January 16, 2010

Centralized Management Support Structure of Microsoft IT

The existing Microsoft IT NOC consisted of three teams that used different processes to perform a variety of technical support functions. These functions ranged from basic, routine tasks to highly complex issues. The three teams were responsible for the following activities:
Network connectivity, wireless access points, switches, and routers
Server configuration and monitoring

Telephony switches and hardware
One of the business challenges that Microsoft IT identified was a lack of standardized processes and workflow efficiencies between these three operationally independent teams. Several teams performed most incident response and change request work. Limited ownership and a lack of collaboration resulted in inefficiencies, and the organization barriers were a hindrance to the support structure. With interdependencies in technology, there was also a need for knowledge convergence across support teams to troubleshoot complex issues. Adhering to support service level agreements (SLAs) on complex issues was a huge challenge that affected the business.

To facilitate a more efficient and consistent structure, Microsoft IT transformed the NOC into the following support teams:

Change operations provided by a global change operations team. This team is responsible for routine change management.

Incident operations provided by a global incident operations team. This team is responsible for customer contact via a service desk team and routine incident management.

Problem management provided by technical escalation teams. These teams are responsible for problem management, creation process efficiencies, and the resolution of complex incidents and chronic errors.
With this new structure in place, Microsoft IT used MOF service desk, incident management, problem management, and change management best practices, coupled with MOM 2005 alerts and events, to respond to customer incidents and change requests.

Delegating support tasks between Microsoft IT and vendors enables Microsoft IT resources to respond more quickly to complex incidents and change requests and focus on chronic error resolution by using MOF best practices for problem management.

SCCM 2007 wrt Asset Intelligence: What's New?

Recent Usage Inventory:
•SCCM metering agent will inventory the last time any executable was running in the user context.
•Data returned through hardware inventory.
•Additional reports will help you answer the “When was the last time this was used?” question.

Auto-created Metering Rules:
•Last Usage Inventory can be used to auto-create full metering rules which you can decide to enable.
•Simplifies the process of creating metering rules.

Asset Change Summarization:
•A summary of changes to computer assets is stored in a central table.
•Managing deltas help reduce the complexity of asset management.
•Additional reports help you answer the “What has changed recently in my environment?” question.
•Client Access Licenses usage tracking for Microsoft Windows and Exchange:
•Both User and Device CALs usage is tracked.
•Based on Security audit logs.
•Additional reports answer the “who used up the CALs” , “when did they do that” questions.

Extending hw inventory to get SMS client's cache size status

If you want to extend HWinventory so you know what client has what size of
Cache, add this to SMS_Def.Mof in clifiles.src\hinv on your server. No need to mofcomp anything on your clients. The clients already know about this class, they just need to be told via a policy change (by added this to your sms_def.mof on the server) to start reporting on it.

//========================
//`'`*._.*`'`*-
// SMS Advanced Client Cache Reporting Class
//`'`*._.*`'`*-
//
#pragma namespace ("\\\\.\\root\\cimv2\\sms")

[ SMS_Report (TRUE), SMS_Group_Name ("SMS Advanced Client Cache"),
Namespace ("root\\\\ccm\\\\softmgmtagent"),
SMS_Class_ID ("MICROSOFT|SMS_ADVANCED_CLIENT_CACHE|1.0") ]

class CacheConfig : SMS_Class_Template
{
[SMS_Report (TRUE),key ] string ConfigKey;
[SMS_Report (TRUE)] boolean InUse;
[SMS_Report (TRUE)] string Location;
[SMS_Report (TRUE)] uint32 Size;
};

Client Cache Size: When the packages delete from the Cache?

As per SMS policies refreshal, it will attempt to do cleanup; going from memory,if something was downloaded and never used, it'll clean it up after 30 days; if it was downloaded & used,it'll be cleared about 24 hours later.

Incremental and cumulative SPs?

A service pack can be incremental, which means it only contains the updates that were not present in the previous service packs or, it can be cumulative, which means it includes the contents of all its predecessors. In the case of Microsoft's products, an incremental update was called a service release. For example, Office 2000 must be upgraded to service release 1 (SR-1) before one can install SP2.

Recent service packs for Microsoft Windows have not been cumulative starting with Windows XP Service Pack 3. Windows XP SP3 requires at least SP1 to be present on an installed copy of Windows XP, although slipstreaming SP3 into the gold release is still supported. An unsupported workaround to install SP3 on Windows XP RTM also exists. Windows Vista Service Pack 2 also is not cumulative and requires at least SP1 to be present on an installed copy of Windows Vista.

What's difference between Security Patch, HotFix and Service Pack?

Security Patch - Publicly released update to fix a known bug/issue
A security patch is a change applied to an asset to correct the weakness described by a vulnerability. This corrective action will prevent successful exploitation and remove or mitigate a threat’s capability to exploit a specific vulnerability in an asset.

Security patches are the primary method of fixing security vulnerabilities in software. Currently Microsoft releases their security patches once a month, and other operating systems and software projects have security teams dedicated to releasing the most reliable software patches as soon after a vulnerability announcement as possible.

Hotfix - update to fix a very specific issue, not always publicly released
A hotfix is a single, cumulative package that includes one or more files that are used to address a problem in a software product (i.e. a software bug). Typically, hotfixes are made to address a specific customer situation and may not be distributed outside the customer organization.

A hotfix package might contain several encompassed bug fixes, raising the risk of possible regressions. An encompassed bug fix is a software bug fix which is not the main objective of a software patch, but rather the side-effect of it. Because of this some libraries for automatic updates like StableUpdate also offer features to uninstall the applied fixes if necessary.

In a Microsoft Windows context, hotfixes are small patches designed to address specific issues, most commonly to freshly-discovered security holes. These are small files, often automatically installed on the computer with Windows Update (although some may only be able to be obtained via Microsoft Support) and could contain a hot patch eliminating the need for a reboot.

Service Pack - Large Update that fixes many outstanding issues, normally includes all Patches, Hotfixes, Maintenance releases that predate the service pack.

A service pack (in short SP) is a collection of updates, fixes and/or enhancements to a software program delivered in the form of a single installable package. Many companies, such as Microsoft or Autodesk, typically release a service pack when the number of individual patches to a given program reaches a certain (arbitrary) limit. Installing a service pack is easier and less error-prone than installing a high number of patches individually, even more so when updating multiple computers over a network.Service packs are usually numbered, and thus shortly referred to as SP1, SP2, SP3 etc