Archive for the ‘Microsoft Dynamics Ax’ category

Bad Rabbit – a virulent wave of data-encrypting malware is sweeping through Eastern Europe

October 28th, 2017

A new, potentially virulent wave of data-encrypting malware is sweeping through Eastern Europe and has left a wake of outages at news agencies, train stations, and airports, according to multiple security companies

A new ransomware outbreak similar to WCry is shutting down computers worldwide, Ransom:Win32/Tibbar.A or Bad Rabbit, as the outbreak is dubbed, is primarily attacking targets in Russia, but it’s also infecting computers in Ukraine, Turkey and Germany, researchers from Moscow-based Kaspersky Lab said. In a blog post, the antivirus provider reported that the malware is using hacked Russian media websites to display fake Adobe Flash installers, which when clicked infect the computer visiting the hacked site. Researchers elsewhere said the malware may use other means to infect targets.

Bad Rabbit appears to specifically target corporate networks by using methods similar to those used in a June data-wiping attack dubbed “NotPetya” that shut down computers around the world.
Bad Rabbit infects Windows computers and relies solely on targets manually clicking on the installer, Kaspersky Lab said. So far, there’s no evidence the attack uses any exploits.

The Ukrainian computer emergency agency CERT-UA posted an advisory on Tuesday morning reporting a series of cyberattacks.

Kevin Beaumont said on Twitter that Bad Rabbit uses a legitimate, digitally signed program called DiskCryptor to lock targets’ hard drives. Kaspersky Labs’ blog post said the executable file dispci.exe appears to be derived from DiskCryptor and is being used by Bad Rabbit as the disk encryption module.

Bad Rabbit relies on hard-coded credentials that are commonly used in enterprise networks for file sharing and takes aim at a particularly vulnerable portion of infected computers’ hard drives known as the master boot record. A malicious file called infpub.dat appears to be able to use the credentials to allow the Bad Rabbit to spread to other Windows computers on the same local network, The malware also uses the Mimikatz network administrative tool to harvest credentials from the affected systems.

Once Bad Rabbit infects a computer, it displays a message in orange letters on a black background. It directs users to a Dark Web site that demands about $283 in Bitcoin to decrypt data stored on the encrypted hard drive. The dark Web site also displays a ticking clock that gives victims 40 hours to pay before the price increases. It’s not yet known what happens when targets pay the ransom in an attempt to restore their data. The NotPetya malware was written in a way that made recovery just about impossible, a trait that has stoked theories that the true objectives of the attackers was to wipe data in an act of sabotage, as opposed to generate revenue from ransomware. It also remains unclear who is behind the attack.

The outbreak is the latest reminder that you should back up all their data on drives that are secured with a password or other measure to protect them from ransomware.

Windows Defender Antivirus detects and removes this threat with protection update 1.255.29.0 and higher.

This threat appears as a fake Adobe Flash Player update.

Microsoft advice:
Microsoft doesn’t recommend you pay the ransom. There is no guarantee that paying the ransom will give you access to your files. If you’ve already paid, then see our https://www.microsoft.com/en-us/mmpc/shared/ransomware.aspx for help on what to do.

Review logs and shutdown or run Windows Defender Offline.

This ransomware attempts to reboot your PC so it can encrypt your files. You might be able to stop your PC from rebooting and instead shut it down or run a Windows Defender Offline scan:
Check event logs for the following IDs: 1102 and 106
• Event 1102 indicates that the audit log has been cleared, so previous activities can’t be seen.
• Event 106 indicates that scheduled tasks “drogon” and “Rhaegel” have been registered (these are ransomware wipers)
• If events 1102 and 106 are present, then issue a shutdown with the parameter -a to prevent a reboot

You can also immediately inititate a Windows Defender Offline scan by using PowerShell or the Windows Defender Security Center app.

Run antivirus or antimalware software

Use the following free Microsoft software to detect and remove this threat:
• Windows Defender Antivirus for Windows 8.1 and Windows 10, or Microsoft Security Essentials for Windows 7 and Windows Vista
• Microsoft Safety Scanner – Run a full scan to look for anyhidden malware.

Advanced troubleshooting – To restore your PC, download and run Windows Defender Offline.

Ask us about how to use cloud protection to guard against the latest malware threats. It’s turned on by default for Microsoft Security Essentials and Windows Defender for Windows 10. Go to All settings > Update & security > Windows Defender and make sure that your Cloud-based Protection settings is turned On.

Indicators of compromise
Presence of the following files in %SystemRoot%:
• infpub.dat
• cscc.dat
• dispci.exe
• You can’t access your files or your PC
• A ransom message in red on a black background

VAT registration U.A.E. – act now deadlines are imminent

October 17th, 2017

The UAE Federal Tax Authority (FTA) online portal is open 24/7 to allow for taxpayers to register for VAT purposes. The FTA has also determined the deadlines for the application for VAT registration based on business turnover.
For larger companies VAT registration is required by 31 October 2017, and such businesses should
immediately consider the timeline requirement given their turnover profile and the other registration
requirements.
Businesses that are required to register for VAT will need to set up an online account on the FTA website and complete the VAT registration form.

The FTA has announced that a phased registration approach has been introduced. In particular, those businesses that meet these criteria must comply with the relevant application dates for registration:
● Businesses with an annual turnover exceeding AED 150 million must apply for registration by
31 October 2017
● Businesses with an annual turnover exceeding AED 10 million must apply for registration by 30 November 2017

● Remaining businesses with an annual turnover exceed the mandatory registration threshold
(expected to be AED 375,000) must apply for registration by 4 December 2017
Prior to the fulfilment of the VAT registration form, the FTA provides a “Getting Started Guide” that shares essential information that businesses should be aware of. This includes information on the registration criteria, registration of a VAT group, and necessity to register if only zero-rated supplies are made.

Additional details clarifying the VAT registration mechanism are found in the VAT registration guide, a document posted on FTA online portal under the “Advice” tab. This document captures the
calculation of turnover for VAT purposes, a walk-through of VAT registration through the FTA
registration portal, registration of a VAT group and types of books and records required to be held by a
taxpayer to ensure accurate tax compliance.

We strongly advise for businesses to visit the FTA website to initiate their VAT registration application by
their applicable deadline after having considered the guidance provided by the FTA and other advice
as required (for instance VAT Grouping).
Businesses should allow time to compile the required information for the VAT registration.

Cumulative Update 13 for Microsoft Dynamics AX 2012 R3 is available for Synergy Software Customers

October 17th, 2017

Compatibility:
Windows Server 2016 is supported with AX 2012 R3 CU 13.
Microsoft Visual Studio Team Foundation Server 2017 is now supported with AX 2012 R3 CU 13.
Microsoft SQL Server 2016 SP 1 is supported with AX 2012 R3 CU 13.

Cortana intelligence services management – showcases Recommendations API integration in Dynamics AX 2012 R3.
Use this capability to create a machine learning model and train that model generate recommendations.
Use this as a reference implementation, and then connect more Cognitive Service APIs or to bring other Cortana intelligence based insights into your Dynamics AX solution.
For more detailed information, review the Cortana Intelligent Services management white paper – available from us on request.

There are a number of enhancements/hotfixes related to DIXF.
A new feature enables an alternate way to report a carry-forward budget. The feature maintains the carry-forward status on relieving documents that were based on an originating document carried
forward.
(If you change functionality mid-year, and not after year-end, then retroactively update the budget for any transactions for the current year.
This feature cannot be disabled after it’s enabled, because transactions which )would not be considered carry-forward might have occurred using the alternate configuration
)

Reprocessing of documents against Budget control. When issues are found, the budget manager can inquire into the documents that were found and reprocess these. After reprocessing, the data maintenance process
becomes a read-only record of the documents that were found, as well as showing the results of the reprocessing.
To update the Ledger takes a long time to run Advanced ledger allocation basis rules, as the TempDB fills up -this addresses that issue.

Many retail enhancements – here are a few:

In Retail the maximum number of fields you can add to a receipt footer is increased from 50 to 100.

Customer data privacy – extra fields in the Customer table indicate privacy choices, such as do not call,
email, text, and so on, for all interfaces in all channels

A Post-sync channel DB clean up will reduce data volume.

The X Report and Z Report (in POS and HQ)will no longer include the amounts from the sales quotations.

A feature is added to display/check loyalty card point balance on the Customer detail, Store operation and Loyalty payment page.

A performance issue arises on the Retail Sales form when there are a large number of SQL records in the AX database. KB 4024615 hotfix adds a Search button, and changes the process so that the query is run only when the button is clicked.

A new control allows users to sell (and return) items outside the store assortment.
A credit memo is created without reference at AX HQ if the credit memo is created during a time when the network at the store is down. KB 4021760 hotfix clears the credit memo that was created previously before creating a replacement.

These are some SCM enhancements that also impact performance:
‘Select packing slip’ takes a long time to process for an intercompany Sales Order when the sales policy is set to Unit price equal to cost price – whichis common practice.
KB 3212427 hotfix resolves the performance issue by optimizing data access and improving the performance of the business logic.

When you have a large number of bills of materials (BOMs), bill of materials lines, or BOM versions, you may experience that the performance of the BOM circularity check, that is optimized for high complexity, is not
acceptable. The hotfix he hotfix improve performance of the BOM circularity check, that is optimized for high complexity, in scenarios where you have a large number of bills of materials (BOMs), bill of materials lines, or BOM versions.

VAT in the U.A.E. – time to act.

October 16th, 2017


VAT, as a general consumption tax, will apply to the majority of transactions in goods and services. A limited number of reliefs may be granted.

As a result, the cost of living is likely to increase slightly, but this will vary depending on an individual’s lifestyle and spending behaviour. If an individual spends mainly on those things which are relieved from VAT, he is unlikely to see any significant increase.

The government will include rules that require businesses to be clear about how much VAT an individual is required to pay for each transaction. Based on this information, individuals can decide whether to buy something.

Implication of VAT on businesses

Businesses will be responsible for carefully documenting their business income, costs and associated VAT charges. Businesses that meet the minimum annual turnover requirement (as evidenced by their financial records) will be required to register for VAT. Businesses that do not think that they should be VAT registered should maintain their financial records in any event, in case the ministry needs to establish whether they should be registered. The FTA does have the power to conduct audits on taxable persons and subsequently impose penal measures on those that are not compliant with the law.

A business must register if the total value of their taxable supplies made within the UAE exceeds the mandatory registration threshold over the previous 12 month period, or they anticipate making taxable supplies with a value exceeding the mandatory registration threshold in the next 30 days.

The mandatory registration threshold is AED 375,000.

A business may also apply to register if they do not meet the mandatory registration criteria and the total value of their taxable supplies or taxable expenditure in the previous 12 months exceeds the voluntary registration threshold, or they anticipate that the total value of their taxable supplies or taxable expenditure will exceed the voluntary registration threshold in the next 30 days.

The voluntary registration threshold is AED 187,500.

For the purposes of understanding whether a registration obligation exists, a taxable supply refers to a supply of goods or services, made by a business in the U.A.E., that may be taxed at a rate of either 5%, or 0%. Imports are also taken into consideration for this purpose, when a supply of such goods or services would be taxable when made within the U.A.E.

VAT registration require some official documents. Before submission of an application some important documents must be completed. Businesses will get VAT registration in the form of a VAT certificate, with the help of official documents. Every VAT certificate will have a specific identification number. The identification number will be essential for all the tasks to be carried out for VAT in UAE.

The process for VAT registration and fee submission will be done online. Following documents are required for the registration of VAT in UAE.
1. Copy of Trade License
2. Passport copy of the owner/partners who owns the license
3. Copy of Emirates ID of the owner/partners who owns the license
4. Memorandum of Association (MOA)
5. Contact Details of company (complete address & P.O Box)
6. Concerned person contact details
7. Email of the concerned person
8. Copy of all bank accounts and statements including IBAN
9. Owner has any other entities?
10. Income statement for the last 12 months
11. Expected revenue and expense for the next 30 days after VAT implementation
12. Are they exporting, or importing?
13. Are they dealing with any custom department? If yes. What is the custom code?
14. Are they doing business with any other G.C.C. country? (Country name)
15. If these are representing more than one entity, whether they want one tax group number for allof the entities, or separate tax numbers for each entity.
16.Experience of business (Owners or directors involved in any previous businesses before for the last 5 years?)

The submission of the documents will be done when you have registered online.
After online VAT registration and fees payments, you will be allowed to submit the documents. After the verification of the documents and completion of the process, a VAT certificate will be provided.

VAT will be charged at 0% in respect of the following main categories of supplies:

Exports of goods and services to outside the GCC States that implement VAT
International transportation, and related supplies
Supplies of certain sea, air and land means of transportation (such as aircrafts and ships)
Certain investment grade precious metals (e.g. gold, silver, of 99% purity)
Newly constructed residential properties, that are supplied for the first time within 3 years of their construction
Supply of certain education services, and supply of relevant goods and services
Supply of certain Healthcare services, and supply of relevant goods and services

The following categories of supplies will be exempt from VAT:

the supply of some financial services
Residential properties
Bare land
Local passenger transport

Registered businesses and traders will charge VAT to all of their customers at the prevailing rate and incur VAT on goods/services that they buy from suppliers. The difference between these sums is reclaimed or paid to the government.

VAT-registered businesses generally:
• must charge VAT on taxable goods or services they supply
• may reclaim any VAT they have paid on business-related goods or services
• keep a range of business records which will allow the government to check that they have got things right.

VAT-registered businesses must report the amount of VAT they have charged and the amount of VAT they have paid to the government on a regular basis. It will be a formal submission and it is likely that the reporting will be done online.

If they have charged more VAT than they have paid, they have to pay the difference to the government. If they have paid more VAT than they have charged, they can reclaim the difference.

Please note there will be a year end rush on consulting services we have already received over 100 inquiries for software consulting support so don’t leave it too late.

SQL Server 2012 Service Pack 4 (SP4) is available

October 16th, 2017

SQL Server 2012 Service Packs, Service Pack 4 (SP4). This release of SQL 2012 Service Pack has 20+ improvements centered around performance, scalability and diagnostics to enable SQL Server 2012 to perform faster and scale out of the box on modern hardware design.

SQL Server 2012 SP4 includes all the fixes up to and including SQL Server 2012 SP3 CU10

Dynamics 365 for Finance and Operations, Enterprise edition platform update 11

October 10th, 2017

Dynamics 365 for Finance and Operations, Enterprise edition platform update 11. This version was released in October 2017 and has a build number of 7.0.4679.35176.
For information about bug fixes : see the LCS article KB 4047244 for PU11 https://fix.lcs.dynamics.com/Issue/Resolved/1191076?kb=4047244&bugId=3869536

Some key new features:
Attachment presence and document count indicator

Auditing of user sign in and sign out
Copy legal entity configurations to a new legal entity
Support for display and edit methods in class extensions
Support for field arrays in table extensions

Synergy Software Systems at the Microsoft Manufacturing Masterclass-

September 27th, 2017

A packed house for the Microsoft Manufacturing Masterclass today with stimulating presentations on Digital transformation.

Security security security

September 26th, 2017

You never know when some item that queries or alters data in SQL Server will cause issues.

Bruce Schneier recently commented on FaceID and Bluetooth security, the latter of which has a vulnerability issue. I was amazed to see his piece on infrared camera hacking. A POC on using light to jump air gaps is truly frightening. It seems that truly anywhere that we are processing data, we need to be thinking (see https://arstechnica.com/information-technology/2017/09/attackers-can-use-surveillance-cameras-to-grab-data-from-air-gapped-networks/)

Airborne attacks, unfortunately, provide a number of opportunities for the attacker. First, spreading through the air renders the attack much more contagious, and allows it to spread with minimum effort. Second, it allows the attack to bypass current security measures and remain undetected, as traditional methods do not protect from airborne threats. Airborne attacks can also allow hackers to penetrate secure internal networks which are “air gapped,” meaning they are disconnected from any other network for protection. This can endanger industrial systems, government agencies, and critical infrastructure. With BlueBorne, attackers can gain full control right from the start. Moreover, Bluetooth offers a wider attacker surface than WiFi, almost entirely unexplored by the research community and hence contains far more vulnerabilities

Finally, unlike traditional malware or attacks, the user does not have to click on a link or download a questionable file. No action by the user is necessary to enable the attack.

Fully patched Windows and iOS systems are protected

– the Equifax breach for example must worry everyone who has ever had credit in the USA. (Hackers broke into Equifax’s computer systems in March, which is two months earlier than the company had previously disclosed, according to a Wall Street Journal report.)

The Securities and Exchange Commission said Wednesday that a cyber breach of a filing system it uses may have provided the basis for some illegal trading in 2016. In a statement posted on the SEC’s website, Chairman Jay Clayton said a review of the agency’s cybersecurity risk profile determined that the previously detected “incident” was caused by “a software vulnerability” in its EDGAR filing system (which processes over 1.7 million electronic filings in any given year.) The agency also discovered instances in which its personnel used private, unsecured email accounts to transmit confidential information.

So let me suggest take a good look at your systems and be honest – do you feel safe?

Microsoft has released Microsoft 365, a complete, intelligent solution, including Office 365, Windows 10, and Enterprise Mobility + Security, that empowers everyone to be creative and work together, securely. Watch Satya introduce it.

What about your websites?
Although acts of vandalism such as defacing corporate websites are still commonplace, hackers prefer to gain access to the sensitive data residing on the database server and then to sell the data.

The costs of not giving due attention to your web security are extensive and apart form direct financial burden and inconvenience also risks:
• Loss of customer confidence, trust and reputation with the consequent harm to brand equity
• Negative impact on revenues and profits arising e.g. from falsified transactions, or from
employee downtime
• Website downtime – is in effect the closure of one of the most important sales and marketing channels
especially for an e-business
• Legal battles and related implications from Web application attacks and poor security
measures including fines and damages to be paid to victims.

Web Security Weaknesses
Hackers will attempt to gain access to your database server through any way they can e.g. out of date protocols on a router. Two main targets are :
• Web and database servers.
• Web applications.

Information about such exploits are readily available on the Internet, and many have been reported on this blog previously.

Web Security Scanning
So no surprise that Web security should contain two important components: web and database server security, and web application security.

Addressing web application security is as critical as addressing server security.

Firewalls and similar intrusion detection mechanisms provide little defense against full-scale web
attacks.
Since your website needs to be public, security mechanisms allow public web traffic to
communicate with your web and databases servers (i.e. over port 80).

It is of paramount importance to scan the security of these web assets on the network for possible vulnerabilities. For example, modern database systems (e.g. Microsoft SQL Server, Oracle and MySQL) may be
accessed through specific ports and so anyone can attempt direct connections to the databases to try and bypass the security mechanisms used by the operating system. These ports remain open to allow communication with legitimate traffic and therefore constitute a major vulnerability.

Other weaknesses relate to the database application itself and the use of weak or default passwords by
administrators. Vendors patch their products regularly, and equally regularly find new ways of
attack.

75% of cyber attacks target weaknesses within web applications rather than directly at the
servers. Hackers launch web application attacks on port 80 . Web applications are more open to uncovered vulnerabilities since these are generally custom-built and therefore pass through a lesser degree of
testing than off-the-shelf software.

Some hackers, for example, maliciously inject code within vulnerable web applications to trick users
and redirect them towards phishing sites. This technique is called Cross-Site Scripting (XSS) and may
be used even though the web and database servers contain no vulnerability themselves.

Hence, any web security audit must answer the questions “which elements of our network
infrastructure are open to hack attacks?”,
“which parts of a website are open to hack attacks?”, and “what data can we throw at an application to cause it to perform something it shouldn’t do?”

Ask us about Acunetix and Web Security
Acunetix ensures web site security by automatically checking for SQL Injection, Cross Site Scripting,
and other vulnerabilities. It checks password strength on authentication pages and automatically
audits shopping carts, forms, dynamic content and other web applications. As the scan is being
completed, the software produces detailed reports that pinpoint where vulnerabilities exist

Industry 4.0 : Digitalization of the Manufacturing Sector Masterclass – Meet Synergy Software Systems Manufacturing experts tomorrow H Hotel Dubai

September 26th, 2017

Hear from industry experts, network, meet with us and let us show you Dynamics 365 Finance and Operations Enterprise at this Microsoft Gul sponsored Manufacturing Master Class.

08:00 – 09:00 Registration
09:00 – 09:20 Omar Saleh – Microsoft – Industry Director, Manufacturing MEA
09:20 – 09:50 Gert Thoonen – Business Development Network & Security Services, ME – Rockwell Automation
09:50-10:20 Nicholas Brunet – Middle East Regional Business Leader – 3M
10:20-10:50 Mustafa Farhan – Strategic Transformation Lead, Middle East and Africa, Microsoft
Break
11:00 – 11:30 Suryanka Jatain – Principal – Digital Strategy and Transformation – KPMG
11:30 – 12:00 Assem Khalaili – Executive Vice President, Customer Services – MEA Digital Factory – Process Industries & Drives – Siemens
12:00 – 12:30 Charif Hamidi – Senior Consultant – Strategy – EY

Join us for lunch.
If you have not yet registered then call us now on 00971 43365589 or email Suresh Savari

Dynamics 2012 R3 CU13 – available for Synergy Software Systems’ Customers

September 20th, 2017

Compatibility:
Windows Server 2016 is supported with AX 2012 R3 CU 13.
Microsoft Visual Studio Team Foundation Server 2017 is now supported with AX 2012 R3 CU 13.
Microsoft SQL Server 2016 SP 1 is supported with AX 2012 R3 CU 13.

Cortana intelligence services management – showcases Recommendations API integration in Dynamics AX 2012 R3.
Use this capability to create a machine learning model and train that model generate recommendations.
Use this as a reference implementation, and then connect more Cognitive Service APIs or to bring other Cortana intelligence based insights into your Dynamics AX solution.
For more detailed information, review the Cortana Intelligent Services management white paper – available from us on request.

There are a number of enhancements/hotfixes related to DIXF.
A new feature enables an alternate way to report a carry-forward budget. The feature maintains the carry-forward status on relieving documents that were based on an originating document carried
forward.
(If you change functionality mid-year, and not after year-end, then retroactively update the budget for any transactions for the current year.
This feature cannot be disabled after it’s enabled, because transactions which )would not be considered carry-forward might have occurred using the alternate configuration
)

Reprocessing of documents against Budget control. When issues are found, the budget manager can inquire into the documents that were found and reprocess these. After reprocessing, the data maintenance process
becomes a read-only record of the documents that were found, as well as showing the results of the reprocessing.
To update the Ledger takes a long time to run Advanced ledger allocation basis rules, as the TempDB fills up -this addresses that issue.

Many retail enhancements – here are a few:

In Retail the maximum number of fields you can add to a receipt footer is increased from 50 to 100.

Customer data privacy – extra fields in the Customer table indicate privacy choices, such as do not call,
email, text, and so on, for all interfaces in all channels

A Post-sync channel DB clean up will reduce data volume.

The X Report and Z Report (in POS and HQ)will no longer include the amounts from the sales quotations.

A feature is added to display/check loyalty card point balance on the Customer detail, Store operation and Loyalty payment page.

A performance issue arises on the Retail Sales form when there are a large number of SQL records in the AX database. KB 4024615 hotfix adds a Search button, and changes the process so that the query is run only when the button is clicked.

A new control allows users to sell (and return) items outside the store assortment.
A credit memo is created without reference at AX HQ if the credit memo is created during a time when the network at the store is down. KB 4021760 hotfix clears the credit memo that was created previously before creating a replacement.

These are some SCM enhancements that also impact performance:
‘Select packing slip’ takes a long time to process for an intercompany Sales Order when the sales policy is set to Unit price equal to cost price – whichis common practice.
KB 3212427 hotfix resolves the performance issue by optimizing data access and improving the performance of the business logic.

When you have a large number of bills of materials (BOMs), bill of materials lines, or BOM versions, you may experience that the performance of the BOM circularity check, that is optimized for high complexity, is not
acceptable. The hotfix he hotfix improve performance of the BOM circularity check, that is optimized for high complexity, in scenarios where you have a large number of bills of materials (BOMs), bill of materials lines, or BOM versions.

Much much more…..contact us to find out.

Microsoft Modern Lifecycle Policy (and Dynamics 365 Finance and Operations)

September 20th, 2017

When you move to Dynamics 365 Finance and Operations, whether on cloud or on premise, ensure your understand the requirements to keep your system updated. The Modern Lifecycle Policy covers products and services that are serviced and supported continuously.

https://support.microsoft.com/en-us/help/30881/modern-lifecycle-policy

The Finance and Operations online service and the Finance and Operations (on-premises) software are covered by the Modern Lifecycle Policy. Licensed customers must stay current with updates to the Finance and Operations online service or the Finance and Operations (on-premises) software in accordance with the following servicing and system requirements:
•Starting with the release of Microsoft Dynamics 365 for Operations version 1611, application versions are supported for three years from the initial date of a major release, as specified in Table 1 later in this topic.

Platform versions are supported for one year . Platform versions maintain backward compatibility. . Critical fixes and non-critical updates are handled in the following way:

Critical fixes – Microsoft may provide a customer with a hotfix for their current platform version of Finance and Operations, or a fix may be provided in the latest platform version of Finance and Operations, at its discretion.

Non-critical updates – Customers must update to the most current Finance and Operations platform version to deploy non-critical updates.

On-premises software update policies

On-premises deployments
The customer is in full control of its on-premises deployments and must follow this policy. The customer is in control of installing updates in its on-premises environments. Microsoft will support the Finance and Operations (on-premises) software through December 31, 2027, at a minimum, but only if the customer keeps the deployed software current according to this policy.

The Finance and Operations (on-premises) software is licensed and supported under the Modern Lifecycle Policy. This policy requires that the customer maintain Software Assurance (SA) or the Enhancement Plan, and that it deploys updates . Customers who want to use the Fixed Support Lifecycle Policy (5+5) must downgrade to Microsoft Dynamics AX 2012 R3.

When a customer lapses on SA or the Enhancement Plan, then it will be eligible only for the perpetual license rights to AX 2012 R3 and must uninstall the Finance and Operations (on-premises) software.

The initial release of the Finance and Operations (on-premises) software will be based on Platform update 8 and the July 2017 update of the application.

For details of what changed with which each update see https://docs.microsoft.com/en-us/dynamics365/unified-operations/dev-itpro/get-started/what’s-new-changed.

Be aware also if deployed on premise of related products like SQL, Windows, Office, Internet Explorer, Visual Studio, Sharepoint etc that may also need to be upgraded.

Note that both Microsoft Dynamics AX 2012 and Microsoft Dynamics AX 2012 R2 support will end in 2018

Here are some products for which support will end in 2018 start planning:
The following list represents some of the products reaching end of support in the next year. For a comprehensive list of Microsoft products and their lifecycle policy timelines, please search the Microsoft Lifecycle Product Database.
Products Under the Modern Policy Moving to End of Support:
The following products, governed by the Modern Policy, have announced end of support for 2018. There will be no new security updates, non-security updates, free or paid assisted support options or online technical content updates.

Products Under the Modern Policy Moving to End of Support
Effective end dates are shown against each>

Microsoft Azure Mobile Engagement March 31, 2018
Parature, from Microsoft
Microsoft Dynamics Marketing May 15, 2018
Adxstudio Portals v7 October 9, 2018

Fixed Policy Products Moving to End of Support:
The following products will be reaching end of support in 2018. There will be no new security updates, non-security updates, free or paid assisted support options or online technical content updates.

Microsoft Dynamics C5 2014
Microsoft Expression Encoder
Microsoft Office Communications Server 2007, all editions
Microsoft Office Communications Server 2007 R2, all editions
Microsoft Office Communicator 2007
Microsoft Office Communicator 2007 R2
Microsoft Office Communicator 2007 R2 Phone Edition
Microsoft Office PerformancePoint Server 2007
Microsoft PlayReady Server Software Development Kit v. 2.0
Microsoft System Center Data Protection Manager 2007
Microsoft System Center Virtual Machine Manager 2007
Windows Embedded Device Manager 2011
Windows Embedded Device Manager Software Development Kit
Windows 10 Mobile Enterprise, released in November 2015**
Windows 10 Mobile, released in November 2015**

January 9, 2018

FAST Unity 2.5 April 1, 2018
Microsoft SQL Server Compact 3.5
Microsoft Visual Studio 2008, all editions
Microsoft Visual Studio Team System 2008, all editions
Microsoft Visual Studio Team System 2008 Team Foundation Server
Microsoft Dynamics CRM 4.0
Microsoft Office Accounting 2008, all editions
Microsoft System Center Capacity Planner 2007
Microsoft Visual Basic 2008 Express Edition
Microsoft Visual C# 2008 Express Edition
Microsoft Visual Web Developer 2008 Express Edition
Windows Embedded CE 6.0

April 10, 2018

FAST Featured Content 1.3
FAST Recommendations 2.2 April 23, 2018
FAST ESP 5.2 May 9, 2018
FAST ImPulse 5.0 July 1, 2018
Microsoft System Center Mobile Device Manager 2008
Microsoft Search Server 2008, all editions
StorSimple 5000/7000 Series
Windows Web Server 2008
July 10, 2018

FAST ESP 5.3 July 16, 2018
FAST Recommendations 2.5 October 8, 2018
Lync for Mac 2011
Lync Meeting room
Microsoft Enterprise Desktop Virtualization
Microsoft Expression Blend 2
Microsoft Expression Design 2
Microsoft Expression Encoder 2
Microsoft Expression Studio 2
Microsoft Expression Web 2

October 9, 2018

FAST AdMomentum 3 November 2, 2018
Microsoft Forefront Threat Management Gateway, Medium Business Edition November 12, 2018
FAST ImPulse 5.1 December 18, 2018

Products Transitioning from Mainstream to Extended Support: The following products will be moving from Mainstream Support into Extended Support over the next year. Extended Support lasts for a minimum of 5 years and includes security updates at no cost, and paid non-security updates and support. Additionally, Microsoft will not accept requests for design changes or new features during the Extended Support phase.

Products Moving from Mainstream to Extended Support

Microsoft Application Virtualization 5.1 for Remote Desktop Services
Microsoft Application Virtualization 5.1 for Windows Desktops
Microsoft Application Virtualization Hosting 5.1 for Windows Desktops
Microsoft Dynamics NAV 2013
Microsoft Dynamics NAV 2013 R2
Microsoft Hyper-V Server 2012
Microsoft Hyper-V Server 2012 R2
Microsoft Visual Studio 2012 Software Development Kit
Microsoft Visual Studio 2012 Tools for Applications Software Development Kit
Service Bus for Windows Server
Windows 8.1, all editions
Workflow Manager 1.0
Workflow Manager Client 1.0
Workflow Manager Tools for Visual Studio 2012

January 9, 2018

Exchange Server 2013, all editions
Microsoft Access 2013
Microsoft Advanced Group Policy Management 4.0
Microsoft Dynamics AX 2009
Microsoft Dynamics GP 2013
Microsoft Excel 2013
Microsoft HPC Pack 2012
Microsoft HPC Pack 2012 R2
Microsoft Lync 2013
Microsoft Lync Phone Edition
Microsoft Lync Server 2013, all editions
Microsoft Office 2013
Microsoft Office Web Apps Server 2013
Microsoft OneNote 2013
Microsoft Outlook 2013
Microsoft PowerPoint 2013
Microsoft Project 2013, all editions
Microsoft Project Server 2013
Microsoft Publisher 2013
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft Visio 2013
Microsoft Word 2013
Skype for Business 2015

April 10, 2018

Microsoft Lync 2013 Software Development Kit April 20, 2018
BizTalk Server 2013, all editions
BizTalk Server 2013 R2, all editions
Microsoft BitLocker Administration and Monitoring 2.0
Windows Embedded 8 Standard
Windows Embedded 8.1 Industry Enterprise
Windows Embedded 8.1 Industry Pro

July 10, 2018

Microsoft Audit and Control Management Server 2013
Microsoft Dynamics AX 2012
Microsoft Dynamics AX 2012 R2

Microsoft SQL Server 2012 Parallel Data Warehouse
Windows Embedded Compact 2013
Windows Multipoint Server 2012, all editions
Windows Server 2012, all editions
Windows Server 2012 R2, all editions
Windows Server Update Services for Windows Server 2012
Windows Storage Server 2012, all editions
Windows Storage Server 2012 R2, all editions

October 9, 2018
** = Windows 10 follows the Windows as a Service (WaaS) lifecycle.

Management reporter 2012 CU16 recent hotfixes

September 10th, 2017

Hotfix 3813390 can be downloaded here:

https://mbs.microsoft.com/Files/customer/MgmtReporter/Downloads/Servicepacks/ManagementReporter2012-CU16-Hotfix-3813390-en-us-update.exe

This hotfix addresses the issue where user security may be removed during Company to Company mapping when there is a SQLException.
If a SQLException occurs during the AX 2012 Companies to Company integration task, such as SQL server being offline, then users may be removed from the security groups in Management Reporter Security and from reporting tree definitions.
Once the cause of the SQL exception is corrected, the data mart integration task will complete, and users will once again be synchronized from Dynamics AX and added to Management Reporter Security, except they will have new user IDs.
The users with new IDs are then not added to the groups/trees that they were in previously.
This issue is logged as bug 3813390. Hotfix 3813390 prevents this issue from occurring.


Hotfix 3815274 is an optional hotfix that can be applied to CU16.
It can be loaded to revert a CU16 change with reporting tree rollups.
The hotfix will allow children nodes to be rolled up to a parent that contains a Dimension filter.
Before making any changes, be sure to have a backup of the MRServiceHost.settings.config file.
You can then do the following:
1. Open the Management Reporter Configuration Console.
You will need to be logged in as a user that has the Administrator role in MR, when starting the console.
2.Stop both the Process Service and the Application Service.
3.Navigate to “C:\Program Files\Microsoft Dynamics ERP\Management Reporter\2.1\Server\Services\MRServiceHost.settings.config”
4.Edit the config file in Notepad and then add the following line.
This will change the functionality such that dimension filters on summary tree units will be ignored (pre-CU15 functionality):

This new line should be added before the

1.Save your changes and close Notepad.
2.In the Management Reporter Configuration Console, start the Process Service and the Application Service.
Once the services are restarted, re-generate your reports for the changes to be applied.

Hotfix 3815274 can be downloaded here:

https://mbs.microsoft.com/files/customer/MgmtReporter/Downloads/ProductReleases/ManagementReporter2012-CU16-Hotfix-3815274-en-us-update.exe

SQL Server 2014 SP2 CU7

September 3rd, 2017

The 7th cumulative update release for SQL Server 2014 SP2 is available for download at the Microsoft Downloads site.
Registration is no longer required to download Cumulative updates.

• CU#7 KB Article: https://support.microsoft.com/en-us/help/4032541/cumulative-update-7-for-sql-server-2014-sp2
• Microsoft® SQL Server® 2014 SP2 Latest Cumulative Update: https://www.microsoft.com/en-us/download/details.aspx?id=53592
• Update Center for Microsoft SQL Server: http://technet.microsoft.com/en-US/sqlserver/ff803383.aspx

Microsoft Dynamics 365 for Sales, Business Edition – ask Synergy Software Systems Dubai

August 30th, 2017

Later this year Dynamics CRM and Dynamics AX will come together to create the Microsoft Dynamics 365 Enterprise edition.

Microsoft Dynamics 365 Business Edition is the set of intelligent Cloud business applications for SMBs with 10-249 employees. (the ‘Dynamics Ax’ part of D365 is targeted at Enterprise companies i.e. above 250 users).
Dynamics 365 Business Edition includes Dynamics 365 for Financials, (which is based the proven Dynamics NAV financials). Microsoft Dynamics 365 for Financials is already available in the USA, Canada and UK, followed by a phased roll out to additional countries.

The Sales and Marketing modules of the Business edition of Dynamics 365 will debut during 2017. CRM Online is now called Dynamics 365 for Sales.

Other than the name Microsoft Dynamics 365 for Sales, Business Edition (I will call it D365SBE) stems from Microsoft CRM Online. Microsoft has really improved and invested in Microsoft Dynamics 365 for Sales Business Edition.The Business edition will be founded on “Project Madeira” (It is in public preview now).

Until this is available SMBs can license Dynamics 365 for Sales from the Dynamics 365 Enterprise Edition at a significantly reduced monthly price per user – until the Business Edition apps are launched.

Leads, Accounts, Contacts, Opportunities, Activities, Marketing Lists, etc. are all expected in the Business Edition when it is released in a few months The pricing is still to be released, expect Microsoft to target at an entry level price around $40 to $65 per user per month.

Mobile and the Outlook app. One click will let you add a contact from whom get an email into to D365SBE. Learn more here:

https://docs.microsoft.com/en-us/dynamics365/get-started/whats-new/customer-engagement/new-in-business-edition

GDPR Affects All European Businesses – What about the G.C.C. and U.A.E.?

August 19th, 2017

See our previous article on this topic for why your company may be affected if you are a branch of a European company, or have branches in Europe, or trade with a European company.

From May 25, 2018, companies with business operations inside the European Union must follow the General Data Protection Regulations (GDPR) to safeguard how they process personal data “wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.”

The penalties set for breaches of GDPR are up to 4% of a company’s annual global turnover.
For large companies like Microsoft that have operations within the EU, making sure that IT systems do not contravene GDPR is critical. As we saw on August 3, even the largest software operations like Office 365 can have a data breach.

Many applications can store data that might come under the scope of GDPR. the regulation has a considerable influence over how tenants deal with personal data. The definition of personal data is “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
GDPR goes on to define processing of personal data to be “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”

That means that individuals have the right to ask companies to tell them what of their personal data a company holds, and to correct errors in their personal data, or to erase that data completely.

Companies therefore need to:
- review and know what personal data they hold,
- make sure that they obtain consents from people to store that data,
– protect the data,
- and notify authorities when data breaches occur.

On first reading, this might sound like what companies do – or at least try to do – today. The difference lies in the strength of the regulation and the weight of the penalties should anything go wrong.

GDPR deserves your attention.

The definitions used by GDPR are broad. To move from the theoretical to the real world an organization first needs to understand what personal data it currently holds for its business operations, and where they use the data within software applications.

It is easy to hold personal information outside of business applications like finance and erp and crm e.g. inside Office 365 applications, including:
• Annual reviews written about employees stored in a SharePoint or OneDrive for Business site.
• A list of applicants for a position in an Excel worksheet attached to an email message.
• Tables holding data (names, employee numbers, hire dates, salaries) about employees in SharePoint sites.
• Outlook contacts, and emails. Skype business,
• Social media sites
• Loyalty programmes
• T@A systems
• E commerce sites
• Mobile apps e.g. What’s App

Other examples might include contract documentation, project files that includes someone’s personal information, and so on.

What backups do you have of the customer’s data?
What business data do your staff hold on BYOD devices e.g. in What’s App?

Data Governance Helps
Fortunately, the work done inside Office 365 in the areas of data governance and compliance help tenants to satisfy the requirements of GDPR. These features include:
• Classification labels and policies to mark content that holds personal data.
• Auto-label policies to find and classify personal data as defined by GDPR. Retention processing can then remove items stamped with the GDPR label from mailboxes and sites after a defined period, perhaps after going through a manual disposition process.
• Content searches to find personal data marked as coming under the scope of GDPR.
• Alert policies to detect actions that might be violations of the GDPR such as someone downloading multiple documents over a brief period from a SharePoint site that holds confidential documentation.
• Searches of the Office 365 audit log to discover and report potential GDPR issues.
• Azure Information Protection labels to encrypt documents and spreadsheets holding personal data by applying RMS templates so that unauthorized parties cannot read the documents even if they leak outside the organization.

Technology that exists today within Office 365 that can help with GDPR.

Classification Labels
Create a classification label to mark personal data coming under the scope of GDPR and then apply that label to relevant content. When you have Office 365 E5 licenses, create an auto-label policy to stamp the label on content in Exchange, SharePoint, and OneDrive for Business found because documents and messages hold sensitive data types known to Office 365.

GDPR sensitive data types

Select from the set of sensitive data types available in Office 365.
The set is growing steadily as Microsoft adds new definitions.
At the time of writing, 82 types are available, 31 of which are obvious candidates to use in a policy because those are for sensitive data types such as country-specific identity cards or passports.

Figure 1: Selecting personal data types for an auto-label policy (image credit: Tony Redmond)

GDPR Policy

The screenshot in Figure 2 shows a set of sensitive data types selected for the policy. The policy applies a label called “GDPR personal data” to any content found in the selected locations that matches any of the 31 data types.

Auto-apply policies can cover all Exchange mailboxes and SharePoint and OneDrive for Business sites in a tenant – or a selected sub-set of these locations.


Figure 2: The full set of personal data types for a GDPR policy (image credit: Tony Redmond)

Use classification labels to mark GDPR content so that you can search for this content using the ComplianceTag keyword (for instance, ComplianceTag:”GDPR personal data”).

Caveats:
It may take 1-2 week before auto-label policies apply to all locations.
An auto-label policy will not overwrite a label that already exists on an item.

A problem is that classification labels only cover some of Office 365. Some examples of popular applications where you cannot yet use labels are:
• Teams.
• Planner.
• Yammer.

Microsoft plans to expand the Office 365 data governance framework to other locations (applications) over time.
Master data management
What about all the applications running on SQL or other databases?
Master Data Management MDM is a feature of SQL since SQL 2012. However, when you have many data sources then you are relay into an ETL process and even with MDM tools the work is still significant.

If you have extensive requirements then ask us about Profisee our specialist, productized MDM solution built on top of SQL MDM that allows you to do much of the work by configuration.

Right of Erasure
Finding GDPR data is only part of the problem. Article 17 of GDPR (the “right of erasure”), says: “The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay.” In other words, someone has the right to demand that an organization should erase any of their personal data that exists within the company’s records.

Content searches can find information about someone using their name, employee number, or other identifiers as search keywords, but erasing the information is something that probably also needs manual processing to ensure that the tenant removes the right data, and only that data.

You can find and remove documents and other items that hold someone’s name or other identifier belonging to them by using tools such as Exchange’s v Search-Mailbox cmdlet, or Office 365 content searches.
What if the the data ahs to be retained because the company needs to keep items for regulatory or legal purposes, can you then go ahead and remove the items?
The purpose of placing content on-hold is to ensure that no-one, including administrators, can remove that information from Exchange or SharePoint.

The GDPR requirement to erase data on request means that administrators might have to release holds placed on Exchange, SharePoint, and OneDrive for Business locations to remove the specified data. Once you release a hold, you weaken the argument that held data is immutable. The danger exists that background processes or users can then either remove or edit previously-held data and so undermine a company’s data governance strategy.

The strict reading of GDPR is that organizations must process requests to erase personal data upon request.
What if the company needs to keep some of the data to satisfy regulations governing financial transactions, taxation, employment claims, or other interactions? This is a dilemma for IT. Lawyers will undoubtedly have to interpret requests and understand the consequences before making decisions and it is likely that judges will have to decide some test cases in different jurisdictions before full clarity exists.

Hybrid is even More Difficult

Microsoft is working to help Office 365 tenants with GDPR. However, I don’t see the same effort going to help on-premises customers. Some documentation exists to deal with certain circumstances (like how to remove messages held in Recoverable Items), but it seems that on-premises customers have to figure out a lot things for themselves.

This is understandable. Each on-premises deployment differs slightly and exists inside specific IT environments. Compared to the certainty of Office 365, developing software for on-premises deployment must accommodate the vertical and company specific requirements with integrations and bespoke developments.

On-premises software is more flexible, but it is also more complicated.
Solutions to help on-premises customers deal with GDPR are more of a challenge than Microsoft or other software vendors wants to take on especially given the industry focus of moving everything to the cloud.

Solutions like auto-label policies are unavailable for on-premises servers. Those running on-premises SharePoint and Exchange systems must find their own ways to help the businesses that they serve deal with personal data in a manner that respects GDPR. Easier said than done and needs to start sooner than later.

SharePoint Online GitHub Hub

If you work with SharePoint Online, you might be interested in the SharePoint GDPR Activity Hub. At present, work is only starting, but it is a nway to share information and code with similarly-liked people.

ISV Initiatives

There many ISV-sponsored white papers on GDPR and how their technology can help companies cope with the new regulations. There is no doubt that these white papers are valuable, if only for the introduction and commentary by experts that the papers usually feature. But before you resort to an expensive investment, ask yourself whether the functionality available in Office 365 or SQL is enough.

Technology Only Part of the Solution

GDPR will effect Office 365 because it will make any organization operating in the European Union aware of new responsibilities to protect personal data. Deploy Office 365 features to support users in their work, but do not expect Office 365 to be a silver bullet for GDPR. Technology seldom solves problems on its own. The nature of regulations like GDPR is that training and preparation are as important if not more important than technology to ensure that users recognize and properly deal with personal data in their day-to-day activities.