TechVirtuoso

Microsoft highlights MED-V features for Windows 7

January 7th, 2010 at 1:33 PM  No Comments

Microsoft Enterprise Desktop Virtualization (MED-V), is a component of the Microsoft Desktop Optimization Pack (MDOP) for Software Assurance customers. It allows administrators to provide a virtualized desktop image to users and manage them from a central console. The upcoming Service Pack 1 for MED-V will expand support for Windows 7 (both 32 and 64-bit) as a host platform. Considering most large companies held off on upgrading to Windows Vista and opted to wait for Windows 7, this technology will help boost the migration since they can do so and run older programs that may no longer be supported or have not been certified for Windows 7.

In V1 SP1, MED-V continues to employ Virtual PC 2007 as the virtualization engine but unlike the consumer “Windows XP Mode” it does not require hardware-assisted virtualization like Intel VT or an AMD-V to be present in the processor. This allows even those with lower end or older processors to take advantage of enterprise desktop virtualization.

Microsoft has put together a screencast demonstrating running a MED-V workspace using a V1 SP1 client in the Windows 7 environment.


Get Microsoft Silverlight

Natural User Interface & Microsoft Research

January 7th, 2010 at 1:11 PM  1 Comment

The QWERTY keyboard and the mouse have been the primary methods of interaction with computers for a long time. But there is a group at Microsoft seeking to make that a thing of the past. Enter the team at Microsoft Research.

Larry Larsen over at Microsoft’s Channel 9 has a great interview with Bill Buxton, one of the Principle Researchers at MSR and the author of Sketching User Interfaces. It talks about their work with what Microsoft has dubbed “Natural User Interface” and how the multi-touch technologies in products like the Apple iPhone and Windows 7 will eventually become a regular part of computing, as well as new technologies like those in the Xbox 360 Project Natal.


Get Microsoft Silverlight

Microsoft CES keynote fails to excite

January 7th, 2010 at 8:28 AM  No Comments

If you couldn’t get a chance to watch the Microsoft CES pre-show keynote last night, you didn’t miss much. If you were actually at the event, I feel sorry for you, it must have been hard to stay awake.

After starting late due to power issues (which fried one of the Microsoft demo units on stage) the keynote got off to a rather boring start with Steve Ballmer, Microsoft CEO, giving various statistics about how well recently released products like Windows 7 and Bing are doing. For the first half hour, the audio stream for the webcast was so bad, it kept cutting out and then required constant volume adjustment. Note to Microsoft, hire a decent sound engineer next time.

If you’d like to watch the keynote for yourself, you can see the saved version on the Microsoft website.

It was all pretty much downhill from there. The much discussed “Courier” tablet that many in the tech press was excited they would announce never came, and there were no details about Windows Mobile 7… at all. Only “we’ll have more about mobile at Mobile World Congress.” So overall, the keynote failed to deliver much of anything that we didn’t know or have not seen already. But, here is a breakdown of what was covered, after the break.

(more…)

Windows Print Server team seeking feedback

January 6th, 2010 at 6:13 PM  2 Comments

There are many less than glamorous roles that a Windows server can take on. Not all of them are born to be an Exchange server, a domain controller, or even a web server. Some are destined to take on the role of managing printers. And for every role in Windows server, there is a team of programmers and engineers behind it, and they need your help.

If use the Print Server role in your environment, Microsoft is looking for your feedback, especially if you’re using the print server management packs for System Center Operations Manager 2007. Your input will help form the future manageability plans for the print server role in Windows Server. If you deal with printers like I do, you probably know how frustrating they can be so you’ve probably got a lot of feedback to give. (Although truthfully none of my issues are really Microsoft’s fault — I’m looking at you Xerox)

Head over to the OpsMgr public site on Microsoft Connect and fill out the “Print Server Management Survey” You’ll need to login to Connect using your Windows Live ID but Microsoft claims the survey is anonymous and should take about 5 minutes to fill out the 11 questions.

Changes in Windows Server 2008 R2

January 6th, 2010 at 5:20 PM  No Comments

Microsoft has posted a little bit of light reading, a document titled Changes in Functionality in Windows Server 2008 R2 that outlines exactly that, the differences between the R2 release and the original 2008 release. It only weighs in at 1.1MB and 211 pages. You can grab it from the Microsoft Download Center in Microsoft Word format or browse the document online through Technet.

Topics such as new features in Active Directory, DNS (including DNSSEC), Group Policy, iSCSI, IIS, clustering, Windows Deployment Server and many other elements are all covered in great detail. If you’re looking at a server wondering if you’d see any significant benefit to upgrading, other then getting the latest guts of Windows, this is a helpful guide.

Windows Server 2008 was released in February 2008, followed by R2 which was released in October 2009. R2 is Microsoft’s first 64-bit only operating system release and is based on many of the same core programming as Windows 7.

Microsoft CES keynote, tonight at 6:30 PST

January 6th, 2010 at 10:54 AM  2 Comments

Microsoft CEO Steve Ballmer and Robbie Bach, president of the Entertainment & Devices Division, will deliver the pre-show keynote address in Las Vegas to kick off the 2010 International Consumer Electronics Show (CES). You’ll be able to watch the keynote live starting tonight, at approximately 6:30 p.m. PST. If you can’t make it, check back here tomorrow for a break down of what was covered. Expected topics include Windows Mobile 7, as well as a possible announcement about a new tablet developed with HP. Even if they don’t cover that, you can at least watch Ballmer jump around the stage for a while.

Take a trip over to the Microsoft CES website tonight to be able to watch their live stream.

Access Denied: Giving users local administrator permissions on their machine?

December 8th, 2009 at 9:56 AM  10 Comments

A recent email discussion over a education security listserv got me thinking about the topic of giving users administrator rights to their local machines. This is a common discussion that comes up about once every month or so, when ever someone new joins the group. The discussion usually starts by asking for methods of removing administrator access in environments where rights have already been given, and then nosedives into a long discussion about the ethical and practical reasoning behind it.

There seems to be two schools of throught about all of this.

  1. Lock the user out of everything that would prevent malware from being installed or the user installing software they’re not suppose to, at the expense of user frustration and IT time spent approving and installing software requested by users.
    Basically, the users are stupid and cannot be trusted. IT will have to monitor them.
  2. Give the user access to everything and let them install whatever they want, at the expense of user frustration and IT time spent removing software they’re not suppose to have and malware that have been installed as a result.
    Basically, trust the users and clean up after their messes when they don’t understand what they’re doing.

In an educational setting, specifically in higher education, you have a lot of competing interests. You’re a business, selling a product (education) and have to compete with other businesses (schools) to gain more customers (students) — therefore, security like what you’d have at any enterprise is necessary. However, you have a group of highly educated and often times very ego-centric individuals called faculty that feel they have a right to gain access to anything and everything in order for them to independently do their job without interruption from IT, or having to ask them for assistance. I would imagine it’s something like working with engineers, but in this case 95% of the people have no idea how to use a computer. Last but not least, the university is an ISP, providing Internet access to students and employees on their personal machines. But that’s a topic for a future entry.

The idea that users need administrative access to their computer or that they somehow have a right to it is wrong in my opinion. When I go into my office, I have services provided to me by other departments on campus that I do not have full control over. If I need a light bulb replaced in my office, do I have a key to go do it myself or do I just call Physical Plant and have them come over? Sure it’d be faster and probably easier for plant to just go take care of it myself. Just because you can give someone full access to a machine, and they’re used to it at home, doesn’t mean they should have that access at work.

I have full access to the thermostat at home (well, I take that back… my wife does… I’m just a user there too) but I can’t just go adjusting the HVAC system at work how I want.

We make as much software as possible that we’ve pre approved user-installable through Group Policy Software Deployment and soon though System Center once we have that up and running. Our staff maintains a repository of approved software installs that require us to do it, so when the user cannot do it themselves it only takes us a few minutes. If a user walks up to our support center, we can usually get the software installed on their laptop right away. We’ve given our Help Desk very easy to use remote access software and can usually get stuff installed for them within 24 hours, if not as soon as they call in or email.

Does malware still get installed on systems where users lack administrative access? Yes. Which brings me to another point.

You also need to look at the amount of damage that can be done in the time period where a user with administrative access disables anti-virus to install something, or even where the AV client doesn’t detect it and the user isn’t aware enough to see what has happened. A few years ago, the malware was about annoying the user or deleting files, but as it has changed to becoming a security breach where data can be stolen often without the user even seeing they’ve been infected.

My wife works for a multinational accounting services firm, where she and her co-workers have access to information that would probably make any hacker wet their pants with excitement. Yet, they have administrative access to their company issued laptops, since they spend most of their time outside of the corporate office. In one case, she told me where one of her co-workers went weeks with a system she knew was infected with porn-popups, yet was “too busy” to do anything about it, like take it into the office and let IT look at the system. Did she know better? Despite required company IT education and training, probably not. Did my wife? You betcha.

That infection may have been harmless, or just designed to generate traffic to your friendly neighborhood porn site, but would the next one be so lucky? Sure, you may put good AV on systems and monitor them daily, but they can’t catch everything. It seems like we should be fighting to do everything in our power to prevent this from happening, even if it means it’s more difficult for the user and IT. The risk of not doing so outweighs the easy of use.

Do your users have administrative rights? Why or why not?

Catchalls, On Behalf of and Google Apps

December 8th, 2009 at 9:22 AM  No Comments
As most of you know for quite some time I have been looking for a way to consolidate multiple email accounts in one nice interface.  I run a small business and have many email accounts that go directly to me.  It would be nice if I were able to log into one web based email service and be able to read/respond the emails from these accounts in one centralized location.  Every service I tried there was a downfall of some kind.  I really liked Google’s email solutions but they had one draw back; the on behalf of annoyance that has bugged many Google mail users since they started to allow users to send email from a different email address.

I got an early Christmas present in July when someone pointed me to this blog post on Google Apps blog.  FINALLY they have setup a work around for the “on behalf of” problem.  I immediately started to go through in my head how this was all going to work.  I did a Google Search on setting up Google Apps to see what other users were doing and I found an article about a completely different approach to managing emails.  Users are setting up a domain on Google Apps and setting their main email as the catchall for the domain.  Brilliant!  Now, when I sign up on a website I use thewebsitename@mydomainname.com and can have my filters automatically tag the emails coming in.  Also, if the website sells my information or gets hacked and I start getting spam I can blackhole the email account and decrease the amount of spam I receive on a daily basis to almost nothing.

Catchalls have been around for sometime and I am surprised over time other users haven’t figured out the benefits of using a catchall email account with a domain like I have setup in this situation.  This is a great setup for any user or a small business who wants to look like more than a one man shop.

KVM over IP and a Bad Demo

November 26th, 2009 at 5:45 PM  1 Comment

We are going through a major Avaya upgrade at work.  Since we are moving to VoIP we are making changes to our network as well as some of the infrastructure to prepare for the upgrades.  We have a bit left over from the budget so we are trying to fit a KVM over IP solution into the current budgeted numbers and I can tell you it has been pretty challenging.

I have previously used the Startech KVM over IP product as well as one of their switched PDU’s and I was not impressed.  The pricing fit into our budget but I didn’t want to buy crappy equipment jut because it fit into our price range.  After looking through the CDW website I found a solution from Aten that I liked so I contacted my CDW rep to schedule a demo.  He also said I should look at a Belkin solution and a Avocent solution all within the budget.

In the mean time Belkin had a demo available on their web site.  I signed up for the demo and it worked pretty well but I was hoping for a more robust solution so I waited for the Aten demo to be setup.

The Aten demo started off like most demos, with a power point presentation written word by word by a sales representative.   The technician that was supposed to be joining the call was running late and after the sales rep. finished his power point, he hunted down the technician and got him on the phone.  The technician shared their screen and logged into one of their units.  He jumped around a lot and the connection between him and the KVM device was severed twice during the 20 minute demo.  He claimed it was network issues at his local site and nothing to do with the Aten equipment.

After the warm and fuzzy feeling disappeared after seeing the bad Aten demo I asked my CDW rep to get a representative from Avocent on the phone.  We scheduled a demo with Avocent and everything went very well.  I was very impressed with their product and everything worked the way it should.

I figured I would end this post with a little bit of advice to any sales representatives reading this.  If someone asks for a demo of your product this is your chance to close the deal.  Make sure everyone is on time, you don’t just read directly from a power point AND when it comes time to show your product it actually works.  I would say if you could only choose one of these points to excel at… the last one is the most important.

Android road warrior has phone, ISO connectivity

November 23rd, 2009 at 9:42 AM  2 Comments

junefabricsAs I stated in my previous post, I have left the world of BlackBerry and Microsoft Exchange behind and transitioned my e-mail, calendar, contacts, and mobile platform to Google Apps and Android. Doing so was no small decision, as my “day job” requires that I have access to all of these items and that they work in unison with each other, my desktop, my laptop, and that I have access to my data anywhere at any time.

I own an IT consulting firm, and as you can imagine, that means that I am not always in the office, and don’t always have connectivity available. With my BlackBerry, it was as simple as loading the Sprint SmartView software on my laptop (similar applications are provided by most carriers) and using my BlackBerry’s data connection. However, SmartView doesn’t work with the Samsung Moment, and Sprint has made the (poor) decision to do away with tethering or “Phone-As-Modem” options on their Simply Everything plans which are required plans for their smartphones. I speculate that their reason for doing away with tethering is an effort to drive customers to the increasing number of mobile broadband devices that they carry, including the new Novatel MiFi 2200 router, but I’ll save that gripe for another post.

(more…)

« Newer PostsOlder Posts »