5. このセッションは内容および図等に関して
大部分を下記から引用しています。
Remote Desktop Services 2019
MyIgnite - What's new in Remote Desktop Services on Windows Server 2019
https://myignite.techcommunity.microsoft.com/sessions/65999
Windows Virtual Desktop
MyIgnite - A tour of Windows Virtual Desktop
https://myignite.techcommunity.microsoft.com/sessions/66957
MyIgnite - Windows Virtual Desktop deep dive
https://myignite.techcommunity.microsoft.com/sessions/64600
MyIgnite - New multi-session virtualization capabilities in Windows
https://myignite.techcommunity.microsoft.com/sessions/66731
15. FIREWALL
RD Clients Remote Desktop Services 2012 R2
Windows Server AD
Domain ServicesSQL DB
RD infra User environment
VMs
RDS 2012 R2
引用元:MyIgnite - What's new in Remote Desktop Services on Windows Server 2019 https://myignite.techcommunity.microsoft.com/sessions/65999?source=sessions
16. Remote Desktop Services 2016
FIREWALL
RD Clients
Windows Server AD
Domain Services
VMs
RD infra User environment
Azure SQL DB
RDS 2016
引用元:MyIgnite - What's new in Remote Desktop Services on Windows Server 2019 https://myignite.techcommunity.microsoft.com/sessions/65999?source=sessions
17. RDS 2019
引用元:MyIgnite - What's new in Remote Desktop Services on Windows Server 2019 https://myignite.techcommunity.microsoft.com/sessions/65999?source=sessions
Remote Desktop Services 2019
FIREWALL
RD Clients
Windows Server AD
Domain Services
VMs
RD infra User environment
Azure SQL DBAzure Key Vault
18. RDS 2019 ARM templates
…が予告されています。
Azure/RDS-Templates: ARM Templates for
Remote Desktop Services deployments
https://github.com/Azure/RDS-Templates
21. Connect to new deployment
After successful deployment, the URL for the Remote Desktop Gateway (RDGW) and
RDWeb site will be
https://%dnsLabelPrefix%.%location%.cloudapp.azure.com/RDWeb.
A self-signed certificate will be used for the deployment. To prevent certificate mismatch
issues when connecting using a self-signed certificate, the certificate will need to be
installed on the local client machines 'Trusted Root' certificate store. Best practice for a
production environment is to configure the deployment to use a trusted certificate.
https://rdsdemo.japaneast.cloudapp.azure.com/RDWeb
23. Windows Server 2019
Desktop Experience
Scalable multi-user legacy
Windows environment.
Windows Server 2019
Multiple users
Win32
Office 2019 Perpetual
Long-Term Servicing Channel
Windows 10
Enterprise
Native single-session modern
Windows experience.
Windows 10
Single user
Win32, UWP
Office 365 ProPlus
Semi-Annual Channel
引用元:MyIgnite - New multi-session virtualization capabilities in Windows https://myignite.techcommunity.microsoft.com/sessions/66731
24. Windows Server 2019
RD Session Host
Scalable multi-user legacy
Windows environment.
Windows Server 2019
Multiple users
Win32
Office 2019 Perpetual
Long-Term Servicing Channel
Windows 10
Enterprise
Native single-session modern
Windows experience.
Windows 10
Single user
Win32, UWP
Office 365 ProPlus
Semi-Annual Channel
Windows 10
Enterprise multi user
Scalable multi-user modern
Windows user experience with
Windows 10 Enterprise security
Windows 10
Multiple users
Win32, UWP
Office 365 ProPlus
Semi-Annual Channel
引用元:MyIgnite - New multi-session virtualization capabilities in Windows https://myignite.techcommunity.microsoft.com/sessions/66731
26. Windows Virtual Desktopライセンス
Windows Virtual Desktop is a benefit of Windows 10
Enterprise and Windows 10 Education customers. Eligible
licenses for the benefit include Microsoft 365 E3 and E5,
as well as Windows E3 and E5.
引用元:Windows Virtual Desktop | Azure updates |
Microsoft Azure https://azure.microsoft.com/en-
us/updates/windows-virtual-desktop/
28. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
29. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
30. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
31. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
32. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
33. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
34. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
35. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
36. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
37. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
要注意!
38. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
39. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
40. 引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM引用元:A tour of Windows Virtual Desktop - THR2302 - YouTube
https://www.youtube.com/watch?time_continue=3&v=ua9P4VsICFM
52. Windows Search Mode
% CPU utilization
100 users logging on simultaneously
% CPU utilization
100 users using Outlook
Disabled 60.6 41.7
Running without optimizations 90.7 52.1
Running with multi-user optimizations 63.4 41.9
Windows
Desktop
Search
optimized for
multi-user
mode
Enables the full Outlook search experience that
users expect
Per-user index files are stored in the user profile
for easy roaming
No impact to CPU usage at steady state, minimal
impact at sign in
引用元:MyIgnite - New multi-session virtualization capabilities in Windows https://myignite.techcommunity.microsoft.com/sessions/66731
53.
54. Windows Virtual Desktop全体像
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
55. Windows Virtual Desktop全体像
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
56. 管理者
◼ デスクトップおよびアプリケーションを公開可能
◼ RDクライアントとWindows仮想マシンとの接続を管理
エンドユーザー
◼ デスクトップおよびアプリケーションに任意のデバイスでインターネット経由でアクセス可能
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
57. Azure ADによる認証
Azure ADによるセキュリティ強化に対応
(条件付きアクセス、多要素認証、Identity Protection等)
Windows 10 VMはActive Directoryに参加
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
1
58. ユーザー接続の流れ
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
1
0
42
3
1. ユーザーがRDクライアントを起動しAzure ADに接続。ユーザーがサインイン。Azure ADがトークンを返す。
2. RDクライアントがトークンをWebアクセスに渡す。ブローカーがDBをクエリし、ユーザーに認可されているリソースを判断する。
3. ユーザーがリソースを選択する。RDクライアントがゲートウェイに接続する。
4. ブローカーがホストエージェントとゲートウェイとの接続を確立する。
>>> RDPトラフィックがRDクライアントとセッションホストVMとの間を流れる(3と4の接続を利用)
59. 引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
Azure SQL DB
VMsAzure AD
0
4
独立性の向上:リバースコネクト
顧客のVMからブローカーおよびゲートウェイへの接続は外向きのWebソケット接続のみ
VMとRDインフラとの双方向の通信はhttps(443)のみ
顧客環境にはインバウンドのポート開放は必要ない
60. Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
Azure AD
Domain Services
User Profile
Azure Files
A A
Azure SQL DB
VMsAzure AD
Azure AD
Domain Services
User Profile
Azure Files
A A
VMsAzure AD
VPN
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600
61. サードパーティーアプリケーションはPowerShellあるいはREST APIを使ってWindows Virtual Desktopプラットフォームの
拡張が可能
例:展開の自動化、VMのスケーリングとプロビジョニング、構成、監視、トラブルシューティングのためのWeb UI等
Windows Virtual Desktop
Microsoft-managed Azure services
FIREWALL
FIREWALL
Windows 10 Enterprise multi-session
Customer-managed Azure VMs & services
RD clients
Customer-managed
A A
VMsAzure AD
PowerShell
Third-party
app
引用元:MyIgnite - Windows Virtual Desktop deep dive https://myignite.techcommunity.microsoft.com/sessions/64600