Categories
Application Resiliency Cloud Computing Disaster Recovery

Application Resiliency

Where I work, we currently use a third party SSO provider to access most of the day-to-day applications we use. When I went this morning to log my hours for the week, I got a Server 500 error! Unfortunately, the cloud SSO provider was offline. This, it turns out, was due to an AWS failure […]

Categories
Cloud Computing Information Security

Azure Security Center

As organizations increasingly move data and services to Azure, it can be difficult to assess whether the services are implemented in a secure fashion. Many of the traditional datacenter security good practices apply in Azure, but they don’t necessarily translate in an obvious way. Moreover, with the ease with which an administrator can add resources, […]

Categories
Information Security

Azure AD Pass-Through Authentication

One of the features that I’m really excited about, announced at Ignite, is Pass-Through Authentication for Azure AD. Many customers feel the need to install AD FS in their environment to provide single-sign-on and consistent authentication for their users, or they have a security (audit, authentication barrier) or HR (enforce logon hours) need to perform authentication via their domain controllers. […]

Categories
Cloud Computing Cloud Migration Information Security

Key Vault and Disk Encryption

I have some follow-ups to my previous post on disk encryption in Azure, after I attended BRK3277 – Protect your data using Azure’s encryption capabilities and key management. I learned some interesting tidbits about how this works – the presenter is the owner of the functionality within Microsoft, so I’d consider his information to be authoritative. There’s […]

Categories
General Information Security

“Defending the New Perimeter” – eBook Review

I was privileged to be asked to review an advance copy of the eBook recently released by Pete Zerger and Wes Kroesbergen on the subject of Information Security. Targeted at an executive audience, the eBook discusses the current state of information security and the challenges that face the security officer in the current environment. It […]

Categories
Cloud Computing Information Security

Encrypting a Virtual Machine in Azure

Note – Update 2018-11-13: The Azure team has released a new disk encryption method that is much less complex! You can read more about it here: https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption-overview This post will walk you through the configuration necessary to encrypt a virtual machine’s hard drives in Azure. This post applies only to Windows VMs running in Microsoft Azure; […]

Categories
Conference Update

Ignite 2016 Post-Conference Summary

Last week, I was in Atlanta for the Microsoft Ignite conference! I had wonderful plans for making a few blog posts during the conference, but that didn’t happen. I’m in awe of those who were able to post great blog posts while participating in the conference, but between information overload, the wonderful fitness regimen that the […]