SCCM 2012 R2 - Secondary site in other forest

Hello,
I've a question about secondary site deployment. Currently, we've a standard sccm infrastructure with only one primary site.
We want to integrate a distant site with low  bandwith and in a other forest. This forest is administrate by someone on site. That people must have SCCM administration rights only for his forest.
Secondary Site is it the best method to isolate sccm rights administration ? (Maybe easier with only one Distribution Point ?)
Secondary Site must be in the new forest or must be in the primary site forest ?
Thank you !
Jérémy

A secondary site in another forest requires a trust.
"Secondary Site is it the best method to isolate sccm rights administration ?" --> not at all! Secondaries do not add an administrative boundary. Even primaries don't. Use RBA (role based access) instead. How many clients are in each forest? Define
"low bandwidth".
Torsten Meringer | http://www.mssccmfaq.de

Similar Messages

  • SCCM 2012 R2 Secondary site server will support the DMZ Zone?

    We are planning for SCCM 2012 Migration, currently we have separate Primary server in DMZ.
    Kindly suggest what is the best method to deploy in the DMZ (separate primary or secondary or DP) because we have only 500 Client in DMZ.

    Hi,
    There is a blog talking about this error. You could try the method in the blog.
    To summarise, when installing SCCM 2012 SP1 secondary site on a pre-configured SQL 2012 instance regardless which SQL edition is being used, “NT AUTHORITY\SYSTEM” account needs to be given
    securityadmin and sysadmin rights. If SQL Express is used, there are few additional steps need to be carried out to configure the SQL TCP connection as documented in my previous blog:
    http://blog.tyang.org/2012/04/09/installing-sccm-2012-rtm-secondary-site-using-a-pre-installed-sql-express-2008-r2-instance/
    Installing SCCM 2012 SP1 Secondary Site with a Pre-Configured SQL 2012 Instance
    Note:
    Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    Best Regards,
    Joyce
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • SCCM 2012 SP1 Secondary Site installation Fails

    Hi.
    I have multiple secondary sites when i am  trying to install  new SCCM 2012 Secondary site server remotely but installation status shows a pending from last few days.
    1) SEC server have privilages on System managent container
    2) Primary site Server account and computer have local admin right on SEC server
    hman logs says the following error message
    Cannot get SQL Certificate from site xxx
    CheckParentSQLServerCertificate: Failed to get SQL certificate for site XXX
    1) Deleted the secondary site and reinstalled the site with different Site code but no luck
    2) Able to telnet 1433 and 4022 from both primary to secondary and vice versa
    3) SQL server Configuration Manager , TCP IP port was set to 1433.
    please let me know if any thing i am missing
    Thanks

    Hi Guys
    Exact same problem as described above:
    Been told to install SQL Express manually first, but even after that, we continued to get the same problem.
    The SQL Communication between the 2 sites doesn't seem to work.
    I noticed that the Primary's SQL Security Account doesn't get created on Primary DB, in the Database replication the link has not yet been created either.
    The "Exec spDrsSendSubscriptionInvalid 'Secondary 3 digit site code','Primary 3 digit site code','configuration data'" worked on 1 Secondary, but fails on all the rest.
    Uninstalling/Installing the Secondary doesn't work either.
    HMAN.LOG:
    Update site server active directory informtion into DB SMS_HIERARCHY_MANAGER 2013/07/28 09:51:12 AM 7964 (0x1F1C)
    CheckSQLServiceRestart : SQL Service hasn't been restart since last time we check, skip it. SMS_HIERARCHY_MANAGER 2013/07/28 09:51:12 AM 7964 (0x1F1C)
       Time to verify if the parent['PRI-SITECODE'] sql server certificate is still valid on site ['SEC-SITECODE'] sql server. SMS_HIERARCHY_MANAGER 2013/07/28 09:51:12 AM 7964 (0x1F1C)
    Cannot get SQL Certificate from Site 'PRI-SITECODE'. SMS_HIERARCHY_MANAGER 2013/07/28 09:51:12 AM 7964 (0x1F1C)
    CheckParentSQLServerCertificate: Failed to get SQL certificate for site PM2 SMS_HIERARCHY_MANAGER 2013/07/28 09:51:12 AM 7964 (0x1F1C)
    Any ideas would be appreciated.

  • SCCM 2012 R2 Secondary Site SQL Express Prerequisites

    Reading Microsoft's 2012 R2 Upgrade checklist (technet.microsoft.com/en-us/library/jj822981.aspx#BKMK_UpgradeR2Checklist ) it says that Secondary Sites now require SQL Server Express 2012 CU2 for new site installs.  Is this also true for Secondary
    sites prior to the upgrade from SP1 to R2?  Does a non R2 SCCM Seconday work with/support SQL Express 2012 CU1?
    Any help would be appreciated.
    Thanks
    Dave

    According to the supported sql version list, a minimum of CU2 is required. See:
    http://technet.microsoft.com/en-us/library/gg682077.aspx#BKMK_SupConfigSQLDBconfig
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • SCCM 2012 R2 Secondary Site client assignment

    I have been doing some research and discovered that you shouldn't directly assign a boundary group to a secondary site. This confuses me a little bit and I was hoping someone can clear it up a bit.
    Currently my client has a primary site (PS1) and a secondary site (SS1) in their environment. The reason for the secondary site is because there is a site with around 700 clients and that exceeded the comfort level of a distribution point. This site is located
    in Valley Forge and we want all clients in this boundary group to use the secondary site. Everywhere else should use primary.
    With that being said and after reading what I read, should I not directly assign the boundary group for Valley Forge to the secondary site? If not, how does the client know to use it? And better yet, what is the point of having the option to directly assign
    to SS1 if it shouldn't be done?
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”

    Jorgen, thank you for the link. This was the original post I read that rocked my world:) I just wanted to get more info on the subject and make sure it was still relevant.
    MadLuka, much appreciate the explanation. Just when you think you know something somebody comes along and proves you wrong. Is there anything that I need to do for the VF clients to establish the understanding that they will need to use the SS like
    assign it as a site system for content management? Even better should I include all site systems (PS and SS) within that content management so that they will use the PS when they roam outside of that boundary?
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”

  • Procedure performing a "Retry Secondary Site" Operation in SCCM 2012 R2 Secondary Server

    Dear Brother,
    My SCCM 2012 R2 Secondary Site Server, unfortunately crashed and required to be restored, doing this I end up performing a "Retry Secondary Site Operation.
    One by one I am clearing out the errors but there are few remaining errors on the prerequisite checks:
    1.[Failed]:The logon account for the SQL Server service cannot be a local user account, NT SERVICE\<sql service name> or LOCAL SERVICE.  You must configure the SQL Server service to use a valid domain account, NETWORK SERVICE, or LOCAL SYSTEM.
    Actions Done: SQL Related Services use Logon As Domain Account "Microsoft-Domain\BillAdmin" , but still the above message still appears in the logs.
    Actions Done: None
    2.[Failed]:The collation of the site database does not match the collation of the parent site's database.  All sites in a hierarchy must use the same database collation.
    3.[Failed]:The site server might be unable to publish to Active Directory. The computer account for the site server must have Full Control permissions to the System Management container in its Active Directory domain. You can ignore this warning if you have
    manually verified these permissions. For more information about your options to configure required permissions, see
    http://go.microsoft.com/fwlink/p/?LinkId=233190.
    Actions Done: None, as this machine is previously a working Secondary site for 1 Year already. So I do not suspect anything from the current related configuration.
    4.[Failed]: Either the user account running Configuration Manager Setup does not have sysadmin SQL Server role permissions on the SQL Server instance selected for site database installation, or the SQL Server instance could not be contacted to verify permissions.
    Setup cannot continue.
    Action Taken:  Domain Account "Microsoft-Domain\BillAdmin" has a
    Sysadmin roles and actually all the check boxes are chosen to acquire all SQL account roles" 
    5. [Failed]:Prerequisite checks complete with failure - check ConfigMgrPrereq.log
    in the root of the primary site server system drive.
    6[Failed]:Unable to complete secondary site server installation - check ConfigMgrSetup.log in the root of the secondary site server system drive.
    ConfigMgrPrereq.log-Start
    ?<12-27-2014 23:39:35> ********************************************
    ?<12-27-2014 23:39:35> ******* Start Prerequisite checking. *******
    ?<12-27-2014 23:39:35> ********************************************
    ?<12-27-2014 23:39:35> Commandline :
    "E:\Program Files\Microsoft Configuration Manager\bin\x64\smsexec.exe"
    ?<12-27-2014 23:39:35> Check Type: Secondary site
     Site Server: SecondarySite2.microsoft.com,
     SQL Server: SecondarySite2.microsoft.com,
     SQL Named Instance: MSSQLSERVER,
     Install Folder: E:\Program Files\Microsoft Configuration Manager\,
     Setup Source Folder: E:\Source\SCCM2012-R2
    ?<12-27-2014 23:39:35> INFO: Executing prerequisite functions...
    ?<12-27-2014 23:39:35> ===== INFO: Prerequisite Type & Server: SITE_SEC:SecondarySite2.microsoft.com =====
    ?<12-27-2014 23:39:35> <<<RuleCategory: Access Permissions>>>
    ?<12-27-2014 23:39:35> <<<CategoryDesc: Checking access permissions...>>>
    ?<12-27-2014 23:39:35> INFO: CheckLocalSys is Admin of <SecondarySite2.microsoft.com>.
    ?<12-27-2014 23:39:43> SecondarySite2.microsoft.com;    Site server computer account administrative rights;    Passed
    ?<12-27-2014 23:39:43> <<<RuleCategory: System Requirements>>>
    ?<12-27-2014 23:39:43> <<<CategoryDesc: Checking system requirements for ConfigMgr...>>>
    ?<12-27-2014 23:39:43> INFO: Check Lanman service: <SecondarySite2.microsoft.com>.
    ?<12-27-2014 23:39:44> SecondarySite2.microsoft.com;    Check Server Service is running;    Passed
    ?<12-27-2014 23:39:45> INFO: OS version:601, ServicePack:1.
    ?<12-27-2014 23:39:46> INFO: Target computer is a Windows server.
    ?<12-27-2014 23:39:46> SecondarySite2.microsoft.com;    Unsupported site server operating system version for Setup;    Passed
    ?<12-27-2014 23:39:46> SecondarySite2.microsoft.com;    Domain membership;    Passed
    ?<12-27-2014 23:39:47> INFO: Free disk space on target
    \\SecondarySite2.microsoft.com\E$\. = 83157 MB
    ?<12-27-2014 23:39:47> SecondarySite2.microsoft.com;    Free disk space on site server;    Passed
    ?<12-27-2014 23:39:47> SecondarySite2.microsoft.com;    Pending system restart;    Passed
    ?<12-27-2014 23:39:48> INFO: The server SecondarySite2.microsoft.com is not read-only domain controller.
    ?<12-27-2014 23:39:48> SecondarySite2.microsoft.com;    Read-Only Domain Controller;    Passed
    ?<12-27-2014 23:39:48> INFO: Check FQDN Length for site server: <SecondarySite2.microsoft.com>.
    ?<12-27-2014 23:39:48> SecondarySite2.microsoft.com;    Site Server FQDN Length;    Passed
    ?<12-27-2014 23:39:48> <<<RuleCategory: Dependent Components>>>
    ?<12-27-2014 23:39:48> <<<CategoryDesc: Checking dependent components for ConfigMgr...>>>
    ?<12-27-2014 23:39:48> SecondarySite2.microsoft.com;    Microsoft XML Core Services 6.0 (MSXML60);    Passed
    ?<12-27-2014 23:39:49> SecondarySite2.microsoft.com;    Microsoft Remote Differential Compression (RDC) library registered;    Passed
    ?<12-27-2014 23:39:49> INFO: Checking Windows Installer version on SecondarySite2.microsoft.com.
    ?<12-27-2014 23:39:50> INFO: Path of Windows Installer is <\\SecondarySite2.microsoft.com\C$\Windows\system32\msi.dll>.
    ?<12-27-2014 23:39:51> INFO: Msi.dll version is: <5.0.7601.17807> .
    ?<12-27-2014 23:39:51> SecondarySite2.microsoft.com;    Microsoft Windows Installer;    Passed
    ?<12-27-2014 23:39:51> INFO: Start Checking InstallSQLExpress on site server: SecondarySite2.microsoft.com, SQL Server instance MSSQLSERVER
    ?<12-27-2014 23:39:51> INFO: SQL Server Express installation was not selected.
    ?<12-27-2014 23:39:51> SecondarySite2.microsoft.com;    SQL Server Express on Secondary Site;    Passed
    ?<12-27-2014 23:39:52> SecondarySite2.microsoft.com;    Existing Configuration Manager server components on site server;    Passed
    ?<12-27-2014 23:39:52> SecondarySite2.microsoft.com;    Firewall exception for SQL Server (stand-alone primary site);    Passed
    ?<12-27-2014 23:39:52> INFO: SQL Server computer <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:39:52> INFO: SQL Server named instance <MSSQLSERVER>
    ?<12-27-2014 23:39:53> SecondarySite2.microsoft.com;    SQL Server service running account;    Error;    The logon account for the SQL Server service cannot be a local user account, NT SERVICE\<sql service
    name> or LOCAL SERVICE.  You must configure the SQL Server service to use a valid domain account, NETWORK SERVICE, or LOCAL SYSTEM.
    ?<12-27-2014 23:39:53> INFO: SQL Server computer <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:39:53> INFO: SQL Server named instance <MSSQLSERVER>
    ?<12-27-2014 23:39:53> INFO: Cannot connect to registry key.
    ?<12-27-2014 23:39:53> SecondarySite2.microsoft.com;    Dedicated SQL Server instance;    Passed
    ?<12-27-2014 23:39:53> INFO: CheckSQLCollationSecondary
    ?<12-27-2014 23:39:53> INFO: Collation on <PrimarySite2DB.microsoft.com> <SQL_Latin1_General_CP1_CI_AS>
    ?<12-27-2014 23:41:27> ERROR: failed to get collation from secondary site
    ?<12-27-2014 23:41:27> SecondarySite2.microsoft.com;    Parent/child database collation;    Error;    The collation of the site database does not match the collation of the parent site's database.  All
    sites in a hierarchy must use the same database collation.
    ?<12-27-2014 23:41:27> INFO: Checking .NET framework versions 3.5...
    ?<12-27-2014 23:41:28> INFO: .NET is installed
    ?<12-27-2014 23:41:28> SecondarySite2.microsoft.com;    Minimum .NET Framework version for Configuration Manager site server;    Passed
    ?<12-27-2014 23:41:28> INFO: Skipping check for .NET version, user did not select to install SQL Server Express for Secondary Site.
    ?<12-27-2014 23:41:28> SecondarySite2.microsoft.com;    Minimum .NET Framework version for SQL Server Express edition installation for Configuration Manager Secondary Site;    Passed
    ?<12-27-2014 23:41:28> INFO: CheckInstallSourceVersion <E:\Source\SCCM2012-R2>
    ?<12-27-2014 23:41:29> SecondarySite2.microsoft.com;    Setup Source Version;    Passed
    ?<12-27-2014 23:41:29> INFO:CheckInstallSourcePath <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:14> SecondarySite2.microsoft.com;    Setup Source Folder;    Passed
    ?<12-27-2014 23:42:14> INFO: Enter CheckSecSiteSqlOnSameMachine.
    ?<12-27-2014 23:42:14> INFO: Target secondary site Machine <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:14> INFO: SQL Server computer <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:14> SecondarySite2.microsoft.com;    SQL Server on the Secondary Site Computer;    Passed
    ?<12-27-2014 23:42:14> INFO:CheckSupportedFQDNFormat <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:15> INFO: NetBIOS <SECONDARYSITE2>
    ?<12-27-2014 23:42:15> SecondarySite2.microsoft.com;    Primary FQDN;    Passed
    ?<12-27-2014 23:42:15> INFO:CheckMachineAccountHasADAccess <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:40> ERROR: Site server does not have create child permission on AD 'System Management'
    ?<12-27-2014 23:42:40> WARN: Site server does not have delete child permission on AD 'System Management'
    ?<12-27-2014 23:42:40> SecondarySite2.microsoft.com;    Verify site server permissions to publish to Active Directory.;    Warning;    The site server might be unable to publish to Active Directory. The computer
    account for the site server must have Full Control permissions to the System Management container in its Active Directory domain. You can ignore this warning if you have manually verified these permissions. For more information about your options to configure
    required permissions, see
    http://go.microsoft.com/fwlink/p/?LinkId=233190.
    ?<12-27-2014 23:42:40> INFO:CheckRemoteWMIConnection <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:42:48> SecondarySite2.microsoft.com;    Remote Connection to WMI on Secondary Site;    Passed
    ?<12-27-2014 23:42:48> INFO: Check required collation of Sql Server.
    ?<12-27-2014 23:42:48> INFO: LangID <409>
    ?<12-27-2014 23:42:48> INFO: NOT primary site or CAS install, skipping check for reqired collation of SQL Server.
    ?<12-27-2014 23:42:48> SecondarySite2.microsoft.com;    Required SQL Server Collation;    Passed
    ?<12-27-2014 23:42:48> ===== INFO: Prerequisite Type & Server: SQL:SecondarySite2.microsoft.com =====
    ?<12-27-2014 23:42:48> <<<RuleCategory: Access Permissions>>>
    ?<12-27-2014 23:42:48> <<<CategoryDesc: Checking access permissions...>>>
    ?<12-27-2014 23:42:48> INFO:RemoteCheckAdminOnSQL <SecondarySite2.microsoft.com>, SQL Server <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:44:33> SecondarySite2.microsoft.com;    SQL Server sysadmin rights;    Error;    Either the user account running Configuration Manager Setup does not have sysadmin SQL Server role permissions
    on the SQL Server instance selected for site database installation, or the SQL Server instance could not be contacted to verify permissions. Setup cannot continue.
    ?<12-27-2014 23:44:33> ===== INFO: Prerequisite Type & Server: MP:SecondarySite2.microsoft.com =====
    ?<12-27-2014 23:44:33> <<<RuleCategory: Access Permissions>>>
    ?<12-27-2014 23:44:33> <<<CategoryDesc: Checking access permissions...>>>
    ?<12-27-2014 23:44:33> SecondarySite2.microsoft.com;    Administrative share (Site system);    Passed
    ?<12-27-2014 23:44:33> INFO:CheckSiteSystemtoSQLConnectivity <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:44:33> INFO: Installing secondary site, skipping SQL Server connectivity check.
    ?<12-27-2014 23:44:33> SecondarySite2.microsoft.com;    Site System to SQL Server Communication;    Passed
    ?<12-27-2014 23:44:33> <<<RuleCategory: System Requirements>>>
    ?<12-27-2014 23:44:33> <<<CategoryDesc: Checking system requirements for ConfigMgr...>>>
    ?<12-27-2014 23:44:33> INFO: The rule 'Check Server Service is running' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:44:34> INFO: OS version:601, ServicePack:1.
    ?<12-27-2014 23:44:35> INFO: Target computer is a Windows server.
    ?<12-27-2014 23:44:35> SecondarySite2.microsoft.com;    Unsupported management point operating system version for Setup;    Passed
    ?<12-27-2014 23:44:35> INFO: The rule 'Domain membership' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:44:36> INFO: Windows Cluster not found on SecondarySite2.microsoft.com.
    ?<12-27-2014 23:44:36> SecondarySite2.microsoft.com;    Windows Failover Cluster;    Passed
    ?<12-27-2014 23:44:36> INFO: The rule 'Pending system restart' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:44:36> <<<RuleCategory: Dependent Components>>>
    ?<12-27-2014 23:44:36> <<<CategoryDesc: Checking dependent components for ConfigMgr...>>>
    ?<12-27-2014 23:44:36> INFO: The rule 'Microsoft XML Core Services 6.0 (MSXML60)' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:44:36> SecondarySite2.microsoft.com;    IIS service running;    Passed
    ?<12-27-2014 23:45:35> INFO: CheckWebSvcExtnRemote, result:<7>.
    ?<12-27-2014 23:45:35> SecondarySite2.microsoft.com;    BITS installed;    Passed
    ?<12-27-2014 23:47:00> INFO: CheckWebSvcExtnRemote, result:<7>.
    ?<12-27-2014 23:47:01> WARN: BITS Service is not running on SecondarySite2.microsoft.com.
    ?<12-27-2014 23:47:01> SecondarySite2.microsoft.com;    BITS enabled;    Passed
    ?<12-27-2014 23:47:01> SecondarySite2.microsoft.com;    IIS HTTPS Configuration for management point;    Passed
    ?<12-27-2014 23:47:01> INFO: Stand-alone primary site or secondary site. Skip checking firewall settings for SQL Server
    ?<12-27-2014 23:47:01> SecondarySite2.microsoft.com;    Firewall exception for SQL Server for management point;    Passed
    ?<12-27-2014 23:47:01> SecondarySite2.microsoft.com;    Administrative rights on management point;    Passed
    ?<12-27-2014 23:47:01> INFO:CheckV4ClientNotInstalled <SecondarySite2.microsoft.com>
    ?<12-27-2014 23:47:45> SecondarySite2.microsoft.com;    Client Version on Management Point Computer;    Passed
    ?<12-27-2014 23:47:45> ===== INFO: Prerequisite Type & Server: DP:SecondarySite2.microsoft.com =====
    ?<12-27-2014 23:47:45> <<<RuleCategory: Access Permissions>>>
    ?<12-27-2014 23:47:45> <<<CategoryDesc: Checking access permissions...>>>
    ?<12-27-2014 23:47:45> <<<RuleCategory: System Requirements>>>
    ?<12-27-2014 23:47:45> <<<CategoryDesc: Checking system requirements for ConfigMgr...>>>
    ?<12-27-2014 23:47:47> SecondarySite2.microsoft.com;    Unsupported distribution point operating system version for Setup;    Passed
    ?<12-27-2014 23:47:47> INFO: The rule 'Domain membership' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:47:47> INFO: The rule 'Windows Failover Cluster' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:47:47> INFO: The rule 'Pending system restart' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:47:47> <<<RuleCategory: Dependent Components>>>
    ?<12-27-2014 23:47:47> <<<CategoryDesc: Checking dependent components for ConfigMgr...>>>
    ?<12-27-2014 23:47:47> SecondarySite2.microsoft.com;    Microsoft XML Core Services 6.0 (MSXML60) for distribution point;    Passed
    ?<12-27-2014 23:47:47> INFO: The rule 'IIS service running' has been run on server 'SecondarySite2.microsoft.com', skipped.
    ?<12-27-2014 23:47:47> SecondarySite2.microsoft.com;    IIS HTTPS Configuration for distribution point;    Passed
    ?<12-27-2014 23:47:47> SecondarySite2.microsoft.com;    Administrative rights on distribution point;    Passed
    ?<12-27-2014 23:47:48> ***************************************************
    ?<12-27-2014 23:47:48> ******* Prerequisite checking is completed. *******
    ?<12-27-2014 23:47:48> ***************************************************
    ?<12-27-2014 23:47:48> INFO: Updating Prerequisite checking result into the registry
    ?<12-27-2014 23:47:48> INFO: Connecting to SecondarySite2.microsoft.com registry
    ?<12-27-2014 23:47:50> INFO: Setting registry values
    ConfigMgrPrereq.log-End
    Well my question is what would be the best solutions as it bugs me for days now.
    Regards,

    Hello,
    ?<12-27-2014 23:44:33> SecondarySite2.microsoft.com;   
    SQL Server sysadmin rights;    Error;   
    Either the user account running Configuration Manager Setup does not have sysadmin SQL Server role permissions on the SQL Server instance selected for site database installation, or the SQL Server instance could not be contacted to verify permissions.
    Setup cannot continue.
    Did you install SQL server with a local account?
    ?<12-27-2014 23:41:27> SecondarySite2.microsoft.com;   
    Parent/child database collation;    Error;   
    The collation of the site database does not match the collation of the parent site's database. 
    All sites in a hierarchy must use the same database collation.
    Try this blog:
    http://jthys.wordpress.com/2012/04/02/sccm-2012-required-sql-server-collation/
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • SCCM Console on Secondary Site 2012 R2

    Hi all,
    I just want to ask whether it is supported or not when install SCCM Console on Secondary Site Server in 2012 R2? I've searched over internet but does not find a conclusion about that.
    From technet SCCM Console requirement and interoperability, there is no information that restrict install console from Secondary Site Server, but this link say it is not supported:
    http://social.technet.microsoft.com/Forums/systemcenter/en-US/7c31b2d6-130c-46d6-b24d-108110cb0b61/install-sccm-admin-console-on-secondary-site-servers-failed-on-one-of-two-server?forum=configmgradminconsole
    Has anyone try this, because today i installed console from one of my secondary site server and successfully connected with the primary site. Hope that does not break anything because with the ability of RBAC in 2012 R2, i can assign the admin at branch
    site permission he need to manage the clients in this secondary site.
    Thanks,

    I've seen it working with multiple customer. Also, I can imagine that it wouldn't be a supported scenario, purely because it's not tested (both new installations as upgrades).
    As, I'm not working for Microsoft and it's not documented, I can't give you any official statements.  
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • How to setup IPV6 boundary for SCCM 2012 R2 Primary Site?

    How to setup IPV6 boundary for SCCM 2012 R2 Primary Site?
    I have Direct Access implemented in my environment. I have Windows 8.1 machine connecting through direct access.
    I want to manage the windows 8.1 through SCCM. How do I setup IPV6 boundary. Can someone guide me through?
    Below are the Windows 8.1 client IP Configuration
    C:\Windows\system32>ipconfig
    Windows IP Configuration
    Wireless LAN adapter Local Area Connection* 3:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Wireless LAN adapter Wi-Fi:
       Connection-specific DNS Suffix  . : home
       Link-local IPv6 Address . . . . . : fe80::7466:11a5:39ed:ffb0%4
       IPv4 Address. . . . . . . . . . . : 192.168.1.5
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 192.168.1.1
    Tunnel adapter isatap.home:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : home
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fd:1494:1339:93d6:439c
       Link-local IPv6 Address . . . . . : fe80::1494:1339:93d6:439c%9
       Default Gateway . . . . . . . . . :
    Tunnel adapter iphttpsinterface:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:1000:e1a7:9cc8:c3c7:d819
       Temporary IPv6 Address. . . . . . : fd64:fc00:d17b:1000:206c:f857:ddbe:2f2b
       Link-local IPv6 Address . . . . . : fe80::e1a7:9cc8:c3c7:d819%10
       Default Gateway . . . . . . . . . :
    Below are the IPConfiguration details for Direct Access server
    C:\Windows\system32>PsExec.exe \\MURA01 ipconfig
    PsExec v1.98 - Execute processes remotely
    Copyright (C) 2001-2010 Mark Russinovich
    Sysinternals - www.sysinternals.com
    Windows IP Configuration
    Ethernet adapter Ethernet:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:3333::1
       Link-local IPv6 Address . . . . . : fe80::b1ad:1c29:b4a:9125%15
       IPv4 Address. . . . . . . . . . . : 10.192.1.25
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 10.192.1.1
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter isatap.{3D6A5E86-D85A-46C8-B69B-FFCF6D5D849C}:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:1:0:5efe:10.192.1.25
       Link-local IPv6 Address . . . . . : fe80::5efe:10.192.1.25%18
       Default Gateway . . . . . . . . . :
    Tunnel adapter 6TO4 Adapter:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter IPHTTPSInterface:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:1000::1
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:1000::2
       IPv6 Address. . . . . . . . . . . : fd64:fc00:d17b:1000:2552:e9f8:87d3:ed8e
       Link-local IPv6 Address . . . . . : fe80::2552:e9f8:87d3:ed8e%20
       Default Gateway . . . . . . . . . :
    ipconfig exited on MURA01 with error code 0.
    Below are the IPCONFIG Details for SCCM Server:
    C:\Windows\system32>PsExec.exe \\sccm01 ipconfig
    PsExec v1.98 - Execute processes remotely
    Copyright (C) 2001-2010 Mark Russinovich
    Sysinternals - www.sysinternals.com
    Windows IP Configuration
    Ethernet adapter Ethernet:
       Connection-specific DNS Suffix  . :
       Link-local IPv6 Address . . . . . : fe80::9f0:86f9:441d:bc07%12
       IPv4 Address. . . . . . . . . . . : 10.192.1.30
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 10.192.1.1
    Tunnel adapter isatap.{0749E47D-AE0A-4D47-9D37-BDDC848E56F6}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    ipconfig exited on sccm01 with error code 0.
    What will be the IPV6 values to configure boundary?

    Depending on how the clients connect use the IPv6 prefix of their 6to4, Teredo, and/ or IP-HTTPS tunnel. Just keep in mind that it could become a long list...
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Issue getting WDS to Install for PXE in SCCM 2012 SP1 Primary Site

    Hi All
    I'm trying to get PXE boot working from our SCCM 2012 box but it never actually gets to the point of installing WDS when I check the box for PXE booting. I don't have  SMSPXE.log since it never gets to that point and the distmgr.log  never reaches
    that point either. I've tried
    uncheck pxe boot option - restart - re-check
    uncheck pxe-boot - restart - install wds - leave it unconfigured - reboot - check pxe boot
    uncheck pxe-boot - uninstall the vcredist 2008 packages - rebooting - install vcredist - check pxe boot option
    the above with installing wds unconfigured
    Below is the relevant portions of the distmgr.log file after I enable the pxe boot option no matter what manner of software is installed. We are running it on a VM in a Hyper-V 2012 enviornment in Windows 2008 SP2 x64. This issue is similar to this link
    WDS PXE Secondary Site Issues but mine is on the Primary Site.
    ConfigureDP SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:09 AM 4008 (0x0FA8)
    DP registry settings have been successfully updated on TUSC2012.TALISKERUTAH.LOCAL SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    STATMSG: ID=9500 SEV=I LEV=M SOURCE="SMS Server" COMP="SMS_DISTRIBUTION_MANAGER" SYS=TUSC2012.TALISKERUTAH.LOCAL SITE=001 PID=2728 TID=4008 GMTDATE=Thu Mar 28 17:48:10.083 2013 ISTR0="["Display=\\TUSC2012.TALISKERUTAH.LOCAL\"]MSWNET:["SMS_SITE=001"]\\TUSC2012.TALISKERUTAH.LOCAL\" ISTR1="" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=1 AID0=404 AVAL0="["Display=\\TUSC2012.TALISKERUTAH.LOCAL\"]MSWNET:["SMS_SITE=001"]\\TUSC2012.TALISKERUTAH.LOCAL\" SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    STATMSG: ID=9503 SEV=I LEV=M SOURCE="SMS Server" COMP="SMS_DISTRIBUTION_MANAGER" SYS=TUSC2012.TALISKERUTAH.LOCAL SITE=001 PID=2728 TID=4008 GMTDATE=Thu Mar 28 17:48:10.084 2013 ISTR0="["Display=\\TUSC2012.TALISKERUTAH.LOCAL\"]MSWNET:["SMS_SITE=001"]\\TUSC2012.TALISKERUTAH.LOCAL\" ISTR1="" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=1 AID0=404 AVAL0="["Display=\\TUSC2012.TALISKERUTAH.LOCAL\"]MSWNET:["SMS_SITE=001"]\\TUSC2012.TALISKERUTAH.LOCAL\" SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    ConfigurePXE SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    CcmInstallPXE SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    RegQueryValueExW failed for Software\Microsoft\SMS\DP, PxeInstalled SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    RegReadDWord failed; 0x80070002 SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    Running: C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist_x64.exe /q /l C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist.log SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    Waiting for the completion of: C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist_x64.exe /q /l C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist.log SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:10 AM 4008 (0x0FA8)
    Run completed for: C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist_x64.exe /q /l C:\Program Files\Microsoft Configuration Manager\bin\x64\vcredist.log SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    Created the DP mutex key for WDS. SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    Finding Wimgapi.Dll SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    MsiEnumRelatedProducts failed SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    FindProduct failed; 0x80070103 SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    MsiEnumRelatedProducts failed SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    FindProduct failed; 0x80070103 SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    GetFileAttributesW failed for SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    FindWimgapiDll failed; 0x80070002 SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    Running: msiexec.exe /quiet /i c:\program files\microsoft configuration manager\wim\wimgapi.msi /log c:\program files\microsoft configuration manager\wim\wimgapi.log SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    Waiting for the completion of: msiexec.exe /quiet /i c:\program files\microsoft configuration manager\wim\wimgapi.msi /log c:\program files\microsoft configuration manager\wim\wimgapi.log SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:14 AM 4008 (0x0FA8)
    Sleep 30 minutes... SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:29 AM 4668 (0x123C)
    Created policy provider trigger for ID 16777217 SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:29 AM 4656 (0x1230)
    Sleep 30 minutes... SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:34 AM 4668 (0x123C)
    Sleep 30 minutes... SMS_DISTRIBUTION_MANAGER 3/28/2013 11:48:39 AM 4668 (0x123C)

    HI again, sorry for the late reply.
    By saying that WDS don't get configured, I mean that when i enabled the PXE functionality, the WDS role got installed but the folder remote install wasn't created.
    I ahve now actually gone back to an earlier snapshot from before I started play with the PXE settings of the VM and now nothing happens when activating PXE on the distribution point, but not even the smspxe.log is created.
    The Account used is a local admin and the distribution point is located on the primary site server.
    EDIT: in the events log, it states the following:SMS_SITE_COMPONENT_MANAGER on computer XXX.XXXX.XXX reported: SIte comoponent Manger failed to to install on this site system.
    On error (source: MsiInstaller) below:
    Product Application Web Service -- Internal Error 25001. 80070490
    I havent mentioned it earlier, but the Server OS is Server 2012.
    I hope this might help you help me :)
     

  • Does SCCM 2012 R2 Secondary and DP servers really need backup?

       Hello to all. I'm involved on a SCCM 2012 R2 project that will install aprox. 20 SCCM 2012 R2 servers: 1 CAS, 3 Primary, 8 Secondary and 8 DPs (just SCCM runs on all these servers). As backup is licensed by Tb and cost is a restriction, I think
    that would be acceptable to backup just CAS and 3 Primary servers. If a failure happens in any Secondary or DP, they could be reinstalled and all necessary information would be replicated from the respective Primary or Secondary.
       Questions:
        1- Is it technically feasible?
        2- If I want to run specific configuration for a site that its Secondary failed, could I run it from the respective Primary?
        3- Does #2 applie to DP (if a DP fails, could I run the necessary configs./action from its respective Secondary or Primary)
        Please feel free to input pros and cons so I can take the best decision.
        Regards, EEOC.

    " 2- If I want to run specific configuration for a site that its Secondary failed, could I run it from the
    respective Primary?"
    Just a comment regarding this design decision.  Based on this sentence, it almost sounds like someone thinks you
    can manage FROM a secondary.  That simply doesn't happen.
    I wonder... Did the person who came up with your cm12 design ever actually work with cm12 in a hierarchy (for more than
    a few weeks), because based on your statements, assumptions appear to be made that cm12 hierarchy works exactly like cm07 ( or SMS 2.0 for that matter, since you couldn't manage from a secondary in cm07 nor SMS 2003 either).  Having a cas and multiple
    primaries will not provide the redundancy of "if one primary goes down then..." As it sounds like is being assumed is true.  I think its tons riskier to have multiple primaries and a cas.
    Standardize. Simplify. Automate.

  • SCCM 2012 AD Publishing in a Single Forest Multiple Domains

    Hi there,
    Let me explain the situation first so that you get the idea. We have a single forest, multiple child domains AD environment. For some reasons each domain is being managed separately by their geographic location IT.
    Forest has been extended for SCCM by the site who holds the forest root domain. Since everyone wants to manage their own domain and systems, each child domain have their own primary site server.
    In one of the domains I have installed brand new SCCM 2012 R2. I haven't done anything yet, havent turned on any discovery except Heartbeat. Now I see one device, which belongs to another domain with totally separate IP address, shows in my SCCM site. I dont
    know why.
    From here question arises for me. Correct me if I'm wrong and please advice what to do domain/forest wide.
    1. System Container is needed in each child domain, not in the forest, right?
    2. Where does/should each SCCM primary site publish information; in each domain or in the forest root domain?
    3. Under Administration > Overview > Site Configuration > Sites > Properties > Publishing I see forest root domain name and its checked. 
    Under Administration > Overview > Hierarchy Configuration > Active Directory Forests > Properties > Publishing my site is checked and its the only one in there. In that same window I went ahead and specified my own domain hoping
    to cure the possible problem.
    So, why would that one device show up in this site? I have disabled Heartbeat together with other discoveries for now till I make everything ready.
    Thanks for your help in advance.

    1. Under Administration > Overview > Site Configuration > Sites > Properties > Publishing If I uncheck forest root domain will devices on my child domain still be able to find my site server?
    2. Under Administration > Overview > Hierarchy Configuration > Active Directory Forests > Properties > Publishing my site is checked and its the only one in there. In that same window I went ahead and specified my own domain
    hoping to cure the possible problem. Is this a good practice?
    3. "When clients look for ConfigMgr info, they use GC lookups meaning they return objects from every System Management container in the forest." So, which one do clients choose and how?
    4. "For that one device, have you opened its properties and examined it?" Yes, what abou it? Its found based on Heartbeat Discovery agent (when heartbeat was enabled).
    5. "Have you reviewed the boundaries and boundary groups set up for site assignment?" Yes, as I mentioned this device belongs to different domain and totally outside of my AD site and SCCM boundaries.
    This is fresh install and not in production yet. I have disabled Heartbeat temporarily so that I fix this problem. I will enable it after. 

  • SCCM 2012 SP1 Beta Site System Roles Installation issues

    My apologies if this isn't the correct place to post this, but I didn't see any SCCM 2012 forums to post this. If there is a better place for this post, please direct me to the proper location. In the meantime this is my scenario:
    I am currently evaluating SCCM 2012 for our company. I have installed SCCM 2012 SP1 Beta on a test server running Server 2012 and SQL 2012. I am testing its ability to manage Windows 8. The server is a member of our company domain. I have enabled Active
    Directory Forest Discovery and CM has detected our forest and domain and set up boundaries automatically.
    I am trying to add the Application Catalog Web Service and Website Roles. When I start the wizard I get exclamation marks next to Active Directory forest and domain fields in the wizard. It shows our proper forest and domain names but won't proceed
    because it insists that the FQDN for my forest/domain is invalid. If I enter any other forest/domain name (e.g. yahoo.com, google.com, help-me.com) the exclamation marks clear and the wizard will proceed. SC seems to recognize our forest/domain name and
    denies it. Adding different suffixes (e.g. .net, .org, .local) changes nothing. I've even flipped our forest-domain name (e.g. "a-b.com" to "b-a.com": we have a "-" in our name) and it STILL denies it. If I add a prefix to the forest/domain name, the
    wizard is happy and lets me proceed (e.g. "domain.a-b.com") Did I miss something in initial setup? If this is a bug in the SP1 beta, how do I let anyone know about this? Any help/suggestions would be appreciated. Thanks.

    Since no one has answer this post, I recommend opening  a support case with CSS as they can work with you to solve this problem.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • SCCM 2012 R2 CU4 - Site Backup Task failed

    Hi, I set up a Site Maintenance Task for Backup our Primary Site, but every time I run this task it fail with the following message:
    Error: Backup folder \\backupserver\backupshare$ does not exist or backup service does not have permission to access the folder.
    I tried to use "erveryone" in share permissions and NTFS Permissions with Full Control and then the Backup works! ... I tried to remove the everyone from NTFS completely then the Backup also still works .. but when I remove everyone from the share
    permissions (and grant the SCCM Site Server and SQL Server Computer Accounts the Full Control Permission) the backup fails..
    so it seems to me that I have a permission issue ... what is the correct Permission setup for UNC Backup? (Share and NTFS Permissions) ... I tried to give the SCCM Server and SQL Server Computer and SQL Cluster Account Full Control without success...)
    kind regards
    Klaus

    "The computer account of the site server and the computer account of the SQL Server, if SQL Server is installed on another computer, must have
    Write NTFS and share permissions to the shared network folder."
    https://technet.microsoft.com/en-us/library/gg712697.aspx
    Also have you read this:
    http://blog.msvconsultancy.co.uk/2014/07/sccm-2012-sp1-site-maintenance-backup-task-error/

  • Configure SUSDB_log.ldf Autogrowth Size on SCCM 2012 Standalone Primary Site Server

    I have configured the rest of my .ldf log files for SCCM use according to best practices by SCCM MVPs, but I have not read anywhere that states how I should go about configuring the auto growth for the WSUS database log file (susdb_log.ldf) itself.
    If someone can offer some guidance here, I would greatly appreciate it.
    Thanks

    Thanks Torsten. 
    So after I run the first full sync, I can just use that value to set the initial size like you stated and then use some other value to set the growth rate? There is only about 1,000 clients in this organization and I want to get this WSUS db log file configured
    prior to installing the SCCM primary site on the server. I have used Kent Agerlund's instructions on pre-configuring the SCCM 2012 R2 database and everything looks good there, but just wanted to know how to go about NOT using that 2TB default limit on the
    SUSDB_log. What is a good rule of thumb to use to determine the file growth value? Like 2x or 3x the initial value size? 
    Thanks

  • Can I set a priority in SCCM 2012 for advertisements or any other ideas to fix my Task sequences?

    I have several task sequences that I deploy to lab computers that we re-image 1 or 2 times a year.  The task sequences run and install specific software
    for that lab after the base image deploys.
    The base image is deployed using WDS without SCCM in the mix.  It is a setup they we are using because of legacy business processes that just make this easier.
     Then after the machine boots up and gets its SCCM policies the task sequences start running to deploy the software.
    The issue I am noticing is that I have no control over what runs first and sometimes Windows Updates that are deployed via SCCM run before or in between the task
    sequences that I have running.  Some installs fail because of the pending Windows Update reboot, which I believe I have gotten around just by checking for it and rebooting before it installs the software.  The issue is that the Windows update could
    and usually is one of those lovely updates that requires multiple reboots.  The second reboot is killing my task sequence.
    The issue is I need to somehow force this updates to run after my task sequences or make sure they run first.  The only way I can think of this is by having
    priorities for the task sequences.  I can't just add installing the updates to the task sequence, because the second reboot will kill my whole task sequence there too.
    Anyone have any ideas on how to get around this issue?  I want the machines to install the Windows updates so I can't just remove them from the collection.

    That's definitely the best option to do everything via the task sequence deployment.
    Also, there are script available in the community to add or remove a device from a collection, see for example:
    http://sccmfaq.wordpress.com/2013/05/20/sccm-2012-sp1-remove-client-from-collection-after-osd/
    Keep in mind that if you want to use a script like that during the task sequence that the device running the task sequence (and by that the script) requires specific rights within ConfigMgr.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

Maybe you are looking for

  • Is it possible to allow the user to revoke its own it resource?

    Is it possible to allow the end-user to somehow revoke its own resource? What would be the correct approach if he decides that he doesn't need access to a specific system and decides to terminate his account ? Thanks for any insight. Adriano.

  • Just purchased new ipad.  screen in foreign language and says "Dand dat Ngon ngu.   What's that all about?

    Just purchased new ipad.  screen in foreign language and says "Dang dat Ngon ngu?   What's going on??

  • Has anybody got a solution?

    My ipod touch works very well accessing the you-tube using the factory built in browser[you-tube widget]. I tried to go to the you-tube account of mine logging on through the google account using the safari.-No problem in getting to my account. Howev

  • Safari out of control in yosemite

    Ever since updating imac, the Safari browser is out of control.  The advertisements are overwhelming and a new tab constantly opens for  mackeeper or other ads.  I am also getting a series of adobe flash player errors saying to change settings to 32-

  • IDOC status 62 -  IDOC passed to application

    Hello Experts, Am posting a inbound sales order custom/extended IDOC into the system from WE19, but, when I saw it in WE02/05, its showing status 62 - IDOC passed to application, i checked ST22 run time error. there is no error and also checked trigg