Inside Track staff, Author at Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/author/insidetrack/ How Microsoft does IT Tue, 07 Apr 2026 14:22:32 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 Understanding Microsoft’s digital transformation http://approjects.co.za/?big=insidetrack/blog/inside-the-transformation-of-it-and-operations-at-microsoft/ Sat, 20 Jul 2024 16:16:41 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=8822 Our Microsoft Digital Employee Experience (MDEE) team builds and operates the systems that run Microsoft, and as such, we’re leading the company’s internal digital transformation. We’re doing this by rethinking traditional IT and business operations, and by driving innovation and productivity for our 220,000-plus employees worldwide. Fueling Microsoft’s digital transformation is improving our ability to […]

The post Understanding Microsoft’s digital transformation appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesOur Microsoft Digital Employee Experience (MDEE) team builds and operates the systems that run Microsoft, and as such, we’re leading the company’s internal digital transformation. We’re doing this by rethinking traditional IT and business operations, and by driving innovation and productivity for our 220,000-plus employees worldwide. Fueling Microsoft’s digital transformation is improving our ability to empower our employees, engage our customers and partners, optimize our operations, and transform our products.

The need for digital transformation

The need for our digital transformation is evident—the global pandemic has created challenges for every organization, from employee placement to supply chain management, to continued retail operations. The investments that Microsoft has made in digital transformation have helped us respond quickly and efficiently to the frequent changes brought by the COVID-19 pandemic.

Our continued digital transformation will enable Microsoft to further its mission of empowering every person and every organization of the planet to achieve more, and it starts right here at home, with MDEE. Every new challenge presents an opportunity to assess our role in the organization and how we can put Microsoft in an even better position to take on new challenges.

Disruptions have always been a catalyst for business transformation. To lead on the forefront, we’re becoming more agile, efficient, and innovative. This means changing our systems and processes to support and quickly adapt to new products, services, business models, regulations, and anything else that comes our way.

Leading with vision and world-class execution

Leading with vision is the primary driver of our digital transformation. MDEE powers the company, and we are critical to both internal and external customers. To lead with vision, we need a clearly articulated view of where we want to take things and what we need to get there. Aligning our work to a larger vision of what we want to accomplish pushes us past day-to-day fire drills and comfortable routines to deliver something truly great for Microsoft.  Each one of our groups has a clear, targeted vision grounded in what our customers need and what we need as an organization. However, articulating the vision is not enough. An inspired and productive vision must accurately reflect what we actually do.

Vision is the foundation for the major decisions we make, not a document that we write once a year and put on a shelf. Building a strong connection between vision and work can be clarified by telling a story. The vision should create a narrative that informs our day-to-day decisions at every level. Each choice, no matter how granular, should connect itself and contribute to the broader vision. In turn, the vision inspires these choices, supporting aspirations for the business and energizing our employees. Telling the story this way makes us think carefully about how a piece of work fits into the broader vision—or if it doesn’t. It also helps us define our work in a way that’s consumable by our various stakeholder audiences, which is critical if we want them to support and partner with us. If we tell the story well, our stakeholders should be able to tell the story of how our work supports them to others.

[Discover how we’re reinventing Microsoft’s Employee Experience for a Hybrid World. Learn more about Microsoft’s cloud-centric architecture transformation. Find out how we’re enabling a modern support experience at Microsoft.]

Making hard choices

Being vision-led means making difficult and specific choices about where we will focus our efforts, and which work we will need to postpone or simply not do. We ruthlessly prioritize, focusing on what to stop investing in as much as what to invest in next. We set a high bar for quality, delivery, cost, and compliance. Our approach includes observing important guidelines for how we implement our vision and how that informs our operations. This includes:

  • Connecting outcomes to the vision and clearly prioritizing.
  • Placing user experiences at the center of our designs.
  • Building capability and depth within role-specific disciplines.
  • Investing in core platforms and systems to drive engineering productivity.
  • Using data and insights to continually assess and prioritize our approach, ensuring that we achieve our most important goals and that they align with our vision.

With this mindset and these guidelines for execution, we empower our employees to think strategically. We want them to continually have this question in their minds: What experience do customers have when interacting with Microsoft, and how can we make it better?

Establishing priorities that support our vision

As part of our Microsoft Digital Product Vision, we established and articulated critical priorities that framed our areas of work. We based the priorities on pain points that existed within MDEE and on best-in-class experiences across other organizations that we studied. The priorities continue to define and guide our work, and they act as an organizational tool for measuring our transformation’s progress:

Cloud-centric architecture

Cloud-centric architecture is designed to deliver a consistently high level of service reliability. Our systems in the cloud are agile, resilient, cost-effective, and scalable, so we can be proactive and innovative. Microsoft Azure is at the core of our architecture. We use Azure to automate our processes, unify our tools, and improve our engineering productivity. This includes transitioning to a DevOps model using the out-of-the-box capabilities that Azure DevOps and Azure Pipelines offer. The DevOps model enables faster deployment of new capabilities that are more secure and compliant. A modern cloud-centric architecture is foundational to our digital transformation, and we’re building integrated, reliable systems, instrumented for telemetry, to gather data and enable experimentation. Our investments include:

  • Transitioning from on-premises to cloud offerings to enable dynamic elastic compute, geo-redundancy, unified data strategy (Azure Data Lake), and flexible software-defined infrastructures.
  • Moving to cloud-centered IT operations, with provisioning, patching, monitoring, and backups for our cloud and on-premises environments utilizing Azure-based offerings.
  • Enabling continued company growth and improvement in our platform services while staying flat on the running cost of our services.
  • Developing deeper and richer insights into our service reliability, via standardization of monitoring solutions through Azure Application Insights, and standardization of incident-management tooling and automatic alerting. At the same time, we’re increasingly modeling our critical business processes and helping ensure end-to-end integrity through the monitoring and alerting of complex processes spanning multiple systems.
  • Providing a powerful feedback loop to our product-group partners (such as those for Azure, Microsoft Dynamics 365, and Windows) to showcase Microsoft running on Microsoft. This results in an improved enterprise-customer experience, including running one of the largest SAP instances entirely on Azure and helping ensure that Azure is SAP-ready for our customers.

Secure enterprise

Security is a never-ending, holistic pursuit that requires the same level of innovation and improvement found in every facet of the tech industry. Cloud-based architecture and ubiquitous user access require an enterprise security strategy that embraces identity as the new perimeter and encompasses our entire digital footprint. Improved security, which we’re seamlessly integrating into all parts of our digital transformation, is a component of every product we develop. Our strategy aligns around six core security pillars: device health, identity management, information protection, data and telemetry, risk management, and security assurance. Some of the specific areas in which we’re investing include:

  • Using Zero Trust as a model to help protect our infrastructure through enforced device health, strong authentication, least-privileged access, and pervasive telemetry that verifies control effectiveness.
  • Eliminating passwords through strong multi-factor authentication.
  • Thwarting phishing attacks on our users by using Microsoft Office 365 safe filters and Safe links, phishing detection, and email-delivery prevention.
  • Making our Security Operations Center even more efficient and effective through automation and the orchestration of detection and response.

Data and intelligence

Data is the most critical asset that modern organizations possess. The exponential increases in data, sophisticated algorithms, and computational power are fueling modern organizations to make rapid advances in technology and business disruptions. Our data’s value is directly proportional to the number of people within our organization who can find it, understand it, know they can trust it, and then connect it in new and meaningful ways for the deepest insights. We’re turning disparate company data into cohesive insights and intelligent experiences, and we’re investing in core areas including:

  • Creating a modern data foundation by aggregating clean, connected, and authoritative data that is catalogued and easily discoverable in a common location and any team can understand how to use to create insights and intelligent experiences.
  • Developing AI and machine learning—not to replace human experts but augment and accelerate human decisions using trusted intelligent models built on the wealth of available data.
  • Using analytics services to understand user journeys, processes, behavior, and insights, which roll up to executive scorecards to measure our progress against strategic goals.

Customer centricity

Employees and customers belong at the center of our focus and need to feel that they’re doing business with “One Microsoft” across all products and channels. Our ability to digitally transform hinges on a strong foundation of customer data. Achieving a holistic understanding allows us to provide customers with relevant and tailored offers and highly customized customer service by responding to their needs proactively. The complete technology solutions in the offers give customers the best value and a consistent experience. To achieve a security-enhanced and 360-degree understanding of our customers, online identity tenants need to be linked with sales accounts, purchase accounts and agreements, billing accounts, and third-party organizational-reference data. Our investments include:

  • Developing customer health-analytics and recommendation engines, using a clean directory and historical customer actions and interactions, to better understand and predict our customers’ needs and how we can add value with our offerings.
  • Publishing a shared, authoritative, and clean directory of organizational data and providing the tools and processes to maintain its accuracy and completeness.
  • Augmenting the organizational data that Microsoft holds by identifying and managing the relationships for any organization, enabling a more holistic understanding of who the customer is and how we can better serve them.

Productive enterprise

Microsoft employees are at the heart of our mission to enable and support our customers and partners to achieve more. We empower our employees to be their most creative and productive in how they work and collaborate across physical and digital environments. We use Microsoft products and services underpinned with Microsoft 365, AI, and machine learning to deliver connected, accessible, interactive, and individualized experiences for our employees. Our specific investments include:

  • Supporting a broad selection of devices, providing a quick and easy setup, and ensuring the devices are always up to date. We provide secure and seamless access to work-related apps, sites, services, documents, and data.
  • Developing enterprise search and task-automation capabilities that use Microsoft Search and integrated digital assistants. We’re providing our employees with a coherent and reliable enterprise-search experience and delivering automated micro-task capability to further enhance productivity.
  • Enabling team productivity by using Microsoft Teams and Office 365 as the backbone, fostering increased engagement, and accelerating decision making across devices and locations.
  • Creating a modern workplace where our employees have integrated digital and physical experiences for finding meeting spaces, indoor wayfinding, transportation, parking, and other workplace services.
  • Providing a customizable web and mobile employee experience focused on what’s important to the individual, delivering personalized access to workplace services, and making it easier to quickly complete common tasks.

Turning vision into a practical reality

Our priorities describe what we do, but how we’ll do it is just as important. We’ve made significant changes to the way we work to enable transformation. These changes allow us to take more ownership of our work, run more efficiently and effectively, and build in a way that’s durable over time. With a model for transformation, we can move away from decisions and directions based on team budget availability and move toward the delivery of clear and prioritized business outcomes. We measure our collective success by directly applying this model to our business and not by pure delivery of features. We prioritize as an organization based on where our vision directs us rather than at the local budget level. The practical goal of our vision-led product mindset is to discover the most effective and efficient solutions that will have the greatest impact on the transformational focus areas that make our vision a reality.

[Learn how we’re creating the digital workplace at Microsoft. Discover how we’re transforming modern engineering here at Microsoft. Check out how we’re redefining the digitally assisted workday at Microsoft. Learn how we’re transforming enterprise collaboration at Microsoft.]

MDEE digital-transformation methodology
Microsoft’s digital transformation methodology.

Transformed operating model

With an operating model for transformation, we can move away from decisions and directions based on team budgets and move toward the delivery of clear and prioritized business outcomes. Through this model, we’re empowering our business groups and employees by giving them autonomy and decision-making capabilities. Each business group maintains its own vision and has the freedom to prioritize its work based on that vision. However, this work still needs to align with the overarching MDEE vision and is assessed twice a year during a central review. This ensures that work is correctly prioritized and funded across the entire organization. Examples of our transformed operating model include:

  • Centralizing funding and prioritization: We’ve moved away from a decentralized, department-focused funding model and toward a centralized model where MDEE owns the budget. In the past, our business groups, such as Finance and Marketing, drove funding and projects. Now, we can use our priorities to fund work based on our vision.
  • Insourcing core systems and engineering: We’re managing the systems most critical to our organization’s success with trained, full-time employees. Historically, we outsourced much of this work. However, we’re bringing it back under the control of our employees and retaining intellectual property. We want our people behind the design, development, and operation of our most-important internal products.
  • Focusing metrics on business outcomes: Our metrics reflect the business outcomes to which we’re driving as opposed to traditional IT operating metrics. To transform successfully, alignment with our vision and contribution to the organization’s success take top priority. Therefore, how we measure success is based on business outcomes and not on arbitrary metrics.

Product-based approach to our business

To enable world-class execution of the services we build and run, we’re taking a product-based approach to our processes. We want to focus on developing solutions that contribute to our vision, and we want to use agile development methods and product-focused management in our development. Taking a product-based approach to our business means:

  • Creating a vision and business-driven agenda: We ensure that anything in which we invest resources aligns to our vision. We’re asking our internal teams to always have the best interest of Microsoft in mind. If it doesn’t align with our vision, it should be questioned—regardless of who’s doing the questioning. We want to produce the best products for our internal and external customers.
  • Focusing on skill development and a DevOps structure: A DevOps structure extends the management lifecycle for developers beyond version release. With the DevOps approach, the people on our team in MDEE who build solutions are responsible for the operation, fixes, troubleshooting and ownership over each line of code they write. A DevOps approach and agile methodology focus our employees on a solution’s success both during its development and after it’s in use. This leads to a more fluid evolution of product features and a focus on functionality rather than on feature addition.
  • Shifting to product management: We manage products rather than projects. Product management keeps our teams focused on the success of the product rather than the completion of a project. Our product managers are involved in the entire process, from managing relationships with stakeholders to understanding the technical foundations of their products. Product management builds on the DevOps structure to help ensure that teams who develop a solution feel invested in the ongoing success of that solution and not just on the release of the latest version.

Modern engineering and design practices across all processes

Modern engineering focuses on providing a common set of tools and automation that delivers code and new functionality to our employees by enabling continuous integration and delivery practices. We prioritize the most effective outcomes for the business, delivering against a ranked backlog. We add telemetry to monitor customer usage patterns, which provides insights on the health of our services and customer experiences. We want to remove functional silos in our organization and increase the ways in which our infrastructure, apps, and services connect and integrate. Behind all this, we have a unified set of standards that protect and enable our employees. We engineer for the future by:

  • Establishing a coherent design system: We’re creating a consistent, coherent, and seamless experience for our employees and customers across all our products and solutions. This means establishing priorities and standards for design and the user experience and creating an internal catalog of shared principles and guidelines to keep our entire organization in sync. Historically, we’ve developed in siloes, which led to varying user experiences and a cacophony of different tools. Now, we’re reviewing work in aggregate and scrutinizing experiences to drive user productivity.
  • Creating integrated and connected services: Our move to the cloud increases the overall agility of the development process and accelerates value delivery to the company. We’ve achieved this by re-envisioning our portfolio into a microservice architecture that promotes code reuse and enables cross-service dependencies through APIs. This further enables the delivery of a seamless and integrated experience that brings data and tools together, providing users with intuitive experiences and new insights.
  • Building privacy, security, and accessibility standards into our workflow: We integrate tools that support our engineers in building improved privacy, security, and accessibility into our solutions. Without these standards and automated policies, we’d have to rework and clean up as situations change. This is more costly and impacts our velocity of releases to users. Creating standards that we apply organization-wide, and from the beginning, creates an environment of trust in our engineering practices. Our innovations in this area ensure that our solutions also benefit our customers as these solutions are integrated into our commercial products.

Using a customer-zero feedback cycle

In MDEE, we have a unique opportunity to help our customers through their own transformations by sharing our best practices and lessons learned. As early adopters of Microsoft solutions, we provide feedback to our product-development teams and we co-develop solutions with them, which ultimately improves the products that we, and our customers, use to transform. Many of our product enhancements begin as internal solutions to business problems at Microsoft and then evolve within the feedback cycle, and then are incorporated into a final product. A key part of being customer zero is that we provide advice, guidance, and reference materials to customers based on our transformation blueprint and early adopter experience.

Key Takeaways
Almost every company in the world, including Microsoft, finds itself at a point unlike any other since the industrial revolution. The old IT model hinders the ability to remain relevant in an ever-changing marketplace, and companies must transform to maintain their competitive positioning. At Microsoft, we’ve rallied around transformation and are well underway. We’ve set ambitious goals, and we’re reshaping what we value and how we work. At our core, we’re vision-led and adopting the expectation for world-class execution. The combination of external and internal change presents a significant challenge but, more importantly, it offers a substantial opportunity for us to become more agile and respond more quickly. As a result, we’re in a better position to empower our employees, engage our customers and partners, optimize our operations, and transform our products.

Transformation does not have a finish line—it’s a journey. As we progress through our transformation, we’ll make mistakes and adjust our strategy accordingly, but we’ll also continue to move forward. We will share our transformation journey with our customers with the hope that our experiences can inspire, advise, and assist them through their own transformations.

Related links

We'd like to hear from you!

Share your feedback with us—take our survey and let us know what kind of content is most useful to you.

The post Understanding Microsoft’s digital transformation appeared first on Inside Track Blog.

]]>
8822
Digital transformation spotlight: Learning from deploying Microsoft Viva, data and AI across Microsoft http://approjects.co.za/?big=insidetrack/blog/digital-transformation-spotlight-learning-from-deploying-microsoft-viva-data-and-ai-across-microsoft/ Wed, 08 Feb 2023 22:30:24 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9578 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=sEI3kFWPvSQ. Microsoft’s internal IT leaders share […]

The post Digital transformation spotlight: Learning from deploying Microsoft Viva, data and AI across Microsoft appeared first on Inside Track Blog.

]]>
We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.
For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=sEI3kFWPvSQ.

Microsoft’s internal IT leaders share their learnings from deploying Microsoft Viva and talk about trends in data and AI across Microsoft.

Microsoft Digital video

Welcome to the first episode of “Spotlight on Digital Transformation,” a new video-based series that shines the spotlight on trends in digital transformation globally. In this episode, Inside Track leader Keith Boyd interviews Dan Scarbrough and Alan Stone, who lead Microsoft Digital’s Regional Experience teams. The discussion includes reflections on 2022, insights about Microsoft Viva, trends in data and AI, and predictions for 2023.

This new recurring series will feature some of our world-class experts in Microsoft Digital as they share ideas, insights, and trends that are impacting IT practitioners and the business of Information Technology globally.

Related links

The post Digital transformation spotlight: Learning from deploying Microsoft Viva, data and AI across Microsoft appeared first on Inside Track Blog.

]]>
9578
How Microsoft employees are leveraging the cloud for file storage with OneDrive Folder Backup http://approjects.co.za/?big=insidetrack/blog/how-microsoft-employees-are-leveraging-the-cloud-for-file-storage-with-onedrive-folder-backup/ Wed, 29 Jun 2022 16:00:45 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=8211 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Any device, no matter the operating system, is susceptible to a ransomware attack or a […]

The post How Microsoft employees are leveraging the cloud for file storage with OneDrive Folder Backup appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Any device, no matter the operating system, is susceptible to a ransomware attack or a device crash.

Microsoft OneDrive Folder Backup (known as Known Folder Move) is a policy deployed by Microsoft that automatically syncs the contents of a user’s critical folders—Documents, Desktop, and Pictures—to the cloud to protect it in the event of device crashes and ransomware attacks. Files are safe in the cloud, easy to share and collaborate on, and are accessible across different devices.

“The goal of this project was to empower every OneDrive user in Microsoft to protect their critical files and sync their “known” folders to the cloud—this gives them seamless access from any of their devices from anywhere without changing the way they work,” says Priya Chebiyam, a senior product manager who leads Microsoft’s internal use of OneDrive for the Microsoft Digital team—the organization that powers, protects, and transforms the company.

Putting data security first

Carini and Chebiyam smile for the camera in a photo taken in an office in a Microsoft building.
Priya Chebiyam (left) and Gaia Carini were instrumental in piloting, testing, and deploying OneDrive Folder Backup (Known Folder Move) across Microsoft. Chebiyam is a senior product manager for Microsoft Digital and Carini is a principal group product manager for the OneDrive product group.

The Known Folder Move project was piloted at the end of 2019, starting with a small group of employees.

A significant step in the pilot was to decide on the deployment approach—would it be silent or prompt-based? With a silent approach, the policy would be automatically initiated for users who would then be notified when their backup was complete. With a prompt-based system, users would be notified at the start of the process and choose whether to opt in or opt out.

While a silent approach is widespread across the industry, Microsoft opted at first to give employees a choice during the program pilot. As the team rolled out the pilot program, a surge in cyberattacks altered the plan.

“We found during the pilot program that opt-in security measures raise levels of vulnerability,” says Chebiyam. “Adoption of security measures was slow in the opt-in pilot. There was also an increased risk of low employee participation.”

“Pivoting to a silent deployment reduces risks,” continues Chebiyam. “So, faced with rising levels of cyberattacks, the choice was clear.”

The Microsoft team swiftly countered rising cyberattacks by switching to silent deployment and rewrote the Microsoft’s corporate security policy to require that all work documents and files reside in a corporate-approved storage system; OneDrive is that system.

With this shift in tactics, the team has been progressively rolling out a new plan that emphasizes security and disaster recovery across the company.

“Security is ingrained in the fabric of our culture,” says James Speller, a client deployment engineer on the project with Microsoft Digital. “The idea is to make data security as easy and non-disruptive as possible without compromising on safety.”

Learning from the results of the Known Folder Move pilot, the company took a different path at LinkedIn from the start, choosing the silent deployment approach.

It’s ideal to keep security measures as non-disruptive to employees as possible, and striking the right balance between security and efficiency has been at the top of our minds during this project.

—Priya Chebiyam, senior product manager

“At LinkedIn, doing it that way was right for their culture and the way they run their business,” Chebiyam says. “We focused on accelerating the adoption of security measures.”

Additionally, the cross-company Known Folder Move team relied heavily on employee feedback to create a better solution and user experience. They took their time to get this rollout right, as this policy affects employee productivity.

“We had to take a step back and consider how the rollout will affect productivity,” says Chebiyam. “It’s ideal to keep security measures as non-disruptive to employees as possible, and striking the right balance between security and efficiency has been at the top of our minds during this project.”

The team used Viva Engage (formerly known as Microsoft Yammer) and OneDrive in-app surveys to collect feedback that would be sent directly to the help desk. Feedback was communicated to the product team, continuously improving the product to provide a better user experience.

After enough feedback was gathered and implemented, the rollout came to the entire Microsoft user base—approximately 290,000 targeted employees and vendors. This user base was divided based on role and geography, and the team started rolling it out to about 5,000 users per batch.

Because files are automatically synced to OneDrive, users don’t have to worry about what happens to their computer, giving them peace of mind that their files are safe.

—Gaia Carini, principal group product manager

New employees and vendors are given this feature by default.

“The rapid growth of KFM-enabled OneDrives will significantly help the admins with any data investigation issues efficiently, with a quicker turnaround during critical emergencies. As a tenant admin, this KFM capability helps me to apply improved security controls on our Corp content residing in user OneDrives across the company,” says Abhishek Sharma, a senior service engineer with the team.

Change management

To get employees on board with using the cloud, messaging focused on the benefits of using OneDrive. These benefits include the amount of storage provided (all OneDrive accounts in Microsoft come with 5 TB of free cloud storage), the ability to access files if your computer is lost, broken, or in a refresh cycle, more secure sharing, easier access, improved collaboration, and real-time versioning.

“Because files are automatically synced to OneDrive, users don’t have to worry about what happens to their computer, giving them peace of mind that their files are safe” says Gaia Carini, a principal group product manager on the experience and devices team. “You don’t have to worry about where your data is or where your content lives.”

While Eva Etchells, a senior content publishing manager on the Microsoft Digital team, worked on messaging internally to employees, our OneDrive product marketing team shaped the narrative around OneDrive Folder Backup outside of Microsoft, communicating the benefits to external stakeholders.

The narrative formed around figuring out how to automatically backup all users’ content without disrupting the way they work. Like Etchells’s messaging, the OneDrive product team focused on device crashes, stolen PCs, ransomware attacks, and so on to drive change management and adoption of the product.

Out of sight, out of mind

With OneDrive Folder Backup, users don’t have to think about the safety and security of their documents or worry about it affecting their productivity. It’s invisible, seamless, and always in sync. Millions of files and hundreds of terabytes of data have been uploaded to OneDrive, and it continues to grow each month.

“OneDrive has provided a valuable benefit to me for a long time,” says Susan Sims, a fan of the service who works in Microsoft Digital as a team Senior Program Manager.

Sims managed global file services years ago that hosted shared content. According to Sims, there was an attack on those file servers nearly monthly, attacks that led to manual lockdowns to make sure the company didn’t lose business-critical content. Microsoft OneDrive Folder Backup has eliminated the risk and concern around losing content from device crashes as well as attacks.

“OneDrive is crucial for recovery from ransomware attacks,” says Vivek Vinod Sharma, a Senior Security Architect who served as the security point of contact for the project for the Microsoft Digital Security and Resilience team. “As a best practice for fast-tracking people to get back to a productive state if affected by an attack, we want more business data to reside in OneDrive.”

Moving forward, the team aims to enable OneDrive Folder Backup through silent deployment for all Windows users.

“OneDrive Folder Backup brings the power of the cloud to the desktop on Windows and macOS,” Carini says.It’s a critical part of the strategy and important for customers to enable in their organizations.”

Key Takeaways
  • Backing up files to the cloud is one of the most secure ways to store critical content to prevent file loss from ransomware attacks.
  • For faster and more effective change management across the organization, focus on the features and benefits employees will gain by adopting the policy to make them more likely to opt-in.
  • For a global rollout, communication is vital to ensure everything runs smoothly, especially when working across four or five different teams and geographies. Defining roles for each person and group is crucial.
  • When you begin moving your employees to OneDrive in the cloud, make sure their needs are at the center of everything you do. Get them as involved in the process as possible and act on as much of their feedback as you can to create a better user experience for everyone.
  • Acknowledge your organization’s policies and processes regarding security and compliance and use that as guidance when rolling out an approach to the entire user base.
  • Employees should be informed regarding what data is being collected and how that data is being used as part of the company security measures.
  • Consider the risks of workers not participating in security back-up options. Enforcing security uniformly as a company-wide policy minimizes potential damage to company assets from ransomware attacks.
Related links
We'd like to hear from you!

The post How Microsoft employees are leveraging the cloud for file storage with OneDrive Folder Backup appeared first on Inside Track Blog.

]]>
8211
Implementing Microsoft Azure cost optimization internally at Microsoft http://approjects.co.za/?big=insidetrack/blog/implementing-microsoft-azure-cost-optimization-internally-at-microsoft/ Tue, 07 Jun 2022 17:35:40 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9389 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Our Microsoft Digital team is aggressively pursuing Microsoft Azure cost optimization as part of our […]

The post Implementing Microsoft Azure cost optimization internally at Microsoft appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Our Microsoft Digital team is aggressively pursuing Microsoft Azure cost optimization as part of our continuing effort to improve the efficiency and effectiveness of our enterprise Azure environment here at Microsoft and for our customers.

Adopting data-driven cost-optimization techniques, investing in central governance, and driving modernization efforts throughout our Microsoft Azure environment, makes it so our environment—one of the largest enterprise environments hosted in Azure—is a cost efficient blueprint that all customers can look to for lessons on how to lower their Azure costs.

We began our digital transformation journey in 2014 with the bold decision to migrate our on-premises infrastructure to Microsoft Azure so we could capture the benefits of a cloud-based platform—agility, elasticity, and scalability. Since then, our teams have progressively migrated and transformed our IT footprint to the largest cloud-based infrastructure in the world—we host more than 95 percent of our IT resources in Microsoft Azure.

The Microsoft Azure platform has expanded over the years with the addition of hundreds of services, dozens of regions, and innumerable improvements and new features. In tandem, we’ve increased our investment in Azure as our core destination for business solutions at Microsoft. As our Azure footprint has grown, so has the environment’s complexity, requiring us to optimize and control our Azure expenditures.

Optimizing Microsoft Azure cost internally at Microsoft

Our Microsoft Azure footprint follows the resource usage of a typical large-scale enterprise. In the past few years, our cost-optimization efforts have been more targeted as we attempted to minimize the rising total cost of ownership in Azure due to several factors, including increased migrations from on-premises and business growth. This focus on optimization instigated an investment in tools and data insights for cost optimization in Azure.

The built-in tools and data that Microsoft Azure provides form the core of our cost-optimization toolset. We derive all our cost-optimization tools and insights from data in Microsoft Azure Advisor, Microsoft Azure Cost Management and Billing, and Microsoft Azure Monitor. We’ve also implemented design optimizations based on modern Azure resource offerings. We extract recommendations from Azure Advisor across the different Azure service categories and push those recommendations into our IT service management system, where the services’ owners can track and manage the implementation of recommendations for their services.

Understanding holistic optimization

As the first and largest adopter of Microsoft Azure, we’ve developed best practices for engineering and maintenance in Azure that support not only cost optimization but also a comprehensive approach to capturing the benefits of cloud computing in Azure. We developed and refined the Microsoft Well-Architected Framework as a set of guiding tenets for Azure workload modernization and a standard for modern engineering in Azure. Cost optimization is one of five components in the Well-Architected Framework that work together to support an efficient and effective Azure footprint. The other pillars include reliability, security, operational excellence, and performance efficiency. Cost optimization in Azure isn’t only about reducing spending. In Azure’s pay-for-what-you-use model, using only the resources we need when we need them, in the most efficient way possible, is the critical first step toward optimization.

Optimization through modernization

Reducing our dependency on legacy application architecture and technology was an important part of our first efforts in cost optimization. We migrated many of our workloads from on-premises to Microsoft Azure by using a lift-and-shift method: imaging servers or virtual machines exactly as they existed in the datacenter and migrating those images into virtual machines hosted in Azure. Moving forward, we’ve focused on transitioning those infrastructure as a service (IaaS) based workloads to platform as service (PaaS) components in Azure to modernize the infrastructure on which our solutions run.

Focus areas for optimization

We’ve maintained several focus areas for optimization. Ensuring the correct sizing for IaaS virtual machines was critical early in our Microsoft Azure adoption journey, when those machines accounted for a sizable portion of our Azure resources. We currently operate at a ratio of 80 percent PaaS to 20 percent IaaS, and to achieve this ratio we’ve migrated workloads from IaaS to PaaS wherever feasible. This means transitioning away from workloads hosted within virtual machines and moving toward more modular services such as Microsoft Azure App Service, Microsoft Azure Functions, Microsoft Azure Kubernetes Service, Microsoft Azure SQL, Microsoft Azure Cosmos database. PaaS services like these offer better native optimization capabilities in Microsoft Azure than virtual machines, such as automatic scaling and broader service integration. As the number of PaaS services has increased, automating scalability and elasticity across PaaS services has been a large part of our cost-optimization process. Data storage and distribution has been another primary focus area as we modify scaling, size, and data retention configuration for Microsoft Azure Storage, Azure SQL, Azure Cosmos DB, Microsoft Azure Data Lake, and other Azure storage-based services.

Implementing practical cost optimization

While Microsoft Azure Advisor provides most recommendations at the individual service level—Microsoft Azure Virtual Machines, for example—implementing these recommendations often takes place at the application or solution level. Application owners implement, manage, and monitor recommendations to ensure continued operation, account for dependencies, and keep the responsibility for business operations within the appropriate business group at Microsoft.

For example, we performed a lift-and-shift migration of our on-premises virtual lab services into Microsoft Azure. The resulting Azure environment used IaaS-based Azure virtual machines configured with nested virtualization. The initial scale was manageable using the nested virtualization model. However, the Azure-based solution was more convenient for hosting workloads than the on-premises solution, so adoption began to increase exponentially, which made management of the IaaS-based solution more difficult. To address these challenges, the engineering team responsible for the virtual lab environment re-architected the nested virtual machine design to incorporate a PaaS model using microservices and Azure-native capabilities. This design made the virtual lab environment more easily scalable, efficient, and resilient. The re-architecture addressed the functional challenges of the IaaS-based solution and reduced Azure costs for the virtual lab by more than 50 percent.

In another example, an application used Microsoft Azure Functions with the Premium App Service Plan tier to account for long-running functions that wouldn’t run properly without the extended execution time enabled by the Premium tier. The engineering team converted the logic in the Function Apps to use Durable Functions, an Azure Functions extension, and more efficient function-chaining patterns. This reduced execution time to less than 10 minutes, which allowed the team to switch the Function Apps to the Consumption tier, reducing cost by 82 percent.

Governance

To ensure effective identification and implementation of recommendations, governance in cost optimization is critical for our applications and the Microsoft Azure services that those applications use. Our governance model provides centralized control and coordination for all cost-optimization efforts. Our model consists of several important components, including:

  • Microsoft Azure Advisor recommendations and automation. Advisor cost management recommendations serve as the basis for our optimization efforts. We channel Advisor recommendations into our IT service management and Microsoft Azure DevOps environment to better track how we implement recommendations and ensure effective optimization.
  • Tailored cost insights. We’ve developed dashboards to identify the costliest applications and business groups and identify opportunities for optimization. The data that these dashboards provide help empower engineering leaders to observe and track important Azure cost components in their service hierarchy to ensure that optimization is effective.
  • Improved Microsoft Azure budget management. We perform our Azure budget planning by using a bottom-up approach that involves our finance and engineering teams. Open communication and transparency in planning are important, and we track forecasts for the year alongside actual spending to date to enable accurate adjustments to spending estimates and closely track our budget targets. Relevant and easily accessible spending data helps us identify trend-based anomalies to control unintentional spending that can happen when resources are scaled or allocated unnecessarily in complex environments.

Implementing a governance solution has enabled us to realize considerable savings by making a simple change to Microsoft Azure resources across our entire footprint. For example, we implemented a recommendation to convert Microsoft Azure SQL Database instances from the Standard database transaction unit (DTU) based tier to the General Purpose Serverless tier by using a simple Microsoft Azure Resource Manager template and the auto-pause capability. The configuration change reduced costs by 97 percent.

Benefits of Microsoft Azure

Ongoing optimization in Microsoft Azure has enabled us to capture the value of Azure to help increase revenue and grow our business. Our yearly budget for Azure has remained almost static since 2014, when we hosted most of our IT resources in on-premises datacenters. Over that period, Microsoft has grown by more than 20 percent,

Our recent optimization efforts have resulted in significantly reduced spending across numerous Microsoft Azure services. Examples, in addition to those already mentioned, include:

  • Right-sizing Microsoft Azure virtual machines. We generated more than 300 recommendations for VM size changes to increase cost efficiency. These recommendations included switching to burstable virtual machine sizes and accounted for a 15 percent cost savings.
  • Moving virtual machines to latest generation of virtual machine sizes. Moving from older D-series and E-series VM sizes to their current counterparts generated more almost 2,500 recommendations and a cost savings of approximately 30 percent.
  • Implementing Microsoft Azure Data Explorer recommendations. More than 200 recommendations were made for Microsoft Azure Data Explorer optimization, resulting in significant savings.
  • Incorporating Cosmos DB recommendations. More than 170 Cosmos DB recommendations reduced cost by 11 percent.
  • Implementing Microsoft Azure Data Lake recommendations. More than 30 Azure Data Lake recommendations combined to reduce costs by approximately 15 percent.

Key Takeaways

Cost optimization in Microsoft Azure can be a complicated process that requires significant effort from several parts of the enterprise. The following are some the most important lessons that we’ve taken from our cost-optimization journey:

Implement central governance with local accountability

We implemented a central audit of our Microsoft Azure cost-optimization efforts to help improve our Azure budget-management processes. This audit enabled us to identify gaps in our methods and make the necessary engineering changes to address those gaps. Our centralized governance model includes weekly and monthly leadership team reviews of our optimization efforts. These meetings allow us to align our efforts with business priorities and assess the impact across the organization. The service owner still owns and is accountable for their optimization effort.

Use a data-driven approach

Using optimization-relevant metrics and monitoring from Microsoft Azure Monitor is critical to fully understanding the necessity and impact of optimization across services and business groups. Accurate and current data is the basis for making timely optimization decisions that provide the largest cost savings possible and prevent unnecessary spending.

Be proactive

Real-time data and effective cost optimization enable proactive cost-management practices. Cost-management recommendations provide no financial benefit until they’re implemented. Getting from recommendation to implementation as quickly as possible while maintaining governance over the process is the key to maximizing cost-optimization benefits.

Adopt modern engineering practices

Cost optimization is one of the five components of the Microsoft Azure Well-Architected Framework, and each pillar functions best when supported by proper implementation of the other four. Adopting modern engineering practices that support reliability, security, operational excellence, and performance efficiency will help to enable better cost optimization in Microsoft Azure. This includes using modern virtual machine sizes where virtual machines are needed and architecting for Azure PaaS components such as Microsoft Azure Functions, Microsoft Azure SQL, and Microsoft Azure Kubernetes Service when virtual machines aren’t required. Staying aware of new Azure services and changes to existing functionality will also help you recognize cost-optimization opportunities as soon as possible.

Looking forward to more optimization

As we continue our journey, we’re focusing on refining our efforts and identifying new opportunities for further cost optimization in Microsoft Azure. The continued modernization of our applications and solutions is central to reducing cost across our Azure footprint. We’re working toward ensuring that we’re using the optimal Azure services for our solutions and building automated scalability into every element of our Azure environment. Using serverless and containerized workloads is an ongoing effort as we reduce our investment in the IaaS components that currently support some of our legacy technologies.

We’re also improving our methods for decentralizing optimization recommendations to enable our engineers and application owners to make the best choices for their environments while still adhering to central governance and standards. This includes automating the detection of anomalous behavior in Microsoft Azure billing by using service-wide telemetry and logging, data-driven alerts, root-cause identification, and prescriptive guidance for optimization.

Microsoft Azure optimization is a continuous cycle. As we further refine our optimization efforts, we learn from what we’ve done in the past to improve what we’ll do in the future. Our footprint will continue to grow in the years ahead, and our cost-optimization efforts will expand accordingly to ensure that our business is capturing every benefit that the Azure platform provides.

Related links

We'd like to hear from you!

Want more information? Email us and include a link to this story and we’ll get back to you.

Please share your feedback with us—take our survey and let us know what kind of content is most useful to you.

The post Implementing Microsoft Azure cost optimization internally at Microsoft appeared first on Inside Track Blog.

]]>
9389
Shining a light on how Microsoft manages Shadow IT http://approjects.co.za/?big=insidetrack/blog/shining-a-light-on-how-microsoft-manages-shadow-it/ Mon, 06 Jun 2022 16:01:33 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9381 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Shadow IT is the set of applications, services, and infrastructure that are developed and managed […]

The post Shining a light on how Microsoft manages Shadow IT appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Shadow IT is the set of applications, services, and infrastructure that are developed and managed outside of defined company standards. These line-of-business-built solutions (aka Shadow IT) have always existed at Microsoft and are a common industry problem.

Over the years, corporate function teams—including business development, legal, finance, human resources, marketing and sales, support, and consulting—have looked to alternative engineering solutions for many different reasons. Some examples include a lack of IT engineering capacity or prioritization of the business need, historically decentralized budgets, a lack of trust between IT and shadow teams, the need for specialized domain solutions, and the availability of modern tools that enable no-code/low-code solutions to be stood up by citizen developers.

Many of these reasons make strong business sense, if it can be done securely. However, because Shadow IT solutions are often built outside of the guardrails of the company’s engineering systems, they pose a potential compliance risk to the enterprise, specifically in the areas of security, privacy, data governance, and accessibility.

At Microsoft, we needed to first understand if applications built by shadow teams met our security compliance standards. In 2019, we conducted a security assessment on a small random sampling built by shadow teams that showed that all the Shadow apps failed to meet at least two out of three of the key security requirements, and one Shadow app failed all key security requirement areas. This presents a huge and unnecessary risk to the whole company.

Ensuring we address our biggest security vulnerabilities has been our first priority internally at Microsoft in our Shadow IT journey, as the risk in today’s environment is huge. The average data breach in the United States costs $4.2 million (2021 IBM), and cybercrime costs the world $6-7 trillion annually (2020 Annual Cybercrime Report).

Vision

Rather than centralizing all applications into IT, our goal is to reduce or eliminate Microsoft risk by enabling teams to self-manage their assets and ensure that they adhere to the compliance standards set forth by Microsoft. Teams must not only get clean, but also stay clean.

Compliance standards

Microsoft compliance standards are typically defined as four areas of focus, which are all supported by our set of Engineering Fundamentals:

 

Compliance scope includes security, privacy, data governance, accessibility, and engineering fundamentals.
Microsoft compliance standards.

Security: To ensure that the confidentiality, integrity, and availability of the data and systems of an organization is maintained.

Privacy: To ensure control over the collection, use, and distribution of information.

Data Governance: To ensure that the organizational roles and responsibilities by which information is retrieved is captured and maintained appropriately.

Accessibility: To ensure that our products or services are usable by everyone.

Of note, Engineering Fundamentals is seen as an enabler to many compliance areas. Solid engineering fundamentals enables teams with the data, processes, and tools to build solutions that are compliant by design. Retrofitting compliance requirements after a solution has been designed creates additional risk and more work for Microsoft. Additionally, engineering fundamentals enable compliance scale.

Engineering maturity

Given the size and scope of this program, we approached the journey as if we were running a marathon, not a sprint. We kicked off this program in 2020 and have been operating on a multi-year time horizon. Our work has involved and impacted many people, processes, and technology across the enterprise.

Initially, it was important for us to recognize that not all teams were at the same level of maturity. As such, we use the following model to ensure a consistent set of criteria is used to measure engineering maturity, which allowed us to engage with teams at the right level and provide the resources they needed to advance.

 

Moving through the Shadow IT journey, from Level 0 (Unsanctioned) through Level 4 (Optimized).
Moving through the Shadow IT journey starts with lower levels of maturity that focus on centralizing tools and platforms, moves to driving culture change, then to full automation and continuous compliance.

Over time, shadow teams matured their level of engineering fundamentals and ability to adhere to compliance requirements. Most teams started their journey with manual efforts, and have made progress over time, but to date are not fully mature yet. We’re continuing to work toward scaling our efforts, especially as the work gets more complex.

Customized support

Likewise, each division had specific needs for the amount and kind of engagement we provided them, depending on the size, scope, and nature of the team. At Microsoft, we customized the approach based on the nature of the team to successfully move the shadow teams forward in their journey.

 

Pattern Characteristics Approach
Small teams with small asset footprints
  • Teams with a smaller asset (services and Azure subscriptions) footprint.
  • These teams can be more agile in how they organize their efforts around the program.
  • Push teams forward in their modern engineering and security journey.
  • Use learnings from Pattern 1 teams to inform Patterns 2 and 3.
Medium to large asset footprints
  • Teams with a medium-to-large asset footprint.
  • These teams may be able more agile in pockets but will need to look at automation and policy in some cases, and will require the organization to solve for the program collectively.
  • Identify points of contact per organization.
  • Push forward with smaller, more technical teams.
  • Ensure more thorough plans and support models in place for less technical teams.
Large to very-large asset footprint
  • Teams with a large-to-very-large asset footprint.
  • Given the size, complexity, and geographic dispersion of assets, these teams will require automation and much more rigorous planning to move forward.
  • Go slow to go fast: take the time required to define plans and engagement model.
  • Take advantage of established processes, channels, and communication models to mobilize the organization.

While we recognize the difference in approach required for each pattern, the intent of the program remains the same, albeit the timing and approach to the work may be different. Eventually, we plan for this program to become a standard operating principle that is absorbed within normal business functions, instead of being managed as a separate program.

Program approach

We prioritized addressing cloud-based solutions because most Shadow applications existed in the cloud, and the digital environment allowed us to scale the program. We developed a three-step approach to guide our work: visibility, controls, and enforcement.

  • Visibility: Understanding all the assets, devices, identities, cloud tenants and subscriptions, and applications allowed us to create an inventory with clear ownership. To help with visibility in our cloud assets, we built a scanner that inventories Microsoft Azure assets and reads their configurations. Once we identified the assets, we were able to clean up by ensuring each asset was aligned to an appropriate division and eliminate assets that were empty or unused. This helped reduce our scope for moving onto the next phase. The Microsoft Azure Tenant Security Solutions scanner ​is available on GitHub.
  • Controls: We used information from our scanner to compare the remaining assets’ configurations to our defined controls and create reports for all configurations that were out of compliance.
  • Enforcement: We used our inventory and controls reports to start enforcing security and engineering compliance. In many cases, we were able to prevent misconfigurations from the start. When that wasn’t possible, we worked to auto-remediate the non-compliant items to quickly resolve existing issues at scale. To date, we’ve been able to auto-remediate about half of the Microsoft Azure controls we enforce. When auto-remediation wasn’t possible, we employed manual remediation. To manage all this activity, we use a central notification tool that tracks action items and notifies owners of pending deliverables. The tool also allows us to create executive-level reporting to bring awareness of our security risk across all levels of the company.

Lessons learned

Over the past two years, we’ve made a lot of progress, but also encountered many roadblocks. One important discovery is that in specific cases, there may be valid business reasons why an engineering asset may not be able to comply with a security control, and we continue to work with those teams to work around individual parameters to ensure both business and security priorities are met. We also know that this work is never “complete” because security is never-ending; we will continue to update our compliance requirements and approaches as the threat landscape and our technology evolve.

Looking back, there are a few key elements of our Shadow program that enabled our success so far:

Build a team: We funded a central Shadow team within the security organization, led by a dedicated Shadow IT program manager who is fully dedicated to this program. We also obtained program support from the security, IT, and finance departments, and worked together to ensure there were enough IT resources dedicated to this effort to assist with inventory, drive engineering tooling adoption, and provide engineering guidance to the shadow teams. Finally, it was critical to build accountability across the business divisions by appointing one “Directly Responsible Individual” (also known as a DRI) within each participating team, who was accountable for helping their teams work toward compliance, and served as our primary contact and for engaging executive support from those teams.

Drive culture change: While the leaders within the space are important, we quickly realized that we needed to reach the individuals who own and run the Shadow solutions across the company. They needed to understand the importance of security and how to ensure security as a part of their day-to-day actions. We began educating our employees by sharing real security events and highlighting the impacts of these events to emphasize the importance of the actions people take.

We have also adopted a culture to “embrace the red” metrics on the scorecards. We shifted our mindsets to understand that “red” or uncompliant metrics help guide our priorities and work. Once we addressed specific security gaps, those specific metrics turned green, and we immediately replaced the “good” metrics with another “red” metric so that we can continually see progress and address new gaps.

We also provided training, support, and best practice guidance to the shadow teams, including:

  • Gathering compliance activities into requirements in quarterly asks
  • Providing guidance on funding and skills needs in the first year
  • Catering to the lowest knowledge state in wikis and trainings

Be data driven: Managing our reporting process was critical in our ability to drive progress and show the importance of this work. In the early stages, we frequently reviewed our status with executives across the company, and took advantage of our executive sponsor to facilitate these conversations, which helped build momentum. We learned quickly that it was important for us to engage the middle management layer in addition to executives. Our DRIs typically sat two to three layers below the executives, so we needed to ensure there was support for the DRIs between them and the executive.

We also learned over time how to interpret our reporting. We started out reporting on compliance, which worked well until a team had an exception against a control. The exceptions would show up green on our reports. However, an exception is an acceptance of risk, not a sign of compliance. So, we made a plan to start reducing exceptions and began reporting on risk instead of compliance. Reporting on risk aligns well with our Zero Trust reporting, so this was a natural way to drive alignment and create clarity across the company.

What’s next

Our Shadow journey is far from over. We will continue expanding our technology controls and governance to ensure all new solutions and cloud tenants meet compliance standards, and work toward securing the developer pipeline. As for the future of the program, we will reduce custom support processes and enable all teams to adopt our standard enterprise-wide security practices, like the enterprise scorecard and the risk committee. Once teams have met the agreed-upon threshold, the security work will transition from a program into the normal operations of the business.

Key Takeaways

Addressing Shadow IT risk at any company can feel overwhelming at first. Here are a few things that we learned along the way that can help you get started:

Build a team

  • Designate a Shadow IT security program manager
  • Obtain a Directly Responsible Individual (DRI) and executive sponsor from all targeted divisions
  • Engage your CIO and finance partner for sponsorship

Define the scope

  • Scan cloud inventory and configurations within your organization
  • Define cloud security controls

Support

  • Expand engineering and security capabilities to support additional services
  • Develop a communication plan for driving compliance
  • Implement a reporting process to identify focus areas and show progress

Related links

The post Shining a light on how Microsoft manages Shadow IT appeared first on Inside Track Blog.

]]>
9381
Modernizing enterprise integration services at Microsoft with Microsoft Azure http://approjects.co.za/?big=insidetrack/blog/modernizing-enterprise-integration-services-at-microsoft-with-microsoft-azure/ Mon, 11 Apr 2022 16:00:41 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9398 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Our Platform Engineering team in Microsoft Digital Employee Experience (MDEE) wanted to improve the capabilities, […]

The post Modernizing enterprise integration services at Microsoft with Microsoft Azure appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Our Platform Engineering team in Microsoft Digital Employee Experience (MDEE) wanted to improve the capabilities, performance, and resiliency of our on-premises integration platform. To do this, the team used Microsoft Azure Integration Services to build a cloud-based integration platform as a service (iPaaS) solution that increased data-transaction throughput and integration capabilities for our enterprise data footprint and improved platform reliability.

Business-to-business (B2B) and app-to-app (A2A) integration are imperatives in modern software solutions. Integration services use middleware technology that helps secure communication between integration points and data exchange between diverse enterprises and business applications. At Microsoft, our business demands integration across multiple independent software systems with diverse message formats such as EDIFACT, X12, XML, JSON, and flat file. Modern integration requires many modes of connectivity and data exchange, and includes the ability to connect:

  • Two or more internal applications.
  • Internal applications to one or more business partners.
  • Internal applications to software as a service (SaaS) applications.

Building on a foundation of enterprise integration

For decades, we as a company have worked to integrate our business data internally and in business-to-business scenarios with partners, vendors, and suppliers. BizTalk Server has been a standard for integration services for us and our partners, providing a foundation for dependable, easy-to-configure data integration.

Our ongoing digital transformation is driving cloud adoption to move business resources out of datacenters. As data storage and application development has evolved, cloud-native solutions based on SaaS and PaaS models have predominated among enterprise applications in most industries. To meet the growing need to supply increased scalability, reduce maintenance overhead for infrastructures, and decrease total cost of ownership, our Platform Engineering team has increasingly moved toward cloud-based solutions for enterprise integration.

Transforming integration with Microsoft Azure

Our Platform Engineering team began investigating Microsoft Azure Integration Services as a potential solution for scalable, cloud-based enterprise integration. Integration Services combines several Microsoft Azure services, including Logic Apps, API Management, Service Bus, Event Grid, and Azure Functions. These services provide a complete platform that companies can use to integrate business applications and data sources. Our team began working with Integration Services to gauge feasibility, test integration scenarios, and plan for enterprise-scale integration capabilities on the platform.

Collaborating to improve Microsoft Azure Integration Services

Throughout the development process, our Platform Engineering team worked closely with the Integration Services product group to enhance and build connectors. This collaboration allowed us to suggest improvements to existing Integration Services functionality. This effort prompted the creation of two new Logic Apps connectors—SAP with Secure Network Communication (SNC) and Simple Mail Transport Protocol (SMTP)—and enhancements to two existing Logic Apps connectors (EDIFACT and X12).

Examining our Azure Integration Services architecture

We in MDEE use all Microsoft Azure Integration Services components in its architecture to support end-to-end integration. Each component supplies an important part of the larger solution, including:

  • API Management for APIs, policies, rate limiting, and authentication.
  • Logic Apps for business workflows, orchestration, message decoding and encoding, schema validations, transformations, and integration accounts to store B2B partner profiles, agreements, schemas, and certificates.
  • Microsoft Azure Event Grid for event-driven integration to publish and subscribe to business events.
  • Microsoft Azure Functions for writing custom logic tasks, including metadata and config lookup, data lookup, duplicate check, replace namespace, and replace segments.
  • Microsoft Azure Data Factory for processing low volume, large payload messages, ETL processes, and data transformation.

We used Microsoft Azure Front Door as the entry point for all inbound traffic and helped secure endpoints by using Microsoft Azure Web Application Firewall configured with assignment permissions for allowed IP addresses. Additionally, API Management enabled us to abstract the authentication layer from the processing pipeline to help increase security and simplify processing of incoming data.

We deployed the entire solution to an integration service environment, which supplied a fully isolated and dedicated integration environment and other benefits, including autoscaling, increased throughput limits, larger storage retention, improved availability, and a predictable cost model.

The following figure illustrates our solution’s architecture using Microsoft Azure Integration Services.

Azure Integration Services architecture diagram, showing the experience layer, messaging layer, and operations layer.
Microsoft Azure Integration Services architecture for Microsoft Digital Employee Experience.

The solution architecture adheres to several important design principles and goals, including:

  • Pattern-based workflows that enable dynamic decisions using partner information.
  • Self-contained extensible workflows that can be modified and improved without affecting existing components.
  • A gateway component to store and forward messages.
  • Publish and subscribe services for data pipeline output.
  • Complete B2B and A2A pipeline processing with 100 transactions per second throughput and message handling up to 100 megabytes (MB) per message.

Designing dataflow pipelines

Our dataflow pipelines perform processing for most of our business-data transformation and movement tasks. We designed the B2B and A2A processing pipelines using Logic Apps and Microsoft Azure Functions, processing documents in their native format and delivering them to line of business (LOB) or enterprise resource planning (ERP) systems such as Finance, HR, Volume Licensing, Supply Chain, and SAP.

  • B2B pipeline. Electronic data interchange (EDI) documents such as purchase orders are brought in using AS2, processed using X12 standards, transformed, decoded and encoded using Logic Apps and Azure Functions, and then sent to the LOB app using the Logic Apps HTTP adapter.
  • A2A pipeline. Documents such as XML/JSON come in using one of the built-in adapters including SAP, File, SQL, SSH File Transport Protocol (SFTP), or HTTP. The documents are debatched, transformed, decoded, and encoded using Logic Apps and Azure Functions, and then sent to the line-of-business system using the appropriate Logic Apps adapter.

Our integration solution used these pipelines in practical business scenarios across many lines of business at Microsoft, such as for volume licensing. A hardware manufacturer that includes Windows or Microsoft Office in their laptops submits an order for Windows or Office license to Microsoft’s ordering system, which sends the order details to our integration suite. The suite validates the messages, transforms them to IDoc format, and routes the IDoc to SAP using a data gateway for taxation and invoice generation. SAP generates an order acknowledgement in IDoc format and then passes it to the integration suite, which transforms the IDoc message into a format that the Microsoft ordering system will recognize.

Here’s another example from Microsoft Finance. An employee incurs an expense using a corporate credit card and the issuing financial institution sends a transaction report to the integration solution, which validates the message and performs currency conversion before sending it to Microsoft’s expense-management system for further approvals. After it’s approved in the expense-management system, the remittance transaction flows through the integration suite back to the banking system for payment settlement.

Capturing end-to-end messaging telemetry

We designed our solution to monitor message flow across the pipeline. Every transaction injects data into the telemetry pipeline using Microsoft Azure Event Hubs. The pipeline synthesizes and correlates that data to identify end-to-end processing status and recognize runtime failures. We built a custom tracking service that monitors and tracks important metrics for end-to-end workflows by using visual indicators on a dashboard. Accurate and readily available telemetry creates a more robust and reliable integration environment and improves the customer experience across pipelines.

Key Takeaways

We’ve realized several benefits across our integration environment, including:

  • Increased scalability. Our integration solution processes millions of monthly transactions, including 10 million B2B, 2.5 million A2A, and 74 million hybrid cloud transactions.
  • Improved quality of service. We used cross-region deployment with active-active configuration and thorough handling of faults to help achieve 99.9 percent in availability and reliability metrics.
  • Reduced total cost of ownership. We’ve reduced monthly costs in Microsoft Azure by more than 40 percent with this iPaaS solution.
  • Increased customer engagements. We’re working toward increasing Microsoft Azure Integration Services adoption by promoting this solution to our partners, vendors, and suppliers.

Microsoft Azure Integration Services has created an improved and more efficient integration environment for Microsoft. The increased scalability, reliability, and cost-effectiveness of Azure Integration Services has moved our business into a better position to actively collaborate with and operate alongside our partners, suppliers, and vendors. We’re continuing to transform our integration services landscape with Azure Integration Services to keep pace with the rapidly changing modern business environment.

Related links

The post Modernizing enterprise integration services at Microsoft with Microsoft Azure appeared first on Inside Track Blog.

]]>
9398
Five key learnings from Microsoft’s Windows 11 upgrade http://approjects.co.za/?big=insidetrack/blog/five-key-learnings-from-microsofts-windows-11-upgrade/ Tue, 05 Apr 2022 21:15:09 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9638 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=1d4z5N5XCsA. Watch as Biswa Jaysingh, a […]

The post Five key learnings from Microsoft’s Windows 11 upgrade appeared first on Inside Track Blog.

]]>
We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.
For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=1d4z5N5XCsA.

Watch as Biswa Jaysingh, a principal group program manager on the Microsoft Digital Employee Experience team, shares five key learnings from releasing Windows 11 across Microsoft. Jaysingh shares how understanding your hardware environment plays a critical role in a good upgrade and explains how existing tools provided by Microsoft make it easy to prepare for a new release.

Microsoft Digital video

The most important lesson learned during this deployment, according to Jaysingh, was the use of Windows Update for Business deployment service. Jaysingh shares how the tool helped create the “smoothest deployment” in the history of Windows releases by supplying a single, simple plan for IT admins to follow.

“In our experience, with every passing day, we are noticing the value it delivers in their day-to-day lives—working remotely or working in-person,” Jaysingh says.

Try it out

Learn about the many advantages of upgrading to Windows 11.

We'd like to hear from you!

The post Five key learnings from Microsoft’s Windows 11 upgrade appeared first on Inside Track Blog.

]]>
9638
Employees are at the heart of Microsoft’s internal Windows 11 upgrade http://approjects.co.za/?big=insidetrack/blog/employees-are-at-the-heart-of-microsofts-internal-windows-11-upgrade/ Tue, 05 Apr 2022 15:28:09 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9623 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=40B99JJpaUo. Wangui McKelvey and Nathalie D’Hers […]

The post Employees are at the heart of Microsoft’s internal Windows 11 upgrade appeared first on Inside Track Blog.

]]>
We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.
For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=40B99JJpaUo.

Wangui McKelvey and Nathalie D’Hers speak about Microsoft’s internal Windows 11 upgrade. McKelvey is the general manager of Microsoft 365 and D’Hers is Microsoft’s corporate vice president of Microsoft Digital Employee Experience.

Microsoft Digital Video

Watch the video to hear Wangui McKelvey and Nathalie D’Hers discuss how Windows 11 is helping Microsoft employees embrace the new hybrid workplace. McKelvey is the general manager of Microsoft 365 and D’Hers is the corporate vice president of the Microsoft Digital Employee Experience team.

“During the pandemic, we’ve seen just how important Windows 11 has become,” McKelvey says. “From remote onboarding to virtual meetings, emails, and casual coffee chats, Windows 11 has become the secure platform that’s foundational to our hybrid workplace strategy.”

Employees are the backbone of any organization, so getting the employee experience right is a foundational tenet of our company’s success.

“Whether it’s day one or year 20, every employee needs the right experience to be successful in their role,” D’Hers says. “To have success in the hybrid workplace requires strong alignment between your digital experiences, physical spaces, and organizational culture.“

Try it out

Learn about the many advantages of upgrading to Windows 11.

We'd like to hear from you!

Want more information? Email us and include a link to this story and we’ll get back to you.

The post Employees are at the heart of Microsoft’s internal Windows 11 upgrade appeared first on Inside Track Blog.

]]>
9623
Unpacking Microsoft’s speedy upgrade to Windows 11 http://approjects.co.za/?big=insidetrack/blog/unpacking-microsofts-speedy-upgrade-to-windows-11/ Tue, 05 Apr 2022 12:24:19 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9193 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. Like our customers, we at Microsoft have a strong business need to address the new […]

The post Unpacking Microsoft’s speedy upgrade to Windows 11 appeared first on Inside Track Blog.

]]>
We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Microsoft Digital technical storiesLike our customers, we at Microsoft have a strong business need to address the new challenges created by remote and hybrid work. The internal adoption of Windows 11 is helping our company meet those needs, while enabling our employees to work smarter and more securely, regardless of where they are.

Upgrading to Windows 11 at Microsoft

Our priority in rolling out Windows 11 internally was to provide employees uninterrupted access to a safe and productive workspace while giving them a chance to try out the new operating system.

Introducing a new operating system, especially across a distributed workforce, naturally led to questions about device downtime and app compatibility. However, with established practices and evolved solutions in hand, historical obstacles became just that—a thing of the past. The rollout of Windows 11 at Microsoft was our most streamlined to date, frictionlessly delivering employees the latest operating system in record time.

What made the deployment of Windows 11 a success?

Over the past decade, our Microsoft Digital Employee Experience team, the organization that powers, protects, and transforms employee experiences, has worked closely with teams such as the Windows product group to improve how it runs Microsoft’s updates, upgrades, and deployments.

Whereas significant time and resources were once dedicated to testing app compatibility, building out multiple disk images, and managing a complex delivery method, processes and tools introduced during Windows 10 have streamlined upgrades and enabled the transformation to a frictionless experience.

Data from App Assure, a Microsoft service available to all customers with eligible subscriptions, shows the company had 99.7 percent compatibility for all apps in Windows 11—that eliminated the need for extensive testing. It also meant that employees’ Windows 10 apps work seamlessly in Windows 11. Additionally, Microsoft Endpoint Manager and Windows Update for Business eliminated the need for using more than one disk image and made it easier for employees to get Windows 11.

Our Microsoft Digital Employee Experience team relied on the same familiar tools and process as a Windows 10 feature update to quickly deliver the upgrade to employees.

The upgrade was divided into three parts:

Plan: Identify an execution and communication plan, then develop a timeline.

Prepare: Establish reporting systems, run tests, ready employees, and build back-end services.

Deploy: Deploy Windows 11 to eligible devices.

It all starts with a good plan

We at Microsoft Digital Employee Experience have a successful history of deploying new services, apps, and operating systems to employees. And it all starts at the same place—creating a disruption-free strategy that enables employees to embrace the latest technology as soon as possible without sacrificing productivity.

Assess the environment

Before the deployment of Windows 11 could begin, we had to take a careful inventory of all devices at Microsoft and determine which they should target. Windows 11 has specific hardware requirements, and a percentage of employees running ineligible devices meant that not every device would be upgraded. Employees with these devices will upgrade to Windows 11 during their next device refresh.

To evaluate the device population, we used Windows Update for Business reports and Microsoft Endpoint Manager’s Endpoint analytics feature. This allowed our team to generate reports on devices that either met or failed to comply with minimum specifications. For example, certain devices, especially older desktops, lacked the Trusted Platform Module 2.0 (TPM) chipset requirements for security in Windows 11.

In the end, 190,000 devices were deemed eligible based on hardware and role requirements. Over the course of five weeks, our Microsoft Digital Employee Experience team deployed Windows 11 to 99 percent of qualifying devices.

Address ineligible devices and exclusions

After evaluating the broad population of devices, our team developed a plan for devices that would not receive a Windows 11 upgrade. Since Windows 10 and Windows 11 can be seamlessly managed side-by-side within the same management system, we only had to designate the number of devices that would not receive the upgrade. Using Windows Update for Business reports to inform deployment policies, we applied controls on ineligible devices, automatically skipping them during deployment. These measures made it easy to know why a device didn’t upgrade, but also assured a disruption-free experience for both employees and those on our team responsible for managing the upgrade.

These controls also allowed the company to bypass deployment on any device that had been incorrectly targeted for an upgrade.

Ineligible devices. Windows 10 and Windows 11 can be managed side-by-side and will be supported concurrently at Microsoft until all devices are upgraded or retired. As devices are refreshed, more and more of our employees will gain access to Windows 11.

Devices that should not receive the upgrade. Other devices, like servers and test labs—where we validate new products on previous operating systems—were issued controls and excluded from receiving Windows 11.

Establish a deployment timeline

Once upgradeable devices were identified, our team was able to create a clear timeline. From this schedule, our communications team developed an outreach plan, support teams readied the helpdesk, and the deployment team developed critical reporting mechanisms to track progress.

For the deployment itself, our team used a ring-based approach to segment the deployment into several waves. This allowed us to gradually release Windows 11 across the company, reducing the risk of disruption.

Graphic showing Microsoft's internal Windows 11 upgrade milestones on a timeline.
Microsoft’s internal upgrade to Windows 11 hinged on effective end-to-end communication.

Create a rollback plan

Windows 11 has built-in support for rolling back to Windows 10 with a default window of 10 days after installation. If needed, our Microsoft Digital Employee Experience team could have revised this period via group policy or script using Microsoft Intune. Post-upgrade, there wasn’t much demand for a rollback, but the strategic release cadence that the team used, paired with the rollback capability, gave our team an easy way to quickly revert devices that might require going back to Windows 10 for a business need.

Preparing for success

Prior to starting the Windows 11 upgrade, we asked employees to complete pre-work needed for a successful upgrade. Because the upgrade was so smooth, only light readiness communications were needed. Instead, we focused on ensuring that employees were aware and excited about the benefits of Windows 11 and that they were ready to share their feedback on what it was like to use it.

Reach everyone

To maximize the impact of our communications, our team readied content that was digestible for every employee, regardless of role, in an onboarding kit. Employees needed clear and concise messaging that would resonate, so that they could understand what Windows 11 would mean for them.

Our team in Microsoft Digital Employee Experience targeted a variety of established channels, including Yammer, FAQs on Microsoft SharePoint, email, Microsoft Teams, Microsoft’s internal homepage, and digital signage to promote Windows 11.

To generate interest, our materials focused on:

  • The new look and features of Windows 11, designed for hybrid work and built on Zero Trust
  • Flexible and easy upgrade options, including the ability to schedule upgrades at a time that worked best for the employee
  • The speed at which employees could be up and running with Windows 11—as quickly as 20 minutes
  • New terms related to Windows 11 and where employees could go to learn more

An entire page on our company’s internal helpdesk site was dedicated to links related to the upgrade, including Microsoft Learn, where users could find a comprehensive library on new features.

Executive announcements from company leadership also conveyed the benefit of moving to Windows 11 and the ease with which it could be done.

Set expectations

Our team directed employees waiting to see if their device met Windows 11’s hardware requirements to the PC Health Check app. At an enterprise level, the team relied on Windows Update for Business reports to assess the device population.

We also used this opportunity to reinforce messaging to Windows 10 users—both operating systems would continue to operate side-by-side until all devices were refreshed. This helped ease concerns for employees who had to wait for an upgrade.

Ready support

Getting the deployment right wasn’t just about sending messages outward. Our team needed to receive and respond to employee questions before, during, and after the Windows 11 rollout.

Our support teams were given an opportunity to delve into Windows 11 prior to the deployment, which, based on experiences with previous upgrades, gave them time to categorize and group by severity any potential issues they might encounter. This familiarity not only helped them give employees informed answers, but also served as another feedback-gathering mechanism.

Open for feedback

We run Microsoft on Microsoft technology and we encourage our employees to join the Windows Insider Program, where users are free to provide feedback directly to developers and product teams.

That’s why communications didn’t just focus on what was new with Windows 11, but on how feedback could be shared. If an employee had comments, they submitted them through a Feedback Hub where other employees could upvote tickets, giving visibility to our engineers in Microsoft Digital Employee Experience and the Windows product group.

Pre-work for deployment readiness

In addition to readying employees, we had to make sure all the back-end services were in place prior to the deployment. This included building several processes, setting up analytics, and testing.

Establish analytics reports

Evolving beyond previous upgrades, the deployment of Windows 11 was the most data driven release we have ever done. Looking closer at diagnostic data and creating better adoption reporting gave our team clear data to look at throughout the deployment.

Using Microsoft Power BI, our team could share insights regarding the company’s environment. This better prepared everyone on the team and allowed us to monitor progress during deployment.

Our team captured the following metrics:

  • Device population
  • Devices by country
  • Devices by region
  • Eligibility
  • Adoption

In addition to visibility into project status, access to this data empowered our team to engage employees whose eligible devices did not receive the upgrade.

Build an opt-out process

To accommodate users whose eligible devices might need to be excluded from the deployment, our team created a robust workback plan that included a request and approval process, a tracking system, and a set timeline for how long devices would be excluded from the upgrade.

Our Microsoft Digital Employee Experience team released communications specifying the timeframe for employees to opt out, including process steps. Employees who needed to remove their devices from the upgrade submitted their alias, machine name, and reason for exclusion. From there, our team evaluated their requests. Only users with a business reason were allowed to opt out. For example, Internet Explorer 11 requires Windows 10, so employees who need that browser for testing purposes were allowed to remove their devices from the deployment.

Once we had approved devices for exclusion, a block was put in place to remove them from the deployment. Data gathered during the opt-out process enabled us to follow up with these employees, upgrading them to Windows 11 at a more appropriate time.

Create a security model

At Microsoft, security is always top of mind for us. A careful risk assessment, including testing out a series of threat scenarios, was performed before Windows 11 was deployed across the company.

Our Microsoft Digital Employee Experience team built several specific Windows 11 security policies in a test environment and benchmarked them against policies built for Windows 10.

After testing the policies and scenarios to see if they would have any impact on employees, we found that devices with Windows 11 would meet Microsoft’s rigorous security thresholds without creating any disruptions. Just as importantly, users would experience the same behaviors in Windows 11 as they might expect from Windows 10.

The deployment

A decade ago, our efforts to deploy feature updates could be challenging, as we needed to account for different builds, languages, policies, and more. This required careful management of distribution points and VPNs prior to beginning deployment efforts in earnest.

When Windows 10 was released in 2015, our team used two deployment strategies: one for on-premises managed devices and one for cloud-managed devices.

Today, the situation is much simpler.

Launched during the Windows 10 era, Windows Update for Business established some of the trusted practices that make product releases and feature updates a great experience for us here at Microsoft. Windows Update for Business deployment service introduces new efficiencies for our team, consolidating two deployment strategies into one.

For the deployment of Windows 11, our team had an advantage—Windows Update for Business deployment service.

Windows Update for Business deployment service enabled our Microsoft Digital Employee Experience team to grab device IDs from across the environment and use them to automate the deployment. Windows Update for Business deployment service handled all the back-end processing and scheduling for us; all we needed to do was determine the start and end dates.

Our team easily managed exclusions and opt-outs with Windows Update for Business deployment service, and when a device needed to be upgraded, the service made it easier to remove and roll them back to Windows 10.

Importantly, Windows Update for Business deployment service provides a single deployment strategy for us moving forward. Deployment has been simplified, and the data loaded into Windows Update for Business deployment service for this upgrade will help speed up future releases.

Policies for success

We had to decide which policies they wanted to work with for the greatest outcome. This included how many alerts an employee would receive before receiving an upgrade to Windows 11.

Windows Update for Business deployment services reduced the long list of policies that our team needed to manage during deployment. This accelerated deployment without compromising security.

From pilot to global deployment

By structuring the deployment timeline to hit a small group of employees before incrementally moving on to a larger population, our Microsoft Digital Employee Experience team ensured Windows Update for Business deployment service ran as expected and that all required controls and permissions were set.

As our team used the Windows Update for Business deployment service to plot out upgrade waves, Windows 11 downloaded in the background and employees received pop-up alerts when their device was ready. The employee could restart at any time and would boot into Windows 11 after a few automated systems completed the installation. Employees could also schedule Windows 11 to upgrade overnight or during the weekend.

Onboarding OEMs

Working closely with Microsoft Surface and other Original Equipment Manufacturer (OEM) partners, the companies who supply Microsoft with new devices, our team was able to ensure that our employees had Windows 11 pre-loaded onto their PCs. This approach guaranteed that new devices complied with the hardware requirements of the new system.

A new device, straight out of the box, only needs to be powered on and connected to the internet before Windows Autopilot authenticates and configures everything for the user. Once initial setup is complete, Windows Autopilot ensures that new devices are equipped with Windows 11 and all the correct policies and settings.
For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=1d4z5N5XCsA.

Biswa Jaysingh shares five key learnings from releasing Windows 11 across Microsoft. Jaysingh is a principal group program manager on the Microsoft Digital Employee Experience team.

Entering the next stage of Windows at Microsoft

The deployment of Windows 11 at Microsoft validates our team’s approach to product releases and upgrades. With no measured uptick in support tickets, the deployment of Windows 11 has been a frictionless experience for employees and the wide adoption of new features confirms the value of the effort. The speed at which the team completed the deployment—190,000 devices in five weeks—represents the fastest deployment of a new operating system in company history.

We credit the success of this deployment to good planning, tools, strong communication, and the positive upgrade experience Windows 11 provides.

Windows Update for Business deployment service proved to be a big step in the evolution of how employees get the latest version of Windows. The service’s ease of use meant the team had a higher degree of control, flexibility, and confidence.

The tighter hardware-to-software ecosystem that comes with Windows 11 means our employees and all users of the operating system benefit from richer experiences. This, along with integration to Microsoft Teams, are just a few examples of what users are seeing now that they’re empowered by Windows 11.

Key Takeaways
  • Understand the hardware eligibility requirements for Windows 11.
  • The better you understand your environment the easier it will be to create a timeline, a communication plan, and ultimately track the deployment.
  • Messaging is key for leaders in the organization to share, especially for adoption.
  • Run a pilot with a handful of devices before deploying company wide. This will allow you to check policies for consistent experiences. Then move on to a ring-based deployment to carefully manage everything.
  • There’s no need to create multiple deployment plans with Windows Update for Business deployment service; it can automate the experience, streamlining the entire workflow. Instead of waiting until everyone is ready, consider running Windows 10 and Windows 11 side-by-side. Prepare today by deploying to those who are ready now.
Try it out

Learn about the many advantages of upgrading to Windows 11.

Related links
We'd like to hear from you!

Want more information? Email us and include a link to this story and we’ll get back to you.

The post Unpacking Microsoft’s speedy upgrade to Windows 11 appeared first on Inside Track Blog.

]]>
9193
Powering IoT-based experiences at Microsoft with the Digital Integration Platform http://approjects.co.za/?big=insidetrack/blog/powering-iotbased-experiences-at-microsoft-with-the-digital-integration-platform/ Wed, 01 Dec 2021 09:01:46 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=11481 For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=UA7Z5EdBF9o. Watch to see how we’re using our Digital Integration Platform to connect data from different IoT devices, which enables our employees and guests to feel supported and be productive when they come to our buildings here at Microsoft. We periodically update our stories, but we […]

The post Powering IoT-based experiences at Microsoft with the Digital Integration Platform appeared first on Inside Track Blog.

]]>
For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=UA7Z5EdBF9o.

Watch to see how we’re using our Digital Integration Platform to connect data from different IoT devices, which enables our employees and guests to feel supported and be productive when they come to our buildings here at Microsoft.

Microsoft Digital video

We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

Instead of managing different signals from dozens of different devices, Eric Slippern and his team standardize disparate signals within the platform before ingesting that data in Microsoft IoT Hub, Microsoft Azure Digital Twins, Microsoft Azure Maps, and Microsoft Azure Time Series Insights. This, along with using real estate core best practices, empowers a plug-and-play environment for quickly creating IoT-driven experiences across Microsoft’s buildings and spaces.

“We rely on some proven patterns to integrate all the data from various sources,” says Slippern, a principal software architect on the Employee Productivity Engineering team in Microsoft Digital Employee Experience. “Then, we leverage Azure Digital Twins to contextualize that and provide a consistent API service that our teams can use to build IoT-powered experiences.”

Related links

The post Powering IoT-based experiences at Microsoft with the Digital Integration Platform appeared first on Inside Track Blog.

]]>
11481
Advancing your meetings with the Microsoft Teams Meeting Guide http://approjects.co.za/?big=insidetrack/blog/advancing-your-meetings-with-the-microsoft-teams-meeting-guide/ Mon, 22 Nov 2021 19:56:21 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9362 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. At Microsoft, we’re transforming the meeting experience to encourage collaboration and increase productivity. At the […]

The post Advancing your meetings with the Microsoft Teams Meeting Guide appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

At Microsoft, we’re transforming the meeting experience to encourage collaboration and increase productivity.

At the beginning of the COVID-19 pandemic, the shift to predominantly remote meetings inspired our Microsoft Digital team to examine what makes an effective meeting in which everyone feels included. We then used this research to develop the Microsoft Teams Meeting Guide, which is a Modern SharePoint site that’s available to all Microsoft employees. We’ve found this information to be so useful that we’re inviting you to check out a report about the guide; we believe that this content can help evolve your company’s meetings, too.

Getting started

Imagine that all your meetings empower participation and meet the goals you’ve set. Imagine further that people attending your meetings know why they’re invited and how to prepare. Imagine still that your meetings encourage building collaboration and communication rather than result in fatigue. Our Microsoft Digital team is helping make these dreams a reality with the creation of the Microsoft Teams Meeting Guide.

We want to improve how Microsoft employees can achieve more together, helping improve collaboration and promote productivity for all of our employees.

To create the Microsoft Teams Meeting Guide, we worked with Microsoft Research and product groups to develop a research-based guide about how to run effective meetings. We’ve been using this engaging guide, built in Modern SharePoint, since March 2021, and have updated it regularly as new Microsoft Teams releases new features or best-practice guidance changes.

This blog post introduces research that led to the development of the Microsoft Teams Meeting Guide and how the guide’s use has helped Microsoft employees. NOTE: We’re providing visuals from the Microsoft Teams Meeting Guide as examples only.

Examining the remote-meeting experience

Before the onset of the COVID-19 pandemic, there usually were attendees who joined meetings remotely while others gathered in person. The remote attendees often found themselves inadvertently left out of conversations and, sometimes, even the meetings.

“The biggest challenge would be that most of the people there were in person and would start discussions, sometimes even before walking into the room,” says Ed Gonzalez, a curriculum manager on the Global CO+I/GOLD Learning & Development team at Microsoft. “They’d be involved in those discussions and, because of that, forget to start the [Teams] meeting. And there’d be two or three of us just waiting and waiting, and so we missed a lot that way.”

The pandemic levelled the playing field, as suddenly everyone was attending meetings remotely. We saw this as an opportunity to examine and learn about the gaps with respect to remote meetings. We then applied this learning to hybrid meetings, where there are both remote and in-person attendees. Our Microsoft Digital team researched what makes meetings inclusive and effective, using internal and external surveys, studies, and employee remarks.

Research conclusions

During our research, we discovered that inclusive meetings are at least three times more likely to be effective. Key elements that make meetings more inclusive include:

  • Sharing an agenda
  • Beginning and ending meetings on time
  • Encouraging attendees to use their video functionality
  • Making it clear who is in the meeting and why
  • Providing a pre-read for the meeting (when you believe it applicable or helpful)

Developing the Microsoft Teams Meeting Guide

6 boxes that show the meeting room styles and suggestions for hosting. Status, Strategic, Tactical, Informative, Ideation and Social.
Screen capture that depicts meetings phases detailed by the Microsoft Teams Meeting Guide.

We developed the Microsoft Teams Meeting Guide to address the challenges we discovered during our research and encourage improvements in those areas. The guide is built on the Microsoft SharePoint Online platform as a site that every employee can access and leverage. It includes helpful guidance about:

  • Starting meetings off right
  • Reducing meeting fatigue and increasing engagement for attendees
  • Deciding whether and how attendees should use video
  • Ensuring attendees have access to the correct information before, during, and after a meeting
  • Using Teams apps to enhance your meeting
  • Conducting hybrid meetings

We want to clearly reveal the most impactful changes that you can make in meetings while encouraging site users to dig deeper into the topics and guidance so they can glean more insights.

“These are simple, thoughtful actions that can make a big difference in the feeling of being comfortable in a meeting, which allows for that inclusion and participation,” says Sara Bush, a principal program manager in Microsoft Digital.

The site supports this with its clean layout and the way it organizes information.

The Microsoft Teams Meeting Guide includes 10 key pages, including:

  • A Home page that provides an overview and links to other important pages
  • Best practices that apply to all meetings at each phase: before the meeting, during the meeting, and after the meeting
  • Information about each of the six common Microsoft meeting archetypes

Promoting the meeting guide internally

 

An icon showing multiple devices connected to an animated laptop with dotted lines. The text next to the icon reads “Expect more from meetings”.
Example of a Microsoft internal promotion for the Microsoft Teams Meeting Guide.

The Microsoft Teams Meeting Guide is available to everyone at Microsoft, and we’re employing many strategies to ensure people know about it. Our promotional campaign includes quick bits of information about the guide and links to it, and tips and tricks. We’ve also developed and shared longer blogs, videos, and articles to drive interest in it, and have used forums such as Teams, Microsoft Yammer, and Microsoft’s internal IT help site, as well as newsletters and emails.

We continue to release campaigns that coincide with new Microsoft Teams feature releases. Additionally, all new hires receive the Microsoft Teams Meeting Guide and managers are starting to include it in their onboarding materials.

Improving our meetings

Jacqueline Le, a senior business program manager in US Manufacturing, has shared the Microsoft Teams Meeting Guide with many of her colleagues, including scheduling quick Microsoft Teams calls to discuss it. She finds it’s a great way to encourage people to implement it. She said she especially appreciates the guidance about agendas, which she has leveraged to help her team decide how much time they need for a meeting.

“It’s relatively easy to use and navigate,” Le says. “You can scroll once and quickly assess what you want to get out of it. And then you can scroll again and get some more information. It’s not heavy reading, and it’s more visually appealing.”

Connor Joyce, a behavioral researcher for the Microsoft Viva Insights team, says the guide’s meeting archetypes enable him to pinpoint the type of meetings he needs to organize, which then helps him invite only the people that are most important to that meeting. This means he doesn’t invite people who aren’t required to achieve the meeting goals, thereby giving people their time back and helping reduce meeting fatigue and overload.

“If they really want to know (about the meeting), they can read the notes or watch the recording,” Joyce says. Thus, some employees are finding that the Microsoft Teams Meeting Guide is saving employees time, as they don’t have to attend some meetings and can review materials asynchronously.

Keeping current

We continue to update the Microsoft Teams Meeting Guide as Microsoft Teams features evolve to help people collaborate more effectively. We’ve been updating guidelines to support hybrid meetings based on our research and Microsoft Teams features that support them. You can track new Microsoft Teams features through the Microsoft 365 roadmap and Microsoft Teams help & learning pages.

Related links
We'd like to hear from you!

Want more information? Email us and include a link to this story and we’ll get back to you.

The post Advancing your meetings with the Microsoft Teams Meeting Guide appeared first on Inside Track Blog.

]]>
9362
Instrumenting ServiceNow with Microsoft Azure Monitor http://approjects.co.za/?big=insidetrack/blog/instrumenting-servicenow-with-microsoft-azure-monitor/ Mon, 15 Nov 2021 15:50:48 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=9356 We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. At Microsoft we have integrated our ServiceNow environment with Microsoft Azure Monitor to create a […]

The post Instrumenting ServiceNow with Microsoft Azure Monitor appeared first on Inside Track Blog.

]]>
Microsoft Digital technical storiesWe periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time.

At Microsoft we have integrated our ServiceNow environment with Microsoft Azure Monitor to create a comprehensive, end-to-end monitoring solution that helps us to ensure performance, reliability, and service excellence across our ServiceNow environment. Combining ServiceNow with Azure Monitor helps us monitor the availability, performance, and usage of the ServiceNow platform and provide actionable insights to our engineering team. Our new monitoring environment results in greater platform reliability and health and a better experience for all our ServiceNow users.

We on the Microsoft Digital Employee Experience (MDEE) team support more than 170,000 employees and partners in more than 150 countries and regions. We use ServiceNow to meet several service and support needs for our organization, including incident management, problem management, service-level agreement (SLA) measurement, request fulfillment, self-service support, and knowledge management. ServiceNow provides built-in, real-time reporting and dashboarding for the aforementioned areas. Global Helpdesk, our support and service management organization, receives more than 3,000 incoming service requests each day.

We have been using ServiceNow as our primary service and support platform since 2015. In July 2019, we established a strategic partnership with ServiceNow to help accelerate digital transformation for our customers. As part of this collaborative effort, we have been using the ServiceNow platform to automate internal support processes while helping ServiceNow to develop and improve their platform to create a more reliable, efficient, and trusted framework for employee support.

[Learn how we’re using Microsoft Teams and ServiceNow to enhance end-user support.]

Examining ServiceNow monitoring at Microsoft

We’ve used ServiceNow’s native reporting features to better understand our support environment since we started using the product in 2015. ServiceNow offers a robust reporting module. Users can generate ad hoc and scheduled reports in ServiceNow to observe current data or visualize and analyze other data, including most major ServiceNow module data. ServiceNow provides an integrated report designer interface and integrated dashboarding capabilities.

However, the massive scope of our ServiceNow environment makes end-to-end visibility of ServiceNow functionality difficult to achieve with the built-in ServiceNow reporting features. While we can report on many aspects of ServiceNow’s business and process-oriented functionality, we wanted to capture a more comprehensive instrumentation of ServiceNow functionality from the perspective of all roles that use ServiceNow. These roles include support agents, engineers, product owners, program managers, external partners, and users. We identified several areas of ServiceNow monitoring and reporting that we wanted to improve, including:

  • Overall platform health monitoring. While ServiceNow’s reporting provided great data for the processes happening within each module, we couldn’t use it to observe the platform itself, including the functional components and architecture that kept ServiceNow running.
  • End-to-end monitoring of business and technical functionality. We wanted to monitor ServiceNow from both business-oriented and technology-oriented perspectives, end to end. Our support and service metrics were important, but so was knowing that the systems that our support and service teams use were operating properly and effectively.
  • Proactive reporting. We wanted a less reactive monitoring environment in which we could actively search for issues and determine the health status of any or all parts of our ServiceNow architecture and functionality.
  • Near real-time monitoring. We wanted near real-time monitoring for all aspects of ServiceNow, not just the business-process results from each module, such as incident management or problem management. We needed to know immediately if an underlying technical component had an issue.
  • Comprehensive objective reporting. We wanted a better way to monitor ServiceNow from the outside, with an objective monitoring tool that wasn’t part of the ServiceNow platform.

Extending ServiceNow monitoring with Azure Monitor

To address the challenges and make the improvements we identified, we in MDEE have integrated Microsoft Azure Monitor with ServiceNow to create more robust reporting capabilities. Our solution is based in Azure Monitor, using Azure Monitor Application Insights to store data from ServiceNow that we’ve extracted and transformed using both ServiceNow’s native reporting data and an internally developed app that translates ServiceNow data and stores it in Application Insights.

Capturing complete data from ServiceNow

ServiceNow provides several native data-output streams. While the end-to-end process of capturing ServiceNow data in Application Insights involved a complex data flow, retrieving raw data from ServiceNow was simple. We used two of ServiceNow’s default data-output streams to capture data for Application Insights:

  • Node and semaphore information from xmlstats.do. Xmlstats.do contains comprehensive data for ServiceNow node and semaphore data. ServiceNow nodes host core functionality, while semaphores define how the load for those nodes is managed and distributed.
  • Usage and business process data from transaction logs. ServiceNow transaction logs contain records for all browser activity and REST API usage for an instance, including performance metrics such as response time and network latency.

Bridging the gap from ServiceNow to Application Insights with Azure Function Apps

We’re using two approaches to extract this data from ServiceNow, with one approach for each of the data types. Our push model assembles data in ServiceNow and pushes it to a REST API endpoint for consumption, while the pull model collects data from a ServiceNow API endpoint. Both models are based in a Microsoft Azure Function App that we call the Translator App. We use the Translator App to translate ServiceNow’s telemetry output, transform the data into usable JSON formatted output, and place the data in Application Insights.

Push model for platform data in nodes and semaphores

Our push model is rooted in an automation routine in ServiceNow that assembles and exports node and semaphore data to the Translator app. This data is collected from the xmlstats.do page in ServiceNow in five-minute increments and pushed to the Translator app in 15-minute intervals. The automation for the push model is built entirely in ServiceNow Studio, ServiceNow’s built-in editor for custom applications. The push model collects data for system health, notification events, and other key datapoints within the ServiceNow node or semaphore architecture. The push model works in near real-time and is best suited to smaller collections of datapoints or when we must perform calculations on the data points prior to exporting the data.

Pull model business data in transaction logs

The pull model is designed to manage a much larger data load. We use the pull model to extract all transaction log data from ServiceNow and place it into Application Insights. The pull model’s functionality is based in the Translator app. Using Azure Function App capability, the Translator app accesses a ServiceNow REST API endpoint and pulls data from a read replica database. Because we use a read replica database in ServiceNow, requests from the pull model don’t affect production functionality or affect the performance of production databases. We pull approximately 2 million to 6 million transactions each day from ServiceNow into Application Insights by using the Translator app.

 

ServiceNow and Azure Monitor solution architecture depicting data sources connected to the translator app using push and pull models.
The ServiceNow and Microsoft Azure Monitor solution architecture.

Creating actionable reporting with Application Insights

After our Translator app transforms and loads data from ServiceNow into Application Insights, we can take advantage of a robust and highly configurable reporting and monitoring environment. We can use Application Insights to monitor technical and business processes across the entire ServiceNow platform. Our Application Insights instance is the primary source for all our querying, reporting, and dashboarding activities for ServiceNow.

Reporting and dashboarding

With the data in Application Insights, we can use any reporting tools included with or compatible with Microsoft Azure Monitor to query and visualize our data. We use several important reporting tools, including:

  • Microsoft Power BI. We use Power BI for most of our dashboarding needs for end-to-end ServiceNow monitoring. Power BI uses a simple, yet powerful interface that users, like our program managers, can use to create their own insights into ServiceNow performance and functionality.
  • Log Analytics. Our engineers use Log Analytics extensively to quickly locate and identify specific transaction log behavior or trends. Log Analytics query language makes it easy for engineers to quickly find what they’re searching for, especially if they’re familiar with the underlying dataset and schema of the ServiceNow data sources.

Key Takeaways
Microsoft Azure Monitor provides a flexible and consistent platform on which we’ve built a broad and comprehensive monitoring solution for ServiceNow. Our new solution, built in Azure, helps us ensure that we deliver a reliable service as our ServiceNow environment grows and changes with our business. Combining ServiceNow with Azure Monitor helps us monitor the availability, performance, and usage of the platform. We can provide actionable insights to our engineering team, which results in higher platform reliability and health and a better experience for all our ServiceNow users.

  • ServiceNow has the extensibility to write custom apps to be able pull data out of your instances and Microsoft Azure gives you the flexibility to be able to ingest the data.
  • Monitor system health and create alerts and notifications in near real-time when certain metrics fall below thresholds. With the new solution, we can capture this data across the entire ServiceNow scope.
  • Track service health over time, correlate, and trend data. Historical and trend-based reporting helps us to anticipate upcoming events and adjust to meet upcoming demand. We can also more accurately predict failures and outages across the environment.
  • Report on feature usage within ServiceNow. This data empowers our program managers and engineers to understand how our customers are using or not using the features and modules that we release to determine return on our investment.

Related links

The post Instrumenting ServiceNow with Microsoft Azure Monitor appeared first on Inside Track Blog.

]]>
9356