SCCM 2012 R2 / Wifi Profiles

Hi
New to SCCM with this release, so apologies if this is a newbie question. Searching doesn't turn up very much!
I am evaluating pushing Wifi profiles to mobile devices using the Intune connector. All seems to be set up and working OK, however I don't seem to be able to create any Wifi profiles that use Pre Shared Keys. Is this correct, or
am I missing something obvious?
If this is the case, please can anyone shed any light on why this might be the case, and whether there are any tweaks / workarounds / 3rd party addons that might be able to do so?
Many thanks for looking
Jon

What's the device type ? (Android,Ios, WP)
There's some restriction depending of the device type.
http://technet.microsoft.com/en-us/library/dn248970.aspx *See step 4
Benoit Lecours | Blog: System Center Dudes

Similar Messages

  • Wifi profiles SCCM 2012 R2 and Windows Intune

    Hi All,
    A quick question regarding SCCM 2012 R2 and the new Wifi Profiles feature...
    Can anyone confirm if you need windows Intune combined with SCCM 2012 R2 to be able to deploy WIFI profiles to users devices i.e Windows 8.1, IOS and Android platforms?  Microsoft documentation is not clear on this subject.
    Any help would be much appreciated.
    Regards PowerShell90

    It not as straight forward as one would hope. I am running the latest version of SCCM 2012 R2 CU2 connected to my Windows Intune subscription. There are a lot of hickups. One is that the direct of management needs to be all or nothing. In other words you
    either need to use Windows Intune solely to manage your devices or SCCM 2012 R2 (via connector). If the later then you must do everything from in SCCM 2012 R2. You cannot hybrid manage your devices as this will screw things up.
    Android for some reason is left out on a lot of features. I would think that MS Devs would work hard on the market share that being Android, not iOS. Any way, accord to some official MS articles Android is supported, but others claim that not all features
    are, these being the important ones like Email and Wi-Fi Profiles. They simply do not work.
    I think MS is heading in the right direction but there is a lot of work that needs to be done before this is a competitive product. I could care less if connects to my SCCM 2012 R2 server or not. Here are few things that I sent o a MS Support Rep today that
    need to be address.
    1. Better response time when updating devices after enrollment (e.g. Name change).
    2. The ability to locked down uninstalling Windows Intune from device.<o:p></o:p>
    3. The ability to locked down certain features in the Windows Intune app on device (e.g. User can reset device with Windows Intune app, rename, etc...).<o:p></o:p>
    4. Ability to rename device in either Windows Intune Admin Portal and/or SCCM 2-12 R2.<o:p></o:p>

  • SCCM 2012 R2 Office 2013 deploiement 64 bit and 32 bit versions

    We have some
    Windows 7 64bit os with office 2013 32 bit
    also
    Windows 7 32bit os with office 2013 32 bit
    We need to deploy office 2013 32 bit all over with sccm 2012 r2
    what's the best way for the deployment
    we also want to be sure to keep all user data for outlook. we don't want to loose that
    can I install a 32 bit office and in the setup /admin use uninstall and everything will work

    setup.exe /admin is the tool to use when customizing the deployment of Office; especially when deploying through SCCM.
    The way I saved user profile data is to set it to Use Existing Profile under Outlook Profile of setup /admin
    Yes, I have the default setup behavior box checked so it removes all previous Office version applications.

  • SCCM 2012 Install :An error has occurred while attempting to download or verify required pre....

    This is not the first time I am installing SCCM 2012 :) , however stuck at this one for some time now.
    I have a lab where SCCM 2012 pre-reqs were downloaded during setup and SCCM 2012 has been installed fine.
    We are doing another install for this client however SCCM download fails as ISA blocks it. Therefore we are trying to use the old setup files which were previously downloaded. However, this does not work (Files under e:\SCCM...). The log still refers to
    downloading the file from the internet.
    Here's the log
    =========
    <07-25-2012 00:57:28> *********************************************
    <07-25-2012 00:57:28> ***** ConfigMgr 2012 Setup Bootstrapper *****
    <07-25-2012 00:57:28> *********************************************
    <07-25-2012 00:57:28> Commandline:
    <07-25-2012 00:57:28> "D:\SMSSETUP\BIN\X64\SetupWpf.exe"
    <07-25-2012 00:57:28> INFO: Checking dotnet framework versions...
    <07-25-2012 00:57:28> INFO: Dotnet 3.5 installed
    <07-25-2012 00:57:28> Starting SetupWpf.exe...
    <07-25-2012 00:57:39> *********************************************
    <07-25-2012 00:57:39> ***** ConfigMgr 2012 Setup Bootstrapper *****
    <07-25-2012 00:57:39> *********************************************
    <07-25-2012 00:57:39> Commandline:
    <07-25-2012 00:57:39> "D:\SMSSETUP\BIN\X64\SetupWpf.exe"
    <07-25-2012 00:57:39> INFO: Checking dotnet framework versions...
    <07-25-2012 00:57:39> INFO: Dotnet 3.5 installed
    <07-25-2012 00:57:39> Starting SetupWpf.exe...
    <07-25-2012 00:57:47> Failed to create process of SetupWpf.exe.
    INFO: Attempting to load resource DLL...  $$<Configuration Manager Setup><07-25-2012 00:58:34.979+420><thread=2320 (0x910)>
    INFO: setupdl.exe: Start  $$<Configuration Manager Setup><07-25-2012 00:58:34.981+420><thread=2320 (0x910)>
    INFO: Downloading files to e:\SCCMPreReqs  $$<Configuration Manager Setup><07-25-2012 00:58:35.000+420><thread=1752 (0x6D8)>
    INFO: Extracted file C:\Users\ADMINI~1.Com\AppData\Local\Temp\2\ConfigMgr.Manifest.xml  $$<Configuration Manager Setup><07-25-2012 00:58:51.749+420><thread=1752 (0x6D8)>
    INFO: Processing file group "MSRDC"  $$<Configuration Manager Setup><07-25-2012 00:58:51.755+420><thread=1752 (0x6D8)>
    INFO: Processing file "msrdcoob.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=95740.  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: File for msrdcoob.exe [Microsoft Remote Differential Compression Library] will be copied with file name: msrdcoob_x86.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: Processing file "msrdcoob.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=95741.  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: File for msrdcoob.exe [Microsoft Remote Differential Compression Library] will be copied with file name: msrdcoob_amd64.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.756+420><thread=1752 (0x6D8)>
    INFO: Processing file group "WUA"  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: Processing file "WindowsUpdateAgent30-x86.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=158451.  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: File for WindowsUpdateAgent30-x86.exe [Windows Update Agent 3.0] will be copied with file name: WindowsUpdateAgent30-x86.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: Processing file "WindowsUpdateAgent30-x64.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=158453.  $$<Configuration Manager Setup><07-25-2012 00:58:51.757+420><thread=1752 (0x6D8)>
    INFO: File for WindowsUpdateAgent30-x64.exe [Windows Update Agent 3.0] will be copied with file name: WindowsUpdateAgent30-x64.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.758+420><thread=1752 (0x6D8)>
    INFO: Processing file group "Silverlight"  $$<Configuration Manager Setup><07-25-2012 00:58:51.758+420><thread=1752 (0x6D8)>
    INFO: Processing file "Silverlight.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.758+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=196277.  $$<Configuration Manager Setup><07-25-2012 00:58:51.758+420><thread=1752 (0x6D8)>
    INFO: File for Silverlight.exe [Silverlight Runtime] will be copied with file name: Silverlight.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: Processing file group "WIC"  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: Processing file "wic_x86_enu.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=234177.  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: File for wic_x86_enu.exe [Windows Imaging Component 32 Bit] will be copied with file name: wic_x86_enu.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: Processing file "wic_x64_enu.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.759+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=234176.  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: File for wic_x64_enu.exe [Windows Imaging Component 64 Bit] will be copied with file name: wic_x64_enu.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: Processing file group "Dot_Net_Framework"  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: Processing file "dotNetFx40_Client_x86_x64.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=199236.  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: File for dotNetFx40_Client_x86_x64.exe [.NET Framework Client Profile 4.0 RTM] will be copied with file name: dotNetFx40_Client_x86_x64.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: Processing file "dotNetFx40_Full_x86_x64.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.760+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=224688.  $$<Configuration Manager Setup><07-25-2012 00:58:51.761+420><thread=1752 (0x6D8)>
    INFO: File for dotNetFx40_Full_x86_x64.exe [.NET Framework Extended 4.0 RTM] will be copied with file name: dotNetFx40_Full_x86_x64.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.761+420><thread=1752 (0x6D8)>
    INFO: Processing file group "SQL_Redist"  $$<Configuration Manager Setup><07-25-2012 00:58:51.761+420><thread=1752 (0x6D8)>
    INFO: Processing file "SQLEXPR_x64_ENU.exe"  $$<Configuration Manager Setup><07-25-2012 00:58:51.761+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=218933.  $$<Configuration Manager Setup><07-25-2012 00:58:51.761+420><thread=1752 (0x6D8)>
    INFO: File for SQLEXPR_x64_ENU.exe [SQL Server 2008 R2 SP1 Express] will be copied with file name: SQLEXPR_x64_ENU.exe.  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: Processing file "msxml6_x64.msi"  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=169539.  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: File for msxml6_x64.msi [MSXML 6.0 Service Pack 1] will be copied with file name: msxml6_x64.msi.  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: Processing file "sqlncli.msi"  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkID=169540.  $$<Configuration Manager Setup><07-25-2012 00:58:51.762+420><thread=1752 (0x6D8)>
    INFO: File for sqlncli.msi [SQL Server 2008 Native Client] will be copied with file name: sqlncli.msi.  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: Processing file "SQLSysClrTypes.msi"  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=169541.  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: File for SQLSysClrTypes.msi [SQL Server 2008 System CLR Types] will be copied with file name: SQLSysClrTypes.msi.  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: Processing file "SharedManagementObjects.msi"  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: File will be downloaded from
    http://go.microsoft.com/fwlink/?LinkId=169542.  $$<Configuration Manager Setup><07-25-2012 00:58:51.763+420><thread=1752 (0x6D8)>
    INFO: File for SharedManagementObjects.msi [SQL Server 2008 Management Objects] will be copied with file name: SharedManagementObjects.msi.  $$<Configuration Manager Setup><07-25-2012 00:58:51.764+420><thread=1752 (0x6D8)>
    ERROR: Verification failed: File e:\SCCMPreReqs\msrdcoob_x86.exe not found  $$<Configuration Manager Setup><07-25-2012 00:58:51.764+420><thread=1752 (0x6D8)>
    ====================================================
    Regards, Vik Singh "If this thread answered your question, please click on "Mark as Answer"

    The file I was hosting is available from Microsoft's site here http://go.microsoft.com/fwlink/?LinkID=234176
    Manually download this and put it into the target dir when running setupdl.exe  from \%SCCM SOURCE LOCATION%\SMSSETUP\BIN\X64\
    I have confirmed that this file is available to download any further issues would be isolated to your environment.
    Regards
    Matt Thorley
    En español
    para Diana....
    El archivo
    estaba dando
    está disponible
    en el sitio
    de Microsoft aquí
    http://go.microsoft.com/fwlink/?LinkID=234176
    Manualmente
    descargar esto
    y ponerlo
    en el
    directorio de destino
    cuando se ejecuta
    setupdl.exe desde
    \%SCCM SOURCE LOCATION%\SMSSETUP\BIN\X64\
    He confirmado
    que este
    archivo está
    disponible para
    descargar cualquier
    problema adicional
    sería aislada
    de su
    entorno.
    Saludos

  • SCCM 2012 - 802.1x authentication for zero touch installation

    Hi guys,
    I'm setting up a demo environment for sccm 2012. Our customer has the requirement to enforce 802.1x authentication (username & password without certificates) on the network. So I need a 802.1x integration into the WinPE image, that clients can access
    the install vlan instead of the guest vlan during the zero touch Windows 7 OS install process.
    What I did before:
     - mount the SCCM modified WinPE image (boot.XXX99999.wim)
     - integration of the KB972831 hotfix into the WinPE
     - creation of a lan profile and eap profile file
     - copy both files into the mounted image
     - creation of new wim file
    I've booted the boot wim via a usb stick to test the 802.1x integration with the following commands:
      net start dot3svc
      => The Wired AutoConfig service was started successfully
      netsh lan add profile filename="X:\8021x\Local Area Connection.xml " interface="Local Area Connection"
      => The profile was added successfully on the interface Local Area connection
     netsh lan set eapuserdata filename=x:\8021x\Wired-WinPE-UserData-PEAP-MSChapv2.xml allusers=yes interface="Local Area Connection"
      => Error setting user data for interface Local Area Connection. The operation is not supported.
    Actually I can't post web links here. If the files are needed I can send them per mail.
    What can I do to solve this problem?
    Thanks!
    Regards
    Bastian

    Hi!
    Did you gave a look at this website: http://myitforum.com/cs2/blogs/lakey81/archive/2011/07/06/configuring-802-1x-network-authentication-for-winpe-3-0-and-configmgr-deployments.aspx
    I've followed those steps and it worked as a charm, even for WinPE 4.0.
    If you have questions let me know.
    Cheers.

  • App-V Streaming in SCCM 2012 - High Availability Possible?

    Hello All,
    Background:
    I'm in the process of designing an SCCM 2012 R2 environment, and one of the things that needs planning for is App-V.
    Currently the client uses App-V 4.5 management servers with a mixture of 4.5 and 4.6 apps so I've been told. There are 2 servers and they are load balanced, I think the SQL server used is clustered. I need to bring this App-V environment into SCCM 2012 R2,
    and as such I am concerned about High availability. (I'm also aware of compatibility of app v packages but this is beside the point)
    SCCM will manage around 7000 workstations, and up to 20,000 users all in all (obviously not at once). The majority of users use any machine, they do not have dedicated ones. The hierarchy will consist of one standalone primary site with SQL on box and I will
    be configuring multiple distribution points and management points.
    Question:
    It is my understanding that Management Points cache policies, and distribution points obviously have all the data cached so to speak. Therefore, if a user is already assigned to a group which is assigned to particular streamed applications - if connection was
    lost to the site database server, and they logged onto a new machine, would they still be able to run those streamed applications? Or would the Site database going down break this?
    Thanks
    Stefan

    Yeah that's a good point Torsten, Thanks - this is what I was unclear on and wanted clarification on. Was happy with the answer but thinking about it now you have said that, I dont see how that can work either...
    If im getting it right now, it would be ok if someone has already logged onto the machine, as the profile would have already been populated with the virtual application information pulled down after the client had run the evaluation and MP had retreived
    the information from the site DB when it was previously online - in that case the application would still work (and be visible) as the client has previoulsy known about it and clicking it can still stream it from the DB.
    But in the case of a new login, are we saying that the MP does not cache policies to the extent that it would know that user would be assigned a particular application - it would have to go back to the site DB for this information - which would be unavaliable
    and therefore would break it?

  • App-V 5.0 SP2 user applications published via SCCM 2012 to VDI workstations with roaming only

    Hi,
    The environment consists of App-V 5.0 SP2 (KB2956985) user based applications published via SCCM 2012 to Windows 7 VDI snapshotted workstations that are reset at user logoff.
    When a user logs on the SCCM 2012 client initiates App-V client package publishing.  After a couple of minutes after logon the shortcuts appear and the user can launch their applications.
    The issue is that at logoff, even with roaming enabled, the publishing information disappears.  This causes the next logon process for that user to repeat, the applications are not available until the SCCM client has completed it's publishing cycle. 
    Roaming profiles are implemented. %APPDATA% is redirected to a UNC path.  The following registry key is set
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppV\Client\Integration\PreserveUserIntegrationsOnLogin=1
    U-EV, global publishing of applications, and AppLocker rules are not an option.  Also, I have read this already - http://technet.microsoft.com/en-us/library/dn659478.aspx#BKMK_PE
    I do not want to wait for the SCCM client to kick in prior to the user applications being available.  What do I need to roam or run to create a seamless transition for the user between sessions? 
    Eddie.

    Hi Tywin (bad username considering the last GoT Episode ;))
    If you ask Microsoft, they always recommend using SCCM for deploying App-V packages and reuse your current SCCM infrastructure if that is already in place. Problem is, as you now experience, is that there is some big caveats both in regards to publishing
    time and to roaming of settings.
    As Nické states I would suggest looking into the Full Infrastructure Model for App-V 5.x, which gives you much better performance in what I call "from no apps" to "being able to click the shortcut" - the add and publishing phase. If you don't have the time/budget/whatever
    to start looking into that, you could look into some community tools like App-V Scheduler which is developed specific by Citrix guys to ease the publishing and management in a Citrix world.
    Microsoft have a great article about Performance Guidelines, which you have read, but it mostly presumes you work with Full Infrastructure. Have you looked into Steve Thomas' session from TechEd NA? It talks about "implementation trends".
    Senior Consultant at Atea Denmark - http://Atea.dk Atea Technical Evangelist for App-V NoLightPeople - http://NoLightPeople.com Access Director - http://www.nolightpeople.com/index.aspx#accessdirector

  • Wifi Profiles with PreShared Key

    Hey everyone,
    I have a client with some pretty basic requirements that would like to see from SCCM/Intune.  One of those is the ability to deploy WPA2-PSK Wireless profiles to newly enrolled Intune devices (iOS, Android, and WP8).  They would like to deploy
    the PSK as part of this process so they don't have to hand out the key to everyone.  I see there isn't a way in the interface to configure a WPA profile with the PSK.  Does anyone know if this possible any other way?  
    If not I guess unless your not broadcasting your SSID, what would be the advantage of deploying a WPA-PSK WiFi profile versus the user just selecting the SSID and clicking connect themselves from whatever device they are on?  Maybe I am missing something?
    Thanks!

    Hi,
    No you are correct it is currently not possible.. The only benefit of deploying the WIFI profile is that the device will connect to it automatically but still you would have to enter the password.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Pre-requisites for SCCM 2012 R2

    Hi Experts,
    I want to know is it mandatory to install and configure WDS, WSUS and MDT before deploying SCCM 2012 R2
     Are the Above roles prerequisites....????
    What would be the possible pre-requisites for SCCM 2012 R2..???

    For the pre-requisites, you can refer to the article that Torsten already shared.
    As Torsten already mentioned, the installation of WDS, WSUS and MDT is optional. However, if you are planning to do OS Deployment (OSD) then consider installing WDS and MDT (Of course, you can install MDT if you would like to take advantage of its use).
    As for WSUS, you can consider installing it if you would like to ensure a central management of Software Updates. So, depending on your requirements, you can decide what to do.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Import certificate in to Firefox certificate store using SCCM 2012 R2

    Hello,
    I'm trying to figure out how to import a certificate in to the Firefox certificate store using SCCM 2012 R2 to push out to 8,000 computers. The only answer I have found was to import the certificate manually on my computer and copy the "cert8.db" file out of my "appdata\Roaming\Mozilla\Firefox\Profiles\******.default\" folder and use this file to copy to all profiles on each computer. I have not tried this since I believe this is not a standard practice. Is there a Firefox certificate scripting tool that I can use to accomplish this or a recommended way?
    Thanks,
    Matt

    Hi,
    It is listed here:http://technet.microsoft.com/en-us/library/gg712298.aspx
    There are a number of limitations to supporting workgroup computers:
    Workgroup clients cannot locate management points from Active Directory Domain Services, and instead must use DNS, WINS, or another management point.
    Global roaming is not supported, because clients cannot query Active Directory Domain Services for site information.
    Active Directory discovery methods cannot discover computers in workgroups.
    You cannot deploy software to users of workgroup computers.
    You cannot use the client push installation method to install the client on workgroup computers.
    Workgroup clients cannot use Kerberos for authentication and so might require manual approval.
    A workgroup client cannot be configured as a distribution point. System Center 2012 Configuration Manager requires that distribution point computers be members of a domain.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • SCCM 2012 SP1 OSD in 802.1X environment

    Dears, 
    we have SCCM 2012 SP1 CU5, and the network team has enabled the CISCO port security (802.1X network authentication) on the desktops VLAN and OSD is not working since then until port security is removed. i've seen some guides regarding how to make SCCM 2007
    OSD, WinPE 3.0 and 802.1X work together like : http://myitforum.com/cs2/blogs/lakey81/archive/2011/07/06/configuring-802-1x-network-authentication-for-winpe-3-0-and-configmgr-deployments.aspx  , but ot's very confusing.
    does anybody have the same scenario with SCCM 2012, WinPE 5.0, and 802.1X . please help me.

    Hello,
    What confused you here? 802.1X authentication is to authenticate before sending network packages. That is why we need import netwrok profile to win pe for anthentication. The point is authenticate, so I think it won't be any difference between
    ConfigMgr 2012 and 2007.          
    Another good article here:
    http://blogs.technet.com/b/deploymentguys/archive/2010/03/02/adding-support-for-802-1x-to-winpe.aspx
    Please also pay attention to the shared document in the blog.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • WSUS 4.0, SQL server, and SCCM 2012 version help

    I am trying to get to the bottom of a version question.
    We currently have SCCM 2012 R2 up and running, with a DB on a separate server version MSQL 2008 R2. Now we also are using the WSUS integration. I am being told WSUS 4.0 cannot be ran on SQL server 2008 R2, so they could only install and use WSUS version
    3.0.
    Can anyone out there please shed some light on my version items from above?
    Thank you

    I am being told WSUS 4.0 cannot be ran on SQL server 2008 R2, so they could only install and use WSUS version 3.0.
    (Pedantically speaking this is true because there is no such beast as "WSUS 4".)
    However, WSUS v6.2 (Windows Server 2012) and WSUS v6.3 (Windows Server 2012 R2) can most certainly be installed on SQL Server 2008 R2, and the official documentation is at
    http://technet.microsoft.com/en-us/library/hh852344.aspx
    However, the *preferred* installation methodology, unless you've expressly chosen to use a remote SQL Server, is to use the Windows Internal Database feature which is built into Windows Server 2012 and 2012 R2.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • Unable to reinstall WSUS on SCCM 2012 Server

    I'm trying to reinstall WSUS on my SCCM 2012 Server after having removed the SUP role from SCCM and then following
    these steps to remove WSUS from the server. However I am not able to reinstall WSUS. I also tried all of the steps outlined
    here but no luck. Here are the results from the WSUSSSetup.log:
    2014-05-05 12:16:44  Success   MWUSSetup          Detected that setup was launched through Server Manager
    2014-05-05 12:16:45  Success   MWUSSetup          Validating pre-requisites...
    2014-05-05 12:16:45  Error     MWUSSetup          Failed to determine if an higher version of WSUS is installed. Assuming it is not... (Error 0x80070002: The system cannot find the file specified.)
    2014-05-05 12:16:45  Error     MWUSSetup          WSUS is outdated. But this will not block setup (Error 0x00000000: The operation completed successfully.)
    2014-05-05 12:19:05  Success   MWUSSetup          Initializing installation details
    2014-05-05 12:19:05  Success   MWUSSetup          Skipping Asp.Net install since not running on win2k3...
    2014-05-05 12:19:05  Success   MWUSSetup          Installing wYukon using ocsetup
    2014-05-05 12:19:05  Success   MWUSSetup          Installing Windows Internal database using ocsetup with command line as "ocsetup "WSSEE" /quiet /norestart"
    2014-05-05 12:19:16  Error     MWUSSetup          The process ocsetup "WSSEE" /quiet /norestart returned error: 0x643 (Error 0x80070643: Fatal error during installation.)
    2014-05-05 12:19:16  Error     MWUSSetup          ExecCmd failed (Error 0x80070643: Fatal error during installation.)
    2014-05-05 12:19:16  Error     MWUSSetup          Install Windows Internal database: Failed to execute "ocsetup "WSSEE" /quiet /norestart" (Error 0x80070643: Fatal error
    during installation.)
    2014-05-05 12:19:16  Error     MWUSSetup          CInstallDriver::PerformSetup: Installation of wYukon failed (Error 0x80070643: Fatal error during installation.)
    2014-05-05 12:19:16  Error     MWUSSetup          CSetupDriver::LaunchSetup: Setup failed (Error 0x80070643: Fatal error during installation.)
    2014-05-05 12:19:23  Error     MWUSSetup          DoInstall: Wsus setup failed (Error 0x80070643: Fatal error during installation.)
    I am at a loss, any suggestions would be greatly appreciated. Perhaps I can try installing SQL express and use that as my database rather than WID, since the problem appears to be with WID installation?
    Shaun

    Another question then - is it okay to have WSUS reside on the same server as SCCM, but without using SCCM SUP role to manage updates?
    I would strongly discourage it. If you're using a single Configuration Manager instance, then most notably ConfigMgr installs an SSL-enabled Management Point website which has been known to interfere with a non-SSL standalone WSUS server.
    But perhaps more importantly, looking for the long term, if at some point you determined you wanted to enable a Software Update Point, you'd be backed into the corner with your standalone WSUS already installed on the Site Server.
    Converting an in-use WSUS Server to a SUP is fraught with complications, the least of which is being without a patch management environment for some period of time whilst you "convert" from standalone WSUS to ConfigMgr Software Updates.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • Top 4 basic issues that are encountered in SCOM 2012 and SCCM 2012

    HI,
    I need to give a presentation on the basic issues that are encountered in SCOM 2012 and SCCm 2012.
    Can anyone help me out with this?
    Thanks in advance
    Rohith Kumar

    Hi,
    I am not familiar with SCCM, so I will give some issue I encounterred in SCOM:
    1. Not monitored and grey agent, here is an article for your reference:
    http://technet.microsoft.com/en-us/library/hh212723.aspx
    2. Failed to discover and install agents, this may caused by the action account or install account does not have proper permissions to install the agents. Some time maybe the discovery rule is not enabled.
    3. Failed to import Management Pack, this may caused by references MPs are not imported to the management group, or sometime the proper referenced MPs are imported, but there may be incorrect typing in the XML file which defines the management pack.
    4. Runas account and Action account fail. If you change password for action account, you may also need to change the password everywhere the account is used in SCOM. For run as account, if the account does not have enough right to run some tasks, we may
    encounter errors. You may refer to the below link which take SQL mp for example:
    http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx
    Regards,
    Yan Li
    Regards, Yan Li

  • SCCM 2012 R2 Mac Management - Step-by-Step

    Hi,
    Can anyone please shed some lights on steps I have taken to manage Mac?
    Active Directory:
    Create 2 groups and named them as follow
    ConfigMgr_IIS_SERVERS_CERTIFICATE
    ConfigMgr_MAC_ENROLLMENT_USERS
    PKI:
    Duplicate following templates
    Web Server Authentication ==> Duplicate and Rename it to ConfigMgr_WEBSERVER_CERT
    ==>Allow Read and Enroll Permission to
    ConfigMgr_IIS_SERVERS_CERTIFICATE Group
    Authenticated Session ==> Duplicate and Rename it ConfigMgr_Mac_CERT
    Workstation Authentication ==> Duplicate and Rename it to ConfigMgr_DistributionPoint_CERT ==> Allow Read and Enroll Permission to
    ConfigMgr_IIS_SERVERS_CERTIFICATE Group ==> Click on Subject tab
    and change subject name format:” to Command name and uncheck “User principle name (UPN)” box
    SCCM 2012:
    Let's say for example there would be a dedicated server to support Mac Management and called it
    "SCCM MAC SERVER". Add following roles on this server
    Enrollment Point
    Enrollment Proxy Point
    Management Point (Client Connections: HTTPS, "Allow mobile devices and Mac computers to use this management point" option checked)
    Distribution Point (HTTPS, Allow intranet and internet connections)
    Add "SCCM MAC SERVER" to AD group "ConfigMgr_IIS_SERVERS_CERTIFICATE"
    Open SCCM Console on CAS -> Administrations -> Client Settings -> Default Settings --> Properties -> Enrollment. Make following changes
     Allow users to enroll mobiledevices and mac computers ->YES
    Click on Set Profile button to create new profile
    Give a name "ConfigMgr - Mobile and Mac Profile"
    Click on Add button, select Enterprise CA authority
    Select ConfigMgr_Mac_CERT and click OK to save the profile
    Assign desired users to AD group ConfigMgr_MAC_ENROLLMENT_USERS
    I will highly appreciate if anyone can give their feedback as if I missed any step in here or I am good to proceed with mac management.
    Thank you and Regards,
    Hunzai

    I think you are correct with 3, I have 4 but have one for Windows clients too.
    1 Web Server.
    1 Distribition Point
    1 Windows client
    1 Mac client.
    I have used this blog which I found helpful.
    http://sccmguy.com/2013/11/26/pki-certificates-for-configuration-manager-2012-r2-part-1-of-4-web-server-certificate/
    There are 4 parts with links, they are just an exact replica from Microsoft with the exact same wording but pictures too.
    http://technet.microsoft.com/en-us/library/gg682023.aspx
    Mac cert details here:
    http://technet.microsoft.com/en-us/library/gg682023.aspx#BKMK_MacClient_SP1

Maybe you are looking for