
Explore Microsoft Endpoint Configuration Manager, formerly System Center Configuration Manager, focusing on administration features, client agent installation, queries, reports, inventory, application and update deployments, OS deployment, endpoint protection, and troubleshooting.
Explore the history of configuration manager, from SMS in 1994 to Microsoft Endpoint Configuration Manager, and learn how current branch delivers updates three times a year with 18-month support.
Explore the major features of configuration manager, including hardware and software inventory, metering, asset intelligence, deployment of applications, updates, and operating systems, plus endpoint protection, compliance baselines, and remote control.
Understand the configuration manager architecture, including the site server, SQL Server database, and scalable role servers, and how management points, distribution points, and software update points support policies and deployments.
Evaluate options to cut traffic between remote offices by enabling branch cache, placing a distribution point in the remote site, or letting local clients share downloaded source files.
Boundaries and boundary groups map IP ranges to the distribution points, so Denver clients use the Denver distribution point and Albuquerque clients use the Albuquerque distribution point, reducing cross-site traffic.
Configure boundaries and boundary groups to route clients to local distribution points by city, defining ip ranges and optional ipv6 subnets, and reference Active Directory Sites and Services for import.
Enable Active Directory system discovery to import domain computer accounts into Configuration Manager, configure scope, schedule, and attributes, and verify new client entries appear in the console.
Configure active directory discovery methods in configuration manager to import computers, IP ranges, sites, and users, using forced discovery and group discovery to optimize boundaries and traffic.
Learn how network discovery finds non domain-joined computers by connecting to clients via SNMP, comparing it with domain-based Active Directory discovery and the option to install the client agent.
Heartbeat discovery, enabled by default after installation, ensures weekly client-generated discovery records so computers stay in the console even if other discovery methods fail, while 90-day aged data are purged.
Install the configuration manager client agent on endpoints using the system setup executable, join the correct site with the site code, and configure cache size and installation path for deployments.
Explore push installation of the client agent from the configuration manager console, including discovery via Active Directory system discovery, site settings, admin accounts, and optional automatic push.
Deploy the SCCM client agent via GPO and WSUS, including creating a domain policy, adding the installation template, and disguising it as a Windows Update for rollout.
Learn to install the SCCM client agent via imaging, including third-party and configuration manager imaging, while avoiding global unique ID conflicts by removing the agent’s GUID and certificates before cloning.
Explore installing the client agent via a login script in Active Directory, using system setup switches and the /logon option to prevent repeated installs, and note the admin rights requirement.
Manage non-domain joined computers with Microsoft Endpoint Configuration Manager using a network access account, covering manual install, imaging, Windows 8.1 and 10 support, Mac limitations, and Linux/Unix deprecation.
Explore internet-based client management via vpn or direct access, ibc, dmz deployments, and cloud options with cloud distribution points and cloud management gateway.
Explore the configuration manager control panel applet to view client info, components, and schedules; force actions like hardware inventory and policy retrieval to troubleshoot software deployments.
Monitor client activity in the monitoring workspace using the client activity pie chart to distinguish active and inactive devices and watch for a growing red slice.
Observe how client activity and client check monitor the Configuration Manager client, showing green if the agent runs and red when it fails, and how system eval fixes issues.
Set up and monitor client activity and client check alerts in configuration manager, using thresholds and pie charts to flag systems not interacting, with email alerts when triggered.
Access the sccm console to run queries that search the sql database for computers and users, then export results to notepad or excel; discover wql and a graphical query designer.
Create queries with the graphical interface to find Windows 10 computers with at least four gig RAM, using operating system captions and memory criteria.
Group criteria with parentheses to force evaluation order in queries, so Windows 10, RAM, and video card conditions are processed first; changing grouping yields different result sets.
Use the general tab to define visible results and omit duplicate rows, and learn inner and left outer joins to refine computer criteria.
Learn criterion types in SCCM queries, including null value, prompted value, list, selected values, attribute reference, and comparing memory to memory history to spot changes.
Export and import queries in SCCM by exporting the query definition to a map file or copying the code from show query language.
Create device collections based on queries with dynamic membership, set refresh schedules, and balance incremental updates against SQL Server load while targeting Windows 10 machines with 4 GB RAM.
Create a static device collection with a direct membership rule using filters and wildcards. Compare this with dynamic query collections and explore include and exclude rules.
Assign maintenance windows to collections to block deployments outside scheduled times, such as 1 to 4 a.m. on Tuesday, ensuring critical servers avoid inopportune reboots; merge windows as needed.
Apply power management to a collection in SCCM by selecting a power plan such as balanced, high performance, or power saver, with customized settings for work hours and after hours.
Learn how client settings policies control inventory schedules and other agent behaviors, deploy department-specific policies, and understand how hourly check-ins affect when changes take effect.
Enable hardware inventory in configuration manager to collect hardware and software details from clients, upload via the management point to the site server and database, with reporting in Resource Explorer.
Customize hardware inventory by using the set classes button to select data like memory, logical disk, and keyboard details, then export settings and wait for policy refresh.
View hardware and software inventory from the console with resource explorer, inspect attribute classes like BIOS version, serial number, processor speed, OS info, installed applications, and perform queries across database.
Explore software inventory as file inventory, collecting executables and PowerShell scripts from client hard drives. Configure a default policy, choose file types, schedule reports, and inspect results via Resource Explorer.
Enable file collection in software inventory to copy selected files from client machines to the site server, then view, open, or save the collected contents from the configuration manager console.
Enable software metering in the config manager client policy, schedule usage uploads, and create or auto-generate rules to meter specific apps; use reports to analyze usage and guide licensing decisions.
Extend inventory with asset intelligence to gather detailed information from client systems. Access a catalog of over 1.5 million software titles and license reports via the asset intelligence synchronization point.
Explore asset intelligence reports, inventory software, and catalog management; identify unidentified applications, request catalog updates, and monitor product life cycle to avoid end-of-life risks.
learn to run hardware and software inventory reports in configuration manager, view, print, export to pdf or excel, access reports via web, and create subscriptions for scheduled delivery.
Access almost five hundred built-in reports in configuration manager, and you can create custom reports with the Skill Report Builder by learning sequel.
Use CMPivot to run live queries directly against clients, bypassing historical data, and quickly view top recently run applications with bar charts generated by the KQ query language.
Understand deployment architecture in Configuration Manager by hosting source files on the site server, distributing to local cache via distribution points, and enabling client installs via the management point.
Create a package in Configuration Manager by specifying source files, defining a silent setup program, and configuring install options, privileges, and prerequisites for target clients.
Explore package properties in SCCM, including data source settings and update options for distribution points. See how binary differential replication and persistent cache improve deployment efficiency.
Distribute the PowerPoint viewer package from the site server to a distribution point using the distribute content wizard, and monitor progress with the pie chart from gray to green.
Update distribution points to push a new package version, sending only changed files, with optional scheduling. Validate package integrity on distribution points and remove packages to free up space.
Explore program properties in Configuration Manager: create install and uninstall programs with quiet switches, configure restarts, logoff, requirements, environment, and advanced settings, plus notifications and alerts.
Choose between required and available deployment styles in SCCM to balance automatic installs with user choice, using software center on roaming devices.
Deploy the PowerPoint viewer package to a device collection with a quiet switch; configure required or available, wake on LAN, maintenance overrides, and caching, then monitor in software center.
Learn how to deploy an application using the newer application feature in Configuration Manager, focusing on MSI/Microsoft installer files, system-wide installations, and automation of install switches.
Learn to deploy a setup executable with the application feature in SCCM by choosing script installer, then manually add the executable and complete the steps.
Explore application properties in SCCM, including publisher, version, and owner, and customize the software center icon and descriptive text while reviewing distribution points.
Learn how supersedence replaces older apps with newer versions in SCCM, choose to replace or install anew, and view the full chain of app relationships.
Use the application deployment feature rather than packages, and define requirements directly in the application—memory, cpu, disk space, and os—to ensure only compatible devices install the software.
Explore how re-evaluation in Configuration Manager runs weekly to ensure required applications stay installed and are reinstalled when missing, using the detection method with product codes or registry checks.
Deploy an application using the SCCM deploy wizard, targeting a user collection and distribution point. Explore available vs required install, application vs package features, maintenance windows, and user approvals.
Configure the cache in Configuration Manager by setting cache size or percentage, enable branch cache for remote offices, and use peer caching to reduce network traffic.
Explore client settings in SCCM to throttle distribution bandwidth, manage reboot countdowns, tune policy refresh intervals, and customize the software center, status messaging, and per-collection policies.
Enable user device affinity in SCCM to assign primary users to devices, restrict software center installs, with automatic affinity triggered after twenty eight hundred minutes of use.
Explore retirement and revision history in the configuration manager console: retire applications to hide them from users, reinstate them later, and review or restore original versions using revision history.
Explore how virtual applications integrate with configuration manager using the app sequencer from the Microsoft Desktop Optimization Pack to create isolated virtual C drives and registries for easy deployment.
Discover how to deploy virtual applications in configuration manager by creating an application and selecting App-V, then use virtual environments to connect Word and Excel across apps.
Learn to deploy Windows Store apps with Configuration Manager by either creating Store links in the Software Center or performing side loading with AppX files.
Explore update architecture: software update point downloads updates, site server stores them, distribution points deliver to clients, and clients report installed, required, not required, or unknown.
Learn to filter updates in the SCCM console, select products and update types, create software update groups, and use compliance reports to track deployment progress.
Deploy updates to a software update group or collection using a template. Configure schedule, required or available, grace period, maintenance windows, reboot suppression, distribution points, and package creation.
Utilize phased deployment in Microsoft Endpoint Configuration Manager to deploy updates to a sales collection first, then to all systems after achieving 95 percent success for seven days.
Use server groups, now called orchestration groups, in configuration manager to update cluster nodes one at a time, moving virtual machines between nodes with pre and post update scripts.
Create automatic deployment rules to deploy updates to the chosen collection, reducing manual work. Configure filters (Windows 10 and critical updates), weekly synchronization, and an update group to store deployments.
Learn to use Windows 10 servicing plans in Configuration Manager to upgrade Windows 10 versions, with semiannual channel options, delays like 100 days, and targeted deployments.
Enable third party updates in configuration manager and subscribe to third party catalogs; some vendors offer catalogs (HP, Dell, Adobe), others don't; consider services like Patch My PC or Davonte.
Explore imaging, or operating system deployment, which captures a reference computer's OS and applications into a deployable image for quick, baseline setups on new machines.
Compare thick and thin image approaches and learn to deploy a single OS image across departments using task sequences. Explore boot images with Windows PE, a minimal, command-line imaging environment.
Initiate a task sequence using a boot disk or pixie network boot, or deploy as zero touch installation to existing clients, selecting the appropriate task sequence via a wizard.
Set up a network access account, configure the state migration point, and import boot images, drivers, and OS install packages to prepare for imaging with a wipe-and-load process.
Import and organize drivers from a raw path in SCCM, unpack executables to DLL driver files, categorize by model, and create a driver package for distribution points during imaging.
Configure boot images in configuration manager, manage 32-bit and 64-bit images, and add drivers from the driver package to support imaging. Import custom boot images and distribute to distribution points.
Enable pixie on the distribution point to support network boot and task sequence imaging; manage authentication, optional password, and import unknown computers to proceed securely.
Create bootable media in configuration manager to boot clients via pixie boot or boot disk, then run a wizard to select and execute a task sequence.
Create a capture disk, insert it into a running reference computer, and run the wizard to name and store the image for upload to the shared folder.
Learn how standalone media and pre staged media enable offline imaging at remote offices by embedding the image, apps, drivers, and updates on a boot disk to avoid network traffic.
Update the deployment image by injecting current Windows updates into the image before deployment, then schedule updates and refresh distribution points so new clients receive the updated image.
Compare wipe and load and upgrade paths from Windows 8 to Windows 10, then import Windows 10 source files and create an upgrade package to distribute content to distribution points.
Create a test task sequence to deploy a Windows 10 image with accounting apps using a wipe and load, including domain join and optional user state migration.
Explore how to build and customize a task sequence in SCCM, capturing system details, handling partitioning with BIOS or UEFI, applying images, drivers, updates, and restoring user profiles.
Copy an existing test sequence to enable thin imaging, rename it for a department, and swap in department apps, enabling hundreds of tailored task sequences instead of many thick images.
Learn how to make a task sequence step conditional using WMI queries to target laptops only, running a custom script after driver installation, and use registry or OS version checks.
Master driver management in SCCM by enforcing model-specific categories and conditional steps so clients install the exact driver, with Dell's free tool to automate this process.
Deploy a task sequence from the console to existing Configuration Manager clients, boot from media, or pixie boot via a distribution point, then schedule and show progress.
Enable multicast in Configuration Manager to deliver a large image to multiple clients from the distribution point, reducing network traffic while noting prerequisites and security risks.
Discover how to customize user state migrations in SCCM by using scanstate and loadstate switches, including last-logged-on filters, offline and hard link options, and local accounts within a task sequence.
set the computer name during imaging in SCCM by using the OASDI computer name variable or a custom script; default bare-metal deployments assign random names, with prompts if left blank.
Manage antivirus from the configuration manager console with endpoint protection, integrating Windows Defender; license required, and third-party options exist but still require endpoint protection licensing.
Enable endpoint protection in SCCM by configuring the endpoint protection point, choosing data sharing with Microsoft, and applying the default policy to enforce protection by hijacking the Windows Defender service.
create and deploy endpoint protection policies in SCCM, configuring scheduled and real-time scans, exclusions, default actions (remove or quarantine), threat overrides, then assign to a collection and manage updates.
Monitor endpoint protection alerts, malware status, Defender charts, and protection reports in the SCCM console, and consider advanced threat protection cloud service for enhanced detection.
Create and deploy Windows Defender Firewall policies for domain, private, and public networks, forcing firewall on or off. Note that port controls reside in AD policy (GPO), not Configuration Manager.
Define compliance baselines in SCCM to enforce security rules, audit computers for anti-malware, updates, and blocked apps, and report compliance progress to the board.
Create configuration items to enforce a compliance baseline on Windows clients by checking the registry for remote desktop settings and remediating noncompliant machines. Explore importing security baselines to simplify setup.
Learn to create and deploy a configuration baseline from a configuration item, enable registry-based remediation, and monitor compliance with scheduled checks and alerts.
Explore how configuration manager manages user data and profiles, including folder redirection to network shares, roaming profiles, offline files, and policy controls for Edge and OneDrive.
Explore troubleshooting in configuration manager by inspecting system and component status for errors. Identify red components and review recent messages, then use online searches and Microsoft documentation to resolve issues.
Explore troubleshooting by checking the component and site status, then inspect detailed log files located on the site server and clients to pinpoint errors.
Switch from reading the hard-to-read hierarchy manager log to cmtrace, a Configuration Manager tool that highlights errors in red and reads many log files.
Enable and audit remote control with the built-in configuration manager tool. Review remote control activity via reports and manage policies and firewall rules to allow or restrict access.
Learn to initiate a configuration manager remote control session, obtain user consent, and observe and interact with the client desktop from the server, including exclusive control and session termination options.
Configure remote control in the SCCM policy for all computers, choosing whether to prompt for permission, enable unattended access, and allow user control via the software center.
In this course, students will learn how to manage the day-to-day operations of a Configuration Manager environment. Additionally, learners will find out how to collect detailed information from your clients for the purposes of queries and reports. By the end of this course, students should have the tools and skills they need to understand and use all of the software deployment capabilities to push applications, updates, and operating system images to your client systems.