自己紹介
2
足利 惟 @yuiashikaga
株式会社 pnop 所属
Microsoft Azure だけでお仕事してます
Azure とはかれこれ8年くらいのお付き合い
Japan Azure User Group (JAZUG) 運営メンバー
勉強会の企画、運営、登壇などを通じてAzureの魅力を発信
Facebookで「JAZUG」検索!!
Microsoft MVP for Azure (2016年4月~2020年6月)
カメラ、釣り、レース観戦
OLYMPUS、バス釣り、F1、Super GT
Diskの詳細なメトリクス
22
VM cached IOPS Consumed Percentage
VM cached bandwidth Consumed Percentage
VM uncached IOPS Consumed Percentage
VM uncached bandwidth Consumed Percentage
OS Disk IOPS Consumed Percentage
Data Disk IOPS Consumed Percentage
OS Disk bandwidth Consumed Percentage
Data Disk bandwidth Consumed Percentage
Azure Bastion
24
踏み台 as a Service
東日本でも使えるよ
Azure Portal
Remote Protocol
(RDP, SSH, et al)
SSL
443,
Internet
AzureBastionSubnet
Port: 3389/22
“AzureBastionSubnet”
Target VM Subnet(s)
Private IP
Azure VM
Azure VM
Azure VM
Customer’s Virtual Network
SSL
Azure Bastion
Azure Bastion
25
今後ロードマップ
Azure AD SSO with MFA
Native RDP/SSH クライアントのサポート
RDP full-session recording for auditing
Azure AD PIM integration
Private IP for Bastion host (access through ExpressRoute or S2S VPN)
Azure Private Link
27
Private
endpoint
Storage
10.0.0.5
SQL DWSQL
Private Link
Service
Deny Internet
Deny Internet
ER Gateway
On-premises
Private
Link
Customer
owned
services
Azure
PaaS
services
Marketplace
services
Virtual Network (10.0.0.0/16)
ER Private
Peering
Private access from Virtual
Network resources,
peered networks and
on-premise networks
In-built Data
Exfiltration Protection
Predictable private IP
addresses for PaaS resources
Unified experience across
PaaS, Customer Owned and
marketplace Services
Azure Private Link ロードマップ
29
Preview Service Q1CY2020
Storage, SQL DB, SQL DW, ADLS
Cusomer own service
Preview more PaaS Q1CY2020
KeyVault, App Service, AKS Control Plane
MySQL, PostgreSQL, MariaDB
VPN (S2S)
30
High throughput VPN - 10Gbps GA
新しい VPN Gateway が登場 (VpnGw3/4/5)
最大10,000のP2Sコネクションが可能 (通常は256)
IKEv1 + IKEv2 on VpnGw1-5 GA
複数のIKEv1 S2S トンネルをサポート
IKEv1, IKEv2 とも共通の VPN Gateway を通る
VPN Gateway パケットキャプチャ Preview
5-tuple パケットフィルター
ETW or PCAP フォーマットで出力
Azure Peering Service
34
Microsoft Global Network
ISP
Geographical area
ISP Branch Office
Geographical area
Public Services
X
✓
ISP
Branch Office
Geographical area
ISP
X Cloud Service
Distributed app hosted in any Msft
DC accessed from any location`
Front Door (Global Load Balancer,
Dynamic Site Acceleration)
Edge Point of Presence
Cloud Service
Connect to nearest Microsoft edge PoP
ISP one hop away from Microsoft
Traffic in Microsoft global network routed w/ SDN-based policies for optimal performance
Azure Peering Service
35
20 million routes monitored real time
against BGP leaks, hijacks or withdrawals
Operational InsightsMonitoring
MAPS Partner
Customer
MS Peering
Partner
Microsoft Internet
Enterprise grade Internet
connectivity to Microsoft
User Telemetry Route Anomalies Detection
and Auto Remediation
(RADAR)
Telemetry platform
Latency deviation
BGP Route anomalies
Performance degradation events
Peering Service Platform
Connectivity Providers partnership
Local and geo peering redundancy
High capacity peers
Optimized Internet traffic routing
Direct private access to Azure
Connect to Azure from anywhere
for satellites
ExpressRouteGround station
C O M M E R C I A L
Directly connect ground stations to Microsoft
Remote
mine
Energy
farm
Oil/gas
rig
Defense and
peacekeeping
Remote
factory
ExpressRoute
GA
Internet Analyzer
Easily measure and compare end user
experience for your application
Cloud migration
Measure the impact of moving the web app to cloud
PREVIEW
CDN and app acceleration
Measure the performance impact of Front Door and CDN
Perform A/B measurements
Measure end user performance of two versions of app
or impact of multiple region deployments
Your real end users,
your customers around the globe
2
Configure your
tests
3
Get your global
perf scorecards
1 Deploy internet
analyzer client
Delivered with
your app
Your current
application
architecture
“What-if”
application
architecture
The
internet
A C T I V E
P E R F O R M A N C E
M E A S U R E M E N T S
Test
configuration
Measurement data
BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
Azure AD Connect cloud provisioning
74
AADCを構築する必要がなくなる(同期処理をクラウド側で管理)
軽量のエージェントをインストールすることで同期処理実施
Public Preview - 2019/12
Azure AD Connect cloud provisioning
75
Azure AD
Active Directory
Disconnected
Active Directory
forests
International
Subsidiary
Acquisition
Branch office
Azure AD Connect cloud provisioning
76
Azure AD
Active Directory
Disconnected
Active Directory
forests
まとめ
77
Azure Virtual WAN
Any-to-Any接続
ExpressRoute, P2S VPN
ExpressRoute 暗号化
Azure Firewall 統合
Azure Firewall Manager
Internet Analyzer
App Service
App Service Managed Certificates
Azure Monitor との統合
Regional VNet Integration
Private Link
Functions
.NET Core 3 のサポート
Powershell のサポート
Premium プラン
Durable Functions v2
Azure Monitor との統合
Application Gateway
AKS Ingress Controller
Azure Key Vault 連携
メトリックの強化
ワイルドカードリスナー
Azure Kubernetes Service
クラスターオートスケール
AZサポート
マルチノードプール
Live Deployment
Live performance metrics
Azure Monitor
Network Insight
SQL Database
SQL Database Serverless
Azure Database for PostgreSQL
Hyperscale
Cosmos DB
Autopilot
Storage
Files:NFS4.1サポート
Files: Active Directory 認証
Blobs:アカウントフェールオーバー
Blobs:NFS v3 サポート
Blobs:任意リージョンへの複製
System Center
Malware reputation screening for Azure Storage
Azure Active Directory
MFA Free
条件付きアクセス
エンタイトルマネジメント
Email + codeによるサインイン
AAD Connect cloud provisioning
Free Certification Exam Offer
Azure Arc
Azure Synapse Analytics
Virtual Machine
Gen2イメージVM
Dav4シリーズ、Eav4シリーズ
Spot VM
VM Mode VMSS
Small Disk 登場
Premium SSD のバースト機能
Incremental snapshots of Managed Disks
Azure Shared Disks
Diskの詳細なメトリクス
Azure Bastion
VNET
Private Link
High throughput VPN
IKEv1 + IKEv2 on VpnGw1-5
VPN Gateway パケットキャプチャ
Azure AD 認証 + MFA サポート
Azure VPN Client
Azure Peering Service
ExpressRoute
ER for satellites