Vito Konopelec Microsoft Slovakia Building The Optimized Desktop Infrastructure with Windows 7 and Windows Server 2008 R2.

Slides:



Advertisements
Similar presentations
2  Industry trends and challenges  Windows Server 2012: Modern workstyle, enabled  Access from virtually anywhere, any device  Full Windows experience.
Advertisements

2  Industry trends and challenges  Windows Server 2012: Modern workstyle, enabled  Access from virtually anywhere, any device  Full Windows experience.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Remote Desktop Services
1. 2 Branch Office Network Performance Caches content downloaded from file and Web servers Users in the branch can quickly open files stored in the cache.
The future of Desktops Transform Your Desktop with Virtualization.
Building on the Foundation of Windows Vista: Introduction to Windows 7: Security and Management Dan Stolts IT Pro Evangelist Microsoft
Network Isolation Using Group Policy and IPSec Paula Kiernan Senior Consultant Ward Solutions.
Understand Virtualized Clients Windows Operating System Fundamentals LESSON 2.4.
Benefits, Risks and Service Desk Impact. Robert Half Technology Kelly O’Connell Robert Half International Branch Manager 2/11/2010.
Unleashing the Power of Ubiquitous Connectivity with IPv6 Sandeep K. Singhal, Ph.D Director of Program Management Windows Networking.
Module 3 Windows Server 2008 Branch Office Scenario.
Connect with life Gopikrishna Kannan Program Manager | Microsoft Corporation
Dan Stolts IT Pro Evangelist US DPE - North East Microsoft Corporation
At their deskAt their desk In a branchIn a branch On the roadOn the road Protect data & PCsProtect data & PCs Built on Windows Vista foundation Easy.
Security and Policy Enforcement Mark Gibson Dave Northey
Jason Leznek, Group Product Manager, Windows Client Justin Graham, Senior Product Manager, Windows Server.
Agenda Understanding the optimized desktop Windows 7 To Date Office 2010 Windows 7 Resources, Resources, Resources.
Sudhir Rao Technology Specialist | Microsoft Corporation.
Ashwin Palekar Principal Group Program Manager Microsoft Corporation Session Code: WSV208 Scott Roberts Senior Program Manager Lead Network Security Microsoft.
Nicola Ferrini IT PRO Trainer
Windows Network Policy Server Fundamentals Ranjana Jain MCSE, MCT, RHCE, CISSP, CIW Security Analyst IT Pro Evangelist Microsoft India
Full Packaged Product (FPP) OEM – PC Preinstall Volume Licensing.
Module 8 Configuring Mobile Computers and Remote Access in Windows 7.
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 14 Remote Access.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
Clinic Security and Policy Enforcement in Windows Server 2008.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Title. 1.Breakdown the components of a personal computer 2.This is what we commonly refer to as a Windows OS 3.VDI moves the OS, Apps and Data to.
1 Week #7 Network Access Protection Overview of Network Access Protection How NAP Works Configuring NAP Monitoring and Troubleshooting NAP.
24 years in IT as a Technology Consultant MCT, MCITP, MCTS President of Pacific IT Professionals A professional association for IT Professionals Join.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
1. Windows Vista Enterprise And Mid-Market User Scenarios 2. Customer Profiling And Segmentation Tools 3. Windows Vista Business Value And Infrastructure.
Implementing Network Access Protection
XPand your capabilities with Citrix ® MetaFrame XP ™ for Windows ®, Feature Release 2.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
Module 8 Configuring Mobile Computing and Remote Access in Windows® 7.
Module 9: Configuring IPsec. Module Overview Overview of IPsec Configuring Connection Security Rules Configuring IPsec NAP Enforcement.
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
Live Migration Failover Clustering with Cluster Shared Volumes (CSV) Support for new Processor features Improved Performance Lower Power Costs Enhanced.
Alessandro Cardoso Microsoft MVP | Readify National Manager |
Q XenDesktop & Windows Server 2012 Value Add – RDS & VDI.
Welcome Windows Server 2008 安全功能 -NAP. Network Access Protection in Windows Server 2008.
V-Alliance Solution Overview Years of Business Success.
Configuring Network Access Protection
Terminal Services Technical Overview Olav Tvedt TVEDT.info Microsoft Speaker Community
ISA Server 2004 Introduction Владимир Александров MCT, MCSE, MCSD, MCDBA Корус, Управител
Enabling Secure Always-On Connectivity [Name] Microsoft Corporation.
Yaniv Feldman Senior Infrasec Architect Microsoft Security Regional Director
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
David Kim Product Manager CLI306 Industry Trends Windows Vista Enterprise Flexible Desktop Computing Options Windows Vista Enterprise Centralized Desktop.
© 2008 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED,
User and Device Management
Simple to deploy, easy to manage Consistently rich experience, regardless of deployment model 1 Platform 1 Experience Pooled virtual machines Highest.
Jurgen Van Duvel Business Manager Windows Client Microsoft
Asif Jinnah Field Desktop Services Enabling a Flexible Workforce, an insider’s view.
Managing Network Access Protection. Introduction to NAP Issues  Although corporate networks are highly secured, no control over the configuration of.
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
Click to edit Master title style TechNet goes virtual ©2009 Microsoft Corporation. All Rights Reserved. TechNet goes virtual NAP and NPS in Windows Server.
Click to edit Master title style TechNet goes virtual ©2009 Microsoft Corporation. All Rights Reserved. TechNet goes virtual Windows Server 2008 R2 Remote.
Implementing Network Access Protection
Forefront Security ISA
Microsoft TechNet Seminar 2006
Microsoft Desktop Optimization Pack for Software Assurance
Access and Information Protection Product Overview October 2013
{ Security Technologies}
System Center Marketing
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Microsoft Virtual Academy
Presentation transcript:

Vito Konopelec Microsoft Slovakia Building The Optimized Desktop Infrastructure with Windows 7 and Windows Server 2008 R2

Branch offices Remote work Mobile and distributed workforce Central office

IT professional needs: Secure and flexible infrastructure for working anywhere Reduce costs Mobile and remote workforce needs: Work anywhere Fast access

Optimized Desktop Compliance Costs Contingency Carbon-Neutral(“Green”) Consumerization

Increase user productivity by enabling access to applications and data quickly, from anywhere Enable faster, more scalable, and efficient access to network resources Implement policy-based network access and security Update and manage mobile PCs even when not on the corporate the network Publish server-based applications directly to users’ desktops Centrally aggregate important client and server events Enhance User Productivity Protect Sensitive Data Reduce Costs with Enhanced Manageability Fundamentals Security | Reliability | Application Compatibility | Device Compatibility | Performance | Power Management Enable faster, more scalable, and efficient access to network resources Implement policy-based network security Centrally aggregate important client and server events

Combined value to deliver the optimized desktop Key Scenario BenefitsFeatures Enhance User Productivity Provide faster, more scalable, and efficient access to network resources Provide users with seamless access to applications and data from anywhere, helping to increase their productivity Provide users with a rich desktop experience from unmanaged or thin clients Receive Window auto-tuning SMB 2.0 IPv6 DirectAccess BranchCache™ VDI enhancements Protect Sensitive Data Enable policy-based network security by allowing only healthy PCs to access network resources Network access protection Server and domain isolation Reduce Costs with Enhanced Manageability Update and manage mobile PCs even when not on the corporate the network Publish server-based applications directly to users’ desktops Centrally aggregate important client and server events to help desk DirectAccess Remote Desktop Services (RDS) Event forwarding

Enhancing User Productivity

IPv6 All services within Windows Vista are IPv6-enabled Seamless cost-optimized transitional approach Receive-side auto-tuning Automatically senses the network environment and adjusts important performance settings Allows increase in the size of the TCP/IP send/receive window SMB 2.0 protocol improvements Number of open files and shares on the server Packet compounding reduces “chattiness” Message signing settings have been improved Client-side encryption is supported Durable handles are supported

Situation Today DirectAccess Office Home Challenging for IT to manage, update, and patch mobile PCs while disconnected from the company network Difficult for users to access corporate resources from outside the office Corporate network boundary includes managed assets no matter where they are on the Internet Easy to service mobile PCs and distribute updates and polices New network paradigm increases mobile user productivity by providing the same experience inside and outside the office HomeOffice

ClientServer Runs on Windows 7 Domain-joined Initial configuration done on the corporate network or over VPN Runs on Windows Server 2008 R2 Sits on the network edge Single box by default Services can be split up for scalability

IT Pro Benefits Improved manageability of remote users IT simplification and cost reduction Consistent security for all access scenarios End-User Benefits Seamless and secure access to corporate resources Consistent connectivity experience inside and outside the office Enhances the end-to-end IW experience when combined with other Windows 7 features

IPv6 Devices IPv4 Devices DirectAccess Server Windows 7 Client Native IPv6 with IPSec IPv6 Transition Services Supports variety of remote network protocols DirectAccess provides transparent, secured access to intranet resources without a VPN Allows desktop management of DirectAccess clients Allows IPSec encryption and authentication Supports direct connectivity to IPv6- based intranet resources Support IPv4 via 6to4 transition services or NAT-PT IT desktop management AD Group Policy, NAP, software updates Internet

Situation Today BranchCache™ Application and data access over WAN is slow in branch offices Slow connections hurt user productivity Improving network performance is expensive and difficult to implement Caches content downloaded from file and Web servers Users in the branch can quickly open files stored in the cache Frees up network bandwidth for other uses

IT Pro Benefits Helps reduce WAN utilization and cost Data encryption is enforced across the network Simple to deploy End User Benefits Less waiting for downloads = more productivity Combined with other Windows 7 features enhances the end to end IW experience

1. First client downloads data from main office server Main Office Client 1 Client 2 2. Second client downloads identifiers from main office server 3. Second client searches local network for data and downloads from first client Branch Office Distributed mode

1. First client downloads data from main office server Client 1 Client 2 Branch Office 2. Content pushed to hosted cache from first client 3. Second client downloads identifiers from main office server 4. Second client downloads from hosted cache Main Office Hosted caching

Aero Glass for Remote Desktop Server Uses have the same new Windows 7 look and feel when using Remote Desktop Server Aero Glass for Remote Desktop Server Uses have the same new Windows 7 look and feel when using Remote Desktop Server RemoteApp and Remote Desktop connections RemoteApp and Remote Desktop icons integrate into the Start menu Icons refresh and update automatically RemoteApp and Remote Desktop connections RemoteApp and Remote Desktop icons integrate into the Start menu Icons refresh and update automatically Multimedia support and audio input Experience rich multimedia redirection Use VoIP applications and speech recognition Multimedia support and audio input Experience rich multimedia redirection Use VoIP applications and speech recognition True multiple monitor support Use up to 10 monitors of any size or layout with RemoteApp and Remote Desktop Applications behave like users expect – e.g. PowerPoint installing them locally True multiple monitor support Use up to 10 monitors of any size or layout with RemoteApp and Remote Desktop Applications behave like users expect – e.g. PowerPoint installing them locally RemoteApp language bar support Configure applications that use different language settings than the local language (such as right-to-left languages) RemoteApp language bar support Configure applications that use different language settings than the local language (such as right-to-left languages)

Protect Sensitive Data

Today’s Challenges Unprotected network taps within an organization’s buildings Administrators have limited control over the health of systems joining the network Result: hardware/network upgrades and increased operational costs, reduced productivity Solution: end-to-end, authenticated, tamper-resistant communication Improved isolation using IPsec Network access protection across IPsec, 802.1X, DHCP, VPN Increased manageability

1 1 Remediation Servers Example: Patch Restricted Network 1 Windows Client DHCP, VPN, or switch/router relays health status to Microsoft Network Policy Server (RADIUS) Network Policy Server (NPS) validates against IT-defined health policy 4 4 If not policy compliant, client is put in a restricted VLAN and given access to fix up resources to download patches, configurations, and signatures (Repeat 1-4) Not policy compliant 5 If policy compliant, client is granted full access to corporate network Policy compliant NPS DHCP, VPN switch/router 4 Policy Servers Example: Patch, AV Corporate Network 5 Client requests access to network and presents current health state

Untrusted Unmanaged/rogue computer Domain Isolation Active Directory Domain Controller X Server Isolation Servers with Sensitive Data HR Workstation Managed Computer X Trusted Resource Server Corporate Network Define the logical isolation boundaries Distribute policies and credentials Managed computers can communicate Block inbound connections from untrusted Enable tiered-access to sensitive resources

Reduce the risk of network security threats An additional layer of defense-in-depth Reduced attack surface area Increased manageability and more healthy clients Safeguard sensitive data and intellectual property Authenticated, end-to-end network communications Scalable, tiered access to trusted networked resources Protect the confidentiality and integrity of data Extend the value of existing investments No additional hardware or software required Get more value from Active Directory and group policy Complements existing third-party network security solutions

Enhanced Manageability

DirectAccess Enables “always-on” management of remote machines to support a fully manageable environment Scenarios include: Group policy updates Folder redirection/client-side caching Software/update distribution Event Subscriptions Proactive management of key issues Pull/forward events to and from multiple machines and search/collate Does not require loading entire log from remote machine

Improved management toolset Reduce repetitive tasks with RDS Powershell support, improved application installation, connection broker installation and profile management Improved management toolset Reduce repetitive tasks with RDS Powershell support, improved application installation, connection broker installation and profile management RDS and VDI – an integrated solution Single broker to connect users to sessions or virtual machines, out-of-the-box solution for VDI scenarios with Hyper-V RDS and VDI – an integrated solution Single broker to connect users to sessions or virtual machines, out-of-the-box solution for VDI scenarios with Hyper-V RemoteApp and Remote Desktop connections Centrally hosted applications integrated into the Start menu and desktop, can personalize a non-work PC with work applications without installing them locally RemoteApp and Remote Desktop connections Centrally hosted applications integrated into the Start menu and desktop, can personalize a non-work PC with work applications without installing them locally Platform investments Multiple levels of extensibility for custom partner solutions for RDS- and VDI-based solutions Platform investments Multiple levels of extensibility for custom partner solutions for RDS- and VDI-based solutions

© 2009 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.