Thursday, July 14, 2011

SharePoint Bible: Your Complete Guide to Microsoft's Collaboration Software

Updated: From pricing questions to enterprise and cloud adoption trends to reviews of SharePoint 2010, CIO.com's SharePoint Bible covers it all. Our guide delivers expert reviews, advice on planning and rollout, and news analysis on Microsoft's powerhouse content and collaboration platform.




Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




The Boston Red Sox have many weapons to keep the team winning on the field: powerful hitters, a seasoned pitching rotation, and an experienced coaching staff.

But off the field — and in the data center — a key role player for the Sox has been SharePoint 2010.

At the SPTechCon SharePoint conference in Boston last week, Red Sox IT director Steve Conley stepped up to the plate for a Q&A with Microsoft's (MSFT) SharePoint Product Management Director Christian Finn.
Similar to this Article

* How We're Using SharePoint 2010 to Connect Our People
* Microsoft SharePoint: 5 Tips for Keeping Content Private
* Three Phases of SharePoint: What Type of User Are You?

Conley's IT group consists of six team members that serve 250 people in the Red Sox organization. For 81 home games a year, the IT group is "in charge of anything that has a plug," says Conley, with a laugh. "If you have to turn it on, I'm probably going to get called."

Boston Red Sox

Microsoft SharePoint

The exception, he adds, is Fenway Park's giant scoreboard in center field, which is managed by a third party.

One of the biggest advances the Red Sox have made recently is to revamp its intranet portal, named "Red Sox Central", using SharePoint 2010.

The team's intranet homepage includes features such as Webcasts of game highlights, photo galleries, a ticket dashboard for executives to manage their game tickets and weather widgets for Boston and Fort Myers, Fla., home of the Red Sox spring training camp.

Slideshow: 10 Things We Love About SharePoint 2010

Within Red Sox Central, Conley — a Red Sox employee since 2001 when they "still had typewriters" — wanted to configure SharePoint to solve problems such as requesting and allocating tickets, getting credentials from visitors, and paying and organizing invoices.

[ For complete coverage on Microsoft's SharePoint collaboration software -- including enterprise and cloud adoption trends and reviews of SharePoint 2010 -- see CIO.com's SharePoint Bible. ]

On the SPTechCon stage, Conley explained how moving to SharePoint in the past few years has liberated the Red Sox from of its tech dark days of scanning and e-mailing documents, snail mailing invoices and waiting days to hear back about ticket requests.
Ticket Request Application

Red Sox employees are allotted a certain number of tickets for the season. These ticket requests had to be made through the Red Sox ticket office via paper forms, a time-consuming process that could take anywhere from hours to days.

"We were able to automate all that with SharePoint using an online form for ticket request and acquisition."

As Conley expected, the online ticket request form quickly became, and has remained, the most popular section of Red Sox Central site for employees.

Wednesday, July 13, 2011

Microsoft: Buy Windows 7 today, keep same PC for Windows 8 upgrade

Microsoft may lower hardware requirements for Windows 8

Any computer running Windows 7 will be upgradable to Windows 8, Microsoft said today while pledging to keep hardware requirements level or even lower when the next version of Windows comes out.




Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



IN PICTURES: The 11 hottest Windows and Android tablets unveiled at CES

Microsoft says it has sold more than 400 million Windows 7 licenses, but Windows XP is still nearly twice as commonly used worldwide. Yet Microsoft has already shown two technical previews of Windows 8, and announced today that a further preview of Windows 8 is coming in September. Therefore, Microsoft has a balancing act to convince businesses and consumers to upgrade to Windows 7 despite the promise of a new operating system around the corner.

"Two-thirds of business PCs are still on Windows XP. Moving these users to Windows 7 is important and urgent work for us to get after together," Tami Reller, corporate VP and CFO for Windows, said at Microsoft's Worldwide Partner Conference at the Staples Center in Los Angeles. The conference is Microsoft's opportunity to talk to partners about how they can make money together.

Windows 8 could be released next year, so to prevent businesses from holding on to their cash Microsoft is arguing that users should upgrade now and use the same PC to run Windows 8 later.

"Whether upgrading an existing PC or buying a new one, Windows will adapt to make the most of that hardware," Reller said. Windows 8 is for "the hundreds of millions of modern PCs that exist today and for the devices of tomorrow."

As we learned earlier this year, Windows 8 will be optimized for both touch-screen tablets and PCs. Microsoft announced at January's Consumer Electronics Show that it will support the ARM architecture, a lower-powered chip for mobile devices, and last month Microsoft showed off the new tablet interface.

"Windows 8 is a true re-imagining of Windows, from the chip to the interface," Reller said. Despite the re-imagining, Microsoft will keep system requirements flat or reduce them. To run Windows 7, PCs need at least a 1GHz processor, 1GB RAM, 16GB available disk space and DirectX 9 graphics.

Windows 7 tablets exist today, but regardless of Microsoft's advice, consumers are better served waiting for Windows 8 tablets to hit the market because they are likely to be more advanced and it's not yet clear whether Microsoft can create something better than Apple's iPad. The "buy today, upgrade later" advice should be applied to PCs only.

While a Windows 8 release date hasn't been revealed, Microsoft said today it will provide another technical preview at the BUILD Conference in Anaheim, Calif., Sept. 13-16.

The conference will "show modern hardware and software developers how to take advantage of the future of Windows," Reller said. "It is the first place to dive deep into the future of Windows."

Windows 8 will feature a start screen composed of applications represented in "tiles," which Microsoft believes are more useful than Apple's iPad icons because they are capable of providing details such as the current weather or state of an application. The traditional interface of Windows XP and Windows 7 will also be there for desktop-oriented applications.

Monday, July 11, 2011

How to survive a cloud outage

You can't prevent your cloud service provider from going down, but there are ways to protect yourself

For example, Web-based disk encryption vendor AlertBoot, headquartered in Las Vegas, used to pay $50,000 a month just for electricity, AlertBoot CEO Tim Maliyil says.



Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com


"We had two physical data centers at one point -- and you can't believe how happy we were to shut it down," he says. "Now, two clouds, bandwidth and hosting is $16,000 a month. There was so much waste of electricity and capacity. The cloud really minimized our costs and ongoing expenses."

Transitioning to cloud providers wasn't difficult, because AlertBoot was already using virtualization software from VMware in its traditional data center, he says. The two cloud providers the company picked are SunGard and OpSource, both of which use VMware technology as well. (Systems integrator Dimension Data announced recently that it plans to acquire OpSource.)

Switching from one cloud provider to another now takes just a minute or two, he says, and the backup cloud can ramp up quickly to handle increased load. The switch-over itself is handled by a service from Zeus Technology, a U.K. vendor that helps companies move applications from one cloud to another.

Maliyil said that his company selected these vendors because they are known for their enterprise-level reliability. "For the kind of business we're in, and our customers' [lack of] tolerance for failure, we've steered away from the Amazon infrastructure," he says.

Another vendor that helps companies manage services running on multiple clouds is rPath, which has more than 90 corporate customers, mostly large enterprises and ISPs, including ADM, Fujitsu, Qualcomm and EMC.

The company currently deploys to 16 types of image formats, which are snapshots of applications that run in cloud environments. Adding another cloud to the list typically takes less than a week, says Jake Sorofman, rPath's chief marketing officer. "It's fairly trivial for us."

The company currently supports Amazon EC2, VMware, Citrix Zen, Microsoft HyperV, Rackspace and several other formats. Once an application is in the rPath system, it takes as little as 15 minutes to generate a new image and deploy it to a new cloud, he says.

However, architecting an application for the rPath system in the first place can take a little longer. "The process of packaging a new application for our platform could take from a couple of hours to a couple of days, depending on its complexity," he says. "But we have a professional services team that does that work for customers if they choose."

Many applications are already packaged up, he says, including the full range of Windows and Linux operating systems, WebLogic and WebSphere, SAP, EMC and RSA products.

"There's a fairly extensive list of complete stacks that have already been modeled using our technology, and can be leveraged," he says.

And having the option to move applications between clouds does more than just provide backup options for companies, he says - it also allows companies to get the best possible deals from their providers.

"There is an arbitrage opportunity that comes with having choice," he says. "Being able to optimize where workloads are running based on performance, policy and price. And, to the extent that you can easily move a workload between Amazon, Rackspace or other environments, you have leverage over your service providers because you have eliminated lock-in."

Saturday, July 9, 2011

When Tech Helps Keep Money Clean

In this context, Synlog, a Globsyn company providing IT solutions to the banking and financial services domain, has launched RAFTS (Real-time AML Filter for Turbo Swift) software that tracks transactions on a real-time basis. While RAFTS has already been well received in the international market—where it is represented by Synlog’s business partner, BankServ Inc (USA)—it has only recently been customised for the Indian market by Synlog’s development centres in Kolkata and Chennai.


Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com

Seernani explains how RAFTS works: “Banks that are authorised to deal in foreign exchange (forex) do so electronically over the international SWIFT network. A connection to the SWIFT network is available through what is called SNL (SWIFT-NetLink), which is a combination of hardware and software. However, in order for the bank to be able to create messages (i.e., transfer requests) to be sent over the SWIFT network using the SNL, the bank needs message management software. The TurboSWIFT suite from BankServ is a popular message management software that has three essential components. TurboSWIFT is the main server that caters to all the users in a bank; TurboConnect is the client software that bank users have installed on their machines to log onto the server to perform their tasks (message creation, verification, authorisation, or system management); and TurboWEB is an Internet browser based front-end for TurboSWIFT that enables users across multiple bank branches to access the TurboSWIFT server (over a wide area network).”

RAFTS functions as an add-on ‘plug and play’ solution to the main TurboSWIFT interface. As an overlay, RAFTS monitors every incoming and outgoing forex transaction occurring over the SWIFT network. To do so, RAFTS uses the Bridgers List of words/patterns. The Bridgers List, issued and regularly updated by organisations in Australia, Canada, Europe, the UK, the US, the United Nations, and the World Bank, is a comprehensive listing of names and keywords that could spell trouble. For instance, it would contain words like Osama Bin Laden, Dawood Ibrahim, Al Qaeda, etc.

Dual protection: manual plus automatic screening

When RAFTS encounters any of these words in a message, it moves the message to a separate folder of suspect transactions, in queue for manual authorisation. This queue appears on the computer terminal of the AML officer of the bank, who may then allow the transaction to go ahead, or reject it and send it back to its creator.

Using RAFTS, an officer may also append patterns to the black-lists (the existence of this pattern means the transaction is to be stopped) and white-lists (the existence of this pattern indicates the transaction is to be allowed). Further, the officer may set the priority in which messages (such as letters of credit, advice of cheque, bank guarantee, etc) of various kinds are to be scanned, as well as define the message types to be scanned or passed without scanning. Essentially, while RAFTS enables a bank to adhere to the first cardinal rule to prevent money laundering—know your customer—it also necessitates a bank’s strict compliance with the second cardinal rule - know your employee—in appointing a completely trustworthy AML officer. And that, in turn, will go a long way in ensuring that funds are not misused, resulting in a safer world in the long run.

Thursday, July 7, 2011

Let's face it: HTML5 is no app dev panacea

Don't believe the hype: building serious applications still takes more than mere Web markup

2. HTML wasn't designed for applications
The buzz on HTML5 is that it's HTML souped up with improvements to support Web applications. But better app support wasn't always the direction of the HTML standard. Originally, the successor to XHTML 1.1 was going to be XHTML2, which would have emphasized semantic markup and integration with XML. True to its roots, XHTML2 was a document-centric markup language.







Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com




The XHTML2 effort foundered, however, and a splinter group called the Web Hypertext Application Technology Working Group (WHATWG) broke off from the W3C's HTML activity to begin work on a different draft of the standard, one that emphasized elements useful for Web applications. It was this work that eventually became the basis of what we now know as HTML5.

But was HTML5 really the best direction to go? HTML5's ballyhooed tag, for example, essentially means "insert a bunch of programmatically generated graphical content that can't be described by markup." That's a pretty strange use of a markup language. If we keep going down this road, are we not perhaps shoehorning Web standards into a role for which they were never really suited? It may be a necessity for the Web, but do we really want to put ourselves in the same bind everywhere else?

3. HTML sucks for building UIs
One of Apple's big innovations with the original Mac was publishing a detailed set of Human Interface Guidelines for developers. As a result, unlike DOS programs, Mac apps looked alike and behaved alike. They all used the same kind of menus, the same dialog boxes, and the same alerts. The resulting impression of coherence and consistency was a big reason why the Mac OS was so wildly successful, even when GUI desktops were still new and unfamiliar.

With Web apps, we're back to the DOS days. Interface designers are free to create any kind of buttons they want, have menus that slide down or pop up from anywhere, and generally paint the entire window any way they see fit. Without a standard set of widgets, apps built with Web technologies feel inconsistent and sometimes downright alien. Even if you go out of your way to build a UI that looks dead-on like a native iPhone app, the same UI won't fit in on an Android phone. Who's going to take the time to build Web-based apps that feel "native" on every platform? Nobody, that's who. (Let's not get started on the screen-size issue.)

Tuesday, July 5, 2011

Sorry, but the TDL botnet is not 'indestructible'

Malware and alarmism over its proliferation are nothing new -- and the latest boot-sector rootkit will be cured soon enough

The sophistication of the TDL rootkit and the global expanse of its botnet have many observers worried about the antimalware industry's ability to respond. Clearly, the TDL malware family is designed to be difficult to detect and remove. Several respected security researchers have gone so far as to say that the TDL botnet, composed of millions of TDL-infected PCs, is "practically indestructible."




Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com



As a 24-year veteran of the malware wars, I can safely tell you that no threat has appeared that the antimalware industry and OS vendors did not successfully respond to. It may take months or years to kill off something, but eventually the good guys get it right.

This isn't the first time we're supposed to be scared of MBR (master boot record)-infecting malware. In 1987, well before the days of the Internet, the Stoned boot virus infected millions of PCs around the world. Subsequent "improvements" in hacking allowed malware authors to create DOS viruses that could manipulate the operating system to hide themselves from prying eyes. (Actually, the first IBM PC virus, Pakistani Brain did this in 1986, too.) Computer viruses became encrypted and polymorphic, and they started taking data hostage.

With each ratcheting iteration of new malware offense, you had analysts and doomsayers predicting this or that particular malware program would be difficult to impossible to defend against. But each time the antimalware industry and other software vendors responded to defang the latest threat. Yesterday's indestructible virus became tomorrow's historical footnote.

Even today's malware masterpiece, Stuxnet -- as perfect as it is for its intended military job -- could be neutralized if it became superpopular. Luckily, military-grade worms are few and far between, so most users don't have to suffer while waiting for defenses to be developed.

The truth is, like every other malware family variant, TDL and its botnet will probably be around for years to exploit millions of additional PCs. But it didn't take an advanced superbot to do that. Take a look at any monthly WildList tally. It always contains malware programs written years ago.

Today, almost every malware program lives in perpetuity, dying off only when the exploited program or process dies with it. Boot viruses from the 1980s and 1990s didn't stop being a threat until floppy disks and disk drives went away. Macro viruses didn't die until people stopped writing macros and Microsoft Office disabled automacros by default.

No, what really bothers me more are the malware programs that do something completely new because it takes so much longer for antimalware programs, software vendors, and users to adapt to the tactic. For instance, it took us years to teach folks not to open every file attachment to defeat email viruses and worms -- but it takes the bad guys only a few minutes to change strategies. Today, we need to tell folks not to click on the Internet link emailed to them by a trusted friend and not to install random applications sent to them in Facebook or through their mobile phone.

But our biggest threat is an MBR PC-infector? Been there, done that.

Monday, July 4, 2011

The 10 worst cloud outages (and what we can learn from them)

Sending your IT business to the cloud comes with risk, as those affected by these 10 colossal cloud outages can attest

Think you have to be a Netflix-size business to stay safe? Think again. Twilio, a company that helps developers integrate communications into their Web apps, uses Amazon's EC2 to host the core of its infrastructure -- yet April's outage had little to no impact on its stability.


Best Microsoft MCTS Training, Microsoft MCITP Training at certkingdom.com


"The fundamental premise of building on the cloud is assuming that the network will have glitches," says Evan Cooke, Twilio's co-founder and chief technology officer. "We built an infrastructure around the idea that a host can and will fail, so we don't rely on any single machine or single component in the core architecture itself."

Colossal cloud outage No. 2: The Sidekick shutdown. Smartphones make it easy to access your data on the go, but just because something has "smart" in its name doesn't mean it can't be dumb. Case in point: the T-Mobile Sidekick screwup, circa fall 2009.

Remember this fiasco? The Microsoft-owned Sidekick suffered a nearly week-long service outage that left users without access to email, calendar info, and other personal data. Then, adding insult to injury, Microsoft confessed it had completely lost the cloud-stored bits and wouldn't be able to restore them. Evidently, the good ol' gang from Redmond had forgotten to make backups.

The technology may have evolved since then, but the lesson remains the same: When it comes to crucial data, never assume someone else is automatically protecting you. Make sure you understand your cloud provider's disaster recovery setup -- better yet, make your own arrangements to back up your important data independently.

"The same operational rules apply even in the cloud," says Ken Godskind, vice president of monitoring products for AlertSite, a SmartBear company. "Organizations using the cloud can't just assume that because it's in the cloud, all the responsibility for business continuity planning has somehow been transferred to the provider."

Colossal cloud outage No. 3: Gmail fail. Of all cloud services, Google's Gmail presents one of the more likely threats to Microsoft's on-premises stranglehold on the enterprise. Replace your high-maintenance Exchange servers with a cheap, dependable email service backed by Postini. What's not to like?

A rash of irksome outages, the most recent of which had 150,000 Gmail users signing into their accounts only to find blank slates -- no emails, no folders, nothing that indicated they were actually looking at their own inboxes. To Google's credit, it provided regular updates and promised a quick fix. But repairs took as long as four days for some of the affected users.

"How could this happen if we have multiple copies of your data, in multiple data centers?" Google vice president of engineering Ben Treynor asked in a blog posted at the time. "In some rare instances, software bugs can affect several copies of the data. That's what happened here."

Google ended up having to turn to actual physical tape backups in order to restore the data. Ultimately, the company's multilayered data protection did work, but not without leaving thousands of users locked out of their email for days.