Showing posts with label AWS VPC AWS SSM. Show all posts
Showing posts with label AWS VPC AWS SSM. Show all posts

Tuesday, December 24, 2024

Microsoft Dynamics Deployment on AWS

 Microsoft Dynamics Deployment on AWS provides businesses with a scalable and secure cloud infrastructure to host and manage Microsoft Dynamics 365 applications. These applications include Business Central, Finance, Supply Chain Management, and Sales, among others. AWS offers flexibility for both Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) models for deployment.


1. Deployment Models for Microsoft Dynamics on AWS

  1. Infrastructure-as-a-Service (IaaS):

    • Use Amazon EC2 instances to host Microsoft Dynamics applications.
    • Configure Windows Server and SQL Server databases.
    • Ideal for businesses that need full control of the infrastructure.
  2. Hybrid Cloud Deployment:

    • Integrates AWS-hosted Dynamics with on-premises systems.
    • Useful for businesses transitioning to the cloud in phases.
  3. Fully Cloud-Native Deployment:

    • Deploy Dynamics 365 using AWS services like RDS, Elastic Load Balancer (ELB), Auto Scaling, and CloudFormation.
    • Best for scalability and operational efficiency.

2. Key AWS Services for Microsoft Dynamics 365 Deployment

  • Compute:

    • Amazon EC2 – Hosts Windows Server and Dynamics services.
    • AWS Auto Scaling – Automatically scales EC2 instances based on demand.
  • Database:

    • Amazon RDS for SQL Server – Fully managed relational database service.
    • Amazon Aurora – For higher performance with SQL compatibility.
  • Storage:

    • Amazon S3 – For backups, logs, and files.
    • Amazon FSx for Windows File Server – Fully managed shared file systems.
  • Networking:

    • Amazon VPC – Isolates Dynamics deployments in a private network.
    • AWS Direct Connect – Ensures secure, low-latency connectivity with on-premises environments.
  • Security:

    • AWS IAM – Manages access permissions and user roles.
    • AWS Shield and WAF – Protects against DDoS and web attacks.
  • Monitoring and Analytics:

    • Amazon CloudWatch – Monitors system performance.
    • AWS CloudTrail – Tracks API usage and logs user activity.
    • Amazon QuickSight – BI tool for reporting and dashboards.

3. Steps to Deploy Microsoft Dynamics 365 on AWS

Step 1: Infrastructure Preparation

  1. Create VPC: Configure subnets, routing tables, and security groups.
  2. Set Up IAM Roles: Define access controls and permissions for EC2 instances.
  3. Provision EC2 Instances:
    • Choose Windows Server with required configurations.
    • Attach EBS volumes for storage.
  4. Configure Network Security:
    • Enable firewalls and VPN connections.
    • Use AWS Direct Connect for hybrid setups.

Step 2: Database Setup

  1. Use Amazon RDS for SQL Server or EC2-hosted SQL Server.
  2. Configure failover clusters for high availability.
  3. Optimize performance with Read Replicas and Elasticache for caching.

Step 3: Application Deployment

  1. Install Microsoft Dynamics 365 Software:

    • Transfer installation media to AWS instances using S3 or AWS Transfer Family.
    • Connect to the server via RDP and install the application.
  2. Connect to SQL Database:

    • Configure Dynamics to communicate with SQL Server hosted on RDS or EC2.
  3. Configure Load Balancers:

    • Deploy Elastic Load Balancer (ELB) for distributing traffic.
  4. Enable Scaling:

    • Use Auto Scaling Groups to handle dynamic workloads.

Step 4: Testing and Optimization

  1. Validate the setup with test transactions.
  2. Use AWS CloudWatch to monitor performance and detect anomalies.
  3. Optimize configurations for network latency and response times.

Step 5: Security and Compliance

  1. Enable AWS Key Management Service (KMS) for encryption.
  2. Apply Security Groups and WAF rules to control access.
  3. Configure Multi-Factor Authentication (MFA) for admin users.
  4. Enable auditing via CloudTrail for compliance tracking.

Step 6: Backup and Disaster Recovery

  1. Schedule automatic backups using AWS Backup.
  2. Enable cross-region replication for disaster recovery.
  3. Implement snapshot-based backups for databases.

4. Integration with Microsoft Services

  • Azure Active Directory:
    • Use AWS Directory Service or integrate with Azure AD for authentication.
  • Office 365 Integration:
    • Connect Dynamics with Microsoft 365 apps like Outlook and Teams.
  • Power BI:
    • Connect Dynamics data to Power BI for advanced analytics and reporting.

5. High Availability and Scalability

  • Use Multi-AZ RDS for SQL Server to ensure database failover.
  • Deploy instances across multiple AWS Availability Zones (AZs).
  • Enable Auto Scaling for application and web servers.

6. Licensing Options

  1. Bring Your Own License (BYOL):

    • Use existing Microsoft licenses on AWS.
  2. License Included Instances:

    • AWS provides pre-configured Windows and SQL Server licenses.
  3. AWS Marketplace Subscriptions:

    • Access Dynamics configurations directly from the AWS Marketplace.

7. Monitoring and Maintenance

  • Use AWS Systems Manager to automate patching and updates.
  • Monitor system performance via Amazon CloudWatch.
  • Schedule regular maintenance windows for updates and optimizations.

8. Benefits of Deploying Dynamics 365 on AWS

  1. Flexibility and Scalability:

    • Easily scale resources based on workload demands.
  2. High Availability and Reliability:

    • Multi-AZ support ensures fault tolerance.
  3. Security and Compliance:

    • Built-in encryption, IAM roles, and auditing features.
  4. Cost Optimization:

    • Pay-as-you-go pricing reduces capital expenses.
  5. Integration with AWS Services:

    • Leverage Lambda, S3, and Redshift for extended functionality.

Conclusion

AWS provides a robust and scalable platform to deploy Microsoft Dynamics 365 with flexible deployment models, high availability, and advanced security features. Businesses can use AWS to integrate Dynamics with other AWS services, ensuring seamless performance, monitoring, and disaster recovery while optimizing costs.

Wednesday, February 17, 2021

AWS VPC endpoints configuration to use Systems Manager to manage private EC2 instances without internet access

Amazon EC2 instances must be registered as managed instances to be managed with AWS Systems Manager. Follow these steps:

  1. Verify that SSM Agent is installed on the instance.
  2. Create an AWS Identity and Access Management (IAM) instance profile for Systems Manager. You can create a new role, or add the needed permissions to an existing role.
  3. Attach the IAM role to your private EC2 instance.
  4. Open the Amazon EC2 console, and then select your instance. On the Description tab, note the VPC ID and Subnet ID.
  5. Create a VPC endpoint for Systems Manager.
    For Service Name, select com.amazonaws.[region].ssm (for example, com.amazonaws.us-east-1.ssm). For a full list of Region codes, see Available Regions.
    For VPC, choose the VPC ID for your instance.
    For Subnets, choose the Subnet ID for your instance. Be sure to choose subnets from different Availability Zones within the Region.
    Note: If you have more than one subnet in the same Availability Zone, you don't need to create VPC endpoints for the extra subnets. Any other subnets within the same Availability Zone can access and use the interface.
    For Enable DNS name, select Enable for this endpoint. For more information, see Private DNS for interface endpoints.
    For Security group, select an existing security group, or create a new one. If you created a new security group, open the VPC console, choose Security Groups, and then select the new security group. On the Inbound rules tab, choose Edit inbound rules. Add a rule with the following details, and then choose Save rules.
    For Type, choose HTTPS.
    For Source, choose your VPC/Subnet CIDR.
    Note the Security group ID. You'll use this ID with the other endpoints.
    Optional: For advanced setup, create policies for VPC interface endpoints for AWS Systems Manager.
  6. Repeat step 5 with the following change:
    For Service Name, select com.amazonaws.[region].ec2messages.
  7. Repeat step 5 with the following change:
    For Service Name, select com.amazonaws.[region].ssmmessages. You must do this if you want to use Session Manager.

After the three endpoints are created, your instance appears in Managed Instances, and can be managed using Systems Manager.



How IdP Groups Are Tied to Databricks Groups (Unity Catalog)

  🔗 How IdP Groups Are Tied to Databricks Groups (Unity Catalog) 🔑 Key Principle (Read This First) Databricks does NOT “map” IdP groups...