Microsoft’s latest server operating system, Windows Server 2012 R2, is due with us on October 18th so let’s take a look at what’s new in the upcoming release.
People Centric IT (PCIT): Borne out of/related to Bring Your Own Device (BYOD), PCIT is a key component of all Microsoft’s upcoming server releases including System Center and Intune.
The Workplace Join feature will enable users to register their devices in Active Directory (AD) and then to enroll them for management in System Center / Intune.
As part of that Workplace Join, we’ve created a user@device record in the Active Directory. In this way, we’re enabling your existing AD infrastructure to be extended to accommodate mobile devices. This allows us to provide the IT Pro with an inventory of devices and their users, and to audit the access that will be subsequently granted to those users on those devices. The certificate issued to the device includes both the identity of that device and the identity of the authenticated user. Access to resources published via our Web Application Proxy (see below), or to any other resource that relies on AD FS for authentication, will rely on this certificate for authentication.
One thing worth noting: The act of registering the device to Active Directory does not allow IT to control the device in any manner — that’s is covered by enrollment. Workplace Join is only used to govern access to corporate resources and to enable SSO.
The new Company Portal gives users a central place to perform common tasks such as:
- Access internal apps
- Manage their devices with remote wipe etc.
- Access their data with Work Folders integration
What are Work Folders you may ask, well:
Work Folders address the bring-your-own device (BYOD) scenario, enabling users to store and access work files on personal PCs and devices as well as corporate PCs. Users gain a convenient location to store work files and access them from anywhere, while organizations maintain control over corporate data, storing the files on centrally managed file servers and optionally specifying user device policies such as encryption and lock screen passwords.
Work Folders can be deployed alongside existing deployments of Folder Redirection, Offline Files, and home folders. Work Folders stores user files in a folder on the server called a sync share, and you can specify a folder that already contains user data, enabling you to adopt Work Folders without migrating servers and data or immediately phasing out your existing solution.
This all makes it easier for users to be able “work anywhere” as:
As part of enrolling for management, users can have their devices provisioned with certificates, WiFi profiles, VPN profiles, and DirectAccess configuration. The VPN profiles can be associated with DNS names or specific applications so that they automatically launch on demand. This allows users to work remotely and always be connected to the corporate network without the need to initiate a VPN connection.
A new feature in Server 2012 R2, SCCM 2012 2 and Windows 8.1 enables apps to initiate the VPN connection when launched.
Another big BYOD addition is this:
With the R2 wave of releases, we have added the ability to selectively wipe corporate information while leaving personal data intact.
That’s a huge thing with BYOD, if users are using their personal devices for work it stands to reason their will be personal data on the device – holiday pictures, music etc. – and the risk of losing all that due to a corporate wipe has put many people off. Some may say that is the price one pays for BYOD but it doesn’t have to be the case and it’s great to see it baked into the new MS products.
Other areas added to in Windows Server 2012 R2 include:
- Identity Management
- IAAS (Infrastructure As A Service)
- Hybrid Networking
- Cloud Integrated Disaster Recovery
To see much more in depth, technical info around all the above (and more) head over to: