Wednesday, October 29, 2014

Microsoft reveals ramped-up security offerings for Windows 10 and Office 365 across multiple devices

Microsoft kicked off its TechEd Europe conference in Barcelona today by joining up the dots with its security plans for Windows 10, as well as offerings for Microsoft services on mobile devices in the nearer future.
Joe Belfiore, corporate vice president of PC, tablet and phone, explained how Windows 10 will "significantly improve system protection against modern security threats".
Further reading
Windows 10 "will enable you to secure the device and the code that's running on any device you deploy" as well as "give you some terrific tools to satisfy end users" and to "protect user identities against all the types of identity theft we're hearing about," Belfiore told delegates.
"In Windows 10, you'll be in control of any of the code that's authorised to run on any device. This way of securing the device means that - by policy - you decide that only signed code runs - that you've signed, or the OEM, or even only Microsoft-signed code," he explained.

Belfiore showed the user experience as including only authorised apps on a custom-built menu. "Default actions" he pointed out, are still simple to carry out, but non-default actions are embedded into the experience without confusion or obstruction.
For example, when a user was about to paste sensitive information from a corporate document into Twitter, it was immediately disallowed.
But the policy could be further customised to instead flash up a message - and invitation to provide a reason - that information from a secure document was posting to Twitter and that the IT department would be informed.
"Because the platform is the same across devices," explained Belfiore, "this works across all of them."
Belfiore also showed two-factor authentication using a phone as the second factor for login, which he reminded delegates was "inexpensive for IT managers" as well as no longer reliant on a password "stored on some server".
The security conversation didn't stop here, as enhanced features for managing mobile devices were then unveiled - beyond devices using just the Windows operating system, and into devices - such as the iPad - just running Microsoft software such as Office 365.
Julia White, general manager of Office 365, demonstrated touch-controlled MDM [mobile device management] of Office 365 on an iPad. App-wrapping will also be featured, as well as secure mobile apps.
"Users want access to all their information, everywhere," said White, explaining that, especially since the launch of Office on iPad, full control via this medium has been one of the most requested functions.
Android will also be included at rollout.
The Office 365 management functions, and the SDK to accompany it, are expected in the first quarter of 2015, while the Windows 10 features will obviously roll out with the OS - though whether they'll all arrive on launch day remains open to speculation.

Managing Exchange Online using Server 2012 R2 Essentials Experience Role (Part 1)

Introduction

Microsoft announced Windows Server 2012 Essentials back in the summer of 2012 as the next version of what used to be called Small Business Server (SBS) Essentials. This was, in many ways, the end of an era.
SBS was very popular as it was without a doubt a great platform: it contained in one box all of the elements a business could need such as the server’s operating system and management tools, together with SharePoint Server and Exchange Server. However, the two main problems with SBS were its 25 licenses limit and the fact it did not provide an easy upgrade path for companies once their needs grew larger than what SBS could handle.
Since SBS 4.0 launched back in 1997, e-mail functionality was provided in all versions of SBS by having Exchange Server installed on the SBS box itself. Eventually, this changed when Microsoft divided SBS 2011 into Standard (with Exchange built-in) and Essentials (without Exchange built-in).
Windows Server 2012 Essentials has been designed to work with three different types of e-mail systems:
  • Office 365;
  • Hosted Exchange;
  • On-premises Exchange.
The first two are very much what SBS 2011 Essentials was also designed to do. Through add-ins in the Essentials console, administrators could manage a large part of the e-mail system even though it was hosted in the cloud. The last one, however, is different as on-premises Exchange is not Exchange built into the SBS server itself, but a separate Exchange server. This has been the biggest complaint about Windows Server 2012 Essentials: the lack of Exchange and SharePoint.
On the other hand, Windows Server 2012 Essentials running on the right hardware can provide small businesses with everything they need to continue managing most of their IT infrastructure from one box. It may not be as simple to set up, but it does offer greater flexibility for small businesses to choose on-premises or cloud-based solutions, migrate from one to the other, or rely on a hybrid of both.
But we are not here to talk about Windows Server 2012 Essentials, but instead explore the new Windows Server 2012 R2 Essentials Experience Role.
Advertisement

Windows Server 2012 R2 Essentials Experience Role

Windows Server 2012 R2 Essentials is an ideal first server for small businesses with up to 25 users and 50 devices. For organizations with up to 100 users and 200 devices, we can now use a Windows Server 2012 R2 server with theWindows Server Essentials Experience role installed.
This role, which can be installed on a “normal” Windows Server 2012 R2 Standard or Datacenter edition server, has the following limitations:
Windows Server 2012 R2 EssentialsEssentials Experience role in Windows Server 2012   R2
Must be the domain controller at the root of the forest and domain, and must hold all the FSMO roles.Does not have to be a domain controller if it is installed in an environment with a pre-existing Active Directory domain.
Cannot be installed in an environment with a pre-existing Active Directory domain.If an Active Directory domain does not exist, installing the role will create an Active Directory domain, and the server will become the domain controller at the root of the forest and domain, holding all the FSMO roles.
Can only be deployed into a single domain.Can only be deployed into a single domain.
A read-only domain controller cannot exist in the domain.A read-only domain controller cannot exist in the domain.
Table 1
Image A major disadvantage that existed   until very recently, was that the online services integration features of the Essentials Experience role, including Azure Active Directory and Office   365, were only supported in environments with a single domain controller...   In environments with more than one domain controller, integration of these   services was blocked due limitations in the user account and password   synchronization mechanism. This has finally been overcome with the release of   the Windows August Update, which added support for both Azure Active   Directory integration and Office 365 integration features in domain   environments consisting of a single domain controller, multiple domain   controllers, or Windows Server Essentials as a domain member server. For more   information, please refer to http://support.microsoft.com/kb/2974308.
When we install the Windows Server Essentials Experience role, we can take advantage of all the features that are available in Windows Server 2012 R2 Essentials without the locks and limits enforced in it. It enables organizations to:
  • Protect servers and clients’ data by backing up servers and client computers within the network using Windows Azure Backup;
  • Manage users and groups through the server’s Dashboard. In addition, integration with Windows Azure Active Directory enables easy data access for Microsoft online services users (such as Exchange Online and SharePoint Online users) through their domain credentials (password sync);
  • Store company’s data in a centralized location;
  • Integrate with Microsoft online services such as Exchange Online, SharePoint Online and Windows Intune:
    • Integration with Office 365 enables administrators to synchronize and manage Office 365 user accounts and access through the Dashboard;
    • Integration with SharePoint Online enables administrators to create and manage SharePoint libraries through the Dashboard.
  • Use the Anywhere Access functionalities on the server (such as Remote Web Access and virtual private networks) to access the server, network computers and data from remote locations in a highly secure manner;
  • Access data from any location and on any device by using the company’s customized web portal (through Remote Web Access);
  • Manage ActiveSync mobile devices that access company’s e-mail by using Office 365;
  • Monitor network health and obtain customized health reports.
As the title of this article suggests, we are going to explore how to manage Exchange Online using the Windows Server Essentials Experience role.

Essentials Experience Role and Office 365

Windows Server 2012 Essentials and the Essentials Experience role build on the previous Office 365 Integration Module for SBS 2011 Essentials. This option is now part of the core product (not a separate download) and provides a seamlessly integrated management experience on Essentials for customers who are using Exchange Online.
On top of the core feature set that was included in the Office 365 Integration Module for SBS 2011 Essentials, such as integrated user account management and automatic user password synchronization, Microsoft also made a few enhancements to make the experience better:
  • Support for multiple e-mail addresses. Having multiple domains and/or assigning multiple e-mail addresses to a single user are common scenarios even for small businesses. Now it is finally possible to easily do that from within the Essentials’ Dashboard;
  • Improved Office 365 domain configuration wizard. In the Office 365 Integration Module for SBS 2011 Essentials, administrators were required to configure Remote Web Access (RWA) when configuring a domain for Office 365, which caused a lot of confusion. For example, administrators had to provide an SSL certificate which was not actually needed by Office 365, but was required by RWA. Now these two have been de-coupled. Another improvement is the option to configure a different domain name for Office 365 and for RWA, allowing small businesses to continue to use the same free domain names like letsexchange.remotewebaccess.com for RWA on Essentials and a different domain name for e-mail in Office 365;
  • Display mailbox usage information. The Office 365 tab on the Essentials Dashboard now shows the mailbox usage information.
Now that we know what the Windows Server 2012 R2 Essentials Experience Role is, in the next article we will be installing it and integrating it with Office 365.

Conclusion

In the first part of this article series, we started by looking at Windows Server 2012 Essentials and the new Windows Server 2012 R2 Essentials Experience Role. In the next part, we will be installing it and integrating it with Office 365.

Mobile Malware Takes Victims by Surprise

Malware writers behind Koler, a bad app that attacks Android devices, have upped their game with a new variant of the pernicious program.
In its original version, Koler hijacked phones it landed on and wouldn't set them free until a ransom was paid. This latest strain of the malapp also does the ransomware thing, but it takes its malignancy a step further.
"This version self-replicates," Denis Maslennikov, a security analyst withAdaptiveMobile, told TechNewsWorld. "This is the first time we've seen self-replicating ransomware on Android."
After a user downloads the new Koler to a phone, the software commandeers the mobile's address book and spams everyone in it -- only it doesn't look like spam to the contacts because the SMS message is coming from a trusted source.
The message tells targets that a photo page has been created about them on the Web and includes a link to the page. After landing on the page, a target is directed to download and install a photo viewer to see the images. Following those instructions will infect the target's phone with Koler.

Toothless Threats

"This is big jump in Koler's propagation mechanism," Maslennikov said. "Before it was just hiding on websites. Now it's actively spreading to all your friends."
Although mobile ransomware can be frightening to someone unfamiliar to its workings, the malware is tame compared to its computer counterpart.
For example, Koler claims to encrypt all the data on a phone. However, it doesn't do that, so the data is always recoverable from the phone without any dependence on Web predators.
Moreover, removing the malware is relatively easy. You can reboot Android in safe mode and kill the malignant program using standard application-removal tools.
"If you reboot the phone normally, it's always going to come back into the ransomware," said Cathal McDaid, AdaptiveMobile's head of data intelligence and analytics.
"The typical user isn't going to know that, so they may go to extremes and do a factory reset, which will work as well -- but they will lose all their data," he told TechNewsWorld.

Bell Tolling for Passwords

While complaints about passwords as a way to authenticate users abound, progress on finding a substitute for them has been glacial. Last week, though, there were signs that was changing.
Microsoft plans to build two-factor authentication into the next version of its desktop operating system, Windows 10, ZDNet reported. It will be based on standards developed by the FIDO Alliance.
Owners of any device running it will be able to enroll the device as "trusted" for the purpose of authentication, according to the report.
In addition, the owner creates a PIN for the device. The PIN can be any combination of letters and numbers.
If PINs are compromised in a data breach, it won't do the thieves much good. When they try to use them to obtain online services, they won't have the associated devices to authenticate their identity. Conversely, if devices are stolen, the thieves won't have the PINs for authentication.

Google Dongle

Meanwhile, Google also floated a two-factor authentication scheme using a USB security key.
Google already has two-factor authentication via SMS messaging, but the USB approach will give its users another option.
Initially, the key will work only with Google's Chrome browser. With the key, you don't have to fuss with any codes. You plug the key into a USB port, wait for a prompt, and tap the key to access your Google accounts.
The key also incorporates authentication technology from the FIDO Alliance.
"The idea here is to move away from just using a password to log into your email, your system, your network," Aryeh Goretsy, a researcher with Eset, told TechNewsWorld.
"What we've seen in the past is a bunch of attacks where people's accounts have been compromised," he said. "So the goal here is to remove the weakest link, which is the password."

Making NFC Respectable

Near-field communication has been around for some time, but it has failed to capture a lot of consumer interest or confidence in its ability to secure mobile transactions.
For example, by a two-to-one margin, consumers give lower security ratings to NFC transactions than those performed with magnetic strip cards, suggests a survey released last week by Phoenix Marketing International.
Apple might be able to change that perception with its Apple Pay system, however. That's because the scheme depends on more than NFC alone for security.
"Apple delayed committing to NFC for a long time so when it entered the market, it could do so with a whole security platform," said Greg Weed, PMI's director of card research. That platform included a secure element chip inside the phone and a fingerprint scanner outside it.
Before Apple Pay, merchants, vendors and card issuers debated what kinds of rewards and enticements were needed to get consumers to use NFC devices. Apple Pay has changed that.
"What it did is take the idea of security and make it the benefit of the platform," Weed told TechNewsWorld. "That's changed the conversation."

Win10: Enough to Convince You it’s Time for a Client Upgrade?

Microsoft had high hopes for Windows 8, but those expectations haven’t quite panned out as planned. As of September, according to NetMarketShare.com statistics, Windows 8/8.1 only had a combined total of 12.26 percent, considerably less than twelve-year-old Windows XP (which garnered 23.87 percent) and far less than its immediate predecessor, Windows 7, which still has more than half of the desktop market share (52.71 percent). This is despite the fact that Windows 8 has been available for almost two years at the time of this writing.
In addition, a large proportion of those machines that are running Windows 8 and 8.1 are consumers’ computers that were bought this past year with the new version of Windows already installed. The majority of businesses have resisted upgrading, and there are several different reasons given for this. One is simple and has nothing to do with the merits of the operating system itself: many companies have adopted an every-other-version OS upgrade policy, and many others tend to avoid upgrading client operating systems, especially, until the one they’re currently running is out of support. Thus we saw many businesses that didn’t move from Windows XP to Windows 7 until Microsoft dropped support for the former in April of this year.
It makes sense from a bottom-line point of view. The cost of upgrading several hundred or several thousand machines to a new OS is significant and includes not just the licenses but in some cases hardware upgrades that are required to run the new operating system, as well as a great deal of administrative overhead, lost productivity as users navigate the inevitable learning curve, and the extra burden on help desk/tech support personnel dealing with user queries and troubleshooting the problems they get themselves into until they become more familiar with the new way of doing things.
Therefore, unless there is a compelling reason to upgrade – such as a real killer feature that will greatly enhance the user experience or important new security mechanisms – companies frequently opt to “sit this one out” when a new OS comes out. Even if they’re considering rolling it out, many will wait a year or more to allow for someone else to find the bugs and for the vendor to fix them.
Of course, this isn’t the only reason businesses don’t upgrade each time Microsoft issues a new release of Windows. There is also at least a perception that for a long time, every other version of the OS has been a failure, with Microsoft coming out with something drastically new and not very well implemented, then listening to consumer feedback and refining it in the next version. Windows XP was well-liked by most users after they got acquainted with it (although I can well remember the hue and cry when it first came out, mostly about its “bubble gum looking” interface). Vista was disparaged as a big flop, thanks to its resource-hogging behavior that made it run like a slow pig on less powerful machines and its in-your-face implementation of User Account Control.

Windows 7 addressed both of those complaints, and more, and was pretty well accepted by both individual users and the enterprise world. Then along came Windows 8 and upset the apple cart again. By taking away the Start button and Start menu that had been the primary basis of navigation since Windows 95, Microsoft invoked the ire and ridicule of a large percentage of its user base.
Yes, the new tiled interface worked great with tablets and touch screens, but unfortunately most business users and many home users were still working with traditional desktop machines, and the mouse/keyboard experience on Windows 8 left a lot to be desired in the eyes of most of those users. Yes, there are third party utilities – both paid and free – that can be installed to restore the Start button and menu, but many consumers weren’t aware of them and many of the more tech-savvy were annoyed at having to install an add-on to gain back the functionality that was once included in Windows out of the box.
Windows 8.1 was released close to one year after Windows 8, and was billed as a major update (i.e., more than a service pack but less than a version upgrade). It added back the Start button, but in an unsatisfying form, as the button only takes you to the hated (by desktop users) Start screen rather than producing the Start menu for which everyone was clamoring.  Since it’s a free upgrade, most of those who were running Windows 8 installed it, but very few of those who were running Windows 7 saw enough of an improvement to make them decide to make the move.
On September 30th, Microsoft held an event in San Francisco, aimed primarily at enterprise customers, to introduce the next real version upgrade, which they’re calling Windows 10. Some have speculated that the reason for skipping number 9 was to put more distance between the not-very-popular Windows 8 and the next iteration, formerly known by its code name Threshold. They also made a technical preview available for public download.
Immediately, most of the tech press rejoiced. The Start menu is back, albeit in a new “Modernized” format that combines the old favorite apps and search box with a panel of Modern UI tiles that can be customized. This makes life much easier for the many desktop users who felt lost without the menu (although most of us power users had long since installed Start 8 or Classic Shell and gone about our business).
The Start menu isn’t the only enhancement in Windows 10, but it’s the one getting most of the attention. Reviews from those testing the new OS have mostly been at least cautiously optimistic. I’ve been working with it since the day after it was released and so far, I like what I see. I’ll be doing a fuller review article for WindowsNetworking.com in the near future. Meanwhile, the big question is whether there’s enough there to persuade companies that it’s time to let go of Windows 7 and take the upgrade plunge this time, when Win 10 becomes generally available sometime around the middle of next year.  Write and tell us what you think. 

Tuesday, October 28, 2014

Tips and Tricks for Network Users

Here I share some tips and tricks relating to networking, but mostly involving user functionality rather than the administration side. You might find a technique or idea that can save you time and frustration. You may find some to share with non-IT network users as well.

Set an alternate IP configuration

If one of the networks you connect to uses static IPs, consider using the Alternate Configuration support natively provided in Windows. You can define the IP settings (including subnet mask, default gateway, DNS, and WINS) that are used when connecting to a network that doesn’t have DHCP.
In other words, if the network doesn’t hand out IP addresses your computer will automatically use the static configuration you defined. This allows you to freely connect to other networks, like your home or Wi-Fi hotspots, without having to change back to automatic configuration. Then it prevents you from having to input all the static settings again when connecting to the non-DHCP network.
To define an Alternate Configuration, open Network Connections, double-click the desired network connection, click the Properties button, and select the Internet Protocol Version 4 (TCP/IPv4). Then you select the Alternate Configuration tab and enter the desired settings.
Advertisement

Use an IP configuration utility

If you use multiple networks where you need static IP configuration, the Alternate Configuration feature built into Windows is likely not enough. If you’re a script enthusiast, consider using Netsh commands in batch files to quickly apply IP settings. If you like to stick with a GUI, consider a third-party utility such as NetSetManIP Config Tool, orSimple IP Config.

Reveal saved Wi-Fi passwords

Although this one is very simple, it can be overlooked. If you don’t know a wireless network’s PSK password you can usually find it by revealing it in the network settings of a PC already connected if they’re running Windows Vista or later. Perhaps you’re helping a client connect to their Wi-Fi and they don’t know the password.
In Windows Vista, 7, and 8: bring up the list of available wireless networks, right-click the network, and select the connection properties. Then on the Security tab, click the Show characters checkbox and you’ll see the Wi-Fi password.
In Windows 8.1, you have to access the network connection properties via the Network and Sharing Center.

Block certain Wi-Fi networks

Starting with Windows Vista, you can use the Netsh WLAN commands to hide networks (SSIDs) from appearing in the list of nearby networks. For instance, you may want to prevent users from accidentally or intentionally connecting to other networks and compromising the security of the computer.
To see list of enabled filters, enter the following into a Command Prompt: netsh wlan show filters
To add a filter: netsh wlan add filter permission={allow|block|denyall} ssid=NETWORKNAME networktype={infrastructure|adhoc}
If using the denyall permission, omit the SSID attribute. This lets you block all infrastructure or adhoc networks, but you can explicitly allow specific networks.
To remove a filter: netsh wlan delete filter permission={allow|block|denyall} ssid=NETWORKNAME networktype={infrastructure|adhoc}
To either display or hide the blocked networks on the Connect to a Network dialog: netsh wlan setblockednetworksdisplay={show|hide}

Toggle between private and public network locations

As you’re likely aware, in Windows Vista and later there’s a network location classification in Windows. When a network is classified as Public, for instance, file sharing is turned off along with locking down the firewall. However, it may not be so obvious how to toggle between the Public and Private classifications, especially in Windows 8 and later.
To switch the classifications in Windows Vista and 7, simply open the Network and Sharing Center and click the current classification link. In Windows 8, you can open the list of available wireless networks, right-click, and select Turn sharing on or off. In Windows 8.1, you must open the Settings app in the new interface, select the Network settings, and then select the current network connection,

Use 5 GHz Wi-Fi when available

Remember when managing or connecting to wireless networks, the 2.4 GHz frequency band can be very congested and full of interference. Of course, this depends, but most of the time the 5 GHz frequency band will provide much cleaner communications. Thus try to utilize the 5 GHz band as much as you can. Try to ensure your computers and devices support both bands, typically referred to as dual-band capable.
When connecting to wireless routers or access points that are also dual-band capable, you may or may not see separate network names (SSIDs) for each band. If you do see a 5 GHz option for a network, I recommend that one if within acceptable range. Some wireless routers or APs broadcast the same network name for each band, thus you don’t see any difference or indication of the bands and it’s up to the device or network to which you’re connected to.

Play with the new network features in Window 8

Microsoft introduced many new network-related features in Windows 8; give them a try. The most basic addition is the ability to track the data usage of Wi-Fi and mobile broadband network connections. In Windows 8, you can right-click a wireless network on the list of available networks and show the estimated data usage. In Windows 8.1, you have to access the network’s settings via the Settings app in the new interface if you haven’t installed the Windows 8.1 Update.
Starting with Windows 8 you’ll also find a Metered connection feature. You can set certain networks to be metered and then some Windows updates, apps, and other traffic is limited to help reduce data consumption. This is useful for 4G and other data limiting connections. Like with enabling data usage, you can right-click a network on the list of available networks in Windows 8 to enable/disable metering. But again in Windows 8.1, you have to access the network settings via the Settings app in the new interface if you haven’t installed the Windows 8.1 Update.
Windows 8 also introduced many new functionalities on the Task Manager. You can see the amount of data usage of each running process on the Processes tab. On the Performance tab, you can see a throughput graph and other details about each network connection. On the App History tab, you can see the amount of data each app has used. Additionally, on the Users tab you can see the usage of each user.

Check out the advanced settings of your network adapter

Most network adapters, whether Ethernet or wireless, have advanced settings within Windows. Perhaps take a look and play around with them. You might find some neat functionality, such as band and roaming preferences, ability to disable the wireless upon a wired connection, enable proprietary performance boosting, and other miscellaneous settings.
To access these advanced settings, open the Network Connection Properties, click the Configure button, and select the Advanced tab. Of course, try to understand what you’re changing beforehand so you don’t cause negative results.

Summary

I discussed ways to ease the switch between static and dynamic IP networks. If you use or manage just one network with static IPs, consider Alternate Configuration in Windows, otherwise consider a third-party utility to manage multiple static networks.
We found out that toggling a network between Public and Private classification is straightforward in Windows Vista and 7, but gets complicated in Windows 8 and 8.1. Nevertheless, there are some new network features and functions you may want to check out in these newer versions.
I discussed a few Wi-Fi tips as well: Utilize the 5GHz band when possible. Forgotten Wi-Fi passwords can usually be revealed in Windows Vista or later. And if you find it necessary you can block Wi-Fi networks from appearing in the list of nearby networks.