Tuesday, 4 August 2015

Microsoft buys sales-gamification startup with eye to CRM combo

Microsoft has acquired Incent Games and plans to integrate the Texas startup's FantasySalesTeam sales-gamification software into Dynamics CRM.

Terms of the deal were not disclosed.

Adding the fantasy sports component to its CRM offering will give companies a tool to make incentive programs for sales staff more engaging, according to Bob Stutz, corporate vice president for Microsoft Dynamics CRM, in a who discussed the news in a blog post.

Microsoft will integrate the platform into its own Dynamics CRM software in the coming months, Stutz said. It will also continue to support customers using FantasySalesTeam with other CRM products.

However, the move drew some derisive commentary from at least one analyst.

"Are they kidding?" said Denis Pombriant, managing principal at Beagle Research Group, via email. "Let's see, for many years and even centuries, we have incentivized sales people with money (the carrot) and job loss (the stick). That wasn't enough? Really?"

The real problem with incentives is the difficulty in individualizing and applying them across a product line that contains more than one product, and that can't be solved with gamification, Pombriant said.

Rather, it's a big data problem, he suggested, and it can be solved by comprehensive compensation-management systems such as what's offered by companies like Xactly and Callidus.

"We spend all kinds of effort and resources trying to squeeze more productivity out of sales reps," Pombriant said. "It makes little sense to me to introduce a game system that takes their attention away from the business at hand rather than pursuing results."

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Sunday, 26 July 2015

7 places you’ll be surprised to learn are still using Windows XP

More than a year after Microsoft ended support for the aging OS, some high-profile organizations are still using Windows XP -- and putting themselves at risk.

7 places you’ll be surprised to learn are still using Windows XP
Microsoft announced in April 2014 that it would no longer support the 13-year-old Windows XP operating system. However, now, more than a year later, Kaspersky Labs and Net Applications both report that between 16-17 percent of computer users still use XP. You may think that it's mostly consumers, but the reality is that millions of business-critical systems are still running Windows XP, leaving them open to potential security issues. "When a company ends support, like Microsoft did, then vulnerabilities don't get fixed. If these vulnerabilities get public, [they] will be all over the Internet and easy to exploit. The problem with XP is that it was such a good, robust system that is still has quite a large user base," says Andrey Pozhogin, senior product marketing manager at Kaspersky Lab North America.

We were surprised to uncover some large organizations still relying on this retired technology. Here's a look at seven places you wouldn't expect to still be using Windows XP.

The U.S. Navy
According to a recently unclassified Navy document, Microsoft applications affect "critical command and control systems" on ships and land-based legacy systems, leaving them open to potential cybersecurity risks. But they aren't standing idly by as they work to rid themselves of these legacy systems.

According to an IDG News Service report, the U.S. Navy just entered into a $9.1 million contract that would keep the XP security patches and updates coming until 2017. Over the entire length of the contract, the total will near $31 million.

"Without this continued support, vulnerabilities to these systems will be discovered, with no patches to protect the systems," the Navy document says. "The resulting deterioration will make the U.S. Navy more susceptible to intrusion ... and could lead to loss of data integrity, network performance and the inability to meet mission readiness of critical networks."

The Navy is also paying for continued support for Microsoft's Office 2003, Exchange 2003 and Server 2003. The Navy has been transitioning away from the obsolete systems but at the time of this report it has more than 100,000 workstations running Windows XP and other aging systems.

The U.S. Army
The Navy isn't the only branch of the military struggling with outdated technology. The Army purchased a Microsoft Custom Support Agreement (CSA) for Windows XP last year. Like the Navy, the Army doesn't want to give specifics on which systems are affected but the document states the following: "This procurement will ensure the Army has continued extended support to avoid security vulnerabilities on the existing licenses. The security updates for vulnerabilities rated 'critical' will be provided at no additional charge, but per hotfix, fees apply for security hotfixes rated 'important.' Non-security hotfixes are not available."

This would seem to indicate that, like the Navy, some of these systems are mission critical.

Crown Commercial Service
The Crown Commercial Service, Great Britain's government agency in charge of the improvement of commercial ties and procurement activities, has paid for XP extended support until 2015, but in May decided to end the contract, leaving thousands of computers at risk to attack from "low-level hackers," according to a recent article from The Guardian. Government officials said the departments in question had known for seven years that this day was coming and they would need to migrate away from Windows XP. "We expect most remaining government devices using Windows XP will be able to mitigate any risks, using the CESG guidance. Where this is not possible, they may need to review their own short term transition support," says Britain's Government Digital Service tech blog.

The National Health Service
Another quick stop in Great Britain brings us to their National Health Service, an organization responsible for a publicly funded healthcare system -- an enormous government agency. Last October, it reported that, "35 percent of NHS Trusts are still running Windows XP seven months after it reached end of life." In fact, 14 percent of those NHS Trusts were so reliant that they were unable to set a date for transition. With the recent high-profile hacking cases, the NHS seems like it could be a privacy disaster waiting to happen.

In 2008, the NHS had implemented a plan to update systems across the entire organization to address these issues but abandoned the endeavor after pouring 12 billion pounds into the plan.
Atms still using Windows XP

ATMs around the globe
Last October, a whopping 95 percent of ATMs were still using Windows XP and hackers where exploiting this to drain ATM machines. In 2014, Kaspersky Lab's Global Research and Analysis Team was hired as forensic investigators to find out how thieves were tapping ATM machines in Eastern Europe.

"During the course of this investigation, we discovered a piece of malware that allowed attackers to empty the ATM cash cassettes via direct manipulation. At the time of the investigation, the malware (Backdoor.MSIL.Tyupkin) was active on more than 50 ATMs at banking institutions in Eastern Europe. Based on submissions to VirusTotal, we believe that the malware has spread to several other countries, including the U.S., India and China," the Kasperky's team reported.

As recent as May, incidents continue to be reported in both Eastern and Western Europe. In the most recent one, thieves made away with 1.23 million pounds. The European ATM Security Team (EAST), the arm responsible for oversight of trends in ATM fraud said, "As a significant number of Europe's ATMs continue to use the Windows XP operating system, there are concerns that many remain vulnerable to ATM malware if the necessary preventative measures are not taken."

Water utility companies using XP
Last year, Forbes reported that an alarming 75 percent of life-sustaining water utility companies were still operating using Windows XP. Numbers like that make this area vulnerable to cyber attacks. According to Matt Wells, general manager for automation software at GE Intelligent platforms, the utilities industry is slow to adopt new technologies but with the ending of XP support, cloud computing will help these outfits transition to newer technology.

The U.S. electrical energy industry
In a recent Forbes article by Michael Assante, the former vice president and CSO for the North American Electric Reliability Corp. and former CSO for American Electric Power Company Inc, Windows XP is still being used on workstations in a majority of the electric and gas utilities in the U.S.

The energy industry reported last August that they were worried, too. In fact, cybersecurity has moved onto the list of the top five concerns for U.S. electric utilities, according to data from a recent U.S. News and World Report article, which revealed that "…if only nine of the country's 55,000 electrical substations were to go down -- whether from mechanical issues or malicious attack -- the nation would be plunged into a coast-to-coast blackout." Federal regulators have stepped in adding cybersecurity standards for the electric industry. Cybersecurity, according to the report, has "surged in the ranking of the Top 10 industry issues … leapfrogging two spots to number four."

Just for laughs

While not an XP issue, this Gizmodo article reports that in 1985, the Grand Rapids School District put into service a Commodore Amiga, programmed by a local student, to control heating and cooling services throughout its 19 public schools. Well, 30 years later, the Amiga is still faithfully performing its duties, although not without its share of repairs and replacement parts over the years. The best part is that the same student who originally programmed the system still lives locally and makes himself available to administer and repair any hiccups along the way. "The kid who programmed the machine is the only one who knows how to fix them," Gizmodo reports.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Saturday, 11 July 2015

PC makers tighten inventories, remain edgy about Windows 10

Even as PC business contracts for 14th straight quarter, Mac sales surge 16%

Skittish about the impact of Windows 10, including the free upgrade-from-Windows-7-and-8.1 offer, computer makers drew down inventories and sent PC shipments plummeting in the June quarter, IDC said today.

The quarter was among the worst ever for personal computers, according to the research firm, which estimated the year-over-year contraction at 11.8%. That decline was bested only twice before in the two decades that IDC has tracked shipments: in early 2013, when the January quarter was off 13% and the September quarter of 2001, which posted a decline of 12%.

OEMs (original equipment manufacturers) shipped approximately 66 million systems in the three months that ended June 30, IDC said, down from the 75 million during the same stretch in 2014.

The dramatic downturn was due to several factors, said IDC analyst Loren Loverde, who runs IDC's PC forecast team, including a tough comparative from last year as enterprises scrambled to replace obsolete Windows XP machines. The 2001 operating system was retired by Microsoft in April 2014.

But Windows 10 also played a part, Loverde contended. "We've heard from various parties, including ODMs [original device manufacturers], component makers and distributors, that they've reduced inventory as Windows 10 approached," he said.

Although the industry is more bullish about Windows 10 than its predecessor, Windows 8, that's not been reflected in larger shipments simply because OEMs aren't sure how the new OS will play out in the coming quarter or two. To safeguard against overstocking the channel, and to some extent preparing for the launch of Windows 10, OEMs played it conservative and tightened inventories by building fewer PCs.

"Although it's very difficult to quantify, I'd say that this inventory reduction is a little bit more dramatic than before Windows 8," said Loverde.

Three years ago, inventories surged as PC makers cranked out devices -- 85 million in the second quarter of 2012, 88 million in the third -- figuring that Windows 8 was going to be a big hit and juice sales. That didn't happen.

"There were a lot of [retail and distribution] customers buying additional inventory and promoting Windows 8," Loverde said. "The [negative] impact on inventory is more substantial this time, and everyone is taking a wait-and-see approach, thinking that they'll make decisions in the second half of the year."

Some of the nervousness on the part of computer makers revolves around the upgrade offer Microsoft will extend to all consumers and many businesses with existing PCs running Windows 7 or Windows 8.1. Starting July 29, Microsoft will give those customers a free upgrade to Windows 10. The deal will expire a year later, on July 29, 2016.

Because Microsoft has never before offered a free upgrade of this magnitude, it's uncharted territory for Windows OEMs. A host of unknowns, ranging from whether the free upgrade will keep significant numbers on old hardware to the eventual reaction to the new OS, have made computer makers edgy about committing to fully packing the channel.

"It's even riskier when the market is declining," Loverde said of carrying large inventories.

And the PC business has been in decline, and will continue to contract.

IDC has held to its prediction that for 2015, global PC shipments will be down 6.2% from last year's 308 million, or to around 289 million. (That may change to an even more depressing number; Loverde said IDC had not yet adjusted the figure to account for the worse-than-expected second quarter.) In 2016, the industry will shrink by another 2%.

The brightest spot in the quarter's forecast was again Apple, which IDC had in the OEM fourth spot with shipments of 5.1 million Macs, a year-over-year jump of 16%. Other manufacturers in the top five -- Lenovo, HP, Dell and Acer -- were pegged with declines of 8%, 10%, 9% and 27%, respectively.

"Apple's a pretty unique company," said Loverde. "They've cultivated their market position and product portfolio, and, of course, their positioning is towards more affluent buyers who are not as price sensitive."

Loverde was convinced that some of the Mac's strong sales in the June quarter benefited from uncertainties about Windows 10 on the part of consumers.

Unclear, said Loverde, is how the Mac will fare if, as IDC and others believe, Apple introduces a larger iPad later this year, a tablet better geared to the productivity chores typically handled by personal computers.

"I think there will be some impact on Mac shipments, but Apple is always willing to cannibalize its own products," he said. "But the upside on tablets [generated by a larger iPad] and as a brand is bigger than the risk."
Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Thursday, 25 June 2015

Best tools for single sign-on

It has been a few years since we last looked at single sign-on products, the field has gotten more crowded and more capable.

Single mindedness
Since we last looked at single sign-on products in 2012, the field has gotten more crowded and more capable. For this round of evaluations, we looked at seven SSO services: Centrify’s Identity Service, Microsoft’s Azure AD Premium, Okta’s Identity and Mobility Management, OneLogin, Ping Identity’s Ping One, Secure Auth’s IdP, and SmartSignin. Our Clear Choice test winner is Centrify, which slightly outperformed Okta and OneLogin. (Read the full review.)

Centrify Identity Service
Centrify has put together a solid single sign-on tool that also has some terrific mobile device management features. If you are in the market for both kinds of products, this should be on your short list. The admin user interface is well thought-out. Set up was quickly accomplished. Multi-factor authentication settings are located in the policy tab for users and in the apps tab for individual apps. The MFA choices are numerous, including email, SMS texts and phone calls, and security questions. Centrify comes with dozens of canned reports, plus the ability to create your own using custom SQL queries.

Microsoft Azure Active Directory Access Control
Earlier this year Microsoft added Azure Active Directory to its collection of cloud-based offerings. It is difficult to setup because you tend to get lost in the hall of mirrors that is the Azure setup process. It is still very much a work in progress and mainly a developer’s toolkit rather than a polished service. But clearly Microsoft has big plans for Azure AD, as its new Windows App Store is going to rely on it for authentication. If you already are using Azure, then it makes sense to take a closer look at Azure AD. If you are looking for a general purpose SSO portal, then you should probably look elsewhere.

Okta Identity and Mobility Management
Okta tied for first place in our 2012 review and it remains a very capable product. Okta’s user interface is very simple to navigate. Okta has beefed up its multi-factor authentication functionality. It now offers a mobile app, Okta Verify, as a one-time password generator. It also supports other MFA methods. Okta has its own mobile app that can provide a secure browsing session and allow you to sign in to your apps from your phone. It contains some MDM functionality, although it is not a full MDM tool. Reports have been strengthened as well, but reports only show the last 30 days.

OneLogin
OneLogin was the other co-winner of our 2012 review and while it is still strong, its user interface has become a bit unwieldy. OneLogin has numerous SAML toolkits in a variety of languages to make it easier to integrate your apps into its SSO routines. It also has specific configuration screens to set up a VPN login and take you to specific apps. OneLogin’s AD Connector requires all of the various components of Net Framework v3.5 to be installed. Once that was done, it was a simple process to install their agent and synchronize our AD with their service. OneLogin has 11 canned reports and you can easily create additional custom ones.

Ping Identity PingOne

Ping began as on-premises solution with PingFederate, but now offers cloud-based PingOne, web access tool PingAccess and OTP soft token generator PingID. Multi-factor authentication support is somewhat limited in PingOne. You can use PingID or SafeNet’s OTP tokens. If you want more factors, you have to purchase the on-premises Ping Federate. Reports are not this product’s strong suit. The dashboard gives you an attractive summary, but there isn’t much else. Ping would be a stronger product if consolidated their various features and focused on the cloud as a primary delivery vehicle. If that isn’t important to you, or if you have complex federation needs, then you should give them more consideration and look at PingFederate.

SecureAuth IdP

Of the products we tested, SecureAuth has the most flexibility and the worst user interface, a combination that can be vexing at times. SecureAuth is the only product tested that has to run on a Windows Server. The interface is supposed to get a refresh later this year, but the current version makes it easy to get lost in a series of cascading menus. The real strength of SecureAuth always has been its post-authentication workflow activities. SecureAuth’s MFA support is strong, featuring a wide selection of factors and tokens to choose from. This is a testimonial to its flexibility.

PerfectCloud SmartSignin
SmartSignin has been acquired by PerfectCloud and integrated into their other cloud-based security offerings. They now support seven identity providers (Amazon, Netsuite and AD) with more on the horizon and more than 7,000 app integrations. The identity providers make use of SAML or other federated means, and come with extensive installation instructions. This is a little more complex than some of its competitors. When it comes to MFA support, SmartSignin is the weakest of the products we reviewed. They are working on other MFA methods, including SMS and voice, but didn’t have them when we tested. Also, MFA is just for protecting your entire user account, there is no mechanism for protecting individual apps.


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


Saturday, 20 June 2015

Microsoft needs SDN for Azure cloud

Microsoft needs SDN for Azure cloud

Couldn't scale without it, Azure CTO says
The Microsoft cloud, through which the company’s software products are delivered, has 22 hyper-scale regions around the world. Azure storage and compute usage is doubling every six months, and Azure lines up 90,000 new subscribers a month.

Six TED Talks that can change your career
Of the hundreds of TED talks available online, many are geared toward helping people view life in a new

Fifty-seven percent of the Fortune 500 use Azure and the number of hosts quickly grew from 100,000 to millions, said CTO Mark Russinovich during his Open Network Summit keynote address here this week. Azure needs a virtualized, partitioned and scale-out design, delivered through software, in order to keep up with that kind of growth.

“When we started to build these networks and started to see these types of requirements, the scale we were operating at, you can’t have humans provisioning things,” Russinovich said. “You’ve got to have systems that are very flexible and also delivering functionality very quickly. This meant we couldn’t go to the Web and do an Internet search for a scalable cloud controller that supports this kind of functionality. It just didn’t exist.”

Microsoft wrote all of the software code for Azure’s SDN. A description of it can be found here.
Microsoft uses virtual networks (Vnets) built from overlays and Network Functions Virtualization services running as software on commodity servers. Vnets are partitioned through Azure controllers established as a set of interconnected services, and each service is partitioned to scale and run protocols on multiple instances for high availability.

Controllers are established in regions where there could be 100,000 to 500,000 hosts. Within those regions are smaller clustered controllers which act as stateless caches for up to 1,000 hosts.
Related

Why is Microsoft killing off Internet Explorer?
Microsoft builds these controllers using an internally developed Service Fabric for Azure. Service Fabric has what Microsoft calls a microservices-based architecture that allows customers to update individual application components without having to update the entire application.

Microsoft makes the Azure Service Fabric SDK available here.
Much of the programmability of the Azure SDN is performed on the host server with hardware assist. A Virtual Filtering Platform (VFP) in Hyper-V hosts enable Azure’s data plane to act as a Hyper-V virtual network programmable switch for network agents that work on behalf of controllers for Vnet and other functions, like load balancing.

Packet processing is done at the host where a NIC with a Field Programmable Gate Array offloads network processing from the host CPU to scale the Azure data plane from 1Gbps to 40Gbps and beyond. That helps retain host CPU cycles for processing customer VMs, Microsoft says.

Remote Direct Memory Access is employed for the high-performance storage back-end to Azure.
Though SDNs and open source go hand-in-hand, there’s no open source software content in the Azure SDN. That’s because the functionality required for Azure was not offered through open source communities, Russinovich says.

“As these requirements were hitting us, there was no open source out there able to meet them,” he says. “And once you start on a path where you’re starting to build out infrastructure and system, even if there’s something else that comes along and addresses those requirements the switching cost is pretty huge. It’s not an aversion to it; it’s that we haven’t seen open source out there that really meets our needs, and there’s a switching cost that we have to take into account, which will slow us down.”

Microsoft is, however, considering contributing the Azure Service Fabric architecture to the open source community, Russinovich said. But there has to be some symbiosis.

“What’s secret sauce, what’s not; what’s the cost of contributing to open source, what’s the benefit to customers of open source, what’s the benefit to us penetrating markets,” he says. “It’s a constant evaluation.”

Some of the challenges in constructing the Azure SDN were retrofitting existing controllers into the Service Fabric, Russinovich says. That resulted in some scaling issues.
Resources

7 Critical Questions to Demystify DRaaS
“Some of the original controllers were written not using Service Fabric so they were not microservice oriented,” he says. “We immediately started to run into scale challenges with that. Existing ones are being (rewritten) onto Service Fabric.

“Another one is this evolution of the VFP and how it does packet processing. That is not something that we sat down initially and said, ‘it’s connections, not flows.’ We need to make sure that packet processing on every packet after the connection is set up needs to be highly efficient. It’s been the challenge of being able to operate efficiently, scale it up quickly, being able to deliver features into it quickly, and being able to take the load off the server so we can run VMs on it.”

What’s next for the Azure SDN? Preparing for more explosive growth of the Microsoft cloud, Russinovich says.

“It’s a constant evolution in terms of functionality and features,” he says. “You’re going to see us get more richer and powerful abstractions at the network level from a customer API perspective. We’re going to see 10X scale in a few years.”
Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Tuesday, 9 June 2015

Apple shows iOS 9's major upgrades, from multitasking to picture-in-picture

Apple shows iOS 9's major upgrades, from multitasking to picture-in-picture

Side-by-side apps, video overlays, and much more are coming to iPads when Apple's mobile OS releases this fall.

Major changes are coming to our iPads, from the way we select text, to the way we interact with our favorite apps and play videos.

Speaking at Apple's Worldwide Developer Conference on Monday, Senior Vice President Craig Federighi showcased an updated version of iOS 9 that included a few new features designed specifically with tablet users in mind.

Let’s start with QuickType, an enhancement to the iPad’s onscreen keyboard that includes new shortcuts and turns into a trackpad when you place two fingers on it. The trackpad can be used to select text, move objects around, and generally combine the convenience of touch controls and the precision of a mouse.

iPads will also get access to true, onscreen multitasking, which allows two apps to run side-by-side on the screen at the same time. The new feature, which Apple calls Split View, opens two resizable virtual windows on the screen. Users will be able to control each app independently, transferring information from one to the other using simple gestures, and quickly change the program running inside each panel using a brand-new app switcher. Note: While multitasking will work on most recent iPad models, Split View will be available only on the iPad Air 2.

Finally, a new picture-in-picture feature allows users to play a video from one app while using a different app. The video appears in a tiny window can be moved around, or even pushed temporarily off-screen to allow you to focus on your work while your favorite movie or game keeps playing along. The window also includes a set of simple controls that let you pause the video or close and dismiss it without leaving the current app.

The new iPad features will arrive with iOS 9 this fall, with a public beta program open to all starting in July.




Wednesday, 3 June 2015

Exam 70-412 Configuring Advanced Windows Server 2012 Services

Exam 70-412 Configuring Advanced Windows Server 2012 Services

Published: 17 September 2012
Languages: English, Chinese (Simplified), French, German, Japanese, Portuguese (Brazil)
Audiences: IT professionals
Technology: Windows Server 2012 R2
Credit towards certification: MCP, MCSA, MCSE

Skills measured
This exam measures your ability to accomplish the technical tasks listed below. The percentages indicate the relative weight of each major topic area in the exam. The higher the percentage, the more questions you are likely to see on that content area in the exam.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

As of January 2014, this exam includes content covering Windows Server 2012 R2.

Configure and manage high availability (15–20%)

Configure Network Load Balancing (NLB)

Install NLB nodes, configure NLB prerequisites, configure affinity, configure port rules, configure cluster operation mode, upgrade an NLB cluster

Configure failover clustering
Configure quorum, configure cluster networking, restore single node or cluster configuration, configure cluster storage, implement Cluster-Aware Updating, upgrade a cluster, configure and optimise clustered shared volumes, configure clusters without network names, configure storage spaces

Manage failover clustering roles
Configure role-specific settings, including continuously available shares; configure virtual machine (VM) monitoring; configure failover and preference settings; configure guest clustering

Manage VM movement
Perform live migration; perform quick migration; perform storage migration; import, export and copy VMs; configure VM network health protection; configure drain on shutdown

Preparation resources
Managing Network Load Balancing clusters
Setting Network Load Balancing parameters
Failover cluster deployment guide

Configure file and storage solutions (15–20%)

Configure advanced file services
Configure Network File System (NFS) data store, configure BranchCache, configure File Classification Infrastructure (FCI) using File Server Resource Manager (FSRM), configure file access auditing

Implement Dynamic Access Control (DAC)
Configure user and device claim types, implement policy changes and staging, perform access-denied remediation, configure file classification, create and configure Central Access rules and policies, create and configure resource properties and lists

Configure and optimise storage
Configure iSCSI target and initiator, configure Internet Storage Name server (iSNS), implement thin provisioning and trim, manage server free space using Features on Demand, configure tiered storage

Preparation resources
Network File System
File Server Resource Manager
Dynamic Access Control: Scenario overview

Implement business continuity and disaster recovery (15–20%)

Configure and manage backups
Configure Windows Server backups, configure Microsoft Azure backups, configure role-specific backups, manage VSS settings using VSSAdmin

Recover servers
Restore from backups, perform a Bare Metal Restore (BMR), recover servers using Windows Recovery Environment (Win RE) and safe mode, configure the Boot Configuration Data (BCD) store

Configure site-level fault tolerance
Configure Hyper-V Replica, including Hyper-V Replica Broker and VMs; configure multi-site clustering, including network settings, Quorum and failover settings; configure Hyper-V Replica extended replication; configure Global Update Manager; recover a multi-site failover cluster

Preparation resources
Windows Server backup overview
Windows Recovery Environment (RE) explained
How to configure bare-metal restore/recovery media

Configure Network Services (15–20%)

Implement an advanced Dynamic Host Configuration Protocol (DHCP) solution
Create and configure superscopes and multicast scopes; implement DHCPv6; configure high availability for DHCP, including DHCP failover and split scopes; configure DHCP Name Protection; configure DNS registration

Implement an advanced DNS solution
Configure security for DNS, including Domain Name System Security Extensions (DNSSEC), DNS Socket Pool, and cache locking; configure DNS logging; configure delegated administration; configure recursion; configure netmask ordering; configure a GlobalNames zone; analyse zone level statistics

Deploy and manage IP Address Management (IPAM)
Provision IPAM manually or by using Group Policy, configure server discovery, create and manage IP blocks and ranges, monitor utilisation of IP address space, migrate to IPAM, delegate IPAM administration, manage IPAM collections, configure IPAM database storage

Preparation resources
Dynamic Host Configuration Protocol (DHCP) overview
Step-by-step: Demonstrate DNSSEC in a test lab
Holistic administration of IP address space using Windows Server 2012 IP Address Management

Configure the Active Directory infrastructure (15–20%)

Configure a forest or a domain
Implement multi-domain and multi-forest Active Directory environments, including interoperability with previous versions of Active Directory; upgrade existing domains and forests, including environment preparation and functional levels; configure multiple user principal name (UPN) suffixes

Configure trusts
Configure external, forest, shortcut and realm trusts; configure trust authentication; configure SID filtering; configure name suffix routing

Configure sites
Configure sites and subnets, create and configure site links, manage site coverage, manage registration of SRV records, move domain controllers between sites

Manage Active Directory and SYSVOL replication
Configure replication to Read-Only Domain Controllers (RODCs), configure Password Replication Policy (PRP) for RODC, monitor and manage replication, upgrade SYSVOL replication to Distributed File System Replication (DFSR)

Preparation resources
Deploy Active Directory Domain Services (AD DS) in your enterprise
Active Directory domains and trusts
Introduction to Active Directory replication and topology management using Windows PowerShell (Level 100)

Configure Identity and Access Solutions (15–20%)

Implement Active Directory Federation Services (AD FS)
Install AD FS; implement claims-based authentication, including Relying Party Trusts; configure authentication policies; configure Workplace Join; configure multi-factor authentication

Install and configure Active Directory Certificate Services (AD CS)
Install an Enterprise Certificate Authority (CA), configure certificate revocation lists (CRL) distribution points, install and configure Online Responder, implement administrative role separation, configure CA backup and recovery

Manage certificates
Manage certificate templates; implement and manage certificate deployment, validation, and revocation; manage certificate renewal; manage certificate enrolment and renewal to computers and users using Group Policies; configure and manage key archival and recovery

Install and configure Active Directory Rights Management Services (AD RMS)
Install a licensing or certificate AD RMS server, manage AD RMS Service Connection Point (SCP), manage RMS templates, configure Exclusion Policies, back up and restore AD RMS

Preparation resources
AD FS deployment guide
Active Directory Certificate Services overview
Deploy a private CA with Windows Server 2012






QUESTION 1
You are employed as a network administrator at ABC.com. ABC.com has an Active Directory
domain named ABC.com. All servers on the ABC.com network have Windows Server 2012
installed.
ABC.com has a server, named ABC-SR07, which is configured as a DHCP server. You have
created a superscope on ABC-SR07.
Which of the following describes a reason for creating a superscope? (Choose all that apply.)

A. To support DHCP clients on a single physical network segment where multiple logical IP
networks are used.
B. To allow for the sending of network traffic to a group of endpointsdestination hosts.
C. To support remote DHCP clients located on the far side of DHCP and BOOTP relay agents.
D. To provide fault tolerance.

Answer: A,C

Explanation:


QUESTION 2
You are employed as a network administrator at ABC.com. ABC.com has an Active Directory
domain named ABC.com. All servers, including domain controllers, on the ABC.com network have
Windows Server 2012 installed.
ABC.com has a domain controller, named ABC-DC01, which is configured as a DNS server. You
are planning to unsign the ABC.com zone.
Why should you unsign the zone?

A. To remove the zone.
B. To change the current zone type.
C. To add a new primary zone.
D. To create an Active Directory-integrated zone.

Answer: B

Explanation:


QUESTION 3
You are employed as a network administrator at ABC.com. ABC.com has an Active Directory
domain named ABC.com. All servers on the ABC.com network have Windows Server 2012
installed.
ABC.com has a server named ABC-SR01, which hosts the IP Address Management (IPAM)
Server feature. ABC.com also has a server, named ABC-SR02, which is configured as a DHCP
server.
You have been instructed to make sure that a user, named Mia Hamm, who belongs to the IPAM
Users group on ABC-SR01, has the ability to modify the DHCP scopes on ABC-SR02 by making
use of use IPAM. You want to achieve this without assigning Mia Hamm any unnecessary
permissions.
Which of the following actions should you take?

A. You should consider making Mia Hamm a member of the DHCP Administrators group on ABCSR02.
B. You should consider making Mia Hamm a member of the IPAM Administrators group on ABCSR02.
C. You should consider making Mia Hamm a member of the Local Administrators group on ABCSR02.
D. You should consider making Mia Hamm a member of the Domain Administrators group.

Answer: A

Explanation:


QUESTION 4
You are employed as a senior network administrator at ABC.com. ABC.com has an Active
Directory domain named ABC.com. All servers on the ABC.com network have Windows Server
2012 installed.
You are currently running a training exercise for junior network administrators. You are discussing
the DNSSEC NRPT rule property.
Which of the following describes the purpose of this rule property?

A. It is used to indicate the namespace to which the policy applies.
B. It is used to indicate whether the DNS client should check for DNSSEC validation in the
response.
C. It is used to indicate DNSSEC must be used to protect DNS traffic for queries belonging to the
namespace.
D. It is used to whether DNS connections over DNSSEC will use encryption.

Answer: A

Explanation:


QUESTION 5
You work as an administrator at ABC.com. The ABC.com network consists of a single domain
named ABC.com. All servers on the ABC.com network have Windows Server 2012 installed.
ABC.com has a server, named ABC-SR07, which has the AD DS, DHCP, and DNS server roles
installed. ABC.com also has a server, named ABC-SR08, which has the DHCP, and Remote
Access server roles installed. You have configured a server, which has the File and Storage
Services server role installed, to automatically acquire an IP address. The server is named ABCSR09.
You then create a filter on ABC-SR07.
Which of the following is a reason for this configuration?

A. To make sure that ABC-SR07 issues ABC-SR09 an IP address.
B. To make sure that ABC-SR07 does not issue ABC-SR09 an IP address.
C. To make sure that ABC-SR09 acquires a constant IP address from ABC-SR08 only.
D. To make sure that ABC-SR09 is configured with a static IP address.

Answer: B

Explanation: