Showing posts with label managed services. Show all posts
Showing posts with label managed services. Show all posts

Tuesday, February 19, 2013

Software vs Service Provider - Barriers to Cloud Hosted Applications

When a user logs in to a virtual desktop, and all their valuable and beloved applications are available to them, fully functional and integrated as they are on the PC, with all their data available to them as well, the reaction is almost always one of excitement, empowerment, and - ultimately - bewilderment. "Why", they ask, "doesn't everyone do this?"

Good question.

The answer, at least in part, is the way software companies license and sell their applications. Now, if you can continue to produce your product in the same way you always have, distribute it using your known distribution channels (which deliver predictable performance), and realize revenue in the manner to which you have become accustomed, why would you actively seek to create disruption in the "normal" flow of things? Especially when status quo seems to be working pretty well.

Another good question.

The adoption of cloud-hosted applications (in this case, hosted desktops and the applications associated with them) is pretty much in the hands of the application software companies. It's certainly not the platform that we are waiting for. The base technology is already proven on the hardware side, with awesome virtualization and high-density machine configurations available. And the software has been proven in a variety of deployments, as demonstrated by Microsoft Terminal Services, Remote Desktops and Remote Apps.

The software companies represent a barrier.

And so it comes down to the application software manufacturers. These guys seem to fall into two main camps when it comes to hosting their applications: redevelop the app with a web framework and deliver a browser-based solution, or pick a single delivery model from the above list, and limit true integration capability. In short - webify or segregate. Either way, it creates severe limitations in the way the software can take advantage of integrations and connections with other applications. And, for most desktop software vendors, integration with other desktop applications is frequently one of the key benefits of the product.

The web-based applications have already come to grips with this reality. Where a download of a document to your favorite word processor was once just fine, the market now demands data re-use and expanded business process integration, forcing the web applications to open themselves to outside connections and 3rd party developments. Just look at the developer network Salesforce.com has created. If that doesn't prove that no app is an island, I don't know what does.

On the other hand, many app developers who have chosen to "webify" using application publishing and delivery tools have evidently forgotten that one reality: integration is part of what makes their app popular. No business process is an island, and the data rarely stands alone. Would ACT! be so popular if it couldn't integrate with your Outlook email client, or with your MS Word word processor? Would MS Excel be so popular if you couldn't push almost anything to it as a spreadsheet file? The answer is no. This is why the integrations were developed in the first place - greater functionality and an improved value proposition, resulting in increased use and user productivity.
visit CooperMann.com
Too many options?

To complicate the problem, there is not just one delivery method that works for every application, business model, or user. With the variety of technologies available, independent software companies have hard choices to make in determining how their cloud hosted products might be offered, and additionally by whom they might be sold. As of today, though, most of the software companies have approached the problem alone, where opting to use their "hosted" editions frequently eliminates the option of integrating on the desktop with other locally-run applications (like what happened with QuickBooks Online Edition).

Not only does the software maker have to find the best technology/platform fit for the delivery and for their market, but they must also then consider their distribution channel - the "food chain"of promotion and delivery of the product or solution. Often this "who" that can offer the product is just as much of a barrier as the "how".

The maker of a given software package is in the business of selling their software, not other peoples' software. While integration with other products is exceptionally important to the product's value in the market, the software maker is fundamentally concerned with only the sales of their own solution. They tend to promote sales through resellers and consultants who can not only provide the software but offer install, training, and ongoing support as well. Designating sales organizations which are "authorized" to represent a product is a typical software company approach.

Many of these authorized resellers are focused exclusively on selling the software solution, not the ongoing support of the platform. These resellers are often highly skilled at working the specific software application, but may lack in-depth understanding of the platform upon which it runs.

Some authorized resellers are actually integrators - companies who sell products from a variety of sources and combine them into "solutions". Historically, integrators have been key players in creating successful markets for certain products, providing the support and other services necessary to keep the products entrenched in the user community.

In many cases, the integrator makes their money on the support element on the arrangement, not necessarily on the product. In these situations, the platform and ongoing maintenance and support are the key revenue drivers, and the integrator may be loathe to recommend a solution to the client that cuts into their involvement and revenue stream. And hosted, managed application services can certainly do that.

So - what is the answer? Well, there isn't just one that jumps out.

One element in the solution is recognition by desktop software companies that their desktop products need to be available in a hosted delivery model. Consumers require choice in terms of their involvement with the business IT infrastructure. Some folks want to control it, others simply need access. The business of hosting applications is growing, but many of the software makers in the market aren't behind the movement.. they are unwilling participants who leave it up to the service providers (the integrators in the datacenter) to make things work. In some cases, end-user licenses are even written to make hosting the software an illegal event.

Another element, equally if not more important, is the service provider community and their approach. With the wide variety of technical standards out there - the different technologies, different approaches, different levels of consideration, and different market sensitivities - it is no wonder that fear and doubt are prevalent in the market.  It would be nice if software developers assisted the hosting service providers with establishing best-practices and standards for implementing the various solutions so that customers didn't have to ultimately bear that burden, too.

And then there is the distribution channel and method of selling licensing. Many software companies work exclusively through their authorized reseller channels. While this may benefit the user from a product knowledge standpoint, it creates difficulties with the new delivery model and frequently puts the software sales channel in direct competition with the hosting providers.

The tweener gets you from here to there.

While the concept of hosting desktop and network applications may seem to be "fraught with peril", it can be done well and deliver significant benefits to the company. By simply changing the way employees access and interact with their applications rather than changing the apps themselves, businesses can introduce an entirely new range of business benefit and capability. Outsourcing the business IT can also represent cost savings and, more importantly, allow businesses to focus personnel and financial resources on the core business. 

For those who see true cloud services as the future, this "tweener" step gets you divested from localized technology and helps to embrace the flexibility and freedom that virtual and mobile computing can deliver without forcing radical change right now.

Make Sense?
J

Thursday, June 10, 2010

QuickBooks POS in a Hosted Environment

http://www.entrepreneur.com/microsites/postrelease/index.php?prx_adv=126&prx_ap=0&prx_rk=1374787251045&prx_t=23209527
entrepreneur.com
QuickBooks Point of Sale in a Hosted Environment

Retail operators and multi-location store owners often face difficulties in attempting to bring cohesion to their accounting, financial, and operational data.  In so many situations, the retail location –  where inventory is sold and money is exchanged – is far-removed from the administrative location where the financial systems and business reporting exist.  It seems that the best case scenario is to create a means for the remote (retail) locations to operate with real-time access to centralized customer, inventory, and financial data from a primary source. Application hosting services can provide this centralization,  and a platform for standardization, of systems.  Further, the application hosting model can deliver security and managed service which ensures that the systems are available and performing as required. 

Even though hosted applications and centralization of the systems and processes in a POS environment may appear to be the right answer, there are caveats and considerations that speak to the realities of today’s technologies.  These caveats should be strongly considered prior to undertaking any reformation of systems and processes relating to the retail locations.

The first fundamental reality which must be addressed is connectivity.  While a retail or store location may enjoy Internet or network connectivity, there should be great consideration given to the wisdom of connecting these locations only and exclusively via remote access systems.  Retail is a dynamic business, and the sale is made when the customer is ready and willing to buy.  Any retail location must be able to process this sale in order to meet the immediacy of customer demand.  If the systems in use are exclusively accessed remotely, then the connectivity to those systems become of paramount importance in the ability to do business.  At the very minimum, any remotely-served retail location should have redundant connectivity options, with local personnel being familiar with the connection failover process.

A second strong consideration for a hosted or remotely-deployed POS or retail system is local device support.  Devices, such as card readers, scanners, cash drawers, receipt printers, etc. typically require local PC/computer drivers in order to function.  When served by a remote system, this connection between the host and the local devices may not function.  Limited device support for POS hardware can significantly impact the location’s accuracy and efficiency.

Another area of consideration for POS and retail systems centralization is integration or synchronization of POS data with core accounting and financial data.  Depending on the software solution in use, this integration may require that the POS software/data and the financial software/data reside on the same computer and/or within the same network.  This may be one area where a hosted implementation may offer a great deal of benefits, but the benefits to be derived are often a function of the design and behavior of the applications integrating.

QuickBooks Point-of-Sale, for example, was designed for use on a single-user PC environment.  The application is not well-suited to a hosted deployment for multiple users, as the software only allows one instance of itself to run on each computer. While there is a “multi-store” option for this solution, the option requires all stores be connected via a LAN/WAN connection to the same network. RDS (remote data sharing) functionality might possibly be used to allow communication between locally-run POS locations and the “master location” at a hosting service provider, but this method of communication has previously been found to be somewhat problematic and platform-specific (see notes following relating to multi-user/store configuration and Vista OS).  Further, the potential poor performance of RDS connections often negatively impacts the value of the integration.  


In many cases, the suitable answer is to keep the POS systems running on the local computers and network, and run the financial applications and the POS integration at the host.  With an installation of the QuickBooks financial application and the point-of-sale solution with the hosting service provider, the core financial data is able to be secured and protected in the virtual environment without risking lost productivity (and lost sales!) due to connectivity failures at the retail locations.  The end-of-day process at each location is to then move a copy of the POS data file to the host system, where it would be integrated with the QB financial data.  In environments where is is desirable to have the POS systems reading customer and/or inventory data directly from the QuickBooks financial data files, the recommendation is to keep an available copy of the financial data file in the POS network, on the local computers.  This copy of the data file provides the point-of-sale systems with necessary customer and product information, and would be copied/updated during the same end-of-day process where POS data is moved up for integration on the host system. 

This process is very similar to the way in which a localized system might be utilized, where the POS application runs at the front counter and the accounting application and data run from a back-office system.  In this scenario, many businesses elect to simply log off from the front counter system so that they can launch the POS application from the back-office computer, and then integrate the POS data with the QB financial data on that same computer.  Even in remote network configurations (WAN configuration), this is often a method which delivers better performance and stability than utilizing the remote data sharing service.



Wednesday, January 20, 2010

Implementing Intuit Statement Writer on a Secure Network

The Intuit Statement Writer is a custom reporting and financial statement tool for use with QuickBooks Premier Accountant and Microsoft Excel. The solution has a few peculiarities that must be addressed in order to make it function properly (or at all!) in a networked or hosted environment.

The issues center primarily around the fact that the application was designed for use on a standalone PC, and doesn’t take into consideration the potential for redirected or restricted data folders. Further, the method of integration with Microsoft Excel requires specific support from the Excel application, so care must be taken in selecting the version of Excel (or Microsoft Office) to be used.

In computing environments where the QuickBooks and Office applications are installed directly on each PC, and where data is stored locally on the PC, most of these issues become irrelevant. When the applications are utilized within a strictly controlled domain, however, a variety of issues may arise. If the applications are to be utilized in a terminal server environment, then many issues will certainly come into play.

The Intuit Statement Writer solution requires QuickBooks Premier Accountant v2010, and Microsoft Office 2003 or greater. The version of Office or Excel used must be at least version 2003, and it must be either the full standalone version of Excel, or Excel as part of MS Office Standard, Professional, or Enterprise. Excel as part of MS Office Small Business, Basic, or Student/Teacher editions is not compatible. All editions of Excel 2007 are compatible.

By default, the Intuit Statement Writer (ISW) stores its files on the local PC where the application is installed. The application utilizes the local “My Documents” folder as the location for ISW files. In an environment where the My Documents folder is redirected to a network folder or share, the program fails to install or run properly. The specific error messages encountered may vary, but are essentially indicating the same issue: you are attempting to use an unsupported file folder location.

Intuit Statement Writer (ISW) requires full trusts and permissions to the My Documents folder, which is automatically granted when the folder is local to the PC. When My Documents folder is pointed to a shared network drive, the trusts and permissions are no longer granted and the error message will appear. According to Intuit, “Intuit Statement Writer files and appearance files (.gsm and .gss) can be stored on a server or network drive, but it is not possible to open and work with the files while they are located on the server without modifying security policies on the machine. Because we don't recommend this, the files must be local when working with them." It is necessary to copy the ISW file you wish to work with to your local drive, and, when finished working with the file, copy it back to the server.

In addition to having difficulties using server or network drives, ISW also will not function as a multi-user application, due to the architecture and reliance upon the MyDocuments folder. While ISW may be used without issue while QuickBooks is in multi-user mode, only one user at any time is able to work with the Intuit Statement Writer files.

Relating to the policy and permissions issue, there is a Microsoft Support article which describes a potential resolution (http://msdn.microsoft.com/en-us/library/9w6bd8f1.aspx How to: Grant Permissions to Documents and Workbooks in Shared Locations (2003 System)) This article addresses this issue and provides information on modifying security policies around the Office Document Membership Condition on the computer(s) where ISW will run.

Two methods are provided: using Visual Studio command line tools, or using the Microsoft .NET Framework configuration tool.

In an effort to simplify making these changes on your systems, Intuit has provided a batch file which can be run on the system where ISW is installed, and where the My Documents folder is redirected for the user.

Obtain the batch file here: https://www.quickbase.com/db/bewwfafti?a=GenNewRecord

This batch file (actually 2 batch files) grant full trust to the ISW dll files, checks to see if and where the My Documents folder is redirected, and attempts to grant full trust to the specific network location of the My Documents folder through the Microsoft .NET Framework 2.0 assemblies. Care must be taken any time .NET security policies or configurations are adjusted, especially when working within a secure domain. The .NET Framework Configuration tool (Mscorcfg.msc) enables users and administrators to modify security policies for the machine policy level, the user policy level, and the enterprise policy level.

From Microsoft: "Prior to the .NET Framework, most Windows applications had free access to all of the local computer resources, including the registry, file system, event logs, environment variables or available printers. Due to the limitations of role-based security, administrators were conditioned to accept that nothing was off limits to a running application as long as the user (or the user context under which the application is running) was authorized to use the resource.With the proliferation of distributed component-centric systems, it's not uncommon for applications to download and execute components from Internet/intranet sites or network shares. The possible negative consequences of such applications are obvious. Malicious code, whether by design or not, could be loaded from an external entity and wreak havoc on a local computer or the network on which it resides. There is also the threat of security breaches that could jeopardize the privacy of sensitive data."

Because the Intuit Statement Writer utilizes features of Microsoft Excel, it relies heavily on the behavior of the Office applications and document permissions on the computer and network. These permissions are often controlled by establishing security profiles or policies via the .NET framework. If the location of a Microsoft Office 2003 document is not secure (for example, a SharePoint site or file share that users—possibly including malicious users—can write to), or if you are not sure who has permission to upload content, you can grant permissions only to documents and workbooks in the location, rather than to all content. You do this by using the Office Document Membership Condition, and modifying the security policy to check for this condition on the computers on which your solution will run.

When you use the Office Document Membership Condition, only Office documents are trusted; assemblies and executables are not granted permissions to be run from the share.This permission or trust is often assigned to a “code group”. Code groups can provide information on how the system determines the allowed permissions. The allowed permission set for the policy level is the permission set associated with the code group that has this attribute.

When all policy levels are considered, the runtime never grants the code more permissions than those associated with the Exclusive code group. Within a given policy level, code can be a member of no more than one code group that has the Exclusive attribute. This may be problematic for some administrators who wish to implement the Intuit “fix”, which creates a policy group and then establishes that group with the Exclusive attribute. Network administrators with pre-existing security policies may well find that the Intuit fix will not work as delivered, due to the fact that Exclusive policy groups may already exist to govern the permissions of Office or other documents.

Intuit KB Article: http://support.quickbooks.intuit.com/support/Pages/KnowledgeBaseArticle/1011230

1. After the zip file is downloaded, you will need to extract it to the desktop...

2. After the file as been unzipped, open up the ISWFix1 folder and double-click on the ISWFix1.bat file.

3. These steps will need to be performed for each computer or user account that needs access to ISW.

4. Terminal Services/Citrix: Ensure the ISWprefs.ini file is set to not delete itself when the user logs out.

http://msdn.microsoft.com/en-us/library/2bc0cxhc(VS.71).aspx#cpconnetframeworkadministrationtoolmscorcfgmscanchor4

Microsoft .NET Framework configuration tool

Tuesday, January 19, 2010

Turning to IT When Times are Tough


-->
Turning to IT When Times are Tough
When budgets get tight and the economic outlook is bleak, business owners and executives tend to turn to information technology departments and projects as a potential area for cost cutting. The reason for this is that many businesses view IT purely as a cost center, making it a prime target when driving to reduce operating costs. A recent survey by McKinsey & Company, however, indicates that the current trend is a bit different.
The new research indicates that many non-IT executives "seemed to have a developed a healthier appreciation for their information technology functions" according to Joe McKendrick in a recent ZD Net article on the subject. McKendrick mentions that business executives generally seem pleased with the way the information technology is helping organizations get through these difficult economic times, "navigating the rough seas" as he puts it.

"The survey also suggests that organizations that took the most advantage of information technology going into the recent downturn may have come out the strongest" observes McKendrick.

The McKinsey & Co Study, authored by Roger Roberts and Johnson Sikes, reported that the recent economic downturn actually increased awareness of the role information technology can play in improving business processes and reducing costs. As for the quality of services delivered? The study revealed that non-IT executives largely believe their IT functions responded effectively to the economic crisis. A majority said current performance in providing basic IT services is very or extremely effective. In contrast, IT executives had a dimmer view of their performance, with only a minority being satisfied with service delivery levels.
There have always been questions about the alignment of information technology to the business need, and IT is often perceived as being out of touch with the business. In this new research, McKinsey & Co indicate that IT executives are very aware of the issues of keeping up with the business and are finding innovative ways of addressing them.
Joanie