|By Matt Hester||
|November 3, 2013 06:00 PM EST||
In Kevin Remde's post this week he talked about many new features for Windows Server 2012 R2 Active directory. You can find his great post here: What’s New for Active Directory in Server 2012 R2. One of the new functionalities he mentioned was Workplace Join. Workplace join allows you to deal with the explosion of devices (Windows and Non-Windows (like iOS) connecting to your organization. This has you constantly trying to maintain your organizations compliance and security. Especially with users located all around the world across multiple platforms and devices this is a challenge.
If this sounds like you currently or is soon going to be you then you will want to check out Workplace join. Workplace join allows users to register devices (including IOS) for single sign-on and access to corporate data. In today’s article I am going to take a look at how to set this feature up step by step.
This feature does require Windows Server 2012 R2, and you will need to configure Active Directory and Active Directory Federation Services to make this work. Additionally you will need to create an Enterprise Certificate Authority for the certificates you will need for this service to work properly. Overall the process is straight forward, but you will need to make sure you dot all your I’s and cross your T’s. For my environment, I created 4 separate virtual machines to test this out. I created an AD DC, AD FS server, a Web Server (for testing) and a Windows 8,1 client. The full configuration and the test application for this configuration can be found here, it is an excellent article: Set up the lab environment for AD FS in Windows Server 2012 R2
Configure the Domain Controller
On the DC you will need to make a Globally Managed Service Account (GMSA). The GMSA account is required during the AD FS installation and configuration.
- Open a PowerShell command window and type:
Add-KdsRootKey –EffectiveTime (Get-Date).AddHours(-10)
New-ADServiceAccount FsGmsa -DNSHostName adfs1.contoso.com -ServicePrincipalNames http/adfs1.contoso.com
Note: This command is for a domain name contoso.com and if your ADFS server is named adfs1.
Configure Your Certificate
When you configure your domain controller you will also want to add and configure the certificate authority services. Here is a great article for this process here: Configure SSL/TLS on a Web site in the domain with an Enterprise CA. However, when you create the certificate you will want to allow for…Also check John’s video out below for a little more detail on how the certificates work. This is also something you want to make sure you follow closely.
Configure Active Directory Federation Services
On the AD FS server you will need to enroll the certificate from the article above on configuring your Enterprise CA. When you bring the cert in you will want to make sure you configure it with the follow attributes
- Subject Name (CN): adfs1.contoso.com
- Subject Alternative Name (DNS): adfs1.contoso.com
- Subject Alternative Name (DNS): enterpriseregistration.contoso.com
After you have configure your certificate you need to add the ADFS role
- Log onto the server using the domain administrator account ([email protected]).
- Open Server Manager. To do this, click Server Manager on the Start screen, or Server Manager in the taskbar on the desktop. In the Quick Start tab of the Welcome tile on the Dashboard page, click Add roles and features. Alternatively, you can click Add Roles and Features on the Manage menu.
- On the Before you begin page, click Next.
- On the Select installation type page, click Role-based or feature-based installation, and click Next.
- On the Select destination server page, click Select a server from the server pool, verify that the target computer is highlighted, and then click Next.
- On the Select server roles page, click Active Directory Federation Services, and then click Next.
- On the Select features page, click Next.
- On the Active Directory Federation Service (AD FS) page, click Next.
- After you verify the information on the Confirm installation selections page, select the Restart the destination server automatically if required check box, and then click Install.
- On the Installation progress page, verify that everything installed correctly, and then click Close.
After the role is installed you will need to configure the service. On the Server Manager Dashboard page, click the Notifications flag, and then click Configure the federation service on the server This is for a domain name confoso,com and an ADFS server named adfs1.
- The Active Directory Federation Service Configuration Wizard is launched.1.On the Welcome page, select Create the first federation server in a federation server farm and click Next.
- On the Connect to AD DS page, specify an account with domain administrator permissions for the contoso.com AD domain that this computer is joined to and then click Next.
- On the Specify Service Properties page, do the following and then click Next:
- Import the SSL certificate that you have obtained earlier. This is the required service authentication certificate. Browse to the location of your SSL certificate.
- Provide a name for your federation service, type adfs1.contoso.com. This is the same value you provided when enrolling an SSL certificated in AD CS.
- Provide a display name for your federation service, type, Contoso Corporation.
- On the Specify Service Account page, select Use an existing domain user account or group Managed Service Account and then specify the GMSA account (fsgmsa) you created when setting up the domain controller.
- On the Specify Configuration Database page, select Create a database on this server using Windows Internal Database and then click Next.
- On the Review Options page, verify your configuration selections and click Next.
- On the Pre-requisite Checks page, verify that all pre-requisite checks were successfully completed, and then click Configure.
- On the Results page, review the results and whether the configuration has completed successfully, and then click Next steps required for completing your federation service deployment.
You will also need to run some PowerShell commands and configurations to finish the ADFS configuration. In a PowerShell command window run the following commands:
When prompted for a service account, type contoso\fsgmsa$ (Or whatever account you created)
NEXT STEP IMPORTANT: After you have run the PowerShell command on your ADFS server open the AD FS Management console. Navigate to Authentication Policies. Select Edit Global Primary Authentication. Select the checkbox next to Enable Device Authentication and then click OK.
Lastly, you will need to make sure you have the following DNS records for the Device Registration Services.
IP address of the AD FS server
You can use the following procedure to add a host (A) resource records to corporate DNS for federation server and the device registration service.
- On DC1, from Server Manager, from the Tools menu, click DNS to open the DNS snap-in.
- In the console tree, expand DC1, expand Forward Lookup Zones, right-click contoso.com, and then click New Host (A or AAAA).
- In Name, type the name you will use for your AD FS farm, for this walkthrough, type adfs1.
- In IP address, type the IP address of the ADFS1 server. Click Add Host.
- Right-click contoso.com, and then click New Alias (CNAME).
- In the New Resource Record dialog box, type enterpriseregistration in the Alias name box.
In the Fully Qualified Domain Name (FQDN) of the target host box, type adfs1.contoso.com and click OK.
Configure Windows Client
- Log on to your Windows 8 Client with your Microsoft account.
- On the Start screen, open the Charms bar and then select the Settings charm. Select Change PC Settings.
- On the PC Settings page, select Network and then click Workplace.
- In the Enter your UserID to get workplace access or turn on device management box, type <login name>@<domain.com> and then click Join.
- When prompted for credentials, type your domain credentials and Click OK.
- You should now see the message: This device has joined your workplace network.
If you want to learn how to set this up for your iOS devices check out this article: Walkthrough Guide- Workplace Join with an iOS Device
As you can see there a lot of moving parts to get this in working, and from my experience you want to make sure you get the certificates correct or you will be troubleshooting into the late evening.
If you want to see this in action, check out this great video by John Savill:
For the full list in the series: Windows Server 2012 R2 Launch Blog Series Index #WhyWin2012R2
The pricing of tools or licenses for log aggregation can have a significant effect on organizational culture and the collaboration between Dev and Ops teams. Modern tools for log aggregation (of which Logentries is one example) can be hugely enabling for DevOps approaches to building and operating business-critical software systems. However, the pricing of an aggregated logging solution can affect the adoption of modern logging techniques, as well as organizational capabilities and cross-team ...
Sep. 2, 2015 12:30 PM EDT Reads: 414
API-Driven Digital Healthcare Solution By @AkanaInc | @DevOpsSummit #API #IoT #DevOps #Microservices
Akana has announced the availability of the new Akana Healthcare Solution. The API-driven solution helps healthcare organizations accelerate their transition to being secure, digitally interoperable businesses. It leverages the Health Level Seven International Fast Healthcare Interoperability Resources (HL7 FHIR) standard to enable broader business use of medical data. Akana developed the Healthcare Solution in response to healthcare businesses that want to increase electronic, multi-device acce...
Sep. 2, 2015 12:00 PM EDT Reads: 266
Docker containerization is increasingly being used in production environments. How can these environments best be monitored? Monitoring Docker containers as if they are lightweight virtual machines (i.e., monitoring the host from within the container), with all the common metrics that can be captured from an operating system, is an insufficient approach. Docker containers can’t be treated as lightweight virtual machines; they must be treated as what they are: isolated processes running on hosts....
Sep. 2, 2015 12:00 PM EDT Reads: 171
17th Cloud Expo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterprises ar...
Sep. 2, 2015 12:00 PM EDT Reads: 1,560
In today's digital world, change is the one constant. Disruptive innovations like cloud, mobility, social media, and the Internet of Things have reshaped the market and set new standards in customer expectations. To remain competitive, businesses must tap the potential of emerging technologies and markets through the rapid release of new products and services. However, the rigid and siloed structures of traditional IT platforms and processes are slowing them down – resulting in lengthy delivery ...
Sep. 2, 2015 11:45 AM EDT Reads: 616
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding bu...
Sep. 2, 2015 11:30 AM EDT Reads: 1,627
Introducing Containers & Microservices Bootcamp at @CloudExpo Silicon Valley | #Containers #Microservices
SYS-CON Events announced today the Containers & Microservices Bootcamp, being held November 3-4, 2015, in conjunction with 17th Cloud Expo, @ThingsExpo, and @DevOpsSummit at the Santa Clara Convention Center in Santa Clara, CA. This is your chance to get started with the latest technology in the industry. Combined with real-world scenarios and use cases, the Containers and Microservices Bootcamp, led by Janakiram MSV, a Microsoft Regional Director, will include presentations as well as hands-on...
Sep. 2, 2015 11:30 AM EDT Reads: 379
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo in Silicon Valley. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading in...
Sep. 2, 2015 11:30 AM EDT Reads: 1,995
The 5th International DevOps Summit, co-located with 17th International Cloud Expo – being held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the ...
Sep. 2, 2015 11:15 AM EDT Reads: 1,611
DevOps Summit, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development...
Sep. 2, 2015 10:45 AM EDT Reads: 1,551
It’s been proven time and time again that in tech, diversity drives greater innovation, better team productivity and greater profits and market share. So what can we do in our DevOps teams to embrace diversity and help transform the culture of development and operations into a true “DevOps” team? In her session at DevOps Summit, Stefana Muller, Director, Product Management – Continuous Delivery at CA Technologies, answered that question citing examples, showing how to create opportunities for ...
Sep. 2, 2015 10:30 AM EDT Reads: 519
Microservice architecture is fast becoming a go-to solution for enterprise applications, but it's not always easy to make the transition from an established, monolithic infrastructure. Lightweight and loosely coupled, building a set of microservices is arguably more difficult than building a monolithic application. However, once established, microservices offer a series of advantages over traditional architectures as deployment times become shorter and iterating becomes easier.
Sep. 2, 2015 09:00 AM EDT
SYS-CON Events announced today that the "Second Containers & Microservices Expo" will take place November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities.
Sep. 2, 2015 07:30 AM EDT Reads: 614
SYS-CON Events announced today that Pythian, a global IT services company specializing in helping companies leverage disruptive technologies to optimize revenue-generating systems, has been named “Bronze Sponsor” of SYS-CON's 17th Cloud Expo, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Founded in 1997, Pythian is a global IT services company that helps companies compete by adopting disruptive technologies such as cloud, Big Data, advance...
Sep. 2, 2015 06:45 AM EDT Reads: 340
Early in my DevOps Journey, I was introduced to a book of great significance circulating within the Web Operations industry titled The Phoenix Project. (You can read our review of Gene’s book, if interested.) Written as a novel and loosely based on many of the same principles explored in The Goal, this book has been read and referenced by many who have adopted DevOps into their continuous improvement and software delivery processes around the world. As I began planning my travel schedule last...
Sep. 2, 2015 06:00 AM EDT Reads: 561
Puppet Labs has announced the next major update to its flagship product: Puppet Enterprise 2015.2. This release includes new features providing DevOps teams with clarity, simplicity and additional management capabilities, including an all-new user interface, an interactive graph for visualizing infrastructure code, a new unified agent and broader infrastructure support.
Sep. 2, 2015 05:15 AM EDT Reads: 549
Any Ops team trying to support a company in today’s cloud-connected world knows that a new way of thinking is required – one just as dramatic than the shift from Ops to DevOps. The diversity of modern operations requires teams to focus their impact on breadth vs. depth. In his session at DevOps Summit, Adam Serediuk, Director of Operations at xMatters, Inc., will discuss the strategic requirements of evolving from Ops to DevOps, and why modern Operations has begun leveraging the “NoOps” approa...
Sep. 2, 2015 03:45 AM EDT Reads: 430
SYS-CON Events announced today that G2G3 will exhibit at SYS-CON's @DevOpsSummit Silicon Valley, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Based on a collective appreciation for user experience, design, and technology, G2G3 is uniquely qualified and motivated to redefine how organizations and people engage in an increasingly digital world.
Sep. 2, 2015 03:00 AM EDT Reads: 529
SYS-CON Events announced today that DataClear Inc. will exhibit at the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. The DataClear ‘BlackBox’ is the only solution that moves your PC, browsing and data out of the United States and away from prying (and spying) eyes. Its solution automatically builds you a clean, on-demand, virus free, new virtual cloud based PC outside of the United States, and wipes it clean...
Sep. 2, 2015 02:30 AM EDT Reads: 456
In his session at 17th Cloud Expo, Ernest Mueller, Product Manager at Idera, will explain the best practices and lessons learned for tracking and optimizing costs while delivering a cloud-hosted service. He will describe a DevOps approach where the applications and systems work together to track usage, model costs in a granular fashion, and make smart decisions at runtime to minimize costs. The trickier parts covered include triggering off the right metrics; balancing resilience and redundancy ...
Sep. 1, 2015 03:30 PM EDT Reads: 255