SlideShare a Scribd company logo
Migrating Windows XP to Windows 7: Get it done using Microsoft Deployment ToolsHarold WongIT Pro Evangelist Microsoft Corporationblogs.technet.com/haroldwong
Event Schedule8:30am – Introduction and Welcome8:45am –Session 1: Migrating Windows XP to Windows 7:         Get it done using Microsoft Deployment Tools9:40 – Break 9:55 –Session 2: Securing Windows 7 in a Windows Server 2008 R2 Environment10:40 – Break 10:55 –Session 3: New Features in Windows Server 2008 R2 Directory Services– Drawing Afternoon MSDN will be here so stick around if you can 
Migrating Windows XP to Windows 7:
AgendaWindows Easy TransferDeployment ToolsUsing USMT Hard-link MigrationSummary of Deployment Solutions
Windows Easy TransferEasily Move Files and SettingsSupports Windows 2000, Windows XP and Windows VistaTransfer done with:CableUSB DriveBetween Computers in a Network
DemoWindows Easy Transfer
Deployment ToolsAutomated Installation Toolkit (AIK)User State Migration Tool (USMT)Microsoft Deployment Toolkit (MDT 2010)
Automated Installation Toolkit (AIK)Windows System Image Manager (WSIM)ImageXDeployment Image Servicing and Management (DISM) Windows Preinstallation Environment (WinPE) User State Migration Tool (USMT)
User State Migration ToolMigrates Files and SettingsComputer Replacement and Computer Refresh MigrationsScriptableHard-Link Migration StoreBenefits and Limitations
Microsoft Deployment Toolkit 2010Unified tools and processes Reduced deployment time“Lite-touch” deployments leveraging Windows deployment tools“Zero-touch” deployments leveraging System Center Configuration Manager 2007 and Windows deployment tools. Support for Windows 7, Windows Server R2.
“Lite-Touch” High-Volume DeploymentClient Migration Store – AIK and USMTConnected to WORKGROUPSource ComputerRun ScanStateand copies user state to shared folder on Windows 7 ClientDestination ComputerRunLoadStateon new Windows 7 platform and restores Windows XP user state from shared folder on Windows 7 ClientDestination ComputerRunLoadStateon new Widows 7 platform and restores Windows Vista user state from shared folder on Windows 7 ClientSource ComputerRun ScanStateand copies user state to shared folder on Windows 7 Client
Demo“Lite-Touch” High-Volume Deployment using the User State Migration Tool’s (USMT) Scanstate and Loadstate
“Zero-Touch” High-Volume DeploymentMigration Store ServerDecommissionDestination ComputerUse Log-on Script, batch file or non-Microsoft technology to run LoadStateon new Windows 7 platform and restores Windows XP user state from serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network serverDestination ComputerUse Log-on Script, batch file or non-Microsoft technology to runLoadStateon new Windows 7 platform and restores Windows Vista user state from serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network server
Summary of Deployment SolutionsSlide 14
SummaryMany Deployment Tools and options for all scenarios from a single PC to 1,000sEasy Transfer makes it simple to move user dataNew Hard-link Migration Option in USMT
TechNet Plus Direct SubscriptionThe ultimate resource for IT professionals. TechNet Plus provides convenient access to full-version Microsoft evaluation software—without time limits! The annual subscription also includes Professional Support incidents, a technical information library, and many other resources for evaluating, deploying, and maintaining Microsoft software.Microsoft software licensed for evaluation purposes.Beta software. Professional Support Incidents.Managed Newsgroup Support. Technical resources for Microsoft products.. Microsoft eLearning courses.Online Concierge Chat. Want a 25% Discount on a new Subscription?Use Discount Code TMSAM04
IT Pro Momentum InvitationA Microsoft program focused on supporting “early adopters” – IT professionals who bet on the newest technologies to drive business value for their companies and advance in their careers Are you?Interested in learning more about the newest Microsoft technologies?Need help to evaluate different Microsoft products and features? Willing to test and pilot in production Microsoft beta products?Would like to have access to exclusive forums and Microsoft product support?Want to share your early adoption experience with the IT Pro community world-wide?If you answered ‘yes’ for all the questions above, IT Pro Momentum can help!Send email with “Add to Momentum” in the subjectHarold.wong@microsoft.com
Momentum 2009 Products
Resources for Windows 7 DeploymentWindows 7 Deployment Guidehttp://technet.microsoft.com/en-us/library/dd349337(WS.10).aspxMicrosoft Deployment Toolkit 2010https://connect.microsoft.com/content/content.aspx?ContentID=12463&SiteID=14
Break Time:  15 minutes
Securing Windows® 7 in a Windows Server® 2008 R2 Environment
What Will We Cover?Better TogetherUser Interface ImprovementsDirectAccess and Terminal Services GatewayHealth Policies
AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
Business and Technical BenefitsReduce the risk of network security threats
Business and Technical BenefitsReduce the risk of network security threatsSafeguard sensitive data and intellectual property
Business and Technical BenefitsReduce the risk of network security threatsSafeguard sensitive data and intellectual propertyExtend the value of existing investments
RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV1DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSClient requests access to network and presents current health state1
RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV12DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSDHCP, VPN or Switch/Router relays health status to Microsoft Network Policy Server (RADIUS)2
RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSNetwork Policy Server (NPS) validates against IT-defined health policy3
RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312Not policy compliant4DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSIf not policy compliant, client is put in a restricted VLAN and given access to fix up resources to download patches, configurations, signatures (Repeat 1-4)4
RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312Not policy compliant4DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSPolicy compliant5If policy compliant, client is granted full access to corporate network5
Demonstration: Configuring NAPConfigure PKI
Install NAP
Configure BasicsAgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
NPS UpdatesNPS TemplatesNetwork Policy ServerLogging ImprovementsUTF-8
AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
Multiple SHV PolicyA single server can now enforce a number of different health policies using a single system health validator (SHV)Requires SHV updates for Windows Server 2008 R2
New NAP Client User InterfaceMessaging Integration with Action Center Tray IconIntegration with Windows 7 Action Center
AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
Integration ImprovementsRemote Desktop GatewayMicrosoft Confidential
Integration ImprovementsRemote Desktop GatewayDirectAccessMicrosoft Confidential
Integration ImprovementsRemote Desktop GatewayDirectAccessMicrosoft® Forefront™ code name StirlingMicrosoft Confidential
DirectAccess Technical DetailsIPv6 DevicesIPv4 DevicesIT desktop managementIPv6 Transition ServicesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
DirectAccess Technical DetailsIPv6 DevicesIPv4 DevicesIT desktop managementIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
DirectAccess Technical DetailsDirect connectivity to IPv6-based Intranet resourcesIPv6 DevicesIPv4 DevicesIT desktop managementNative IPv6 with IPSecIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
DirectAccess Technical DetailsDirect connectivity to IPv6-based Intranet resourcesIPv6 DevicesIPv4 DevicesSupport IPv4 via 6to4 transition services or NAT-PTIT desktop managementNative IPv6 with IPSecIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
Demonstration: Direct Access - End User ExperienceDirectAccessSession SummaryBetter TogetherUser Interface ImprovementsDirectAccess and Terminal Services GatewayHealth Policies
Break Time:  15 minutes
Active Directory Domain Services in Windows Server 2008 R2 Technical Overview
What Will We Cover?Identity Management and Simplified Management Capabilities Improved Management of User AccountsEnhanced Windows Management Deployments
What Will We Cover? Identity Management and Simplified Management Capabilities Improved Management of User AccountsEnhanced Windows Management Deployments
AgendaActive Directory Overview Active Directory Management Managing Active Directory DeploymentsIdentity and Access Management
Solutions That  Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole Enhancements
Solutions That  Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole EnhancementsTask-OrientedBetter Management
Solutions That  Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole EnhancementsTask-OrientedBetter Management Analyzers Expanded to All Core Windows Server 2008 R2 Roles
Solutions That  Address IT Pro ChallengesWindows Server 2008 R2 Forest Functional LevelNew Windows PowerShell cmdletsConsole EnhancementsDeals with Accidental Object DeletionDeals with Mapping of Various PropertiesDeals with Pre-Provisioning of Computer AccountsDeals with Managed Service AccountsTask-OrientedBetter Management Analyzers Expanded to All Core Windows Server 2008 R2 Roles
AgendaActive Directory Overview Active Directory ManagementManaging Active Directory DeploymentsIdentity and Access Management
Active Directory Administrative CenterCustomizable GUI
Active Directory Administrative CenterCustomizable GUI
Active Directory Administrative CenterCustomizable GUI
Demonstration Environment
Create an Organizational UnitCreate a UserCreate a New Group and Add a UserDemonstration: Creating Objects Using Active Directory Administrative Center
Active Directory Recycle BinReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe  or Windows PowerShell Cmdlets
Active Directory Recycle Bin—NotesReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe  or Windows PowerShell CmdletsSetup RequirementsAdprep must be used for Windows Server 2003 and Windows Server 2008 forestAll domain controllers in your Active Directory forest are running Windows Server 2008 R2Raise the functional level of your Active Directory forest to Windows Server 2008 R2
Active Directory Recycle Bin—NotesReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe  or Windows PowerShell CmdletsSetup RequirementsAdprep must be used for Windows Server 2003 and Windows Server 2008 forestAll domain controllers in your Active Directory forest are running Windows Server 2008 R2Raise the functional level of your Active Directory forest to Windows Server 2008 R2In this release, the process of enabling Active Directory Recycle Bin is irreversible. After you enable Active Directory Recycle Bin in your environment, you cannot disable it.
Enable Active Directory Recycle BinView Objects That Are in the Deleted Objects ContainerRestore Deleted ObjectsDemonstration: Working with the Active Directory Recycle Bin
AgendaActive Directory Overview Active Directory Management Managing Active Directory DeploymentsIdentity and Access Management
Best Practices Analyzer1BPA Run Time
Best Practices AnalyzerAD DS BPA Windows PowerShell Script1BPA Run Time
AD DS BPA  scans verify:DNS rules
Operation master connectivity rules
Operation master ownership rules
Number of controllers in the domain
Required services rules
Replication configurations rules
W32time configuration rules
Virtual machine configuration rulesBest Practices AnalyzerAD DS BPA Windows PowerShell Script1BPA Run Time
Best Practices Analyzer—NotesAD DS BPA  scans verify:DNS rules
Operation master connectivity rules
Operation master ownership rules
Number of controllers in the domain
Required services rules
Replication configurations rules

More Related Content

PPT
WBH 4.0 Mod 6 - Server Purposing.ppt
PPTX
Connect Remotely Using Windows® 7 Direct Access
DOCX
Resume Edit_7pm
PPTX
MDOP 2011
PPT
Domain Migration/Administration for the
PPT
Windowsserver2003twpppt
DOC
Vikas Yadav
PPTX
Q1 Southern California Session Slides
WBH 4.0 Mod 6 - Server Purposing.ppt
Connect Remotely Using Windows® 7 Direct Access
Resume Edit_7pm
MDOP 2011
Domain Migration/Administration for the
Windowsserver2003twpppt
Vikas Yadav
Q1 Southern California Session Slides

What's hot (20)

DOCX
ops300 Project(3)
PPT
Packaging Event 2008
PPTX
Installation & configuration
DOCX
Sudheendra
PPTX
TechEd Africa 2011 - OFC308: SharePoint Security in an Insecure World: Unders...
DOCX
Sql server 2008 r2 security overviewfor admins
PPTX
Microsoft Windows 7 Enhanced Security And Control
PPT
Windows 7 by microsoft
PPT
0828 Windows Server 2008 新安全功能探討
PPTX
Patch Management: 4 Best Practices and More for Today’s Banking IT Leaders
PPTX
Using SCCM 2012 r2 to Patch Linux, UNIX and Macs
PDF
Protecting Microsoft Exchange with the NEW Backup Exec 15
PPT
Common WSUS Issues in Deployment Operations and Diagnostics
PDF
Proxy Networks - Proxy Pro 8.10 Remote Desktop Software
PPTX
Day1 track4 session1_mdt2010_kaliyan
PDF
VMworld 2013: Introducing NSX Service Composer: The New Consumption Model for...
PPT
Common WSUS Errors Codes - Decoded and Resolved
PPT
What's New in Windows 7
PPTX
June Patch Tuesday 2018
PPTX
May 2018 Patch Tuesday Analysis
ops300 Project(3)
Packaging Event 2008
Installation & configuration
Sudheendra
TechEd Africa 2011 - OFC308: SharePoint Security in an Insecure World: Unders...
Sql server 2008 r2 security overviewfor admins
Microsoft Windows 7 Enhanced Security And Control
Windows 7 by microsoft
0828 Windows Server 2008 新安全功能探討
Patch Management: 4 Best Practices and More for Today’s Banking IT Leaders
Using SCCM 2012 r2 to Patch Linux, UNIX and Macs
Protecting Microsoft Exchange with the NEW Backup Exec 15
Common WSUS Issues in Deployment Operations and Diagnostics
Proxy Networks - Proxy Pro 8.10 Remote Desktop Software
Day1 track4 session1_mdt2010_kaliyan
VMworld 2013: Introducing NSX Service Composer: The New Consumption Model for...
Common WSUS Errors Codes - Decoded and Resolved
What's New in Windows 7
June Patch Tuesday 2018
May 2018 Patch Tuesday Analysis
Ad

Viewers also liked (11)

PDF
Windows Server 2008 R2 Active Directory ADFS Claims Base Identity for Windows...
PDF
Windows server 2008 step by-step guide for dns in small networks
DOC
Technical interview questions -networking
PPTX
Top 10 technical support specialist interview questions and answers
PDF
Masters of SlideShare
PDF
10 Ways to Win at SlideShare SEO & Presentation Optimization
PDF
What Makes Great Infographics
PDF
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
PDF
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
PDF
You Suck At PowerPoint!
PDF
How to Make Awesome SlideShares: Tips & Tricks
Windows Server 2008 R2 Active Directory ADFS Claims Base Identity for Windows...
Windows server 2008 step by-step guide for dns in small networks
Technical interview questions -networking
Top 10 technical support specialist interview questions and answers
Masters of SlideShare
10 Ways to Win at SlideShare SEO & Presentation Optimization
What Makes Great Infographics
STOP! VIEW THIS! 10-Step Checklist When Uploading to Slideshare
How To Get More From SlideShare - Super-Simple Tips For Content Marketing
You Suck At PowerPoint!
How to Make Awesome SlideShares: Tips & Tricks
Ad

Similar to Windows 2008 R2 & Windows7 (20)

PPTX
How Microsoft Technologies And Windows Vista Improve Supporting
PPT
W7 Enterprise
PPT
W7 for IT Professionals
PPTX
Windows 7 Feature Overview
PPTX
Windows 7 for IT Professionals
PPTX
Windows 7 Deployment Enhancements
PPTX
Windows 7
PPTX
Microsoft Solutions For Windows Vista Management
PPTX
Ws08 R2 Itpro Session 1 Technical Overview Part1
PPTX
Windows 7 And Windows Server 2008 R2 Combined Value
PPTX
Win Connections Technical Overview (Harold W)
PPTX
Win Connections Technical Overview ( Harold W)
PPTX
Discover what's new in Windows Server 2012 Active Directory
PPTX
Windows 7 Feature Overview It Academic Day 2009
PPTX
Deploying Windows Vista Service Pack 1
PPTX
Microsoft Platform Security Briefing
PPTX
Windows 7 Optimized Desktop
PPTX
Sogeti Experience Windows 7
PPTX
Group Policy Preferences, Templates, And Scripting
How Microsoft Technologies And Windows Vista Improve Supporting
W7 Enterprise
W7 for IT Professionals
Windows 7 Feature Overview
Windows 7 for IT Professionals
Windows 7 Deployment Enhancements
Windows 7
Microsoft Solutions For Windows Vista Management
Ws08 R2 Itpro Session 1 Technical Overview Part1
Windows 7 And Windows Server 2008 R2 Combined Value
Win Connections Technical Overview (Harold W)
Win Connections Technical Overview ( Harold W)
Discover what's new in Windows Server 2012 Active Directory
Windows 7 Feature Overview It Academic Day 2009
Deploying Windows Vista Service Pack 1
Microsoft Platform Security Briefing
Windows 7 Optimized Desktop
Sogeti Experience Windows 7
Group Policy Preferences, Templates, And Scripting

More from Gabe Akisanmi (10)

PDF
SaaS company in north america
PDF
Netscout threat report 2018
PDF
Cloud security monitoring
PDF
VMware Validated Design
PDF
Should we fear the cloud?
PDF
Hybrid cloud- driving a business
PDF
Is your infrastructure holding you back?
PDF
The shortest path to cloud success - your roadmap
PDF
Clustered data ontap_83_physical_storage
PDF
Alert logic cloud security report
SaaS company in north america
Netscout threat report 2018
Cloud security monitoring
VMware Validated Design
Should we fear the cloud?
Hybrid cloud- driving a business
Is your infrastructure holding you back?
The shortest path to cloud success - your roadmap
Clustered data ontap_83_physical_storage
Alert logic cloud security report

Windows 2008 R2 & Windows7

  • 1. Migrating Windows XP to Windows 7: Get it done using Microsoft Deployment ToolsHarold WongIT Pro Evangelist Microsoft Corporationblogs.technet.com/haroldwong
  • 2. Event Schedule8:30am – Introduction and Welcome8:45am –Session 1: Migrating Windows XP to Windows 7: Get it done using Microsoft Deployment Tools9:40 – Break 9:55 –Session 2: Securing Windows 7 in a Windows Server 2008 R2 Environment10:40 – Break 10:55 –Session 3: New Features in Windows Server 2008 R2 Directory Services– Drawing Afternoon MSDN will be here so stick around if you can 
  • 3. Migrating Windows XP to Windows 7:
  • 4. AgendaWindows Easy TransferDeployment ToolsUsing USMT Hard-link MigrationSummary of Deployment Solutions
  • 5. Windows Easy TransferEasily Move Files and SettingsSupports Windows 2000, Windows XP and Windows VistaTransfer done with:CableUSB DriveBetween Computers in a Network
  • 7. Deployment ToolsAutomated Installation Toolkit (AIK)User State Migration Tool (USMT)Microsoft Deployment Toolkit (MDT 2010)
  • 8. Automated Installation Toolkit (AIK)Windows System Image Manager (WSIM)ImageXDeployment Image Servicing and Management (DISM) Windows Preinstallation Environment (WinPE) User State Migration Tool (USMT)
  • 9. User State Migration ToolMigrates Files and SettingsComputer Replacement and Computer Refresh MigrationsScriptableHard-Link Migration StoreBenefits and Limitations
  • 10. Microsoft Deployment Toolkit 2010Unified tools and processes Reduced deployment time“Lite-touch” deployments leveraging Windows deployment tools“Zero-touch” deployments leveraging System Center Configuration Manager 2007 and Windows deployment tools. Support for Windows 7, Windows Server R2.
  • 11. “Lite-Touch” High-Volume DeploymentClient Migration Store – AIK and USMTConnected to WORKGROUPSource ComputerRun ScanStateand copies user state to shared folder on Windows 7 ClientDestination ComputerRunLoadStateon new Windows 7 platform and restores Windows XP user state from shared folder on Windows 7 ClientDestination ComputerRunLoadStateon new Widows 7 platform and restores Windows Vista user state from shared folder on Windows 7 ClientSource ComputerRun ScanStateand copies user state to shared folder on Windows 7 Client
  • 12. Demo“Lite-Touch” High-Volume Deployment using the User State Migration Tool’s (USMT) Scanstate and Loadstate
  • 13. “Zero-Touch” High-Volume DeploymentMigration Store ServerDecommissionDestination ComputerUse Log-on Script, batch file or non-Microsoft technology to run LoadStateon new Windows 7 platform and restores Windows XP user state from serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network serverDestination ComputerUse Log-on Script, batch file or non-Microsoft technology to runLoadStateon new Windows 7 platform and restores Windows Vista user state from serverSource ComputerUse Log-on Script, batch file or non-Microsoft technology to run ScanStateand copies user state to network server
  • 14. Summary of Deployment SolutionsSlide 14
  • 15. SummaryMany Deployment Tools and options for all scenarios from a single PC to 1,000sEasy Transfer makes it simple to move user dataNew Hard-link Migration Option in USMT
  • 16. TechNet Plus Direct SubscriptionThe ultimate resource for IT professionals. TechNet Plus provides convenient access to full-version Microsoft evaluation software—without time limits! The annual subscription also includes Professional Support incidents, a technical information library, and many other resources for evaluating, deploying, and maintaining Microsoft software.Microsoft software licensed for evaluation purposes.Beta software. Professional Support Incidents.Managed Newsgroup Support. Technical resources for Microsoft products.. Microsoft eLearning courses.Online Concierge Chat. Want a 25% Discount on a new Subscription?Use Discount Code TMSAM04
  • 17. IT Pro Momentum InvitationA Microsoft program focused on supporting “early adopters” – IT professionals who bet on the newest technologies to drive business value for their companies and advance in their careers Are you?Interested in learning more about the newest Microsoft technologies?Need help to evaluate different Microsoft products and features? Willing to test and pilot in production Microsoft beta products?Would like to have access to exclusive forums and Microsoft product support?Want to share your early adoption experience with the IT Pro community world-wide?If you answered ‘yes’ for all the questions above, IT Pro Momentum can help!Send email with “Add to Momentum” in the subjectHarold.wong@microsoft.com
  • 19. Resources for Windows 7 DeploymentWindows 7 Deployment Guidehttp://technet.microsoft.com/en-us/library/dd349337(WS.10).aspxMicrosoft Deployment Toolkit 2010https://connect.microsoft.com/content/content.aspx?ContentID=12463&SiteID=14
  • 20. Break Time: 15 minutes
  • 21. Securing Windows® 7 in a Windows Server® 2008 R2 Environment
  • 22. What Will We Cover?Better TogetherUser Interface ImprovementsDirectAccess and Terminal Services GatewayHealth Policies
  • 23. AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
  • 24. Business and Technical BenefitsReduce the risk of network security threats
  • 25. Business and Technical BenefitsReduce the risk of network security threatsSafeguard sensitive data and intellectual property
  • 26. Business and Technical BenefitsReduce the risk of network security threatsSafeguard sensitive data and intellectual propertyExtend the value of existing investments
  • 27. RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV1DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSClient requests access to network and presents current health state1
  • 28. RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV12DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSDHCP, VPN or Switch/Router relays health status to Microsoft Network Policy Server (RADIUS)2
  • 29. RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSNetwork Policy Server (NPS) validates against IT-defined health policy3
  • 30. RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312Not policy compliant4DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSIf not policy compliant, client is put in a restricted VLAN and given access to fix up resources to download patches, configurations, signatures (Repeat 1-4)4
  • 31. RemediationServersExample: PatchNetwork Access ProtectionCorporate NetworkPolicy Serverssuch as: Patch, AV312Not policy compliant4DHCP, VPNSwitch/Router WindowsClientRestrictedNetworkNPSPolicy compliant5If policy compliant, client is granted full access to corporate network5
  • 34. Configure BasicsAgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
  • 35. NPS UpdatesNPS TemplatesNetwork Policy ServerLogging ImprovementsUTF-8
  • 36. AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
  • 37. Multiple SHV PolicyA single server can now enforce a number of different health policies using a single system health validator (SHV)Requires SHV updates for Windows Server 2008 R2
  • 38. New NAP Client User InterfaceMessaging Integration with Action Center Tray IconIntegration with Windows 7 Action Center
  • 39. AgendaReviewing Network Access ProtectionExamining Deployment ImprovementsExploring Configuration and ManagementViewing Network Access Protection Integration Improvements
  • 40. Integration ImprovementsRemote Desktop GatewayMicrosoft Confidential
  • 41. Integration ImprovementsRemote Desktop GatewayDirectAccessMicrosoft Confidential
  • 42. Integration ImprovementsRemote Desktop GatewayDirectAccessMicrosoft® Forefront™ code name StirlingMicrosoft Confidential
  • 43. DirectAccess Technical DetailsIPv6 DevicesIPv4 DevicesIT desktop managementIPv6 Transition ServicesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
  • 44. DirectAccess Technical DetailsIPv6 DevicesIPv4 DevicesIT desktop managementIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
  • 45. DirectAccess Technical DetailsDirect connectivity to IPv6-based Intranet resourcesIPv6 DevicesIPv4 DevicesIT desktop managementNative IPv6 with IPSecIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
  • 46. DirectAccess Technical DetailsDirect connectivity to IPv6-based Intranet resourcesIPv6 DevicesIPv4 DevicesSupport IPv4 via 6to4 transition services or NAT-PTIT desktop managementNative IPv6 with IPSecIPv6 Transition ServicesAD Group Policy, NAP, software updatesInternetDirectAccessServerIPSec encryption and authentication. 2 Tunnels are established - DirectAccess Server acts as gatewaySupports variety of remote network protocolsWindows 7 Client
  • 47. Demonstration: Direct Access - End User ExperienceDirectAccessSession SummaryBetter TogetherUser Interface ImprovementsDirectAccess and Terminal Services GatewayHealth Policies
  • 48. Break Time: 15 minutes
  • 49. Active Directory Domain Services in Windows Server 2008 R2 Technical Overview
  • 50. What Will We Cover?Identity Management and Simplified Management Capabilities Improved Management of User AccountsEnhanced Windows Management Deployments
  • 51. What Will We Cover? Identity Management and Simplified Management Capabilities Improved Management of User AccountsEnhanced Windows Management Deployments
  • 52. AgendaActive Directory Overview Active Directory Management Managing Active Directory DeploymentsIdentity and Access Management
  • 53. Solutions That Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole Enhancements
  • 54. Solutions That Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole EnhancementsTask-OrientedBetter Management
  • 55. Solutions That Address IT Pro ChallengesNew Windows PowerShell cmdletsConsole EnhancementsTask-OrientedBetter Management Analyzers Expanded to All Core Windows Server 2008 R2 Roles
  • 56. Solutions That Address IT Pro ChallengesWindows Server 2008 R2 Forest Functional LevelNew Windows PowerShell cmdletsConsole EnhancementsDeals with Accidental Object DeletionDeals with Mapping of Various PropertiesDeals with Pre-Provisioning of Computer AccountsDeals with Managed Service AccountsTask-OrientedBetter Management Analyzers Expanded to All Core Windows Server 2008 R2 Roles
  • 57. AgendaActive Directory Overview Active Directory ManagementManaging Active Directory DeploymentsIdentity and Access Management
  • 58. Active Directory Administrative CenterCustomizable GUI
  • 59. Active Directory Administrative CenterCustomizable GUI
  • 60. Active Directory Administrative CenterCustomizable GUI
  • 62. Create an Organizational UnitCreate a UserCreate a New Group and Add a UserDemonstration: Creating Objects Using Active Directory Administrative Center
  • 63. Active Directory Recycle BinReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe or Windows PowerShell Cmdlets
  • 64. Active Directory Recycle Bin—NotesReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe or Windows PowerShell CmdletsSetup RequirementsAdprep must be used for Windows Server 2003 and Windows Server 2008 forestAll domain controllers in your Active Directory forest are running Windows Server 2008 R2Raise the functional level of your Active Directory forest to Windows Server 2008 R2
  • 65. Active Directory Recycle Bin—NotesReduces Downtime and EffortAD Objects Are PreservedFunctional for AD DS and AD LDSUse LDP.exe or Windows PowerShell CmdletsSetup RequirementsAdprep must be used for Windows Server 2003 and Windows Server 2008 forestAll domain controllers in your Active Directory forest are running Windows Server 2008 R2Raise the functional level of your Active Directory forest to Windows Server 2008 R2In this release, the process of enabling Active Directory Recycle Bin is irreversible. After you enable Active Directory Recycle Bin in your environment, you cannot disable it.
  • 66. Enable Active Directory Recycle BinView Objects That Are in the Deleted Objects ContainerRestore Deleted ObjectsDemonstration: Working with the Active Directory Recycle Bin
  • 67. AgendaActive Directory Overview Active Directory Management Managing Active Directory DeploymentsIdentity and Access Management
  • 69. Best Practices AnalyzerAD DS BPA Windows PowerShell Script1BPA Run Time
  • 70. AD DS BPA scans verify:DNS rules
  • 73. Number of controllers in the domain
  • 77. Virtual machine configuration rulesBest Practices AnalyzerAD DS BPA Windows PowerShell Script1BPA Run Time
  • 78. Best Practices Analyzer—NotesAD DS BPA scans verify:DNS rules
  • 81. Number of controllers in the domain
  • 85. Virtual machine configuration rulesSchema2BPA Run TimeAD DS BPA Windows PowerShell ScriptDocument1BPA Run Time
  • 86. Best Practices Analyzer—NotesAD DS BPA scans verify:DNS rules
  • 89. Number of controllers in the domain
  • 93. Virtual machine configuration rulesSchema2BPA Run TimeAD DS BPA Windows PowerShell ScriptDocument3BPA Run TimeAD DS BPARules Set1BPA Run Time
  • 94. Best Practices Analyzer—NotesAD DS BPA scans verify:DNS rules
  • 97. Number of controllers in the domain
  • 101. Virtual machine configuration rulesSchema2BPA Run TimeAD DS BPA Windows PowerShell ScriptDocument3BPA Run TimeAD DS BPAReportAD DS BPARules Set1BPA Run TimeAD DS BPAGuidance
  • 102. AgendaActive Directory Overview Active Directory Management Managing Active Directory DeploymentsIdentity and Access Management
  • 103. Offline Domain JoinDjoin.exeReduces time and effort for large-scale deploymentsEstablishes trust between operating system and Active Directory Domain
  • 104. Offline Domain JoinDjoin.exeReduces time and effort for large-scale deploymentsEstablishes trust between operating system and Active Directory DomainAdvantagesAD state changes are completed without network traffic to the computerComputer state changes are completed without any network traffic to a domain controllerEach change can be completed at different times
  • 105. Offline Domain Join —NotesDjoin.exeReduces time and effort for large-scale deploymentsEstablishes trust between operating system and Active Directory DomainAdvantagesAD state changes are completed without network traffic to the computerComputer state changes are completed without any network traffic to a domain controllerEach change can be completed at different timesSpecial ConsiderationsRun on Windows® 7 or Windows Server 2008 R2Must have user rights to join workstation to the domainDefaults target domain controller running a version of Windows Server 2008 R2
  • 106. Perform an Offline Domain JoinDemonstration: Using Offline Domain Join
  • 107. Management of Service AccountsLess Disruption of ServiceReduce Recurrent Administrative TasksDomain-Based Service Accounts Managed by ADEnhanced SecurityLocal AccountsSQLIIS
  • 108. Management of Service AccountsLess Disruption of ServiceReduce Recurrent Administrative TasksDomain-Based Service Accounts Managed by ADEnhanced SecurityManaged ServiceAccountLocal AccountsSQLIIS
  • 109. Management of Service AccountsLess Disruption of ServiceReduce Recurrent Administrative TasksDomain-Based Service Accounts Managed by ADEnhanced SecurityManaged ServiceAccountVirtual AccountsLocal AccountsSQLIIS
  • 110. Management of Service AccountsLess Disruption of ServiceReduce Recurrent Administrative TasksDomain-Based Service Accounts Managed by ADEnhanced SecurityAdministrative BenefitsCreate class domain accountsAccounts are now reset automaticallySPN management tasks are not completedCan be delegated to non-administratorsManaged ServiceAccountVirtual AccountsLocal AccountsSQLIIS
  • 111. Session SummaryActive Directory Domain Services improves management capabilities that automate Active Directory tasks
  • 112. The new Active Directory Administrative Console and Windows PowerShell module allow for flexible discovery and output
  • 113. Use and implement the new features of Windows Server 2008 R2 Domain Services