Secure private access to your internal apps without a VPN

Welcome everyone to my contribution to this year's Festive Tech Calendar. Thanks, as always, to the event organisers who put this event together. It's always great to see such amazing and varied content each December throughout the tech community. This year, I've picked a classic solution that I still turn to time and time again. … Continue reading Secure private access to your internal apps without a VPN

Using Traffic Manager to Failover or Bypass Azure Front Door

Microsoft unfortunately suffered not one but two major service outages in October 2025 on their Azure Front Door service. This is a global (non-regional) load balancing service offering CDN and WAF services as a front-end to web applications and services. As this is a global service, it does not follow traditional high availability or disaster … Continue reading Using Traffic Manager to Failover or Bypass Azure Front Door

Migrating to Azure? Decide carefully when choosing your firewall

So, you've decided to move to the cloud and you have migrated your workloads over to Azure but what decision did you make about the firewall? You've probably got a long standing preferred firewall vendor that you've been using for your NGFW on premises. It works well and you trust it, right? Of course, the … Continue reading Migrating to Azure? Decide carefully when choosing your firewall

Default outbound access retirement – one month to go!

This post is just to serve as a timely reminder to ensure that you are ready for the upcoming behaviour changes in how Azure will treat default outbound network access. Azure will soon change how default outbound network access is handled by Virtual Machines, which could impact resources that rely on implicit outbound access routes … Continue reading Default outbound access retirement – one month to go!

Exploring Network Security Perimeters in Azure

Spring is here again and I'm pleased to once again be contributing a post as part of the Azure Spring Clean event organised by Joe Carlyle and Thomas Thornton. Continuing on from last year's post on Azure Networking where I discussed default outbound access, this year's post will focus on a new service called Network Security Perimeter. … Continue reading Exploring Network Security Perimeters in Azure

Tidings of Comfort and Joy with Azure’s Business Continuity Center

I'm delighted to present my contribution to the Festive Tech Calendar which is now in it's sixth year. Thanks to all the event organisers for pulling together so much fantastic content once again, it just continues to get bigger and better each year. Well done everyone. This year, I have chosen to write a post … Continue reading Tidings of Comfort and Joy with Azure’s Business Continuity Center

Managing ACLs in Azure at scale without IaC or scripts

If you are reading this post then you have probably at some point had to perform maintenance on an access control list (ACL). A list of allowed (whitelisted) or blocked (blacklisted) public IP addresses controlling access to a particular resource or set of resources. We come across these in Azure quite a bit. Firewalls policies, … Continue reading Managing ACLs in Azure at scale without IaC or scripts

Using Azure Compute Gallery to help deliver a managed multi-customer desktop solution

As the kids go back to school this September, the Azure learning continues and I'm pleased to be contributing once again to the Azure Back to School event. There's so many great sessions this month and I've already learned a lot from the community contributions. My thanks to Dwayne Natwick and Derek Smith for organising. … Continue reading Using Azure Compute Gallery to help deliver a managed multi-customer desktop solution

Point-to-Site Internet breakout through Azure Virtual WAN

This is an interesting one that has come up a few times with some customers who want to use forced tunnelling through a VPN to Azure for remote workers and NAT out to the Internet using a Microsoft public IP address. This is usually required as an additional security measure for easier user whitelisting through … Continue reading Point-to-Site Internet breakout through Azure Virtual WAN

Routing hub & spoke virtual networks through a network virtual appliance

I was recently involved in deploying a Watchguard network virtual appliance (NVA) to Azure, something I had last performed several years ago but back then it was a very basic setup and everything, including the NVA itself was deployed to a single Azure virtual network. Nowadays, most deployments will call for a hub and spoke … Continue reading Routing hub & spoke virtual networks through a network virtual appliance

Does data going to M365 count as Internet egress bandwidth in Azure?

I do get asked from time to time from customers if they should account for usage of Microsoft 365 services in an Azure Virtual Desktop environment towards their Internet egress traffic estimations. Afterall, a new customer deployment may have hundreds or even thousands of users running M365 desktop apps in an Azure Virtual Desktop environment … Continue reading Does data going to M365 count as Internet egress bandwidth in Azure?

How to query a Private DNS Zone over Point-to-Site connection with Azure DNS Private Resolver

The issue With more and more services going cloud native it's becoming increasingly more common for organisations not to rely on DNS servers anymore. Just like how we are seeing new 'greenfield' organisations going fully cloud native and opting not to use domain controllers at all. We are also starting to see organisations not want … Continue reading How to query a Private DNS Zone over Point-to-Site connection with Azure DNS Private Resolver

Azure customer management for MSPs

It's that time of the year again and I’m delighted to be taking part once more in Azure Spring Clean, a community event focused on Azure management best practises. Many thanks to Joe Carlyle and Thomas Thornton for organising the event again this year. Please check out the website from the link above for loads more excellent Azure articles, there's … Continue reading Azure customer management for MSPs

MSP: The well-tempered Azure tenant – Part 5

Welcome to part 5 of my well-tempered Azure tenant series for MSPs. This time we will take a look at Azure Monitor. A powerful solution for collecting performance metrics and logs from your customer tenants. Using this telemetry we can provide proactive managed services through monitoring dashboards and alerts which is essential for any managed … Continue reading MSP: The well-tempered Azure tenant – Part 5

How to save your old virtual machines to low cost archive storage

I had an interesting request this week with a customer who had some decommissioned Azure virtual machines but for compliance reasons needed to retain the data on the disks for 7 years. Even on Standard HDD storage a 1TB managed disk might cost around €35 per month which adds up to quite a lot over … Continue reading How to save your old virtual machines to low cost archive storage

Don’t use user accounts for your Logic App connections

I have seen an increasing number of users switching from using automation accounts to using virtual machine automation task templates (logic apps) for virtual machine stop/start automation. This is not entirely surprising as this template is wizard driven and generally very straightforward to set up whereas configuring an automation account to trigger a script was … Continue reading Don’t use user accounts for your Logic App connections

Developing an automated Advent calendar static web app

Yes, it's that time of the year once again! This post accompanies my contribution to the Festive Tech Calendar 2021 which as always is an online community event running throughout the month of December. My thanks to Gregor Suttie and Richard Hooper for organising the event. I love taking part in this event and it just keeps getting better every year … Continue reading Developing an automated Advent calendar static web app

How to remove Azure Disk Encryption from disks that have already been decrypted

I had an interesting one this week that I thought was worth posting about just in case it might help some others in the same situation. Scenario: Customer has some Azure Windows virtual machines that are encrypted with Azure Disk Encryption and integrated with Azure Key Vault. They want to move these virtual machines to … Continue reading How to remove Azure Disk Encryption from disks that have already been decrypted

Azure Virtual Network Manager (Preview) – A First Look

One of the many Azure networking announcements at Microsoft Ignite recently was the release to public preview of Azure Virtual Network Manager (AVNM). AVNM promises to be a service to help apply connectivity and security configurations to groups of virtual networks across multiple Azure subscriptions. This post gives my initial thoughts on this service as … Continue reading Azure Virtual Network Manager (Preview) – A First Look

Autoscaling Managed Disk Performance Tiers without downtime

In the past week, Microsoft have released a new feature into general availability that allows you to change the performance tier of managed disks without any downtime to the virtual machine. Whilst reading up on this new feature I was quickly reminded that there are already some disk-level bursting options available for just this scenario. … Continue reading Autoscaling Managed Disk Performance Tiers without downtime

It’s time to start using Generation 2 virtual machines in Azure

In this post, I wanted to highlight the key benefits of using Generation 2 virtual machines in Azure. These have been in general availability for a while now but from my own experience I don't see too many Gen2 virtual machine deployments in the wild yet. If you have a Hyper-V background like myself, then … Continue reading It’s time to start using Generation 2 virtual machines in Azure

Live Monitoring Your VM Connections With Network Watcher

I’m delighted to be taking part once again in Azure Spring Clean, a community event focused on Azure management best practices. Many thanks to Joe Carlyle and Thomas Thornton for organising this event and allowing me to contribute. Please check out the website from the link above for loads more excellent Azure articles. This year my focus is going to … Continue reading Live Monitoring Your VM Connections With Network Watcher

Have you correctly licensed your migrated SQL Server VMs in Azure?

Are you migrating SQL Server virtual machines to Azure? If so, how are you handling the SQL licensing once migrated? If you are running SQL Server Standard or Enterprise edition then you need to have either an active software assurance agreement or a current CSP subscription for SQL Server in order to qualify for license … Continue reading Have you correctly licensed your migrated SQL Server VMs in Azure?

First look at Active Directory authentication over SMB for Azure Files (Preview)

I've been waiting for this one for a long time so I was very keen to get stuck in with a deployment as soon as the public preview was announced late last week. Firstly, why is this important? Although many of us have now migrated file based sharing solutions over to the likes of Sharepoint … Continue reading First look at Active Directory authentication over SMB for Azure Files (Preview)

A lesson learned on outbound connections with Standard SKU Public IP Addresses

I had a curious issue this week that I could not explain for some time.  I eventually got to the bottom of it with some assistance from Azure Support and thought I would share some details in case anyone else comes across the same issue. The problem:  I had a couple of Virtual Machines in … Continue reading A lesson learned on outbound connections with Standard SKU Public IP Addresses

Monitoring failed login attempts to your Azure Virtual Machines

I've been spending a lot more time recently working with Azure Monitor and Log Analytics. With Log Analytics you can not only monitor your Virtual Machine performance counter metrics but your Windows event logs as well. Something that I discovered is that although you can query the system and application Windows event logs you cannot … Continue reading Monitoring failed login attempts to your Azure Virtual Machines

Uploading blobs direct to Azure archive tier storage

The archive tier feature of the storage account v2 is something that is gaining more and more attention from customers.  Why…because of the price and recently Microsoft announced a price reduction of up to 50% for some regions.  In addition to this there have been some new features launched which at the time of writing … Continue reading Uploading blobs direct to Azure archive tier storage

Hybrid Cloud: Using Azure to secure and monitor on-premises systems

My first blog article isn’t going to be about a new feature but more something that I wanted to write about because I believe many customers who are using Azure are not aware of it. Many people think of Azure as its own self-contained world, and that it’s either running on Azure or it’s not.  … Continue reading Hybrid Cloud: Using Azure to secure and monitor on-premises systems