EUT on Tour

The team will be attending the Microsoft Management Summit 2010



We also have updates from Lotusphere 09, Microsoft Management Summit 08, TechEd Europe 08 and the Lotus Leadership Alliance 08


Showing posts with label Colin. Show all posts
Showing posts with label Colin. Show all posts

Friday, April 23, 2010

MMS 2010

Done!

Desktop Error Monitoring

This was an excellent session which covered a component of the MDOP suite called Desktop Error Monitoring (DEM). I was extremely impressed with this product demonstration and can see immediate use for it in both our current and future environments. The tool would assist primarily the tier 3 teams (EUT), in strategic problem solving, but would also be useful to tier 2 teams in terms of published problem management, and statistical information. I understand that the tool itself is free, however because we don't have desktop OS enterprise licensing, there will be some commercial issues which would need to be ironed out prior to us deploying - I certainly intend to pursue this investigation, and if necessary raise a business case to implement MDOP as the benefits are clear and immediate.

In order to describe the product, the speakers first talked about why the product exists - this was mainly user need driven:

• Provide an immediate ROI
• Deliver end to end solutions
• Better TCO on desktops/laptops
• Requirement for low cost monitoring for knowledge and productivity issues
• Requirement for better visibility of desktop issues (users automatically reboot, often overwriting error data in the process)

DEM offers the following to help with the above:

• Crash monitoring
• Application and System crash/hang data captured and stored centrally
• Direct access to troubleshooting & solutions
• Agentless deployment (via group policy)
• Lower helpdesk volume calls
• Engagement with support partners
• Internal 'Watson' back-end
• Patch and update tracking
• Easy analysis of captured data reports

The requirements for a DEM deployment are pretty standard:

• A management server
• A reporting server
• An SQL server
• Active Directory
• Global Policies in use in the environment

It's worth noting that DEM is a separate product to SCCM, although SCCM does effectively do the same job albeit on a much bigger scale. DEM is focussed directly on the desktop/laptop environment.

DEM also offered such features as customisable web pages displayed on the desktop when a crash occurs - which means that if we have a solution or workaround already, the user is notified straightaway. This has an obvious effect of reducing helpdesk calls. DEM can also suppress the "Send details to Microsoft" dialog, which users as often as not will click "No" on - once deployed, DEM automatically sends the error data to the central server, and then can display the kind of web page as described above.

Along with application issues, DEM also records system errors such as the dreaded BSOD. One of the issues EUT has faced recently is the issue of collecting BSOD error data - our environment is such that this is not easy on all devices and the user was usually forced to reboot prior to the full error log completing - this could be negated with the DEM system. It is often essential for our vendors that we provide complete error logging so that they can quickly resolve these types of issues, so anything that can help with this will be invaluable to us.

In addition to error data, DEM also captures the CAB file associated with application issues and bundles this in with the reporting - this would help Satyam with issues in packaging and us with patching and update problems. When use in conjunction with crash analysis tools, this is a very powerful way of identifying issues in applications.

In terms of UI, DEM looks very much like SCCM. It has facilities groups similar issues together, but in granular detail (ie by revision/version of individual DLLs) so things like video driver errors etc are clearly visible, even on a cursory glance at the logs.


As I said in the beginning of this article, I intend to follow this up with a serious intent to raising a business case to implement this technology in our environment as soon as possible. It can be used very soon - as soon as the new AD is in production to be exact, and I think the support teams will see the practical benefits immediately. Management should also see benefits from this too - apart from the obvious potential to improve our problem management, quicker and more proactive issue resolution and the potential for ticket reduction; they will also enjoy both the high level reporting available, with the options to produce highly granular reporting if required as well.

Thursday, April 22, 2010

Best practices from Microsoft IT on Config Manager 2007

This was a nice wrap up to the day - the internal MS IT department team lead gave a presentation on how they handle the normal everyday jobs that all users of their products need to do.

The thing that surprised me was that they do not seem to be early adopters of their own technology...obviously they are heavily involved in the Alpha, Beta and QA for their new products (a process they delightfully call "Dogfooding", but in their own environment, they have only recently implemented some of the things I just assumed they would use from day one of it going gold. To give you a couple of highlighted examples, they only began to deploy O/S images six months ago using MDT, and only use one App-V based application throughout the entire organisation.

The other surprise was the size of their team - although the speaker did admit they outsourced for some tasks, their core team is only 13 people. This team services 274,000 clients based at six HQ and client sites globally.

Their SLAs are quite impressive too - for software compliancy (patching etc) they adhere to a 95% compliancy within 3 business days for active exploit patching. For critical updating the SLA is 95% within nine business days.

A large portion of the presentation was around performance monitoring - with such a large organisation which such a high data throughput, they needed to develop their own type of custom reporting, which they achieved with the LogMan tool, and a bundle of custom scripting.

One last point which was quite interesting - they stated that their DC operational costs had reduced by 75% using a virtualisation strategy - they have defined an 8-1 virtual to physical server ratio. They claim that most of the 75% savings are down to power and physical server cost savings, along with standardising the builds for easy and fast provisioning.

Forefront Endpoint Protection 2010

As is becoming very routine now in these sessions, the speakers started off by extolling the virtues of the 'single pane of glass' approach to SCCM and it's components, and Forefront is no exception. Again with this product, we would be able to manage a major portion of our infrastructure seamlessly from a single user interface.

Forefront, for those not familiar, is Microsoft's answer to antivirus, malware, spyware and firewall for enterprise customers. I had my reservations, previous consumer products have been eh....not great, only offering basic protection at best. Forefront however, has been designed from the ground up to be industry class, and my first impressions are that it may well become best of breed.

Of course, being an SCCM component, deployment of policy, updates and signature files are simple and managed in the same way as any other deployment.

In terms of provisioning Forefront to an environment, Microsoft have pushed the boat out somewhat to make it an admins dream. All that is required is for the installation to be completed on a root site, and it's automatically provisioned across the hierarchy, automatically creating additionally required components such as distribution packages. Another good feature is that when deployed to clients, Forefront will (again!) automatically remove/uninstall and other protection software you have installed, although I'm guessing our heavily scripted installations may cause it some issues.

Some of the other benefits mentioned were:

• Protects clients without complexity
• Admin control of protection level
• Protects apps, file systems and network layers
• Template driven policy creation
• SCCM distribution
• Option to control via legacy group policy if required
• Ability to limit the clients apps CPU utilisation of the PC, so as not to slow down the users during mandatory scans
• By leveraging SCCM and WOL (Wake up on LAN), updating and scans can be scheduled out of hours
• Centralised monitoring, alerting and reporting on protection levels, signature and update compliance across the environment via SCCM

Zero Touch Installation using MDT 2010 & SCCM 2007

This lab session went though the steps to configure SCCM/MDT2010 up to the deployment phase for deploying a Windows 7 workstation image. The steps included:

• Configuration of the deployment environment
• Configuration of offline installation of language packs and updates
• Configuration of a new computer PXE environment installation of Windows 7
• A refresh install of Windows 7

The lab was fairly routine, but it was good to go through the steps as I suspect my team will be involved in this heavily in the future.

Configuration Manager v.Next: Device management

Just my 2p's worth....

This session was the best of the week for me - as you know, one of my passions is mobile devices, and especially finding ways to integrate them into the Mars environment to enhance the user experience by giving more choice and flexibility. I've previously reviewed the current crop of Mobile Device Management tools in my blog entries from TechEd 2008, and am very excited to see the new developments and functionality that will be available in SCCM v.Next, particularly as this may well be something we can implement our new environment.

The speakers gave a few interesting statistics which I recorded:

• By 2013, there will be more smartphones than PCs in enterprise level business today
• Devices are trending away from platform conformance (ie iPhone, Android etc are becoming more common)
• 75% of smartphones are consumer bought, but still used for business (guilty as charged m'lord...)

In Mars, this is particularly worth noting due to tight control over business supported mobile devices - associates and contractors who don't qualify will often look for alternatives ways to access their corporate data, and in our environment this could pose a risk to us in terms of data security and corporate privacy as we have no control over these devices currently.

Using the tools available today, we have the following opportunities to take control:

• SMS 2003 - Windows Mobile / CE devices only
• SCCM 2007 - CE 4.2 / Pocket PC 2003 - basic control and provisioning
• MDM 2008 SP1 - Windows Mobile 6.1, mobile VPN, Rich Device Management (remote wipe etc)

When v.Next is available, we can look forward to:

• Management integration in the same UI for desktop, server and mobile devices
• Over the air enrolment (using AD credentials)
• Mobile application deployment (this is cool, see below)
• Monitoring and remediation of non compliant devices
• Support for WinCE 5+, Windows Mobile 5/6/6.1 and Windows Phone 6.5
• Additional platform support (ie Nokia Symbian)
• Over the air inventory and setting management including software and patch deployment, remote device lock/unlock and wipe

The topology v.Next includes the following key server roles for device management:

• Enrolment web proxy point
• Enrolment service point
• Software catalog roles
• Management point
• Distribution point

The speakers went over some enrolment and deployment scenarios, describing the process for establishing mutual trust between the mobile device and the enrolment web proxy, which demonstrated the over the air provisioning. This can be invoked either by the admin in the console in a few easy steps, or by the remote user, using the web based software catalogue which is part of SCCM's standard services. Whichever method is chosen , the end result is the user receiving a notification with instructions specific to their device type, and includes a one time PIN number which is valid for 8 hours by default. Once the user initiates the enrolment process on the device using the PIN, a secure session is initiated and enrolment is completed in the background on the device. Once the process is complete (which can either be bound to the users AD credentials, or specific credentials to the device), you're ready to deploy software, policy and patching to the device, along with being able to over the air inventory, status report (ie memory, CPU, free storage etc) & remote control in the same way as any other domain device. Specifically for mobile devices, you may lock/unlock or wipe the device.

Settings management for mobile devices direct from the console was also covered, and includes:

• Integrated mobile settings
• Support for monitoring and enforcement of policies
• Standard settings and simple UI which will be familiar to any SCCM admin
• Administrator defined settings via mobile registry or omni-uri (configuration via web link)
• All evaluation and remediation is done by the server so that the device isn't slowed by any processes required.

Alongside this, another great thing about this product is that you don't need to create separate security policies for mobile devices - rather you use your baseline desktop/laptop policy and add a supplement configuration item for mobile devices. This will save time for admins and security teams, and also ensure that sweeping security changes, for example a change to the 8/90 password policy, would be affected for all device types at once without the need for many policy changes to encompass all devices. The configuration item contains control for such things as bluetooth networking and sharing, camera use etc, specific to smartphones, along with and password lock policies etc.

Software distribution to mobile devices works in the same way as with any other SCCM deployment, so I won't go into detail here, however one point worth mentioning is that once a mobile device application or patch is packaged, it can be grouped into software collections along with the same applications for other devices on the DP servers, using the same requirement rules (for example device type, available memory and storage etc), and SCCM automatically works out which version to deploy to which device. Also, packages can be signed with a corporate certificate, so that the user can have confidence in the source, and the enterprise maintains continuity of the packages.

So to try and make this clear, if user Colin requires Adobe Reader and had a desktop PC and a smartphone, all the admin needs to do is deploy Adobe Reader once - it will appear on all devices if available and required. The only thing which isn't clear to me at this stage is how license constrains are observed here, user Colin may well own the application on his desktop, but may not be licensed on the mobile device - so I'm not currently clear on how this is handled. I am sure there will be a way though, it's not like Microsoft to miss something as fundamental to their business model as licensing!

Software distribution packages can be in several flavours, including MSI, App-V and mobile CAB. Software can be deployed either via SCCM or user initiated web based self service. The beauty of all this for admins, is that now, mobile devices can be treated pretty much in the same way as desktops and laptops all from the same UI, using the same packaging, monitoring and reporting functionality - giving us control of the devices in our environment finally!

Wednesday, April 21, 2010

Software updates for smart admins

"Software updates for smart admins" consisted of two admins, one from a 50k user strong company, the other with barely 2k users. The point was to show best practices on software updating from different perspectives, with often diverse methods, but ultimately achieving the same end result of software compliance. The session was lively and obviously both admins had very different views on achieving their goal, and although they didn't quite argue about it on stage, they did agree to disagree. The only things they did agree on was that WSUS was old and SCCM was infinitely easier to manage. That and don't sync drivers, which seemed pretty obvious....who wants to download 70gb+ a month?

I will be getting the slide deck from this one though, as some of the methods described looked like they could save quite a bit of time for any admin - please let me know if you'd like a copy.

Monitoring Networks with Operations Manager 2007 R2

Next session was "Monitoring Networks with Operations Manager 2007 R2" I took a lot of notes on this one as I can see the benefits to an ops team, in that we often need to go to the Central Processing or Enterprise Networks teams and say dumb things like "My application is running bad", whereas "Server 51 is connected to Switch ABC on port 1, and we're seeing a lot of dropped packets between 9-11am" would be a bit more useful.

As you'll already doubtless know, R2 supports SNMP (V1 & v2) and can create either SNMP or SysLog workflows. What I didn't know is that it will also integrate with other monitoring solutions such as Solarwinds via a connector so that we can see the outputs of that alerting system right in the SCCM console. Pretty cool eh?

The larger part of the session was devoted (of course!) to v.Next, and how this offers more functionality. Please note this is all work in progress so subject to change before it goes gold.

The key points I noted are:

* Out of the box monitoring/discovery and reporting
* Server to network dependency discovery
* Multi Vendor/Multi Protocol support (SNMP v1/2/3 & IP v4/6 (note that discovery is IP4 ONLY!)
* Better scalability

Discovery can be manual or automatic (auto only needs one router IP address to discover the entire network!) and can be scheduled, via SMNP trigger or used on demand. This will support layer 2 & 3, VLAN memberships and HSRP (Cisco). Key monitor components by default are memory, CPU, Port, Interface card, PSU, temperature and voltage.

Monitoring defaults out of the box include port/interface up/down, traffic volume, CPU % utilisation, data drop and broadcast rates, memory counters (inc total and free RAM), PSU temperature and voltage and connection health end to end.

Final point was on inbuilt visualisation, which comes in either Dashboard or Diagram flavours - both looked common sense and useful, and of course were configurable ad infinitum.

Config Manager v.Next Admin UI

First up today (after the keynote) was "Config Manager v.Next Admin UI" and as you can imagine, was focussed on the improvements of the user interface, compared with previous/current versions. This will only be interesting to existing users of SCCM, new users will just expect the "wunderbar" and ribbon approach, which is delivered. The UI changes are more than just cosmetic of course - of particular note are the very fast and easy sorting and filtering options, both of which are very configurable. Tagging makes grouping very easy and is available on virtually all objects - so for example, you could tie this in with the Role Based Management, and allow site admins to only view objects, policies and devices on their own turf - for example an EU deployment manager could be configured to only see the relevent tasks, devices and functions that he required. Even if we didn't use this kind of restriction, the technology would still be useful to just to simplify views, reports and workflows for any admin working in the environment.

Speaking of reports, they showed an overview of the new graphical functionality built into v.Next - this looked very Spectrum like, and was of course dynamic, allowing you to drill down through the environment, for example down to server certificates and application issues reported by the internal alerting engine.

Also of mention was the automatic deployment statistic reporting options, which by default right out of the box show performance and failure alerting.

Tuesday, April 20, 2010

v.Next overview

Day 2, session 4 was a very good presentation. This one focussed on the upcoming Config Manager v.Next, and the benefits it will offer. The main points I recorded were:

User Centric Client Management - allowing users to connect from anywhere, embracing mobile technologies and central control of assets. v.Next still focuses on system management as with previous versions, but will allow such enhancements as highly configurable deployment options for applications, O/S and patching, for example allowing deployment only for the primary user of a device, out of hours and user selectable download and installation of apps and patches, advanced application management (but with considerably less scripting) and the facility to setup system requirement and dependency checks prior to app deployment, including available memory, disk space and CPU type.

Other points include integration of RBS with templates, a better admin interface and distribution point grouping, cross platform mobile management, including a cute feature which would allow an administrator to package for example Acrobat reader for several device types, and only need to add the user once to the distribution list - v.Next would then deploy to all the users devices as appropriate without the need for separate processes. Also, remote control is integrated into the console for easy multi platform control of devices.

Please check my previous post for the O/S deployment options available with v.Next.

Automating windows

Day 2, session 3 was "Automating windows"- details were pretty sketchy, but I though it sounded interesting...This presentation focussed on manipulating WMI and CIM using Powershell 2, and showed the benefits of replicating changes to single or multiple PCs, even those outside of a DMZ in a secure manner. I must admit, not being a Powershell/WMI wizard myself, I got somewhat lost in the detail on this session, although the benefits of automation were quite clear for task like client monitoring and configuration. Currently we manage this type of activity in the Zen environment, however going forward I can see this technology will be commonly used in the new Mars environment.

Configuration Manager: State of the union

Day 2, Session 2 was entitled "Configuration Manager: State of the union" and was easily the most entertaining session of the day. The hosts started off the presentation showing the various name ideas that the team went through before settling on v.Next, which was amusing if not entirely useful.
They did of course get serious in the presentation, and covered some very slick ideas including integrated Adobe updates in SCCM by the end of 2010, and other 3rd party updates via a third party add-on for SCCM called SCUPdate. The big demo for me was centred around Citrix XenApps deployment of applications via thin client, were the application itself remains on the server, and is seamlessly delivered to the client over either network or internet connection. This seemed to me to be an idea way to deploy and provision applications, and I'm surprised that we haven't seen this technology in Mars as yet.

The rough release timeline for Config Manager v.Next for those interested:

Beta 1 - May 2010
Beta 2 - Q1 2011
RTM - Q3 2011

Day 2 - Keynote from Bob Muglia

Today's event kicked off with a keynote speech from Bob Muglia, president of MS Server and Tools Business. The kenote was quite lively and well presented as you would expect. I didn't take notes during the keynote, but I know Mat will blog heavily about this, so I just robbed some highlights and will let him add the detail.

1) Official releases of both System Centre Data Protection Manager 2010 and System Centre Service Manager 2010.
2) Demonstration of a Distributed Application (DA) with components which were locally monitored and available from the cloud using MS Azure. Demonstration of a task to “Add Web Rule Instances” for the cloud resources. Demonstration of performance information gathered via the web front-end components in Azure. These functions were provided via a management pack that was stated to be publicly available “later this year”.
3) SCVMM 2011 Tech Preview version – The ribbon concept (Microsoft Office, etc) was integrated with SCVMM which implies that this is a technical direction for the UI for the System Centre product line.
4) First sighting of an Opalis workflow within a Operations Manager 2007 R2 console.
5) SCVMM 2010 Tech Preview version – Demonstrated scans for compliance of the image offline, patching offline, and orchestrating deployment of the image. SCVMM was stated to communicate with WSUS for patches.
6) OpsMgr v10 screenshot – displaying changes to the console including the removal of the “Authoring” section and the addition of the “Modelling Configuration”.

Day one wrap

To wrap up the day, I attended an orientation session (better late than never) and then hit the expo hall with Mat to do the tat run. I'm now fully loaded with product brochures, silly putty, badge holders, t-shirts and a rubber duck. Mission accomplished.

Operations Manager 2007 R2: An Introduction

Next up was "Ops Manager 2007 R2: An introduction", which was not what I'd hoped for - the monitoring and alerting processes described where efficient and relatively easy to configure, however the focus in this session was for monitoring Unix/Linux servers, and although I can see the benefits, I didn't feel they were very relevant. I'm looking forward to later sessions on SCOM which will outline the dashboard functions, which I can see will be very useful. Most of the alerting described in this session is adequately covered in our present Spectrum system, and I didn't see much in the way of additional benefits.

Monday, April 19, 2010

Deploying Windows 7 with Config Manager 2007

The next session was "Deploying Windows 7 with Config Manager 2007", a subject which will become dear to the hearts of the ops team. The lab ran through creating a Win7 image, processing for DVD/Server based distribution, scripting (read wizarding, no programming required) the migration from a Windows XP SP3 workstation up to Windows 7 using a customised PXE build process, and verification of the build, complete with re-partitioning if required, all from within the config manager console. The process was quite lengthy, and took all of the available time that I had in the lab (80 minutes), but was ultimately successful, which is very encouraging for our future use. Most of the time was spent creating the Win7 image, which of course only needs to be done once and would be done long before production deployment. The actual migration/deployment portion was pretty quick even on a VM, but I'd love to try the process on metal to see what the performance is like. Methinks I'll be building a nice little environment in STU before long.....

SCCM

My first session today was entitled "Basic Software Distribution in Config Manager v.Next"
v.Next seems to be the latest incarnation of the SCCM software suite for 2010, perhaps Mat can clarify as it wasn't very clear to me, but no matter, it pretty much rocked whatever it's called.
I was really pleased to see that the "Basic" in the title didn't mean simple or beginner - for me basic in this context means that all of the everyday stuff I'd want to do with software distribution was easy to find and very easy to manipulate. The interface is different to what I remember, but they seem to have made simple tasks much easier to manage. The tasks in this lab centred around taking an application which had been previously packaged, and sending it to the distribution points. Once set there, a simple policy change pushed the package out to my virtual clients, and based on my selected settings installed the package automatically. The process was flawless, and monitoring both the distribution points, the clients and the install status was very clear. The lab built in a deliberate error so that you could demonstrate a remote package fix and re-install from the console - very slick. This technology will make both client package and client enforced security updates a doddle to manage centrally.

How big is this hotel? It's more like a small city...

The MMS event is being held at The Venetian hotel in the heart of the Las Vegas strip, and is quite simply immense. I had thought that Treasure Island, the hotel where Mat & I are staying was huge, but I think it would fit 3 times over in The Venetian. Anywhere that takes 10 minutes from the front entrance just to the start of the conference area is big in my books. The conference centre is pretty huge too, comprising of several ballrooms, ante rooms and chambers on two floors, and is easily accommodating the 3500 or so attendees.

Mat and I arrived bright and early for registration, and I was amazed to see several hundred people already queuing up. I have to say though, the MS conferencing staff are pretty organised, and we got through registration in less than 20 minutes, which was a relief as I'd had visions of standing around for a couple of hours when I initially saw the queues.

One of the very best things about the MS events are the labs, either instructor led, or self paced. They give you the opportunity to properly play with the software in a virtual production environment which include everything you could possibly need: multiple servers and clients, and several disparate environments mixing Windows, Unix, Linux (sadly no Macs yet, can't think why...), and they provide this setup individually for up to 100 users at a time, in no less than 10 separate labs - simultaneously! Lets put that into perspective...at any one time, 1000 users can be individually rocking two or three servers, 2 workstations of multiple flavours, doing heavy duty system admin tasks and if anything goes bad for a user or you simply want to start from scratch, the whole setup can be re-provisioned in around 2 minutes. This is a real testament to how impressive virtual environments are these days, and I can't say just how impressed I am with it. I wonder how long it will be before Mars starts taking full advantage of what this technology could offer us? Dev' team, let me know, 'cause it'd make the ops and site teams jobs sooooo much easier!

Welcome to Vegas!

This is my first visit to Las Vegas, so Mat & I spent the weekend 'chillaxing' wandering up and down the strip. Mat's obviously been before, and pointed out some of the attractions - to be honest for a poor country boy like me, it's all a bit overwhelming - the noise is deafening 24/7 and it's constantly busy everywhere. What doesn't help is that you can walk down to the lobby at 4am and it's as busy and loud in the perpetual twilight casinos as it is at 2pm. Trust me when I say that this does not help with jet lag! All in all though, it's pretty exciting to be here, and I'm really looking forward to the MMS .

This week, I'll be concentrating predominantly on SCCM (Systems Centre Config Manager), packaging deployment, desktop deployment and migration, with a fair smattering of SCOM (Systems Centre Operations Manager). If there is anything that you want me to investigate on your behalf, be it attending sessions or gathering information from vendors, please let me know.

The summit's content overview is here so please take a look and tell me if you need me to focus on anything I didn't mention above.

Tuesday, April 29, 2008

Colin's Bag

Colin asked me to get him a bag if I could for his laptop. I managed to get you this one...it ties in with the company's sustainability theme too!

Only kidding, the conference bag is perhaps more your style...