The Microsoft Solution Accelerator for Business Desktop Deployment, the Microsoft Solutions Framework and the Microsoft Operations Framework

Last week, I spent three days learning about the Microsoft Solution Accelerator for Business Desktop Deployment (BDD).

According to Microsoft:

    “The Microsoft Solution Accelerator for Business Desktop Deployment delivers end-to-end guidance for efficient planning, building, testing, and deploying Microsoft Windows XP Professional, Windows XP Tablet PC Edition, and Office Professional 2003 Editions. It helps IT professionals realize a quick return on investment while also setting new standards for reliability, performance, security, and ease of use.”

Basically, BDD is a framework for successful Windows XP desktop deployment. A collection of guidance, sample templates, tools and scripts, wrapped around a Windows XP and Office 2003 installation source, BDD version 1 has been around for some time now, and version 2 has two variant editions:

  • BDD Standard Edition is intended for medium sized organisations, enabling a highly automated (light touch) desktop deployment, requiring a LAN infrastructure with at least one server and sufficient space to store all of the working files and images (although Microsoft do recommend the use of Active Directory and Remote Installation Services) as well as either PowerQuest DeployCenter 5.5 or Symantec Ghost 8.0 and Windows PE 2004.
  • BDD Enterprise Edition is intended for large enterprises, utilising Active Directory, Remote Installation Services, Microsoft SQL Server 2000 and Microsoft System Management Server (SMS) 2003 (with the Operating System Deployment Feature Pack) to deliver a zero touch deployment. To use all of the features in BDD enterprise Edition, including provisioning, Microsoft BizTalk Server 2004, Microsoft Exchange Server 2003 and Microsoft Operations Manager (MOM) Server 2005 are also required. In short, BDD Enterprise can use just about every element of the Windows Server System.

Both editions additionally rely on the Microsoft User State Migration Toolkit (USMT) 2.6, Microsoft Application Compatibility Toolkit 3.0, Microsoft Office Access 2003 Conversion Toolkit, Windows XP Professional with Service Pack 2, and Office Professional 2003 Edition Service Pack 1.

The crossover between the two BDD variants (in terms of the cost of development vs. the number of desktops) is somewhere between 500 and 2000 desktops and the BDD framework scales up to a deployment of many thousands of PCs.

I’ve been working with unattended operating system builds for many years, and the consultancy that I work for (Conchango) already has a highly automated standard operating environment (SOE) process, built around the same technologies. BDD is a formalisation of existing best practices, packaged in a manner that allows an organisation to:

  • Create a software and hardware inventory to assist in deployment planning.
  • Test applications for compatibility with Windows XP Professional and mitigate the compatibility issues discovered during the process.
  • Set up an initial lab environment with deployment and imaging servers.
  • Customise and package core and supplemental applications.
  • Automate desktop image creation and deployment.
  • Ensure that the desktop is hardened to improve security within the environment.
  • Manage processes and technologies to produce a comprehensive and integrated deployment.

Even with BDD in place, rolling out a new standard desktop to hundreds or even thousands of computers, possibly spread across the globe, is not a trivial task and is likely to include a large team of people. In fact BDD is based around the idea of feature teams, each of which is responsible for one area of the solution.

BDD Standard and Enterprise Editions

As can be seen from the diagram above (which relates to BDD Enterprise Edition – BDD Standard Edition does not include provisioning), at the heart of BDD is the business case, and project management. Surrounding this function are the feature teams:

  • Application compatibility remediation – discovering which applications are in use, which are to be migrated, and investigating application compatibility.
  • Infrastructure compatibility remediation – analysing the current state of the infrastructure, to determine whether it is suitable to support the implementation of the new business desktop, then implementing new infrastructure as required. For example, does the network have sufficient bandwidth? Where are the bottlenecks? Are all of the PCs of a suitable specification to run Windows XP? How many will need to be replaced? etc.
  • Computer imaging system – which technologies will be used for deployment? Will this be zero touch or light touch? How many images will there be and what is the basis for creating a separate image? (e.g. functional images, or hardware variations). Functional images can be difficult to manage because of the number of images to keep up to date and in general the number of images should be minimised (in my last company we had just two, hardware-based, images for the various PC models across Europe). Where there are specific hardware concerns, it may be more cost-effective to replace some PCs than to develop an separate image for a particular computer type.
  • Core and supplemental application packaging – packaging those applications which will be included within the image (generally just Microsoft Office, Adobe Reader and some system software), and those supplemental applications that need to be deployed on a per user or per group basis.
  • User state migration – to be avoided wherever possible, user state migration is problematic and time consuming – therefore expensive; however, it is very rare that a deployment will not require the transfer of files and settings.
  • Securing the desktop – security should be included in every area of the design, but it is still necessary for someone to take control of the overall security for the desktop.
  • Deployment process – the process of actually getting the software into PCs throughout the organisation.
  • Preparing for operations – involving operations staff in the project, to ensure that the new platform is taken on board and managed well by the people who are often under-appreciated and over-utilised, and whose buy-in can ensure the success or failure of the entire project.
  • Upgrading Office – ensuring that Microsoft Office functionality is unaffected by the upgrade, paying attention to file versions, macros, file locations, etc.
  • Provisioning – allowing staff to help themselves – provisioning may be as simple as providing a website for users to reset their password after answering a few security questions, or it may be a process to request a new application, with full workflow throughout the approval process right up to the automatic deployment of the application to the desktop.

Of course some roles may be combined, depending on the size of the organisation. In fact the whole point about BDD is that it is designed to scale.

Fundamental to the whole process is the Microsoft Solutions Framework (MSF). MSF provides people and process guidance to help teams and organisations become more successful in delivering business-driven technology solutions to their customers. It is a deliberate and disciplined approach to technology projects based on a defined set of principles, models, disciplines, concepts, guidelines, and proven practices from Microsoft.

MSF Process Model and BDD

At the heart of MSF is the process model, which includes a five stage lifecycle for the solution. Based on phases and milestones, at each stage there are clear requirements in order to justify the ongoing cost of development. For example, there is no value in spending time, effort and money on planning the solution until the vision and scope for the project has been agreed.

The vision may be a single global desktop but the scope may impose restraints on this. In my opinion, envisioning is one of the most important areas of any desktop deployment and is also one of the most overlooked, generally because a customer can’t see the value in up-front planning and needs to be seen to deliver something to the business as soon as possible.

As the solution is deployed (and during preparation for operations), the Microsoft Operations Framework (MOF) is employed to provide operational guidance for the management of the solution. MOF is based on the UK government IT Infrastructure Library (ITIL) – the most widely accepted approach to IT Service Management in the world – and is fundamentally split into a set of models: a process model, a team model and a risk management discipline, as well as a set of service management functions.

MOF Team Model

The MOF team model organises the IT operations group into several role clusters – individuals or groups who perform related activities to accomplish a particular component of an IT service, based on industry best practices for structuring operations teams. MOF then provides additional guidance that applies collectively and individually to the role clusters.

MOF Process Model

The MOF process model assumes that the main responsibility of the IT operations groupÂ’ is managing change in the IT environment. The most effective way to deal with change throughout the lifespan of a service is to group related changes together into a package called a release, so that the changes can be planned and managed as a unit. The MOF process model describes a life cycle that can be applied to any release and the processes and activities that make up each part of that life cycle and groups similar service management functions (SMFs) into each of four quadrants relating to a specific mission of service.

MOF Risk Management Discipline

The MOF risk management discipline applies proven risk management techniques to the daily problems faced by operations staff. Many models, frameworks, and processes exist for managing risks and all share similarities in how they identify and manage risk. MOF applies key principles, along with customised terminology, structured and repeatable risk analysis and evaluation process, integrated within a larger operations framework.

All of the above is just an overview – I recommend that anyone looking to manage a major desktop deployment considers using the BDD framework, and that any organisation running on a primarily Microsoft desktop and server platform takes a serious look at MSF and MOF.

Technology’s role in the demise of the English language

The English language is dying.

I know that languages evolve over time and that change is inevitable, but I would say the vast majority of people in England do not write (or even speak) good English. Witness the number of signs with mis-placed apostrophes (e.g. HGV’s use next entrance) – and one of my recent customers even has painted markings on the surface of their car park which suggest walkers possess that particular area (i.e. pedestrian’s).

My own English is far from perfect; but I can blame that on being a child of the 1970s and 1980s who had a state school education. I remember one teacher at my middle school who was so frustrated as the class struggled with basic punctuation such as full stops, commas and apostrophes that they decided not to teach us how to use semi-colons and colons. That was that and I never learnt how to use them.

So what has this got to do with a (we)blog about technology? Well, I recently read Lynne Truss’ best seller “Eats, Shoots and Leaves: The Zero Tolerance Approach to Punctuation“. In the last chapter, Truss discusses technology’s role in the destruction of our language. To quote:

“…by tragic historical coincidence a period of abysmal under-educating in literacy has coincided with this unexpected explosion of global self-publishing. Thus people who don’t know their apostrophe from their elbow are positively invited to disseminate their writings to anyone on the planet stupid enough to double-click and scroll”.

She continues:

“…Even in the knowledge that our punctuation has arrived at its present state by a series of accidents; even in the knowledge that there are at least seventeen rules for the comma, some of which are beyond explanation by top grammarians – it is a matter for despair to see punctuation chucked out as worthless by people who don’t know the difference between who’s and whose, and whose bloody automatic ‘grammar checker’ can’t tell the
difference either”.

I did chuckle when I read about Bob Hirschfield’s pluperfect virus (the Strunkenwhite Virus), which first appeared in the Washington Post. Intended to provide a satirical view on the rise in hoax virus e-mails, it describes a virus (named Strunkenwhite after the authors of a classic guide to good writing), which returns e-mail messages that have grammatical or spelling errors.

Somewhat unfairly IMHO ;-), Truss also attacks emoticons but all of this does leave me wondering whether my son will grow up to read text or txt, and, does all of this, like, really matter as the erosion of our written language is just part of a wider issue with the spoken form, innit?

In the UK, The Economist recently ran a poster campaign which read something like:

“You can so tell the people who don’t like read the Economist”.

For those of us who do care about the correct use of language, Answers.com provides an online dictionary with definitions (e.g. blog), pronunciation, explanations (courtesy of Wikipedia); or there is WordSpy (the Website devoted to lexpionage, the sleuthing of new words and phrases).

I commend these as examples of where technology can help us to become more expressive in our online use of language.

Long live the English language!


Online dictionary, thesaurus, encyclopedia and much more…

Microsoft buys into the anti-virus market

Following Microsoft’s recent foray into the anti-spyware market and ending months of speculation, Microsoft announced today that it is to attack another form of malware through its purchase of Sybari Software.

Whether anti-virus technologies will be included within Windows (alongside the Windows Firewall), or made available as a separate download (as for Microsoft Windows AntiSpyware) is yet to be seen but with the US Department of Justice and the European Union already investigating the bundling of middleware within Windows it will be interesting to see how Microsoft positions its new acquisition.

Sending SMS messages from within Outlook

A couple of months back, my colleague James Simmonds wrote about a free Microsoft Office SMS Add-in (MOSA) which allows the sending (but not receipt) of text messages from within the Outlook 2003 client (in this context, SMS is Short Message Service – not Systems Management Server). I finally downloaded MOSA this afternoon and it looks good.

MOSA can only send messages using a GSM mobile handset that supports the Protocol Description Unit (PDU) standard. Initially, I attempted to send a message using a standard modem (without success – generating a “the modem does not support messages in PDU format” message) but once I paired my notebook PC with a Nokia 6310i via Bluetooth, everything jumped into life.

For anyone wondering (as I was), what exactly the PDU format is, I found some further information about SMS and the PDU format as well as a PDU string analyser and converter.

Preselecting English (United Kingdom) settings during Windows XP setup

By default, Windows XP installs English (United States) as the input language. It is possible to add other languages, for example English (United Kingdom), but if you try to remove English (United States) you are prompted that it is in use and will be removed after the next reboot. This may only be a minor inconvenience, but can be circumvented using an unattended setup file, either for a fully- or partially-unattended build.

Within the [Unattended] section of the answer file, a KeyboardLayout= entry may be specified. The Microsoft Windows Preinstallation Reference states that this entry is used to specify the type of keyboard layout to install during text-mode setup and I have found that by using a United Kingdom keyboard for text-mode setup, no United States entries are created during GUI-mode setup.

The KeyboardLayout= entry must match one of the strings (in quotation marks after the =) in the [Keyboard Layout] section of txtsetup.sif (which is found in the Windows XP installation source).

For reference, my RIS-based unattended installation uses the following entries to specify UK-only regional settings and location:

[Unattended]
KeyboardLayout="United Kingdom"

[RegionalSettings]
Language=00000809
SystemLocale=00000809
UserLocale=00000809
InputLocale=0809:00000809
UserLocale_DefaultUser=00000809
InputLocale_DefaultUser=00000809

Further information on the available regional settings may be found in Microsoft knowledge base article 289125 and the Microsoft global development website has a full list of the available National Language Support (NLS) code pages.

ieSpell – a spell checker for Internet Explorer

One of my favourite features in .Text (the blogging engine used by my Conchango Blog) is ieSpell – a spell checker for Internet Explorer.

ieSpell is a free (for non-commercial use) Internet Explorer browser extension which can be used to check the spelling of text input boxes on a web page. Particularly useful for users who perform a lot of web-based text entry (e.g. web mails, forums, blogs, diaries), it is both fast (i.e. it runs client-side) and flexible, as its personal word list (custom dictionary) is the same for whichever site it is run against (cf. a server-side system, which would only work for one particular web application). I also like it because it has a UK English dictionary as well as the ubiquitous US English default dictionary.

Once installed, ieSpell may be accessed in one of three ways:

  1. Using the Tools menu.
  2. Using the Toolbar button.
  3. Using a context-sensitive (right-click) menu.

ieSpell is available for download from the ieSpell website.

Five ways to help protect your identity

A few months back I wrote about the Microsoft At Work microsite and its advice for maintaining your computer at work. It may be a little high level – but it is aimed at end users and that in itself is good because us techies are generally not too good at communicating with non-technical people.

Microsoft At Work has a sister microsite – Microsoft At Home. Again, it’s full of practical advice, but is more consumer-focused and one of the articles that caught my eye recently discusses avoiding phishing scams. Phishing is a rapidly increasing form of online crime concerned with identity theft. In a phishing scam, a malicious person attempts to obtain personal information such as credit card numbers, passwords, account information, or other personal information by convincing the end user to give it to them under false pretences. Phishing schemes usually come via spam e-mail or pop-up windows.

Windows Update Services name change?

Windows Update Services (WUS) is the new name for Software Update Services (SUS). Except it might not be. Last week, Thomas Lee (who is well placed to comment on such things, being both a Microsoft Regional Director and an MVP) quite rightly pointed out that WUS a) sounds bad; and b) is not an accurate description of what the product does.

For more information about SUS/WUS see SUSserver.com and the Windows Update Services Wiki.

Biometric USB flash drive – how cool is that?!

I know that it is just a logical evolution of the humble USB flash drive and the decreasing cost of biometric security (even my local gym uses a fingerprint reader now for members to sign in and out) but last week Thomas Lee showed me the Trek ThumbDrive Swipe, which combines fingerprint swipe sensor technology with flash memory based USB storage. Fingerprint security on a USB stick is cool. Now all I need is for someone to invent something to stop me losing mine all the time…

New features of Windows Server 2003 Active Directory

A couple of weeks back, I was at a Microsoft TechNet UK event, where the topic was New features of Windows Server 2003 Active Directory, presented by John Howard, IT Pro Evangelist, Microsoft UK.

I’ve been working with Active Directory (AD) since the early days of Windows 2000 (windows NT 5.0 as it was then), and to be perfectly honest wondered how much there could be that’s new with the latest version. Whilst the session was possibly a little lightweight, I was surprised to learn just how many new features there are, as my previous view of Windows Server 2003 was that much of the improved functionality comes in the form of new services.

The new AD features fall into in four main areas:

  • Simplified management.
  • Connecting forests.
  • Connecting small offices.
  • Managing group policies.

The rest of this post will discuss each of these in turn.

Simplified management
Simplified management is about improving the user experience for administrators. For example, within the AD User and Computers and AD Sites and Services Active Directory management tools, users can now drag and drop users into new containers, OUs or groups, e.g. when adding user(s) or group(s) to a group, or moving a server to a new site.

Tip: Within AD users and computers it helps if the option to view users, groups and computers as containers is selected.

Improvements have also been made in locating objects, with new functionality such as saved queries in AD users and computers, accessed like a folder, e.g. queries based on a user or group name or description, or the number of days since the last logon). The queries are LDAP-based and can have their own root (i.e. do not have to be relative to the whole domain). It should also be noted that saved queries are local to the computer and can be exported – e.g. űbergeek queries can be created and exported to a help desk machine.

Tip: To see exactly where an object exists in the directory, turn on advanced features and look in the object page of the item properties.

There are also a whole head of new tools, which can be called from the command line or from within custom scripts, allowing for repetitive tasks to be automated and complex commands to be simplified. Back in September 2004, I posted further information on new commands in recent Windows releases and Microsoft knowledge base article 322684 discusses using the directory service command-line tools to manage Active Directory objects in Windows Server 2003.

Connecting forests
It is now possible to connect forests using trusts (e.g. following a merger or acquisition, of under some business partnership scenarios), simplifying access to resources in both forests, and facilitating single sign-on.

Forest trusts can be one- or two-way and create a transitive trust between the domains in each forest, but not between forests. With a forest trust, UPN suffixes are used to publish namespaces, which in turn are used to establish where a logon originates from. Each forest is trusted to be authoritative for the namespace(s) which it publishes.

In order to support forest trusts, both forests must be running at Windows Server 2003 forest functional level.

Connecting small offices
Small or branch offices are often characterised by low speed wide area network links and may not have a local global catalog server, leading to slow logons. Windows Server 2003 includes a new option in the Active Directory Installation Wizard (dcpromo) to create a domain controller from a replica. It works by backing up the system state from an existing domain controller to removable media, then restoring that data on a remote server and running dcpromo /adv. In this way, the initial synchronisation time is reduced, as all the new domain controller needs to synchronise is the changes since the backup was taken. There is one gotcha through – the backup cannot be older than the tombstone lifetime (60 days by default).

Another useful new feature when connecting small offices is universal group membership caching. Because universal groups may span multiple domains, a global catalog server is required to query the membership (non-global catalog-enabled domain controllers only hold full details for objects in their own domain).

By caching the membership lists for universal groups, global catalog lookups only need to occur once for each universal group. The membership list is held indefinitely, but is refreshed every 8 hours. Universal group membership caching is enabled at the site level, within the NTDS Site Settings.

One alternative to universal group membership caching is to make each branch office domain controller a global catalog server, but this has a cost in increased domain replication traffic.

Managing group policies
One of the major criticisms of Active Directory group policy objects (GPOs) is that they are is difficult to administer. Microsoft does provide tools, but until recently, they have been limited in their capabilities. Shortly after Windows Server 2003 was released, Microsoft made the Group Policy Management Console (GPMC) available for download. Since then, GPMC with service pack 1 has been released which includes a number of bug fixes, revised licensing (to allow GPMC to be run against Windows 2000 domain controllers), support for more languages and a revised XML engine.

The GPMC is a new administrative tool for centralised management of GPOs, together with a collection of scriptable objects and associated scripts, which use a combination of Windows Management Instrumentation (WMI), Active Directory Services Interfaces (ADSI) and the GPMC object model.

Surprisingly, although in almost every organisation which uses Active Directory, GPOs affect every user within the business, many organisations do not think about backing up and restoring GPOs. Whilst they can be restored with an authoritative AD restore, that is not a simple process, and the scripts provided with the GPMC allow policies to be backed up and restored, as well as exported and imported (e.g. between test and production domains/forests).

Tip: Beware (as I found out with one of my clients), that if naming standards allow the use of non-standard characters (e.g. & and ‘) the GPMC scripts may not work as intended. For further information, refer to the September 2004 post which discusses recommendations for Active Directory object naming.

The GPMC also allows modelling of group policies in a similar manner to the previous Resultant Set of Policy (RSoP) tool. This is particularly useful for its ability to highlight the winning GPO for a policy setting, as well as the ability to view (and save) reports in HTML, or XML format (e.g. for intranet publishing and reference by IT support staff). Note that some settings (e.g. WMI, loopback, IPSec, Wireless, and disk quotas) may be estimates. Also, if a client PC used for modelling is running Windows XP service pack 2 with the default Windows Firewall settings and the original version of GPMC is used (i.e. without service pack 1), it will fail as described in Microsoft knowledge base article 883611.

Other useful group policy management tools include Group Policy Monitor (gpmonitor), which is used to create and display reports when policy settings are refreshed and the Group Policy Verification Tool (gpotool), which allows administrators to check GPO stability and monitor policy replication including checking for consistency within and across domains. This tool also displays information about GPOs, including properties that cannot be accessed through the Group Policy Object Editor such as the functionality version number and extension globally unique identifiers (GUIDs). Other diagnostic tools (also available in Windows XP) include Group Policy Results (gpresult) and the Group Policy Refresh Utility (gpupdate).

When diagnosing issues with GPOs, it is also worth checking DNS, as at the event I attended, Microsoft commented that 50% of GPO-related support calls are actually DNS issues.

Another new feature of Windows Server 2003 group policy is software restriction policies, which can be used to confront the problem of regulating unknown or untrusted code. Software restriction policy rules create one or more exceptions to the default security level, defined by software restriction policies.

The following types of software restriction policy rules can be created:

  • Certificate rules, which recognise software that is digitally signed by an authenticode software publisher certificate.
  • Hash rules, which recognise specific software based on a hash of the software.
  • Path rules, which recognise software based on the location in which the software is stored.
  • Registry path rules, which recognise software based on the location of the software as it is stored in the registry.
  • Internet zone rules, which recognise software based on the zone of the Internet from which the software is downloaded.