Real-world OS Deployment Samples

Slides:



Advertisements
Similar presentations
What’s coming in Sccm 2007R2 aka Sccm 2007R2: 10 reasons to upgrade Kim Oppalfens SCUG.be.
Advertisements

Chris Nackers Senior Consultant Microsoft MVP - ConfigMgr.
Operating System Customization
Asking Questions Office Migration Planning Manager Windows Security Guides Group Policy Guides Image Servicing Operations Manager Desired Configuration.
Devices and Deployment Management & Security Identity Cloud.
Managing software and Windows deployments with ConfigMgr and 1E DANIEL RATLIFF TECHNOLOGY ARCHITECT
4/17/2017 7:07 AM © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Hands-On Microsoft Windows Server 2003 Chapter 2 Installing Windows Server 2003, Standard Edition.
CONFIGMGR 2012 R2 OSD TIPS AND TRICKS Presenter - Fred
Inside Windows Azure Virtual Machines Vijay Rajagopalan Microsoft Corporation.
A Tour of System Center Configuration Manager Adam Duffy Edina Public Schools.
Implementering af Windows 8 in real life Windows 8 OS Deployment Windows 8 OS Deployment features of ConfigMgr 2012 SP1 Take a look at what’s coming.
WIN-B331 Get a consistent, personal Windows experience that matches your unique work style Easy for IT to deliver personal, user-defined experiences.
1 Objectives Discuss the Windows Printer Model and how it is implemented in Windows Server 2008 Install the Print Services components of Windows Server.
GROUP POLICY An overview of Microsoft Windows Group Policy.
Managing Your Datacenter with Microsoft System Center Configuration Manager Kent Agerlund, ECM MVP, Coretech.
MANAGEMENT ANTIMALWARE PLATFORM Microsoft Malware Protection Center Dynamic Signature Svc Available only in Windows 8 Endpoint Protection Management.
Troubleshooting Windows Vista Security Chapter 4.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
Module 7: Fundamentals of Administering Windows Server 2008.
Windows XP to Windows 7 using P2V Migration. Agenda Deploying Local P2V Migration for SA Retro Mode Scripts Customize MDT 2010 with Disk2VHD Windows Virtual.
1 st Lost Data and Files Recovery Planning Distributed Workforce System Failures Traditional approaches to machine recovery don’t meet the needs.
Lost Data and Files Recovery Planning Distributed Workforce System Failures Traditional approaches to machine recovery don’t meet the needs of.
Richard Zuraff General Mills
Yes, Applications DO work in task sequences!
Systems Management Server 2.0: Backup and Recovery Overview SMS Recovery Web Site location: Updated.
Maintaining and Updating Windows Server Monitoring Windows Server It is important to monitor your Server system to make sure it is running smoothly.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Are you Ready for Configuration Manager vNext?
House of tails dogs charity All donations go 100% to the charity #MMSGIVEBACK.
The Art of deploying Windows 10 With ConfigMgr 2012 R2 Johan Mikael
Service Pack 2 System Center Configuration Manager 2007.
OS Deployment - LEVEL 500OS Deployment - LEVEL 500 Johan
Community Rules Session Subtitle Jörgen Nilsson Kent Agerlund
Customizing Windows 10 for the Enterprise
Deploying Windows 7 with Configuration Manager Tips from the field With Niall Brady, MVP ConfigMgr, Zipper.
Configuration Manager Deploying Surface Pro 3 with Configuration Manager Niall Brady ECM MVP
SmartCenter for Pointsec - MI
IT06 – HAVE YOUR OWN DYNAMICS NAV TEST ENVIRONMENT IN 90 MINUTES
Chapter Objectives In this chapter, you will learn:
Stress Free Deployments with Octopus Deploy
Exploring the wealth of Configmgr Community tools
Deployment Internals: Mastering Windows Deployment Services
OSD Front-Ends Henrik Rading Blog.coretech.dk/hra Senior Consultant
Modernize ConfigMgr OSD with Community Tools
Expert-level Windows 10 deployment
Troubleshooting Windows 10 Deployment: Top 10 Tips and Tricks
Windows 10 Imaging and Deployment
9/18/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
9/18/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Servicing Windows 10 in the Real World
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Windows 10 Deployment Expert Level Johan Arwidmark
Microsoft Virtual Academy
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
11/29/2018 1:22 AM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Microsoft Virtual Academy
12/10/2018 5:32 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or.
Windows 8.1 Deployment Jump Start
TechEd /23/2019 9:23 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Windows 10 Deployment with MDT 2016 (8443)
(c) 2011 Microsoft. All rights reserved.
Service Template Creation from the Ground Up
Service Template Creation from the Ground Up
6/5/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Advanced Offline Servicing Windows 10 Server 2016 / 2019
Simple Offline Servicing for Windows 10 and Server 2019 and Server 2016 and Windows 7 and Server 2012 R2
Fundamentals of a Task Sequence
Bethesda Cybersecurity Club
Presentation transcript:

Real-world OS Deployment Samples Jörgen Nilsson Principal Consultant Onevinn @Ccmexec http://ccmexec.com Johan Arwidmark CTO Truesec @Jarwidmark http://deploymentreaserch.com

Jörgen Nilsson Johan Arwidmark @ccmexec @Jarwidmark MVP MVP 2x A lot! Liverpool FC, Beer, Meat Steak

Session takeaway Common Challenges Windows 10 Challenges Sample Task Sequence Walk-Through Real World examples & Scenarios And all the qeeky stuff you didn’t know you needed to know ;-)

Size matters!! Windows 10 Size Feature Update size Cumulative Update Size

Common Challenges

Webservice! Why Webservice Stabile Less ports open from clients to the Primary Site server, example Remove a computer from a collection script requires: RPC High-Ports WMI Webservice requires only 443 (NOT 80)

Community Webservices Web Service for OS Deployment https://gallery.technet.microsoft.com/Web-Service-for-OS-93b6ecb8 ConfigMgr WebService https://gallery.technet.microsoft.com/ConfigMgr-WebService-100-572825b2 Deployment Webservice (Maik Koster) http://mdtcustomizations.codeplex.com/

Updating definitions during OSD Windows Defender, Endpoint Protection Script to Schedule definition download and package update on a Server Script to deploy during OSD Remember different definitions for Endpoint and Defender

Microsoft Laps Great solution, if you don’t use it you should!! However during OSD you must clear the ”ms-mcs-admPwdExpirationTime” or else! … you will not now the password on the machine until the date there is passed

Pre start commands Boot Image Set system time! Delete any existing ”unknown” object Kick off OSDBackground.exe What is runsilent.exe?

Windows 10 Challenges

What is new under the surface in Windows 10 1607

Driver Signing

TPM Management changes in Windows 10 1607

TPM backup No Longer Possible? In Windows 10 1607 / Server 2016 ADMX files are the options to take backup of TPM is removed. MBAM the agent does not have access to the key by default in Windows 10 1607 anymore Solution!! - TPMPassTheHash _OSDOAF = Passwordhash If you use pre-provisioning PowerShell Script that writes the variable to the registry and sets the OSManagedAuthLevel = "4" And the last step that change it back to "2"

_OSDOAF

Language Support Managing Multiple languages during deployment Deployment, Offline or Online Windows 10 Servicing challenge

MBAM deployment Regfiles to control encryption level otherwise = default in PE version that is used = No Control MBAM TPM Pass the Hash The normal script to enable MBAM and encryption

Using App-v and UE-V Needs to be enabled now that it is builtin the operating system = Powershell Enable Ue-v and to get it to sync on first logon requires: Enable-Uev Set-uevconfiguration -computer -EnableWaitforSyncOnApplicationStart –enablewaitforsynconlogon We also need to register the UE-V templates we need.

Task Sequence walk through

Task Sequence groups Initilize section Format Disk, convert UEFI Sets default values in the TS, example SMSTSErrorDialogTimeout Format Disk, convert UEFI Error Handling Completion Section Error Section

Completion Section Remove from Collection Report completion Copy OSD Logs Stop OSD Background Process

Error Section Save TS Error Code (so we can use it later) OSDBackground Error Set OSD Variables Copy OSD Logs Remove From OSD Collection Disable computer account (a failed machine should never ever be used) SetError Fail the TS with the actual error code that caused the failure

Customer TS example

Real World Samples