Monday, 13 October 2014

Application Management Event 2014

I was worried that no one would show-up, but show up they did. The annual AppManagEvent 2014 Event (organised by PDS) in the Netherlands was a great success.

Fortunately, I was able to present on one of the technical break-out sessions on virtualization with summary of the past few years of application virtualization titled, "The Rise and Fall and Rise of Virtualization". 

Here are some quick photos from the session:

Greg Lambert presenting at the Application Management Event
We also had a stand at the exhibition, and had a chance to get some feedback on our cloud-based Assessment, Remediation and Conversion service.

Qompat Demos at Application Management Event
You can view the virtualization presentation via Slide Share here.

Overall, we had a great response to our planned products, services and pricing.

If you would like to find out more about how we can assist with your migration or business as usual application management efforts, please join our BETA program, listed below.


Monday, 6 October 2014

Join us at the AppManagement Event 2014



Join us the Application Management (and Packaging) Event.

I will be presenting one of the technical break-out sessions at the Application Packaging event in the Netherlands.

The delights and frustrations of technology are such that with each wave of progress, a new set of issues come to light. In this session, I will reflect on the early history and technical challenges encountered in the process of migrating desktop, and sometimes server environments, to virtualised platforms 

Time, October 9th, 13:40 – 14:20

It would be great to see you, and if you have time, please stop by the Qompat stand to see a demo.





Monday, 4 August 2014

Getting everyone on the Web to work: IE11 Compatibility on Windows Phone 8.1 Update

The two Program (co-program) Manager for the Microsoft Internet Explorer team recently released a pretty substantial blog posting on some of the compatibility challenges facing modern browsers today.  Pairing their posting with the release of Windows Phone 8.1 Update and the subsequent inclusion of IE 11 they mentioned some of deep technical challenges facing most web developers including;
  • Faulty browser detection not recognising IE as a mobile browser and giving the desktop experience
  • Using only old webkit-prefixed features that have been replaced by standards
  • Using proprietary webkit-prefixed features for which there is no standard
  • Using features that IE does not support with no graceful fall-back
  • Running into interoperability bugs and implementation differences in IE
Some of the most important issues that they raise include sites not detecting that IE on the phone is a mobile browser and subsequently providing desktop content.

Here are two examples


The first image represents a desktop experience while on the right is the mobile view as expressed by IE 11 on Windows Phone 8.1 Update. 



In addition this issue, the IE group indicated that one of the larger browser compatibility issues is touch enabled devices. The new method of using Pointer Events offer significant performance and functional advantages for multi-funtion sites that use mice, pens touch and other pointer inputs. This is compared with the legacy Touch Events  which the IE11 team have endeavoured to support as well. Following from these significant challenges, Microsoft has decided not to support all of the web-kit and vendor pre-fixed API’s and looks pretty committed to helping developers migrate their existing web code bases through their community outreach program and collaborating with the Mozilla webcompat.com effort.

Microsoft believes that the Web should just work for everyone, but there still looks like a lot work is required by everyone to achieve that goal.

References:

The Mobile Web should just work for everyone
http://blogs.msdn.com/b/ie/archive/2014/07/31/the-mobile-web-should-just-work-for-everyone.aspx

Monday, 7 July 2014

Server 2003 is new the Windows XP

As a grizzled veteran of many desktop migrations, I remember (all too well) the many pitfalls and challenges in migrating to Windows XP. Even worse, I also remember migrating to Windows 200. Which is really showing my age. Time to move on? No way. We are getting pretty good now at migrating desktops. We have automated workstation builds, large scale deployment platforms applications and we seem to get getting the update process working without causing major service outages with each month. 

Now it is time to focus on our server platforms. Microsoft has a rolling lifecycle policy that details when each platform will receive mainstream support, extended support and also details the final day of patches and bug-fixes to the specified platform. I have included an image from Microsoft’s support lifecycle web page that details the basic structure of how Microsoft supports its applications and development platforms.




As you can see from the chart below, for Microsoft’s Windows 2003 (R2) mainstream support has already ended. This means that though the platform will still receive security updates, Microsoft will no longer respond to feature requests. And, no more complimentary (free) support for Windows 2003.  Here are some of the details on the support lifecycle for Windows Server 2003.





Migrating to Windows 7 from Windows XP was a big problem with a host of associated technical and logistical challenges including;
  • refresh of desktop hardware was required
  • application compatibility issues were a significant technical challenge
  • potential complications from a new, more restricted security model were possible
  • a browser change (from IE6 to IE 7 or IE10) caused unforeseen migration issues

Now, with the current impetus to migrate from Windows 2003, we are again facing all these issues and the following additional challenges;
  • hand-crafted server builds and application installations are difficult to replicate
  • there is an increased business risk to higher numbers of users affected by server outages
  • database and other server connections and dependencies are more likely and more complex
  • older applications may no longer be supported
  • cross-dependency issues are exacerbated on newer 64-bit platforms

And if Windows 2003 end-of-life support wasn't enough of an issue, the following other technologies will expire also on the same day (July 15th, 2015);
  • Compute Cluster Pack: 14 July 2015
  • Forefront Client Security: 14 July 2015
  • Host Integration Server 2004: 13 January 2015 (I haven’t heard of this one inyears)
  • Internet Security and Acceleration Server 2004 Enterprise Edition: 14 April 2015
  • Internet Security and Acceleration Server 2004 Standard Edition: 14 October 2014
  • Microsoft Operations Manager (MOM) 2005: 13 January 2015
  • Systems Management Server 2003 and 2003 R2: 13 January 2015
  • Virtual Server 2005 and Virtual Server 2005 R2: 13 January 2015


According to HP, over 11 million systems are currently running Windows server 2003. That’s over 25,000 servers that need to be migrated each day before extended support expires.

The time to start planning is now!

Monday, 30 June 2014

Microsoft Security Baselines for Window 8.1 and IEII

As a nod to the idea that it's not just compatibility that you have to worry about, Microsoft has release their latest iteration security baselines for Windows 8.1, Internet Explorer 11 and Server 2012.

This collection of documentation and Group Policy Objects (GPO's) details a secure baseline for your server and desktop environments.

Here is a quick highlight of the topics included in this documentation pack;

  • Use of new and existing settings to help block some Pass the Hash attack vectors
  • Blocking the use of web browsers on domain controllers
  • Incorporation of the Enhanced Mitigation Experience Toolkit (EMET) into the standard baselines
  • Removal of the recommendation to enable "FIPS mode" 
  • Removal of almost all service startup settings, and all server role baselines that contain only service startup settings.

This documentation pack includes the following folders;

  • Administrative Templates
  • Documentation
  • GP Reports
  • GPO
  • WMI Filters
The two key sections in the Recommended Security Baseline Settings document (.DOC file) are the new settings in Server 2012 R2 and the removed (deprecated) settings for Windows and Internet Explorer.



Note: that this is a BETA version and is subject to change.

Thanks to Aaron Margosis's very nice MSDN blog for the update. 

Monday, 9 June 2014

Flash Compatibility in Internet Explorer 10


As like many of you, I have downloaded the Windows 8 and like a few of you, I have installed it on a number of machines, virtual environments and different hardware platforms. My DELL All-in-One is currently is my favorite as it supports a touch interface. That said, the Touch-enabled drivers are not quite there yet (gestures are not currently working) but otherwise the initial experience has been positive.

And now, for the real world: my middle child (of three) was trying to visit a flash based "Barbie dress-up" site (no, not one of my favorites, for those at the back) and things got a little more complicated. The site loaded in the desktop view (currently our default) but would not in the Metro side of things.

Doing a little reading, I found about the IE 10 Compatibility View list on MSDN which reads; 
"While any site can play Flash content in Internet Explorer 10 for the desktop, only sites that are on the Compatibility View (CV) list for Flash can play Flash content within Internet Explorer 10 in the Windows Metro style UI."
And further on;
"Internet Explorer 10 uses the CV list to enable specific sites to run with the Flash Player functionality supported in Internet Explorer 10. Microsoft manages and distributes the CV list and determines which sites go on the list. Decisions regarding how sites that require Flash Player are treated on the CV list are evaluated based on the quality of experience of the site in Internet Explorer 10, taking into consideration factors like performance, responsiveness, touch interaction, security, privacy, and battery life."

So, if you have Flash site, you need to submit it to Microsoft to get it on the CV list, and see it in its wonderful glory on IE10 Metro mode. You can submit your domain and site to Microsoft at the following address; iepo@microsoft.com

If you want to just get things working (my preferred approach) you can also edit the following registry entry; HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Flash\DebugDomain

If you are wondering what WILL NOT work under Flash for IE10, Microsoft has provided a rather long list including;
  • Camera
  • Microphone
  • Printing
  • Feature bookmark (for example, Flash Anchors)
  • Relying on double-click (double-click is consumed by the player, for zoom to fit, and not propagated to the Flash content as a double-click event)
  • Use of rollover and rollout event
  • Relying on P2P (Windows Metro style design guidelines disallows the creation of a socket server)
  • Relying on the following Flash touch APIs: Pan, Zoom, Rotate, Swipe, and PressAndTap

I am not a fan of Flash, but it makes sense for Microsoft to support Flash (with a heavy future focus on HTML5 and JavaScript) and it appears that they have come a reasonable compromise with Flash support on desktop mode and not for Metro.

Read more here:

Developer Guidance for Web Sites with Flash Content in Windows 8

Developer guidance for websites with content for Adobe Flash Player in Windows 8

Wednesday, 21 May 2014

Application Management for the rest of us

What does Application Management for the rest of us really mean?

I started my career in IT attempting to create the necessary tools and infrastructure to deploy large numbers of applications in a demanding and dynamic enterprise environment. Over the past 15 years I have progressed through a journey in automating as much of the application management process as possible. This process involved several stages including:
  • Discovery: Finding out who owns/wants/understands a particular application 
  • Application Packaging: getting the installation routines into standard and manageable format (e.g. MSI installer or App-V)
  • QA and Testing: ensuring consistent quality and compliance to the corporate standards
  • User Acceptance Testing: ensuring that users got what we they requested
  • Deployment: the actual delivery of the applications to the intended platform (both server and desktop)
  • Retirement: the process of removing or decommissioning applications that are no longer required

As you can imagine each of these steps requires technical skill, expertise and time to complete. And therefore, the cost for each stage and the aggregate of the entire process is expensive and risky.  In addition, like any non-core business process a potential distraction to the task of running a business. So, why do organizations go through this process?

I think that there are three reasons;
  1. Cost
  2. Risk
  3. Increased User Expectations

Creating a process that can be optimized, automated and quality checked will generally be cheaper in the long run if not immediately compared to an ad-hoc informal approach when applied to large-scale systems. If you know all of your users by name, you may not need an automated deployment tool. If you can’t count all of your offices on both hands, you definitely do. Added to the expected cost savings, most organizations will generally prioritize the risk of failure over anything else. And more recently, application users and owners expect a rapid and robust delivery process for their business critical applications. The bar has been raised with the perceived ease of installation and upgrades with Apple’s iPhone based applications. And, now large corporates are now expected to support many disparate systems and timescales that would not even be considered only a few years ago. 

And, what if I am not a large corporate?
Here is where life gets’ interesting. What if I only have 200 applications instead of 10,000? Do I still need a packaging process and deployment systems? With large-scale systems the cost saving are large and easily quantified. With smaller systems, the benefits may not outweigh the investment of standardized processes and automation technology. 

There are definite benefits to managing your application portfolio with tools and processes including;
  • Faster deployments - if business agility is important, getting applications deployed and updated quickly may be a key business driver
  • Lower support costs: sometimes difficult to measure, but standardized process and industry best practices generally lower IT supper costs
  • Regulatory compliance:  some industries will require high levels of processes and documentation that only automation tools can deliver

There are a host of other reasons, but most organizations benefit from reduced overheads, better business agility and are more profitable if they employ standardized, highly automated IT processes. If you are not doing, chances are that your competition will and will deliver a faster, better and cheaper product that you.

How can smaller organizations get these benefits without the associated high costs?
A new approach is needed. Through the use of new levels of automation, web-based self-service access and per-application pricing, organizations can benefit from the tools and technologies previously only enjoyed by the large corporate IT environments. 

We can raise the quality bar for smaller organizations IT systems while reducing the barriers to entry through;
  • Easy to use, web-based services (minimizing infrastructure requirements and investments)
  • Extensive process automation (saving time, and reducing costs)
  • Low-risk Pay-as-you-go usage models 

Watch this space, to find out more.