Translate

Wednesday, September 7, 2016

Updates needed to serve Windows 10 updates and upgrades with WSUS

I created a demo environment and thought it would be nice to use latest SCCM on latest Windows and guess what?  (SCCM Current Branch on Windows Server 2016 TP5)


You WILL FAIL!











Reason is you need to install a patch to WSUS to enable Windows 10 catalog.
But this patch is only available to Windows Server 2012 R2.
Not yet available to Windows Server 2016 TP5 (curious but that's the way it is)


So I installed another WSUS Server on Windows Server 2012 R2 latest patches stand alone. Then I enabled WSUS role.


But before you start configuring it. You must install at least these patches for 
Windows Server 2012 R2:
This Update enables the Win10 classification in the WSUS catalog
KB3095113

https://support.microsoft.com/en-us/kb/3095113
(also checkout note from WSUS team:
https://blogs.technet.microsoft.com/wsus/2015/12/03/important-update-for-wsus-4-0-kb-3095113/)

If you synced the catalog already and you missed the fix in the first place you need to read this for fixing it!https://blogs.technet.microsoft.com/wsus/2016/01/29/how-to-delete-upgrades-in-wsus/


This Update enables the ESD function. Without it you can not deploy 1607 or newer!
BE CAREFULL AND READ THE MANUAL STEPS NECESSARY!!!
https://support.microsoft.com/en-us/kb/3159706

This update also replaces the problematic fix KB3148812. If it is installed you can install the KB3159706 on top of it! But don't miss the manual steps!


HINT:
You get all the updates also through (you need to know the KB article number)
http://catalog.update.microsoft.com




Microsoft promised these steps are not necessary for WSUS on Windows Server 2016 RTM.


HAPPY UPDATING!



Wednesday, August 24, 2016

Virtualization based security (Device Guard, Credential Guard) vs. VMware Workstation

Recently a customer asked me what's about the coexistence of the new Microsoft security features like Credential Guard and Device Guard when you need to work with VMware Workstation where you have some VMs locally used for application compatibility where they run older OSes and they need specific interface types like COM Port or USB for their machine diagnostic software?


So the basic question is: Can virtualization based security in Windows 10 which uses Client Hyper-V underneath coexist with VMware Workstation?

When you need more to know about Credential Guard then check this here: https://technet.microsoft.com/itpro/windows/keep-secure/credential-guard


I took the question to MS an the clear answer currently is:
This is CURRENTLY not supported!  (as of Redstone 1 build release in 08/2016)
They are aware of this issue and looking to solve this in some point of time.


The main reason for this is that Client Hyper-V and VMware Workstation occupy exclusively the hardware virtualization extensions (like IOMMU or VT-X).
In this case nested virtualization does not work. For nested virtualization you find more info here:
https://msdn.microsoft.com/en-us/virtualization/hyperv_on_windows/user_guide/nesting

Also running other virtualization solutions like VirtualBox in a Hyper-V VM that supports nested virtualization is currently not supported!Some VMware Workstation users tried that recently as reported in forums and end up with bluescreens. Check out this here: https://communities.vmware.com/thread/528385?start=0&tstart=0

When you need VMs with older OSes regarding App Compat you have currently these options:

  1. Use Client Hyper-V for virtualization. And explore the improved interface mappings like COM-Port or USB port redirection.  To check out the new possibilities read this here:https://technet.microsoft.com/en-us/windows-server-docs/compute/hyper-v/learn-more/use-local-resources-on-hyper-v-virtual-machine-with-vmconnect
    for COM Port this may also help:
    https://blogs.technet.microsoft.com/jeff_stokes/2013/05/06/how-to-redirect-serial-ports-in-windows-server-2012-rdsvdi/
    or make use of Terminal server devices with physical com port redirection via TCP-IP like these here: http://www.fabulatech.com/serial-port-redirector.html  There are a couple different vendors available.

  2. A few other virtualization applications have an “emulator” mode.  This mode don’t require hardware virtualization extensions. But their performance is mostly really bad.
  3. Disable Credential Guard and Device Guard, and run a different virtualization technology.


So my recommendation is give Client Hyper-V another trial :-)
Hyper-V was further developed over the last years and is now really break even with VMware virtualization. In some points its even better :-)
 






Wednesday, August 17, 2016

Mobile Device Management - simplified joining options

With 1607 the options to join MDM while joining Active Directory or Azure AD where simplified a lot. So you do not need to check 2 different options anymore.


So best is to prepare your Azure AD with the right options first and enable auto MDM enrollment there.






See here:
https://blogs.technet.microsoft.com/enterprisemobility/2015/08/14/windows-10-azure-ad-and-microsoft-intune-automatic-mdm-enrollment-powered-by-the-cloud/




From a user perspective you you have now 4 major options described further here:


https://msdn.microsoft.com/en-us/library/windows/hardware/dn925028(v=vs.85).aspx


Options are so far:
Corporate owned - Active Dirctory
Corporate owned - Azure Active Directory
Private owned - Azure Active Directory
Independent - MDM using a deeplink

Thursday, July 14, 2016

Azure AD Connect: Synced attributes

I am asked from time to time what attributes are synced with Azure AD through Azure Active Directory Connect tool:


In general its just selected user, group and contact information.

Here you find a list of synced attributes:
https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsync-attributes-synchronized


Depending on Windows 10 features there are also a few machine attributes synced to Azure AD as well. This is necessary for specific scenarios like Passport for work and requires actual versions of Windows 10 build (build 10551 or newer) for devices:
https://azure.microsoft.com/en-us/documentation/articles/active-directory-azureadjoin-devices-group-policy/


Be carefull and dont think you know what you are doing by partially not syncing them. Depending on the services they are really necessary. E.g. Exchange onpremise stores a lot of informations in AD. So Exchange online do as well. Therefore these attributes are necessary for proper function.


Unless you are the developer of the cloud application like Exchange Online you are not the one to judge if an attribute is necessary for correct function or not.


So either you feel comfortable with the attributes or just dont use Azure AD at all. Everything else will just mess up the AAD information and the cloud applications will not work properly.


Azure AD also stores Bitlocker keys but only for Azure AD joined machines.
https://blogs.technet.microsoft.com/home_is_where_i_lay_my_head/2016/03/14/automatic-bitlocker-on-windows-10-during-azure-ad-join/



Sunday, June 12, 2016

Windows 10 privacy is always a reason for rumors - whats the fact?

Windows 10 privacy is often a discussion that I have with MS customers especially in Europe and there especially in Germany. Therefore I developed a workshop to discuss all the different settings which finally ends up in a 60 slides deck. But as it get outdated with every version I just use anymore the "online" version of information in the TechNet Blog.




In the last years the technology evolves and with this we have much more possibilities we can use these technologies.


E.g. lets think about Cortana. Cortana is a brilliant assistant. She can do amazing things. And each newer version can even more.


But to let Cortana doing these things you need to share informations so she can use them to serve you better.


Lets assume you want to get a reminder when you are on your way home to buy milk. In this case Cortana need to know when you are driving home (GPS data and also your typical way from your working place to your home address). Without these data she is not able to serve you the right information right in time.


That finally means an assistant can only be as usefull as possible when you share the needed amount of data so she can do their job.


This is not different to a physical assistent. Lets say her name is Mary. She can also only be as supportive as possible when I let her know the things she need to know to be able to do her job.


Microsoft changed their way now how they communicate these privacy settings. They are much more transparent as they were in the past.


Please checkout this technet article from time to time as it gets updated over time with new features as well: https://technet.microsoft.com/en-us/itpro/windows/manage/manage-connections-from-windows-operating-system-components-to-microsoft-services


There are also telemetry stages discussed. You find more Informations about them here:https://technet.microsoft.com/en-us/itpro/windows/manage/configure-windows-telemetry-in-your-organization


When you are through these articles you are very familiar which data is when shared for what purpose and how you can control it.


During my time working for MS labs I get in contact with the way how MS is dealing internally with customers privacy data. And believe me they take this very seriously. From this experience on I trust MS fully in the way how they handle privacy.

Wednesday, May 18, 2016

Advanced Threat Protection - brandnew feature in Windows 10 (Anniversary release 2016)

Microsoft responded to their customers requests regarding security threats and how to get hold on them especially when the breach already occured.


Antivirus tools we were used to use where yesterday. Now its ATP time!


This tool is really outstanding and uses unique techniques and possibilities that only Microsoft can do!




Please CLICK here to watch the video!
https://channel9.msdn.com/Events/Build/2016/B890


And to learn more and check it out you can sign up here:
https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp




ATP consists of 3 components:
1. The Client – end-point behavioral sensor, built into Windows 10 (Windows 10 Anniversary update, Windows Insider Preview Build number 14332 and later) and activated upon service enrollment. The client logs relevant security events and behaviors from the endpoint.     
2. Cloud security analytics service – processing data from endpoints in combination with historical data and Microsoft’s wide data repository to detect anomalous behaviors, adversary techniques and similarity to known attacks. The service runs on the Microsoft scalable big data platform, and uses a combination of Indicators of Attacks (IOAs), generic analytics and machine learning rules, as well as Indicators of Compromises (IOCs) collected from past attacks.
3. Microsoft and community intelligence – our Hunters and researchers investigate the data, finding new behavioral patterns and correlating the data with existing knowledge from the security community.

Windows 10 Update Assistant for failing upgrades from RTM to 1511

Recently MS released an update that let you update your system to the latest public release (1511) if your system is still on RTM and may not update automatically to the recent version due to errors in Windows Update.






Please chekcout this KB article therefore https://support.microsoft.com/en-us/kb/3159635


The update to 1511 is essential to receive the new Redstone release coming in few weeks!