Deploying Configuration Manager Current Branch with PKI - Step by Step
Deploying Configuration Manager Current Branch with PKI - Step by Step
About the Book
This book covers the entire end-to-end planning, installing, updating, configuring and deploying a complete system with a full PKI infrastructure to boot! That element alone, documented in Chapter 2, cannot be overemphasized and is worth the cost of the book all by itself! When I was looking into the implementation of the then-new and shiny Internet Based Client Management (IBCM) feature many years ago, all I knew of PKI was how to spell it. I would have given anything for this information back then. For you, it’s all crystal clear, and found right here in chapter 2.
Beyond that element, you will first see listed out all the prerequisites necessary, the various roles and features to be implemented, the black magic that is SQL Server, your domain configurations clearly explained and necessary (which will keep your Domain Admins away from your desk!), and then walk you through how to install it all. You’ll then end up with SSL security, the MDT Toolkit fully integrated, updated to Current Branch 1710, initial configuration settings applied, and clients deployed. In other words, you’ll create a completely functional system with all of the latest-and-greatest. If you’re naturally lazy like me, and you don’t particularly want to go through all of this yourself but just want it DONE so you can get on with it, guess what? There’s a SCRIPT to do it all FOR you!!!
Lastly, the authors’ then go on to also manage all of that hocus-pocus called networking! I never pretended to be a network engineer. As far as I’m concerned, they all live in a foreign land complete with its own language. NAT? Wasn’t that a famous singer back in the day??? What’s that got to do with anything? Well, in a simple-to-follow procedure in the prerequisites section, they make it all clear, and why.
Bundles that include this book
Table of Contents
Foreword by: Ed Aldrich iii
Acknowledgements iv
From Dave iv
About the Authors v
Dave Kawula - MVP v
Allan Rafuse – MVP vi
Cristal Kawula – MVP vii
Emile Cabot - MVP viii
Technical Editors ix
Cary Sun – CCIE #4531 (Future Microsoft MVP) ix
Contents xi
Introduction 16
North American MVPDays Community Roadshow 16
Sample Files 17
Additional Resources 17
Chapter 1 19
Pre-Requisites 19
Lab Server Names 19
Building the Lab with BigDemo_CM.PS1 21
Enable Routing in the Lab 25
Software Requirements 39
Configure Certificate Authority to Support SHA256 certificates 40
Create Configuration Manager Groups and Users 41
Configuration Manager Service Accounts Required for Build 43
Chapter 2 45
Configuring PKI for Configuration Manager Current Branch 45
Create and Issue Web Certificates 45
Enroll Web Certificate on the site server 52
Create and Issue Windows Client Certificate 58
Create and issue the Workstation Authentication certificate template on the certification authority 60
Configure Autoenrollment of the Workstation Authentication Template by using Group Policy 66
Automatically enroll the Workstation Authentication certificate and verity its installation on computers 69
Deploy the Client Certificate to Distribution Points 71
Create and issue a custom Workstation Authentication certificate on the Certificate Authority 71
Request the custom Workstation Authentication Certificate on the Distribution Points 78
Export the Client Certificate for the rest of the Distribution Points 82
Chapter 3 86
Install required Roles and Features 86
Using the ConfigMgr Prerequisites Tool 3.01 86
Download and Install the ConfigMgr Prerequisite Tool 87
Install the core Features / Roles for a Single Primary Site Server 89
Install the core Features / Roles for a Management Point 90
Install the core Features / Roles for a Distribution Point 91
Download and Install Windows ADK for Windows 10, version 1709 92
Install WSUS Role 93
Add a 2 VHDx drives to the Config MGR Server for the Site Server and SQL Install 95
Chapter 3 104
Install SQL Server 2016 SP1 104
SQL Server Service Accounts 104
Configure SQL Firewall Port Exceptions 105
Install Default Instance of SQL 2016 SP1 109
Download and Install SQL Server Managemetn Studio (SSMS) 118
Configure SQL Server Memory Limits 120
Chapter 5 124
Configure Domain Settings 124
Configure Firewall Group Policy for Configuration Manager Client Communication 124
Mount Configuration Media on Site Server 130
Extend AD Schema 132
Create System Management Container 134
Chapter 4 140
Install Configuration Manager Current Branch 1702 140
Configure SSL Bindings 140
Install MDT 2013 Update 2 build 8443 145
Configure No_SMS_on_Drive.sms 149
Install Site Server Role 150
Register CMTrace as the Default Log Viewer 162
Perform MDT Integration with CM 163
Verify Console Status and System Health 166
Chapter 5 168
Update to Configuration Manager Current Branch 1710 168
Upgrade to Current Branch 1710 using In-Console Upgrade 168
Chapter 6 178
Configuring Initial Site Settings 178
Enable Discovery Methods 178
Configure the Subnets in AD Sites and Services 183
Configure Boundaries 185
Configure Boundary Groups 187
Configure Client Push Installation Settings 190
Chapter 7 192
Deploy Clients 192
Configure Client Push Installation Settings 192
Deploy Clients to the Lab 194
Appendix 199
BigDemo_CM.PS1 199
Contact Info 215
Join us at MVPDays and meet great MVP’s like this in person 215
Live Presentations 215
Video Training 215
Live Instructor-led Classes 216
Consulting Services 216
Twitter 217
Other books by these authors
The Leanpub 60 Day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
Now, this is technically risky for us, since you'll have the book or course files either way. But we're so confident in our products and services, and in our authors and readers, that we're happy to offer a full money back guarantee for everything we sell.
You can only find out how good something is by trying it, and because of our 100% money back guarantee there's literally no risk to do so!
So, there's no reason not to click the Add to Cart button, is there?
See full terms...
Earn $8 on a $10 Purchase, and $16 on a $20 Purchase
We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.
(Yes, some authors have already earned much more than that on Leanpub.)
In fact, authors have earnedover $13 millionwriting, publishing and selling on Leanpub.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them