/
Building your “cloud” platform with Windows Building your “cloud” platform with Windows

Building your “cloud” platform with Windows - PowerPoint Presentation

sherrill-nordquist
sherrill-nordquist . @sherrill-nordquist
Follow
345 views
Uploaded On 2020-01-17

Building your “cloud” platform with Windows - PPT Presentation

Building your cloud platform with Windows Server 2012 Julius Davies and Clive Watson Datacenter Technology Specialist Microsoft UK Ltd This presentation provides an overview of the top technical features of Windows Server 2012 ID: 773061

server virtual storage windows virtual server windows storage network machine management access hyper

Share:

Link:

Embed:

Download Presentation from below link

Download Presentation The PPT/PDF document "Building your “cloud” platform with ..." is the property of its rightful owner. Permission is granted to download and print the materials on this web site for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.


Presentation Transcript

Building your “cloud” platform with Windows Server 2012 Julius Davies and Clive WatsonDatacenter Technology SpecialistMicrosoft UK Ltd

This presentation provides an overview of the top technical features of Windows Server 2012. Agenda IntroductionServer VirtualizationStorage including Cloud Integrated Storage with Storsimple NetworkingManagement and Automation Web and Application PlatformVirtual Desktop Infrastructure Identity and Access 2

Introduction and Licensing

Industry trends and challenges 4 How do I embrace the cloud? How do I increase the efficiency in my datacenter? How do I deliver next-generation applications? How do I enable modern work styles? New apps Device proliferation Data explosion Cloud computing

Windows Server 2012 editions Windows Server 2012 Foundation Windows Server 2012 Essentials Windows Server 2012 Standard Windows Server 2012 Datacenter 5 ' Microsoft Hyper-V Server 2012

Two editions differentiated only by virtualization rights Datacenter offers unlimited virtualization. Standard offers two virtual instances. Common licensing structure Both editions will have a processor + CAL licensing model. Each software license will cover up to two physical processors on a single server. Common features across e ditions High availability features such as failover clustering are included. Same memory and processor capabilities across edition. Simplified Licensing for Standard and Datacenter Editions 6 '

Server Virtualization

Virtualization – Just the facts 8 VIRTUAL MACHINE MOBILITYSimultaneous live migrations ease management burdensShared-nothing live migration enables live migration between clusters CONTINUOUS SERVICES ISOLATION AND MULTITENANCY SCALE AND PERFORMANCE OPEN AND EXTENSIBLE Dynamic Memory increases capacity with no downtime Network Virtualization supports multitenancy and IP portability Resource Metering shows how many resources each tenant is using Larger virtual machines support increased workloads Hardware offloading offers better performance and scale Open, extensible switch helps support security and management needs Increased support for Windows PowerShell helps increase automation Clustering enhancements increase availability

System Resource Maximum numberImprovement factor Windows 2008 R2 Windows Server 2012 Host Logical processors on hardware 64 320 5× Physical memory 1 terabyte 4 terabytes 4× Virtual processors per host 512 1,024 2× Virtual machine Virtual processors per virtual machine 4 64 16× Memory per virtual machine 64 GB 1 terabyte 16× Active virtual machines 384 1,024 2.7× Virtual disk size 2 terabytes 64 terabytes 32× Cluster Nodes 16 64 4× Virtual machines 1,000 8,000 8× Scale enhancements 9

Migrate virtual machines without downtime 10ImprovementsFaster and simultaneous migrationLive migration outside a clustered environmentStore virtual machines on a File Share VM VM Target host Live migration setup SMB network storage IP connection Configuration data Memory pages transferred Memory content MEMORY MEMORY Modified pages transferred Modified memory pages Storage handle moved VIRTUAL MACHINE MOBILITY Live migration of VM’s on SAN or File Share (SMB3) VM

Computer running Hyper‑V Target device Move virtual machine storage without downtime Source device VIRTUAL MACHINE MOBILITY Benefits Manage storage in a cloud environment with greater flexibility and control Move storage with no downtime Update physical storage available to a virtual machine (such as SMB-based storage) Windows PowerShell cmdlets Live migration of storage Move virtual hard disks attached to a running virtual machine Reads and writes go to the source VHD Disk contents are copied to new destination VHD VHD Disk writes are mirrored; outstanding changes are replicated Reads and writes go to new destination VHD Virtual machine VHD 11

Destination Hyper‑V Virtualmachine Target device Source device Virtual machine Source Hyper‑V IP connection Configuration data Memory content Modified memory pages Migrate virtual machines without downtime VIRTUAL MACHINE MOBILITY Benefits Increase flexibility of virtual machine placement Increase administrator efficiency Reduce downtime for migrations across cluster boundaries Shared-nothing live migration Reads and writes go to the source VHD Reads and writes go to the source VHD. Live Migration Begins Disk contents are copied to new destination VHD Disk writes are mirrored; o utstanding changes are replicated Live Migration MEMORY MEMORY VHD VHD Live Migration Continues Live Migration Completes 12

Benefits Affordable in-box business continuity and disaster recovery Failure recovery in minutesMore secure replication across networkNo need for storage arraysNo need for other software replication technologiesAutomatic handling of live migrationSimpler configuration and managementNew featureReplicate Hyper ‑V virtual machines from a primary site to a replica site Hyper‑V Replica VIRTUAL MACHINE MOBILITY 13 Hyper‑V role and tools Hyper‑V cmdlets Hyper‑V PS integrated UI Hyper‑V Management Module tracks and replicates changes for each virtual machine Hyper‑V role and tools Hyper‑V cmdlets Hyper‑V PS integrated UI Hyper‑V Management Module receives and applies the changes to the replica virtual machine Primary site CRM virtual machine SQL virtual machine SharePoint virtual machine Exchange virtual machine IIS virtual machine Exchange replica virtual machine CRM replica virtual machine Replicate over WAN link SMB file s hare Send/receive replica t raffic SAN R1 R2 R3 P1 P2 Replica site

Virtual machine failover prioritization Lets you configure virtual machine prioritiesControls the order in which virtual machines fail over or startAffinity (and anti-affinity) virtual machine rulesLets you configure partnered Virtual machines to migrate simultaneously during failover.Allows you to specify that two virtual machines cannot coexist on the same node in a failover scenario (anti-affinity)Hyper‑V clustering enhancements CONTINUOUS SERVICES 14 Features Encrypted Cluster Volumes Use Bitlocker Drive Encryption to encrypt cluster volumes hosting virtual machines Hyper-V App Monitoring Monitors services and event logs inside WIN2012 virtual machines Restart services\ vm’s if necessary

Vote Vote Vote Vote Vote Vote Last Man Standing! Cluster Survives! N = 5 Majority = 3 N = 4 Majority = 3 N = 3 Majority = 2 N = 2 Majority = 2 N = 1 Majority = 1 1 2 3 4 5 6 Hyper‑V clustering enhancements Dynamic Quorum… Aka “Last Man Standing” CONTINUOUS SERVICES

Hyper-V Demo 16

Storage

Storage – Just the facts ALWAYS ON, ALWAYS UP SERVICESCONTINUOUS APPLICATION AVAILABILITYENTERPRISE-CLASS FEATURES ON LESS EXPENSIVE HARDWAREApplication storage support through SMB 3.0Server Message Block (SMB) Direct Data D eduplication Storage Spaces IMPROVED PERFORMANCE AND MORE CHOICE THROUGH INDUSTRY INNOVATION Virtual Fibre Channel for Hyper-V Windows Storage Server Windows Cluster in a Box Offloaded Data Transfers (ODX) SMB Transparent Failover SMB Multichannel Cluster-Aware Updating (CAU) File system e nhancements Online backup SIMPLIFIED MANAGEABILITY Unified storage management Management options 18 High availability with iSCSI and NFS

Virtualization of storage with Storage Pools and Storage Spaces Storage resilience and availability with commodity hardware Resiliency and data redundancy throughn-way mirroring (clustered or unclustered) or parity mode (unclustered)Utilization optimized through thin and trim provisioning and enclosure awarenessIntegration with other Windows Server 2012 capabilitiesSerial Attached SCSI (SAS) and Serial AT Attachment (SATA) interconnectsStorage Spaces Windows V irtualized S torage Windows Application Server or File Server Physical or virtualized deployments Physical S torage (Shared) SAS or SATA Integrated with other Windows Server 2012 capabilities Storage Pool Storage Pool File Server Administration Console Hyper-V Cluster Shared Volume Failover Clustering SMB Multichannel NFS Windows Storage Mgmt. NTFS SMB Direct 19 Storage Space Storage Space Storage Space

Efficient storage through Data Deduplication 20 VHD LibrarySoftware Deployment ShareGeneral File ShareUser Home Folder (My Docs)0% 20% 40% 60% 80% 100% Average savings with Data D eduplication by workload type Maximize capacity by removing duplicate data 2:1 with file shares, 20:1 with virtual storage Less data to back up, archive, and migrate Increased scale and performance Low CPU and memory impact Configurable compression schedule Transparent to primary server workload Improved reliability and integrity Redundant metadata and critical data Checksums and integrity checks Increase availability through redundancy Faster file download times with BranchCache Source: “Microsoft Internal Testing"

SMB Transparent Failover Failover share – connections and handles lost,temporary stall of I/O2Normal operation1 Connections and handles auto-recovered Application I/O continues with no errors 3 Windows Server file server cluster \\foo1\share1 \\foo2\share1 \\foo\share Hyper-V or SQL Server High-performance, continually available fileshares for business critical applications Failover transparent to server applications with zero downtime and with only a small I/O delay Support for planned moves, load balancing, operating system restart, unplanned failures, and client redirection (scale-out only) Resilient for file and directory operations All servers involved should have Windows Server 2012 21

Continuous availability with NFS and iSCSI 22NFS SUPPORTALWAYS ON,ALWAYS UP SERVICESISCSI SOFTWARE TARGETIntegrated with clustering to enable a high availability iSCSI Target Faster recovery from hardware failures iSCSI network boot provides a reliable, cost effective, and highly available option for Hyper-V host and HPC boot Microsoft iSCSI Software Target now an in-box feature in Windows Create iSCSI cluster using Server Manager UI or Windows PowerShell NFS 4.1 support for early adopters Cost-effective alternative for virtualized deployments Better reliability with stateful protocol Continuous availability for applications deployed over NFSv3 or NFSv2 (specifically VMware) with transparent server-side failover

Online backup to Windows Azure 23 Registration Sign upBilling Third-party cloud Sign up Billing Microsoft online backup service Microsoft online backup portal Third-party online backup service Third-party online backup portal Inbox engine Inbox UI Windows Server 2012 b ackup (extensible ) Windows Server 2012 Agents Microsoft online b ackup Third-party agents IT Pro Registration Backup / Restore Ability to leverage Windows Azure cloud services to back up data Reduced cost for backup storage and management Options for third-party cloud services Ideal for small businesses, branch offices, and departmental business needs

Cloud Integrated Storage with StorSimple 24 Applications in Physical or Virtual Servers SAS local tier Automatic Tiering + Cloud Snapshots Most active data on SSD Inactive data + backup\archive in Azure storage Connects Windows, Hyper-V and VMware servers to Windows Azure Storage in minutes with no application modification Key Capabilities & Benefits Consolidates primary, archive, backup, DR thru seamless integration with Azure Automatic tiering of data between SSD\SATA\Azure Cloud Snapshots = revolutionary speed, simplicity & reliability for backup & recovery Reduces enterprise storage TCO by 60-80% ISCSI Connectivity

StorSimple Tiered ArchitectureSSD Performance, Deduplication and Auto-Tiering to Cloud SSDDeduplicatedSASDeduplicatedCompressedCloudDeduplicatedCompressedEncryptedSSDLinear Tier A B C A B D E C D E D E E 25

Seamless Scalability & Rapid Recovery with StorSimple 26 CloudSnapshotsEnterprise Data Center 1Production Data Enterprise Data Center 2 Connect many servers to cloud storage and scale data sets with StorSimple solution Rapidly recover to any data center – location independent via mounting the cloud

StorSimple Demo 27

Networking

Networking - Just the facts NIC Teaming Dynamic Host Configuration Protocol (DHCP) failoverPrivate virtual local area network (PVLAN)Hyper-V Network VirtualizationSIMPLIFIED MULTITENANT INFRASTRUCTURE OPERATIONAL EFFICIENCY RICHER ECOSYSTEM CONTINUOUS APPLICATION AVAILABILITY Cross-premises connectivity Hyper-V Extensible Switch Hardware partners Server Message Block (SMB) 3.0 Multichannel Quality of Service ( QoS) HIGH-PERFORMANCE NETWORKING SMB Direct Single Root I/O Virtualization (SR-IOV) Receive-Side scaling (RSS) Receive Segment Coalescing (RSC) Dynamic Virtual Machine Queue (D-VMQ) IP Address Management (IPAM) Resource Metering Microsoft Windows PowerShell BranchCache 29

NIC Teaming Virtual adapters NIC Teaming Team n etwork a dapter Team network a dapter 30 Operating system Provides network fault tolerance and continuous availability when network adapters fail by teaming multiple network interfaces Vendor agnostic and shipped inbox Provides local or remote management through Windows PowerShell or UI Enables teams of up to 32 network adapters Aggregates bandwidth from multiple network adapters Includes multiple nodes: switch dependent and independent

Benefits Layer 2 virtual interface Managed programmaticallyExtensible by partners or customersNew featureHandles network traffic among virtual machines, external network, and host operating system Hyper‑V Extensible Switch31 Virtual machine Network application Virtual network adapter Hyper–V host Hyper‑V Extensible Switch Physical network adapter Physical switch Virtual machine Network application Virtual network adapter Virtual machine Network application Virtual network adapter

Parent PartitionOther featuresExtension monitoringExtension uniquenessExtensions that learn virtual machine life cycleExtensions that can veto state changesMultiple extensions on same switchTwo platforms for extensionsNetwork Device Interface Specification (NDIS) filter driversWindows Filtering Platform (WFP) callout drivers You can extend or replace NDIS filter drivers WFP callout drivers Ingress filtering Destination lookup and forwarding Egress filtering Extending the Hyper‑V Extensible Switch For new capabilities 32 Hyper‑V Extensible Switch architecture Extension C Extension D Extension A Extension Miniport Extension Protocol Virtual Switch Physical NIC Virtual Machine Host NIC VM NIC Virtual Machine VM NIC Capture Extensions Filtering Extensions Forwarding Extension

Hyper‑V Extensible Switch extension types 33 ExtensionPurposePotential examples Extensible component Network packet inspection Inspecting network packets, but not altering them sFlow and network monitoring ( InMon ) NDIS filter driver Network packet filter Injecting, modifying, and dropping network packets Security NDIS filter driver Network forwarding Third-party forwarding that bypasses default forwarding OpenFlow (NEC), Virtual Ethernet Port Aggregator (VEPA), and proprietary network fabrics (Cisco Nexus V1000 \ UCS) NDIS filter driver Firewall/intrusion detection Filtering and modifying TCP/IP packets, monitoring or authorizing connections, filtering IPsec-protected traffic, and filtering RPCs Virtual firewall and connection monitoring (5nines – virtual firewall\AV) WFP callout driver

BENEFITS ARP spoofing protection DHCP guard protectionVirtual port ACLsTrunk mode to virtual machinesMonitoringWindows PowerShell | Windows Management Instrumentation (WMI)Enhanced security and isolationManageabilityIsolation of customers’ networks from one anotherNo need to set up and maintain VLANsProtection against malicious data interceptionOTHER TOOLSMultitenant security and isolation34

NVGRE Standards based tunneling technology built on IETF standard GRE protocol Better network scalability by sharing PA among VMsExplicit Virtual Subnet ID for better multi-tenancy supportStrong partner eco-system with silicon partners, switch extension partners, switch and load balancer partners and gateway partnersManage using System Center Virtual Machine Manager 2012 SQL Server Web Orange sees SQL Server Web Blue sees SQL Server SQL Server Web Web Hyper-V 2 Hyper-V 1 192.168.2.12 192.168.1.10 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 What’s really happening 192.168.n.n PROVIDER ADDRESS SPACE (PA) 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 10.1.1.2 10.1.1.1 10.1.1.1 10.1.1.2 CUSTOMER ADDRESS SPACE 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 10.1.1.1 192.168.1.10 10.1.1.2 192.168.2.12 10.1.1.1 10.1.1.2 10.1.1.1 10.1.1.2 Hyper-V Network Virtualization 35

Hyper-V QoS bandwidth control Features and mechanisms Relative minimum bandwidthStrict minimum bandwidth36FeaturesEstablishes either a bandwidth floor or capAssigns specified bandwidth for each type of trafficHelps to ensure fair sharing during congestion Can exceed quota with no congestion Two mechanisms Enhanced packet scheduler (software) Network adapter with DCB support (hardware) Normal priority High priority Critical Hyper‑V Extensible Switch W=1 W=2 W=5 Bronze tenant Silver tenant Gold tenant Hyper‑V Extensible Switch 100 MB 200 MB 500 MB 1 Gbps Strict maximum bandwidth Bronze tenant Silver tenant Gold tenant Hyper‑V Extensible Switch 100 MB 200 MB 500 MB 1 Gbps Be careful of oversubscription !

General benefits Needs fewer expensive network adapters Makes best use of 10-GbE hardware For public cloud hosting providers Manages performance levels for SLAsDelivers minimal impact or compromise in shared infrastructureQoS minimum bandwidthBenefits37 Runtime bandwidth demand (gigabits per second) Service Reservation T1 T2 T3 Virtual machine 30% 4 4 2 Storage 40% 5 5 6 Live migration 20% 0 3 2 Cluster Shared Volume 10% 0.5 1 0 T1 4 5 0.5 T3 2 6 2 T2 3 4 1 2 Actual bandwidth usage by each service When bandwidth is available, each service takes as much as it can When the link is congested, each service takes its fair share W hen bandwidth becomes available, each service takes as much as it wants

Management and Automation

Windows PowerShell 3.0 provides more features to allow more activities to be automated across the server ecosystemWindows Management Framework provides a common platform for building automation and integration incorporating PowerShell, WS-Management and WMI STANDARDS-BASED MANAGEMENTJust the facts 39 MULTISERVER MANAGEMENT ECOSYSTEM AND EXTENSIBILITY Server Manager enables a multiserver management experience that builds on the standardized approach to management and robust automation capabilities Standardized interfaces and tools extend the interoperability with DevOps Cross platform capabilities enable automation across the datacenter ROBUST AUTOMATION

Key features Broader coverage Rich management through more than 2300 cmdletsWindows PowerShell Web AccessGreater resiliencyRobust session connectivityDisconnected sessionsSession configuration filesJob schedulingWindows PowerShell Workflow More intuitive Integrated Scripting Environment 3.0: IntelliSense | Code Snippets Syntax simplification Cmdlet discovery and module autoloading Updatable help Script-sharing Higher performance On-the-fly compilation—up to six times faster Performance improvements Windows PowerShell 3.0 40 ROBUST AUTOMATION

Windows Server 2012 Configuration Levels Server with a GUI Minimal Server InterfaceServer CoreNEW Full Server without Server Graphical ShellNo Explorer, Internet Explorer or associated filesMMC, Server Manager, and a subset of Control Panel applets are still installedProvides many of the benefits of Server Core for those applications or users that haven’t yet made the transitionServer Core NEW Can move between Server Core and Full Server by simply installing or uninstalling componentsClassic “Full Server” Full Modern-style GUI shellInstall Desktop Experience to run Metro-style apps

Transitioning : PS cmdlets Full Server to Server CoreServer Core to Full Server POWERSHELLUninstall-WindowsFeature Server-Gui-Mgmt-Infra -RestartPOWERSHELLInstall-WindowsFeature Server-Gui -Mgmt -Infra,Server- Gui -Shell -Restart NEW Can install multiple features with one command by separating with commas Single reboot required to restart all services

Converting to and from Server Graphical Shell Server ManagerUninstall Server Graphical Shell: Install Server Graphical Shell:Server Core to Minimal Server InterfacePOWERSHELLUninstall-WindowsFeature Server-Gui-Shell -RestartPOWERSHELLInstall-WindowsFeature Server-Gui-Shell - Restart POWERSHELL I nstall- WindowsFeature Server- Gui - Mgmt -Infra - Restart

Web and Application Platform

Web Platform - Just the facts 45 Application Initialization improves user experience of first requestsCPU throttling helps ensure that no single web application affects the performance of othersDynamic FTP and IP restrictions set policies to block unwanted access Server Name Indication (SNI) allows high-density sites that are more secure Non-Uniform Memory Architecture (NUMA) takes advantage of hardware that has complex specifications Centralized SSL store dynamically maps sites to certificates MUTLTENANT HIGH-DENSITY WEBSITES CONSISTENT AND REPEATABLE CONFIGURATIONS ECOSYSTEM AND EXTENSIBILITY Configuration Editor provides a rich, visual method to edit web configurations and create repeatable actions Shared configuration helps ensure consistency across web farms Provides a common development platform across clouds Embraces web standards to work more easily with PHP and node.js HIGH-PERFORMANCE WEB APPLICATIONS

Virtual Desktop Infrastructure (VDI)

User Profile Disk maintains user personalization in pooled deployments Fair Share dynamically distributes bandwidth, CPU, and disk useMultiple storage options support direct-attached, network-attached, or storage area network (SAN) storage of virtual machinesEasy deployment automates deploying and configuring server roles Unified administration uses a single, integrated console for management Streamlined management helps IT manage pooled and personal virtual machines Efficient Management RDS and VDI - Just the facts 47 Rich User Experience USB redirection enables access to locally attached devices in remote desktops RemoteFX for wide area network (WAN) dynamically detects network conditions and tunes experience Seamless experience supports multitouch, new Windows Experience, and Start menu integration Graphics processing unit (GPU) support for both physical and software GPUs Best Value for VDI

Maintain user personalization in pooled deployments Dynamically distribute bandwidth, CPU, and disk use Support direct, attached, network, or SAN storage of virtual machines Best value for VDI with key platform capabilities 48 User Profile Disk Multiple storage options Fair Share High availability for all roles

Hardware and software GPUsRich multimediaUSB redirectionMultitouchWAN accelerationSingle sign-onCorporate LANRemoteFX over LAN or WAN RemoteFX delivers a consistently richuser experience to users over LAN or WAN (regardless of deployment model) RICH USER EXPERIENCE 49 Internet or WAN

VDI Demonstration 50

Identity and Access

Identity and Access - Just the facts Protection of corporate resources Data access management and protectionSimplified deployment and management of identity infrastructure Dynamic Access ControlActive Directory virtualization Active Directory cloning Kerberos constrained delegation Private VLAN Multitenant security and isolation Classification DirectAccess Simpler deployment of Active Directory Domain Name System Security Extensions 52

Activate clients using existing Active Directory infrastructure Computers running Windows 8 or Windows Server 2012 automatically activateActivation object is maintained in the configuration partitionBeyond installation and service-specific requirements, no data is written back to the directoryActive Directory-based activation53

Classification Access control AuditingRights Management Services protectionFiles inherit classification tags from parent folderFile owners tag files manuallyFiles are tagged automaticallyFiles are tagged by applicationsCentral access policies are based on classificationAccess conditions for user claims, device claims, and file tags are based on expressions Assistance is available for denial of access Central audit policies can be applied across multiple file servers Audits for user claims, device claims, and file tags are based on expressions Audits can be staged to simulate policy changes in a real environment Automatic Rights Management Services (RMS) protection is available for Microsoft Office documents Protection is in near-real–time when a file is tagged RMS protection extends to files not created in Microsoft Office Dynamic Access Control 54

User claims User.Department = FinanceUser.Clearance = High Access policyFor access to financial information that has high business impact, a user must be a finance department employee with a high security clearance, and must use a managed device registered with the finance department.Device claimsDevice.Department = FinanceDevice.Managed = TrueResource propertiesResource.Department = FinanceResource.Impact = HighActive Directory Domain ServicesExpression-based access rules 55 File server

Active Directory Domain ServicesCharacteristicsComposed of central access rules Applied to file servers through Group Policy objectsSupplement (not replace) native file and folder access control lists from New Technology File System (NTFS)Central access policies56Corporate file servers Personally identifiable information policy Finance policy User folders Finance folders Organizational policies High business impact Personally identifiable information High business impact policy Finance department policies High business impact Personally identifiable information Finance

Audit everyone who does not have a high security clearance and who tries to access a document that has a high impact on businessAudit all vendors when they try to access documents related to projects that they are not working onAudit policy examplesAudit | Everyone | All-Access | Resource.BusinessImpact=HBI AND User.SecurityClearance!=HighAudit | Everyone | All-Access | User.EmploymentStatus=Vendor AND User.Project Not_AnyOf Resource.Project.57

DirectAccessEnables dynamic cloud access Ease of deploymentExpress setup wizardAbility to work with existing network equipmentConnectivity to IPv4 and IPv6 serversDeployment mode supporting only remote management of mobile computers Improved manageability Unified remote access management experience Enriched experience for monitoring remote client activity and status Reporting and accounting capabilities for audit/compliance Rich Windows PowerShell management interface Enhanced troubleshooting tools Enabling new scenarios Multisite and hybrid cloud Support for one-time password and Trusted Platform Module authentication Provisioning support for off-premises clients Deployment of DirectAccess server behind network address translation device Improved scale and performance Support for high availability and external load balancers Improved performance in virtualized environments Dramatically more users per server 58

Dynamic Access Control Demonstration 59

Get the evaluation Get the evaluation, get certified, and get trained 60Microsoft Server and Cloud Platform:http://www.microsoft.com/en-us/server-cloud/windows-server/2012-default.aspxMicrosoft Learning:http://www.microsoft.com/learning/Microsoft Virtual Academy:http://www.microsoftvirtualacademy.com Microsoft Technet Library: Windows Server 2012http:// technet.microsoft.com/en-gb/library/hh801901.aspx Get certified Get trained

© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.