Cloud and Datacenter Management Blog

Microsoft Hybrid Cloud blogsite about Management


Leave a comment

Azure Update Management for Windows and Linux in Multi Cloud #Azure #Winserv #Linux

Microsoft Azure Update Management Center

Microsoft Azure Update Manager (preview) is a unified service to help manage and govern updates for all your machines. You can monitor Windows and Linux update compliance across your deployments in Azure, on-premises, and on the other cloud platforms from a single dashboard. Important: It’s still in Preview but GA is coming Soon 

To support management of your Azure VM or non-Azure machine, Update Manager (preview) relies on a new Azure extension designed to provide all the functionality required to interact with the operating system to manage the assessment and application of updates. This extension is automatically installed when you initiate any Update manager (preview) operations such as check for updatesinstall one time updateperiodic assessment on your machine. The extension supports deployment to Azure VMs or Arc-enabled servers using the extension framework. The Update Manager (preview) extension is installed and managed using the following:

The extension agent installation and configuration are managed by the Update Manager (preview). There’s no manual intervention required as long as the Azure VM agent or Azure Arc-enabled server agent is functional. The Update Manager (preview) extension runs code locally on the machine to interact with the operating system, and it includes:

  • Retrieving the assessment information about status of system updates for it specified by the Windows Update client or Linux package manager.
  • Initiating the download and installation of approved updates with Windows Update client or Linux package manager.

In my case I’m updating Windows Server Insider version which is Azure Arc enabled in the following steps :


Here you see my Azure Arc enabled Domain Controller with Windows Server Insider.
Here you Click on Check for Updates
Go to Update Management Center

When you Click on Machines you will get a Nice Overview of your Servers

When you Click on History, you will see the assessment and keeps all activity history in one place.

Update reports are Important and you can make your Own reports or download
Public Templates.

In the following steps we are going to install the three updates on the Azure Arc Enabled Server :

Select the machine(s) for the One-time updates.
Click on Next

here you see the Updates.

You can select your reboot Options and the Maintenance Window in Minutes.

If everything is correct you can click on Install.

In History you see your job in progress

Update Management Overview
In Progress

This is what I like most, when you have to manage more then 100 Servers and they are in your Own Datacenter On-premises but also at Multi Cloud vendors Like in Azure, AWS, Google Cloud or are not Domain Joined Servers then here you can see your Update Compliance in a Single point of Dashboard Overview in the Microsoft Azure Cloud.

Create your Own Maintenance Configuration.

Click on Next DynamicScopes

Add a Dynamic Scope

Select the Filter(s)

Filter for Arc Servers and OS type Windows.

Then you see the Azure Arc Servers by your Filter.

Dynamic Scope is set.

select.

Machines.

Include Update Classification

Azure Update Management Center Overview with Updates Completed 🙂

Updates completed on Windows Server Insider Domain Controller.

Conclusion

Microsoft Azure Update Management Center is still in Preview but is a Great Single Dashboard Overview for managing your Updates on Windows Servers and Linux at any Place. It gives you Great Overview and you can see the status in one view. GA is coming soon, but you can now test and experience it before you go in production with this Awesome product.
Follow Microsoft Azure Update Manager here on X

More information on Microsoft Azure Update Management Center (Preview) here

 


Leave a comment

Windows Terminal with #AzureCLI Cloud Shell and #AI Knowledge Base

Windows Terminal with Azure Cloud Shell CLI

Microsoft Azure Artificial Intelligence (AI) is going fast in the Cloud, It can support you with the tools you use like Azure CLI for example to manage Azure resources. But AI can support you in Security too, like Microsoft Security Copilot

Microsoft security CoPilot Create a visual to explain.

But I was busy with Windows Terminal in Windows 11 Insider Preview Build and Azure Cloud Shell.
First getting the latest Build of Azure CLI in my Windows Terminal :

az upgrade

Installing Azure CLI 2.48.1

Click on Install

Click on Finish

For the Changes you need to Restart your machine.

After the reboot we have the Newest Azure CLI Version 2.48.1

Login Azure with Windows Terminal.

I’m connected with Azure via Windows Terminal Azure Cloud Shell.

Here I’m checking if I have a Connection with Azure AI-examples :

az ai-examples check-connection

Connection was successful.

The Azure AI knowledge base made me find examples 🙂

When a command is incomplete or wrong, the AI knowledge base is doing
a suggestion and gives a link to Microsoft docs.

Conclusion

This is where I Like Microsoft Azure Artificial Intelligence (AI) to make my IT Management easier and faster to do the job.
It’s supporting me in my work and not doing things I don’t like. It’s going fast with AI and It’s important to keep it in Control for doing IT Management tasks.


Leave a comment

Azure Arc and Windows 11 Insider Preview Build Update #WindowsInsiders #WIMVP #AzureHybrid

Microsoft Azure Arc

Microsoft Azure Arc Services is a bridge that extends the Azure platform to help you build applications and services with the flexibility to run across datacenters, at the edge, and in multicloud environments. Develop cloud-native applications with a consistent development, operations, and security model. Azure Arc runs on both new and existing hardware, virtualization and Kubernetes platforms, IoT devices, and integrated systems. Do more with less by leveraging your existing investments to modernize with cloud-native solutions.

Azure Arc Control Plane

So with this Awesome Microsoft Feature Azure Arc, I have connected my Windows Insiders Domain mvplab.local servers like a Windows Server Insider Domain Controller, Windows Server Insider Cluster with a SQL Instance on it and Windows 11 Insider Preview Build in the Beta Channel domain joined. Here you can find how to install the Azure Arc Agent on your Servers

Microsoft Azure Arc comes with great features like Azure Security with Cloud Defender to keep your Azure Arc enabled Servers as secure as possible. Azure Policies is very handy to keep your IT governance on every Server the same. With inventory and Change tracking you are in control to get the right information of your machines. Monitoring your Azure Arc enabled servers with Insights and Log analytics is very powerful. But for now I’m going to use Updates feature of Azure Arc enabled Windows 11 Insider Preview Build machine.

Important :  I’m working with Windows Server Insider preview Build and Windows 11 Insider Preview Build.
They are for testing purpose only and not for production environments!
Of course you can use Windows Server 2019 / 2022 or Windows 10 / 11 Build with Azure Arc 🙂

Here we have Windows 11 Insider Preview Build with new Updates in the Beta Channel.
Click on One time Update

I’m going to update this Azure Arc enabled Windows 11 Insider preview Build once manually but you can schedule updates also and use Update Management Center.

Select the Machine and Click on Next

Here you can select the updates or exclude updates.
Then Click on Next

Here you can set the Reboot option and
Maintenance Window in minutes.
Click on Next

Review and Click on Install

Install Updates Request is submitted.

At Updates of your Azure Arc enabled Machine you can open
Update Management Center

Here you can see the Complete Overview of the Updates on your Machines.
Left under you see the 3 updates for the Windows 11 Insider Beta Build.

When you Click on the left panel on Machines you get this status overview.

When you click on History you will see the status in progress.

Updates are running on the Machine.

But with the Azure Resource Graph Explorer you can also
see when the updates are succeeded.

Update Management Center after successful running updates

Updates Done for Azure Arc enabled Windows 11 Insider Beta Build.

Now I have got the Newest Windows 11 Insider Preview Build in the Beta Channel at this moment

Conclusion

You have seen how easy it is to work with Microsoft Azure Arc services to manage your Virtual Machine with Updates, when you have lot of Virtual Machines / Servers to manage you can configure them once and do this automatically via schedule tasks for every month. Now I can manage my on-prem Servers / machines in the same way I do the Microsoft Azure Virtual Machines.
So this was only Updates, but you can do the same for Security and keep your machines secure by default with the same Azure policies on your machines for IT Governance. Hope you see the benefits of Azure Hybrid and please start your own journey.
When you have a test environment, please consider the Microsoft Windows Insider program for Windows 11 Insider Builds and for Windows Server Insider Build to work with the newest features and getting experience before GA becomes available.

 JOIN the Azure Hybrid Community Group on LinkedIn

 


Leave a comment

#Microsoft Azure Arc enabled Servers managed with Windows Admin Center in #Azure #AzureHybrid #MVPBuzz

Microsoft Azure Hybrid Management

With Windows Admin Center in the Azure portal you can manage the Windows Server operating system of your Arc-enabled servers, known as hybrid machines. You can securely manage hybrid machines from anywhere–without needing a VPN, public IP address, or other inbound connectivity to your machine.

With Windows Admin Center extension in Azure, you get the management, configuration, troubleshooting, and maintenance functionality for managing your Arc-enabled servers in the Azure portal. Windows Server infrastructure and workload management no longer requires you to establish line-of-sight or Remote Desktop Protocol (RDP)–it can all be done natively from the Azure portal. Windows Admin Center provides tools that you’d normally find in Server Manager, Device Manager, Task Manager, Hyper-V Manager, and most other Microsoft Management Console (MMC) tools.

In the following steps we will install Azure Windows Admin Center (Preview) on a Microsoft Azure Arc enabled Server from the Azure Portal.

Click on Windows Admin Center (Preview) on the Left side.
Then click op Setup

Set the port.
Click on Install

Installing extension Windows Admin Center

At the Activity log you can follow the installation.

and See the Quick Insights

No Problems here 😉

Let’s Connect

Sign in with your Username and Password

 

Running Windows Admin Center from the Azure Portal.

Azure Windows Admin Center of the Azure Arc enabled Server.

PowerShell session remote on the Azure Arc enabled Server.

Events of the Azure Arc enabled Server.

Conclusion

With Microsoft Azure Windows Admin Center and Azure Arc enabled Servers you can manage your servers from anywhere.
You got all the benefits of Microsoft Azure Hybrid features. Try it yourself, Windows Admin Center is still in preview and for testing only.
You can experience this awesome Azure Hybrid solution before it goes in production 😉

 


Leave a comment

#MVPLABSerie Azure Update Management Center (Preview) and #AzureArc enabled Servers #AzureHybrid

Microsoft Azure Update Management Center (Preview)

Update management center (preview) is a unified service to help manage and govern updates for all your machines. You can monitor Windows and Linux update compliance across your deployments in Azure, on-premises, and on the other cloud platforms from a single dashboard. Using Update management center (preview), you can make updates in real-time or schedule them within a defined maintenance window. Here you can find more information about Azure Update Management Center

In the following step-by-step guide, we will start with Azure Update Management Center (Preview) and Microsoft Azure Arc enabled Windows Servers running on-premises in my mvplab.local domain.

With getting started you can configure the environment.

I start here with my Azure Arc enabled Storage Server.

You have options like Hotpatch

We Check manually for Updates on Windows Server mvpstore01
Click on OK for Assessment.

Here are the Windows Server Security updates.
You can click on One-time-Update
But first we look in Update Management Center.

Here you see the Pending Windows Updates in Azure Update Management Center
Open query 

Microsoft Azure Resource Graph Explorer can be really powerful tool

When you have to manage many Windows Servers you can get the status
of these Azure Arc enabled servers and export the results into a CSV file.
Here you find some Azure Resource Graph Explorer queries

Now we start to Install One-time Updates.

Include Update Classification
Click on Add

Click on Next

Select the option if you want to reboot or not.

Review and Install

Updates installed on the Azure Arc Enabled Windows Server.

In Azure Update Management Center Overview Dashboard
you can see that one machine is completed.

For Monitoring you can make your own workbooks.

I like this History, to see if updates are successful or not.

Conclusion

Microsoft Azure Update Management Center is still in Preview but it’s a new way to manage all of your updates on your Servers on-premises with Azure Arc enabled, or on Azure Cloud, but also in other Clouds if you want. One Update Management Center from the Azure Portal is Awesome to work with and gives you control and overview of your update compliance in your datacenter(s).
Important: This Great tool is still in preview and not for production environments yet until it’s made GA by Microsoft and you have the full support on this awesome management tool.

JOIN Azure Hybrid Community Group on LinkedIn

 


Leave a comment

#MVPLABSerie Azure Arc enabled Servers #AzureHybrid

Azure Arc Infrastructure overview

In the last blogpost of MVPLABSerie we learned how to add Servers from anywhere to Microsoft Azure Arc services to get the Azure Hybrid benefit with awesome features and Management tools. you can find that blogpost over here:

MVPLABSerie Azure Hybrid with Arc Enabled Windows Servers on-premises

So with this I have added my on-premises Windows Insider Servers to Microsoft Azure Arc:

Connected Azure Arc Servers

In the following steps we are going to add Windows Admin Center to the Arc enabled Windows Servers on-premises.
Here you can read more about Azure Arc-enabled Servers using Windows Admin Center in Azure (preview)

With Windows Admin Center in the Azure Portal you can manage the Windows Server operating system of your Arc-enabled servers, known as hybrid machines. You can securely manage hybrid machines from anywhere–without needing a VPN, public IP address, or other inbound connectivity to your machine.

Open Servers and open your Azure Arc Enabled Server.

First of all we have to add the right Role assignment.
Click on Access Control on the Left.
Click on Add => Add Role Assignment.

Here you have to add the following Role Assignment.
Windows Admin Center Administrator Login.
Add this to your account

When the account is done, then go to Windows Admin Center (Preview)
on the left panel. Click then on Setup.

Click on Install

Setup Successfully!

Now you can Connect your Azure Arc Enabled Windows Server.

Here we have my Storage Windows Insider Server in mvplab.local domain.
From here you can do your IT Management with WAC.

Remote PowerShell on Azure Arc enabled Server.

Microsoft Azure Arc Insights Monitoring and Log Analytics

For IT Management and troubleshooting, monitoring and getting Insights is important to act quickly to keep the business and IT solutions running. With Azure Arc Insights you can see with Maps the connections of the Windows Server.

Azure Arc Insights with Map.
See also the Quick Link to Connection details

This is a really cool overview of your connections.
Here you can see if you have a Malicious connection!

Microsoft Azure Arc Log Analytics is very Powerful
Here you find more information about Log Analytics

Here I do a Query on the Arc Enabled Server mvpstore01
Update Summary.

There are a lot of Log Analytics queries to play with and mark them as your favorite for your Arc enabled Windows Server 😉

In the following blogpost we will have a closer look at Microsoft Azure Auto Manage and Update Management Center for
Microsoft Azure Arc enabled Windows Servers. We will not forget Security with Azure Defender for Cloud coming in the next blogposts.

Conclusion

With Microsoft Azure Arc enabled Servers you get a Microsoft Azure Hybrid environment with Great features and solutions.
Some features are still in preview and not supported for production workloads, but you can test them now like I do with my mvplab.local
This new innovative technology is going fast forward for Azure Hybrid Services to Manage your Windows Servers, Azure Stack HCI Clusters or your Linux virtual Machines. Azure Arc rocks and you can connect Microsoft Azure Anywhere 🙂


Leave a comment

#MVPLABSerie Azure Hybrid with Arc Enabled Windows Servers on-premises #AzureHybrid #Winserv

Microsoft Azure Hybrid with Arc enabled Servers

the last MVPLABSerie blogposts was about Windows Servers Insider with mvplab.local domain and SQL Clustering on-premises :

Today every company wants to benefit from Cloud to achieve more for the business. Microsoft made Azure Arc to simplify governance and management by delivering a consistent multi-cloud and on-premises management platform.

Microsoft Azure Hybrid

In the following steps we are going to onboard the Windows Insider Servers and Windows 11 Insider Beta Virtual Machine which are running in mvplab.local domain into the Microsoft Azure Cloud. We will install the Azure Connected Machine Agent via a PowerShell Script in the next steps :

Login in the Azure Portal

1. Search for azure arc
2. Click on Azure Arc.

Getting Started with Azure Arc

Click on Servers and then Click on Add.

Here you can Choose for the right script.
I choose for Add Multiple Servers with a Service Principle.
Click on Generate Script.

Read the prerequisites access to port 443.
view Outbound URLs link.
Click Next

Select the right Azure Subscription and Resource Group.
Select your Azure Region.
Select Operating System
Select the Connectivity method.
Click on Next

If you don’t have a Azure Service principal, you can create one here.

Click on Create Service principal.

Create your Service Principal

Copy your Client ID and Client Secret !
You need this later.

Select the just created Service Principal.

Here you can Tag the Arc Servers.
Here you can read more about Tagging
Click on Next

Choose the Deployment method :
Basic Script or Configuration Manager ( I choose for Basic)
Download the Script

I have copied the script to my Domain Controller On-premises here.

Open with PowerShell ISE the OnboardingScript.ps1
and Copy / Paste your
Service Principal Client ID and Secret here in the Script.
Click on save and run the script.

Start PowerShell in Admin modus

Run Script .\OnboardingScript.ps1

Server is connected with Azure 🙂

Here is the Azure Arc Enabled Server, my Domain Controller.

Here I have all the Azure Arc Capabilities available for my Domain Controller.
Azure Hybrid

With the Same Script I added the mvplab.local Windows Insider Servers to Azure
They are all Azure Arc Enabled Servers.

On all Azure Arc enabled Servers is the Azure Connected Machine Agent installed.

Conclusion

In a simple way you can deploy Azure Arc agent on your on-premises Servers to make them Azure Arc Enabled so you can enjoy the Azure Hybrid features from the Cloud. IT management and Security from Azure becomes available for your on-premises Servers.
It’s not only Infrastructure but also Data Services and Application Services what you can use for your Azure Hybrid Solution.
In the next Blogpost we will have a look at the Microsoft Azure Arc Features in my mvplab.local domain.


Leave a comment

Windows Admin Center and Deploying Windows Server Insider Build 25099 Core #WindowsAdminCenter #Winserv #WIMVP

Windows Admin Center Version 2110.2 Build 1.3.2204.19002

Windows Admin Center is a customer-deployed, browser-based app for managing servers, clusters, hyper-converged infrastructure, and Windows PCs. It comes at no additional cost beyond Windows and is ready to use in production. Learn more about Windows Admin Center.

Benefits

  • Simple and modern management experience
  • Hybrid capabilities
  • Integrated toolset
  • Designed for extensibility

Languages
Chinese (Simplified), Chinese (Traditional), Czech, Dutch (Netherlands), English, French, German, Hungarian, Italian, Japanese, Korean, Polish, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Swedish (Sweden), Turkish

In the following step-by-step guide I will deploy Windows Server 2022 Insider Build 25099 Core Edition with Windows Admin Center tool together with some great features for managing Windows Servers in a secure hybrid way with Microsoft Azure Cloud services. Like Azure Defender for Cloud, Azure Backup Vault, Azure Monitor, Security and more.
So I have Windows Admin Center 2110.2 installed and I have a Windows Server 2022 Hyper-V Server for my Virtual Machines in my MVPLAB Domain.
Now we will deploy the new Windows Server 2022 Insider Preview Build 25099.

In WAC on my Hypervisor in Virtual Machines

When you explore and open your Hyper-V Host and go to Virtual Machines, you can Click on Add and then on New for Creating your Windows Server Insider VM.

Create a New Windows Server Insider VM called StormTrooper01

Here you can configure your new Windows Server 2022 Insider VM with the following :

  • What kind of Generation VM (Gen 2 Recommended)
  • The path of your Virtual Machine and the path of your virtual disk(s)
  • CPU and you can make nested Virtualization too
  • Memory and use of Dynamic Memory
  • Network select the Virtual Switch
  • Network Isolation by VLAN
  • Storage, Create the size of the Virtual Disk. Choose an ISO or Select an existing VHD(x)

I Created a New 70GB OS Disk
and I want to Install the New Windows Server Insider OS from ISO.
Click on Browse

Here you Browse Default on your Hyper-V Host and select the ISO.

When the Windows Server ISO is selected you can hit Create

We get the Notification that the virtual machine is successfully created.

Only the Virtual Machine is now made with your specs and visible on the Hyper-V Host.
Select the New Virtual Machine (StormTrooper01) click on Power and hit Start.

After you started the VM, you can double click on it and go to Connect.
Click on Connect to the Virtual Machine.

Now you are on the console via VM Connect.

Click on Install Now

We are installing Windows Server 2022 Insider Core edition, because we have WAC 😉

Installing Windows Server 2022 Insider Core Preview Build 25099 via Windows Admin Center

Create New Administrator Password.

And here we have Sconfig of the Windows Server 2022 Core.
via Virtual Machine Connect.

Now we can add and connect the New Virtual Machine with Windows Server 2022 Insider Preview Build in Windows Admin Center via IP-Address.

The Next step is to join the Windows Server 2022 Insider to my Domain MVPLAB.

Click on the Top on Edit Computer ID
Click on Domain and type your domain name.
Click op Next
Add your administrator account for joining the server
Reboot the VM.

Windows Server 2022 Insider Preview Core edition is domain joined.

Now we have the New Microsoft Windows Server 2022 Insider Preview Build 25099 running in Windows Admin Center, we can use all the tooling provided by WAC also in a Azure Hybrid way. Think about Azure Defender for Cloud, Azure Monitor. In Microsoft Windows Admin Center we also have a topic Azure Hybrid Center :

Here you see all the Azure Hybrid benefit features for your Windows Server 2022 Insider.

  • Microsoft Azure Arc
  • Azure Backup
  • Azure File Sync
  • Azure Site Recovery
  • Azure Network Adapter
  • Azure Monitor
  • Azure Update Management
  • and More…

Microsoft Azure and the Windows Admin Center Team made the wizards customer friendly and easy to get those Azure Hybrid services for your Windows Server.
When you have your Server running, you want to make backups and Monitoring your Server for management. And after that you want to be in control of your security of your new Server. In the following steps you see some examples on the same Windows Server 2022 Insider Preview Build:

Microsoft Azure Backup via WAC

Click on Azure Backup
Select your Azure Subscription and the Azure Backup Vault.
Select your data and make the schedule.

Enter the Encryption passphrase and Apply.

Here you have Azure Backup Vault working together with WAC.

Azure Defender for Cloud Security

Click op Microsoft Defender for Cloud
Click on Setup
Add the right Azure Subscription and Workspace
Click on Setup.

Configuring Azure Defender for Cloud agent and Subscription.

Azure Defender for Cloud in Windows Admin Center on your Windows Server 2022 Insider Preview Build.

In Windows Admin Center there is also a Security tab for the Windows Server.

Here you can see your Secured-Core status

Here you can see if your system is supported for this security features 🙂

Enable the supported features and Restart de Virtual Machine.

And here you see my status overview.

Further more you can manage RBAC in Windows Admin Center when you have to work with different kind of users.

You can find RBAC in settings.

Conclusion

Windows Server Insider Core edition and Windows Admin Center are working better together! You have all the tools you need to startup your Windows Server and
manage it with WAC. Windows Admin Center is getting better and better to manage your Hybrid Datacenter and keep you as an Administrator in Control!
So is how I manage my MVPLAB but also for Production workloads I use Windows Admin Center and the Azure Portal together. With Microsoft Azure Arc Services
Azure Hybrid becomes your solution where Windows Admin Center can Support you with making Azure Stack HCI Clusters with Azure Kubernetes for your DevOps environment.

Windows Admin Center Community Group on LinkedIn


Leave a comment

Windows Admin Center v2103 Available! What’s New #Winserv #Azure #Management #WindowsAdminCenter #MVPBuzz

Windows Admin Center v2103

With Windows Admin Center you can remotely manage Windows Server running anywhere—physical, virtual, on-premises, in Azure, or in a hosted environment.
The tool, available with your Windows Server license at no additional charge, consolidates and reimagines Windows OS tools in a single, browser-based, graphical user interface.
At Microsoft Ignite 2021 Global Virtual Event they launched Windows Admin Center version 2103. Here you find the download.

What’s New in Windows Admin Center v2103

WAC Updates Automatically

Events Tool ReDesign (Preview)

Great Overview of the Server Events 😉

Azure IoT Edge for Linux on Windows

Windows Admin Center in The Azure Portal 

Set Proxy Server in Windows Admin Center Settings.

Open in a Separate Window

This is a Separate Window on my Second Screen, this works Awesome!

Windows Admin Center Virtual Tool improvements 🙂

Conclusion

Microsoft is working hard to make Hybrid IT Management better for Administrators to manage Hybrid Cloud datacenters. Windows Admin Center is a must have for managing
Windows Server Core, AzureStack HCI, and Cluster Services. I can say: I love to work with Windows Admin Center 🙂

 

When you have feedback for the Product Team please do that here at User Voice


Leave a comment

Today is Microsoft Ignite 2021 Event of the Year #MSIgnite #Azure #Cloud #AzureStackHCI #Winserv and More

JOIN Microsoft Ignite 2021 Event

You don’t want to miss this Live Awesome Virtual Global Event of Microsoft 😉