You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/cloud-services/cloud-services-guestos-msrc-releases.md
+43-1Lines changed: 43 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,12 +10,54 @@ ms.service: cloud-services
10
10
ms.topic: article
11
11
ms.tgt_pltfrm: na
12
12
ms.workload: tbd
13
-
ms.date: 12/5/2019
13
+
ms.date: 12/13/2019
14
14
ms.author: raiye
15
15
---
16
16
# Azure Guest OS
17
17
The following tables show the Microsoft Security Response Center (MSRC) updates applied to the Azure Guest OS. Search this article to determine if a particular update applies to the Guest OS you are using. Updates always carry forward for the particular [family][family-explain] they were introduced in.
18
18
19
+
## December 2019 Guest OS
20
+
21
+
>[!NOTE]
22
+
>The December Guest OS is currently being rolled out to Cloud Service VMs that are configured for automatic updates. When the rollout is complete, this version will be made available for manual updates through the Azure portal and configuration files. The following patches are included in the December Guest OS. This list is subject to change.
23
+
24
+
| Product Category | Parent KB Article | Vulnerability Description | Guest OS | Date First Introduced |
25
+
| --- | --- | --- | --- | --- |
26
+
| Rel 19-12 |[4530692]| Windows Security | 2.93 | Dec 10, 2019 |
27
+
| Rel 19-12 |[4530677]| Internet Explorer | 2.93 | Dec 10, 2019 |
28
+
| Rel 19-12 |[4530677]| Internet Explorer | 3.80 | Dec 10, 2019 |
29
+
| Rel 19-12 |[4530698]| Windows Security | 3.80 | Dec 10, 2019 |
30
+
| Rel 19-12 |[4530730]| Windows Security | 4.73 | Dec 10, 2019 |
31
+
| Rel 19-12 |[4530677]| Internet Explorer | 4.73 | Dec 10, 2019 |
Microsoft Azure enables companies to acquire compute and storage resources in minimal time without lengthy procurement cycles. Azure Virtual Machine service allows companies to deploy classical applications, like SAP NetWeaver based applications into Azure and extend their reliability and availability without having further resources available on-premises. Azure Virtual Machine Services also supports cross-premises connectivity, which enables companies to actively integrate Azure Virtual Machines into their on-premises domains, their Private Clouds and their SAP System Landscape.
313
313
This white paper describes the fundamentals of Microsoft Azure Virtual Machine and provides a walk-through of planning and implementation considerations for SAP NetWeaver installations in Azure and as such should be the document to read before starting actual deployments of SAP NetWeaver on Azure.
@@ -325,7 +325,7 @@ With Microsoft Azure Virtual Machine Services, Microsoft offers a comprehensive
325
325
The paper itself focuses on two main aspects:
326
326
327
327
* The first part describes two supported deployment patterns for SAP NetWeaver based applications on Azure. It also describes general handling of Azure with SAP deployments in mind.
328
-
* The second part details implementing the two different scenarios described in the first part.
328
+
* The second part details implementing the different scenarios described in the first part.
329
329
330
330
For additional resources, see chapter [Resources][planning-guide-1.2] in this document.
331
331
@@ -387,8 +387,7 @@ General default limitations and maximum limitations of Azure subscriptions can b
387
387
## Possible Scenarios
388
388
SAP is often seen as one of the most mission-critical applications within enterprises. The architecture and operations of these applications is mostly complex and ensuring that you meet requirements on availability and performance is important.
389
389
390
-
Thus enterprises have to think carefully about which cloud provider to choose for running such business critical business processes on. Azure is the ideal public cloud platform for business critical SAP applications and business processes. Given the wide variety of Azure infrastructure, nearly all existing SAP NetWeaver and S/4HANA systems can be hosted in Azure today. Azure provides VMs with many Terabytes of memory and more than 200 CPUs. Beyond that Azure offers [HANA Large Instances](https://docs.microsoft.com/azure/virtual-machines/workloads/sap/hana-overview-architecture), which allow scale-out HANA deployments of up to 24TB and scale-out ANA deployments of up to 120TB.
391
-
390
+
Thus enterprises have to think carefully about which cloud provider to choose for running such business critical business processes on. Azure is the ideal public cloud platform for business critical SAP applications and business processes. Given the wide variety of Azure infrastructure, nearly all existing SAP NetWeaver and S/4HANA systems can be hosted in Azure today. Azure provides VMs with many Terabytes of memory and more than 200 CPUs. Beyond that Azure offers [HANA Large Instances](https://docs.microsoft.com/azure/virtual-machines/workloads/sap/hana-overview-architecture), which allow scale-out HANA deployments of up to 24TB and scale-out ANA deployments of up to 120TB. One can state today that nearly all on-premise SAP scenarios can be run in Azure as well.
392
391
393
392
In order to successfully deploy SAP systems into either Azure IaaS or IaaS in general, it is important to understand the significant differences between the offerings of traditional outsourcers or hosters and IaaS offerings. Whereas the traditional hoster or outsourcer adapts infrastructure (network, storage and server type) to the workload a customer wants to host, it is instead the customer's or partner's responsibility to characterize the workload and choose the correct Azure components of VMs, storage and network for IaaS deployments.
394
393
@@ -454,6 +453,18 @@ Read [this article][vpn-gateway-create-site-to-site-rm-powershell] for more info
454
453
* SAP applications and releases supported on Azure Virtual Machine Services are documented in SAP Note [1928533].
455
454
* Only 64Bit images are supported to run as Guest VMs in Azure for SAP scenarios. As a result, only 64-bit SAP applications and databases are supported.
456
455
456
+
457
+
## First steps planning a deployment
458
+
The first step in deployment planning is NOT to check for VMs available to run SAP. The first step can be one that is time consuming, but most important, is to work with compliance and security teams in your company on what the boundary conditions are for deploying which type of SAP workload or business process into public cloud. If your company deployed other software before into Azure, the process can be easy. If your company is more at the beginning of the journey, there might be larger discussions necessary in order to figure out the boundary conditions, security conditions, that allow certain SAP data and SAP business processes to be hosted in public cloud.
459
+
460
+
As useful help you can point to [Microsoft compliance offerings](https://docs.microsoft.com/microsoft-365/compliance/offering-home) for a list of compliance offers Microsoft can provide.
461
+
462
+
Other areas of concerns like data encryption for data at rest or other encryption in Azure service is documented in [Azure encryption overview](https://docs.microsoft.com/azure/security/fundamentals/encryption-overview).
463
+
464
+
Don't underestimate this phase of the project in your planning. Only when you have agreement and rules around this topic, you need to go to the next step which is the planning of the network architecture that you deploy in Azure.
465
+
466
+
467
+
457
468
## Microsoft Azure Virtual Machine Services
458
469
The Microsoft Azure platform is an internet-scale cloud services platform hosted and operated in Microsoft data centers. The platform includes the Microsoft Azure Virtual Machine Services (Infrastructure as a Service, or IaaS) and a set of rich Platform as a Service (PaaS) capabilities.
459
470
@@ -1637,8 +1648,6 @@ The cross-premises or hybrid scenario can be roughly described like in the graph
1637
1648
1638
1649
![Site-to-Site connectivity between on-premises and Azure assets][planning-guide-figure-2100]
1639
1650
1640
-
The scenario shown above describes a scenario where the on-premises
1641
-
1642
1651
The minimum requirement is the use of secure communication protocols such as SSL/TLS for browser access or VPN-based connections for system access to the Azure services. The assumption is that companies handle the VPN connection between their corporate network and Azure differently. Some companies might blankly open all the ports. Some other companies might want to be precise in which ports they need to open, etc.
1643
1652
1644
1653
In the table below typical SAP communication ports are listed. Basically it is sufficient to open the SAP gateway port.
0 commit comments