New SCCM deployment for 10,000 users, single domain across 2 sites connected with a fast WAN link

Hi,
 I'm looking at rolling out an SCCM 2012 deployment in my environment. We have 10,000 users, a single AD domain, several thousand Windows 7 laptops and desktops, as well as few hundred MAC OS 10.6 devices and we currently use WSUS for updates. We have
2 main sites with the users equally split across the sites and we have an internal PKI. 
I'm looking at doing the following:
 - deploying a single primary SCCM 2012 site server (site A)
 - 1 or 2 distribution points in site B
 The main things I'm after are:
 - Computer inventory (MAC + Windows)
 - Application deployment (MAC + Windows)
 - Hardware inventory (MAC + windows)
 - Deploy updates (MAC + windows)
 - Remotely power on devices and patch overnight 
I'm aiming to setup an SCCM infrastructure and aim to achieve the above in a month.
What I'm not sure about is:
- if I need a secondary site server?
- How I should handle WSUS updates ? I don't know if SCCM can leverage the current WSUS infrastructure or whether it's better just to get rid of it and install the WSUS role as part of SCCM?  
- I believe that to enable application deployment for MACs I need to install a PKI certificate on my distribution points. If do I this, presumably all my Windows clients will also connect via HTTPs. Are there any downsides to doing this?
If anyone has deployed a similar setup I'd be keen to hear from them.
Thanks in advance

1. WSUS: Be careful here. If you just remove the WSUS policy computers can just revert back to their default setting which would be to connect to the Internet at 3am and automatically install the updates. I've seen this happen on a large site and it is not
pretty. It's better practice to leave the policy in place but to disable automatic updates (or you could change the WSUS server to be your new ConfigMgr WSUS instance - this would have the same effect).
2. Secondary Sites: It's not uncommon for customers to start without the secondary site and monitor the WAN link for excessive traffic. The secondary site can be introduced afterwards if it is deemed neccessary.
Gerry Hampson | Blog:
www.gerryhampsoncm.blogspot.ie | LinkedIn:
Gerry Hampson | Twitter:
@gerryhampson

Similar Messages

  • H/w requirements for DIrectory server for 200,000 users

    Hi,
    I would like to implement Directory services for 200,000 users. How can I know whether iPlanet Directory 5.1 will support this many users or not? If supports, Which h/w I have to use?
    If any one can let me know the formula to calculate users and h/w
    Thanks

    The directory server can handle many more users than 200K. The hardware requirements calculations are amply explained in the book "Solaris and LDAP Naming Services" by Bialaski. If you have iPlanet support contract they can provide you tuning information which includes this info.
    You should remember the possibility of growth and load in terms of number of clients and peak requests per second. With your needs, my gut feeling is that even a Netra can host it. However, if it's an enterprise service you may want to go with at least 220 machines in a replicated configuration for load balancing and availability.
    DISCLAIMER: Use these opinions at your own risk. You must do your own analysis and calculations to design a suitable physical/logical architecture.

  • Forgot password for client 000 user DDIC

    We forgot password for client 000 user DDIC & SAP*
    please suggest any one how to recover the password
    Thanks in advance

    Hi,
    Pls refer below link explaining step by step details of activating SAP* user login.
    [http://forums.sdn.sap.com/thread.jspa?threadID=1497131]
    [http://www.sap-img.com/basis/changing-the-default-password-for-sap-user.htm]
    Regards,

  • HT1848 MY wife has an Iphone 4  and I have a 5. To date we haev used one apple is/account to manage music purchases. Recently we bought a Mac and created a new apple account for her. How do I synched her phone with new apple account?

    MY wife has an Iphone 4  and I have a 5. To date we have used one apple account to manage music purchases/library. I updated ny phone to the new OS version and all her texting is showing up on my phone.  I understand if i create an apple account for her I will not see her texts. Recently we bought a Mac and created a new apple account for her. How do I synched her phone with new apple account and get access to the music library under my account on the new MAC laptop  before I update her phone to the new OS?
    Going forward if I purchase music under my apple id and want her to have it on her device, how can I acheive that?

    You can continue to share an Apple ID for purchases.
    Sign her in to her new account here:
    Settings > iCloud > Delete Account (Keep on Phone if you want to transfer contacts, calendars, etc...) then sign in with her new ID
    Settings > Messages > Send & Receive > Apple ID > Sign out then in with new
    Settings > FaceTime > Apple ID > Sign out then in with new
    Use the same Apple ID here:
    Settings > iTunes & App Stores > Apple ID

  • I have a MAC Pro from 2011 currently running MAC OS 10.9.5.  This weekend I cloned the MAC HD drive to a new SSD drive for improved performance.  The clone was completed successfully with no errors.  After the clone completed I successfull restarted my sy

    I have a MAC Pro from 2011 currently running MAC OS 10.9.5.  This weekend I cloned the MAC HD drive to a new SSD drive for improved performance.  The clone was completed successfully with no errors.  After the clone completed I successfully restarted my system using the SSD as the boot device.  I then successfully tested all of my products, including Photoshop CS6 and all of its plug-ins.  I successfully tested the key features that I frequently use.  Today while attempting to launch Photoshop CS6 a message is being displayed indicating that a scratch disk cannot be found.  All drives are available on the system via the Finder and Disk Utility.  I can access all drives including the old MAC HD which is no longer the boot device.  I've even attempted to launch Photoshop from the old device yet the same error persist.  Is there a way to review/edit/change Photoshop preferences if Photoshop doesn't launch?  I've even restarted my system several times to see if that would resolve the issues.  Does anyone have any recommendations for this issue?  Have you previously address this issue? 
    Thank you Gregg Williams

    Boilerplate text:
    Reset Preferences
    http://forums.adobe.com/thread/375776
    1) Close the program and press Ctrl+Alt+Shift/Cmd+Option+Shift during startup (not reversible)
    or
    2) Move the Folder. See:
    http://www.bugge.com/Family-and-friends/Illy/illy.html
    --OB

  • I recently updated my MacBook Pro to the new software, and now my iMessage and my FaceTime are not connected with my computer. How do I get them to match so that I would be able to use my cellphone number?

    I recently updated my MacBook Pro to the new software, and now my iMessage and my FaceTime are not connected with my phone number like it is supposed to be. How do I get them to match so that I would be able to use my cellphone number on my notebook?

    To reset any OS X program just go to the folder and trash the affected files.
    Open a new Finder Window
    Click "Go" in the above status bar
    Click and HOLD the "option/alt" key and you will see "Library" now show in the above list
    Click Library while still holding the option/alt key and a new window will open with all of your system files
    Go to the preference file (NOT Preference Panes)
    Locate a file named <com.apple.FaceTime.bag.plist>
    Locate another file named <com.apple.FaceTime.plist>
    Locate the file <com.apple.iMessage.bag.plist>
    Drag the files to the trash
    Delete the trash
    Close FaceTime and iMessage if not already closed
    Relaunch FaceTime and iMessage from Applications folder
    This should reset the program back to default. You will have to put your information back into the program but it should work.
    Good Luck.

  • Powershell script for removing some users from a particular Site Collection

    Hi,
    I am looking for a PowerShell script to delete a few users from a particular Site Collection. I am unable to delete them from/_catalogs/Users/simple.aspx page therefore need some other medium to
    delete users from the site collection.
    My ultimate aim is to have no user profile with "tp_deleted" field's value as 0 in the USERINFO table. Currently there are about 40 odd users with this field's value as 0 and this is affecting my crawling of this content database.

    Thanks for the reply Alex & eHaze,
    I have a content source of root site which crawls all the site collections under it. Out of the 9 site collections, only 8 are getting crawled and 1 doesn't get crawled at all. The error in the crawl logs is 
    The SharePoint item being crawled returned an error when requesting data from the web service. ( Error from SharePoint site: Value does not fall within the expected range. )
    I tried a lot of things, searched over the net and finally found
    this which helped me solve the same issue in my development environment. I deleted these users from userInfo table and ran a full crawl. And the issue was fixed.
    Now since I cannot delete the users from userInfo table directly from PROD environment, I used .../_catalogs/Users/simple.aspx list
    to delete users from this site collection. While some of the users I could delete, quite a few I could not. Clicking on the profile redirected me to the home page rather than the info page of the profile. 
    This
    is why I have to delete these users from the site collection.
    Alex - the link you shared, I guess it is for a web application level.
    eHaze - the script you shared throws this error:
    Get-SPSite : Cannot find an SPSite object with Id or Url: http://dev-apps/divisions/BT. At C:\PowerShell Scripts\DeleteUserFromSiteCollection1.ps1:4 char:19
    + $site = get-spsite <<<< $siteURL
    + CategoryInfo : InvalidData: (Microsoft.Share...SPCmdletGetSite:
    SPCmdletGetSite) [Get-SPSite], SPCmdletPipeBindException
    + FullyQualifiedErrorId : Microsoft.SharePoint.PowerShell.SPCmdletGetSite
    You cannot call a method on a null-valued expression.
    At C:\PowerShell Scripts\DeleteUserFromSiteCollection1.ps1:9 char:27
    + $site.SiteUsers.Remove <<<< ($LoginName)
    + CategoryInfo : InvalidOperation: (Remove:String) [], RuntimeExc
    eption
    + FullyQualifiedErrorId : InvokeMethodOnNull
    hope this info helps.

  • Hi, i use my iphone4s as thetering for my lhi, i use my iphone4s as thetering for my laptop. Can i share this connecaptop. Can i share this connection with my ipad, hi, i use my iphone4s as thetering for my laptop. Can i share this connection with my ipad

    i use my iphone 4s as tethering for my laptop, can i use the same connection through my laptop for my ipad internet access

    You can use the iPhone as a personal hotspot for the iPad - the iPad should see the iPhone as a wifi network.
    Personal hotspot : http://support.apple.com/kb/HT4517

  • When i click on a link that opens up a new page i only get a page that says 'search bookmarks and history' when it should show up as a new page like for a survey. I tried re-installing firefox with no luck. How can i fix this?

    I tried re-installing firefox with no luck. no matter what i get this:
    http://i237.photobucket.com/albums/ff136/BrittRyuu/alliget.png
    How can i fix this?

    Start Firefox in [[Safe Mode]] to check if one of your add-ons is causing your problem (switch to the DEFAULT theme: Tools > Add-ons > Themes).
    * Don't make any changes on the Safe mode start window.
    See [[Troubleshooting extensions and themes]] and [[Troubleshooting plugins]]
    If it does work in Safe-mode then disable all your extensions and then try to find which is causing it by enabling one at a time until the problem reappears.
    * Use "Disable all add-ons" on the [[Safe mode]] start window to disable all extensions.
    * Close and restart Firefox after each change via "File > Exit" (Mac: "Firefox > Quit"; Linux: "File > Quit")
    >In Firefox 4 Safe mode also disables plugins (Tools > Add-ons > Plugins) and hardware acceleration (Tools > Options > Advanced > General)

  • Bugzilla connector for otpc (jdev 11.1.1.4) cannot connect with @in userid

    Hi,
    I am using jdev 11.1.1.4 with otpc 11.1.1.4 and bugzilla connector. Our bugzilla uses userids in the format of [email protected] (email addresses as userids) as it configured to use windows authentication
    TPC00015: Failed to log in to "myRespository". Do you want to go to Account Manager to fix the problem?
    When i select "Yes" and test the connection under "Manage Accounts" i get the following error. in status.
    TPC-00029: Test failed. oracle.xml.parser.v2.XMLParseException: Expected '>'.
    My guess is that the bugzilla connector for some reason cannot take in user ids with @ characters. Can Susan Duncan or other PM please confirm this and tell me a workaround.
    Thanks,

    Defect 13743183 has been created for the issue.
    Bug 13743183.

  • Interested in getting the new iPad air, although nobody can confirm whether I this will connect with any tv to watch tv programmes?

    Could anybody confim that I can connect an iPad air to any tv to watch tv programmes. For instance bbc iplayer? I'm able to do this with my iPad 3, but I can't find info for the iPad air.

    Anyone have any ideas or information to help with this?  Any help and consideration is MUCH appreciated.

  • New email settings for Mac Mail & 3rd party...

    Anyone have instructions for new email port settings for users who are:
    -Using Mac Mail
    -Using third mail email service provider (i.e., not sending and receiving through a Verizon address)
    Thanks,
    Pardon me while I rant (I'm hoping a Verizon employee reads this)...
    I use my third party email account exclusively. It's listed on my verizon account page. So, does verizon do the logical thing and send announcements to my third party email address (?) - of course not, they send them to the verizon address which I have never once used in years.
    New port settings for some email users...
    I got a phone call from an automated Verizon attendant telling me to check the following for new port settings for some email users:
    http://www22.verizon.com/ResidentialHelp/HighSpeed/Email/Setup+And+Use/QuestionsOne/124333.htm
    I guess Verizon hasn't heard that there are millions of people using Mac computers, with Mac Mail as their email clients. And, some of these users are using obscure third party email service providers with names like 'Google'. On the above linked page, there are no instructions for these users.
    I tried to use the online live support feature to get a clarification about using the new port settings. A polite gentleman with a long Indian name told me he couldn't help me and gave me an 800 number to call. After calling the 800 number, a nice lady in the Philippines (on a terrible voice connection) told me she couldn't help me - she transferred me to another department where I waited and waited and waited. I finally had to hang up.
    I'm beginning to think that Verizon is a division of the United States Postal Service. Come to think of it, I get much better service from the USPS than I get from Verizon.

    Are you using the Mac Mail client or Verizon's netmail?
    If a forum member gives an answer you like, give them the Kudos they deserve. If a member gives you the answer to your question, mark the answer as Accepted Solution so others can see the solution to the problem.
    "All knowledge is worth having."

  • Group Policy for Remote Desktop Users

    Hi,
    Currently my users use desktops and have user and computer GPOs applied (typical things like logon scripts etc.) at the OU level where they reside e.g. Finance Users, Sales Users etc.
    I am planning a Remote Desktop 2012 environment.
    I have read the following:
    TechNet cc779327
    So, my understanding is that I create a new OU for my Remote Desktop Server only (not users), and create a new security Group for my RD Users and a security group for my RD server.
    Remote Desktop Servers OU
               * RD User GPO (filter on RD User security Group and RD Computer Security Group)
               * RD Computer GPO (filter on RD User security Group and RD Computer Security Group)
    I then apply all computer settings to the RD Computer GPO (loopback processing, Windows installer, hide shortcuts etc.).
    I then apply all user settings to the RD User GPO (app specific, templates etc.)
    Why not consolidate the two GPOs into one?
    If I set computer settings in the computer GPO, and apply it as above to filter to the RD Server group and RD Users Group will this apply to only users un the RD User Group...or ALL users since I added the server to the filter?
    If a user currently gets a setting in their normal OU e.g. Finance logon script, will they still get it on the Remote Desktop? Or do I need to copy that GPO setting to my new RD User GPO also?
    Am I right to add both RD Server and RD User groups to the filter on both RD User and RD Computer GPOs?
    Loopback processing - merge or replace typically for Remote Desktop?

    Hi,
    Thank you for posting in Windows Server Forum.
    Create OU for RDS Server in Active Directory. Create security group for users who will use Remote Desktop Host (i.e. RDS Users). Create GPO (i.e. RDS Server Lock Down). In Security Filtering delete Authenticated Users, add RDS Server Account, and the security
    group created in previous step.
    Please check beneath article might useful for better understanding.
    Lock Down Remote Desktop Services Server 2012
    How to secure your remote desktop server with GPO
    Hope it helps!
    Thanks,
    Dharmesh

  • New housing/fascia for nokia 7373

    hi can anybody tell me were i can buy a new fascia/housing for a 7373, i have tried loads of places with no joy, i need a new 1 as i have a crack in my screen!
    thanks.

    ema7373
    Try this website http://shop.nokia.co.uk/ or contact your local Nokia Service Centre
    Today Me Tomorrow You

  • Ecc6, after i've changed all the passwords for all oracle users, then how

    ECC6, after i've changed all the passwords for all oracle users, now sap can't connect to oracle , then,  How can i config the sap to make sure it can boot normal?
    If our database is sqlserver, i've changed the database password for all database users, then, How can i config the sap?
    Thanks!

    My db is oracle ,                           the oracle host name is dbserver.
    The sap ap server only install the SAP. SAP host name is apserver.
    Just now i've altered all the password of the oracle database db user account, Include the account "sys".
    (I must alter the password.)
    Now the SAP service in the host "apserver" can't boot.
    Could you teach me  how can i config the "apserver" to make the SAP normal boot ?
    Thanks!
    Best regards!

Maybe you are looking for

  • Error while J1INCHLN - Business Place for document  could not be determined

    Dear All Experts, I am getting below error while running J1INCHLN Business Place for document could not be determined. For updating Business Place & Section Code I am running J1INPP Update Business Place information in FI document. So I am getting er

  • JAVA_HOME does not point to the JDK Error.

    Hello Friends,                      I unable build my local DC due problem with JAVA_HOME Parameter. I am using j2sdk1.4.2_08. Is this a problem. (JDK Version). I have checked the file C:\usr\sap\J2E\JC00\work\dev_server0 I got the following error wh

  • How to modify a class in .jar and compile it back

    Hi, I have questions reg .jar, I need to test my application and I need to modify certain files in that .jar and compile it back. How do I do that? I have extract all the classes and decompile it to .java, and I just want to edit just 1 file, but I a

  • Fonts missing in PSE7

    I just installed PSE7 on a new Windows 7 computer, but there seem to be some font styles missing from my choices in the drop-down list that had been available on my other computer. My previous install was on another Windows 7 PC. Any ideas?

  • Enhancing standard ESS Component

    Hi Experts, I am going to make changes in standard ESS component in WD ABAP through enhancement button given on menu by creating an enhancement implementation. I want to know is it the right way to create enhancement and suppose any enhancement packa