Setting SCCM Cloud Management gateway step-by-step in my lab using certificates from internal CA PT1

preview_player
Показать описание
We will also see how to generate certificates, request them and use them to setup CMG in SCCM for managing Windows 10 clients over the internet.

This is part-1, in part -2 we will enable SCCM agent to use CMG forusers who are working from home over public internet with no VPN connectivity to on-prem and they cannot come to office to connect the PC and get the SCCM policy so that SCCM agent knows the URL of CMG.
We will give a script to users which will run with local admin credentials and re-install SCCM agent on machine using cloud MP as users do not have local admin rights

PT-2 link
Рекомендации по теме
Комментарии
Автор

Thanks for your effort in explaining the whole thing related to CMG. That was really helpful.

subhojitchoudhury
Автор

Good explanation.. Appreciate your effort ..

soheluddin
Автор

Thank you for video and your effort.
Quick question. Do you need client authentication certificate issued by the internet CA on the SCCM Client to be able to communicate with the CMG?
Our environment is running on HTTP only mode and I assume we can enable E-HTTP and you don't need any cert for MP / SUP?

tomsstudents
Автор

Hi Anu, is it possible to install Cloud Management Gateway on a server which have DP role only?

benedict
Автор

Hi Chief, at 13:13, you've also added your external domain to the internal DNS forwarding zone. Can you demonstrate how you added it and what other configurations are required?
Thanks

Dadisfit
Автор

Hi we currently have our CMG but it is intermittently failing the last test in the connection analyzer and only restarting the CMG services in Sccm seem to fix it but only for a short time do you have any ideas what I could check?

robtsan
Автор

Hi Anubhav, thank you for the detailed explaination. I have one question regarding server authentication certificate, if I decide use FQDN as "mycmg.cloudapp.net" while requesting the certificate, should I still create a CName. If it is not required then why not use cloudapp.net instead of using a domain based FQDN?

prasanthreddy
Автор

Thanks for the great video Chief... Just trying to figure out, do I actually need a public domain ? Is there any way I can workaround without it ? I have internal PKI (CA installed on DC).

Henuntl
Автор

Hi Abhinav, if I have to deploy applications from SCCM to Intune only windows 10 devices do I need co-management setup? or just cloud management gateway will suffice?

prasanthreddy
Автор

Thank you Anubhav, for the detailed Video on CMG configuration. I have a Standalone Primary site server in HTTP mode with Azure AD. Can I configure the CMG using Public certificate and do I need to import the Public certificate in to the Site Server where I am installing MP and SUP role as HTTPS enabled.

skconfigseekhle
Автор

Thanks for your videos, but could you increase the video quality little bit

ehabgalal
Автор

Smoke detector battery warning beeping in the background of your videos?

webcomment
Автор

Hello Anubhav, Hope you doing well.
Could you please help me on this, when i try to configure CMG its throwing error " A valid azure ad app is required. Please deploy azure service for Cloud management first" even though i already deployed both the apps also am a global admin. Your response will be appreciated. Thanks in Advance !!

soheluddin