mountainss Cloud and Datacenter Management Blog

Microsoft SystemCenter blogsite about virtualization on-premises and Cloud

Leave a comment

#Microsoft Azure Security Center Overview #Cloud #Security #HybridCloud #Azure

Microsoft Azure Security Center provides unified security management and advanced threat protection across hybrid cloud workloads. With Security Center, you can apply security policies across your workloads, limit your exposure to threats, and detect and respond to attacks.

You can select an existing Log Analytics workspace to store data collected by Security Center. To use your existing Log Analytics workspace:
• The workspace must be associated with your selected Azure subscription.
• At a minimum, you must have read permissions to access the workspace.

You can edit the default security policy for each of your Azure subscriptions in Security Center. To modify a security policy, you must be an owner, contributor, or security administrator of the subscription. To configure security policies in Security Center, do the following:
1. Sign in to the Azure portal.
2. On the Security Center dashboard, under General, select Security policy.
3. Select the subscription that you want to enable a security policy for.
4. In the Policy Components section, select Security policy.
This is the default policy that’s assigned by Security Center. You can turn on or off the available security recommendations.
5. When you finish editing, select Save.

Here you find more on Set security policies in Azure Security Center

Some policies need the upgrade Enhanced Security

Contact information for Notifications

Azure Security Center provides unified security management and advanced threat protection for workloads running in Azure, on-premises, and in other clouds. It delivers visibility and control over hybrid cloud workloads, active defenses that reduce your exposure to threats, and intelligent detection to help you keep pace with rapidly evolving cyber attacks.
Pricing tiers
Security Center is offered in two tiers:
The Free tier is automatically enabled on all Azure subscriptions, and provides security policy, continuous security assessment, and actionable security recommendations to help you protect your Azure resources.
The Standard tier extends the capabilities of the Free tier to workloads running in private and other public clouds, providing unified security management and threat protection across your hybrid cloud workloads. The Standard tier also adds advanced threat detection capabilities, which uses built-in behavioral analytics and machine learning to identify attacks and zero-day exploits, access and application controls to reduce exposure to network attacks and malware, and more. The Standard tier is free for the first 60 days. Read here more…….

What are OS Security Configurations?
Azure Security Center monitors security configurations using a set of over 150 recommended rules for hardening the OS, including rules related to firewalls, auditing, password policies, and more. If a machine is found to have a vulnerable configuration, a security recommendation is generated.
Customization of the rules can help organizations to control which configuration options are more appropriate for their environment. This feature enables users to set a customized assessment policy and apply it on all applicable machines in the subscription.

• Currently OS Security Configuration customization is available for Windows Server 2008, 2008R2, 2012, 2012R2 operating systems only.
• The configuration applies to all VMs and computers connected to all workspaces under the selected subscription.
• OS Security Configuration customization is available only on Security Center’s Standard tier.

Download the Baseline configuration JSON file

You can make a Custom Baseline with Visual Studio Code and Upload to Azure

Microsoft Azure Security Center QuickStart :

Configure Security Policy

Managing security recommendations in Azure Security Center

Security health monitoring in Azure Security Center

Managing and responding to security alerts in Azure Security Center

Documentation :

Microsoft Azure Security Center Documentation 

Microsoft Azure Security Center Forum

Planning guide
This guide covers a set of steps and tasks that you can follow to optimize your use of Security Center based on your organization’s security requirements and cloud management model. To take full advantage of Security Center, it is important to understand how different individuals or teams in your organization use the service to meet secure development and operations, monitoring, governance, and incident response needs. The key areas to consider when planning to use Security Center are:

Security Roles and Access Controls
Security Policies and Recommendations
Data Collection and Storage
Ongoing non-Azure resources
Ongoing Security Monitoring
Incident Response

Here you will learn how to plan for each one of those areas and apply those recommendations based on your requirements.

All Events view in Azure Security Center

Upgrade to standard Tier for Hybrid Security

Search with analytics

Queries can be used to search terms, identify trends, analyze patterns, and provide many other insights based on your data.

Have a look and play with Azure Log Analytics.

Getting Started with the Analytics Portal

in this tutorial you will learn to write Azure Log Analytics queries. When completing this tutorial you will know how to:

  • Understand queries’ structure
  • Sort query results
  • Filter query results
  • Specify a time range
  • Select which fields to include in the results
  • Define and use custom fields
  • Aggregate and group results

Getting Started with Queries

Azure Security Center gives you Recommendations

For example to Encrypt your Virtual Machines in Azure with a Link

Integrated Azure security solutions
Security Center makes it easy to enable integrated security solutions in Azure. Benefits include:

Simplified deployment: Security Center offers streamlined provisioning of integrated partner solutions. For solutions like antimalware and vulnerability assessment, Security Center can provision the needed agent on your virtual machines, and for firewall appliances, Security Center can take care of much of the network configuration required.
Integrated detections: Security events from partner solutions are automatically collected, aggregated, and displayed as part of Security Center alerts and incidents. These events also are fused with detections from other sources to provide advanced threat-detection capabilities.
Unified health monitoring and management: Customers can use integrated health events to monitor all partner solutions at a glance. Basic management is available, with easy access to advanced setup by using the partner solution.

More on Integrated Azure Security Solutions

Compute Security Overview

Compute Security and Components view

Networking Security Overview

Storage & Data Security Overview

Identity and Access Overview in Azure Security Center

Application Whitelisting

Just in time virtual machine (VM) access can be used to lock down inbound traffic to your Azure VMs, reducing exposure to attacks while providing easy access to connect to VMs when needed.

Attack scenario
Brute force attacks commonly target management ports as a means to gain access to a VM. If successful, an attacker can take control over the VM and establish a foothold into your environment.

One way to reduce exposure to a brute force attack is to limit the amount of time that a port is open. Management ports do not need to be open at all times. They only need to be open while you are connected to the VM, for example to perform management or maintenance tasks. When just in time is enabled, Security Center uses Network Security Group (NSG) rules, which restrict access to management ports so they cannot be targeted by attackers.

More on Just in Time Virtual Machine

Security Alerts

Azure Security Center’s advanced detection capabilities, helps you identify active threats targeting your Microsoft Azure resources and provides you with the insights needed to respond quickly

More on Azure Security Center detection capabilities

Custom Alert Rules

What are custom alert rules in Security Center?

Security Center has a set of predefined security alerts, which are triggered when a threat, or suspicious activity takes place. In some scenarios, you may want to create a custom alert to address specific needs of your environment.

Custom alert rules in Security Center allow you to define new security alerts based on data that is already collected from your environment. You can create queries, and the result of these queries can be used as criteria for the custom rule, and once this criteria is matched, the rule is executed. You can use computers security events, partner’s security solution logs or data ingested using APIs to create your custom queries.

More information about Custom Alert Rules in Azure Security Center

Threat Intelligence

Azure Security Center Playbooks

What is security playbook in Security Center?
Security playbook is a collection of procedures that can be executed from Security Center once a certain playbook is triggered from selected alert. Security playbook can help to automate and orchestrate your response to a specific security alert detected by Security Center. Security Playbooks in Security Center are based on Azure Logic Apps, which means you can use the templates that are provided under the security category in Logic Apps templates, you can modify them based on your needs, or you can create new playbooks using Azure Logic Apps workflow, and using Security Center as your trigger.

More on Azure Security Center Playbook

Hope this Microsoft Azure Security Center Overview will help to make your Hybrid IT more Secure !


Leave a comment

Awesome #Microsoft Azure 101 Cards and Interactive Sites #Azure #Cloud

Microsoft Azure Services 101 Cards

From here you can get the Azure Container Instances Information

Go and see for your self the Microsoft Azure 101 Cards

Microsoft Interactives :

  • Azure Products
  • Cloud Design Patterns
  • Azure Security and Operations Management

Microsoft Azure Security Interactive

Leave a comment

Inside the #Microsoft Operations Management Suite E-book #MSOMS #Azure by #MVPbuzz #MSFT

Description: This is the updated release (v2.0) of “Inside the Microsoft Operations Management Suite”, an end-to-end deep dive into the full range of Microsoft Operations Management Suite (OMS) features and functionality, complete with downloadable sample scripts.

The chapter list in this edition is shown below:

  • Chapter 1: Introduction and Onboarding
  • Chapter 2: Searching and Presenting OMS Data
  • Chapter 3: Process Automation
  • Chapter 4: Configuration Management
  • Chapter 5: Change & Update Management
  • Chapter 6: Extending OMS Using Log Search
  • Chapter 7: Alert Management
  • Chapter 8: Log Management & Performance Data
  • Chapter 9: Azure & Office 365 Solutions
  • Chapter 10: Service Map & Wire Data
  • Chapter 11: Network Performance Monitor
  • Chapter 12: Other OMS Solutions
  • Chapter 13: Assessment Solutions
  • Chapter 14: Security & Compliance
  • Chapter 15: Protection & Recovery
  • Chapter 16: ITSM Integration
  • Chapter 17: Custom OMS Solutions

Here you can download this Free Awesome Ebook Inside the Microsoft Operations Management Suite Version 2


Thank you all for this Great work !

Leave a comment

Getting Started with Microsoft #Azure Cloud #Security Center

Microsoft Azure Security

With Microsoft Azure Cloud Services you can make a lot of  resources using for your Business. Think about Storage, Compute, Databases, Networks and
applications. Microsoft Azure Security is there to keep your resources and data as save as possible against cybercrime.

Microsoft Azure Compliance offerings

Learn how to use Azure Security Center to get visibility into and control over the security of your Azure resources

Here you see an example of what Azure Security can do for you in the Cloud :

Overview of Azure Security with Advice for better Protection against Cybercrime.

Here you see Storage and Azure SQL Database need attention !

Azure SQL Database in Security Center

You can act right away by enabling Auditing & Threat Detection

For prevention you can enable Security data collection on the Virtual Machines.

It’s really easy to start with Microsoft Azure Security Center with the Quick Starts :

You can Read the Azure Security Center planning and operations guide here

Microsoft Azure Security Center gives recommendations on your resources in your Azure subscription

It’s a on-going process to keep your security under control and monitoring the alerts for preventing against Cybercrime or leaking data.

Here you find more resources on Microsoft Azure Security :

Microsoft Technical Azure Security Docs

Microsoft Azure Security Blog

Microsoft Azure Security and Compliance Blog on MSDN

Microsoft Security in Operations Management Suit

Microsoft Technical OMS Security Docs

Who to follow on Social media for Azure Security :



Keep your Cloud resources save with Azure Security !

Leave a comment

JOIN The #Microsoft Tech Community Today #MStechSummit #Azure #MSOMS #AzureStack #Sysctr #Winserv

Sign Up Here for the Microsoft Tech Community

Jeff Woolsey in action Talking about Windows Server 2016 Security and Containers
Thanks Jeff Great Sessions !

Of course It’s a tradition that @ClusterMVP & @WSV_GUY  & @Jamesvandenberg are on a Picture 😉
Cloud and Datacenter Management Rocks

#MVPbuzz Time with Ask Me Anything (AMA) sessions at the Microsoft Tech Summit 2017
Great questions and feedback on Microsoft :

Windows Server 2016
System Center
Operations Management Suite (OMS)

Microsoft Tech Summit 2017 Amsterdam Dutch MVP’s at the Booth

Multitasking showing of the Microsoft Surface Studio and supporting the Microsoft Tech Community
Thanks Ladies !

Microsoft Tech Summit 2016-17

Build your cloud and infrastructure skills with a two-day free technical training event
Here you can see in which cities the Microsoft Tech Summit 2017 is

Thank you Microsoft and Community for these Awesome two Cloud and Infrastructure Days in Amsterdam !  😉

Leave a comment

#Microsoft OMS Service Map for Hybrid IT Management #MSOMS #Azure #Linux #HybridCloud

Service Map in #MSOMS automatically builds a common reference map of dependencies across your servers, processes, and third-party services. It discovers and maps all TCP dependencies, identifying surprise connections, remote third-party systems you depend on, and dependencies to traditional dark areas of your network such as Active Directory. Service Map discovers failed network connections that your managed systems are attempting to make, helping you identify potential server misconfiguration, service outages, and network issues.


Microsoft Operations Management Suite


OMS Service Map Overview of my Demo Environment


Machine Changes on HybridCloud01 Server


You now can see that the Previous Service State Running is changed in Stopped.

When you go more in details and look at the log Search in this event :


When this event is important to you you can make an OMS Alert on this Change :


With OMS Alert you can take actions like :


With Microsoft OMS Runbooks you can make Automation solutions for Hybrid IT Events.


Servicemap Summary


Servicemap Server Properties


OMS Service Map Performance


OMS Service Map Updates

More information about using Awesome Service Map solution in Operations Management Suite (OMS) you can find here

Configuring Service Map solution in Operations Management Suite (OMS)

Service Map gets its data from the Microsoft Dependency Agent. The Dependency Agent is dependent on the OMS Agent for its connections to OMS. This means that a server must have the OMS Agent installed and configured first, and then the Dependency Agent can be installed. The following table describes the connected sources that are supported by the Service Map solution.

Here you can find more information about configuring OMS Service Maps

Operations Management Suite (OMS) SDK

I like Microsoft OMS Service Map a lot because you can see the relations between Servers, Services, Applications in a Hybrid IT environment and
get proactive alerts to take action to keep your Hybrid Datacenters Healthy 🙂

#MSOMS Rocks


Leave a comment

#Microsoft MAP Toolkit 9.6 Now Available! #Winserv #SQL2016 #Azure #Office365 #Cloud #Tool


Microsoft MAP Toolkit 9.6

The Microsoft Assessment and Planning Toolkit (MAP) is an agentless, automated, multi-product planning and assessment tool for quicker and easier desktop, server and cloud migrations. MAP provides detailed readiness assessment reports and executive proposals with extensive hardware and software information, and actionable recommendations to help organizations accelerate their IT infrastructure planning process, and gather more detail on assets that reside within their current environment. MAP also provides server utilization data for Hyper-V server virtualization planning; identifying server placements, and performing virtualization candidate assessments. More information about MAP Toolkit can you find here

Software Requirements:
        • Operating system. Any of the following:
          • Windows 10 (Professional, Enterprise and Ultimate editions only)
          • Windows 8.1 (Professional and Enterprise editions only)
          • Windows 8 (Professional and Enterprise editions only)
          • Windows 7 with Service Pack 1 (Professional, Enterprise, and Ultimate editions only)
          • Windows Server 2012 R2
          • Windows Server 2012
          • Windows Server 2016
          • Windows Server 2008 R2 with Service Pack 1
        • .NET Framework 4.5 (download from
        • Installation of all updates for the operating system. Note: In some cases updates may not install automatically. To download updates for your computer manually, go to
        • By default, the MAP Toolkit will install SQL Server 2012 Express LocalDB during setup. You may also use an existing installation of SQL Server 2008, SQL Server 2008 R2, or SQL Server 2012 if you create an instance named “MAPS” before running the MAP Toolkit installer. The MAP Toolkit requires the collation order of the database engine to be set to “SQL_Latin1_General_CP1_CI_AS”.


        • Some of these prerequisites require restarting your computer. You may have to restart multiple times if all the prerequisites are not met prior to running Microsoft Assessment and Planning Toolkit setup.

Scenario-dependent requirements:

    • For machines that will be used to run the Forefront Endpoint Protection Usage Tracking, Lync Usage Tracking, Exchange Server Usage Tracking, or Volume Licensing scenarios, please note: PowerShell 2.0 or higher must be installed.
    • For machines that will be used to collect Oracle schema information, please note: The 64 bit Oracle client must be installed on the MAP machine to collect the schema information. If the 64 bit client is not installed, MAP will only be able to collect instance information. MAP will not collect schema information if the 32 bit Oracle client is installed.


Export results in Excel for Windows Server 2016 Assessment Example


Microsoft Azure Virtual Machine Sizing Example in Excel


With MAP Toolkit Training available 😉

You can download MAP Toolkit 9.6 here