- Видео 34
- Просмотров 67 795
BlueScreen Brothers
Норвегия
Добавлен 11 сен 2022
The video podcast home for the BlueScreen Brothers. Here we share video related to Azure, Microsoft 365 and other things we care about.
Members are Olav Tvedt, Alexander Solaat Rødland, Pål-Erik Winther and Marius Solbakken Mellum
Members are Olav Tvedt, Alexander Solaat Rødland, Pål-Erik Winther and Marius Solbakken Mellum
Unlocking Surface IT Toolkit with Rohan Brooker!
Join us as we dive deep into the world of Surface for Business with Surface PM Rohan Brooker! Discover the latest tools, repairability insights, and security features that make Surface devices a game-changer for IT pros. From in-house development to management of the UEFI - to the Surface IT Toolkit, we've got all the insider info you need to maximize your Surface experience. Don't miss out! 🎥🔧💻 And yes, our favorite "Surface Eraser Tool" have recently got a new cool addition!
Просмотров: 46
Видео
ScottishSummit 2024 - The ultimate IT(AI) Security discussion (Live podcast)
Просмотров 34Месяц назад
Listen in on the engaging discussion from the Scottish Summit 2024, where Alexander Solaat Rødland (Storebrand) are hosting with Aarin Rendall (Encodian), Malin Martnes (Matoma) and Dona Sarkar (Microsoft) as guest on AI security. Recorded live in Aberdeen, Scotland, this podcast features industry experts sharing insights on the latest trends and challenges in AI and cybersecurity. With a mix o...
Inside the new 2024 Surface lineup
Просмотров 935 месяцев назад
We have again gotten some quality time together with Chauncey Larsen, senior product manager at the Microsoft Surface commercial technical market team. He is takin us through the 2024 lineup of Microsoft Surface models. A real generation changes are happening this year as AI, NPU and Copilot are entering the marked And as always it is with a more technical view. Windows Hello, Snapdragon CPU's ...
Entra Apps - Owner or Cloud Application Administrator?
Просмотров 5305 месяцев назад
Protection of Entra/Azure App registrations and Enterprise Applications is important, but it is easy to forget about the users already having or needing privileged access. For many the default solution has been using the "Owners" feature on the application. But it might be much wiser to use the built-in role "Cloud Application Administrator" or a custom version of it. Especially when you combin...
NPU Insights: Powering the Copilot+ PC Revolution
Просмотров 2256 месяцев назад
We are joined by Chauncey Larsen, senior product manager at the Microsoft Surface commercial technical market team. Chauncey loves to geek out and takes us into a deep dive understanding of the Neural processing unit and the concept of copilot PC. The NPU is a specialized processor that could revolutionize the way we think about computing power, potentially complementing or even replacing tradi...
Windows 365 and Azure Virtual desktop With Microsoft Product Manager Megan Gremmell and Alexander
Просмотров 1407 месяцев назад
After the brother’s trip to Redmond, we booked a podcast slot with Megan, a former teacher who found her passion for the Windows Cloud. Megan introduces us to what she does as a product manager for the Windows 365 and Azure Virtual Desktop teams. Connecting people across the globe sometimes provides challenges like language and social constructs - where she shares her stories how and why the wo...
Entra, legacy, licenses and other security nags with the ITBro's
Просмотров 798 месяцев назад
Alexander and Olav are meeting up with long-time friends and fellow MVPs Raymond and Sander from the Netherlands podcast show ITBro's, itbros.nl/ The talk goes freely from limitations on modern hardware to more serious topics like Entra, the security co-pilot licensing model, and security challenges. Sander gives us an insight into why development often starts without security in mind and that ...
Azure Policy - Custom policies
Просмотров 4379 месяцев назад
Olav are once again together with Niclas Madsen, and this time they start with a recap of what Azure policies are and how they work before they deep dive into creating custom policies. Niclas does a thorough review of definition files, effects of the different ways of using policies and how to use them to remediate findings. We also gives some tips when creating a policy from scratch, there is ...
API Security with 42Crunch and Microsoft Defender product group
Просмотров 18010 месяцев назад
Marius, Olav and Niclas are continuing their quest for API security. Yura Lee, Liana Tomescu and Haris Sohail, from the Microsoft Defender product team are back in studio. But the main person in this episode is Isabelle Mauny from 42Crunch. The episode starts with an general insight into why APIs need more attention on the security side, and it goes over to demos on how to use 42Crunch in both ...
Microsoft Defender for APIs w/Product managers from The Microsoft Defender Team
Просмотров 43511 месяцев назад
In this episode, the BlueScreen Brothers dive into one of the newest and most exciting features of Microsoft Defender for Cloud, the Defender for APIs. Marius and Olav are joined by recurring guest Niclas Madsen from Accenture and three exciting first-time guests. Yura Lee, Liana Tomescu and Haris Sohail are from the Microsoft product team behind Defender for APIs. Agenda: 00:00 Welcome 00:39 N...
Entra App registration - Step-by step part 4
Просмотров 545Год назад
This time the focus are on using service principals together with Terraform, in settings like GitHub actions or Azure Devops pipelines (interactively). Marius are showing 3 different methods in his examples and you can find the files here: github.com/goodworkaround/bluescreen_scripts 00:00 Intro 00:20 Terraform 01:10 Creating the App registration 01:55 Giving permissions 03:30 Client secret or ...
Entra App registration - Step-by step part 3
Просмотров 500Год назад
Using Azure CLI with a service principal instead of interactive sign in are this episodes topic. Showing how to do it from scratch, starting with Entra/Azure App registration and ending with creation of a Key Vault in our example 00:00 Intro 00:47 App registration 01:39 Granting permissions 02:30 The right role / Permissions 03:08 Login in with service principal 04:30 Certificates and secrets T...
Entra App registration - Step-by step part 2
Просмотров 836Год назад
Marius shows how to use the "magic" of Managed service identities instead of secrets to make Entra/Azure AD Apps more secure and easier to maintain. We are creating it from scratch with Apps, permissions and Logic Apps 00:00 Intro 01:15 Managed service identity 01:45 Creating a Logic App 02:45 System assigned identity 03:45 Azure role assignments 04:50 Adding permissions/roles from PowerShell/ ...
Entra App registration - Step-by step part 1
Просмотров 2 тыс.Год назад
Step-by-step guide to follow up our deep dive series of App registration. In this first part, we will show how to create an App registration and a Service principal to connect and work from PowerShell Location of the example scripts are: github.com/goodworkaround/bluescreen_scripts 00:00 Intro 00:45 Microsoft Graph from PowerShell 01:45 App registration 02:30 Assigning permissions 03:35 Client ...
Entra App Registration: A deep dive into configuration part 4
Просмотров 2 тыс.Год назад
This time Marius and Olav are looking into the confusing side of roles and permission on the App registrations. Keywords are: Roles and administrators, App roles, Group claims with security groups and directory roles, Owners 00:00 Intro 00:55 The confusion! 01:34 Roles and administrators 02:22 PIM assigning roles like "Cloud application administrator" 05:00 Owners 06:44 API permissions 07:05 Pr...
Entra App Registration: A deep dive into configuration part 3
Просмотров 2,4 тыс.Год назад
Entra App Registration: A deep dive into configuration part 3
Entra App Registration: A deep dive into configuration part 2
Просмотров 3,7 тыс.Год назад
Entra App Registration: A deep dive into configuration part 2
Entra App Registration: A deep dive into configuration part 1
Просмотров 17 тыс.Год назад
Entra App Registration: A deep dive into configuration part 1
Microsoft Defender for Cloud - Workbooks
Просмотров 570Год назад
Microsoft Defender for Cloud - Workbooks
Microsoft Defender for Cloud - Using and understanding the portal
Просмотров 410Год назад
Microsoft Defender for Cloud - Using and understanding the portal
Azure Policy - Assigning and Exemptions
Просмотров 707Год назад
Azure Policy - Assigning and Exemptions
Azure - App registration and Enterprise Applications part 3, Managment and monitoring
Просмотров 1,4 тыс.2 года назад
Azure - App registration and Enterprise Applications part 3, Managment and monitoring
Azure - App registration and Enterprise Applications part 2, Managed Identities joins inn
Просмотров 2,7 тыс.2 года назад
Azure - App registration and Enterprise Applications part 2, Managed Identities joins inn
Azure - App registration and Enterprise Applications
Просмотров 26 тыс.2 года назад
Azure - App registration and Enterprise Applications
Thanks for the in-depth video, cleared a lot of doubts I had.
This is for apps that you have built and want to register for Microsoft Entra ID, correct? I want to make sure it is not for another organizations app that a company wants to deploy to their Azure environment.
Yes, this is how we setup and test our App registration. But as long as you have the appid, tenantid and secret you can connect, check the token and do what it gives you the permission to do
Big great for nice presentation 😍
Yeah, I learned something! :) Kudos Have you covered removing the permissions or grants from demo tenant when you don't want to use the enterprise app anymore?
Thanks for the input, will see if we can do an episode on that
Nice video thanks, but the part with service principal (SP) I didn't understand, SP can use app only in CLI (not UI mode), so as I understand: Adele activates permission for 1 hour and runs a script with SP? And SP is part of "Demo-Pim" application. This Entra ID is really hard to understand, in AWS is much clearer
The Enterprise App here is just a "random" app to show how you can use the Cloud application administrator role combined with Privileged Identity Management. This will increase the security since you must activate the role before making any changes to the app. If you are the owner you will be able to make changes to the app all the time. It will not affect the usage of the Enterprise app/SP, just the possibility to modify the "attributes" of the application itself. If you want to combine PIM with the usage of the app you can use access packages, and/or groups that require activation. As you point out, using it as a service principal you would not use PIM.
Good job guys 🎉
Good video, disks can cost a lot of money if left out, especially as an SSD. Do you know if its possible to detect how long a VM has been turned off? Its almost the same problem with solo disks and if it would be possible to be notified if a VM has been turned off for 30 days or more it could be a way to reduce costs as well, as the VM might not be in use similar to a disk.
Thanks. Sorry about the late answer. But maybe this blog post will help you on the way with when VMs where turned off www.altaro.com/hyper-v/get-virtual-machine-last-on-off-time/
Do you know a way to get this on Windows 10?…and does it work with Zoom?
Only a Windows 11 feature, but it should be working on zoom
This is a good 1 hour learning session..Thanks for your efforts.
Great video! Thx
Blue screen Brothers, “we’re on a mission from god.”
Thank you for the excellent presentation and the rich content you shared. If possible, could you please include a 1080p quality option? The text is a bit difficult to read.
Will check, most are uploaded with 1080. Weird that this one isn’t
Why the focus on laptops over desktops in terms of on-board AI and integrated NPUs? Why not both?
Was just because the recent release of new Surface models happened that period
nice nice nice
Thanks
Thank You very much, It's so helpful
I want to register azure enterprise app through .net code not power shell.. suggest any video demo for this..
So insightful , thank you :)
Glad you enjoyed it! - Alex :)
Thanks a lot guys. First time i understood this mess.
nice episode!
nice content
good video, thanks guys
Promo-SM 😌
Extremely helpful series! I watched all and learned so much. Thank you ❤
amazing video thank for that
Thank you for the amazing explanation. You got a sub. ❤
thanks for these informative videos. You earned a sub.
Hi, maybe its possible for next episode to make a step by step guide how to configure custom claims mapping in access_token, for example how to add stuff to it from entra id. like jobtitle, company name and etc
Thanks for proposal, will check with Marius if we can plan an episode soon
really enjoyed it. looking forward to more awesome sessions just like this.
Glad to hear, will continue with more of the same stuff
Is there a timeframe for integration to Azure DevOps? Another great presentation!! Would be good to know with MS have plans to look outside APIM for standalone API's both in Azure and On-Premise?
Unfortunately this is information that cannot be shared without NDA. But I completely agree with both.
It's a lot of thing coming you can keep an eye on the upcoming changes here: learn.microsoft.com/en-us/azure/defender-for-cloud/upcoming-changes?wt.mc_id=4020472
well done.
Great presentation, really looking forward to Part 2!!
Coming soon, just need to be edited
@@bluescreenbrothers Would be great to know if MS will expand the service to include Azure API's outside of APIM, and/or on-premise API's.
@@andrewlloyd5140 I agree :-)
Excellent. Bravo.
Thanks!
Great deep dive on this, appreciate you posting. I will admit this episode lost me a bit. You covered how to add app roles, and how to identify them in a token, but I still have no idea how they work. How do app roles actually give you extra permissions to the app? What does it key off of? Are there a list of app roles that are pre-built that we can see. You seemed to type random names for the app roles, but I didn't see any drop down to actually choose an app role that would grant you extra permissions, so I really don't understand that feature. From this demo, I didn't see any benefit to app roles at all other than administrative grouping. Perhaps another video to better explain it? Thanks!
Thanks for good feedback, will look into making a episode highlighting your questions
Brilliant , thank you
Thank you for this great video
Glad you enjoyed it!
Great videos I am following through them. I get an error 'the remote server returned an error: 401 Unauthorized' I can query the info fine from the graph portal. Any idea what the cause might be?
Sound like permissions related, we are planning an permission episode. could it be that you haven't added the user yet?
Could you guys demo service to service use cases (like microservices)? Basically no users, only application to application calls. Also would be curious how to auto provision roles for client apps without the manual admin approval step.
Is there still the Microsoft Tenant Demo? How to access?
Some customers have access to the new version of demos with this link: cdx.transform.microsoft.com/ (This is the one we are using in out demos) Or I think you might use this for free: developer.microsoft.com/en-us/microsoft-365/dev-program
@@bluescreenbrothers Thank you, Bro. And congratulations, good job with this video.
Nice Session
Thx
This is Cool & Awesome
Part 3!
And that's why I should not publish on a sunday evning :-D Thanks for the headsup
This is very, very good. I loved the multi tenant service provider piece of the puzzle. Thanks for putting the effort in.
great video thanks for the tutorial!
Great vid. Thanks, guys.
Thanks for watching! Next episode will come on monday ;-)
Very helpful and informative. Thanks, guys.
Glad it was helpful! Stay tuned for more. Editing part 2 and 3, finished record part 4 and planned some more :-D
Please complete the app registration part . Need to know about all options in App registration. If possible, you can show the demo app config and then check for user sign in. Also how to add optional claims and location mapping.
I am now editing the 3 first episode about deep diving into App registration ;-)
This is just multiple documentation pages in one hr ...no words...great stuff....keep continuing
This was really cool! I’m just starting with this stuff and the explanation was really great! Thanks!
Waiting for your custom policies
Will be published next week, I will do the editing this weekend
Hi guys , Really Interesting Video but i have a question regrading sign in logs for each application , i created a kusto query to get all formation about my application sign-in logs but i got a application informtion in azure enterprise application thats are microsoft Built in i guess but how to get all application information except microsoft built app : Office 365, Visual studio , Azure Devops & so on
Maybe adding the "where AADTenantId" will help? Haven't testet it. learnsentinel.blog/2022/03/16/maintaining-a-well-managed-azure-ad-tenant-with-kql/