Friday, September 23, 2011

Microsoft acquires BHOLD technology assets

It has just been announced that Microsoft has acquired BHOLD technology assets! This will be a very interesting move towards Identity Management and the future of Forefront Identity Management (FIM).

"...Microsoft has acquired certain assets of BHOLD, a leading provider of identity and access governance functionality. BHOLD will continue as an independent entity. The terms of the deal will not be disclosed. Roadmap and licensing will be announced later..."

"...BHOLD’s product capabilities currently augment Forefront Identity Manager by adding identity and access governance functionality including in-depth role management, separation of duties, access certification, and authorization management. These capabilities help to ensure access controls are enforced and that customers meet their controls policies and obligations.
Today, customers use BHOLD’s capabilities to augment FIM by:
  • Managing access rights of people by role to achieve business goals while minimizing risk
  • Increasing end user productivity through self-service role management and access recertification
  • Aiding in risk management and GRC initiatives with respect to identities and their associated access rights..."
Sources:
http://www.microsoft.com/pathways/bhold/default.htm
http://blogs.kuppingercole.com/kuppinger/2011/09/23/microsoft-acquires-bhold-technology-assets/

Tuesday, September 20, 2011

Remote Desktop Client in Windows 8 (version 6.2.8101, RDP 8.0)

I have installed the Windows Developer preview of Windows 8 (client) on my lab. Time to check what’s new in the Remote Desktop Client in Windows 8. See the first screenshot below. Besides some minor design changes the client seems to look the same.


When we take a look at the properties we see that it’s version is now 6.2.8101, and that the client now supports Remote Desktop Protocol 8.0. (This perfectly matches the naming of the OS of course J)


The only visual difference in the Remote Desktop Client is that there is a new option in the experience  tab. We now have the option to choose “Detect connection quality automatically”. This will grant us  some flexibility when it comes to connection speeds and performance.

A list of actual changes inside the Remote Desktop Protocol 8.0 isn’t available yet, but not doubt that it will be related to RemoteFX and better WAN performance. I.e. a recent article on ZDnet shows that RemoteFX will also be available in Remote Apps.
When you start a connection you now also have the option to authenticate using a LiveID and sync personal settings. This would, of course, require additional configuration on the destination server (or client) but Cloud-driven is the word that comes into mind here. Will it mean true User State Virtualization? Or in the Bring Your Own series; BYORP "Bring Your Own Roaming Profile". :-)

Next step will be Installing Windows Server 8 and checking what’s new in the various RDS roles.
To be continued….

UPDATE: Great presentation and slides on what's new in RDS in Windows 8 here:
http://channel9.msdn.com/Events/BUILD/BUILD2011/SAC-642T

Friday, September 9, 2011

Big announcement about upcoming TechMentor Conference, October 10-14, Las Vegas

The TechMentor Conference is coming soon in Las Vegas, and this blog, as a offical social media supporter of the event, have information to share with you that won’t be officially announced until Monday – so you’re the first to know!
Coming up October 10-14 at the Planet Hollywood Resort & Casino, TechMentor is the place where IT pros go to learn tips, tricks and solutions to everyday problems – straight from today’s top IT experts. Session tracks include:
The big announcement: Due to an overwhelming number of requests, the Early Bird discount of $200 is being extended one more week to Friday, Sept. 16th! TechMentor isn’t announcing this officially until Monday, Sept. 12th, but they’ve provided me with this information to share with you early!
So, if you want to brush up your skills, boost your knowledge and supercharge your IT investment (or, you just need an excuse to go to Vegas), TechMentor is your best bet. Register today to save $200: http://bit.ly/TMLVReg

“Allow Logon through Terminal Services” GPO and the “Remote Desktop Users” group.

In case you're confused about the GPO setting “Allow Logon through Terminal Services” and the security group  “Remote Desktop Users”, a new blog post by the Ask the Performance Team was just posted on blogs.technet.com on this subject. It provides a clear explanation on the differences and the combination of those two settings.

"...I am sure many of you are already familiar this GPO and this group. But still there has been some confusion around whether you should be using the GPO for allowing the user to RDP to the server or should be using the Remote desktop users group or both. And at times, even what to choose between them and what is the best recommended practice.

Hence I wanted to provide a short simple explanation about this group policy and the user group and how they are interrelated.

To start with, there are two types of user rights; Logon rights & Privileges. In simpler terms these are:
1) Remote Logon: rights to machine
2) Logon: privileges for access to the RDP-TCP Listener

These play the vital part in allowing an RDP session to the server.
When a user is able to validate the above two conditions successfully, only then is the user provided with a successful RDP connection to the server.

The Remote Logon is governed by the “Allow Logon through Terminal Services” group policy. This is under Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment.
By default, the Administrators and Remote Desktop Users groups are given remote logon rights. So, users who are a part of these groups will be authorized to logon remotely to the server.

Now, if you have a user account which is not a part of the Administrators or the Remote Desktop Users groups and you go ahead and add him to the GPO for “Allow Logon through Terminal Services”, they will still not be able to create a successful RDP connection to the server. The reason being that adding a user to this GPO only authorizes him for a Remote Logon to the server but does not give him the permissions to connect to the RDP-Listener.

Now comes into play the Logon privileges for the RDP-Listener. Once the user is authorized for remote logon his privileges to connect to the RDP-Listener is verified. If the user has permissions on the listener then the connection is successful. These permissions can be verified from RDP-TCP Listener properties..."
Source: http://blogs.technet.com/b/askperf/archive/2011/09/09/allow-logon-through-terminal-services-group-policy-and-remote-desktop-users-group.aspx

Thursday, September 8, 2011

Quest releases the free Quest vWorkspace Desktop Optimizer

Great news! Quest Software has just released the free Quest vWorkspace Desktop Optimizer. It looks very promising. For details, see below.

"...One of the biggest advantages that our customers see when they choose to use VDI as their desktop virtualization technology of choice is simplicity. In their current environment they have mastered the art of creating, deploying and managing a Windows desktop operating system and choosing VDI allows them to reuse all of that knowledge. Blindly deploying entirely the same Windows desktop image that was used for the physical desktops is a little naive though. Running Windows in a VDI environment requires a decent amount of optimizing. This optimizing is nothing new. We have been optimizing SBC environments for over ten years now and many of things that we learned there (the hard way) apply equally to VDI environments.
We have created a piece of software that contains our entire ‘optimizing knowledge’ called the Quest vWorkspace Desktop Optimizer and we have decided to make it available to the desktop virtualization community, completely free of charge!.."

Source: http://communities.quest.com/community/vworkspace/blog/2011/09/08/introducing-the-free-quest-vworkspace-desktop-optimizer

RD Gateway and logon attempt failed errors

A new blog post by the Remote Desktop Services team blogs.msdn.com discusses fixing the logon attempt failed error when trying to connect to a RDS farm through the RD Gateway.


"...To resolve this issue, locate the HTTP redirection setting and disable it:

1.In Server Manager, on the RD Gateway server, open Internet Information Services (IIS) Manager.
2.In the IIS navigation tree, expand the server and the sites, and then select Default Web Site.
3.In the middle pane (the settings area), double-click HTTP Redirect.
4.Clear the Redirect requests to this destination check box.


After completing this, single sign-on was working externally as well, but the question remained: “How can I enable the redirection?” I didn’t want to manually type in http://contoso.com/rdweb because I wanted to use http://contoso.com/ instead. After doing some research and getting help from my colleagues, I found that it could be done by just making a small change, detailed in the following steps.

To redirect HTTP:
1. Open IIS Manager.
2. Go to the RD Web Access website (by default, it’s the “Default Web Site”).
3. In the middle pane, click HTTP redirect.
4. Select the Redirect requests to this destination check box, and type the address for your website; for example: http://contoso.com/rdweb.
5. In the Redirect Behavior section, select the Only redirect requests to content in this directory (not subdirectories) check box.
6. Apply settings...."

For the complete blog post see:
http://blogs.msdn.com/b/rds/archive/2011/09/07/how-to-troubleshoot-logon-attempt-failed-messages-when-connecting-through-rd-gateway.aspx

Wednesday, September 7, 2011

Windows Server 2008 R2 stops responding when an application performs many I/O operations to a network share

A new hotfix has been released that might be interesting if you publish applications on a Remote Desktop Session Host 2008 R2 server that heavily use network shares.

Details, see below.

Article ID: 2582112 - Last Review: September 7, 2011 - Revision: 1.0
Windows 7 or Windows Server 2008 R2 stops responding when an application performs many I/O operations to a network share

Consider the following scenario. You use an application to access a network share from a computer that is running Windows 7 or Windows Server 2008 R2. The application performs many I/O operations to the network share. In this scenario, Windows may stop responding.
This issue occurs because of a new behavior of the Server Message Block (SMB) mini-redirector (mrxsmb.sys) in Windows 7 and in Windows Server 2008 R2.

In Windows 7 and Windows Server 2008 R2, a power request object is created and then destroyed for every SMB network file operation. When an application performs heavy I/O to the network share, many threads that read or write to the network share create many power request objects. Therefore, the Power service cannot process the power request objects as fast as they are generated.