couple of new Teams-certified devices. These include the Yealink UH35 headset, the Bang & Olufsen Cisco 950 MS earbuds, and the Dell WL7024 headset.

Last but not least, Microsoft has introduced a new setting that lets administrators limit presenter role permissions within their organization. This feature can be used to prevent presenters from performing certain actions such as controlling attendees’ mics and cameras, removing participants, lowering hands, and changing the roles of other participants.

The post Copilot in Microsoft Teams Now Supports Multi-Turn Conversations appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has added new device management capabilities to Intune this month. * The updated app supersedence feature lets IT admins easily keep Win32 applications up to date. * The new remote diagnostics feature aims to simplify the process of obtaining diagnostics from Microsoft 365 apps running on Android and iOS devices.

Microsoft released several new device management capabilities for its Intune solution in April 2024. The company highlighted several improvements, including streamlined app updates for better security and productivity and simplified troubleshooting for Microsoft 365 apps.

Microsoft has introduced updated app supersedence to help administrators keep Win32 applications up to date. The supersedence feature lets IT admins update and replace existing Win32 apps with new versions of the same app or a different Win32 app. They can now add an app to Intune and create a supersedence relationship with an existing app. This capability eliminates the need to monitor app updates and manually update applications.

The new remote diagnostics feature is designed to simplify the process of getting diagnostics from Microsoft 365 apps running on Android and iOS devices. IT admins can configure this feature by navigating to the Intune admin center >> Tenant administration >> Device diagnostics and setting the ”Diagnostics for Microsoft 365 applications…” option to enabled.

Remote diagnostics (Image Credits: Microsoft)Microsoft Intune adds Windows update distribution reportThe new Windows update distribution report in Intune provides a summarized report on what quality updates are running on which devices. It consists of three separate organizational reports that offer insights into devices and their associated Windows update versions. To access this feature, IT admins will need to navigate to Reports > Windows Updates > Reports tab > Windows Update Distribution Report.

“The report provides a drill down for each quality update that aggregates devices based on windows 10/11 feature version and the update statuses,” Microsoft explained. “The report includes Intune managed and co-managed devices, and is based on the OS version updated at every device check-in. The report can slice the data based on device scope tags.”

Windows update distribution report (Image Credits: Microsoft)Microsoft plans to make some improvements to the Windows update distribution report in the coming months. The company will add new select all and deselect all options in the Scope tags dropdown menu. Microsoft will also introduce additional filters in the managed by managed by and last check-in columns.

The post Microsoft Intune Gets New Device Management Capabilities appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has introduced an Offline mode for the OneDrive web app, enhancing accessibility and productivity for work and school accounts. * Users can now access, manage, and modify files via web browsers even without an internet connection. * The new Offline mode brings significant performance improvements, offering users a smoother and faster experience.

Last year, Microsoft unveiled its plans to introduce a new Offline mode for the OneDrive web app. Now, the company has announced the rollout of new Offline capabilities for work and school accounts.

With this new Offline mode, OneDrive lets users access their files via a web browser when offline and then automatically sync back any changes once the Internet connection is restored. Moreover, the feature allows users to navigate to different sections such as Home, My files, Shared, Favorites, People, and Meeting. Users can also rename, sort, move, copy, and delete files without Internet access.

Additionally, the new Offline mode allows users to perform certain actions that previously required using File Explorer on Windows and Finder on macOS. For instance, it’s possible to mark files available offline as well as conserve local storage space simply by marking them as “online only.”

Microsoft claims that the new Offline mode also brings performance improvements for users with internet connectivity. Users should notice 3x faster loading times when viewing files in the OneDrive web app and the OneDrive experience in Teams or Outlook.

“By accessing your content from your local cache instead of fetching it from a cloud server, data retrieval speeds are significantly improved,” the OneDrive team explained. “The result? A smooth OneDrive experience that’s insulated against slow or intermittent connections. Furthermore, this enhancement has the added advantage of bypassing cloud service-related throttling issues.”

Offline mode in OneDriveHow to enable the Offline mode in OneDrive?Microsoft has announced that the rollout of the new Offline mode will occur gradually for all users with work and school accounts, but it is currently unavailable for consumers. Users should be running the latest version of the OneDrive Sync app on their PCs. The Offline mode supports Chromium-based browsers in Windows and macOS, and users can enable or disable this feature through a per-device setting.

Currently, the new offline capabilities in the OneDrive web app come with limitations. This feature is operational only when the user’s repository contains fewer than 250,000 files. Moreover, the Offline mode does not support shortcuts to shared folders in OneDrive. Keep in mind that users won’t be able to access certain capabilities, including Copilot, search, file version history, managing access, and file deletion. “

The post Microsoft OneDrive Starts Rolling Out New Offline Mode for Work and School Accounts appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has launched the Trusted Signing solution, offering a fully managed end-to-end signing service aimed at simplifying app development and distribution processes. * The solution supports both public and private trust signing scenarios and incorporates modern security features like Smart App Control and SmartScreen. * Developers and ISVs can take advantage of a free trial of the Trusted Signing solution until June 2024.

Microsoft has recently announced the public preview of its new Trusted Signing solution. This fully managed end-to-end signing service is designed to streamline processes, allowing developers to effortlessly build and distribute apps.

“The service supports both public and private trust signing scenarios and includes a timestamping service. With Trusted Signing, users enjoy a productive, performant, and delightful experience on Windows with modern security protection features enabled such as Smart App Control and SmartScreen,” Microsoft explained.

Microsoft highlights that the new solution offers an intuitive experience in Azure to simplify the signing process. Moreover, it helps to manage the full certificate lifecycle and key storage that is FIPS 140-2 Level 3 compliant. The service also offers support for different profile types such as Public Trust, Private Trust, and Test.

Creating a Trusted Signing Account (Image Credits: Microsoft)Additionally, the new trusted signing solution integrates with popular developer toolsets like SignTool.exe, GitHub, and Visual Studio. For Private Trust, it provides PowerShell cmdlets for IT admins to sign Windows Defender Application Control (WDAC) policies. Microsoft plans to offer potential integrations with IT endpoint management solutions in the future.

Trusted Signing PricingMicrosoft will provide two SKUs (basic and premium) for the new trusted signing solution, and you can view the pricing details in the screenshot below:

Trusted Signing Basic and Premium SKUsMicrosoft notes that developers and ISVs will need to navigate to the Azure portal to try out the trusted signing solution. The company says that Azure customers will be able to access the new trusted signing solution for free until June 2024. We invite you to check out this quick-start guide to learn more about the onboarding process.

The post Microsoft Introduces Trusted Signing Solution: Simplifying App Development for Developers appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft is introducing a new meeting response option called “Follow” for the new Outlook for Windows and the Outlook web app. * The “Follow” response enables users to stay informed about meeting events even if they can’t attend, fostering greater engagement and collaboration. * This feature aims to cater to individuals with busy schedules and conflicting meetings.

Microsoft Outlook is about to add a new meeting response option (RSVP) to the new Outlook for Windows and the Outlook web app. The new “Follow” option for meeting responses will provide users with a way to stay engaged even when they can’t attend.

The new follow feature will inform organizers that the user won’t attend the meeting but still wants to remain informed and access post-meeting information. The Follow response will also remind the organizer to record the meeting and take collaborative notes.

The attendees will be able to access the meeting chat, recordings, and transcripts. Moreover, the attendees’ calendars will show the time as free, enabling them to manage their schedules more effectively.

“Follow is a new meeting response (RSVP) option that goes beyond the traditional Accept, Tentative and Decline choices geared towards individuals with high meeting loads and conflicting meetings each day. Follow is the ideal RSVP option for meetings you can’t attend but still want to stay engaged and receive info about. Other attendees will be able to see if you are following a meeting,” Microsoft explained.

Meeting invitation email with new Follow option (Image Credits: Microsoft)Microsoft Outlook’s ‘Follow’ feature to hit GA in JulyMicrosoft says that attendees will be able to respond with the “Follow” option only when a meeting has two or more participants and the organizer has requested responses. Moreover, the meeting response will appear as “Tentative” in the classic version of Outlook for Windows, Outlook for Mac, and the Outlook mobile apps. The organizer will also see a notification that the invitee is following the meeting.

Microsoft says that the new meeting response option will begin rolling out to targeted release customers in May. The feature is expected to become generally available for commercial customers in July 2024. At launch, this capability won’t be available for Outlook for Mac or the Outlook mobile apps.

The post Microsoft Outlook will Let Users Follow Teams Meetings appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s FY24 Q3 earnings beating all expectations as the company’s huge bet on Copilot and generative AI continues to pay off.

The post First Ring Daily: Big Numbers appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has introduced multi-tenant organization (MTO) capabilities for Entra ID customers to enhance cross-tenant collaboration in Microsoft Teams and Viva Engage. * MTO allows up to five Entra ID tenants to share resources and collaborate, which is beneficial for organizations with multiple Microsoft 365 tenants. * Participation in multi-tenant organizations requires Entra ID Premium P1 licenses for users.

Microsoft has announced the general availability of the new multi-tenant organization (MTO) capabilities for Entra ID customers. The new feature is designed to enhance the cross-tenant collaboration experience in Microsoft Teams and Viva Engage.

A multi-tenant organization is a group of up to five Entra ID tenants that are linked together by cross-tenant access policies to let users collaborate and share resources. This solution could be useful for organizations that span multiple Microsoft 365 tenants and need to share information.

Microsoft first announced released of the new Entra ID multi-tenant organization feature in public preview in mid-2023. It allows users to share applications and engage across tenants with Microsoft Teams and Viva Engage.

“As your organization evolves, you may need to integrate multiple tenants to facilitate collaboration,” said Joseph Dadzie, Partner Director of Product Management. “With disparate identity management systems, it can be costly and complex for admins to manage multiple tenants while ensuring users across tenants have access to resources to collaborate.”

Multi-tenant organization capabilitiesWhy should you use multi-tenant organization capabilities?Microsoft has highlighted several key benefits of a multi-tenant organization. In the new Microsoft Teams desktop client, employees can use chat, call, and meeting experiences to collaborate with users in another tenant. The new app also allows users to receive real-time notifications from all tenants across the multi-tenant organization.

Additionally, multi-tenant organizations allow IT administrators to centrally manage permissions and policies to prevent unauthorized access to data. Multi-tenant organizations facilitate enhanced compliance for organizations by simplifying the management of user access to data.

Getting started with Entra ID multi-tenant organizationsTo get started with multi-tenant organizations, IT admins will first need to create their multi-tenant organization via Microsoft 365 admin center, PowerShell, or Microsoft Graph API. The second step involves adding users to each other’s tenants as an external member for collaboration. Lastly, IT admins should ensure to meet specific requirements for Microsoft Teams or Viva Engage

Microsoft notes that users participating in multi-tenant organizations will require Entra ID Premium P1 licenses. It’s important to note that each employee within a multi-tenant organization needs only one license, and each tenant must possess at least one Microsoft Entra ID P1 subscription. You can learn more about multi-tenant organization capabilities in our previous article.

The post Microsoft 365 Multi-Tenant Organization Capabilities Generally Available for Enhanced Cross-Tenant Collaboration appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft is shrinking the size of update packages for Windows 10 version 22H2. * This change promises faster downloads, minimized network traffic, and better performance on Windows 10 PCs. * Users will find that recent Windows 10 Cumulative Updates (CUs) have shrunk by 22%, making updating less burdensome and more manageable.

Microsoft has announced its plans to significantly reduce the size of its updates for Windows 10 version 22H2. The company has introduced an improved cumulative update (CU) technology that promises expedited downloads, reduced network congestion, and optimized performance, particularly benefiting users on slower connections.

In 2021, Microsoft detailed its efforts to cut down the size of Windows 11 update by around 40 percent. Specifically, Microsoft no longer includes the reverse-differential bits in Windows 11 cumulative updates. The company found a way to generate these bits only in cases where they are needed. Microsoft also changed the internal structure of the cumulative update to deliver smaller CUs to Windows 11 devices.

Now, Microsoft is bringing the same compression technology to reduce the size of monthly cumulative updates on Windows 10 devices. “Starting April 23, 2024, the LCU will no longer have the reverse differentials. The client will generate the reverse update data. This change will help to reduce the LCU package size by about 20%. This change also offers a few advantages,” Microsoft explained.

Microsoft highlighted notable reductions in the size of its latest cumulative update (LCU) Windows packages. For example, the KB5036892 and KB5036979 updates, released earlier this month, are sized at 830 MB and 650 MB, respectively. This improved cumulative update (CU) technology has resulted in a reduction of approximately 22 percent in the Windows 10 update size.

Windows 10 updates (Image Credits: Petri/Rabia Noureen)What are the benefits of smaller Windows 10 updates?Microsoft noted that distributing large Windows updates consumes significant bandwidth, particularly for customers with limited access to high-speed broadband connections. The new cumulative update enhancements aim to assist both organizations and consumers in conserving bandwidth and reducing network traffic. It should also make it easier for customers to remain up-to-date and secure.

It’s important to note that Windows 10 will reach end of support on October 14, 2025. Microsoft says that organizations that want to keep using the operating system will need to pay to access Windows 10 extended security updates. The Windows 10 ESU program will offer critical or important security patches for a maximum of three years.

The post Microsoft Reduces Size of Windows 10 Updates for Faster Downloads appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced the retirement of the classic Teams desktop app, with end of support scheduled for July 1, 2024. * Microsoft says access to classic Teams will be blocked on Windows 7, 8, 8.1, and Mac OS Sierra in October. * Microsoft recommends IT admins to transition users to the new Teams to receive new features and improvements.

Microsoft will soon officially retire the classic version of Microsoft Teams. The company has announced on the Microsoft 365 admin center that the classic Teams desktop app will reach end of support in July this year.

Starting July 1, 2024, Microsoft will begin informing its commercial customers through periodic in-app dialog messages that classic Teams is no longer supported. The classic Microsoft Teams desktop client will stop getting any new features and improvements. Microsoft says the informational messages will urge users to switch to the new Teams desktop client.

When will classic Teams reach end of availability?Microsoft plans to block customers from accessing classic Teams on October 23, 2024. This change will impact Windows 7, Windows 8, Windows 8.1, and Mac OS Sierra (10.12). However, the app will continue to work for users with configuration issues on Windows 10, macOS versions Big Sur(11) or lower until July 1, 2025. After that date, the new Teams web app will be available on supported browsers as an alternative.

“This gives admins more time to address any issues encountered during this process. We do ask that users update their OS and address any other issues to continue using the Teams client after this time, as new features are only being added to the new Teams client,” Microsoft explained.

Non-dismissible in-app dialogs (Image Credits: Microsoft)Why should you switch to the new Microsoft Teams app?Microsoft announced the general availability of its new Teams desktop client in October 2023. The new app is based on the React framework and Edge WebView 2 rather than the resource-intensive Electron framework. Microsoft says that the new Teams is now two times faster and consumes 50 percent less memory compared to the previous app.

The new version of Microsoft Teams offers various features such as 7×7 video, contextual search in chat, call queues, and breakout rooms. It also supports custom line-of-business apps, third-party apps, Copilot for Microsoft 365, and multi-tenant organization capabilities.

Microsoft recommends administrators to transition their end users to the new Teams app as soon as possible. The company advises them to mitigate issues (such as IT policy/firewall blocking app installation and missing WebView2) within their organizations. You can find the prerequisites for new Teams on this support page.

The post Microsoft to Retire Classic Teams on July 1, 2024 appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Real-time co-authoring capabilities allow Dropbox customers to collaboratively edit Word, PowerPoint, and Excel documents. * Dropbox also announced enhanced security features, including end-to-end encryption and advanced data protection tools. * IT admins can now manage team membership and invites from a central dashboard.

Dropbox and Microsoft are teaming up to more closely integrate the cloud storage service into Microsoft 365. The company has announced today several new features aimed at improving organization and collaboration for Microsoft 365 customers.

Microsoft Teams already allows users to search, preview, upload, and share files and other content stored in Dropbox. The latest update now lets customers use Dropbox’s plugin extension for Copilot for Microsoft 365 to answer questions and summarize documents. Dropbox is also getting real-time co-authoring support for Office files, allowing team members to collaboratively edit Word, PowerPoint, and Excel documents. This top-requested feature is available in beta for all desktop, mobile, and web users.

Additionally, Dropbox has introduced a new integration called Dropbox Replay for OneDrive. Dropbox Replay is a tool that helps to streamline the process of video reviews and approvals. This new feature enables users to bring media files from OneDrive directly into Dropbox Replay for efficient reviews and approvals. Users can sign up for the Co-Authoring beta and access the Dropbox Replay for OneDrive integration on this page.

Real-Time Co-Authoring beta (Image Credits: Microsoft)Security featuresDropbox has also announced several advanced data protection capabilities for commercial customers. The company has added end-to-end encryption support to provide an additional layer of security for confidential content stored in team folders. Moreover, it’s now possible to configure a unique encryption key managed by FIPS 140-2 Level 3 key management services. This feature should make it easier for users to protect and manage all team Dropbox files.

Dropbox adds new management toolsLast but not least, Dropbox has introduced new tools that should make it easier for administrators to access important information. A central dashboard allows IT admins to keep track of license usage and pending invites. The company has introduced an updated Trust Center to monitor security, reliability, privacy, and compliance issues. It also helps administrators to complete internal reviews, audits, and risk assessments.

Dropbox says that the new security capabilities are available for all Dropbox Advanced, Business Plus, and Enterprise customers worldwide. If you’re interested, you can learn more about these updates on Dropbox’s official website.

The post Dropbox Introduces New Real-Time Co-Authoring Support for Microsoft 365 Apps appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: * A new monitoring dashboard within Configuration Manager enhances administrators’ ability to detect and address software update issues efficiently. * Microsoft has announced the discontinuation of support for Windows Server 2012/2012 R2 operating system site system roles. * Microsoft also released improvements to BitLocker key escrow verification to prevent data loss.

Microsoft has announced the release of the update 2403 for Configuration Manager (Current Branch). Among its notable features are the rebranding of Azure Active Directory to Microsoft Entra ID, a new monitoring dashboard for detecting software update issues, streamlined search capabilities, and more.

Microsoft Configuration Manager is a software management suite that lets organizations manage large numbers of computers running macOS, Windows, Linux, and mobile operating systems. The service offers various tools to streamline software deployment, compliance monitoring, patch management, and remote administration.

Microsoft has rebranded Azure Active Directory (Azure AD) to Microsoft Entra ID within Configuration Manager. Additionally, a new dashboard in the monitoring workspace facilitates easier detection of software update issues. The Configuration Manager console now includes a search box to enhance search efficiency and consolidate access to important information. This feature saves time and effort previously spent navigating through various nodes or sections.

Software update health dashboard (Image Credits: Microsoft)Folder support for scriptsThe latest Configuration Manager update allows administrators to use folders to organize and manage scripts. This feature is available for both full administrators and operations administrators. Additionally, Microsoft has deprecated HTTP-only communication, advising customers to opt for HTTPS or Enhanced HTTP for client communication instead. The latest version of Configuration Manager no longer supports Windows Server 2012/2012 R2 operating system site system roles.

Software & OS updatesMicrosoft has added a new SoftwareUpdateO365Language parameter to the PowerShell Save-CMSoftwareUpdate cmdlet. This feature streamlines the process by removing the requirement to manually check for specific languages in the Software Update Point (SUP) Properties. Furthermore, Windows 11 ARM 64 devices are getting support for Configuration Manager operating system deployment. This capability currently supports importing and customizing Arm 64 boot images, Media creation TS, Wipe and load TS, CMPivot, and WDS PXE for Arm 64.

Support for ARM 64 Operating System Deployment (Image Credits: Microsoft)Cloud-attached managementMicrosoft has also deprecated the option to upgrade to Configuration Manager 2403 for customers running cloud management gateway V1 (CMG) as a cloud service (classic). Administrators will need to manually convert CMG deployed with the classic cloud service to a virtual machine scale set deployment before starting the upgrade process.

Updates to BitLockerLastly, the latest release brings a couple of improvements to BitLocker. This feature ensures that key escrow is verified correctly and helps to prevent any message drops. It checks if the key is successfully stored in the database before adding the key protector. Moreover, Bitlocker now prevents a situation where data could be lost if there are any failures to escrow. It happens when BitLocker protects volumes using keys that are never backed up to the database.

The post Microsoft’s Configuration Manager Update 2403 Brings Diagnostic Dashboard, Other New Features appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft Intune Remote Help now offers full control support for macOS devices. * The new feature allows IT help desk agents to gain complete control over Mac systems to reduce time to mitigation. * This capability streamlines troubleshooting processes, allowing help desks to tackle problems quickly and efficiently.

Microsoft Intune Remote Help has introduced full control support for macOS devices. The new feature allows IT help desk agents to quickly address issues by gaining full control over any Mac device.

Microsoft Intune Remote Help is a cloud-based solution that provides secure help desk connections. It uses role-based access controls to let support agents remotely troubleshoot issues on employees’ computers. Remote Help can be used to improve efficiency, mitigate security risks, and support workers. It’s available as an add-on to all Microsoft 365 plans that include Intune.

Microsoft emphasizes that this release is part of its broader initiative to provide cross-platform support, allowing administrators to manage any device using Microsoft Intune. The Remote Help app for macOS now offers both view-only and full control capabilities. This new feature enables support staff to remotely control the mouse and keyboard on Mac devices.

“With this new functionality, IT help desks can now not only view Mac devices, but also take full control of them, streamlining troubleshooting and reducing time to mitigation. Whether it’s configuring settings, troubleshooting software glitches, or assisting information workers, help desks can tackle problems quickly and efficiently,” the Microsoft Intune team explained.

The Intune admin console (Image Credits: Microsoft)How Remote Help works with macOS devicesWhen an employee reports an issue, the help desk agent identifies the relevant device and initiates a Remote Help session through the Intune Admin Center. The agent can then opt to begin either a new screen-sharing session or a full control session on a macOS device. The Remote Help app lets employees view information about the help desk agent, including their name, photo, job title, and domain verification via Entra ID.

Lastly, the Remote Help app prompts the employee to either allow or deny the Remote Help session. The help desk agent also receives warnings about devices that are not compliant with the organization’s security policies.

Overall, the addition of full control support for macOS devices in Microsoft Intune Remote Help should enhance the troubleshooting experience for IT help desk agents. This update streamlines processes and enhances security measures, facilitating quicker issue resolution and better support for employees within organizations.

The post Microsoft Intune Remote Help Gets Full Control Support for macOS Devices appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Russian hackers are exploiting a Windows print spooler flaw to gain elevated privileges and steal credentials in compromised enterprise networks. * The hacker uses a custom tool named GooseEgg to target organizations, indicating a sophisticated and deliberate approach to cyber infiltration. * Microsoft advises applying patches and implementing to mitigate the risk of cyberattacks.

Microsoft has warned customers about the exploitation of a Windows print spooler vulnerability by Russian hackers, enabling them to elevate privileges and pilfer credentials within compromised enterprise networks. The Russian hacking group is using a custom tool known as GooseEgg to target a range of organizations.

What is Windows Print Spooler vulnerability?Microsoft patched the print spooler elevation of privilege vulnerability (CVE-2022-38028) in October 2022. The security flaw, which carries a CVSS rating of 7.8, allows attackers to attackers to remotely execute code with system-level privilege on vulnerable machines. The Windows print spooler service manages the printing process in Windows environments.

On Monday, Microsoft disclosed that Forest Blizzard (aka Fancy Bear) has been exploiting the CVE-2022-38028 vulnerability in the Windows Print Spooler service since at least June 2020. The hacking group has been linked by the US and UK governments to the Russian General Staff Main Intelligence Directorate (GRU).

Microsoft found that the Russian-backed threat actor exploited the security flaw to gain unauthorized access to a target Windows device. The attackers use a simple batch script to deploy the GooseEgg executable and establish persistence on the compromised system.

“While a simple launcher application, GooseEgg is capable of spawning other applications specified at the command line with elevated permissions, allowing threat actors to support any follow-on objectives such as remote code execution, installing a backdoor, and moving laterally through compromised networks,” the Microsoft Threat Intelligence team explained.

GooseEgg binary adding driver stores to an actor-controlled directory (Image Credits: Microsoft)According to Microsoft, Forest Blizzard is using GooseEgg to launch attacks on organizations based in Ukraine, Western Europe, and North America. These targets span across various sectors including government, non-government, education, and transportation.

How to protect Windows devices against Forest Blizzard cyberattacks?Microsoft’s advisory suggests that administrators should ensure that the fix for CVE-2022-38028 and CVE-2021-34527 has been deployed on Windows devices. Additionally, the company recommends disabling the print spooler service on domain controllers. A domain controller is a server computer that authenticates and validates user access on a network, and it doesn’t require printing capabilities.

Microsoft Defender for Identity offers a built-in security assessment that helps system admins detect the availability of Print Spooler services on domain controllers. You can find the full list of threat-hunting queries and indicators of compromise on Microsoft’s official blog post.

The post Russian Hackers Exploit Critical Windows Vulnerability to Deploy ‘GooseEgg’ Malware appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft discourages the use of iPerf3 on Windows devices due to compatibility issues and performance concerns. * Microsoft warns that older versions of iPerf3 may limit network benchmarking capabilities on Windows machines. * Microsoft recommends alternative tools like ntttcp and ctsTraffic for network performance testing.

Microsoft has issued an advisory against using the iPerf3 tool on Windows devices, citing compatibility and performance concerns. The company highlights issues with iPerf3’s reliance on Cygwin emulation layer and potential discrepancies in network testing.

iPerf is a popular tool that is used for measuring network bandwidth and performance across different platforms. It’s maintained by Energy Sciences Network (ESnet) and enables users to assess their network’s capabilities and ensure optimal performance.

Why you shouldn’t use iPerf3 on Windows?Microsoft has outlined three main reasons why it discourages the use of iPerf3 on Windows PCs. First of all, ESnet officially supports CentOS 7 Linux, FreeBSD 11, and macOS 10.12, and does not extend its support to running iPerf3 on Windows. The company recommends customers to use iPerf2 for monitoring network performance on Windows devices.

Secondly, Microsoft notes that iPerf3 does not make native API calls on Windows machines. The tool uses Cygwin as an emulation layer to work on Windows, and it causes significant performance issues. Microsoft also mentioned that some advanced iPerf3 features for network testing are either not supported or may trigger unexpected issues on Windows PCs.

“The iPerf3 calls are sent to Cygwin, which translates them to Windows APIs calls. Only then does the Windows network stack come into play. The iPerf3 on Windows maintainers do an excellent job of making it all work together, but, ultimately, there are potential issues with this approach,” Microsoft explained.

Last but not least, Microsoft warned that some Windows customers are probably using an older version of the iPerf3 tool. The company released iPerf3 version 3.1.3 for Windows back in June 2016. It’s important to note that this release uses Cygwin as an emulation layer and contains a bug that limits the socket buffer to 1MB. This could potentially lead to performance issues and inaccuracies in testing.

What are the recommended network benchmarking tools?Microsoft recommends that customers should use its network benchmarking solutions such as ntttcp (Windows NT Test TCP) and ctsTraffic. The ntttcp tool allows users to assess and measure the performance of TCP/IP networks on Windows. It simulates various network traffic scenarios to evaluate network throughput, latency, and other metrics.

Meanwhile, ctsTraffic is used to analyze network performance as well as measure throughput, latency, and packet loss. The tool helps to evaluate the behavior of networking devices under different load conditions.

The post Microsoft Advises Against iPerf3 Usage for Network Testing on Windows appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways:* Microsoft has announced a public preview of the Purview Audit Search Graph API. * The new API provides organizations with a more efficient and reliable way to search and retrieve audit logs. * The Purview Audit Search Graph API is expected to hit general availability in June 2024.

Microsoft has launched its new Purview Audit Search Graph API in public preview for commercial customers. This new API allows IT administrators to programmatically search and retrieve audit logs, improving how organizations track and secure their data usage.

Microsoft Purview Audit is a feature that lets IT administrators monitor and track data usage and access within their organizations. It offers various capabilities like generating audit reports, logging data access events, and monitoring activities across data sources and platforms.

“The Microsoft Audit Search Graph API is designed to provide a more efficient and reliable way to search audit logs, making it easier for customers and partners to monitor and investigate security incidents. With this new feature, users can expect faster search times, more complete search results, and a more robust and reliable search experience,” Microsoft explained.

The new Microsoft Purview Audit Search Graph API offers various search, reliability, and performance improvements over the existing Search-UnifiedAuditLog PowerShell cmdlet. For starters, the API provides an asynchronous Audit search experience with automation capabilities for both apps and end users. It’s also designed to offer enhanced search completeness and reduce timeouts.

Microsoft Purview Audit Search Graph API introduces enhanced granular permissionsMicrosoft has introduced new granular permissions that let security admins scope access to Audit logs. This capability supports several Audit workloads, including OneDrive, Microsoft Entra, Intune, and Exchange. Moreover, Security admins can now use 10 parameters to programmatically filter Audit logs.

New granular permissions (Image Credits: Microsoft)The Microsoft Purview Audit Search Graph API is expected to become generally available for commercial customers in June 2024. Microsoft recommends existing customers to switch from the Search-UnifiedAuditLog cmdlet to leverage the benefits of the Audit Search Graph API.

Overall, the new Audit Search Graph API underscores Microsoft’s commitment to enhance security measures and streamline administrative tasks. This feature should enable organizations to effectively monitor and protect their enterprise environments. We invite you to check out this support page to learn more about how to use the new Audit Search Graph API.

The post Microsoft Purview Launches Audit Search Graph API for Seamless Data Monitoring appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of PowerShell Crescendo 1.1.0 for all its customers. This latest iteration brings several improvements, such as a brand-new cmdlet, enhanced error handling capabilities, a new method to bypass output handling, and support for argument value transformations, among other exciting features. “Crescendo is a development accelerator enabling you to rapidly...

The post PowerShell Crescendo 1.1.0 is Now Generally Available appeared first on Petri IT Knowledgebase.

View Details

Microsoft has partnered with Motorola to launch an enhanced Windows 365 App experience for Android devices. The new built-in feature is designed to enable seamless connectivity between Lenovo ThinkPhone and Windows 365 Cloud PCs. Microsoft launched the Windows 365 app in public preview in March this year. It allows users to directly access their Cloud...

The post Microsoft Launches Enhanced Windows 365 App Experience to Boost Productivity on Android Devices appeared first on Petri IT Knowledgebase.

View Details

Microsoft has unveiled its strategy to replace the classic Outlook desktop application, but the transition won’t be a swift one. In a recent announcement, the company confirmed that this monumental shift will be a gradual process, stretching over at least a couple of years for its commercial customers. Last week, Microsoft published a new YouTube...

The post Microsoft Details Roll Out Plan for New Outlook for Windows Client appeared first on Petri IT Knowledgebase.

View Details

Microsoft 365 Defender, Identity Protection, and Microsoft Sentinel generate an avalanche of security incidents that require attention. In this article, I will give you an overview of what tools are at your disposal, what incidents are useful, and how to make Microsoft Sentinel reduce alerts. Security incidents in a single pane of glass Today’s security...

The post Using Microsoft Sentinel to Automate and Reduce Security Alerts appeared first on Petri IT Knowledgebase.

View Details

Microsoft released the September 2023 Patch Tuesday updates for Windows 11 and Windows 10 yesterday. The monthly updates were quite easy to miss yesterday as Apple’s iPhone 15 event pretty much dominated the news cycle, but there’s actually quite a lot to discuss this month. This month, Microsoft fixed a total of 65 vulnerabilities in...

The post Microsoft Releases September 2023 Patch Tuesday Updates for Windows 11 and Windows 10 appeared first on Petri IT Knowledgebase.

View Details

In a notable shift for developers, Microsoft has revealed its plan to retire the Outlook REST API v2.0 in 2024. This decision stems from feedback received from customers and partners. The Outlook REST API is undergoing this transition to make way for a smoother and more secure future with Microsoft Graph. The Outlook REST API...

The post Microsoft to Sunset Outlook REST API v2.0 in 2024 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has launched a new Bing Chat Enterprise service plan that gives organizations more control over who can access the service. The new offering allows IT admins to test the service with a small group of testers prior to broader deployment. Microsoft started rolling out the new Bing Chat Enterprise service in preview back in...

The post Microsoft’s Bing Chat Enterprise Service Adds New Deployment Controls appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: * W3LL, a sophisticated cyber threat group, has successfully targeted more than 8,000 Microsoft 365 corporate accounts across the US, Europe, and Australia. * W3LL’s tactics include bypassing multifactor authentication (MFA) and employing convincing Microsoft Outlook animations to deceive victims into opening malicious attachments. * To defend against such threats, organizations are urged to implement FIDO 2.0 authentication solutions, enforce strict access policies, and bolster email protection tools.

Security researchers have discovered a new threat actor that has been using a highly advanced phishing kit to bypass multifactor authentication (MFA) safeguards. The cyber threat group has successfully compromised over 8,000 Microsoft 365 corporate accounts across the US, Europe, and Australia.

According to a report released by Group-IB, the hackers had built a highly sophisticated phishing kit (W3LL Panel) with multifactor authentication (MFA) bypass capabilities. The security researchers believe that the custom tools were used to breach over 56,000 Microsoft 365 accounts between October 2022 and July 2023.

Group-IB found that the cyber threat group targeted several industries, including IT, healthcare, legal services, manufacturing, consulting, and financial services. The researchers estimate that the W3LL crew had generated more than $500,000 during the last 10 months.

The attacker first gained access to a mailing list of potential victims and used the W3LL custom email validator tool to scan the list. Then, the hackers used additional custom tools (such as link stagers and phishing kits) to create a phishing lure.

“Once the victim has downloaded and accessed an attachment, a new blank browser window opens with a genuine-looking MS Outlook animation designed to make the victim think that the action is legitimate,” Group-IB explained. “What the phishing attachment actually does is load a W3LL Panel phishing page in the newly opened window.”

Group-IB suggests a layered defense approach to block W3LL phishing attacksThe phishing toolkit uses Adversary-in-the-Middle (AitM) attacks to steal session cookies and Microsoft 365 credentials. Finally, the attacker could abuse the unauthorized access for malicious activities such as malware distribution, impersonation, and data theft.

Group-IB recommends that organizations should take a layered approach to minimize the risk of cyberattacks. Enterprise customers should implement FIDO 2.0 authentication solutions and enforce strict conditional access policies. It’s also advised to configure additional email protection tools and review security policies.

The post W3LL Phishing Group Breaches Thousands of Microsoft 365 Corporate Accounts appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: * Microsoft’s new Conditional Access overview dashboard lets IT Pros get a comprehensive view of their Conditional Access posture. * It helps administrators track unprotected sign-ins, non-compliant/unmanaged devices, and malicious sign-in alerts. * The Conditional Access templates make it easier for IT admins to deploy policies aligned with Microsoft recommendations.

In today’s constantly evolving digital landscape, finding the perfect harmony between strong security measures and seamless access for a hybrid workforce can prove to be quite a daunting task. To simplify this challenge, Microsoft has introduced a new Conditional Access overview dashboard, designed to assist Entra ID customers in effortlessly navigating this intricate terrain.

The Conditional Access overview is a built-in dashboard that allows organizations to gain detailed insights about their Conditional Access posture. It’s the default landing page that lets administrators create new policies with Conditional Access templates. The Conditional Access overview dashboard helps to track unprotected sign-ins, non-compliant/unmanaged devices, and malicious sign-in alerts.

“As an administrator, it provides a concise summary of your policies, identifies any gaps in your policy coverage, and provides valuable insights based on sign-in activity within your tenant. This feature enables you to swiftly pinpoint areas where you can enhance the enforcement of Zero Trust principles, ultimately bolstering your defense mechanisms,” Microsoft explained.

Conditional Access templates are designed to make it easier for IT admins to deploy new policies aligned with Microsoft recommendations. The templates help to ensure that the policies provide maximum protection for corporate assets as well as promote optimal and secure access for hybrid teams.

Microsoft says that customers can select from 16 predefined Conditional Access templates that are organized into different categories. These include zero trust, secure foundation, emerging threats, protect administrators, and remote work.

Getting started with Conditional Access templatesTo get started with templates, head over to the Microsoft Entra admin center and select Protection > Conditional Access, and use the templates to create new policies. Then, click the “Show more” option to view all policy templates in each category.

Microsoft introduced a new continuous access evaluation (CAE) setting in public preview for Entra ID Conditional Access. It enables IT admins to strictly enforce location policies for network access in their organizations. The feature lets CAE-enabled applications (such as Microsoft Teams, Exchange Online, SharePoint, and Microsoft Graph) to quickly invalidate tokens that violate IP-based location policies.

The post Microsoft Entra ID Gets Conditional Access Overview Dashboard and Templates appeared first on Petri IT Knowledgebase.

View Details

Azure Backup can be used to back up not only an organization’s critical cloud workloads but also all types of on-premises resources, even if they are running on Azure Stack HCI or Azure Stack Hub.

Before explaining how Azure Backup can be set up and used for disaster recovery (DR), I want to get a common backup misconception out of the way: Backup is not the same as disaster recovery.

Backup vs. disaster recoveryIn the case of Azure, Azure Backup keeps your data and workloads safe and recoverable by backing them up to the Azure cloud. For example, if a user deletes a file from an Azure File Share, you can restore that file; or if a virtual machine (VM) is no longer responsive or bootable, you can restore it from a backup.

In addition to Azure Backup, there is Azure Site Recovery, which serves as a cloud disaster recovery solution. It allows you to replicate workloads running on physical servers or VMs, both inside and outside of Azure, from a primary site to a secondary location. In the event of an outage at your primary site, you can fail over to the secondary location, access all applications and workloads from the secondary site, and subsequently fail back to the primary site once it is operational again.

Resilience in hybrid environmentsTo achieve comprehensive resiliency in a hybrid environment, it is vital to ensure the high availability of all your resources in addition to implementing backups and disaster recovery.

But in this article, our focus will be Azure Backup. We will begin by discussing the types of resources that can be backed up and restored using Azure Backup, and this list is currently quite extensive, as illustrated below:

  • On-premises files, folders, system state, VMs (Hyper-V and VMware), and other on-premises workloads
  • Azure VMs (Windows and Linux)
  • SQL Server in Azure VMs
  • SAP HANA databases in Azure VMs
  • Azure File Shares
  • Azure Database for PostgreSQL servers (preview)
  • Azure Managed Disks (preview)
  • Azure blobs (preview)

It is important to note that backup capabilities may vary depending on the type of workload, including the availability of different features. Furthermore, it’s worth mentioning that some resource types are still in the preview phase at the time of writing.

Backing up a virtual machine using Azure Backup (Image credit: Petri/Wim Matthyssen)Once you get started with Azure Backup on the Azure portal, the wizard will guide you through choosing the workloads to back up and their location.

Azure Backup in action (Image credit: Petri/Wim Matthyssen)How to use Azure BackupTo begin backing up your workloads with Azure Backup, you will need an Azure subscription to create a Recovery Services vault. This vault serves as an online storage entity that enables you to back up workloads to or from Azure, following the Azure Resource Manager model.

Storage and replicationWhen creating a Recovery Services Vault using tools such as Azure Resource Manager (ARM), Azure Bicep, Terraform, or Azure PowerShell, it is crucial to select the appropriate backup storage. This choice will impact your Azure Backup pricing, in addition to the type of workload that is being backed up, which we will discuss in detail later on.

You have the option to choose between locally redundant storage (LRS), zone redundant storage (ZRS), geo-redundant storage (GRS), or read-access geo-redundant storage (RA-GRS) as the replication type for your backup storage.

Note: When you enable Cross Region Restore, your backup GRS storage will automatically be upgraded to RA-GRS storage. Enabling this option will let you restore your backup data in a secondary paired region, but it will also affect your Azure Backup pricing.

Figure 3

Azure Backup configuration (Image credit: Petri/Wim Matthyssen)When it comes to backing up business-critical or production resources, it is advisable to set the replication type to GRS (or ZRS). For non-production resources, the replication type can be set to LRS to reduce costs. If both types of resources coexist within the same subscription or if resources from different regions exist in the same subscription, it is better to deploy two separate Recovery Services vaults.

Deploying two separate Recovery Services vaults (Image credit: Petri/Wim Matthyssen)Naming and tagging conventionFurthermore, like your other Azure resources, it is essential to establish a solid naming and tagging convention for your Recovery Services vault(s), as described in your Azure Governance plan. After all, this enables you to locate specific recovery vaults more efficiently during various management tasks, including cost optimization or when restoring resources.

You can build up an example naming convention for your Recovery Services vaults in the following manner:

rsv---<landing zone type(optional)>-<rsv type>-<location>-<##>

You can also refer to the example screenshot below, which showcases both the naming convention and a set of tags that can be utilized in conjunction with Azure Backup.

You need a solid naming and tagging convention for your Recovery Services vaults (Image credit: Petri/Wim Matthyssen)A very useful example of a tag to use in combination with Azure Backup, alongside commonly used tags like Environment, Criticality, and CostCenter, is a tag that describes the backup policy. This way, it is quite easy to determine if a resource is backed up and to see what backup policy is being used.

Here is an example:

BackupSchedule: pol-vm-1100-pm-2ir-3th-sun-27d-4w-12m-5y; BackupSchedule: pol-fs-0900-pm-2nd-sat-27d-4w-12m-3y

You can add a tag that describes the backup policy (Image credit: Petri/Wim Matthyssen)Here is another example:

Adding a tag that describes your backup policy (Image credit: Petri/Wim Matthyssen)As well as using a robust naming convention and tagging structure, it is also essential to adhere to other Azure Governance best practices, like granting backup administrators the least privilege access to perform their backup-related tasks by assigning them to specific Azure AD groups with an explicit role-based access control (RBAC) role.

Also, to apply the necessary security and monitoring settings, like configuring the soft delete retention period, you need to set your vault as immutable or configure diagnostic settings.

Configuring soft delete settings (Image credit: Petri/Wim Matthyssen)You can also set vault immutability to ensure recovery points cannot be deleted before the set expiry period.

Enabling vault immutability (Image credit: Petri/Wim Matthyssen)Diagnostic settings can be used to configure streaming export of logs and metrics.

Configuring diagnostic settings (Image credit: Petri/Wim Matthyssen)There are several different options for storing logs and metrics:

The different options for storing logs and metrics (Image credit: Petri/Wim Matthyssen)Backup policiesOnce you have set up and configured your required Recovery Services vault(s), you can proceed to add the necessary backup policies, which should be created based on resource type and criticality.

While there are default policies available, as shown in the screenshot below, it is advisable to create your own based on your specific Recovery Point Objective (RPO) and Recovery Time Objective (RTO).

You need to add backup policies based on resource type and criticality (Image credit: Petri/Wim Matthyssen)Before creating a backup policy, it is crucial to ask yourself a few questions: What retention settings (daily, weekly, monthly, or yearly) are necessary? How many instant recovery snapshots do we require? Do I need the capability to back up multiple times a day? And so on.

Next to that, also keep in mind that there are various settings available depending on the resource type you are backing up, such as the choice to foresee differential backups when backing up SQL Server in an Azure VM. Or the option to select between a standard backup policy or an enhanced policy when backing up Azure VMs.

Your backup policy can include full backups or differential backups (Image credit: Petri/Wim Matthyssen)If you opt for an enhanced policy, you can choose between once daily, multiple backups a day, and other advanced configurations.

The Enhanced policy sub type offers more options (Image credit: Petri/Wim Matthyssen)Furthermore, I recommend you assign a name to your policy that describes its backup settings, such as the number of instant recovery points and the retention ranges utilized. As previously mentioned, you can also use this backup policy name as a tag to be able to better govern and foresee backup-related automation tasks for specific resources within your environment.

Some examples of backup policies are:

Azure File Share: pol-fs-1100-pm-3th-sun-27d-54w-12m-5y; SQL Server in Azure VM: pol-sql-0100-am-3th-sun-d27d-f54w-f12m-f3y (d = differential backup, f = full backup)

Azure Backup policies examples (Image credit: Petri/Wim Matthyssen)Again, using descriptive backup policy names will help you manage Azure Backup.

It’s recommended to use descriptive policy names (Image credit: Petri/Wim Matthyssen)Here is another backup policy with a descriptive name.

Another example of a descriptive backup policy name (Image credit: Petri/Wim Matthyssen)Restoring data using Azure BackupBackup is important, but what matters most is having the capability to restore data whenever it becomes necessary. Therefore, setting expectations for data restoration and describing your requirements within a backup and disaster recovery plan is crucial.

When using Azure Backup, you have various options for restoring workloads or data, depending on the type of data source type you have backed up. For instance, when you have backed up an Azure VM, you can choose to restore the VM, which gives you the possibility to either create a new VM, restore disks, or replace the disk(s) of the existing VM. You also have the option to restore specific files.

You have multiple options when restoring an Azure VM (Image credit: Petri/Wim Matthyssen)You also get to choose the restore type, group, and location when recovering a virtual machine as a new instance.

Choosing the restore type, resource group, and staging location for your VM (Image credit: Petri/Wim Matthyssen)If you want to replace an existing VM from backup, you can choose the staging location.

Replacing an existing VM for backup (Image credit: Petri/Wim Matthyssen)You also have the option to recover individual files.

Recovering individual files (Image credit: Petri/Wim Matthyssen)If your backup data source is an Azure File Share, you have the choice to restore the entire share to either its original location or an alternate location. Moreover, similar to an Azure VM, you also have the option for file recovery.

You can restore an entire share of opt for file recovery (Image credit: Petri/Wim Matthyssen)When choosing the restore location, you can choose between the original location or an alternate one.

Choosing the restore location (Image credit: Petri/Wim Matthyssen)The Azure Backup Center provides a centralized and unified way of managing your backup operations across multiple subscriptions and regions. It offers a consolidated view of all your Azure backups and complete backup infrastructure, making it easier to monitor, govern, and manage backups at scale.

To navigate and start using Backup Center, simply search for “Backup center” in the Azure portal global search bar, and under services, select Backup Center to open the dashboard.

Accessing the Azure Backup Center (Image credit: Petri/Wim Matthyssen)On the Overview blade, you will find a comprehensive summary of all backup jobs and instances, which can be filtered using various tiles.

You can filter backup jobs and instances (Image credit: Petri/Wim Matthyssen)The Backup Center also provides various options to help you with monitoring, reporting, implementing policies, and ensuring compliance within your Azure Backup environment. As an Azure Backup administrator, backup reports and backup compliance, for example, provide valuable insights into the overall status of your resource backups and compliance.

Accessing Backup reports in the Azure Backup Center (Image credit: Petri/Wim Matthyssen)Below, you can see an example of a Backup compliance report.

A Backup compliance report (Image credit: Petri/Wim Matthyssen)Azure Backup offers reliable and scalable data protectionAs you have hopefully seen and read, Azure Backup can really help you safeguard your organization’s vital assets by providing you with reliable and scalable data protection for your hybrid or cloud environment.

The post Protect Your Organization’s Assets: Disaster Recovery with Azure Backup appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* BullWall Server Intrusion Protection offers a robust solution to the pressing issue of unauthorized access during Remote Desktop Protocol (RDP) sessions. * The integration of multi-factor authentication (MFA) and the BullWall Ransomware Containment system not only blocks unauthorized access but also provides an effective means of containing and neutralizing ransomware attacks at their inception. * BullWall Server Intrusion Protection represents a proactive and practical solution for organizations seeking to enhance their server security.

Bullwall announced the launch of its new Server Intrusion Protection solution this week. In an age where remote access is integral to business operations and security concerns loom large, this solution aims to prevent unauthorized access during Remote Desktop Protocol (RDP) sessions due to compromised credentials.

BullWall is a cybersecurity solution provider that allows organizations to block ransomware attacks targeting corporate data and critical IT infrastructure. The company offers specialized solutions to protect servers against unauthorized intrusion in enterprise environments.

According to BullWall, Remote Desktop Protocol (RDP) has historically been a common attack vector for ransomware and other cyberattacks. It lets threat actors deploy ransomware on vulnerable machines that could lead to data encryption and exfiltration.

How BullWall Server Intrusion Protection works?BullWall Server Intrusion Protection leverages the BullWall Ransomware Containment service to contain ransomware on the systems. It provides a multi-factor authentication challenge (such as a traditional MFA or a token grid). The service blocks the intrusion and prevents unauthorized access in case the MFA challenge fails. It initiates the BullWall Response Protocol that triggers an alert, blocks the breached admin/user accounts, and then isolates the device.

“One of the biggest stumbling blocks to obtaining cyber insurance is the requirement for MFA on servers in addition to endpoints, for every login attempt. BullWall Server Intrusion Protection provides a game-changing MFA solution for server access that doesn’t require a second device. We’re thrilled to offer a solution that increases security, reduces user friction and stops today’s most common attack vector,” said Morten Gammelgard, BullWall Co-Founder and EVP of EMEA.

Overall, BullWall Server Intrusion Protection represents a timely and practical response to the ever-growing threat landscape. It should allow organizations to bolster their defenses and take proactive steps toward a more resilient and secure digital future. If you’re interested, you can learn more about the BullWall Server Intrusion Protection solution on the official website.

The post RDP Server Security Enhanced by Bullwall’s New Solution Against Ransomware Attacks appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft is taking a proactive stance in defending commercial customers against copyright infringement lawsuits related to its AI-powered Copilot services. * Microsoft is offering protection and financial support for those who utilize the tool to generate content. * The Copilot Copyright Commitment covers Microsoft 365 Copilot, Bing Chat Enterprise, Windows Copilot, GitHub Copilot, Microsoft Security Copilot, and other products.

Microsoft has announced that it will defend customers of its AI-powered Copilot services from the daunting specter of copyright infringement lawsuits. This initiative, part of the company’s unwavering dedication to customer satisfaction, seeks to alleviate the concerns that have long loomed over the utilization of the Copilot tool for content generation.

The Microsoft Copilot Copyright Commitment promises to protect organizations and pay related fines or settlements. This policy applies to commercial customers who have used the built-in content filters and safety measures as well as the paid versions of the products.

“If a third party sues a commercial customer for copyright infringement for using Microsoft’s Copilots or the output they generate, we will defend the customer and pay the amount of any adverse judgments or settlements that result from the lawsuit, as long as the customer used the guardrails and content filters we have built into our products,” said Microsoft President Brad Smith and Chief Legal Officer Hossein Nowbar.

Microsoft also pledged to address the concerns of authors whose content is used to train machine learning models. “We believe the world needs AI to advance the spread of knowledge and help solve major societal challenges. Yet it is critical for authors to retain control of their rights under copyright law and earn a healthy return on their creations,” Smith and Nowbar explained.

Microsoft’s Copilot Copyright Commitment only covers paid toolsThe Copilot Copyright Commitment covers several paid tools available for commercial customers. These include Microsoft 365 Copilot, Bing Chat Enterprise, Windows Copilot, GitHub Copilot, Microsoft Security Copilot, Viva Sales Copilot, Dynamics 365 Copilot, Power BI Copilot, and Power Platform Copilot. However, Microsoft will not protect consumers who generate copyright-infringing content with Bing Chat and the free version of GitHub Copilot.

It’s important to note that Microsoft, OpenAI, and GitHub faced a class-action lawsuit back in November 2022. The complaint accused the companies of scraping licensed code to build and train the Copilot coding assistant available for GitHub customers.

The post Microsoft to Protect Copilot Commercial Customers Against Copyright Lawsuits appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:

  • Microsoft’s Ignite 2023 conference will be held in Seattle on November 14-17, and you can already register for the in-person or free online event.
  • The theme of the conference will be “AI transformation”, continuing what’s been a very important theme for Microsoft this year.
  • Ignite 2023 will be preceded by a special Microsoft event on September 21 and a OneDrive-themed event on October 3.

Microsoft has now opened registrations for its Ignite 2023 conference, which will be held in Seattle on November 14-17. This year, the theme of the conference for IT pros is “AI transformation,” so you can expect Microsoft to continue its streak of AI announcements that started with GitHub Copilot two years ago.

While the full session catalog for Ignite 2023 isn’t available yet, Microsoft already announced that there will be over 140 sessions this year. The list of featured speakers includes CEO Satya Nadella, EVP of Experiences and Devices Rajesh Jha, EVP of the Cloud + AI Group Scott Guthrie, and Microsoft 365 Collaborative Apps and Platforms lead Jeff Teper.

If you want to attend the event in person in Seattle, Microsoft is offering a $1,525 early-bid pricing ($300 off) until October 11. Everyone else can already register for the free online sessions on November 15-16, which is when the live in-person keynotes are scheduled.

Start booking your flights or get your desk setup ready because #MSIgnite registration is OPEN!

Tune in for an overview from @RicksterCDN and @Karuana and learn how we've evolved the event to a next-level experience. Register today: https://t.co/WNntQYGaRq pic.twitter.com/bdS8sA23oG

— Microsoft Ignite (@MS_Ignite) September 6, 2023

Microsoft has been making huge investments in AI this year, with the Microsoft 365 Copilot launching earlier this year via an early access program. The productivity assistant will be priced at $30 per user per month for all enterprise customers with Microsoft 365 E3, E5, Business Standard, and Business Premium subscriptions, and Microsoft likely still has some work to do to convince organizations that it will be worth it.

Microsoft also announced at its Build conference earlier this year that its Microsoft 365 will soon get support for third-party plugins. The company with working with OpenAI to make ChatGPT plugins compatible with its own Copilot experiences across Microsoft 365, Bing, and Windows, and we may well hear more about these efforts at Ignite.

Ignite 2023 will follow other Microsoft events this fallIn addition to Ignite, Microsoft has already announced a special event in New York on September 21. The company hasn’t shared any details about it yet, but we’re likely to see new Surface devices and some Windows news as well. Windows 11 version 23H2 is right around the corner, and this update will bring the new AI-powered Windows Copilot to the desktop.

On October 3, Microsoft will also hold a digital event that will focus on OneDrive. The company is planning to showcase the next generation of file management across Microsoft 365 and give “a sneak peek at our AI plans which include new search, sharing, and information queries across all your files in OneDrive,” the company said in the announcement.

While Microsoft’s September 21 will be behind closed doors, the OneDrive event on October 3 will be streamed live on Microsoft Teams. Jeff Teper, one of the featured speakers at Ignite 3 will also be present along with the OneDrive team.

The post Microsoft Opens Registrations for its Ignite Conference on November 14-17 appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Google’s upcoming antitrust battle in the US, as well as the EU designating Alphabet, Amazon, Apple, ByteDance, Meta, and Microsoft as the six “gatekeepers” following the adoption of the Digital Markets Act.

The post First Ring Daily: Google Goes to Court and the EU Lists Out “Gatekeepers” appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft is discontinuing support for third-party printer drivers via Windows Update, shifting towards Printer Support Apps distributed through the Microsoft Store. * The transition will be implemented gradually over the next few years, with existing drivers still available through the Windows Hardware Compatibility Program (WHCP) until 2026. * Microsoft will continue to provide security updates for the existing printer driver platform on all supported Windows versions.

Microsoft is set to bid farewell to third-party printer drivers offered via Windows Update. This change, scheduled for a staggered rollout, will let printer manufacturers harness the UWP development framework to create Printer Support Apps available through the Microsoft Store.

Microsoft explained that the upcoming change will eliminate the need for printer manufacturers to distribute their drivers through Windows Update. They will be able to use the UWP development framework to build Printer Support Apps and distribute them via the Microsoft Store. It should bring performance and reliability improvements for Windows users. Microsoft also notes that printer manufacturers will no longer need to build separate solutions for different versions of Windows.

“With the release of Windows 10 21H2, Windows offers inbox support for Mopria compliant printer devices over network and USB interfaces via the Microsoft IPP Class Driver. This removes the need for print device manufacturers to provide their own installers, drivers, utilities, and so on.  Device experience customization is now available via the Print Support Apps that are distributed and automatically installed via the Windows Store,” the company wrote.

Microsoft understands that the end of support for legacy v3 and v4 printer drivers would impact many Windows customers. The company plans to roll out the change in a staggered manner in the next few years.

Microsoft has no plans to remove existing features supported by legacy printer driversIt’s important to note that printer manufacturers will still be able to use the Windows Hardware Compatibility Program (WHCP) to ship existing drivers through Windows Update. However, this capability will no longer be available for new printer drivers starting in 2026. This means that customers will need to use an alternate method to download and install printer drivers on their Windows PCs.

Microsoft will continue to support existing features supported by v3 and v4 printer drivers on Windows 11 and 10 devices. The company also plans to release security updates to the legacy printer driver platform on all supported versions of Windows.

The post Microsoft to Drop Support for Third-Party Printer Drivers on Windows PCs appeared first on Petri IT Knowledgebase.

View Details

Ransomware protection is one the most important topics for IT Pros and C-Level technology executives. Learn how immutable backups and immutable storage help to protect your organization against data corruption and loss, malware, viruses, and ransomware – and how to implement them.  This post is sponsored by Object First Veeam 2023 Ransomware trends report – most ransomware targets backups In May...

The post How Immutable Backups Protect Against Ransomware appeared first on Petri IT Knowledgebase.

View Details

Microsoft recently disclosed a cyber-espionage campaign that allowed Chinese hackers to steal a signing key and breach sensitive US government email accounts. The company launched an investigation into the security incident, which led to the publication of detailed findings in a report released on Wednesday. In July, Microsoft detailed that a Chinese hacking group (tracked...

The post Microsoft Explains How Chinese Hackers Breached US Government Email Accounts appeared first on Petri IT Knowledgebase.

View Details

It was a busy August and I took the long weekend off, so I’m a few days late to cover everything that’s new with Microsoft’s Power Platform in August 2023. Either way, let’s get started with the most interesting Power Platform updates that came in August, say goodbye to the summer, and here is hoping...

The post What’s New With Microsoft’s Power Platform – August 2023 appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* MSI has rolled out new BIOS updates, specifically aimed at resolving BSOD unsupported processor errors for Windows users with Intel 700 and 600 Series motherboards. * The issue was traced to a firmware setting in Intel’s Hybrid Architecture, impacting 13th Gen Core i9 processors. * The BIOS updates are not yet available to all users, but MSI plans to gradually expand them to more motherboard models this week.

Microsoft recently acknowledged a technical hiccup causing Blue Screen of Death (BSOD) unsupported processor errors on Windows 11 and 10. To combat this issue, MSI has collaborated with Intel to release BIOS updates specifically aimed at their Intel 700 and 600 Series motherboards.

In a recent blog post, MSI explained that it has worked with Intel to determine the root cause for the BSOD errors. The companies found that the issue specifically impacts Intel’s 13th Gen Core i9 processors running on Intel 700 and 600 series motherboards. It was caused by a firmware setting in the Intel Hybrid Architecture that got triggered following the installation of the latest Windows 11 and Windows 10 updates.

MSI to issue BIOS updates for more motherboard models in late SeptemberMSI has released BIOS updates to fix the BSOD issue affecting several Intel 600 and 700 Series motherboards. These include MEG Z790 ACE, MPG Z790 CARBON WIFI, MPG Z790 EDGE WIFI, MAG Z790 TOMAHAWK WIFI, PRO Z790-A WIFI, PRO Z790-P WIFI, PRO Z790-P, PRO Z690-A WIFI, and PRO Z690-A.

“The new BIOS coming will include an update on the Intel CPU uCode which will prevent any more messages regarding the “UNSUPPORTED_PROCESSOR” issues. This upcoming update will correspond to both 13th-generation and newer ones,” MSI explained.

It’s important to note that the new BIOS updates are not available for all Windows 11 and 10 users just yet. MSI plans to roll out the updates for more 600 and 700 Series motherboard models later this week. Moreover, the BIOS updates are expected to be available for all affected motherboards by the end of this month.

The post MSI Releases New BIOS Updates to Fix Unsupported Processor BSOD Errors on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft’s “Explicit proxy mode” for Azure Firewall offers direct proxy configuration within sending applications, simplifying traffic routing. * Single-click upgrade/downgrade support for Azure Firewall Premium subscriptions streamlines subscription management, enabling IT administrators to focus on critical tasks with minimal service disruption. * Azure Firewall services are now available in Poland Central, extending their global reach to 52 regions worldwide.

Microsoft has introduced a new Explicit proxy mode for Azure Firewall that allows direct proxy configuration within sending applications. The latest update also brings a seamless single-click upgrade/downgrade experience for Azure Firewall subscriptions.

“With this mode enabled, you have the option to configure a proxy setting directly on the sending application, such as a web browser, with Azure Firewall acting as the designated proxy. This configuration allows traffic from the sending application to be directed to the private IP address of the firewall, facilitating direct egress from the firewall without the need for a UDR,” Microsoft explained.

The new Explicit proxy mode is available in addition to the default mode, and it currently supports HTTP/S traffic. It’s possible to use a proxy auto-config (PAC) file or manually configure the IP address on the application or browser.

Azure Firewall adds new single-click upgrade/downgrade experience Microsoft has announced the general availability of single-click upgrade/downgrade support in Azure Firewall. The feature enables customers to upgrade or downgrade their Azure Firewall Premium subscriptions with a single click. This should make it easier for IT admins to focus on important tasks and minimize service downtime.

The auto-learn SNAT (Source Network Address Translation) routes feature is now available in public preview for Azure Firewall customers. Azure Firewall SNAT is a built-in capability that routes outbound traffic to the Internet. It leverages Azure Route Service integration to auto-learn private and registered ranges and then use the routes for SNAT.

Lastly, Microsoft has announced the general availability of Azure Firewall Basic, Standard, Premium, and Azure Firewall Manager in Poland Central. The Azure Firewall service is now available for customers in 52 regions worldwide.

The post Azure Firewall Gets Explicit Proxy Support and Other New Features appeared first on Petri IT Knowledgebase.

View Details

Multi-tenant organizations in Microsoft 365 have just hit public preview in August of 2023. In this article, I will give you an overview of the Microsoft 365 multi-tenant organization scenario and the related capabilities in Azure Active Directory (now Microsoft Entra ID). I will also detail the various scenarios Microsoft offers for multi-tenant organizations and if they work for your specific company needs.

What is a multi-tenant organization in Microsoft 365?A tenant is an instance of Azure Active Directory in which information about a single organization resides. That includes organizational objects such as users, groups, and devices, as well as application registrations for Microsoft 365 and third-party applications.

A tenant also contains access and compliance policies for resources including applications registered in the directory. The primary functions served by a tenant include identity authentication as well as resource access management.

At its core, multi-tenancy refers to the practice of hosting multiple, independent instances of a software application or service on a single physical or virtual infrastructure. These can occur due to mergers and acquisitions, and various subsidiaries being independent.

In the context of Microsoft 365, a multi-tenant organization encompasses a scenario where a single instance of the Microsoft 365 platform serves multiple distinct and separate entities, often referred to as tenants. Each tenant represents an individual organization with its own users, resources, data, settings, and admins, all coexisting within the same Microsoft 365 environment.

Basics of a multi-tenant organization (Image credit: Microsoft)Key aspects of multi-tenant organizations in Microsoft 365A multi-tenant organization allows seamless cross-tenant collaboration and effortless cross-tenant synchronization. It also allows coworkers to easily send an invitation to guest users for a boost in productivity.

It’s important to understand how multi-tenant organizations differ from Microsoft Teams shared channels, and I’ll have more on that down below. But let’s start with the key aspects of multi-tenant organizations in Microsoft 365:

Tenant isolationOne of the foundational principles of multi-tenancy is tenant isolation. Each organization’s data, user accounts, settings, and configurations are logically isolated from those of other tenants, ensuring data privacy, security, and compliance. Cross-tenant access settings are granular and secure to make sure different tenants don’t inadvertently have access to external identities.

Shared infrastructureMulti-tenant environments share the underlying infrastructure such as servers, storage, and networking resources. This efficient resource sharing enables economies of scale and reduces the operational overhead for both Microsoft and the tenants.

Global scalabilityThe Microsoft 365 multi-tenant architecture allows organizations of various sizes and locations to leverage the platform’s global scalability. From small businesses to large enterprises, multi-tenancy caters to diverse user bases.

Single code baseDespite serving multiple tenants, Microsoft 365 maintains a single code base for its applications and services. This ensures that updates, features, and security enhancements are delivered to all tenants in a consistent manner.

What are the main benefits of Microsoft 365 multi-tenant organizations?There are a good number of benefits to using multi-tenant organizations in your Microsoft 365 environment. Let me touch on a few here.

Cost efficiencyMulti-tenant environments enable organizations to share infrastructure costs, providing cost savings compared to maintaining individual on-premises solutions or two or more completely separate Microsoft 365/Entra ID tenants.

ScalabilityMicrosoft 365’s multi-tenant architecture allows organizations to scale their usage up or down as needed, accommodating growth without significant infrastructure adjustments.

Enhanced collaborationMulti-tenant organizations foster collaboration and communication among users within the same tenant, streamlining teamwork and information sharing. In the increasing world of hybrid work and efficiency, especially when working remotely, seamless collaboration has quickly become an expectation for your users, especially frontline workers.

Unified managementAdministrators can manage multiple tenants from a single console, simplifying administrative tasks and reducing complexity.

Quick deployment/setupSetting up a new tenant within the Microsoft 365 environment is streamlined, allowing organizations to onboard new users and resources efficiently.

Challenges related to multi-tenant organizationsWhile the benefits are significant, multi-tenant organizations also present certain challenges and considerations every IT Pro needs to take into consideration. Let me explain the most prevalent.

The first one is related to data security and privacy. This is really something that you need to take into consideration as sensitive information from different organizations will coexist within the same environment.

Additionally, multi-tenant environments may have limitations on customizations, as changes to the underlying infrastructure can affect all tenants. Lastly, resource-sharing benefits might lead to performance variations based on the activities of other tenants.

Comparing multi-tenant organizations with Teams shared channelsMulti-tenant organizations in Microsoft 365 and Microsoft Teams shared channels are two distinct concepts within the Microsoft ecosystem, each serving unique purposes and addressing different collaboration needs.

Here are the key differences between Teams shared channels and multi-tenant organizations:

  • Use case: Multi-tenant organizations are suited for businesses, institutions, or entities seeking comprehensive cloud-based productivity solutions. Shared channels are designed for organizations that need to collaborate with external partners, clients, or vendors within a single Teams channel.
  • Scope: Multi-tenancy applies to the broader Microsoft 365 ecosystem, encompassing various services and applications, while shared channels specifically focus on collaboration within Microsoft Teams.
  • Audience: Multi-tenancy caters to organizations as a whole, serving their overall IT and productivity needs, whereas shared channels target specific collaboration scenarios involving teams from different organizations.
  • Data sharing: Multi-tenancy involves sharing infrastructure and resources, while shared channels enable the sharing of communication and collaboration spaces.

Microsoft Teams Shared Channels (Image credit: Microsoft)Overall, multi-tenancy addresses the overarching IT infrastructure and productivity needs of multiple organizations within a shared ecosystem, while shared channels facilitate external collaboration by enabling teams from different organizations to work together within a unified Teams channel. The choice between these two concepts depends on an organization’s specific collaboration requirements and its broader adoption of Microsoft 365 services.

Hybrid approaches and third-party optionsOrganizations seeking more granular control, customization, or specialization may consider third-party alternatives or hybrid approaches:

  • Private cloud solutions: Some businesses opt for private cloud solutions, where they maintain dedicated resources for their exclusive use. This approach offers more control over infrastructure but might lack the scalability of a true multi-tenant environment.
  • Hybrid environments: Hybrid solutions combine on-premises resources with cloud services, allowing organizations to retain some data and applications locally while leveraging the cloud for specific tasks.
  • Industry-specific solutions: Certain industries with strict regulatory requirements may choose industry-specific cloud providers that offer specialized services tailored to their needs.

ConclusionIn the ever-evolving landscape of modern business, multi-tenant organizations in Microsoft 365 have emerged as a pivotal paradigm, enabling organizations to harness the power of cloud-based collaboration, communication, and productivity. By facilitating efficient resource sharing, scalability, and cost savings, multi-tenant environments have become the bedrock of today’s digital workplaces.

While considerations regarding data security, customization, and resource impact are pertinent, organizations have the flexibility to explore alternatives, including private cloud solutions and hybrid approaches, based on their unique needs and requirements. As technology continues to shape the future of work, multi-tenant organizations stand as a testament to the evolution of cloud computing and its role in propelling organizations toward greater efficiency, collaboration, and success.

The post What is a Multi-Tenant Organizations in Microsoft 365? appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft is phasing out TLS 1.0 and 1.1 protocols, enhancing security on future Windows operating systems, with the changes beginning in Windows 11 Insider Preview Builds in September 2023. * While this change won’t affect Windows 11 Home users, enterprise customers need to prepare, as some applications like SQL Server 2016 and SQL Server 2012 may be impacted. * Microsoft’s move to disable older TLS protocols represents a proactive step toward bolstering cybersecurity, as these outdated encryption protocols are susceptible to vulnerabilities.

Microsoft is set to bids farewell to outdated Transport Layer Security (TLS) 1.0 and 1.1 protocols in Windows. The company plans to drop support for the encryption protocols starting with Windows 11 Insider Preview Builds in September.

Transport Layer Security (TLS) is a cryptographic protocol that ensures secure data transmission over a computer network. It encrypts data for confidentiality, ensures data integrity to detect tempering, and provides authentication to confirm server identity. TLS relies on digital certificates issued by trusted Certificate Authorities, and it’s widely used to secure web traffic, VPN connections, email communication, and more.

“This change applies only to future new Windows operating systems, both client and server editions. Windows versions that have already been released will not be affected by this change. Windows 11 Insider Preview builds starting in September 2023 will have TLS versions 1.0 and 1.1 disabled by default. There is an option to re-enable TLS 1.0 or TLS 1.1 for users who need to maintain compatibility,” Microsoft explained.

Which Windows apps would be affected by TLS 1.0 and TLS 1.1 disablement? Microsoft confirmed that this change won’t impact Windows 11 Home users, and it would only impact enterprise customers. Microsoft has published a list of apps that could be broken by disabling support for TLS 1.0 and TLS 1.1 on Windows. The list includes SQL Server 2016, SQL Server 2012, Safari version 5.1.7, and much more.

Microsoft recommends enterprise admins to run tests and check if all their applications behave as intended. These applications will be automatically disabled and will be tagged using Event 36871 in the Windows Event Log. Microsoft will let IT admins re-enable older versions through Windows Registry, though it’s not recommended.

The post PSA: Microsoft to Disable Older TLS Protocols in Windows appeared first on Petri IT Knowledgebase.

View Details

In the fast-paced world of digital collaboration, Microsoft continues to raise the bar with its latest enhancements to Microsoft Teams in August 2023. The major highlights include an updated compact chat view, dynamic meeting backgrounds, new admin controls, as well as updates for Microsoft Teams Rooms and devices. Chat & collaboration features First off, Microsoft...

The post What’s New in Microsoft Teams – August 2023 appeared first on Petri IT Knowledgebase.

View Details

The excessive use of digital devices in enterprises and their exposure to various networks have increased the probability of cyber-attacks. Enterprise-owned devices contain confidential data that hackers can easily access if devices are not controlled efficiently, and that can cause damage to the values and reputation of the organizations. Thus, data security is now of...

The post Securing Enterprise Devices: Embracing Zero Trust Security appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft has announced a series of updates for Entra ID cross-tenant access settings. * IT administrators will now have greater control over cross-tenant collaboration with the ability to configure custom roles. * A new storage model enables IT admins to seamlessly configure policies for as many partners as needed.

Microsoft is improving the collaboration experience with updates to Entra ID cross-tenant access settings. These enhancements include support for custom roles in cross-tenant access settings, protected actions, the removal of partner limits, and more.

Microsoft announced the commercial release of Entra ID cross-tenant collaboration settings in preview last year. The feature is designed to make it easier for organizations to share access with trusted organizations. The new settings allow organizations to control how users collaborate with other Microsoft 365 tenants. There are also inbound and outbound settings to control access on an application, group, or tenant-wide basis.

With this release, Microsoft has released a new feature that lets organizations configure custom roles for IT admins managing cross-tenant access settings. Moreover, it’s possible for IT Pros to use Conditional Access policies to protect management actions. For instance, a policy requires admins to perform Multi-Factor Authentication (MFA) before making any changes to the default settings for B2B collaboration.

“Today, you need to use either a Global or Security admin to fully manage cross-tenant access settings. Now you can use custom roles to create roles that meet the requirements you have. We’ve seen customers create a full cross-tenant access administrator, a partner administrator, and even a cross-tenant access reader. This allows you to delegate only the rights needed to perform these management actions without granting too many permissions,” Microsoft explained.

Microsoft removes limits on the number of partners in cross-tenant access settingsMicrosoft has also removed a previous limit on the number of partners added in cross-tenant access settings. The company has introduced a new storage model that lets IT admins configure policies for as many partners as required. Microsoft plans to gradually move all commercial customers to this new model in the coming months. IT admins will see an entry in the audit logs informing them about the updated cross-tenant access settings.

Last but not least, Microsoft has introduced a change to ensure that B2B invitations respect cross-tenant access settings. The new capability will check the cross-tenant access settings and allow/block list at the time of invitation. It should help IT admins to prevent unapproved users from sending invitations to their organizations.

The post Microsoft Releases Improvements for Entra ID Cross-Tenant Access Settings appeared first on Petri IT Knowledgebase.

View Details

Roaming profiles are a Windows feature that allows user profiles to be used across multiple workstations within a network. A user profile contains personalized application settings, desktop configurations, application preferences, and other user-specific data. In this article, I will show you how to deploy roaming user profiles in your Windows environment so that users have the same experience when logging into any computer in your domain.

Understanding how roaming profiles workWith roaming profiles, users can enjoy a consistent experience regardless of the computer they’re using. Their settings and data follow them from one machine to another when they log in with their username.

Their profile data is typically saved on a central file share on the corporate network. This is especially useful in environments where users regularly switch between different computers or locations.

Although there are a good number of efficiency benefits and productivity-related boosts when using roaming profiles, the feature has not been the most reliable feature in Windows since its inception several decades ago. I have almost always experienced reliability issues with roaming profiles when providing consulting and troubleshooting value to customers over the years.

Let’s learn more about how roaming profiles work:

  1. Profile creation: When a user logs into a computer for the first time, Windows creates a user profile on that computer. This profile includes personal settings, documents, and other user-specific data.
  2. Roaming profile setup: In a network environment with Active Directory, administrators and IT Pros can configure roaming profiles. This involves designating a network location, often on a server, to store user profiles instead of keeping them only on the local computer. The profile path is saved with a variable in the user’s profile folder attribute in Active Directory, making administration simple.
  3. Profile synchronization: When a user logs into a different computer within the same network, their roaming profile is downloaded from the designated network location. This process ensures that their personalized settings and data are available on the new machine.
  4. Synchronization at logoff: As the user logs off, any changes made to the roaming profile are synchronized back to the network location. This ensures that the latest changes are preserved and ready for use on other computers. If a user makes an edit to a file on their desktop or adjusts their computer configuration, those changes will get sent back to their home folder on the network file server.

Simple diagram showing some roaming profile concepts – Image Credit: MicrosoftCan roaming profiles be problematic?While roaming profiles can offer some benefits to IT Pros and users, there are some challenges and considerations to keep in mind:

  1. Profile size: Roaming profiles can become large due to accumulated settings and user data. This might impact login and logout times, as well as consume network bandwidth during synchronization.
  2. Network performance: Frequent synchronization of large profiles can affect network performance, particularly in environments with limited bandwidth. The user experience can be painful, at best, especially with many large roaming profiles.
  3. Profile conflicts: If a user logs into multiple computers simultaneously and makes conflicting changes, resolving these conflicts during synchronization can be complex.
  4. Application compatibility: Some applications may not work seamlessly with roaming profiles, leading to unexpected behaviors or conflicts.

Software and hardware requirements for roaming profilesSetting up roaming profiles in Windows 10 or Windows 11 requires specific software and hardware configurations, including a check of Windows versions to ensure smooth profile synchronization across a network. Let me go through a high-level breakdown of the software and hardware requirements for roaming profiles, covering the network environment, server requirements, and client requirements:

Network environmentRoaming profiles are typically managed through Active Directory, a directory service provided by Microsoft. Active Directory stores user account information, manages network resources, and facilitates authentication and access control. You can use various features in Active Directory such as the Group Policy Management Console to create a new Group Policy Object (GPO) to handle the management of roaming profiles for all your users!

Regarding network Connectivity, a stable and reliable network connection is crucial for seamless synchronization between user computers and the server where the profiles are stored.

Server requirementsTo host roaming profiles, you need a file server that has sufficient storage space to accommodate the profiles of all users who will be using roaming profiles. A simple SMB share will suit your needs here nicely.

It is typically prudent to project your space needs ahead of time so that you can proactively account for your users’ growth and data storage needs. Any supported version of Windows Server will certainly suffice for these needs.

Client requirements Operating System Version: The Windows client computers and the server should be running Windows operating systems that support roaming profiles. This includes the latest supported versions of Windows 10, Windows 11, and Windows Server 2016, 2019, and 2022. * User Privileges: Users should have the necessary permissions to access, modify, and create files within their roaming profiles on the server. Adequate permissions need to be configured to ensure the security and integrity of user data. You can customize permissions with this feature to stay compliant within your organization. * Active Directory Account: This should go without saying, but for completeness, each user must have an Active Directory account, which provides a unique identity within the network. This account allows the user to log into different computers and access their roaming profile. * Domain Membership:* Client computers need to be part of the same Active Directory domain as the server hosting the roaming profiles. This domain membership is essential for authentication and communication.

Roaming profiles and Folder Redirection: What are the benefits?To optimize the use of roaming profiles, administrators often implement Folder Redirection. This feature involves redirecting specific user folders, such as Documents, Desktop, and AppData, from the local profile to network locations. This reduces the size of the roaming profile, improves login/logout times, and enhances data protection.

Profile size reductionOne of the primary advantages of using Folder Redirection is the reduction of the size of roaming profiles. Again, roaming profiles can become large due to content like documents, downloads, and media files.

When Folder Redirection is enabled, when these folders are redirected to network locations, only essential data required for the user’s session is included in the profile. This reduces the size of the roaming profile significantly. You’ll also see reduced network bandwidth usage as only essential data is synchronized.

Faster logins and logoutsFolder Redirection contributes to faster login and logout times for users. By excluding bulky folders like Documents and Desktop from the roaming profile, the amount of data that needs to be synchronized between the user’s computer and the network is minimized. As a result, users experience quicker logins and logouts, allowing them to quickly switch between computers and improving their overall productivity.

Data protectionFolder Redirection enhances data protection by ensuring that user data is stored on network locations rather than on local machines. This is, in my mind, absolutely paramount.

I can not tell you how many client sites I visited over the past 25 years that included at least one computer with vital data stored on the C: drive, in a dirty warehouse, with poor or no circulation. Those are ticking time bombs!

Everypiece of important data should be stored on the network, period. No exceptions. Using Folder Redirection to validate that all files on the Desktop, Documents, etc. folders are stored (and backed up each night, right?) in a safe location will ensure that user data remains secure even if the local machine encounters hardware issues. Easier data recovery and restoration in case of hardware failures.

Options to manage roaming user profilesManaging roaming user profiles involves handling profile synchronization, data integrity, and user-specific settings effectively. Windows provides several options to manage roaming user profiles, each offering different features and capabilities. Here are some of the main options.

Group PolicyGroup Policy is a powerful tool for managing various aspects of Windows environments, including roaming user profiles. Through Group Policy settings, administrators can configure how roaming profiles are managed and synchronized.

Folder RedirectionAs previously discussed, Folder Redirection is an option that works in tandem with roaming profiles to optimize profile management. By redirecting specific user folders like Documents, Desktop, and AppData to network locations, you can reduce profile sizes and improve performance.

Offline FilesOffline Files is a feature that allows users to access network files even when they are disconnected from the network. This can be useful for users who work remotely or frequently switch between online and offline modes.

Roaming profiles alternativesThere are more viable, robust, and modern options available to IT Pros. Let’s go through them here. By the way, Roaming Profiles have been in Windows since Windows NT 3.1! We’re talking 1993, 30 years ago as I write this.

OneDrive (Known Folders)Recent versions of Windows 10 and Windows 11 include a new feature in the OneDrive sync client: Known Folders.

Using Known Folders in the OneDrive sync client to backup important files (Image credit: Petri/Michael Reinders)This is often an even better option than using Folder Redirection. You don’t need to worry about your corporate network, file space, etc. With OneDrive (and Microsoft) handling all the details, every machine that a user logs into with OneDrive syncing will automatically back up every file, picture, and document in their designated key folders. This takes a LOT of burden off of your IT staff!

FSLogixFSLogix is a powerful technology that addresses many of the challenges associated with managing roaming user profiles in Windows environments. Roaming profiles, while beneficial, have issues, as I’ve discussed above. FSLogix offers solutions to these problems by providing dynamic profile management and application masking, ultimately enhancing user experience and simplifying profile management for administrators.

Through its ability to reduce logon times, optimize profile storage, and prevent conflicts, FSLogix plays a significant role in creating a smoother and more efficient computing environment for both end users and IT personnel.

Some details about FSLogix – Image Credit: MicrosoftUser Experience Virtualization (UE-V) – Windows 10 onlyUser Experience Virtualization (UE-V) is a technology developed by Microsoft to address the challenges and concerns associated with roaming profiles in Windows environments. UE-V provides a solution that alleviates the stated concerns of this post by virtualizing user settings and configurations, allowing for a consistent and personalized experience across different devices.

Here is how UE-V works:

  • Configuration Settings Capture: UE-V captures the user’s configuration settings from applications, the operating system, and personalization options. These settings are stored in a settings package.
  • Settings Package Creation: The captured settings are compiled into a settings package, which is stored in a central location, such as a network share.
  • Roaming Settings Package: When a user logs in to a different device, the settings package is applied to the local machine. Only the necessary settings are synchronized, ensuring a fast login process.
  • Synchronization: UE-V monitors changes to user settings in real time. Changes are synchronized to the settings package, ensuring that the user’s configuration remains up to date.

Roaming profiles reduce the learning curve when using multiple devicesUnderstanding how roaming profiles work in Windows is essential for creating a seamless user experience across different devices within a network. Roaming profiles allow users to access their personalized settings, files, and applications irrespective of the computer they use. This consistency enhances productivity and reduces the learning curve associated with transitioning between devices.

However, the challenges of profile size, synchronization speed, and conflicts have led to the development of various solutions, including third-party alternatives. These alternatives offer advanced features such as dynamic profile management, virtualization, and enhanced application masking.

While Windows provides native tools like Group Policy and Folder Redirection to manage roaming profiles, exploring third-party solutions can offer more tailored, efficient, and modern profile management approaches that address the limitations of traditional roaming profiles. It is recommended to first explore third-party tools that will undoubtedly offer more benefits with fewer headaches.

As usual, thank you for reading, and feel free to leave a comment or question!

The post What is a Roaming User Profile on Windows? appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft is launching a public preview of its new Teams client for Mac this month, featuring improved performance and efficiency. * The new Microsoft Teams desktop app replaces the resource-intensive Electron framework with Microsoft’s WebView2 technology, resulting in a faster and less memory-intensive application. * The new Teams client will be available on Mac devices running macOS Big Sur (11) or higher.

Microsoft is gearing up to release the public preview of its new Teams client for macOS later this month. The revamped Microsoft Teams for Mac aims to enhance performance and efficiency, shedding the resource-intensive Electron framework in favor of Microsoft’s WebView2 technology.

Microsoft launched a significant revamp of its Teams app in public preview on Windows back in March 2023. The current Teams client is built on the Electron framework, which is notorious for resource utilization and poor performance. Since its launch, Microsoft has been continuously working on improvements for Teams to reduce RAM and CPU usage, especially on low-end or older hardware.

Fortunately, Microsoft has now ditched Electron and moved toward the WebView2 technology instead. The primary goal of the new Microsoft Teams desktop client was to make it faster and less resource-intensive. Microsoft boasts that the app is two times faster and uses 50 percent less memory compared to the previous version. It also supports new AI-powered features, multi-tenant collaboration, and seamless switching between different tenants and accounts.

“With multi-tenant organization (MTO), users in organizations that manage employees across multiple tenants will have the ability to search for coworkers in another tenant, have single chat thread with other users, receive real-time notifications, join meetings, and calls in another tenant, and multitask from their home tenant,” Microsoft explained on the Microsoft 365 admin center.

How to try the new Microsoft Teams for Mac clientOnce rolled out, macOS users will see a “Try the new Teams toggle” within the classic Microsoft Teams app (version 1.6.00.12303 or higher). It will be available in preview on Mac devices running macOS Big Sur (11) or higher. This change will be applicable to tenants where the UseNewTeamsClient is configured to Microsoft default.

The new Microsoft Teams for Mac will support all the features available in the Windows client except Green Screen, Cameo, and NDI. Microsoft Teams users will be able to switch back to the classic app at any time with the same toggle button.

Microsoft also plans to make its new Teams app the default client for all enterprise and business customers (Business Basic, Business Standard, Business Premium, and Teams Essentials, etc.) next month. The company recommends IT administrators to prepare for this upcoming change in their organizations.

The post New Microsoft Teams for Mac Client to Launch in Preview This Month appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft has announced the general availability of its new Group Policy analytics tool. * The tool can help IT admins understand their current GPO environment and detect any potential conflicts or issues. This information can be used to make informed decisions about how to migrate to Intune. * The total size of the imported XML file must be less than 4 MB.

Microsoft has released a new Group Policy analytics tool that lets organizations import, analyze, and migrate on-premises GPOs to Microsoft Intune. The new offering provides a detailed report for each GPO and includes a migration wizard that helps IT admins move supported settings to mobile device management (MDM) tools.

Specifically, the Group Policy analytics tool provides a detailed report for each GPO with information about the settings, usage, conflicts, as well as Intune equivalent policy. “Group Policy analytics helps you import your GPOs, analyze the settings through sharable reports, and migrate settings from your GPO to Intune. From here, the settings can be managed just like a standard Intune device configuration policy,” Microsoft explained.

The Group Policy analytics tool shows various settings supported by Microsoft Intune and other cloud-based MDM providers. It also allows administrators to remove Windows client dependencies on on-premises Active Directory and move to Microsoft Intune management instead.

Group Policy migration readiness reportWith the Group Policy analytics tool, IT admins can view a migration readiness report with details about Group Policy Objects (GPOs) that could have conflicts with Intune policies. The report also makes it easier to track missing policies that are similar to the GPO. It’s also possible to view GPOs that are ready for migration or deprecated.

Group Policy analytics tool offers Migration SupportThe Group Policy analytics tool provides a migration wizard that can help IT admins move the supported settings to MDM tools. It gives IT admins the ability to migrate settings from a single or multiple GPOs to a Settings catalog policy.

“Any settings that successfully migrate will be included in the new Settings catalog profile. For those that don’t migrate successfully (possibly due to a missing parent/child setting or an unexpected format), the process will report an error in the Notifications field on the Group Policy analytics page,” Microsoft added.

To get started with Group Policy analytics, IT admins will need to perform a couple of steps to export their GPO as an XML file. Then, administrators can view the details with the Group Policy Analytics feature in the Microsoft Intune Admin Center portal. However, keep in mind that the total size per import should be less than 4 MB in order to import multiple GPOs at one time.

The post New Group Policy Analytics Tool Lets IT Admins Assess MDM Migrations appeared first on Petri IT Knowledgebase.

View Details

Key takeaways:* Microsoft has published a roundup of all the new capabilities added to Windows Autopatch in the past few weeks. * IT admins are getting finer control over Windows updates with the ability to pause and resume updates for specific Autopatch groups or rings. * Microsoft added a new registry conflict detection feature, allowing IT admins to identify and resolve potential update-blocking conflicts.

Microsoft has rolled out a series of Windows Autopatch enhancements designed to redefine how organizations approach updates and device management. The major highlights include a new Autopatch deployment guide, finely-tuned update controls, registry conflict detection, and support for self-serve device deregistration.

Microsoft has created a new deployment guide that helps IT admins to plan their migrations to Windows Autopatch. It explains some common objectives and suggests a recommended deployment plan. Moreover, the Windows Autopatch deployment guide details some migration considerations for Windows Update for Business (WUfB) and Microsoft Configuration Manager. The guide also provides suggested business case benefits and stakeholder communications.

New IT controls for pausing Windows updatesAdditionally, Microsoft has added a new feature that gives IT admins better control when pausing quality updates on Windows Autopatch-managed devices. It’s now possible to pause/resume updates for individual/multiple Autopatch groups or at the ring level. The feature lets IT admins view a list of all deployment rings that would be affected as a result of pausing Windows updates.

Registry conflict detectionMicrosoft has introduced a new capability that helps administrators to detect conflicts during the device registration process. The device readiness check now lets IT admins search for registry settings that could block devices from getting Windows updates or working with Windows Autopatch. They will be able to view details about these devices as well as remediation suggestions in the “Not ready” tab of the Windows Autopatch Devices blade.

Self-serve device deregistration from Windows AutopatchLastly, Microsoft has made it easier to remove a specific device from Windows Autopatch management. However, the feature will move the device to the “Not registered” tab in the Devices blade instead of completely removing it from the Azure AD group.

Last month, Microsoft announced a slew of updates to celebrate the first anniversary of its Windows Autopatch service. The company added the ability for IT admins to create discrete Autopatch groups and opt out of Microsoft 365 updates and Expedited updates. The service now supports automated deployment of recommended driver and firmware updates on Windows devices.

The post What’s New in Windows Autopatch – August 2023 appeared first on Petri IT Knowledgebase.

View Details

On this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s upcoming special event on September 21, why AI could be a big part of it, and they also look back at an app that didn’t ship.

The post First Ring Daily: Ahead of AI appeared first on Petri IT Knowledgebase.

View Details

After the European Commission started investigating Microsoft’s bundling of Teams with its Microsoft 365 and Office 365 commercial subscriptions last month, Microsoft is ready to address the concerns of EU regulators. This morning, the company announced that will start unbundling Teams from its Microsoft 365/Office 365 commercial suites in the EU and Switzerland on October...

The post Microsoft is Unbundling Teams From its Microsoft 365/Office 365 Commercial Subscriptions in Europe appeared first on Petri IT Knowledgebase.

View Details

Microsoft has quietly discontinued its once-generous unlimited cloud storage option for the OneDrive for Business service. Indeed, all new commercial customers are now limited to OneDrive for Business (Plan 1), which offers 1 TB of storage for $5 per user per month. Up until now, Microsoft used to offer unlimited storage as a part of...

The post OneDrive for Business Kills Unlimited Storage Option for Commercial Customers appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to enhance the user experience for Mac devices with its upcoming Platform Single Sign-On (SSO) capabilities. The new feature will offer a seamless and secure way for macOS users to access their Entra ID accounts across various applications and websites. Microsoft launched its Enterprise Single Sign-On (SSO) plug-in for Apple devices...

The post Microsoft to Introduce Platform SSO Support for Mac Devices appeared first on Petri IT Knowledgebase.

View Details

In a leap towards fortifying data security, Microsoft has unveiled several enhancements for Microsoft Purview Data Loss Prevention. These latest updates boost protection, expand DLP capabilities across platforms, and facilitate seamless day-to-day tasks for administrators. First off, Microsoft has introduced optical character recognition (OCR) support in public preview in Microsoft Teams and Exchange Online. The...

The post Microsoft Purview Gets OCR Support and Other New Data Loss Prevention Capabilities appeared first on Petri IT Knowledgebase.

View Details

Endpoint security plays a vital role in safeguarding enterprise cybersecurity, particularly in the context of remote work scenarios. As the number of endpoints accessing corporate networks rises with the growth of remote work, the need for robust endpoint security becomes increasingly paramount, enabling a secure environment for users on the move. In this article, I...

The post How to Protect Windows Devices with Microsoft Defender for Endpoint appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced its plans to enable Extended Protection by default on Exchange Server later this year. Scheduled to roll out with the 2023 H2 Cumulative Update, the new security feature will help organizations to boost protection against credential theft and man-in-the-middle attacks. Windows Extended Protection is a security feature that is designed to secure...

The post Microsoft to Enable Extended Protection By Default on Exchange Server appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out a set of updates for its new Microsoft Teams desktop client, designed to take employee collaboration in multi-tenant environments up a notch. The focus is on refining chat, calling, meetings, search, and content-sharing experiences to address the needs of today’s diverse workplace dynamics. The new Microsoft Teams desktop app launched...

The post The New Microsoft Teams Client Gets a Big Update to Enhance Multi-Tenant Collaboration appeared first on Petri IT Knowledgebase.

View Details

For any modern enterprise that uses Azure Active Directory (now Microsoft Entra ID) to manage user and service access to cloud resources, it’s hard to escape the term Zero Trust (ZT), which implies that your organization must have a layered approach to security. In this article, you’ll learn about five Microsoft Zero Trust tactics for...

The post Five Tactics Towards Achieving Zero Trust with Azure Active Directory appeared first on Petri IT Knowledgebase.

View Details

Microsoft continues to evolve its offerings with the latest August (2308) service release for Microsoft Intune. A notable highlight is the much-anticipated Remote Help for Android support, a cloud-based solution that promises to enhance the way technical issues are diagnosed and resolved. The Remote help service enables IT admins to remotely diagnose and resolve technical...

The post Microsoft’s New Remote Help Service Adds Support for Android Devices appeared first on Petri IT Knowledgebase.

View Details

Security researchers have exposed a new supply chain attack that targeted entities across Asia, with a particular focus on Hong Kong. An unidentified hacking group, named Carderbee, employed an ingenious tactic — exploiting legitimate software — to infect around 100 computers with the PlugX/Korplug backdoor. According to the Symantec Threat Hunter Team, the hackers hijacked...

The post Carderbee Hackers Abuse Microsoft Signing Keys in Supply Chain Attacks appeared first on Petri IT Knowledgebase.

View Details

Amazon Web Services (AWS) recently made waves with the announcement of a new service called Dedicated Local Zones. This new on-premises cloud offering is a strategic response to the evolving needs of organizations in the public sector and other industries with stringent regulatory and compliance needs. AWS Dedicated Local Zones provide a cloud computing infrastructure...

The post AWS Unveils New Dedicated Local Zones Service for Critical Workloads appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: Microsoft has announced the imminent launch of the self-service Teams Premium trial for commercial customers. Scheduled for a global rollout in September, the self-service trial feature will give users a hands-on experience with the AI-powered Microsoft Teams Premium capabilities. What is Microsoft Teams Premium? Microsoft launched the new Teams Premium add-on for commercial...

The post Microsoft Teams Premium Self-Service Trial Licenses to be Available Next Month appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Nvidia doubling its revenue in Q2 thanks to high demand for AI chips, and Microsoft not planning to cut prices for Xbox hardware.

The post First Ring Daily: AI Boom Helps Nvidia Double its Quarterly Revenue appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: Microsoft’s latest optional update for Windows 11 version 22H2, KB5029351, designed to bring improved features and experiences, has instead left some users staring at the familiar ‘Blue Screen of Death’ (BSOD) accompanied by an ‘UNSUPPORTED_PROCESSOR’ error message. The company acknowledged the issue on the Windows Health Dashboard yesterday. “Microsoft has received reports of...

The post Microsoft Acknowledges New “Unsupported Processor” BSOD Errors on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

SQL Server’s T-SQL query language has a plethora of data retrieval options. That includes the ability to query a SQL database, as well as providing a sum function, a count aggregate function, and grouping columns. The SQL GROUP BY clause can make use of all of these capabilities. In this article, I’ll show you how...

The post SQL Server Essentials: Using the SQL GROUP BY Clause appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: Microsoft has announced API-driven provisioning support for Microsoft Entra ID (formerly Azure Active Directory). This new release allows businesses to seamlessly integrate their authoritative system of record with Azure AD provisioning, encompassing everything from HR and payroll apps to SQL tables and spreadsheets. The API-driven provisioning feature is designed to help organizations ensure...

The post Microsoft Entra ID Gets API-Driven Provisioning Support in Public Preview appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: Cameyo has a new app accessibility feature with this latest update: a seamless integration of its Virtual App Delivery (VAD) service with ChromeOS. The service empowers organizations to traverse platform boundaries, unleashing the potential to run Windows and Linux applications on ChromeOS devices. Cameyo is a technology company that provides application virtualization solutions...

The post Cameyo Unveils New Solution to Run Windows Apps on ChromeOS appeared first on Petri IT Knowledgebase.

View Details

Microsoft is giving IT pros more control over the optional updates available on commercial devices running Windows 11 version 22H2. That also includes what Microsoft calls “Controlled Feature Rollouts” (CFRs), which some organizations may want to keep disabled by default to maintain some stability.  These CFRs are the new Windows 11 features that Microsoft releases...

The post Microsoft Releases New Policy to Control Optional Updates on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: RARLAB has released a crucial update aimed at addressing a high-severity security loophole within its popular WinRAR compression and archiving tool. This flaw enables threat actors to execute arbitrary code upon the launch of a RAR file, thus raising significant concerns about user data safety and system integrity. The WinRAR vulnerability, tracked as...

The post WinRAR Patches Flaw That Lets Attackers Run Malicious Code When Opening RAR Files appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out version 116 of its Edge browser on the Stable channel. The latest update includes a new Microsoft Edge for Business experience, which offers a dedicated work environment complete with company branding, native security measures, and automatic switching between personal and work-related browsing sessions. Microsoft Edge for Business is a dedicated...

The post Microsoft Edge Version 116 is Out With New Edge for Business Experience appeared first on Petri IT Knowledgebase.

View Details

The PowerShell Get-MessageTrace command can help Office 365 admins track down the delivery and processing of email messages that may not be getting into their users’ mailboxes. In this article, I’ll show you how to use the Get-MessageTrace command to manage and analyze email message traces in Office 365. Using PowerShell Get-MessageTrace with Exchange Online...

The post How to Use the PowerShell Get-MessageTrace Command in Office 365 appeared first on Petri IT Knowledgebase.

View Details

Parallels Desktop 19 for Mac is now available on macOS Mojave or newer, and it introduces more ways to manage Windows virtual machines (VMs) on Macs. Parallels Desktop for Mac is now an officially supported solution for running Windows 11 on Apple Silicon Macs (in addition to Windows 365 Cloud PCs), and this new annual...

The post Parallels Desktop 19 for Mac Improves Windows VMs Management via Microsoft Intune appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: Microsoft has unveiled an ambitious new chapter in its partnership with none other than VMware. The company announced today a new solution that blends the Windows 365 service seamlessly into VMware Horizon Cloud. VMware Horizon Cloud is a managed Desktop-as-a-service (DaaS) that allows organizations to provide virtual desktops and applications to end users....

The post Microsoft Brings Windows 365 Cloud PCs to VMware Horizon Cloud appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: Step aside old-school collaboration tools, Microsoft’s Loop app is getting ready for its debut to a broader range of Microsoft 365 users next month. Loop is set to change up the way people work with Microsoft 365, evolving the nature of work and emphasizing seamless, real-time collaboration. Microsoft Loop is a revamped version...

The post Microsoft Loop to Become Enabled By Default for More Customers appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: US Cybersecurity and Infrastructure Security Agency (CISA) has warned about a critical vulnerability present in Citrix ShareFile. CISA has mandated that all federal agencies undertake necessary measures to apply patches for the security flaw by September 6, 2023. Citrix ShareFile is a cloud-based file sharing and storage platform that enables organizations to securely...

The post CISA Issues Advisory on Critical File Transfer Flaw in Citrix ShareFile appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: Microsoft has released a new update that enables IT admins to designate sponsors for Entra ID guest accounts. The feature launched in public preview in July, allowing organizations to appoint individuals or groups as sponsors for their guest accounts (via Office 365 for IT Pros). A sponsor is a “responsible individual” who tracks...

The post Microsoft Now Lets IT Admins Assign Sponsors to Entra ID Guest Accounts appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Bing’s stagnating market share despite Microsoft investing over 10 billion dollars into OpenAI.

The post First Ring Daily: Bing Isn’t Growing, But AI Still Has a Place appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: Attention all IT Pros! Security researchers have unveiled three design flaws within the PowerShell Gallery, an online platform for distributing PowerShell code modules. These vulnerabilities have the potential to let malicious hackers upload harmful packages onto the repository, introducing risks such as typosquatting and supply chain attacks. Specifically, researchers at Aqua Nautilus first...

The post Researchers Disclose PowerShell Gallery Design Flaws Vulnerable to Supply Chain Attacks appeared first on Petri IT Knowledgebase.

View Details

Key Takeaways: Microsoft Defender for Identity has added a cutting-edge addition to its toolkit – a new sensor now deployable on Active Directory Certificate Services (AD CS) servers. The sensor augments the existing capabilities, significantly enhancing the detection mechanisms for identifying questionable certificates within enterprise environments. Active Directory Certificate Services (AD CS) is a Windows...

The post Microsoft Defender for Identity Adds New Sensor to Detect Certificate Abuse appeared first on Petri IT Knowledgebase.

View Details

Key takeaways: Microsoft Defender for Endpoint has introduced device tagging support in public preview for mobile devices. This capability allows IT admins to tag iOS and Android devices during the onboarding process. Microsoft highlighted that tags enable administrators to label and classify devices in enterprise environments. The feature is designed to enhance searching and organization...

The post Microsoft Defender for Endpoint Gets Device Tagging Support for iOS and Android appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new version of the August 2023 security updates for Exchange Server. The company pulled the updates from its Windows Update servers and enterprise update channels following reports about issues with the non-English installations of Exchange Server. Microsoft released the Patch Tuesday updates for on-premises Exchange Server 2016 and 2019 on August...

The post Microsoft Releases New Exchange Server Security Updates to Fix Localization Issues appeared first on Petri IT Knowledgebase.

View Details

Security researchers have disclosed a new campaign that exploited a critical Citrix NetScaler vulnerability to infect thousands of devices. They found that hackers have abused the security flaw to target around 2,000 NetScaler instances in Europe. Last month, Citrix disclosed a zero-day vulnerability, tracked as CVE-2023-3519, which impacts NetScaler Citrix Application Delivery Controller (ADC) and...

The post Hackers Exploit Critical Citrix Flaw to Compromise 2,000 NetScaler Instances appeared first on Petri IT Knowledgebase.

View Details

If you’re following industry trends, there’s no doubt that generative AI is the hottest new technology of the past year. And with Microsoft, Google, and other major tech companies jumping on this generative AI bandwagon, this trend isn’t going to be abated anytime soon. In IT, a rapidly growing number of software vendors now have...

The post Is AI Going to Change Backup and Recovery Strategies? appeared first on Petri IT Knowledgebase.

View Details

Microsoft Loop, the company’s new online collaboration app that launched in public preview earlier this year now integrates with two popular Atlassian products, Jira and Trello. Microsoft Loop users can now add Jira and Trello boards to Loop pages and update them right from the app.  Jira, which is Atlassian’s flagship product, is a popular...

The post Microsoft Loop Now Lets Users Add Jira and Trello Boards appeared first on Petri IT Knowledgebase.

View Details

Amazon Web Services (AWS) has introduced support for GitLab in its AWS CodePipeline service. This release allows developers to leverage their GitLab.com source repository to build, test, and deploy code changes with AWS CodePipeline. AWS CodePipeline is a fully managed continuous integration and continuous delivery (CI/CD) service. It’s designed to automate and streamline the process...

The post AWS CodePipeline Introduces Support for GitLab appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced some new monitoring and logging capabilities for Azure Firewall. The first new feature that the company highlighted today is a public preview of the new Resource Health section. Azure Resource Health enables IT admins to monitor the overall health of their Azure Firewall system. The feature makes it easier for administrators to...

The post Azure Firewall Adds New Resource Health and Latency Probe Metric Features appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new update that brings enhancements to its Universal Print service. The company announced that the secure release feature now supports QR codes on Android and iOS devices. Universal Print is a cloud-based service that allows IT admins to centralize print management within their organization. They can control which employees have access...

The post Universal Print Gets QR Code Scanning Support on Android and iOS appeared first on Petri IT Knowledgebase.

View Details

The Cyber Security Review Board (CSRB) has recently announced that it will investigate the recent compromise of Exchange Online used by the US government. The board also plans to conduct a review of the identity and authentication infrastructure used by cloud providers. Last month, Microsoft confirmed that China state-backed hackers (dubbed ‘Storm-0558’) breached the email...

The post US Government to Investigate Chinese Hack That Breached Exchange Online appeared first on Petri IT Knowledgebase.

View Details

Azure Data Studio is a database management tool from Microsoft. It offers a modern and user-friendly UI for performing several database operations and building customizable dashboards. In this article, I’ll explain how Azure Data Studio works, how it differs from SQL Server Management Studio, and how you can download and install it on your PC....

The post What is Azure Data Studio? appeared first on Petri IT Knowledgebase.

View Details

Microsoft has introduced support for mixed licensing in its Microsoft Defender for Endpoint solution. The new capability allows IT admins to control how licenses are applied to client devices in enterprise environments. Microsoft Defender for Endpoint is a security solution that provides threat detection and response capabilities to protect endpoints (such as laptops, computers, and...

The post Microsoft Defender for Endpoint Now Supports Mixed Licensing Scenarios appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that it’s bringing the Copilot AI assistant to apps used by frontline workers. The company has launched a public preview of Copilot integration in its Dynamics 365 Field Service application. Microsoft explained that the new Copilot for Dynamics 365 Field Service helps frontline workers (such as technicians and retail workers) save time...

The post Microsoft Integrates Copilot into Dynamics 365 Field Service App for Frontline Workers appeared first on Petri IT Knowledgebase.

View Details

Microsoft has officially supported running SQL Server in a container since SQL Server 2017. Today, most support is for SQL Server on Linux containers, and Microsoft only supports SQL Server 2022 on Linux containers for production workloads. In this article, I’ll show you how to configure SQL Server Docker containers on Linux. Why would you...

The post How to Install SQL Server Containers on Linux Using Docker appeared first on Petri IT Knowledgebase.

View Details

Last year, Microsoft introduced a new Remote Help solution for the Microsoft Intune Suite. The company announced yesterday that the Remote Help app is coming to Android devices this month. Remote Help is a cloud-based solution that allows helpdesk agents to remotely connect to the user’s device and troubleshoot issues. The service is available as...

The post Remote Help to Add Support for Android Devices This Month appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss the new ‘Downfall’ vulnerability affecting older Intel CPUs, Microsoft’s modernized File Explorer on Windows 11, and the company’s potential trick for selling more new PCs.

The post First Ring Daily: Selling the Chips appeared first on Petri IT Knowledgebase.

View Details

Microsoft Entra ID will soon start delivering multifactor authentication (MFA) text messages through WhatsApp. The company announced on the Microsoft 365 Admin Center yesterday that this update will begin rolling out to customers in select markets next month. As of today, the Microsoft Entra ID Multifactor Authentication feature uses text messages to send one-time passcodes...

The post Microsoft Entra ID to Start Delivering MFA Text Messages Through WhatsApp appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday several new capabilities coming to Microsoft Defender for Cloud. The latest updates are designed to help organizations proactively reduce risks and respond to security threats. Microsoft Defender Cloud Security Posture Management will extend its data-aware security posture, advanced agentless scanning, attack path analysis, and cloud security graph capabilities to Google Cloud Platform...

The post Microsoft Defender for Cloud Adds New Security Features to Block Threats appeared first on Petri IT Knowledgebase.

View Details

For IT administrators managing Office 365 and Exchange Server, having control over mailbox folder-level permissions is a crucial task. PowerShell, a powerful scripting language developed by Microsoft, offers a convenient and efficient way to control access to specific mailbox folders for users within an organization, including the calendar folder. In this article, I will detail...

The post How to Add, Change, and Remove Mailbox Folder Permissions With PowerShell in Office 365 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that Conditional Access for protected actions support is now generally available for Entra ID (Azure AD) customers. The new security feature enables IT admins to use Conditional Access policies to protect critical administrative operations. In Microsoft Entra ID (previously known as Azure AD), the Protected Actions feature provides additional protection by assigning...

The post Microsoft Entra ID Conditional Access Gets Protected Actions Support to Boost Security appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the public preview of its Windows 365 Switch service. The new offering allows users to switch between their Windows 365 Cloud PC and physical device on Windows 11. “Windows 365 Switch provides the ability to easily move between a Windows 365 Cloud PC and the local desktop using the same familiar keyboard...

The post Windows 365 Switch Now Available in Public Preview appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released today the August 2023 Patch Tuesday updates for Windows 11 and Windows 10. This month, Microsoft fixed 86 vulnerabilities in Windows, Office, and other components, and you can also expect the usual bug fixes and quality improvements. After the July Patch Tuesday update for Windows 11 version 22H2 enabled the new “Moment...

The post August 2023 Patch Tuesday Updates are Now Available on Windows 11 and Windows 10 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released the July 2023 update for its Windows 365 Enterprise service. The company announced that the new Move Cloud PC feature is now generally available for commercial customers. Microsoft first released the Move Cloud PC feature in public preview back in June. It enables administrators to move their Windows 365 Cloud PCs to...

The post Microsoft Releases New Windows 365 Features for Enterprise Customers appeared first on Petri IT Knowledgebase.

View Details

Last month, Microsoft launched its new Bing Chat Enterprise service in preview for commercial customers. The company has announced on the Microsoft 365 Admin Center that the Bing Chat Enterprise service plan will be available for Microsoft 365 subscribers next month. Bing Chat Enterprise is an AI-powered chatbot that offers business-focused data privacy and governance...

The post Bing Chat Enterprise Service Plan Coming to Microsoft 365 Subscriptions Next Month appeared first on Petri IT Knowledgebase.

View Details

Last year, Microsoft launched its new Syntex service that uses AI to organize large sets of data and unorganized content for searching. Now, the company has announced several new features and enhancements for Microsoft Syntex. Microsoft has reduced the cost of unstructured document processing from $0.10 to $0.05 per page. The company has also released...

The post Microsoft Syntex Gets New Features, Drops Price for Unstructured Document Processing appeared first on Petri IT Knowledgebase.

View Details

Microsoft-owned GitHub has released a new code referencing tool for GitHub Copilot. The new feature will inform developers when AI-powered code suggestions are taken from public repositories. GitHub first unveiled the Copilot tool back in June 2021. The AI programming assistant allows developers to get code suggestions with natural language commands. Copilot has been trained...

The post GitHub Copilot Adds New Code Referencing Feature in Private Beta appeared first on Petri IT Knowledgebase.

View Details

Microsoft has fixed a critical vulnerability that could let hackers gain unauthorized access to sensitive data and cross-tenant applications managed by Azure AD. The fix comes shortly after security researchers criticized Microsoft for its “grossly irresponsible” cybersecurity practices. In a post on LinkedIn, Amit Yoran, the CEO of the security firm Tenable, called out Microsoft...

The post Microsoft Patches Critical Azure Flaw Following Criticism for ‘Irresponsible’ Security Practices appeared first on Petri IT Knowledgebase.

View Details

By default, Microsoft Outlook prevents users from sending emails with attachments larger than 20 MB. This means that users may receive an error message while attaching files that exceed the allowed limit. In this guide, I will detail different methods to increase the Outlook attachment size limit. How to increase the Outlook Attachment Size Limit...

The post How to Increase the Attachment Size Limit in Microsoft Outlook appeared first on Petri IT Knowledgebase.

View Details

This Week in IT now has its own YouTube Channel! If you have been watching This Week in IT since it started more than a year ago, you will probably realize that home was the Petri IT Knowledgebase YouTube channel. We recently decided that it would be nice to give the show its own identity...

The post Subscribe to ‘This Week in IT’ on YouTube appeared first on Petri IT Knowledgebase.

View Details

The Cybersecurity and Infrastructure Security Agency (CISA) has warned about two vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM). The security flaws allowed threat actors to compromise 12 Norwegian government agencies. Ivanti’s Endpoint Manager Mobile is a solution that lets IT admins secure and manage mobile devices in enterprise environments. They can enforce policies, deploy applications,...

The post CISA Warns About New Ivanti EPMM Vulnerabilities appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to introduce support for the Microsoft Azure Attestation (MAA) service on Windows 11. The company announced yesterday that the feature will begin rolling out to all commercial customers in mid-August. Currently, Windows 11 and Windows 10 use the Windows Device Health Attestation (DHA) service for client device attestation. The configuration service...

The post Windows 11 to Get Support for Microsoft Azure Attestation Service appeared first on Petri IT Knowledgebase.

View Details

In Office 365 (Exchange Online) and Exchange Server environments, granting ‘Full Mailbox’ access to a user is a common administrative task, especially when dealing with shared mailboxes, delegation, or troubleshooting. In this article, we will explore step-by-step procedures for granting Full Mailbox access to users in both Office 365 and Exchange Server environments. I will...

The post How to Grant Full Mailbox Access to Users in Office 365 and Exchange Server appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft killing off the Cortana app on Windows 11, what the new Windows Copilot brings to the table, and more.

The post First Ring Daily: AI on the Desktop appeared first on Petri IT Knowledgebase.

View Details

Microsoft is making some minor changes to its cloud licensing policies for specific customers that run Microsoft Office on AWS. This move comes a week after the European Commission opened an antitrust investigation of Microsoft Teams bundling with Office 365/Microsoft 365 subscriptions. In 2019, Microsoft announced new licensing terms that made it more expensive to...

The post Microsoft Revises Cloud Licensing Policies to Let Customers Run Office on AWS appeared first on Petri IT Knowledgebase.

View Details

Microsoft has issued a security advisory about a new Russia-linked hacking group dubbed Midnight Blizzard. The threat actors used Microsoft Teams chat to launch social engineering campaigns (which started in late May) that affected dozens of organizations. According to the Microsoft threat intelligence team, the hackers (known as APT29) pretend to be technical support staff...

The post Russian Hackers Used Microsoft Teams to Target Government Agencies appeared first on Petri IT Knowledgebase.

View Details

With the exception of Windows 11 Moment 3 landing for everyone in July, it’s been a fairly quiet month. But Insiders did get access to Windows Copilot and the new Outlook for Windows client and Microsoft revealed more about Windows 11 version 23H2. Let’s get started! Windows 11 Moment 3 generally available with July Patch...

The post What’s New in Windows – July 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft is planning to sunset its Microsoft Managed Desktop service next year. The company has quietly updated its support document to indicate that the service will be deprecated on July 31, 2024. Microsoft Managed Desktop (MMD) is a cloud-based device management service that includes Windows 10/11 Enterprise and Microsoft Office apps. It provides a simplified...

The post Microsoft Managed Desktop Service to Retire in July 2024 appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday that it will soon deprecate Transport Layer Security (TLS) versions 1.0 and 1.1 on Windows 11. The company plans to drop support for the encryption protocols by default on the latest Windows 11 Insider Preview Builds in September. TLS is a cryptographic protocol that’s designed to provide communication security over a computer...

The post Microsoft to Disable TLS 1.0 and 1.1 Support By Default on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

Starting with SQL Server 2017, Microsoft has supported SQL Server on Linux, which has the same underlying database engine as the Windows version. In this article, I’ll show you how to install SQL Server on Linux, as well as Azure Data Studio. The most recent release of SQL Server is SQL Server 2022, which offers...

The post SQL Server Essentials: How to Install SQL Server 2022 and Azure Data Studio on Linux appeared first on Petri IT Knowledgebase.

View Details

Summer is in full swing, and it is hot out there! Speaking of hot things, Microsoft just released last month the 2023 Release Plan Wave 2 for its Power Platform, which details updates coming between October 2023 and March 2024. Let’s take a look at what’s in the pipeline!   Power Apps: More upcoming AI-assisted features...

The post What’s New with Microsoft’s Power Platform in July 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released updates to fix a bug that was previously impacting the Windows Server Update Services (also known as WSUS). The company detailed on the Windows Health Dashboard that the issue prevented the distribution of updates to client devices running Windows 11 version 22H2 as well as Windows Server 2022. Windows Server Update Services...

The post Microsoft Fixes WSUS Bug Preventing Updates Distribution on Windows 11 version 22H2 appeared first on Petri IT Knowledgebase.

View Details

Earlier this year, Microsoft released watermarking support in public preview for Azure Virtual Desktop (AVD). The company detailed in a blog post yesterday that the security feature is now generally available for all commercial customers. Azure Virtual Desktop (AVD) is a cloud-based virtual desktop and application virtualization solution that runs in Microsoft Azure. The managed...

The post Azure Virtual Desktop Introduces Watermarking Support to Protect Sensitive Data appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday a new update for its Microsoft Entra ID Protection service. This release brings a new dashboard, advanced detection capabilities, integration with Microsoft 365 Defender, and more. The Microsoft Entra ID Protection service leverages machine learning to detect, investigate, and remediate identity-based sign-in risks and unusual activities. It uses risk-based adaptive access policies...

The post Microsoft Entra ID Protection Gets New Dashboard, Advanced Detections appeared first on Petri IT Knowledgebase.

View Details

Clipchamp, the video editing app that Microsoft acquired back in 2021 will soon be available for Microsoft 365 commercial customers. The cloud-based video editor is adding support for work accounts, and it will also seamlessly integrate with OneDrive, SharePoint, Teams, and other Microsoft productivity apps.  Microsoft believes that Clipchamp can become a great resource for...

The post Microsoft’s Clipchamp Video Editor is Adding Support for Work Accounts appeared first on Petri IT Knowledgebase.

View Details

Amazon Web Services (AWS) is planning to charge organizations for the use of public IPv4 addresses. Starting on February 1, 2024, AWS customers will need to pay $0.005 per IP address per hour for all public IPv4 addresses. According to AWS, the cost of purchasing a single IPv4 address increased by over 300 percent during...

The post AWS to Start Charging for Public IPv4 Addresses in February 2024 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a public preview of a new continuous access evaluation (CAE) setting for the Entra ID Conditional Access service. The new feature enables IT admins to strictly enforce location policies for network access in enterprise environments. Continuous Access Evaluation is a mechanism that offers real-time evaluation of Conditional Access policies for certain apps....

The post Microsoft Entra ID Introduces Strict Location Enforcement To Block Stolen Token Access appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out the July 2023 service release (2307) for Microsoft Intune. The latest update brings several new capabilities to enhance support for App management, Device configuration, security, and more. Microsoft has introduced a top-requested feature that lets standard users uninstall Win32 and Microsoft Store apps from within the Company Portal for Windows....

The post Microsoft Intune Gets Support for Uninstalling Apps in the Company Portal for Windows appeared first on Petri IT Knowledgebase.

View Details

In today’s rapidly evolving technology landscape, Amazon Web Services (AWS) remains one of the biggest players in the cloud computing industry. For most IT pros, AWS certifications have become a crucial stepping stone for career advancement. These certifications validate professionals’ expertise with AWS services and indicate their ability to design, deploy, and manage applications on...

The post AWS Certifications: A Complete Guide appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that the malware scanning capability will become generally available on September 1. The new agentless SaaS solution will be available as an add-on for Microsoft Defender for Storage customers and will cost $0.15 (USD)/GB of data scanned. Microsoft Defender for Storage is a security solution that identifies unusual attempts to access or...

The post Microsoft Defender for Storage to Add Malware Scanning Support in September appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a new strategic partnership with Samsung to enhance mobile security for business customers. The companies have unveiled a new mobile hardware-backed device attestation solution that works seamlessly on company-owned and personal Samsung Galaxy devices. Device attestation is a security process used to verify the authenticity and integrity of a device before allowing...

The post Microsoft and Samsung Unveil New Mobile Device Attestation Solution for Businesses appeared first on Petri IT Knowledgebase.

View Details

PowerShell is a powerful scripting language for many reasons. One such reason is its support for conditional logic, which can help you supercharge your PowerShell scripts to make them even more efficient and effective. In this article, I’m going to teach you how to use If, Else, and Elseif conditional logic and explain how this...

The post How to Use PowerShell If Statements to Add Conditional Logic to Your Scripts appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced some important changes coming to Windows Server Update Services (WSUS). The company detailed in a blog post that customers will now have to use a PowerShell script to import updates for Windows devices. Windows Server Update Services (WSUS) is a solution that allows IT admins to manage the distribution and installation of...

The post Microsoft Asks IT Admins to Import Updates into WSUS with PowerShell Script appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday that firmware security advisories are now available for the Microsoft Defender Vulnerability Management service. The new feature enables organizations to continuously monitor firmware security advisories based on information from vendors’ websites and inventories as well as third-party websites. Microsoft Defender Vulnerability Management is a service that allows customers to discover critical vulnerabilities...

The post Microsoft Defender Vulnerability Management Gets Firmware Security Advisories appeared first on Petri IT Knowledgebase.

View Details

The European Commission (EC) has launched a formal probe into Microsoft’s bundling of the Teams app with Office 365 and Microsoft 365. The EU regulators plan to conduct an in-depth investigation into whether Microsoft violated the EU’s competition rules “as a matter of priority.” Microsoft’s rival Slack lodged a complaint with the European Commission back...

The post EU Starts Antitrust Probe into Microsoft Teams Bundling with Office 365 appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s financial results for the last quarter of its fiscal year 2023, and they take a closer look at the company’s Windows and Surface businesses.

The post First Ring Daily: Microsoft Releases its FY23 Q4 Earnings appeared first on Petri IT Knowledgebase.

View Details

An Office 365 tenant to tenant migration can be a complex undertaking that requires careful planning and execution. Whether due to mergers, acquisitions, or organizational restructuring, a tenant to tenant migration project involves transferring data, applications, and configurations while ensuring minimal user disruption. In this article, I will guide you through the essential steps to...

The post Planning for a Successful Office 365 Tenant to Tenant Migration Project appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of improved company branding functionality for enterprise customers. The new feature launched in preview last year, allowing organizations to customize the sign-in experiences of Microsoft Entra ID (Azure AD) and Microsoft 365 apps. “With enhanced company branding, you’ll be able to create a custom look and feel for the...

The post Microsoft Entra ID Enhanced Sign-In Branding Now Generally Available appeared first on Petri IT Knowledgebase.

View Details

Microsoft Teams is getting a new Meet app that should make it easier for users to track and manage their meeting activities and content. The company announced on the Microsoft 365 admin center that new experience will exclusively become available for customers on the Microsoft Teams 2.0 preview client next month. The Meet app will...

The post Microsoft Teams 2.0 to Add New Meet App to Manage Meeting Activities and Content appeared first on Petri IT Knowledgebase.

View Details

Microsoft has launched a URL page for its Microsoft 365 Defender solution. The new page provides a unified hub that lets security teams investigate URLs and domains as well as take remediation actions. “Whether it’s pivoting to emails, user clicks, or devices associated with URLs and fully qualified domain names (FQDNs), the enhanced functionality of...

The post Microsoft 365 Defender Adds New URL Page to Block Phishing Attacks appeared first on Petri IT Knowledgebase.

View Details

Tavis Ormandy, a Google Security researcher has discovered a new vulnerability affecting AMD’s Zen 2 processors. Dubbed Zenbleed, the security flaw could let attackers steal passwords, cryptographic keys, and other sensitive information from software running on vulnerable machines. In a recent blog post, Ormandy detailed that the Zenbleed vulnerability (CVE-2023-20593) was first reported to AMD...

The post New AMD ‘Zenbleed’ Flaw Lets Hackers Steal Passwords and Encryption Keys From Ryzen CPUs appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new firmware analysis feature for Microsoft Defender for IoT. The new capability conducts an automated analysis of a binary firmware image that runs on an IoT device to identify potential security threats and vulnerabilities. With firmware analysis, IT admins can view a detailed listing of open-source packages found in the firmware...

The post Microsoft Defender for IoT Gets New Firmware Analysis Capabilities appeared first on Petri IT Knowledgebase.

View Details

Microsoft has recently disclosed a security breach that allowed Chinese hackers to access the email accounts of around two dozen organizations. Now, security researchers have found that the stolen security key provided access to far beyond Outlook and Exchange Online email accounts. According to Microsoft, the Chinese hacking group (dubbed Storm-0558) used forged authentication tokens...

The post Report: Stolen Microsoft Key Gave Chinese Hackers Widespread Access to Cloud Services appeared first on Petri IT Knowledgebase.

View Details

Last month, Microsoft unveiled its plans to replace Windows 11’s Mail and Calendar apps with the new web-based Outlook for Windows client in September 2024. The company later detailed that it’s re-evaluating the timeline and implementation of this change. In a recent update posted on the Microsoft 365 Admin Center, Microsoft indicated that it would...

The post Microsoft to Force Migrate Mail and Calendar Apps to New Outlook for Windows Next Month appeared first on Petri IT Knowledgebase.

View Details

Microsoft provides a comprehensive suite of tools for effectively administrating and managing various aspects of the Microsoft 365 platform. There’s not just one Office 365 portal, IT pros actually have access to various admin centers, each tailored to manage specific aspects of the platform. In this article, we will explore the key admin centers available...

The post Mastering Microsoft 365 Administration: A Guide to Microsoft’s Various Admin Centers appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a public preview of Azure Boost for enterprise customers this week. The new offering is designed to offload virtualization processes onto dedicated hardware and software. The new Azure Boost service enables customers to access experimental SKUs. This release should make it easier to test integrations with their existing virtual machines (VMs) ahead...

The post Microsoft Azure Boost Launches to Offload Virtualization Processes appeared first on Petri IT Knowledgebase.

View Details

SQL Server Data Tools for Visual Studio 2022 (SSDT) is the modern replacement for Business Intelligence Development Studio (BIDS), which was introduced with SQL Server 2005. SQL Server Data Tools for Visual Studio 2022 is now delivered as a part of Visual Studio 2022, and it enables you to create and modify new projects for...

The post SQL Server Essentials: Downloading and Installing SQL Server Data Tools for Visual Studio appeared first on Petri IT Knowledgebase.

View Details

Microsoft-owned GitHub has announced the limited public beta release of GitHub Copilot Chat for enterprise customers and organizations. This release brings a context-aware conversational coding assistant into Visual Studio and Visual Studio Code development environments. GitHub launched the chatbot as a part of the Copilot X initiative to extend its code completion tool to more...

The post GitHub Copilot Chat Now Available in Public Preview for Businesses appeared first on Petri IT Knowledgebase.

View Details

Every system administrator dreams of building the perfect Rube Goldberg machine of IT automation to manage the employee IT lifecycle, end to end, including IT offboarding. A new hire joins the company, HR files a ticket, and BAM! In an instant, all of the birthright accounts, access, and permissions are granted in a glorious cascade...

The post The Dirty Truth About IT Offboarding Automation appeared first on Petri IT Knowledgebase.

View Details

Splunk Inc. announced this week a new strategic partnership with Microsoft. The new deal will enable both companies to build Splunk’s enterprise security and observability solutions on Microsoft Azure. Splunk is a popular platform that enables customers to search, analyze, and visualize machine-generated data in real-time. It collects and processes data coming from a wide...

The post Splunk Announces New Partnership with Microsoft to Boost Digital Resilience appeared first on Petri IT Knowledgebase.

View Details

Microsoft unveiled a couple of new additions to the Microsoft 365 ecosystem at its Inspire 2023 conference this week. The company plans to introduce Microsoft 365 Backup and Microsoft 365 Achieve solutions to help enterprise customers to protect and manage large volumes of data. Microsoft 365 Backup is a new service that will let organizations...

The post New Microsoft 365 Backup Solution to Launch in Preview for Exchange, SharePoint, and OneDrive appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday that it will provide organizations access to expanded cloud logging data at no additional cost to prevent potential cyberattacks. The announcement comes in response to criticism the company faced regarding the lack of security logs for select cloud licenses. Last week, Microsoft confirmed a series of attacks from a Chinese hacking group...

The post Microsoft Expands Free Access to Cloud Security Logs Following Exchange Hacks appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s pricing model for the Microsoft 365 Copilot, as well as how Microsoft’s proposed acquisition of Activision Blizzard will impact the company financially.

The post First Ring Daily: Microsoft’s AI Now Has a Price appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of its Sales Copilot at Inspire 2023 conference. The company is also bringing new AI-powered features to the Dynamics 365 customer insights platform to help organizations enhance customer engagement and sales. Microsoft Sales Copilot is an AI-based digital assistant designed for sales teams. The new service can generate content,...

The post Microsoft Launches Sales Copilot, Teases New Customer Insights Tools appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that hotpatch support is now generally available for Windows Server Azure Edition VMs running the Desktop experience. This release enables organizations to patch and install updates to Windows Server virtual machines on Azure without rebooting. The Hotpatch feature accomplishes this goal by applying the patch in-memory code of running processes without restarting...

The post Microsoft Releases Hotpatch Support for Windows Server Virtual Machines with Desktops appeared first on Petri IT Knowledgebase.

View Details

Encountering the “User profile service failed sign-in” error message can be frustrating and prevent you from accessing your logon user account on Windows. This error typically occurs due to issues with the user profile, and it can affect both local and domain accounts. In this article, I will provide a comprehensive troubleshooting guide to help...

The post Troubleshooting Guide: Fixing the “User Profile Service Failed The Sign-In” Error appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced at its Inspire conference yesterday that it’s expanding its AI partnership with Meta to accelerate innovation in that field. Microsoft will be Meta’s preferred partner to distribute Llama 2, the company’s next-gen and open-source large language model (LLM) designed for commercial use.  Over the past couple of months, the AI conversation has mostly...

The post Microsoft to Distribute Llama 2, Meta’s Open-Source Alternative to OpenAI LLM Models appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced this morning the pricing details of its Microsoft 365 Copilot tool alongside a new version of its Bing chatbot for enterprise users. The Microsoft 365 Copilot will be available as an add-on for $30 per user per month for all enterprise customers with Microsoft 365 E3, E5, Business Standard, and Business Premium subscriptions....

The post Microsoft Announces Bing Chat Enterprise and Microsoft 365 Copilot Pricing appeared first on Petri IT Knowledgebase.

View Details

Nasuni has announced a new integration with Microsoft Sentinel. This release enables organizations to automatically detect security threats and initiate responses in enterprise environments. Nasuni’s file data platform offers a cloud-native solution to help organizations manage and store their data. The unified platform combines primary file storage, backup, disaster recovery, and file-sharing capabilities. Some key...

The post Nasuni Unveils New Features, Integration with Microsoft Sentinel to Protect File Data Against Security Threats appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that the Edge Workspaces feature is now generally available for enterprise customers. The new collaboration experience launched in public preview back in April, and it lets users work together in a shared workspace within the web browser. Microsoft Edge Workspaces allow users to share a set of tabs and favorites with their...

The post Microsoft Edge Workspaces Now Generally Available for Enterprise Customers appeared first on Petri IT Knowledgebase.

View Details

Last week, Microsoft confirmed that Chinese hackers gained unauthorized access to email accounts of U.S. government agencies and other sensitive organizations. On Friday, the company detailed a blog post to explain the cause of the security breach that compromised Exchange Online email services. According to Microsoft’s Threat Intelligence team, the Storm-0558 hacking group abused three...

The post Microsoft Shares More Details About Chinese Cyberattack That Breached Exchange Email Accounts appeared first on Petri IT Knowledgebase.

View Details

When working with SQL Server databases, the SQL COALESCE expression is commonly used to detect null values and provide a fallback or default value when dealing with nullable columns or expressions in SQL queries. It’s like a syntactic shortcut for the CASE expression, and it’s typically used to make subsequent calculations easier. In this article,...

The post SQL Server Essentials: Using SQL COALESCE appeared first on Petri IT Knowledgebase.

View Details

Microsoft has added support for new system-based alerts in public preview for Windows 365 Enterprise customers. The new feature enables IT admins to keep track of Windows 365 Cloud PCs that are in a grace period. With this release, the Windows 365 IT admin alerts feature triggers an email when a Cloud PC enters the...

The post Microsoft Intune Lets IT Admins Configure Windows 365 Alerts for Cloud PCs in Grace Periods appeared first on Petri IT Knowledgebase.

View Details

Microsoft has introduced restricted management administrative units support in public preview for Microsoft Entra ID. The new role-based access control (RBAC) feature lets organizations allow only select IT admins, security teams, or devices to access specific resources. “Restricted management administrative units allow you to protect specific objects in your tenant from modification by anyone other...

The post Microsoft Entra ID Adds Restricted Management Administrative Units in Preview appeared first on Petri IT Knowledgebase.

View Details

Amazon Kinesis Data Firehose is a fully managed service for efficiently streaming data from virtually any data source to your AWS applications. It provides near-real-time ingestion capabilities for building real-time data applications. In this article, we’ll detail how Amazon Kinesis Data Firehose works and the best use cases for it. What is Amazon Kinesis Data...

The post What is Amazon Kinesis Data Firehose? appeared first on Petri IT Knowledgebase.

View Details

Microsoft Edge for Business will soon become the default experience for all enterprise customers. Microsoft has announced its plans to release version 116 of its Edge browser with the new dedicated work experience next month. Microsoft Edge for Business launched in public preview back in May 2023. This release allows users to better separate their...

The post Microsoft Edge for Business to Be Enabled By Default Next Month appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started discussing its plans regarding Windows 11 version 23H2, the next annual update for the OS to be released later this fall. On its Windows IT Pro blog yesterday, the company announced that Windows 11 version 23H2 will be released as an enablement package in the fourth quarter of 2023. “The upcoming Windows...

The post Windows 11 Version 23H2 to be Released as an Enablement Package in Q4 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft Defender for Endpoint has announced that Device isolation and Antivirus scanning capabilities are now available in preview for macOS and Linux devices. The new response actions should help to protect organizations against security threats. The device isolation feature blocks the compromised device from connecting to the corporate network. Meanwhile, Microsoft Defender for Endpoint continues...

The post Microsoft Defender for Endpoint Adds Device Isolation and Antivirus Scanning Support on Linux and macOS appeared first on Petri IT Knowledgebase.

View Details

Microsoft has disclosed that Chinese hackers breached the email accounts of US government employees. The hacking group (tracked as Storm-0558) exploited a flaw in Microsoft’s cloud email service to gain unauthorized access to email systems. Microsoft found that the threat actors used forged authentication tokens to access affected user accounts through Outlook Web Access in...

The post Microsoft Says Chinese Hackers Compromised Exchange Email Accounts appeared first on Petri IT Knowledgebase.

View Details

GitHub announced this morning that it has added support for passkeys in public beta. The passkeys feature is a standardized new way that lets users seamlessly and securely access GitHub.com. A passkey is a sequence of characters that helps to ensure that only authorized users gain access to sensitive resources. The security feature is used...

The post GitHub Adds Support for Passkeys in Public Beta for Passwordless Authentication appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft Teams 3D avatars reaching general availability and Amazon allowing all developers to release their Android apps on its App Store on Windows 11.

The post First Ring Daily: Amazon Opens its App Store on Windows 11 to All Android Apps appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that it will soon rebrand Azure Active Directory (Azure AD) as Entra ID. The name change will be a gradual process, and it’s expected to be rolled out to all Microsoft products and experiences in the second half of 2023. The Microsoft Entra product family first made its debut back in May...

The post Microsoft Rebrands Azure AD to Microsoft Entra ID appeared first on Petri IT Knowledgebase.

View Details

Nested Microsoft 365 groups refer to the practice of creating a group within another group in the Microsoft 365 ecosystem using the dynamic functionality in Azure AD. For IT admins, this practice lets them organize groups in a hierarchical manner, enabling a more structured approach to managing access, permissions, and collaboration within an organization. Membership...

The post Nested Microsoft 365 Groups: What You Need To Know appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new update that enables IT admins to manage security configuration settings directly in Microsoft Defender for Endpoint. The native security management capabilities are available in public preview on Windows, macOS, and Linux. Previously, IT administrators had to depend on external tools for handling endpoint security settings. This approach often resulted in...

The post Microsoft Defender for Endpoint Lets IT Admins Natively Manage Security Settings appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released today the July Patch Tuesday updates for Windows 11 and Windows 10. The KB5028185 patch for Windows 11 version 22H2 brings the new “Moment 3” features that Microsoft previously made available in the optional update released in the last week of June.  Microsoft’s patches for July 2023 also include fixes for 130...

The post July Patch Tuesday Updates Are Out With ‘Moment 3’ Features appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to end support for Windows 11 version 21H2. The company updated its support life cycle page to remind customers that the original version of the operating system will reach the end of servicing deadline on October 10, 2023. Microsoft detailed that the upcoming end of support affects the Home, Pro, Pro...

The post Microsoft to End Windows 11 version 21H2 Support on October 10 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a slew of updates for its Microsoft Entra product family. The company detailed two new security offerings, Microsoft Entra Internet Access and Microsoft Entra Private Access, to protect organizations against cyberattacks. “In the last twelve months, we saw an average of more than 4,000 password attacks per second, an almost threefold increase...

The post Microsoft Entra Gets New Identity and Access Management Solutions appeared first on Petri IT Knowledgebase.

View Details

Microsoft launched its Dev Box cloud-powered workstations in public preview back in August 2022. The company announced yesterday that it has decided to make the service generally available following successful testing in multiple organizations. Microsoft first teased Dev Box at its Build developer conference last year. The new offering provides secure access to pre-configured developer...

The post Microsoft Dev Box Goes Out of Preview appeared first on Petri IT Knowledgebase.

View Details

Amazon Web Services (AWS) has announced a new end-to-end solution called Clickstream Analytics on AWS. The new service enables customers to collect, ingest, analyze, and visualize clickstream data within their web and mobile applications. Clickstream Analytics on AWS is built on standard AWS services. The company says that clickstream data plays a vital role in...

The post Clickstream Analytics on AWS Launches to Enhance Data Visualization in Mobile and Web Apps appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the release of the latest version of Visual Studio Code. The July 2023 Update (version 1.80) comes with a few enhancements, such as terminal image support, accessibility improvements, and more. Last month, Microsoft added terminal image support in public preview in Visual Studio Code. Now, the feature is enabled by default that...

The post Visual Studio Code 1.80 is Out with Terminal Image Support and More appeared first on Petri IT Knowledgebase.

View Details

Cisco has recently warned customers about a new high-severity vulnerability that affects select data center switch models. The security flaw, which is tracked as CVE-2023-20185, could enable unauthenticated attackers to read or modify encrypted traffic. “This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption...

The post Cisco Discloses New Flaw in Enterprise Switches That Lets Hackers Intercept Encrypted Traffic appeared first on Petri IT Knowledgebase.

View Details

In the ever-evolving digital landscape, organizations are generating an increasing volume of emails and other electronic communications. Efficiently managing this growing influx of messages while maintaining compliance with regulatory requirements has become a critical aspect of modern business operations. One effective solution offered by Microsoft’s Office 365 suite is the archive mailbox feature. In this...

The post How To Enable Archive Mailboxes In Office 365 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has detailed several updates to celebrate the first anniversary of Windows Autopatch. The new capabilities that are designed to help IT admins improve productivity and security will become generally available on July 25. Microsoft launched its Windows Autopatch back in July 2022. It’s a cloud-based service that allows customers to automate the patching of...

The post Microsoft Celebrates the First Anniversary of Windows Autopatch with the Latest Updates appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday the general availability of its Windows 365 Frontline service. The new offering launched in public preview in April, allowing organizations to offer Cloud PCs to frontline, shift, and part-time workers. With Windows 365 Frontline, customers can purchase a certain number of Cloud PC licenses that can be shared among different employees. The...

The post Microsoft’s Windows 365 Frontline is Now Generally Available appeared first on Petri IT Knowledgebase.

View Details

As Microsoft is still busy implementing AI-powered Copilot experiences across all of its cloud services, this month we’re going to take a look at some of the quieter features Microsoft added to its Power Platform to help makers be more efficient and secure when building apps. Delegation improvements for Power Apps Anybody who’s ever built...

The post What’s New With Microsoft’s Power Platform in June 2023 appeared first on Petri IT Knowledgebase.

View Details

Researchers have developed an exploit for a new critical vulnerability in the FortiGate firewall that affects around 336,000 Internet-exposed devices. The security advisory warned that IT admins have yet to install the patches released in June 2023. The heap-based buffer overflow vulnerability (tracked as CVE-2023-27997) has a severity rating of 9.8 out of 10. It...

The post Critical FortiGate Vulnerability Affects 336,000 Vulnerable Firewalls appeared first on Petri IT Knowledgebase.

View Details

In today’s dynamic business landscape, managing user access to resources is critical for organizations. Azure Active Directory (AAD), a comprehensive identity and access management solution from Microsoft, offers a powerful feature called dynamic groups. These dynamic user groups provide a flexible and automated approach to managing user access based on predefined rules and user attributes....

The post How to Use Microsoft 365 Dynamic Groups to Streamline Access Management appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to make its new Teams 2.0 client available for all users. As of today, the new app is available via a toggle in public preview, but the same toggle will become generally available for customers in September. Microsoft launched the new Teams 2.0 client in public preview in March 2023. The...

The post Microsoft Teams 2.0 to Become Default Client on Windows in September appeared first on Petri IT Knowledgebase.

View Details

Microsoft has introduced support for app health recommendations in Microsoft Entra Workload Identities. The feature provides insights with actionable guidance to help organizations prevent outages and secure their Azure AD environments. Microsoft Entra Workload Identities launched back in November 2022. It’s an identity and access management (IAM) solution that enables IT admins to configure Conditional...

The post Microsoft Entra Workload Identities Service Adds Support for App Health Recommendations appeared first on Petri IT Knowledgebase.

View Details

The T-SQL LIKE operator is one of the most useful additions to the SQL SELECT statement. The latter retrieves a result set, and you can easily filter the results using equality operators and the WHERE clause to select certain specific conditions. But what about those times when you might want to select rows that are...

The post SQL Server Essentials: Using the SQL LIKE Operator appeared first on Petri IT Knowledgebase.

View Details

Microsoft has shared the latest round of updates made to its Teams collaboration platform in June 2023. The company released 45 new features to improve meetings, chats, Teams Rooms devices, and much more. Here’s a look at everything you need to know. Meeting and calling features Last month, Microsoft introduced a new Spatial audio feature...

The post Microsoft Teams Meetings Get New Spatial Audio Experience, Together Mode Improvements appeared first on Petri IT Knowledgebase.

View Details

Microsoft Teams Meeting Notes is a feature in the Teams and Outlook apps that allows you to take collaborative notes during meetings in Microsoft Teams. Meeting Notes are Loop components stored in the chat transcript for the meeting, so you can easily access them later or share them elsewhere. In this article, I will show...

The post How Microsoft Teams Meeting Notes Can Supercharge Your Meeting Efficiency appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a new strategic partnership with New York-based financial risk assessment firm Moody’s. The company explained that the deal will enable Moody’s to bring generative AI capabilities to its enterprise solutions. Moody’s plans to use Azure OpenAI service to build new research and risk assessment products and services in order to improve data...

The post Microsoft, Moody’s Partner to Empower Financial Services with Generative AI Tools appeared first on Petri IT Knowledgebase.

View Details

Microsoft has acknowledged a new compatibility issue with Trellix’s endpoint security software and some Windows 11 and Windows 10 devices. The company detailed on the Windows Health dashboard that the bug prevents users from opening Microsoft Office and third-party apps. According to Microsoft, the problem is caused by the latest Patch Tuesday updates released on...

The post Microsoft Confirms New Windows Bug Affecting Some Endpoint Security Tools appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started testing Windows Copilot, its new AI Assistant for Windows 11 with Windows Insiders yesterday. The first Windows Copilot preview is available for a subset of Insiders who will install the Dev Channel build 23493, and Microsoft plans to expand to other Insiders channels over time.  Windows Copilot was first announced during Microsoft’s...

The post Windows Copilot Preview is Now Available for Insiders appeared first on Petri IT Knowledgebase.

View Details

Earlier this year, Microsoft unveiled its plans to ditch the Yammer brand in favor of Viva Engage. Now, the company has announced that the Yammer.com web experience has been renamed to Viva Engage. Yammer was initially launched as a startup at a TechCrunch startup event back in 2008. It was designed to help organizations create...

The post Microsoft Rebrands Yammer Web Experience to Viva Engage appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released new updates to improve Adoption Score, Usage Reports, and Experience insights in the Microsoft 365 admin center. The company announced yesterday that the Adoption Score feature is now generally available for all commercial customers. The Adoption Score feature uses metrics to help customers understand how Microsoft 365 software gets used in enterprise...

The post Microsoft Adoption Score Feature Now Generally Available for Commercial Customers appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a new partnership with Zero Trust cybersecurity vendor Rubrik. The deal will allow enterprise customers to utilize natural language processing and generative AI to speed up security response times during cyber attacks. Rubrik is a cybersecurity company that focuses on enhancing data security and operational resilience for organizations. It offers a platform...

The post Microsoft Partners with Rubrik to Enhance Incident Response with Generative AI appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Windows 11 Moment 3 now being available as an optional update, and Windows Copilot still missing in action despite Microsoft promising a June preview release.

The post First Ring Daily: Windows 11 Moment 3 Approaches, Windows Copilot Still MIA appeared first on Petri IT Knowledgebase.

View Details

Grafana has recently released new security updates to patch a critical vulnerability in its application. The flaw could enable threat actors to hijack Grafana accounts that use Azure Active Directory (Azure AD) for authentication. Grafana is a popular analytics and visualization service that enables IT admins to monitor and analyze time-series data. It provides access...

The post Grafana Patches Critical Azure AD Authentication Bypass Vulnerability appeared first on Petri IT Knowledgebase.

View Details

Implementing identity and access management processes is an effective way to protect sensitive corporate data. It allows organizations to regulate user access and prevent instances of identity theft, data breaches, and unauthorized access to confidential corporate information. In this article, we’ll detail how organizations can significantly minimize their exposure by controlling access privileges with Microsoft...

The post Implementing Access Controls using Microsoft Intune appeared first on Petri IT Knowledgebase.

View Details

Microsoft could be working to launch a consumer version of its Windows 365 Cloud PC service. According to a new report from Windows Central, the company unveiled its plans in an internal document released to the public as part of Microsoft’s legal battle with the Federal Trade Commission. Microsoft introduced its Windows 365 offering back...

The post Microsoft Reportedly Working on Windows 365 Cloud PC Offering for Consumers appeared first on Petri IT Knowledgebase.

View Details

Microsoft made the Windows 11 ‘Moment 3’ update available with the optional June 2023 preview release yesterday. This update (KB5027303) was previously rolled out to Insiders on the Release Preview channel earlier this month, and the new features will roll out to the general Windows 11 version 22H2 audience with next month’s Patch Tuesday.  ...

The post June 2023 Preview Release Brings ‘Moment 3’ Features to Windows 11 appeared first on Petri IT Knowledgebase.

View Details

Last month, Microsoft announced the launch of its Microsoft 365 Copilot Early Access Program. Now, the company has detailed a lengthy blog post to inform potential customers about how to prepare for Microsoft 365 Copilot. Microsoft 365 Copilot uses large language models to help users write/edit documents, organize data, and analyze information. Users can leverage...

The post Microsoft Details Onboarding Requirements for Microsoft 365 Copilot appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out a new Notes tab to Microsoft Teams for Enterprise customers. Powered by OneNote, the Notes tab will be automatically added when a user creates new standard channels in Microsoft Teams. OneNote is a digital notetaking app that is available for Microsoft 365 customers. It lets users capture, organize and share...

The post Microsoft Teams Adds New Notetaking Experience to Channels appeared first on Petri IT Knowledgebase.

View Details

Security researchers have recently discovered a new vulnerability in Microsoft Teams. The flaw could enable threat actors to deliver malware to Teams users through a federated chat. The vulnerability was originally discovered by security researchers Max Corbridge and Tom Ellson from the JUMPSEC Labs’ Red Team. The researchers found that the flaw exists in the...

The post Microsoft Teams External Access Vulnerability Lets Attackers Deliver Malware appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the release of the June 2023 service release (2306) for Microsoft Intune. The latest update brings Mobile Application Management (MAM) support for Microsoft Edge for Business on Windows. Mobile Application Management (MAM) is a feature that enables organizations to protect and manage mobile apps installed on tablets and smartphones. It helps IT...

The post Microsoft Intune Gets MAM for Edge on Windows Support appeared first on Petri IT Knowledgebase.

View Details

Microsoft has acknowledged a new issue that causes high CPU usage in Windows 11 versions 21H2 and 21H2. The File Explorer bug only impacts users who had installed the KB5026368 and KB5026372 updates released on May 9. Effective Access is a feature that determines permissions and privileges that a user or user group has to...

The post Microsoft Confirms New High CPU Usage Bug in Windows 11 File Explorer appeared first on Petri IT Knowledgebase.

View Details

These days, document theft and data siphoning are common for most ransomware gangs. Because digital theft is different from analog theft, digital security should be different from analog security. In this article, we’ll explore how Windows Hello for Business and seamless single sign-on (SSO) can help organizations to mitigate many identity-related risks. We’re holding on...

The post Mitigating Identity-Related Risks With Windows Hello for Business and Seamless Single Sign-On (SSO) appeared first on Petri IT Knowledgebase.

View Details

Microsoft has patched a new security vulnerability that was discovered in some applications leveraging Azure Active Directory (Azure AD). The authentication bypass flaw could allow threat actors to completely take over the victim’s account. The security vulnerability, dubbed nOAuth, was first discovered by the security researchers at Descope. It lets threat actors modify email attributes...

The post Microsoft Patches Critical ‘nOAuth’ Flaw in Azure AD Apps appeared first on Petri IT Knowledgebase.

View Details

If you have recently encountered issues accessing Microsoft Teams, Outlook, and other Microsoft 365 apps, you’re not alone. Several IT admins detailed on Reddit and Microsoft support forums that the problem started affecting customers worldwide on June 19 (via Bleeping Computer). Specifically, IT admins received reports that some Outlook users are unable to access the...

The post Microsoft 365 Customers Locked Out of Outlook, Teams, and Other Apps appeared first on Petri IT Knowledgebase.

View Details

AWS Lambda is an event-driven, serverless compute service offered by Amazon Web Services (AWS). It enables developers to run code in response to events without having to manage the computing resources and infrastructure needed to run these applications. In this article, I’ll explain how AWS Lambda works and detail the best use cases for this...

The post What is AWS Lambda? appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the release of the 0.2 preview version of the Dev Home app for Windows 11. The latest update brings several quality improvements and bug fixes to enhance the overall experience for developers. Microsoft launched the new Dev Home app for Windows 11 in preview at its annual Build developer conference. The new...

The post Dev Home Preview 0.2 Now Available With Several Improvements and Bug Fixes appeared first on Petri IT Knowledgebase.

View Details

Google has officially filed an antitrust complaint against Microsoft with the Federal Trade Commission (FTC), according to a report from The Information. The company claimed that Microsoft abused its dominant position in the enterprise software market to push more customers toward its cloud services. In a letter to the FTC, Google explained that Microsoft used...

The post Google Takes on Microsoft with New Antitrust Complaint Over Cloud Practices appeared first on Petri IT Knowledgebase.

View Details

As an IT pro, the process of exporting users’ mailboxes to PST is rather straightforward. However, importing PST email and calendar items into new mailboxes can be tricky. In this article, I will detail how to import PST files to Office 365 using either Outlook or the Microsoft Purview Compliance portal and Azure AzCopy. How...

The post How to Import PST Files to Office 365 appeared first on Petri IT Knowledgebase.

View Details

Microsoft is working to fix a bug causing Outlook to become unresponsive on the startup screen for a while before launching normally. The company acknowledged the issue in a support document published on June 19. According to Microsoft, the Outlook desktop app syncs the entire offline data file (.ost) during the startup process. “Investigation of...

The post Microsoft to Fix Slow Startup or Freezing Issues in Outlook appeared first on Petri IT Knowledgebase.

View Details

ASUS has rolled out a new set of firmware updates to address critical vulnerabilities in its several router models. The company published a security advisory yesterday recommending customers to apply the security patches or restrict WAS access. Specifically, the latest firmware updates aim to fix two critical vulnerabilities with a 9.8 severity rating out of...

The post ASUS Routers Get New Firmware Updates to Patch Critical Vulnerabilities appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to sunset its Bookings mobile apps next month. The apps will be retired on July 15, and users will no longer be able to access Microsoft Bookings through Android and iOS devices. Microsoft Bookings is an appointment scheduling and booking management service that launched in March 2017. The tool is primarily...

The post Microsoft Bookings Mobile Apps to Retire Next Month appeared first on Petri IT Knowledgebase.

View Details

An often-overlooked element of security is the Web Application Firewall (WAF), especially in cloud computing. In this article, I explain what a WAF does, the different kinds of WAF, and I discuss why you should deploy one or more WAFs in your architecture. What is a Web Application Firewall (WAF)? A Web Application Firewall, often...

The post The Ultimate Guide to Web Application Firewalls (WAF) appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new upgrade/downgrade experience for Azure Firewall. The feature allows customers to switch between the Azure Firewall Standard and Premium offers with a single click. Azure Firewall is a cloud-native security solution for Azure environments. It enables customers to protect their network resources and applications against unauthorized access and security threats. Azure...

The post Microsoft Azure Firewall Adds New Upgrade/Downgrade Experience appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Brad Sams and Paul Thurrott discuss Microsoft’s plan to replace the Windows 11 Mail and Calendar apps with the new web-based Outlook for Windows in September 2024.

The post First Ring Daily: New Outlook to Replace Mail and Calendar Apps in 2024 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced some changes coming to the security settings management capabilities in Microsoft Defender for Endpoint this month. The company plans to remove the Azure Active Directory (AD) join or Hybrid Azure AD join enrollment requirement for Windows devices. Last year, Microsoft released a new feature called Security Management for Microsoft Defender for Endpoint....

The post Microsoft Defender for Endpoint Eases Enrollment Requirements for Devices Managed via Intune appeared first on Petri IT Knowledgebase.

View Details

There are quite a few methods IT Pros can use to block malicious and harmful emails from flowing into their organizations. Similar to my previous post on adding a whitelist email address or domain to your Microsoft 365 settings, I’m going to detail different methods to block senders in Officer 365 and offer some commentary...

The post How To Block Senders in Office 365 appeared first on Petri IT Knowledgebase.

View Details

Earlier this month, Microsoft confirmed a major outage that affected Azure, Outlook, Teams, and other Microsoft 365 services. The company has now acknowledged that the disruption to its services was caused by a distributed denial of service (DDoS) attack. On June 5th, Microsoft tweeted about an outage that prevented thousands of users from accessing its...

The post Microsoft Confirms Recent Cloud Outages Caused By Storm-1359 DDoS Attacks appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to replace the UWP Mail and Calendar apps with the new Outlook desktop client for Windows. The company announced in a message on the Microsoft 365 Admin Center that the web-based app will be shipped with all new Windows 11 devices starting in September 2024. Microsoft started testing its redesigned Outlook...

The post Microsoft’s New Outlook for Windows Client to Replace Mail and Calendar Apps in 2024 appeared first on Petri IT Knowledgebase.

View Details

I recently spoke to Sean Deuby, who is Principal Technologist at Semperis and an Identity expert. Sean told me about the importance of protecting identities in the current landscape and how Identity Threat Detection and Response (ITDR) is a critical component of the Zero Trust security model. The emergence of cloud computing and the shift...

The post The Role of Identity Threat and Detection Response in Zero Trust Security appeared first on Petri IT Knowledgebase.

View Details

Microsoft Teams is getting a new collaborative meeting notes feature to improve the meeting experience. This release enables participants to collaborate on notes with their colleagues during Teams meetings. In Microsoft Teams, the collaborative meeting notes feature allows users to take notes, create agendas, as well as generate action items. It eliminates the need to...

The post Microsoft Teams Gets New Collaborative Meeting Notes Experience appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced new AI-powered Copilot features for Microsoft Dynamics 365 enterprise resource management (ERP) solutions. The new Copilot capabilities are available in public preview for Dynamics 365 Project Operations, Finance, and Supply Chain Management. “Complex and rigid processes within ERP create more work for people, and repetitive manual data entry overwhelms departments. Dynamics 365...

The post Microsoft Adds New Copilot AI Capabilities to Dynamics 365 ERP appeared first on Petri IT Knowledgebase.

View Details

Microsoft Exchange Online Archiving allows you to alleviate issues your users run into when their mailboxes approach their allocated quota. As an IT admin, Exchange Online Archiving is a really powerful tool that should not be overlooked. In this article, I’ll examine why archiving is necessary and how to enable Exchange Online Archiving to help...

The post How to Get Started With Exchange Online Archiving appeared first on Petri IT Knowledgebase.

View Details

Microsoft unveiled its plans to introduce Win32 app isolation support in Windows 11 at its Build 2023 conference. The company announced yesterday that the feature is now available in public preview for Windows 11 users. With this release, Windows 11 users can run Win32 apps in an isolated environment to protect other parts of the...

The post Microsoft Introduces Win32 App Isolation Support to Boost Security on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

Intel announced this week a new branding structure that the company will start to use with its upcoming 14th gen Meteor Lake CPUs. The company will simplify the branding of its Core processors by dropping the “i” letter for processor tiering, and it’s also creating a new Ultra label for its most advanced processors.  Intel...

The post Intel Reveals New Core Branding For its Upcoming Meteor Lake CPUs appeared first on Petri IT Knowledgebase.

View Details

To improve the repairability and durability of its various Surface devices, Microsoft has started selling official Surface replacement parts on its Microsoft Store. The dozens of components currently available include batteries, SSDs, screens, keyboards, and more. Microsoft makes Surface devices for both consumers and professionals and in recent years, the company significantly improved their repairability...

The post Microsoft Now Sells  Replacement Parts for Surface Tablets, Laptops, and All-in-Ones appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of Azure Firewall structured...

The post Microsoft Releases Azure Firewall Structured Logs Feature to Troubleshoot Network Issues appeared first on Petri IT Knowledgebase.

View Details

Microsoft has officially dropped support for Windows 10 version 21H2....

The post Microsoft Drops Support for Windows 10 Version 21H2 appeared first on Petri IT Knowledgebase.

View Details

Microsoft’s SQL Server Management Studio (SSMS) is the primary tool...

The post SQL Server Essentials: Installing SQL Server Management Studio and Azure Data Studio appeared first on Petri IT Knowledgebase.

View Details

Microsoft has just released the June 2023 Patch Tuesday updates...

The post Microsoft Releases June 2023 Patch Tuesday Updates appeared first on Petri IT Knowledgebase.

View Details

Last week, Microsoft acknowledged an issue that triggered connectivity issues...

The post Microsoft Claims Azure Outage Caused By ‘Huge Spike’ in Network Traffic appeared first on Petri IT Knowledgebase.

View Details

In this episode, I sit down with Microsoft MVP, Darrell...

The post UnplugIT Episode 2 – In The Loop appeared first on Petri IT Knowledgebase.

View Details

Microsoft Defender for Endpoint has introduced a new monthly security...

The post Microsoft Defender for Endpoint Adds New Monthly Security Summary Report appeared first on Petri IT Knowledgebase.

View Details

Last year, Microsoft started testing a new multi-app kiosk mode...

The post IT Admins Can Now Set Up Multi-App Kiosk Mode on Windows 11 PCs appeared first on Petri IT Knowledgebase.

View Details

Microsoft-owned GitHub has launched a new GitHub Enterprise Importer tool....

The post GitHub Enterprise Importer Tool Launches to Make Cloud Migrations Easier appeared first on Petri IT Knowledgebase.

View Details

MC584218 – Direct email notifications are sent to users who...

The post M365 Changelog: Upcoming changes to direct email notifications appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released two new capabilities for Microsoft Teams certified...

The post Microsoft Teams Certified Devices Let Users Join Meetings From the Pre-Join Screen appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new threat-informed security posture recommendations feature...

The post Microsoft 365 Defender Now Supports Threat-Informed Security Posture Recommendations appeared first on Petri IT Knowledgebase.

View Details

Microsoft has modified the procedures for IT Pros and Exchange...

The post How To Export An Office 365 Mailbox To PST: A Complete Guide appeared first on Petri IT Knowledgebase.

View Details

MC546939 – Updated June 8, 2023: Microsoft has updated the...

The post M365 Changelog: (Updated) Microsoft Viva – Auto-Categorization Coming to Meeting Category Insights in Viva Insights appeared first on Petri IT Knowledgebase.

View Details

MC560731 – Updated June 8, 2023: Microsoft has updated the...

The post M365 Changelog: (Updated) Updating the Bookings app to the Virtual Appointments app appeared first on Petri IT Knowledgebase.

View Details

MC565271 – Updated June 8, 2023: Microsoft has updated the...

The post M365 Changelog: (Updated) System preferred MFA method is Generally Available appeared first on Petri IT Knowledgebase.

View Details

MC578279 – To assist in the implementation of security best...

The post M365 Changelog: Microsoft Purview – Data Lifecycle and Records Management – Scope the administration of retention and label policies appeared first on Petri IT Knowledgebase.

View Details

MC549348 – Updated June 8, 2023: Microsoft has updated the...

The post M365 Changelog: (Updated) Webinar Email feature updates -customize content and time to send reminders appeared first on Petri IT Knowledgebase.

View Details

MC574387 – Updated June 8, 2023: Microsoft has updated the...

The post M365 Changelog: (Updated) Microsoft Viva – Quick Access to Homesite on Viva Connections Mobile appeared first on Petri IT Knowledgebase.

View Details

Microsoft is getting ready to deprecate the calendar board view...

The post Microsoft’s Outlook Web App to Retire Calendar Board View This Month appeared first on Petri IT Knowledgebase.

View Details

Microsoft has introduced a new site-based licensing model for its...

The post Microsoft Defender for IoT Switches to New Site-Based Licensing Model appeared first on Petri IT Knowledgebase.

View Details

Google has released several new security features to improve the...

The post Google Password Manager to Add Support for Biometric Authentication for Desktop Users appeared first on Petri IT Knowledgebase.

View Details

Exchange Online PowerShell is a command-line tool that allows you...

The post How to Connect to Exchange Online Using PowerShell appeared first on Petri IT Knowledgebase.

View Details

MC578237 – Starting the first week of July, the same...

The post M365 Changelog: New tenant configuration experiences within Viva Engage admin center appeared first on Petri IT Knowledgebase.

View Details

MC468492 – Updated June 8, 2023: Number matching is now...

The post M365 Changelog: (Updated) Authenticator number matching to be enabled for all Microsoft Authenticator users appeared first on Petri IT Knowledgebase.

View Details

Microsoft unveiled its plans to retire the old Exchange Admin...

The post Microsoft to Retire Old Exchange Admin Center for Exchange Online Customers This Month appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the release of a preview version of...

The post Microsoft Rolls Out New C# Dev Kit for Visual Studio Code in Preview appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday that its Azure OpenAI Service is now...

The post Microsoft Releases Azure OpenAI Service for Government Customers appeared first on Petri IT Knowledgebase.

View Details

Google has opened pre-orders for Duet AI for Google Workspace...

The post Google Opens Pre-Orders for Duet AI for Google Workspace Enterprise appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced this morning the general availability of Microsoft Entra...

The post Microsoft Entra ID Governance Service is Now Generally Available appeared first on Petri IT Knowledgebase.

View Details

Last month, Google introduced passkey support for consumer Google accounts....

The post Google Workspace Introduces Passkey Support to Protect Users Against Phishing Attacks appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new update for its Windows 365...

The post Microsoft Lets IT Admins Move Windows 365 Cloud PCs to Another Region appeared first on Petri IT Knowledgebase.

View Details

SQL CROSS JOIN queries are used to generate a paired...

The post SQL Server Essentials: Using SQL Cross Joins appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced today that Visio is now available as...

The post Microsoft Teams Adds New Visio App to Improve the Diagramming Experience appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a new integration that will let users sync their task lists between Loop components and Microsoft Planner and To Do. This release should make it easier for users to manage their tasks from Microsoft 365 applications.

Microsoft introduced Loop components at its Build developer conference back in 2019. Microsoft Loop components are based on the Fluid Framework to let users collaborate on notes, tables, or lists (tasks) in emails, chats, and documents. Task lists in Loop components allow users to create collaborative lists of tasks and assign them to people with @ mentions. It’s also possible to set due dates and track the status of tasks.

Currently, task lists in Loop components are available in Microsoft Teams and Outlook. Users can add them to their chat and email conversations via the “Loop Components” menu. The new integration will allow users to edit the tasks (such as the title, due date, or assignees) via Microsoft Planner. In Microsoft To Do, users will be able to view their tasks in the‘Assigned to me’ section.

“With this change, all tasks created in these lists will automatically sync and be visible in Planner, and assigned tasks will show up in To Do in the ‘Assigned to me’ smart list. These tasks will also be visible in all apps that show Planner and To Do tasks such as the Tasks app in Microsoft Teams,” the company explained on the Microsoft 365 Admin center.

Loop components task lists integration with Microsoft Planner and To Do to roll out this monthMicrosoft notes that this update will start rolling to the Microsoft Loop desktop, web, and mobile clients later this month. The feature will become generally available for all customers in mid-July.

In case you missed it, Microsoft launched a standalone Loop app in public preview in March 2023. The app has been available in beta since last year, and it lets teams collaborate in real-time with workspaces, pages, and other Loop components.

The post Microsoft Loop Components to Sync Task Lists with Planner and To Do appeared first on Petri IT Knowledgebase.

View Details

Microsoft Outlook went down for almost 8 hours on Monday, along with Teams, OneDrive for Business, SharePoint Online, and other Microsoft 365 services. Microsoft confirmed on Twitter this morning that the problem has popped up again.

In a Reddit thread, several Microsoft 365 users reported that the first outage started hitting organizations at around 10:00 ET on Monday. The reports on various social media platforms suggest users could not access emails or other Microsoft 365 services. Microsoft rolled back the problematic update that caused the technical problem and reported a service improvement.

However, Microsoft 365 services were hit again just after a couple of hours. Microsoft acknowledged the second outage in a tweet at around 16:15 ET and deployed a fix within three hours. Downdetector indicates that the first outage affected around 18,000 users at the peak of the problem. Meanwhile, the website reported more than 5,000 complaints from customers impacted by the second glitch at its peak.

Unfortunately, Microsoft 365 apps and services are facing issues again today. Microsoft first acknowledged the issue at 05:06 ET, though it looks like the problem started even before that. At the time of writing, it’s not clear how widespread the Microsoft 365 outage is or whether it’s affecting all Microsoft 365 services.

“We’re seeing a recurrence of the issue and a drop in service availability, so we’re applying mitigations to provide relief for the affected users, while we continue to investigate the root cause. We’ll be providing updates related to this event under MO572252 in the admin center,” Microsoft explained.

Microsoft 365 customers have expressed their concern with the company’s handling of the downtime. “Already we lost our production yesterday and today also it started. When will you resolve this issue permanently. Everyones business affected by your incapability,” a Microsoft 365 subscriber wrote on Twitter.

Source: DowndetectorMajor Microsoft 365 outages continue to plague organizationsIt’s important to note that this is not the first time that users are experiencing issues while accessing Microsoft 365 apps and services. Microsoft suffered two global outages in January and February that prevented users from accessing emails and Microsoft Teams.

Back in April, Microsoft confirmed an issue that broke the search functionality across various Microsoft 365 services. These include Microsoft Teams, Outlook on the Web, Outlook desktop clients, SharePoint Online, and Exchange Online.

The post Microsoft 365 Services Hit With Another Outage Causing Connectivity Issues appeared first on Petri IT Knowledgebase.

View Details

Apple unveiled yesterday a new M2 Ultra chip that is coming to its desktop workstations, the Mac Studio and the Mac Pro. The latter was also the last Mac model that had yet to make the transition from Intel chips to Apple Silicon, and this is finally happening almost three years after the introduction of Apple’s first M1 chip in the fall of 2020.

Even though Apple’s PC market share dropped from 8.6% to 7.2% between Q1 2022 and Q2 20233 according to IDC, Apple’s M-series chips continue to deliver an unmatched level of performance per watt. And even though Apple isn’t going as hard on AI as its competitors these days, M-Series chips also come with a powerful neural engine for running complex AI workloads.

New Mac Studio with M2 Max and M2 Ultra ChipsThe original Mac Studio that Apple launched last year was the most powerful Mac ever with its M1 Max and M1 Ultra chips. The base model is now being upgraded with the same M2 Max chip that first launched on the new 14-inch and 16-inch MacBook Pros earlier this year.

The M2 Max offers 12 CPU cores, up to 38 GPU cores, and up to 96GB of unified memory with 400GB/s of memory bandwidth. Overall, Apple promises up to 50 percent faster performance compared to the previous Mac Studio model with M1 Max.

The Mac Studio can also be configured with Apple’s brand new M2 Ultra chip, which combines two M2 Max chips together to deliver even more performance. The M2 Ultra includes 24 CPU cores, up to 76 GPU cores, and up to 192 GB of unified memory with 800GB/s bandwidth. Apple says that the M2 Ultra Mac Studio is up to 3x faster than the previous model with an M1 Ultra chip.

The Mac Studio now comes with M2 Max and M2 Ultra chips (image credit: Apple)With a total of six Thunderbolt 4 ports that support native DisplayPort output over USB-C, the M2 Max Mac Studio can connect to up to five displays at once, while the M2 Ultra model can support up to eight displays simultaneously. The Mac Studio with M2 M comes with an HDMI 2.1 port. The Mac Studio also comes with a 10 GB Ethernet port, and it supports Wi-Fi 6E and Bluetooth 5.3.

The Mac Studio with an M2 Max chip starts at $1999, while the M2 Ultra model starts at $3999. Both models are available to pre-order and will start shipping next week.

The Mac Pro is the first Apple Silicon Mac to offer PCIe ExpansionApple Silicon finally comes to the Mac Pro as the new model now comes with the same M2 Ultra chip Apple offers on the high-end Mac Studio. Again, this chip offers 24 CPU cores, up to 76 GPU cores, and up to 192GB of unified memory with 800GB/s bandwidth. “This is far more memory than the most advanced workstation graphics cards,” Apple emphasized yesterday.

The Mac Pro is also the first Apple Silicon Mac to offer expansion capabilities with six open PCIe Gen 4 expansion slots. There are also eight Thunderbolt 4 USB-C ports, two USB-A ports, two HDMI 2.1 ports, and two 10Gb Ethernet ports.

The Mac Pro features six open PCle expansion slots (image credit: Apple)“From audio pros who need digital signal processing (DSP) cards, to video pros who need serial digital interface (SDI) I/O cards for connecting to professional cameras and monitors, to users who need additional networking and storage, Mac Pro lets professionals customize and expand their systems, pushing the limits of their most demanding workflows,” Apple said yesterday.

The M2 Mac Pro starts at $6999, and there’s also a rack-mounted version that starts at $7499. Yes, that remains very expensive, but this finally completes the Mac transition to Apple Silicon.

Apple Launches Bigger 15-inch MacBook AirUntil now, Apple enthusiasts looking for a MacBook with a bigger display had to opt for the 14-inch or 16-inch MacBook Pros, which start at $1999. That finally changes with the new 15-inch MacBook Air Apple announced yesterday.

This new 15-inch MacBook uses the same M2 chip as the 13-inch model that launched last fall, and this chip includes an 8-core CPU, a 10-core GPU, and up to 24GB of unified memory. Apple also promises up to 18 hours of battery life, the same as on the 13-inch MacBook Air.

The 15.3-inch Liquid Retina display on the new 15” MacBook Air offers a 2880×1864 resolution and up to 500 nits of brightness. However, it doesn’t support the adaptive refresh rate technology that’s available on the 14-inch and 16-inch MacBook Pros.

Apple says its 15-inch MacBook Air is the thinnest 15-inch laptop (image credit: Apple)Apple says that its new 15-inch MacBook Air is the thinnest 15-inch laptop with a 0.45 inch (1.15 cm) height, and it also weighs just 3.3 pounds (1.51 kg). However, the port selection is quite limited with just two Thunderbolt/USB4 ports, one MagSafe port for charging, and a headphone jack.

This new 15-inch MacBook Air starts at $1299, and the 13-inch model has seen its price cut to $1099. The M1 model from 2020 also remains available at $999.

Overall, Apple’s Mac lineup in 2023 is pretty solid, and Apple Silicon Macs have become good Windows machines now that Microsoft recognizes Parallels Desktop for Mac as a supported scenario for running Windows 11. You can actually get better Windows performance with an Apple Silicon Mac than you would with a Windows on ARM workstation powered by Qualcomm’s latest Snapdragon 8cx Gen 3 chip.

The post Apple’s M2 Ultra Mac Pro Completes the Mac Transition to Apple Silicon appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new zoom controls feature in preview for Microsoft Teams. This update allows participants to zoom in and out while viewing content on a shared screen in Teams meetings and calls.

Up until now, Microsoft Teams only allowed meeting attendees to use pinch to zoom gesture on trackpads or other shortcuts to view content such as Excel Spreadsheets or PowerPoint presentations. The new zoom controls should be a welcome addition for people with low vision or visual impairment.

“Users in a Teams call or meeting will now see new buttons to zoom in, zoom out and restore the original size of the incoming screen share. This will greatly enhance the experience of users viewing screen share,” the Office Insider team explained.

To try out zoom controls, IT admins will have to sign up for the Microsoft Teams public preview program. They will need to configure an update policy in the Microsoft Teams admin center. However, keep in mind that meeting participants will not be able to view zoom controls while using the watermarking feature during Teams meetings.

Microsoft Teams zoom controls available for desktop and web usersAs of this writing, the feature is only available in the Microsoft Teams app for Windows, macOS, and web app. It remains to be seen if Microsoft plans to add zoom controls to the Teams mobile clients.

In related news, Microsoft is getting ready to make the new Teams 2.0 client the default experience on Windows later this year. Last week, Microsoft Product Lead for Teams 2.0 Anupam Pattnaik confirmed in the first episode of Petri’s UnplugIT podcast that the app is also coming in preview to macOS, the web, and other platforms later this year.

Microsoft Teams 2.0 debuted in public preview on Windows back in March 2023. The app has been rebuilt from the ground up to improve performance and reduce power consumption on Windows devices.

The post Microsoft Teams Meetings Get New Zoom Controls to Improve Screen Sharing appeared first on Petri IT Knowledgebase.

View Details

Microsoft plans to redirect all users with unsupported browsers to the light version of the Outlook web app. The company has now started notifying IT admins that this change will begin rolling out to customers in Fall 2023.

Microsoft Outlook Lite is a version of the regular Outlook web app with faster performance for low-end devices on any network. The app provides basic email features compared to the standard version of Outlook. The Outlook Lite app lacks support for tasks and notes, an offline mode, multiple Exchange email accounts, inbox rules, retention policies, and other capabilities.

With this change, web users will legacy browsers will be automatically redirected to the Outlook Lite app. Microsoft explained that this change aims to align the Outlook web app with the minimum browser support requirements of Microsoft 365 web apps.

“This initial communication is to notify customers that starting in Fall 2023 (September 2023), users using unsupported bowsers will be redirect to the light version of Outlook on the web. This will align with the experience with other Microsoft 365 web applications,” Microsoft explained in a message on the Microsoft 365 Admin center.

Microsoft to roll out Outlook web app browser restriction in September 2023Microsoft notes that this change will impact customers who use unsupported web browsers, including Brave and Opera. The company warned that it could potentially cause disruptions for both small businesses and organizations. Microsoft recommends IT admins to upgrade their fleet of devices to a supported browser (like Microsoft Edge, Google Chrome, Mozilla Firefox, or Safari).

Alternatively, users who can’t switch to a supported browser can use Outlook for Windows or the Outlook mobile app. They can also use an email program that provides support for the POP or IMAP protocols.

Microsoft plans to begin rolling out this restriction to all targeted release tenants in September of this year. The company expects to complete the deployment process worldwide in November 2023. Let us know in the comments below if you’re using unsupported browsers in your organizations.

The post Microsoft to Block Outlook Web App on Unsupported Browsers in Fall 2023 appeared first on Petri IT Knowledgebase.

View Details

As an IT Pro, it is crucial to your organization to make sure that your users receive legitimate emails. Sometimes, Exchange Online Protection (EOP) can flag these emails as spam. Safely creating whitelists for specific domains/email addresses allows you to efficiently manage email flow in your organization and protect your users from malicious activity. In this guide, I will show you how to whitelist a domain in Office 365 using a mail flow rule, the Microsoft 365 Defender portal, and PowerShell.

Why you may need to whitelist a domain in Office 365? A typical scenario encountered by IT pros managing Exchange Online is to have users complain that important emails are “hiding” in their ‘Junk Email’ folder in Outlook. There are two main reasons why this can occur:

  1. Users have configured Outlook’s Junk Mail Options feature and added the sender’s email address or entire domain to the Blocked Senders tab.
  2. The Exchange Online Protection (EOP) feature that comes with the Exchange Online service has flagged the email as spam using Microsoft’s score-based algorithm. You can determine this by doing a Message Trace in the Exchange Admin Center. The log entry will show the final status as ‘FilteredAsSpam.’

The first reason is specifically tied to the Outlook desktop application. The important point is that the feature only works when Outlook is open.

I will be covering the second reason here in this post. Before the email ever gets to the user’s mailbox, the protection service acts on the email. It puts it directly in the ‘Junk Email’ folder, so the email is never delivered to the user’s Inbox folder. So, in terms of email flow, this occurs before the email enters Outlook.

In order to avoid these legitimate emails being delivered to ‘Junk Email’ folders, we can create a whitelist rule or change in the Microsoft 365 service. However, you must be careful to choose the best and most secure method. In some cases, configuration changes will open the door to spammers and malicious actors to exploit the settings you modify. I will go through the security aspect of each method below.

Should users create their own whitelists?Well, not really. The main reason I say that is because it’s not nearly as effective. As I said earlier, when users create whitelists, they’re setting up what’s called client-side rules. This means that the Outlook desktop application itself is processing the user’s Inbox only when it’s open and running. If there happens to be an issue with Outlook, this processing will not occur.

The advantage of using the methods in this post is that they create server-side rules. That means that they process before any emails enter a user’s mailbox, period. It’s simply safer that way. And, more efficient – it simply happens automatically behind the scenes.

How to whitelist a domain in Office 365 using a mail flow ruleArguably, the most secure method of allowing an email address or domain to bypass spam filtering is to create a Mail Flow Rule in Exchange Online. However, there are very important settings you need to understand.

  • First, navigate to the Exchange Admin Center.
  • On the left, expand Mail flow, then click on Rules.

The Exchange Admin Center is where we’ll create our mail flow rule (Image credit: Petri/Michael Reinders) Click the + Add a rule button and choose Bypass spam filtering*.

Setting up the rule conditions (Image credit: Petri/Michael Reinders) Write a brief description in the ‘Name‘ field. * For the ‘Apply this rule if‘ field, choose ‘The sender.’ Next to that, choose ‘domain is‘ from the dropdown menu. A new screen will open up. * In the ‘specify domain‘ field, enter the domain name and click Add, then click Save*.

Adding our email domain name (Image credit: Petri/Michael Reinders) Next, click the + button to add another condition. Choose ‘The message headers…‘, then ‘includes any of these words’, and type in ‘dmarc=pass‘. The rest should be good! * The ‘Set rule settings’ screen should be fine. You can make adjustments as you see fit. Click Next*.

The Set rule settings page (Image credit: Petri/Michael Reinders) On the Review and finish screen, click Done*.

Our email transport rule is created! (Image credit: Petri/Michael Reinders)That’s all there is to it. Here’s the crucial part – adding the check in the message headers for a passing grade for DMARC and authentication! If you don’t put those checks in, the rule opens a relatively large hole for hackers to exploit it. Potential attackers can send malicious emails to your organization by spoofing that domain, bypassing your critical security checks and balances.

How to whitelist a domain in Office 365 using Microsoft 365 DefenderAnother relatively safe method to whitelist a domain in Office 365 is to use Microsoft 365 Defender. Here, we’ll update the default anti-spam inbound policy.

  • To get there, open the Microsoft 365 Defender portal.
  • Browse to Email & collaboration -> Policies & rules -> Threat policies -> Anti-spam policies.

The Anti-spam policies section is where we will modify our default policy (Image credit: Petri/Michael Reinders) Click on the Anti-spam inbound policy (Default) item. This will allow you to make changes. * Scroll all the way down to the ‘Allowed and blocked senders and domain‘ section and click the link titled Edit allowed and blocked senders and domains*.

At the bottom of the policy is where we add our email domain (Image credit: Petri/Michael Reinders) Here, you will find the policy graciously offers some helpful granularity. It allows you to enter an email address or domain to allow (options 1 and 2), as well as an email address or domain to block (options 3 and 4). Let’s choose Allow domains*.

We’ll click ‘Allow domains’ to add our domain (Image credit: Petri/Michael Reinders) Here, I will click on the ‘+ Add domains‘ button, then I’ll enter the domain in the ‘Domain‘ field and click Add domains* at the bottom.

We use the Manage allowed domains window to add our domain (Image credit: Petri/Michael Reinders) Then, I’ll click Done again at the bottom. Finally, click Save. * We can now see there is one domain added to the Allowed domains* section of the policy!

We now have one domain added (Image credit: Petri/Michael Reinders)How to whitelist a domain in Office 365 by IP addressGranularity strikes again! We are also able to whitelist a connection by using its IP Address. When an email is inbound from the Internet and it routes through your tenant, Exchange Online (EXO) will check the IP Address of the sending SMTP server.

This is not commonly used and can sometimes be spoofed. However, there are business cases where this is the easiest way to always allow emails into your employee’s Inbox folders. Again, we’ll be using the Microsoft 365 Defender portal here.

  • Navigate to the same location – Email & collaboration -> Policies & rules -> Threat policies -> Anti-spam policies.
  • This time, click on Connection filter policy (Default).

This time we’re editing the ‘Connection filter policy (Default)’ (Image credit: Petri/Michael Reinders) Next, click the Edit connection filter policy link. * In the ‘Always allow messages from the following IP addresses or address range:‘ field, go ahead and type in either individual IP addresses or IP ranges using standard notation (152.4.45.179, 8.6.4.0/24, etc.) * Click Save*.

That’s all there is to it!

How to whitelist a domain in Office 365 using PowerShellI hope you didn’t think I would forget PowerShell! You’ll probably be amazed at how simple it is to make a similar change with one command.

Let’s go through the steps to add another email domain to the default anti-spam policy.

  • Once you’ve connected to Exchange Online, start by entering this command. This gives us the ‘Name’ of the policy we modified earlier -‘Default‘.

Get-HostedContentFilterPolicy Using Get-HostedContentFilterPolicy to see the name of our default policy (Image credit: Petri/Michael Reinders)* We can now use the associated ‘Set-‘ command to add another domain. Watch this.

Set-HostedContentFilterPolicy -Identity 'Default' -AllowedSenderDomains 'secondinvestments.com' With one command we can add another email domain to our policy (Image credit: Petri/Michael Reinders)Now, THAT was easy. Instead of browsing all around the GUI of the Microsoft 365 Defender website, you can run that simple command to whitelist a domain in Office 365.

You should only whitelist domains that you trustWhitelisting a domain in Office 365 is an excellent and effective way to ensure that specific emails are not filtered as spam. This can be useful if you receive emails from a specific domain that are frequently marked as spam. Once you have whitelisted a domain, this will no longer happen.

It is important to note that whitelisting a domain can also increase your risk of receiving spam. This is because spammers can often spoof the sender’s address, making it appear as if the email is coming from a legitimate domain. If you whitelist a domain that is being used to send spam, you may end up receiving more spam!

For this reason, it is important to only whitelist domains that you trust. You should also regularly review your whitelisted domains and remove any that are no longer needed.

Please feel free to leave a comment below – thank you for reading!

The post How to Whitelist a Domain in Office 365 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced some important changes coming to Server Message Block (SMB) signing on Windows 11 Enterprise edition. Starting with the latest Windows 11 Insider Canary Build, SMB signing is now required by default for all connections.

Server Message Block is a client-server communication protocol that allows users to share access to resources such as files, printers, and serial ports on a network or remote servers. Meanwhile, SMB signing is a security feature in Windows that adds a digital signature to authenticate communication between the client and server.

Microsoft explained that the SMB signing requirement changes should help to protect Windows 11 users against NTLM relay attacks. The SMB signing feature is designed to prevent threat actors from tempering SMB packets during data transmission.

“This changes legacy behavior, where Windows 10 and 11 required SMB signing by default only when connecting to shares named SYSVOL and NETLOGON and where Active Directory domain controllers required SMB signing when any client connected to them. This is part of a campaign to improve the security of Windows and Windows Server for the modern landscape,” explained Microsoft Principal Program Manager Ned Pyle.

Source: MicrosoftSMB signing requirement changes could impact performanceMicrosoft notes that the upcoming changes could potentially impact the performance of SMB copy operations on Windows 11 PCs. Users will be able to address the problem by buying a faster CPU or adding more CPU cores/virtual CPUs.

Additionally, Microsoft warned that users might encounter errors (such as 0xc000a000 and -1073700864) while connecting to a remote share on a third-party SMB server that lacks support for the SMB signing capability. The company recommends customers to configure the feature on the third-party SMB server.

IT Pros can disable SMB signing on Windows 11However, it will be up to the IT admins to turn off the SMB signing requirement in server and client connectors. To do this, they will need to run the following PowerShell commands:

  • Set-SmbClientConfiguration -RequireSecuritySignature $false
  • Set-SmbServerConfiguration -RequireSecuritySignature $false

Microsoft plans to roll out the new default change for SMB signing to Windows 11 Education, Pro, and other editions as well as Windows Server later this year. “Depending on how things go in Insiders, it will then start to appear in major releases,” Pyle added. You can find more details about the change on Microsoft’s support page.

The post Microsoft to Enable SMB Signing By Default to Boost Security on Windows 11 appeared first on Petri IT Knowledgebase.

View Details

MC566393 – Microsoft has released updates to the following update channel for Microsoft 365 Apps:

  • Current Channel

When this will happen:

Microsoft will be gradually rolling out this update of Microsoft 365 Apps to users on that update channel starting June 1st, 2023 (PST).

How this will affect your organization:

If your Microsoft 365 Apps clients are configured to automatically update from the Office Content Delivery Network (CDN), then no action is required.

If you manage updates directly you can now download this latest update and begin deployment.

What you need to do to prepare:

To get more details about this update view the following release notes:

  • Current Channel

Additional information

The post M365 Changelog: Updates available for Microsoft 365 Apps for Current Channel appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out a new search experience in preview to Microsoft Word, Excel, and PowerPoint for Mac. The new feature should make it easier for users to find information across multiple sources.

According to Microsoft, the revamped search experience offers smart search suggestions to help users improve productivity and save time. Users can also search for web results, commands, help articles, and commands.

Microsoft has also released some enhancements for people with low vision or blindness. These include better keyboard navigation within groups and VoiceOver support in Word, Excel, and PowerPoint for Mac.

How the new search experience works in Word, Excel, and PowerPoint for Mac Open a presentation, document, or worksheet. Click the Search box and select the search suggestions option. Now, type the phrase or keyword in the Search* box. * Users can also type the command name in the Search box to find it.

  • Click the Find in this document option to find specific information within the file.
  • Finally, users can click the Open Search pane to find web or media results in any document, presentation, or worksheet.

Additionally, Microsoft notes that Office users can access the improved search experience through keyboard shortcuts. Users can use them to open the search pane (Cmd + Ctrl + L), search dropdown (Cmd + Ctrl + U), and find content in the document (Cmd + F).

Enhanced search experience available for Office InsidersTo try out the new search experience, users will need to join the Office Insider program. This capability is available for testers in the Beta Channel running Version 16.74 (Build 23043001) or newer. The feature is also available for users who have installed Microsoft Office 2021 on their devices.

Last week, Microsoft announced the general availability of Outlook, Edge, Power Apps, and Viva Engage on shared devices. The feature is designed to let frontline workers securely access apps on all shared Android devices enrolled via Microsoft Intune.

The post Microsoft Starts Testing New Search Experience in Word, Excel, and PowerPoint for Mac appeared first on Petri IT Knowledgebase.

View Details

In this article, I will explain how to auto login Windows 10 to reach the desktop environment without having to enter a username and password. I’ll also outline the pros and cons associated with configuring auto login on this version of Windows.

What is auto login on Windows 10?Windows 10 provides robust security features to help users to protect their personal data, including the protection of user accounts by passwords. It’s generally not recommended to remove a password for a Windows device that is being used by an individual. However, configuring Windows to provide a passwordless experience could be appropriate in specialized cases, such as kiosk PCs with multiple users.

Windows auto login is a feature that automatically signs a user into a Windows 10 PC without entering a username and password. It enables users to bypass the login screen and directly access the specified user’s desktop.

What are the advantages of setting up Windows 10 auto login?There are a few reasons you may want to set up the auto login on Windows 10. Let’s have a quick overview of some of the main benefits of this feature, though keep in mind that auto login should be used with caution.

User convenienceAuto login eliminates the need to manually enter credentials to log in to a user account during system startup on Windows 10. The feature could be particularly useful for users who don’t share their PC with anyone else. Bear in mind that unless you can guarantee the physical security of the device, enabling auto login could put your account and data at risk.

Streamlined boot processThe auto login feature allows users to start up and reach their Windows desktops more quickly. This can be useful if you don’t want to be bothered after your PC restarted to install system updates.

Task automationWith auto login, it’s possible to automate specific processes and tasks that require the computer system to be logged in. The feature helps to ensure that scripts or programs run at startup without any user intervention.

AccessibilityAuto login provides an efficient and seamless user experience for people with physical disabilities. It lets them get quick access to Windows 10 without requiring assistance from others during the login process.

How to enable auto login on Windows 10There are a couple of ways to configure auto login on Windows 10. The first method is suitable for those using Windows 10 in a small office setup or at home. The second method I’ll be detailing is recommended for domain-joined Windows 10 devices. In large business environments, user credentials are centrally stored in Active Directory and managed by the IT department.

Method 1: Configure User Accounts settings First, log in to the local Administrator account. Open the Run command box by pressing the Windows key + R. * Type netplwiz in the Open field and click the OK* button. Netpwliz is a built-in utility tool for managing user accounts

Opening the Netpwliz utility tool (Image credit: Petri/Rabia Noureen) Select the Users tab and uncheck the Users must enter a user name and password to use this computer box. Click OK* at the bottom of the window.

(Image credit: Petri/Rabia Noureen) In the pop up window, enter the user name and password to disable password protection. * Finally, click the OK* button and restart the device.

Last step for disabling password protection (Image credit: Petri/Rabia Noureen)That’s it, users will now be able to sign in on this PC without having to enter a username and password.

Method 2: Configure auto login for computers connected to a domainThe process to enable auto login is slightly different on domain-joined computers due to additional security measures and policies enforced by the domain.

  • Press the Windows + R keys to open the Run dialog box, then type regedit and click OK to open the Registry Editor:

Opening the Registry Editor (Image credit: Petri/Rabia Noureen) In the Registry Editor, navigate to the following path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon * Select Winlogon, and then locate the AutoAdminLogon registry value in the right pane. * Double-click AutoAdminLogon, then change the value data from 0 to 1 and click OK*.

Confirming the registry change (Image credit: Petri/Rabia Noureen) If the AutoAdminLogon value isn’t available, users may need to create it manually. To do this, click Edit >> New >> String Value. Enter AutoAdminLogon in the Value name and type 1 in the Value data field. Click OK* when you’re done.

Lastly, you’ll need to reboot the Windows 10 PC after performing this registry change. Now, you’ll need to follow the steps outlined in method 1 to allow users to sign in on this PC without having to enter a username and password.

Is it safe to auto login Windows 10 devices?Keep in mind that while auto login provides various time-saving benefits, it’s important to consider all the security and usability implications. With auto login configured, anyone with physical access to the computer can access sensitive data stored on it, or install malware. In general, it’s highly recommended to not configure auto login on Windows PCs devices that are often used away from a home or office.

Moreover, keep in mind that auto login makes switching between multiple accounts a more cumbersome process. Users will need to log out and then manually log in to the other account on that device.

Overall, the auto login feature provides a seamless user experience and helps to save some extra time and effort. However, it’s recommended that users should carefully evaluate their specific usage of the device, the level of required security, and the sensitivity of data stored on the PC before implementing it.

The post How to Enable Auto Login on Windows 10 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of Conditional Access authentication strength policies for Azure Active Directory (Azure AD). The new feature allows IT admins to choose which multifactor authentication (MFA) methods can be used while accessing network resources.

Multifactor authentication (MFA) is a security feature that allows customers to use two or more methods of verification to prove their identity and gain access to a system. It helps to protect users against cyberattacks such as password guessing and credential theft.

How Conditional Access authentication strength feature works?Azure Active Directory Conditional Access feature already lets organizations enforce specific access controls based on predefined conditions to protect data and resources. The Authentication Strength feature provides an additional level of protection by allowing IT Pros to mention the type of MFA methods that should be used.

“With Conditional Access authentication strength, administrators can define a minimum level of authentication strength required for access, based on factors such as the user’s sign-in risk level or the sensitivity of the resource being accessed. This can be especially useful for organizations that operate in highly regulated industries or have strict compliance requirements,” Microsoft explained.

Microsoft notes that customers can choose between three built-in Authentication Strength methods such as Temporary Access Pass or password. They can also choose to set up custom authentication strength policies based on specific needs.

  • MFA strength: It’s the set of combinations (like Microsoft Authenticator and Certificate-based authentication) that could be used to meet the “Require multifactor authentication” setting.
  • Passwordless MFA strength: It supports authentication techniques that don’t require a password but satisfy the MFA requirements.
  • Phishing-resistant MFA strength: It’s a set of techniques that require communication between the sign-in surface and the authentication method. For example, the FIDO2 security key and Windows Hello for Business.

Conditional Access authentication strength requirementsThe authentication strength feature could help organizations to address various scenarios. For instance, a user needs to access an application or take sensitive action within the app. Moreover, IT admins can configure the feature to let guest users securely access the resource tenant.

Microsoft notes that IT admins will have to purchase an Azure AD Premium P1 license to use Conditional Access within their organization. Customers will also need to configure combined MFA and SSPR registration. This capability is already in place for all Azure AD tenants created before August 15th, 2020.

The post Microsoft’s New Authentication Strength Feature Provides More Control Over CA Policies appeared first on Petri IT Knowledgebase.

View Details

As a true Power Platform guy, I watched the breaking headlines from Microsoft Build 2023 last month and came away with 2 words to caption the bulk of it: Copilot Everywhere! Microsoft’s powerful AI service is making its way into various Power Platform and Microsoft 365 products. Imagine having an intelligent assistant at your fingertips that integrates with the tools you’ve grown comfortable using and the data that drives your company? That’s what Microsoft is trying to achieve with its various Copilot announcements.

Copilot integration with Power Platform products The new Copilot for Power Pages is designed to assist with copy-editing and text and layout generation using natural language prompts. You’ll even be able to embed a Power Virtual Agent (PVA) chatbot into your Power Pages that uses natural language models to have a more free-flowing conversation with your site visitors. What is truly amazing about Copilot’s integration into our favorite and even lesser-used products is that it can take your prompt and help you to build the solution you want, even if you don’t necessarily have the time or know-how to build it yourself.

The Microsoft 365 Copilot, which is currently available in private preview, will be able to sit over all your data, and then you will interact with it just like prompting ChatGPT or Bing Chat. However, there’s a distinction here I don’t want you to miss: We’re traditionally trained to think of these AI assistants as natural-language search engines. It used to be that you would type in a keyword to a search engine, and it would bring up the top matching websites or documents.

However, as AI assistants have begun popping up, there’s more to them than just keyword searches, because the AI understands the data around the matches it comes up with. And on top of that, it isn’t just parsing through documents and files looking for matching metadata: It can crawl through your data tables and understand more about your data, then take relevant action based on that data. This is what revolutionizes the platform.

Along with the Copilot integration into Power Automate, Power Automate’s flow design studio is finally getting a facelift. Obviously, the Copilot stuff is great. Being able to describe in natural language what I want my flow to do, and then let Copilot do the heavy lifting in assembling the pieces to make that happen is exactly what I wanted an AI assistant in Power Automate to do. But in addition to that, the larger Expression editor brought a tear to my eye.

If there’s a jaw-dropping feature to top all jaw-dropping features in these announcements, Copilot for PVA chatbots just might be the one. Not only do I love the idea of using a natural language prompt to help me build my chatbot, but that chatbot being automatically powered by the new language models and being able to interact with both my customers and my company data has me blown away by just how simple yet effective it is.

Copilot in Power Virtual Agents (image credit: Microsoft)New Power Apps Homescreen, starting templates, and start from ExcelThe Power Apps home screen got a facelift as part of Microsoft’s Build 2023 announcements. This new home screen is designed to make getting started with Power Apps easier for everyone. It does so by breaking out the home screen into 3 starting points, “Start with Data”, “Start with Page Design”, and “Start with app template”.

The standout feature under the “Start with Data” section is the innovative “Upload an Excel file” option. With a few clicks, you can transform your static Excel data into a dynamic Power App. The process is as straightforward as it is ingenious.

Once you’ve selected your Excel file to upload, the system retrieves the data and presents a preview of a Dataverse table based on the information from your spreadsheet. This step gives you a visual representation of how your data will be structured and allows for adjustments to ensure it fits your needs perfectly.

After any necessary modifications, hitting “Create App” brings your data to life. The system generates a Dataverse table from your data, seamlessly importing all your Excel information into this table. But the magic doesn’t stop there.

In the next stage, a responsive Power App is built automatically to work harmoniously with your newly created Dataverse table. This entire process, from Excel upload to app creation, happens in a blink – mere seconds. The result is a robust, personalized application, ready for you to explore and utilize.

This new feature epitomizes the spirit of Power Apps: transforming data handling from a mundane task into an exciting journey of discovery and innovation. If you want a walkthrough of how to use the new Excel feature, you can check out my demo video.

Custom Dataverse plugins When you’ve got complex operations that you need to automate, you’re probably accustomed to going to Power Automate for a flow or even putting custom code into an Azure Function. However, with custom Dataverse plugins, you can write out these operations using PowerFX, the same code base powering your Power Apps and Virtual Agents, and keep it all within the Dataverse platform.

The power of these plugins isn’t relegated to those super nerdy cases, though. Remember how Microsoft really wants us to stop putting hundreds of lines of variables and collection initializations in our App OnStart property? Guess what, custom Dataverse plugins make for a very powerful alternative, allowing you to offload all that data to the server and really streamline your app loading process.

A new era of AI assistance and collaborationThere is so much that Microsoft announced at Build for us Power Platform fans to get excited about. Copilot is a major piece, but it isn’t the only one. I’ve highlighted just a few of my favorite announcements in this article.

One thing that I kept thinking through all of them is that we’re witnessing a new era of AI assistance and collaboration. With Copilot seamlessly integrated into various Power Platform products, users are empowered to unleash their creativity and achieve their desired outcomes, even without extensive technical expertise.

The post What’s New With Microsoft’s Power Platform – May 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has discovered a new macOS vulnerability dubbed Migraine. The company detailed in its security advisory that the flaw allows attackers to bypass System Integrity Protection (SIP) and perform malicious operations on macOS machines.

Apple first launched System Integrity Protection (SIP) in macOS Yosemite back in 2014. The feature is designed to prevent threat actors from making any changes to important system files and folders on Mac devices. System Integrity Protection (SIP) helps users to block unwanted modifications that could impact the system’s stability and security.

According to Microsoft, the “Migraine” security vulnerability (CVE-2023-32369) exploits the Migration Assistant app that lets users transfer files from Windows to macOS. Microsoft’s researchers used an Apple script that caused the tool to import a malicious Time Machine backup and infect the host system.

“By focusing on system processes that are signed by Apple and have the com.apple.rootless.install.heritable entitlement, we found two child processes that could be tampered with to gain arbitrary code execution in a security context that bypasses SIP checks,” the Microsoft Threat Intelligence team explained.

Apple releases patches to fix the Migraine vulnerability on macOSMicrosoft warned that the security flaw could be used to gain physical access to sensitive data, computer accessories, and devices. The technique shares similarities with the method employed in 2021 to exploit the Shrootless vulnerability. Microsoft disclosed the vulnerability to Apple, which released a security update to mitigate it on May 18.

Microsoft emphasized that organizations should use security tools (such as Microsoft Defender for Endpoint) to monitor malicious activities. Additionally, Microsoft Defender Vulnerability Management helps to quickly detect and fix critical vulnerabilities. Microsoft also recommends that security teams should collaborate with vendors to prioritize security patching.

The post Microsoft Discloses New ‘Migraine’ Flaw ByPasses Built-In Protections on macOS appeared first on Petri IT Knowledgebase.

View Details

Microsoft has detailed all the improvements made to its Teams collaboration service in May 2023. The major highlights include a new active speaker view, 3D avatars, offline meetings, as well as management and security features. Here’s a look at everything you need to know.

Active speaker view for Microsoft Teams meetingsMicrosoft Teams has introduced a new Speaker View for both desktop and web users. The feature enables participants to easily track active speakers during Teams meetings. The meeting stage will prominently display the active speaker and shared content at the center, while the remaining participants will be shown at the top. Speaker View could be particularly useful for training sessions, town hall meetings, and lectures.

Last week, Microsoft released a new avatars feature in the Teams desktop client for Windows and macOS. The feature is only available for organizations with Microsoft 365 Business and Enterprise licenses. Microsoft Teams is also getting a new meeting recap experience that lets attendees view shared content, meeting notes, and transcripts. Other features include organizer support for Breakout Rooms on VDI and control for profanity filters in Live Captions.

Expanded view for profile cardMicrosoft released some enhancements to improve the profile card in Microsoft Teams. Just like Microsoft Outlook, the feature allows users to view contact details, organizational chart, LinkedIn tab, birthday, and other relevant information. It’s now possible for Microsoft Teams users to schedule offline (in-person) meetings, including lunch breaks and personal appointments.

Additionally, Microsoft Teams added a new Files experience that lets users search content shared in chats, channels, and meetings. The new app makes it easier for meeting attendees to discover and locate files without switching between Microsoft 365 apps. Moreover, Microsoft Teams users will see a new Notes tab while creating a new standard channel.

Updates coming to Microsoft Teams Rooms and devicesMicrosoft detailed a few new features and enhancements for Teams Rooms devices. First, IT admins can manage automatic firmware updates for Android devices via the Teams Admin Center. Furthermore, administrators can choose to pre-configure meeting layout controls for Teams Rooms on Android.

Microsoft also highlighted some new devices certified for Microsoft Teams Rooms. These include Yealink MCore Pro Kit, Shure Microflex Advance MXA902, Jabra Evolve2 30 and 40 Stereo headsets, and New Epos wireless headsets.

Microsoft adds new management and security featuresLast but not least, Microsoft released a couple of new management features for IT admins. They can configure a new setting that prevents anonymous users from accessing meeting chat via the Teams Admin Center or PowerShell. Microsoft introduced a new widget that lets IT Pros quickly view unspent Microsoft Azure consumption commitment (MACC) in the Teams Admin Center.

The post Microsoft Teams Adds Active Speaker View, 3D Avatars, and Other New Features appeared first on Petri IT Knowledgebase.

View Details

Last month was packed with Windows announcements as Windows 11 did get a lot of stage time during Microsoft’s annual Build developer conference. With Windows Copilot, Microsoft will integrate a new AI assistant into the OS, and Windows Insiders will get to test it first later this month.

The software giant also made various announcements for Windows developers including Dev Home, a new developer-focused experience that’s now available in preview. The company also detailed what to expect from the upcoming “Moment 3” update for Windows 11 that’s coming in June.

May 2023 Patch Tuesday added a new Windows Update toggleLast month’s Patch Tuesday update for Windows 11 version 22H2 introduced a new toggle in Windows Update that lets users get the latest non-security updates, fixes, and improvements as soon as they roll out. This toggle is disabled by default on managed devices.

Windows 11’s “Moment 3” update is coming soon Windows 11 is getting another “Moment” update this spring. The optional update for Windows 11 version 22H2 released on May 24 already includes some of the upcoming “Moment 3” features, such as support for Bluetooth Low Energy (LE) audio.

This month, Microsoft will start rolling out the rest of the “Moment 3” quality of life updates, and there’s quite a lot: Highlights include a new VPN status icon in the system tray, the option to display seconds in the system tray clock, new access key shortcuts in File Explorer, live kernel memory dump (LKD) collection in Task Manager, new presence sensor privacy settings, and a new limit of 20 most recent tabs in Alt + Tab and Snap Assist.

Phone Link for iOS is Now Available for All Windows 11 UsersMicrosoft announced on May 15 that Phone Link for iOS was now available for all Windows 11 users in 85 markets. iPhone owners can now use the Phone Link app to send and receive text messages, make and receive phone calls, and see contacts and iPhone notifications right from their Windows 11 PC.

Phone Link for iOS is now available for all Windows 11 users (image credit: Microsoft).Microsoft Gets Ready to Push Windows 10 Version 22H2 to All UsersWith Windows 10 version 21H2 reaching end of servicing this month, Microsoft announced last month that it will soon start pushing Windows 10 version 22H2 to consumers and non-managed business devices that are approaching end of servicing.

Windows driver and firmware updates are coming to IntuneIT pros will soon be able to manage Windows driver and firmware updates in Intune. This will allow admins to get more granular controls for optional drivers and firmware updates, access detailed reporting, and take advantage of an integration with Windows Autopatch.

Build 2023 announcementsWindows Copilot was one of the main announcements Microsoft made during its Build 2023 developer conference, but there was much more.

Windows Copilot for Windows 11 is Coming in JuneWindows 11 will be the first OS to get an AI-powered personal assistant that will integrate with Microsoft 365. Windows Copilot is expected to be much more capable than Cortana, and it will also be able to connect with third-party services using plugins. Microsoft said that the new Windows Copilot will be available for Insiders in preview on June 11.

New Dev Home app launches in previewDev Home is a new developer-focused app that’s now available in preview on Windows 11. The app streamlines the configuration of WinGet, GitHub, and other coding environments in the cloud using Microsoft Dev Box and GitHub Codespace.

The new Dev Home app (image credit: Microsoft)GitHub Copilot X integration into Windows TerminalWindows Terminal, Microsoft’s new command line tool now integrates with GitHub Copilot X. This allows developers to natural language to interact with an AI to recommend commands, explain errors, and more. Microsoft also announced that it’s planning to Microsoft is also planning to integrate its GitHub Copilot with other developer tools including WinDBG.

Native support for .rar and other archive formatsWindows 11 is getting native support for the rar, tar, 7-zip, gz, and other archive formats later this year. The company will be leveraging the libarchive open-source project to implement this functionality.

Windows on ARM updates for developersMicrosoft continues its push to make Windows on ARM a better platform for developers. Visual Studio 17.6 will soon add MAUI support for ARM-based devices. Moreover, the ARM version of Visual Studio 17.71 Preview 1 also added support for Linux development with C++.

Windows Insider updatesIf the new Windows Copilot won’t be available for Insiders until June 11, Microsoft started testing several new features with Canary, Dev, and Beta channel testers last month.

New Dev Drive and Windows Backup AppThe Windows 11 Insider build 23466 released on the Dev Channel on May 24 lets developers set up a new Dev Drive on an existing drive or a virtual hard disk. Dev Drive leverages Resilient File System (ReFS) technology to improve performance for developer workloads.

This build also introduced a new Windows Backup app that lets users back up their PC settings (pinned app preferences, Wi-Fi networks, and other passwords) to the cloud. These settings can be restored on a new Windows 11 PC running the Windows 11 build 23466 during the out-of-box experience.

The new Windows Backup app (Image credit: Microsoft)vTPM Support in Hyper-V for Windows on ARM VMsThe Windows 11 Insider build 25370 released for Canary Channel testers on May 22 also brought support for virtual TPM 2.0 chips in Hyper-V on Windows on ARM devices. As a result, Windows 10 on ARM virtual machines created with Hyper-V can now be upgraded to Windows 11.

That’s it for the biggest Windows updates announced throughout the month of May. Again, we should have a lot to write about this month with the first preview of Windows Copilot expected to be released for Insiders on June 11.

The post What’s New in Windows – May 2023 appeared first on Petri IT Knowledgebase.

View Details

MC564198 – The latest version of Teams Rooms on Windows app 4.17 update includes new in-meeting experiences including:

  • Breakout room support
  • Choose your Together Mode scene and select it for everyone

This message is associated with Microsoft 365 Roadmap ID 95680, 126105

When this will happen:
Microsoft will begin rolling out in mid-June and expect to complete rollout by late July.

How this will affect your organization:

Breakout room support:

Teams Rooms on Windows can participate in a breakout room and be moved in and out of the main meeting, depending on a meeting organizer’s control. Breakout room organization is not intended experience for Teams rooms and is not offered.

1) Join a breakout room

  • When an organizer turns ON the ‘Automatically move people to rooms’ setting, room users see the ‘We’ll move you to your assigned room in 10 seconds’ notification.
  • When an organizer turns OFF ‘Automatically move people to rooms’ setting

View image in new tab

View image in new tab

2) Return to the main meeting

  • When an organizer turns ON ‘Automatically move people to rooms’ setting, room users see the ‘We’ll move you back to the main meeting in 10 seconds’ notification.
  • When an organizer turns ON ‘Automatically move people to rooms’ setting:

View image in new tab

View image in new tab

Choose your Together Mode scene and select it for everyone:

  • Teams Rooms on Windows can now choose a Together Mode scene that fits your meeting type, using the view switcher on console.
  • When your Teams Rooms on Windows is an organizer or presenter, you can have all of the participants see the same scene by clicking the ‘Select for everyone’ checkbox and ‘Apply’ button.

View image in new tab

What you need to do to prepare:

Kindly notify your users about this new experience and update your training and documentation as appropriate.

The post M365 Changelog: Microsoft Teams – Breakout rooms support and Select Together Mode for everyone on Microsoft Teams Rooms on Windows appeared first on Petri IT Knowledgebase.

View Details

MC564197 – Adoption Score in the Microsoft 365 admin center will soon be enabled by default without the need to opt-in before first use. If you want to opt-out, you can still navigate to the Adoption Score dashboard and opt-out of the experience. Adoption Score continues to be backed by Microsoft’s commitment to user-level privacy.

When will this happen:

Adoption Score within the Microsoft admin center will be enabled by default ON for all worldwide tenants beginning June 28, 2023.

How will this affect my organization

For organizations that do not have Adoption Score enabled, Microsoft is providing the capability for organizations to manage preferences to opt-in or opt-out ahead of default enablement of Adoption Score through the Microsoft 365 Admin Center. For organizations that have already chosen to opt-in or opt-out of Adoption Score, there will be no change.

View image in new tab

View image in new tab

What you need to do to prepare:

Visit this page to learn how to opt-out of Adoption Score.

Learn more about Adoption Score here:

  • Adoption Score Supporting Documentation
  • Privacy Controls for Adoption Score
  • Adoption Score Overview Video

Additional informationHelp and supportBlog

The post M365 Changelog: Microsoft 365 admin center – Adoption Score Default On appeared first on Petri IT Knowledgebase.

View Details

MC564196 – Users can soon select a playlist to be displayed in the list webpart in the full-blown playlist view along with video playback.

This message is associated with Microsoft 365 Roadmap ID 124808

When this will happen:

Standard Release: Microsoft will begin rolling out in early June 2023 and expect to complete rollout by late June 2023.

How this will affect your organization:

  • Users will be able to select a playlist from the list picker while configuring the list webpart.
  • Users will be able to see the full-blown playlist view as the default view for playlists.

View image in new tab

What you need to do to prepare:

There is no action required at this time, this change will be enabled automatically.

The post M365 Changelog: Microsoft Stream – Playlist View in SharePoint List Webpart appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the general availability of cross-tenant synchronization for Azure Active Directory customers. The new feature allows IT admins to automate the creation of user accounts across tenants in their organization.

Microsoft launched the public preview of cross-tenant synchronization for Azure AD back in January. Cross-tenant synchronization helps to save the time and effort previously required to manage consent prompts and redemption process in Azure AD B2B collaboration.

“Cross-tenant synchronization automates creating, updating, and deleting B2B collaboration users. Users created with cross-tenant synchronization are able to access both Microsoft applications (such as Teams and SharePoint) and non-Microsoft applications (such as ServiceNow, Adobe, and many more), regardless of which tenant the apps are integrated with,” Microsoft explained.

Under the hood, the feature uses the Azure AD B2B functionality and provides integration with conditional access, cross-tenant access settings, and other security and governance capabilities. It lets IT admins limit access to content and resources to a specific group of users within the organization. This capability helps to reduce the likelihood of potential administrative errors and security threats.

License requirements for cross-tenant synchronizationAs of this writing, the cross-tenant synchronization feature is only available for commercial cloud customers. Microsoft says that it’s designed to improve intra-organization cross-tenant application access. However, the feature doesn’t support cross-cloud synchronization (such as public cloud to Azure Government).

Keep in mind that customers will need to purchase an Azure AD Premium P1 subscription to access cross-tenant synchronization as a source tenant. Microsoft has detailed three easy steps to configure the feature in Azure AD on this support page.

The post Microsoft Releases Cross-Tenant Synchronization for Seamless Azure AD B2B Collaboration appeared first on Petri IT Knowledgebase.

View Details

Amazon Web Services (AWS) has announced that Amazon Security Lake is hitting general availability this week. The new service enables organizations to create a specialized data lake to aggregate, normalize, and store security data.

Security teams often face difficulties in gathering scattered security data within an organization. This is primarily because identity providers, firewalls, and applications each maintain their own event data and logs. It’s time-consuming and costly to create processes to normalize data across multiple sources.

With Amazon Security Lake, customers can store, analyze, and understand the security data coming from both on-premises and cloud infrastructure. The service converts security data into the Open Cybersecurity Schema Framework (OCSF) standard. It should help security engineers quickly identify, investigate and respond to security incidents.

“Security Lake centralizes security data from Amazon Web Services (AWS) environments, software as a service (SaaS) providers, on-premises, and cloud sources into a purpose-built data lake that is stored in your AWS account. With Open Cybersecurity Schema Framework (OCSF) support, the service normalizes and combines security data from AWS and a broad range of security data sources,” Amazon Web Services explained.

What are the use cases of Amazon Security Lake?Amazon Security Lake is designed to help organizations improve their overall security posture. The service also helps to streamline the compliance monitoring and reporting process as well as unify security data management across hybrid environments.

Additionally, Amazon Security Lake aggregates data from different AWS services, like GuardDuty, CloudTrail, AWS Firewall Manager, AWS Security Hub, and Lambda. The service also integrates with various third-party solutions, including SentinelOne, Splunk, Cribl, Aqua Security, Claroty, and Confluent.

Amazon Security Lake expands support for third-party integrationsAWS has introduced support for the latest version of OCSF in Amazon Security Lake. The service normalizes CloudTrail management events into the Authentication, Account Change, and API Activity OCSF event classes. The company has also updated resource names and schema mapping to improve the usability of log data.

If you’re interested, you can sign up for a 15-day free trial to test the Amazon Security Lake solution. The service is currently available for customers in several AWS Regions located in the US, Asia Pacific, Europe, and South America.

The post Amazon Security Lake is Now Generally Available appeared first on Petri IT Knowledgebase.

View Details

As an IT admin, preventing your users from using simple or known-hacked passwords has become critical for the overall security of your enterprise. An excellent step to take is to plan for and deploy Azure AD Password Protection. In this article, I’ll walk you through installing the Proxy service and DC agent in your on-premises Active Directory, then register them with your Azure Active Directory tenant.

What is Azure AD Password Protection?More often than you want to admit, users in your organization often create passwords using common local words like a birthday, a child’s name, a school, or even a famous person. Because these passwords are easy to guess, they open up your enterprise to hackers and major security risks.

To enforce strong and complex passwords in your environment, Azure AD Password Protection provides a global and automatically downloaded banned password list. A local password change request will fail if a user attempts to use a banned password from the file.

The first steps to implement Azure AD Password Protection include installing the proxy service and domain controller (DC) agent software on a few of your on-premises servers. Then you register these with your Azure Active Directory tenant.

There are two modes that the solution runs in, Audit mode and Enforce mode:

  • Audit mode is used to monitor and log infractions from your users changing their passwords.
  • After you pilot the software for a while, you can switch to Enforce mode which will block users from changing their passwords with a banned password.

Azure AD Password Protection licensingIs Azure AD Password Protection free? Well, that depends. The two downloads you’ll use (the proxy service and DC agent I mentioned above) are no-cost. The only potential cost is listed in the table below.

If your environment is running on hybrid mode with both Active Directory and Azure AD, you will need either Azure AD Premium P1 or P2 licenses for your users. If you happen to have ‘cloud-only’ users and only wish to use the global banned password list, then there will be no costs for your organization.

Here is a small table that details what specific features require Azure AD Premium license plans.

| Users | Azure AD Password Protection with global banned password list | Azure AD Password Protection with custom banned password list | | --- | --- | --- | | Cloud-only users | Azure AD Free | Azure AD Premium P1 or P2 | | Users synchronized from on-premises AD DS | Azure AD Premium P1 or P2 | Azure AD Premium P1 or P2 |

Licensing details of Azure AD Password ProtectionHow are passwords evaluated with Azure AD Password Protection?If you look at the architectural diagram provided by Microsoft below, you get an idea of how the tool works.

  1. A user initiates a password change.
  2. The DC agent on one of your domain controllers processes the password filter DLL and sends the request to the proxy service on one of your domain member servers.
  3. The DC agent service processes them by using the current password policy and returns a result of pass or fail.

The architecture of Azure AD Password Protection (Image credit: Microsoft)Global banned password listAzure AD Password Protection includes a global banned password list. The content of this list isn’t publicly available, but it’s based on the ongoing results of Azure AD security telemetry and analysis of user passwords utilized in Azure AD.

When a user tries to change their password, the desired password will be checked against this list. This will happen automatically for every Azure AD customer.

Custom banned password listTo offer customers more flexibility on what passwords are allowed in your organization, Azure AD Password Protection also supports custom-banned password lists. These lists work alongside the global list mentioned above to enforce your enterprises’ specific requirements in terms of words that may resemble people, products, headquarter sites, etc.

Users will see an error like these when trying to use one of these custom-banned passwords:

  • Unfortunately, your password contains a word, phrase, or pattern that makes your password easily guessable. Please try again with a different password.
  • Unfortunately, you can’t use that password because it contains words or characters that have been blocked by your administrator. Please try again with a different password.

Password spray attacks and third-party compromised password listsAnother security threat addressed by Azure AD Password Protection is password spray attacks. The majority of password spray attacks submit only a handful of known insecure passwords against each of the accounts in an organization.

Azure AD Password Protection blocks all known weak passwords likely to be used in these password spray attacks. This is based on real-world security telemetry data from Azure AD to build the aforementioned global banned password list. Because third-party websites that contain millions of compromised passwords are geared towards brute-force methods of invasion, those techniques aren’t the best way to improve overall password strength.

What are the requirements for Azure AD Password Protection? Let’s take a look at the requirements for implementing Azure AD Password Protection. Then I’ll offer some guidance on how to deploy this solution, how many servers to use, how many DCs to install the agents on, and more.

Here are some general Windows Server software requirements from Microsoft to be aware of.

  • All machines, including domain controllers, that have Azure AD Password Protection components installed must have the Universal C Runtime installed.
  • You need an account that has Active Directory domain administrator privileges in the forest root domain to register the Windows Server Active Directory forest with Azure AD.
  • The Key Distribution Service must be enabled on all DCs in the domain that runs Windows Server 2012 and later versions. This service is enabled via a manual trigger start by default
  • Network connectivity must exist between at least one domain controller in each domain and at least one server that hosts the proxy service for Azure AD Password Protection. This connectivity must allow the domain controller to access RPC endpoint mapper port 135 and the RPC server port on the proxy service.
  • All machines where the Azure AD Password Protection Proxy service will be installed must have network access to https://login.microsoftonline.com for authentication requests and https://enterpriseregistration.windows.net for Azure AD Password Protection functionality.

There are other requirements for the Azure AD Password Protection DC agent and proxy service, and you can check out the support page on Microsoft Learn for more details.

How to implement Azure AD Password ProtectionNow that we have all the requirements fresh in your mind, let’s start with the installation steps. We’ll begin with the proxy service.

Deploying the Azure AD Password Protection proxy serviceThis first install step will typically require at least two member servers in your Active Directory domain. These servers will communicate with Azure AD to maintain a copy of the global and custom banned password lists for your Azure AD tenant.

Note: each server can only provide password policies for a single forest. The server must be joined to the domain. You will also need network connectivity between at least one DC in each domain of the forest and one password protection proxy server.

To install the proxy service, we will first download the software from the Microsoft Download Center.

Here is my Downloads folder on one of my member servers (WS22-FS02).

Downloads folder showing the two downloads for AAD Password Protection (Image credit: Petri/Michael Reinders)Let’s double-click on AzureADPasswordProtectionProxySetup.exe. We will check the license terms checkbox and click Install.

Installing the Azure AD Password Protection Proxy Bundle (Image credit: Petri/Michael Reinders)And we’re done!

That was easy! Setup is complete (Image credit: Petri/Michael Reinders)We now turn to PowerShell to finish the setup. Let’s first import the new module that was just installed with the Import-Module command. Then, we will run the Get-Service command to confirm that the service is running.

Import-Module AzureADPasswordProtectionGet-Service AzureADPasswordProtectionProxy | fl Using PowerShell to import the modules (Image credit: Petri/Michael Reinders)Next, we need to register the idle proxy with our Azure AD tenant. You will need a Global Administrator account to provision your first proxy service in your tenant. Although various authentication methods are available, let’s go with the most common and do it interactively.

Register-AzureADPasswordProtectionProxy -AccountUpn 'mdreinders@x3v6p.onmicrosoft.com' Registering the proxy in Azure (Image credit: Petri/Michael Reinders)No news is definitely good news. Let’s run a test command and verify the config worked.

Test-AzureADPasswordProtectionProxyHealth -Testall Confirming the prior command registered successfully (Image credit: Petri/Michael Reinders)Yes! Looking good so far. Next, we register our on-premises AD forest with the appropriate credentials to communicate with Azure. You will need to use an account with either Global Administrator or Security Administrator rights, Enterprise Administrator AD rights, and an account with local administrator permissions. Yikes.

Register-AzureADPasswordProtectionForest -AccountUpn mdreinders@x3v6p.onmicrosoft.com Doing final checks for all initial configurations (Image credit: Petri/Michael Reinders)Again, we’re solid. Let’s move on to the DC agent!

Deploying the Azure AD Password Protection DC agentIf that seemed like a lot of steps, don’t worry. There’s literally a single step for installing the Azure AD Password Protection DC agent.

From the earlier download location, you just need to install the .MSI file and that’s it! I’ve logged into one of my DCs (WS16-DC2) and am double-clicking on the AzureADPasswordProtectionDCAgentSetup.msi file.

Installing the AAD DC agent software (Image credit: Petri/Michael Reinders)Let’s check the license agreement box and click Install.

It worked! Setup complete (Image credit: Petri/Michael Reinders)That’s all there is to it! Oh, and a reboot.

Confirming the service is installed and running (Image credit: Petri/Michael Reinders)Looks like we’re 5 by 5 (Aliens reference, thank you very much…).

Enabling on-premises Azure AD Password Protection (in Azure)There is one final step. We need to enable this feature in the Azure Active Directory administrative center.

The Azure Portal website (Image credit: Petri/Michael Reinders)On the left navigation, first, click Security -> Authentication methods -> Password protection.

Password Protection features in Azure AD (Image credit: Petri/Michael Reinders)That’s interesting: Here, the Enable password protection on Windows Server Active Directory feature is already enabled and set to Yes. Plus, we are in Audit mode, meaning only banned password change events are logged. Users are NOT blocked… yet. When you switch to Enforce, users WILL be blocked when attempting to change their password from the list.

Using the Custom banned passwords list is as easy as setting that feature to Yes (Image credit: Petri/Michael Reinders)Enabling Azure AD Password Protection is worth itThis is a relatively easy-to-install solution that will help you control your users’ security. Implementing the custom banned password list will prevent your users from using common publicly known product names, headquarter sites, and even local sports team names from being used as passwords.

If you have any questions or comments, please leave them below, and thanks for reading!

The post How to Enable Azure AD Password Protection: A Step-by-Step Guide appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced yesterday that the AI-based intelligent recap feature is now generally available for Microsoft Teams Premium subscribers. Powered by OpenAI’s GPT-3.5 model, the feature provides an overview of the most important information discussed during Teams meetings.

In Microsoft Teams, the intelligent recap feature can automatically generate meeting notes, recommended tasks, and personalized highlights. Users will also see timeline markers to quickly catch up on what was shared or discussed in the meeting. The feature eliminates the need to switch between apps/screens to view AI-powered insights, including meeting recordings, transcripts, shared content, and more.

“With intelligent recap, you can focus on the meeting discussion itself and not on capturing notes. AI-generated notes allow users to see key points and takeaways after the meeting, automatically created and powered by GPT. And follow-up is easy with AI-generated tasks and action items automatically suggested for you,” Microsoft explained.

The intelligent recap feature also provides a full transcript that highlights the speaker’s contributions in a timeline of topics and chapters. Microsoft Teams users can access intelligent recaps in the new “Recap” tab available in the Teams chat and calendar. The feature respects the organization’s security, privacy, and compliance policies for Microsoft Teams.

Microsoft has also released some enhancements to improve the existing meeting recap experience for all Teams users. “The new meeting recap will also be available on the ‘Recap’ tab and will enable users to watch the meeting recording directly within Teams, as well as provide co-created collaborative meeting notes, meeting transcript, and content shared,” Microsoft added.

Intelligent recap for Microsoft Teams meetings to add support for more languagesOverall, the intelligent recap feature is a welcome addition to the Microsoft Teams Premium plan. It might encourage more businesses to switch to the new premium tier that costs $7 per user per month until June 30th, 2023.

Microsoft notes that most of the intelligent recap capabilities are available starting today. However, some other features are expected to arrive in the next few months. Currently, intelligent recap is only available for Premium subscribers in English, with support for more languages to follow later this year.

The post Microsoft Teams Premium Adds New AI-Powered Intelligent Recap Feature for Meetings appeared first on Petri IT Knowledgebase.

View Details

The new Microsoft Teams 2.0 client that Microsoft made available in public preview in late March will become the default app for Windows users later this year. Anupam Pattnaik, the Product Lead for Teams 2.0 detailed the company’s plans in the first episode of UnplugIT, our new IT pro podcast hosted by Microsoft veteran Stephen Rose.

Microsoft Teams 2.0 has been rebuilt from the ground up to make it 2x faster and consume fewer resources than the “classic” Teams desktop app. The new Teams 2.0 client leverages the same WebView2 technology that already powers the new Teams for Consumers client that made its debut with Windows 11 last year.

“Right now, the classic Teams is the default because we do not have all the features that we support in classic Teams in the new Teams,” Pattnaik explained. “That’s the reason we have right now classic Teams as the default option, but sometime later this calendar year, we’ll make the new Teams the default option when we have feature parity, and when we feel confident that users can switch to the new Teams.”

Pattnaik also confirmed that the new Teams 2.0 client will launch in preview on non-Windows platforms later this year. “We plan to make the preview of the new Teams available to our Mac, VDI, and web users later this calendar year. We also do plan to roll it out to our other customer segments like EDU, and Government Cloud later this calendar year,” the Product Lead for Teams said.

The new Teams 2.0 client will become the default experience later this yearWhat to expect from the new Microsoft Teams 2.0As of today, IT admins can opt in to test the new Teams client in their organizations. After joining the preview program, end users can switch between the new Teams and the classic app with a toggle switch.

The new Teams 2.0 already brings a slightly revamped UI and significant performance improvements. According to data from benchmarking company GigaOm, app launch and meeting joins are twice faster. The new client also brings multiple accounts support, and users can receive real-time notifications no matter which account is currently in use.

Pattnaik confirmed that Microsoft is still working on adding support for advanced meeting capabilities such as Breakout Rooms, which should be available in the new Teams client before the end of the year. “Our team is continuously working on making sure that those features are available as soon as possible so that it makes it easier for customers to basically adopt the new Teams platform,” the Product Lead said.

You can learn more details about what to expect from the new Teams 2.0 client in the first episode of our new UnplugIT podcast.

The post Microsoft Will Make Teams 2.0 the Default Client Later This Year appeared first on Petri IT Knowledgebase.

View Details

In this first episode, Stephen talks to Microsoft’s Anupam Pattnaik, Product Lead for Teams. In this inaugural show, Stephen and Anupam discuss how IT can control access to the new Teams experience for end users, when Teams 2.0 will become the default experience for everyone, when the new client will reach feature parity with classic Teams, and when Teams 2.0 will be available for other platforms, like MacOS and web. And more!

TranscriptStephen Rose

Hey everybody, I’m Stephen Rose, and thank you for joining this brand new show, Unplug IT here on Petri. We’re going to be sitting down, taking a look at what topics are important to IT Pros, digging into really what you need to know to be successful as you pilot, deploy, secure, manage, and drive adoption within your own organizations. One of the top products that’s out right now that so many of you are asking questions on is the new Teams or Teams. 2.0. So I thought there’s nobody better to answer those questions than my friend, Anupam Pattnaik. Hey, Anupam, how are you?

Anupam Pattnaik

I’m doing great, Stephen. How are you?

Stephen Rose

I’m good. You are the senior product marketing manager for Teams 2.0 at Microsoft, and take a moment, explain your role, and then we’ll dig in and start talking about the new product and what that means for folks.

Anupam Pattnaik

Sure. So, my name is Anupam Pattnaik and I’m actually driving the product marketing work for Teams desktop and mobile clients. And today, I want to take my time and speak to you about the exciting news we just announced on March 27th about the new Microsoft Teams. I’m excited to chat with you, Stephen, on that.

Stephen Rose

Awesome. So, the new Teams is something that our TAP (Technology Adoption Program) customers, and TAP is an internal private program at Microsoft that, you know, that their largest customers are invited to to start to play with. So, this is something they’ve had for a little while, they’ve been playing with it, giving feedback, and on March 27th, you turned that into a public preview. And what that means is if it was allowed, companies could turn it on and allow end users to see a button that says “Try the new Teams.” Is that that correct? Is that the understanding of what happened on the 27th?

Anupam Pattnaik

Yeah. So basically, late last year we actually announced the private preview of the new Microsoft Teams, so within the Technology Adoption Program, within the TAP program, the customers were able to privately preview the new Microsoft Teams late last year. Then on March 27th this year, we actually announced the public preview of the new Microsoft Teams. So, we basically made the preview version of the new Microsoft Teams available to the general public. So basically, with the March 27th announcement, the preview of new Teams is available to the commercial Windows users. It’s not yet available to our users on Mac, VDI, the web, and…

Stephen Rose

We’ll get into that. So now, with this, there’s now a button that shows up that says “Hey, try the new Teams.” What if an IT pro does not want their end users yet… They want to test it, they want to play with it, but they don’t want their end users yet because there is some functionality missing, we’ll talk about that. How do they… Can they turn that off? Is that something that they can wait on right now and not let people try just yet?

Anupam Pattnaik

Yeah, so with the public preview announcement on March 27, basically, there are two sets of audiences. One set of audience is our customers who are in the public preview program. We have a public preview program where around 1,000,000 users are there, and we have a targeted release program where around 15 to 20 million users are there. So, our customers that are in the public preview program and in the targeted release program, they are the end users who can directly see the toggle. These end users, without admins doing anything, they can see, they can try the new Teams. But for rest of our commercial Windows users that are not in targeted release or in the public preview program, the admins need to select users in their organization. So once the admins opt in, go select their users in their organization, then these end users can see the toggle and try the new Teams. Then, end users use the switch to experience the new Teams. And keep in mind there will be a coexistence of the new and classic Teams for quite some time. So, that’s basically the lay of the land, yeah.

Stephen Rose

OK. And of course, end users can always switch back to the previous version of Teams at any time, they can move back and forth. It’s literally a toggle and a bit of a reboot of the app, it takes a few seconds, but they can go back if there’s something they’re trying to do because there is some functionality that’s missing, like the ability to create a team, third-party apps, and things like that that will come, and we’ll talk about that. But some folks may find it’s still missing some things that keep them from being able to do. So, it’s very easy to move back and forth. Now, is there a time when there will be no choice, that toggle is going to be there for everybody, whether IT wants it there or not… Is that going to become an issue, or will they always have control over that?

Anupam Pattnaik

Yeah, so we want to make it a really smooth transition for our customers, because we want to make sure that we are enabling our customers’ success. So, sometime later this year, later this calendar year, we will make the new Teams to be the default Teams product. Right now, the classic Teams is the default because we do not have all the features that we support in classic Teams in the new Teams. That’s the reason we have right now classic Teams as the default option, but sometime later this calendar year, we’ll make the new Teams the default option when we have feature parity, and when we feel confident that users can switch to the new Teams. That’s the time when we’ll make the new Teams the default option, and that’s something we are planning to do later this calendar year. That’s the tentative timeline, yeah.

Stephen Rose

So, it won’t require a new rollout or new deployment, it will just naturally become Teams, it’s what it’s going to be? Not the new Teams, but the new Teams will just become Teams and that will be it, and IT pros will be good in doing that, correct?

Anupam Pattnaik

Yeah, so, unlike some of our other product transitions, for example, if you look at Skype for Business to Teams, that was like a very complex migration. But this one won’t be like that. So, this will be like, at a certain point later this calendar year and also this transition will go over next year as well. So, this will not be a complex migration process. This will be like all the users of classic Teams should be able to easily port all of their chats and everything, even custom apps, their apps that they have created onto the new Teams. They won’t need to manually migrate those custom apps. Once they’re in the new Teams, they will all be reappearing in the new Teams.

Stephen Rose

Got it. So, the new Teams is different from the core app. I know when I was working on OneDrive, that was really important that we rebuilt the app from the bottom up so that we got rid of the groove.exe client and a lot of that legacy code and really created something that was smart and fast, and it’s very much the same here. One of the biggest shifts was moving from Electron to Reactive. Now, what does that mean for folks that aren’t familiar with either of those platforms or what that means? What is the Reactive platform and what does that mean for, you know, for Teams?

Anupam Pattnaik

Yeah, so that’s a great question so thanks, Stephen. So, to give you some background, the classic client of Microsoft Teams, actually with the classic client, we actually used some open source software like Electron. We use Electron as the host, and we use AngularJS as the web development framework. So, along with these two, we also used a variety of custom controls. Those are like constructed using various web technologies like HTML and CSS. So, the reason we opted for these technologies like Electron and AngularJS with the classic Teams is because these choices actually enabled the rapid delivery of cross-platform web clients. Because we we support Microsoft Tems. on Windows, Mac, with various differences across platforms, these technology choices with classic Teams such as Electron and AngularJS helped us enable rapid delivery of the app.

But, as you know, the capabilities and innovation of Teams expanded significantly over time. And it actually placed a lot of strain on the devices’ resources. So, recognizing this change, we actually began analyzing the available technologies. We performed a few benchmarks internally, we built some prototypes, and that’s when we actually redefined the new architecture. And some of the key decisions that we have made during this transition was to transition from Electron and leveraging Web View 2 as the host. We also decided to transition from Angular to a React platform to build user interfaces. And as you know, the consumer version of Microsoft Teams, it already began this transition before. And obviously, it makes sense that we bring this next phase of technology with Web View 2 and the React platform to the commercial version, and that’s why we are calling it the new Microsoft Teams.

Stephen Rose

Right. It becomes more of a “code it once and that’s it” rather than coding for every platform. Now, the other thing about Reactive, and it’s important to remember that Teams is still built on top of SharePoint, and every time you create a new Teams space, you’re creating a SharePoint space etc., was that it was really slow and memory intensive. Logging into Teams and launching it the first time you do it just takes forever. If you have to switch tenants, it got better, but it still was slow. This is one of the biggest reasons for moving to Reactive, and I know you have a demo you want to show, so let’s have you, you know, let’s take a look at the demo and let’s talk about performance both in CPU, memory, etc. inside of Teams.

Anupam Pattnaik

Yeah, so the reason we decided to redesign the Teams app from the ground up and rearchitect the entire Teams app is because we wanted to… We heard it from our customers that the Teams app can be very resource- hungry, and we wanted to improve the speed as well as the performance of Teams.

At a high level, the new Microsoft Teams is up to 2x faster, and it can consume less than 50% computer resources compared to classic Teams. So, the reason we need a new Teams is that when we were rearchitecting, redesigning the Teams app, the North Star reason we set ourselves for was that the new Teams will be twice as fast as classic Teams, and it will consume less than 50% resources as classic Teams. And we plan to improve our performance of the new Teams throughout this calendar year. We did a performance benchmark with a third-party research vendor called Giga Ohm, and we were delighted to see the performance of the new Teams that we rolled out as part of our public preview announcement on March 27. So, the initial public preview build of the new Teams, that actually was very close to our performance goals. So, it was actually twice as fast. For example, starting from the Teams app installation to the launch of the app, as well as helping users to join meetings or switching chats was twice as fast compared to classic Teams. Also, in terms of resource consumption, the new Teams was consuming less than 50% memory, and also it was consuming less than 70% disk space compared to the classic Teams. And this is what we saw with our benchmarking project with a third-party research vendor called Giga Ohm.

Stephen Rose

Teams 2.0: faster, thinner, that’s great. Is there any functionality, though, that we’re going to lose? Because I know that when the new Teams came out, although it’s not feature complete, I couldn’t do things like present in Teams. And now I can and that functionality is rolling out, but is there any functionality that we’re going to lose altogether with the new Teams that we currently have today?

Anupam Pattnaik

So that’s a great question, Stephen. So, with the new Teams, there are certain features and capabilities that are actually going to be chased a bit. But we actually try to ensure that it’s a very smooth experience for the customers. So basically, what I’m trying to say is that with the new Teams, customers are going to achieve the goals that they were achieving with classic Teams, but certain things have changed.

For an example, I’ll give you a quick example here. With classic Teams, our customers can actually add a third party cloud storage service from the Files app in the classic Teams. So, by third-party cloud services, think of something like Box. But, with the new Teams, they can no longer see the “Add cloud storage” in the Files app on Teams’ left navigation bar, but they can still achieve the same objective, same goal. And how they can add a third party cloud storage now was changed.

So, with the new teams, what they can do is they can add third-party cloud storage apps such as Box directly from the Teams App Store. So, they can directly download the app from the Teams App Store versus adding it from the Files app in classic Teams. So, we have published some of those features that are changing from the classic to new Teams in our learn.microsoft.com pages. I’m happy to share the link with you so that users can go through that to see what are the experiences that are being changed in the new Teams.

Stephen Rose

Got it. So, we’re not losing any functionality, but some functionality in how we use it or how we access it may change, and there’s some new functionality that’s coming. One of the things that made me crazy and my Slack friend, Hyatt Horley, would constantly bang on my door about, is I hate the fact that I have to keep changing tenants and can’t get messages from other tenants without being in it, and that is making me a little crazy. And that’s something that is… I don’t want to say “fixed” because it was not really broken, it just worked differently, but we’ve made it work better. You know that Teams has made it work better in the new version, so let’s talk about multiple accounts support. And I know you have a video, but I want you to take a moment and tell us what we’re going to see, and then we’ll run the video to show some of the new functionality that’s part of that.

Anupam Pattnaik

Yeah, absolutely. So, we actually understand how challenging it is for our users to collaborate across organizations and to manage multiple work or school accounts. So, with the new Teams, we are actually offering a few new features such as multiple tenants and multiple accounts. So, with these two features, we are going to enable our users to collaborate more effectively across the organizational boundaries, which means that with the new Teams, the users can stay signed into multiple accounts, work and school simultaneously, and they can receive real time notifications no matter which one is currently in use. And also, they can seamlessly engage with users across multiple accounts and organizations without having to drop out of a call or a meeting. That really ensures that there is no disruption to their workflow. So, I would love to play a video to showcase that.

Stephen Rose

OK, good to know. Now on Mac, you know Microsoft released a M1 and M2 client, I believe it was last year. When will we see a new Teams for Mac? And then while I’m at it, let’s talk about VDI and even web. When will we see a new version for those platforms?

Anupam Pattnaik

Yeah, so basically, we will see the preview of the new Teams available for our Mac, VDI, and web customers sometime later this calendar year. So, similar to what we did with our March announcement, we made the preview of the new Teams available to our commercial Windows users. Similarly, we plan to make the preview of the new Teams available to our Mac, VDI, and web users later this calendar year. We also do plan to roll it out to our other customer segments like EDU, and Government cloud later this calendar year.

Stephen Rose

So, does that mean everybody can see it? What if I’m not seeing that functionality or not all of it? Does it mean it just hasn’t gotten to me yet? Or maybe I’m not in first release? So, I want to make sure people see that, that they can go do it, and if they can’t, understand what they need to do to be able to.

Anupam Pattnaik

Yeah, so when we announced the public preview of the new Microsoft Teams, some of the anchor features, those were missing in the public preview of the new Teams in March. When we’ll announce this, like third-party and LOB apps and certain advanced meeting capabilities like breakout rooms, those that are missing, our team is continuously working on making sure that those features are available as soon as possible so that it makes it easier for customers to basically adopt the new Teams platform. So, the good news is that we have been making really good progress, and we plan to support some of those features such as third party and LOB apps, as well as breakout rooms in the next few months, so we will definitely send out a message, send a post, or publish a blog whenever we make those big anchor features available in the app. So, I would say stay tuned for more updates, yeah.

Stephen Rose

So, maybe sometime this summer, before fall… maybe?

Anupam Pattnaik

Yeah. So, I would say that at this point like the next few months, but yeah, it could be available, yeah.

Stephen Rose

But you’re not going to release it obviously before it’s tested and working good and all that. But you know it it’s going to come and it will happen, and then we’ll see feature parity later this calendar year, maybe around Ignite time frame, maybe when we release the Mac version, etc. But the goal is before the end of the year that it will be on par.

So, great that the new Teams is faster, it’s using less RAM, it’s thinner, but are we losing anything? You know, my understanding is, you know, that some of the commands are going to be more streamlined. It’s going to be easier to add third-party apps, and even the way that you share and things like that are going to be simplified. So, is this the correct understanding that it’s going to be simplified and easier, that we’re not losing anything, but there may be easier ways to do the things that we’re already doing.

Anupam Pattnaik

Yeah, I agree. So, certain end-user experiences are being enhanced with the new Teams for a better experience. So, the goal behind the new teams is that we are simplifying the UX. So, our goal is that our end users could be able to achieve their goals in less number of clicks and the UX will be less complex than before. And one of those changes that I’m talking about, also, I’ll give you an example. For example, with classic Teams, our end users they can actually add a third-party cloud storage service such as Box from the Files app in the Teams left navigation bar on classic Teams. But that experience is changing with the new Teams. Our users will no longer see the option to add cloud storage in the Files app on the Teams left navigation bar. Instead, they can add the third-party cloud storage app directly from the Teams app store. So, this is just one example, there are some of these changes that will be coming to the new Teams with the goal that we’ll simplify the end-user experience, and we have published some of this information on our website.

Stephen Rose

Great, all right. And we’re showing a few of the slides showing off some of the new navigation stuff as well. That’s awesome. All right, so let’s wrap things up here. What do you want to say to the audience on why they should, if they’re not already playing with the new Teams, why they should turn it on today?

Anupam Pattnaik

Yeah, so that’s a great question. So, I would highly encourage our end users and admins of Teams to turn on and experience the new Teams. It’s twice as fast in terms of loading the app, switching chats. Also, it will it put less strain on your computer resources. For example, if you are video conferencing and you are trying to share your screen, it will push less drain on your memory and disk space and battery. So, I’m sure you are going to love the new Teams experience, and this will help you achieve more in less time and help you being more productive. And we would encourage you to be the first to preview the new Teams experience and share your thoughts with us. And as you said, there are certain features that are not available on the new Teams, but we will be adding those features and functionalities as they continue to be released. And we are excited to hear from you and help us shape the future of Teams!

Stephen Rose

Awesome.

Anupam Pattnaik

So, thank you for being such a valued user.

Stephen Rose

I know a lot of the UX like some of the sharing dialogue is much easier to take a look at and figure out. But you’re right, the key thing is if you have thoughts, things you like, don’t like, etc., now’s the time to share that. There are easy ways to share and to get that out. And again, we’ve talked about the different websites to go to where to learn more. So, that is great. And Anupam, I’d love to have you back on a little later on this year when we release more of this functionality and we’re on parity to talk about what’s next and how IT pros can prepare to switch over to the new version, if that’s good with you.

Anupam Pattnaik

Yeah, that sounds great. And we have a ton of work to do and like a long journey ahead of us and I’m happy to be back on your show. And we will have some exciting news to share, not only for our users on Windows, but also on Mac, VDI and Web, so yeah, excited to be back.

Stephen Rose

All right, that sounds great. All right, for petri.com and for Unplug IT, I want to thank all of you for joining me on this pilot, on this inaugural first show. And I look forward to seeing you all again in two weeks with my next show. We’ll see you soon, take care everybody, bye bye.

The post Unplugging What’s Next for Teams 2.0 appeared first on Petri IT Knowledgebase.

View Details

I’m delighted to announce that Stephen L Rose has joined Petri.com as Chief Technology Strategist. For those who don’t know Stephen, for fourteen years he led Microsoft deployment, adoption, and usage of Windows, Office, OneDrive, and Teams and Co-Pilot for IT professionals worldwide. And Stephen currently holds over 15 Microsoft and CompTIA technical certifications.

As part of his new role as Chief Technology Strategist at Petri, Stephen will be producing a new twice-monthly podcast, UnplugIT, where he will be interviewing a range of guests from across the industry, including leaders and decision makers at Microsoft and many of the clients that he’s worked with over the years.

Here’s more about the new Petri.com podcast:

UnplugIT! with host Stephen RoseUnplugIT! is an IT professional focused webcast hosted by IT influencer, 15-year Microsoft veteran, and Petri.com Chief Technology Strategist, Stephen Rose. Stephen focused on leading the efforts to help IT pros, technical decision makers, developers, understand the ins and outs of piloting, deploying, managing, securing, and driving adoption technologies like Windows, Office 365, OneDrive, Microsoft Teams, and other products.

His previous webcast, “Inside Microsoft Teams”, where he sat down with IT leaders from Lego, Polaris, Special Olympics, AEG, Kent State University, and more garnered over 2 million views in just over 18 months.

In these new webcasts, Stephen goes beyond just Teams and sits down with industry experts to explore the latest trends, best practices to help our audience understand first-hand, the do’s, don’ts, and gotchas to get the most out of your tech investments.

Unplugging What’s Next for Teams 2.0Check out the first episode, where Stephen talks to Microsoft’s Anupam Pattnaik, Product Lead for Teams. In this inaugural show, Stephen and Anupam discuss how IT can control access to the new Teams experience for end users, when Teams 2.0 will become the default experience for everyone, when the new client will reach feature parity with classic Teams, and when Teams 2.0 will be available for other platforms, like MacOS and web. And more!

If you’d like to see the rest of season one as episodes become available, please subscribe to the UnplugIT YouTube channel. Upcoming episodes will feature among others:

  • Christina Warren talking about GitHub for IT Pros
  • Understanding the new era of Security, Chips and Device with Frank Buchholts
  • Understanding Microsoft Syntex with Chris McNulty
  • And many more!

The Editorial team at Petri is looking forward to working with Stephen over the coming months to produce invaluable content for IT Pros that we hope you will find not only interesting but also entertaining. So don’t miss out and subscribe to UnplugIT on YouTube now! And don’t forget to hit the bell icon to make sure you are notified when new episodes are published.

The post Stephen L Rose Joins Petri.com as Chief Technology Strategist appeared first on Petri IT Knowledgebase.

View Details

Microsoft has recently announced the release of tenant restrictions version 2 (TRv2) for commercial cloud customers. The latest release enables IT admins to control whether end users can use externally issued identities to access external apps from org-owned devices or corporate networks.

The tenant restriction feature builds on the cross-tenant access settings that launched in preview for Azure Active Directory users in February 2022. It allows administrators to control how employees can securely collaborate with people from other organizations. Up until now, tenant restrictions only used an on-premises proxy server to perform cloud authentication with Azure Active Directory (Azure AD).

“We’ve been hearing that data exfiltration is a big concern for our customers moving to M365 cloud services, especially those with a need to collaborate across organizational boundaries. TRv2 addresses those concerns by preventing information leaks due to token infiltration, anonymous access of external SharePoint online data, or anonymous join of external Teams meetings, and enables secure external collaboration,” Microsoft explained.

What are the benefits of Tenant Restrictions V2 (TRv2)?Microsoft highlighted several key features of tenant restrictions V2 (TRv2). This release gives IT admins more control over external tenant access within their organization. It’s also possible to create granular partner-specific collaboration policies for external tenants.

Additionally, tenant restrictions V2 makes it easier for IT Pros to manage externally issued user identities. Other capabilities include improved security as well as seamless configuration and management.

Microsoft explained that tenant restrictions V2 allows IT admins to define granular access controls on a per-organization, user, group, and application basis. The feature can be used to protect Office apps, UWP .NET applications, Microsoft Edge, SharePoint Online, Exchange Online, and other apps.

Microsoft recommends customers to implement TRv2 in order to ensure secure cross-company collaboration in enterprise environments. We invite you to check out this support page to find more details about setting up the tenant restriction policy.

The post Microsoft Releases Tenant Restriction v2 to Ensure Secure External Collaboration appeared first on Petri IT Knowledgebase.

View Details

In this episode of First Ring Daily, Stephen Rose, Petri’s Chief Technology Strategist, talks to Paul and Brad about the most interesting news from Build 2023.

The post First Ring Daily – Stephen Rose Talks Build 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft released the public preview of Authenticator Lite for its Outlook mobile apps back in March 2023. The company has announced that the feature is now generally available on Android and iOS devices.

Microsoft’s Authenticator Lite feature allows users to approve multifactor authentication requests for work or school accounts directly in the Outlook mobile app. Users will receive push notifications with time-based one-time passwords (TOTP) via the Authenticator Lite app.

Additionally, Authenticator Lite prompts end users to enter a number displayed on the screen
to block multifactor authentication (MFA) fatigue attacks. It’s a social engineering technique that involves bombarding a target victim with MFA push notifications. The Authenticator Lite feature aims to enhance security for users who have not already installed the Microsoft Authenticator app.

“We strongly recommend moving your users off phone transports for authentication and towards more secure methods such as push notifications. Authenticator Lite (in Outlook) expands the opportunity to convert users by bringing the enhanced security of push notifications to devices that have not yet downloaded the Microsoft Authenticator App,” Microsoft explained.

Microsoft to enable “Managed Setting” for Authenticator Lite in JuneMicrosoft notes that IT admins can configure and manage Authenticator Lite capabilities in the Microsoft Entra portal and via MS Graph. However, the company plans to enable the Microsoft-managed setting for all organizations next month. It will let Azure Active Directory choose to turn on or off certain features for customers.

“Until June 9, leaving the feature set to ‘Microsoft managed’ will have no impact on your users and the feature will remain turned off unless you explicitly change the state to enabled. Due to the security enhancement this feature provides users, the Microsoft managed value of this feature will be changed from ‘disabled’ to ‘enabled’ on June 9,” Microsoft added.

Currently, Authenticator Lite is only supported in the Outlook mobile app, and it’s not yet available for desktop users. If you’re interested, you can find more details about how to enable the feature on this support page.

The post Microsoft Authenticator Lite is Now Generally Available for Outlook Mobile Apps appeared first on Petri IT Knowledgebase.

View Details

Nvidia announced several new AI products at the Computex annual trade show in Taipei, Taiwan. The biggest announcements made by the chip maker include the Nvidia DGX GH200, a new supercomputer designed for enterprise AI, an accelerated networking platform for hyperscale generative AI, as well as a new modular server architecture optimized for AI workloads.

As Google and Microsoft both filled their recent annual developer conferences with various generative AI announcements, Nvidia is positioning itself as a leading provider of hardware, software, and services to power this new AI revolution.

“We’re now at the tipping point of a new computing era with accelerated computing and AI that’s been embraced by almost every computing and cloud company in the world,” said Nvidia founder and CEO Jensen Huang at the company’s Computex keynote. According to the exec, 40,000 large companies and 15,000 startups are now leveraging Nvidia technologies such as the company’s CUDA parallel computing platform.

Nvidia announces new DGX GH200 AI supercomputerThe Nvidia DGX GH200 is a new AI supercomputer designed for generative AI, data processing, and recommender systems. It provides 1 exaflop of computing performance and 144 terabytes of shared memory, which is approximately 500x more than the DGX A100 supercomputer Nvidia announced back in 2020.

The Nvidia DGX GH200 (Image credit: Nvidia)The DGX GH200 is powered by 256 Nvidia GH200 Grace Hopper chips, which combine an Arm-based Nvidia Grace CPU with an Nvidia H100 Tensor Core GPU. All this computing power will help customers such as Google Cloud, Meta, and Microsoft to improve their generative AI workloads, which require a lot of resources.

“Training large AI models is traditionally a resource- and time-intensive task,” said Girish Bablani, CVP of Azure Infrastructure at Microsoft. “The potential for DGX GH200 to work with terabyte-sized datasets would allow developers to conduct advanced research at a larger scale and accelerated speeds.”

Nvidia details new MGX server specificationNvidia MGX is the name of a new modular server architecture designed to accelerate AI, high-performance computing (HPC), and Nvidia Omniverse workloads. It will allow system makers to quickly create over 100 server designs with a large choice of GPUs, CPUs, data processing units (DPUs), and network adapters.

“With MGX, manufacturers start with a basic system architecture optimized for accelerated computing for their server chassis, and then select their GPU, DPU and CPU. Design variations can address unique workloads, such as HPC, data science, large language models, edge computing, graphics and video, enterprise AI, and design and simulation,” the company explained.

Nvidia’s new MGX modular server architecture support different form factors (Image credit)Nvidia said that QCT, AsRock Rack, Asus, Gigabyte, Pegatron, and Super Micro will be among the first system makers to launch new MGX server designs, which will be supported by Nvidia’s full software stack.

Nvidia Launches Spectrum-X networking platformAt Computex, Nvidia also announced Spectrum-X, a new accelerated networking platform designed to improve AI workflows running on Etherned-based AI clouds. Nvidia Spectrum leverages the company’s Spectrum-4 Ethernet switches, which are built specifically for AI networks, as well as Nvidia’s BlueField-3 DPUs.

With Spectrum-X, Nvidia promises 1.7x better AI performance and power efficiency compared to traditional Ethernet fabrics, all while maintaining interoperability with Ethernet-based stacks. “NVIDIA Spectrum-X enables unprecedented scale of 256 200Gb/s ports connected by a single switch, or 16,000 ports in a two-tier leaf-spine topology to support the growth and expansion of AI clouds while maintaining high levels of performance and minimizing network latency,” the company said in the announcement.

Nvidia’s new Spectrum-X networking platform (Image credit: Nvidia)At its Build conference last week, Microsoft also detailed its partnership with Nvidia to improve AI workloads on Windows 11 PCs powered by Nvidia’s latest RTX GPUs. The company has already released new drivers that provide big performance improvements for workloads relying on text-to-image models

Soon, Nvidia will also launch new Max-Q low-power inferencing for AI-only workloads on RTX GPUs. This will allow mobile workstations with Nvidia’s latest GPUs to optimize Tensor Core performance for these workloads while keeping GPU power consumption as low as possible.

The post Nvidia Announces New Hardware and Services for Enterprise AI at Computex appeared first on Petri IT Knowledgebase.

View Details

MC561187 – This is an important message for customers who use the Stream (Classic) webpart to add videos to SharePoint Pages and news posts. Microsoft will retire the Stream (Classic) webpart on Aug 15, 2023 and it will no longer be available for use after this date. The Stream (Classic) webpart will be replaced by the new Stream (on SharePoint) webpart.

This change is associated with Microsoft 365 Roadmap: 124800

When this will happen:

The Stream (Classic) webpart will be retired on August 15, 2023.

The Stream (on SharePoint) webpart will begin its general availability roll out in mid-June, and Microsoft expects the rollout to complete by mid-July.

How this will affect your organization:

  • Your organization will not be able to use Stream (Classic) webpart after August 15, 2023.
  • All SharePoint pages and news posts that were built using Stream (Classic) webpart with single video as a source will continue to play your videos until February 2025.
  • After your organization migrates video content to Stream (on SharePoint), single videos configured on the Stream Classic webpart continues to play inline while channels configured on the webpart is replaced by a button that redirects to the migrated folder location.
  • If you would like to publish videos from Stream (on SharePoint) on SharePoint Pages, you can currently use video eligible webparts such as “File and Media”, “Hero”, “Highlighted content” and “List” webparts. Additionally, you will be able to use the new Stream (on SharePoint) webpart when it becomes available.
  • For re-publishing Stream Classic webpart videos post migration, users will have to manually do so using the share URL via above mentioned webparts.

What you can do to prepare:

Please follow this documentation for detailed timelines and video publishing guidance on the new Stream: Stream (Classic) web part transition plan & new Stream Webpart

Help and support

The post M365 Changelog: Stream Classic webpart retirement and new Stream (on SharePoint) webpart availability appeared first on Petri IT Knowledgebase.

View Details

MC561186 – Microsoft Teams IT Admins will soon be able to block internal users from accessing chats when these users join meetings organized on external non-trusted tenants, including cross-cloud join. This release of Microsoft Teams’ new meeting chat setting will be rolling out across MS Teams Desktop, Mobile and Web and will provide a new way for tenants to manage users’ chat access in meetings hosted on external non-trusted tenants.

This message is associated with Microsoft 365 Roadmap ID 123975

When will this happen:

Targeted Release: Microsoft will begin rollout in early July and expect to complete rollout by mid-July.

GA: Microsoft will begin rollout in mid-July and expect to complete rollout by late July.

GCC: Microsoft will begin rollout in early August and expect to complete rollout by mid-August.

GCCH: Microsoft will begin rollout in mid-August and expect to complete rollout by late August.

DoD: Microsoft will begin rollout in mid-September and expect to complete rollout by late September.

How this will affect your organization:

IT Admins can modify this setting for internal users from the Teams Admin Center under External Meeting Chat or from PowerShell under AllowExternalNonTrustedMeetingChat. Internal users who have External Meeting Chat as OFF from the Admin Center or AllowExternalNonTrustedMeetingChat as False from the PowerShell will not have read or write chat access in meetings hosted on external non-trusted tenants on any Teams platforms.

What you need to do to prepare:

You may want to notify your users about this new setting and the potential effect on their chat access when joining external meetings.

The post M365 Changelog: Microsoft Teams – Block Meeting Chat Access in External, Non-Trusted Meeting Joins appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that Microsoft Outlook, Edge, Viva Engage, and Power Apps are generally available on shared Android devices. The shared device mode allows frontline workers to securely access these apps on shared Android devices enrolled via Microsoft Intune.

Microsoft introduced shared device mode support for Edge, Outlook, Viva Engage, and Power Apps on Android devices in preview in January this year. It’s an Azure Active Directory (Azure AD) feature that allows frontline workers to seamlessly sign into and out of supported Microsoft 365 apps while using shared devices. Up until now, shared device mode was available for the Microsoft Teams and Managed Home Screen apps.

“Once signed into a shared Android device, frontline workers can immediately send and receive emails on Outlook to communicate with team members and their leadership team. Many organizations are automating manual and fragmented processes with the help of Power Apps to save frontline workers’ time to focus more on customers,” the company explained.

How does the shared device mode work in Microsoft Edge and Viva Engage?The shared device mode feature enables frontline workers to access any web-based app on Microsoft Edge. Moreover, frontline workers can use Viva Engage to stay connected with other people across their organizations. It’s possible to view announcements and notifications, learn valuable skills as well as participate in Q&A sessions.

Microsoft notes that the shared device mode lets frontline workers sign out globally on the Android device at the end of their shifts. This means that their sensitive data will no longer be accessible to anyone using the device. “When used with Intune’s Application Protection Policies, you can provide additional data protection so other parts of the device do not leave data behind,” Microsoft added.

Microsoft says that this release should help customers to protect user data in Microsoft 365 apps on shared Android devices. The company has also published a guide to help IT admins configure shared device mode through Microsoft Intune. If you’re interested, you can learn more about the feature on this support page.

The post Microsoft Outlook, Edge, and Viva Engage Now Available on Shared Android Devices appeared first on Petri IT Knowledgebase.

View Details

Creating backups is one of the most important duties of an SQL Server database administrator, and there are a number of different ways to back up your most important databases. In this article, I’ll explain how to create a simple SQL Server backup job using SQL Server Management Studio (SSMS).

The different ways to create SQL Server backup jobsDatabase backups are different from regular system or storage backups as databases are not just simple files. They have internal objects like users, permissions, indexes, views, and transactions.

While the end result of a database backup is a backup file that can be restored, the actual backup process needs to be database-aware in order to maintain complete consistency after a restore operation.

There are three main types of SQL Server backups:

  • Full database backup: A full database backup is created by the BACKUP DATABASE statement, as we’ll see below. When you restore this backup, the entire database is restored to the state when the backup was taken.
  • Transaction log backup: This backup type can only be created after having performed a full database backup. As you can guess, it only backs up the transaction log, which is backed up from the last successfully executed log backup at the current end of the log. Log backups can also be restored to a specific time or transaction.
  • Differential backup: This backup type only includes the portions of the database or files that changed since the last full backup. It usually takes up less space than a full backup. Using this option also eliminates the need to restore all individual log backups performed since the last full backup.

The 3 types of SQL Server database recovery modelsThe type of backup and restore that you can perform depends on the SQL Server database recovery model you’ll be using. The recovery model is a database configuration option that determines the type of backup that you can perform. There are three different recovery models you can use:

  • Full: This recovery model supports all restore operations including full database backups, differential database backups, and file-level backups. It also supports transaction log point-in-time restores, page restores, and file restores.
  • Simple: This recovery model supports full, differential, and file-level backups. Transaction log backups are not supported.
  • Bulk-Logged: This recovery model works like the full recovery model, except that certain bulk operations are minimally logged and it’s not possible to restore specific point-in-time data.

The different ways to back up an SQL Server databaseThere are a number of different ways you can backup a SQL Server database, here are the main ones you should know about:

T-SQL BACKUPThe T-SQL BACKUP command is core to most of the other backup mechanisms. When run from the Query Editor, the command will backup up a single database. This option can make an effective backup strategy when combined with scripts or the SQL Server Agent, as you will see later in this article.

SQL Server Management Studio (SSMS) Backup WizardThe SSMS Backup Wizard is best for one-off ad hoc backups. However, it isn’t scalable and not well suited for routine data protection.

Azure Data StudioLikewise, Azure Data Studio provides an interactive database backup wizard that enables you to perform ad hoc database backups. However, as the SSMS option, this method is not scalable or suited to being used for routine data protection.

SQL Server Maintenance PlansSQL Server maintenance plans provide a way to automate database backups, and they can be a good option for smaller businesses. These maintenance plans can be created fairly easily using the SSMS GUI, but they are not as flexible as some of the other options.

PowerShellYou can also perform SQL Server database backups using the PowerShell Backup-SqlDatabase cmdlet. This cmdlet has essentially the same capabilities as the native T-SQL BACKUP statement, and it includes the option to backup transaction logs.

Overall, PowerShell backups can be a good option if you want to include SQL Server database backups as a part of some external backup script or process.

Ola Hellengren scriptsOla Hellengren is a Data Platform MVP who created an award-Winning SQL Server solution for backups and maintenance. These scripts are not officially a part of SQL Server, and they are not provided by Microsoft. However, many businesses have incorporated them into their SQL Server operations routines to perform tasks such as backups, integrity checks, index and statistics maintenance. For SQL Server backups, they create SQL Server Agent jobs.

SQL Server Agent jobsThe SQL Server Agent is a popular and reliable way to run one or more database backups. The SQL Server Agent works as an automated job scheduler, and it can run many different types of routine operations including backups automatically.

Creating a SQL Server Agent backup job with SSMSTo schedule an SQL Server database backup, you first need to create an SQL Server Agent job, and then add the T-SQL BACKUP command to that job.

Starting the SQL Server AgentTo create a backup job using the SQL Server Agent, you first need to open SQL Server Management Studio and then navigate to the SQL Server Agent node, as you can see in the following figure.

Accessing the SQL Server Agent node in SSMS (Image credit: Petri/Michael Otey)If you have not used the SQL Server Agent before, it might not have started already. You can start it by right-clicking on the node and then selecting Start from the context menu.

Creating a new backup jobTo create a new backup job, right-click the SQL Server Agent node and select New> Jobfrom the context menu.

Creating a new backup job with the SQL Server Agent (Image credit: Petri/Michael Otey)This will display the New Job dialog shown in the following figure. Here, you can provide a name and description for your new SQL Server Agent job.

  • The Name prompt allows you to name the job. In this case, the job name is ‘AdventureWorksBackup’.
  • The Owner prompt defaults to the current user, but you can change it to a different user.
  • The Category prompt is mainly used as a description that tags the job
  • The Description field allows you to key in several lines of descriptive text about the job.

Add a name and description for your new SQL Server Agent job (Image credit: Petri/Michael Otey)After you’ve filled out this page, click OK to add the job to the SQL Server Agent. This will add the ‘AdventureWorksBackup’ job under the Jobs note in Object Explorer.

Adding the T-SQL BACKUP command to your jobNext, to add the T-SQL BACKUP command to your job, right-click the AdventureWorksBackup job node and then select Properties from the context menu.

Accessing the Properties for our job (Image credit: Petri/Michael Otey)This will launch the Job Properties dialog where you can specify the job’s commands, schedules, notifications, and more:

  • To add the T-SQL BACKUP statement, click on the Steps node in the left panel to display the list of job steps. For a new job, it will be blank because you haven’t created any steps yet.
  • To add a backup step, click on New.

Adding a new backup step for our job (Image credit: Petri/Michael Otey)This will display the New Job Step dialog which allows you to create a new job step.

  • First, give the job step a name. Here, we used ‘Backup’.
  • Select the Type: There are several step types to choose from, and the default is Transact-SQL script (T-SQL).
  • Next, supply the T-SQL BACKUP command in the Command pane. You can type it manually, but it’s usually better if you test it by running the command from inside a Query Editor window and then cut-and-paste the command into the Command pane.
  • To back up the AdventureWorks2019 SQL Server database, you can use the following command:

BACKUP DATABASE AdventureWorks2019 TO DISK = 'c:\backups\AdventureWorks2019.bak' Adding the T-SQL BACKUP command to back up our database (Image credit: Petri/Michael Otey)This command creates a full SQL Server database backup of the AdventureWorks2019 user database to the disk file AdventureWorks2019.bak that’s located in the c:\backups folder. This example uses a disk device as the backup target, but you could also use tape or other backup media.

After entering your command, click OK to return to the Job Properties page where your new job step will be listed. At this point, you can either add additional commands to the command pane or add additional job steps. For instance, you could add additional steps for all the different databases you want to back up.

Scheduling your jobNext, to schedule your job, click on Schedules in the left pane, which will display the Schedule list dialog shown below. Here, click New to open the New Job Schedule dialog.

The Schedule list dialog (Image credit: Petri/Michael Otey)Now, give the new schedule a name and then choose the frequency and interval that’s right for your backup job. Click OK when you’re done.

Choose the frequency and interval for your backup job (Image credit: Petri/Michael Otey)More options to create SQL Server backup jobsIn this tutorial, I detailed the different types of SQL Server backups that are available. I also explained how the SQL Server Agent can be used to schedule one or more jobs to run automatically.

Many businesses do periodic full backups along with more frequent differential backups and even more frequent transaction log backups. While the example I used in this article was a simple backup type, you also have the option of using encryption, compression, mirroring, and more.

The post SQL Server Essentials: How to Create a Simple Backup Job in SQL Server appeared first on Petri IT Knowledgebase.

View Details

Microsoft has discovered that a Chinese government hacking group dubbed Volt Typhoon is targeting critical infrastructure environments in the United States. The campaign is designed to steal network credentials and sensitive data to disrupt critical communications with the Asia Pacific region.

According to Microsoft, the Volt Typhoon group has been actively targeting companies in Guam and other parts of the United States for at least two years. The campaign affected various industries such as manufacturing, construction, communications, government, maritime, education, information technology, utility, and transportation.

The Chinese hackers use the “living off the land” technique to manually control tools already installed on the victim’s computers. Additionally, the threat actors use home and small office network equipment (such as firewalls, routers, and VPN hardware) to hide their communications with infected devices.

“Volt Typhoon achieves initial access to targeted organizations through internet-facing Fortinet FortiGuard devices,” the Microsoft Threat Intelligence team explained. “The threat actor attempts to leverage any privileges afforded by the Fortinet device, extracts credentials to an Active Directory account used by the device, and then attempts to authenticate to other devices on the network with those credentials.”

Volt Typhoon attack diagramHow to protect organizations against Volt Typhoon attacksMicrosoft detailed indicators of compromise that could help IT admins identify whether their enterprise network is infected by Volt Typhoon attacks. The company urges customers to close or change the credentials of all compromised user accounts. It’s also recommended to monitor the activity of these accounts to prevent further damage.

Microsoft noted that organizations should enforce strong multi-factor authentication (MFA) policies to mitigate security risks. Moreover, IT admins can configure attack surface reduction rules to prevent credential spoofing, process creation, and execution of malicious scripts. Microsoft Defender for Endpoint customers can run endpoint detection and response (EDR) capabilities in block mode to defend against security threats.

The post Microsoft Warns Chinese Volt Typhoon Hacking Group Infects Critical US Infrastructure appeared first on Petri IT Knowledgebase.

View Details

MC485549 – Updated May 25, 2023: Microsoft has updated the rollout timeline below. Thank you for your patience.

With hundreds of new and updated feature announcements across Microsoft 365, it can be challenging to track when the feature or change is available in your tenant. To help you track feature availability in your organization, Microsoft will provide a release status for each new and updated feature announcement in Message center

This message is associated with Microsoft 365 Roadmap ID 108078

When this will happen:

  • Targeted Release (if applicable): Microsoft will begin rolling out mid-December 2022 and expect to complete by mid-January 2023.
  • Standard Release (if applicable): Microsoft will begin rolling out mid-April 2023 and expect to complete by late June (previously mid-May).

How this will affect your organization:

The release status will initially be available for a limited number of Microsoft Teams, Outlook on the web and Microsoft 365 admin center feature announcements. Admins will see three release statuses in the “Status for your org.” field on each applicable message which will be updated over the lifecycle of the feature release.

  • Scheduled: The feature is planned to release, and is not available to the applicable users in your organization
  • Rolling out: The feature is beginning to roll out to some applicable users in your organization
  • Launched: The feature is available to all the applicable users in your organization

View image in new tab

Updates to feature release status will be provided on the original Message center post. Filtering capability on “Status for your org.” field will allow easier visibility on the updated release status. The release status will sync to Microsoft planner as part of the notes, if Planner sync is turned on in Message center.

View image in new tab

The release status will ONLY be available for generally available new and updated features that are also announced on Microsoft 365 Public Roadmap. If you do not see release status on a message, it means the release status is not available for that feature.

What you need to do to prepare:

You may want to consider updating your training and documentation as appropriate. For more information, please visit this Track new and changed features in the Microsoft 365 Message center.

Additional information

The post M365 Changelog: (Updated) Feature release status for your organization in Message center appeared first on Petri IT Knowledgebase.

View Details

Microsoft has recently released a major update for its Microsoft Lists app. The company detailed that the latest update brings several new capabilities and performance optimizations for Microsoft List users.

Under the hood, Microsoft has made various enhancements to make the Lists app twice as fast as before. Users should now notice faster loading times, better responsiveness, and smoother scrolling while using the app.

“We’ve supercharged Lists in the browser, in the PWA, and inside Teams to load in half the time. Whether you’re driving Lamborghinis or Lists, performance is the ultimate feature. So if you stop reading here, and don’t change a thing about how you work with Lists, you’re still going to enjoy a summer of lightning-fast views, forms, and fields,” the company explained.

Additionally, Microsoft unveiled a set of UI and UX optimizations to make Lists more consistent with other Microsoft 365 apps. Microsoft Lists now features a modern and cleaner look to improve the usability and accessibility of the app. The company has introduced support for different views, filtering and sorting options, as well as conditional formatting and rules.

Calendar view improvementsMicrosoft Lists Calendar view is getting a new top-requested week layout feature. This means that users can now choose between the month and week views to visualize list information. The new week layout enables users to get a more detailed view of tasks that are scheduled for the week.

Microsoft Lists to get a new forms experienceMicrosoft has released a new forms experience that should make it easier for users to collect information, track tasks, and stay organized within Microsoft Lists. Moreover, the app is getting a range of formatting options such as user-friendly questions, custom logos, descriptions, and names. Users can create multiple forms for the same list, which could be useful for event organizers.

Turnkey TemplatesMicrosoft has announced plans to bring support for organizational templates to all Microsoft 365 tenants worldwide. These include approvals integration, custom list templates, as well as Power Automate flows packaged into custom List templates.

Commenting feature coming to the Microsoft Lists mobile appsLastly, Microsoft detailed several improvements coming to the Lists mobile apps. The company expects to release MSA support to the Lists iOS app later this month, with Android support to follow by the end of June. Furthermore, Microsoft Lists will soon allow users to view and edit comments on iOS devices.

The post Microsoft Lists Gets Big Update with Performance Improvements and Other New Features appeared first on Petri IT Knowledgebase.

View Details

When planning for an Azure Stack HCI environment, many organizations may struggle to decide if they should go for a large Azure Stack HCI cluster or plan for smaller, use-case-specific clusters. Today, I would like to detail the ups and downs of both solutions. To do that, I’ll be discussing the required initial investments, maintenance costs, workload-specific needs, and more for large clusters vs. small specialized clusters.

Azure Stack HCI deployment: Initial investmentsIf you decide to invest resources in an Azure Stack HCI environment, a large cluster can often make more sense from an investment point of view. You normally plan for a stamp – a group of servers within a cluster – that has a specified number of active nodes plus one or two nodes for redundancy and maintenance purposes.

If you start with a big stamp, the initial investment can be lower due to the smaller required number of cluster nodes. In the table below, you can see that a large cluster can be created with just one unified cluster with 12 nodes plus two additional ones for redundancy and maintenance purposes.

| Cluster deployment | Large Cluster | Smaller Clusters | | Unified Cluster | 12 + 2 nodes | 4 + 1 nodes | | Database cluster | 2 + 1 nodes | | Stretched cluster | 4 nodes | | Test Cluster | 2 + 1 nodes | | Total number of nodes | 14 Nodes | 15 nodes |

If you chose to deploy smaller specialized clusters, however, the initial number of nodes is superior because we have 4 different clusters. If you need to use more clusters, you’ll also need more nodes for redundancy purposes.

If you want to deploy hardware-hungry applications such as SAP in a mixed environment, you will need to have a larger hardware stamp and larger nodes. That means investing more resources into faster CPUs, more memory, more storage, and better network connectivity.

Smaller stamps, however, can be better specialized:

  • You could have a small number of nodes to run SAP and they would be based on a high-end hardware tier.
  • Other stamps could be powered by more affordable hardware if they’re dedicated to running general services like file- or web servers.

With smaller specialized clusters, you may have much more nodes to manage, but the monetary investment could stay the same. The only additional costs to consider are power draw and cooling, which will add additional operating costs. Depending on your data center regions, those can be quite significant.

Upgrade flexibility for your Azure Stack HCI deploymentSmaller Azure Stack HCI clusters can help you avoid vendor lock-in more easily. If you build a large cluster and you want to add similar additional nodes, you’ll often have to keep relying on the same vendor, even if they make you pay more than competitors. However, you could still mix different vendors and configurations in one cluster or buy used server hardware on the second or third market.

If you chose to go with smaller clusters in your environment and want to upgrade their capabilities, you can do that with newer-generation hardware. In practice, you will migrate your virtual machines to the newer cluster and keep your old hardware for other purposes. You could also sell it or just free up space for additional use cases.

If we take all these cost factors into account, here how the comparison table looks like.

| Criteria | Large Cluster | Smaller Cluster | | Number of nodes | + | . | | Initial investment | + | (+ with different hardware) | | Flexibility | – | + | | Compatibility and long-term use cases | – | + | | Vendor and market flexibility | – | + |

Maintenance needs for your Azure Stack HCI deploymentDuring the lifecycle of your Azure Stack HCI environment, you’ll need to apply patches, driver and firmware updates, and even new versions of the Azure Stack HCI operating system. In case of an operating system update, you’ll need to apply it around six months after release, otherwise, you’ll lose the support of Microsoft for your cluster.

The Azure Stack HCI update cycle (Image credit: Microsoft)Depending on your server vendor, you may lose a few months of support until they catch up with the latest release of Azure Stack HCI. But here comes the issue: When installing operating system, firmware, driver updates for your clusters, you need consistency across all nodes.

Disadvantages of large clustersHere, the large cluster option has a major downside. Depending on the number of spare nodes you have, you can only update up to two nodes at a time. While these two nodes are updating or upgrading, your cluster will be running in a critical state. That means, if you happen to lose another node due to a hardware or power outage, you may not be able to maintain and run your workload, or you may encounter a major impact on performance.

Another key downside for the large cluster option is the time the maintenance process takes. Let’s say that during an upgrade cycle, you have 14 cluster notes to upgrade. You’ll be updating two nodes at a time and this process requires 30 minutes. Overall, this maintenance process will take at least seven hours during which your infrastructure will be in a critical state.

If one of your nodes fails during that cycle, the upgrade process will stop. You will end up in a “halfway-through” mode, which means that half (more or less) of your nodes are updated while the other half is still untouchedand you’ll have to troubleshoot the issue to update these remaining nodes. In addition, if the installation of a software or firmware update fails, this will result in significant issues for your cluster, and all your workloads may be impacted or go down.

Advantages of smaller clustersWith smaller clusters, you can stretch out the update process more easily: You can do maintenance on uncritical clusters first before proceeding with more crucial clusters. If one of your clusters goes down, you could migrate its workload to another cluster and run it there while you’re troubleshooting the issue.

With smaller clusters, you can also run updates in parallel and update more than one cluster at a time. There’s no limit as every cluster is operating independently from the other. That helps to shorten the maintenance cycle by several hours and if a node fails to update on one cluster, the other ones won’t be impacted and can proceed with the maintenance.

Another benefit of small clusters, especially when you use hardware from different vendors, is that you may have the opportunity to update clusters early. It may often happen that one vendor adds support for the new version of Azure Stack HCI earlier than the others. As an example, that would allow you to start the update process of your Lenovo or HPE cluster a month prior to other clusters running on different hardware.

One downside I see with small clusters during maintenance is that you must invest more time into planning your maintenance cycle. However, with good planning, your overall maintenance should become much smoother and with lower overall risks.

| Criteria | Large Cluster | Small Cluster | | Overall time for updates/upgrades | – | + | | Time running in critical state | – | + | | Update/Upgrade parallelization | – | + | | Risk reduction | – | + | | Additional planning required | + | – |

Managing large and small Azure Stack HCI clustersWhen it comes to cluster management, larger clusters have much better standing. In the Azure portal, keeping an overview of resources and issues in large clusters is much easier than doing the same homework for multiple smaller clusters. You can also have a much better view of your infrastructure by using Azure Arc or other integrated components such as the Azure Resource Bridge.

With smaller clusters, you need to manage more machines and connectors. You also need to have separate views and filters for every cluster. That can produce some overhead in management.

Splitting up a cluster into much smaller chunks also brings no benefit in costs etc. when it comes to support. Because every Azure Stack HCI node and cluster that’s connected to a subscription will inherit the support agreement of the subscription, you will have access to the best available support in any case.

Supportability and outagesWhen you need to engage with support and perform support tasks on your cluster, a large cluster has a higher risk of outages than a smaller one. For example, if you need to perform some reconfigurations because of performance issues, your entire workload in the large cluster may be impacted, and it could happen that you bring down all these workloads by accident. You may even struggle to perform those tasks because of the high impact on your production environment.

When using smaller clusters, however, you can evacuate the cluster where you need to perform the support tasks. That minimizes the overall risk of downtime for your various workloads. Here, small clusters have a major advantage over large clusters.

Stretched clusteringIf you want to mix workloads and use solutions like Kubernetes or Azure Virtual Desktop, then you need to use a stretched cluster deployment. This is best for disaster recovery as you get automatic failover to restore your production environment.

Here, a small cluster deployment would make more sense as you can deploy workloads that do not support stretched clustering on a regular cluster. Other workloads that need that kind of disaster and failover solution could be deployed within a stretched cluster.

Choosing the best solution for your Azure Stack HCI deploymentDepending on your needs and budget for an Azure Stack HCI deployment, you may decide to go with either large or smaller clusters. It often comes down to pricing and the type of workload deployed on the clusters.

Personally, and with the correct budget, I prefer to use smaller clusters instead of a larger one. In general, I found out that the management overhead of a large cluster does not outperform the overall benefits of smaller clusters.

The post Azure Stack HCI Deployment: Choosing Between Smaller Specialized Clusters vs. Large Clusters appeared first on Petri IT Knowledgebase.

View Details

Last year, Microsoft released support for number matching in push notifications for its Microsoft Authenticator app. Starting today, the number matching feature will become the default experience for all Authenticator users worldwide.

Microsoft’s Authenticator app’s number matching feature requires users to type the number displayed on the sign-in screen to approve access requests. It helps to counter Multi-Factor Authentication (MFA) fatigue attacks that rely on push notification spam. MFA fatigue attacks occur when a threat actor spams the victim with MFA push notifications. It’s a social engineering tactic that is used to gain unauthorized access to a corporate network.

With this release, Microsoft will enable the number matching feature for all supported cloud services. Users will also see additional context (such as the app’s name and the login location) to prevent accidental approvals.

“Number matching is a key security upgrade to traditional second factor notifications in Microsoft Authenticator. We will remove the admin controls and enforce the number match experience tenant-wide for all users of Microsoft Authenticator push notifications starting May 8, 2023,” Microsoft explained.

Microsoft suggests users to upgrade to the latest version of Microsoft Authenticator on their mobile devices. However, the authentication process will fail for users running older versions of the app that lack support for number matching.

Microsoft Authenticator number matching won’t be available for Apple Watch usersAccording to Microsoft, the number matching security protection will also be required for Self Service Password Reset (SSPR) and combined registration flows. The AD FS adapter will also require the feature on Windows Server versions 2022, 2019, and 2016. However, number matching won’t be available on Apple Watch devices.

“As services deploy, some may see number match while others don’t. To ensure consistent behavior for all users, we highly recommend you enable number match for Microsoft Authenticator push notifications in advance,” Microsoft added.

As MFA fatigue attacks continue to rise, it has become crucial for organizations to implement robust security measures to protect end users. The number matching feature provides an additional layer of security to prevent potential threats and breaches.

The post Microsoft Authenticator Enables Number Matching By Default to Block MFA Fatigue Attacks appeared first on Petri IT Knowledgebase.

View Details

MC546441 – Updated May 5, 2023: Microsoft has updated the content below for clarity. Thank you for your feedback.

Microsoft Purview Data Loss Prevention (DLP) for Teams helps organizations prevent sensitive data from being shared via Microsoft Teams channel or chat session. To prevent users from sharing sensitive information on Teams, customers need to assign Microsoft 365 E5/A5/G5/F5 licenses to their users as Teams DLP is made available through Microsoft 365 E5/A5/G5/F5 licenses. You can find a list of licenses that include Teams DLP capability here.

Please note – this is not a new change and Teams DLP has been a part of the Microsoft 365 E5/A5/G5/F5 licenses since it was launched.

Currently organizations with Microsoft 365 E3/G3/A3/F3 licenses assigned to their users are able to create Teams DLP policies, however starting June 30, 2023, organizations will require Microsoft 365 E5/A5/G5/F5 (or equivalent) licenses to use Teams DLP.

When this will happen:

June 30, 2023

How this will affect your organization:

You are receiving this message as a reminder to ensure your users who are currently covered with Teams DLP policies have the required Microsoft 365 E5/G5/A5/F5 licenses before June 30 2023. If you already have the mentioned E5 licenses, this message is not relevant to you, and Microsoft requests you kindly ignore this message.

If your users within the scope of your Teams DLP policies are assigned Microsoft 365 E3/G3/F3/A3 licenses, post June 30, 2023, your existing Teams DLP policies covering these users will become dormant and will not process any Teams messages for data loss prevention. You will not be able to create new Teams DLP policies or make changes to your existing Teams-only DLP policies that cover these users, and these users will not be block/audited while sharing sensitive information over Teams. The existing alerts while the policy was active will continue to be available for triage and remediation but no new alerts will be generated for these users.

If you have a DLP policy that covers multiple locations and one of the locations is Teams, that policy will continue to be active for all other locations except Teams. You will be able to edit such policies and remove Teams as a location in the policy configuration experience.

Please note that your Teams only DLP policies will not be deleted and will continue to be visible in the Microsoft Purview compliance portal for future use in the event that you are able to assign the required licenses to your users.

Microsoft recommends you assign the users within the scope of the Teams DLP policies appropriate Microsoft 365 E5/G5/A5/F5 licenses to continue to benefit from Teams DLP.

See which licenses include Teams DLP here.

Learn more about Teams DLP here.

The post M365 Changelog: (Updated) Licensing Check implementation for Teams DLP appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the release of its new cumulative update (CU13) for Exchange Server 2019. The latest update brings modern authentication support to Outlook for Windows in Exchange Server 2019 and addresses around 200 bugs.

Specifically, the 2023 H1 cumulative update adds support for modern authentication to on-premises Exchange Server 2019 environments. The security feature uses ADFS to issue and manage the OAuth 2.0 tokens. It lets organizations use stronger authentication mechanisms such as certificate-based authentication, smart cards, MFA, and third-party identity solutions.

“When Modern auth is enabled for a user, their Outlook client is redirected to ADFS. Users can then authenticate by providing credentials or performing multi-factor authentication. Once ADFS authenticates a user, it generates access tokens. These access tokens are validated by Exchange Server to provide client access to the user’s mailbox,” the Exchange team explained.

Source: MicrosoftModern authentication support coming to other Outlook clients in Exchange Server 2019Additionally, Microsoft explained that IT admins can now configure authentication policies to allow or block modern authentication for user accounts. The company says that administrators can use PowerShell commands to manage authentication policies.

As of this writing, modern authentication support is only available for Outlook for Windows (version 16327.20200 or later). The company plans to bring this capability to Outlook for macOS, the Outlook mobile apps, and other clients later this year.

Going forwards, Microsoft may opt to make modern authentication the default setting and gradually phase out basic authentication from on-premises servers. The company has already implemented this change for Exchange Online customers.

Backup and restore configurationMicrosoft mentioned that cumulative updates often overwrite various configuration files and custom settings. It’s a challenging task for IT admins to back up and restore these settings after installing the updates.

With this release, the setup process can now create a backup of the existing files, install the CUs, and then restore the most critical configuration settings. It eliminates the need to manually restore the settings to their pre-Setup state. You can find more details about Exchange Server custom configuration preservation on this support page.

The post Microsoft Brings Modern Authentication Support to Exchange Server 2019 appeared first on Petri IT Knowledgebase.

View Details

This month, Windows is getting memory safe Rust code in the kernel, Microsoft announces Windows 11 LTSC edition to launch late 2024, Windows 12 could be getting a special edition to support Arm and A.I. features, plus lots of updates for Insider Program builds.

Windows gets support for Rust in the Windows kernelAt the BlueHat security conference in Israel last month, Microsoft Vice President David Weston announced that some parts of the Windows kernel would be rewritten in Rust. Rust is a memory safe language that delivers improved security while maintaining the performance of C and C++. Weston said that we will see Windows booting with Rust in the kernel in the coming weeks and months. It wasn’t clear whether he was referring to Insider builds or the stable channel.

Microsoft has written 36,000 lines of Rust code in the Windows kernel to date. Weston says that there is a system call in the kernel written in Rust, which allows apps to interact with Kernel level functions.

The DirectWrite Core library has already been recoded with 152,000 lines of Rust as a proof of concept. And it is available today in the Windows App SDK. We can also expect some Rust work on Windows GDI components in the near future.

Despite these changes, Weston noted that Microsoft isn’t planning to rewrite Windows in its entirety. Check out Windows 11 Gets Rusty in the Name of Security for more details about updates to the Windows 11 kernel.

Microsoft is developing a special edition of Windows 12 for Arm and A.I.Windows Latest claims this month that Microsoft could be developing a special edition of Windows 12, which will run on Arm and be optimized for A.I. We know that Microsoft is working on some new A.I. features for Windows, like Smart Snap. But it’s not yet clear if these A.I. features will be available in all versions of Windows or limited to editions that are designed to run on specific hardware.

Windows 11 LTSC expected in late 2024As it stands, there is no LTSC edition of Windows 11. But Microsoft announced this month that it is planning to release an LTSC version of Windows 11 in late 2024. I expect this to coincide with the release of Windows 12.

Patch Tuesday new features for Windows 11Microsoft sneaked in a couple of updates to Windows 11 in the April cumulative update. Windows 11 now has Microsoft account notifications on the Start menu, improved Search box rendering on the taskbar for those with custom color modes, and updates to Microsoft Defender for Endpoint.

But more importantly, Windows 10 and Windows 11 users now get to enjoy Windows LAPS as a built in operating system component.

Phone Link iOS support now rolling out to Windows 11 usersMicrosoft announced that an updated version of Phone Link with support for iOS is now rolling out to Windows 11 users. The updated software brings basic support for calls, messages, and access to contacts. Microsoft says that if you need access to photos, the you should use the iCloud integration for the Windows 11 photos app.

Windows 11 coming to HoloLens 2Windows 11 is coming to HoloLens 2 with the latest tools for developers. Microsoft says that Windows 11 will bring ‘confidence’ to mixed reality customers that they are getting the most secure version of Windows.

The update to Windows 11 will be free and it includes Microsoft Edge WebView2. To update HoloLens 2, go to Settings > Update & Security > Check for Updates.

Download updates as soon as they are available in Windows 11In the April 2023 update preview, there’s now an option in Windows 11 22H2 to download updates as soon as they are available. The toggle applies to non-security updates released during the last week of every month and to other improvements and enhancements made available via Windows Update.

Microsoft Edge updatesThere are a couple of updates for Edge users this month. Plus, Workspaces enters public preview.

Browser essentialsMicrosoft added a feature called Brower essentials to the Canary channel. The Browser essentials icon in the tool bar will give you a quick overview of the performance and security status of the browser.

Microsoft Edge browser essentials (Image Credit: Microsoft)Microsoft Designer on sidebarMicrosoft also said that it was rolling out an option to add its Microsoft Designer preview to the sidebar for users on the stable channel.

Microsoft Edge Workspaces in public previewMicrosoft Edge Workspaces is now available in public preview. The feature allows users to collaborate on a tab group together. Microsoft explains that Workspaces helps users not lose track of links that are important for getting work done in your team.

Microsoft Edge Workspaces (Image Credit: Microsoft)Windows Insider Program updatesHere are the most notable updates to Windows on the Insider Program from April.

Facebook widgetMicrosoft released a Facebook widget across all three Insider Program channels. The widget lets users see Facebook notifications. There’s a separate widget for Facebook Messenger.

File Explorer details paneBuild 23451 on the Dev channel got an updated details pane in File Explorer. The new pane was made available for a subset of users and it adds more contextual information about files.

File Explorer details pane (Image Credit: Microsoft)File Explorer galleryWindows 11 Insider Preview Build 23435 gets a Gallery view in File Explorer. Microsoft says: “Gallery is a new feature in File Explorer designed to make it easy to access your photo collection. The set of content shown in Gallery is the same as what you’ll see in the All Photos view in the Photos app.”

App labels on the taskbarMicrosoft could be bringing back app labels to programs on the taskbar. According to a report in The Verge, while not in public testing yet, a new setting could be coming that allows you to display ‘icons and labels’ for apps on the taskbar.

A label is essentially the name of the running app and labels were previously available as an optional feature in Windows 10.

File Explorer Gallery view (Image Credit: Microsoft)Presence sensing privacyWindows 11 preview build 22624.1610 on the Beta channel got the ability to test new presence sensor and privacy settings under Settings > Privacy & security > Presence sensing. If your device has compatible hardware, you can manage presence sensing access and block apps from using sensors.

Windows Subsystem for Android updatesFinally this month, the Windows Subsystem for Android gets some updates:

  • Support for picture-in-picture mode
  • A new setting in the WSA Settings app, which runs the subsystem with minimal resources but apps launch quicker than in “As needed” mode. The setting is called “Partially running”.
  • Linux kernel updated to 5.15.78
  • Reliability improvements
  • Security updates for Android 13

And that’s it for another month!

The post What’s New in Windows – April 2023 appeared first on Petri IT Knowledgebase.

View Details

MC550584 – Effective May 31, 2023, Grade Sync feature of Microsoft Teams Assignments will no longer be available to new customers. Existing customers may continue to use it until June 30, 2023.

When this will happen:

June 30, 2023

How this affects your organization:

After June 30 2023, Grade Sync will no longer sync Assignments and grades from Microsoft Teams Assignments and the student information system (SIS). After this change, teachers will need to manually create assignments and update the grades from Teams Assignments into the SIS.

Microsoft continues to support Grade Export to Excel and also have Education APIs for Microsoft Graph covering assignments and grades that may be useful for customers exploring alternatives.

What you can do to prepare:

If you have any questions regarding this change, please contact Microsoft Education Technical Support https://aka.ms/edusupport.

No further action is needed on your part during this change.

The post M365 Changelog: GradeSync for Teams Assignments retirement appeared first on Petri IT Knowledgebase.

View Details

Last year, Microsoft released a public preview of Azure Active Directory certificate-based authentication (CBA) on mobile. The company announced yesterday that Azure AD CBA support is now generally available on iOS and Android devices.

The new security solution allows IT admins to provision certificates with a hardware security key for authentication on mobile devices. The company explained that its FIPS Federal Information Processing Standards)-certified helps to protect users against phishing attacks.

“We support both on-device certificates and external hardware security keys, like YubiKeys over USB or NFC on iOS and Android devices. With Bring Your Own Device (BYOD) on the rise, this feature will give you the ability to require phishing-resistant multi-factor authentication (MFA) on mobile without having to provision certificates on the user’s mobile device,” explained Vimala Ranganathan, Product Manager for Microsoft Entra.

According to Microsoft, Android users can leverage the latest MSAL support to enable Azure AD CBA support on their mobile devices. They can use the USB to plug in their YubiKey, select a certificate and, enter the PIN to access the app.

How the Azure AD certificate-based authentication (CBA) feature works?On iOS, users will first need to register through the Yubico Authenticator app. Then, they can copy YubiKey’s public certificate into the iOS keychain. Finally, iOS users can choose the YubiKey certificate for authentication and enter a unique PIN code.

Azure AD CBA on iOS mobile with YubiKey Microsoft’s Azure Azure AD CBA feature should help to prevent credential theft via social engineering or phishing attacks in hybrid environments. The company plans to introduce certificate filtering capabilities and support for additional smart card providers.

The passwordless authentication market continues to growLast year, Microsoft, Google, and Apple announced a partnership to expand passwordless login support across all major platforms. Since then, many security providers have been working on their own passwordless authentication solutions. The global passwordless authentication market is expected to grow to $53.64 billion by 2030.

The announcement comes just a few days after Google announced passkey support for Google accounts. It enables users to sign in to applications and websites with a screen-lock PIN or biometrics. This approach makes it difficult for threat actors to get unauthorized access to users’ accounts.

The post Microsoft Launches Azure AD Certificate-Based Authentication (CBA) on Mobile Devices appeared first on Petri IT Knowledgebase.

View Details

Microsoft has recently unveiled the Intune Microsoft Store repository integration, which is intended to replace the current Microsoft Store for Business integration with Intune and provide a more consumer-like experience for employees. Microsoft has also released the WinGet Windows Package Manager, which allows IT pros to manage apps and updates through the Microsoft Store repository integration. In this article, I will explain how the Intune integration with the Microsoft Store works and how to add Microsoft Store apps to Intune.

What is the Intune integration with the Microsoft Store?This Intune integration with the Microsoft Store was announced in conjunction with the retirement of the Microsoft Store for Business and Education, which was scheduled to occur on March 31, 2023. However, Microsoft recently updated their announcement post to announce that the retirement of the Microsoft Store for Business will occur in several stages ending on September 15, 2023.

The Microsoft Store repository integration is expected to offer a number of improvements over the current Microsoft Store for Business integration such as enhanced app deployment, better update controls, and the ability to easily install and uninstall apps. In the current Microsoft Store for Business integration, apps must be manually synced in order to be made available in Intune, and there is no native update control for store apps.

The Microsoft Store repository integration, on the other hand, will automatically make new apps available and offer more control over app update deployments from Intune, as well as custom install and uninstall options. This should make it easier for enterprise admins to install, update, and manage apps on their organization’s devices.

One of the key features of the Intune integration with the Microsoft Store is the expanded catalog of apps it provides, which includes both UWP apps (Universal Windows Platform apps) and Win32 apps (traditional Windows apps). This means that in addition to the traditional Windows apps that have been available through the Microsoft Store for Business, the Intune integration with the Microsoft Store will also include apps from the Microsoft Store. This expanded catalog should offer more options for organizations looking to deploy apps to their devices.

How does the WinGet Windows Package Manager work?The WinGet Windows Package Manager, which serves as the client interface for the Windows Package Manager service, allows for the discovery, installation, upgrading, removal, and configuration of applications on Windows 11 or Windows 10 PCs. The WinGet tool connects to centralized application sources and provides a command line interface for installing and searching for apps. The apps and their packages are maintained centrally by the publishers, and the WinGet tool retrieves the packages as needed.

The WinGet tool offers a number of benefits for the management of apps on an organization’s devices. Enterprise admins can use the tool to discover and install new apps, as well as upgrade or remove existing ones. The tool also allows for the configuration of apps, which can be useful for setting up and customizing the behavior of certain apps.

In addition to benefits for enterprise admins, the Microsoft Store repository integration and the WinGet tool also offer benefits for end-users. The improved app deployment and update controls offered by the Microsoft Store repository integration should also make it easier for employees to stay up to date with the latest versions of the apps they use.

How to add Microsoft Store apps to IntuneThe process for adding a Microsoft Store app to Intune is very straightforward. Here are the steps you need to follow:

  • From the Intune admin center, head to the Apps menu in the left panel, choose All Apps, and then click on Add.

Accessing the Apps menu in Intune (Image credit: Petri/Dean Ellerby) In the Select app type dialog, choose Microsoft Store App (new), and click on Select* at the bottom to move to the next screen.

Choosing a Microsoft Store app to add to Intune (Image credit: Petri/Dean Ellerby) In the Add App section, click on the Search the Microsoft Store app (new)* link.

We’ll be searching for a Microsoft Store app (Image credit: Petri/Dean Ellerby) In the search box that appears, enter the name of the app you wish to deploy and choose Select*

We’ve picked up Mozilla Firefox as the Microsoft Store app to deploy (Image credit: Petri/Dean Ellerby) In the App information section, review the metadata related to the app. Here, the information has been provided automatically. Click Next* when you’re done.

You need to review the metadata related to the app (Image credit: Petri/Dean Ellerby)* On the Assignments section, you need to decide which devices or users will receive the application. At this stage, you can also determine if the app is deployed as “Required” or “Available for enrolled devices.”

We’re ready to add our Microsoft Store app to Intune (Image credit: Petri/Dean Ellerby) Finally, click Next and then Create* to add the app to Intune. * nominated devices.

You’re now ready to deploy your app to nominated devices. Once you add a Microsoft Store app to Intune, you won’t have to worry about keeping it up to date, Intune will do that automatically when a new version becomes available.

Overall, the new Microsoft Store app integration with Intune is a welcome improvement for IT pros, though there are some limitations you need to be aware of. In some cases, you may not be available to add Microsoft Store apps to Intune. As of today, not all Win32 apps will be available or searchable, and paid apps are also not currently supported.

The post How to Add Microsoft Store Apps to Intune appeared first on Petri IT Knowledgebase.

View Details

Google has started rolling out its passkey technology to Google accounts across all platforms. The feature allows users to log into any of their accounts with passkeys instead of passphrases and multifactor authentication (MFA).

A passkey is an authentication feature that enables users to securely access apps and services. It’s designed to let users authenticate through a facial or fingerprint ID or PIN on computers or phones. Passkeys rely on a robust security mechanism that links login credentials to their device.

Previously, Google allowed users to utilize passkeys as a part of the two-factor authentication process for their accounts. The latest update enables users to use passkeys to sign into Google websites. Currently, passkeys work alongside other authentication mechanisms, such as hardware security keys and passwords.

Why Google accounts should be protected with passkeys?Unlike passwords, passkeys bring several security benefits to secure Google accounts. The feature helps to protect devices against brute force attacks, phishing campaigns, and other security threats. Moreover, it’s a convenient authentication method that eliminates the need to remember passwords. The passkeys are stored locally on the device, which ensures that the data is not shared with Google or any other third-party entities.

“Passkeys are still new and it will take some time before they work everywhere. However, creating a passkey today still comes with security benefits as it allows us to pay closer attention to the sign-ins that fall back to passwords. Over time, we’ll increasingly scrutinize these as passkeys gain broader support and familiarity,” Google explained.

How to enable Google passkeys on Android devicesTo get started with passkeys, head over to the passkey setup page and then use the existing password to sign into the Google account. Click the “Use passkeys” button available in the center of the screen.

Last year, Microsoft, Google, and Apple announced their passkey initiative aimed at a passwordless future. PayPal, Docusign, eBay, and other businesses are already using passkeys for user authentication. It’s great to see that Google is finally moving one step closer to ditching passwords.

Google says that passkey support is currently only available for consumer devices. The feature is also available for users enrolled in Google’s Advanced Protection program. However, the company will soon bring the new passwordless sign-in experience to Google Workspace accounts.

The post Google Adds Support for Passkeys to Protect Google Accounts appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released a new email alerts feature that should make it easier for IT admins to keep track of known issues in Windows PCs. The highly requested feature enables administrators to sign-up for email notifications about Windows bugs via Microsoft 365 admin center.

Essentially, known issues are problems that impact the user experience, security, and performance of different versions of Windows. Up until now, Microsoft used to provide information about known issues affecting Windows 11/10 and Windows Server 2022 on the Windows release health dashboard. However, IT admins often do not have sufficient time to keep up with any new announcements on the page.

How does the Windows email alert feature work?According to Microsoft, the email alerts feature will enable eligible IT admins to receive email notifications for Windows update-related issues. These include changes in issue status, new workarounds as well as resolutions.

“The notification body will include the full content published about the issue in the Windows release health section of the Microsoft 365 admin center. With a quick glance, you’ll be informed of the status of the issue, as well as versions affected. You’ll find links to view the message in the admin center,” Microsoft explained.

How to subscribe for Windows known issue email alertsMicrosoft says that users will need to sign-up for email notifications about known Windows issues by following these steps:

  • Go to Windows release health in the Microsoft 365 admin center.
  • Select Preferences >> Email and click “Send me email notifications about Windows release health.”
  • Provide the email address and Windows versions to receive the notifications.
  • Finally, click the Save button. However, it may take up to 8 hours to apply the changes.

Microsoft notes that users will receive only one email alert in the event that an issue affects multiple versions of Windows. This means that IT admins can sign-up for multiple Windows versions without worrying about getting duplicate emails.

Overall, the new email alerts feature should help IT Pros to make well-informed decisions regarding Windows update deployments within their organizations. Currently, it’s only available for customers with Windows 11 Enterprise E3/A3, Windows 11 Enterprise E5/A5, Windows 10 Enterprise E3/A3, Windows 10 Enterprise E5/A5, Microsoft 365 Enterprise E3/A3/F3, and Microsoft 365 Enterprise E5/A5 subscriptions.

The post Microsoft Now Provides Email Alerts About Known Issues for Windows Admins appeared first on Petri IT Knowledgebase.

View Details

This Week in IT, I look at upcoming changes to the Windows 11 kernel that bring support for Rust. Plus, reports suggest that Microsoft could be developing its own Arm chip for a client device, Windows 12 will get a special edition to support Arm and A.I., and AWS Verified Access reaches general availability.

The post Windows 11 Kernel Gets Rust Support appeared first on Petri IT Knowledgebase.

View Details

Microsoft is removing the waitlist for its new AI-powered Bing today, and the company also detailed several new features to enhance the search experience with AI. The software giant also plans to turn its Bing chatbot into a platform and let developers create third-party plugins for it, echoing the recent launch of the first plugins for OpenAI’s ChatGPT.

In just three months, Microsoft says that its new Bing AI has gained real momentum: The company observed over a half billion chats, over 200 million images created with Bing Image Creator, and over 100 million daily active users for the search engine. By recently integrating its Bing AI into the Windows taskbar, Microsoft also claims that it’s now able to reach over 500 million users every month.

“Thanks to tremendous customer adoption, engagement and feedback, we’re ready to take the next step and are announcing the new Bing is now in Open Preview and no longer has a waitlist. This means that it will now be easier than ever for everyone to try the new Bing and Edge by simply signing into Bing with your Microsoft Account,” explained Yusuf Mehdi, CVP and Consumer Chief Marketing Officer at Microsoft.

Microsoft’s AI-powered Bing is getting image results, chat history, and moreIf everyone can now try the new AI-powered Bing, a lot of new features are also in the pipeline. Here’s everything Microsoft announced today:

  • More languages for Bing Image Creator: The Bing Image Creator, which lets users create images with a simple description now supports more than 100 languages currently supported on Bing.
  • More visual answers: The Bing chatbot will be able to include charts and graphs in its answers, building on Bing’s existing Knowledge Cards and visual search features.
  • Visual search in chat: Users will be able to upload images in conversations with the Bing chatbot to search the web for more information.
  • Chat history: Soon, Bing users will be able to continue a previous conversation with the Bing chatbot. Microsoft is also working on making Bing capable of using context from a previous conversation in a new one.
  • Chat export and share: Another top requested feature coming soon is the ability to export a conversation with the Bing chatbot to share it with others or embed it in a document.
  • Third-party plugins: Microsoft will let developers create plugins allowing Bing users to access third-party services within a chat conversation.

That’s it for the main new features coming soon to Microsoft’s AI-powered Bing, and the company said that it will share more details about third-party plugins at its Build developer conference later this month. However, the company also announced today some new AI-powered capabilities for its Edge browser.

Microsoft Edge is getting new AI-powered features tooMicrosoft Edge is the only web browser to offer a deep Bing integration, and Microsoft says it’s where 25% of Bing chats come from. The Chat feature in Microsoft Edge will soon get improved summarization capabilities for long documents and web pages. On mobile, Microsoft Edge will also let users ask questions about a page they’re viewing.

In the coming weeks, Microsoft will also introduce Edge actions in the browser’s sidebar. “For example, if you want to watch a particular movie, actions in Edge will find and show you options in chat in the sidebar and then play the movie you want from where it’s available,” Mehdi explained.

Lastly, Mehdi teased that Microsoft was in the process of redesigning Microsoft Edge. “As these changes begin to roll out, you’ll begin to see a sleeker and enhanced user interface including a streamlined look, rounded corners, organized containers and semi-transparent visual elements,” the exec said.

Microsoft is iterating really fast on its new AI-powered Bing, but the company’s partnership with OpenAI is already impacting many other Microsoft products. The software giant is in the process of implementing new “Copilot” experience across Microsoft 365 apps and services, and SharePoint is one of the latest apps to receive the Copilot treatment.

The post Microsoft’s Bing Chatbot Launches in Open Preview and Will Get Third-Party Plugins appeared first on Petri IT Knowledgebase.

View Details

Polly has teamed up with video technology provider Pexip to launch new cloud-based and on-premises communications services. The new offerings are designed to meet the business communication and privacy needs of the public, government, and private customers.

Specifically, Poly has integrated Pexip’s technology into its products to provide three communication solutions. These include Poly PrivateConnect powered by Pexip, Poly CloudConnect powered by Pexip, and Poly FedConnect powered by Pexip. The company says its new offerings could be particularly useful for the healthcare and financial sectors.

“We are introducing three offerings that prioritize better user experiences, deeper customization, higher levels of interoperability, and alliance strength while adhering to robust security protocols. These solutions will be a replacement for Poly’s existing Clariti and RealConnect offerings for on-premise and cloud-based communications,” said Chris Moss, Product and Portfolio Management, HP Hybrid Systems.

Poly PrivateConnect powered by PexipPoly has announced a secure video technology service called Poly PrivateConnect powered by Pexip. It offers a unified, flexible, and scalable meetings experience, all while maintaining strict security measures. The solution provides interoperability modules to let users connect with Google Meet or Microsoft Teams.

Poly CloudConnect powered by PexipMoreover, Poly launched another cloud-based video technology platform dubbed “Poly CloudConnect powered by Pexip.” The service offers interoperability for Google Meet and Microsoft Teams to enhance customization, user experiences, and management capabilities.

Poly FedConnect powered by PexipLastly, Poly FedConnect powered by Pexip is a FedRAMP-authorised solution for US government organizations. The SaaS-based video conferencing service provides a secure connection to let users join Teams calls from standards-based video systems.

Poly’s new on-premises and cloud-based collaboration solutions are available for government, public, and private sector organizations worldwide. These offerings should help users to meet the data privacy and compliance requirements of their organization. If you’re interested, you can check out the blog post for more details.

The post Poly Partners with Pexip to Provide Secure Video Collaboration Solutions appeared first on Petri IT Knowledgebase.

View Details

Microsoft is planning to make web links in Microsoft Outlook and Teams to open by default in its Edge browser. The company is giving IT admins a 30 days notice that this change will be gradually rolled out in Outlook for Windows for all business customers.

Microsoft first announced the web link behavior change for consumers with Microsoft 365 Personal or Family subscriptions in February 2023. The company claimed that it should make it easier for users to stay focused on important tasks. It should also eliminate the need to switch between different applications.

Now, Microsoft is getting ready to roll out the behavior change to commercial customers with Azure Active Directory (AAD) and Microsoft (MSA) accounts. Microsoft says that the Outlook desktop client will open web links in Microsoft Edge’s sidebar by default. This means that the app will completely ignore the default browser selected in Windows Settings. Microsoft has already rolled out similar changes that impact the search experience and widgets in Windows 11.

“Web links from emails in the Outlook for Windows app will open side-by-side with the email in Microsoft Edge so users can easily reference the link and email without switching back and forth between apps. The email will open in the Outlook app in the Edge sidebar. Links will open in Microsoft Edge even if it is not the system default browser in Windows,” the company explained on the Microsoft 365 admin center.

Going forwards, Microsoft plans to roll out the new default behavior for links in Microsoft Teams. The company explained that web links shared in Teams chats messages will open in Microsoft Edge, though there is no ETA yet. Meanwhile, Microsoft confirmed that similar changes will also arrive in Outlook for iOS and Android in the coming weeks.

Microsoft’s latest Edge push triggers backlash from IT adminsApparently, the recent announcement has generated a significant amount of criticism from IT administrators. “This has been going on for some time now with Outlook on Android. It completely bypasses the default browser setting and opens all links in Edge. It’s annoying.” an IT admin wrote on Reddit.

Microsoft advises IT admins to configure policies to manage the change for Microsoft 365 Apps. However, customers with a Microsoft 365 Business plan will need to control the settings on individual client machines. Do you think that this change would cause unnecessary headaches for thousands of small businesses with IT resources and budget restrictions? Let us know in the comments section below.

The post Microsoft Outlook and Teams to Open Web Links in Microsoft Edge By Default appeared first on Petri IT Knowledgebase.

View Details

Microsoft published a detailed roundup of all the new features added to Microsoft Teams in April 2023. This time around, the company highlighted improvements to meetings, webinars, management capabilities, Teams Rooms devices, and much more. Let’s dive in!

Meetings featuresStarting with meetings, Microsoft has released a new feature that will automatically lower a participant’s raised hands after speaking in the meeting. Users can choose to keep their hands raised by clicking the “Keep it raised” button. This capability is only available for desktop users, and it helps organizers to focus on unanswered questions.

Microsoft has also added a new ultrasound howling detection feature to eliminate the feedback loop and echo in Teams meetings. When a user joins a Microsoft Teams meeting and other participants are physically present in the same room, the app will automatically mute your microphone and speakers. This feature is only supported on the Teams desktop client for Windows and macOS.

Microsoft has introduced closed captions support for embedded videos in PowerPoint Live for Teams. Microsoft Teams now supports a new green screen feature that enhances virtual background effects. The feature helps users to increase the sharpness and definition of the backgrounds around the user’s face, ears, hair, and head.

Reminder Emails for WebinarsAs for webinars, Microsoft has introduced support for reminder emails to drive excitement and attendance for the event. All registered webinar participants will receive the emails at a specific date and time. These automated reminder emails will include webinar details and a custom-branded header along with a link to join the event.

Microsoft Teams can now auto-install approved appsThere are also some changes to the management side of Microsoft Teams. Administrators can now use the Auto install approved apps (AAA) feature to surface apps that are highly relevant to users’ needs. It will automatically install approved apps for users who sign into SaaS apps with their Azure AD credentials. The Auto install approved apps feature is designed to reduce administrative costs and manual processes.

Microsoft says that ISVs can now visit the partner center to target applications to select geographies. This means that Microsoft Teams users will only see apps relevant to their specific country or region.

Microsoft Teams Rooms devices and moreMicrosoft has announced several new devices for Microsoft Teams Rooms in April 2023. You can check out the full list below:

  • Audiocodes RXV81 video collaboration bar for Microsoft Teams on Android
  • Yealink Meeting Board Camera 6X for Microsoft Teams Rooms on Android
  • Bose Videobar VB-S for Microsoft Teams Rooms on Windows
  • DTEN D7X 55” for Microsoft Teams Rooms on Android
  • Q-SYS Certified Teams Rooms Bundle
  • Aver TR313V2 Camera, Back of Room Presenter’s Camera
  • Lenovo ThinkVision MC60 Monitor Webcam

Q-SYS Certified Teams Rooms BundleFinally, Microsoft has started rolling out the features already available for commercial customers in multi-tenant cloud environments to government customers. These include the United States Department of Defense (DoD), Government Community Cloud (GCC), and Government Community Cloud High (GCC-High) tenants.

The post Microsoft Teams Adds Auto Install Approved Apps Feature, Webinar Reminders appeared first on Petri IT Knowledgebase.

View Details

Microsoft detailed yesterday several new updates coming to its SharePoint platform over the coming months, including a new AI-powered Copilot experience. Microsoft has an ambitious product roadmap for SharePoint sites and pages this year, and advanced image editing features and a new integration of Sharepoint pages into emails will roll out first in the next couple of months.

According to Adam Harmetz, Vice President of Product Management at Microsoft, the following SharePoint roadmap is “the biggest step we’ve ever taken in the 22-year history of the product to reimagine how sites, pages, and new types of content are created in SharePoint.”

Microsoft’s SharePoint product roadmap for 2023 (Image credit: Microsoft)We’ll start with the new Copilot experience in SharePoint, which is expected to launch in preview by the end of 2023.

New Copilot in SharePointThe new Copilot experience in SharePoint will simplify the creation of SharePoint sites with generative AI features. Users will be able to use Copilot when creating sites from scratch from the SharePoint Start page. “With only a brief prompt, Copilot in SharePoint creates a starter site for you, brings in information from across your organization as needed, and automatically aligns to your organization’s brand,” explained Harmetz.

Copilot will also be able to assist users looking to turn an existing document or presentation into a SharePoint page. Again, using a simple prompt such as “Create an employee onboarding site for Product Managers using this PowerPoint as a base” will be able to get the Copilot ball rolling.

The new Copilot experience in SharePoint (image credit: Microsoft).If Copilot promises to greatly reduce the time spent on setting up SharePoint sites, the platform is also getting a major aesthetic update with advanced features for creating sophisticated sites and pages.

New aesthetic capabilities coming to SharePointA new SharePoint Start page is planned for the September/October timeframe, and it will provide design templates, a list of recent posts and drafts, as well as analytics data. If the new Start page will make it easier to start creating a SharePoint site or page, Microsoft is also upgrading the content creation experience in various ways:

  • Microsoft has redesigned the entire branding, theming, fonts, video, animations, and motion experiences with a touch of Fluent Design.
  • A new brand center will let users reuse branding elements across sites more seamlessly
  • A new content pane will provide relevant design suggestions when you’re working on a page.

The new content pane in SharePoint pages (Image credit: Microsoft)* The upgraded image editor will add support for shape cropping, color adjusting, adding filters, and overlaying text. * Co-authoring capabilities for SharePoint pages are coming by the end of the year.

To improve engagement with SharePoint content, Microsoft also announced new SharePoint integrations with other apps including Microsoft Stream and Microsoft Viva. Over the next few months, it will also be possible to share an entire SharePoint page via email.

The post SharePoint is Getting a New Copilot Experience and Other Updates appeared first on Petri IT Knowledgebase.

View Details

Windows Local Administrator Password Solution (Windows LAPS) is a powerful tool that allows organizations to better manage and protect their local administrator account passwords on Windows devices. This feature is available on Azure Active Directory-joined or Windows Server Active Directory-joined devices. In this article, I will explain how to configure Windows LAPS in an Azure Active Directory scenario and how to manage it from Microsoft Entra, the company’s new identity and access management platform.

Windows LAPS vs. Microsoft LAPS: What’s the difference?Windows LAPS is currently in public preview, with much of the capability available for all Azure Active Directory (Azure AD) customers. While the legacy Microsoft LAPS is still available for download, Windows LAPS offers several advantages over its predecessor.

  • Firstly, Windows LAPS is an entirely separate implementation that is native to Windows.
  • Windows LAPS also includes several new features not available in legacy Microsoft LAPS, such as the ability to back up passwords to Azure AD, encrypt passwords in Windows Server Active Directory, and store password history.
  • Since Windows LAPS is now included in Windows, additional licensing is not required to take advantage of it. It’s also possible to use with the Azure AD free tier, meaning Azure AD Premium licensing is not required.

The vast adoption of legacy Microsoft LAPS over the previous decade means that this new solution will need to offer a migration procedure that’s as simple as possible. The migration process that Microsoft recommends to organizations is a side-by-side approach: They can run both solutions in parallel until the migration to the new Windows LAPS is complete.

The new native Windows LAPS capabilities are included in the April 2023 Patch Tuesday updates, and they support the following editions of Windows and Windows Server:

  • Windows 11 (Pro, Education, Enterprise)
  • Windows 10 (Pro, Education, Enterprise)
  • Windows Server 2019
  • Windows Server 2022

If you’re using any of these versions of Windows and you’ve installed the April 2023 security updates, you’re ready to go and start configuring Windows LAPS. There’s no separate installer or agent required! However, while Windows LAPS is now built-in, you will likely need to use a configuration tool such as a Group Policy Object (GPO), ConfigMgr, or Intune to manage configurations on the client.

Before we get started with the configuration of Windows LAPS, you should be aware that Microsoft has acknowledged two potential regressions related to interoperability with legacy LAPS scenarios. “If you install the legacy LAPS agent on a device patched with the April 11, 2023 security update and an applied legacy LAPS policy, both Windows LAPS and legacy LAPS will enter a broken state where neither feature will update the password for the managed account,” Microsoft explained. As of this writing, the company is already working on a fix for this issue.

Windows LAPS configuration in an Azure AD ScenarioWindows LAPS for Azure AD joined devices can be configured with just a few clicks. We’ll start by enabling the feature tenant-wide. Microsoft recommends using the Microsoft Entra portal for the best experience.

Enabling Windows LAPS from the Microsoft Entra admin center* Browse to the Microsoft Entra admin center select choose Go to Azure Active Directory

Accessing Azure AD settings on the Microsoft Entra portal (Image credit: Petri/Dean Ellerby) From Azure AD, choose DevicesAll Devices*.

Accessing Device settings for Azure AD (Image credit: Petri/Dean Ellerby) Here, open the Device settings* menu.

Azure AD join and registration settings (Image credit: Petri/Dean Ellerby) Scroll down to the Local Administrator Settings (preview) section. * Toggle the slider for Enable Azure AD Local Administrator Password Solution (LAPS)* to Yes.

Enabling Azure AD Local Administrator Solution (LAPS) (Image credit: Petri/Dean Ellerby)Once enabled at the Azure AD tenant level, we can move to Intune and explore the various methods to configure Windows LAPS.

Configuring Windows LAPS within IntuneHere are the different ways to configure Windows LAPS within Intune.

  • Windows Powershell with the Azure AD Powershell Module.
  • Deploying a custom Open Mobile Alliance – Uniform Resources (OMA-URI) profile that uses a Windows Configuration Service Provider (CSP).
  • The Intune settings catalog.
  • A rich native Intune configuration profile.

Depending on your use case, you may choose any one of the above options to configure Windows LAPS for Azure AD joined devices. In this guide, however, I’ll show you how to do that using a rich native Intune configuration profile.

  • From the Microsoft Intune admin center, choose Endpoint Security:

Accessing Endpoint security settings in the Intune admin center (Image credit: Petri/Dean Ellerby) Next, click on Account Protection*.

The Account protection page is where you can create a policy (Image credit: Petri/Dean Ellerby) On this page, click on Create Policy*.

Let’s create a policy to configure Windows LAPS (Image credit: Petri/Dean Ellerby) In the platform dropdown menu, choose Windows 10 and later*.

Our Intune profile will target Windows 10 and later (Image credit: Petri/Dean Ellerby) In the Profile box, choose Local admin password solution (Windows LAPS)*.

Choosing Windows LAPS for our Intune profile (Image credit: Petri/Dean Ellerby) Click on Create* when you’re done.

(Image credit: Petri/Dean Ellerby) Now, you’ll have to enter a name and description for your profile and click Next*.

(Image credit: Petri/Dean Ellerby) In the Configuration settings* tab, configure the policy as required using the reference table below

| Setting | Description | Default | Options | | --- | --- | --- | --- | | Backup Directory | Use this setting to configure which directory the local admin account password is backed up to. | Disabled (password will not be backed up). | – Disabled (password will not be backed up).– Backup the password to Azure AD only.– Backup the password to Active Directory only. | | Password Age Days | Use this policy to configure the maximum password age of the managed local administrator account. | 30 | 1 to 365 for AD7 to 365 for Azure AD | | Administrator Account Name | Use this setting to configure the name of the managed local administrator account. Note: This option does not create an account, it only determines which account is to be managed if present. | If not specified, the default built-in local administrator account will be located by a well-known SID (even if renamed). | | Password Complexity | Use this setting to configure the password complexity of the managed local administrator account. | Large letters + small letters + numbers + special characters | – Large letters – Large letters + small letters – Large letters + small letters + numbers– Large letters + small letters + numbers + special characters | | Password Length | Use this setting to configure the length of the password of the managed local administrator account. | 14 characters | 8char to 64char | | Post Authentication Actions | Use this setting to specify the actions to take upon expiration of the configured grace period. | Reset the password and log off the managed account. | – Reset password: upon expiration of the grace period, the managed account password will be reset. – Reset the password and log off the managed account.-Reset the password and reboot. | | Post Authentication Reset Delay | Use this setting to specify the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions. | 24 hours | 0 (disabled) to 24 hours |

Table showing Configuration Name, Description, Default value and Possible value Once you’ve chosen the right configuration, click Next*.

Configuring settings for our Intune profile (Image credit: Petri/Dean Ellerby) On the Scope tags screen, assign any scope tags that are required and click Next*.

You can assign any scope tags to your profile (Image credit: Petri/Dean Ellerby) On the Assignments page, choose the groups of users or devices to be targeted, or choose All Devices. Click Next* when you’re done.

Choosing the groups of users or devices to be targeted by our profile (Image credit: Petri/Dean Ellerby) Finally, choose Review & Create* to complete the creation of your Windows LAPS profile in Intune

Manage Windows LAPS from Microsoft EntraAfter creating our Windows LAPS profile in Intune, we can manage it from the Microsoft Entra profile. Here, we’ll be able to see the list of all devices that have Windows LAPS configured.

From the Microsoft Entra admin center, we’ll go back to the Devices page of the Azure AD section.

  • From the Azure AD section on the left, click on All Devices.

(Image credit: Petri/Dean Ellerby) Next, Click on Local Administrator password recovery (Preview)*.

Opening the Local Administrator password recovery (Preview) screen (Image credit: Petri/Dean Ellerby)The Local Administrator password recovery (Preview) screen shows a list of all devices that have Windows LAPS configured, and it contains the following fields for each device.

  • Device name: The name of the Azure AD device. This is also a link to the Azure AD device.
  • Local administrator password: This field includes a link to show the local administrator password.
  • Last password rotation: Date/time that the password was last changed.
  • Next password rotation: Date/time that the password will be changed next.

Checking settings for devices that have Windows LAPS configured (Image credit: Petri/Dean Ellerby) To view a device’s local administrator password, choose Show local administrator password. * A new pane will appear with the same details seen in the table. From here, choose Show:*

Showing a local administrator password (Image credit: Petri/Dean Ellerby)* Here, you can see the local administrator password:

The local administrator password has been revealed (Image credit: Petri/Dean Ellerby)Manage Windows LAPS with IntuneWhile Microsoft Intune can be used for the initial configuration of Windows LAPS, it can also be leveraged to perform key actions related to Windows LAPS. For example, in the Devices blade of the Intune admin center, you can rotate the local admin password for a device that is managed by Windows LAPS.

You can rotate the local admin password for a device managed by Windows LAPS in Intune (Image credit: Petri/Dean Ellerby)It is also possible to view the Local admin password in the Intune console, bypassing the need to use the Azure AD admin center or the Microsoft Entra admin center. To do that, you can simply choose the Local admin password in the Monitor section for the managed device:

You can view the Local admin password in the Intune console (Image credit: Petri/Dean Ellerby)Why you need to manage access to Windows LAPSFor a number of reasons, it’s important to strictly control access to the LAPS feature for admins in the environment. Microsoft has leveraged the native and built-in role based access control (RBAC) capabilities in Azure AD and Intune to ensure organizations can limit access to the feature.

Lastly, if you’re not ready to enable Windows LAPS in your environment yet, you can also start experimenting with it with the new emulation mode. When you’re ready to move away from the legacy Microsoft LAPS, you can choose to migrate over to the new features gradually.

The post How to Configure Windows LAPS in an Azure Active Directory Scenario appeared first on Petri IT Knowledgebase.

View Details

This month, as promised, we’re seeing the Microsoft Power Platform lean into AI enhancements. Many of these new AI-powered features are genuinely useful, and they should certainly improve as users provide feedback to the company.

As I always advise, you shouldn’t use experimental features in production apps, but once they cross the threshold to preview, that means that Microsoft is going to be rolling them out to all users in the future. Certainly, you should try out experimental features in non-production apps to get a feel for them yourselves. Anyway, let’s peek at some of the new Power Platform features introduced in April 2023.

Improved variables and collections experience in Canvas DesignerThe Power Apps Canvas Designer now includes a side-rail tab for variables and collections. Much like how the “Tree viewer” allows the selection of individual controls, you can now select your variable and then view the code where it’s defined and used in your app. Selecting the code section also brings it up in your formula bar for easy editing. This function allows you to view variables of all types, including collections, without leaving your canvas screen.

The new variables pane in Canvas Designer (Image credit: Microsoft)Power Apps gets better at implicit type conversionPower Apps has just gotten smarter at what Microsoft is calling “implicit type conversion,” or “coercion.” What does that mean? It means that you won’t need to define the specific data type for your function anymore.

Power Apps is now smart enough to attempt to figure out when you need to do a mathematical calculation and understand when your data is a value vs. a text. In other words, you will not always have to wrap textual numerals in a Value() so that the formula recognizes you want to use the number 3 and not the text character 3.

Formulas and mathematical operators will also be able to hazard a guess whether your data is Boolean(), Value(), or Text() based on the context of your formula. You may still need to help define it in some more complex formulas, but this is a positive step forward when you’re trying to incorporate untyped objects (such as JSON) into your formulas.

This feature, though still experimental (you must enable ParseJson function and untyped objects), should move to Preview soon.

Microsoft expands access to Copilot in Power AppsYou may have seen my demo in the last month related to using Copilot for Power Apps where I use natural language to create a working app. Microsoft is now making these Copilot capabilities available to builders on a sign-up basis. That, and the other new experimental features that rolled out in the March 2023 update are summarized on the Power Apps blog.

Comments in Power Apps and Power AutomateMicrosoft just announced the general availability of comments in Power Apps and Power Automate. Just as in other Microsoft products, comments can now assist users in collaborative app/automation building in Canvas Studio, Modern App Designer, and Power Automate.

Comments are now generally available in Power Apps (Image credit: Microsoft)A look at Power Automate’s “Describe it to design it” future updatesThere’s not much else to update this month regarding Power Automate, but Stephen Siciliano, VP of Power Automate gave us a look-ahead at the work that the Power Automate team is doing to enhance their Describe it to design it feature which rolled out last October. Specifically, they are fine-tuning their Azure OpenAI models based on our usage.

Interestingly, the exec provided a stat revealing that 76% of the flows within a week’s time ran at least once, vs. a mere 43% when created by scratch, or 64% when created via template. So, this is an indicator that developers are successfully using them with more room for growth. Rest assured, Microsoft is going to continue developing the Copilot feature for Power Automate and plans on releasing more features for it in the coming months.

PowerBI updatesIn the PowerBI realm, we mentioned last month that you can now use the new On-Object Interaction feature, which is currently in preview. Microsoft has been busy incorporating our feedback into this feature as they continue to enhance it.

Also, if you have been using the opt-in experimental Quick Measure Suggestions feature based on Azure OpenAI, you should be aware that it’s now enabled by default. Microsoft is pretty confident that using the power of AI in converting natural language into DAX is going to be something that we’ll all appreciate!

The post What’s New With Microsoft’s Power Platform in April 2023 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a new version of the OneDrive web app for business and education customers. The company highlighted today that the updated app will include a new home experience that reduces the time required to find important files and documents.

With this release, the OneDrive web app is getting a new “For you” section that leverages AI-powered file recommendation features to surface personalized and relevant content. Microsoft plans to roll out the feature in the coming months.

“We’ve also added rich, context-based organization, such as views that show you recent, shared, and favorite and files from meetings. These views help you get back to content quickly. And lastly, inline activity updates let you catch up on files at a glance or jump right to comments in files that you want to address,” the OneDrive team explained.

Shared viewMicrosoft is adding a new Shared view to the OneDrive web app. The new feature will provide a central hub to view all internal and external files shared with the OneDrive user. The company will begin rolling out the new Shared experience later this quarter.

People viewAnother important update for OneDrive is a new People view that will let users organize files by people and view recent file activity. Users will be able to pin specific people to the top of the page for easier access. The new People view will be available in the OneDrive web app later this year.

New meetings view and other updates coming to OneDrive Microsoft is also introducing a new Meetings view that will let users view files shared through notes, online meetings, and Microsoft Loop. Moreover, the OneDrive web app is getting the ability to filter PowerPoint, Excel, Word, and PDF files. There is also a new customization feature that will let users change the color of the folders in OneDrive. Other capabilities include offline support and a new sharing experience.

Filter specific file types in OneDriveLast but not least, the OneDrive web app will let users create File Shortcuts links and pin certain files as Favorites. Microsoft also announced today that the new features will also make their way to the Files app in Microsoft Teams.

The post Microsoft OneDrive to Get New Web Experience with AI-Powered File Recommendations appeared first on Petri IT Knowledgebase.

View Details

Microsoft has detailed a bunch of new features added to its Windows Autopatch service in May 2023. The company explained that this is the most “impactful” update since Windows Autopach was launched back in May 2023.

Windows Autopatch is a cloud-based service that enables IT admins to automate the patching of Windows, Microsoft 365 apps, Microsoft Teams, and Microsoft Edge. Microsoft highlighted that its Windows Autopatch has helped businesses to save more than $1 million. These include $470,000 in on-site infrastructure costs and $848,000 in efficiency improvements.

“The theme of this release is responding to real enterprise needs – all because we’ve heard from Autopatch customers and would-be customers about what they want from the service. So here they are: new capabilities, controls, and reports, all geared towards helping IT administrators improve security and productivity with less effort,” Microsoft explained.

Up until now, the deployment of Windows feature updates was a resource-intensive process for organizations. The latest Windows Autopatch update gives customers greater control over feature updates on client devices. Microsoft says that IT admins can configure updates to specific Windows Autopatch groups called “Deployment rings” within their tenant. It’s also possible to roll out these updates in a staggered manner.

Windows Autopatch gets policy health alerts and new notificationsMicrosoft has introduced support for alerts and notifications about missed and modified policies in Windows Autopatch. This release lets IT admins view and track the details within the Tenant Management section. They can initiate action for the Autopatch service to restore policies and deployment rings without raising an incident.

Lastly, Microsoft has released some updates to improve the reporting experience for both feature and quality updates in Windows Autopatch. It provides a summary view of current status as well as trending or current views.

Microsoft added that the new Windows Autopatch updates are available in public preview for customers. The company will continue to test these features before making them generally available for all organizations. We invite you to check out the official blog post for more details.

The post Windows Autopatch May 2023 Update Adds Support for Autopatch Groups appeared first on Petri IT Knowledgebase.

View Details

Microsoft has partnered with Stripe, PayPal, and GoDaddy to launch a new Payments app for Microsoft Teams. The app allows small businesses in the US and Canada to accept payments for webinars, one-on-one sessions, classes, appointments, and events within Teams meetings.

“We have partnered with leading players in the payments space to combine the core collaboration capabilities in Teams with powerful commerce features in this first-of-its-kind app. With a mutual focus on helping SMBs prosper, we are excited to partner with GoDaddy, PayPal, and Stripe to make it even easier for customers to interact with you and help you get paid faster,” said Brenna Robinson, GM of Microsoft 365, Small and Medium Business.

Microsoft mentioned that the new Payments app is aimed at 11 million small businesses that use Microsoft Teams. This app could be useful for various professionals such as consultants, teachers, and real estate agents.

Microsoft’s new Payments app is available to download from Microsoft’s AppSource repository. Once installed, customers can configure the app to connect with any third-party payment provider. Then, users can send payment requests, and customers can use their digital wallet, debit or credit card, or other methods to send money. It’s also possible to track received and outstanding payments in Microsoft Teams.

Microsoft Teams Payments app to get integration with GoDaddyThe new Payments app is available for free in public preview for Teams Essentials ($4 per month) and Microsoft 365 business (from $6 per month) subscribers based in the US and Canada. As of this writing, the Payments app only supports PayPal and Stripe, with GoDabby integration coming in the near future.

Microsoft has teamed up with Small Business Association to celebrate National Small Business Week (NSBW) in the United States. As a part of the celebration, Microsoft is offering a 15 percent discount for the first full year of Microsoft 365 Business and Microsoft 365 Business Standard subscriptions. However, the limited-time offer is only valid for purchases made through Microsoft’s official website.

The post Microsoft Teams Meetings Now Let Small Businesses Request Payments from Clients appeared first on Petri IT Knowledgebase.

View Details

Last week, Google announced account synchronization support for its Authenticator app. On April 25, the security research team Mysk highlighted on Twitter that the feature lacks support for end-to-end encryption (E2EE).

The security researchers found that the network traffic used to sync the credentials is not end-to-end encrypted. This means that the seed used to generate 2FA codes is transmitted in a format that is likely visible to both Google and attackers. The researchers warned that there is no setting that allows users to protect their synced 2FA codes.

Additionally, Google could potentially use the information linked to users’ accounts to show personalized advertisements. The security researchers recommended that users should not enable the new syncing feature until it adds support for end-to-end encryption.

Google product manager Christiaan Brand announced on Twitter that its Authenticator app will gain support for end-to-end encryption. However, he emphasized that users should not be concerned because the company encrypts data in transit and at rest across all its products.

“To make sure we’re offering users a full set of options, we’ve started rolling out optional E2E encryption in some of our products, and we have plans to offer E2EE for Google Authenticator down the line,” Brand explained. “Right now, we believe that our current product strikes the right balance for most users and provides significant benefits over offline use. However, the option to use the app offline will remain an alternative for those who prefer to manage their backup strategy themselves.”

Use Google Authenticator offline or without syncAs of this writing, Google has not provided an ETA for bringing end-to-end encryption to the new account syncing feature in Google Authenticator. In the meantime, users can get around the security issue by continuing to use Google Authenticator in offline mode or without Google Account sync.

The post Google Authenticator to Get End-to-End Encryption Support appeared first on Petri IT Knowledgebase.

View Details

Amazon has announced the general availability of its AWS Verified Access service. The service enables IT admins to provide secure access to enterprise applications without using a Virtual Private Network (VPN).

AWS Verified Access originally launched in public preview in November at AWS re:Invent 2022.
The service allows customers to create, configure and manage a collection of policies and criteria for accessing private applications. The feature provides an additional layer of security to prevent users from sharing corporate data through insecure VPN servers.

“Built using AWS Zero Trust principles, customers can use Verified Access to reduce the risks associated with remote connectivity. IT administrators and developers can define fine-grain access per application using real-time contextual signals, including identity and device posture. Verified Access also simplifies security operations. Customers can manage policies for each application all in one place,” Amazon explained.

Benefits of Verified AccessAmazon highlighted several advantages of its AWS Verified Access service, including security posture improvement. It evaluates each application access request to grant access to users that meet specific security requirements. AWS Verified Access also integrates with identity and device management services to maintain access logs. It should make it easier for administrators to troubleshoot issues.

AWS Verified Access gets two new featuresAmazon has also added two new security features to AWS Verified Access. The service is getting a new AWS Web Application Firewall (WAF) integration to block application-layer attacks (such as SQL injection) targeting web applications. It helps to protect various resources such as AWS App Runner service, Amazon CloudFront distribution, and Application Load Balancer.

Additionally, AWS Verified Access supports passing signed identity context (email, username, and other attributes) to application endpoints. It’s possible to use the context to personalize applications.

AWS Verified Access is currently available for all enterprise customers, and you can get started today on the official website. Amazon says that users will be charged for each application on Verified Access, and the amount of data processed by the service.

The post AWS Launches New Verified Access Service to Replace VPN appeared first on Petri IT Knowledgebase.

View Details

In relational databases like SQL Server, the SQL JOIN statement is used to query, connect and retrieve data from multiple tables based on data relationships between those tables. You can use the SQL JOIN statement with two or more tables, and it essentially returns records that have matching values in the different tables. In this tutorial, I will explain how to use the most common SQL JOIN types including the SQL INNER JOIN, the SQL LEFT JOIN, the SQL RIGHT JOIN, and the SQL OUTER JOIN.

SQL Joins are an essential feature to use when working with relational databases. They are mainly executed using the SQL SELECT statement. You can learn more about getting started with the T-SQL SELECT statement in my previous SQL Servers article: Using SQL SELECT and the WHERE and HAVING Clauses to Retrieve Data.

SQL INNER JOINThe SQL INNER JOIN operation creates a result set by combining rows that have matching values in two or more tables. This is probably the most commonly used join operation in T-SQL. SQL INNER JOIN only returns rows that have matching values, and it’s used to retrieve data that appears in all tables.

The following diagram illustrates how an SQL INNER JOIN operation works with two tables.

How an SQL INNER JOIN operation works with two tables (Image credit: Petri/Michael Otey)The syntax for an INNER JOIN is pretty straightforward. As part of your SELECT statement, you specify the two tables to join and the columns to use to match rows.

Let’s take a closer look at two tables from the AdventureWorksLT2019 sample database. If we use the SalesLT.Customer and SalesLT.SalesOrderHeader tables, we can use an SQL INNER JOIN to retrieve the orders for the customers in the SalesLT.Customer table by joining the two tables on the CustomerID column, which is a common column in both tables.

Here’s the T-SQL query you can use to accomplish that:

USE AdventureWorksLT2019SELECT c.CustomerID, c.FirstName, c.LastName, soh.SalesOrderID, soh.OrderDate FROM SalesLT.Customer cINNER JOIN SalesLT.SalesOrderHeader soh ON c.CustomerID = soh.CustomerID Here’s how the syntax for the SQL INNER JOIN works:

  • Here, you can see we’re selecting the ‘CustomerID’, ‘FirstName’, and ‘LastName’ columns from the SalesLT.Customer table, and the ‘SalesOrderID’ and ‘OrderDate’ columns from the SalesLT.SalesOrderHeader table.
  • The ‘c’ and ‘soh’ are shorthand table aliases that eliminate the need to always use the full table name when referring to columns.
  • We’re using the INNER JOIN keyword to join the two tables. The ON keyword specifies the column to use for the join. Here it’s the ‘CustomerID’ column.

This query will return a result set that includes the ‘CustomerID’, ‘FirstName’, ‘LastName’, ‘SalesOrderID’, and ‘OrderDate’ columns for each customer who has placed an order, as you can see in the following figure.

The result of our SQL INNER JOIN query (Image credit: Petri/Michael Otey) SQL LEFT JOINThe SQL LEFT OUTER JOIN operation will also create a result set by matching rows between our two previous tables. With the SQL LEFT JOIN, however, if no records match from the left table, it will show those records with null values.

This is useful when you want to include all rows from the first table and only the matching rows from the second table, even if there’s no match in the right table. The SQL LEFT OUTER JOIN will return null values in columns from the right table if there’s no match.

The following diagram illustrates how an SQL LEFT OUTER JOIN operation works with two tables.

How an SQL LEFT OUTER JOIN works with two tables (Image credit: Petri/Michael Otey)The syntax for the LEFT JOIN is also fairly simple. As part of the SELECT statement, you specify the two tables to join, the columns to use to match rows, and the LEFT JOIN clause.

Let’s take a closer look at two tables from the AdventureWorksLT2019 database. For example, to retrieve all customers and any orders they have, you can use the SalesLT.Customer and SalesLT.SalesOrderHeader tables and perform a LEFT JOIN as you can see in the following listing:

USE AdventureWorksLT2019SELECT c.CustomerID, c.FirstName, c.LastName, soh.SalesOrderID, soh.OrderDateFROM SalesLT.Customer c LEFT JOIN SalesLT.SalesOrderHeader soh ON c.CustomerID = soh.CustomerID * In this example, we’re selecting the ‘CustomerID’, ‘FirstName’, ‘LastName’, ‘SalesOrderID’, and ‘OrderDate’ columns from the SalesLT.Customer and SalesLT.SalesOrderHeader tables. * We’re using the LEFT JOIN keyword to join the two tables and the ON keyword that we will be using in the ‘CustomerID’ column to join the two tables.

You can see the results of this SQL LEFT JOIN query in the figure below.

The results of our SQL LEFT JOIN query (Image credit: Petri/Michael Otey)This query will return a result set that includes all customers in the SalesLT.Customer table, along with any corresponding order information from the SalesLT.SalesOrderHeader table. If a customer does not have any orders in the SalesLT.SalesOrderHeader table, then the columns from that table will be null. You can see several null values in the previous figure.

SQL RIGHT JOINAs you might guess, the SQL RIGHT OUTER JOIN operation is essentially the opposite of the LEFT OUTER JOIN. The RIGHT OUTER JOIN selects data from the right table (Table 2) and matches this data with the rows from the left table (Table 1).

The RIGHT JOIN returns a result set that includes all rows in the right table, even if they do not have matching rows from the left table. If a row in the right table does not have a matching row in the left table, then the result set for the columns from the left table will be null.

The following diagram illustrates how a right JOIN works with two tables:

How a right JOIN works with two tables (Image credit: Petri/Michael Otey)We can show this with the SalesLT.Customer and SalesLT.SalesOrderHeader from the AdventuresLT2019 database. To retrieve all orders and their corresponding customer information, you can use a RIGHT JOIN query as you can see in the following example:

USE AdventureWorksLT2019SELECT c.CustomerID, c.FirstName, c.LastName, soh.SalesOrderID, soh.OrderDateFROM SalesLT.Customer c RIGHT JOIN SalesLT.SalesOrderHeader soh ON c.CustomerID = soh.CustomerID * In this example, we’re selecting the ‘CustomerID’, ‘FirstName’, ‘LastName’, ‘SalesOrderID’, and ‘OrderDate’ columns from the SalesLT.Customer and SalesLT.SalesOrderHeader tables. * The RIGHT JOIN keyword is used to join the two tables, and the ON keyword specifies that we’re joining the two tables on the ‘CustomerID’ column.

This query will return a result set that includes all orders in the SalesLT.SalesOrderHeader table, along with their corresponding customer information from the SalesLT.Customer table if it’s available. If an order does not have a corresponding customer in the SalesLT.Customer table, the customer columns in the result set will be null.

You might notice this query is very much like the preceding query. However, the LEFT JOIN resulted in many rows from the SaleOrderHeader table that had null values. However, our last query has no null values in the rows from the SaleOrderHeader table.

The results of our SQL RIGHT OUTER JOIN operation are shown in the following figure.

The results of our SQL RIGHT OUTER JOIN operation (Image credit: Petri/Michael Otey)SQL OUTER JOINSQL OUTER JOIN is not the most common type of join operation. Sometimes called a FULL JOIN, the OUTER JOIN query will not only retrieve the matching rows but the unmatched rows as well. In other words, it returns data from the joined table when there is a match in either the left or right tables.

As you might guess, this tends to produce larger result sets than the other join types. The following diagram illustrates how an SQL OUTER JOIN works with two tables.

How an SQL OUTER JOIN works with two tables (Image credit: Petri/Michael Otey)I’ll give you an example of an SQL OUTER JOIN operation using the SalesLT.SalesOrderHeader and SalesLT.SalesOrderDetail tables. Here, we want to retrieve all sales orders and their associated details, including orders that don’t have any details records.

To do this, we can use a FULL OUTER JOIN. This will also return any SalesOrderDetail rows that didn’t have a corresponding SalesOrderHeader row. In most normal cases all SalesOrderDetails rows should have a corresponding SalesOrderHearder row but this might not be the case if there has been an application or system error which this can help detect.

Here’s a T-SQL query showing an example FULL OUTER JOIN:

USE AdventureWorksLT2019SELECT soh.SalesOrderID, soh.OrderDate, sod.ProductID, sod.OrderQty, sod.UnitPriceFROM SalesLT.SalesOrderHeader sohFULL OUTER JOIN SalesLT.SalesOrderDetail sodON soh.SalesOrderID = sod.SalesOrderID * In this example, we’re selecting the ‘SalesOrderID’, ‘OrderDate’, ‘ProductID’, ‘Quantity’, and ‘UnitPrice’ columns from both the SalesLT.SalesOrderHeader and SalesLT.SalesOrderDetail tables. * We’re using the FULL OUTER JOIN keyword to join the two tables, and the ON keyword to specify that the SalesOrderID column will be used to join the two tables. * This query will return a result set that includes all sales orders in the SalesLT.SalesOrderHeader table, along with their corresponding detail information from the SalesLT.SalesOrderDetail table. It will also include all details in the SalesLT.SalesOrderDetail table, along with their corresponding order header information if it’s available. * If a sales order does not have any details in the SalesLT.SalesOrderDetail table, then the columns will be NULL. If a detail does not have a corresponding sales order in the SalesLT.SalesOrderHeader table, then the sales order columns will be NULL.

The results of this FULL OUTER JOIN operation are shown in the following figure.

The results of our FULL OUTER JOIN operation (Image credit: Petri/Michael Otey)Learning SQL Join fundamentalsIn this tutorial, I covered the most common different types of SQL JOINS. I showed how to use the INNER JOIN, the LEFT JOIN, the RIGHT JOIN, and the OUTER JOIN, and I also explained how they are different and where they can be used. In an upcoming post, I’ll be covering some of the less common joins like the CROSS JOIN and the SELF JOIN, so stay tuned to Petri!

The post SQL Server Essentials: Using SQL Joins appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced some new capabilities for its Azure Virtual Desktop service. The top requested feature should help organizations to enhance endpoint security, configuration, storage, and employee experience.

Microsoft has introduced FSLogix profiles support for Azure AD-joined VMs in Azure Virtual Desktop. The feature lets users access file shares from Azure AD-joined VMs in order to store FSLogix profile containers. The VHD Disk Compaction feature lets users automatically decrease the storage space of a user’s container during the sign-out process.

“Next, we’ve added a new process during the sign-out phase which creates an AppX package manifest for employees. This enables faster app launch experiences the next time they sign in as the manifest is used to re-register the AppX applications. And lastly, when employees delete data from a session, we now roam their Recycle Bin which allows them to restore it from another session,” Microsoft explained.

Configure new endpoint security policiesMicrosoft has announced the general availability of Microsoft Intune user scope configuration for Azure Virtual Desktop multi-session Virtual Machines (VMs). The feature enables IT Pros to configure user certificates, PowerShell scripts, and settings catalog.

Azure Virtual Desktop Insights at scaleAdditionally, Azure Virtual Desktop Insights at Scale feature is now generally available for customers. The feature provides a central hub to view insights from different resources. For instance, IT admins can simultaneously monitor diagnostic and connection details for multiple subscriptions.

Security featuresMicrosoft has added watermarking support in public preview on Azure Virtual Desktop. The security feature is designed to protect sensitive information shared on client devices. It’s now possible to enable private endpoint access for workspaces and session hosts within a virtual network. Microsoft has also introduced RDP Shortpath support to enhance the transport reliability of Azure Virtual Desktop connections.

Microsoft Teams application window sharing support for Azure Virtual DesktopLastly, Microsoft Teams application window-sharing support is generally available for Azure Virtual Desktop. Previously, it was only possible to share a Microsoft PowerPoint Live presentation or full desktop during Teams meetings. This capability enables users to share a specific window directly from their desktop screens. Microsoft also released a new Multimedia Redirection (MMR) feature to improve the video playback experience on Azure Virtual Desktop.

The post Azure Virtual Desktop Adds New Security Features, Storage Enhancements appeared first on Petri IT Knowledgebase.

View Details

Apache Superset has released fixes to patch a security flaw in the default configuration that could lead to remote code execution. Tracked as CVE-2023-27524, the vulnerability allows threat actors to potentially steal sensitive data, harvest credentials, and then execute malicious code.

Apache Superset is an open-source data exploration and virtualization solution. It enables users to create interactive dashboards, graphs, and charts based on NoSQL databases, SQL databases, flat files, and other data sources. Apache Superset provides various advanced analytics capabilities such as ad-hoc data analysis, custom SQL queries, and integration with machine learning models.

In a recent advisory, Security firm Horizon3.ai explained that Apache Superset signs authentication session cookies with a default Flask Secret Key. The attacker could use the value of the default key to generate and sign cookies for authentication purposes.

“The security of the web application depends critically on ensuring the SECRET_KEY is actually secret. If the SECRET_KEY is exposed, an attacker with no prior privileges could generate and sign their own cookies and access the application, masquerading as a legitimate user,” explained Naveen Sunkavally, Chief Architect at Horizon3.ai.

Horizon3.ai releases script to discover the Apache Superset flawThe security firm found that around 2,000 vulnerable Superset instances relied on the default configuration, including government agencies, corporations, and universities. As a result, any attacker with administrative privileges can log in to the vulnerable servers. The researchers notified some organizations to address the vulnerability and protect their enterprise networks.

Horizon3.ai has released a script to help IT admins find vulnerable Apache Superset instances in their organization. “It’s commonly accepted that users don’t read documentation and applications should be designed to force users along a path where they have no choice but to be secure by default,” Sunkavally added. “The best approach is to take the choice away from users and require them to take deliberate actions to be purposefully insecure.”

The post Apache Superset Auth Bypass Flaw Exposes Vulnerable Servers to RCE Attacks appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced some new updates for its Microsoft Sentinel solution this week. The company has highlighted a new Workspace Manager feature, Hunts feature to identify security threats, and other improvements.

Specifically, Microsoft Sentinel is getting a new Workspace Manager that enables IT admins to manage multiple Sentinel workspaces from a central workspace. The feature supports both single and multi-tenant scenarios with Azure Lighthouse. However, Workspace Manager is ideal for multitenant customer management scenarios that deal with distributed workloads.

Microsoft explained that the Workspace Manager supports various active content types. These include workbooks, analytics rules, automation rules (excluding Playbooks), hunting and livestream queries, as well as Parsers, Saved Searches and Functions.

Microsoft Sentinel Workspace Manager architectureMicrosoft Sentinel’s Workspace Manager offers three different architectures to accommodate different scenarios. For instance, Direct-link provides a central workspace that lets IT admins control all member workspaces. Moreover, Co-Management is designed for situations requiring more than one central workspace to manage a member workspace. N-Tier supports complex scenarios that involve hierarchical controls.

Microsoft notes that customers will need at least two Microsoft Sentinel workspaces to use Workspace Manager. It also requires the Microsoft Sentinel Contributor role assignment for managing central and member workspaces. Microsoft has provided a step-by-step guide to enable the Workspace Manager feature on the central workspace.

Microsoft Sentinel to get new Hunts feature in MayMicrosoft is also planning to add a new Hunts threat-hunting feature in Microsoft Sentinel next month. It will allow security analysts to generate bookmarks, custom hunting queries, and security-researcher-generated hunting queries to improve investigations.

“With the upcoming public preview in May 2023 of the new “Hunts” feature we are providing a first step towards an end-to-end hunting experience within Microsoft Sentinel by allowing customers to keep track of new, active, and closed hunts in one place,” Microsoft explained.

Lastly, Microsoft has announced the public preview of a new DNS Essentials Solution. It’s designed for DNS security scenarios and supports Cisco Firewall, Zscaler Internet access (ZIA), GCP DNS, Windows Server DNS, and other DNS products.

The post Microsoft Sentinel Gets New Workspace Manager and Hunts Feature appeared first on Petri IT Knowledgebase.

View Details

This Week in IT, Editorial Director Russell Smith looks at the new AI features in Microsoft Designer, which has just entered public preview. Plus, Microsoft is hoping to simplify security in Microsoft 365 with a new cloud.microsoft domain for apps and services, Windows Laps now gets support for Azure AD joined devices in public preview, plus Phone Link is rolling out to Windows 11 users with iOS support.

The post Microsoft Designer Public Preview, Windows LAPS Support for Azure AD, and More… appeared first on Petri IT Knowledgebase.

View Details

If you’re an IT pro working with Active Directory, you can use Group Policy to configure the Windows environments of your users’ computers and your enterprise servers using Group Policy Objects (GPO). However, the struggle to reach an intuitive and secure environment is real. In this article, I will explain how to create a GPO, and how to link, delete, and disable them. When we’re done, you should better understand the nuances of the wonderfully complex world of Group Policy.

Working with GPOsThere are two ways to work with GPOs: You can either use the Local Group Policy Editor to adjust the policies on a local computer or use the Group Policy Management Console (GPMC) to work on your enterprise environment. Because local policies are processed first (before domain policies) and to sustain and design a robust environment, we will focus on the enterprise scenario in this article.

Installing the Group Policy RSAT ToolThe Group Policy Management Console is part of the traditional Remote Server Administration Tool (RSAT) toolset. It is an MMC-based (Microsoft Management Console) tool that is installed with the modern Windows Settings app in Windows. I’ll show you how to install it next.

On a domain controller (DC), Group Policy settings are stored in the ‘SYSVOL’ shared folder and replicated to all other DCs in the domain (and forest, if you are set up that way). This describes the built-in redundancy of Group Policy infrastructure.

To show you how to install the Group Policy Management Console tool, I’ll be using my Hyper-V lab running a Windows Server 2022 Active Directory domain. I have logged into my Windows 10 version 22H2 workstation, so let’s get started:

  • First, click the Start button and type in ‘optional‘.

Searching for ‘optional’ features in the Start Menu (Image credit: Michael Reinders) Click on ‘Manage optional features‘ and click the ‘+ Add a feature‘ button at the top. * Scroll down and put a checkmark in ‘RSAT: Group Policy Management Tools‘ and click Install*.

Selecting the Group Policy Management RSAT toolset (Image credit: Michael Reinders) After that is complete, click Start and open ‘Windows Administrative Tools.’ * Double-click on ‘Group Policy Management*.’

Locating Group Policy Management in Administrative Tools (Image credit: Michael Reinders)Now we see the Group Policy Management console. Here, we are introduced to the overall structure of how Group Policy is laid out and how you can target specific logical entities in your organization.

The Group Policy Management Console (Image credit: Michael Reinders)At this point, IT Pros, with the consultation of their security and compliance teams can do any of the following:

  • Modify existing Group Policy Objects (GPOs)
  • Create new GPOs
  • Modify the filtering of specific GPOs at a group level
  • Use WMI Filtering to target specific computers
  • Use Group Policy Modeling and results to ‘test’ or perform ‘What-If’ scenarios

Next, we’ll start with creating a new GPO.

Create GPOLet’s create a new setting that will demonstrate how to modify your users’ computers in another way.

  • First, I will right-click on ‘Domain Windows Computers‘ and click ‘Create a GPO in this domain, and Link it here…

Starting a new GPO in Domain Windows Computers (Image credit: Michael Reinders) I will name it ‘Start Menu Cleanup‘ and click OK*.

Naming our new GPO (Image credit: Michael Reinders) Then, I will right-click on the new GPO and click Edit.*

Our new GPO – ready to configure settings! (Image credit: Michael Reinders) Let’s browse to Computer Configuration -> Policies -> Administrative Templates -> Start Menu and Taskbar*.

We’ve found our settings category for our Domain Windows computers (Image credit: Michael Reinders) Here, I will double-click on Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands*.

Modifying a policy setting (Image credit: Michael Reinders) After reading the Help, I’ll toggle Enabled on and click OK*.

Adjusting settings with our ‘Start Menu Cleanup’ GPO (Image credit: Michael Reinders)Now, be advised, this setting is now live in the environment. Every computer object in that OU will see these settings during the next refresh. By default, domain computers and servers will process Group Policy every 90 minutes with a 30-minute random offset. However, when testing (and troubleshooting), the gpresult command is your friend.

You can also force the computer to update Group Policy on the machine by running the following gpupdate command in your favorite terminal/shell. This will process all Group Policy changes for the computer and the logged-in user. The ‘/force’ switch forces the changes without request for approval.

gpupdate /force Using gpupdate /force to process all related group policies right away (Image credit: Michael Reinders)Ok, changes have now been processed. Let me right-click on the Start button and go to the Shut down or sign out menu, and… it worked! Those items we set to remove are now hidden.

The Shut Down, Restart, Sleep, and Hibernate commands are now hidden (Image credit: Michael Reinders)This rather simple change prevents your users from restarting or shutting down their computers. Obviously, there are a lot of variables and use cases for settings like this. It is ideal in some situations and painful in others. This is the balance you’ll go through as an IT Pro to decide what works best for your organization.

Link GPOLet me show you how to link an existing GPO to a specific location in Active Directory. In a previous lifetime, I created a GPO called ‘Domain Controller Security Lockdown.’ The settings in this GPO contain security compliance standards for domain controllers per our company’s guidelines. I can easily link these new settings to the DCs in my domain – reinders.local.

  • First, I right-click on the Domain Controllers OU and select Link an existing GPO.

Linking an existing GPO to a container in AD (Image credit: Michael Reinders) Next, I will choose Domain Controller Security Lockdown from the list and click OK*.

We linked an existing GPO to the Domain Controllers OU (Image credit: Michael Reinders)Now you can see that GPO is linked to domain controllers. The next time our DCs check for Group Policy updates, they will process the settings in that GPO. That’s the beauty of the central control you have. Create and craft a group of settings once, then deploy (link) it easily to a container in your environment. You’re done!

Modify an existing GPOLet’s look at my domain – reinders.local – and see what we have.

As this is a lab, it is rather basic, almost primitive. In larger enterprises, it is not uncommon to discover hundreds or thousands of GPOs in a single domain. The complexity of inheritance of some GPOs, using WMI to target specific operating systems, dealing with local GPOs, child OUs, and local policies in the mix – all of it can be quite daunting.

As an aside, the sheer number of GPOs in your domain will start to dictate some overall performance penalties when computers start up and when users log in. This is probably the biggest debate today: Do you create a bunch of GPOs and only include one setting in each of them for ease of manageability? Or do you create a handful of GPOs with your policy changes to cut down processing time? This could be an article all on its own!

GPO scopeI previously installed Windows Server Update Services (WSUS) – there’s my GPO for the setup – ‘WSUS_Config_01’. If I click on it, you’ll see the scope defined.

The settings for our ‘WSUS_Config_01’ GPO (Image credit: Michael Reinders)The location is at the root of the domain (reinders.local). This means, by default, EVERY computer and server object in the domain will see and implement this GPO. Again, there are ways to filter out specific users, computers, OUs, and security groups. More on this later.

Here, the Security Filtering section shows the Authenticated Users group. This is almost saying ‘Everyone’: Any account that has authenticated to the domain will see this GPO.

WMI FilteringThe WMI Filtering setting below is where you can target specific SKUs. For example, you could target a specific WSUS installation to only touch Windows 10 version 21H2 and 22H2 computers.

Using the WMI Filtering capability is straightforward (Image credit: Michael Reinders)Edit GPOLet me show you how to edit a GPO.

  • First, right-click on the GPO you want to and to modify and click ‘Edit…

This is the initial screen after choosing to Edit a GPO (Image credit: Michael Reinders) A new window will open showing you the logical layout – Computer Configuration and User Configuration trees. * To locate the WSUS settings, expand Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Windows Update. * Here, you can see there are two settings ‘Enabled’ or configured. Let’s open up Configure Automatic Updates.*

The settings for ‘Configure Automatic Updates’ (Image credit: Michael Reinders)This is a more involved setting, but you get the gist. These are the settings for how Windows Updates are applied to my domain. Rather granular, wouldn’t you say? But, the point here is you can manage all of your computers (or a subset) centrally here.

Here is an example of how GPOs “lock down” settings on computers. Did you notice the ‘Install updates for other Microsoft products‘ option checked at the bottom? If I check Windows Update -> Advanced options on this workstation, note that the first setting, ‘Receive updates for other Microsoft products when you update Windows’ is now controlled by Group Policy.It is marked On and is greyed out.

The 1st item is now controlled by Group Policy (Image credit: Michael Reinders)This is precisely what the “Some settings are managed by your organization” blurb signifies on top. Technically, it states that some Group Policies have been applied to this computer and you can’t adjust the setting.

Managing the default GPOsTwo GPOs are created when a new domain is created – ‘Default Domain Policy’ and ‘Default Domain Controllers Policy.’ At the minimum, these will dictate the domain password policies, account lockout policies, Kerberos policies, basic security options, and other network security options.

For decades, it has been strongly held that, as an IT pro, you should NOT modify these 2 policies – you should create new GPOs instead. There are several reasons for this, but I believe the most fundamental is that when troubleshooting your domain, you have a knowing that this default config has not been changed.

This has often been the first question out of Microsoft Technical Support when I’ve worked with them over the years on issues in Active Directory/Group Policy. They know those core settings and need to start there, at the bottom of the ocean, to make sure their inherent baseline is accurate.

So, that is also my recommendation on how you should manage the default GPOs – DON’T!

Disable a GPOIf you want to disable a GPO and prevent its settings from applying to future computers, simply right-click on the GPO and click Link Enabled. That will remove the link and set the GPO to a “dormant” state.

After clicking the ‘Link Enabled’ checkbox, the GPO is now disabled (Image credit: Michael Reinders)Delete a GPOIf you are performing cleanup and/or troubleshooting, you can delete a GPO by right-clicking on it and clicking Delete. To be thorough and efficient, I recommend you go to the Group Policy Objects view in the tree and delete it from there.

Deleting a Group Policy Object (Image credit: Michael Reinders)ConclusionImplementing Group Policy is deceptively simple… at first. It is rather easy to lay out your Group Policy Objects infrastructure. Confirming, validating, and later, troubleshooting why specific computers’ Office installations are updating on their own and others prompt the user… that’s where the fun begins.

All in all, the moral of the story is quite simple: Test, Test, Test! The more you can validate and get compliance in the beginning, the more efficient and streamlined your environment will be. Easier for troubleshooting and enabling new policies.

Please leave a comment below if you have any questions!

The post Managing Group Policy Objects: Create GPOs, Link GPOs, and Edit GPOs appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced updates for its Windows 11 and Windows 10 support roadmaps yesterday, and the biggest news is that a Long-Term Servicing Channel (LTSC) version of Windows 11 will be released in the second half of 2024. This should be good news for organizations that have been waiting to upgrade their PCs to Windows 11 before Windows 10 reaches end of support in 2025.

The Redmond giant also revealed yesterday that Windows 10 version 22H2, the latest feature update for the OS released back in October 2022 will be the final version of the OS. In other words, there won’t be a 23H2 update for Windows 10 later this fall.

Windows 11 LTSC is coming in the second half of 2024For organizations waiting for a Windows 11 LTSC release, Microsoft said that Windows 11 Enterprise LTSC and Windows 11 IoT Enterprise LTSC will be available in the second half of 2024. The company plans to share more details closer to release.

LTSC editions of Windows are best used on special use devices that don’t need to receive updates as frequently as other devices. LTSC versions of Windows also receive updates for a longer period of time.

Microsoft is already recommending organizations preparing to upgrade their PC fleets to Windows 11 to start testing their apps on devices using Windows 11 version 22H2. “It’s important for organizations to have adequate time to plan for adopting Windows 11,” the company emphasized.

Windows 10 version 22H2 will be the final version of the OSIt’s almost the end of the road for Windows 10, an OS released back in July 2015. Microsoft confirmed that Windows 10 version 22H2 will be “the final version of Windows 10,” and it will reach end of support on October 14, 2025.

Until that date, Windows 10 will continue to receive monthly security updates, but the OS won’t receive any new features. The writing was already on the wall when Microsoft didn’t announce any new features in Windows 10 version 22H2 last fall.

Even though support for Windows 10 will end on October 2025, that won’t be the case for LTSC versions of the OS. Windows 10 Enterprise LTSC 2021 will be supported until January 12, 2027, while Windows 10 IoT Enterprise LTSC 2021 will reach end of servicing on January 13, 2032.

The post Microsoft to Release Windows 11 LTSC in the Second Half of 2024 appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that its App Governance add-on will soon be a part of the Microsoft Defender for Cloud Apps service. Starting on June 1, the feature will be available for all customers with an E5 Security/Microsoft 365 E5 or any other subscription at no additional cost.

Microsoft highlighted that threat actors are increasingly targeting enterprise customers with app-based attacks. The App Governance add-on is a security feature that enables organizations to protect OAuth-enabled apps connected to Azure Active Directory (Azure AD). It provides actionable insights to give IT admins complete visibility into how third-party apps access sensitive data stored in Microsoft 365 services.

“Because we are seeing a continued rise in app-based attacks, we believe this is a foundational capability for customers. That’s why today, we are excited to announce that going forward the App Governance add-on will be included in Defender for Cloud Apps at no additional cost. On June 1, 2023, new and existing customers will be able to start the opt-in process to begin using these capabilities,” Microsoft explained.

How does the App governance add-on work?The App Governance add-on provides a single dashboard that enables IT admins to view, react, and respond to the apps’ status and alert activities. It also lets them create governance policies for app and user patterns to block non-compliant or malicious applications. App Governance provides detection and mitigation strategies to protect end users against suspicious in-app activities and risky apps.

Microsoft will cancel subscriptions for all existing App Governance customers on June 1. The company confirmed that this change will not impact the current App Governance experience. However, Microsoft didn’t mention any details about refund or compensation policies. If you’re interested, you can learn more about App Governance capabilities on this support page.

The post Microsoft Defender for Cloud Apps to Get App Governance Add-On in June appeared first on Petri IT Knowledgebase.

View Details

Today, Microsoft Designer goes into public preview and it adds new A.I. features. Like Canva, Designer offers a collection of templates and elements like graphics, photos, and video so that you can easily create eye-catching content for your social media channels.

What is Microsoft Designer?Essentially a clone of popular graphic design tool Canva, Microsoft Designer brings drag-and-drop design features allowing you to quickly create designs for social media content, like Instagram posts and Facebook ads. Microsoft Designer was originally announced at the Ignite conference in October 2022.

Use Microsoft Designer to create visuals and social media posts using A.I.One key difference with Canva is that the free version of Microsoft Designer lets you create graphics using a natural language model driven by Artificial Intelligence. For example, you could ask it to draw a YouTube thumbnail for a video about Microsoft Designer. If you don’t like the results, you can give the A.I. more context and slowly have it refine the design for you.

It’s worth noting that natural language generative A.I. could become a premium feature when Designer is made generally available.

If you would prefer to get started without the help of A.I., you can work with a blank canvas from where you can drag elements, such as photos and illustrated graphics, to build your perfect design.

Microsoft Designer AI generates captions, hashtags, and copy also part of the dealA.I. isn’t just used in the visuals. Microsoft has also included tools that harness A.I. to help you quickly generate captions, hashtags, headlines, and other text for your social media posts. It can even go as far as to suggest which fonts to use.

Repurposing content with automatic resizingThe resize features automatically moves elements in your design to accommodate different canvas sizes. If you manage more than one social media channel, you will be familiar with the different dimensions and aspect rations for each platform. The resize tool is designed to help you repurpose content originally intended for one set of dimensions to be quickly refactored to work with another.

AnimationsDesigner can also help you bring your designs alive by adding animations.

Microsoft Designer is coming to the Edge browserMicrosoft says that it is gradually rolling out Designer to the Edge sidebar. And whether you want it or not, Edge will be the first browser to natively include an integrated AI-powered graphic design app. Although it looks like it won’t be enabled on the sidebar by default.

Like other sidebar apps in Edge, you can use Microsoft Designer without leaving the webpage your currently on. The idea being that if you are creating a social media post, you can use Designer to create it without having to download a browser extension or switch apps to get the job done.

PricingWhen Microsoft Designer reaches general availability, there will be a free version and a premium version available to consumers with Microsoft 365 Personal and Family subscribers. There’s no mention of whether Microsoft 365 business subscribers will need to pay extra to get access to the premium features.

Features lined up for the futureMore A.I. features are on the horizon for Designer. Including the ability to automatically remove backgrounds and lift out a foreground subject using a feature called Erase. You can also replace a background with something more to your liking.

You will be able to expand backgrounds to fill a canvas without stretching the original image. Microsoft notes that this is just the start for Designer and it plans more features going forward.

Microsoft Designer vs CanvaMicrosoft Designer has a limited set of templates in the current preview. And in turn, that means limited support for social media content. But I expect that to change over the coming months.

Canva has plenty of A.I. features too. But the free version doesn’t allow you to use generative A.I. to create designs from scratch and then tweak them using natural language. You’ll need the Pro subscription for access to that feature in Canva.

Canva is also expanding to become something more akin to Microsoft 365, offering a suite of applications. It’s new Visual Worksuite brings Docs, Whiteboards, Presentations, Social Media, Video, Print, and Websites to the table. Visual Worksuite is behind a paywall. And I don’t expect it will be possible for Canva to challenge Microsoft 365 in the enterprise space.

You can try out the public preview of Microsoft Designer for free here.

The post Microsoft Designer Enters Public Preview with New A.I. Features appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released the optional April 2023 security patches for Windows 11 versions 21H2 and 22H2. The optional updates (KB5025298 and KB5025305) address interoperability issues between Windows LAPS and legacy LAPS policies.

Microsoft recently announced the native integration of Windows LAPS (Local Administrator Password Solution) on Windows 11, Windows 10, and Windows Server 2019. The tool allows IT Pros to manage passwords on Windows Server Active Directory-joined and Azure Active Directory-joined devices. It helps administrators to regularly rotate and backup passwords to on-premises Active Directory.

Microsoft highlighted that the native integration eliminates the need to download and install an MSI file to use the Windows LAPS tool. Moreover, Windows LAPS gets serviced monthly like all other Windows components.

However, many IT admins found that installing the latest Patch Tuesday updates break the new Windows LAPS and legacy LAPS tools. Microsoft acknowledged the issue and provided a temporary workaround solution. Thankfully, Microsoft has now released an update to address the Windows LAPS interoperability bug on Windows 11 PCs.

“This update addresses an issue that affects the legacy Local Administrator Password Solution (LAPS) and the new Windows LAPS feature. They fail to manage the configured local account password. This occurs when you install the legacy LAPS .msi file after you have installed the April 11, 2023, Windows update on machines that have a legacy LAPS policy,” Microsoft explained.

Install Windows 11 preview updates to fix compatibility issues between Windows LAPS and legacy LAPS policiesIf you’re running Windows 11 22H2 or Windows 11 21H2, you can install the update by going to Settings >> Update & Security >> Windows Update. Keep in mind that users who skip the updates will get these fixes with the May 2023 Patch Tuesday update for Windows 11.

In related news, Microsoft has announced a public preview of Windows Local Administrator Password Solution (LAPS) for Azure AD joined and hybrid Azure AD joined devices. The company says that IT admins can perform the initial Windows LAPS setup through the Azure Portal.

The post Latest Windows 11 Update Fixes Windows LAPS Interop Issues appeared first on Petri IT Knowledgebase.

View Details

Group Policy is an infrastructure feature in Active Directory that allows IT pros to manage their users’ Windows environments and servers. In this article, I will explain in detail what is Group Policy, what is a Group Policy Object (GPO), and how to adjust the policy settings to meet your security needs and compliance requirements. Creating a streamlined and consistent user experience is a beautiful plus.

What is Group Policy?Group Policy was released with Active Directory back in 1999 with the release of Windows 2000 Server. It was developed to provide enterprises with a secure and streamlined method to facilitate a consistent desktop experience for users (and servers).

You use Group Policy to control the environment of user and computer accounts. This is the most important distinction of how Group Policy was developed – User (based) policies and Computer (based) policies.

  • User policies (user configuration) are applied when a user logs in to a computer on the domain.
  • Computer policies (computer configuration) are applied during computer startup.

Separating these two core buckets allows IT admins to target specific user settings and computer settings, separately, including group policy preferences.

What is a Group Policy Object (GPO)?A Group Policy Object (GPO) is a collection of Group Policy settings and configurations. Essentially, they are a prettier front-end to modify the registry in Windows.

We all know how cumbersome, unintuitive, and dangerous it can be to modify the registry with Registry Editor. For these impactful reasons, Group Policy was developed.

The most basic functions a GPO modifies are password policies, allowing only specific users to connect to a specific group of servers via the Remote Desktop Protocol (RDP), and blocking or restricting users from specific shares. These settings manipulate how a system will look, how it will operate, and how it will behave for a somewhat granular group of users.

GPOs are generally created to target organizational units (OUs). Every user and computer object in a specific OU will apply these policy settings. There is a somewhat staggering number of flags and switches you can set to make sure what order these settings are used. I’ll get to that later.

What are some examples of what Group Policy can control?There are a dizzying number of settings that Group Policy supports. Let me give you some examples:

  • Deploying operating systems and other software to all or specific groups of computers/servers.
  • Running computer startup scripts and user logoff scripts.
  • Changing everyone’s desktop background wallpaper.
  • Adding a disclaimer after user login explaining unauthorized use is prohibited.
  • Configuring the local Windows Defender Firewall policies and settings.
  • Restricting access to Control Panel and Settings.
  • Block the command prompt.

How do you access Group Policies?To manage the local group policy objects on a single computer, you can use the Local Group Policy Editor. To manage Group Policies at the Active Directory domain level, the default common native tool is the Group Policy Management Console.

The Local Group Policy EditorGenerally, you can open the Start Menu and search for ‘group policy‘ to access the Local Group Policy Editor. This a snap-in for the Microsoft Management Console (MMC) that you can use to configure and modify Group Policy settings within Group Policy Objects.

Accessing Local Group Policy Editor on Windows 11 (Image credit: Petri/Michael Reinders)The Group Policy Management ConsoleTo access the Group Policy Management Console, you can use the Microsoft Management Console (MMC) to access it. Even though you can log in to a domain controller to access this tool, that’s generally a ‘No-no.’ It’s best to install it on a local computer or workstation running Windows 10 or Windows 11.

The Group Policy Management Console (Image credit: Petri/Michael Reinders)I have a separate article explaining how to install the Group Policy Management Console coming very soon!

Permissions and delegation for GPOsYou need to be a member of the Administrators group in an Active Directory domain to create and edit GPOs. There is also a global group called Group Policy Creator Owners. They can also create GPOs; however, they can only modify policies that they have created themselves.

To avoid IT pro burnout, or if your company has more robust compliance requirements around duty ownership, you can delegate these permissions using the Delegation feature in the Group Policy Management Console. This also helps to segment certain admins so they only have the keys to a specific OU or group of OUs.

As an example, a specific desktop support group could get delegated access to the ‘Workstations’ OU levels to handle all the Office and application-specific settings on your desktops.

GPO processing and linkingA key aspect of how Group Policy works is how they are linked in Active Directory and in what order they are processed. The complexity here can vary wildly. This starts the discussion on ‘who wins when a conflict occurs?’

This is the order that GPOs are applied to users and computers:

  1. Local GPOs (single computer) or local policies
  2. Site
  3. Domain
  4. Organizational Unit (OU)

The settings further down in the list will win any conflicts. This means that GPOs linked to an OU will get final precedence. Also, each GPO has what’s called a Link Order. The lowest link order is processed last and wins any conflicts that arise.

Contextual properties on a Group Policy Object (Image credit: Petri/Michael Reinders)Troubleshooting issues after linking a GPO to an OUAnother thought around troubleshooting – you can create a new GPO, link it to an OU, go to a workstation to update Group Policy, and then validate the outcome. If the desired outcome is NOT found, a quick tip is to ‘unlink’ the GPO.

Right-click on it and click the ‘Link Enabled‘ checkbox to uncheck it. After you click the ‘Link Enabled’ checkbox/toggle, the GPO is not linked. It will NOT be processed!

Unlinking a GPO can help to troubleshoot issues (Image credit: Petri/Michael Reinders)Child OUs and GPO inheritanceUnless you make any changes when creating your GPOs, child OUs will inherit all GPOs from their parent. To offer some granularity here, you can block inheritance to stop a GPO from applying to a child OU.

This is as simple as right-clicking on the OU/container and selecting ‘Block Inheritance.’ This will tell Group Policy not to process GPOs further up in the hierarchy.

Blocking Inheritance on a GPO (Image credit: Petri/Michael Reinders)If there are any GPOs linked at the domain level, they will not be processed in the ‘Citrix Test Users’ OU. This provides a clean environment for, you guessed it, testing!

Enforcing a GPOAnother important topic in GPO processing is enforcement. By default, the settings in parent OUs are overwritten by settings in GPOs from child OUs.

If you right-click on a specific GPO and click Enforced, that GPO’s settings will be the end all, be all. This will make sure these settings get processed even if ‘Block Inheritance’ is in effect.

Enforcing a GPO will make sure it gets processed (Image credit: Petri/Michael Reinders)You can use the Group Policy Modeling wizard at the bottom of the menu to simulate GPOs to troubleshoot this very topic. This is where you enter a specific user container or user account and a specific computer container or computer object, and tell Group Policy to simulate what the end result is and what GPOs would apply. This will show all GPOs that apply, why some GPOs would not apply (permissions, WMI Filtering, etc.), and what the ‘winning GPO’ is for each group policy setting.

The Group Policy Modeling Wizard (Image credit: Petri/Michael Reinders)Group Policy loopbackThe last item I want to mention is lookback processing of Group Policy. This is a specific type of group policy setting that allows you to apply user policies to computers.

When this is enabled, Group Policy processes settings to a computer as if a user was logged in. It’s an excellent troubleshooting tool when you are trying to determine why a specific setting is not applying as expected.

Adjusting the ‘Group Policy Loopback’ processing mode (Image credit: Petri/Michael Reinders)Security and change control for GPOsA very important part of the process when implementing Group Policy is to keep it robust and under control. This should include some sort of security framework, on paper and in action.

  1. You need to be aware of who can create, modify, and delete certain GPOs.
  2. Educate your IT pros on how GPOs are created and saved.
    • When you modify a specific setting in GPMC, it goes ‘live’ immediately. A computer or server could conceivably see that and incorporate that setting within seconds or minutes!
    • Be firm about leaving the Default Domain policy and Default Domain Controllers policy objects.
  3. Change Control platform. Incorporate auditing on your domain controllers using the security event log to audit changes to Group Policy Object changes.
  4. Invest in a software solution that ‘takes control’ over Group Policy administration, such as GPOADmin from Quest Software.

Group Policy is an integral aspect of your IT infrastructureGroup Policy has been near the top of the heap of IT pros’ biggest headache lists for many years. If Group Policy is generally straightforward in design and nature, it can be extremely difficult to troubleshoot due to the mishandling of complex frameworks of GPOs.

Hopefully, you’ve gained a greater understanding of how it works and what the basics of Group Policy entail. Please feel free to leave a comment or question below and thank you very much for reading!

The post What is Group Policy? appeared first on Petri IT Knowledgebase.

View Details

Microsoft announced this week that it’s planning to move its various Microsoft 365 web apps to a unified cloud.microsoft domain. This should really help to simplify access to Microsoft 365 apps and services on the web as the various subdomains Microsoft currently uses result in an inconsistent experience for users.

“As Microsoft cloud services have grown over the years, the domain space they live on has grown as well – into the hundreds. Over time, this fragmentation has created increasing challenges for end user navigation, administrative simplicity, and the development of cross-app experiences,” the Microsoft 365 team explained yesterday.

Microsoft has too many different domains (image credit: Microsoft) Microsoft obtained exclusive rights for the .microsoft top-level domain, which will help to ensure trustworthiness. However, the company opted to use the cloud.microsoft unified domain to provide access to its various Microsoft 365 apps in a consistent and secure manner.

“There are also anti-spoofing and integrity benefits to hosting such experiences on an exclusive, purposefully-managed TLD like .microsoft vs. a generic TLD like .com,” the company explained. This is also why the company didn’t want to make any changes to its microsoft.com domain, which will continue to be exclusively used for marketing, support, and e-commerce.

How the unified cloud.microsoft domain will work.Soon, instead of using outlook.office365.com to access the Outlook web app and teams.microsoft.com to access the Teams web app, users will need to visit outlook.cloud.microsoft and teams.cloud.microsoft, respectively. Microsoft says that this will be a gradual transition and that “only net-new services” will be deployed on the cloud.microsoft domain initially.

The software giant will notify customers at least 30 days in advance when it plans to transition a Microsoft 365 web app to the new cloud.microsoft domain. This will allow organizations to make necessary changes to their network configuration.

“In most cases, no customer action will be needed to continue using Microsoft 365 workloads the same way you do today,” the Microsoft 365 team said. Microsoft will also implement long-term redirects to make sure that existing links and bookmarks will redirect users to the new domain.

The post New cloud.microsoft domain Will Simplify Access to Microsoft 365 Web Apps appeared first on Petri IT Knowledgebase.

View Details

MC546489 – Microsoft has released updates to the following update channel for Microsoft 365 Apps:

  • Current Channel

When this will happen:

Microsoft will be gradually rolling out this update of Microsoft 365 Apps to users on that update channel starting April 25th, 2023 (PST).

How this will affect your organization:

If your Microsoft 365 Apps clients are configured to automatically update from the Office Content Delivery Network (CDN), then no action is required.

If you manage updates directly you can now download this latest update and begin deployment.

What you need to do to prepare:

To get more details about this update view the following release notes:

  • Current Channel

Additional information

The post M365 Changelog: Updates available for Microsoft 365 Apps for Current Channel appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started rolling out support for personal accounts in its Microsoft Loop app on mobile devices. Indeed, the company announced yesterday that the feature is now available in preview on iOS and Android.

Microsoft officially launched its new Loop app in public preview in March this year. The app provides a real-time collaboration experience that lets teammates work together on tasks, documents, and projects. It allows users to share specific pieces of content (like Loop components, pages, and workspaces) with both internal and external users.

Microsoft Loop comes with new AI-powered features with the integration of the Microsoft 365 Copilot tool. The app makes it easier to keep projects organized and has integrations with other Microsoft services such as PowerPoint and Word.

Up until now, the Microsoft Loop app only supported work accounts on mobile devices. However, Microsoft promised that support for personal accounts would be available soon. Rebecca Keys, the project manager of Microsoft Loop, confirmed on Twitter that users can now access Microsoft Loop on Android and iOS.

Microsoft Loop opens a limited number of spots for iOS usersTo test the new support for personal accounts in Microsoft Loop, Android users will need to download the app from the Google Play Store. On iOS, Microsoft Loop is only available for select users who have enrolled in Apple’s TestFlight program.

Keep in mind the app is still under development, and users might encounter some unexpected issues. Microsoft invites testers to use the Loop app and provide their feedback and suggestions to enhance the overall experience. Do you use Microsoft Loop to organize work and collaborate on projects? Let us know in the comments section below.

The post Microsoft Loop Adds Support for Personal Accounts on iOS and Android appeared first on Petri IT Knowledgebase.

View Details

Microsoft is changing its Windows Server 2022 licensing policies to better compete with rivals. Earlier this month, the company quietly updated the Product Terms page with three major changes that should help organizations to reduce costs and drive cloud adoption (via The Register).

Microsoft explained that customers no longer need a minimum of 16 core licenses to use virtual machines (VMs) or the Azure Hybrid Benefit. Secondly, the company is easing the Azure Hybrid Benefit requirements to let customers align the licensed cores with the actual core count of their virtual machine. Until now, a 20-core virtual machine required three sets of eight licenses. However, IT admins no longer need to comply with these criteria while licensing a VM with more than 8 cores.

Microsoft has also updated licensing requirements for companies that buy Windows Server subscriptions via cloud service providers (CSPs). It’s now possible to use Standard licenses with Windows Server Datacenter virtual machines. This capability is available for customers running VMs in on-premises data centres or with Authorized Outsourcers.

Lastly, Microsoft notes that organizations won’t need Windows Server CALs or External Connector licenses to access Windows Server software managed by a CSP-Hoster partner.

Windows Server 2022 licensing changes aim to reduce costsMicrosoft is making these changes to maintain its Windows Server market share and better compete with open-source alternatives such as Linux. It’s important to note that many organizations are now running Linux distributions on Azure servers to reduce licensing costs. These new licensing terms are aimed at providing more value to customers.

It remains to be seen if these changes will help Microsoft to maintain its dominance in the cloud computing space. However, it’s great to see that the company is taking steps to remain competitive and adapt to the changing landscape.

The post Microsoft Changes Windows Server 2022 Licensing Policies appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced the public preview of its new Microsoft Defender for APIs solution. The new powerful tool enables organizations to improve the security and management of their “business-critical APIs.”

Microsoft explained that Defender for APIs is available as part of its Microsoft Defender for Cloud service. It’s a security solution that protects cloud-native applications against identity-based attacks.

“Now through the integration of Defender for APIs with Azure API Management, security teams can use the Defender for Cloud portal to gain visibility into these business-critical Azure APIs, understand their security posture, prioritize vulnerability fixes, and detect and respond to active runtime threats within minutes – using machine-learning powered anomalous and suspicious API usage detections,” Microsoft explained.

Microsoft’s new Defender for APIs solution enables IT admins to monitor all managed APIs in a single dashboard. It also leverages AI to analyze details about external, unused, or unauthenticated APIs. The feature makes it easier to detect security flaws and protect APIs in enterprise environments.

Additionally, Microsoft Defender for APIs enables administrators to monitor threat intelligence feeds and runtime traffic as well as access threat detection alerts. It provides security recommendations to let customers enhance their API security posture. This capability should help to harden API configurations to mitigate critical security risks. Other capabilities include API data classification that could be useful for risk prioritization tasks.

Microsoft Defender for APIs provides SIEM IntegrationMicrosoft Defender for APIs integrates with several security information and event management (SIEM) systems to facilitate threat mitigation activities. The service also provides seamless integration with the Cloud Security Graph in Defender Cloud Security Posture Management (CSPM).

Microsoft notes that IT admins can view security recommendations and alerts within the Azure Portal or Microsoft Defender for Cloud Portal. Microsoft Defender for APIs is available in preview for commercial customers in most Azure regions. Let us know in the comments below if you think that the tool will help security teams to protect, manage and optimize API infrastructures.

The post Microsoft Defender for APIs Now Available in Preview appeared first on Petri IT Knowledgebase.

View Details

Google has released a new much-awaited feature for its Authenticator app on Android and iOS. The latest update allows users to sync their two-factor authentication codes (2FA) to Google accounts.

Google launched its Authenticator app for mobile users back in 2010. It’s designed to help customers protect their online accounts with two-factor authentication (2FA). The app generates unique one-time passwords (OTPs) that let users securely log in to online services.

Until now, the Google Authenticator app used to store OTPs only on the primary device. This meant that if a user lost access to their device, they wouldn’t be able to access any of their accounts secured with the 2FA mechanism. This issue was a significant drawback of the app, and Google has finally taken steps to address the problem.

“With this update we’re rolling out a solution to this problem, making one time codes more durable by storing them safely in users’ Google Account. This change means users are better protected from lockout and that services can rely on users retaining access, increasing both convenience and security,” said Christiaan Brand, Group Product Manager a Google.

How to sync 2FA codes in Google AuthenticatorTo use the cloud syncing feature, Google Authenticator users will need to install the latest update from the App Store or Google Play Store. Once enabled, users will see a cloud icon at the top right corner of the screen. It indicates that all codes will be automatically backed up to users’ Google Accounts. However, keep in mind that the security feature is not available for everyone just yet.

Overall, the new cloud syncing feature is a great improvement that makes multifactor authentication more secure and convenient for customers. “While we’re pushing towards a passwordless future, authentication codes remain an important part of internet security today, so we’ve continued to make optimizations to the Google Authenticator app,” Brand added.

The post Google Authenticator Now Lets Users Back Up 2FA Codes to the Cloud appeared first on Petri IT Knowledgebase.

View Details

Microsoft has introduced several new features to its Microsoft Intune admin center. The company highlighted that these updates should help IT admins boost security and improve Defender Firewall management.

Microsoft announced that Windows Defender Application Control (WDAC) Application ID tagging support is now available with Intune Firewall Rules policy. It enables customers to scope firewall rules to a specific app or group of applications. The feature is currently available for Windows 11 devices, with support for Windows 10 version 20H2 (and newer) to follow later this month.

“The WDAC AppID functionality adds an administrator defined tag to the given process token. By using these tags, the Firewall Rules policy won’t need to rely on an absolute file path or use of a variable file path that can reduce the rule security. Use of this capability requires you to have WDAC policies in place, which include AppId tags,” Microsoft explained.

Microsoft has also added endpoint security firewall policy support for network list manager settings. This capability lets IT admin identify if an Azure AD device is connected to subnets within their on-premises domain. Moreover, it’s now possible to use the IcmpTypesAndCodes setting to set up inbound and outbound rules for Internet Control Message Protocol (ICMP). IT admins can access the setting in the Microsoft Defender Firewall rules profile on Windows Server, Windows 11, and Windows 10.

Finally, Microsoft released a new feature that enables administrators to configure firewall logging options in the endpoint security Firewall policy. The list of new settings includes Log File Path, Enable Log Success Connections, Enable Log Ignored Rules, and Enable Log Dropped Packets.

How to configure Windows Defender Firewall management settings in Microsoft IntuneMicrosoft notes that IT Pros can configure the new settings by heading to the Microsoft Intune admin center >> Endpoint security >> Firewall. They can access policy templates through Create policy >> Windows 10, Windows 11, and Windows Server >> Microsoft Defender Firewall or Microsoft Defender Firewall Rules. However, this security capability is not available for Windows machines with the Security Management for Microsoft Defender for Endpoint attach solution.

In related news, Microsoft announced that IT admins can now configure and manage Windows LAPS on Windows endpoints with Microsoft Intune. This capability is available in public preview for enterprise customers.

The post Microsoft Intune Gets New Windows Defender Firewall Management Features appeared first on Petri IT Knowledgebase.

View Details

The latest Linux kernel is now available, and it comes with some important new features. Linux Kernel 6.3 is a minor release and it shouldn’t cause any major problems when you get round to upgrading. But like any change you introduce into your environment, it should be properly tested.

So, let’s look at the most important features in this update.

  1. User-mode Linux support for RustRust support was added in Linux kernel 6.1, which was released back in December 2022. And this new release brings support for Rust code in user-mode. Essentially, these updates to the kernel make Rust an officially supported language for Linux kernel development, along with C as the primary language.

  2. Updated support for Intel and AMD CPUs and graphics hardwareThe updated kernel supports technology to be released in upcoming AMD and Intel CPUs and graphics processors. Although some of the changes will also affect current hardware. Kernel 6.3 supports AMD Indirect Branch Restricted Speculation (IBRS). It is a new mitigation for Spectre that doesn’t involve such a hit on performance compared to Retpoline speculative execution.

  3. ARM and RISC-V power managementRISC-V architectures now have accelerated string function support thanks to the Zbb bit manipulation extension, which aims to bring code size reduction, performance improvement, and energy reduction to the table.

And ARM gets Scalable Matrix Extension (SME) 2 instructions, which build on previous scalable vector extensions to add new capabilities and performance to improve matrix multiplications that are commonly used in scientific simulations, computer vision, and machine learning (ML) and augmented reality (AR) scenarios.

  1. Filesystem improvements for NFS, EXT4m, BRTFS, and EROFSNFS gets better encryption with the AES-SHA2 standard. There are direct I/O performance optimizations for EXT4, BRTFS now has a faster filesystem driver, and EROFS gets low-latency decompression.

  2. Networking improvementsKernel 6.3 adds support for Realtek RTL8188EU Wi-Fi cards and Qualcomm Wi-Fi 7 wireless chipsets. NVIDIA BlueField 3 Data Processing Unit (DPU), an infrastructure compute platform with line-rate processing of software-defined networking, storage, and security, gets Ethernet support. And there’s also multi-path TCP support for mixed IPv4 and IPv6 flows.

While the new Linux kernel is available now, if you want to use it, you’ll have to ‘roll your own’ by compiling it yourself. That is until your distro is updated to support kernel 6.3.

The post 5 New Features in Linux 6.3 Kernel appeared first on Petri IT Knowledgebase.

View Details

Amazon announced this morning some important updates for Amazon GuardDuty. The service has added support for Amazon EKS Runtime Monitoring, RDS Protection for Amazon Aurora, and Lambda Protection.

Amazon DutyGuard is a managed security monitoring service that uses machine learning to detect potential threats that can compromise Amazon Web Services (AWS) environments. It analyzes different data sources such as Amazon Virtual Private Cloud (VPC) Flow Logs, domain name system (DNS) logs, and AWS CloudTrail for potentially unauthorized and malicious activities.

“GuardDuty’s new capabilities build on this powerful foundation to expand security detection and monitoring even further, to where customers tell us they need it most: containers’ runtime monitoring, databases, and serverless applications. We’ve now more than tripled the number of managed detections since we introduced GuardDuty,” said Jon Ramsey, VP for Security Services at AWS.

Amazon GuardDuty has introduced support for Amazon EKS Runtime Monitoring. The feature leverages a GuardDuty security agent to offer insights about network connections, process execution, file access, and other container runtime activities. It helps customers to identify and monitor compromised EKS clusters and privilege escalation attempts.

With Amazon GuardDuty RDS Protection, IT admins can detect potential threats to sensitive data stored in Aurora databases. The feature analyzes and profiles RDS login activity to detect security risks like suspicious logins and high-severity brute force attacks. IT Pros can view the threat alerts in the GuardDuty console as well as via other services like Amazon Detective, AWS Security Hub, and Amazon EventBridge.

Amazon GuardDuty adds Lambda Protection support Lastly, Amazon GuardDuty is getting support for Lambda Protection. The security feature makes it easier for customers to identify and mitigate security risks in serverless applications. Lambda Protection provides real-time monitoring of network activity logs to detect suspicious network traffic, including unauthorized cryptocurrency mining.

Amazon explained that the new threat detection capabilities are available for GuardDuty customers in most AWS regions. You can find more details about Amazon GuardDuty on the official AWS website.

The post Amazon GuardDuty Gets New Threat Detection Capabilities appeared first on Petri IT Knowledgebase.

View Details

Last week, Canonical announced the release of Ubuntu 23.04. The latest version of its Linux distribution includes improved Azure Active Directory support, a new desktop installer, and other enterprise-focused features.

Codenamed Lunar Lobster, Ubuntu Desktop 23.04 provides native user authentication with Azure Active Directory (Azure AD). This release enables Microsoft 365 enterprise customers to authenticate their Ubuntu Desktops with a common set of credentials. Canonical will continue to listen to user feedback before backporting Azure AD support to Ubuntu 22.04 Long-Term Support (LTS) later this year.

“This Ubuntu milestone release demonstrates our progress in raising the bar for the enterprise developer desktops, thanks to our best-in-class Linux integration with Active Directory (AD) Domain Services and now Azure Active Directory,” explained Canonical CEO Mark Shuttleworth.

Canonical also announced that the latest release adds support for the Active Directory Bridging Toolsuite’s Samba winbind domain service. It lets customers use Ubuntu with AD on Amazon Workspaces and older AD configurations. Other capabilities include support for network shares, app confinement, and enterprise proxy. However, keep in mind that some enterprise features may require an Ubuntu Pro license.

Ubuntu 23.04 adds a new installer and snap improvementsUbuntu Desktop 23.04 adds a new desktop installer called Subsiquity. It’s a streamlined installer designed to help IT admins with enterprise deployment and image customization at scale. Canonical has introduced an updated Snap package manager that allows users to download updates in the background and install them automatically when the desktop app is closed.

Last but not least, Ubuntu Desktop 23.04 brings improved toolchains and runtimes for all popular programming languages such as C++, .Net, Java, and Python. The latest distribution also comes with enhanced debugging support and container security and lifecycle management capabilities.

Canonical notes that Ubuntu 23.04 is available to download for free on the Ubuntu website. If you’re interested, we invite you to check out the official blog post to learn more about the aforementioned features.

The post Canonical Releases Ubuntu 23.04 with Azure Active Directory Support appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced a public preview of Windows LAPS with Microsoft Entra Azure Active Directory. The new long-awaited feature enables IT admins to rotate and backup passwords using Azure Active Directory.

Windows Local Administrator Password Solution (LAPS) is a tool that enables IT admins to automatically manage and back up passwords for local administrator accounts. Previously, Windows LAPS was only available as a standalone solution for enterprise customers.

Microsoft has recently unveiled that the tool is now natively integrated into Windows and Windows Server devices. The native version brings support for automatic password rotation, password history, and password encryption. It helps to minimize the risk of password theft as well as Pass-the-Hash (PtH) and lateral traversal attacks.

Windows LAPS management via Microsoft Intune available in previewWith this release, Microsoft is making Windows LAPS available for Azure AD joined and hybrid Azure AD joined devices managed by Microsoft Intune. It enables IT admins to store passwords in Microsoft Azure, recover them, and configure settings via Microsoft Intune. It’s also possible to view audit logs, create Azure AD role-based access control (RBAC) policies, and configure Conditional Access policies.

“Windows LAPS has been revamped to integrate into the Windows platform to securely rotate and backup passwords using Microsoft Entra, Azure Active Directory (Azure AD). IT admins can use the first-class management experiences built into Intune to configure Windows LAPS and leverage the capabilities that are now available,” the Intune Support team explained.

Windows LAPS for Azure Active Directory: Configuration and License requirementsTo get started, customers will need an Azure Active Directory and Microsoft Intune subscription. IT admins should also ensure that the latest April cumulative update is installed on Windows 10 or 11 devices. We invite you to check out a full list of prerequisites on this support page.

Microsoft notes that Windows LAPS with Azure Active Directory capabilities are available in preview for customers with Azure AD free or higher licenses. Currently, the feature only supports Windows devices that are joined to Azure AD or Hybrid Azure AD. It’s not available for use with Azure AD-registered devices and non-Windows platforms.

Microsoft has recently confirmed that the native version of Windows LAPS is causing interoperability issues with legacy LAPS. The company is working on a fix, and it recommends customers to either uninstall legacy LAPS or delete all values available under the HKLM\Software\Windows\CurrentVersion\LAPS\State registry key.

The post Microsoft Announces Windows LAPS Support for Azure AD Joined Devices appeared first on Petri IT Knowledgebase.

View Details

MC544789 – Microsoft has disabled the Dynamic Ordering feature for classic search experiences in SharePoint. While the UI for the feature is still present, all configurations associated with this feature are ignored.

When this will happen:

The UI will be removed by June 1, 2023.

How this affects your organization:

Dynamic Ordering is a classic search sorting feature which appeared in the SharePoint Query Builder dialog. The Query Builder dialog may be accessed three ways:

  1. as part of configuring a web part,
  2. configuring a result source,
  3. configuring a Query Rule with a query re-write action.

The Dynamic Ordering feature appears in the “Sort” tab of the dialog. The Dynamic Ordering feature allowed promotion or demotion of items in search results through configuration, by adding XRANK clauses to the query request.

What you can do to prepare:

Functional parity may be achieved by adding XRANK clauses directly to the query template in the Query Builder dialog.

This change does not affect the modern search experience, except for Site Scoped search queries which trigger Query Rules defined in the SharePoint Search Admin UI at the tenant level which added Dynamic Ordering rules.

As part of the evolution of the Microsoft 365 service, Microsoft periodically evaluates the capabilities of the service to make sure that we’re delivering the utmost value to customers. As Microsoft continue to invest in Microsoft Search capabilities, the company determined the “Dynamic Ordering” feature offered limited utility and after careful consideration decided to deprecate its entry points.

This link, How to change the order in which classic search results are displayed in SharePoint Server, documents Dynamic Ordering and will be updated to reflect the change in behavior.

Additional information

The post M365 Changelog: Retirement of Dynamic Ordering feature in classic search experiences appeared first on Petri IT Knowledgebase.

View Details

How much exactly does Google stand to lose if Samsung replaces it with Bing as the default search experience? Windows is set to get new A.I. smarts, and Microsoft is hoping to reduce reliance on Nvidia in the datacenter with its own Arm A.I. chips.

The post A.I. Wars – Google ‘In Panic’ over Samsung Threat to Make Bing Default Search appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released an updated version of Windows Update Health Tools for Windows 11 and Windows 10. The company detailed in a support document that the new update is designed to improve the reliability of the Windows update process.

Specifically, the new KB4023057 intends to address issues that could prevent the installation of critical updates on Windows 11 and 10 PCs. It’s available for PCs running Windows 11 versions 21H2 and 22H2 as well as Windows 10 versions 21H2 and 22H2.

According to Microsoft, the new update will be delivered automatically to consumer devices through Windows Update. Alternatively, it’s also possible to manually download Update Health Tools from the Microsoft Download Center.

“This update should automatically install if your device is connected to Windows Updates services and allows automatic updates. If your device isn’t regularly receiving quality updates, because of low disk space or have low activity, this may prevent the device from installing the Update Health Tools. If you currently don’t have the client installed, you can then try triggering a normal Windows Update scan,” Microsoft explained.

How to deploy Update Health Tools via Windows Update for Business (WUfB)Microsoft recommends IT admins to deploy the update in enterprise environments via Windows Update for Business (WUfB). However, the update will not be offered to devices that are managed via Windows Server Update Services (WSUS).

Microsoft notes that commercial customers can confirm the installation of Microsoft Update Health Tools by checking the contents of the following folder: C:\Programme\Microsoft Update Health Tools. As shown in the screenshot, enterprise customers can also verify if the service is running on their machines. Did you receive the KB4023057 update on your Windows 10 or 11 machines? Let us know in the comments section below.

The post Microsoft Improves Windows Update Process on Windows 11 and 10 PCs appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that its Azure Storage Mover is now generally available for enterprise customers. The new tool intends to make it easier to migrate files and folders from on-premises systems to Azure cloud storage.

Microsoft’s Azure Storage Mover made its debut in public preview in December last year. The managed cloud migration service enables IT admins to plan, launch and monitor workload migrations directly via the Azure Portal, CLI, or PowerShell. It’s useful for customers who need an efficient and cost-effective way to move large amounts of data to the cloud.

“You can use Storage Mover for different migration scenarios such as lift-and-shift, and for cloud migrations that you have to repeat occasionally. Azure Storage Mover also helps maintain oversight and manage the migration of all your globally distributed file shares from a single storage mover resource,” Microsoft explained.

Currently, Azure Storage Mover supports the migration of an on-premises network file system (NFS) share to an Azure blob container. It leverages virtual machines (VMs) as migration agents that can be deployed close to the source storage. The agents include details regarding metrics, job migration run and copy logs. Moreover, IT admins can manage all agents in a single place in Azure.

Azure Storage Mover minimizes workload downtimeMicrosoft emphasizes that the new Azure Storage Mover service is designed to reduce workloads’ downtime during repeated source and target migrations. This tool is a part of Microsoft’s ongoing efforts to make going migrations easier for businesses. It will compete with existing third-party cloud migration solutions.

If you’re interested, you can download Azure Storage Mover from the official website. Microsoft plans to add more features to improve the Azure Storage Mover service, including migration customization options and insights about selected sources. Microsoft will also introduce support for post-migration tasks such as data protection and data validation.

The post Microsoft’s New Azure Storage Mover Makes Cloud Migrations Easier appeared first on Petri IT Knowledgebase.

View Details

AWS Amplify is an Amazon Web Services (AWS) application development framework that organizations can use to develop and deploy web and mobile applications. It’s an end-to-end solution for creating an app backend and a frontend UI in just a couple of hours. In this article, I will explain how AWS Amplify works and how it can help organizations create cloud-based mobile and web apps in a more efficient way.

What is AWS Amplify?AWS Amplify includes an extensive set of tools allowing developers to build full-stack applications on AWS. It also provides pre-built UI components and code libraries for connecting apps to new or existing AWS services. Moreover, a powerful command-line interface (CLI) is also available to configure an app with just a couple of commands.

The major components of AWS AmplifyHere are the major components of AWS Amplify you should know about before getting started with the development platform.

  • Amplify CLI Toolchain: This is a set of command-line interface tools allowing developers to create their apps, integrate them with other AWS services, and deploy them with ease.
  • Amplify Studio (formerly Admin UI): This is a visual interface for managing backend services and resources for your apps.
  • Amplify Libraries: AWS Amplify provides a set of libraries allowing developers to easily connect their apps to new and existing AWS backends.
  • Amplify UI components: This is an open-source design system offering cloud-connected components for building your apps.
  • Amplify Web Hosting: This is a fully managed CI/CD and hosting service for web apps.

AWS Amplify lets you create an app backend and a frontend UI (Image credit: Amazon)What are the differences between AWS Lambda and AWS Amplify?AWS Lambda is a cloud-based “serverless” infrastructure that lets developers run code on the AWS cloud without having to manage any infrastructure. Although both AWS Amplify and AWS Lambda can be used to build cloud-powered applications that integrate with other AWS services, there are some major differences between these two platforms.

| Differences | AWS Lambda | AWS Amplify | | Type of Service | Serverless computing | Development framework | | Supported Languages | Multiple programming languages including Java, Python, and Node.js, among others | Primarily JavaScript, but it supports other languages through its integration with AWS services | | Event Source | Triggered by external events | No external event source triggers, but it can integrate with various AWS services | | Deployment | Manual deployment of code and configuration updates | Automatic deployment is possible with CI/CD | | UI Components | No built-in UI components | Comprehensive library of customizable UI components |

The top features of AWS AmplifyAWS Amplify allows developers to simplify the development of their web and mobile apps and reduce development costs. Here are the top features of AWS Amplify for building full-stack applications:

  • Low-code Development: AWS Amplify provides an easy-to-use low-code development environment through the Amplify Studio.
  • Multi-platform support: AWS Amplify lets developers build mobile and web applications using the most popular frontend frameworks such as React, Angular, and Vue.Js.

AWS Amplify supports the most popular frontend frameworks (Image credit: Amazon) Scalability: AWS Amplify allows organizations to easily scale up or down their applications by leveraging the AWS cloud infrastructure. * Real-time data synchronization: Amplify supports real-time data synchronization for your applications thanks to AWS AppSync. * Analytics: AWS Amplify allows organizations to collect data for their apps using geolocation, logging, caching, session tracking, and more. It also provides predictive analytics capabilities through the machine learning-powered Amazon Personalize service. * Security: Amplify integrates with several AWS security services such as AWS Identity and Access Management (IAM), Amazon Cognito, AWS Key Management Service (KMS), AWS Shield, and AWS Web Application Firewall (WAF). * CI/CD*: AWS Amplify offers tools for continuous integration and continuous delivery (CI/CD). These tools can help to automate the development, testing, and deployment of code changes

How does AWS Amplify work?We’ve just detailed the top AWS Amplify features allowing organizations to build cloud-powered applications quickly and easily. Now, let me explain how building an app with AWS Amplify actually works.

Initializing your projectThe first step in building an application with AWS Amplify is to initialize the project using the Amplify CLI. During this step, you create your project structure and install the necessary dependencies. The Amplify CLI is available for download as a Node.js package, and it integrates with the most popular Javascript libraries and frameworks.

Configuring backend servicesOnce your project is initialized, you can configure the backend services required for your application including authentication, storage, analytics, APIs, and more. AWS Amplify provides a set of libraries that make it easy to integrate these services into your application. You can add, remove, or modify backend services using the Amplify CLI.

Configuring backend services for your application with AWS Amplify (Image credit: Amazon)Building your applicationWith your backend services now configured, you can start building your application’s frontend UI using Amplify’s pre-built components. These components allow you to add functionalities to your application without necessarily having to write your own custom code.

Testing your application locallyOnce you finish building your application, you can test it locally using Amplify’s local development environment. This environment includes a local server and a mock API allowing you to test your code without interacting with any cloud services.

Deploying your applicationWhen you’re ready to deploy your application, you can use Amplify Studio to deploy it to the cloud with just a few clicks. Amplify Studio provides a seamless experience when you need to automate building/testing/ deployment processes.

Manage your applicationAfter deploying your application, you can use Amplify Studio to manage it. There, you can configure how user authentication works in your app and add other services to it. You can also use Amplify Studio to manage hosting and CI/CD pipelines, view usage and metrics, and troubleshoot your application.

The main limitations of AWS AmplifyEven though AWS Amplify offers many benefits for web and mobile developers, it also comes with some limitations. Here is what you need to be aware of.

Limited customizationAWS Amplify provides developers with several pre-built libraries, templates, and components that simplify the process of building applications. However, developers may be quite limited when it comes to customizing their apps and building custom attributes for them.

Learning CurveAWS Amplify is a new service in the market and developers can have a tough time reading through documentation to troubleshoot any issues. Like any other cloud-based service, AWS Amplify is consistently evolving and users need to stay on top of updates to be able to get the most out of the platform.

CostAlthough AWS Amplify offers a free tier, it is unlikely to serve your professional or business needs due to storage and bandwidth limitations. Additionally, because Amplify offers integrations with other AWS cloud services, your overall billing costs may increase. We’ll have more on AWS Amplify costs below.

How much does AWS Amplify cost?Getting started with AWS Amplify is free. You can create your backend with Amplify Studio, the Amplify CLI, and Amplify libraries, and there is also a free tier for using backend resources. For building your frontend UI, you can also use Amplify Studio and UI components for free.

Hosting an app built with Amplify on AWS is free for 12 months, though there are some limitations on storage and bandwidth. The free tier offers 5GB of storage per month and up to 15GB of data transfer per month. To build and deploy your apps, you also get up to 1,000 build minutes per month.

If you need more capacity than what the free tier offers, you can pay as you go for AWS backend resources. Here are some of the AWS Amplify pricing details in the United States.

  • Data storage: $0.023 per GB per month
  • Build and deploy: $0.01 per minute
  • Data Transfer rates: $0.15 per GB of data sent out
  • Request count (SSR): $0.30 per 1 million requests
  • Request duration (SSR): $0.20 per hour (GB-hour)

On top of these basic resources, you might also be billed for the additional resources and AWS services that you consume. The pricing structure might change as per your location and usage patterns, but you can request a custom quote from AWS for your Amplify usage.

ConclusionAWS Amplify is a feature-packed and flexible development platform for building web and mobile applications using the AWS cloud. It provides templates and custom components for rapid full-stack development. With a pay-per-usage model, the platform also provides a cost-effective solution for small businesses that may or may not already use AWS services.

The post What is AWS Amplify? appeared first on Petri IT Knowledgebase.

View Details

MC531738 – Updated April 20, 2023: As shared previously, Microsoft is working on control for admins to manage this feature and expect it to be available in early May.

Currently users open links automatically from Outlook for iOS and Android in their default browser. This change will prompt users to choose their browser instead. Users can choose their default browser if they prefer and configure that preference in their Outlook Mobile settings.

Microsoft apologizes for not communicating about this change sooner, per our commitment to proactive change communication.

When will this happen:

This is currently rolling out.

How will this affect your organization:

  • Users will be seeing this experience launch when they open a link.
  • If Edge is not installed, they will have the option to download it.
  • Microsoft is working on a configuration for you to turn this off if there is a browser your workplace already uses, and will provide an update when it is released.

View image in new tab

The post M365 Changelog: (Updated) Launching new way to open links in Edge from Outlook for iOS and Android appeared first on Petri IT Knowledgebase.

View Details

MC538385 – Updated April 20, 2023: Microsoft will not be rolling this feature to customers in GCC at this time. We will communicate via Message center when we are ready to proceed. Thank you for your patience.

Teams across Microsoft are coming together to provide tools that help make meetings more effective. More specifically, we’re improving how you track what you want to discuss (Agenda), what you discussed/decided (Notes) and what you need to follow up on (Follow-up Tasks). These capabilities are now integrated into the end-to-end meeting experience in Teams, Loop, Planner, To Do, Office.com and OneDrive for Business.

This message is associated with Microsoft 365 Roadmap ID 101509

When this will happen:

Preview Release: Microsoft will begin rolling out late April and expect to complete by mid-May.

Standard Release: Microsoft will begin rolling out late May and expect to complete by late June.

How this will affect your organization:

Users within your tenant will see a Notes button during meetings that invokes these new capabilities. The meeting notes will be shown on the right pane of the meeting window with the ability to open them in the browser for more room or on a second monitor. Participants can collaborate in real time, create an agenda, take notes and add tasks. When participants are assigned a task in the meeting, they will also receive an email notification and it will be synced with the Planner and To Do apps.

View image in new tab

Meeting organizers will also see an ability to add Collaborative notes before meetings, to prepare by adding agendas or other materials in one place.

View image in new tab

After the meeting, Collaborative notes will remain accessible for all participants on the Teams calendar meeting details page. The experience is a Loop component, so they can be copied easily out of the meeting and into chats, group chats, emails and other documents. This makes prepping and follow-up even more seamless.

What you need to do to prepare:

Nothing is required to prepare. This capability will be enabled by default when it rolls out.

Note: the new Collaborative notes file will generate a Company Shareable Link (CSL) by default.

You can manage this feature via SharePoint PowerShell with:

Set-SPOTenant -IsCollabMeetingNotesFluidEnabled (boolean)

You can read more about admin controls here: Manage Loop experiences (Loop app and Loop components) in SharePoint.

The post M365 Changelog: (Updated) Collaborative Meeting Notes appeared first on Petri IT Knowledgebase.

View Details

MC543773 – Microsoft will be removing the Microsoft Store for Business tab from the Microsoft Store app on Windows 10 and 11 PCs. The Microsoft Store for Business tab will continue to be available on HoloLens devices.

Note: The retirement of Microsoft Store for Business and Education on Windows 11 was announced in 2021

When this will happen:

We’ll be gradually rolling this out to all customers on or after mid-May.

How this will affect your organization:

Users will no longer be able to see Line of Business products listed in the Microsoft Store for Business tab in Microsoft Store when this change is implemented.

Microsoft recommends adding your apps through the new Microsoft Store app experience in Intune. If an app is not available in the Microsoft Store, you will need to retrieve an app package from the vendor and install it as a line-of-business (LOB) app or Win32 app. For instructions read the following articles:

  • Add Microsoft Store apps to Microsoft Intune
  • Add a Windows line-of-business app to Microsoft Intune
  • Add, assign, and monitor a Win32 app in Microsoft Intune

Stay tuned to the Intune Customer Success blog as Microsoft will be publishing more information about this soon.

The post M365 Changelog: Removal of Microsoft Store for Business tab from Microsoft Store app on Windows 10 and 11 PCs appeared first on Petri IT Knowledgebase.

View Details

MC543390 – Microsoft is announcing Intelligent Meeting Recap functionality in Microsoft 365 Feed for both Teams Premium users and users without Teams Premium.

This message is associated with Microsoft 365 Roadmap ID 122529

When this will happen:

Targeted Release: Microsoft will begin rolling out mid-April 2023.

Standard Release: Microsoft will begin rolling out late April 2023.

How this will affect your organization:

For Teams Premium users

Focus on what matters with AI-powered meeting recap recommendations in the Microsoft 365 Feed. Get personalized recommendations to catch-up or revisit important meetings, including key insights from these meetings.

What’s in the card?

  • Indication of which part of the meeting you missed
  • Automatically generated AI tasks
  • When your name was mentioned
  • List of top speakers
  • Quick links to the full meeting recap and recording

What’s next?

  • Starting gradual rollout to GA by the end of April
  • GPT-based AI meeting notes
  • Recommending key meetings you attended
  • Rolling out to the Outlook Mobile feed
  • Showing Files related to the meeting

For users without Teams Premium

Focus on what matters with meeting recap recommendations in the M365 Feed. Get recommendations to catch-up or revisit important meetings.

What’s in the card?

  • List of speakers
  • Quick link to the full meeting recap and recording

What’s next?

  • Starting gradual rollout to GA during May
  • Rolling out to the Outlook Mobile feed
  • Showing Files related to the meeting

What you need to do to prepare:

There is no action needed to prepare for this change. You may want to notify your users about this change and update any relevant documentation as appropriate.

The post M365 Changelog: Intelligent Meeting Recap in Microsoft 365 Feed appeared first on Petri IT Knowledgebase.

View Details

MC543384 – In Nov ‘22, Power BI (PBI) launched the preview of integration with Microsoft Graph, with the goal to increase discovery of PBI reports, dashboards and apps across several surfaces like Microsoft 365, SharePoint and Bing @ Work.

This setting allows users in your org to see certain Power BI metadata (such as content titles and types, or open and sharing history) in Microsoft 365 services like search results and recommended content lists. Metadata from Power BI datasets are not displayed.

For example, a report that was shared with you in Teams or Outlook, will now appear in Microsoft 365 Home, SharePoint or Bing @ Work. You can also search for Power BI items in Microsoft 365 Home.

This setting applies only if your Power BI and Microsoft 365 tenants are in the same geographical region.

Between mid-May to end of June, Microsoft will automatically enable this setting for all users, unless you disable it manually (instructions below).

This message is associated with Microsoft 365 Roadmap ID 102409

When this will happen:

Microsoft will begin to roll out feature capabilities by mid-May and will complete by late June.

How this will affect your organization:

Power BI admins will have the ability to disable this experience for their users. These new capabilities will be on by default unless you disable the “Users can see Power BI metadata in Microsoft 365 services” setting prior to mid-May. Admins have the ability to enable or disable the setting at any time.

Note: It may take up to 24 hours for the changes to go into full effect.

What you need to do to prepare:

Microsoft will be looking to turn on the capability by default between mid-May and end of June. To disable this experience, follow the steps below:

  1. Log into your Power BI (app.powerbi.com) account from your browser using your admin account credentials.
  2. Click on Settings located on the right-hand side of the top banner, proceed to click Admin Portal from the drop-down menu.
  3. Once in the Admin portal tab, navigate to the Tenant settings tab located in the left navigation pane.
    1. From inside the Tenant settings tab, scroll down to the list of settings titled “Share data with your Microsoft 365 services” and click on the setting titled “Users can see Power BI metadata in Microsoft 365 services” to expand it.
  4. If the setting is enabled, then toggle it to Disabled (see fig 1)
  5. If the setting is already disabled, then toggle to Enabled and then toggle to Disabled.
  6. See Fig 2 for how a disabled setting looks like
  7. Click ‘Apply’ to save the changes.

Once the setting is enabled or disabled, it may take ~24 hours for you to see changes within Office.com, SharePoint and Bing@Work. More details can be found here: Share data with your Microsoft 365 services tenant settings.

The post M365 Changelog: Your Microsoft 365 services will automatically display your Power BI content by end of June appeared first on Petri IT Knowledgebase.

View Details

MC543382 – The user’s policy details page in Microsoft Teams admin center provides admins with the ability to manage policies for individual users. However, the current experience falls short in meeting critical needs, such as presenting a comprehensive view of all policies assigned to a user and a policy assignment view to understand how a policy is applied to the user.

To address these concerns, the new user details policy page offers an enhanced experience that enables admins to view all effective policies for a user, along with a clear policy assignment hierarchy view. With this new functionality, admins can easily troubleshoot any problematic policy assignments, ensuring that policies are correctly assigned, and their users’ experiences are optimal.

When this will happen:

Standard Release: Microsoft will begin rolling out early May 2023 and expect to complete by late May 2023.

How this will affect your organization:

With the new and improved user details page, you can now do a host of enhanced actions, including:

  1. Edit policy assignments: To edit policy assignments for one or more policy types.
  2. View policy assignments: To view what policies are assigned and how a policy` becomes effective for a user for each policy types in a hierarchical format. Inside this view, admins can:
    1. Assign/Remove “Direct assignment.”
    2. Edit direct assignment.
    3. Manage group assignments.
    4. Manage the effective policy assigned group in M365 admin center.
  3. Remove direct assignments: To unassign/remove a directly assigned policy to make way for correct effective policy either view group policy assignment or Global(org-wide) default.

The above information is presented in a table format, which also offers support for sorting, filtering, and searching capabilities.

The hierarchy view for policy assignments provides administrators with valuable information on which policies are assigned to a user through Direct, Group, or Default assignments, and offers a range of actions to manage these assignments to ensure that the user receives the appropriate effective policy.

What you need to do to prepare:

Review how the policy assignment for users and groups and policy precedence rules works. For a better understanding, administrators can follow the scenarios provided –

  1. Review and understand what policies are effective and how are they effective for a user.Steps:
    1. Login to TAC and navigate to Manage users > click on a user > navigate to Policies tab.
    2. Review the table showing effective policies for all policy types.
    3. In the table, check the column – Effective policy and Assignment type, to understand by what assignment method a policy is assigned to a user.
  2. View policy assignment hierarchy to understand the policy precedence rules for effectiveness.Steps:
    1. Select a policy type that you want to see the policy assignment hierarchy.
    2. Click “View”
    3. Verify details in the side panel.

The post M365 Changelog: User’s policies details page enhancements appeared first on Petri IT Knowledgebase.

View Details

Microsoft has released Hotpatching support for Windows Server Azure Edition VMs running the Desktop Experience installation mode. The company originally introduced Hotpatching for Server Core in February 2022, and this capability is now available in preview for the Desktop Experience.

Hotpatching is a feature that is used to apply security patches to Windows devices without requiring a reboot. It enables users to update critical components of the operating system without stopping services and applications. Hotpatching allows for the replacement of old code with new code while the system is still running.

Microsoft highlights that customers can use Hotpatching capabilities to speed up the deployment of updates and minimize reboots. It could also be useful in scenarios where a security update must be applied immediately to address critical vulnerabilities.

“With this new support, all Windows Server 2022 Azure Edition VMs in Azure (including Azure Stack HCI) can take advantage of rebootless updates using Preview images! This marks our continued investment in making Azure the best destination to run Windows Server, with many capabilities that optimize your server management through services such as Azure Automanage,” Microsoft explained.

You can see how Hotpatching works in the video below:

How to create a new Windows Server VM with HotpatchTo get started, IT admins will need to create a Windows Server 2022 Datacenter: Azure Edition Desktop Experience virtual machine with pre-configured Hotpatch. Microsoft has provided a step-by-step guide to create the VM from the Azure portal or programmatically with an ARM template and the Azure CLI.

Keep in mind that customers will need to host Windows Server 2022 Datacenter: Azure Edition on a supported platform (such as Azure Stack HCI version 21H2 or newer) to enable Hotpatching. If you’re interested, be sure to check out this support page to read a detailed comparison of Server Core vs. Desktop Experience.

The post Microsoft Releases Hotpatching Windows Server Azure Edition with Desktop Experience appeared first on Petri IT Knowledgebase.

View Details

Microsoft’s new Azure Virtual Desktop app is available to download from the Microsoft Store. The company announced the app’s availability in public preview yesterday, and it runs on both Windows 11 and Windows 10 PCs.

Until now, the only way to access Azure Virtual Desktop resources was to download the Microsoft Remote Desktop application. Additionally, it’s possible to use the service via a web browser across all platforms, including Windows, Mac, and Linux.

Microsoft explained that the new Azure Virtual Desktop app provides the same features available in the existing Remote Desktop for Windows client. However, the Microsoft Store version of the application also brings some new capabilities for Windows users.

First off, the Azure Virtual Desktop app utilizes its own auto-update mechanism, which eliminates the need for manual downloads to get new features and releases. Users can also pin the Azure Virtual desktops and apps to the Start Menu on their Windows devices. To do this, they will need to right-click on any app or desktop and click the Pin to Start Menu button.

“Azure Virtual Desktop is a cloud VDI service that delivers secure remote desktop and app experiences from virtually anywhere. It provides the flexibility and control organizations need with exclusive support for Windows 11 and Windows 10 multi-session cost-savings capabilities and the built-in security and reliability of Azure. Company data is safe and secure because it lives in the cloud and not on your personal devices,” Microsoft explained.

Enterprise deployment of the Azure Virtual Desktop Store app for WindowsMicrosoft notes that IT admins can use management tools (such as Microsoft Intune or Configuration Manager) to deploy the Azure Virtual Desktop app in their organizations. Meanwhile, users can provide feedback, and opt-in to test new Insider builds before they’re generally available for everyone.

You can head over to the Microsoft Store to download the Azure Virtual Desktop app on Windows 11 or Windows 10 PCs. We invite you to check out this support page to troubleshoot issues with the Azure Virtual Desktop app.

The post Microsoft’s Azure Virtual Desktop App is now Available on the Microsoft Store appeared first on Petri IT Knowledgebase.

View Details

When you virtualize an Azure Stack HCI cluster, you may want to load balance applications running on it to optimize server utilization. While there are various built-in options to do that, they may be quite limited depending on your usage scenarios. In this article, I’ll discuss the various options you have to implement Azure Stack HCI load balancing, and I’ll also detail all the opportunities and drawbacks they may come with.

Using an external load balancer with Azure Stack HCIUsing external load balancer appliances with your Azure Stack HCI cluster is a very classic way to evenly distribute incoming traffic across your resources. These external load balancer appliances can be either hardware-based or virtualized.

The purpose of these appliances is to load balance your applications and forward traffic to the fabric infrastructure and into the virtualization environment. You can load balance applications running in different clusters and in different locations, and you can see how such an infrastructure works in the image below.

Using an external load balancer with Azure Stack HCI (Image credit: Petri/Flo Fox)Using external load balancers with your Azure Stack HCI cluster can really help to improve the overall reliability and availability of your infrastructure. However, this solution also comes with some drawbacks: You’ll always need some external components, and you’ll also need to make additional investments in hardware and/or licenses.

External load balancers can also include a cloud-based load balancer such as Azure Traffic Manager, which is a DNS-based traffic load balancer. Azure Load Balancer is another alternative that offers various fully-managed load balancing solutions.

However, cloud-based load balancers are rather inefficient for load balancing data center internal traffic as they’re sending all traffic up to the cloud and back to your infrastructure. Cloud-based load balancers are much more efficient for load balancing geo-distributed workloads.

Using a virtual load balancer on Azure Stack HCIAnother feasible load balancer option for Azure Stack HCI is to use Network Virtual appliances or Network Function Virtualization (NFV) appliances. These appliances can be hosted on Azure Stack HCI within a virtual machine and provide the same experience as external virtual appliances.

Using a virtual load balancer on Azure Stack HCI (Image credit: Petri/Flo Fox)Having a virtual load balancer on Azure Stack HCI offers a good “everything in one box” solution. However, there is still one caveat you need to consider: if your cluster goes down, so will your load balancer.

In the end, the best way to deploy virtual load balancers on Azure Stack HCI is to use them as multi-cluster load balancers to distribute your applications on different clusters.

Using virtual load balancers in a multi-cluster infrastructure (Image credit: Petri/Flo Fox)With such a solution, you will improve the reliability and overall availability of your workloads. However, this isn’t an “everything in one box” solution and you may need to invest in additional hardware to implement it.

Using Software-Defined Networking with Azure Stack HCISoftware-Defined Networking (SDN) in Azure Stack HCI allows organizations to centrally manage network services and load balancing in their data center. This solution also offers a Software Load Balancer (SLB) to distribute network traffic across virtual network resources.

Using a Software Load Balancer for Software-Defined Networking can help to improve availability and scalability for your workloads. However, it does add another layer of complexity and requires additional resources for Network Controller, the server role used to manage your virtual network infrastructure.

Using Software Defined Networking with Azure Stack HCI also comes with some limitations: Firstly, Multitenancy for virtual local area networks (VLANs) isn’t supported by the Network Controller feature. Moreover, as you can see below, the Software Load Balancer for SDN is bound to one cluster, so there is no option to load balance applications across different clusters.

Using a Software Load Balancer for Software-Defined Networking (Image credit: Petri/Flo Fox)Application-dependent load balancing optionsSome applications come with an integrated load balancing mechanism. A good example of that is Kubernetes, as the container orchestration tool offers load distribution as the most basic type of load balancing.

When load balancing is built into an application, you should benefit from a combination of reliability and performance optimization. Of course, the caveat here is that not every application has an integrated load balancer mechanism.

Personally, I prefer to deploy cluster-independent load balancing solutions. Here are the main benefits of that option:

  • You can more easily adapt to changes regarding (geo)redundancy requirements.
  • You can reduce fabric complexity.
  • Application owners can adjust load balancing depending on workload requirements.
  • You can leverage other technologies and cloud services to make application owners less reliant on specific environments.
  • You can add your applications to another cluster when you run out of resources on your original Azure Stack HCI cluster

ConclusionAfter understanding all the different ways to implement Azure Stack HCI Load Balancing described in this article, you should find the best solution that fits the needs of your organization. And even though Azure Stack HCI is a rather new cloud-integrated product, it’s just another hypervisor, and using it shouldn’t result in more complexity for your environment.

Lastly, you should also aim to keep your applications as independent as possible from fabric, location, or cloud environments. That way, you’ll avoid the risk of being locked into a certain technology or ecosystem.

The post Three Ways to Load Balance Applications Running on Azure Stack HCI appeared first on Petri IT Knowledgebase.

View Details

Microsoft is adopting a new weather-themed taxonomy to describe threat actors across the world. Some nation-state actors such as Russia, North Korea, China, and Iran will be designated with a specific weather event in the new threat actor naming taxonomy, and the company will do the same for more specific threat actor groups.

Microsoft currently tracks over 300 threat actors across the globe, and soon, the company’s threat research group will use terms such as “Midnight Blizzard” or “Hazel Sandstorm” to describe threat actors. And no, this really isn’t a late April Fool’s joke.

“With the new taxonomy, we intend to bring better context to customers and security researchers that are already confronted with an overwhelming amount of threat intelligence data,” explained John Lambert, Distinguished Engineer and CVP, Microsoft Threat Intelligence. “It will offer a more organized, memorable, and easy way to reference adversary groups so that organizations can better prioritize threats and protect themselves.

How Microsoft’s new threat actor naming taxonomy worksMicrosoft acknowledged that other security vendors use their own taxonomies to describe threat actors, and the company is committed to making its new system easy to understand for customers already familiar with other taxonomies. “We will strive to also include other threat actor names within our security products to reflect these analytic overlaps and help customers make well-informed decisions,” Lambert said.

You can see below the different threat actor groups that Microsoft tracks with the type of weather event assigned to them.

| Actor category | Type | Family Name | | Nation state | China | Typhoon | | Iran | Sandstorm | | Lebanon | Rain | | North Korea | Sleet | | Russia | Blizzard | | South Korea | Hail | | Turkey | Dust | | Vietnam | Cyclone | | Financially motivated | Financially motivated | Tempest | | Private sector offensive actors | PSOAs | Tsunami | | Influence operations | Influence operations | Flood | | Groups in development | Groups in development | Storm |

Microsoft’s new weather-themed threat actor naming taxonomy (source: Microsoft.com)To distinguish actor groups within the same weather family, Microsoft will be using adjectives. As an example, the Iranian threat actor PHOSPORUS is named “Mint Sandstorm” in the new taxonomy. For threat actor groups in development, however, Microsoft will use a weather event followed by a four-digit number instead of an adjective.

Microsoft will use adjectives to distinguish threat actors within the same family (image credit: Microsoft)“The naming approach we have used previously (Elements, Trees, Volcanoes, and DEVs) has been retired. We have reassigned all existing threat actors to the new taxonomy, and going forward will be using the new threat actor names, Lambert explained.

Microsoft’s new threat actor naming taxonomy will start appearing in public-facing content and Microsoft services over the coming weeks. The company expects the rollout of the new taxonomy to be complete by September 2023, though it also said that there will be “some surfaces that will not be updated.”

The post Microsoft Adopts Weather-Themed Threat Actor Naming Taxonomy appeared first on Petri IT Knowledgebase.

View Details

Microsoft Defender for Endpoint is getting a new update that will enable IT admins to discover internet-facing devices. The new feature leverages the existing network telemetry and RiskIQ integration to automatically map all onboarded devices that are connected to the internet.

Microsoft has clarified that identifying and prioritizing internet-facing devices to address potential security threats can be a challenging task for organizations. This is due to the fact that many customers use different classification logics, data sources, and public IP ranges to cross-reference devices in enterprise networks. It makes it difficult for IT admins to verify the accuracy of insights collected across their digital assets.

“Microsoft Defender for Endpoint will automatically map and flag onboarded devices that are exposed to the internet in the Microsoft 365 Defender portal, providing more context to security teams and deeper insights into device exploitability. By providing a view into internet-facing devices, security teams can better prioritize alerts, recommendations and incidents as internet-facing devices oftentimes become an adversary’s entry point into the corporate network,” Microsoft explained.

How does internet-facing device mapping enhance security in Microsoft Defender for Endpoint?As shown in the screenshot above, IT admins can view the classified internet-facing devices on the device inventory page. The information is also available through Advanced Hunting. Microsoft says that administrators can view internet-facing properties in the device pane.

Microsoft notes that the ability to identify internet-facing devices is available in public preview for Microsoft Defender for Endpoint customers. It should help organizations remediate vulnerabilities within the network and bolster their overall security posture.

Microsoft Defender for Endpoint has recently introduced new device isolation support for Linux devices. This capability has been available to protect Windows PCs since June 2022. The device isolation feature helps to prevent hackers from connecting to compromised devices and stealing sensitive information.

The post Microsoft Defender for Endpoint Can Now Discover Internet-Facing Devices appeared first on Petri IT Knowledgebase.

View Details

Security researchers have discovered a new LockBit ransomware that’s designed to target macOS devices. The MalwareHunterTeam detailed on Twitter that the malware enables threat actors to encrypt files stored on Arm-powered Macs.

LockBit is a Russian-based group that has historically targeted Windows PCs, Linux, and virtual host machines. The gang has been running ransomware-as-a-service (RaaS) operations since 2019. Over the years, the LockBit group has deployed its malware against many high-profile targets in several countries.

Interestingly, Twitter user vx-underground found that the macOS variant of the LockBit ransomware has been available since November 2022. The malware has infected around 1,000 organizations worldwide. Security researchers believe that the LockBit gang managed to steal tens of millions of dollars from the victims.

Not a single person I can find tweeted LockBit has a Mac targeting version before I did above yesterday, nor can find any blog posts mentioning it, etc. So even if the gang had the first build in 2022 November, for public, this is not late at all, but even yet, seems the first… pic.twitter.com/4iR71cuLpo

— MalwareHunterTeam (@malwrhunterteam) April 16, 2023

LockBit ransomware doesn’t pose a real threat to Mac devicesApple security expert Patrick Wardle has performed a detailed analysis of the macOS version of LockBit. He found that the malware can encrypt files on macOS, but it currently doesn’t pose any real threat. Wardle also pointed out that LockBit uses an invalid digital signature, and it can’t run easily on a Mac device. The built-in security features (such as System Integrity Protection (SIP) and Transparency, Consent, and Control (TCC)) will help to significantly reduce its impact.

“While this may be the first time a large ransomware group created ransomware capable of running on macOS, it’s worth noting that this sample is far from ready for prime time. From its lack of a valid code-signing signature to its ignorance of TCC and other macOS file-system protections as it stands it poses no threat to macOS users,” Wardle explained.

Emsisoft threat analyst Brett Callow explained that the LockBit ransomware for Mac is currently in its early development stages. Moreover, he confirmed that there is no evidence it has been exploited in the wild. “It is, however, an indication that LockBit is, or at least was, thinking about Macs,” Callow said.

The post Researchers Uncover New LockBit Ransomware Created to Encrypt Files on macOS appeared first on Petri IT Knowledgebase.

View Details

According to a recent report, cyberattacks increased by 38% in 2022 compared to 2021, meaning that it’s more important than ever to be vigilant when it comes to cybersecurity. One way to strengthen operational resilience against cyberattacks is by mastering Identity Threat Detection and Response (ITDR). As Gartner notes, “misused credentials are now the top technique used in breaches…. attackers are targeting Active Directory and the identity infrastructure with phenomenal success.”

Windows Server Active Directory is a legacy technology that is still used by 80% of organizations today. But because it was often poorly implemented and the IT organization has limited expertise on its incident response team, AD poses a significant risk. Some of the biggest concerns are detecting attacks not surfaced by security monitoring tools, vulnerabilities in AD, failure to regularly test a recovery plan, and detecting attacks that move from Windows Server AD to Azure AD.

ITDR and operational resilience In this expert-led webinar, 18-time Microsoft Valuable Professional (MVP) Gil Kirkpatrick, Chief Architect for products at Semperis, walks you through the connection between ITDR and operational resilience, recent identity-related cyberattacks, how threat actors breach AD and Azure AD, and how you can close common attack entry points.

In this session, you’ll learn:

  • Why ITDR is key to operational resilience
  • Common tactics that threat actors use to target AD/Azure AD as an entry point into your environment
  • How to detect vulnerabilities in hybrid AD environments, including indicators of exposure (IOEs) and indicators of compromise (IOCs)
  • How to guard against attacks that bypass traditional logging methods
  • How to ensure a fast, clean AD forest recovery post-attack

Register for the webinar today!

The post Cyberattacks Increased 38% in 2022 – Secure Active Directory Now appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced new File Hash and URL Search capabilities for its Microsoft Defender Threat Intelligence solution. It’s a top-requested feature that enables customers to get detailed insights about specific hashes or URLs identified within their enterprise network.

Microsoft Defender Threat Intelligence (Defender TI) is a cloud-based service that provides real-time data about threats and vulnerabilities across IT environments. It leverages machine learning and AI capabilities to identify patterns and anomalies and track malicious activities. The service integration with other security solutions to help organizations improve security posture and protect against sophisticated cyber attacks.

“Defender TI leverages Microsoft’s threat intelligence through static and dynamic analysis of files and URLs within and outside its ecosystem, providing comprehensive coverage of potential threats. The static study examines the file’s code without executing it, while dynamic analysis involves executing it in a controlled environment to observe its behavior,” Microsoft explained.

How Microsoft Defender’s URL and Hash Search Intelligence works?Microsoft highlights that this dual approach lets the Defender TI tool to use static analysis techniques to detect and categorize potential threats. The service also uses dynamic analysis methods to identify and analyze the actual behavior.

For instance, IT admins can use the search bar to search any URL or hash value. They will be able to view the reputation score and basic details about the file hash or URL entities. Moreover, the Data tab shows threat intelligence data directly from the MDTI tool.

With the increasing incidence of cyberattacks, Microsoft emphasizes the importance of implementing robust security measures to safeguard sensitive data and business operations. The newly introduced security feature aims to assist IT admins in detecting potential threats and taking proactive measures to protect their organization.

Earlier this month, Microsoft announced new threat intelligence capabilities for its existing security solutions. A new Intel Profiles feature provides contextual information regarding threat actors, exploits, and infrastructure. Microsoft Defender TI API is now available to help security teams respond to potential threats at scale.

The post Microsoft Defender Boosts Threat Intelligence with File Hash and URL Search Capabilities appeared first on Petri IT Knowledgebase.

View Details

Microsoft Teams has introduced support for user-managed call queue and auto-attendant greetings. The long-awaited calling feature lets IT admins designate authorized users to manage greetings and announcements for their respective call queues and auto attendant directly within Microsoft Teams.

In Microsoft Teams, the call queues feature is a waiting area that allows incoming calls to be routed to agents who are responsible to answer them. Moreover, auto attendants are automated voice menus that route incoming calls based on caller input.

Previously, Microsoft Teams did not give users the ability to manage call queues and auto attendants. IT Pros had to grant specific Teams admin permissions to fulfill this requirement. The latest update now enables designated users to manage greetings without leaving Microsoft Teams.

“Changing business conditions often require adjustments to call queue/auto attendant greetings and announcements. However, it can be difficult to identify the right Teams admin to make these changes, and addressing high request volumes can be time-consuming for the responsible admins,” Microsoft explained.

How to enable user-managed call queue and auto attendant greetings in Microsoft TeamsTo get started, IT admins will first need to designate authorized users by creating Voice application policies in the Teams admin center or via PowerShell cmdlets. Once configured, Microsoft Teams users will be able to update the call queue for auto attendant greetings. To do so, click the three dots (…) menu >> Settings, and scroll down to select the auto attendant or call queue to update the greetings.

The new user-managed call queue and auto-attendant greetings feature is available in preview in the Microsoft Teams desktop and web clients. Microsoft plans to roll out the new capability to all users globally in June 2023.

Microsoft Teams has recently added a new My Day view in the Tasks by Planner and To Do app. It allows users to consolidate their tasks to organize and prioritize important workflows.

The post Microsoft Teams Now Lets Authorized Users Manage Call Queue and Auto Attendant Greetings appeared first on Petri IT Knowledgebase.

View Details

Microsoft has announced that all new Windows 365 PCs will now be encrypted at rest. Starting this month, the new security feature will be available for all Windows 365 Cloud PC SKUs at no additional cost.

Windows 365 is a cloud-based service that allows users to access a virtual computer from any device with an active internet connection. It lets users create a secure Windows 10 or Windows 11 cloud PC to access their applications and files remotely. Microsoft offers Windows 365 Business and Enterprise Editions on a per-user, per-month subscription basis.

“All data is encrypted at rest and flows encrypted from the host to the storage service, where it’s persisted. Essentially, encryption at the host encrypts your data from end-to-end. Encryption at host doesn’t use your Cloud PC’s CPU and doesn’t impact your Cloud PC’s performance,” Microsoft explained. “It’ll also be in addition to the storage encryption that already exists for Cloud PC data at rest today.”

The Windows 365 end-to-end encryption feature uses platform-managed keys to encrypt Temporary disks and ephemeral OS disks at rest. It’s up to the IT Pros to use the customer-managed or platform-managed keys in order to encrypt the OS and data disk caches.

Limitations of host-based encryption in Windows 365 Cloud PCsMicrosoft notes that customers will need to enable encryption at rest for their new Windows 365 Cloud PCs in the Azure Portal. However, keep in mind that the feature support isn’t available for legacy VM Sizes and ultra disks or premium SSD v2 managed disks. Microsoft says that IT admins will need to deallocate and reallocate existing VMs to encrypt them.

Microsoft provides Windows 365 Cloud PC troubleshooting tipsIn related Windows 365 Cloud PC news, Microsoft detailed some troubleshooting steps to help end users and IT admins address and monitor Cloud PC connectivity issues. Connection failures may occur if a user reboots their system after a Windows update or loses internet connectivity.

Microsoft recommends IT admins to put their Cloud PCs under review if the troubleshooting function doesn’t fix the connection issues. It will allow the Microsoft Global Helpdesk team to review and find the root cause of the problem.

The post Windows 365 Cloud PCs Now Protected with Host-Based Encryption appeared first on Petri IT Knowledgebase.

View Details

Are you creating PowerShell scripts for the first time? One important skill to master is how to write PowerShell functions, which work as a block of code that you can easily reuse. In this article, you will learn about the basics of building your first function and how to call it when you need it.

If you want to follow along with the article, you will want to use either Windows PowerShell ISE or Microsoft Visual Studio Code with the PowerShell extension.

Ready? Let’s learn about PowerShell functions!

What is a PowerShell function?Imagine for a moment that you have a toolbox with a hammer, a wrench, and a pencil. Each tool performs a specific task. We can use independently these tools or in combination with each other to complete a task.

PowerShell functions are the tools in your toolbox.

A PowerShell function is a block of code that performs a specific task or set of tasks. Functions in PowerShell are like functions in other programming languages and can encapsulate a piece of code that can be called multiple times from within a script or from the PowerShell console.

What makes PowerShell functions usefulPowerShell functions are very useful for three main reasons: reusability, modularization, and abstraction.

ReusabilityFunctions allow you to encapsulate a specific piece of code that can be used repeatedly throughout your PowerShell scripts or modules. Once you define a function, you can call it multiple times with different inputs to perform the same action without having to rewrite the code each time.

ModularizationPowerShell functions make it easier to organize your code into smaller, more manageable chunks. By breaking down your script into smaller functions, you can focus on one task at a time, making it easier to read, maintain, and troubleshoot.

AbstractionFunctions allow you to abstract the details of a particular task, making it easier to use and understand. By hiding the implementation details of a task behind a function, you can create a simpler interface that other users can interact with without needing to know the details of how the task is performed.

Overall, PowerShell functions are a powerful tool for automating tasks and managing systems. By learning how to write and use functions effectively, you can become a more proficient PowerShell user.

How to create a PowerShell functionNow that you have a basic understanding of the role functions play, let’s get started creating your first one. You can see the syntax of a basic function below:

function Verb-Noun { code} Every function starts out with the keyword of the function followed by a name (verb-noun) for the function. The proper way to name a function is by using an approved verb-noun format. All code between the curly braces will be the tasks the function will perform when called.

PowerShell functions do’s and don’ts

  • Remember the KISS principle, meaning accomplishing a single task in the simplest way possible. The goal of a function is to do one job and do it well with the least amount of code as possible.
  • Avoid using aliases and positional parameters in your code. You should format for readability, as the next person troubleshooting your code could be you!
  • Don’t hard-code values. It’s best to create variables and use parameters.

Basic PowerShell functionsLet’s try it out by making a basic function that will fetch the first 5 processes running on your computer. The name of the function is Get-FiveProcesses, which will filter the first five processes passed down the pipeline from Get-Process:

function Get-FiveProcesses { Get-Process | Select-Object -First 5} Saving a function is just like saving a PowerShell script. Simply save the function using the same name used in your code, Get-FiveProcesses.ps1. Once saved, load the script using the dot-sourcing technique into your session. Dot-sourcing allows you to run a PowerShell script in the current scope instead of in the script scope. Now you can run Get-FiveProcesses just like built-in cmdlets:

After saving a PowerShell function, we can run it like a built-in cmdlet (Image credit: Petri/Bill Kindle)Your function will remain loaded for the rest of your PowerShell session. When you close your session, your function will need to be reloaded again.

Advanced PowerShell functionsAdvanced PowerShell functions give you some powerful features that make your functions professional grade. What do I mean by that? Professional grade scripts include help, possibly some error handling, parameters, or accepting pipeline input.

Using the previous example, Get-FiveProcesses was a basic function that included no help. Let’s make some changes to this script by adding some comment-based help:

function Get-FiveProcesses { <# .SYNOPSIS Gets the first five processes. .DESCRIPTION Get-FiveProcesses performs basic filtering of processes to show a user only the first five processes of a host system. .NOTES This function works on Windows and Linux running PowerShell 7+ .LINK Be sure to check out more PowerShell articles on https://petri.com .EXAMPLE Get-FiveProcesses Get the first five processes. #> Get-Process | Select-Object -First 5 } Now, if you load your function again, you will use PowerShell’s Get-Help cmdlet to find out how to use your function. Below is an example:

Showing built-in help for the Get-FiveProcesses function (Image credit: Petri/Bill Kindle)Using a function in a PowerShell scriptYou can use a function as a session cmdlet or as part of a broader PowerShell script. In the previous section, you learned about a technique called dot-sourcing. You can also use functions within a script. Here’s an example:

```

Simple script with a function built-in# Declare the functionfunction Get-FiveProcesses { <# .SYNOPSIS Gets the first five processes. .DESCRIPTION Get-FiveProcesses performs some basic filtering of processes to show a user only the first five processes of a host system. .NOTES This function works on Windows and Linux running PowerShell 7+ .LINK Be sure to check out more PowerShell articles on https://petri.com .EXAMPLE Get-FiveProcesses Get the first five processes. #> Get-Process | Select-Object -First 5 Write-Host “Here are the first five processes!” }# now you call your functionGet-FiveProcesses

``` Save the example above as ProcessScript.ps1. Now, run the script in your PowerShell session:

Running the ProcessScript.ps1 script in our PowerShell session (Image credit: Petri/Bill Kindle)Passing parameters to a PowerShell functionPowerShell advanced functions can accept parameters if you define them using a parameter block within your function code. Below is a basic parameter block example that contains a Parameter() block to designate the type and name of the parameter:

function Write-MyFunctionMessage { [CmdletBinding()] param ( # This parameter allows you to type a message string [Parameter()] [string] $MyName ) Write-Host “Hello $MyName! How are you today?”} The Write-MyFunctionMessage function passes the string value typed when using the parameter, as shown below:

The Write-MyFunctionMessage function in action (Image credit: Petri/Bill Kindle)Parameters can have attributes that change how a function behaves. Let’s say you have a parameter that is needed in order for a command to complete successfully. By default, all parameters are optional. Using the attribute Mandatory in the Parameter () block forces you to enter the parameter, as shown below:

function Write-MyFunctionMessage { [CmdletBinding()] param ( # This parameter allows you to type a message string [Parameter(Mandatory)] [string] $MyName ) Write-Host “Hello $MyName! How are you today?”} To test the behavior change, try to run the function again and this time, don’t use the -MyName parameter. Since the parameter is mandatory, PowerShell will prompt you for the value. If you were to leave the value blank again, you will get an error:

Not using the -MyName parameter results in an error (Image credit: Petri/Bill Kindle)Parameters can also have default values assigned. Let’s say that you want the default parameter value to be “Reader”. Your code would then use the = sign after $MyName followed by a string value “Reader”:

function Write-MyFunctionMessage { [CmdletBinding()] param ( # This parameter allows you to type a message string [Parameter()] [string] $MyName = “Reader” # Default Value ) Write-Host “Hello $MyName! How are you today?”} Now, when you forget to enter a parameter value for -MyName, the function will no longer return an error:

The Write-MyFunctionMessage function no longer returns an error (Image credit: Petri/Bill Kindle)Returning values from a PowerShell functionIn PowerShell, you can return values from a function using the return keyword or by using the Write-Output cmdlet. I’ll give you an example of each of them below.

Using the return keyword function Add-Numbers { param( [int]$num1, [int]$num2 ) $result = $num1 + $num2 return $result} In this example, the Add-Numbers function accepts two integer parameters and returns their sum using the return keyword.

The Add-Numbers returns the sum of our two integer parameters (Image credit: Petri/Bill Kindle)Using the Write-Output cmdlet function Get-ServiceNames { $services = Get-Service Write-Output $services.Name} In this example, the Get-ServiceNames function retrieves all services on the system and returns their names using the Write-Output cmdlet.

The Get-ServiceNames function retrieves all services on the system (Image credit: Petri/Bill Kindle)Both approaches can return values from a function. The difference between them is that the return keyword exits the function and returns the value immediately, while the Write-Output cmdlet continues executing the function and sends the value to the output stream.

In most cases, using the Write-Output cmdlet is preferable because it allows you to pipe the function’s output to other cmdlets for further processing.

Accepting pipeline inputTo make a PowerShell advanced function accept pipeline input, you need to define a parameter that accepts input from the pipeline. You can do this by adding the ValueFromPipeline parameter attribute to the parameter you want to accept input from the pipeline.

Here’s an example of how to create a function that accepts pipeline input:

function Get-ProcessOwner { [CmdletBinding()] param ( [Parameter(ValueFromPipeline=$true)] [string[]]$ProcessName ) begin { Write-Verbose “Starting the function” } process { foreach ($p in $ProcessName) { $process = Get-Process -Name $p -ErrorAction SilentlyContinue if ($process) { $owner = $process | Select-Object -ExpandProperty UserName Write-Output “$p is owned by $owner” } else { Write-Warning “$p is not running” } } } end { Write-Verbose “Ending the function” }} In this example, the ProcessName parameter accepts an array of strings from the pipeline. The ValueFromPipeline parameter attribute allows the function to accept pipeline input.

You can then use this function with pipeline input like this:

Get-Process | Get-ProcessOwner This would return the owner (if found) of each (running) process that is piped to the Get-ProcessOwner function.

Error handlingYou can use PowerShell’s advanced function error handling to define how errors within your script or function are handled. By default, PowerShell will halt the execution of a script or function if an error occurs, but advanced function error handling lets you customize this behavior to handle errors in a more controlled way.

To implement advanced function error handling in PowerShell, you can use the try/catch construct. Here’s an example:

function My-Function { [CmdletBinding()] param ( [Parameter(Mandatory=$true)] [string]$Path ) try { # Attempt to perform some operation that may generate an error Get-ChildItem $Path -Recurse -ErrorAction Stop } catch { # Handle the error in some way Write-Error “An error occurred: $($\_.Exception.Message)” }} In this example, the try block attempts to run the Get-ChildItem cmdlet with the specified $Path parameter. If an error occurs, the catch block will execute, and the function will display the error message using the Write-Error cmdlet:

If an error occurs, the catch block will execute (Image credit: Petri/Bill Kindle)You can also use the finally block to define code that will execute regardless of whether an error occurred. Consider the next example:

function My-Function { [CmdletBinding()] param ( [Parameter(Mandatory=$true)] [string]$Path ) try { # Attempt to perform some operation that may generate an error Get-ChildItem $Path -Recurse -ErrorAction Stop } catch { # Handle the error in some way Write-Error “An error occurred: $($\_.Exception.Message)” } finally { # Clean up any resources that were used in the try block Write-Verbose “Cleaning up resources...” }} In this example, the finally block will always execute, even if an error occurred in the try block. This can be useful for tasks like closing open file handles or releasing other resources.

The My-Function -Path command in action (Image credit: Petri/Bill Kindle)And here’s the command again, but this time with the -Verbose parameter, which details more information about the operation done by the command.

Running the same command with the -Verbose parameter (Image credit: Petri/Bill Kindle)Notice that the Write-Verbose cmdlet as set in your function is the last bit of code to run before the function exists.

Overall, advanced function error handling in PowerShell gives you greater control over how errors are handled in your scripts and functions and can help make your code more robust and resilient.

Where can you learn more about writing PowerShell functions?Congratulations! You’ve made it to the end of this article on writing PowerShell functions. If you want to know more, you read our guide on how to create advanced functions in PowerShell. You can also find more information on PowerShell functions on Microsoft Learn, the PowerShell.org forum, and the PowerShell Discord server.

The post Use PowerShell Functions to Quickly Simplify Your Scripts appeared first on Petri IT Knowledgebase.

View Details

Microsoft has started testing support for profiles in its Outlook for Mac app. Until now, it wasn’t possible to mute notifications by account, but the new feature helps to create a distraction-free user experience across several accounts.

Microsoft highlighted that this release will let Outlook users switch between profiles by pressing the Control + Tab keys. It’s also possible to use Siri automation to switch between personal and work profiles at a scheduled time.

“In Outlook Mac, you can now create profiles – for example, one for your work account, and another for your personal account. You can then select your work profile and Outlook will not bother you with any notifications from your personal email accounts. Similarly, if you select your personal profile at home, Outlook will not bother you with work-related emails,” the Office Insider team explained.

In Outlook for Mac, the new Profiles feature enables users to apply different themes to their work and personal accounts. It also lets macOS users connect their email accounts to Apple’s Focus Filters.

How to create profiles in Outlook for MacTo try out the new feature, users will need to create a new profile in Outlook for Mac by clicking the Globe icon on the navigation bar. Now, follow the on-screen instructions to create a work or personal profile. The new profiles will show up in the navigation bar, and users will be able to edit the default profile preferences by selecting Profiles >> Manage Profiles.

Microsoft says that the new profile-switching experience is only available for Office Insiders in the new Outlook for Mac client. However, they will need to add at least two accounts to use the feature in the app. Microsoft will keep listening to user feedback to improve the existing experience before making it generally available for everyone.

Last month, Microsoft announced that its new Outlook for Mac app is now free to use on macOS. This means users won’t need a Microsoft 365 subscription or an Office license to use the app on their devices.

View Details

Microsoft is investigating an interoperability issue between the new Windows Local Administrator Password Solution (LAPS) and legacy LAPS policies. The company has confirmed that installing the April 2023 Patch Tuesday updates will break the functionality of both Windows LAPS and legacy LAPS on Windows devices.

Earlier this week, Microsoft announced the native integration of Windows Local Administrator Password Solution (LAPS) on Windows 11, Windows 10, and Windows Server. The feature allows IT admins to manage local account passwords on Windows PCs. LAPS supports both Active Directory and Azure Active Directory (Azure AD) environments. Windows LAPS policies can be managed with Group Policy templates or the CSP interface on Windows.

Up until now, Windows Local Administrator Password Solution was available as a free download on the Microsoft Download Center. Going forwards, the tool will continue to exist as an optional download, but it will now be called “Legacy LAPS.”

“There is a legacy LAPS interop bug in the above April 11, 2023 update. If you install the legacy LAPS GPO CSE on a machine patched with the April 11, 2023 security update and an applied legacy LAPS policy, both Windows LAPS and legacy LAPS will break. Symptoms include Windows LAPS event log IDs 10031 and 10032, as well as legacy LAPS event ID 6,” Microsoft explained.

How to fix legacy LAPS interop bug on Windows Fortunately, Microsoft says that it’s working to resolve the problem, and a fix should be available in the near future. In the meantime, the company has provided a temporary workaround to help organizations address the LAPS interop bug in on-premises environments.

Microsoft recommends that IT admins can uninstall legacy LAPS to mitigate the problem. Alternatively, they can delete all values under the following registry key: HKLM\Software\Microsoft\Windows\CurrentVersion\LAPS\State

Did you experience any problems with the LAPS functionality on Windows PCs? Let us know in the comments below.

View Details

If you’re planning to go on a vacation, you might want to set automatic out-of-office (OOO) replies in Microsoft Outlook. OOO replies send automated email responses when you are unable to respond. In this article, I’ll explain how to set up out-of-office messages in Outlook for Windows, Mac, and the web.

Typically, OOO messages inform the sender that the recipient is away and they may contact someone else in case of any emergency. It’s possible to schedule out-of-office replies in Outlook for a specific timeframe and customize them to suit your needs.

How to create out-of-office messages in Outlook for WindowsUsers can create an out-of-office reply in Outlook for Windows by following these steps:

  • Launch the Outlook for Windows app and click the File tab.
  • Navigate to the top-left corner, select Info, and then click Automatic Replies.

Accessing Automatic Replies options in Outlook for Windows (Image credit: Petri/Rabia Noureen) In the Automatic Replies window, select Send automatic replies and enter the message in the text box. * Users click the Only send during this time range* checkbox to schedule the reply. Select the start and end dates and times respectively.

Choose a specific time range for your out-of-office messages (Image credit: Petri/Rabia Noureen) Alternatively, users can choose to disable the out-of-office reply manually by clicking the Do not send automatic replies option in this window. * Finally, click the OK* button to apply the changes.

You can disable out-of-office replies manually (Image credit: Petri/Rabia Noureen)Outlook lets you enable automatic replies for users outside of your organization (including your personal contacts and/or external users), but you may want to think twice about enabling this setting. In addition to exposing yourself to spam, you may also reveal personal information such as your schedule, location, and availability times, leading to unwanted emails and potential security risks.

How to create out-of-office messages in Outlook on the webHere’s how users can schedule automatic replies in Outlook on the web:

  • Click the Gear icon in the top-right corner to open the Settings flyout.

Accessing settings on Outlook on the web (Image credit: Petri/Rabia Noureen) Select Automatic replies at the bottom of the pane, and then choose Mail >> Automatic Replies*.

Accessing Automatic replies settings on Outlook on the web (Image credit: Petri/Rabia Noureen) Click the Turn on automatic replies* toggle to enable out-of-office messages.

You can also choose a specific time range for automatic replies (Image credit: Petri/Rabia Noureen) Write the content of the out-of-office message in the text box. Users with Microsoft work or school accounts can type separate messages for people who are inside or outside their organization. * It’s also possible to set a time period for sending out-of-office replies to emails sent during a specific period. Click the Save* button at the bottom right corner and close the window.

How to create out-of-office messages in Outlook for MacMac users can follow these steps to create an out-of-office message in Outlook for Mac:

  • In Outlook for Mac, navigate to the menu bar and click Tools > Automatic Replies

Access Automatic Replies settings in Outlook for Mac (Image credit: Petri/Rabia Noureen) Click the Send automatic replies for account* checkbox and write the message in the text box as shown below.

Enabling automatic replies in Outlook for Mac (Image credit: Petri/Rabia Noureen) Select the Send Replies Only During This Time Period option to schedule replies. Choose the start and end dates and times and then click O*K to save the changes.

Choosing a specific time range for your out-of-office-messages (Image credit: Petri/Rabia Noureen)Outlook for Mac users who don’t use the schedule feature can disable the automatic replies manually.

How to set out-of-office replies for unsupported email accountsNotably, the Outlook Automated Replies feature doesn’t support Yahoo, Gmail, IMAP, or POP accounts. In this case, users will need to create a rule to respond to email messages automatically.

Create an out-of-office message template Open the Outlook desktop app and click New Email*.

Creating an out-of-office message template (Image credit: Petri/Rabia Noureen) Enter the subject line and compose the email message. * Select File > Save As and write the name of the template. Then, select the Outlook Template (.oft) option in the Save as type** drop-down menu. * Save the template in the location c:\users\username\appdata\roaming\microsoft\templates.

Create an out-of-office rule Select File > Manage Rules & Alerts*.

Accessing Rules and Alerts in Outlook for Windows (Image credit: Petri/Rabia Noureen) Click the New Rule* button in the E-mail Rules tab.

Creating a new rule in Outlook for Windows (Image credit: Petri/Rabia Noureen) Under Start from a blank rule, select Apply rule on messages I receive and click the Next* button.

Select ‘Apply rule on messages I receive’ (Image credit: Petri/Rabia Noureen) In the Rules wizard, don’t make any changes to the Step 1 and Step 2 boxes to automatically reply to all emails. Click the Next button and Yes* to confirm the changes.

Don’t make any changes to the Step 1 and Step 2 boxes in the Rules wizard (Image credit: Petri/Rabia Noureen) In the What do you want to do with the message? popup, click the reply using a specific template option in Step 1: Select action(s) available. In Step 2, click the a specific template* link.

Choose to reply using a specific template (Image credit: Petri/Rabia Noureen) Click the Look In dropdown menu and select the User Templates in File System option. Now, click the custom template and select Open >> Next*.

Choosing your custom template (Image credit: Petri/Rabia Noureen) Choose any necessary exceptions that you want to add and click the Next* button again.

Choose any exceptions you want to add (Image credit: Petri/Rabia Noureen) Enter a name for the rule, select the Turn on this rule option, and click Finish*.

It’s important to note that the Outlook desktop app should be running to send out-of-office replies automatically while you’re away. The rule will stop working if Microsoft Outlook is closed.

To disable out-of-office replies, you will need to head over to File > Manage Rules & Alerts to manually turn off the rule.

ConclusionCreating personalized out-of-office replies in Outlook is useful to let your colleagues know that you won’t be available for a few days. This can reduce stress and avoid miscommunication while you’re away attending a conference, taking a vacation, or simply having a break from work.

Lastly, be aware that the out-of-office messages you set up in Outlook will also be displayed in Microsoft Teams. This means that anyone who tries to reach you through Teams will see the message and be informed that you are unavailable.

View Details

Amazon announced yesterday Amazon Bedrock, a new platform allowing organizations to build and scale generative AI applications in the likes of OpenAI’s ChatGPT. Despite being the leading cloud provider with Amazon Web Services, the company was a bit late to join the generative AI race but it’s well positioned to catch up.

“At AWS, we have played a key role in democratizing ML and making it accessible to anyone who wants to use it, including more than 100,000 customers of all sizes and industries. AWS has the broadest and deepest portfolio of AI and ML services at all three layers of the stack,” emphasized Swami Sivasubramanian, VP, Database, Analytics and ML at AWS.

Amazon Bedrock lets companies build and scale generative AI applicationsWith Bedrock, Amazon isn’t interested in building its own version of ChatGPT. Instead, the company will allow other companies to build generative AI apps using foundation models (FMs) from AI startups including AI21 Labs, Anthropic, and Stability AI, as well as Amazon’s own Titan FMs.

Amazon Bedrock is currently available in limited preview, but the company claims that it will be “the easiest way to build and scale generative AI applications with FMs” due to the variety of foundation models available to developers. As an example, Amazon’s two Titan models are optimized for summarization, text generation, and detecting harmful content in data, but other models from AI partners are optimized for other things including text processing tasks and image generation.

For developers using AWS to train ultra-large machine learning models, the company also announced the general availability ofAmazon EC2 Inf2 instances powered by AWS Inferentia2 chips, which add a cost-effective solution for running generative AI workloads. New EC2 Trn1n instances powered by AWS Trainium chips are also available to train generative AI models faster.

Amazon’s three products for building generative AI apps on AWS (Image credit: Amazon)Amazon’s CodeWhisperer AI coding companion is now free to useAmazon also announced yesterday that CodeWhisperer, the company’s AI-powered code-generating service tool was now available free of charge for developers. CodeWhisperer supports Python, Java, JavaScript, TypeScript, C#, and many other languages, and it can be accessed within the AWS Lambda Console, Visual Studio Code, and other IDEs.

You can sign up to use CodeWhisperer for free on the official product page. A CodeWhisperer Professional Tier is also available with more administration features and higher limits on security scanning.

View Details

MC528361 – Updated April 13, 2023: Microsoft has updated the rollout timeline below. Thank you for your patience.

Integrations in Viva Goals help save time and energy by automatically updating your key results and projects through connections to other applications from Microsoft and third parties. These integrations allow data to flow from the connected applications into Viva Goals so that results and initiatives are up to date. Viva Goals is launching a new integration for Microsoft Project for the Web which will enable users to automatically update Initiatives and Key Results in Viva Goals based on progress in Project for the Web.

This message is associated with Microsoft 365 Roadmap ID 117462

When this will happen:

Microsoft will begin rolling out in early May (previously mid-April) and expect to complete rollout by late May (previously early May).

How this will affect your organization:

Once the integration is enabled by global admins, Viva Goals users will be able to connect Project for the Web as a data source for Initiatives and Key Results.

What you need to do to prepare:

Global admins or Viva Goals admins will need to enable Project for the Web in their tenant by following the steps outlined in Enable Integrations in Viva Connections.

Additional information

View Details

Microsoft has published guidance to help businesses protect their Windows devices against the BlackLotus UEFI bootkit. The company also detailed some mitigation strategies to recover from BlackLotus attacks in enterprise environments.

BlackLotus is a sophisticated malware that allows attackers to target the UEFI (Unified Extensible Firmware Interface). It enables threat actors to bypass Secure Boot and hijack the boot process even on updated Windows 11 machines. BlackLotus modifies the registry files to disable OS security mechanisms, including Windows Defender, BitLocker encryption, and Hypervisor-protected Code Integrity (HVCI).

Essentially, BlackLotus exploits the CVE-2022-21894 vulnerability to bypass Secure Boot and other advanced protections. Microsoft fixed this vulnerability in January 2022, but the signed binaries still need to be included in the UEFI revocation list

“It is critical to note that a threat actor’s use of this bootkit is primarily a persistence and defense evasion mechanism. It is not a first-stage payload or an initial access vector and can only be deployed to a device to which a threat actor has already gained either privileged access or physical access,” the Microsoft Incident Response team explained.

Microsoft has detailed a couple of artifacts that should be analyzed to track BlackLotus infections in enterprise environments. The company suggests IT admins to use the mountvol command-line utility to mount the boot partition, and find recently created and locked bootloader files. The Microsoft Incident Response team also recommends security teams to examine registry keys, network logs, Windows Event logs, and boot configuration files.

Effective strategies for recovery and prevention against BlackLotus attacksMicrosoft has provided some recommendations that should help organizations to recover Windows devices infected with BlackLotus. The company urges IT Pros to disconnect these devices from the network and reinstall with a clean operating system and EFI partition. It’s also possible to restore from a clean backup with an EFI partition.

It’s highly recommended that organizations should maintain credential hygiene, and restrict local administrative privileges to block BlackLotus attacks. Moreover, IT admins should ensure that their antivirus products are always up to date.

View Details

This Week in IT, Microsoft slips more new features into the April CU for Windows 11, including Windows Local Administrator Password Solution (LAPS), Iran is coming after hybrid cloud environments, the Outlook for Windows preview gets support for Gmail accounts, and much more.

View Details

Microsoft has released version 2303 of the Microsoft Configuration Manager for the Current Branch. The company announced that Microsoft Endpoint Configuration Manager is now branded as Microsoft Configuration Manager.

Microsoft has made improvements to the Cloud Sync feature in Microsoft Configuration Manager. Specifically, IT admins can view collection member sync status (such as success, in progress, and failed) in the Collection Cloud Sync dashboard. In the Monitoring workspace, Microsoft has introduced dedicated dashboards to show the Cloud Sync status for user and device collections.

IT Pros can now view Endpoint Security reportsWith Configuration Manager version 2303, Microsoft added support for Endpoint Security reports in Intune admin center to show insights about tenant-attached devices. Microsoft has introduced audit messages support for authorization failure in the admin service. Up until now, the authorization failure messages used to be logged in log files.

Microsoft has added SQL Server 2022 RTM version support for Microsoft Configuration Manager. It’s possible to use the SQL Server version with the central administration site, a primary site, and a secondary site.

The Unified update platform (UUP) is now generally availableMicrosoft has started offering on-prem Unified Update Platform (UUP) that promises smaller and faster uploads of Windows updates. However, the first UUP update will require a one-time 10GB download for businesses to on-premises Windows 11 22H2 devices. Microsoft recommends using the Configuration Manager Current Branch version 2203 or higher, and supported versions of Windows Server Update Services (WSUS).

Continuous innovation control integration with Configuration Manager 2303Microsoft has released a new commercial control integration with Configuration Manager version 2303. The client policy allows IT admins to control select features introduced via servicing that are off by default.

Additionally, Microsoft introduced dark theme support to the delete secondary site wizard available in the Configuration Manager console. IT admins will need to navigate to the top left corner of the screen and click the arrow to switch to the dark theme.

What are the deprecated features in Configuration Manager version 2303?Microsoft has detailed the features that have been deprecated in Configuration Manager version 2303. The company has removed the Community hub service and integration with the service. Moreover, administrators can no longer create a new Microsoft Store for Business in Configuration Manager.

In case you missed it, Microsoft is also changing the release cadence of Microsoft Configuration Manager to better align with Windows, and we invite you to check out our separate post for details.

View Details

Microsoft-owned LinkedIn has announced some new features that will let users verify their identity and current jobs on the professional networking platform. The new identity verification capabilities are available for free and don’t require any paid subscription plans.

“On LinkedIn, when you show that you’re the real you, you’ll have an even greater chance of finding the professional opportunities that matter to you and your community. That’s why we introduced verification options in October 2022, and starting today, we’re rolling out three additional ways to verify your identity and where you work,” said Oscar Rodriguez, VP of Product Management at LinkedIn.

LinkedIn has partnered with the electronic identity verification platform CLEAR. It allows employees to securely confirm their identity using a US government-issued ID and phone number. The verification badge (a blue or green check) will appear next to the profile name on LinkedIn.

Additionally, LinkedIn now allows users to verify their identity on the platform using their company email addresses. However, this feature is currently available for more than 4,000 organizations. LinkedIn plans to expand support to more companies, though there is no ETA yet.

LinkedIn Identity verification with Microsoft Entra Verified IDLinkedIn has announced that users will be able to use a Microsoft Entra Verified ID credentials for verification purposes. Microsoft Entra Verified ID is based on open standards, and the verified ID credentials could be used for rewards programs, background checks, loan applications, and much more. It’s now included with an Azure Active Directory (Azure AD) free subscription.

LinkedIn is currently testing Microsoft Entra verification support with over 70 organizations, including Microsoft, Avanade, and Accenture. The company will begin rolling out this capability to customers later this month. However, it will initially be limited to 2 million LinkedIn users.

Microsoft intends to expand the use of this verification solution to support numerous other applications. “But this is just the beginning. Verified ID credentials can increase trust, authenticity, and verifiability while reducing cost, time, and friction in many scenarios,” Microsoft added. Let us know in the comments below if you think that the new verification features will make it easier to prove your identity.

View Details

Cohesity, a data security and management service provider, has announced an expanded partnership with Microsoft. The deal includes new software integrations on both platforms that should help to protect businesses against ransomware threats and cybersecurity attacks.

First off, Cohesity has announced the integration of its DataProtect backup and recovery solution with Microsoft Sentinel. It will enable customers to access AI-powered anomaly detection capabilities for incident reporting and ransomware alerts.

Cohesity also provides seamless integration with Azure Active Directory (Azure AD) and multi-factor authentication (MFA). It makes it easier for IT admins to securely manage and access the Cohesity Data Cloud and Cohesity Cloud Services.

“This expanded collaboration will make it simple for thousands of Microsoft customers and ecosystem partners to access Cohesity’s award-winning platform, including its differentiated benefits of scalability, simplicity, and security, in hybrid-cloud or multicloud scenarios,” said Sanjay Poonen, CEO and president, Cohesity.

Cohesity has also teamed up with data management provider BigID. Powered by BigID, Cohesity data classification enables customers to leverage actionable data intelligence for discovery, security, privacy, and governance across Microsoft environments.

Cohesity cloud services now available on Microsoft AzureAdditionally, Cohesity has announced that its popular Cohesity Cloud Services are now available on Microsoft Azure, including Cohesity FortKnox. This release lets organizations protect their sensitive data in multi-cloud and hybrid environments. Microsoft plans to announce the general availability of FortKnox on Azure in the coming months.

Last but not least, Cohesity has introduced Microsoft 365 support in its DataProtect backup as a service (BaaS). The feature allows customers to host their Microsoft 365 data to a data plane hosted on Microsoft Azure.

Cohesity offers various solutions to simplify data management, enhance efficiency, and lower expenses for businesses operating in enterprise environments. The integration of Cohesity with Microsoft Azure is a welcome addition that should help organizations to stay ahead of cybercriminals.

View Details

In this article, I’ll cover the basics of using the SQL SELECT statement to retrieve data from one or more SQL Server tables. I’ll also detail how to retrieve selected columns, as well as how to use the SQL WHERE and HAVING clauses to filter rows.

The samples in this article all use the AdventureWorksLT2019 sample database. In the previous article of this series, I explained how to populate SQL Server tables using the INSERT, UPDATE, and DELETE statements. These Structured Query Language (SQL) statements modify the contents of a table, but the SQL SELECT statement has a different purpose.

How to use a simple SQL SELECT statementThe SQL SELECT statement is used to query data from a table. The following code illustrates the most basic syntax of the SELECT statement.

SELECT columns FROM schema\_name.table\_name; As you should know, table data is organized in a row-and-column format. Each row represents a unique record in a table, and each column represents a field in the data set.

The first agreement of the SELECT statement is a list of the column names that will be retrieved. Here, you specify a list of comma-separated columns from which you want to retrieve data.

Next, the FROM clause specifies the source table and its schema name if that’s required. SQL Server uses schemas to logically group tables and other database objects. The default schema for every database is dbo, and because it’s the schema that’s being used here it can be omitted.

The following listing shows an example of a simple SELECT statement:

  • The first USE command sets the current database to AdventureWorksLT2019.
  • The SELECT statement supplies a column list for the result set that will be retrieved from the SalesLT.Customer table.
  • In this case, the AdventureWorksLT2019 sample database uses the schema name of ‘SalesLT’ (amongst others), so you need to include the schema name, a dot, and then the table name, which is ‘Customers’.
  • The ‘FirstName’ and ‘LastName’ columns retrieve the first name and the last name of the customer.

USE AdventureWorksLT2019SELECT FirstName, LastName from SalesLT.Customer An example of a simple SQL SELECT statement (Image credit: Petri/Michael Otey)As a shorthand, you can use an asterisk (*) to retrieve all of the columns in the table regardless of the number of columns. You can see an example of that below:

USE AdventureWorksLT2019SELECT * from SalesLT.Customer You can use an asterisk (*) to retrieve all of the columns in the table (Image credit: Petri/Michael Otey)The SELECT * statement is useful for ad-hoc queries or for examining the columns and data of a table that you are not familiar with. However, you should not use this statement for production code – It typically retrieves more data than your application needs, and you don’t want to increase your SQL Server workload.

How to filter rows with the SQL WHERE clauseThe real power of the SELECT statement is found in its filtering and joining capabilities. The SELECT query can use an optional WHERE clause to filter the data that will be returned.

The WHERE clause uses one or more Boolean conditions to select the desired table data. The WHERE clause always comes after the FROM clause and before the GROUP BY, HAVING, and ORDER BY clauses.

You can see an example of using the SQL WHERE clause below. Here, the WHERE clause is used to filter out a select list containing the ‘FirstName’, ‘LastName’, ‘Phone’, and ‘CompanyName’ columns from the rows that contain the value ‘Sharp Bikes’ in the ‘CompanyName’ column.

USE AdventureWorksLT2019SELECT FirstName, LastName, Phone, CompanyName FROM SalesLT.Customer WHERE CompanyName = 'Sharp Bikes'; Using the WHERE clause to filter data that will be returned (Image credit: Petri/Michael Otey)Filteringrows that contain a value as part of a stringThe power of using the WHERE clause with the SELECT statement lies in its flexibility. The WHERE clause goes far beyond the simple equality, “greater than” and “less than” comparison operators. Let’s take a closer look at some of the things you can do with the WHERE clause, starting with using the LIKE operator.

The LIKE operator is used to determine whether a specific character string matches a specified pattern. In the example below, we retrieve all of the rows from the Customer table that contains the word ‘Bike’ anywhere in the ‘CompanyName’ column. Here, we need to use the % wildcard character both before and after the word ‘Bike’.

USE AdventureWorksLT2019SELECT SalesPerson, CompanyName FROM SalesLT.Customer WHERE CompanyName LIKE('%Bike%'); Using the WHERE clause with the LIKE operator (Image credit: Petri/Michael Otey)Filtering rows that meet any of three conditionsYou can also use the WHERE clause to filter rows based on multiple different values. The following code listing shows how to use the SELECT statement with a WHERE clause to select three different values from the Product table. In this example, the WHERE clause is used with the OR operator to select rows where the ‘ProductID’ is equal to 680, 711, or 722.

USE AdventureWorksLT2019SELECT Name, ProductID, ProductNumber FROM SalesLT.Product WHERE ProductID = 680 OR ProductID = 711 OR ProductID = 722; Filtering rows that meet different conditions with the WHERE clause (Image credit: Petri/Michael Otey)Filtering rows that are in a list of valuesLikewise, you can use the WHERE clause to select rows that are contained in a list that is defined by using the IN operator. In the following example, the SELECT statement will return the rows that contain the values of ‘Bothell’, ‘Bellevue’, or ‘Renton’ in the ‘City’ column of the SalesLT.Address table.

USE AdventureWorksLT2019SELECT AddressID, AddressLine1, City FROM SalesLT.AddressWHERE City IN ('Bothell', 'Bellevue', 'Renton'); Filtering rows that are in a list of values with the IN operator (Image credit: Petri/Michael Otey)Filtering rows that have a value between two valuesYou can also use the SELECT statement’s WHERE clause with the BETWEEN operator to select row values that fall inside of a certain predefined range in a specific column. The following example shows how you can use BETWEEN to just return the rows in the Product table that have a value in the ‘ListPrice column’ that’s greater than 10 and less than 50.

USE AdventureWorksLT2019SELECT ProductID, Name FROM SalesLT.Product WHERE ListPrice Between 10 AND 50; Filtering rows that have a value between two values (Image credit: Petri/Michael Otey)Filtering rows with the HAVING clauseYou can also filter rows in a result set by using the HAVING clause. The HAVING clause was added to SQL Server because the WHERE keyword cannot be used with aggregate functions such as GROUP BY. It’s used to specify a search condition for a group or an aggregate that includes one or more conditions that are true for different groups of records.

The HAVING clause always comes after the GROUP BY clause and before the ORDER BY clause, as you can see in the following SQL statement. In this example, the result set consists of the ‘SalesOrderID’ and the column alias ‘SubTotal’. The order is asc (ascending) and the rows are aggregates grouped by the ‘SalesOrderID’.

USE AdventureWorksLT2019 ; SELECT SalesOrderID, SUM(LineTotal) AS SubTotal FROM SalesLT.SalesOrderDetail GROUP BY SalesOrderID HAVING SUM(LineTotal) > 5000.00 ORDER BY SalesOrderID ; Filtering rows with the HAVING clause (Image credit: Petri/Michael Otey)SummaryIn this tutorial, I explained the basics of using the T-SQL SELECT statement to filter out rows in a number of different ways. The WHERE clause provides an extremely flexible set of operators that enable you to select rows based on a number of different conditions. Likewise, the HAVING clause enables you to select groups of rows that meet a certain condition. Thanks for reading and stay tuned for my next article in this SQL Server Essential series.

View Details

Security researchers have discovered a design flaw in Microsoft Azure. The vulnerability could enable threat actors to get access to storage accounts and gain full control of the environment.

According to Orca Security researchers, the design flaw exists in a mechanism known as Shared Key authorization. Shared Key authorization is enabled by default while creating storage accounts, and it can be exploited easily.

Microsoft claims that Azure automatically generates two 512-bit storage account access keys while setting up a storage account. The access keys, which are utilized for granting data access, have a total length of 512 bits. The data access can be provided either via Shared Key authorization or with SAS tokens signed with the shared key.

Orca Security found that threat actors could manipulate Azure Functions to steal access tokens of highly privileged identities. This means that a hacker who gains access to the Storage Account Contributor role could potentially access sensitive business assets, and execute remote code (RCE) on virtual machines.

“At this point stealing credentials and Escalating Privileges, as scary as it may sound, is fairly easy. Once an attacker locates the Storage Account of a Function App that is assigned with a strong managed identity, it can run code on its behalf and as a result acquire a subscription privilege escalation (PE),” Orca Security explained.

Microsoft: Shared Key authorization is a “by-design flaw” in Azure Storage accountsThe Microsoft Security Response Center investigated the problem and concluded that it’s a design flaw rather than a security issue. Microsoft recommends that IT admins should disable Azure Shared Key authorization and switch to Azure Active Directory authentication instead.

Microsoft also plans to disable shared access signature authorization by default for new storage accounts. However, there is currently no information available on the timeline for this update. Meanwhile, Microsoft recommends IT admins to learn more about how to use identity-based authorization for Azure Storage accounts.

View Details

Microsoft’s new Windows Local Administrator Password Solution (LAPS) is now natively integrated into Windows 11, Windows 10, and Windows Server. Windows LAPS lets IT Pros secure local administrator accounts on Windows devices, and it supports on-premises Active Directory and Azure Active Directory scenarios.

With the release of the April 2023 Patch Tuesday updates yesterday, Windows LAPS is now an inbox feature that will be updated via the normal Windows patching process. The existing Microsoft security product known as Local Administrator Password Solution (LAPS), which is an optional download, continues to exist but Microsoft now refers to it as “Legacy LAPS.”

Windows LAPS brings new features for on-premises AD and Azure AD scenariosThe native version of Windows LAPS adds support for password encryption, password history, and automatic password rotation. Windows LAPS also adds Directory Services Restore Mode (DSRM) backups to improve the security of domain controllers.

Windows LAPS supports rich policy management via both Group Policy and Configuration Service Provider (CSP), and a new PowerShell module also gives IT pros better password management capabilities. Additionally, Windows LAPS adds support for hybrid-joined devices.

The new PowerShell module for Windows LAPS (image credit: Microsoft)If you’re not ready yet to migrate over to the new features, Windows LAPS also offers an emulation mode. “We do strongly recommend adopting the new features in order to take advantage of the new security improvements,” Microsoft explained yesterday on the Windows IT Pro blog. “Doing this will be much more secure for these sensitive passwords, especially when stored in Active Directory with encryption enabled, or in Azure AD.”

Windows LAPS support for Azure Active Directory in private preview The new LAPS scenario in Azure Active Directory, which is currently in private preview, will give IT pros more options for managing passwords in the cloud. New capabilities include Azure management portal support for retrieving and rotating passwords, as well as Azure role-based access control (Azure RBAC) policies for authoring authorization policies for password retrieval.

Microsoft said yesterday that LAPS support for Azure Active Directory will enter public preview “later this quarter.” The company said that making LAPS a native Windows feature was a popular request, and it’s inviting organizations to use the new feature in their existing deployment.

View Details

Microsoft has released today the April 2023 Patch Tuesday updates for Windows 11 and Windows 10. This month, Microsoft fixed 97 vulnerabilities in Windows and other components, with one of them being already exploited by attackers.

On the quality and experience updates front, Microsoft is making the new Windows Local Administrator Password Solution (LAPS) an inbox feature on Windows 11, Windows 10, and Windows Server 2019 or newer. The feature is now natively integrated and will be serviced via the normal Windows patching process.

Let’s start with the long list of security flaws Microsoft released this month, which includes a good amount of remote code execution vulnerabilities.

97vulnerabilities fixed in the March Patch Tuesday updatesAmong the 97 security vulnerabilities addressed with the April 2023 Patch Tuesday updates, 7 are rated “Critical” and the rest are rated “Important.” The Zero Day Initiative also pointed out that none of the bugs disclosed during the recent Pwn2Own Vancouver are being addressed with these updates.

Here are the most important patches you should know about this month:

  • CVE-2023-28252: This is a Windows Common Log File System Driver Elevation of Privilege Vulnerability that’s already being exploited by attackers to gain SYSTEM privileges.
  • CVE-2023-28231: This DHCP Server Service Remote Code Execution Vulnerability can be exploited by an authenticated attacker using a specially crafted RPC call to the DHCP service.
  • CVE-2023-28219: This Layer 2 Tunneling Protocol Remote Code Execution Vulnerability requires an unauthenticated attacker to send a specially crafted connection request to a RAS server.
  • CVE-2023-21554: This Microsoft Message Queuing Remote Code Execution Vulnerability can be exploited by an attacker sending a specially crafted malicious MSMQ packet to an MSMQ server.
  • CVE-2023-28291: This Raw Image Extension Remote Code Execution Vulnerability requires an attacker or victim to execute a specially crafted application or file from the local machine to take control of the system.
  • CVE-2023-28232: This Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability could be triggered when a user connects a Windows client to a malicious server.

Here’s the full list of patches Microsoft released this month:

| Product | Impact | Max Severity | Article | Download | Details | | Windows 10 Version 20H2 for ARM64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 20H2 for 32-bit Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 20H2 for x64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows Server 2022 (Server Core installation) | Information Disclosure | Important | 5025230 | Security Update | CVE-2023-21729 | | Windows Server 2022 | Information Disclosure | Important | 5025230 | Security Update | CVE-2023-21729 | | Windows Server 2019 (Server Core installation) | Information Disclosure | Important | 5025229 | Security Update | CVE-2023-21729 | | Windows Server 2019 | Information Disclosure | Important | 5025229 | Security Update | CVE-2023-21729 | | Windows 10 Version 1809 for ARM64-based Systems | Information Disclosure | Important | 5025229 | Security Update | CVE-2023-21729 | | Windows 10 Version 1809 for x64-based Systems | Information Disclosure | Important | 5025229 | Security Update | CVE-2023-21729 | | Windows 10 Version 1809 for 32-bit Systems | Information Disclosure | Important | 5025229 | Security Update | CVE-2023-21729 | | Microsoft ODBC Driver 18 for SQL Server | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28304 | | Microsoft OLE DB Driver 19 for SQL Server | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28304 | | Microsoft OLE DB Driver 18 for SQL Server | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28304 | | Microsoft ODBC Driver 17 for SQL Server | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28304 | | Azure Service Connector | Security Feature Bypass | Important | Release Notes | Security Update | CVE-2023-28300 | | Raw Image Extension | Remote Code Execution | Important | Update Information | Security Update | CVE-2023-28292 | | Windows Server 2012 R2 (Server Core installation) | Information Disclosure | Important | 5025285 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2012 R2 (Server Core installation) | Information Disclosure | Important | 5025288 | Security Only | CVE-2023-21729 | | Windows Server 2012 R2 | Information Disclosure | Important | 5025285 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2012 R2 | Information Disclosure | Important | 5025288 | Security Only | CVE-2023-21729 | | Windows Server 2012 (Server Core installation) | Information Disclosure | Important | 5025287 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2012 (Server Core installation) | Information Disclosure | Important | 5025272 | Security Only | CVE-2023-21729 | | Windows Server 2012 | Information Disclosure | Important | 5025287 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2012 | Information Disclosure | Important | 5025272 | Security Only | CVE-2023-21729 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Information Disclosure | Important | 5025279 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Information Disclosure | Important | 5025277 | Security Only | CVE-2023-21729 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Information Disclosure | Important | 5025279 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Information Disclosure | Important | 5025277 | Security Only | CVE-2023-21729 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5025271 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5025273 | Security Only | CVE-2023-21729 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Information Disclosure | Important | 5025271 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Information Disclosure | Important | 5025273 | Security Only | CVE-2023-21729 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5025271 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Information Disclosure | Important | 5025273 | Security Only | CVE-2023-21729 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Information Disclosure | Important | 5025271 | Monthly Rollup | CVE-2023-21729 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Information Disclosure | Important | 5025273 | Security Only | CVE-2023-21729 | | Windows Server 2016 (Server Core installation) | Information Disclosure | Important | 5025228 | Security Update | CVE-2023-21729 | | Windows Server 2016 | Information Disclosure | Important | 5025228 | Security Update | CVE-2023-21729 | | Windows 10 Version 1607 for x64-based Systems | Information Disclosure | Important | 5025228 | Security Update | CVE-2023-21729 | | Windows 10 Version 1607 for 32-bit Systems | Information Disclosure | Important | 5025228 | Security Update | CVE-2023-21729 | | Windows 10 for x64-based Systems | Information Disclosure | Important | 5025234 | Security Update | CVE-2023-21729 | | Windows 10 for 32-bit Systems | Information Disclosure | Important | 5025234 | Security Update | CVE-2023-21729 | | Windows 10 Version 22H2 for 32-bit Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 22H2 for ARM64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 22H2 for x64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 11 Version 22H2 for x64-based Systems | Information Disclosure | Important | 5025239 | Security Update | CVE-2023-21729 | | Windows 11 Version 22H2 for ARM64-based Systems | Information Disclosure | Important | 5025239 | Security Update | CVE-2023-21729 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 21H2 for ARM64-based Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 10 Version 21H2 for 32-bit Systems | Information Disclosure | Important | 5025221 | Security Update | CVE-2023-21729 | | Windows 11 version 21H2 for ARM64-based Systems | Information Disclosure | Important | 5025224 | Security Update | CVE-2023-21729 | | Windows 11 version 21H2 for x64-based Systems | Information Disclosure | Important | 5025224 | Security Update | CVE-2023-21729 | | Send Customer Voice survey from Dynamics 365 | Spoofing | Important | Release Notes | Security Update | CVE-2023-28313 | | Azure Machine Learning | Information Disclosure | Important | Release Notes | Security Update | CVE-2023-28312 | | Microsoft Office 2019 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Microsoft 365 Apps for Enterprise for 32-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Microsoft Publisher 2013 Service Pack 1 RT | Remote Code Execution | Important | 5002213 | Security Update | CVE-2023-28287 | | Microsoft Office 2019 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Microsoft 365 Apps for Enterprise for 64-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Microsoft Office LTSC 2021 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Microsoft Office LTSC 2021 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2023-28287 | | Visual Studio Code | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-24893 | | Microsoft Dynamics 365 (on-premises) version 9.1 | Spoofing | Important | XXXXXXX | Security Update | CVE-2023-28314 | | Microsoft Dynamics 365 (on-premises) version 9.0 | Spoofing | Important | XXXXXXX | Security Update | CVE-2023-28314 | | Microsoft Visual Studio 2022 version 17.5 | Spoofing | Important | Release Notes | Security Update | CVE-2023-28299 | | Microsoft Visual Studio 2022 version 17.0 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28260 | | Microsoft Visual Studio 2022 version 17.2 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28260 | | Microsoft Visual Studio 2022 version 17.4 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28260 | | Microsoft Office LTSC for Mac 2021 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28311 | | Microsoft Office 2019 for Mac | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-28311 | | Microsoft Publisher 2016 (32-bit edition) | Remote Code Execution | Important | 5002221 | Security Update | CVE-2023-28295 | | Microsoft Publisher 2013 Service Pack 1 (64-bit editions) | Remote Code Execution | Important | 5002213 | Security Update | CVE-2023-28295 | | Microsoft Publisher 2013 Service Pack 1 (32-bit editions) | Remote Code Execution | Important | 5002213 | Security Update | CVE-2023-28295 | | Microsoft Publisher 2016 (64-bit edition) | Remote Code Execution | Important | 5002221 | Security Update | CVE-2023-28295 | | Windows 11 version 21H2 for ARM64-based Systems | Denial of Service | Important | 5025239 | Security Update | CVE-2023-28302 | | Microsoft Visual Studio 2019 version 16.11 (includes 16.0 – 16.10) | Spoofing | Important | Release Notes | Security Update | CVE-2023-28299 | | Microsoft Visual Studio 2017 version 15.9 (includes 15.0 – 15.8) | Spoofing | Important | Release Notes | Security Update | CVE-2023-28299 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | Monthly Rollup | CVE-2023-28297 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022346 | Security Only | CVE-2023-28297 | | Windows Server 2012 R2 | Elevation of Privilege | Important | 5022352 | Monthly Rollup | CVE-2023-28297 | | Windows Server 2012 R2 | Elevation of Privilege | Important | 5022346 | Security Only | CVE-2023-28297 | | Windows Server 2012 (Server Core installation) | Elevation of Privilege | Important | 5022348 | Monthly Rollup | CVE-2023-28297 | | Windows Server 2012 (Server Core installation) | Elevation of Privilege | Important | 5022343 | Security Only | CVE-2023-28297 | | Windows Server 2012 | Elevation of Privilege | Important | 5022348 | Monthly Rollup | CVE-2023-28297 | | Windows Server 2012 | Elevation of Privilege | Important | 5022343 | Security Only | CVE-2023-28297 | | Windows Server 2016 (Server Core installation) | Elevation of Privilege | Important | 5022289 | Security Update | CVE-2023-28297 | | Windows Server 2016 | Elevation of Privilege | Important | 5022289 | Security Update | CVE-2023-28297 | | Windows 10 Version 1607 for x64-based Systems | Elevation of Privilege | Important | 5022289 | Security Update | CVE-2023-28297 | | Windows 10 Version 1607 for 32-bit Systems | Elevation of Privilege | Important | 5022289 | Security Update | CVE-2023-28297 | | Windows 10 for x64-based Systems | Elevation of Privilege | Important | 5022297 | Security Update | CVE-2023-28297 | | Windows 10 for 32-bit Systems | Elevation of Privilege | Important | 5022297 | Security Update | CVE-2023-28297 | | Windows 10 Version 22H2 for 32-bit Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 22H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 22H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 11 Version 22H2 for x64-based Systems | Elevation of Privilege | Important | 5022303 | Security Update | CVE-2023-28297 | | Windows 11 Version 22H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022303 | Security Update | CVE-2023-28297 | | Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 21H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 21H2 for 32-bit Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 11 version 21H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022287 | Security Update | CVE-2023-28297 | | Windows 11 version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022287 | Security Update | CVE-2023-28297 | | Windows 10 Version 20H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 20H2 for 32-bit Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows 10 Version 20H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | Security Update | CVE-2023-28297 | | Windows Server 2022 (Server Core installation) | Elevation of Privilege | Important | 5022291 | Security Update | CVE-2023-28297 | | Windows Server 2022 | Elevation of Privilege | Important | 5022291 | Security Update | CVE-2023-28297 | | Windows Server 2019 (Server Core installation) | Elevation of Privilege | Important | 5022286 | Security Update | CVE-2023-28297 | | Windows Server 2019 | Elevation of Privilege | Important | 5022286 | Security Update | CVE-2023-28297 | | Windows 10 Version 1809 for ARM64-based Systems | Elevation of Privilege | Important | 5022286 | Security Update | CVE-2023-28297 | | Windows 10 Version 1809 for x64-based Systems | Elevation of Privilege | Important | 5022286 | Security Update | CVE-2023-28297 | | Windows 10 Version 1809 for 32-bit Systems | Elevation of Privilege | Important | 5022286 | Security Update | CVE-2023-28297 | | Microsoft SharePoint Foundation 2013 Service Pack 1 | Spoofing | Important | 5002383 | Security Update | CVE-2023-28288 | | Microsoft SharePoint Server Subscription Edition | Spoofing | Important | 5002375 | Security Update | CVE-2023-28288 | | Microsoft SharePoint Server 2019 | Spoofing | Important | 5002373 | Security Update | CVE-2023-28288 | | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | Spoofing | Important | 5002381 | Cumulative Update | CVE-2023-28288 | | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | Spoofing | Important | 5002383 | Security Update | CVE-2023-28288 | | Microsoft SharePoint Enterprise Server 2016 | Spoofing | Important | 5002385 | Security Update | CVE-2023-28288 | | .NET 7.0 | Remote Code Execution | Important | 5025916 | Security Update | CVE-2023-28260 | | .NET 6.0 | Remote Code Execution | Important | 5025915 | Security Update | CVE-2023-28260 | | Remote Desktop client for Windows Desktop | Information Disclosure | Important | Release Notes | Security Update | CVE-2023-28267 | | Microsoft Malware Protection Engine | Denial of Service | Important | Security Update | CVE-2023-24860 | | Microsoft SQL Server 2022 for x64-based Systems (GDR) | Remote Code Execution | Important | 5021522 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2019 for x64-based Systems (CU 18) | Remote Code Execution | Important | 5021124 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2017 for x64-based Systems (CU 31) | Remote Code Execution | Important | 5021126 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connectivity Pack | Remote Code Execution | Important | 5021128 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | Remote Code Execution | Important | 5021129 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU 4) | Remote Code Execution | Important | 5021045 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2019 for x64-based Systems (GDR) | Remote Code Execution | Important | 5021125 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU 4) | Remote Code Execution | Important | 5021045 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR) | Remote Code Execution | Important | 5021037 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR) | Remote Code Execution | Important | 5021037 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2008 for x64-Based Systems Service Pack 4 (QFE) | Remote Code Execution | Important | 5020863 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2008 R2 for x64-Based Systems Service Pack 3 (QFE) | Remote Code Execution | Important | 5021112 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2008 R2 for 32-Bit Systems Service Pack 3 (QFE) | Remote Code Execution | Important | 5021112 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2017 for x64-based Systems (GDR) | Remote Code Execution | Important | 5021127 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE) | Remote Code Execution | Important | 5021123 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE) | Remote Code Execution | Important | 5021123 | Security Update | CVE-2023-23384 | | Microsoft SQL Server 2008 for 32-bit Systems Service Pack 4 (QFE) | Remote Code Execution | Important | 5020863 | Security Update | CVE-2023-23384 |

Quality and experiences updatesWith the April 2023 Patch Tuesday updates, Microsoft’s Local Administrator Password Solution (LAPS) is now natively integrated into Windows. This affects Windows 11 and Windows 10 Pro, EDU, and Enterprise, Windows Server 2022 and Windows Server Core 2022, as well as Windows Server 2019.

The new built-in Windows LAPS also adds support for Azure Active Directory in private preview. Moreover, there are a couple of new capabilities for on-premises Active Directory scenarios, as well as new features for both Azure AD and on-premises AD scenarios. You can more details about what’s new in this article.

On Windows 11 version 22H2, this month’s KB5025239 patch will make the search box on the taskbar look slightly lighter when using custom color mode. This will be especially noticeable if you set Windows mode to dark and app mode to light on your PC.

Lastly, Microsoft has also fixed the following bugs in this patch:

  • USB printers are no longer classified as multimedia devices.
  • Microsoft Narrator can now read dropdown lists in Excel.
  • PowerPoint will no longer become unresponsive when using accessibility tools.
  • NotePad will now show the combo box with all options in Settings.

On Windows 10 versions 20H2, 21H2, and 22H2, the KB5025221 patch addresses a known issue with kiosk device profiles which caused devices where automatic logon is enabled to not work. As mentioned above, this update also adds the new Windows Local Administrator Password Solution (LAPS) as a Windows inbox feature.

Windows Update testing and best practicesOrganizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.

If you have any problems with this month’s patches, please let us know in the comments below. Other readers might be able to share their experiences in how to roll back problematic updates or mitigate issues caused by patches that are important to have in place.

View Details

Microsoft announced yesterday that its Yammer mobile apps for iOS and Android have now been rebranded as Viva Engage. The new app should make it easier for employees to connect with coworkers, find and share content and engage in communities.

Viva Engage is an evolution of the Yammer Communities app in Microsoft Teams that launched back in July 2022. The new service is designed to enable organizations to connect and engage with their employees. Viva Engage provides several tools to help employees with community building, self-expression, knowledge sharing, and leadership engagement.

Microsoft has decided to eliminate the Yammer brand because having two separate social platforms was confusing for enterprise customers. This situation also made it challenging for IT admins to promote adoption and provide clarity for end users.

“With the new Viva Engage app on iOS and Android, you can stay connected with your colleagues, get updates on important projects, and share information easily, all from your mobile device. The app comes with a modern interface, support for device-specific features, and an improved user experience,” Microsoft explained.

Getting started with the Viva Engage mobile appMicrosoft highlights that the new Viva Engage app lets users view important announcements and messages directly from their mobile devices. It also makes it easier for users to participate in org-wide communities on the go. The Viva Engage app lets users upload videos and photos and react to messages from the notifications. It’s also possible to participate in Live Events while using other applications.

Microsoft says that users can download the new Viva Engage app from Google’s Play Store and the App Store. Meanwhile, existing users will need to update their Yammer app to see new features and the Viva Engage branding. “The App Store and Play Store listings will continue to carry a reference to Yammer, as will the push notifications until Yammer.com is rebranded later this year,” Microsoft added.

View Details

Microsoft is officially killing off its extended support for SharePoint Server 2013 today. It’s been a long time coming, but today marks the end of updates for SharePoint Server 2013 and SharePoint Server 2013 Service Pack 1 (SP1).

Microsoft initially released SharePoint Server 2013 back in January 2013. It’s a content management and collaboration platform that included various features and capabilities, including social networking. It also supported a powerful search experience, business intelligence, and automated business processes and workflows.

Microsoft ended mainstream support for SharePoint Server 2013 five years ago on April 10, 2018. Starting today, the company will no longer offer feature and security updates, bug fixes, and other technical support for SharePoint Server 2013.

Microsoft suggests upgrading to SharePoint 2019 or SharePoint OnlineMicrosoft recommends customers to migrate their content to SharePoint Server 2019 or SharePoint Server Subscription Edition in on-premises environments. The company plans to provide extended support for SharePoint 2019 until January 9, 2024.

Alternatively, Microsoft notes that organizations can also choose to switch to the cloud to leverage the new features of SharePoint Online. It should help to reduce the resources required to maintain the platform in on-premises environments.

What happens to organizations still using SharePoint Server 2013?Microsoft has warned that customers who will continue to run SharePoint Server 2013 would be vulnerable to cyberattacks. They will need to deploy additional security solutions (such as advanced firewalls and intrusion detection systems) to protect their unsupported environments. Microsoft noted that organizations running SharePoint Server 2013 will also inevitably be at a higher risk of workflow disruption or downtime.

View Details

Microsoft has announced several new capabilities added to its Windows Autopatch service this month. The company has introduced a new feature that enables customers to set custom schedules for the deployment of quality updates for each ring in their tenants.

Specifically, IT admins can now configure deadline-driven or scheduled install settings in Microsoft Intune. The scheduled install feature lets IT Pros apply updates outside of working hours on Windows machines. Deadline-driven customizations enable customers to modify deadlines, deferrals, and grace periods within 14 days.

Last month, Microsoft unveiled a new Windows Autopatch feature that lets IT admins block updates for Microsoft 365 Apps. The company has announced that this capability is now generally available for all enterprise customers.

“Since Windows Autopatch currently sets enrolled devices to Microsoft 365 App updates via the Monthly Enterprise Channel, this feature allows organizations subscribed to different channels to still take advantage of Windows Autopatch,” Microsoft explained.

Microsoft has also announced some enhancements coming to the Tenant management blade. The company will alert IT admins about expired licenses that need to be replaced or renewed to retain access to Windows Autopatch.

Windows Autopatch to add new reporting features and much moreMicrosoft has also announced several new capabilities that will soon be available in public preview in Windows Autopatch. First up, IT admins will be able to use Windows Autopatch to deploy Windows 11 updates. Additionally, they will be able to utilize Autopatch groups to apply various cadences and ring configurations to a specific set of Windows devices.

Microsoft’s Windows Autopatch is also getting support for new reports that will provide more insights such as feature updates. Some new settings will help organizations ensure the enforcement of policies and configurations. Other capabilities include a new 5-ring default option and support for custom ring configurations.

View Details

Microsoft Teams has added a new feature that should make it easier for users to spice up their virtual meetings. Indeed, Microsoft has partnered with Snap to bring new Snapchat Lenses to Microsoft Teams meetings.

With this release, Microsoft Teams users can now access a collection of 26 popular Snapchat Lenses during meetings. Participants can use the Lenses to transform themselves into cartoon characters and add a variety of backgrounds to their video feeds. The feature eliminates the need to use third-party apps to use these Lenses in Teams.

“Lenses allow users to add augmented reality (AR) effects to video calls, bringing livelier human interaction to meetings. AR captures and processes information about our physical environment and then overlays it with virtual objects and information, allowing us to see and experience the world in a different way. Since AR uses cameras, sensors, and displays, which are already built into video conferencing, it is a perfect and seamless fit with Teams,” Microsoft explained.

How to enable Snapchat Lenses in Microsoft TeamsTo turn on Snapchat Lenses before a meeting, Microsoft Teams users will need to click Video Effects and select the More Video Effects option. Navigate to the right pane and click Snapchat under the Filters category. Select any Lens and then click the Join Now button.

Alternatively, Microsoft Teams users can turn on Snapchat Lenses during an ongoing meeting. To do this, click the More (. . .) menu at the top of the screen and select Video Effects. Navigate to the Filters category and click the Snapchat option. Finally, select any Lens from the list and click Apply to preview the changes.

Microsoft confirmed that the new Snapchat Lenses are only available for work accounts in Microsoft Teams. For now, the feature is currently supported in the classic version of the Teams desktop app. The company plans to add support for the new Microsoft Teams client by the end of this year. Let us know in the comments below if you think the new Snapchat Lenses will help to make hybrid meetings more fun and engaging for the participants.

View Details

Register for our webinar on April 12th to discover how to establish hardened configurations for your Windows servers and endpoints, and how to monitor file activity to spot potential attacks in progress.

Dirk Schrader, VP of Security Research at Netwrix, will cover:

  • Using best-practice benchmarks to establish hardened configurations across your IT estate.
  • Tuning baselines to fit your needs and risk tolerance.
  • Monitoring file activity while avoiding alert fatigue.
  • Promptly remediating configuration drift.
  • And how to maintain and prove regulatory compliance.

Most compliance regulations and security frameworks recommend implementing system hardening and FIM whenever possible. So, this webinar is essential for organizations that need to be compliant or want to avoid security breaches and disruptions to business processes.

System hardening and FIMSystem hardening involves changing the out-of-box configuration of Windows and Windows Server to a more secure default that helps protect against common threats. You should establish secure baselines that provide additional protection but also don’t break important functionality.

File Integrity Monitoring (FIM) checks operating system and application files to ensure they haven’t been modified or are corrupted. Comparing files to a known and trusted baseline allows IT to establish whether changes might indicate a problem or malicious activity.

FIM is an important component of Windows change auditing and it is required to meet some compliance mandates. In the webinar, you will learn how FIM can help with system hardening, and block and detect malware and other cyberthreats that might endanger your environment.

Register now using the link below or at petri.com.

View Details

Microsoft has warned that an Iranian state-backed threat actor dubbed Mercury has been carrying out destructive attacks in hybrid environments. The Microsoft Threat Intelligence team has found that the attackers teamed up with another hacking group code-named DEV-1084 to target both on-premises and cloud customers.

According to Microsoft, Mercury first exploited the log4j vulnerability to gain initial access to the system. The threat actors established persistence and then moved laterally throughout the enterprise network. Once done, Mercury handed out network access to the DEV-1084 group that launched two separate attacks against on-premises resources and Microsoft Azure.

Specifically, the threat actor leveraged Group Policy Objects (GPO) to interfere with the security tools and distribute ransomware in the NETLOGON shares on Active Directory domain controllers (DCs).

Additionally, the hacking group used the AADInternals tool to harvest credentials for the Azure AD Connector account. They also used RDP to compromise another Global Administrator account and bypass MFA.

“Azure AD Connector account and the compromised administrator account were then used to perform significant destruction of the Azure environment—deleting within a few hours server farms, virtual machines, storage accounts, and virtual networks. We assess that the attacker’s goal was to cause data loss and a denial of service (DoS) of the target’s services,” the Microsoft Threat Intelligence team explained.

How to block destructive attacks in on-prem and Azure AD environmentsMicrosoft has detailed a couple of recommendations to protect organizations against similar attacks. Customers should enable Tamper protection features in Microsoft Defender for Endpoint to prevent misconfigurations in antivirus solutions. Secondly, IT admins should review global admin permissions in their Microsoft 365 environment.

Furthermore, Microsoft suggests enforcing Conditional Access policies (like trusted IP address and device compliance). It’s highly recommended to enable continuous access evaluation (CAE) to block access to compromised accounts to mitigate cyberattacks. Microsoft says that administrators should also keep an eye on any unusual activities on the Azure AD connector and AD DS connector accounts.

View Details

Last year, Microsoft unveiled that it would phase out Client Access Rules (CARs) in Exchange Online in September this year. Now, the company has announced that it has delayed the deprecation of CARs, and it’s expected to be complete until September 2024.

Client Access Rules (CARs) is a feature that enables IT admins to allow or block client connections to Exchange Online based on various parameters, including user agents, IP addresses, and authentication methods. The feature lets administrators configure policies to protect Exchange Online resources against security risks, security risks, and ensure compliance with regulatory requirements.

Last October, Microsoft disabled CARs for Exchange Online customers who were not using the cmdlets. This change was aimed at encouraging organizations to switch to more secure methods like continuous access evaluation (CAE) and Azure Active Directory (Azure AD) conditional access.

Microsoft has acknowledged that some enterprise customers are facing challenges while migrating certain CARs to conditional access and CAE. This means that these organizations won’t be able to complete the migration process until September this year.

“We have been working with customers to learn how they use CARs and how they can migrate to these newer features, but we have encountered a few scenarios where it’s not possible to migrate current rules. For these scenarios, we will allow the use of CARs beyond the previously announced September 2023 deadline until we can support them,” the Exchange team explained.

Microsoft Exchange team to help IT admins with Client Access Rules migration plansMicrosoft explained that the migration process would require some planning and testing within the organization. The company recommends IT admins to open a support ticket to address any technical issues that might be preventing them from switching CARs to Conditional Access and CAE.

Last month, Microsoft also announced its plans to postpone the deprecation of Remote PowerShell (RPS) in Exchange Online until October 2023. The Exchange team advised all customers to move from the legacy Remote PowerShell Protocol to the PowerShell v3 module.

View Details

The Windows Subsystem for Linux 2 (WSL2) allows Windows 10 and Windows 11 users to run a Linux distribution without using a virtual machine. Recent versions of Windows 10/11 make it very easy for developers to get started with WSL2 and run Linux repositories natively. In this article, I’ll explain how to install WSL2 on Windows 10 or Windows 11, and I’ll also show you everything you can do with WSL2 on Windows.

Install WSL2 on Windows 10 and Windows 11You can install WSL2 on Windows 10 or Windows 11 by running the following PowerShell command (with admin privileges):

wsl --install This command will install WSL2, the virtual machine platform, as well as the Ubuntu Linux distribution for you. Reboot your PC to see them appear in your Start Menu.

Keep reading for more detailed instructions on how to install WSL2 on a virtual machine or on an older version of Windows 10 version 1909 or older.

What is the Windows Subsystem for Linux 2 (WSL2)?Many people across various user bases cried joy when Microsoft announced the Windows Subsystem for Linux in 2016. This developer-focused feature allows a wide variety of users to run a Linux environment natively in Windows 10 and Windows 11 without needing to dual boot or use a virtual machine. All the required technology is now a part of Windows.

There are two versions available: WSL1 and WSL2. In May of 2019, WSL2 was announced with some significant new features, most notably a native Linux kernel utilizing some core Hyper-V functionality. A key performance improvement included substantially faster read/write I/O operations.

Installing WSL2 on modern versions of Windows 10 and Windows 11What are we waiting for? Let’s get started with the technical requirements to install WSL2 on modern versions of Windows 10 and Windows 11

Technical requirements for installing WSL2* Windows 10 version 1803 or newer + (Optional) You need to run Windows 10 version 2004 (or higher) or Windows 11 to be able to use the simple installation commands below. * x64 or ARM processor. * Virtualization attributes must be enabled in your system’s BIOS. + If you are planning to install WSL2 on a virtual machine, you need to have nested virtualization enabled. I will cover that later on in the article.

Microsoft initially had quite a few steps required to get WSL1 installed and working about seven years ago. You’ll discover those in the section below if you’re running Windows 10 version 1909 or earlier (By the way, what didn’t you upgrade already?)

Once you are running Windows 10 2004 or newer (build 19041 or newer), you’ll be able to get up and running with minimal effort. Let’s jump in!

Enabling WSL2 with PowerShellStarting with my Windows 10 PC (Image credit: Petri/Michael Reinders)I will be using my Hyper-V lab on my (new) desktop computer. I have a VM running Windows 10 Enterprise version 22H2. However, you only need version 2004 or newer – just being complete.

  • To start, open a PowerShell prompt with admin privileges.

Windows PowerShell (Image credit: Petri/Michael Reinders)* Enter the following command to install WSL2:

wsl --install Using the ultra-efficient ‘wsl –install’ powerhouse command! (Image credit: Petri/Michael Reinders)Watch it go! The command installs the Virtual Machine Platform, Windows Subsystem for Linux, and even installs the Ubuntu Linux distribution for you. How nice. Next, let’s restart.

After a reboot, you’ll notice that Windows Subsystem for Linux and Ubuntu now appear in the Start Menu.

New WSL items in the Start Menu (Image credit: Petri/Michael Reinders)Plus, on my system, Ubuntu launched on its own. Another nice touch. However, in my case, we encounter a temporary issue regarding virtualizations.

We need to resolve the issue with virtualization before proceeding… (Image credit: Petri/Michael Reinders)As I stated above, WSL2 uses a subset of Hyper-V technologies. Because of this, your computer’s BIOS (UEFI) needs to have CPU virtualization features enabled.

If this was a physical desktop or laptop (or server), you would boot into your BIOS settings and confirm these are enabled. But in this case, I am already running a virtual machine. So, I need to run a PowerShell command on my host computer to enable special flags on the VM I am using.

  • I will power down my VM and run this command.

Set-VMProcessor -VMName "Windows 10 22H2 - AAD - x3v6p (Petri)" -ExposeVirtualizationExtensions $true Enabling nested virtualization on our Hyper-V VM… (Image credit: Petri/Michael Reinders)* Now, I can power up my VM and run Ubuntu from the Start Menu.

Ubuntu is alive! (Image credit: Petri/Michael Reinders)Success, Ubuntu now works after enabling nested virtualization.

Post-setup tasks and best practicesAfter I launched Ubuntu, I was prompted to create a UNIX username and enter a password (twice). I did that and voila! Ubuntu 22.04.1 LTS running natively on Windows 10. Pretty slick.

As a Linux learner, I do have a decent amount of commands at my disposal. I have a few things I run whenever I fire up a new distro. You can run the following command to get updates for the core modules in this flavor, then upgrade said modules in one fell swoop!

sudo apt-get update && sudo apt-get upgrade -y Running some ‘apt-get’ commands to update and upgrade our distro’s modules (Image credit: Petri/Michael Reinders)Now we have the newest and most secure modules in our Linux distribution.

Installing WSL2 on older versions of Windows 10If you happen to be running Windows 10 version 1909 or earlier on your PC, you will need to hop through considerably more hoops. But, don’t fret, the command line helps here. It’s not that bad. Plus, it gives you an excuse to remain familiar with your favorite pal, PowerShell.

Enabling WSL2Let’s begin. I just installed Windows Terminal so I can copy and paste.

  • Open an administrative Terminal window and run this command to install Microsoft WSL.

dism.exe /online /enable-feature /featurename:Microsoft-Windows-Subsystem-Linux /all /norestart Next, we will enable the Virtual Machine platform feature. Again, if you happen to be running this in a VM, you need to make sure you’ve enabled the virtualization flags for the VM. As I already did it above, I don’t need to perform the steps here.

  • Run the following command to enable WSL, and then reboot.

dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart Using PowerShell to enable WSL the ‘hard’ way (Image credit: Petri/Michael Reinders)* After the reboot, download the ‘WSL2 Linux kernel update package for x64 machines’ via this link. Make sure to run it from a command prompt with admin rights.

Updating the WSL kernel via a download from Microsoft (Image credit: Petri/Michael Reinders)Next, this should already be done, but we will make sure the default version of WSL used in future distros will be the newer ‘WSL2’.

  • Use the command below to ensure that all future Linux distros will be using WSL2:

wsl --set-default-version 2 Verifying all future distros will run as ‘WSL2’ (Image credit: Petri/Michael Reinders)Ok, we are almost there. From here, we can open the Microsoft Store and search for distributions. You can use keywords like ‘ubuntu’, ‘suse’, ‘opensuse’, etc. Here are a good number of direct links from Microsoft to get you started.

  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • openSUSE Leap 15.1
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP1
  • Kali Linux
  • Debian GNU/Linux
  • Fedora Remix for WSL
  • Pengwin
  • Pengwin Enterprise
  • Alpine WSL
  • Raft(Free Trial)

And that’s it! After you click ‘Get’ on each Store item, it will install and prompt you to run through its respective user provisioning.

After installing the Linux distribution of your choice, I recommend to go through the additional steps and best practices I detailed earlier in my article.

Tips and tricks for WSL2There are countless things to accomplish in the world of Linux, and venturing off into that lovely world is outside the scope of this article. The potential here to increase productivity by running native Linux distros is boundless. However, the first tip I highly recommend is using Windows Terminal.

Windows TerminalWindows Terminal is the most useful tool you have to run WSL2, especially when you’re running multiple distros. Each time you launch Windows Terminal, it will check and discover local WSL distros you can launch right in the same window.

Using Terminal to access various distros seamlessly! (Image credit: Petri/Michael Reinders)As you can see, Terminal knows what distros I have. I can open a new tab in Terminal, each running a different flavor of Linux.

Using Windows Terminal to see all your distros in one window (Image credit: Petri/Michael Reinders)Very cool! And I’m a Windows user!

Can you use WSL1 and WSL2 simultaneously?In case you’re asking about the two versions of WSL, yes, you can certainly run some distros on WSL1 and some on WSL2. You can run the following command to list all the distros you have installed and what version they’re running.

wsl --list --verbose I have 3 distros at the moment and they are all WSL2. That is the default.

Want to convert one of them to WSL1? Go ahead and run the following command. After the ‘–set-version’, you enter the distribution name (in this case ‘Ubuntu’), and there it is.

wsl --set-version ubuntu 1 Seeing if distros are running WSL1 or WSL2 (Image credit: Petri/Michael Reinders)WSL1 vs WSL2: How to choose?As Microsoft explained on a support page, There are reasons why you may need or want to use WSL1 for some of your scenarios. The first one would be a project that requires cross-compilation using both Windows and Linux tools on the same files

File performance across the Windows and Linux operating systems is actually faster in WSL1 than it is in WSL2. As a result, if you’re using Windows applications to access Linux files, you will currently achieve faster performance with WSL1.

The second use case where using WSL1 beats WSL2 is if your project files must be stored in the Windows file system. If you use your WSL Linux distribution to access project files on the Windows file system, which cannot be stored on the Linux file system, you will achieve faster performance across the OS file systems by using WSL1.

Advantages to running native Linux distributions in WindowsThere are many advantages to running native Linux distributions in Windows 10/11 with WSL2. You don’t need to worry about having another computer, or even another virtual machine. A subset of core Hyper-V technology was developed solely for this purpose. Plus, using Windows Terminal to have a handle on ALL your local distros, PowerShell, command prompt… it’s a truly wonderful solution.

There are several hooks for developing applications with Visual Studio. You can read these Microsoft documentation links for more information.

  • Walkthrough: Build and Debug C++ with Microsoft Windows Subsystem for Linux 2 (WSL2) and Visual Studio 2022 | Microsoft Learn
  • Get started using VS Code with WSL | Microsoft Learn
  • Targeting the Windows Subsystem for Linux from Visual Studio – C++ Team Blog (microsoft.com)

Thank you for reading – please leave a comment below with a question!

View Details

MC538726 – Microsoft is bringing improvements for Meeting Recapping. Now, you can find your recording, transcripts, meeting content, and meeting notes all under a single new Recap tab. Watch your recording directly in the Recap tab to catch up on what was discussed while reviewing the notes and transcript without having to switch screens/apps.

When this will happen:

Targeted Release: Microsoft will begin rolling out late April and expect to complete by early May.

Preview: Microsoft will begin rolling out late April and expect to complete by early May.

Standard Release: Microsoft will begin rolling out late May and expect to complete by early June.

How this will affect your organization:

Users can access Recap from Calendar after meeting ended or directly from meeting chat.

When both recording and transcript is available from the meeting, the recap tab will show (if applicable for the meeting)

  • Recording
  • Content (Presented PowerPoint Live files, Sent file in Meeting Chat, Attendance Report for organizer)
  • Manual notes (if added)
  • Transcript (view, search and download)

This feature does not require Teams Premium license. For Teams Premium Meeting Recap, see MC post: MC537956.

View image in new tab

View image in new tab

What you need to do to prepare:

You may consider updating the training materials for you users to inform this feature is now available.

View Details

MC538725 – Starting with Edge 113, Microsoft Edge for macOS will begin using a new updater called EdgeUpdater.

Note: This change only affects Microsoft Edge on macOS.

Microsoft Edge on macOS

  • Timing: Beginning with Microsoft Edge version 113 (scheduled for the week of May 4, 2023)
  • Action: If you use update preferences for Microsoft Autoupdate to prevent browser updates, you will need to transition to the new EdgeUpdater UpdateDefault policy before Edge 113 to prevent future automatic updates.

How this will affect your organization:

If you do not transition before the new EdgeUpdater is deployed with Edge 113 (scheduled for the week of May 4. 2023), the new updater will default to updating Microsoft Edge automatically on your macOS devices.

What you need to do to prepare:

To maintain your desired update preferences, you will need to transition to the new EdgeUpdater UpdateDefault policy and set your preferences prior to Edge 113.

Additional information:

  • See our article on Microsoft Learn
  • Microsoft 365 Roadmap – Feature ID: 114512

Microsoft always value feedback and questions from our customers. Please feel free to submit either feedback or questions via Message Center.

Help and support

View Details

Microsoft has announced some important changes coming to its Microsoft Entra Entitlement Management service. Starting on May 3, employees in the user admin role won’t be able to perform identity governance tasks such as managing Entitlement Management catalogs and access packages.

Microsoft Entra Entitlement management is an identity management feature that lets customers manage and control access to applications and resources. It helps to automate access requests, access assignments, reviews, and expiration workflows. Entitlement management makes it easier for IT admins to ensure that only authorized internal and external users have access to groups, applications, and SharePoint Online sites.

Essentially, an access package is a bundle that comprises all the necessary resources that a user requires to carry out their tasks. These access packages are defined within containers called catalogs.

User Admin role updates in Microsoft Entra Entitlement ManagementGoing forwards, Microsoft says that organizations will need to use the Identity Governance Administrator role for daily management tasks. It’s highly recommended that IT admins should ensure that only those users have permission to manage Entitlement Management catalogs and access packages.

“We want to ensure minimal customer impact when we remove Entitlement Management permissions from the User Administrator role. By assigning admins the Identity Governance Administrator role, they will have the necessary permissions to continue managing catalogs and access packages,” Microsoft explained in a message on the Microsoft 365 admin center.

Microsoft explained that IT admins will be able to manage role assignments through the Azure Active Directory admin center or Graph API. You can find more details on how to update or remove existing role assignments on this support page.

View Details

Microsoft has started testing a new Browser Essential feature in Microsoft Edge. The new tool provides a unified dashboard that enables users to monitor the performance and security of the web browser.

Microsoft explained that users can click on the Browser Essentials toolbar icon to view key performance metrics in Microsoft Edge. It provides insights about features such as the Performance Detector, Sleeping Tabs, and Sleeping Tabs.

“We know it can be difficult to understand whether a browser is really giving you a great experience. For that reason, we’ve improved upon the previous Performance Hub and created Browser essentials to reveal how Microsoft Edge’s performance and security features make your everyday browsing fast, efficient, and safe,” the Microsoft Edge team explained.

Microsoft Edge uses the SmartScreen service to protect users from phishing and malware websites and applications. Browser Essentials includes reports that offer insights into the harmful websites and downloads that have been scanned and blocked within the browser.

Last but not least, the Performance Detector feature helps to detect performance issues (such as high RAM and CPU usage of background tabs) in Microsoft Edge. It uses Browser Essentials to provide recommended actions to reduce memory usage and other resources. Microsoft plans to add support for more recommendations in future releases.

How to access Browser Essentials in Microsoft Edge?Currently, the Browser Essentials tool is only available to all Edge Insiders in the Canary Channel and select testers in the Dev Channel. Browser Essentials will eventually replace the existing Performance Hub in Microsoft Edge version 112.

Microsoft Edge users can access the feature by clicking the heart pulse icon available on the toolbar. Microsoft will continue to listen to user feedback to expand the tool to more users in the coming months.

Microsoft Edge has also introduced a new Workspaces feature in public preview. It allows users to save and share a group of browser tabs with other people. Microsoft Edge Workspaces support is currently supported on Windows and macOS.

View Details

SQL Server sample databases can be very useful for learning new techniques or trying out various samples of code. In this article, I’ll detail what you can do with the main SQL Server sample databases including Northwind, AdventureWorks, and WideWorldImporters. I’ll also show you how to find these SQL Server sample databases and install them.

What are SQL Server sample databases?SQL Server sample databases contain fictitious information that can be safely used for testing and development. However, no sample databases have been installed during the SQL Server installation process since SQL Server 2005.

At some point, Microsoft felt that sample databases were a potential security exposure, and that’s why they removed them from the SQL Server code base. That said, over the years Microsoft has provided several sample databases for the SQL Server relational database management system and Analysis Services.

The main sample databases available today are Pubs, Northwind, AdventureWorks, and WideWorldImporters.

As you’ll see throughout this article, these different sample databases give you different types of data you can use for your testing and development scenarios.

Pubs and Northwind sample databasesPubs is the first sample publisher database that came with SQL Server, and it was originally developed by Sybase. It’s based on a publishing company tracking books, authors, and sales.

The Pubs sample databse used to be available as an option as a part of the SQL Server installation process until the SQL Server 2005 release. However, many SQL Server users thought it was too simple to be a good sample.

To provide a more complex sample database, Microsoft made the Northwind database available with SQL Server 2000 release. It was originally developed by the Access team, and it’s based on a food import and export company called Northwind Traders.

Microsoft later removed the Northwind database with the release of SQL Server 2005. However, SQL Server users can still download them from Northwind and pubs Sample Databases for SQL Server 2000.

The download is a .msi installation file called SQL2000SampleDb.msi. Running the installation file extracts T-SQL database scripts into the default folder (C:\SQL Server 2000 Sample Databases), as you can see below.

You can still install the Northwind and Pubs sample databases (Image credit: Petri/Michael Otey)You can install the two samples by running the instpubs.sql script to install the Pubs sample, as well as the instnwnd.sql script to install the Northwind sample. The scripts contain all of the code needed to create and populate the tables for each database.

  • First, open the .sql files using the SQL Server Management Studio (SSMS) Query editor as you can see in the image below.

Opening the .sql files for the two sample databases with SSMS’ Query Editor (Image credit: Petri/Michael Otey) Click the green Execute* button to run the scripts.

When I first ran the instpubs.sql script to install the Pubs sample, I got the error “Could not find stored procedure ‘sp_dboption’.” This stored procedure was removed from SQL Server following the SQL Server 2008 release. However, deleting the following lines allowed the script to run with no errors.

execute sp\_dboption 'pubs' ,'trunc. log on chkpt.' ,'true'GO Running the instnwd.sql script to install the Northwinds sample produced the same “Could not find stored procedure ‘sp_dboption’ error.” In this case, deleting the following lines allowed the script to run to completion.

exec sp\_dboption 'Northwind','trunc. log on chkpt.','true'exec sp\_dboption 'Northwind','select into/bulkcopy','true'GO Running these T-SQL scripts will create and populate the Pubs and Northwind sample databases. Afterward, you can use them like any other SQL Server database.

AdventureWorks and AdventureWorksLT sample databasesStarting with SQL Server 2005, Microsoft released the AdventureWorks sample database, which was intended to replace Pubs and Northwind. AdventureWorks is an example database for a multinational bicycle manufacturing and sales company called Adventure Works Cycles, and it uses the SQL Server user-schema naming system that Microsoft introduced with SQL Server 2005.

The primary relational versions of the AdventureWorks databases are AdventureWorks and AdventureWorksLT. The latter is a smaller and simpler version of the full AdventureWorks database. There are multiple versions of these databases for each release of SQL Server since SQL Server 2008 R2. However, so far, there hasn’t been a new release for SQL Server 2022.

The AdventureWorks samples for the different SQL Server versions were originally found on CodePlex, but the CodePlex site was shut down in 2017. They have since been moved to GitHub. The table below includes download links for all versions of the AdventureWorks sample database.

| AdventureWorks sample database | AdventureWorksLT sample database | | AdventureWorks2019.bak | AdventureWorksLT2019.bak | | AdventureWorks2017.bak | AdventureWorksLT2017.bak | | AdventureWorks2016.bak | AdventureWorksLT2016.bak | | AdventureWorks2016_EXT.bak | N/A | | AdventureWorks2014.bak | AdventureWorksLT2014.bak | | AdventureWorks2012.bak | AdventureWorksLT2012.bak | | AdventureWorks2008R2.bak |

These downloads are full database backups (.bak) files that you can use to install the AdventureWorks samples. You can simply download the .bak file and then use SSMS or the T-SQL RESTORE statement to restore the backup file as a SQL Server database.

In the image below, you can see that SSMS restore dialog for the AdventureWorks2019 prompts you for the .bak file to restore and also asks for a database name.

Restoring the AdventureWorks2019 sample database from a backup file (Image credit: Petri/Michael Otey)In addition to the relational database samples, Microsoft has also made business intelligence/data warehousing samples for the AdventureWorks database called AdventureWorksDW and AdventureWorksAS. These samples can be used with SQL Server Analysis Services. They are installed just like the relational samples by downloading a restoring a .bak file. The BI samples are at the following GitHub locations:

  • AdventureWorksDW2019.bak
  • AdventureWorksDW2017.bak
  • AdventureWorksDW2016.bak
  • AdventureWorksDW2016_EXT.bak
  • AdventureWorksDW2014.bak
  • AdventureWorksDW2012.bak
  • AdventureWorksDW2008R2.bak

WideWorldImporters sample databaseWith the release of SQL Server 2016, Microsoft made the new WideWorldImporters database available. It’s for an example wholesale novelty goods importer and distributor, and it can be used to get familiar with temporal tables, In-Memory OLTP, columnstore indexes, Row-Level Security (RLS), dynamic data masking (DDM), and more.

There are different versions of the WideWorldImporters relational database for the on-premises version of SQL Server 2016 and higher as well as for Azure SQL Database:

  • WideWorldImporters-Full.bak: For the SQL Server 2016 Enterprise edition and higher. It is in the backup file format.
  • WideWorldImporters-Standard.bak: For the SQL Server 2016 Standard edition and higher. It is also in the backup file format.
  • WideWorldImporters-Full.bacpac: This is for the Azure SQL Database Premium tier. It provides a full-featured OLTP sample database in BACPAC format.
  • WideWorldImporters-Standard.bacpac – This is also for the Azure SQL Database Standard tier and it provides a standard edition OLTP sample database in BACPAC format.

To install the WideWorldImporters sample database on a local SQL Server system, you can download the .bak file and then use SSMS or T-SQL RESTORE to restore the backup file as a SQL Server database. You can see the SSMS restore dialog for the WideWorldImporter database in the following figure.

Installing the WideWorldImporters sample database by restoring a backup file (Image credit: Petri/Michael Otey)The various BACPAC files can be used with SQL Server on-premises or Azure SQL Server. To import a .bacpac file as a new SQL Server database, you can use the SQL Server Management Studio.

  • Click on the Database node and select the Import Data-Tier Application option from the context menu.
  • Follow the prompts in the Import Wizard you can see below to import the sample database from the .bacpac file.

Importing a .bacpac file as a new SQL Server database in SSMS (Image credit: Petri/Michael Otey)Like you might expect, in addition to the relational samples there are also several data warehousing examples.

  • WideWorldImportersDW-Full.bak – For the SQL Server 2016 Enterprise edition and higher. It is in the backup file format.
  • WideWorldImportersDW-Standard.bak – For the SQL Server 2016 Standard edition and higher. It is in the backup file format.
  • WideWorldImportersDW-Fullbacpac – For Azure SQL Database Premium tier. It provides a full featured OLTP sample database in the BACPAC format.
  • WideWorldImportersDW-Standard.bacpac – For Azure SQL Database Standard tier. It provides a standard edition OLTP sample database in BACPAC format.

For more details about generating data for the sample database, you can check out the article about WideWorldImporters data generation on Microsoft Learn. There are code samples in the samplescripts.zip file that contain T-SQL scripts showing how to use different features in this database. Plus, there is a workloaddrivers.zip file that contains two programs that can that simulate a workload running against the WideWorldImporters database.

SummaryIn this tutorial, you learned about the different Microsoft SQL Server sample databases including Northwind, AdventureWorks, and WideWorldImporters. This guide should help you decide which samples you might want to use for your testing and development, and you can find more information in the Microsoft SQL Server documentation.

View Details

MC537956 – Users with a Teams Premium license will now be able to access a comprehensive meeting overview in the new ‘Recap’ tab in Teams, which leverages AI to provide personalized highlights and key insights from the meeting.

This message is associated with Microsoft 365 Roadmap ID 122529

When this will happen:

Targeted Release and Preview: Microsoft will begin rolling out late April and expect to complete by early May.

Standard Release: Microsoft will begin rolling out mid-May and expect to complete by late May.

How this will affect your organization:

For users with a Teams Premium license, Intelligent Meeting Recap is a comprehensive AI-powered meeting recap experience that helps users catch-up, recall, and follow-up on hour-long meetings in minutes by providing recording and transcription playback with AI assistance. Located on the new ‘Recap’ tab in Teams calendar and Chat app, this experience also allows users to browse the recording by speakers, and topics, as well as access AI-generated suggested notes, suggested tasks, and @mentions.

View image in new tab

What you need to do to prepare:

The feature is only available for Teams Premium users and for meetings that were transcribed and recorded. The user can toggle an option to be anonymized in meeting transcripts, by access Teams setting -> Captions and Transcripts.

You may consider notifying your Teams Premium users about this change and updating your training and documentation as appropriate.

View Details

MC537955 – A new authorization model is implemented for Planner plans, which will be a ‘shared container-based’ authorization model, where OneDrive and SharePoint Online files can be linked to plans to provide users with access to the plan if they have access to the shared container. This means that file-based authorization for plans will provide streamlined access to roster-backed plans that are connected to one or more SharePoint Online/OneDrive files. Note: Graph API is available only in beta

For eg: A user with access to a Loop component or meeting notes that is linked to a plan in Planner will be able to access the plan without needing to be added as a roster member and thereby reducing any potential authorization errors that may arise owing to either roster limits or the absence of another user who can grant access.

When this will happen:

Standard Release: Microsoft will begin rolling out early April 2023 and expect to complete by mid-April 2023.

How this will affect your organization:

The users will have a revised authorization experience for the roster plans. The new authorization model allows users to access roster plans that have been shared with a file if they have access to the file (even if the user is not a direct member of the plan).

Users of a Planner plan will see an informatory note as “People with access to these files can also access this plan”.

Users who do not have access to the file (but are roster members) will be informed that a file is providing access to the plan but will not be informed what that file is.

What you need to do to prepare:

There is no action needed to prepare for this change. You may want to notify your users about this change and update any relevant documentation as appropriate.

View Details

MC537952 – Microsoft is updating the chat details experience for Teams Mobile Group Chats, One on One Chats, and Self Chats.

This message is associated with Microsoft 365 Roadmap ID: 114938

When this will happen:

Targeted Release (Preview): Microsoft will begin rolling out in mid-April and expect to complete rollout by mid-May.

Standard Release: Microsoft will begin rolling out in mid-April and expect to complete rollout by mid-May.

GCC, GCC-H, DoD: Microsoft will begin rolling out in late May and expect to complete rollout by early June.

How this will affect your organization:

The following items will be new:

  • Updated UI and layout.
  • Users are now able to access their own people card from the chat details and see Files and Apps from that conversation rather than seeing Files and Apps from the chat canvas, which will be deprecated.

View image in new tab

View image in new tab

View image in new tab

What you need to do to prepare:

There is no action required at this time. You may want to notify your users of this change.

View Details

Microsoft announced this morning that its Windows 365 Cloud PC service is now available in public preview for frontline workers. The new offering is designed to provide secure and personalized experiences for shift workers, seasonal staff, and part-time employees.

Microsoft introduced its Windows 365 Cloud PC service back in July 2021. It enables users to remotely access their Windows 10 and Windows 11 PCs on any device through a web browser. Microsoft’s new Windows 365 Frontline offering lets organizations use a single license to configure up to three Cloud PCs.

“With Windows 365 Frontline, each license you purchase enables three people to access a Cloud PC during their work hours. This means that instead of purchasing a license for every shift worker, you can purchase only enough licenses for the number of active employees at a given time,” explained Wangui McKelvey, GM for modern work apps at Microsoft.

Windows 365 Frontline lets IT admins set session time limitsMicrosoft highlighted that Windows 365 Frontline also includes some additional capabilities to meet the needs of businesses with shift or part-time workers. First up, IT admins can use the automatic lock screen feature to set up a configuration that will log users out of their Cloud PCs after a specific period of inactivity. It helps to protect sensitive data and confidential information from unauthorized access.

Microsoft has introduced the ability to automatically sign out users at the end of their shifts. There are also some new management features to deploy Windows updates outside of working hours to minimize reboots. The frontline utilization report lets administrators monitor the usage patterns of Cloud PCs in Microsoft Intune.

The auto reset feature lets users restore the Windows 365 Cloud PCs to their original state for each new session. It should be useful for employees who handle sensitive data such as healthcare workers, technical support, and customer service agents. However, this capability is currently not available during the public preview.

Windows 365 Cloud PC gets new LG TV integrationMicrosoft says that customers can sign up to access the public preview of Windows 365 Frontline on this website. Notably, IT admins will be able to use Microsoft Intune to manage Windows 365 Frontline Cloud PCs alongside other Cloud PCs and endpoints.

Finally, Microsoft has expanded Windows 365 support to more devices, including LG’s latest smart TVs and Motorola Android phones. The company has announced that its Windows 365 app is now available to download in the Microsoft Store. Microsoft is also planning to add offline support to Windows 365 that will let users work locally due to connectivity issues.

View Details

Amazon GuardDuty has introduced Amazon EKS Runtime Monitoring support this week. The new capability enables organizations to detect runtime threats from more than 30 security findings to protect EKS clusters.

Amazon launched the Amazon GuardDuty feature back in 2017. It’s a threat detection service that uses AI and other security tools to monitor AWS accounts for suspicious activities and potential security threats. Amazon GuardDuty provides detailed insights and real-time alerts to help security teams investigate and remediate potential security issues.

The new EKS Runtime Monitoring capability utilizes a fully managed EKS add-on to provide insights into the specific container runtime activities. These include network connections, file access, and process execution. These insights make it easier for IT admins to detect and contain potential threats before they escalate.

“GuardDuty can now identify specific containers within your EKS clusters that are potentially compromised and detect attempts to escalate privileges from an individual container to the underlying Amazon EC2 host and the broader AWS environment. GuardDuty EKS Runtime Monitoring findings provide metadata context to identify potential threats and contain them before they escalate,” Amazon explained.

Amazon EKS runtime monitoring pricing detailsAmazon is offering a free 30-day trial of GuardDuty for EKS Runtime Monitoring for all existing GuardDuty accounts at no additional cost. However, customers will be required to pay for the service after the completion of the trial period.

It is important to note that the cost is based on the number and size of protected EKS workloads, and it’s measured in vCPUs. For more details, you can refer to the GuardDuty pricing page. We also invite you to check out this step-by-step guide to learn about how to configure EKS Runtime Monitoring in GuardDuty.

View Details

Microsoft has announced that the Workspaces feature is now available in limited public preview in Microsoft Edge. The new collaboration enables users to share a set of browser tabs and favorites with multiple people.

Microsoft first unveiled the Workspaces feature for its Edge browser at Ignite 2022. Up until now, it was only available in public preview for enterprise customers. With Edge Workspaces, consumers can now collaborate in a group space within the browser. The shared tabs are updated in real-time as people work within a workspace.

According to Microsoft, the Workspaces feature enables Microsoft Edge users to plan trips, organize activities, and more. It also makes it easier for managers to add new people to a project.

“In Workspaces, you can create a single, shared view of your group’s web pages and documents within a unique browser window, with real-time updates. For that trip you’re planning, you can invite those in your group to view the same pages, share flights, lodging options, and even create a shared document to collaborate on trip activities and plans,” Microsoft explained.

Microsoft clarified that it had introduced some privacy and security controls to protect customer data. This means that the Workspaces feature won’t share private information (such as passwords, collections, extensions, cookies, and downloads) with others who can access the shared workspace.

How to get access to the Microsoft Edge Workspaces previewMicrosoft Edge Workspaces are available for users on macOS and Windows devices. However, users will need to be signed in to their personal Microsoft account in Microsoft Edge version 111.0.1661.51 (or higher).

Microsoft says that users can sign up for the Microsoft Edge Workspaces limited preview on this page. Moreover, beta testers can invite 5 friends and family members to access the Workspaces preview. Microsoft didn’t say when users can expect the feature to be generally available for everyone.

View Details

Apart from the release of Windows 11 22H2 Moment 2, it’s been a fairly quiet month. But not for Windows Insiders, where there’s been a ton of new features added.

So, let’s get started!

Windows 11 22H2 Moment 2 now generally availableThe primary change in this update is to the Search box in the taskbar, which is now typable. There’s also partial integration with Bing A.I. While you can’t interact with the Bing A.I. chatbot directly in Windows 11, you do get the option to open Bing Chat when searching.

Other updates include the ability to access Windows Studio Effects from Quick Settings, assuming you have a compatible device. And the taskbar has been optimized for 2-in-1 devices. There’s now a swipe gesture to switch between collapsed and expanded states.

For users who have joined their Windows 11 device to Azure Active Directory (Azure AD), there are also A.I-powered recommendations in the bottom half of the Start menu. As a reminder, Recommended on the Start menu displays files in Microsoft 365. I’ve read in several places that search is now faster in File Explorer and that it should better surface recommended local and cloud files. In my testing, it seems as slow as ever.

Quick Assist has got a minor design makeover and it is now installed by default on Windows 11 22H2 devices. It is also now available by default on the Start menu. But again, that doesn’t appear to be the case on devices that are upgrading to Moment 2.

Widgets gets third-party app support. At release, Facebook Messenger, Phone Link, and Spotify were added as new apps.

Notepad got tab support. The Windows 365 app was made generally available, and Windows 11 Phone Link gets iPhone support in preview.

Windows 11 Phone Link iOS supportChanges to app pinning in Windows 11Microsoft wants to give users more control over the apps that get pinned to the desktop, Start, and the taskbar. Several new features are coming to help achieve that goal.

The first is a deep link URI for apps that takes users to the right location in the Windows 11 Settings app where they change defaults. There’s going to be a new API that will let apps pin primary or secondary tiles to the taskbar. The idea is to present users with a trusted and consistent Windows experience so it’s clear what is happening and provide the option for the user to confirm or deny the change.

Microsoft Edge ‘video super resolution’Edge Canary got a new feature called video super resolution (VSR). It automatically upscales low resolution videos. Providing you have a Nvidia RTX 20/30/40 series or AMD RX5700-RX7800 series graphics card, the device is plugged in, the video is less than 720p, and it’s not protected by Digital Rights Management, Edge will upscale the video.

Microsoft says it’s working on support for devices that have multiple GPUs.

Windows Insider BuildsEarly in March, Microsoft announced changes to the Canary Channel, saying that it is going to be the place where preview platform changes are tested that require a longer lead time before a more general release. For example:

  • Changes to the Windows kernel
  • New APIs

Some of the changes tested in the new Canary Channel may never ship to customers. Microsoft notes that builds coming to the Canary Channel will have seen very little internal validation or testing before they are released. And with little documentation, so don’t expect a blog post to accompany every new build.

Nothing changes with the Dev Channel, it is where Microsoft will incubate news ideas and preview new features. Again, some features may never see a general release to customers. Insiders should note that the Dev Channel will continue to provide better platform stability over the Canary Channel.

So, bearing all that in mind, make sure that you switch to the channel that suits your needs best.

New English dialects for voice accessWindows 11 build 22624.1391 brings improvements to voice access. There’s a redesigned in-app command help page and support for new dialects including: English -UK, English – India, English – New Zealand, English – Canada, English – Australia.

Mixer, pizza, and auto color managementWindows 11 Insider Preview Build 25309 brings a new volume mixer experience to Quick Settings. And there are new options for touch keyboard settings:

  • Never – suppresses the touch keyboard even when there’s no keyboard attached
  • When no keyboard attached – shows the touch keyboard only when the device is used as a tablet
  • Always – shows the touch keyboard when the hardware keyboard is connected.

Auto Color Management (ACM), on qualifying Standard Dynamic Range (SDR) displays, can be switched on and colors across all Windows apps, color managed or not, are displayed accurately on all supported displays.

File Explorer gets a new pizza icon that denotes the user is working with the updated ‘Windows App SDK’ version of File Explorer.

Theme aware widgets are now a thing – widgets will change appearance depending on the user’s Windows theme, i.e., light or dark.

Live caption languages and File Explorer XAML menu access keysWindows 11 build 23403 gets more live caption languages. The original release of live captions supported English (United States). Now we get these languages:

  • Chinese (Simplified and Traditional)
  • French
  • German
  • Italian
  • Japanese
  • Portuguese (Brazil)
  • Spanish
  • other English dialects

File Explorer is getting access keys on the XAML context menu.

LSA protectionWindows 11 Insider Preview Build 25314 introduces ‘LSA Protection Enablement on Upgrade’. This new option helps protect login credentials by preventing unsigned drivers and plugins loading into the Local Security Authority (LSA). Microsoft says:

Starting with on upgrade, we will audit for a period of time to check for incompatibilities with LSA protection. If we do not detect any incompatibilities, we will automatically turn on LSA Protection. You can check and change the enablement state of LSA protection in the Windows Security application under the Device Security > Core Isolation page.

Windows 10 Build 19045.2787Check out the Windows Blog for more information about Windows 10 Build 19045.2787 on the Release Preview Channel.

Microsoft account notifications on the Start menu, live kernel memory dumps in Task Manager, and a USB4 Settings pageWindows 11 Build 22621.1483 gets notifications for Microsoft accounts in the Start menu. Microsoft says the feature is only available to a small number of testers at the moment.

Windows 11 Insider Preview Build 23419 brought live kernel memory dumps in Task Manager and a new USB4 settings page in the Settings app. It will allow you to:

  • View the tree of connected USB4 hubs and devices
  • See attributes and capabilities of connected devices and hubs
  • Copy details so they can be shared with customer support or sysadmins

A larger widgets board, SHA-3 support, and improved Content Adaptive BrightnessWindows 11 Insider Preview Build 25324 has a widget board with a wider canvas along with sections for widgets and feed content.

This build also gets SHA-3 support:

  • Supported SHA-3 hash functions: SHA3-256, SHA3-384, SHA3-512 (SHA3-224 is not supported)
  • Supported SHA-3 HMAC algorithms: HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512
  • Supported SHA-3 derived algorithms: extendable-output functions (XOF) (SHAKE128, SHAKE256), customizable XOFs (cSHAKE128, cSHAKE256), and KMAC (KMAC128, KMAC256, KMACXOF128, KMACXOF256).

And unsafe password copy and paste warnings has been expanded to provide a UI warning on copy and paste actions, like currently when typing in a password.

Windows 11 Insider Preview Build 23424 gets improved Content Adaptive Brightness Control (CABC) on mobile devices where the OEM has enabled it. Now CABC runs on laptops and 2-in-1 devices when plugged into a charger.

And that’s it for another month!

View Details

MC537415 – With the newly introduced toggle for turn on/off profanity filtering in Live Captions, users will now be able to control whether they want to continue to leverage the profanity filtering capability provided out of the box, or if they want to see every word as-is.

This message is associated with Microsoft 365 Roadmap ID 113412.

When this will happen:

Targeted Release (Public preview): Microsoft will begin rolling out early April and expect to complete by mid-April.

Standard Release: Microsoft will begin rolling out early May and expect to complete by mid-May.

GCC-High and DoD: Microsoft will begin rolling out early July and expect to complete by mid-July.

How this will affect your organization:

Users now have a new option to turn off the profanity filtering and be able to see the Captions as is. They can control this option via Settings in Teams > Captions and transcripts > Filter profane words in meeting captions.

View image in new tab

What you need to do to prepare:

You may consider updating the training materials for you users to inform this feature is now available.

View Details

MC537412 – Teams Rooms on Windows devices that are eligible for Windows 11 upgrade will receive the Windows 11 22H2 release in May 2023. This will be offered and installed on their devices with 4.16 dot release (a newer release than 4.16.40.0 currently available). Devices that are not eligible due to an incompatible processor will continue to use Windows 10 per Windows hardware support policy. These devices will be offered Windows 10 22H2 release.

Devices that cannot upgrade to Windows 11 will continue to be supported until the end of Windows 10 End of servicing for General Availability Channel or hardware support from OEM, whichever comes first. Windows 10 releases information at https://learn.microsoft.com/en-us/windows/release-health/release-information. Please note, not all Windows releases are supported for Teams Rooms, to find supported version, see https://learn.microsoft.com/en-us/microsoftteams/rooms/rooms-lifecycle-support#windows-10-release-support.

In addition, Teams Rooms on Windows OEMs will shift their manufacturing to Windows 11 IoT Enterprise as Windows 10 IoT Enterprise end of license sales is fast approaching (10/14/2023). OEMs with existing Windows 10 licenses inventory (or to support recovery media for existing Windows 10 based devices) may continue to provide Windows 10 based images for some time that should automatically update to Windows 11 post setup. All OEMs are expected to move to Windows 11 IoT Enterprise based images in future. Customers should ensure all new hardware purchases check for Windows 11 compatibility to future proof their device investment.

This message is associated with Microsoft 365 Roadmap ID 122148

When this will happen:

Standard Release: Microsoft will begin rolling out early May and expect to complete by late May.

How this will affect your organization:

Microsoft Teams Rooms on Windows application release 4.16.XX. X (a dot release, on top of current release 4.16.40.0) will be available in May 2023. This app will allow eligible Teams Rooms on Windows devices to receive Windows 11 22H2 update through Windows update. After the dot release has booted normally at least once, customers can either wait for 8 days for Windows 11 22H2 to install automatically or can pull the latest Windows 11 update from Windows Updates manually by checking for updates from the Windows Settings app. Devices that are not eligible will be offered Windows 10 22H2 release.

To check if your device is eligible for Windows 11, you can either check the list of eligible Intel processors for Windows 11 at https://learn.microsoft.com/en-us/windows-hardware/design/minimum/supported/windows-11-supported-intel-processors

What you need to do to prepare:

To ensure that there are no issues preventing the Windows update in your environment, it is recommended to manually check for updates on a small set of devices, after the Windows 11 enabled 4.16.XX.X release has been installed and booted normally at least once on them. From admin mode, check for updates using the Windows Settings app: Windows 11 22H2 or Windows 10 22H2 (depending on what’s supported for your devices) should be offered and should download and install. If the updates are not offered or installed, check for external policies (such as MDM or Active Directory Group Policies) that might be in place for your organization that could block this update.

View Details

MC537341 – Microsoft has released updates to the following update channel for Microsoft 365 Apps:

  • Current Channel

When this will happen:

Microsoft will be gradually rolling out this update of Microsoft 365 Apps to users on that update channel starting April 4th, 2023 (PST).

How this will affect your organization:

If your Microsoft 365 Apps clients are configured to automatically update from the Office Content Delivery Network (CDN), then no action is required.

If you manage updates directly you can now download this latest update and begin deployment.

What you need to do to prepare:

To get more details about this update view the following release notes:

  • Current Channel

Additional information

View Details

Microsoft has announced some new logging and metric improvements to provide more insights into Microsoft Azure Firewall traffic. The Latency Probe metric feature enables IT admins to monitor the overall latency and health of Azure Firewall to troubleshoot app performance issues.

“In the case that Azure Firewall is experiencing latency, this can be due to various reasons, such as high CPU utilization, traffic throughput, or networking issues. As an important note, this tool is powered by Pingmesh technology, which means that the metric measures the average latency of the firewall itself. The metric does not measure end-to-end latency or the latency of individual packets,” Microsoft explained.

Previously, the firewall logs didn’t show the complete journey of the packet in the TCP handshake. Microsoft has introduced Flow Trace logs that allow IT administrators to monitor all packets traversing through the firewall. The capability makes it possible to view the return packet, failed connections, and unrecognized packets.

Microsoft Azure Firewall now supports Top Flow logsThe Top Flows log feature shows the top connections that are responsible for the maximum data transfer in a specific time frame through the firewall. IT admins can monitor the top traffic to detect any unexpected or anomalous traffic. The Top Flows log also helps to allow or block network traffic based on the results.

Microsoft says that the new logging and metric capabilities are available in public preview for Azure Firewall customers. You can check out this support page to learn more about configuring Flow Trace and Top Flows Logs.

View Details

Microsoft has released a new My Day view in the Tasks by Planner and To Do app for Microsoft Teams. The feature enables users to consolidate their task lists to effectively organize and prioritize important workflows.

“’My Day’ view brings together tasks from various sources such as Microsoft To Do, Microsoft Planner (tasks assigned to you in Plans), and flagged emails from Microsoft Outlook. Now, you can view all your tasks in a single, unified interface. If you’re concerned about a task today, just add it to My Day by right-clicking the tasks and selecting the ‘Add to My Day’ option,” Microsoft explained.

Microsoft highlights that the My Day view lets users sort tasks by priority level and due date. The feature also makes it easier for the users to track their progress throughout the day. Moreover, the My Day view provides an option to mark tasks as completed to declutter their workspace.

How to access the My Day view in the ‘Tasks by Planner and To Do’ App for Microsoft TeamsMicrosoft Teams users can access the My Day view by following the steps listed below:

  • Launch Microsoft Teams and navigate to the sidebar and click the Apps tab.
  • Use the search bar to find and install the Tasks by Planner and To Do app.
  • It’s also possible to pin the app in the left navigation bar in Microsoft Teams. To do so, users will need to right-click on the app and select the Pin option.
  • Users can access the My Day view in the left-hand panel.

Microsoft has also introduced a green screen feature in public preview for Microsoft Teams meetings. Keep in mind that this capability is only supported on macOS and Windows devices with Intel-based processors. The green screen effect doesn’t support Apple’s M1 and M2 chips and AMD-powered laptops.

View Details

Microsoft has started rolling out support for third-party accounts in its Outlook for Windows preview app, which is currently available for Office Insiders. The web-based version of Outlook now lets users add a Gmail account in addition to personal Microsoft accounts and work and school accounts, and the preview client also supports displaying calendars and contacts from Google accounts.

“Longtime Outlook for Windows users will note that third-party account support has also been improved over the classic client experience, which didn’t have Google Calendar or Contacts support. Now people can use their Gmail email, Google Calendar and Contacts within the new Outlook for Windows preview. This has been a popular ask and is made possible by our modern codebase in the new Outlook for Windows,” the Outlook team said yesterday.

Outlook for Windows preview now supports Gmail accounts (Image credit: Microsoft)Outlook for Windows Preview will soon support more third-party email accountsSupport for Gmail accounts will roll out gradually to beta testers, and a pop up will warn them when the ability to add a Google account becomes available to them. The calendar experience also supports adding multiple shared calendars, multiple time zones, as well as displaying daily weather in the Calendar view.

If Gmail is one of the most popular email services out there, the Outlook for Windows preview will soon add support for Yahoo, iCloud, and other IMAP email accounts. Native support for .ics files is also in the pipeline, along with offline support.

Outlook for Windows preview supports Google calendars and contacts (Image credit: Microsoft)Microsoft will soon expand testing for the Outlook for Windows preview Microsoft is planning to make this new web-based version of Outlook for Windows available for all users later this month. The new experience will be available via a toggle within the classic Outlook for Windows app, but IT pros will be able to block it.

While the new codebase will allow Microsoft to iterate faster on this new Outlook for Windows app, the company isn’t planning (yet) to deprecate the classic Outlook for Windows app, which has many features and add-ons that power users still rely on. However, the new Outlook for Windows experience should eventually the UWP-based Mail and Calendar apps on Windows 10 and Windows 11, which are no longer in active development.

View Details

Did someone say it’s already Spring? It sure feels like it with all of the Microsoft Power Platform changes and new AI-enhanced features that the company touted in March. Don’t worry though, we’ll whet your appetite and provide some links below.

New Microsoft 365 CopilotIf you missed the announcement of the Microsoft 365 Copilot last month, then you may have been visiting another galaxy. Copilot is entering the fray across Microsoft Office to assist you in creating, synthesizing, linking, sharing, and much more for the Microsoft 365 products we use at work every day. It is designed to be a virtual assistant that you can interact with using use natural language.

The new Microsoft 365 Copilot (Image credit: Microsoft)New AI Copilot for Power AppsMicrosoft also announced last month a new AI Copilot for Power Apps that you can sign up for, if you live in the United States and have an environment in English, as an experimental feature. In short, it’s a very quick way for someone with very little app-building experience to create an app, with sample data, built right on top of Dataverse.

Yes, that will make it a premium feature, but the possibility of empowering your entire organization as Power Apps makers is looking more realistic. I’ve personally tried and demonstrated Copilot for Power Apps, and it works!

Microsoft also has a new AI Copilot for Power Apps (Image credit: Microsoft)As Microsoft held its Business Applications Business Applications Launch Event yesterday, you can expect much, much more integration with AI in future app building. Again, AI is not gaining steam to replace you, but it’s going to enhance what you can do. I told my team this week that AI isn’t going to take your job, someone using AI is going to take your job. You should be the person using AI!

AI Builder and Copilot in Power AutomateThis month in Power Automate, we have been using the AI Builder and Copilot. AI builder is a non-premium feature that is already available. While there are a limited number of connectors that are currently usable, it is a very nice tool to help any user create a flow and significantly cut down on the amount of time required to do it. Stand by for more enhancements to make Power Automate more and more user-friendly through the help of AI.

Copilot in Microsoft Power Virtual AgentsCopilot has also taken off in Power Virtual Agents. Hopefully, you’re seeing this trend that we’re noticing where Copilot drafts the work for you to adjust and correct.

Copilot is making it so easy to explain in natural language what you want the interaction with a user to look like and produce a working dialog within seconds. It’s so easy even Buddy the dog could do it!

Copilot in Power Virtual Agents (Image credit: Microsoft)Modern controls for Power Apps canvas appsWe’ve had a very late addition last month regarding Modern controls for Power Apps canvas apps. Many of these are already available in model-driven apps, so this is an attempt to share those with canvas apps.

Microsoft tells us to expect lots of updates to these controls in the coming months, but for now, if you adjust your app settings in the Upcoming features to include these controls, you’ll be able to employ 13 Modern controls in canvas apps. Pro tip: do not include these in any customer solutions yet, but have fun trying them out. You can also watch a deep dive here.

You can now enable modern controls in canvas apps (Image credit: Microsoft)New Power BI featuresFor our data scientists out there, who dwell in the Power BI bailiwick, there was a new update pushed in March 2023. One significant add includes a preview of On-Object interactions, allowing you to right-click your visual and gain instant access to formatting, data, and many other customizations without leaving the visual (including changes directly to items inside of the visual). Very cool!

Another update that’s not in preview that you might appreciate is a new ‘Apply all slicers’ button, which allows a user to select various slicers in your report, then apply them all at once. Conversely, you can then ‘Clear all slicers’ too.

Another new Power BI feature is the Multiple Audiences feature: This one allows you to set different views for the same organization, based on group permissions. Finally, the new Storytelling Power BI feature allows you to add live and up-to-date reports or (now) visuals directly to your PowerPoint presentation.

Stay tuned in the coming months to see how your ability to automate via the Power Platform is being enhanced on a regular basis!

View Details

Microsoft introduced yesterday its latest Surface Dock with Thunderbolt 4, which now uses a USB-C port to connect to Surface devices instead of Microsoft’s proprietary Surface Connect port. The Surface Thunderbolt 4 dock should be a good companion device for the latest Surface devices that also support Thunderbolt 4, and it’s also compatible with Windows OEM devices and Apple Macs.

The new Surface Thunderbolt 4 Dock is already available for purchase at the Microsoft Store where it’s priced at $299.99. It allows users to connect up to two 4K monitors at up to 60Hz, transfer data with up to 40Gbps speeds, and charge laptops using up to 96W of power.

Thanks to Thunderbolt 4 and USB4 support, this new Surface Dock supports higher data transfer speeds and there are also built-in management and security features for enterprise users.

Surface Thunderbolt 4 dock portsMicrosoft’s latest Surface Dock is slightly slimmer than previous models, and it also features a more inclusive design with raised tactile indicators above the rear ports. In addition to the main USB4/Thunderbolt 4 USB-C cable that supports up to 96 watts of power passthrough, there is one USB-C port and one USB-A 3.1 Gen 2 on the front of the dock.

The front ports on the Surface Thunderbolt 4 dock (Image credit: Microsoft)On the back, there are 2 USB-C ports, 2 USB-A ports, a 3.5mm audio jack, a 2.5 Gigabit Ethernet port, and a DC power port. All USB-C ports on the dock support high-speed USB4/Thunderbolt 4, and all USB-A ports are USB 3.1 Gen 2.

The rear ports on the Surface Thunderbolt 4 dock (Image credit: Microsoft)Cable Matters will also offer a desk mount that’s certified for the Surface Thunderbolt 4 Dock, which can help to save desk space and provides easier access to the various ports. However, pricing and availability details for this third-party accessory are still unknown

The Cable Matters mount for the new Surface dock (Image credit: Microsoft)Surface Thunderbolt 4 Dock has built-in management featuresJust like previous Surface Dock models, the Surface Dock with Thunderbolt 4 will support automatic firmware updates via Windows Update or the Surface app. Driver and firmware updates will also be available to download from the Microsoft Download Center.

The Surface Thunderbolt 4 Dock supports MAC address passthrough for maintaining device network identity across docks. It also supports Wake on LAN from Modern Standby, which allows devices to stay connected while in a low-power state.

IT pros can also use Surface Enterprise Management Mode (SEMM) to lock down specific ports on the dock, and they can also use Windows Management Instrumentation (WMI) to manage firmware updates, policy state, and related data remotely. These enterprise management and security features are only available with Surface devices.

Microsoft will continue to sell its existing Surface Dock and Surface Dock 2 for customers who need a dock that’s compatible with Microsoft’s proprietary Surface Connect port. However, the move to USB-C/Thunderbolt 4 on the latest model should be very welcome.

View Details

Microsoft has recently unveiled several updates to improve threat intelligence in its existing products and services. The company has introduced a new Defender TI integration in Microsoft 365 Defender to protect enterprise customers against sophisticated cyberattacks.

Microsoft explained that Defender TI capabilities are now directly available to licensed customers within the Microsoft 365 Defender portal. It provides detailed insights about emerging security threats to facilitate the investigation process. Microsoft Defender Threat Intelligence now offers a new Intel Profiles feature that provides contextual information about threat actors, infrastructure, and exploits used in cyberattacks.

“Intel profiles combine 65 trillion threat signals with the expertise of over 8,500 dedicated security professionals to translate that global threat landscape into immediately actionable insights. By comprehending their tactics, infrastructure, and methods of operation, security teams can take proactive steps to prevent threat actors from breaching their organization’s defenses,” Microsoft explained.

Microsoft Defender TI API is now available to respond to threats at scaleAdditionally, Microsoft has released a new Defender Threat Intelligence (TI) API that provides insights gathered from various tools, threat actors, and vulnerabilities. The API enables security teams to understand entities involved in an incident, automate triage efforts, and integrate with security tools like Microsoft Sentinel. Microsoft Sentinel playbooks can also use the API to find indicators of compromise in a security incident.

Microsoft highlights that IT admins can leverage Microsoft Sentinel Data Connector and Microsoft Threat Intelligence analytics rule to protect their users against the latest threats. Customers will get free access to indicators of compromise (IOCs) directly from the Microsoft Sentinel TI blade.

Finally, the built-in Microsoft Defender Threat Intelligence Analytics rule makes it easier to check IPs, domains, and URLs against known IOCs. If you’re interested, you can learn more about Microsoft Defender TI on this support page.

View Details

Microsoft announced some changes yesterday to its release schedule for Microsoft Configuration Manager updates. The company is switching the product from its usual tri-annual updates to a bi-annual release cycle.

Microsoft Configuration Manager is a tool that enables IT admins to manage large groups of Windows machines. It helps to deploy applications, automate patch management and software updates, and monitor system health. Microsoft Configuration Manager lets administrators generate reports on software and hardware inventory and system compliance.

Going forward, Microsoft plans to release Configuration Manager updates in the Spring and Fall of every year. The company explained that this change aims to better align with the release schedule of Windows updates that arrive once per year. The new update cycle should make it easier to prioritize top customer feature requests. Moreover, IT admins will now need to manage fewer deployments annually.

“With this change and the longer development cycle, the Configuration Manager 2309 update will be able to address key customer asks around policy sync, software update troubleshooting, improved alerts, dashboarding, and more. Hotfix rollups and security updates will continue to be made available as necessary to address any critical bugs,” Microsoft explained.

Microsoft Configuration Manager to get four technical previews annuallyMicrosoft plans to roll out the change with the release of baseline version 2303 of Microsoft Configuration Manager later this year. The company will roll out four technical previews per year through an “in-console update and servicing process.”

It’s important to note that Microsoft isn’t making any changes to the support lifecycle of the current branch. The company has confirmed that the technical preview releases of Microsoft Configuration Manager will be supported for 18 months.

View Details

Microsoft has announced several new features coming to Windows Autopatch next month. These enhancements will notify IT admins about expiring licenses and access issues related to Windows Autopatch.

Windows Autopatch is a new cloud service that enables customers to automate the patching of Windows, Microsoft 365 apps, Microsoft Edge and Microsoft Teams. The managed service eliminates the need for IT admins to plan and operate the Windows update process. The service is designed to minimize disruptions and improve security across an organization.

With this release, the Tenant management blade will alert IT admins that the expired licenses should be renewed/replaced to continue using Windows Autopatch. It will also inform administrators to resolve access-related issues with the service. Microsoft advises organizations to take action immediately for potential issues to avoid any disruptions in the workflows.

“We are also introducing the ability to mark the Windows Autopatch section of your tenant as “inactive” if there are any actions that need to be taken. To know if action is required, visit the Tenant management section and select the banner displayed within the Windows Autopatch Devices blade that alerts you to take action,” Microsoft explained.

Microsoft adds support for Windows Autopatch GroupsMicrosoft has also introduced several new features to help customers better manage their Windows environments. The Windows Autopatch Groups feature will let IT admins set up their own deployment rings and release frequency. Microsoft is updating the existing reporting experience with details about deployment status, update failures, and update compliance.

Lastly, Microsoft says that a new feature will allow IT Pros to leverage deployment rings and Windows Autopatch groups while creating Windows feature update deployments. Moreover, the policy health and remediation capabilities should make it easier to restore policies and deployment rings.

The new Window Autopatch capabilities are available in preview for select customers that opt-in in the Microsoft Intune admin center. Microsoft plans to roll out these changes to all organizations in May 2023.

View Details

Last month, Microsoft unveiled that it’s adding green screen background support to improve Teams meetings. The company announced this morning that the new feature is now available in the Microsoft Teams desktop app for Windows and macOS.

“Microsoft Teams now supports a green screen feature which provides an enhanced virtual background effect. Green screen improves the sharpness and definition of the virtual background effect around your face, head, ears, and hair. It also allows you to show a prop or other object in your hand to be more visible to other meeting participants,” Microsoft explained.

Microsoft explains that the meeting attendees should have a flat screen or a clean background behind them. The participants should also ensure that the screen or wall doesn’t have stains or imperfections. Moreover, the background color should not match their clothing or props.

How to enable the green screen effect in Microsoft Teams meetingsTo enable the green screen feature, Microsoft Teams desktop users will need to follow the steps mentioned below:

  • Navigate to the meeting toolbar, click the More icon, and then select video effects.
  • Click the Green Screen Settings link available under the Backgrounds section.
  • Go to the Settings page and turn on the Green Screen toggle button.
  • Click the backdrop icon to manually select a background color and return to the meeting.

Microsoft notes that the green screen effect is available for Teams meeting on Windows and macOS with Intel CPUs. The feature uses Advanced Vector Extension (AVX), and it doesn’t support Apple’s M1 and M2 chips. Microsoft also acknowledged that the green screen effect may not properly detect transparent and thin objects.

The green screen effect is available for commercial and GCC tenants enrolled in the Microsoft Teams public preview program. It supports PowerPoint Live Standout, Presenter modes (such as Reporter, Standout, and Side-by-side mode), and background replacement.

Last week, Microsoft announced a significant revamp for Microsoft Teams. The company has improved the performance of the app to make it faster and less resource intensive. The new version of Microsoft Teams comes with a simplified UI, a new channel experience, AI-powered features, and multi-account support.

View Details

Microsoft has introduced a new Incident Response Retainer service for enterprise customers. The new service provides flexible pre-paid hours for specialized incident response and recovery before, during, and after a security attack.

Microsoft Incident Response is a process that enables organizations to identify and respond to security incidents in their network. It aims to streamline incident management with various tools and technologies, including security information and event management (SIEM).

Microsoft Incident Response Retainer offers several AI-powered investigation capabilities. These include malware analysis support, threat investigation, log analysis, attacker containment, and digital forensics. Moreover, an assigned security delivery manager will be responsible for proactively scheduling services throughout the year.

Additionally, Microsoft Incident Response Retainer assists in the recovery and remediation of critical systems. It enables IT admins to restore full administrative control and improve security posture to prevent security breaches.

“It’s contracted on an annual basis and the retainer hours can be used in any combination of proactive and reactive services. If additional hours are needed, customers can easily uplift extra hours as requirements change. This service provides our fastest response times and direct access to our global team of experts. It was designed to work with cyber insurance vendors and has flexible delivery options that meet the unique needs of each customer,” Microsoft explained.

Microsoft Incident Response Retainer provides quarterly threat briefingsMicrosoft incident response experts help customers to mitigate an active security incident. The service also delivers quarterly threat intelligence briefings with insights on the latest threats and analysis/validation of security alerts.

Finally, Microsoft has announced a new partnership with an incident response provider Kivu. The companies plan to leverage existing relationships with cyber insurance providers to better respond to security attacks. We invite you to check out the official website to learn more about the Microsoft Incident Response Retainer.

View Details

Microsoft Stream, which is part of Microsoft 365, is a video creation and collaboration service available with nearly all license and pricing plans. Learn about its noteworthy features including the ability to record your screen and yourself, catch up on your company’s Teams meeting recordings, and distribute your videos across your Microsoft 365 tenant.

What is Microsoft Stream?The Microsoft Stream service is the video recording and sharing tool available to all Microsoft 365 colleagues in the enterprise. When your organization utilizes the full breadth of key features, you and your users will be able to upload videos to the service and use the following features:

  • Search: Find the content you need with video search across your organization
  • Watch: Users can view videos from across the org using the latest accessibility features including transcription, closed captions, noise suppression, chapters, and speed controls.
  • Manage: As an IT Pro, you can manage online videos in your tenant just like documents. Your benefits include security, administration controls, retention, and compliance across Microsoft 365.

Originally built on a legacy video platform (Classic), the newer Stream is built on SharePoint and allows for a richer video viewing experience and rich media experiences for files stored on SharePoint and OneDrive for Business. The Microsoft Learn website has a detailed article about the differences between the old and new Stream.

Why use Microsoft Stream?Why should be using Microsoft Stream instead of Loom or YouTube to share videos across your enterprise? Well, the strongest reason to use it is that it is heavily integrated into the Microsoft 365 ecosystem.

  • The recordings of Microsoft Teams meetings will automatically appear on users’ office.com homepages.
  • Sharing newly-recorded Stream videos is as easy as sharing OneDrive documents.
  • The app is efficient, integrated, secure, and robust.

How to access Microsoft StreamWe are blessed with the ability to access many Microsoft 365 features in a variety of ways. Microsoft Stream is no different. The two easiest methods are the website and the mobile app.

The Microsoft Stream websiteNavigate to office.com, log in with your Microsoft 365 credentials, click the App Launcher in the upper-left corner, and click Stream!

The Microsoft Stream website (Image credit: Microsoft.com)You can use all of the app’s features on the web. And, no matter what device you switch to, the switch provides you seamless access allowing you to continue working where you left off without disrupting your workflow.

The Microsoft Stream mobile appMicrosoft has a Stream mobile app for both Android and Apple devices. Browse this link on your mobile device to download the app!

The Microsoft Stream mobile app homepage (Image credit: Microsoft.com)If you need more information about the revamping of the mobile app to the new Stream (on SharePoint) service, Microsoft has a support article dedicated to that.

Using Microsoft Stream’s FeaturesAs this is an overview article, let me go through the basics of how Microsoft Stream can offer strong value for your organization.

How to start: The Microsoft 365 App LauncherThe best place to start is to launch the app on the web:

  • First, navigate to office.com and click the App Launcher in the upper-left corner of the page.
  • Click the Stream icon. If you do not see it in your ‘most-used’ list, click the All Apps link and select it there.

Using the app picker on office.com (Image credit: Petri/Michael Reinders)As I am using my Microsoft 365 (Developer) tenant, there isn’t much to see here yet. No worries, we’re just getting started.

The app’s homepage is currently empty (Image credit: Petri/Michael Reinders)Record your screen and yourselfRegardless of your device’s capabilities, you will be able, at a minimum, to record your screen using the ‘+ New recording‘ button towards the top of the homepage. If your device is equipped with a camera and/or microphone (like a laptop), you can also record yourself and your voice to accompany your screen recording. This offers great value for your videos, especially when creating training sessions or recordings of classes for your users.

Starting a new Screen recording (Image credit: Petri/Michael Reinders)After you click Start screen recording, you are offered some choices on what exactly you want to capture. You can choose:

  • Entire Screen: This will capture everything on your device.
  • Window: This allows you to choose only one specific app, like Word, NotePad, Outlook, etc.
  • Microsoft Edge tab: this gives you helpful granularity to pick one specific Edge browser tab (very useful!)

Choosing what exactly you want to capture (Image credit: Petri/Michael Reinders)After you stop the recording, a preview window shows the video you just recorded. At the tap of a button, you can click Publish in the lower-right corner.

Reviewing the newly recorded video before publishing it (Image credit: Petri/Michael Reinders)You now have a plethora of options including changing the video thumbnail, generating transcriptions, comments, analytics, and video language. You can also review the video and add a description for it. Very easy I would say!

Post-recording options galore! (Image credit: Petri/Michael Reinders)Catch up with Teams meeting recordingsMicrosoft Stream is where Microsoft Teams meeting recordings are accessed after they are created. Remember, the app is the repository for both OneDrive for Business and SharePoint.

After you attend a Teams Meeting that was recorded, you can use Microsoft Stream to access those videos and view transcription and closed captions for them.

Share and collaborateNow that we have some content (ok, just one video…), let’s see how we can share and collaborate with colleagues using Microsoft 365’s enterprise-level security.

  • I just opened a new browser tab and logged in as Megan Bowen, the colleague I shared my video recording with.
  • As you can see, the Quick access section below shows the recording – ‘Michael Reinders shared this with you.’

Logging in as Megan Bowen to see the new video shared with her (Image credit: Petri/Michael Reinders) I click on it and the recording starts. She can click the Comments* tab on the right side and see the comment where I asked Megan to review the file.

Megan browsing my screen recording at her leisure (Image credit: Petri/Michael Reinders)* There, she can then reply and tag others to review or for further tasks. She can also work on the file later using offline download. She’ll be able to keep it and review it in case she loses Internet connectivity for any reason.

Adding Comments to an existing video – collaboration boost! (Image credit: Petri/Michael Reinders)Distribute your videos across Microsoft 365Because the more modern Microsoft Stream is another cog in the Microsoft 365 experience, videos can easily be shared across other apps such as Teams channels, SharePoint sites, Viva Engage (previously Yammer), and office.com to name a few.

  • Back on office.com on the Stream website, I can click the ‘…’ link for my recording, click the Share menu, and then pick up Teams.
  • You can specify the Team and channel name here – this allows me to post this right inside a Team!

Sharing a Stream video to a Teams channel… (Image credit: Petri/Michael Reinders)* The link to the recording has now been posted in the Teams channel I chose.

Tight integration with Microsoft Teams! (Image credit: Petri/Michael Reinders)ConclusionOverall, Microsoft Stream allows your users to collaborate and be productive with minimal effort – they won’t need to learn a whole new app as it’s part of Microsoft 365. The service is quite easy to use, and it’s a handy cloud-based solution for recording your screen. The various integrations with other Microsoft 365 services including Teams are also really welcome.

As usual, thanks for reading and let me know in the comments if you have any questions about this app!

View Details

MC535703 – Microsoft Feed items will soon show a Viva Topic pill when it is relevant for SharePoint content. This allows the user to easily learn more about the topic and get to the people and content related to the topic for that item.

This message is associated with Microsoft 365 Roadmap ID 118063

When this will happen:

Targeted Release: Microsoft will begin rolling out in late March and expect to complete rollout by early April.

Standard Release: Microsoft will begin rolling out in early April and expect to complete rollout by mid-April.

How this will affect your organization:

Licensed Viva Topics users in your organization will begin to see Topic pills alongside their feed items. This allows them to discover and engage with more knowledge for the content around these topics.

What you need to do to prepare:

There is nothing needed to prepare for this. You may want to notify users of this update.

View Details

MC535702 – With the deployment of the Tenant Allow/Block List, as being the single source of truth for Tenant Allows, other mechanisms for Tenant Allows are being removed. This will give SecOps teams one place to manage all Tenant Allows.

Today, the “DoNotRewrite” list is used to Skip:

  • Wrapping URLs
  • Detonation
  • Verdicts

The intended purpose of “DoNotRewrite” is to give tenants the ability to skip the wrapping of URLs. With the deployment of the Tenant Allow Block List, it is expected that all tenant allows (ex Detonation and Verdicts) shall be managed there.

When this will happen:

In late April the entries on the Do Not Rewrite list will only skip Safe Links wrapping. After this change is made, entries on the Do Not Rewrite list will no longer skip Detonations or Verdicts in mailflow or at Time of Click.

In late April the following capabilities will be removed from the DNR list:

  • Skip Detonation
  • Skip Verdicts

How this will affect your organization:

With this change, the “DoNotRewrite” list behavior will be changed back to its intended purpose to skip the wrapping of URLs: Learn More here.

What you need to do to prepare:

Review your “DoNotRewrite” URLs list(s) and ensure you have not added entries to it for uses other than to skip wrapping of URLs.

Additional information

View Details

MC411463 – Updated March 31, 2023: The general availability of PowerShell script to deactivate user request in the tenant is now April 2023. We apologize for inconveniences caused by the delay.

Microsoft Teams apps help facilitate collaboration and enhance team productivity. Some organizations choose to control which apps their users can use, blocking apps from use until IT has reviewed and approved them. For these organizations, the recent app discovery update (MC350372) enables users to indicate which blocked apps they want to use, allowing IT to focus their attention on the apps their users want. As always, IT retains control over which apps their users can use.

Microsoft heard from some IT organizations that they have existing processes to manage how users should request access to apps, and they want to use these same processes for approving Teams apps as well. In response, Microsoft is adding optional organizational settings to enable Teams admins to customize the experience for their users to request access to apps that are blocked from use. These settings include:

  1. A customizable instructional message shown to users when they find an app that’s blocked from use. The default message is “This app requires approval from your IT admin to make it available for you to add.”
  2. An IT provided URL that will open in a browser when users click the “Request approval” button to request access to an app (e.g., IT support ticketing systems, user education pages, or corporate policy pages).

In the Teams app store, users who discover apps that are blocked from use will see the customized instructional message (if provided) on the app details page and be redirected to the URL (if provided) when the “Request approval” button is clicked.

Example scenario: Contoso’s IT department has configured Teams to block all third-party apps by default. They have enabled access only to specific third-party apps that they have evaluated and determined to be acceptable. For the user request feature, the Teams admin for Contoso configures the instructional message to say “This app is not allowed by Contoso IT. If you have a business need for this app, please submit your request in the Contoso helpdesk portal.” This makes clear (i) that the app cannot be used, and (ii) instructions to submit a request. They then configure the “Request approval” button to point to their internal portal where users can submit IT helpdesk requests: https://intranet.contoso.com/helpdesk. This experience drives awareness of corporate policy and the existing Contoso request process.

This feature is associated with Microsoft 365 Roadmap ID 89288.

Note: As an administrator, if you prefer to deactivate the ability for users to see and request apps that are blocked from use, you will be able to do so via PowerShell that is expected to be delivered in January 2023. Microsoft will update this message once the PowerShell script is available.

When this will happen:

This feature will be available in April 2023.

How this will affect your organization:

If you have an existing process for user requests, it can be linked directly from the Teams app store.

  1. In the Teams app store the default configuration shows as follows:
    • The configurable message defaults to “This app requires approval from your IT admin to make it available for you to add.”
    • By clicking ‘Request approval’ the request appears in Teams admin center as an aggregated count.
  2. Customizations can be done in Teams admin center:
    • A new ‘User requests configuration’ section is added to the Org-wide app settings.
    • The instructional message can be customized.
    • Redirect is activated by flipping the switch to ON and entering the URL.
  3. The customizations show in the Teams app store like this:
    • The admin configured instructional message will appear as seen below.
    • If a redirect is configured, clicking ‘Request approval’ opens a browser window to the URL.
    • The request still appears in Teams admin center as an aggregated count, even if a redirect is configured.
  4. After the user clicks the ‘Request approval’ button, the Teams app store looks like this:
    • The ‘Request approval’ button will be grayed out.
    • The admin configured instructional message is still present.
    • The URL can still be reached from ‘Get details’.

What you need to do to prepare:

Configure the User requests section when it becomes available with the link to the in-house user request systems and/or customize the instructional message.

View Details

Are you using Microsoft Teams? Try the Microsoft Teams 2.0 preview and experience the future of team collaboration! This Week in IT, I’ll give you 5 reasons why you should try Microsoft Teams 2.0 today. From new features to improved performance, I’ll show you why Microsoft Teams 2.0 is a great collaboration tool for your team.

View Details

Amazon Web Services has announced the general availability of AWS Chatbot for Microsoft Teams. The new integration allows customers to securely monitor and troubleshoot their AWS infrastructure directly from Microsoft Teams channels.

AWS Chatbot was first announced back in 2019. The service enables IT admins to receive real-time alerts about their AWS resources within the chat applications. AWS Chatbot is a powerful tool that helps to streamline workflows, improve collaboration and manage AWS infrastructure.

With this release, enterprise customers can implement ChatOps for AWS within their Microsoft Teams channels. The integration between Amazon CloudWatch and Amazon Simple Notification Service lets users receive notifications from more than 200 AWS services within Teams channels. Amazon EventBridge also integrates with Amazon Simple Notification Service to send event-related information.

“AWS Chatbot allows you to receive predefined CloudWatch dashboards interactively and retrieve Logs Insights logs to troubleshoot issues directly from the chat thread. You can also directly type in the chat channel most AWS Command Line Interface (AWS CLI) commands to retrieve additional telemetry data or resource information or to run runbooks to remediate the issues,” AWS explained.

AWS Chatbot for Microsoft Teams lets users ask questions in natural languageAdditionally, AWS Chatbot for Microsoft Teams enables users to ask questions using natural language commands. It scans AWS documentation and support articles to provide relevant answers directly within Teams channels.

If you’re interested, you can download AWS Chatbot from the Microsoft Teams app at no additional cost. You can find the step-by-step guide about configuring the integration between AWS Chatbot and Microsoft Teams on this support page.

View Details

If you’re working as Linux administrator or just started learning the basics of Linux, then it’s essential to understand how Linux file permissions work. In this article, I will detail everything you need to know about file permissions on Linux, including how to change file permissions and file ownership using the chmod and chown commands.

How do Linux file permissions work?On Linux, file permissions allow Linux admins to control the access level and ownership of files on the system. For this tutorial, I’ve been using a device running Ubuntu 22.04 LTS with sudo privileges.

The different permission types on LinuxUnderstanding how permissions groups work on Linux is important when you need to check the permissions of a file or a directory. To start this tutorial, create a directory named Documents in the home directory:

  • I’ll first login to my Ubuntu machine using my favorite SSH client, PuTTY.
  • In the home directory, create a directory named ‘Documents’ by running the command below.

mkdir Documents * After you’ve created the directory, run the following chmod command to change its access permissions. I’ll explain what the chmod 755 command does below

chmod 755 Documents/ * Next, you can list permissions for this directory and get other details about it using the ls -lh command.

ls -lh We get details about file permissions using the ls -lh command (Image credit: Petri/Sagar)Now, let’s analyze the attributes of the Documents directory (drwxr-xr-x)

  • The first character (d) is a file type (directory). However it can also have a ‘-‘ which represents a regular file, or a ‘c’ that represents a character device, or a ‘b’ that represents a block device.
  • After the directory (d), there are three triplets of permissions (rwx, r-x and r-x) which are associated to the owner of the file or directory, the group that has access to it, and the ‘others’ group, which designates everyone who isn’t the owner or a member of the group. Moreover, (-) indicates the absence of permissions.
  • Here, the owner of the file has read, write and execute permissions (‘rwx’), the group has read and execute (‘r-x’) permissions, and the ‘others’ group also has read and execute (‘r-x’) permissions.
  • ‘ec2-user’ is the owner of the documents directory, and the group name is also ec2-user, which is the primary group of the owner of the directory.

On Linux, the permissions for the owner, group, and ‘others’ can be constructed using r, w, x, or – where:

  • r indicates the read permission, and it means that the file/directory is readable.
  • w indicates the write permission, and it means that the file can be modified.
  • x indicates the execute permission, and it means that the file can be executed.
  • indicates the absence of permissions

Checking file permissions on Linux with the ls commandReading and understanding file permissions is important because if a file is assigned the wrong permissions, it may allow attackers to access it and potentially corrupt the entire operating system. In this section, I’ll create a new file in the home directory:

  • On the Ubuntu terminal in the home directory, run the command below to create and switch to the my_file directory.

mkdir my\_file * Next, create an empty text file named new_file using the touch command.

touch new\_file * Finally, run the ls -lh or ls -l command to check the permissions for the file that you’ve just created.

ls -lh There are three triplets of permissions for our file (Image credit: Petri/Sagar)Let’s analyze the results of this command:

  • Here, ‘new_file’ is the file name that exists under the home directory of the (ec2-user) user.
  • The first character (-) indicates that it’s a regular file.
  • After the first character (-), there are three triplets of permissions (‘rw-‘,’r–‘, and ‘r–‘) which belong to the owner, the group which has access to the file, and the ‘others’ group, respectively.
  • The owner has read and write permissions, while the group and ‘others’ are only allowed to read the file.
  • ‘ec2-user’ is the owner of the file, and the ec2-user is also the name of their primary group.
  • ‘0’ is the size of the file. The size is 0 because contents of the file is empty.

How to change file permissions on Linux with the chmod commandOn Linux, the chmod command can be used to change file permissions, and there are two different ways to do that: The symbolic (text) method and the numeric method. We’ve already used the symbolic method before, but let’s dive into details.

Symbolic (text) methodTo show you how to change file permissions with the symbolic method, let’s first create a file named file.txt in the home directory using the touch command.

touch file.txt * Next, we’ll review the permissions of the file.txt using the ls -lh command.

ls -lh We’re about to change permissions for this file with the chmod command (Image credit: Petri/Sagar)* Now, we’ll use the following chmod a-w command to remove the write permission from all the three permission groups (user, group and others).

chmod a-w file.txt * Now again, we’ll review the permissions of file.txt using the ls -lh command.

We’ve removed the write permission from all permission groups (Image credit: Petri/Sagar)This time, you can see that the write permission (w) has been removed from the user group, which is why we’re seeing ‘-r-‘ instead of ‘-rw’. The group and ‘others’ permission groups didn’t have the write permissions initially, so there’s no change on that front.

If we want to add the read, write and execute permissions to the user group, we can once again use the chmod command with ‘rwx’. The ‘u+’ in the command below indicates that we’re only changing permissions for the user group.

chmod u+rwx file.txt ls -lh Using the chmod command to add read, write and execute permissions (Image credit: Petri/Sagar)Similarly, If you need to subtract the read permission from the group that has access to the file, then consider running the command below where ‘g-‘ indicates that the permission is only removed from the group.

chmod g-r file.txtls -lh We used the chmod command to remove the read permission from the group (Image credit: Petri/Sagar)Numeric methodThe other way to use the chmod command to change file permissions is the numeric method. Here’s how the syntax works:

As I previously explained, ‘r’ represents the read permission and it has a 4 octal value. Moreover, ‘w’ stands for write and has a 2 octal value, while ‘e’ stands for execute and has a 1 octal value. So, if you use r+w+x in a command, the read, write, and execute permissions have an octal value of 7.

Let’s dive into an example and see how to change permissions for the file.txt file we’ve created earlier using the numeric method.

  • First, let’s verify again the permissions of the file.txt that we created earlier using the ls -lh command.

No changes to file permissions… yet (Image credit: Petri/Sagar)* Now, run the following chmod command will change the permission set of the file.

chmod 714 file.txtls -lh The chmod 714 command grants the read, write and execute permissions (7) to the owner of the file, the execute permission (1) to the group, and the ‘others’ group is granted both read and write access (4).

What are chmod 777, chmod 775 and chmod 755?As we learned earlier, using ‘7’ with the numeric method will assign all permissions (read, write, and execute) to a user group, whereas ‘5’ will only assign read and write permissions. The chmod 777, 775, and 755 commands are used quite often, and here’s what they do:

  • chmod 777 changes the permission of the file by granting the read, write, and execute permissions to the owner, group and others.
  • chmod 775 changes the permission of the file by granting the read, write, and execute permissions to the owner and the group that has access to the file, while the ‘others’ group is granted both read and write access.
  • chmod 755 changes the permission of the file by granting read, write and execute permissions to the owner, while the group and ‘others’ are granted both read and write access.

How to change file ownership in Linux with the chown commandIn the previous sections, we learned how to change the permissions of a file. However, if you need to change the ownership of a file or directory, then you should use the chown command.

To see how the chown command works, let’s run it on file.txt and follow up with the ls -lh command.

sudo chown -R root:root file.txt ls -lh Using the chown command to change ownership of a file (Image credit: Petri/Sagar).

After running this command, we can see that ‘root’ is the new owner of the file and the name of its primary group.

How to change groups ownership with the chgrp commandI just explained how to change the ownership of a file or directory using the chown command. However, if we want to just change the group membership of a file or directory, then we can use the chgrp command.

In the command below, we are changing the ownership of file.txt and transfer it from ‘root’ to ‘ec2-user’.

sudo chgrp ec2-user file.txt ls -lh We used the chrgp command to change the group ownership of the file (Image credit: Petri/Sagar)

Note: The chown and chgrp commands just change the permissions of files or directories, but they dont change any of the directory’s content.

ConclusionIn this tutorial, I explained everything you need to know about the different permission types on Linux. I also detailed how to use the chmod command to add and remove permissions from the different user groups, and how to use the chown and chgrp to change the group and ownership of files and directories. I hope that this knowledge will help you become a better Linux administrator.

View Details

Security researchers have discovered a new vulnerability in Microsoft Azure Active Directory (Azure AD). The security flaw allowed users to modify Bing search results and access users’ private data, including Outlook emails, calendars, and Microsoft Teams messages.

Dubbed BingBang, the misconfiguration in Azure Active Directory (Azure AD) was first discovered by Wiz researchers back in January. It was caused due to an authorization misconfiguration in Microsoft’s multi-tenant apps in Azure AD. These applications allow logins from potentially any Azure user, and it’s the developers’ responsibility to perform additional authorization checks.

Wiz researchers have found that approximately 25 percent of multi-tenant applications they scanned lacked proper validation. Specifically, the researchers created a new account and signed in to the Bing Trivia application. They accessed the Content Management System (CMS) and manipulated the Bing search results.

Security researchers have also discovered that the flaw could be exploited to initiate cross-site scripting (XSS) attacks. Moreover, Bing’s Work section allows users to search Office 365 data of other employees. These include emails, calendars, Teams messages, OneDrive files, and SharePoint documents.

“A malicious actor with the same access could’ve hijacked the most popular search results with the same payload and leak sensitive data from millions of users. According to SimilarWeb, Bing is the 27th most visited website in the world, with over a billion pageviews per month – in other words, millions of users could’ve been exposed to malicious search results and Office 365 data theft,” Wiz researchers explained.

Microsoft releases fix for a flaw affecting Bing and Office 365According to Wiz researchers, the vulnerability is present in more than 1,000 cloud-based applications and websites. These include Mag News, Power Automate Blog, Contact Center, the PoliCheck tool, and the Cosmos file management system.

The security researchers reported the Bing flaw to Microsoft’s Security Response Center on January 31, 2023. Microsoft has already released updates to patch the vulnerability in all affected applications. Fortunately, there is no evidence that the flaw has been exploited by attackers in the wild.

Nevertheless, Microsoft has made some changes to prevent future misconfigurations in Azure Active Directory applications. The Wiz team advises IT admins to check app logs to track any suspicious activities and potential security breaches.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Iain Smith on Unified Communications & The Pace of AIIain Smith is a 9-time Microsoft MVP and a much-respected figure in the field of Unified Communications. Iain joins Azure and Peter on the show this week to discuss:

  • The history of Unified Communications, from MSN Messenger & Sync to MS Teams
  • The current state of play with Teams from a UC viewpoint
  • His thoughts on what’s next
  • AI: Is the current pace of progress appropriate or concerning?
  • And much more!

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

MC514084 – Updated March 30, 2023: Microsoft has updated the rollout timing below. Thank you for your patience.

The Advanced deployment guides & assistance page in the Microsoft 365 admin center and the setup.microsoft.com website will have a new guide to help admins plan, deploy, and scale Windows 365 Enterprise in their organization. Windows 365 is a cloud-based service that provisions and hosts Cloud PCs as virtual machines for users. The guide includes a checklist with Cloud PC configuration tasks, best practices, tools, and recommendations based on a tenant’s configuration.

This message is associated with Microsoft 365 Roadmap ID 102406

When this will happen:

This guide will be available to Targeted Release in April 2023 and Standard Release in May 2023 (previously March). It can be found on the Advanced deployment guides & assistance page, and shortly after, on setup.microsoft.com.

How this will affect your organization:

Admins will use the Windows 365 Cloud PC advanced deployment guide for recommendations on how to make key decisions and identify prerequisites and tasks needed to deploy Cloud PCs in accordance with their org’s requirements. The guide is organized by IT area (Azure, networking, identity, management, security, and applications) to help admins work with multiple groups and staff members. Admins can track the status of each task within the guide and share tasks with others via email.

What you need to do to prepare:

You don’t need to do anything to prepare for this change.

Additional information

View Details

Microsoft has released a new update for its Windows 365 Cloud PC service this week. The company announced that this release brings a new pinning experience for the Windows 365 app, security enhancements, and much more.

Windows 365 is a cloud-based PC solution that allows users to access a virtual Windows desktop from a web browser on any device. The service is intended to make it easier for enterprise customers to manage their desktop environments. The service is designed to meet the needs of temporary and seasonal workers like contractors and interns. Windows 365 Cloud PC is available on all devices, including Android, iPads, and Macs.

What’s new in Windows 365 Enterprise?Microsoft has introduced a new feature that enables users to create templates that automatically generate unique names for new Windows 365 Cloud PCs. The Windows 365 app now allows users to pin their Cloud PC to the taskbar on Windows 11 machines. It should help users quickly launch the Cloud PC directly from the taskbar.

Additionally, Microsoft introduced support for FQDN tags to help IT admins secure Windows 365 environments. It’s designed to streamline the process of configuring and maintaining the rules for Azure Firewall.

Windows 365 Gov now supports higher Cloud PC screen resolutionLastly, Microsoft has started rolling out two new features for Windows 365 Government. It’s a specialized version of the service that is designed to meet the needs of Government Community Cloud (GCC) and GCC-High customers.

Microsoft notes that government customers can now transfer files to and from a Cloud PC with the Windows 365 web client. Moreover, it’s now possible to select a higher screen resolution while connecting to the Windows 365 Cloud PC.

View Details

Amazon has announced some important updates for its Application Migration Service. The latest release includes a new server migration metrics dashboard, import and export features, and additional post-launch modernization actions.

AWS Application Migration Service is a fully managed service that enables IT admins to migrate their on-premises applications to the cloud. It supports automated application discovery, application testing, and server migration. Application Migration Service is designed to reduce the time and effort required to migrate on-premises applications to the cloud.

Amazon has introduced a new import feature that enables customers to import their inventory list into Application Migration Service with a CSV file. It’s also possible to export source server inventory for scenarios such as offline reviews and updates, reporting purposes, and bulk configuration changes.

Additionally, the new Server migration metrics dashboard provides a central hub to view the migration lifecycle status of the source server. It also allows customers to view associated alerts and get a quick overview of the data replication status.

Application Migration Service now supports additional post-launch actionsFinally, Application Migration Service added support for eight new predefined post-launch actions. IT admins can apply the actions after launching the migrated applications on AWS. The list of new actions includes convert MS-SQL license, create AMI from instance, upgrade Windows version, conduct EC2 connectivity checks, validate volume integrity, validate volume integrity, CloudWatch agent installation, and join Directory Service domain.

Amazon says that the new features are available for all customers in all Application Migration Service-supported regions worldwide. The service supports Red Hat Enterprise Linux (RHEL) 5.5 (or later) as well as CentOS 5.5 and later. You can learn more about Application Migration Service pricing on the AWS website.

View Details

Cybersecurity vendor Logpoint detailed this week a new update for Converged SIEM, the company’s new platform that combines SIEM (Security information and event management), SOAR (Security orchestration, automation and response), User Entity and Behavior Analytics (UEBA), and business-critical security in a single offering.

Logpoint Converged SIEM became generally available back in March 2022 as a SaaS-delivered service or on-premises. The cloud-based solution offers organizations an all-in-one platform with threat detection, advanced security analytics, automated investigation, and response across different endpoints.

“With the latest update of Logpoint’s Converged SIEM security analysts receive a wide set of new and improved features that provide enhanced observability and the added advantage of decreasing the time to respond to threats,” the company explained yesterday.

New Case Management interface for Logpoint’s Converged SIEM platformThe new Case Management interface in Logpoint Converged SIEM will allow security teams to quickly get an overview of ongoing cases. Related incidents are intelligently grouped into the same case, which allows analysts to implement more efficient actions within a case.

“These capabilities make it easier for SOC teams of all sizes to efficiently manage cases and resolve incidents faster,” Logpoint said about its new Case Management interface.

The new Case Management interface on Logpoint Converged SIEM (Image credit: Logpoint)New AgentX endpoint security agent and other updatesLogpoint’s Converged SIEM platform is also adding AgentX, a new endpoint security agent. AgentX can collect logs and telemetry from various endpoints, bring them to the SIEM, and investigate and find remedies to potential threats in real-time.

Logpoint is also adding various new features to improve security within an organization, including:

  • More reliable alerts in case of a delay in log collection.
  • Users can now add devices by their hostname, making them easier to track compared to using IP addresses that can change.
  • Backing up and restoring all playbook and actions is now possible
  • Azure Active Directory-related detectors have also been added for UEBA.

The latest version of Logpoint’s Converged SIEM platform is now available to download from the company’s website. Logpoint will also demo all these new features during a webinar on April 19, and you can register for it on this page.

View Details

MC534742 – OneNote is making an important change to how it treats embedded files that have dangerous extensions. Previously, OneNote would show users a warning dialog when users tried to open an embedded file with a dangerous extension; users could open the file by choosing OK in the dialog.

With this update, OneNote will show users a dialog that will let them know that their administrator has blocked them from opening the embedded file that has a dangerous extension, to also align with the same extensions that Outlook, Word, Excel and PowerPoint currently block. For a list of extensions, please visit Blocked attachments in Outlook.

If the user trusts the person that sent the embedded file and they need to open the embedded file, they can save the file to their local device and open the file from there.

This post is associated with Microsoft Roadmap ID 122277

When will this happen:

This change will begin rolling out in Version 2304 in Current Channel (Preview) in late April 2023 and is expected to be complete by late May 2023.

For more information about the release schedule, see OneNote will block embedded files that have dangerous extensions.

How this will affect your organization:

This change only affects OneNote for Microsoft 365 on devices running Windows.

The change does not affect OneNote on a Mac, OneNote on Android or iOS devices, OneNote on the web, or OneNote for Windows 10.

View image in new tab

What you need to do to prepare:

You should make users and your support organization aware of this upcoming change and update any relevant training documentation.

You can also use a Group Policy setting to block additional extensions that you deem to be dangerous. For more information, see OneNote will block embedded files that have dangerous extensions.

Additional information

Help and support

View Details

MC534739 – When using Microsoft 365 Apps on the web for Word, Excel, and PowerPoint, files that have a sensitivity label will also apply those labels to PDFs created in those apps. Documents that also have encryption cannot be converted to PDF without first removing protection.

This message is associated with Microsoft 365 Roadmap ID 117594

When this will happen:

Standard Release: Microsoft will begin rolling out early May 2023 and expect to complete by early June 2023.

How this will affect your organization:

Users who are already configured for sensitivity labels will automatically persist their document’s label to PDFs they create in Word, Excel, and PowerPoint for the web. If a document is protected with encryption, the PDF functionality is not available. Users who try to convert a protected Office document to PDF are prevented from completing the scenario without removing protection if they have the rights to do so.

What you need to do to prepare:

No action is required by admins or users to enable this functionality.

Additional information

View Details

MC534738 – The Viva Engage admin experience currently available within the Teams application will soon be available within the Yammer web surface (being renamed to Viva Engage) for Microsoft Viva customers.

This web Viva Engage admin center is accessible from web.yammer.com and provides an additional entry point for admins (especially users who don’t have access to Teams due to licensing constraints) to setup, configure and manage the various features for their organization.

When this will happen:

This feature will begin rollout in late April and is expected to be complete by late May.

How this will affect your organization:

All functionalities that are currently available within the Viva Engage admin center in the Teams application will be released in the web version, and access to these admin experiences will continue to honor the role permissions in place.

View image in new tab

What you need to do to prepare:

There is no action required from you at this time as this update will be enabled automatically. Resources to learn more about the Viva Engage admin center and all the functionalities offered can be found here. For an overview on the entire new admin experience that was released in February, check out this blog.

Additional information

Blog

View Details

MC534736 – Viva Engage will soon have an improved @mentioning behavior available. Users will be able to @mention someone just using their first name/last name. This change would be available on web, and on mobile. 

Admins will also have the ability to turn off this feature through their admin portal.

This message is associated with Microsoft 365 Roadmap ID 108071

When this will happen:

Standard Release: Microsoft will begin rolling out mid-April 2023, and will complete the rollout by late April. 

How this will affect your organization:

Users will be able to @mention someone just using their first name/last name. This change would be available on web, and on mobile.

Admins will also have the ability to turn off this feature through their admin portal.

What you need to do to prepare:

Raising awareness that this feature is now available within Engage might be helpful for existing users. but outside of that, since this is a long asked for improvement on an existing feature, you will not need to do much to prepare. 

View Details

MC534735 – Teams Video Clip was released last November, Microsoft is updating the feature with auto-generated captions support. 

When this will happen:

Targeted Release: Microsoft will begin rolling out late March and expect to complete by early April.

Standard Release: Microsoft will begin rolling out early April and expect to complete by mid-April.

How this will affect your organization:

This is closing the accessibility gap for Teams Video Clip. The captions will be auto-generated once the video is uploaded. User now can watch Teams Video Clip without audio with auto-generated captions on.

  1. Only creator of the TVC can download the captions/transcript of the TVC.
  2. User can delete the captions by delete the video clip.

What you need to do to prepare:

There is no action needed to prepare for this change. You may want to notify your users about this change and update any relevant documentation as appropriate.

View Details

MC534356 – Microsoft has released updates to the following update channel for Microsoft 365 Apps:

  • Current Channel

When this will happen:

We’ll be gradually rolling out this update of Microsoft 365 Apps to users on that update channel starting March 28th, 2023 (PST).

How this will affect your organization:

If your Microsoft 365 Apps clients are configured to automatically update from the Office Content Delivery Network (CDN), then no action is required.

If you manage updates directly you can now download this latest update and begin deployment.

What you need to do to prepare:

To get more details about this update view the following release notes:

  • Current Channel

Additional information

View Details

Last year, Microsoft announced its plans to deprecate Remote PowerShell (RPS) in Exchange Online in June 2023. Now, the company has decided to delay the deprecation of the RPS protocol until October this year.

Remote PowerShell is a feature that allows IT admins to connect to their Exchange Online through PowerShell commands. It lets administrators perform various tasks, including managing distribution groups, mailboxes, public folders, and contacts. Remote PowerShell depends on Basic Authentication which makes it vulnerable to cyberattacks.

Microsoft is killing off the Remote PowerShell connections for all existing Exchange Online customers in May this year. However, the company will still let IT admins re-enable RPS in these tenants until September. Microsoft says that all new tenants created on April 1 will also be able to re-enable the protocol until June 2023. This capability will not be available for new subscribers coming on board after July 1.

Microsoft releases the RPS self-service tool for Exchange Online Microsoft has made this decision based on the initial feedback received from organizations. It should give customers sufficient time to migrate to the REST-based PowerShell v3 module that launched in September 2022. The latest v3 module is more secure because it supports certificate-based authentication.

“We have released a self-service tool in the Microsoft 365 admin center and the Exchange admin center that admins can use to request an extension or re-enablement of RPS. We are adding this tool to help you minimize disruptions as you transition away from using RPS. We want you to use the tool only if you really need to use RPS, and not just because you think you might need to,” the Exchange team explained.

Keep in mind that Microsoft will remove the option to re-enable RPS connections in September. This means Remote PowerShell for Exchange Online will get completely blocked for all customers in October 2023. Microsoft recommends IT Pros to plan migrations before the final cut-off date to protect their end users against cyberattacks.

View Details

Microsoft has announced a new Collaboration Security feature for Microsoft Teams. The new set of capabilities provides preventive, detective, and protective features that ensure end-to-end security for select Microsoft Teams customers.

“With 71% of companies admitting that sensitive and business-critical data is regularly shared via collaboration tools like Microsoft Teams, organizations are increasingly realizing the need to make collaboration security an integral part of their overall SOC strategy. That’s why we are bringing the full feature set that customers use to protect their email environments across prevention, detection, and response to Microsoft Teams,” Microsoft explained.

First up, the Collaboration Security feature allows users to report suspicious messages and files directly within Microsoft Teams. Microsoft says that security teams can review the reported messages for further investigation within the Microsoft 365 Defender portal.

Additionally, Microsoft has introduced Zero-Hour Auto Purge (ZAP) support to its Teams collaboration platform. The security feature scans all delivered messages to detect and quarantine phishing or malicious messages. IT admins can review and manage these quarantined messages in Microsoft 365 Defender. It’s also possible to release messages that are deemed safe for sharing in Microsoft Teams.

Microsoft Teams adds support for advanced hunting Microsoft is also bringing advanced hunting capabilities that should make it easier to proactively identify security threats. It’s a query-based threat-hunting tool that lets security teams explore 30 days of data to locate indicators of threat across email, endpoints, identities, SaaS apps, and DLP.

Last but not least, Microsoft notes that IT admins can configure phishing simulations to protect users against phishing attacks in Microsoft Teams. Some training tools provide advanced analytics and insights about the most common threat vectors within Microsoft Teams.

Collaboration Security for Microsoft Teams is available in public preview for customers with Microsoft Defender for Office 365, Microsoft E5, and Microsoft E5 Security licenses. Microsoft has yet to announce when this feature will become generally available for all businesses worldwide.

View Details

Tables are one of the core components of every relational database system and SQL Server is no different. Tables store the data that the relational database engine uses for queries, reports, and other operations. In this article, I’ll show you how to modify data from a SQL Server table using T-SQL INSERT, T-SQL UPDATE, T-SQL DELETE and TRUNCATE.

In my previous article, Essential SQL Server: Creating Databases and Tables, I showed how you can create basic SQL Server databases and tables. In this article, we’ll take a look at how you populate those tables by adding, updating, and deleting rows.

I created the following table in my previous article. The syntax from this simple example DDL command shows that the table has three columns and each of them uses a different data type:

CREATE TABLE dbo.myLogins ( id INT NOT NULL PRIMARY KEY, name VARCHAR (20), login\_date DATETIME ); In this article, we’ll look at adding data to a table using the INSERT statement, modifying data in a table using the UPDATE statement, and deleting data using the DELETE statement. Data in a table can be deleted in a couple of different ways, so we’ll also cover the difference between using the DELETE statement and the TRUNCATE statement.

Adding rows using T-SQL INSERTYou can add data to a SQL Server table in a number of ways:

  • You can use SQL Server Management Studio’s (SSMS) interactive Query Designer to add rows to a table
  • You can use PowerShell
  • You can use the SQL Server Import and Export Wizard or Integration Services to import data into a table
  • You can use the command line tool bcp utility.

That said, the most common way that data is added to a SQL Server table is by using the SQL INSERT statement. The T-SQL INSERT statement adds one or more rows to a SQL Server table.

The following example shows how to add a row to the example table that you saw earlier:

INSERT INTO myLogins (id, name, login\_date) VALUES (2, 'John Smith', '3-12-2023') Here, the INSERT INTO statement identifies the table that will contain the inserted rows. Next, within the parenthesis, you can see a list of the columns that will be used. This list uses all of the columns in the table, but you don’t have to do that.

Finally, the VALUES clause provides the actual values that will be inserted into the table. As a shortcut, you can omit the column list in an INSERT statement. For example, the following INSERT statement performs exactly the same function as the previous example:

INSERT INTO myLogins VALUES (2, 'John Smith', '3-12-2023') As a shortcut, you can omit the column list in an INSERT statement (Image credit: Petri/Michael Otey)Unless the column is defined using the NOT NULL keywords, you can also explicitly specify NULL in the values list of an INSERT statement. Alternatively, when you do not wish to specify a value for a column, you can leave that column out of your column and values lists which will cause it to contain a NULL value.

Inserting table rows from the results of a queryIn addition to using a standard T-SQL INSERT statement with a VALUES clause, you can also add rows to a table as a result of a SQL query. The query can be simple or complex, and the results can be inserted into the target table.

For example, to copy rows from the myLogins2 table to the myLogins table you can use a query like the one you can see below:

INSERT INTO myLogins (id, name, login\_date) SELECT id, name, login\_date FROM myLogins2 where id > 50. This example uses the results of the subquery from the myLogins2 table to insert rows into the myLogins table. The INSERT statement inserts data into the three columns in the table. The subquery uses a SELECT statement to select the same three columns from a second table named myLogins2.

However, in this example, only those rows with an id value greater than 50 will be returned and added to the myLogins table. In this simple example, the column names are the same, but that is not a requirement. For this to work, you need one or more rows in the myLogins2 table that have an id value greater than 50 that are not present in the myLogins table.

Updating rows using T-SQL UPDATELike adding rows to a table, there are a number of ways you can modify the rows in a table. SSMS’s Query Designer enables you to interactively update rows, but you can also use PowerShell or Integration Services.

However, the most common way to modify existing rows in a database table is to use the SQL UPDATE statement. The T-SQL UPDATE statement modifies the values in one or more rows in a SQL Server table.

Typically, you would want to use the UPDATE statement along with a WHERE clause to specify which rows to update. If you do not use the WHERE clause then all the rows in the table will be updated. The following listing shows a simple example of using the T-SQL UPDATE statement to modify the values in one row of the myLogins table.

UPDATE myLogins SET name = ‘John Smith’ WHERE id = 1 As I mentioned, if you were to omit the WHERE clause, the name column of every row would be set to the new value. Likewise, if the WHERE clause includes multiple rows as it might if you used the < or > operators, then multiple matching rows would be updated.

Updating table rows for the results of a queryJust like with the INSERT statement, you can also update rows in one table using values from another table. In the following listing, you can see how to use a SQL update from another table.

UPDATE myLogins SET myLogins.name = myLogins2.name FROM myLogins2 WHERE myLogins.id = myLogins2.id Here, you can see the UPDATE statement will be acting on the myLogins table, and that the name column will be updated using the values from the myLogins2 table where the value in the id columns of the two tables match.

The UPDATE statement lets you update rows in one table using values from another table (Image credit: Petri/Michael Otey)As you might guess, there are a lot more options for using the UPDATE statement. Your query can update multiple rows, it can be more complex using joins, and you can use the TOP clause, the ORDER BY clause, Common Table Expressions (CTEs) and more to build your update queries.

Deleting rows with T-SQL DELETE and TRUNCATEAs you might expect, you can delete rows from a table using the interactive SSMS Query Designer, PowerShell, or Integration Services. However, the most common method is using the SQL DELETE statement.

The T-SQL DELETE statement removes one or more rows from a SQL Server table. It goes without saying, but you should use the SQL DELETE statement carefully as it permanently deletes data from your tables. If you make a mistake, you might need to restore the data from a snapshot, the transaction log, or a backup.

The following example shows how to delete one row from the myLogins table:

DELETE FROM myLogins WHERE id = 1 Here, you can see that one row in the myLogins table will be deleted where the value of the id column equals 1. You can also delete multiple rows by changing the WHERE clause as in the following statement, which deletes all of the rows where the id value is greater than 50.

DELETE FROM myLogins WHERE id > 50 You can delete multiple rows by changing the WHERE clause (Image credit: Petri/Michael Otey)Like the UPDATE state, if you omit the WHERE clause all of the rows in the table will be deleted. For instance, the following example deletes all of the rows in the myLogins table:

DELETE FROM myLogins Deleting rows from the results of a queryLike the INSERT and UPDATE statements, the DELETE statement is also capable of acting from the results of a query. The following example shows how you can delete rows based on a query:

DELETE FROM myLogins WHERE login\_date < '12-31-2022' Here, all the rows in the myLogins table that have a date that is less than 12/31/22 in the login_date column will be deleted.

I’ve been using simple examples throughout this article, but like the INSERT and UPDATE statements, your queries can be much more complex. You could use JOINs and multiple tables in the DELETE statement’s subquery, use clauses like TOP and ORDER BY, and more.

DELETE vs TRUNCATEThe T-SQL DELETE command is capable of removing one or more rows from a table. However, it is not the only way to delete rows from a table. You can delete all of the rows in a SQL Server table using the T-SQL TRUNCATE TABLE statement.

The DELETE statement is a fully logged action. On the other hand, the TRUNCATE TABLE statement is a minimally logged action. This means that the TRUNCATE command will perform slightly better and fewer entries will be added to the transaction log. You can see an example of using TRUNCATE in the following listing.

TRUNCATE TABLE myLogins This will delete all of the data in the myLogins table.

SummaryIn this tutorial, you saw how to add, modify and delete rows in a SQL Server table using the T-SQL INSERT, UPDATE, and DELETE statements. In each case, I explained how to work with single-row values and how to work with multiple rows as a result of a subquery. In addition, you saw how the DELETE and TRUNCATE statements are different, even though they can both essentially delete rows from a table.

View Details

Microsoft announced yesterday a second-generation Surface Hub 2S digital whiteboard that will be available later this year. The new digital whiteboard will be running a new Teams Rooms experience that will differ from the existing Windows 10 Team Edition that powers the existing Surface Hub 2S.

The Surface Hub 2S was originally released back in 2019, and it’s currently available in 50-inch and 85-inch sizes. The device is designed for meeting rooms and its large multitouch screen allows multiple people to brainstorm using Microsoft Whiteboard and other apps. The Surface Hub 2S is also certified for Microsoft Teams and can be coupled with Teams Rooms devices, but the second-gen version coming later this year will make it a Teams Rooms device on its own.

“The future of Surface Hub will meet the realities of modern work, combining the latest Teams Rooms features with the iconic Surface Hub 2S design and premium hardware – a thin edge and bezel, dual active inking, and 20-point multi-touch – and providing users with a natural experience for enhanced collaboration,” Microsoft explained.

New Surface Hub 2S will run Teams Rooms on WindowsThe new Teams Rooms on Windows experience on the upcoming Surface Hub 2S will add support for the latest Teams Rooms features including Front Row. Microsoft promises feature parity with other Teams Rooms on Windows devices, as well as a “best-in-class” Whiteboard experience.

In addition to the built-in Teams Rooms features, the second-gen Surface Hub 2S will make it just as easy to join Zoom and Webex meetings. Microsoft didn’t share a lot of details about the new Teams Rooms on Windows experience yesterday, but the software change also means that IT pros will be able to manage Surface Hub 2S devices more easily in the Microsoft Teams Admin Center and Pro Management Portal.

Microsoft Whiteboard being used during a Teams meeting on the Surface Hub 2S (Image credit: Microsoft)Existing Surface Hub 2S models will be supported until October 14, 2025Microsoft also said yesterday that existing Surface Hub 2S devices running Windows 10 Team Edition will continue to receive software support until October 14, 2025. It won’t be possible to upgrade these devices to the new Teams Rooms experience, which will be exclusive to the second-gen Surface Hub 2S launching later this year.

While this is unfortunate for a device starting at $8,999 (the 85-inch version is priced at $21,999), Microsoft has made it possible to install Windows 10 or Windows 11 Pro and Enterprise on existing Surface Hub 2S models. This basically turns the digital whiteboards into full-fledged Windows PCs and removes the Windows 10 Team limitation that restricts Surface Hub 2S devices from running apps that haven’t been published to and signed by the Microsoft Store.

View Details

Microsoft announced the release of a new Security Copilot tool for cyber security professionals. The AI-powered chat assistant is designed to help analysts better understand potential threats and assess risk exposure to prevent security breaches in their environments.

Microsoft’s Security Copilot feature is based on OpenAI’s GPT-4 generative AI and its own proprietary security models. The service integrates with other security products (such as Microsoft Defender and Microsoft Sentinel) to create a summary of potentially malicious activities in natural language. It also provides step-by-step incident remediation guidance to quickly respond to threats.

“Our cyber-trained model adds a learning system to create and tune new skills. Security Copilot then can help catch what other approaches might miss and augment an analyst’s work. In a typical incident, this boost translates into gains in the quality of detection, speed of response and ability to strengthen security posture,” said Vasu Jakkal, CVP, Security, Compliance, Identity, and Management.

How does Security Copilot work to provide end-to-end protection?Microsoft highlighted that Security Copilot can help to reverse engineer security vulnerabilities. The AI-powered tool can also surface potential threats in real time, predict the next move of attackers, and answer security questions. Microsoft Security Copilot can also provide recommendations to help researchers improve their skills.

Microsoft acknowledged that its new Security Copilot solution could potentially make mistakes. However, the company emphasized that customer data would be protected by enterprise compliance controls. Microsoft also promised that user data or business processes won’t be used to train its AI models.

“Security Copilot is a closed-loop learning system, which means it’s continually learning from users and giving them the opportunity to give explicit feedback with the feedback feature that is built directly into the tool,” Jakkal added.

Microsoft Security Copilot availabilityMicrosoft Security Copilot is currently available in preview for enterprise customers. However, there is no word on when it will become generally available for all businesses. At launch, the AI tool only supports Microsoft security solutions, but Microsoft plans to add support for third-party products in the future.

Recently, Orca Security, a cloud security provider, announced its ChatGPT extension that provides step-by-step remediations to help security teams mitigate the impact of breaches. It’s great to see Microsoft catching up to grow its market share in enterprise security.

View Details

Microsoft has started rolling out a new Authenticator Lite feature in preview for its Outlook mobile app. The company announced on the Microsoft 365 admin center that it allows users to sign into their work or school accounts where MFA is enabled via the Outlook app on iOS and Android devices.

Multifactor authentication (MFA) is a security feature that allows customers to use multiple forms of authentication (such as a PIN or one-time code) to access a service. It adds an extra layer of security and makes it difficult for unauthorized users to access sensitive data.

The Microsoft Authenticator app already allows users to verify their sign-in for Microsoft 365 apps on mobile devices. The app generates a unique 6-digit code that can be used to approve authentication requests for Microsoft accounts and third-party services.

Microsoft explained that Authenticator Lite is designed to boost security for users who have not installed the Microsoft Authenticator app on their mobile devices. The feature lets users get code directly within the Outlook app on both Android and iOS. For now, it only supports push notifications with number matching and one-time codes.

“Microsoft Authenticator Lite is another surface for Azure Active Directory (Azure AD) users to complete multifactor authentication by using push notifications or time-based one-time passcodes (TOTP) on their Android or iOS device. With Authenticator Lite, users can satisfy a multifactor authentication requirement from the convenience of a familiar app,” Microsoft explained.

Microsoft Authenticator Lite to hit general availability next monthMicrosoft notes that the Authenticator Lite is available in public preview for select Outlook users. This means IT admins can use the Authentication Methods policy in Azure Active Directory to enable the feature for end users in their tenant. Microsoft expects to make the feature generally available in late April.

Microsoft has announced that it will enable Authenticator Lite by default for all enterprise customers on May 26th. However, IT admins will have the option to disable the feature or include/exclude users or groups before that date.

View Details

Microsoft has announced the public preview of a new custom claims provider feature for Azure Active Directory (Azure AD). The custom extension allows organizations to call an API and map custom claims into the security token during the authentication process.

The custom extensions feature enables Azure Active Directory (Azure AD) users to interact with external systems. It provides a way to store additional data in Azure AD on user objects, groups, tenant details, service principles, and other directory objects. Custom extensions let users build custom solutions to meet their unique business requirements.

“A custom claims provider lets you call an API and map custom claims into the token during the authentication flow. The API call is made after the user has completed all their authentication challenges, and a token is about to be issued to the app. We heard from many of you that you need to return additional claims into the tokens sent to your apps so that they could function as intended,” Microsoft explained.

Microsoft explained that organizations often store user data (such as sensitive information and billing details) in external systems. It’s possible that some IT admins might want to configure custom claim providers to keep identity data in on-premises environments. The new feature eliminates the need to use legacy identity systems, including Active Directory Federation Services (AD FS) and LDAP directory.

Azure AD custom claims provider integrates with other data storesCurrently, it’s not possible to synchronize attributes to Azure AD due to data residency or regulatory requirements. The custom claims provider feature provides integration with third-party systems and other data sources that can’t be synced to the Azure AD directory. You can see how the Azure AD custom extensions and custom claims providers work in the video below:

Microsoft plans to add support for more customization options for authentication flow in the future. “Custom claims providers is just the first use of a custom extension. We’ll continue to release additional custom extension events, so you can customize your authentication flows even more,” Microsoft added. You can learn more about configuring custom claims providers on this support page.

View Details

MC533687 – Today we’re starting to roll out the preview of the new Microsoft Teams desktop app for Windows. The new Microsoft Teams desktop app is built on a foundation of speed, performance, and flexibility—saving you time and helping your organization work together more efficiently.

How will this benefit my organization:

Our goal for the new Teams app is to make it twice as fast while using half the system resources. Microsoft hasn’t done optimizing the performance of new Teams, but Microsoft is already seeing common scenarios such as app load and meeting join hit that goal, as well as a 50% reduction in memory. Microsoft has also observed significant gains in installation time, disk space used, chat and channel switch time, search, and more.

The new Teams app also adds support for organizations that have multiple tenants and users who must manage multiple accounts. Users can be signed into multiple tenants and accounts simultaneously and receive notifications no matter which one is currently in use.

Note: Not all customer segments (Education, Special Cloud, GCC, GCC-High and DoD) and platforms (Mac, VDI, and Web) will receive this update at this time. While the new Teams preview includes much of the same functionality as classic Teams, there are a few features which are not yet available. Visit this page to learn more about what’s currently available and what’s coming up.

How will I preview the new Teams experience:

  • If you are in the public preview program, you will have access to the Try the new Teams toggle. Our preview roll out will begin on March 27, 2023 and expected to complete over the following week.
  • If you are in the Targeted release program, you will have access to the preview of new Teams starting mid-April. Please refer to MC post MC510331 for Targeted release rollout timelines. Prior to this announcement, the Targeted release provided early access to OneDrive for Business, SharePoint Online, Office for the web, Microsoft 365 admin center, and some components of Exchange Online. Admins and select users in the Targeted release program can be among the first to see the latest Teams innovations.
  • If you are in production, as an admin you will have the option to opt-in your users by using the Teams update management policy to select which users in your organization can see the toggle and get access to new Teams. Users can use the new Teams and switch back to classic Teams anytime. Our goal is to ensure you are fully empowered to try new Teams in a manner that’s right for you as early as possible.

Visit the admin page, support article or download resources to learn how to get started with previewing the new Teams experience.

Additional information

Help and support

Blog

View Details

MC533652 – Avatars for Microsoft Teams gives you that much-needed camera break, while still allowing you to collaborate effectively. You can add a new layer of choice to your meetings and represent yourself the way you want with customizable avatars and reactions.

Represent yourself the way you want with customizable avatars and reactions. Save up to three avatars for different meeting types, such as casual, professional, and day to day. Note that Avatars for Microsoft Teams is designed for users 18+.

This release is associated with Microsoft 365 Roadmap ID: 107969

View image in new tab

When this will happen:

  • Targeted Release (Public Preview): Microsoft expect to begin rolling out late March and expects to be complete by early-April.
  • Standard Release: Microsoft is working hard to begin rolling this out in May and will communicate any changes via Message Center

How this affects your organization:

You can create your avatar for Microsoft Teams from the Avatars app and select your avatar from the pre-join and in-meeting scenarios.

Create your avatar: You can create your avatar for Microsoft Teams through the Avatars app. To access the Avatars app, you can search and install from the Teams App store, through the pre-join screen by clicking the button ‘Create your avatar’ and in-meeting through the More menu under Effects and avatars.

Select from hundreds of combinations to customize an avatar that represents your physical attributes, wardrobe, accessories, and more. Save up to three avatars for different meeting types.

View image in new tab

Before joining a Teams meeting, you can access Avatars from the quick tray when your camera is disabled.

View image in new tab

After joining a meeting, you will be able to apply your avatar from selecting Effects and avatars on the side pane under the More menu. Additional settings are provided to express yourself through avatar reactions, update your background, change your camera position and more!

View image in new tab

View image in new tab

What you can do to prepare:

Since Avatars are based on apps in Teams, you can manage these apps just as you would any others. See this page to learn more about how to manage apps in the Microsoft Teams admin center. Find out more at Manage your apps in the Microsoft Teams admin center – Microsoft Teams | Microsoft Learn

Got feedback on features in the public preview or other areas of Teams? Let us know straight from Teams via Help > Give feedback. This is on the bottom left of your client.

Blog

View Details

As Microsoft is kicking off its Enterprise Connect conference this morning, the company announced a new Teams desktop client that brings big performance improvements for Windows users. Microsoft has also unveiled several new features and capabilities coming to Microsoft Teams this month.

The new version of Microsoft Teams has been built from the ground up, and it consumes 50 percent less memory and 70 percent less storage space. Microsoft claims that launching the app or joining meetings should now be two times faster. Users should experience 1.7 times faster performance while switching between chats and channels.

The Microsoft Teams desktop client brings multi-account support for enterprise customers. The app supports AI-powered experiences such as Copilot for Microsoft Teams and intelligent recaps for meetings. Microsoft has introduced customizable group chats, threaded conversations, and interactive emojis. Other capabilities include an updated gallery view, screen-sharing support, and a pre-join experience.

Mesh Avatars for Microsoft TeamsMicrosoft has released a new update that allows users to create animated Mesh Avatars for Teams meetings. The feature is similar to the existing 3D avatars available in Zoom, Apple Facetime, and Meta’s Horizon Worlds platform. Microsoft has been testing Mesh Avatars since October 2022, and the feature is finally available in public preview.

Microsoft Teams gets a new Channel experienceMicrosoft has introduced a new channel experience that’s designed to be a bit more intuitive and modern to drive engagement. This release moves the compose box and recent posts to the top of the window to help users catch up on important conversations. There is also a new information pane that makes it easier to keep track of pinned posts, new channel members, and other contextual information. Microsoft has added the ability to pop out channel conversations like 1:1 chats.

New Files App in Microsoft TeamsMicrosoft Teams is getting a new Files app that should make it easier to find, access, and share documents in chats, channels, and meetings. It features dedicated sections in the sidebar, such as Home, My files, Shared, Downloads, and Quick access.

Microsoft is adding an expanded view of the profile card in Microsoft Teams. The feature enables users to view contact information, job title, organizational chart, and LinkedIn profiles of colleagues. The profile card can now show Insights such as suggested tasks, birthdays, and career updates to help users celebrate important milestones. It’s now possible for users to add pronouns to profile cards and view LinkedIn profiles of external users.

Lastly, Microsoft announced a new feature that lets administrators view users and groups assigned to a specific policy. Moreover, IT Pros can now export Teams list as a CSV file directly from the Teams admin center. The company has also announced some new Teams devices, and we invite you to check out the blog post for more details.

View Details

This week, March 30th at 9.20am ET, Petri is hosting its first free virtual 1-day conference of the year on identity management and privileged access management (PAM). In our 2023 audience survey, IT Pros cited security as their number one concern. And because identity and privilege management form the basis of good security and a zero-trust security model, it’s essential that you and your organization is on top of how to properly manage user identities and manage the level of access users have once they have access.

Join me and our experts as we navigate the topic. Plus, we’ll be taking a first look at Microsoft Intune Elevation Rules for the first time as they enter public preview. You can register for free to get access to the sessions live on the day or on-demand for three months after conference day. Registrants will also be able to download an exclusive eBook that contains the most important information from each session.

How to implement and manage hybrid identities with Azure AD Connect – Michael Reinders

Michael Reinders, a regular contributor at Petri, kicks off the sessions at 9.30am ET with a look at how to manage hybrid cloud identities using Windows Server Active Directory, Azure AD, and Azure AD Connect. Michael explains how these technologies work together for easy identity management and a single sign-on experience for end users. Michael will walk through how to configure Azure AD Connect so you can also get your on-premises identities synchronizing to the cloud.

Roundtable – Your Identity Management and PAM Questions Answered – Russell Smith and guests

At 10.30am ET, I host a roundtable with Dean Ellerby, Chris Hills, and Michael Reinders. We will answer the top questions IT Pros have about implementing PAM, identity management, and achieving zero-trust security. So, don’t miss out!

Setting Up Windows Hello for Business and Seamless Single Sign-On (SSO) – Sander Berkouwer

Sander Berkouwer introduces a session on passwordless authentication at 11.00am ET. Sander looks at the different ways Windows Hello for Business can be implemented and walks through how to set it up using a cloud trust model.

Negate Ransomware at the Point of First Contact: Here’s How Ransomware poses an imminent threat to all organizations – Chris Hills

Conference sponsor, BeyondTrust, give a session at 12pm ET on how to stop ransomware in its tracks before it infects endpoints and moves laterally across your network. Chris Hills, Chief Security Strategist at BeyondTrust, outlines how ransomware is a real and present danger for organizations of all shapes and sizes. And how PAM can be used to stop ransomware and limit any potential damage it might do.

Implement Access Controls Using Microsoft Intune – Dean Ellerby

If you’re interested in Microsoft’s soon to be released PAM solution, be sure not to miss Dean Ellerby’s session on implementing access controls using Microsoft Intune. Dean demos the new Elevation Rules feature in Intune and how it can be used to provide access to elevated privileges for apps and processes sanctioned by IT.

Configure Azure AD User Authentication for Cloud-Native Apps – Andy Schneider

The day rounds up with a session that takes a deep dive into how authentication works for cloud-native apps with Azure AD. Andy Schneider, IT systems engineer and architect at Ravenswood Technology Group, takes us through how to work with protocols like OAUTH and SAML to enable authentication in your cloud-native apps.

Register now for the conference so you don’t miss out on this exclusive content from Petri.com!

View Details

It’s been a long time coming for long-suffering Microsoft Teams users. Today, Microsoft is launching access to a public preview of its new client software for Teams on Windows. The new client, which is officially version 2.1, will bring x2 faster performance while using 50% less memory.

The current Teams client is Electron based, a cross-platform programming framework, which while bringing an easy way for Microsoft to code once and have it run on multiple platforms, Electron apps are notorious for poor performance and resource utilization. So, if you are running the current Teams client on a notebook or poorly-spec’d device, then interacting with the app is likely a painful experience that drains the battery quickly. That’s all set to change.

Microsoft says about the updated client:

We have been listening to your feedback which has culminated in a reimagining of Teams from the ground up. The new app is built on a foundation of speed, performance, flexibility, and intelligence — delivering up to 2x faster performance while using 50% less memory so you can save time and collaborate more efficiently. We have also streamlined the user experience so that it is simpler to use and easier to find everything in one place. These enhancements also provide the foundation for game changing new AI-powered experiences such as Copilot for Microsoft Teams, announced earlier this month.

New Microsoft Teams 2.0 client based on WebView2The new Teams client is based on Microsoft’s WebView2 technology, which itself is based on Chromium and Microsoft Edge. Work has been undertaken to improve data, network, chat, and video speed and performance. Although, Microsoft notes this is just the start and it’s not done optimizing performance. Microsoft claims, using data from benchmarking company GigaOm, that app launch and meeting joins are already twice faster.

User experiences have also been updated in the new app. Including making it easier to track notifications, search for information, manage messages, and organize Teams channels.

Usability improvements in Microsoft Teams 2.0The authentication model has been updated so that it’s easier to switch tenants, much like it has been in the mobile version of the Teams app for some time. There’s no need to log in and out of different tenants using the new desktop client. And, regardless of which tenant you are signed in to, you will receive notifications from all of them.

New authentication experience allows you to switch tenants easily in the new Teams clientMicrosoft is building in new artificial intelligence (A.I.) features, like intelligent recap and Copilot for Teams into the new app.

When will the new Teams 2.0 client be available?Users in the Microsoft 365 Public Preview program get access to the new Teams app today. Microsoft is aiming to release the new client more generally later in 2023 and extend access to Mac users.

Commercial customers will need an admin to opt-in for the Preview Program before end users can access the updated client app. Users who choose to use the new client will be able to switch back to the classic Teams app any time using a toggle switch.

90+ new features coming to Microsoft TeamsMicrosoft also announced today that it is bringing ninety new features to Teams. More details will be available later this week as part of its Enterprise Connect event. One new feature we do know about is the new Files app experience, which will be available in preview this week and generally available mid-April.

View Details

Microsoft unveiled its plans to increase the price of its cloud services in the European Union (EU) in January 2023. Indeed, Microsoft’s cloud offerings (including Microsoft 365 and Microsoft Azure) will become up to 15 percent more expensive for European commercial customers on April 1, 2023.

Microsoft explained that it’s working to standardize the prices of its cloud services worldwide. Starting next month, all new or renewed product subscriptions (whether monthly, annual, or tri-annual) will be charged at a higher price in certain regions.

As a result, the new price for Microsoft cloud services will be increased by 15 percent for customers in Sweden. Moreover, Norway, Denmark, and other European countries will experience a price hike of 11 percent. Microsoft says that UK-based customers will need to pay 9 percent more for these services.

Microsoft announces bi-annual pricing reviews for cloud servicesGoing forwards, Microsoft plans to review the prices of Microsoft 365, Microsoft Azure, Exchange Online, and other cloud services in local currency twice a year. The company will take into account exchange rate fluctuations against the US dollar to adjust the prices accordingly. This change should help to increase transparency and predictability for commercial customers.

“The Microsoft Cloud continues to be priced competitively, and Microsoft remains deeply committed to the success of its customers and partners. We will continue to invest to enable customers to innovate, consolidate and eliminate operating costs, optimize business performance and efficiency and provide the foundation for a strong security strategy that customers around the world have come to rely on,” Microsoft explained.

Microsoft says that the new pricing will only impact European businesses. However, existing customers will see changes at the end of their current billing period. For now, there will be no adjustments to the pricing for Microsoft 365 Personal and Family subscriptions.

View Details

Many of you have been using Azure Active Directory Connect to manage your hybrid identities and synchronization of users from Active Directory to Azure Active Directory (Azure AD). This modern technology is called Azure AD Connect cloud sync. In this article, I’ll walk you through the installation and basic configuration of Azure AD Connect cloud sync and explain how to implement it into your Active Directory/Azure AD infrastructure.

What is Azure Active Directory Connect cloud sync?Many IT Pros are familiar with Azure AD Connect – the syncing software you use to sync your identities from your on-premises Active Directory to Azure Active Directory and offer seamless single sign-on. The next evolution is to bring everything to the cloud.

So, Microsoft has moved from a software application installed on a domain-joined server in your on-premises environment to a simple provisioning agent. A much lighter footprint as all the ‘heavy lifting’ is now done in Azure. No more need for a database on-premises – this is all done in the cloud.

Lightweight agents have been the way to go recently. This is a boon if you have gone through a merger or an acquisition recently or are planning for one.

Azure AD Connect cloud sync is designed to meet and accomplish your hybrid identity goals by syncing your users, contacts, groups, devices, and more to Azure AD. An important note – you can use Azure AD Connect side-by-side with the cloud sync provisioning agent!

What are the differences between Azure AD Connect sync and Azure AD Connect cloud sync?Great question! Here is a table from Microsoft that shows the feature comparisons between the two products.

| Feature | Azure AD Connect sync | Azure AD Connect cloud sync | | --- | --- | --- | | Connect to a single on-premises AD forest | ● | ● | | Connect to multiple on-premises AD forests | ● | ● | | Connect to multiple disconnected on-premises AD forests | ● | | Lightweight agent installation model | ● | | Multiple active agents for high availability | ● | | Connect to LDAP directories | ● | | Support for user objects | ● | ● | | Support for group objects | ● | ● | | Support for contact objects | ● | ● | | Support for device objects | ● | | Allow basic customization for attribute flows | ● | ● | | Synchronize Exchange online attributes | ● | ● | | Synchronize extension attributes 1-15 | ● | ● | | Synchronize customer-defined AD attributes (directory extensions) | ● | ● | | Support for Password Hash Sync | ● | ● | | Support for Pass-Through Authentication | ● | | Support for federation | ● | ● | | Seamless Single Sign-on | ● | ● | | Supports installation on a Domain Controller | ● | ● | | Support for Windows Server 2016 | ● | ● | | Filter on Domains/OUs/groups | ● | ● | | Filter on objects’ attribute values | ● | | Allow a minimal set of attributes to be synchronized (MinSync) | ● | ● | | Allow removing attributes from flowing from AD to Azure AD | ● | ● | | Allow advanced customization for attribute flows | ● | | Support for password writeback | ● | ● | | Support for device writeback | ● | Customers should use Cloud Kerberos trust for this moving forward | | Support for group writeback | ● | | Support for merging user attributes from multiple domains | ● | | Azure AD Domain Services support | ● | | Exchange hybrid writeback | ● | | Unlimited number of objects per AD domain | ● | | Support for up to 150,000 objects per AD domain | ● | ● | | Groups with up to 50,000 members | ● | ● | | Large groups with up to 250,000 members | ● | | Cross-domain references | ● | ● | | On-demand provisioning | ● | | Support for US Government | ● | ● |

Azure AD Connect sync vs. Azure AD Connect cloud sync (source: Microsoft)There is one major and prevalent scenario that is currently not supported with the newer Azure AD Connect cloud sync feature, and that’s Exchange hybrid. Here is the current answer from Microsoft’s documentation:

The Exchange Hybrid Deployment feature allows for the co-existence of Exchange mailboxes both on-premises and in Microsoft 365. Azure AD Connect is synchronizing a specific set of attributes from Azure AD back into your on-premises directory. The cloud provisioning agent currently does not synchronize these attributes back into your on-premises directory and thus it is not supported as a replacement for Azure AD Connect.

Prerequisites for installing Azure Active Directory Connect cloud syncMicrosoft mentions a few prerequisites to take note of before starting the installation. Let’s go over those here.

  • In the Azure portal:
    • You need to have access to a cloud-only Global Administrator account.
    • You will need a custom domain name in place in Azure to match the UPN domain name in your Active Directory. If you are migrating from Azure AD Connect this should already be in place, but it is worth nothing.
  • In your on-premises environment
    • You will need a domain-joined machine running Windows Server 2016 or newer. You need at least 4 GB of ram and .NET Framework 4.7.1 or greater. The server simply needs network access to at least one domain controller in your on-premises AD forest.
    • Your edge firewall will need to allow outbound ports 80 and 443 to be made from your server here to Azure AD.

The only other (optional) step is to first uninstall Azure AD Connect if you have it installed. This is not required, but for the purposes of this article, I will walk through the simple steps next.

Oh, and it is very easy to take advantage of high availability with this setup. Simply install the provisioning agent on more than one server in your network. You’ll see the steps below.

Uninstalling Azure AD Connect (optional) Log into your Azure AD Connect server and open Control Panel. * Open the ‘Uninstall a program*‘ menu.

Using Control Panel – Programs and Features to uninstall the older Azure AD Connect software (Image credit: Petri/Michael Reinders) Click the Microsoft Azure AD Connect entry and click the Uninstall* toolbar button.

Uninstalling Azure AD Connect (Image credit: Petri/Michael Reinders)My suggestion here is to make sure the checkbox is checked to remove everything. I always like to uninstall software as cleanly as possible, doing my best to not leave any remnants lying around.

  • Click Remove and allow it to finish.

It is gone. Out with the old, in with the new… (Image credit: Petri/Michael Reinders)There, all gone. Now, we can move on to the new installation steps.

How to implement Azure AD Connect cloud sync into your AD / AAD infrastructureAs I have said, you can install an Azure AD Connect cloud sync agent with or without an existing Azure AD Connect installation in your environment. In this case, I just removed my existing Azure AD Connect software, so we have a clean slate. Let’s get started!

InstallationWe will start on my Windows Server 2022 domain-joined server, WS22-FS02.

  • First, log in to the Azure Portal and access the Azure Active Directory (Azure AD) site.

The Azure Active Directory portal (Image credit: Petri/Michael Reinders) On the navigation menu on the left, scroll down and click on Azure AD Connect. Then, click Cloud sync* on the left again.

The Azure AD Connect Cloud Sync overview (Image credit: Petri/Michael Reinders) It’s not surprising that we have a nice clean slate. Click on the Agents‘ menu on the left, then click Download on-premises agent*.

Downloading the agent to install on our on-premises server (Image credit: Petri/Michael Reinders)* After you’ve downloaded the agent, go ahead and double-click on the MSI file. The installation will start.

Installing the bits for the provisioning agent (Image credit: Petri/Michael Reinders) Check the box and click Install*!

Installing…and waiting… (Image credit: Petri/Michael Reinders)Next, we move on to Configuration.

Active Directory ConfigurationAfter the initial agent is installed, the Microsoft Azure Active Directory Connect Provisioning Agent Configuration wizard will start. Say that 5 times fast. Yikes, Microsoft. Always hitting home runs with product names!

  • On the Welcome screen, click Next.

Starting the very-long-titled wizard (Image credit: Petri/Michael Reinders) On the ‘Select Extension‘ screen, choose HR-driven provisioning (Workday and SuccessFactors) / Azure AD Connect Cloud Sync. This is the most likely scenario. Only if you’re planning to provision on-premises applications to Azure would you choose the 2nd option. * Click Next*.

On the ‘Select Extension’ screen (Image credit: Petri/Michael Reinders) Next, the Connect Azure AD screen comes up, asking for the credentials for your Azure AD Global Administrator. Enter those, and be ready for MFA! * Next up, the Configure Service Account screen. Here, we will accept the default, Create gMSA. Because we are asking it to create a gMSA account to manage the synchronization from AD to Azure AD, we need to enter an account with Domain Admin privileges. Enter that and click Next*.

Configuring the Service Account (Image credit: Petri/Michael Reinders) Continuing, we come to the ‘Connect Active Directory*‘ screen. Yes, you are right. This is rather similar to the installation wizard for installing Azure AD Connect.

Connecting to Active Directory (Image credit: Petri/Michael Reinders) Anyway, verify that the correct Active Directory domain is set. If you see any errors, you may have mistyped your credentials. Go ahead and correct if necessary and click Next*.

We are done. We’re on the Confirm screen (Image credit: Petri/Michael Reinders) We have come to the final Confirm screen. Verify all looks good and click that Confirm* button.

We’re done! (Image credit: Petri/Michael Reinders)Azure AD configurationWe now move to Azure Active Directory. To manage Azure AD cloud sync, browse again to the Azure Portal.

  • Click on Azure AD Connect, and click Cloud sync.
  • Click the ‘New configuration‘ button on the top to start the configuration process in the cloud.

Back at the Cloud Sync configuration page (Image credit: Petri/Michael Reinders) Here we have the New cloud sync configuration. The defaults should be OK assuming you only are syncing the one AD domain – in my case ‘reinders.local.’ We’ll keep ‘Enable password hash sync*‘ checked to allow for automatic password management.

Our new configuration is all ready and verified. (Image credit: Petri/Michael Reinders) Click Create* at the bottom.

Well, check this out! We are done. I don’t know about you, but I almost ALWAYS prefer cloud-based configurations vs. traditional ‘thick’ client software. It’s cleaner. Plus, they can iterate on the UI and add features much faster. And, because it is cloud-based, you don’t need to worry about upgrades to the software, servers going down, etc. It just works. The cloud, 100% of the time, right?

Testing – VerificationLet’s go and simply enable the configuration. We can address the scoping filters, attribute mapping, etc. a little later.

  • Click the Review and enable configuration button at the top, then click Enable Configuration.
  • After that is complete, wait about 2 minutes, then refresh your browser, and click the Overview tab on top.
  • First off, you’ll want to enter a notification email address. Click the Properties tab and click the pencil (Edit) icon next to Basics.
  • Enter an administrator email to receive alerts about the syncing infrastructure. Click Apply at the bottom.

Setting up a notification email address (Image credit: Petri/Michael Reinders)Now, regarding validation and advanced customization, click back to the Users view in the Azure AD portal to view all of your users. I took note that the number of users went from 31 to 32. So, I know SOMETHING happened. And, if you really are paying attention, you may have remembered that I filtered out a user in a specific OU when I configured Azure AD Connect. So, because I have not done any filtering yet, a new user has been synced – John Reinders.

Let me go through the three core configuration screens you’ll use to maintain and adjust your synchronization settings. The first is Scoping filters.

Scoping Filters (Image credit: Petri/Michael Reinders)The default is to sync all the users in your Active Directory. You can choose to sync only select security groups OR select organization units (OUs). And yes, this is one example of cloud software being, for the moment, less configurable than on-premise software. But, this is continually changing. Eventually, they will incorporate ALL the features and options into Azure AD Connect cloud sync.

Attribute Mapping Screen (Image credit: Petri/Michael Reinders)Next, let’s look at Attribute mapping. Here we can choose to edit the default list of attributes and how they are synced from Active Directory to Azure AD, and even add additional items by clicking ‘+ Add attribute mapping.’

Adding a new attribute mapping (Image credit: Petri/Michael Reinders)Rest assured there are a lot of options here. As I said, Microsoft is continually adding more features to this functionality. So, don’t be surprised if you notice some of these screens change around or add/remove bits. This is the cloud, folks!

Finally, let’s look at the Expression builder. This is where you can really add some customization to how certain attributes get synced, and how to use expressions to match specific user attributes from one Active Directory domain and other attributes from another AD domain to produce the best single object in Azure AD. Again, there is a lot of power here, and you’ll be familiar with the general setup if you’ve used custom features like synchronization rules in the Azure AD Connect software.

ConclusionWell, that is a lot of information. And, I do want to point out the biggest disadvantage to Azure AD Connect cloud sync – it does have fewer features and can support fewer scenarios than Azure AD Connect.

This is normal and by design. Azure AD Connect has been around for years and Azure AD Connect cloud sync was released about a year ago. So, naturally, there is more functionality in the older software.

My advice: As soon as the supported scenarios with Azure AD Connect cloud sync match your environment, take the steps to migrate to it. After using Azure AD Connect for quite a few years in my ‘day jobs’, the cloud functionality looks very nice – and MUCH less to administer and keep tabs on.

Please feel free to leave a comment or question below and thank you for reading!

View Details

Microsoft Loop is here! Are you ready to take your productivity to the next level? With its new features and capabilities, Loop is set to change the way you work in Microsoft 365. In this video, I’ll take a closer look at what Loop has to offer and how it compares to Notion.

View Details

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new open-source incident response tool. The Python-based utility is designed to help organizations track vulnerabilities in Microsoft cloud environments.

Specifically, CISA has teamed up with the U.S. Department of Energy’s Sandia National Laboratories to develop the Untitled Goose Tool. It utilizes different sophisticated hunting queries to detect the signs of exploitation in Microsoft 365, Microsoft Azure, and Azure Active Directory (AAD). The utility can also be used with other Microsoft security solutions to identify and mitigate security threats.

CISA detailed that the Untitled Goose Tool allows IT admins to perform the following operations:

  • Export and review AAD sign-in and audit logs, M365 unified audit log (UAL), Azure activity logs, Microsoft Defender for IoT (internet of things) alerts, and Microsoft Defender for Endpoint (MDE) data for suspicious activity.
  • Query, export, and investigate AAD, M365, and Azure configurations.
  • Extract cloud artifacts from Microsoft’s AAD, Azure, and M365 environments without performing additional analytics.
  • Perform time bounding of the UAL.
  • Extract data within those time bounds.
  • Collect and review data using similar time bounding capabilities for MDE data.

Getting started with the Untitled Goose ToolCISA says that customers can download and install the Untitled Goose Tool on Windows, macOS, and Linux machines. However, it requires users to install Python version 3.7, 3.8, or 3.9 to run on their systems.

Earlier this month, the Cybersecurity and Infrastructure Security Agency (CISA) released a free tool called Decider. Its purpose is to help security teams map attackers’ behavior to the Mitre ATT&CK framework. Decider comes with intuitive search and filtering capabilities, making it easy for users to find the information they need. It also allows users to export results to commonly used formats for further analysis.

View Details

Microsoft is introducing a transport-based enforcement system in Exchange Online that will throttle and block emails from old Exchange Servers. The company explained that this change aims to encourage organizations to upgrade to a supported version of Exchange Server.

Microsoft has found that thousands of on-premises customers are running outdated versions of Exchange Servers. The list includes Exchange 2007, Exchange 2010, and Exchange 2013 which will become unsupported next month. Moreover, unpatched Exchange 2016 and Exchange 2019 servers are also persistently vulnerable to known attack vectors, including the Hafnium hacks that started in March 2021.

Microsoft plans to address the problem by implementing a transport-based enforcement system in Exchange Online on June 26, 2023. Initially, it will report, throttle, and block messages sent from Exchange 2007 Servers over an inbound OnPremises type of connector. However, the change will not impact emails coming from unsupported servers via a different pathway.

“The system is designed to alert an admin about unsupported or unpatched Exchange servers in their on-premises environment that need remediation (upgrading or patching). The system also has throttling and blocking capabilities, so if a server is not remediated, mail flow from that server will be throttled (delayed) and eventually blocked,” the Exchange team explained.

What are the throttling-blocking enforcement stages?Microsoft plans to implement the enforcement in a progressive manner to include other Exchange Server versions. The company will begin notifying all customers with vulnerable servers that they will be subject to throttling within 60 days. The enforcement process will be divided into 30-day chunks that involve reporting, throttling, and blocking.

Microsoft will be implementing a progressive enforcement plan to cover other versions of Exchange Server. All customers with vulnerable servers will receive a notification that throttling will be applied within 60 days. This enforcement process will be divided into 30-day chunks, involving reporting, throttling, and blocking.

The stages of progressive enforcementMicrosoft advises patching vulnerable on-premises Exchange ServersMicrosoft urges organizations to upgrade/patch their vulnerable on-premises servers. However, the company is aware that this change may cause disruptions in business workflows. It will allow IT admins to request a temporary enforcement pause for up to 90 days per calendar year. For customers who continue to use outdated on-premises Exchange Servers, the blocking process will resume from the same point where it was paused.

Microsoft plans to hold an AMA session to inform customers about these changes on May 10, 2023, at 9 AM PT. If you’re interested, you can register for the event on the Exchange Events website.

View Details

As a Linux administrator or DevOps engineer, it’s important to understand how Linux groups work as each folder, directory, or file is linked to specific users and groups. In this tutorial, I’ll show you how to list all groups on a Linux machine, how to list all users, and how to see the groups they belong to.

How to list all groups on LinuxThere are multiple commands you can use to find all the groups that are present on Linux. But first of all, let’s start with an explainer about Linux groups.

What are groups on Linux?Groups on Linux-based operating systems are used to assign a set of privileges to a group of users. There are mainly two types of groups in the Linux distribution operating systems.

Whenever a Linux user creates a file or directory, then the files within it are allocated to a primary group, which has the same name as the one of the current user. Every user has at least one primary group associated with them. Whenever a new user is created, it is allocated within a primary group. Apart from their primary group, Linux users can also belong to other groups known as secondary groups.

Listing all groups with the groups commandBy using the groups command, we will see all the primary groups that are present on a Linux machine.

groups The groups command shows all primary groups on Linux (Image credit: Petri/Sagar)

Listing all groups with the /etc/groups fileAnother way to see all groups is to navigate to the /etc/groups directory using the cat utility. By navigating to the /etc/groups directory, you can see all the groups with their associated group identifier (GID).

In the image below, you can see that the GID for the root group is 0, the GID for the bin group is 2, and so on.

cat /ect/group The cat utility let us list all Linux groups with their group identifier (Image credit: Petri/Sagar)

Listing all group names with the cut commandWe can also use the cut command to see all group names. When we run this command, it retrieves all the details about groups in different columns, so we’ll be using the (-d) flag as delimiter as well as the (-f) option to select the column we want.

cut -d: -f1,6 /etc/passwd Using the cut command to list all group names on Linux (Image credit: Petri/Sagar)

Listing all groups with the getent commandThe getent command is another way to find groups. Using this command, you can fetch various information such as user accounts, their creation date, their group information, etc.

You can use the simple command below:

getent group The getent command is another way to list groups on Linux (Image credit: Petri/Sagar)

How to list all users on LinuxAs a Linux administrator, you may need at times to fetch the list of all users to perform some actions on them such as checking the groups they are attached to, the permissions they have, etc. I’ll now show you different ways to list all users on Linux.

Listing all users with the cat command on the ‘/etc/passwd” fileThe cat command can once again be used to check the users of a file or the groups attached to it. The /etc/passwd file contains information about all Linux users including their user identifier (UID), group identifier (GID), and more.

In the command below, the first line shows details about the ‘root’ user: It has 0 as its UID and GID, and we can also see that it can log into the Bash terminal.

cat /etc/passwd Using the cat command on the ‘/etc/passwd” file (Image credit: Petri/Sagar)

(Image credit: Petri/Sagar)

Listing users with the “who” and “users” commandsThe who command provides details about users who are logged into the Linux machine. The users command is another way to check who is currently logged into Linux.

The who and users commands can be used to list users connected to Linux (Image credit: Petri/Sagar)

How to list the groups of a specific userAfter I explained how to list all groups on Linux, I’ll now show you various ways to check the groups of a specific user.

With LibuserTo check the groups of a specific user, we can use a tool named libuser, which stands for “library of users.” You can use the command below to install libuser:

sudo apt install libuser Now, to check the list of groups of a specific user, you can run the commands below.

sudo libuser-lidsudo libuser-lid ubuntusudo libuser-lid sudosudo libuser-lid root Checking the list of groups of a specific user with libuser (Image credit: Petri/Sagar)

A couple of notes about these commands:

  • In the first command, we are not declaring any user so the command automatically picks ‘root’ as the user.
  • In the second command, we used ‘ubuntu’ as the user and we can see all the groups associated with this user.
  • In the third command, ‘sudo’ isn’t a correct user, that’s why the command doesn’t show any groups.
  • The last command shows the ‘root’ user, which has only one group.

With the /etc/group file.We can also use the cat command on the /etc/group file to see the groups of a specific user. In the command example below, we are extracting all the groups of the user ‘ubuntu’ from the /etc/group file by running the cat command followed by the grep command to filter the ubuntu user.

cat /etc/group | grep ubuntu Checking the list of groups of a specific user with the cat command (Image credit: Petri/Sagar)

With the id commandFinally; we can use the id command to list the groups of a specific user. In the example below, we can see that the ‘ubuntu’ user has ‘ubuntu’ as its primary group with 1000 as the GID, and the rest of the groups such as dialout, adm, etc. are all secondary groups.

id ubuntu The id command shows all groups for a specific user (Image credit: Petri/Sagar)

ConclusionYou should now have a good understanding of the different types of groups and Linux and the different ways to get more information about them. I hope that this knowledge will help you be more efficient when working with different file systems and disk permissions, which are quite important from a Linux administrator point of view.

View Details

Intel introduced yesterday its 13th gen vPro CPUs for business PCs. Intel’s vPro platform offers advanced security and management features for organizations, and the company’s 13th gen Core CPUs bring an improved hybrid architecture with a combination of Performance and Efficient cores.

“With our new 13th Gen Intel Core processors, the Intel vPro platform remains the premier business computing foundation, providing the best in security, business management and performance for organizations of all sizes,” said Stephanie Hallford, Intel vice president and general manager of the Commercial Client Division.

Intel’s 13th gen vPro CPUs: Performance updatesIntel’s 13th Gen vPro CPUs use a new process technology with redesigned Performance cores and an increased number of Efficient cores on select models. As an example, the top-of-the-line Core i9-13900 CPU now comes with 8 Performance cores and 16 Efficient cores, while the 12th gen Core i9-12900 had 8 Performance Core and only 8 Efficient Cores.

On the performance front, Intel’s Thread Director technology also does a better job at assigning tasks to the right type of cores. The Intel Dynamic Tuning technology should also provide better energy efficiency. Overall, Intel promises up to 65% faster Windows application performance with its Core i9-13900 CPU compared to a PC with a 3-year-old Core i9-10900 CPU.

Intel 13th Gen vPro CPUs offers lots of benefits for business PCs (Image credit: Intel)Intel’s 13th Gen vPro CPUs also include the Intel Connectivy Performance suite, which can optimize wireless performance and improve video and sound quality on a busy network. These CPUs also support the latest connectivity standards including Wi-Fi 6E and Thunderbolt 4.

Intel’s 13th gen vPro CPUs: Security and Management featuresIntel’s latest vPro CPUs offer better security features with silicon-based virtualization security on Windows 11. Moreover, security vendors are now enabled with Intel’s Threat Detection technology. Overall, Intel promises an attack surface reduced by 70% compared to 4-year-old Intel-based PCs.

On the management front, the Intel Endpoint Management Assistant console allows organizations to efficiently maintain PCs with Intel vPro CPUs from deployment to retirement. The new Intel Platform Service Record also introduces tamper-resistant ledgers for collecting system wear and tear data reliably.

Intel expects to see over 170 notebooks, desktops, and entry workstations use its latest 13th Gen vPro CPUs this year. Acer, ASUS, Dell, HP, Lenovo, Fujitsu, Panasonic, and Samsung will be among the first PC OEMs to use these new CPUs in their business PCs.

View Details

MC505088 – Updated March 22, 2023: Microsoft has updated the rollout timeline below. Thank you for your patience.

Microsoft is updating the recommended quarantine notification policy in the Standard and Strict preset security policies.

| Policy | Quarantine Policy | Standard | Strict | | --- | --- | --- | --- | | Anti-Spam | SpamQuarantineTag | DefaultFullAccessPolicy | DefaultFullAccessWithNotificationPolicy | | Anti-Spam | HighConfidenceSpamQuarantineTag | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy | | Anti-Spam | PhishQuarantineTag | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy | | Anti-Spam | HighConfidencePhishQuarantineTag | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy | | Anti-Spam | BulkQuarantineTag | DefaultFullAccessPolicy | DefaultFullAccessPolicy | | Anti-Phish | TargetedUserQuarantineTag | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy | | Anti-Phish | TargetedDomainQuarantineTag | DefaultFullAccessWithNotificationPolicy | DefaultFullAccessWithNotificationPolicy | | Anti-Phish | MailboxIntelligenceQuarantineTag | DefaultFullAccessPolicy | DefaultFullAccessPolicy | | Anti-malware | QuarantineTag | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy | | Safe Attachments | QuarantineTag | AdminOnlyAccessPolicy | AdminOnlyAccessPolicy |

With the DefaultFullAccessWithNotificationPolicy, Users will receive quarantine notifications for emails quarantined due to the corresponding threat policy.

Here is what the quarantine notification looks like:

View image in new tab

When this will happen:

Microsoft will begin rolling this out in mid-February 2023 and complete rolling out by mid-April 2023 (previously mid-March).

How this will affect your organization:

If your organization has enabled preset security policies, these will be automatically updated to include the quarantine notification policies (DefaultFullAccessWithNotificationPolicy) as listed in the above table for the standard and strict protection preset profiles.

What you need to do to prepare:

No action required. Please review the following links to learn more:

  • What are quarantine notifications? Quarantine notifications (end-user spam notifications) in Microsoft 365 – Office 365 | Microsoft Learn
  • Specific controls set in Preset Security Policies: Microsoft recommendations for EOP and Defender for Office 365 security settings – Office 365 | Microsoft Learn
  • Microsoft recommends enabling preset security policies for your organization: Steps to quickly set up the Standard or Strict preset security policies for Microsoft Defender for Office 365 – Office 365 | Microsoft Learn

View Details

The Microsoft Teams desktop client is about to get a new Files app on Windows and macOS. The new experience will replace the existing Files app, and it will make it easier to find and organize content across chats, channels, meetings, and other Microsoft 365 apps.

“Securely store, organize, and collaborate on all your files anytime, from anywhere and across all of your devices with the new files app experience in Teams. The new files app brings a modern experience to all of your content from your chats, channels or meetings including any location from OneDrive or SharePoint,” Microsoft explained in a message on the Microsoft 365 Admin Center.

Microsoft will introduce an updated menu bar that will help users quickly navigate to the desired content. The Home and My files tabs will let users view recently opened files and access personal documents stored on OneDrive. There is also a dedicated tab that should make it easier to find shared content. The new Files app will include a Quick Access pane to access channel files and pinned document libraries.

New Files app coming to Microsoft Teams in previewAccording to the Microsoft 365 roadmap, the new Files app is currently in development, and it’s expected to be released in preview later this month. Microsoft plans to make it generally available for all enterprise customers in mid-April.

Microsoft Teams is also getting a new green screen feature that will provide an improved virtual background effect in meetings. It will work on Intel-based Windows and macOS devices and lack support for Apple’s M1 and M2 chips.

View Details

Security researchers have found a new vulnerability in the Snipping Tool app available in Windows 11. The security flaw dubbed aCropalypse could allow threat actors to reveal sensitive information blurred or cropped out in screenshots.

Snipping Tool is a built-in screenshot-capturing tool that comes with the Windows operating system. In Windows 11, Microsoft introduced a new version that replaced the legacy Snipping Tool and Snip & Sketch apps. The new Snipping Tool app provides more features and options for taking and editing screenshots without using third-party software.

The aCropalypse vulnerability was first discovered by software engineers Chris Blume and David Buchannan in the Windows 11 Snipping Tool. As it turns out, the Snipping Tool doesn’t delete the original information from the edited file. Typically, the data is appended at the end of the edited screenshots in such a way that it remains invisible to Windows 11 users. However, any threat actor could exploit the vulnerability to retrieve the hidden information.

Microsoft to fix the Windows 11 Snipping Tool vulnerabilityFortunately, Microsoft’s engineers are investigating the security flaw and a fix should be available soon. “We are aware of these reports and are investigating. We will take action as needed to help keep customers protected,” a Microsoft spokesperson said in a statement to BleepingComputer.

In the meantime, it’s highly recommended to use alternative image editing tools (such as Adobe Photoshop) on Windows 11 PCs. It’s also important to implement access controls and encryption measures to block unauthorized access to sensitive information. It should significantly reduce the risk of data breaches that could potentially reveal personal data, including credit card information and phone numbers.

View Details

After years of development, Microsoft Loop is finally available in public preview starting today. But what is Loop for? And can it compete with productivity incumbent Notion? Let’s find out more.

What is Microsoft Loop?Microsoft Loop is a feature and app in Microsoft 365. Based on the Fluid Framework, Loop components can be created across Microsoft 365 apps, like Teams and Outlook. Loop components blur the lines between apps and content. For instance, if you want to insert a table into an email, instead of opening Excel, creating a table, and then pasting it into your email, you can create a table using the Loop Table component right in Outlook.

That might not sound very exciting on its own. But Loop components can be edited after the fact by you or team members you choose to share the component with. And unlike content that is simply copied and pasted between apps, Loop components support co-authoring.

Jumpstart a Microsoft Loop workspaceComponents are saved separately as a .fluid file (soon to be renamed .loop) and they can also be inserted into other documents. Loop components are portable pieces of content that stay synchronized across all the places that they have been shared. In addition to sharing individual components, you can share whole pages as a link or live page.

Currently Microsoft Loop supports the following components:

  • Bulleted list
  • Checklist
  • Numbered list
  • Paragraph
  • Table
  • Task list

Which Microsoft 365 apps support Loop components?Loop components are currently supported across these Microsoft 365 apps:

  • Microsoft Loop
  • Teams (chat only but coming soon to channels)
  • Outlook
  • Whiteboard
  • Word for the Web

Loop components are stored in the creator’s OneDrive. So, in Teams chat, only users that have access to OneDrive in the Microsoft 365 tenant can create Loop components.

But what about the Microsoft Loop app?The Microsoft Loop app lets you create shared workspaces that contain pages where you can create or collect existing Loop components in one place. So, instead of switching between different apps to view, create, and collaborate with team members, the Microsoft Loop app provides a single workspace where you can work on all the components associated with your project.

The app goes further by allowing you to collate documents across Microsoft 365 that are related to your project. To help you get started, you can enter a few keywords and have Loop suggest which documents might be connected to your project so that you can add them to your new workspace.

Loop does the searching for you to start a workspaceWorkspaces and pages are flexible in that you can organize documents and components in the way you want. You can comment and react, just like you might in a document or Teams. Microsoft describes Loop pages as ‘flexible canvases’. The app also supports notifications you can keep pace with changes.

Loop progress tracker, labels, and nudgesIs Microsoft 365 Copilot integrated with Loop?Microsoft 365 Copilot, the artificial intelligence system Microsoft is building into its productivity apps, will be fully integrated into the Loop app to help you generate content. Copilot for Loop is currently in private preview but when it becomes available, will allow you to create, brainstorm, blueprint, and describe along with your teammates. You or your coworkers will be able to go back to earlier prompts and modify them to refine the output.

Microsoft 365 Copilot in LoopUnderstand essential information quickly with summarizationNot available in the current public preview, Microsoft will be rolling out summarization over the next few months. The summarization pane allows users to quickly establish what’s important on a Loop page and understand the context of documents linked to the workspace. It will be possible to edit summaries so that you can correct mistakes and add more context.

SummarizationNotion vs Microsoft LoopClearly the Microsoft Loop app is inspired by Notion. Even down to typing ‘/’ to add a new component in the Loop app. Just like in Loop, you can create a Notion workspace where your team will work on a project. The workspace can be used to store all the documentation related to the project. And team members can update the documents in real-time together.

Insert menuNotion is often used by small and medium-sized organizations as a self-contained project management and collaboration solution. It’s a mature product that has carved out a place in the market with a strong, even devoted following.

Notion blocks vs Microsoft Loop componentsLoop components, while similar to Notion blocks, are limited at this stage. Notion blocks support more sophisticated content like databases (similar to Microsoft Lists), and all the different views that go with a database like table, board, gallery, calendar, and timeline views.

Loop Microsoft 365 integrationThe big selling point for Microsoft Loop is its integration with Microsoft 365. Overall, Notion isn’t as feature rich as Microsoft 365. And integrating Loop with all your documents, email, and collaboration and chat in Teams, means that Loop meets you where you are likely already at as an organization.

Is there a Microsoft Loop mobile app?The Microsoft Loop mobile app lets you access project content on your phone. You can easily move around different workspaces and pages. Or add ideas by typing text or adding photos to a workspace.

Loop mobile appCompliance, eDiscovery, and sharing Microsoft Loop componentsContent you create in the Microsoft Loop app can be quickly turned into Loop components that you can share with specific people outside your team. For example, there might be information you want to share with people who don’t have access to your Loop workspace. So, you can turn content into a Loop component and share it with certain people.

Loop helps you stay in control by quickly showing you were components have been shared and who has access. And access permissions are set on Loop components just like on any other document in Microsoft 365.

Loop control (where a component has been shared and people it has been shared with)As Loop components are stored in OneDrive and can be searched like any other Microsoft 365 document, Loop components can be searched and collected for eDiscovery purposes in eDiscovery Standard and Premium. Components are discoverable and have eDiscovery workflow support in the Microsoft Purview tool providing they stay within Microsoft 365 online storage. Microsoft says that it is working on a third-party export API for Loop components.

Access policy for Microsoft Loop app and componentsIT admins can control who has access to Microsoft Loop components and where, and the Loop app. Access to Loop components are managed using Cloud Policy and the SharePoint PowerShell command. You can configure Loop Cloud Policy for your Microsoft 365 tenant using the following settings:

  • Create and view Loop files in Microsoft apps that support Loop
  • Create and view Loop files in Outlook
  • Create and view Loop files in Loop

Before applying the settings, you must create a security group that contains the users to which the policy will apply. You can find more information about how to control access to Microsoft Loop components on Microsoft’s website.

Microsoft Loop isn’t as powerful as Notion, yet…Microsoft Loop can’t match Notion just yet. The missing piece is Notion databases. Microsoft Lists are like Notion databases. But at least right now, Microsoft hasn’t enabled Lists as a Loop component. And it’s not clear whether that’s on the roadmap.

Nevertheless, after years of waiting, Loop is getting off to a promising start. Albeit one that doesn’t include what I believe is the killer feature of Notion: databases. But Microsoft Loop, and its integration with Microsoft 365, is a selling point that will enamor it to organizations already invested in Microsoft 365.

View Details

Microsoft has announced that it’s adding OpenAI’s GPT-4 to its Azure OpenAI Service. The new integration will enable organizations to utilize the large language model for building AI applications and services.

Microsoft launched the Azure OpenAI service back in January 2023. It’s designed to provide access to OpenAI’s powerful language models, such as GPT-3, Codex, and DALL-E. The models can be used to build applications that perform specific tasks, including text summarization, content generation, semantic search, and more.

GPT-4 is a large multimodal model that has been improved over its predecessor to accept both text and image-based inputs. It can handle more than 25,000 words and understand content in multiple languages. The GPT-4 model provides more accurate responses that are natural and contextual.

“GPT-4 has the potential to take this experience to a whole new level using its broader knowledge, problem-solving abilities, and domain expertise. With GPT-4 in Azure OpenAI Service, businesses can streamline communications internally as well as with their customers, using a model with additional safety investments to reduce harmful outputs,” Microsoft explained.

How to get started with GPT-4 in Azure OpenAI ServiceMicrosoft highlights that some companies are already using the Azure OpenAI GPT-4 model to improve their apps and services. For instance, Coursera has used it to create personalized learning experiences for end users. It helped Epic Healthcare’s physicians and nurses to investigate medical data.

Microsoft says that GPT-4 support is currently available in preview, and existing Azure OpenAI customers can signup to join the waitlist on this page. The billing for GPT-4 usage will begin on April 1, 2023, with pricing based on per 1,000 tokens used in prompts and query completions. Microsoft is holding an Azure AI Bootcamp event from March 28 to 30 for developers and data scientists interested to learn more about Azure AI services.

View Details

Failover clustering in Windows Server and Azure Stack HCI can help to reduce disruptions in service within an organization. In this article, I’m going to explain why you need to have a Windows Server Active Directory domain controller outside of your Azure Stack HCI cluster. I will also detail how to deploy this domain controller in an edge scenario.

Why do you need a domain controller outside of your Azure Stack HCI cluster?If you’re using Azure Stack HCI and cluster accounts in Active Directory, there is still a legacy requirement for organizations to have DNS and sometimes Active Directory available to start the failover cluster service. Active Directory computer accounts are later used to manage cluster ownership and permissions.

Without the required Active Directory computer accounts, your cluster will not start. If you’re using Azure Stack HCI, that’s a hard condition as storage with the Storage Spaces Direct feature heavily depends on the failover cluster service to operate.

Without Storage Spaces Direct running, Hyper-V will not be able to start any virtual machine. So, if your only domain controllers are deployed on the Azure Stack HCI clustered stage, you have a chicken-and-egg problem: You cannot start the clustered storage service to start your domain controllers because they are stored on storage that cannot be used.

You may want to start or restart a complete cluster after deployment for a couple of reasons, such as the maintenance of power grids or power outages forcing you to shut down your workloads. In any case, you should prepare for this scenario.

Setting up a domain controller and DNS server outside of your Azure Stack HCI clusterThe only way to solve the aforementioned issue is to set up a domain controller and DNS server outside of your Azure Stack HCI Cluster.

Setting up a domain controller outside of your Azure Stack HCI cluster (Image credit: Petri/Flo Fox)There are several ways to put a domain controller outside your Azure Stack HCI cluster. The most common practice is to have a domain controller on another server. In that case, the server can be virtualized or physically deployed.

For edge or limited-budget scenarios, putting additional systems into a location is often not an option. Therefore, there is another way to deploy a domain controller, and the only requirement is to have a Virtual Private Network connection to a remote location nearby. The remote location could be another office, data center, or cloud service such as Microsoft Azure where a domain controller is available.

You can have your domain controller set up in a remote location and connected via VPN (Image credit: Petri/Flo Fox)After your cluster is kickstarted, you can also start virtual domain controllers within your Azure Stack HCI cluster to support your users.

You can set virtual domain controllers within your Azure Stack HCI cluster (Image credit: Petri/Flo Fox)With these external domain controllers set up, you should be able to restart your Azure Stack HCI clusters after any disaster or planned shutdown.

Closing NoteAs I explained in this article, you cannot start Windows Server or an Azure Stack HCI cluster without having Windows Server Active Directory deployed first. In an enterprise scenario, you also need to be a supported solution. Depending on your environment, it may be a good choice to have a remote domain controller to kickstart your Azure Stack HCI cluster. That can also help to reduce costs and overload in a branch or edge scenario.

View Details

Microsoft announced some changes yesterday regarding its release schedule for Windows monthly updates. While nothing changes for the “Patch Tuesday” updates released on the second Tuesday of each month, the company announced a new release window for optional non-security preview patches released later in the month.

Starting next month, Microsoft will now target the fourth week of the month to release these optional non-security preview patches for Windows 11 and Windows 10. These optional patches used to be called either “C” or “D” releases, and they include all fixes coming in the following monthly security update release. In some cases, these optional non-security preview releases also include new Windows features, as was the case with File Explorer tabs or Search highlights.

Why Microsoft is changing its release schedule for optional non-security updates“We have found this to be the optimal time for us to publish and for you to consume these updates,” Microsoft said about the new release schedule on the Windows IT Pro blog. “That’s two weeks after your latest monthly security update and about two weeks before you’ll see these features become part of the next mandatory cumulative update. We’re excited for this improvement as it is meant to optimize the validation of payloads, improve consistency, and enhance the predictability of your testing, update, and upgrade experience.”

In practice, this isn’t going to be much of a change. In recent months, these optional Windows patches have been released either in the third week of the month (as was the case in January), or the fourth one (as was the case in February). Anyway, going forward, Microsoft will now make things more predictable for Windows users and IT Pros as these optional updates will now be released in the fourth week of the month.

No more optional updates for Windows 10 versions 20H2 and 21H2In addition to this new release schedule for optional non-security preview updates, Microsoft also announced yesterday that Windows 10 versions 20H2 and 21H2 will no longer receive such updates starting next month. While monthly security (Patch Tuesday) updates will continue to be released as expected, Windows 10 version 22H2 will now be the only version of the OS to receive optional updates at the end of every month.

The March 2023 non-security preview patch released yesterday for Windows 10 versions 20H2, 21H2, and 22H2 includes several bug fixes. It also addresses an issue causing USB printers to be classified as multimedia devices even though they are not. The preview updates for Windows 11 versions 21H2 and 22H2 should be available very soon.

View Details

Microsoft Teams is set to introduce a new green screen feature on Windows and macOS. The company has announced on the Microsoft 365 Admin center that the green screen technology will allow desktop users to replace their backgrounds with custom images in Teams meetings.

“Green screen improves the sharpness and definition of the virtual background effect around your face, head, ears, and hair. It also allows you to show a prop or other object in your hand to be more visible to other participants in a call. The virtual background with a green screen provides the best virtual background effect, consuming fewer system resources, allowing your Teams to run smoother,” Microsoft explained.

To get started, participants will first need to enable the feature in Settings and place a solid-colored screen or a clean background wall behind them. Users will be able to select a specific background effect and a backdrop color to experience better video quality.

Microsoft Teams green screen technology won’t support Mac M1/M2 devicesMicrosoft notes that the green screen feature is compatible with existing Teams features such as background effects, Presenter modes, and PowerPoint Live Standout. It will automatically disable Together Mode and background blur in Teams meetings. Keep in mind that the feature will only support Windows and macOS devices with Intel processors. However, it won’t be available for Mac machines with M1 and M2 chips.

Microsoft plans to release the green screen feature for Teams meetings in public preview later this month. The company plans to make it generally available for all commercial and government tenants in late April.

Overall, the green screen feature would be a welcome addition that should help desktop users to personalize their meeting experience without using third-party plug-ins. Let us know in the comments below if you think that the feature will help to make meetings more professional and engaging for virtual attendees.

View Details

Microsoft has announced that its Microsoft Defender for IoT solution is now generally available for enterprise customers. The new cloud-powered solution helps IT Pros manage network assets, monitor security threats, and control risks across their organization.

“With Microsoft Defender for IoT, you can achieve faster time-to-value, improve agility and scalability, increase visibility, and strengthen the resiliency of your network and infrastructure without making significant changes. The Defender for IoT cloud is designed to augment your on-premises processing power while providing a source of centralized management for global security teams—raising the bar for OT defense,” Microsoft explained.

Microsoft explained that cloud-powered IoT and OT security tools provide several advantages over traditional solutions. It supports the end-to-end discovery of assets and reduces the time required for detecting and responding to security threats. The solution utilizes AI to detect threats in real time, provide recommendations and safeguard against known and unknown security threats.

Microsoft Defender for IoT allows customers to create and manage tailored compliance reports. The service also provides cloud-to-cloud integrations that make it easier for users to access data from different sources.

Microsoft Defender for IoT provides simplified integration for end-to-end protectionMicrosoft has introduced Device inventory support that lets IT admins manage OT devices via the Microsoft Azure Portal. It provides a comprehensive view of assets to proactively mitigate security vulnerabilities.

Device inventoryMicrosoft Defender for IoT works in conjunction with Microsoft Sentinel to deliver security information and Event Management (SIEM) for OT and IT environments. The solution also shares threat data with Microsoft Defender for Cloud, Microsoft 365 Defender, ServiceNow, IBM QRadar, Splunk, and other third-party products.

As businesses increasingly integrate existing OT platforms with their broader IT infrastructure, the importance of safeguarding enterprise networks against emerging cyber threats continues to grow. Security tools like Microsoft Defender for IoT can provide IT admins with valuable insights and early detection capabilities to address potential issues within their networks.

View Details

Microsoft will start offering on-prem Unified Update Platform (UUP) updates to Windows 11 PCs on March 28. The company is recommending organizations to prepare for a one-time 10GB download to receive future updates via UUP.

Microsoft’s Unified Update Platform (UUP) technology is designed to reduce the size of Windows updates. The on-prem UUP interoperates with management tools such as Windows Service Update Services (WSUS) and Microsoft Configuration Manager.

Microsoft touts that the servicing change should bring several benefits for organizations managing Windows 11 version 22H2. The UUP mechanism promises 30 percent smaller and faster client update downloads for enterprises. The on-prem UUP also integrates cumulative updates with feature updates. It should enable organizations to get both in a single reboot.

Microsoft highlighted that Features on Demand and Language Packs will be retained during feature updates. Moreover, the operating system will be automatically healed during the update process without any need for manual intervention.

Microsoft’s on-premises Unified Update Platform (UUP) to hit GA on March 28On March 28, Microsoft will release a security update (KB5023706) to enable future UUP updates on all eligible Windows 11 devices. However, this update will not be available for users who have already installed the KB5023706 update released on March 14.

“To summarize, UUP is the future of Windows 11, version 22H2 updates. If your WSUS or Microsoft Configuration Manager is configured to sync, your organization will start syncing the extra 10GB download after March 28th. It’s just a one-time download to distribution points. Thereafter, all Windows 11, version 22H2 updates will be UUP on-premises updates, and downloads to distribution points will be the same size as pre-UUP updates,” Microsoft explained.

Microsoft advises administrators to use a supported version of Windows Service Update Services (WSUS) and configure their firewall to receive WSUS updates. Moreover, IT Pros should also ensure that they have the correct MIME type configuration, and you can check out the FAQs document for more details.

View Details

The March Patch Tuesday update for Windows 11 version 22H2 may be causing some new SSD performance issues, according to various user reports. This is the “Moment 2” update that introduced various new features to Windows 11 including a search box in the taskbar as well as AI-powered recommendations in the Start Menu.

Since the release of Windows 11 version 22H2 last fall, Microsoft has acknowledged a known issue causing slowdowns when copying files on devices running the latest version of Windows 11. Microsoft is still working on a fix for this bug that affects both local copies and network share via the SMB protocol.

However, the SSD performance issues reported by users since the release of this month’s Patch Tuesday update appear to be unrelated to this already-known bug.

Windows 11 users point out SSD speeds and longer boot times after installing this month’s Patch TuesdayIn the Reddit thread related to this month’s Patch Tuesday updates, the top comment from user mesp1 mentions an SSD performance degradation issue after installing this month’s KB5017389 patch for Windows 11 version 22H2.

“Tanked my SSD nvme reading and writing speeds, like A LOT. Went from 7000 to 3000, sometimes 1000 using the balance energy profile in my Legion 5 2021.” The Reddit user also mentioned that his SSD speeds went back to normal after uninstalling the update.

In the same Reddit thread, another popular comment from user sebascq also pointed out a similar issue on their device after installing this month’s Patch Tuesday update.

“I updated my laptop to the 22H2 SO 22621.1344 and noticed that the boot up time increased by a lot it went from around 14 seconds to 31 seconds which is weird because I have 0 programs or apps on startup or background when I boot up the pc with the exception of Nvidia Config,” the post reads.

As of this writing, it appears that Microsoft has yet to comment on this new issue affecting SSD performance on Windows 11 version 22H2. It’s not clear if this is a widespread problem, but if SSD read and write speeds are really critical to your workload, you may want to hold on before installing this update.

View Details

MC530354 – Microsoft is reaching out to inform you that it’s disabling the Monitor for model-driven apps while the company works on making improvements. You may continue to use Monitor for canvas apps.

When will this change happen?
This change will go into effect following the usual deployment schedule. Microsoft will notify you when Monitor is available again for model-driven apps.

If you require assistance, please contact Microsoft Support.

View Details

Microsoft has recently announced the general availability of Amazon Linux 2023. The latest cloud-optimized Linux distribution is designed to improve security and delivers a predictable lifecycle as well as deterministic updates.

Amazon Linux 2023 introduces new pre-configured security policies to help customers adhere to industry standards. IT administrators can configure these policies at launch or runtime for end users in their organizations. Amazon has also turned on several Linux kernel hardening features by default to boost security.

Additionally, Amazon has announced its plans to release major updates to its operating system every two years. The bi-annual updates should include security and performance enhancements for customers. The company also expects to release significant changes to the kernel, OpenSSL, toolchain, GLib C, and other utilities and system libraries.

Amazon has also promised to release quarterly updates with new capabilities, security updates, and bug fixes. The quarterly updates might bring software packages like Docker/Ansible and language runtimes such as Java or Python.

“Each major version, including 2023, will come with five years of long-term support. After the initial two-year period, each major version enters a three-year maintenance period. During the maintenance period, it will continue to receive security bug fixes and patches as soon as they are available. This support commitment gives you the stability you need to manage long project lifecycles,” Amazon explained.

The lifecycle of Amazon Linux distributionsLastly, Amazon Linux 2023 uses versioned repositories to provide deterministic updates. The company has used Fedora’s dnf instead of yum to implement the change. It should make it easier for IT admins to ensure that the package versions are consistent across all systems.

How to get started with Amazon Linux 2023To get started with Amazon Linux 2023, customers can use the AWS Management Console, AWS Command Line Interface (AWS CLI), the EC2 run-instances API, and any of the four Amazon Linux 2023 AMIs. Amazon provides support for x86_64 and ARM machine architectures as well as standard and minimal sizes. The standard version comes with the basic applications and Amazon Linux 2023 AMIs include the basic utilities and tools.

View Details

Microsoft released Edge version 111 on Windows, macOS, and Linux last week, and this update brought a noticeable UI change: There’s now a big Bing button at the right side of the Edge toolbar, which integrates the new Edge Copilot experience that leverages Microsoft’s Bing chatbot powered by OpenAI’s ChatGPT.

Clicking the Bing icon in the toolbar opens the new Edge Copilot experience within the Edge sidebar (if users have signed up for the Bing preview). From there, users can ask questions to the Bing Chatbot or use its “generative AI” capabilities to create content about any topic.

The new Edge Copilot experience in the sidebar (Image credit: Petri/Laurent Giret)The “Insights” tab of the Edge Copilot experience can also identify relevant information about the web page that’s currently open. At the bottom, users can also get more information about the website including traffic information.

Clicking on the Bing icon makes the Edge sidebar and the Edge Copilot experience stick, but you can also just hover your mouse over the Bing icon to make the sidebar appear. This new auto-hide feature is nice, though the new Bing icon may look slightly intrusive for Edge users.

IT admins can still customize the Edge sidebar experienceAs of today, IT Pros can use the HubsSidebarEnabled policy to allow or block the sidebar for Edge users. There are 3 options with this policy:

  • Not configured: Edge users will have access to the Sidebar and Edge Copilot experience and be able to always show the sidebar or hide it automatically.
  • Enabled: With this option, the sidebar will appear at all times in Edge, and clicking the Bing icon will just open the Edge Copilot experience.
  • Disabled: This option will make the Sidebar and the Edge Copilot experience inaccessible for Edge users.

Microsoft noted that it’s currently not possible to enable the Edge sidebar while having the new Copilot experience disabled. However, the company said that additional customization options for the Bing button in the Edge toolbar are coming.

New policy to enable the built-in Adobe Acrobat PDF readerIn a new update for Microsoft Edge 111 released on March 15, Microsoft also made two new policies available for controlling the built-in PDF reader in Edge. The NewPDFReaderEnabled enables the new Adobe Acrobat PDF engine that Microsoft announced last month. This new PDG engine will provide higher fidelity, improved performance, and more accessibility features for Edge users.

Lastly, IT pros can use the ShowAcrobatSubscriptionButton policy to show a button in this new built-in PDF reader to allow users to sign up for an Adobe Acrobat subscription. Microsoft plans to roll out this Adobe Acrobat PDF engine to all organizations starting in September 2023, and the legacy PDF engine in Microsoft Edge will be retired in March 2024.

View Details

Microsoft Lists is the evolution of the SharePoint List feature. Several years ago, the Microsoft brain trust set out to make this ultra-powerful tool more accessible to the masses. By removing ‘SharePoint’ from the marketing pages, and making it ‘an app’, they succeeded in surprisingly productive ways. In this article, I will explain what is Microsoft Lists and give you an overview of everything you can do with this new Microsoft 365 app.

What is Microsoft Lists?Microsoft Lists is a free Microsoft 365 app that helps you organize your workflows and track information across your enterprise. Lists are flexible, simple, and smart, so you are always in the know of what matters most to your team.

Using the robust feature set and templates available, you can track issues, contacts, assets, inventory, and more using customizable views and intelligent rules to alert you to changing and dynamic environments. Want to get an email when someone creates a new desktop asset? Piece of cake!

How to access Microsoft ListsIf you’ve read my other articles here on Petri demonstrating some of the main apps in Microsoft 365, you’ll know that the access methods for many of them are similar – making it easy for your users to utilize them with a minimal learning curve.

The Microsoft 365 App LauncherLet’s start at the beginning. We can log into office.com (or microsoft365.com) and access the App Launcher.

Using the App Launcher in Microsoft 365 to find Microsoft Lists (Image credit: Petri/Michael Reinders)We can click on Lists if it’s been pinned or accessed recently. If not, click All apps and find it in the entire listing.

You can see below the homepage for Microsoft Lists which allows us to open existing lists, favorite a list to keep it pertinent, and click the ‘+ New list‘ button at the top to create a new list.

Our Microsoft Lists homepage (Image credit: Petri/Michael Reinders)Installing Microsoft Lists as an appWhen you first launch the Microsoft Lists website, you’ll probably see a fleeting tip to download the latest desktop app. If/when you see that, go ahead and download and install it. If you missed it, and you’re using Microsoft Edge, you can install the Progressive Web App by clicking the ‘App available. Install Microsoft Lists’ button in the address bar.

Adding Microsoft Lists as a Progressive Web App in Microsoft Edge (Image credit: Petri/Michael Reinders)Now, we essentially have our ‘desktop’ app that can be pinned to the Windows taskbar. Most important, we can launch it directly from the taskbar, the Start Menu, etc.

The Microsoft Lists mobile appLastly, there is a Microsoft Lists app for your mobile device in both the iOS and Android app stores. You can get the iPhone/iPad app with this link. You can get the Android app with this link!

Let’s now go through some of the core features of Microsoft Lists and I’ll be demonstrating them for you.

What can you do with Microsoft Lists?When Microsoft ventured to evolve and ‘reboot’ SharePoint Lists, they knew they needed the existing core feature set in addition to collaboration enhancements. This is apparent from the various methods you can use to create lists, edit them, collaborate with them, and share them across the Microsoft 365 ecosystem including the OneDrive for Business service I recently wrote about.

The main advantage of using Microsoft Lists instead of SharePoint Lists is the ease of use and accessibility of the app. Instead of needing to create a SharePoint site collection and manage that, you can free yourself of all that rigamarole and use the ‘Lists’ feature/app all on its own. Plus, it’s free!

Many companies struggle with the onboarding (and offboarding) of employees. Microsoft Lists has employee onboarding as the basis for one of their templates. Have no fear – when a new employee comes on board, you can keep track of everything. Human resources will thank you!

Create a list from a templateThanks to a wonderful set of ready-made templates, you can get a new List made in no time. Let’s create a new Asset tracking list to keep track of some assets.

  • First, log into office.com with your Microsoft 365 credentials.
  • Then, click the App Launcher in the upper-left corner, click All apps, then click Lists. (You can optionally click the three vertical dots when you hover over Lists and select Pin to launcher.)

Accessing the Lists app from office.com (Image credit: Petri/Michael Reinders) Here we are at the homepage. Let’s start by clicking the ‘+ New list*‘ button at the top.

The Microsoft Lists homepage (Image credit: Petri/Michael Reinders)* You have several options here including starting from scratch, creating a list based on an existing list, importing from Excel or CSV, or using a template.

The plethora of options to create a new List includes wonderful templates! (Image credit: Petri/Michael Reinders)Before we proceed, let me explain the advantages of using Microsoft Lists vs. Microsoft Excel. The primary advantage here is that you can be unburdened by the Excel learning curve and focus solely on your list and data.

Plus, once you have your data in Microsoft Lists, you have a tool that makes it easier to add visual cues and highlights to your data. With the ready-made templates in Microsoft Lists, you can present and sell an idea/story to your supervisor or other colleagues in decision-making roles.

Let’s get back to creating our first list:

  • Let’s choose the ‘Asset manager’ template.

Choosing the Asset Manager template (Image credit: Petri/Michael Reinders) Here we can name our list, enter a Description, choose a color for our List (icon), and choose where to save it. We can either save it to our own private list repository or a Teams channel. * Feel free to embellish your needs and click Create*.

We already created a new Asset managing List! (Image credit: Petri/Michael Reinders) As the courteous assistant says, let’s click the ‘+ New*‘ button in the upper-left corner to create an asset!

Adding an asset to our List… (Image credit: Petri/Michael Reinders)By now, you’ve probably noticed the similarities to working in a SharePoint List: That’s because that’s what we’re using. It’s just been given some fit-and-finish work to make accessing this powerful tool a little easier. Well, for that matter, a LOT easier.

  • Let me go through and enter information in the various fields and click Save.

We’ve already created two assets! (Image credit: Petri/Michael Reinders)As you can see, this is pretty easy. And remember, if you happen to have an Excel file with all this info pre-populated, it is a breeze to import it into Lists. You can have your asset list in an easy-to-read system and share it effortlessly with colleagues.

Keep your team in sync in Microsoft TeamsBecause of the beautiful synergy and interoperability across Microsoft 365, we can use Microsoft Teams to access our lists.

  • Once you’re in Microsoft Teams, click the Apps button on the left navigation/app bar and search for ‘Lists‘.

Using Microsoft Teams as our ‘Lists’ tool (Image credit: Petri/Michael Reinders) Select Lists and then click the ‘Add to a team*‘ button.

Here we can add the Lists infrastructure right into a team channel (Image credit: Petri/Michael Reinders) I will choose the Design channel in my ‘Mark 8 Project’ team and click Set up a tab. Next, I will click Save. * After adding the Lists app to the channel, we can choose ‘Create a list‘ and select the ‘Issue tracker*‘ template.

Adding the Lists app to the navigation bar on top (Image credit: Petri/Michael Reinders)* I have filled out the Title and Description and added an icon.

Creating a new Issue tracker List in our Teams channel! (Image credit: Petri/Michael Reinders)* Now, as you can see, we have a convenient tab right in the Team channel to keep track of all issues with the overall ‘Design’ of our project/team!

Our new Design Issues/Tracker list, is right in Teams (Image credit: Petri/Michael Reinders)Share your List with another colleagueAnother core feature in Microsoft Lists is the ability to share your list, like other items in Microsoft 365, with other colleagues.

  • Back in my ‘Mark 8 – Assets List’, I can click the Share item on the top toolbar.
  • Now, all I need to do is type in Grady’s name, add a quick note, then click the Send button to have an email sent to them.

Sharing our List with another colleague – Grady (Image credit: Petri/Michael Reinders)Let’s log in as Grady and access our new list. On Grady’s Microsoft 365 homepage, we can see in the ‘Quick access‘ section below the fact that I shared my list with him. Let’s click on it!

Logging into office.com as Grady – there’s our shared List! (Image credit: Petri/Michael Reinders)There it is! As you can see, Grady also has permission to make changes and additions to the list. And, a sneak peek at the next section – he can access it from anywhere!

Grady now has full access to our List! (Image credit: Petri/Michael Reinders)I mentioned this earlier, but I wanted to point out the notifications you can set up. When working on a list, you can click the ‘…’ on the toolbar, and click Alert me.

Setting up Alerts on changes to your Lists (Image credit: Petri/Michael Reinders)This allows you to be emailed (or texted) when specific changes are made to your list. There is a good deal of granularity here.

ConclusionA welcome addition to the Microsoft 365 feature list, Microsoft Lists can help many users organize various types of data. You can start quickly with ready-made templates, and you can also easily access recent and favorite lists. Moreover, you can also track and manage lists wherever you’re working, even on your smartphone! Being mobile and agile always assists your users in being more productive and efficient.

If you have any comments or questions, please let me know in the Comments section below. Thank you for reading!

View Details

This Week in IT, Google one ups Microsoft ahead of its ‘Reinventing Productivity with A.I.’ event but it still doesn’t have a product to show. While Microsoft already has ChatGPT-like features integrated into Bing, Edge, and Windows 11.

View Details

Microsoft has released new PowerShell scripts to address a BitLocker security vulnerability on Windows PCs. The PowerShell scripts are designed to automate the Windows Recovery Environment (WinRE) update process on Windows 11 and Windows 10.

BitLocker is a built-in security feature that helps users to protect data stored on their computers from unauthorized access. Once enabled, the feature requires a password or a smartcard to decrypt the entire disk or individual files or folders. BitLocker protection is particularly useful to protect sensitive data on portable devices like USB drives and Windows laptops.

Microsoft confirmed the BitLocker vulnerability (CVE-2022-41099) back in November 2022. It enables threat actors to bypass the BitLocker encryption protection to access sensitive information on vulnerable Windows devices. Microsoft released a security update to address the security flaw in January this year. However, IT admins had to manually install the update into the Windows Recovery Environment.

How to use the PowerShell scripts to address the BitLocker bypass vulnerabilityMicrosoft explained that the new PowerShell scripts should help administrators to automatically update WinRE images on both operating systems. The company says that IT Pros will need to run these scripts with administrative privileges to protect affected devices against cyberattacks.

Microsoft recommends enterprise admins to install the PatchWinREScript_2004plus.ps1 script on Windows 11 and Windows 10 version 2004 and newer. The company emphasized that it’s comparatively more robust than the second script.

Additionally, the PatchWinREScript_General.ps1 is designed mainly for Windows 10 version 1909 or earlier, but it can also run on Windows 11. If you’re interested, you can check out this support page to learn more about using the PowerShell scripts to update WinRE images on Windows PCs.

View Details

Last month, Google unveiled some important pricing changes for Google Workspace customers. The company announced this week that it’s increasing the monthly cost of several Google Workspace offerings this week.

Steve Holt, Vice President for Google Workspace, penned a lengthy blog post to justify the price hike impacting multiple Workspace tiers. The pricing update follows the newly announced generative AI features coming to Gmail, Google Docs, Sheets, and Slides.

“The updates range from improvements to our world-class security and reliability that are required by our largest customers, to tools that increase the simplicity and helpfulness desired by smaller teams. The power of our apps running in the cloud is that these enhancements are immediately available to all our customers, increasing the value we deliver,” Steve Holt explained.

Here are all the details about the pricing changes that will impact three main business editions of Google Workspace:

  • Business Starter plans are going from $6 per account per month to $7.2
  • Business Standard plans are going from $12 to $14.40
  • Business Plus plans are going from $18 to $21.60

Google Workspace launches annual plansGoogle has (re)launched an annual billing option that will let customers commit to a year of Workspace at a fixed cost. Previously, organizations had to call a corporate sales representative to purchase an annual plan. However, IT admins can now sign up for an annual plan directly online. Google says that existing flexible plan customers can easily switch to the annual plan through the Admin Console.

Additionally, Google Workspace Enterprise Standard is getting a price hike this month. Unfortunately, the company did not disclose the new pricing, and customers will need to reach out to the sales department directly to get more information.

Google plans to begin rolling out the pricing changes for existing customers next month and will continue through 2024. The price hike will not impact organizations with less than 10 user licenses until January 2024. Google plans to provide advance notice of at least 30 days before making any changes to the pricing.

View Details

In this post, I want to discuss a topic that is getting an increasing amount of attention in Europe: the impact of cloud computing on the energy sector. This was already a concern before the current energy crisis started, but the power consumption of cloud computing is rarely out of the news now.

First of all, my knowledge of this topic is skewed toward Microsoft’s data centers in Ireland. However, the issue is not restricted to Ireland or Microsoft; everything I’ll be discussing here includes all of the big cloud service providers and their data centers around the world.

The core issue: The power consumption of data centersCloud computing requires a lot of power. Did you know that the power consumption of data centers is measured by megawatts? A cloud data center is even bigger and denser, driving huge amounts of storage and power-intensive hardware such as GPUs which are required for graphics, machine learning, high-performance computing, and simulation workloads.

According to Ireland’s Central Statistics Office, data center power consumption in the country is greater than the one from the entirety of rural Ireland. Rural Ireland is approximately 1.8 million people or approximately 35% of the population of the country. Imagine that one industry consumes more power than 35% of the population of an entire country!

The cloud computing industry pays its wayIs that really a problem if the cloud computing industry is paying its fair share of taxation to cover the impact of energy consumption? Unfortunately, this is a rather complex equation.

According to a recent report from consulting firm Baringa, the information and communications technology industry is responsible for 15% of the economy in Ireland. Of that 15%, how much of it is sourced from the cloud?

The Irish subsidiary of Microsoft recorded a profit of €2.6 billion in its 2021 fiscal year. Meanwhile, a recent study from the Center for Corporate Tax Accountability and Research revealed that Microsoft is paying no direct taxes in Ireland by claiming a tax residency in Bermuda.

Some will argue that these data centers announce huge employee counts and those employees are paying taxes – so maybe the big 3 clouds (Microsoft Azure, Amazon Web Services, and Google Cloud Platform) are paying indirect taxes?

Microsoft, Amazon, and Google keep building more and more data centersWhen the construction of a new data center build is announced, it usually results in the creation of hundreds of new jobs. Those jobs are short-term contract workers hired to build the data center. However, most of the long-term local employees are lower-paid security and operator staff, while most of the high-skilled workers are already employed in a few globally dispersed locations.

Ultimately, all these data centers need to operate is people to guard the doors and swap out any failed disks. If you want evidence of that, go ahead and use the satellite view in your favorite mapping tool and search for the data centers of the big 3. You will not see many car parking spaces – and the locations are remote enough to preclude the use of public transport.

Anyway, Microsoft (and probably the other big two cloud providers) are using 35% of the power from Ireland while paying no taxes. Is that really fair and sustainable?

The electricity is paid forLet’s say that company X consumes Y megawatts from the grid. All is legal and cool if they pay for those Y megawatts.

As winter descended upon us last year, the company that runs the national grid in Ireland was constantly in the news, warning us that blackouts were a possibility because of the increased power consumption during that time of year. Recently, we have been told to avoid using electricity between 5 PM and 8 PM… which is when you usually cook dinner or do your laundry after a day of work.

Microsoft has since realized that it cannot get enough electricity from Ireland’s grid. The Business Post reported in December that Microsoft was planning to build a €900 million diesel-powered power station in Dublin producing 170 megawatts to power their “North Europe” region of data centers for Azure, Microsoft 365, and other cloud services.

The impact of cloud computing on power consumption in Ireland has led Eirgrid, the national electric power transmission operator to issue a moratorium on data center builds in the greater Dublin region until at least 2028. However, 21 new data centers are already planned outside the city according to The Business Post.

The impact of renewable energyThis isn’t the place to discuss whether climate change is artificial, natural, or a woke attack on orange ex-presidents. However, the truth is that supplies of carbon-based fuels are finite and costs have sky-rocketed following the invasion of Ukraine by Russia. Renewable energy must play a larger role in providing more power to countries around the world.

Amazon, Microsoft, and Google are snapping up the entire production of renewable power farms as they are built. These power farms are installations that take up swathes of land, and they probably received planning permission on the premise that they would power a certain number of homes. However, instead of powering the homes of tax-paying citizens, these power farms are sending all of the electricity they produce straight to the biggest cloud computing providers.

In 2017, Microsoft signed a 15-year exclusive contract with General Electric to consume power from a wind farm in the southwest of Ireland – 15 years of production that could have reduced the carbon footprint of domestic users and businesses that pay taxes in Ireland. Last November, the Redmond giant also signed an agreement to switch to 100% renewable power by 2030 in Ireland, creating further competition against citizens and businesses paying Irish taxes for power resources that still have not been built.

Isn’t the cloud green already?There is an argument that migrating workloads to the cloud will reduce power consumption, and therefore, pressure on a national grid. However, it’s hard to verify that in practice.

I’m not so sure that the levels of density in an Azure data center are impressive. In the early days of Azure with just A-Series virtual machines (remember – all Platform as a Service offerings hide a virtual machine under the covers), there were only a handful of machines per physical host. Meanwhile, those of us using on-premises Hyper-V or VMware were getting much higher levels of VM density.

Cloud regions are like gravity wells, sucking compute and storage into central locations. For example, the Microsoft West Europe region in the northwest Netherlands is providing compute and storage for customers in many countries all over Europe. The power grids for those customers are under less pressure, but the power grid in the Netherlands is put under more pressure.

Sea-powered cloudYou might remember Microsoft’s Project Natick, an experiment to run a mini-cloud data center in a deep sea tank. Uninformed persons might assume that Project Natick has inspired a broad industry change – no it has not. This was an interesting project, but there are many obstacles that I (not a deep sea expert) can think of.

Microsoft tested underwater data centers with Project Natick (Photography by Scott Eklund/Red Box Pictures)The submersible tank in the photos and video was tiny. How many of those tanks would be required to replace a building that is hundreds of meters long? And that’s assuming that these tanks are even feasible:

  • Won’t there be huge protests against a data center installation that will replace precious sea floor life with concrete beds?
  • Placement in international waters will be too complex and expensive, not to mention the threat of an unfriendly nation tapping wires insidethe cloud network.
  • The cost of the tanks will be crazy – underwater data centers would need to be highly resilient to survive years without needing to be raised to be repaired. And what happens if one of those things leaks and the customer hasn’t used availability zones?

Ultimately, sea-located data centers are a nice story, but they seem to be far from practical.

Using data centers as power generatorsAn Amazon data center in Dublin, which was once a biscuit factory that teased my olfactory senses as a child, is set to use its excess heat to warm an educational facility, government buildings, and 133 apartments. At first sight, this seems like a nice feel-good story, but sit back and think for a moment: How much power is this data center consuming? Now, compare that to the power required to heat 133 homes, a school, and an office building for 6-8 months per year.

Microsoft recently announced a plan to become a UPS for the national grid. The concept is that a cloud data center has huge amounts of battery power. Should a national grid be reaching low levels of supply capacity, if a data center is in a healthy state, it could output power to the grid to power other businesses and homes.

One could see this as the data center acting as a battery for the grid. For example, Ireland’s renewable energy sources are heavily skewed towards wind power, which is not reliable. Wind farms could charge the battery (the data center) and if the wind stops blowing, the battery could feed consumers. This is an interesting concept, but it will be necessary to see how it might work out.

ConclusionIt’s clear by my career choice (I’m a cloud consultant) that I’m in favor of cloud computing. However, I think there needs to be a reasonable conversation about how the cloud consumes power from a country and provides a contribution back to that country.

This isn’t to be mistaken with what some call “socialism”, it’s a hard reality that these companies are making huge impacts on economies and are not contributing back to those economies, breaking some of the concepts of capitalism. Technology innovation is interesting, but precious and expensive power is being devoured by cloud data centers in small areas, and something needs to be done to balance the equation.

View Details

MC516348 – Updated March 16, 2023: Microsoft has updated the rollout timeline below. Thank you for your patience.

As part of the DMARC (Domain-based Message Authentication Reporting & Conformance) standard, the owner of the domain whose MX is pointed to Office 365 can request DMARC aggregate reports through the RUA of the DMARC record. This will help the domain owner to monitor their domain’s traffic passing through Office 365 and adjust their sender authentication configurations to reach an actionable DMARC policy.

This message is associated with Microsoft 365 Roadmap ID 109535

When this will happen:

Standard Release: Microsoft will begin rolling out mid-March (previously mid-February) and expect to complete by late March.

How this will affect your organization:

Domain owners will receive DMARC reports to RUA email addresses.

What you need to do to prepare:

DMARC reports are only sent to domains whose MX is pointed to O365. In order to obtain DMARC aggregate reports for your domain, it must have a valid DMARC record that includes a valid RUA email address.

You can learn more about DMARC here

View Details

MC469578 – Updated March 16, 2023: Microsoft has updated the rollout timeline below. Thank you for your patience.

Microsoft is excited to announce the OneNote viewer feature within Teams mobile apps.

Through this new feature, users will be able to open and view OneNote notebooks right within their Teams mobile apps. Users interested in editing the content will be directed to the standalone OneNote mobile app. The experience will be available as part of the Teams mobile apps on Android and iOS (including iPads) starting with English language users, followed by international languages.

This message is associated with Microsoft 365 Roadmap ID 103097

When this will happen:

Standard Release: Microsoft expects to begin rolling out the OneNote viewer starting early December 2022 and complete the rollout by late March (previously late February). 

Rollout for Android has completed.

What you need to do to prepare:

No admin action is needed to support these changes.

View Details

MC455520 – Updated March 16, 2023: Microsoft apologizes for the delay and have updated the rollout timeline below. Thank you for your patience.

SharePoint is updating the site detail panel to include Microsoft Teams and Microsoft 365 Groups information.

This message is associated with Microsoft 365 Roadmap ID 100053

Standard Release: Microsoft will begin rolling out mid-November 2022 and expect to complete by late April (previously late February).

How this will affect your organization:

Admins that have permissions to SharePoint, Teams and Groups admin centers can now manage all related attributes (membership, group name, description, etc.) from a single site detail panel in the SharePoint admin center ‘Active Sites’ tab. SharePoint admins with SharePoint only permissions will have read-only access to the new attributes.

View image in new tab

View image in new tab

What you need to do to prepare:

No preparation is required

View Details

MC504326 – Updated March 16, 2023: Microsoft has updated the content below to show as intended. Thank you for your patience.

Microsoft is pleased to announce that the configuration of Private CDN is no longer required. It is now automatically managed within the SharePoint online service.

Public CDN should however be configured as recommended. Please contact Microsoft support should you have any further questions.

When this will happen:

The change will start rolling out to customers starting early March 2023, and we expect to complete by end of March 2023.

How this will affect your organization:

You no longer have to configure private CDN for your SharePoint online environment for all image file types. If you are using private CDN for other files (like JS and CSS) please reconfigure to use public CDN. Public CDN can be configured as recommended. Please contact Microsoft support should you have any further questions.

Additional information

Help and support

View Details

MC528800 – Today Microsoft announced Microsoft 365 Copilot – new experience that combines the power of large language models with your data in the Microsoft Graph and the Microsoft 365 apps. Copilot is integrated into Microsoft 365 in two ways. First, it works alongside the user, embedded in Word, Excel, PowerPoint, Outlook, Teams, and more. Second, we’ve also introduced Business Chat that works across all Microsoft 365 apps and data in real-time: user’s calendar, emails, chats, documents, meetings, and contacts.

How this will affect your organization:

Integrated into Microsoft 365, Copilot automatically inherits all of your company’s security, compliance, identity, and privacy policies and processes. Two-factor authentication, compliance boundaries, privacy protections, and more make Copilot the AI solution you can trust. Copilot works only with content to which your users already have permission to access.

Today’s announcement does not impact any Azure Active Directory (AAD) users in your organization, as the new features are currently only available to a limited set of commercial customers through a Private Preview program.

As these services become more broadly available, Microsoft will be providing admins with an advance notice and technical documentation about available controls and policies.

What you need to do to prepare:

There is nothing you need to do at this time. As soon as the additional roll out dates are ready to be announced, Microsoft will inform you through the Message Center in the Microsoft 365 admin center. You can also follow these features on Microsoft 365 public roadmap website.

Learn more about other technical details in this blog.

Blog

View Details

Thursday 16, March, at its Reinventing Productivity with A.I. event, Microsoft announced Microsoft 365 Copilot, a new set of Artificial Intelligence (A.I.) integrations in its suite of Office applications, powered by ChatGPT and technology it has developed using the Microsoft Graph and large language models (LLMs).

Introducing Microsoft 365 CopilotOffice apps already have A.I. features today, like PowerPoint’s Designer, where it suggests design layouts for your slides. But Copilot takes A.I. integration a step further by allowing you to interact with apps using natural language. And Copilot is able to analyze information not only in the current document, but also other relevant documents stored in your Microsoft 365 tenant.

Microsoft 365 Copilot for PowerPoint (Image Credit: Microsoft)The Copilot system is an orchestration engine that harnesses the power of information via the Microsoft Graph and large language models (LLMs). It’s not just ChatGPT bolted on to Microsoft 365 apps. Microsoft demonstrated how Copilot can analyze sales information in an Excel spreadsheet and identify key trends. And dig deeper to surface more detailed information in a table and graph on a new sheet.

That’s not trivial. Especially if your Excel skills are limited. Microsoft said during the presentation: ‘Most people use no more than ten percent of what PowerPoint can do. Copilot unlocks the other ninety percent.’ And that applies across the board with Microsoft’s productivity apps.

OutlookCopilot will help you separate important information from noise by triaging your inbox. And on mobile, it can summarize long email threads, draft replies, integrate data from other sources like Excel. And it can make your email replies more concise, add more context, or change the writing style.

Microsoft 365 Copilot for Outlook (Image Credit: Microsoft)TeamsIf you are unable to attend a meeting, you can let Copilot follow it and produce a summary of what you missed. The recap will arrive as a notification in Teams and include content shared during the meeting, summarize notes, and provide a list of any action items that were assigned to you and others.

When information provided by the summary isn’t enough, you can use Copilot and natural language to ask for more details or why certain decisions were made. And if you want to understand more, Copilot can surface what other solutions were considered. Much like in Bing Prometheus, Copilot will provide citations from the meeting transcript to back up its conclusions.

PowerPointCopilot lets you generate a slide deck just from just words and using natural language. You can provide as much context as required and documents that contain relevant information. You can hone the results manually or ask Copilot to do it. Imagine you have a slide that just has words. You can ask Copilot to make it more visual. Or you could ask Copilot to animate a slide and even add speaker notes.

‘What if the tools could learn how you work, rather than the other way round?’

Microsoft also demonstrated how more people will be able to use tools like Power Automate using natural language. Power Automate is a no-code solution for developing apps. But it’s not always easy to build more than very simple workflows without experience. Copilot will help Power Automate become an app that you use every day, just like Word and PowerPoint.

Copilot Business ChatDo you struggle to find the information you need for a project? Copilot Business Chat is a bot that pulls all the information you are looking for in a single place using natural language. Business Chat brings many of the Copilot features found in the individual apps into a single place. Once you’ve surfaced the information you require, you can ask it to produce a slide deck or email.

Microsoft 365 Copilot Business Chat (Image Credit: Microsoft)Copilot and Microsoft LoopLoop is still in private preview at the time of writing but it hasn’t been left out. Copilot also works with Loop components to help you organize and generate content.

Copilot for the enterpriseMicrosoft emphasized during the event that Copilot is grounded in your organization’s data and that it works securely while respecting compliance rules and privacy. So, you don’t need to worry about Copilot surfacing private information when it is used to query data across your Microsoft 365 tenant.

Microsoft 365 Copilot for Word (Image Credit: Microsoft)The content Copilot generates is intended to be used as a draft to get you started. Microsoft admitted that sometimes Copilot gets it wrong and that engineers are working with customers to improve the results over time.

Microsoft 365 Copilot availabilityThere was no exact date given as to when Copilot would be made available. But Microsoft has said that Copilot will be released in Microsoft 365 apps during the months ahead. Starting with Word, Excel, PowerPoint, Outlook, Teams, Viva, Power Platform, and more.

Earlier in March, Microsoft announced Dynamics 365 Copilot, which it claims is the world’s first A.I. Copilot in Customer Relationship Management (CRM) and Enterprise Resource Planning (ERP) software.

Is Copilot the answer to managing information overload and faster content generation?Google managed to one up Microsoft this week with an event on Tuesday where it announced similar A.I. integrations in Google Workspace. But Google still doesn’t have a product to show. Although, a preview was promised by the end of the month.

The Microsoft demos we saw today, to be honest, were mind blowing. But the proof is in the pudding. It remains to be seen whether similar results can be reproduced with real-world data and scenarios. And what the additional cost, if any, will be for Copilot.

Having seen what Microsoft has achieved with Bing Prometheus, it’s A.I. powered search feature that uses technology from OpenAI, including ChatGPT, I’m confident that we will eventually be able to experience similar results to what was shown today. But like Prometheus, it’s early days and I would expect Copilot to be far from perfect out of the gate.

View Details

Microsoft has announced the general availability of Azure Firewall Basic. The affordable SKU launched in preview in October 2022 to help small and medium-sized businesses (SMBs) protect their Azure cloud environments.

Azure Firewall is a cloud-based solution that provides an additional layer of security to protect Azure Virtual Network resources from external and internal threats. Microsoft says that customers have widely adopted Azure Firewall Basic since its launch in public preview. The company has now added a new feature that lets users deploy Azure Firewall within a virtual hub.

“Deploying Azure Firewall in a virtual network is recommended for customers who plan to use traditional hub-and-spoke network topology with a Firewall on the hub. Whereas, deploying on a virtual hub is recommended for customers with large or global network deployments in Azure where global transit connectivity across Azure regions and on-premises locations is needed,” explained Mark Gakman, Senior Product Manager for Azure Networking.

In addition to the Basic plan, Azure Firewall is available in two other SKUs to meet the specific needs of businesses. Azure Firewall Standard is designed for customers that need Layer 3–Layer 7 firewall protection with threat intelligence, custom DNS, Domain Name System (DNS) proxy, and other features. Moreover, Azure Firewall Premium helps organizations protect highly sensitive workloads.

Azure Firewall Basic: A cloud-native network firewall security solutionMicrosoft has highlighted several key capabilities included in Azure Firewall Basic. It provides built-in high availability, network and application traffic filtering, as well as threat intelligence features to detect malicious traffic.

Additionally, IT admins can use templates to easily deploy Azure Firewall Basic in their Azure environments. Other features include automatic updates, centralized management, and support for Infrastructure as Code (IaC).

Microsoft has acknowledged a couple of limitations in Azure Firewall Basic. Currently, the new SKU supports Threat Intel alert-only mode. Secondly, Azure Firewall Basic is ideal for environments that have an approximate data transfer rate of 250 Mbps. Microsoft says that it has a fixed scale unit to run the service on backend virtual machine instances. We invite you to check out the Azure Firewall website for pricing details.

View Details

Microsoft has released patches to address a critical security flaw in Outlook for Windows. The company confirmed that a Russian hacking group exploited the NTLM vulnerability to target several European and military organizations in 2022.

The zero-day flaw (CVE-2023-23397) was first reported discovered by Ukraine’s Computer Emergency Response Team (CERT-UA). It’s a privilege escalation vulnerability with a 9.8 CVSS score affecting all supported versions of Outlook for Windows.

Essentially, the vulnerability lets remote attackers send a specially crafted email to a vulnerable system to access the victim’s NTLM password hash. Windows New technology LAN Manager (NTLM) is a suite of security protocols that use hashed login credentials for authentication in Windows domains. Once stolen, the NTLM password hash can be used for authentication purposes.

“CVE-2023-23397 is a critical EoP vulnerability in Microsoft Outlook that is triggered when an attacker sends a message with an extended MAPI property with a UNC path to an SMB (TCP 445) share on a threat actor-controlled server,” Microsoft explained. “The connection to the remote SMB server sends the user’s NTLM negotiation message, which the attacker can then relay for authentication against other systems that support NTLM authentication.”

It is important to note that the Outlook Web app doesn’t use NTLM to authenticate users. Microsoft has confirmed that the NTLM vulnerability only impacts customers running Outlook for Windows clients.

Microsoft details mitigation strategies to block Outlook NTLM attacksMicrosoft recommends its customers to install the latest security updates available for Outlook for Windows to address the NTLM vulnerability. Additionally, IT admins can block TCP 445/SMB outbound from their networks.

Microsoft also advises administrators to add on-premises accounts to the Protected Users Security Group. The company has also developed a PowerShell script to find and remove suspicious items in on-premises and cloud environments.

View Details

MC527924 – Microsoft is making some changes to the location of Teams meeting add-in log files.

When this will happen:

Microsoft will begin rolling out to Standard tenants in mid-March and expect to complete rollout by mid-April.

GCC, GCCH, and DoD will begin rollout in mid-April and expect to complete by mid-May.

How this affects your organization:

Teams meeting add-in log files will be stored in %localappdata%\Temp\Microsoft\Teams\meeting-addin. Administrators will need to look at the new location when verifying issues with Teams meeting add-in from the log files, when this change is implemented.

What you can do to prepare:

When this change takes effect, IT Admins will need to update any scripts or tooling that is looking for Teams meeting add-in logs from the previous location.

View Details

Microsoft has announced the general availability of AWS Application composer. First introduced in December 2022, the new low-code tool enables developers to visually design and build serverless applications from multiple AWS services.

“You can drag, drop, and connect AWS services into an application architecture by using AWS Application Composer’s browser-based visual canvas. AWS Application Composer helps you focus on building by maintaining deployment-ready infrastructure as code (IaC) definitions, complete with integration configuration for each service,” the company explained.

AWS has also made some improvements to the Application Composer tool based on customer feedback. The service now provides better integration with Amazon SQS (Simple Queue Service). AWS Application Composer also introduced zoom controls and smaller resource cards that let users view more details on a single screen. A new change inspector feature helps to track changes when resources are connected.

How to get started with AWS Application ComposerTo get started, users will need to head to the AWS Management Console and select the Open demo option. They will see a simple cart app with various resources such as AWS Lambda, Amazon DynamoDB, and Amazon API Gateway. Users can drag and drop AWS services from the left Resources panel onto the canvas to expand their architecture. It’s possible to connect resources in the middle Canvas panel.

AWS highlighted that AWS Applicatio be useful in various scenarios. For instance, developers can use the tool to build a prototype of serverless applications. It also helps to create diagrams for documentation or onboard new team members. AWS Application Composer can be used to improve existing serverless projects.

AWS Application Composer is available in the US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Singapore), Asia Pacific (Tokyo), Europe (Stockholm), Europe (Frankfurt), and Europe (Ireland) regions. You can refer to the AWS Application Composer developer guide for details.

View Details

Microsoft has warned customers about Adversary-in-the-Middle (AiTM) phishing kit available for sale on a popular cybercrime forum. The software is designed to make it easier for attackers to deploy phishing campaigns to target enterprise accounts.

According to the Microsoft Threat Intelligence team, this phishing kit is an open-source tool that is developed by a hacking group called DEV-1101. Last year, cybercriminals started selling the Adversary-in-the-Middle (AiTM) phishing kit for $300 for a standard version and VIP licenses for $1,000.

Microsoft explained that the tool provides various advanced features that support the deployment of phishing campaigns in enterprise environments. Specifically, it gives threat actors the ability to bypass multi-factor authentication (MFA). The security feature requires users to provide one or more forms of authentication to access a service. It makes it difficult for hackers to gain unauthorized access to users’ accounts.

Interestingly, the AiTM kit leverages different techniques to avoid detection. First up, it enables threat actors to insert a CAPTCHA into the phishing process, which lets humans access the final phishing page. There is also a feature that uses antibot functionality that triggers an href redirection to a benign page. It makes it easier to bypass blocklists maintained for malicious URLs.

“These attributes make the kit attractive to many different actors who have continually put it to use since it became available in May 2022. Actors using this kit have varying motivations and targeting and might target any industry or sector,” the Microsoft Threat Intelligence team explained.

The AiTM phishing attack chainHow to mitigate AiTM phishing attacks?Microsoft detailed several security measures that help organizations to block AiTM phishing attacks. The company suggests using certificate-based authentication (CBA), Microsoft Authenticator, FIDO2 security keys, and other methods to implement MFA in Azure AD.

Microsoft also recommends customers to use security defaults, continuous access evaluation, and use advanced anti-phishing solutions. Moreover, IT admins should continuously monitor suspicious activities to protect their users against AiTM attacks.

View Details

In this article, I will explain what are affinity and anti-affinity rules and how to use them with Azure Stack HCI and Windows Server Hyper-V. If you’ve been using other hypervisors, you may already be familiar with affinity and anti-affinity rules, which are used to define the relationship between virtual machines and hosts.

What are affinity and anti-affinity rules?Affinity and anti-affinity rules describe how virtual machines on a hypervisor are placed next to each other when deployed and in operation. Let’s dive into details about how they work.

Affinity RulesWhen configuring the relationship between two virtual machines with an affinity rule, you want to keep them as close as possible. In the best case, you want to keep them on the same hypervisor host.

You can use an affinity rule to keep two VMs as close as possible (Image credit: Flo Fox/Petri)Normally, you use affinity rules to keep systems close to each other. That is often required for virtual machines that need very fast and reliable communication with each other.

A good use case could be a high-performance compute cluster where very fast communication for calculations is more important than redundancy. Another example could be frontend and backend systems where the frontend needs very fast communication with the backend system.

An affinity rule can ensure very fast communication in a high-performance compute cluster (Image credit: Flo Fox/Petri)Anti-affinity rulesAnti-affinity rules are the direct opposite of affinity rules: Those rules are used to ensure that virtual machines are never running on the same hypervisor host.

Anti-affinity rules are used to ensure that VMs are never running on the same hypervisor host (Image credit: Flo Fox/Petri)You may want to use anti-affinity rules for virtual machines that are, for example, running as a cluster or hosting the same service and never should fail at the same time if the host fails. A good example of such a service would be a Windows Server Active Directory domain controller: You should normally have a minimum of two domain controllers, though you don’t want to have them running on the same host to prevent any outages of your directory service.

In any case, clustered systems are always a good use case for using anti-affinity rules.

Clustered systems are always a good use case for using anti-affinity rules (Image credit: Flo Fox/Petri)Why combine affinity and anti-affinity rules in Azure Stack HCIIn more complex environments with larger application systems depending on several frontend and backend application servers, you may want to combine affinity and anti-affinity rules to improve performance while keeping availability as high as possible.

In such a case, you would for example put frontend and backend application services in an affinity group and the backend systems in a separate anti-affinity group.

You may want to combine the two types of rules to improve performance in complex systems (Image credit: Flo Fox/Petri)In Azure Stack HCI, you can create server and site-based affinity and anti-affinity rules. You have the option to create those via PowerShell and the Windows Admin Center. To learn more, Microsoft created a great guide for creating server and site affinity rules for virtual machines.

What could impact the placement of virtual machines?Normally, an Azure Stack HCI cluster should be perfectly able to place your virtual machines using the affinity rules you defined. However, the following are factors that could negatively impact that placement:

  • Maintenance: During maintenance, you may have not enough host resources or servers available. That could either result in virtual machines running in a not desired host combination, or your automated maintenance stopping because it cannot maintain the availability.
  • Host outages: You may not have enough host resources or servers available. That could result in virtual machines running in a not desired host combination.
  • Contradictory rules: There’s always the possibility that the rules you created are contradictory, and that could impact your placement. Every time you’re planning your rules, think them through a few more times to make sure you don’t miss anything.
  • Virtual machine load balancing: This feature allowing you to optimize server utilization in your clusters may also impact the placement of virtual machines.

Depending on your Virtual machine load balancing configuration, your virtual machines could move around and may not run optimally for your application systems and services. It is normally a good thing to keep load balancing aggressiveness medium to low. That helps to prevent unpredicted moving around of virtual machines.

ConclusionAffinity and anti-affinity rules are very important tools in your toolset for Windows Server Hyper-V and Azure Stack HCI. It helps you increase your virtual machine performance and availably of critical workloads. In any case, you should always try to use them to optimize your environment.

View Details

MC516263 – Updated March 14, 2023: Microsoft has updated this message to show as intended. Thank you for your patience.

The Stream migration tool, which has been in preview since August of 2022, has now entered general availability. The tool is designed to help IT admins migrate video content from Stream (Classic) to Stream (on SharePoint). Admins can access the tool by logging on to the Stream Admin Center and then navigating to Stream Migration > Migration tool.

As announced in January, Stream (Classic) will be retired on Feb 15, 2024 for all customers, except GCC customers. The successor service Stream (on SharePoint) is currently available for all customers. A critical step to begin adopting Stream (on SharePoint) is to migrate video content to it. The Stream migration tool has been designed to help admins move content from Stream (Classic) to Stream (on SharePoint) as there is no auto-migration within Stream (Classic).

This message is associated with Microsoft 365 Roadmap ID 93361

Note: This message center post does not apply to Government Commercial Cloud (GCC) customers. The migration tool is not yet available for GCC customers, and Microsoft has not yet set a retirement date for the GCC instance of Stream (Classic). Until those dates are announced, GCC customers can continue to use Stream (Classic) without interruption. When these dates are announced GCC customers will receive both access to the migration tool and one-year advance notice of retirement.

When this will happen:

GA: Microsoft will begin rolling out on February 15,2023 and expect to complete rollout by late February.

How this will affect your organization:

As part of the Stream (Classic) retirement process Microsoft is introducing two default date settings which admins can adjust using the Stream (Classic) admin center.

How to delay the change that will block users from uploading to Stream (Classic):

  • Beginning May 15, 2023 users will be blocked from uploading content to Stream (Classic) unless you take action to delay this change. You can delay this change to as late as August 15, 2023, after which videos will start saving to Stream (on SharePoint) by default. You can access the setting by navigating to the Stream (Classic) Admin center > Stream Migration > Settings. Under “Save videos to Stream (on SharePoint)” change the “Scheduled for” to your desired date. For more information please visit this page.
  • After the “scheduled for” date, users who attempt to upload to Stream (Classic) will see only the option to upload to Stream (on SharePoint). Users who click on this option will be redirected to the Stream start page (Stream.Office.com) where they can upload to Stream (on SharePoint).

How to delay the change that will block users from accessing Stream (Classic):

  • Beginning October 15, 2023 users will no longer be able to access or use Stream (Classic) unless you take action to delay this change. You can delay this change until February 15, 2024, after which your users will not be able to access Stream (Classic). You can access this setting by navigating to the Stream (Classic) Admin center > Stream Migration > Settings. Under “Disable Stream (Classic) for users” change the “Scheduled for” date to your desired date.
  • The date you enter in the “Scheduled for” box will be the date that end users lose access to Stream (Classic). Note: Admins will retain access Stream (Classic) and the migration tool until February 15, 2024. For more information, please visit this page.

What you need to do to prepare:

Microsoft recommends that you consider taking these actions:

  1. Begin planning your video content migration. While Stream (Classic) will be available until February 15, 2024, Microsoft plans to retire some functionality sooner than 2024.
  2. View the Stream (Classic) retirement timeline for the most current dates in the retirement process.
  3. Delay default service retirement date settings if needed.

See the documentation below to familiarize yourself with the migration process:

  • Stream (Classic) to Stream (on SharePoint) migration tool
  • Step-by step guide to run the Stream migration tool
  • Stream migration tool settings
  • Stream migration tool reports, permissions and embed support
  • Migration strategies for moving from Stream (Classic) to Stream (on SharePoint)
  • Stream (Classic) retirement timeline

If you would like to provide feedback to the product team on any items that may be blocking you from using this migration tool in its current state, please provide your feedback here.

Additional information

View Details

Microsoft has just released the March 2023 Patch Tuesday updates for Windows 11 and Windows 10. For Windows 11 users, today marks the public rollout of the “Moment 2” feature update that brings a new search box to the taskbar and many other new features.

On the security front, this month’s Patch Tuesday updates include fixes for 74 vulnerabilities in Windows and other components. Two of them are currently being exploited by attackers, including an Outlook spoofing vulnerability.

74 vulnerabilities fixed in the March Patch Tuesday updatesHere are the most critical vulnerabilities fixed with this month’s Patch Tuesday updates:

  • CVE-2023-23397: This Microsoft Outlook Elevation of Privilege Vulnerability is already being exploited by attackers sending specially crafted emails that are triggered automatically when they’re retrieved and processed by the email server.
  • CVE-2023-24880: This Windows SmartScreen Security Feature Bypass Vulnerability has been publicly disclosed and is also being exploited by attackers. It requires a malicious malicious file that would evade Mark of the Web (MOTW) defenses.
  • CVE-2023-23392: This HTTP Protocol Stack Remote Code Execution Vulnerability could allow an unauthenticated attacker to send a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets.
  • CVE-2023-23415: This Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability could allow an attacker to send a low-level protocol error containing a fragmented IP packet inside another ICMP packet in its header to the target machine.
  • CVE-2023-23411: This Windows Hyper-V Denial of Service Vulnerability could allow a Hyper-V guest to affect the functionality of the Hyper-V host.

You can find the full list of CVEs included in this month’s Patch Tuesday below:

| Product | Impact | Max Severity | Article | Download | Details | | Windows 11 Version 22H2 for x64-based Systems | Remote Code Execution | Critical | 5023706 | Security Update | CVE-2023-23392 | | Windows 10 for x64-based Systems | Elevation of Privilege | Critical | 5023713 | Security Update | CVE-2023-1018 | | Windows 10 Version 22H2 for x64-based Systems | Elevation of Privilege | Critical | 5023696 | Security Update | CVE-2023-1018 | | Windows Server 2012 R2 | Information Disclosure | Important | 5023765 | Monthly Rollup | CVE-2023-24911 | | Windows Server 2012 R2 | Information Disclosure | Important | 5023764 | Security Only | CVE-2023-24911 | | Windows Server 2012 (Server Core installation) | Information Disclosure | Important | 5023756 | Monthly Rollup | CVE-2023-24911 | | Windows Server 2012 (Server Core installation) | Information Disclosure | Important | 5023752 | Security Only | CVE-2023-24911 | | Windows Server 2012 | Information Disclosure | Important | 5023756 | Monthly Rollup | CVE-2023-24911 | | Windows Server 2012 | Information Disclosure | Important | 5023752 | Security Only | CVE-2023-24911 | | Windows Server 2016 (Server Core installation) | Information Disclosure | Important | 5023697 | Security Update | CVE-2023-24911 | | Windows Server 2016 | Information Disclosure | Important | 5023697 | Security Update | CVE-2023-24911 | | Windows 10 Version 1607 for x64-based Systems | Information Disclosure | Important | 5023697 | Security Update | CVE-2023-24911 | | Windows 10 Version 1607 for 32-bit Systems | Information Disclosure | Important | 5023697 | Security Update | CVE-2023-24870 | | Windows 10 for 32-bit Systems | Information Disclosure | Important | 5023713 | Security Update | CVE-2023-24870 | | Windows 10 Version 22H2 for 32-bit Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 10 Version 22H2 for ARM64-based Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 11 Version 22H2 for ARM64-based Systems | Information Disclosure | Important | 5023706 | Security Update | CVE-2023-24870 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 10 Version 21H2 for ARM64-based Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 10 Version 21H2 for 32-bit Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 11 version 21H2 for ARM64-based Systems | Information Disclosure | Important | 5023698 | Security Update | CVE-2023-24870 | | Windows 11 version 21H2 for x64-based Systems | Information Disclosure | Important | 5023698 | Security Update | CVE-2023-24870 | | Windows 10 Version 20H2 for ARM64-based Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows 10 Version 20H2 for 32-bit Systems | Information Disclosure | Important | 5023696 | Security Update | CVE-2023-24870 | | Windows Server 2022 (Server Core installation) | Security Feature Bypass | Moderate | 5023705 | Security Update | CVE-2023-24880 | | Windows Server 2022 (Server Core installation) | Security Feature Bypass | Moderate | 5023786 | AzureHotpatch | CVE-2023-24880 | | Windows Server 2022 | Security Feature Bypass | Moderate | 5023705 | Security Update | CVE-2023-24880 | | Windows Server 2022 | Security Feature Bypass | Moderate | 5023786 | AzureHotpatch | CVE-2023-24880 | | Windows 10 Version 20H2 for x64-based Systems | Remote Code Execution | Important | 5023696 | Security Update | CVE-2023-24876 | | Windows Server 2019 (Server Core installation) | Remote Code Execution | Important | 5023702 | Security Update | CVE-2023-24876 | | Windows Server 2019 | Remote Code Execution | Important | 5023702 | Security Update | CVE-2023-24876 | | Windows 10 Version 1809 for ARM64-based Systems | Remote Code Execution | Important | 5023702 | Security Update | CVE-2023-24876 | | Windows 10 Version 1809 for x64-based Systems | Elevation of Privilege | Important | 5023702 | Security Update | CVE-2023-24910 | | Windows 10 Version 1809 for 32-bit Systems | Elevation of Privilege | Important | 5023702 | Security Update | CVE-2023-24910 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Important | 5023765 | Monthly Rollup | CVE-2023-24909 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Important | 5023764 | Security Only | CVE-2023-24909 | | Microsoft Visual Studio 2022 version 17.5 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23946 | | Microsoft Visual Studio 2022 version 17.4 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23618 | | Microsoft Visual Studio 2022 version 17.0 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23618 | | Microsoft Visual Studio 2019 version 16.11 (includes 16.0 – 16.10) | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23618 | | Microsoft Visual Studio 2022 version 17.2 | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23618 | | Microsoft Visual Studio 2017 version 15.9 (includes 15.0 – 15.8) | Remote Code Execution | Important | Release Notes | Security Update | CVE-2023-23618 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Remote Code Execution | Important | 5023769 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Remote Code Execution | Important | 5023759 | Security Only | CVE-2023-24869 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Remote Code Execution | Important | 5023769 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Remote Code Execution | Important | 5023759 | Security Only | CVE-2023-24869 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5023755 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5023754 | Security Only | CVE-2023-24869 | | Azure Service Fabric 9.1 for Ubuntu | Spoofing | Important | Release Notes | Security Update | CVE-2023-23383 | | Azure Service Fabric 9.1 for Windows | Spoofing | Important | Release Notes | Security Update | CVE-2023-23383 | | Microsoft Dynamics 365 (on-premises) version 9.0 | Spoofing | Important | 5023506 | Security Update | CVE-2023-24891 | | Microsoft Dynamics 365 (on-premises) version 9.1 | Spoofing | Important | 5023505 | Security Update | CVE-2023-24891 | | OneDrive for iOS | Security Feature Bypass | Important | App Store | Security Update | CVE-2023-24890 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Remote Code Execution | Important | 5023755 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 for x64-based Systems Service Pack 2 | Remote Code Execution | Important | 5023754 | Security Only | CVE-2023-24869 | | OneDrive for MacOS Installer | Elevation of Privilege | Important | App Store | Security Update | CVE-2023-24930 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5023755 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Remote Code Execution | Important | 5023754 | Security Only | CVE-2023-24869 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Remote Code Execution | Important | 5023755 | Monthly Rollup | CVE-2023-24869 | | Windows Server 2008 for 32-bit Systems Service Pack 2 | Remote Code Execution | Important | 5023754 | Security Only | CVE-2023-24869 | | Microsoft Edge (Chromium-based) | Spoofing | Important | Release Notes | Security Update | CVE-2023-24892 | | OneDrive for Android | Information Disclosure | Important | App Store | Security Update | CVE-2023-24882 | | Microsoft Office for Universal | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2023-24910 | | Microsoft Office for Android | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2023-24910 | | Microsoft Office LTSC for Mac 2021 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2023-24910 | | Microsoft Office 2019 for Mac | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2023-24910 | | Azure HDInsights | Spoofing | Important | Release Notes | Security Update | CVE-2023-23408 | | Microsoft Outlook 2016 (64-bit edition) | Elevation of Privilege | Critical | 5002254 | Security Update | CVE-2023-23397 | | Microsoft Outlook 2013 Service Pack 1 (32-bit editions) | Elevation of Privilege | Critical | 5002265 | Security Update | CVE-2023-23397 | | Microsoft Outlook 2013 RT Service Pack 1 | Elevation of Privilege | Critical | 5002265 | Security Update | CVE-2023-23397 | | Microsoft Outlook 2013 Service Pack 1 (64-bit editions) | Elevation of Privilege | Critical | 5002265 | Security Update | CVE-2023-23397 | | Microsoft Office 2019 for 32-bit editions | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft 365 Apps for Enterprise for 32-bit Systems | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft Office 2019 for 64-bit editions | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft 365 Apps for Enterprise for 64-bit Systems | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft Office LTSC 2021 for 64-bit editions | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft Outlook 2016 (32-bit edition) | Elevation of Privilege | Critical | 5002254 | Security Update | CVE-2023-23397 | | Microsoft Office LTSC 2021 for 32-bit editions | Elevation of Privilege | Critical | Click to Run | Security Update | CVE-2023-23397 | | Microsoft Office Web Apps Server 2013 Service Pack 1 | Remote Code Execution | Important | 5002362 | Security Update | CVE-2023-23399 | | Microsoft Office 2013 Service Pack 1 (64-bit editions) | Remote Code Execution | Important | 5002198 | Security Update | CVE-2023-23399 | | Microsoft Office 2013 Service Pack 1 (32-bit editions) | Remote Code Execution | Important | 5002198 | Security Update | CVE-2023-23399 | | Microsoft Office 2013 RT Service Pack 1 | Remote Code Execution | Important | 5002198 | Security Update | CVE-2023-23399 | | Microsoft Excel 2013 Service Pack 1 (64-bit editions) | Remote Code Execution | Important | 5002348 | Security Update | CVE-2023-23399 | | Microsoft Excel 2013 Service Pack 1 (32-bit editions) | Remote Code Execution | Important | 5002348 | Security Update | CVE-2023-23399 | | Microsoft Excel 2013 RT Service Pack 1 | Remote Code Execution | Important | 5002348 | Security Update | CVE-2023-23399 | | Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Important | 5002197 | Security Update | CVE-2023-23399 | | Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Important | 5002197 | Security Update | CVE-2023-23399 | | Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002351 | Security Update | CVE-2023-23399 | | Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002351 | Security Update | CVE-2023-23399 | | Microsoft Office Online Server | Remote Code Execution | Important | 5002356 | Security Update | CVE-2023-23399 | | Microsoft SharePoint Foundation 2013 Service Pack 1 | Spoofing | Important | 5002367 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Foundation 2013 Service Pack 1 | Spoofing | Important | 5002168 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Server Subscription Edition | Spoofing | Important | 5002355 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Server 2019 | Spoofing | Important | 5002358 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | Spoofing | Important | 5002366 | Cumulative Update | CVE-2023-23395 | | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | Spoofing | Important | 5002367 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | Spoofing | Important | 5002168 | Security Update | CVE-2023-23395 | | Microsoft SharePoint Enterprise Server 2016 | Spoofing | Important | 5002368 | Security Update | CVE-2023-23395 | | Microsoft Malware Protection Engine | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2023-23389 |

Quality and experience updatesI’ve previously detailed all the new features included in the “Moment 2” update for Windows 11 version 22H2 last month, but here’s a summary of all the new features in this update:

  • There’s a new search box in the taskbar for using Windows Search
  • The taskbar is now optimized for 2-in-1 devices with new “Expanded” and “Collapsed” states
  • On Windows on ARM devices that support Windows Studio Effects, these options are now accessible from Quick Settings in the taskbar
  • The Start Menu now displays recommended files on Azure AD joined devices
  • Support for new Braille devices and Voice Access improvements.
  • Task Manager now lets users filter processes
  • The Quick Assist app is now accessible from the All Apps list in the Start Menu
  • The Settings app has a new section with Energy Recommendations.

For IT pros managing Windows Updates via Windows Update or WSUS, a new client policy now allows them to control the availability of new features introduced via servicing. Moreover, Microsoft said that new features that may be disruptive such as the new touch-optimized taskbar are disabled by default on managed devices.

Windows Update testing and best practicesOrganizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.

If you have any problems with this month’s patches, please let us know in the comments below. Other readers might be able to share their experiences in how to roll back problematic updates or mitigate issues caused by patches that are important to have in place.

View Details

Google announced this morning new ChatGPT-like generative AI capabilities for its Google Workspace productivity suite. The new AI-based features will begin rolling out in the Google Docs and Gmail apps for select users later this month.

In Google Docs, the new AI generative capabilities will enable users to create outlines for new documents. For instance, HR professionals will be able to create an outline for a job description with a brief prompt. Going forward, Google plans to introduce the ability to proofread, brainstorm, write, and rewrite text directly within documents.

Google has announced that new AI-powered features are coming to Gmail. Users will be able to draft and summarize emails, adjust the tone, and split the content into bullet lists. The feature will also let Gmail users create longer drafts based on short prompts. Additionally, Gmail is getting the “I am feeling lucky” feature that will generate email content based on existing information.

“We’re designing our products in accordance with Google’s AI Principles that keep the user in control, letting AI make suggestions that you’re able to accept, edit, and change. We’ll also deliver the corresponding administrative controls so that IT is able to set the right policies for their organization,” explained Johanna Voolich Wright, Vice President of Google Workspace.

Google teases generative AI features coming to other Google Workspace productsGoogle teased that AI-powered features can be integrated into other products such as the Sheets, Slides, Chat, and Meet apps. For example, Google Meet could automatically create meeting notes from a video call. The generative AI tools might also be used to auto-generate images, audio, and video in Google Slides.

Google plans to gradually roll out new generative AI features to Google Workspace customers. The AI tools will initially be available for users enrolled in the trusted tester program in the United States. The company plans to expand these capabilities to other regions in the coming months.

Last month, Microsoft has announced that it’s bringing OpenAI’s language AI technology to its Office productivity apps. It will be interesting to see if Google’s new AI features would be able to compete with ChatGPT-like tools coming to Outlook, Word, and PowerPoint.

View Details

Microsoft has introduced support for near real-time custom detections in its Microsoft 365 Defender solution. The new Continuous (NRT) feature enables customers to create custom detection rules that run in near real-time to block sophisticated attacks.

Microsoft 365 Defender allows customers to create custom detection rules to monitor specific threats, activities, and misconfigured endpoints. These rules are based on the specified conditions and can be used to trigger alerts, notifications, and response actions. Microsoft 365 Defender also provides a set of pre-defined detection rules that can be customized to meet specific requirements.

“These detections can be integrated with the broad set of Microsoft 365 Defender across email, endpoint, and identity, leading to faster response times and faster mitigation of threats. This means your custom logic will run and evaluate all available signals and alerts faster than ever before and will trigger your predefined response action immediately, once a match is detected,” the Microsoft 365 Defender team explained.

Microsoft 365 Defender can now monitor recent vulnerabilitiesMicrosoft has emphasized that enterprise customers are facing a growing number of online threats. Therefore, organizations must implement strong security measures to address these threats and protect sensitive data. These custom detections and automated response capabilities will help IT admins to monitor recent vulnerabilities. The feature also makes it easier for administrators to detect and remove unwanted emails.

Microsoft says that the near real-time detection capabilities are available in preview for all businesses. The company encourages customers to provide feedback to improve threat detection and response mechanisms in enterprise environments.

View Details

Microsoft is set to release its long-awaited unified Outlook for Windows app for all users. The new web-based experience has been available for Office Insiders since May 2022, and it will begin rolling out to users on the Current Channel in early April.

Microsoft has confirmed that the new Outlook for Windows client will first be available for personal Microsoft accounts and Exchange Online accounts. However, the toggle button to switch to the web-based Outlook app will not show up for Microsoft 365 subscribers. Microsoft plans to add support for more account types in the coming months.

“With a wealth of feedback from these early adopters, we are excited to expand access to users in Current Channel. The experience is an option to try, and nothing will change without end users taking action. We will give notice before any required changes occur, after the preview has received sufficient usage and feedback,” the company explained on the Microsoft 365 Admin Center.

Microsoft’s new Outlook app for Windows features a simplified ribbon with quick actions to make navigation easier. It also supports dynamic calendar column widths to help users easily view details of all events on their schedule. The new Outlook experience offers better integration with Microsoft Teams.

What you should do to prepare for the release of the new Outlook for Windows clientMicrosoft notes that conditional access (CA) policies will also apply to the unified Outlook client for Windows. Moreover, the app won’t support COM/VSTO add-ins, and IT admins are advised to migrate to web-based add-ins. Microsoft says that administrators will be able to hide the toggle button with a registry key.

Eventually, Microsoft’s new Outlook app plans to replace the built-in Mail and Calendar apps on Windows 10 and Windows 11 PCs. However, this change could take months or even years to happen on both operating systems. Microsoft has recently announced that it’s making the Outlook for Mac app free to use on macOS. The free version of Outlook will be ad-supported, and work with Gmail, Outlook.com, iCloud, Yahoo, IMAP, and POP accounts.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Katie McMillan on Information Security vs. Legacy Technology and MentoringKatie McMillan is a rising star in the tech community and specialises in Information Security across all platforms, but with a more recent focus on Microsoft. In addition to being an inspiring mentor, Katie is also a passionate advocate for women in the tech industry and is a TechWomen100 Winner – 2021, and a Women In Tech Excellence Finalist – 2021.

Katie McMillan joins Kat and Peter on the show this week to discuss:

  • Katie’s career journey
  • How legacy technologies are the biggest challenge to implementing modern security principles
  • Mentorship
  • Women in tech
  • And much more!

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft has made some changes to the way the AppLocker application control policies work on Windows PCs. The company has quietly removed the checks that were previously used to identify the specific edition of Windows 11 or 10 installed on a system

AppLocker is a security feature that enables IT Pros to enforce policies to manage applications that users can run on their systems. These policies can be configured to allow or block specific packaged apps, installers, scripts, EXE, and DLL files.

AppLocker policies can be configured to allow or block specific applications, scripts, installers, and DLLs. Administrators can create the policies with the Group Policy Editor or PowerShell. The AppLocker rules can be applied on a per-user or per-group basis.

AppLocker rule enforcementIT Admins can now apply AppLocker policies across all Windows editionsPreviously, AppLocker application control policies were enforced based on the Windows edition and the endpoint management method. “For instance, systems managed by mobile device management (MDM) enforced AppLocker policies on all editions of Windows 10 and Windows 11. Also, systems managed by Group Policy only enforced AppLocker policies on Windows 10 and Windows 11 Enterprise or Education editions,” Microsoft explained.

According to Microsoft, IT admins can now deploy the policies across Windows 11 versions 22H2 and 21H2 as well as Windows 10 versions 2004, 20H2, and 21H1. The change allows administrators to enforce AppLocker policies on more managed Windows 10 and 11 PCs.

Moreover, it can help to free up some extra time to focus on other important tasks, including managing security updates and troubleshooting issues. You can check out this support page to learn more details about AppLocker deployment on Windows 11 and Windows 10.

View Details

Windows 10 Pro, Enterprise, and Education editions contain a free virtualization software named Hyper-V. The underlying code works nearly the same as what’s provided in Windows Server. In this article, I will discuss how to enable Hyper-V on Windows 10, how to create your first virtual machine, and briefly talk about nested virtualization.

How to enable Hyper-V on Windows 10You can enable Hyper-V on Windows 10 by using PowerShell or the Windows GUI. PowerShell is probably the easiest way to do it, and here’s two proceed:

  • Open a PowerShell console with elevated permissions.
  • Run the following command:

Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V –All * Reboot your Windows 10 PC when prompted. * You can now access Hyper-V and create your first virtual machine!

Keep reading for more detailed instructions on how to enable Hyper-V using either PowerShell or the Windows GUI.

What is Hyper-V?Hyper-V is Microsoft’s free virtualization software in all editions and versions of Windows Server and Windows 10/11 Pro, Enterprise, and Education SKUs. Whether you’re an IT professional, a software developer, or a technology enthusiast, I imagine you would prefer to run multiple, independent operating systems on one computer instead of having to purchase a computer for each one. That can get expensive!

Virtual machines running in Hyper-V run on what’s called virtual hardware. Hard disks, switches, and DVD Drives are virtualized and presented to your guest OS. The guest VM doesn’t necessarily know it’s running as a virtual machine.

Hyper-V system requirementsThere are a few technical and specific requirements and prerequisites before enabling the Hyper-V feature in Windows 10. First, your host computer must meet these requirements:

  • 64-bit CPU with Second Level Address Translation (SLAT).
  • CPU support for VM Monitor Mode Extension (VT-c on Intel CPUs).
  • 4 GB Memory (you will want MORE, trust me)

There are additional requirements later on if you wish to run a virtual machine inside of a virtual machine – don’t worry, I’ll talk about nested virtualization soon enough.

Can you install Hyper-V on Windows 10 Home? Hyper-V requires Windows 10 (or 11) Enterprise, Pro, or Education editions, and it’s not available on Windows 10 Home. However, you can upgrade from Windows 10 Home to Windows 10 Pro on your PC by going into Settings > Update and Security > Activation.

How to enable Hyper-V with PowerShellInterestingly the steps required to enable the feature in Windows are relatively easy. I say interesting because being able to run another operating system ‘inside’ your current operating system is a very cool technology. And, thanks to the rather powerful and efficient tech behind Powershell, you’ll be up and running and creating virtual machines (VMs) in no time.

  • Go ahead and open a new PowerShell console as Administrator.

Searching for and launching PowerShell (Image credit: Petri/Michael Reinders)* Run the following command to enable Hyper-V:

Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All Enabling Hyper-V with PowerShell (Image credit: Petri/Michael Reinders) Go ahead and restart your computer when prompted. Then, click the Start button and search for ‘Hyper-V‘. * Click to open Hyper-V Manager*.

The Hyper-V Manager console (Image credit: Petri/Michael Reinders)Piece of cake! We are (sort of) all set to start creating VMs. Well, I discovered an ‘issue’ here. More on that very soon.

How to enable Hyper-V with the Windows Settings GUILet me show you how to perform the same steps using the legacy Control Panel GUI.

  • First, click the Start button and search for ‘optional features.’ Select Manage optional features.
  • Click the More Windows features link in the upper-right corner.

Managing optional features in Windows 10 (Image credit: Petri/Michael Reinders) Now, here’s where we hit a temporary block. If you scroll down to Hyper-V and expand it, you’ll see that the ‘Hyper-V Platform*‘ item is greyed out.

Looks like we can’t enable Hyper-V…yet… (Image credit: Petri/Michael Reinders)When I hover over the Hyper-V Platform item, I see: “Hyper-V cannot be installed: The processor does not have the required virtualization capabilities.”

So, how about some background? Sure. I am utilizing my Hyper-V lab on my main desktop computer running Windows 11. I am using one of my Windows 10 VMs to demonstrate the topic. I am already one layer down in the virtual world if you will (think Inception).

However, what I am asking Windows to do is called nested virtualization. I will go over this in more detail below, but basically, I need to add a second layer. Run Hyper-V as a feature inside another Hyper-V VM. I know, I had to watch Inception 5 times to wrap my head around it!

Anyway, if you aren’t already running Windows 10 in a VM (as I am), Hyper-V won’t be greyed out in the list of optional Windows Features. You’ll be able to select it, click OK, then you’ll be prompted to reboot your Windows 10 PC.

Creating a virtual machine with Hyper-VSo, we have Hyper-V enabled and ready to go. Let’s go through the basics of creating a new Windows VM. In the Hyper-V Manager, we’ll first create a new Virtual Switch so we can pass the network/Internet connection on our host machine down to our new VM.

  • Click Virtual Switch Manager… under the Actions menu on the right.
  • Click the Create Virtual Switch button.

Creating a new Virtual Switch (Image credit: Petri/Michael Reinders)Let’s name it ‘Internet Switch.’ Then, the defaults should be good – we are using the External network and the Microsoft Hyper-V Network Adapter to pass thru whatever connection the VM host has down to the new VM. This will allow DHCP servers to give the new machine an IP Address.

  • Click OK.
  • Next, under Actions, click New -> Virtual machine…
  • Click Next, and then enter a name for the new machine and click Next.

Creating a new Virtual Machine (Image credit: Petri/Michael Reinders) On the Specify Generation screen, you’ll want to choose Generation 2. Click Next*

Specifying the Generation of our machine. Most likely you will be choosing ‘Generation 2’. (Image credit: Petri/Michael Reinders) I will assign 4 GB of ram for our new machine and turn off Dynamic Memory for these demo purposes. My initial Hyper-V VM has 8 GB, so that should be fine. Click Next. * We will choose the ‘Internet Switch‘ from the Connection dropdown on the Configure Networking screen and click Next*.

Choosing our new Virtual Switch to provide network and Internet access to the VM (Image credit: Petri/Michael Reinders) We can leave all the defaults for the virtual hard disk, click Next and choose the default to install the operating system later * Click Next again, and then Finish*!

There’s our new Virtual Machine – ‘Windows 10 Inception’ (Image credit: Petri/Michael Reinders)There you have it!

Recommended configuration changes for your Hyper-V VMI will go through a few more common config changes I make when setting up a new VM and explain them to you.

  • Right-click on your virtual machine and click Settings.
  • In the Add Hardware default menu, SCSI Controller should be selected. Click the ‘Add‘ button, select ‘DVD Drive‘, and then click Add again.

Adding a DVD Drive so we can install an operating system (Image credit: Petri/Michael Reinders) Once you have an installation ISO file available, you can choose the ‘Image file:‘ option and browse to it. * After you have your ISO ready, you should click the Firmware menu on the left and move the DVD Drive to the top of the list so the VM boots to it when you power it on. * Then, click the Processor menu and verify how many virtual CPUs* (vCPUs) you want to assign to it. The more you add, the faster it will run. However, this will also negatively impact your host operating system, so you’ll need to tweak these settings over time.

Well, those are the salient points and should definitely get you headed in the right direction.

Hyper-V and nested virtualizationI’ve already briefly described the concept of nested virtualization. For the scope of this article, let me ask you to get more detail by checking out our previous post on how to enable nested virtualization on Windows 10 Hyper-V.

However, I want to address a few ‘issues’ I mentioned earlier in this article. The main issue is the fact that I can’t really use the Hyper-V software until I resolve the nested virtualization requirements. Personally, I find it odd that Windows allows you to run the PowerShell command to enable the Hyper-V platform without the required prerequisites!

Being able to turn on the Hyper-V feature in a VM requires a special PowerShell command to be run from your initial host computer. Before you proceed, make sure the VM you wish to modify is powered off. I will fire up a PowerShell console as Administrator and run a few commands.

First, I will run the Get-VM command:

Get-VM Running ‘Get-VM’ and then enabling the virtualization Features on my Windows 10 VM (Image credit: Petri/Michael Reinders)Yep, I do have a lovely assortment of machines, don’t I? The one I am working with is called ‘Windows 10 22H2 – MSA – ISO‘. So, I will run this command to enable the special CPU features for that specific VM.

Set-VMProcessor -VMName "Windows 10 22H2 - MSA - ISO" -ExposeVirtualizationExtensions $true Simply power up your VM and now you’ll be able to enable Hyper-V in it. You can refer to the steps above using PowerShell or the GUI.

ConclusionHyper-V is a free, easy-to-use virtualization solution built right into Windows. I have been using it ever since it became a part of Windows, back in the Windows 8 days!

I strongly encourage you, as IT Pros, to use it for your day-to-day testing needs. There is no need to buy another desktop or laptop just to see if an older version of Adobe Acrobat will work on Windows 11. Just fire up a new Windows 11 VM and give it a go!

Please leave any comments or questions below. I would love to assist you if you run into any configuration issues. Thanks for reading!

View Details

Microsoft’s owned GitHub has recently announced that it will soon require two-factor authentication (2FA) for developers who contribute code on the platform. Starting today, the company will begin rolling out the 2FA requirement to all software developers worldwide.

GitHub first unveiled its plans to enroll all contributors in 2FA by the end of 2023. The company made the 2FA requirement mandatory for maintainers of the top 100 npm packages in February 2022. Then, GitHub expanded this policy to include all maintainers of popular packages with more than 500 dependents or over one million weekly downloads.

GitHub explains that this move is part of its efforts to improve account security to secure the software development process. These compromised accounts could be used to roll out malicious changes or steal private code.

“Our 2FA initiative is part of a platform-wide effort to secure software development by improving account security. Developers’ accounts are frequent targets for social engineering and account takeover (ATO). Protecting developers and consumers of the open source ecosystem from these types of attacks is the first and most critical step toward securing the supply chain,” GitHub explained.

GitHub to gradually expand 2FA requirement roll out to minimize disruptionGitHub plans to roll out the 2FA policy in a staggered manner to minimize disruption in the workflows. Initially, the company will begin notifying smaller developer groups, and it will scale the requirements to larger groups over the course of this year. GitHub has not detailed any specific criteria for inclusion in the 2FA cadence. However, the company indicated that these groups will be selected based on their impact on the broader ecosystem.

GitHub contributors selected for enrollment will get advance email notifications to enable 2FA around 45 days before the deadline. Users who miss the cut-off date will be prompted to turn on the feature the next time they access the GitHub website. They will be able to pause the prompt for up to one week. Once the deadline passes, users will be unable to access GitHub.com without configuring 2FA.

According to Microsoft, developers can choose between various 2FA methods to protect their accounts. These include SMS (Short Message Service), TOTP (Time-based One-Time Password), security keys, and GitHub Mobile 2FA. GitHub warns that SMS-based 2FA is less secure and urges contributors to use one-time passcodes and security keys as their preferred 2FA method.

Lastly, GitHub announced that it’s testing support for passkeys internally with employees. The company highlights that this security feature should provide better protection against sophisticated phishing attacks and other exploits.

View Details

MC526130 – Microsoft is making some changes to the default configuration for new tenants for Azure B2B integration with SharePoint & OneDrive.

When this will happen:

Starting March 31, 2023, new tenants will have Azure B2B Integration with SharePoint & OneDrive enabled by default. 

How this will affect your organization:

This message is for your information and there is no impact to existing tenants or tenants created before March 31, 2023. 

What you need to do to prepare:

No change is needed for existing customers. New tenants can opt out of using Azure B2B Integration using the SharePoint Online Management Shell.

Please click Additional Information to learn more.

Additional information

View Details

MC526129 – The Advanced deployment guides & assistance page is getting revamped to help you manage data in your tenant. We’ll differentiate deployment tasks based on your license: Office 365 E3, Microsoft 365 E3, Office 365 E5, and Microsoft 365 E5.

This message is associated with Microsoft 365 Roadmap ID 117373

When this will happen:

Standard Release: This will begin rolling out in mid-March.

How this will affect your organization:

We’re updating this deployment guide to provide clarity on Microsoft 365 E3/E5 and Office 365 E3/E5 functionalities when managing an organization’s content, records, and governance strategies. The steps provided will allow you to manually or automatically apply governance to emails, files, messages, and content based on the settings chosen. The additional features will allow admins to upload file plans for current retention labels used in the organization, create an adaptive scope to identify locations where labels are applied, and proactively manage mailbox content with the relocation of the Exchange (Legacy) portal.

What you need to do to prepare:

If you’ve bookmarked sections of the Advanced deployment guides & assistance page, those links will redirect to the new Deployment guides’ section. You might need to make IT staff in your org aware of the new navigation. You don’t need to do anything to prepare for the changes on setup.microsoft.com.

Additional information

View Details

MC526127 – Microsoft Whiteboard is making Whiteboard tabs in Teams configurable using Teams app permission policies. This provides more control and flexibility to enable or disable Whiteboard tabs in Teams and complements the already existing meeting policy for Whiteboard in Teams meetings.

When this will happen:

Rollout will begin in early March and is expected to be complete by mid-March.

How this will affect your organization:

Whiteboard will become configurable via Teams app permission policies. This change applies to Whiteboard tabs but does not change Whiteboard in meetings or Teams Annotations.

Tenants who have the policy of “Allow specific apps and block all others” for Microsoft apps will need to add Whiteboard to the list of specific apps once this change is in place to keep Whiteboard tabs functioning.

What you need to do to prepare:

Verify if you are using “Allow specific apps and block all others” in the Teams Admin Center. If so, add Whiteboard to the list of allowed apps. Please note that Whiteboard will not appear until after it has rolled out to your tenant, so you will need to check after March 15, 2023.

Please click Additional Information to learn more.

Additional information

View Details

MC526126 – Soon, Viva Connections will include an analytics experience. Use analytics to understand how and when users engage with components of the Viva Connections experience, popular content types, and the platforms used to access the app.

This feature is associated with Roadmap ID 93367

Note: Viva Connections analytics data is aggregated and cannot be tracked to an individual user.

When this will happen:

The Viva Connections analytics experience will start rolling out to your organization in March and will be completely rolled out by early April.

How this will affect your organization:

Viva Connections Analytics is available to users who have Site Member (or higher permissions) on the organization’s SharePoint home site. More specifically, user with “Full Control”, “Edit”, “Design” and “Contribute” access should have access.

How to opt out of Analytics:

Viva Connections analytics can be turned off by setting the DisableVivaConnectionsAnalytics parameter to off using PowerShell in the M365 Admin Center (MAC). Get more details about the PowerShell command.

What you need to do to prepare:

You do not need to do anything to prepare for the analytics experience. Viva Connections Analytics data can be viewed from the SharePoint home site by selecting the Settings gear, then select Manage Viva Connections, and then select View analytics. Learn more about how to access the report, the metrics provided, and metric definitions.

Additional information

View Details

MC525664 – Microsoft is renaming file viewer webpart to ‘File and Media’ to make this webpart inclusive of more file types like videos.

When this will happen:

Standard Release: Microsoft will begin rolling out in mid-March and expect to complete rollout by mid-April 2023.

How this will affect your organization:

Users will see the new name for the webpart. Functionally, nothing changes w.r.t. the capabilities of the webpart. This is a step to educate users about the capabilities of the webpart beyond Word, Excel, PowerPoint, PDF and extended to videos as well.

View Details

MC525663 – Microsoft is updating the SharePoint Online Site Sharing backend to use Azure B2B Invitation Manager instead of the legacy SharePoint Invitation Manager.

This message is associated with Microsoft 365 Roadmap ID 117557

When this will happen:

This change will begin rolling out in late February, and complete rollout by end of April.

How this will affect your organization:

Today, sharing just the SharePoint site goes through the original SharePoint Invitation Manager which always creates guest users in your organization’s directory. Microsoft is now updating this flow & experience to use the Azure B2B Invitation Manager instead. The sharing flow will remain identical to what users see today, but external recipients will now go through your organization’s B2B Invitation Manager experience.

What you need to do to prepare:

You may want to review your Azure B2B Invitation Manager policies.

Additional information

Help and support

View Details

MC525662 – Microsoft Teams App Developers will soon be able to target applications to select geographies (countries/regions) via partner center. Developers, at times, build applications that are only relevant in a few countries or regions for operational reasons or for adhering to different compliance requirements across countries & regions. Once this change rolls out, Microsoft Teams app users will only be able to see apps that are applicable for their country or region.

This message is associated with Microsoft 365 Roadmap ID 100974

When this will happen:

Standard Release: Rollout will begin in mid-April and is expected to be complete by late April.

How this will affect your organization:

Currently, Microsoft Teams users can see all Teams apps from the App store. When this update rolls out, Teams users will only see apps based on their country or region.

What you need to do to prepare:

There is no specific action you need to take at this time. You can still manage all apps from the Teams Admin Center. In case your users need to access apps outside of their country or region they can go to Microsoft AppSource, search across all Microsoft Teams apps and install any app from there.

This feature does not limit users from installing apps outside of their country/region but will only hide these apps from the Teams App Store.

View Details

MC525660 – Microsoft is introducing two new list templates with the Approvals app integration. With this change, Microsoft Lists templates, specifically Travel Requests with approvals and Content Scheduler with approvals, will begin to leverage integration with the Approvals app in Microsoft Teams.

This message is associated with Microsoft 365 Roadmap ID 100502

When this will happen:

Targeted Release: Microsoft will begin rolling out in early March 2023 and expect to complete rollout by late March 2023.

Standard Release: Microsoft will begin rolling out in early May 2023 and expect to complete rollout by mid-May 2023.

How this will affect your organization:

In a new list created using either of these two templates, users can create a list item and submit it for approval by creating an approval request and specifying the approver, the request will appear in the Approvals app in Teams or can be approved directly within the list. Once approved, the list item status is updated.

The new list templates will automatically appear on the Create list from the template screen. This is an optional feature that users can leverage by using one of the two new list templates.

View image in new tab

What you need to do to prepare:

No action is required by admins to enable this.

View Details

Microsoft is getting ready to launch its Microsoft Loop app in public preview later this month. Microsoft Loop has been available in private preview since November, allowing users to collaborate with their colleagues across Microsoft 365 apps.

Microsoft Loop is based on Microsoft’s Fluid Framework, and it has three main structural elements: Loop components, Loop pages, and Loop workspaces. First up, Loop components are live pieces of content that work across multiple Microsoft 365 apps. These include tables, checklists, bulleted lists, and numbered lists. Loop components are updated in real time and can be shared in Microsoft Teams and Outlook.

Additionally, a Loop page is a document that allows users to share and collaborate on one or more Loop components. Loop workspaces make it easier for users to track and organize their Loop pages. For instance, users can organize related Loop pages in different groups or sections, which is particularly useful for large projects. Microsoft says that multiple users will be able to collaborate on Loop pages and workspaces.

How to prepare for the public preview of Microsoft Loop?For now, Microsoft Loop will be disabled by default, and it will be up to the IT admins to enable it in their tenants. “The Loop app is entering a public preview phase. It is default off and does not yet meet all of Microsoft’s compliance capabilities. Regulated organizations will note that we are still working on features such as eDiscovery, Sensitivity labeling, and others. A more complete list of these capabilities will come in future roadmap updates,” the company explained on the Microsoft 365 admin center.

To prepare for this release, Microsoft suggests IT admins to enable the Loop app in their organization. The company notes that IT Pros can control Microsoft Loop with a Microsoft Cloud Policy. They will first need to create a Security Group for all users and then deploy the Loop setting to that group. Furthermore, Loop components across the Microsoft Suite can be controlled separately from the Loop app, and you can find more details on this support page.

Microsoft Loop vs. NotionMicrosoft continues to improve the collaboration experience to help businesses adapt to this new hybrid work era. Microsoft wants to position its Loop app as a strong competitor to popular productivity solutions such as Notion.

Microsoft Loop and Notion offer several features to enhance content creation, project management, and note-taking experiences. However, Microsoft Loop has an edge over Notion because it’s seamlessly integrated into the Microsoft Office ecosystem. Do you think that the Loop app can help to improve your productivity? Sound off in the comments section below.

View Details

Microsoft has warned that threat actors are increasingly using business email compromise campaigns to target enterprise customers. The company has found that it could be challenging for the victims to identify and mitigate the attacks on time.

Business email compromise (BEC) is a type of cyberattack that lets hackers use phishing emails to request payments or gain access to sensitive information. The threat actor impersonates a trusted individual (like an executive or customer) to convince the target to take a specific action. The FBI 2021 Internet Crime Report revealed that BEC attacks increased by 65 percent from July 2019 to December 2021.

Microsoft explained that the attacker used a phishing technique called adversary-in-the-middle (AiTM) to get the session cookie and bypass multi-factor authentication (MFA). They signed in to the target account and spent two hours searching for email threads to hijack. The next step involves using homoglyph characters to register deceptive domains similar to the legitimate website.

The cybercriminals made a rule to move and hide emails in a different folder. They also emailed the business partner and asked them to send money to an account they owned. After that, the threat actors deleted the email so the compromised user wouldn’t notice. Microsoft says that its Microsoft 365 Defender alerted about the BEC attacks around 20 minutes after the email was deleted from the mailbox. The solution disabled the compromised account to mitigate the cyberattack.

Timeline of the BEC campaignMicrosoft 365 Defender disrupted 38 BEC attacksMicrosoft highlighted that the tool uses AI-based detection capabilities to mitigate 38 BEC attacks targeting 38 enterprise customers. “In our testing and evaluation of BEC detections and actions in customer environments faced with real-world attack scenarios, dozens of organizations were better protected when accounts were automatically disabled by Microsoft 365 Defender,” Microsoft explained.

If you’re interested, you can learn more about the BEC attack disruption capabilities available in Microsoft 365 Defender in our previous post.

View Details

The Intel vPro platform was first announced by the chip maker back in 2007, and it designates a collection of advanced CPU technologies for business PCs. As of today, it provides various features to increase security and manageability to support IT departments in organizations of all sizes. In this article, I’ll explain how the Intel vPro platform works and how features like Active Management Technology (AMT) allow IT pros to remotely manage devices in a secure manner.

What is the Intel vPro platform?Intel vPro is a platform that provides a set of hardware and software technologies designed to enhance the security and manageability of business PCs. It is supported by a wide range of business-class devices from major computer manufacturers.

Over the years, vPro has become an important platform for businesses that require high levels of security, manageability, and performance for their computer fleets. It combines hardware-level security and remote management capabilities with advanced performance features such as Intel’s Thread Director technology (more on that below).

Intel’s vPro platform is designed for business PCs (image credit: Intel)Intel vPro vs EVO: What’s the difference?Both Intel vPro and the more recent Intel EVO brand offer several unique features that cater to different target audiences. While the Intel vPro platform is targeting business users, the EVO platform is targeting mainstream consumers and “prosumers.”

Here are some of the key differences between them both.

| Feature | Intel vPro | Intel EVO | | Security | Offers very comprehensive hardware-level security features | Provides security features such as hardware-based threat detection and identity protection | | Compatibility | Supported by a wide range of business-class devices | Supported by different high-end devices from various manufacturers | | Manageability | Remote management capabilities | No remote management capabilities |

Are Intel vPro CPUs faster?Intel vPro CPUs are not necessarily faster than other CPUs: Performance will depend on the overall configuration of the system. The primary purpose of Intel’s platform is to provide additional security and management features to business and enterprise-level users.

There are power differences between mobile and desktop Core i5, i7, and i9 CPUs. The “K” SKU with a 125W Thermal Design Power (TDP) includes the most powerful CPUs with professional-grade performance for intensive workloads such as multimedia creation or data analysis. Additionally, some CPUs are optimized for specific use cases such as the Xeon processors designed for server and workstation environments.

Where can we find Intel vPro CPUs?Intel vPro CPUs can be found in a wide range of form factors, including desktops, laptops, mobile, and workstations. They are commonly used in business and enterprise-level devices that require advanced security and management features. That includes:

  • Desktop computers: Business-class desktops, including mini PCs, all-in-one desktops, and tower desktops.
  • Laptop computers: Business-class laptops, including ultrabooks, traditional laptops, and rugged laptops.
  • Workstations: High-performance workstations used for intensive tasks such as video editing, 3D rendering, and scientific simulations.
  • Servers: In server environments, these CPUs can provide advanced security and remote management capabilities.

What are the Intel vPro features for IT pros?Here are the top features providing a secure and efficient platform for business users.

Intel Active Management Technology (AMT)Intel Active Management Technology allows IT administrators to remotely manage and maintain devices even when they are powered off or unresponsive. Some of the features of AMT include remote power, hardware, and security management along with remote data wiping ability.

AMT operates at the firmware level, making it independent of the operating system. That’s why it can be used to remotely manage and maintain devices even in the cases of faulty or corrupt operating systems.

Intel Hardware ShieldIntel Hardware Shield is a hardware-based PC protection feature that is integrated into vPro processors. It provides additional protection against a range of security threats including firmware-level attacks, rootkits, and ransomware. Intel Hardware Shield is an accumulation of several different Intel technologies including Threat Detection Technology and Trusted Execution Technology to provide an additional layer of security for companies to better manage their employees.

Lastly, this technology also offers below-the-OS security to minimize the risk associated with malware injection and prevent planted malware from causing damage. It also helps to ensure your PCs launch into a trusted state.

Intel Virtualization TechnologyIntel Virtualization Technology (VT) is a set of hardware features that enable the creation of virtual environments on a single physical machine. It allows multiple operating systems including Windows, Linux, and others along with associated applications to run independently and securely on the same hardware, without interfering with each other. Some of the key features include hardware-level virtualization, improved security, and support for multiple operating systems.

Intel Endpoint Management AssistantIntel Endpoint Management Assistant (EMA) is a cloud-based remote management platform designed to help IT administrators manage and secure all organizational endpoints including firewalls. EMA also allows businesses to perform remote management and monitoring, asset management, and data security management of devices even when they are powered off or in a non-operational state.

The Intel Endpoint Management Assistant (image credit: Intel.com) Intel Identity Protection TechnologyIntel Identity Protection Technology (IPT) is a hardware-based security technology that provides an extra layer of protection for online accounts and transactions. It uses two-factor authentication, which requires both a password and a physical token, such as a USB key or a smartphone to verify a user’s identity. IPT also provides a secure environment for sensitive data and transactions, protecting against malware and other threats.

Intel Stable IT Platform Program (SIPP)The Intel Stable IT Platform Program (SIPP) helps individuals, IT teams, and organizations maintain stability and consistency in their computer hardware and software environments. It’s designed to provide a stable platform for businesses and IT departments, allowing them to better manage their IT infrastructure more efficiently and reduce the overall cost of ownership. The SIPP program specifies a set of hardware and software requirements that ensure compatibility and stability across different generations of Intel processors.

What are the different Intel Core vPro CPUs?The latest 12th Gen Core vPro CPUs include mobile and desktop processors for Windows PCs that support DDR5 and LPDDR5 memory, 1 Gbps and 2.5 Gbps Ethernet, Wi-Fi 6E, and Thunderbolt 4. The company’s 12th gen CPUs also support Thread Director, a new feature that makes Windows assign the right task to either performance cores or efficient cores.

The family of 12th Gen vPro CPUs includes 4 different categories of processors:

  • Intel vPro Enterprise for Windows: The full-featured solution for big organizations looking for business PCs with modern management capabilities.
  • Intel vPro Essentials: These CPUs are best for SMBs and they include Intel’s Hardware Shield and device management capabilities with Standard Manageability.
  • Intel vPro Enterprise for Chrome: These CPUs for business Chromebooks.

Intel vPro Enterprise for ChromeIntel also extended its vPro set of features to Chrome OS to allow businesses and organizations to have a comprehensive set of manageability and security features.

How much do Intel vPro CPUs cost?The cost of vPro CPUs can vary depending on the specific processor, manufacturer, and model that you choose. However, these CPUs are priced higher than other CPUs due to their additional security features and capabilities.

For a few processors, Intel directly redirects you to partner retailers where you can directly buy the processors. More information about the pricing and the associated systems of the Intel vPro processors can be found on Intel’s website.

Are Intel vPro CPUs worth it?PCs with Intel vPro CPUs are worth the premium money because they offer advanced hardware-enhanced security features, remote management capabilities, and business-class performance. computing. These features are particularly valuable for enterprise, business, and IT professionals who need to manage and secure a fleet of devices and associated resources.

View Details

This Week in IT, I talk to Stephen Rose about whether ChatGPT is just marketing hype or will it really change the way we do everything. Plus, Stephen shows me the new integration between Windows 11 ‘Moment 2’ Phone Link and iOS, and we discuss whether organizations will be willing to pay a premium for A.I. features in Microsoft 365.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Fabian Bader: Protecting Azure AD hybrid identity and Microsoft DefenderFabian Bader is a cyber-security architect and Microsoft MVP. In this week’s Cloud Conversations episode, he joins Ru Campbell to talk about:

  • Changing tactics to protect domain controllers and on-premises Active Directory
  • Microsoft Defender for Identity as part of your hybrid identity security
  • Why FIDO2 is critical and a level up compared to traditional MFA
  • The intricacies of Defender for Endpoint exclusions and tamper protection

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft has just announced a new ChatGPT integration coming to its Azure OpenAI Service. This release enables developers to add custom AI-powered capabilities to build their next-generation applications.

Microsoft partnered with OpenAI to launch the Azure OpenAI Service in private preview in November 2021. It’s a cloud-based solution that allows developers to access OpenAI’s powerful language models (GPT-3 and Codex) and create data-driven applications. Azure OpenAI Service helps with natural language processing tasks, including semantic search, code generation, and content summarization.

Microsoft highlights that the new ChatGPT integration will help developers to create intelligent solutions for businesses. Some common scenarios include improving existing chatbots, automated claims processing, and recapping call center conversations. Microsoft says businesses can also create new ad copies with personalized offers for customers.

“Customers and partners can also create new intelligent apps and solutions to stand out from the competition using a no-code approach in Azure OpenAI Studio. Azure OpenAI Studio, in addition to offering customizability for every model offered through the service, also offers a unique interface to customize ChatGPT and configure response behavior that aligns with your organization,” said Eric Boyd, Corporate Vice President for AI Platform.

How much does it cost to use ChatGPT in Azure OpenAI Service?Microsoft notes that the new ChatGPT integration is currently available in preview in Azure OpenAI Service. The feature is priced at $0.002/1k tokens and provides improved security, compliance, and lower latency for enterprise customers. The company plans to begin billing for ChatGPT usage on March 13th, and you can find more details on the Azure OpenAI Service support page.

View Details

Microsoft has announced the general availability of Delivery Optimization in Windows Update for Business reports. The new Delivery Optimization report provides important data points that enable customers to track the performance of Windows update delivery across an organization.

Windows Update Delivery Optimization is a feature that enables Windows devices to download and share software updates with other PCs on the same network. This feature utilizes peer-to-peer networking technology to distribute updates, which ultimately helps to reduce bandwidth consumption.

Microsoft launched Windows Update for Business reports back in November 2022. It’s a cloud-based solution that allows IT admins to track the deployment status of feature, quality, and security updates on Windows 10 and 11 devices. The service also provides valuable insights to identify devices that are not up-to-date and troubleshoot issues.

The Delivery Optimization Window Update for Business report provides insights about how software updates got delivered during the last 28 days. It includes Delivery Optimization stats such as total bandwidth savings, download volume, and device count.

“We genuinely appreciate those of you who participated in the public preview! You helped us verify the accuracy of the new data tables and revise the layout. Your responses helped us identify and address all critical issues, so it can now be offered to all Delivery Optimization users,” Microsoft explained.

IT admins can customize the Delivery Optimization Window Update for Business reportsMicrosoft says that IT admins can customize the Windows content delivery data into dashboard views. The report shows the peering status as a pie chart and configuration names & device counts as a bar graph. There are also separate tabs for commonly used group settings such as City, ISP, Country, and GroupID.

As a reminder, Microsoft is planning to replace its Update Compliance solution with Windows Update for Business reports. The company will kill off the Update Compliance service for all existing users at the end of this month. If you’re interested, you can learn more about Windows Update for Business reports on this support page.

View Details

Microsoft Edge is getting a new update that will allow enterprise customers to securely save files to OneDrive on mobile devices. The new security feature is currently available for Edge Insiders in version 111 on iOS and Android devices.

Previously, some organizations prohibited users from saving files to local device storage on mobile devices. This measure helped IT administrators in preventing malicious actors from gaining unauthorized access to sensitive enterprise data. Microsoft aims to address the problem by providing a secure way to save, access, and share files from the Edge mobile app.

“We heard time and again from customers that their users needed a way to save files without compromising security. Saving files to OneDrive (instead of locally) offers a simple solution that allows users to easily save, access, and share files from the Edge mobile app while respecting security parameters set their enterprise,” the Edge Insider team explained.

According to Microsoft, the new file-saving experience joins the existing security features available in the Edge browser. For instance, Microsoft allows IT Pros to manage the Edge mobile app with Intune’s App Protection Policy (APP). It’s also possible to restrict the sharing of browser data with Outlook, OneDrive, and other Microsoft 365 apps.

How to enable the secure file-saving experience in Microsoft EdgeMicrosoft has detailed a couple of prerequisites to use this new security feature in the Edge mobile app.

  • First of all, enterprise customers will need to use their Azure AD accounts to log on to the Microsoft Edge mobile app.
  • IT admins will need to assign Intune App Protection Policy (APP) to all end users.
  • Finally, administrators will need to allow OneDrive in the “Allow user to save copies to selected services” setting.

Microsoft is planning to add the ability to view files stored in OneDrive for Business or SharePoint directly within the Microsoft Edge mobile app. This feature can be useful for customers who don’t want to download Microsoft Word, Excel, PowerPoint, and PDF documents. Microsoft Edge is also getting a built-in VPN functionality that will help users to protect sensitive data against security threats.

View Details

Microsoft announced yesterday several new features for developers at its Azure Open Source Day 2023. The company explained that these capabilities enable software developers to quickly build intelligent applications.

“Most companies have leveraged AI to improve efficiency and costs. Large AI applications leveraging natural language processing (NLP), automatic speech recognition (ASR), and text-to-speech (TTS) are becoming prevalent, but what powers these applications is the underlying infrastructure optimized for large AI workloads. Azure is the best place to build AI workloads,” explained Eric Boyd, CVP for AI Platform.

First up, Microsoft has announced the public preview of new Vision Services that help developers to create computer vision apps across industries. Vision Services provide several features such as background removal, smart cropping, automatic captioning, image search, model customization, and video summarization. Microsoft has also introduced new AI controls to help users with real-time alerts, environment analysis, and movement tracking.

Microsoft announced its plans to launch foundation models in Azure Machine Learning. The new service will enable users to deploy pre-trained open-source foundation models for various machine-learning tasks, such as multi-modality and natural language processing. It eliminates the need for users to manage and optimize dependencies manually.

Microsoft unveils new Responsible AI Toolbox additionsMicrosoft has recently introduced two new open-source tools to increase the adoption of responsible AI practices. The Responsible AI Mitigations Library makes it easier to mitigate errors in Machine Learning models.

Finally, the Responsible AI Tracker extension lets users view models, code, and visualization artifacts within the same framework. Microsoft claims that it should help to speed up the model interaction and evaluation process. You can check out Microsoft’s blog post to learn more about new capabilities announced at the Azure Open Source Day 2023.

View Details

Microsoft has announced that it’s deprecating Remote PowerShell (RPS) for Exchange Online in new tenants next month. The company will begin blocking RPS connections for all new Exchange Online customers on April 1, 2023.

“Today, we are announcing that starting April 1, 2023, we will start blocking RPS connections for all tenants created on or after April 1, 2023. After April 1, 2023, new tenants will not be able to use RPS when connecting to Exchange Online and will have to use the v3 module with REST cmdlets instead,” Microsoft explained.

Microsoft originally announced its plans to deprecate the use of the Exchange Online PowerShell v2 module in December 2022. The company built RPS to let IT admins use local workstations for managing Exchange 2010 on-premises servers. However, Remote PowerShell uses Basic Authentication that is subject to password spray attacks in organizations. Moreover, it also lacks support for the multifactor authentication (MFA) mechanism.

Microsoft launched the new REST-based Exchange Online management v3 module to boost security in September 2022. The company has already started deprecating Remote PowerShell for Exchange Online v2 in favor of v3, with a complete cut-off in July 2023. However, Microsoft found that many IT admins still use RPS to communicate with Exchange Online.

Update to Exchange Online PowerShell v3 moduleMicrosoft recommends Exchange Online customers to switch to the v3 PowerShell module as soon as possible instead. The company claims that the latest version supports modern authentication and it’s more secure as compared to the older PowerShell modules. Moreover, it includes a couple of new features and performance enhancements.

Microsoft acknowledged that many administrators might face challenges in migrating to the Exchange Online PowerShell v3 module. The company plans to let IT Pros delay the deprecation of Remote PowerShell in their tenants. “We heard your concerns related to deprecation timelines. We will soon release a tool to allow tenant admins to request an extension to use RPS for a little longer. We will keep you posted,” Microsoft added.

View Details

Remote and virtual desktop solutions provide a flexible way for users to access remote services securely while maintaining control of how the users access those services. In this article, I’ll explain how FSLogix can optimize remote and virtual desktop environments by leveraging Profile Containers and Application Masking. I’ll also detail the FSLogix features allowing users to provide customized, user-based access to applications in a virtual desktop environment.

How FSLogix Profile Container and Application Masking optimize the VDI experience Providing a consistent experience as users log into non-persistent or shared desktops is an essential factor in the success of a remote and virtual desktop environment. Microsoft acquired FSLogix in 2018, and it is the recommended way to manage user profiles in Azure Virtual Desktop environments.

FSLogix is not limited to use with Microsoft solutions. It is available to use with Citrix, VMware Horizon, and other virtual desktop infrastructure (VDI) platforms to manage user profiles and the desktop experience.

There are three main components included with FSLogix:

  1. Profile Container
  2. Application Masking
  3. Java Version Control

FSLogix Profile Container creates a container on a network share that holds the user’s profile. The profile is available as the user moves between different computers in a remote or virtual desktop environment, providing a consistent desktop experience with non-persistent and multi-user desktops.

Departments or business units within an organization require access to unique combinations of applications. Managing images with different collections of applications can be time-consuming in these environments. FSLogix Application Masking simplifies image management by dynamically hiding and blocking access to applications based on user or group membership. This leads to fewer images to manage while limiting access to applications on those images.

Lastly, Java Version Control allows administrators to specify versions of Java for web applications based on a URL. Java Version Control only works with Internet Explorer. Internet Explorer has reached its end of life, and I won’t cover Java Version Control in this article.

How FSLogix Profile Container worksFSLogix provides a way to centralize user profiles so they can be accessed as users log into different computers. Centralizing profiles provides a consistent desktop experience in shared, non-persistent, and multi-user desktop environments.

When a user who is enabled for FSLogix Profile Container logs into a computer, the FSLogix application checks the network share for a profile. Then, the Profile Container is mounted if it exists. If not, one is created and then mounted. The Profile Containers are in a .VHD or .VHDX virtual disk format.

The FSLogix application redirects profile reads and writes to the Profile Container on the network share. Some profile items, such as temporary files or session-specific information, do not need to be stored in the profile container. A file with the format “Local_UserName” is created on the local computer to store these items. This folder is removed once the user logs off.

FSLogix Profile Container overview (Image credit: Petri/Travis Roberts)Office Containers The Profile Container stores all user data by default. Sometimes, it may be desirable to separate Office 365 data into a separate container. Separating Office 365 data is possible with FSLogix Office containers.

Office 365 data is a cached copy of Office 365 data, Outlook .OST files, and the local OneDrive cache. For example, Office 365 data is easily recreated from the Microsoft online copy.

By splitting Office 365 data, we can limit the amount of data backed up and replicated for disaster recovery preparation. Also, separating the Office 365 data into a different Profile Container will spread profile reads and writes across multiple file shares, potentially increasing performance.

How Office 365 Containers work (Image credit: Petri/Travis Roberts)Cloud Cache With traditional Profile Containers, only one file share location is used for profiles and another file share for Office 365 data, if used. However, some organizations require a low recovery point objective (RPO) for their business continuity and disaster recovery plans.

FSLogix Cloud Cache offers near real-time profile redirection to multiple file share locations. Cloud Cache uses multiple file locations simultaneously, keeping all copies updated with changes.

Cloud Cache leverages the computer’s local drive to build a profile cache when the user logs in. The cache is populated with profile data from one of the remote shares. The profile reads come from the cache. Profile writes are written to the local cache, then asynchronously to the profile shares. The remote profiles are kept up to date in near real-time.

How FSLogix Cloud Cache works (Image credit: Petri/Travis Roberts)The profile locations can be local, at a remote or disaster recovery site, or both. Should one copy become unavailable, the available copy is used. The offline location is brought up to date once it’s available again. This makes Cloud Cache a good option for high availability with failover to a remote site.

What happens when FSLogix Cloud Cache is unavailable (Image credit: Petri/Travis Roberts)Cloud Cache is a good option for high availability, but there are some things to consider before implementing it:

  • User log-ons can be slower as FSLogix builds the local profile from the remote cache.
  • Logoffs can be slower as FSLogix updates all changes to the remote locations at logoff.
  • The time between logons and logoffs can be faster as all profile reads and writes occur locally at the cache. Therefore, using fast local disks with Cloud Cache in multi-user environments is important.
  • Fast local disks are required to avoid read-and-write contention.

How FSLogix Application Masking worksImage management requires significant time and effort in environments with various applications and many business units. Each department has its own catalog of applications that must be available to end users. Creating images for virtual and remote desktops that meet the application requirements can lead to multiple images, and managing these multiple images can be time-consuming and complex.

FSLogix Application Masking lets us control what applications users have access to on the client operating system. For example, an organization can reduce the number of images by adding more applications to a smaller number of images. Access to the applications is granted or denied with Application Masking based on the user, group membership, or other factors.

App Masking rules are created with the Application Masking rule editor. The rule editor can be found in the FSLogix installation files. The rule editor has the option to create a blank rule, a rule from a program file path, or select an installed application.

App Masking Rule Editor (Image credit: Petri/Travis Roberts)Here’s what you can do in practice:

  • You can use the rule editor to add one or more applications to the rule.
  • Next, add the rule assignments after adding the applications to the rule.
  • After that, apply the assignment to a user, group, process, network location, computer, directory container, or environmental variable.
  • The assignments can apply to the target or not apply to the target. That allows for granular control over how the rule is applied.

App Masking Rule Assignments (Image credit: Petri/Travis Roberts)FSLogix Application Masking streamlines the image creation and management process. More applications can be added to a smaller number of images, reducing image management overhead. Application Masking controls access to the application with rule assignments.

What do you need to use FSLogix? Eligibility to use FSLogix is dependent on Microsoft licensing. The list below shows the license eligibility to use FSLogix:

  • Microsoft 365 E3/E5
  • Microsoft 365 A3/A5/ Student Use Benefits
  • Microsoft 365 F1/F3
  • Microsoft 365 Business
  • Windows 10 Enterprise E3/E5
  • Windows 10 Education A3/A5
  • Windows 10 VDA per user
  • Remote Desktop Services (RDS) Client Access License (CAL)
  • Remote Desktop Services (RDS) Subscriber Access License (SAL)
  • Azure Virtual Desktop per-user access license

FSLogix can be used in public or private data centers. It supports Windows 7 clients, Windows Server 2008 R2, and newer client and server operating systems.

Summary FSLogix Profile Container solves the problem of profile management by creating a central location for user profiles, then attaching those profiles to user sessions as they move between computers in a virtual or remote desktop environment. In addition, FSLogix Profile Container provides a way to split Office 365 data into its own profile container, and it can keep multiple copies of profile containers up to date in near real-time with Cloud Cache.

Lastly, FSLogix Application Masking simplifies image management by managing access to applications installed on the image. Users are restricted to only the applications they need access to with App Masking rules. Overall, FSLogix Profile Container and Application Masking are really helpful tools for optimizing your user’s VDI experience.

View Details

MC524212 – Microsoft is introducing a default change for Excel Windows desktop apps that run XLL add-ins: XLL add-ins from untrusted locations will now be blocked by default.

For XLL add-ins in files from untrusted locations, you will no longer be able to enable content with a click of a button. A message will appear notifying you of the risk and a link to get more information about possible workarounds and support. This change will help you stay more secure by blocking popular attack techniques.

This message is associated with Microsoft 365 Roadmap ID 115485

When this will happen:

Preview: Microsoft has already completed rolling out to Insiders preview.

Standard Release: Microsoft will begin rolling out early March and expect to complete by late March.

How this will affect your organization:

Users in your organization will not be able to open Excel XLL add-ins from untrusted locations. Steps to make locations a trusted location is provided in our support article.

What you need to do to prepare:

If your organization uses any Excel XLL add-ins, follow the steps provided in our support article to ensure those add-ins are coming from a trusted location.

Help and support

View Details

MC524210 – Microsoft will be retiring the Groups and Yammer Verticals from Microsoft Search in Bing in April 2023. This change aligns with our overall promise to customers to keep our enterprise search platforms (Bing, Office.com, SharePoint) coherent.

When this will happen:

We’ll be gradually rolling this out in early April, and the roll out will be completed by the end of April.

How this affects your organization:

Users will no longer be able to access the dedicated Groups and Yammer Verticals when this change is implemented.

View image in new tab

What you can do to prepare:

Instead of using the Groups and Yammer Verticals, Microsoft recommends looking for Groups/Yammer information within the remaining verticals.

View Details

MC524208 – This feature would allow users to easily get location recommendations for emergency location. Confirming the location via the autosuggest will mark the location as an assist driving emergency call directly to PSAP. Microsoft will still allow manual location confirmations.

This message is associated with Microsoft 365 Roadmap ID 94692

When this will happen:

General Availability: Microsoft will begin rolling out early March and expect to complete by mid-March.

How this will affect your organization:

There are no admin changes required.

What you need to do to prepare:

There is no action needed to prepare for this change.

Additional information

View Details

Microsoft has started rolling out a new system-preferred authentication policy in preview for Azure AD customers. The feature enables the system to evaluate which authentication method should be used when a user signs in to Azure AD.

With system-preferred authentication, Azure AD will check all authentication methods registered for an account and only show the strongest option. However, the system will continue to use usernames/passwords for accounts that don’t have a registered MFA method.

“For example, if a user registered both SMS and Microsoft Authenticator push notifications as methods for MFA, system-preferred MFA prompts the user to sign in by using the more secure push notification method. The user can still choose to sign in by using another method, but they’re first prompted to try the most secure method they registered,” Microsoft explained.

Microsoft notes that the new system-preferred authentication policy will be disabled by default. It will be up to the IT admins to turn on this feature for users in their tenant with MSGraph API. In April, Microsoft will add a new toggle to let administrators configure the policy through the Azure AD admin center.

Microsoft to enforce system-preferred authentication for all Azure AD accounts in JulyOverall, the system-preferred authentication policy is a part of Microsoft’s ongoing efforts to improve the security of Azure AD accounts in organizations. Last year, Microsoft warned about the increasing use of MFA fatigue attacks by threat actors to target enterprise customers. The Microsoft Authenticator app recently added support for number matching and location details to boost security.

Microsoft plans to enable the system-preferred authentication policy for all Azure AD accounts in July 2023. We invite you to check out this support page for details about configuring the system-preferred authentication policy.

View Details

Microsoft has announced that its Outlook for Mac client is now available as a free app on Apple’s App Store. The company detailed yesterday that users no longer need a Microsoft 365 subscription or paid license to use the macOS version of the Outlook app.

“The Outlook for Mac app complements Outlook for iOS – giving people a consistent, reliable, and powerful experience that brings the best-in-class experience of Outlook into the Apple ecosystem that so many love,” Microsoft explained. “We are rebuilding Outlook for Mac from the ground up to be faster, more reliable, and to be an Outlook for everyone.”

Microsoft is continuing to improve the new Outlook for Mac experience that launched in February 2022. The company mentioned that it has optimized the Outlook for Mac app to run faster on Apple Silicon devices. The design language of the app is consistent with the macOS and it supports unified mailboxes. It provides support for Gmail, Outlook.com, Microsoft 365, Yahoo Mail, POP, IMAP, and iCloud.

Outlook for Mac to add support for new Outlook Profiles featureMicrosoft has also announced several new features coming to the Outlook for Mac app. The company is adding a new feature that will let users view their upcoming events in Outlook. Microsoft is also planning to integrate a new Outlook Profiles feature with the Focus mode on macOS. It will enable users to assign specific accounts to different profiles to avoid distractions.

Outlook ProfilesMicrosoft has been testing its new web-based Outlook app on Windows PCs for quite some time now. However, the company mentioned that it has no plans to launch a progressive web app (PWA) version of Outlook for Mac.

“Just to be clear, the new Outlook for Mac is a native macOS app. Microsoft plans to continue building and maintaining best-in-class native apps on macOS and iOS. There is no plan to build a web app version of Outlook for Mac,” Microsoft added.

If you’re interested, you can download Outlook for Mac from Apple’s App Store. Have you tried the new Outlook for Mac experience? Let us know in the comments section below.

View Details

Pure Storage, the US-based company known for its innovative flash-based storage solutions recently unveiled FlashBlade//E, a new cost-effective solution for managing unstructured data using flash storage. The new offering follows the launch of the FlashBlade//S family last year that brought a modular architecture that separates compute from capacity.

“Where FlashBlade//S is tuned for critical, high-performance workloads that consistently require cutting-edge high performance, FlashBlade//E addresses capacity of all unstructured repository workloads while helping you address cost and power utilization,” explained Amy Fowler, VP & General Manager, FlashBlade at Pure Storage.

Pure Storage promises that organizations interested in moving away from disk-based systems due to management and budget reasons now have a more sustainable and scalable alternative with FlashBlade//E. The company compared the transition to disk-based storage to all-flash unstructured data storage as “the shift from incandescent to LED,” with FlashBlade//E using one-fifth of the space and power and improving reliability by a 10x-20x factor.

How Pure Storage’s FlashBlade//E worksFlashBlade//E is a scalable system that starts with 2 chassis, with one EC chassis mixing storage and compute and another EX chassis for storage. Each chassis takes 5U of rack space, and there are also two external fabric modules (XFMs) taking 1U each.

How Pure Storage’s FlashBlade//E works (Image credit: Pure Storage)With this basic configuration, organizations get 4 petabytes of storage space with up to 16x100GbE connectivity. As FlashBlade//E is highly scalable, customers will be able to add more chassis and storage at under $0/20 per GB.

Pure Storage announced that FlashBlade//E will be generally available by the end of April 2023. While exact pricing details are currently unknown, customers interested in a pay-as-you-go model will be able to deploy FlashBlade//E through a new service tier of Pure’s Evergreen//One Storage as-a-Service subscription. Lastly, you can register to a March 15 webinar to get more information about this new product.

View Details

As Microsoft puts it, teams and channels are where ‘real work gets done’. Let’s look more closely at Teams channels vs chats.

Microsoft Teams is a complex tool that allows users to collaborate using a mixture of apps provided by Microsoft 365, like OneDrive files, SharePoint libraries, Microsoft Lists, Planner, Approvals, and many others. In this article, I’m going to help you understand Microsoft Teams channels vs. chat.

What is a team in Microsoft Teams?A team is a collaboration space for internal groups and you can set who has access to each team. For instance, you might give everyone in your organization access to a team or restrict it to specific people. Teams are subdivided into channels. There will always be at least one channel in a team.

A SharePoint portal added as a tab in a team channel (Image Credit: Petri/Russell Smith)Teams are good for organizing work that happens over a long period of time and they allow you to:

  • Create channels to organize files, apps, and posts
  • Add tabs for managing access to information or apps. You might add a tab that contains access to a Planner board for instance.
  • All channels have a Files tab by default. This allows you to organize files that are associated with a project and work on them together individually or in real time.
  • You can link meetings to your team
  • You can share channels with other organizations and add external users

Because teams need to be set up and structured, they are better suited to long term projects initiated in your department, location, or business.

More on Petri: How to Create a Team in Microsoft Teams

Using channels in Microsoft TeamsChannels let you organize work and information in a team. For example, each client project might have its own dedicated channel. You might have a sales team that works on selling different products. So, you could create several channels with information and apps connected to each product.

Posts in channels appear as threaded conversations (Image Credit: Petri/Russell Smith)Channels are a great way to organize information and keep it in one place so that it’s easy to find what it is that you need to complete a task or project. It could be a file, a post, or information contained in an app.

When you are finished working on a project, channels can either be hidden from the list of channels associated with a team or archived.

Channels can be hidden by users and archived by a Teams administrator (Image Credit: Petri/Russell Smith)When you add a new channel to a team, you can choose to give everyone on the team access or restrict the new channel to specific people. The Shared Channels feature also makes it easier for you to give business partners access to a channel if you need to share the information outside of your organization. Shared channels allow you to share one channel with external users instead of a whole team.

Team members can adjust the notifications they get from a channel. Unlike chat, where notifications are set globally, users can configure notifications on a per-channel basis. You can opt to receive all notifications, none – expect direct replies and @mentions, or your own custom option. This can really help notification overload.

Customize notifications per channel (Image Credit: Petri/Russell Smith)More on Petri: How to Use Microsoft Teams Shared Channels

Microsoft Teams one-to-one and group chatsThe best way to think of chats in Teams is like a WhatsApp-style conversation. Chats can be one-to-one, with a group of people, and include external users. Chats are best suited to short term discussions that don’t require you to organize information or access tools that will help you to complete a project or task.

The biggest difference between chats and teams is that you can’t organize work into channels. In a chat, you can collaborate on files and add apps if you need to. It’s also worth noting that external users cannot upload files to chats.

A one-to-one chat in Microsoft Teams (Image Credit: Petri/Russell Smith)Chats are best suited to short term projects that are not likely to require a lot of organization. For example, you can use a chat to:

  • Share information during a meeting
  • Quick one-time collaboration on a document
  • General conversation that doesn’t need to be structured

The disadvantage of chats is they can become unwieldy fast. If a chat lasts many weeks, because the information is unstructured, it can be difficult to find the information you need. And topics can either be forgotten or work not completed because they get lost in the noise.

Using chats for long term projects and discussions is tough because you can’t manage and track the progress of individual conversations.

Getting stuff done with teams and channelsTo harness the full power of Microsoft Teams you need to set up teams in your organization. That’s not to say that chat doesn’t have a place in your collaboration strategy. But bear in mind, Teams chat doesn’t differ that much from WhatsApp, which you probably wouldn’t want to use for the serious business of getting stuff done.

View Details

Microsoft’s Windows Insider Program, which lets consumers and business users test new Windows 11 features ahead of their public release is getting an overhaul. Microsoft is launching a new Canary channel today while the existing Dev channel is getting a “reboot.”

Microsoft originally launched its Windows Insider Program back in the fall of 2014, almost a year before the release of Windows 10. The program has evolved quite a lot over the years, and Microsoft is probably aware that keeping up with Windows Insider updates isn’t exactly easy even for Windows enthusiasts.

Back in 2020, the company replaced the existing “rings” systems with “channels”: The Fast & Skip Ahead rings became the Dev channel, while the Slow ring became the Beta channel. Starting today, Microsoft is adding a new Canary channel to the mix.

What is the new Windows Insider Canary channel?According to Microsoft, the new Canary channel will be used to preview “platform changes” that require significant testing, including major changes to the Windows kernel, new APIs, and more. The company will use this Canary channel to test new features and improvements that may never ship. In practice, Microsoft says that “this is very similar to what we’ve been flighting to the Dev Channel in the past.”

Starting today, all devices that are currently receiving Dev channel builds will be moved to the new Canary channel, and they’ll continue to receive Windows 11 builds from the 25000 series. All Dev channel Insiders will be notified about this change via pop-up notifications and emails.

Microsoft also expects to release new Windows 11 builds for the Canary build more frequently, but not all of them will come with release notes. “We will not publish a blog post for every flight – only when new features are available in a build,” Microsoft said today.

Overall, the Canary channel will receive less stable builds and if that’s not for you, you’ll need to perform a clean install to get out of this channel. Going forward, the revamped Dev channel will be Microsoft’s recommended channel for most Insiders.

What happens with the “rebooted” Dev Channel?Microsoft says that the rebooted Dev channel will continue to provide early access to new Windows 11 features (including some that may never ship), but with better platform stability compared to the Canary channel. “This will be the place where we incubate new ideas and preview new features and experiences, not tied to a specific Windows release,” Microsoft explained today.

Insiders on the Dev channel will receive Windows 11 builds from the 23000 series, and all of them will come with detailed release notes. In some cases, some new Windows 11 features may come first to the Dev channel before they land in the Canary channel. That’s because Microsoft can now enable new features with Controlled Feature Rollout (CFR) technology.

This is often perceived as the most confusing aspect of the Windows Insider program, but Microsoft is testing new features with different Insider groups on purpose. “We will only communicate about features that we are purposefully enabling for Insiders to try out and give feedback on,” the company said.

Since nothing is changing for the Beta and Release Preview channels, Microsoft recommends Insiders on those rings who want to get early access to new features switch to the Dev channel. However, going back to the Beta and Release Preview channels will require a clean install since these two rings receive builds with lower build numbers.

The new channels of the Windows Insider programWhat does this mean for the Windows Insider Program for Business?The Windows Insider Program for Business uses the same channels as the regular Windows Insider Program, but it comes with extra features to help organizations participating in the program. IT admins with an Azure Active Directory domain can install and manage Insider builds across multiple devices using Group Policy, MDM solutions such as Intune, Configuration Manager, or Windows Server Update Services.

For all managed devices receiving Dev channel via Windows Update for Business policy, Microsoft Intune, or through Group Policy, Microsoft said today that “the changes to the policy to enable customers to opt-into the new Canary Channel via policy will be coming soon.” You can learn more about how to manage Windows 11 Insider builds across your organization on this page.

View Details

Microsoft announced this morning a new Microsoft Dynamics 365 Copilot solution. The new AI-powered tool allows customers to automate repetitive tasks for customer relationship management (CRM) and enterprise resource planning (ERP).

“Dynamics 365 Copilot takes advantage of recent advancements in generative AI to automate these tedious tasks and unlock the full creativity of the workforce. Dynamics 365 Copilot puts CRM and ERP to work for business users to accelerate their pace of innovation and improve business outcomes in every line of business,” said Charles Lamanna, CVP of Business Applications and Platform.

The new Copilot capabilities in Dynamics 365 Sales and Viva Sales let businesses write customers’ email responses and summarize Microsoft Teams meetings in Outlook. The AI-powered feature can also draft contextual answers to customers’ questions. Moreover, Copilot enables marketing teams to gain insights into customer segments. The data could be used to create target email campaigns in Dynamics 365 Customer Insights and Dynamics 365 Marketing.

In Dynamics 365 Business Central, the Copilot integration allows customers to quickly create e-commerce product listings. It’s possible to publish these product details on Shopify with a couple of clicks.

Microsoft Supply Chain Center gets new AI-powered Copilot featuresMicrosoft Supply Chain Center is also getting new Copilot capabilities to help organizations respond to potential supply chain issues. The tool automatically composes emails to notify impacted partners about disruptions such as weather, geography, and finances.

Lastly, Microsoft has introduced generative AI capabilities in Power Virtual Agents and AI Builder. A new conversation booster feature in Power Virtual Agents lets organizations connect the bot to websites or internal databases to respond to customers’ questions. Microsoft’s AI Builder tool is now powered by a new GPT model that brings text generation capabilities to Power Automate and Power Apps.

Microsoft says the new Copilot features are available in preview for business and enterprise customers. The company expects to make these updates generally available later this year, though there is no ETA yet. The Copilot feature is bundled with existing Dynamics 365 licenses at no additional cost, and you can check out the official blog post for more details.

View Details

Microsoft has announced the release of version 5.0 of the Microsoft Teams PowerShell module. The latest release brings major performance improvements and new filtering capabilities for the Get-CsOnlineUser cmdlet.

The Get-CsOnlineUser cmdlet is a PowerShell command that is used in Microsoft Teams to retrieve information about user accounts. It fetches information about the user name, email address, and more. Microsoft Teams PowerShell module 5.0 improves performance while retrieving accounts with filters. Microsoft has also introduced several new properties for filtering user accounts.

Additionally, Microsoft has added support for new filtering operators in the Get-CsOnlineUser cmdlet. The server-side filtering capability makes it easier for users to retrieve information. Microsoft has also introduced a new feature that lets IT admins get details of unlicensed users for 30 days.

What’s new in Microsoft Teams PowerShell Module version 5.0You can find the highlights for this 4.5.0 release below:

  • Performance improvements especially with “-Filter” scenarios like using wildcard operator (), OnPrem and Timestamp attributes.
  • New attributes have now been introduced in the output to ensure parity with scenarios involving the “-Identity” parameter: CountryAbbreviation, SipProxyAddress, TeamsMediaLoggingPolicy, UserValidationErrors, WhenCreated.
  • These attributes are now enabled for filtering: Alias, City, CompanyName, CompanyName, HostingProvider, UserValidationErrors, OnPremEnterpriseVoiceEnabled, OnPremHostingProvider, OnPremLineURI, OnPremSIPEnabled, SipAddress, SoftDeletionTimestamp, State, Street, TeamsOwnersPolicy, WhenChanged, WhenCreated, FeatureTypes, PreferredDataLocation, LastName.
  • These filtering operators have been reintroduced into Get-CsOnlineUser:
  • “-like” operator now supports use of wildcard operators in ‘contains’ and ‘ends with’ scenarios. Example: Get-CsOnlineUser -Filter “DisplayName -like ‘abc'”
  • “-contains” can now be used for filtering on properties that are an array of strings like FeatureTypes, ProxyAddresses and ShadowProxyAddresses. Example: Get-CsOnlineUser -Filter {FeatureTypes -contains “PhoneSystem”}
  • “-gt” (greater than), “-lt” (less than), “-le” (less than or equal to) can now be used for filtering all string properties. Example: Get-CsOnlineUser -Filter {UserPrincipalName -gt/-le/-lt “abc”}
  • “-ge” (greater than or equal to) can now also be used for filtering on policies. Example: Get-CsOnlineUser -Filter {ExternalAccessPolicy -ge “xyz_policy”}
  • Updates to type of users displayed:
  • Unlicensed Users – Unlicensed users would show up in the output for 30 days post license removal.
  • Soft deleted users – These users will be displayed in the output with SoftDeletionTimestamp set to a value.

As always, you can use the Update-Module command to install to the latest version of the Microsoft Teams PowerShell module. If you’re interested, you can learn more about how to create and manage teams with Microsoft Teams PowerShell on this page.

View Details

Microsoft has introduced a new feature that allows customers to configure an app instance property lock for Azure AD enterprise applications. The new capability helps organizations prevent attackers from making any changes to sensitive properties of multi-tenant application objects.

OAuth is a security protocol that enables users to share information about their accounts with third-party websites. It uses a token-based authentication process to provide access to resources and data, without requiring users to share their usernames and passwords. OAuth is widely used by all major tech companies such as Microsoft, Facebook, and Google.

Previously, threat attackers have exploited credentials such as X.509 certificates to take control of enterprise applications. The technique allows hackers to gain access to organizations’ cloud environments and steal sensitive information. It was used in the infamous SolarWinds attacks back in 2021.

With property lock, IT admins can block any modifications to select or all sensitive properties of an app after it has been provisioned in a new tenant. “This feature provides application developers with the ability to lock certain properties if the application doesn’t support scenarios that require configuring those properties,” Microsoft explained.

How to configure app instance property lock for Azure AD appsMicrosoft detailed a couple of steps that can be used to configure an app instance lock with the Azure portal.

  • Sign in to the Azure portal.
  • Navigate to the top menu and click the Directories + subscriptions filter to switch to the specific tenant.
  • Select Azure Active Directory >> App registrations and then click the Azure AD application.
  • Select Authentication, navigate to the App instance property lock section, and select Configure.

  • Finally, select the lock settings in the App instance property lock pane and save the changes.

It is important to note that the Azure AD property lock feature is available in preview for all Azure AD customers. Microsoft encourages IT admins to configure it before their apps are used in other tenants.

Overall, the new property lock feature is a welcome addition that should help to strengthen data protection measures and prevent breaches in enterprise environments. However, Microsoft recommends that administrators remain vigilant and monitor their apps for any suspicious activities.

View Details

SQL Server is Microsoft’s premier data platform. While its core is a relational database engine, it also includes many other subsystems and capabilities that go far beyond just a relational database. In this tutorial, I’ll explain how to create two of the most important relational database components: databases and tables.

While not everyone realizes this at first, SQL Server provides business intelligence using Analysis Services, reports from Reporting Services, data integration using Integration Services, data validation with Master Data Services, business continuity using Azure and Availability Groups, and more. These are all of the features that businesses require from an enterprise data platform.

That said, the core of all of these services is relational data. SQL Server’s relational database engine runs on both Windows and Linux.

Understanding SQL Server databasesDatabases are the primary containers for your relational database objects. SQL Server lets you create your own user databases, and some of the main relational database objects include tables, schema, indexes, views, logins, and roles. In addition, SQL Server provides a number of built-in system databases including the master, model, msdb and tempdb databases.

Creating an SQL Server databaseSQL Server databases and database objects like tables can be created in a variety of ways. SQL Server Management Studio’s (SSMS) Object Explorer has a menu option that enables you to create a table interactively.

However, the most basic way to create databases and other database objects is by executing Transact-SQL (T-SQL) commands. T-SQL commands are text-based, and they’re usually executed using either the SSMS Query Editor or Azure Data Studio.

Using the CREATE DATABASE statementCreating a SQL Server database using T-SQL command is pretty straightforward. You can do it by using the CREATE DATABASE command like the one below:

CREATE DATABASE myDatabase; This T-SQL command created a database named myDatabase. As you might guess, you can specify the number of additional parameters.

We’ve created an SQL Server database named myDatabase (Image credit: Petri/Michael Otey)Understanding SQL Server tablesOnce you have created a user database, you can begin to create tables and other database objects in the database. Databases typically have many different tables.

Tables are structures that contain raw data. Table names are descriptive, and their data is organized by rows and columns. You can access this data using T-SQL queries.

Columns and data types in an SQL Server tableEach column in an SQL Server table has a specified column name and data type that represents the values that will be stored in the column. This is essentially the column definition.

A data type is an attribute that specifies the type of data that the column can hold. Some of the most common data types include:

| Int | Stores whole numbers | | Bigint | Stores whole numbers larger than the standard integer | | Smallint | Stores small integers to save storage space | | Bit | Stores 0, 1, or NULL | | Decimal | Stores fixed precision decimal numbers | | Numeric | Stores fixed precision numbers | | Money | Stores monetary data | | Float | Stores floating precision numbers | | Real | Stores larger floating precision numbers | | Datetime | Stores date and time values from January 1, 1753 to December 31, 9999 | | Date | Stores only date from January 1, 0001 to December 31, 9999 | | Time | Stores only time only values with an accuracy of 100 nanoseconds | | Char | Stores fixed width character strings with a maximum of 8,000 characters | | Varchar | Stores variable width character strings with a maximum of 8,000 characters | | Varchar (max) | Stores variable width character strings with a maximum of 1,073,741,824 characters | | Text | Stores variable width character strings with a maximum of 2,147,483,647 characters |

Table 1 – SQL Server data typesCreating an SQL Server table with the CREATE TABLE StatementJust as there are different ways of creating SQL Server databases, there are also a number of ways to create tables. SQL Server Management Studio has an interactive Table Designer, but the most basic way to create tables is by executing the T-SQL CREATE TABLE command.

The CREATE TABLE command is typically executed using either the SSMS Query Editor or Azure Data Studio. There are a lot of options when it comes to creating tables. You can incorporate constraints, foreign keys, advanced data types like FILESTREAM and XML, and even make partitioned tables. However, the basic table syntax is fairly simple.

You can see a basic example of a T-SQL CREATE TABLE command below:

USE myDatabase;GOCREATE TABLE dbo.myLogins ( id INT NOT NULL PRIMARY KEY, name VARCHAR (20), login\_date DATETIME ); GO In this example, the USE T-SQL command specifies which SQL Server database will be the current database that will be used by any following commands. The semi-colon indicates the end of a T-SQL statement within a batch of commands. The GO command signals the end of a batch of commands.

Next, the CREATE TABLE statement is used to create a table named myLogins. You may notice the schema name of dbo, which is the default schema of every database for all users. An SQL Server schema is essentially a tag for database objects that allows you to group and secure related database objects into separate namespaces.

The three columns in our table are defined inside the parenthesis. This simple example uses three columns: id, name, and login_date. Each column has a defined data type, and they do not have a default value. The id column is an INT and it acts as an identifier for the row. The name column is a VARCHAR and login_date is a DATETIME data type.

The three columns in our table have a defined data type (Image credit: Petri/Michael Otey)In case you were wondering, tables can have a maximum of 4096 columns – although in practice you would never want to use anywhere near that. You can learn more about the complete syntax of the command from the Microsoft documentation CREATE TABLE.

Creating a Primary Key and a clustered IndexOne thing you may notice about the id column is that it uses the PRIMARY KEY keyword to specify that it is the primary key for the table. The primary key should contain unique values. The NOT NULL keyword means that the column must have a value. In other words, it cannot contain a null value.

A primary key is not required, but most tables use them. A table can have only one primary key constraint, and it can consist of single or multiple columns. The purpose of the primary key is to uniquely identify each row in a table.

SQL Server automatically creates a clustered index when you create a primary key. The clustered index causes all of the rows that are stored in the table to be in the same order as the primary key. This typically improves access efficiency.

Querying tables using the T-SQL SELECT statementData gets stored in tables using the T-SQL INSERT statement, and it is usually retrieved using the T-SQL SELECT statement. Likewise, table data is updated using the UPDATE statement and it is deleted using the DELETE statement.

Querying tables can be an involved topic as you have the ability to select the rows and columns that you want, as well as join multiple related tables together and retrieve the results. However, the basic SELECT statement is fairly simple.

The following SELECT statement will retrieve all of the rows and columns from my myLogins table:

SELECT id, name, login\_date FROM myLogins (Image credit: Petri/Michael Otey)Creating an SQL Server table from another table using SELECT INTOA variation of the SELECT statement can be used to create new tables that are a copy of an existing table. The SELECT INTO statement will create a new table and insert the resulting rows from the query into that table. You can see an example of the SELECT INTO statement in the following listing.

SELECT * INTO myLogins2 FROM myLogins; This will create a new table named myLogins2. As a shortcut, you can use ‘SELECT *’ to retrieve all of the columns from a table.

This practice is fine for occasional ad hoc queries. However, this is not a good practice for your applications as you can wind up retrieving more data than you need, which would result in needlessly increasing the system’s overall workload.

SummaryIn this article, I detailed the basics of using databases and tables, which are core components of the SQL Server relational database engine. Most tables are permanent structures but you can also create temporary tables. Primary key constraints can be used to uniquely identify and retrieve each row. In addition, you can use foreign key constraints to specify relationships between tables.

View Details

This Week in IT, I show you the future of search engines in action! Microsoft’s Bing Prometheus is set to revolutionize search with its integration of ChatGPT. Join me as I unveil the lightning-fast speed and accuracy of Bing Prometheus in answering your questions!

View Details

Microsoft has released an update that brings new premium capabilities for Microsoft Defender Vulnerability Management. The new security features provide comprehensive assessments to help IT admins track and mitigate security risks in their most critical assets.

Microsoft Defender Vulnerability Management is a security tool that uses AI to detect, analyze, prioritize, and fix vulnerabilities in enterprise networks. It provides a centralized dashboard and automated patch management capabilities that make tracking and managing known vulnerabilities easier.

With this release, IT admins can use customized profiles to analyze and monitor all endpoints against STIG, CIS, and other industry security benchmarks. The security baselines assessment helps to detect changes in real time and eliminates the need to run time-consuming compliance scans.

“Microsoft Defender Vulnerability Management has provided foundational vulnerability management capabilities such as device discovery, inventory and vulnerability and configuration assessments. Our new generally available premium capabilities provide advanced assessments to give in-depth visibility into the potential exposure to your assets,” Microsoft explained.

Microsoft Defender Vulnerability Management hardware and firmware assessment provides details about device manufacturer, processors, and BIOs information. It should help to protect customers against increasing hardware and firmware-level attacks. Moreover, the network share configuration assessment aims to ensure secured access to files and folders shared with people on the network.

The authenticated scan feature enables IT admins to run scans on unmanaged Windows devices and mitigate software vulnerabilities. It’s also possible to gain entity-level visibility into digital certificates and browser extensions installed across endpoints within the organization.

Microsoft Defender Vulnerability Management can now block vulnerable applicationsMicrosoft has recently introduced a new feature that enables customers to block known vulnerable versions of applications. Once enabled, end users will see a notification informing them that the vulnerable app has been blocked on their Windows device. However, users will be able to click the “Allow” button to open the application.

Application blockMicrosoft notes that the new premium capabilities are available for Microsoft Defender for Cloud and Microsoft Defender for Endpoint Plan 2 customers. However, organizations that don’t have a Defender for Endpoint Plan 2 subscription can use the Microsoft Defender Vulnerability Management Standalone solution with their existing EDR tools.

View Details

The security researchers at ESET issued a security advisory about the BlackLotus vulnerability this week. The research warned that the BlackLotus flaw can now bypass Secure Boot even on fully updated Windows 11 PCs.

Secure Boot is a security feature that prevents unauthorized software (malware) from running on Windows machines. Almost all modern hardware with UEFI firmware supports this feature, which ensures that Windows PCs will only boot with trusted programs from the Original Equipment Manufacturer (OEM).

Kaspersky first discovered the BlackLotus bootkit back in October 2022. It exploits a year-old CVE-2022-21894 vulnerability to bypass the secure boot process on Windows systems. Microsoft patched the security flaw in January last year. Moreover, a proof-of-concept for the vulnerability has been publicly available since August 2022.

According to ESET malware analyst Martin Smolár, the flaw can still be exploited because the signed binaries have not been added to the UEFI revocation list. The attackers leverage the CVE-2022-21894 vulnerability to deploy the bootkit’s files to the EFI system partition (ESP). It allows the hackers to disable various security tools on the victim’s machines. These include Windows Defender, Hypervisor-protected Code Integrity (HVCI), and BitLocker encryption.

BlackLotus execution overviewAdditionally, BlackLotus enables malicious actors to deliver a kernel driver and an HTTP downloader. The kernel driver prevents users from removing the bootkit files from ESP. Moreover, the HTTP downloader is designed to download and execute payloads.

What are the mitigations and remediation strategies to block the BlackLotus malware?ESET recommends that organizations should keep their Windows PCs and security solutions updated to block the attack vector. However, customers can mitigate the attacks by reinstalling the operating system on infected Windows systems and removing the attackers’ (Machine Owner Key) MOK key with the mokutil utility. We invite you to check out ESET’s blog post for more details.

View Details

It’s been a busy month. Microsoft started testing the next Windows 11 ‘moment’, plus the Unified Update Platform (UUP) is coming to WSUS and ConfigMgr at the end of March. And Microsoft is now officially supporting Windows on Arm on Apple silicon. And much more! So, let’s get started.

Windows 11 ‘Moment’ dropsMicrosoft announced February 28 that it was releasing its next ‘moment’ update for Windows 11. It’s available for testing as an optional download via Windows Update but it won’t be pushed out more generally until mid-March. And only for those on Windows 11 22H2.

Let’s take a look at what it includes.

Updated search experienceThe biggest change is that the Search box on the taskbar is now ‘typable’. Before, you clicked Search and it would open a dialog where you start typing your query. Now, you can type your query directly in the Search box on the taskbar and press ENTER to open the dialog to get a list of results.

Additionally, the dialog has been updated to accommodate Prometheus, the new Bing A.I. search engine that is currently available in preview to users who have signed up.

More on Petri: Microsoft Bing ‘Prometheus’ – A First of Its Kind A.I. Model

Updated Search in Windows 11 22H2 Moment (Image Credit: Microsoft)Interestingly, Microsoft says that the search box is one of the most widely used features on Windows. It has more than half a billion users every month. So, it’s no wonder Microsoft won’t let you change the search engine used in Windows to anything other than Bing.

Phone Link for iOSThere’s a preview of functionality that will allow meaningful interaction between Microsoft’s Phone Link app, previously Your Phone, and iOS devices. Phone Link will now allow iPhone users to send and receive messages and calls, and see notifications. Although there’s no mention of photos at the moment.

Phone Link iOS Windows 11 (Image Credit: Microsoft)The functionality being offered at this stage in Phone Link uses a Bluetooth connection between the iOS device and PC. Which is how Intel Unison works, although Unison already has support for viewing and transferring photos.

Android users aren’t left out. They are getting a richer experience. Providing you have a Samsung phone that is. Microsoft has made it easier to activate the personal hotspot with a single click in the list of Wi-Fi networks on your PC. That’s quite cool. And it’s easier to transfer browser sessions from Samsung smartphones to Windows PCs using the Recent Websites feature.

Windows Studio EffectsWindows Studio Effects are now available from the taskbar in Quick Settings. Windows Studio Effects is only available on devices with compatible hardware.

Microsoft Teams for Windows 11I’m not sure who is using the consumer version of Teams that’s integrated with Windows 11, but Microsoft has worked to improve the experience with this update. Including a fully revamped chat experience where you can preview your video and go straight to a call or share a call link. You can also navigate between conversations in Chat in one window.

Quick Assist redesignedAside from a slightly new look, the app is now easily accessible from the Start menu. Plus, a new laser pointer can be used to highlight anything you need on the screen.

New widgetsNew widgets from Microsoft and third parties include:

  • Phone Link
  • Xbox Game Pass
  • Meta
  • Spotify

Updated touch experienceWhen you detach your keyboard from a touch device, the taskbar now slides away to give you more screen real estate. And if you need to get it back, you just swipe up from the bottom of the screen to expand it.

Screen recording in the Snipping ToolIf you didn’t have a third-party tool, screen recording was available in Windows in a round about kind of a way through the Xbox Game Bar. And it wasn’t ideal for sure. Now, screen recording is built directly into the Snipping Tool.

Notepad gets tabsFile Explorer got tabs at the tail end of 2022. Now it’s the turn of Notepad. Not much to say about this but I think it’s a welcome feature.

New energy recommendationsThe Settings app brings new energy recommendations. The updated interface lets you more easily understand the choices you have to configure your PC to be more power efficient.

Windows 11 Energy Recommendations (Image Credit: Microsoft)Recommended Files is A.I. poweredIf you are running Windows 11 Pro devices and higher that are joined to Azure Active Directory (AAD), then you can benefit from the new A.I. powered Recommended Files feature on the Start menu. As far as I can work out, before it just showed you a list of recently accessed files.

Microsoft also mentions ‘fastest every file search to recommended local and cloud files’ in File Explorer. I’m not sure if this is a change in this update or just a mention of what already exists in the form of the Quick access, Favorites, and Recent sections under Home in File Explorer. Most likely the latter.

New Windows 365 app for Cloud PCsThe Windows 365 app is now generally available in the Microsoft Store.

More on Petri: Microsoft’s New Windows 365 App Brings Cloud PCs into Windows 11

More on Petri: What IT Pros Need to Know About the Latest Windows 11 Feature Update

Windows 11 now supported officially on Apple SiliconNo, this is not the return of Bootcamp. But Microsoft now officially supports Windows 11 on Arm running in a virtual machine (VM) on Apple hardware. Parallels 18 makes it easy for you to set up Windows 11 in a VM. And this is a good stopgap solution while we wait for actual hardware that can run Windows 11 on Arm natively with the same speed and battery life afforded to Apple users.

More on Petri: How to Install Windows 11 on a Mac with Parallels Desktop

File Explorer moving to Windows App SDKIn a live WinUI Community Call this month, Microsoft revealed that it was working to move File Explorer to the Windows App SDK and WinUI 3, which is the evolution of UWP apps. Microsoft says the rebuilt File Explorer will be available in the Windows Insider Preview Program soon.

More on Thurrott.com: Microsoft is Moving File Explorer to the Windows App SDK

.NET Framework updates to require less reboots and Unified Update Platform comes to on-premises update technologyLess reboots is always a good thing. This month Microsoft said that .NET Framework updates would require less updates when at the end of March, the Unified Update Platform (UUP) becomes available to on-premises WSUS and ConfigMgr setups.

UUP has been available for devices updating from the cloud using Microsoft Update for several years. Microsoft says that UUP is “a single publishing, hosting, scan and download model for all types of OS updates … for everything from monthly quality updates to new feature updates”.

All Windows 11 22H2 and later updates will be delivered using UUP starting from the end of March. And those updating from Windows 10 to Windows 11 22H2.

Once you are on Windows 11 22H2 or later, you can benefit from UUP and .NET Framework updates with less reboots. And a better update experience overall, including:

  • More control over installation time
  • More seamless updates
  • Better battery life
  • Lighter download size
  • And more

More on Petri: Microsoft Introduces the On-Premises Unified Update Platform for Seamless Windows Updates

Adobe Acrobat is coming to Microsoft EdgeMicrosoft said this month that it will be partnering with Adobe to bring Acrobat PDF features to its Edge browser. This will involve natively embedding Acrobat PDF code in the browser to deliver a more complete experience compared to the current PDF viewer in Edge.

More on Thurrott.com: Microsoft is Bringing Adobe Acrobat PDF to Edge

Windows users can now escape the Insider Preview Program until March 8th, 2023Apparently, Microsoft is letting you off-ramp windows so that you can unenroll devices from the Windows Insider Program. You have the chance until March 8, 2023. But only if you are currently on Build 22621.1325 or 22623.1325.

Windows Subsystem for Android February updatesWindows Insiders got an update for the Windows Subsystem for Android this month, bringing improvements for the camera, graphics, and general reliability and security updates. The updates include:

  • Better audio input latency and reliability
  • Improved framerate performance
  • Fixed zooming out (in apps)
  • Latest Chromium WebView (version 108)
  • Android 13 security updates

And that’s it for another month!

View Details

As part of Microsoft’s ongoing investment in its Power Platform, the company recently published its Power Platform 2023 release wave 1 plan, which details new features that will be released between April and September 2023. In the meantime, the company introduced several new features for PowerBI and Dataverse in February, so let’s take a look at the main highlights.

Power BI gets new reporting features and moreNew reporting features have been added to Power BI, such as conditional formatting based on string fields. Formatting rules can be set up to color columns in a bar chart based on the string value specified.

In this example from Microsoft, the rule checks to see if the string value is “Audio” and colors the bar red if it evaluates to true. Additionally, users can format image height and width in a table or matrix, add indentation capabilities in a text box, and access new accessible report themes. You can check out some examples on the PowerBI blog.

Formatting rules can be set up to color columns in a bar chart (Image credit: Microsoft)An upcoming security feature for Power BI is the enhancement of sensitivity labels and a Power BI app for Teams. Microsoft will support sensitivity labels in the service to classify and restrict data traveling from Power BI to Office, for example in an export or live connection in Excel. This will apply to sharing, dashboards and reports, and embedded visuals.

One way your security admin will be able to set this up is to specify which Azure Active Directory groups can access data with a certain label in Microsoft Purview Information Protection. Then a user will be able to apply that label to a report protecting data. This is set to enter public preview in June.

Dataverse improvementsTo address delegation limitations in Power Apps, Microsoft has introduced new delegable capabilities for the RemoveIf and UpdateIf Power Fx functions for Dataverse. Since Dataverse is the primary data source for Power Apps, Microsoft has focused on making more functions delegable, such as Search. This feature will be generally available in April.

Microsoft is also improving the Dataverse experience, enabling users to use their SharePoint lists more effectively by accessing choices, Boolean, and attachment data. Personal environments, also known as developer environments, can be created at make.powerapps.com. Power Platform admins can govern the creation of personal environments and manage them within their tenants.

Makers can now build applications using Microsoft Dataverse in a personal environment without any added license cost. The personal environment allows makers to experience all the capabilities of Dataverse and is limited to 2GB storage per environment. This feature will also be available for public preview in April 2023.

Lastly, makers will be able to create virtual tables in Dataverse using existing data from sources such as SQL and SharePoint without migrating the data into Dataverse. This will allow makers to work with data from SQL directly in a model-driven app and create relationships between virtual tables and other Dataverse tables.

The process of creating virtual tables has been made easier with a guided, step-by-step wizard in Power Apps, making it accessible to all makers. This feature will allow makers to read and update data sourced in SQL and SharePoint and create new relationships with existing data.

Microsoft’s Power Platform retains its leading position in Gartner’s 2023 Magic QuadrantOverall, all these improvements should make it easier for developers to work with data and create more powerful apps and reports. At this rate, Microsoft should remain a leader in the Low-Code Application field for years to come. Actually, the 2023 Gartner Magic Quadrant for low-code app platforms recently confirmed Microsoft’s leading position in the market, naming them a leader for the fourth year in a row.

As an independent company, Gartner looks at a company’s “completeness of vision” combined with the “ability to execute” to determine their placement in their quadrant. They have evaluated Microsoft as high in both areas, therefore naming them a leader in the field. Microsoft believes this “underscores our command in the market, materialized in amazing innovations built by more than 7.4 million monthly active developers of Microsoft Power Platform.”


View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Paul Huijbregts, Justen Graves, and Joe Anich on Microsoft Defender for EndpointPaul Huijbregts, Justen Graves, and returning guest Joe Anich join Ru Campbell to talk about Microsoft Defender for Endpoint in-depth. They have a new book that offers a comprehensive guide to building a deeper understanding of Defender for Endpoint, its capabilities, and successful implementation. They also talk about:

  • Microsoft Defender for Endpoint product history, going all the way back to the 90s
  • The cool tips and advice the book offers
  • Hidden gems and misunderstandings of Defender for Endpoint
  • And much more!

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft has launched the public preview of its Azure Operator Nexus service. It’s a next-generation hybrid cloud platform that allows communication service providers (CSPs) to run their workloads both on-premises and on Microsoft Azure.

Microsoft’s Azure Operator Nexus platform debuted in private preview in 2022. It’s designed for customers performing network functions, including virtual radio access network (vRAN), packet core, subscriber data management, and more.

Azure Operator Nexus expands on Azure Operator Distributed Services that launched last year. It provides features like Hybrid AKS, Mariner Linux, Arc, observability, and life cycle management. Azure Operator Nexus offers support for NUMA Alignment, CPU Pinning, and Layer 2 Networking. These capabilities are not available in other cloud services such as Azure IaaS.

“Operator Nexus enables operators to use cloud technology to modernize and monetize their network investments—lowering total cost of ownership (TCO), driving operational efficiency and resiliency with advanced AI and automation, improving the security of highly distributed, software-based networks,” explained Jason Zander, Executive Vice President for Strategic Missions and Technologies.

Additionally, Microsoft has announced its new Azure Operator Nexus Ready program. It allows network operators to integrate containerized network functions (CNF) and virtual network functions (VNF) into their mobile networks.

Microsoft announced the public preview of two AIOps servicesMicrosoft released Azure Operator Insights and Azure Operator Service Manager in public preview. Azure Operator Insights leverages AI to analyze large amounts of data collected from network operations and troubleshoot health issues. Moreover, the Azure Operator Service Manager tool enables network operators to gain insights regarding their network operations.

Last but not least, Microsoft announced the general availability of its Azure Private 5G Core solution. The Multi-Access Edge Compute service allows operators to deploy a 5G standalone network for customers with Azure Stack Edge.

View Details

Microsoft announced the release of the latest major update for Windows 11 this week. The company also announced the general availability of its Windows 365 app for Windows 10 and Windows 11.

Windows 365 is a virtualization service that enables business customers to access Cloud PCs from anywhere. It’s only available for business and enterprise customers. Up until now, users had to access Windows 365 desktops through a web browser. However, the new app integrates the service more deeply with Windows 11.

Microsoft first launched its Windows 365 app in public preview back in October 2022. It allows users to access their Cloud PCs directly from the taskbar or Start menu. It can be used in a window or in fullscreen mode. The Windows 365 app provides support for Microsoft Authenticator and Azure Active Directory multi-factor authentication.

“With the Windows 365 app, you can go from your desktop straight to your Cloud PC, which provides you with a personalized experience tailored to your settings, profile, and work style. It also reduces friction for IT administrators who can enable employees with single sign-on experience,” Microsoft explained.

Windows 365 gets new device management and provisioning capabilitiesMicrosoft has also announced some new capabilities for the Windows 365 web client. The latest update adds multimedia redirection (MMR) support to improve video playback performance on Cloud PCs. Microsoft explained that hardware acceleration is now turned on by default, which should help improve motion performance during video playback, moving windows, and scrolling.

Lastly, Microsoft released a new feature that lets users add more Azure Network Connection (ANC) to a provisioning policy and configure a priority order for their usage. It should improve the reliability of the provisioning process for customers experiencing capacity constraints in Azure regions. Microsoft notes that the Geography setting is now available in provisioning policies for US Government Community Cloud (GCC) and GCC High customers.

View Details

Microsoft has published a round-up of all the new features rolled out to Teams users during the month of February. The highlights include a new Microsoft Teams Premium plan, schedule send suggestions, Teams-certified devices, and management features. Here’s a look at everything you need to know:

Microsoft Teams PremiumMicrosoft introduced its OpenAI’s GPT-3.5 powered Teams Premium plan last month. The new premium tier of Microsoft Teams includes an intelligent recap feature that automatically generates recommended tasks, meeting notes, and highlights of meetings. Microsoft is also making Live translated captions available to premium customers. The feature will be available for a 60-day grace period for existing Microsoft Teams users.

Additionally, Microsoft Teams Premium enables IT admins to create custom meeting templates. This capability could be useful for scenarios like help desk calls, brainstorming meetings, and client calls. Moreover, it’s possible to define rules for different employee groups with custom user policy packages. The new premium version also provides support for branded meetings, organizational backgrounds, and together mode scenes.

Meeting templatesMicrosoft Teams Premium also brings advanced meeting protection capabilities for remote meetings. These include end-to-end encryption (E2EE), Microsoft Purview-powered sensitivity labels, and watermarking support for screen sharing. There are new controls to prevent participants from copying text and recording meetings. Other features include new Advanced webinars and Virtual appointment capabilities, and you can find more details in our previous post.

What’s new in Microsoft Teams (non-premium)Microsoft announced several new features for the non-premium version of Microsoft Teams. The company has enabled developers to create tab experiences for anonymous users in Teams meetings. Moreover, meeting organizers can now use bots to send in-meeting notifications to select participants.

Virtual Appointments (basic functionality)Microsoft introduced basic Virtual Appointments capabilities for all Microsoft 365 and Office 365 subscribers. Developers can use Graph APIs to programmatically create and manage Virtual Appointments. This release allows organizers to use the Virtual Appointments Teams meeting template to create an external meeting directly from a Teams calendar.

Chat & Collaboration/Calling featuresMicrosoft highlighted a bunch of new chat and collaboration capabilities added to Teams in February. A new feature lets users start a chat with distribution groups, Microsoft 365 groups, and mail-enabled security groups. Microsoft released a new Viva Insights-powered feature that lets users schedule messages in Teams chats. Microsoft noted that users can now catch up on missed calls directly from the activity feed.

Schedule send suggestionsMicrosoft released some updates to improve the calling experience in Microsoft Teams. The company added support for co-organizers to manage Breakout Rooms. Moreover, Microsoft updated the authentication mechanism to reduce the impact of outages. Customers will be able to access new call controls with Survivable Branch Appliance to deal with network outages.

New Microsoft Teams-certified devices and management featuresMicrosoft detailed some new devices certified for Microsoft Teams Rooms and personal peripherals. These include the following devices:

  • Lenovo ThinkSmart One collaboration bar and Lenovo Core Bundle for Teams Rooms on Windows
  • Crestron FLEX Microsoft Teams Rooms kit with the Dell OptiPlex for Teams Rooms on Windows
  • Yealink UH37 Dual/ Mono Headset

Finally, Microsoft introduced a couple of new management features for IT admins last month. It’s possible to view and manage third-party app subscriptions directly within the Teams client. Microsoft Intune now allows IT Pros to choose the type of content users can see on lock screen notifications on iOS and Android devices. Microsoft says IT admins can manage Surface Hubs as Teams devices from the Teams admin center.

View Details

MC521886 – Microsoft Teams: Insights about people in profile cards now coming to Microsoft Teams

This message is associated with Microsoft 365 Roadmap ID 116006

When this will happen:

Microsoft will begin rolling out in early March 2023 and expect to complete rollout by the end of March 2023.

How this will affect your organization:

To help you know more about people in your organization, Teams will begin surfacing information such as birthdays, LinkedIn posts, career changes, or pending meeting invites within profile cards. This is an existing feature in other Microsoft365 products such as Outlook, which is being brought to Teams.

More information on insights can be found here: Notifications and insights about people in Microsoft apps

What you need to do to prepare:

Nothing needs to be done to prepare. For users interested to learn more about this feature, please direct them to the help article: Notifications and insights about people in Microsoft apps

Help and support

View Details

MC521812 – Microsoft has released updates to the following update channel for Microsoft 365 Apps:

  • Current Channel

When this will happen:

We’ll be gradually rolling out this update of Microsoft 365 Apps to users on that update channel starting February 28th, 2023 (PST).

How this will affect your organization:

If your Microsoft 365 Apps clients are configured to automatically update from the Office Content Delivery Network (CDN), then no action is required.

If you manage updates directly you can now download this latest update and begin deployment.

What you need to do to prepare:

To get more details about this update view the following release notes:

  • Current Channel

Additional information

View Details

Microsoft has launched a new cloud-based Microsoft Intune Suite for enterprise customers. It’s a cost-effective plan that brings advanced endpoint management solutions, including Remote Help, Endpoint Privilege Management, advanced endpoint analytics capabilities, and Microsoft Tunnel for Mobile App Management.

“Microsoft Security and Microsoft 365 deeply integrated with the Intune Suite will empower IT and security teams with data science and AI to increase automation, helping them move simply and quickly from reactive to proactive in addressing endpoint management and other security challenges,” said Michael Wallent, CVP for Enterprise Mobility Management Products.

Microsoft Endpoint Privilege ManagementMicrosoft has announced the public preview of its Endpoint Privilege Management solution. The service is designed to reduce the burden on IT admins by providing temporary administrative rights to employees. It allows users to perform specific tasks on Windows devices such as installing software, setting up local printers, and managing other peripheral devices.

Endpoint Privilege Management is expected to hit general availability next month. It will be included in the Intune Premium Suite and also available as an add-on for Microsoft Intune subscribers.

Remote Help to add support for Android and Mac devicesMicrosoft launched its Remote Help solution on Windows back in April 2022. The tool enables IT admins to remotely log into any joined domain or Microsoft account desktop and troubleshoot issues. Microsoft has announced that Remote Help support is coming to Android and Mac devices. This release should make it easier for customers to manage Android devices used by frontline workers.

Microsoft Tunnel for Mobile App ManagementThe new Microsoft Intune plan also includes Microsoft Tunnel for Mobile App Management. It’s a new micro-VPN that allows employees to securely access on-prem applications and resources on their personal Android and iOS/iPadOS devices. It helps organizations to ensure user privacy and corporate data protection on BYOD devices.

Advanced endpoint analyticsThe new Microsoft Intune Suite provides advanced endpoint analytics features that let customers to proactively mitigate critical issues. Moreover, real-time insights make it easier for IT admins to enhance the user experience of employees in their organization. Microsoft’s new Intune Suite helps to manage specialty devices, including RealWear.

New Microsoft Intune Suite to get advanced app management featuresLastly, Microsoft announced its plans to add advanced app management capabilities to the Intune Suite. This release should enable administrators to easily deploy and automatically update apps in their tenants. Microsoft will also launch a new advanced cloud certificate management solution in the coming months. The service will eliminate the need for on-premises infrastructures to manage VPN and Wi-Fi certificates from Microsoft Intune.

Microsoft highlights that the new Intune Suite is available for all Microsoft Intune subscribers (including Microsoft 365 E3 and E5). It should help organizations to reduce management overhead and costs, simplify endpoint management and improve security against sophisticated attacks.

View Details

Microsoft released the first big update of the year for Windows 11 yesterday. The update improves the search experience on the taskbar by adding a new search box that integrates Microsoft’s new Bing AI, but there are other notable changes for the taskbar, the Start Menu, and more.

As of today, this feature update is available as an optional update for Windows 11 version 22H2. All the new features will roll out to all users with next month’s Patch Tuesday update. However, IT pros will be able to control what is being rolled out in their organization.

What’s new in this Windows 11 feature update?I’ve detailed yesterday the biggest new features in this new Windows 11 features, but here are the main highlights:

  • A new search box in the taskbar that provides access to the new Bing AI (if you’re enrolled in the preview).
  • Windows Studio Effects are now available from Quick Settings in the taskbar.
  • A new touch-optimized taskbar for 2-in-1 tablets that support two states: collapsed and expanded.
  • The Start Menu now displays AI-powered recommendations on devices that are joined to Azure Active Directory.
  • Enhanced support for braille devices and improvement for Voice Access.
  • New Energy recommendations in Settings.

Some of the new features that Microsoft announced yesterday such as Tabs in Notepad and the new screen recorder in Snipping Tool will roll out via Microsoft Store app updates. Microsoft is also improving its Your Phone app with new features for owners of high-end Samsung Galaxy phones, and the company is also testing iPhone support with select Windows Insiders.

The new search box on the taskbar will integrate Microsoft’s new Bing chatbot (Image credit: Microsoft)What does this mean for the Windows 11 release cycle?When Microsoft announced Windows 11 last year, the company explained the latest version of Windows would receive major updates once a year. Now that Windows 11 is on an annual feature update cadence, feature updates like Windows 11 version 22H2 receive 24 months of support for Home and Pro users and 36 months of support for Enterprise and Education editions.

It’s safe to say that Windows 10 getting major updates twice a year was too much for enterprise users. The company also ditched the bi-annual release cycle for Windows 10 updates, and the OS will now receive one “major” update every year until its end of support in 2025.

However, Windows 11 getting a major update once a year isn’t enough for Microsoft. That’s why the company now releases interim “Moment” releases with new features, as was the case this week. In a FAQ for IT pros posted yesterday, the company explained why it’s now releasing new features via interim releases instead of waiting for annual feature updates.

“We receive feedback that people want more from their Windows experience. By delivering new value through servicing technology more often, we can help your organization benefit from improved security, productivity, and collaboration today in a proven, reliable way without sacrificing quality,” the company explained.

Even though Microsoft believes that releasing new features when they’re ready should bring “value” to the majority of Windows 11 users, most enterprise users will prefer to have more stability. Fortunately, Microsoft provides controls for disabling new Windows 11 features coming throughout the year.

How IT pros can manage new Windows 11 featuresIn the same FAQ for IT pros published yesterday, Microsoft explained that the rollout of new Windows 11 features introduced outside of annual updates can be controlled on devices managed via Windows Update or WSUS. Moreover, features that may be disruptive for some organizations such as the new touch-optimized taskbar are off by default.

IT admins can now use a new client policy to control select features introduced via servicing. When the policy for “Enable features introduced via servicing that are off by default is enabled, new features will go live after a device reboot.

“For select features, we will also introduce new policies that enable you to configure the feature in a preferred way for your organization,” the company explained yesterday. “For example, for search on the taskbar, you can utilize the ConfigureSearchOnTaskbarMode policy to show the search box, search icon and label, search icon only, or hide search on the taskbar altogether.”

Lastly, IT pros should know that even though they can block new features introduced outside of annual updates, these features will still be included in the next annual feature update for Windows 11. In that case, that will be Windows 11 version 23H2, which should be released in the fall of 2023.

View Details

Last week, Microsoft released a new update that adds pod sandboxing support to its Azure Kubernetes Service (AKS). The new feature allows organizations to run modern applications on AKS in an isolated and secure environment.

Microsoft explained that it’s a standard practice to use Kubernetes for hosting and managing modern applications in cloud environments. However, one of the major drawbacks is that the service doesn’t provide robust support for multi-tenancy capabilities. This makes it impossible to host multiple customers or workloads within a single instance of Kubernetes.

According to Microsoft, modern applications that are bundled together as containers use the same operating system. Each container works like a separate process running on the computer which makes it challenging to keep the containers isolated from each other. This problem could be resolved by running each pod (a collection of containers) on a dedicated VM. However, this approach causes significant performance issues for customers.

To address this problem, Microsoft has developed a lightweight virtual machine (VM) infrastructure called Kata Containers. It’s compatible with Kubernetes and the container runtime interface (CRI) specifications. Microsoft explained that pods that target Kata Containers are treated by Kubernetes like all other containers. However, the process involves adding the containers to a lightweight virtual machine.

“Kata Containers on AKS are built on top of a security-hardened Azure hypervisor using Mariner Linux AKS Container Host (MACH). The isolation per pod is achieved by using a nested lightweight Kata VM that carves out resources from a parent VM node. In this model, each Kata pod gets its own kernel per nested Kata guest VM. This allows users to pack many Kata containers in a single guest VM, while continuing to run containers in the parent VM, providing strong Isolation boundary within a shared AKS Cluster,” Microsoft explained.

Kata Containers provides support for several Linux host and guest imagesCurrently, Kata Containers only support Linux host and guest images, including Clear Linux, Fedora, and CentOS 7. However, it’s also possible to create custom images for running other operating systems. Microsoft highlighted that the new feature should help to optimize operations for various industries such as health, finance, and ISV/SaaS Partners. You can find detailed instructions on how to use Pod Sandboxing with Azure Kubernetes Service on this support page.

It is important to note Google also provides a gVisor feature that works like a hypervisor to provide secure isolation between containers. It’s designed for enterprise customers that want to guarantee the security of their container workloads. Meanwhile, Amazon came up with its open-source virtualization technology called Firecracker. However, it has yet to get integration with Elastic Kubernetes Service (EKS) to ensure pods isolation.

View Details

Microsoft has started force-installing its Microsoft Defender for individuals app on Windows 10 and Windows 11 PCs. The company is sending out emails to inform Microsoft 365 subscribers that the app will now be automatically installed while installing or updating Microsoft 365 apps.

Microsoft launched its new cross-platform Defender app for consumers with Microsoft 365 Personal and Family subscription in June 2022. It provides a central hub for managing and monitoring the security status of all devices linked with a Microsoft account. The app can continuously scan new and existing security threats and provides real-time security alerts and tips to protect each device.

Up until now, the Microsoft Defender app worked as a complement to the built-in antivirus protection on Windows PCs. This means it was up to Microsoft 365 subscribers to download and install it from the Microsoft Store. Over the weekend, some users reported that Microsoft quietly began automatic installations of the Defender app on Windows 10 and Windows 11 devices.

“Starting in late February of 2023, the Microsoft Defender app will be included in the Microsoft 365 installer. That means that when you install the Microsoft 365 apps on your Windows device, the Microsoft Defender app will automatically be installed for you along with the other apps,” Microsoft explained in a support document.

Source: TwitterMicrosoft 365 app update to auto-install Microsoft Defender on Windows devices Microsoft also mentioned that an upcoming update for the Microsoft 365 apps may automatically install Microsoft Defender on Windows PCs that do not have it installed already. Users will be able to open the app from the Start menu and sign in with their personal Microsoft accounts.

Microsoft Defender for individuals provides the same level of protection it offers to protect business customers from malware. Microsoft also added new identity theft protection capabilities to make the app even more useful for consumers. The Microsoft Defender app is currently available in select markets, and you can find the full list on this support page.

View Details

Microsoft is releasing today a major update for Windows 11 version 22H2. This update introduces a new search box in the taskbar that integrates the new AI-powered Bing that Microsoft started testing earlier this month.

Despite Windows 11 now receiving major updates once a year (the latest one being the version 22H2 released last fall), Microsoft now releases new Windows features throughout the year when they’re ready. The company reportedly refers to these updates as “Moment” updates internally, and we had an example of such an update back in November when Microsoft rolled out File Explorer tabs, a new overflow menu UI on the taskbar, and other new features.

Today’s update for Windows 11 is available as an optional update for users running Windows 11 version 22H2, and all the new features will be available for all users with next month’s Patch Tuesday Update. Let’s dive into all the biggest changes in this update.

Microsoft brings back a search box to the taskbar with a Bing tweak The biggest change coming with today’s update for Windows 11 version 22H2 is that Microsoft is bringing back a typable search box in the taskbar, similar to how Windows Search looks on Windows 10. However, this new search box integrates Microsoft’s new Bing chatbot.

“It’s a first step to see how the idea of a copilot comes to life for you on Windows for everything you will do on the PC,” said Microsoft’s Chief Product Officer Panos Panay. The exec added that this new Bing integration in the taskbar will “provide hundreds of millions of Windows 11 users the next era of computing.”

The new search box in the taskbar integrates Microsoft’s Bing AIMicrosoft has already released a new policy allowing IT admins to control how search looks on the taskbar. Using this policy, IT admins can choose to show the new search box, a search icon with a label, a search icon only, or hide the search icon on the taskbar altogether.

In addition to this new search box, today’s Windows Update also makes Windows Studio Effects available from the Quick Settings section of the taskbar. If you have a Windows ARM device with a neural processing unit, it’s now easier to enable features such as background blur, eye contact, and automatic framing during video calls.

Lastly, the Windows 11 taskbar is now optimized for 2-in-1 devices with detachable keyboards. Users will be able to use a swipe gesture to make the taskbar switch between a “Collapsed” state and an “Expanded” state, and the latter will automatically be enabled when a keyboard is disconnected on a Windows 11 tablet. This new touch-optimized taskbar can be disabled in Windows 11 settings.

New AI-powered recommendations in Start Menu and File ExplorerOn Windows 11 Pro devices that are Azure Active Directory (AAD) joined, the Start Menu will now display AI-powered recommendations. The “Recommended” section at the bottom of the Start Menu will display relevant Office files and shared documents you may need to prepare for your next meeting.

The Start Menu now displays AI-powered recommendations on Azure Active Directory joined PCsMicrosoft is also tweaking its File Explorer with this update. Search should now be faster, and the app will better surface recommended local and cloud files.

Microsoft is also making its Quick Assist app, which allows Windows 11 users to receive or provide PC assistance over a remote connection available right from the Start Menu. The app is now preinstalled on all PCs running Windows 11 version 22H2, and it has also been redesigned.

Improvements to widgets and accessibilityThe Windows 11 Widgets board may soon become more useful as it now supports third-party apps. There are new widgets for Microsoft’s Phone Link app, Facebook Messenger, and Spotify, but it will be interesting to see if more serious productivity apps start embracing the Windows 11 Widgets board.

On the accessibility front, today’s update adds support for more braille displays, and it also enhances the functionality of the Voice Access app. This feature already allows users to control their PC and author text using only their voice, and it’s now compatible with more Microsoft apps including Word and File Explorer.

Voice Access is now compatible with more Microsoft apps on Windows 11Tabs in NotePad, Windows 365, and other app updatesMicrosoft is also rolling updates to several Windows 11 inbox apps today. Notepad is the latest app after File Explorer to receive tabs support, while Snipping tool is getting a built-in screen recorder.

Microsoft is also making its Windows 365 app generally available today. On Windows 11, the app provides the best experience for accessing a Windows 365 Cloud PC thanks to better integrations to the Windows 11 taskbar and Start Menu. The app also lets users use their Windows 365 Cloud PC as a window or full screen.

Microsoft’s Windows 365 app is now generally available on Windows 11Windows 11’s Phone Link app adds iPhone support in previewMicrosoft’s Phone Link, which currently works best with high-end Samsung Galaxy Android phones is adding support for iPhones in preview. Starting today, select Windows Insiders will be able to pair their iPhone in the app and get access to text messages and iPhone notifications right from their Windows 11 PC.

The iOS integration is currently quite limited as sending messages to a group and sending media are not supported. Microsoft says that it will expand the availability of the Phone Link for iOS preview soon.

The Phone Link for iOS preview will let select Insiders send text messages and check their iPhone notifications.A little more than a year since the initial release of Windows 11, Microsoft’s Chief Product Officer Panos Panay said that the OS still continues to enjoy some momentum. “Since the launch, Windows 11 users continue to be more engaged than Windows 10 and customer satisfaction is higher than any version of Windows ever,” the exec said.

Again, today’s big update for Windows 11 version 22H2 is available as an optional update in Windows Update, but it will roll out to all users with next month’s Patch Tuesday updates. IT admins will also have some control over the rollout of these new features.

“If your organization uses Windows Update for Business or WSUS to control which Windows updates are offered to your managed devices, you can use a new client policy to control the rollout of select features introduced via servicing. By default, all features introduced via servicing that are behind this commercial control will be off for Windows-Update-managed devices until they are released as part of the next annual feature update,” Microsoft explained on its Windows IT Pro blog.

View Details

Last week, C-Facts announced a new partnership with Ingram Micro. The companies have signed a five-year agreement to provide C-Facts Cloud Cost Management services to Ingram Micro Cloud Partners and their clients worldwide.

C-Facts is a popular cloud cost management solution that enables organizations to monitor and control their spending on cloud services. The tool provides real-time insights that make it easier to optimize usage and reduce costs in enterprise environments. It offers multi-cloud support for Microsoft Azure, Google Cloud, AWS, Oracle Cloud, and Microsoft 365.

The new deal will enable Ingram Micro Cloud Partners to provide an intuitive and shareable dashboard to customers. The dashboard lets IT admins view detailed information that helps to make informed business decisions and increase organization-wide cost awareness. C-Facts Cloud Cost Management will allow customers to automate cross-charging to select apps, projects, departments, countries, and other cost centers.

C-Facts to launch cloud optimization module for Ingram Micro PartnersC-Facts highlights that the new long-term partnership should be beneficial for both companies. It expects to increase international sales and deliver valuable services to both cloud partners and customers.

“My Team has their roots in the Cloud and managed services business. We speak the same language as the Ingram Micro Cloud Partners, so we are very well positioned to help the Managed Service Providers optimize their services to the end-customers. I love that part of our job,” said Martijn van Zoeren, CEO of C-Facts.

C-Facts has also announced its plans to release a new cloud optimization module for Ingram Micro Partners later this year. If you’re interested, you can check out the official C-Facts website to learn more about its Cloud Cost Management solution.

View Details

Microsoft has introduced a new Report Suspicious Activity feature in Azure Active Directory (Azure AD). Suspicious activity reports provide detailed information about unusual sign-in attempts to help organizations detect and respond to potential security threats.

According to Microsoft, the new feature enables users to report suspicious activities for unknown authentication requests. Users can report the fraudulent attempt via the Microsoft Authenticator app or their phone call. IT Admins can then review the activity logs to investigate and take necessary action to protect their data and resources.

“Administrators can use risk-based policies to limit access for these users, or enable self-service password reset (SSPR) for users to remediate problems on their own. If you previously used the Fraud Alert automatic blocking feature and don’t have an Azure AD P2 license for risk-based policies, you can use risk detection events to identify and disable impacted users and automatically prevent their sign-in,” Microsoft explained.

Source: MicrosoftHow to enable the Report suspicious activity feature in Azure ADTo enable the Report Suspicious Activity feature, administrators will need to follow the steps mentioned below:

  • Sign in to the Azure portal and select Azure Active Directory >> Security >> Authentication Methods >> Settings.
  • Enable the Report Suspicious Activity option.
  • Select if the new setting applies to all end users or a specific group.

Once enabled, IT admins will be able to view the risk detection report by heading to Azure Active Directory >> Security >> Identity Protection >> Risk detection. The risk event will appear as detection type “User Reported Suspicious Activity,” with risk level High and source End user reported.

Earlier this month, Microsoft warned about a new consent-based phishing campaign that tricks users into authorizing permissions for malicious OAuth apps. The Report Suspicious Activity feature should make it easier for IT admins to proactively identify and mitigate security risks in their organizations. This capability is currently available in preview, and it’s unclear when it becomes generally available for all enterprise customers.

View Details

Using OneDrive for Business will help your users be more productive with their files, from any place with an Internet connection. Do they know how to access the OneDrive website? Do they know how to use the OneDrive sync app in Windows? Read on to discover everything you need to know about how to use OneDrive for Business.

How to use OneDrive for Business: The basicsBy early 2023, every IT pro knows what Microsoft’s OneDrive is: OneDrive is Microsoft’s file-sharing service for consumers and enterprises in the cloud. There is a distinction between consumer and business accounts, however.

What is OneDrive for Business?As a consumer, you use a Microsoft account to access your files in OneDrive. OneDrive for Business is the marketing term for the business/enterprise crowd – here, you use your Microsoft 365 work or school account. Although there are very few GUI changes between OneDrive and OneDrive for Business (which is by their design, of course), there are subtle differences.

As this is an IT knowledgebase website, we will focus on OneDrive for Business. Instead of continuing to manage traditional, old, and costly on-premises fileserver infrastructures, hobbling your users by requiring them to be in the office or having a secure connection to your network, you can set them free and encourage them to use OneDrive for Business.

The most unique advantage (at least to me as an IT Pro AND an end user) is the ability to access my files anywhere on various applications and websites. You can have your IT department go ahead and decommission your G: drive and your K: drives, save some IT budget money. With OneDrive for Business, I can have native, integrated functionality in File Explorer on my work computer, my home computer (if necessary and compliant), and my mobile device.

Here’s an example of the productivity boosts you can realize very quickly: Imagine you are working on an Excel file at the end of the day and have to run to a personal appointment. While you’re waiting at the car repair shop, you can open the OneDrive app on your phone and make some final changes to your Excel spreadsheet and send a link to the file in your OneDrive to your manager. Pretty slick!

What do your users need to access OneDrive for Business?Because OneDrive for Business is so central to file-sharing in the Microsoft 365 space, every user has access to the service. Almost every Microsoft 365 SKU includes licensing for OneDrive for Business. There is nothing special users need to do to use it.

One quick note: when a new user is provisioned either in the Microsoft 365 admin center or synced from an on-premises identity (Active Directory), they need to access the OneDrive website in order to have their account activated.

Don’t worry, there’s nothing special here. It’s just something you may have noticed when using the M365 admin center – when you click the OneDrive tab in the details of a new user, there will be verbiage showing no account exists, yet. All they have to do is browse the OneDrive app online to activate it. Again, very straightforward.

Are OneDrive for Business files secure and safe?Microsoft always has security in mind with all of its services, and OneDrive for Business is no exception. BitLocker encryption is employed across the entirety of OneDrive for Business and SharePoint Online. In addition, per-file encryption is also included.

All data at rest in Microsoft’s cloud is encrypted with this design (BitLocker). However, per-file encryption goes even further by including a unique encryption key for each and every file! Plus, when a file is updated, every update to that file is encrypted with its own private encryption key.​​​

How to use OneDrive for Business on the webThere are two core methods of accessing OneDrive for Business – online and on Windows (and macOS). Let’s start by investigating the online landscape. Because the web is so pervasive and generally accessible, using the OneDrive for Business service with your web browser is nice and simple across all platforms.

Methods to access the appThere are a few ways you can get to your OneDrive for Business account online. We’ll go through each one here.

First, browse to office.com or microsoft 365.com and log in with your work account.

The Microsoft 365 website (Image credit: Petri/Michael Reinders)Click the ‘App Selector’ in the upper left corner of the website and choose OneDrive from the list (if you don’t see OneDrive, click the All apps link to expand and locate it).

Using the Microsoft 365 App Selector to open OneDrive (Image credit: Petri/Michael Reinders)A new tab will open in your browser and open your OneDrive for Business account.

The OneDrive for Business ‘Home’ page (Image credit: Petri/Michael Reinders)Here you can see your folders and files and the front end of your file-sharing capabilities in Microsoft 365. Microsoft engineers have progressed the UI and feature set over the years – it has become very nice, intuitive, and useful. We’ll go through the specific parts of the interface next.

Another direct method you can use is simply browse to the OneDrive website at onedrive.com.

The various functions of OneDrive for BusinessSo, the interface looks pretty straightforward, right? Let me take you through the core areas of the website. First, on the left, you’ll see the core views and the ‘Quick access‘ menus.

The navigation bar on the left side of the screen (Image credit: Petri/Michael Reinders)Now, as I write this in February 2023, the core view is labeled ‘My files’. This is where you see your file repository. However, Microsoft has announced a new ‘OneDrive Home’ view coming in late February and early March.

This new OneDrive Home view will more closely match the current view at office.com and will show all of the files that you’ve used, ordered by when you last opened them. You’ll be able to filter this list by file type to quickly find the file you’re looking for. You’ll also be able to stay up to date on any changes happening in the file with Activity.

This new refresh of the OneDrive for Business website is coming in February/March 2023 (Image credit: Microsoft)Across the top, you’ll find the OneDrive toolbar. This is where you can click ‘+ New‘ button to create new folders and Word, Excel, PowerPoint, OneNote, etc. files from scratch. I tell you, the integration is beautiful here. I’ll cover the other core buttons below.

Creating a new folder or Office app document from the ‘New’ picker (Image credit: Petri/Michael Reinders)How to upload files to OneDrive for BusinessYep, that next button is called ‘Upload.’ This is how you can transfer files from your computer to your online account. You have the option to upload an entire folder or individual files. You can also drag and drop folders (or files) right onto the OneDrive website for efficiency.

Uploading files from your computer to OneDrive (Image credit: Petri/Michael Reinders)I’ll show you how to upload files directly in Windows later on. Stay tuned!

Sharing files with OneDrive for BusinessMicrosoft has also refined the sharing experience in OneDrive for Business over the years. Because of the tight integration across the Microsoft 365 stack of services, you can share files from many different locations and apps seamlessly and effortlessly.

By default, every file in your OneDrive is yours, and yours alone. No one else has access to them (except Administrators). To share one of your files with another user, simply select the file, and click the ‘Share‘ button on the top toolbar.

Using the ‘Share’ button to share your OneDrive files with others (Image credit: Petri/Michael Reinders)Start typing in the name of the user or users and choose if they should have ‘Can view’ or ‘Can edit’ or ‘Can review’ rights (they only could propose changes, not actually make them). Optionally, you can send an email to these users right from this interface!

Choosing who will have access and what types of access they will have (Image credit: Petri/Michael Reinders)Using the OneDrive Recycle Bin to restore filesThe final core feature of the OneDrive UI is the Recycle Bin and the related ‘Restore your Onedrive‘ functionality. First, the Recycle Bin works just like the icon in Windows – it contains all the files you’ve deleted from your OneDrive for Business account.

The OneDrive Recycle Bin (Image credit: Petri/Michael Reinders)Here, you can select a file, multiple files, or entire folders and click the ‘Restore’ button on top.

Restoring files from the OneDrive Recycle Bin – a piece of cake! (Image credit: Petri/Michael Reinders)Nice and simple. The other, more ‘impactful’ feature is called Restore your OneDrive. Click the ‘gear‘ icon in the upper right corner, and click ‘Restore your OneDrive.’

Accessing the ‘Restore your OneDrive’ feature from the Settings icon (Image credit: Petri/Michael Reinders)Here, you will see a new window that allows you to take the state of your OneDrive for Business account and revert it to a prior point in time, similar to how System Restore on Windows worked/works. This is especially helpful if you’ve been subjected to a ransomware attack or virus. If you lost a ton of folders due to piracy or a security breach, you can go back 2 days or 10 days and bring them all back!

Here, I have selected ‘One week ago‘ in the dropdown menu. Then, listed below are all the activity items that have occurred in the last week.

Using the ‘Day’ slider to view proposed changes to the entire state of your OneDrive repository (Image credit: Petri/Michael Reinders)All I need to do is click the Restore button and my DeLorean will do its thing and revert all of those changes. If I created a file since that time, it will be gone. If I deleted a file, it will be restored. This is why I said this was an impactful feature – you have to be aware of the repercussions of all the changes you’re asking to be done. Tread carefully.

How to use the OneDrive for Business sync client on WindowsThe other core feature of OneDrive for Business is the OneDrive sync client for Windows and its tight integration into the Windows shell interface. By default, on vanilla installs of Windows 10 (and Windows 11), the OneDrive application is installed and starts upon login. Depending on how your device has been configured, it will either auto-log you on when you sign in with your Microsoft 365 credentials, or the OneDrive window will pop up and ask you to sign in for a more cohesive and productive experience on your device.

One of the convenient features is the addition of the OneDrive folder in your Windows Explorer application. Let’s read more to find out how it all works.

Accessing the OneDrive sync client on WindowsThe OneDrive Sync application runs in the System Tray by default. Look in the lower right corner of your device for the SysTray and find the blue cloud icon (or white).

The main OneDrive for Windows application interface (Image credit: Petri/Michael Reinders)Click it, then click the Settings gear icon.

Accessing the OneDrive Settings menus (Image credit: Petri/Michael Reinders)Here we are presented with the recently rolled out modern ‘Windows 11’ interface/UI. Although the UI on Windows 10 is more traditional, the same settings and screens are all here. They’re just laid out differently.

The new ‘Windows 11’ UI menu interface for OneDrive in Windows (Image credit: Petri/Michael Reinders)On the Sync and backup screen, you can manage the Known Folders feature. This lets you sync your users’ 3 critical folders to OneDrive.

When migrating users to new devices, the most cumbersome aspect of making sure they have everything from their old device on their new one is the Desktop, Documents, and Pictures folders. This makes it easy to set up the syncing of these folders to OneDrive. That way, no matter what device they are using, they will always have these folders and files available.

Accounts and notificationsClick on the Accounts menu option on the left and you’ll see what accounts are linked on the device.

The OneDrive Accounts page (Image credit: Petri/Michael Reinders)You can also see what specific folders are permanently synced (available offline) and how much local storage space they take up. Click Choose folders and you can choose which folders will be available offline all the time.

Choosing which folders will permanently be synced to your device (Image credit: Petri/Michael Reinders)Click the Notifications option and you’ll see various options around receiving prudent OneDrive activity in Windows.

Using the Notifications menu in OneDrive (Image credit: Petri/Michael Reinders)Key aspects of using OneDrive for Business when offlineMicrosoft has gone back and forth between OneDrive and offline functionality over the years. It wasn’t pretty going through Windows Vista, Windows 7, Windows 8/8.1, and then Windows 10. With almost every major Windows version, they effectively changed how offline modes worked. Thankfully, with Windows 10 and forward, they came to their senses and determined Files On-Demand was the best.

Back on the Sync and backup menu, click the Advanced settings dropdown and you’ll find the Files On-Demand options.

The lovely ‘Files-On-Demand’ offline functionality settings in OneDrive (Image credit: Petri/Michael Reinders)You can basically leave the defaults as they will work best for your users. Only the files your users explicitly access and open will be copied and stored on their devices. You don’t have to worry about a user’s 750GB of OneDrive files saturating every device they log into. This is nice and efficient.

Best tips for dealing with sync conflictsAs an IT Pro, I have needed to support end users and their issues sometimes when using the sync tool in Windows. Heck, I have had these issues, too!

If you glance down and see a red ‘x’ circle on your OneDrive icon, it means that there’s a sync problem. Click it and you’ll be presented with the fact that there is a sync conflict with one or more files. Maybe you worked on updating a file locally and it’s having issues syncing those changes up to the cloud. Now what?

Well, I’ll admit that even though the ‘wizard’ that pops up to assist you with resolving the issue is often cumbersome, it has improved with the service over the years. And, honestly, I could write an entire post about this issue. But, let me give some general steps to resolve this within the scope of this post.

  • Try unlinking your OneDrive account, and signing in again from scratch. This, by design, will remove the conflict. Hopefully, when you get signed in again, the issue will self-heal.
  • Move the files out of whatever folder they reside in. This sometimes will resolve the stuck issue with one of your files.
  • Reboot your computer. (I mean, come on. If all else fails, reboot).
  • Do a full reset of OneDrive synchronization.​​​

How to sync a SharePoint Online document libraryHonestly, I would be remiss if I didn’t mention a wonderful productivity tool related to OneDrive for Business and SharePoint. By the way, the OneDrive service (and website) is essentially a highly-customized SharePoint Online site collection. So, it’s natural that Microsoft would include some tightly integrated features between the two.

Navigate to one of your favorite SharePoint sites and access the Documents link.

A SharePoint Online Document Library (Image credit: Petri/Michael Reinders)Who wants to keep a browser tab open to your SharePoint files? Wouldn’t it be nice if you could just work in Windows Explorer with the rest of your files and OneDrive files? Well, you can. See that Sync button on the toolbar? Click it!

Syncing the SharePoint documents via the OneDrive Sync application (Image credit: Petri/Michael Reinders)We’ve initiated the process to start syncing all the files in this Document Library with the OneDrive app. Now, let me open Windows Explorer… I spy something new!

Look at the new ‘red-circled’ tree… (Image credit: Petri/Michael Reinders)That ‘x3v6p‘ is the name of my tenant in Microsoft 365. The naming convention is ‘different’ because it’s part of my Developer tenant. You will see your company name here instead.

Anyway, click that, and now you have full access and feature parity as if you were on the SharePoint website. Every individual SharePoint Document Library you’ve synced will appear here. This is a boon for accessing all of your files in one place!

Native access to your SharePoint Online documents right within File Explorer! (Image credit: Petri/Michael Reinders)Additional ways to access OneDrive for BusinessI will round out this post by giving you two more helpful locations to access your OneDrive files.

The OneDrive mobile appYes, there’s an app for that! Browse to the Apple or Android app store on your smartphone, search for ‘OneDrive‘, and download the app. Sign in with your Microsoft 365 credentials and you will have a very useful utility to give you a dashboard of sorts on your OneDrive account, recent activity, and the ability to do limited editing of files. Plus, you can share files and send links right from your device!

Always wishing to be transparent, I will mention an odd productivity snag when using the OneDrive app. It has to do with copying files from your OneDrive to SharePoint libraries. Unfortunately, there is no direct way to do this. The ‘easiest’ workaround is to first download your file(s) in your OneDrive app and then click the ‘Libraries’ link at the bottom of the UI, browse to your SharePoint document library, and upload.

(If you know of a better way to do this, please leave a comment at the end of this article. There are inquiring minds that would love to know!)

Microsoft TeamsIn the desktop application in Microsoft Teams, access the Files app on the left, and click the OneDrive item under Cloud storage.

Accessing your OneDrive files right inside Microsoft Teams – Efficiency! (Image credit: Petri/Michael Reinders)Here’s another helpful view into your OneDrive account. You will essentially have the same UI and features available to you as if you were on the OneDrive website.

ConclusionOneDrive for Business is a full-featured, easy-to-access file-sharing service that is integral to Microsoft 365. They have given us multiple methods to access your files, multiple options to share files, and even use collaboration tools to edit files in real-time with other colleagues! I love using that feature.

Please leave a comment below if you have any questions or comments about this topic. Thank you!

View Details

MC520318 – Viva Goals currently has a field named “type” while creating and filtering OKRs which designates where the OKR would be created. The terminology is now changing from “type” to “teams.” In addition to the name change, the functionality of the “teams” field will expand to include additional context and faster search capability as OKR owners assign a team to an OKR.

All OKRs created from the My OKRs page will now be set to unassigned by default. OKRs being created from a specific team or organization page will continue to have the current default of the selected team or the organization.

OKRs can continue to be created at an individual, team or at the organization level. An OKR can be co-owned by both a team and the organization so that an OKR can serve not only as companywide initiatives, but also team and organization initiatives.

When this will happen:

Roll out will begin in late February and is expected to be complete by early March.

How will this affect your organization:

With this update, users of Viva goals will continue to be able to create OKRs at an individual, team or the organization level. By default, when creating OKRs from the My OKRs page, the team will be set to “Unassigned”.

View image in new tab

In all views where the term “type” existed will begin to be reflected as “teams.”

View image in new tab

What you need to do to prepare:

There is nothing you need to do to prepare. You may want to update and relevant training documentation.

View Details

MC520315 – Creating external networks in Yammer and Viva Engage will now require verified admin privileges for reasons of security and system reliability.

When this will happen:

This update is now available.

How this will affect your organization:

  • Creating a new external network can only be done by a verified admin.
  • All newly provisioned Yammer or Viva Engage networks will have external network functionality disabled by default.
    • Note: after 30 days a verified admin can create an external network.

What you need to do to prepare:

User experience improvements to support this change can be expected to be deployed in the coming weeks.  If you have someone that is creating external networks today and is not a verified admin, you will need to promote them to verified or coordinate transition of responsibility.

View Details

Microsoft is getting ready to release a pay-as-you-go licensing option for its Microsoft Syntex service. The new plan will include unstructured and prebuilt document processing, and it will become generally available for customers on March 7.

Microsoft Syntex is an AI-powered service that lets organizations automatically analyze unstructured content (like documents, images, and videos) and extract information relevant to business needs. It allows organizations to automate manual tasks and streamline business processes. Microsoft Syntex is designed to seamlessly integrate with other Microsoft 365 services. The service is available as an add-on product for Microsoft 365 subscribers.

Microsoft explained that Syntex usage will be billed to the customers’ Azure subscriptions. “This will enable all users in your organization to create and apply unstructured and prebuilt document processing models, and customers can upload documents to libraries configured to use Syntex. This is charged on a pay-per-use basis, specifically charging for the total number of pages processed,” Microsoft explained.

Microsoft Syntex pay-as-you-go model currently supports document processingMicrosoft clarified in the FAQs section that the pay-as-you-go licensing will only apply to document processing in Microsoft Syntex. Currently, the model doesn’t provide support for AI Builder, Universal annotation, Syntex content assembly, Content query, and other Syntex services.

Microsoft has introduced a new tool called the Syntex cost calculator, which can assist organizations in understanding usage trends and estimated costs. The company has also launched a new Microsoft Syntex training module. It’s designed to explain how IT admins can use the service to automate time-consuming document management tasks.

At launch, Microsoft’s Syntex pay-as-you-go model will only be available for Microsoft 365 commercial cloud. The company plans to make it available to government customers (GCC and GCC High) in the future.

View Details

Microsoft has published an advisory recommending IT admins to remove select antivirus exclusions in Exchange Servers. The company explained that this configuration change should help IT admins to improve the security posture of their organizations.

Up until now, Microsoft recommended Exchange Server admins to configure antivirus solutions to protect their systems. It is also a good practice to enable exclusions for specific file types, processes, and paths. It helps to reduce the chances of unexpected failures (such as unexpected database dismounts) caused by restricted access to a file or folder.

Microsoft detailed that IT administrators should remove certain objects from the exclusion list. These objects include the PowerShell and w3wp processes as well as the Temporary ASP.NET Files and Inetsrv folders. Microsoft warned that these exclusions could allow attackers to deploy malware in vulnerable Exchange Server environments.

“We’ve found that some existing exclusions, namely the Temporary ASP.NET Files and Inetsrv folders, and the PowerShell and w3wp processes – are no longer needed, and that it would be much better to scan these files and folders. Keeping these exclusions may prevent detections of IIS webshells and backdoor modules, which represent the most common security issues,” the Exchange team explained.

Which antivirus exclusions should you remove from Exchange Server?Here’s the list of folder and process exclusions that should be removed from Exchange Server 2016 and Exchange Server 2013.

| Folders | 1) %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files2) %SystemRoot%\System32\Inetsrv | | Processes | 1) %SystemRoot%\System32\WindowsPowerShell\v1.0\PowerShell.exe2) %SystemRoot%\System32\inetsrv\w3wp.exe |

Microsoft notes that removing the exclusions should not cause stability or performance issues for customers using Microsoft Defender on Exchange Server 2019. Meanwhile, the company suggests IT Pros to monitor and mitigate potential issues that might occur on Exchange Server 2016 and Exchange Server 2013. Microsoft advises customers who encounter any issues to reconfigure exclusions and share their feedback with the Exchange team.

View Details

Windows 11 is the first version of Windows that Mac users can’t install natively on Mac. That’s because Intel-based Macs don’t need the minimum requirements for the new OS, while Apple Silicon Macs have dropped support for Apple’s Boot Camp multi-boot utility. In this article, I’ll explain how to install Windows 11 on Mac using Parallels Desktop 18 for Mac, which is now an officially-supported scenario.

Parallels Desktop for Mac is the most popular virtualization solution for virtualizing Windows and Linux on a Mac. Parallels Desktop for Mac added support for Windows 11 back in 2021, but Microsoft didn’t recognize it as a supported scenario for running the latest version of Windows until February 2023.

How to install Windows 11 on a Mac with Parallels Desktop (article snippet)Here’s how to install Windows 11 on a Mac with Parallels Desktop in a couple of easy steps:

  • Download Parallels Desktop for Mac from the company’s website
  • Install Parallels Desktop on your Mac
  • Let the Installation Assistant in Parallels Desktop install Windows 11 in a virtual machine
  • Once Windows 11 is installed, create your free Parallels Desktop account.
  • You’re now ready to use Windows 11 virtual machine on your Mac!

Parallels Desktop offers a 14-free trial, but after that, you’ll need to pay for a license. If you want to use Windows 11 without any restrictions, you’ll also need an activation key.

Can you install Windows 11 natively on Intel or Apple Silicon Macs?Unfortunately, it’s not possible to install Windows 11 on a Mac using Apple’s Boot Camp multi-boot utility. The M1 and M2-based Macs released since the fall of 2020 have dropped support for Boot Camp, and it’s not clear yet if Apple will ever bring it back to Apple Silicon Macs.

As for Intel-based Macs, these models can only use Boot Camp to install Windows 10, but upgrading it to Windows 11 isn’t supported. That’s because the latest Intel-based Macs don’t meet the minimum hardware requirements to install Windows 11.

Why Windows 11 can’t run natively on Macs?For Apple Silicon Macs, the absence of the Boot Camp multi-boot utility means that it’s not possible to install any other OS than macOS on these devices. For Intel-based Macs, however, Windows 11 can’t be installed natively via Boot Camp because these Macs lack a TPM 2.0 security chip.

Even though all Intel-based Macs that have been released since 2016 actually come with the TPM 2.0 security chip that Windows 11 requires, Apple has actually never supported the technology on these Macs. While some hacks exist to install Windows 11 on Intel-based Macs by creating a custom ISO that bypasses the TPM 2.0 requirement, this is out of the scope of this article and not something I recommend you should do.

The supported scenarios for running Windows 11 on MacsA little more than a year after the release of Windows 11, Microsoft has now clarified that there are two options for Mac users to run Windows 11: Windows 365 Cloud PCs and Parallels Desktop for Mac version 18.

Running Windows 11 on Macs with Windows 365Windows 365 is Microsoft’s software-as-a-service solution for running Windows 11 on a cloud PC on a per-user, per-month basis. Microsoft offers different pricing options for Windows 365, starting at $31 per user per month for a Cloud PC with 2 virtual CPUs, 4GB of RAM, and 128GB of storage.

For Mac users, running Windows 11 via a Windows 365 Cloud PC offers the convenience of accessing a personalized Windows 11 desktop via a web browser. For developers, Windows 365 also supports virtualization-based workloads, something that Parallels Desktop for Mac is missing. I’ll have more details on that later.

You can learn more about how to set up Windows 365 in our dedicated article on Petri.

Running Windows 11 with Parallels Desktop for MacParallels Desktop 18 for Mac, the latest version of the virtualization app is the other supported way to run Windows 11 on a Mac. Parallels Desktop added support for Windows 11 back in 2021, with the version 17 of the app introducing a virtual TPM 2.0 chip to ensure hardware compatibility with the latest version of Windows.

Parallels Desktop 18 for Mac, which was released last year, supports running Windows 11 in a virtual machine on both Intel-based and Apple Silicon Macs. On Macs with M1 and M2 chips, however, it’s the ARM version of Windows 11 that will be installed in a virtual environment.

Windows 11 running in a virtual machine via Parallels Desktop for Mac (Image credit: Petri/Laurent Giret)Unfortunately, running Windows 11 on ARM via Parallels Desktop for Mac comes with some limitations. Features such as DirectX 12 and nested virtualization aren’t supported, and I’ll have more details on that below.

Parallels Desktop for Mac 18 has a 14-day free trial. After that, you can either purchase a Parallels Desktop Standard license or subscribe to Parallels Desktop Pro or Parallels Desktop Business Edition:

  • Parallels Desktop Standard Edition ($99.99) targets students and home users, and it’s limited to 8GB of vRAM and 4 vCPUs.
  • Parallels Desktop Pro Edition ($119.99/year) supports up to 128GB of vRAM, up to 32 vCPUs, and it’s recommended for installing Windows 11 Pro or Enterprise.
  • Parallels Desktop Business Edition ($149.99/year) offers everything included in the Pro Edition plus centralized administration and management, unified volume license key for mass deployments, and other features for IT departments.

Installing Parallels Desktop on Intel-based and Apple Silicon MacsLet’s install Parallel Desktop 18 for Mac, which comes with a 14-day free trial. Visit the Parallels Desktop for Mac product page on the company’s website and click on Try now. On the next page, click on Download Free trial.

Downloading the Parallels Desktop for Mac free trial (Image credit: Petri/Laurent Giret)Once the installer has been downloaded, open it and double-click on Install Parallels Desktop. You may see a pop-up window asking you if you really want to install this app downloaded from the Internet. Click Open.

Opening the Parallels Desktop 18 installer (Image credit: Petri/Laurent Giret)During the installation process, the installer will ask for access to files in your Desktop folder. Click Ok on the pop-up window.

(Image credit: Petri/Laurent Giret)The installation of Parallels Desktop for Mac 18 will begin, and it will take a couple of minutes. Once it’s installed, the app will ask you to enable access to several directories: Click Ok to allow the app to access files in your Desktop folder (again), your Documents folder, and your Downloads folder. Click on Finish when you’re done giving the app all these permissions.

Parallels Desktop needs access to several directories in your Mac (Image credit: Petri/Laurent Giret)How to download and install Windows 11 with Parallels Desktop for MacNow, Parallels Desktop will ask you to download and install Windows 11 on your Mac. You’ll see a message informing you that you’ll need to “activate this copy of Windows 11 after installation”, but you don’t need to worry about that right now.

  • Click on Install Windows to begin the installation process.

Parallels Desktop lets you install Windows 11 on your Mac in just a couple of clicks (Image credit: Petri/Laurent Giret)* The app will then start downloading the Windows 11 on ARM ISO. It should take less than an hour depending on the speed of your Internet connection.

The app is downloading the Windows 11 ISO (Image credit: Petri/Laurent Giret)* Once the ISO file has been downloaded, the installation of Windows 11 in a virtual machine will begin. Parallels Desktop will also ask you to access your camera and microphone during that step, but this is optional. It will take some time for the installation of Windows 11 to complete, so just be patient during the out of box experience

Windows 11 is now being installed in a virtual machine (Image credit: Petri/Laurent Giret)* The installation of Windows 11 is now finished. The virtual machine is currently running in windowed mode on my M1 MacBook Air, and I’m now asked to accept the Windows License agreement.

The installation of Windows 11 is complete (Image credit: Petri/Laurent Giret) When you click on the screen, a pop-up window will open and Parallels Desktop will ask you to sign in to a Parallels account. If you don’t have one already, choose “I am a new user*” at the top and create your free account.

Create a free Parallels account to continue using your Windows 11 VM (Image credit: Petri/Laurent Giret) Now, you can proceed with accepting the Windows License Agreement in your Windows 11 VM. Click on Accept* at the bottom right corner of the window.

You’ll need to accept the Windows License Agreement (Image credit: Petri/Laurent Giret)That’s it! Our Windows 11 on ARM virtual machine is now up and running on our Apple Silicon Mac. Now, I’ll show you how to adjust the amount of resources you want to allocate to your virtual machine.

Adjusting settings for your Windows 11 virtual machineIf I go to System settings on my Windows 11 virtual machine, I can see that it’s using 4 CPUs and 6GB of RAM by default. That’s more than enough for running Windows 11 in good conditions.

Our VM uses a default CPU and RAM configuration (Image credit: Petri/Laurent Giret)However, if you need more resources for your Windows 11 VM, you can allocate them in Parallels Desktop Settings.

  • First, you need to shut down your VM. You do that by opening the Windows 11 Start Menu, clicking the power button, then clicking on Shut down.
  • Alternatively, you can click on the Parallels icon on the macOS menu bar, then go to Actions > Shut Down.

You need to shut down your VM to change CPU and memory allocation (Image credit: Petri/Laurent Giret) Next, click again on the Parallels Desktop icon in the macOS menu bar, and click on Control Center*.

You can access your VM settings in the Control Center (Image credit: Petri/Laurent Giret)* The Control Center displays all the VMs you have installed. Click the cog button under your Windows 11 VM

(Image credit: Petri/Laurent Giret) Here, you can see that my Windows 11 VM is using the recommended settings for my M1 Mac: That’s 4 CPUs and 6GB of RAM. If you need to change that, click on Manual.*

The VM is using recommended CPU and Memory settings by default (Image credit: Petri/Laurent Giret)* I actually have 16 GB of unified memory on my M1 MacBook Air. If I want to allocate 8 GB of RAM or more to my Windows 11 VM, I’ll just select what I want in the Memory field.

Allocating more RAM to our Windows 11 VM (Image credit: Petri/Laurent Giret)* I can now close down the Settings and relaunch my Windows 11 VM from the Control Center. As you can see, the Windows 11 Settings app now shows that the VM has 8GB of RAM.

Our Windows 11 VM now has 8GB of RAM (Image credit: Petri/Laurent Giret)Do you need to activate Windows 11 on your virtual machine?As you use your Windows 11 VM on your Mac, you’ll sell a pop-up window asking you to activate Windows. You can either buy a product key from Microsoft or enter one you already have one.

Windows 11 will ask you for an activation key (Image credit: Petri/Laurent Giret)You’re actually not required to activate Windows, though some features will be restricted if you don’t. Simple things like personalizing your background won’t be available without first activating Windows.

Some features won’t be available until you activate Windows (Image credit: Petri/Laurent Giret)How to use Windows 11 apps from the macOS desktop with Coherence modeParallels Desktop for Mac lets you run your Windows 11 in windowed mode and full-screen mode, but there’s also a Coherence mode that lets you hide the VM completely. You can activate it by clicking on the blue icon at the top left corner of your VM window. Alternatively, you can click on the Parallels Desktop icon in your menu bar, scroll down to View and choose Enter Coherence.

Activating Coherence mode for our Windows 11 VM (Image credit: Petri/Laurent Giret)After entering Coherence mode, your VM will disappear and you’ll be able to use Windows apps from your macOS desktop.

Coherence mode hides the VM and lets you access Windows apps from the macOS desktop (Image credit: Petri/Laurent Giret)When you click on the Windows 11 icon in your macOS dock, the Windows Start Menu will show up and you can launch any Windows app you have installed and run it side by side with macOS apps. Pretty neat!

You can run Windows apps and Mac apps side by side with Coherence mode (Image credit: Petri/Laurent Giret)To exit Coherence mode, you can once again click the Parallels Desktop icon on the macOS menu bar, scroll down to view, then click on Exit Coherence

You can Exit coherence mode from the macOS menu bar (Image credit: Petri/Laurent Giret)Windows 11 on ARM VM on M1 Macs: What are the limitations?Windows 11 on ARM has some limitations when it’s running in a virtual machine on Apple Silicon Macs. Nested virtualization isn’t supported, which may affect the workloads of app developers. But some Windows apps also won’t be compatible.

Here are the main limitations of Windows 11 on ARM running on a Mac via Parallels Desktop:

  • Any app that requires DirectX 12 or OpenGL 3.3 or newer won’t be compatible
  • 32-bit ARM Windows apps are also unsupported, leaving Mac users with just native 64-bit ARM apps and emulated x64 or x86 Windows apps.
  • The Windows Subsystem for Linux and the Windows Subsystem for Android are also not supported
  • The Windows Sandbox environment that lets users run Windows apps in isolation is also unsupported
  • Virtualization-based Security (VBS), a new Windows 11 feature that lets users create and isolate a secure region of memory from the normal operating system is also not supported.

That’s quite a lot of asterisks, but this shouldn’t have too much of an impact on most workloads. If you really miss the Office apps for Windows on macOS, Parallels Desktop for Mac is a great way to get them back. Even better, you can run Office for Windows alongside other macOS apps with Coherence Mode, letting you enjoy the best of both worlds.

ConclusionAs someone who’s been using Parallels Desktop for Mac for many years, I’d say this remains a great solution for running Windows 11 or Windows 10 on Mac. Performance is really solid on Apple Silicon Macs, and Apple’s M1 and M2 chips still deliver an unmatched level of performance per watt on laptops.

Parallels Desktop’s Coherence mode, which lets users run Mac and Windows apps side by side is probably the app’s killer feature. Parallels Desktop gets major updates every year with new features and performance improvements, and I highly recommend taking advantage of the 14-day free trial to check out if virtualizing Windows 11 can help you get more value from your Mac.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Merethe Stave on ChatGPT, Community, and Viva ExplorersMerethe Stave is a Senior Cloud Architect at Cloudway and a Microsoft MVP. In this week’s episode, she joins Femke and Peter to discuss:

  • ChatGPT
  • Viva Explorers
  • Working at Cloudway
  • Tech community events in Norway
  • And much more!

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

This Week in IT, Microsoft reveals details of how its new Prometheus A.I. model for Bing works and a faster more efficient Teams client is coming in preview to users in March.

View Details

This Week in IT, could a new framework based on Rust spell the end of slow, resource-intensive apps, like Microsoft Teams that are based on Electron? I look at Tauri, and how in the future it could replace Electron to improve the end-user experience in many popular consumer and enterprise apps.

View Details

Microsoft has announced a new Elgato Stream Deck integration with Microsoft Teams. Indeed, the company has released a new Teams plugin that enables users to manage their meetings with the streaming tool.

The Elgato Stream Deck is a customizable control pad that is quite popular for Twitch live-streaming sessions. Microsoft explained that the Elgato Stream Deck Teams plugin allows participants to toggle their camera and microphone on and off with the touch of a button. Moreover, it lets users blur their messy backgrounds, raise/lower virtual hands, start/stop recordings and leave Teams meetings.

Additionally, the Elgato Stream Deck plugin for Microsoft Teams allows attendees to post live emoji reactions, including laugh, like, wow, and applause. This capability could be particularly useful for quickly approving or disapproving an idea during meetings and webinars.

How to setup Microsoft Teams on Elgato Stream DeckTo install the Microsoft Teams plugin on the Elgato Stream Deck, you’ll need to follow the steps mentioned below:

  • First of all, download the Teams plugin from Elgato’s app store.
  • Launch the Microsoft Teams desktop app, navigate to Settings >> Privacy, and select Manage API. Click the Enable API toggle button to generate the API token.
  • Now, copy and paste the API token into the Stream Deck software to connect it to Microsoft Teams.
  • Finally, join any meeting to use the new Teams meeting controls on the Elgato Stream Deck.

It’s important to note that native support for the Elgato Stream Deck is only available for 1:1 calls and meetings in the Teams desktop app on Windows and macOS. However, it’s currently not supported on the web client. Microsoft claims that this is one of the top-requested features that should help users easily manage meetings and webinars in Microsoft Teams.

Microsoft has recently unveiled a new Teams Premium add-on that brings GPT 3.5-powered features to make the meeting experience more personalized and secure for users. It includes support for intelligent recaps, personalized highlights, advanced webinar capabilities, and much more.

View Details

Microsoft has announced the release of a new update that brings improvements to reports in its Universal Print service. The company has made it easier for IT administrators to monitor print activity in their organization by updating the Usage and Reports page with new graphs, charts, and data points.

Microsoft launched the Universal Print service at its Ignite 2021 conference. It’s a cloud-based solution that eliminates the need for IT admins to manually set up print servers and manage print drivers in their tenants. Universal Print enables IT admins to control access to specific printers, manage default settings, and view printer properties. The service supports printer models from popular vendors such as HP, Epson, Toshiba, Brother, Canon, and Xerox.

With this release, IT admins can track the total number of registered active printers, printer shares, and connectors in Universal Print reports. There are also new line charts representing the total number of daily print jobs completed successfully and pages printed during a specific timeframe.

“Organizations need immediate reporting that keeps usage, cost, and infrastructure health front and center when managing print deployments as Universal Print deployments grow. Fortunately, the Usage and Reports dashboard now has five new data points, graphs, and charts with the option to view data from the previous day, week, or month,” the company explained.

Universal Print usage chats visualize Color vs. Black and White printed pages and more Microsoft has added a new donut chart to give an overview of the total number of black and white and color pages printed during a selected period. The Usage and reports dashboard also shows a dedicated chat with details about the printed single-sided and double-sided sheets.

Microsoft says customers can access the improved Universal Print reports today on the Usage and Reports page. Microsoft encourages IT admins to test the new features and provide feedback on the Azure portal. You can also learn more about the new experience on this support page.

View Details

Amazon Elastic Compute Cloud (Amazon EC2) is a service that provides scalable cloud capacity in the Amazon Web Services (AWS) cloud. With Amazon EC2, organizations can choose between a wide variety of instances that are optimized for different cloud computing use cases. In this tutorial, we’ll explain everything you need to know about the different EC2 instance types and their pricing model.

What is an AWS EC2 instance?With AWS EC2, you can choose between different instance types and scale up and down the resources (CPU, memory, storage, networking capacity, etc.) you need to run your applications in the cloud. With AWS EC2, you’ll just need to pay for the time you use your instances.

AWS EC2 instances are secure as you’ll connect to them using SSH keys. You can create or launch your instance using the AWS Command Line Interface or the AWS Management Console. Moreover, you can view all your EC2 instances in the AWS Management Console.

You can manage your EC2 instances from the AWS Management Console (Image credit: Petri.com/Sagar)Why use AWS EC2 instances?For organizations, using AWS EC2 instances for their various cloud computing needs offers various advantages. Here are the main benefits you should know about:

  • You can launch instances quickly without having to deal with complex hardware configuration and setup.
  • You can securely log in to your instance using AWS key pairs.
  • You can align persistent volume for your data using Amazon Elastic Block Store (EBS).
  • You can easily scale the size of your instances without losing any data.

What are the different AWS EC2 instance types?When you create an AWS EC2 instance, you’ll need to choose your instance type. Each type offers different hardware, computing, memory, and storage capabilities

General purpose instancesGeneral purpose instances provide a balanced set of computing power, memory, and networking resources. They are suitable for small to medium-sized databases, backend servers, gaming servers etc.

Compute-optimizedCompute-optimized instances are tailored for applications that require high-performance processors. They are mostly used to perform batch processing workloads, scientific modeling, machine learning, and other compute-intensive applications.

Memory-optimizedMemory-optimized instances are designed to provide fast performance for workloads involving large databases. They’re mostly used by organizations working with high-performance MySQL, NoSQL, or MongoDB databases, but they’re also well-suited for the real-time processing of big data.

Accelerated ComputingAccelerated computing instances use hardware accelerators to perform functions such as floating point number calculations, graphics processing, or data pattern matching.

Storage-optimizedStorage-optimized instances are used for workloads that require high read and write access to very large data. These instances are well suited for data processing applications and Redis, an in-memory data structure store that can be used for databases.

What are the features offered by AWS EC2 instances?As we’ve seen previously, AWS EC2 instances come with various configurations of CPU, memory, storage, and networking capacity. EC2 instances are launched in virtual computing environments, and Amazon provides preconfigured templates that contain the operating system and other software required to run them.

What Is An Amazon Machine Image (AMI)?An Amazon Machine Image (AMI) is a template that is used to launch an instance. It contains the operating system, system configurations, an application server, and applications, and launch permissions that control which AWS accounts can use the AMI to launch instances.

Supported operating systemsYou can manage Amazon EC2 instances with one of the following operating systems:

  • Linux
  • macOS
  • Raspberry Pi OS (formerly Raspbian)
  • Windows Server

Burstable Performance instancesIn some cases, an instance can be provisioned with excess CPU and memory capabilities. As a result, customers may pay for more resources than what they really use.

Burstable performance instances are optimized for applications that have low-to-moderate CPU usage. They offer a baseline CPU performance, but organizations can still burst above the baseline when their workload requirements change.

These instances are suitable for large-scale micro-services, web servers, small and medium databases, data logging, code repositories, virtual desktops, and development and test environments. Amazon claims that customers can save up to 15% in costs compared to using regular instances.

Storage optionsWhen launched, AWS EC2 instances need storage space. Below are some of the storage options that are available to be used with AWS EC2:

  • Amazon Elastic Block Store
  • Amazon EC2 instance store
  • Amazon EFS with Amazon EC2
  • Amazon S3 with Amazon EC2

Elastic IP addressesWhen you launch an Amazon EC2 instance, it’s assigned a private IP address by default, and a public IP address can also optionally be allocated to it. However, when an instance is restarted, then both the private and public addresses are changed.

If you need a static IP for your instance, then you should use an Elastic IP address. It is a static and public IPv4 address, meaning it’s accessible from the internet. If your instance doesn’t have a public IPv4 address, you can associate an Elastic IP address to it to enable communication with the Internet.

Automated scalingAutomated Scaling is an important feature that adjusts the capacity of all your instances to maintain a predictable performance for all applications at the lowest possible cost.

With Auto Scaling, it’s easy to set up application scaling for multiple resources across multiple services in minutes. Auto Scaling can be enabled with the AWS Management Console, the AWS Command Line Interface (CLI), or the AWS SDK, and it’s available at no additional charge.

Pause and restartAn Amazon EC2 instance goes through different states from the moment you launch it to its termination. When you initially launch an EC2 instance, it first goes into a pending state before it reaches its running state.

[image][LG3]

Checking the state of your instance on the AWS Management Console (Image credit: Petri.com/Sagar)Your instance will also go into a pending state again if you stop it, or when it’s being restarted. When the instance is transitioning from a pending state to a running state, it is not billed at all. It’s also not billed when it’s preparing to be stopped and once it’s been shut down.

Amazon CloudWatchIt is very important to monitor your AWS EC2 instances, and you can do it with AWS CloudWatch. This service collects data such as CPU, memory, and more, and it makes it easily accessible in automated dashboards. By default, Amazon EC2 sends metric data to CloudWatch in 5-minute periods.

[image][LG4]

You can monitor your instances with Amazon CloudWatch (Image credit: Petri.com/Sagar)It’s your choice to enable AWS CloudWatch monitoring or not. However, there are no charges involved in monitoring your AWS EC2 instances.

Some of the crucial instance metrics that should be monitored include:

  • CPU Utilization: This metric identifies the processing power required to run an application on a selected instance.
  • DiskReadOps: This metric checks all the read operations from all instance store volumes.
  • DiskWriteOps: This metric checks all the write operations to all instance store volumes.
  • NetworkIn and NetworkOut: These metrics check the number of bytes received and sent by the instance on all network interfaces.

Can you change an AWS EC2 instance type?Yes, you can change the type of an AWS EC2 instance depending on your needs. You can easily identify if the instance is overloaded by monitoring the CPU and memory utilization of the instance, then you can downgrade it anytime if necessary.

On the other hand, if your t2.micro instance is too small for its workload, you can increase its size by changing it to a bigger T2 instance type, such as t2.large.

AWS EC2 instances pricingThere are multiple ways to pay for Amazon EC2 instances, but you can also get started with the AWS Free tier. Let’s take a look at all the possibilities at your disposal.

What can you do with the AWS Free tier?The AWS Free tier lets you access AWS services for 12 months free of charge. You can use an AWS EC2 instance with the AWS Free subscription under the following conditions:

  • A maximum of 750 hours per month of Linux, RHEL, or SLES t2.micro or t3.micro instances dependent on the region.
  • A maximum of 750 hours per month of Windows t2.micro or t3.micro instances dependent on the region.

On-demand instancesThere is no long-term commitment when you use on-demand instances, so you just need to pay your usage per second or per hour with a minimum period of 60 seconds. On-demand instances are mainly used for short-term, irregular workloads that can be interrupted. They’re more costly than Spot instances, which we’ll detail right after.

Spot instancesIf you require to launch your instance very quickly, then you can use Spot instances, which let you request unused EC2 instances at very high discounts. Spot instances can be up to 90% cheaper than on-demand instances, though they’re mainly used for quick data analysis, batch jobs, and background processing.

Saving plansWith Savings plans, organizations can take advantage of a more flexible pricing model with low prices on EC2 and Fargate usage. However, customers need to use these instances for a one- or three-year term.

Dedicated hostsA Dedicated host is a physical EC2 server with a capacity that is fully dedicated to your use. Dedicated hosts can be purchased on-demand (hourly), and you can save money by using your own software licenses, including Windows Server, Microsoft SQL Server, SUSE, and Linux Enterprise Server.

ConclusionOverall, AWS EC2 provides a very wide range of instance types with a large choice of processors, storage, networking, and operating systems. Amazon also offers different pricing models allowing organizations to choose the instance type that fits the needs of their workloads. We hope that after reading this overview you’ll be ready to get started with your first EC2 instance in the AWS cloud.

View Details

ChatGPT has rapidly ushered AI into mainstream technology in a big way. Launched in November of 2022, ChatGPT has already garnered millions of users with its natural language AI-based responses to a huge variety of queries that range from writing term papers, articles, and software to answering emails, creating song lyrics, and even debugging many types of programming code.

In case you were wondering, ChatGPT stands for Chat Generative Pre-Trained Transformer. It is a chatbot launched by OpenAI and it’s built on top of OpenAI’s GPT-3 family of large language models.

Microsoft is one of the main backers of OpenAI. Satya Nadella, Chairman and CEO of Microsoft has stated that “We formed our partnership with OpenAI around a shared ambition to responsibly advance cutting-edge AI research and democratize AI as a new technology platform.” He continued, “In this next phase of our partnership, developers and organizations across industries will have access to the best AI infrastructure, models, and toolchain with Azure to build and run their applications.”

Sam Altman, CEO of OpenAI added that “The past three years of our partnership have been great. Microsoft shares our values and we are excited to continue our independent research and work toward creating advanced AI that benefits everyone.” ChatGPT was indeed trained on the Microsoft Azure supercomputing platform.

ChatGPT gained quite a bit of notoriety by generating passing grades on law exams at the University of Minnesota. However, ChatGPT is not a search engine like Google or Bing: Search engines index the web to help users find information, while ChatGPT does not have the ability to search the internet for current information. Instead, it uses the information it learned from training data to generate responses.

The data used to train ChatGPT was collected prior to 2022. ChatGPT is currently open to the public and is free to use. However, the company is currently piloting a new ChatGPT Plus subscription plan that will provide priority responses for $20 per month.

AWS CTO Werner Vogels Says ChatGPT is “not concerned about the truth”However, in spite of its surging popularity, not everyone is a fan of ChatGPT and there are several good reasons for that. AWS CTO Werner Vogels took to Twitter to criticize ChatGPT regarding its answer to one of his questions regarding cloud cybersecurity.

It’s commonly accepted that many businesses have moved to the cloud in order to improve security. However, much to the dismay of the AWS CTO, when he asked the chatbot to write a news story about the impact of cybercrime on the growth of cloud computing, ChatGPT created an article that was titled “Cybercrime takes a toll on cloud computing’s rapid growth”.

Without citing any facts, the article went on to say:

“According to a recent report, cybercrime has had a significant impact on the growth of cloud computing, with businesses losing billions of dollars each year due to data breaches, hacking attempts and other forms of cyberattacks. Many businesses are now questioning the security of the cloud and whether it is worth the risk.”

The AWS CTO saw ChatGPT write a misleading article about cybersecurityWerner Vogels ripped ChatGPT stating that it was “not concerned about the truth”. He went on to explain that “security has become one of the main drivers of companies migrating to the AWS.” Vogels continued, “However, if you ask ChatGPT it will tell you the opposite, based on ‘a recent report’, which shows you it is not concerned about the truth, but just about putting words together convincingly.”

Stack Overflow temporarily bans ChatGPT-generated answersWerner Vogel isn’t the only one to take issue with ChatGPT limitations. The well-regarded tech Q&A site StackOverflow has temporarily banned ChatGPT-generated responses to questions.

The StackOverflow moderators stated that ChatGPT answers are “potentially harmful” to users looking for correct answers. They went on to say, “The primary problem is that while the answers which ChatGPT produces have a high rate of being incorrect, they typically look like they might be good and the answers are very easy to produce.”

If you want to find out more for yourself about ChatGPT, you can access the chatbot by visiting chat.openai.com and creating a free OpenAI account.

View Details

Microsoft is adding a new policy that enables IT admins to customize the Windows Search experience on the Windows 11 taskbar. The company announced yesterday that the feature is already available in the latest Windows 11 preview builds for Insiders in the Beta and Dev channels.

Microsoft recently started testing improvements to the search experience on the taskbar to help users find documents, apps, settings, and important information. “After shipping Windows 11 with a search icon on the taskbar, we received feedback that some didn’t find it discoverable or engaging enough. Based on this feedback, we are adding the ability for users to search directly from the taskbar,” Microsoft explained.

With the new policy, IT Pros can hide the taskbar’s search icon by default on Windows 11 PCs. Moreover, administrators can also hide the search icon with or without an accompanying label. Microsoft says that it’s also possible to only show a search box similar to the one found on the taskbar in Windows 10.

How to customize the search experience on the Windows 11 taskbarMicrosoft notes that Windows admins can configure the new search experience on the taskbar through Configuration Service Provider (CSP) or Group Policy. Notably, the feature will respect the default settings on Windows 11 devices in tenants where IT admins have either not configured or turned off the policy.

Meanwhile, Windows 11 users will be able to change the search experience in taskbar settings. To do this, head over to the Settings app and click Personalization >> Taskbar. Alternatively, they can right-click on the taskbar and then select Taskbar settings.

Microsoft plans to launch the new search experience on the Windows 11 taskbar to all managed devices on April 11. However, Microsoft will roll out an optional quality update to make the ConfigureSearchOnTaskbarMode policy available for enterprise customers later this month. This release should enable IT admins to configure the new search experience ahead of its official release on Windows 11 machines.

View Details

MC495330 – Updated February 2, 2023: Microsoft updated the content below to show as intended. Thank you for your patience.

Video Filters are a new feature in Microsoft Teams meetings that will allow participants to augment their video stream with visual effects, such as frames and styles. These filters are built on the Teams Platform infrastructure and provided by Microsoft first- and third-party partners as apps and displayed as a collection of filters.

This message is associated with Microsoft 365 Roadmap ID 86811

When this will happen:

  • Public Preview: Microsoft will complete rollout in late January 2023.
  • Standard Release and GCC: Microsoft will begin rolling out in early March (previously early February) and expect to complete rollout in late May (previously late April).

How this will affect your organization:

Users can browse and select video filters from the pre-join screen and in-meeting scenarios. During pre-join, users can access Video filters from the quick tray when they have the camera enabled. After joining a meeting, users will be able to apply effects from the meeting toolbar with the camera fly-out window or navigate all Video filters options on the side pane by clicking the Video effects button under the More menu.

View image in new tab

View image in new tab

View image in new tab

View image in new tab

To apply video filters, users will need to give consent to install the apps.

View image in new tab

Note: The video filters can be enabled/disabled by app level from the Tenant Admin Center. For EDU tenants, these apps will be turned off by default and can be turned on by individual tenant admins, if required.

What you need to do to prepare:

You may want to consider updating your training and documentation as appropriate.

View Details

MC510331 – Microsoft Teams will support Targeted Release for commercial cloud customers.

With this support, users opted-in to Targeted Release will be the first production users to see the latest Microsoft Teams features and help shape the product by providing early feedback.

Prior to this, Targeted Release provided early access to OneDrive for Business, SharePoint Online, Office for the web, Microsoft 365 admin center and some components of Exchange Online.

What is Targeted Release?

  • Targeted release allows early access to high quality feature releases across Microsoft 365 apps and services, which customers can opt-in to prepare for the upcoming changes before they roll out to the rest of the organization.
  • Customers can choose to have a select set of individuals, or the entire organization receives updates early via Targeted Release.

This message is associated with Microsoft 365 Roadmap ID: 117577

When this will happen:

Microsoft will begin rolling out in late February and expect to complete by mid-March 2023.

How this will affect your organization:

If you already have users set up for Targeted Release on a test or production tenant, these users will start getting early access to new and updated Microsoft Teams features.

If you would like to set up Targeted release for specific users or your organization to receive early access to Microsoft Teams features, please follow the process to set up the release option in the admin center. PS: this will also provision the users to targeted release for other Microsoft 365 products. If you desire to have users just in early access for Teams then please use Teams admin preview policy.

Note: Tenants with users currently in Teams Technology Adoption Program (TAP) will remain in TAP, and this change will not impact those users.

What you need to do to prepare:

Review: Set up the Standard or Targeted release options.

Update your training and documentation as appropriate.

Please encourage your users to send feedback about new Teams features through Help > Give feedback and following the prompts. Their feedback will help shape the Microsoft Teams experience for rest of your organization.

View Details

MC510330 – Microsoft Purview Information barriers v2 (IB v2) is now generally available for all new customers onboarding to IB after February 15, 2023. IB v2 has enhanced architecture which enables the following features:

  • Large scale segment support: The segment limit in organizations has increased from 250 to 5,000 segments.
  • Multi-segment support: Users can be assigned to up to 10 segments instead of being limited to just one segment.
  • Flexible user discoverability: Organizations can now choose to allow IB-protected users to discover each other while adhering to IB communication and collaboration policies.

Organizations with IB configured prior to February 15, 2023, will be eligible to upgrade to IB v2 in the future. For more information about the upgrade timeline, keep checking the information barriers roadmap.

This message is associated with Microsoft 365 Roadmap ID 93232

When this will happen:

Standard Release: Microsoft will begin rolling out early February and expect to complete by mid-February 2023.

What you need to do to prepare:

There is no action needed to prepare for this change.

Additional information

View Details

MC510329 – To align deeper with the OKR methodology, “Projects” in Viva Goals is renamed to “Initiatives”. In addition to changing the default terminology to Initiatives, Viva Goals will also be introducing the ability for organization admins to customize the term to a term of your choosing.  

When this will happen:

Standard Release: Microsoft will begin rolling out mid-February 2023 and expect to complete by late February 2023.

How this will affect your organization:

  • This change will not affect existing users and orgs in your tenant.
  • Any new organizations will use the term “initiatives”.
  • If any org admin needs to customize the term, they can do so in the org admin section.

What you need to do to prepare 

  • This change will not affect existing users and orgs in your tenant.
  • Any new organizations will use the term “initiatives”.
  • If any org admin needs to customize the term, they can do so in the org admin section.

View Details

MC500906 – Meeting Recap is a new feature on Outlook on the web that allows meeting participants to quickly access meeting content, such as the meeting recording, easily from the calendar event. After a meeting has ended, users can open a meeting on their calendar to find links to meeting artifacts for easy access. The feature currently supports meetings scheduled using Microsoft Teams with the following limitations:

  1. Meeting recordings started through auto-record in Teams will not appear in the recap
  2. Teams channel meetings
  3. Meetings scheduled on group calendars
  4. Ad-hoc meetings

This message is associated with Microsoft 365 Roadmap ID 98805

When this will happen:

Targeted Release: Microsoft will begin rolling out in late January and expect to complete rollout by late February.

Standard Release: Microsoft will begin rolling out in late February and expect to complete rollout by late May.

How this will affect your organization:

On the web version of Outlook, when meeting participants click on a meeting event in their calendar to view details, they may now find a link to various meeting content if they exist. E.g. if the meeting was recorded, a link to the recording will be accessible from the meeting invite from the calendar. Note that this is simply a link to the content and Outlook does not store any of the content as part of this feature. User access and permission to view the content such as the recording remain unchanged and controlled by the file owner.

View image in new tab

View image in new tab

What you need to do to prepare:

There is nothing you need to do to prepare at this time. You may want to update any relevant training documents as appropriate.

For more information, please read this Outlook announcement.

View Details

MC500904 – Microsoft is updating the Yammer mobile app’s navigation to make it easier for people to jump to their profile, access their Bookmarks, and view and adjust Settings.

When this will happen:

Rollout will begin in late January and users can expect to begin seeing this change in early February.

How this will affect your organization:

Microsoft will be adding a ‘View All‘ tab in the navigation bar at the bottom of the app which will open a larger menu with these shortcuts. The profile icon in the top left will now only be a shortcut to the user’s profile. Instructions that include accessing the existing shortcuts may need to be updated. The navigation updates themselves don’t require additional actions.

View image in new tab

View image in new tab

What you need to do to prepare:

There is nothing you need to do to prepare as these changes will be automatic.

View Details

MC500903 – Praise in Microsoft Teams is designed to appreciate the effort that goes into the wide-ranging, collaborative work that Teams users do. Users can send praise to their colleagues through the messaging extension pinned to the Teams messaging bar or through the Microsoft Viva Insights app in Teams. For both, admins can use the Microsoft Teams admin center to enable/disable Praise.

With updates coming soon, praises received will be highlighted on a user’s profile card in Teams and Outlook. There are settings available for users that prevent praise highlights from being visible on their profile card.

This message is associated with Microsoft 365 Roadmap ID 109551

When this will happen:

Standard Release: Microsoft will begin rolling out in early February and expect to complete rollout by late February.

How this will affect your organization:

When a user receives praise, the title and note will be visible on their profile card in Team and Outlook People in their organization whom they have emailed, chatted, or met with in the past year will be able to view their praise details.

View image in new tab

Users can go to settings in their Viva Insights app in Teams and switch the praise visibility toggle off to disable praise highlights from showing.

View image in new tab

What you need to do to prepare:

Refer to Praise with Viva Insights | Microsoft Docs which will be updated in sync with this roll out.

Help and support

View Details

MC500891 – The Service Trust Portal is Microsoft’s public site for publishing audit reports and other compliance-related information associated with Microsoft’s cloud services.

“My Download History” is a net new functionality now live on STP. On the My Download History tab, you can view and export a download history of documents downloaded from the Service Trust Portal within the last 18 months. The history includes the document title and download date, and the document status, such as whether it is live, has a newer version, or has been deleted. The full download history can be exported to a CSV file.

View image in new tab

When this will happen:

Available now.

How this will affect your organization:

With this change you can view and export a download history of documents downloaded from the Service Trust Portal within the last 18 months.

What you need to do to prepare:

You may consider updating your training and documentation as appropriate.

Additional information

View Details

MC500888 – Originally announced in MC450188 (October ’22), Outlook for Android is making it easier to find all your contacts, files, and more. See our blog post at Navigating Outlook for Android and iOS – Microsoft Community Hub

Users will see changes to the tab bar at the bottom of Outlook for Android, a new Floating Action button, search will be renamed Feed with a new Icon, and Contacts and Files will be found under the “More” button.

Microsoft apologizes for the delay and is now proceeding with the rollout of this feature.

This message is associated with Microsoft 365 Roadmap ID 100570

When this will happen:

These changes are available now in Android Beta.

Microsoft will begin rolling out to production mid-January and plan to complete rollout by late February.

How this will affect your organization:

There is no admin-level control of this change. Admins can learn more about these changes and why they are happening in our blog post at Navigating Outlook for Android and iOS – Microsoft Community Hub

Blog

View Details

MC500886 – Originally announced in MC462919 (October ’22), ​​Context IQ allows users to easily search for and insert entities like people and files in a message they’re writing.

Microsoft apologizes for the delay and are now proceeding with the rollout of this feature.

This message is associated with Microsoft 365 Roadmap ID 88943

When this will happen:

Microsoft will began rolling out in late December and expect to complete rollout by early February.

How this will affect your organization:

When users type the “@’ key, a menu will appear that allows them to search for, filter, and insert entities that exist across their Microsoft 365 account. Outlook can also proactively assist users by suggesting relevant content to insert based on the context of their current message.

View image in new tab

What you need to do to prepare:

There is no action required at this time. For more information, please visit this page.

Blog

View Details

Amazon Web Services (AWS) has announced the launch of its second cloud region in Melbourne, Australia. The new Asia Pacific region (codenamed: ap-southeast-4) will consist of three Availability Zones, and it should help customers comply with data residency and regulatory requirements.

AWS first announced its plans to open the new Melbourne region back in December 2020. The company plans to invest $4.5 billion in the country by 2037. This AWS cloud region is expected to drive economic development by creating more than 25,000 full-time job opportunities for local people annually. It will provide services such as storage, compute, networking, developer tools, business applications, data analytics, security, and more.

“The AWS Asia Pacific (Melbourne) region adds to our ongoing infrastructure expansion and investments in Australia since we launched the AWS Asia Pacific (Sydney) region in 2012. We are proud to deepen our investment by driving local job creation, building cloud skills, and creating opportunities for growth and collaboration with our local customers and AWS Partners,” said Prasad Kalyanaraman, VP of Infrastructure Services at AWS.

Additionally, AWS has pledged to become a carbon-negative organization by 2040. Moreover, the company highlighted three projects that will generate 717,000 megawatt-hours of renewable energy annually to support 115,000 Australian households.

AWS continues to invest in the cloud computing spaceSince 2017, AWS has announced various programs (like AWS Academy, AWS Educate, and AWS Industry Quest) to train more than 200,000 Australian citizens with cloud skills. The company has announced a new “Victorian Digital Skills” program to help local people gain access to higher-paying jobs.

Meanwhile, AWS continues to invest in data centers to better compete with rivals like Microsoft, Google, and Oracle. The new Melbourne region will join the existing cloud regions already available in the Asia Pacific region. These include Tokyo, Mumbai, Singapore, Hong Kong, Hyderabad, Sydney, Seoul, Jakarta, Osaka, Beijing, and Ningxia regions.

View Details

Microsoft has released a new feature that adds support for concurrent license assignments in Exchange Online. The latest release enables organizations to assign more than one Exchange Online license to each Azure Active Directory (Azure AD) user.

Previously, the Microsoft 365 admin center and Azure AD PowerShell restricted IT admins from allocating concurrent Exchange Online licenses to the same Azure AD user. This means that administrators were required to remove the old license before making any new assignments.

Specifically, the license assignment wasn’t permitted for any combination of the following plans: Exchange Online Essentials, Exchange Online Kiosk, Exchange Online Plan 1, Exchange Online Plan 2, Microsoft /Office 365 (F1, F2, F3, E1, E3, E5, A1, A3, A5), Microsoft 365 Business packages, as well as select Microsoft Teams and Project licenses.

With this release, Microsoft has now introduced the ability for IT admins to stack licenses for Exchange Online customers. This capability has been available for both SharePoint Online and Microsoft Teams for quite some time now. Microsoft notes that the license that supports more features (such as protocol access, transport limits, and mailbox quotas) will take higher precedence over the other assigned plan.

“For example, if the user has E3 and Kiosk assigned, but E3 is then removed from the AAD user, then Exchange Online will ensure the corresponding Mailbox User or Mail User will be granted access to Kiosk features only. If the user is later also assigned E5, Exchange Online will grant the user access to all the features of E5, regardless of if the user still has assigned a concurrent Kiosk license,” the Exchange team explained.

Benefits of concurrent Exchange Online license assignmentsMicrosoft explains that the new approach will help to streamline the Exchange Online license management process for large enterprise customers. It should also be helpful for companies switching to SharePoint or Microsoft Teams. Microsoft plans to roll out this feature to government customers in the first half of this year.

In related news, Microsoft is working to improve the Exchange Server update and deployment process in on-premises environments. The company has invited IT Pros to provide their feedback through an “Update Experience” survey until the end of this month.

View Details

Microsoft has announced a new multibillion-dollar partnership with OpenAI. The company explained that the deal marks the beginning of the third phase of its existing partnership with the ChatGPT-maker, following two previous investments in 2019 and 2021, respectively.

In a press release, Microsoft highlighted that this new partnership should enable both companies to create AI-powered experiences to help developers and organizations build and run their workloads. Microsoft has yet to disclose the terms of its extended partnership with OpenAI, but some previous reports indicated that it planned to invest around $10 billion and take a 49 percent stake.

Microsoft has detailed several benefits of its multibillion-dollar deal with OpenAI. First off, the company aims to make Azure OpenAI’s exclusive cloud provider that will power all workloads across API services, products and research. Microsoft will also support OpenAI’s research with the deployment of specialized supercomputers.

Microsoft will deploy OpenAI models to its consumer and enterprise productsAdditionally, Microsoft will integrate OpenAI’s technology into its various enterprise and consumer-focused products. The company is reportedly looking to integrate ChatGPT into the Office applications, such as Word, PowerPoint, and Outlook. Microsoft also plans to leverage ChatGPT to make its Bing search engine more competitive with Google.

“We formed our partnership with OpenAI around a shared ambition to responsibly advance cutting-edge AI research and democratize AI as a new technology platform,” said Microsoft CEO Satya Nadella. “In this next phase of our partnership, developers and organizations across industries will have access to the best AI infrastructure, models, and toolchain with Azure to build and run their applications.”

Last week, Microsoft announced the general availability of its Azure OpenAI service. The new solution lets developers access OpenAI’s models (GPT-3.5, Codex, and DALL-E), and incorporate AI tools into their applications. It will be interesting to see how Microsoft plans to leverage this new partnership to further commercialize Azure OpenAI.

View Details

In this article, I’ll show you how to successfully install Windows 11 or Windows Server 2022 in VMware Workstation 17 Pro.

It’s taken more than a year for VMware to release a new version of VMware Workstation Pro that officially supports Windows 11. But there are still some issues that haven’t been resolved since the previous release, version 16. For example, Workstation Pro detects you are installing Windows from an ISO file but Windows Server 2022 setup fails because the default hardware configuration assigned to the virtual machine (VM) doesn’t work with Windows Server.

But the solution is simple and I’m going to share it with you below.

Before you can follow the instructions below, you’ll need an Internet connection to download the relevant image files for the version of Windows that you want to install. And you’ll need either a trial version or licensed version of VMware Workstation Pro installed on your local PC.

How to install Windows 11 on VMware Workstation 17 ProBefore you can install Windows in a virtual machine powered by VMware Workstation Pro, you are going to need to download the latest image file (ISO) for Windows.

Download an evaluation version of Windows or Windows ServerAll currently supported versions of Windows and Windows Server are available to download from the Microsoft Evaluation Center.

Microsoft Evaluation Center (Image Credit: Petri/Russell Smith)* Select the version of Windows you want to download from Microsoft’s website. * In this example, I’m going to download and install Windows 11 Enterprise.

Windows 11 Enterprise download iso file (Image Credit: Petri/Russell Smith) Fill out all the required fields on the registration form and click Download now* at the bottom of the page.

Evaluate Windows 11 Enterprise registration form (Image Credit: Petri/Russell Smith)* Select the 64-bit edition of Windows and save the file using your browser to your PC.

Please select your Windows 11 Enterprise download (Image Credit: Petri/Russell Smith)Install Windows in a VMware virtual machineNow that you have the ISO file for Windows on your device, you can install Windows in a VM.

  • Launch VMware Workstation Pro.
  • Click Create a New Virtual Machine on the Home tab.

Create a new virtual machine VMware Workstation Pro (Image Credit: Petri/Russell Smith) In the New Virtual Machine Wizard, check Typical (recommended) and click Next >*.

VMware Workstation Pro new virtual machine wizard welcome dialog (Image Credit: Petri/Russell Smith) In the Guest Operating System Installation dialog, check Install disc image file (iso) and click Browse. Select the ISO file you downloaded from the Microsoft Evaluation Center in the previous steps. Click Next* to continue.

Guest operating system installation (Image Credit: Petri/Russell Smith) Accept or change the given name for the new VM in the Name the Virtual Machine dialog window and click Next* to continue.

Name the Virtual Machine (Image Credit: Petri/Russell Smith) If you are installing Windows 11, you’ll need to enter a password that VMware can use as an encryption key for the Trusted Platform Module (TPM). Enter a password and make sure you record it somewhere secure and safe. You’ll need it to start the VM. * Click Next*.

Encryption information (Image Credit: Petri/Russell Smith) Accept the default disk configuration on the Specify Disk Capacity dialog by clicking Next*.

Specify disk capacity (Image Credit: Petri/Russell Smith) Click Finish in the Ready to Create Virtual Machine* dialog to start the new VM and begin the Windows installation process.

Ready to create virtual machine (Image Credit: Petri/Russell Smith)* VMware Workstation Pro will create the disk for the VM and then start the virtual machine. You’ll need to quickly click on the VM screen and press the spacebar on your keyboard to boot the VM from the virtual DVD ROM drive where your downloaded ISO file is attached. If you don’t manage in time, shut down the VM and start it again.

Press any key to boot from CD or DVD (Image Credit: Petri/Russell Smith)Once you boot into Windows setup inside the VM, you install Windows 11 in the same way as installing the OS on a physical device.

Related article: How to Install Windows 11 – The Ultimate Guide

Getting past the ‘Windows Cannot Find Microsoft Software License Terms’ errorIf you are installing Windows Server 2022, you might get an error when stepping through the install process: ‘Windows cannot find the Microsoft Software License Terms’.

To complete the install process successfully, follow the steps below:

  • If your Windows Server VM is running, stop it by selecting VM from the menu then Power > Power Off. Confirm the operation by clicking Power Off in the pop-up dialog.

Power Off virtual machine (Image Credit: Petri/Russell Smith) On the tab for the VM, click Edit virtual machine settings*.

Windows Server 2022 tab (Image Credit: Petri/Russell Smith) In the Virtual Machine Settings dialog, click Floppy in the list of hardware devices on the left. On the right, uncheck Connect at power on and click OK*.

Virtual Machine Settings dialog (Image Credit: Petri/Russell Smith) Back on the tab for the VM, click Power on this virtual machine* and the installation of Windows Server should complete as normal without an error.

And that is it! If you’d like more information on installing Windows 11 in a Hyper-V virtual machine, check out the link below.

Related articles

  • Guide: How to Install Windows 11 in a Virtual Machine (Hyper-V)

View Details

Microsoft Teams has introduced a set of new video filters in preview to enhance video calls and meetings. The Microsoft Teams desktop app already supports brightness and soft-focus filters, but the latest update now lets participants apply frames and styles before and during meetings.

“Video Filters are a new feature in Microsoft Teams meetings that will allow participants to augment their video stream with visual effects, such as frames and styles. These filters are built on the Teams Platform infrastructure and provided by Microsoft first- and third-party partners as apps and displayed as a collection of filters,” the company explained in a message on the Microsoft 365 Admin Center.

To apply the new video filters, attendees will need to provide consent to install the Custom Filters app to process data about their facial features. Once enabled, Microsoft Teams users can enable video filters from the quick tray available on the pre-join screen. It’s also possible to apply video effects during the meeting by clicking the More menu and selecting the Video effects button.

IT admins can use the Custom Filters App to control video filter effectsMicrosoft notes that video filters are enabled by default for all commercial and GCC customers. Administrators can head to the Teams admin center to disable them for end users in their organization. Meanwhile, the feature is turned off in education tenants, and it’s up to the IT admins to allow meeting participants to apply video effects with an app permission policy.

It is important to note that support for new video filter effects is currently available in the public preview version of Microsoft Teams. Microsoft plans to start rolling out the feature to all commercial and GCC customers next month. The company has recently announced several updates for Microsoft Teams, Viva, Outlook, as well as other Microsoft 365 apps, and you can find more details in our separate post.

View Details

In this article, I’ll show you how to export Active Directory users to a CSV file using PowerShell and Active Directory Users and Computers (ADUC). Using PowerShell is recommended as IT Pros can use it to extract task-specific information about a subset or all of their users from Active Directory. This can be really helpful when you need to export all of your user information for access into other systems like an HR import or third-party authentication systems.

There is a myriad of commands, cmdlets, and other functions that allow you to obtain said information with ease. This article will demonstrate the most common tasks you’ll come across when exporting AD information and the intricacies of these cmdlets to finish the job.

How to export Active Directory users to CSV The easiest way to export a list of users in Active Directory to a .CSV file is to use PowerShell Export-CSV cmdlet. Here’s the command you need to use to export all of your users to a CSV file.

Get-ADUser -filter * -Properties * | export-csv -path AllUsers.csv Exporting all of your users to a CSV file with the ‘Export-CSV’ cmdletKeep reading if you would like to learn other commands to export a specific set of users from Active Directory!

How to export Active Directory users to CSV with PowerShellBefore we get started, you’ll need to be using a computer account that has read permissions to your Active Directory, and an appropriate shell to accommodate this. You can either log into a domain controller (not generally advisable) or log into a workstation with the Remote Server Administration Tools (RSAT) installed.

Using Get-ADUser to get a list of users in Active DirectoryThe most common PowerShell cmdlet we’ll use is Get-ADUser. Go ahead and launch the Active Directory Module for Windows PowerShell from the Start Menu.

Launching ‘Active Directory Module for Windows PowerShell’ from the Start MenuTo get a list of all users with the default attributes output to the console, enter this command.

Get-ADUser -filter * A somewhat useful output from the ‘Get-ADUser’ PowerShell cmdletAs you can see above, this will list every user in your Active Directory with the default attributes:

  • DistinguishedName
  • Enabled(/Disabled)
  • GivenName
  • Name
  • ObjectClass
  • ObjectGUID
  • SamAccountName
  • SID
  • Surname
  • UserPrincipalName

Now, my Windows Server 2022 Hyper-V environment is rather simple. I have a dozen or so users. Your enterprise environment likely consists of hundreds or thousands of users. So, sending the output to the console won’t really be helpful.

The main point of this post is to explain how to export them to a much more manageable and helpful interface – a CSV file. You can use Microsoft Excel or other software to manipulate this data – we’ll go into this more throughout this article.

To export all your users to a CSV file, run the following command:

Get-ADUser -filter * -Properties * | export-csv -path AllUsers.csv Exporting all of your users to a CSV file with the ‘Export-CSV’ cmdletThe ‘-filter ’ tells the command to export EVERY user. The ‘-Properties ’ tells the command to export every attribute for each user account. And yes there are many. I opened the file in Excel to show you an example of how the output looks.

Excel showing the output of our CSV exported fileHow to export all user properties for a single userYou’ll often need to work on a specific user and investigate an attribute or two for them. Let me show you how to export all the properties for one user.

Get-ADUser mreinders -properties * And yes, there are a lot of attributes for each user. I am showing only a few columns/attributes. In Excel, the columns go all the way to ‘CV’!

How to export specific user attributes with Select-ObjectSo, we have shown you the default attributes and then ALL the attributes. However, to stay efficient, we of course need to be able to export only pertinent attributes for your users. We will use the Select-Object command to achieve the results we need.

Let’s grab each user’s Name, their Department, and their email address (mail) with the following command:

Get-ADuser -filter * -Properties * | Select-Object name, description, office, department, mail | export-csv -path UsersAttributes.csv Using the ‘Select-Object’ cmdlet to extract only a subset of attributesIf we open the file in Excel, we can see only the attributes we asked for are in the output.

Excel showing the output of our CSV file with select attributesNow, we have some data worth our while. In Excel, we of course have the ability to filter specific columns/attributes to find everyone in the Houston office or everyone in the HR department.

How to export Active Directory users from a specific organization unit (OU)We will also come across the need to pull all the users from a specific organizational unit (OU) instead of our entire directory. We can use the ‘-SearchBase‘ command to accomplish this. We will use the DistinguishedName attribute of said OU to make this work.

Get-ADUser -Filter * -SearchBase "OU=Test Users,DC=reinders,DC=local" -Properties * | Select-Object name | export-csv -path UsersinOU.csv Excel file showing the output from our CSV file with users from a single OU in ADAnd there we have it. We have our simple list of users in a specific OU. It is clear by now how easy and powerful PowerShell is in disseminating information and finding just the data we need!

How to export Active Directory users with the last logon dateNow, let’s dig into some more useful and helpful attributes that will undoubtedly assist you in troubleshooting some service tickets in your organization. When did that user last log onto the domain? Let’s find out with the command below:

Get-ADUser -filter * -Properties * | Select-Object name, lastlogondate | export-csv -path LastLogonDate.csv This Excel output shows the Name and LastLogonDate attribute of our usersAgain, my sample data is not the most useful set in the world, but, you get the idea. Plus, you can sort and filter this data easily in Excel.

How to only export enabled Active Directory user accountsIf you want to export a list of your users but exclude any disabled accounts, you can use the ‘Enabled‘ attribute in your filter section. Here’s the command you need to use:

Get-ADuser -Filter {(Enabled -eq $True)} -Properties * | Select-Object name, lastlogon | export-csv -path EnabledUsers.csv This output shows all the enabled users (Disabled users are excluded)Notice someone missing by chance? I disabled ‘Cassandra Reinders’ before running the command and she is nowhere to be found. So, that works!

How to export all Active Directory users by NameAlright. Now, you may have a need, maybe for HR, to get a list of all your users with just their names. We can use a previous command with a tweak or two to accomplish this.

Get-ADUser -filter * -Properties * | Select-Object givenname, surname, name | Export-CSV -path Users-Names.csv We are able to see the details of our users’ Name attributes in this outputHere, we have each user’s first name (givenname), last name (surname), and their ‘complete’ name (name). Again, HR would obviously love this type of information.

Plus, whenever you are exporting user information to import into another application or cloud service, this is precisely the type of information you will need to present to them. Again, tweaking the Get-ADUser command is vital and very helpful!

How to export all Active Directory Users by Name and LastLogonDateLet’s export all our users with their full name information and the attribute showing when they last logged onto a domain computer.

Get-ADUser -filter * -properties * | Select-Object givenname, surname, name, lastlogondate | Export-CSV -path Users-LastLogon.csv This screenshot also shows the Name details and the LastLogonDate attributeJust like in similar commands above, we have a simple list of our users and their last logon time/date in a simple, easy-to-read format. Excellent!

How to export Active Directory users to CSV with Active Directory Users and Computers (ADUC)Well, did you know that you can also use the Active Directory Users and Computers snap-in/tool to export users to a CSV file? Actually, there’s probably a very good chance you kind of do, and I’ll tell you why.

When you go to click the Refresh icon on the toolbar, the icon just to the right of Refresh is ‘Export List.’ That’s right. You probably clicked ‘Export List’ by mistake and ‘woven a tapestry of obscenity that, as far as we know, is still hanging in space over your datacenter.’

Anyway, let me show you how to use this function.

How to export Active Directory users from a specific folder to CSVGo ahead and navigate to a specific folder/OU in Active Directory. Then, click the ‘Export List‘ button.

We can use Active Directory Users and Computers (ADUC) to export a small subset of information of our usersWhen we open the file in Excel, we see a much more limited set of information and attributes. This function only exports the information displayed in the ADUC tool. To extract more attributes, you would need to first modify the displayed columns in the GUI. You would then run the export again.

This is a rather limited function. Unfortunately, it only exports what is displayed on the screen. So, if you click on the root of your domain and click ‘Export List’, you will only get what you see.

When we export from the root of the domain, you simply get the view you see in the ADUC toolProbably not the most helpful information. But, you get the idea.

ConclusionWell, as you can see, there are a lot of ways to extract and export very useful information on your users in Active Directory. This post only scratches the surface in terms of the power and breadth of using PowerShell to get at this information. I didn’t even touch on manipulating the information in Active Directory using the Set-ADUser command. Besides changing a user’s ‘Department’, you can also use a PowerShell Foreach loop to change everyone’s business address in the ‘Pittsburgh, PA’ office to the new office building you just moved into!

Thank you for reading about exporting users to CSV file. If you have any questions or comments, please leave a comment or question below!

View Details

This Week in IT, researchers claim ChatGPT could be used to create malware that can morph to evade detection. So, I discuss what you might do about that today. Googles says Chromium will start to phase in the use of Rust to improve security without affecting performance. And Twitter officially bans third-party developers using its APIs.

View Details

MC499441 – The Room Remote feature enables touchless meetings by allowing users to control a nearby shared meeting room device from their Desktop/PC with Teams client.

This feature was first launched on Mobile and will now be available on your Desktop device formfactor. 

This message is associated with Microsoft 365 Roadmap ID 95482

When this will happen

Rollout is expected to start mid-January 2023 and will complete late January 2023.

How this will affect your organization

This new feature will be automatically available on the Teams Desktop Client on your Windows Desktop PC so long that the Room Remote feature is enabled on the shared meeting room device and in TAC. 

What you need to do to prepare

No preparation work required. 

View Details

MC499440 – Cross-tenant synchronization lets you automate creating user accounts across tenants in your organization. Users created by the synchronization process continue to authenticate in the same way they do on their primary tenant and each application can assign conditional access policies as appropriate. So now, users across your organization can access applications regardless of the tenant where they are hosted, including Microsoft applications like Teams and SharePoint, as well as non-Microsoft applications like ServiceNow, Adobe, and hundreds more SaaS apps.

Behind the scenes and transparent to the user, the sync process leverages the robust Azure AD B2B functionality and is fully integrated with Azure AD’s security and governance capabilities such as conditional access, cross-tenant access settings, and entitlement management.

This message is associated with Microsoft 365 Roadmap ID 109568

When this will happen:

Preview: Microsoft will begin rolling out mid-January 2023 and expect to complete by early-February 2023.

How this will affect your organization:

This feature enables multi-tenant organizations to automate creating, updating, and deleting B2B users across tenants within an organization.

What you need to do to prepare:

Once the feature is in public preview, you will be able to choose when to enable cross-tenant synchronization. Prior to the public release, you can begin conversation internally to understand which users need access to which tenants within your organization and understand what attributes you would like to synchronize across tenants.

Additional information

View Details

Microsoft has confirmed that the System Restore feature could break some apps on Windows 11 version 22H2. The company detailed that the problem affects select first and third-party applications that use the MSIX Windows app package format, including Microsoft Office, Windows Terminal, Cortana, Notepad, and Paint.

In Windows 11, System Restore is a recovery tool that allows users to revert their computer’s state to an earlier point in time without losing their files. It’s designed to help users recover certain files and folders (such as registry keys, drivers, installed programs, and system files) to previous versions and settings. This is a useful feature that can undo system changes in case of critical problems or instability issues.

Microsoft explained in a support document that restoring the operating system from a system restore point causes instability issues for some Windows applications on Windows 11 devices. For instance, the app may fail to launch with the “This app can’t open” error message. Moreover, Windows 11 users could see duplicate entries of the app on the Start menu.

Additionally, Microsoft says it’s possible that the app triggers an I/O error, becomes unresponsive, and then crashes on Windows PCs. The bug impacts the latest versions (22H2) of Windows 11 SE, Windows 11 Home and Pro, Windows 11 Enterprise Multi-Session, Windows 11 Enterprise and Education, and Windows 11 IoT Enterprise.

Microsoft suggests a workaround to fix “This app can’t open” errors on Windows 11 version 22H2Microsoft has suggested a potential workaround for customers who run into this issue on Windows 11 PCs. The company recommends that users can open the application again or reinstall the app from the original source/Windows Store. Microsoft notes that installing the latest windows updates might also help to address the problem.

Last week, Microsoft released a PowerShell script to fix a problem that caused app shortcuts to disappear from the Taskbar or Start Menu on Windows 11 and Windows 10. The company acknowledged that the glitch was caused by a Microsoft Defender Antivirus security intelligence update, and you can check out our previous post for more details.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations: Eswar Prakash on Physical Computing with Power PlatformEswar Prakash is a Technical Development Lead in Power Platform at Resonate. In this episode, Eswar joins Azure and Peter to discuss:

  • Unified Communications
  • Power Platform
  • Early computers
  • Mathematics
  • The Internet of Things
  • His passion for Science Fiction and food

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft 365 includes powerful collaboration features that allow teams to work on and share Office documents more easily than ever before. But do you understand how file sharing works within Microsoft 365 and how to manage and secure your files? In this article, we’ll take you through the basics of file sharing and collaboration in Microsoft 365, and how you can control who can share what, and with whom, in the Microsoft 365 Admin Center.

We’ll also be discussing Microsoft 365 Groups, what they’re for, and how to boost your productivity with them. You will also learn how Microsoft’s new dynamic Loop components work and how Office and OneDrive for Business facilitate file sharing and co-authoring.

The benefits of using Microsoft 365 to share files The best way to demonstrate the benefits of using Microsoft 365’s file sharing and collaboration features in your organization is to compare the old (not so good) way of doing it, and the new (wonderful!) way. First, let’s try to envision how we shared files in the past (and still do…).

How we shared files in the pastImagine sending an Excel spreadsheet as an attachment to ten employees in your organization. You ask each of them, as heads of specific teams, to leave feedback about the decommissioning process of a few dozen legacy servers.

To accomplish your task to remove unused and obsolete servers safely, you need to gather feedback from several individuals in varying areas of your organization. Imagine a situation where:

  • Employee A replies to everyone on the thread with their feedback on two of the servers.
  • Then, Employee B replies (to everyone) with their information on three other servers.
  • Now, Employee C replies and mentions that they must contradict information and details about one of the servers from Employee A, and two of the servers from Employee B. They also have info on their own five servers.

Now, before I go off the rails here, imagine anyone being on this thread, much less you, the team lead, on this project, trying to make heads or tails of any precise action items that make sense to everyone involved.

Not a smooth picture, is it? Not the greatest knowledge flow, huh? Could we benefit from some efficiency?

Why using Microsoft 365 for file sharing is more efficientLet’s move into the future (now) and see how we can use file sharing with Microosft 365 to make that process more efficient. As the team lead, here’s what you can do to improve this collaboration process:

  1. You start by creating an Excel spreadsheet with the server names, the team responsible for them, and the ‘server-owner’ of each.
  2. You upload the Excel file into your OneDrive for Business account and share it by creating a link that grants the recipient(s) the ability to open, view, and edit the file.
  3. You then send the email or chat in Microsoft Teams explaining the project and paste the link to the Excel file right in the Teams chat (or channel).
  4. Now, all eleven users can collaborate on one central document in real-time, seeing others’ actions as they work, from any device, at any time.

Now, THAT’S cool! As the team lead, you have a single, central location in the cloud with all critical information about the project.

Let’s say your manager is mobile at the airport, and he’s looking to get a high-level status update on your project. You send him a read-only link to the file in Microsoft Teams. On his mobile device, he opens the Teams app, opens the link, and he’ll be able to open the spreadsheet in the Office mobile app and see your vast progress. Excellent!

Administering Microsoft 365 file sharing So, how can IT Pros manage how files are shared with employees and with external collaborators? Simple – the Microsoft 365 admin center website, and the SharePoint admin center website.

Before we go further, I strongly suggest you or your Office 365 administrators double-check what your sharing and external sharing settings are. If any of them are still at the defaults, I highly suggest you propose and make some changes after clearing them with senior leadership and the various teams that need to be informed. Let me explain.

Checking file sharing settings in the Microsoft 365 Admin CenterTo demonstrate how to verify and make these types of changes, I recently created a small Microsoft 365 Developer sandbox environment. This creates a pre-filled, sixteen-user (plus an admin) Microsoft 365 E5 environment that allows you to develop applications in various pillars of the Microsoft 365 stack.

This just so happens to provide a perfect opportunity to show you how to check these settings in your own environment and make appropriate changes. I will say that the default options are VERY lax in terms of security and integrity. Let me show you.

First, open the Microsoft 365 admin center. Browse to Settings -> Org settings -> SharePoint.

Settings for SharePoint sites in the Microsoft 365 Admin Center (Image credit: Petri/Michael Reinders)As you can see, the ‘Anyone’ option is not a very secure setting. This means that anyone that gains access to the link to this file can access it, read it, and even make changes. I’ll get to that in a moment.

At a minimum, please change this setting to ‘New and existing guests’. When you send this to external users (outside your Office 365 / Azure Active Directory tenant), they will be required to log in with an account associated with the email address you send it to. They can use their own Office 365 email address (if they have one), or a ‘personal’ Microsoft Account (MSA).

The point is, external users now need to at least have an account to authenticate instead of blindly having free reign over your precious files. There are quite a few more settings and granularity in the SharePoint admin center. Let’s go there next.

Additional sharing controls in the SharePoint admin center Now, go back to your Microsoft 365 admin center website, go down to the ‘Admin centers‘ section along the left side, and find SharePoint.

Accessing the SharePoint admin center from the Microsoft 365 admin center (Image credit: Petri/Michael Reinders) Once you have that open, expand the Policies section and click on Sharing.

SharePoint ‘Sharing’ options in the admin center (Image credit: Petri/Michael Reinders)As you can see here, there are a lot of file sharing options. Again, by default, it’s kind of the wild west. When your users share files via SharePoint or OneDrive, they will have the option to share files anonymously. That’s a security no-no, in case it hasn’t sunk in yet.

My recommendation (and common best practice) is to choose the next setting down for both – ‘New and existing guests‘. Again, this requires external users to authenticate against some form of ‘Microsoft authentication mechanism’ to gain access to the file(s).

There are quite a few more settings to investigate and a few more that you need to change.

Additional SharePoint / OneDrive sharing settings in the SharePoint admin center (Image credit: Petri/Michael Reinders)Sharing files with users for real-time collaboration Let’s go ahead and put all this to productive use. I will now demonstrate how to share an Office file with a colleague and how to collaborate in real-time with my developer environment using Microsoft 365.

Sharing a file with a colleague via Microsoft 365First, I will browse to office.com (or microsoft365.com) and log in.

The office.com website (Image credit: Petri/Michael Reinders)Let me click on the Excel app icon along the left side and start a new spreadsheet. I’ll quickly add some sample data (found on the Information Superhighway).

New Excel file – in the cloud! (Image credit: Petri/Michael Reinders)Let me name this file by clicking the title bar where it currently says ‘Book 1’ and name it ‘Sales Figures 2020-2021’. This file is automatically saved in my OneDrive account. Now, let’s share it.

I’ll click the ‘Share‘ button in the upper-right corner and choose Share.

‘Sharing’ my Excel spreadsheet (Image credit: Petri/Michael Reinders) I will not be using the default setting allowing anyone to access the file. I’ll choose the most restrictive option, Specific people. I’ll also check the box for ‘Allow editing‘ so the recipient(s) has/have the ability to make changes to my file.

Choosing to share my file with specific people only (Image credit: Petri/Michael Reinders) Next, I’ll start typing in my colleague Lynne’s name in the To: line and choose it from the autocomplete feature. I’ll then write a concise note to Lynne asking her to look over the numbers.

Sending Lynne a quick note about the spreadsheet we need to review (Image credit: Petri/Michael Reinders) Click Send. The recipient will receive an email with a link to the file. (For some reason, my Microsoft 365 Developer sandbox is not playing nicely and rejecting those emails for some reason. I do have a way around this, of course…).

Let’s switch over to the recipient, Lynne Robbins. I will log in to the Office web app as her, and I can already see that the shared file is available to her.

Lynne Robbins now has advertised and efficient access to the Excel report! (Image credit: Petri/Michael Reinders) I simply click on the ‘Sales Figures – 2020-2021‘ file under the Recommended category and the file opens in Excel Online.

Lynne viewing the Excel file. Note the purple highlighted box with ‘my’ initials (Image credit: Petri/Michael Reinders) Collaborating in real-time on an Office fileNow that Lynne has the file open, she and I now have real-time, collaborative access to the file. You’ll note that cell J10 is highlighted in purple, and it shows my initials. That is the cell I currently have selected. At a glance, every user can see, live, where everybody else is working. Pretty slick!

Also, you can see in the upper-right corner next to the ‘Share‘ button each user that has the file open. They can be using Excel Online, the Excel desktop app, the Office mobile app, and even Teams! Everyone shares the same, essential information and can make changes efficiently.

As Lynne, I will now update a few figures. Let’s jump back to ‘my’ view of the file, and you’ll see the numbers in cells F13 and H13 updated with new figures. You can also see that Lynne was last in cell H15.

Seeing the cells that Lynne made updates to (Image credit: Petri/Michael Reinders) Using comments for task assignmentOne more very cool feature is Comments. As Lynne, I’ll click the ‘Comments’ button in the upper-right corner and click New.

(Lynne) Adding a new comment to the spreadsheet (Image credit: Petri/Michael Reinders) Lynne is asking me to double-check with another colleague to verify some sales numbers. She assigned this as a task, so we have accountability in accomplishing the task.

Back in my view of the spreadsheet, I can click on Comments and see the assigned task.

Viewing the task assigned to me (Image credit: Petri/Michael Reinders) Brief summary of how Microsoft 365 Groups can enhance your team collaboration Another very helpful and full-featured tool in Microsoft 365 is Groups. Microsoft 365 Groups (formerly Office 365 Groups, formerly ‘Distribution Lists’) help to add multiple efficient weapons to your arsenal in collaborating amongst your team, your department, and even your organization.

Microsoft 365 Groups were designed to allow you to easily set up a collection of resources for your team members to share. Resources such as a shared Outlook inbox, shared calendar, or a document library for collaborating on Office files, and more.

The administration of Microsoft 365 Groups is fairly easy – adding members to the Group automatically gives them the permissions they need to the tools your group provides. Additionally, Microsoft 365 Groups are the new and improved experience for what we used to use distribution lists or shared mailboxes for.

Let me show you how to create a group via Outlook on the Web. At the bottom of your email folder list, you’ll find ‘Groups.’ Go ahead and click ‘New group.’

Locating the Groups section in Outlook on the web (Image credit: Petri/Michael Reinders) You’ll have different settings to configure:

  • You need to choose the Name of the Microsoft 365 group (the email address will be auto-filled in for us).
  • You can add an optional Description if you want.
  • You can choose if you want to keep the Microsoft 365 group Private (recommended).
  • You can also choose the suitable Language, and if you want group members to receive all emails and conversations in their own private Inbox, in addition to the group.

When you’re done, click Create.

Our new Microsoft 365 Group settings (Image credit: Petri/Michael Reinders) Next, I’ll add Lynne Robbins as a Member of the new Microsoft 365 Group.

Adding Lynne Robbins as a member (Image credit: Petri/Michael Reinders) It’s done. Our new private, Microsoft 365 group is ready for use!

Behold our new Microsoft 365 group! (Image credit: Petri/Michael Reinders) Using Microsoft Loop components in a Microsoft Teams Chat Microsoft Loop components are a new feature surrounding efficient collaboration of information that started rolling out to Microsoft Teams at the end of 2021. Microsoft Loop components are “a new app that combines a powerful and flexible canvas with portable components that move freely and stay coordinated across apps, enabling teams to think, plan, and create together.”

At the beginning of November 2021, Microsoft announced Loop components. This is one of three elements of Microsoft Loop – the other two being Loop pages and Loop workspaces… those are still to come. Microsoft Loop components are supported in Teams chats for desktop and mobile, the Outlook for Windows app, as well the Word, Outlook, and Whiteboard web apps.

At the time of this writing, Loop Components are still a fairly new feature, and they may only be available for ‘Targeted users’ in your Office 365 tenant. To check, open the Microsoft 365 admin center. Click on Settings -> Org settings -> Organization profile -> Release preferences.

Your tenant’s Release preferences – For newer features (Image credit: Petri/Michael Reinders) You can choose any of these three options. Normally you choose a small subset of users to be in the ‘Targeted release’ category to ‘test’ new features before most of your users receive them.

Back to regular programming: Microsoft Loop components offer a new way to think, plan, and create together by adding a dynamic component – an Office table, list, paragraph, even a task list – right to your Teams chat.

To get started, open the Chat module in Microsoft Teams and select the user you wish to collaborate with. Next, click the icon for Loop components.

Creating a new Loop component in a Teams desktop chat (Image credit: Petri/Michael Reinders) Here, I chose Checklist, entered some initial tasks for Lynne and me, and then changed the sharing scope from ‘Anyone in the organization can edit’ to ‘Share within this Chat only’.

A dynamic, inline, editable Loop component that allows Lynne and I to collaborate in real-time on Teams (Image credit: Petri/Michael Reinders) Now, let me switch over to Lynne Robbins and make some changes to the checklist.

Updates to the Loop checklist component after Lynne made some updates (Image credit: Petri/Michael Reinders) As you can see, Lynne marked the first item complete and added a few tasks with a callout to ‘me’ that will grab my attention next time I’m in Teams. Efficiency and productivity at their best!

In my Activity Feed, you’ll notice Lynne mentioned me in a live component (Image credit: Petri/Michael Reinders) When I logged back into Teams, I saw a notification on my Activity module and saw in my Feed that Lynne (Robbins) mentioned me in a live Loop component. Very cool!

ConclusionI hope you learned something new about file sharing and collaboration features in Microsoft 365. If you’re inspired to give these Office tips and tricks a try, feel free to leave me a comment below. Thank you!

View Details

MC485096 – Updated January 19, 2023: Microsoft has updated the timeline and content below. Thank you for your patience.

The resource-specific consent (RSC) permissions model for receiving all message, originally developed for Microsoft Teams Graph APIs, is being extended to bot scenarios. This feature was available for the channel scope and now is being extended to chat scope. With RSC, conversation owners can consent for a bot to receive all user messages in standard channels and chats without being @mentioned.

This change is related to Microsoft 365 Roadmap ID: 100883

When this will happen:

Will begin rolling out early March (previously early January) and expect to complete by late March (previously late January).

How this effects your organization:

When developing Teams apps, this feature will enable a bot defined in the app manifest to receive all conversations messages without being @mentioned in relevant contexts where the permissions apply.

What you can do to prepare:

For more details, review: Receive all conversation messages with RSC

This is for your information only and no action is needed.

Additional information

View Details

Microsoft has announced that it’s rebranding the Office Insider program as the Microsoft 365 Insider program. The company says that this name change aligns with the rebranding of the Office app to Microsoft 365 on Windows, iOS, Android as well as the office.com web portal.

Microsoft launched its Office Insider program about seven years ago. It’s designed to allow users to get early access to improvements and changes for Office applications, including Microsoft Word, PowerPoint, Excel, and Outlook. The program provides the opportunity to try out new features and submit feedback about bugs and potential issues.

According to Microsoft, the new Microsoft 365 Insider branding doesn’t bring any changes for the participants enrolled in the program. Microsoft notes that Office Insiders will continue to receive updates in the Current Channel (Preview) and Beta Channel. However, the company has updated the name of the program on the official portal and changed the Twitter handle to @MSFT365Insider.

Additionally, Microsoft indicated that it has moved the Release Notes of the program to the Microsoft Learn website. “You may have noticed that we’ve been publishing blog posts about offerings beyond the traditional Office apps. We will continue to expand our blog coverage of features, apps, and services under the Microsoft 365 umbrella moving forward,” the Office Insider team explained.

When will the Microsoft 365 Insider branding changes happen?The Microsoft 365 Insider branding changes started rolling out yesterday, and the updates will become generally available in March 2023. Microsoft emphasizes that it’s not completely dropping the Office brand just yet. The company will continue to use the Office branding for its Office long-term servicing channel (LTSC) products and the perpetual licenses of the productivity suite.

Last week, Microsoft announced that it’s launching an affordable Microsoft 365 Basic plan later this month. The new offering is priced at $1.99 per month, and includes 100 GB of OneDrive storage, access to the Office web apps, customer support, and more.

View Details

MC489125 – Microsoft Power Automate emails are moving to a new internal email provider. This change will result in emails from an additional Microsoft email account and IP addresses. This information was previously communicated under MC489125.

Description:
As of Thursday, January 19, 2023, Microsoft Power Automate email notifications, such as approvals, flow alerts, and sharing notifications, will be sent from the following email addresses:

  • maccount@microsoft.com
  • flow-noreply@microsoft.com

These emails will be sent from the IP addresses outlined here: Power Automate approval email delivery information

Action Needed:
If you do not utilize custom allowlists/blocklists for emails you receive, no action is required at this time.

However, if you do utilize custom allowlists/blocklists for your emails, please add the above email addresses and IP addresses to your tenants’ allowlists. Please notify your system administrators to update these custom allowlists/blocklists on any program you use to receive email. When doing so, it is recommended to allow the SPF record where possible, instead of the specific IP addresses, to ensure any newly added IP addresses are accounted for automatically.

Please contact Microsoft Support and reference ticket ICM347570815 if you require further assistance.

View Details

Microsoft has finally decided to stop selling Windows 10 licenses to consumers and enterprise customers by the end of this month. The company has quietly announced on the Windows 10 product pages that it will block digital downloads of the Home and Pro editions of the OS on January 31, 2023.

“January 31, 2023 will be the last day this Windows 10 download is offered for sale. Windows 10 will remain supported with security updates that help protect your PC from viruses, spyware, and other malware until October 14, 2025,” the company explained on the Windows 10 Home and Pro product pages.

Customers can still buy Windows 10 Home and Pro licenses from third-party retailersIt is important to note that this move is a part of Microsoft’s efforts to push more Windows 10 users to upgrade to its new Windows 11 operating system. Going forwards, customers who want to purchase Windows 10 licenses will need to contact third-party retailers until their digital stock remains available. For instance, online retailers like Amazon and websites like Kinguin will continue to sell OEM copies of Windows 10 Home and Windows 10 Pro.

Microsoft released Windows 10 all the way back in 2015. The company allowed Windows 7 and Windows 8 users with genuine license keys to upgrade to Windows 10 at no additional cost. However, Microsoft ended support for Windows 7 ESU and Windows 8.1 on January 10, 2023. This means that these operating systems will no longer receive security updates or emergency patches to protect their computers.

If you’re still running Windows 7 or Windows 8.1, Microsoft recommends upgrading to Windows 11. Meanwhile, business customers with legacy hardware that doesn’t meet the minimum hardware requirements for Windows 11 should either buy a new PC or purchase a Windows 10 license sooner rather than later.

View Details

MC496248 – Microsoft is announcing that Wiki’s will be retired from Teams. The company is offering note taking capabilities through Teams Channels powered by OneNote.

When this will happen:

The following change will be rolled out starting mid-February

How this affects your organization:

With this release, users have an option to export their wiki content to OneNote notebooks in Teams standard channel. After exporting users can go to the Notes tab to collaborate using OneNote in channels.

Note: With this change users can continue to access and edit existing wikis but can’t create new wikis in Teams channels.

View image in new tab

OneNote provides an enhanced note taking experience.

  • Easy collaboration across the team
  • View all channel notes in a team in one place organized within a single notebook
  • Rich editing with typing, ink annotations, highlighting, file attachments, etc.
  • Easy recall & search for channel notes within OneNote on any platform

Upcoming plans

Soon Notes tabs powered by OneNote will be added by default when users create new channels. For now, users can create OneNote tabs manually using the add tab experience (via +).

Microsoft will share out the details of Wiki retirement in advance to help our customers prepare for this change.

What you can do to prepare:

Microsoft urges users to export their channel wikis to OneNote once it is available.

If your organization has not enabled OneNote you can review this documentation:

  • Deployment guide for OneNote

View Details

MC496849 – Microsoft will retire Stream (Classic) on February 15, 2024. Certain parts of the service will retire sooner unless you take action. For example, end users will be blocked from uploading new videos on May 15, 2023 and will not be able to access Stream (Classic) at all after October 15, 2023, unless you delay these changes by using the new migration settings in Stream (Classic) admin center. These new migration settings will become available to you in February. See the timeline in the link below for more details.

Stream (Classic)’s successor service, Stream (on SharePoint), entered general availability in October 2022. Microsoft recommends that you 1) begin using Stream (on SharePoint), 2) direct your users to upload videos SharePoint, Teams, OneDrive, and Yammer, and 3) put a plan in place for migration.

Microsoft has not yet announced a retirement date for Stream live events. In the coming months, the company will announce the retirement date of Stream live events and give you a six-month period to begin using the successor service, Teams live events with external encoder support, currently in public preview.

When this will happen:

The timeline for Stream (Classic) retirement can be found here: https://aka.ms/StreamClassicRetireTimeline

How this affects your organization:

Stream (on SharePoint) brings your users many of the capabilities of Stream (Classic) while allowing them to record and play videos directly in many everyday work and school apps such as Teams, Office.com, Yammer, Viva, PowerPoint, and SharePoint. In addition, Stream (on SharePoint) also enables your and your users to:

  • Easily manage video files with the same security, admin controls, multi-geo support, compliance (eDiscovery, legal hold, retention, and data loss prevention policies), permissions, and sharing controls as the rest of your files in SharePoint and OneDrive.
  • Record videos with advanced tools directly in the camera like background blur or replace, inking, text, audio only, and teleprompter.
  • Search for videos anywhere in Microsoft 365. You can now find videos and Teams meeting recordings across Microsoft 365 by searching keywords.
  • Find what you need quickly on the Stream start page in Office. The new start page shows recent, shared, and favorite videos, with playlists coming soon. (Note: The Stream start page doesn’t show you videos in Stream (Classic).)
  • View Teams Meeting Recordings with transcripts, chapters, timeline markers, speaker attribution, and comments.
  • Create custom page, site, and portal experiences to feature videos as part of your intranet and Viva Connections.
  • Share videos the same way you would any other file in Microsoft 365 with support for Guests, People in your Organization links, or unauthenticated external sharing with “anyone” links.
  • Get analytics per video, for all the videos in a site, or see who has watched your video.
  • Add videos to the Viva Connections Feed.
  • Use APIs based on the Microsoft Graph Files API for basic video file operations.

These benefits add up to ease of video management for admins and more productivity for your teams.

What you need to do to prepare:

Migrating your content from Stream (Classic):

All your existing Stream (Classic) videos can be transferred to Stream (on SharePoint) to take advantage of Stream’s rich integration within Microsoft 365. To support your move to Stream (on SharePoint) Microsoft has created migration tools that allows you to transfer your videos to SharePoint while also bringing over metadata, links and permissions associated with your videos.

To begin using the migration tool please see our Migration Overview – Stream (Classic) to Stream (on SharePoint)

The migration process involves both moving your content and directing your users to Stream (on SharePoint) which has a different look and feel than Stream (Classic). Microsoft recommends that you begin planning your migration soon.

Note: In 2022, some admins requested to opt out of a change on the upload page for Stream (Classic), which added a button for uploading to Stream (on SharePoint). Beginning on Jan. 18, 2023 all end users in all customer tenants will see the option to upload to Stream (on SharePoint).

Learn more

Below are links to more information about migration and Stream (on SharePoint):

  • Stream retirement and timeline overview and migration tool details.
  • Learn about the migration tool
  • Stream (Classic) video report
  • Settings (coming soon) to delay block-upload and disablement
  • IT admin overview of Stream (on SharePoint)
  • Stream (on SharePoint) adoption and end user guides.
  • Stream (Classic) to Stream (on SharePoint) comparison

Additional information

View Details

MC496631 – Shared device mode is a feature of Azure Active Directory that allows you to use applications that support frontline workers and enable shared device mode on the devices deployed to them

Your frontline workers can preview Outlook on their shared Android devices until full rollout begins. Enabling frontline worker workflows includes challenges not usually presented by typical information workers. Such challenges can include high turnover rate and less familiarity with an organization’s core productivity tools. To empower their frontline workers, organizations are adopting different strategies. Some are adopting a bring-your-own-device (BYOD) strategy in which their employees use business apps on their personal phone, while others provide their employees with shared devices like iPads or Android tablets.

This message is associated with Microsoft 365 Roadmap ID 107506

When this will happen:

Public Preview will be rolling out in mid-January 2023.

General Availability will be rolling out in mid-June 2023 and is expected to be complete by mid-July 2023.

Because mobile devices running iOS or Android were designed for single users, most applications optimize their experience for use by a single user. Part of this optimized experience means enabling single sign-on across applications and keeping users signed in on their device. When a user removes their account from an application, the app typically doesn’t consider it a security-related event. Many apps even keep a user’s credentials around for quick sign-in.

To allow an organization’s employees to use its apps across a pool of devices shared by those employees, developers need to enable the opposite experience. Azure Active Directory will enable the following scenarios with the shared device mode features:

  • Employees will have the ability to pick a device from the pool and “make it theirs” for the duration of their shift.
  • At the end of their shift, employees can sign out globally on the device, with all of their personal and company information removed so they can return it to the device pool.
  • If an employee forgets to sign out, the device will automatically be signed out at the end of their shift and/or after a period of inactivity.

What you need to do to prepare:

You can use the Microsoft Authentication Library (MSAL) and Microsoft Authenticator app to enable a device state called shared device mode. When a device is in shared device mode, Microsoft provides your application with information to allow it to modify its behavior based on the state of the user on the device, protecting user data. For more information, please visit this page.

Additional information

View Details

Microsoft has released some much-anticipated updates for Microsoft Planner this week. The company announced that its popular task management tool is getting support for a new recurring tasks feature and Grid view.

The recurring tasks feature should be a welcome addition for people who need to create dedicated tasks for daily scrum meetings, weekly progress reviews, monthly reports, quarterly planning, and yearly review and planning.

“You can reduce extra work by easily setting up automatic repeating tasks for daily, weekly, or monthly recurrence – and many other interval options – with custom repeat settings,” the Microsoft Planner team explained.

Recurring tasks in PlannerHow to create recurring tasks in Microsoft PlannerTo specify a recurring task, Microsoft Planner users will need to follow the steps listed below:

  1. In Board view, click the task card in order to open the Details panel.
  2. Use the Start date and Due date fields to set task timing parameters.
  3. Open the Repeat menu by clicking the adjacent Repeat field. Now, select a recurrence interval such as Daily, Weekdays (M-F), Weekly, Monthly, or Yearly.
  4. Select Custom to open the Custom repeat pane that provides customization options to create recurring tasks that occur on a specific date, week, month, or year.

Custom repeatRecurrence rulesMicrosoft detailed a couple of recurrence rules for creating Planner tasks. Users can only see one occurrence for a recurring task, and an upcoming task will be visible in the Schedule tab after the completion of the previous one. Moreover, Microsoft Planner will stop recurring a specific task when its due date is removed by the user. Users can also choose to remove the selected instance or all instances while deleting recurring tasks.

Microsoft Planner gets a new Grid viewMicrosoft has also introduced a new Grid view that streamlines the process of creating new tasks and managing existing ones. The company emphasizes that the Grid view provides a central hub that lets users view their assigned tasks across all plans. Users can switch to the Grid view by selecting the Assigned to Me tab or clicking Grid at the top of any plan.

View Details

Advanced password attacks, like brute force and those launched by malicious insiders, are devastating the security of today’s enterprises and cloud services. ADSelfService Plus from ManageEngine can protect web properties from such attacks with multi-factor authentication (MFA).

Multi-factor authentication is the best way to protect Active Directory and cloud-based user accountsAs the impacts of cybersecurity attacks have increased, and the vectors malicious actors utilities continue to grow, it is important to keep one step ahead in network security and enterprise environments. This includes your Active Directory (AD) and cloud-based identity solutions like Microsoft 365/Azure Active Directory (AAD).

This post is sponsored by ManageEngine

Multi-factor authentication is a relatively intuitive acronym. Think of a factor as an identifier you use to prove who you are. The most common factor is a password. When you sign in with a username, you need to prove to the authentication engine that you are authorized to use that username. And only you. And that the associated password matches that held for the account in the database. Going back to how things were from the start, the password was essential and it was the only factor you needed to access ‘secure’ systems.

Today, passwords can be impersonated, guessed, and cracked. So, we progressed logically by inventing and eventually requiring a second (or third) factor, thus multi-factor authentication was born. The additional factors can be push notifications to the Microsoft Authenticator app, a physical security key (YubiKey, for example), a fingerprint, or an SMS text response.

Thankfully, a solution exists that checks all the boxes required, plus a few nice perks – ADSelfService Plus from ManageEngine.

Why can multi-factor authentication be difficult to deploy for on-premises Active Directory?When everyone essentially worked in the office, most of your users and computers were on the corporate Local Area Network (LAN). Everyone was readily available and on your network if you needed to deploy a new security solution with Active Directory. In today’s hybrid-enabled workforce, many of your employees are likely working from home. Some employees may even be in remote areas, geographically spread out, making it nearly impossible to get them on the LAN.

How do you get all your computers on this new solution?In addition, Microsoft does not offer any native solutions for using MFA with Active Directory. There are no specific APIs available for developers. So, third-party software solutions were created. Or, you have the option of implementing Active Directory Federated Services (AD FS), which is time-consuming, difficult to learn, and adds a good deal of ‘older’ technology into your modern architecture.

Microsoft is pushing customers from on-premises Active Directory (AD) to Azure AD and its native MFA technology. But there must be a better solution…

The solution: What is ADSelfService Plus and how it makes multi-factor authentication easy to deploy and manage?ADSelfService Plus is an identity security solution that can help secure your networks from many cyberattacks, save IT costs, and start your Zero Trust Security plan. With this full-featured solution, you can secure multiple IT resources including identities, computers, and Virtual Private Network (VPN), reduce the burden on your helpdesk, and empower users with many self-service capabilities.

Most importantly, you gain 360-degree visibility and control over your resources spread across on-premises, cloud, and hybrid scenarios.

Because ADSelfService Plus includes such a wide variety of authentication factors (19), it is much easier to rollout a security solution like this to your entire user base. Due to the accommodating design of the solution’s framework, you’re able to protect all of the ingress points in your environment, regardless of ‘where’ your users are located.

What is adaptive MFA (risk-based MFA)?Adaptive MFA, otherwise known as risk-based MFA, provides users with authentication factors that adjust to the method they use to log in. A calculation of security risk is made with each attempt based on the following factors:

  • The physical location of the user requesting access.
  • The type of device (desktop/laptop PC, mobile device, tablet, RDP session, etc.).
  • The number of consecutive login failures.
  • The day of the week and the time of the day.
  • The IP address.

The authentication factors available to the user are adaptable based on these risk assessments. As an example, if a user, known to be on vacation, attempts a log in to the domain at their work desktop at 3 am, additional authentication factors will be required with this attempt, to make extra sure the user is who they say they are. If all things checkout, access is granted. If user activity is suspcious, access to network resources can be denied.

Windows Server Active Directory and Remote DesktopWith ADSelfService Plus’s MFA for Windows feature enabled, users are protected when logging into domain-joined computers (desktops, laptops) and servers, using Remote Desktop Protocol (RDP). This gives you the peace of mind that every login request to any computer on your domain will be MFA-protected.

MacOS and LinuxWhen you enforce MFA on macOS devices using ADSelfService Plus, every user is required to authenticate their identity via two factors before they can log into their device. Here are some benefits to your macOS users and devices:

  • MFA at a granular level – you can configure MFA based on a user’s domain, their Organizational Unit (OU), and even group membership levels.
  • Compliance with regulations – secure your macOS endpoints based on compliance mandates for NIST SP 800-63B, the NYCRR, the FFIEC, the GDPR, and HIPAA.
  • Conditional access – you can strengthen authentication based on the real time security risk by user.

ADSelfService Plus includes a feature to protect Linux devices as well. It builds an additional layer of security for the user login process. As with the other solutions mentioned, Linux users will log into workstations with their AD credentials and then a second factor including:

  • Fingerprint
  • Face ID
  • Duo Security
  • MS Authenticator
  • Google Authenticator
  • YubiKey
  • Email
  • SMS

Virtual Private Network (VPN) loginsBack in the day, VPNs were all the rage, rolled out by corporate IT security teams to protect remote user connections and file access using a secure tunnel into your LAN. Today, just typing in a username and password is sadly not enough. That is where MFAs for VPN come in.

ADSelfService Plus enables you to secure your VPN connection endpoints for the most popular VPN client solutions, including:

  • Fortinet
  • Cisco IPSec
  • Cisco AnyConnect
  • Windows native VPN
  • Sonicwall
  • Pulse
  • Check Point
  • OpenVPN Access Server
  • Palo Alto
  • Juniper

SAML 2.0-enabled cloud applicationsCloud application proliferation has been on the rise for many years now. And yes, that introduces another login session for end users. By enabling single sign-on (SSO) between ADSelfService Plus and a wide range of cloud-based applications (SAML 2.0-enabled cloud applications) like Salesforce, Google Workspace, and Dropbox, you can secure these inroads into your data, too.

How users are protected logging into SAML 2.0-enabled cloud applications with ADSelfService Plus

  • During SP-initiated SSO, users first access the cloud application by entering its URL directly in a browser. The cloud application then redirects the user to the ADSelfService Plus login page for authentication.
  • Users will need to enter their Active Directory domain credentials to prove their identity.
  • Next, users must authenticate themselves through the alternative authentication methods configured.
  • The user is now directly logged into the SSO-enabled cloud app!

Outlook Web Access (OWA) and Exchange Admin Center (EAC)Instead of using the Outlook desktop application to access email, users have the option (unless restricted by IT policy) to use their web browser to access email via Outlook on the Web (OWA). Again, only using their email address and password is not secure. This is where the MFA feature in ADSelfService Plus helps. The product provides MFA for Outlook on the Web and the Exchange Admin Center (EAC). It implements additional authentication steps beyond the login and password.

Using ADSelfService Plus to login to Outlook on the Web & the Exchange Admin Center

  1. The user attempts to log into OWA or the EAC.
  2. The user is asked to complete the primary authentication on the OWA webpage.
  3. If this is successful, the OWA app passes a request to the ADSelfService Plus connector which informs ADSelfService Plus to request additional factors.
  4. If the user completes all requests successfully, they are logged in!

ADSelfService Plus installation requirements for Active Directory and endpointsLet’s get into the weeds a bit here and go through some of the general system requirements for ADSelfService Plus.

Hardware RequirementsHere are the minimum and recommended hardware requirements for ADSelfService Plus:

| Hardware | Minimum requirements | Recommended requirements | | Processor | 2.4 GHz | 3 GHz | | RAM | 8 GB | 16 GB | | Disk Space | 100 GB (SSD preferred) | 200 GB (SSD preferred) |

Table 1 – Hardware Requirement for installing ADSelfService Plus on a Windows computer

Software RequirementsThe following server and client Windows versions are compatible with software installations and endpoint installations.

  • Windows Server
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012 R2
    • Windows Server 2012
  • Windows Client
    • Windows 11
    • Windows 10

The installation process is straightforward. All you need to do is download the executable (EXE) file from this link, and run it on a Windows machine joined to your AD domain. There are some post-install security hardening steps you’ll need to run through – click here for that guide.

As an IT Pro, you can launch the service in your web browser by typing in http://hostname:8888/ in the address bar. The hostname will be the computer name of the device you installed the software on. Once you deploy the ADSelfService Plus login agent, users will be able to reset their password and/or unlock their account right from the login screen on their computers.

How users can reset their password and unlock their account right from the Login screen!

There are older server and client versions supported by ManageEngine, but as Microsoft does not support them, I will not include them here. You can get more information directly from ManageEngine.

What else can ManageEngine ADSelfService Plus do?Besides the various MFA tools and features described, there are more features available in their suite. Let’s go through some of the hottest right here:

  • Self-service password reset
    • This allows users to reset passwords for their computers and enterprise applications themselves, on any domain-joined PC, any web browser, or their mobile device, if you have that option enabled.
  • Passwordless authentication
    • You can improve your user experience by enabling passwordless login for enterprise (cloud) applications. This allows users to use push notifications and number-matching technology without needing to remember (easily remembered) passwords.
  • Directory self-update
    • Allow your users a secure portal to update core AD profile attributes and information.
  • Reporting
    • Keep admins up-to-date on all your account password statuses through detailed reports. Get ahead of the game with proactive communications to your end users.
  • Learn about additional features by accessing this informative link!

Download a free trial of ManageEngine ADSelfService Plus and try out multi-factor authentication for yourselfIf you’d like to take ADSelfService Plus for a spin, you can use this link to download a fully-functional evaluation for unlimited users for 30 days.

You can also register on that same page to get free technical support during your evaluation period. In addition – click on this link to sign up for a personalized web demo from ManageEngine!

After you’ve trialed the software, you can purchase the professional edition and gain a host of new features – read about them here!Thank you for learning more about ADSelfService Plus and how it can safely and efficiently secure your entire environment from intruders and hackers.

View Details

Microsoft has announced that it’s bringing Internet Protocol version 6 (IPv6) support to its Azure Active Directory services. The company plans to roll out IPv6 support to all enterprise customers in a staggered manner on March 31.

With this release, users will be able to access Azure Active Directory (AD) services through IPv6, IPv4, or dual-stack endpoints. “We’re excited to bring IPv6 support to Azure Active Directory (Azure AD), to support customers with increased mobility, and help reduce spending on fast-depleting, expensive IPv4 addresses,” Microsoft explained.

How to prepare for the upcoming IPv6 change in Azure ADMicrosoft says that IPv6 support might be a major change for some customers, and recommends IT administrators to prepare in advance. First, customers who use named locations will need to determine egress IPv6 addresses, and then update Review and update existing named locations to add the identified IPv6 ranges.

Meanwhile, organizations that use Conditional Access (CA) policies should first identify the usage of named locations as a condition. Then, they will need to update existing CA location-based policies to meet compliance requirements.

Microsoft explained that Exchange Online accounts for the majority of the IPv6 traffic that’s proxied to Azure Active Directory. “When available, Exchange will prefer IPv6 connections. So if you have any Conditional Access policies for Exchange, that have been configured for specific IPv4 ranges, you’ll want to make sure you’ve also added your organizations IPv6 ranges,” Microsoft added.

It is important to note that IPv6 addresses could automatically get triggered in certain situations. For example, an employee uses a legacy authentication method to connect to Microsoft Exchange Online. Moreover, customers who use Azure VNets will receive traffic from IPv6 addresses, and they should audit Azure AD Conditional Access policies for IPv6 exclusions.

Microsoft notes that IT Pros can identify IPv6 traffic in the Azure AD Sign-in activity reports. However, it’s important to add an IP address column to the report, and you can find more details on this support page.

View Details

In this article, you will learn how to edit the Windows 11 hosts file. There are several easy ways that you can edit the file, and in this article, I will take you through each method step-by-step.

In the early days of the Internet, there was just one ‘hosts’ file that was used to match computer names to IP addresses. All devices connected to the Internet are represented by an IP address. An IP address might look something like this: 172.217.23.238. As you can see, it would be difficult to remember the IP address of every device connected to the Internet! So, the hosts file contained a phonebook-like directory of IP addresses mapped to computer hostnames.

As the Internet developed and more devices were connected in different geographical locations, it was no longer practical to maintain a single hosts file. The Domain Name System (DNS) was created in 1984 to provide devices connected to the Internet with a way to look up hostnames by querying a set of distributed servers. And that is how the Internet works to this day.

Perhaps the easiest way to view and/or edit the hosts file is to use the new Hosts File Editor in Microsoft PowerToys. But if you want more information about what the Hosts file is and how to edit it manually, skip to the next section.

Quickly view and edit the hosts file using Microsoft PowerToys Hosts File Editor toolPowerToys is a free set of tools for sysadmins and developers that you can download for free from GitHub. Before you can use Hosts File Editor, you’ll need to download PowerToys from the Microsoft Store.

Once PowerToys are installed, follow the instructions below to use Hosts File Editor:

  • Click Search on the taskbar and type powertoys. Click PowerToys in the search results to open the tools.
  • In the PowerToys app, click Hosts File Editor in the list of tools on the left.
  • Under Activation, click Launch Hosts File Editor. By default, the tools is enabled and set to run with admin privileges so that you can edit the Hosts file.

Launch PowerToys Hosts File Editor (Image Credit: Petri/Russell Smith)

  • Click Accept on the warning dialog.
  • You’ll see all the entries listed in your Hosts file. From here you can add, delete, and reorder the entries. To add an entry, click + New entry.

Hosts File Editor (Image Credit: Petri/Russell Smith)

  • In the Add new entry dialog, add the IP address, or IP addresses separated by commas, for the entry and then the host name in the Hosts field. Comments are optional.
  • Click Add to add the entry and make it active straight away.

Add new entry (Image Credit: Petri/Russell Smith)

  • To delete an entry, right click it in the list and select Delete from the context menu.
  • Confirm the action to delete the entry.

Delete an entry (Image Credit: Petri/Russell Smith)

You can right click entries to reorder them too.

Where is the hosts file in Windows 11?But the hosts file remains part of most operating systems. It can be used to override results provided by DNS servers and provide hostname lookup on a local area network (LAN) in the absence of a DNS server. Depending on the operating system, the hosts file is found in a different location. For instance, in Unix, you will find the hosts file in /etc/hosts. And on all modern versions of Windows, including Windows 11, the hosts file is in %SystemRoot%\System32\drivers\etc\hosts. The %SystemRoot% environment variable by default points to C:\WINDOWS.

How the hosts file worksThe hosts file contains lines of text with two columns. In the first column there is an IP address. And in the second column, there is a computer hostname. The two columns can be separated by a space or tab. So, an example hosts file might look like this:

192.168.0.10 bobpc
192.168.0.11 clairepc
192.168.0.129 printserver

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)If you add these entries to the host file on a device, then you can ping each host by name and the computer can resolve it to the corresponding IP address. For example, ping printserver would return a reply like this:

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)You can also use Fully Qualified Domain Names (FQDN) in a hosts file. For example:

172.217.23.238 google.com

The hostnames you add to the hosts file are not case sensitive. They can be in uppercase, lowercase, or a mixture of both. Be aware that the hosts file is sometimes used by hackers to redirect network traffic to malicious sites. That is why only administrators can edit the hosts file in Windows.

View the hosts file in Windows 11By default, the hosts file in Windows 11 doesn’t contain any valid entries. By that, I mean everything is commented out using the hash # symbol. Let start by opening the hosts file in Notepad.

  1. Click Start on the taskbar.
  2. Type notepad and press ENTER.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)3. Press the Windows key (WIN) + E to open File Explorer.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)4. In the box where it says ‘Quick access’, paste the following path and press ENTER: %SystemRoot%\System32\drivers\etc\ 5. In the list of files, you will see hosts.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)6. Arrange File Explorer and Notepad so that are side-by-side. 7. Drag the hosts file from File Explorer into the Notepad window.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)You’ll see that there are two entries at the bottom that are both commented out. The first entry is the IPv4 address for localhost. And the second entry is the IPv6 address for localhost.

127.0.0.1 localhost

::1 localhost

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)But if you try to add an entry to the hosts file, you won’t be able to save it. The hosts file can only be edited by administrators because it is in a protected system directory.

Edit the hosts file in Windows 11There are two ways that you can edit the host file. The first involves making a copy of the original file and then replacing it. The second uses the command line to append a line to the hosts file.

Edit the hosts file using the GUI and NotepadThe easiest way to edit the hosts file is to make a copy of it and then replace the original in the ‘etc’ folder.

  1. Open File Explorer by pressing the Windows key (WIN) + E.
  2. In the box where it says ‘Quick access’, paste the following path and press ENTER: %SystemRoot%\System32\drivers\etc\
  3. In the list of files, right click hosts while at the same time dragging the file to the desktop.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)4. Release the mouse button and then select Copy here from the menu. 5. Click Start on the taskbar. 6. Type notepad and press ENTER. 7. Drag the hosts file from the desktop into the Notepad window. 8. Add your entry at the bottom of the file. In this example, I will add the following entry for my local area network:

192.168.1.10 BOBPC

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)9. Press CTRL + S to save the file. 10. Close Notepad. 11. Now using the mouse, drag the hosts file on the desktop back to the File Explorer window. 12. In the Replace or Skip Files dialog, click Replace the file in the destination.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)13. In the Destination Folder Access Denied dialog, click Continue. 14. You may be required to provide consent or enter an administrator username and password to complete the operation.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)15. Open Notepad again by clicking Start on the taskbar, typing notepad, and pressing ENTER. 16. Drag the hosts file from File Explorer into the Notepad window. 17. Now you can see your new entry in the hosts file.

Edit the hosts file using the command lineThis method uses the command line and is much faster than the method above.

  1. Click the Start menu on the taskbar.
  2. Type command and then making sure Command Prompt is highlighted on the left, click Run as administrator in the pane on the right of the search results.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)3. Give consent or provide an administrator username and password as prompted.

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)4. In the command prompt window, use the echo command as shown here to add an entry to your hosts file. In this example, I’ll add 192.168.1.12 TOMPC to the hosts file.

echo 192.168.1.12 TOMPC >> %SystemRoot%\System32\drivers\etc\hosts

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)5. To check that the hosts file was updated, use the ‘type’ command as shown below:

type %SystemRoot%\System32\drivers\etc\hosts

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)Remove an entry from the hosts file using the command lineThe easiest way to remove an entry is to open Notepad from the command line. The command line must be started with administrator privileges as described above.

notepad %SystemRoot%\System32\drivers\etc\hosts

Easily Edit the Hosts File in Windows 11 (Image Credit: Russell Smith)Notepad will open the hosts file. You can add or remove entries and then save the file to disk.

And that’s it!

Related articles

  • The Ultimate Guide to Installing Windows 11

View Details

Microsoft has announced its plans to launch a new Microsoft 365 Basic tier later this month. The affordable plan costs $1.99 per month (or $19.99 per year), and includes 100GB of OneDrive cloud storage as well as an ad-free experience in the Outlook web app, with additional security features to follow later this year.

Microsoft highlighted that Microsoft 365 Basic subscribers will get access to the web-based Office apps. Users will also be able to contact support for Windows 11 and Microsoft 365 via phone and online chat. However, it doesn’t include the Office desktop apps already available for Microsoft 365 Personal and Family subscribers.

“Initially, Microsoft 365 Basic will include essential peace of mind benefits like 100 gigabytes (GB) of cloud storage, ad-free and secure email with Outlook, and access to support experts for help with Microsoft 365 and Windows 11. And we plan to make Microsoft 365 Basic even better with advanced security features like ransomware recovery and password-protected sharing links in OneDrive later in 2023,” said Liat Ben-Zur, CVP for Modern Life, Search, and Devices.

Microsoft 365 Basic to launch later this monthIt is important to note that Microsoft 365 Basic will replace Microsoft’s 100 GB OneDrive plan on January 30. The company will automatically upgrade all subscribers of its standalone OneDrive plan to Microsoft 365 Basic. However, this change will not impact Microsoft 365 Personal and Microsoft 365 Family plans.

Microsoft mentioned that it will roll out a simplified experience to let users view, upgrade, or manage OneDrive cloud storage. It will be accessible through Windows settings or a Microsoft account on the web on February 1.

Lastly, Microsoft announced that its new Microsoft 365 app is now available for web users. The app replaces the existing office.com portal, and it will begin rolling out to Windows, iOS, and Android users at the end of this month.

View Details

Last month, Microsoft launched a new Teams Premium plan in preview as an add-on for commercial customers. Now, the company has quietly announced that it’s moving some existing features available for Microsoft 365 subscribers to the costly Premium edition (via The Register).

Microsoft first unveiled its Teams Premium add-on at its Ignite 2022 conference in October last year. It comes with new AI-powered features such as custom meeting branding, intelligent meeting recap, and live translations. There are also some new security features that let users add watermarks to protect sensitive content.

Microsoft has recently updated its licensing documentation to indicate that Microsoft Teams Premium will soon provide exclusive access to several popular features. The list includes live translated captions, custom Together Mode scenes, and timeline markers in Teams recordings for participants joining or leaving the meeting. Microsoft Teams Premium will also include virtual appointment options like SMS notifications, scheduled queue view, and organizational analytics.

“When Teams Premium becomes generally available to purchase, there will be a 30-day grace period for admins to purchase Teams Premium. After the 30-day grace period, users will lose access to features previously available in Teams without the Teams Premium add-on, unless the admin purchases and assigns Teams Premium licenses for their users,” Microsoft explained on a support page.

Virtual appointmentsMicrosoft Teams Premium pricing details will be revealed next monthThe Microsoft Teams Premium offering is currently available with a free 30-day trial. However, Microsoft could charge $10 per user per month once it hits general availability in early February.

Overall, Microsoft has positioned Teams Premium as an enterprise-centric offering to cater to the specific needs of businesses. However, this move will likely offend many customers with budget restrictions who would be forced to pay an additional cost to use the existing capabilities in Microsoft Teams.

View Details

Microsoft has released yesterday the January 2023 Security Updates (SUs) for all supported versions of the Exchange Server. The latest updates aim to address critical security vulnerabilities that could allow attackers to gain system privileges in Exchange Server 2013, 2016, and 2019.

Microsoft also highlighted that the January 2023 updates for Exchange Server should improve the security for PowerShell payloads. The company has introduced a new feature that lets IT admins configure certificate-based signing of PowerShell serialization payloads. It’s designed to protect customers against cyber attacks on serialized data.

“Serialization is the process of converting the state of an object into a form (stream of bytes) that can be persisted or transmitted to memory, a database, or a file. PowerShell, for example, uses serialization (and its counterpart deserialization) when passing objects between sessions,” the Exchange team explained.

Update pathsHow to enable certificate signing of PowerShell serialization payloadMicrosoft notes that it’s up to the IT admins to manually enable the certificate-based signing feature in Exchange Server 2013, 2016, and 2019. However, administrators will need to ensure that the January 2023 security updates are installed on all Exchange-based servers.

Additionally, Microsoft warned that those who turn on the feature before updating the servers might encounter deserialization failures or other problems. The Exchange team plans to enable certificate signing of PowerShell serialization payload by default in an upcoming update.

Microsoft has acknowledged a known issue with the latest Exchange Server security updates. Specifically, the bug causes rendering issues with web page previews for URLs shared in the Outlook Web App (OWA). The company has promised to deliver a fix in a future update, though there is no ETA yet.

Microsoft has also released new Patch Tuesday updates for Windows 10 and Windows 11 PCs. The January 2023 Patch Tuesday updates also marked the end of support for Windows 7 Extended Security Updates and Windows 8.1, and you can check out our separate post for more details.

View Details

Microsoft has released yesterday the January Patch Tuesday updates for Windows 11 and Windows 10. Yesterday also marked the end of support for Windows 7, Windows 8.1, and Windows RT 8.1. Microsoft had already ended support for Windows 7 back in January 2020, but the company is now sunsetting its Extended Security Updates program for the OS released back in 2009.

This month’s Patch Tuesday updates include fixes for 98 vulnerabilities in Windows, Office, Microsoft Exchange Server, and more. The company also addressed an issue affecting the Local Session Manager (LSM), and it also fixed a known issue that was preventing apps that use Microsoft Open Database Connectivity (ODBC) SQL Server Driver (sqlsrv32.dll) to connect to databases.

98 vulnerabilities fixed with the January 2023 Patch Tuesday updatesAmong the 98 vulnerabilities that Microsoft fixed this month, 11 are rated “Critical,” and there’s also one “Important” vulnerability that is already being exploited by attackers. “This volume is the largest we’ve seen from Microsoft for a January release in quite some time,” the Zero Day Initiative emphasized yesterday.

Let’s take a closer look at some of the most important vulnerabilities Microsoft fixed this month:

  • CVE-2023-21674: This Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability is already exploited by attackers to gain SYSTEM privileges.
  • CVE-2023-21561: This Microsoft Cryptographic Services Elevation of Privilege Vulnerability could be exploited by attackers to execute code or access resources at a higher integrity level than that of the AppContainer execution environment.
  • CVE-2023-21743: This SharePoint Server Security Feature Bypass Vulnerability could allow an unauthenticated attacker to bypass authentication and make an anonymous connection.
  • CVE-2023-21543: This Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability could allow an unauthenticated attacker to send a specially crafted connection request to a RAS server, which could lead to remote code execution (RCE) on the RAS server machine.
  • CVE-2023-21535: This Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability could also allow an unauthenticated attacker to send a specially crafted connection request to a RAS server, which could lead to remote code execution (RCE) on the RAS server machine.
  • CVE-2023-21763/CVE-2023-21764: These Elevation of Privilege vulnerabilities in Microsoft Exchange Server could allow attackers to gain SYSTEM privileges. Microsoft said that Exchange Online customers are already protected and don’t need to take any action other than updating Exchange servers in their environment.

You can find below the full list of CVEs released by Microsoft for the month of January:

| Product | Impact | Max Severity | Article | Details | | Windows RT 8.1 | Elevation of Privilege | Important | 5022346 | CVE-2023-21773 | | Windows 11 version 21H2 for ARM64-based Systems | Elevation of Privilege | Important | 5022287 | CVE-2023-21768 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21767 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21760 | | Windows 10 Version 21H2 for x64-based Systems | Denial of Service | Important | 5022282 | CVE-2023-21758 | | Windows 10 Version 21H2 for x64-based Systems | Denial of Service | Important | 5022282 | CVE-2023-21757 | | Windows RT 8.1 | Elevation of Privilege | Important | 5022346 | CVE-2023-21754 | | Windows 10 Version 20H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | CVE-2023-21749 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21748 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5022282 | CVE-2023-21776 | | Windows 10 for x64-based Systems | Elevation of Privilege | Important | 5022297 | CVE-2023-21774 | | Windows Server 2012 (Server Core installation) | Elevation of Privilege | Important | 5022348 | CVE-2023-21747 | | Windows 10 Version 1809 for x64-based Systems | Denial of Service | Important | 5022286 | CVE-2023-21525 | | Windows Server 2019 (Server Core installation) | Elevation of Privilege | Important | 5022286 | CVE-2023-21750 | | Windows RT 8.1 | Elevation of Privilege | Important | 5022346 | CVE-2023-21772 | | Windows Server 2016 (Server Core installation) | Information Disclosure | Important | 5022289 | CVE-2023-21766 | | Windows Server 2019 | Elevation of Privilege | Important | 5022286 | CVE-2023-21765 | | Windows 11 version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022287 | CVE-2023-21771 | | Windows 10 Version 1809 for 32-bit Systems | Elevation of Privilege | Important | 5022286 | CVE-2023-21752 | | Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | CVE-2023-21755 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21524 | | Windows 10 Version 20H2 for x64-based Systems | Security Feature Bypass | Important | 5022282 | CVE-2023-21759 | | Windows Server 2019 (Server Core installation) | Information Disclosure | Important | 5022286 | CVE-2023-21753 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21746 | | Windows 10 Version 1607 for 32-bit Systems | Elevation of Privilege | Important | 5022289 | CVE-2023-21739 | | Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | CVE-2023-21733 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Important | 5022352 | CVE-2023-21732 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Critical | 5022352 | CVE-2023-21730 | | Windows Server 2012 R2 (Server Core installation) | Denial of Service | Important | 5022352 | CVE-2023-21728 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21726 | | Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Important | 5022282 | CVE-2023-21724 | | Windows Server 2012 R2 (Server Core installation) | Denial of Service | Important | 5022352 | CVE-2023-21683 | | Windows Server 2012 R2 (Server Core installation) | Information Disclosure | Important | 5022352 | CVE-2023-21682 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Important | 5022352 | CVE-2023-21681 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21680 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21679 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21678 | | Windows Server 2012 R2 (Server Core installation) | Denial of Service | Important | 5022352 | CVE-2023-21677 | | Windows 10 Version 21H2 for x64-based Systems | Remote Code Execution | Important | 5022282 | CVE-2023-21676 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21675 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21674 | | Windows Server 2012 R2 (Server Core installation) | Security Feature Bypass | Important | 5022352 | CVE-2023-21563 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Critical | 5022352 | CVE-2023-21561 | | Windows Server 2012 R2 (Server Core installation) | Security Feature Bypass | Important | 5022352 | CVE-2023-21560 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5022282 | CVE-2023-21559 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21558 | | Windows Server 2012 R2 (Server Core installation) | Denial of Service | Important | 5022352 | CVE-2023-21557 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21556 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21555 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21552 | | Windows 10 Version 21H2 for x64-based Systems | Elevation of Privilege | Critical | 5022282 | CVE-2023-21551 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5022282 | CVE-2023-21550 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21549 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21548 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21543 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21542 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21541 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5022282 | CVE-2023-21540 | | Windows 10 Version 21H2 for x64-based Systems | Remote Code Execution | Important | 5022282 | CVE-2023-21539 | | Windows Server 2016 (Server Core installation) | Denial of Service | Important | 5022289 | CVE-2023-21547 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21546 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21537 | | Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5022282 | CVE-2023-21536 | | Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5022352 | CVE-2023-21535 | | Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5022352 | CVE-2023-21532 | | Windows Server 2012 R2 (Server Core installation) | Denial of Service | Important | 5022352 | CVE-2023-21527 |

Quality and experience updatesOn Windows 11 and Windows 10, Microsoft fixed a Local Session Manager (LSM) issue that could allow users without admin rights to perform actions that only an admin can. Additionally, Microsoft fixed a known issue causing apps that use Microsoft Open Database Connectivity (ODBC) SQL Server Driver (sqlsrv32.dll) to fail to connect to databases.

In the release notes for Windows 11 version 21H2 and Windows 10 versions 22H2, 21H2, and 20H2, Microsoft mentioned an additional fix for a startup issue. In some cases, Windows 10 and Windows 11 users could receive an error (0xc000021a) and see a blue screen during the startup process, but this should no longer be happening.

There are no UI changes with this month’s Patch Tuesday updates. Microsoft sometimes introduces minor new features or UI changes in the optional “C” updates released at the end of every month, but Microsoft skipped these optional preview releases last month due to the holidays.

Windows Update testing and best practicesOrganizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.

If you have any problems with this month’s patches, please let us know in the comments below. Other readers might be able to share their experiences in how to roll back problematic updates or mitigate issues caused by patches that are important to have in place.

View Details

MC495888 – Microsoft is excited to announce a new experience to improve the app pre-install experience in Teams Admin Center.

When this will happen:

Microsoft will be rolling out in mid-January 2023 and expect rollout to be complete by late January 2023.

How this will affect your organization:

For the public preview release, you will receive the feature if:

  • Your tenant settings allow end users access to most Teams add-in apps.
  • Your tenant settings do not contain custom setup policies.

Pre-installed apps can make your users more productive in their daily work. With this new feature, you can now install useful apps for all your end users through a few simple clicks.

For Admins:

  • Pre-install an app from the banner
  • Pre-install an app from the app details page
  • Manage a pre-installed app

View image in new tab

View image in new tab

View image in new tab

View image in new tab

For Users:

After an app is pre-installed by Admins, the app will appear in the flyout of the Teams client end for your users.

View image in new tab

What you need to do to prepare:

Admins do not need to take any action at this time.

View Details

MC495886 – Microsoft Teams Shifts connector for UKG Dimensions is now generally available. This bi-directional, near real-time connector provides a single, seamless interface to simplify scheduling.

When this will happen:

This is now available.

{How this will affect your organization:

Admins will be able to setup, configure and manage Shifts UKG Connector via Microsoft 365 Admin Center or, if preferred, cmdlets.

  • You can select and register a connection to UKG at the tenant level.
  • You can register multiple instances for the same connector, by defining the data syncing and team’s mapping between platforms.
  • You can view and manage on-going errors.
  • Subscribe to Shifts changes, write back to UKG, for 2-way syncing.

For your frontline, this integration means actions taken in UKG Dimensions can be reflected in Microsoft Shifts, or vice-versa.

  • Authentication is Single Sign On.
  • Subscription to notifications on changes made are available.
  • As an example, your frontline managers can manage requests in both UKG and in Shifts; and, your frontline workers can clock in/out, request time off and view and request open shifts in Shifts.

What you need to do to prepare:

  • You need UKG Dimensions service account name and password and service URLs (application program interface URL, application Key, client ID, client Secret and single sign on URL). Contact UKG Dimensions support, if you don’t have this information.
  • You need federated single sign-on authentication enabled in your UKG Dimensions environment.
  • You need to have, at least, one team in Microsoft Teams.
  • You need to create and add a Microsoft 365 system account as a team owner to all teams you want to map.
  • You need to make sure the teams you want to map do not have schedules, before mapping those to UKG Dimensions.

Note: Instead of using a personal account, Microsoft recommends the creation of an account specifically for this purpose, since Shifts Connector uses the account when syncing Shifts changes to/from UKG Dimensions.

Please ensure that every used device has the latest updates on Microsoft Teams to continuously ensure Shifts Connector is working to the best of its capabilities.

Additional information

Blog

View Details

MC495884 – Microsoft is making some changes to the way firmware auto-updates are managed for Android-based Teams devices.

You are receiving this message because our reporting indicates one or more users in your organization are using Teams devices. Administrators using Teams admin center to manage these devices will see some changes for Phones, panels, displays, and Teams Rooms on Android devices.

When this will happen:

These updates will start rolling out in early-January 2023 and expect to be complete by late January 2023.

How this will affect your organization:

The following changes will occur:

  • New names for automatic update phases
    • Select a device (Android-based) from the device list and select Update. Under the section Firmware auto-update, you can select a phase to be assigned to the device.
      • Test – This option is best for lab or test devices. Updates start as soon as the latest firmware is released. Previously called As soon as possible.
      • General– This is the default option and is best for your general-purpose devices. Updates start after 30 days have elapsed from the release of the new firmware. Previously called Defer by 30 days.
      • Final – This option is best for devices used by VIPs and in large settings. Updates start only after 90 days have elapsed from the release of the new firmware. Previously called Defer by 90 days.
    • A new ‘Firmware auto-update‘ column in the device list under the sections Devices > Teams Rooms on Android, Phones, Panels, Phones, and Displays. The column displays the phase that has been assigned to the device. You can click the phase name to open the Update section.
    • Ability to select multiple devices and assign them an update phase.
  • A new ‘Auto-update phase‘ filter

What you need to do to prepare:

When these changes take effect, there is no action required from your end. Any configurations made prior to this change will not be impacted other than the change in phase name. For example, if you had configured firmware auto-update frequency for a device as ‘Defer by 90 days‘, it will now appear to be in ‘Final‘ phase. The behavior will remain the same as before.

To learn more, please visit this page.

Additional information

View Details

MC495880 – As announced in November 2022 (MC455898), we’ve recently retired the Reports page from the Microsoft Purview compliance portal. Beginning in early February, we’re retiring legacy Microsoft Purview Data Loss Prevention reporting cmdlets.

Impact to your organization

The following legacy DLP reporting cmdlets will soon be retired:

  • Get-DlpDetectionsReport
  • Get-DlpDetailReport
  • Get-DlpSiDetectionsReport
  • Get-DlpIncidentDetailReport

Going forward, data currently available via the Get-DlpIncidentDetailReport cmdlet can be downloaded through Activity Explorer.

What you need to do to prepare

No action is needed to enable this change; however, Microsoft recommends that you update any internal documentation or processes that reference the retiring cmdlets.

Get started with Activity Explorer in the Microsoft Purview compliance portal:

  • Microsoft Purview compliance portal for WW and GCC cloud environments
  • Microsoft Purview compliance portal for GCC-High cloud environments
  • Microsoft Purview compliance portal for DoD cloud environments

Learn more: Get started with Activity explorer

Additional information

View Details

MC411669 – Updated January 9, 2022: Microsoft is updating this message as a reminder that Resume Assistant will be retired. Thank you for your patience.

Resume Assistant is being phased out, starting in September 2022. By the end of January 2023, it will be removed and no longer supported.

Microsoft is committed to improving your Microsoft 365 subscription. As a result, Microsoft occasionally removes features and benefits that duplicate equivalent offerings that are available to subscribers.

Timeline of removal from Word:

  • September 2022 – Removed from the Semi-Annual Enterprise Channel (Preview)
  • January 2023 – Removed across Windows (Current Channel, Monthly Enterprise Channel, Semi-Annual Enterprise Channel), macOS, and Word for the web

For creating a resume that gets you noticed by recruiters and hiring managers, Microsoft recommends starting with a professionally designed resume template in Word or using the LinkedIn Resume Builder.

For more details, see Use Resume Assistant and LinkedIn for great resumes

View image in new tab

How this will affect your organization:

Note: You may have already disabled this feature with the group policy Allow LinkedIn Resume Assistant feature – if you have already disabled this feature for your users then you won’t be impacted and can ignore this notice.

From mid-August, users will see a message when they launch Resume Assistant in Word, informing them that the feature will be going away.

If you’re concerned about the in-product message, you can use the Allow LinkedIn Resume Assistant feature policy to disable the feature and the in-product message.

View image in new tab

From September 13th, 2022, Resume Assistant will be removed from Word’s Semi-Annual Enterprise Channel (Preview).

From January 10th, 2023, Resume Assistant will be removed from Windows (Current Channel, Monthly Enterprise Channel, Semi-Annual Enterprise Channel), Mac, and Word for the Web. The functionality of Resume Assistant will no longer be available, and users on old builds that can still launch Resume Assistant in Word will see the following end of support message.

View image in new tab

What you need to do to prepare:

No action is required. You may want to circulate the support article among your help desk which provides more context and alternative solutions in case users contact them. Use Resume Assistant and LinkedIn for great resumes

Help and support

View Details

At Petri, we are committed to delivering quality content and an engaging experience for our readers. To do that, we commission an audience survey every year to help us understand what is important to our audience.

The Petri 2023 Audience Survey is your chance to help shape the future of Petri and let us know what are your pain points, which technologies you are looking to deploy and learn, and how you deploy Microsoft and other solutions in your organization.

Win a $250 Amazon gift card (or equivalent)The answers you provide will help us determine the areas in which we should develop content in 2023. And as a thank you, when you submit a completed survey, you have the option to be entered into a prize draw where you could win a $250 Amazon gift card or equivalent depending on where you live.

So, if you have a few minutes to spare and would like to be entered into the drawing, then we’d appreciate your time in completing this year’s audience survey!

Editorial Director of Petri.com,
Russell Smith.

View Details

Microsoft is finally ending support for Windows 7 Extended Security Updates (ESUs) and Windows 8.1. This means that the company will no longer provide software updates and technical assistance to PCs running legacy versions of Windows operating systems.

Microsoft announced the end of mainstream support of Windows 7 in January 2020. However, the company introduced an extended security update (ESU) program for businesses that were not ready to upgrade to Windows 10. It allowed customers to pay for crucial security updates and technical support for three additional years.

Starting today, Microsoft is ending support for these extended security updates for Windows 7 Professional and Enterprise editions. Users who will continue to run Windows 7 would be vulnerable to security vulnerabilities and other threats.

Microsoft advises Windows 7 and Windows 8.1 users to upgrade to Windows 10 or 11Meanwhile, Microsoft is discontinuing support for Windows 8.1 today. The company isn’t providing an ESU program for these operating systems due to low usage. It is highly recommended that Windows 7 and 8.1 users should upgrade their PCs to Windows 10 or 11.

Keep in mind that most Windows 7 or 8.1 devices don’t support the minimum hardware requirements for Windows 11. This means that affected customers would need to purchase a new Windows 11 machine. “If devices do not meet the technical requirements to run a more current release of Windows, we recommend that you replace the device with one that supports Windows 11,” Microsoft explained in a support document.

It is important to note that Microsoft Edge and WebView2 Runtime 109 and Google Chrome 109 will be the last versions to support Windows 7 and Windows 8.1. Going forward, IT admins will need to upgrade their fleet of PCs to protect end users. Let us know in the comments below if you have already planned upgrades in your organization.

View Details

Microsoft has announced a handful of new features across Microsoft Teams, Viva, and other Microsoft 365 apps. The new solutions are designed to help retailers and frontline workers streamline operations, improve communication, and boost security for shared devices.

First off, Microsoft has released new updates to improve the Walkie-Talkie feature in Microsoft Teams. The prompt to join feature can now automatically select the last channel used by the Walkie-Talkie device. The transmission usage report feature will allow IT admins to get insights about call quality and overall usage next month. These Walkie-Talkie features will be available for devices sold by popular vendors like Zebra Technologies, Samsung, and Honeywell.

Microsoft has partnered with a human capital and workforce management firm UKG to launch a Teams Shifts connector for UKG Dimensions. It’s designed to make it easier for frontline workers to perform various tasks such as clock in and out, view and accept open shifts, and request time off.

The Teams Shifts connector for UKG DimensionsMicrosoft announced some improvements for the Updates app that launched in Microsoft Teams in May 2022. The Updates app is getting support for deep link sharing that will let IT admins create links for particular updates and share them with end users. Next month, the Updates Power Automate connector will help organizations to automate their workflows with triggers and actions.

Viva Engage adds support for StoriesMicrosoft unveiled a couple of enhancements coming to its Viva employee experience platform. The company has released a new Stories feature for Viva Engage in public preview. The Facebook Stories-like feature allows users to post short videos for promoting an ongoing event or celebrating an achievement.

Stories in Microsoft Viva EngageAdditionally, Microsoft introduced support for Viva Connections pre-configuration in public preview. The feature provides a central hub to view important information such as tasks, top news, approvals, and shifts. The Viva Learning mobile app is getting a new home page experience that provides easier access to learning content and training assignments.

New shared device mode for Microsoft 365 appsMicrosoft is making it easier for IT admins to deploy Microsoft 365 apps on shared devices. The latest update brings support for a new shared device mode that lets users securely access Microsoft Edge, Outlook, Yammer, and Power Apps on Android devices. IT admins will be able to configure shared device mode for Microsoft Teams via Microsoft InTune on iOS devices in February 2023. Microsoft also plans to add shared device mode support for some third-party endpoint management tools like SOTI and VMware Workspace One.

Last but not the least, Microsoft is introducing two new features in Outlook next month. Group mailboxes will help frontline workers streamline communication across departments. There is also a new feature that will enable customers to filter recipients by job function, department, and location for sending targeted emails.

View Details

Microsoft has announced the acquisition of Fungible, a start-up selling composable disaggregated infrastructure solutions for data centers. The company plans to use the Fungible technology and team to boost the Microsoft Azure cloud infrastructure.

Fungible launched its data processing unit (DPU) back in 2016 to enhance the efficiency of data-centric computations within server nodes in scaled-out data centers. DPUs are programmable processors used to decouple network and communication tasks from processing tasks. It helps to reduce the workload on CPUs to focus on data processing tasks such as network routing and security.

Microsoft explained that the Fungible team will join its own data center infrastructure engineering teams as a part of the deal. The company already uses DPUs in Azure, but this new acquisition should improve network and storage performance in data center infrastructure.

“Fungible’s technologies help enable high-performance, scalable, disaggregated, scaled-out data center infrastructure with reliability and security,” said Girish Bablani, CVP of Microsoft’s Azure Core division. “Today’s announcement further signals Microsoft’s commitment to long-term differentiated investments in our data center infrastructure, which enhances our broad range of technologies and offerings including offloading, improving latency, increasing data center server density, optimizing energy efficiency and reducing costs.”

Fungible is Microsoft’s second data center-centric acquisition in recent monthsMicrosoft has yet to disclose the terms of the deal, and it remains unclear when Fungible’s DPU technology would be integrated into Microsoft’s data centers. Fungible’s solutions have already been used by popular companies such as VMware and IBM. We hope that Microsoft’s acquisition of Fungible will help Microsoft Azure to better compete with its rivals.

This announcement comes a month after Microsoft purchased the high-speed fiber startup Lumenisity in December 2021. This acquisition should help to decrease latency with hollow-core fiber (HCF) optic cables that reduce the amount of time required to transfer data across cloud data centers.

View Details

Hyperconverged infrastructure (HCI) is a software-defined infrastructure that virtualizes and packages all the components of a conventional data center including network, storage, and computing resources. Hyperconverged infrastructure platforms allow businesses to virtualize servers, storage, and underlying networks and implement a software-driven control of their IT environment. In this article, we’ll look at the top 5 hyperconverged infrastructure platforms and explain how they can help to reduce your overall IT costs.

What are the benefits of using hyperconverged infrastructure (HCI) platforms?Hyperconverged infrastructure platforms allow businesses to reduce their operational, infrastructure setup, and maintenance costs. Here are some of the other key benefits of using HCI.

Easy managementManaging, operating, and monitoring an hyperconverged infrastructure platform is much easier than handling a traditional infrastructure. Since it is software-driven, IT admins can configure the HCI system to auto-assign resources, perform redundant tasks, eliminate management siloes, and perform data backup and restoration.

ScalabilityAdding or removing nodes from an HCI cluster is easy and convenient. You can start small when your business is in its starting phases and scale out as you grow.

Hyperconverged infrastructure platforms allow you to do these configuration changes without heavy upfront infrastructure and maintenance expenses. Moreover, as HCI nodes are pre-configured and pre-optimized, IT admins can easily add or remove them from the clusters without any integration challenges.

PerformanceHyperconverged infrastructure platforms are capable of running multiple different applications and application types simultaneously. The software-defined nature of HCI platforms can help you to easily accommodate changing performance requirements depending on your workload.

Cloud-friendlyThe software-defined infrastructure of hyperconverged infrastructure platforms and their cloud-like experiences are rapidly helping businesses to accomplish their digital transformation. HCI leverages advanced virtualization, which makes it easy to integrate these platforms with other cloud services.

HCI platforms make it easy to integrate other cloud servicesHow do hyperconverged infrastructure platforms work?A hyperconverged infrastructure platform unifies and integrates the core entities of a data center stack including storage, networking, and virtualization. An HCI platform is powered by a distributed software layer, which is an effective way to mitigate the pain points associated with traditional infrastructure.

An HCI cluster is made up of preconfigured and self-contained building blocks called nodes or servers. These nodes can be added or removed from a cluster as per the needs and requirements of your organization.

Each of these nodes contains compute resources such as x86 processors along with storage (SSD and HDD) and dedicated software. Software running on each of these nodes distributes the workload and operating functions across any nodes within a cluster as per the availability and load-balancing configuration.

A hyperconverged infrastructure platform unifies and integrates the core entities of a data center stackOn top of this, almost all modern HCI solutions offer a centralized management console that enables you to easily monitor your HCI resources.

What qualifies for a hyperconverged infrastructure?The categorization of IT infrastructure between traditional, HCI, dHCI (disaggregated hyperconverged infrastructure), and composable infrastructure is complex. However, for your IT infrastructure to qualify as a hyperconverged infrastructure, it must:

  • Be able to integrate with other hardware and software.
  • Virtualize storage, computing (servers), and the networks connecting them.
  • Offer data backup and recovery options to the virtualized data.
  • Be able to scale the underlying virtualized infrastructure when needed.

Choosing the Right HCI ProviderThere are several HCI vendors today and you’ll need to have a good understanding of the IT landscape, tech stack, and the feature set that you need before making a decision. Here are some of the key aspects to consider before zeroing in on a vendor.

Storage ManagementAn ideal hyperconverged infrastructure solution should let you easily integrate and configure a wide range of storage systems. It should also allow you to map these storage systems to meet the dynamic system requirements of your IT environment. Some modern HCI systems are offering support for NVMe-OF (non-volatile memory express over fabrics), a technology that simplifies storage re-architecture using flash memory.

AnalyticsBecause hyperconverged infrastructure is an aggregator of storage, computing, and network resources, it is very crucial for you to be able to manage resource utilization, allocation, and health. Choosing an HCI platform that offers centralized dashboards with pre-made and custom metrics along with reporting abilities can be very beneficiary.

An ideal hyperconverged infrastructure solution should let you easily integrate and configure a wide range of storage systemsEase of Use Most HCI solutions support multiple hypervisors, and that can increase configurational overhead for IT pros. Therefore, it is important for you to understand if your may or may not need this capability.

IntegrationsIt is crucial for your HCI platform to integrate with different types of storage, computing, and network resources along with cloud services. Having container support could also be a very important requirement if your organization ever starts using containers.

The top 5 HCI vendorsLet’s look at some of the most widely used and adopted HCI platforms on the market today. We’ve picked these services based on their feature set, the use cases they address, their ease of use, and their pricing structure.

Microsoft Azure Stack HCIMicrosoft Azure Stack HCI platform is delivered as an Azure service that integrates on-premises operations with Azure’s cloud capabilities. It allows organizations to easily manage their resources remotely, and it provides a secure virtualization platform for Windows and Linux guests.

Azure Stack HCI comes with built-in enterprise-grade storage virtualization and disaster recovery availability through the stretched cluster option. Azure Stack HCI also makes it very easy to connect to any Azure service. It’s easy to integrate with your existing IT environment, and it offers great flexibility in hardware options with your preferred vendors.

Top reasons to choose Azure Stack HCI* It integrates with Microsoft’s Azure Kubernetes Service to run cloud-native apps on-premises. * The versatile form factor of Azure Stack HCI nodes is ideal for branch office and edge computing requirements. * Azure Stack HCI enables you to simplify your infrastructure and resource management with GUI-based Windows tools.

PricingAzure Stack HCI offers a 60-day free trial of the instance after registration. After the free trial, you will be charged a monthly service fee of $10 for every physical core per month. Moreover, users can get a Windows Server data center with software assurance with the Azure Stack HCI instance for no extra cost. More information on the pricing can be found on Microsoft’s Azure website.

HPE Nimble StorageHPE Nimble Storage is a disaggregated hyperconverged infrastructure (dHCI) solution that overcomes the limitations of traditional HCI platforms. HPE is built for companies with business-critical applications running mixed workloads.

HPE Nimble Storage boasts modular components and it’s built on top of a universal hardware platform. It lets organizations scale computing and storage resources, and it also supports integrations with other cloud services.

HPE Nimble Storage is a disaggregated hyperconverged infrastructure (dHCI) solutionTop reasons to choose HPE Nimble Storage* Being a dHCI storage solution, HPE Nimble Storage can incorporate artificial intelligence and let your organization scale storage and compute independently. * You can use HPE InfoSight, an AI-driven predictive intelligence system that helps you optimize resource usage and allocation. * HPE Nimble Storage also integrates with the HPE GreenLake cloud-to-cloud platform.

PricingHPE Nimble Storage doesn’t offer a free trial, but the company has a detailed pricing calculator on its website. You’ll need to purchase hardware and software separately, and you can find more information about HPE Nimble Storage system information and pricing on this page.

Cisco HyperFlexCisco HyperFlex is another versatile and agile HCI platform. It can be deployed at any edge location, and it integrates well with hybrid cloud setups. Cisco HyperFlex can also be operated through Cisco Intersight to perform predictive scaling.

Top reasons to choose Cisco HyperFlex* Cisco HyperFlex provides strong enterprise data protection and backup. * Hyperflex users can also leverage Cisco’s Virtual Desktop Infrastructure (VDI) to give users a seamless and secure experience on any device.

PricingYou’ll be able to view Cisco’s license fees along with the costs involved with the usage of Hyperflex on the Cisco License website. This is a comprehensive solution targeting large corporations and enterprises, and that’s clearly reflected in its pricing.

Nutanix AcropolisNutanix Acropolis is an HCI platform designed for companies operating on a massive scale. All aspects of Acropolis are completely software-controlled, allowing for easy scalability and hosting with no single point of failure. However, the highly scalable and distributed nature of Nutanix still allows companies of any size to benefit from this HCI solution.

Nutanix Acropolis is a platform designed for companies operating on a massive scale. Top reasons to choose Nutanix Acropolis* Nutanix allows you to customize your environment by choosing any hypervisor and cloud services from their supported catalog. * It unifies public, private, and distributed cloud environments, which lets you focus on the delivery of your applications and data * Nutanix Acropolis helps in simplifying your data center operations by combining computing, storage, and virtualization into a simplified interface.

PricingNutanix Acropolis has three different editions – Starter, Pro, and Ultimate.

  • The Starter edition offers the core set of features and Nutanix software functionality, and it’s ideal for limited workloads with small-scale deployments.
  • The Pro edition offers richer data services along with the core features, and it’s ideal for enterprises running multiple applications.
  • The Ultimate edition consists of the full suite of Nutanix software.

You can view the full licensing costs through the Nutanix Portal after you sign up with your work email.

Dell EMC VxRailDell EMC VxRail is a single HCI platform built to handle every VMware workload and use case including VDI, traditional and modern applications, as well as compute-heavy applications running on a hybrid infrastructure. VxRail also supports Dell SmartFabric services to automate the network configuration and help you in simplifying your deployment.

Top reasons to choose Dell EMC VxRail* If your organization is already using VMware for some workloads, VxRail is probably the best option for you as VxRail’s HCI software is jointly engineered with VMware. * VxRail is highly configurable, and it lets you choose between various deployment options including integrated rack offerings with or without networking hardware included. This allows you to choose the right option from the VxRail portfolio to meet your workload, performance, graphics, storage, IO, and cost requirements.

PricingEMC VxRail offers several options ranging from single appliances to integrated racks. Dell provides custom quotes to its customers based on their requirements. You can get a custom quote for the products you need by either chatting with a business advisor or by having a sales team member from Dell call you back. More information on the pricing can be found on this page.

ConclusionHCI platforms can help organizations of all sizes to overcome traditional operational and business challenges and benefit from scalable and rapid deployment options. In this article, we’ve looked at some of the best HCI platforms on the market, and we’ve also detailed everything you need to consider before choosing an HCI provider. It is crucial for you to choose the right HCI solution that really fits your organization’s needs and budget.

View Details

December was relatively quiet as Microsoft shuts down for the last two weeks of the year. But we did get some interesting information about updates coming to Windows 11 in 2023, OneNote for Windows will get support for vertical tabs, Microsoft Edge 110 will drop support for Windows 7 and Windows 8/8.1, and more! So, let’s get started!

Windows 11 getting new ‘Moment’ update in early 2023In some Windows 11 news, and as expected, Microsoft is planning to roll out the next ‘moment’ update for Windows 11 in February/March 2023. According to Zac Bowden of Windows Central, the moment could include:

  • changes to the taskbar that are being tested now in Insider builds, like a tablet-optimized taskbar, redesigned Search button, Windows Studio Effects in Quick Settings, and some changes to the System Tray overflow menu
  • energy recommendations in the Settings app
  • full-screen Widget board support
  • search in Task Manager
  • voice access improvements

Bowden also expects that another ‘moment’ will follow early summer.

Windows 11 23H2 may not contain any major new featuresBut most interesting, Bowden claims that Windows 11 23H2 likely won’t contain any major new features and it may be shipped as a small cumulative update much like ‘moments’ have been.

Microsoft testing tabs in NotepadSpotted by Windows Central, a Senior Product Manager at Microsoft tweeted that ‘Notepad in Windows 11 now has tabs’. The tweet was quickly deleted. Microsoft has made various improvements to Notepad over the last years. And tabs has been a highly-requested feature for some time.

Windows 11 gets updated OneDrive appMicrosoft rolled out a new version of its OneDrive client app to Windows 11 devices. The new app gets an updated interface in the Settings app, where it now uses the Windows 11 design language and lefthand navigation bar. The update is mainly cosmetic but one new feature gives users granular control over which OneDrive notifications they receive. Before, it was all or nothing.

Microsoft Edge 110 will end support for Windows 7 and 8/8.1Microsoft will end support for Edge and the WebView2 Runtime on Windows 7 and Windows 8/8.1 with Edge version 110. Microsoft Edge 109 will be the last supported version on Windows 7 and 8/8.1. And on Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2. But Microsoft added that Internet 11 will be supported on those systems for as long as the OSes remain in support.

Microsoft said in its blog post that the only way to get support for newer versions of Edge will be to upgrade to Windows 10 or later. And at the same time, it encouraged developers to end support for Windows 7 and 8/8.1 to help keep users safe and secure as those OSes go out of support January 10th, 2023.

Microsoft announces WebView2 Runtime to start rolling out to managed/domain-joined devices running Windows 10In more Edge news, and after completing the rollout of WebView2 Runtime for consumers on Windows 10 over the summer, Microsoft is now planning to do the same for managed/domain-joined Windows 10 devices on the April 2018 Update and later. Microsoft says:

As a follow-up step to the Consumer rollout, we are also announcing that after January 16th, 2023, we will start rolling out WebView2 Runtime to managed/domain-joined devices with Windows 10 April 2018 Update or later.

IT Pros that would like to manage the rollout themselves have a couple of options. Group Policy can be used to manage the update behavior after the runtime has been deployed. Or you can opt out of the update altogether using the WebView2 install policy setting. Although Microsoft doesn’t recommend opting out because it can negatively impact applications like Outlook that depend on the runtime for certain features.

Microsoft Edge 108 releasedYes, and that is it. There’s not much more to say about this release other than there are two features for IT pros and the usual slew of security fixes. IT pros get:

  • Graph APIs for managing IE Mode site lists in the cloud
  • Policy to hide the Microsoft 365 app launcher on the new tab page

Patch Tuesday updatesThe cumulative update (CU) for Windows 11 this month added a couple of new features. There are now storage alerts for OneDrive users. And Microsoft Windows Spotlight is now on the same Personalization page as Windows Themes in the Settings app. There is also a new Mobile Device Management (MDM) policy setting that lets IT send messages to managed PCs running Windows 11 22H2.

The CU update for Windows 11 22H1 makes Microsoft’s updated Quick Assist app available and has a new method for authenticating to Azure Active Directory (AAD) that determines first whether the PC attempting to join is on a trusted network.

OneNote desktop app for Windows to get vertical tab supportLet’s clear up any confusion right from the get-go. OneNote for Windows is the desktop app that comes when you install the Microsoft 365 desktop apps. OneNote for Windows 10 is the UWP Store app that Microsoft shipped initially with Windows 10 and then abandoned in favor of the desktop app, which it had previously abandoned. Got it? Good.

Vertical tabs in OneNote (Image Credit: Microsoft)Microsoft announced that the desktop version of OneNote will be getting support for vertical tabs, which had previously been a thing in OneNote for Windows 10. Makes sense right, vertical tabs are supported in Edge and in my opinion are easier to work with if you don’t have a tiny monitor at least. So, bring it on for OneNote users. And apparently, vertical tab support is the number 1 request from OneNote users.

Once vertical tab support is available in OneNote, users will be able to enable or disable by going to View > Tabs Layout. The feature is set to roll out early next year.

Windows Insider buildsHere is a quick summary of the most important changes and new features that appeared in Insider builds in December:

  • updates to voice access bring more flexibility and interaction with UI controls
  • Microsoft has been messing around with search on the taskbar and continues to experiment with different designs
  • Windows Security (firewall) notification dialogs now use the Windows 11 design language

Windows Firewall notification dialogs updated to Windows 11 design language (Image Credit: Microsoft)* The sign in requirement for Widgets was removed * A link was added to the updated Quick Assist app in Settings > System > Troubleshooters * The Snipping Tool now has screen recording

Snipping Tool to get screen recording (Image Credit: Microsoft)And that is it for another month! Happy New Year and see you in 2023!

View Details

Microsoft Teams is getting a new update that brings co-organizer support for managing breakout rooms. The company has recently announced that this feature is rolling out in public preview to the Windows and macOS desktop apps.

Just like meeting organizers, Microsoft Teams now allows co-organizers to create and manage Breakout Rooms. The feature also enables co-organizers to add/remove rooms, open/close rooms, rename rooms, assign attendees, and make announcements. Co-organizers can configure Breakout Rooms settings to select additional managers and perform other tasks.

“Users assigned as the co-organizers in the main meeting can create and manage breakout rooms on behalf of the organizer. They are also automatically assigned the co-organizer role in breakout room meetings and can access/modify meeting options for any breakout rooms. When rooms are opened, co-organizers will be treated like organizers with regards to the ability to join and move freely between Breakout Rooms,” Microsoft explained.

Breakout Rooms in Microsoft TeamsMicrosoft has also detailed some limitations that are worth noting. At the moment, it’s not possible to create Breakout Rooms ahead of the meeting and pre-assign participants. This capability is only available for co-organizers during Microsoft Teams meetings.

Microsoft Teams adds a new paging feature for video gallery in meetingsAdditionally, Microsoft has announced that support for paging on video gallery is now available in Teams meetings. As shown in the screenshot below, desktop users can use navigation controls to view video feeds that couldn’t fit on the first page of the meeting stage. However, the number of videos may vary based on the type of shared content, internet bandwidth, and device configuration.

Paging in Teams meetingsThe paging feature is currently available in public preview for Windows and macOS devices. Microsoft says that it should be a welcome addition for people with smaller displays. The company plans to make it generally available in late January.

View Details

Microsoft is working on a slew of notable improvements for Windows 11 that are expected to arrive with different “Moment” updates in 2023. Indeed, a new report from Windows Central suggests that the company plans to release the first update for Windows 11 PCs in February or March of next year.

Microsoft officially announced the release of Windows 11 version 22H2 (also called the Windows 11 2022 update) in September 2022. It’s the first major feature update to Windows 11 that addresses a lot of early complaints with the initial OS release in October last year. The latest update introduced some most anticipated changes like tabs in File Explorer, a new Photos app, and support for swipe gestures for the notifications and Quick Settings panels.

According to Windows Central’s Zac Bowden, the upcoming “Moment 2” update should bring a couple of enhancements to the Taskbar. These include updates to the System Tray overflow menu, a tablet-optimized taskbar experience, and a full-screen widget panel. Microsoft is also expected to add a new Search experience in Task Manager, Voice Access updates, and other minor improvements.

Moreover, Microsoft is reportedly working on a Moment 3 update that is scheduled for release in May or June 2023. The company has yet to share details about the new features, but Bowden believes that it will include improvements for dual-screen devices and a better Windows Search interface. Microsoft may also ship the new web-based Outlook desktop client, which should replace the existing Mail and Calendar app in the near future.

Microsoft could ship Windows 11 23H2 with minor improvements in Fall 2023Lastly, Microsoft could be planning to release Windows 11 version 23H2 in Fall 2023 (around September or October). However, the report indicates that it won’t be a major feature update like Windows 11 version 22H2. “It will be delivered just like a Moment update, and not like a full new release of Windows like the 22H2 feature update was,” Bowden wrote.

Overall, Microsoft had a quite busy year in 2022, and the company continues to experiment with more Windows 11 features through its Insider Program. Do you think these changes could convince more Windows 10 users to upgrade to Windows 11? Let us know in the comments below.

View Details

This Week in IT, I’m going to be looking back at the best and worst tech news of 2022! Including:

The first major update to Windows 11 which brought File Explorer tabs and changes to the Start menu, iOS 16 with its new lockdown mode and customizable lockscreen, the rise of Mastodon after Elon Musk’s takeover of Twitter scares away staff and users alike, and a look at Apple’s M2 chip and new devices in 2022. Plus, much more!

  • The first major update to Windows 11, 22H2 and Moment 1
  • Major new features in Microsoft Teams and the 2.0 enterprise client, which is missing in action
  • Skype real-time translation with a synthesized version of your voice • Is Teams for consumers a failure?
  • One Outlook (Project Monarch) and why you would use it over Outlook on the Web. And predictions about how Microsoft may develop the client for Windows in the future.
  • Elon Musk’s Twitter buyout and the rise of open-source decentralized alternative Mastodon.
  • The Apple M2 chips, M2 MacBook Air, and the future of Windows on ARM, including this year’s developer device, Project Volterra.
  • iOS 16 lockdown mode and the customizable lockscreen.
  • The state of security in 2022 and what you can do to stay safe in 2023 and beyond.

View Details

MC492903 – In Microsoft Teams, presenters will soon have the new Presenter window at their disposal while screen sharing.

This message is associated with Microsoft 365 Roadmap ID 100392

When this will happen:

Preview: Microsoft will begin rolling out for preview in early January 2023 and expect to complete rollout in mid-January 2023.

Production and GCC: Microsoft will begin rolling out in early February 2023 and expect to complete rollout by late February 2023.

GCC-H: Microsoft will begin rolling out in late February 2023 and expect to complete rollout by mid-March 2023.

DoD: Microsoft will begin rolling out in early March 2023 and expect to complete rollout by mid-March 2023.

How this will affect your organization:

The new presenter window will give more awareness of meeting activity while users are sharing screen or multitasking away from the main meeting window.

In the new presenter window, controls are docked at the top, which makes active speakers’ faces clearly visible. Raise hands and other important meeting notifications are surfaced for easier recognition.

Note: Presenter window updates are for desktop clients only.

View image in new tab

View image in new tab

What you need to do to prepare:

There is no action required from you at this time to enable this feature. You may want to consider updating your training and documentation as appropriate.

View Details

It’s been more than a month since Azure Stack HCI version 22H2 became generally available. With this latest update for Microsoft’s hyper-converged infrastructure cluster solution, there are some significant changes in storage network capacity and network equipment requirements. In this article, I would like to give you a quick overview of the changes IT pros need to take into consideration to implement the latest version of Azure Stack HCI.

Storage network capacity changes with Azure Stack HCI version 22H2With the release of Azure Stack HCI version 21H2 last year, Microsoft recommended a 25 Gbps bandwidth between all storage network interfaces, even in smaller clusters. With Azure Stack HCI version 22H2, this recommendation has been removed. The minimum interface bandwidth for Azure Stack HCI storage interfaces is now at 10 Gbps.

Depending on the cluster size, it often makes sense to have a 25 Gbps bandwidth per interface, especially if you’re using flash storage with clusters above two to three nodes. For medium to larger clusters, a 10 Gbps RDMA (remote direct memory access) connection often becomes a bottleneck for storage replication.

Network switch requirements with Azure Stack HCI version 22H2With the new features coming to Azure Stack HCI version 22H2 such as enhanced Software Defined Networking, Microsoft introduced additional requirements for the switches you use to interconnect Azure Stack HCI nodes. Please be aware that not all of these requirements are necessary for all use cases and scenarios, but if your switch does not support required features, you could encounter some issues and Microsoft may not be able to support you with the troubleshooting.

If you want to ensure that all network switch requirements are met, you should either select a switch that Microsoft tested or use an integrated solution for Azure Stack HCI. The following vendors have worked with Microsoft to confirm that their switches support the latest Azure Stack HCI requirements:

Physical network requirements for Azure Stack HCI version 22H2 (Source: Microsoft Learn)I will focus on the new physical network requirements for Azure Stack HCI version 22H2 from now on.

Standard: IEEE 802.1QazAccording to Microsoft, a minimum of three Class of Service (CoS) priorities are required without downgrading the switch capabilities or port speed. If your device does allow ingress Quality of Service (QoS) rates to be defined, Microsoft recommends not to configure ingress rates or configure them to the exact same value as the egress (ETS) rates.

Custom Type-Length-Values (TLV) requirementsLink Layer Discovery Protocol (LLDP) allows organizations to define and encode their own custom Type-Length Values (TLVs) requirements, which are called Organizationally Specific TLVs. As Microsoft explained, all of them start with an LLDP TLV type value of 127.

The following table shows which Organizationally Specific Custom TLV (TLV Type 127) subtypes are required for Azure Stack HCI version 22H2

Custom TLV requirements for Azure Stack HCI version 22H2 (source: Microsoft Learn)Maximum Transmission Unit (MTU)This is a new requirement starting with Azure Stack HCI version 22H2. As explained by Microsoft, “the maximum transmission unit is the largest size frame or packet that can be transmitted across a data link.” Starting with Azure Stack HCI version 22H2, a range of 1514 – 9174 is now required for SDN encapsulation.

Border Gateway Protocol (BGP)This is another new requirement for Azure Stack HCI version 22H2. Border Gateway Protocol (BGP) is a routing protocol allowing the exchange of routing and reachability information between two or more networks. “Routes are automatically added to the route table of all subnets with BGP propagation enabled. This is required to enable tenant workloads with SDN and dynamic peering,” Microsoft explained.

DHCP Relay AgentThis is the last new requirement that Microsoft implemented with Azure Stack HCI version 22H2. The DHCP relay agent is any TCP/IP host which is used to forward requests and replies between the DHCP server and client when the server is present on a different network. It is required for PXE boot services,” Microsoft explained.

DHCP Relay Agent requirements for Azure Stack HCI version 22H2What is the impact of these changes?With these new requirements, some switches you may have will no longer be officially supported. If you are using them within a test or demo environment, you should be fine. In a production environment, however, you should definitely ensure that your switches support the required features.

When using a switchless design for your storage interfaces, the requirements may change too as your switch does not need to support RDMA. In most cases and with most vendors, your switches will only need an update of their firmware and/or operating system.

ConclusionThe network requirements changes for Azure Stack HCI version 22H2 are quite significant overall, and they may have an important impact on network equipment costs and acquisitions. As Microsoft is still updating the documentation, we should eventually get more details on which requirements are necessary for specific scenarios and deployed architectures.

View Details

Microsoft is once again reminding customers that it will permanently turn off Basic Authentication in Exchange Online in early January. The company is pushing organizations to adopt Modern Authentication (OAuth 2.0) as soon as possible.

Three years ago, Microsoft announced its plans to deprecate Basic Authentication support in favor of secure user authentication techniques. Since then, the company has released security updates to move several Microsoft 365 apps to Modern Authentication, including the Outlook desktop and mobile clients.

Microsoft started disabling Basic Authentication support in random Microsoft 365 tenants worldwide in October of this year. Up until now, millions of companies have already moved away from the insecure authentication method, but it seems like many customers are still not ready for the change despite multiple warnings. Consequently, Microsoft allowed IT admins to re-enable select protocols in Exchange Online until the end of the year.

Now, Microsoft has issued a final warning that Basic Authentication will be permanently turned off for various protocols in the first week of January 2023. The change will apply to seven email connection protocols, such as POP, IMAP, MAPI, RPC, Offline Address Book, Remote PowerShell, Exchange Web Services, and Exchange ActiveSync.

“Beginning in early January, we will send Message Center posts to affected tenants about 7 days before we make the configuration change to permanently disable Basic auth use for protocols in scope. Soon after basic auth is permanently disabled, any clients or apps connecting using Basic auth to one of the affected protocols will receive a bad username/password/HTTP 401 error,” the Exchange team explained.

Getting ready for Basic Authentication deprecation in Exchange OnlineBasic Authentication is a legacy authentication method that involves sending user credentials in plain text to computer systems. It doesn’t support multi-factor authentication (MFA), making it easier for threat actors to steal credentials via sophisticated cyber attacks.

Microsoft has warned that Exchange Online customers will no longer be able to turn on Basic Authentication starting January 2023. The Exchange team has published a guide to help IT administrators prepare for this change, and you can find more details in this blog post.

View Details

MC447338 – Updated December 27, 2022: The New home experiences for Viva Connections desktop will start rolling out to production tenants through Q1 of next calendar year.

A new desktop experience is being released for Viva Connections that’s easier and faster to set up and optimizes content to deliver a modern employee experience. The new Viva Connections desktop design serves as a new home experience option that centers essential job tasks, personalized content, easy access to other Viva experiences, and better aligns with the mobile experience.

It uses existing assets from your organization’s home site and Viva Connection’s Dashboard, Feed, and Resources. If your organization already has Viva Connections set up, you’ll have the option to choose to keep the existing desktop experiences that features the home site or to use the new home experience. Learn more about the new Viva Connections home experience.

Key points:

  • If you’ve already set up Viva Connections, existing content will pre-populate the new home experience.
  • If you haven’t set up Viva Connections yet, the default experience includes starter cards on the Dashboard but otherwise doesn’t impact the current mobile experience.
  • There will be an option to select the default landing experience if your organization already has a home site. This option will become available to all customer by mid-November in the form of a PowerShell command. More information about the PowerShell command will be in the customization guidance.

This message is associated with Microsoft 365 Roadmap ID 99917

When this will happen:

  • The new home experience will become available to Targeted release customers soon. More details about the release schedule will be shared in a MC post in the near future.
  • The new home experience will become generally available in 2023.

How this will affect your organization:

For customers who are currently using Viva Connections, the new home experience will automatically update in Microsoft Teams. Customers with existing home sites can choose to keep the existing desktop experience using a new PowerShell command that will become available to all customers by mid-November. Get more details in the customization guidance.

View image in new tab

What you need to do to prepare:

With the new desktop experience, admins and editors will be able to edit content and manage permissions from Microsoft Teams. To prepare for this change, help admins and editors for Viva Connections learn more about how to customize the new home experience and how permissions work.

End users in your organization will use the same entry point in Teams as the previous desktop experience. When they view the new experience for the first time, visual prompts will walk them through the main functions of the design and how to interact with different elements. Share guidance with end users.

Additional information

Help and support

Blog

View Details

Microsoft has released a new update that enables customers to configure policies for Windows feature updates and expedited quality updates in Microsoft Intune. These capabilities leverage the Windows Update for Business service to give IT admins more control over the deployment of updates to Windows PCs across an organization.

First up, Microsoft has introduced a new feature that allows organizations to configure policies that control which feature update is delivered to Windows devices. Specifically, IT admins can deploy updates immediately, on a specific date, and gradually to all Windows 10 and Windows 11 clients.

Moreover, it’s possible to deliver new OS releases via a phased rollout to specific user groups and choose the time interval between the group updates. The ability to configure Windows Update for Business feature update policies is available for Windows 10 and 11 Pro, Enterprise, and Education editions. However, it doesn’t support Enterprise long-term service channel releases of the operating systems.

How to configure expedited quality updates in Microsoft IntuneMicrosoft has also announced that Windows Update for Business allows IT admins to speed up the rollout of quality updates on Windows 10 and Windows 11. Essentially, quality updates are security patches that are released on the second Tuesday of every month.

“Whether you use them in the context of a zero-day vulnerability or an urgent quality fix for a set of devices, expedited updates temporarily override deferrals and other settings to install updates as quickly as possible. Once completed, they restore to the normal settings automatically, so you don’t have to,” Microsoft explained.

To configure expedited quality updates, IT admins can head over to the Endpoint Manager admin center. Select Home >> Devices >> Quality updates for Windows 10 and later >> Create quality update profile.

The Create quality update profile settings paneAs seen in the screenshot above, IT Pros can configure two specific settings to expedite quality updates. The first setting lets them select the minimum OS version for all devices. Moreover, the second one allows IT admins to choose the number of days (0, 1, or 2) before a restart is enforced on Windows machines.

Last but not least, this release brings the ability to view feature updates and expedited quality updates in the Microsoft Endpoint Manager admin center. It shows overall results, device alerts, granular details for each device, and other information. Microsoft also detailed recommended practices for managing Windows updates in Microsft Intune, and we invite you to check out the blog post for details.

View Details

Notion is a cloud-based productivity and collaboration all in-one workspace tool. In this article, I’ll answer the question ‘what is Notion?’ and provide some examples of how it can be used for productivity, real-time collaboration, and project management in your organization.

Notion allows small teams of people to work together in real-time on documents, tasks, notes, wikis, and databases from different devices. For example, you could create a Notion workspace where your team will work on a project. The workspace can be used to store all the documentation related to the project. And team members can update the documents in real-time together.

In addition to being a productivity tool, Notion can be used for project management. For example, you could create a task list, a calendar for important events, a Kanban board to track the status of projects, and databases for work management.

The Notion app competes with other productivity and collaboration platforms. There are many Notion alternatives, like Microsoft 365, Microsoft Teams, Asana, Monday.com, Trello, ClickUp, note-taking app Evernote, and the list goes on. Notion is primarily an app that works in your web browser but there is also a mobile app available for iOS and Android.

One of the key differences between Notion and Microsoft Teams, is that Notion allows you to freely organize to-do lists, databases, calendars, documents, and other components on a single page. This is in contrast to Microsoft 365, where apps like Planner and Lists are siloed from each other. Although that is gradually changing in Microsoft 365 as Loop components are introduced to Outlook and Teams. But more on that later.

How does Notion work?When you first log in to Notion, it can be hard to know where to start if you don’t understand how the platform is designed to work conceptually. Documents, to-do lists, and other Notion components are organized in workspaces and pages. You can create more than one workspace. In a workspace, you can create one or more pages that contain ‘blocks’.

BlocksEach block contains some kind of data or media component. At the simplest level, a block can be a paragraph of text. Or it could be a media item, like an image or uploaded PDF document. There are many different types of components that can constitute a block in Notion. Here are a few key features:

  • A to-do list
  • A heading (H1, H2 etc.)
  • A table
  • A bulleted list
  • A database in table, board, list, or gallery view
  • An image or video
  • Embedded media content from other platforms like GitHub, Loom, OneDrive, Google Drive, Miro, Jira, Slack, and many other integrations.

Blocks allow you to format the look and layout of a page and add different types of content.

BlocksUnlike Microsoft OneNote, which is completely freeform, blocks in Notion create a more rigid and predictable layout for your notes, documents, and other content.

TemplatesWorkspaces can get complicated quickly. And while they aren’t necessarily that difficult to set up, you can download Notion templates to quickly set up a workspace for your needs. One of the great things about Notion is that there is a large community of users offering templates for a variety of needs. Many of them are available to download for free. Some for a small fee. You can download many templates from the official Notion template gallery.

Notion templatesHow to use Notion for documents, wikis, notes, and tasksAs you get started with Notion, you will likely want to begin by using it for project documentation, notes, and tasks. You can either upload pre-existing documentation to Notion as a block, like a Word or PDF document. But to unleash the full power of Notion, add a new page to Notion to create a document that allows you to work in real-time with team members.

Pages can be used to create long documentation, wikis, or short notes. And just like you might do in Google Docs and Microsoft Word, you can add comments and see the version history. You can also add to-do lists.

To add a block to a page, type a forward slash (/) and then the name of the component you want to add or choose one from the list. So, for example, to add a to-do list, add a new block either by pressing ENTER or the plus icon (+) that appears to the top left of an existing block when you hover over it with the mouse, and then type / and to-do. When To-do list appears in the context menu, press ENTER to select it.

Adding a block (to-do list)This method can be used to add any kind of block to Notion, whether it’s H1 headings, tables, databases, file uploads, images, or any other component.

Reminders and mentionsJust like most competing software, you can @mention a team member to grab their attention to a particular block. And you can add reminders so that you don’t forget about something you need to do in the future.

Notion team membersEach workspace in Notion includes at least one default teamspace for team collaboration. Any pages that are added to a teamspace can be accessed by all workspace team members. You can add more teamspaces to a workspace if you like. And drag and drop pages between workspaces and teamspaces.

Notion lets you add team members to a workspace by clicking Settings & members in the list of options in the top left of Notion. You can add team members by clicking Add members under Workspace > Members.

Adding team members in NotionNotion databasesThe concept of databases in Notion can seem a little daunting at first. The best way to think of a Notion database is like a hybrid spreadsheet/database application. If you are familiar with Microsoft Lists or SharePoint Lists, then you will be able to get started with Notion databases quickly.

Essentially a Notion database is a spreadsheet-like table that can be queried and displayed in different ways. For example, you could create a database that contains information about employees and display it in gallery view, where employee pictures are displayed as part of a card that contains other important employee information.

A database in gallery view (Image Credit: Notion)While the employee information might have initially been entered using a database in list form, the power to change the way the data is displayed and the ability to query it allows you to easily find the information you are looking for. And unlike spreadsheets, Notion databases are designed to be used for real-time collaboration from the get go.

A Notion database in list viewAnother example is a database with information about sessions at a conference. You might change the default view to calendar view so that you can see the sessions by date and time rather than as a list.

Database in calendar view (Image Credit: Notion)Databases can also be used as a project management tool. To-do lists are useful of course as a task management tool. But a more advanced use of Notion is to create a database and then use the Kanban board view. A Kanban board allows you to see that status of a project across a series of steps that are required for completion, much like a product might move around an assembly line in a factory.

A database in Kanban board view (Image Credit: Notion)Can Notion be used offline?The Notion desktop app for Mac and Windows does support offline use, but the experience is limited. Before you can work on a page offline, it must be preloaded while you still have an Internet connection. And while in theory, any changes that you make while offline to a page should be synchronized back to your workspace when you come online, Notion often fails to do so. The company is hoping to address this issue in the future.

Notion mobile app for iOS and AndroidI have personally also found the Notion mobile app for iOS to be rather slow and clunky. Believe it or not, Microsoft’s mobile apps offer a better experience and performance.

Creating automated workflows in NotionThe Notion API lets you pull or push information from other apps and automate tasks in Notion. To create your own automations you’ll need to know how to code. Alternatively, an app you want to integrate with Notion might have a native automation that meets your needs. You could also build Notion automations using Zapier.

Is Notion for free?Notion has a free plan to get you started. But it is limited to the number of blocks you can create and some features, like adding groups or team members are not available on the free plan.

There are three paid plans:

  1. Plus (formerly Team)
  2. Business
  3. Enterprise

The Plus Plan, which costs $8 per user/month, brings an unlimited number of blocks and file uploads, 30-day page history, and up to 100 guest users.

The Business Plan is intended for companies that want to connect several teams and tools to Notion. For $15 per user/month, you get everything in the Plus Plan and other features like SAML single sign-on (SSO), private teamspaces, 90-day page history, and up to 250 guest users.

The Enterprise Plan includes everything in Plus and Business. And you’ll get:

  • user provisioning
  • audit logs
  • advanced security and controls
  • Up to 500 guests
  • Unlimited page history
  • And more.

You’ll need to contact Notion sales to get a quote for the Enterprise Plan.

Notion vs Microsoft TeamsIf you are already invested in Microsoft 365, then Microsoft Teams offers most of the features you find in Notion. The advantage of Microsoft Teams is that it integrates with all the applications and features available in Microsoft 365, has integrated automation in the form of Power Platform, works with the Microsoft Graph API and Power BI, and has more advanced security and compliance controls for large enterprises.

While Teams isn’t as flexible as Notion, apps like Microsoft Lists and Planner are easier to use in my opinion. Teams also includes the ability to hold meetings, webinars, and live events without the need for third-party software like Zoom or GoToWebinar, although Teams doesn’t currently offer integration with HubSpot.

As part of a Microsoft 365 subscription, you’ll also get document storage, email, and depending of the plan you choose, access to the Office desktop apps for Windows and Mac. Overall, Microsoft 365 offers a much wider range of solutions than Notion, including endpoint security and management.

Microsoft LoopIn what is a clear challenge to the flexibility Notion provides, Microsoft announced Loop. Microsoft Loop componentizes certain elements of Microsoft 365 apps, like task lists, tables, bulleted lists, etc and allows you to add them to Teams chats and Outlook emails wherever you like and have team members collaborate on them in real-time.

Microsoft Loop vs. Notion (Image Credit: Microsoft)Microsoft will also be releasing Loop as an app in the future. The sneak previews we’ve seen at the time of writing this article suggest that the app will allow you to work with Loop components in a similar way to how blocks can be arranged on Notion pages.

Is Notion the right solution for your business?The answer is, of course, it depends. If you are starting from scratch with no investment in other productivity and collaboration platforms, then Notion is a popular productivity app that is worth considering. While it is not so easy to set up, once you have it configured for your needs, it is relatively simple to use.

However, my personal opinion is that Notion is better suited to users that have some technical background. Much like Slack, the user interface is a bit geeky and it might not be best suited to users that aren’t tech-savvy.

Cost is often a deciding factor. You should carefully evaluate whether Notion meets your current and future needs, will it be accepted by users, and whether it is cost effective for your business, considering that it might require you to add other tools to fulfil all your collaborative needs. Microsoft 365 is a more complete solution but it can be complex to navigate if you don’t have the right skills and experience in-house.

View Details

Microsoft has announced some changes in its plans to kill off Internet Explorer (IE11) on Windows 10. The company detailed that it will release a Microsoft Edge update to permanently disable the legacy Internet Explorer desktop app on select versions of Windows 10 in February 2023.

Previously, Microsoft announced that it would disable Internet Explorer 11 through a Windows update on Windows 10 devices. The company started to gradually redirect all IE11 users toward its Edge browser on June 15, 2022. However, Microsoft didn’t reveal when this process will be completed.

Microsoft explained that it will redirect all remaining Windows 10 devices through a Microsoft Edge update on February 14, 2023. It should ensure a better user experience and make the transition easier for enterprise customers. However, this change will not impact organizations that have already ditched Internet Explorer.

Microsoft highlights that its new Chromium-based Edge comes with a dedicated IE Mode. The feature enables customers to keep using their legacy IE-based sites and apps that were previously designed to run on Internet Explorer.

“Users will see a dialogue box when they are transitioned to Microsoft Edge. When they try to click any IE11 icons or other entry points, they will be redirected to Microsoft Edge. Users’ browsing data will be automatically brought over to Microsoft Edge from IE11 so they can seamlessly continue browsing,” Microsoft explained.

How to prepare for the permanent disablement of Internet Explorer Microsoft plans to completely remove all Internet Explorer references from Windows 10 machines with the Patch Tuesday updates scheduled for June 13, 2023. This means that users will no longer see the IE icon in the Start menu or on the taskbar.

Microsoft recommends organizations to switch to Microsoft Edge as soon as possible. However, those who fail to complete the transition may experience disruptions in their business workflows. The company encourages IT admins to open a support ticket or contact its App Assure team to deal with any technical or app compatibility issues.

View Details

Microsoft unveiled its plans to launch Microsoft Teams Premium as an add-on at its Ignite 2022 conference. Now, the company has announced that the new offering is available in public preview for commercial customers.

Microsoft Teams Premium is a new version for organizations that need some additional capabilities to make the meetings more personalized, intelligent, and secure. First up, IT admins can now brand the meeting experience with custom templates, themes, meeting backgrounds, and together mode scenes.

Additionally, Microsoft Teams Premium includes AI-powered features such as intelligent meeting recaps, live translations, meeting guides, as well as live translations for captions. The new offering also supports AI-generated tasks and insights to help users quickly catch up on missed meetings.

Virtual appointmentsMicrosoft also mentioned that Teams Premium supports advanced webinar capabilities. These include a custom logo, manual approvals, registration waitlist, registration date & time limit, presenter bio, and a virtual green room. In B2C environments, Teams Premium helps customers manage advanced virtual appointments with SMS notifications, branded lobbies, scheduled and on-demand appointment queues, and analytics.

Lastly, Microsoft’s new Premium offering improves the security of Teams meetings with end-to-end encryption. It also allows users to add watermarks to protect sensitive information shared during meetings. Moreover, it’s possible to use sensitivity labels to prevent participants from copying/pasting the meeting chat and recording meetings.

WatermarksMicrosoft Teams Premium licensingTo get started, head over to the Microsoft 365 admin center and navigate to the Purchase services section. Now, search for Teams Premium under Collaboration and communication. Once enrolled, IT admins will receive 25 free trial licenses for 30 days that can be assigned to end users in their organization.

Microsoft notes that some Teams Premium features (intelligent recap and custom branding for meetings will be rolled out in a staggered manner through January next year. The company expects to make the new offering generally available in February 2023, and it will be priced at $10 per user per month.

View Details

With earlier versions of Microsoft Office reaching end-of-support milestones throughout 2023, IT Pros need to offer their managers recommendations on how to proceed – Upgrade to Office 2021 LTSC or migrate to the subscription model, Microsoft 365 Apps for enterprise? Read this article to find out.

We all know that Microsoft has steadily increased the rate at which they release ‘new’ anything into the business technology world. The speed at which they iterate features (and fixes) in Microsoft Teams is staggering. The monthly blog posts that Jared Spataro, Corporate Vice President of Microsoft 365, publishes highlighting and showcasing new features across the myriad of Microsoft 365 apps and services might put Steven Sinofsky to shame.

However, as Microsoft’s engineers continue to innovate at this pace, they need to track all the endpoints and client machines that connect to these services. To be a global leader in this realm of innovation, you need to ask your customers to stay up-to-date with their software packages, namely Microsoft Office.

Why you should plan to upgrade to Office 2021 LTSC or Microsoft 365 Apps?Regarding Microsoft Office, there are two critical end-of-support measures occurring in 2023 – these will certainly play a part in your company’s discussions about your current Office licensing infrastructure, and when you may need to make some changes – notably upgrading Office versions or migrating ‘to the cloud.’

Office 2013 will reach the end of Extended Support on April 11, 2023If you are running the Office 2013 suite of applications on any of your computers, you will need to upgrade or migrate in 2023. After April 11, 2023, Office 2013 will be completely unsupported. You will not be able to get any technical support from Microsoft, and the applications themselves will start to encounter issues.

As of this writing, connecting Outlook 2013 to your Exchange Online mailbox is an unsupported scenario. If one of your users can’t get their Outlook Calendar module to see a shared calendar that they have access to, you are on your own!

Bottom line: As early as possible, and for sure by mid-April 2023, you will need to upgrade your Office 2013 to a newer version of the perpetual version of Office (2021) or migrate your users to the subscription model – Microsoft 365 Apps for enterprise.

Connecting Office 2016 and Office 2019 to Microsoft 365 will reach end of support in October 2023All right, so this one surprised me a little. Office 2016 and Office 2019 will be unsupported when connecting to Microsoft 365 apps and services as of Patch Tuesday, October 2023. That is coming up faster than you may think.

However, Microsoft explained on a support page that these older versions of Office will still be able to connect to Microsoft 365, though users may start experiencing issues over time:

In practical terms, what this means is that these older Office versions might not be able to use all the latest functionality and features of Microsoft 365 services. In addition, over time, these older versions might encounter other unexpected performance or reliability issues while using Microsoft 365 services. That’s because as we make improvements to Microsoft 365 services, we’re not taking into account or testing with these older Office versions.

Installing Office 2016…The two Office tracksLet me explain a bit about the two Office tracks. Office 2013, 2016, 2019, and 2021 LTSC are the versions of Office referred to as the perpetual versions. Up until a few years ago, you installed these versions of Office using the traditional MSI installer package software. They are licensed per user and allow you to install the suite of Office apps on one computer indefinitely (which of course really means when Microsoft stops supporting them!).

Once you install these versions, you do not receive new features, only security fixes, and code fixes. The only way to get new features is to upgrade the version you’re running – from say Office 2013 to Office 2016. Because these versions of Office don’t receive code updates offering new features, Microsoft is unable to offer these applications access to new features in the cloud.

The Microsoft 365 apps (for enterprise) is the subscription-based track of software. This version perpetually receives new features based on what channel you’re configured for. You can get new features twice a year (Semi-Annual Enterprise Channel), or get them as Microsoft’s engineers release them (Current Channel).

In terms of essentially never having to worry about being supported, this is your choice. Again, as of this writing, when your users use the Microsoft 365 apps model, they will always be supported, especially when using them to connect to Microsoft 365 cloud apps and services. This is the biggest ‘pro’ with this option.

Microsoft 365 AppsShould you upgrade to Office 2021 LTSC or migrate to Microsoft 365 Apps?This is the biggest question you will need to process in 2023 in relation to your Microsoft Office usage and plans for the future. Let me go through the most common scenarios you as IT pros will be in, and I’ll offer my recommendations on how to evaluate your options: I’m sure you’d like to know which scenario works best from the cost-benefit analysis, and which one will be easiest on your cloud engineers and desktop support engineers!

What if your company is using Office 2013?If you’re in this boat, you are under the most pressure to make a choice and move into the future with confidence. You will need to either upgrade to a newer perpetual version of Office or migrate to Microsoft 365 Apps. If you are going to stay on this track, I would recommend (as I know Microsoft would) you upgrade these users to Office 2021 LTSC. This version of Office will go out of support on October 13th, 2026.

I say this because if you upgrade to Office 2016 or Office 2019, you will start running into issues next October when Microsoft drops support of those versions connecting to Microsoft 365. This gives you the most time in between needing to make these types of decisions.

Again, the other option is spending money on subscription-based Microsoft 365 apps. This will solve your issue with support, but it’s more expensive. Plus, I would make a bet that there are reasons you’re still running Office 2013. It just works, right? Well, sure, but not for long.

What if your company is using Office 2016 and/or Office 2019?As you are running a more recent version of perpetual Office, you have several more months before you need to make a decision. Starting next October, these versions will be unsupported connecting to Microsoft’s cloud services. The main recommendation is essentially the same as above (Office 2013) – upgrade to Office 2021 LTSC or migrate to Microsoft 365 Apps. You can read my thoughts above as they are essentially the same.

Microsoft Office Professional 2021One note I can include here is the extended support expiration dates for these two suites. Interestingly, they will both go out of support on October 14, 2025, which coincides with the last day of support for Windows 10… I know!

How to make your decision?With all the facts presented here, what criteria should you use to decide how to proceed in 2023? Here are the main items.

  • Cost
  • Ease of Administration / Longevity of solution

Regarding cost, there will likely be a cost increase in migrating from the perpetual version of Office to the subscription product. This, of course, is what Microsoft is recommending to its customers as it guarantees the company perpetual revenue. However, in their defense, they would tout the fact that this choice provides unending support and the latest new features, which is true. No versions to worry about!

The ease of administration/longevity of the solution is generally easier with the Microsoft 365 apps. Users have the option of installing the software right from office.com. And, in a more structured method, you can use Microsoft Endpoint Manager (SCCM) to handle the rollouts of the software. If you need to take the perpetual route and want to install Office 2021 LTSC, you can use the Office Customization Tool, which can be found at this link.

ConclusionYou do have two relatively divergent choices with regard to Office in your enterprise. Stay on the perpetual, lower-cost traditional ‘a major version every two to three years’ Office LTSC, or choose the Microsoft 365 Apps subscription model. If your company can afford the operating and license expense of Microsoft 365 Apps, go for it. It will make your admins very happy, your users will be able to rely on scheduled new features, and you will not need to worry about support questions – you’re covered!

Thank you for reading. If you have any specific questions about this topic, please leave a comment below!

View Details

MC487016 – Microsoft Feed provides users with a mix of relevant content from across Microsoft 365 that helps users discover and learn about people and interests relevant at work. The feed is personal to users and will show users content based on what’s likely to be most relevant to the current user at any given time.

This message is associated with Microsoft 365 Roadmap ID 106124

When this will happen:

  • Targeted Release: Microsoft will begin rolling out mid-January and expect to complete by mid-February
  • Standard Release: Microsoft will begin rolling out mid-February and expect to complete by early March

How this will affect your organization:

Microsoft Feed will be accessible on the left navigation of Microsoft 365. Microsoft Feed will show users a mix of relevant content from across Microsoft 365 that helps them discover and learn about people and interests relevant at work. Microsoft Feed is personal to users and will show users content based on what’s likely to be most relevant to the current user at any given time.

View image in new tab

Please note that only content that the user has permission to access will be shown.

What you need to do to prepare:

You might want to make your users aware of this option and that the experience is personalized.

View Details

MC487011 – To provide the ability to tenant admins to enable/disable Attribution functionality for OneDrive for Business (ODB) backed whiteboards.

  • This policy controls whether users can use the attribution functionality within Whiteboard application to view who was the first and latest to write on the sticky note.
  • If you enable or don’t configure this policy setting, everyone on the whiteboard can view attributions. When enabled, board owner of the whiteboard can disable attributions for that whiteboard from Settings Panel.
  • If you disable this policy setting, users on the whiteboard cannot view attributions

This message is associated with Microsoft 365 Roadmap ID 66765

When this will happen:

This functionality will start rolling out to Whiteboard web, Teams, Windows app, Mobile, Tablets, Surface Hubs and MTRs experiences for users by end December 2022 and expect to complete by early January 2023.

How this will affect your organization:

This service can be controlled by ‘Allow attributions in Whiteboard’ policy in the Microsoft 365 Apps admin center, which controls whether users have access to the functionality.

Sticky notes before attribution:

View image in new tab

Sticky notes after attribution:

View image in new tab

What you need to do to prepare:

Note: This policy configuration will be independent of the OCE policy in OCPS (valid for other optional connected experiences) in Whiteboard.

No change is necessary, unless you wish to disable the Attribution functionality.

To do this, you can use the Office cloud policy service in the Microsoft 365 Apps admin center.

  • Sign in to https://config.office.com/ with your Microsoft 365 admin credentials
  • Select Customization from the left pane.
  • Select Policy Management
  • Create a new policy configuration or edit an existing one.
  • In Choose the scope, choose the security group for which you want to apply the policy.
  • In Configure Settings, choose ‘Allow attributions in Whiteboard’
  • In configuration setting, choose either – enabled, disabled, or not configured. The implication of each of these options is mentioned below:

-> Enabled: Attribution functionality is available to users

-> Disabled: Attribution functionality isn’t available to users

-> Not configured: Attribution functionality is available to users

  • Save the policy configuration.
  • Reassign priority for any security group if required. (If two or more policy configurations are applicable to the same set of users, the one with the higher priority is applied)
  • In case you create a new policy, configuration or change the configuration for an existing policy, there will be a delay in the change being reflected as mentioned below:

If there were existing policy configurations prior to the change, then it will take 90 mins for the change to be reflected

If there were no policy configurations prior to the change, then it will take 24 hours for the change to be reflected

To learn more, visit the Microsoft Whiteboard Help Hub page.

Additional information

View Details

This Week in IT, I look at the new interactive chat system from OpenAI, ChatGPT, and whether it could be used to replace programmers and writers.

View Details

Earlier this week, Microsoft released the December 2022 Patch Tuesday updates for various supported versions of Windows. Now, the company has warned that the latest Windows Server updates could prevent IT admins from creating new virtual machines (VMs) in some Hyper-V hosts.

“After installing KB5021249 on Hyper-V hosts managed by Software Defined Networking (SDN) configured System Center Virtual Machine Manager (VMM), you might receive an error on workflows involving creating a new Network Adapter (also called a Network Interface Card or NIC) joined to a VM network or a new Virtual Machine (VM) with a Network Adapter joined to a VM network,” Microsoft explained on the Windows Health Dashboard.

Specifically, IT admins could encounter Ethernet connection errors while creating a new virtual machine or a network adapter on an existing virtual machine. Additionally, these errors might appear when the SLB Load Balancer or SDN RAS Gateway services fail. Administrators may also see Ethernet connection warning messages during live migrations of non-highly available VMs.

The issue only affects new network adapters created after installing the latest Patch Tuesday updates (KB5021237 and KB5021249) on Windows Server 2019 and Windows Server 2022. However, it doesn’t cause connection issues for existing VMs with network adapters.

Microsoft provides a workaround to address Hyper-V issues in Windows ServerThankfully, Microsoft says that its engineers are currently working on a fix that should be arriving in the near future. As a workaround, Microsoft suggests users to run the following commands in PowerShell with administrator privileges:

$lang = (Get-WinSystemLocale).Name
C:\Windows\system32\wbem\mofcomp.exe C:\Windows\system32\wbem\$lang\VfpExt.mfl
C:\Windows\system32\wbem\mofcomp.exe C:\Windows\system32\wbem\VfpExt.mof

Microsoft has provided a dedicated script to help organizations with large-scale deployments on the SCVMM Management Server. Moreover, there is also a post-installation script that can be used with patching tools. IT admins can download both scripts from this support page.

View Details

MC448368 – Updated December 16, 2022: Microsoft has updated the timeline below. Thank you for your patience.

Duplicate contacts are hard to remove manually and as a result people information often remains scattered across contacts. Microsoft is offering end users of Outlook Web App (OWA) the ability to discover duplicate contacts and merge information for a profile into one contact. As a tenant admin of an organization, you are receiving this message because your end users may be introduced to duplicate contact merge suggestions in OWA.

This means that our service will proactively detect duplicate contacts for users of your tenant and will present merge suggestions in OWA. All user merged contacts will appear subsequently in Outlook Desktop and Mobile. As part of feature completeness, Microsoft provides an option to control the audience within your organization. You can control the audience for this feature by disabling/enabling the service for a part of your organization or for your entire organization. For details, please refer to the ‘What you need to do to prepare’ section below.

This message is associated with Microsoft 365 Roadmap ID 98124

When this will happen:

The admin and user settings to enable or disable this feature is currently live.The feature is enabled by default and the service has started rolling out in early December 2022. Although 100% rollout is expected by the end of March 2023, it may complete sooner in the first quarter of calendar year 2023.

Once activated, the feature will be enabled/disabled based on the tenant admin and user configurations. No action is taken on the users’ contact lists without explicit user consent.

User settings are documented here – contactMergeSuggestions resource type. End-users can disable/enable the feature by going to myaccount.microsoft.com > Settings & Privacy > Privacy > Services > Merge duplicate contacts.

How this will affect your organization:

The service will detect duplicate contacts for end users starting October 31, 2022. Once the duplicates are detected, end users will see merge suggestions in OWA.

If you decide to disable the feature using a command with input “false” and then at a later point enable it again using the same command with input “true”, the duplicate contact merge suggestions will be re-generated after about 10 days (+/- 4 days) of enabling the feature and users won’t see the feature live until then.

What you need to do to prepare:

If you do NOT want the service to detect duplicates and present merge suggestions to some or all your end-users, please follow instructions in the section below. No action is required if you want the contact de-duplication feature available to your end-users.

Public documentation on how to control the audience for this feature using contactInsights: insightsSettings resource type

Instructions to use MS Graph SDK PowerShell cmdlet to disable/enable contact de-duplication:

  1. Pre-requisite: Setup Graph SDK PowerShell using Install the Microsoft Graph PowerShell SDK

  2. To read the setting: List contactInsights

  3. To update the setting: Update insightsSettings

Additional information

Help and support

Blog

View Details

MC486329 – The self-service trial (MC306669, December 2021) was rolled out for Microsoft 365 customers to try out Visio. Starting early January 2023, Microsoft 365 users will also be able to start a Visio trial from the web app.

Note: These trial capabilities will be available worldwide except for India. They are not available for Education or Government customers.

How this will affect your organization:

Microsoft 365 users will see an option to sign up for a Visio trial from the Visio web app (aka, Visio in Microsoft 365) using their AAD account. To complete sign up for the trial, the user will be prompted to provide payment details. You will be able to take over a self-service license to consolidate billing if needed.

Global or billing admins can use the same self-service purchase controls to disable self-service trials while making use of subscription management capabilities to oversee and manage trial licenses on the License page in the Billing section of Microsoft 365 admin center. If admins have previously disabled the self-service purchase functionality for Visio, self-service trial sign-ups will automatically allow users to request licenses directly from the admin. To view license requests, go to the Billing > Licenses page, then select the Requests tab.

What you need to do to prepare

No action is required. You can view self-service trial licenses in the Microsoft 365 admin center by going to Billing > Your Products page. Click on the filter icon, then choose Self-service.

Discover more on how to manage self-service licenses, including consolidating billing and disabling self-service trials in your organization:

  • Manage self-service purchases (Admins) | Microsoft Docs
  • Self-service purchase FAQ | Microsoft Learn
  • Manage license requests | Microsoft Learn

View Details

MC486328 – Use the OneDrive sync health dashboard in the Microsoft 365 Apps Admin Center to get an executive summary of everything happening with OneDrive so that you can resolve common issues quickly and focus on other strategic tasks as an administrator.

Proactively keeping OneDrive healthy helps ensure that your organization’s information is protected. The dashboard provides you with sync health reports for tracking relevant health issues and advisories, checking the sync status and app version of individual devices, and monitoring Known Folder Move roll out.

This message is associated with Microsoft 365 Roadmap IDs 88871 and 81982.

When this will happen:

Standard Release: Microsoft will begin rolling out mid-December 2022 and expect to complete by late December 2022.

How this will affect your organization:

Once you have configured sync clients to send diagnostic data, the preview dashboard allows you to view deployed OneDrive sync app versions, view errors on individual devices and in aggregate, and monitor the deployment progress of Known Folder Move for both macOS and Windows devices.

What you need to do to prepare:

This release requires OneDrive sync client version 22.232 or later and will only be available on the Production and Insiders ring. This feature will be available in the Deferred ring once 22.232 is rolled out to that ring. To learn more, visit https://docs.microsoft.com/en-us/onedrive/sync-health.

Additional information

Help and support

View Details

MC481284 – Starting on January 10, 2023, support for the “Submit as a template” button will no longer be available. This functionality enables users to submit flow templates as candidates for Power Automate’s public template gallery. As a result, users will no longer be able to submit their flows as templates using the “Submit as template” button.

How does this affect me?
Following deprecation of the “Submit as template” experience, we will be introducing an alternative submission process.

Action Needed:
No action is required at this time. Future updates to the submission process can be viewed here.

Please contact Microsoft Support if you need further assistance.

View Details

Microsoft has announced the general availability of RDP Shortpath support for public networks in Azure Virtual Desktop. The RDP Shortpath feature is designed to establish a direct UDP-based transport between the client and session host to improve the reliability of Azure Virtual Desktop connections.

Microsoft first started rolling out the RDP Shortpath feature back in September. Essentially, there are four major components required to establish the RDP Shortpath data flow for public networks. These include Remote Desktop client, session host, Azure Virtual Desktop Gateway, and Azure Virtual Desktop STUN Server.

“When connecting to Azure Virtual Desktop using a public network, RDP Shortpath uses a standardized set of methods for traversal of NAT gateways. As a result, user sessions directly establish a UDP flow between the client and session host. More specifically, RDP Shortpath uses Simple Traversal Underneath NAT (STUN) protocol to discover the external IP address of the NAT router,” Microsoft explained.

You can see how the RDP Shortpath feature works for public networks in the screenshot below:

RDP Shortpath enhances transport reliability for Azure Virtual DesktopThe RDP Shortpath feature provides several key benefits for Azure Virtual Desktop connections. It removes extra relay points to improve connection reliability and user experience for latency-sensitive applications. Moreover, the transport is based on the Universal Rate Control Protocol (URCP) which helps to improve the performance of UDP.

Microsoft notes that RDP Shortpath is enabled by default for all connections, and it doesn’t require any additional configurations. However, the company recommends IT admins to allow outbound UDP connectivity to the Internet, and you can find more details about configuring firewalls for RDP Shortpath on this support page.

View Details

Microsoft has started rolling out a new Communities feature in Microsoft Teams for Consumers and Teams Essentials. This release enables users and small businesses to connect, share ideas as well as collaborate with groups and teams.

Up until now, Microsoft Teams for Consumers allowed users to send chat messages, start video calls and share files/images with their friends and families. The new Communities feature lets users post announcements for all group members, organize community events, and share documents. Users can also filter content to easily access images, videos, links, and events.

“Whether your group is a recreational sports team, event planning committee, parent-teacher association, or even a small business, this new experience gives groups of all kinds a digital space to stay connected before, during, and after gatherings. Communities is currently rolling out in the free version of Microsoft Teams,” said Manik Gupta, CVP for Microsoft Teams Product.

With Communities, users can now organize in-person, virtual, and hybrid events in Microsoft Teams. For example, organizers can add new events to their community calendar, send invitations to attendees, and track attendance.

Microsoft Teams will also get a new SignUpGenius integration in 2023. It’s a popular signup tool that helps to organize group events with built-in payment processing, email and SMS reminders, and other features. This release will let users hire volunteers, coordinate events, and manage the signup process.

Small businesses can create customer communities in Microsoft TeamsMicrosoft highlights that Communities should be a welcome addition for small and medium-sized businesses (SMBs). The Communities feature is already supported on Facebook, WhatsApp, Discord, Twitter, and other social media platforms. It eliminates the need to switch between apps to engage with customers. The feature is available in Microsoft Teams Essentials when an employee logins with a Microsoft account and Microsoft 365 Family and Personal.

“With communities in Teams, your small business can move seamlessly from customer calls to team events and everything in between. You can create a virtual community group with diehard customers to announce a new sale, or just as easily create a Carpool Community for coworkers who want to share a ride to the office,” Gupta added.

Microsoft says that the new Communities feature is currently available for Android and iOS users in Microsoft Teams for Consumers. The company plans to bring this capability to desktop users, though there is no ETA yet. We invite you to check out this support page to learn more about creating communities in Microsoft Teams.

View Details

It’s been a relatively quiet month what with Thanksgiving in the U.S. and Microsoft slowly winding down for the holiday season. Nevertheless, Windows 11 officially got File Explorer tabs in the November Patch Tuesday update, Qualcomm announced new Arm technology for Windows on Arm PCs, and Microsoft released its last Windows Insider preview build of 2022.

Windows 11 officially gets File Explorer tabs and moreAs part of November’s Patch Tuesday cumulative update (CU), Windows 11 22H2 users got an updated version of File Explorer that now includes a tabbed interface and a new Favorites section where you can pin individual files. Additionally, app overflow is now supported on the taskbar.

Windows 11 File Explorer tabsOther features in File Explorer include improved OneDrive integration, where you can see the syncing status of a folder and quickly access OneDrive settings, recycle bin, and view the folder online. The update naturally comes with the usual array of security and reliability fixes.

Windows 10 version 22H2 now ready for broad deploymentWhile we’re still not sure exactly what this update contains apparently, Microsoft announced that the Windows 10 22H2 update is now ready for broad deployment. Such announcements are not usually made until 6 months after release. But considering this is such a minor update, this time round it’s happened faster.

The update is optional for users running Windows 10 version 20H2 or newer. Microsoft says it includes ‘a scoped set of features’, but it has never shared more details. My guess is that most of these new ‘features’ are for enterprises and won’t concern most small businesses or consumers.

Windows Photos app gets iCloud Photos integration on Windows 11If you use the Windows 11 Photos app to manage your photographs, then you can now use iCloud Photos in addition to OneDrive to sync your photo storage. To get this integration, you’ll need to install the iCloud for Windows app from the Microsoft Store.

Windows Subsystem for Linux now generally available in the Microsoft StoreDevelopers and other interested parties can now install the Windows Subsystem for Linux (WSL) directly from the Microsoft Store. This feature was previously available in preview. Microsoft is saying that the Store version of WSL is now the default experience and that those who use the Store to install WSL will receive updates much faster.

Windows Subsystem for Linux in the Microsoft StoreUp until now, the supported method of installing WSL was by adding it as an ‘optional’ Windows component in the Settings app. The Store version of WSL brings WSL 2 as the default distribution type. WSL 1 can still be used but it will only be supported for users who installed WSL as an optional Windows component.

The new Store version of WSL also brings Linux GUI app support for Windows 10 users, which was previously only available in Windows 11.

Windows App SDK 1.2 now availableMicrosoft released the Windows App SDK version 1.2 in November. This new version of the SDK brings the ability for developers to create widgets for their own apps in Windows 11. There are also more modern WinUI controls, including for media playback, support for dynamic refresh rates, and an app notification builder.

Importantly, the SDK brings support for Visual Studio Arm64, allowing developers to natively develop apps with WinAppSDK on Arm64 devices, starting with Visual Studio 17.3 Preview 2.

Qualcomm announces new Oryon cores for Windows on Arm PCsYes, Oryon is the Nuvia tech that we’re all hoping will change the game for Windows on Arm and help it compete with Apple. It’s just that Qualcomm doesn’t want to say it directly. Qualcomm did say:

“The creation of our custom CPU was started by Nuvia engineers while employed at Nuvia and, after the acquisition of Nuvia by Qualcomm Technologies, the custom CPU was completed by engineers at Qualcomm Technologies.”

We don’t know much about Oryon cores at the moment. To be clear, this is a technology for the processor cores that will go in Arm chips. It’s not a chip in itself. It’s likely that we won’t see devices ship with this new technology until the second half of 2024 but let’s hope for sooner. And that performance and power efficiency live up to expectations.

New AI-accelerated experiences for Windows 11 on Arm usersIn other Arm news, Qualcomm announced that it will be bringing new AI-accelerated experiences for Windows 11 users, like:

  • Windows Studio effects
    • Voice Focus
    • Background Blur
    • Automatic Framing and Eye Contact

These features are already enabled in the Surface Pro 9 5G, which uses the Microsoft SQ3 Arm chip.

Windows Insider preview buildsWindows 11 Insider Preview Build 25252 got a ‘glanceable’ VPN status icon in the system tray. That is when Windows is connected to a recognized VPN profile.

Windows 11 VPN status icon on the taskbarThis build also gets some different variations of the Search bar on the taskbar.

Windows 11 Insider Preview Build 25247 users get access to Windows Studio Effects from the Quick Settings menu on the taskbar. At least for devices that have a compatible Neural Processing Unit (NPU) that enables Studio Effects. The Settings app gets a new feature that brings energy recommendations for applying settings that reduce the device’s carbon footprint. And there’s now the ability to search processes in Task Manager!

Search processes in the Windows 11 Task ManagerBuild 25247 also has an improved visualization for OneDrive cloud storage in the form of a ‘bar’ graphic displaying the amount of storage used for the logged in account.

OneDrive storage improvements in the Windows 11 Settings appFinally, Microsoft shipped an update for the Windows Subsystem for Android in Windows 11 to all users on the Dev and Beta Channels. Microsoft says that the update improves camera, general reliability, and performance. The full list of updates is:

  • Enhancement of audio recording quality
  • Enhancement of OAuth scenarios
  • Support for MPEG2 decoding
  • Improvements to the camera experience when the device is not equipped with a camera
  • Improvements in input reliability
  • Chromium update to 106

You can find more information about the update on Microsoft’s website.

And that’s it for another month!

View Details

Microsoft has acknowledged a new issue with the latest batch of Patch Tuesday updates released on November 8. The company warned that the bug may prevent certain database connections from working on Windows 10 and Windows 11 PCs.

On the Windows Heath Dashboard, Microsoft noted that users might encounter database connectivity problems with some applications that use ODBC (Open Database Connections) via the Microsoft ODBC SQL Server driver. The bug affects Windows 11, Windows 10, Windows 8.1, and Windows 7 machines.

“You might receive an error within the app or you might receive an error from SQL Server, such as “The EMS System encountered a problem” with “Message: [Microsoft][ODBC SQL Server Driver] Protocol error in TDS Stream” or “Message: [Microsoft][ODBC SQL Server Driver]Unknown token received from SQL Server,” Microsoft explained.

Upcoming updates to fix database connection problems with Windows appsMicrosoft has not provided any temporary workaround solution to address database connection issues with apps on Windows devices. However, users can check whether their PC is running any app that’s using the problematic SQL Server driver. To do this, open the app and run the following command in the Command Prompt: tasklist /m sqlsrv32.dll

Meanwhile, Microsoft is working on a fix and it’s expected to be delivered with the December Patch Tuesday updates. It’s still unclear if this bug affected many Windows users who installed last month’s Patch Tuesday. However, it’s really unfortunate to see Microsoft once again dealing with buggy Windows patches. The company is already investigating another LSASS memory leak bug that causes freezes and reboots on some domain controllers (DCs).

Have you experienced any database connectivity problems while using apps on your PCs? Sound off in the comments down below.

View Details

Microsoft has released a new Adobe Acrobat integration in Microsoft Teams. The latest update allows users to set Acrobat as the default app to view and edit PDF files in the Teams desktop and web clients.

With this release, Microsoft Teams can open all PDF files shared in the chats and channels within the Adobe Acrobat app. This new integration lets users search, view, comment, and annotate PDF files without purchasing an Adobe Acrobat subscription. However, an Acrobat Standard or Pro account is required for creating, combining, organizing, and exporting PDFs.

“People can stay in the flow of work by securely accessing and collaborating on PDFs directly from within the Acrobat viewer in Teams. This includes the ability to share and review PDFs, collaborate in real time with comments and annotations, get notifications of comments, and easily access PDFs that are stored in Microsoft SharePoint and OneDrive,” the company explained.

How to allow Adobe Acrobat in your tenantTo get started, IT admins will need to allow the Adobe Acrobat app by following the steps mentioned below:

  • In the Microsoft Teams admin center, head over to Teams app >> Manage apps.
  • Search for the Adobe Acrobat app and click on it to navigate to the app details page.
  • Click the Permissions tab >> select Review permission >> Accept.

Org-wide permissionsHow to install the Adobe Acrobat app for all end usersOnce done, administrators can make the Acrobat app available on users’ Teams clients by following these steps:

  • Login to the Teams admin center and go to Teams app >> Setup policies.
  • Navigate to the Manage policies tab and select Global (Org-wide default) >> Edit.

App setup policies Select the Add apps option available under Installed apps. * Search for the Acrobat* app, add it and then save the policy.

It’s also possible to use app permission policies to allow the Adobe Acrobat app for select users or a group. “From a digital security standpoint, PDFs collaborated on are sent to Adobe Document Cloud servers in the region in which the user is located for transient processing. They are then deleted within 24 hours. The documents remain encrypted both in transit and at rest during this process,” Microsoft added.

Last month, Microsoft released several new features for its Teams collaboration service. These include a scheduled send feature, instant polls for meetings, and the ability to filter unread notifications in the Activity tab. Microsoft Teams users can now chat with Office 365 Groups, Mail-enabled Security Groups, and Distribution Groups with up to 250 participants.

View Details

Cloud Conversations is a regular podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations – Ana Inés Urrutia on Viva Explorers, Travel and Flying planesAna Inés Urrutia is a Dynamics 365 Human Resources specialist and a Microsoft Business Applications MVP. In this new Cloud Conversations episode, she joins Azure and Peter to chat about travel and her career with Dynamics 365 and Human Resources. They also chat about:

  • Fashion
  • Flying planes
  • The Viva Explorers
  • And much more!

More on Cloud ConversationsThe podcast is hosted by Peter Rising, Ru Campbell, and Kat Beedim, all Petri contributors. They’re joined by Azure McFarlane, a Microsoft MVP, Data Analyst, and Power Platform Consultant, and Femke Cornelissen, an Adoption and Modern Workplace Team Leader and Microsoft 365 blogger. Each week, Peter, Ru, Kat, Azure, and Femke speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

In this review, we show you how you can use Action1’s free platform to patch Windows and third-party applications. See how it works here.

What is Action1 and why do I need it?Action1 is a class-leading patch management software with a robust feature set that automates the deployment of security updates and patches to your endpoints. IT professionals know that new security vulnerabilities are discovered daily, so it is vital to stay on top of patching to keep your devices and data secure.

The move to a hybrid work environment for many organizations has created an additional layer of complexity. Patching devices that aren’t directly connected to your corporate intranet can be challenging. Action1 provides a solution.

How does Action1 work?Action1 offers a comprehensive suite of remote patch management functionality in a single cloud-native platform. Internal IT teams and MSPs can efficiently support the modern in-office, remote, and hybrid workforce infrastructures prevalent today.

Through a fully cloud-based management interface, you can deploy the agent to your endpoints regardless of their location. You can then use the core features of Action1 to keep endpoints secure, up-to-date, and protected from today’s dynamically changing vulnerability landscape.

What is cloud-native patch management?Action1 is a cloud-native platform, so you don’t need any servers or infrastructure in your on-premises environment. And, regardless of endpoint location, you can manage them from anywhere.

No virtual private networks (VPNs) and no on-premises local area network (LAN) access is needed. You simply log into Action1’s management web interface, deploy the agent to your endpoints, and create your policies and schedules. Then you watch, through compliance and real-time reports, a successful rollout of secure endpoints. You can also refer to interactive dashboards and real-time reports to check the status of your endpoints. Plus, you can gain insight into pending patches, update rollout results, and general overview of your managed infrastructure.

Action1 vs Windows Server Update Services (WSUS)As an on-premises solution, WSUS is poorly placed to serve remote workforces and dynamic IT environments. It is isolated, doesn’t scale well, and it can’t deal with remote endpoint management and security natively.

With a cloud-native platform for automated patch management, IT staff can install Windows updates remotely on thousands of endpoints simultaneously. It doesn’t matter where your employees’ devices are located or how many endpoints need to be protected.

While WSUS offers a central location to check updates and patches, it lacks flexibility, agility, and control across environments and projects. Action1 allows users to create different patch policies for different clients, servers, and workstations.

Action1 provides an unmatched level of flexibility and control, including custom security, specified reboot options, and the ability to run pre– or post-patch scripts based on need.

Securing Windows endpoints with Action1Action1 excels by including features any endpoint security platform should include to keep your endpoints secure. Action1 helps you step away from expensive legacy solutions. And it offers a fresh new solution, encompassing precise control over your entire patch management requirements and all the required features for remote monitoring and assistance.

The overall experience is streamlined, and it provides you peace of mind when determining if all your endpoints are secure.

Let’s go through each patch management feature so you get a better idea of how Action1 works.

Deploying Windows patches to endpointsSimplifying patch management through automation – that is one of Action1’s mantras of sorts. Their automated patch deployment system brings value to your company in several ways.

Enterprises today are facing pressure to keep data and information safe. Defending against attacks takes a measured and automated process to stay secure. Incorporating Action1’s patch management for Windows into your IT strategy gets you one step closer to meeting your established security baselines.

Action1 – free cloud-native patch management for WindowsYou get a centralized cloud dashboard, flexible automation and scheduling, and complete visibility with alerts and reports.

Action1 endpoint actionsUpdating third-party softwareThe deployment of apps can be consuming and tiring, much less keeping them up-to-date and secure. Bringing software deployment and third-party patching under a single-solution umbrella is efficient for IT. Action1 makes it even easier for you by offering the following features:

  • Access to the Action1 App Store with the most used apps
  • Ability to add custom apps through manual configuration
  • Centralized and automated distribution
  • Update versioning
  • Ability to rollback changes

Action1 app storeIn addition to the apps you have access to out-of-the-box, you can always upload as many apps as you need to your private storage within Action1. You can keep multiple versions of an app to avoid app compatibility issues and adjust the rollout and scheduling of updates to endpoints.

Simply pick an app and select Deploy Update, choose the endpoints you want to target, then set a scheduled rollout that works for you and your end users.

Action1 – create a new patch management policy for WindowsGenerating patch compliance reportsAction1 includes an extensive list of built-in reports. These give you full insight into the status of your endpoints, including installed software, Windows Updates status, and hardware specifications.

These reports help to:

  • Bring clarity into the IT inventory management
  • Make informed decisions about your infrastructure
  • Assess your system health state
  • Prove compliance with security standards and regulations

Here are some examples of the reports you’ll find beneficial in your environment:

Update Statistic report

Action1 – update statistics reportUpdate History report

Action1 – Windows update history reportMissing Updates report

Action1 – missing updates reportWhat other tools does Action1 include?There are a good number of additional features and tools included in Action1’s portfolio to assist your IT department with efficiency and productivity across the board.

Built-in secure remote desktop accessAction1 provides a secure, low-latency built-in remote desktop solution that is compliant with many modern data privacy standards and regulations. It offers remote assistance functionality and remote desktop capability to all your endpoints.

Remote desktop lets you see exactly what’s happening on remote endpoints. And you can take over remote sessions to solve many of your remote workers’ support issues.

App deploymentFrom Action1’s App Store, you can deploy packages to all or a subset of your endpoints. After selecting the application that you want to deploy, click on Deploy App. You have the option of manually selecting the endpoints or rolling an app out to an entire group.

Action1 – application deploymentDeployments can be run immediately or scheduled for a specific date and time. Even if an endpoint is offline, the software will retry deployment within 24 hours. For monthly schedules, the retry window is set at 7 days.

Even if your endpoint is offline for longer, you’ll always be able to get status updates using the built-in compliance reports. Moreover, you’ll be able to set up a time frame to catch up on the missed schedule when your endpoint is online again.

Software and hardware inventoryAction1 streamlines IT software inventory management with many helpful reports. Overview data, such as “Installed Software”, as well as reports that focus on specific assets, are available in Action1’s central console.

Action1 – installed apps dashboardThe Installed Software report shows you a list of software on each remote workstation and the software version. You can get basic, quick at-a-glance dashboard perspectives. And you can drill down to get more detail about a specific application or endpoint.

There are many additional detailed reports available.

  • Cloud Storage Apps
  • Instant Messages
  • Web Browsers
  • Windows Drivers
  • MS Outlook Versions

Hardware inventory management is robust and detailed with Action1. The system inventory tool discovers and catalogs your devices. And it also includes printers, sound and display adapters, and various other hardware components.

Action1 – hardware inventoryHardware Summary is a comprehensive report that provides a nice overview of your endpoints. You’ll discover the operating system, CPU architecture and performance, memory, hard drive storage details, and more.

Both features are a boon for keeping your IT asset inventory compliant and accurate. And if the built-in reports don’t meet your needs, then there is also the option to create your own custom reports using Action1’s data sources as templates.

Get the first 100 endpoints free foreverAction1 makes it easy to get started with their free tier. You are free to use it on up to 100 registered endpoints. After that, you will need to purchase a minimum of 50 endpoints beyond your initial 100 free licenses.

Large enterprises can get a fully functional 15-day trial on an unlimited number of endpoints.

Action1 summary – ease of use and low total cost of ownershipIt is easy to get started with Action1. In as little as 5 minutes, you can have your first endpoints deployed with data already pulled into a dashboard. It’s an elegant solution that helps organizations manage Windows and third-party software patching quickly and without the complexity associated with WSUS and other enterprise-level solutions.

Creating your own software packages will certainly take some time and effort. However, as you grow, the solution scales with you. And when you incorporate your endpoint-deployment policies in Active Directory, newly provisioned devices will automatically get the Action1 agent deployed to them.

Action1 includes free access for up to 100 endpoints, secure remote desktop capabilities, and excellent reporting and compliance capabilities, so you can try it out risk free. IT administrators will also appreciate the simple and intuitive interface when rolling out patches, helping to lower the total cost of ownership of endpoint devices. Plus, with new features being added via Action1’s roadmap, you’ll get access to updated toolsets regularly.

View Details

Environment variables allow you to access command line tools and control the execution of programs on your operating systems. In this article, we’ll explain how environment variables work and how to set an environment variable with PowerShell.

PowerShell provides an easy way to access, edit, and clear the Windows environment variables. PowerShell can also be used to set an environment path, edit existing paths, and handle the user profile working on the computer.

How to set an environment variable with PowerShellTo set a new environment variable with PowerShell, you can use the Set-Item cmdlet. This lets you modify an environment variable or create a new one if it doesn’t already exist.

Here’s the syntax you need to use:

Set-Item -Path Env:<variable-name> -Value ($Env:<variable-name> + ";<new-value>") Keep reading to learn different ways to set an environment variable in Powershell!

What are environment variables in Windows?Environment variables contain crucial information needed for the execution of your operating system and applications. They include information about directory paths and the location of certain core files for the operating system to function.

Environment variables also collect information about your system’s execution, and they can store data between reboots and sessions. On Windows, there are multiple ways to access and manage environment variables, and that includes using Windows File Explorer, text editors like Notepad, command prompt, and PowerShell.

PowerShell allows you to manage and access environment variables in all supported operating systems. It lets you access, change, clear, and even delete them when needed.

The 3 different scopes for environment variablesOn Windows, there are three different scopes for environment variables. These scopes follow a Machine > User > Process hierarchy, and each of them is capable of overwriting the parent one if needed.

Machine (system) scopeThe machine or system scope contains all environment variables that are related to the system and are associated with Windows instances. System variables can be seen and accessed by any user accessing the system. However, you need to have sufficient privileges to be able to change these variables.

User scopeThe user scope contains the environment variables linked to the user currently running processes on Windows. They can take priority over the machine or system variables, and with sufficient privileges, they can overwrite the system scope variables that have the same name.

Process scopeThe process scope contains all the environment variables associated with the process or PowerShell session that’s currently running. Environment variables under the process scope are a combination of both Machine and User scopes, and they’re usually inherited from the parent process along with a few Windows-created dynamic variables.

How to check environment variables with PowerShellAll the environment variables in PowerShell are stored in a PS drive called ‘Env:‘. There are multiple ways you can retrieve the environment variables along with their values in your operating system using PowerShell.

First, you can use the dir env: command:

dir env: Checking environment variables with the dir env: commandAlternatively, you can use the Get-ChildItem cmdlet to check environment variables:

Get-ChildItem -Path Env: Checking environment variables with the Get-ChildItem cmdletYou can also retrieve a specific environment variable by appending the variable name after the aforementioned commands.

Example: To retrieve HomeDrive (an example variable), you can use the command below:

Get-ChildItem -Path Env:\HomeDrive How to set environment variables with PowerShellThere are a few different ways to set environment variables using PowerShell. We’ll start with an easy method to do that.

Adding environment variablesTo add an environment variable with PowerShell, you can use the $Env variable to either set an environment variable using the assignment operator (=), or create a new one using the (+=) operator.

For example, if you wish to create the AZURE_RESOURCE_GROUP environment variable in your system in case it doesn’t already exist by default, you can do so using the command below:

$env:AZURE\_RESOURCE\_GROUP = ‘SampleResourceGroup' Note: If the AZURE_RESOURCE_GROUP already existed in your system, it will be replaced with the value you pass in the command above.

Using the $Env variable to set an environment variableUsing the Set-Item cmdletThe Set-Item cmdlet can be used to change and retrieve the value of environment variables. You can also use the Set-Item cmdlet to set or create an environment variable.

The cmdlet below will set the environment variable AZURE_RESOURCE_GROUP to ‘SampleResourceGroup2.’

Set-Item -Path env:AZURE\_RESOURCE\_GROUP -Value “SampleResourceGroup2" The PowerShell Set-Item cmdlet lets you set or create an environment variable.Using the System.Environment .NET class methodMicrosoft’s .NET framework class library is a powerful way to use and execute PowerShell scripts. The .NET class System.Environment offers methods to set environment variables.

To proceed, you need to use the SetEnvironmentVariable() method for a given scope. You can also create a new one if it doesn’t already exist.

For example, you can use SetEnvironmentVariable() to set the AZURE_RESOURCE_GROUP environment variable using the command below.

```

``` Using the System.Environment .NET class method to set an environment variableAre changes to environment variables permanent?Due to the nature of the different scopes for environment variables, your mileage may vary. All changes made to an environment variable in the process scope are volatile as they only apply to the current process (session). However, changes made to environment variables in the user or machine scopes are permanent to that respective user and machine.

How to remove an environment variable with PowerShellThere are different ways to remove or delete an environment variable with PowerShell. Firstly, you can remove them using the $Env or SetEnvironmentVariable() method of the .NET class.

For this example, let’s create a test environment variable called ‘MyTestEnvVariable’ using the following cmdlet:

$Env:MyTestEnvVariable =‘testVariable’ Now, to remove this system-wide environment variable, you can use the cmdlet below that uses the SetEnvironmentVariable() method:

```

``` Alternatively, you can also use the $Env variable to clear and delete the environment variable using the cmdlet below:

$Env:MyTestEnvVariable = $null ConclusionIn this article, we’ve detailed how environment variables work on Windows, as well as different ways to set them up with PowerShell. However, it’s important to understand the 3 different scopes for environment variables, and you also need to keep in mind that some methods to set them only apply to the current PowerShell session.

View Details

MC478688 – As previously announced, the Internet Explorer 11 (IE11) desktop app has been retired as of June 15, 2022. IE11 retirement is occurring through two phases:

  1. a redirection phase, currently in progress with devices progressively redirected from IE11 to Microsoft Edge and
  2. an upcoming Windows Update phase that includes IE11 being permanently disabled. The Windows security update (“B”) release that will permanently disable IE11 is scheduled to be available for roll out on February 14, 2023.

When this will happen:

  • The Windows Update containing the permanent disablement of IE11 is scheduled to be available in the following releases:
  • January non-security preview release, also known as 1C, scheduled for January 17, 2023
  • February security release, also known as 2B, scheduled for February 14, 2023
  • The permanent disablement of IE11 will be included in all subsequent Windows Updates after the January non-security preview release and February security release

How this will affect your organization:

  • All IE11 activity, including shortcuts using IE11 and invoking iexplore.exe will be redirected to Microsoft Edge
  • Opening shortcuts or file associations that use IE11 will be redirected to open the same file/URL in Microsoft Edge
  • The IE11 icons on the Start Menu and the taskbar will be removed
  • This Windows Update will only affect in-scope SKUs (see our FAQ for in-scope SKUs)

At this time, IE11 has been retired for over five months, but if your organization has not yet completed your transition away from IE11, continued reliance on IE11 when the Windows Update becomes available may cause business disruption.

What you need to do to prepare:

For organizations that are ready to remove IE11, it is strongly recommended to use the Disable IE policy to remove IE11 on your organization’s devices to control the timing of permanent IE11 disablement on your own schedule before the Windows Update. This way, if you discover any parts of business where IE11 disablement is disruptive, you have the time and ability to roll back and remediate with low risk. Please see the Disable IE blog for information on how and when to configure the Disable IE policy to replicate the effects of the Windows Update.

If you need help moving off IE11, please open a support ticket for help with technical issues or reach out to the App Assure team for help with app compatibility issues. Many customers have already made the move to Microsoft Edge and seen performance and productivity benefits. Microsoft Edge brings you a faster, more secure, and more modern web experience than Internet Explorer and is the only browser with built-in compatibility for legacy IE-based sites and apps with IE mode.

Support

  • If you have site compatibility issues or concerns with functionality in IE mode, reach out to App Assure for free assistance

Additional Information

  • Read the June 15, 2022 blog on IE11 retirement
  • Read the FAQ to help answer your questions.

Microsoft always values feedback and questions from our customers. Please feel free to submit either feedback or questions via Message Center.

View Details

MC478687 – Microsoft Loop components are live, interactive, collaborative objects that you can embed in Teams chats and emails – and now in Word for the web – as a convenient way to ideate, create, and plan together. While working in a Word online document, you can now create or paste a Loop component, which will insert it directly in the document canvas and can be shared with others on teams or email as well. This will help in easier and faster collaboration on documents as others’ edits will be immediately seen in your Word document. Everyone in your organization with whom you’ve shared the document will be able to edit it and see changes instantly.

When this will happen:

Targeted release: Microsoft will begin rolling out to target release users in early December and expect to complete by early February.

How this will affect your organization:

Loop components add dynamic elements to your document that you can share in Teams or email, where everyone’s edits keep your document up to date. You can insert or paste a Loop component in your Word online document to track work items, gather ideas, and more. Click here (Use Loop components in Word for the web) to learn more about Loop components and how to use them in Word Online documents.

What you need to do to prepare:

This feature will be gradually rolled out to users who are part of our Targeted release audience. Please make sure Loop components are enabled for your tenant for users to use this feature. You can check if Loop components are enabled for your tenant and take the necessary steps to enable them, if not already enabled, here: Manage Loop components in SharePoint.

Additional information

View Details

Today I’m going to tell you why you should sign up for Petri’s December Teams conference and how the knowledge you gain could help YOU supercharge Teams in your organization and even pass SC-400. I’ll be looking at the sessions delivered by MVPs and industry experts on backup and recovery, process automation, information protection, and more!

Register here: Registration link

View Details

MC477852 – With comments you can share your thoughts, celebrate with your teammates, or just have a conversation in Microsoft Whiteboard.

This message is associated with Microsoft 365 Roadmap ID: 98083

When this will happen:

Rollout will begin in late January and is expected to be complete by late February.

How this will affect your organization:

Your users would have the following experiences:

  • The ability to add comments on a whiteboard to aid in discussion with board participants.
  • This will include a comments pane to see all comments on a given whiteboard.

View image in new tab

Note: The commenting experience initially will not be supported for the Android and IOS apps. Microsoft eventually plans to bring this experience to mobile as well.

What you need to do to prepare:

There is no action required at this time. Continue checking the Microsoft Whiteboard Blog and support pages on details about upcoming features and how best to use them.

Blog

View Details

MC477851 – This feature allows users who are viewing a video to search for keywords contained in the video transcript. This feature is available on video files that have transcripts and are stored in OneDrive or SharePoint.

This message is associated with Microsoft 365 Roadmap ID 99920

When this will happen:

Targeted Release: Rollout begins in late November and is expected to be complete by mid-January.

GA: Rollout begins in mid-January and is expected to be complete by late February.

How this will affect your organization:

Users can navigate through the search results and click on a portion of the transcript to be taken to the respective spot in the video. Users need view or edit permissions on a file to search the transcript.

View image in new tab

Note: This feature is for searching the transcript of a single video. Users also have the option to search the transcripts of all videos they have permissions to view using Microsoft 365 search.

What you need to do to prepare:

There is no action required at this time. This feature will be enabled automatically. You may want to notify your users and update and training documentation as appropriate.

Help and support

View Details

MC477845 – Teams Rooms on Windows application version 4.15 includes key new features and improvements to existing functionality.

This message is associated with Microsoft 365 Roadmap ID 95260, 103659, 98423

When this will happen:

Microsoft will begin rolling out early December and expect to complete by late December.

How this will affect your organization:

  1. In-meeting notification improvement
    • This update delivers improvements to in-meeting notifications on Teams Rooms on Windows and aligns them with Desktop’s framework and new UI. All critical notifications that require user action will be shown on console.
  2. Meeting chat on Gallery, Large gallery, and Together mode

    • Always know the context by bringing the chat pane on to front of room display for Teams Rooms on Windows. In room participants can use the touch console to show and hide chat on the front of room display alongside meeting participants and/or content. The ability to show and hide chat is available through the view switcher menu. IT admins have configuration control to hide a meeting chat for a room if needed via XML. XML details will be added to https://learn.microsoft.com/microsoftteams/rooms/xml-config-file#create-an-xml-configuration-file
      View image in new tab

    View image in new tab 3. Start whiteboard in Teams meetings * Microsoft Teams Rooms users can now share a Whiteboard in a Teams meetings using ‘Share’ user interface on console. With hybrid work, whiteboarding is a key feature to enable collaboration between in-room and remote users. When the Whiteboard is started from the room, it is attributed to the meeting organizer so that the organizer can manage access to the artifact. A touch front of room display is required to use Whiteboard in the room. 4. Fit to frame Room video roster control * ‘Fit to frame’ and ‘Fill the frame’ options are available for the roster on console. Room users can change remote video participant’s status between ‘Fit to frame’ and ‘Fill the frame.’
    View image in new tab 5. Overflow meeting support. * In large meetings which are at capacity, Microsoft Teams Rooms will be able to join and stream the meeting content. This is a single screen and view-only experience similar to the one on Teams desktop client. Best practices for a large Teams meeting – Microsoft Support 6. Join Zoom meeting by ID (Direct guest join) * Microsoft Teams Rooms will be able to attend a Zoom meeting using a Zoom meeting ID. 7. Quality fixes for Third party meetings (Direct guest join) * Update to Chromium 106 which improves audio and video quality when Microsoft Teams Rooms join Zoom meetings. 8. Fix for license information in settings showing no license when Teams is not signed in * If a device is not signed in, the settings show invalid license today. This is fixed in application version 4.15.

What you need to do to prepare:

You might want to notify your users about this updated experience and update your training and documentation as appropriate.

View Details

The shopping season is finally here. That’s right, Black Friday...

View Details

This Week in IT, I look at how well the...

View Details

Earlier this month, Microsoft rolled out a new set of...

View Details

MC399073 – Updated November 23, 2022: Based on learnings from...

View Details

MC467234 – Updated November 23, 2022: Microsoft has updated the...

View Details

MC470781 – The Advanced deployment guides & assistance page in the Microsoft...

View Details

MC470780 – As part of the Non-Native and Hybrid Yammer...

View Details

Microsoft has announced that the Windows Subsystem for Linux (WSL)...

View Details

MC470147 – The ability to copy/paste live Loop components from...

View Details

MC470146 – The Power BI Service’s expanded view gives you...

View Details

MC470138 – A new Dashboard page was added to the...

View Details

MC470137 – In December 2021, a new section was added...

View Details

MC465552 – In October, Microsoft announced at Microsoft Ignite that...

View Details

MC430100 – Updated November 9, 2022: Microsoft has updated the...

View Details

Microsoft launched a preview of new server protection capabilities in...

View Details

GitHub announced yesterday that it’s bringing the AI-powered Copilot coding...

View Details

MC432475 – Updated November 9, 2022: Microsoft has updated the...

View Details

MC462923 – As announced at Ignite 2022, the ability to rename...

View Details

Zoom has announced the release of the beta version of...

View Details

Microsoft announced the general availability of .NET 7 at its...

View Details

Microsoft has released yesterday the November 2022 Patch Tuesday for...

View Details

A number of things can go wrong during the Microsoft...

View Details

MC461864 – Microsoft has released updates to the following update...

View Details

Microsoft has announced the release of a big update for...

View Details

Microsoft has announced that a new Teams Progressive Web App...

View Details

A programmer has filed a lawsuit against Microsoft, GitHub, and...

View Details

Microsoft has announced a new Webinars experience for its Teams...

View Details

This article will offer you two straightforward ways to list...

View Details

MC442480 – Updated November 4, 2022: Microsoft has updated the...

View Details

MC455545 – Microsoft will be retiring the ability to convert...

View Details

MC455520 – SharePoint is updating the site detail panel to...

View Details

MC455512 – Microsoft Defender for Office 365 (Exchange Online Protection)...

View Details

MC445202 – Updated November 3, 2022: Microsoft has updated the...

View Details

MC387038 – Updated November 3, 2022: Microsoft has updated the...

View Details

Microsoft claims that it has optimized the Microsoft Teams desktop...

View Details

Microsoft announced yesterday that it would deprecate the distribution list...

View Details

To effectively handle various types of security break-ins, many organizations...

View Details

Microsoft has released cross-tenant migration capabilities for Exchange Online. The...

View Details

Microsoft today announced the release of Azure AD Certificate-based authentication...

View Details

The Microsoft Digital Contact Center Platform is a new customer...

View Details

MC383901 — Updated November 1, 2022: Microsoft has updated the...

View Details

MC437263 – Updated November 1, 2022: Microsoft updated the content...

View Details

MC454810 – Microsoft 365 Apps are disabling server sign-in prompts...

View Details

MC454802 – Microsoft will be retiring the Popular Around Me...

View Details

MC454715 – Microsoft Power Platform will begin relying on a...

View Details

Microsoft has shared a roundup of improvements made to its...

View Details

After a whirlwind of news from the first annual Microsoft...

View Details

Microsoft Teams is getting a new app that will allow...

View Details

Microsoft has announced Microsoft Syntex, a new set of apps...

View Details

In this article, we’ll be comparing Microsoft’s Azure Directory Premium...

View Details

MC445423 – With reactions in Outlook, you can now react...

View Details

MC445422 – This message is to inform you that the...

View Details

MC445421 – The Emissions Impact Dashboard (EID) for Microsoft 365...

View Details

MC445418 – Microsoft is removing the “Turn on file synchronization...

View Details

MC394844 – Updated October 13, 2022: Microsoft has updated the rollout...

View Details

Microsoft announced yesterday that a new Windows 365 application is...

View Details

Microsoft announced several new security features and services at its...

View Details

Microsoft introduced a new Microsoft 365 app at its Ignite...

View Details

Amazon File Cache, a new high-speed cache service on Amazon...

View Details

This week at Ignite, I caught up with Steve Dispensa,...

View Details

At Ignite 2022, Microsoft unveiled several new updates coming to...

View Details

Microsoft just kicked off its Ignite 2022 conference this morning,...

View Details

Microsoft has announced its plans to roll out a new...

View Details

Microsoft has announced a range of new chat and meetings...

View Details

Microsoft is set to introduce a new service plan called...

View Details

Microsoft is getting ready to release a new Microsoft 365...

View Details

Microsoft kicked off its Ignite 2022 conference today, and there’s...

View Details

Microsoft has announced a new Designer app that provides AI-powered...

View Details

Microsoft has officially announced new Surface devices this morning, a...

View Details

Microsoft recently announced a new channel type in Teams: shared...

View Details

Microsoft has released yesterday the October 2022 Patch Tuesday updates...

View Details

Google has announced plans to bring its physical cloud infrastructure...

View Details

Google Cloud has announced several new security tools, products, and...

View Details

Microsoft Teams is getting a new update that enables users...

View Details

Last week, Microsoft released the Basic edition of its Azure...

View Details

Microsoft has recently released a fix to address a bug...

View Details

In this article, I’ll explain how to use the PowerShell...

View Details

Last week, cybersecurity researchers warned that the North Korean hacking...

View Details

This Week in IT, Intel Unison promises to bring an...

View Details

MC443901 – The ability to insert links with rich preview...

View Details

MC443900 – The ability to insert & embed online Videos...

View Details

MC443390 – Microsoft recently announced the launch of the Microsoft...

View Details

Microsoft started rolling out Windows 11 version 22H2 to all...

View Details

The Azure Command-Line Interface (CLI) is a cross-platform command line...

View Details

Microsoft has announced that Linux desktop management support is generally...

View Details

Microsoft has started rolling out the Windows 11 2022 Update...

View Details

Microsoft has released an advisory to warn Exchange Online users...

View Details

Amazon WorkSpaces added support for Ubuntu-based virtual desktops last week. If...

View Details

In this article, we’ll explore what you need to take...

View Details

Microsoft has partnered with Experian to bring identity theft protection...

View Details

The big news this month is the availability of the...

View Details

Microsoft has confirmed a new issue that is currently affecting...

View Details

The Microsoft Power Platform Conference in Orlando, Florida was on...

View Details

Cameo in PowerPoint Live

View Details

PsExec is a command-line utility program for Windows written by...

View Details

This Week in IT, I look at my top 5...

View Details

MC427758 – Updated September 30, 2022: Microsoft has updated the...

View Details

Microsoft has issued an advisory about two new zero-day vulnerabilities...

View Details

Microsoft started rolling out the Windows 11 2022 Update (22H2)...

View Details

When you need to manage file permissions on Linux or...

View Details

MC408689 – Updated September 29, 2022: Microsoft has updated the...

View Details

Microsoft has announced new contact management features for its Outlook...

View Details

MC439275 – Updated September 28, 2022: Microsoft has updated the...

View Details

Microsoft is getting ready to end support for Client Access...

View Details

Back in May, Microsoft started testing a beta version of...

View Details

Russell Smith, Editorial Director of Petri, talks to Maurice Cote...

View Details

Windows 11 Smart App Control is a new feature that...

View Details

MC411679 – Microsoft will be retiring the support for ‘My...

View Details

MC439312 – Microsoft has released updates to the following update...

View Details

Microsoft has announced Azure AD-based single sign-on and passwordless authentication...

View Details

Microsoft has unveiled a recent cybersecurity attack that allowed the...

View Details

Amazon announced last week the availability of local clusters for Amazon...

View Details

Microsoft is planning to make it easier for users to...

View Details

Microsoft has acknowledged a new issue with the recent Windows...

View Details

The Attribute Editor in Active Directory Users and Computers (ADUC)...

View Details

Earlier this year, Microsoft announced its plans to add support...

View Details

In this video, I explain the justifications behind Microsoft’s decision...

View Details

Back in March, Microsoft started testing a new SMB authentication...

View Details

As we’re currently going through times of economic uncertainty, an...

View Details

Microsoft has announced the integration of new apps and services...

View Details

Last week, Uber confirmed a major cybersecurity attack that compromised...

View Details

MC417898 – Updated September 21, 2022: Microsoft has updated the...

View Details

MC390413 – Updated September 21, 2022: Microsoft has updated the...

View Details

Microsoft Defender for Endpoint will soon turn on tamper protection...

View Details

Data Management as a Service (DMaaS) is a new IT...

View Details

MC360766 – Updated September 21, 2022: Microsoft has updated the...

View Details

The just-released Windows 11 2022 Update is bringing several new...

View Details

Following months of testing with Windows Insiders, Microsoft has finally...

View Details

Microsoft has started rolling out the Windows 11 2022 Update...

View Details

Microsoft has launched its Defender for Endpoint solution on Android...

View Details

Microsoft announced a major change to how it delivers new...

View Details

Microsoft Teams is getting a new schedule send feature that...

View Details

After you’ve built a solid, robust, and redundant Active Directory...

View Details

This Week in IT, I explain how IT certifications can...

View Details

Windows 10 version 21H1, also known as the Windows 10...

View Details

Security researchers have recently identified a vulnerability in the Microsoft...

View Details

A hybrid cloud architecture is an environment that combines private...

View Details

MC295027 – Updated September 15, 2022: Microsoft has updated the rollout...

View Details

Microsoft has introduced a new Group Policy that should make...

View Details

Microsoft has released a remixed version of its default Teams...

View Details

vCenter Converter, the former physical to virtual (p2V) machine migration...

View Details

Microsoft has released yesterday the September 2022 Patch Tuesday updates...

View Details

Microsoft has announced the release of Windows Terminal version 1.16,...

View Details

In this guide, we’ll show you how to schedule an...

View Details

Microsoft Teams is getting an improved search experience, which will...

View Details

Microsoft announced yesterday some important updates for Microsoft Sentinel. This...

View Details

Microsoft has introduced a new “update under lock” feature to...

View Details

Google announced this morning that its $5.4 billion acquisition of...

View Details

Security researchers have unveiled a new malware that is infecting...

View Details

As an IT Pro, it is highly likely that you’ve...

View Details

Last month, Microsoft launched its Viva Engage social networking platform...

View Details

Microsoft has released a patch to address an issue that...

View Details

Would you like to never be bothered by Windows Update...

View Details

Back in July, Microsoft unveiled a new Excel Live feature...

View Details

Azure Data Factory is a cloud-based data integration platform from...

View Details

Microsoft is getting ready to retire its Scheduler service for...

View Details

Microsoft has detailed some new features added to its Windows...

View Details

Microsoft has launched a new WebRTC-based enterprise content delivery network...

View Details

Last month, Microsoft announced that it’s revising the pricing structure...

View Details

PowerShell is a cross-platform object-oriented language and shell that IT...

View Details

Amazon and VMware announced last week the general availability of...

View Details

Microsoft Teams is working on a new update that will...

View Details

Microsoft has released an update that blocks the use of...

View Details

In this guide, we’ll explain how to back up Active...

View Details

It’s time for you and your team to take a...

View Details

MC399074 – Updated September 2, 2022: Availability for the web...

View Details

MC420056 – Updated September 2, 2022: Microsoft has updated the...

View Details

This Week in IT, I show you how sharing files...

View Details

Microsoft has announced the release of version 1.71 of its...

View Details

MC364307 – Updated September 2, 2022: Microsoft has updated the...

View Details

In this article, we’ll explain the basics of networking, networking...

View Details

Microsoft is once again notifying customers that it will finally...

View Details

September is shaping up to be a month of working...

View Details

MC382821 — Updated September 1, 2022: Microsoft has updated the...

View Details

MC424414 – Non-Native and Hybrid Yammer Networks will be upgraded...

View Details

MC399868 – Updated September 1, 2022: Microsoft has updated the...

View Details

Amazon Web Services (AWS) has announced the launch of a...

View Details

Microsoft’s Azure Managed Grafana service that launched in preview back...

View Details

Microsoft has acknowledged that customers may experience domain name system...

View Details

Microsoft Teams is getting a new update that will enable...

View Details

Microsoft launched a preview of Arm support on Azure virtual...

View Details

In this article, we’ll explain how to install Grammarly for...

View Details

Microsoft has started rolling out a new update for Outlook...

View Details

In this guide, we’ll explain how to create and connect...

View Details

Microsoft has announced some important changes to its restrictive software...

View Details

Last year, Microsoft released two new Windows 365 Endpoint analytics...

View Details

Cybersecurity company Mandiant has discovered that an elite group of...

View Details

Microsoft is getting ready to sunset its Kaizala group messaging...

View Details

Microsoft has launched a new tool to help IT admins...

View Details

As more organizations look to consolidate infrastructure in the cloud,...

View Details

LastPass has announced that its development environment was recently compromised...

View Details

The Microsoft Teams Exploratory experience is a free trial license...

View Details

MC419812 – Today, Microsoft is pleased to introduce Adoption Score,...

View Details

Microsoft and Amazon have reportedly halted their plans to build...

View Details

Microsoft Teams is getting a new update that will enable...

View Details

If you can’t make it to this year’s AWS re:Invent...

View Details

VMware has acknowledged a new issue with its Carbon Black...

View Details

Avast has launched a new Ransomware Shield to protect small...

View Details

Microsoft has announced the general availability of Azure Communication Services...

View Details

Windows Autopatch is a new Microsoft service that organizations can...

View Details

Microsoft unveiled its plans to integrate Viva Engage within Teams...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring...

View Details

Microsoft has announced that real-time co-authoring support for protected documents...

View Details

Google has announced an important configuration change for Google Workspace...

View Details

System Restore on Windows 10 is a crucial backup feature...

View Details

Cybersecurity company Mandiant has discovered that hackers are using a...

View Details

Microsoft has acknowledged a new issue with the recent security...

View Details

Microsoft has released a new update for its Microsoft Defender...

View Details

MC415922 – Viva Learning is introducing a separate toggle to...

View Details

MC415902 – With this update, users will be able to...

View Details

Google has announced that it blocked the largest distributed denial-of-service...

View Details

In this article, I will show you how to share...

View Details

Microsoft has announced the release of version 14.0 of Sysmon....

View Details

The Microsoft Teams admin center is a convenient tool for...

View Details

Microsoft has announced some important pricing changes regarding Microsoft Teams...

View Details

Microsoft has released time-based one-time passcode (TOTP) support for Azure...

View Details

Microsoft has released the optional patch (KB5016693) for Windows Server...

View Details

MC414834 – Microsoft Graph connectors have introduced a simplified setup...

View Details

Microsoft has partnered with Canonical to bring native .NET 6...

View Details

This article will detail the different versions of Microsoft’s Azure...

View Details

MC414802 – To help create better boundaries and protect personal...

View Details

MC414800 – The Briefing email from Microsoft Viva helps users start their...

View Details

MC414799 – These updates include our new Assignments web part...

View Details

MC414798 – You can now configure the availability of attendance...

View Details

Microsoft has announced the launch of a new datacenter region...

View Details

MC414474 – In Microsoft Teams, Microsoft will be releasing a...

View Details

Microsoft has launched a public preview of its Microsoft Dev...

View Details

Microsoft Teams has started rolling out a new Video Clip...

View Details

Microsoft has released a new guided hunting notebook for its...

View Details

Office LTSC 2021 is the latest perpetual version of Office...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring...

View Details

MC412836 – In mid-November 2021 (MC289683), Microsoft announced the rollout...

View Details

Microsoft announced this week that it’s changing the default location...

View Details

MC411668 – Updated August 12, 2022: Microsoft has updated the...

View Details

MC394785 – Updated August 12, 2022: Microsoft has updated the...

View Details

According to the tech press, ‘it’ doesn’t exist until Apple...

View Details

Active Directory is an essential part of Windows Server. It...

View Details

Amazon recently announced the general availability of license-included Visual Studio...

View Details

Google has released a new update that should help to...

View Details

Need to search for a string inside a string? Never...

View Details

Microsoft has launched a new Experience Insights dashboard this week....

View Details

In this article, we will explore in detail what AWS...

View Details

Microsoft has announced the release of Visual Studio 2022 17.3....

View Details

Microsoft is celebrating 15 years of its OneDrive cloud storage...

View Details

Microsoft has released yesterday the August 2022 Patch Tuesday updates...

View Details

Google has announced that it’s building three new cloud regions...

View Details

Microsoft has announced that its Entra Verified ID service is...

View Details

In this article, I will show you how to test...

View Details

The AWS re:Invent 2022 conference is the main AWS technical...

View Details

Microsoft has announced that new Universal Print capabilities that debuted...

View Details

Slack has confirmed that a security vulnerability accidentally exposed the...

View Details

Microsoft has started rolling out Edge version 104 to the...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring...

View Details

In this article, I will share my recommendations on how...

View Details

PowerShell’s built-in exit keyword allows you to terminate scripts without...

View Details

Check out this week’s video for my top 5 new...

View Details

MC409422 – Microsoft is introducing three new SharePoint team site...

View Details

Microsoft has announced the general availability of its Azure Fluid...

View Details

Windows PowerShell has a robust error handling capability with PowerShell...

View Details

For organizations looking to use Amazon Web Services to get...

View Details

MC409015 – Microsoft has released updates to the following update...

View Details

MC408994 – Updated August 4, 2022: Microsoft has updated the...

View Details

Microsoft has unveiled some security enhancements for the Smart App...

View Details

Back in May, Microsoft unveiled a new Defender Experts for...

View Details

Microsoft Teams client for macOS is finally getting native support...

View Details

Microsoft is investigating a new issue that is causing the...

View Details

Ever found yourself wanting to learn more about Linux shell...

View Details

MC397430 – Updated August 2, 2022: Microsoft has updated the...

View Details

Microsoft has announced two new security services to enhance the...

View Details

Grep (Global Regular Expression Print) is a commonly used Linux...

View Details

Microsoft Viva Goals, a new goal-setting and management tool that...

View Details

Last month, Microsoft announced its plans to launch a new...

View Details

Cloudflare and Amazon CloudFront are two of the most renowned and reliable...

View Details

As I sat down to write this month’s installment of...

View Details

It’s that time of year when the lightning strikes and...

View Details

Last week, Microsoft started rolling out an update to block...

View Details

Microsoft has detailed a round-up of new features that were...

View Details

VMware has announced the release of the Fusion 22H2 Tech...

View Details

Earlier this month, we reported that Microsoft Teams is adding...

View Details

Are you in the market for a new laptop? Or...

View Details

Microsoft has released the Windows 11 preview build 25169 for...

View Details

Windows Autopilot is a new Microsoft tool that IT pros...

View Details

MC406436 – Microsoft is excited to announce that early access updates for...

View Details

MC406259 – Users in Forms for the web can now...

View Details

Amazon has released new security updates for its Amazon Elastic...

View Details

One of the features that both makes PowerShell so easy...

View Details

Microsoft announced the public preview of Azure Active Directory Certificate-Based...

View Details

MC345824 – Updated July 27, 2022: Microsoft has updated the...

View Details

MC397476 – Updated July 27, 2022: Microsoft has updated the...

View Details

MC387036 – Updated July 27, 2022: Microsoft has updated the...

View Details

MC312070 – Updated July 27, 2022: Microsoft has updated the...

View Details

Microsoft has published a security advisory about a new wave...

View Details

Because Microsoft announced its quarterly and annual earnings this week, I’m back with a new edition of Short Takes that looks exclusively at the results across all of the software giant’s major business units.

View Details

Microsoft has launched a new Unified Update Platform (UUP) that...

View Details

The “trust relationship between this workstation and the primary domain...

View Details

MC405987 – IT admins may notice that Microsoft Teams Real-Time...

View Details

MC405984 – SharePoint recommends a maximum of 2,000 lists and...

View Details

Apple has released a new update that brings a much-anticipated...

View Details

Microsoft has acknowledged a new issue that is currently preventing...

View Details

PowerShell is an object-oriented shell for Windows, Linux, and macOS....

View Details

Microsoft has announced the general availability of new Azure AD...

View Details

Last year, Microsoft released security updates to address Windows Server...

View Details

In this article, we are going to take a brief...

View Details

MC403916 – Meeting categories in Outlook allow users to easily...

View Details

Back in February, Microsoft announced that it would begin blocking...

View Details

VB.NET is a Windows-only technology. So, moving these applications to...

View Details

Microsoft has announced its plans to retire the built-in Windows...

View Details

SQL Server is Microsoft’s premier enterprise database platform. But in...

View Details

Microsoft is apparently scrapping next year’s big update for Windows...

View Details

MC403644 – Updated July 22, 2022: Microsoft has updated this...

View Details

The internet infrastructure firm Cloudflare has released an advisory about...

View Details

Google has officially launched Chrome OS Flex, a free version...

View Details

Azure Bastion native client support provides a secure way to...

View Details

Depending on what part of the country you’re in, coping...

View Details

Apple iOS 16 Lockdown Mode – what is it and...

View Details

Microsoft has announced that it’s bringing support for Apple M1/M2...

View Details

Microsoft has recently announced some important updates for Azure AD...

View Details

Microsoft has released server protection capabilities for its Defender for...

View Details

MC393821 – Updated July 13, 2022: Microsoft has updated the...

View Details

Google Cloud today announced Tau T2A, its first virtual machines...

View Details

Microsoft released the July 2022 Patch Tuesday updates yesterday for...

View Details

Microsoft has discovered a new massive AiTM phishing campaign that...

View Details

Microsoft is preparing to drop support for its Microsoft 365...

View Details

In the past few months, Azure Stack HCI pricing has...

View Details

Microsoft has announced the general availability of new enterprise IoT...

View Details

Microsoft has launched a new Health dashboard in public preview...

View Details

Windows Autopatch, an enterprise service that launched in public preview...

View Details

This past July 6, 2022, Amazon announced the release of...

View Details

MC398250 — This feature is an Intelligent translation feature. Teams Mobile...

View Details

MC398204 — Microsoft is excited to announce the preview of Managed...

View Details

Microsoft Teams is getting an update that will automatically end...

View Details

Microsoft has recently released a new update (version 1.69) for...

View Details

Microsoft is investigating a new Windows 11 bug that is...

View Details

In this guide, we’ll explain how to install Git on...

View Details

MC395422 – With Cameo in PowerPoint Live, users will be...

View Details

Microsoft has announced that its Entra Permissions Management solution is...

View Details

Microsoft recently announced a new Teams app called Admin, which...

View Details

Microsoft has released version 4.5.0 of the Teams PowerShell module....

View Details

Microsoft is set to backtrack on its decision to block...

View Details

The “Remote Desktop Connection: an internal error has occurred” message...

View Details

Last week, Microsoft announced the release of the Windows Server...

View Details

Microsoft’s Azure cloud is experiencing capacity issues due to ongoing...

View Details

Microsoft has announced some important updates that should improve the...

View Details

Microsoft has warned customers about a new high-risk worm called...

View Details

Microsoft has announced Ephemeral OS disk support for Azure confidential...

View Details

In this post, I’ll detail five essential principles for successful...

View Details

Back in May, the Cybersecurity & Infrastructure Security Agency (CISA)...

View Details

There have been many exciting updates for Microsoft’s Power Platform...

View Details

Microsoft has announced the release of a new Admin App...

View Details

Microsoft announced a big update for Teams on the web...

View Details

Microsoft has started rolling out the Edge WebView2 Runtime to...

View Details

Microsoft has announced that the Temporary Access Pass (TAP) is...

View Details

Microsoft has released the KB5014668 update for Windows 11, a...

View Details

Microsoft Defender for Identity is getting a new update that...

View Details

At its past re:MARS conference last week, Amazon announced that...

View Details

A virtual machine (VM) is an emulated or digital version...

View Details

Microsoft is getting ready to end support for its almost...

View Details

The US Cybersecurity and Infrastructure Agency (CISA) has warned that...

View Details

Microsoft first announced plans for a new and faster Teams...

View Details

SQL Server 2022, the latest release of Microsoft’s relational database...

View Details

Microsoft has announced new features and improvements coming to its...

View Details

QNAP has released a patch to address a new PHP...

View Details

Microsoft has released a new Windows 11 build to Insiders...

View Details

Microsoft Lists calendar view is getting better with conditional formatting...

View Details

Microsoft has announced that it’s expanding the Secured-core initiative to...

View Details

GitHub has announced that its Copilot AI coding assistance tool...

View Details

When you need to create files and folders on a...

View Details

Microsoft announced yesterday that it has started rolling out several...

View Details

If you’re having issues with Microsoft 365 services right now,...

View Details

Microsoft has released out-of-band patches for Windows 11 and various...

View Details

QNAP has published an advisory about a new stream of...

View Details

Microsoft has confirmed a new issue that causes Microsoft 365...

View Details

First introduced back in November 2021 at AWS re:Invent, Amazon...

View Details

When trying to join a computer to an Active Directory...

View Details

Microsoft Teams is getting a new update that enables users...

View Details

Microsoft has acknowledged a new known issue causing the Wi-Fi...

View Details

Microsoft has teamed up with Apple to improve the security...

View Details

If you’re using Git for source code management, you may...

View Details

Earlier this week, Microsoft released the June 2022 Patch Tuesday...

View Details

Microsoft has launched a new Microsoft Defender for individuals app...

View Details

Amazon announced a couple of weeks ago that AWS DataSync...

View Details

Microsoft has finally launched the first native ARM64 version of...

View Details

Microsoft announced yesterday that it has entered into a definitive...

View Details

Organizations adopting Microsoft’s cloud services need to keep their employees...

View Details

Microsoft has released yesterday the June 2022 Patch Tuesday updates...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring...

View Details

Microsoft is finally ending support for its Internet Explorer 11...

View Details

Microsoft has announced a new set of AI-powered capabilities to...

View Details

Microsoft-owned GitHub is getting ready to retire Atom, an open-source...

View Details

Microsoft has released some important updates for its Microsoft Entra...

View Details

With GPUpdate, administrators can update Group Policy settings from a...

View Details

This week in IT, I take a look at the...

View Details

Microsoft is set to introduce a new algorithmic newsfeed on...

View Details

Security researchers have discovered a new Linux malware dubbed Symbiote...

View Details

Microsoft Defender for Endpoint has released a new Contain feature...

View Details

Through Microsoft Purview Insider risk management in Microsoft 365, organizations...

View Details

MC337955 – Updated June 9, 2022: Microsoft has updated the...

View Details

Cybersecurity researchers have found that attackers are exploiting the recently...

View Details

MC390752 – The SharePoint multilingual feature is expanding to include...

View Details

MC390410 – Authenticated Received Chain (ARC) is an email authentication...

View Details

MC390407 – The new experience for accessing Mail, Calendar, People,...

View Details

MC390406 – While composing an email or a meeting invitation...

View Details

Microsoft has announced that it’s expanding its Windows Customer Connection...

View Details

Microsoft Teams on Mac and iOS has finally added support...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring...

View Details

As your organization’s logical layout changes, you may need to...

View Details

MC320165 – Updated June 7, 2022: Microsoft has updated the...

View Details

Microsoft has announced that Windows 11 version 22H2 is now...

View Details

Microsoft has launched a new software updates dashboard in the...

View Details

Purple Knight is a free security assessment tool for Microsoft...

View Details

Apple has officially unveiled its first Macs powered by the...

View Details

Microsoft claims that it has optimized its Teams desktop app...

View Details

Atlassian has released new security updates to fix a critical...

View Details

In this guide, I’ll explain how AWS Lambda lets you...

View Details

MC388229 – Microsoft is making enhancements to Microsoft Defender for...

View Details

MC341571 – Updated June 2, 2022: Microsoft has updated the...

View Details

Atlassian has published a security advisory about a new critical...

View Details

This week in IT, I take a look at the...

View Details

MC384778 — Updated June 2, 2022: Microsoft has updated the content...

View Details

MC350768 – Updated June 2, 2022: Based on learnings from...

View Details

Microsoft has delayed its plans to release the next version...

View Details

If your company is interested in modernizing its infrastructure with...

View Details

MC362277 – Updated June 2, 2022: Microsoft has updated the...

View Details

MC387684 – Microsoft asks that you pardon us for not...

View Details

MC387683 – Recording your thoughts and jotting down notes using...

View Details

MC387641 – This new feature will allow members of Team...

View Details

MC387640 – Call queue agents can now place calls from...

View Details

Security researchers have discovered a new zero-day vulnerability that allows...

View Details

Microsoft has released a hotfix today to address data logging...

View Details

Back in April, Microsoft unveiled a new feature to help...

View Details

This month, Microsoft announces an update to the Surface Laptop...

View Details

Windows 10 offers many ways for you to reset a...

View Details

Microsoft has officially announced its new Surface Laptop Go 2...

View Details

Just like that, it’s Summer. Though many are thinking about...

View Details

Microsoft has launched a new product family of identity and...

View Details

Microsoft has acknowledged a new zero-day remote code execution flaw...

View Details

DevOps Pipelines help you to deliver new features in your...

View Details

Microsoft has unveiled a couple of security improvements to Azure...

View Details

This week in IT, I talk about Microsoft’s latest addition...

View Details

MC336858 – Updated May 13, 2022: Microsoft has updated the...

View Details

Microsoft has announced that it’s adding a new built-in virtual...

View Details

Microsoft has added re-authentication support in Azure AD Conditional Access....

View Details

MC284259 – Updated May 13, 2022: Microsoft has updated the...

View Details

MC317765 – Updated May 13, 2022: Microsoft has updated the...

View Details

MC305100 – Updated May 13, 2022: Microsoft has updated the rollout...

View Details

MC285905 – Updated May 13, 2022: Microsoft is removing this...

View Details

MC337246  – Updated May 13, 2022: Microsoft has updated the rollout...

View Details

MC379026 – Microsoft is pleased to announce that the next...

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations – Kevin McDonnell on Security & Compliance, Hybrid Work, and Viva Kevin McDonnell is a Microsoft 365 Solutions Architect at CPS, a Microsoft MVP (Office Apps & Services), and the co-host of the GreyHatBeardPrincess podcast. In this week’s Cloud Conversation episode, Kevin joins Peter Rising to talk about:

  • The future of hybrid working
  • What’s new in Security & Compliance
  • Microsoft Viva
  • Objectives and Key Results (OKRs)
  • Assembling a team to produce a new online book on Microsoft Purview Compliance

More on Cloud Conversations The podcast is hosted by Peter Rising, Ru Campbell, and Kat Greenan, all Petri contributors; and Azure McFarlane, a Microsoft Microsoft (MVP), Data Analyst, and Power Platform Consultant. Each week, Peter, Ru, Kat, and Azure speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft has announced some important changes regarding its Update Compliance service. The company says that Update Compliance will require the use of the cloud-based Azure AD service starting October 15, 2022.

For those unfamiliar, Update Compliance is a Windows Analytics service hosted in Microsoft Azure. It enables IT Admins to monitor the deployment status of the feature, security, and quality updates for Windows 10 and Windows 11 PCs. It helps organizations to keep their devices up to date, secure, troubleshoot issues, and monitor bandwidth usage.

Going forward, all organizations that want to keep using the Update Compliance service will need to move to Azure Active Directory (direct or hybrid). Furthermore, all enrolled Windows 10 or 11 devices should meet the Windows diagnostic data processor configuration requirements. This capability allows organizations to manage data collection permissions. These changes will go into effect on October 15 this year.

“To use the Windows diagnostic data processor configuration, targeted devices must be Azure Active Directory (Azure AD) joined or hybrid Azure AD joined. As a result, beginning October 15, 2022, devices that are neither joined nor hybrid joined to Azure AD will no longer appear in Update Compliance. All Windows diagnostic data processor prerequisites must be met to continue using the service after that date,” the company explained.

Microsoft to retire CommercialID support in Update Compliance Microsoft is also planning to replace CommercialID with Azure AD tenant ID in its Update Compliance service in early 2023. The Log Analytics service uses the unique CommercialID to identify each device within an organization.

In addition to the Azure AD requirement for Update Compliance, Microsoft advises IT Admins to ensure proper configuration of their CommercialID before October 15th. These steps are mandatory for organizations to continue using the Update Compliance service.

Last but not least, Microsoft has also announced some changes for all customers currently using the Workplace Join capability. The company says that these Windows devices would no longer meet the new requirements for its Update Compliance service in mid-October.

View Details

Microsoft is getting ready to drop support for Basic Authentication in its Exchange Online e-mail service. The company is reminding customers that it will begin to permanently disable this feature for select protocols in its multi-tenant service worldwide starting October 1, 2022.

Essentially, Basic Authentication means that an application provides a user name and password for client access requests. It is a legacy authentication mechanism typically used by apps to connect to services, servers, and APIs. Basic Authentication is relatively easier to configure, and it’s turned on by default on various services and servers.

However, Basic Authentication makes it makes for threat actors to steal user credentials, and it’s also subject to password spray attacks. Moreover, this outdated industry standard doesn’t allow organizations to enforce multifactor authentication (MFA). Microsoft says that turning off Basic Authentication should help improve the security of its Exchange Online service by preventing attackers from compromising user accounts.

“As a reminder, Basic Auth is still one of, if not the most common ways our customers get compromised, and these types of attacks are increasing. We’ve disabled Basic Auth in millions of tenants that weren’t using it, and we’re currently disabling unused protocols within tenants that still use it, but every day your tenant has Basic Auth enabled, you are at risk from attack,” the Exchange team explained.

Microsoft to disable Basic Authentication for specific protocols in Exchange Online Microsoft has noted that it plans to end Basic Authentication support for most protocols in Exchange Online, such as POP, IMAP, RPC, MAPI, Remote PowerShell, Exchange Web Services (EWS), as well as Offline Address Book (OAB). The company has already disabled SMTP AUTH for all Office 365 tenants who do not use it. It advises organizations to turn off the protocol at the tenant level and only enable it for specific employees as needed.

The Redmond giant plans to provide IT Admins a 30-day advance notice via Message Center notifications prior to disabling Basic Authentication in their tenants. “There is no way to request an exception after October. Tenant selection is random, and we cannot put your tenant to the back of the queue to give you more time or change your settings on any specific date,” the Exchange team added.

Microsoft recommends customers to switch their email clients and apps to modern authentication (OAuth 2.0 token-based authorization) methods. The firm has provided some guidelines to help IT Pros prepare for this change, and you can check out the blog post for details.

View Details

Whether you’re a PowerShell pro or just starting out, it’s useful to know how to check your PowerShell version. We’ll explain how to do that in this guide.

How to check your PowerShell version Let’s quickly check the version of PowerShell installed on your device:

  1. Launch PowerShell by opening the Start menu and typing powershell.
  2. In the list of search results, click Windows PowerShell or PowerShell v7.
  3. In the PowerShell window, type $PSVersionTable.PSVersion and press ENTER to get the exact version of PowerShell.

For more details on the different ways to check the PowerShell version, and getting the version of PowerShell installed on remote systems, keep reading!

From PowerShell 1.0, to Windows PowerShell, to PowerShell v7- but which version are you using? PowerShell 1.0 was released in 2006 for the Windows operating system, including Windows XP (SP2), Windows Server 2003 (r2 SP1), and Windows Vista. It is part of the .NET framework and even comes with a graphical program called the PowerShell ISE. You can search for it in the Start menu.

Searching for the PowerShell ISE in the Start Menu In typical Microsoft fashion, there is a myriad of ways to determine what version of PowerShell you’re running. However, you should be careful in using the ‘best’ one as some methods won’t necessarily give you the accurate results you’re looking for – especially if you need to satisfy a certain requirement or prerequisite before you can run a specific command or load a certain module.

But don’t worry, I’ll go through some of the basic methods and then finish with the silver bullet you should definitely keep in your PowerShell toolbelt.

The Get-Host command and $host commands The basic ‘client-server’ dynamic that PowerShell uses is the concept of a host. A host is a program that is hosting PowerShell.

You can have multiple versions of PowerShell hosts installed on a computer, so each engine of PowerShell is its own host. The main culprit for the inaccuracy of the following commands is that you can have a host that has a version that is independent of PowerShell itself.

Let me show you by opening a new PowerShell window on my Windows 11 client in my Windows Server 2022 Active Directory lab environment (Hyper-V). You can also specify your PowerShell console as your default profile in Windows Terminal.

The Get-Host command You can use the Get-Host command to get an idea of the version of PowerShell you’re running. However, again, this can be inaccurate.

Get-Host

Using the Get-Host command – for now, it’s accurate… The $host and $host.Version commands The $host variable is an automatic variable that returns the same output as the above ‘Get-Host’ command.

$host

$host.Version

The $host and $host.Version commands As you can see, the output is identical to the original commands above.

Why are these two commands not always recommended? I’ll get to why these two commands are not reliable in a bit. But, let me give you a sneak preview. When I run a command on a remote computer (one of my Windows Server 2022 Domain Controllers), it does not report accurate results.

Invoke-Command -ComputerName WS16-DC1 -ScriptBlock {$host.Version} -Credential $cred

The $host.Version command, when run remotely, does NOT report accurate results The $PSVersionTable command So, remember when I was talking about a silver bullet? Well, this is it. The native command we’ll use is the PSVersionTable automatic variable that returns information specifically about the PowerShell engine version.

The $PSVersionTable command not only returns the version of PowerShell, but also the ‘Edition’. Incidentally, this command will also report if you’re running PowerShell Core or PowerShell Desktop.

$PSVersionTable

The $PSVersionTable command works wonderfully! How to check your PowerShell version using Registry As with nearly every application and feature in Windows, you can open the Registry to get configuration and version information. This includes PowerShell. You can run this command to view the PowerShellVersion registry key with the ‘Get-ItemProperty’ command.

(Get-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\PowerShell\3\PowerShellEngine -Name 'PowerShellVersion').PowerShellVersion

Accessing the Registry to determine PowerShell version information How to check the PowerShell version on remote PCs Thanks to the robustness and scalability of PowerShell, you can verify the versions of PowerShell on remote computers, too. You can use the same commands as if you were locally on the remote machine. However, there are a few prerequisites you’ll want to verify on your remote machines first.

The most basic is to verify Windows Management Framework (WMF) is installed and enabled. You can run the winrm quickconfig command one time on the remote machine (as an Administrator) to have Windows take care of all the checks and balances.

winrm quickconfig

Running ‘winrm quickconfig’ prepares a machine to be remotely accessed via PowerShell After preparing a PC to be remotely accessed by PowerShell, here are some examples of the remote commands you can run to verify PowerShell versions. Let’s start with the Get-Host command

Invoke-Command -ComputerName WS16-DC1 -ScriptBlock {Get-Host} -Credential $cred

Checking remote PowerShell versions isn’t accurate using these earlier commands… Again, this is one of my Windows Server 2022 DCs reporting the inaccurate version of 1.0. This is NOT correct. So, again, you’ll want to use our silver bullet remotely, too, the $PSVersionTable command.

Using $PSVersionTable on remote PCs The $PSVersionTable command, when run remotely, will accurately report the version of PowerShell running on the remote computer.

Invoke-Command -ComputerName WS16-DC1 -ScriptBlock {$PSVersionTable.PSVersion} -Credential $cred

Using $PSVersionTable remotely works wonderfully! How can I install the latest version of PowerShell? Again, as per typical Microsoft fashion, there are even little hints when launching PowerShell that there are better and brighter versions you could be using. Will they stop at nothing? Is nothing sacred?

Microsoft ‘advertising’ later versions of PowerShell when you…launch PowerShell! So, let me give you a few methods you can use to install a more recent and secure version of PowerShell.

Microsoft Store On Windows 10 and Windows 11, you can just open the Microsoft Store and search for PowerShell.

Downloading PowerShell from the Microsoft Store WinGet You can use the package manager, WinGet, to download the latest version from your favorite command line/terminal. Because the winget command can download PowerShell from various repositories, (Microsoft Store (msstore) or ‘winget’), I use the ‘-s’ option to specify ‘winget.’

winget show PowerShell -s winget

Downloading the latest version of PowerShell right from the command line – No websites to browse! Information superhighway You can also browse Microsoft’s Docs website to download various package types of PowerShell.

PowerShell for Windows Download Site Are you looking for a macOS version? Browse here! What about Linux? You guessed it. PowerShell is cross-platform and open source. Grab the Linux version here!

Conclusion I hope you learned a little bit more about PowerShell and how to determine what version of it your computer is running. You also have several avenues to download and install the latest version on your PCs, and my own preference is using winget.

Please feel free to leave a comment if you have any questions or want to voice your opinions. Thank you for reading!

View Details

Security researchers at Armis have discovered five critical vulnerabilities in multiple network devices sold by Aruba and Avaya. The security flaws, dubbed TLStorm 2.0, could allow malicious actors to gain complete control of network switches typically used in hospitals, hotels, airports, and other businesses.

According to the security researchers, the TLStorm 2.0 vulnerabilities have CVSS scores of 9.0 to 9.8 and exploit the security issues in the NanoSSL TLS library. These flaws enable an attacker to modify the behavior of a network switch, gain remote access to enterprise networks and eventually steal sensitive information.

The NanoSSL TLS library implementation introduces three critical bugs on Avaya devices. The first Avaya flaw (CVE-2022-29860 is a TLS reassembly heap overflow that could potentially lead to remote code execution. Moreover, the attackers can abuse the second vulnerability (CVE-2022-29861) to execute arbitrary malicious code remotely on the network switch. Lastly, the second critical Avaya bug could cause an exploitable heap overflow.

Similarly, the first Aruba vulnerability, tracked as CVE-2022-23677, is triggered by weakness in NanoSSL. This critical flaw can be exploited by threat actors through the captive portal system. Meanwhile, CVE-2022-23676 is a memory corruption bug that exists in the RADIUS client implementation of network switches. It lets attackers overflow heap memory for remote-code execution.

“These research findings are significant as they highlight that the network infrastructure itself is at risk and exploitable by attackers, meaning that network segmentation alone is no longer sufficient as a security measure,” Armis explained.

The TLStorm 2.0 flaws affect 10 million Aruba and Avaya network switches The threat analysts found that the new set of flaws impacts around 10 million Aruba and Avaya network switches. The list of affected models includes Avaya ERS3500 Series, ERS3600 Series, ERS4900 Series, and ERS5900 Series. Additionally, Aruba devices impacted by TLStorm 2.0 include Aruba 5400R Series, 3810 Series, 2920 Series, 2930F Series, 2930M Series, 2530 Series, and 2540 Series.

Armis security researchers have collaborated with Aruba and Avaya to address the TLStorm 2.0 vulnerabilities in their network devices. They have confirmed that these flaws have not been exploited in the wild. However, Armis recommends customers to install the latest patches released by both vendors to mitigate potential exploitation attempts in their organizations.

View Details

Microsoft has launched a new standalone version of its Defender for Business solution for commercial customers. The new cost-effective enterprise-grade endpoint security offering was first announced at Ignite 2021, and it’s designed for small to medium-sized businesses with up to 300 employees.

The Redmond giant started rolling out Microsoft Defender for Business to organizations with a Microsoft 365 Business Premium plan in March. The premium product costs $22 per user per month, and it includes Office apps, Microsoft Intune, Azure Virtual Desktop, Azure Active Directory Premium P1, as well as Azure Information Protection.

This new Microsoft Defender for Business standalone edition explicitly targets those small businesses (with limited resources) who don’t want to purchase the premium suite. It’s available to purchase via Microsoft Partner Cloud Solution Provider (CSP) partners at $3 per user per month, billed annually. The new security offering is available across Windows, macOS, iOS, and Android.

“Microsoft believes in security for all. We are proud to further deliver on that vision today. With the GA of Defender for Business, SMBs will get greater protection with simplified security to help them better protect, detect and respond to threats,” explained Vasu Jakkal, CVP, security, compliance & identity at Microsoft.

Specifically, Microsoft Defender for Business comes with a bunch of key security capabilities such as attack surface reduction, threat and vulnerability management, endpoint detection and response, automatic investigation, and remediation. The company also claims that it offers “Next-gen” protection against viruses, malware, and ransomware attacks.

Microsoft Defender for Business to get server OS support in late 2022 Moving forward, Microsoft is also planning to add Windows and Linux server support to the standalone edition as an add-on later this year. “Windows Server experience will be the same as Windows client. Linux servers will use deployment scripts allowing you to integrate into your existing management platforms such as Chef, Puppet, and Ansible,” the company explained.

Microsoft has noted that the new Defender for Business standalone solution should help its partners push more customers to the Microsoft 365 Business Premium suite. Additionally, it offers integration with Microsoft 365 Lighthouse, which allows partners to track security incidents across tenants in a unified administrator solution.

Microsoft Defender for Business is also getting some new integrations with third-party Remote Monitoring and Management (RMM) tools, including Datto RMM. Meanwhile, ConnectWise RMM integration with Microsoft 365 Business Premium and Microsoft Intune is expected to arrive in the coming months.

Microsoft is offering a free 30-day trial of its Defender for Business service, and we invite you to check out the product page for details. If you are interested to learn more about Defender for Business, the company will hold a free webinar for its partners on May 5, 2022.

View Details

Last week, QNAP published a security advisory to warn customers about new critical flaws in an open-source fileserver technology integrated into its network-attached storage (NAS) devices. The company has advised customers to look out for updates to address the vulnerabilities affecting some of its products.

QNAP explained in its advisory that these flaws exist in Netatalk. It is a free open source version of Apple Filing Protocol (AFP) used to share files between clients and servers. Specifically, AFP enables macOS clients to access data stored on NAS devices. The company says that this outdated file access protocol is still being used because it supports various macOS attributes not found in other protocols.

It is important to note that Netatalk released an update (v3.1.13) to patch all the security issues in March. QNAP confirmed that it has already addressed the Netatalk flaws in QTS 4.5.4.2012 build 20220419 and later. However, these vulnerabilities still impact several older versions of its QTS operating system. The list includes:

  • QTS 5.0.x and later
  • QTS 4.5.4 and later
  • QTS 4.3.6 and later
  • QTS 4.3.4 and later
  • QTS 4.3.3 and later
  • QTS 4.2.6 and later
  • QuTS hero h5.0.x and later
  • QuTS hero h4.5.4 and later
  • QuTScloud c5.0.x

QNAP advises users to temporarily disable AFP The company is currently investigating the security vulnerabilities, and it’s planning to release updates for all impacted QNAP OS versions soon. “QNAP is thoroughly investigating the case. We will release security updates for all affected QNAP operating system versions and provide further information as soon as possible.” QNAP explained.

In the meantime, QNAP is urging customers to disable AFP on QTS or QuTS hero NAS devices to mitigate the Netatalk vulnerabilities in their organization. To do so, head to the Control Panel > Network & File Services > Win/Mac/NFS/WebDAV > Apple Networking. Finally, disable the “AFP (Apple Filing Protocol)” option.

View Details

There are new features this month across the Power Platform including some brand-new Power Apps functions, a new version of Power Automate for desktop, and UX updates for Power BI.

Power Apps now supports the new SharePoint list image column type Power Apps now supports the new SharePoint list image column type. The concept is cool, in that you can see an image associated with your SharePoint list item, along with thumbnails that were previously available with a SharePoint document library; however, these are “read only” columns.

Microsoft says that they’re developing the capability to update this data, but it’s not there yet. Another limitation is that if you download this type of column into a collection, the image will not render. So, with the current limitations to this feature, it does narrow the applications for it.

Power Fx new features Power Fx has a trio of new features fully deployed in April including String interpolation, the Index function, and the RandBetween function.

String interpolation is not strange to those who have programmed in C#. You can begin a string with a $ sign then add quotes with a normal text string. Then you can insert Variables into the string by using curly braces {}, such as: $”Did you notice this new feature, {User().FullName}?” Quotes are only needed once in this context, but it’s just another way to combine strings with variables. If the other ways work for you, you can continue to use them.

The Index function comes to Power Fx from Excel and enables you to go directly to a record within a table. It is designed to tidy up the earlier method to find a record by a more complex formula like Last(FirstN(Table, N); simply using Index(Table, N) now does the trick of finding record “N”.

RandBetween also comes via Excel and allows you to generate a random number between and including a bottom and top number. You can tell the RandBetween function a low and high value which returns a single integer between (and inclusive of) the given values. The syntax for this one is: RandBetween(Bottom, Top).

Dataverse AAD User table On the Dataverse side of Power Apps, there is now a new AAD User table including every user in your AAD, not just those with a Dataverse license. Whereas the User table in Dataverse only shows Dataverse-licensed users, the AAD User table portrays all the organizational users. A shortfall is that the Dataverse AAD User table is not able to retrieve groups or expanded information (such as manager). It is also not available for Power Automate. Read more here.

Power Automate Flows Power Apps Studio Within Power Apps, you can now work on Power Automate flows within the studio. Though in Preview mode, you can now use the Power Automate pane to open an actual flow creator within your screen window (without going into a new browser tab). Additionally, you can add flows to your app by using a Power Automate tab on the left side of your screen, like the way you can add data sources.

Another new feature in preview is wrap for Power Apps. Though originally touted in November 2021, it is currently only available in North America, and it needs to be installed into your environment. Wrap enables you to take your app and package it with your own branding, then allow your users to download the package as a standalone app (meaning they don’t have to go through Power Apps to use it). Another feature touted is that you can embed multiple Canvas apps into the package. If these things sound like something you’re looking for you can read more about that here.

In a similar vein, Power Apps (Preview) is available on Windows, and available through the Microsoft Store. The Windows version supplies users a way to run apps offline and uses native device capabilities, like running Power Apps on an Android or iOS device.

Power Automate for desktop Power Automate has offered a new update for Power Automate for desktop. There are now built-in example desktop flows to help you get started. Another feature enables cloud or region selection during sign in. There’s a new action to mimic hovering your mouse over a UI element in a window. Another interesting new feature is the ‘Populate text sending keystrokes’ which imitates your keystrokes on a keyboard, for certain Javascript tasks that require this vs. sending text.

Finally, the new version offers a new recorder experience which could improve the performance; however, Microsoft warns that the tradeoff is that the action ‘Drag and drop UI element in window’ isn’t part of the recorder. So, if you’re a user depending on this one, don’t go to the new version.

Power BI updates Power BI has pushed some updates this month with some significant changes to the UX in the Reporting section. Plan on getting used to the new Format Pane experience, sometime in May the old experience will go away. Some goodness of the new experience is that you’ll be able to customize your controls a bit easier. Tooltips support now has broadened (in Preview) to include drill actions for matrix, line, and area charts.

Viewing composite models and navigating through the complexities of assigning permissions for your data consumers is becoming a thing of the past (in premium workspaces) as Microsoft has simplified permissions to enable read/view access to them. The Error bars rolled out last month for line charts have been expanded to include clustered column and bar charts.

I hope you can enjoy all the new features in the Power Platform this month. As more and more businesses catch on to the possibilities within reach through the available tools our skills are increasingly being sought out. It’s a fun journey to be on!

View Details

This month sees Microsoft announce a whole load of new features for Windows 11, but it’s not clear when they will all be generally available. Plus, Microsoft gives some advice on upgrading to Windows 11 and Edge beats Safari to become the 2nd most used web browser on desktop devices.

Microsoft offers advice on upgrading to Windows 11 from its own experience In a recent post on Microsoft’s website, Lukas Velush said that the upgrade to Windows 11 of 190,000 end user devices was the smoothest ever and it was completed in only five weeks. The post goes on to say:

“Our success was built around several factors: far fewer app compatibility challenges than in the past, not needing to build out a plethora of disk images, and delivery processes and tools already that were greatly improved during the rollout of Windows 10. We divided our upgrade into three stages: plan, prepare, and deploy.”

Microsoft used Windows Autopilot and coordinated with its OEM partners to make sure that all new devices came with Windows 11 preinstalled. Then Windows Autopilot configured everything for the employee on first boot.

Windows 11 deployment (Image Credit: Microsoft) Windows 10 21H2 now ready for broad deployment Microsoft announced in April that Windows 10 21H2 is ready for broad deployment in businesses. This milestone is typically reached 6 months after a Windows feature release is made generally available. It means that Microsoft has patched any major bugs and you can roll out the feature update in confidence. After performing your own validation of course.

Windows licensing in Azure is anticompetitive according to some critics If you want to run Windows in Google Cloud or AWS, you will end up paying more for the privilege. In a recent Bloomberg article, Microsoft acknowledged that Windows pricing is cheaper in its own Azure cloud. And that maybe the current situation should be addressed.

Microsoft President and Vice Chairman Brad Smith said: “There definitely are some valid concerns. It’s very important for us to learn more and then make some changes.”

New Windows 11 features announced at Hybrid Work event In an online event earlier in April, Microsoft announced a whole load of new features coming to Windows 11. Some of which are already available as you read this article, like Remote Help. And for others, it’s not clear when they will see the light of day. Nevertheless, here’s a rundown of the new features:

  • Passwordless single sign-on
  • Enhanced phishing protection
  • Smart App Control
  • Start menu folders
  • Tabs in File Explorer
  • Cloud PC integration – Windows 365 Boot, Windows 365 Switch, and Windows 365 Offline
  • New Snap layouts
  • Favorite files
  • Widgets improvements
  • Live captions
  • Improved focus tools

For a description of each new feature, check out Here Are the New Windows 11 Features That Microsoft Announced on Thurrott.com.

The Your Phone app is now called Phone Link The app that allows Windows users to easily access info and apps on Android smartphones is now called Phone Link. In a post on evolving the connection between your phone and your Windows PC, Microsoft said:

“We see this experience as more than just bringing your phone into your PC but as a bridge between the two devices, so we are renaming the app to Phone Link. And to further celebrate this connection between your two devices, we have also renamed the mobile companion app from Your Phone Companion to Link to Windows for all Android users”

Microsoft Teams app coming to the Store in May According to its Microsoft 365 roadmap, the Teams app should be coming to the Microsoft Store in Windows in May. The version available for Windows 10 users will support work, school, and consumer accounts. The Windows 11 version will support just work and school accounts because the built in app already supports consumer MSA logins.

At this moment, it’s not clear whether this is just the current Electron app packaged for the Store, or the promised Teams 2.0 client that has only been seen in a prerelease version until now.

SMB v1 file sharing protocol disabled by default in upcoming Windows 11 release Microsoft is now disabling SMB v1 in Insider builds of Windows 11.

“There is no edition of Windows 11 Insider that has any part of SMB1 enabled by default anymore. At the next major release of Windows 11, that will be the default behavior as well,” explained Ned Pyle, Principal Program Manager in the Windows Server engineering group.

Smart App Control requires a fresh install of Windows 11 If you want to take advantage of Smart App Control, a new feature coming to Windows 11 that prevents untrusted or unsigned applications running, you’ll need a fresh install of Windows to get it.

“It goes beyond previous built-in browser protections and is woven directly into the core of the OS at the process level. Using code signing along with AI, our new Smart App Control only allows processes to run that are predicted to be safe based on either code certificates or an AI model for application trust within the Microsoft cloud. Model inference occurs 24 hours a day on the latest threat intelligence that provides trillions of signals.”, says David Weston.

So while Smart App Control will be enabled by default on new Windows 11 devices, existing users will have to reinstall the operating system or use the ‘Reset this PC’ feature.

Microsoft Edge improved sleeping tabs and 10% market share As of writing, Edge 101 was just released. But in version 100, Microsoft touted increased performance with sleeping tabs.

“Beginning in Microsoft Edge 100, we’ve updated sleeping tabs to enable pages that are sharing a browsing instance with another page to now go to sleep. With this change, 8% more tabs on average will sleep, saving you even more resources! On average, each sleeping tab saves 85% of memory and 99% CPU for Microsoft Edge.”

Microsoft Edge 100 performance gains (Image Credit: Microsoft) Microsoft Edge also now has 10% of the desktop browser market, apparently knocking Safari off second place. The gap between Edge and Google Chrome is still massive, naturally.

Windows 11 Insider builds The only interesting feature that hasn’t already been mentioned elsewhere in this article is a series of new MDM and Group Policy controls for IT admins in Windows 11 build 22610.

The new policies are for controlling certain aspects of the taskbar, notification center, and Start menu:

  • Disable Quick Settings flyout
  • Disable Notification Center and calendar flyouts
  • Disable all taskbar settings
  • Disable search (across Start & taskbar)
  • Hide Task View from taskbar
  • Block customization of ‘Pinned’ in Start
  • Hide ‘Recommended’ in Start
  • Disable Start context menus
  • Hide ‘All apps’ in Start

And that is it for another month!

View Details

Microsoft unveiled its plans to launch the Lists app for Android at its Ignite conference back in November 2021. The Redmond giant has now announced on the Microsoft 365 Admin center that the Lists app is now available to download for business and enterprise customers from the Google Play Store.

First launched in 2020, Microsoft Lists is designed to help customers keep track of tasks or projects and track issues. It is a powerful alternative for Asana, Jira, Airtable, and other task management tools. This new Android app should make it easier for users to create and manage lists, access lists offline, edit list items, as well as collaborate on tasks with their colleagues while on the go.

Microsoft Lists for Android also lets users scan and upload documents as attachments to list items. Moreover, it provides ready-made templates that let managers create lists using pre-configured layouts for various scenarios. These include employee onboarding, asset manager, content scheduler, work progress tracker, issue tracker, and more.

“With access on the go and collaboration, you can keep everyone connected with Microsoft Lists. Start quickly with ready-made templates, add content to the columns, set priorities, share lists, invite teammates, and manage your work and information seamlessly,” the company explained.

Microsoft Lists for Android doesn’t support personal accounts According to Microsoft, customers will need an Office 365/Microsoft 365 commercial subscription that includes SharePoint to access the Lists app on their mobile devices. However, Microsoft Lists for Android doesn’t support personal MSA accounts yet. The firm is working to make it available to mobile users with a free personal account, though there’s currently no ETA.

Microsoft has noted that the Lists app has Intune device management support with mobile device management (MDM) and mobile app management (MAM) policies. However, the Android version of Lists currently only supports “Require app protection policy.” The company plans to add the Conditional Access (CA) grant access control support later this month. This should bring the app on par with other Microsoft 365 apps like SharePoint.

View Details

Cloud Conversations is a weekly podcast that we’ll be featuring here on Petri. It’s about everything connected to cloud computing, including technologies like Azure, Microsoft 365, Power Platform, Microsoft Endpoint Manager (MEM), Microsoft Defender, Windows, Intune, and much more!

Cloud Conversations – Nikki Chapple Teams Governance, Community, and Tech Nikki Chapple is a Principal Cloud Architect at CloudWay, and she’s also an Office Apps and Services MVP. In this week’s episode, Nikki joins Kat and Azure to talk about:

  • What is Teams sprawl
  • How tech has changed over 30 years
  • Speaking and networking events
  • Music – Duran Duran and raving

More on Cloud Conversations The podcast is hosted by Peter Rising, Ru Campbell, and Kat Greenan, all Petri contributors; and Azure McFarlane, a Microsoft Microsoft (MVP), Data Analyst, and Power Platform Consultant. Each week, Peter, Ru, Kat, and Azure speak to a guest who shares their industry insights and technical experience.

Cloud Conversations doesn’t only focus on the technical. Each episode covers topics like career progression, community, productivity to get the most out of your day as an IT pro, equality and diversity in IT, and much more to help IT pros survive and thrive out in the wild!

Previous guests on Cloud Conversations include a list of well-known industry experts and technologists, including Stephen Rose, who is a Microsoft Teams Senior Product Marketing Manager, Petri’s Steve Goodman, who is an MVP in Microsoft Office Apps and Service, and Andy Malone, who is an MVP in Enterprise Mobility and a Microsoft Certified Trainer.

View Details

Microsoft has published a monthly roundup of the updates made to its Teams collaboration service during the month of April. This includes new chat & collaboration features (such as suggested replies), enhancements to the meetings experience, new Teams certified devices, and much more. Here’s a look at everything you need to know.

Microsoft Teams’ Presenter mode gets new move & resize options First up, Microsoft has rolled out some improvements for the Presenter mode feature in Teams. The latest update adds new buttons to the presenter modes preview window that allows the speaker to appear on the right or left side of the content. It is also possible to adjust the size of the overlayed video feed to make meetings more engaging.

Microsoft also released a new update that lets IT Admins configure call forwarding settings for end-users. The configuration of call delegation and group call pickup capabilities can be done via the Teams admin center or the Teams PowerShell Module.

Suggested replies coming to Teams chats There are also some new chat & collaboration features for Microsoft Teams. Now, desktop users can use suggested replies to quickly respond to chat messages without having to type them. The AI-powered feature takes into account the context of the previous message to generate three short responses.

The suggested replies feature is on by default, but users will be able to disable them manually. To do this, head to Settings > General, then uncheck the Show suggested replies in chat option available under the Suggested replies section.

Additionally, IT Admins will now see a new Power Automate tab in select Microsoft-provided team templates. It offers a wide range of Power Automate flow templates for creating new teams with predefined channels and preinstalled applications. In addition, the Approvals app in Teams now displays files uploaded through the Power Automate portal within the view details window.

Microsoft announced new Teams certified devices Microsoft has also rolled out some enhancements for Teams Rooms devices on Windows. The “Present” button has been renamed as Share and it is now available on the Teams Rooms home screen. Users will now find the Cortana push-to-talk button at the bottom of the home screen. Nevertheless, this change will only appear on select Teams Rooms devices that have already enabled the Cortana voice assistance policy.

The Redmond giant has also unveiled some new Teams certified devices for professional conference room configurations. There is a new Logitech RoomMate device that allows IT admins to deploy Teams Rooms on Android and other video conferencing services in meeting rooms of any size. Other Teams certified devices include Logitech Tap Scheduler Panel, Yealink Teams HD IP Conference Phone, and Yamaha ADECIA Ceiling Solution.

IT Admins can now pin message extensions for end-users Last but not least, Microsoft has also announced some new management capabilities for Teams. Administrators can now pin message extensions for end-users in their tenants. These apps will be accessible to all users via the compose bar.

The Microsoft Teams device store is now available in the Teams Admin Center for customers in the US and Canada. It makes it easier for IT Pros to find and purchase new certified Teams devices for their organizations. The company plans to expand this capability to other markets in the coming months.

View Details

In episode 17 of This Week in IT, Petri’s Editorial Director, Russell Smith, looks at Microsoft’s rapidly growing security business after the recent earnings report. Plus, there’s more security news as Emotet moves from feeding off Office macros to PowerShell. And Microsoft teams up with Red Button to provide independent testing of Azure cloud infrastructure.

Plus, Microsoft is providing small businesses with one hour of free presales support for Microsoft 365, registrations for Build open, and Microsoft is quietly moving Microsoft 365 commercial customers to the Monthly Enterprise Channel.

And as always, there’s a spotlight on the best now tutorial articles on Petri.com. And this week’s Hot Tip shows you how to create Microsoft Loop ‘paragraphs’.

About This Week in IT This week in IT is a weekly podcast hosted by Petri’s Editorial Director Russell Smith. Each week, Russell rounds up the most important stories for IT pros in a short video.

View Details

Microsoft has released new patches to address critical security vulnerabilities affecting its Azure PostgreSQL product. Discovered by security researchers from Wiz Research, the “chain” of flaws dubbed “ExtraReplica” could be exploited to gain unauthorized cross-account database access.

According to the security advisory published by the Wiz Research team, the vulnerabilities allow attackers to bypass tenant isolation in Azure’s infrastructure. ExtraReplica exploits a flaw that lets unauthorized users get read access to PostgreSQL databases.

“By exploiting an elevated permissions bug in the Flexible Server authentication process for a replication user, a malicious user could leverage an improperly anchored regular expression to bypass authentication to gain access to other customers’ databases. This was mitigated within 48 hours (on January 13, 2022),” Microsoft Security Response Center (MSRC) explained.

Specifically, the threat actor first selects a public PostgreSQL Flexible Server and then finds the target’s Azure region. Once done, they create an attacker-controlled database in the same region.

The attacker can now exploit the first security flaw on the target attacker-controlled instance. This vulnerability was discovered in Azure’s PostgreSQL engine modifications, and it makes it possible to escalate privileges and run malicious code. The next step involves abusing the second flaw found in the certificate authentication process to gain read access to the target instance.

Microsoft fixes the ExtraReplica bug on all vulnerable servers It is important to note that the security vulnerabilities don’t affect “Single Server instances or Flexible servers with the explicit VNet network configuration (Private access).” Microsoft says that it has addressed the flaws on all vulnerable servers. The company reiterated that it had not found evidence that this vulnerability was actively exploited or compromised customer data.

“No action is required by customers. In order to further minimize exposure, we recommend that customers enable private network access when setting up their Flexible Server instances,” MSRC added. We invite you to check out the Flexible Server networking support page for more details.

View Details

Microsoft has released built-in authentication support for its Azure Container Apps, a new fully managed serverless container service. The feature enables developers to secure external ingress-enabled container apps without writing code.

The Redmond giant launched Azure Container Apps at its Ignite conference in November 2021. It is a serverless hosting solution that builds on Azure Kubernetes Service (AKS). Azure Container Apps allow developers to deploy multiple containers without dealing with complex infrastructure.

Microsoft understands that it takes a considerable amount of time and effort to build secure authentication and authorization solutions. It requires developers to follow certain cybersecurity standards and practices as well as ensure that their implementation remains updated.

With this release, Azure Container Apps introduced some new features that provide access to various built-in authentication providers. Essentially, these features don’t require a specific SDK, language/security expertise as well as code. This should make it easier for developers to focus on the functional implementation of their applications.

“The authentication and authorization middleware component is a feature of the platform that runs as a sidecar container on each replica in your application. When enabled, every incoming HTTP request passes through the security layer before being handled by your application,” the company explained.

Azure Container Apps support Azure AD, GitHub, and more Microsoft highlights that Azure Container Apps currently support various identity providers and the list includes Azure Active Directory, GitHub, Twitter, Google as well as Facebook. Moreover, it’s also possible to integrate any third-party identity provider that supports OpenID Connect.

The built-in authentication for Azure Container Apps is currently available in preview for all customers worldwide. Microsoft has also detailed some considerations for using this new built-in authentication mechanism. These include using HTTPS, disabling the “allowInsecure” attribute, restricting app access to authenticated users, and more. If you’re interested, you can find more details on this support page.

View Details

Microsoft has announced in a message on the Microsoft 365 Admin Center that it will automatically begin updating all devices with Office apps to the Monthly Enterprise Channel next month. The Redmond giant is urging commercial customers to get ready for the move for various reasons, based on user feedback.

The Monthly Enterprise Channel allows users to get new Office updates on the second Tuesday of each month. The monthly release schedule is particularly useful for organizations with IT departments looking for a predictable release schedule for downloading new features, security improvements, and non-security patches.

“Customers on a monthly feature update cadence, such as those customers on Monthly Enterprise Channel, have reported higher satisfaction than those receiving semi-annual feature updates. In addition to receiving the latest features and fixes, having all devices on the same update frequency helps enable better collaboration experiences for users in your organization,” the company explained on the Microsoft 365 Admin Center.

Microsoft noted that this change affects both existing and new Office installations in tenants on all update channels except the Monthly Enterprise Channel. Additionally, Microsoft Office will get updates “directly from the internet.” It should make it easier for IT Pros to keep their Office installations up-to-date.

For end-users, this switch to the Monthly Enterprise Channel will happen in the background while using the Office 365 apps. With this change, users will be able to get some new features that were not previously available in their tenant.

Microsoft recommends IT Pros to opt-out of this change before May 20 To prepare for this change, IT admins will need to manually opt-out before May 20 to keep their devices on the existing channel. To do so, head to the Microsoft 365 Apps admin center, select View details option available on the notification. Finally, click the Keep my devices on current configuration button.

Microsoft plans to begin rolling out this change to Microsoft 365 commercial customers in late May, and the deployment is expected to be complete in early June. Do you think that moving to the Monthly Enterprise Channel will help to reduce the administrative workload in your organization? Let us know in the comments section below.

View Details

While there are some limitations, there’s a lot that you can do to make the Windows 11 Start menu and taskbar more like Windows 10, but you can also personalize them in other ways. Let’s take a closer look at some of the ways you can configure the Windows 11 Start menu and taskbar to be more to your liking.

If you’ve been a long-time Windows 10 user (and who isn’t?), the first things that you’ll notice on Windows 11 are, without a doubt, the changed Start menu and taskbar. In what seems to be a fairly blatant attempt to copy the Mac, Microsoft has moved the Start menu from the left bottom of the screen to the center of the bottom of the screen. In addition, the taskbar, which was previously moveable, is now glued to the bottom of the screen.

While some people may like these changes, I think it’s fair to say that there are quite a number of people that don’t. What you might not realize is the fact that the new Windows 11 Start menu and taskbar can be customized in many ways.

How to customize the Windows 11 Taskbar The taskbar is typically used as a quick launchpad, and it also lets Windows users keep track of all the apps that are currently running. You can see how the new Windows 11 default taskbar looks below.

The default look of the Windows 11 taskbar Before we start, it’s important to emphasize that the new taskbar is more limited than the Windows 10 taskbar, which was moveable and resizable. The new Windows 11 taskbar is not moveable, and there’s nothing you can do about it for now. However, there are many things that you can still customize.

How to move the taskbar and Start Menu to the left In Figure 1, you can see the taskbar icons and the Start Menu are centered by default. One of the first things you might want to do is to move the Start menu back to the left corner of the taskbar.

After long-term usage, you can come to expect to find your apps in a specific place, and having to look for them elsewhere can be a waste of time. This is what you could call muscle memory

There are a couple of important advantages to having the Start Menu on the left corner as well. If you have a lot of items on your taskbar and you tend to use it as a shortcut for launching different apps, then you can run out of room pretty quickly if the icons are all centered.

Here’s how to move the Start menu to the left corner of your screen:

  • Do a right-click on the taskbar and select Taskbar settings
  • In the Settings app, scroll down to the Taskbar behaviors section.
  • Use the Taskbar alignment dropdown and select Center to Left, as you can see in the image below.

Changing the taskbar alignment After closing the Settings window, the Start menu and app icons in the taskbar will move to the left, as seen below. Now, that looks much more familiar!

The Windows 11 Start Menu has now moved to the left How to automatically hide the taskbar Just like on Windows 10, the Windows 11 taskbar can also be made to disappear when it’s not used. It will automatically reappear when you hover the mouse in the lower section of the screen where the taskbar is normally displayed.

Here’s how to make the Windows 11 taskbar automatically disappear:

  • Right-click on the taskbar and select Taskbar settings.
  • Scroll down to the Taskbar behaviors section, and check the Automatically hide the taskbar box as seen below.

You can automatically hide the taskbar How to customize which items show on the Taskbar You can also control and customize which items are on the Windows 11 taskbar as well as how the taskbar displays the taskbar corner icons, just like on Windows 10.

How to pin apps to the taskbar for quick access If an app is running then the icon for that app will be displayed in the taskbar and there will be a line underneath it indicating that the app is active. If you want that app’s icon to remain in the taskbar even after you’ve closed it, right-click on the icon and select Pin to taskbar.

Pinning a running app to the taskbar For an app that already has a desktop shortcut, you can pin it to the Taskbar by right-clicking on the desktop icon, then selecting Show more options from the context menu. This will display an expanded context menu where you can select Pin to taskbar.

Pinning a desktop shortcut to the taskbar In File Explorer, you can also pin any .exe files to the taskbar by following the same procedure. Right-click on the .exe file that you want to pin, then select Show more optionsfrom the context menu, and select Pin to taskbar from the expanded context menu.

Pinning an app from File Explorer to the taskbar You can also pin all apps that appear in the Windows 11 Start Menu to the taskbar. Here’s how to do it:

  • Open the Start menu and click the All apps button
  • From the full list of apps, you can right-click on the app you want to add to the taskbar and move the mouse pointer over More from the context menu
  • This will display an expanded context menu where you can click on the Pin to taskbar option.

Pinning an app from the Start Menu to the taskbar How to remove apps from the taskbar If you want to remove apps from the taskbar, right-click on the taskbar icon and select Unpin from taskbar. This works for most apps.

You can easily unpin apps from the taskbar The Search, Task view, Widgets, and Chat icons can all be toggled on or off. Here’s how to do it:

  • Right-click on the taskbar and select Taskbar settings
  • In the Taskbar items section, you can toggle each icon on or off

You can show or hide buttons for Search, Task view, Widgets, and Chat As you might expect, the Start menu icon cannot be removed. Do you remember the original version of Windows 8 had no Start button on the taskbar? Yeah, those were the days.

How to customize taskbar corner icons and overflow The taskbar corner icons are found in the right corner of the taskbar. That’s where you can see the time and date, your volume level, your network status, your OneDrive status, as well as various other things. The overflow is the pop-up menu that appears when you click on the arrow that is immediately to the left of the corner icons.

Taskbar corner icons and the overflow pop-up menu Many of the corner icons cannot be changed. However, a handful of them can be hidden from the taskbar settings:

  • Right-click on the taskbar and select Taskbar settings
  • Go to the Taskbar corner icons section, where you can to toggle the Pen menu, Touch keyboard and Virtual touchpad icons on or off.
  • Likewise, you can toggle the Microsoft OneDrive, Windows Security, and Windows Update icons on or off in the overflow section.

You can choose which icons will appear on the right corner of the taskbar and the overflow menu How to show the taskbar on multiple displays By default, the taskbar should stretch over multiple monitors. However, if for some reason the taskbar doesn’t appear on multiple monitors, you can open up taskbar settings and scroll down to the Taskbar behaviors section where you can check the Show my taskbar on all displays setting.

You can choose to show the taskbar on external displays You can also use the When using multiple displays, show my taskbar apps dropdown to select which monitor the taskbar icons will be displayed on. Here you can choose All taskbars, Main taskbar and taskbar where the windows is open, or Taskbar where window is open from the dropdown menu.

How to show your accent color on your Start menu and taskbar Just like Windows 10, Windows 11 lets you personalize your desktop in various ways. You can still choose between light and dark modes, and you can also use a custom accent color across your desktop.

Here’s how you can customize your desktop appearance on Windows 11:

  • Right-click on the desktop to open the Settings menu, then select go to Personalizations > Colors
  • If you want to carry your customized accents to the Start menu and taskbar, scroll to the Accent Colors section and toggle the Show accent color on Start menu and taskbar option.

You can show your accent color on your Start menu and taskbar How to resize the Windows 11 taskbar While you can’t resize the Windows 11 taskbar with the mouse or with any settings, it can still be resized by editing the Windows 11 registry. This isn’t really complicated, though you always need to be careful if you decide to change anything in the Windows 11 registry.

Anyway, here’s how to proceed:

  • Use Regedit to open the Windows 11 registry
  • Navigate to the following registry key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • Right-click the Advanced key and select New > DWORD (32-bit) Value.
  • Add the name TaskbarSi as a new key.
  • Next, double-click Taskbarsi to display an edit window.
  • In the Value Data field, enter 0, 1, or 2. 1 represents the default size. 0 represents the smallest one while 2 represents the biggest one.
  • Enter 2 to increase the taskbar size and click OK.

Editing the Registry to increase the taskbar size The change will take effect when you close the Registry Editor and restart your system. This change also alters the sizes of the icons that are displayed on the taskbar.

We’ve made the taskbar and icons larger thanks by editing the registry The default taskbar size can be restored by either deleting the TaskbarSi value or by entering the value of 1 and restarting the system.

Creating a custom taskbar You can also create a completely custom taskbar that overrides the default set of apps with your own set of apps. However, that requires editing and deploying XML documents which is beyond the scope of this article. You can learn more about creating custom taskbars from the Microsoft docs at Customize the Taskbar on Windows 11.

How the customize the Windows 11 Start Menu After using Windows 10 for years, the spartan Start menu on Windows 11 can be rather jarring. While most people won’t miss the Live Tiles, I think just about everybody used icon grouping which is now MIA.

That said, the new Start menu is limited to 18 items per page – far smaller than the Windows 10 Start menu. Let’s have a closer look at some of the main ways to customize the Windows 11 Start menu.

How to change which items show on the Start Menu The Windows 11 Start menu is primarily used as a quick launchpad to easily find and run apps. However, the new Start menu also incorporates elements from File Explorer, and it can show the most recently used files and apps.

One of the first things you’ll notice about the new Start menu is that all your favorite app groups are gone, replaced by recently used apps and a number of bloatware icons like Disney+, Amazon Prime Video, TikTok, and others. Some of these may be great on a personal system, but you typically don’t want them on a work system.

The default Windows 11 Start menu First, let’s look at adding and deleting items on the Start menu.

How to pin your favorite apps The easiest way to add missing apps to the Start menu is to select them from the All apps list:

  • Click the All apps button in the top-right corner of the Start menu
  • Scroll through the list until you see the apps that you want to pin to the Start menu
  • Right-click the app and then select the Pin to Start option.

Pinning items to the Start menu from the All apps list How to show or hide your recently added and most-used apps You can customize the Windows 11 Start menu to show your recently added apps, your most-used apps, as well as your most recently used items. Here’s how to enable these customizations:

  • Open the Start menu and click Settings
  • Navigate to Personalization and Start.
  • Here, you can toggle on Show recently added apps,Show most used apps, and Show recently opened items in Start, Jump Lists and File Explorer.

Showing your most recently used apps on the Start menu The Recommended section at the bottom of the Start menu will now show our recently opened items.

How to add shortcuts to library folders By default, the Windows 11 Start menu doesn’t show the common system library folders. However, you can easily add them back, here’s how to do it:

  • Open the Start menu and click Settings.
  • Next, open Personalization and Start, and click the Folders option to display the Folders settings that you can see below
  • You can choose the folders you want to display on the Start menu by toggling on or off the different system folder options including Settings, File Explorer, Documents and Downloads.

Showing which folders appear on Start next to the Power button As you can see below, we now have shortcuts for File Explorer, Downloads, Documents, and Settings right next to the Power button.

Removing apps from the Start menu If you want to remove apps from the Start menu, right-click on the Start menu icon and select Unpin from Start. This works for most items on the Start menu. As you might expect, the account and power icons cannot be removed.

You can easily unpin apps from the Start menu Creating a custom Start menu layout Like the taskbar, you can also create a completely custom Start menu layout that overrides the default Start menu. However, that requires editing and deploying XML and JSON documents which is beyond the scope of this article. You can learn more about creating a custom Start menu from the Microsoft docs at Customize the Windows 11 Start layout.

How to get a “classic” Start Menu experience Early versions of Windows 11 supported a registry hack that enabled you to display a version of the Start menu that was a lot like the Windows 10 Start menu. However, Microsoft disabled that registry hack last year with the Windows 11 build 22000.65.

Fortunately, there are several Windows 11 Start menu alternatives that you can install that will customize how the Windows 11 Start menu works. Here’s a quick look at The some of the main Windows 11 Start menu alternatives are:

Start11 Provided by Stardock, Start11 customizes both the Windows 11 Start menu and the taskbar. It allows you to move the taskbar as well as restore the taskbar context menu. It supports both Windows 7 and Windows 10 styles of Start menus as well as adding folders to the Start menu and many more customizations. It integrates with the other Stardock desktop products.

Stardock offers a classic and customizable Start Menu experience Start11 sells for $5.99 for 1 Active Install or for $14.99 you can get 5 Active Installs. You can try it free for 30 days.

StartAllBlack StartAllBlack allows you to move the taskbar and provides taskbar jump lists. It also provides Windows 7 and Windows 10 style Start menus.

StartAllBlack provides Windows 7 and Windows 10 style of Start menus You can buy a Personal Edition license for $4.99 per PC or two PCs for $8.99. There is a 30-day trial for StartAllBack. Multiple PC licensing options are available with the Business Edition.

Start Menu X Start Menu X is a Windows 11 Start menu alternative that does not customize the taskbar. However, it provides a flexible Virtual Groups feature that enables you to easily group your Start menu items together as well as collapse and expand the groups. The Start Menu X Start menu supports tab groupings, it can be moved anywhere on your desktop, and it can also be resized to fill your entire desktop.

There is a Freeware version of Start Menu X as well as a Pro version. The Freeware version is limited to five Virtual Groups and does not support one-click launch or tabs. The Pro version sells for $9.99 for a single PC or $7.99 for two or more.

Conclusion Even though the Windows 11 Start Menu and taskbar seem to offer fewer customization options compared to previous versions of Windows, it’s still quite easy to align the taskbar to the left and pin your favorite apps to it. The Windows 11 Start Menu, however, is quite a departure from the Windows 10 Start Menu and its live tiles, but again, it’s still quite easy to pin your favorite apps up there.

For Windows 11 users who really need more flexibility, there are already various third-party apps that can provide that today. Windows 11 also remains a work in progress and maybe we’ll see Microsoft improve its Start Menu and Taskbar in the coming months and years.

View Details

Cybersecurity researchers have discovered that the threat actors are testing new attack techniques to distribute malware. Indeed, the latest version of the highly sophisticated Emotet botnet uses PowerShell commands attached to the XLL files to target Windows PCs.

Emotet is an advanced Trojan that is primarily used to spread malware via phishing emails on compromised Windows systems. It was widely used as a backdoor to distribute ransomware before a global law enforcement operation shut down the servers in January 2021. The Emotet botnet reemerged in November with a massive email campaign aimed at thousands of customers worldwide.

According to the security researchers at Proofpoint, the attackers are now targeting compromised email accounts to send phishing emails. These emails contain catchy subject lines (such as Salary) that entice the recipient to click on them. However, the email body includes a OneDrive URL that hosts zip files with Microsoft Excel Add-in (XLL) files. Once the recipient clicks and runs the Emotet payload, the XLL files infect Windows machines with malware.

Emotet campaigns are moving away from VBA macros Unlike previous Emotet attacks, the latest campaign uses the XLL files containing PowerShell commands rather than Visual Basic for Applications (VBA) scripts. This change follows Microsoft’s announcement about its plans to block VBA macros by default across its products in April 2022. The Redmond giant says that this move should help protect customers from phishing attacks.

“After months of consistent activity, Emotet is switching things up. It is likely the threat actor is testing new behaviors on a small scale before delivering them to victims more broadly, or to distribute via new TTPs (Tactics, Techniques, and Procedures) alongside its existing high-volume campaigns,” explained Sherrod DeGrippo, VP of threat research and detection at Proofpoint.

Cybersecurity researchers have advised organizations to create awareness among employees regarding the new phishing techniques. It is also recommended that they should use simulated attacks and train employees in the cybersecurity domain.

View Details

Microsoft has released a new feature that allows users to switch between multiple personal and work accounts in Microsoft 365 web apps. The account switching capability began rolling out to all Microsoft 365 customers earlier this month, and it should become generally available in late June.

Previously, the only way to switch accounts was to sign out of one account and then log in with another account. This latest update eliminates the need to use separate Microsoft Edge profiles or InPrivate windows and should help to increase users’ productivity.

To try out this feature, users will need to click the account manager option available in the top-right corner of the Microsoft 365 web app. Now, users will be able to log in with a new account or switch to a different account previously signed into the browser. Once done, the webpage will automatically research to show the content from the new account.

Microsoft has also detailed a few limitations of the account switching feature. Currently, it is impossible to run two or more active Microsoft 365 apps with different simultaneously in the same browser instance. For example, if a user has two browser tabs open with work and personal accounts, the app will prompt them to refresh the inactive tab.

Account switching support coming to more Microsoft 365 web apps The firm ensures that it will maintain user data integrity and privacy across work/school accounts and organizations. “Security and privacy are extremely important for both Microsoft and our customers, and this feature maintains data integrity and privacy across different account and organization boundaries. In other words, each account will continue to only have access to the data they have permissions for,” Microsoft explained.

The account switching feature is currently supported in Outlook on the web, Word, Excel, OneDrive for the web, PowerPoint for the web, Office.com, SharePoint, and the Microsoft 365 admin center. Meanwhile, Microsoft is actively working on expanding its support to more Microsoft 365 web apps, though there’s currently no ETA.

View Details

Microsoft has announced a new partnership with Red Button, an Israel-based Distributed Denial-of-Service (DDoS) attack simulation testing solutions provider. The Redmond giant believes that this collaboration will enable organizations to identify gaps and develop effective strategies to mitigate DDoS attacks.

“With Red Button’s DDoS Testing service suite, you will be able to work with a dedicated team of experts to simulate real-world DDoS attack scenarios in a controlled environment. Simulation testing allows you to assess your current state of readiness, identify gaps in your incident response procedures, and guide you in developing a proper DDoS response strategy,” explained Alethea Toh, Product Manager for Azure Networking.

Microsoft says that Red Button’s DDoS Testing suite consists of three different stages. As part of the planning process, Red Button experts analyze the network architecture, identify test scope and targets for DDoS attacks, and establish test schedules.

The second step involves launching DDoS attacks against the client’s Azure services. Finally, the Red Button team delivers a detailed report summarizing the test results, vulnerabilities, and recommendations.

Red Button also provides two additional service suites for Azure DDoS Protection customers. First up, there is an annual service called “DDoS 360” that provides various capabilities such as testing, hardening, skills development, as well as incident response.

DDoS Incident Response is another service that offers a 30-day incident response plan. This service is designed to help organizations analyze the attacks and apply mitigations. Moreover, the Red Button also conducts training sessions to create awareness among employees regarding DDoS attacks.

Red Button is an approved DDoS testing partner for AWS It is important to note that Red Button is also an approved DDoS testing partner for Amazon Web Services (AWS). Microsoft reports that DDoS attacks are on the rise as attackers are using powerful techniques to target gaming services, financial services, and media organizations. Earlier this year, the Redmond giant unveiled that it mitigated 359,713 unique DDoS attacks against its services in the second half of 2021.

Microsoft Azure already offers built-in Azure DDoS protection services, but this new partnership should provide independent testing and validation services to help organizations adhere to security compliance requirements. We invite you to check out this support page to learn more about Azure DDoS Protection simulation testing partners and policy.

View Details

Atlassian has released new security patches for its Jira and Jira Service Management solutions. The latest set of updates aims to address a critical vulnerability that could let attackers to bypass authentication controls.

According to Atlassian’s security advisory, the bug was first discovered by Khoadha of Viettel Cyber Security. Tracked as CVE-2022-0540 and issued a CVSS score of 9.9, the security flaw resides in Jira’s authentication framework called Jira Seraph.

For those unfamiliar, Seraph is a Servlet security framework that is used in J2EE web applications. It offers various security tools that help IT admins protect their Jira installations from cyber attacks. In Jira and Confluence, Seraph uses some pluggable core elements to handle all authentication requests.

“A remote, unauthenticated attacker could exploit this by sending a specially crafted HTTP request to bypass authentication and authorization requirements in WebWork actions using an affected configuration,” the company explained.

Atlassian confirmed that the CVE-2022-0540 vulnerability affects several products such as Jira Core Server, Software Server, Software Data Center, the Service Management Server, and the Management Data Center. However, the security flaw doesn’t impact the cloud-based Jira and Jira Service Management products.

Here’s the full list of versions affected by the CVE-2022-0540 vulnerability:

  • Jira Core Server, Software Server, and Software Data Center prior to versions 8.13.18, the 8.14.x, 8.15.x, 8.16.x, 8.17.x, 8.18.x, 8.19.x, 8.20.x before 8.20.6, and 8.21.x.
  • Jira Service Management Server and Management Data Center prior to versions 4.13.18, 4.14.x, 4.15.x, 4.16.x, 4.17.x, 4.18.x, 4.19.x, 4.20.x before 4.20.6, and 4.21.x.

The Jira authentication bypass vulnerability affects over 200 Atlassian marketplace apps In addition to these Jira products, Atlassian noted that the security flaw affects its Mobile Plugin for Jira and Insight – Asset Management applications. Moreover, the vulnerability impacts more than 200 apps available on the Atlassian marketplace.

Atlassian advises customers to upgrade to the latest version of Jira or Jira Service Management to mitigate potential security attacks. However, users who can’t install the security patches can simply update the vulnerable apps to a fixed version or disable them altogether.

View Details

Apple is phasing out its macOS Server application that was first released back in 2011. Indeed, the company has announced in a support document that macOS Server is discontinued as of April 21, 2022 (via MacRumors).

According to Apple, all existing customers can still continue to download and use the app on the latest macOS Monterey. However, the company added that various server features from the app have already made their way into recent macOS versions.

“The most popular server features—Caching Server, File Sharing Server, and Time Machine Server are bundled with every installation of macOS High Sierra and later, so that even more customers have access to these essential services at no extra cost,” Apple explained.

The discontinuation of macOS Server shouldn’t be surprising because Apple has gradually deprecated many functionalities over the past few years. The list includes Dynamic Host Configuration Protocol (DHCP), Domain Name System (DNS), Virtual Private Network (VPN), messages, the Wiki, a mail server, NetInstall, AirPort management, as well as contact and calendar support.

It is important to note that this change was a part of Apple’s efforts to shift its focus towards consumer products such as Macs and iPads. The company also indicated its lack of interest in the server business by killing off the Xserve family of rack servers in 2010.

Apple advises macOS Server customers to migrate from Profile Manager Apple recommends users to switch from Profile Manager to third-party alternatives such as Microsoft’s Active Directory (AD). The company has also provided support documents to help organizations migrate to other mobile device management (MDM) solutions.

Do you still use macOS Server for managing Macs and iOS devices in your organization? Let us know in the comments down below.

View Details

Git Bash is a terminal emulator shell and limited Linux-like environment for Windows that lets you run Git commands. Learn how to use the app in this detailed guide.

What is Git Bash? Git Bash is a software tool for Windows. It runs Git commands using an emulation layer. Bash is a command-line shell for Nix operating systems. Git Bash installs Bash, some bash utilities, and Git on Windows.

The app also lets you connect to remote Git repositories such as GitLab or GitHub, and run hundreds of Git commands like git clone, git config, etc. Although the app allows you to run all Git-related commands, it’s also a Linux terminal that can run any standard Unix commands.

What can you do with Git Bash on Windows? Now that you have a basic idea of what Git Bash is, it’s also important to understand everything you can do with it.

The app allows you to execute Linux commands, and run shell scripts, and it also allows you to navigate to text files and directories using the ls (list files) or cd (change directory) commands, or edit files using the vim command.

For example: cd /usr/bin changes the working directory to the bin directory.

The app also allows you to connect to Git repositories and manage them.

How to download and install Git Bash You can download and install the app by following these simple steps.

  • Download Git-2.31.0-64-bit.exe from the Git website.
  • Double click the downloaded executable.
  • In the dialog box, click Yes.
  • Click Next again and select the default settings until you see the Git 2.31 Setup wizard screen, as shown below.

Next, select the location on your system where you would like to store the Git installation files.

Now, tick the checkbox Additional icons -> On the desktop to make it easier to access the app in the future. Also, you can set up the integration with the File Explorer here.

Add a desktop shortcut and enable the Windows Explorer integration Next, on the Adjusting your PATH environment screen, select the Git from the command line and also from 3rd party software option.

Next, when you need to choose the SSH executable, select OpenSSH. This will allow you to work with Secure Shell (SSH) connections, like when you log into a Linux machine.

Select OpenSSH as the SSH executable Finally, select Use MinTTy, select the default terminal MSYS2, which the app will use as a terminal emulator. After clicking Next, the app will start.

How to use Git Bash on Windows Now let’s open Git Bash and use it. First, navigate to the path where you installed app and click on the .exe file. You can also search for the app in the Windows Start menu.

By default, the background color of the app is black, but if you wish to change any configuration settings, you can do it anytime by right-clicking on the toolbar at the top of the terminal window and navigating to the Options screen.

After you navigate to Options, you will see a lot of configuration settings that you can change according to your preferences.

As you can see below, we’ve changed the text size and the background color has turned to dark blue.

Using Unix commands If you want to execute a shell script on Windows or any Unix command, then you can run them in the app as it works like the Windows command-line shell. Let’s execute some Unix commands as shown below.

As you can see below, I created a folder using the Unix command mkdir and later verified it using the ls and grep commands.

``` mkdir Folder

ls Folder | grep Folder ```

Similarly, if you run the echo command, it prints the output in the terminal, as shown below.

echo "Hello"

Popular Git commands Git Bash is used for running Git commands, so let’s get familiar with some of the most important ones.

  • Open the app.
  • Next, run the git init command to initialize your new repository, as shown below.

git init

  • Next, create a file inside the same directory using the echo command. This command will create the file and add data into it.

echo "My first change" > adding-new-file.txt

  • Now, check the status of the Git repository using the git status command.

git status

  • Now add the file to the Git repository using the git add command below.

git add

  • Again check the status of the git repository, and you should see the file has been added to the local repository.

git status

  • To commit your changes in the Git repository, run the git commit command below.

git commit -m "MY FIRST COMMIT"

Using Git commands in the Command Prompt Did you know that running Git commands is possible in the Windows command prompt as well? The command prompt allows you to execute any Git command such as git init, git commit, etc. This will still require you to install Git Bash for Windows.

As you can see below, the git status command has been executed in the command prompt successfully.

Conclusion Git Bash is a free tool with a whole lot of features. With this guide, you learned how to install and use the app on Windows. Also, you learned how to connect to a Git repository manage it with various other commands.

Now that you have a good idea of what the app can do, which commands do you plan to execute with it?


View Details

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory about ongoing cyberattacks against internet-connected uninterruptible power supply (UPS) devices. The US government encourages organizations to change their default user name and password settings to prevent hackers from targeting UPS devices.

An uninterruptible power supply (UPS) is a device that allows computer systems and IT equipment to keep running during a power outage. Many UPS devices can connect to the internet which enables enterprise admins to carry out monitoring and maintenance activities.

However, these internet-connected UPS units are also susceptible to cyber-attacks, disrupting the power supply in mission-critical environments, such as data centers and server rooms.

“CISA and the Department of Energy (DOE) are aware of threat actors gaining access to a variety of internet-connected uninterruptable power supply (UPS) devices, often through unchanged default usernames and passwords. Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet,” the federal agencies explained in the security advisory.

CISA provides remediation steps to block attacks against Internet-connected UPS devices CISA has advised IT Admins to ensure that all UPS devices in their organization are not accessible via the internet. Nevertheless, the agencies understand that sometimes this is not possible and have also made some recommendations in this regard. These organizations should enforce multi-factor authentication, hide UPS devices behind virtual private networks (VPNs), and implement login timeout/lockout policies.

Moreover, CISA also urges enterprise customers to ensure that the UPS credentials adhere to strong password-length requirements. “This ensures that going forward, threat actors cannot use their knowledge of default passwords to access your UPS,” CISA said yesterday.

It is important to note that these cyberattacks don’t necessarily allow hackers to steal sensitive data or information. However, it is important to protect UPS devices because such attacks could potentially cause physical damage or alter the firmware of the UPS to gain control over the targetted network remotely.

View Details

Microsoft has announced a revamped version of Azure Front Door, its secure cloud content delivery network (CDN) service for protecting apps and websites. The new enterprise CDN service provides higher availability, improved security, low latency, as well as scalability to help meet the demands of the hybrid working models.

The Azure Front Door service comes with two Standard and Premium tiers, and it will replace the older Azure Front Door and Azure Content Delivery Network (CDN) products.

“Today, we are announcing the general availability of the new Azure Front Door, our native, modern cloud content delivery network (CDN) catering to both dynamic and static content acceleration with built-in turnkey security, and a simple and predictable pricing model,” the company explained.

Microsoft highlights that the new version of Azure Front Door brings improvements in three key areas. First up, the service is built on modern architecture with enhanced automation, rules engine, manageability, as well as simplified provisioning. It also adds improved analytics capabilities like a health probe diagnostic log, making it easier for IT Admins to monitor, troubleshoot, and debug issues.

In addition to the modern architecture, the Redmond giant emphasized that the new Azure Front Door service utilizes over “118 edge locations across 100 metro cities” via its private Wide Area Network (WAN). The service comes with a simplified cost model and aims to ensure the unified delivery of static and dynamic content.

Lastly, Microsoft has also introduced new “intelligent” security features in Azure Front Door. The list includes support for Azure Web Application Firewall (WAF) and Azure Private Link. It also offers protection against malicious bots and distributed denial-of-service (DDoS) attacks. However, these security capabilities are only available for Premium customers.

Azure Front Door pricing details As for the pricing, the Azure Front Door Standard edition will cost users $35 /month and the Azure Front Door Premium plan is priced at $330 /month. According to Microsoft’s pricing page, the base fee is currently listed at a 50 percent discounted price, and the new GA pricing changes will go live on May 1, 2022.

Going forward, the existing Azure Front Door and Azure CDN products will not receive any new features and will be rebranded as “Classic” services. Meanwhile, the company plans to add support for “zero downtime migrations” to help users migrate from legacy products to the new Azure Front Door service later this year.

View Details

Do you often look for the easiest way to take a screenshot on your PC? Screenshots can be extremely helpful if you want to share what you are seeing on your screen with others, or to keep something for reference later.

Here are ten easy-to-use ways to take a screenshot on your Windows devices.

Keyboard shortcuts for taking screenshots There are three main methods for taking screenshots using keyboard shortcuts on Windows. For all of them, you’ll need to be familiar with the Print Screen key, the Windows key, and the Alt key on your keyboard.

For those unfamiliar, the PrtScn key is usually in the upper right corner of your keyboard. The Windows key is in the lower-left corner, while the Alt key is right next to the Windows key.

Here are the keyboard keys you need to use to take screenshots Here are three different ways to take screenshots using your keyboard.

  1. Print Screen You can press the Print Screen (the PrtScn key) to capture a full-screen screenshot, including the taskbar on your screen. It will send the image automatically to the Windows clipboard. On laptops, you may have to hold the Function (Fn) key while pressing the PrtScn to capture a screenshot.

Once your screenshot is on the clipboard, you can open it with Microsoft Paint or any other image editing software to edit and save it. If you need a quick screenshot, Print Screen is a really straightforward option.

  1. Win + Print Screen The Win + PrtScn option also captures your entire screen, the only difference is that it saves the screenshot as an image file. You can access the saved file in the subfolder ‘Screenshots’ in the Pictures folder of your PC.

The Screenshots folder in the Pictures folder of your PC 3. Alt + Print Screen The Alt + PrtScn keyboard shortcut is used for capturing a screenshot of your active window. Therefore, you should highlight the preferred window, by clicking anywhere in it, before taking the screenshot.

Just like screenshots captured by the PrtScn shortcut, using Alt + PrtScn will send the screenshot directly to the clipboard instead of saving the image as a file.

  1. The new Snipping tool Microsoft’s new Snipping Tool, previously known as Snip & Sketch, is a utility that lets you easily take screenshots of an entire screen or selected areas of an open window.

You can find the new Snipping Tool either in the list of installed apps on the Start menu or open it by pressing Win + Shift + S on your keyboard. You can also pin this tool to your taskbar for quick access.

When you click + New in the Snipping Tool, you can choose the area of the screen that you want to snip. Or if you opened the tool using the keyboard shortcut, you can go ahead and select an area straightaway.

You can choose different types of snips including rectangular, freeform, window, or the full screen snip to capture the image the way you want.

The Snipping Tool also allows you to customize the captured screenshot using touch writing, the pen, highlighter, eraser, and other tools available in the top center of your screen. After customizing the screenshot, you can save it as a file.

The new Snipping Tool on Windows 11 5. The legacy Snipping Tool The legacy Snipping Tool is a free utility for capturing screenshots on Windows 10, 8, 7, and Windows Vista. Like the modern Snipping Tool mentioned above, it can capture different types of screenshots.

To open the Snipping Tool on Windows 10 and Windows 7, go to the Start menu, type Snipping Tool in the search area, and select the tool from the list. You can also open it in Windows 10 by pressing Win + Shift + S.

On Windows 8, you can swipe in from the right corner of the screen to access the search box, type Snipping Tool, and select it from the results.

Once the Snipping Tool is open, you can choose Mode to select the type of snip. Select from free-form snip, rectangular, window, and full-screen snip. The Snipping Tool also allows you to capture a specific moment from a video or animation by setting up a one to five-second delay.

After capturing the screenshot, you can edit or annotate it by using the pen, highlighter, or eraser. Once you’re done with editing, you can save the screenshot by selecting the Save As option from the File menu, then you can choose the file format and add the file name and location. Finally, save the screenshot by clicking the Save button.

The legacy Snipping Tool 6. Xbox Game Bar The Xbox Game Bar is an inbox app on Windows 10 and Windows 11 which allows you to take a screenshot while playing a game or using other apps. You can access the Game bar by pressing the Windows key + G.

The Game Bar will appear as an overlay, and you can press the Camera Icon from the Widget Menu to capture the screenshot or use the Win + Alt + PrtScn keyboard shortcut. Once you’re done, you can find this screenshot as a PNG file in the Capture section of the Widget Menu.

The Xbox Game Bar can be used to take screenshots 7. Power Button + Volume Up on Surface devices Most of Microsoft’s Surface devices allow users to take screenshots without using the keyboard. You can take screenshots on Surface devices by pressing and holding the Power button together with the Volume Up button, a key combination that many smartphones and tablets also use for taking screenshots.

While pressing these keys, the screen will first dim for a couple of seconds, then you can release the buttons to capture a screenshot. The image will be automatically saved to the Screenshots folder in the Pictures folder.

Use hardware buttons to take screenshots on Surface devices Third-party Windows applications for taking screenshots If the methods above are not enough, some third-party apps also provide a range of features to improve the effectiveness of your screenshots. Here are some of the most interesting third-party tools.

  1. TechSmith SnagIt TechSmith SnagIt is a paid app providing advanced editing options and effects when taking screenshots. After opening the app, you can use the red color Capture button to see the different options for taking a screenshot.

Three options are available: All-in-one, Image, and Video. You’ll need to choose the Image option, select the capture mode that you want to capture from the Region section, and click the Capture button to take a screenshot.

The different capture options with SnagIt 9. Greenshot Greenshot is a free screenshot capturing tool for Windows and macOS. The app lets you quickly capture a screenshot, and it also lets you take a screenshot of an entire web page by scrolling down.

You don’t need to open Greenshot manually as the app will start running in the background by default right after installing. Different capture modes are available:

  • Capture region (PrtScn Key): Click and hold down the left button on your mouse to define the area that you want to capture, then release the mouse button.
  • Capture window (Alt + Print Screen): This lets you take a screenshot of an app window.
  • Capture full-screen (Ctrl + PrtScn): This option allows you to capture the entire screen.
  • Capture web page (Ctrl + Shift + PrtScn): You can use this when you need to capture an entire web page.

The different capture options with Greenshot Greenshot also enables you to edit screenshots by using its image editor, and you can save the file when you’re done by choosing Screenshot Destination.

  1. PicPick Being one of the best freemium screen capture tools developed by NGWIN, PicPick encompasses a range of features including seven different capture modes, a pixel ruler to measure the size of the screenshot, image editing tools, and more.

To capture the screen with PicPick, right-click the PicPick icon and select the Screen Capture option. At this moment, you can choose your output type or capture mode from a list that includes full-screen, active window, scrolling window, region, freehand, and more.

After taking the screenshot, you can edit the image with the PicPick Editor and save, share, or upload the image anywhere you want.

The different capture options with PicPick 11. ShareX ShareX is a free screenshot app widely used by gamers as it supports video captures and various workflows, along with a huge number of filters and effects to edit your screenshots.

To capture a screenshot on ShareX, open the app and select Capture, then you can choose the capture mode. The app also lets you set up a delay or choose how many scrolls of a window you want to capture. Once you’re done taking a screenshot, you can save, share, or upload it to a remote sharing service.

The different capture options with ShareX That’s it for these ten different ways to take a screenshot on a Windows PC, including an additional button combination if you’re using a Surface device. Taking screenshots is a great way to keep track of different things, and we hope the different options covered in this guide will help you to improve your workflow.

View Details

In today’s DevOps era, most organizations use hundreds of different services. Monitoring all of these is crucial for keeping your systems running without any issues. And one of the most widely used service monitoring tools is Grafana.

In this ultimate guide, we will give you a complete overview of Grafana, so let’s get started!

What is Grafana? Grafana is an open-source tool that allows you to query, visualize, analyze, and receive alerts on metrics and logs, no matter where they are stored. It also allows you to query data and it supports dozens of visualizations.

Grafana comes with rich support for many databases like Graphite, Prometheus, Elasticsearch, and Influx DB. And it supports various cloud monitoring solutions such as Amazon Cloud Watch, Microsoft Azure, SQL, Postgres, and MySQL databases.

See what a Grafana Dashboard looks like and all the features it has.

What is Grafana used for? Although Grafana provides lots of features on its dashboard, the main use of Grafana is to collect data from various data sources and then visualize the data. It can also notify you of issues once you have configured alerting.

Collecting data Grafana collects data from various sources, which you will learn about later in the guide. Grafana uses APIs to collect data. As an example, the GET /api/datasources API is used to collect data.

Visualizing data When it comes to visualization, nothing can beat Grafana. It provides dozens of visualizations in various formats such as tables, bar charts, and many more. We’ll discuss the most important visualizations later in this guide.

Grafana dashboard features and functions Grafana provides hundreds of useful functions to build a strong monitoring dashboard. Let’s jump into this interesting section and look at the great features and functions that Grafana provides.

  • The Grafana dashboard has a variety of features, and one of them is annotations. With annotations, you can easily mark points to add information accordingly.

Using annotations in Grafana * The dashboard provides a great way to structure your folders and subfolders. You can store data according to teams or projects. Also, you can create folders, move, and delete dashboards inside folders, etc.

Using folders in Grafana * At the top of Grafana, there is a search box where you can specify the dashboard’s name. And as you specify a name, you will see the list of dashboards with identical names. * Grafana provides dozens of ways to manage the time ranges of the data you want to view, as well as alerts based on seconds, minutes, hours, weeks, days, years, etc. * One of the coolest features in Grafana is the ability to import dashboards in JSON format from public repositories.

Grafana Installation options You can set up Grafana in two ways:

  1. Either by hosting it on your own device
  2. Or using the Grafana cloud service

Grafana is supported on various platforms and it is easy to set up. Grafana can be installed on Debian or Ubuntu, RPM-based Linux (CentOS, Fedora, OpenSuse, RedHat), macOS, and Windows.

Nowadays, applications are deployed mostly using container orchestration tools such as Kubernetes. And similarly, you can deploy Grafana on Kubernetes.

To test Grafana on the machine where it’s installed, use the curl localhost:3000 command. Also, admin is the default username and password.

Grafana Cloud Grafana Cloud provides a simple way to get up and running quickly with high availability, all without the need to manage the underlying infrastructure. Grafana Cloud is a SaaS-based service that is highly available, load-balanced, and fault-tolerant, allowing customers to log and visualize metrics.

With Grafana Cloud, you can quickly monitor applications without worrying about the infrastructure. Grafana Cloud also reduces management complexity compared to self-hosting Grafana without restricting choice or control.

If you wish to monitor your application with Grafana Cloud, get started with a free account. It allows you to access 10k metrics, 50GB logs, 50GB traces, two weeks of data retention, and three users.

What does Grafana Enterprise offer? Grafana Enterprise is the commercial edition of Grafana. It comes with some additional features not available in the free open-source version. Grafana Enterprise includes authentication options such as GitLab OAuth, Azure AD OAuth, LDAP, Okta, and SAML.

Also, Grafana Enterprise includes integrations such as Kibana, AppDynamics, DataDog, Dynatrace, Gitlab, Honeycomb, Jira, MongoDB, New Relic, Salesforce, etc.

To install and set up Grafana Enterprise, you will need a trial license, for which you will need to connect with the Grafana Labs Sales Team.

Grafana alerting When it comes to alerting, Grafana provides a robust and effective solution. Within the Grafana dashboard, you can create rules-based alerts using specific thresholds, and then send alerts to customers based on frequency. Also, you can set a notification policy.

Notifications in Grafana are sent using a messaging template based on the Go templating system, where some fields are evaluated as text while others are evaluated as HTML. Grafana also integrates well with Slack.

With the latest version of Grafana, you can set up alerts based on multiple data sources, such as queries in Prometheus and MySQL. I.e., Grafana lets you aggregate data from multiple sources. Also, the latest version of the product has centralized alerting on a single page.

Types of data sources in Grafana Grafana supports various data sources such as:

  • Alertmanager,
  • AWS CloudWatch
  • Azure Monitor
  • Elasticsearch
  • Google Cloud Monitoring
  • Graphite
  • InfluxDB
  • Microsoft SQL Server (MSSQL)
  • OpenTSDB
  • PostgreSQL
  • Prometheus
  • Jaeger
  • and Test data that you define in the dashboard.

Once you define a data source, you will need to provide specific settings, such as the URL of the data source, and credentials to access it.

Defining a data source is easy. Just go to the Grafana Dashboard→ Settings button → Data sources, as shown below.

Adding data sources Grafana plugins Grafana supports a handful of plugins. Some of the most widely used plugins are for Influx DB, Prometheus, Pie chart, Stack driver, Tempo, Jaeger, Loki, and Logs.

If you want to build your own Grafana plugin, then you can use the Grafana Toolkit.

To view all plugins installed in Grafana, go to Settings → Plugins, as shown below.

Accessing plugins in Grafana Grafana API and libraries There are hundreds of APIs that use their own libraries for management, configuring or setting up Grafana, adding data sources to Panels, etc.

Some of the most important APIs that Grafana uses are listed below:

  • Data API Library: work with various data types in Grafana. For example, this library has one function called SortedVector, which returns numbers in a sequence.
  • e2e Library: used to execute end-to-end tests.
  • UI Library: contains the different design components for the Grafana ecosystem.

Types of data visualization in Grafana Now you know how useful Grafana is for monitoring and visualization, you might be wondering what Grafana dashboard visualizations look like.

There are many visualizations that Grafana supports:

  • Time series is the default and main graph visualization.
  • Bar chart shows data based on categories.
  • The histogram shows value distribution in a bar chart.
  • Heatmap visualizes data in two dimensions. Stat, Gauge, and Bar gauge are used to check the data in number format.

Summary Grafana is a free tool with a whole lot of features. In this guide, we covered what’s possible with this feature-rich tool. From monitoring interfaces for various data sources, executing queries, and supporting dozens of visualizations, Grafana can do a lot.

Now that you have a good idea about what Grafana does, what do you plan to monitor with it?

View Details

Microsoft has released a new gradual rollouts feature for its Windows Update for Business deployment service. This new capability was first announced in November 2021, and it aims to ensure a smoother feature update experience for organizations with specific software and hardware compatibility issues.

For those unfamiliar, Windows Update for Business was introduced in March 2021. It is designed to provide IT administrators with greater control over the approval and scheduling of Windows updates. It works with PowerShell, Microsoft Graph APIs, and Microsoft Endpoint Manager.

With this new gradual rollouts feature, enterprise Admins can now use a machine learning-based approach to automatically determine which Windows 10 or Windows 11 PCs should receive the latest feature update.

“The deployment service enables you to successfully update your entire population of Windows PCs or devices and limit the impact of potential issues through gradual rollouts. It does so by intelligently ordering devices to be updated in waves, where every wave is designed to help you discover incompatibilities and implement solutions with the fewest devices and users affected,” the company explained in a blog post.

How to configure a gradual rollout policy in Microsoft Intune To get started with the gradual rollouts feature, IT Admins will first need to set up and configure the AllowWUfBCloudProcessing policy in their tenant by following these steps:

  1. First of all, head to the Microsoft Endpoint Manager admin center and navigate to Devices > Configuration profiles > Create profile.
  2. Select the “Windows 10 and later platform and then set Profile type as “Settings catalog (preview)” under Profile type.
  3. Select the “Add settings” option on the Configuration settings page. Now, enable the “Allow WUfB Cloud Processing” setting available under the System category section.
  4. Finally, assign the profile to the specific group on the Assignments page and then complete and Create this settings catalog profile, to deploy the newly created profile.

With the profile configuration profile deployed, any Windows 10 or 11 device that uses the gradual rollout option in Feature update profiles will now be eligible for intelligent rollout optimizations.

Notably, Windows Update for Business is only available for organizations with an active Windows 10/11 Enterprise E3 or greater subscription. If you’re interested, you can learn more details about this new deployment service on this support page.

View Details

Microsoft has announced its plans to launch Office 365 Government Secret, a new cloud offering for government agencies and their partners. The company says that this new security offering is currently in government review, and it’s expected to become generally available in mid-2022.

Microsoft highlighted that the Office 365 Government Secret cloud service is built on its Azure Government classified environments. This service supports Impact Level 6 (IL6), and it’s designed for the US government agencies who need to manage secret classified data.

The goal is to modernize the existing legacy infrastructure to meet data management demands of the Department of Defense (DoD), US Federal Civilian, Intelligence Community (IC), as well as other US government partners that deal with Secret-classified information.

“This new environment will run the latest enterprise-grade Office 365 Government productivity, security, compliance, and collaboration applications. We have a comprehensive approach to build, test, onboard, and audit our products to be compliant with government regulations, which will help ensure security and compliance for the environments. We work to drive efficiencies internally and with government regulatory bodies to help improve the timeliness of products to market,” explained Paul Lorimer, CVP for Office 365 Enterprise and Cloud Engineering.

Office 365 Government Secret joins the existing family of Azure clouds It is important to note that this new service joins the existing family of Azure clouds available to US government customers, including Azure Government Secret and Top secret clouds. These services are designed to help users with text translation, human and signals intelligence, computer vision, metadata and text extraction, optical character recognition (OCR), and much more.

Microsoft added that customers interested in Office 365 for Government Secret can reach out to its onboarding teams to arrange for deployment and remediation activities. It should make it easier for IT Admins to ensure that all transition challenges are addressed ahead of a broader rollout later this year. We invite you to check out Microsoft’s official blog post for more details.

View Details

Security researchers have uncovered five critical vulnerabilities in Microsoft Azure Defender for IoT. The Redmond giant has already released new security patches to address these exploits, and it recommends all enterprise customers to install them as soon as possible.

According to a report from SentinelOne‘s SentinelLabs, these security vulnerabilities were first discovered by researchers Kasif Dekel and Ronen Shustin. The cyber security company explained that the flaws could potentially allow attackers to exploit certain weaknesses in Azure’s password reset mechanism to remotely gain unauthorized access to targeted machines.

SentinelLabs says that the security vulnerabilities, tracked as CVE-2021-42310, CVE-2021-42312, CVE-2021-37222, CVE-2021-42313, as well as CVE-2021-42311, affect both on-premises and cloud customers. Security researchers awarded the flaws a “high” severity score and privately reported it to Microsoft back in June 2021.

“Successful attack may lead to full network compromise, since Azure Defender For IoT is configured to have a TAP (Terminal Access Point) on the network traffic. Access to sensitive information on the network could open a number of sophisticated attacking scenarios that could be difficult or impossible to detect,” SentinelLabs explained in its security advisory.

Microsoft Defender for IoT (formerly known as Azure Defender for IoT) is a unified security solution that helps enterprise customers to secure their IoT/OT environments. It offers a wide range of capabilities such as IoT/OT asset discovery, automated threat detection as well as vulnerability management.

Microsoft releases security updates to patch Azure Defender for IoT vulnerabilities Fortunately, Microsoft has implemented its own fix to patch the aforementioned security issues, and the company advises customers “to take action immediately.” Moreover, SentinelLabs claims there is no evidence that these flaws have been exploited by threat actors.

“Security vulnerabilities are serious issues we all face and that is why we partner with the industry and follow the Coordinated Vulnerability Disclosure (CVD) process to protect customers before vulnerabilities are public. We addressed the specific issues mentioned and we appreciate the finder working with us to ensure customers remain safe,” a Microsoft spokesperson said in a statement to VentureBeat.

SentinelLabs added that the findings of this research study raise serious concerns regarding the security solutions as well as their impact on the security posture of sectors vulnerable to cyber attacks. As a security measure, it encourages customers to apply a “defense-in-depth approach” to block potential internal or external threats.

View Details

In this guide, we’re going to explain the differences between static and dynamic IP addresses. Both types of Internet Protocol (IP) addresses have pros and cons, and we’ll help you to understand which one is best suited to your needs.

But first of all, here’s a bit of geeky humor to get started: “There’s no place like 127.0.0.1.” If you can get that joke, you might have a lot of this article understood already.

IP addresses have been around for almost 40 years. Since the first Internet protocol was used in ARPANET, which was a predecessor to the modern-day Internet. We’ve seen IP addresses using the Internet Protocol v4 (IPv4) become exhausted. And the creation of Internet Protocol v6 (IPv6) coming into its own in recent years.

IP networking is likely always going to be something IT Pros need to understand. However, the world is changing. The likelihood of our grandchildren needing to worry about subnets is unlikely, with the release of IPv6 and its massive amount of usable IP Addresses, which totals 340 trillion trillion trillion unique addresses. That is a much more than the 4,294,967,296 that IPv4 provides.

The key thing here is to realize that with a traditional IPv4 network, IP address can be assigned to a host dynamically when it is added to your network. Otherwise, a host is assigned a persistent address through the configuration of the hardware or software on the network.

What is a static IP address? A static IP address is also known as a persistent IP address. Often, we assign this static IP address to the host and the device will use it until the device is removed from the network. Otherwise, when the network undergoes some changes, the device will need to have a new static IP address assigned to it.

Another reason we may have a static IP address is if we want to have one assigned to our business or home network from our Internet Service Provider (ISP). By having a static IP, we can enable Domain Naming System (DNS) to point external services, such as websites or line of business applications, to the address without worrying about it having to change.

Some key reasons why static IP addresses are useful are because of the following:

  • Hosting a website: If you want to send everyone back to the same location without having to provide a third-party solution such as DynDNS, you’ll need a static IP address.
  • Running Security Cameras: If you want to be able to remotely access a closed-circuit television (CCTV) / security camera, this normally requires a static IP address.
  • Voice over Internet Protocol (VoIP): Older VoIP systems required you to have a static IP address. This has become less apparent with the use of Microsoft Teams, Zoom, or Webex. However, what we often see is that the reliability of these solutions is improved when using a static IP address.

These are all positives, but what about the disadvantages of having a static IP address? Here are some examples:

  • Attacks:Static IP addresses are far more likely to be vulnerable to hacking and data trafficking attacks. I once had a VMWare ESX host directly attached to the internet as a honey pot machine and I had nearly 4 billion attempts at someone trying to log onto it – this would have been less likely had I had a dynamic address from my ISP.
  • Cost: There is a cost attributed to an IP address that is static as there is a finite amount of the 4 billion addresses left. Where there is a lack of supply and an increase in demand there is a value attributed to it.

What is a dynamic IP address? Dynamic IP addresses are assigned to the host system. The address can change, or it could ultimately become sticky, which we will talk about in a moment.

Because of the limitations of IPv4 addresses outlined above, IT pros need to adapt to how their internal networks operate. For example, if we were to run a business or a home network, our Internet provider could give us a single IP or a small range of IP addresses, which would be used sparingly. Internally, we could have hundreds, if not thousands of IP addresses being assigned to hosts.

IP addresses are assigned dynamically using something called Dynamic Host Configuration Protocol, or DHCP. The perks of using a DHCP server is that it removes the requirement of manually assigning a new IP address to every single item which joins your network. It also ensures that the IP address assigned to everything on your network is only assigned for a period.

For example, your son’s friend who stopped off last week and joined their phone to your home’s broadband network was assigned an IP address, and for a period that IP address is allocated to the phone. However, after a determined period, that IP address that was assigned to the phone will be reallocated to the DHCP pool of IP addresses, and it can be reassigned to the next host that requires it. By default, with most modern equipment, dynamic IP configuration is the norm.

“Sticky” IP addresses are an informal way of saying that a dynamic IP address very rarely changes. We may have a piece of equipment that is always on our home network such as a doorbell, a CCTV camera, or any smart item that never leaves the confines of your home network – this device will be assigned a dynamic IP address.

However, when it comes to renewing the address, the host and the DHCP server will likely agree on the same IP address. In doing so, the IP address will become “sticky,” as it never changes unless something else does.

It’s a bit like the first law of motion with physics – An object will remain at rest or in a uniform state of motion unless that state is changed by an external force. A dynamic IP address works the same: It will remain unless it is impacted by an external force.

Can a static IP address change? The rule of thumb is that anything can change. However, it’s unlikely that you would change a static IP address unless there is a good technical reason to do so.

A common reason you might want to change a static IP address is your constant level of attacks to an external static IP address. If you’ve made the decision that moving from one IP address to another is going to occur, yes, this is technically possible.

However, it does mean that you will need to update your DNS records, which will affect any items hard-wired to use the old IP address – it’s not a small undertaking.

Can a dynamic IP address change? Dynamic IP addresses are meant to change. As the pool of IP addresses is used by the hosts that require them, when these dynamic IP addresses are no longer needed, they are returned to the pool.

You can think of this as a public library – when you need to add yourself to your network you ‘check out’ the IP address book. When you’re finished, you return it to the ‘librarian’ who puts the IP address book back on the shelf.

When to use static IP addresses You should use a static IP address when you consistently want to get back to the same location. An example of this would be a server being hosted on my local network. This could be something like a website, intranet, email server – most servers are assigned a static IP address.

Is a static IP address less secure? Using static IP addresses outside your local network can raise a security risk as they make you easier to find. If you are always using the same address and someone wanted to find you, it’s easier with the same address vs. someone who’s changing it regularly.

If you have a static IP address, someone with the right tools could also find out exactly where you live. There are websites dedicated to doing a reverse look-up from your IP address and then applying this to your IP location. Therefore, businesses can get roughly close to where you are located and apply adverts to things that are within proximity of where you are.

When to use dynamic IP addresses Dynamic IP addresses are useful when we want to assign an IP address without having to worry about the administrative overhead of the assignment of the address. Traditionally we would allow the DHCP servers or network routers to handle the allocation for us. We would use a dynamic IP address in places where we don’t require a static IP to be applied.

IP address pools An IP address pool is a sequential range of IP addresses within your network. For complex networks, we can find that there are multiple pool configurations using multiple IP address pools. With a DHCP server, we would apply an address from a single pool or from multiple pools and the server infrastructure will apply it.

Most IP address pools utilize something called the Least Recently Used (LRU) method when assigning an address. This means that IP addresses are assigned to a queue and the IP address is released when it reaches the end of the queue.

This is pretty much everything you need to know about static and dynamic IP addresses, and we hope this guide helped you to understand the best use cases for each of them. If you need more information about IP addresses, DNS, and other core Internet technologies, make sure to check out our Networking category on Petri.

View Details

Earlier this month, Amazon relaunched its AWS Educate offering, which is a set of learning courses that are designed specifically for pre-professional learners. As a part of the relaunch, AWS Educate is now open to all individuals no matter what level of education or technical experience they may have.

Previously, AWS Educate was restricted to educators, students with a .edu email address, and US Military veterans. Now, it’s available for all learners who are 13 years old and older, and Amazon is also leveraging its Twitch platform to offer cloud training content with no additional account or login required.

AWS Educate courses are designed to build knowledge and skills about Amazon Web Services cloud computing, with hundreds of hours of free, self-paced training and labs. All of the content on AWS Educate is specifically designed for learners who are new to cloud computing.

The main content changes on AWS Educate The new courses are organized into six content groups and are tagged by proficiency level. All 59 available courses can now be viewed on a single page. There are ten labs in English, with plans to offer additional languages later this year.

Some of the main new features that have been added to Amazon’s education platform include:

  • Four new courses—Cloud Computing 101, AWS DeepRacer Primer, Machine Learning Foundation, and Builder Labs.
  • A redesigned website to guide learners to training content based on their knowledge, goals, interests, and age.
  • Learners can explore recommended courses organized in six content groups, such as Cloud Skill Basics and Cloud Skill Advanced.
  • Learners only need an email address to begin using the AWS Management Console
  • A new Explore option on the homepage features supplementary content, such as new courses, Twitch videos, blogs, and white papers.

Available in more than 200 countries and territories around the world, individuals can learn, practice, and evaluate cloud skills with AWS Educate without creating an Amazon account. Their progress is saved along the way so they can pick up where they left off at any time.

You can learn more details about Amazon’s on-demand education platform at AWS Educate.

View Details

Microsoft has released a new security feature that should help to protect Windows PCs against malicious drivers. David Weston, Microsoft’s Vice President of Enterprise and OS Security, announced on Twitter today that the vulnerable driver blocklist feature is now available on Windows 10, Windows 11, as well as Server 2016 and higher.

The new vulnerable driver blocklist feature is designed to prevent third-party malicious drivers from running on Windows devices, and Microsoft says that it blocks all potentially vulnerable drivers with known security vulnerabilities. Moreover, the feature prevents threat actors from exploiting vulnerabilities in signed kernel drivers in order to inject malware into the Windows kernel.

Microsoft highlighted that it collaborates with partners and security experts to track malicious drivers. The company keeps adding these drivers to its “ecosystem block policy” to protect against security threats across all Hypervisor-protected code integrity (HVCI) and Windows 10 in S mode devices.

“Microsoft works closely with our IHVs and security community to ensure the highest level of driver security for our customers and when vulnerabilities in drivers do arise, that they’re quickly patched and rolled out to the ecosystem. Microsoft then adds the vulnerable versions of the drivers to our ecosystem block policy” the company explained on a support page.

How to enable the vulnerable driver blocklist feature in Windows Security To enable the vulnerable driver blocklist feature, you will need to open Windows Security on Windows 10 or Windows 11. Then, you’ll need to select Device Security and then click the Core isolation details option. Finally, turn on the Memory Integrity toggle button and restart your Windows device. As shown in the screenshot, the Microsoft Vulnerable Driver Blocklist option should show up under the Device Security section.

It is important to note that the vulnerable driver blocklist appears to be rolling out gradually to all Windows PCs, and it’s not available for everyone just yet. Have you spotted the new security capability on your PCs? Let us know in the comments down below.

View Details

Microsoft has announced the release of a new Windows Server Insider Preview Build 25075. The latest build is for the next Long-Term Servicing Channel (LTSC) release for the OS, which should be Windows Server version 2022.

This new Windows Server build brings new security capabilities that should help organizations to prevent brute-force dictionary attacks. Microsoft has introduced a new SMB NTLM authentication limiting feature, which adds a 2-second delay between each failed New Technology LAN Manager (NTLM) or PKU2U-based authentication request.

“Starting in Windows Insider build 25069.1000.220302-1408 and later on Windows 11 and Windows Server 2022, the SMB Server service now implements a default 2-second delay between each failed NTLM-based authentication. This means that if an attacker previously sent 300 brute force attempts per second from a client for 5 minutes, the same number of attempts would now take 25 hours at a minimum,” the Windows Server Insider team explained.

For those unfamiliar, the Server Message Block (SMB) is a popular file server protocol. It lets users communicate with remote PCs and servers to access their resources such as files and directories or perform tasks like sharing, opening, and editing documents.

The SMB server service is usually enabled on non-file server machines so that users can access remote files and copy logs. However, threat actors could abuse the SMB authentication mechanism to launch brute-force dictionary attacks on vulnerable machines. The new SMB NTLM authentication limiting feature allows IT Admins to slow down the brute force attacks targeted at SMB endpoints.

The Windows Server Insider team has recently released a 3-minute video demonstration of the SMB NTLM Authentication Rate Limiter feature.

The SMB NTLM Authentication Rate Limiter feature can cause issues with select third-party apps Keep in mind that this new SMB NTLM Authentication Rate Limiter is still an experimental feature, and it may trigger issues with select third-party applications. The company also encourages Windows Server users to provide their feedback on the Feedback Hub.

Microsoft is also planning to bring this feature to Windows 11 Insider Dev Channel and Windows Server Azure Edition Insider builds in the coming weeks. If you’re interested, you can learn more about the new SMB NTLM authentication rate limiter on Microsoft’s official blog post.

View Details

The US Cybersecurity and Infrastructure Security Agency (CISA) and FBI released an alert about a Russian state-backed activity that allowed hackers to bypass multi-factor authentication (MFA) and exploit a security flaw to compromise networks. The security advisory indicates that the cyberattacks targeting a non-governmental organization (NGO) started back in May 2021.

The threat actors leveraged a “misconfigured” account setting to set default MFA protocols and then enrolled a new device to access the NGO’s network. Once done, the cyber attackers exploited a previously disclosed critical Windows 10 PrintNightmare flaw (CVE-2021-34481) to run malicious code with system privileges.

“The victim account had been un-enrolled from Duo due to a long period of inactivity but was not disabled in the Active Directory. As Duo’s default configuration settings allow for the re-enrollment of a new device for dormant accounts, the actors were able to enroll a new device for this account, complete the authentication requirements, and obtain access to the victim network,” CISA explained.

Additionally, the Russian threat actors managed to modify a domain controller file to prevent the Duo MFA from contacting its server for authentication. With MFA disabled, the attackers authenticated the NGO’s VPN as non-administrators and established connections to the Windows domain controllers via Remote Desktop Protocol (RDP).

“Using these compromised accounts without MFA enforced, Russian state-sponsored cyber actors were able to move laterally to the victim’s cloud storage and email accounts and access desired content,” CISA added.

The FBI-CISA advisory outlines mitigation measures to prevent Russian attackers from exploiting MFA Flaw The cyber security advisory outlines several best practices that should help security teams to protect their organizations from Russian state-sponsored cyber attacks. It recommends that government and agencies should enforce MFA for all users, patch known exploited vulnerabilities on all systems, and enable security features such as time-out and lock-out. Furthermore, IT Admins are advised to make sure all inactive accounts are disabled uniformly across the Active Directory (AD) and MFA systems.

View Details

Today I want to explain some more details about the maximum possible distance between two Azure Stack HCI nodes within an active/active cluster.

As you may know, Azure Stack HCI has two cluster options, active/active or stretched cluster. A standard active/active cluster, with at least two server nodes in a single site or the same server rack, is the recommended setup.

The other option is a so-called ‘stretched cluster‘. It has at least four server nodes that span across two sites, and at least two nodes per site.

Many customers are asking if they can add more nodes to a standard cluster. And if they can deploy a standard cluster over a larger distance than one single location or data center.

The short answer is yes. That is possible. But you need to follow some hard guidelines.

Guidelines for Azure Stack HCI standard clusters After some discussion with Microsoft Product Groups, we found out that there are some pretty good and understandable requirements at the networking level for standard cluster nodes.

Network latency First, let’s start with the latency requirements. Between two nodes, Azure Stack HCI expects a high-performance, low latency connection. In numbers, that means the latency between two nodes must be less than one millisecond and a minimum speed of 25 Gbit/s or more is required.

Another major requirement is to avoid asymmetry latency between nodes. The connection between the HCI nodes must be non-routed, which means only a switch connection between nodes and both HCI nodes must be in the same subnets.

These two requirements make wide area network (WAN) deployments quite complex, as you need to deploy direct layer 2 WAN links that are bridging the same distance. As nearly every network service provider deploys and configures WAN circuits to be redundant and not taking the same routes, it is impossible to not end up with asymmetric latency.

From an active/active cluster deployment view, it also makes the most sense to deploy on the same office, building, or within the same metropolitan area.

Please be aware that Microsoft still recommends having all cluster nodes in one server rack, even if more deployment options are possible.

Possible deployments An additional deployment guideline is to use two top-of-rack (ToR) switches and two interconnect uplinks per server. One uplink is connected to ToR switch one and the other connection to ToR switch two.

If you have a single rack Within a single rack, the deployment would look like the diagram below.

How to deploy an Azure Stack HCI active/active cluster in a single rack Deployment options over larger distances If you want to deploy an Azure Stack HCI active/active cluster over a larger distance, there are basically two options you could try.

One ToR switch per location 1. The cheapest option would be to deploy one ToR switch in location one, and the other ToR switch in the second location. One server link is connected to the ToR switch locally and the other one is connected via WAN Link to the remote ToR switch.

You can deploy one ToR switch in location one and the other ToR switch in the second location This setup requires one WAN Link per server, and it is most likely not feasible for more than two servers.

Two ToR switches per location The other option is to deploy four ToR switches, two per location, and connect the ToR switches with the required amount of WAN links. For redundancy, there should be a minimum of two links, but for larger clusters, you would require more capacity. So, it makes sense to use Links with 50 Gbit/sec or above.

You can also deploy four ToR switches, two per location Here it is important to keep latency as symmetric as possible and stay beneath one millisecond.

How to maintain virtual machine redundancy When using an active/active cluster, one important issue you’ll have to deal with is how to maintain virtual machines and virtual machine clusters highly available between sites. You may want to avoid virtual machines, which belong to a cluster, failing at the same time.

To avoid such outages and to ensure that both virtual machines will be offline at the same time, you can set up VM affinity rules using PowerShell.

If you are using System Center Virtual Machine Manager 2019 or later, you can also use virtual machine settings to configure preferred and possible owners of virtual machines and availability sets for those virtual machines.

Things to keep in mind There are a few things you should always keep in mind.

Software Defined Networking (SDN) considerations If you use Software Defined Networking (SDN) and converge all traffic into two 25 Gbit/sec physical network interfaces, for example, you might not have enough throughput capacity. So, it makes sense to use larger interfaces, (48 Gbit/sec and higher), or use dedicated network interfaces. For example, you can separate interfaces for management, storage, and virtual machine access.

Remote Direct Memory Access (RDMA) As Azure Stack HCI with Storage Spaces Direct requires Remote Direct Memory Access (RDMA), you need to be aware of the protocol you want to use. Currently, there are two protocols out there. iWARP, which is simple to implement but with lower performance and it is not routable. And RoCE (RDMA over Converged Internet), which has better performance but your switches need to support Datacenter Bridging (DCB).
If you want to learn more about Remote Direct Memory Access, I would recommend Intel’s product brief about iWARP and RDMA.

Configuration of affinity and placement rules You may want to automate the configuration of affinity and placement rules. You could for example set up a task on one of your management hosts that scans your host for specific names like DC-01 and DC-02. Using those names, you would then configure your affinity and placement rules.

Lastly, if you are spreading out your cluster nodes, please set up proper monitoring and configure alerts and warnings so that you are notified as soon as the given thresholds and warning levels are reached.

Summary It is still recommended to have all active/active cluster nodes in one rack to reduce external impact. But when staying within the guidelines set by Microsoft, you can build a much more flexible Azure Stack HCI deployment.

When following Microsoft’s guidelines, you can easily “stretch” an active/active cluster through your campus without using the actual stretch clustering option.

Please plan carefully for high availability and virtual machine placements in those environments. Also keep network monitoring and storage replication a high priority, as you may stretch your cluster to its limits.

View Details

Microsoft has unveiled several new features and capabilities for its Office productivity suite to better suit the needs of the new hybrid work era. The Redmond giant also announced this morning a new AI-powered Surface Hub Smart Camera, and Teams Rooms innovations to help users improve the remote meeting experience.

Outlook adds support for Loop components First off, Outlook on the web is getting a new RSVP feature that will let meeting attendees specify and choose to participate remotely or in person. This new capability should help organizers book meeting rooms that can accommodate all participants. The RSVP experience is slated to begin rolling out in preview to Outlook on the web later this year.

Microsoft is also planning to bring new Loop components to Outlook mail. Microsoft Loop components arrived in Teams last year, and they allow users to plan, complete action items, collaborate with team members on projects. Microsoft says that this feature is already available in the Office Insider Beta channel, and users can try it right now.

Microsoft Surface Hub 2 Smart Camera In addition to the new Teams features, Microsoft has also announced the new Surface Hub 2 Smart Camera. This new AI-powered camera comes with “automatic reframing, wide field of view, and intelligent image correction” capabilities. Microsoft’s Surface Hub 2 Smart Camera can detect and track people’s posters and ensures that everyone present in the meeting is visible to remote participants. The Surface Hub 2 Smart Camera is available to purchase now, and it costs $799.99.

Microsoft has also unveiled some new Teams certified touch-enabled displays from its partners such as Yealink and Neat. These new Android-powered meeting room solutions will be available in the coming months.

PowerPoint gets a new Cameo and Recording Studio experience Microsoft PowerPoint is introducing new capabilities that should help to make hybrid presentations more impactful and engaging. Later this year, Microsoft is adding a combined Recording Studio and Cameo experience to PowerPoint. This update will let users annotate slides, choose custom backgrounds as well as select during views while recording their presentations. Similarly, it will enable presenters to integrate their Teams camera feed directly into a PowerPoint presentation.

Microsoft Teams adds new 3D emojis, Shared Channels, and Speaker Coach Microsoft is continuing to improve the collaboration experience in Teams with a skin tone selector option and Fluent 3D emojis. These updates are currently available in public preview for Microsoft Teams users. Language Interpretation, a new feature that allows human interpreters to translate everything that is said by the speaker during a meeting in real-time, is arriving in late 2022.

Shared Channels is another much-anticipated feature coming to Microsoft Teams later this month. With Shared Channels, users will be able to collaborate seamlessly with internal and external partners without switching tenants.

Microsoft is also bringing a new AI-powered feature, Speaker Coach, to Teams in Q2 2022. This tool is designed to monitor the speaker’s pace during meetings and provide feedback. It also checks if the presenter keeps eye contact with the camera and reminds them to interact with their audience.

Last but not least, Microsoft is updating the Whiteboard app in Teams with new collaboration features later this year. The list includes contextual reactions, more than 50 new templates, collaboration cursors, and much more.

View Details

If you want to use Hyper-V on Windows Server Core, you’ll have to do that without a Graphical User Interface (GUI), which requires some knowledge about the different Hyper-V installation options? We’re going to explore them all in that guide, and we’ll also explain why you may find Windows Server Core to be a great option for using Hyper-V.

Why Windows Server Core is the best platform for Hyper-V There are advantages and disadvantages to using Windows Server Core as the platform for the Hyper-V role. Let’s get a few disadvantages out of the way first. You don’t have a local GUI environment (Desktop experience) to administer the server with. Really, that’s the ‘core’ one, no pun intended…or is it intended?

Advantages compared to Windows Server with the Desktop experience The main advantage is the fact that the desktop environment is not installed. As a result, a huge security attack vector is missing. Plus, the complexity of Windows is greatly diminished. This is precisely why the Server Core option is so good for Hyper-V.

Ideally, Hyper-V is installed as a low-footprint hypervisor on a bare metal server. And Microsoft did release this specific SKU in the past, going back to Windows Server 2008. However, ‘Hyper-V Server 2019’ is the last version Microsoft has released and will release. There will be no ‘Hyper-V Server 2022’ released.

So, the next best thing (besides heading into the Azure lands in the clouds) is to install Windows Server (2022) Core and install the Hyper-V role. This comprises most of what this article will detail and explain.

Why choose Windows Server 2022 to run Hyper-V? I pretty much started to answer this question above. Let’s be a bit more nuanced though, shall we?

Running the latest and greatest version of Windows Server has advantages, most notably performance and security related. Plus, using Hyper-V Server 2019 will only get you to the end of support quicker. Windows Server 2022 will go out of extended support on October 14, 2031! That’s over nine years to go!

Staying up to date has its advantages, obviously. Also, Microsoft will undoubtedly spend the most R&D resources on their ‘latest’ platforms.

Hyper-V installation options There are technically three major installation options for installing and using the Hyper-V role on Windows Server.

  1. Installing Hyper-V Server 2019 on a bare metal server.
  2. Installing the Hyper-V role on Windows Server with the Desktop Experience.
  3. Installing the Hyper-V role on Windows Server Core.

I am going to focus on the third option above for the remainder of this article. I will show you how to install the Hyper-V role on an installation of Windows Server 2022 Core.

Hyper-V in Windows Server Core Mode Installing the Hyper-V role on Windows Server Core is the next best thing to installing Hyper-V Server 2019 on bare metal. Let’s get started!

How to install Hyper-V on Windows Server Core Now I’ll get down to brass tax and explain the procedures and steps to installing and using the Hyper-V role on Windows Server Core. First, let’s go over the requirements.

Hyper-V Server Core requirements Regardless of the Hyper-V features you want to use, you’ll need:

  • A 64-bit processor with second-level address translation (SLAT): To install the Hyper-V virtualization components such as Windows hypervisor, the processor must have SLAT, also known as nested paging. However, it’s not required to install Hyper-V management tools like Virtual Machine Connection (VMConnect), Hyper-V Manager, and the Hyper-V cmdlets for Windows PowerShell.
  • CPU support for VM Monitor Mode Extension (VT-x on Intel CPUs)
  • Enough memory – plan for at least 4 GB of RAM. More memory is better. You’ll need enough memory for the host and all virtual machines that you want to run at the same time.
  • Virtualization support turned on in the BIOS or UEFI:
    • Hardware-assisted virtualization: This is available in processors that include a virtualization option – specifically processors with Intel Virtualization Technology (Intel VT) or AMD Virtualization (AMD-V) technology.
    • Hardware-enforced Data Execution Prevention (DEP) must be available and enabled. For Intel systems, this is the XD bit (execute disable bit). For AMD systems, this is the NX bit (no execute bit).

You can also open an administrative command prompt or Terminal and run:

Systeminfo.exe

Then, you can scroll down to the Hyper-V Requirements section for details.

Install and Configure Windows Server Core I previously wrote an article on how to install Windows Server 2022 Core using the Core option. I also included a few crucial ‘post-setup’ tasks.

Install The Hyper V platform/server role The next step is to install the Hyper-V platform on our new server. To accomplish this, we will add the ‘Hyper-V’ role using several methods.

For the purposes of this article, I have an existing virtual machine (VM) we’ll be using for demonstration purposes.

Install Hyper-V using PowerShell Before we go any further, I get to broach the lovely topic of nested virtualization.

Typically, you install a hypervisor (Hyper-V, VMWare ESXi, etc.) on a bare metal server. You’re adding a hypervisor layer (virtualization) onto bare metal. No big deal…this has been done for decades.

However, I don’t have a bare metal (physical) server handy, so I need to use my Hyper-V lab environment for the purposes of showing you the steps involved. Installing the Hyper-V role on an existing (virtualization) layer involves some cool computer science.

By default, Hyper-V VMs do not support enabling a nested hypervisor layer inside its operating system (Windows Server). There are special processor requirements needed for this. So, we need to run a PowerShell command to ‘expose virtualization extensions’ from the Hyper-V hypervisor layer to the VM itself. Let me show you.

First, you can exit out of the sconfig utility by typing ’15’ to exit to PowerShell. Then, run the Get-VM PowerShell command to identify the name of the VM we’re going to work with.

Get-VM

Listing all Hyper-V Virtual Machines (VMs) with the PowerShell Get-VM Command The one I’m using is called ‘AD-WS22-FS03-Core’. So, I’ll need to use it with the PowerShell Set-VMProcessor command:

Set-VMProcessor -VMName "AD-WS22-FS03-Core" -ExposeVirtualizationExtensions $true

There’s no real output or reply. Just assume no news is good news. OK, now we are ready to install the role. PowerShell makes it awesome easy. Open a PowerShell prompt with administrator privileges and run the Install-WindowsFeature cmdlet:

Install-WindowsFeature -Name Hyper-V -IncludeManagementTools -Restart

It should automatically reboot the server when the installation is successful. To quickly verify the role is installed, just use the Get-WindowsFeature cmdlet from any computer on the domain.

Get-WindowsFeature -ComputerName WS22-FS03-Core

You should see Installed next to ‘Hyper-V’ (or an ‘x’):

The ‘Hyper-V’ role is successfully installed on our Windows Server Core machine Install Hyper-V using the Windows Admin Center For the current, recommended, graphical method, we’ll turn to our trusty Windows Admin Center. I’m on a Windows 11 client workstation on our domain and have Windows Admin Center running.

The main view in Windows Admin Center I need to manipulate the installed ‘Roles and Features’ on our server so I will click on ‘ws22-fs03-core.reinders.local’ (and login)

‘Overview’ view on our ‘ws22-fs03-core’ server We’re selecting ‘Hyper-V’ to install the Role On the top, click ‘+ Install‘. Check the box to ‘Reboot the server automatically, if required‘ and click Yes.

After clicking Install, it shows what features will be installed Then, you’ll be able to check progress on the installation of the Hyper V platform and server role.

How to create and manage Hyper-V virtual machines I’m not sure what you all think, but I feel it’s pretty cool that we have the Hyper-V role installed on top of a Hyper-V VM! And trust me, that’s a nifty accomplishment in its own right.

But what good is the Hyper-V role if we don’t use it? Let’s install and manage a few VMs using the three main tools listed here.

Using Windows Admin Center First, we’ll use the modern Windows Admin Center to create a new Windows 10 VM. But before we create a new VM, we first need to create a virtual switch. Open Windows Admin Center and click on the server you’re using (in my case, WS22-FS03-Core). Next, scroll down to the bottom of the Tools list and choose Virtual switches.

Adding a ‘New virtual switch’ We need to create a virtual switch that will allow our Hyper-V host to manage network traffic between itself and the VM. Here’s how to do it:

  • Click ‘+ New‘.
  • Enter a switch name that suits your needs
  • Choose the Switch type of ‘External‘ from the dropdown menu
  • Place a checkmark next to the ‘physical’ network adapter on your Hyper-V server (Ethernet)
  • Make sure the ‘Allow management OS to share these network adapters‘ is checked
  • Click Save.

Our Virtual switch Now, we can create our Virtual Machine. Under Tools, right above Virtual switches, click on Virtual machines.

The Virtual machines view in Windows Admin Center Click the ‘Add’ dropdown and click ‘+ New‘. Enter a Name for the new VM, choose if you want Generation 1 or 2, then adjust the location of the VM configuration and virtual hard disks, if you don’t prefer the defaults.

Building our new Windows 10 VM, inside Hyper-V Choose the number of Virtual processors you want to grant the VM, and the amount of memory (RAM). Be sure to choose the new Virtual switch we just created, then under Storage, click the ‘+’ sign. Decide how large you initially want the ‘C: drive’ to be in the VM and confirm that ‘Install an operating system later’ is selected. Then, finally, click Create!

Our new Virtual machine Using Hyper-V Manager Let’s transition over to using Hyper-V Manager to make some additional changes and to start our new VM. I’m back on my Windows 11 client machine and have launched ‘Hyper-V Manager’ from the Administrative Tools menu.

The initial launch of Hyper-V Manager on our Windows 11 client machine Right-click on ‘Hyper-V Manager’ in the upper left corner, and choose ‘Connect to server…’ I’ll type in ‘ws22-fs03-core’ in the ‘Another computer’ field and click OK.

After connecting to the Hyper-V Role, we can see the Windows 10 VM we created There’s our VM! I’m going to go through a few other settings before we fire it up. Right-click on the VM and click Settings:

  • On the ‘Add Hardware’ menu, confirm ‘SCSI Controller’ is highlighted and click the ‘Add’ button.
  • Choose ‘DVD Drive’ and click ‘Add.’
  • Click the ‘Image file:’ radio button and click the ‘Browse…’ button.
  • Locate your Windows 10 installation ISO and click OK.
  • Now, go up to the ‘Firmware’ category on the left, click the new ‘DVD Drive’ and click ‘Move Up’ until it’s at the top. This should do it.

We’ve added a DVD Drive to our VM so we can choose the Windows 10 ISO to install Windows Using PowerShell You can always count on PowerShell to give you a shot of efficiency in your day-to-day tasks, and managing your Hyper-V environment is no exception. Incidentally, the larger and more complex your Hyper-V environment is, the faster you’ll get things done with PowerShell at your side. Let me go through a few of the basic cmdlets.

A great place to start is to get a list of all the cmdlets available related to the Hyper-V module.

Get-Command -Module hyper-v

Yes, there are an awful lot. Let’s start simple. Use the Get-VM cmdlet to get a list of VMs.

Get-VM

Running ‘Get-VM’ to see our new Windows 10 VM – using PowerShell If you wanted to list only VMs in the ‘Running’ state, you can use a filter:

Get-VM | where {$\_.State -eq 'Running'}

Anyway, to start a VM, use the ‘Start-VM’ cmdlet.

Start-VM -Name "Windows 10 version 21H2"

After running ‘Start-VM’ we can see our new VM is in the ‘Running’ state Let’s finish off this lovely post with an example of how to create a new VM. You could use the ‘PowerShell ISE’ to create this script and run it against your Hyper-V Server.

``` $VMName = "Windows 11 version 21H2"

$VM = @{ Name = $VMName MemoryStartupBytes = 2147483648 Generation = 2 NewVHDPath = "C:\Virtual Machines\$VMName\$VMName.vhdx" NewVHDSizeBytes = 53687091200 BootDevice = "VHD" Path = "C:\Virtual Machines\$VMName" SwitchName = (Get-VMSwitch).Name }

New-VM @VM ```

This will create a new VM using the Name of “Windows 11 version 21H2”. It will start with 2GB of RAM, create a Generation 2 VM, set the file path for the VHD file in the path above, set the initial C: drive partition size to about 50GB, and boot from the .VHDX file. This is pretty simple, but there are many more options and parameters you can use to create some pretty sophisticated VMs using PowerShell.

That’s it for our guide about how to install Hyper-V on Windows Server Core, be aware that we have a separate guide on how to install Hyper-V on a Windows 10 PC.

View Details

German federal cybersecurity agency BSI has warned its citizens against using antivirus products from Russian-based Kaspersky Lab. The security agency has issued a statement today saying that the Kaspersky antivirus software could be exploited in launching cyberattacks amid Russia’s ongoing war in Ukraine.

The advisory did not accuse Kaspersky Lab of any specific security violations, but it warned that certain organizations and authorities could be particularly vulnerable. The German security agency is now recommending companies to replace the Kaspersky antivirus solution with alternative products non-Russian software vendors.

“The actions of military and/or intelligence forces in Russia and the threats made by Russia against the EU , NATO and the Federal Republic of Germany in the course of the current military conflict are associated with a considerable risk of a successful IT attack. A Russian IT manufacturer can carry out offensive operations itself, be forced to attack target systems against its will, or be spied on without its knowledge as a victim of a cyber operation, or be misused as a tool for attacks against its own customers,” BSI explained in a press release.

Kaspersky says this decision is based on political grounds In a statement shared with Bleeping Computer, a Kaspersky spokesperson explained that it believes this warning has been issued on political grounds and isn’t based on a detailed technical analysis of its antivirus software.

“We will continue to assure our partners and customers in the quality and integrity of our products, and we will be working with the BSI for clarification on its decision and for the means to address its and other regulators’ concerns,” Kaspersky said. “Kaspersky is a private global cybersecurity company and, as a private company, does not have any ties to the Russian or any other government.”

It remains to be seen how Kaspersky will address the new security concerns, which could give other antivirus vendors an incentive to attract more enterprise customers. Kaspersky received a fair share of criticism when the Trump administration banned Kaspersky software in all government departments in 2017. The U.S. government claimed that Kaspersky Lab worked on secret projects with Russian Intelligence agencies, but the company denied all the accusations.

Do you use Kaspersky antivirus products in your organization? Let us know in the comments below.

View Details

Welcome to the new look Petri.com! Our team has been working hard over the past three months to completely redesign the look and feel of the Petri IT Knowledgebase. Not only does the site now have a more modern look, but a lot of work has gone into improving performance and usability of the site.

The redesigned site aims to bring Petri up-to-date with modern web design trends and make it the best possible resource for our readers. Petri is committed to providing the best content and community resources to help IT professionals be successful in their jobs and keep end users and businesses running 24 hours per day, 365 days per year.

Homepage and search The homepage is now organized in a way that provides you with quick access to the latest how-tos in categories that are important to you. The site is more visual, helping you navigate around it faster and to help you more quickly focus on what’s important.

The new Petri IT Knowledgebase homepage

Search is now blazing fast, so you can find anything that you are looking for quickly! We also have new sections for podcasts and video. And if you want to find out more about our authors, there is an expanded author details page with a short bio and links so that you can contact them directly.

Petri.com user accounts get access to more content If you had an account on Petri prior to the redesign, you can continue to log in using your existing username and password. If you don’t have an account, we encourage you to create an account to get easy access to exclusive content like our quarterly GET-IT 1-day virtual conferences, webinars, whitepapers, and much more.

New Category page on the Petri IT Knowledgebase website

In this initial version of the new site, we don’t have user account login. Stay tuned over the next few weeks as add user accounts back to the site.

Petri believes that IT Professionals are business heroes Petri believes that IT Professionals are business heroes.​ And the site redesign is aimed at helping IT Pros navigate the everchanging discipline of information technology. Whether that is solving a problem at work, studying for the latest certification, or keeping up with the latest changes in IT.

Feedback As we continue to tweak and improve the new site over the coming weeks, we’d love to hear what you think! If you have any comments on the design, performance, or usability of the new site, then please use this form.

View Details

Here’s a look at what you need to know * QNAP has issued an advisory about a new Dirty Pipe Linux vulnerability that affects a wide range of Network Attached Storage (NAS) devices. * It allows attackers to overwrite data in arbitrary read-only files. * The Dirty Pipe security flaw affects all NAS devices running kernel version 5.10.60. * QNAP plans to release security updates soon to address this vulnerability.

QNAP, a company specializing in developing networking solutions, has issued an advisory about a new Linux vulnerability that affects most of its Network Attached Storage (NAS) devices. The company warned that this high severity Linux exploit called “Dirty Pipe” could be abused by attackers to gain root privileges on affected systems.

The Dirty Pipe vulnerability, tracked as CVE-2022-0847, was discovered by a security researcher by Max Kellermann back in April 2021. It allows non-privileged users to overwrite data in arbitrary read-only files, leading to local privilege escalation. The attacker can exploit this vulnerability to carry out various malicious actions such as creating unauthorized user accounts, installing backdoors, injecting code into scripts, and altering binaries used by privileged apps or services.

Essentially, the security vulnerability resides in a Linux mechanism called pipeline, which the OS uses for unidirectional communication between processes. The flaw has since been fixed in the latest Linux kernel versions, but it could potentially target devices running Linux kernel version 5.8 or newer.

The Dirty Pipe flaw affects all QNAP NAS devices running QTS 5.0.x and QuTS hero h5.0.x QNAP says that the Dirty Pipe exploit affects all devices running QTS 5.0.x and QuTS hero h5.0.x, and you can check out the full list of all affected models in the release notes for Kernel Version 5.10.60.

“If exploited, this vulnerability allows an unprivileged user to gain administrator privileges and inject malicious code,” QNAP explained in a security advisory. “Currently there is no mitigation available for this vulnerability. We recommend users to check back and install security updates as soon as they become available.”

The company has advised all users to wait for its security patches that should help to mitigate the vulnerability on Network Attached Storage (NAS) devices. Meanwhile, it recommends that users with Internet-exposed NAS devices should disable the “Port Forwarding function of the router” and the “UPnP function of the QNAP NAS,” at least until a fix is available.

View Details

Microsoft has removed an important upgrade block that should finally allow more users to upgrade to Windows 11. Last week, Microsoft updated the Windows health dashboard (via Bleeping Computer) to mention that the latest version of VirtualBox has finally removed the last Windows 11 safeguard hold, and users should update the app to version 6.1.28 or later.

“Oracle has resolved this issue in VirtualBox 6.1.28 and later. To remove the safeguard hold on your device, you will need to update to VirtualBox 6.1.28 or later. Please note, if there are no other safeguards that affect your device, it can take up to 48 hours before the update to Windows 11, version 21H2 is offered,” the company explained.

Back in October 2021, Microsoft had applied an upgrade block on all Windows 10 devices with

VirtualBox where the Hyper-V or Windows Hypervisor had been installed. This was caused by a compatibility issue between the app and the OS, as the bug could cause errors triggering startup problems on virtual machines. This issue has now been resolved and VirtualBox users should no longer experience any problems while upgrading to Windows 11.

Microsoft warns that some users may still be unable to upgrade to Windows 11 Even though the safeguard hold has been removed, keep in mind that it can take up to 48 hours before you can install Windows 11 on your PCs. It is also important to note that there are still some VirtualBox compatibility issues that may prevent users from upgrading their devices.

“If you do not have VirtualBox installed but are receiving this safeguard hold, you might have an application that is based on VirtualBox or which has bundled VirtualBox within their installation,” Microsoft noted.

Microsoft has provided a temporary workaround that should help to mitigate this problem. The company recommends users to update or uninstall all the applications (such as VirtualBox, Hyper-V, Windows Hypervisor) from their Windows PCs.

View Details

Microsoft Azure is now the most widely used enterprise cloud computing service, according to a new report from the IT management firm Flexera. Currently, Azure, AWS, and Google Cloud Platform are the top three public cloud providers, and the adoption rate of Azure has surpassed AWS in several areas.

The 2022 State of the Cloud Report survey collected the responses of the 753 business professionals and cloud decision-makers worldwide. The survey was conducted in late 2021, and it outlines whether the enterprise respondents are currently running significant workloads, some workloads, experimenting with a cloud provider, or planning to use it in the future.

According to the report from Flexera, 80 percent of enterprise respondents are currently using Microsoft Azure, which is 4 percent points higher than last year. Meanwhile, the usage share of AWS dropped from 79 percent to 77 percent during this period. Google Cloud Platform remains in third place with 48 percent adoption, which is followed by Oracle Cloud with a 27 percent adoption rate.

“Data from this year’s survey indicates Azure seems to be either closing the gap — or has slightly surpassed — AWS with some users.” the report says. “As the first large-scale cloud provider, AWS is used more frequently by organizations that have been using the cloud over a longer period and are heavy cloud users.”

AWS is still popular amongst SMBs Notably, the survey data indicates that AWS is still one of the popular cloud service providers amongst small and midsized businesses (SMBs), but its adoption rate dropped from 72 percent to 69 percent. However, Microsoft Azure inches up in popularity, and it is now used by 59 percent SMBs.

Overall, this is a significant milestone for Microsoft as Azure is bridging the gap in some key areas by positioning itself as the “most trusted cloud for enterprise and hybrid infrastructure.” That said, we may have to wait until later this year to get a better picture of the Azure cloud ecosystem.