Session Agenda Designed to address BIOS Limitations Needed for the larger server platforms (Intel-HP Itanium) First called Intel Boot Initiative.

Slides:



Advertisements
Similar presentations
Microsoft Windows NT Embedded 4.0
Advertisements

Microsoft ® Official Course First Look Clinic Overview of Windows 8 By Ragowo Riantory, S.Kom, MCP.
Improving the boot experience POST OS Initialization Service & App Initialization Service & App Init.
Preparing for security in Windows 8
Windows 8: Windows To Go Overview Zvezdan PavkovicTanya Koval Senior ConsultantArchitect WCL333.
Unified Extensible Firmware Interface (UEFI) Framework UEFI Overview
Leveraging WinPE and Linux Preboot for Effective Provisioning Jonathan Richey | Director of Development | Altiris, Inc.
Sony White House Anthem Lockheed Aramco Bushehr nuclear reactor NSA Hacked Facebook Hacked Apple,Google,Microsoft,
Copyright © Clifford Neuman - UNIVERSITY OF SOUTHERN CALIFORNIA - INFORMATION SCIENCES INSTITUTE USC CSci599 Trusted Computing Lecture Three.
MCITP: Microsoft Windows Vista Desktop Support - Enterprise Section 1: Prepare to Deploy.
Mobility for the Enterprise
Windows Store AppsTraditional Desktop Apps Setup.exe installers Windows Installer (MSI) OneClick (.NET) App-V, Click-to-Run Can be installed silently.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 2 Installing Windows Server 2008.
Implementering af Windows 8 in real life Windows 8 OS Deployment Windows 8 OS Deployment features of ConfigMgr 2012 SP1 Take a look at what’s coming.
©2010 Check Point Software Technologies Ltd. | [Unrestricted] For everyone Endpoint Security Current portfolio and looking forward October 2010.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
64-BIT WINDOWS 7: IS NOW THE TIME TO DEPLOY? Michael Niehaus Senior Software Development Engineer Microsoft SESSION CODE: CLI301 (c) 2011 Microsoft. All.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Joe Chen Sr. Manager, Insyde Software
Tony Mangefeste Senior Program Manager SYS-005T Why UEFI? UX value prop from Day one: Fast Boot, OEM Certification, smooth transitions, etc. Secure Boot.
Host and Application Security Lesson 4: The Win32 Boot Process.
WINDOWS XP PROFESSIONAL Bilal Munir Mughal Chapter-1 1.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 15 Installing and Using Windows XP Professional.
Week #7 Objectives: Secure Windows 7 Desktop
UEFI与固件程序设计 Tel: 同济大学软件学院.
MANAGEMENT ANTIMALWARE PLATFORM Microsoft Malware Protection Center Dynamic Signature Svc Available only in Windows 8 Endpoint Protection Management.
Tel : 同济大学软件学院 UEFI 与固件程序设计.
Windows Enterprise: windows.com/enterprisewindows.com/enterprise.
Hardware Boot Sequence. Vocabulary BIOS = Basic Input Output System UEFI = Unified Extensible Firmware Interface POST= Power On Self Test BR = Boot Record.
DUAL BOOTING  KNOWING LEGACY BIOS & UEFI FIRMWARE  KNOWING MBR & GPT PARTITION D.BHARANI AM.EN.U4CSE12013.
Firmware Storage : Technical Overview Copyright © Intel Corporation Intel Corporation Software and Services Group.
Power onPlatform initialization Operating system (OS) boot Shutdown Run Time (RT) OS-Present Application Final OS Environment Final OS Boot Loader.
Compatibility and Interoperability Requirements
Scott Drucker, Systems Engineer Migrating to Microsoft Vista with WinINSTALL.
Tel : 同济大学软件学院 UEFI 与固件程序设计.
DMTF and UEFI A Partnership for Platform Manageability
4 Key Threats Internet was just growing Mail was on the verge Key Threats Melissa (1999), Love Letter (2000) Mainly leveraging social engineering.
TechEd /25/2017 5:34 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Are cybersecurity threats keeping you up at night? Your people go everywhere with devices, do the apps and data they need go with them? Can you adopt.
Trusted Computing and the Trusted Platform Module Bruce Maggs (with some slides from Bryan Parno)
Adding a Hard Drive. BIOS / UEFI The Unified Extensible Firmware Interface (UEFI) defines a software interface between an operating system and platform.
– Blog:
Tony Mangefeste Senior Program Manager Microsoft Corporation SYS-457T.
Integrated Platform Flexible Virtualization Modern Managemen t.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
Windows 8 tablets with Intel Core 64-bit processors Windows 8 tablets with Intel Atom 32-bit processors Windows RT tablets with ARM processors.
Course 03 Basic Concepts assist. eng. Jánó Rajmond, PhD
Customizing the Browser Deploying IE10 Browser Management App Compat.
Planning Server Deployments Chapter 1. Server Deployment When planning a server deployment for a large enterprise network, the operating system edition.
A+ Guide to IT Technical Support, 9th Edition

Windows 10 Device Health Attestation (DHA)
CIS 221 Lesson 2. What is the first phase of the of the Installation of Windows XP? MS-DOS phase Why is the MS-DOS phase needed? the computer required.
Overview A) Power on or reset B) 1st stage boot loader C) 2nd stage boot loader D) Operate system.
Prepare for Windows 10 and UEFI
Chapter Fifteen Working with Windows 8/8.1.
Virtual Roundtable Discussion
Create setup scripts simply and easily.
Trusted Computing and the Trusted Platform Module
A Fast Track into Device Guard
From Zero to UEFI Shell Jason Jin Technical Marketing Engineer/ECG
Device Guard: AppLocker on steroids
Chapter 2 Objectives Identify Windows 7 Hardware Requirements.
Building hardware-based security with a Trusted Platform Module (TPM)
Booting Up 15-Nov-18 boot.ppt.
11/23/2018 3:03 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Delivering a secure and fast boot experience with UEFI
BIOS Chapter 6.
TPM, UEFI, Trusted Boot, Secure Boot
Booting “Most people, I think, don’t even know what a rootkit is, so why should they care about it?” ~Head of Sony BMG’s global digital business.
Presentation transcript:

Session Agenda

Designed to address BIOS Limitations Needed for the larger server platforms (Intel-HP Itanium) First called Intel Boot Initiative then renamed to EFI Specification and Source Code encouraged the UEFI forum Provides support for newer hardware Addresses the need to support x64 bit system Streamlines the boot process into the OS Simplifies the integration with 3 rd party components

Divided by working groups USWFG UTWG PIWG ICWG UEFI encourages industry participation 11 Promoters 20+ Contributors 70+ Adopters

Enables Innovation Support for Large Disks CPU-Independent Architect Flexible pre-OS Environment Modular Design Why UEFI?

ScenarioMin Server version Min WinPE version Min Boot program version Notes X64 UEFI2008 X64 feature UEFI support introduced in 2008 X64 UEFI support added in 2012 X86 UEFI2012 Support for x86 UEFI added in 2012 UEFI PXE IPv Support for IPv6 added in 2012 The version of the Windows PE boot files must match the computer architecture. An x64-based UEFI computer can boot by using only Windows PE x64 boot files. An x86-based computer can boot by using only Windows PE x86 boot files. *

UEFI Version or newer

Firmware Platform Specific UEFI Firmware Windows OS System hardware UEFI Runtime Services UEFI OS Loader ACPI BIOS ACPI registers ACPI tables ACPI driver UEFI Win32/NT APIs Compatibility Support Module (CSM) BIOS OS loader BIOS mode Legacy BIOS UEFI mode

Power onPlatform initialization Operating system (OS) boot Shutdown Run Time (RT) OS-Present Application Final OS Environment Final OS Boot Loader Driver Execution Environment (DXE) Boot Dev Select (BDS) Transient System Load (TSL) OS-Absent App UEFI Shell Transient OS Boot Loader Boot Manager Device, Bus, or Service Driver UEFI Interfaces EFI Driver Dispatcher Architectural Protocols Pre-EFI Initialization (PEI) CPU Init Chipset Init Board Init verify Security (SEC) PEI Core Pre Verifier

Fat32 LBA 0 LBA z

If a computer is in “Legacy” or “Mixed” mode it is NOT in native UEFI mode

Default UEFI/GPT drive partitions Disk 0 MSR Windows RE tools

Recommended UEFI/GPT drive partitions Disk 0 Windows RE tools MSR Recovery Image

Creating a Bootable USB Drive Option #2: Create Multiple Partition on a WTG USB Drive Option #3: Create your image using two USB sticks Option #4: Boot straight from the Windows OS USB

Looks and feels like a regular shutdown / boot Leverages Hibernate technology to cache the core system Enabled by default Delivers considerable improvements: Boots more than twice as fast on SSD-based netbooks, including POST Need partners to continue work to reduce POST times POST OS initialization Service & app initialization Service & app init Hiberfile read Device initialization Explorer ready Windows 7 Windows 8

Can you really tell the difference?

Secure Boot Process Only executes signed UEFI binary images Includes Option ROMs, pre-boot utilities and OS loaders. Benefit: Helps prevent malicious code before the OS loads Benefit: Provides Time-authenticated variables Benefit: Allows stronger keys for encryption Secure boot is a UEFI specification, not a Microsoft product!

Secure Boot

Measured Boot TPM [PCR Data] [AIK pub] [Signature] Boot Log Hash of next item(s)

Windows 7 Windows 8 Malware is able to start before Windows and Anti-malware Trusted Boot starts Anti-Malware early in the boot process Early Launch Anti-Malware (ELAM)

Current Windows-Specific UEFI Highlights Multicast Deployment Fast boot and resume from hibernation Future UEFI Capabilities Rootkit prevention Network Authentication Deployment Server

Key Objectives Covered

Windows Enterprise: windows.com/enterprisewindows.com/enterprise

System Center 2012 Configuration Manager us/evalcenter/hh aspx?wt.mc_id=TEC_105_1_33 Windows Intune Windows Server Windows Server 2012 VDI and Remote Desktop Services us/evalcenter/hh aspx?ocid=&wt.mc_id=TEC_108_1_33 desktop-infrastructure.aspx More Resources: microsoft.com/workstyle microsoft.com/server-cloud/user-device-management For More Information