Windows Vista Client Manageability 7/15/2019 10:50 PM Windows Vista Client Manageability James O’Neill Evangelist Microsoft Corporation
Contents Introducing Vista’s Management Goals 7/15/2019 10:50 PM Introducing Vista’s Management Goals Maintain PC Configuration User Account Control Resource Protection Simplify Configuration Management Group Policy Update Management Desktop Troubleshooting & Task Automation New / revamped tools
Management Features and Improvements in Windows Vista 7/15/2019 10:50 PM 3 Management Goals: User Account Control Windows Resource Protection Group Policy Enhancements Update Management Improvements New WMI Providers and Windows Remote Management Maintain PC configuration Simplify Configuration Management Desktop Troubleshooting and Task Automation New Event Viewer and Logging Infrastructure New Task Scheduler Reliability Analysis Component
Windows Vista Client Manageability Goal 1: Maintain PC Configuration
“…a locked and well-managed PC can save 40%.” User Account Control 7/15/2019 10:50 PM Lowers total cost of ownership by making it practical to run as standard user PC is kept in known state Restrict installations of unapproved software Less downtime and higher productivity Reduce need to re-image system “…a locked and well-managed PC can save 40%.” —Gartner, December 2005
Barriers to Deploying as Standard User 7/15/2019 10:50 PM 7/15/2019 10:50 PM Can user perform required tasks to be productive without help desk support? (Connect to network, add printer, etc.) Will existing 3rd party and LOB applications run for standard users? Does enterprise have required tools, processes, and policies to support and maintain desktops where users do not have administrator privileges? 6 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Moving the mountain… You will encounter hurdles during this effort. 7/15/2019 10:50 PM You will encounter hurdles during this effort. Here are a few to watch out for: Communication is key. There are applications in your environment you probably don’t know about. Standard Users need a deployment service. Helpdesk is going to get more calls as you start the process. In Vista, Microsoft makes this easier. © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Standard Users Can Do More 7/15/2019 10:50 PM View system clock and calendar Change time zone Configure secure wireless (WEP/WPA) connection Change power management settings Create and configure a Virtual Private Network connection Add printers and other devices that have the required drivers installed or allowed by IT policy Disk defragmentation is a scheduled background process Shield icon consistently marks actions that require elevation 8 © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
User Account Control All users run as Standard User by default 7/15/2019 10:50 PM All users run as Standard User by default Filtered token created during logon Only specially marked apps get the unfiltered token Explicit consent required for elevation Predictable shell elevation paths High application compatibility Data redirection Enabling legacy apps to run as standard user Installer Detection © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Elevation Model Administrator Privileges 7/15/2019 10:50 PM Administrator Privileges Ways to Request Elevation Application marking Setup detection Compatibility fix (shim) Compatibility assistant Run as administrator Administrator Account Standard User Privileges (Default) Standard User Account © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Data Redirection for Legacy Apps 7/15/2019 10:50 PM Legacy apps write to admin locations HLKM\Software; %SystemDrive%\Program Files etc. Redirection removes need for elevation Writes to HKLM go to HKCU redirected store Writes to system directories redirected to per-user store Copy-on-write This is a crutch for legacy applications. © 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Windows Resource Protection 7/15/2019 10:50 PM Maintain PC configuration by preventing potentially damaging system configuration changes System files and registry settings protected from accidental changes by user or from software installers Only OS Trusted Installer Service can change Windows Resource Protection resources If modified, boot critical files are replaced with trusted copies
Windows Vista Client Manageability Goal 2: Simplify Configuration Management
Improvements in Group Policy for Windows Vista 7/15/2019 10:50 PM Extends the reach of Group Policy with hundreds more settings Reliably and efficiently apply policy Easier to use
Extending Group Policy Reach 7/15/2019 10:50 PM Over 500 new settings across key areas Power Management Device Installation and Usage Internet Explorer IPSEC & Windows Firewall Printer Deployment Troubleshooting & Diagnostics User Account Control iSCSI Windows Defender Windows Error Reporting Remote Assistance Terminal Services Globalization Shell Tablet
Improvements In Group Policy Applied more reliably, and easier to use 7/15/2019 10:50 PM Reliable and Efficient Application of Policy Easier to Use Network aware application of Group Policy Support for editing Group Policy settings in Multilingual Environments Support for Multiple Local GPOs GPMC integrated into Windows Search and filter (Post Windows Vista) Templates (Post Windows Vista)
We’re Making Progress Reducing the Pain of Update Management… 7/15/2019 10:50 PM Fewer updates delivered via Windows Update (WU) require reboots Updates requiring a reboot reduced by at least 17% since August 2003 Reduction in update delivery frequency from once a week to once a month Consolidate multiple reboots into a single reboot when multiple patches requiring a reboot are installed together
… And Getting Even Better With Windows Vista 7/15/2019 10:50 PM Patches can be applied directly to images Auto-update everything Platform technology to reduce reboots
Windows Vista and 2007 Office System Further Reduce Disruptions from Reboots 7/15/2019 10:50 PM Fewer reboots when using the Windows Add/Remove Programs feature Corporate Developers can reduce reboots for installations and updates by using the Windows Installer Automatically restart after a reboot due to an installation or update Recreate application state upon restart Windows Installer (MSI) Key 2007 Microsoft Office applications (1) (1) Selected Microsoft applications that take advantage of Microsoft Office Restart Manager Word, Office Excel, Office Outlook, Office PowerPoint, and Internet Explorer
Windows Management Infrastructure (WMI) Enhancements Improve Manageability 7/15/2019 10:50 PM Windows Vista includes 13 new WMI Providers: BitLocker Drive Encryption Trusted Platform Module Boot Configuration Database Intelligent Platform Management Interface Windows Parental Controls Network Access Protocol Client Others…
WinRM: Windows Remote Management 7/15/2019 10:50 PM Firewall Friendly Remote Access Protocol (Replaces DCOM) HTTP & HTTPS Microsoft’s implementation of WS-Management Use Windows Remote Management to Access WMI Information over the Internet
Windows Vista Client Manageability Goal 3: Desktop Troubleshooting and Task Automation
Lack of Awareness of End-User Problems Unreported issues drive productivity, costs, satisfaction Productivity/Cost Implications Productivity losses Potential data loss No IT awareness Root problem not fixed All costs above and … Help desk FTE cost Additional productivity loss in time with helpdesk One-off escalations often low priority Little ability to track problems from changes (i.e., patch, new app) + Desktop Crash! Reboot Most common end-user behavior Call Help Desk Few help desks equipped to resolve <10%(1) >90%(1) Resolve Known error fielded before Escalate Desktop Admin likely sees few crashes <5%(1) (1) CER TAP participant interviews; MS Help desk qualitative discussions
7/15/2019 10:50 PM OUT WITH THE OLD….
New Event Logging Infrastructure: Windows Eventing 6.0 7/15/2019 10:50 PM Right data to diagnose problems The right data…but not too much data Improved supporting data and documentation for all events Infrastructure supports Ad-hoc diagnosis and management tools Schematized events (XML) provide richer information Easy integration with management tools
User Experience in Event Viewer is Dramatically Improved 7/15/2019 10:50 PM Single place to view events for all Windows Vista components Focus on important events with filtering and custom views Events are actionable Associate a task with an event with a single click Event Subscriptions IT Professionals can subscribe to events and view them centrally Based on Windows Remote Management
What’s New in Task Scheduler? 7/15/2019 10:50 PM Power and flexibility Sophisticated Scheduling Options with new triggers, conditional launch, and action chaining Completely scriptable Visibility Task dashboard shows active and upcoming tasks Improved reliability and resource allocation Retry tasks in case of failure Run when next available
Reliability Analysis Console 7/15/2019 10:50 PM Helps you understand causes of crashes and hangs Tracks frequency and type of user disruptions Shows connections between application installs and other system events
Summary: Management Features & Improvements in Windows Vista 7/15/2019 10:50 PM User Account Control Windows Resource Protection New Event Viewer and Logging Infrastructure New Task Scheduler Reliability Analysis Component Group Policy Enhancements Update Management Improvements New WMI Providers and Windows Remote Management Maintain PC configuration Simplify Configuration Management Desktop Troubleshooting and Task Automation
Windows Vista Resources 7/15/2019 10:50 PM Windows Vista Resources Technical Chats and Webcasts http://www.microsoft.com/communities/chats/ http://www.microsoft.com/events/webcasts/ Microsoft Learning and Certification http://www.microsoft.com/learning/ MSDN & TechNet http://www.microsoft.com/MSDN http://www.microsoft.com/TechNet http://microsoft.com/TechNet/WindowsVista/Library/ Virtual Labs http://www.microsoft.com/technet/traincert/virtuallab/rms.mspx Newsgroups and Forums http://www.microsoft.com/communities/newsgroups Technical Community Sites http://www.microsoft.com/communities/ http://www.microsoft.com/WindowsVista/community/ User Groups http://www.microsoft.com/communities/usergroups/
What else does TechNet give you? FREE TechNet Newsletter” FREE Events and Webcasts FREE quarterly “TechNet” magazine FREE comprehensive technical website FREE TechNet Radio, Security Centre, Learning Paths and Virtual Labs TechNet Plus Subscription DVD A range of tools and resources for IT professionals that let you plan, manage ,deploy TechNet is a range of tools and resources providing IT professionals with all the information they need to plan, manage ,deploy and maintain their systems and applications To subscribe to the newsletter or just to find out more, please visit www.microsoft.com/uk/technet
Thank you for attending this TechNet Event http://www.microsoft.com/uk/technet PS (The evaluation form is now sent out electronically with your thank you e-mail. This can take up to 5 working days. Please do feedback as we read all the comments and use them to shape future event content)