sessiontitletimeslot fdn02enabling enterprise mobility with windows intune, microsoft azure, and...

28

Upload: shona-horn

Post on 18-Jan-2016

223 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,
Page 2: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

What’s New with OSD in ConfigMgr & MDTAaron CzechowskiSr Program Manager, Microsoft@AaronCzechowski

PCIT-B340

#tena14osd

Page 3: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Microsoft Deployment Toolkit (MDT)

Page 4: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

MDT 2013 OverviewReleased in October 2013• Installer, release notes, documentation

New support• Windows ADK for Windows 8.1• Windows 8.1 & Windows Server 2012 R2• System Center 2012 R2 Configuration Manager

Retired support• Windows XP & Windows Server 2003• Windows Vista & Windows Server 2008• System Center Configuration Manager 2007• System Center 2012 Configuration Manager SP1

MDT

Page 5: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Version ComparisonMDT

Windows 8.1 ADK

Windows 8.1Windows 8Windows 7

ConfigMgr 2012 R2

Windows 7 AIK

Windows 7Windows VistaWindows XP

ConfigMgr 2007

MDT 2013 MDT 2012 Update 1

Windows 8 ADK

Windows 8Windows 7Windows Vista

ConfigMgr 2012 SP1

Page 6: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

MDT 2013 Known IssuesRelease Notes• Compiled HTML help files • GPO Packs• Check for Updates• ZTI Server task sequence template fails on UEFI system – fixed in 2012 R2 CU1• Configure ADDS• OOBE settings missing from Windows 8.1 Unattend.xml

Other Issues• Windows 8.1 Start screen tiles missing – fixed in 8.1 Update, see KB2947485• OS Condition includes Windows XP and not Windows 8.1

MDT

Page 7: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Work in ProgressAccessibility• VPAT published to Microsoft 508 site • Testing underway, phased approach

Documentation to TechNet• Migration underway, publication date TBD• Retiring in-product CHMs & downloadable DOCX• Future offline documentation plan under consideration

Support Lifecycle• KB2872000• Sustained engineering plan• Bugs and feedback (DCRs) to Connect site

MDT

Page 8: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Windows 8.1 UpdateRevised ADK: recommended, not requiredAfter upgrading:• USMT: need to update the deployment share to refresh the content• WinPE: do not need to update the deployment share• Windows PE 5.1 not included, but not needed or supported by MDT 2013• Get latest full install source (aka refresh or slipstreamed media)

Windows 8.1 Update Servicing• Do not add to Packages node of deployment share, can’t guarantee ordering• Install as Applications to ensure proper ordering in task sequence (especially with

language packs)• Apply updates manually via DISM /Add-Package• Get latest full install source (aka refresh or slipstreamed media)

WIMBoot• Not supported by MDT today• Results of Michael Niehaus’ experimentation on his personal blog

MDT

See full details on MSDeployment

blog

Page 9: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Configuration Manager OS Deployment (OSD)

Page 10: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

What’s New in R2 OSDWindows 8.1 & Windows Server 2012 R2Windows ADK for Windows 8.1Windows PE 3.1Virtual Hard DisksNew Task Sequence Steps

OSD

Page 11: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

OSD

Page 12: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Virtual Hard DisksScenarios• Task sequence validation• Datacenter integration

Create VHD• Hyper-V required with ConfigMgr console• New task sequence template

Modify VHD• Schedule updates (offline servicing)• Add new applications

Upload to VMM

OSD

Page 13: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Demo

Virtual Hard Disks

Page 14: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

New Task Sequence StepsOSD

Check Readiness(MDT: Validate)

Prevent late failuresPrevent bad targeting

Run PowerShell Script(MDT: Run PowerShell Script)

Run .ps1Set execution policy

Set Dynamic Variables(MDT: Gather)

Dynamic task sequenceConditional rulesGathered variables

_SMSTSMake_SMSTSModel_SMSTSMacAddresses_SMSTSIPAddresses_SMSTSDefaultGateways_SMSTSSerialNumber_SMSTSAssetTag_SMSTSUUID

Page 15: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Demo

New Task Sequence Steps

Page 16: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

R2 OSD Known IssuesRelease Notes• Multicast-enabled DPs stop working after upgrade• Windows 8.1 AppX cleanup maintenance task and Sysprep

Fixed in Cumulative Update 1 (KB2938441)• KB2905002: WDS stops working on PXE Service Point• KB2905002: Slow content download• KB2907591: Computer variables are filtered from policy• KB2910552: Bootsect error with WinPE 3.1 to WinXP• KB2928122: Stand-alone media, application content appears multiple times in the

client cache• USB ‘fixed’ disk as media• Sorting of software updates for offline servicing, optional components for boot image• …and more!

Under Investigation• Task sequence fails if software updates require multiple restarts (see KB2894518)

OSD

This update is intended to correct only the problems that are described in the support article. Apply this update only to systems that are experiencing the problems described in the article. This update might receive additional testing. Therefore, if you are not severely affected by these problems, we recommend that you wait for the next service pack that contains this update.

CU Note

Page 17: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Upgrading to Windows 8.1Upgrade Scenario• In-place upgrade of Windows (setup.exe)• Preserve applications, user data and settings• Fast: 20-30 minutes on average• “Bulletproof” rollback on failure to functional downlevel system

Microsoft IT Proof of Concept• Addition of new /auto:upgrade switch for Windows 8.1 setup• Deploy Windows 8.1 setup.exe as a Configuration Manager application• No task sequence, let ConfigMgr client recover afterwards• Wildly successful: 80,000 clients, 97% success, 48% help desk reduction

IT Showcase• Quick Reference Guide: Moving from Windows 8 to Windows 8.1 at Microsoft• Technical whitepaper: High-Volume Windows 8.1 Update

OSD

Page 18: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Upgrading to Windows 8.1Constraints, Caveats & Risks• System Center 2012 R2 Configuration Manager only (client recovery)• Downlevel Windows 8 to uplevel Windows 8.1 Update• Multiple languages increases already large content, requires carefully planned

distribution• Best to use device-targeted, available deployments via Software Center• Company Portal/Application Catalog: better user experience but additional

complexities• Simultaneous deployment to a large population can cause performance issues• Multi-site hierarchy with roaming clients: complex, greater risk of problems (such as

replication)• Client policy evaluation: increase from default seven days to one day• Admin experience: initial invalid state, client will eventually resolve• Cloud DPs, HTTPS may be problematic

Recommendations• Refresh (wipe and load) remains primary OS deployment scenario today• Future investigations for better upgrade capability• Carefully consider upgrade, and then test, test, test

OSD

Page 19: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Windows 8.1 UpdateRevised ADK: recommended, not requiredAfter upgrading:• USMT: need to update the default package to refresh the content• WinPE: do not need to update the boot images• Windows PE 5.1 not included, but not needed or supported by Configuration Manager• Get latest full install source (aka refresh or slipstreamed media)

Windows 8.1 Update Servicing• System Center 2012 R2 offline servicing can’t guarantee ordering, so process

individually• Install as Packages to ensure proper ordering in task sequence (especially with

language packs)• Apply updates manually via DISM /Add-Package• Get latest full install source (aka refresh or slipstreamed media)

WIMBoot• Not supported by Configuration Manager today

See full details on ConfigMgrTeam

blog

OSD

Page 20: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Windows XP End Of LifeScenarios

Resources• How to migrate user data from Windows XP to Windows 8.1 with System Center 2012

R2 Configuration Manager (ConfigMgrTeam blog)• Migrating from Windows XP to Windows 8.1 using MDT 2013 (MNiehaus blog)

Refresh/Replace to Windows 8.1

Refresh/Replace to Windows 8,upgrade to Windows 8.1

Refresh/Replace to Windows 7

Page 21: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Related contentSession Title Timeslot

FDN02 Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows Server

Monday, May 12 11:00 AM - 12:00 PM

PCIT-B212 Design Considerations for BYOD Tuesday, May 13 10:15 AM - 11:30 AM

PCIT-B213 Access Control in BYOD and Directory Integration in a Hybrid Identity Infrastructure

Wednesday, May 14 3:15 PM - 4:30 PM

PCIT-B310 Empowering Your Users and Protecting Your Corporate Data Monday, May 12 1:15 PM - 2:30 PM

PCIT-B313 Hybrid Identity: Extending Active Directory to the Cloud Monday, May 12 4:45 PM - 6:00 PM

PCIT-B314 Understanding Microsoft’s BYOD Strategy and an Introduction to New Capabilities in Windows Server 2012 R2

Tuesday, May 13 8:30 AM - 9:45 AM

PCIT-B321 Deploying the New RMS for Cloud-Friendly and Cloud-Reluctant Customers Tuesday, May 13 5:00 PM - 6:15 PM

PCIT-B322 Deploying and Managing Work Folders Wednesday, May 14 10:15 AM - 11:30 AM

PCIT-B324 How to Rapidly Design and Deploy an Active Directory Federation Services Farm: The Do's and the Don'ts

Wednesday, May 14 8:30 AM - 9:45 AM

PCIT-B326 Providing SaaS Single Sign-on with Microsoft Azure Active Directory Thursday, May 15 10:15 AM - 11:30 AM

PCIT-B327 Introducing Web Application Proxy in Windows Server 2012 R2: Enable Work from Anywhere

Wednesday, May 14 3:15 PM - 4:30 PM

PCIT-B328 Microsoft Identity Manager vNext Overview Wednesday, May 14 5:00 PM - 6:15 PM

PCIT-B330 Active Directory + BYOD = Peace of Mind Thursday, May 15 8:30 AM - 9:45 AM

Page 22: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Breakout Sessions

Related content

Code Title Time

FDN02 Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows Server Mon, May 12 11:00 AM

PCIT-B311 What's New in Enterprise Management with Microsoft System Center Configuration Manager and Windows Intune Mon, May 12 1:15 PM

PCIT-B215

What's New in Microsoft System Center 2012 R2 Configuration Manager Infrastructure Mon, May 12 3:00 PM

PCIT-B410

Microsoft System Center 2012 Configuration Manager: MVP Experts Panel Mon, May 12 4:45 PM

PCIT-B216 Infrastructure Deployment for Mobile Device Management with Microsoft System Center Configuration Manager and Windows Intune

Tue, May 13 8:30 AM

PCIT-B317 Enrollment and Management of Mobile Devices with Microsoft System Center Configuration Manager and Windows Intune

Tue, May 13 1:30 PM

PCIT-B320 Microsoft System Center Configuration Manager Community Jewels Tue, May 13 5:00 PM

PCIT-B323 Application Management with Microsoft System Center Configuration Manager and Windows Intune Wed, May 14 8:30 AM

PCIT-B325 Protecting Your Corporate Data with Microsoft System Center Configuration Manager and Windows Intune Wed, May 14 10:15 AM

PCIT-B336 Managing Mac OS X Clients and Linux Servers Using Microsoft System Center Configuration Manager Thu May 15 8:30 AM

PCIT-B339 How Microsoft IT Manages Their Microsoft System Center Configuration Manager Application Lifecycle with Zero Touch

Thu, May 15 10:15 AM

PCIT-B333 How Microsoft IT Solves BYOD Using Microsoft System Center 2012 R2 Configuration Manager and Windows Intune

Thu, May 15 1:00 PM

Page 23: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Related contentInstructor Led Labs

Code Title Time

PCIT-IL200 Introduction to Microsoft System Center 2012 R2 Configuration Manager Mon, May 12 3:00 PMWed, May 14 5:00 PM

PCIT-IL201 Upgrading from Configuration Manager 2012 SP1 to Microsoft System Center 2012 R2 Configuration Manager

Thu, May 15 10:15 AM

PCIT-IL300

Deploying Windows 8.1 to Bare Metal Clients Wed, May 14 1:30 PMThu, May 15 1:00 PM

PCIT-IL305 Basic Software Distribution with Microsoft System Center 2012 R2 Configuration Manager Tue, May 13 5:00 PMWed, May 14 3:15 PM

PCIT-IL306 Implementing Endpoint Protection in Microsoft System Center 2012 R2 Configuration Manager Tue, May 13 10:15 AMThu, May 15 8:30 AM

PCIT-IL307 Managing Microsoft Software Updates in Microsoft System Center 2012 R2 Configuration Manager Tue, May 13 1:30 PMWed, May 14 8:30 AM

PCIT-IL308 Migrating from Configuration Manager 2007 to Microsoft System Center 2012 R2 Configuration Manager

Wed, May 14 10:15 AM

Page 24: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Related contentHands On Labs

Code Title

PCIT-H302 Deploying a Microsoft System Center 2012 R2 Configuration Manager Hierarchy

PCIT-H303 Deploying Microsoft System Center 2012 R2 Configuration Manager

PCIT-H304

Deploying Windows 8.1 to Bare Metal Clients

PCIT-H309 Implementing App-V 5.0 in Microsoft System Center 2012 R2 Configuration Manager

PCIT-H310 Implementing Endpoint Protection in Microsoft System Center 2012 R2 Configuration Manager

PCIT-H311 Implementing Linux Clients in Microsoft System Center 2012 R2 Configuration Manager

PCIT-H312 Implementing Role-Based Administration in Microsoft System Center 2012 R2 Configuration Manager

PCIT-H314 Managing Clients with Microsoft System Center 2012 R2 Configuration Manager

PCIT-H315 Managing Content in Microsoft System Center 2012 R2 Configuration Manager

PCIT-H316 Managing Software Updates in Microsoft System Center 2012 R2 Configuration Manager

Page 25: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Resources

Learning

Microsoft Certification & Training Resources

www.microsoft.com/learning

msdn

Resources for Developers

http://microsoft.com/msdn

TechNet

Resources for IT Professionals

http://microsoft.com/technet

Sessions on Demand

http://channel9.msdn.com/Events/TechEd

Page 26: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Complete an evaluation and enter to win!

Page 27: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

Evaluate this session

Scan this QR code to evaluate this session.

Page 28: SessionTitleTimeslot FDN02Enabling Enterprise Mobility with Windows Intune, Microsoft Azure, and Windows ServerMonday,

© 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.