There is a tsunami of bad heading our way Michael Hayden Four star general Director of the NSA Director of the CIA Director of National Intelligence.

Slides:



Advertisements
Similar presentations
Data centers Scalability Targets -Storage Account.
Advertisements

SIM212 Service Management in Clouds Self-Service -- Metered -- Elastic (Key Tenets) Multi-tenant -- Automation -- Scalable Datacenter Admin Service.
Develop your database with Visual Studio
Consumer / personal data Individual work data Team / group work data Personal devices Data location SkyDrive Public cloud SkyDrive Pro SharePoint.
Windows PowerShell Crash Course Don Jones Concentrated Technology Jeffrey Snover Microsoft WSV321.
Agenda Human Process + System Automation Better together Demos Identify self service opportunities Enable cloud through automation Key Takeaways.
Find an app in the Start Screen: just type on the screen.
Faith Allington Program Manager Microsoft Corporation WSV322.
Unified. Simplified. Unified Communications Launch 2007.
Turning PowerShell Commands into Reusable CLI and GUI Tools Don Jones Senior Partner and Principal Technologist Concentrated Technology, LLC WCL404.
4/9/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
What Is Azure ! Thierry Gasser Technical Solution Professional (TSP)
4/11/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Microsoft Dynamics AX Technical Conference 2013
What most companies get from ARIN In total, that range is only 3,566 blocks of /24!!!
4/11/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Computer CPU BUS Memory VM Back Channel Memory BUS Node 1 Node 2 VM.
Module 1: Demystifying Software Defined Networking Module 2: Realizing SDN - Microsoft’s Software Defined Networking Solutions with Windows Server 2012.
4/14/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Come Visit Us in the Microsoft Solutions Experience! Look for Datacenter and Infrastructure Management TechExpo Level 1 Hall.
Session Goal Be familiar with the possibilities of the operating system From the user mode and kernel mode We are NOT talking about the forensics!
Lower costs and improve predictability Automation Enable service owners to focus on work that adds business value Reduce error-prone manual activities.
6 Hypervisor Management OS Guest VM 1 Guest VM n Hardware User Mode Kernel Mode User Mode … Kernel Mode User Mode.
Server Roles and Features.NET Framework 3.51.NET Framework 4.5 IIS Web Server IIS Default Document IIS Directory Browsing IIS HTTP Errors.
Richard Seroter Director of Product Management Microsoft MVP for Integration Cloud Editor for InfoQ.com Technical Trainer at Pluralsight 3-time Book.
CMDB Ticketing Billing Management Systems Web based Runbook Authoring: Service Administrator can create runbooks to automate all aspects of cloud.
Hyper-V Recovery Service DR Orchestration Extensible Data Channel (Hyper-V Replica, SQL AlwaysOn)
Develo p Rapid reaction to feedback Operate Software to value delivery Monitor Fix No actionable feedback resulting in high MTTR Isolated operations.
Service Provider Next generation managed services Public Cloud (true multi- tenant) Private Cloud Hybrid Cloud Delivering the highest levels of user.
Overview of Microsoft DR solution for the three clouds Learn how to setup protection and recover to Microsoft Azure Planning guidance on choosing topologies.
4 2) Code Repository 1) Developers 3) Build4) Test5) Deploy to Cloud 6) Monitor and Improve Contoso App Azure.
Accelerate adoption, provide customer insights to engineering, and deliver knowledge to the IT Pro community.
On Premises Microsoft Azure Service Provider Business Continuity Tenant Services Service Administration Fabric Management Admin Portal Tenant.
Monitor Linux OS health & performance Monitor log files Monitor JEE app servers Monitor line-of-business applications Monitor databases and web.
Traditional Virtualized Private Cloud Public Cloud  Windows  Linux  UNIX  Windows  Linux  UNIX  Windows  Linux  Windows  Linux.
Looking Ahead…Embracing Our Past Building upon our successes for the future of operations.
Available in 2012 R2 UR2 & 2012 SP1 UR6.
Focus on “services” describing “what you deliver” Improve quality and consistency Continuous improvement in service delivery Prove it… and “show.
PowerShell Desired State Configuration for Securing Systems Jeffrey Snover Distinguished Engineer (MSFT) Hemant Mahawar Senior Program Manager (MSFT) #devconnections.
3 VIRTUAL MACHINES WEB SITES SERVICE BUS DATABASE.
Datacenters of the Past StorageNetworkCompute Today’s datacenter.
Scale Unit 1-Many SMA DB Monitor Workflow Executions New End User Request Monitor SharePoint Lists Monitor TFS for new scripts to deploy Check.
4/24/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Create Incident Create Checkpoint Start Maint Mode Shut Down VM on error Update on success Invoke Web Services Compare Values Send .
PowerShell Desired State Configuration for Securing Systems Jeffrey Snover Distinguished Engineer (MSFT) Hemant Mahawar Senior Program Manager (MSFT) #devconnections.
Deeper research never hurts! Memory dumps contain personal information, but… how personal?
Microsoft Virtual Academy Module 12 Managing Services with VMM and App Controller.
Develop – minimize your dependencies Package – know your dependencies Configure – use intent based configuration Deploy – use modular, componentized.
Let's build a VMM service template from A to Z in one hour Damien Caro Technical Evangelist Microsoft Central & Eastern Europe
WINDOWS AZURE AND THE HYBRID CLOUD. Hybrid Concepts and Cloud Services.
Managed Hybrid automatedusage based economics elastic always up. always on. PowerShell Automation Easy Scale-Out Easy Scale-Up.
Script Have done OS Deployment since 8” floppys. Build and connect Clouds Work as Consultant and Trainer You find.
Troubleshooting Tools
Review Windows Server 2016 The Cloud OS optimized for DevOps
PowerShell 2.0 Remoting Ravikanth C.
8/8/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Configuration Management with Azure Automation DSC
Download dumps - Microsoft Real Exam Questions Dumps4download
Configuring and Deploying Just Enough and Just-In-Time Administration
11/12/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
11/20/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Обзор Windows Azure Connect
11/30/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Managing Services with VMM and App Controller
System Admin Best Practices for NAV 2013 R2
2/24/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Service Template Creation from the Ground Up
Service Template Creation from the Ground Up
Day 2, Session 2 Connecting System Center to the Public Cloud
Microsoft Virtual Academy
Presentation transcript:

There is a tsunami of bad heading our way

Michael Hayden Four star general Director of the NSA Director of the CIA Director of National Intelligence

Edward Snowden Age 30 College dropout

You’re an Admin PWNED!!! Admins have the keys to the kingdom

PS> Enter-PSSession Server1 FAIL! – Talk to your supervisor for assistance “Jeffrey I need to be admin on Server1 to restart SQL” “No Eddie. Just use Jea and connect to the ‘Maintenance EndPoint” PS> Enter-JeaSession Server1 –Name Maintenance Server1> Restart-Service MSSQLSERVER Server1 Server1> Steal-Secrets Error: You are not authorized to Steal-Secrets

JeaEndpointAccounts puts the server in a blast container Avoid domain accounts and Group Managed Service Accounts [GMSA] because they extend any breach to all servers that these accounts have access to

Configuration FileServers { foreach ($node in Get-FileServers) { Node $node { JeaToolkit StorageTools {CommandSpecs Module Storage SMBShare } JeaEndpoint StorageAdmin {ToolKit = 'StorageTools‘ SecurityDescriptorSddl = 'O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;RM)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)' } FileServers -OutputPath. Start-DscConfiguration.\FileServers -ComputerName (Get-StorageServers)

JeaToolkit SQLMaintenace { Name = ‘SQLMaintenance’ CommandSpecs Module,Name,Parameter,ValidateSet,ValidatePattern SQL,GET-*,Get-Process,Get-Service,Stop-Process,Name,calc;notepad,Restart-Service,Name,,^SQL }

JeaToolkit SQLMaintenace { Name = "SQLMaintenace" CommandSpecs = cat.\SQL.csv -raw }

Server1 PowerShell Remoting connects to Configurations Name ACL StartupScript RunAsCredentials Get-Command *PSSessionConfiguration

$ss = $ExecutionContext.SessionState $ss.Scripts.Clear() $ss.Applications.clear() $s.Applications.add("C:\windows\system32\calc.exe") (Get-Command restart-computer).visibility=“private” Always hide Invoke-Expression New-Object

Get-Module $Module | % {$_.LogPipelineExecutionDetails = $true}

$user = $PSSenderInfo. ConnectedUser Send-MailMessage –Message “$user on machine $(hostname)” $today = [DateTime]::NOW.DayofWeek If ($today –in “Saturday”,”Sunday”) { throw “GO HOME”}

$myid = $ExecutionContext.host.Runspace.InstanceId Get-WinEvent -LogName Microsoft-Windows-PowerShell/Operational | where {$_.properties.Value -match "Runspace ID = $myid"} | foreach { New-Object PSObject Command = $_.Properties[2].Value Time = $_.TimeCreated } }

BlackHat 2010 Q: What do we do about all these attacks? A: “Man up and defend yourselves!”

Jea – Just Enough Admin PowerShell role-based administration to secure a post-Snowden world

Come Visit Us in the Microsoft Solutions Experience! Look for Datacenter and Infrastructure Management TechExpo Level 1 Hall CD For More Information Windows Server 2012 R2 Microsoft Azure System Center 2012 R2 Azure Pack cloud/products/windows-azure-pack