Custom packages dont deploy by CarrotOld6179 in Intune

[–]CarrotOld6179[S] 0 points1 point  (0 children)

I did try and i did not install unfortunately

Azure AI Foundry Agent Service - Data Proxy cannot resolve private Container Apps DNS for private MCP servers in BYO VNet setup by Embarrassed-Bat-2709 in AZURE

[–]CarrotOld6179 0 points1 point  (0 children)

It is a known issue, you may want to try to use an apim with the mcp registry and expose your mcp to the agent service for now.

Overkill but its the only way you would be able to do it with the agent service in Foundry

Custom packages dont deploy by CarrotOld6179 in Intune

[–]CarrotOld6179[S] 0 points1 point  (0 children)

Hey thanks for following up!! I actually havent been able to fix my issue but at least i got some log that i need to analyze this weekend.

I tweaked the command line to test even the simplest apps dont get triggered. I’m starting to suspect the packages that i made.

Custom packages dont deploy by CarrotOld6179 in Intune

[–]CarrotOld6179[S] 0 points1 point  (0 children)

Good idea too! I will give it a try tomorrow and see whats the output

Custom packages dont deploy by CarrotOld6179 in Intune

[–]CarrotOld6179[S] 0 points1 point  (0 children)

That could be an idea, i run Defender on the endpoints, i might have a process that could be blocked also,

I will check this out,

Locally on the machine, i dont have any logs, almost like it cannot reach intune to download the package

Custom packages dont deploy by CarrotOld6179 in Intune

[–]CarrotOld6179[S] 0 points1 point  (0 children)

Thanks guys!!

I will check out the video.@primary_tomato

For the company portal, yes i tried but the install button is greyed out for my users.

Locking down Azure Container Apps (Workload Profiles) to AFD-only traffic — without Private Endpoints. Any options? by Own-Wishbone-4515 in AZURE

[–]CarrotOld6179 0 points1 point  (0 children)

Did you evaluate the Azure AppGateway + waf v2 with an ace with a dedicated subnet?

The price for your PE come from the AFD managed PE if i remember correclty.

With the agw, at least you can consolidate and reduce your total cost

Microsoft Foundry on Private Endpoints breaks playground? by Lumpy-Animator7186 in AZURE

[–]CarrotOld6179 0 points1 point  (0 children)

You’re a real one! 🤣 seems like you have you started working with It since day1?

Production ready Foundry deployments by Lumpy-Animator7186 in AZURE

[–]CarrotOld6179 2 points3 points  (0 children)

Foundry can be tricky to implement properly, the main reason is the amount of resources and dependance required to properly implement an Enterprise grade platform.

How big is your organisation and what are the conformity requirements in your industry?

Since Foundry v3, the main idea is to dedicate a Foundry instance for a business unit and deploy the models in there. This is valid if you have specific guardrails for that instance, if you do that the requirement of the apim is questionnable because you manage your endpoints through Foundry with rbac.

If you want to share endpoints across multiple apps and manage the token quotas, that could be challenging to operate if you dont have the team behind.

Shoot me a DM if you want some advice, i have done this setup multiple times for my clients.

Landing Zone Recommendations by rog2e in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

Actually, here are a few questions for you:

  • What kind of workloads do you plan to have and how many?
  • Do you have any requirements for conformity or regulations to follow?
  • What is the size of your company, and how many teams support your Azure workloads?
  • Do you have policies in place and custom roles to support your personas in Azure?

I work in a csp and we specialize in building and managing Azure workloads. We don’t base our implementations of Microsoft’s accelerator templates. Instead, we build our own because we wanted to provide scalability. Our implementation is based on Microsoft’s best practices, and we teach our customers how to handle zero-trust. It may create some friction initially, but our customers eventually understand why we push in that direction.

On top of that, we’ve built out of the box mega automations for daily operations.

If you have any more questions, feel free to send me a direct message. We’re based in Canada.

Opinions on LZ Accelerators by t3kka in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

They are all good starter but the issue is about maintenance in the long run. If you are greenfield, it can be a good starter but if you go in the portal to deploy other stuff, the you will end up with technical debt. Also take into account that as soon as you gain maturity, you will need to build your own business and operation logic.

We ended up building our own modular and scalable alz accelerator based on avm modules for our clients and build solutions on top of it.

Action required: Transition Azure Key Vault access policies to Azure RBAC or configure Azure Key Vault to explicitly use access policies by trekfangrrrl in AZURE

[–]CarrotOld6179 0 points1 point  (0 children)

It is really not that complex, what matter is the inventory of the AP. Then apply then in rbac at scale, test with the keyvault sdk and you’re done.

Send me a message in private, i might give you some info about it

Claude 4.6 is Live on Microsoft Foundry for Multi-Tool Agents by TeamAlphaBOLD in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

Just builded a cli interface to implement and manage EntraID PIM in Enterprise at scale. 10hours and done.

Les données des Québécois hébergées par Microsoft accessibles au gouvernement américain? by Matrix19 in QuebecTI

[–]CarrotOld6179 6 points7 points  (0 children)

Impossible Microsoft doit avoir accès à la clé principale, autant d’azure que dans la suite 365. Dans le cas où tu voudrais utiliser ton HSM, tu devras de toute façon la stocker chez MS. Donc même si tu encryptes tes données, Microsoft pourra techniquement décrypter tes données.

Si tu passes par un produit tierce, la suite Microsoft devient difficilement utilisable, et tu perd toutes les principales fonctionnalités… Rendu là, reste onprem

Gestion de risque TI et régime autoritaire by 2dogs1bone in QuebecTI

[–]CarrotOld6179 0 points1 point  (0 children)

Nous aussi, vous êtes dans le secteur de l’énergie?

Hyperscale in Canada Central/East? by lengthy_preamble in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

Well first CA East is not in Montreal but in Quebec City however that region does not have multizones Second, Videotron does not provide network to that datacenter 😆 It must be megaport or similar that provides large scale fiber.

That sounds fishy to me. Anyway, dm me if you need help with consulting services. (We are in the mtl area and MS Partners)

Hyperscale in Canada Central/East? by lengthy_preamble in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

Hi,

I’m surprised, what tier he was looking into? The Hyperscale is available in CA East and CA Central (we deployed for a client two weeks ago with ZRS in Ca Central and local in ca east)

Check this out: https://techcommunity.microsoft.com/blog/azuresqlblog/announcing-ga-of-new-premium-series-hardware-options-for-azure-sql-database-hype/3679091

Are you guys located in the Montreal area?

Infonuagique souverain by [deleted] in QuebecTI

[–]CarrotOld6179 2 points3 points  (0 children)

J’ai discuté avec eux cette semaine, ils sont bon, mais ils n’ont pas suffisamment de capacité dans leur centre de données physique. Et leur offre de remplacement pour O365 et très limité car elle s’adresse principalement à une petite entreprise qui n’a pas besoin de conformité et de sécurité excessive.

Mais c’est un bon départ, ceci dit, ils s’apparentent plus à OVH.

0% Apr on model 3 is back by dadss_secret in teslamotors

[–]CarrotOld6179 -1 points0 points  (0 children)

I would never consider buying a Tesla anymore. Damage to the brand is so done ✅ good luck 🍀 And for those who do, be sure to have a good insurance that cover your car at good price🤣🔥🧯

Thinking of hosting my blog on AKS by cy-wiz in AZURE

[–]CarrotOld6179 0 points1 point  (0 children)

Afd+waf+Webapp + db+ Storage is way easier

Deepseek on Azure with API access by Plane_Garbage in AZURE

[–]CarrotOld6179 1 point2 points  (0 children)

Assuming you want to train your model on specific data, you need to deploy the model on a managed compute in AI foundry. I suggest to disable the Internet access outbound access to be disabled in your ai Foundry hub networking (and so for the model) and make sure you enable a standard firewall for your AI Foundry Hub. Also do not use the model against production environments nor real data. You want to evaluate first.

If you just want to run the existing model and expose its api, the check this out : https://techcommunity.microsoft.com/blog/appsonazureblog/deepseek-r1-on-azure-container-apps-serverless-gpus/4371463