EUT on Tour

The team will be attending the Microsoft Management Summit 2010



We also have updates from Lotusphere 09, Microsoft Management Summit 08, TechEd Europe 08 and the Lotus Leadership Alliance 08


Showing posts with label MMS2010. Show all posts
Showing posts with label MMS2010. Show all posts

Friday, April 23, 2010

Server Quarium

I said I'd try to get some pics of the Server Quarium that was running the labs so you could see some of the plasma screens. Some of these are examples of Configuration Manager Dashboards too. I think you can click through to see them larger.

Not sure how well these have come out -












Centralising and managing user data

Just after 8am on the morning after the attendee party and as you can guess this session was not well attended. That was a shame as it was very good.

The two presenters are part of the Windows File team and had done some work internally at MS to centralise and manage data of users on this pilot.

Aims:

  1. 99.99% availability (less than 5 mins a year downtime in their environment)
  2. Near local access times, regardless of the location of user/data
  3. Recovery Point Objective (RPO) of zero data loss for the central location
  4. Single backup server
  5. Selective file/folder restore by end user.
  6. Same view of files wherever the user logs on

Technologies leveraged:

  • 10Gb quota per user
  • Folder redirection and offline file cache
  • Backups via SCDPM
  • Windows 7 - when user logs on first time, files are moved to local offline cache then synced with server transparently. This is better than previous versions of Windows which blocked access to desktop until files copied up to server and then back to local offline cache.
  • Slowlink mode in Windows 7 - detects when link is slow and makes user work locally then syncs when Lan/Wan is better
  • SMB 2.1 - better Oplock model so client can sleep (Office uses oplocks and would stop computers sleeping unnecessarily.
  • File System Resource Manager (FSRM) - quotas, allowed file types, periodic or on demand reporting to see storage trends etc
  • File Classification Infrastructure - assesses how files are used long term, can choose to compress, or tie into Hierarchial Storage Management (HSM)
  • Shadow copy for shared folders - allows users to be self sufficient in restoring previous file versions (they have to be online to recover).
  • Policies/GPO

All the demos worked smoothly to prove it. We are doing some similar things with our solution, such as shadow copy, backups in data centre. Here is a great example of how we can take this forward, particularly for roaming users - why should my data be tied to ISB, if MTO can provide a much better service in every location; rather than good service in ISB but shocking elsewhere?

Again one to consider for the roadmap.

Diagnostics and Recovery Toolset

The Diagnostics and Recovery Toolset (DART), is another great tool in the MDOP suite.

The MDOP suite typically saves $70-80 net per pc per year (WIPRO reseach). DART can be $10 dollars of that.

DART is basically a bootable CD/DVD (USB and WIM work but are not supported) that runs on WinRE (Windows Recovery Environment) and is used to troubleshoot/repair a client machine before just rebuilding.
It Can:
  1. Recover an unbootable PC
  2. Detect and remove malware (whilst the PC is booted in WinRE)
  3. Delete, recover, save off files
  4. Reset local Admin password
  5. Manipulate services
  6. etc

Benefits:

- Accelerates TCO savings by minimising recovery time and preventing data loss.

- Recover instead of rebuild - saves user time and allows root cause analysis

Rebuilding a unbootable PC guarantees data loss, this tool gives you the option to do data recovery at worst case and full system recovery at best. This way the user does not lose data or their time waiting on a rebuild and then their time setting things up just right.

Case study of a company called Ultrasonic Precision Inc they saw Help desk costs decrease 27% and end user downtime decrease between 50-60%.

Demo's were very effective is providing the crash analysis of a blue screen, and restoring data that had been accidentally deleted.

Tools included in DART:

  • ERD Regedit - similar to normal one
  • Locksmith - local admin PW reset
  • Crash analysis - assesses BSOD and gives reasons/help
  • File restore - will scan for all deleted files and give you a likelihood of recovery
  • Disk commander - repair MBR, recover volumes/partition table
  • Disk wipe - secure DoD level wipe to prevent data recovery
  • Computer management - similar to normal
  • Explorer - Gui based, not command prompt as normal WinRE, USB active to save files off or copy them back to restore service
  • Solution Wizard - Wizard to help you choose the right tool to fix the problem (I would think if you need the wizard, you maybe are not the right person to be doing the work - ironically the presenter just said that too)
  • TCP/IP config - if you want to get onto LAN or ensure you can get to internet for System sweeper toget updates.
  • Hotfix uninstall
  • System sweeper - malware/rootkit detection tool,
  • SFC Scan - system file check can be used in Windows (assuming it boots), great to see it here at WinRE level (I have used SFC successfully a few times - correctly restore corrupt system files).

You can add DART tools to a hidden system partition of your builds to ensure they are a F8 option for troubleshooting (probably should not include locksmith).

Whilst it is a MDOP feature, once you are licensed for MDOP on your desktops, you can use it on servers too.

You can create a DART cd/dvd from within a virtual machine - very cool.

Find out more here

Desktop Error Reporting

I was also in this session and agree with what Colin has written, Microsoft Desktop Optimisation Pack, is a great tool. DEM is a great feature of it and the presenter demonstrated these well.

Something we should definitely look further into to understand the cost impact of getting MDOP into our environment and using these tools.

Find out more about it here (Pdf will open)

MMS 2010

Done!

Desktop Error Monitoring

This was an excellent session which covered a component of the MDOP suite called Desktop Error Monitoring (DEM). I was extremely impressed with this product demonstration and can see immediate use for it in both our current and future environments. The tool would assist primarily the tier 3 teams (EUT), in strategic problem solving, but would also be useful to tier 2 teams in terms of published problem management, and statistical information. I understand that the tool itself is free, however because we don't have desktop OS enterprise licensing, there will be some commercial issues which would need to be ironed out prior to us deploying - I certainly intend to pursue this investigation, and if necessary raise a business case to implement MDOP as the benefits are clear and immediate.

In order to describe the product, the speakers first talked about why the product exists - this was mainly user need driven:

• Provide an immediate ROI
• Deliver end to end solutions
• Better TCO on desktops/laptops
• Requirement for low cost monitoring for knowledge and productivity issues
• Requirement for better visibility of desktop issues (users automatically reboot, often overwriting error data in the process)

DEM offers the following to help with the above:

• Crash monitoring
• Application and System crash/hang data captured and stored centrally
• Direct access to troubleshooting & solutions
• Agentless deployment (via group policy)
• Lower helpdesk volume calls
• Engagement with support partners
• Internal 'Watson' back-end
• Patch and update tracking
• Easy analysis of captured data reports

The requirements for a DEM deployment are pretty standard:

• A management server
• A reporting server
• An SQL server
• Active Directory
• Global Policies in use in the environment

It's worth noting that DEM is a separate product to SCCM, although SCCM does effectively do the same job albeit on a much bigger scale. DEM is focussed directly on the desktop/laptop environment.

DEM also offered such features as customisable web pages displayed on the desktop when a crash occurs - which means that if we have a solution or workaround already, the user is notified straightaway. This has an obvious effect of reducing helpdesk calls. DEM can also suppress the "Send details to Microsoft" dialog, which users as often as not will click "No" on - once deployed, DEM automatically sends the error data to the central server, and then can display the kind of web page as described above.

Along with application issues, DEM also records system errors such as the dreaded BSOD. One of the issues EUT has faced recently is the issue of collecting BSOD error data - our environment is such that this is not easy on all devices and the user was usually forced to reboot prior to the full error log completing - this could be negated with the DEM system. It is often essential for our vendors that we provide complete error logging so that they can quickly resolve these types of issues, so anything that can help with this will be invaluable to us.

In addition to error data, DEM also captures the CAB file associated with application issues and bundles this in with the reporting - this would help Satyam with issues in packaging and us with patching and update problems. When use in conjunction with crash analysis tools, this is a very powerful way of identifying issues in applications.

In terms of UI, DEM looks very much like SCCM. It has facilities groups similar issues together, but in granular detail (ie by revision/version of individual DLLs) so things like video driver errors etc are clearly visible, even on a cursory glance at the logs.


As I said in the beginning of this article, I intend to follow this up with a serious intent to raising a business case to implement this technology in our environment as soon as possible. It can be used very soon - as soon as the new AD is in production to be exact, and I think the support teams will see the practical benefits immediately. Management should also see benefits from this too - apart from the obvious potential to improve our problem management, quicker and more proactive issue resolution and the potential for ticket reduction; they will also enjoy both the high level reporting available, with the options to produce highly granular reporting if required as well.

Thursday, April 22, 2010

Best practices from Microsoft IT on Config Manager 2007

This was a nice wrap up to the day - the internal MS IT department team lead gave a presentation on how they handle the normal everyday jobs that all users of their products need to do.

The thing that surprised me was that they do not seem to be early adopters of their own technology...obviously they are heavily involved in the Alpha, Beta and QA for their new products (a process they delightfully call "Dogfooding", but in their own environment, they have only recently implemented some of the things I just assumed they would use from day one of it going gold. To give you a couple of highlighted examples, they only began to deploy O/S images six months ago using MDT, and only use one App-V based application throughout the entire organisation.

The other surprise was the size of their team - although the speaker did admit they outsourced for some tasks, their core team is only 13 people. This team services 274,000 clients based at six HQ and client sites globally.

Their SLAs are quite impressive too - for software compliancy (patching etc) they adhere to a 95% compliancy within 3 business days for active exploit patching. For critical updating the SLA is 95% within nine business days.

A large portion of the presentation was around performance monitoring - with such a large organisation which such a high data throughput, they needed to develop their own type of custom reporting, which they achieved with the LogMan tool, and a bundle of custom scripting.

One last point which was quite interesting - they stated that their DC operational costs had reduced by 75% using a virtualisation strategy - they have defined an 8-1 virtual to physical server ratio. They claim that most of the 75% savings are down to power and physical server cost savings, along with standardising the builds for easy and fast provisioning.

Forefront Endpoint Protection 2010

As is becoming very routine now in these sessions, the speakers started off by extolling the virtues of the 'single pane of glass' approach to SCCM and it's components, and Forefront is no exception. Again with this product, we would be able to manage a major portion of our infrastructure seamlessly from a single user interface.

Forefront, for those not familiar, is Microsoft's answer to antivirus, malware, spyware and firewall for enterprise customers. I had my reservations, previous consumer products have been eh....not great, only offering basic protection at best. Forefront however, has been designed from the ground up to be industry class, and my first impressions are that it may well become best of breed.

Of course, being an SCCM component, deployment of policy, updates and signature files are simple and managed in the same way as any other deployment.

In terms of provisioning Forefront to an environment, Microsoft have pushed the boat out somewhat to make it an admins dream. All that is required is for the installation to be completed on a root site, and it's automatically provisioned across the hierarchy, automatically creating additionally required components such as distribution packages. Another good feature is that when deployed to clients, Forefront will (again!) automatically remove/uninstall and other protection software you have installed, although I'm guessing our heavily scripted installations may cause it some issues.

Some of the other benefits mentioned were:

• Protects clients without complexity
• Admin control of protection level
• Protects apps, file systems and network layers
• Template driven policy creation
• SCCM distribution
• Option to control via legacy group policy if required
• Ability to limit the clients apps CPU utilisation of the PC, so as not to slow down the users during mandatory scans
• By leveraging SCCM and WOL (Wake up on LAN), updating and scans can be scheduled out of hours
• Centralised monitoring, alerting and reporting on protection levels, signature and update compliance across the environment via SCCM

Zero Touch Installation using MDT 2010 & SCCM 2007

This lab session went though the steps to configure SCCM/MDT2010 up to the deployment phase for deploying a Windows 7 workstation image. The steps included:

• Configuration of the deployment environment
• Configuration of offline installation of language packs and updates
• Configuration of a new computer PXE environment installation of Windows 7
• A refresh install of Windows 7

The lab was fairly routine, but it was good to go through the steps as I suspect my team will be involved in this heavily in the future.

Configuration Manager v.Next: Device management

Just my 2p's worth....

This session was the best of the week for me - as you know, one of my passions is mobile devices, and especially finding ways to integrate them into the Mars environment to enhance the user experience by giving more choice and flexibility. I've previously reviewed the current crop of Mobile Device Management tools in my blog entries from TechEd 2008, and am very excited to see the new developments and functionality that will be available in SCCM v.Next, particularly as this may well be something we can implement our new environment.

The speakers gave a few interesting statistics which I recorded:

• By 2013, there will be more smartphones than PCs in enterprise level business today
• Devices are trending away from platform conformance (ie iPhone, Android etc are becoming more common)
• 75% of smartphones are consumer bought, but still used for business (guilty as charged m'lord...)

In Mars, this is particularly worth noting due to tight control over business supported mobile devices - associates and contractors who don't qualify will often look for alternatives ways to access their corporate data, and in our environment this could pose a risk to us in terms of data security and corporate privacy as we have no control over these devices currently.

Using the tools available today, we have the following opportunities to take control:

• SMS 2003 - Windows Mobile / CE devices only
• SCCM 2007 - CE 4.2 / Pocket PC 2003 - basic control and provisioning
• MDM 2008 SP1 - Windows Mobile 6.1, mobile VPN, Rich Device Management (remote wipe etc)

When v.Next is available, we can look forward to:

• Management integration in the same UI for desktop, server and mobile devices
• Over the air enrolment (using AD credentials)
• Mobile application deployment (this is cool, see below)
• Monitoring and remediation of non compliant devices
• Support for WinCE 5+, Windows Mobile 5/6/6.1 and Windows Phone 6.5
• Additional platform support (ie Nokia Symbian)
• Over the air inventory and setting management including software and patch deployment, remote device lock/unlock and wipe

The topology v.Next includes the following key server roles for device management:

• Enrolment web proxy point
• Enrolment service point
• Software catalog roles
• Management point
• Distribution point

The speakers went over some enrolment and deployment scenarios, describing the process for establishing mutual trust between the mobile device and the enrolment web proxy, which demonstrated the over the air provisioning. This can be invoked either by the admin in the console in a few easy steps, or by the remote user, using the web based software catalogue which is part of SCCM's standard services. Whichever method is chosen , the end result is the user receiving a notification with instructions specific to their device type, and includes a one time PIN number which is valid for 8 hours by default. Once the user initiates the enrolment process on the device using the PIN, a secure session is initiated and enrolment is completed in the background on the device. Once the process is complete (which can either be bound to the users AD credentials, or specific credentials to the device), you're ready to deploy software, policy and patching to the device, along with being able to over the air inventory, status report (ie memory, CPU, free storage etc) & remote control in the same way as any other domain device. Specifically for mobile devices, you may lock/unlock or wipe the device.

Settings management for mobile devices direct from the console was also covered, and includes:

• Integrated mobile settings
• Support for monitoring and enforcement of policies
• Standard settings and simple UI which will be familiar to any SCCM admin
• Administrator defined settings via mobile registry or omni-uri (configuration via web link)
• All evaluation and remediation is done by the server so that the device isn't slowed by any processes required.

Alongside this, another great thing about this product is that you don't need to create separate security policies for mobile devices - rather you use your baseline desktop/laptop policy and add a supplement configuration item for mobile devices. This will save time for admins and security teams, and also ensure that sweeping security changes, for example a change to the 8/90 password policy, would be affected for all device types at once without the need for many policy changes to encompass all devices. The configuration item contains control for such things as bluetooth networking and sharing, camera use etc, specific to smartphones, along with and password lock policies etc.

Software distribution to mobile devices works in the same way as with any other SCCM deployment, so I won't go into detail here, however one point worth mentioning is that once a mobile device application or patch is packaged, it can be grouped into software collections along with the same applications for other devices on the DP servers, using the same requirement rules (for example device type, available memory and storage etc), and SCCM automatically works out which version to deploy to which device. Also, packages can be signed with a corporate certificate, so that the user can have confidence in the source, and the enterprise maintains continuity of the packages.

So to try and make this clear, if user Colin requires Adobe Reader and had a desktop PC and a smartphone, all the admin needs to do is deploy Adobe Reader once - it will appear on all devices if available and required. The only thing which isn't clear to me at this stage is how license constrains are observed here, user Colin may well own the application on his desktop, but may not be licensed on the mobile device - so I'm not currently clear on how this is handled. I am sure there will be a way though, it's not like Microsoft to miss something as fundamental to their business model as licensing!

Software distribution packages can be in several flavours, including MSI, App-V and mobile CAB. Software can be deployed either via SCCM or user initiated web based self service. The beauty of all this for admins, is that now, mobile devices can be treated pretty much in the same way as desktops and laptops all from the same UI, using the same packaging, monitoring and reporting functionality - giving us control of the devices in our environment finally!

App-V Overview

This session was to give a brief overview of App-v, it's benefits and some demos.

Application deployments are costly (as we know), App-v enables a desktop virtualisation solution by virtualising applications. (This is often known as presentation virtualisation - think traditional Citrix, however this has evolved slightly and now MS and Citrix include app streaming too)

A couple of customer examples: One cut app deployment from 3 months to 3 days, another reduced packaging costs by 50% and finally one reduced the amount pf PC images they needed.

The App-v sequencer was demonstrated with the app packaged in a matter of minutes. Obviously this package can then be deployed to any hardware, quickly and managed centrally. You can choose to stream (allow user to start the app before it is installed locally) or just do the deployment - streaming would be great for a large app.

Obviously it all ties into the one infrastructure, one management product suite tools message and helps you become user centric.

The recent 4.6 release of App-v is 64bit on servers/apps/infrastructure - so making the best use of what you have in terms of performance, CPU/Ram usage. There are specific things that allow for better Office 2010 virtualisation. They have managed to create a shared cache for apps between VDI and Terminal Services saving on diskspace significantly - often you would have previously had a package for each. Best of all, each app operates independently, so an app crash does not take down the whole OS.

It is still a good product (as it was when it was Softricity Softgrid), and may well be worth some investigation, we would need to contrast this with our existing investment in Citrix technologies.

Client of the Future: Capabilities, Considerations and Costs

This was a really good session and one that will be hard to illustrate without the slide desk. Once I have it, am happy to take people through it in more detail.

The session was run by one of the Strategists from the 'War on Costs' team internal to MS. It covered how previously the aim was to get standardised and locked down and make one size fits all. However now and into the future this is no longer true. We are shifting to being more user centric from device centric and should be looking at multiple ways to address their needs rather than the one size fits all approach.

This is good as it is what I have been pitching for a couple of years. One problem you have when trying to justify this is TCO, having a cost based model is not great for:
- emerging technologies which start off more expensive but give you competitive advantage
- solutions with a high upfront cost (typically we will have this problem for premium services in our software catalog - how do we make it fair to the sites that take the higher cost early on?)
- where value is only for a subset of users (e.g. VDI for our business partners)

TCO also does not measure, agility, efficiency, flexibility and productivity.

The presenter stated that a new model is needed which provide the 4 pillars of business value:
  1. Direct cost
  2. Agility
  3. Quality of Service
  4. Governance, risk, management and compliance

By building your cost models with these themes in mind you will get a more balanced view of what will work.

Next steps are to assess the various solutions against these and see what will be a good fit for your portfolio. Again there was a number of steps to go through before having a user centric environment.

I'll leave the recap here, but hopefully it was enough to give you a taste. Once I get the slides I can elaborate further, but the detail on them and the pace he was going was more than I could get good notes down for and I'd like to do it justice.

To give a bit more background, this was the abstract:


Application virtualization? Workspace virtualization? Desktop virtualization? Composite desktops? Desktops-as-a-service? In an ever-more-complex game of "buzzword bingo" it has become very difficult to compare vendor offerings and choose the client-computing technologies and capabilities that will help you succeed as a business. This session leverages the "War on Cost" team's most recent research into client computing, and provides a framework for comparing the capabilities and considerations of emerging client models.

We'll compare the costs, benefits, and optimal use-cases for application virtualization, desktop virtualization and more; we'll discuss the impacts of each model on desktop deployment and management, datacenter workloads, application delivery, user productivity and business agility; and we'll highlight the key factors and best practices that must be considered when aligning your desktop strategy with business priorities. This session will equip you to make well-informed choices as you work to implement an agile and effective next-generation client-computing environment that meets your business needs.

Best practices from MS IT - SCCM 2007

Both Colin and I were in this session and as it was more relevant for him I'll let him add the details.

Key things I noted - MS IT manage 275k clients with their SCCM infrastructure, so we don't need to worry about scale!
They have 13 people globally to manage all: servers and clients, patching, software updates, App-v, OS deployments and two of these are permanent packagers. The rest of the packaging they outsource.

13 people, 275k machines - pretty impressive!

Does this make me a proper geek?

Yesterday I queued up to get a free SCOM 2007 R2 book, and the authors signed it for me.
In my defence I only went because it was free, don't judge me!




Mobile Device Managment

So day 4 starts, its cold, rainy and windy. Fortunately I get to spend all my time in a conference center ;-)

However it does mean the attendee pool party has been moved to the underground car park - not quite going to be the same atmosphere methinks!

First session today was about Device Management and they mean specifically mobiles.

Fact roll:
  • Smartphones have increased significantly in importance to businesses
  • 2013 will see more smartphones in the enterprise than PC/Laptops
  • Trend is away from platform conformance (irritatingly for us)
  • Often consumer purchased but used for business (as an example all the pics here are with my personal smartphone)
  • Customers want 'a single pane of glass' view over their infrastructure from Servers to phones, not multiple consoles/infrastructures, and certainly not an infrastructure per vendor!

Microsoft have decided to invest more in this areas and thus have rolled their System Center Mobile Device Manager product into Configuration Manager v.Next. They have already announced that they will support Nokia/Symbian platforms at RTM and are stating that they are working with other vendors, no time lines committed yet.

This is interesting as when I was at MMS in 2008, they were saying then that they were in discussions with Apple and Rim, so either these discussions a)take a really really long time, b)are not going well or c)lost focus... Might be worth getting a more formal roadmap under NDA to understand what is really happening.

Apart from Symbian, MS will also support WinCE 5.0+ WM6.1+. These devices will be able to do over the air enrollment, inventory, settings management, software distribution and remote wipe. WinCE devices wont be able to remote wipe or do over the air.

Over the air enrollment ties into SCCM and your EA Certificate infrastructure (PKI - which we will have as part of Connex). Demo'd well and worked flawlessly.

Admins can register users, or they will be able to self register.

They are working to make the user experience the same on all platforms, so things like offloading compliance check/remediation assessment to the SCCM server will ensure the user is not impacted regardless of how powerful their device is or what OS it runs.

Demo's of settings management and software distribution were equally impressive, and tie into the new Software catalog with v.Next - i.e user can choose to register their phone in it, or what software they want installed.

Public beta will be available by end May 2010

Really interesting session and I'm very hopeful it can be a good solution. I would want to see some firm commitments on timelines and platforms. Again though as we have Software Assurance on SCCM, we will be entitled to the product in the future anyway. Definitely one worth investigating!.

Wednesday, April 21, 2010

Operating System deployment for ordinary admins

"Operating System deployment for ordinary admins" focussed on two free MS tools for Windows 7 deployment, namely MAP and ACT (MS Assessment & Planning and "Application Compatibility Toolkit).

Both toolkits should be in use (especially ACT Stan!) in Mars already, and I enjoyed the overview. If anybody wants an overview on them, let me know.

Software updates for smart admins

"Software updates for smart admins" consisted of two admins, one from a 50k user strong company, the other with barely 2k users. The point was to show best practices on software updating from different perspectives, with often diverse methods, but ultimately achieving the same end result of software compliance. The session was lively and obviously both admins had very different views on achieving their goal, and although they didn't quite argue about it on stage, they did agree to disagree. The only things they did agree on was that WSUS was old and SCCM was infinitely easier to manage. That and don't sync drivers, which seemed pretty obvious....who wants to download 70gb+ a month?

I will be getting the slide deck from this one though, as some of the methods described looked like they could save quite a bit of time for any admin - please let me know if you'd like a copy.

Monitoring Networks with Operations Manager 2007 R2

Next session was "Monitoring Networks with Operations Manager 2007 R2" I took a lot of notes on this one as I can see the benefits to an ops team, in that we often need to go to the Central Processing or Enterprise Networks teams and say dumb things like "My application is running bad", whereas "Server 51 is connected to Switch ABC on port 1, and we're seeing a lot of dropped packets between 9-11am" would be a bit more useful.

As you'll already doubtless know, R2 supports SNMP (V1 & v2) and can create either SNMP or SysLog workflows. What I didn't know is that it will also integrate with other monitoring solutions such as Solarwinds via a connector so that we can see the outputs of that alerting system right in the SCCM console. Pretty cool eh?

The larger part of the session was devoted (of course!) to v.Next, and how this offers more functionality. Please note this is all work in progress so subject to change before it goes gold.

The key points I noted are:

* Out of the box monitoring/discovery and reporting
* Server to network dependency discovery
* Multi Vendor/Multi Protocol support (SNMP v1/2/3 & IP v4/6 (note that discovery is IP4 ONLY!)
* Better scalability

Discovery can be manual or automatic (auto only needs one router IP address to discover the entire network!) and can be scheduled, via SMNP trigger or used on demand. This will support layer 2 & 3, VLAN memberships and HSRP (Cisco). Key monitor components by default are memory, CPU, Port, Interface card, PSU, temperature and voltage.

Monitoring defaults out of the box include port/interface up/down, traffic volume, CPU % utilisation, data drop and broadcast rates, memory counters (inc total and free RAM), PSU temperature and voltage and connection health end to end.

Final point was on inbuilt visualisation, which comes in either Dashboard or Diagram flavours - both looked common sense and useful, and of course were configurable ad infinitum.

SCCM 2007 - Configuration Manager v.Next migration

A lot of things here have been covered already, secondly this is based on the migration to the beta without full functionality yet.

Having said that, here's the deets:

Migration Console is in the Administartion tab of the v.Next console

Goal of migration: flatten hierachy, minimise WAN impact, Maximise reusability of x64 hw, assist migration of clients and objects

Plan - asses current environment, POC, Design.
Requires SCCM 2007 R2 SP2, 64bit hw, SQL server 2008 SP1 cumulative update 6.

Deploy -
  1. Setup initial v.Next primary/Cas
  2. Configure software update point and sync updates
  3. Setup server roles
  4. Make sure hierarchy is operating and software deployment works

Migrate - Map v.Next to existing 2007, migrate objects/clients/DP, Uninstall 2007 sites

All sounds so simple doesn't it ;-)

Enable migration in v.Next, specify hierachy - v.Next gathers info from 2007 for baseline, info is retained for reporting and displaying progress. I have some more details for those interested.

Concern for me is that it seems to be a side by side migration, not an in place - does this mean we will potentially need to buy new hardware to do an upgrade not long after we have finished our migration?

Config Manager v.Next Admin UI

First up today (after the keynote) was "Config Manager v.Next Admin UI" and as you can imagine, was focussed on the improvements of the user interface, compared with previous/current versions. This will only be interesting to existing users of SCCM, new users will just expect the "wunderbar" and ribbon approach, which is delivered. The UI changes are more than just cosmetic of course - of particular note are the very fast and easy sorting and filtering options, both of which are very configurable. Tagging makes grouping very easy and is available on virtually all objects - so for example, you could tie this in with the Role Based Management, and allow site admins to only view objects, policies and devices on their own turf - for example an EU deployment manager could be configured to only see the relevent tasks, devices and functions that he required. Even if we didn't use this kind of restriction, the technology would still be useful to just to simplify views, reports and workflows for any admin working in the environment.

Speaking of reports, they showed an overview of the new graphical functionality built into v.Next - this looked very Spectrum like, and was of course dynamic, allowing you to drill down through the environment, for example down to server certificates and application issues reported by the internal alerting engine.

Also of mention was the automatic deployment statistic reporting options, which by default right out of the box show performance and failure alerting.