Wednesday, 20 June 2012

Windows Phone 8 Enterprise Features

Microsoft showed off some of the new platform features (mainly developer focused not consumer) that Windows Phone 8 will be bringing later this year (October - November time).

I'm not going to go over all the new features like dual core etc, there's plenty of info already out there for you to find.

However I did want to mention briefly a couple of the new Enterprise level features that in my opinion mean you might want to reconsider using a Windows Phone within your business when WP8 arrives.


The big announcement from my view was the use of the shared kernel bringing BitLocker(ish) Encryption and UEFI Secure Boot to the Windows Phone platform.

It's apparently not full blown BitLocker but is derived from it and uses secure keys.


Having a secure phone platform like that "out of the box" is certainly a huge plus in my opinion.
Another couple of great features are around the custom app store and the ability to bypass the app store and presumably push apps to the phone via either or both Intune and Configuration Manager.



Speaking of System Centre 2012 Configuration Manager, it might be a safe bet to say that we may see a native configmgr client agent become available for Windows Phone 8, unless Microsoft decide that Intune becomes the preferred management platform.
I'd also like to know if that picture of the "Company Hub" is just a mock-up or not. If not then it would be interesting to know what System Centre integration we might see with the alert center and ticket status parts of it.

Tuesday, 19 June 2012

Configuration Manager 2012 and VMware vCenter Protect Update Catalog

My colleague spent some time in the TrustLab today installing VMware vCenter Protect Update Catalog.  This was previously a solution from Shavlik and provides update management of third party applications such as Adobe Reader, QuickTime, Sun Java etc directly from within System Center 2007/2012 Configuration Manager alongside the normal Microsoft patch updates.



You can find Part 1 of his blog post on the installation here: http://ixrv.blogspot.co.uk/2012/06/configuring-scup-2011-shavlikvmware.html

More info on vCenter Protect Update Catalog (They need a better name!) can be found here:
http://www.vmware.com/products/datacenter-virtualization/vcenter-protect-update-catalog/overview.html

Friday, 15 June 2012

System Center 2012 Service Pack 1 CTP2 - What's New?

So Service Pack 1 CTP2 has just been released for download:
http://www.microsoft.com/en-us/download/details.aspx?id=30133

With the Technical Documentation here:

I don't know if it's an oversight or not, but there is currently no technical doc for ConfigMgr....

From scanning the documents quick, here's a high level new feature list:

App Controller
  • Upload a virtual hard disk or image to Windows Azure from a VMM library or network share
  • Add a virtual machine to a deployed service in Windows Azure
  • Start, stop, and connect to virtual machines in Windows Azure
  • Migrate a virtual machine from VMM to Windows Azure
  • Deploy a virtual machine in Windows Azure to create hosted service
  • Add a Service Provider Framework (SPF) hosting provider connection
Orchestrator
  • In System Center 2012 Service Pack 1 (SP1), Windows Server 2012 and SQL Server 2012 are both supported.
  • Additional support for Integration Packs, including 3rd party
  • Manage VMM self-service User Roles
  • Manage multiple VMM ‘stamps’ (scale units), aggregate results from multiple stamps
  • Integration with App Controller to consume Hosted clouds

Virtual Machine Manager
  • Network Virtualization
  • VHDX Support
  • SMB 3.0 File Shares
  • Live Migration Enhancements
  • Storage enhancements
  • Provision a Physical Computer as a Hyper-V Host - Enhancements
  • Support for VMM console add-ins

Service Manager
  • SQL Server 2012 Support
  • New Charge Back Feature

Operations Manager
  • New APM Monitoring Capabilities (WCF, MVC and .NET NT services)
  • New MP and support for Windows Server 2012 and IIS 8
  • Azure SDK support

Configuration Manager
  • Support for Windows 8
  • Support for Mac OS clients
  • Support for Linux and Unix servers

Data Protection Manager
  • Improved backup performance of Windows Server 2012 Hyper-V over CSV 2.0 deployments
  • Protect Hyper-V over remote SMB share
  • Protect Windows 8 deduplicated volumes
  • Support for Live Migration (Uninterupted Protection)
  • Use SQL Server 2012 to host DPM database
Server App-V
  • Support for applications that create scheduled tasks during packaging
  • Create virtual application packages from applications installed remotely on native server

Thursday, 14 June 2012

Microsoft Private Cloud Exams

I posted a while back about two new exams that Microsoft were introducing:

  • Exam 70-246: Private Cloud Monitoring and Operations with System Center 2012.
  • Exam 70-247: Private Cloud Configuration and Deployment with System Center 2012.

Well these exams have now gone live and with that it means those that took them in the Beta format at MMS 2012 are starting to get their results.

I hadn't recieved an e-mail so I thought I would check manually and this is the result:

So I've passed the 70-247 exam, which I thought was the harder of the two due to the ammount of SCVMM questions that were in it and I'm still learning that product.

I've still yet to hear the result of the 70-246, but my fingers are crossed!

**Updated 15/06/2012 00:08** I've just checked again and Prometric have updated my history page and it looks like I've managed to pass 70-246 as well meaning I've passed BOTH the exams!!

That's one step closer to getting certified as MCSE: Private Cloud.

Tuesday, 12 June 2012

MBAM 2.0 plus other MDOP updates

The Redmond machine really is in high gear at the moment as lots of other products and solutions start to recieve tweaks and new features, mainly in preperation for Windows 8 and Server 2012.

One set of tools getting some love is the Microsoft Desktop Optimisation Pack (MDOP).

Microsoft had already previously announced that MDOP was seeing a new component being added called UE-V which along with App-V makes MDOP a desirable solution to have in any environment looking to have a fantastic dynamic desktop, but today MS announced MBAM will also be getting some new features.

The Microsoft Bitlocker Administration and Monitoring (MBAM) will be updated to include new options such as:
  • Used Space Only Encryption where only the part of the drive containing data will be encrypted instead of the full disk to save time
  • Integration with hardware encrypted hard disks
  • Complex PIN enforcement
  • Self Service Key Recovery (I would prefer to see some SCSM integration here)
  • Management of fully FIPS compliant configurations/designs
  • Some SC 2012 Configuration Manager integration for reporting
Microsoft have also promised another update to UE-V very soon but so far during my tests I've seen no issues other than some poor documentation around its setup/configuration (hint... watch out for Offline Files or rather the lack of...)

App-V 5 is in Beta with new features such as shared cache which is amazing for VDI infrastructure.

Advanced Group Policy Management (AGPM) 4.0 SP1 beta is also available with mainly bug fixes and Windows 8/Server 2012 support rather than new features.

DaRT is also getting an update, again mainly to support Windows 8.

Monday, 11 June 2012

System Center 2012 Service Pack 1 CTP Update

I wish I was across at TechEd North America right now as there is some nice information starting to come out around some of the new features that Service Pack 1 for System Center 2012 will be bringing.

From the information I'm seeing on other blogs and the twitter feeds it looks like we'll be seeing an updated CTP (Community Technical Preview) of SP1 arriving within the week with some of the following new features and changes for Configuration Manager:

  • Windows 8/Server 2012 Deployment Support
  • Ability to deploy Windows 8 To Go
  • Linux Support
  • Unix Support
  • Mac OSX Support including EndPoint Protection Support
  • The ability to add a CAS to an existing Primary Site
  • New Deployment Types for Metro Apps and OSX Software
  • The ability to migrate from one 2012 site to another
  • Further e-mail notification support/options
  • Software Update changes, including the ability to fall back to Windows Update for content
  • Powershell cmdlets!!!
There has also been talk about some new User Profile and Data Management features such as Roaming User Profiles and Folder Redirection support, but I don't have enough information about what this means to explain any further but it could be interesting.

So I can't wait for SP1 now!  Linux/Mac OSX support is huge and a long awaited feature but the announcement of being able to add a CAS at a later date is also greatly welcomed as it makes my life so much more simplified when designing ConfigMgr implementations for customers.


There's also going to be an Update 1 for MDT 2012 soon which will bring the expected Windows 8 support, but it's also been announced it will have Orchestrator integration allowing running of runbooks during an OSD deployment.  How cool will that be!!

Wednesday, 30 May 2012

System Center 2012 Service Accounts & Permissions

Following on from my first post which set the scene for what I was trying to achieve with my new test environment (Dubbed the Customer Experience Center within Trustmarque!) I promised a post capturing some of the information you might find yourself needing when setting up an environment.

In this post I thought I would provide some information around the requirements for some of the accounts System Center 2012 requires when installing and some of the immediate accounts for the base configuration.

I think that all this information is already out there, but this post helps to pull it all into one central location and hopefully easier to digest.

All this information is of course assuming that you:
  1. Have already drawn up a design for your System Center 2012 Infrastructure with considerations to components, layout, performance sizing etc...
  2. You already have all your base VM's and SQL installs done.
  3. All Pre-reqs are installed.
  4. You know how to install the System Center 2012 Components. 
If you need more information on points 3 & 4 then a further post is coming listing lots of install guides and powershell scripts to install the pre-requisites.

Couple of tips first though:

Tip # 1 - Ensure the account used during install has rights to create databases on the SQL instance(s)/server(s) you specify during installation and can add security rights etc. Easiest option is to give the account SQL SysAdmin privileges and then look to revoke later.

Tip #2 - While using the Local System or Network Service option for the accounts is the easiest, I would personally only recommend this for lab/test environments.

Tip #3 - Again, using the same account over and over is easiest, but from a security and also risk mitigation perspective, separate accounts is what I recommend.  For example, using one account for all services possibly across multiple products would mean more than one system would fail if this account became locked out.

Tip #4 - If using (and it's recommended) domain accounts for the SQL services, don't forget to ensure the SPN's are registered for them.

Tip #5 - Staying on SPN's, ensure the data access service accounts get their SPN's registered

Tip #6 - Rule of least privileges.  It's always tempting just to drop the accounts into either the local admins group, sysadmin or heaven forbid the domain admins group.  Hopefully this information will help with only assigning the accounts the least amount of privileges they require which will always be best practise.

Below are a series of tables with example account names, their purpose and the permissions they require.
I've used the domain of TrustLab in this example so all accounts are in the format of <DomainName>\<AccountName>
Like I say, these are examples only, use your own naming conventions for service accounts.




Virtual Machine Manager Accounts
http://technet.microsoft.com/en-us/library/gg697600.aspx

Account ExamplesPurposePermissions
TrustLab\SCVMMSASCVMM Service Account Local Admin rights on VMM Server
TrustLab\SCVMMHVHostAdding Hyper-V hosts to VMMLocal Admin rights on target Hyper-V server.
TrustLab\SCVMMOMConSCVMM to SCOM connector accountSCOM Administrator Role
SCVMM Administrator Role
TrustLab\DomJoinDomain Joining Account used in templates for VM DeploymentDo not grant the account interactive logon rights.
Use Delegate Control in AD:
Computer Objects -
Reset Password
Validated write to DNS host name
Validated write to service principal name
Read/Write Account Restrictions

This object and all descendant objects -
Create/Delete Computer Objects


Configuration Manager Accounts
http://technet.microsoft.com/en-us/library/hh427337

Account ExamplesPurposePermissions
TrustLab\SCCMNASCCM Network Access AccountRequires "Access this computer from the network" right on the Distribution Points.
Minimum rights to access content on the Distribution Points.
TrustLab\DomJoinDomain Joining Account used within task sequences to join the OS to the domain.Do not grant the account interactive logon rights.
Use Delegate Control in AD:
Computer Objects -
Reset Password
Validated write to DNS host name
Validated write to service principal name
Read/Write Account Restrictions

This object and all descendant objects -
Create/Delete Computer Objects
TrustLab\SCCMCPSCCM Client Push AccountDo not grant the account interactive logon rights.
Must be local admin on the target devices you push clients to.
TrustLab\SCCMRASCCM Reporting Service Point AccountAccount is granted rights if chosen as a new account during Reporting Point creation from the console.

N.B. There are FAR too many accounts to realistically list for ConfigMgr, please refer to the link above for a full breakdown.  Listed are the most common ones needed for the base install.


Operations Manager Service Accounts
http://technet.microsoft.com/en-us/library/hh298609.aspx

Account ExamplesPurposePermissions
TrustLab\SCOMAASCOM Action AccountLocal Admin (NOT Domain Admin)
TrustLab\SCOMDASCOM Data Access AccountLocal Admin
TrustLab\SCOMDRSCOM Data Warehouse Read AccountSetup assigns Read to DW DB.
Best Practice to ensure account has SQL Logon rights before installation
TrustLab\SCOMDWSCOM Data Warehouse Write AccountSetup assigns Read to Operational DB, Write to DW DB.
Best Practice to ensure account has SQL Logon rights before installation

N.B. Always use the same Action Account & Data Access Account for each Management Server you deploy.
N.B. This list does not cover RunAs accounts for management packs such as the SQL or AD MP's.  Please refer to the applicable guide for the management pack for details/requirements.


Service Manager Service Accounts
http://technet.microsoft.com/en-US/library/hh495662.aspx

Account ExamplesPurposePermissions
TrustLab\SCSM Admins
(This is a group not an account)
Management group administratorsAccount used to run setup must be able to add users to this group as it will try to auto add the user to it.
TrustLab\SCSMSASCSM Service AccountLocal Admin on SCSM Server(s)
Must be same account for DW & MS Servers.
TrustLab\SCSMRASCSM Reporting AccountNothing specific, will be granted rights in SQL during install.
TrustLab\SCSMASSCSM Analysis Services AccountNothing specific, will be granted rights in SQL during install.
TrustLab\SCSMWFSCSM Workflow AccountNormal User permissions, but must have mailbox and send permissions for notifications.
Manually add account to Service Manager Administrators after install if not present.

N.B. I haven't listed the accounts here that are used for setting up SharePoint which will be needed when installing SharePoint dedicated for the Self Service Portal as I am not a SharePoint expert and would recommend seeking dedicated SharePoint best practise advice for that.



Service Manager Connector Accounts

Account ExamplesPurposePermissions
TrustLab\ SCSMADCONActive Directory Connector AccountAD Read
Advanced Operator in Service Manager
TrustLab\SCSMOMCICONSCOM CI Connector AccountOperations Manager - Operator Privileges
Service Manager -Advanced Operator
TrustLab\SCSMOMALCONSCOM Alert Connector AccountOperations Manager - Administrator
Service Manager -Advanced Operator
TrustLab\SCSMCMCONSCCM Connector AccountSCCM SQL DB -smsdbrole_extract & db_datareader roles
Service Manager -Advanced Operator
TrustLab\SCSMSCOCONSCORCH Connector AccountRead Properties, List Contents and Publish permissions to the root Runbook folder and all child objects. Grant via the Runbook Designer.
TrustLab\SCSMVMMCONSCVMM Connector AccountSCVMM Administrator
Local Admin on VMM Server
Service Manager -Advanced Operator

Orchestrator Service Accounts
http://technet.microsoft.com/en-us/library/hh912319.aspx

Account ExamplesPurposePermission
TrustLab\SCORCHSAOrchestrator Management ServiceRecommended to be a domain account. No special permissions required other those that the installer assigns during installation.
TrustLab\SCORCHSAOrchestrator Runbook ServiceRecommended to be a domain account so that if Runbooks require access to remote resources, rights can be granted to this account.
TrustLab\SCORCHSAOrchestrator Runbook Server Monitor serviceSame account used as Orchestrator Management Service and same rights required.

N.B. As is common with most deployments of Orchestrator, if you install the Management Server and Runbook Server components at the same time on the same server they will both use the same service account.
N.B. To deploy an IP to Runbook Designer, ensure the account running the Deployment Manager has local admin rights on the target otherwise you will get Access Denied.


Part 2 - Service Accounts & Permissions

Part 3 - Installation Guide Links
Part 4 - Partner Solutions & Extensions