POPULARITY
Strategic Technology Consultation Services This episode of The Modern .NET Show is supported, in part, by RJJ Software's Strategic Technology Consultation Services. If you're an SME (Small to Medium Enterprise) leader wondering why your technology investments aren't delivering, or you're facing critical decisions about AI, modernization, or team productivity, let's talk. Show Notes "In the agentic world that makes a lot of people really uncomfortable because what ends up happening is the agent has it, the agent has its own ID and then interacts with your data database."— Jerry Nixon Hey everyone, and welcome back to The Modern .NET Show; the premier .NET podcast, focusing entirely on the knowledge, tools, and frameworks that all .NET developers should have in their toolbox. I'm your host Jamie Taylor, bringing you conversations with the brightest minds in the .NET ecosystem. Today, Jerry Nixon returned to the show to talk about SQL MCP Server, something of a new product _and_ the evolution of Data API Builder; which we talked to Jerry about back in episode three of this season (there'll be a link in the show notes). Jerry does a much better job of introducing it than I can, but suffice it to say that SQL MCP Server is an MCP Server which abstracts away intracting with a SQL database... of almost any flavour. SQL Server, CosmosDB, Postgres, you name it. "I mean there is nothing better for any agent than saying "new session." That is how you like create better answers all the time. You might feel like you have this session, you've been training it so long and you've told it so much, it has so much context that now when you ask it, it'll finally have the answer that you're looking for."— Jerry Nixon Along the way, Jerry shared a lot of solid gold nuggets of advice about MCP servers, best practices for interacting with agents and models, and even context management. And, of course, we talk about how simple is almost always the best solution (and how SQL MCP Server might be one of the ways for you to achieve that). Before we jump in, a quick reminder: if The Modern .NET Show has become part of your learning journey, please consider supporting us through Patreon or Buy Me A Coffee. Every contribution helps us continue bringing you these in-depth conversations with industry experts. You'll find all the links in the show notes. So let's sit back, open up a terminal, type in `dotnet new podcast` and we'll dive into the core of Modern .NET. Full Show Notes The full show notes, including links to some of the things we discussed and a full transcription of this episode, can be found at: https://dotnetcore.show/season-8/giving-ai-agents-safe-access-to-your-data-sql-mcp-server-with-jerry-nixon/ Useful Links: Data API Builder & SQL MCP Serverdocumentation Data API Builder on GitHub Book time with Jerry to discuss SQL MCP an your projects Agentic Design Patterns by Antonia Gulli Supporting the show: Leave a rating or review Buy the show a coffee Become a patron Getting in Touch: Via the contact page Joining the Discord Remember to rate and review the show on Apple Podcasts, Podchaser, or wherever you find your podcasts, this will help the show's audience grow. Or you can just share the show with a friend. And don't forget to reach out via our Contact page. We're very interested in your opinion of the show, so please get in touch. You can support the show by making a monthly donation on the show's Patreon page at: https://www.patreon.com/TheDotNetCorePodcast. Music created by Mono Memory Music, licensed to RJJ Software for use in The Modern .NET Show. Editing and post-production services for this episode were provided by MB Podcast Services.
What happens when the database becomes an active participant in AI applications instead of just a place to store data? In this session of The Ravit Show, I sat down with Jay Gordon and Patty Chow to unpack the biggest announcements and takeaways from CosmosDB Conf!!!!One theme stood out throughout the conference:AI is not just changing applications. It's changing the database itself.We discussed:- How OpenAI scales from zero to millions of queries per second- Why Walmart relies on globally distributed architectures to keep checkout systems running during failures- How vector search, full-text search, and hybrid search are becoming native database capabilities- The rise of agent memory architectures and AI-native applications- Why developers need real-time visibility into query costs- How to think about CosmosDB vs Azure DocumentDB based on workload requirements- What the Azure CosmosDB Agent Kit means for developers building AI-powered systemsOne of my biggest takeaways was that retrieval is increasingly moving into the database layer itself. Instead of stitching together multiple services, developers can now work with a more unified approach to search, AI, and data.If you're building AI applications, working with data infrastructure, or trying to understand where databases are headed next, this conversation is worth watching.The full interview is now live.What was your biggest takeaway from CosmosDB Conf this year?#data #ai #azure #cosmosDB #microsoft #api #microservices #theravitshow
How do you intelligently surface access to your database? While at NDC Toronto, Richard spoke with Jerry Nixon about Data API Builder, Microsoft's tool that enables data professionals using Microsoft databases, including SQL Server, Postgres, CosmosDB, and MySQL, to provide an API layer with security, schema extraction, and governance policies. You can expose the API as a REST interface, a GraphQL interface, and an MCP server! This is a powerful tool for providing controlled access to data while still allowing for ad-hoc access. The potential is huge - you need to check it out! Links Data API Builder GraphQL Recorded May 7, 2026
If you are building anything in AI right now, you need to pay attention to this. I recently sat down with Kirill Gavrylyuk, VP of Azure Cosmos DB, Microsoft on The Ravit Show, and one thing was very clear. The biggest challenge in AI today is not just models. It is the data layer. We talked about where things are actually breaking. Teams are building AI apps, but they struggle with memory, real-time data, and systems that need to scale globally. This is exactly where Cosmos DB is becoming critical.What stood out to me is how practical this is getting. This is not about concepts anymore. It is about how real teams are building AI agents, how they manage state and memory, and how they design systems that actually work in production.That is why Cosmos DB Conf 2026 next week matters.This is not a theory-heavy event. It is focused on what is actually working. Real use cases, real architectures, real lessons. You will hear how teams are building RAG systems, scaling applications, and handling performance and cost in the real world.Also, it is completely free. Which honestly makes it a no-brainer.And you do not just watch. The Skills Challenge gives you a way to actually build and apply what you learn.I will be covering this live on April 28 and sharing the key takeaways.If you are serious about AI, data, or building systems that scale, this is worth your time.Register here: https://lnkd.in/ggNcVK6YApril 28 -- Show up and learn what actually works#data #ai #azure #cosmosDB #microsoft #api #microservices #theravitshow
Fredrik chats to Shawn Wildermuth about evolving in the world of software development, small changes adding up, developer hiring, not chasing the new thing, and quite a bit more. Fredrik is still hoping for the last episode of Shawn’s old podcast. Making sure you use your time in a way that’s right for you. Whether it’s spending lots of time learning new stuff or getting deep into the tech you really enjoy. Recorded during Øredev 2025. Thank you Cloudnet for sponsoring our VPS! Comments, questions or tips? We a re @kodsnack, @tobiashieta, @oferlund and @bjoreman on Twitter, have a page on Facebook and can be emailed at info@kodsnack.se if you want to write longer. We read everything we receive. If you enjoy Kodsnack we would love a review in iTunes! You can also support the podcast by buying us a coffee (or two!) through Ko-fi. Links Shawn Shawn on Github Shawn’s old podcast Hello world Richard Campbell and Carl Franklin, of the .NET rocks podcast Science Friday, from PBS What’s new in C# 14 and .NET 10 - Shawn’s presentation at Øredev 2025 .NET core Blazor ASP.NET Null forgiveness .NET conf Nullable reference types Objective-c Tell the C# compiler to act like older versions Generics Nullable value types Pluralsight Windows phone Foxpro Impostor syndrome Shawn’s film Hello world - confronting bias in software development Support us on Ko-fi! Oslo Winfs Practical file system design with the Be file system - The Beos file system book by Dominic Giampaolo Beos GEOS Silverlight Open sourced Webassembly-based Silverlight version Kotlin CLR Fortran COBOL MUMPS Vue Cosmos DB Azure foundry Eleventy Titles I feel like I never did a podcast Edit the last one What’s your focus? There’s not enough to talk about here Null forgiveness Talk about nullability The next fifteen years Where I’m best used Paid to learn the new stuff I’m just happy to be around Those quiet voices Win the design meeting Wrong about Webassembly Actual system languages Five years from being useful A two-IDE person
In this episode, host Sandy Vance and Hari Balasubramanian, the Chief Technology Officer, Health Information Systems at Solventum, sit down for a deep dive into how AI-driven healthcare technology is reshaping the industry. Together, they explore how Solventum is building innovative products and services that streamline documentation, billing, and coding while improving the patient experience and saving valuable time for healthcare professionals. From what's happening at Solventum right now to the company's move toward fully autonomous coding, this conversation unpacks how healthcare payers and providers can rethink financial performance in the age of artificial intelligence. Hari also shares practical insights for CIOs evaluating these systems and explains how Solventum measures real-world improvements driven by AI. If you're interested in healthcare innovation, revenue cycle transformation, or the future of AI in health information systems, this is an episode you won't want to miss.Check out Solventum's Education Session and Case Study Session that was presented in the AI Zone at HLTH 2025.In this episode, they talk about:What's going on with Solventum right nowHow Solventum is serving healthcare payersSolventum's move toward complete autonomous codingThe common misconceptions about improving financial performance for providersHow CIOs should evaluate their work when engaging with these systemsMeasuring the improvements produced by AI with Solventum's systemsA Little About Hari:Hari Bala joined Solventum as Chief Technology Officer, Health Information Systems, in May 2025, bringing more than 25 years of experience building large-scale, distributed systems across healthcare, cloud, and security, with deep expertise in GenAI, data science, analytics, and machine learning. Previously, he led AI, data, analytics, and cloud transformation efforts at GE Healthcare and Oracle Cerner, where he helped establish Oracle's AI Services organization and later led the Health Data Intelligence and Analytics platform following the Cerner acquisition. Earlier, Hari spent nearly 19 years at Microsoft in leadership roles spanning Azure, Search, Cosmos DB, Windows, Office 365, and mobile and browser technologies.
In this episode Michael, Sarah and Mark talk with guest Ryen Macababbad, Principal Security Program Manager at Microsoft about her current work on standardizing security terminology and taxonomy across Microsoft. Also, how getting terminology right is important to security, especially for those with neurodiverse conditions, such as autism.We also discuss Azure Security news about the Microsoft AI tour Sarah is doing, Cosmos DB, and Michael goes on a rant about TLS certificate checking. https://aka.ms/azsecpod
This is episode 300 recorded on July 31st, 2025, where John & Jason talk the Microsoft Fabric July 2025 Feature Summary including tags in Fabric Domains, Fabric Data Agent integration with Microsoft Copilot Studio, enhancements to Activator, manual control of Auto-Refresh in pipelines, and CosmosDB in preview now in Fabric. For show notes please visit www.bifocal.show
This is episode 296 recorded on June 6th, 2025, where John & Jason talk the Microsoft Fabric May 2025 Feature Summary including a REST API updates for Fabric, updates to User Data Functions, Copilot in Power BI support for Fabric data agents, CosmosDB in Fabric, DataFlows Gen 2 CI/CD support is now GA, updates to Data Pipelines & Mirroring, and much more. For show notes please visit www.bifocal.show
Bentornati e bentornate su Azure Italia Podcast, il podcast in italiano su Microsoft Azure!Per non perderti nessun nuovo episodio clicca sul tasto FOLLOW del tuo player
In this episode we speak to Nic Fillingham who is a Senior Program Manager at Microsoft about security conferences and mainly about the Microsoft Bluehat conference he runs. We also discuss security about PostgreSQL, Cosmos DB, IP address management, containers and AI Studio. https://aka.ms/azsecpod
Leverage Azure Cosmos DB for generative AI workloads for automatic scalability, low latency, and global distribution to handle massive data volumes and real-time processing. With support for versatile data models and built-in vector indexing, it efficiently retrieves natural language queries, making it ideal for grounding large language models. Seamlessly integrate with Azure OpenAI Studio for API-level access to GPT models and access a comprehensive gallery of open-source tools and frameworks in Azure AI Studio to enhance your AI applications. ► QUICK LINKS: 00:00 - Azure Cosmos DB for generative AI workloads 00:18 - Versatile Data Models 00:39 - Scalability and performance 01:19 - Global distribution 01:31 - Vector indexing and search 02:07 - Grounding LLMs 02:30 - Wrap up ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Get a unified solution for secure access management, identity verification, and Zero Trust security for cloud and on-premises resources. The new Microsoft Entra suite integrates five capabilities: Private Access, Internet Access, ID Protection, ID Governance, and Face Check as part of Verified ID Premium, included with Microsoft Entra Suite. With these capabilities, you can streamline user onboarding, enhance security with automated workflows, and protect against threats using Conditional Access policies. See how to reduce security gaps, block lateral attacks, and replace legacy VPNs, ensuring efficient and secure access to necessary resources. Jarred Boone, Identity Security Senior Product Manager, shares how to experience advanced security and management with Microsoft Entra Suite. ► QUICK LINKS: 00:00 - Unified solution with Microsoft Entra Suite 00:38 - Microsoft Entra Private Access 01:39 - Microsoft Entra Internet Access 02:42 - Microsoft Entra ID Protection 03:31 - Microsoft Entra ID Governance 04:18 - Face Check in Verified ID Premium, included with Microsoft Entra Suite 04:52 - How core capabilities work with onboarding process 06:08 - Protect access to resources 07:22 - Control access to internet endpoints 08:05 - Establish policies to dynamically adjust 08:45 - Wrap up ► Link References Try it out at https://entra.microsoft.com Watch our related deep dives at https://aka.ms/EntraSuitePlaylist Check out https://aka.ms/EntraSuiteDocs ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
CosmosDB makes ChatGPT fast! While at Build in Seattle, Carl and Richard chatted with Mark Brown about CosmosDB's role in AI. Mark talks about how ChatGPT switched over to CosmosDB early on - when the number of users started to climb, database performance became essential, and CosmosDB was there. Today, many AI-centric CosmosDB features exist, like vector storage, indexing, and search! The conversation also digs into the impact of the large language model on development - things are different now!
CosmosDB makes ChatGPT fast! While at Build in Seattle, Carl and Richard chatted with Mark Brown about CosmosDB's role in AI. Mark talks about how ChatGPT switched over to CosmosDB early on - when the number of users started to climb, database performance became essential, and CosmosDB was there. Today, many AI-centric CosmosDB features exist, like vector storage, indexing, and search! The conversation also digs into the impact of the large language model on development - things are different now!
CosmosDB makes ChatGPT fast! While at Build in Seattle, Carl and Richard chatted with Mark Brown about CosmosDB's role in AI. Mark talks about how ChatGPT switched over to CosmosDB early on - when the number of users started to climb, database performance became essential, and CosmosDB was there. Today, many AI-centric CosmosDB features exist, like vector storage, indexing, and search! The conversation also digs into the impact of the large language model on development - things are different now!
Ensure high-accuracy, efficient vector search at massive scale with Azure Cosmos DB. Leveraging Microsoft's DiskANN, more IO traffic moves to disk to maximize storage capacity and enable high-speed similarity searches across all data, reducing memory dependency. This technology, powering global services like Microsoft 365, is now integrated into Azure Cosmos DB, enabling developers to build scalable, high-performance applications with built-in vector search, real-time fraud detection, and robust multi-tenancy support. Join Kirill Gavrylyuk, VP for Azure Cosmos DB, as he shares how Azure Cosmos DB with DiskANN offers unparalleled speed, efficiency, and accuracy, making it the ideal solution for modern AI-driven applications. ► QUICK LINKS: 00:00 - Latest Cosmos DB optimizations with DiskANN 02:09 - Where DiskANN approach is beneficial 04:07 - Efficient querying 06:02 - DiskANN compared to HNSW 07:41 - Integrate DiskANN into a new or existing app 08:39 - Real-time transactional AI scenario 09:29 - Building a fraud detection sample app 10:59 - Vectorize transactions for anomaly detection 12:49 - Scaling to address high levels of traffic 14:05 - Manage multi-tenancy 15:35 - Wrap up ► Link References Check out https://aka.ms/DiskANNCosmosDB Try out apps at https://aka.ms/DiskANNCosmosDBSamples ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
In this episode, Warner is joined by Sandeep Arora to discuss the main announcements from the Microsoft Build 2024 conference in Seattle. These include the new GPT 4-o generative AI model, new AI capabilities in Fabric, improvements coming to Azure Database for Postgresql, CosmosDb and more!
In this episode, Steve, Frank and Mike discuss the benefits of using the free tier in Microsoft Azure. They explore the various free offerings available, such as Azure Cosmos DB, Azure DevOps, and speech-to-text translation. They also discuss the importance of monitoring costs and implementing processes to prevent unexpected expenses. Mike shares insights on cost optimization for Cosmos DB and announces an upcoming video on the topic.
Build low-latency recommendation engines with Azure Cosmos DB and Azure OpenAI Service. Elevate user experience with vector-based semantic search, going beyond traditional keyword limitations to deliver personalized recommendations in real-time. With pre-trained models stored in Azure Cosmos DB, tailor product predictions based on user interactions and preferences. Explore the power of augmented vector search for optimized results prioritized by relevance. Kirill Gavrylyuk, Azure Cosmos DB General Manager, shows how to build recommendation systems with limitless scalability, leveraging pre-computed vectors and collaborative filtering for next-level, real-time insights. ► QUICK LINKS: 00:00 - Build a low latency recommendation engine 00:59 - Keyword search 01:46 - Vector-based semantic search 02:39 - Vector search built-in to Cosmos DB 03:56 - Model training 05:18 - Code for product predictions 06:02 - Test code for product prediction 06:39 - Augmented vector search 08:23 - Test code for augmented vector search 09:16 - Wrap up ► Link References Walk through an example at https://aka.ms/CosmosDBvectorSample Try out Cosmos DB for MongoDB for free at https://aka.ms/TryC4M ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
In this first episode following Mad March™, the trio tackle the deluge of news not only from Fabric Community Conference, but also from Intune, CosmosDB, the new Surface devices and much more!Show notes Hosted on Acast. See acast.com/privacy for more information.
In this first episode following Mad March™, the trio tackle the deluge of news not only from Fabric Community Conference, but also from Intune, CosmosDB, the new Surface devices and much more!Show notes Hosted on Acast. See acast.com/privacy for more information.
Join Scott Hanselman and James Codella to learn how you can turn your natural language questions about your data into Azure Cosmos DB NoSQL queries to find the right data to power your applications more easily. Chapters 00:00 - Introduction 00:55 - Copilot for Azure in Cosmos DB 02:40 - Demo 08:30 - Discussion 10:20 - Wrap-up Recommended resources Microsoft Copilot for Azure enables natural language queries for Azure Cosmos DB data Generate NoSQL queries with Microsoft Copilot for Azure in Cosmos DB Frequently asked questions about Microsoft Copilot for Azure in Cosmos DB Create a Pay-as-You-Go account (Azure) Create a free account (Azure) Connect Scott Hanselman | Twitter/X: @SHanselman James Codella | Twitter/X: @JamesCodella Azure Cosmos DB | Twitter/X: @AzureCosmosDB Azure Friday | Twitter/X: @AzureFriday Azure | Twitter/X: @Azure
Join Scott Hanselman and James Codella to learn how you can turn your natural language questions about your data into Azure Cosmos DB NoSQL queries to find the right data to power your applications more easily. Chapters 00:00 - Introduction 00:55 - Copilot for Azure in Cosmos DB 02:40 - Demo 08:30 - Discussion 10:20 - Wrap-up Recommended resources Microsoft Copilot for Azure enables natural language queries for Azure Cosmos DB data Generate NoSQL queries with Microsoft Copilot for Azure in Cosmos DB Frequently asked questions about Microsoft Copilot for Azure in Cosmos DB Create a Pay-as-You-Go account (Azure) Create a free account (Azure) Connect Scott Hanselman | Twitter/X: @SHanselman James Codella | Twitter/X: @JamesCodella Azure Cosmos DB | Twitter/X: @AzureCosmosDB Azure Friday | Twitter/X: @AzureFriday Azure | Twitter/X: @Azure
Join Scott Hanselman and James Codella to learn how you can turn your natural language questions about your data into Azure Cosmos DB NoSQL queries to find the right data to power your applications more easily. Chapters 00:00 - Introduction 00:55 - Copilot for Azure in Cosmos DB 02:40 - Demo 08:30 - Discussion 10:20 - Wrap-up Recommended resources Microsoft Copilot for Azure enables natural language queries for Azure Cosmos DB data Generate NoSQL queries with Microsoft Copilot for Azure in Cosmos DB Frequently asked questions about Microsoft Copilot for Azure in Cosmos DB Create a Pay-as-You-Go account (Azure) Create a free account (Azure) Connect Scott Hanselman | Twitter/X: @SHanselman James Codella | Twitter/X: @JamesCodella Azure Cosmos DB | Twitter/X: @AzureCosmosDB Azure Friday | Twitter/X: @AzureFriday Azure | Twitter/X: @Azure
Join Scott Hanselman and James Codella to learn how you can turn your natural language questions about your data into Azure Cosmos DB NoSQL queries to find the right data to power your applications more easily. Chapters 00:00 - Introduction 00:55 - Copilot for Azure in Cosmos DB 02:40 - Demo 08:30 - Discussion 10:20 - Wrap-up Recommended resources Microsoft Copilot for Azure enables natural language queries for Azure Cosmos DB data Generate NoSQL queries with Microsoft Copilot for Azure in Cosmos DB Frequently asked questions about Microsoft Copilot for Azure in Cosmos DB Create a Pay-as-You-Go account (Azure) Create a free account (Azure) Connect Scott Hanselman | Twitter/X: @SHanselman James Codella | Twitter/X: @JamesCodella Azure Cosmos DB | Twitter/X: @AzureCosmosDB Azure Friday | Twitter/X: @AzureFriday Azure | Twitter/X: @Azure
CosmosDB has been a great data platform in the Azure cloud that helps companies deal with disparate types of data. The CosmosDB APIs include those for MongoDB, PostgreSQL, Cassandra, and Gremlin. These wire-level protocols let you work in a way that is compatible with those systems for storing data. That's coming to SQL Server. Read the rest of CosmosDB APIs Inside SQL Server 2024
Take advantage of Azure Cosmos DB for your AI-driven applications. Seamlessly integrate with large language models like ChatGPT, for real-time operational efficiency and limitless scalability. With its built-in vector search engine and multi-model support, Azure Cosmos DB for MongoDB vCore optimizes for just-in-time data retrieval, so you can build cutting-edge solutions at any scale. Kirill Gavrylyuk, General Manager for the Azure Cosmos DB team, joins Jeremy Chapman to share how you can increase performance and cost-effectiveness, whether managing millions of users globally or building smaller-scale apps. ► QUICK LINKS: 00:00 - Get your database ready for AI with Azure Cosmos DB 02:33 - Solve for real-time data access requirements 03:39 - Automatic scaling 05:35 - How Azure CosmosDB works for copilot-style apps 06:38 - App using vectorized data 07:24 - Jupyter notebook demo 09:19 - Vector indexing and search in Cosmos DB 10:14 - Building a small copilot-style app 12:10 - Run smaller apps serverless 12:35 - Set maximum throughput thresholds 13:39 - Auto scale using Cosmos DB 14:38 - Wrap Up ► Link References: See how Cosmos DB vector search capabilities work at https://aka.ms/CosmosVector Get a free trial at https://aka.ms/trycosmosdb ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
How do you choose an Azure data storage solution? Richard talks to Nicole Stevens about her experiences helping companies move data into the cloud - typically in SQL Server. The obvious answer is Azure SQL, but that doesn't always make it the best solution! Nicole talks about a customer moving to Cosmos DB for the unstructured data capabilities and a lot of speed. But does the price make sense? All these factors are in play in choosing a data storage solution, and there is never one right choice - often, a mix of services makes the most sense!Links:Azure SQLAzure Cosmos DBAPIs in Cosmos DBAzure Table StorageAzure Queue StorageAzure Messaging Servicesdapr - Distributed Application RuntimeMicrosoft CertificationsData Architecture GuideData Landing Zones Azure Security BaselinesRecorded September 6, 2023
In this episode Michael, Sarah, Gladys, and Mark talk with guest Roberto Rodriguez about attack simulation, Cloud Katana, and AI.We also discuss Azure Security news about Azure SQL DB, Azure Key Vault, Cosmos DB, Trusted Launch VMs, Azure Artifacts, Zero Trust, Windows and TLS and Entra ID.
Jak powstała usługa Allegro Pay i co ma wspólnego z ratatouille? Jakie projekty i technologie stoją za tym rozwiązaniem? Jak to jest pracować w Azure i obsługiwać ruch, który generuje Allegro? Czym inżynierów może zaskoczyć praca w Allegro Pay i co czeka na nich (na przykład) w programie All4Customer? O migrowaniu baz CosmosDB, wymaganiach skali i dostępności, a także o rozwijaniu ludzi i technologii rozmawialiśmy z Mariuszem Budzynem i Tomaszem Szczerbą. Zapraszamy do słuchania! Mariusz BudzynSenior Manager w Allegro Pay. Lider zespołów technicznych dla usług finansowych Allegro Pay, Allegro Pay Business oraz Merchant Finance. Mocne umiejętności analityczne wykorzystuje do upraszczania świata finansów przez technologię, a jako fan F1 dąży do rozwiązań szybszych i niezawodnych. Czuje, że w jego żyłach płynie również benzyna, a wolne chwile przeznacza na adaptację rozwiązań smart home w swoim domu. Tomasz SzczerbaSenior Manager w Allegro Pay. Na co dzień zajmuje się ulepszaniem Allegro Pay od strony użytkowej i technologicznej. Najlepiej czuje się z C#, ale lubi poznawać nowe rzeczy, co sprawiło, że pisał też między innymi w Scali, F# i JavaScript. Prywatnie lubi zwiedzać na rowerze, czytać książki o kosmosie i pykać w giereczki Nintendo.
Microsoft Build 2023 Book of NewsFull Keynote | Satya Nadella at Microsoft Build 2023Cosmos DB Burst CapacityEvent Gridin pull-toimintoMesh private previewEmpowering every developer with plugins for Microsoft 365 CopilotWindowsin copilotAI Content Safety
This week, Michael, Mark and Gladys talk to Anthony Shaw about some of the best practices and tooling for securing Infrastructure as Code (IaC) solutions. Sarah is away in Singapore, presenting at BlackHat.We also cover security news about DDoS, Cosmos DB, Microsoft Defender for APIs, Load Balancer, Zero Trust and discovering Internet-facing devices.
In episode 135 of our SAP on Azure video podcast we talk about Protecting your Rise and S/4HANA application layer with MS Sentinel today and the certified Microsoft Sentinel 1.0 connector for SAP, Microsoft Azure Applications for Neptune DXP, a new ebook on modernizing SAP on the Microsoft Cloud, updates to the SAP Collaborative ERP with Share to Microsoft Teams, and an upcoming reCAP event which will also look at Cosmos DB integration. Then we Robert will talk about a "refresh day" which should remind customers and partners to revisit their cloud implementations with SAP on Azure. The Microsoft Assessments, like the Azure Well-Architected assessment can be a good starting point for this. https://www.saponazurepodcast.de/episode135 Reach out to us for any feedback / questions: * Robert Boban: https://www.linkedin.com/in/rboban/ * Goran Condric: https://www.linkedin.com/in/gorancondric/ * Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure
About Chris Chris Farris has been in the IT field since 1994 primarily focused on Linux, networking, and security. For the last 8 years, he has focused on public-cloud and public-cloud security. He has built and evolved multiple cloud security programs for major media companies, focusing on enabling the broader security team's objectives of secure design, incident response and vulnerability management. He has developed cloud security standards and baselines to provide risk-based guidance to development and operations teams. As a practitioner, he's architected and implemented multiple serverless and traditional cloud applications focused on deployment, security, operations, and financial modeling.Chris now does cloud security research for Turbot and evangelizes for the open source tool Steampipe. He is one if the organizers of the fwd:cloudsec conference (https://fwdcloudsec.org) and has given multiple presentations at AWS conferences and BSides events.When not building things with AWS's building blocks, he enjoys building Legos with his kid and figuring out what interesting part of the globe to travel to next. He opines on security and technology on Twitter and his website https://www.chrisfarris.comLinks Referenced: Turbot: https://turbot.com/ fwd:cloudsec: https://fwdcloudsec.org/ Steampipe: https://steampipe.io/ Steampipe block: https://steampipe.io/blog TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: Tailscale SSH is a new, and arguably better way to SSH. Once you've enabled Tailscale SSH on your server and user devices, Tailscale takes care of the rest. So you don't need to manage, rotate, or distribute new SSH keys every time someone on your team leaves. Pretty cool, right? Tailscale gives each device in your network a node key to connect to your VPN, and uses that same key for SSH authorization and encryption. So basically you're SSHing the same way that you're already managing your network.So what's the benefit? Well, built-in key rotation, the ability to manage permissions as code, connectivity between any two devices, and reduced latency. You can even ask users to re-authenticate SSH connections for that extra bit of security to keep the compliance folks happy. Try Tailscale now - it's free forever for personal use.Corey: This episode is sponsored by our friends at Logicworks. Getting to the cloud is challenging enough for many places, especially maintaining security, resiliency, cost control, agility, etc, etc, etc. Things break, configurations drift, technology advances, and organizations, frankly, need to evolve. How can you get to the cloud faster and ensure you have the right team in place to maintain success over time? Day 2 matters. Work with a partner who gets it - Logicworks combines the cloud expertise and platform automation to customize solutions to meet your unique requirements. Get started by chatting with a cloud specialist today at snark.cloud/logicworks. That's snark.cloud/logicworksCorey: Welcome to Screaming in the Cloud. I'm Corey Quinn. My guest today is someone that I have been meaning to invite slash drag onto this show for a number of years. We first met at re:Inforce the first year that they had such a thing, Amazon's security conference for cloud, as is Amazon's tradition, named after an email subject line. Chris Farris is a cloud security nerd at Turbot. He's also one of the organizers for fwd:cloudsec, another security conference named after an email subject line with a lot more self-awareness than any of Amazon's stuff. Chris, thank you for joining me.Chris: Oh, thank you for dragging me on. You can let go of my hair now.Corey: Wonderful, wonderful. That's why we're all having the thinning hair going on. People just use it to drag us to and fro, it seems. So, you've been doing something that I'm only going to describe as weird lately because your background—not that dissimilar from mine—is as a practitioner. You've been heavily involved in the security space for a while and lately, I keep seeing an awful lot of things with your name on them getting sucked up by the giant app surveillance apparatus deployed to the internet, looking for basically any mention of AWS that I wind up using to write my newsletter and feed the content grist mill every year. What are you doing and how'd you get there?Chris: So, what am I doing right now is, I'm in marketing. It's kind of a, you know, “Oops, I'm sorry I did that.”Corey: Oh, the running gag is, you work in DevRel; that means, “Oh, you're in marketing, but they're scared to tell you that.” You're self-aware.Chris: Yeah.Corey: Good for you.Chris: I'm willing to address that I'm in marketing now. And I've been a cloud practitioner since probably 2014, cloud security since about 2017. And then just decided, the problem that we have in the cloud security community is a lot of us are just kind of sitting in a corner in our companies and solving problems for our companies, but we're not solving the problems at scale. So, I wanted a job that would allow me to reach a broader audience and help a broader audience. Where I see cloud security having—you know, or cloud in general falling down is Amazon makes it really hard for you to do your side of shared responsibility, and so we need to be out there helping customers understand what they need to be doing. So, I am now at a company called Turbot and we're really trying to promote cloud security.Corey: One of the first promoted guest episodes of this show was David Boeke, your CTO, and one of the things that I regret is that I've sort of lost track of Turbot over the past few years because, yeah, one or two things might have been going on during that timeline as I look back at having kids in the middle of a pandemic and the deadly plague o'er land. And suddenly, every conversation takes place over Zoom, which is like, “Oh, good, it's like a happy hour only instead, now it's just like a conference call for work.” It's like, ‘Conference Calls: The Drinking Game' is never the great direction to go in. But it seems the world is recovering. We're going to be able to spend some time together at re:Invent by all accounts that I'm actively looking forward to.As of this recording, you're relatively new to Turbot, and I figured out that you were going there because, once again, content hits my filters. You wrote a fascinating blog post that hits on an interest of mine that I don't usually talk about much because it's off-putting to some folk, and these days, I don't want to get yelled at and more than I have to about the experience of traveling, I believe it was to an all-hands on the other side of the world.Chris: Yep. So, my first day on the job at Turbot, I was landing in Kuala Lumpur, Malaysia, having left the United States 24 hours—or was it 48? It's hard to tell when you go to the other side of the planet and the time zones have also shifted—and then having left my prior company day before that. But yeah, so Turbot about traditionally has an annual event where we all get together in person. We're a completely remote company, but once a year, we all get together in person in our integrate event.And so, that was my first day on the job. And then you know, it was basically two weeks of reasonably intense hackathons, building out a lot of stuff that hopefully will show up open-source shortly. And then yeah, meeting all of my coworkers. And that was nice.Corey: You've always had a focus through all the time that I've known you and all the public content that you've put out there that has come across my desk that seems to center around security. It's sort of an area that I give a nod to more often than I would like, on some level, but that tends to be your bread and butter. Your focus seems to be almost overwhelmingly on I would call it AWS security. Is that fair to say or is that a mischaracterization of how you view it slash what you actually do? Because, again, we have these parasocial relationships with voices on the internet. And it's like, “Oh, yeah, I know all about that person.” Yeah, you've met them once and all you know other than that is what they put on Twitter.Chris: You follow me on Twitter. Yeah, I would argue that yes, a lot of what I do is AWS-related security because in the past, a lot of what I've been responsible for is cloud security in AWS. But I've always worked for companies that were multi-cloud; it's just that 90% of everything was Amazon and so therefore 90% of my time, 90% of my problems, 90% of my risk was all in AWS. I've been trying to break out of that. I've been trying to understand the other clouds.One of the nice aspects of this role and working on Steampipe is I am now experimenting with other clouds. The whole goal here is to be able to scale our ability as an industry and as security practitioners to support multiple clouds. Because whether we want to or not, we've got it. And so, even though 90% of my spend, 90% of my resources, 90% of my applications may be in AWS, that 10% that I'm ignoring is probably more than 10% of my risk, and we really do need to understand and support major clouds equally.Corey: One post you had recently that I find myself in wholehearted agreement with is on the adoption of Tailscale in the enterprise. I use it for all of my personal nonsense and it is transformative. I like the idea of what that portends for a multi-cloud, or poly-cloud, or whatever the hell we're calling it this week, sort of architectures were historically one of the biggest problems in getting to clouds two speak to one another and manage them in an intelligent way is the security models are different, the user identity stuff is different as well, and the network stuff has always been nightmarish. Well, with Tailscale, you don't have to worry about that in the same way at all. You can, more or less, ignore it, turn on host-based firewalls for everything and just allow Tailscale. And suddenly, okay, I don't really have to think about this in the same way.Chris: Yeah. And you get the micro-segmentation out of it, too, which is really nice. I will agree that I had not looked at Tailscale until I was asked to look at Tailscale, and then it was just like, “Oh, I am completely redoing my home network on that.” But looking at it, it's going to scare some old-school network engineers, it's going to impact their livelihoods and that is going to make them very defensive. And so, what I wanted to do in that post was kind of address, as a practitioner, if I was looking at this with an enterprise lens, what are the concerns you would have on deploying Tailscale in your environment?A lot of those were, you know, around user management. I think the big one that is—it's a new thing in enterprise security, but kind of this host profiling, which is hey, before I let your laptop on the network, I'm going to go make sure that you have antivirus and some kind of EDR, XDR, blah-DR agents so that you know we have a reasonable thing that you're not going to just go and drop [unintelligible 00:09:01] on the network and next thing you know, we're Maersk. Tailscale, that's going to be their biggest thing that they are going to have to figure out is how do they work with some of these enterprise concerns and things along those lines. But I think it's an excellent technology, it was super easy to set up. And the ability to fine-tune and microsegment is great.Corey: Wildly so. They occasionally sponsor my nonsense. I have no earthly idea whether this episode is one of them because we have an editorial firewall—they're not paying me to set any of this stuff, like, “And this is brought to you by whatever.” Yeah, that's the sponsored ad part. This is just, I'm in love with the product.One of the most annoying things about it to me is that I haven't found a reason to give them money yet because the free tier for my personal stuff is very comfortably sized and I don't have a traditional enterprise network or anything like that people would benefit from over here. For one area in cloud security that I think I have potentially been misunderstood around, so I want to take at least this opportunity to clear the air on it a little bit has been that, by all accounts, I've spent the last, mmm, few months or so just absolutely beating the crap out of Azure. Before I wind up adding a little nuance and context to that, I'd love to get your take on what, by all accounts, has been a pretty disastrous year-and-a-half for Azure security.Chris: I think it's been a disastrous year-and-a-half for Azure security. Um—[laugh].Corey: [laugh]. That was something of a leading question, wasn't it?Chris: Yeah, no, I mean, it is. And if you think, though, back, Microsoft's repeatedly had these the ebb and flow of security disasters. You know, Code Red back in whatever the 2000s, NT 4.0 patching back in the '90s. So, I think we're just hitting one of those peaks again, or hopefully, we're hitting the peak and not [laugh] just starting the uptick. A lot of what Azure has built is stuff that they already had, commercial off-the-shelf software, they wrapped multi-tenancy around it, gave it a new SKU under the Azure name, and called is cloud. So, am I super-surprised that somebody figured out how to leverage a Jupyter notebook to find the back-end credentials to drop the firewall tables to go find the next guy over's Cosmos DB? No, I'm not.Corey: I find their failures to be less egregious on a technical basis because let's face it, let's be very clear here, this stuff is hard. I am not pretending for even a slight second that I'm a better security engineer than the very capable, very competent people who work there. This stuff is incredibly hard. And I'm not—Chris: And very well-funded people.Corey: Oh, absolutely, yeah. They make more than I do, presumably. But it's one of those areas where I'm not sitting here trying to dunk on them, their work, their efforts, et cetera, and I don't do a good enough job of clarifying that. My problem is the complete radio silence coming out of Microsoft on this. If AWS had a series of issues like this, I'm hard-pressed to imagine a scenario where they would not have much more transparent communications, they might very well trot out a number of their execs to go on a tour to wind up talking about these things and what they're doing systemically to change it.Because six of these in, it's like, okay, this is now a cultural problem. It's not one rando engineer wandering around the company screwing things up on a rotational basis. It's, what are you going to do? It's unlikely that firing Steven is going to be your fix for these things. So, that is part of it.And then most recently, they wound up having a blog post on the MSRC, the Microsoft Security Resource Center is I believe that acronym? The [mrsth], whatever; and it sounds like a virus you pick up in a hospital—but the problem that I have with it is that they spent most of that being overly defensive and dunking on SOCRadar, the vulnerability researcher who found this and reported it to them. And they had all kinds of quibbles with how it was done, what they did with it, et cetera, et cetera. It's, “Excuse me, you're the ones that left customer data sitting out there in the Azure equivalent of an S3 bucket and you're calling other people out for basically doing your job for you? Excuse me?”Chris: But it wasn't sensitive customer data. It was only the contract information, so therefore it was okay.Corey: Yeah, if I put my contract information out there and try and claim it's not sensitive information, my clients will laugh and laugh as they sue me into the Stone Age.Chris: Yeah well, clearly, you don't have the same level of clickthrough terms that Microsoft is able to negotiate because, you know, [laugh].Corey: It's awful as well, it doesn't even work because, “Oh, it's okay, I lost some of your data, but that's okay because it wasn't particularly sensitive.” Isn't that kind of up to you?Chris: Yes. And if A, I'm actually, you know, a big AWS shop and then I'm looking at Azure and I've got my negotiations in there and Amazon gets wind that I'm negotiating with Azure, that's not going to do well for me and my business. So no, this kind of material is incredibly sensitive. And that was an incredibly tone-deaf response on their part. But you know, to some extent, it was more of a response than we've seen from some of the other Azure multi-tenancy breakdowns.Corey: Yeah, at least they actually said something. I mean, there is that. It's just—it's wild to me. And again, I say this as an Azure customer myself. Their computer vision API is basically just this side of magic, as best I can tell, and none of the other providers have anything like it.That's what I want. But, you know, it almost feels like that service is under NDA because no one talks about it when they're using this service. I did a whole blog post singing its praises and no one from that team reached out to me to say, “Hey, glad you liked it.” Not that they owe me anything, but at the same time it's incredible. Why am I getting shut out? It's like, does this company just have an entire policy of not saying anything ever to anyone at any time? It seems it.Chris: So, a long time ago, I came to this realization that even if you just look at the terminology of the three providers, Amazon has accounts. Why does Amazon have Amazon—or AWS accounts? Because they're a retail company and that's what you signed up with to buy your underwear. Google has projects because they were, I guess, a developer-first thing and that was how they thought about it is, “Oh, you're going to go build something. Here's your project.”What does Microsoft have? Microsoft Azure Subscriptions. Because they are still about the corporate enterprise IT model of it's really about how much we're charging you, not really about what you're getting. So, given that you're not a big enterprise IT customer, you don't—I presume—do lots and lots of golfing at expensive golf resorts, you're probably not fitting their demographic.Corey: You're absolutely not. And that's wild to me. And yet, here we are.Chris: Now, what's scary is they are doing so many interesting things with artificial intelligence… that if… their multi-tenancy boundaries are as bad as we're starting to see, then what else is out there? And more and more, we is carbon-based life forms are relying on Microsoft and other cloud providers to build AI, that's kind of a scary thing. Go watch Satya's keynote at Microsoft Ignite and he's showing you all sorts of ways that AI is going to start replacing the gig economy. You know, it's not just Tesla and self-driving cars at this point. Dali is going to replace the independent graphics designer.They've got things coming out in their office suite that are going to replace the mom-and-pop marketing shops that are generating menus and doing marketing plans for your local restaurants or whatever. There's a whole slew of things where they're really trying to replace people.Corey: That is a wild thing to me. And part of the problem I have in covering AWS is that I have to differentiate in a bunch of different ways between AWS and its Amazon corporate parent. And they have that problem, too, internally. Part of the challenge they have, in many cases, is that perks you give to employees have to scale to one-and-a-half million people, many of them in fulfillment center warehouse things. And that is a different type of problem that a company, like for example, Google, where most of their employees tend to be in office job-style environments.That's a weird thing and I don't know how to even start conceptualizing things operating at that scale. Everything that they do is definitionally a very hard problem when you have to make it scale to that point. What all of the hyperscale cloud providers do is, from where I sit, complete freaking magic. The fact that it works as well as it does is nothing short of a modern-day miracle.Chris: Yeah, and it is more than just throwing hardware at the problem, which was my on-prem solution to most of the things. “Oh, hey. We need higher availability? Okay, we're going to buy two of everything.” We called it the Noah's Ark model, and we have an A side and a B side.And, “Oh, you know what? Just in case we're going to buy some extra capacity and put it in a different city so that, you know, we can just fail from our primary city to our secondary city.” That doesn't work at the cloud provider scale. And really, we haven't seen a major cloud outage—I mean, like, a bad one—in quite a while.Corey: This episode is sponsored in part by Honeycomb. When production is running slow, it's hard to know where problems originate. Is it your application code, users, or the underlying systems? I've got five bucks on DNS, personally. Why scroll through endless dashboards while dealing with alert floods, going from tool to tool to tool that you employ, guessing at which puzzle pieces matter? Context switching and tool sprawl are slowly killing both your team and your business. You should care more about one of those than the other; which one is up to you. Drop the separate pillars and enter a world of getting one unified understanding of the one thing driving your business: production. With Honeycomb, you guess less and know more. Try it for free at honeycomb.io/screaminginthecloud. Observability: it's more than just hipster monitoring.Corey: The outages are always fascinating, just from the way that they are reported in the mainstream media. And again, this is hard, I get it. I am not here to crap on journalists. They, for some ungodly, unknowable reason, have decided not to spend their entire career focusing on the nuances of one very specific, very deep industry. I don't know why.But as [laugh] a result, they wind up getting a lot of their baseline facts wrong about these things. And that's fair. I'm not here to necessarily act as an Amazon spokesperson when these things happen. They have an awful lot of very well-paid people who can do that. But it is interesting just watching the blowback and the reaction of whatever there's an outage, the conversation is never “Does Amazon or Azure or Google suck?” It's, “Does cloud suck as a whole?”That's part of the reason I care so much about Azure getting their act together. If it were just torpedoing Microsoft's reputation, then well, that's sad, but okay. But it extends far beyond that to a point where it's almost where the enterprise groundhog sees the shadow of a data breach and then we get six more years of data center build-outs instead of moving things to a cloud. I spent too many years working in data centers and I have the scars from the cage nuts and crimping patch cables frantically in the middle of the night to prove it. I am thrilled at the fact that I don't believe I will ever again have to frantically drive across town in the middle of the night to replace a hard drive before the rest of the array degrades. Cloud has solved those problems beautifully. I don't want to go back to the Dark Ages.Chris: Yeah, and I think that there's a general potential that we could start seeing this big push towards going back on-prem for effectively sovereign data reasons, whether it's this country has said, “You cannot store your data about our citizens outside of our borders,” and either they're doing that because they do not trust the US Silicon Valley privacy or whatever, or because if it's outside of our borders, then our secret police agents can come knocking on the door at two in the morning to go find out what some dissidents' viewings habits might have been, I see sovereign cloud as this thing that may be a back step from this ubiquitous thing that we have right now in Amazon, Azure, and Google. And so, as we start getting to the point in the history books where we start seeing maps with lots of flags, I think we're going to start seeing a bifurcation of cloud as just a whole thing. We see it already right now. The AWS China partition is not owned by Amazon, it is not run by Amazon, it is not controlled by Amazon. It is controlled by the communist government of China. And nobody is doing business in Russia right now, but if they had not done what they had done earlier this year, we might very well see somebody spinning up a cloud provider that is completely controlled by and in the Russian government.Corey: Well, yes or no, but I want to challenge that assessment for a second because I've had conversations with a number of folks about this where people say, “Okay, great. Like, is the alt-right, for example, going to have better options now that there might be a cloud provider spinning up there?” Or, “Well, okay, what about a new cloud provider to challenge the dominance of the big three?” And there are all these edge cases, either geopolitically or politically based upo—or folks wanting to wind up approaching it from a particular angle, but if we were hired to build out an MVP of a hyperscale cloud provider, like, the budget for that MVP would look like one 100 billion at this point to get started and just get up to a point of critical mass before you could actually see if this thing has legs. And we'd probably burn through almost all of that before doing a single dime in revenue.Chris: Right. And then you're doing that in small markets. Outside of the China partition, these are not massively large markets. I think Oracle is going down an interesting path with its idea of Dedicated Cloud and Oracle Alloy [unintelligible 00:22:52].Corey: I like a lot of what Oracle's doing, and if younger me heard me say that, I don't know how hard I'd hit myself, but here we are. Their free tier for Oracle Cloud is amazing, their data transfer prices are great, and their entire approach of, “We'll build an entire feature complete region in your facility and charge you what, from what I can tell, is a very reasonable amount of money,” works. And it is feature complete, not, “Well, here are the three services that we're going to put in here and everything else is well… it's just sort of a toehold there so you can start migrating it into our big cloud.” No. They're doing it right from that perspective.The biggest problem they've got is the word Oracle at the front end and their, I would say borderline addiction to big-E enterprise markets. I think the future of cloud looks a lot more like cloud-native companies being founded because those big enterprises are starting to describe themselves in similar terminology. And as we've seen in the developer ecosystem, as go startups, so do big companies a few years later. Walk around any big company that's undergoing a digital transformation, you'll see a lot more Macs on desktops, for example. You'll see CI/CD processes in place as opposed to, “Well, oh, you want something new, it's going to be eight weeks to get a server rack downstairs and accounting is going to have 18 pages of forms for you to fill out.” No, it's “click the button,” or—Chris: Don't forget the six months of just getting the financial CapEx approvals.Corey: Exactly.Chris: You have to go through the finance thing before you even get to start talking to techies about when you get your server. I think Oracle is in an interesting place though because it is embracing the fact that it is number four, and so therefore, it's like we are going to work with AWS, we are going to work with Azure, our database can run in AWS or it can run in our cloud, we can interconnect directly, natively, seamlessly with Azure. If I were building a consumer-based thing and I was moving into one of these markets where one of these governments was demanding something like a sovereign cloud, Oracle is a great place to go and throw—okay, all of our front-end consumer whatever is all going to sit in AWS because that's what we do for all other countries. For this one country, we're just going to go and build this thing in Oracle and we're going to leverage Oracle Alloy or whatever, and now suddenly, okay, their data is in their country and it's subject to their laws but I don't have to re-architect to go into one of these, you know, little countries with tin horn dictators.Corey: It's the way to do multi-cloud right, from my perspective. I'll use a component service in a different cloud, I'm under no illusions, though, in doing that I'm increasing my resiliency. I'm not removing single points of failure; I'm adding them. And I make that trade-off on a case-by-case basis, knowingly. But there is a case for some workloads—probably not yours if you're listening to this; assume not, but when you have more context, maybe so—where, okay, we need to be across multiple providers for a variety of strategic or contextual reasons for this workload.That does not mean everything you build needs to be able to do that. It means you're going to make trade-offs for that workload, and understanding the boundaries of where that starts and where that stops is going to be important. That is not the worst idea in the world for a given appropriate workload, that you can optimize stuff into a container and then can run, more or less, anywhere that can take a container. But that is also not the majority of most people's workloads.Chris: Yeah. And I think what that comes back to from the security practitioner standpoint is you have to support not just your primary cloud, your favorite cloud, the one you know, you have to support any cloud. And whether that's, you know, hey, congratulations. Your developers want to use Tailscale because it bypasses a ton of complexity in getting these remote island VPCs from this recent acquisition integrated into your network or because you're going into a new market and you have to support Oracle Cloud in Saudi Arabia, then you as a practitioner have to kind of support any cloud.And so, one of the reasons that I've joined and I'm working on, and so excited about Steampipe is it kind of does give you that. It is a uniform interface to not just AWS, Azure, and Google, but all sorts of clouds, whether it's GitHub or Oracle, or Tailscale. So, that's kind of the message I have for security practitioners at this point is, I tried, I fought, I screamed and yelled and ranted on Twitter, against, you know, doing multi-cloud, but at the end of the day, we were still multi-cloud.Corey: When I see these things evolving, is that, yeah, as a practitioner, we're increasingly having to work across multiple providers, but not to a stupendous depth that's the intimidating thing that scares the hell out of people. I still remember my first time with the AWS console, being so overwhelmed with a number of services, and there were 12. Now, there are hundreds, and I still feel that same sense of being overwhelmed, but I also have the context now to realize that over half of all customer spend globally is on EC2. That's one service. Yes, you need, like, five more to get it to work, but okay.And once you go through learning that to get started, and there's a lot of moving parts around it, like, “Oh, God, I have to do this for every service?” No, take Route 53—my favorite database, but most people use it as a DNS service—you can go start to finish on basically everything that service does that a human being is going to use in less than four hours, and then you're more or less ready to go. Everything is not the hairy beast that is EC2. And most of those services are not for you, whoever you are, whatever you do, most AWS services are not for you. Full stop.Chris: Yes and no. I mean, as a security practitioner, you need to know what your developers are doing, and I've worked in large organizations with lots of things and I would joke that, oh, yeah, I'm sure we're using every service but the IoT, and then I go and I look at our bill, and I was like, “Oh, why are we dropping that much on IoT?” Oh, because they wanted to use the Managed MQTT service.Corey: Ah, I start with the bill because the bill is the source of truth.Chris: Yes, they wanted to use the Managed MQTT service. Okay, great. So, we're now in IoT. But how many of those things have resource policies, how many of those things can be made public, and how many of those things are your CSPM actually checking for and telling you that, hey, a developer has gone out somewhere and made this SageMaker notebook public, or this MQTT topic public. And so, that's where you know, you need to have that level of depth and then you've got to have that level of depth in each cloud. To some extent, if the cloud is just the core basic VMs, object storage, maybe some networking, and a managed relational database, super simple to understand what all you need to do to build a baseline to secure that. As soon as you start adding in on all of the fancy services that AWS has. I re—Corey: Yeah, migrating your Step Functions workflow to other cloud is going to be a living goddamn nightmare. Migrating something that you stuffed into a container and run on EC2 or Fargate is probably going to be a lot simpler. But there are always nuances.Chris: Yep. But the security profile of a Step Function is significantly different. So, you know, there's not much you can do there wrong, yet.Corey: You say that now, but wait for their next security breach, and then we start calling them Stumble Functions instead.Chris: Yeah. I say that. And the next thing, you know, we're going to have something like Lambda [unintelligible 00:30:31] show up and I'm just going to be able to put my Step Function on the internet unauthenticated. Because, you know, that's what Amazon does: they innovate, but they don't necessarily warn security practitioners ahead of their innovation that, hey, you're we're about to release this thing. You might want to prepare for it and adjust your baselines, or talk to your developers, or here's a service control policy that you can drop in place to, you know, like, suppress it for a little bit. No, it's like, “Hey, these things are there,” and by the time you see the tweets or read the documentation, you've got some developer who's put it in production somewhere. And then it becomes a lot more difficult for you as a security practitioner to put the brakes on it.Corey: I really want to thank you for spending so much time talking to me. If people want to learn more and follow your exploits—as they should—where can they find you?Chris: They can find me at steampipe.io/blog. That is where all of my latest rants, raves, research, and how-tos show up.Corey: And we will, of course, put a link to that in the [show notes 00:31:37]. Thank you so much for being so generous with your time. I appreciate it.Chris: Perfect, thank you. You have a good one.Corey: Chris Farris, cloud security nerd at Turbot. I'm Cloud Economist Corey Quinn and this is Screaming in the Cloud. If you've enjoyed this podcast, please leave a five-star review on your podcast platform of choice, whereas if you've hated this podcast, please leave a five-star review on your podcast platform of choice along with an angry insulting comment, and be sure to mention exactly which Azure communications team you work on.Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.Announcer: This has been a HumblePod production. Stay humble.
In this first episode of 2023, the trio sift through the news, covering Outlook roaming signatures, the challenges facing Tableau, news from Azure Synapse and Power BI, changes to CosmosDB naming and what's new in Windows Autopatch.They also dive into a discussion about representing or not on social media. Hosted on Acast. See acast.com/privacy for more information.
In this first episode of 2023, the trio sift through the news, covering Outlook roaming signatures, the challenges facing Tableau, news from Azure Synapse and Power BI, changes to CosmosDB naming and what's new in Windows Autopatch.They also dive into a discussion about representing or not on social media. Hosted on Acast. See acast.com/privacy for more information.
The punycode parsing in OpenSSL, missing authentication in Azure Cosmos DB Notebooks, the importance of documentation in security, labeling IoT security, bad response to a security disclosure Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw219
The punycode parsing in OpenSSL, missing authentication in Azure Cosmos DB Notebooks, the importance of documentation in security, labeling IoT security, bad response to a security disclosure Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw219
In this episode Warner and Luan cover the biggest announcements from the Microsoft Ignite Fall 2022 conference. These include new features for Cosmos Db, PostgreSQL, MySQL, Azure Purview, Synapse Analytics and more!
Build highly scalable applications using the distributed Postgres relational database in Azure Cosmos DB for PostgreSQL. See how it works with current Postgres tools, how to scale out with distributed tables and nodes to keep apps responsive, and how to eliminate latency with geo-replication capabilities for globally distributed apps. Cosmos DB has a variety of APIs, including native NoSQL and compatible APIs, targeted at NoSQL workloads. With the introduction of Postgres, Cosmos DB offers relational capabilities— a key cornerstone for application developers. With distributed Postgres in Cosmos DB, you can build highly scalable, cloud native apps using NoSQL and relational capabilities within a single managed service. Principal Group Program Manager, Charles Feddersen, from the Cosmos DB team joins Jeremy Chapman to walk you through the process. Join the Azure Cosmos DB team for all our announcements from Ignite 2022. Visit https://aka.ms/azurecosmosdbliftoff ► QUICK LINKS: 00:00 - Introduction 00:51 - Relational capabilities and scalability 01:46 - See it in action 02:48 - Connect code to cluster 05:20 - Scaling your application 07:49 - SaaS application example 11:05 - Geo-replication 13:21 - Wrap up ► Link References: Get started at https://aka.ms/trycosmosdb ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries?sub_confirmation=1 • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/website • To get the newest tech for IT in your inbox, subscribe to our newsletter: https://www.getrevue.co/profile/msftmechanics ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Michael sits down with Michael Melone to discuss hunting for adversaries using Microsoft 365 Defender's Advanced hunting capabilities.Azure security news this week includes Azure Advisor for MySQL, using custom CAs with AKS, App Gateway Private Link, continuous backup in Cosmos DB, and API Management CSP and CORS support.
In this episode Warner and Luan recap the Microsoft Build 2022 conference including announcements related to SQL Server 2022, Synapse Analytics, Azure Purview, Cosmos Db, new container offerings and more!
In this episode we speak to Thomas Weiss from the Azure Data team about new security capabilities in CosmosDB, specifically Always Encrypted and data-plane RBAC. We also have security news about Confidential Compute, Azure Data Explorer, Load Balancer, DNS Reservations, ZLoader malware, Azure Monitor, MSTICPy and NIST SP 800-40.
Il cloud è come un iceberg: ciò che emerge è maestoso e affascinante ma, per poter esistere, ben di più è nascosto "sotto". Una puntata "sotto il cofano" del cloud, per comprendere ancora meglio l'unicità della value proposition, migliorare la nostra comprensione architetturale e, perchè no, scoprire qualche curiosità.Video citati nell'episodio:* Playlist "Cavi Sottomarini" di Geopop: https://www.youtube.com/playlist?list=PL8AiOx5ykoRPCLHt2BpcetJOxLHcjKPX_* "Building the world's computer with Microsoft Datacenters": https://www.youtube.com/watch?v=9nLD7bc5O1gI nostri contatti:* Canale Telegram: https://t.me/CloudChampions* Facebook: https://www.facebook.com/TheCloudChamps* LinkedIn: https://www.linkedin.com/showcase/cloudchampions * Sito web: https://www.cloudchampions.tech/* Twitter: https://twitter.com/TheCloudChamps
In this special episode, Mark chats about the MCRA as well as the Cloud Adoption Framework (CAF), and various related topics. We shied away from the news this week to focus on Mark's topic, but Michael couldn't resist talking about the fact that CosmosDB now supports Always Encrypted.
Hackers often make it look easy when in fact they started with no plan and were just following their curiosity, going down paths erratically just like a rabbit. Researchers Nir Ohfeld and Sagi Tzadik join The Hacker Mind to talk about their presentation at Black Hat Europe 2021 on the ChaosDB vulnerability. It's about how they started with a deliberately misconfigured version of CosmosDB and ended up with complete unrestricted access to the accounts and the databases of thousands of Microsoft Azure customers.
We chat with Al Eardley about Compliance, Security and Microsoft Compliance Manager, as well as news about CosmosDB, Azure Load Testing, CodeQL, Azure Active Directory, Zero Trust, Sentinel and new cyber blog from Microsoft.
Updates to the managed, limitless scale, NoSQL Azure Cosmos DB database. For your smaller apps, get the best cost performance with the new serverless option for on-demand querying and the Azure Cosmos DB free tier for provisioned throughput. For larger workloads, embed and partition your data, and leverage autoscale for cost optimizations. Estefani Arroyo, Azure Cosmos DB Program Manager, joins host Jeremy Chapman to share updates and benefits of Azure Cosmos DB. Run smaller apps for less than $1/month, pay only by operation Increase scalability and multi-region support with provisioned throughput Choose the best partition key- evenly spread operations and data across partitions Run applications efficiently with autoscale throughput ► QUICK LINKS: 00:00 - Introduction 00:44 - How is Azure Cosmos DB different? 02:32 - Scale out architecture 04:33 - Example of new serverless option 06:43 - Free tier and provisioned throughput 07:27 - Run NoSQL workloads at scale 09:58 - Partitioning with partition keys 12:04 - How to identify the cause of throttling 13:42 - Autoscale 15:20 - Wrap up ► Link References: Get started with Azure Cosmos DB free https://azure.microsoft.com/services/cosmos-db/ Access free Azure Cosmos DB training on Microsoft Learn at https://aka.ms/learncosmosdb Set up a free trial at https://aka.ms/trycosmosdb ► Unfamiliar with Microsoft Mechanics? We are Microsoft's official video series for IT. You can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries?sub_confirmation=1 Join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog ► Keep getting this insider knowledge, join us on social: Follow us on Twitter: https://twitter.com/MSFTMechanics Follow us on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
The biggest news this week (and will likely trump any sort of news for the next couple of weeks in the Microsoft space) is that Azure has a vulnerability dubbed “ChaosDB” that exposed its customers keys to the world, leaving every single CosmosDB customer's database data exposed for the taking. There's a technical deep-dive into this vulnerability as well. I hope the Azure team is wearing their brown pants.This is as bad as it gets. Good news though! They gave out a bounty of $40,000 to the finder of this vulnerability. Which values this vulnerability as akin to a Tesla Model 3 — and not even a fully decked out one.Apply rounded corners in desktop apps for Windows 11. In some cases, rounded corners will be applied to your applications automatically, in others, here's what you can do to make them rounded. As Apple intended.Razer Bug lets you become a Windows 10 admin by plugging in a mouse. This is a pretty easy exploit to… well.. exploit, so if you're using Razer mouses in a corporate context, you may want to rethink that decision.The real names of features in Visual Studio. It's a bit inside baseball, but still a wonderful walkthrough.David Fowler writes to tell us that New .NET 6 APIS [are] driven by the developer community. In this blog post, David details new APIs available in .NET 6, and highlights the fact that well, they were authored by members of the community. I'm a fan of Parallel.ForEachAsync, as that seems rather useful for my needs.This is your warning: Get out of the Dev Channel for Windows 11 unless you want to experience some turbelance. If you want stability, use the beta channel or get out of the insider program entirely. If you want to see new builds of Windows 11 that may have the stability of Windows Vista, stay in the Dev channel.Nicole Miller-Abuhakmeh is the new Community Manager for the .NET Foundation. This is a wonderful choice for CM, congrats Nicole and the .NET foundation.Looks like there's another tactic available to exploit Proxyshell vulnerabilities. A few weeks ago, a researcher showed off an exploit of Microsoft Exchange Server dubbed ‘ProxyShell' and it seems like the gift that keeps on giving to attackers. Bottom line: keep your Exchange servers up to date.In .NET 6, FirstOrDefault(), LastOrDefault() and SingleOrDefault() now let's you specify a default value. Sadly it has to be a compile-time constant so you can't have something like new Random().Next() available.Microsoft Ignite is November 2-4, 2021 and is virtual again this year because people can't bother to vaccinate.Github's Copilot can get you in trouble 40% of the time and if you're the type to use AI to write code, maybe you deserve to have problems.Using SignalR in your Blazor applications This is an nice pairing of technologies. Like Chardonnay and Brie, or Hotdog and Chili. Ketchup is forbidden, Mustard is recommended, however.And I say this with a twing of irony, but that's it for what happened Last Week in .NET.