Friday, April 23, 2010
Desktop Error Monitoring
In order to describe the product, the speakers first talked about why the product exists - this was mainly user need driven:
• Provide an immediate ROI
• Deliver end to end solutions
• Better TCO on desktops/laptops
• Requirement for low cost monitoring for knowledge and productivity issues
• Requirement for better visibility of desktop issues (users automatically reboot, often overwriting error data in the process)
DEM offers the following to help with the above:
• Crash monitoring
• Application and System crash/hang data captured and stored centrally
• Direct access to troubleshooting & solutions
• Agentless deployment (via group policy)
• Lower helpdesk volume calls
• Engagement with support partners
• Internal 'Watson' back-end
• Patch and update tracking
• Easy analysis of captured data reports
The requirements for a DEM deployment are pretty standard:
• A management server
• A reporting server
• An SQL server
• Active Directory
• Global Policies in use in the environment
It's worth noting that DEM is a separate product to SCCM, although SCCM does effectively do the same job albeit on a much bigger scale. DEM is focussed directly on the desktop/laptop environment.
DEM also offered such features as customisable web pages displayed on the desktop when a crash occurs - which means that if we have a solution or workaround already, the user is notified straightaway. This has an obvious effect of reducing helpdesk calls. DEM can also suppress the "Send details to Microsoft" dialog, which users as often as not will click "No" on - once deployed, DEM automatically sends the error data to the central server, and then can display the kind of web page as described above.
Along with application issues, DEM also records system errors such as the dreaded BSOD. One of the issues EUT has faced recently is the issue of collecting BSOD error data - our environment is such that this is not easy on all devices and the user was usually forced to reboot prior to the full error log completing - this could be negated with the DEM system. It is often essential for our vendors that we provide complete error logging so that they can quickly resolve these types of issues, so anything that can help with this will be invaluable to us.
In addition to error data, DEM also captures the CAB file associated with application issues and bundles this in with the reporting - this would help Satyam with issues in packaging and us with patching and update problems. When use in conjunction with crash analysis tools, this is a very powerful way of identifying issues in applications.
In terms of UI, DEM looks very much like SCCM. It has facilities groups similar issues together, but in granular detail (ie by revision/version of individual DLLs) so things like video driver errors etc are clearly visible, even on a cursory glance at the logs.
As I said in the beginning of this article, I intend to follow this up with a serious intent to raising a business case to implement this technology in our environment as soon as possible. It can be used very soon - as soon as the new AD is in production to be exact, and I think the support teams will see the practical benefits immediately. Management should also see benefits from this too - apart from the obvious potential to improve our problem management, quicker and more proactive issue resolution and the potential for ticket reduction; they will also enjoy both the high level reporting available, with the options to produce highly granular reporting if required as well.
Thursday, April 22, 2010
Best practices from Microsoft IT on Config Manager 2007
The thing that surprised me was that they do not seem to be early adopters of their own technology...obviously they are heavily involved in the Alpha, Beta and QA for their new products (a process they delightfully call "Dogfooding", but in their own environment, they have only recently implemented some of the things I just assumed they would use from day one of it going gold. To give you a couple of highlighted examples, they only began to deploy O/S images six months ago using MDT, and only use one App-V based application throughout the entire organisation.
The other surprise was the size of their team - although the speaker did admit they outsourced for some tasks, their core team is only 13 people. This team services 274,000 clients based at six HQ and client sites globally.
Their SLAs are quite impressive too - for software compliancy (patching etc) they adhere to a 95% compliancy within 3 business days for active exploit patching. For critical updating the SLA is 95% within nine business days.
A large portion of the presentation was around performance monitoring - with such a large organisation which such a high data throughput, they needed to develop their own type of custom reporting, which they achieved with the LogMan tool, and a bundle of custom scripting.
One last point which was quite interesting - they stated that their DC operational costs had reduced by 75% using a virtualisation strategy - they have defined an 8-1 virtual to physical server ratio. They claim that most of the 75% savings are down to power and physical server cost savings, along with standardising the builds for easy and fast provisioning.
Forefront Endpoint Protection 2010
Forefront, for those not familiar, is Microsoft's answer to antivirus, malware, spyware and firewall for enterprise customers. I had my reservations, previous consumer products have been eh....not great, only offering basic protection at best. Forefront however, has been designed from the ground up to be industry class, and my first impressions are that it may well become best of breed.
Of course, being an SCCM component, deployment of policy, updates and signature files are simple and managed in the same way as any other deployment.
In terms of provisioning Forefront to an environment, Microsoft have pushed the boat out somewhat to make it an admins dream. All that is required is for the installation to be completed on a root site, and it's automatically provisioned across the hierarchy, automatically creating additionally required components such as distribution packages. Another good feature is that when deployed to clients, Forefront will (again!) automatically remove/uninstall and other protection software you have installed, although I'm guessing our heavily scripted installations may cause it some issues.
Some of the other benefits mentioned were:
• Protects clients without complexity
• Admin control of protection level
• Protects apps, file systems and network layers
• Template driven policy creation
• SCCM distribution
• Option to control via legacy group policy if required
• Ability to limit the clients apps CPU utilisation of the PC, so as not to slow down the users during mandatory scans
• By leveraging SCCM and WOL (Wake up on LAN), updating and scans can be scheduled out of hours
• Centralised monitoring, alerting and reporting on protection levels, signature and update compliance across the environment via SCCM
Zero Touch Installation using MDT 2010 & SCCM 2007
• Configuration of the deployment environment
• Configuration of offline installation of language packs and updates
• Configuration of a new computer PXE environment installation of Windows 7
• A refresh install of Windows 7
The lab was fairly routine, but it was good to go through the steps as I suspect my team will be involved in this heavily in the future.
Configuration Manager v.Next: Device management
This session was the best of the week for me - as you know, one of my passions is mobile devices, and especially finding ways to integrate them into the Mars environment to enhance the user experience by giving more choice and flexibility. I've previously reviewed the current crop of Mobile Device Management tools in my blog entries from TechEd 2008, and am very excited to see the new developments and functionality that will be available in SCCM v.Next, particularly as this may well be something we can implement our new environment.
The speakers gave a few interesting statistics which I recorded:
• By 2013, there will be more smartphones than PCs in enterprise level business today
• Devices are trending away from platform conformance (ie iPhone, Android etc are becoming more common)
• 75% of smartphones are consumer bought, but still used for business (guilty as charged m'lord...)
In Mars, this is particularly worth noting due to tight control over business supported mobile devices - associates and contractors who don't qualify will often look for alternatives ways to access their corporate data, and in our environment this could pose a risk to us in terms of data security and corporate privacy as we have no control over these devices currently.
Using the tools available today, we have the following opportunities to take control:
• SMS 2003 - Windows Mobile / CE devices only
• SCCM 2007 - CE 4.2 / Pocket PC 2003 - basic control and provisioning
• MDM 2008 SP1 - Windows Mobile 6.1, mobile VPN, Rich Device Management (remote wipe etc)
When v.Next is available, we can look forward to:
• Management integration in the same UI for desktop, server and mobile devices
• Over the air enrolment (using AD credentials)
• Mobile application deployment (this is cool, see below)
• Monitoring and remediation of non compliant devices
• Support for WinCE 5+, Windows Mobile 5/6/6.1 and Windows Phone 6.5
• Additional platform support (ie Nokia Symbian)
• Over the air inventory and setting management including software and patch deployment, remote device lock/unlock and wipe
The topology v.Next includes the following key server roles for device management:
• Enrolment web proxy point
• Enrolment service point
• Software catalog roles
• Management point
• Distribution point
The speakers went over some enrolment and deployment scenarios, describing the process for establishing mutual trust between the mobile device and the enrolment web proxy, which demonstrated the over the air provisioning. This can be invoked either by the admin in the console in a few easy steps, or by the remote user, using the web based software catalogue which is part of SCCM's standard services. Whichever method is chosen , the end result is the user receiving a notification with instructions specific to their device type, and includes a one time PIN number which is valid for 8 hours by default. Once the user initiates the enrolment process on the device using the PIN, a secure session is initiated and enrolment is completed in the background on the device. Once the process is complete (which can either be bound to the users AD credentials, or specific credentials to the device), you're ready to deploy software, policy and patching to the device, along with being able to over the air inventory, status report (ie memory, CPU, free storage etc) & remote control in the same way as any other domain device. Specifically for mobile devices, you may lock/unlock or wipe the device.
Settings management for mobile devices direct from the console was also covered, and includes:
• Integrated mobile settings
• Support for monitoring and enforcement of policies
• Standard settings and simple UI which will be familiar to any SCCM admin
• Administrator defined settings via mobile registry or omni-uri (configuration via web link)
• All evaluation and remediation is done by the server so that the device isn't slowed by any processes required.
Alongside this, another great thing about this product is that you don't need to create separate security policies for mobile devices - rather you use your baseline desktop/laptop policy and add a supplement configuration item for mobile devices. This will save time for admins and security teams, and also ensure that sweeping security changes, for example a change to the 8/90 password policy, would be affected for all device types at once without the need for many policy changes to encompass all devices. The configuration item contains control for such things as bluetooth networking and sharing, camera use etc, specific to smartphones, along with and password lock policies etc.
Software distribution to mobile devices works in the same way as with any other SCCM deployment, so I won't go into detail here, however one point worth mentioning is that once a mobile device application or patch is packaged, it can be grouped into software collections along with the same applications for other devices on the DP servers, using the same requirement rules (for example device type, available memory and storage etc), and SCCM automatically works out which version to deploy to which device. Also, packages can be signed with a corporate certificate, so that the user can have confidence in the source, and the enterprise maintains continuity of the packages.
So to try and make this clear, if user Colin requires Adobe Reader and had a desktop PC and a smartphone, all the admin needs to do is deploy Adobe Reader once - it will appear on all devices if available and required. The only thing which isn't clear to me at this stage is how license constrains are observed here, user Colin may well own the application on his desktop, but may not be licensed on the mobile device - so I'm not currently clear on how this is handled. I am sure there will be a way though, it's not like Microsoft to miss something as fundamental to their business model as licensing!
Software distribution packages can be in several flavours, including MSI, App-V and mobile CAB. Software can be deployed either via SCCM or user initiated web based self service. The beauty of all this for admins, is that now, mobile devices can be treated pretty much in the same way as desktops and laptops all from the same UI, using the same packaging, monitoring and reporting functionality - giving us control of the devices in our environment finally!
Wednesday, April 21, 2010
Software updates for smart admins
I will be getting the slide deck from this one though, as some of the methods described looked like they could save quite a bit of time for any admin - please let me know if you'd like a copy.
Monitoring Networks with Operations Manager 2007 R2
Next session was "Monitoring Networks with Operations Manager 2007 R2" I took a lot of notes on this one as I can see the benefits to an ops team, in that we often need to go to the Central Processing or Enterprise Networks teams and say dumb things like "My application is running bad", whereas "Server 51 is connected to Switch ABC on port 1, and we're seeing a lot of dropped packets between 9-11am" would be a bit more useful.
As you'll already doubtless know, R2 supports SNMP (V1 & v2) and can create either SNMP or SysLog workflows. What I didn't know is that it will also integrate with other monitoring solutions such as Solarwinds via a connector so that we can see the outputs of that alerting system right in the SCCM console. Pretty cool eh?
The larger part of the session was devoted (of course!) to v.Next, and how this offers more functionality. Please note this is all work in progress so subject to change before it goes gold.
The key points I noted are:
* Out of the box monitoring/discovery and reporting
* Server to network dependency discovery
* Multi Vendor/Multi Protocol support (SNMP v1/2/3 & IP v4/6 (note that discovery is IP4 ONLY!)
* Better scalability
Discovery can be manual or automatic (auto only needs one router IP address to discover the entire network!) and can be scheduled, via SMNP trigger or used on demand. This will support layer 2 & 3, VLAN memberships and HSRP (Cisco). Key monitor components by default are memory, CPU, Port, Interface card, PSU, temperature and voltage.
Monitoring defaults out of the box include port/interface up/down, traffic volume, CPU % utilisation, data drop and broadcast rates, memory counters (inc total and free RAM), PSU temperature and voltage and connection health end to end.
Final point was on inbuilt visualisation, which comes in either Dashboard or Diagram flavours - both looked common sense and useful, and of course were configurable ad infinitum.
Config Manager v.Next Admin UI
Speaking of reports, they showed an overview of the new graphical functionality built into v.Next - this looked very Spectrum like, and was of course dynamic, allowing you to drill down through the environment, for example down to server certificates and application issues reported by the internal alerting engine.
Also of mention was the automatic deployment statistic reporting options, which by default right out of the box show performance and failure alerting.
Tuesday, April 20, 2010
v.Next overview
User Centric Client Management - allowing users to connect from anywhere, embracing mobile technologies and central control of assets. v.Next still focuses on system management as with previous versions, but will allow such enhancements as highly configurable deployment options for applications, O/S and patching, for example allowing deployment only for the primary user of a device, out of hours and user selectable download and installation of apps and patches, advanced application management (but with considerably less scripting) and the facility to setup system requirement and dependency checks prior to app deployment, including available memory, disk space and CPU type.
Other points include integration of RBS with templates, a better admin interface and distribution point grouping, cross platform mobile management, including a cute feature which would allow an administrator to package for example Acrobat reader for several device types, and only need to add the user once to the distribution list - v.Next would then deploy to all the users devices as appropriate without the need for separate processes. Also, remote control is integrated into the console for easy multi platform control of devices.
Please check my previous post for the O/S deployment options available with v.Next.
Automating windows
Configuration Manager: State of the union
They did of course get serious in the presentation, and covered some very slick ideas including integrated Adobe updates in SCCM by the end of 2010, and other 3rd party updates via a third party add-on for SCCM called SCUPdate. The big demo for me was centred around Citrix XenApps deployment of applications via thin client, were the application itself remains on the server, and is seamlessly delivered to the client over either network or internet connection. This seemed to me to be an idea way to deploy and provision applications, and I'm surprised that we haven't seen this technology in Mars as yet.
The rough release timeline for Config Manager v.Next for those interested:
Beta 1 - May 2010
Beta 2 - Q1 2011
RTM - Q3 2011
Day 2 - Keynote from Bob Muglia
1) Official releases of both System Centre Data Protection Manager 2010 and System Centre Service Manager 2010.
2) Demonstration of a Distributed Application (DA) with components which were locally monitored and available from the cloud using MS Azure. Demonstration of a task to “Add Web Rule Instances” for the cloud resources. Demonstration of performance information gathered via the web front-end components in Azure. These functions were provided via a management pack that was stated to be publicly available “later this year”.
3) SCVMM 2011 Tech Preview version – The ribbon concept (Microsoft Office, etc) was integrated with SCVMM which implies that this is a technical direction for the UI for the System Centre product line.
4) First sighting of an Opalis workflow within a Operations Manager 2007 R2 console.
5) SCVMM 2010 Tech Preview version – Demonstrated scans for compliance of the image offline, patching offline, and orchestrating deployment of the image. SCVMM was stated to communicate with WSUS for patches.
6) OpsMgr v10 screenshot – displaying changes to the console including the removal of the “Authoring” section and the addition of the “Modelling Configuration”.
Day one wrap
Operations Manager 2007 R2: An Introduction
Monday, April 19, 2010
Deploying Windows 7 with Config Manager 2007
SCCM
v.Next seems to be the latest incarnation of the SCCM software suite for 2010, perhaps Mat can clarify as it wasn't very clear to me, but no matter, it pretty much rocked whatever it's called.
I was really pleased to see that the "Basic" in the title didn't mean simple or beginner - for me basic in this context means that all of the everyday stuff I'd want to do with software distribution was easy to find and very easy to manipulate. The interface is different to what I remember, but they seem to have made simple tasks much easier to manage. The tasks in this lab centred around taking an application which had been previously packaged, and sending it to the distribution points. Once set there, a simple policy change pushed the package out to my virtual clients, and based on my selected settings installed the package automatically. The process was flawless, and monitoring both the distribution points, the clients and the install status was very clear. The lab built in a deliberate error so that you could demonstrate a remote package fix and re-install from the console - very slick. This technology will make both client package and client enforced security updates a doddle to manage centrally.
How big is this hotel? It's more like a small city...
Mat and I arrived bright and early for registration, and I was amazed to see several hundred people already queuing up. I have to say though, the MS conferencing staff are pretty organised, and we got through registration in less than 20 minutes, which was a relief as I'd had visions of standing around for a couple of hours when I initially saw the queues.
One of the very best things about the MS events are the labs, either instructor led, or self paced. They give you the opportunity to properly play with the software in a virtual production environment which include everything you could possibly need: multiple servers and clients, and several disparate environments mixing Windows, Unix, Linux (sadly no Macs yet, can't think why...), and they provide this setup individually for up to 100 users at a time, in no less than 10 separate labs - simultaneously! Lets put that into perspective...at any one time, 1000 users can be individually rocking two or three servers, 2 workstations of multiple flavours, doing heavy duty system admin tasks and if anything goes bad for a user or you simply want to start from scratch, the whole setup can be re-provisioned in around 2 minutes. This is a real testament to how impressive virtual environments are these days, and I can't say just how impressed I am with it. I wonder how long it will be before Mars starts taking full advantage of what this technology could offer us? Dev' team, let me know, 'cause it'd make the ops and site teams jobs sooooo much easier!
Welcome to Vegas!
This week, I'll be concentrating predominantly on SCCM (Systems Centre Config Manager), packaging deployment, desktop deployment and migration, with a fair smattering of SCOM (Systems Centre Operations Manager). If there is anything that you want me to investigate on your behalf, be it attending sessions or gathering information from vendors, please let me know.
The summit's content overview is here so please take a look and tell me if you need me to focus on anything I didn't mention above.
Tuesday, April 29, 2008
Colin's Bag

Only kidding, the conference bag is perhaps more your style...
