|By Matt Hester||
|November 3, 2013 06:00 PM EST||
In Kevin Remde's post this week he talked about many new features for Windows Server 2012 R2 Active directory. You can find his great post here: What’s New for Active Directory in Server 2012 R2. One of the new functionalities he mentioned was Workplace Join. Workplace join allows you to deal with the explosion of devices (Windows and Non-Windows (like iOS) connecting to your organization. This has you constantly trying to maintain your organizations compliance and security. Especially with users located all around the world across multiple platforms and devices this is a challenge.
If this sounds like you currently or is soon going to be you then you will want to check out Workplace join. Workplace join allows users to register devices (including IOS) for single sign-on and access to corporate data. In today’s article I am going to take a look at how to set this feature up step by step.
This feature does require Windows Server 2012 R2, and you will need to configure Active Directory and Active Directory Federation Services to make this work. Additionally you will need to create an Enterprise Certificate Authority for the certificates you will need for this service to work properly. Overall the process is straight forward, but you will need to make sure you dot all your I’s and cross your T’s. For my environment, I created 4 separate virtual machines to test this out. I created an AD DC, AD FS server, a Web Server (for testing) and a Windows 8,1 client. The full configuration and the test application for this configuration can be found here, it is an excellent article: Set up the lab environment for AD FS in Windows Server 2012 R2
Configure the Domain Controller
On the DC you will need to make a Globally Managed Service Account (GMSA). The GMSA account is required during the AD FS installation and configuration.
- Open a PowerShell command window and type:
Add-KdsRootKey –EffectiveTime (Get-Date).AddHours(-10)
New-ADServiceAccount FsGmsa -DNSHostName adfs1.contoso.com -ServicePrincipalNames http/adfs1.contoso.com
Note: This command is for a domain name contoso.com and if your ADFS server is named adfs1.
Configure Your Certificate
When you configure your domain controller you will also want to add and configure the certificate authority services. Here is a great article for this process here: Configure SSL/TLS on a Web site in the domain with an Enterprise CA. However, when you create the certificate you will want to allow for…Also check John’s video out below for a little more detail on how the certificates work. This is also something you want to make sure you follow closely.
Configure Active Directory Federation Services
On the AD FS server you will need to enroll the certificate from the article above on configuring your Enterprise CA. When you bring the cert in you will want to make sure you configure it with the follow attributes
- Subject Name (CN): adfs1.contoso.com
- Subject Alternative Name (DNS): adfs1.contoso.com
- Subject Alternative Name (DNS): enterpriseregistration.contoso.com
After you have configure your certificate you need to add the ADFS role
- Log onto the server using the domain administrator account ([email protected]).
- Open Server Manager. To do this, click Server Manager on the Start screen, or Server Manager in the taskbar on the desktop. In the Quick Start tab of the Welcome tile on the Dashboard page, click Add roles and features. Alternatively, you can click Add Roles and Features on the Manage menu.
- On the Before you begin page, click Next.
- On the Select installation type page, click Role-based or feature-based installation, and click Next.
- On the Select destination server page, click Select a server from the server pool, verify that the target computer is highlighted, and then click Next.
- On the Select server roles page, click Active Directory Federation Services, and then click Next.
- On the Select features page, click Next.
- On the Active Directory Federation Service (AD FS) page, click Next.
- After you verify the information on the Confirm installation selections page, select the Restart the destination server automatically if required check box, and then click Install.
- On the Installation progress page, verify that everything installed correctly, and then click Close.
After the role is installed you will need to configure the service. On the Server Manager Dashboard page, click the Notifications flag, and then click Configure the federation service on the server This is for a domain name confoso,com and an ADFS server named adfs1.
- The Active Directory Federation Service Configuration Wizard is launched.1.On the Welcome page, select Create the first federation server in a federation server farm and click Next.
- On the Connect to AD DS page, specify an account with domain administrator permissions for the contoso.com AD domain that this computer is joined to and then click Next.
- On the Specify Service Properties page, do the following and then click Next:
- Import the SSL certificate that you have obtained earlier. This is the required service authentication certificate. Browse to the location of your SSL certificate.
- Provide a name for your federation service, type adfs1.contoso.com. This is the same value you provided when enrolling an SSL certificated in AD CS.
- Provide a display name for your federation service, type, Contoso Corporation.
- On the Specify Service Account page, select Use an existing domain user account or group Managed Service Account and then specify the GMSA account (fsgmsa) you created when setting up the domain controller.
- On the Specify Configuration Database page, select Create a database on this server using Windows Internal Database and then click Next.
- On the Review Options page, verify your configuration selections and click Next.
- On the Pre-requisite Checks page, verify that all pre-requisite checks were successfully completed, and then click Configure.
- On the Results page, review the results and whether the configuration has completed successfully, and then click Next steps required for completing your federation service deployment.
You will also need to run some PowerShell commands and configurations to finish the ADFS configuration. In a PowerShell command window run the following commands:
When prompted for a service account, type contoso\fsgmsa$ (Or whatever account you created)
NEXT STEP IMPORTANT: After you have run the PowerShell command on your ADFS server open the AD FS Management console. Navigate to Authentication Policies. Select Edit Global Primary Authentication. Select the checkbox next to Enable Device Authentication and then click OK.
Lastly, you will need to make sure you have the following DNS records for the Device Registration Services.
IP address of the AD FS server
You can use the following procedure to add a host (A) resource records to corporate DNS for federation server and the device registration service.
- On DC1, from Server Manager, from the Tools menu, click DNS to open the DNS snap-in.
- In the console tree, expand DC1, expand Forward Lookup Zones, right-click contoso.com, and then click New Host (A or AAAA).
- In Name, type the name you will use for your AD FS farm, for this walkthrough, type adfs1.
- In IP address, type the IP address of the ADFS1 server. Click Add Host.
- Right-click contoso.com, and then click New Alias (CNAME).
- In the New Resource Record dialog box, type enterpriseregistration in the Alias name box.
In the Fully Qualified Domain Name (FQDN) of the target host box, type adfs1.contoso.com and click OK.
Configure Windows Client
- Log on to your Windows 8 Client with your Microsoft account.
- On the Start screen, open the Charms bar and then select the Settings charm. Select Change PC Settings.
- On the PC Settings page, select Network and then click Workplace.
- In the Enter your UserID to get workplace access or turn on device management box, type <login name>@<domain.com> and then click Join.
- When prompted for credentials, type your domain credentials and Click OK.
- You should now see the message: This device has joined your workplace network.
If you want to learn how to set this up for your iOS devices check out this article: Walkthrough Guide- Workplace Join with an iOS Device
As you can see there a lot of moving parts to get this in working, and from my experience you want to make sure you get the certificates correct or you will be troubleshooting into the late evening.
If you want to see this in action, check out this great video by John Savill:
For the full list in the series: Windows Server 2012 R2 Launch Blog Series Index #WhyWin2012R2
Adding public cloud resources to an existing application can be a daunting process. The tools that you currently use to manage the software and hardware outside the cloud aren’t always the best tools to efficiently grow into the cloud. All of the major configuration management tools have cloud orchestration plugins that can be leveraged, but there are also cloud-native tools that can dramatically improve the efficiency of managing your application lifecycle. In his session at 18th Cloud Expo, ...
Jul. 29, 2016 11:30 AM EDT Reads: 1,213
SYS-CON Events announced today that LeaseWeb USA, a cloud Infrastructure-as-a-Service (IaaS) provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LeaseWeb is one of the world's largest hosting brands. The company helps customers define, develop and deploy IT infrastructure tailored to their exact business needs, by combining various kinds cloud solutions.
Jul. 29, 2016 11:15 AM EDT Reads: 1,330
SYS-CON Events announced today that Venafi, the Immune System for the Internet™ and the leading provider of Next Generation Trust Protection, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Venafi is the Immune System for the Internet™ that protects the foundation of all cybersecurity – cryptographic keys and digital certificates – so they can’t be misused by bad guys in attacks...
Jul. 29, 2016 09:45 AM EDT Reads: 1,462
No matter how well-built your applications are, countless issues can cause performance problems, putting the platforms they are running on under scrutiny. If you've moved to Node.js to power your applications, you may be at risk of these issues calling your choice into question. How do you identify vulnerabilities and mitigate risk to take the focus off troubleshooting the technology and back where it belongs, on innovation? There is no doubt that Node.js is one of today's leading platforms of ...
Jul. 29, 2016 08:30 AM EDT Reads: 617
DevOps at Cloud Expo – being held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real results. Am...
Jul. 29, 2016 04:45 AM EDT Reads: 2,368
Let's just nip the conflation of these terms in the bud, shall we?
"MIcro" is big these days. Both microservices and microsegmentation are having and will continue to have an impact on data center architecture, but not necessarily for the same reasons. There's a growing trend in which folks - particularly those with a network background - conflate the two and use them to mean the same thing.
They are not.
One is about the application. The other, the network. T...
Jul. 29, 2016 04:45 AM EDT Reads: 3,701
The 19th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportuni...
Jul. 29, 2016 04:15 AM EDT Reads: 2,680
This is a no-hype, pragmatic post about why I think you should consider architecting your next project the way SOA and/or microservices suggest. No matter if it’s a greenfield approach or if you’re in dire need of refactoring. Please note: considering still keeps open the option of not taking that approach. After reading this, you will have a better idea about whether building multiple small components instead of a single, large component makes sense for your project. This post assumes that you...
Jul. 29, 2016 04:15 AM EDT Reads: 4,267
Before becoming a developer, I was in the high school band. I played several brass instruments - including French horn and cornet - as well as keyboards in the jazz stage band. A musician and a nerd, what can I say? I even dabbled in writing music for the band. Okay, mostly I wrote arrangements of pop music, so the band could keep the crowd entertained during Friday night football games. What struck me then was that, to write parts for all the instruments - brass, woodwind, percussion, even k...
Jul. 29, 2016 01:30 AM EDT Reads: 2,346
SYS-CON Events announced today that Isomorphic Software will exhibit at DevOps Summit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Isomorphic Software provides the SmartClient HTML5/AJAX platform, the most advanced technology for building rich, cutting-edge enterprise web applications for desktop and mobile. SmartClient combines the productivity and performance of traditional desktop software with the simp...
Jul. 28, 2016 10:15 PM EDT Reads: 1,256
In his session at @DevOpsSummit at 19th Cloud Expo, Yoseph Reuveni, Director of Software Engineering at Jet.com, will discuss Jet.com's journey into containerizing Microsoft-based technologies like C# and F# into Docker. He will talk about lessons learned and challenges faced, the Mono framework tryout and how they deployed everything into Azure cloud. Yoseph Reuveni is a technology leader with unique experience developing and running high throughput (over 1M tps) distributed systems with extre...
Jul. 28, 2016 10:15 PM EDT Reads: 2,240
Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 19th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world and ThingsExpo Silicon Valley Call for Papers is now open.
Jul. 28, 2016 09:00 PM EDT Reads: 2,732
Sharding has become a popular means of achieving scalability in application architectures in which read/write data separation is not only possible, but desirable to achieve new heights of concurrency. The premise is that by splitting up read and write duties, it is possible to get better overall performance at the cost of a slight delay in consistency. That is, it takes a bit of time to replicate changes initiated by a "write" to the read-only master database. It's eventually consistent, and it'...
Jul. 28, 2016 08:30 PM EDT Reads: 2,348
Jul. 28, 2016 07:15 PM EDT Reads: 3,954
Ovum, a leading technology analyst firm, has published an in-depth report, Ovum Decision Matrix: Selecting a DevOps Release Management Solution, 2016–17. The report focuses on the automation aspects of DevOps, Release Management and compares solutions from the leading vendors.
Jul. 28, 2016 11:00 AM EDT Reads: 1,823
If you are within a stones throw of the DevOps marketplace you have undoubtably noticed the growing trend in Microservices. Whether you have been staying up to date with the latest articles and blogs or you just read the definition for the first time, these 5 Microservices Resources You Need In Your Life will guide you through the ins and outs of Microservices in today’s world.
Jul. 28, 2016 04:15 AM EDT Reads: 4,164
This digest provides an overview of good resources that are well worth reading. We’ll be updating this page as new content becomes available, so I suggest you bookmark it. Also, expect more digests to come on different topics that make all of our IT-hearts go boom!
Jul. 28, 2016 12:30 AM EDT Reads: 3,756
Keeping pace with advancements in software delivery processes and tooling is taxing even for the most proficient organizations. Point tools, platforms, open source and the increasing adoption of private and public cloud services requires strong engineering rigor – all in the face of developer demands to use the tools of choice. As Agile has settled in as a mainstream practice, now DevOps has emerged as the next wave to improve software delivery speed and output. To make DevOps work, organization...
Jul. 28, 2016 12:15 AM EDT Reads: 2,292
There's a lot of things we do to improve the performance of web and mobile applications. We use caching. We use compression. We offload security (SSL and TLS) to a proxy with greater compute capacity. We apply image optimization and minification to content. We do all that because performance is king. Failure to perform can be, for many businesses, equivalent to an outage with increased abandonment rates and angry customers taking to the Internet to express their extreme displeasure.
Jul. 27, 2016 03:30 PM EDT Reads: 1,650
Right off the bat, Newman advises that we should "think of microservices as a specific approach for SOA in the same way that XP or Scrum are specific approaches for Agile Software development". These analogies are very interesting because my expectation was that microservices is a pattern. So I might infer that microservices is a set of process techniques as opposed to an architectural approach. Yet in the book, Newman clearly includes some elements of concept model and architecture as well as p...
Jul. 27, 2016 02:30 PM EDT Reads: 9,797