A guide to desktop management

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

TECH GUIDE

The desktop PC may be an invaluable business tool, but it also presents huge challenges in terms of day-to-day management and support — especially when it comes to large organisations with hundreds, if not thousands, of them to cope with.

Just keeping track of who has what hardware and where can be a real headache, let alone making sure it’s all configured correctly with the right application software, the latest patches, suitable firewall, antivirus and other security tools, and so on. Factor in the human element — users — and it’s easy to understand why desktop management can account for the lion’s share of any IT budget.

Desktop management: the story so far
There are plenty of available products designed to address the issues of desktop management. Most start with some kind of inventory tool, to discover and identify desktop assets and how they’re configured. To this can then be added tools to distribute applications, patches and other software, along with utilities to ensure that licence counts are enforced and yet more to enable support staff to remotely diagnose and fix faults when they arise.

Some of these tools are now built into the Windows desktop itself, but that’s a fairly recent innovation. Most are, therefore, implemented as standalone third-party applications or, more commonly, as part of larger integrated management suites from vendors such as Computer Associates, HP, Microsoft, Novell, Symantec and others.

Software-based management solutions are far from perfect, though. For a start, one or more client agents will normally have to be installed on each and every desktop PC for them to work. Distribution of these agents can be complex and presents a logistical challenge in itself. More importantly, most only work while the client PC is turned on and running a fully functional operating system. When users turn their systems off — at the end of the day, for example — management is effectively blocked except where specialised hardware features, such as Wake-on-LAN (WOL), enable them to be remotely powered back on.

Unfortunately WOL doesn’t help that much because even when desktops are on, the operating system needs to be fully operational. There are additional security and performance issues. For example, in most cases there's no encryption to protect the traffic sent between the remote management agents and central consoles; management traffic is also carried along with everything else over standard shared Ethernet LAN/WAN links — which are, again, only available with a fully functioning OS in place.

Compatibility can be an issue too, with only very basic common standards to insure interoperability between the hardware and software being managed, and the tools designed to facilitate that management. Finally, the whole setup can be compromised by a general lack of security on the desktop itself. Indeed, no matter how well you manage your desktops, it’s still hard to prevent users — or worse still, viruses and other malware — getting through the defences and messing them all up again.

Enter vPro
Intel’s answer to these and other desktop management issues is to take the functionality currently provided by software-based management clients, add extra features, make it more secure and build it into the PC. An approach it calls vPro, although as with the Centrino mobile platform and Viiv, Intel’s digital entertainment brand, vPro is more of a marketing concept than a single discrete technology. Indeed, just as with those brands, vPro really describes a collection of technologies. Some are new and others have been around for a while, but all are designed to work together to address desktop management issues.

Announced towards the end of 2006, the various bits of hardware and software required for vPro have taken a while to develop and deliver, but are starting to appear. The latest vPro development adds wireless support, about which more later.

In the meantime one of the most important of the vPro components is AMT (Active Management Technology), which has actually been around for a number of years. It’s the second generation of AMT, which is now built into Intel’s Q965 chipsets, which forms the core of what vPro is all about.

AMT at the core
One of the main things AMT does is take over where hardware enhancements such as Wake-on-LAN leave off, by making sure a desktop PC is always available to be managed, no matter what its power or operational status. In fact, as long as the PC is connected to a power supply, AMT makes sure the desktop is always accessible to management software, even when it’s otherwise switched off or there’s no functioning operating system.

To facilitate this always-on availability, AMT adds a secure communication channel connected via another key vPro component — an integrated Intel Gigabit Ethernet adapter. Described as 'out-of-band', this new secure channel is implemented using a logically separate and independent networking stack implemented in the hardware. This, like the other parts of vPro, is always available whether or not the PC is powered up or the host OS loaded. It’s also accessible using standard TCP/IP and addressing rather than a special communications protocol as with WOL.

Using this secure channel, a PC can be remotely powered up or down and crashed PCs rebooted even when the OS has hung. Moreover, using another vPro component — IDE-Redirect — it’s possible to remotely boot a PC to a known clean state by redirecting the boot device to a clean image on local storage, a CD mounted at the help desk or an image held on another remote drive.

Error logs and inventory information can, similarly, be accessed regardless of desktop state, the AMT firmware storing inventory data in secure non-volatile memory every time the PC is powered up.

The secure AMT channel can also be used by support staff to diagnose and resolve problems remotely. Indeed, using yet another vPro component technology — Serial-over-LAN (SOL) — engineers can remotely manage the PC independent of the OS, right down to editing BIOS settings remotely over the network.

All of this can be performed over secure encrypted links with access controlled by an Access Control List (ACL), which is stored in the non-volatile memory managed by vPro. The AMT firmware itself (digitally signed and encrypted) is also stored in this memory, along with third-party code and data for use by management applications, which make up another part of the vPro story.

 

Related stories

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Strain

Just gimme a map to the fridge. :D

51 minutes ago by Jack Strain via Facebook on Indoor navigation coming to a mobile near you soon
dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

9 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

10 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

16 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

20 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

22 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

1 day ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

2 days ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

2 days ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

3 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

3 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

3 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

3 days ago by Moley on Windows 8 start-up speed forces USB boot workaround