Showing posts with label just. Show all posts
Showing posts with label just. Show all posts

Wednesday, February 4, 2026

Compliant Cloud Computing

Okay, great.
Well first off we just
wanna welcome everyone for
coming to our session today.
Thank you very much.
My name is Dennis Garcia, I'm
an Assistant General Counsel for
Microsoft.
I'm based in Chicago.
I lead Microsoft's legal
support function to our
US Central Region Enterprise and
partner group team.
We're gonna have a conversation
today about compliant cloud
computing.
I will let my fellow panelists
introduce themself individually.
Edward.
>> I am Edward Efkeman,
I am with Fed-Ex.
I am a director of compliance
within the legal department.
So we have a compliance
department but
it is within
the legal department.
My responsibility is somewhat
outward facing customers and
data privacy.
Data protection is within
my area of responsibility.
>> Hi, I'm Darryl Hobbs.
I'm also at Microsoft.
I support what's known as
Microsoft's mid market business.
So I like to think of it like
we have our top customers, and
then our mid market,
which is everything else,
about 6 million customers
that we sell to.
So it's a breath business,
I sell across almost
every industry.
So I see a lot of different
things on a daily basis,
and happy to be here.
>> My name is Jude Soundar.
I work for
the Army General Counsel.
I'm an ethics attorney and
my profile includes financial
disclosure and social media I'm
also the program manager for
Financial Disclosure and
Management.
It's the main application
that DOD uses for
financial disclosure.
Basically all senior
officials in DOD and actually
government must disclose their
assets and liabilities so
we can do a conflict analysis
to make sure that there's no
conflicts with the DOD and
the work that they are doing.
I'm also an Army reservist,
a major in the Army Reserve.
And I'm a JAG attorney also and
I do work around
conflict minerals and
other issues like that.
>> Well, great, thank you very
much guys, I appreciate it.
So in terms of a format today,
we thought what we'd do is,
recognizing that folks may
have different degrees of
understanding as to what
cloud computing is all about.
We wanted to take a step
back and provide a basic
overview of cloud computing,
what I call a Cloud 101.
So I'll provide a 10 to 12
minutes overview of the cloud,
if you will.
And then we'll switch gears and
we'll open it up to various
questions to the panelists.
And we want this to be
highly participatory.
So to the extent that
folks have any questions,
don't be shy in answer,
asking your questions.
We're here to address any
questions that you have.
So feel free to chime in.
So what I'm gonna give
is sort of a layperson's
overview of the cloud.
Of course I'm a lawyer,
I'm not an engineer,
so I'm not gonna get into
the tactical details per say.
So this is gonna be more
of a cloud computing for
compliance professionals.
And I think a great place to
start when you're thinking
about the cloud is to realize
that whether we like it or
not, whether we realize it or
not we're all using the cloud
each and every day as part of
our personal lives, right?
After all, many of us have
been using web hosted email
since the late 1990s, right?
To send message use to
friends and family.
I know when I started using web
hosted email Was it was through
an AOL.com account,
I moved to a Yahoo account.
Of course now I'm
working at Microsoft,
I have a live.com account.
But all of us are sending
emails each and everyday, and
that is largely powered
by cloud computing.
So many of us have smart
phones nowadays, right?
I know I have a smart phone,
I use my smartphone
probably too much.
A lot of that data which is
generated though our phone is
stored in the cloud and
of course,
many of us are using
social media.
Each and every day.
I'm a big fan of Facebook,
I use LinkedIn.
I'm a big fan of Twitter.
Social media is largely
powered by the cloud.
So the cloud really
isn't anything so new.
And it's become more and
more a ubiquitous part
of our everyday lives.
In terms of a definition
of the cloud.
Like a lot of technologies,
there's no one uniform
definition of cloud computing.
There's a variety of definitions
but the National Institute of
Standards and Technology which
is part of the Department of
Commerce, and of course they're
only a few blocks away.
Back in 2011 they put together
a white paper with a pretty
involved definition of cloud
computing which has become more
of the defacto industry standard
definition of cloud computing.
I'm not gonna cover
that definition.
It's a pretty involved and
robust definition.
If you wanna look
at the white paper,
by all means take a look at
the citation on my slide.
But I prefer this more
straightforward and simpler
definition of cloud computing,
which I found in a legal ethics
opinion from the state of
Pennsylvania a few years ago.
And in that opinion they talked
about how cloud computing
is really a fancy way of saying
stuff's not on your computer.
And you may say, well Dennis
that's really an over
simplification.
But I think in many respects
this captures the essence
of what the cloud is all about,
because the cloud is really
all about this notion of
off-premises remote computing.
So when I joined Microsoft
back in December of 2002,
the primary way which we
provided our solutions and
our software was through
software licences so that our
software could be downloaded and
then installed on our customer's
servers and work stations and
machines which were on their
on premises environment within
the firewall of their companies.
But the whole notion of moving
to the cloud is that you'll get
services and software on
a remote basis by a third party
cloud services provider.
So it's being provided
remotely and off premise.
The cloud is also all
about the data centers.
A lot of folks think about the
cloud as being something which
is amorphous and
touchy and feely, but
it's really bricks and
mortars at the end of the day.
It's really all about
these data centers.
And of course these data centers
are massive, massive facilities.
They are the size of
football fields and
they contain racks and racks of
servers and computing equipment.
And at Microsoft,
of course we have lots of data
servers throughout the world.
We actually have over
100 data centers in
over 40 different
countries in the world.
Last week we announced
that we're gonna be
having data centers,
effective 2018,
in Africa,
in South Africa actually.
And we're the first major cloud
provider to have a data centers
in the African continent.
So when you think about
the cloud, it's really tangible,
it's really powered by these
massive data center facilities,
which should also be highly
secured environments.
When you think about the cloud,
you're always thinking
the cloud is provided in
three different forms, what I
call the big three of the cloud.
The first part of that Big 3
is something known as software
as a service, where in essence,
software is provided to
you through the Internet.
We think a great example
of software as a service is
Microsoft Office 365 Solution,
where you can get anytime,
anywhere access Microsoft Office
suite of products just by having
a connection to the Internet.
A second type of cloud
computing is something known as
infrastructure as a service.
Also really known as
hardware as a service.
So leading provider in this
space is Amazon web services,
Microsoft also has
a competing solution known as
Microsoft Azure.
And the whole basis of
infrastructure as a service is
that you can buy on
a subscription basis,
computing power,
hardware power, server power.
You can store your data
with an infrastructure
as a services provider.
A final mode of cloud computing
It's something known as
platform as a service.
This is generally
geared to developers,
people who are creating
information technology such as
web applications,
mobile applications and
platform as a service provides
you with a virtual sandbox
where you can engage in
development sorts of activities.
Now there's lots of benefits
associated with
moving to the cloud.
One of the benefits we speak to
with our customers is that we
believe that you can save a lot
of money by moving to the cloud.
By moving away from an on
premises environment
because you no longer have to
buy servers or rent servers.
You don't have to power
those servers up,
you don't need to have space for
those servers,
you don't need to have somebody
to maintain those servers.
So there's lots of business,
financial advantages by
moving to the cloud.
It's also highly scalable,
so you can, if
your business is very seasonal
in nature as an example.
If you need more cloud
services you can ramp up or
ramp down depending
upon your need.
We feel it also allows
our customers to
focus on their core business.
So they really get out of
information technology,
let the expert handled that,
and that they can better
serve there customers.
And assuming that your working
with a trusted cloud provider or
a reliable cloud provider.
There's also this perspective
that you could probably be
more secure providing your data
to a trusted cloud provider and
that they could do a better
job at protecting that data
versus what you can do
on premises environment.
In fact,
most cloud providers push out
updates to their solutions and
to their software.
So we saw a few weeks ago
with the Wannacry situation
where various companies did
not upgrade their Windows
operating system.
If you're working with
a cloud services provider,
those updates are pushed
out automatically.
Now some folks have
identified various concerns
in moving to the Cloud.
Some folks believe that the act
of providing their data,
and their customer's data,
and their partner's data,
to a third party can be
inherently unstable and
it can cause maybe
some security concerns.
We hear that, on occasion,
from some of our customers.
There's this perspective that,
perhaps the larger cloud
services providers could be
viewed as a bigger target for
potential cyber criminals and
hackers.
Sometimes, when you're moving to
the cloud you may have to also
migrate data to a cloud
services provider.
There could be time and effort
and cost associated with that.
So folks have also
identified some
potential concerns in
moving to the cloud.
But regardless, we have seen
that over the last few years
that the cloud marketplace
has grown exponentially.
Here is a survey done by
the Forrester Research Group
where they talk about how
the cloud marketplace is gonna
be growing to almost
$250 billion by 2020.
And so it's become big
business cloud computing.
And because of that
there are a number
of cloud services
providers out there.
It's become what I
call sort of a crowded
cloud provider marketplace.
A lot of times,
companies aren't sure which
cloud provider they
should select and choose.
And so
when I look at the marketplace,
I view the marketplace really
being in four categories.
The first category
are the traditional information
technology providers who
are providing cloud solutions.
Companies like my company,
IBM and Oracle.
Then there is this
other category of
providers who like to say
they've been born in the cloud.
I'm not sure what born in
the cloud really means.
But those providers
are the Googles, the Amazons,
the Salesforce.coms.
There's also a third category
of smaller cloud providers which
are out there, some of them
make money, some of them don't.
Some of them maybe
an acquisition for
a target for an acquisition
by another company.
Then I think a fourth category
are these providers who perhaps
were really never in the
information technology space,
but they've re-engineered their
business to get involved in
cloud computing and
offer cloud storage solutions.
Examples of those companies
are the phone companies,
telephony companies.
Companies like AT&T and Verizon.
But a key point and one of the
key takeaways, I think from our
discussion today is if you're
thinking about moving to cloud,
and lots of entities are and
have already moved to the cloud.
It's really important that you
spend your time conducting some
thoughtful due diligence and
ensuring that you can
trust your cloud provider.
Something which our
Microsoft President and
Chief Legal Officer, Brad Smith,
likes to say time and
time again is that in these
uncertain times when we've
seen cyber attack issues, data
loss issues, that companies will
only use technology that
they can truly trust.
So make sure you're spending
your time properly evaluating
cloud services providers.
So when I think of a possible
framework which folks may want
to use in evaluating potential
cloud services providers,
I think a key foundational
element is this whole notion
of compliance.
You wanna work with
a cloud provider who,
hopefully, can help enable you
to meet your compliance needs.
But there's also other key
areas to really hone in on,
such as security.
What do they do to protect
your data in the cloud?
How about privacy and
data control?
What are they doing to ensuring
that you continue to own your
data, that you can get access
to your data even though it's
stored in a cloud
provider's cloud?
And also transparency, you wanna
work with a cloud provider who
hopefully is very clear.
And truly transparent to you
regarding their cloud services,
business practices and
where your data is
located in their cloud.
So, what we'll do now is
change gears a little bit and
we'll have a conversation
about the cloud.
And again, we invite
the audience to ask whatever
questions that they may have.
But let me throw out
a first question.
It's sort of a two
part question.
Who are the key stakeholders
that should be involved
in deciding which cloud
provider to use and
what should be the role of
a compliance professional during
the cloud provider
evaluation stage?
Edward, you may have
some thoughts on that.
>> I do, it's good that's first
question, because Dennis,
when you first asked me to be
on a panel on cloud computing.
My first thought was, well,
that's not my primary focus,
I don't do cloud computing.
But then when you start thinking
about it, there's no one person
in most corporations that,
that's there focus.
It's a team, it's a very
varied team of people
that you need to collect.
And it's not just legal and
InfoSect,
the one's that
first come to mind.
It's not yeah, the infosec or
IT say based on cost savings and
based on efficiency here's
what we want to do and
then the legal is it's
a binary go, no go.
It's not like that or
it shouldn't be like that.
There are a lot of other
factors and considerations
on moving to the cloud and you
need the entire team to do that.
We focus on going
to the business and
figuring out what
the use case is.
What data is being proposed
to put into the cloud.
How it's gonna be used?
Where it's gonna be going?
And then that really informs
the entire decision,
so maybe want to narrow the type
of data you are moving in.
Maybe there is some data
that is too sensitive for
you to put it into the cloud.
Maybe there are others that you
are not comfortable with that
particular proprietor.
There is a lot of different
patterns and variations to go.
But you need to have all
those discussions right from
the beginning, gather all your
team right from the beginning.
I think that is the second
part what is the compliance
professional in my world
of privacy professionals.
Role is to make sure all
of those people have input,
make sure all of
the voices are heard.
And make sure that each concern
is addressed along the way.
>> And just to highlight
a few points which you made.
I think it's when we see this
in our customers when they don't
get the key folks and
stakeholders involved early and
often.
And that's something which
you really need to do.
We've seen time and
time again some of our customers
have signed our cloud computing
contracts, but after they sign
the contract then they wanna
start using our solutions So
we get involved in sort
of a second sales cycle,
a second negotiation
because they haven't had
key decision makers
involved in the front end.
So make sure you group
those folks in very,
very early and often.
I think there's an interesting
role for the compliance
professional to play sort
of a quasi quarterback,
to making sure that the right
folks get involved.
>> Yeah, I would just say, also
from an efficiency standpoint,
I mean, to your point Dennis,
oftentimes people will
sign cloud contracts and
the board of directors have no
idea that things are actually in
the cloud or
that a contract has been signed.
And you wanna get everyone
involved cuz oftentimes
you'll have these really very
valuable security briefings
about the cloud.
And ultimately the right
people are not in the room.
And so when it comes to legal,
when it comes to procurement,
the CMO,
they've had no participation or
no involvement or
buy in on this decision.
So you find yourself
doing it over and
over again trying to
get the right people so
that they will embrace cloud
services, essentially.
>> No doubt and
I would also make another point
that you definitely wanna get
the right stakeholders involved,
but
be sensitive to maybe getting
too many folks involved.
Sometimes at Microsoft we'll get
involved in our cloud contract
negotiations and a customer
will get 25, 30 folks involved.
We can't tell a customer how
many folks they should get
involved.
But I think focus in on the core
stakeholders who can really
provide value,
who could be sort of nimble and
sort of efficient
in the process.
>> Dennis, I just wanna add,
so we have a very structured
DOD acquisition process.
So it's very structured and
every cloud service provider and
cloud server offering must be
certified by the Defense
Information Service Agency.
That being said, we spend
$8.3 billion on IT just for
the Army alone.
So moving to the cloud,
we're looking to reduce cost.
But one thing I wanna point out,
it also harmonizes our security.
So some of this security
risk can be reduced by using
the cloud, since we don't
have so many systems.
The other thing I like to
point out is like we always do
a cost-benefit analysis on the
systems that we wanna move to
the cloud.
Because, in some cases,
moving to the cloud won't
save us money actually.
If it's just a one-off system,
that we not gain efficiency
by moving to the cloud.
>> That's great points,
great points.
Any questions from the audience?
Just pause here for
a second, okay.
So let's move on to
another question.
What are the key criteria that
customers should consider when
evaluating a cloud
services provider?
>> Yeah,
I'll jump in on this one.
So the things that you
had up there before.
It's security, compliance,
transparency, control.
Not everything fits neatly
into those buckets.
But those things tend to be,
again,
the board of director
level involvement.
So when you think
about security,
security is still a big issue.
I think it really depends on
the industry, quite frankly.
I sell to, again,
a broad base of customers.
So security is
a really big issue.
But you have to think about it
from the standpoint that your
cloud providers, the big ones,
it's a core competency security.
So they can do
the patch management,
the virus monitoring,
the firewall, things like that.
Whereas in a lot of smaller
companies it's very
difficult and
not cost-effective to do that.
When you start thinking about
other things like data loss,
I mean, that's a big issue for
people.
But in a public
cloud environment,
it's very very rare for
that to happen,
simply because of the way
the data is stored in the data
centers and we'll probably
get to that in a little bit.
In terms of compliance and
control,
that's another big issue for
customers.
And my advice to people
is to do some research
on your cloud provider.
Make sure that they're using
the data just to provide
the service, and nothing else.
So there should be no targeting
of ads, no data mining,
things like that.
I kind of like to look at it
from a philosophy of that you
should be almost in
no worse position,
because the CSP should be,
in a sense, a custodian.
It's almost like a safe
deposit box, if you will.
You're putting that data
in that safe deposit box,
you control it.
You should have all the legal
benefits as if you had control
of that data yourself.
So if you think about
what that looks like,
an example would be
government access, right?
So does your CSP
have in protocols,
procedures, process that if
government access, if government
comes to request data, that
they're gonna notify you first.
And if they can't notify your
first, what's their procedure?
Are they willing to contest it?
Are they willing to
take it to court?
That's a big control issue.
The compliance aspect of it
is that you can't comply if
your standardized service that
you're using does not comply.
So all cloud providers
should strive to meet
any regulation that applies
to cloud providers.
And that is a situation too
where you need to look at
the history of your
cloud service provider.
Where were they when
ISO 27018 came out?
27001, Safe Harbor,
model clauses.
Did they comply with
those regulations?
And that'll give you sort of a
backdrop as to their history and
their core competencies and
whether they take it
seriously or not.
>> Two things I wanted to add.
The one thing for DOD and
Army, it's very important,
is past performance.
We always look at the past
performances of how
they performed in
other contracts.
And the other thing is the value
add services that they can add.
One thing that's very important
to us is migration support.
So when we're moving that data
from our existing system to
the cloud, that support
is very important to us.
And how they can plug in and
help us with that migration.
>> Just a few follow-up points.
For those of you that don't
know what ISO-27018 is,
that's an international standard
regarding how a cloud services
provider needs to protect
data in the cloud.
It was the first
international cloud service
certification compliance
standard, Microsoft was
the first major cloud provider
to achieve certification with
that standard.
But make sure that your
cloud services provider
complies with that
important standard.
One thing which we've seen
with some of our customers,
in terms of the due diligence
in evaluation process is that,
often times they will send us a
detailed security questionnaire
document.
Sometimes they'll send us
a request for proposal documents
asking us a variety of questions
as to how we secure data in
the cloud and what our practices
and our protocols are.
So that may be a practice
which you want to consider.
Yes, ma'am?
>> So with respect
to that [INAUDIBLE]
[INAUDIBLE].
>> Thank you for the question,
it's a great question.
The question is at
the end of the day,
Microsoft talks about its
practices and policies.
Are they willing to step up to
the plate, if you will, and
to provide what I would call
a proactive hold harmless
indemnity provision?
It's a very good question, we
see that from customers time and
time again.
We're gonna be talking about
the allocation of risk.
So at Microsoft, we have what
we think are commercially
reasonable limitational
liability terms and conditions,
whereby we are willing to
protect up to 12 months of fees
paid for the services.
We don't technically have
an indemnity provision built-in
in our standard contracts.
I know we're on video tape here.
But I will say that depending
upon the nature of the customer,
the size of the deal, we have
been willing to provide what
we call a reimbursement of
customer mitigation costs,
if there is a data loss,
a security incident.
But that reimbursement is always
capped by whatever cap on
limitation liability
which we agree to.
So it's not an unlimited
stance vis-a-vis indemnity.
And so we've spent a lot of
time over the years, of course,
benchmarking the standard
contracts of our customers.
So we think that, for
the most part, our terms are
very commercially reasonable.
But I think that's
part of the give and
take of the negotiation
process with the customer.
But that's a terrific question,
thank you very much for it.
>> Let me add one more
consideration that I really
hadn't talked about before and
actually for
the three of us, it probably
doesn't matter as much.
But I heard yesterday from
a gentleman from the FBI and
he was talking about
the potentiality
of future ownership.
So his example was
Amazon Web Services,
which might be a little
bit example too far.
But there are a lot of
smaller cloud providers,
a lot of startups that are.
And his thought was if you go
ahead and put your data with
them and then they get sold to
somebody who's got a beneficial
owner in China or North Korea or
some other state which may not
be as friendly to data privacy
law, what's gonna happen?
I don't know, it's only been 24
hours since I thought about it.
I'm trying to decide whether
that's too paranoid or not but
maybe it's not.
Maybe thinking ahead a little
bit to how that provider's gonna
be and what the likelihood is in
a year or two of the stability
of your data in that cloud
provider, is probably not bad.
>> I think it's a fair point,
and that's something which
you should ask as part of
the due diligence process,
to understand the makeup of
the cloud services provider,
what their reputation has been.
Do they make money or not?
What's the likelihood
of them being a target?
How good are they
doing financially?
If they declare insolvency or
bankruptcy,
what happens to your data?
Also, just sort of as
a corollary point on
the indemnity piece.
There may be some smaller
cloud services providers who
are willing to indemnify you,
and that's all well and good.
But what does that indemnity
really mean at the end of
the day?
So when you're thinking about
indemnity, I would say to you
that indemnity probably means
more from a well capitalized
cloud services provider
versus a smaller provider.
>> Yeah,
one thing I wanna add is also,
we talked about indemnity, but
also the portability
of the data.
If all else fails,
I think it's very important
to have a contract clause
that talks about
the portability of that data and
how it's gonna be exported and
what format that will be.
So that's very important to us.
>> Yeah and I would say for the
indemnity standpoint as well,
our duty to defend.
There are things you should be,
in a sense, made whole.
If you're utilizing
the service and
you're sued as a result of
just using the service, right?
And to your point,for
the FBI example,
I mean you still
have a contract.
You still have breach
of contract remedies.
You also have encryption.
And as cloud services evolve,
there's encryption where you
bring your own key, essentially,
where you have
control of that data.
So if you're using best
industry practices with respect
to encryption,
there is some protection there
even in a cloud service.
>> Yes sir?
>> So on this issue of
portability of data, [INAUDIBLE]
took over [INAUDIBLE] of
the cloud a few years ago,
reacting to
the company's contract,
there's nothing in there
about affordability.
Whether or not they go bankrupt
or whether we decide to split.
So is there
an industry standard,
is there standard terms for
something that we
should have been savvy,
to insist on deployment.
>> Well a few thoughts and
I'll let others jump in.
But I think you should always
make sure that it's part of
your contract,
the cloud provider,
that you always have
access to your data.
That you always very clear
that you retain ownership to
your data.
I know at Microsoft,
in the event that there is
an end of our contract, we
always provide the ability for
our customers to get access to
their data for a period of time.
Or they may want us
to delete their data.
And if they want us
to delete the data,
we're willing to do that too.
So we give options, but
I think that's an important
consideration to include and
to think about in your contract.
You really need to be cognizant
of the so-called exit strategy,
if you will.
>> Right, and one thing I may
add is the migration services.
I think you need to have in that
contract is a period of time.
If this relationship
doesn't work out,
then you have a period of
time where they're gonna help
you migrate that data
off that system.
And then you specify the formats
of that data's gonna be,
I think that should
be in the contract.
>> Yeah, I think also
with GDPR coming out,
there are gonna be some
provisions in there
on data portability and
migration of data.
So if your cloud service
provider provides services to
people in Europe, then they're
gonna have to comply with GDPR.
Or if they have offices
that are based in Europe,
will have to comply with GDPR.
I think it's almost impossible
from a cloud contract standpoint
to say well, how much time
is enough time to migrate
data to the new service, right?
Most cloud contracts
will say 90 days,
that that's their
responsibility.
And that's
a standardized service,
keeping in mind that you have
literally tens of thousands,
hundreds of thousands
of customers, right?
So you're standardizing
that service, so
what happens if it takes
you longer than 90 days?
And so that's something that you
can talk about with your cloud
service provider, but
there should be a plan in
place to migrate the data.
And as long as you're paying for
it, by the way,
they have to maintain it.
So even if the contract says 90
days, if you still have a valid
contract and you're going
month to month, for example,
they're still providing
the service and
you could be planning to migrate
that data as you move along.
Just food for thought.
>> Just a point on the acronym
GDPR, that stands for
the General Data
Protection Regulation.
It's a new law which will come
into effect about a year or
so from now.
And it's gonna be if you
have a personal identifiable
information of folks in the EU,
or companies in the EU,
if you do business in the EU,
you're gonna wanna make sure
you comply with this new law.
It contains a number of
different requirements
from a legal perspective,
I think there was a session
yesterday on the GDPR.
And if you don't
comply with the GDPR,
you stand to be responsible for
up to, I believe,
4% of your revenues if you're
in violation of the GDPR.
So make sure that as you're
moving to the cloud,
give some thought as to how
do you become GDPR ready.
I'll just give one more plug,
if you don't mind, for a second.
Tomorrow there's gonna
be a webcast with our
Microsoft President and
Chief Legal Officer, Brad Smith,
and our Chief Privacy Officer,
Brendon Lynch, where they're
gonna talk about what Microsoft
does from a GDR perspective.
It starts at 9 AM Eastern
time tomorrow morning.
I know all of us will be still
here at Compliance Week, but
you can still listen to it on
demand as your schedule permits.
Yes ma'am?
>> Yeah,
I am coming at this from
the GDPR perspective.
And we're trying to
engage a lot of new
SaaS services for
security purposes.
And I'm trying to make sure that
we are GDPR compliment now, so
that I don't have
to do it next year.
And get the right privacy
clauses in a contract.
And try to get our works
council approval for
these sorts of new services.
And every single provider
I talk to acts like
I'm the first one that's
ever asked and so
the responsibility is falling
on me to draft those clauses.
And to put together
presentations and materials for
works councils to convince
them that this is a good idea.
And I feel it's not sustainable
and it can't be the right way
cuz I don't know anything
about SaaS services [LAUGH].
I'm not the best person
to be doing this.
And so I'm wondering, am I
talking to the wrong people?
How can this process
go more smoothly?
It feels like I must be
doing something wrong.
>> Well, first of all,
it's a great question.
And I don't think you're
doing anything wrong.
I think you're asking the right
questions at this point in time,
cuz it's really
important to gear up for
GDPR because it's
a pretty involved law.
At Microsoft, at our Microsoft
Trust Center we have a number of
resources which you
can take a look at,
which provide some advice,
some sorta rules of the road if
you will,
as to how to become GDPR ready.
At Microsoft also we're
the first major cloud services
provider which is offering GDPR
contract terms as part of our
cloud contract.
So also make sure that your
cloud provider isn't just
talking about GDPR,
if you will, but
they're willing to back it up in
terms of actual commitments in
their cloud contracts.
I'll also say that we've
been seeing more and
more of our
sophisticated customers,
asking about what are you
doing vis-à-vis GDPR.
So you're asking the absolute
right questions.
And I do think you're
probably gonna see more.
At Microsoft, we like to feel
that we sort of set the tone for
the industry, if you will.
I think you're
gonna see more and
more cloud providers
have a conversation and
talking about what they
are doing to comply with GDPR.
But definitely ask
those questions,
drill down in more detail.
>> [INAUDIBLE] Does
this [INAUDIBLE],
is there typically someone
internally who has this in mind.
We want our service to be
used by this company, so
we're going to help this
company convince its work
councils that-
>> People within the cloud
providers business bascially.
>> [INAUDIBLE] People, or?
>> We don't have folks who,
I would say directly would
advocate on your behalf in front
of those regulatory authorities.
But we have a bunch of lawyers,
regulatory folks who constantly
interact with these folks.
And we've been getting
our house in order,
to make sure that
we're GDPR ready.
So you wanna work with
a cloud provider who has
resources available.
Which then you can show to
these regulators to say,
hey we've selected this provider
because they really know what
they're doing there
with GDPR readiness.
>> So
I'm asking the same questions,
I'm in the same boat as you.
>> It's like why am
I putting together
a presentation on crowdstrike,
I don't know anything about-
>> I do understand.
And I have not found that
person in any cloud providers.
That one person that is like,
yeah, here's the deck we use for
the works council
on our last client.
I mean, we don't have that.
But on the works council, I will
say it's not apples and oranges,
but there are separate issues.
And each company's
works councils, and
actually each country's work
council within that company,
do have different tolerances.
So I do from that side.
I can understand
why a Microsoft, or
it doesn't say here's our
works council presentation,
cuz it does differ.
But you're right, you do
need to ask those questions.
First of your HR, this gets
back to our first point.
Get with your HR and say,
what are your worse councils and
you're going to be looking for.
What sorts of information
do I need to gather
about this new solution?
So from the provider, and from
the business and from IT, so
we can package it all and go
to the works councils and say,
here, this is what
we plan on doing.
But it's not an easy answer.
Especially if you're
an American company and
you're dealing with a US cloud
provider, a lot of times, you're
gonna hear from them, we don't
have anything to do with GDPR.
We don't wanna deal with it.
That's not the right answer.
And they'll find that
out in about 369 days.
>> [LAUGH]
>> But it's evolving.
>> It's the answer for army,
all our systems, right?
>> [LAUGH]
>> So I'll give a plug,
microsoft.com/gdpr has
a lot of materials on it.
There's a whole industry
popping up around this as well.
They estimate it's
about a 4 to $5 billion
industry in terms of helping
companies prepare for GDPR.
So there are a lot of people
out there who are doing this.
Microsoft has a lot of partners
who help our customers
in this format as well.
So there's stuff out there, but
certainly willing to talk with
you more about it if
you have questions.
>> Yes, ma'am?
>> [INAUDIBLE].
And they've been very helpful
in going through agreements.
And put in clauses
[INAUDIBLE] for
the providers to need
to comply with GDRP.
So I would have no idea.
But if you get a [INAUDIBLE]
they should be up to speed
with it.
>> [INAUDIBLE]
>> So
yeah, and keep in mind too
that it's a partnership with
your cloud service
provider on this as well.
Obviously the cloud service
provider has a lot of things
that it needs to do, to make
sure that it complies with GDPR.
And it's a huge,
huge engineering commitment.
I mean very expensive to do.
But on the flip side,
you've also got a lot of things
that you have to do as well.
I mean,
if you have loyalty programs,
all kinds of things where you're
collecting personal information,
you've gotta ensure
that you're complying
with GDPR also in how you
collect that information.
So it's not as simple as just
dumping it in the cloud,
problem solved.
I mean, there's a lot of work
to be done on both parties' end,
to make sure that
you're successful.
>> So I'll just make one
point about Microsoft.
So I'll be happy to talk more
offline, but Microsoft stands
ready to help you navigate
through those issues as needed,
so, okay?
Any other questions?
Okay, well,
let's move to another question.
>> I think we had
one over there.
>> I'm sorry, yes ma'am.
>> You mentioned
earlier about
[INAUDIBLE].
>> Well, we're transparent
as to where our customers,
where their data is
located in our cloud.
So as an example, let's say you
provision, you are what we call
a tenant, or a data center
in North America, or the US.
We say that your data,
at rest, will remain in US or
North America.
I'm assuming we will make
similar commitments vis-a-vis
Africa and maybe the Middle East
& Africa region, if you will.
>> Yeah, I would just say that
that's correct as I understand
it, that we can keep, the way
we engineer our services,
we can keep your data
in a particular region.
There is some redundancy,
so it's something that we
can talk about with our
technical specialist to ensure
that you have data where
you think it should be.
The other thing that I
would say is important for
a CSP is to ensure that wherever
the data rests, the laws
of that particular jurisdiction
will apply to the data.
And that might sound sort
of counter intuitive.
But you don't want some foreign
government coming in and
issuing a subpoena, trying
to get access to your data,
because it's in the US, or
some other place, or whatever.
So again, look at your CSPs
track record in defending that.
I mean,
are they willing to stand up.
I can tell you, and this is
not a plug for Microsoft, but
we've sued the US
government over this.
So right now it's, I guess,
in the Appeals Court.
We won the last round but it may
go higher, depending on one of
the the government decides to
appeal or not, but anyway.
>> Not just the data, but
it's also how [INAUDIBLE].
>> Absolutely, it's all
really important for sure.
And that's the other thing.
It comes back to control,
which there's a whole bunch
of questions we probably will
not have time to get to.
But that's part of control, and
who has access, and is it
logged, that kind of thing.
And the physical security
aspect of the data,
while it resides with your CSP,
is extremely important as well.
So when you have that
conversation, I think that's
an important aspect of
the conversation to have.
And how do they control
the data, what's the physical
control, and who has access,
and how is that logged in third
party access, subcontractors,
all kinds of things.
I think those are discussions
that you will need to have.
>> Critical question,
okay, well,
let's move on to
another question.
So what other trends do you
guys see in the space of cloud
computing?
>> So a big thing for
Army and DoD is SaaS.
So we're Service as a Service.
That is Software as a service.
That's a huge thing for us.
And it looks like we can move
many of our applications to
the cloud, using SaaS,
especially around
the office environment.
>> Yeah, I'd say for
me the biggest trend seen across
various industries, is just
embracing of the cloud, right?
So three or four years ago,
a lot of companies would have
never put sensitive
workloads into the cloud.
Not only are they doing that,
but they're doing it a public
cloud format, taking advantage
of the huge economies of scale.
So I think public cloud,
there was a survey by LinkedIn,
their information
security community,
which spans across seven or
eight different industries.
And this survey is
about two years old.
But 71% were either
in the cloud or
actively planning
to go in the cloud.
So I would say that it's not
only where you are today in
terms of your planning, but
where will you be in a year from
now vis-à-vis your competitors.
And if you're not in the cloud,
is that gonna put you or
your company,
at a competitive disadvantage.
So I mean those are the big
things that I see.
And it used to be number
one conversation, security,
security, security.
Now the number one conversation
is about privacy and control.
And security's still important,
don't get me wrong.
It's still a big thing,
but most people have done a lot
of research now about cloud and
they feel a lot more
comfortable about security.
And I've heard a lot
of CIOs say this.
That the fact of the matter
is that the major
cloud pro vendors can
protect their data,
better than they can do
it in-house themselves.
And that, again,
is because of the monitoring.
We spend over a $1 billion
a year, just in security alone.
So it's now a core competency
of all of your major cloud
providers.
>> I think the other thing is
having your data at one cloud,
is you can do big data analysis.
So when all your data is
residing at one system, allows
many big data analysis that
wouldn't be available before.
So it's a huge
business analytic.
>> The other point I would
just make before going to
the question, is that we've been
seeing customers atop what is
known as a hybrid approach.
There are some customers who
don't wanna go all in the cloud,
and so they keep some of
their data on-premises,
maybe some of the more
sensitive data.
And they move other workloads
and data to a cloud.
Yes sir, you had a question.
>> I do, thank you, and I wanna
turn back to the indemnification
issue, if I could, as we were
talking about data security.
In our situation, we're actually
taking our customer data, and
then we would be putting
it on the clouds.
So there's an expectation
from our customer,
that we will be
safeguarding that data,
to the extent that the 12
month subscription cap exists.
That's not cutting it
with our customers.
They want a more absolute
commitment from us.
How do you suggest
we bridge the gap?
Because I have seen over
the last five or eight years,
where the 12 month subscription
value, becomes the standard.
But it's wholly inadequate in
terms of the potential liability
that we could expect.
How do we bridge that gap?
>> Well, we see that come up
many times as part of our
discussions with our customers.
And I think at the end of
the day, from my viewpoint,
it's ultimately a business
risk financial issue, right?
Depending upon the economics
of the deal, the nature of
the customer, we may be
willing to elevate that cap.
But it's all really based
upon the financial aspects of
the deal.
It has come up time and
time again too.
>> I'll be honest with you.
I mean I very rarely rarely not
see a deal not happen because of
limitation of liability,
or because of indemnity.
Normally, the parties are able
to get to a point where they're
both comfortable.
And it takes a while
to get there.
I mean many times there's
security briefings,
understanding what the service
is, and how we store the data,
how it's encrypted.
So if the issue is
data being stolen,
some companies get more
comfortable when they
understand how we store
the data, how it's encrypted.
How your data's not
gonna reside on one box.
It's gonna be stored across the
data center on many different
servers.
So hypothetically, if a server
were penetrated, not only is it
encrypted, but it's only gonna
be a piece of your information.
It doesn't answer your question.
I think there's flexibility
there among cloud
providers, right?
So yeah, I've often heard,
this cloud provider will take
uncapped liability and
that sort of thing.
I would just tell you to read
the fine print on those.
Because it's not really true in
what some cloud providers say
about uncapped liability, and
what they're willing to provide.
I think at the end of the day,
there's no cloud provider that's
willing to bet their
entire company.
Because essentially,
it's not gonna be one
customer that's hit.
It's gonna be a multiple,
across hundreds,
thousands, tens of thousands
of customers potentially.
So there's gotta be some
reasonable cap on liability.
What that is, I think you'll
have to get comfortable with
your cloud service provider.
But those are one of the things
that, quite frankly,
a cloud service provider
can negotiate with you.
There's certain things that,
because of the way the service
is engineered, I can't
change even if I wanted to.
But indemnity, limitation, and
liability, my commitment to
you or your cloud services
provider's commitment to you.
Those are things that,
quite frankly, I believe can be
negotiated where you can
get to a level of comfort.
>> Well,
it's a risk analysis, right?
And you have to look
at the alternative.
So I don't know what
your situation is, but I
mean there is a lot of companies
that are starting out, and they
don't have very sophisticated
IT resources themselves.
So while you might say, look,
we wanna go into the cloud but
we want protection.
But from your customer
standpoint, and even from your
board of director's standpoint,
what's the alternative?
You are to maintain it inside,
on premises,
what protections are you
affording there?
I mean, what would be
your exposure there?
You might not be increasing your
exposure dramatically to go into
the cloud, either from
a security standpoint, or
from a financial standpoint.
So it's not a simple math
>> [INAUDIBLE]
>> Yeah.
>> [INAUDIBLE]
>> Yes sir.
>> You talk about [INAUDIBLE].
>> What are the cloud providers
doing to ensure that their
component pieces comply with
data protection requirements?
>> Well, I'll throw
a possible answer there, and
feel free to chime in.
At Microsoft, we use a number
of subcontractors as part of our
provision of cloud services.
We use these subcontractors, cuz
quite frankly, it's a way for
us to provide competitive costs,
associated with our cloud.
But we take responsibility on
behalf of those subcontractors.
We put that into our contract,
that we're responsible on
behalf of our subcontractors.
We also notify you and tell you
when our Microsoft Trust Center
site, who our subcontractors
are, so you're aware of it.
So we flow down a number
of those terms and
conditions, which we're signing
up to with our customer, through
our sub-contract agreements
with our subcontractors.
>> I'm sorry,
just the question's are you more
concerned with ensuring that
we're keeping up with rules and
regulations with respect to our
hardware, that it's
best of breed?
Maybe I didn't understand
the question fully,
so if you can either drill down.
I'm sorry about that.
>> No problem, no problem.
I work a lot with
component systems, right?
My job is to go in and
look at them, and
make sure that they meet the
data protection requirements.
But dealing in
the digital world, right,
it's a combination of a lot of
different pieces glued together
to make the cloud.
>> Gotcha, okay.
>> What I wanna know is,
what is the focus of
the cloud service providers?
What is their due
diligence focus right now,
on ensuring that one of
those components, or
all of those components, meet
data protection requirements?
Is the focus just
on the software,
is the focus on the hardware?
Cuz we talk a lot
about security and
how impenetrable a network is.
But do we also
look at whether or
not each component of that
cloud system, the hardware and
the software, meets the data
protection requirements?
>> Yeah, so I would just say
that we're building data centers
around the world.
Some of them we own outright,
we construct.
We build some of them.
Our list but
we stand behind our SLA.
So we're looking at
the entire system.
We're ensuring that your
hardware specifically, I think
we take our useful service
out of life every two and
a half to three years.
They're shredded, broken into
pieces, new servers replaced.
So, we try to ensure that we're
using best of breed services,
hardware.
Again, there's penetration
testing, all types of patching,
things like that that go on
on a daily basis to ensure
that we're meeting our
SLA requirements and
that we stand
behind our service.
We say that we're going
to comply with all laws.
So it comes to any cloud service
provider not just Microsoft,
but you want to make sure
that they're putting these
things into their SLAs,
into their contract and
if not then it's a breach,
right?
So you want to make sure that
they have some skin in the game,
with respect to these things.
>> I'll just add a few
other points too.
It's my understanding that as
part of our contract terms we
have a robust definition of
Microsoft Online Services.
So it's really the combination
of our services,
which go into our
cloud services.
It's a combination of items
basically, if you will, and
we stand behind
all of our terms,
stand behind that definition
of Microsoft Online Services.
I also think, I believe that
it's part of the servers which
we have in our data
center environment.
I think we design the
blueprints, if you will, as to
how these servers are supposed
to be architected if you will.
And then we have our providers
package their servers
appropriately.
>> So one of the riskiest
elements that we see and
we look out for
is that human element.
So that insider attack is
the other thing that we're
very much concerned
about at DOD.
So we have very strict
requirements on security
clearances on the contractors
that work on our system,
so that's the other risk
factor is that human element.
>> Just a question,
I know we touched upon
this a little bit is how
about thoughts about
third party or
law enforcement access
to data issues?
Any perspective on that?
>> Yes,
I deal with it all the time.
My system is financial
disclosure of management and
there's a formal protocol to
request every senior leader
in DOD or actually in the
government needs to file what's
called the office of
government ethics 278 form.
And there's a formal process
where that can be requested and
so we provide that
data as requested.
We've also provided bulk data
to researchers, anonymized data,
so that they could do big data
analysis on the data that's
in our systems actually.
To match the assets to see what
DOD officials or what assets
they hold and in aggregate
>> Any thoughts about that?
>> Other then making sure that
your CSP has a process in place
with respect to
government request.
I mean, make sure that there
is transparency around that.
Make sure that, for example,
the results are published so
you know how many
requests there have been.
How many times your CSP has
actually had to turn over data.
Is your CSP,
is there a built in process?
I mean,
when I talked earlier about
the safe deposit box analogy, I
mean our position is that you're
in a better position than your
CSP to decide what complies with
a third party requested data.
So, our position is that
we will always, and
this is engineered in, we will
always redirect any request for
data to the owner of that data.
And if we're not permitted to
do that we will contest it.
And so I would encourage you
whatever CSP that you look at to
make surethey have
a process in place.
And make sure they have
a demonstrated history
of doing that.
Have they ever sued the
government with respect to this?
Or are they just saying?
You can write anything
in a contract?
But do you or are you
willing to stand behind it?
>> As a customer we
absolutely expect that.
If we're putting data and
assets into the cloud
then we are looking at it like
a safe deposit box too and
we expect the cloud
provider to protect it and
defend it against all requests
as we would ourselves.
>> And another question.
I know we touched upon parts
of this question earlier, but
with regard to limitation and
liability and indemnity but,
how much contract negotiation
changes should a cloud provider
be willing to entertain and
or accommodate,
in terms of a sometimes
we see with our customers
a proverbial battle
of the forums.
Microsoft has got a standard
cloud services contract.
Sometimes our
customers come back,
and they have a specialized
exhibit with regards to their
security protocols and
practices.
So, any thoughts on that?
>> Yeah, I have a comment
it goes to the question
over here about the GDPR and
new.
A lot of times you are not
negotiating against your cloud
service provider, you are
negotiating with them to ensure
that the contract that the two
of you put together is going to
be satisfactory to a regulator,
or to whoever looks at it later.
Or to a work's counsel.
Sometimes there is some
work's counsel think
about Germany in particular
that can sometimes get so
detailed they actually
want to see contracts.
So they want to see
the protections are in there.
So you need that discussion with
your cloud service provider is
not necessarily adversarially,
it's not.
I want two years worth
of fees instead of one.
It's not that sort of thing.
IS what do we need to add
to this contract so that
the regulators from data privacy
perspective believe that we're
both protecting the individual
data that we put into it?
So sometimes it takes
a little getting used to
from a negotiation standpoint.
But if it's done right, it's
not as painful as it could be.
>> Okay, great.
Another question.
Are there any third party
resources out there which you
would encourage folks
to take a look at?
I'll just do a quick
answer to that question.
I think a great resource is
this organization known as
the Cloud Security Alliance.
They've become more of a leading
think tank in the area of cloud
services, so check out their
websites and their resources.
Another terrific organization is
the International Association of
Privacy Professionals.
IAPP and they have got some
great information about data
security privacy, especially
as it relates to the cloud.
But any other
research you wanna-
>> Yeah except for the DOD.
There is the Defense Information
Services all of our cloud
are related there in
the public domain.
I'd say for the private sector,
feel free to leverage what we
have there, it's all available
in the public domain.
>> Okay, okay.
Just maybe one last question
I'll throw out there.
So once your cloud
contract is signed,
how important is it to
consider managing and
monitoring your contract in
this ever changing environment?
>> Yeah, I think at
the end of the day, again,
it's a partnership, right?
So I think you have to do that.
I mean there's a whole industry
that's sort of sprung up around
that today.
To be honest with you,
we're struggling to keep
up with it because we're
really trying to have some
consistency around the process.
So, I can tell you what we do.
We publish a lot things,
we republish the results
of our audit.
We republish the results of
log enforcement requests.
We try to get everything out as
much as possible on our website
so that our customers
can look at it.
Our challenge is
when you have so
many customers, how do you have
a standardized process for
them to evaluate cloud
service after the fact?
And this industry that's
sprung up around it.
You get these security
questionnaires from
existing customers, and
they're all different.
And so from a cost to sales
perspective it's extremely
difficult to reply to every
single security questionnaire.
So we try to have
a standardized response.
For some customers, quite
frankly, that's acceptable.
For some customers, it's not.
So, I'll be honest.
For us,
it's a real challenge right
now in how to do that because
our prior model much like most
of the old line companies
was to deliver software, and
you sort of maintained it.
Now we're doing that.
And so there is that continuing
partnership that you
go through the life of the
contract that you have today.
>> I would just consider, really
to encourage you guys once you
sign a cloud computing contract,
actively manage and
monitor that contract.
Especially with regard to
the service level agreement SLA
commitment.
You want to make sure that
you keep your cloud services
provider honest in that area.
So I think we're right up
against time or so, but
do any folks have
any other questions?
Okay, seeing that there's
no other questions,
we again really appreciate
your attention and for
joining our session today.
Thank you very much.
>> Thank you.
>> [APPLAUSE]

Conversations on AI with customers Emerging Trends

The direction we’re going in is, we just have this integrated system.
We call it our ecosystem of all these different data points.
So all this data is being captured,
everyone’s moving this direction on how best to bring all this data together and leverage it for AI.
Over the next couple of years, what I expect is
a lot more activity around causal inference, around explainable models.
The decision makers want to have the understanding of how their decisions are driving impact
and not just in terms of making predictions.
How do we use AI? A lot of robots that we’ve been trying to deploy
that can take care of some of the mundane tasks that associates used to have to do,
and then associates can then focus really on human aspects of retail.
Being able to spend time with our customers and interact and engage.
I think it becomes an imperative in our companies.
Reconciliations in your accounting.
In the past, people we’re sending thousands of emails around
companies to basically look for reconciliations.
You can really automate a lot of those.
The trend is actually that it’s becoming
more pervasive in all areas of your company.

CMJ Masterclass Shaping The Future Music, Technology and Creative Collaboration

My name is Steve Milton, as Lisa just said,
and would like to welcome you all here. Would
absolutely love to thank CMJ as well as Microsoft
for making this all possible.
Also we’d like to begin by introducing everybody
else up on stage here. We have Charlie Whitney,
Dave Rife, and Kamil Nawratil. I almost got
it.
Listen. This is who we are. Thought it would
be great to give you guys a little bit of
background on the project. I am the founding
partner of Listen. We are a creative and strategic
group just down the street.
And most of our work is focused, and many
of the projects we do, are focused on the
intersection of music and marketing. The two
projects that we’re going to talk about
today are part of an ongoing partnership that
we have with Microsoft.
Delqa is the first project we’re going to
look at, that we worked on with Matthew Dear.
And the second, something that’s actually
launching this week, was a live show visual
system for Neon Indian.
When we think about music and technology and
we think about how technology has really over
history shaped how musicians are able to express
themselves and how audiences receive music
and then how we also define what is music.
Technology definitely plays a role in that.
And this is true now more than ever, and is
core to the work that we’re doing with Microsoft.
Specifically our work involves developing
and concepting ideas and projects like this,
so we can bring together musicians with technologists
and talented folks like the people who are
here on stage today.
Delqa is a project here, we’re going to
watch a video in just a minute which will
help set it up, and then Dave and Charlie
are going to talk a bit about, uh, get under
the hood a little bit on this project.
But it was a project, it was an installation
that went up at the New Inc. space, at the
New Museum, over the summer. And you know,
I think I’m going to let the video speak
for itself.
Technology’s allowing for this openness.
It’s this living, breathing sound sculpture.
You can play with it, and tweak it.
I wouldn’t make the song that I made for
DELQA at any other point in my career or my
life because it only works for a space like
that.
To have that opportunity, and to meet wonderful
new people and learn from them and see what
they’re doing and get ideas that I wouldn’t
have come up with, I mean, that’s the best
. . . that’s art.
We saw this project as an opportunity to create
something that had never been done, pulling
together an amazing artist with a team of
amazing artists using Microsoft’s technology.
Seeing the guys break it apart, I’m seeing
the guts of the system. It’s a lot of math
and a lot of numbers. These guys are smart;
they’re really smart.
The big idea that we were exploring was being
able to step inside of Matthew’s music.
This piece is really about creating a sonic
environment. So one of the ways that we’re
going to achieve that is by installing 40
loud speakers throughout the space.
Those will all be linked together into a spatial
audio system that allows for a three-dimensional
field of sound.
You’ll be inside of all these different
musical ideas that make up one beautiful composition.
We were able to leverage the Microsoft Kinect’s
ability to track people’s movements spatially
through this experience.
The Kinect is everywhere in this thing. You’re
almost always covered by a Kinect. We specifically
sourced this fabric material. It was opaque
to the depth cameras, so we can actually read
the surface of the fabric, but it was transparent
to the colored infrared cameras, so we can
actually see through it.
As people push on the walls and displace the
membranes, they’re actually able to change
the quality of the music.
Different areas of the installation affect
the music in different ways. Sometimes a user
will be changing the actual part that’s
playing. Sometimes they’ll be introducing
new parts into the music.
We wanted every interaction to feel very powerful
for the audience. So, if we take the drum
part for example, as they press in, the rhythmic
density of it becomes much more complex, but
we’re also changing the tamboral qualities
of those synthesized drum sounds.
All of these parameters allow the audience
to have a multidimensional influence across
the composition.
So you could visit this piece on a number
of occasions and you’ll hear something different
each time. It would never be the same if you
went there twice.
Our desire was to create a new type of architecture,
influenced by how we experience sound.
Doing interactive design is really about creating
a magical experience, and having really powerful
things like a Kinect that help you create
those experiences.
There’s so much that we can do with a project
like this.
The more accessible these technologies become,
the more people are able to use them and do
surprising things with them.
People want to make music, people want to
be part of the music making process. Technology
allows that.
Your mind is totally free to wander. There’s
no right or wrong answer. It’s just however
far you want to push it.
To be able to bend music, make music, and
put that in different worlds, that’s what
makes this fun.
So, uh…that should help to give it a little
bit of context around the project, what we
were up to and how that all came together.
Now I think I’ll hand it over to Dave to
talk a little bit about the composition and
the sound and light and even a bit more.
Check, check, check, we’re here. So I’m
glad that video played. I can kind of be done,
now. But no, we’ll go a little bit under
the hood – [To Kamil] yeah, you can go ahead.
I lead a company with Gabe Liberti, who is
out there somewhere. Where are you Gabe? Raise
your hand so everyone knows—that’s Gabe
Liberti!
We have a creative studio called Dave and
Gabe. We do a lot of sound and light work
with immersive and interactive environments.
I have a background in architectural acoustics,
and, how sound behaves in space.
Gabe has a really strong background in production,
and you can see why we ended up doing a lot
of the work on this project.
If you go to the next slide, you’ll see
some of our work. It all involves interaction,
it, most of it, involves sound and lights.
Go ahead, go to the next one, oh good that
was out…
I think one of the first things that we talked
about as a team, that entire team that you
saw in the video, was, what is this interaction
going to feel like?
Like, how are you going to trigger these different
moments in the sound, and how are you going
to create this composition based on what Matt
already wrote.
And so, we really loved the idea of something
being physical. Actually like physically touching
something, something like an interface, but
something more architectural.
So we had these two different types of meshes.
One of them was kind of “spandexey” like
this, and one was more like a net.
And as you pushed into it, you would change
the composition, you would change different
parts of this music, and so based on how you’re
pushing like this, and also where you are
in the space, like if you’re pushing on
this side or that side, you would trigger
different sounds and different effects.
You saw in the video -- this is how it kind
of works. So that’s great. We can go to
the next one. But very tactile, was what we
were going with.
And then, at the same time, we were working
with Matt on the composition. So Matt totally
got it right away. He met with the whole team
and totally understood this would be rad as
an environment. I’ll create some music.
But how does it work in terms of making that
music interactive? Because typically you’re
listening just over headphones or out of your
speakers and you’re just taking it in as
the listener.
But what we were all going after was putting
you inside of his music, so pulling his music
apart and surrounding you with it, but also
giving you as a listener agency to change
what’s going on, to manipulate the sounds
that are happening. [To Kamil] No, not yet
not yet.
So, what you see here is the Ableton session.
So Matt created his composition in Ableton,
and then we all shared that session together.
And we worked with him to take specific tracks,
so you’re seeing six different tracks here,
so six different parts of the music.
But we write multiple clips per track. Right?
So there’s different energies within each
one of those tracks.
There’s different kind of sounds that are
happening within that, but it’s all aligned
to one type of sound, so like, one might be
a high hat, one might be a kick drum, one
might be arpeggios, that’s all kind of in
the vertical there, and then within each one
of those are different sounds, so that when
you push into the netting, you can trigger
those different sounds. [To Kamil] So if you
go to the next one we should see that.
This is kind of the way that we made up the
media nodes that were synthesizing some of
the drum sounds, so you see, as we push in,
you get more rhythmically complex, a little
bit more dense patterns, and then as you push
out all of that goes back away… next slide
And so I don’t know – go ahead and hit
it again so it plays the movie – so you
can kind of see right in the middle, um, there’s
a kick selector, and then this is the Microtonic
VSC. Right in the middle, you’ll see, right
around here…somebody is starting to push
in to the music and you see that little arrow
clicking down on the different tunes, and
you hear the different complexity that’s
happening within the music.
I think it’s a little out of sync with the
visuals, but you can also see within the Microtonic,
there’s different filters happening, and
that’s all based on the real time information
about where people are pushing as well.
So this is a custom tool that we wrote within
Max for Live that Yotam Mann, that you saw
in the video, wrote. In order to be able to
make this music more interactive, and not
just like a static copy of what’s going
on.
And then so now we have the interaction that
we want to do, and we have the music and the
music is flexible. So now we wanted to reproduce
it over a huge audio system that’s all around
the listener.
And so we had 44 loud speakers. And the point
of this was not for loudness—it’s not
to make the thing really loud—it’s so
that we can pull the tracks apart. We can
take the stems out, and give each its own
place to be. And we can also give all of the
stems, or some of the stems, we give them
trajectories, so there’s sounds that are
moving around the space all around you, and
there’s some sounds that are moving based
on what you’re doing within the architecture.
So we laid it out in six different zones—A,
B, C, D—so A, B, and C and D were kind of
four different instruments, and then E and
F were when you climbed up into the middle
of the netting, you’d get this kind of drone
type thing happening around your ears if you
were there, and if you weren’t there it
wouldn’t be there. Go ahead.
And then this is kind of what it looked like
in one zone. So we had ten loud speakers for
each of those quadrants, and some of the sounds
would be really diffuse and be happening all
around you if you weren’t pushing into the
net, and then if you pushed into the net it
would go local to where you were.
So you could really like spatialize where
the sound was happening just based on what
you were doing, on top of all of the compositional
stuff that was happening. And you already
saw that. I think that this is just a really
funny clip because Gabe is in slow mo with
a speaker on his head. I had to show that,
sorry. Keep going, oh there it is again. Wonderful.
And then in terms of the spatialization we
used MaxMSP. We had some of the tracks within
the piece. These were not so much interactive,
but they were always moving around you.
So what you’re looking at here on the right
side of the screen is like a top down view
of all the loud speakers in the space, so
you’re looking at the floor.
And then those green dots are actually sound
sources, so that’s like particular parts
of his track that are always like slowly rotating
in the space, and then we had these high hats,
which is kind of that crazy one, randomly
going all around, and that ended up feeling
like it was like a fly kind of going all around
your ear. It was super cool.
And this is kind of what it looked like to
mix the piece. It’s really interesting to
mix a piece over a large spatial system like
this, and also interactive, so we had to set
up in front of each one of the quadrants and
get the local mix right and then sit and listen
to the overall piece and get the overall thing
right, so it’s a ton of variables, but that’s
kind of what it looked like.
And then you’ll notice here, go ahead, that
there’s lighting in the space too that was
also reactive to what you were doing in the
space and it was also tied to the music, so
Ableton was kind of driving some of the lighting
as well.
So what you’re seeing here is again a planned
view overhead of the lighting system, a whole
bunch of DMX-addressable wash lighting that
we hit the netting with. Go ahead
And then we used TouchDesigner to drive that.
So we had these different color palettes within
touch for each part of the song. There were
kind of three parts of the song in the timeline.
And then as you pushed in, you’ll see here,
so this is the live installation and you’ll
see different color palettes happening, that’s
based on people actually pushing and pulling.
This is the software working in real time.
And then you’ll see, this is what it kind
of looked like to be there. And this is the
arpeggio, as you can hear.
The lights go in and out, the lights also
change color based on how far in you are,
and this particular instrument was an arpeggiator,
so as you push in you get higher frequencies.
This is a binaural recording. If you all were
listening over headphones right now, as Gabe
is pushing with his right hand and soon with
his left you’d hear it spatialize to that
side and the other side.
And then this is what it looked like in the
end. I don’t know how many of you saw it.
But again, around the perimeter you were pushing
and pulling that kind of spandex mesh and
then in the middle you were encouraged to
climb up in the top and kind of chill out
and listen to the entire piece.
I should also say that the point of this was
so that everybody could manipulate these different
tracks around the room, but all contribute
to the one composition together, so it wasn’t
like you were isolated if you were listening
on one side, you would hear the entire piece
happening.
And I was just going to end on this to say
that we used eight Kinects and Charlie here
who’s brilliant wrote a really rad application
that he’s going to tell you about, but it
was all done over OSC over the network, so
the Kinects and Cinder were driving Ableton,
Max for Live, and MaxMSP. And that was also
driving TouchDesigner for the lights. Charlie,
take it away.
Alright. So I am Charlie Whitney and sometimes
I go by Sharkbox. And I was responsible for
doing a lot of the programming that was taking
the Kinect and taking this data, and then
shipping it out to the other pieces so we
could make cool music.
I’m going to show you some protoypey kind
of things because obviously we couldn’t
build this thing full scale. This was a really
big installation process. It was fabricated
from scratch by our friends The Principals.
And so this is us in their shop. Their very
messy shop at the time. And this is just a
piece of this fabric. So we tested a bunch
of different fabrics, and we needed something
that felt really good.
So my background is in installation work.
So I’m a coder but I do a lot of kind of
media art installation, and if you want people
to touch something, it’s got to feel really
good.
So we had a couple other pieces of fabric
that were maybe more readable by the Kinect,
but they didn’t feel as good. And if you’re
in somewhere where it’s this completely
immersive thing with all of these 40 channels
of sound, its non directional kind of, so
you don’t know where its coming from. So
you really feel like you’re inside something.
So we wanted to encourage people to touch
and explore this thing that you’re inside
of to make you really comfortable. So this
is a single swatch of this fabric that we
had. We ended up stitching three of these
together for the outer panels.
And these deform really easily. They’re
really soft so that we can get these sort
of highlighted areas where you’re pushing
out.
And like I said in the video, the holes in
this are a weird size, where the Kinect 2
is a Time of Flight camera as opposed to the
Kinect 1, which is more like laser grid. And
for whatever reason the size of the fabric
is just… the holes are big enough so that
the depth camera hits em and stops.
But all the other cameras see right through
them. And we had a really funny experience
when we were testing this where if you push
too far, if you’re really stretching it
out you’re actually stretching the holes
out and there becomes a point where if you
push it too far the holes actually became
see through and all of a sudden the depth
camera would pop through and you would see
a person behind there. It was really weird.
So we almost had to work around that but it’s
a cool interaction – maybe something in
the future.
Here’s another pretty dirty prototype. This
is one of the first things we did. So that
same piece of fabric we were just looking
at. And there was even a video that Dave showed
earlier, just pushing on this one piece of
fabric, and what you can see here is there’s
these 4 blue dots.
And this was our first attempt at getting
differences in the fabric, like what happens
when you press up, down, left, and right.
So what we’re literally doing is just sampling
the depth at the fabric underneath these blue
points.
So on this, the top point is fully triggered.
So we had a four-channel sound system hooked
up just to mess around with this and we were
just seeing – can you do up, down, left,
right – what is actually possible? I don’t
know if anybody had done as fine an articulation
of fabric, and it was a lot of testing to
figure out what this thing could be.
We weren’t sure at the beginning. Cool.
So this is actually, this is Dave from above.
This is something we were going to try to
do. We had this idea for these kind of cylindrical
things that you would go inside of or be on
the outside of and we wanted to see if you
could test the fabric deforming from up above.
These were going to be these really weird
percussive-like almost drums we were going
to make, but it didn’t really work, so this
disappeared, but it was a cool point of the
process. Actually could you go back to the
blank one? I think that was a video? Alright,
no? Alright, keep going.
So this is where the Kinects were actually
positioned. So this is just the front side
of it. There were four on the front and four
on the back side, so this is just looking
from the front.
And you can see that we have two in the far
corners, which were looking at that really
fine, that soft touchable mesh that I was
talking about. And these two kind of in the
middle were just looking at the cargo net
fabric in the middle.
And this is kind of what they were covering.
So the blue ones are the ones that were covering
the fabric net, and then the pink is covering
the cargo. So this is very approximate, I
just drew this, but it gives you an idea of
how much coverage we really could get.
The Kinect 2 can see I think 120 degrees,
maybe even a little bit more, so we were able
to get close and really wide with these, and
get a really good amount of coverage.
And then we were able to get like an x, y
position of where somebody was touching on
this fabric. We can get the x, we can kind
of approximate the y, and we were trying to
get a z position, how far someone pushes into
the fabric.
And it was a little bit tricky because we’re
not hitting it head on. But what we found
was that if you just push a little bit it
only deforms the fabric a tiny bit, but when
you start pushing huge, the whole fabric moves.
So it was a much better metric to kind of
see how much fabric was moving instead of
how far they were pushing it.
Because a bigger push would move more fabric.
It’s kind of weird but I’ll show you an
example.
So this is a video that’s maybe playing…
all right so this is actually an application
that you can download. We took some of our
tools and made it into an app that you can
download. So you can see this pink box that’s
happening – this is sort of the amount of
fabric that is being displaced. And then there’s
a dot in the center, and this is sort of our
x, y position.
So up in the upper right hand corner we have
the image from the depth camera. The left
side is the debug, what’s happening after
all these sliders and filters are messed around
with.
And that thing down here is what is called
our region of interest, so that’s what we’re
really looking at and trying to figure out
like where is this depth. It’s just a little
snapshot. So this will actually output OSC,
so if you’re a musician and you want to
do something with soft tracking you can just
boot this up and it will start sending you
messages that you can map to Ableton or Max
or whatever.
And it’s a little bit blue but this is the
address, it’s http://github.com/cwhitney/DelqaTools
and it’s free. It’s open source. It’s
pretty rad that Microsoft let us put that
up. So check it out.
Okay cool. Thanks guys. So…. yeah. There
you go.
I think we’re going to open it up to questions
but first we’re going to go take a look
at this Neon Indian project.
I think just worth saying about this one,
we’re going to watch a little preview video
that’ll give you a sense of what is about
to premiere with the Neon Indian show this
week, actually tomorrow at Webster Hall.
But really again, like with Matthew Dear,
Alan from Neon Indian, we sat with him. We
had some conversations about how can the band
take their show to the next level. Started
kicking around some ideas, and really arrived
at what I think is a really great output.
Let’s play this video and then we can hop
into it.
Short and sweet. But you get the picture.
So, Kamil.
Hello? Thank you Steve. Hello everyone. My
name is Kamil Nawratil. I’m the Creative
Director at VolvoxLabs. We’re based in Brooklyn.
We specialize sort of in interactive installations
as well as content creation as well as kind
of pushing all these ideas into the physical
world.
So what was interesting with this project
is, so essentially, before we worked with
other DJs and musicians, we thought about
how to recreate the virtual into the physical
world and add something on stage.
So, you know, digitally fabricate walls that
we projection map or use screens that we project
through to add another dimension on stage.
But this one, we actually took it backwards
and sort of used the Kinect sensors to recreate
the actual reality, the human geometry, and
put it into our digital software.
So we called it “Reconstructing the Realities,”
and essentially the project consists of three
elements, so first we’re going to use the
Kinects to scan the environment where the
band is. So we’re going to look at the stage,
what’s around, and use the Kinect to get
the geometry data to put in our software and
use it to generate visuals.
This will then… obviously we’re also going
to look at the band members to look at their
movements, get data from that, and project
it back behind them as an extension of the
reality that they’re in.
Also we will be able to use artist content
to sort of feed the color schemes and different
effects within the virtual system.
So again, quickly, about the process. Scanning
– I will show in the bit, I have a little
demo – but the Kinect has a really cool
feature where you can actually point it at
something and retrieve geometrical data as
an object and sort of use it anywhere in other
3D packages to texture it, or spin around
it, shade it, so it’s really interesting.
The second part is looking at the musicians
through the Kinect sensors. So we have five
Kinects on the stage. Each one generates particles
and different instances within our software
which is TouchDesigner to drive the visuals
and represent the music in real time.
Thirdly, we can get inputs from the musicians,
so midi OSC data, doesn’t matter we can
get it in, and drive colors and shapes and
scale of all these objects. That also ties
into the style of the band or the DJ that
possibly can use this package later on.
And then at the end we combine it all together
to recreate reality.
So as Steve mentioned, we sat down with Neon
Indian, with Alan, and he gave us his references,
his visual aesthetic to inspire us a little
bit and sort of add our style on top of it.
So what we came up with is three different
styles within the show. He’s a big fan of
“glitchy” things, so there’s a lot of
glitchiness. Maybe you saw it on Fallon last
night. There was a nice little glitchy river
flowing.
But we’re also pushing the new technology
so you can see these particle people walking
around, its going to be the band members,
as well as virtual cameras spinning around
the stage, so it should be a pretty cool mix
of different stuff.
So scans. I’ll show you a quick demo of
what the Kinect can do.
Just to let you know, Kinect, the awesome
thing about it is that Microsoft opened up
the SDK for it, so you can access pretty much
any information that the Kinect provides,
so whether it’s the tracking of your face,
tracking of your movement, sound tracking,
as well as scanning of the 3D environment,
the environment where the Kinect sits.
What I’m using here is Fusion Explorer,
so you can see the environment, there’s
the depth camera, the camera pose finder,
but what it really does…
So this is how we’ll scan the stage, obviously
it’s Dave, but we can look at room, and
stage and instruments, and we’ll essentially
add that in front of all the dynamic simulation
particle people.
But the cool thing about this is you can actually
walk around an object and get a 360 scan that
you can use later on. You can actually texture
it, too, there’s a capture color mode.
We’re using the depth image to get information
from space and generate different reactions
within our software to where the musicians
are and where their hands are, and where we
are in space essentially. So Kinect is really
great for that. It can actually tell you a
lot about the environment that you’re in.
And here you can see the effects based on
the depth images and point cloud images. Point
cloud image is essentially the position of
ever pixel that the camera looks at in x,
y, z. So here you can see all these instances
attached to those points. It’s really interesting
how you can actually see the 3D geometry of
the shapes that the camera is looking at.
And quickly about the set up on stage. So
we have 5 Kinects. Alan, the main guy, we’re
looking at his whole silhouette. He’s very
dynamic on stage, so we’re going to try
to capture his entire movement and reproject
that as dynamic simulations.
All the other guys, we’ll focus on their
movements, on the instruments, and whatever
they’re doing to create the sound, which
is a little bit different than what we used
to do before with musicians and bands, mainly
DJs, because since we’re looking at their
movements while they’re creating the music,
this is already giving us sound-reactive visual,
which is different than when working with
DJs where you’re trying to really syncopate
everything to the beat and the DJ just stands
there really.
So we’re trying to make up for that with
visuals. But this one, we’re actually getting
a freebie by looking through these sensors
at the musicians and getting these sound-reactive
visuals.
So here you can see all the Kinects are looking
now at a person in space. This is within TouchDesigner
software.
So we’re able to look at the points in the
3D environment and position them wherever
we are, so that during the performance we
can actually move the virtual cameras from
one guy to another. Let’s say Drew at this
point is making the most movements, we’d
probably cut to that to sort of show the situation
and the action.
All that is happening on GPU. GPUs are getting
super powerful these days and anything that’s
real time needs to be sent through that. So
we developed a bunch of techniques to look
at the depth camera image and generate particles
based on that. So we have hundreds of thousands
of objects and geometries happening at the
same time from five people and running at
60 frames per seconds, so that’s really
amazing.
So when Steve approached us he also mentioned
that this will be touring and this should
be packaged so that anyone can tap into it,
like I mentioned before where you can add
your content in and drive the visual style
of your own show.
So we created this DJ interface where you
can access everything from, change the virtual
camera positioning, change the colors, choose
your tracks, and actually also play with the
Kinect cameras. You can see on top there,
there’s five.
You can manipulate the depth image and what
the camera can see in terms of distance. And
on the bottom you can see all the virtual
cameras switchers, so whoever is interesting
at this point you can switch to that super
quickly, as well you can set it to automatic
mode so it’s going to just switch around
on its own.
So. Great job Kamil. Round of applause.

CEO Satya Nadella on the Importance of Education

My great grandfather,
who was a marginal farmer,
had just passed away, leaving my great grandmother
a young widow with two sons and no source
of income.
To provide for her sons and their future,
she had to move to a town nearby,
and make some difficult choices.
She became a domestic servant, but still could
only afford to send one of her sons to school.
While the two boys were close in age, both
in grade school, one was seen as being more
responsible, while the other was a bit of
a troublemaker.
My great grandmother opted to send the more
responsible, diligent son, viewed as having
more potential, into the workforce.
He became a day laborer at a construction
site.
He would continue in that field for the rest
of his life, never given the opportunity to
gain new skills and gain higher level employment.
The other son was sent to the local school,
and that boy was my grandfather.
Despite being seen as the less responsible,
he continued through school and eventually
became a police officer.
Despite entering the workforce nearly a decade
after his brother, his starting salary was
exponentially higher.
It was my grandfather's education and the
eventual career that enabled my father to
pursue his own education, which eventually
allowed me to follow my own passions.
The opportunity my grandfather was given impacted
the trajectories of the generation to come.
This personal story reflects that often repeated
adage, "talent is everywhere but opportunity
is not."
Today's event is about education and technology.
More specifically, it is about empowering
the students of today to create the world
of tomorrow.
We live in an amazing time of technological
progress.
Every aspect of our lives, economies and societies
are being shaped by digital technologies.
However, technology is also creating disruption.
There's a growing concern over job growth,
economic opportunity, and the world we are
building for the next generation.
The real question is how can technology create
more opportunity not for a few but for all.
Addressing that question is core to our mission,
to empower every person and every organization
on the planet to achieve more.
This is not just a set of words for us, but
something we care deeply about.
Our success is measured by others' success.
Democratizing educational opportunities speaks
directly to our mission,
and it's one of the most pressing societal challenges.
Technology can amplify the work of dedicated
people and institutions, but rarely can substitute
for it.
Kentaro Toyama, a former researcher at Microsoft,
and the author of the book, Geek Heresy, captures
it best when he says, "that societal change
requires more than just technology."
"Technocrats," a term that refers to them, have
a tendency to extol the virtues of technology
and view it as a remedy to all that ails the
system.
I'm here today as a heretic.
We are under no illusion that technology alone
is the answer to transforming education.
Dedicated administrators, great teachers,
motivated students, and involved parents and
communities are the ones changing education.
And technology is merely a tool to empower
their creativity, their ingenuity.
It is this opportunity that motivates our
work in education and everything you'll see today.
One of my favorite parts of the job is to
be able to see and learn from the students
all around the world.
Over the past two years, I've had a chance
to visit students from 20-plus countries,
to see students in Jakarta and Tel Aviv use
the same Office tools that my daughters use
in Seattle, how teachers in Tokyo and Madrid
are using Minecraft to teach students computational
thinking, how a group of young female students
in Cairo were inspired to learn to code and
built an app to assist the Syrian refugees
in their own community.
I've been struck by the commonalities amongst
the students, their ingenuity, their thirst
for learning, diversity, and dreams for future.
As I've spent time visiting these classrooms,
a few things stick out to me each time.
First, technology should help, not hinder
teachers' work in the classroom.
Teachers have constant demands on their time.
They must create curriculum, grade tests and
papers, manage classrooms, discipline, educate and inspire.
Each time I leave a classroom, the job of
a teacher makes my job look easy in comparison.
Technology should make teachers' lives simpler
and spark students' creativity, not distract
from it.
This is a top priority that we are focused
on at Microsoft.
Today, you'll see how we're delivering an
accessible, streamlined platform readily available
to all classrooms so teachers spend less time
focused on technology, and more time doing
what they love doing -- inspiring students.
Secondly, the nature of work is changing drastically.
Much of work today happens in teams, within
groups of people working together to solve
a problem, where the sum becomes greater than
the parts.
We need to prepare our students for this future
and enable team-based learning experiences
in the classroom.
Amongst groups of students, between students
and teachers, between teachers and parents
-- what you'll see today is how any classroom
can promote learning through collaboration,
hubs for teamwork, personalized learning tools,
and the ability to co-create.
By empowering students to learn together,
their educational opportunities get better.
Third, we must prepare our students for tomorrow.
Consider the report from the World Economic
Forum and their Jobs Report.
An estimated 65 percent of the students entering
school today will have jobs that do not yet
exist.
Teachers know this.
And they're hungry to equip their students
for this future.
They know that computational thinking and
problem-solving skills are key to the future,
but they also know that they need to take
a much broader view of STEM by bringing STEM
curriculum alongside reading, writing, design,
and art will set these students up for success
in the future.
Throughout today's presentation, we will show
you new technologies designed to address these needs.
And most importantly, how technology can empower
students and teachers to enhance learning
outcomes and create a world of tomorrow.
Lastly, democratizing educational opportunity
must be inclusive of everyone, not just a
select few.
To me, this is something that's deeply personal.
This includes students with disabilities and
different learning styles.
They must be given an opportunity to pursue
their own dreams.
Dyslexia is estimated to impact one in five
people.
72 percent of the classrooms of students with
special learning needs.
Reading is an essential competency.
And once a student falls far behind, it's
difficult to catch up.
And it's just not about reading, you fall
behind in every other subject area.
This is something that we aim to address with
the OneNote Learning Tools designed specifically
to help students with dyslexia, but it can
help students everywhere with their reading
and writing skills.
It's been incredible to hear the feedback
from the teachers using this to teach emerging
first-grade readers, or from parents who have
exhausted their options, seeking help for
their dyslexic children learning to read,
or how a teacher in Macedonia used the learning
tools to teach young students English.
We will take a look at these learning tools
and much more as Terry Myerson joins me today
to share more of the news.
To close, I want everyone to imagine the world
we're building for tomorrow.
Just as my grandfather's opportunity changed
the trajectory of our family, this is what
inspires me.
How can we collectively come together to democratize
the educational opportunity for every student,
both for this generation and the generations
to come?
Thank you all very, very much.
(Cheers, applause.)