Showing posts with label Windows Server 2012 R2. Show all posts
Showing posts with label Windows Server 2012 R2. Show all posts

Monday, March 31, 2014

Remote Desktop Gateway Pluggable Authentication and Authorization Sample

With the release of Windows Server 2012 R2, Microsoft added a new feature for the RD Gateway role called Pluggable Authentication.

“…Remote Desktop Gateway pluggable authentication. Both customers and partners asked for a more flexible way to authenticate users connecting from the Internet. RD Gateway pluggable authentication allows custom authentication routines to be used with RD Gateway. This can provide custom two-factor authentication and works seamlessly with Remote Desktop Web Access (RD Web Access) or RDP file resource launching (even when using third-party browsers with RD Web Access)…”
Source: http://blogs.msdn.com/b/rds/archive/2013/07/09/what-s-new-in-remote-desktop-services-for-windows-server-2012-r2.aspx

In addition to that, Microsoft released sample code to explain the available Remote Desktop Gateway (RD Gateway) authentication and authorization models and demonstrate how to deploy authentication and authorization plug-ins for RD Gateway.

More info and download: http://code.msdn.microsoft.com/Remote-Desktop-Gateway-517d6273/view/Reviews

Thursday, August 8, 2013

KB: Error "Invalid parameter" when add Domain Local group for VDI collection (2877941)

A new KB article (2877941) was released today (FAST PUBLISH type) regarding adding Domain Local groups to the User Groups section of a Session Collection. Apparently, this is not supported yet, but will be added in Windows Server 2012 R2.

“…Consider the following scenario:
1. Click on a VDI collection (Personal or Pooled)
2. Click Task, then click “Edit properties”
3. In the opened window of the collection properties, click “User Groups”
4. Add a group, the type is "Security Group - Domain Local"
5. Click OK, we see error "Invalid parameter"

This is a known limitation with Windows Server 2012, There is no workarounds other than using other group types. This issue will be fix in Server 2012 R2…”

Source: http://support.microsoft.com/kb/2877941/en-us?sd=rss

Wednesday, July 10, 2013

New Remote Desktop App for Windows 8.1 in the Microsoft Store!

For Windows 8.1, which is currently available in preview, a new Remote Desktop App is available in the App Store. The version has some significant improvements compared to the one available for Windows 8 and Windows Server 2012.

When we use the Remote Desktop App to signup a connection to a workplace to retrieve published Remote Apps and Desktops we did not have the ability to remove this sign up or manually update the sign up to retrieve the most up to date Remote Apps and Desktops assigned to our account. In order to do this you had to switch back to the Classic Control panel and perform those actions in the RADC Control Panel applet (Remote App & Desktop Connections). This functionality has been added to the Remote Desktop App available in the Windows Store for Windows 8.1 !

After doing a sign up we can swipe from the right and select “Manage RemoteApp and Desktops”. This option was previously called “Access RenoteApp and Desktops”.

Windows 8.1 Windows 8
image image

When we choose this option we get an overview of all the Work Resources we have performed a signup for. The name Work Resources is the default name of a RDS deployment in 2012, which can be changed

image

When we click the a Work Resources item we’re presented with the screen below. This contains an overview of the details of the connection with the Connection URL and the amount of Remote Apps and Desktops.

image

Here we can easily hit “Update” to retrieve the latest set of Remote Apps and Desktops assigned to us. And we have the ability to remove this sign up by choosing “Remove”.

The functionality itself is not new of course as it has always been available in the classic RADC, however it’s good to see that this functionality is now also available in Desktop Desktop App!

Second improvement is accessing the on screen keyboard and touch pointer from within a Full Desktop Session using the Connect option inside the Remote Desktop App.

image

When we’re running the Full Desktop Session we can now easily swipe from the bottom and instantly select the on screen keyboard as well toggle the touch pointer on and off.

image

Thursday, July 4, 2013

Closer look at Remote App and Full Desktop experience improvements in Windows Server 2012 R2 and Windows 8.1

At Tech Ed 2013 US, Microsoft releases more info on the improvements on Remote Apps and Full Desktops in Windows Server 2012 R2. I highlighted the improvements in my What's New in Windows Server 2012 R2 Virtual Desktop Infrastructure and Remote Desktop Services (more details!) blog post. Now that the R2 release is officially in preview, let’s take a closer look at the improvements in experience compared to Windows Server 2012.

As a background, Remote Apps are published application on a RD Session Host (or VM) and interact seamlessly with the local desktop. With the upcoming R2 release Microsoft improved the way Remote Apps behave (from a client’s perspective) in order to create an experience that’s now even closer to locally installed applications than before.

One of the improvements is related to Remote App window’s. In order to be able to show those differences, I configured my lab with a RD Session Host running 2012 and a RD Session Host running 2012 R2 in separate Session Collections, as part of the  same deployment. In both Session Collection I published the same Remote App, WordPad. That results in the following Web Access view.

image

When we open both Remote Apps two separate sessions are logged on, one for each Session Collection, and we’re presented with two Remote Apps.

image

Better experience dragging, minimizing and maximizing a Remote App

We notice the first improvement immediately when moving the Remote Apps on our Desktop. When we drag the Remote App running on Windows Server 2012, we’ll notice a thick black border and while dragging we the window the actual window is not shown, only a border representing the window we’re dragging.

image

Doing the same action on Windows Server 2012 R2 results in a much better experience (although this is complicated to capture in a screens shot). Dragging a Remote App running on R2 is much much closer to the experience of dragging a local application. Black borders don’t occur, and while dragging the contents of the application are also shown.

Live taskbar preview of a Remote App

Another improvement becomes visible when hovering over task bar. With Server 2012 R2 we’re able to show a live preview of the Remote App, were server 2012 only shows a icon. The screenshot below shows this difference.

image

Automatically adapting to rotation

The experience for Remote Apps on Tablets and hybrids has also been improved. If we run a Remote App on a Windows 8 tablet and hybrid and rotate the tablet from landscape to portrait that would result in a disconnect and reconnect of the Remote App.

The Remote App running in landscape on a Windows 8 tablet
image

When turning the tablet to portrait, the Remote App disconnects and reconnect. And although the reconnect is automatic, it’s annoying, especially when running multiple Remote Apps.
image

The Remote App running in landscape on a Windows 8.1 tablet
image

When turning the tablet to portrait, the Remote App instantly rotates and no disconnect and reconnect exists.
image

This improvement makes the Remote App experience on tablets and hybrids much better.The improvement relies on the Remote Desktop Client (RDC) version 8.1 and thus at this point requires Windows 8.1 or Windows Server 2012 R2 (as the client). Although we can expect a RDC 8.1 update to be released for Windows 8. This means that this improvement is also in place when connecting to a Windows Server 2012 using a RDC 8.1

Automatically adapting to screen resolution change

For Full Desktops, a improvement has been made related to automatically adapting to the local screen resolution. With Windows Server 2012 and RDP 8.0, if you had a full desktop session running in full screen mode, and you would change the local screen resolution, and then come back to the RDS session and maximize that, it would still maximize to the previous resolution. With RDP 8.1, the screen resolution of the remote session automatically adapts to the resolution of the local session. In this example I opened 2 full desktop sessions, 1 session to a RD Session Host server running Server 2012 and 1 to a RD Session Host server running 2012 R2, both part of the same deployment (two separate Session Collections). II then minimized both sessions and changed the local screen resolution to be smaller. Upon maximizing both Full Desktop sessions again this is what Windows Server 2012 looks like (scroll bars all over the place)

image

This is what Windows Server 2012 R2 looks like. It automatically adapted to the local resolution!

image

Note that to use this new feature both the Remote Desktop Client (RDC) version 8.1 is also needed.

This concludes this blog post on Remote App and Full Desktop experience improvements in Windows Server 2012 R2 and Windows 8.1. The improvements introduced result in a Remote App experience that is much closer to the experience of running local applications. I’m looking forward to the General Availability of R2 and 8.1 !

Monday, July 1, 2013

Detailed walkthrough on Remote Control (Shadowing), reintroduced in Windows Server 2012 R2

As you probably know the ability to Remote Control a user in RDS (shadowing) was removed from Windows Server 2012. I briefly talked about that in a Customer Review I wrote for blogs.msdn.com. In the R2 upgrade of Windows Server 2012, Remote Control has been reintroduced! I briefly discussed this in the blog post What's New in Windows Server 2012 R2 Virtual Desktop Infrastructure and Remote Desktop Services (more details!)

Now that the preview bits for Windows Server 2012 R2 have been released during Tech Ed Europe in Madrid, I’m able to show Remote Control (shadowing) in Windows Server 2012 R2 in greater detail.

With Windows Server 2012, there are 2 options to perform the Remote Control of a user session. Using the Server Manager GUI or using a the Command Line.

Remote Control using Server Manager GUI

Open the Server Manager Console and select Remote Desktop Services. You now have two options to find the user you want to Remote Control. Click on “Collections” and the look at the Connections section. This view contains all active or idle sessions within every Session Collection as part of the deployment.

image

Or, if you know the Session Collection under which the user is active, in stead of clicking on “Collections”, click on the collection in question and then look at the Connections section.

To Remote Control a user, right click the user and choose Shadow

image

You will then be prompted asking if you would like to view or control the session and if the users needs to be prompted, which can also be enforced using GPO.

image

The user in question will receive an authorization request as shown below.

image

While waiting for the users response the administrator is represented with the dialog below.

image

If the user clicks No or does not respond within 30 seconds the administrator that launched the Remote Control will be presented with a “The operator or administrator has refused the request”.

image

The 30 seconds is also configurable suing the GPO:

Computer Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Connections\Set Rules for Remote Control of Remote Desktop user Session

If he chooses to accept, the Remote Control will start and the administrator will be presented with the remotely controlled session easily recognizable by looking at the name of the window as shown below.

image

Remote Control using the Command line

The second method to Remote Control is by using the command line. In order to be able to perform the command line Shadow the client machine must be running at least Remote Desktop Client 8.1 (which at this point is only available for Windows 8.1 (preview) or Windows Server 2012 R2 (preview), but will be become available for Windows 8 and Windows Server 2012 in the future.

image

The reason for this requirement is that the shadowing option has become part of the mstsc.exe executable itself.

To be more precise, the shadowing is now a command line parameter of mstsc.exe which can be confirmed by running mstsc.exe /help, which will result in the screenshot below.

image

The syntax to shadow a session is as follows:

mstsc /v:<ServerName> /shadow:<SessionID>

We obviously first need to find out the ID of the session we want to Remote Control. The Session ID can be found by running the PowerShell command “”Get-RDUserSession” (make sure you first import the module RemoteDesktop) and is retrieved in the UnifiedSessionId column.

image

And while inside the PowerShell console it’s probably most convenient to do the mstsc command from within there is as well.

image

The authorization process is the same compared to launching the Shadow option from the GUI, however, by default the command line will start the Remote Control in “View” mode. If you want to be able to interact with the session the parameter /control also needs to be specified. If you want to bypass the authorization prompt, use the /noConsentPrompt option.

In the introduction I also mentioned that shadowing has not only been reintroduced in R2 but also improved. We’re now also able to Shadow a Remote App, which was previously not supported. And also it now supported to shadow a client session running multiple monitors.

Shadowing a Remote App

As an example we launch Paint as a Remote App

image

If you perform a Remote Control on this user Session (and after running through the same authorization process) you are represented with the screen below. Because the user we’re shadowing does not have a desktop we see a black screen presenting the users desktop.

image

As you might know, if a user runs more than 1 Remote Apps, additionally launched Remote Apps all run in the same user session (and thus same Session ID). Therefor, if a user would run multiple Remote Apps, they will all be visible for the administrator who is shadowing, as shown below.

image
Do note that if the end user minimizes the Remote App, it will become invisible for the administrator doing to Remote Control. So if all Remote Apps are minimized the administrator will end of with a black screen.

image

Also, note that since the black screen represents the user local desktop, I the administrator chose the Control option and would move to the lower left part of the black screen that triggers the local start menu. In the screenshot below the administrator moved the cursor to the area marked by the red square on the left. That causes the File Explorer on the local user’s client (on the right) to show a preview pane.

image

The administrator obviously cannot interact with the local desktop by performing left or right clicks, but the experience above is something to be aware of.

The black screen does not occur when shadowing a full desktop that the end user minimizes. The admin will still be able to interact with a minimized full desktop session.

Permissions

In order to be able to perform Shadowing you need permissions. If no permissions are in place it will result in the error below.

image

Being local administrator on the destination server obviously works. However, to allow non-administrators permissions to shadow you can use the following command which is also applicable for Windows Server 2008 R2 (Credits for this command go to fellow RDS MVP TP who posted this on TechNet Forum.

wmic /namespace:\\root\CIMV2\TerminalServices PATH Win32_TSPermissionsSetting WHERE (TerminalName="RDP-Tcp") CALL AddAccount "domain\group",2

Than concludes this blog post on the reintroduction or Remote Control (shadowing) in Windows Server 2012 R2.

Happy shadowing !!

Friday, June 14, 2013

Tech Ed 2013, Madrid.

bling_bethere[1]The Europe edition of Tech Ed 2013 will be held in Madrid, June 25-28. I will be staffing in the VDI booth as part of the Microsoft Solutions Experience area!

I will be doing demo’s of VDI / RDS in Windows Server 2012. If you have questions on VDI / RDS in Windows Server 2012 (or what’s coming in the R2 release) or want to see it live in action, drop by at the booth!


More info: http://europe.msteched.com/MicrosoftSolution

Opening hours of the Microsoft Solutions Experience area:

Day/Date

Hours

Tuesday, 25 June

10:30 – 13:30

Wednesday, 26 June

11:30 – 17:30

Thursday, 27 June

11:30 – 17:00

Friday, 28 June

11:30 – 15:00

Tuesday, June 4, 2013

Predefining and customizing the Modern UI Start Screen on RDS 2012 R2

In a previous blog post called Predefining and customizing the Modern UI Start Screen on RDS 2012 I explained a way to predefine the contents and layout of a Start Screen in Windows Server 2012 and publish that to your users by creating and distributing the file appsfolder.itemdata-ms (with the read attribute either disabled or enabled).

As a quick recap, the new modern UI Start Screen can no longer be controlled by commonly used techniques (despite their downsides) like folder redirection, only the All Apps section can be controller. The Start Screen contents and look and feel are stored in a binary file as part of the users (roaming) profile. The previous article showed a step-by-step guide how to create a pre-defines start screen, publish that to your end users and be allow them to modify that pre-defined Start Screen to their needs.

So what's new?

As you might have heard Windows Server 2012 R2 was announced June 3rd 2013 at Tech Ed 2013 NA. During one of the sessions a new way to customize, predefine and distribute a Start Screen to end users got introduced. So it’s time for an update!

Note that Windows Server 2012 R2 has not been released yet, I too am not able to personally test this new mechanism until preview release, which will be later this month, so the screenshots and steps below are taken from the sessions held at Tech Ed.

After you have modified the Start Screen the way you want it to look for your end users, you can use the following PowerShell command to Export the Start Screen

image

You can then store that .XML file in a central location use the following Group Policy Object called “Start Screen Layout” which is inside:

User Configuration \ Polcies \ Administrative Templates \ Start Menu and Taskbar

image

To define the centrally stored .XML file

image

In case you’re wondering, this is the description of the GPO setting.

image

So the process became much easier compared to before! As it now seems this method will be supported on Windows Server 2012, Windows 8.1 and Windows RT 8.1.

Source: http://channel9.msdn.com/Events/TechEd/NorthAmerica/2013/Key01#fbid=YavD-8dO8_f

What's New in Windows Server 2012 R2 Virtual Desktop Infrastructure and Remote Desktop Services (more details!)

Yesterday, Adam Carter (Technical Product Manager) did a session on What's New in Windows Server 2012 Virtual Desktop Infrastructure and Remote Desktop Services on Tech Ed 2013 North America and announced the some of the new features in R2 in more detail! So I’m now able to talk some more on those details. Here is a wrap up of some of the announcements on R2!

image

Let’s start with the big feedback item Microsoft got after the release of Windows Server 2012 and that is bring shadowing (Remote Control) back! Back in September 2012 I wrote a review on RDS in Windows Server 2012 for blogs.msdn.com called Managing RDS/VDI with Windows Server 2012 where I mentioned that I was very surprised and not too happy about the fact that Shadowing was a deprecated feature. And I was not the only one. I’ve seen many questions on TechNet Forum, replies to blog posts and many e-mail’s from people asking where shadowing was moved to. It is a widely used feature and it’s good that Microsoft listened to the feedback and reintroduced (and even improved!) shadowing in Windows Server 2012 R2.

A session can be shadowed using the Server Manager GUI

image

And you’ll be asked to view or interact with the session.

image

The user will be prompted to accept (if configured that way)

image

And also, it’s now fully supported to Shadow RemoteApps!! Which was previously not supported.

On the left you see a Remote App ran by the user, on the right you see the Remote Control Interface as seen by the admin.

image

Actually Shadowing / Remote Control  is now build into mstsc.exe so you don’t need the GUI to start the shadowing, for example using the command mstsc /v:<servername> /shadow 6 /control

Dynamically add / Remove monitors
Upon changing resolution or adding monitors you used to have to disconnect and reconnect to use the new resolution, that’s now dynamically. No more logoff, logon! This also works for tablet or surfaces when you rotate the device the session will pick up on that.

Improved RemoteApp behavior.
There have been many improvements in the way RemoteApp behave. Before when dragging a Window of a Remote App you just get the the windows outline

image

And, when you look at the taskbar preview you just see a genuine Excel Icon.

image

With Windows Server 2012 R2, when you drag a RemoteApp, it’s not just the border and a full preview of the application is available!

image

Quick Reconnect
The Remote App and Desktop Connections (RADC) can be used to sign up for corporate applications and desktops and publish them in the users local start screen or start menu. Part of this feature was the ability to disconnect all Remote Apps and later reconnect them. It used to take a long time to perform the full reconnect, they improved the time it takes the reconnection process to finish in R2 and it now does so under 5 seconds! Also, network loss detection has been improved to allow for a more intuitive reconnect phase.

Codec improvements
The continuing improvements in the codecs that are being used, less bandwidth, better performance.

There are some other new features not shown / announced yet, so I’m not allowed to show you that, but stay tuned to find out soon!

Source: http://channel9.msdn.com/Events/TechEd/NorthAmerica/2013/WCA-B350#fbid=YavD-8dO8_f

Monday, June 3, 2013

RDS Enhancements - Enhanced VDI in Windows Server 2012 R2

Windows Server 2012 R2 has just been announced at Tech Ed NA 2013! With Windows Server 2012 R2 new features and improvements around RDS are also announced to further enhance VDI !

I’m not allowed to show detailed information yet, but here is a quick wrap up based on what’s just been posted on blogs.microsoft.com

“'…RDS Enhancements - Enhanced VDI in Server 2012 R2 which delivers improvements in Management, Value, and User Experience. Session Shadowing allows Admins to view and remotely control active user sessions in an RDSH server. Disk dedupe and storage tiering allow for lower cost storage options. User experience for RemoteApps, network connectivity and multiple display support has been improved. Administrators can now easily support users with session desktops to provide helpdesk style support. Administrators now have even more flexible storage options to support a VDI environment without expensive SAN investments. End users will find RemoteApp behavior is more like local apps, and the experience in low-bandwidth is better, with faster reconnects and improved compression, and support for multiple monitors…”

Source: http://blogs.windows.com/windows/b/springboard/archive/2013/06/03/what-s-new-for-the-enterprise-in-windows-8-1.aspx

Expect more detailed information on these features soon on this blog including screenshots!