Microsoft SCCM Post Installation and Configuration (Boundaries, Client Settings, and more)

Поділитися
Вставка
  • Опубліковано 16 вер 2024

КОМЕНТАРІ • 125

  • @ThePandaFather
    @ThePandaFather 4 роки тому +8

    Justin, these videos are of excellent quality and I appreciate you explaining what some items do rather than just the cursory glance over.

    • @PatchMyPC
      @PatchMyPC  4 роки тому +2

      Thanks for the feedback!

  • @markherrera3593
    @markherrera3593 4 роки тому +3

    Just installed it in August 2020. Slight differences. I want to thank you so much for this step by step guide. One tip for anyone doing it "pay attention to the inbound windows firewall GPO rules, the schema admin rights for the push account, and the SQL admin account needs to be a service account" I had a setback with these for not paying attention.

  • @dosto-evsky
    @dosto-evsky 5 років тому +4

    Thanks Justin, simple presentation, high level quality. Much appreciated you sharing this content.

  • @kristian4805
    @kristian4805 3 роки тому +2

    Thank you very much, I was ready to give up on finding a good guide for all of this, and here it is!. Love the pace, and how much is actually explained.

  • @robinsondurai
    @robinsondurai 3 роки тому +2

    Dear Justin, Thanks for the best tutorial on the SCCM installation & prerequisites, I just simply followed your videos in new deployment. its working with no issues. Great thanks for your knowledge sharing . God bless your work

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      Thanks for watching.

    • @robinsondurai
      @robinsondurai 3 роки тому

      @@PatchMyPC Dear Justin, On my scenario we have existing the WSUS Server running, kindly share the link or blog how can we configured the SCCM SUP with existing WSUS, do we need to follow the same above steps mentioned in the video. appreciate your support

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      @@robinsondurai Generally it's not a good idea to re-use a WSUS that used to be standalone WSUS

    • @robinsondurai
      @robinsondurai 3 роки тому

      @@PatchMyPC Thanks for information I have two question
      1- as you informed to have Standalone WSUS role in the Same SCCM server ? , it that correct ?
      2- we would like to install the SCCM Console package for some Helpdesk computer , I have followed the Microsoft blog with silent installation but in the Helpdesk computer on software center (it showing) but when we try to install giving the error 0x80070002(-2147024894) ? what could be issue do i need to do as package or applications. kindly suggest some blog or your videos

  • @m8radojevic
    @m8radojevic 5 років тому +3

    As someone from *nix part of the system, just finished full sccm install and conf. based just on these two first videos(not the exact layout, since sql is on separate server)... Really great stuff. Tnx

  • @stephenweeks
    @stephenweeks 4 роки тому +3

    I really appreciate the time you took to make this video. It's very informative

  • @kearneyIT
    @kearneyIT 2 роки тому +1

    I love your content. helps me soooooo much in work

  • @stokni
    @stokni 5 років тому +3

    Really Really awesome videos, saved me hours and hours of googling!

  • @eng.mohmmedmerajuddin6064
    @eng.mohmmedmerajuddin6064 2 роки тому

    Excellent video with good pace and lot of features coverage

  • @Hollywood-xb7xm
    @Hollywood-xb7xm 5 років тому +2

    Really great videos, thank you. You have thought me a ton.

    • @PatchMyPC
      @PatchMyPC  5 років тому

      Thanks for watching!

  • @Jump_Ace
    @Jump_Ace 5 років тому +1

    Great stuff guys! Please keep up the good work!

  • @tendyfish
    @tendyfish 5 років тому +1

    great informative video, thank you very much

  • @klausvaldek
    @klausvaldek 2 роки тому

    Thanks !
    Great Job.
    Helped me a lot.

  • @conradlapointe3029
    @conradlapointe3029 5 років тому +1

    Great videos, thank you!

  • @WillianBuddySantos
    @WillianBuddySantos Рік тому

    Look me again doing another SCCM lab using video from Justin for the [a lot of times] hahaha...

  • @Theguficek
    @Theguficek 5 років тому +2

    If I may ask... WSUS server role can be unconfigured? its enough to configure a SUP role in SCCM and Win Updates are downloaded through WSUS?
    Second question, why do you set up in 'Report Server Configuration Manager' database 'ReportServer' and in 'SCCM Report Services role' you let the default SCCM database... If you could explain, I would be grateful.
    Nice video btw, keep going ^^

    • @PatchMyPC
      @PatchMyPC  5 років тому

      Because I need to pull the latest Microsoft updates from Microsoft to my WSUS server.

    • @Theguficek
      @Theguficek 5 років тому

      @@PatchMyPC I edit my comment, if you can recheck xD

  • @huseeinalsayed8238
    @huseeinalsayed8238 7 місяців тому

    Thanks

  • @jamesdeano8093
    @jamesdeano8093 5 років тому +1

    thank you

    • @PatchMyPC
      @PatchMyPC  5 років тому

      Thanks for watching!

  • @AdiMahluf
    @AdiMahluf 5 років тому +1

    That's a bunch of great videos, thank you Justin!
    just one question, which software you are using to open the log files? its looks much better and dynamic then just a notepad or notepad++ one.
    thank you!

    • @PatchMyPC
      @PatchMyPC  5 років тому +2

      CMTrace.exe from the SCCM install

  • @jerrinkarippai
    @jerrinkarippai 4 роки тому +2

    Great Video, clearly and specifically explained everything. Thank you very much.
    I have one issue, may by you can help a bit
    I would like to Install SCCM just to manage Windows Defender. My idea was to keep the existing WSUS servers separate to provide updates also Defender updates to the clients.
    1. Is it possible ?
    2. In this case will SCCM Client Installation in Client machines work?
    3. I did everything except WSUS installation in SCCM Server (WSUS Administration Console I have installed though). Now I am getting mainly two errors while installing SCCM Client (in ccmsetup Log file in Client machine). and SCCM Client is not getting installed. I am wondering it has to do with not installing WSUS.
    1. Failed to get DP locations as the expected version from MP 'SMDSCCM.xxx.yy.zzz'. Error 0x87d00215
    2. Failed to connect to machine policy namespace. 0x8004100e ccmsetup 07.08.2020 14:37:30 3808 (0x0EE0)
    At moment I have not added extra DP, I am using Site server as DP.
    Thanks & Regards
    Jerrin

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      Thanks for the feedback

  • @sergeolenek7414
    @sergeolenek7414 Рік тому

    Merci😊

  • @HeyRadu
    @HeyRadu 6 років тому +1

    Hello Justin, a BIG thank you for the top notch video tutorial ! One question please: at one point you are mentioning the second service account "SCCM_NAA", isn't suppose to be added to the same Administrators (built-in) local group as the other one "SCCM_PUSH" using the same GPO "SCCM Settings, or is there another way, for example Restricted Groups ?

    • @PatchMyPC
      @PatchMyPC  6 років тому +1

      The network access account shouldn't be part of the local admin group on the client devices. The NAA is only intended to be used for authentication to the site when the device isn't domain joined (Think OSD / Untrusted Domain). You wouldn't want it added to any groups with elevated access.

    • @HeyRadu
      @HeyRadu 6 років тому

      Agreed and also if you want to avoid any security risks in the case the account is somehow compromised, a good practice would be to add NAA into "Deny to log on locally".

    • @PatchMyPC
      @PatchMyPC  6 років тому

      Hey Pete ah got it, I misread your first comment, great point! No need for the NAA to have login rights.

  • @Cookiedata
    @Cookiedata Рік тому

    Hey Justin, after i ran Active Directory System Discovery, i still cant see my windows 10 on devices. What am i doing wrong here?

  • @ahmedsaad-lk2og
    @ahmedsaad-lk2og 2 роки тому

    Thank

  • @thomaswalsh476
    @thomaswalsh476 4 роки тому +1

    Hi Justin thank you for your content.
    I am working through setting up a test environment to learn more about sccm. I have been with you up to adding the group policy (~16:00). When I open Group Policy Management I do not have the managed and unmanaged folders. I am wondering if they are manually added OUs or it is a sign something went wrong.

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      There are just custom OU's I had created in my environment.

    • @thomaswalsh476
      @thomaswalsh476 4 роки тому

      @@PatchMyPC Thanks!

  • @Atreus21
    @Atreus21 5 років тому +1

    Had a question sir. In an environment spanning multiple trusted domains, do you think it's necessary to give the site server's computer account Read permissions to ADS&S for the various domains to facilitate Forest Discovery? Have an issue discovering subnets from two domains and was thinking about that.

    • @PatchMyPC
      @PatchMyPC  5 років тому +1

      I think those permissions may replicate, but i'm not that deep in knowledge on the AD side of things. I would make sure there's a security group of all site server computer accounts that has permissions to the container. - Justin

    • @Atreus21
      @Atreus21 5 років тому +1

      @@PatchMyPC Thank you very much sir. If you're interested I found the solution, or rather the peculiar way SCCM behaves when discovering multiple forests It had nothing to do with ADS&S permissions.
      For some reason, after you add your forests and turn on discovery for all of them, SCCM discovers one at a time in reverse alphabetical order. If any discovery errors occur during that process, all of discovery stops. For that reason, the lowest alphabetical forest we had, starting with T, discovered fine. The next one, starting with M, threw an error and everything stopped, leaving the remaining domains, starting with I and A respectively, stuck with discovery status Unknown. Once we turned off discovery for all, then enabled and discovered one at time, everything worked fine.
      We'll just have to keep that in mind whenever it's necessary to do forest discovery from now on. Thanks very much for your help sir.

  • @alekseibird
    @alekseibird 3 роки тому +1

    Justin, in what video you are considering the installation of the client via GPO? For some reason, it does not work (((

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      I don't have one for client deployment on GPO. I think Jason Sandy's has a blog on it though.

    • @alekseibird
      @alekseibird 3 роки тому

      @@PatchMyPC give a link. Thanks!

  • @bdzbdz
    @bdzbdz Рік тому

    Hi Justin, I have 2 questions regarding Reporting Services.
    So I have 3 servers 2019 in my lab environment:
    1. DC/DHCP/DNS/ADDC
    2. SCCM
    3. SQL
    On all 3 servers Firewall is disabled and they all see each other and everything works fine
    My questions are:
    1. where should I install SQLServerReportingServices, On SCCM server or SQL server?
    2. On my SCCM server, when I go to Administration>Site Configuration>Servers and Site System Roles I see two sites - \\SCCM.lab.local and SQL.lab.local. On which one should I check the Reporting services point box?
    p.s. I Realized that I can install SQLServerReportingServices on Both servers, but when I open Reports on SCCM in Monitoring, and try to create report I get the error:
    Could not find and installed Reporting services point. I guess that is regarding my second question :)

    • @PatchMyPC
      @PatchMyPC  Рік тому +1

      It could be any site system for where you install SSRS.

  • @Cannon5000
    @Cannon5000 6 років тому +1

    Hello Justin, so right off the bat I'm running into problems. I've watched your 1st video. Followed all the steps to the T. And then when I open up Reporting Services and try to connect to the server it says it can't find the server. What happened? Nothing has changed.

    • @PatchMyPC
      @PatchMyPC  6 років тому

      Hmm, is this in the SSRS Configuration wizard? Can you post a screenshot?

    • @theduke8767
      @theduke8767 5 років тому

      I don't know if you resolved this already but just to put in my 2 cents, go to services and verify that the SQL Server Reporting Services is running and install (or re-install) the Microsoft SQL Server Report builder. That solved it for me. Good luck

  • @timemediaonline3658
    @timemediaonline3658 5 років тому +1

    Hello Justin,
    Thank you for making these educational videos. I am following your steps and did couple changes in process. I have a SCCM Server and SQL Server separate. I installed the Reporting Services Role installed on SQL Server from SCCM. I see following in red in SiteComp.log and don't see SRSRP.log.
    ============================================================
    Cannot getcopy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS\SRSRP registry key on server SQLOP1V.MYTESTLAB.LOCAL. The operating system reported error 5: The system cannot find the file specified.
    ============================================================
    If you can please assist me in correcting this for my learning test lab. I would greatly appreciate.
    Sincerely,
    Ash

    • @PatchMyPC
      @PatchMyPC  5 років тому +1

      That can be ignored unless you are having issues. I recall seeing this logged out a lot.

    • @timemediaonline3658
      @timemediaonline3658 5 років тому

      @@PatchMyPC Thank you Justin for your prompt response! I rebooted both server and everything else is working. I still don't have SRSRP.log file under Logs for me to view and troubleshoot. Please guide me in right direction.

  • @tarikibouzidene6399
    @tarikibouzidene6399 2 роки тому

    Dear, Another Question please.
    With SCCM 2203, ADK 2004. can support the OS W7 ent. or I need to install also the AIK for W7...?
    Please if another solution...

    • @PatchMyPC
      @PatchMyPC  Рік тому

      Would recommend checking MS docs on this.

  • @christiancastro1618
    @christiancastro1618 2 роки тому

    Great videos! I have a question.
    If I'm building my infrastructure in VMWare, should my DC, SCCM server, and my client VM be in NAT or bridged or is there a specific network they should be assigned? Thank you.

    • @PatchMyPC
      @PatchMyPC  2 роки тому +1

      It shouldn't really matter as long as there is communication and DNS is working.

    • @christiancastro1618
      @christiancastro1618 2 роки тому

      @@PatchMyPC thank you!

  • @somvirsharma5951
    @somvirsharma5951 4 роки тому

    Hello Justin, while creating a service account do they need to be part of any specific group like you created for client push?

    • @PatchMyPC
      @PatchMyPC  4 роки тому +1

      It depends on the account. It's not a requirement, but may be helpful for some operations and delegation.

  • @tomaskulikauskas1333
    @tomaskulikauskas1333 5 років тому

    Hello Justin,
    I get a lot errors with event ID 12:
    Process C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\ReportServer\bin\ReportingServicesService.exe (PID 2228, TID 8108) called the CollectSMSPerformanceData() function in SMSPERF.DLL and the function detected that the virtual memory block containing the SMS performance data was not properly initialized. No performance data will be returned to the caller. If process C:\Program Files\Microsoft SQL Server Reporting Services\SSRS\ReportServer\bin\ReportingServicesService.exe is a performance monitoring application, it may display incorrect data for the SMS performance counters or no data at all.
    Do you know what it could be and how to fix it?
    Thanks,
    Tomas

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      Did you get this figured out?

  • @theduke8767
    @theduke8767 5 років тому +1

    Justin, great videos. I have learn little tricks and shortcuts I have not seen before and I've been using SCCM for quite a while and have had my own lab for training for some time as well. I have an issue that I have seen in the past in my labs and wonder if you know the answer. I have noticed that if I reboot my server, certain services turn off. CONFIGURATION_MANAGER_UPDATE, SQLSERVERAGENT, MSSQLSERVER, SQLServerReportingServices, SMS_EXECUTIVE and WsusService. they are all set to automatic and will start (and stay that way until reboot) if I click on them and select start. I just noticed that several NET.xxx services are stopped as well. If I log off then back on, they stay on. Any suggestions?

    • @PatchMyPC
      @PatchMyPC  5 років тому

      Hmm that's odd, I haven't done across this issue before.

    • @theduke8767
      @theduke8767 5 років тому

      yes, very odd. The previous SCCM I built (SCCM 1610), did not do this at all. The only real differences were SCCM version and I used SQL 2016 instead of SQL 2017. Thanks for the quick response. I'll keep investigating.

    • @theduke8767
      @theduke8767 5 років тому +1

      Justin, I think I found a solution. I changed the SQLSERVERAGENT service from Automatic startup to Automatic (Delayed Start). I rebooted several times and after about a minute, the service starts up ok. I did the same with CONFIGURATION_MANAGER_UPDATE and WSUS services and they started up about a minute after logging in.

  • @chaosmassive8627
    @chaosmassive8627 3 роки тому

    Hi, thank you for your concise and detailed guide, when I try to generate the report, I get an error saying "An error has occurred during report processing. (rsProcessingAborted)", when checking the details there are bunch of error and one of them says
    Microsoft.Reporting.WinForms.ReportServerException
    Log on failed. Ensure the user name and password are correct. (rsLogonFailed)
    can you please help to give me some pointer? thanks again

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      Looks like a password or username issue.

  • @Atreus21
    @Atreus21 3 роки тому

    Had another question sir: Is there any good reason NOT to enabled LEDBAT on onprem Distribution Points?

    • @PatchMyPC
      @PatchMyPC  3 роки тому +1

      I can't think of any

    • @Atreus21
      @Atreus21 3 роки тому

      @@PatchMyPC Great. Thanks sir.

  • @bardfox9878
    @bardfox9878 5 років тому

    Hello Justin fantastic video I am getting this message in the event logs on the server i have installed SCCM The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description. can you please advise where i am going wrong ?

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      Did you get this figured out?

  • @miketripodo2879
    @miketripodo2879 4 роки тому

    I just completed a fresh install, thank you for this very helpful video! At the end of the video when you look at the reports section (Client Push report), are there supposed to be pre-existing reports there, or do all of the reports and categories have to be created? I have nothing there, Reporting > Reports has 0 items. If they need to be created, do you have another video to do that?
    Also, what are the certificate and CA requirements/GPO/settings? Thanks again.

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      You would need to install the reporting point.

    • @miketripodo2879
      @miketripodo2879 4 роки тому

      @@PatchMyPC .. Thank you. Can you expand on that a little? Where in the instructions does it say to do that? Did I miss it?

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      @@miketripodo2879 I believe I may cover it in guide 1 installing sccm

  • @235koolcat
    @235koolcat Рік тому

    Hi Sir.
    We have one primary site and one remote location DP. Both have VLan wise boundaries.
    On the primary site having 25 VLan boundaries and remote DP having 20 VLan wise boundaries.
    I have made 3 boundaries groups.
    1. One for site assignment and added all the boundaries, like primary and remote DP, total: 20+25= 45 boundaries and on the reference tab I checked the box site assignment.
    2. Created 2nd boundary group for primary server and added only 25 boundaries and on reference tab, just added primary server.
    3. Created 3rd boundary group for remote DP and added 20 boundaries and on the reference tab just added remote DP server.
    Is it ok or need some changes?
    Please suggest.
    Thanks!

    • @PatchMyPC
      @PatchMyPC  Рік тому

      Hope you figured this one out. Sorry for the delay this is a little but to complex to try to resolve on comments. The Microsoft docs for ConfigMgr can often be a great resource.

  • @smcfall14
    @smcfall14 3 роки тому

    followed but Client Installation Settings are greyed out for me..

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      Can you post a screenshot.

  • @ErraticSpeculations
    @ErraticSpeculations 4 роки тому +1

    Hey there Justin, firstly if like to say fantastic guides you have here! I recently inherited an SCCM site that wasn't working properly and had to reinstall it from scratch using configmgr 2002. These guides have helped A LOT!
    However I'm having some issues with policy being pushed out to my devices.. On some machines the client gets installed and no issues, on other machines it gets stuck trying to use BITS to transfer a client.msi and firewall.msi (I don't remember the full name at the moment). I get the BG context error 4 and 0x80200024 error.
    I don't know if you'd be available to assist me. Any help would be greatly appreciated! :)

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      Are you still having issues?

    • @ErraticSpeculations
      @ErraticSpeculations 3 роки тому +2

      @@PatchMyPC I am not anymore. Firewall was blocking us. I inherited the environment and the IP addresses changed still strange for some it worked and other did not.
      HTTPS OSD deployment issues now haha

  • @ZayScott
    @ZayScott 3 роки тому

    I know this is an old tutorial, however, I installed V2017 (1702), and Software center is not listed when I try to configure policies

    • @joextreme
      @joextreme 3 роки тому

      It show up in the default client settings? Probably upgrade to a different branch. I just got done installing 2103

    • @ZayScott
      @ZayScott 3 роки тому

      @@joextreme thanks yeah once I upgraded, all is fine

    • @joextreme
      @joextreme 3 роки тому +1

      @@ZayScott awesome

    • @PatchMyPC
      @PatchMyPC  3 роки тому

      Thanks for helping out!

  • @tarikibouzidene6399
    @tarikibouzidene6399 2 роки тому

    Dear, can we install & configure sccm without wsus role ?

  • @jamesdeano8093
    @jamesdeano8093 5 років тому

    What is the right you gave to your account sccm_push ? Is he a standard domain user

    • @PatchMyPC
      @PatchMyPC  5 років тому

      Local administrator of devices you want to push the agent out to using client push.

    • @energyiilove
      @energyiilove 4 роки тому

      @@PatchMyPC Isn't there an inherent security risk in making SCCM_Push a local admin??

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      @@energyiilovedocs.microsoft.com/en-us/configmgr/core/clients/deploy/plan/security-and-privacy-for-clients#use-the-most-secure-client-installation-methods-that-are-practical-for-your-environment

  • @mikerosco4267
    @mikerosco4267 5 років тому

    Do you have a Udemy course by any chance?

    • @binaryblog
      @binaryblog 5 років тому +1

      Why use Udemy when it's already for free here?

    • @PatchMyPC
      @PatchMyPC  4 роки тому

      No, everything on UA-cam

  • @klalakomacoi
    @klalakomacoi 5 років тому

    Can you stop swallowing into the mic please.

    • @PatchMyPC
      @PatchMyPC  5 років тому +1

      Not for this video :), I am using some tools now to filter out background noise for future videos.

  • @madhusunke1102
    @madhusunke1102 6 років тому +1

    Thank you

    • @PatchMyPC
      @PatchMyPC  6 років тому

      Thanks for watching!