Presentation is loading. Please wait.

Presentation is loading. Please wait.

Physical Topology Logical Topology Authentication Licensing.

Similar presentations


Presentation on theme: "Physical Topology Logical Topology Authentication Licensing."— Presentation transcript:

1

2

3

4

5

6 Physical Topology Logical Topology Authentication Licensing

7

8 Hyper–V host AHyper–V host B Web tier Application tier Database tier

9 Hyper–V host AHyper–V host B Web tier Application tier Database tier

10 On Critical Path For Most RequestsInteractive / Serving End-user Requests Doing Background Processing Request Management Distributed Cache User Profile Application Metadata Services Business Data Connectivity Secure Store State Session State Access User Code Search Query PerformancePoint Visio Excel Services PowerPivot Project User Profile Sync Crawl Target Content DB Jobs Workflow WMA Machine Translation Search Crawl Document Conversion SPC192 11/13 1:45 PM

11 Front End Low latency Back End More tolerant latency Database tier Routing and Caching Very low latency Request Management Distributed Cache User Profile Application Metadata Services Business Data Connectivity Secure Store State Session State Access User Code Search Query PerformancePoint Visio Excel Services PowerPivot Project User Profile Sync Crawl Target Content DB Jobs Workflow WMA Machine Translation Search Crawl Document Conversion

12 Front End Low latency Back End More tolerant latency Database tier Routing and Caching Very low latency Search (Query, Index, Admin) Low latency For all but the smallest enterprise deployments, you will want to split Search Query functionality to a separate tier SPC007 11/13 9:00 AM

13

14

15 Office Web Applications

16

17

18

19 Application Pool ”SharePoint” Logical functionality ”My Sites”Logical functionality ”Intranet” Logical functionality ”Teams” Logical functionality ”Communities” Logical functionality ”Projects” IIS Web Site – ”SharePoint”

20 One Web application, one zone Have a good business reason why you deviate from this Use Host Named Site Collections Scales Better Reduced Resource Consumption (Memory for App Pools, Cache, etc) Mitigates x-site scripting risks the same as multiple web apps SSA (Secure Site Access) - You can still have multiple host names !

21

22

23 Use a single web application with a single zone configured for the various auth methods that you require Use Claims based auth (Win or FBA) For SAML Claims IP STS needs to support wildcard domain WSFedEndpoint We are working with ADFS Team to enable this scenario Anonymous on the same web app? Extend the web app to another zone and configure that for Anonymous SPC209 11/13 5:00 PM

24 Be Ready for oAuth In oAuth Farm 2 Farm conversation only a subset of attributes are provided SharePoint S2S depends on mapping to a user account through the user profile application User Token is rehydrated on the destination farm UPA stores user attributes (claims) used for rehydratation Be sure all claims are in the UPA Otherwise, new custom claims provider might be needed Be ready for the Cloud and Hybrid Be sure attributes are all in your Directory Service (e.g. AD) Be sure your Directory Service can fully sync to MSODS SPC243 11/13 9:00 AM

25

26 What we had in SharePoint 2010: Licensing control was per farm. If you had to differentiate licensing model: You needed 1 farm for Standard You needed 1 farm for Enterprise Ah, and we only had 2 different licenses Different mix & matches were not possible

27 2013: Increased ability to manage licensing vs previous versions. Licenses and licenses check are per user Requires Claims auth: licenses are “assigned” by mapping claims to users E.g. assigning an enterprise license to an Active Directory Group Works for SharePoint (Enterprise & Standard), OWA and Project Server 4 licenses provided OOB

28

29 Configured and controlled by PowerShell Get-SPUserLicensing Enable-SPUserLicensing Disable-SPUserLicensing Get-SPUserLicense Get-SPUserLicenseMapping New-SPUserLicenseMapping Add-SPUserLicenseMapping Remove-SPUserLicenseMapping Licensing enforcement: Web Parts Web Part Gallery Web Templates Document Libraries

30 MySPC

31

32 Is stretched farm supported ? No – Officially unsupported – Do not ask us to re-visist this decision. We are firm. Do we need to enable MT ? Yes – But only a single tenant How many farms do I need ? One How Many Web Applications do I need ? One – With one Zone What about Anonymous access ? This is the “Exception Case” for a single zone. Anonymous will require extending to a second zone. Cloud App Model only works on the default zone !!

33 Multi tenant feature: yes Subscription Settings Service required for new cloud App Model This should be the extent of your utilization of MT Multiple tenants on the same farm: better not MT is the “Deep End of the Pool” – There is a high level of investment in both development as well as maintenance MT Only becomes cost effective when tenant numbers scale into the multiple thousand range.

34

35

36

37

38

39

40

41 ©2012 Microsoft Corporation. All rights reserved.

42


Download ppt "Physical Topology Logical Topology Authentication Licensing."

Similar presentations


Ads by Google