Goodbye VPN! Hello Microsoft Global Secure Access

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ต.ค. 2024

ความคิดเห็น • 152

  • @LivingInCloud1
    @LivingInCloud1 9 หลายเดือนก่อน +16

    Very good. I set up Internet Access and blocked Social Media etc. It blocked most sites but not Facebook to my surprise! I then investigated and found that Facebook uses QUIC protocol, which is UDP based. As GSA not yet support UDP, that traffic was let through. It will be there in a future version of the client, but for now this may be good to know.. 🍺🍺
    EDIT: Now it seems to also stop Facebook with the new version of the Client. Cheers!

    • @BillAnt
      @BillAnt 9 หลายเดือนก่อน

      I would never use a VPN which just an aggregate for all your traffic and a target by governments and hackers. Most websites nowadays are already encrypted via HTTS so it's just redundant encryption by a VPN. But hey, to each their own.

    • @LivingInCloud1
      @LivingInCloud1 9 หลายเดือนก่อน +2

      @@BillAnt I think you have misunderstood the product. It's not there for encryption of traffic. It's there for filtering and control of it.

  • @jameslochridge4265
    @jameslochridge4265 9 หลายเดือนก่อน +49

    Seems to me this gives even more access to your info than Microsoft already has and IMO that's too much knowledge.

    • @johnwade7430
      @johnwade7430 9 หลายเดือนก่อน

      OK, thanks.

    • @johnwade7430
      @johnwade7430 9 หลายเดือนก่อน +4

      Without a VPN, China blocks this site so I think I will stick with what I know works:-)

    • @OneAndOnlyMe
      @OneAndOnlyMe 9 หลายเดือนก่อน +3

      It's an interesting point you make. This kind of service gives MS and similar players much insight into how companies govern their employees.

    • @veterantruthtube3298
      @veterantruthtube3298 9 หลายเดือนก่อน

      ​@@johnwade7430no thank you

    • @LivingInCloud1
      @LivingInCloud1 9 หลายเดือนก่อน +4

      If you don't trust your service provider, change provider or run your own service. Easy.

  • @flarestarwingz
    @flarestarwingz 9 หลายเดือนก่อน +12

    I've been trailing the GSAC / Zero trust for a little while now and really liking it. Much more stable than trying to deploy out AOVPN and much finer access controls too.

    • @g0hl
      @g0hl 9 หลายเดือนก่อน +1

      AOV has always been pretty rocky for us... looking forward to trying this out!

  • @MadMadDude
    @MadMadDude 9 หลายเดือนก่อน +3

    IDk, this is complicated and does it really do anything for me that I'm not already doing.. idk.. Thanks and please keep them coming :-)

  • @Harmonee_hues
    @Harmonee_hues 8 หลายเดือนก่อน +1

    Great Job! Thank you Jeremy and Andy ~ 😘

  • @JaniPellikka
    @JaniPellikka 9 หลายเดือนก่อน +14

    And the second he mentioned Entra I thought "Nah, VPN is not going anywhere" ... I get it, it is probably a great solution, but boldly claim VPN is done for is just wrong. Not everyone uses Entra, especially private home users.
    And what happens the day Microsoft has a hickup? Cannot access my own on-prem environment. I rather not put all my eggs in the same basket.

  • @MrPirreE
    @MrPirreE 9 หลายเดือนก่อน +13

    I wish Microsoft could team up with Google and save my privacy and security once for all. 🤣

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      You'd think eh :-)

    • @veterantruthtube3298
      @veterantruthtube3298 9 หลายเดือนก่อน +1

      wishfull thinking. Do you have an eternity?

    • @veterantruthtube3298
      @veterantruthtube3298 9 หลายเดือนก่อน +3

      Absolute power corrupts absolutely, lord Acton

  • @CraigOpie
    @CraigOpie 9 หลายเดือนก่อน +5

    This is a pretty close copy of Twingate. Even called the elements of the technology the same names.

    • @AndrewTSq
      @AndrewTSq 9 หลายเดือนก่อน +3

      Microsoft have never stolen anything before.. Not even Javascript, I mean Microsoft Jscript was something completely different, and that it got the same bugs as the original javascript must just be a coincidence.

    • @deritozgaming
      @deritozgaming 9 หลายเดือนก่อน

      I was going to say the same thing. "Where have I seeen that before". Microsoft is a copycat

    • @henryesparza8663
      @henryesparza8663 6 หลายเดือนก่อน

      twingate has been great so far

  • @1.618Golden
    @1.618Golden 9 หลายเดือนก่อน +3

    Great video, It was hard to follow in a few spots, but I think I understand the major points.

    • @scifibob
      @scifibob 9 หลายเดือนก่อน +1

      We are a small (10k user) municipality with E5 licenses on our main users.
      We are seeing that Microsoft are finding more and more "special" and "premium" licenses, and I can guarantee that our politicians never will agree to these.
      So, will these features be available to our existing clients?
      Microsoft, you do not have a great track record for these exciting changes to be available for existing users/licences.
      In my opinion, our (really expensive) E5 licences are buried down to E3 level over the years. Soon to come close to E1.

  • @iam0ri
    @iam0ri 9 หลายเดือนก่อน +1

    I'd love to hear more about DC-less Entra-authed SMB.

  • @Azarael7002
    @Azarael7002 3 หลายเดือนก่อน

    Love your greeting - reminds me so much of our priest - I mean that in a complimentary manner, he also has such a cheerful, pleasant manner of greeting.

    • @AndyMaloneMVP
      @AndyMaloneMVP  3 หลายเดือนก่อน

      😂🤣 Hehe no one has ever said that before. I’m delighted to have you on board 👍🙂

  • @warmonkey96
    @warmonkey96 8 หลายเดือนก่อน

    Great that it's built into the defender app for mobile. Trouble is it consumes so much battery life as it is now.

  • @michaelmcdonald3275
    @michaelmcdonald3275 9 หลายเดือนก่อน +80

    Microsoft and secure in the same sentence. Pffft.

    • @AndrewTSq
      @AndrewTSq 9 หลายเดือนก่อน +4

      Lol I thought the same thing, so many wierd servers that Windows connects to and do something.. thats why I moved over to Linux now.

    • @fluppi123
      @fluppi123 9 หลายเดือนก่อน +4

      Exactly my thoughts. 👍

    • @dreammix9430
      @dreammix9430 9 หลายเดือนก่อน +3

      Haha NOT!
      I wouldn't trust Microsoft with anything

    • @dimitriyates2701
      @dimitriyates2701 8 หลายเดือนก่อน +1

      Yep. They got over that problem and for the past few years have been making some of the most secure and well integrated prods.

    • @AndrewTSq
      @AndrewTSq 8 หลายเดือนก่อน

      @@dimitriyates2701 and that is why hijacking 365 accounts is popular.

  • @cloudnsec
    @cloudnsec 9 หลายเดือนก่อน +2

    Awesome content Andy! Plus I really appreciate and love the production of the video, it's looking amazing!

    • @iamrahulkarur
      @iamrahulkarur 9 หลายเดือนก่อน

      @andymalonemvp
      What did the speaker, Jeremy use as a Webcam/DSLR/phone, he looks like he was in real.

  • @MarkShell-h4m
    @MarkShell-h4m 8 หลายเดือนก่อน

    We currently use Cisco VPN - just to confirm that GSA could replace that and we would still have same or similar access levels to on premise resources such as file shares, etc.? I guess we will find out really soon as my network engineer wants to setup GSA as a proof of concept.

    • @AndyMaloneMVP
      @AndyMaloneMVP  8 หลายเดือนก่อน

      At the moment I have not personally played a lot with this product. And as you can see it’s currently in public preview so pricing and availability have not yet been confirmed. I apologise that I can’t give you a more definite answer.

    • @laxativee
      @laxativee 7 หลายเดือนก่อน

      We have had GSA in production use already since may-june '23 and to answer your question; yes, GSA will entirely replace the need for a client vpn.

  • @PrinceJohn84
    @PrinceJohn84 9 หลายเดือนก่อน +2

    Great video! Will Entra Private Access replace the traditional Azure Application Proxy going forward?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน +1

      As I believe the web app, proxy service will remain as a standalone feature, but has been for Intune

  • @TayschrennSedai
    @TayschrennSedai 9 หลายเดือนก่อน +1

    When are our Server Licenses going to be less expensive to renew SA on, now that they're removing any doubts in our minds that ANY R&D is happening in on premises software? RRAS is dead. But we still pay for it, along with all the other software they've pushed new versions of to the cloud (Azure Files replacing DFS-R, etc) - it's extremely annoying paying them boatloads for SA when they're not actually providing what they did when we bought Server originally.

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      No news on licensing yet I’m afraid.

    • @TayschrennSedai
      @TayschrennSedai 9 หลายเดือนก่อน

      @@AndyMaloneMVP probably because there won't be. Why would they drop pricing that enterprises currently pay without a second thought in their Enterprise Agreement renewals, PLUS continue to add more opex 🤣
      It's just really unfortunate that what we once got for licensing is now less. Imho, things like paying for System Center should get you Azure credits as well, especially if it's like getting access to this sort of technology. It's an extension of the product set.

  • @roythomason1921
    @roythomason1921 9 หลายเดือนก่อน +4

    Can't see myself trusting cloud-based security.

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน +3

      It’s way better than on prem

  • @62128Kevin
    @62128Kevin 9 หลายเดือนก่อน +2

    Hello and happy new year,
    If I understand well, the file server was installed in Windows Server On-Premise machine, the device to access this file server is not domain joined but only AzureAD join.
    My question is: how did you manage NTFS permission for AzureAD user to access to the different shares ? Did you need to enable security group writeback to get the group on your On Premise Active Directory and assign it on the share and give the appropriate NTFS permission or there is another way to do it please ?
    Regards.

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน +1

      Interesting question. In relation to NTFS, whatever permissions you set locally, will waterfall downwards. Group Writeback only works if you have hybrid enter ID, and in this case is unnecessary. This is yet another layer that Microsoft are adding into it in tune technologies that will make the need for active directory, unnecessary

  • @expatph
    @expatph 8 หลายเดือนก่อน

    Great content, thank you. Philippines

  • @kb8570
    @kb8570 5 หลายเดือนก่อน

    This is amazing but I have heard this is going to be very expensive. It will not be included as part of the E5 license.

    • @AndyMaloneMVP
      @AndyMaloneMVP  5 หลายเดือนก่อน

      No details as of yet I’m expecting not I suspect it may be an extra cost, let’s wait and see though.

  • @dave24-73
    @dave24-73 9 หลายเดือนก่อน +3

    How does check address work if you are on the road a lot? Looks like way too much effort. It’s clear Microsoft just wants everyone on their cloud platform. I would do anything to avoid this if given a choice.

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Remember this is a corporate solution which can be managed by your IT. This is not a personal feature.

    • @dave24-73
      @dave24-73 9 หลายเดือนก่อน +1

      @@AndyMaloneMVP I appreciate this, but having everything in the cloud although makes life easier, it also locks you in pretty badly, and often charges go up, I personally would limit cloud services where possible. I was thinking more about sales reps, consultants etc who travel a bit.

  • @OneAndOnlyMe
    @OneAndOnlyMe 9 หลายเดือนก่อน +1

    Very interesting. How does it work though with file shares that are controlled through on-prem AD groups if there's no on-prem domain auth?

  • @o12jordan
    @o12jordan 9 หลายเดือนก่อน +1

    Is this the new "Direct Access"? Interesting.

  • @exmuslimstv-308
    @exmuslimstv-308 9 หลายเดือนก่อน

    2 ways to access conditional access - one from devices and another one from Endpoint security
    and each one has different functions

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Actually, they’re the same tools

  • @maulwurf62
    @maulwurf62 9 หลายเดือนก่อน +1

    I just want to know if this means I can watch the NFL when I‘m in Europe! 😃

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      No it’s not intended for that

  • @brokebrolife5132
    @brokebrolife5132 9 หลายเดือนก่อน +1

    Does Group Policy work over this? VPN gives you GP but Sophos ZTNA we are using doesnt give us Group Policy so its not a direct replacement of VPN :(

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Intune provides an equivalent service

  • @maheshdesilva2308
    @maheshdesilva2308 9 หลายเดือนก่อน

    Love private access. fingers crossed the licensing is announced soon. Any options for machine that are only azure ad registered?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน +1

      I’m sure these will be added in to conditional access policies

  • @rangiz99
    @rangiz99 9 หลายเดือนก่อน +3

    Any idea on price?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Not yet I'm afraid.

    • @MrMarcLaflamme
      @MrMarcLaflamme 9 หลายเดือนก่อน +4

      This is the first thing I always look for when I see these new products because for us price is almost always the primary driver. If it's going to cost us more than we can afford, I won't bother wasting my time and energy digging into it more. Unfortunate to not have this information available. If they don't have a per user cost but know it'll be included in existing SKU's (eg E3/5, Business Premium, etc) then at least state that.

    • @12Burton24
      @12Burton24 9 หลายเดือนก่อน +1

      Price: Money AND your Privat Datas free to MS including all your picture datas they will say its in the name of fighting crime/criminals but i tell you its not they are not the police.

    • @michaelgomez3238
      @michaelgomez3238 9 หลายเดือนก่อน +3

      This. Need to have pricing when demonstrating products. Can’t assess value of technology unless the costs are known. Demonstrating without pricing might generate awareness but really is a waste of time when we try our best to be informed buyers. We have similar SSE solutions from Palo Alto. We have E5 and MDE and MDfCA. I’m renewing my Palo Alto solutions.

  • @IamHere2007de
    @IamHere2007de 6 หลายเดือนก่อน

    Should GSA appear automatically within the defender app on iOS? I was not able to find Microsoft documentation about the iOS client setup - only Windows and Android is available.

    • @AndyMaloneMVP
      @AndyMaloneMVP  6 หลายเดือนก่อน

      Still in preview so some features may not be 100%

  • @marcoapdantasify
    @marcoapdantasify 8 หลายเดือนก่อน

    Really cool stuff !

  • @skeginaldp1533
    @skeginaldp1533 9 หลายเดือนก่อน

    Well done.

  • @andrerobitaille982
    @andrerobitaille982 9 หลายเดือนก่อน

    Does this is more like Easy access to the NSA? I suggest targeting more efficiently.

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Don’t be silly

  • @imtithewave
    @imtithewave 9 หลายเดือนก่อน

    Hey Andy, you are Superb.

  • @saqiazam
    @saqiazam 9 หลายเดือนก่อน

    Can I use it as a replacement for my current firewall?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      It’s not a firewall. But has firewall elements

  • @driver288
    @driver288 9 หลายเดือนก่อน

    Hmm. That SMB share access does require Kerberos cloud trust to be set up first too, right? Or is that built into this service now?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Ping Jeremy on that one :-)

    • @DeployJeremy
      @DeployJeremy 9 หลายเดือนก่อน +1

      There is still a domain on premises with DCs for the domain joined servers like we showed with the fileshare and Hyper-V server. The user's device however doesn't need to be domain joined or hybrid joined for this to work. It's issued the tickets needed after the conditional access challenge by the Private Access cloud service with gateway connector in place.

    • @martinzonderland1543
      @martinzonderland1543 9 หลายเดือนก่อน +2

      @@DeployJeremy is this already working, because I'm testing from a EntraID Joined system to connect to SMB file share, but seems to be not receiving Kerberos ticket at this moment, access denied... Is it also working in combination with Windows Hello for Business? At this moment I receive a popup with Windows Hello PIN, after that access denied to fileshare... I see in logging it's trying to connect with the fileshare.... Or do I have to wait for future release?

    • @DeployJeremy
      @DeployJeremy 8 หลายเดือนก่อน

      @@martinzonderland1543 It is already possible, but needs to be documented for implementation as it moves toward general availability. Documentation is in the works now, but no ETA yet for publishing.

  • @ao4514
    @ao4514 8 หลายเดือนก่อน

    It's a mouth full!

  • @pleasuredome11
    @pleasuredome11 9 หลายเดือนก่อน +1

    I use VPN for hiding IP in foreign countries as I travel most of the year. VPN under pressure with TV corps blocking software to prevent viewing, unstable. Frustrating. How could this replace my nerd for VPN, simple basic nerd I am done with VPN imstability

    • @jeschinstad
      @jeschinstad 9 หลายเดือนก่อน +3

      You mean that you use some commercial VPN service that is well-known and blocked by streaming services? You can run your own VPN service at home so that you have access to all your local things on your network and then nobody in the world can tell that you're not home. They won't be able to block you, because from a technical point of view, you are home.

  • @fareast20
    @fareast20 9 หลายเดือนก่อน

    Will this allow access to azure file share without azurevpn and be able to mount it like a local drive?

  • @SHSolutions
    @SHSolutions 9 หลายเดือนก่อน

    Is there an access client for Linux available too?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน +1

      Yes coming shortly👍

  • @SnaxMuppet
    @SnaxMuppet 9 หลายเดือนก่อน +1

    And you think this is simpler than a VPN?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Wait till you see Internet access feature coming soon

  • @PyrateGraphics
    @PyrateGraphics 9 หลายเดือนก่อน +2

    how does anything with Microsoft in its name get remotely associated with Security lol

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      Don’t think of yourself personally, watch the video fully and you’ll understand

    • @PyrateGraphics
      @PyrateGraphics 9 หลายเดือนก่อน

      @@AndyMaloneMVP I did, no thanks

  • @greglipschitz
    @greglipschitz 9 หลายเดือนก่อน

    Is this available for Linux machines?

  • @johnwade7430
    @johnwade7430 9 หลายเดือนก่อน +1

    Will this work in China?????

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      No idea sorry

    • @johnwade7430
      @johnwade7430 9 หลายเดือนก่อน

      Trouble, Microsoft do cave into China’s demands. The company’s Web browser is a case in point. So I doubt myself whether this would be at all useful.

  • @demoncoco1386
    @demoncoco1386 8 หลายเดือนก่อน

    How to use it

  • @Ahmedaljawad
    @Ahmedaljawad 9 หลายเดือนก่อน

    Does it support the management tunnel when the user is not logged in to the window ? That was the limitation on direct access where we cant remote manage laptops when the users are away

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      At present I'm not up to date with the exact technical details. Please checkout the links in the video as well as learn.microsoft.com

  • @texasboys101
    @texasboys101 8 หลายเดือนก่อน

    VPN not going anywhere people like different things

  • @KeithGadget
    @KeithGadget 8 หลายเดือนก่อน +1

    All at an extra per user subscription cost. Cost that keep increasing and where MS keep moving the goalposts. Naaaaaaaaahhhhh I’ll pass thanks

  • @MD-gc4xq
    @MD-gc4xq 9 หลายเดือนก่อน +5

    Trust Microsoft?! Your having a laugh aren’t you?

  • @chrisdavis9848
    @chrisdavis9848 9 หลายเดือนก่อน

    Is this the new Azure App Proxy? What licenses are required for this?

  • @driver288
    @driver288 9 หลายเดือนก่อน

    Hmm. An app on-prem protected by a conditional access policy… a web app in this case no less. Sounds an awful lot like application proxy… what’s the upside to using that here?

    • @AndyMaloneMVP
      @AndyMaloneMVP  9 หลายเดือนก่อน

      App Proxy is now integrated in to CA

    • @driver288
      @driver288 9 หลายเดือนก่อน

      @@AndyMaloneMVP You still need the agent on-premise i guess?

  • @charles603
    @charles603 9 หลายเดือนก่อน +1

    Microsoft and security does not go together!

  • @obaidullahnoori7066
    @obaidullahnoori7066 9 หลายเดือนก่อน

    More money to charge !!!

  • @12Burton24
    @12Burton24 9 หลายเดือนก่อน +9

    Microsoft is not even able to make encryption where you cant read out the key of the SSD/HDD. So why should i trust MS?😂

    • @b3at2
      @b3at2 9 หลายเดือนก่อน

      You trust their 2 factor authentication dont you?

    • @12Burton24
      @12Burton24 9 หลายเดือนก่อน

      @@b3at2 do they have one 😂🤣

    • @laxativee
      @laxativee 7 หลายเดือนก่อน

      So youve seen the scriptkiddy youtube video? Old news, it has already been fixed years ago, lazy admins just havent enabled the boot up PIN-codes..

    • @12Burton24
      @12Burton24 7 หลายเดือนก่อน

      @@laxativee scriptkiddy?never heard about that one

  • @77pontoon
    @77pontoon 8 หลายเดือนก่อน

    don't think so !