
Design and build a configuration manager environment by installing the site server and configuring essential role servers. Explore distribution points, site structures, hardware sizing, internet-based clients, permissions, and ongoing maintenance.
Explore the history and current branch of Microsoft Endpoint Configuration Manager, and learn how three quarterly updates deliver small, incremental changes while staying within 18 months of the current version.
Explore the major features of endpoint configuration manager, including inventory, software metering, deployment, endpoint protection, compliance baselines, and remote control, with a focus on building the underlying infrastructure.
Examine the basic architecture of configuration manager, including the site server and SQL database. Big three roles (management point, distribution point, and software update point) drive policy, deployments, and updates.
Run the prerequisite checker to validate SQL Server 2012 or later with Latin1 collation. Avoid SQL Express for primary sites; enable Always On and use a 64-bit server with GUI.
Extend the Active Directory schema to publish Configuration Manager role server information, then grant the site server permission to the system container so clients locate role servers via domain controller.
Launch the configuration manager installation wizard to build a primary site, set language, site code, sql server and database, configure http and roles, select service connection point, and complete prerequisites.
Prepare to install the configuration manager client agent on Windows and Macintosh computers, set up the management point, and configure boundaries for targeted app deployment, inventory, and remote control.
Run the ccmsetup.exe installer to deploy the Configuration Manager client, using switches to specify your site code, configure the cache size and cache directory, and set the installation path.
Push the client agent from the SCCM console by configuring admin accounts and installation properties, enabling automatic pushes, and targeting collections while noting installation timing and sharing requirements.
Deploy the configuration manager client agent using a GPO, selecting the MCI installer. Customize installation with parameters from the installation template on the Configuration Manager DVD.
Deploy the client agent to many computers using the software update installation method with WSUS, disguising it as an update, then approve and deploy via the software update point.
Deploying the client agent via a logon script uses the /logon switch to install on first login and avoid reinstallations, but requires admin rights and is an unpopular, supported method.
Learn to include the Configuration Manager client agent during OS deployment via task sequence, integrating client installation with imaging steps such as partitioning, applying an image, domain join, and apps.
Deploy the client agent via third party imaging by creating a reference computer and cloning it, then strip the GUID before imaging to let Configuration Manager assign new IDs.
Manage non-domain joined work group clients with Configuration Manager by manual agent installation or imaging, and set a network access account to authenticate to role servers.
Offload configuration manager roles to other servers to prevent site server overload, distributing roles such as management point, distribution point, and software update point, with easy signing and reassigning later.
Explore the big three configuration manager roles: distribution point stores deployment content and handles traffic, management point issues policies and inventory uploads, software update point retrieves updates and supports scans.
Explore how the state migration point (smp) stores and restores user profiles during imaging to preserve desktop settings, and how the fallback status point (fsp) reports a broken domain trust.
Explore additional configuration manager roles, including the reporting services point, service connection point, and asset intelligence synchronization point, to offload workload and support certificate registration and enrollment workflows.
Set up the data warehouse service point to store historical inventory and application deployment data on a separate SQL Server, enabling long-term reports beyond the 90-day main database purge.
Install and configure the management point in configuration manager, including adding the role, handling admin rights, and choosing http or https. Enable alerts and connect to the site database.
Explore the software update point architecture in Configuration Manager, including Microsoft synchronization, client scan cycles, and how the site server downloads updates and distributes them via distribution points.
Install and configure a software update point on a site system server, including prerequisites, proxy options, port numbers, and synchronization settings.
Configure a state migration point and a fallback status point to preserve user profiles during imaging, with adjustable retention, upload limits, and boundary group localization.
Configure the data warehouse to store historical data with daily synchronization from the main database, and set up the reporting services point with a folder and SQL Server.
Enhance high availability in configuration manager by deploying multiple distribution, management, software update, and state migration points, plus site server passive mode and automatic failover after 30 minutes.
Optimize bandwidth in remote offices by using branch cache and distribution points in SCCM. Choose between no special setup, branch cache, or a local distribution point to reduce traffic.
Create boundaries from specific IP ranges and attach them to boundary groups with corresponding distribution points to ensure clients use the local point, minimizing cross-site traffic.
Create boundaries and boundary groups in SCCM by defining Albuquerque IP ranges, optionally importing Active Directory sites, and assigning Albuquerque role servers for VPN clients.
Configure boundary group relationships to route clients to alternate distribution points when the local point fails, selecting the fastest options and enabling localization for software update and management points.
Learn how the default site boundary group places unassigned clients into a manageable set, letting you choose role servers to ensure basic connectivity when new subnets appear.
Configure distribution point role on the server by enabling http or https, installing IIS if needed, and using branch cache, pre staged content, and Microsoft connected cache to optimize deployments.
Configure a distribution point in SCCM by setting drive reservations, selecting storage drives for content, enabling automatic spillover, and excluding a drive while distinguishing applications from packages.
Explore pull distribution points, or pole distribution points, to reduce wan traffic by having remote points pull from a central distribution point instead of the site server.
Enable pixie on the distribution point to boot clients over the network with the Windows boot image, eliminating boot disks. Manage unknown computers, passwords, and pre-staged imports for imaging.
Multicast lets you image multiple computers with one file, saving bandwidth and speeding imaging, but requires multicast-capable equipment and careful configuration due to security concerns.
Finish creating the distribution point, enable validate content on a schedule (once a week), and organize distribution points into groups or boundary groups to streamline deployments.
Set distribution point schedules to queue content for off-peak hours and throttle bandwidth with rate limits. Elevate certain packages to high priority for daytime transfer.
Enable branch cache on client settings to share cached distribution files with neighbors. Be aware of potential double storage from branch cache and config manager cache.
Enable bandwidth throttling between clients and distribution points with bits or background intelligent transfer service, setting a limit such as one meg and adjusting by work hours.
Explore deploying packages and applications to distribution points, updating distribution points on a schedule, and optimizing bandwidth with binary differential replication and cache-first install decisions.
Implementing a secondary site in a remote office localizes the management point and distribution point, reduces cross-WAN traffic, but increases administration and may use SQL Express.
Create a secondary site in configuration manager by installing management and distribution points on a remote server, configuring SQL Express, and synchronizing data with the parent site.
Explore when to deploy a remote office as a primary site in ms endpoint configuration manager, with its own site server and console for administration, and compare to secondary sites.
Learn how a central administration site acts as a parent to multiple primary sites, enabling company-wide reporting and centralized deployment across the hierarchy.
Install a central administration site using the wizard, configure language, site code, database, and console options, and set up the service connection point. You can place central administration and primary sites in either order, with primaries existing before secondaries, then run prerequisites and complete the installation.
Examine site-to-site replication in a central administration and primary site hierarchy. Configure file replication for application packages and SQL replication for policy and inventory data, with port considerations.
Right-size your configuration manager environment by sizing hardware for primary and central administration sites, including site server and SQL server requirements, CPU, RAM, and data drives.
Right-size your Microsoft endpoint configuration manager deployment by sizing role servers and sites—management points up to 25k clients each, distribution points per 4k clients, and central administration sites.
Learn internet-based client management (IBC) with Configuration Manager, using VPN and a DMZ to manage internet-connected devices, deploying apps and updates via device collections.
Configure internet-based client management by placing role servers in the DMZ with https and encryption, issuing certificates for the management point, distribution point, and software update point.
Configure outer and inner firewalls for internet-based client management with SCCM, opening https and necessary RPC/SMB/SQL ports. Register the management point in DNS so clients resolve its public IP.
Learn how to use Azure cloud services to deploy a cloud distribution point and cloud management gateway, enabling cloud-based client management with reduced on-premise dmz complexity.
Explore how Microsoft Exchange enables mobile email and policy synchronization, and compare Configuration Manager’s Exchange Connector and Intune for managing mobile devices and Windows 10 systems.
Group users, assign built-in security roles, and copy a role to create custom permissions in configuration manager. Limit remote control to Denver clients for the Helpdesk group.
Learn how to create security groups, assign roles and collections, and use security scopes in SCCM to restrict desktop admins to specific apps, updates, and computers.
Explore site maintenance tasks to delete aged data, set schedules and thresholds, and perform SQL maintenance like rebuilding indexes and monitoring keys, supporting backup and updating the application catalog.
Configure and schedule backups in Configuration Manager to protect the site server and MySQL database, including management points, state migration points, and fallback status points, via the backup control file.
Use the recover option in the setup wizard to restore a lost site server from backups, returning it to its exact prior state with Configuration Manager and the SQL database.
Build a complete configuration manager environment—from installing the product and creating a primary site to configuring distribution points, bandwidth controls, site hierarchies, internet-based clients, backup and maintenance, and permissions.
With nearly 10,000 training videos available for desktop applications, technical concepts, and business skills that comprise hundreds of courses, Intellezy has many of the videos and courses you and your workforce needs to stay relevant and take your skills to the next level. Our video content is engaging and offers assessments that can be used to test knowledge levels pre and/or post course. Our training content is also frequently refreshed to keep current with changes in the software. This ensures you and your employees get the most up-to-date information and techniques for success. And, because our video development is in-house, we can adapt quickly and create custom content for a more exclusive approach to software and computer system roll-outs.
In this course you will learn how to build an Endpoint Configuration Manager environment from scratch. Provide role servers that meet your performance-based design goals. Meet the needs of an enterprise by building sites. Extend the power of Endpoint Configuration Manager by supporting external internet-based clients.
Like most of our courses, closed caption subtitles are available for this course in: Arabic, English, Simplified Chinese, German, Russian, Portuguese (Brazil), Japanese, Spanish (Latin America), Hindi, and French.
This IAAP-certified counts for ## recertification points for the CAP certification under the Technology and Information Distribution content area.
Email info@intellezy.com with proof of completion of the course to obtain your certificate.”