EUT on Tour

The team will be attending the Microsoft Management Summit 2010



We also have updates from Lotusphere 09, Microsoft Management Summit 08, TechEd Europe 08 and the Lotus Leadership Alliance 08


Showing posts with label SCCM. Show all posts
Showing posts with label SCCM. Show all posts

Friday, April 23, 2010

Diagnostics and Recovery Toolset

The Diagnostics and Recovery Toolset (DART), is another great tool in the MDOP suite.

The MDOP suite typically saves $70-80 net per pc per year (WIPRO reseach). DART can be $10 dollars of that.

DART is basically a bootable CD/DVD (USB and WIM work but are not supported) that runs on WinRE (Windows Recovery Environment) and is used to troubleshoot/repair a client machine before just rebuilding.
It Can:
  1. Recover an unbootable PC
  2. Detect and remove malware (whilst the PC is booted in WinRE)
  3. Delete, recover, save off files
  4. Reset local Admin password
  5. Manipulate services
  6. etc

Benefits:

- Accelerates TCO savings by minimising recovery time and preventing data loss.

- Recover instead of rebuild - saves user time and allows root cause analysis

Rebuilding a unbootable PC guarantees data loss, this tool gives you the option to do data recovery at worst case and full system recovery at best. This way the user does not lose data or their time waiting on a rebuild and then their time setting things up just right.

Case study of a company called Ultrasonic Precision Inc they saw Help desk costs decrease 27% and end user downtime decrease between 50-60%.

Demo's were very effective is providing the crash analysis of a blue screen, and restoring data that had been accidentally deleted.

Tools included in DART:

  • ERD Regedit - similar to normal one
  • Locksmith - local admin PW reset
  • Crash analysis - assesses BSOD and gives reasons/help
  • File restore - will scan for all deleted files and give you a likelihood of recovery
  • Disk commander - repair MBR, recover volumes/partition table
  • Disk wipe - secure DoD level wipe to prevent data recovery
  • Computer management - similar to normal
  • Explorer - Gui based, not command prompt as normal WinRE, USB active to save files off or copy them back to restore service
  • Solution Wizard - Wizard to help you choose the right tool to fix the problem (I would think if you need the wizard, you maybe are not the right person to be doing the work - ironically the presenter just said that too)
  • TCP/IP config - if you want to get onto LAN or ensure you can get to internet for System sweeper toget updates.
  • Hotfix uninstall
  • System sweeper - malware/rootkit detection tool,
  • SFC Scan - system file check can be used in Windows (assuming it boots), great to see it here at WinRE level (I have used SFC successfully a few times - correctly restore corrupt system files).

You can add DART tools to a hidden system partition of your builds to ensure they are a F8 option for troubleshooting (probably should not include locksmith).

Whilst it is a MDOP feature, once you are licensed for MDOP on your desktops, you can use it on servers too.

You can create a DART cd/dvd from within a virtual machine - very cool.

Find out more here

Desktop Error Reporting

I was also in this session and agree with what Colin has written, Microsoft Desktop Optimisation Pack, is a great tool. DEM is a great feature of it and the presenter demonstrated these well.

Something we should definitely look further into to understand the cost impact of getting MDOP into our environment and using these tools.

Find out more about it here (Pdf will open)

Desktop Error Monitoring

This was an excellent session which covered a component of the MDOP suite called Desktop Error Monitoring (DEM). I was extremely impressed with this product demonstration and can see immediate use for it in both our current and future environments. The tool would assist primarily the tier 3 teams (EUT), in strategic problem solving, but would also be useful to tier 2 teams in terms of published problem management, and statistical information. I understand that the tool itself is free, however because we don't have desktop OS enterprise licensing, there will be some commercial issues which would need to be ironed out prior to us deploying - I certainly intend to pursue this investigation, and if necessary raise a business case to implement MDOP as the benefits are clear and immediate.

In order to describe the product, the speakers first talked about why the product exists - this was mainly user need driven:

• Provide an immediate ROI
• Deliver end to end solutions
• Better TCO on desktops/laptops
• Requirement for low cost monitoring for knowledge and productivity issues
• Requirement for better visibility of desktop issues (users automatically reboot, often overwriting error data in the process)

DEM offers the following to help with the above:

• Crash monitoring
• Application and System crash/hang data captured and stored centrally
• Direct access to troubleshooting & solutions
• Agentless deployment (via group policy)
• Lower helpdesk volume calls
• Engagement with support partners
• Internal 'Watson' back-end
• Patch and update tracking
• Easy analysis of captured data reports

The requirements for a DEM deployment are pretty standard:

• A management server
• A reporting server
• An SQL server
• Active Directory
• Global Policies in use in the environment

It's worth noting that DEM is a separate product to SCCM, although SCCM does effectively do the same job albeit on a much bigger scale. DEM is focussed directly on the desktop/laptop environment.

DEM also offered such features as customisable web pages displayed on the desktop when a crash occurs - which means that if we have a solution or workaround already, the user is notified straightaway. This has an obvious effect of reducing helpdesk calls. DEM can also suppress the "Send details to Microsoft" dialog, which users as often as not will click "No" on - once deployed, DEM automatically sends the error data to the central server, and then can display the kind of web page as described above.

Along with application issues, DEM also records system errors such as the dreaded BSOD. One of the issues EUT has faced recently is the issue of collecting BSOD error data - our environment is such that this is not easy on all devices and the user was usually forced to reboot prior to the full error log completing - this could be negated with the DEM system. It is often essential for our vendors that we provide complete error logging so that they can quickly resolve these types of issues, so anything that can help with this will be invaluable to us.

In addition to error data, DEM also captures the CAB file associated with application issues and bundles this in with the reporting - this would help Satyam with issues in packaging and us with patching and update problems. When use in conjunction with crash analysis tools, this is a very powerful way of identifying issues in applications.

In terms of UI, DEM looks very much like SCCM. It has facilities groups similar issues together, but in granular detail (ie by revision/version of individual DLLs) so things like video driver errors etc are clearly visible, even on a cursory glance at the logs.


As I said in the beginning of this article, I intend to follow this up with a serious intent to raising a business case to implement this technology in our environment as soon as possible. It can be used very soon - as soon as the new AD is in production to be exact, and I think the support teams will see the practical benefits immediately. Management should also see benefits from this too - apart from the obvious potential to improve our problem management, quicker and more proactive issue resolution and the potential for ticket reduction; they will also enjoy both the high level reporting available, with the options to produce highly granular reporting if required as well.

Thursday, April 22, 2010

Best practices from Microsoft IT on Config Manager 2007

This was a nice wrap up to the day - the internal MS IT department team lead gave a presentation on how they handle the normal everyday jobs that all users of their products need to do.

The thing that surprised me was that they do not seem to be early adopters of their own technology...obviously they are heavily involved in the Alpha, Beta and QA for their new products (a process they delightfully call "Dogfooding", but in their own environment, they have only recently implemented some of the things I just assumed they would use from day one of it going gold. To give you a couple of highlighted examples, they only began to deploy O/S images six months ago using MDT, and only use one App-V based application throughout the entire organisation.

The other surprise was the size of their team - although the speaker did admit they outsourced for some tasks, their core team is only 13 people. This team services 274,000 clients based at six HQ and client sites globally.

Their SLAs are quite impressive too - for software compliancy (patching etc) they adhere to a 95% compliancy within 3 business days for active exploit patching. For critical updating the SLA is 95% within nine business days.

A large portion of the presentation was around performance monitoring - with such a large organisation which such a high data throughput, they needed to develop their own type of custom reporting, which they achieved with the LogMan tool, and a bundle of custom scripting.

One last point which was quite interesting - they stated that their DC operational costs had reduced by 75% using a virtualisation strategy - they have defined an 8-1 virtual to physical server ratio. They claim that most of the 75% savings are down to power and physical server cost savings, along with standardising the builds for easy and fast provisioning.

Forefront Endpoint Protection 2010

As is becoming very routine now in these sessions, the speakers started off by extolling the virtues of the 'single pane of glass' approach to SCCM and it's components, and Forefront is no exception. Again with this product, we would be able to manage a major portion of our infrastructure seamlessly from a single user interface.

Forefront, for those not familiar, is Microsoft's answer to antivirus, malware, spyware and firewall for enterprise customers. I had my reservations, previous consumer products have been eh....not great, only offering basic protection at best. Forefront however, has been designed from the ground up to be industry class, and my first impressions are that it may well become best of breed.

Of course, being an SCCM component, deployment of policy, updates and signature files are simple and managed in the same way as any other deployment.

In terms of provisioning Forefront to an environment, Microsoft have pushed the boat out somewhat to make it an admins dream. All that is required is for the installation to be completed on a root site, and it's automatically provisioned across the hierarchy, automatically creating additionally required components such as distribution packages. Another good feature is that when deployed to clients, Forefront will (again!) automatically remove/uninstall and other protection software you have installed, although I'm guessing our heavily scripted installations may cause it some issues.

Some of the other benefits mentioned were:

• Protects clients without complexity
• Admin control of protection level
• Protects apps, file systems and network layers
• Template driven policy creation
• SCCM distribution
• Option to control via legacy group policy if required
• Ability to limit the clients apps CPU utilisation of the PC, so as not to slow down the users during mandatory scans
• By leveraging SCCM and WOL (Wake up on LAN), updating and scans can be scheduled out of hours
• Centralised monitoring, alerting and reporting on protection levels, signature and update compliance across the environment via SCCM

Zero Touch Installation using MDT 2010 & SCCM 2007

This lab session went though the steps to configure SCCM/MDT2010 up to the deployment phase for deploying a Windows 7 workstation image. The steps included:

• Configuration of the deployment environment
• Configuration of offline installation of language packs and updates
• Configuration of a new computer PXE environment installation of Windows 7
• A refresh install of Windows 7

The lab was fairly routine, but it was good to go through the steps as I suspect my team will be involved in this heavily in the future.

Troubleshooting Windows 7 Deployments

This lecture was a little dry albeit very informative. The synopsis is: Windows 7 deployments can have problems, check the multitude of log files for help and RTFM before hand.

For those that would like some more tech detail:

Setupact.log - setup actions during process
setuperr.log - only the error messages - both these need to be read together, and depending at what poitn the failure was, they may be in different locations!
KB927521 has more
cbs.log - DISM commands - drivers, languages, security updates
setupapi.dev.log - %windir%\inf - driver install
netsetup.log - %windir%\Debug - Domain join errors
Windowsupdate.log - %windir% - Windows update, WSUS or SCCM (SUP) errors
wpeinit.log - startup issues in WinPE - gets deleted after reboot
wdsserver.log - WDS - logging is off by default - KB936625
usmtestimate.log - estimation of space errors
usmtcapture.log or scanstate.log - capturing the data
usmtrestore.log - restore errors
smsts.log - task sequence failures (another log that moves)
drivercatalog.log - inport drivers
tasksequenceprovider.log - save or import task sequences
smspxe.log - pxe issues
smsprov.log - save or import task sequences too.

In SCCM you can enable a checkbox for enable command support, if you then hold F8 during winPE you can get a command prompt to go find these logs. If you have got as far as windows setup Shift+F10. Having the command prompt window open, holds any reboot too.

Common issues:
  • Bad computer name - more than 15 characters
  • Mismatched product key to image file
  • Broken domain join - KB944353
  • Deploying with a KMS key! (KMS keys are for machines that provide keys to rest of org)
  • Crashes - check for stop errors, you may need to turn off auto reboot.
  • WinPE - generally networking related
  • SCCM - task sequences, hash mismatch (refresh DP - it is a bug MS cannot reproduce so far)
  • Make sure you test all task sequences at least one before deploying
  • Make sure packages are present (if not push them out)

Finally he mentioned a tool called SMStrace, which has the option to enter error codes, this can be very helpful.

Best practices from MS IT - SCCM 2007

Both Colin and I were in this session and as it was more relevant for him I'll let him add the details.

Key things I noted - MS IT manage 275k clients with their SCCM infrastructure, so we don't need to worry about scale!
They have 13 people globally to manage all: servers and clients, patching, software updates, App-v, OS deployments and two of these are permanent packagers. The rest of the packaging they outsource.

13 people, 275k machines - pretty impressive!

Wednesday, April 21, 2010

Software updates for smart admins

"Software updates for smart admins" consisted of two admins, one from a 50k user strong company, the other with barely 2k users. The point was to show best practices on software updating from different perspectives, with often diverse methods, but ultimately achieving the same end result of software compliance. The session was lively and obviously both admins had very different views on achieving their goal, and although they didn't quite argue about it on stage, they did agree to disagree. The only things they did agree on was that WSUS was old and SCCM was infinitely easier to manage. That and don't sync drivers, which seemed pretty obvious....who wants to download 70gb+ a month?

I will be getting the slide deck from this one though, as some of the methods described looked like they could save quite a bit of time for any admin - please let me know if you'd like a copy.

Config Manager v.Next Admin UI

First up today (after the keynote) was "Config Manager v.Next Admin UI" and as you can imagine, was focussed on the improvements of the user interface, compared with previous/current versions. This will only be interesting to existing users of SCCM, new users will just expect the "wunderbar" and ribbon approach, which is delivered. The UI changes are more than just cosmetic of course - of particular note are the very fast and easy sorting and filtering options, both of which are very configurable. Tagging makes grouping very easy and is available on virtually all objects - so for example, you could tie this in with the Role Based Management, and allow site admins to only view objects, policies and devices on their own turf - for example an EU deployment manager could be configured to only see the relevent tasks, devices and functions that he required. Even if we didn't use this kind of restriction, the technology would still be useful to just to simplify views, reports and workflows for any admin working in the environment.

Speaking of reports, they showed an overview of the new graphical functionality built into v.Next - this looked very Spectrum like, and was of course dynamic, allowing you to drill down through the environment, for example down to server certificates and application issues reported by the internal alerting engine.

Also of mention was the automatic deployment statistic reporting options, which by default right out of the box show performance and failure alerting.

2nd Keynote

Today Brad Anderson got to be the main man, as is tradition, first some stats:
  1. Windows 7 is the fastest selling OS in history

  2. In March 90 million Win7 machines were patched via Windows Update.

  3. Windows Update patches 725million PCs each month - bear in mind most corporates wont point to Windows Update.

SCCM 2007 R3 - will include more power management features. You can enable it in a data gathering mode first and understand how your estate is used, and understand the savings you could make. Typically Windows 7 has saved between $30-60 per machine by tweaking the power options from Windows XP. You will also be able to configure wake up for out of band patch/app distribution.

With the reports you can show CO2 savings as you implement the policies, therefore we could quantify the savings back to the sites. This helps as site power is obviously a different budget so whilst Mars IS wont see the benefit we can show the site what benefit they are getting because of our service.

SCCM 2007 R3 beta is available from today.

Brad says there are 5 things you need to build the core of your desktop strategy.

1) You must have one infrastructure to manage all your types of desktop - physical, vdi, app-v, etc. It must have comprehensive management tools for all the things you manage. Guess what? The system center suite does this ;-) In all seriousness it is a good point, for so long we have tried to go for best of breed and often suffered, there is a lot to be said for the one throat to choke approach.

2)Common way of integrating and managing all versions of virtualisation - vdi, VMs, App-v, Med-v Hyper-v, vmware, Citrix etc. Speaking of Citrix, XenApp can now be managed by the System Center suite (available in 60 days). Configuration Manager will allow for increased automation/management of XenApp and its server infrastructure - so delivery of apps to the server, through to publishing them to end users. Using Citrix Dazzle home users can gets apps delivered via Citrix and SCCM.

Some Hyper-V tweaks - Remote effects (fx?) and Dynamic memory, the first allows you to use a high end graphics card in your hyper-v server and provide full windows aero effects to end users with VDI - the GPU takes the workload so performance is not affected. Other VM providers cannot do this - this would mean the user experience is seamless from physical desktop to virtual - sounds insignificant but is very impressive - they demo'd it running 720p HD video in a virtual machine with all Aero feature on. Dynamic memory essentially allows you to define a range of RAM for your VM machines - this way as the user runs an intense app, they can dynamically grow their RAM usage, and when they close it, it will reduce. This allows for much more efficient RAM usage and again a significantly improved user experience. These tools will be available in SP1 for W2k8 R2 (I cant wait for my home server ;-) ).

3) Convergence of security and management - lower cost, simplified management and enhanced protection. Forefront product will now run off System Center infrastructure (no additional servers required). It will be built into Configuration Manager so you will get anti virus/malware/spyware. This also ties into the one infrastructure theme. RTM by end of year. As we consistently seem to have problems with our Symantec tools, maybe this would be worth a look! In fact the install package it includes in SCCM will auto uninstall other vendors security problems to avoid headaches (almost like a virus itself!) This combination will tie into the SQL reporting services and provide very rich reports to see overall status, any detections and so on. Tied into the Dashboard (see previous blog) a great addition to the office plasma!

4) Cloud based client management or as they define it, 'route to the cloud'. I have blogged about Windows Intune, so see this post for more.My view is that 2-5 years this product set will have developed enough to rival the on premise solutions, so by the time we come to look at the desktop management infrastructure again, this may be a viable solution.

Then Brad went off on a bit of a detour from the Cloud to the System Center Service Manager tool. This tool had 2 main design principles, simplicity and tight integration with AD and System Center. As blogged previously this tool will do compliance, incident/change and problem management. They gave an example of a customer having a meaningful CMDB within 2 hours of install, it is that simple.

In terms of compliance, it will do PCI, SOX, records management and one other I didn't catch. Service Manager can automate the discovery to assess compliance, demo'd in 3-4 clicks. If you already have VISA compliance and now you want to check for AMEX it will assess the delta that AMEX may require that VISA does not, but not duplicate the work already covered. It can even auto remediate to gain compliance. The integrated reporting can allow you to check compliance, or even generate the report direct for the auditor. Non compliance can auto generate a ticket for items it is unable to remediate. Microsoft will update the tool as regulations are updated.

Beta 2 available in June RTM later in the year.

5) User focused - enabling productivity anywhere on any device (sounds familiar!) - reiteration of much of what I have already written about SCCM, Configuration Manager v.Next. Talked about auto remediation of DCM/Settings management which is pretty cool, even to the extent of reinstalling apps a user may mistakenly remove.

There was a roadmap slide


Image credit: Hans Vredevoort - click the pic for his site.

Next years MMS will be at Mandalay Bay March 21st-25th 2011


Tuesday, April 20, 2010

Configuration Manager v.Next - Hierarchy Design

This presentation build on the previous Configuration Manager v.Next talks and is around designing your architecture. For those non techies, skip to the next post now!

You should have a Central Administration Site, 1 Primary and Secondary's as required.

Central Admin Site - Location for all admin and reporting. No client data processing, no clients assigned and limited site roles.

Primary Site - services clients in well connected network. No tiered primaries, only add more for scale out; not needed for data segmentation, client agent settings or network bandwidth control.

Secondary - services clients in remote locations where network control is needed. Bundle Proxy MP and DP fr install. Tiered content routing via Secondary SQL replication.

Advanced features (multicast/streaming) are not available on file share only DPs (or W2k3 ones).

You can throttle and/or schedule to remote DPs

Branch DPs - can be run on a workstation, 100 or fewer clients, BITS gives you enough network control.
Utilise branche cache if you have W2k8 R2 (Mars traditional will) - they have seen a 71% drop in network utilisation at one customer.

Replication stays file based for content, but is SQL for global and site data.
SQL reporting services is the only reporting tool that can be used.

Topology views in Sites tab rather than event viewer - this will greatly aid troubleshooting replicating as the picture will show the alert and the link state.

Keynote - Detail

As Colin has said I took lots of Notes. I also took some pics of the empty stage, to give an idea of the size

These were from the 1/3 nearest the stage - I reckon about 6k attendees could be accommodated.


You could really see the impact the flight ban has had on attendance as it was maybe 3/5s full at most. Hopefully there will be more attendees tomorrow now flight restrictions have eased.


Anyhoo back to the details...


Brad Anderson started off as the warmup for his boss Bob Muglia, Brad took us through some stats -
3 out of 4 attendees use SCCM, 80% of which are already on R2
2 out of 3 use SCOM, again 80% at R2
50% of SCOM users, take advantage of its hetergenous features to manage Unix/Linux
50% of attendees use System Center Virtual Machine Manager (SCVMM)
25% use App-V
10% are beta'ing System Center Service Manager


7 years ago MS first announced the Dynamic Systems Initiative, the first step on the path to Dynamic IT now they are making it a reality, the vision will continue to evolve.


He talked about things like the Lab management tool in Visual Studio 2010 which allows you to deploy your own test lab using Hyper-V and SCVMM.

Brad talked about Opalis, a recent acquisition, which has a Orchestration feature, which automates moving (virtual) Dev environments into production, with the whole environment available at once - no more multiple changes/over time.(Opalis is something we may own but is outside of scope of Connex - something for EUT to investigate further I think).


Next up was a demo and a pretty impressive one. There is a feature within Hyper-V which allows you to do a long distance live migration. This would allow failover between say ISB and MTO, with no user impact as the servers would migrate in a live state even over the huge distance.


Obviously MS are keen to push new parts of the System Center suite, they talked about the human workflow of change and how it can slow the process, System Center Service Manager (SCSM) can now do a change automation based on ITIL. System Center Data Protection Manager (SCDPM) has better functionality for backing up (Hyper-V) based virtual machines, down to individual files on VMs, not just a snapshot. Multi site clustering with Hyper-V and System Center products....and so on.


Actually they are making some significant improvements, I could well see it being time for Mars to assess Hyper-V certainly for Dev/QA environments as it is much cheaper than VMware and seems to be catching up in functionality and adding features VMware does not have.


Further areas of improvement will be including more Compliance management in SCSM and SCDPM. All about proving how they have and continue to deliver on their vision of Dynamic IT.


So Microsoft asks, "What next?"


The Cloud.


All the attributes MS have defined as Dynamic IT apply to the cloud. The Cloud they defined as just in time provisioning and scaling of services on shared hardware.


Why Cloud? Accelerates the speed and lowers the cost of IT. Brief definitions of Public/Private clouds (hosted/in house) and Shared/Dedicated (Shared with other customers/Service dedicated to you).


Microsoft is working to provide dedicated clouds with Azure in the future (Shared only now).

They are looking to deliver one platform, one application model and one management solution across all of - customer premise, partner cloud, MS clouds.


There are a few key enablers -

Hardware Model - Windows server is now 75% of all servers globally. MS now buy servers in 2000 server containers, they just plug in power, network and water. This is 10x more efficient than the process of provisioning individual/racks of servers. They are working with hardware partners on the learnings and expect to see smaller containers offered to end users in the future.


Application Model - This is a set of services delivered as part of the cloud - this reduces dev time, has increased scalability, higher high availability and greater flexibility. Again a 10x improvement over current methodologies to be faster to market. We need to understand that servers will fail, however, applications should not, the service should continue. MS are developing a new model language currently code named 'M' this allows a developer to build apps based on a model rather than traditional methods.


Operating Model - They have learnt a lot from running Bing! as a service with a small number of admins. They have taken this knowledge and built it into Azure and System Center to improve their products. They can now have 1 admin managing 1000's of servers! They suggest that IT jobs in this sector will evolve to provide a higher service, faster delivery etc. The underlying operating model enables this. They have seen (you guessed it), a 10x reduction in the cost of operations.


New features coming -
SCVMM v.Next will have the ability to manage OS/Apps that run across multiple machines (1 OS, multiple VMs - this I have not explained well, I'll try to find more info over the rest of the week). Applications are referred to as 'fabric layers'.#


Service Designer feature - allows you to deploy new services based on your templates (Customer logs call for more Oracle capacity - admin clicks on deploy Oracle service and the capacity is provisioned) basically you can draw the picture of your service in Visio and then SCVMM will deploy it....SCVMM will also scale up/down as the load increases/decreases as per your requirements. Great for end users, a nightmare for licensing compliance!


Server App-V use multiple apps on the one OS independently, SCVMM manages the underlying application fabric.


Greater control of offline patching - remember the app service must stay up, gives greater control and automation.


SQL Azure - running SQL as a service across 6 datacenters and 1000's of servers, provision of a new DB is as simple as clicking on a web page.


Finally, integrated monitoring between on premise and cloud - a SCOM management pack shipping later this year for Azure. The demo showed a diagram of the environment with hw onsite and cloud based, a simulated problem in the cloud alerted via SCOM allowed the admin to run a task to provision more capacity in the cloud. Again very impressive, but how do you manage the cost of this up/down scaling and the capacity required on standby? I think contracts will be very interesting!


My takeaways - we probably need to look at all the features of the products we have bought as part of Connex, not just focus on the immediate need (I think a common mistake in Mars and industry wide). There is much more to many of the tools that could allow for greater automation and much slicker operations just with a bit more upfront effort.


Secondly, we need to think more holistically and not just in our GIST silo's, products EUT are using will be more than useful to other teams, we need to ensure we highlight these to our colleagues (as we have done with SCCM and SCOM to Processing). This is probably a great example of where an Enterprise Architect function would be particularly useful - I think Chris Lane is going to be busy ;-)


I'll leave it here as I have another 4 sessions to blog, but you can find more info below.


For those that would like to watch today's keynote, it is now available here


Finally, tomorrow's keynote will be streamed live here from 8.30am Pacific

v.Next overview

Day 2, session 4 was a very good presentation. This one focussed on the upcoming Config Manager v.Next, and the benefits it will offer. The main points I recorded were:

User Centric Client Management - allowing users to connect from anywhere, embracing mobile technologies and central control of assets. v.Next still focuses on system management as with previous versions, but will allow such enhancements as highly configurable deployment options for applications, O/S and patching, for example allowing deployment only for the primary user of a device, out of hours and user selectable download and installation of apps and patches, advanced application management (but with considerably less scripting) and the facility to setup system requirement and dependency checks prior to app deployment, including available memory, disk space and CPU type.

Other points include integration of RBS with templates, a better admin interface and distribution point grouping, cross platform mobile management, including a cute feature which would allow an administrator to package for example Acrobat reader for several device types, and only need to add the user once to the distribution list - v.Next would then deploy to all the users devices as appropriate without the need for separate processes. Also, remote control is integrated into the console for easy multi platform control of devices.

Please check my previous post for the O/S deployment options available with v.Next.

Configuration Manager: State of the union

Day 2, Session 2 was entitled "Configuration Manager: State of the union" and was easily the most entertaining session of the day. The hosts started off the presentation showing the various name ideas that the team went through before settling on v.Next, which was amusing if not entirely useful.
They did of course get serious in the presentation, and covered some very slick ideas including integrated Adobe updates in SCCM by the end of 2010, and other 3rd party updates via a third party add-on for SCCM called SCUPdate. The big demo for me was centred around Citrix XenApps deployment of applications via thin client, were the application itself remains on the server, and is seamlessly delivered to the client over either network or internet connection. This seemed to me to be an idea way to deploy and provision applications, and I'm surprised that we haven't seen this technology in Mars as yet.

The rough release timeline for Config Manager v.Next for those interested:

Beta 1 - May 2010
Beta 2 - Q1 2011
RTM - Q3 2011

Monday, April 19, 2010

Deploying Windows 7 with Config Manager 2007

The next session was "Deploying Windows 7 with Config Manager 2007", a subject which will become dear to the hearts of the ops team. The lab ran through creating a Win7 image, processing for DVD/Server based distribution, scripting (read wizarding, no programming required) the migration from a Windows XP SP3 workstation up to Windows 7 using a customised PXE build process, and verification of the build, complete with re-partitioning if required, all from within the config manager console. The process was quite lengthy, and took all of the available time that I had in the lab (80 minutes), but was ultimately successful, which is very encouraging for our future use. Most of the time was spent creating the Win7 image, which of course only needs to be done once and would be done long before production deployment. The actual migration/deployment portion was pretty quick even on a VM, but I'd love to try the process on metal to see what the performance is like. Methinks I'll be building a nice little environment in STU before long.....

SCCM

My first session today was entitled "Basic Software Distribution in Config Manager v.Next"
v.Next seems to be the latest incarnation of the SCCM software suite for 2010, perhaps Mat can clarify as it wasn't very clear to me, but no matter, it pretty much rocked whatever it's called.
I was really pleased to see that the "Basic" in the title didn't mean simple or beginner - for me basic in this context means that all of the everyday stuff I'd want to do with software distribution was easy to find and very easy to manipulate. The interface is different to what I remember, but they seem to have made simple tasks much easier to manage. The tasks in this lab centred around taking an application which had been previously packaged, and sending it to the distribution points. Once set there, a simple policy change pushed the package out to my virtual clients, and based on my selected settings installed the package automatically. The process was flawless, and monitoring both the distribution points, the clients and the install status was very clear. The lab built in a deliberate error so that you could demonstrate a remote package fix and re-install from the console - very slick. This technology will make both client package and client enforced security updates a doddle to manage centrally.

Configuration Manager Dashboards

This lecture was much more interesting, it involved a brief discussion about Dashboards for SCCM and how Microsoft IT use them, with some demos chucked in.

Dashboards have been developed for two key personas - firstly, the business user who needs to make decisions without too much information overloads, and secondly, the IT professional, who needs 'at a glance' management, customisation and create your own abilities, as well as having a dashboard that can fit on an office plasma screen.

The dashboard itself is a freely downloadable Microsoft Solution Accelerator, and is near real time (configurable amount of minutes between refreshes). You can create lots of individual tailored dashboards (GTS might want problems, Commercial would want license compliance, IMPACT deployment %ages and so on). By default it comes with six reports - Software Update management, OS deployment, Software Distribution, Client health and OS overview. Furthermore as we deploy Sharepoint, teams can add a relevant dashboard to their team site, you don't have to always go to a dashboard. For example, GTS may have a patch deployment screen on their website to relate to calls logged.

The demo was literally less than two minutes to set up a new dashboard, the only part we may struggle with, is that it uses SQL queries (however MS provide many examples free). MS IT manage almost 261k machines via their dashboards, so an obvious improvement they took was to add a filter, this way a dashboard could be broken by site, machine model, patch etc.

(As a side note, I noticed their stats showed they manage 224k physical machines and 37k virtual, that is more virtual PCs than all of 'traditional' Mars, secondly they are 50/50 split between 32 and 64bit computing - I think this is a good suggestion of our future!)

Finally they showed the dashboard configured to suit a plasma screen, I think this would be a great addition to the Mars IS hub site screens, very simple but very rewarding!

Registration Complete!

Today Colin and I arrived bright and early for registration at 8am, as did a couple of other thousand people. I have to say they did a good job of getting people queued and processed quickly. I'm sure an English person must have been involved to make the queue just right ;-)

For the morning, there are no lecture type sessions planned, so I did some self paced labs, I have spent some time in the next version of System Center Configuration Manager, currently branded v.Next. It has a completely new interface which reminds me of Outlook/MoM consoles in its layout but is no longer based on the MMC, which has been the MS admin console basis for a number of years.

A couple of interesting notes I made during the lab was that there seems to be a lot more around asset management and compliance - this seems to allow you to configure your own rules. Furthermore it has the ability to import software licenses(XML or CSV format) so I'll try to find out a bit more about that during the week. Currently we partner with a vendor called Concorde to help us with our compliance, it may be the next version of SCCM can provide more in house.

Second thing I found whilst browsing around the admin console is that they have formally introduced pre-staged media as a build option. This would allow us to provide HP/Dell with a pre-built image of a desktop/laptop/server which they can install and ship. Once on the network it would receive any changes in the meantime. This would be a pretty rapid way to deploy servers and clients and again I'll listen out for more details in the lectures.

Unfortunately due to the Icelandic Volcano many EU based attendees, vendors and speakers have not made it here, so sessions are being juggled. Today I'll be attending - Virtualisation scenarios for business critical apps, Win7 deployment with MDT and Configuration Manager Dashboard.
The Vendor Expo opens at 17.30 so I'll take a first look around and see if I can meet some of the new vendors we will be introducing to our environment with the Connex project. (Intrinsic and SCCM Expert).

Friday, April 9, 2010

Mat's Agenda Sessions



These will be the sessions I am attending at MMS:


  1. Deploying Windows 7 with MDT 2010

  2. Configuration Manager: State of the Union

  3. Cloud Computing in the Enterprise: Enabling the foundation with the Dynamic Infrastructure Toolkit for System Center

  4. Configuration Manager v.Next: Overview

  5. Configuration Manager v.Next: Hierarchy Design

  6. Birds of a Feather session (Similar to a Tif event in UK)

  7. Online services for PC management

  8. Configuration Manager x.Next Software Distribution Parts 1 and 2

  9. Protecting Windows Clients with Data Protection Manager 2010 (Potential SDS Backup replacement)

  10. Configuration Manager v.Next: Device Management

  11. Troubleshooting Windows 7 Deployments

  12. Leveraging System Center to manage your Citrix environment from desktop to data center

  13. Best Practice's From Microsoft IT's use of SCCM SP2/R3

  14. Centralising and managing User Data

  15. Desktop Error Monitoring

  16. Keeping Windows running efficiently with the Diagnostics and recovery toolset.

  17. Plus 2 Keynotes - User Centric Client Management and Managing Systems from the Data Center to the Cloud

If you are interested in the key themes, you can see more here: www.mms-2010.com/public/contentoverview.aspx

There is also the vendor exhibition hall and some labs, both instructor led and self paced.

So it should be a full on information overload ;-)