SCCM 2012 Basics
SCCM 2012 Basics
SCCM 2012 Basics
About SCCM
1. Scan and inventories all managed devices.
2. Client software deployed to supported devices
- Tracks software and hardware components
- Streamlines software deployment.
- Manages patches
3. Bare metal OS Deployments
4. Endpoint protection
- Provides an antimalware and security solution for the Microsoft platform.
5. Settings Management
- Desired configuration management
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
Primary Site
Primary site can support up to 100,000 clients
Manages clients in well-connected networks.
Primary sites in System Center 2012 Configuration Manager have the following differences from primary sites in
Configuration Manager 2007:
Secondary Site
Controls content distribution for clients in remote locations across links that have limited network bandwidth.
Secondary sites in System Center 2012 Configuration Manager have the following differences from secondary sites in
Configuration Manager 2007:
SQL Server is required and SQL Server Express will be installed during site installation if required.
A management point and distribution point are automatically deployed during the site installation.
Secondary sites can send content distribution to other secondary sites.
Participates in database replication.
You can define primary devices. These are typically the devices that users use on a daily basis to perform their work.
When you create an affinity between a user and a device, you gain more software deployment options. For example, if
a user requires Microsoft Office Visio, you can install it on the users primary device by using a Windows Installer
deployment. However, on a device that is not a primary device, you might deploy Microsoft Office Visio as a virtual
application. You can also use user device affinity to predeploy software on a users device when the user is not logged
in. Then, when the user logs on, the application is already installed and ready to run.
Application Supersedence
Application Retire
Per documentation, When you retire an application, it is no longer available for deployment but the application and
any deployments of the application are not deleted. Existing copies of this application that were installed on client
computers will not be removed. If an application that has no deployments is retired, it will be deleted from the
Configuration Manager console after 60 days. However, any installed copies of the application are not removed.
Wellthis is really interesting, it is more interesting that you can reinstate the application if needed, but be aware,
only retiring the application will not block people from installing. if have an active deployment, people can still use it.
Windows Management Instrumentation (WMI), registry, script, and all mobile device settings in Configuration
Manager let you automatically remediate noncompliant settings when they are found.
SCCM Roles
Site Server:
A computer on which you run the Configuration Manager setup program and which provides the core
functionality for the site.
Site Database Server:
A site system role that runs Microsoft SQL server and hosts the configuration Manager Site Database
Component Server:
Any server running SMS Executive and Configuration Manager services. This role is automatically installed
when you install all the site system roles except for the Distribution Point role.
Management Point:
A site system role that replies to configuration Manager Clients requests and accepts management data from
configuration manager clients
Distribution Point:
A site system role that contains source files for clients to download, such as application content, software
packages, software updates, operating system images, and boot images.
Reporting services Point:
A site system role that provides integration with SQL server reporting services to create and manager reports
for configuration manager
State migration point:
A site system role that stores user state data when a computer is migrated to a new operating system.
Software update point:
A site system role that integrates with windows server update services (WSUS) to provide software updates to
configuration manager clients.
System Health Validator Point:
This role must be installed on a Network Policy Server, to validate if Configuration Manager clients are
compatible or not with software updates you select and passes the health state of the computers to the
Windows Network Policy Server.
Endpoint Protection Point:
This role allows you to manage Window Firewall and antimalware security policies for client computers in
your hierarchy.
Fallback Status Point:
This site system role gathers state messages from clients for monitoring client installation and identifies
clients that are not able to communicate with their Management Point.
Out of band service point:
It allows administrators to connect to the computers that have the Intel vPro chip set and a version of Intel
Active Management Technology (Intel AMT), when the computer is turned off, in hibernation, or not
responding.
Asset Intelligence Synchronization Point:
A site system role that connects to System Center Online to download and manage Asset Intelligence catalog
information and upload uncategorized titles to consider them for future inclusion in the catalog.
5
Full Administrator
Endpoint Administrator
Security scope
Collection
Scope
Management Point
1. A site system role that provides policy and service location information to clients and receives configuration
data from clients.
2. Facilitates communication between clients and the SCCM server
3. An initial management point was installed during SCCM installation
4. No longer need to use load balancers for High availability. Clients use AD to find the right MP
5. Services previously offered by the server locator point role have been merged into the MP
Every primary and secondary site requires that a MP be specified.
- CAS cannot host MP
- Secondary sites can use proxy MP
MP requirements
-
IIS
6
Distribution Point
A site system role that contains source files for clients to download, such as application content, software packages,
software updates, operating system images, and boot images.
A DP was installed during SCCM installation