Thursday, April 22, 2010
Best practices from MS IT - SCCM 2007
Key things I noted - MS IT manage 275k clients with their SCCM infrastructure, so we don't need to worry about scale!
They have 13 people globally to manage all: servers and clients, patching, software updates, App-v, OS deployments and two of these are permanent packagers. The rest of the packaging they outsource.
13 people, 275k machines - pretty impressive!
Does this make me a proper geek?
Mobile Device Managment
However it does mean the attendee pool party has been moved to the underground car park - not quite going to be the same atmosphere methinks!
First session today was about Device Management and they mean specifically mobiles.
Fact roll:
- Smartphones have increased significantly in importance to businesses
- 2013 will see more smartphones in the enterprise than PC/Laptops
- Trend is away from platform conformance (irritatingly for us)
- Often consumer purchased but used for business (as an example all the pics here are with my personal smartphone)
- Customers want 'a single pane of glass' view over their infrastructure from Servers to phones, not multiple consoles/infrastructures, and certainly not an infrastructure per vendor!
Microsoft have decided to invest more in this areas and thus have rolled their System Center Mobile Device Manager product into Configuration Manager v.Next. They have already announced that they will support Nokia/Symbian platforms at RTM and are stating that they are working with other vendors, no time lines committed yet.
This is interesting as when I was at MMS in 2008, they were saying then that they were in discussions with Apple and Rim, so either these discussions a)take a really really long time, b)are not going well or c)lost focus... Might be worth getting a more formal roadmap under NDA to understand what is really happening.
Apart from Symbian, MS will also support WinCE 5.0+ WM6.1+. These devices will be able to do over the air enrollment, inventory, settings management, software distribution and remote wipe. WinCE devices wont be able to remote wipe or do over the air.
Over the air enrollment ties into SCCM and your EA Certificate infrastructure (PKI - which we will have as part of Connex). Demo'd well and worked flawlessly.
Admins can register users, or they will be able to self register.
They are working to make the user experience the same on all platforms, so things like offloading compliance check/remediation assessment to the SCCM server will ensure the user is not impacted regardless of how powerful their device is or what OS it runs.
Demo's of settings management and software distribution were equally impressive, and tie into the new Software catalog with v.Next - i.e user can choose to register their phone in it, or what software they want installed.
Public beta will be available by end May 2010
Really interesting session and I'm very hopeful it can be a good solution. I would want to see some firm commitments on timelines and platforms. Again though as we have Software Assurance on SCCM, we will be entitled to the product in the future anyway. Definitely one worth investigating!.
Wednesday, April 21, 2010
Operating System deployment for ordinary admins
Both toolkits should be in use (especially ACT Stan!) in Mars already, and I enjoyed the overview. If anybody wants an overview on them, let me know.
Software updates for smart admins
I will be getting the slide deck from this one though, as some of the methods described looked like they could save quite a bit of time for any admin - please let me know if you'd like a copy.
Monitoring Networks with Operations Manager 2007 R2
Next session was "Monitoring Networks with Operations Manager 2007 R2" I took a lot of notes on this one as I can see the benefits to an ops team, in that we often need to go to the Central Processing or Enterprise Networks teams and say dumb things like "My application is running bad", whereas "Server 51 is connected to Switch ABC on port 1, and we're seeing a lot of dropped packets between 9-11am" would be a bit more useful.
As you'll already doubtless know, R2 supports SNMP (V1 & v2) and can create either SNMP or SysLog workflows. What I didn't know is that it will also integrate with other monitoring solutions such as Solarwinds via a connector so that we can see the outputs of that alerting system right in the SCCM console. Pretty cool eh?
The larger part of the session was devoted (of course!) to v.Next, and how this offers more functionality. Please note this is all work in progress so subject to change before it goes gold.
The key points I noted are:
* Out of the box monitoring/discovery and reporting
* Server to network dependency discovery
* Multi Vendor/Multi Protocol support (SNMP v1/2/3 & IP v4/6 (note that discovery is IP4 ONLY!)
* Better scalability
Discovery can be manual or automatic (auto only needs one router IP address to discover the entire network!) and can be scheduled, via SMNP trigger or used on demand. This will support layer 2 & 3, VLAN memberships and HSRP (Cisco). Key monitor components by default are memory, CPU, Port, Interface card, PSU, temperature and voltage.
Monitoring defaults out of the box include port/interface up/down, traffic volume, CPU % utilisation, data drop and broadcast rates, memory counters (inc total and free RAM), PSU temperature and voltage and connection health end to end.
Final point was on inbuilt visualisation, which comes in either Dashboard or Diagram flavours - both looked common sense and useful, and of course were configurable ad infinitum.
SCCM 2007 - Configuration Manager v.Next migration
Having said that, here's the deets:
Migration Console is in the Administartion tab of the v.Next console
Goal of migration: flatten hierachy, minimise WAN impact, Maximise reusability of x64 hw, assist migration of clients and objects
Plan - asses current environment, POC, Design.
Requires SCCM 2007 R2 SP2, 64bit hw, SQL server 2008 SP1 cumulative update 6.
Deploy -
- Setup initial v.Next primary/Cas
- Configure software update point and sync updates
- Setup server roles
- Make sure hierarchy is operating and software deployment works
Migrate - Map v.Next to existing 2007, migrate objects/clients/DP, Uninstall 2007 sites
All sounds so simple doesn't it ;-)
Enable migration in v.Next, specify hierachy - v.Next gathers info from 2007 for baseline, info is retained for reporting and displaying progress. I have some more details for those interested.
Concern for me is that it seems to be a side by side migration, not an in place - does this mean we will potentially need to buy new hardware to do an upgrade not long after we have finished our migration?

