Tuesday, February 22, 2011

Turn existing scripts into dynamic and reusable tasks

A lot of administration, particularly on servers, is used with scripts either with Powershell, VB or Secure Shell (SSH).  You can basically do anything with scripts and more and more features are exposed to scripting.

The problem with scripts is that they are usually hard to maintain and troubleshoot. They are rarely documented which results in painful hand overs to new administrators. Scripts are also often created for one distinct purpose and cannot be reused.

So how can you take existing scripts and make them dynamic and reusable?

The answer is RES Automation Manager.

In RES Automation Manager you can easily import your existing scripts and turn them into a module/task. This task can then be scheduled in a controlled fashion by administrators with no administrative rights on the systems the script is being executed on. By using parameters in RES Automation Manager the scripts can be generic, dynamic and reusable. I will explain exactly how it works in the below video.



If you want to know more on how to get in control, please visit RES Software on the web.


Patrik

Query uptime and perform controlled reboots

I got a question last week from a company if they, with RES Automation Manager, could easily query uptime on their Windows servers and then perform a controlled reboot.

I have created a video that demonstrates how this can be done.



Beware that this is a very powerful tool and could cause unwanted results if used in the wrong way.

This can be avoided by delegating control and setting a scope on possible systems where the task can be executed.

If you want to know more about RES Automation Manager please visit RES Software on the web.

/Patrik

Monday, February 21, 2011

How to change local administrator password in less than 60 seconds on all computers

In this video I demonstrate how easy it is to change the local administrator password on all servers and desktops in less than 60 seconds.

With RES Automation Manager making changes like this is as easy as 1 2 3!

This module can be delegated to help desk and the actual change is done without them having local administrative rights. All changes are audited.



For more information, please visit RES Software on the web.

/Patrik

Wednesday, February 9, 2011

How to remove local admin rights and elevate rights when needed

Removing local administrator rights from desktops and laptops have a huge impact! According to Gartner you could reduce the TCO with as much as $1237 per user per year! It could also, according to Microsoft, mitigate the effect of 92% of critical vulnerabilities.

There are a lot of reasons why local administrative rights is needed. It could be legacy applications, access to specific Control Panel applets or applications that need to change hardware settings.

What are we waiting for? Let's go ahead and see how it can be done.

RES Workspace Manager 2011 have the possibility to add Dynamic Privileges to specific processes for specific users.

In the video I demonstrate how it is configured and the way it works.




If you want to know more, please visit RES Software.

/Patrik

Friday, January 21, 2011

How to enforce Separation of Duties in a Windows Server environment

Some regulations require organisations to enforce separation of duties. In a Windows server environment this is very hard to achieve. When doing maintenance on a Windows server and logging on to the server, you automatically have access to all applications and resources. There is no way of giving different user groups access to individual application sets. If you have to do maintenance on a domain controller it is even worse. You now have been given the keys to the kingdom.

Here´s an excerpt from Wikipedias definition of Separation of Duties:

In information systems, segregation of duties helps reduce the potential damage from the actions of one person. IS or end-user department should be organized in a way to achieve adequate separation of duties. According to ISACA's Segregation of Duties Control matrix [3], some duties should not be combined into one position. This matrix is not an industry standard, just a general guideline suggesting which positions should be separated and which require compensating controls when combined.

Separation of duties should prevent any individual to have access to a single complete system.

With RES Dynamic Desktop Studio, life will become a lot easier. You can make sure users only can access applications tied to their duties, and when they have to perform these duties, an approval process need to take place.

In this demo I show how this could work.



Please visit RES Software for more information about RES Dynamic Desktop Studio.

/Patrik

Wednesday, January 19, 2011

RES Virtual Desktop Extender (VDX) Demo

I have produced a short video demonstrating the capabilities of RES Virtual Desktop Extender. RES Virtual Desktop Extender technology let users seamlessly access local applications from their virtual desktop or terminal server start menu. In the video I demo the difference looking at a HD video on your virtual desktop with and without VDX.




Another reason for using this technology, apart from resource intensive applications, is applications that needs access to local hardware. How do you burn a DVD from your virtual desktop?

For more information about this technology, please visit RES Software.

/Patrik

Monday, January 10, 2011

How do you secure a virtual desktop environment?

Securing central environments like Terminal Server (with or without Citrix) has always been a challenge due to the fact that many people are accessing the same computer. Worst case you have to have multiple Terminal Server farms to adapt to different security needs. This requires complex configuration and management.  The challenge is the same when it comes to VDI.

A successful and cost effective VDI implementation requires as few images as possible running in stateless/non-persistent mode. Traditional desktop management tools is not enough.  Traditional security based around the device will also fall short. Since the user's desktop now runs in the data center, knowing the physical location of the user is critical.

This also brings us to another question; how do you troubleshoot an environment where desktops reverts back to the previous state when the user's log off? More about this in my next blog article.

What you need is dynamic context aware computing. Settings, configuration and security based around the user's context will ease the adoption and management of virtual desktop infrastructures.

In this movie I demo context aware security to comply to some security regulations where applications only are allowed to run at specific physical locations. By having a context aware and dynamic VDI environment, changes in the user's context (in this case the location) will automatically update the workspace and make sure security regulations are followed.



Please watch my previous video about User Workspace Management to get more details about the concept of context aware computing.

/Patrik