SlideShare une entreprise Scribd logo
1  sur  13
Télécharger pour lire hors ligne
Building a Managed
Desktop Environment
Mike Julian
Wednesday, August 8, 12
Who am I?
• Windows (and a bit of Linux) sysadmin
• First Win7 deployment at UTK: ~1500
machines
• Win98,WinXP, Vista, Win7, ~15+
deployments, 20-1k+ each
Wednesday, August 8, 12
What is a ‘Managed
Desktop Environment’?
• Automated
• Controlled
• As lean as the business needs, and no
leaner.
Wednesday, August 8, 12
I. Define
     A. What do I mean when I say a 'Managed desktop environment'?
     B. Those of you working in large scale systems know that it's easier and more efficient to rebuild a system than to repair it. The same principle applies in a desktop environment as well.
C. The goal of a managed desktop environment is very similar to that of a well-managed server environment: automate everything, know *exactly* what is on your systems, who needs
what, where the systems reside, etc.
Why does it matter?
• The lens through which users view IT.
• Do this right, and perceptions of IT will
swing to positive.
Wednesday, August 8, 12
II. Why does it matter?
A. You may have the most beautifully-designed and managed server infrastructure, but if the computers your customers use are slow, then in their minds, your network sucks.
B. If a new user arrives and their computer and all accounts are not waiting for them by the time they get to their desk, the reputation of IT is immediately tarnished in their minds--no
matter what the reason is.
C. There really is no excuse for a desktop to be down longer than an hour.
C. What I'm getting at is that your desktop environment is the lens through which your customers view IT. Do this right and you make great bounds in building user faith in IT.
How do I start?
• Do an inventory
• Decide on methodology
• HTI vs LTI vs ZTI
• Thin,Thick, Hybrid
Wednesday, August 8, 12
Inventory
• Workstations, printers, software, file
shares, usage patterns
• Microsoft Assessment & Planning Toolkit
(MAP)
• Script it:VBS or PowerShell
Wednesday, August 8, 12
IV. The Approach
A. Inventory
1. Software
2. Hardware
3. Printers
4. Users
5. Shared folders/mapped drives
6. Usage patterns (eg, groups of users)
7. MAP can be a huge help here
Methodology
• Install Types
• HTI: High Touch Install
• LTI: Lite Touch Install
• ZTI: Zero Touch Install
Wednesday, August 8, 12
III. Terms
A. ZTI - Zero Touch Installation
1. Fully automated deployment. You don't touch the system at all. In fact, you could sit at your desk and never get up.
2. Requires SCCM in order to do, which costs a good sum of money. It's worth it, but some of your companies may not have the budget or scale for it.
B. LTI - Lite Touch Installation
1. Just short of ZTI: your interaction is minimal, such as entering a computer name, or initiating the imaging process manually
2. All the functionality needed for LTI is built-in on Server 2008, or comes free from Microsoft.
Methodology
• Image types
• Thin Image
• Thick Image
• Hybrid Image
Wednesday, August 8, 12
C. Thick Image
1. Also called a flat image. Many of you are familiar with this already. This is where you build a system as your reference machine, then clone it as-is. Anyone who has ever used Ghost
for deployment has done this.
D. Thin Image
1. Way cooler stuff. The image isn't really an image. An example can explain it better: in my latest project, I have the Windows 7 vanilla WIM in WDS. I used WAIK to build an unattend
file, which I applied to it through MDT. MDT has a driver database stored on a network share. When I launch MDT and tell it to install this image, it goes through a standard Win7 install,
applies the unattend file, installs drivers and updates from the local network. Part of the unattend is joining the domain. By the time the system does the first boot, it gets group policy, which
then applies a ton of custom settings, and installs a bunch of software. As you can see, it's not really an image, as the system is built piece by piece through the process. One of the neat
things about this method is that you can change things at any point in the process, unlike with a thick image, which would have to be snapshotted again. Changing anything on a thin image
requires no deployment of it first. It's way more flexible.
2. This is the method I advocate for most implementations.
The Tools
• MDT
• WAIK
• WDS
• SCCM - $$$
Wednesday, August 8, 12
IV. OS Deployment
A. Windows 7
1. MDT as thin or thick image
2. SCCM - We won't be covering this, as awesome as it is.
3. WAIK for building the unattend file
B. Windows XP
1. MDT can deploy as a thick image
Customization
• Group Policy!
• Printers
• Software
• Settings
• File shares
Wednesday, August 8, 12
V. Group Policy
A. System customization
1. Group policy is your best friend. There is way too much to list here.
B. Printer Deployment
a. Printer deployment sucks, but it's better than it used to be.
b. On printers, there's a lot of nitty gritty technical. Here's the overview: Use a print server, then pick one of the following methods:
(1). Group Policy Preferences - An excellent choice and should be your first choice.
(2). Print Management MMC through the Print Server role on 2k8 - Really easy to deploy, however, it has the limitation of not being able to use security groups to apply selectively
(3). VBS script - Really easy, simple, and stable. I tend to use built-in functionality instead of scripting things, but this method works just fine.
c. I mentioned security groups, so let me touch on that. Create a security group for each printer you have. Put computers or users in it, depending on where you're applying this in
group policy. When you set up a printer for deployment, use the security group as the condition. The result is that only people or computers in that group will get the printers installed. Person
needs a new printer added? Simply add them to the group and tell them to reboot.
C. Software Deployment
1. Most major software packages have MSIs with transforms available. Add them to the Software Installation bit in group policy. If the package lacks an MSI, there is software available
to repackage as an MSI, though I don't have any experience with them. Another option is to set a batch script to perform a silent install against the EXE. MDT can also perform software
installation itself.
D. File shares
1. Couple different options: Use Group Policy Preferences, or a script (batch/VBS). I prefer GPP.
Licensing
• Three licensing types
• OEM
• Retail
• Volume Licensing
• OnlyVL has imaging rights
Wednesday, August 8, 12
VI. Licensing Concerns
A. There are three types of licensing
1. OEM - This what you get when you purchase a new computer. It's the sticker on the side of the box. Individual keys.
2. Retail - This is when you buy from a retailer, such as Best Buy. Individual keys.
3. Volume Licensed - Purchased from resellers. Multiple different licensing models available; ask your reseller for more information on those, as it can get confusing quickly.
B. Only VL has reimaging rights.
1. One of the more important bits to know here is that a VL license for Win7 is an upgrade license, not a full license. You need an OEM or retail license on the computer already.
Resources
• Windows 7 Resource Kit by Mitch Tulloch
• Microsoft TechNet
• MSVolume Licensing Service Center:
microsoft.com/licensing
Wednesday, August 8, 12
Q&A
• Questions?
• mike@mikejulian.com
Wednesday, August 8, 12

Contenu connexe

Dernier

AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 

Dernier (20)

AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

En vedette

AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 

En vedette (20)

AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 

LOPSA-ETENN - Building a Managed Desktop Environment

  • 1. Building a Managed Desktop Environment Mike Julian Wednesday, August 8, 12
  • 2. Who am I? • Windows (and a bit of Linux) sysadmin • First Win7 deployment at UTK: ~1500 machines • Win98,WinXP, Vista, Win7, ~15+ deployments, 20-1k+ each Wednesday, August 8, 12
  • 3. What is a ‘Managed Desktop Environment’? • Automated • Controlled • As lean as the business needs, and no leaner. Wednesday, August 8, 12 I. Define      A. What do I mean when I say a 'Managed desktop environment'?      B. Those of you working in large scale systems know that it's easier and more efficient to rebuild a system than to repair it. The same principle applies in a desktop environment as well. C. The goal of a managed desktop environment is very similar to that of a well-managed server environment: automate everything, know *exactly* what is on your systems, who needs what, where the systems reside, etc.
  • 4. Why does it matter? • The lens through which users view IT. • Do this right, and perceptions of IT will swing to positive. Wednesday, August 8, 12 II. Why does it matter? A. You may have the most beautifully-designed and managed server infrastructure, but if the computers your customers use are slow, then in their minds, your network sucks. B. If a new user arrives and their computer and all accounts are not waiting for them by the time they get to their desk, the reputation of IT is immediately tarnished in their minds--no matter what the reason is. C. There really is no excuse for a desktop to be down longer than an hour. C. What I'm getting at is that your desktop environment is the lens through which your customers view IT. Do this right and you make great bounds in building user faith in IT.
  • 5. How do I start? • Do an inventory • Decide on methodology • HTI vs LTI vs ZTI • Thin,Thick, Hybrid Wednesday, August 8, 12
  • 6. Inventory • Workstations, printers, software, file shares, usage patterns • Microsoft Assessment & Planning Toolkit (MAP) • Script it:VBS or PowerShell Wednesday, August 8, 12 IV. The Approach A. Inventory 1. Software 2. Hardware 3. Printers 4. Users 5. Shared folders/mapped drives 6. Usage patterns (eg, groups of users) 7. MAP can be a huge help here
  • 7. Methodology • Install Types • HTI: High Touch Install • LTI: Lite Touch Install • ZTI: Zero Touch Install Wednesday, August 8, 12 III. Terms A. ZTI - Zero Touch Installation 1. Fully automated deployment. You don't touch the system at all. In fact, you could sit at your desk and never get up. 2. Requires SCCM in order to do, which costs a good sum of money. It's worth it, but some of your companies may not have the budget or scale for it. B. LTI - Lite Touch Installation 1. Just short of ZTI: your interaction is minimal, such as entering a computer name, or initiating the imaging process manually 2. All the functionality needed for LTI is built-in on Server 2008, or comes free from Microsoft.
  • 8. Methodology • Image types • Thin Image • Thick Image • Hybrid Image Wednesday, August 8, 12 C. Thick Image 1. Also called a flat image. Many of you are familiar with this already. This is where you build a system as your reference machine, then clone it as-is. Anyone who has ever used Ghost for deployment has done this. D. Thin Image 1. Way cooler stuff. The image isn't really an image. An example can explain it better: in my latest project, I have the Windows 7 vanilla WIM in WDS. I used WAIK to build an unattend file, which I applied to it through MDT. MDT has a driver database stored on a network share. When I launch MDT and tell it to install this image, it goes through a standard Win7 install, applies the unattend file, installs drivers and updates from the local network. Part of the unattend is joining the domain. By the time the system does the first boot, it gets group policy, which then applies a ton of custom settings, and installs a bunch of software. As you can see, it's not really an image, as the system is built piece by piece through the process. One of the neat things about this method is that you can change things at any point in the process, unlike with a thick image, which would have to be snapshotted again. Changing anything on a thin image requires no deployment of it first. It's way more flexible. 2. This is the method I advocate for most implementations.
  • 9. The Tools • MDT • WAIK • WDS • SCCM - $$$ Wednesday, August 8, 12 IV. OS Deployment A. Windows 7 1. MDT as thin or thick image 2. SCCM - We won't be covering this, as awesome as it is. 3. WAIK for building the unattend file B. Windows XP 1. MDT can deploy as a thick image
  • 10. Customization • Group Policy! • Printers • Software • Settings • File shares Wednesday, August 8, 12 V. Group Policy A. System customization 1. Group policy is your best friend. There is way too much to list here. B. Printer Deployment a. Printer deployment sucks, but it's better than it used to be. b. On printers, there's a lot of nitty gritty technical. Here's the overview: Use a print server, then pick one of the following methods: (1). Group Policy Preferences - An excellent choice and should be your first choice. (2). Print Management MMC through the Print Server role on 2k8 - Really easy to deploy, however, it has the limitation of not being able to use security groups to apply selectively (3). VBS script - Really easy, simple, and stable. I tend to use built-in functionality instead of scripting things, but this method works just fine. c. I mentioned security groups, so let me touch on that. Create a security group for each printer you have. Put computers or users in it, depending on where you're applying this in group policy. When you set up a printer for deployment, use the security group as the condition. The result is that only people or computers in that group will get the printers installed. Person needs a new printer added? Simply add them to the group and tell them to reboot. C. Software Deployment 1. Most major software packages have MSIs with transforms available. Add them to the Software Installation bit in group policy. If the package lacks an MSI, there is software available to repackage as an MSI, though I don't have any experience with them. Another option is to set a batch script to perform a silent install against the EXE. MDT can also perform software installation itself. D. File shares 1. Couple different options: Use Group Policy Preferences, or a script (batch/VBS). I prefer GPP.
  • 11. Licensing • Three licensing types • OEM • Retail • Volume Licensing • OnlyVL has imaging rights Wednesday, August 8, 12 VI. Licensing Concerns A. There are three types of licensing 1. OEM - This what you get when you purchase a new computer. It's the sticker on the side of the box. Individual keys. 2. Retail - This is when you buy from a retailer, such as Best Buy. Individual keys. 3. Volume Licensed - Purchased from resellers. Multiple different licensing models available; ask your reseller for more information on those, as it can get confusing quickly. B. Only VL has reimaging rights. 1. One of the more important bits to know here is that a VL license for Win7 is an upgrade license, not a full license. You need an OEM or retail license on the computer already.
  • 12. Resources • Windows 7 Resource Kit by Mitch Tulloch • Microsoft TechNet • MSVolume Licensing Service Center: microsoft.com/licensing Wednesday, August 8, 12