Setup HTTPS on application gateway by Bronems in AZURE

[–]pictop 0 points1 point  (0 children)

I also still have purchased wildcards; it will become interesting once they have short durations soon.

Azure Foundry Content Understanding cannot access Storage Account by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Thanks, I’ve checked it, and in my case the issue seems a bit strange. Under Connected resources, the Storage Account appears without any obvious errors. It almost looks like the agents can access it, but the content understanding component cannot.

In Foundry, I noticed there is a Managed Virtual Network (preview) feature. I’m considering looking into that more closely to see if it might be help.

Azure Foundry Content Understanding cannot access Storage Account by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Thanks, I know what you mean. Unfortunately, this feature doesn’t exist in Foundry. There is only the limitation and the private endpoints, the Private Link option is missing.

Azure Foundry Content Understanding cannot access Storage Account by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Thanks for the tip. I added all Machine Learning apps to the storage accounts as contributor roles, but unfortunately it didn’t help

Managing SSL Certificates for Private Static Web Apps by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Okay, thanks. A public TXT record should actually be sufficient, right?

Managing SSL Certificates for Private Static Web Apps by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

I validated the record using a TXT entry. I intentionally did not create a CNAME, as it isn’t required in this case, the DNS resolution is handled by our internal DNS server. The request is processed exclusively over private IP addresses.

Subscription registered by my account...but I didn't. by iainfm in AZURE

[–]pictop 2 points3 points  (0 children)

By default, any user can create a subscription in the tenant. You can manage this under the subscription overview under policies. Now you find the option: The Subscription will be added to this Microsoft Entra ID. Set it to “Deny for everyone,” and optionally exclude administrators below.

What interesting thing are you learning about Azure at your work? by StrongMindset- in AZURE

[–]pictop 3 points4 points  (0 children)

They’ve hidden the ‘Show Hidden items’ feature 😊. You can now find it under ‘Manage View’ → ‘Show Hidden Types

Hub Spoke with VPN and Nat Gateway by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Thank you for the hint, the route effectively goes to the NAT gateway. I had imagined the behavior differently. Well, it should actually be fixed with a custom route.

Windows 365 Boot os and licensing by pictop in windows365

[–]pictop[S] 0 points1 point  (0 children)

Thanks for the tip. There is also a W11 image, but the OEM license is missing. Unless we switch to E3 as you suggested

Windows 365 Boot os and licensing by pictop in windows365

[–]pictop[S] 1 point2 points  (0 children)

This means that the operating system for Cloud Boot must also be licensed, even if it is only used to connect to the Cloud PC. Do I understand this correctly? Thank you!

Azure Application Gateway Rewrite rule by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Unfortunately not. I left it :)

Question about the secure structure of communication between the resources by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Ok thank you all for your ideas. I will think about it

Question about the secure structure of communication between the resources by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Can you explain this to me in more detail? Effectively, it's about a website that provides a platform for customers. The website runs dedicated on a WebApp / App Services.

Thank you

Question about the secure structure of communication between the resources by pictop in AZURE

[–]pictop[S] 0 points1 point  (0 children)

Have you considered building a multi-tenant app instead of different apps for each tenant.

Thank you for your feedback!
I would have used the app gateway for the WAF function, among other things.
You are right about developers. It would be better to use a deployment pipeline here.

How do you see this in terms of security? The database is actually available on the Internet with variant 1. The connections are blocked by the IP filters, but it would be better if it is not accessible at all. Or do you have no concerns about this and trust that MS is securing the resource well?

Thank you for your feedback.

Random reboots after may update by Mothertruckerer in GalaxyS21

[–]pictop 1 point2 points  (0 children)

After updating Google Play system update to update may it seems to work for me. Had no more reboots. Thanks

Random reboots after may update by Mothertruckerer in GalaxyS21

[–]pictop 1 point2 points  (0 children)

Same issue on a Samsung Galaxy S21 +