Tag Archives: microsoft

Visual Studio 2013 is released. What’s new?

Microsoft released Visual Studio 2013 yesterday:

VS 2013 can be installed side by side with previous versions of Visual Studio or, if you have a VS 2013 pre-release, it can be installed straight over  top of the pre-release.

I installed over the top of the pre-release and I’m happy to say that this worked without incident. This is how it should be.

image

Oddly, the launch of Visual Studio 2013 is not until November 13th, proving that in Microsoft’s world products can “launch” before, at or after general release.

So what’s new in Visual Studio 2013? Tracking Visual Studio is difficult, because many important features show up as updates and add-ons. After all, at heart Visual Studio is just a shell or platform in which development sit. The Visual Studio LightSwitch HTML client, for example, which made LightSwitch into a strong tool for rapid application development of mobile web apps, appeared as part of Visual Studio 2012 Update 2. Now in Visual Studio 2013 we have LightSwitch support for Cloud Business Apps, though the new project type is shown under Office/SharePoint rather than under LightSwitch:

image

A Cloud Business App is an add-on for SharePoint typically running on Office 365. In the new model SharePoint apps do not really run on SharePoint, but are web apps that integrate with SharePoint. This is great in an Office 365 context, since you can write a web app that is accessible through the Office 365 site and which is aware of the logged-on user; in other words, it uses Azure Active Directory automatically. There’s more on the subject here.

What else is new? Here are some highlights:

  • Better ISO C/C++ compliance in Visual C++
  • Upgraded F# with language tweaks and improved performance
  • .NET Framework 4.5.1 with minor enhancements
  • Support for new Windows 8.1 controls and APIs in Windows Store apps – these are extensive.
  • “Just my code” debugging for C++ and JavaScript, and Edit and Continue for 64-bit .NET apps
  • Graphics diagnostics for apps running remotely
  • Sign into Visual Studio with a Microsoft account. Microsoft pulls developers further into its cloud platform.
  • Windows Azure Mobile Services – build a back end for an app running on Windows, Windows Phone, iOS, Android or web

Does that amount to much? Compared to the changes between Visual Studio 2010 and 2012, no. That is a good thing, since what we have is a refinement of what was already a capable tool, rather than something which gives developers a headache learning new ways to work.

7 types of Windows 8 users and non-users

When I was in Seattle earlier this month I visited the Microsoft Store in Bellevue. I nearly bought a Nokia Lumia 1020, but also observed an enthusiastic salesperson showing off Surface 2 (a pre-launch demo unit) to an older customer. She watched patiently while he showed how it handled pictures, SkyDrive, Office, Email, Facebook and more. At the end she said. “I don’t need any of that. Show me your cheapest laptop.”

image

Yes, it’s tough for Microsoft. The incident got me thinking about computer users today and whether or not they are in the market for Windows 8 (or the forthcoming Windows 8.1).

Here is a light-hearted at some categories of users. And yes, I think I have met all of them. For those that are saying no, what would change their minds?

1. The Apple fan.

Switched to Mac from Windows XP around 2007. Has Mac, iPhone, iPad. So much easier, no anti-virus nags, boots quicker, less annoying, always works smoothly. Occasionally runs a Windows app on Parallels but nothing non-nuclear would persuade them to switch back.

Buying Windows 8? No.

2. The Enterprise admin.

In latter stages of migration from Windows XP to Windows 7. Still a few XP machines running awkward apps or run by awkward people. Last holdouts should be gone by year end. Job done, won’t even think about another migration for 3-5 years. Next focus is on BYOD (Bring your own device); will be mostly iPhones and iPads with the occasional Android or Windows 8 tablet.

Buying Windows 8? Mostly no.

3. The older Windows user

Son thinks a Mac would be better, but Windows works fine, is well understood, and does all that is needed. No desire to upgrade but when PC conks out will look for the most familiar looking machine at a good price. Would prefer Windows 7 but may be forced into Windows 8 if those are the only machines on offer.

Buying Windows 8? Maybe reluctantly.

4. The PC guy

This is the guy who understands PCs back to front. Never saw the point of Macs, overpriced, fewer apps, and little different in functionality. First thing to do with a new PC is either spend 3 hours removing all the crapware, or reinstall Windows from scratch. The Windows 8 user interface took some adjustment at first but fine with it now, likes the slightly better performance, and even uses a few Metro apps on the Surface Pro tablet.

Buying Windows 8? Yes, best Windows yet.

5. The tablet family

Used to update the family PC every few years, but mum got an iPad, son got an Android tablet, then dad went Android too, and now they spend so much time doing email, games, web browsing, YouTube, Facebook and BBC iPlayer on the tablets that the PC gets little use. It’s still handy for household accounts but it won’t be replaced unless it breaks.

Buying Windows 8? Not soon, and maybe not ever.

6. The tried it once never again person

It was embarrassing. Used Windows for years, then a friend brought over a Windows 8 laptop. Clicked on desktop, but with no Start button how do you run anything? Clicked around, right-clicked, pressed ESC, pressed Ctrl-Alt-Del, but nothing doing. Friend was laughing. Now the sight of Windows 8 evokes a chill shudder. Never, just never.

Buying Windows 8? No way.

7. The “Make it like 7” person

Windows 8? No problem, it’s just like 7 really. Installed Start8, got the Start menu back, set it to boot to desktop, set file associations for PDF and images to desktop apps, and never sees the Metro environment.

Buying Windows 8? Kind-of, but will never run a Metro app.

Usability: Microsoft’s big weakness

The iPhone, or maybe the iPod, was the beginning of the era of usability. Make something nice to use, reasoned Apple, and users will come flocking.

After the iPhone came the iPad; and then Android which while lacking the polish of iOS, mostly has the same characteristics of appliance rather than computer in its user interface.

What about Microsoft? It has learned to some extent. Windows Phone is a user-friendly operating system. The touch interface in Windows 8, although a shock to existing Windows users, shows obvious effort towards usability and sometimes succeeds. Navigating the weather app, for example, is a pleasure.

There are times though when Microsoft seems to have learned nothing. Take the new SkyDrive integration in Windows 8.1 for example. It is foundational in Microsoft’s effort to wrest Windows into being a cloud-centric operating system, where you could lose your device, buy a new one, log in, and find all your stuff. I’ve posted about its progress here.

But then you are on a train, say, with a poor internet connection, and you double-click a file in SkyDrive that has not been downloaded to your PC. This is the dialog you see (at least, it is the one I just saw):

image

There is so much wrong with this dialog that I don’t know where to start. But I will have a go.

First, I doubt the error is really unexpected. If my internet connection is poor, problems downloading stuff from SkyDrive are expected, not unexpected. You would think that the client could figure out, “It looks like I have a poor connection to SkyDrive” and inform the user accordingly.

Second, the error number. The dialog invites me to search for help using this number; however to do so I would have to copy it manually as it is unselectable. The number of course is in hexadecimal, so there is a high chance of copying an O instead of a zero as the difference is not obvious other than to programmers. Nor is it clear where I should search. Should I bang the number into Bing and hope for the best? Such searches can be fruitful, but they can also go badly wrong when you hit sites that tell you to download their utility to clean your registry, or some such nonsense.

Third, there is space for a human-understandable description of the error, but it is says “No error description available”. Lazy programming somewhere. Maybe in a code base the size of Windows it is too much to expect helpful messages for every error but this is not something users should normally see.

Fourth, there are three choices: Try Again, Skip and Cancel. Bearing in mind that I double-clicked only one document, what is the difference between Skip and Cancel?

Fifth, there is a More details button but it is disabled. Why, if no more details are available, does this More details button appear at all? Though I’d suggest that Error 0x80040A41 is a great candidate for “More details” rather than being something non-technical users are expected to make sense of.

What should happen? First, SkyDrive and/or its client should work better. This is a critical feature; but users are complaining (yes, I found this by searching for the error code) and it seems that problems persist in Windows 8.1 RTM. Microsoft has been working on file sync for decades, yet upstarts like Dropbox work more smoothly.

Second, when bad things happen, I am all in favour of plain English. I don’t see any reason ever to confront users with error numbers in hex. Put it in a technical details option by all means. In this particular case, why not something like, “Windows is having problems downloading from SkyDrive. You may have a poor internet connection; please try again later, and if the problem persists, contact support.”

Getting this right is not easy; but for as long as ordinary users see this kind of dialog in day to day use of Windows, the flight to iPad and Android will continue.

Update: the error fixed itself when I found a better connection

Getting up and running with Workplace Join

A key part of Microsoft’s strategy for supporting tablets and smartphones in the enterprise is Workplace Join, which lets devices register with Active Directory:

When you join your personal device to your workplace, it becomes a known device and will provide seamless second factor authentication and single-sign-on to workplace resources and applications. When a device is Workplace-Joined, attributes of the device can be retrieved from the directory to drive conditional access for the purposes of authorizing issuance of security tokens for applications.

Devices currently supported are Windows 8.1 (RT or x86) and Apple iOS, with Android in preparation. It is a kind of lite version of domain join, enabling single sign-on but not group policy (centralised control of device settings). In order to control device settings, you can use ActiveSync (limited but includes password requirements and remote wipe) or device management through the cloud-based InTune.

I set myself the task of implementing Workplace Join on my test network, mainly using the guide here. It was somewhat arduous. Here are a few points to note.

Workplace Join is also called Device Registration and is a feature of Active Directory in Windows Server 2012 R2. It depends on Active Directory Federation Services (ADFS).

I wasted some time juggling with certificates and Service Principal Names (SPNs). On my test network I have Active Directory, Certificate Server and ADFS on the same virtual machine, which is not recommended. Here are some things to note.

You need a Server Authentication certificate which includes a Subject Name and two Subject Alternative Names, one of which is enterpriseregistration.yourdomain.com In order to get this out of Certificate Server I ended up copying and modifying a template to allow this additional data to be entered when the certificate is requested. I did not need to purchase any certificates; it all works as long as the Enterprise CA (Certification Authority) certificate is trusted by the device.

IIS will need this certificate as the default web site must accept secure connections to enterpriseregistration.yourdomain.com.

I got into difficulty when configuring ADFS. Initially I used the same name for the Federation Service Name as the computer name. This in turn caused a conflict with the registration of an SPN for the ADFS service account, probably because I have too much installed on one box. SPNs are used by Kerberos for secure communications and each SPN must be unique. The solution was to remove ADFS and re-install, using a different Federation Service Name. Then I modified DNS so that all three names – computer name, Federation Service Name, and enterpriseregistration – resolve to the same box.

I have not published my ADFS to the internet so mine is only an intranet solution for now.

Once all this was resolved I was able to run the PowerShell scripts to enable the Device Registration Service, and to check Enable device authentication in ADFS:

image

Of course my first efforts at actually using Workplace Join on a device (I used Surface RT and Surface Pro) failed with a generic error.

image

Confirm you are using the correct sign-in info, and that your workplace uses this feature. Also, the connection to your workplace might not be working right now. Please wait and try again.

The first thing to check is that your device can access the device registration service over HTTPs. Open a browser and go to this URL:

https://enterpriseregistration.[yourdomain.com]/EnrollmentServer/Contract?api-version=1.0

If this does not resolve, or returns a certificate error, you need to fix this before registration will work. Possible reasons:

  • Your device does not trust the certificate
  • IIS has the wrong certificate
  • A necessary service is not running on the server (check ADFS and the Device Registration Service as well as IIS)
  • The device cannot access the Certificate Revocation List for your domain

There is also an event log for workplace join, buried in the Applications and Services section, even on Windows RT.

Once fixed, I was successful and saw my devices show up in Active Directory under Registered Devices.

image

Sunspider JavaScript Benchmark on 4 models of Microsoft Surface

Today I got my first sight of Microsoft’s new models of Surface, its Windows tablet, on display at the Microsoft Store in Bellevue.

image 

I ran the Sunspider JavaScript benchmark on the new models, and then on the old ones for comparison.

  • Surface RT 1.0: 922ms
  • Surface 2.0 (RT): 397ms
  • Surface Pro: 127ms
  • Surface Pro 2.: 114ms

No surprises; but what this confirms is that Surface 2.0 RT, which has an NVIDIA Tegra 4 chipset, is substantially faster than the earlier Tegra 3 model; whereas Surface Pro which has an updated Intel Core i5 processor is only a little faster on this particular test.

Microsoft is attempting to continue selling Surface RT alongside Surface 2.0 RT, at $349 vs $449 for the 32GB model. However the new one is a better buy and I imagine the price of the earlier model will fall further, given that Microsoft appears still to have substantial stocks.

Windows 8.1 and cloud-centric computing

If your iPad breaks or gets stolen, it’s bad but not that bad. The chances are that there is no data on the iPad that is not copied elsewhere, especially if you let Apple’s iCloud do its default thing and copy everything you create. Get a new iPad, sign in, and you can carry on where you left off; the apps are there, the data is there too, even if you do not actually have a backup of the device itself.

Google’s Chromebook goes even further in this direction. When you sign into the device you sign into Google and all your data is there.

This kind of freedom from worry about losing apps or data stored on the device seems to be Microsoft’s goal with Windows as well, though it is more difficult because historically applications have complex local installs, sometimes protected by activation tied to the PC itself, and data is stored locally in your user folders – Documents, Pictures, Music and so on – or in some cases elsewhere, depending on how well behaved the application is. In order to defend against data loss if the PC is lost or damaged, you have to keep regular backups, or make a conscious effort not to store data locally.

Windows 8.1 includes a significant change. It is optional, but the default is that documents save to SkyDrive (note that the name will change soon) by default.

image

This is in addition to synchronisation of settings, passwords and application data. Again, SkyDrive is where this data gets stored. You can see and control what is synchronised in Charms – PC Settings – SkyDrive -  Sync Settings:

image

The list is extensive and includes web browser favourites (provided you use Internet Explorer) and “settings and purchases” within apps. Note that apps in this context means new-style Windows Store apps, not desktop applications. Separately, there is a Camera Roll setting that syncs images and optionally videos from the Camera Roll folder in your  Pictures folder.

How close then is Window 8.1 to a cloud-centric experience, where you could thrown your machine in the bin, buy another one, sign in and carry on where you left off?

It is getting there, but in practice there are plenty of snags and oddities. The big one is desktop apps, of course, which do not participate in this synchronisation other than via SkyDrive if you save documents there. You will have to reinstall the applications as well as reconfigure them. That said, certain desktop applications now have a subscription model. Two big examples are Microsoft Office, if you buy via an Office 365 subscription, and Adobe’s Creative Cloud which includes Photoshop, Dreamweaver, Audition and so on. Using cloud-aware applications such as these helps, but it is not seamless. For example, in Office 2013 I have to reconfigure the Quick Access Toolbar and copy my custom templates manually to a new machine.

New-style apps do roam to a new machine and you can now use them on up to 81 different machines, which should be enough for anyone. Note though that your apps, which are listed when you sign into a new machine with a Microsoft account , are not actually installed until you run them for the first time. Not a problem is you are on the internet, but worth knowing before you catch that flight. In the following example, only two of the apps are actually installed:

image

Microsoft takes a similar approach with SkyDrive documents. The feature called SkyDrive “smart files”, described here, means that documents are by default only available online. I can see this catching people out, especially with pictures, for which a thumbnail shows even when the actual picture has not yet been downloaded. Here are some pictures I took at Microsoft Build in June; they are on SkyDrive but although they look as if they are on my PC a message in the status bar says “Available online only.”

image

A nice feature in terms of seamlessly connecting to cloud storage without filling your local hard drive (or often, small SSD drive), provided you understand it. Of course, you can mark a file or folder to be available offline if you choose, in which case it is downloaded.

Some things are confusing. If you have a domain-joined machine then passwords do not sync, which makes sense for security, but also raises the question of what all this consumer SkyDrive stuff is doing on a domain-joined machine anyway? Of course there are other ways of doing something similar in domain environments:

  • Settings determined by Group Policy
  • Default document location set to corporate shared folder
  • Roaming profiles

The odd thing though is that you can link a Microsoft account (SkyDrive, App Store account) to a domain account and you then end up with a mixture of consumer and corporate features which work in different ways. It would be tempting simply to block the use of Microsoft accounts completely – which you can do with group policy – especially if you are concerned about sensitive corporate documents arriving on consumer cloud services and mobile devices through the magic of sync.

It is also confusing that Office 365 users cannot use SharePoint in Office 365 to sync settings.

I also feel that the user interface in Windows 8.1 needs some work in this area. Here are some things I find odd:

Applications like Paint and Notepad use a principle of “default to where you last saved.” This means that even if you set SkyDrive as the default document location, if you save once to the documents or pictures folder on the PC, it will default to that local destination next time you use it.

Since both SkyDrive and the local PC have a folder called Documents, it would be easy not to notice.

Office 2013 is even more confusing. I have Office 365, so when I hit save in Word I get offered Office 365 SharePoint, SkyDrive, “Other web locations” which includes an on-premise SharePoint, and Computer. Oddly, if I hit Computer, the default location is SkyDrive:

image 

Much of this confusion is a legacy problem as Microsoft attempts to transition Windows to become a cloud-centric OS, but it could be better done. I would suggest clear naming to help users know whether a save location is local or cloud. Most of all, I would like to see consistency between consumer and corporate deployments so that a domain-joined PC can have the same options that work in the same way, except that data is stored to a corporate location.

How to change a network from public to private in Windows 8.1

So I arrive at a hotel and turn on wi-fi and connect. That little dialog comes up, Do you want to find PCs devices and content on this network? The correct answer in a hotel is No, but in my jet-lagged stupor I click Yes. Oops.

image

No problem, just change it, right? Hmm. Go to the Network and Sharing center and it is not obvious how to change the profile of a network. It tells me that the network is Private, but the setting seems to be read-only:

image

Not much of a Network and Sharing Center if you cannot change this setting; but never mind. How about just “forgetting” the network so that the dialog reappears?

I took a look here. Press and hold a network in the list to forget it. Unfortunately this does not work in Windows 8.1, and apparently that is by design.

OK, so try the command line:

netsh wlan delete profile name="ProfileName"

The profile name in this context is the wi-fi SSID. Seems to work; but when I reconnect the profile dialog does not appear. Apparently the network is not fully “forgotten”.

There is a way. Regedit, and go to:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles

and find the GUID that matches your network, in my case Network 11.

image

Delete this profile. Do the command line thing as well to delete the profile. Now the network really is forgotten. Reconnect, the profile dialog comes up again, and now you can choose Public.

There must be an easier way though. Anyone know the user-friendly way to fix things when you accidentally select the wrong profile for a connection?

Update

It seems that this is meant to be set in Charms – PC Settings – Network. In fact, you can do it for wired connections. Here is what I get if I tap a wired connection, which I presume changes the profile:

image

However, if I tap a wireless connection I get this:

image

This looks like a bug to me, either with my 8.1 install or more generally.

Microsoft acquires Nokia’s device business: a risky move for Windows Phone

Microsoft is to acquire Nokia’s device business:

Microsoft Corporation and Nokia Corporation today announced that the Boards of Directors for both companies have decided to enter into a transaction whereby Microsoft will purchase substantially all of Nokia’s Devices & Services business, license Nokia’s patents, and license and use Nokia’s mapping services.

Nokia’s Stephen Elop is no longer CEO:

Stephen Elop, who following today’s announcement is stepping aside as Nokia President and CEO to become Nokia Executive Vice President of Devices & Services

The plan is that Elop, together with other executives from his team, will move to Microsoft. This is a circle completed for Elop, who was formerly in charge of Microsoft Office.

Nokia is retaining its patent portfolio, but licensing its patents to Microsoft for a 10 year term. 

Microsoft is acquiring approximately half of Nokia’s business overall, but all of its phones including the low end Asha range.

What are the implications for Windows Phone? One the face of it, the deal makes some sense. Nokia was the only Windows Phone OEM making real efforts to support and establish the platform, and has a large market share within the Windows Phone market. Although Windows Phone is struggling versus the iOS and Android giants, to Nokia’s credit it has established itself as a firm number three, ahead of Blackberry, and done some impressive work especially with the camera element.

Nokia has also managed to push out low-end but still capable Windows Phones at keen prices, and it is this more than anything else that has won it increasing market share. Recently, Kantar published a report showing solid gains for the platform:

Windows Phone, driven largely by lower priced Nokia smartphones such as the Lumia 520, now represents around one in 10 smartphone sales in Britain, France, Germany and Mexico. For the first time the platform has claimed the number two spot in a major world market, taking 11.6% of sales in Mexico.

What will be the effect of the acquisition on the Windows Phone platform and ecosystem? On the plus side, it gives Elop’s team access to more funds and removes any uncertainty surrounding Nokia’s future. If Microsoft keeps the proven team and its design and manufacturing expertise together, this could work.

There are obvious risks though. Without Nokia, Microsoft did a poor job of marketing Windows Phone, and while some of that is down to half-hearted hardware partners, Microsoft was also to blame for poor execution. Now that Nokia is Microsoft, there is a danger that its effectiveness will slip back.

Another question is how this will impact the other Windows Phone vendors, such at HTC and Samsung. Nokia already seemed to be a favoured partner, so perhaps little will change, but it seems unlikely that this will energise the other partners and it may have the opposite effect. The Windows OEMs hate Microsoft’s efforts with Surface (even though it was their own failings that forced Microsoft into the venture) and the phone vendors may well feel the same about Micro-Nok.

There is now no non-Microsoft smartphone vendor for whom Windows Phone is anything but a small sideshow. That could change, but it is not a sign of health.

Whether Nokia was right to embrace Windows Phone rather than Android is an open question; and perhaps it should not have abandoned its Meego (Linux) efforts, but given that it did both, it seems to me that Elop has performed well and was successfully growing the platform, albeit from a small base. Will he be allowed to continue that work at Microsoft, as well as gaining greater control over the software side of Windows Phone whose slow pace of development, it is rumoured, was a source of frustration to Nokia?

Alternatively, history tells that Microsoft can suffocate its acquisitions (remember Danger?).

Personally I like Windows Phone. When I looked at a Samsung Android recently, I was struck by how disorganised and confusing an Android smartphone can be, though impressed by its capability. Windows Phone is decent and I hope it carves out a reasonable market share.

The risks, though, are obvious.

Hands on with Microsoft’s Azure Cloud Rights Management: not ready yet

If you could describe the perfect document security system, it might go something like this. “I’d like to share this document with X, Y, and Z, but I’d like control over whether they can modify it, I’d like to forbid them to share it with anyone else, and I’d like to be able to destroy their copy at a time I specify”.

This is pretty much what Microsoft’s new Azure Rights Management system promises, kind-of:

ITPros have the flexibility in their choice of storage locale for their data and Security Officers have the flexibility of maintaining policies across these various storage classes. It can be kept on premise, placed in an business cloud data store such as SharePoint, or it can placed pretty much anywhere and remain safe (e.g. thumb drive, personal consumer-grade cloud drives).

says the blog post.

There is a crucial distinction to be made though. Does Rights Management truly enforce document security, so that it cannot be bypassed without deep hacking; or is it more of an aide-memoire, helping users to do the right thing but not really enforcing it?

I tried the preview of Azure Rights Management, available here. Currently it seems more the latter, rather than any sort of deep protection, but see what you think. It is in preview, and a number of features are missing, so expect improvements.

I signed up and installed the software into my Windows 8 PC.

image

The way this works is that “enlightened” applications (currently Microsoft Office and Foxit PDF, though even they are not fully enlightened as far as I can tell) get enhancements to their user interface so you can protect documents. You can also protect *any* document by right-click in Explorer:

image

I typed a document in Word and hit Share Protected in the ribbon. Unfortunately I immediately got an error, that the network location cannot be reached:

image

I contacted the team about this, who asked for the log file and then gave me a quick response. The reason for the error was that Rights Management was looking for a server on my network that I sent to the skip long ago.

Many years ago I must have tried Microsoft IRM (Information Rights Management) though I barely remember. The new software was finding the old information in my Active Directory, and not trying to contact Azure at all.

This is unlikely to be a common problem, but illustrates that Microsoft is extending its existing rights management system, not creating a new one.

With that fixed, I was able to protect and share a document. This is the dialog:

image

It is not a Word dialog, but rather part of the Rights Management application that you install. You get the same dialog if you right-click any file in Explorer and choose Share Protected.

I entered a Gmail email address and sent the protected document, which was now wrapped in a file with a .pfile (Protected File) extension.

Next, I got my Gmail on another machine.

First, I tried to open the file on Android. Unfortunately only x86 Windows is supported at the moment:

image

There is an SDK for Android, but that is all.

I tried again on a Windows machine. Here is the email:

image

There is also note in the email:

[Note: This Preview build has some limitations at this time. For example, sharing protected files with users external to your organization will result in access control without additional usage restrictions. Learn More about the Preview]

I was about to discover some more of these limitations. I attempted to sign up using the Gmail address. Registration involves solving a vile CAPTCHA

image

but got this message:

image

In other words, you cannot yet use the service with Gmail addresses. I tried it with a Hotmail address; but Microsoft is being even-handed; that did not work either.

Next, I tried another email address at a different, private email domain (yes, I have lots of email addresses). No go:

image

The message said that the address I used was from an organisation that has Office 365 (this is correct). It then remarked, bewilderingly:

If you have an account you can view protected files. If you don’t have an Office 365 account yet, we’ll soon add support…

This email address does have an Office 365 account. I am not sure what the message means; whether it means the Office 365 account needs to sign up for rights management at £2 per user per month, or what, but it was clearly not suitable for my test.

I tried yet another email address that is not in any way linked to Office 365 and I was up and running. Of course I had to resend the protected file, otherwise this message appears:

image

Incidentally, I think the UI for this dialog is wrong. It is not an error, it is working as designed, so it should not be titled “error”. I see little mistakes like this frequently and they do contribute to user frustration.

Finally, I received a document to an enabled email address and was able to open it:

image

For some reason, the packaging results in a document called “Azure IRM docx.docx” which is odd, but never mind.

My question though: to what extent is this document protected? I took the screen grab using the Snipping Tool and pasted it into my blog for all to read, for example. The clipboard also works:

image

That said, the plan is for tighter protection to be offered in due course, at lease in “enlightened” applications. The problem with the preview is that if you share to someone in a different email domain, you are forced to give full access. Note the warning in the dialog:

image

Inherently though, the client application has to have decrypted access to the file in order to open it. All the rights management service does, really, is to decrypt the file for users logged into the Azure system and identified by their email address. What happens after that is a matter of implementation.

The consequences of documents getting into the wrong hands are a hot topic today, after Wikileaks et al. Is Microsoft’s IRM a solution?

Making this Azure-based and open to any recipient (once the limitation on “public” email addresses is lifted”) makes sense to me. However I note the following:

  • As currently implemented, this provides limited security. It does encrypt the document, so an intercepted email cannot easily be read, but once opened by the recipient, anything could happen.
  • The usability of the preview is horrid. Do you really want your trusted recipient to struggle with a CAPTCHA?
  • Support beyond Windows is essential, and I am surprised that this even went into preview without it.

I should add that I am sceptical whether this can ever work. Would it not be easier, and just as effective (or ineffective), simply to have data on a web site with secure log-in? The idea of securely emailing documents to external recipients is great, but it seems to add immense complexity for little added value. I may be missing something here and would welcome comments.

 

 

 

 

 

 

 

 

 

 

had to sign in twice since I didn’t check “Remember password!"

image

If you try recursion, it will package the already packaged file.

Microsoft completes Windows 8.1, it says, but developers are unable to test their apps

Microsoft has released Windows 8.1 to its hardware partners according to VP Antoine Leblond; but developers will be unable to test whether or not their apps work on the updated operating system until it is also in the hands of users:

While our partners are preparing these exciting new devices we will continue to work closely with them as we put the finishing touches on Windows 8.1 to ensure a quality experience at general availability on October 18th. This is the date when Windows 8.1 will be broadly available for commercial customers with or without volume licensing agreements, our broad partner ecosystem, subscribers to MSDN and TechNet, as well as consumers.

One reason for subscribing to MSDN is to get early access to new versions of Windows for test and development, so this is a surprising and disappointing move.

We pay thousands for MSDN access so we can test our software/apps properly, early testing, before GA, is an important part of that process! We don’t care about a couple of bugs in your OS, we about bug in our software. Most of us actually want to support Windows 8.1, a lot of us want to get apps ready for the awesome 8.1 features, but we can’t properly do that unless we get the RTM bits before the public gets the Windows 8.1 update!

says one comment to Leblond’s post.

It is hard to make sense of Microsoft’s reasoning here, though Microsoft’s Brandon LeBlanc comments that despite the RTM (Release to Manufacturing), Windows 8.1 is not altogether finished:

We are continuing to put the finishing touches on Windows 8.1 to ensure a quality experience at general availability

he says.

Windows 8 needs more high quality apps in order to win users over to its new tablet-friendly user interface, so it is unfortunate that Microsoft is not doing more to help developers support it.