Showing posts with label Enterprise. Show all posts
Showing posts with label Enterprise. Show all posts

Sunday, 25 August 2013

Apple and the enterprise: A complicated relationship

When Microsoft shipped Windows 2000 and Active Directory, Apple didn’t really have a solution for identity management or for linking Macs to an enterprise network. The company was just beginning the transition from its classic Mac OS—the first version of which had shipped on the first Mac in 1984—to OS X. Although Apple did ship a public beta of OS X in second half of the year, the final release didn’t arrive until March 2001.

The classic Mac OS was not for multi-user systems. It offered limited user account creation and management for file sharing between Macs, but there was no built-in mechanism for logging into an individual Mac—it booted right to the desktop, where you had full access to the entire file system and all installed software.

Apple did make a couple of attempts to create a multi-user system, however. In the early 1990s, the company shipped At Ease, which provided some multi-user support, first on a single Mac and later for multiple Macs on a network. But At Ease never gained much traction beyond some pockets of the education market for it which it seemed to be designed.

In planning the transition to the true multi-user environment of OS X, Apple added a modicum of multi-user functions in Mac OS 9 that allowed each Mac to support multiple users with basic file permissions, individual user settings and preferences, and limited account-based restrictions. Apple also created Macintosh Manager, which redirected Mac OS 9’s multi-user functions to a server-based data store and copied certain settings and configuration files from that data store to an individual Mac. It wasn’t really an enterprise-grade solution, even when incorporated into the first few releases of OS X Server, but it was a functional pre-OS X stop-gap.

Student Exclusive: Buy a Windows 8 PC and save $100 on your next purchase
Apple’s first real move toward enterprise functionality, including identity management, came with OS X and OS X Server. The first release of OS X was essentially the Unix-based core of NeXTStep with an Apple-inspired GUI on top of it. NeXT gave OS X solid enterprise bones right away, including support for local and network user accounts.

NeXTStep and the first releases of OS X and OS X Server relied on a proprietary user and client management system known as NetInfo. Functionally, NetInfo served many of the same roles as Active Directory. It allowed for centralized user and computer accounts and user authentication for access to network resources; worked with the file system to support a POSIX permissions model; and it could be used to define user settings and experience in the same way group policies do in Active Directory.

Although NetInfo worked and remained in the mix of Apple’s enterprise components for several years, it had some serious limitations. The biggest one: It was proprietary and didn’t integrate with other platforms.

The other achilles heel for NetInfo in early OS X releases was that it didn’t support directory server replication. That meant that either a single server had to support the enterprise identity functionality for an entire organization or multiple servers—each with a unique directory of users, computers and configuration data—had to be deployed. Even though it was possible for Macs to search for enterprise identity data across multiple servers, the process was far from the multi-master replication capabilities of Active Directory domain controllers.

The proprietary nature of NetInfo led Apple to sell a complete end-to-end solution to enterprise IT. Today, Apple is well known for its end-to-end approach to technology; in many ways, it’s been a winning strategy because it allows Apple to maximize profits and create a controlled ecosystem. It’s also the same strategy that allowed Apple to disrupt industries so effectively and deliver some of the most polished products on the market. iTunes, with its link to the iPod and iOS, is the greatest example of what Apple can achieve using it.

Apple didn’t have a lot of luck selling that end-to-end system to enterprise IT. Part of that was because of the proprietary nature of Apple’s solutions. But the company was also still pulling back from its near collapse in the mid-to-late 1990s. At the time, its market share was abysmally low and it was a complete outlier in virtually every business market.

OS X Panther (and Panther Server) was one of the most important releases of OS X from an enterprise perspective. It rectified the limitations of NetInfo by introducing a broad-based solution for enterprise identity and directory services. It also added support for Active Directory. That represented a major shift in Apple’s strategy, as the company quietly acknowledged it couldn’t succeed in business without really offering support for existing enterprise systems.

Open Directory was technically a collection of directory and identity technologies that included NetInfo support, with a connection for legacy NetInfo server as well as for storing local accounts and records as well as an LDAP-based replacement for NetInfo’s proprietary data store. In practice, Open Directory became synonymous with Apple’s LDAP implementation; as that was integrated with Kerberos, it represented a replacement for NetInfo. In addition to being based on open standards, the Open Directory architecture included support for directory server replication. Even so, it remained a master/slave replication environment that was more like Windows NT’s use of a primary server and one or more backup servers than Active Directory.

Panther was one of the most important OS X releases from an enterprise perspective. It rectified the limitations of NetInfo by introducing a broad-based solution for enterprise identity and directory services.
The scalability advances, which continued to improve in later OS X and OS X Server releases, were only part of the advantage Apple gained by deprecating and eventually discontinuing NetInfo. The other was a move to open standards, including LDAP and Kerberos, the technologies at the foundation of Active Directory. As a result, Apple was able to offer Active Directory integration on Macs running Panther and later releases.

Out of the box the integration was pretty limited. Apple’s Active Directory plug-in for Open Directory only mapped three attributes for user account records (username, password, and home directory), but Apple offered three ways to deepen that integration: extend the Active Directory schema to include the new records and attributes used by Open Directory, map the Apple-defined records and attributes to existing but unused Active Directory counterparts, or use what was called the magic triangle. That involved Macs that were joined to the Active Directory domain for enterprise identity and user authentication and to an Open Directory domain for Mac client management.

Apple also allowed third-party companies to produce their own Open Directory plug-ins to support additional directory types like Novell’s eDirectory or provide new capabilities when using Active Directory. Centrify, an enterprise identity management developer, was one of the first companies to offer more powerful Active Directory integration. Its Direct Control for Mac, which is still on the market, allows Active Directory admins to manage Macs using group policies stored in Active Directory without modifying the schema. Group Policy options are available for virtually every Mac client and user management option available from Apple.

2007 was a big year for Apple. It introduced the iPhone that summer and it OS X Leopard that fall. Leopard was among the most feature-packed OS X releases to come out of Apple and boasted more than 300 features and improvements. The most notable enterprise identity change in Leopard was that Apple finally phased out NetInfo, which was until then still used for storing local user accounts on Macs.

Leopard Server, on the other hand, included key features that would eventually determine Apple’s current place in the enterprise. The first was a new option for joining Macs and Mac servers to an Active Directory domain. To streamline Mac integration with Active Directory, Apple created a new type of Open Directory mechanism known as augmented records. It essentially simplified the magic triangle approach. A user’s Active Directory data still managed his or her enterprise identity and authentication, but Leopard Server could automatically include just the Apple-specified records needed for OS X Server services or client management. Everything else was passed to Active Directory.
snow leopard server

This streamlined approach was part of a new form of OS X Server setup and administration. For small organizations or Mac-centric workgroups at a large company, Apple introduced simplified management by way of a new tool called Server Preferences. It allowed users with limited technical skills to set up and manage a server running a subset of the most commonly used business services: file and printer sharing, email and chat, websites and wikis, backup and VPN access.

This approach showed that Apple was willing to work with existing enterprise technologies. Specifically, it showed that Apple was happy to leave enterprise identity in the hands of Active Directory. And it marked one of the first instances of Apple marketing an enterprise product, in this case, Leopard Server, directly to users rather than to IT shops. That approach has been viewed as fueling the success of iOS devices—and the BYOD trend—in business.

Though it wasn’t obvious at the time, Apple was also the beginning to refocus OS X Server as a small business solution rather than an enterprise server OS.

Lables: Purchase Structured Settlements,Mesothelioma Lawyers San Diego,Secured Loan Calculator,Structured Settlement
Investments,Endowment Selling,Mesothelioma Patients,Mesothelioma attorney san diego,Austin Texas dwi lawyers,New
York Mesothelioma Lawyers,Phoenix dui lawyers,Secured Loans,Insurance Auto,Phoenix dui attorney,car free insurance
online quote,students debt consolidation loans,Pennsylvania mesothelioma lawyers,data recovery Denver,adverse
credit remortgages,bad credit remortgages,data recovery service los angeles

Sunday, 21 July 2013

SANS: Is the help desk the forgotten part of enterprise security defense?

A survey of 900 information technology professionals found almost half of enterprise help desks have gaps in security controls and training that could help ward off attacks like social-engineering assaults.

The SANS 2013 Help Desk Security and Privacy Survey published this week indicated the main jobs of help desk agents were to field requests from employees and others related to computer incidents, password-reset requests or personal information. Helpdesk agents "are trained to be friendly and get as many calls completed, resolved or transferred as possible," the survey notes. But a third of the IT professionals responding in the survey acknowledged they had "weak" risk management and security awareness training for their help desk staff, while 5% had "none" and 6.0 "didn't know."

Seventy percent of the survey respondents acknowledged "social engineering" attacks in which someone tries to get sensitive information or passwords from helpdesk agents as a significant risk. Helpdesk agents, who may have access to sensitive corporate resources, tend to be rated on productivity and speed metrics, the survey said, often meaning help desk agents are under pressure to work quickly. And help desks are often understaffed.

"As a result, an agent may ignore or work around compliance or quality requirements by trying too hard to meet the goals for quantity and timeliness," the SANS report states. The report also notes that entry-level-position helpdesk agents aren't particularly well-paid and there's a lot of "churn" in job changes, with annual turnover rates of 30% to 40% being common.

The SANS report said IT professionals related several types of problems they see in their help desk operations, such as personal health information inadvertently ending up in help desk system databases because a customer and help desk agents were e-mailing it back and forth.

In terms of budgeting for security, help desk operations are simply often overlooked, the SANS report said. Almost half did have some kind of training provided directly by managers and supervisors and much less often, automated help desk staff training, whether via internal tools or service providers.

Automation of help desk operations in general remains fairly low. Less than half also said they use some kind of automated user-authentication tools and authorisation tools. The help desk remains "far from the most critical line item on the corporate budget," the SANS report notes. About a quarter of the IT professionals responding to the SANS survey said they took into consideration what it might cost to have a security incident occurring -- such as a user password being compromised -- when establishing the help desk budget, but the majority did not.


"Effective help desks operations are as much a security problem as they are anything else, but it's a problem that falls through many cracks because the risks are hard to quantify and resolve," the SANS survey report concludes.

Novell serves up enterprise printing for BYOD era

Seeking a foothold in more enterprises running Microsoft software, Novell has introduced an application to streamline the process of connecting employees to workspace printers, even if they are using non-Microsoft computers and mobile devices, such as iPhones.

"We're giving the administrator a very easy way to do browser-based administration of the print environment," said Kai Reichert, a Novell product manager for collaboration. For the end user, the iPrint software provides a Web interface for easily setting up a new device relationship with a printer.

IPrint has been available as part of Novell's Open Enterprise Server (OES) for some time, though now it can be run as a stand-alone software package. This version of iPrint is packaged in a VMware-based virtual machine, so it can be run as a virtual appliance.

IPrint provides a way for users to set up connections between their Microsoft Windows, Apple Mac, or Linux computers with their workplace's network printers, without the need for contacting an administrator.
"The user would just go on the browser and see the floor plan, and click on the printer next to his [workspace] and from there iPrint would take care of everything else," Reichert said.

Through iPrint, Apple iOS and Android mobile devices can also print documents, which is a new feature that Microsoft's own enterprise software can't offer.

Even BlackBerry and Windows Phone users can print their documents as well, by emailing attachments of what they need to print to the iPrint server.

Novell has had a long history of offering software for managing enterprise printers, dating from its widely used NetWare network operating system of the 1990s, which, among other duties, acted as a print server.
NetWare successor OES, based on SUSE Linux Enterprise Server, includes the iPrint capability, but this is the first time Novell has split iPrint off into its own offering, Reichert said. Purchased by Attachmate in 2011, Novell has recently embarked on a mission to regain prominence in the market for enterprise software.
To prevent unwanted guests from using the organization's printers, iPrint can also work with any LDAP (the Lightweight Directory Access Protocol) setup, such as Microsoft's Active Directory, in order to permit or deny employees access to specific printers, based on their roles defined by the administrator.
"We're just synchronizing the user information, but we're not synchronizing the passwords. So the administrator can assign the rights, but the actual authentication is always done against whatever back end the customer has," Reichert said.

IPrint has some competition in the enterprise printing space. Hewlett-Packard offers similar capabilities though its own ePrint, which can also provide printing services to mobile devices.
Novell's iPrint could be more appealing to enterprises, because unlike many other mobile printing offerings, it does not need to communicate with outside cloud services to complete a print job. Organizations that worry about the security of their documents may be wary of routing print jobs outside the enterprise firewall, Reichert said.

With Apple iOS devices, iPrint uses the Apple AirPrint wireless printing feature. The printers themselves don't need to be AirPrint compatible. IPrint connects with the Apple devices through AirPrint, and then relays the print jobs to the non-AirPrint printers.

The software package currently will run only on a VMware virtualized environment, though the next version of iPrint will also be packaged in virtual machines able to run on Microsoft Hyper-V and Citrix Xen hypervisors as well.

IPrint Enterprise edition starts at US$900 for a 50-seat annual subscription license, covering both mobile and desktop use. Pricing options are also available for mobile-only clients -- for offices that already have printing management for desktop computers -- that start at $350 for an annual subscription of 50 users.

Friday, 19 July 2013

Egnyte synchronises Google Drive with enterprise storage

Hybrid cloud and on-premises provider Egnyte has integrated its product with Google Drive, allowing users to access Google Drive directly from a corporate network drive.

Egnyte’s latest release provides users with access to Google Drive, Microsoft Office, CAD drawings, images and multimedia files via the cloud or on-site storage. The Egnyte product enables IT departments to control and manage visibility of these files, with centrally managed access permissions as well as real-time auditing of all file, folder and login activity.

In spite of the popularity of cloud storage, businesses rely heavily on on-premises storage to enable employees to create and share files securely. “Our hybrid approach provides a unified name space for all these files, no matter where they reside,” said Egnyte CEO Vineet Jain. 

“This new Google Drive integration provides a single, simple view into all files [that users in the enterprise] have access to, no matter where those files are located – on-premises, in the cloud, or in Google Drive,” he added.

Egnyte uses secure folders that enable files to be synchronised between on-premises network attached storage (NAS), storage area network-based (SAN) enterprise storage and cloud-based storage. Users can access the Egnyte folder from smartphones, tablets and computers connected over a local area network (LAN) to local storage or to Egnyte’s cloud.

Balfour Beatty is an Egnyte user. The construction firm, which is building a new airport terminal at Dallas Fort Worth Airport, uses Egnyte to synchronise architectural blueprints using onsite ReadNAS devices. The blueprints are distributed to site managers, who access the files via iPads.

Thursday, 18 July 2013

Most enterprise networks riddled with vulnerable Java installations, report says

Despite the significant Java security improvements made by Oracle during the past six months, Java vulnerabilities continue to represent a major security risk for organizations because most of them have outdated versions of the software installed on their systems, according to a report by security firm Bit9.
Bit9's report was released Thursday and is based on data about Java usage collected from approximately 1 million enterprise endpoint systems owned by almost 400 organizations that use the company's software reputation service.

The data shows that Java 6 is the most prevalent major version of Java in enterprise environments, present on more than 80 percent of enterprise computers that have Java installed.

Java 6 reached the end of public support in April, and only Oracle customers with a long-term support contract will continue to receive security updates for it. Java 7, the version that is the focus of Oracle's recent security strengthening efforts, was only found on around 15 percent of endpoint systems sampled by Bit9.
Furthermore, most companies that run Java 6 on their systems don't have the latest security updates for it, the security firm found.

The most widely deployed Java version, according to Bit9's data, was Java 6 Update 20, which was installed on a little over 9 percent of endpoints. This version of Java is vulnerable to a total of 215 security issues, 96 of which have the maximum impact score on the Common Vulnerability Scoring System (CVSS) scale, Bit9 said.

The last publicly available security update for Java 6 is Java 6 Update 45, which was released in April at the same time as Java 7 Update 21, the latest version of Java available when Bit9 collected data for its report.
Only 3 percent of enterprise endpoint systems were running Java 7 Update 21, the company said. However, those endpoints belonged to only 0.25 percent of the sampled organizations, which seems to indicate that organizations with a larger number of endpoints are more likely to have the latest version of Java installed on their systems.

Another issue is that many enterprise systems have multiple versions of Java running on them. Around 65 percent of systems had more than two versions of Java installed at the same time, and approximately 20 percent had more than three versions.

According to Bit9's report, on average, organizations have more than 50 distinct versions of Java installed in their environments. About 5 percent of organizations have more than 100 versions.

This problem mainly stems from how the Java installation and updating process deals with older versions.
The Java 7 updater will attempt to remove existing installations of Java 6, but a clean installation of Java 7 won't remove older versions, said Harry Sverdlove, Bit9's chief technology officer. Java 5 versions are not removed during Java 7's installation or update processes, he said.

The Bit9 data showed that 93 percent of organizations have a version of Java on some of their systems that's at least five years old. Fifty-one percent have a version that's between five and 10 years old.

The problem with having multiple versions of Java installed at the same time on a system is that attackers can target the older and vulnerable versions to hack into that computer. Once that happens, the security of the newer Java versions doesn't help.

Code that enumerates all Java versions installed on a system for reconnaissance purposes has already been seen in real attacks, Bit9 said in the report.

Having different Java versions on a system increases usability because customers can run legacy applications, but from a security perspective it's a nightmare, Sverdlove said. Every version that is installed introduces yet another set of known vulnerabilities that attackers can target, he said.

Sverdlove compared the situation of companies running five-to-10-year-old versions of Java to running Windows 95. This practice might be convenient for compatibility reasons, but it's a horrible security risk, he said.
In most cases, this kind of Java version fragmentation inside enterprise environments is probably not even intentional, as many companies don't understand or keep track of how many versions they have installed, Sverdlove said.

First and foremost, organizations should get an assessment of what Java versions they have in their environments and where, Sverdlove said. The next step should be for them, as a matter of security policy, to stop and seriously consider whether they need Java, and if they do, for what purposes, he said.

The results of this assessment will vary among organizations, Sverdlove said. Some companies might find that a particular version of Java is needed to run legacy applications, but only on certain computers. Others might discover that certain websites that require Java work with the latest version of the software, and some might find that Java is only needed on their servers and not on desktops, he said.

Regardless of their individual Java needs, organizations should create a Java deployment policy and enforce it, Sverdlove said. If their policy is to not have Java, then they should use tools to block it from running; if they determine that they only need Java on certain machines, then they should remove it from all other machines, he said.

The most common way for hackers to attack Java installations is through the software's Web browser plug-ins by using exploits hosted on websites.

The Bit9 report did not contain specific information about how many of the Java installations identified on enterprise endpoints were accessible through the Web browsers on those computers. However, the majority of the sampled endpoint systems were desktops and laptops, so the likelihood of those Java installations being exposed to Web attacks is high, Sverdlove said.

Thursday, 11 July 2013

Microsoft's 'enterprise feature pack' for Windows Phone adds auto VPN

Microsoft said Wednesday that it planned to release an “enterprise feature pack” for corporations who wish to adopt Windows Phone, while extending the support lifecycle for Windows Phone 8 to 36 months, through 2016.

The new feature pack includes VPN functionality that will automatically trigger when protected resources are accessed, Microsoft said, plus S/MIME to sign and encrypt email and EAP-TLS enterprise Wi-Fi support. The pack will be released in the first half of 2014, Microsoft said in a blog post on Wednesday.
Microsoft
The real question, however, is whether Microsoft’s carrier partners will allow the feature pack to be pushed to their customer’s phones—or, at least, that was what virtually every commenter on Microsoft’s post had in mind. Carriers typically review, test, and deploy new OS upgrades over a matter of months, with no guarantee that updates will actually be pushed to consumers.



And while Microsoft also extended the support lifecycle of Windows Phone 8, it did not extend that same courtesy to those who own Windows Phone 7 devices, making Microsoft’s older platform less attractive. Microsoft will make updates, including security updates, available on WP7 phones for a total of 18 months, or until Sept. 9, 2014. At that point, they’ll be forced to shift over to WP8 phones, which will be supported, including security updates, through Jan. 12, 2016. (TechHive has rounded up eight other reasons for upgrading to Windows Phone and WP8, and written a Windows Phone SuperGuide, to boot.)

In all, however, Microsoft hopes that businesses sign on to the Windows Phone platform with the same enthusiasm they've shown for Windows 8. (Kevin Turner, Microsoft’s chief operating officer, told attendees at Microsoft’s Worldwide Partner Conference that 73 percent of enterprises are “current” on Windows.)
MicrosoftYou could be seeing this screen in a corporate environment if Microsoft has its way.
”By lengthening the Windows Phone support lifecycle policy and announcing the enterprise feature pack, we show Microsoft’s commitment to the Windows Phone platform,” Tony Mestres, vice president of Windows Phone partner and channel marketing, wrote. “This gives business customers the confidence to invest in Windows Phone today, with the knowledge that their investments are secure, and the platform is evolving to be an even better choice for business.”

The full list of the enterprise feature pack includes:
S/MIME to sign and encrypt emailAccess to corporate resources behind the firewall with app aware, auto-triggered VPNEnterprise Wi-Fi support with EAP-TLSEnhanced MDM policies to lock down functionality on the phone for more enterprise control, in addition to richer application management such as allowing or denying installation of certain appsCertificate management to enroll, update, and revoke certificates for user authentication
Nevertheless, some users were doubtful that they’d ever see what Microsoft promised. “This is all excellent news, and I can’t wait for this to be available... but how will this feature pack be released?” a commenter named “GoodThings2Life” wrote. “Will we continue to be at the mercy of carriers and OEMs to publish this in a timely manner, or will it be available as a store app or customer-installable or enterprise-pushable update?

”I vividly remember Joe Belfiore saying at 2012 Build and again at the WP8 launch event how we would be able to participate in an Early Adopter style program, and that has yet to materialize for customers,” the commenter added. “I would hate to see another situation where we’re stuck waiting on OEMs and carriers.”

Wednesday, 3 July 2013

Oracle Enterprise Manager 12c gears up for the private cloud

For the latest update of Oracle Enterprise Manager, the company has taken additional steps to help organizations set up their own private clouds, using Oracle systems, software and even non-Oracle products.

"Our goal is to is to allow enterprises to take any [Oracle] platform and offer it as a service," said Sushil Kumar, vice president of product strategy and business development.

Oracle Enterprise Manager 12c Release 3, released Tuesday, comes with new workflow capabilities and new connectors for managing additional Oracle products and systems.

Oracle Enterprise Manager was originally created to deploy and manage groups of Oracle databases. Over the years, Oracle has extended the software to manage the Oracle Application Server and third-party software packages from Microsoft and others, through the use of plug-ins and connectors. Today, the Oracle Enterprise Manager Extensibility Exchange, a sort of app store for the software, offers more than 135 add-ons for third-party programs.

In addition to aiding in the deploying and managing software, Oracle Enterprise Manager also offers a number of operational health metrics, based on information collected by agents installed on the same server as the software being monitored.

To help organizations set up cloud services for internal use, Oracle has been adding more features to Oracle Enterprise Manager.

In this version, reporting capabilities for charge backs have been enhanced in the software. Organizations running internal clouds may want to bill individual business units for their cloud usage. Earlier editions of this software could provide reports of usage by processor, storage, database queries and other metrics. This version allows organizations to create their own usage reports based on other metrics provided by the software, which then can be used as the basis for internal billing.


OracleThe activity planner tool.
An activity planner has been added, which will allow administrators to set up workflows to automate a series of tasks, such as updating a set of databases. "The change activity planner helps administrators plan, execute, tracks and report on long-running operations," Kumar said. The software uses the built-in operational health metrics as a way to determine that individual steps of a workflow have been completed.

Oracle Enterprise Manager 12c Release 3 also improves on a new capability introduced in the last version, the ability to build and manage a Java-based PaaS (platform as a service).The prior version of the software required administrators to provision and coordinate multiple WebLogic servers in order to build a service. This update eliminates that step.

"In a physical environment people had to pre-deploy the WebLogic software on the machines, and then Enterprise Manager could dynamically create the domains," Kumar said. A domain is any one of a number of logical containers that WebLogic creates to hold applications. "It goes one step further in that you do not have to pre-deploy the software."

The software adds more support for Oracle engineered systems. It now allows administrators to control multiple Exadata racks as a single entity. It provides the first full support for the Oracle Exalytics in-memory data analysis system. In addition to WebLogic, Oracle Enterprise Manager now can work with Oracle's other application servers, Glassfish (which Oracle acquired in the Sun Microsystems purchase) and Tuxedo (acquired in the BEA Systems purchase).

Oracle Enterprise Manager 12c R3 will also "fully support" the newly released Oracle 12c database, Kumar said. Oracle 12c was released last month with little advance notice from Oracle, and features a number of new advanced capabilities, such as multitenancy.

Kumar, however, would not discuss in detail how Oracle Enterprise Manager 12c R3 supports Oracle 12c, noting that Oracle will make another announcement within a few weeks. "We have all the capabilities for supporting database 12c," he said, including the ability to control individual tenants in the database, as well as the ability to manage Oracle 12c itself in the same way it manages prior versions of the database.

When asked about Oracle's reluctance to go into details about Oracle Enterprise Manager's support of the new Oracle database, Ovum principal analyst Tony Baer noted that, while the Oracle Enterprise Manager officially supports the database, the company may still have yet to work out all the particulars of assuring the management software works with the database across all possible scenarios, a large undertaking given the complexity of the new database and the wide variety of possible deployment scenarios.