SCCM 2012 Design and Management

I'll preface this by saying I dont have much experience beyond setting up a stand alone primary site for SCCM 2012. 
Here's the situation:
1. Central Office in LA, CA with smaller offices in Texas and in SF (totaling about 4k clients)
a. Fast 10G link to TX
b. Slow link to SF
2. Korea office with 500 clients (slow link)
3. Europe office with 1500 clients (slow link)
4. Local IT staff managing systems and software deployment in each location. 
5. Central office would like oversight and management of other regions. 
If anyone could provide suggestions on hierarchy design that would be appreciated. 
Originally I was going to setup a CAS and a Primary Site in the US (DPs for SF and TX), and 2 other Primary Sites for KR and EU regions (Remote DPs and what not for the smaller branches within). IT staff for each region would manage their own primary. But this
apparently isn't ideal. 
My question is how a stand-alone primary design would work in this instance? And if the primary resides in the US, would administrative users have to use the console to access the primary over the slow WAN link?
I think my confusion in design comes from whether the regional admins need direct access to the Primary site or not. 
Thanks, and please excuse my ignorance. 

I'm not sure what the internet cloud is there for.  Your LA Primary should be in that spot; remember those servers all need to be able to communicate with the primary, usually on the same domain.  If what you meant by that 'internet" cloud
you really meant "Our Internal Company WAN Links", then ok.  By that I mean... I presume in SF, KR, EU... there are domain controllers servicing those locations?  then it's sorta similar to CM12.
If you really *do* mean internet is how those locations are linked, no domain trusts, then what you may be looking at is pki certificates, and internet based client management.  And/Or possibly considering leveraging Intune for those clients.
Regarding console usage; either publish the console via Citrix, or publish the console as a TS App.  i.e., publish the console from citrix via a citrix server in the same datacenter as the LA Primary--and everyone uses that console (if they need to
use the console). 
fyi/off topic... my opinion.  "helpdesk" type personnel have no need to be in the console, nor does anyone who simply needs to run reports.
Standardize. Simplify. Automate.
Correct, internal WAN links, all computers are domain joined. We will eventually move to internet management too but that seems to be something we'll tackle later down the road. 
I will need to check with the other admins to see what kind of VDI we have in place. 
Console access is for other admins to create/modify collections for their region, deploy software, etc. The console itself wont be made available to helpdesk/service desk.
response to edit:
- Correct, TX will only have a DP on a "site server" (not a secondary site). 
- link to SF would be 1GB, and change to 10GB once they move into a perm location. In my diagram they would also just receive a DP
edit 2: ok my vocab is off, when i put "site server" in the diagram i really mean "site system server"

Similar Messages

  • SCCM 2012 Design Consideration / Advice

    I have been tasked with a SCCM 2012 Design.  We will be starting a fresh so I want to get this design right the first time and looking to you all on advice / Considerations I need to look at.  Any help/feedback is appreciated.
    Company Layout:
    1 Main Office (Corporate Headquarters)
    15+ Remote Locations with T1 Connections back to Main Office
    3 Remote Locations with 100MB Connection to Main Office
    2 Remote Locations with 10MB Connection to Main Office
    2 Remote Locations with T3 Connections back to Main Office
    300+ Remote Sales Rep (Work From home, coffee shops, etc...)
    Approxamitly 3500 Clients throughout the organization
    What we want to accomplish with SCCM:
    Hardware/Software Inventory
    Computer Imaging & Users State Migration
    Deploy Packages / Applications
    Application Portal (Self Service)
    Windows/Software Updates (Even to Remote Sales Reps)
    Manage Mobile Devices
    What are your thoughts on the design?  Do we run SQL on the CAS/Primary Site Servers or do we run it on a separate server? 
    Main Office = CAS (Probably Don't need), & Primary Site, & a Distribution Point for Internet Based Clients.
    Primary Site Roles:
    Site Server
    Component Server
    SMS Provider
    Site System
    Site Database Server
    Application Catalog Web Service Point
    Application Catalog Website Point
    Distribution Point
    Management Point
    Software Update Point
    State Migration Point
    Fallback Status Point
    Remote Offices do I do all Secondary Sites or Mix and match DP or do I make some of them Primary Sites?
    Secondary Site Roles:
    Site Server
    Component Server
    SMS Provider
    Site System
    Site Database Server
    Management Point
    Distribution Point
    Software Update Service
    State Migration Point
    Fallback Status Point
    Also do you agree with the specs I am thinking for each server role?
    CAS
    8 cores (Intel Xeon 5504 or comparable CPU) 
    32 GB of RAM 
    500 GB of disk space 
    Primary
    4 cores (Intel Xeon 5140 or comparable CPU)
    16 GB of RAM
    500 GB of hard disk space 
    Secondary Site
    4 cores (Intel Xeon 5140 or comparable CPU)
    8 GB of RAM
    200 GB of hard disk space
    Distribution Points
    2 cores (Intel Xeon 5140 or comparable CPU)
    8 GB of RAM
    200 GB of hard disk space 

    Based on that you'll have a total of approx. 3500 clients in your organization I do not see the immediate requirements of secondary sites but if you have sites with approx. 500 users a secondary site is a good idea.
    IOPS is the most important thing when looking at hardware requirements for a site server due to it being SQL intensive. And it is actually only the database file storage that requires high IOPS. Due to that measuring IOPS is more of an art than science I
    cant give you any numbers but SSD drives is nice to have :)
    Based on your list of hardware I guess you've found
    http://technet.microsoft.com/en-us/library/hh846235.aspx and
    http://technet.microsoft.com/en-us/library/gg682077.aspx#BKMK_SupConfigClientNumbers
    As you wrote and that other has written, do not use a CAS for this scenario.
    If you can pull of some SSDs I would say something like
    120 GB non-SSD for OS (remember, that pagefile needs some room too!)
    80 GB non-SSD for Program Files
    64 GB SSD for Database's
    64 GB non-SSD for logs
    500 GB non-SSD for Content Source
    500 GB non-SSD for Content Library
    Figures above is an estimate for your Primary Site Server based on the information you've given. I can not guarantee these figures due to forum post. The point of this post is to show you where you need SSD/lots of IOPS for good performance.
    I usually recommend you to run your system as virtual machines due to the fact that you can use snapshots while performing upgrades and other maintenance tasks.
    Tim Nilimaa | Blog: http://infoworks.tv | Twitter: @timnilimaa

  • Wifi profiles SCCM 2012 R2 and Windows Intune

    Hi All,
    A quick question regarding SCCM 2012 R2 and the new Wifi Profiles feature...
    Can anyone confirm if you need windows Intune combined with SCCM 2012 R2 to be able to deploy WIFI profiles to users devices i.e Windows 8.1, IOS and Android platforms?  Microsoft documentation is not clear on this subject.
    Any help would be much appreciated.
    Regards PowerShell90

    It not as straight forward as one would hope. I am running the latest version of SCCM 2012 R2 CU2 connected to my Windows Intune subscription. There are a lot of hickups. One is that the direct of management needs to be all or nothing. In other words you
    either need to use Windows Intune solely to manage your devices or SCCM 2012 R2 (via connector). If the later then you must do everything from in SCCM 2012 R2. You cannot hybrid manage your devices as this will screw things up.
    Android for some reason is left out on a lot of features. I would think that MS Devs would work hard on the market share that being Android, not iOS. Any way, accord to some official MS articles Android is supported, but others claim that not all features
    are, these being the important ones like Email and Wi-Fi Profiles. They simply do not work.
    I think MS is heading in the right direction but there is a lot of work that needs to be done before this is a competitive product. I could care less if connects to my SCCM 2012 R2 server or not. Here are few things that I sent o a MS Support Rep today that
    need to be address.
    1. Better response time when updating devices after enrollment (e.g. Name change).
    2. The ability to locked down uninstalling Windows Intune from device.<o:p></o:p>
    3. The ability to locked down certain features in the Windows Intune app on device (e.g. User can reset device with Windows Intune app, rename, etc...).<o:p></o:p>
    4. Ability to rename device in either Windows Intune Admin Portal and/or SCCM 2-12 R2.<o:p></o:p>

  • SCCM 2012 R2 - Multiple Management Points

    Hi,
    We are deploying SCCM 2012 R2 and it will cover 15 geographical locations.  There will be 1 site and 1 site server with DB.  The 15 locations will each have a Distribution Point .  The number of hosts is around 10,000 total.
    Can multiple (15) Management Points be installed along with the Distribution Points to communicate back to 1 site server?  Is it necessary or even possible?
    Thanks.

    It's possible yes (with many caveats), but not generally necessary. If you are concerned about client to MP traffic, which is generally quite small (which I why I say it's generally not necessary), then the use of secondary sites is recommended instead of
    stand-alone DPs. The secondary site will then provide a local DP, MP, and SUP for clients at that location to use.
    Directly placing an MP that is part of the primary site is problematic because clients do not choose MPs within a single primary site based upon their location. Thus, placing an MP remotely does not address geographically dispersed locations/clients in any
    way and may make the problem worse. As of 2012 R2 CU3, you can hard-code MPs into clients, but this creates a bit of an overhead problem and does not address SUPs.
    Thus, as mentioned, if you are truly concerned with this traffic, secondary sites are the way to go. Without knowing how many clients are at each location and the bandwidth available to those locations, I wouldn't make a recommendation as to which to use
    though. In general, I always lean towards stand-alone DPs for remote locations unless the bandwidth is severely constrained or there are a large number of clients at that location.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Deploy Java Updates using SCCM 2012 SP1 and SCUP 2011

    What is the best way to deploy Java updates using sccm 2012 SP1 and SCUP 2011?

    I didn´t find Kent´s blog useful when talking about Java. I can deploy Adobe products fine, but I have to import Java manually because not having Shavlik certificate. So with that said, I have the fallowing problem;
    I have full offline installer unpacked, .msi file and Data1.cab. When I´m importing these binaries to SCUP, I only can point to .msi. Doing that, installation fails in client side fails because of lack of data1.cab fine, which is the main file.
    Should I use some other downloaded files of Java? I couldn´t find any Java-update-file only type of files to download.

  • SCCM 2012 Software Update Management for Windows Servers and how to automatic set SCOM maintenance mode?

    Hi,
    We planning to go one level higher to automat and have more dynamic Software Update Management for Windows Servers. We have SCCM 2012 R2, SCOM 2012 R2 and SCO 2012 R2.
    Our plan is to pur server in an AD-Group to get Update Schedule, from the servers will be importet to an Collection for Automatic Update and reboot. If I understand Everything right SCOM can't read AD-Group and put then in an Schedule maintenance mode. SCOM
    can read reg value as exempel.
    IS there any smar way to make the SCOM Maintenance Mode Schedule dynamic?
    I found this
    http://www.scom2k7.com/scom-2012-maintenance-mode-scheduler/?
    /SaiTech

    You could use Orchestrator to put the servers from a specific collection, or AD group, in maintenance mode in SCOM. For an example see:
    http://www.systemcentercentral.com/orchestrator-how-to-scom-maintenance-mode-for-windows-computers-in-an-sccm-collection/
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • SCCM 2012 SP1 and MDT 2012 Task Sequence Templates, MDT File/Settings Packages

    We're setting up SCCM 2012 integrated with MDT 2012 for our OSD. My main issue is finding actual reference material for the MDT task sequence templates when integrated with SCCM. The MDT documentation has a lot of information on variables and task sequences
    outside of SCCM integration. 
    One thing I'd love to find information on is what's actually going on during an MDT Client Task Sequence template. I found this http://social.technet.microsoft.com/Forums/en-US/645a77b2-5be6-431d-818c-57d24b1435cc/understanding-mdt-task-sequence?forum=configmgrosd but
    it doesn't delve into the kind of detail I'm looking for. I can dig up information through the MDT reference material on some things, but I just can't find anything out there that actually walks you through an SCCM/MDT task sequence template. For instance,
    under State Restore what is being referenced in Install Software with base variable name PACKAGES, vs Install Applications and base variable name COALESCED APPS. And, where are you supposed to put these applications? That's just a specific example, I'm hoping
    to find some kind of walkthrough.
    Two things I'm hazy on are the MDT packages. What exactly are the MDT Settings Package, and the MDT Files Package? What are they used for? What benefits do you get out of using them? And, how exactly do you use them? I know one of them has something to do
    with customsettings.ini, but what's the point of using SCCM with MDT if you still have to muck around in the customsettings.ini file?
    Either way, it seems like there are a lot of references to SCCM task sequences, and a lot of references to MDT task sequences. But, not together. Which is a bit annoying since the MDT-integrated task sequence templates are very obviously different than either
    SCCM or MDT by itself. Any help would be appreciated, even just information on where to look. Maybe I'm just really bad at finding reference material for SCCM/MDT. Thanks. 

    When MDT integrated with SCCM, We need the following MDT components to be created:
    MDT Boot image
    MDT Toolkit Files
    MDT Settings
    The MDT boot image (for example) gives you extra abilities over the standard ConfigMgr boot image such as the ability to display a HTA Refer here:
    http://www.windows-noob.com/forums/index.php?/forum/98-frontends-and-web-services/
    MDT Files once created, you will find UDIWizard_Config.Xml file in which you can start User driven Installation OSD using UDI designer.
    Refer these links for better understanding:
    http://www.windows-noob.com/forums/index.php?/topic/5131-using-sccm-2012-rc-in-a-lab-part-16-integrating-mdt-2012-rc1-with-configuration-manager-2012/
    http://www.windows-noob.com/forums/index.php?/topic/5221-using-sccm-2012-rc-in-a-lab-part-17-using-mdt-2012-rc1-within-configuration-manager-2012/
    http://www.windows-noob.com/forums/index.php?/topic/5250-using-sccm-2012-rc-in-a-lab-part-18-deploying-a-udi-client-task-sequence-with-mdt-2012-rc1-integrated-in-configuration-manager-2012/
    Thanks, Prabha G
    Thanks for the quick reply. But, what about the MDT Settings Package? Also, both have a pretty big folder structure for each package. Surely it does more than just provide a couple xml and ini files? I'm not looking for anyone to spoon-feed me the information,
    but at least a pointer in the right direction for finding the reference material. It seems for SCCM/MDT integration you have to go all over the place finding scraps of information to put together. 
    Also, any info on the SCCM/MDT task sequence templates? Thanks. 

  • SCCM 2012 R2 and folder SMSPCKSIG??

    Hello!
    My question is simple, SCCM 2012 SMSPCKSIG folder contains another folders and no more tar files, is a change in design?
    I' ve been looking for any article or doc in internet that explains this change but I don't find anything, please anyone can help me?
    Thanks!! 
    MCITP Exchange 2007, MCITP Windows Server 2008, MCSE Windows Server 2003 + Messaging

    This should explain all
    As of ConfigMgr 2012, Configuration Manager uses a new feature called Content Library that includes a feature for SIS / Single Instance Store. You can read more about it in the link provided by iainrobins above.
    Tim Nilimaa | Blog: http://infoworks.tv | Twitter: @timnilimaa

  • SCCM 2012 R2 Configuration Manager Client Package - stuck "In Progress"

    Hi Team; I’m having 2 issues with SCCM 2012 R2:
    Issue 1: I'm having a strange issue with the default XXX00002 package - "Configuration Manager Client Package",
    it will not deploy to the Secondary Site DP. The console is saying "In Progress" - below is the output from the
    distmgr.log file.
    ~Package BDC00002 does not have a preferred sender. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.443+240><thread=6032 (0x1790)>
    ~CDistributionSrcSQL::UpdateAvailableVersion PackageID=BDC00002, Version=1, Status=2301 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.444+240><thread=6032 (0x1790)>
    ~StoredPkgVersion (1) of package BDC00002. StoredPkgVersion in database is 1. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.462+240><thread=6032 (0x1790)>
    ~SourceVersion (1) of package BDC00002. SourceVersion in database is 1. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.462+240><thread=6032 (0x1790)>
    ~Package BDC00003 does not have a preferred sender. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.443+240><thread=6092 (0x17CC)>
    ~CDistributionSrcSQL::UpdateAvailableVersion PackageID=BDC00003, Version=1, Status=2301 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.464+240><thread=6092 (0x17CC)>
    STATMSG: ID=2301 SEV=I LEV=M SOURCE="SMS Server" COMP="SMS_DISTRIBUTION_MANAGER" SYS=BBK-SCCM-PRI.bbk2310.com SITE=PRI PID=2768 TID=6032 GMTDATE=Mon Mar 17 20:00:23.476 2014
    ISTR0="Configuration Manager Client Package" ISTR1="BDC00002" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=1 AID0=400 AVAL0="BDC00002" 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.477+240><thread=6032 (0x1790)>
    StateTable::CState::Handle - (2301:1 2014-03-17 20:00:23.476+00:00) >> (0:0 2014-02-28 16:33:45.383+00:00) 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.484+240><thread=6032 (0x1790)>
    CStateMsgReporter::DeliverMessages - Queued message: TT=1401 TIDT=0 TID='8ACCAE01-5079-4FCD-A988-C1CD3004B698' SID=2301 MUF=0 PCNT=2, P1='PRI' P2='2014-03-17 20:00:23.476+00:00' P3='' P4=''
    P5=''  $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.495+240><thread=6032 (0x1790)>
    ~StoredPkgVersion (1) of package BDC00003. StoredPkgVersion in database is 1. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.496+240><thread=6092 (0x17CC)>
    ~SourceVersion (1) of package BDC00003. SourceVersion in database is 1. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.497+240><thread=6092 (0x17CC)>
    STATMSG: ID=2301 SEV=I LEV=M SOURCE="SMS Server" COMP="SMS_DISTRIBUTION_MANAGER" SYS=BBK-SCCM-PRI.bbk2310.com SITE=PRI PID=2768 TID=6092 GMTDATE=Mon Mar 17 20:00:23.510 2014
    ISTR0="Configuration Manager Client Upgrade Package" ISTR1="BDC00003" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=1 AID0=400
    AVAL0="BDC00003"  $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.510+240><thread=6092 (0x17CC)>
    StateTable::CState::Handle - (2301:1 2014-03-17 20:00:23.510+00:00) >> (0:0 2014-02-28 16:33:45.383+00:00)
     $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.515+240><thread=6092 (0x17CC)>
    CStateMsgReporter::DeliverMessages - Queued message: TT=1401 TIDT=0 TID='8ACCAE01-5079-4FCD-A988-C1CD3004B698' SID=2301 MUF=0 PCNT=2, P1='PRI' P2='2014-03-17 20:00:23.510+00:00' P3='' P4=''
    P5=''  $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.526+240><thread=6092 (0x17CC)>
    CStateMsgReporter::DeliverMessages - Created state message file: D:\Program Files\Microsoft Configuration Manager\inboxes\auth\statesys.box\incoming\1sfb1dbj.SMX  
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.571+240><thread=6032 (0x1790)>
    Successfully send state change notification 8ACCAE01-5079-4FCD-A988-C1CD3004B698 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.572+240><thread=6032 (0x1790)>
    ~Exiting package processing thread. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.574+240><thread=6032 (0x1790)>
    CStateMsgReporter::DeliverMessages - Created state message file: D:\Program Files\Microsoft Configuration Manager\inboxes\auth\statesys.box\incoming\abaibh8y.SMX  
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.637+240><thread=6092 (0x17CC)>
    Successfully send state change notification 8ACCAE01-5079-4FCD-A988-C1CD3004B698 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.683+240><thread=6092 (0x17CC)>
    ~Exiting package processing thread. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:23.685+240><thread=6092 (0x17CC)>
    Sleep 30 minutes... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:26.886+240><thread=2936 (0xB78)>
    ~Used 0 out of 3 allowed processing threads. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:27.948+240><thread=4900 (0x1324)>
    ~Sleep 3600 seconds... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:27.950+240><thread=4900 (0x1324)>
    Sleep 30 minutes... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:31.934+240><thread=2936 (0xB78)>
    ~Used 0 out of 3 allowed processing threads. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:33.021+240><thread=4900 (0x1324)>
    ~Sleep 3600 seconds... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:33.023+240><thread=4900 (0x1324)>
    ~Used 0 out of 3 allowed processing threads. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:38.108+240><thread=4900 (0x1324)>
    ~Sleep 3600 seconds... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:00:38.111+240><thread=4900 (0x1324)>
    Sleeping for 60 minutes before content cleanup task starts.~ 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:06:28.094+240><thread=4968 (0x1368)>
    Sleep 30 minutes... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 16:30:52.271+240><thread=2936 (0xB78)>
    Sleep 30 minutes... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 17:01:10.002+240><thread=2936 (0xB78)>
    ~Used 0 out of 3 allowed processing threads. 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 17:01:10.977+240><thread=4900 (0x1324)>
    ~Sleep 3600 seconds... 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 17:01:10.979+240><thread=4900 (0x1324)>
    Sleeping for 60 minutes before content cleanup task starts.~ 
    $$<SMS_DISTRIBUTION_MANAGER><03-17-2014 17:06:55.337+240><thread=4968 (0x1368)>
    Issue 2: I'm trying to deploy a couple of Packages/Applications using SCCM 2012 R2 running on Win2K8 R2 with no luck, knowing that I could install the packages
    on a test VM “in the DataCenter site”, but when trying to deploy the packages to production PC “in the Office Site”,
     the status is packages deployment compliance stuck at 0%
    Infrastructure:
    3 SCCM servers: CAS, PRI & SEC. Both CAS and PRI are in the DataCenter site, and SEC is in the Office site. The office site has several IP subnets.
    Boundaries are configured through Forest Discovery “IP Ranges and AD Sites” since that the AD site should contain all the IP subnets that the AD site contains, Boundaries groups are also configured and a site reference
    server is configured for each group respectively.
    A OU based Collection has been configured that contains 13 PC "the collection contains the PCs that the packages should be installed.
    Packages/Applications are configured correctly since that I could successfully deploy the packages to the test VM which is on the same subnet as the CAS and the PRI servers "the DataCenter subnet". The issue
    is that I can't deploy the packages to production PCs in the Office subnet!
    Firewall rules are configured and applied via GP, and I even turned Windows Firewall off, and still nothing! I tried to manually initiate Computer Policy download via the SCCM GUI and via a script, still no luck!
    I tried configuring IP Subnet Boundaries, still no luck!!
    Here are the last 2 lines in the LocationServices.log of a client PC at the Office Site:
    <![LOG[MPLIST requests are throttled for 00:00:44]LOG]!><time="14:47:00.766+240" date="03-17-2014" component="LocationServices" context="" type="2" thread="5776"
    file="lssecurity.cpp:4528"> <![LOG[Current AD site of machine is Default-First-Site-Name]LOG]!><time="14:47:00.777+240" date="03-17-2014" component="LocationServices" context="" type="1"
    thread="4884" file="lsad.cpp:770">
    And here are the last 4 lines in the ClientLocation.log
    <![LOG[Rotating assigned management point, new management point [1] is: BBK-SCCM-PRI.bbk2310.com (7958) with capabilities: <Capabilities SchemaVersion="1.0"><Property Name="SSLState"
    Value="0"/></Capabilities>]LOG]!><time="14:49:04.880+240" date="03-17-2014" component="ClientLocation" context="" type="1" thread="3600" file="lsad.cpp:6311">
    <![LOG[Assigned MP changed from <BBK-SCCM-PRI.bbk2310.com> to <BBK-SCCM-PRI.bbk2310.com>.]LOG]!><time="14:49:04.891+240" date="03-17-2014" component="ClientLocation" context="" type="1"
    thread="3600" file="lsad.cpp:1532"> <![LOG[Rotating proxy management point, new management point [1] is: BBK-SCCM-SEC.bbk2310.com (7958) with capabilities: <Capabilities SchemaVersion="1.0"><Property Name="SSLState"
    Value="0"/></Capabilities>]LOG]!><time="14:49:05.345+240" date="03-17-2014" component="ClientLocation" context="" type="1" thread="3600" file="lsad.cpp:6374">
    <![LOG[Rotating local management point, new management point [1] is: BBK-SCCM-SEC.bbk2310.com (7958) with capabilities: <Capabilities SchemaVersion="1.0"><Property Name="SSLState" Value="0"/></Capabilities>]LOG]!><time="14:49:05.786+240"
    date="03-17-2014" component="ClientLocation" context="" type="1" thread="3600" file="lsad.cpp:6436">
    It looks like clients in the Office Site can’t connect to the DP/MP of the Secondary Site server which is also a DP.
    While on the PC that the application was installed on I see the folowing in the LocationService.log:
    <![LOG[Distribution Point='http://BBK-SCCM-PRI.bbk2310.com/SMS_DP_SMSPKG$/Content_69547d2a-339f-4ac4-9523-238c79ff8a52.1', Locality='LOCAL', DPType='SERVER', Version='7958', Capabilities='<Capabilities SchemaVersion="1.0"><Property
    Name="SSLState" Value="0"/></Capabilities>', Signature='http://BBK-SCCM-PRI.bbk2310.com/SMS_DP_SMSSIG$/Content_69547d2a-339f-4ac4-9523-238c79ff8a52.1.tar', ForestTrust='TRUE',]LOG]!><time="14:42:59.506+240"
    date="03-17-2014" component="LocationServices" context="" type="1" thread="224" file="lsutils.cpp:415"> <![LOG[Calling back with locations for location request {144620BC-4BF0-4878-9554-F67D305ECCF8}]LOG]!><time="14:42:59.522+240"
    date="03-17-2014" component="LocationServices" context="" type="1" thread="224" file="replylocationsendpoint.cpp:220">
    Is there something wrong with the Distribution point on the Secondary Site server?
    Please help…
    Thanks..

    Update:
    I fixed the issue with the default XXX00002 package - "Configuration Manager Client Package", it will not deploy to the Secondary Site DP. I did that through "Update Distribution Points" option, and after a while the status was 100%.
    However; the second issue is still unsolved...
    Please help..

  • Windows 8.1 Update (with WinPE 5.1) ADK + SCCM 2012 R2 and WinXP

    Hello,
    I see new ADK version (8.1 Update) is released
    http://www.microsoft.com/en-US/download/confirmation.aspx?id=39982
    It contains WinPE 5.1 and new USMT (which version?), does it support migration from WinXP to Win7?
    Previously I used USMT5 (instead of 6.3) and modified WinPE 5.0 with bootsect.exe from WinPE 4.0 (from ADK 8.0) on SCCM 2012 R2 CU3.
    And can I use ADK 8.1 Update with SCCM 2012 R2?

    He does answer your question about the USMT version.
    The rest still applies in terms of XP support. See below.
    http://blogs.technet.com/b/mniehaus/archive/2014/01/09/migrating-from-windows-xp-to-windows-8-1-using-mdt-2013.aspx
    Yes, ConfigMgr 2012 R2 is supported.
    http://blogs.technet.com/b/configmgrteam/archive/2014/04/03/understanding-the-adk-for-windows-8-1-update-and-configmgr-osd.aspx
    Daniel Ratliff | http://www.PotentEngineer.com
    in the article I found:
    Windows PE version 5.1 is not needed for Configuration Manager and can actually be problematic if you try to use it. Windows PE 5.0 can continue to be used to deploy Windows 8.1 Update. There is a documented process to upgrade Windows PE to version 5.1,
    but this should be considered incompatible with Configuration Manager at this time.
    So for a new installation of SCCM 2012 R2 I can install ADK 8.1 update because in contains WinPE 5.0 and option to update to 5.1. And unclear about XP, it seems XP is not supported again.
    Also fourth release was in September 2014, but article was posted in April 2014.

  • SCCM 2012 license for managing Servers

    Hi,
    We want to manage windows servers with SCCM 2012. Can someone explain what are the licensing options available and how much it cost per server. 
    Regards,
    Madhan

    This came up on this forum recently. Here you go
    http://social.technet.microsoft.com/Forums/en-US/db10f78f-3c44-40fd-92a8-1264ee06dccb/configmgr-2012-licensing?forum=configmanagergeneral
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Installation of SCCM 2012 R2 and SQL Server 2014 error

    Hello All,
    I am attempting to setup SQL Server 2014 and SCCM 2012 R2 but I keep running into an error stating that "Configuration Manager requires Microsoft SQL Server
    2008 SP2 w/ CU9........ all the way up to Microsoft SQL Server 2012 with CU2 or higher." I am using all evaluation versions for this configuration as we are looking to test and evaluate the products. I was trying it with SQL 2014 because I was running
    into the same error with SQL 2012 and according to "http://blogs.technet.com/b/configmgrteam/archive/2015/03/30/updated-sc2012-configmgr-sp1-and-sc2012r2-configmgr-support-sql-server-2014.aspx" SQL
    2014 is supported with SCCM 2012 R2. SQL is installed locally on the same box. 
    Any suggestions would be appreciated.
    Thanks,
    Tucker
    Update: When running the Pre-Req check these are some of the failed returns.....
    SQL Server Edition: Failed: Configuration Manager primary site and central administration site don't support SQL Server Express Edition
    Not sure why it is recognizing SQL Express as this is a new machine.
    SQL Server service running account: Failed: The logon account for the SQL Server service cannot be a local user account, NT SERVICE\<sql service name> or LOCAL SERVICE.  You must configure
    the SQL Server service to use a valid domain account, NETWORK SERVICE, or LOCAL SYSTEM.
    For the SQL Service I am using a domain account created specifically for this.

    This has nothing to do with moving or restoring. The kb article says "This hotfix provides updated versions of the setup files and enables new installations
    of the System Center 2012 R2 Configuration Manager site database role and the System Center 2012 Configuration Manager SP1 site database role in Microsoft SQL Server 2014"
    Torsten Meringer | http://www.mssccmfaq.de

  • Using a custom certificate store for SCCM 2012 clients and primary site server

    I have read what seems to be all the pki related documentation out there for SCCM 2012. I have a PKI infrastructure up and running issueing certificates with an offline root through group policy autoenrollment. The problem that i'm faced with is we are migrating
    from SCCM 2007 that was in native mode and we chose not to use the CA that we used for the old SCCM environment. When the clients attempt to communicate with the M.P. it runs through all of the different certificates and adds a tremendous amount of overhead
    to the M.P. We will have ten's of thousands of clients by migration end. Could someone please point me to a document that goes over how to leverage a custom certificate store that I could then tell the new 2012 environment to use? I know that it's in there,
    I've seen it in the console. The setup is one primary site server with SQL on box and the pki I just mentioned as well as the old 2007 environment that is still live.
    I read that you can try and use SAN as a method of identifying the new certs but I haven't found a good document covering exactly how that works. Any info you could provide I would be very grateful for. Thanks.

    Jason, thank you for your reply. I'm getting the impression that you have never been in the situation where you had to deal with 2 different PKI environments. Let me state that I understand what your saying about trust. We have to configure the trusted root
    CA via GPO. That simply isn't enough, and I have a valid example to backup this claim. When the new clients got the advertisement and began the ccmsetup process I used the /pki switch among others. What the client end up doing was selecting a certificate that
    had the longest validity period which was issued by our old CA. It checked the authentication chain, found it to be valid and selected it for communication. At that point the installation failed, period, no caveats as you say. The reason the install failed
    because the new PKI infrastructure is integrated into the new environment, and the old is not. So when you said " that
    are trusted and they can use *any* cert that is trusted because at the end of the day, there is no
    difference between two valid certs that have the same purpose as long as they are trusted. "
    that is not correct. Both certs are trusted, and use the same certificate template, but only one certificate would allow the install to complete successfully.
    Once I started using the CCMCERTISSUERS
    switch the client install went swimmingly. The only reason I'm still debating this point is because someone might read this thread see your comments and assume "well I've got my new PKI configured as a trusted root CA, I should be all set" and their
    deployment will fail, just as my pilot did.
    About Intune I'm looking forward to doing a POC in the lab i built with my Note 3. I'm hoping it goes well as I really want to have our MDM migrated into ConfigMgr... I think the
    biggest obstacle outside of selling it to management will be the actual device migration from the current MDM solution. From what I understand of the enrollment process manual install and config is the only path forward.
    Thanks Jason for your post and discussion.

  • SCCM 2012 R2 Power Management - Machine Wake Up Time is Randomly Offset

    We have recently migrated to SCCM 2012 R2 from SCCM 2007 R3. Since moving the clients to the SCCM 2012 R2 server I have noticed that the Power Management Wakeup Timer is not working as it used to.
    Power Management is configured as follows:
    Peak Hours: 5:30AM - 6:00PM
    Wakeup Time: 5:30AM
    Previously, all power management configured clients would wakeup at around 5:30AM, some a minute or so before, some a minute or so after. Now they are on SCCM 2012 R2, I'm finding that they are waking up anywhere from 5:30AM to 7:30AM. At first
    I thought this was due to the Deadline Randomization settings, so I set "Disable deadline randomization" to Yes on the Computer Agent. However, the machines are still waking up at random times. To ensure the change was propagated properly,
    I changed the Wakeup Time by 1 min to 5:29AM and updated policy on a few test machines, but no joy.
    Does anyone know why this is occurring?
    Thanks
    Kate

    Hi,
    This setting determines whether the client uses an activation delay of up to two hours to install required software updates and required applications when the deadline is reached. By default, the activation delay is disabled.
    If required software updates and required applications must install without delay when the configured deadline is reached, select
    Yes for this setting.
    For more infomation, please review the link below:
    Disable deadline randomization
    http://technet.microsoft.com/en-us/library/4acd0c29-e453-4863-8194-e479263291c8#BKMK_ComputerAgentDeviceSettings
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Sccm 2012 migration and MDT

    In our current environment we have sccm 2007 and MDT 2013 separate to deploy workstation OS images. We have MDT just referencing SCCM package ID's (package path on the DP) to install applications during the build process.
    We are currently migrating to SCCM 2012 and because the DP folder structure has changed now - i.e. 'SCCMContentLib' can we still use MDT separately and reference the 'DataLib' directory in MDT or is the best option to fully integrate MDT in SCCM?

    Hi,
    The following two blog could help you to understand SCCMContentLib structure.
    An adventure in the sccmcontentlib - single instance store
    http://blogs.technet.com/b/hhoy/archive/2012/05/31/an-adventure-in-the-sccmcontentlib-single-instance-store.aspx
    Understanding the Configuration Manager Content Library
    http://blogs.technet.com/b/configmgrteam/archive/2013/10/29/understanding-the-configuration-manager-content-library.aspx
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

Maybe you are looking for

  • Where can I reload the games for my Nokia 5130?

    I've accidentally deleted them so I need a link to get them back. Thanks

  • Needed Help on database lookups Scenario

    Hi All, I'm Trying work with database lookups and i wanted to do this scenario [url]  /people/siva.maranani/blog/2005/08/23/lookup146s-in-xi-made-simpler [url] I need to retrive data from  DB2 database on my system im facing problems with the UserDef

  • Latest Security Update.... WHAT IS GOING ON!?

    Seems like tons of people are having problems. My main issue is that my dock is freezing whenever I right click on anything in it. The menu pops up but then the whole dock freezes and I have to click around/wait a few minutes before everything comes

  • SQL Fails when a division is included in query (in Java Code)

    Not sure this is the correct Forum to as this: Running Oracle 10g R2 on XP/Vista I have a query that contains a division operation (y.value as x.value/z.value) runs in SQLPlus and The NetBeans 6.5.1 Query Editor OK but when I insert it into Java (1.6

  • Transparent graphic not completely transparent

    I have a line graph on which a gradient arc has been built in the lower left corner. This was in a Freehand file (created by a coworker) I've imported into Illustrator CS2 and am updating. In this file I am importing a graphic from Photoshop that has