Windows Server 2016 Secure IaaS Hosting Challenges
Description: Windows Server 2016 Secure IaaS Hosting Challenges Integration with Dev and Ops Fast and lightweight OS How to plan for public cloud Looking for cost savings Need to reduce datacenter footprint Lack of integration between solutions Cost
Related Topics
Download Presentation
"Windows Server 2016 Secure IaaS Hosting Challenges" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Windows Server 2016 Secure IaaS<br>
slide2. Hosting Challenges Integration with Dev and Ops
Fast and lightweight OS
How to plan for public cloud Looking for cost savings
Need to reduce datacenter footprint
Lack of integration between solutions Cost Efficient Infrastructure Next Generation Application Platform Security Increasing breaches incidents
Identity is target of attacks
Not easy to secure virtual environments<br>
slide3. Next Generation Application Platform Traditional & cloud-native apps
Containers & microservices
Azure Hybrid Use Benefit Built-in compute, storage and network virtualization
Hyper-Converged
Hyper-Scale Azure Inspired, Software Defined Infrastructure Advanced Multi-Layer Security Privileged identity protection
Secure virtualization platform
Breach resistance Presenting Windows Server 2016 The operating system that powers Azure and Your Business<br>
slide4. Hosting Opportunities Use industry-standard hardware to build lower-cost, high density, highly available and scalable storage. Cost Efficient Reliable Storage Secure IaaS Provide higher density and performance for container-based apps and microservices.
Compatible with existing server applications. Platform for Modern Apps Using Windows Server 2016 Prevent and block attacks against virtual machines, applications, and data with layers of protection built into the OS. Achieve cost-savings and flexibility with software-defined compute, storage and network virtualization technologies inspired by Microsoft Azure. Software Defined Datacenter. Establishes new revenue streams with value added services every step of the way<br>
slide5. Secure IaaS (Virtual Machines) Shielded VMUse BitLocker to encrypt the disk and state of virtual machines protecting secrets from compromised admins & malware
Host Guardian Service Attests to host health releasing the keys required to boot or migrate a Shielded VM only to healthy hosts
Generation 2 VM Supports virtualized equivalents of hardware security technologies (e.g. TPMs) enabling BitLocker encryption for Shielded VMs COMPUTER ROOM BUILDING PERIMETER S<br>
slide6. Shielded Virtual MachinesWorks with Host Guardian Service Fabric Controller Cloud/Datacenter Hyper-V Host 1 Hypervisor Guest VM Guest VM Guest VM Host OS Hyper-V Host 2 Hypervisor Guest VM Host OS Hyper-V Host 3 Hypervisor Guest VM Host OS Please sir, may I have some keys? Key Protection Host Guardian Service<br>
slide7. Shielded Virtual MachinesWorks with Host Guardian Service Fabric Controller Cloud/Datacenter Hyper-V Host 1 Hypervisor Guest VM Guest VM Guest VM Host OS Hyper-V Host 2 Hypervisor Guest VM Host OS Hyper-V Host 3 Hypervisor Guest VM Host OS Key Protection Host Guardian Service Sure, I know you and you look healthy Key release criteria (TPM-mode)
Known physical machines
Trusted Hyper-V instance
CI-compliant configuration<br>
slide8. Challenges in protecting the OS New exploits can attack the OS boot-path all the way up through applications.
Known and unknown threats need to be blocked without impacting legitimate workloads.<br>
slide9. Help protect the OS and applicationsOn-premises or in any cloud Device Guard
Ensure that only permitted binaries can be executed from the moment the OS is booted.
Windows Defender
Actively protects from known malware without impacting workloads.
Control Flow Guard
Protects against unknown vulnerabilities by helping prevent memory corruption attacks.<br>
slide2. Hosting Challenges Integration with Dev and Ops
Fast and lightweight OS
How to plan for public cloud Looking for cost savings
Need to reduce datacenter footprint
Lack of integration between solutions Cost Efficient Infrastructure Next Generation Application Platform Security Increasing breaches incidents
Identity is target of attacks
Not easy to secure virtual environments<br>
slide3. Next Generation Application Platform Traditional & cloud-native apps
Containers & microservices
Azure Hybrid Use Benefit Built-in compute, storage and network virtualization
Hyper-Converged
Hyper-Scale Azure Inspired, Software Defined Infrastructure Advanced Multi-Layer Security Privileged identity protection
Secure virtualization platform
Breach resistance Presenting Windows Server 2016 The operating system that powers Azure and Your Business<br>
slide4. Hosting Opportunities Use industry-standard hardware to build lower-cost, high density, highly available and scalable storage. Cost Efficient Reliable Storage Secure IaaS Provide higher density and performance for container-based apps and microservices.
Compatible with existing server applications. Platform for Modern Apps Using Windows Server 2016 Prevent and block attacks against virtual machines, applications, and data with layers of protection built into the OS. Achieve cost-savings and flexibility with software-defined compute, storage and network virtualization technologies inspired by Microsoft Azure. Software Defined Datacenter. Establishes new revenue streams with value added services every step of the way<br>
slide5. Secure IaaS (Virtual Machines) Shielded VMUse BitLocker to encrypt the disk and state of virtual machines protecting secrets from compromised admins & malware
Host Guardian Service Attests to host health releasing the keys required to boot or migrate a Shielded VM only to healthy hosts
Generation 2 VM Supports virtualized equivalents of hardware security technologies (e.g. TPMs) enabling BitLocker encryption for Shielded VMs COMPUTER ROOM BUILDING PERIMETER S<br>
slide6. Shielded Virtual MachinesWorks with Host Guardian Service Fabric Controller Cloud/Datacenter Hyper-V Host 1 Hypervisor Guest VM Guest VM Guest VM Host OS Hyper-V Host 2 Hypervisor Guest VM Host OS Hyper-V Host 3 Hypervisor Guest VM Host OS Please sir, may I have some keys? Key Protection Host Guardian Service<br>
slide7. Shielded Virtual MachinesWorks with Host Guardian Service Fabric Controller Cloud/Datacenter Hyper-V Host 1 Hypervisor Guest VM Guest VM Guest VM Host OS Hyper-V Host 2 Hypervisor Guest VM Host OS Hyper-V Host 3 Hypervisor Guest VM Host OS Key Protection Host Guardian Service Sure, I know you and you look healthy Key release criteria (TPM-mode)
Known physical machines
Trusted Hyper-V instance
CI-compliant configuration<br>
slide8. Challenges in protecting the OS New exploits can attack the OS boot-path all the way up through applications.
Known and unknown threats need to be blocked without impacting legitimate workloads.<br>
slide9. Help protect the OS and applicationsOn-premises or in any cloud Device Guard
Ensure that only permitted binaries can be executed from the moment the OS is booted.
Windows Defender
Actively protects from known malware without impacting workloads.
Control Flow Guard
Protects against unknown vulnerabilities by helping prevent memory corruption attacks.<br>