<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Andrew Page, Technology Architect, Microsoft Technology Center </title><link>http://blogs.technet.com/apage/default.aspx</link><description>Infrastucture Systems and their impact on business</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Quick Tip:  Using HP ProCurve Manager</title><link>http://blogs.technet.com/apage/archive/2009/07/02/quick-tip-using-hp-procurve-manager.aspx</link><pubDate>Thu, 02 Jul 2009 17:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260797</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3260797.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3260797</wfw:commentRss><description>&lt;P&gt;So, normally i reserve posting quick tips on technical details here.&amp;nbsp; But, i spent hours troubleshooting an issue and wanted to post it SOMEWHERE so the search engines pick this up.&amp;nbsp; And it's less than well documented.&amp;nbsp; I'm hoping by posting here someone doesn't spend the time I did trying to fix this.&lt;/P&gt;
&lt;P&gt;If you use HP ProCurve Manager to manage your ProCurve switches, you know its a pretty powerful product.&lt;/P&gt;
&lt;P&gt;There's a security feature that you need to modify if you want to have another workstation view the information from your ProCurve Manager server.&amp;nbsp; By default, no other workstations can connect to your PCM server, such as an Operator or extra monitor in your NOC.&amp;nbsp; If you install PCM on a workstation, and try to connect to the PCM server, you will receive a message:&amp;nbsp; "&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: #1f497d; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;:&amp;nbsp; the server would not authenticate this client, you may need to upate the list of authenticated clients on the management server&lt;?xml:namespace prefix = u1 /&gt;&lt;u1:p&gt;&lt;/u1:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;A search online and in the help yields nothing.&amp;nbsp; So, here's what to do...&lt;/P&gt;
&lt;P&gt;On the server, locate the file ACCESS.TXT.&amp;nbsp; Edit this file.&amp;nbsp; It will probably be empty.&lt;/P&gt;
&lt;P&gt;add a line of the address of the workstation that wants to connect, or even easier, add the subnet of workstations that you trust to connect (like 10.*.*.*)&lt;/P&gt;
&lt;P&gt;restart PCM client on the workstation, and you should now be able to connect...&amp;nbsp; hope that helps. &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260797" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/HP/default.aspx">HP</category><category domain="http://blogs.technet.com/apage/archive/tags/ProCurve+Manager/default.aspx">ProCurve Manager</category><category domain="http://blogs.technet.com/apage/archive/tags/PCM/default.aspx">PCM</category></item><item><title>VDI and streaming the OS</title><link>http://blogs.technet.com/apage/archive/2009/07/02/vdi-and-streaming-the-os.aspx</link><pubDate>Thu, 02 Jul 2009 17:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260794</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3260794.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3260794</wfw:commentRss><description>&lt;P&gt;I'm continuing to get lots of interest in application virtualization and in particular VDI - hosting the entire desktop and a user simply "remotes" to their desktop in the cloud / datacenter.&amp;nbsp; Spent some time with Citrix, who is a close partner of Microsoft and the MTCs.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;We deployed an interesting solution that makes me want to revisit the whole "stream the OS to the desktop" scenario.&amp;nbsp; With Citrix added on to Windows Server 2008, you can boot from an ISO image.&amp;nbsp; We use that here to avoid some conflicts with an existing demo, where we boot the ISO and start up a VHD, and then connect the user to the VHD for their VDI experience.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But this got me thinking... if i can boot to an ISO, i'm in effect streaming the OS down to the workstation.&amp;nbsp; if i create my own special ISO image, and can send it down as the workstation boots, we can basically operate a diskless workstation.&lt;/P&gt;
&lt;P&gt;So, now that the environment is up &amp;amp; running here, i need to spend some time with this to see how this could enable some solutions in highly unmanaged environments (retail scenarios, fast food chain restaurants, etc.).&amp;nbsp; Stay tuned. &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260794" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.technet.com/apage/archive/tags/Hyper-V/default.aspx">Hyper-V</category><category domain="http://blogs.technet.com/apage/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/apage/archive/tags/virtualziation/default.aspx">virtualziation</category><category domain="http://blogs.technet.com/apage/archive/tags/VDI/default.aspx">VDI</category></item><item><title>Behind the Scenes at new Microsoft Technology Center - Chicago</title><link>http://blogs.technet.com/apage/archive/2009/04/14/behind-the-scenes-at-new-microsoft-technology-center-chicago.aspx</link><pubDate>Tue, 14 Apr 2009 21:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226400</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3226400.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3226400</wfw:commentRss><description>&lt;P&gt;Here's a total ad-hoc video posted on edge about our new MTC in Chicago.&lt;/P&gt;
&lt;P&gt;(also known as "how i spent my christmas vacation")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="http://edge.technet.com/Media/Inside-the-new-Chicago-Microsoft-Technology-Center-MTC/"&gt;http://edge.technet.com/Media/Inside-the-new-Chicago-Microsoft-Technology-Center-MTC/&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3226400" width="1" height="1"&gt;</description></item><item><title>Speaking today at Technical Experts Conference</title><link>http://blogs.technet.com/apage/archive/2009/03/23/speaking-today-at-technical-experts-conference.aspx</link><pubDate>Mon, 23 Mar 2009 15:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3216907</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3216907.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3216907</wfw:commentRss><description>&lt;P&gt;I'll be speaking today at the Technical Experts Conference (TEC), which is Quest's technical conference where they have topics about Exchange and Active Directory.&amp;nbsp; I'll be presenting on the work we've done at the Microsoft Technology Center Chicago about making our new datacenter virtualized, and the value of using VLAN Tagging at the VM /switch level.&lt;/P&gt;
&lt;P&gt;I'll try to get my deck posted somewhere.&amp;nbsp; If you're at the conference stop by and say hello... &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3216907" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/VLAN/default.aspx">VLAN</category><category domain="http://blogs.technet.com/apage/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Little known but oh so enabling...</title><link>http://blogs.technet.com/apage/archive/2008/12/01/little-known-but-oh-so-enabling.aspx</link><pubDate>Tue, 02 Dec 2008 00:16:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3162623</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3162623.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3162623</wfw:commentRss><description>&lt;P&gt;Windows Server 2008 added two new features that enable some very cool remote-use scenarios, that really enable some new ways for using and publishing applications:&amp;nbsp; RemoteApp(tm) and Terminal Server Gateway.&lt;/P&gt;
&lt;P&gt;RemoteApp allows you to publish out an application, as if it was installed locally on the users workstation but actually runs in the memory space of the server.&amp;nbsp; This is ideal for users that need access to an application every once in a while, or need it remotely, but doesnt require you to install anything on the users desktop.&amp;nbsp; And if the program uses a file extension, like .MPP for Microsoft Project files the client can actually recognize this and start the remote program on the clients behalf.&lt;/P&gt;
&lt;P&gt;Now this is great if you are on the corporate network or VPN'd in.&amp;nbsp; What if you want this access for a person who only has https:// access?&amp;nbsp;&amp;nbsp; Dovetail RemoteApp with Terminal Server Gateway, and you can enable this across untrusted networks.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;We ran this for a very large customer who wanted to proof-of-concept our Microsoft Dynamics applications, and it worked like a champ.&amp;nbsp; Now, we had to create a cert through Microsoft trust chain, which was the worst part about the process, but once setup it was hands off.&amp;nbsp; and *very* enabling!&lt;/P&gt;
&lt;P&gt;I can really see this changing way applications are deployed and managed... &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3162623" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/apage/archive/tags/Terminal+Server+Gateway/default.aspx">Terminal Server Gateway</category><category domain="http://blogs.technet.com/apage/archive/tags/remote+applications/default.aspx">remote applications</category><category domain="http://blogs.technet.com/apage/archive/tags/TSG/default.aspx">TSG</category><category domain="http://blogs.technet.com/apage/archive/tags/RemoteApp/default.aspx">RemoteApp</category></item><item><title>Using VLAN tagging with Hyper-V - reduces management!</title><link>http://blogs.technet.com/apage/archive/2008/12/01/using-vlan-tagging-with-hyper-v-reduces-management.aspx</link><pubDate>Tue, 02 Dec 2008 00:13:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3162620</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/3162620.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=3162620</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I’ve been spending majority of my free time rebuilding our core infrastructure services in our data center at the Microsoft Technology Center in Chicago.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We’re moving offices in December 2008, so perfect time to do this.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;I’ve been wanting to look into VLAN identification feature of Hyper-V, and see how this can really benefit us and our customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;After some reading and experimentation got it figured out and wanted to share my experience...&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;In the old days, I’d have a physical NIC for each VLAN and configure the switch port the NIC went into to be “hardcoded”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;(untagged in HP ProCurve lingo) to a VLAN. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;On the Server, I have it configured according to the common preferred practices:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;one NIC on Management network used only for management, the others are are cabled to a port on our ProCurve switch . &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Important note:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;the physical NICs themselves are not VLAN tagged (i.e. properties of the NIC card), but the port on the switch that the NIC goes into is marked as TAGGED.&lt;/FONT&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Now, I build out lots of VMs.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In Hyper-V / SCVMM, I can indicate which VLAN I want the VM to be on.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This now makes it a BREEZE for me to say which VLAN I want a server to participate on, I can switch it from network to network without having to go into the ProCurve tool, and can even script it for installs (for example, start on management network for the building and patching… and then VLAN it over to the customer network when all done).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;And now, can even do more from a single management console – SCVMM. &lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3162620" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.technet.com/apage/archive/tags/VLAN/default.aspx">VLAN</category><category domain="http://blogs.technet.com/apage/archive/tags/Hyper-V/default.aspx">Hyper-V</category><category domain="http://blogs.technet.com/apage/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Application Distribution via Streaming</title><link>http://blogs.technet.com/apage/archive/2008/02/12/application-distribution-via-streaming.aspx</link><pubDate>Wed, 13 Feb 2008 01:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2880047</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/2880047.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=2880047</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Wall Street Journal had an article today about application virtualization at the desktop.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I never thought I’d see the day when this topic would end up in the ‘Journal.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Wow.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The thing that makes me cringe is thinking about the conversations we've had with customers on thsi topic at the Microsoft Technology Center Chicago.&amp;nbsp; We're&amp;nbsp;having flashbacks to infrastructure discussions held back in 2003, and in this case hoping history doesn’t repeat itself.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Think back to the early 2000s:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;server consolidation was the buzzword, and every IT department soon had this initiative in their portfolio of projects to complete to “reduce costs”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;All my customers wanted to throw hoards of physical servers onto one big server to increase their optimization, usually through virtualization.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What we quickly learned from customers was there were several approaches to server consolidation, not just virtualization, and taking a step back and choosing the most appropriate approach to consolidation became the most important factor in predicting success.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;For example, its very possible and achievable to consolidate File and Print services, or Exchange email services or SQL databases, onto fewer number of like boxes without having to virtualize.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;We saw some glorious failures out during that euphoric consolidation wave, and we can take the same learning’s and apply them to the newest buzzword:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;application virtualization (we’ve also heard it referred to as “OS streaming” and “on demand installs”).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When we saw the first wave of server consolidation hit, IT shops wanted to stack tons of servers onto few number of physical boxes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What we learned was:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.75in; TEXT-INDENT: -0.25in; mso-add-space: auto; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=Calibri size=3&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;There are many approaches to consolidation, and some thought needs to go into which is the most appropriate&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.75in; TEXT-INDENT: -0.25in; mso-add-space: auto; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=Calibri size=3&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;Good IT practices (change management, monitoring, etc.) trump any technology solution&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Introduction to Application Virtualization and “Streaming”&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;If you aren’t familiar with application virtualization, it’s taking an applications running instance (installation, execution, etc.) and encapsulating it, so it can run in its own isolated environment on a workstation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Microsoft’s solution in this area is called Microsoft Application Virtualization (MAV), previously known as SoftGrid.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This solution is part of Microsoft’s Virtualization portfolio which includes server virtualization, presentation virtualization, and desktop virtualization. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Application streaming to desktop is somewhat new and has lots of attention (see Gartner’s Hype Cycle for PC Technologies, June 25,2007).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Microsoft purchased SoftGrid about a year ago to have a solution this space, and it’s a pretty compelling solution as are others out there with a lot of viable implementations. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;As we move to application streaming, we start shifting the “work” to other components.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It inherently increases the reliance on other core components, most importantly the network and general connectivity.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For example, another virtualization technology solution in the space takes an entire application and compiles it into one .EXE by taking a snapshot before and after an application installation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Therefore, it’s highly isolated from other apps that run.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, this requires the network to be always available, must be capable of a large increased load of transferring the entire .EXE across the network in one big bite.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;MAV, on the other hand, transfers only what is needed and not the entire application, but still has a (reduced) reliance on the network. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Suitability for all situations&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;This has some real potential for organizations where there are large number applications, often due to factors like acquisition or consolidation in an industry (such as healthcare).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Another is where multiple distributed IT departments have come under one umbrella as a part of IT consolidation, removing departmental or divisional IT groups and collapsing into one. So, now where each division may have had its own order system or HR system for example, now may need to run several side by side. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;With every app isolated, this becomes a very compelling option due to the large number of application install combinations per workstation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The result of all these apps that need to run side by side would be a large and impractical testing matrix.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Value form app virtualization would come from the reduction of time needed to test out the different iterations of application compatibility. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Where we have the most concern are the IT departments which are engulfed in the hype to the point where this is &lt;U&gt;the&lt;/U&gt; solution (similar to server consolidation), without considering other factors such as their ability to support this environment.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impacts of streaming &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Streaming removes some big headaches.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, it has some caveats:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The IT groups must have a highly reliable set of operational practices, and robust experiences in network and application performance monitoring.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Your dependant components (parent or host OS, router, application, workstation, etc.) has to expose out performance information.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also, your management tools must be there to capture and smartly digest that performance information into actionable tasks.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is probably the single, biggest overlooked area in all of virtualization (such as server virtualization, where there’s a strong need to monitor the host &lt;U&gt;in addition to the child VMs themselves).&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Bottom line:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;1) If you aren’t using good IT operational practices today, such as MOF or ITIL, you better start and get good before taking on immature technologies such as OS streaming.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Good IT practices trump the best technology solutions.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;2) If you aren’t that mature in IT operational processes (see IT Infrastructure optimization), you might be better consider more mature solutions like traditional application packaging and distribution.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is a very proven and established solution with a lot less risk.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;3) If your organization is not traditionally an early adopter to leading edge solutions, your audience&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;probably won’t have the appetite for such a bleeding edge technology.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;We’d encourage copious amounts of testing and validation for performance, network latency, etc.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2880047" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Deployment/default.aspx">Deployment</category><category domain="http://blogs.technet.com/apage/archive/tags/Management/default.aspx">Management</category></item><item><title>The Enterprise Enabled Desktop</title><link>http://blogs.technet.com/apage/archive/2008/02/11/the-enterprise-enabled-desktop.aspx</link><pubDate>Mon, 11 Feb 2008 21:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2870769</guid><dc:creator>apage</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/apage/comments/2870769.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=2870769</wfw:commentRss><description>&lt;P&gt;At the Microsoft Technology Center Chicago, one infrastructure topic that never seems to be absent from our customer agendas, no matter their level of IT maturity, is the concept of a “locked down” desktop. &lt;/P&gt;
&lt;P&gt;The locked down desktop, like its brothers &lt;EM&gt;server consolidation&lt;/EM&gt; and &lt;EM&gt;single sign-on&lt;/EM&gt;, is an umbrella term that often means different things to different people. The drive here by IT, I find, comes down to a desire for better desktop management, and more often grows into philosophy of what exactly are IT departments trying to accomplish by locking-down. &lt;/P&gt;
&lt;P&gt;First off, I tend to avoid using the term locked down. It gives off a negative connotation, and I have yet to find a user that wants to sign up to be “locked down”. I prefer, and encourage our clients to use, the friendlier term “Enterprise Enabled Desktop”. &lt;EM&gt;(side note: our legal team and desktop marketing had no interest in protecting this term, so please feel free to use generously in your own IT marketing.)&lt;/EM&gt; &lt;/P&gt;
&lt;P&gt;After a brief discovery and understanding of what a client is hoping to accomplish in an Enterprise Enabled Desktop (or EED), the answers most commonly break down to: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;desire for reduced configurations, therefore reducing known variables for updates&lt;/LI&gt;
&lt;LI&gt;removing access to configuration areas on the workstation that IT doesn’t want users changing, reducing the overall costs of managing the desktop (i.e. reduced help desk calls or support hours)&lt;/LI&gt;
&lt;LI&gt;more control over the configuration of the end user desktop&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;It’s no secret Microsoft has a wealth of tools to help IT departments gain and keep control over environments. Many are shared here later, but before diving into a solution I find it most helpful to prime the EED conversation with an illustration of my “Spectrum of Workstation Management”. I usually draw a line on the whiteboard and explain that on the left side is what I consider the wild, wild west, and the right side is your fixed function corporate device. &lt;/P&gt;
&lt;P&gt;Here’s an analogy I often share: Imagine a driver for a package delivery company. This driver is given a truck every morning in which he or she makes deliveries. Can they take that truck home on the weekend to help move his friend’s apartment? No, that increases liability for the company, and increases the wear and tear among other things. Can they take that truck in for a paintjob or to install a new radio? Or course not, it’s not his truck. That truck is a corporate asset, given to him for the purpose of conducting his job duties. This same perspective can be used for a corporate workstation. I put this at the far right of my spectrum. &lt;/P&gt;
&lt;P&gt;On the far left, as I mentioned, is the wild, wild west. Anything goes here. Users can install, change, and tweak anything they want to. They can update the drivers, install a screensaver the pulled down from any website, copy their personal movie collection to the device. Basically, treat it they would their home machine.&lt;/P&gt;
&lt;P&gt;There is tons of evidence that a machine closer to the left side of the spectrum costs more to own and maintain (Gartner says: $5,500/yr). But, traditionally as a workstation moves further to the right, the amount of freedom the user has on that device decreases. This can be good or bad, depending on the tasks the user needs or wants to perform. &lt;/P&gt;
&lt;P&gt;The point I make with our customers is this: classify your users by find the most appropriate place for your classes of users and/or workstations, and where they should be on the spectrum. It is probably not appropriate for all users in an organization to be in the same spot on the spectrum. For example, non-techie groups that perform a fixed set of tasks such as HR or customer services reps might be pretty far right on the spectrum. Developers or executives might be more in the middle or closer to the left, giving them more freedom over their machines yet still having some basic policies applied to their machine to ensure some level of corporate compliance or adherence to corporate IT policies. &lt;/P&gt;
&lt;P&gt;&lt;EM&gt;(another side note: This is often where the “thin clients” which act as a terminal and connect to a terminal service in, but too much to cover here) &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Once the classes of users are identified, then we begin a very basic discussion on options available for helping enforce the level of placement. There are many tools that help support the locations of workstation on that spectrum. At the very basic is Active Directory and Group Policy, which manage the most basic of settings and configurations for user identity, machine identity, and basic configuration. Once a machine is joined to the directory, we can introduce server and domain isolation to know that authorized clients can connect, and establish &lt;U&gt;the&lt;/U&gt; corporate identity. You can also consider Network Access Protection in Windows Server 2008 here. &lt;/P&gt;
&lt;P&gt;More advanced management tools as we move just a bit further to the right is Microsoft Software Update Services for critical patches. Vista has added many features and modification of existing XP components specifically for making it more granular and enabling for users to have more control without the need to be an administrator on the workstation, such as adding a printer. User Access Control, while being considered a nuisance by many, when managed through policy helps to get more classes of users closer to the right and more fixed-function that ever before. &lt;/P&gt;
&lt;P&gt;As we get closer to the rightmost side of the spectrum, System Center Configuration Manager (SCCM, previously known as Systems Management Server, or SMS) comes into play, which enables a complete solution for workstation management – from bare metal provisioning to full management and even drift from a desired state. We could also get into more advanced areas such as client monitoring with SCOM to really understand performance and trending of a workstation for future diagnostics, troubleshooting, and response levels. &lt;/P&gt;
&lt;P&gt;Keep in mind - even though developers and users with laptops might be father to the left, they can still have some basic, core policies applied (Active Directory group policies for things like firewall, proxy, and NAP) in order to maintain some degree of manageability and confidence of the security around that workstation without impairing the ability for them to do their job function successfully. &lt;/P&gt;
&lt;P&gt;Information on all the technologies discussed here can be found on Microsoft.com. Search on these terms:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;domain and server isolation&lt;/LI&gt;
&lt;LI&gt;group policy&lt;/LI&gt;
&lt;LI&gt;Vista improvements for manageability&lt;/LI&gt;
&lt;LI&gt;SCCM and workstation management &lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2870769" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Management/default.aspx">Management</category></item><item><title>Healthcare Applications and Identity</title><link>http://blogs.technet.com/apage/archive/2008/01/16/healthcare-applications-and-identity.aspx</link><pubDate>Wed, 16 Jan 2008 23:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2752075</guid><dc:creator>apage</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/apage/comments/2752075.aspx</comments><wfw:commentRss>http://blogs.technet.com/apage/commentrss.aspx?PostID=2752075</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;Healthcare applications are notorious for using proprietary identity systems for user authentication and authorization.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It’s a problem in many industries but seems to be most rampant the healthcare industry and continually challenges most every healthcare customer that comes into the Microsoft Technology Center (MTC) in Chicago.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;It is surprising, but not expected.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As healthcare application developers seek to get their product to market quickly, and the fact that the application is typically sold to the “almost” end user customers at healthcare providers, little consideration is given to see if the application has the ability to honor any kind of enterprise directory IT may have, or even leverage a common identity provider like LDAP or Kerberos.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;I have yet to speak to a client in the healthcare field that comes to the MTC to consolidate down their identity management where this doesn’t come up.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And it always comes up as a hindrance as they try to reduce infrastructure complexity and get to reduced sign on, let alone single sign on. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;This prevents optimization of healthcare IT environments.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Our healthcare clients are unable to increase their IT maturity without driving down the complexity around identity.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;The biggest reason application providers don’t do this correctly, I’ve found, comes down to education. Let’s look at a much better way for the app developer to have this necessary functionality and be a better IT participant.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;The most beneficial way for application authors to compose their application is to embrace a mechanism that can allow for a &lt;U&gt;local authentication source&lt;/U&gt;, yet be able to &lt;U&gt;honor an upstream enterprise directory&lt;/U&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;While this sounds complex, it is actually easier to follow some preferred practices that can actually reduce the effort and time for an application developer to offload this component of plumbing for any and all applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;Microsoft offers several methods for an application developer – Active Directory Lightweight Directory Service, or AD LDS (previously known as Active Directory Application Mode, or ADAM) is ideal for a standalone application that requires a store for managing users and identity.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is ideal for standalone applications – can store applications settings in addition to the basic LDAP signon.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But what if this application needs to authenticate to an enterprise directory based on Active Directory?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;No problem – the AD LDS can honor an upstream Active Directory (AD) implementation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What’s even better is the local application settings can reside in AD LDS while the authentication still happens at the AD level. No extra replication.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Keep in mind that AD LDS and AD use the same interface calls and parameters, so its relatively easy for app developers to leverage AD skills for AD LDS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;Customers of these applications, in an attempt to streamline and optimize are starting to use this criteria in selection of healthcare applications.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We are advising all customers that come through the MTC to challenge their application vendors to honor their enterprise directory source.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'"&gt;Lots of information on how to use AD LDS on microsoft.com, here’s a link to the FAQ: &lt;A href="http://www.microsoft.com/windowsserver2003/adam/ADAMfaq.mspx"&gt;http://www.microsoft.com/windowsserver2003/adam/ADAMfaq.mspx&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2752075" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/apage/archive/tags/Identity/default.aspx">Identity</category></item></channel></rss>