What can Windows Server 2008 do for you?

I know there are many websites that lists a bunch of features of Microsoft’s latest Windows Server 2008.  I also know that these lists sometimes forget the fact that technology in the workplace is only as good as the business value benefited from it. I understand that during these tough economic times, migrating and upgrading your systems to Windows Server 2008 will be an option that is heavily scrutinized.  Hopefully, this blog entry will help you create an informed decision for your business.

Below are the features that stand out to me when deploying Windows Server 2008. I will try to explain how these features can translate to a more secure, efficient, and stable network.

Active Directory

  • Restartable Active Directory Domain Services (RADDS)
    Essentially, this increases uptime for a domain controller and it’s installed services. Currently, when security patches must be applied, offline defragmentation or authoritive restores must be performed, the entire server has to be rebooted.  This equates to significant downtime for ALL the services provided by the server. If this was a heavily used server, such as a file server, a lot of users would end up calling the IT department.Scenario:

      Lets say an Active Directory object needs to be restored from backup. Previous to Windows Server 2008, a server would have to be restarted in Directory Services Restore Mode.  During this time, ALL services provided by that server would be offline. Then, once the restore is complete, we must restart the server again. Now, with RADDS, you only need to stop the service, perform the restore, and restart the service.  Meanwhile, your other services are still working.

Translated Value:

    Increased uptime, Simplified restoration of Active Directory objects.

Business Circumstance:

    This is useful for all businesses.
  • Read-Only Domain Controller (RODC)
    Back in the good ‘ol NT4 days, Microsoft had primary and backup domain controllers (PDCs and BDCs).  The backup domain controllers would be Read-Only.  Then, they touted the multi-master capabilities of Active Directory for Windows 2000/2003. What they didn’t tell you was the best solution was “C. All of the Above“. In Windows Server 2008, we can have multi-master domain controllers AND read-only domain controllers. When would you use either of these scenarios?  Well, you would want multi-master replication for Fault Tolerance and Management Simplicity.   Now, an RODC would allow for increased security since the LDAP database can not be tampered with. Unfortunately, there are limitations that might negate the benefits of this.  Essentially, the RODC needs to have access to a writable Domain Controller in order to perform basic functions, such as DNS updates, password changes, and user authentication (if not cached on RODC). There could also be software compatibility issues.Translated Value:

      This is a feature that’s great to have, but wouldn’t benefit an existing organization tremendously.

Business Circumstance:

    This is most useful for medium/large businesses with multiple locations.

OS Enhancements

  • NTFS Self-Healing
    As with previous operating systems, when a file on the NTFS filesystem becomes corrupt, there’s no way to know unless you a) run chkdisk b) try to open the file.  Of course, if you periodically run chkdsk to detect corruptions or try to open a corrupt file, you would have to reboot your server to fix it. This is not the case with Windows Vista and Windows Server 2008.  In 95% of the cases, it will automatically detect a corruption in your filesystem and attempt to fix it at the same time.  This eliminate the need to reboot.  I’m sure everyone knows the disadvantages of having to reboot a computer by now (read previous sections).Translated Value:

      Higher uptime, important data is recovered

Business Circumstance:

    This is useful for all businesses.
  • Server-core
    Everyone can agree that Microsoft has it’s GUI advantages over Linux, while Linux has it’s high stability and security aspects due to it’s lack of “fluff”.  Well, as Linux tries to enter the Desktop market, Microsoft is trying to imitate Linux with Server-core. IT provides a minimal (non-GUI) OS environment for running specific server roles, which reduces the attack surface for those server roles.  Similar to Linux, in which you would manage your server from an SSH connection, Server Core could be managed from the local command console, Terminal Server connection, or using the MMC console. Once again, Server-core can only provide a subset of the full roles available to a full installation.  Server-core can provide the following roles: Active Directory Domain Services (AD DS), Active Directory Lightweight Directory Services (AD LDS), DHCP Server, DNS Server, File Services, Print Services, Streaming Media Services, Internet Information Services (IIS), Windows Virtualization.Translated Value:

      Increased security and performance gains, and ease of deployment due to low footprint.

Business Circumstance:

    This is most useful for medium/large businesses with multiple locations.
  • Terminal Services Gateway (TS Gateway)
    Lets say you had to remotely connect to multiple servers at the Office, yet you are prevented from using a VPN connection. What do you do?  Well, there are many ways around this, including the use of 3rd party applications, but Microsoft has blessed us with their solution. A TS Gateway securely proxies applications running the RDP protocol (Remote Desktop, Remote Applications, etc..) through SSL encryption.  This negates the typical firewall configurations necessary to allow VPN tunnels to be created.Translated Value:

      Mobile Office is even more robust. You can truly access your servers and workstations from anywhere.

Business Circumstance:

    This is most useful for businesses running Terminal Services or those with lots of servers.
  • Terminal Services Remote Application (TS Remote Application)
    Aligned with their virtual application technology, TS Remote Application uses the RDP protocol to allow users access to specific applications stored on a server. Instead of using more computing resources than necessary and  providing access to an entire Desktop, users can now be limited only to the capabilities of the application. Advance connection policies can be set in place to maintain compliance with security policies set within the company.Scenario:

      Accounting staff requires access to the Quickbooks server when they are offsite.  Using a VPN connection alone is not an acceptable solution since the data transfer size is too large. The use of Remote Desktop through a VPN connection would work, but that can cause unecessary confusion for users. With TS Remote Application, the Quickbooks application RDP file can be exported on a users’s desktop.  When they run the file, either locally or remotely, they will see the Quickbooks applications open on their computer. This application is actually running on the remote computer, but the interface is exactly the same as if they opened it locally on their computer.

Translated Value:

    Granular access to applications, secure access to network resources, improved capacity and performance for Terminal Services applications

Business Circumstance:

    This is most useful for businesses running Terminal Services or those with lots of servers.
  • Windows Deployment Services (WDS)
    This service allows is the needed replacement for Remote Installation Services (RIS). Windows Deployment Services enables you to deploy Windows operating systems, particularly Windows Vista, using images and PXE booting. I know there are 3rd party applications that provide this capability in a more simplified manner, but they are often too costly. Once setup, WDS is a pretty cool application.  It works well and have few heart-stopping limitations.Translated Value:

      You can setup new Microsoft workstations quickly and in an automated way.

Business Circumstance:

    This is most useful for new businesses or ones that are growing in the near future.
  • Hyper-V
    Here’s the deal.  The IT industry is realizing that on average, the load on a server is pretty low due to minimal resource usage and advancing. This results in wasted Energy Costs and lower Return on Investment (ROI) in the hardware. Hyper-V is a hypervisor-based virtualization technology that allows servers to run multiple instances of Microsoft and certain Linux distributions. What is sometimes overlooked when it comes to virtualization is the ease and consistency in obtaining a solid backup and recovery of files using snapshoting technologies.  Also, the management of these virtual servers are simplified since there is only one platform to work off of.Translated Value:

      Increased efficiency of resources, increased stability, reduction in cost for new server deployments, High availability, increased security.

Business Circumstance:

    This applies to all businesses.  From consolidation to saving on energy costs, virtualization is beneficial for all businesses.