Archive for client

ADMT 3.1 error – ERR3:7075 Failed to change domain affiliation

I migrated a few machines using ADMT 3.1 from a source Domain A.local to target Domain B.net
I had a few errors with the Agent and it took me a long time to find the solution.

It looked like a DNS issue, as it is the most common cause for failed ADMT agent operations.
The error was ERR3: 7075 (“ERR3:7075 Failed to change domain affiliation”), which drove me to this KB – http://support.microsoft.com/kb/929493
But that was not the solution, as the problem was caused by a specific setting on the Server 2008 Domain Controller policies.

1. The solution: Log on to a Windows Server 2008-based domain controller.

2. Click Start, click Run, type gpmc.msc, and then click OK.

3. In the Group Policy Management console, expand Forest: DomainName, expand DomainName, expand Domain Controllers, right-click Default Domain Controllers Policy, and then click Edit.

4. In the Group Policy Management Editor console, expand Computer Configuration, expand Policies, expand Administrative Templates, expand System, click Net Logon, and then double-click Allow cryptography algorithms compatible with Windows NT 4.0.

5. In the Properties dialog box, click the Enabled option, and then click OK.

Source: http://support.microsoft.com/kb/942564

Happy Migration!

Path to Windows 7 – Part III. Application Compatibility

compatible_with_windows_7

One of the main reasons why companies are delaying their migration from Windows XP to Windows 7 is the lack of compatibility with business critical applications, and sometime it can be a show stopper. There are a few tools and application delivery mechanism that can solve those issues.

Now that we have a complete inventory and rationalized our applications with MAP and Centrix WorkSpace iQ, we are left with a list of application that will be delivered to the Windows 7 users. The next step is to assess the compatibility of those applications on Windows 7 and on the platform that will deliver the application. There are a few different options here. The first decision to make is “32 or 64 bit” version of Windows 7, this decision will imply changes on the application compatibility results. The recommended platform is 64 bit, and it is recommended to companies without a complex application stack and even more important, no legacy applications.

The second decision is on how to deliver the applications. Will it be installed directly to the physical machine through a MSI? Will it be virtualized with App-V and delivered via streaming? Will it be installed on a Remote Desktop pool and the application will be delivered through presentation virtualization? This is also important, as standards for compatibility for App-V and Servers are different from the OS.

Some of the new security features introduced in Windows Vista and Windows 7 may cause the lack of compatibility. Common issues are Session Zero Isolation, 16 bit components, legacy drivers, hardcoded paths, and application that require to run as administrator. There are different ways to test for application compatibility. Microsoft has a very nice tool called ACT – Application Compatibility Toolkit that will help you run applications on a Standard User Mode (non-admin). It will flag all the issues that are preventing the application to run correctly to help you fix the issues. It will also provide a list of potential fixes and will work with Shims.

But the process with ACT can be very lengthy and painful as the amount of information provided is low the tasks are very manual. An alternative is to use AppTitude by App-DNA (now part of Citrix). App-Titude allows you to import applications and it will run code and behaviour analysis based on the application’s MSI. It will run compatibility analysis and give you results for Windows 7, 64 bit, App-V, XenApp, Server 2008, Server 2008 R2. It will also help you choosing the best option to deploy that application, physical, virtual or hosted on a server. All the results are displayed on a RAG status and in case it is amber or red it will give you remediation guidelines, suggest shims and even propose auto fixes with MSTs. App-Titude will also automate packaging for App-V to help you accelerate the deployment. The greatest advantage of this tool is that you can send all the application that come out as Green straight to UAT and focus your packaging team on the applications that require remediation. It will also tell you how complex it is to fix a specific app so you can easily manage your internal resources or take the decision to use an external packager for that.

Internet Explorer compatibility is also something worth looking at. Some websites where coded a long time ago and might have components that will not run on Internet Explorer 8 or 9. AppTitude can handle analysis of web applications. Another way to solve web application issues is Browsium, a nice piece of software that integrates legacy browser tabs on your current Internet Explorer version, so you can run web application in IE6 mode inside IE9.

There are other methods to solve compatibility issues. For very small companies or departments, you can use Med-V, but you will still need to manage the Windows XP running under Windows 7 and it will also be out of support soon.

Dealing with applications is the lengthiest process on the path to Windows 7 and that is the main reason why you should at it sooner rather than later on the migration journey. The next step is to consider how to deliver Windows 7 to the end user.

Resources:
ACT – Application Compatibility Toolkit

AppTitude by App-DNA

Browsium

Med-V

The Springboard Series

 

Share your connection through a virtual wireless Access Point with Windows 7

wifi_hostednetwork

Windows 7 offers a very cool feature where you can connect multiple devices to any wired and wireless network connection (hotel, cable, 3G, UMTS, EDGE, WIFI, RJ45, Ethernet, etc.) by turning your own laptop into a wireless AP (Access Point) to relay those devices not directly connected to the internet.

For this just enter these two commands to an elevated (right click on CMD.EXE, run as administrator):

netsh wlan set hostednetwork mode=allow ssid=YOURFRIENDLYSSID key=SOMEPASSWORD

netsh wlan start hostednetwork

At this point, if Internet Connection Sharing (ICS) is setup, anyone can connect to your SoftAP (if they know the PWD of course) and the traffic will be sent through whatever adapter you want. You can actually bridge it across an entirely different adapter… or the same on a different Wifi LAN.

A GUI to set this up can be downloaded for free here: http://www.connectify.me/

Path to Windows 7 – Part II. Application and Hardware Discovery

map_assessment and planning_sq

The first step to get ready to migrate to Windows 7 is to understand your environment very well. You will probably want to start identifying your applications and hardware. It is also a good time to consider improving some of your internal procedures such as OS deployment and application distribution, as well as improvements on user experience.

You should start with a hardware and software inventory. I recommend using MAP, the Microsoft Assessment and Planning Toolkit. MAP is an agentless application that will take an inventory of machines on your network and tell you what hardware they have. It will also tell you what software is installed on the machines. It will go even further and tell you if the machines are ready to run Windows 7 and Office 2010, based on a few pre-defined factors. Make sure you take out DVD Drive as a requirement (this is a default value), as you will probably use something like WDS and/or MDT to deploy Windows 7. MAP can do much more; check the resources at the end of this article.

MAP will provide the inventory, but it is still hard to understand how the applications are being used. Having an application installed does not mean that the users actually use it. Furthermore, do they use the application when they are at the office or when they work from home? How many concurrent users do you have for an application? Those answers can seriously affect the price you will pay for your licences. To tackle this problem I recommend Centrix WorkSpace iQ. It will monitor application usage on workstation with the agent installed. It can also help you understand how laptops are used. I had a client to run the laptop analysis in 700 laptops and after 3 months we found out that only 96 of them where ever taken away from the docking station, which means that potentially 604 of them can be replaced by a desktop on the next hardware refresh cycle.

Once you understand your hardware and software current state you will need to rationalize the software that is used on your company. It is a great time to remove old versions and retire legacy software. On average each retired application can save up to 3000 dollars during a migration. Choose carefully with software will be delivered on your new Windows platform and work to solve potential application compatibility issues.

Make a list of the hardware that needs to be replaced and find a solution for it, If you have the budget get new machines. If you are tight in budget but have a decent licence agreement give Windows ThinPC a try.

Resources:

Microsoft Assessment and Planning Toolkit

Centrix WorkSpace iQ

 

TechDays Online UK 2011 – Windows 7 and Internet Explorer

techdaysuk

 

TechDays Online UK 2011 was a very interesting event. I had the pleasure to present 2 sessions, the first about Windows 7 as the best desktop experience and Why Internet Explorer is awesome for the Enterprise. All the recordings for TechDays are available at the TechNet UK Team Blog.

I managed to re-encode my sessions so they can be uploaded to youtube. Enjoy and leave your feedback.

 


Find the link for the presentations on slideshare on this other post: http://davidnudelman.com/2011/techdaysuk/

TechDays Online UK Presentations

Last Thursday, October 27th I had the pleasure to present 2 sessions at the Microsoft Techdays Online.
On the first session I covered the enterprise features of Windows 7 and why it is a good time to migrate away from Windows XP.

 

On my session I talked about Why Internet Explorer 9 is awesome for the enterprise. Also had the opportunity to demo Cross-site scripting and Group Policies for IE.