Deploying Configuration Manager Current Branch with PKI - Step by Step
Deploying Configuration Manager Current Branch with PKI - Step by Step
About the Book
This book covers the entire end-to-end planning, installing, updating, configuring and deploying a complete system with a full PKI infrastructure to boot! That element alone, documented in Chapter 2, cannot be overemphasized and is worth the cost of the book all by itself! When I was looking into the implementation of the then-new and shiny Internet Based Client Management (IBCM) feature many years ago, all I knew of PKI was how to spell it. I would have given anything for this information back then. For you, it’s all crystal clear, and found right here in chapter 2.
Beyond that element, you will first see listed out all the prerequisites necessary, the various roles and features to be implemented, the black magic that is SQL Server, your domain configurations clearly explained and necessary (which will keep your Domain Admins away from your desk!), and then walk you through how to install it all. You’ll then end up with SSL security, the MDT Toolkit fully integrated, updated to Current Branch 1710, initial configuration settings applied, and clients deployed. In other words, you’ll create a completely functional system with all of the latest-and-greatest. If you’re naturally lazy like me, and you don’t particularly want to go through all of this yourself but just want it DONE so you can get on with it, guess what? There’s a SCRIPT to do it all FOR you!!!
Lastly, the authors’ then go on to also manage all of that hocus-pocus called networking! I never pretended to be a network engineer. As far as I’m concerned, they all live in a foreign land complete with its own language. NAT? Wasn’t that a famous singer back in the day??? What’s that got to do with anything? Well, in a simple-to-follow procedure in the prerequisites section, they make it all clear, and why.
Table of Contents
Foreword by: Ed Aldrich iii
Acknowledgements iv
From Dave iv
About the Authors v
Dave Kawula - MVP v
Allan Rafuse – MVP vi
Cristal Kawula – MVP vii
Emile Cabot - MVP viii
Technical Editors ix
Cary Sun – CCIE #4531 (Future Microsoft MVP) ix
Contents xi
Introduction 16
North American MVPDays Community Roadshow 16
Sample Files 17
Additional Resources 17
Chapter 1 19
Pre-Requisites 19
Lab Server Names 19
Building the Lab with BigDemo_CM.PS1 21
Enable Routing in the Lab 25
Software Requirements 39
Configure Certificate Authority to Support SHA256 certificates 40
Create Configuration Manager Groups and Users 41
Configuration Manager Service Accounts Required for Build 43
Chapter 2 45
Configuring PKI for Configuration Manager Current Branch 45
Create and Issue Web Certificates 45
Enroll Web Certificate on the site server 52
Create and Issue Windows Client Certificate 58
Create and issue the Workstation Authentication certificate template on the certification authority 60
Configure Autoenrollment of the Workstation Authentication Template by using Group Policy 66
Automatically enroll the Workstation Authentication certificate and verity its installation on computers 69
Deploy the Client Certificate to Distribution Points 71
Create and issue a custom Workstation Authentication certificate on the Certificate Authority 71
Request the custom Workstation Authentication Certificate on the Distribution Points 78
Export the Client Certificate for the rest of the Distribution Points 82
Chapter 3 86
Install required Roles and Features 86
Using the ConfigMgr Prerequisites Tool 3.01 86
Download and Install the ConfigMgr Prerequisite Tool 87
Install the core Features / Roles for a Single Primary Site Server 89
Install the core Features / Roles for a Management Point 90
Install the core Features / Roles for a Distribution Point 91
Download and Install Windows ADK for Windows 10, version 1709 92
Install WSUS Role 93
Add a 2 VHDx drives to the Config MGR Server for the Site Server and SQL Install 95
Chapter 3 104
Install SQL Server 2016 SP1 104
SQL Server Service Accounts 104
Configure SQL Firewall Port Exceptions 105
Install Default Instance of SQL 2016 SP1 109
Download and Install SQL Server Managemetn Studio (SSMS) 118
Configure SQL Server Memory Limits 120
Chapter 5 124
Configure Domain Settings 124
Configure Firewall Group Policy for Configuration Manager Client Communication 124
Mount Configuration Media on Site Server 130
Extend AD Schema 132
Create System Management Container 134
Chapter 4 140
Install Configuration Manager Current Branch 1702 140
Configure SSL Bindings 140
Install MDT 2013 Update 2 build 8443 145
Configure No_SMS_on_Drive.sms 149
Install Site Server Role 150
Register CMTrace as the Default Log Viewer 162
Perform MDT Integration with CM 163
Verify Console Status and System Health 166
Chapter 5 168
Update to Configuration Manager Current Branch 1710 168
Upgrade to Current Branch 1710 using In-Console Upgrade 168
Chapter 6 178
Configuring Initial Site Settings 178
Enable Discovery Methods 178
Configure the Subnets in AD Sites and Services 183
Configure Boundaries 185
Configure Boundary Groups 187
Configure Client Push Installation Settings 190
Chapter 7 192
Deploy Clients 192
Configure Client Push Installation Settings 192
Deploy Clients to the Lab 194
Appendix 199
BigDemo_CM.PS1 199
Contact Info 215
Join us at MVPDays and meet great MVP’s like this in person 215
Live Presentations 215
Video Training 215
Live Instructor-led Classes 216
Consulting Services 216
Twitter 217
Other books by these authors
Authors have earned$9,886,858writing, publishing and selling on Leanpub, earning 80% royalties while saving up to 25 million pounds of CO2 and up to 46,000 trees.
Learn more about writing on Leanpub
The Leanpub 45-day 100% Happiness Guarantee
Within 45 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers), EPUB (for phones and tablets) and MOBI (for Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them
Top Books
C++ Best Practices
Jason TurnerLevel up your C++, get the tools working for you, eliminate common problems, and move on to more exciting things!
OpenIntro Statistics
David Diez, Christopher Barr, Mine Cetinkaya-Rundel, and OpenIntroA complete foundation for Statistics, also serving as a foundation for Data Science.
Leanpub revenue supports OpenIntro (US-based nonprofit) so we can provide free desk copies to teachers interested in using OpenIntro Statistics in the classroom and expand the project to support free textbooks in other subjects.
More resources: openintro.org.
Functional Design and Architecture
Alexander GraninSoftware Design in Functional Programming, Design Patterns and Practices, Methodologies and Application Architectures. How to build real software in Haskell with less efforts and low risks. The first complete source of knowledge.
Atomic Kotlin
Bruce Eckel and Svetlana IsakovaFor both beginning and experienced programmers! From the author of the multi-award-winning Thinking in C++ and Thinking in Java together with a member of the Kotlin language team comes a book that breaks the concepts into small, easy-to-digest "atoms," along with exercises supported by hints and solutions directly inside IntelliJ IDEA!
R Programming for Data Science
Roger D. PengThis book brings the fundamentals of R programming to you, using the same material developed as part of the industry-leading Johns Hopkins Data Science Specialization. The skills taught in this book will lay the foundation for you to begin your journey learning data science. Printed copies of this book are available through Lulu.
I am a Software Engineer and I am in Charge
Alexis Monville and Michael DoyleI am a Software Engineer and I am in Charge is a real-world, practical book that helps you increase your impact and satisfaction at work no matter who you work with.
In the book, we will follow Sandrine, a fictional character who learns to think in a new way enabling her to take a different course of action.
C++20
Rainer GrimmC++20 is the next big C++ standard after C++11. As C++11 did it, C++20 changes the way we program modern C++. This change is, in particular, due to the big four of C++20: ranges, coroutines, concepts, and modules.
Invest In Digital Health - The Medical Futurist's Guide
Dr. Bertalan MeskoArtificial Intelligence and Digital Health are booming. In this book, we explain why now it's a good time to invest in Digital Health and give recommendations on where to invest by looking at the top 24 technological trends we find the most promising.
Ansible for DevOps
Jeff GeerlingAnsible is a simple, but powerful, server and configuration management tool. Learn to use Ansible effectively, whether you manage one server—or thousands.
The Hundred-Page Machine Learning Book
Andriy BurkovEverything you really need to know in Machine Learning in a hundred pages.
Top Bundles
- #1
Software Architecture for Developers: Volumes 1 & 2 - Technical leadership and communication
2 Books
"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before... - #2
CCIE Service Provider Ultimate Study Bundle
2 Books
Piotr Jablonski, Lukasz Bromirski, and Nick Russo have joined forces to deliver the only CCIE Service Provider training resource you'll ever need. This bundle contains a detailed and challenging collection of workbook labs, plus an extensively detailed technical reference guide. All of us have earned the CCIE Service Provider certification... - #3
The Future of Digital Health
6 Books
We put together the most popular books from The Medical Futurist to provide a clear picture about the major trends shaping the future of medicine and healthcare. Digital health technologies, artificial intelligence, the future of 20 medical specialties, big pharma, data privacy and how technology giants such as Amazon or Google want to conquer... - #4
Cisco CCNA 200-301 Complet
4 Books
Ce lot comprend les quatre volumes du guide préparation à l'examen de certification Cisco CCNA 200-301. - #5
Modern Management Made Easy
3 Books
Read all three Modern Management Made Easy books. Learn to manage yourself, lead and serve others, and lead the organization. - #6
CCDE Practical Studies (All labs)
3 Books
CCDE lab - #7
Modern C++ by Nicolai Josuttis
2 Books
- #8
"The C++ Standard Library" and "Concurrency with Modern C++"
2 Books
Get my books "The C++ Standard Library" and "Concurrency with Modern C++" in a bundle. The first book gives you the details you should know about the C++ standard library; the second one dives deeper into concurrency with modern C++. In sum, you get more than 600 pages full of modern C++ and about 250 source files presenting the standard library... - #9
Linux Administration Complet
4 Books
Ce lot comprend les quatre volumes du Guide Linux Administration :Linux Administration, Volume 1, Administration fondamentale : Guide pratique de préparation aux examens de certification LPIC 1, Linux Essentials, RHCSA et LFCS. Administration fondamentale. Introduction à Linux. Le Shell. Traitement du texte. Arborescence de fichiers. Sécurité... - #10
Advanced Product Management
3 Books
Get The Art of Strategy, Product Discovery and Lean Product Management with a 20% discount.