310 likes | 459 Views
Windows for the Enterprise. Boris Ulík Technology Solutions Professional Microsoft Slovakia. Why Windows 8.1?. What’s new in Windows 8.1. UI enhancements. Platform enhancements. Start button Boot to desktop Start screen sync Multiple tile sizes Enhanced Search Reading List
E N D
Windows for the Enterprise • Boris UlíkTechnology Solutions ProfessionalMicrosoft Slovakia
What’s new in Windows 8.1 UI enhancements Platform enhancements Start button Boot to desktop Start screen sync Multiple tile sizes Enhanced Search Reading List Take calls from lock screen Flexible window sizes Multi-monitor improvements Improved built in apps (incl. Mail) Automatic app updates Improved touch keyboard 7-10” tablet support SkyDrive integration InstantGo devices MiraCast support Personal hotspot Assigned access (kiosk) Tap to print (NFC) Auto triggered VPN Device Encryption Improved fingerprint log in support Mobile device mgmt. (MDM) Remote business data removal
Enhanced Performance • Windows 8.1 – better than Windows 7 Faster boot times Newer Windows 8 certified PCs can boot up to 36% faster. Better battery life Users upgrading Windows 8 certified scan experience up to 13% longer battery life. Advanced security Windows 8 is 21 times less likely to be infected by malware than Windows XP, and 7 time less likely than Windows 7. Better overall performance Windows 8 uses fewer system resources, resulting in up to 22% less memory usage than Windows 7. Familiar desktop The desktop you're used to is still here and better than ever Longer Battery Life Less Memory Usage Faster Boot 13% 22% 36% Security Familiar Desktop
Staying with Windows XP is a bad idea Faster boot times Support for Windows XP ends April 8, 2014. Implications:Security risksCompatibility issuesNo one to callPotential down time Search your PC, web and SkyDrive from one location Office 365 Beautiful devices Skype call from lock screen Better performance Windows store and modern apps Faster Wi-Fi reconnection Improved task manager Easier and more powerful file explorer with ribbon UI Longer battery life Auto-triggered VPN
anywhere, anytime expectations BYOD goes mainstream enabling mobility critical for success changing security landscape
At home At work
Devices for Different Customer Needs All-in-Ones and Desktops For those who need power and style Tablets For those always out and about Two-in-Ones and Convertibles For the virtual mobile professional Laptops For the specialty user Example Customer Profiles: Sales representative Insurance or real estate agent Home repair/contractor Law enforcement Inflight crew Retail Example Customer Profiles: Executive Office worker Business Consultant Presenter/Speaker Shop owner Example Customer Profiles: Doctor/healthcare professional Manufacturing Delivery service Example Customer Profiles: Advertising agency Design shop Engineer/Software developer Financial services Office manager Home office
Windows 8.1 on ARM Outlook 2013 RT Support for 3rd party MDM solutions Workplace join and work folders Inbox 3rd party VPN clients
Windows 8.1 Editions OEM – PC Preinstalled Windows RT Windows 8.1 Windows 8.1 Pro Full Packaged Product (FPP) Windows 8.1 Windows 8.1 Pro Volume Licensing Windows 8.1 Pro Windows 8.1 Enterprise
Paths from Windows 8 to Windows 8.1 Free update through the Windows Store Windows 8 Windows 8.1 Windows 8 Pro Windows 8.1 Pro OEM/FPP Customers Free update through the Volume License Service Center (VLSC) No Active SA Windows 8.1 Pro Active SA Windows 8.1 Enterprise VL Customers
Microsoft Desktop Optimization Pack Virtualize Restore • Microsoft Application Virtualization (App-V) • Virtually any application, anywhere • Microsoft Diagnostics and Recovery Toolset (DaRT) • Restore user productivity quickly • Microsoft User Experience Virtualization(UE-V) • Change your device, keep your experience • Microsoft Enterprise Desktop Virtualization (MED-V) • Enable your Windows XP-based apps on Windows 7 Manage • Microsoft BitLocker Administration and Monitoring (MBAM) • Simplified BitLocker management • Microsoft Advanced Group Policy Management (AGPM) • Checkpoint your policy rollout, minimize downtime
Windows 8.1 Enterprise Enterprise Sideloading Start Screen Control Windows To Go DirectAccess BranchCache Virtual Desktop Infrastructure AppLocker • Deploy Windows 8 apps from outside of the Windows Store • Control Start screen configurations for different groups and roles using Group Policy • Create a corporate Windows 8.1 environment on a USB stick • Connected to corporate networks, seamlessly and more securely • Users in the branch office can download documents and apps faster • Improved end-user experience • Specify what software is allowed to run on a user's PCs
DirectAccess • Productivity • Transparent direct connection to corporate resources – no user interaction is required • Windows 8.1 / Windows Server 2012 R2 do not require: • Two consecutive public IPv4 addresses (DirectAccess servers can be deployed behind NAT device) • IPv6 deployed within internal corporate network (integrated NAT64 / DNS64) • PKI (certificates) deployed at the domain-joined computers (can employ Kerberos Proxy functionality) • Consider “computer-only” scenario • Windows 8.1 Devices with TPM chip can benefit from Virtual Smart Cards • Support for “Metered Internet Connections”
Windows To Go • Productivity • Windows 8.1 on Certified USB drive • USB 3.0, capable of 2 partitions at least (“Basic Disk”) • Supports various scenarios • VPN replacement, Vendors, BYOD, … • Secured with encryption (BitLocker) • Connected via VPN or DirectAccess • Managed by Group Policies, SCCM, Windows Intune • Applications can be installed or loaded via App-V
BranchCache • Productivity • Enables documents caching within subnets interconnected over unreliable WAN • Centralized / Distributed modes • Centralized mode requires Windows Server OS deployed on the local subnet • Centralized mode is configurable for Cache Preloading • GPO / Self-configuration of branch office computers • Support for SMB, HTTP, FTP
Virtual Desktop Infrastructure • Productivity • Software Assurance includes VDA license • Windows Server Remote Desktop Services scenarios: • Session based (Full desktop / RemoteApps) • Virtual Machine based (Personal Desktop / Desktop Pool) • Requires only HTTP(S) / RDP • Enables BYOD / Contingent staff / VPN replacement scenarios • RDP client with RemoteFX
App-V (MDOP) • Productivity • Enables virtualization of applications • Applications run within App-V agent as if locally installed • Ability to run different versions of the same software • Includes all components for various scenarios • From standalone deployment to full infrastructure (integrated with SCCM) • Ability to load and cache / pre-cache software to the client • Windows To Go / VDI (Desktop Pool) • Ability to track and manage license usage
UE-V (MDOP) • Productivity • Apps and OS personalization settings roam across Windows • Synchronization is smart – logins are fast • Based on GP configuration via Templates • Template Generator is included / Microsoft Gallery • Ability to roll back settings to initial state • Integrated with existing tools • Active Directory Group Policies, MDT, SCCM
Workplace Join • Productivity • Device enrollment • Device equipped with certificate – not managed, yet, not “unknown” • Leverage Windows Intune • Manage access to corporate data • Integrate with Work Folders • Support for iOS
Assigned Access • Productivity • Enables a single Windows Store app experience on the device • User only experiences the specified app • Unable to access system files and other apps • Windows Embedded 8.1 Industry • Broader set of device lockdown capabilities (ATM, etc.)
BitLocker & BitLocker to Go • Security • Available also in Windows 8(.1) Pro • Consider for Data Leakage / OS Integrity scenarios • Windows 8(.1) / Windows Server 2012 (R2) BitLocker enhancements: • Encryption of only “used” disk space • Network unlock capability • Employ TPM chip with PIN, whenever possible • BitLocker to Go protects removable media • Enforced via GPO
AppLocker • Security • Ability to deploy rules for using (and / or potentially installing) applications • Separate rules for Applications, Installers, and Scripts • Enables control Modern UI Apps from Microsoft Store as well • Support for “Application Whitelisting” scenarios within corporations • Ability to protect from Portable Applications • Managed via Group Policies
Other Improvements • Security • UEFI Trusted / Measured boot process • Early Loading of Anti-Malware (ELAM) • Windows Defender integrated with anti-virus capabilities • Picture Passwords • Virtual Smart Cards • Selective Wipe of Corporate Data
MBAM (MDOP) • Management • Simplifies the BitLocker provisioning process • Report on device encryption compliance and audit access to keys • Self-service Web Portal for users to recover devices • Users can initiate PIN resets and volume encryption tasks • MBAM prevents reuse of BitLocker recovery keys
DaRT (MDOP) • Management • Set of tools for Diagnostics and Recovery • Bootable WIM, ISO, USB • Transparent UEFI machine boot integration • Tools for troubleshooting • Memory scanning, Disk Scans, Antivirus analysis • Memory Dump “Reader” • Data Recovery from BitLocker Protected Drive
Other Improvements • Management • Support for 3rd party MDM solutions • Enterprise side-loading / SCCM Application Catalog • Booting from VHD(X)
Virtualize, Manage, Restore with MDOP Work from any device with more Flexible Licensing Unique access to Windows 8 Enterprise • Microsoft User Experience Virtualization (UE-V) • Change your device, keep your experience • Windows To Go • Run a corporate Windows 8 environment securely on a USB stick from anywhere • Windows To Go Use Rights • DirectAccess • Always connected to corporate networks, seamlessly and more securely • Microsoft Application Virtualization (App-V) • Virtually any application, anywhere • Virtualization Rights • BranchCache • Users in the branch office can download documents and apps faster • Microsoft BitLocker Administration and Monitoring (MBAM) • Simplified BitLocker management • Companion Device Licensing • Virtual Desktop Infrastructure (VDI) • Improved end-user experience • Microsoft Advanced Group Policy Management (AGPM) • Checkpoint your policy rollout, minimize downtime • AppLocker • Specify what software is allowed to run on a user's PCs • Enable BYOD Scenarios • Microsoft Diagnostics and Recovery Toolset (DaRT) • Restore user productivity quickly • Enterprise Side-load • Side-loading enabled for internal new Windows 8 apps SA foundation Use rights, Technology, Support • Microsoft Enterprise Desktop Virtualization (MED-V) • Enable your XP apps on Windows 7 Solid business foundation in Windows 8 Pro
Call to action Deploying Windows 7 today? Continue your deployment, bring in Windows 8 tablets side by side Target Windows touch devices for hardware refresh Consider Windows 8.1 Download and evaluate Windows 8.1 Start developing Windows apps for your business Evaluate Windows 8.1 tablets for all your tablet deployments Target Windows 8.1 for adoption across all PC form factors in your company