Month: October 2024
VHD Compact Disk – Deleting whole profile
“Disk was compacted: true. Logoff time increased by 34375 milliseconds. Disk size reduced by 81792 MB. (VHDPath: \*.file.core.windows.netfslogixprofiles*.VHDX)”
Not sure why this is happening, Just wipes the entire profile during the compaction process, No obvious cause
”Disk was compacted: true. Logoff time increased by 34375 milliseconds. Disk size reduced by 81792 MB. (VHDPath: \*.file.core.windows.netfslogixprofiles*.VHDX)” Not sure why this is happening, Just wipes the entire profile during the compaction process, No obvious cause Read More
Windows 11, version 24H2 | Security, experience, performance, and migration updates.
Enhance security, performance, and user experience with Windows 11, version 24H2. Keep your data and identity protected with features like personal data encryption, Windows Hello with passkeys, and Windows Studio Effects. Built-in AI capabilities, including live captions with real-time translation and advanced video call enhancements, leverage powerful NPUs for seamless, efficient performance. Whether you’re a business professional or a creative, Windows 11, version 24H2 offers significant improvements in productivity, energy efficiency, and multitasking capabilities.
Deployment and migration to Windows 11, version 24H2 is straightforward, ensuring compatibility with most existing hardware and peripherals. Tools like Windows Autopatch and Windows Autopilot, integrated with Microsoft Intune, streamline the update and provisioning processes, making device setup and compliance effortless. Jeremy Chapman, Director of Microsoft 365 shares how Windows 11, version 24H2 ensures your organization stays secure, productive, and ready for the future.
Windows 11, version 24H2 updates are here.
Scrollable quick settings menu, Wi-Fi 7 support for faster connectivity, and enhanced File Explorer with text labels for easy file management. Take a look.
Boost performance and efficiency.
Improved battery life, superior video playback, and enhanced productivity. See it here.
Streamline your migration from Windows 10 to Windows 11.
Enhanced Windows update, deployment, and migration tools using Windows Autopatch. Automate device provisioning for an out-of-the-box setup, ensuring compliance with policies using Windows Autopilot. Get started.
Watch our video here.
QUICK LINKS:
00:00 — Windows 11, version 24H2
00:51 — Personal Data Encryption
02:20 — Windows Hello with passkeys
03:26 — Default proactive protection
04:01 — Windows 11, version 24H2 Updates
05:35 — Accessibility updates
06:03 — AI capabilities- live captions
07:13 — Built-in AI — Windows Studio Effects
08:29 — Performance and efficiency
09:13 — Deployment and migration
10:25 — Windows Autopatch
11:36 — Windows Autopilot
12:29 — Wrap up
Link References
Get started at https://aka.ms/Windows11Enterprise
Unfamiliar with Microsoft Mechanics?
As Microsoft’s official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
Keep getting this insider knowledge, join us on social:
Follow us on Twitter: https://twitter.com/MSFTMechanics
Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
-Windows 11 24H2 is here, and today, we’ll take a deeper look at what’s new in this release of Windows, from the experiences to new admin controls, including the latest security enhancements exclusive to Windows 11 with additional data encryption options and phish-resistant strong authentication to help protect you from evolving threats. Then experience updates everyone will see in 24H2 spanning the system tray, File Explorer, improvements in connectivity, and more.
-Then, for Copilot+ PCs, we’ll explore new integrated AI options using on-device models with Windows Studio Effects, and if your PCs are currently running Windows 10, we’ll show you how things have improved to manage your migration and your options to extend security updates if you need more time. So let’s get into this, starting with security. Here, it’s worth noting that Windows 11’s existing security improvements with credential safeguards, malware shields, and application protection have already led to a reported 58% drop in security incidents, including a 3.1x reduction in firmware attacks. That said, with the threat landscape evolving faster than it ever has, there are a number of new Windows 11 security protections lighting up in 24H2.
-First, to better protect your files, personal data encryption is a new capability for Windows 11 Enterprise and EDU editions that relies on Windows Hello for business authentication. It creates a unique key for each user profile’s desktop, documents, and pictures folders. Protection is indicated by the lock icon, making files only readable during an active user session, and it works independently of BitLocker or any other volume-level encryption as additional protection, and if a PDE-enabled device is shared or has multiple user accounts, even if another user is a local administrator on that device, while they can see folder and file names, they won’t be able to decrypt and view the contents of those files. They’re locked. Personal data encryption can be enabled on Microsoft Intune-managed devices via policy. Then, once enforced, encryption can take up to seven days to complete, and processing happens during the defined device maintenance window to avoid productivity impacts.
-And for increased protection against credential theft without compromising convenience, Windows Hello is now extended to work with passkeys for more secure phish-resistant multi-factor authentication when accessing apps and websites. When you register with an online service or set up your device with a Microsoft Entra account using a passkey, Windows generates a new cryptographic key pair where the private key is stored securely on your device and the public key is registered with the online service.
-Then, to authenticate, your Windows device first proves that it possesses the private key, which can only be used after you unlock it with Windows Hello using your face, fingerprint, or PIN. Additionally, for PCs that come with 24H2 pre-installed, when you set up or use Windows Hello, your credentials are more protected by default using virtualization-based security, which isolates credentials while generated and in use in a secure container outside of the running operating system, so even if you just use a PIN, that’s also stored in the secured container. That means this works from devices with or without built-in biometric sensors. Windows 11 24H2 devices also add default proactive protection against malware-based credential theft. Local security authority protection is now on by default. This prevents untrusted code from running and accessing LSA memory where credentials can be stored. It helps prevent increasingly common malware attacks where app tokens are stolen as you sign into sites and services and transferred to another device in order for it to gain access to resources in what’s known as a token replay attack. So those are just a few security-based highlights.
-With that, let’s move on to the Windows 11 experience updates and what’s new for 24H2 that everyone will see, followed by the AI-powered experiences available for Copilot+ PCs. Starting in the system tray, Windows adds a scrollable view of quick settings. Instead of editing the list to add new quick actions, you can scroll through the list and rearrange them. From quick settings to extend battery life, you can enable or disable energy saver, which works even when PCs are plugged in, in case you want to conserve energy at any time. For Wi-Fi quick settings, we’ve added a new refresh button where you can now trigger a scan of available Wi-Fi networks that are within range. If your device supports it, Windows 11 24H2 also can connect to Wi-Fi 7 networks, which are up to four times faster than Wi-Fi 6, and by the way, Wi-Fi 7 also supports multi-link operation, ultra-wide bandwidth for high-bandwidth scenarios like virtual and augmented reality, and 4096 QAM for improved video streaming. Now this will also speed up connectivity for file transfers. In fact, in the task bar, once you’ve started a longer process like a file transfer, a download, or a video render, with the new thin line representing 100% percent, you’ll be able to more easily gauge progress, and one more thing to point out for the files themselves in File Explorer.
-In addition to the icons from previous Windows 11 versions with the right-click context menu, we’ve now added text labels for cut, copy, paste, rename, share, and delete. There are also more options for accessibility. You can now toggle live captions on and off directly from quick settings. For better accessibility when using supported Bluetooth low-energy hearing aids, we’ve streamlined Bluetooth device connection and pairing, and by the way, you can now use direct pairing with Swift Pair, and once connected, compatible devices work with audio streaming and smooth call handling. Again, these updates are available for everyone.
-Now, if you are using a Windows 11 24H2 Copilot+ PC, advanced on-device AI capabilities also light up. These devices have more than 40 models that bring various intelligent local capabilities and take advantage of power-efficient neuro-processing units or NPUs that can do, at minimum, 40 trillion or more operations per second. Let me show you a few highlights. First, I’m in settings under Accessibility and Captions, using live captions with translations, and Windows can interpret any audio played on the system from any app. So I’ll try this out, playing a video in the Windows Media Player that I made earlier. Now that I have live captions enabled with translation… And as you saw, while I spoke in English, German, and Mandarin, it translated everything back to me in English captions in real time, and this is all running using the local models on the device baked into Copilot+ PCs so there’s no latency to round-trip the data and it’s almost instantaneous.
-For more built-in AI, let’s look at Windows Studio Effects, which is easily accessible in quick settings and works with the NPU to improve your online presence regardless of which app is using your built-in camera or microphone. For example, Portrait Light automatically adjusts the image quality to help you show up better in not so well lit environments. Also, participating in a video call using the three creative filters gives you some fun options. Here, the animated option is selected, and you can now see the cartoon effect on our subject while still preserving their facial features. Then, the improved portrait blur with real-time depth estimation off the camera feed, as you can see, does much better than previous iterations, and even though you can’t see it in the demo, the enhanced voice focus uses the NPU for deep echo cancellation and removes background noise when you’re on a call for Teams, Zoom, or WhatsApp. Of course, the automatic framing continues to keep you in the ideal position, which is super handy with some of the ultra-wide field of view cameras, and if you combine eye contact with teleprompter turned on, it’s pretty powerful. So eye contact is enhanced as you read content on the screen, making you appear more engaged and natural with others on the call.
-Now, let’s go under the hood of Windows 11 to look at recent performance and efficiency improvements. In a study by Principal Technologies, which predates Copilot+ PCs and compares popular business laptops from HP and Lenovo running Windows 11 and Windows 10 on equivalent spec devices, PCMark 10 benchmarks saw battery life improvements across the board for Windows 11. Local video playback and streaming video tests also favored Windows 11. Then, for productivity tasks, also using PCMark 10 benchmarks, Windows 11 also scored higher. Additionally, for creative work using Cinebench R23 benchmarks, both single and multi-core Windows 11 outscored Windows 10.
-So, now, let’s move on to your Windows 11 24H2 deployment considerations, especially if some or most of your devices are currently running Windows 10. First, in the area of compatibility, your Windows 10 hardware and peripherals will just work with Windows 11. In fact, the overwhelming majority of business PCs running today will run Windows 11. As rule of thumb, any device with eighth-gen Intel processors or newer released after 2017 will work, and unless your PCs are more than seven years old, there should be nothing holding you back, and for applications, more than 99.7% of Windows 10 apps will run on Windows 11, and if you’re running Windows 10 on some or most of your systems now, it’s really a good time to start thinking about your migration. Windows 10 end of support is coming in October 2025, at which point, if you’ve not yet migrated, there are more options to purchase extended security updates for systems running Windows 10 22H2 and newer. Now, this option gives you more time to migrate and should be thought of as a last resort. Extended security updates are included with Windows 365 and Azure Virtual Desktop, as well as physical devices used to connect to Windows 365, and the good news is we’ve been enhancing the Windows update, deployment, and migration tools ever since your last migration, so when you’re coming from Windows 10, you don’t need to re-image existing devices.
-For Microsoft Intune, you can manage Windows devices, and using Windows Autopatch, our fully-managed cloud native update solution, which is included with Microsoft 365, E3, and E5, you can update your Windows 10 devices to Windows 11. Enrolling your tenant into Windows Autopatch, as you can see here, is easy. You’ll agree to assessing your tenant for readiness, then enroll, accept the terms, and add contact information for your Windows Autopatch admins. The solution will automatically create multiple progressive deployment rings, allowing you to apply the latest updates according to your organization’s custom configuration, where you can configure release settings and group assignments for each deployment ring. So you maintain full control over the deployment of updates, and by design, Autopatch minimizes disruptions and distractions with early issue identification, and it supports safe rollout with halt and rollback support.
-Next, as you refresh your hardware with new devices, the Windows Autopilot deployment service can also be managed from Microsoft Intune, where you can automate device provisioning to streamline the out-of-box set-up experience and make the devices you purchase compliant with your management policies and settings, as well as install your required apps and run any defined scripts in order to make sure those devices are immediately business ready. As you purchase new devices, you’ll work with your hardware supplier to create the management connection between your organization and those devices so they can be directly shipped to your employees. Then, once the device is powered up and connected to the internet, your policies and settings are enforced and the device is made compliant before it’s allowed to connect to your managed resources. Migration from Windows 10 to Windows 11, in fact, has never been easier, and there are no compromises with 24H2.
-Now, to learn more and get started, check out aka.ms/Windows11Enterprise and keep watching Microsoft Mechanics for more updates. Subscribe if you haven’t yet, and thanks for watching.
Microsoft Tech Community – Latest Blogs –Read More
Publishing Custom Teams App to Microsoft Store failed
Hello, can someone help me? I’ve completed all the details needed upon submission on app. also i have setup my identifier already, but I am getting ‘Your account is not currently eligible to publish to the marketplace. To enable publishing, review your account settings and follow the instructions to resolve any issues. Learn more‘ error.
Hello, can someone help me? I’ve completed all the details needed upon submission on app. also i have setup my identifier already, but I am getting ‘Your account is not currently eligible to publish to the marketplace. To enable publishing, review your account settings and follow the instructions to resolve any issues. Learn more’ error. Read More
Is it possible to reassign a Task Marked Completed by the original delegated task recipient
I often receive task completed notices in situations where the task has not in fact been completed but requires to be completed by someone else. Instead of chasing the original recipient to have him/her assign the task to someone else (which would run counter to our organizational chain of command) or recreating the task, is it possible to reassign the task to someone else using either the original task or the task completed message?
I often receive task completed notices in situations where the task has not in fact been completed but requires to be completed by someone else. Instead of chasing the original recipient to have him/her assign the task to someone else (which would run counter to our organizational chain of command) or recreating the task, is it possible to reassign the task to someone else using either the original task or the task completed message? Read More
Font is Different within a Table
I have:
Microsoft® Word for Microsoft 365 MSO (Version 2409 Build 16.0.18025.20030) 64-bit
I have encountered what appears to be a common problem – when I create a table the font withing the table is different than the rest of the document. However, the online help says:
“The default font used for the text in a table will be that defined in the Table Grid Style. If the font for the text in the table is not the font that you want it to be, modify that Style so that it uses the font that you want.”
Ok, great, but exactly how do I do that? I’d be grateful if someone could take me click by click through the process.
I have:Microsoft® Word for Microsoft 365 MSO (Version 2409 Build 16.0.18025.20030) 64-bitI have encountered what appears to be a common problem – when I create a table the font withing the table is different than the rest of the document. However, the online help says:“The default font used for the text in a table will be that defined in the Table Grid Style. If the font for the text in the table is not the font that you want it to be, modify that Style so that it uses the font that you want.” Ok, great, but exactly how do I do that? I’d be grateful if someone could take me click by click through the process. Read More
HTML or other method to add new line, color, italic, bold within a Service’s Details fields
I need to add a “new line” character within the Service’s Detail field.
All these failed: multiple returns, <br>, %0a%0d , n , %
, {control J pasted from Excel}
I would also like to be able to do italics , bold , and color for both the “Service Name” field, the “Description” field, and it’d be nice for the “Custom Fields” too.
I cannot seem to find anyone else asking for this in forums, surprisingly.
I need to add a “new line” character within the Service’s Detail field.All these failed: multiple returns, <br>, %0a%0d , n , % , {control J pasted from Excel} I would also like to be able to do italics , bold , and color for both the “Service Name” field, the “Description” field, and it’d be nice for the “Custom Fields” too. I cannot seem to find anyone else asking for this in forums, surprisingly. Read More
Creating unique headers and footers?
I am looking for a word processing product that I can create a template with unique headers and footers that I can share with users who can only add text content but not change or delete the headers and footers. I looked at Word, but it does not have this capability. I am trying to convince my boss to use Google doc’s but he is old school. I tried telling him that Word is old, outdated tech and very limited, but he asked me to check if there is another MS product that comes with our 365 platform that can do what I described here?
I am looking for a word processing product that I can create a template with unique headers and footers that I can share with users who can only add text content but not change or delete the headers and footers. I looked at Word, but it does not have this capability. I am trying to convince my boss to use Google doc’s but he is old school. I tried telling him that Word is old, outdated tech and very limited, but he asked me to check if there is another MS product that comes with our 365 platform that can do what I described here? Read More
Secure, High-Performance Networking for Data-Intensive Kubernetes Workloads
The intersection of Generative AI and cloud computing has been transforming how organizations build and manage their infrastructure. The demands on networking infrastructure are greater than ever, especially as data-intensive workloads are increasingly built using Kubernetes-based compute. This is particularly true in high-performance computing (HPC) environments, where the need to build advanced training models securely using Kubernetes is paramount. The scalability and flexibility offered by its ecosystem makes Kubernetes a preferred choice for managing complex workloads, but it also brings forward unique networking challenges that need to be addressed. This blog series offers practical insights and strategies to build secure, scalable Kubernetes clusters using Azure infrastructure.
Networking Requirements for HPC and AI Workloads
High-performance computing and AI workloads, such as the training of large language models (LLMs), demand networking platforms with high input/output (I/O) capabilities. These platforms must provide low latency and high bandwidth to ensure efficient data handling and processing. As the size and complexity of datasets grow, the networking infrastructure must scale accordingly to maintain performance and reliability. Overall, the requirements can be classified into –
Scalability: As organizations expand their AI initiatives, the networking infrastructure must be capable of scaling up to accommodate increasing data loads and more complex models. Scalable solutions allow seamless growth without compromising performance.
Security: Protecting data integrity and ensuring secure access to workloads are paramount. Networking platforms must incorporate robust security measures to safeguard sensitive information and prevent unauthorized access. Implementing a least-privilege approach minimizing the attack surface by granting only the necessary permissions to users and applications.
Observability: Monitoring network performance and identifying potential issues are critical for maintaining optimal operations. Advanced observability tools help in tracking traffic patterns, diagnosing problems, and ensuring efficient data flow across the network.
Low Latency: AI training models, particularly for LLMs, require high-speed data transfer to process vast amounts of information in real-time. Low latency is crucial to minimize delays in data communication, which can impact the overall training time and model accuracy.
High Bandwidth: The volume of data exchanged between compute nodes during training processes necessitates high bandwidth. This ensures that data can be transferred quickly and efficiently, preventing bottlenecks that could slow down computations.
Key Implementation Strategies
By leveraging AKS, developers can easily deploy and manage containerized AI models, ensuring consistent performance and rapid iteration. The built-in integration with Azure’s high-performance storage, networking and security features ensures that AI workloads can be processed efficiently. Additionally, AKS supports advanced GPU scheduling(reference), enabling the use of specialized hardware for training and inference, thus accelerating the development of sophisticated GenAI applications.
Let’s now examine some of the latest cluster networking features we’ve introduced to deliver a high-performance network datapath architecture, helping users in building a secure and scalable network platform. With Azure CNI powered by Cilium, users have the right foundational infrastructure to address those requirements, along with comprehensive integrations with Azure’s extensive networking capabilities.
Azure CNI Powered by Cilium
Azure Container Networking Interface (CNI), powered by Cilium, is built on a Linux technology called eBPF (Extended Berkeley Packet Filter). eBPF allows the execution of sandboxed programs in the kernel with high efficiency and minimal overhead, making it ideal for advanced networking tasks. Azure CNI leverages eBPF to offer multiple performance benefits, along with advanced in-cluster security and observability capabilities.
Performance Benefits of eBPF
eBPF provides numerous advantages that are essential for high-performance networking:
Efficient Packet Processing: eBPF enables the execution of custom packet processing logic directly in the kernel, reducing the need for context switches between user space and kernel space. This results in faster packet handling and lower latency.
Dynamic Programmability: eBPF allows for dynamic updates to networking policies and rules without requiring kernel recompilation or system restarts. This flexibility is crucial for adapting to changing network conditions and security requirements.
High Throughput: By offloading packet processing to the kernel, eBPF can handle high throughput with minimal impact on system performance. This is particularly beneficial for data-intensive workloads that demand high bandwidth.
Efficient IP Addressing for Scale and Interoperability
Planning IP addressing is a cornerstone of building dynamic data workloads on AKA. Leveraging overlay mode, which is the default in AKS clusters starting with v1.30, and Azure CNI by Cilium, supports both overlay and Vnet addressing for direct-to-pod access. Furthermore, Azure CNI by Cilium supports dual stack IP addressing that allows for both IPv4 and IPv6 protocols to coexist within the same network. This flexibility is essential for supporting legacy applications that may still rely on IPv4 while simultaneously enabling the adoption of newer, more efficient IPv6 based systems. By utilizing dual stack network configurations, organizations can ensure compatibility and smooth interoperability, reducing the overhead associated with maintaining separate network infrastructures. Additionally, mixed IP addressing facilitates a smoother transition to IPv6, enhancing future-proofing and scalability as network demands grow.
In-Cluster Security and Observability
Azure CNI, powered by Cilium, enhances in-cluster security and observability through several key features:
Advanced Network Policies: Azure CNI supports Layer3, Layer4 network policies along with Fully Qualified Domain Name (FDQN) based advanced network policies. This enables users to restrict connections to specific DNS names, enhancing security by limiting access to trusted endpoints.
Comprehensive Network Observability: Azure CNI’s network observability platform, based on Cilium, provides detailed insights into network traffic and performance. Users can identify DNS performance issues, such as throttling of DNS queries, missing DNS responses, and errors, as well as track top DNS queries. This level of visibility is crucial for diagnosing problems and optimizing network performance. Users can trace packet flows across their cluster for detailed analysis and debugging with the Hubble CLI on-demand network flows.
Users can unlock the recently launched observability and FQDN based features by enabling Advanced Container Networking Services(ACNS) on AKS clusters. Let’s take a closer look at how you can enable FQDN filtering through CiliumNetworkPolicy (CNP), and DNS Proxy that allows you to upgrade Cilium Agent with minimal impact to DNS resolution. Let’s say you have a Kubernetes pod labeled app: genai_backend and you want to control its egress traffic. Specifically, you want to allow it to access to “myblobstorage.com” while blocking all other egress traffic, except for DNS queries to the kube-dns service.
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-genai-to-blobstorage
spec:
endpointSelector:
matchLabels:
app: genai_backend
egress:
– toEndpoints:
– matchLabels:
“k8s:io.kubernetes.pod.namespace”:kube-system
“k8s:k8s-app”:kube-dns
– toFQDNs:
– matchName: app1.myblobstorage.com
– toPorts:
– ports:
– port: “53”
protocol: ANY
rules:
dns:
– matchPattern: “*.myblobstorage.com”
Additional considerations for High-Performance Networking
Kubernetes-based data applications will also require high-performance networking from the container networking platform. The underlying networks often require high throughput and low latency translating into high-speed interfaces configured with technologies like Infiniband. These interfaces can deliver bandwidths up to 100 Gbps or more, significantly reducing data transfer times and enhancing application performance.
Often, configuration management of multiple interfaces can be cumbersome, as it involves setting up network fabrics, managing traffic flows, and ensuring compatibility with existing infrastructure. We have heard from many of our users the need for native features that integrate seamlessly with their Kubernetes environments. With Azure CNI, users have the flexibility to securely configure these high-speed interfaces using native Kubernetes constructs like Custom Resource Definitions (CRDs). Additionally, Azure CNI supports SR-IOV (Single Root I/O Virtualization) technologies, which allows for dedicated network interfaces for pods, further enhancing performance by reducing the CPU overhead associated with networking. We will cover this more in a future blog.
Conclusion
The demands on networking infrastructure are intensifying as data-intensive workloads become more prevalent in HPC and AI environments. Kubernetes-based compute offers the scalability and flexibility needed to manage these workloads, but it also presents unique networking challenges. Azure CNI, with its eBPF-based architecture, addresses these challenges by providing high-performance networking dataplane, advanced security, and comprehensive observability. So, why wait, give it a try and let us know (Azure Kubernetes Service Roadmap (Public) · Azure Kubernetes Service Roadmap (Public) (github.com)) how we can evolve our roadmap to help you build the best with Azure. In the next blog, we will focus on how you extend your security controls from Layer4 to Layer7, along with configuration simplifications. So, stay tuned!
Microsoft Tech Community – Latest Blogs –Read More
September 2024 Recap: Azure Postgres Flexible Server
Hello Azure Community,
This September, we’ve rolled out some cool updates to Azure Database for PostgreSQL Flexible Server that you’ll want to check out. We’re excited to bring you a sneak peek at the DiskANN Vector Index, the latest PostgreSQL 17 preview, and our new Fabric Mirroring feature. These updates are all about making your database smarter and more efficient. Let’s dive into what’s new this month and see how these changes can help you.
Feature Highlights
DiskANN Vector Index – Preview
Postgres 17 – Preview
Fabric Mirroring – Private Preview
Migration Service – Now supports Google Cloud SQL, Custom FQDN
Auto Migrations – Single to Flexible server
Python SDK Update
Automation Tasks – Generally Available
DiskANN Vector Index – Preview
We’re thrilled to announce the preview of DiskANN, a leading vector indexing algorithm, on Azure Database for PostgreSQL – Flexible Server! Started by Microsoft Research, DiskANN enables developers to build highly accurate, performant, and scalable Generative AI applications, surpassing pgvector’s HNSW and IVFFlat in both latency and accuracy. DiskANN implements the following powerful techniques:
Optimized storage – allows algorithm to scale beyond limits of RAM without sacrificing search speed.
Vector quantization – keeps quantized vectors in memory. Our implementation of DiskANN on PostgreSQL balances the interactions between quantized and unquantized vectors, delivering both low latency and high accuracy.
Iterative post filtering – enhances the accuracy of filtered vector search results without compromising on speed or precision.
New Vamana graph structure robust to index updates – Vamana is more robust to changes than existing graph indices by maintaining accuracy despite many insertions, modifications, and deletions, without the need for expensive index rebuilds.
Explore more about DiskANN: Documentation, Blog, Demo, Join Public Preview
Postgres 17 – Preview
We’re thrilled to announce the preview release of PostgreSQL 17 on Azure Postgres Flexible Server, which is now available for early testing. This version features significant upgrades like:
Memory Insights: Enhanced EXPLAIN command for better resource management.
Vacuum Enhancements: Minimized transaction interference for smoother operations.
JSON Enhancements: Direct JSON data conversion into relational tables with JSON_TABLE function.
Dynamic Logical Replication: No restarts needed for replication setup changes.
The Azure Postgres team contributed significantly to this release, enhancing system efficiency. We’re preparing for a Major Version Upgrade soon and invite you to test this preview and share your feedback. For more details, check out blog PostgreSQL 17 Preview on Azure Postgres Flexible Server.
Fabric Mirroring – Private Preview
Fabric Mirroring enhances Azure Database for PostgreSQL Flexible Server by seamlessly integrating operational and analytical data, eliminating data silos and enabling powerful analytics with Microsoft Fabric. This feature supports real-time data replication into Fabric OneLake in Parquet format, allowing direct querying and data synchronization without traditional ETL processes. Key benefits include:
Easy and Quick Integration: Seamlessly integrate and analyze data with a few clicks.
Real-time Data Replication: Incrementally mirror changes almost in real-time.
Advanced Query Capabilities: Directly query data within OneLake using SQL, supporting complex queries and views.
Integration with Analytical Tools: Access data through Fabric’s SQL analytics endpoints or third-party SQL tools.
Enhanced Data Visualization and BI Reporting: Utilize BI tools to create dynamic reports and dashboards directly from OneLake.
For further reading, check out blog Mirroring Azure Database for PostgreSQL Flexible Server in Microsoft Fabric – Private Preview.
Migration Service – Now supports Google Cloud SQL, Custom FQDN
The Migration service for Azure Database for PostgreSQL streamlines transferring your databases to Azure, supporting migrations from cloud services, on-prem environments, and VMs. Newly added sources include:
Amazon Aurora PostgreSQL: Now supports offline and online migrations.
Google Cloud SQL for PostgreSQL: Supports offline and online migrations.
Burstable SKU support
Customers can now migrate directly into a Burstable SKU without having to provision a higher SKU for migration and then scale down later. This feature reduces overhead for Single server users of Basic SKU to migrate to Flexible server.
Custom FQDN/IP
Additionally, you can now use custom FQDNs or IP addresses for source and target connections, simplifying migrations for those using custom DNS settings. These updates enhance flexibility and ease the migration process significantly.
Auto Migrations – Single to Flexible server
The auto migration feature provides a highly resilient and self-healing offline migration experience during a planned migration window, with minimal downtime. Auto migration removes the overhead to manually migrate your server. Post migration, you can take advantage of the benefits of Flexible Server, including better price & performance, granular control over database configuration, and custom maintenance windows.
There is a nomination process in place for users who want to voluntarily fast-track their migration to Flexible server. If you own a Single Server workload, you can now nominate yourself (if not already scheduled by the service) for auto migration. Submit your server details through this form.
Python SDK Update
The Python SDK now allows easy automation of tasks such as server creation and configuration directly within Python applications. It supports Azure’s identity and access management for secure operations. The older azure-mgmt-rdbms library is deprecated, replaced by the new azure-mgmt-postgresqlflexibleservers library. Simply update the import statement in your application to switch to the new library.
For detailed instructions and more examples, refer to the updated Quick-start-guide.
Automation Tasks – Generally Available
Task Automation now generally available for Azure Database for PostgreSQL – Flexible Server boosts management by automating routine processes like starting and stopping servers on a consumption-based billing model. Unlike Azure Automation, this solution is lightweight and leverages Azure Logic Apps specifically for resource-related tasks. Key Features include:
Schedule server START / STOP.
Automate routine tasks like sending resource costs or server scaling.
Customize task frequency and timing.
Monitor task history including statuses like Canceled, Failed, and Succeeded.
Edit tasks directly or use the workflow designer for tailored management.
For more detailed guidance, visit doc Manage Azure Database for PostgreSQL Flexible Server using automation tasks.
Learning Bytes
How to Mirror Server Properties in Azure PostgreSQL with Ease
In this section we will explore how to export or copy all the properties of an existing server to set up a target server with same properties as the previous server. Suppose you have two instances of Azure PostgreSQL Flexible Server and want to replicate all the properties from “server1” to “server2”. You can achieve this by using parameter filtering with ‘jq’ on Azure CLI. Once all the parameters are filtered you can set those properties to server2 and then restart the server to reflect those changes.
To copy the parameters to the new server we can use this command that filters out the parameters and sets those to the new server and then restarts the server:
parameters=$(az postgres flexible-server parameter list –resource-group <server1-resource-group> –server-name <server1-name> | jq -r ‘.[] | select(.isReadOnly == false and .source == “user-override”) | [.name, .value] | @sh’)
while IFS= read -r parameter; do
name=$(echo “$parameter” | awk -F “‘” ‘{print $2}’)
value=$(echo “$parameter” | awk -F “‘” ‘{print $4}’)
az postgres flexible-server parameter set –resource-group <server2-resource-group> –server-name <database2-name> –name “$name” –value “$value”
done <<< “$parameters”
count=$(az postgres flexible-server parameter list –resource-group <server2-resource-group> –server-name <server2-name> | jq ‘[.[] | select(.isConfigPendingRestart == true)] | length’)
if [[ $count -ge 1 ]]; then
az postgres flexible-server restart –resource-group <server2-resource-group> –name <server2-name>
fi
There are certain server properties which cannot be mirrored or copied. To explore more about setting up resources and server through Azure CLI you can follow the documentation on – Quickstart Guideline
Conclusion
That wraps up our September 2024 feature recap! We hope you’re as excited as we are about these updates. Give them a try, and see how they can improve your database management and performance. Your feedback is incredibly valuable to us, so please share your thoughts and experiences. Finally, Stay tuned for more exciting announcements and updates next month as we gear up for Microsoft IGNITE 2024!
Microsoft Tech Community – Latest Blogs –Read More
Intune windows hello configuration questions
First off thank you to anyone that helps!
We are looking to turn on Windows Hello for Buisness in intune for our Hybrid joined enviorment. We would like to use Cloud Keyberos for auth instead of cert.
We would like to be able to have all user have the abilty for this but exclude certain tablets and devices from use.
From what I understand we need the below
1 enable Cloud Keyberos
2 Create a csp to setup the settings for windows hello for buiness.
3 Create a csp to enable windows hello for buiness and also cloud keyberos
3.b – create a excluded group for the devices that we do not want to get windows hello enabled
I know this is a very simplistic overview of what we need to do and I am looking for pointers on this or vides/articles to help guide us
Again any help would be greatly appricated
First off thank you to anyone that helps! We are looking to turn on Windows Hello for Buisness in intune for our Hybrid joined enviorment. We would like to use Cloud Keyberos for auth instead of cert. We would like to be able to have all user have the abilty for this but exclude certain tablets and devices from use. From what I understand we need the below1 enable Cloud Keyberos2 Create a csp to setup the settings for windows hello for buiness.3 Create a csp to enable windows hello for buiness and also cloud keyberos 3.b – create a excluded group for the devices that we do not want to get windows hello enabledI know this is a very simplistic overview of what we need to do and I am looking for pointers on this or vides/articles to help guide usAgain any help would be greatly appricated Read More
Strengthening Security in Azure IoT Hub: Transitioning to TLS 1.2+ and Planning for TLS 1.3
To align with the broader Azure effort for all services to adopt TLS 1.2+, Azure IoT Hub will officially remove support for Transport Layer Security (TLS) 1.0 and 1.1 starting July 1st, 2025. Although Microsoft’s implementation of older TLS versions is not known to be vulnerable, the adoption of TLS 1.2 and later versions brings significant improvements to security through stronger cryptographic algorithms, perfect forward secrecy, and more resilient cipher suites.
Why TLS 1.2 and Beyond?
TLS 1.2 offers substantial benefits over older versions:
Perfect Forward Secrecy (PFS): PFS helps ensure that even if long-term keys are compromised, past communications remain secure.
Stronger Cipher Suites: TLS 1.2 helps support more modern and robust cryptographic algorithms, helping to make your data and device connections more resistant to potential attacks.
Better Performance: TLS 1.2 is designed to be faster and more efficient, helping reduce latency for secure communications.
Additionally, we are committed to helping support TLS 1.3 in the upcoming calendar year (2025), bringing even more secure cipher suites and faster handshakes. This forward-looking investment will ensure Azure IoT Hub remains ahead of evolving security threats, delivering faster, more secure, and more efficient communication for your IoT devices. This means that customers who transition to TLS 1.2 now will be well-positioned for the future as we roll out TLS 1.3 support across the service.
Recommended Actions
To avoid potential service disruptions after July 1st, 2025, please confirm that devices connected with Azure IoT Hub are using TLS 1.2 or later. Then:
If devices are already exclusively using TLS 1.2 or later, no further action needs to be taken.
If devices still have a dependency on TLS 1.0 or 1.1, transition them to TLS 1.2 or later by July 1st, 2025.
Monitoring and Analyzing TLS Versions
Azure IoT Hub emits resource logs for several categories that can be analyzed using Azure Monitor Logs. And to assist with this transition, Azure IoT Hub provides insights into client connections, allowing you to monitor the TLS versions in use by your devices. You may utilize this feature to determine the impact of this change in your IoT solution.
To view these logs, follow these steps:
1. Enable diagnostic settings under Monitoring section for your Azure IoT Hub . Ensure “Connections” category is checkmarked.
2. Navigate to Logs and use the following query to find the devices that recently connected and their respective TLS version, an example of the query is shown in the screenshot below:
Note: HTTPS connections will not generate an event in Azure Monitor logs.
For more information on Azure IoT Hub TLS support, refer to Azure IoT Hub TLS support | Microsoft Learn.
Microsoft Tech Community – Latest Blogs –Read More
Issues refreshing Pivot Table
Hi! I’ve a Pivot Table that when I try to change its Data Source to a new one, Excel just closes with no message on screen, someone know how can i achieve this? Or how can I copy the table structure without the Data Source to connect later the new one
When Excel opens again the repaired file says something like “The table was discarded due to integrity problems”
Hi! I’ve a Pivot Table that when I try to change its Data Source to a new one, Excel just closes with no message on screen, someone know how can i achieve this? Or how can I copy the table structure without the Data Source to connect later the new oneWhen Excel opens again the repaired file says something like “The table was discarded due to integrity problems” Read More
Essential Customer Requirements for Purchasing SaaS Solutions on Microsoft Marketplace
Customer requirements to purchase a SaaS solution through Microsoft Marketplace (AppSource or Azure Marketplace):
Microsoft Account:
Requirement: The customer must have an active Microsoft work or school account. This account is essential for managing subscriptions, billing, and accessing the purchased SaaS solution.Reason: The marketplace transactions are tied to Microsoft accounts for security and authentication
Microsoft 365 Subscription (In Some Cases):
Requirement: For many transactions, particularly through AppSource, customers may need to have an active Microsoft 365 (M365) subscription. This is often necessary to facilitate billing and integrate SaaS solutions with Microsoft productivity tools.Reason: Some SaaS solutions are designed to integrate directly with M365 apps (e.g., Dynamics 365, Microsoft Teams), and the marketplace uses M365 for account and payment management.
Azure Subscription (For Azure Marketplace):
Requirement: To purchase a SaaS solution on Azure Marketplace, the customer typically needs an Azure subscription. This subscription allows the customer to manage billing, access SaaS services, and deploy cloud solutions within their Azure environment.Reason: SaaS offers in Azure Marketplace are often integrated with other Azure services, requiring an Azure account for deployment, management, and billing.
Billing Information:
Requirement: Customers must provide valid billing details, such as a credit card, or set up invoicing through their Microsoft or Azure account.Reason: Billing is handled through the Microsoft or Azure billing system, and payment details are necessary to complete transactions for SaaS subscriptions or services.
Access to Admin or Purchasing Permissions:
Requirement: The customer must have the necessary permissions (e.g., admin or purchasing rights) within their organization to make purchases through Microsoft Marketplace.Reason: Some organizations restrict purchase permissions to specific roles (e.g., IT admin, finance team). Users without these permissions may need approval from their organization’s administrator.
Agreement to Terms of Service:
Requirement: Customers need to agree to the terms and conditions of the SaaS solution and the Microsoft Marketplace before completing the purchase.Reason: Legal requirements ensure that both Microsoft and the SaaS vendor are covered by the agreement, and customers understand their rights and obligations.
Compatibility with Existing Microsoft Ecosystem:
Requirement: In some cases, customers may need to verify that the SaaS solution is compatible with their existing Microsoft ecosystem, such as M365, Azure, or Dynamics 365.Reason: Many SaaS solutions on Microsoft Marketplace are designed to work with Microsoft services, so compatibility is critical for successful integration.
Payment Model Understanding:
Requirement: Customers need to understand the payment models (e.g., monthly subscription, annual billing, pay-as-you-go) offered for the SaaS solution.Reason: Each SaaS solution has its own pricing structure and understanding the payment model ensures that the customer is aware of recurring fees or usage-based charges.
Organization’s Compliance with Microsoft’s Billing and Procurement Policies:
Requirement: The organization must comply with Microsoft’s billing and procurement policies, which may involve certain approvals or process steps depending on the size and type of the company.Reason: Larger enterprises often have internal procurement processes that must align with Microsoft’s marketplace systems.
Geographical Availability:
Requirement: The SaaS solution must be available in the customer’s region. Certain offers might have regional restrictions based on service availability or regulatory reasons.Reason: Microsoft Marketplace enforces regional availability for certain solutions due to compliance or technical constraints.
Customer requirements to purchase a SaaS solution through Microsoft Marketplace (AppSource or Azure Marketplace): Microsoft Account:Requirement: The customer must have an active Microsoft work or school account. This account is essential for managing subscriptions, billing, and accessing the purchased SaaS solution.Reason: The marketplace transactions are tied to Microsoft accounts for security and authenticationMicrosoft 365 Subscription (In Some Cases):Requirement: For many transactions, particularly through AppSource, customers may need to have an active Microsoft 365 (M365) subscription. This is often necessary to facilitate billing and integrate SaaS solutions with Microsoft productivity tools.Reason: Some SaaS solutions are designed to integrate directly with M365 apps (e.g., Dynamics 365, Microsoft Teams), and the marketplace uses M365 for account and payment management.Azure Subscription (For Azure Marketplace):Requirement: To purchase a SaaS solution on Azure Marketplace, the customer typically needs an Azure subscription. This subscription allows the customer to manage billing, access SaaS services, and deploy cloud solutions within their Azure environment.Reason: SaaS offers in Azure Marketplace are often integrated with other Azure services, requiring an Azure account for deployment, management, and billing.Billing Information:Requirement: Customers must provide valid billing details, such as a credit card, or set up invoicing through their Microsoft or Azure account.Reason: Billing is handled through the Microsoft or Azure billing system, and payment details are necessary to complete transactions for SaaS subscriptions or services.Access to Admin or Purchasing Permissions:Requirement: The customer must have the necessary permissions (e.g., admin or purchasing rights) within their organization to make purchases through Microsoft Marketplace.Reason: Some organizations restrict purchase permissions to specific roles (e.g., IT admin, finance team). Users without these permissions may need approval from their organization’s administrator.Agreement to Terms of Service:Requirement: Customers need to agree to the terms and conditions of the SaaS solution and the Microsoft Marketplace before completing the purchase.Reason: Legal requirements ensure that both Microsoft and the SaaS vendor are covered by the agreement, and customers understand their rights and obligations.Compatibility with Existing Microsoft Ecosystem:Requirement: In some cases, customers may need to verify that the SaaS solution is compatible with their existing Microsoft ecosystem, such as M365, Azure, or Dynamics 365.Reason: Many SaaS solutions on Microsoft Marketplace are designed to work with Microsoft services, so compatibility is critical for successful integration.Payment Model Understanding:Requirement: Customers need to understand the payment models (e.g., monthly subscription, annual billing, pay-as-you-go) offered for the SaaS solution.Reason: Each SaaS solution has its own pricing structure and understanding the payment model ensures that the customer is aware of recurring fees or usage-based charges.Organization’s Compliance with Microsoft’s Billing and Procurement Policies:Requirement: The organization must comply with Microsoft’s billing and procurement policies, which may involve certain approvals or process steps depending on the size and type of the company.Reason: Larger enterprises often have internal procurement processes that must align with Microsoft’s marketplace systems.Geographical Availability:Requirement: The SaaS solution must be available in the customer’s region. Certain offers might have regional restrictions based on service availability or regulatory reasons.Reason: Microsoft Marketplace enforces regional availability for certain solutions due to compliance or technical constraints. Read More
Dell BIOS configuration and firmware updates concern
Hello all,
I recently looked into managing BIOS settings for Dell devices enrolled in Intune.
My organization also manage drivers and firmware updates in Intune for these devices.
One of the requirements I was instructed to deploy is to enable BIOS Admin Password on the targeted devices.
While applying a password may increase security, my concern is that firmware updates will now fail, unless Intune can “know” the device’s BIOS admin password.
My question is how I can ensure that firmware updates can still be pushed successfully to these devices even though BIOS admin password is enabled?
Hello all,I recently looked into managing BIOS settings for Dell devices enrolled in Intune.My organization also manage drivers and firmware updates in Intune for these devices.One of the requirements I was instructed to deploy is to enable BIOS Admin Password on the targeted devices.While applying a password may increase security, my concern is that firmware updates will now fail, unless Intune can “know” the device’s BIOS admin password.My question is how I can ensure that firmware updates can still be pushed successfully to these devices even though BIOS admin password is enabled? Read More
How to return text after entering an associated number?
I have a database of location names an their corresponding location codes. Over time, people using the database have used slightly different spellings of the location names, which leads to inaccurate totals for each location because each spelling becomes a new entry. The location codes have never changed.
Can I use some from of an IF and VLOOKUP function to return the proper location name (text) in one cell after entering the associated location code (number) in a different cell?
Here’s an example of the location names and their codes:
Fish Ladder1519Ballard Marine1520NW Adhesives1521James Ranch1522
I have a database of location names an their corresponding location codes. Over time, people using the database have used slightly different spellings of the location names, which leads to inaccurate totals for each location because each spelling becomes a new entry. The location codes have never changed. Can I use some from of an IF and VLOOKUP function to return the proper location name (text) in one cell after entering the associated location code (number) in a different cell? Here’s an example of the location names and their codes:Fish Ladder1519Ballard Marine1520NW Adhesives1521James Ranch1522 Read More
Staff, services, etc disappeared again from Bookings just now.
Happening to anyone else? I logged in to change the wording on one of the notifications and all the services, staff, etc have disappeared. Appointments still show synced in Outlook and it looks like customers can still book but the admin side isn’t working.
Happening to anyone else? I logged in to change the wording on one of the notifications and all the services, staff, etc have disappeared. Appointments still show synced in Outlook and it looks like customers can still book but the admin side isn’t working. Read More
Windowed apps have UI artifacts
Hello,
I´ve encountered a problem with almost all my apps on Windows 11 Home. Almost all apps (except Visual Studio, Discord and all games) have problems with fonts, are blurry, the UI elements are overlapping, everything is jagged and hovering through menu items “selects” them.
In this image are snippets / screens from ClipChamp, Teams and from Lenovo Vantage as examples.
You can see the the artifacts as I have described.
SETUP:
I5-13400F
RTX 4060 TI 8GB,
64GB RAM 4400 MHZ
1TB SSD
WIN specs: Win11, Version 23H2 Build 22631.4317, Windows Feature Experience Pack 1000.22700.1041.0
Monitor HP 27mx , 144hz
I would be glad, If anyone has advice how to fix this
Thank you a lot,
Lukas
Hello,I´ve encountered a problem with almost all my apps on Windows 11 Home. Almost all apps (except Visual Studio, Discord and all games) have problems with fonts, are blurry, the UI elements are overlapping, everything is jagged and hovering through menu items “selects” them.In this image are snippets / screens from ClipChamp, Teams and from Lenovo Vantage as examples.You can see the the artifacts as I have described. SETUP:I5-13400FRTX 4060 TI 8GB,64GB RAM 4400 MHZ1TB SSDWIN specs: Win11, Version 23H2 Build 22631.4317, Windows Feature Experience Pack 1000.22700.1041.0Monitor HP 27mx , 144hzI would be glad, If anyone has advice how to fix thisThank you a lot,Lukas Read More
Microsoft Intune connection
Am I missing license? Also, we have another EDR and don’t have any plan to use Defender for endpoint but seeing this option in MDE, what’s the benefit and how will this help with MDI.
Am I missing license? Also, we have another EDR and don’t have any plan to use Defender for endpoint but seeing this option in MDE, what’s the benefit and how will this help with MDI. Read More
Fraud Protection Tech Community Live
Fraud Protection Tech Community Live on Nov 12th, 2024. Mark your calendars
Click here for details: Fraud Protection Community Live
Fraud Protection Tech Community Live on Nov 12th, 2024. Mark your calendars
Click here for details: Fraud Protection Community Live
Read More
Excel links used to open in one click
Company uses microsoft teams to mange construction projects. One hope page with links to each jobs tracking page. The links used to open in one click, now we have to hover, and click on the popup link, or use command click to open the link on mac computer
I’m assuming an update of sort changed this. How do I reset it to open links just by clicking them once??
Thanks!!
Company uses microsoft teams to mange construction projects. One hope page with links to each jobs tracking page. The links used to open in one click, now we have to hover, and click on the popup link, or use command click to open the link on mac computer I’m assuming an update of sort changed this. How do I reset it to open links just by clicking them once?? Thanks!! Read More