Windows 8.1
deployment planning
A guide for education
January 2014
Table of
contents
2 Windows 8.1 in education
2 ITbenets
2 Facultybenets
3 Studentbenets
4 Windows 8.1 purchase and licensing
6 Volume Activation
10 Network infrastructure
10 Internetingressandegress
11 Networkbandwidth
12 Wirelessnetworking
15 Accessibility
16 Printers
18 Security and privacy
21 Internetaccess
21 Applicationaccess
21 Deviceaccess
22 Remoteconnectivity
24 DirectAccess
25 Virtualprivatenetwork
26 Windows Store apps
27 User accounts
29 Deployment
31 Institution-owneddevices
32 Personallyowneddevices
33 VirtualDesktopInfrastructure
34 WindowsToGo
36 Device roaming and multiple devices
39 WindowsWorkFoldersandWorkplaceJoin
40 WindowsFolderRedirection
41 WindowsOfineFiles
41 WindowsRoamingUserProles
42 Defaultuserproles
42 UserExperienceVirtualization
43 MicrosoftApplicationVirtualization
44 Conguration and management
46 GroupPolicy
47 WindowsPowerShell
47 CongurationManager
47 WindowsIntune
1WINDOWS 8.1 DEPLOYMENT PLANNING
Windows 8.1
deployment planning
A guide for education
This guide is designed for IT pros, school administrators,
and other faculty members who are responsible for the
deployment of devices running Windows 8.1 in educational
institutions. This guide covers the key considerations and
questions that should be answered as a part of a typical
Windows 8.1 deployment.
SomeofthekeystosuccessinaWindows8.1(oranytechnology
deployment)thatwewillcoverineachsectionareasfollows:
• DevelopandcommunicateyourWindows8.1deploymentplan
beforeyoudeploydevices.
• Starttheplanningprocessandvalidateyourdesignasearly
inyourdeploymentprojectaspossible,becausebaddesign
decisionsbecomedifculttocorrectthelateryoudiscoverthem
intheprocess.
• Includerepresentativesfromcurriculumandtechnology
leadership(inadditiontothosewhoareresponsiblefor
performingtheactualdeployment)tohelpensurethatthenal
solutionmeetsorexceedscurriculumandlearningoutcome
requirements.
Eachsectioninthisguideliststhekeyplanningconsiderationsand
questionsforthetopicscoveredinthatsection.Eachsectionalso
includeslinkstoadditionalresourcestohelpintheWindows8.1
deploymentplanningprocessdiscussedinthatsection.
NOTE
Classroomcurriculum
designisoutsidethe
scopeofthisdocument.In
addition,althoughmostof
theplanningdecisionsin
thisguideareapplicable
toWindowsRT8.1,
WindowsRT,andWindows
8,thisguidefocuseson
Windows8.1deployment
only.
2WINDOWS 8.1 DEPLOYMENT PLANNING
Windows 8.1 in education
Windows8.1providesanincredibleopportunityforeducatorsandstudentstotakeadvantageof
thenewworldofdigitaleducationandexcitingnewdevices,leveragingtheworldwidestandard
Microsoftplatformandcloudservicestoensureseamlessmanageability,robustsecurity,backward
compatibility,andcosteffectiveness.RunningWindows8.1ondevicesdesignedforWindows8.1
canhelpyoumeetthechallengesandmaximizethebenetsofusingWindows8.1ineducation.
IT benets
ManyITorganizationswithineducationalinstitutionsalreadysupportaMicrosoftinfrastructure.
Inmanyinstances,theITstaffcanusethesametoolstheyarealreadyfamiliarwithtomanage
Windows8.1devices.Institutionscanalsooutsourcethisworktopartnerswhoareabletoleverage
thepartner’sWindows8.1managementexperienceandskillsets.
YoucanmanageWindows8.1devicesandappsautomaticallybyemployingon-premisesand
off-premisesmanagementsolutions.Thesesolutionsdramaticallyreducetheeffortrequiredfrom
ITprostokeepdevicescurrentwithsoftwareandsecurityupdatesandtoperformcommonIT
administrativetasks.Inmanyinstances,educationalinstitutionscancreateself-serviceportalsthat
allowuserstosolvemanycommonproblemsthemselves(suchasresettingapassword,deploying
anapp,orinstallingsoftwareupdates).ThismeansthatITproscanspendfewerhoursmanaging
hardware,software,andservicestoprovidehigher-qualityserviceswiththesameorlesslevelof
effort.
Faculty benets
Windows8.1hasalargeecosystemofprovidersandservices,providingeducatorstheexibilityto
choosethedevicesandservicestheyprefer–sotheycanteachthewaytheywant.Windows8also
helpsteachersmanagetheclassroombylimitingavailabilityofdistractingapplications(suchas
instantmessagingorsocialnetworking)duringclassandviewingandsharingstudentscreensto
improveclassroomparticipation.
MostinstructorsandfacultymembersarefamiliarwiththeWindowsoperatingsystemandusually
haveanexistingdevicerunningWindowsintheclassroomorathome.Facultymembershave
avastlibraryofexistingWindowssoftwareandperipheralstoincorporateintotheirlearning
curriculum.DevicesrunningWindows8.1supportWindowsStoreappsanddesktopapplications,
whichallowseducatorstohavetheultimateinexibilityanddiversitywhenselectingtechnology
resourcesfortheclassroom.IfapplicationsandperipheralsworkedinWindows8andWindows7,
theywilloftenworkjustaswellinWindows8.1,decreasingbothcostanddeploymenttime.
3WINDOWS 8.1 DEPLOYMENT PLANNING
Thismeansthatinstructorsandfacultymemberswillbeabletorealizethebenetofusing
Windows8intheclassroommorequicklythanotheroperatingsystems.
Student benets
Learningisaboutconsuming,collaboration,andcreation.MostWindowsdeviceshavea
multitouchuserinterfacethatprovidesanimmersiveuserexperienceforconsumingand
collaborating,buttheyalsocomewithafull-functioningkeyboardthatisessentialforcontent
creation.Nowthereistheadditionofauidandimmersiveuserexperiencethatenablestablets
andtouchscreensaswell.Withthehugeinterestintabletsforthestudentmarket,Windows8.1is
abletoprovideaconsistentuserexperienceacrossformfactors.Inaddition,studentshaveaccess
tothevastlibraryofexistingsoftwarecreatedforWindows—includingWindowsStoreappsand
Windowsdesktopapplications—andmostapplicationsthatrunontheWindows8,Windows7,or
WindowsXPoperatingsystemwillalsorunonWindows8.1.
MoststudentsalreadyknowhowtousedevicesrunningaWindowsoperatingsystem.They
typicallyhaveaccesstodevicesrunningWindowsathome,aswell,whichallowsstudentsto
continuetheireducationathomewithoutadditionalcostonthepartoftheeducationalinstitution
orthestudent’sfamily.
4WINDOWS 8.1 DEPLOYMENT PLANNING
Windows 8.1 purchase
and licensing
NotethefollowingkeyWindows8.1purchaseandlicensingplanning
considerations:
• Howmanyusersdoyouneedtoenable?
• HowmanynewdeviceswillyoubuywithWindows8.1
preinstalled?
• HowwillyouupgradeexistingWindows8devicesto
Windows8.1?
• HowmanyWindows8.1licensesdoyouneedtopurchaseto
upgradeexistingdevices(notethatsomeproductswillrequire
licenseupgrades,suchasWindows8.1Enterpriseedition)?
• HowdoesyourinstitutionhandleWindow8.1licensingfor
personallyowneddevices?
• HowcanfacultyandstudentspurchaseWindows8.1licensesat
educationalprices?
• Whateducationalpricingandlicensingprogramsareavailable
foreducationalinstitutions?
Eachphysicaldeviceorvirtualmachine(VM)runningWindows8.1
musthaveavalidlicense.Mostdevicehardwarevendorsprovide
aWindows8.1licenseforeachdevicetheinstitutionpurchases.
However,youmustobtainWindows8.1licensesforanyexisting
devicesrunningpreviousversionsofWindowsthatwillbeupgraded
toWindows8.1(suchasdevicesrunningWindows7).
ThelistbelowprovidestheWindows8.1licensingconsiderationsfor
devicesbasedontheirownership:
• Institution owned Educationalinstitutionscanacquire
licensesforWindows8(andotherMicrosoftproducts)
throughtheMicrosoftEnrollmentforEducationSolutions
(EES)program.TheMicrosoftEESprogramisaneasy,cost-
NOTE
ExistingWindows8
licensescanbeupgraded
toWindows8.1licenses
withoutadditional
licensingfeesforthesame
editionofWindows8.1.For
example,aWindows8Pro
licensecanbeupgradedto
Windows8.1Prowithout
additionallicensingfees.
However,upgradinga
Windows8licenseto
Windows8.1Prowould
requiretheWindows8Pro
licensepriortoupgrading.
NOTE
Microsoftworkswith
organizationsinthepublic
sectorthroughtheShape
theFutureprogram.For
moreinformationabout
theShapetheFuture
program,seehttp://
www.microsoft.com/
shapethefuture.
5WINDOWS 8.1 DEPLOYMENT PLANNING
effectiveofferthatprovidesqualiedacademiccustomers
asimpliedwaytoacquireMicrosoftsoftwareandservices
underasinglesubscriptionagreement.Formoreinformation,
see“ProgramsforEducationalInstitutions”athttp://www.
microsoft.com/education/en-us/buy/licensing/Pages/
enrollmentforeducationsolutions.aspx.
• Personally owned Facultyandstudentsareresponsiblefor
havingtheappropriateWindows8licensesfortheirdevices.
InadditiontopotentiallybeingabletopurchaseMicrosoft
softwarethroughtheeducationalinstitution,facultyand
studentscanindividuallypurchaseMicrosoftproductsat
educationaldiscountsthroughresellerssuchas:
• JourneyEdat />Microsoft/284074
• OnTheHubat
UsethisinformationtodeterminethenumberofWindows8.1
licensesyoumustobtainforyoureducationalinstitution.Also,
usetheinformationtodetermineinstitution-sponsoredMicrosoft
educationalbenetprogramsforfacultyandstudents.
INFO
Formoreinformation,see
“MicrosoftinEducation”
atrosoft.
com/education/
en-us/buy/Pages/
academicsavings.aspx.
6WINDOWS 8.1 DEPLOYMENT PLANNING
Volume Activation
NotethefollowingkeyMicrosoftVolumeActivationplanningconsiderations:
• WhichlicensingmodelsareavailableforWindows8.1andMicrosoftOfceProfessional
Plus2013?
• Whattechnologiesareavailabletoactivatevolumelicenses?
• Whattypeofconnectivityisavailablefordevicestoperformactivation?
ThefollowinglistshowstheVolumeActivationtechnologiesandprovidesabriefdescriptionof
each:
• Active Directory-Based Activation (ADBA) ADBAisaroleservicethatallowsyoutouse
ActiveDirectoryDomainServices(ADDS)tostoreactivationobjects,whichcanfurther
simplifythetaskofmaintainingVolumeActivationservicesforanetwork.WithADBA,no
additionalhostserverisneeded,andactivationrequestsareprocessedduringcomputer
startup.ADBAworksonlyfordevicesrunningWindows8thataredomainjoined.
• Key Management Service (KMS) KMSisaroleservicethatallowsorganizationstoactivate
systemswithintheirnetworkfromaserveronwhichaKMShosthasbeeninstalled.WithKMS,
ITproscancompleteactivationsontheirlocalnetwork,eliminatingtheneedforindividual
computerstoconnecttoMicrosoftforproductactivation.KMSdoesnotrequireadedicated
system,anditcanbecohostedonasystemthatprovidesotherservices.Bydefault,volume
editionsofWindows8connecttoasystemthathoststheKMSservicetorequestactivation.
Noactionisrequiredfromtheuser.
• Multiple Activation Key (MAK) AMAKisavolumelicensekeythatisusedforone-time
activationwithactivationservicesthatMicrosofthosts.YoucanactivateMAKsoverthe
Internetorbytelephone.
Table1onpage7liststheVolumeActivationtechnologiesandtheinformationnecessaryfor
selectingtheappropriatetechnologiesforyourinstitution.Youcanselectanycombinationof
thesetechnologiestodesignacompleteVolumeActivationsolution.
7WINDOWS 8.1 DEPLOYMENT PLANNING
ADBA KMS MAK
Device must be domain
joined
Yes No No
Devices must connect to
the network at least once
every 180 days
Yes Yes No
Supports Volume
Activation of Windows 8.1
and Windows 8
Yes Yes Yes
Supports Volume
Activation of Windows 7
No Yes Yes
Supports Volume
Activation of Microsoft
Ofce
Yes
(Ofce2013
only,not
Microsoft
Ofce365
orprevious
versionsof
Ofce)
Yes Yes
Can use Volume
Activation services in
Windows Server 2012 R2
and Windows Server 2012
Yes Yes N/A
Can use Volume
Activation services in
operating systems prior
to Windows Server
2012 R2 and Windows
Server 2012
Yes,but
requiresthat
theActive
Directory
schemabe
updatedto
Windows
Server 2012
orWindows
Server 2012
R2
Yes N/A
Microsoft Volume
Licensing information is
stored in AD DS
Yes No No
Can be activated with
Internet access only
No No Yes
Can be activated by
telephone
No No Yes
TABLE 1 Volume
ActivationTechnology
Selection
8WINDOWS 8.1 DEPLOYMENT PLANNING
ADBA KMS MAK
Required infrastructure AD DS
KMSserver,
however
having
AD DS
makesKMS
management
easier
Internet
accessor
telephone
9WINDOWS 8.1 DEPLOYMENT PLANNING
Additionalinformation:
• “PlanforVolumeActivation”at />• “VolumeLicensing”at />• “IntroductiontoVAMT”at />• Volume Licensing Guide for Windows 8.1 and Windows RT 8.1atrosoft.
com/download/9/4/3/9439A928-A0D1-44C2-A099-26A59AE0543B/Windows_8-1_
Licensing_Guide.pdf
• “MicrosoftLicensingfortheConsumerizationofIT”at />about-licensing/briefs/consumerization-it.aspx
• “MicrosoftLicensingfortheConsumerizationofIT-AcademicLicensingScenarios”athttp://
www.microsoft.com/licensing/about-licensing/briefs/consumerization-it-academic.aspx
• “LicensingWindowsdesktopoperatingsystemforusewithvirtualmachines”athttp://www.
microsoft.com/en-in/licensing/about-licensing/briefs/win8-virtual.aspx
• “VolumeactivationofOfce2013”at />aspx
10WINDOWS 8.1 DEPLOYMENT PLANNING
Network infrastructure
BecauseWindows8.1devicesarenotjustcloud-connecteddevices(theyworkofinetoo),your
existingnetworkinfrastructurewilloftenbeadequatetosupportWindows8.1.Aspartofthe
planningprocess,determineanynetworkinfrastructureremediationthatyoumustperformprior
todeployingWindows8devices.
Internet ingress and egress
NotethefollowingkeyInternetingressandegressplanningconsiderations:
• WhatTCPandUserDatagramProtocol(UDP)trafcmustbeallowedtoandfromthe
Internet?
• Whichwebsitesmustbeaddedtotheapprovedsiteslistforedge-of-networkappliances?
• WhataretherequirementsforbeingcompliantwiththeChildren’sInternetProtectionAct
(CIPA)?
• Whichrewallsshouldyouuse(rewallappliancesandWindowsrewall)?
OneofthekeyfeaturesinWindows8.1istheintegrationwithInternet-basedcontentandservices,
especiallytheWindowsStore.YoumustplananynecessarychangestoyourInternetingressand
egresstoprovideaccesstosuchcontentandservices,asdescribedinthefollowinglist:
• TCP and UDP trafc PlantheTCPandUDPtrafcthatmustbeallowedtoandfromthe
Internet.Specically,allowthetrafcrequiredforanynewWindowsStoreappordesktop
applicationsthatwillbeaddedaspartoftheWindows8.1deploymentprocess.
• Approved website list Manyedge-of-networkappliances(suchasrewallsorwebproxies)
supportalistofapprovedwebsites.Inyourplan,specifythatthelistincludestheWindows
Storeandothersupportingsites.
• CIPA compliance YoureducationalinstitutionmayneedtocomplywithCIPA,which
imposescertainrequirementsonschoolsorlibrariesthatreceivediscountsforInternetaccess
orinternalconnectionsthroughtheE-rateprogram,whichmakescertaincommunications
servicesandproductsmoreaffordableforeligibleschoolsandlibraries.Formoreinformation
aboutCIPA,see“Children’sInternetProtectionAct”at />internet-protection-act.
11WINDOWS 8.1 DEPLOYMENT PLANNING
• Firewall usage YoucanuserewallappliancesandWindowsFirewalltoprotectdevicesand
providesecuritydefenseindepth.Ifyouuseboth,ensurethatyouprovidetheappropriate
accesstotheWindowsStoreandotherInternet-basedcontentandservicesbyconguring
bothrewalls.YoucanspecifythattheWindowsFirewallbeconguredbyusingGroupPolicy
rewallsettings.FormoreinformationonusingGroupPolicytocongureWindowsFirewall,
seetheMicrosoftTechNetarticle,“CongureFirewallPortRequirementsforGroupPolicy,”at
/>Network bandwidth
Notethefollowingkeynetworkbandwidthplanningconsiderations:
• CantheLANandWi-Finetworksupportahighdensityofdevices?
• Doesthenecessaryavailablenetworkbandwidthexistforconnectingtoon-premises
resources?
• DoesthenecessaryavailablenetworkbandwidthexistforInternetaccess?
TheuseoftechnologyinmostcurriculumplansrequiresaccesstolocalandInternet-based
resourcesandcontent(suchasdocumentstoragelibraries,multimediales,oronlinestudy
resources).Thefollowingisalistofplanningconsiderationsthatrelatetonetworkbandwidth:
• Support for a high density of devices Educationalenvironmentstendtohaveahigh
concentrationofdevicesinasmallgeographicarea.Facultyandstudentsrequirenetwork
accessfromclassrooms,labs,andcommonareas.Thesenumberscanrangefrom20–30
devicesinaclassroomtohundredsofdevicesinacommonarea(suchasalibraryorstudent
center).Typically,thisnumberimpliesthateachclassroommayrequireadedicatednetwork
connectiontotheon-premisesnetwork,andcommonareasmayrequiremultiplededicated
networkconnectiontotheon-premisesnetworktosupportthenumberofdevicesinagiven
geographicarea.
• On-premises available network bandwidth Alldevicestypicallyneedhigh-speed,
persistentconnectionstoon-premisescontentandresources(suchasprinters,leservices,
orintranet-basedsites).Ensurethattheon-premisesnetworkhassufcientbandwidthto
providereasonableresponsetimeswhenaccessingtheon-premisesresources.Also,include
Internettrafcwhenevaluatingyouron-premisesnetwork,becausedevicesconnecttothe
Internetthroughtheon-premisesnetwork.Youcanestimatethistrafcbyobservingthe
typicalintranettrafcadevicegenerates,thenmultiplyingthatbythenumberofdevices
withinagivengeographicarea.
12WINDOWS 8.1 DEPLOYMENT PLANNING
• Internet available network bandwidth AlldevicestypicallyneedaccesstoInternet-based
contentandresources(suchastheWindowsStoreandotherInternet-basedwebsites).Ensure
thattheInternetconnectionhassufcientbandwidthtoprovidereasonableresponsetimes
whenaccessingtheInternet.Youcanestimatethisresponsetimebyobservingthetypical
Internettrafcadevicegenerates,thenmultiplyingthatbythenumberofdeviceswithina
givengeographicarea.
Thephysicalnetworkdesignisspecictothetypeofdevicesandthevendorspecicationsfor
eachdevice.Contactthenetworkinfrastructurevendorsforplanningtoolsandresourcestohelp
indeterminingnetworkbandwidth.
Wireless networking
Notethefollowingkeywirelessnetworkplanningconsiderations:
• HowmanyWi-Fiwirelessdeviceswillbeusedwithineachclassroomandincommonareas
(devicedensity)?
• WhatWi-Fitechnologiesdoyouneedtosupport(suchasInstituteofElectricaland
ElectronicsEngineers[IEEE]802.11n,802.11g,or802.11b)?
• Willbroadband(cellular)deviceconnectivitybesupported?
Mostmoderndevicesuseawirelessconnectiontoaccessnetworks.Althoughwirelessconnection
reducestheclutterandproblemsassociatedwithwirednetworkconnections,itaddstothe
complexityofplanningandsupportingnetworks.
• Wi-Fi–supported standards MostdevicessupportavarietyoftheIEEE802.11XWi-
Fistandards,suchas802.11n,802.11g,or802.11b.Ensurethatthewirelessaccesspoints
(WAPs)supportthehighestspeedstandardthedevicesupports.Supporttheslowerspeed
standardstoprovidecompatibilitywitholderdevices.Forexample,mostnewdevicessupport
IEEE802.11n,butolderdevicesmayonlysupportIEEE802.11b.
• Network frequency IEEE802.11Xwirelessstandardsusethe2.4gigahertz(GHz)and5.0GHz
frequenciesforcommunicationbasedonthestandardused.MostmodernWAPssupport
bothfrequencies.Mostnewdevicessupport5.0GHzfrequencies,whileolderdevicesonly
supportthe2.4GHzfrequencies.EnsurethatyourWAPssupportthecorrectfrequenciesto
supporttheplanneddevicepopulation.
• Wireless device density Thisconsiderationissimilartotheplanningdecisionsforwired
networks.Fromthewirelessperspective,determinethenumberandplacementofWAPs.
Mostenterprise-classWAPscansupportupto50devices;however,wirelessnetwork
13WINDOWS 8.1 DEPLOYMENT PLANNING
performancewilldegradedramaticallyasthenumberofdevicesapproachesthemaximum
value.AWAPtypicallyhasasinglewirednetworkconnect,whichmeansthatalldevices
connectingthroughtheWAPsharethatsinglewirednetworkconnection.Forexample,ifyou
haveaWAPthatsupports30studentsandhasagigabitwirednetworkconnection,those30
studentssharethatsinglegigabitnetworkconnection.Inareaswithalargeconcentrationof
devices,multipleWAPsmayberequired.
• Wireless coverage Ensurethateachdevicehaswirelessconnectivitywithintheareaswhere
thedevicesareused(classroomsandcommonareas)byproperlyplacingWAPs.Placing
WAPstoofarfromeachotherresultsinareaswheredeviceswillnotbeabletoconnect.
PlacingtheWAPstooclosetoeachothercanincreaseyourcostbycreatingunnecessary
WAPs.EnsurethatthecoverageareasforWAPsoverlapslightly.WAPsthatoverlapeachother
shoulduseauniquechannel(frequency).
• Hidden service set identier (SSID) YoucancongureWAPsnottobroadcasttheirSSIDs,
alsoknownasahidden SSID.HiddenSSIDsaretypicallyusedasasecuritymeasure;however,
avoidtheuseofhiddenSSIDs,becauseitismoredifcultforadevicetojoinahiddenSSID,
andthereisminimalsecuritybenetinhidingSSIDsineducationalsolutions.Becauseusers
tendtoroam,hiddenSSIDscanleadtopooruserexperienceanddelaysinwirelessnetwork
associationtime.
• Broadband cellular support Manydevicesmayhavebroadbandcellularnetworkadapters
thatprovideInternetconnectivity.Broadbandcellularconnectivitycanreducethenetwork
congestiononyourwirelessWi-Finetworks.However,broadbandcellularconnectivityalso
requiresacontractwithacellularprovider.
• Rogue Wi-Fi hotspots ManyusersmaybringWi-Fi–enableddevicesthatcanactasWi-
Fihotspots(suchashotspotsprovidedbycellularprovidersorsmartphones).Ensurethat
youspecifyalistofpublishedSSIDsinyourdesignforthefacultyandstudents.Also,specify
policiesandproceduresthatdiscouragefacultyandstudentsfromstartinganunauthorized
Wi-Fihotspot.
YoucanspecifytheuseofGroupPolicytocongurethewirelessnetworkadaptersettingsfor
devices.Doingsoallowsyoutoprovideconsistentwirelesscongurationsettingsfordomain-
joineddevices.
14WINDOWS 8.1 DEPLOYMENT PLANNING
Additionalinformation:
• “Congure802.1XWirelessAccessClientsbyusingGroupPolicyManagement”athttp://
technet.microsoft.com/library/dd759173.aspx
• “IdentifyingtheAreasofCoverageforWirelessUsers”at />library/cc780260(v=ws.10).aspx
• “DeterminingHowManyWirelessAPstoDeploy”at />cc782947(v=ws.10).aspx
• “DeterminingWheretoPlaceWirelessAPs”at />cc739928(v=ws.10).aspx
• “SelectingChannelFrequenciesforWirelessAPs”at />cc783011(v=WS.10).aspx
15WINDOWS 8.1 DEPLOYMENT PLANNING
Accessibility
Notethefollowingplanningconsiderationsforuserswithspecialaccessibilityneeds:
• WhatEaseofAccessandPersonalizationoptionsdofacultyandstudentsrequire?
• Whatassistivetechnologiesdofacultyandstudentsrequire?
Windows8.1providesessentialaccessibilitytocomputersforthosewithsignicantvision,hearing,
dexterity,language,orlearningneeds.ThesefeaturesareavailableinWindows8.1,Windows8.1
Pro,Windows8.1Enterprise,andWindowsRT8.1.
NotethefollowingplanningconsiderationsforWindows8accessibility:
• Ease of Access and Personalization options TheseoptionsinWindows8.1makedevices
easiertosee,hear,anduse;theyincludescreenmagnication,speechrecognition,narration,
on-screenkeyboard,keyboardshortcuts,stickykeys,andvisualnotications.
• Assistive technologies Thebuilt-inassistivetechnologiesinWindows8.1workwithboth
WindowsStoreappsandWindowsdesktopsoftwaretoprovideseamlessaccesstotheentire
Windowsexperience.DevicesrunningWindows8.1alsoallowyoutouseassistivetechnology
softwarefromspecialtyassistivetechnologyvendors.
Additionalinformation:
• “AccessibilityinWindows8” at />• “AssistiveTechnologyProducts”at />• “Windows8.1VoluntaryProductAccessibilityTemplate(VPAT)”atrosoft.
com/download/B/1/B/B1BDCD6D-4EBC-4D92-9405-5E81AAE159D0/Remote_Server_
Administration_Tools_for_Windows_8_1_VPAT.docx
16WINDOWS 8.1 DEPLOYMENT PLANNING
Printers
Notethefollowingkeyprinterplanningconsiderations:
• WhichprinterdriversdoesWindows8.1support?
• WhatisneededtosupportWindowsStoreappsandAdvanced
PrintSettingsforWindowsStoreapps?
• Howwillusersconnecttoprinters?
• Whichwillrequiresecuredaccess?
Facultyandstudentsneedtoconnecttoprinterresources.You
needtoplanforuserconnectivitytoinstitution-ownedprinters.
Typically,theseprintersarenetwork-based(throughwirelessor
wirednetworks).However,insomeinstances,theseprintersmaybe
connectedtotheWindows8devicesbyUSBcables.
NotethefollowingplanningconsiderationsforWindows8printer
connectivity:
• Printer drivers Windows8.1supportsthev3printerdriver
model(usedinWindows7)andthev4printerdrivermodel
(usedinWindows8.1andWindows8).Printersthatare
connectedtoWindows8.1deviceswithv3printerdrivers
installedwillcontinuetoworkastheycurrentlydowithdesktop
applications.Somelimitationsexisttousingprinterdrivers
basedonthev3printerdrivermodelforWindowsStoreapps.
• Windows Store device app and Advance Print Settings
support FormanyWindows8.1—andWindows8—certied
printers(v4printerdrivermodel),Windows8.1automatically
discovertheprintersandinstallsthenecessarydrivers.
Otherwise,youcanspecifytheGroupPolicysettingsforprinters
fordomain-joineddevices.Youcanalsospecifythatusers
manuallyaddandcongureprintersastheydidinWindows7.
Ensurethatyouspecifyalistofavailableprinters(includingany
necessaryIPinformation)tostudentsandfaculty.
NOTE
Ensureyouhave
Windows8.1-certied
printerdevicedrivers
forasmanyprintersas
possible.
17WINDOWS 8.1 DEPLOYMENT PLANNING
• User connection to printers FormanyWindows8–certiedprinters(v4printerdriver
model),Windows8automaticallydiscovertheprintersandinstallsthenecessarydrivers.
Otherwise,youcanspecifytheGroupPolicysettingsforprintersfordomain-joineddevices.
YoucanalsospecifythatusersmanuallyaddandcongureprintersastheydidinWindows7.
Ensurethatyouspecifyalistofavailableprinters(includinganynecessaryIPinformation)to
studentsandfaculty.
• Security for printing Insomeinstances,youmaywanttolimitprinterusageto
authenticatedusers.Doingsorequiresthatthosewhoneedtousetheseprintershave
accountsinanADDSdomainsothattheappropriatepermissionscanbeappliedtoeach
printer.
• Protected printing Windows8.1includessupportforprotectedprinting,whichallowsusers
tospecifyaPINthatisthenusedattheprinterpriortothejobbeingprinted.Windows8.1
alsoallowsyoutospecifyadefaultPINtoreducewastefulpaperconsumptionrelatedto
contentthatisprintedbutneverretrieved.
Additionalinformation:
• “PrintersExtension”at />• “DeployingPrintersbyUsingGroupPolicy”at />aspx
• “OverviewofPrintinginWindows8”at />hardware/hh852373.aspx
• “DriverSupportforProtectedPrinting”at />hardware/dn265277(v=vs.85).aspx
18WINDOWS 8.1 DEPLOYMENT PLANNING
Security and privacy
NotethefollowingInternetplanningconsiderations:
• WhicheditionofWindows8.1isnecessarytosupportthedesiredsecurityandprivacy
features?
• HowareusersanddevicesprotectedwhenconnectedtotheInternet?
• Whatmethodsareavailabletopreventusersfrominstallingorrunningunauthorizedapps?
• WhatmethodsareavailabletoprotectuserprivacywhenrunningWindowsStoreapps?
• Whatmethodsareavailabletoprotectdevicesandtheinformationonthem?
• Whatpoliciesshouldyouconsiderimplementingwithstudents,parentsandfaculty?
Windows8.1includesseveralnewsecurityandprivacyfeatures.Table 2liststhesecurity
andprivacytechnologiesbyWindows8.1edition.Usethislisttodeterminewhicheditionof
Windows8.1youneedtosupportthesecurityandprivacytechnologiesyouwanttouse.Selectthe
appropriateWindows8.1editionthatprovidesacompletesecurityandprivacysolutionthatyou
canthencustomizeforeachuser.
WinDoWS 8.1 WinDoWS 8.1
Pro
WinDoWS 8.1
EntErPriSE
Windows Store App
privacy
Yes Yes Yes
Family Safety Yes Yes Yes
Unied Extensible
Firmware Interface (UEFI)
Secure Boot
Yes Yes Yes
SmartScreen Filter Yes Yes Yes
Windows Defender
(malware protection)
Yes Yes Yes
Windows Firewall Yes Yes Yes
Picture Password Yes Yes Yes
TABLE 2 Securityand
PrivacyTechnologiesby
Windows8.1Edition
19WINDOWS 8.1 DEPLOYMENT PLANNING
WinDoWS 8.1 WinDoWS 8.1
Pro
WinDoWS 8.1
EntErPriSE
BitLocker Drive
Encryption and BitLocker
To Go
No Yes Yes
Encrypting File System
(EFS)
No Yes Yes
Domain membership No Yes Yes
Group Policy objects
(GPOs)
No Yes Yes
AppLocker No No Yes
Microsoft DirectAccess No No Yes
Auto-triggered VPN Yes Yes Yes
Windows To Go No No Yes
Forinstitution-owneddevices,Windows8.1ProorEnterpriseis
recommended(dependingonthefeaturesdesired)forinstitutions
thatrequiremanagementofdevicesbyusingMicrosoftmanagement
productsandtechnologies,suchasGroupPolicyandMicrosoft
SystemCenter2012R2CongurationManager.Inmanaged
environmentsWindows8.1shouldbeafactorforpersonallyowned
devicesinBringYourOwnDevice(BYOD)scenarios.
Thesubsequentsectionswilllookathowthesefeaturesareused
forInternetaccess,applicationaccess,anddeviceaccess.Formore
informationaboutthefeaturesinTable2onpage18,seethe
followingresources:
• Windows Store App privacy Seesection4,“WindowsStore
appsputthecustomerincontrol,”inthetopic,“Appcertication
requirementsfortheWindowsStore,”atrosoft.
com/en-us/library/windows/apps/hh694083.aspx
• Family Safety Seethetopic,“What’sNewinWindows8Family
Safety,”at />desktop/jj155495(v=vs.85).aspx
NOTE
Thereisnocentralized
managementofthe
FamilySafetyfeature
byusingGroupPolicies.
TheMicrosoftaccount
shouldbeviewedasa
personalaccountfor
usebystudentsortheir
guardians.
20WINDOWS 8.1 DEPLOYMENT PLANNING
• UEFI Secure Boot Seethetopic,“SecuringtheWindows8BootProcess,”athttp://technet.
microsoft.com/en-US/windows/dn168167.aspx
• SmartScreen Filter and Windows Defender Seethetopic,“HowdoIndandremovea
virus,”at />topic,“SmartScreenFilter:FAQ,”at />smartscreen-lter#ie=ie-10
• Windows Firewall Seethetopic,“WindowsFirewallfromstarttonish,”athttp://windows.
microsoft.com/en-US/windows-8/Windows-Firewall-from-start-to-nish
• Picture Password Seethetopic,“Signinginwithapicturepassword,”athttp://windows.
microsoft.com/is-is/windows-8/picture-passwords#1TC=t1
• BitLocker and BitLocker To Go Seethetopic,“HelpprotectyourleswithBitLocker
DriveEncryption,”at />encryptionandthetopic,“HelpprotectyourleswithBitLocker,”atrosoft.
com/en-US/windows-8/bitlocker#1TC=t1
• EFS Seethetopic,“Encryptordecryptafolderorle,”at />US/windows-vista/Encrypt-or-decrypt-a-folder-or-le
• Domain membership Seethetopic,“ActiveDirectoryDomainServicesOverview,”athttp://
technet.microsoft.com/en-us/library/hh831484.aspx
• GPOs Seethetopic,“GroupPolicyOverview,”at />library/hh831791.aspx
• AppLocker Seethetopic,“AppLockerOverview,”at />library/hh831409.aspx
• DirectAccess Seethetopic,“UsingDirectAccess,”at />windows/dn168168.aspx
• Auto-triggered VPN Seethetopic,“What’sNewinRemoteAccessinWindowsServer2012
R2,”at />• Windows To Go Seethetopic,“WindowsToGo:FeatureOverview,”athttp://technet.
microsoft.com/en-us/library/hh831833.aspx
21WINDOWS 8.1 DEPLOYMENT PLANNING
Internet access
WhenusersconnecttotheInternet,theyareattheirgreatestriskofhavingsecurityattacksfrom
malicioususersandsoftware.Windows8.1includesseveralbuilt-infeaturesthathelpprotect
usersduringaccess.YoucanenableandenforcemanyofthesefeaturesbyusingGroupPolicy.
Forexample,youcanuseGroupPolicytoenableWindowsDefenderandWindowsFirewall.These
securityfeaturesareenabledinWindows8.1bydefault.
SpecifysecuritypoliciesthatimplementsafetyfeatureswhenconnectingtotheInternet,where
applicable.Forexample,guardiansofstudentscanusetheFamilySafetyfeaturetorestrictaccess
towebsitesbasedonuserage(suchasrestrictingthetypesofappsthatuserscanviewinand
installfromtheWindowsStore).
Application access
Application-relatedsecurityandprivacyaredividedintocontrolling:
• The installation and running of approved apps only Forinstitution-owneddevices,ensure
thatusersrunonlyapprovedapps.Youcanenforcewhichappscanbeinstalledandrunon
institution-owneddevicesbyusingtechnologiessuchasFamilySafety,AppLocker,andGroup
Policy.Forpersonallyowneddevices,educatefacultymembers,students,andguardianson
howtouseFamilySafetyfeaturestoshowage-appropriatecontentonly.
• Any personal information the apps collect while it is running SomeWindowsStoreapps
cancollectprivateinformationwhiletheappisrunning(suchaslocationoroptionsselected
intheapp).WindowsStoreappsincludetheabilityforuserstooptinorprovideconsentto
collectsuchinformationbydesigntopassWindowsStoreappcertication.Becausetheuser
mustprovideconsent,educateusersontheinformationthatcouldpotentiallybecollected
andtherisksofprovidingtheinformation.Thiswouldbetrueforinstitution-owneddevices
andpersonallyowneddevices.
Device access
Devicesecurityandaccessrepresentoneofthelargestopportunitiesfordataloss,forgotten
passwords,andothersecurity-relatedissues.Helpusersmitigatetherisksofdeviceaccessby
usingWindows8features.Forexample,youcanuseBitLockertopreventcondentialdatabeing
obtainedfromalostorstolendevice.Thisisparticularlyimportantfordevicesthatstorefacultyor
studentinformationonthedevice.
22WINDOWS 8.1 DEPLOYMENT PLANNING
Table 3liststhedeviceaccesssecurityandprivacytechnologiesandthenecessaryinformation
forselectingtheappropriatetechnologiesforyourinstitution.Youcanselectanycombinationof
thesetechnologiestodesignacompletesolution.
TABLE 3 DeviceAccessSecurityandPrivacyTechnologySelection
EFS BitLocKEr AnD
BitLocKEr to Go
PicturE PASSWorD WinDoWS to Go
Encrypts
condential
information
Yes(individualles
andfolders)
Yes(entirexed
orremovabledisk
volumes)
N/A N/A
Reduces the
complexity of
signing on
N/A N/A Yes N/A
Reduces the risk of
information loss
when a device is
lost or stolen
Yes Yes Yes
Yes(ifencrypted
withBitLocker)
Reduces the cost of
replacement when
a device is lost or
stolen
N/A N/A N/A Yes
Infrastructure None None None None
Ownership
scenarios
Personallyor
institution-owned
Personallyor
institution-owned
Personallyor
institution-owned
Institution-owned
Domain join
required
No
No(butrecovery
keyscanbestored
inADDSfor
domain-joined
devices)
No
No,butrequires
Windows8.1
Enterpriseedition
Remote connectivity
Notethefollowingremoteconnectivityappplanningconsiderations:
• Whichusersrequireremoteconnectivitytoresourcesontheinstitution’sintranet?
• Howcanusersaccessintranetresources?
• Whattypesofdevicesrequireremoteconnectivity?