Showing posts with label Direct Access. Show all posts
Showing posts with label Direct Access. Show all posts

Tuesday, May 24, 2016

Difference between Intune Standalone and ConfigMgr hybrid mode (part 4)

Recently I did some blogposts about the difference using Intune Standalone or ConfigMgr hybrid mode.
You can find them here: part 1 / part 2 / part 3

For ConfigMgr hybrid mode I mentioned the following:
As for ConfigMgr hybrid mode, this must be done in Configuration items and baselines, where not sure when they arrive. Monitoring - deployments is not the right place also, given a 'Unknown' status most of times. Did a lot of compliance checks and reboots on mobile devices, but nothing seems to happen..

Trick is, you need to do some additional configuration. When policies in Intune are working immediately, they are in ConfigMgr not.
When creating configuration items in ConfigMgr, "Remediate noncompliant settings" is turned on by default.
When creating and deploying configuration baselines, this is not the case. "Remediate noncompliant rules when supported" is not turned on by default. Trick is, you need to enable this for making them active.

In the baseline deployment properties "Remediate noncompliant rules when supported" must be selected. I did change the schedule for 7 days to 5 minutes too. After that configuration was starting on mobile devices right away.

Why this isn't configured by default is the question? Without this setting you can wait forever for policies to come through..

Wednesday, May 11, 2016

Difference between Intune Standalone and ConfigMgr hybrid mode (part 3)

In an earlier blogpost i wrote about pros and cons between Intune standalone and ConfigMgr hybrid mode, and the difference in speed between both solutions. This because Intune standalone (SAAS) is very fast (few seconds, sometimes few minutes) on enrollment of applications and/or policies. With ConfigMgr hybrid mode this is way slower, and can take up to multiple hours (or more) for making it happen. This time I want to share something on difference for Windows and Windows Phone devices.

With Windows 10, Microsoft is saying that there is One universal app platform, One security model, One management system, One deployment approach, and One familiar experience. Unfortunately that's not true when using a Windows 10 Mobile, managed by Intune standalone or ConfigMgr hybrid mode.

When deploying applications from one of both solutions, you will see that sometimes it's needed to choose Windows, the other time Windows Phone. Some apps are available for Windows, but not for Windows Phone (or the other way around). Very confusing if you ask me! So you must choose between a Windows app package or Windows Phone app package. That's hard to explain to customers..

When choosing a Windows app package (like I did), applications will not be offered on Windows 10 Mobile. In my perception this is not a Windows Phone anymore, with a different Windows Phone store. So yes, you must still use Windows Phone app package to make them available on Windows 10 Mobile. Very confusing if you ask me. Where does this fit in the One unified app store across devices, One great experience model? But wait there's more..

Within the post: Windows 10: A Store That’s Ready for Business, Microsoft is mentioning the following: 'with Windows 10 we will deliver one Windows Store for all Windows devices'. But therefore the new web-based Store portal must be used. So open Windows Store for Business and start adding apps to your inventory. When signing in with your Azure account (or add it next to your Live ID) a new tab in the default Store will be present.

After that a new tab is present in Windows Store, with the company name used, with apps added in Windows Store for Business. Because it can take up to 24 hours for the app to get present in the Private store, you must be patience on this :-)

More on that in a next blogpost. Thanks for reading.
Read more on part 1 and part 2

Thursday, April 28, 2016

Difference between Intune Standalone and ConfigMgr hybrid mode (part 2)

In an earlier blogpost i wrote about pros and cons between Intune standalone and ConfigMgr hybrid mode. Is this post I will mention the difference in speed between both solutions. This because Intune standalone (SAAS) is very fast (few seconds, sometimes few minutes) on enrollment of applications and/or policies. With ConfigMgr hybrid mode this is way slower, and can take up to multiple hours (or more) for making it happen. This is very annoying indeed!
 
I'm using the SAAS solution myself; using it for demo purpose on my Windows 10 Mobile (Lumia 950). When doing enrollment on that and start a deploying applications and/or policies, they will be visible in a few seconds. Just have a look at some examples on that:
 
When deploying applications, or changing icons (or something like that), they are visible almost immediately.
 
When using Allow manual unenrollment (No), Intune cannot be removed from a Windows Phone or Windows 10 Mobile. Way better, because this isn't possible on iOS or Android devices, or special configuration is needed (iOS).
 
When using Allow application store for Windows 10 Mobile (No), the store isn't available anymore. Just an example how easy an application can be blocked, but again for Windows Phone only.
 
This for both the tile on start screen as for the start menu present on Windows Phones. They will be greyed out on start screen and start menu. Just want to see more off that.

When using Allow Camera (No), the following message is given, presenting a black screen when choosing OK. A message that the camera is blocked would be better I guess then presenting a black screen, but maybe it will be in future.

As for ConfigMgr hybrid mode, this must be done in Configuration items and baselines, where not sure when they arrive. Monitoring - deployments is not the right place also, given a 'Unknown' status most of times. Did a lot of compliance checks and reboots on mobile devices, but nothing seem to happen..

As mentioned in an earlier blogpost: Still I truly believe in ConfigMgr hybrid mode, having best of both worlds. But Microsoft still needs some development for a way better experience on that!

More on that in a next blogpost. Thanks for reading.
Read more on part 1 and part 3

Wednesday, April 20, 2016

Difference between Intune Standalone and ConfigMgr hybrid mode

When using Microsoft Intune, you can choose between Intune Standalone and ConfigMgr hybrid mode. Both have their own pros and cons. Microsoft is still recommending hybrid mode, because then you have best of both worlds. Point is, I'm not convinced anymore. Both ConfigMgr and Intune are great products, where Intune still need some development on new features. Customers are not always convinced about the solution, asking more enterprise features.
 
Having a look at my experience so far, I detect the following:
 
Intune standalone (pros):
-Easy to setup, Software As A Service (SAAS) solution;
-Can be managed everywhere with internet access;
-Very fast on enrollment of applications and/or policies (!);
-Can be used for both patch management & antivirus on endpoints with internet access;
-New features are released immediately.
Intune standalone (cons):
-With ConfigMgr in-place, two consoles for management;
-On some parts, less features then hybrid mode;
-You need to sign-in at every application change.
 
ConfigMgr hybrid mode (pros):
-Recommended configuration by Microsoft;
-Best of both worlds in a single management console;
-More features then Intune standalone;
-Deployment types and deployments are easier to handle.
ConfigMgr hybrid mode (cons):
-Less easy to setup; on-premises ConfigMgr infrastructure needed;
-Cannot be managed from everywhere, on-premises ConfigMgr console needed;
-Way slower on enrollment of applications and/or policies (!);
-Cannot be used for both patch management & antivirus on endpoints with internet access, because you need direct access or internet-based client management (IBCM) for that;
-New features will released slower in hybrid mode.

So yes, Microsoft is working on the feature part, and new features are available in ConfigMgr hybrid mode sooner. This because of the Service Connection point in ConfigMgr Current Branch.
But what's most annoying, You cannot have both patch management & antivirus on endpoints with internet access, because a ConfigMgr agent will be present on the device. Not an Intune agent, pointing to a SAAS solution. Therefore additional solutions like direct access or internet-based client management (IBCM) are needed.

And overall; when deploying applications and/or policies from Intune standalone, they are applied in few seconds. Within ConfigMgr hybrid mode it can take multiple hours (or more) when something happens. Still I truly believe in ConfigMgr hybrid mode, having best of both worlds. But Microsoft still needs some development for a way better experience on that! Hope they will soon :-)

More on that in a next blogpost. Thanks for reading.
Read more on part 2 and part 3

Monday, July 6, 2015

Microsoft Surface Pro 3 experience after Windows 10 Build 10159 installation

Recently I upgraded my Surface Pro 3 to Windows 10 Build 10159. With Windows 8.1 Update 1 (which is default installed) the device was making a lot of noise when plugged in. Also with multiple programs open (most of time Internet Explorer and/or Adobe Reader) it was making a lot of noise too. After many firmware updates the issues was still not gone. In March this year, I wrote the following about this behavior:

As mentioned in the links below, this is being caused by the Windows Installer Module and the Windows Installer Module Worker, which start in the background at random times and cause the CPU to work at higher speeds. This causes the heat and the fans to kick into overdrive. When stopping these processes in Task Manager, my Surface is as quiet as on battery in seconds! Hope that this issue is fixed when moving to Windows 10 in a few months. Otherwise a hardware replacement may be needed to resolve this.

Last week I updated my device to Windows 10 Build 10159. After the update the issue is gone indeed. Even during a stress test (screenshot) at almost 100% CPU the fan makes less noise than before. Happy that this issue seems to be gone now! :-)

Downside is, Out of sleep (when in sleep mode, it will wake up. for it seems because of the keyboard?) is back again. This issue was solved on Windows 8.1 after installing a system firmware update.
Sometimes my device will go out-of-sleep, which is annoying because all open programs will be gone afterwards. Strange thing that no hibernation is used for this? For it seems the device stays on, till battery power is reached a critical state. After that the device turns down. Lucky me this happens around rarely and not always.


Furthermore I really like Windows 10, and hope to implement it many times this year already! Windows 10 (a.k.a. Windows as a service) is the new generation of Windows. No specials (issues or other things) to mention on Surface Pro 3.

Update 7-7: Still during installing updates (Windows 10 Build 10159 to 10162) my device makes a lot of noise. Next device will be a fanless one :-)

More information about the fan blowing:
Fix found for Microsoft's Surface 3 overheating issues
Excessively loud fan, constant overheating during idle and light tasks
Tools To Simulate CPU / Memory / Disk Load (for testing purpose)

More blogposts on this topic:

Microsoft Surface Pro 3 first experience
Microsoft Surface Pro 3 second experience
Microsoft Surface Pro 3 experience after 5 months

Thursday, March 12, 2015

Microsoft Surface Pro 3 experience after 5 months

Since November last year I'm using a Microsoft Surface Pro 3 as primary device for my daily work. I wrote multiple blogposts about my experience in November and December. For over 5 months I'm very happy with my choice, never had a doubt I made the wrong choice here. But still there are some minors left. Let's have a look at my experience so far. Pro's and Con's are taken from my post before.

Pro's (changes in bold)
-Fast (with i7 CPU, i5 performance don't know)
-Quiet (on battery always, on power not all the time)
-Battery (approx. 8/9 hours with Office and Internet open)
-12" display (sharp, resolution, pen support)
-Pen (great in presentations)
-Weight (1,1 kg with keyboard)
-New generation device, high wow factor!
-Windows 10 upgrade coming (waiting for RTM to upgrade)
-Kickstand (can be placed in all positions)
-It's both a notebook and tablet


Con's (changes in blue)
-Fan blowing (on power only, not all the time)
As mentioned in the links below, this is being caused by the Windows Installer Module and the Windows Installer Module Worker, which start in the background at random times and cause the CPU to work at higher speeds. This causes the heat and the fans to kick into overdrive. When stopping these processes in Task Manager, my Surface is as quiet as on battery in seconds! Hope that this issue is fixed when moving to Windows 10 in a few months. Otherwise a hardware replacement may be needed to resolve this.
-Out of sleep (when in sleep mode, it will wake up. for it seems because of the keyboard?)

Sometimes my device will go out-of-sleep, which is annoying because all open programs will be gone afterwards. Strange thing that no hibernation is used for this? For it seems the device stays on, till battery power is reached a critical state. After that the device turns down. Lucky me this happens around rarely and not always. Hope this issue is fixed also when moving to Windows 10.
-One USB port only (far too little to connect multiple devices!)

Last week I ordered a Microsoft Arc Touch Mouse Surface Edition, because of this. The mouse works really fine, and benefit of it is a free USB port which I have now. Again no doubt I made the wrong choice here, and it looks great next to my Surface!
-Keyboard function keys (sometimes Fn is needed, sometimes not, which is confusing)

Well, you will get used to it ;)
-There is no insert key on the keyboard (mentioned by @scambler)
Didn't miss it myself actually. What I am missing on modern devices is the lack of pause key, which is really handy during PXE boot. Just have a look HERE for a workaround on the insert key.

More information about the fan blowing:
Fix found for Microsoft's Surface 3 overheating issues
Excessively loud fan, constant overheating during idle and light tasks
Tools To Simulate CPU / Memory / Disk Load (for testing purpose)

More blogposts on this topic:
Microsoft Surface Pro 3 first experience
Microsoft Surface Pro 3 second experience

Friday, December 5, 2014

Microsoft Surface Pro 3 second experience

One month ago my new work device was delivered, a Microsoft Surface Pro 3. I decided to order one because of great look & feel, very good feedback (reviews) and Windows 10 in pipeline. A blogpost about my first experience can be found HERE. Let's have a look at my second experience, after using it for over one month now. Most of my experiences are positive, but some negative ones also!

Still very happy with my device, it's fast, quiet, and have a good battery. It's both a notebook and tablet. Let's have a look!


Pro's
-Fast (with i7 CPU, i5 performance don't know)
-Quiet (on battery always, on power not all the time)
-Battery (approx. 6/7 hours with Office and Internet open)
-12" display (sharp, resolution, pen support)
-Pen (great in presentations)
-Weight (1,1 kg with keyboard)
-New generation device, high wow factor!
-Windows 10 upgrade coming (free?)
-Kickstand (can be placed in all positions)
-It's both a notebook and tablet

Con's
-Fan blowing (on power only, not all the time)
-Out of sleep (when in sleep mode, it will wake up. for it seems because of the keyboard?)
-One USB port only (far too little to connect multiple devices!)
-Keyboard function keys (sometimes Fn is needed, sometimes not, which is confusing)

That's it for now. As you can see more pro's than con's are mentioned, so my total experience with the device is still very good. Hope that Microsoft can fix fan blowing with a future system firmware. Then it will be even better. Microsoft did a great job here!

Monday, November 3, 2014

Microsoft Surface Pro 3 first experience

Last week my new work device was delivered, a Microsoft Surface Pro 3. I decided to order one because of great look & feel, very good feedback (reviews) and Windows 10 in pipeline. In the past I did have a Surface (1) RT, but that was not actually what I wanted. This device however is a real notebook killer, no need to have a notebook next to this one. Great to experience the whole Windows look & feel, with touchscreen and pen functionality. With Windows 10 in pipeline this will become even better! Really happy with my choice here ;)
 
 
Because Surface Pro 3 is delivered with Windows 8.1 Pro, and Enterprise is needed for Direct Access functionality, I upgraded my device. Just start an inplace upgrade, so no need to format or remove anything. After the upgrade type in the new Windows Enterprise key and you're done! Just leave the recovery partition inplace, so when there's something wrong you can start a rollback. I did that once, so just leave it when needed sometime. After the upgrade however I did not see Windows 8.1 Update 1 features setup. This will be done at a later moment, when more software updates are installed.
 
When the power button on the start menu is needed, use registry instead. For it seems the power button is not displayed always, given the fact the operating system can be used in desktop or tablet mode. Just start registry editor and browse to "HKEY_CURRENT_USER > Software > Microsoft > Windows > CurrentVersion > ImmersiveShell". Expand the tree and create a new key called "Launcher". Create a new DWORD (32-bit) value here called "Launcher_ShowPowerButtonOnStartScreen". Give it a value of "1" to activate it and start the device again. Now it will be visible at once.

Nice thing that I worked whole day with type cover and pen. No mouse? Actually I didn't miss it today. With the pen you can do all daily operations also, without the need for a mouse. Curious if I switch back to a mouse or using the pen instead. Time will tell ;)

Can't wait for Windows 10 to complete my Surface experience! Expect more to come in a few weeks, when I did more on my device!
-My personal experience with Windows 10 Technical Preview
-Windows 10 Technical Preview updated with 7,000 changes and fixes  

When the pen isn't working right (open OneNote with a single click and Screen Capture with a double click) check these guides too:
-Quick Things to Try If Your Surface Pro 3 Pen Doesn’t Work
-Deploying Surface Pro 3 Pen and OneNote Tips
-Troubleshoot Surface Pen

Thursday, October 9, 2014

My personal experience with Windows 10 Technical Preview

Last week I did the upgrade from Windows 8.1 Enterprise (which is needed for Direct Access) to Windows 10 Technical Preview. When looking for a download just look here. In my case the installation was done in 15 a 20 minutes on SSD drive, not too bad! After the upgrade everything seems to work okay, applications and data were still in place, and new functionality was added. Let's have a look at a few new (and really cool) features!

First there is the new Start menu (where everyone is talking about). Personally I think it's great to have it back now. No more switching between desktop and tiles is easier then loosing focus on desktop everytime. The combination of applications and apps is a good match, and looks/feels good. > Welcome back Start menu!

When you want to change back to tiles or have a tablet device, the Start screen (known from Windows 8.x) can be displayed as well. Just use what you prefer, and fits best on the device you are using. Windows 10 is looking at the device you're using and switch on Start menu or Start screen by default. Seems okay to me!?

When looking at the task bar you will see a few new icons added. They are all handy for sure. First there is 'Search' to find data (documents for example), which is much easier then before. Second there is 'Task view', where you can quickly see which programs or folders are opened/active. Just click the window you want. Another one is 'Favorites', where you can find most used and opened files and folders (e.g. Favorites, Frequent folders and Recent files).

Another great feature is when moving a task to the left- or right side of the screen. In the other part an overview is displayed on other active tasks. Just click a task, and that one will be showed in the other part of screen. When dragging a task to a random corner, it will be placed there, without showing other active tasks. In that scenario you will see 4 opened tasks with only a few clicks. You can also generate a new desktop where (active) programs are not visible at once. Just start tasks on multiple desktops with this!

Applications and apps can run both in same screen now, instead of switching from desktop to tiles screen. Apps can run in a full windows or in a window as shown in the screenshot. Much easier that way if you ask me. No need to go left above to switch from a fullscreen app to desktop (remember?), when working on a fat client device. Things are now as they should be in the first place.

Maybe I missed some more features, but for me these are enough reason to move on to Windows 10 already! No need to worry about things like Direct Access, Office 2013 or other features. All seems to work okay! Expect a Final release in May 2015 and multiple Preview versions (Consumer Preview, Release Candidate) in between.

Windows 10 may be the best OS since Windows 7 finally! Windows 10: One product family, One platform, One store. Love it!

Update: Back to Windows 8.1 now because of Privacy Statements for Windows Technical Preview. But for the few days I used it, I personally think that the OS is great already. Just want some more features like Cortana, and it will be even greater. Thanks!

Monday, March 3, 2014

How to force an IP-HTTPS connection on a DirectAccess client

Today Direct Access wasn't working because of IP-HTTPS malfunction. Normally I'm using the following commands when Direct Access isn't working, this because off multiple Proxy changes a week.
  • Restart "Network Location Awareness" service
  • Restart "IP Helper" service
  • "netsh dnsclient show state" (inside/outside office)
  • "netsh interface httpstunnel show interfaces" (connected/not connected)

But this time nothing seems to help. The error message (this time) were: Interface Status: IPHTTPS interface deactivated.
 
Lucky me I found the following blogpost: Hidden Microsoft
It mentions:  You should try using netsh to disable Teredo.

For example, if you execute the following command: "netsh interface teredo set state disable". You will in fact disable Teredo. Provided that your IP-HTTPS solution is working, the Direct Access client will then switch over to IP-HTTPS. You can verify this using the following command: "netsh interface httpstunnel show interfaces". Now, to re-enable Teredo you would use the following command: "netsh interface teredo set state default".

After that everything went fine again. Strange thing however we don't use Teredo at all, but still this can be the solution! ;)