Matt McKenzie
Matt McKenzie
  • 14
  • 35 141
Azure AD - Enterprise Application Proxy - VMWare VCenter Example
Setting up an Azure AD Enteprise Application Proxy to use to access VCenter securely without port forwarding or VPN.
Requirements
1. Certificate from a public certificate authority
2. Internal DNS Entry / Host File Entry on App Proxy Agent Server
3. Windows Server 2012 R2 or Better for Application Proxy Agent installation
4. (Optional) Custom Domain Name with access to modify the public DNS
Prework for specifically VCenter...
Discovered VCenter really doesn't like wildcard certificates. Make sure you set your internal host name for VCenter first, create your CSR in VCenter, complete the process with your .crt renamed to .cer extension and the same for the intermediate certificate. This will require your VCenter to be offline temporarily while the services restart. Create your internal DNS entry to match your custom host name.
How to:
1. Go to entra.microsoft.com / aad.portal.azure.com
2. Go to Applications / Enterprise Applications
3. New Application then Create your own Application
4. Give it a Name then Set Configuration Application Proxy for Secure Remote Access to an On-Premise Application
5. Enter in the internal URL for the application
6. Enter the desired external URL for the application
7. Click Create
8. Go back to Enterprise Applications then Application Proxy
9. Download the agent and install on Windows Server 2012 R2 or Newer
10. Sign in using a Global Administrator account to associate it with your tenant
11. Go back to your Enterprise Applications and find the application you create.
12. Upload the PFX with secret (password) for the exported certificate
13. Set access using the Users & Groups section above the Application Proxy side bar navigation
14. Test with a user account you added on an outside connection (smart phone, no Wi-Fi)
15. Verify you are required to use Azure AD to sign in if you're using the pre auth for Azure AD
learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy
มุมมอง: 1 424

วีดีโอ

Azure - MFA for NPS
มุมมอง 11Kปีที่แล้ว
We're installing and configuring the Azure MFA for NPS configuration. We aren't going over the NPS setup because we're assuming you have that setup already and working in production. You'll have some prereqs to make sure you have completed in order for this to work properly. 1. Azure AD Connect with users sync'd 2. Proper Licensing (AAD P1 / P2 / Enterprise Mobility 3. Working NPS setup 4. User...
Azure Virtual Desktop (AVD) - Host Pool Setup, Workspace Setup, and App Group Creation
มุมมอง 5Kปีที่แล้ว
We cover setting up a new workspace, host pool setup, and the app group setup for both desktop app group and remote app group.
Azure Virtual Desktop (AVD) Image Creation
มุมมอง 5Kปีที่แล้ว
This video is about creating a Microsoft Azure Virtual Desktop Image to use for personal or pooled desktops. Typically we'd use Windows 10 or Windows 11 for this. We'll first take a market place image to get the multi session part of the image. Then we'll install Office 64 bit with shared activation & no updates, FSLogix for profile management, OneDrive Per Machine Install, and Teams Per Machin...
Azure Azure VPN Gateway Setup for Point to Site
มุมมอง 1084 ปีที่แล้ว
Azure Azure VPN Gateway Setup for Point to Site
Azure Migrating On Prem Hyper V Virtual OS Disk to Azure and Creating a VM in Azure
มุมมอง 2.6K4 ปีที่แล้ว
Azure Migrating On Prem Hyper V Virtual OS Disk to Azure and Creating a VM in Azure
Azure Backup On Premise MARS Agent File Recovery
มุมมอง 1.7K4 ปีที่แล้ว
Azure Backup On Premise MARS Agent File Recovery
Azure Backup On Premise Server Backing up with the MARS Agent
มุมมอง 7K4 ปีที่แล้ว
Azure Backup On Premise Server Backing up with the MARS Agent
Windows Server 2019 Adding a Second DC
มุมมอง 2054 ปีที่แล้ว
Windows Server 2019 Adding a Second DC
Windows Server 2019 Demoting a Domain Controller
มุมมอง 984 ปีที่แล้ว
Windows Server 2019 Demoting a Domain Controller
Windows Server 2019 Installing Windows Server Core and promoting to DC
มุมมอง 1944 ปีที่แล้ว
Windows Server 2019 Installing Windows Server Core and promoting to DC
Windows Server 2019 Initial Install on Hyper V Server
มุมมอง 284 ปีที่แล้ว
Windows Server 2019 Initial Install on Hyper V Server as a VM
Windows Server 2019 VM Installing Active Directory Domain Services and DNS
มุมมอง 1094 ปีที่แล้ว
Windows Server 2019 VM Installing Active Directory Domain Services and DNS on a Windows Server Hyper V
Windows Server 2019 Active Directory Organizational Unit Setup
มุมมอง 824 ปีที่แล้ว
Windows Server 2019 Active Directory Organizational Unit Setup

ความคิดเห็น

  • @RoiRetulla-r7o
    @RoiRetulla-r7o หลายเดือนก่อน

    Hi, what if I created a virtual machine first instead of the workspace, how do I add that virtual machine in there and transfer it to the newly created workspace

  • @geeksified
    @geeksified 6 หลายเดือนก่อน

    When I add Azure AD User, do they need to have an azure account though? I'm confused on that part. I just want my team to have access to multi-session vm without an azure account. How can I add an azure AD User on that part? Thanks!

  • @ccc778811
    @ccc778811 7 หลายเดือนก่อน

    vsphere 8.0u2 new feature th-cam.com/video/6TnyEDr0yQM/w-d-xo.htmlsi=CtFGE6O7IfZ9RUaA

  • @aniloy83
    @aniloy83 8 หลายเดือนก่อน

    The video is not clear. Seems recorded from a mobile

  • @deathcard2003
    @deathcard2003 11 หลายเดือนก่อน

    I just wanted to thank you for this, configuring Azure AD for vCenter and this video was invaluable.

  • @axeldelloni2550
    @axeldelloni2550 ปีที่แล้ว

    Hi, Thanks for the demo, is it possible to pass the credentials to the vcenter so as not to enter credentials twice?

    • @lee161a
      @lee161a 3 หลายเดือนก่อน

      VMWare 8 supports Entra ID Natively. VMWare 7 can use Entra ID's oidc v1 endpoints, and LDAP. You shouldn't expose either version to the internet, as your risk getting zero day'd. VMware 7 exposes it's PowerCLI/API interface on HTTPS, and it uses the older ADAL libraries for authentication (aka single factor auth only, unless you use an LDAP MFA Proxy)

  • @exlr8in
    @exlr8in ปีที่แล้ว

    Hey Matt Great Videos Thanks! Hey would you have cliff notes for Azures upgraded GUI and also when i attempt to somewhat follow the steps (because the Azure GUI is updated), i am asked to download\install MAPS vs. MARS. Thoughts?

  • @jesseniaalvarenga9468
    @jesseniaalvarenga9468 ปีที่แล้ว

    Thank you so much! I had done this step by step but my vhd got messed up so I figured it would be better to rebuild than trying to troubleshoot (since I spent a lot of time troubleshooting). This saved me so much time when I needed it. I ran across the error "Cannot install for all users when a VDI environment is not detected" when installing Teams but was able to fix by using the following: # create registry key and value for WVDEnvironment New-Item -Path "HKLM:\SOFTWARE\Microsoft" -Name "Teams" -Force New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Teams" -Name "IsWVDEnvironment" -Value 1 -Force

  • @bigfatbonus
    @bigfatbonus ปีที่แล้ว

    Thank you for the great explanation and demo! I see you installed the Application Proxy Connector on the server where you already have the AAD Connect running. Do you see any problem running them on the same machine in the production environment?

  • @samibenlaribi2565
    @samibenlaribi2565 ปีที่แล้ว

    Perfect, Great Work, but the Vm created from captured image retain old hostname, did you have any idea ? Thanks

  • @GopalakrishnanN
    @GopalakrishnanN ปีที่แล้ว

    Hi Can I know the user issue? Since am also the facing the same problem. Thank you.

    • @MattMcKenzie13
      @MattMcKenzie13 ปีที่แล้ว

      I have Azure AD Connect setup for hybrid identity. I assigned a cloud only user for a domain joined machine so I had to get them added in to sync them.

  • @ericabardu
    @ericabardu ปีที่แล้ว

    great work!

  • @mikesand6495
    @mikesand6495 2 ปีที่แล้ว

    Hi Matt. Thank you for a great video. Do you by any change know how to generate an incremental backup using the MARS agent? On MS Docs they point to the schedule setup, but I see no options to change that there. Also, some of the documentation I have read suggests that this should be done on the vault in Azure Portal. I have the same setup as you do in the video, onprem backup to Azure. Should I first initialize a full backup and after that, on the Portal, create the incremental backup?

    • @MattMcKenzie13
      @MattMcKenzie13 2 ปีที่แล้ว

      Hey Mike, Azure Backup MARS agent should only be uploading the files that have been changed. It doesn't do a full backup every time.

  • @wongkawang2483
    @wongkawang2483 2 ปีที่แล้ว

    thanks for the demo video, is it possible to use MARS back up a on-premise server that NOT connect to the Internet?

    • @MattMcKenzie13
      @MattMcKenzie13 2 ปีที่แล้ว

      Hey Wong, I don't believe so since Azure Backup has to connect up to Azure Recovery Services Vault to upload the VHD. Veeam maybe a better option for the air gapped system.

  • @Riya-nz4xq
    @Riya-nz4xq 2 ปีที่แล้ว

    Can I enable win 2019 server backup which will store to azure blob storage?

    • @MattMcKenzie13
      @MattMcKenzie13 2 ปีที่แล้ว

      Hey Riya, it'll go to the Azure Recovery Services vault which will have some retention policy on it. If you need to do a snapshot to blob storage though, you could look into doing AzCopy.exe to upload files from the Server 2019 VM into an Azure Storage Blob after creating a SAS URL and giving permissions.

  • @austinzamora4736
    @austinzamora4736 2 ปีที่แล้ว

    If you use azure for a let’s say a file server that runs win server 2019, it should keep the ntfs permissions right ?

    • @austinzamora4736
      @austinzamora4736 2 ปีที่แล้ว

      For the backing up the file server on premises

    • @MattMcKenzie13
      @MattMcKenzie13 2 ปีที่แล้ว

      @@austinzamora4736 It does backup the NTFS permissions but you have the option to restore without. docs.microsoft.com/en-us/azure/backup/backup-azure-file-folder-backup-faq#does-the-mars-agent-back-up-and-restore-acls-set-on-files--folders--and-volumes-

    • @austinzamora4736
      @austinzamora4736 2 ปีที่แล้ว

      @@MattMcKenzie13 thank you!