by

How to Setup a Private Network Connection to your Office 365 ?

Here’s a question I get quite often during my compliance and data protection presentations. I thought about writing this post so I can easily redirect folks here. I am all about reusing explanations Smile

Is it Possible to Have a Secure Tunnel Connection to SharePoint Online? My Own Private Connection?

Yes, it is. Using Express Route. Not only to SharePoint Online, but to the whole Office 365. I would say, 80% of the time when folks are looking for this answer is because they are talking about a hybrid environment where they want to integrate their SharePoint on-premise with SharePoint Online and normally involved handling sensitive data.

image

What is Express Route and What it Does?

ExpressRoute initially was an Azure-only solution that got expanded to Office 365. It’s goal is to establish a private and managed connection to Office 365. What it does is to provide a dedicated network connectivity through a private connection from their (users) network to Microsoft Azure or Office 365.

How Does it Look Like from a Helicopter View?

Here’s a simple diagram of how ExpressRoute can be used with Office 365.

image

Will Having my Own Private Network to Office 365 Impact Performance?

Yes and No. Network performance will be as predictable as your own on-premises environments, it is up to you then to take care of your own network performance, of course. In some ways this is like having an Office 365 environment in your own datacenter.  One added benefit you will certainly have is that using ExpressRoute most Office 365 network traffic can be configured to avoid the public Internet, providing additional data privacy. And here is your answer for privacy and sensitivity concerns.

As usual, your data is still your data.

Who Are the Best Candidates to Use Express Route with Office 365?

Organizations that require a higher class, premium managed connectivity to the cloud. Governments also can use it. Actually Microsoft did this as a development of the famous Safe Harbour case issue.

What if my Company has Multiple Locations Across the Globe?

No worries. ExpressRoute offers something called “circuits” that applies the traffic to different geographic locations with redundancy and geo-resiliency.

image

Explain a Bit More What these Circuits are…

OK, so these ExpressRoute Circuit are geographically distributed connections that delivers by default 2 active physical connections for high availability. The networking elements are still backed by Microsoft’s connection uptime SLA (99.9 %). On a cool note, as of today, Microsoft is the only public cloud provider to offer this level of guaranteed availability for the connection. An additional benefit is that if you have Azure applications, you can this same single ExpressRoute connection.

image

 

How Do I Buy ExpressRoute?

There is no additional licensing costs to use ExpressRoute, however not everyone can guarantee these circuits for you, so you will have to work with the Microsoft Cloud Approved Providers. These guys can guarantee the premium network connectivity required by Microsoft and they have their own price list. Here’s a list of the MS Cloud Approved Providers for your query.

I Want It!! What Should I Do?

Network capacity plan. I mean, you are deciding to setup your own private connection to the public cloud, you’ve got to do your homework Smile Here’s a good link with some guidelines for your network infrastructure plan then contact one of the Approved Providers.

Good Luck. If you’ve done an ExpressRoute for Office 365 project, share your thoughts with the wider community. Love to hear from you.

See ya!

by

InfoPath on SharePoint Online error: “This form cannot be opened in a web browser. To open this form, use InfoPath”

Here’s an annoying error you might experience when using InfoPath Forms with Office 365 (SharePoint Online).

infopath-office 365-this form cannot be opened in a web browser-use infopath-

So to save your time, let’s go straight to the solution:

Enable Form Rendering in the Office 365 Admin Console

Go to your Office 365 Portal (http://portal.office.com) and choose Admin console.

infopath-office 365-this form cannot be opened in a web browser-use infopath- (1)

infopath-office 365-this form cannot be opened in a web browser-use infopath- (2)

infopath-office 365-this form cannot be opened in a web browser-use infopath- (3)

Then Enable Form Templates Rendering for Browsers

You will see a warning about InfoPath being discontinued in the future, don’t worry about it for the moment, this is another discussion. For now, you just want to get this done.

infopath-office 365-this form cannot be opened in a web browser-use infopath- (4)

infopath-office 365-this form cannot be opened in a web browser-use infopath- (5)

 

Re-publish Your InfoPath Form Again

Now, what you have to do is to:

  1. Close your browser session
  2. Republish your InfoPath Form

Note that at the end you will see Security Level: Domain. If you see this, it means it worked. Previously you would see Security Level: Restricted.

infopath-office 365-this form cannot be opened in a web browser-use infopath- (6)

That’s it! I hope this was helpful to you and saved you a couple of hours banging your head against the Surface keyboard Smile

by

How is Machine Learning Used in Cyber Security?

Also posted at Quora

image

Let's start with 2 points:

  1. The objective of cyber security (strategy) is not to avoid 100% the attacks, something unattainable; but to reduce the "attack surface" to a minimal.
  2. the number of attack perpetrators will be always bigger than the number of people trying to protect against attacks.

With that in mind, several companies discovered soon enough that fighting for protection was becoming an ever increasing ($$) exercise. The biggest security/infrastructure firms (symantec, mcafee, palo alto, checkpoint etc) united to work in common initiatives, such as developing web apps against DDoS attacks (web apps not in the sense of website but in firewall webapps, also called next generation firewalls).

 

The SecIntel Exchange

Now, a very important concept here to remember: They do not exchange their solutions, they do exchange their attacks. That's a very important point. This is called SecIntel Exchange. The whole idea behind this is: To understand how attacks are done and what types of exploits are there, we need to increase our catch network, so they can be aware of attacks BEFORE they become a real worry.

OK, now that these companies found a common protocol to receive and analyze their attacks, and are able to collect information about what's going on out there in the wild, each company go about and find solutions appropriate for their own products. This is a great strategy, defend as a stronghold, attack as a militia. However, another challenge comes up: Slowly but surely this process is also becoming time-consuming and expensive. In short, it does not scale. Remember, while a company has a team of 10 people to protect, the world always will have thousands working 24x7 trying to break it. (that also explains why Linux/Unix systems don't have as many vulnerabilities as Windows for example, but that's another topic)

 

image

 

The Machine Learning Angle

Good. Now that's when machine learning (ML) comes in nicely!  In conjunction with other technologies (virtual machines, test simulators, honey pots etc) machine learning algorithms can pick up the information collected by the SecIntel and QUICKLY SCALE the analysis process. What used to take 2 days for an InfoSec team to understand, takes 1 day for an ML algorithm to understand...but that's not the main benefit of ML. The main benefit is that the ML algorithms will learn and predict based on experience and results. It means that today it takes 1 day, tomorrow it will take 20 hours, the next day it will take 12 hours and so on. ML by "learning and predicting" effectively scale the effort to a level human teams cannot do, specially when dealing with automated tasks.

 

A Real World Analogy

Imagine when you do blood tests if your blood had to be analysed individually. It would take weeks before you get your results not because the process is slow but mainly because the queue to get to you will be too large and by then the effort to get the results could be potentially wasted. By scaling the effort, ML will free up the InfoSec teams to focus in the higher ground and strategy trying to be one step ahead of the game.

It is about scale and quick response to market.

images credits: @msau

by

I Am Presenting at the Azure Smorgasbord in December 2015

How does your day look like on December 9th 2015?

Come join me a Microsoft to discuss and share ideas about IoT, Azure and Office 365 in Australia.

iot edge

 

Session Name: “IoT - The Invasion of Australia”

Abstract: “Five million new IoT devices will come online every day in 2016. Do you want a piece of this 50 billion dollar cake? Join Edge Pereira to discuss a use case of IoT in Australia and why we are in a prime position to lead the world in this area.”

Click here to register

 

Where Can I Find the Presentation Slides?

You can find the slides for this presentation here.

by

Hour of Code 2015. I am Volunteer. Again.

Once again this year I am volunteering time for the Hour of Code. And proud of it. Listen what Bill Gates, Mark Zuckerberg, Jack Dorsey and others have to say about this event.

 

 

What is the Hour of Code?

Launched in 2013, Code.org is a non-profit dedicated to expanding access to computer science, and increasing participation by women and underrepresented students. The vision is that every student in every school should have the opportunity to learn computer science. Code.org believes that computer science should be part of core curriculum, alongside other courses such as biology, chemistry or algebra.

 

Untitled

When It Happens?

Volunteers from all over the world help local teachers and their classes during the Computer Science Education Week that happens every year in December. This year it will be from December 7th to 13th.

 

How Can You Help?

We have this year 13.000 requests from teachers from all over the world, but only 4.000 volunteers. We need volunteers to help with the activities and help the teachers. Here are a few things you can do also to get involved:

  1. Recruit co-workers to volunteer:  Blog, share, tell your friends and co-workers about the Hour of Code and ask them to sign up as a volunteer.
  2. If you know someone who’s a volunteer, connect them with people who wants to setup Hour of Code parties.

 

I Want to be a Volunteer. What Do I Need to Do?

To get a better idea about what your volunteer experience will be like, have a look at this guide. There's also some extra tips about how you can get your employer and community involved with the Hour of Code.

 

If you know anyone needing help with it, feel free to connect with me. Remember: I am a volunteer! Smile

by

Infrastructure Saturday 2015 Social Media Stats #infrasat

We’ve just done another successful Infrastructure Saturday event. It takes a lot of time and passion to setup personal time aside and to organize such an event. This is an annual event totally built and sponsored by the community, so the people you find there (attending, organizing or presenting) are 100% committed to the cause. Big shout for the guys organizing: Alan Burchill and Shane Hoey

Below are some of the social media stats collected during the last week up to the event day. This years top contributors were: JustBroady, superedge, david_obrien, pzerger, cloudtidings, bneusergroup, alanburchill, twalex2, blkchninstitute, reecestewart4

If you’ve been to the sessions, thank you very much. I hoped you enjoyed and see you next year.

imageimage

image

image

 

image

image

image

image

image

image

image

 

Top Links about the #infrasat Infrastructure Saturday 2015 Event

  1. https://www.flickr.com/photos/alborath/albums/72157660731316669
  2. https://twitter.com/DigitalGlobe/status/667834517428682752
  3. https://code.visualstudio.com
  4. http://www.infrastructuresaturday.com/
  5. http://www.superedge.net/2015/11/ethereum-blockchain-service-bitcoin.html
  6. https://lnkd.in/b_GeEXZ
  7. https://lnkd.in/bk9tVcN
  8. https://doc.co/75WgEz
  9. http://www.linkedin.com/pulse/want-increase-privacy-protection-your-cloud-data-worries-edge-pereira
  10. http://www.infrastructuresaturday.com
  11. http://infrastructuresaturday.org
  12. https://lnkd.in/buajN7R
  13. https://lnkd.in/bkYJbY4
  14. https://lnkd.in/bBgh534
  15. http://www.superedge.net/2015/11/infrastructure-saturday-2015-australia.html
  16. https://lnkd.in/bhp3pyZ
by

Azure DevTest Labs Now in Preview

Busy week for Microsoft Azure. Another feature comes in preview today: Azure DevTest Labs

image

What it is ?

Azure DevTest Labs gives developers on-demand self-service for Azure-based test environments. With DevTest Labs developers can:

  • Quickly provision development and test environments.
  • Minimize waste with quotas and policy enforcement.
  • Set automated shutdowns to minimize costs.
  • Create a VM in a few clicks with reusable templates.
  • Get going quickly using VMs from pre-created pools.
  • Build within Windows and Linux environments.
  • Integrate directly with your preferred CI tool, IDE, or automated release pipeline.

A really cool feature is that the Dev VMs can be saved as templates and reused across organizational teams  of developers.

image

How Much it Costs?

Azure DevTest Labs is a free service. However, you will be charged for other Azure resources that are created in the Lab. For example, you will be charged for the virtual machines that are created in the DevTest Labs per our virtual machine.

See this new product here at the Azure DevTest Labs webpage

by

Azure Disk Encryption Now Available

Brand new feature deployed today on Microsoft Azure as preview: Disk Encryption

About Azure Disk Encryption

Azure Disk Encryption for virtual machines (VMs) is the answer to many organizations that could not have VMs running in the cloud mainly due to security and legislation compliance requirements.

image

 

What it Does?

What this technology does it to encrypt the VM disks, including boot and data disks, with keys and policies which are controlled in the Azure Key Vault.

image

 

It Works for non-Windows Systems

Disk Encryption for VMs works for both Linux and Windows operating systems. It also uses Key Vault to safeguard, manage, and audit the use of disk encryption keys. All the data in your VM disks is encrypted at rest using industry-standard encryption technology in your Azure Storage accounts.

image

 

What Encryption is Used?

Windows VMs uses BitLocker and the Linux VMs are using dm-crypt

 

How Much it Costs?

This is at no charge. Gratis! The reason for that is because this is brand new and still in preview mode. Microsoft is expected to start charging for it in some way when the product becomes live. Meanwhile it is a great opportunity for you to start playing around with it and testing your systems.

by

I’m Speaking at the Infrastructure Saturday 2015 Australia

Once again I am honoured to be part of the Infrastructure Saturday event in Australia. This is such a great opportunity to connect with the local IT community and talk about tech and experiences with a local flavour and feel.

Session Details

  • Title: “When a data breach happens, what’s your plan ?”
  • Abstract: Ashley Madison, Sony, Kapersky Labs, LastPass, CentreLink, G20 event in Brisbane…What do they all have in common? They were victims of data breaches. And as you probably know by now, some were handled better than others. In this session we will talk about strategies, from mitigation to handling, used when a data breach happens (not “if”) and what controls do we have if you are using Office 365.”
  • Local: Microsoft Offices, George St, 4000, Brisbane, Australia

 

Where Are the Slides?

You can find the slides here

 

Looking forward to talk about this topic!! Below are some of the art done to promote my session. Loved the work Smile

image

edge-pereira-infrastructure-saturday-2015-1

image

edge-pereira-infrastructure-saturday-2015-2

by

List of the Most Common Passwords

Ah the joys of working on a specialized cloud security company. This list got to my hands and I am quickly circulating them with you. These guys do a lot of pen testing, network and cloud vulnerability assessment, cloud assurance etc.

Is any of these your current password somewhere? I hope not! Smile

image

Full list you can get it here

by

Microsoft to Store Data in Germany. Make it Harder for Foreign Authorities. Safe Harbour Lesson #1.

Here’s a way to increase your data protection from US government access: Store it in Germany!

As you probably know, in October 2015 the European Court of Justice declared invalid a "Safe Harbor" agreement between the European Union and the U.S. that allowed Facebook and other firms to transfer data in huge quantities to their servers in the U.S.

The court threw this deal in the bin because it was worried about "mass indiscriminate surveillance and interception" of personal data by the U.S. authorities.

And that’s what’s Microsoft is proposing: to make it harder for Government authorities to put their hands in people’s data.

image

 

Why Germany?

After the whole saga between Microsoft vs. USA Justice Department, European consumers, rights groups and lawmakers have expressed concern about what U.S.-based companies share with American authorities.

image

The European Union has very rigorous rules to protect data, and Germany's regulations are considered especially strict. Besides that EU authorities have been clamping down on data protection in recent months over concerns about mass spying by U.S. intelligence services. Especially after the revelations made by former NSA contractor Edward Snowden that the U.S. spied on German officials, including Chancellor Angela Merkel, angered Berlin.

 

Where Will the Datacenters be Located in Germany?

They will be in Magdeburg and Frankfurt. These new datacenters will maintain the same level of expectations , security, service and quality standards as all Microsoft datacenters globally. The services offered will abide by the Microsoft trusted cloud principles of security, privacy, control, compliance and transparency, as well as consistency with Microsoft’s global cloud services.

image

The reason for 2 datacenters is to ensure business continuity. Also their data will be exchanged through a private network to ensure data resides in Germany even in transit.

 

What is Planned to be Stored in Germany?

As part of this big initiative, Office 365 customers will soon be able to choose to store all data from the following products in Germany:

  • Azure,
  • Office 365 and
  • Dynamics CRM Online

 

Who Will Oversee this Data?

Deutsche Telekom will be the assigned data trustee and will control and oversee access to all customer data.

 

What is a Data Trustee?

Data trustee is an entity that will handle data on your behalf. In this case, it will be a company called T-Systems, which is a subsidiary of Deutsche Telekom. It means that Microsoft will not be able to access this data without the permission of either:

  • customers or
  • the data trustee itself

and if permission is granted by the data trustee, will only do so under its supervision.

This is ground-breaking stuff. Never done it before in Europe and after the repercussion of the Safe Harbour case, this service is expected to grow rapidly.

 

What are the Impacts on Compliance for Customers?

These new cloud services in Germany will specifically address organizations and enterprises operating in data-sensitive areas such as the public, financial or health sector. The immediate effect on this is positive: Now you can even choose the datacenter within the EU jurisdiction which will translate in a better granularity of controls.

We are talking about the German Government which traditionally have a very high level of data handling regulations and security by default. As a matter of fact, Germany is one of the leaders in this quadrant. Together with Customer Lockbox, customers will be able to view how and where data is processed.

 

Will this Avoid the US Authorities to Access my Data?

Honestly, No. Any government that requires access to data stored in the cloud, regardless of the provider (Microsoft, AWS, Google etc) will get this access. In a fight between governments and private companies, governments always win.

However this move will make it increasingly harder for governments to have this access. And that’s the main goal here. It is not to block the access, but to put stronger controls around data access by other people except the data owner.

This move will be likely followed by Amazon and Google very soon.

 

Sounds Great! When Can I Move my Data to Germany?

There is a LOT of ground work to cover. Involving auditing, certifications, and buildings construction. Microsoft is releasing this information now to calm-down the nerves of some big customers. The expected timeline for availability will be around the 2nd semester of 2016

Read the official announcement here from Microsoft Europe.

by

CheckList to Buy an Used iPhone

I am in the market for a new phone. Got tired of my Windows Phone, which I gave so much love for years but unfortunately the market didn’t care for it. Windows Phone is like a beautiful princess locked in a castle that noone knows where it is.

I am going for an iPhone. You can’t beat its app store. Nowadays people don’t buy phones, they buy the app store.

I am thinking about buying a 2nd-hand device so I listed a few things to check when I found one and I am sharing these tips here with you. Hope it helps you as well if you’re in similar situation.

Here are my 9 checks to perform a good smoke-test on the device you want to buy:

  1. Check for Warranty and Support Status
  2. Check the iPhone Activation Lock Status
  3. Examine the Device
  4. Test the Display
  5. Access the Internet over Wi-Fi and Cell Network
  6. Make a Call and Send a Text to a Friend
  7. Take a Picture and Make a Movie
  8. Check the Battery
  9. Disassociate the Device from iCloud

And now let’s go into more details on how to check them.

1) Check for Warranty and Support Status

If the phone you’re buying is sold as “under warranty”, make sure it is.  Enter the iPhone serial number into the Apple’s site to see the report. You can check this here. 

image

2) Check the iPhone Activation Lock Status

Before transferring ownership of an iPhone make sure the Activation Lock has been disabled and the device is ready for the next user. This also applies for iPad, iPods and Apple Watches. You can check this here.

image

Note: Once an IMEI is blocked, let’s say due to theft or lost device,  it cannot be undone. It means the device has officially become a brick. With no use for noone except the recycling company. So if the IMEI is locked here, don’t bother testing anything else…actually, you CAN report it to the police.

3) Examine the Device

Scratches, chipped glass, dock connector. Then plug the phone in a charger to make sure it will take a charge. Listen to music through the headphones. Use the headphone’s controls to navigate music and volume.

4) Test the Display

This is tricky as well. Make sure you are in a place with good natural light when inspecting the phone screen. Visit this website iPhone Dead Pixel Tester to test for dead pixels. Make sure the screen displays a solid colour and it does not have any stuck pixels that won’t go away.

image

5) Access the Internet over Wi-Fi and Cell Network

Go and browse places like news or weather sites because they have tend to have small local caches.

6) Make a Call and Send a Text to a Friend

This is to make sure the phone perform trivial tasks as expected. During the call, put the volume up and down. Pay attention how you communicate with your friend and check if the call behaves as expected.

7) Take a Picture and Make a Movie

Make sure the photo does not look weird, too dark or too bright or have fuzzy spots.

8) Check the Battery

Go to  Settings/General/Usage and check the time when the device had the last full charge. This is a bit tricky, but once you have the phone use it as much as you can and see if you are getting the battery duration expected.

9) Disassociate the Device from iCloud

Hopefully you won’t be buying a stolen iPhone so make sure the current owner disassociates the device from the iCloud account otherwise you won’t be able to login using your credentials and activate your new phone. See how to do this here.

image

If you find out later that the previous owner did not disassociated it properly or he/she doesn’t know how to do it, ask him/her to go to iCloud, login and remove the device from their account. They can do this by going here.

image