SCCM 2012 AD Publishing in a Single Forest Multiple Domains

Hi there,
Let me explain the situation first so that you get the idea. We have a single forest, multiple child domains AD environment. For some reasons each domain is being managed separately by their geographic location IT.
Forest has been extended for SCCM by the site who holds the forest root domain. Since everyone wants to manage their own domain and systems, each child domain have their own primary site server.
In one of the domains I have installed brand new SCCM 2012 R2. I haven't done anything yet, havent turned on any discovery except Heartbeat. Now I see one device, which belongs to another domain with totally separate IP address, shows in my SCCM site. I dont
know why.
From here question arises for me. Correct me if I'm wrong and please advice what to do domain/forest wide.
1. System Container is needed in each child domain, not in the forest, right?
2. Where does/should each SCCM primary site publish information; in each domain or in the forest root domain?
3. Under Administration > Overview > Site Configuration > Sites > Properties > Publishing I see forest root domain name and its checked. 
Under Administration > Overview > Hierarchy Configuration > Active Directory Forests > Properties > Publishing my site is checked and its the only one in there. In that same window I went ahead and specified my own domain hoping
to cure the possible problem.
So, why would that one device show up in this site? I have disabled Heartbeat together with other discoveries for now till I make everything ready.
Thanks for your help in advance.

1. Under Administration > Overview > Site Configuration > Sites > Properties > Publishing If I uncheck forest root domain will devices on my child domain still be able to find my site server?
2. Under Administration > Overview > Hierarchy Configuration > Active Directory Forests > Properties > Publishing my site is checked and its the only one in there. In that same window I went ahead and specified my own domain
hoping to cure the possible problem. Is this a good practice?
3. "When clients look for ConfigMgr info, they use GC lookups meaning they return objects from every System Management container in the forest." So, which one do clients choose and how?
4. "For that one device, have you opened its properties and examined it?" Yes, what abou it? Its found based on Heartbeat Discovery agent (when heartbeat was enabled).
5. "Have you reviewed the boundaries and boundary groups set up for site assignment?" Yes, as I mentioned this device belongs to different domain and totally outside of my AD site and SCCM boundaries.
This is fresh install and not in production yet. I have disabled Heartbeat temporarily so that I fix this problem. I will enable it after. 

Similar Messages

  • Understanding Lync 2013 Deployment for Single forest multiple domain Infrastructure

    Hello Everyone,
    I have an issue in understanding a deployment scenario of Lync 2013 Enterprise edition.
    We have a single forest multiple domain infra. 
    My My question here is, while AD prep, do we need to run Domainprep on every domain in the forest. 
    Thanks!
    Thank You!!! BR, Ammi.

    Hi Ammi,
    To prepare Active Directory Domain Services for your Lync Server 2013 deployment, you must perform three steps in a specific sequence.
    1.
     Preparing the Active Directory schema in Lync Server 2013
    Extends the Active Directory schema by adding new classes and attributes that are used by Lync Server.
    Run once for each forest in your deployment where Lync Server will be deployed.
    2. Preparing the forest for Lync Server 2013
    Creates global settings and universal groups that are used by Lync Server.
    Run once for each forest in your deployment where Lync Server will be deployed.
    3. Preparing domains for Lync Server 2013
    Adds permissions on objects to be used by members of universal groups.
    Run once per user domain or server domain.
    Hope it can be helpful.
    Best regards,
    Eric

  • Exchange 2003 migrate to Exchange 2010 - single forest multiple domain. Active Sync problem

    Hi All, 
    I have AD single forest and multiple domain. for example, the forest domain is jakarta.co.id, and the other domain is bali.co.id.
    Exchange 2003 deployed in jakarta.co.id, User mail enabled in domain jakarta.co.id and bali.co.id.
    Then, I upgrade to Exchange 2010 (deploy in jakarta.co.id) and move mailbox from Exchange 2003 to Exchange 2010.
    All users in bali.co.id are able to access email from Owa, BlackBerry (BIS), Outlook, but cannot access from Android, Windows Phone. (Active-Sync).
    I got error information generated from https://testconnectivity.microsoft.com, as following:
    Attempting the FolderSync command on the Exchange ActiveSync session.
    The test of the FolderSync command failed.
    Tell me more about this issue and how to resolve it
    Additional Details
    Exchange ActiveSync returned an HTTP 500 response (Internal Server Error).
    Active-Sync still not work even I check option "Include inheritable permissions from this object" in security tab.
    any idea to fix this issue?
    Thanks.
    Endrik
    Endrik | blog: itendrik.wordpress.com Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

    Hi Sathish, 
    We are planning to migrate Exchange 2003 to Exchange 2013, all user already in Exchange 2010 and Exchange 2003 was decommissioned
    Event Viewer log as following:
    Log Name:      Application
    Source:        MSExchange ActiveSync
    Date:          1/17/2014 10:00:48 PM
    Event ID:      1008
    Task Category: Requests
    Level:         Warning
    Keywords:      Classic
    User:          N/A
    Computer:      EXC2010.jakarta.co.id
    Description:
    An exception occurred and was handled by Exchange ActiveSync. This may have been caused by an outdated or corrupted Exchange ActiveSync device partnership. This can occur if a user tries to modify the same item from multiple computers. If this is the case,
    Exchange ActiveSync will re-create the partnership with the device. Items will be updated at the next synchronization. 
    URL=/Microsoft-Server-ActiveSync/default.eas?Cmd=Sync&User=bali%5Csteveng&DeviceId=SAMSUNG123456789&DeviceType=SAMSUNGGTN7000
    --- Exception start ---
    Exception type: Microsoft.Exchange.AirSync.AirSyncPermanentException
    Exception message: A null value was received for the NTSD security descriptor of container CN=ExchangeActiveSyncDevices,CN=Steven Gerrard,OU=IT,DC=bali,DC=co,DC=id.
    Exception level: 0
    HttpStatusCode: 500
    AirSyncStatusCode: 110
    XmlResponse: 
    This request does not contain a WBXML response.
    Exception stack trace:    at Microsoft.Exchange.AirSync.ADDeviceManager.SetActiveSyncDeviceContainerPermissions(ActiveSyncDevices container)
       at Microsoft.Exchange.AirSync.ADDeviceManager.CreateActiveSyncDeviceContainer(Boolean retryIfFailed)
       at Microsoft.Exchange.AirSync.ADDeviceManager.CreateActiveSyncDevice(GlobalInfo globalInfo, ExDateTime syncStorageCreationTime, Boolean retryIfFailed)
       at Microsoft.Exchange.AirSync.ADDeviceManager.CreateActiveSyncDevice(GlobalInfo globalInfo, ExDateTime syncStorageCreationTime)
       at Microsoft.Exchange.AirSync.Command.UpdateADDevice(GlobalInfo globalInfo)
       at Microsoft.Exchange.AirSync.Command.CompleteDeviceAccessProcessing()
       at Microsoft.Exchange.AirSync.Command.WorkerThread()
    --- Exception end ---.
    I think KB817379 is not related because Exchange 2003 was decommissioned.
    Regards, 
    Endrik
    Endrik | blog: itendrik.wordpress.com Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

  • Identity firewall with Single Forest/Multi-Domain

    I have a question with regard to setting up the ID firewall on the ASA 5585 in a single forest, multiple domain windows network.
    Currently I have a semi-operational IDF at the top level but can't find users on the lower other domains, here is the setup:
    I have 3 domains.
    domain1.test.com
    domain2.domain1.test.com
    domain3.domain2.domain1.test.com
    Both domains have a two way parent-child trust and I can look for users in AD Users/Computer on both domains.  I initially setup the ASA to look at domain1.test.com using an LDAP aaa-server per the IDF instructions, and then proceeded to configure the ad-agent.  I installed the adagent on the domain1.test.com domain controller configured the settings on that system and had no problem adding users to the firewall and getting functionality within domain1.  I looked to see if I could see domain 2 and domain 3 users and found none.  I went ahead and added the domain2 system to the adagent on the DC and the system says that it is up, but when I search for users is not pulling them from domain2.  Instead, it shows domain1 users as domain2\user1.  I also configured another adserver in the ASA to search ldap on domain 2 to no avail.
    The cisco documentation states the following:
    •Before you configure even a single domain controller machine using the adacfg dc create command, ensure that the AD Agent machine is first joined to a domain (for example, domain J) that has a trust relationship with each and every domain (for example, domain D[i]) that it will monitor for user authentications (through the domain controller machines that you will be configuring on the AD Agent machine).
    Single Forest, Multiple Domains—All the domains in a single forest already have an inherent two-way trust relationship with each other. Thus, the AD Agent must first be joined to one of the domains, J, in this forest, with this domain J not necessarily being identical to any of the domains D[i] corresponding to the domain controller machines. Because of the inherent trust relationship between domain J and each of the domains D[i], there is no need to explicitly configure any trust relationships.
    Reading that it sounds like it should just work.  I had everything properly configured before I installed the adagent, but I'm guessing that there is a chance that you can't have the adagent on the top level DC and get to communicate with the lower level domains.  I wanted to ask though before I blow everything up and start over.  The instructions are not overwhelming clear on what needs to done in this scenario.  Suggestions?

    Hi Matthew,
    If I understand your post correctly, the problem is that the ASA is unable to search users in domain2, correct? This portion of the communication is unrelated to the AD Agent, but it sounds like the Agent can talk to the DC just fine. The ASA searches for users directly on the DC via LDAP queries. The communication between the ASA and the Agent is all done via RADIUS.
    If the above is correct, I would focus on why the LDAP queries are failing between the ASA and the domain2 DC. Feel free to open a TAC case on this as well for additional assistance from the AAA experts.
    -Mike

  • Database instance for SCCM 2012 and WSUS on a single primary site server

    I am going to install SCCM 2012 and its SQL database on a single physical server. This is going to be a single primary site server. The default SQL instance will be dedicated to SCCM 2012 with no other named instances to be added on the SQL server down
    the road.
    During the WSUS server role installation, there is the Database Options page asking for using (1) Windows Internal Database, (2) existing db server on this computer, or (3) an external db server.
    Since SCCM 2012 doesn't share db instance with others, how should I handle the WSUS db that's going to be hosted on the same SCCM/SQL physical server? Do I really need to create a separate SQL instance just for the WSUS db?
    Thanks and regards. 

    Even though you can do it, it is the best practice to have SCCM 2012 and WSUS installed on separate instances.
    http://technet.microsoft.com/en-us/library/hh692394
    When the Configuration Manager and WSUS databases use the same SQL Server and share the same instance of SQL Server, you cannot easily determine the resource usage between the two applications. When you use a different SQL Server instance
    for Configuration Manager and WSUS, it is easier to troubleshoot and diagnose resource usage issues that might occur for each application.

  • SCCM 2012 R2 Computer reports not displaying users and domain information for some systems.

    I have a recently deployed SCCM 2012 R2 server which has been running well so far.
    I have, however, noticed in the reporting (example: "Computers in a specific site" report) that some computers are not showing information like "User domain" and "User Name" (for about 500 of the 1500 computers).
    If I go to a collection, select such a computer and right click to properties and go to the general tab I can see that the below fields are blank:
    Last Logon User Domain
    Last Logon User Name
    All other fields are populated similarly for both affected and non-affected agents. Agent versions are the same as well. Hardware/Software inventory appears to be completing on all systems.
    Has anyone else seen this type of behavior and found a solution? Appreciate any advice. Thanks.
    Edit: Most agents have been installed for close to 2 months.
    Hardware inventory: Daily
    Software inventory: Weekly

    Hi,
    Those two values are populated by the Heartbeat agent and if no user is logged on when the heartbeat is sent, then the value is blank so I would say this would be as expected.
    If you want to know which user has been using a computer you should have a look at the assett Intelliengence reports with console usage, then you can see who has been using a computer most frequently.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Install Exchange server 2010 in Single forest Multiple AD domain Scenario

    Hello Folks,
    I am trying to install a new exchange 2010 server in an enviroment which never had exchange.
    Below is the env details
    1 Forest
    3 AD domains
    Coustmer's requirement is that he wants to install exchange in only domain and other domain will not have exchange server the domain A which has server install should host the exchange mailbox's for other 2 domains and also capable enough to handle
    the mailflow of each domain with diffrent SMTP domain. Have done research but havent got the exact scenario.
    Now i am confused on how to start with this project any feedback inputs would be of great help to me.
    BR/Deepak

    Exchange server is forest wide role, so it does not depend much on number of domains in the same forest. Usually, you install Exchange in forest root domain in your forest, and Exchange will host mailboxes from any user from entire forest. So, actually,
    your scenario is supported by default :). Just go and install Exchange in one domain. As soon as you prepare other domains for Exchange recipients, you will be able to create mailboxes from all domains in your forest.
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Damir

  • SCCM 2012 R2 - Secondary site in other forest

    Hello,
    I've a question about secondary site deployment. Currently, we've a standard sccm infrastructure with only one primary site.
    We want to integrate a distant site with low  bandwith and in a other forest. This forest is administrate by someone on site. That people must have SCCM administration rights only for his forest.
    Secondary Site is it the best method to isolate sccm rights administration ? (Maybe easier with only one Distribution Point ?)
    Secondary Site must be in the new forest or must be in the primary site forest ?
    Thank you !
    Jérémy

    A secondary site in another forest requires a trust.
    "Secondary Site is it the best method to isolate sccm rights administration ?" --> not at all! Secondaries do not add an administrative boundary. Even primaries don't. Use RBA (role based access) instead. How many clients are in each forest? Define
    "low bandwidth".
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM 2012 Access, Publisher, Infopath deployment

    I've succesfully deployed project and visio as separate apps via sccm. However due to our organisations need they require access, publuisher and infopath to not be included in the inital install. They however require it to be installed if it is requested
    I had an idea that possibly I could use an xml file
    setup.exe /config _ConfigFiles/configAccess2010.xml
    It works in theory if I test it locally. However if I put it into SCCM it deploys the full installatin of office without access.
    That would indicate that it is not reading the xml files. I was wondering if any one has come across this before or if the alternitive msp files are better to work with in this case.

    Seems that's all right when you install Office without access, publuisher and infopath from local site. I am afraid there might be something wrong on SCCM configuration.
    Whatever, this is the MSP file which is created in my site, you can download and modify based on it.
    http://1drv.ms/1cZcq2G
    Tony Chen
    TechNet Community Support

  • SCCM 2012 and Exchange Connector some how getting wrong domain when associating devices to users

    I happen to go to the SCCM software catalog site and click devices and noticed that my mobile device was not included.
    After finding my device in All Mobile Devices I found the following:
    For my device the connect assigned Foo\UserName where it should have actually been Bar\UserName.
    Our domain is foo.domain but when we log in to computers we use bar\Username. If I login as
    [email protected] authentication works.
    So how do I get the SCCM Exchange connector to select Bar\UserName and not foo\username? I'm guessing that this is actually an Exchange issue but I figure I would ask here first.
    Thanks!

    Since no one has answer this post, I recommend opening  a support case with CSS as they can work with you to solve this problem.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • SCCM 2012 R2: easy way to disable/enable MULTIPLE maintenance windows at once?

    I have been racking my brain on this one for a while.
    Scenario: you have an ADR set up that is deploying updates once a month. You have multiple collections set up that each have their own special maintenance window (example: 1st weekend - sat - 8-9pm)
    Then, one week you are asked to not deploy updates for the upcoming weekend. Well, the ADR already ran and the machines for "1st weekend" are just waiting for the maintenance window to open. Now, at this point you can obviously go into EACH collection
    associated with "1st weekend" and disable the maintenance window. But if you are asked to do this often and/or you have multiple collections with maintenance windows this could be a hassle.
    Is there a way to easily enable and disable multiple maintenance windows at a time?
    GUI: I have not found a way to select multiple collections and disable all MWs
    PowerShell-module: set-CMMaintenanceWindow doesn't appear to have ability to modify "IsEnabled" property of MWs
    PowerShell-WMI: Can't find in WMI where to modify "Isenabled" Property
    Please see my other thread
    regarding PowerShell
    What other creative options are there? Disable a service via PowerShell on members of "1st Weekend" collections? Which service? Should I be looking in SQL? Where? Other options in GUI?
    I may end up getting stuck doing this manually but I want to make sure I am not overlooking something first... it's such a simple task - just seems like there should be an easy way to accomplish this.
    (And please, for the sake of my question, lets not get into the semantics of whether or not the ADR technically DEPLOYS the updates or not.)

    I didn't even think about that.... so having one MW that is disabled or having no MW at all would allow the client to install at will? I guess I was thinking that if it had a MW but it was disabled it just wouldn't update.
    The MWs on the collections are all different.
    Perhaps I need to re-assess my approach...
    The original plan was to have one ADR (patch tuesday) update 1 SUG (which is deployed to all machines) each month. Machines would then install based off MWs.
    Now I'm thinking it might be best to have 2 ADRS:
    ADR1- updates existing SUG which is already deployed to Dev/Test machines.
    ADR2- creates new SUG - which I then manually deploy to Prod collections. 
    This would automate the deployment to Non-Prod machines but it would give me the power to withhold updates to Prod machines for the month if needed.

  • Boot\BCD error - SCCM 2012 R2

    Hi,
    This is a last ditch attempt before I throw in the towel and rebuild the server. 
    I am running an SCCM 2012 R2 Hierarchy with two primaries and multiple distribution points. 
    One of our main DPs has started coming up with an error when pxe booting a windows 7 machine. This happened after a corrupt driver was added to the boot image. The driver was removed and all the DP's rolled back but the issue still remains on this server
    alone. We use an IPhelper to point the pxe requests at this server. 
    The error message is:
    File: \Boot\BCD
    Status: 0xc0000098
    Info: The Windows Boot Configuration Data file does not contain a valid OS entry. 
    I have tried the following:
    1. Removing the PXE role and reapplying it.
    2. Removing the Boot images and reapplying them.
    3. Removing the DP altogether from the console and reapplying. 
    4. Removing all data from the DP and starting again. 
    5. Redistributing the boot images. both x86 and x64
    6. creating a new boot image for both x86 and x64 and applying those.
    smspxe log is as follows 
    D4:3D:7E:BF:11:A4, 00000000-0000-0000-0000-D43D7EBF11A4: device is not in the database.
    SMSPXE 20/10/2014 09:30:44
    5064 (0x13C8)
    Warning: Matching Processor Architecture Boot Image (0) not found
    SMSPXE 20/10/2014 09:30:44
    5064 (0x13C8)
    D4:3D:7E:BF:11:A4, 00000000-0000-0000-0000-D43D7EBF11A4: Not serviced.
    SMSPXE 20/10/2014 09:30:44
    5064 (0x13C8)
    Warning: Matching Processor Architecture Boot Image (0) not found
    SMSPXE 20/10/2014 09:31:04
    5064 (0x13C8)
    D4:3D:7E:BF:11:A4, 00000000-0000-0000-0000-D43D7EBF11A4: Not serviced.
    SMSPXE 20/10/2014 09:31:04
    5064 (0x13C8)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 09:33:20
    2208 (0x08A0)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 09:33:20
    2208 (0x08A0)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 10:33:20
    5012 (0x1394)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 10:33:20
    5012 (0x1394)
    Found new image CAS00004 SMSPXE
    20/10/2014 10:53:11 6076 (0x17BC)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 10:53:11
    6076 (0x17BC)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 10:53:11 6076 (0x17BC)
    Opening image file D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
    SMSPXE 20/10/2014 10:53:11
    6076 (0x17BC)
    Found Image file: D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
     PackageID: CAS00004
     ProductName: Microsoft® Windows® Operating System
     Architecture: 0
     Description: Microsoft Windows PE (x86)
     Version:  
     Creator: 
     SystemDir: WINDOWS
    SMSPXE
    20/10/2014 10:53:11 6076 (0x17BC)
    Closing image file D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
    SMSPXE 20/10/2014 10:53:11
    6076 (0x17BC)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 10:53:40
    6076 (0x17BC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 10:53:40
    6076 (0x17BC)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 10:58:12
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 10:58:12
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 10:59:07
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 10:59:07
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:00:05
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:00:05
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:05:24
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:05:24
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:06:05
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:06:05
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:07:15
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:07:15
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:07:58
    4928 (0x1340)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:07:58
    4928 (0x1340)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:09:31
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:09:31
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:11:58
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:11:58
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:13:52
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:13:52
    4664 (0x1238)
    Client lookup reply: <ClientIDReply><Identification Unknown="0" ItemKey="0" ServerName=""><Machine><ClientID/><NetbiosName/></Machine></Identification></ClientIDReply>
    SMSPXE
    20/10/2014 11:15:27 5064 (0x13C8)
    E8:03:9A:B3:F3:8A, 163A84E0-1DD8-11B2-8000-DF82815C2DDB: device is not in the database.
    SMSPXE 20/10/2014 11:15:27
    5064 (0x13C8)
    Getting boot action for unknown machine: item key: 2046820364
    SMSPXE 20/10/2014 11:15:27
    5064 (0x13C8)
    Client boot action reply: <ClientIDReply><Identification Unknown="0" ItemKey="2046820364" ServerName=""><Machine><ClientID>47938388-164c-4bfb-8621-28b57859ad3c</ClientID><NetbiosName/></Machine></Identification><PXEBootAction
    LastPXEAdvertisementID="" LastPXEAdvertisementTime="" OfferID="PNL20009" OfferIDTime="26/02/2014 15:13:00" PkgID="PNL0000C" PackageVersion="" PackagePath="http://INTCMNCLDP001.intraining.co.uk/SMS_DP_SMSPKG$/CAS00004"
    BootImageID="CAS00004" Mandatory="0"/></ClientIDReply>
    SMSPXE
    20/10/2014 11:15:27 5064 (0x13C8)
    E8:03:9A:B3:F3:8A, 163A84E0-1DD8-11B2-8000-DF82815C2DDB: found optional advertisement PNL20009
    SMSPXE 20/10/2014 11:15:27
    5064 (0x13C8)
    Getting boot action for unknown machine: item key: 2046820364
    SMSPXE 20/10/2014 11:16:14
    5064 (0x13C8)
    Client boot action reply: <ClientIDReply><Identification Unknown="0" ItemKey="2046820364" ServerName=""><Machine><ClientID>47938388-164c-4bfb-8621-28b57859ad3c</ClientID><NetbiosName/></Machine></Identification><PXEBootAction
    LastPXEAdvertisementID="" LastPXEAdvertisementTime="" OfferID="PNL20009" OfferIDTime="26/02/2014 15:13:00" PkgID="PNL0000C" PackageVersion="" PackagePath="http://INTCMNCLDP001.intraining.co.uk/SMS_DP_SMSPKG$/CAS00004"
    BootImageID="CAS00004" Mandatory="0"/></ClientIDReply>
    SMSPXE
    20/10/2014 11:16:14 5064 (0x13C8)
    E8:03:9A:B3:F3:8A, 163A84E0-1DD8-11B2-8000-DF82815C2DDB: found optional advertisement PNL20009
    SMSPXE 20/10/2014 11:16:14
    5064 (0x13C8)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:26:15
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:26:15
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:27:12
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:27:12
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:27:25
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:27:25
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:28:36
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:28:36
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:29:41
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:29:41
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:30:43
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:30:43
    4664 (0x1238)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:33:20
    4664 (0x1238)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:33:20
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:33:51
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:33:51
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:35:31
    4664 (0x1238)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:35:31
    4664 (0x1238)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:37:29
    6076 (0x17BC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:37:29
    6076 (0x17BC)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:39:25
    6076 (0x17BC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:39:25
    6076 (0x17BC)
    ================= PXE Provider shutdown. =====================
    SMSPXE 20/10/2014 11:42:25
    4700 (0x125C)
    ================= PXE Provider loaded. =====================
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Machine is running Windows Longhorn. (NTVersion=0X603, ServicePack=0)
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Initializing PXEPerfObject. SMSPXE
    20/10/2014 11:43:19 4372 (0x1114)
    Could not load logging configuration for component ccmperf. Using default values.
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    HTTP is selected for Client. The current state is 0.
    SMSPXE 20/10/2014 11:43:19
    4372 (0x1114)
    Client lookup reply: <ClientIDReply><Identification Unknown="0" ItemKey="0" ServerName=""><Machine><ClientID/><NetbiosName/></Machine></Identification></ClientIDReply>
    SMSPXE
    20/10/2014 11:43:20 4372 (0x1114)
    PXE::CBootImageInfo::CBootImageInfo: key= SMSPXE
    20/10/2014 11:43:20 4372 (0x1114)
    PXE::CBootImageInfo::CBootImageInfo: key= SMSPXE
    20/10/2014 11:43:20 4372 (0x1114)
    Adding CAS00004.40 SMSPXE
    20/10/2014 11:43:20 4372 (0x1114)
    Adding CAS00005.45 SMSPXE
    20/10/2014 11:43:30 4372 (0x1114)
    Found new image CAS00004 SMSPXE
    20/10/2014 11:43:44 4372 (0x1114)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 11:43:44
    4372 (0x1114)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 11:43:44 4372 (0x1114)
    Opening image file D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
    SMSPXE 20/10/2014 11:43:44
    4372 (0x1114)
    Found Image file: D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
     PackageID: CAS00004
     ProductName: Microsoft® Windows® Operating System
     Architecture: 0
     Description: Microsoft Windows PE (x86)
     Version:  
     Creator: 
     SystemDir: WINDOWS
    SMSPXE
    20/10/2014 11:43:44 4372 (0x1114)
    Closing image file D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
    SMSPXE 20/10/2014 11:43:44
    4372 (0x1114)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:44:34
    2028 (0x07EC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:44:34
    2028 (0x07EC)
    Found new image CAS00005 SMSPXE
    20/10/2014 11:44:56 4372 (0x1114)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 11:44:56
    4372 (0x1114)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 11:44:56 4372 (0x1114)
    Opening image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:44:56
    4372 (0x1114)
    Found Image file: D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
     PackageID: CAS00005
     ProductName: Microsoft® Windows® Operating System
     Architecture: 9
     Description: Microsoft Windows PE (x64)
     Version:  
     Creator: 
     SystemDir: WINDOWS
    SMSPXE
    20/10/2014 11:44:56 4372 (0x1114)
    Closing image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:44:57
    4372 (0x1114)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:45:45
    2028 (0x07EC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:45:45
    2028 (0x07EC)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:45:54
    4372 (0x1114)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:45:54
    4372 (0x1114)
    PXE Provider finished loading. SMSPXE
    20/10/2014 11:45:54 4372 (0x1114)
    Error opening file: D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim. Win32=32
    SMSPXE 20/10/2014 11:46:33
    4744 (0x1288)
    Retrying D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:46:33
    4744 (0x1288)
    Boot image CAS00005 has changed since added
    SMSPXE 20/10/2014 11:46:36
    4744 (0x1288)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 11:46:36
    4744 (0x1288)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 11:46:36 4744 (0x1288)
    Opening image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:46:36
    4744 (0x1288)
    Found Image file: D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
     PackageID: CAS00005
     ProductName: Microsoft® Windows® Operating System
     Architecture: 9
     Description: Microsoft Windows PE (x64)
     Version:  
     Creator: 
     SystemDir: WINDOWS
    SMSPXE
    20/10/2014 11:46:36 4744 (0x1288)
    Closing image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:46:36
    4744 (0x1288)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:46:53
    2028 (0x07EC)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:46:53
    2028 (0x07EC)
    Boot image CAS00005 has changed since added
    SMSPXE 20/10/2014 11:47:50
    4744 (0x1288)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 11:47:50
    4744 (0x1288)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 11:47:50 4744 (0x1288)
    Opening image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:47:50
    4744 (0x1288)
    Found Image file: D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
     PackageID: CAS00005
     ProductName: Microsoft® Windows® Operating System
     Architecture: 9
     Description: Microsoft Windows PE (x64)
     Version:  
     Creator: 
     SystemDir: WINDOWS
    SMSPXE
    20/10/2014 11:47:50 4744 (0x1288)
    Closing image file D:\RemoteInstall\SMSImages\CAS00005\boot.CAS00005.wim
    SMSPXE 20/10/2014 11:47:50
    4744 (0x1288)
    ================= PXE Provider shutdown. =====================
    SMSPXE 20/10/2014 11:47:58
    4372 (0x1114)
    ================= PXE Provider loaded. =====================
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Machine is running Windows Longhorn. (NTVersion=0X603, ServicePack=0)
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Cannot read the registry value of MACIgnoreListFile (00000000)
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    MAC Ignore List Filename in registry is empty
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Begin validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Completed validation of Certificate [Thumbprint C435C200EAF495312097132FFE12CF330A54DA8A] issued to '3ed87d92-4f15-4d7d-ba52-35dc6b972484'
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Initializing PXEPerfObject. SMSPXE
    20/10/2014 11:48:26 5008 (0x1390)
    Could not load logging configuration for component ccmperf. Using default values.
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    HTTP is selected for Client. The current state is 0.
    SMSPXE 20/10/2014 11:48:26
    5008 (0x1390)
    Client lookup reply: <ClientIDReply><Identification Unknown="0" ItemKey="0" ServerName=""><Machine><ClientID/><NetbiosName/></Machine></Identification></ClientIDReply>
    SMSPXE
    20/10/2014 11:48:26 5008 (0x1390)
    PXE::CBootImageInfo::CBootImageInfo: key= SMSPXE
    20/10/2014 11:48:26 5008 (0x1390)
    PXE::CBootImageInfo::CBootImageInfo: key= SMSPXE
    20/10/2014 11:48:26 5008 (0x1390)
    Adding CAS00004.40 SMSPXE
    20/10/2014 11:48:26 5008 (0x1390)
    Adding CAS00005.45 SMSPXE
    20/10/2014 11:48:50 5008 (0x1390)
    Found new image CAS00004 SMSPXE
    20/10/2014 11:49:15 5008 (0x1390)
    ADK installation root registry value not found.
    SMSPXE 20/10/2014 11:49:15
    5008 (0x1390)
    Loaded C:\Windows\system32\wimgapi.dll SMSPXE
    20/10/2014 11:49:15 5008 (0x1390)
    Opening image file D:\RemoteInstall\SMSImages\CAS00004\boot.CAS00004.wim
    SMSPXE 20/10/2014 11:49:15
    5008 (0x1390)
    If anyone has any further info on this please can you let me know?
    Thanks so much.
    Katie

    Hello,
    Is your WDS running properly? If WDS is stopped, can you start it manually?
    Or you get an error like 'The service did not respond in a timely fashion'?
    The symptom is so similar to that I have encountered. You referred that you have tried to remove WDS, DP, but I wonder how. Before removing WDS and DP role, try to delete corrupt package in SCCMContentLib folder.
    I just recreated SCCMContentLib, and WDS did start working. I guess there are corrupt packages in the my folder as well. But another problem occur, I installed all the roles on the same server in my lab, so it is a primary site server as well. As a result,
    it seems that I have to re-deploy all the packages. Not sure if there is any further problem yet. Since it is just a lab environment, it doesn't matter for me.
    I hope what I have done will give you some clue.

  • Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 IP for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS which is in a different .Domain

    Hi,
    Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 Ip for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS . ?
    Scenario: We are building 1 SCCM 2012 primary site and 2 DPs in one domain . In future this will attach to a CAS server which is in different domain. Can we assign  2 IPs in Primary site server , one IP will use to communicate with its 2 DPs and second
    IP for communicating with the CAS server which is in a different domain.? 
    Details: 
    1)Server : Windows 2012 R2 Std , VM environment .2) SCCM : SCCM 2012 R2 .3)SQL: SQL 2012 Std
    Thanks
    Rajesh Vasudevan

    First, it's not possible. You cannot attach a primary site to an existing CAS.
    Primary sites in 2012 are *not* the same as primary sites in 2007 and a CAS is 2012 is completely different from a central primary site in 2007.
    CASes cannot manage clients. Also, primary sites are *not* used for delegation in 2012. As Torsten points out, multiple primary sites are used for scale-out (in terms of client count) only. Placing primary sites for different organizational units provides
    no functional differences but does add complexity, latency, and additional failure points.
    Thus, as the others have pointed out, your premise for doing this is completely incorrect. What are your actual business goals?
    As for the IP Addressing, that depends upon your networking infrastructure. There is no way to configure ConfigMgr to use different interfaces for different types of traffic. You could potentially manipulate the routing tables in Windows but that's asking
    for trouble IMO.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Can an SCCM 2012 instance handle multiple Active Directories?

    Hi All,
    Historically (SCCM 2007 or
    earlier version), each active directory
    domain has need an SCCM instance. Has that changed/improved in SCCM 2012 so that each instance can handle multiple Active Directories?

    Historically (SCCM 2007 or
    earlier version), each active directory
    domain has need an SCCM instance.
    That's not true BTW.
    Torsten Meringer | http://www.mssccmfaq.de

  • Silently uninstall using sccm 2012 Manually installed software in my domain

    Dear All
    i am new to sccm 2012,
    we are experiencing headache issue in my domain.my domain users are roaming laptop users.
    we need to uninstall software silently using sccm 2012 configuration manager which software installed does not use sccm 2012(Manually installed by users).
    please share your valuable article and  suggestion according to this issue.....
    Thanks
    Parthiban.S
    [email protected]

    The most important is that you have to inventory the applications that are installed and based on that you have to decided which applications you want to remove. For those applications you can create uninstalls in ConfigMgr.
    For some information:
    http://blogs.technet.com/b/christianwb/archive/2014/03/17/using-configmgr-application-model-to-uninstall-old-software.aspx
    And: http://technet.microsoft.com/en-us/library/gg682013.aspx
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

Maybe you are looking for

  • "do not have enough access privilege" error message when trying to synch iPhone with iTunes

    Primary computer crashed and got this error message when trying to synch my iPhone to iTunes with another computer I have on my Home Share.

  • Black background in app

    while trying to close a kindle app on my iphone I changed to background in that app to black with white letters and cannot get it to change back.  Invert colors is off

  • Constant Freezing/Crashing of Browser

    After I updated Flash player this morning, it has become almost unusable!! It will work for a little while, then I get a message, "Flash plug-in is not responding". I have to kill my browser. Usually, only restarting my computer will make it work aga

  • Font Book acting very very weird, had to abandon it...

    Hi all. This happened before but this time it seems permanent... I use Chinese True Type Fonts (.TT) as part of my daily work, but I only load them when I need to use them in Photoshop. Today as usual I enable the whole lot of them in Font Book as an

  • How to stop Oracle Process Manager(Instances) ?

    Hi, I have installed OBIEE 11g. For some purpose I tried to stop the Oracle Process Manager(Instances) in services.msc. But it not get stopped its keep showing as stopping. Is there any command to force shutdown this serives or is there any other way