Posted on Leave a comment

Considering a career in cybersecurity? Baseline tools can give you a quick start

I wrote a series of blogs last year on how gamified learning through cyber ranges can create more realistic and impactful cybersecurity learning experiences and help attract tomorrow’s security workforce. With the global talent shortage in this field, we need to work harder to bring people into the field. This blog is for new cyber professionals or perhaps younger aspirants considering getting into cyber. From an employee’s perspective, it can seem daunting to know where to start, especially when you’re entering an organization with established technology investments, priorities, and practices. Having come to this field later in my career than others, I say from experience that we need to do a better job collectively in providing realistic and interesting role-based learning, paths toward the right certifications and endorsements, and more definitive opportunities to advance one’s career.

I’m still a big fan of gamified learning, but if gaming isn’t your thing, then another way to acquire important baseline learning is to look at simpler, more proactive management tools that up-level different tasks and make your work more efficient. Microsoft has recently released two important cloud security posture management tools that can help a newer employee quickly grasp basic yet critically important security concepts AND show immediate value to your employer. They’re intuitive to learn and deserve more attention.  I’m talking about Azure Security Defaults and Microsoft Secure Score (also including Azure Secure Score). While tools like these don’t typically roll off the tongue, and your experience won’t grab you like an immersive gaming UI, their purpose-built capabilities that focus on commonly-accepted cyber hygiene best practices reinforce solid foundational practices that are no less important than SecOps, incident response, or forensics and hunting. Learning how to use these tools can make you a champion and influencer, and we encourage you to learn more below. These capabilities are also built directly into our larger Azure and M365 services, so by using built-in tools, you’ll help your organization maximize its investments in our technologies and help save money and reduce complexity in your environment.

Azure Security Defaults is named for what it does—setting often overlooked defaults. With one click, you automatically enable several foundational security controls that if left unaddressed are convenient and time-tested targets for attackers to go after your organization. One question that I frequently receive is why Microsoft doesn’t simply pre-configure these settings by default and force customers to turn them off. Several large, high-threat customers have asked specifically that we do that. It’s tempting, but until or unless we make such a move, this is a great self-service add-on. As explained in this blog, ASD does the following:

  • Requires all users to register for Azure Multi-Factor Authentication.
  • Requires admins to perform MFA.
  • Blocks legacy authentication protocols.
  • Requires users to perform MFA when necessary.
  • Protects privileged activities to access the Azure Portal.

A recent important addition to ASD is that Microsoft announced on August 12th that ASD is now also available through Azure Security Center. This is an important and beneficial addition in that it adds another opportunity for your IT organization—whether identity and access management, or security operations—to implement the defaults. I’ve noticed on several occasions when briefing or providing a demo on Azure Security Center to a CISO team that a challenge in effectively using this service may come down to organizational issues, specifically, Who OWNS it?  Is ASC a CISO tool? Regardless of who may own the responsibility, we want to provide the capability upfront.

MICROSOFT SECURE SCORE is a relatively new feature that is designed to quantify your security posture based on how you configure your Microsoft resources. What’s cool and impactful about it is that it provides in a convenient top-down meu approach the relative approach your organization has taken compared (anonymously) with your industry segment’s peers (given in many cases similar reference architectures), and provides clear recommendations for what you can do to improve your score. From a Microsoft perspective, this is what we’d say all carrot and no stick. Though as covered above we provide Azure Security Defaults, customers are still on point to make a proactive decision to implement controls based on your particular work culture, compliance requirements, priorities, and business needs. Take a look at how it works:

This convenient landing page provides an all-up view into the current state of your organization’s security posture, with specific recommendations to improve certain configuration settings based on an art-of-the-possible. In this demo example, if you were to turn enable every security control to its highest level, your score would be 124, as opposed to the current score of 32, for a percentage of 25.81. Looking to the right of the screen, you get a sense of comparison against peer organizations. You can further break down your score by categories such as identity, data, device, apps, and infrastructure; this in turn gives a security or compliance team the opportunity to collaborate with hands-on teams that control those specific resources and who might be operating in silos, not necessarily focused on security postures of their counterparts.

An image of Microsoft Secure Score.

Azure Secure Score

You’ll also find Secure Score in the Azure Security Center blade where it provides recommendations front and center, and a color-coded circular graph on important hybrid infrastructure configurations and hygiene.

An image of Secure Score in the Azure Security Center.

Drilling deeper, here we see a variety of recommendations to address specific findings.  For example, the top line item is advice to ‘remediate vulnerabilities’, indicating that 35 of 59 resources that ASC is monitoring are in some way not optimized for security. optimized for security.

An image of variety of recommendations to address specific findings.

Going a level further into the ‘secure management ports’ finding, we see a sub-heading list of actions you can take specific to these resources’ settings. Fortunately, in this case, the administrator has addressed previously-discovered findings, leaving just three to-do’s under the third subheading. For added convenience, the red/green color-coding on the far right draws your attention.

An image of the ‘secure management ports’ finding.

Clicking on the third item above shows you a description of what ASC has found, along with remediation steps.  You have two options to remediate:  more broadly enable and require ‘just in time’ VM access; or, manually enable JIT for each resource. Again, Microsoft wants to incentivize and make it easier for your organization to take more holisitic and proactive steps across your resources such as enabling important settings by default; but we in no way penalize you for the security settings that you implement.

An image of a description of what ASC has found, along with remediation steps.

To learn more about Microsoft Security solutions visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us at @MSFTSecurity for the latest news and updates on cybersecurity.

Posted on Leave a comment

Microsoft statement on TikTok

ByteDance let us know today they would not be selling TikTok’s US operations to Microsoft. We are confident our proposal would have been good for TikTok’s users, while protecting national security interests. To do this, we would have made significant changes to ensure the service met the highest standards for security, privacy, online safety, and combatting disinformation, and we made these principles clear in our August statement. We look forward to seeing how the service evolves in these important areas.

Posted on Leave a comment

New cyberattacks targeting US elections

In recent weeks, Microsoft has detected cyberattacks targeting people and organizations involved in the upcoming presidential election, including unsuccessful attacks on people associated with both the Trump and Biden campaigns, as detailed below. We have and will continue to defend our democracy against these attacks through notifications of such activity to impacted customers, security features in our products and services, and legal and technical disruptions. The activity we are announcing today makes clear that foreign activity groups have stepped up their efforts targeting the 2020 election as had been anticipated, and is consistent with what the U.S. government and others have reported. We also report here on attacks against other institutions and enterprises worldwide that reflect similar adversary activity.

We have observed that:

  • Strontium, operating from Russia, has attacked more than 200 organizations including political campaigns, advocacy groups, parties and political consultants
  • Zirconium, operating from China, has attacked high-profile individuals associated with the election, including people associated with the Joe Biden for President campaign and prominent leaders in the international affairs community
  • Phosphorus, operating from Iran, has continued to attack the personal accounts of people associated with the Donald J. Trump for President campaign

The majority of these attacks were detected and stopped by security tools built into our products. We have directly notified those who were targeted or compromised so they can take action to protect themselves. We are sharing more about the details of these attacks today, and where we’ve named impacted customers, we’re doing so with their support.

What we’ve seen is consistent with previous attack patterns that not only target candidates and campaign staffers but also those they consult on key issues. These activities highlight the need for people and organizations involved in the political process to take advantage of free and low-cost security tools to protect themselves as we get closer to election day. At Microsoft, for example, we offer AccountGuard threat monitoring, Microsoft 365 for Campaigns and Election Security Advisors to help secure campaigns and their volunteers. More broadly, these attacks underscore the continued importance of work underway at the United Nations to protect cyberspace and initiatives like the Paris Call for Trust and Security in Cyberspace.

Strontium

Strontium is an activity group operating from Russia whose activities Microsoft has tracked and taken action to disrupt on several previous occasions. It was also identified in the Mueller report as the organization primary responsible for the attacks on the Democratic presidential campaign in 2016. Microsoft’s Threat Intelligence Center (MSTIC) has observed a series of attacks conducted by Strontium between September 2019 and today. Similar to what we observed in 2016, Strontium is launching campaigns to harvest people’s log-in credentials or compromise their accounts, presumably to aid in intelligence gathering or disruption operations. Many of Strontium’s targets in this campaign, which has affected more than 200 organizations in total, are directly or indirectly affiliated with the upcoming U.S. election as well as political and policy-related organizations in Europe. These targets include:

  • U.S.-based consultants serving Republicans and Democrats;
  • Think tanks such as The German Marshall Fund of the United States and advocacy organizations;
  • National and state party organizations in the U.S.; and
  • The European People’s Party and political parties in the UK.

Others that Strontium targeted recently include businesses in the entertainment, hospitality, manufacturing, financial services and physical security industries.

Microsoft has been monitoring these attacks and notifying targeted customers for several months, but only recently reached a point in our investigation where we can attribute the activity to Strontium with high confidence. MSTIC’s investigation revealed that Strontium has evolved its tactics since the 2016 election to include new reconnaissance tools and new techniques to obfuscate their operations. In 2016, the group primarily relied on spear phishing to capture people’s credentials. In recent months, it has engaged in brute force attacks and password spray, two tactics that have likely allowed them to automate aspects of their operations. Strontium also disguised these credential harvesting attacks in new ways, running them through more than 1,000 constantly rotating IP addresses, many associated with the Tor anonymizing service. Strontium even evolved its infrastructure over time, adding and removing about 20 IPs per day to further mask its activity.

We are also working with our customers to assist them in proactively hunting for these types of threats in their environments and have published additional detail and guidance on Strontium activity.

Zirconium

Zirconium, operating from China, has attempted to gain intelligence on organizations associated with the upcoming U.S. presidential election. We’ve detected thousands of attacks from Zirconium between March 2020 and September 2020 resulting in nearly 150 compromises. Its targets have included individuals in two categories.

First, the group is targeting people closely associated with U.S. presidential campaigns and candidates. For example, it appears to have indirectly and unsuccessfully targeted the Joe Biden for President campaign through non-campaign email accounts belonging to people affiliated with the campaign. The group has also targeted at least one prominent individual formerly associated with the Trump Administration.

Second, the group is targeting prominent individuals in the international affairs community, academics in international affairs from more than 15 universities, and accounts tied to 18 international affairs and policy organizations including the Atlantic Council and the Stimson Center.

Zirconium is using what are referred to as web bugs, or web beacons, tied to a domain they purchased and populated with content. The actor then sends the associated URL in either email text or an attachment to a targeted account. Although the domain itself may not have malicious content, the web bug allows Zirconium to check if a user attempted to access the site. For nation-state actors, this is a simple way to perform reconnaissance on targeted accounts to determine if the account is valid or the user is active.

Phosphorus

Phosphorus is an activity group operating from Iran that MSTIC has tracked extensively for several years. The actor has operated espionage campaigns targeting a wide variety of organizations traditionally tied to geopolitical, economic or human rights interests in the Middle East region. Microsoft has previously taken legal action against Phosphorus’ infrastructure and its efforts late last year to target a U.S. presidential campaign. Last month, as part of our ongoing efforts to disrupt Phosphorus activity, Microsoft was again given permission by a federal court in Washington D.C. to take control of 25 new internet domains used by the Phosphorus. Microsoft has since taken control of these domains. To date, we have used this method to take control of 155 Phosphorus domains.

Since our last disclosure, Phosphorus has attempted to access the personal or work accounts of individuals involved directly or indirectly with the U.S. presidential election. Between May and June 2020, Phosphorus unsuccessfully attempted to log into the accounts of administration officials and Donald J. Trump for President campaign staff.

Bolstering Cybersecurity

We disclose attacks like these because we believe it’s important the world knows about threats to democratic processes. It is critical that everyone involved in democratic processes around the world, both directly or indirectly, be aware of these threats and take steps to protect themselves in both their personal and professional capacities. We report on nation-state activity to our customers and more broadly when material to the public, regardless of the actor’s nation-state affiliation. We are taking extra steps to protect customers involved in elections, government and policymaking. We’ll continue to disclose additional significant activity in our efforts to defend democracy.

We also believe more federal funding is needed in the U.S. so states can better protect their election infrastructure. While the political organizations targeted in attacks from these actors are not those that maintain or operate voting systems, this increased activity related to the U.S. electoral process is concerning for the whole ecosystem. We continue to encourage state and local election authorities in the U.S. to harden their operations and prepare for potential attacks. But as election security experts have noted, additional funding is still needed, especially as resources are stretched to accommodate the shift in COVID-19-related voting. We encourage Congress to move forward with additional funding to the states and provide them with what they need to protect the vote and ultimately our democracy.

Tags: , , , , , , ,

Posted on Leave a comment

Empowering NFL clubs and fans with help from the Microsoft Playbook

At Microsoft, we’re honored to partner with the NFL to bring modern fan experiences to the game of football. Since 2013, the NFL has used Microsoft Surface to help manage all aspects of their business and gameday operations. Earlier this year, we expanded this deep technology partnership to include Microsoft Teams, enhancing communication and collaboration across the League, and enabling new digital experiences. In April, when the pandemic made us change our way of life, the League used both Surface devices and Teams to help power the first-ever virtual NFL Draft. And today we’re announcing new innovations – developed with the League and NFL Clubs – that reimagine gameday for players and fans and help keep operations safe during a season unlike any other.

“Microsoft technology has been an integral part of NFL operations for several years,” says Michelle McKenna, CIO, NFL.  “And with the new challenges ahead of us this season, Microsoft will be instrumental in helping us innovate the best possible experiences for our players, coaches, officials, and fans, through activation like the Fan Mosaic and the Bud Light Showtime cam.”

New gameday experiences

  • Crowd energy and engagement energizes players and connects fans to one another. With fans mostly unable to attend games live, the NFL turned to Microsoft to create rich, virtual experiences that bring fans into the game when they can’t be there in person.
  • Using Microsoft Teams technology, key games this season will feature a feed of virtual fans called a Fan Mosaic. The Fan Mosaic will be displayed in stadiums on LED screens, and on broadcast to create a richer viewing experience.
    • For each game, the home team will invite lucky fans to a virtual VIP experience in which they watch the game together via a Microsoft Teams meeting. These fans will see a dual screen display of the live game next to a Gallery View of fellow fans. Each fan video feed will be isolated and mixed into the Fan Mosaic display. Fan audio from the Teams meeting will be mixed with augmented crowd noise customized for each stadium.
  • We also wanted to help the NFL digitally reimagine touchdown celebrations. This season, it will debut the Bud Light Showtime cam in stadiums at key games to give players a new way to connect with fans after scoring touchdowns.
    • After a player scores a touchdown they will see fans from the Fan Mosaic appear on LED screens installed at each end zone, allowing them to connect and celebrate the moment.

New operations experiences

  • NFL Football Operations will reduce the number of representatives onsite at each game. It will use Microsoft Teams to virtually manage operations for all games every week, supporting communication to gameday staff before, during, and after the game, and helping with document collaboration, reporting, and adherence to League and gameday protocols.

Ongoing support with Surface

  • Along with these new Teams integrations, Surface devices continue to be a vital tool for the League, clubs, players, and coaches on and off the field, on game day and every day.
  • Game preparation: NFL Game Officials rely on Surface to prepare for games by analyzing game film and collaborating as an officiating crew and the League office in advance of game day. At the club level, players and coaches prepare for the game with video reviews and playbooks.
  • Gameday: For players and coaches, the Microsoft Surface Sideline Viewing System has become an integral part of the game as Microsoft technology helps power 269 NFL gameday events each year with more than 2,000 Surface devices and 170 Windows Servers deployed across 30 NFL stadiums.
  • Additionally, Surface is an important tool for tracking all elements in-game. For example, it is critical in monitoring key parts of the IT infrastructure during a game.

In a season of countless challenges, we are honored to deploy Microsoft’s powerful combination of hardware and software to help the NFL bring football to people everywhere. With new fan and player experiences and operations solutions that keep everyone safe, we have developed a deep and lasting partnership with the NFL, and we look forward to future collaboration in the days to come.

Posted on Leave a comment

Xbox and Taco Bell give fans the chance to win an Xbox Series X before they can buy it

It’s that time! For the fourth year in a row, Xbox and Taco Bell are teaming up to offer fans a spectacular giveaway. However, this year is extra special as Xbox and Taco Bell fans in the United States will have the exclusive opportunity to win our fastest, most powerful and compatible console ever – the Xbox Series X – before it launches on November 10.

Beginning September 24, fans who purchase any medium or large drink via the Taco Bell app or in-person will receive a code on the cup for a chance to win a new Xbox Series X bundle. You can play up to three times per day – and did we mention there will be a winner every 15 minutes throughout the promotion?

The Xbox Series X bundle contains an Xbox Series X console, a new Xbox Wireless Controller and a six-month membership to Xbox Game Pass Ultimate. Xbox Game Pass Ultimate includes all the benefits of Xbox Live Gold and access to over 100 high-quality games on console and PC. Play new Xbox Game Studios titles such as Halo Infinite (coming 2021) the same day they release and enjoy exclusive member discounts and free Perks. Additionally, starting September 15, Ultimate members in 22 markets across North America, Europe and in South Korea will be able to play more than 100 games from the cloud on their Android phones and tablets.

To get your hands on a free taco and gain even earlier access to win an Xbox Series X bundle, make sure you sign up for Taco Bell’s all-new rewards program. All you need to do is download the Taco Bell app and join the Taco Bell Rewards Beta program by September 13. Those that have opted-in to receive emails will be able to register and gain exclusive access to be included in daily drawings from September 15 to September 21.

Xbox and Taco Bell partnered in 2001 to launch the original Xbox, so it’s only fitting that the two reunite to bring fans the brand-new Xbox Series X almost two decades later.

For complete details, head to the promotion’s official page.

Posted on Leave a comment

When a crisis becomes an opportunity: A culture of innovation fuels business resilience and economic recovery

In times of crisis, innovation becomes a necessity. And history tells us that humankind often ends up in a better place.

A cholera pandemic in 19th century London led to the creation of a new scientific field, epidemiology. The challenge of decrypting enemy messages during World War II spurred the development of computers.

With the current pandemic, it’s not surprising to see a similar process of innovation. Since COVID-19 hit the global economy, “we have witnessed firsthand how a wave of transformative change has swept across the region,” says Ahmed Mazhari, president  of Microsoft Asia. “This is no easy feat; organizations have challenges to overcome and innovation is no longer a luxury. It has to form the core part of an organization’s DNA.”

Many others in the business world agree.

A new Microsoft-IDC study, Culture of Innovation, Foundation for business resilience and economic recovery in Asia Pacific (APAC) shows that 41% of businesses view COVID-19 as an opportunity. Those businesses also expect to recover more quickly and come out of the crisis with similar or better revenue than before.

Innovation helps

However, let’s not paint an overly rosy a picture. COVID-19 is taking a devastating toll on human life, and the resulting economic downturn has seen many people lose their jobs or suffer reduced incomes.

In the face of this disruption, people and companies are doing their best to keep going. In Asia Pacific , organizations that are adapting have increased their ability to innovate in the past six months. What’s more, as they embrace change, they are finding it easier to innovate.

Not all organizations are progressing equally, but there are many things we can learn from those leading the way.

Understanding the culture of innovation

The study includes a culture of innovation framework, which describes an interplay of people, process, data and technology to assess how an organization approaches innovation.

It also identifies four stages along the journey to a mature culture of innovation: traditionalist, novice, adopter and leader. Additionally, it provides guidance to help organizations become leaders, so they can respond to challenges and recover faster.

What do leaders have in common?

Almost all (98%) of the organizations identified as leaders, with the most advanced culture of innovation, share a belief that innovation is key to responding quickly to market challenges and opportunities. These leaders are more resilient to crises like the current pandemic and they expect to recover faster.

This resilience shapes their perception of business outcomes. Around 50% of those organizations identified as leaders reported an expected increase in overall revenue when asked what impact they think COVID-19 will have on their overall business in 2020.

Leaders also recognize the importance of digital transformation and are accelerating the pace of digitalization in response to the crisis. Eighty-seven percent intend to speed up initiatives, such as  launching digital products, digital payments, ecommerce and automation. Only 66% of other organizations intend to do similarly.

Beyond digital products, services and processes, leaders understand the urgency of redesigning their overall business models. Indeed, leaders have already rethought their current business models and are exploring new ones to ensure business resilience and faster recovery.

Perhaps the most striking feature of the leaders is their approach to future planning. Leaders are looking to future-proof their businesses by focusing on technological and people capabilities. This attitude appears years ahead of other organizations that are still working on digitalization. Leading organizations know that people are the key ingredient and that empowering them to use technology successfully is the challenge of the future.

People are key

Mazhari puts it this way: “The current crisis has shown us how much business continuity and our future success depend on people, who need to be fully ready to embrace the digital reality, together with technology. While important, technology on its own will not make a difference. It is people’s capabilities and skills that allow organizations to innovate and transform.”

Leading organization share certain best practices that everyone can implement.

Eighty-nine percent have developed a culture promoting disruptive ideas and encouraging innovation as a corporate value. Eighty-two percent prioritize and formalize innovation rewards over traditional performance and hire a diverse cross-industry, multicultural and multigenerational workforce. And 70% invest in growing enterprise-wide capabilities and skilling initiatives.

This openness helps to unlock the potential of people to accelerate transformation.

Resilience and recovery

When the people of an organization have fully embraced the concept of a culture of innovation, the other elements of technology, data and process fall into place.Leading organizations overwhelmingly (92%) invest in disruptive technologies to drive innovation and business transformation.

Leaders are also more systematic in their approach. They develop specific processes to drive innovation. They also have dedicated budgets to drive their digital innovation and programs.

They also understand the importance of leveraging data to differentiate and enhance

their products and services. Additionally, they make decisions to enable enterprise-wide collaboration and knowledge sharing.

This combination of tech adoption and tech capability is known as tech intensity. “Now, with every organization becoming a digital one, achieving the success in transformation requires both the adoption of tools and technologies as well as their own digital capabilities,” Mazhari says. “Culture that encourages innovation and embraces digital opportunities is critical as it prepares the workforce and organizations for current and future challenges.”

The study lays out four steps that any organization can follow:

  1. Fortify resilience with technology
  2. Invest in people’s capabilities and skills
  3. Leverage data to increase competitiveness
  4. Redesign processes to empower people to continuously drive innovation

Mazhari reiterates that the culture of innovation is achieved through the critical combination of technology and employee empowerment.

“To succeed in the new normal and drive digital transformation, we not only need to have a robust digital foundation, we also need to ensure our people have the skills and tools to work together to drive disruption. Ultimately, we want to ensure a more resilient and inclusive future for all organizations. At Microsoft, we are committed to working with organizations in Asia Pacific to make this happen, together.”

Posted on Leave a comment

AI visits the art museum: Algorithm finds connections among the collections

The art world may not be the first business sector that comes to mind when you think about applications of AI, but a new algorithm developed by Microsoft and MIT is proving to be quite the curator.

Microsoft Research Development Engineer Mark Hamilton
Microsoft Research Development Engineer Mark Hamilton is a PhD student at MIT.

Microsoft Research Development Engineer Mark Hamilton , who is also a PhD student at MIT, helped develop the algorithm, which can find similarities in color, texture, theme and meaning between otherwise disparate works of art. The algorithm was recently highlighted by Smithsonian Magazine and several other publications. We chatted with Hamilton to learn more about the project and how it could be broadly applied to other areas.

Blog: Why art?

Mark: I love art, and we had a previous collaboration with the Metropolitan Museum of Art that let you explore an exhibit, understanding similarities between works of art and visualizing the space between various pieces. MosAIc was inspired by an exhibit that paired art from two artists who never met and showed that they have very similar structure. We thought we could do that on a larger scale, and we are continuing to be surprised by some of the connections we are able to find.

Blog: The algorithm can find similar works of art within specific styles or media based on colors, shapes and content, as well as meaning and themes. How can an algorithm take meaning and themes into account?

Mark: Today’s vision algorithms behave a lot like we do. When we look at an image, we get a gut feel for what it contains, such as the objects, people and composition. We train our neural network to understand thousands of objects across millions of different real-world scenes. We then feed that algorithm artworks and capture its ideas, or gut feel, about these works. These neural network ideas have even been shown to be similar to the ideas that humans have about images. It’s these neural network ideas that allow us to compare the content of different works of art.

Blog: What is new and innovative about the MosAIc algorithm?

Mark: One of the new contributions of the work is a new type of algorithm we call a conditional image retrieval system. If you think about something like reverse image search, you put in an image and find all the similar images from the web. What we have done is allow you to find not only the most similar items across the whole collection, but also any sub-collection such as the Egyptian artworks, the prints or even the works by an individual artist. This allows us to find matches across widely different artistic traditions, which is something that regular approaches cannot do efficiently. More technically, we created a data structure that generalizes K-Nearest Neighbor trees to allow them to specialize to particular sub-collections quickly and efficiently.

Blog: In what other ways could it be used?

Mark: At the core of this, you have a new kind of search technology that can be applied to any data. The data can be images like art, products or really anything you want. One example from retail would be a fashion aware search; you could take your favorite pair of pants and use this approach to find the best matching blouse. In the realm of text and documents, let’s say you have an email that is talking about a given topic. Using our approach, you could pull up all of the memos or receipts with similar content as the email. To make these systems, one could just swap out our vision networks with equivalent networks for text, music or other data.

This approach also gives you the ability to add diversity to your search engines in a controlled and structured way. For example, you could imagine showing not only the top results for a restaurant search, but also top results from other sub-categories like vegetarian food, or Black or African American owned restaurants. This way you can supply results that are relevant and highlight many diverse types of content.

Blog: How can people learn more about this project?

Mark: They can explore the MosAIc app, read the paper about our research, watch our Microsoft Research webinar or check out the code on GitHub.

Caption: One of the MosAIc pairings. On the left, a British dress from 1840. At right, Vaas van paars glas, Chris Lebeau, c. 1924 – c. 1925.

Posted on Leave a comment

Microsoft and Copenhagen University researchers create new kind of quantum device

In a paper published this week in Nature Physics, a team of researchers from Microsoft and Copenhagen University demonstrated a novel heterostructure with remarkable properties. A heterostructure is, roughly, a device formed out of a sandwich between different solid materials. When the interfaces between the different materials are clean, the device can have properties that would be difficult, if not impossible to obtain in any single material. But when the interfaces contain impurities, the device may capture the worst, rather than the best properties, of the materials comprising it.

The device described in the new Microsoft-Copenhagen University paper is a heterostructure between a semiconductor, a superconductor, and a ferromagnet. The three materials and the interfaces between them were fabricated within an ultra-high-vacuum molecular beam epitaxy (MBE) machinemade possible by the compatibility between the growth and fabrication conditions for the three materialseuropium sulfide (ferromagnet), aluminum (superconductor), and indium arsenide (semiconductor)leading to extremely flat and clean interfaces. 

The authors showed that the device has gate-tunable superconductivity and ferromagnetism induced in and coexisting in the semiconductor. These two phenomena, ordinarily antithetical, are able to peacefully coexist due to a property of indium arsenide called spin-orbit coupling. In fact, when such coexistence occurs in a quantum wire device of the type fabricated and measured by the Microsoft-Copenhagen University teamMajorana zero modes can result, enabling such a wire to be an integral component of a topological quantum computer. The new Nature physics paper shows data that is consistent with the presence of Majorana zero modes in their devices. 

Previous devices without a ferromagnetic layer have exhibited similar signatures upon the application of a large magnetic field, in a direction aligned with the wireBut such a large field brings problems of its own, including the need to align all of the wires in a topological quantum computer to fairly high accuracy, as well as the field’s possible effect on other components higher in the stack. In the devices created by the Microsoft-Copenhagen University teamthe magnetic moment due to the ferromagnetic layer is highly localized and automatically aligned with a preferred crystal axis. 

Microsoft’s Quantum program has made a big bet that new methods for the design, fabrication, and measurement of these types of novel heterostructures will be essential if we are to build a commercial-scale quantum computer. While some might argue that tools invented for classical devices will be sufficient to produce quantum devices, Microsoft and Copenhagen University have already shown in previous work that long-envisioned, but never previously realized, combinations of superconducting and semiconducting elements could be grown and fabricated via MBE and probed by quantum transport, overturning conventional wisdom about what is possible. 

Thus, this work, has intrinsic interest as a new device type with unique mix of features and is also a significant step towards the creation of simpler topological quantum computing systems. It is also another example of how Microsoft and its partners, such as Copenhagen University, are reinventing the science and engineering of quantum devices. 

Posted on Leave a comment

Vroom with a view: HoloLens 2 powers faster fixes for Mercedes-Benz USA

The tools enable diagnostic technicians at the dealerships to troubleshoot a problem in real time by tapping into Mercedes-Benz’ vast ecosystem of remote technical specialists with particular expertise across its various car lines. That network ranges from Mercedes-Benz field specialists in the U.S. who are schooled on the intricacies of each model to engineers at company headquarters in Germany who helped design those vehicles.

Now, a service technician like Edgar Campana, who works at Mercedes-Benz of Coral Gables, can wear a HoloLens 2 and share his view of the car part or car system in question while talking with one of the company’s remote technical specialists, via Dynamics 365 Remote Assist.

Edgar Campana smiles while standing in a repair ship with cars behind him in the distance.
Edgar Campana.

If he needs to peer deep inside the layers of machinery, Campana can gesture with his fingers at, say, the engine and immediately see a 3D hologram that appears next to the car.

Watching from a laptop or desktop computer, the remote specialist can ask Campana to turn his head toward a specific part or sensor, then share wiring diagrams, notes or other visual information directly into the view of the HoloLens 2.

What’s more, the remote specialist can draw on the hologram a picture of that engine (or other component) to show the technician where, for example, to adjust a specific cable. Multiple Mercedes-Benz specialists can join the same call.

“It’s like they are there. It’s like I am them,” Campana says. “The expert is looking through my eyes and seeing what I’m seeing so they can guide me.”

Mike Munoz sits at his corner desk with his hands on the surface as he smiles, looking away from his compute screen. hands
Mike Munoz.

During his virtual conversations, Campana can keep his hands free to use his tools. He also can use the HoloLens 2 to drag the specialist-shared diagrams and documents behind him, away from his field of view. If he needs to view them again, he can just turn backward to reference them or drag them back in front.

“It makes everything easier,” Campana says. “We’re able to diagnose and address issues right there, get the car out of the garage and back to the customer much quicker.”

Mercedes-Benz USA has supplied HoloLens 2 devices to its authorized U.S. dealership partners, including Mercedes-Benz of Coral Gables.

Before the rollout, Campana and his fellow diagnostic technicians typically communicated via email with the remote technical specialists, who often are working to troubleshoot multiple queries across U.S. dealerships. Those back-and-forth email exchanges took time.

“We can now resolve issues often in minutes and hours as compared to days, allowing us to serve our customers more quickly with faster turnaround times,” Munoz says.

Posted on Leave a comment

Xbox Series S and Xbox Series X launch Nov. 10, starting at $24.99 a month with Xbox Game Pass Ultimate and EA Play

Now more than ever, gaming plays an important role in our lives. As one of the greatest forms of creative expression, gaming sparks in our imagination and connects us to new worlds, stories, and our friends.

On November 10, a new generation of console gaming begins. That’s when our vision becomes reality with the most performant, immersive and compatible next-generation console gaming experiences, and the freedom to play your games with your friends, anytime, anywhere.

To empower you more than ever to jump into the next generation of gaming, today we confirmed:

  • Xbox Series X, our most powerful console ever made, and Xbox Series S, next-generation performance in our smallest console ever built at a more affordable price, launch globally November 10, pre-orders start September 22.
  • The expansion of Xbox All Access to 12 countries, offering you a next generation Xbox and 24 months of Xbox Game Pass Ultimate starting at $24.99 a month, with no upfront costs.
  • EA Play Comes to Xbox Game Pass at no additional cost.

Bringing the Next Generation of Gaming to Everyone on Day One

We believe that access to the next generation should be available to everyone. And we know that price is an important factor for many of our fans. To complement Xbox Series X and invite more players into the next generation sooner, we built Xbox Series S—an all-digital, next-gen console designed to deliver everything that is core to next-generation gaming – faster load times, higher frame rates, and richer, more dynamic worlds – in our smallest, sleekest Xbox ever. Developing two consoles in parallel from the beginning enables us to deliver the most powerful console ever in Xbox Series X and make next-gen gaming available and affordable to more players on day one with Xbox Series S.

Empowering you with freedom and choice is core to everything we do at Xbox. In addition to the traditional option of purchasing the new generation of Xbox Series X and S at $499 (Estimated Retail Price) and $299 (Estimated Retail Price) respectively, we’re expanding our Xbox All Access program to 12 countries this holiday, with more to come in 2021.

Whether you’re upgrading to the newest consoles or joining the Xbox family for the first time, Xbox All Access is the easiest way to get the best of Xbox. Xbox All Access provides an Xbox Series X, or Series S, along with 24 months of the full Xbox Game Pass Ultimate experience. In total, that means you get access to:

  • The next-generation Xbox console of your choice
  • Over 100 high-quality games to play on console, including next-gen Optimized games
  • Over 100 high-quality games to play on PC
  • An EA Play membership to play more than 60 of EA’s biggest and best console and PC games
  • And over 100 games to play from the cloud

That’s all with no upfront costs and a low monthly price. Xbox Series S will be available starting from $24.99 a month for 24 months and Xbox Series X will be available starting from $34.99 a month for 24 months.

The Ultimate Gaming Membership Goes Beyond the Console and Keeps Getting Better

With the Xbox Game Pass community now over 10 million players, we know how critical it is that your friends can easily access and play the same games you can. And you’ve pushed us to make Xbox Game Pass the only membership with access to more than 100 games on your console, PC, and mobile.  

To provide even more value, we are teaming up with Electronic Arts to provide Xbox Game Pass Ultimate and PC members with an EA Play membership at no additional cost starting this holiday. This means Ultimate members can enjoy EA Play on Xbox One, Xbox Series X and Series S, and Windows 10 PCs, and Xbox Game Pass for PC members get EA Play on Windows 10. In addition to the 100+ games in the Xbox Game Pass library today, Ultimate and PC members will be able to play more than 60 of EA’s biggest and best console and PC games like FIFA 20, Titanfall 2 and Need for Speed Heat, as well as titles from some of EA’s most popular franchises like Battlefield, Mass Effect, Skate, and The Sims. Some of the best EA Play games will also be available for Ultimate members to play on Android devices from the cloud at no additional cost.

And we’re continuing to add great games and experiences to Xbox Game Pass for PC. Game Pass for PC and the Xbox App will become generally available on September 17.

The Best Place to Play the Biggest Games

When Xbox Series X and Series S launches this November, it will herald a new generation of game experiences. Optimized games for Xbox Series X and Series S coming this year are built to take full advantage of our fastest consoles ever. On day one you will be the first to enjoy next-gen versions of the most anticipated games of the year such as Gears Tactics, Tetris Effect: Connected and Ubisoft’s Assassin’s Creed Valhalla and Watch Dogs: Legion. Ubisoft is known for leveraging new technologies and the power of new hardware to deliver groundbreaking games, and we think you’ll be blown away by the experience you’ll have playing Assassin’s Creed Valhalla and Watch Dogs: Legion on Xbox.

Xbox Series S is designed around the same technology that will make these games and so many others look and feel incredible. In speaking to game developers, we identified the areas that are most difficult to scale effectively, including the CPU and I/O, and made it easy to include Xbox Series S for developers who are targeting their experiences for Xbox Series X.

Powered by the Xbox Velocity Architecture, you can expect the same benefits from Xbox Series S such as faster load times and Quick Resume. Xbox Series S also supports all the same next gen features including HDMI 2.1, frame rates up to 120fps, DirectX Raytracing and Variable Rate Shading. It will also support Spatial Sound, including Dolby Atmos, and Dolby Vision via streaming media apps like Disney+, Vudu and Netflix at launch. Plus: Dolby Vision support for gaming will come first to our next-gen Xbox consoles in 2021.

And the new Xbox consoles are also the only next-generation, backward-compatible consoles that allow you to play thousands of games from four generations better than ever before, and empower you to play with friends wherever you want across your console, PC, and mobile device.

The Best Generation of Gaming Yet

Gaming has evolved in the last decade to make it easier, simpler and more affordable for any player to make that first connection with a new world, a new story, or a new friend. With a family of next-gen Xbox consoles, even greater variety and value with Xbox Game Pass, and an expansion to Xbox All Access, we invite everyone to join us for this next generation of gaming.