Microsoft pauses free Windows 365 cloud PC trials after ‘significant demand’
theverge.com
theverge.com
Why is it so popular? I can't understand the economics of it. Can someone explain? Why would I pay ~$10k over 5 years for something that's similar to the laptop I'm typing on which costed me $700 used?
I know it's for businesses, but even then, does it come with tooling or something that makes management easier? What justifies an annual cost that is close to the lifetime cost of a physical machine?
You still need a physical machine to access "the cloud", so don't you still have all the expensive problems related to managing a fleet of PCs, but now you have to do it x2?
Is data security so important that some companies are willing to pay 5x hardware costs and 2x maintenance costs for it?
I really don't get it. When I looked at the cost of using Azure for failover on a single server, the conclusion I came to is that it only made sense to run something short term while new hardware was shipped in. Who the heck is buying these VMs that cost 5x real hardware?
On the books this can be a boon for the bean counters.
Yes. Also, maintaining a fleet of hardware is a resource suck. Being able to provision everyone with something like this lets them use their personal hardware without much compromised in the way of security. (It should also make onboarding much smoother.)
How do they protect against an attacker compromising this client, waiting until the employee is asleep or away for a few minutes, then using the employee's session to compromise the remote machine?
Even if session establishment requires 2FA, the attacker could keep the session alive after the user attempts to close it.
However I think an automated attack would be difficult, especially if the VD sent its data to the client as a video stream, and only recieved keyboard and mouse inputs. Now maybe there's some fancy computer vision that could handle this (and all without the employee noticing)...
It's definitely going to keep a lot of the commodity malware out, but it's only going to stay secure until attackers start targeting it. And the risks from "inside" the machine (user downloads and runs something bad) don't go away, although the company gets a bit more control over the network (could also be done with an always-on VPN).
Try to buy a keyboard though and forget it.
- Fill out some form to get one of their salespeople to contact me.
- Find a time to meet with them that works for both of us - may be a week or more out.
- Talk to the salesperson for half an hour.
- Get a quote emailed to me a day or two later.
- Talk it over with my boss. This is fairly low overhead, but he's a busy guy so it may take a few days. He'll want to know the basics, if I've considered any alternatives, what we'll use it for, etc.
- Sign the document - hopefully my boss/finance don't request any significant changes.
- Start using the service once they get the contract and provision stuff for us.
Usually we are looking at a few weeks lag time, and maybe half a day of my time taking care of all of this. If it is something available on AWS, here is what I have to do:
- Click a button, maybe fill out a form to configure it.
- Start using the service a few minutes later.
Even if it costs 2x the other service, it is unlikely that anyone is going to notice or care about the small increase in our AWS bill, and if they do saying "oh yeah, I added xyz service" is not going to raise any objections.
It is kind of funny to think about the difference, but it comes down to the fact that it is genuinely less friction in the AWS case, coupled with a bit of psychology on our end I guess.
Shenanigans like that shouldn't be necessary just to get the stuff you need, but big corporations are so dysfunctional sometimes.
Anyways, final approver should be somewhere between you and the CTO.
Right. This has already been tried in the "game streaming" business. There have been multiple services where you rent a PC in "the cloud" by the hour, or for some number of hours per month. Either they cost too much, and fail for lack of customers, or they are underpriced as a loss leader, and get shut down after losing money. Google Stadia and NVidia Cloud Gaming are currently live, but Stadia is likely to join Google's list of discontinued products, and NVidia's offering involves being kicked off if you stay connected too long.
By the same logic, you could say that game streaming is like a search engine, because some of the companies that do the latter are also doing the former.
The idea of provisioning remote cloud VMs is far older than Stadia or Xbox Cloud anyway.
Your point about game streaming being like a search engine is nonsensical.
They may be, or may not be, but your logic to say that they are similar isn’t right (otherwise other product lines must be similar by extension).
I am not talking about Microsoft and Google. I know a guy who runs one of these companies: they offer VMs for gaming, they offer VMs for offices, the machines are set up identically.
8 hours, which is a pretty decent gaming session. You can reconnect just afterwards anyways.
> but Stadia is likely to join Google's list of discontinued products
Highly unlikely, they're spending tens of millions to get EA and Ubisoft's catalogues on Stadia.
In any case, cloud gaming works, sells, and is very useful for some subset of users, even more so with the ongoing global chip shortage. I have both Geforce Now and Stadia and I'm very happy with them. Playing on my laptop and TV ( with a Chromecast) is great. Playing from my phone in a hotel room is a fun experience. Stadia even makes financial sense, because there's a free version ( at 1080p/30fps), you only need to buy the games ( which you would anyways regardless of the platform), saving you hundreds of (insert currency) in the process. The paid one is 10 eur/usd/month for better quality and some free games. And if you're the type of person that wants 4K 120Hz 60fps, this isn't for you and isn't the point.
Loon also cost tens of millions, made no sense, and was eventually canceled.
Like I said, it's used, so yes. I think the new cost is right in your $2500-$3000 range for a new version.
Being able to give them credentials to a machine that's ready to go is pretty huge.
Standard users don’t get local root/admin in a corporate environment since the Win2k days, and seem to have few issues in comparison.
Many devs seem perfectly willing to pull any random executable off the internet and run it without inspection or concern. Because they “know what they are doing”, right?
This offering makes perfect sense to replace those dumb dell machines equipped with 4gb ram and a core i3 with even dumber machine and slash the local it team.
Think of thin clients, all over again.
Think of call centers.
Think of receptionists, or bank clerks that all they do is use internal web-based software, and print a pdf file.
No more hardware maintenance, just throw away the whole thing (the dumb terminal) and replace it with a new one, we'll send it in for repair later.
Heck, you could even netboot the raspberry pi and save on SD cards too.
It's a security/usability trade off for me.
Installing an Ethernet LAN network is the best investment for anyone who works from home.
Wi-fi really sucks in urban areas and soon even in rural areas because of the IoT crap.
And I could've done the wiring for 2/3 of the price, btw.
Also, if GP had laid cat-6 cables maybe they might upgrade switch and clients to 10gbit/sec Ethernet.
Also Ethernet is definitely useful for latency. Having sub 1ms latency on a wifi network is very very difficult, and definitely not going to happen with 5 routers.
I work on a lot of systems with public and private facing endpoints and so I have a remote session running on a machine outside our network as well.
It works pretty well.
If it takes you 2-3 weeks to onboard ANYONE please realize that your IT processes are complete, unmitigated garbage. Paying Microsoft for some Windows VMs through the nose isn't going to change anything about that.
I think the most extreme example of slow process I saw was an organization where central IT wanted to charge $20k and take two months to quote for a project.
In that kind of environment things like this with opex pricing that can be assigned to a project's budget and fast spin up are a much better option :)
So I can see internal pricing being an issue as well. Internal IT charges for quotes. MSFT just quotes.
This happened at a prior company as well. IBM was routinely hired over our internal team as they were cheaper.
At a prior company, one of the only reasons we adopted anything SaaS was that IT didn't have to know it existed.
I'm a security person. I often work with my customers' central IT. I'm not going to have an opinion or judge you, but consider:
You're giving people nightmares. I've seen it go very wrong (front-page news wrong). And then the threads commenting on "how incompetent can they be, blabla". I've worked with the people stressed, sad and disappointed that they got pwned because of shadow IT. It's a ticking time bomb.
The cloud wont save you from shadow IT's insecurities. In two years, when you switch to another SAAS provider, or the domain changes, and the enterprise app is left in your azure subscription, and the baddies notice... Then you'll call me or someone like me, and I can earn my paycheck :)
In the former case there was high turnover (replace the team in 1.5 years) and in the latter cases there was high turnover coupled with a problem more than a month away not being considered a problem. So in the former knowledge poured out the door and in the latter knowledge poured out the door and nobody had an interest in anything beyond the quarter, so you do what gets you to the next review cycle.
Basically in both cases the bomb does not matter as you either probably won't be there when it goes off or it doesn't matter as you miss your quarterly goal instead.
We need software to do X.
Call IT, they give you software that sort of does part of X, but it's some enterprise garbage where you quit your job if you have to use it.
Call IT and tell them that's not a good solution. We have this other realistic solution instead.
IT, not wanting to be bothered, laughs and hangs up the phone. Sometimes they'll throw in an excuse that everyone knows doesn't make any sense.
The workers that need to do their job pay for an actually working solution out of other funds (or use their personal software).
Things go wrong and they call you. It's the ineffectiveness of IT to help people get their work done that's the source of the problem.
The way I read shadow IT is as the requirements analysis central IT hasn't done. People aren't taking on all of that extra expense because they want two jobs, they're doing it because central IT is making it hard to do their jobs. When security policies conflict with productivity, it has a direct cost from inefficiency but often a greater one by training people to think of central IT as an obstacle to be bypassed rather than an ally. That inevitably causes other problems and takes a considerable amount of work to improve.
Who cares about front-page news wrong lol. Equifax was front-page news wrong, and there were 0 actual consequences for people in it.
I'm sure that breach was expensive to Equifax internally, but as you say 0 external consequences mean, what company will change their ways...?
If you put someone in business into the position of choosing between getting their job done/making money and adhering to a set of IT/Security rules, I can tell you which one they'll take :)
How do you avoid this? Well it's not easy and it's not cheap. The most important part is ensuring that IT isn't treated like an expense, but an enabler. then you work with your business teams to make sure they have the services they need to get the job done, as safely as possible.
Security teams shouldn't be blockers, but advisors. for this to work, it needs to be acknowledged that the business leaders own the risks ofc.
That's massively easier to write than do, but from what I've seen of various companies, it's pretty much the only way to have a chance of doing things without huge amounts of shadow IT.
Hence IT department has to charge everything it does, swamping everyone involved - business and IT both - in bullshit paperwork, taking time from everyone. Like a finance version of fighting entropy, you can have everything perfectly neatly ordered but it takes effort.
Then someone in IT gets sick of hearing bullshit hopes and dreams ideas from business; "Ok, but what if cereal box toys were spruced up with crypto? Go cost it up will ya?"
And so IT swings the financial ban hammer with $20000 quotes. Bullshit begets bullshit.
There will be a "who you know" club of people from business and IT who can skip the bullshit, not fill out the financial paperwork, meet over coffee or lunch and hash out ideas. If this club does not exist, woe betide the company.
At a former workplace, we got our own internet connection to not have to deal with IT. We got our own computers for that connection. We hired outside contractors instead of using internal people because IT was a hassle to deal with.
We spent tons and tons of money to only have to deal with accounting and not coordinate with IT.
You built a better IT. Shouldn't they replace your existing legacy IT dept?
Seriously, IT shouldn't impede dev teams.
Now if they can simplify this a bit into the cloud, the key for business is to DOWNSKILL this so basically an office manager can do it, then you are golden. If they can even save ONE it salary - amazing. And if users can self service a bit more - also amazing.
The rampant dysfunction in large organizations never ceases to amaze me.
It can make it a little awkward when you finally work for a client who knows what they're doing and you do "8 weeks" of work in 5 days, but that's rare.
Not really any different than when you're an FTE and you're dependent on external factors to get your work done.
I want to redirect this to a certain authority in The Netherlands, but I might get shot. It takes more than month to onboard and even then, you still need to do something extra to get certain rights.
That sounds as if the person dealing with it would be completely incapable of replacing a failing dev. system in a timely manner. Keep a few replacement systems ready and your IT has all the time in the world to deal with those issues without blocking anything important.
I can just imagine the people responsible for that mess dealing with cloud services: I am sorry but we used up all the cloud licenses management signed of on, we will push for more licenses on the next quarterly budget meeting until then have these leftover sheets of paper and this dried out pen from our office supplies.
https://www.microsoft.com/en-us/microsoft-365/business/compa...
But mainly, companies aren't doing what you're doing: looking at the five-year cost. They don't care what it costs over five years, or often even over one year. This quarter, the cost for that beast is $474. Can you deliver an 8-CPU PC with 32GB of RAM for $474? Today? Then the MS offering is better.
Also, when you lay off an employee, you get to stop paying for their Windows license, instead of it being a sunk cost.
There's definitely a reason they're targeting companies first. The economics make so much more sense in that world.
If you're willing to pay $10k over 5 years for a $2k PC, wouldn't there be a ton of financing companies willing to convert the capital expenditure to an operating expenditure for that? Where else can you make 80% annual returns on a capital investment?
Actually the economics still does not make any sense in that world, but some people in some companies count things (only) using such rituals that they think it does. Which is, obviously, all that matters.
I'd need more info on the service, but I'd imagine this is very cost competitive. As to "why?" - because for things like HIPPA data, I'd MUCH rather have my doctors/IT staff logging into a remote desktop session that I can lock down so if their laptop gets stolen from their car I don't have to worry about whether or not some day someone will be able to crack drive level encryption. Or worry that an employee didn't have drive level encryption for some reason. Same for financial institutions/etc.
Furthermore a doctor or insert staff can connect from home, and I don't have to worry about whether or not they properly secured their home desktop. Yes there is still some attack surface there, but far, far less than them storing files locally on their home PC.
Every person I've ever seen using VDI has a company PC plus a virtual desktop, so there's no cost savings there. The main advantages I can see are easier backups and not having to worry about network bandwidth too much (just enough for RDP is good), but there are drawbacks too like dealing with remote printing, a lack of support for hardware security tokens, etc..
For example, try to get a YubiKey working [1] with WebAuthN or FIDO when using RDP / VDI. It's basically impossible and you're stuck with crappy 2FA like TOTP.
I've spent way too long reconfiguring yubikeys to act as an OTP device so that they work over RDP.
(edit: reconfiguration is needed to capture the device ID/secret and get them registered to our MFA provider as an OTP token, I realize they do OTP OOB :) )
Severely restrict Windows without taking away liberties of the computer that the employee has.
An employee can simply login to their Windows workspace and continue work regardless of their their thin client(s).
Update windows without annoying your employee…
Prevent employees from installing that random chat program that is almost definitely a spyware right alongside their work programs..
Oh and prep a golden image Windows workspace and onboard any employee within seconds..
I can see how this product makes its argument to enterprise IT.
I've seen Trojans that would detect keypresses that look like bank accounts, take a screenshot and put it on top, replace the bank account number and then, seriously, detect with ocr on the confirmation page where the replaced account was and replace it there too. And these were made to steal amounts like 2k euro, maximum. I mean I guess that's still 2k euro * 1000 or so victims, but still (they do it this way because of 2FA, the customer must confirm on a second device, the little irritating calculators, the transaction)
Everything depends critically on endpoint security. You cannot make this work securely. I mean a simple Trojan could simply fake a logout, then transmit the screen + keypress control to an attacker.
And I would add: your enterprise security is not just dependent on a device you don't control, this also represents a "get out of jail free" card for malicious insiders. If they just make sure to have 4-5 viruses installed on their home machine, whatever they did in the company machine is excused ...
CapEx vs OpEx.
Also, your iPad is now a Windows machine with eight vCPUs, 32GB of RAM, and 512GB of storage for $158 per month.
Until Apple decides they're not comfortable with that and bans it.
If you need to provision someone you can buy them a laptop, but that's CapEx and has to go through some equipment purchasing bureaucracy that's hell on wheels to deal with.
Cloud services are OpEx though and might be something you as an IT person or department head can just approve as long as the monthly cost is low enough. The cumulative cost difference over many months or years doesn't factor into it.
A whole lot of the cloud trend can be explained this way.
Of course other use cases include temporary employees, testing, external contractors, etc.
My guess is that this kind of financial inanity is being driven by accounting rules: CapX vs OpX, revenue recognition rules, etc...
just reducing some of the policy enforecemnet requirements with machines being virtual is probably worth the cost of two or three laptops
no need to overthink VPNs with tricky clients vm's already on the right network/subnet/whatever, hell each machine can have nice software controller azure IAM roles it's a dream for cloud working
Microsoft Intune/Endpoint manager is actually pretty easy to setup/enroll laptops. Autopilot takes a bit of work, but it does get you to the point where IT doesn't have to do anything on a new laptop shipped to a user.
Ultimately if you don't want your users doing much on their laptops you can make it pretty simple to manage them.
> Is data security so important that some companies are willing to pay 5x hardware costs and 2x maintenance costs for it?
It really depends on the industry. Most folks aren't doing this because security isn't a priority.
Some firms may not survive a data breach, others might incur tens or hundreds of millions of dollars in costs (directly and indirectly) for one large breach. These folks do care and will spend whatever it takes because it's got a business justification.
For the same reasons people pay for the was clouf offerings or the Google cloud equivalent.
Less hassle, less stuff to manage, faster provisioning, hassle-free decommissioning.
Those with the ability to pay. The Microsoft sales force knows who they are and goes after them aggressively. There really isn't anyone like you in these targetted organisations who can question these decisions. Palms have been well-greased. Try to have an intelligent converstation with a Microsoft sales person. It is like you are talking to someone in a cult.
I have idly wondered how trivial it would be to exfiltrate data through HDMI. HDCP strippers exist and would let you record the output with perfect fidelity (1920x1080x3 is a lot of data). Simplistically, could compress data files, push through hexdump, paginate at chosen rate, and done.
It's probably not similar to the PC you're typing on in many ways, including the following:
- Probably significantly higher bandwidth to the internet
- Astonishingly high bandwidth to Azure resources (fiber)
- Outstanding security: cameras, carefully controlled access, 24x7 physical security
- Hardware reliability automatically serviced
- Multiple sources of power (usually more than one power utility company connected, plus generators)
- Multiple network connections typically, for redundancy
- Backups managed for you
- Can push a button and make a clone of your PC that your friend can log in to for a couple days then delete it when you're done
- If someone wanted to steal your hard drive by breaking into your house, they totally could. But getting your cloud PC hard drive image is going to take more determination than breaking through a window.
For many users, none of the above things matter. But for a lot of users, having all those things taken care of is a big win. Have you ever had a fan or a hard drive die on your pc? Or deal with the pain of migrating data off a dead PC onto its new replacement? Maybe that sort of thing happens only once every few years to you. But if you're managing, say, 25 pc's, every month you're going to be dealing with 1-3 problems in your fleet.
Also don't forget: Companies love OPEX and hate CAPEX. Does it make sense from a pure sticker price perspective? Maybe not. But it could from an accounting and tax perspective.
Considering this is microsoft and theverge, this "news" story is just paid PR/ad like so much of these type of stories are.
Microsoft has still problems with scaling ;)
Those are looong lasting projects with years of planing prior rollout...your example is the opposite to scaling NOW.
I really don't see Windows 365 as a viable option for most developers, when there are so many better -- and cheaper -- alternatives readily available.
Whether this breaks their tos is a bit gray....
Yes
https://developer.microsoft.com/en-us/windows/downloads/virt...
https://developer.microsoft.com/en-us/microsoft-edge/tools/v...
Parallels is magic and runs both ARM and x86 windows apps
I’d pay extra for Windows 365 to avoid ads.
The only one that runs well in virtual box was XP. Everything else had extremely slow disk accès, graphics performance and cpu. It took like an hour to boot windows 10.
Parallels was what I would consider native speed with better features. That was really disappointing as I wanted to use OSS.
Running links in Vbox seems fine though and I run a few vms 24/7.
I could see this if you needed better performance than that, I guess, or were developing on a machine that has trouble running x86 Windows very well under any circumstances (ARM).
Windows as a service, if decently priced, would be pretty sweet.
I'd call them both niche products that I'd be more interested in developing on if it wasn't so expensive to do so (at 16 GB of RAM). I'm not entirely sure I can describe what the normal deployment scenario looks like (e.g. traveling salesman doesn't work because you'd need too high of internet quality on the road, developer doesn't work as RAM pricing, and in a lot of scenarios you need on-prem hardware to connect to it anyway).
But nope, just checked, it's a flat rate per month, irrespective of use, so definitely looks cheaper to just buy a high-end machine and install Windows on it (or Mac + Parallels + Windows like others have noted.)
I can't imagine this happening with AWS, what a horrible PR
All of AWS free tier is either low impact resource wise (Couple thousand emails out per day, or metered to the lowest option, like a single t2.micro (Shared CPU, 1GB ram)
I think you need to supply payment information to use it and I believe this is pretty lucrative for Amazon. At this point you already caught half the fish.
Absolutely not, the average connection speeds for 99% of the globe are nowhere near offering a solid desktop experience.
Plus, chips are plenty fast days. Rarely do typical uses need to upgrade because of new software.
For exampe, there's 70ms between my Verizon phone and the PC sitting in front of me on a very well connected network. The traffic goes from WNY > NYC > DC > NYC > CNY > WNY. Very much not optimal.
At the same time, AWS us-east1 is 9ms away from my desktop.
And if we had a computer that could be a dumb terminal - it would cost 10-20 dollars, have wifi, ethernet, an HDMI connection and support a mouse and a keyboard.
>for something that's similar to the laptop I'm typing on which costed me $700 used?
lol? I'd want to see benchmark difference because I don't believe it