基于Exchange 2003 和 Windows Mobile 企业移动消息最佳实战

Slides:



Advertisements
Similar presentations
Web Role 的每台虚机运行有 IIS ,用于处理 Web 请求 Worker Role 用于运行后台进程 Cloud Service 是什么? 支持多层架构的应用容器 由多个 Windows 虚拟机集群构成 集群有两种类型: Web 和 Worker Cloud Service 做什么 进行应用的自动化部署.
Advertisements

应用技术 陕西华辉科技有限公司.
泛舆情管理平台 ——助力媒体业务创新 新模式 新格局 创新盈利增长点 2/26/2017 1:59 AM 屈伟: 创始人,总裁
中国银行业前置端操作系统移植研究.
3/3/ :01 PM © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
NAP – 高可靠性,高安全性兼备的新一代网络安全接入解决方案
请点击以下链接下载WinHEC的演讲材料
借助公有云实现游戏的弹性运营 Shaun Fang (方兴) Azure开发技术顾问
吴峻 软件设计工程师组长 Exchange Server 微软有限公司
请点击以下链接下载WinHEC的演讲材料
1. 设定愿景,确定业务场景 Microsoft Corporation
广东省广州市花都区教育局教研室 汤少冰 优化评估方式, 促进中学英语的教与学 广东省广州市花都区教育局教研室 汤少冰
張書源 Microsoft MVP MCT 趨勢科技 技術經理 網酷科技 資深顧問 集英信誠 資深顧問
企業如何建置安全的作業系統 Windows XP 網路安全
Office 2013 全新功能介紹 台灣微軟 Office 大使 楊承恩 Marcus Microsoft Office
講師姓名:黃信嘉、黃振宇 職稱:微軟技術支援副理 公司名稱:台灣微軟 課程代碼:WCL305
四川省集体林权流转平台 中国西部林权交易网
全国信息技术标准化技术委员会 (SAC/TC28)工作交流
Windows 10 混合现实 Mingfei Yan 高级项目经理
Exchange 2013搶先預覽: 新功能快速導覽與解析
WCL304 體驗全新桌面虛擬化App-V 5.0 & UE-V 佐藤大輔 Daisuke Sato.
W371 如何使网络设备更好的和Windows Vista工作
MBL 340 Tablet PC SDK:在您的应用程序中使用数字墨水
資料檔案的安全性管理 羅英嘉 2007年4月.
今天很高兴能够利用Web Cast和大家讲解嵌入式XP的新增功能。
什麼是電子軟體下載 Electronic Software Download (ESD).
OFC 302 InfoPath2007新特性及解决方案.
最新 Windows Server 徽标 要求和计划
Windows Mobile 轻松接轨GPS
Microsoft Office SharePoint Server 2007 事件追蹤與專案管理
SOLUTIONACCELERATORS Windows Vista Hardware Assessment 1
MSG 321 统一消息架构和PBX集成.
朝雲端專業DBA邁進: 深入剖析 Windows Azure SQL Database 完整資料庫管理、雲端報表建立、建置分散式雲端資料庫
利用最新Hyper-V Replica 功能達成Hyper-V 災難備援機制
Windows Server 2008 NAP整合802.1x網路安全控管
Exchange Server 2007 用戶端存取 謝合宜 微軟特約技術顧問
互聯網安全資訊 助您達至更安全的網上體驗.
服務啟用、導入流程、 郵件移轉步驟簡介 Microsoft Office 12/2/2018
MBL 325 开发跨平台的 Windows Mobile应用程序
MBL 327 Windows Mobile开发中的异构系统集成
David Edfeldt Senior Program Manager Windows Logo Program
构建 Windows TV Tuner 产业 生态环境的重要观点
微软新一代云计算 面向企业的 Office 365 客户培训大纲
使徒行傳 21:17-23章「保羅的見證(一)」 引言 預言保羅為主的名受許多的苦難的實現
2/24/2019 5:40 AM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Exchange 2007 系統部署 -- 儲存預測與測試
教师课堂教学能力提升培训 ---“互联网+教育”考勤小测验 Plickers 洛阳理工学院
Microsoft SQL Server 2008 報表服務_設計
利用 ASP.NET MVC 提升您的 Web 應用程式


橫跨電腦、手機與軟體的全方位端點管控解決方案
请点击以下链接下载WinHEC的演讲材料
CON223 UDDI:服务的发现和搜索.
呂政周 精誠恆逸教育訓練處 資深講師 Windows PowerShell 呂政周 精誠恆逸教育訓練處 資深講師
使用WPF创建Windows应用和Web应用
4/30/2019 7:40 AM 約翰福音 15:9;17:20-23 加拉太書 6:1-2 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product.
DEV 343 VS2005超快速开发方案/EEP2006控件包.
5/4/2019 4:42 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
使徒行傳 24-26章 [ 保羅的見證(二)] 徒9:15 “  主 對 亞 拿 尼 亞 說 、 你 只 管 去 . 他 是 我 所 揀 選 的 器 皿 、 要 在 外 邦 人 和 君 王 並 以 色 列 人 面 前 、 宣 揚 我 的 名 。 ”]
TechEd /6/ :36 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Windows 徽标计划工具:综述与发展趋势
5/5/2019 7:06 PM 两跨框架梁截面配筋图的绘制 © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may.
顧武雄 台灣微軟特約資深講師 Exchange 2007 管理工具活用秘訣 Entry Slide
百万亿次超级计算机诞生记 姓名 Xiangyu Ye 职务 微软中国技术中心资深HPC顾问 公司 微软中国
5/15/2019 姓名: 公司名称: 云赛空间BP模板 Now let’s take a look at who we are, what we’re doing and why we’re doing it in China... This is an image of a technology.
DEV 343 VS2005超快速开发方案/EEP2006控件包.
MGT 213 System Management Server的昨天,今天和明天
Bob Combs Lead Program Manager Microsoft Corporation
Windows Workflow Foundation CON 230
Presentation transcript:

基于Exchange 2003 和 Windows Mobile 企业移动消息最佳实战 07/11/2018 MBL220 基于Exchange 2003 和 Windows Mobile 企业移动消息最佳实战 辛浩 资深IT服务顾问 大家好,我是辛浩;很荣幸能借助teched 2006 这次机会跟大家分享本次讲座; 先允许我做一下自我介绍,我现在是一名IT服务顾问, 我有8年的IT服务经验和多年的培训经验,专注于企业基于windows 产品的IT服务解决方案;同时我也是一名webcast 讲师,一直和微软合作在Mobile的ITpro方面作一些培训; 今天我将用50分钟的时间跟大家分享的一个主题:基于Exchange 2003 和 Windows Mobile 企业移动消息最佳实战; 主要是面对IT pro 和企业信息管理者,如何通过Exchange Sp2 结合 Mobile 5.0 实现企业移动消息服务的战略; --〉翻页 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

议程 Exchange 2003 SP2 企业移动消息应用 Windows Mobile 5 with MSFP 07/11/2018 议程 企业移动消息应用 Exchange 2003 SP2 Windows Mobile 5 with MSFP 企业Exchange 消息服务实践 移动消息安全、管理、扩展 这次培训的议程为: 首先介绍一下企业移动消息应用的趋势和挑战; 然后介绍 Exchange 2003 sp2 的移动消息模块 然后 介绍 基于Windows Mobile 5 with MSFP的客户端应用 最后是跟大家分享一下企业Exchange 消息服务实践 如果有时间,我们做一下FAQ, OK, 让我们开始我们今天的课程…. © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

企业移动消息应用 丰富的实现多目的设备终端 无处不在的低成本的无线网络 逐渐增强的安全管理基础架构 日渐成熟的企业移动消息应用 07/11/2018 企业移动消息应用 丰富的实现多目的设备终端 无处不在的低成本的无线网络 逐渐增强的安全管理基础架构 日渐成熟的企业移动消息应用 Exchange Server 2003 / Windows Mobile 5 LCS 2005 /Mobile Office Communicator CRM 2.0 /Mobile CRM Mobile OA Mobile ERP … 当前的企业移动消息应用日渐成熟,是由以下一些因素所导致的,也可以说是水到渠成; 首先是市场上有非常丰富移动设备终端—手机,而且大家都可以发现,他们的趋势,是成为多用途目的的核心,电话,音乐,媒体,游戏,办公,所以市面上存在不同目标群的用户----商务,休闲,学生;Mzone, Up新势力… 另外 无处不在的低成本的无线网络已经成为现实,半年前我还为高额的GPRS 数据流量所担心,现在。。。。 逐渐增强的安全管理基础架构 安全是永恒的话题,对企业更是至关重要的东西,。。。,当前对移动设备的安全管理也逐渐成为企业移动消息应用的重要环节,这一部分在 后面。。。。。 日渐成熟的企业移动消息应用, Exchange Server 2003 / Windows Mobile 5 LCS 2005 /Mobile Office Communicator CRM 2.0 /Mobile CRM Mobile OA Mobile ERP … 其实对我们大多数IT的人来说,Mobile 给我们提供一个新的平台,Dos时代的个人英雄又可以在Mobile平台展现,企业应用无疑是一个最适合各位 发展的方向,下面我们从不同角度来分析 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

企业移动消息应用的挑战 总拥有成本 连接性 安全性 管理性 扩展性 Scalability Device and Network 07/11/2018 企业移动消息应用的挑战 总拥有成本 连接性 Scalability 安全性 Device and Network 管理性 Provisioning and Support 扩展性 Leveraging infrastructure Focus: Microsoft Exchange Server 2003 Service Pack 2 Microsoft Windows Mobile 5 Messaging and Security Feature Pack Architecture Best Practices TCO 是CIO 首要考虑的内容,在企业带来好处的时候,他的cost 到底有多少。。。 连接性是一个广泛的问题,对移动消息来说 延展性(Scalability), ---扩展性 (Scalability)       可伸缩性移动功能性来自路由器,而非各IP设备。无需再做任何额外的工作,成百或成千上万部设备就可加入到网络中。 安全性---从企业安全的角度; 管理性---设备管理和应用管理 扩展性--- © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

企业移动消息应用的起点:E-Mail E-Mail 已经是企业的核心应用 已经存在多种成熟设备和解决方案 07/11/2018 企业移动消息应用的起点:E-Mail E-Mail 已经是企业的核心应用 已经存在多种成熟设备和解决方案 Exchange Server 2003 是第一个集成的解决方案 结合ISA可以提供更高的可用性和管理性 结合IT策略可以实现更高的安全性  除了微软和RIM,目前市场上至少还有四家公司提供各自的手机push email系统,它们分别是:Good Technology,Nokia,Seven以及Visto。另外,DataViz在他的RoadSync产品中支持微软的服务,该产品可以工作在 Symbian和Palm平台上。在手机移动电子邮件市场,也出现了一些企业间的合并案例,比如Seven在收购了Commtag后,又收购了 Smartner。 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

07/11/2018 Exchange 2003 SP2 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange Server 2003 Service Pack 2 07/11/2018 Exchange Server 2003 Service Pack 2 更高的安全性 Certificate based authentication Local and Remote Wipe capability Central control of device policy 直推技术 很多的新特色 Directory search Pictures in Contacts GZip © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange Server 2003 移动访问服务 07/11/2018 Exchange Server 2003 移动访问服务 Windows CE based devices Pocket PC, Pocket PC Phone Edition, Smartphone 2002 Windows MobileTm 2003 (AUTD support) Windows Mobile 5 (AUTD & DP support) Outlook Mobile Access (real-time) Microsoft ActiveSync (synchronization) RPC/HTTP or OWA Exchange 2003 Mobile Services SP2 Laptop Cellular Phone Pocket PC SmartPhone 9 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

基于Windows Mobile 的OWA 访问 07/11/2018 基于Windows Mobile 的OWA 访问 小屏幕浏览 Pocket Internet Explorer (single windows) 支持 OWA Limited frame 10 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

基于Windows Mobile 的OMA 访问 07/11/2018 基于Windows Mobile 的OMA 访问 Based on WAP/WML Legacy Mobile Phones 11 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

07/11/2018 ActiveSync 访问机制 AirSync HTTP (basic authentication) [SSL] (preferred) IIS MASSYNC.DLL ISAPI DAVEX.DLL ISAPI Front End Server Back End Server DS_ACCESS Active Directory Read User Properties & obtain Kerberos TGT WebDAV HTTP (Integrated authentication) Clear Exchange disables certain services on FE servers. The idea is that FE servers should only be used to proxy client requests to BE servers (and possibly relay SMTP traffic). Since they sit in a DMZ, FE servers should not perform other tasks. The services which are disabled are: DSProxy Offline Address List Generation Recipient Update Service Mailbox Cleanup Agent Therefore before converting a server to a FE (or before applying SP2 to a FE) you should move the Offline Address List Generation and the Recipient Update Service to other servers. Also, any system folders, such as Free and Busy, Offline Address Book and Organisational forms should also be moved to a different server. Remember, that Public Stores should not exist on a FE server. Back End Server Files On a BE server IIS redirects requests to the following DLL files: DAVEX.dll – This is for OWA requests. POP3BE.dll – This is for POP3 requests. IMAP4BE.dll – This is for IMAP4 requests. Front End Server Files When a server is converted to a FE all that happens is the FE DLLs are activated and the BE DLLs are unused. The FE DLLs are: EXPROX.dll – For OWA requests. POP3FE.dll – For POP3 requests. IMAP4BE.dll – For IMAP4 requests. 12 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange Server ActiveSync 的应用 07/11/2018 Exchange Server ActiveSync 的应用 13 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

07/11/2018 Mobile 5.0 with MSFP © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

在线联系人查找(GAL) 需要 Windows Mobile 5 +MSFP 集成的应用 导入 GAL 记录 到本地联系人列表 07/11/2018 在线联系人查找(GAL) Service Pack 2 需要 Windows Mobile 5 +MSFP 集成的应用 导入 GAL 记录 到本地联系人列表 Windows Mobile 5 15 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange直推技术 真正的AUTD解决方案(always-up-to-date ) 实现条件 不需要 SMS通知 07/11/2018 Exchange直推技术 真正的AUTD解决方案(always-up-to-date ) 不需要 SMS通知 支持所有的 PIM 数据: Inbox, Calendar, Contacts and Tasks 不增加额外的数据流量 伸缩性:全球范围 不需要额外的软件及服务器安装 实现条件 服务器配置激活—缺省配置 支持 “SP2-ready” 的设备 该方案依赖于实时连接 需要调整防火墙的连接超时时间为: 15-30mins How it works Uses IP Push and no longer uses SMS notifications Device initiates an always-on IP (https) connection to Exchange Server and keeps IP connection alive and healthy using a “heartbeat” © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

直推技术(Direct Push) Direct Push Mail 技术原理 (心跳时间为 15min) 07/11/2018 直推技术(Direct Push) Direct Push Mail 技术原理 (心跳时间为 15min) Device : 如果我在15分钟内有邮件请告诉我,否则告诉我“没有邮件”. Time = 0 min Server: “没有邮件” Time = 15 min Device : 如果我在15分钟内有邮件请告诉我,否则告诉我“没有邮件”. Time = 15 min Server: “你有新邮件” Time = 23 min Point to make here is about customer firewall and IIS timeouts and the open HTTP request. The WM client sends a request to be honored by the Exchange Server of 15 minutes, by default. The firewall and IIS timeout should be set to at least 15 minutes for this to work properly. Example, MSIT has slowly fine tuned to the point where they are at 30 minutes, today – with 2 front end servers handling all traffic for RPC/HTTP, OWA, IMAP, POP and Sync. Anywhere from 10000-18000 unique sync users on thoise two servers. Not all running the new IP notification. Additional data will be available later on this metric. Heartbeat: Device sends ping to server to generate IP connection Some bandwidth overhead incurred in keeping IP connection to Exchange alive “always on“ Assuming heartbeat every 15min, incremental overhead required to keep IP connection “alive“: 370 Bytes/heartbeat x 4 heartbeats/hour x 24h x 30days = 1,06MB (No consideration to block rounding) Windows Mobile Device with MSFP Device : 给我邮件 Time = 23 min Server running Exchange 2003 SP2 Heartbeat: 370 Bytes/heartbeat x 4 heartbeats/hour x 24h x 30days = 1,06MB (No consideration to block rounding) © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange Server 2003 SP2 配置 07/11/2018 18 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

07/11/2018 企业Exchange 消息服务 实践 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

架构总揽 防火墙 支持反向代理(Publish) 前端服务器 后端服务器 一个或多个 至少支持端口过滤 可以是 企业版或标准版 07/11/2018 架构总揽 防火墙 一个或多个 至少支持端口过滤 支持反向代理(Publish) 前端服务器 可以是 企业版或标准版 Pub/private Store can be removed 可以部署在: Internet, DMZ, inside corporate firewall 后端服务器 Inside corporate firewall Stores mailboxes and public folders © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

FE/BE Deployment Scenarios Single firewall (简单) 07/11/2018 FE/BE Deployment Scenarios Single firewall (简单) Firewall Ports 443, 993, 995 Exchange Server 2003 Front-End Servers Exchange 2003 Server Active Directory Global Catalog Server Internet © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

FE/BE Deployment Scenarios DMZ/Perimeter network (安全) 07/11/2018 FE/BE Deployment Scenarios DMZ/Perimeter network (安全) Firewall Ports 443, 993, 995 Exchange Front-End Servers Exchange 2003 Servers Active Directory Global Catalog Server Firewall Ports, 80 143, 110, LDAP, etc DMZ Internet © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

ISA Reverse Proxy DMZ/Perimeter network (推荐) 07/11/2018 ISA Reverse Proxy DMZ/Perimeter network (推荐) AD/GC Exchange 2003 Server Internet Exchange 2003 Server Firewall Port 443 ISA Firewall Ports 443 or 80 Exchange FE Exchange 2003 Server © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

移动消息安全 07/11/2018 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

air transmissions PAN LAN 07/11/2018 Mobile 的安全访问 management 1 4 VPN 2 3 devices air transmissions PAN LAN WAN public networks private networks applications mobility wireless traditional security © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Mobile 的安全威胁 Stolen information 07/11/2018 Mobile 的安全威胁 Stolen information Host intrusion, stolen device Unauthorized network/application access Compromised credentials, host intrusion Virus propagation Virus susceptibility Lost information Lost, stolen or damaged device Mabir Windows CE DUTS Windows CE BRADOR 29Dec04 1Feb05 Locknut (Gavno) Vlasco 21Nov04 Skulls 20June04 Cabir 17Jul04 5Aug04 8Mar05 Comwar 7Mar05 Dampig 12Aug04 Qdial 4Apr05 Fontal 6Apr05 Drever 18Mar05 Hobbes 15Apr05 Doomed 4Jul05 = Symbian OS (Nokia, etc) = Windows CE (HP, etc) Source: Trend Micro © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Mobile 的内容安全 (访问安全) 简单锁定 加密 防止不安全重启动 Private key storage? 07/11/2018 Mobile 的内容安全 (访问安全) 简单锁定 加密 Private key storage? Smartcard/TPM Hash private key (dictionary attack) Couple with strong password policies 防止不安全重启动 Analogous to BIOS password and Drivelock © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

身份认证 Username/Password Client Certificate One-time Password 07/11/2018 身份认证 Username/Password Encrypted on device Client Certificate Prevents ISA from SSL-bridging Non-trivial enrollment One-time Password © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

安全连接 Infrastructure similar to OWA (HTTP) 07/11/2018 安全连接 Infrastructure similar to OWA (HTTP) SSL certificate-checking by the access device 1. HTTPS connection ActiveSync Client 2. IIS presents the vitual Server SSL Certificate Validation of Root CA Root CA Root CA Issued by Certificate for Visual Server Root CA of the SSL Certificate Must be installed on the Windows Mobile TM client “Known” Certificate authorities: Thawte (server and Premium server Secure Server GTE Cybertrust Globalsign Entrust.net Class 2 and 3 Public Primary Certificates 29 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

强制安全策略 目标: 确保移动设备启用了安全策略 内容: PIN code strength Remote Wipe 2018/11/7 07/11/2018 强制安全策略 目标: 确保移动设备启用了安全策略 内容: PIN code strength Remote Wipe Specific web UI Device Locking 30 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Exchange Servers的安全 前后端直接不启用SSL IIS Trusted physical/switched network 07/11/2018 Exchange Servers的安全 前后端直接不启用SSL Trusted physical/switched network IPsec everything or specific ports such as 80 IIS Enable IIS logging Disable non-essential script mappings Always keep up to date on available fixes Standard hardening procedures © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

使用IPsec IPsec 用于加密 Exchange 前后端的传输 IPsec 策略 使用 GPO 推 IPsec policies 07/11/2018 使用IPsec IPsec 用于加密 Exchange 前后端的传输 IPsec 策略 Exchange front end: meany; TCP any80; Encrypt Exchange back end: Respond only 使用 GPO 推 IPsec policies Exchange 2003 前后端使用Kerberos authentication User credentials are encrypted by default Not guaranteed, Kerberos can fail due to clock skew, etc. © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

推荐配置 不要end-to-end 直接连接 使用SSl桥接(ISA) 在前端进行认证 07/11/2018 推荐配置 不要end-to-end 直接连接 使用SSl桥接(ISA) 在前端进行认证 前后端之间使用IPSec ISA and FE需要配置证书 有exchang 12 的资料也来些,学习学习 hotxin@马上快听Mao MianQiang的webcast ing 说: i see; Nancy Yang - ICE AGE II 说: 主要就是这些 https://www.microsoft.com/exchange/preview/default.mspx 这个你看过吗 http://msexchangeteam.com/archive/category/10058.aspx 还没 team blog推荐 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

移动消息管理 07/11/2018 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

使用移动设备管理MDM (Mobile Device Management) 07/11/2018 使用移动设备管理MDM (Mobile Device Management) 降低TCO, 特别是技术支持消耗 Central console, reporting 更可靠的平台部署商务营运应用程序 (line-of-business ) 更容易使用和被用户接受 安全: 可保障的配置的完整性 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

不同的MDM 产品 基于桌面管理的 整体解决方案的 MDM 标准的 Altiris Microsoft SMS Good 07/11/2018 不同的MDM 产品 基于桌面管理的 Altiris Microsoft SMS 整体解决方案的 Good Intellisync* OneBridge MDM 标准的 iAnywhere Afaria mFormation* © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

MDM 成熟等级 Infancy Adolescence Mature 资产管理 基础软件更新 软件更新 配置管理 设备强制安全 07/11/2018 MDM 成熟等级 Infancy 资产管理 基础软件更新 Adolescence 软件更新 配置管理 设备强制安全 Mature 数据发布和同步 多平台支持 基于策略的软件分发 空中下载启动和维护 (OTA) 扩展的桌面管理 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

企业MDM 需求 Integrated Management Console Centralized Policies 07/11/2018 企业MDM 需求 Integrated Management Console Directory (AD/LDAP) integration Centralized Policies Policy polling User cannot remove Screen-lock/Idle-lock © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

移动消息服务扩展 07/11/2018 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Mobility 的扩展体系架构 Access Layer Distribution Layer Content Layer 07/11/2018 Access Layer Distribution Layer Content Layer Presentation rendering synchronization local processing Device services rendering synchronization content- aggregation personalization location OLTP/OLAP databases CRM ERP Connectivity services roaming compression optimization VPN Business process automation Connectivity Roaming VPN e-mail rich media Internet/ intranet Management and Security Infrastructure provisioning, user support, load balancing identity management, authorization © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Microsoft的 Mobility 扩展体系架构 07/11/2018 Access Layer Distribution Layer Content Layer Presentation .NET CF SQL CE Media Player Device services ASP.NET Mobile Controls Microsoft SQL CRM ERP Connectivity services Server- ActiveSync ISA Server Exchange FE BizTalk Connectivity ActiveSync Exchange Windows Media IIS Management and Security Infrastructure Active Directory, SMS, MSFP © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

更多资源 SP2 / Windows Mobile Deployment Guide 2018年11月7日1时21分 07/11/2018 更多资源 SP2 / Windows Mobile Deployment Guide http://www.microsoft.com/technet/itsolutions/mobile/deploy/msfpdepguide.mspx Exchange Team Blog - Mobility http://msexchangeteam.com/archive/category/3827.aspx Windows Mobile for Business Web Site http://www.microsoft.com/windowsmobile/5/Business/default.mspx Microsoft IT Case Study http://msexchangeteam.com/archive/2006/06/09/427913.aspx 42 © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

更多资源 Technical Chats and Webcasts Microsoft Learning and Certification 07/11/2018 Technical Chats and Webcasts http://www.microsoft.com/communities/chats/default.mspx http://www.microsoft.com/usa/webcasts/default.asp Microsoft Learning and Certification http://www.microsoft.com/learning/default.mspx MSDN & TechNet http://microsoft.com/msdn http://microsoft.com/technet Virtual Labs http://www.microsoft.com/technet/traincert/virtuallab/rms.mspx Newsgroups http://communities2.microsoft.com/ communities/newsgroups/en-us/default.aspx Technical Community Sites http://www.microsoft.com/communities/default.mspx User Groups http://www.microsoft.com/communities/usergroups/default.mspx © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

请填写反馈表 07/11/2018 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

07/11/2018 © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.