Tag Archives: fundamental

Teens play an active role in their own online safety, new Microsoft research shows – Microsoft on the Issues

It’s fundamental that each of us plays a critical role in our own online safety, and young people and teens are no exception. Adults could take a cue from teens in this area, however, as teenagers are more likely to act in response to online risk, defend others and ask for help, according to preliminary results of a new Microsoft study.

Nine in 10 teens polled said they acted in response to an online risk; nearly two-thirds (65 percent) said they stood up for others in the digital space, and more than three quarters (77 percent) asked for help when they encountered online abuse. That compares to 84 percent of adults who acted in response to an online risk, 59 percent who defended someone else and 60 percent who asked for help. Teens outpaced adults across all three categories. In addition, 56 percent of teens said they knew where to go for help with an uncomfortable online situation, compared to just one-third of adults.

Microsoft study expands research launched last year
The findings are from Microsoft’s latest research on digital civility — encouraging safer and healthier online interactions. The study, “Civility, Safety and Interaction Online — 2017,” polled teens ages 13-17 and adults ages 18-74 in 23 countries. This year’s results build on a study done last year that surveyed the same age groups in 14 countries. In 2017, there were 11,584 teens and adults polled in total.

Indeed, it’s up to young people – with solid guidance from parents, teachers, technology companies and others – to understand their digital rights and responsibilities, to recognize the risks and benefits of their online communications and transactions, and to realize the personal and ethical implications of their online behavior. These are some of the reasons Microsoft organized its pilot Council for Digital Good this year.

Council for Digital Good members want to improve life online for all
Last month, we welcomed to Microsoft’s Redmond, Washington, campus 15 teens from across the U.S., selected to explore the state of digital civility and how to foster a kinder, more respectful and empathetic web.

Council members have embraced their assignments and dove into how to go about making changes for the better when it comes to online life. In addition to drafting individual written manifestos for responsible online behavior, the teens created artistic representations of their manifestos after they returned home. We’ve received two rap songs, one video of an interpretative dance, several visual arts projects, animations and other imaginative creations.

Here is a photo of an artistic manifesto from Erin, a 15-year-old from Michigan, as well as a link to a video produced by 16-year-old Rees from Maryland. We’ll make other council members’ projects available on our website and other online properties soon.

Council for Digital Good teen artwork
Erin’s manifesto artwork.
Student video screenshot saying
A screenshot from Rees’ manifesto video.

And, teen council members were in demand before they even arrived on campus for the two-day August summit. We let nongovernmental organizations and other partner groups know that we were forming the council, and that it would be in operation for about 12 months. Several NGOs expressed interest in tapping our teens for their thoughts and perspectives about various campaigns and other work that their groups were planning.

New Thorn PSA aims to raise awareness of ‘sextortion’
One such organization was Thorn, which asked for teen council members’ feedback on a public service announcement (PSA) it was developing about “sextortion.”

Sextortion takes place when someone threatens to distribute private and sensitive material if a victim fails to provide money, or images of a sexual nature or sexual favors. (The perpetrator may also threaten to harm a victim’s friends or family members by using information obtained from the victim’s electronic devices unless the victim complies with the abuser’s demands.)

Thorn wants to make teens aware of common tactics used in sextortion, to destigmatize the issue by raising awareness, and to promote open conversations with trusted adults so teens have a stronger safety net in place if something goes wrong. Thorn held an online focus group with our teens in late July, just days before council members arrived for the Council for Digital Good summit.

Thorn’s new PSA launched Tuesday, and Microsoft is helping to draw attention to this clever and informative resource that benefited from the teens’ input. Council members liked the approach and imagery, saying that the cat video animation made it easier to broach a sensitive subject. While still in development, the teens said the PSA was a resource they would promote on social media and share with their friends. We congratulate Thorn on the new video, and look forward to hearing of many tens of thousands of views and “likes.”

Materials like the new Thorn PSA are essential to generate interest among teens and young people to safeguard their online reputations and to help instill safer online habits and practices. For more about Thorn’s mission, visit the Thorn website.

To learn more about online safety, Microsoft’s Council for Digital Good and digital civility, visit Microsoft’s website, review our resources, “like” us on Facebook and follow us on Twitter.

[1] Countries surveyed: Argentina, Australia, Belgium, Brazil, Chile, China, Colombia, France, Germany, Hungary, India, Ireland, Italy, Japan, Malaysia, Mexico, Peru, Russia, South Africa, Turkey, the United Kingdom, the United States and Vietnam.

Tags: Council for Digital Good, Online Safety

The Complete Guide to Hyper-V 2016 Integration Services

28 Sep 2017 by Eric Siron
Hyper-V Articles

Isolation represents one of the fundamental features of a hypervisor. If we didn’t want isolation, we would have little need to virtualize anything. We could install one operating system on a host and add software until we ran out of capacity. Security and compatibility prevent that approach. However, too much isolation causes other problems. Microsoft supplies the Hyper-V Guest Services as one solution.

The Isolation Model

Visually, Hyper-V’s isolation model looks something like this:

Hyper-V's isolation model

The management operating system loads the hardware drivers that Hyper-V utilizes, but otherwise, stays separated. Hyper-V keeps the management operating system and virtual machines “partitioned” from itself and each other. Of course, 100% isolation is neither possible nor practical. So, Hyper-V provides several interfaces for the virtual machines to use. VMBus manages most of these interfaces. As a “bus”, it carries requests and responses between Hyper-V and the guests.

The available interfaces in Hyper-V 2016 (that I know of):

  • Emulated and synthetic hardware, SR-IOV, and Discrete Device Access
  • Automatic virtual machine activation (Datacenter Edition only)
  • PowerShell Direct
  • Service monitoring (Failover Clustering only)
  • Integration services
    • Operating system shutdown
    • Time synchronization
    • Data Exchange
    • Heartbeat
    • Backup (volume shadow copy)
    • Guest services
  • Virtual Trusted Platform Module (vTPM)
  • Hyper-V Sockets

This article focuses on the integration services.

An Overview of the Integration Services

Each integration service provides a specific function to the virtual machine. For most, you can figure out its function just by looking at its name. The functions are projected into each virtual machine, but a matching software construct must exist and be enabled within the guest operating system.

For Windows guests, Microsoft provides a set of standard Windows services.

  • Hyper-V Data Exchange Service: aligns with Data Exchange
  • Hyper-V Guest Service Interface: aligns with Guest services
  • Hyper-V Guest Shutdown Service: aligns with Operating system shutdown
  • Hyper-V Time Synchronization Service: aligns with Time synchronization
  • Hyper-V Volume Shadow Copy Requestor: aligns with Backup (volume shadow copy)

Microsoft has distributed these as core components of its operating systems since Windows Vista/Windows Server 2008. Up through Windows Server and Hyper-V Server 2012 R2, every server maintained a local copy of the integration services and conveniently packaged them as vmguest.iso at each reboot. You can find the files in the host’s “Windowsvmguest” folder and the packaged ISO in “WindowsSystem32”.

Starting with Windows 10/Windows Server 2016, these files no longer exist on the host.

Windows Services that are Not Part of the Hyper-V Integration Services

You may see additional services that include Hyper-V or something that implies Hyper-V. Other than the ones that I listed, none are part of the official Hyper-V 2016 Integration Services stack that we’re talking about in this article.

Those services:

  • HV Host Service: Rather than re-invent the wheel, I’ll just paste the perfectly adequate description text right from the service: “Provides an interface for the Hyper-V hypervisor to provide per-partition performance counters to the host operating system.”
  • Hyper-V Host Compute Service: You will find this service on Hyper-V 2016 hosts, including Windows 10 and nested Hyper-V instances. It provides an API for container systems.
  • Hyper-V Remote Desktop Virtualization Service: I have no idea what this service does. It’s always running on my 2016 guests but not on my 2012 R2 guests. My first thought was that it enables Enhanced Session Mode from within the guest. So I stopped it. I had no trouble using Enhanced Session mode after that. It may be for RemoteFx.
  • Hyper-V Virtual Machine Management: This is the familiar VMMS that has been with us since the beginning. In previous versions, it was just called “Virtual Machine Management”. It runs on all Hyper-V hosts and enables VM control functionality (start, stop, etc.).

Integration Services Version Compatibility

Even though the host-side projections exist within every virtual machine that it creates, not every guest operating system has access to the matching client-side service. As an example, the Hyper-V Guest Service Interface cannot be installed into any guest prior to Windows 8.1/Windows Server 2012 R2. Therefore, that service will not be available on earlier operating systems.

Also, the host’s version rules over all guests. If you install a later version on a guest and then move it to an older host, you might have some difficulties.

Installing/Updating Hyper-V Guest Services on Windows

As previously mentioned, all currently supported versions of Windows and Windows Server ship with the guest services already installed. The process for updating them has changed since its inception, however.

For Windows XP/Windows Server 2003 up through Windows 8.1/Windows Server 2012 R2 while running on any Hyper-V host version from 2008 through 2012 R2, you would install/update by inserting the host’s vmguest.iso in the guest. The Hyper-V Virtual Machine connect window included an action:

Integration Services Setup Disk

Any time that Microsoft released an update for the integration services via Windows Update, only the host would be automatically updated. The guests could only be updated via a manual process. You could use the action shown above, manually insert the vmguest.iso, or even manually transfer the install files into the guest.

Now, the client packages for the integration services are also delivered via Windows Update. Simply keep your guests up-to-date and you will no longer need to worry about this.

Note 1: I am not certain what operating systems are included. I know that W8.1/WS2012 R2 and W10/WS2016 receive updates this way. I am not certain about earlier versions. If you know, please tell me.

Note 2: For older operating systems, remember that the host version rules. Meaning, do not attempt to install the files from a 2012 R2 host into a guest running on Hyper-V Server 2008.

Note 3: You’ll face some challenges for unsupported legacy operating systems such as Windows XP. You’ll need to find the newest versions that will still install by trying each of the server versions in turn. Do not expect perfect results.

Installing/Updating Hyper-V Guest Services on Linux

The core Hyper-V guest services have been natively built into the Linux kernel for quite some time. If you use a recent, mainstream distribution, then you’ve already got most of the services. They will automatically be updated anytime you update or upgrade your kernel.

If you wish to update the components separately or on a system with an older kernel, Microsoft makes the Linux Integration Services available for download. As of this writing, the current release version is 4.2. The lis-next GitHub project provides the source for feature backports to older versions. You can watch Microsoft’s official virtualization blog for notifications about new versions.

Not all features are included by default with the kernel-embedded integration services, notably Data Exchange and file copy (the only part of Guest services that Linux supports). Start on Microsoft’s official Linux on Hyper-V page. On the left or at the link list at the bottom, find your distribution’s page. Follow the directions to enable the additional features on your distribution.

Details on the Hyper-V Integration Services

Each service provides specific functionality, described below.

The Hyper-V Operating System Shutdown Service

Hyper-V’s Operating System Shutdown Service communicates with the matching service in the guest operating system to gracefully shut down the guest operating system. Without it, you can only force stop the virtual machine from Hyper-V.

The Hyper-V Time Synchronization Service

Hyper-V’s Time Synchronization Service keeps the guest’s time inline with the host’s. It respects any time zone differences. Do not use it for virtualized domain controllers, especially one that holds the PDC emulator role. Otherwise, it’s generally a good idea to leave it enabled for all guests.

The Hyper-V Data Exchange Service

Hyper-V uses key-value pairs to transmit unformatted information between the guest and the host. On Windows guests, the service operates through the guest’s registry. On Linux, the service operates through specially formatted files. On the host side, the Hyper-V WMI API facilitates key exchange for all guests. I have an article series that explains all of this and provides some plumbing to make it easy to use.

The Hyper-V Heartbeat Service

Due to isolation, the hypervisor can only directly sense if a virtual machine is in a powered on state. Beyond that, whatever happens inside the VM stays inside the VM. The heartbeat service is a simple sort of up/down tool. If the service can respond to the hypervisor, then the guest operating system is running at least well enough to start services. There may be some more detailed checks included, but that’s the basic summary of this service.

The Hyper-V Backup (volume shadow copy) Service

The volume shadow copy service (usually known as VSS) is a mechanism that Windows uses to facilitate crash- and application-consistent backups without stopping a computer. It functions by quiescing I/O and notifying applications that a backup will be occurring. Virtual machines present a problem if you want to back them up from the host. Even though Hyper-V can pause processing for a virtual machine, it can’t directly quiesce the guest operating system. So, its backup integration service operates as an intermediary.

When backup begins on the host, it can use this integration service to notify the VSS service within the guest. On Linux, the integration services uses a similar mechanism, although it can only quiesce I/O.

In older versions of Hyper-V, virtual machine backup used the standard VSS mechanism in the host. In modern versions, it relies on Hyper-V’s checkpointing mechanism instead. However, in-guest operations are still controlled by VSS.

Hyper-V Guest Services

I really wish that Microsoft had come up with a better name than just Guest services. Without context, it’s tough to realize that this is not a synonym for the overall category of Hyper-V integration services. The Guest services Hyper-V service allows you to copy files directly between the host and the guest.

How to Manipulate Integration Services in PowerShell

You should not manipulate services from within the guest. Use PowerShell or the GUI at the Hyper-V level. It will automatically handle service status within the guest.

Be aware that you can’t force a feature to work if the guest’s integration services don’t support it. For instance, you can’t enable the Guest Service for a Windows 2008 R2 guest and then copy a file into it.

Retrieve Integration Services in PowerShell

To see the guest services and their statuses for a virtual machine, use Get-VMIntegrationService.

Get-VMIntegrationService -VMName svdc1


From the output, you can see if a service is enabled and, if it is, its current status. Note that disabled services will always show a primary status of OK. This particular VM shows a nice example for secondary statuses as well. For the Heartbeat service, you can see that its monitored indicators are all OK. For VSS, it wants to tell us something about the component version, but we can’t read it all here.

To expand a secondary status description, specify the Name of the integration service to check, enclose the whole thing in parenthesis, and use the dot selector to pick the SecondaryStatusDescription property. Ex:
(Get-VMIntegrationService -VMName svdc1 -Name ‘VSS’).SecondaryStatusDescription.


Basically, the integration service is out of date, so I might have problems backing this one up.

Enable Integration Services in PowerShell

Enable an integration service with Enable-VMIntegrationService.

Enable-VMIntegrationService -VMName svdc1 -Name ‘Guest Service Interface’.

It will help if you run Get-VMIntegrationService first so that you can copy/paste the name. You can also use the pipeline to send objects from Get-VMIntegrationService to Enable-VMIntegrationService.

Disable Integration Services in PowerShell

Disable an integration service with Disable-VMIntegrationService.

Disable-VMIntegrationService -VMName svdc1 -Name ‘Guest Service Interface’.

It will help if you run Get-VMIntegrationService first so that you can copy/paste the name. You can also use the pipeline to send objects from Get-VMIntegrationService to Disable-VMIntegrationService.

How to Manipulate Integration Services in Hyper-V Manager

In Hyper-V Manager, you can determine if any given service is enabled. It will show the status of the Heartbeat service, but no others. Failover Cluster Manager uses the same dialog to show enabled/disabled state for services but does not show status for any of them.

On the virtual machine’s Settings dialog, look on the Integration Services tab. A service is enabled if it is checked. Be aware that checking a box for a service that the client does not support has no effect. For instance, you can check the Guest service box for a 2008 R2 guest, but you will not be able to copy files to/from it.

Integration Services for Hyper-V 2016 Management

To check the Heartbeat status, highlight the VM in Hyper-V Manager’s Virtual Machines pane. In the lower section, ensure that you are on the Summary tab. Look for the Heartbeat field:

Hyper-V Manager 2016

Leveraging Integration Services in Automation

I think that you can easily determine uses for these services, so I won’t throw a lot of silly ideas at you.

I would recommend that you find a way to incorporate regular checks of the Heartbeat service into your monitoring system. If the secondary status doesn’t return OK, there’s a solid chance that the virtual machine has crashed.

Look around a bit, and you might find other uses.

Have any questions or feedback?

Leave a comment below!