Präsentation "Arbeiten Sie wo Sie wollen – Ihre Daten bleiben zentral und sicher verwahrt" von Rolf Kersten.
Diese Session gibt einen Überblick über Amazon WorkSpaces, den WorkSpaces Application Manager und Desktop Application Marketplace und zeigt Anwendungs-Szenarien sowie Kundenbeispiele unterschiedlicher Größe, von einer Handvoll WorkSpaces bis zu großen Installationen mit mehreren tausend WorkSpaces und weltweit verteiltem Zugriff.
Deploying and Scaling Your First Cloud Application with Amazon Lightsail
Arbeiten Sie wo Sie wollen – Ihre Daten bleiben zentral und sicher verwahrt
1. Arbeiten von wo Sie wollen
Ihre Daten bleiben zentral und sicher verwahrt
Rolf Kersten, EMEA Platform Business Development
15. November 2016
2. Sie haben den Schlüssel zu Ihrer Arbeitsumgebung
immer dabei
Ihre gewohnte
Windows
Umgebung
Immer maximale
Performance
Im Zugriff von jedem
beliebigen
Endgerät
3. Ihre IT Abteilung freut sich ebenfalls
Herausforderungen
der
Alternativen
Ein PC oder Laptop
Bestand verwalten
Gegen Datendiebstahl absichern
Datensicherung
Skalierung herausfordernd
Lokal gehostete VDI Umgebung
Hardware Investment
Skalierung und weltweite
Verteilung herausfordernd
Sicherer
Zugang mit
persönlichen
Geräten
Netzwerkzugang
für Saisonkräfte
Mobiles
Arbeiten: Wo
Netz ist, ist auch
sicherer Zugang
Daten sind
sicher und
ausschließlich
zentral
gespeichert
Neuen
Mitarbeitern
schnell
Zugang
einrichten
4. Sichere Desktopumgebungen aus der Cloud
Sicher
Abrechnung nach Verbrauch
Einfaches Management
Die Nutzer haben ihre gewohnte
Windows-Umgebung
Skaliert ohne
Performanceeinbußen
5. Grosse Auswahl an Zugangsgeräten
Desktop, Laptop: PC, Mac
Tablets: iOS, Android, Kindle, Surface
Zero Clients
Chromebooks
6. Passt zu vorhandenen Management-Tools
Microsoft Active
Directory
Multifactor
Authentication
(Radius)
SCCMIhr Intranet
Amazon WorkSpaces integriert sich transparent in Ihre vorhandene Umgebung
7. In der Cloud sind Ihre Daten sicher
• Alle Daten sind in der AWS Cloud gespeichert, in einer Region Ihrer Wahl (z.B.
Frankfurt), nicht auf den Endgeräten
• Daten werden auf dem Weg mit 256-bit verschlüsselt
• Gespeicherte Daten mit AWS Key Management Service verschlüsselt
• Benutzer authentifizieren sich gegen Ihr Corporate Directory
• Einsatz von Multi-Factor Authentication (MFA) unterstützt
• Certification – SOC 1, SOC 2, ISO 9001, 27001, 27017 und 27018
• AWS Data Processing Addendum enthält „Model Clauses” anerkannt von EU
Article 29 Working Party, EU Privacy Shield Compliance
Keine
sicherheits-
relevanten
Daten auf den
Endgeräten der
Benutzer
8. Reagieren Sie flexibel auf sich wandelnde
Anforderungen
• Neue WorkSpaces sind in Minuten bereit, Bestehende können zum
Monatsende deaktiviert werden
• Neue Mitarbeiter auf einem anderen Kontinent? WorkSpaces sind
weltweit verfügbar
• Mehr Rechenleistung oder Speicherplatz flexibel zuteilbar
• Einfaches Verteilen von Zugang zu neuen Anwendungen
• Kaufen Sie diese Anwendungen im AWS Desktop Marketplace (und
zahlen Sie nach Verbrauch), oder bringen Sie Ihre eigenen
Lizenzen mit
9. Keine Überraschungen beim Desktop Management
Verwalten Sie Ihre WorkSpaces mit Hilfe der AWS Console oder mit
Hilfe Ihrer gewohnten Tools:
• Integration in Ihr bestehendes Directory und Netzwerk
• Authentifizierung und Policies wie im Active Directory definiert
• Patching: WSUS, SCCM, 3rd-party
• Softwareverteilung: SCCM, App Layering, App Virt
• Profile Management: 3rd-party
• Automation: Powershell, .NET, und weitere
10. Amazon WorkSpaces Im Detail
• Für den Endanwender
Große Auswahl an Zugangsgeräten Tablets (iOS, Android, Fire),
Windows, MacOS, Zero Clients und Chromebooks
Lokal angeschlossene Drucker mit Windows und MacOS
High DPI Monitor Unterstützung
Audio (z.B. für Skype/WebEx Calls vom WorkSpace)
• Verwaltung
Benutzerdefinierte Images
WorkSpaces Application Manager (WAM)
API Support (via AWS SDK, CLI)
• Monitoring
Amazon CloudWatch und AWS CloudTrail Integration
Network Health Checks
11. NEU: WorkSpaces mit 3D Grafikkarte
• Für 3D Applikationen:
CAD/CAE, Simulation, Visualisierung,
Architektur
NVIDIA GPU mit 1,536 CUDA Cores und 4
GiB Speicher auf der Grafikkarte.
8 vCPUs
15 GiB Hauptspeicher
100 GB “C:” Laufwerk, 100 GB “D:”
Laufwerk
Windows 2008 Server Desktop Experience
Lizenz inkludiert,
oder Windows 7 / Windows 10 als BYOL
Basispreis pro Monat plus Stundenpreis je nach
Nutzung
16. • Endemol Shine Nederland uses contract video crews in
locations around the world to create their shows
• Preparing for a project took two weeks as the team had to set
up, secure, and ship hardware to a production site
• Endemol Shine Nederland decided to provide contract video
crews with Amazon WorkSpaces to run on their own devices
• The switch saved Endemol Shine Nederland 70% in PC
capex, 30% in PC operations, and reduced preparation time
to two hours.
Leon Backbier
IT Manager, Endemol Shine Nederland
”
“
Endemol Shine Nederland is a world leading creator,
producer and distributor of multiplatform entertainment with a
portfolio that includes Big Brother, MasterChef, Man vs.
Food, The Biggest Loser, and Wipeout.
“With Amazon WorkSpaces, we are able to
provide video crews with a secure cloud
desktop they can run on their own devices while
onsite. By using Amazon WorkSpaces, we
have saved 70% on PC capital expenditure, and
30% on desktop operations, while reducing our
preparation time from two weeks to two hours.”
Endemol Shine Nederland: Contract Workers
17. • Schnelle und sichere Desktops mit voller PC Performance
• Alle Daten zentral und sicher in der Cloud gespeichert
• Ideal für mobile und weltweit verteilte Teams
• Verwaltungsaufgaben werden einfacher
• Kompatibel mit existierenden Verwaltungs-Tools
• Kostenabrechnung feingranular nach Verbrauch
(Pro Monat, pro Stunde, Desktops und Applikationen)
Zusammenfassung
Familiar Windows desktop with an available app catalog
Persistent desktop so users can pick up right where they left off
Access to WorkSpaces from most popular devices over any network
Consistent performance thanks to cloud scale and global availability
Our customers are telling us that they are increasingly looking at new and novel solutions to address five key business imperatives:
The first of these is embracing personal devices. the phenomena known as Bring your own device, BYOD
As the consumer device landscape expands and becomes more diverse, employees expect that they can use any device of their choosing to do work.
Organizations who meet this expectation are seeing significant productivity gains.
The second is the expansion of contract work.
As supply chains span the globe,
businesses are increasingly turning to vendors and contractors for critical projects.
And IT needs to provide them with secure and convenient access to proprietary company data and systems.
Supporting such workers securely is an important challenge.
Work is increasingly mobile.
The traditional workday, where you spent 9-to-5 at a desk at the office, is a thing of the past.
Now, work happens at home, on the road, from a coffee shop, or from a customer’s site.
Many workers take advantage of flexwork arrangements and they are remote most of the time.
Moreover, Travel has become an integral part of work.
Employees expect to be productive regardless of where they are.
All these use cases, BYOD, Contract workers, and Mobile Access, require IT to focus on Data Security.
And this has become a fast moving target: While attach vectors have proliferated, regulatory requirements have also increased.
And finally, our customers tell us that in order to face these challenges, flexibility and agility is crucial.
The two traditional choices have been deploying corporate-managed personal computers
And On-premises deployment of virtual desktop infrastructure.
But neither option has worked.
[Click]
Solution is Amazon Workspaces.
Amazon Workspaces is a Desktop-as-a-Service (DaaS) offering hosted in the AWS cloud.
With A-Wspces, you get a cost effective, managed cloud desktop.
That provides a highly interactive cloud desktop which your users will love.
Fast, responsive user experience on any network
Available on wide range of personal devices including
It is Simple to manage:
No infrastructure or servers to worry about
Integrates with your existing IT tools and practices
Workspaces provides :
Secure access to the business desktop: applications, documents, and corporate resources
And it let’s you take advantage of Cloud economics:
Scale at your pace
Deploy rapidly
anywhere in the world
Only pay for what you use
HW refresh: Also consider re-purposing of existing hardware with partner solutions such as Neverware (Chromium) therefore extend the lifetime of HW and reduce IT burden
We have slides covering Improved Security and ease of management for MFA & SCCM later
Integrate with Active Directory (Corporate Identity), MFA for additional security and SCCM for application management (integrated with existing on-premises tools)
7
8
9
Lets recap on the Amazon WorkSpaces Capabilities.
Lets recap on the Amazon WorkSpaces Capabilities.
Customer initiates a TLS v1.2 for Authentication (SSL)
Authentication GW uses AWS Directory Services AD Connector to proxy Kerberos authentication to the customers own Active Directory
Client uses the Kerberos TGT ticket to initiate a PCoIP AES 256 streaming session to the customer WorkSpace
PCoIP Streaming protocol (think VPN endpoint)
14
STORY BACKGROUND
[One sentence about the company or role within an industry]. E.g. Vodafone operates a live, interactive mobile television service, known as Mobile TV, through the Cricket Live Australia application
[One sentence about what the company runs on AWS]. (E.g. ERP, analytics suite, statistical modeling platform, ad impression analytics platform, website, content delivery, etc)
[One sentence about a core benefit or transformational achievement].
SOLUTION & BENEFITS
[Why Amazon Web Services? #1]. E.g. By using AWS, Vodafone is able to provide its streaming mobile service to any mobile device on any network cost-effectively
[Why Amazon Web Services? #2]. E.g. Able to provide up to 10,000 simultaneous live streams compared to 3,000 before AWS
[Why Amazon Web Services? #3]. E.g. Streaming service would have cost millions without the AWS Cloud
CONTENT TAGS
Main use case: Options are: Archiving; Batch Processing,; Backup and Storage; Big Data, Analytics and Business Intelligence (BI); Business Applications – Microsoft; Business Applications – Oracle; Business Applications – SAP; Content Delivery; Datacenter Migration; Database and Data Warehouse; Development and Test; Disaster Recovery; High Availability: High Performance Computing; Internet of Things; Mobile; Website/Web App
Additional use case(s): Options are same as above.
Keywords (seperated by commas): E.g. “Hadoop, gaming,”
All AWS Services used by the customer: E.g. Using Amazon EC2, Auto Scaling, Amazon EBS, Amazon CloudWatch, and Amazon RDS
Benefits Realized: Options are: Agility, Availability, Better Performance, Durability, Ease of Use, Flexibility, Lower Cost, Lower Time To Market, Reliability, Scalability/Elasticity, Security, Speed, User Experience
Video: https://aws.amazon.com/solutions/case-studies/endemol-shine/
To learn more, please visit the resources you see here.