Modernizing your Remote Access

Slides:



Advertisements
Similar presentations
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Advertisements

demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
Virtual desktops in the cloud: Experiences from the field
Secure Hyperconnectivity with TeamViewer and Windows technologies
Enterprise Security in Practice
From IT Pros to IT Heroes - with Azure DevTest Labs
5/21/2018 9:40 PM BRK3021 Learn about modern infrastructure roles in RDS: Next generation Windows desktop & app virtualization Clark Nicholson - Principal.
5/22/2018 1:39 AM BRK2156 Power BI Report Server: Self-service BI and enterprise reporting on-premises Christopher Finlan Senior Program Manager © Microsoft.
Azure File Sync Setup, configuration and management
Azure Cloud Shell Magic of Modern Command-line Management
Microsoft /17/2018 4:24 AM BRK4012 Dive deep on Skype Web SDK & Skype for Business App SDK - Build apps across Web, IOS & Android Srividhya Chandrasekaran Amit.
Windows 10 and the cloud: Why the future needs hybrid solutions
6/25/ :13 PM BRK1076 Make Windows devices more secure by taking them out of your existing infrastructure Chris Rhodes & Andrew Bettany MCTs & MVPs.
Get Typed with TypeScript!
Optimizing Microsoft OneDrive for the enterprise
Build /4/2018 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
What a Real, Functioning DevOps Team Looks Like
Virtual Machine Diagnostics in Microsoft Azure
SQL Server on Linux on All-Flash Arrays
Microsoft Ignite /31/ :08 AM
8/6/ :17 AM THR2214 Hybrid Cloud Activated A customer case study optimizing on-premises & Azure performance and cost Mor Cohen-Tal Senior Product.
Microsoft Planner: How to manage your team’s work in Office 365
Microsoft 365 Business: Under the Hood
Workflow Orchestration with Adobe I/O
Customize Office 365 Search and create result sources
How we got a traditional bank collaborating across boundaries
Windows 10 Subscription Activation
Group Policy in MDM: Dealing with ADMX backed policies
Automate all things! Microsoft Azure continuous deployment
Microsoft Teams Mobile Collaboration on the go
Using AAD B2C for WordPress & Secure Deployment Scenario
Agile Planning with Visual Studio Team Services (VSTS)
Servicing Windows 10 in the Real World
9/22/2018 3:49 AM BRK2247 Learn from MVPs: Panel discussion on all things SharePoint and OneDrive © Microsoft Corporation. All rights reserved. MICROSOFT.
Azure PowerShell Aaron Roney Senior Program Manager Cormac McCarthy
Continuous Delivery with Visual Studio Team Services
Azure Advisor: Optimization in the best way
Bring existing desktop apps to UWP with the Desktop Bridge
Mobile Center and VSTS:​ Better together for your Mobile DevOps
12/5/2018 2:50 AM How to secure your front door with real-time risk assessments of your logons Jan Ketil Skanke COO and Principal Cloud Architect CloudWay.
Microsoft products for non-profits
TechEd /6/2018 8:16 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Automating security for better, continuous compliance in the cloud
Introduction to ASP.NET Core 1.0
Five cool things you can do with Windows PowerShell on Office 365
What do YOU get from SharePoint Hybrid?
Microsoft To-Do Preview
Microsoft Exchange: Through the eyes of MVPs (Panel discussion)
MDM Migration Analysis Tool (MMAT)
Overview: Dynamics 365 for Project Service Automation
Understand your Azure cloud assets dependencies with BMC Discovery
Surviving identity management in a hybrid world
Breaking Down the Value of A Yammer Post: 20 Things to Do
Cool Microsoft Edge Tips and Tricks
When Bad Things Happen to Good Applications
Getting the most out of Azure resources with Azure Advisor
Manage your App Service resources using Command line tools
“Hey Mom, I’ll Fix Your Computer”
4/21/2019 7:09 AM THR2098 Unlock New Opportunities with Nintex Hawkeye Process Intelligence and Workflow Analytics Sr. Product.
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Consolidate, manage, backup, and secure your cloud content
Designing Bots that Fit Your Organization
Ask the Experts: Windows 10 deployment and servicing
Passwordless Service Accounts
Шитманов Дархан Қаражанұлы Тарих пәнінің
Azure Networking inside and out
Digital Transformation: Putting the Jigsaw Together
WCF and .NET Framework Microservices in Containers
Diagnostics and troubleshooting in Azure App Service Support Center
Optimizing your content for search and discovery
Presentation transcript:

Modernizing your Remote Access 6/20/2018 1:43 AM BRK2317 Modernizing your Remote Access Lily Wang Aman Arneja © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Overview VPN in Windows 10 Remote Access Scenarios What’s new 6/20/2018 1:43 AM Overview VPN in Windows 10 Remote Access Scenarios What’s new © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Key Takeaways Available options for remote access 6/20/2018 1:43 AM Key Takeaways Available options for remote access Real world configuration scenarios New features in Windows 10 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows 10 VPN Options VPN Windows 10 Classic Win32 6/20/2018 1:43 AM Windows 10 VPN Options VPN Windows VPN Platform Inbox Solution Native Protocols : L2TP, PPTP, SSTP, IKEv2 Takes advantage of all new Win 10 Features Shares Drivers with the Site to Site VPN used for Servers UWP VPN Plugin Platform Based on UWP APIs Available on Desktop/Phone/HoloLens etc. Classic Win32 Based on Win32 NDIS Kernel Drivers Does not take advantage of new VPN Features Only Available on Desktop (Excluding Windows 10S) Windows 10 © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Remote Access Scenarios 6/20/2018 1:43 AM Remote Access Scenarios © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Your remote access solution 6/20/2018 1:43 AM Your remote access solution © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Your VPN toolkit Deployment On demand Authentication Security MDM SCCM 6/20/2018 1:43 AM Your VPN toolkit Deployment On demand Authentication Security MDM SCCM Always On App Trigger Destination name based trigger Certificate Smart Card WHfB auth Traffic Filtering Lockdown Windows Information Protection © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Scenario 1 Always Connected Split traffic Simple configuration 6/20/2018 1:43 AM Scenario 1 Always Connected Split traffic Simple configuration Faster initial deployment Ease of maintenance Clientless Ease of use Direct Access-like Non corp traffic should go over physical interface © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Keeps users always connected to corp Boolean feature Corporate network 6/20/2018 1:43 AM payroll Network shares Always On Keeps users always connected to corp Boolean feature Corporate network Netflix Split Tunnel Facebook Configure what traffic should go over the VPN interface The Internet Cat videos © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Connection management Scenario 2 On demand Corporate namespaces Connection management Only connected when corporate resources are needed Defined namespaces for corporate resources Reduce # of concurrent connections

Destination Name based Trigger payroll.contoso.com payroll Network shares Destination Name based Trigger Corporate network Netflix Only connects when configured domains are queried FQDN, Suffix or short name Split Tunnel Facebook Configure what traffic should go over the VPN interface The Internet Cat videos © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Connection management 6/20/2018 1:43 AM Scenario 3 On demand Line of Business apps Connection management Restrict VPN Only connected when corporate resources are needed Uses mainly LoB apps for enterprise productivity Reduce # of concurrent connections Only configured apps to send traffic over VPN © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Only connects when configured app is launched 6/20/2018 1:43 AM payroll Network shares App Trigger Netflix Only connects when configured app is launched Launch Edge Corporate network Facebook The Internet Cat videos Netflix Traffic Filter Non configured apps cannot access the VPN Launch App 1 payroll Network shares © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Scenario 4 On demand Line of Business apps Restrict App Traffic Only connected when LoB apps are open Uses mainly LoB apps for enterprise productivity No app traffic to go over physical interface

Only connects when configured app is launched 6/20/2018 1:43 AM payroll Network shares App Trigger Only connects when configured app is launched Launch Edge Corporate network The Internet Netflix Traffic Filter Configured app traffic must go through VPN Non configured apps cannot access the VPN Launch App 1 payroll Network shares © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Common Across Scenarios Authentication Certificate based WHfB Deployment Trusted network detection Server Network settings – proxy, firewall rules, DNS, DHCP

What’s new

Infrastructure tunnel Remote login Manage out Always Connected First time login Disabled Cached credentials Push updates to a device regardless of user login (ie: Windows Update, SCCM policy update, etc) Direct Access-like Clientless Ease of use

IKEv2 with machine cert auth 6/20/2018 1:43 AM IKEv2 with machine cert auth Management traffic (domain controllers, SCCM, etc) Corporate network All other corporate traffic Infrastructure tunnel Always On as long as device is in a wake state Management traffic configurable in the profile Can coexist with one other active user tunnel © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM Demo © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Conditional Access for VPN Security Posture Detection On-Prem Integration Simple configuration Short Lived Certificate Tied directly with MFA Minimal changes to existing VPN servers Works with all VPN Servers Simple dashboard in AAD portal Minimal addition to the VPN profile for Client Rich MDM based compliance policy options

Conditional Access Client Internet Intranet Domain 6/20/2018 1:43 AM 1. Token auth through AAD Token Broker 2. Check compliance VPN Platform Token Broker Corp. User CA 6 5 4 3 7 VPN Client/Plugin Certificate Store Client 8 Internet VPN server Intranet RADIUS server 9 10. Authenticate user Domain © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Conditional Access Now in Public Preview

Please evaluate this session Tech Ready 15 6/20/2018 Please evaluate this session From your Please expand notes window at bottom of slide and read. Then Delete this text box. PC or tablet: visit MyIgnite https://myignite.microsoft.com/evaluations Phone: download and use the Microsoft Ignite mobile app https://aka.ms/ignite.mobileapp Your input is important! © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6/20/2018 1:43 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.