Professional Documents
Culture Documents
com
Natalia Jimenez / najimene@microsoft.com
Windows apps & Deployment Cost Secure & extensible
desktops anywhere flexibility reduction platform
Enable users to access Windows On-premises, Consolidate infrastructure Protect sensitive corporate data
applications and desktops from cloud-based, or Improve efficiency Build customized solutions
any device and any location hybrid deployments
Microsoft Remote
Desktop Protocol
Session-based desktops Access to pooled or Remote Desktop Session Windows 10 Desktops in Azure
and RemoteApp personal Virtual Desktops Host deployed on cloud
running Windows Client OS infrastructure services Create a VDI solution
Cost-effective, without large CAPEX
easy to manage High performance, Customizable with minimum
app compatibility capital expenditure
On-premises In cloud
https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients
Increased Enhanced Optimized
performance scale for cloud
FIREWALL
RD WEB ACCESS
RD GATEWAY
FIREWALL
RD CONNECTION BROKER
DATABASE
RD SESSION HOSTS
RD LICENSE SERVER
FILE ACTIVE
STORAGE DIRECTORY
Public Internet
VM
Virtual Network
UPD Storage
AAD DS File Server
(UPD, etc.) RDSH
Public Internet
VM
VM
Virtual Network
UPD Storage
AAD DS Azure SQL DB File Server
(UPD, etc.) RDSH
1.
VM
Virtual Network
VM
AD
RDSH
New with Windows Server 2016 RD Connection Broker!
Why? Azure SQL DB significantly lowers cost and complexity.
https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-connection-broker-cluste
Reduces complexity
Provides built-in sync with AAD
https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-azure-adds
Why?
• Reduce attack surface. RDGW and RDWeb move inside the firewall
• Eliminate the need to place domain joined GW in the DMZ
• For small deployments, combine RD CB, GW, Web, Lic on same VM.
AAD AP
Internet Internet (PaaS)
https://docs.microsoft.com/en-us/azure/active-directory/application-proxy-publish-remote-desktop
HA RDS / Azurev1 : RDS12R2
Public Internet
Azure Services
Management Interfaces Load Balancer/VPN
8 VMs Storage
Azure Services
RDS 2016 Infra: Management Interfaces Public Networking Infrastructure
5 Role Services
6 VMs Tenant1 Resource Group Ext Load Balancer
...
$43 /user /mo
VM
8 VMs Storage
Azure Services
RDS 2016 Infra: Management Interfaces Public Networking Infrastructure
4 Role Services
4 VMs Tenant1 Resource Group Ext Load Balancer
...
$38 /user /mo
VM
AAD
Domain RDLic RDCB RDSH
RDSH
Services VM
VM VM
Desktop/RemoteApp
8 VMs Storage
AAD AP
Azure Services
Management Interfaces Public Networking Infrastructure
AAD
Domain RDLic RDCB RDSH
RDSH
Services VM
VM VM
Desktop/RemoteApp
VM Collection
Compute
Azure Fabric
Storage
Network
HA RDS / Azurev2: RS2016 + AAD AP (2)
Public Internet
AAD AP
Azure Services
RDS 2016 Infra: Management Interfaces Public Networking Infrastructure
4 Role Services
2 VMs Tenant1 Resource Group
...
$33 /user /mo
VM
8 VMs Storage
WS12R2/Azure WS16/Azure
S2D SOFS in Availability Set
Desktop Hosting
Service
https://aka.ms/rd2016upgrade
On-prem only Azure and On-prem
Feature RemoteFX vGPU Direct device assignment
Device GPU Assignment Para-virtualized 1-1 assignment to GPU
Scale Best scale / 1 GPU to many VMs Low scale / 1 or more GPUs to 1 VM
App compatibility DX 11.1, OpenGL 4.4, OpenCL 1.1 All GPU capabilities provided by vendor (DX 12, OpenGL, CUDA, etc)
AVC444 Enabled By default (Windows 10 & WS2016) Available through Group Policy (Windows 10 & WS2016)
GPU VRAM Up to 1 GB VRAM / 4k resolution GPU / Azure’s N-Series VMs supported
Frame Rate ~30fps ~60fps
GPU driver in guest RemoteFX 3D adapter display driver (Microsoft) GPU vendor driver (NVIDIA, AMD, Intel)
Guest OS support WS2012R2, WS2016, Windows 7 SP1, Windows 8.1, Windows 10 WS2012R2, WS2016 (multi-session), Windows 10*, Linux
*Intel E5-2690v3
Security: RDS-hosted environments can use authentication with Azure Active Directory, providing:
• Conditional Access policies
• Multifactor Authentication
• Integrated authentication with other SaaS Apps using Azure AD
• Ability to get security signals from the Intelligent Security Graph.
• Isolate the infrastructure roles (Gateway, Web, connection broker and others) from the desktop and app
deployment hosts.
https://cloudblogs.microsoft.com/enterprisemobility/2017/09/20/first-look-at-updates-coming-to-remote-desktop-services
Traditional Cloud Cloud
Traditional installable Comprehensive Hybrid Simple, Secure, cloud- Simplest way to publish
Package End-to-end virtual apps Simple Window 10 VDI
software for complete IT virtual apps & based web-browser remote applications in
Description control
and desktops solution
desktop service solution
on Azure
the cloud
Citrix Infra.
IT Dept. Partner Citrix Citrix Citrix Citrix
Management
Workload
IT Dept. / Partner Partner IT Dept. / Partner Managed by Citrix IT Dept. / Partner IT Dept. / Partner
Management
Perpetual + Subscription Subscription Subscription Subscription Subscription
Licensing
Maintenance (varies) (user/year) (user hours) (User/month) (User/month)
Private cloud or Public Private, Partner,
Cloud Partner Cloud Citrix Selected Azure-only Azure-only
IaaS Public IaaS
RTM Normal Channel Normal Channel Normal Channel Normal Channel Azure Marketplace Azure Marketplace
Enterprises deploying VDI Windows 10 Windows 10 & Cloud
Cost Savings
Windows 7 User Experience
Proximity
Windows 8 Security
Flexibility
XenDesktop Essentials Service on Azure
Customer Subscription
Windows Windows
Server Server
Server
10 Server
10
VDAs VDAs
VDAs VDAs
Customer managed Customer also pays
Azure subscription for IaaS consumption
Customer’s Azure Subscription
License
Studio Director
Server
New XenDesktop Essentials
(operated by Citrix)
StoreFront/
Delivery
Receiver for SQL
Controllers
Web
Connector
Connector
Customer/Partner
managed Azure
NetScaler Windows
Server
Windows
Server
subscription
Gateway 10
Server 10
Server Active
VDAs VDAs Directory
VDAs VDAs
Azure
Microsoft
Citrix Microsoft Citrix HDX
Windows
Cloud Azure
Apps
Delivered from Citrix Windows apps to any App Workloads run in Superior in-session experience
Cloud device Azure
All supported Citrix Receivers
Simplified management Bring your own Windows Azure Resource Manager
images
Customer Subscription
Windows Windows
Server Server
Server
App Server
App
VDAs VDAs Customer managed Customer also pays
VDAs VDAs
Azure subscription for IaaS consumption
Customer’s Azure Subscription
Client Remote
Service Providers Desktop Services
https://azure.microsoft.com/en-us/pricing/licensing-faq
XenDesktop Essentials (XDE) XenApp Essentials (XAE)
• Helps deliver Windows 10 desktops hosted in Azure • Helps deliver Windows apps hosted in Azure
• Customer brings their own Win 10 license & leverages • Alternative to Azure Remote App (end-of-life Aug 2017)
AHUB • Cost to customer:
• Cost to customer: $12/user/month*
$12/user/month* + optional data transfer packs at $12/25GB/mo*
+ Azure IaaS consumption + $6.25/user/month Remote Access fee¥
+ Azure IaaS consumption
Activate your Azure Account:
https://azure.microsoft.com/en-us/offers/ms-azr-0044p/
Citrix on Azure
Build the Intelligent Cloud
Additional Steps
Get the most out of your Azure IUR benefit
Ensure your organization is leveraging your Azure IUR benefit to learn first-hand about the solution.
Step 1:
Learn how to implement the key Azure workloads: aka.ms/AzureIURWorkload
*Requires access to the Microsoft Partner Network portal. To associate to your organization’s MPN account, follow the steps at http://aka.ms/SimplifiedAssociation.
http://aka.ms/mpnsupport latampts@microsoft.com http://aka.ms/supportcommunities