Category: DaaS
Desktop as a Service – Design Decisions
Desktop as a Service – Design Decisions
Helpdesk, Self-Service, Billing and Account Management
- ConnectWise
- ManageEngine
- Citrix Cloud Service Portal
- emersion.com.au
- Xero
- https://web.cloudmore.com/
Session Layer
- Microsoft RDP
- This is a very cost effective options with allot of feature restrictions
- Citrix ICA
- This is a fully featured option, while its more expensive, the issues that will be faced with a pure RDP options will add to cost for support over time and anything other than the most basic small 10 man organisations will become a burden.
Flexcast Model
- Hosted shared non-persistent
Infrastructure Layer
- Build own Server Rack
- This is much too cumbersome to build, can use a single server for PoC and Testing/Dev
- AWS
- Run into Microsoft licensing issues on AWS, but has better advance networking features.
- Azure
- As Microsoft is the core product for Windows Desktop, this is the ideal voice.
- VMware based IaaS
Use DaaS Platforms
- Citrix Workspaces
- Can you this layer for the VPN / Dashboard access
- VMware Horizon DaaS
- Too restrictive,, when a complex customer requirement is required, this model wont allow for that..
- 3rd Party DaaS providers
- No way, i want to have complete ownership and flexibility and to reduce any middle men.
Session Isolation and Architecture
- Shared Delivery Group/Shared Delivery site isolation.
-
The Shared Delivery Group/Shared Delivery Site isolation model uses shared Delivery Groups for application and desktop workers between smallest tenants within the same shared delivery site. This model presents the lowest cost of service delivery to the CSP (and as should follow, to the tenants) with least security. (Other types;Private Delivery Site isolation / Private Delivery Group/Shared Delivery Site isolation)
-
Solution Result
- Use Azure to increase End-to-End Partnership with Microsoft.
- Utilise Microsoft products as much as possible and fully managed
- Use Citrix Workspace for entry / Dashboard access.
Network Design/Security Groups and vLANS
- DMZ
- Internet facing (SSL Port 443 only)
- First hop (Firewall/NetScaller/VPN/Proxy)
- Second hop (WebServer/Proxy
- Firewall to Internal
- Shared Session Servers vLAN
- Isolated Private Tenant AD, Site and Network
- Private AD
- Private SL
- Private Exchange
- Private AppServers
- Private File Servers
- Private SharePoint
- Azure AD Connect
- Application vLAN
- Management vLAN
- Active Directory
- ADFS
- Azure AD
- DNS/DHCP
- CERTs
- SQL
- CloudPortal Services Manager
- XenDesktopControllers
- StoreFront Servers
- License Servers
- NTP Server
- ITSM Server
- ConnectWise
- ManageEngine
- Chat/Ticket
- Security Applications
- Session Screen Recording
- Virus Protect
- Windows OS Endpoint protection
- Microsoft Antimalware for Azure Cloud Services.
- Email and Web Security
- MDM
- SIEM
- Storage vLAN
- Shared Internal SMB File Server
- Disk Storage
- Web Opensource Sharefile
Citrix Cloud
- Citrix Cloud is way too early and missing critical features and not secure.
- XenApp Service Only
- Smart Tools
- NetScaler Gateway Service
- Printing
- Security
- https://docs.citrix.com/en-us/citrix-cloud/overview/secure-deployment-guide-for-the-citrix-cloud-platform.html
- https://citrixcloud.uservoice.com/forums/255803-citrix-cloud/category/205519-xenapp-essentials
- 2FA/FMA??
- https://discussions.citrix.com/topic/387646-multi-factor-authentication/
- Citrix Cloud Services secure integration with Azure
- https://www.jasonsamuel.com/2018/01/23/how-to-extend-your-on-premises-xenapp-xendesktop-environment-to-citrix-cloud-xa-xd-service-and-microsoft-azure/
- https://docs.citrix.com/en-us/xenapp-and-xendesktop/service/secure.html
- ** SSL is not yet supported in Citrix Cloud for the StoreFront or NetScaler traffic, so Citrix recommends configuring firewall rules, VLANs, and/or IPsec tunnels for these services.
- What firewall rules is require to restrict access to Citrix Cloud IPs and any other secure design information.
Network Connectivity
- Private Direct Links and VMware SD-WAN or NetScaler SD-WAN (which ever has NTU)
Active Directory OU Design
- CPSM
- CSM_MGTM
- Tenant1(T)
- Tenant2(2)
Office 365
- Advanced Features
- Enhance Security
- Backup
- Archival
- Largefile
Azure Componets
https://azure.microsoft.com/en-au/services/#analytics
Azure Automation Build
- https://www.loginconsultants.com/en/news/all/item/base-image-script-framework-bis-f
- https://xenappblog.com/2015/automation-framework-3-0/
- https://github.com/citrix
- https://marketplace.visualstudio.com/items?itemName=CitrixDeveloper.CitrixDeveloperVisualStudioExtension
- https://youtu.be/Z52wet-18mA
- https://www.centric.eu/NL/Default/Craft/Blogs/2017/04/03/Deploy-Citrix-infrastructure-in-Azure-using-automation
- https://www.citrix.com/blogs/2018/04/10/citrix-tips-series-deploying-citrix-workloads-on-microsoft-azure/
- https://www.citrix.com/blogs/2018/06/07/automate-the-cloud-citrix-azure-mcs-powershell/
- https://www.christiaanbrinkhoff.com/2018/05/18/how-to-use-azure-quick-deploy-and-workspace-aggregation-for-citrix-cloud-xenapp-and-xendesktop-service-virtual-apps-and-desktops-deployments-in-azure/
Azure CSP, MSPLA and CSP licensing Options
- Microsoft Server VM
- Azure Subscription per user/per month
- Microsoft RDS
- Azure Subscription per user/per month
- BYO RDS MSPLA Server (invisible)
- Azure Citrix XenApp Essentials
- https://www.citrix.com/global-partners/microsoft/remote-app.html
- BYO/CSP (invisible)
- Azure Subscription per user/per month
- Cost Comparision
- $12.00 USD per user/month, NetScaler Gateway Service, 1 GB data transfer per user per month, 25 minimum user per month.
- $6.25 USD RDS
- Exchange USD = 1.33816 AUD
- Total $456.25 USD / $610.53 AUD
Citrix XenApp Base | 9.21 |
NetScaler Gateway | 2.86 |
RDS | 7.38 |
Citrix VM | 1.59 |
RDS | 1.59 |
NetScaler Gateway | 1.59 |
605.5 |
- Citrix NetScaler
- BYO/CSP (invisible)
- Azure Subscription per user/per month
- Cost Comparison
- Due to the minimum required of $610.53 per month this is not the ideal option to start and its also a service so not configurable So all BYO
Automation Frameworks
Automation Frameworks
- Base Image Script Framework – https://www.loginconsultants.com/en/news/all/item/base-image-script-framework-bis-f
- XenApp Automation Framework – http://xenappblog.com/2015/automation-framework-3-0/
3D Graphics for Virtual Desktops Smackdown
3D Graphics for Virtual Desktops Smackdown
Citrix Profile Management and Folder re-direction Configuration
Citrix Profile Management and Folder re-direction Configuration
- Folder Re-Direction Group Policy
- Exclude Policy
- Citrix UPM Install and Configuration
- Sync “AppData\Local\Microsoft\Windows\UsrClass.dat”
Reference
- UPM Checker – http://support.citrix.com/article/CTX132805
- Best Practice – http://support.citrix.com/article/ctx120285
- UPM Configuration – http://blogs.citrix.com/2012/02/11/citrix-profile-management-and-vdi-doing-it-right/
- IE Settings – http://blogs.citrix.com/2014/09/25/citrix-user-profile-manager-cookies-and-history-support-for-internet-explorer-10-11/?utm_source=dlvr.it&utm_medium=twitter
- UPM 5.x – http://support.citrix.com/proddocs/topic/user-profile-manager-5-x/upm-wrapper-kib.html
- UPM FAQ – http://support.citrix.com/servlet/KbServlet/download/19059-102-665944/ProfileMgtCrossPlatformFAQ.pdf
HowTo: Design a Secure Windows 2012 R2 Standard Operating Environment (SOE)
HowTo: Design a Secure Windows 2012 R2 Standard Operating Environment (SOE)
It does’t matter the size of your organisation or the compliance posture that it must adhere to. Every device on the network should be hardened and maintained. I worked for one of the largest IT companies in the world and it was the only company that had proper Windows Operating System hardening and Security Compliance Management. I also worked for a very large bank and the Security Team numbering in the 50+ just didn’t understand how develop a proper basis line for Security Compliance and copy and pasted information from another IT Vendor! What I am trying to say is . They are different levels of Security Experts..
So here is a basic Overview of how to create a Secure Windows 2012 R2 SOE. This method can be applied to any support OS.
Firstly, understand your security posture requirements:- I have listed a few here : http://virtualizationandstorage.wordpress.com/2013/02/21/compliance-information/
It is also important to understand SAN Critical Controls and Defeating Kill Chains.
This course is also a good starting point -SEC505: Securing Windows with the Critical Security Controls:- http://www.sans.org/course/securing-windows
Understand the Critical Security Controls – http://virtualizationandstorage.wordpress.com/2014/10/23/critical-security-controls-and-defeating-kill-chains/
Security Standards
These are the core Security Standards and vital information for Windows harderning
- NIST Check lists
- DIAG STIG
- IT Security Database
- Common Configuration Enumeration
- Microsoft Solutions Accelerators
- http://technet.microsoft.com/en-us/library/cc936627.aspx
- http://technet.microsoft.com/en-au/solutionaccelerators/dd229342.aspx
- Microsoft Security Compliance Manager – http://technet.microsoft.com/en-us/solutionaccelerators/cc835245.aspx
- Microsoft Solutions Accelerator Security baseline scans – http://technet.microsoft.com/en-us/library/jj898542.aspx
- Microsoft Baseline Configuration Analyzer – http://www.microsoft.com/en-au/download/details.aspx?id=16475
- Microsoft Best Practice Analyzer Role and SQL – http://www.microsoft.com/en-us/download/details.aspx?id=29302
- Microsoft Security Configuration Wizard
- SOX Settings
- United States Government Configuration Baseline (USGCB)
- Puppet CIS hardening
- CIS Benchmark
- Implement NIST OpenSCAP
The above website and tools can be used to develop the require base line for your environments.. The Microsoft Security Compliance manager is the starting point for this process. You can use this software to understand all the settings and then export them into a Group Policy that can be used to harden the Operating System. Once you have a policy setup, you need to maintain that posture using Desired State management and Continuous Monitoring
Desired State
- Using Group Policy is the best method to insure the settings are applied to all servers. You can also use System Center Configuration manager Desired State management and puppet to monitor and alert on these settings..
- Or yo could use some like http://www.deepfreeze.com.au/download.html
- The other Options for Application Servers is to use OS Streaming like Citrix PVS
- Microsoft Creating Steady States – http://technet.microsoft.com/en-us/library/gg176676(v=ws.10).aspx
Security Scanners
Once you have the base policy using the above methods, You need to run a two types of scanners on your base OS.. The first is to use a Security Scanner against your OS and make adjust as required.. The other one I recommend is to run a tool to check and update all your software on the base OS image.. Key tool to use is Nessus which can be configured to scan and alert on items for PCI compliance,etc..
The follow three tools are required to create a sold secure SOE: These tools are NIST Security Content Automation Protocol (SCAP 1.2) Validation approved tools.
- Microsoft Security Base Line Scanner – http://www.microsoft.com/en-au/download/details.aspx?id=7558
- Secunia Software Inspector
- Tripwire SecureCheq – https://www.tripwire.com/free-tools/securecheq/
- Nessus Scanner – http://www.tenable.com/tips/enabling-the-compliance-checks-with-nessus
- SureCheck
** you can not create a Secure hardened OS without a Security Scanner..
Implement OS Encryption
Implement Bootlocker
Bitlocker
Install Microsoft Enhanced Mitigation Experience Toolkit https://technet.microsoft.com/en-us/security/jj653751
Here is a link to my own SOE settings – http://virtualizationandstorage.wordpress.com/2014/01/16/windows-2012-r2-soe/
BREAKING TYPICAL WINDOWS HARDENING IMPLEMENTATIONS – https://www.trustedsec.com/blog/breaking-typical-windows-hardening-implementations/
Complexity of Application Presentation/Streaming and Distribution
Complexity of Application Presentation/Streaming and Distribution
I wanted to highlight and explain the complexity of designing Application Deployment and Management for Windows Desktops and VDI environments in a single diagram.
(opps, I mean Microsoft 🙂
Update 02/04/16 Adding a few Application Deployment Options
- Click Once Applications
- Container Applications (AppZerto)
- Application Layer (e.g. Citrix AppDisk.)
There are so many options for Application Deployment and they are all very complex and architecturally different and affects the user interaction with the application.
You can also have combination of these application deployment and management technologies. Example Citrix XenApp + AppV + SCCM.
The core problems is Usability, when you design such complex solutions its almost impossible to guarantee the same level of usability as a locally installed application which is what the end user is expecting.. (Example of usability – Copy/Pase, Print, Content sharing,etc)
Combining this with the complexity of User State and profile management options, it is no wonder many VDI projects fail and cause major frustrations for end users.
The key is to provide the same user functionality as locally installed application when using different technologies to deliver and manage applications and user environments. (Click here to find out how to solve this problem.)
Overview of Application Deployment and Management options
- Citrix XenApp Published Application (HDX Stream) + FlexCast Models
- Citrix VDI-in-a-BOX
- VMware ThinApp
- Microsoft RemoteApp (RDS Stream)
- App-V Application
- App-V and SCCM (App-V Local Interaction feature, Virtual Environment and Connection Groups)
- Application Deployment (Kace, LanDesk, Altris, SCCM)
- Locally Installed Application
[Update 07.11.2014] – I saw information on Cloudvolumes,com, when it was released, but, they didn’t release any information. Until VMware acquired them. I think this is the future of Application Deployment – VMWare AppVolumes. This essentially can solve this complexity. Al thought, how it handles, upgrades, conflicts,etc Needs to be tested. I can’t wait for Microsoft to come up with a similar solution. –
Since writing this article and doing some more research on VMWare AppVolumes and UniDesk. http://www.unidesk.com/software, could solve the problem of delivering applications and maintaining Microsoft and Application updates.
[youtube=https://www.youtube.com/watch?v=EwKHP4RQpNM]
User State Profile Management
- Microsoft UE-V
- Citrix Profile Management
- AppSense Profile Management
- MANProfiles, FlexKit, Folder Re-Direction,etc
- Citrix Personal vDisk
User/Application Interactions
- Copy/Paste
- Application Content Sharing
- mailto: and hyperlinks,etc
- File Sharing
- Application Plug-ins
FlexCast Models
- Hosted VDI- Assigned VDI Server OS (Windows Experience) (Persistent)
- Hosted Shared – Pooled VDI Server OS (Windows Experience) (Non-persistent)
- Streamed Desktops
- Hosted Blade PCs (VDI)
- Hosted VM-Based Desktops (VDI)
- Shared Published Desktop
- Remote PC
and of course Persistent vs Non- Persistent Desktops, Pooled vs Static,etc.. add to the complication and that is another topic.
I thought this was a relevant diagram on the subject.
Be careful Will Robinson, most Citrix pre-sales guru’s don’t understand this complexity. (yeah you!)
But, dont worry, I am building a DaaS platform to solve all of this..
Alternative Application Deployment options in order of preference:-
- UniDesk
- Microsoft App-V
- AppZero
- FsLogix
- cloudhouse.com
- VMware AppVolumes
- Microsoft Docker (Beta only)
- VMware ThinApp
- AppDNA
- http://www.cloudhouse.com/how-we-do-it/cloudhouse-applications-anywhere
Organizations with growing VDI environments find the tools used to deliver applications and updates to physical computers create significant issues when used for VDI. This research compares alternative approaches to software delivery to help organizations make the best choice for their environment. https://www.gartner.com/doc/2870717/selecting-right-application-delivery-model
So, now that we understand the issues, how do we solve the problem. Here is some technology that is absolutely required for any VDI deployment.
DaaS Build Phase
DaaS Build Phase
- Setup Proliant Server
- Install XenServer
- Setup XenServer GUI Appliance and Configure it to Autostart
-
[source language=”bash”]</li>
<li>Setup a Autostart vApp
Create a Autstart vApp and add VMS
Get uuid of vApp: xe appliance-list name-label="autostart"
edit rc.local:
echo "xe appliance-start uuid=869aabc7-5b30-b0bf-79cf-ca5acbb162be" >> /etc/rc.loca
xe vm-param-set uuid=29025d12-5148-9ed3-9e21-78c1fc35a44a other-config:auto_poweron=true
29025d12-5148-9ed3-9e21-78c1fc35a44a</li>
<li>[/source]
- Create Windows 2012 R2 DataCenter Template
- Install DC
- Install Management Server
- Install SQL Server in HA
- Install KMS and activate
- Install Windows Activation Tool – http://www.microsoft.com/en-au/download/details.aspx?id=11936
- Install Citrix Server
- Install Citrix License Server
- Install RDS Licenses
-
Install RDS License Role
-
Run RD licensingManager
-
Active Server Wizard
-
Install Licenses / Service Provider License Agreement / Windows 2012 / RDS Per User CAL /
-
User Corporate Enrolment Number
-
Setup RDS License GPO – Computer Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Licensing
-
- Install SQL Server 2012
- Build SCCM
- ConfigMgr 2012 R2 Prerequisites Installation Tool 1.3.0 – http://gallery.technet.microsoft.com/ConfigMgr-2012-R2-e52919cd
- Install SQL Server 2012 SP2 on the same server as SCCM, as SQL is free. SQLConfiguration.ini
- Pre-requisits
- Servers Accounts must be in Local Administrator Group
- Create a SQLAdmin Group and add it as the SQL Administrators
- Check Pre-requisites – start \E:\SMSSETUP\BIN\X64\prereqchk.exe /LOCAL
- Test Schema Extension .\ADSchemaExtensionConflictAnalyzer.ps1 –inputfile E:\SMSSETUP\BIN\X64\ConfigMgr_ad_schema.ldf –outputfile results.ldf
- http://technet.microsoft.com/en-us/library/gg712264.aspx
- Install WSUS via Windows Features
- Extend Schema *.ldf / \SMSSETUP\BIN\X64\extadsch.exe
- AD schema has now be extended, AD must be configured to allow
each ConfigMgr Site security rights to publish in each of their domains. - Create System Manager Container and give the SCCM computer object full permissions
- DSA.msc
- View Advanced Features
- Create new Container under System called System Manager
- Create a Group and add all SCCM Computer names it and add Full Permissions to this container
- Select Advanced and select this group Edit and Allow / This object and all descendant objects (Select All)
- Server Roles
- NET Framework 4.0
- Windows Server Features:
- .NET Framework 3.5.1 Features
- .NET Framework 3.5.1
- Background Intelligent Transfer Service (BITS)
- Add Required Role Services
- Remote Differential Compression
- Windows Role Services
- Web Server
- Common HTTP Features
- WebDAV publishing
- Application Development
- ASP.NET
- “Add Required Role Services”
- ASP
- Security
- Windows Authentication
- Management Tools
- IIS 6 WMI Compatibility
- Install Remote Differential Compression – Install-WindowsFeature Rdc
- Change the SQL Server(MSSQLSERVER) Logon with Domain Service Account
- Install Bits – install-windowsfeature BITS
- Create a Firewall Group Policy and Allow inbound rules for SQL Replication ports 1433 and 4022 (http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-84-45-metablogapi/5305.clip_5F00_image010_5F00_46C83E62.png)
- Install Windows ADK for Windows 8.1 – http://www.microsoft.com/en-us/download/details.aspx?id=39982
- NOT Installed – In Server Manager select Features, Add Features, Select .NET Framework 3.5, also select WCF Activation and when prompted answer Add Required Role Services click next and next again. (Make sure the BIT and IIS service is running/restart after install).
- Not installed – Set SQL Server Properties/General/Server Colation/SQL_Latin1_General_CP1_CI_AS
- http://technet.microsoft.com/en-us/library/ms175835.aspx
- http://msdn.microsoft.com/en-us/library/ms180175.aspx
- Not installed – Enable Bits – http://technet.microsoft.com/en-us/library/cc753227.aspx
- Download prerequisites – SMSSETUP\BIN\X64\SetupDL.exe <target dir>
- Add the SCCM Server domain computer account to local Administrators group of the SQL Server
- Setup SQL Properties/Memoy/ 50% of the Maximum memory and set MIN and MAX to same/static
- Add IIS 6 Management Compatibility Role
- IIS Configuration
- IIS \ Server \ Authentication \ Windows Authentication – Enable
- IIS \ Sites \ Default Web Site\ Add Authoring Rule – All content | All Users | Read | Local
- IIS \ Sites \ Default Web Site\ WebDAV Settings ????
- Reporting Services Configuration ???
- Change Server Collation SQL_Latin1_General_CP1_CI_AS (Run CMD as Administrator)
-
- Setup.exe /QUIET /ACTION=REBUILDDATABASE /SQLCOLLATION=SQL_Latin1_General_CP1_CI_AS /INSTANCENAME=MSSQLSERVER /SQLSYSADMINACCOUNTS=BUILTIN
\Administrators - http://technet.microsoft.com/en-us/library/ms179254(v=SQL.100).aspx
- Reattach existing database
- Setup.exe /QUIET /ACTION=REBUILDDATABASE /SQLCOLLATION=SQL_Latin1_General_CP1_CI_AS /INSTANCENAME=MSSQLSERVER /SQLSYSADMINACCOUNTS=BUILTIN
- Reference:
- http://sccmentor.wordpress.com/2014/01/08/sccm-2012-r2-step-by-step-installation-guide/
- http://www.david-obrien.net/2013/06/25/configmgr-2012-r2-step-by-step-installation/
- http://blogs.technet.com/b/uktechnet/archive/2013/04/10/guest-post-a-step-by-step-guide-to-system-center-2012-configuration-manager-with-sp1.aspx
- Checklist for Required Post Setup Configuration Tasks
- Checklist for Required Post Setup Configuration Tasks – http://technet.microsoft.com/en-au/library/bb633240.aspx
- Configure Sites and the Hierarchy in Configuration Manager – http://technet.microsoft.com/library/gg712682.aspx
- System Center Updates Publisher 2011 – Install – http://www.microsoft.com/en-us/download/details.aspx?id=11940
- Clients for Additional OS – http://www.microsoft.com/en-us/download/details.aspx?id=39360
- Install SP1
- Install App-V Integration and Clients
- Install Update Publisher
- Install WSUS
- Setup download schedule
- Desired Configuration Management (DCM)
- OSD + Integration with the Microsoft Deployment Toolkit (MDT)
- Configure Application Packages
- Tools
- Install RightClick Tools
- Client Center for Configuration Manager – https://sccmclictr.codeplex.com/
- Install System Center 2012 R2 Confiugration manager Toolkit – http://www.microsoft.com/en-au/download/details.aspx?id=36213
- Install System Center 2012 Configuration Manager Support Center – http://www.microsoft.com/en-us/download/details.aspx?id=42645
- Configuration Manager Trace Log Tool
- Install System Center Dashboard – http://www.microsoft.com/en-us/download/details.aspx?id=2753
- http://www.signatureconsultancy.com/smtrak.html
- Microsoft SQL Report Builder – http://www.microsoft.com/en-au/download/details.aspx?id=29072
- Install App-V Standalone
- http://stealthpuppy.com/app-v-faq-4-where-can-i-download-app-v/
- http://www.virtualizationadmin.com/articles-tutorials/application-virtualization-articles/app-v-basics-installing-and-configuring-app-v-5-infrastructure-part1.html
- https://www.youtube.com/watch?v=7MgFSv0P71s
- Setup Citrix Integration
- http://support.citrix.com/article/CTX126082
- https://www.youtube.com/watch?v=q_JpUP_fqYQ
- Components
- App V Report Server
- Run the Installed and install the Reporting Services on the SQL Server.
- App-V Management Server
- Download the software Microsoft Desktop Optimisation -E:\App-V\Installers\5.0\Server
- Prerequisites – http://technet.microsoft.com/en-us/library/jj713458.aspx
- Install Silverlight on the management Server
- http://www.netdavidic.com/2013/01/implementing-app-v-50-full.html
- Install the Web Server ISS Role on the Management Server
- Install Application Services Role and Net.3.5
- App-V Sequence Server
- SQL Server
- Client
- App V Report Server
- Build App-V and App-V Sequence
- Install App-V Remote Application Packager – http://www.microsoft.com/en-us/download/details.aspx?id=36216.
- Build XenApp RDS Host Template Server
- Configure KMS licenses for RDS and OSs
- Install Volume Activation Management Tool – http://www.microsoft.com/en-au/download/details.aspx?id=11936
- Activiate
- Setup DNS for KMS
- Configure Citrix License Server + Citrix Licensees
- Setup a Windows 8.1 and Windows 2012 OSD
- setup a isolated PXE boot environment and DHCP config – http://support.citrix.com/article/CTX115094
- MED-V
- MDOP
- Microsoft Assessment and Deployment Kit – http://www.microsoft.com/en-gb/download/details.aspx?id=39982[/embed]
- Citrix Profile Server
- Setup IPAM
- Test Federated Access
- Monitoring
- Setup Puppet Server
- Setup Nessus
- Setup Splunk Server
- Setup WireShark
- OpenVMS
- Snort
- Wireshark
- HP Isight Manager for Linux – https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPSIM-Linux-7.x
- HP Version Control Repository Manager – HP Version Control Repository Manager (VCRM)
- HP Service Pack for ProLiant (SPP) Version 2014.02.0 – http://h17007.www1.hp.com/us/en/enterprise/servers/products/service_pack/spp/index.aspx
- HP Supplement – ftp://ftp.hp.com/pub/softlib2/software1/supportpack-windows/p1072349968/v79572
- ManageEngine Free Monitoring – http://www.manageengine.com/free-xenserver-health-monitor/free-xenserver-health-monitor-index.html
- Install Microsoft Best Practice Analyser
- Install Microsoft Software Inventory Analyser (MSIA) and Asset Inventory Service
- Microsoft Baseline Security Analyser
- Citrix License Reporting Tool
- Deploy Remote Server Administration Tools on Management Server
- Install Windows PowerShell Web Access on Management Server
- Windows Assessment Services
- Best Pratice Analysers
- XenServer Backup – http://www.quadricsoftware.com/alike/Free.php#requirements-tab
- PKI Infrastructure
- XenServer Orchestra – https://xen-orchestra.com/
- GPO Configurations
- Windows Defender and Active Protection Services – http://technet.microsoft.com/en-us/library/jj618314.aspx
- Configure Desktop Experience in Windows Server 2012 R2
- Setup PVS Server
- Configure BSMh
- http://blogs.citrix.com/2010/04/13/three-steps-to-a-pxe-free-xendesktop-on-hyper-v/
- http://support.citrix.com/proddocs/topic/provisioning-61/pvs-boot-devices-utility.html
- Configure BSMh
- Setup Sophos Virus Protection
- Update exclusions for Citrix, SQL, Clustering
- Install Microsoft Malicious Software Removal – http://www.microsoft.com/en-gb/download/malicious-software-removal-tool-details.aspx[/embed]
- Microsoft Saftey Scanner – http://www.microsoft.com/security/scanner/en-us/default.aspx[/embed
- Setup Management Server
-
- Window Server Essentials Experience
- User Access Logging
- Windows Inventory Logging
- Windows System Resource Manager
- Configure Printer Servers
- Application Server
- Setup Desktop Template
- Windows Desktop Experience Configuration
- Adds the Desktop Experience and XPS Viewer features to the Windows server configuration
- Moves the Citrix folder items in the Start menu to the Administrative Tools folder (including the Citrix AppCenter)
- Creates a new Windows Theme file and sets the default wallpaper
- Starts the Windows Themes service and configures it to start automatically
- Configure Citrix CloudPortal and vWorkspaces
- http://blogs.citrix.com/2014/06/26/automated-install-of-xendesktop-7-5-on-cloudplatform/#comment-146741
- Billing System
- Self-Services Website
- Manager Engine Self-Services
- Setup Puppet and Desired State Manager
- Setup Desired State Pull/Push – http://foxdeploy.com/2014/03/10/desired-state-configuration-what-it-is-and-why-you-should-care/
- Active Directory
- Enable Active Directory Recycling Bin
- Setup GPO Backup and System State
Microsoft SPLA licensing for Windows 8
Microsoft SPLA licensing for Windows 8
update – http://www.itnews.com.au/News/397582,microsoft-allows-per-user-volume-licensing-of-windows.aspx#ixzz3IG3TsLeT
This is a subject that is always a discussion in almost all DaaS opportunities. Can a Microsoft MSP provide Windows 8 OS. The quick Answer is NO. Microsoft MSP/ SPLA licensing only covers Windows SERVER Operating Systems. (I won’t go into the all the different FlexCast models here and stick with providing a dedicated OS for users.)
However, there is a way a Microsoft MSP can provide Windows 8. Here is a quick guide:
- Customer and Microsoft MSP must sign up for License Mobility Through Software Assurance. Volume Licensing customers can license their server applications on-premises and in the cloud on a qualified service provider’s shared hardware environment for specific applications. https://www.microsoft.com/licensing/software-assurance/license-mobility.aspx
- Customer must purchase all Windows 8 OS Licenses.
- Customer must purchase all Virtual Desktop Access licenses. (If the client devices aren’t PCs covered by [Software Assurance].
- Windows Virtual Desktop Access (VDA) is an authorization strategy that requires each device seeking access to a Windows virtual desktop in a virtual desktop infrastructure (VDI) to be licensed.
- Windows Virtual Desktop Access (Windows VDA): A standard benefit of Software Assurance and a stand-alone subscription-based license which allows roaming access to Windows virtual machines (VMs) from thin clients, third party, and non-Windows-based devices.
- The goal of Windows Virtual Desktop Access is to simplify licensing requirements in a virtual environment by licensing the devices that seek access to virtual desktops, instead of licensing the virtual desktops themselves.
- Because VDA is included as a feature of Software Assurance (SA), primary users of devices covered by SA can access their virtual desktops at no extra charge. Microsoft defines a primary user as someone who has used the computing device for more than 50% of the time in a 90 day period.
- If the user wishes to access a Microsoft VDI from a device that is not covered by Software Assurance, however, a separate Windows VDA license is required. Such devices include thin clients, zero clients and third-party devices such as contractor-owned PCs. As of this writing, a separate VDA license costs $100 per year, per device.
- Licensing_Windows_Desktop_OS_for_Virtual_Machines
- Providing Microsoft Desktop as a Service licensing guide
- More info :- http://splalicensing.com/tag/rds/
- Transfer these licenses to the Service Provider: [Detailed steps]
- The Microsoft MSP must provide the Windows 8 OS on DEDICATED hardware and not shared infrastructure with any other customer. Which cannot be used to provide any kind of service to any other customer of the service provider. Microsoft advise the dedicated-hardware requirement applied to all of the hardware utilised to provide the solution to the customer: servers, storage and, presumably, switching infrastructure as well.
- Windows 8 can be used for Rental Desktops can not be used either. Remote access. Rental Rights do not allow for remote access to software. Microsoft Rental Rights are a simple way for companies to rent, lease, or outsource desktop PCs with Windows desktop operating system and Microsoft Office licenses to third parties (such as Internet cafés, hotel and airport kiosks, business service centers, and office equipment leasing companies) through a one-time license transaction valid for the term of the underlying software license or life of the PC. Solidify your role as trusted advisor by helping your customers be in compliance, by using an additive license that fits their business model—without requiring special tools, processes, reporting, or paperwork.
Definition of Severity Levels
Definition of Severity Levels
Severity Definitions are intended to provide guidance on correct assignment of severity levels in the event of an incident.
- Sev 1 The product, service or channel is unavailable or unusable with NO planned and agreed sustainable workaround
The problem may be directly impacting either:
· External customers’ ability to interact with the customer
· Customers’s ability to service its customers
· The Business unit’s production workflow
The product, service or channel must be classified as business critical (eg it needs to be available within 24 hours of a disaster)
- Sev 2 The product, service or channel is available however functions are restricted or degraded
Significant exposure may exist. Business can continue to operate at a reduced capacity while the problem exists.
- Sev 3 The product, service or channel is available with no immediate impact to external or internal customers
Acceptable workaround is in place. The business can continue to operate at full or close to full capacity while the problem exists.
1. CIO Override – a vulnerability that poses a serious threat to the Customer, is wormable (i.e. Sasser
Virus) and code is in the wild and available to hackers. 247 to put this on the environment.
2. Critical – a vulnerability that poses a serious threat to , is typically wormable (i.e. Sasser Virus),
however code is not in wild as yet. Normal business hours to deploy this on the environment.
3. Important – vulnerability that poses a threat to is typically vulnerability that needs to be initiated
within and is local to the workstation. Normal business hours to deploy this on the environment.
4. Moderate – a minor vulnerability may pose a threat to . Usually patched to keep the platform
current. This type of patch will only be deployed if is deploying other hot fixes, otherwise it is deployed in the next Enterprise release.