Azure Local – Recreate VM switch for Network ATC Intent

This article contains commands for recreating a VM switch with VM Switch Embedded Team for the Converged Switch for management and compute. This assumes that management and compute is combined in the same Network ATC Intent on your cluster. Normally this is not something you would do, but if you see issues or errors like …
Continue reading Azure Local – Recreate VM switch for Network ATC Intent

Email Communication with Azure Communication Services

Intro Sending emails from an application can be very useful. There are also other scenarios where Azure Communication Services can be very useful to implement, e.g. when moving from Exchange Online Basic Auth which Microsoft will retire by September 2025. Key considerations Sending rate limits Microsoft informs about the initial rate limits for the service …
Continue reading Email Communication with Azure Communication Services

Microsoft Global Secure Access – Private Access – Part 6 – Additional Conditional Access Policies

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect Intro Target applications are subject to the Conditional Access policies that the user attempting to access the application is already subject to. However, there may be situations where you want to add additional protection …
Continue reading Microsoft Global Secure Access – Private Access – Part 6 – Additional Conditional Access Policies

Microsoft Global Secure Access – Private Access – Part 5 – Bypass GSA on local corporate network with direct access to target applications

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect Intro Global Secure Access protects applications much more effectively and securely than traditional VPN solutions. When using conditional access together with global secure access, zero trust principles are maintained. If you have servers on-premises …
Continue reading Microsoft Global Secure Access – Private Access – Part 5 – Bypass GSA on local corporate network with direct access to target applications

Microsoft Global Secure Access – Private Access – Part 4 – Test configuration and target application

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect Intro I have created an Entra ID joined VM in Azure running Windows 11 Pro 24H2. The user I test with has been assigned Microsoft 365 E3 + Microsoft Entra Suite licenses (if you …
Continue reading Microsoft Global Secure Access – Private Access – Part 4 – Test configuration and target application

Microsoft Global Secure Access – Private Access – Part 3 – Configure target application

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect Configure your first application Once the initial configuration is setup and client software deployed to clients, we can go ahead and create our first protected application. Go to Global Secure Access > Applications > …
Continue reading Microsoft Global Secure Access – Private Access – Part 3 – Configure target application

Microsoft Global Secure Access – Private Access – Part 2 – Deploy client software

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect Intro Below I have highlighed some crusial things to consider and prepare before you start your deployment Prerequisites Deploy using Intune Microsoft Learn has an excellent article about deployment of the Global Secure Access …
Continue reading Microsoft Global Secure Access – Private Access – Part 2 – Deploy client software

Microsoft Global Secure Access – Private Access – Part 1 – Initial configuration

This article is part of a series: Microsoft Global Secure Access – Private Access – Christoffer Klarskov Jakobsen – Microsoft Architect To get started using Private Access within Global Secure Access, go to https://entra.cmd.ms (sign in with global administrator account or account with required permissions: https://learn.microsoft.com/en-us/entra/global-secure-access/reference-role-based-permissions) Intro This article is part of a series. Navigate …
Continue reading Microsoft Global Secure Access – Private Access – Part 1 – Initial configuration

Microsoft Global Secure Access – Private Access

This will be a series of articles about Microsoft Global Secure Access and specifically Private Access (also called Private Access Profile). Licensing overview Prerequisite to use Microsoft Entra Private Access and Microsoft Entra Internet Access is Microsoft Entra ID P1 or Microsoft Entra ID P2.

Azure subscriptions – limit and monitor Pay-as-you-go subscription

Intro There is not direct way to deny administrators the ability to create free trial, Pay-as-you-go and Azure for Students subscriptions in Azure. However their are a few ways to limit and monitor creations. These settings should every organization enable to limit the possibility for users to create subscriptions and resources that is not govern …
Continue reading Azure subscriptions – limit and monitor Pay-as-you-go subscription