Saturday, January 22, 2011

Confimgr / SCCM Pro / Cons

ConfigMgr 2007 Limitations

image 

 

What is DISTRIBUTION POINT (DP): A site system that has the role of storing package source files. Clients contact distribution points to obtain source files when they run advertised programs, advertised task sequences, or deployed software updates.
Types of Distribution Points:

clip_image002

Some distribution point types are not compatible with other distribution point types. For example, a branch distribution point cannot support Internet-based clients. The following table shows which types of distribution points can be combined and which are mutually exclusive.

clip_image004

1 Configuring a server share on a site system already configured to support Internet-based clients will cause content location requests to fail.

2 On branch distribution points, enable File Streaming to support streaming using server message blocks (SMB).

Bandwidth Control:
The following table summarizes the bandwidth controls as packages move through the Configuration Manager 2007 system.

clip_image006

Grouping Distribution Points : You can create groups of distribution points to facilitate the processes of copying packages to distribution points. Packages can then be targeted to a distribution point group rather than to individual distribution points. For example, you might create a group of distribution points as Region 1 DP’s and copy packages for only region1 Locations only to that distribution points.

Why to depend on Branch Distribution Point:

clip_image008

 

 

 

Internet based Clients Limitations

In native mode, clients communicate over HTTPS to the following site systems:

ü Management points

ü Default management point

ü Network load balanced management points

ü Proxy management point

ü Internet-based management point

ü Standard distribution points (not branch distribution points)

ü Software update points

ü State migration point


Features that Are Not Supported on the Internet

ü Branch distribution points (a branch distribution point cannot support Internet clients, and clients on the Internet cannot be configured as a branch distribution point)

ü Software distribution that is targeted to users (either directly or through Microsoft Windows security groups)

ü Client deployment over the Internet

ü Auto-site assignment

ü Network Access Protection (NAP)

ü Wake On LAN

ü Operating system deployment

ü Task sequences

ü Remote control

ü Out of band management in Configuration Manager 2007 SP1 and later

ü The client ping functionality used with the client status reporting feature in Configuration Manager 2007 R2

 

 

 

 

Asset Intelligence Reporting Limitations

Example Dependencies:

The accuracy of installed software title quantities and license information displayed in Asset Intelligence reports can vary from the actual amounts currently in use because of the complex dependencies involved in inventorying software license information for software titles in use in enterprise environments.

The following are example dependencies involved in inventorying installed software and license usage in the enterprise using Asset Intelligence that might affect the accuracy of Asset Intelligence reports:

Client hardware inventory dependencies:

Asset Intelligence installed software reports are based on data collected from SMS or Configuration Manager clients by extending hardware inventory to enable Asset Intelligence reporting. Because of this dependency on hardware inventory reporting, Asset Intelligence reports will reflect data only from SMS or Configuration Manager clients that successfully complete hardware inventory processes with the required Asset Intelligence WMI reporting classes enabled. In addition, because SMS or Configuration Manager clients perform hardware inventory processes on a schedule defined by the administrator, there might be a delay in data reporting that affects the accuracy of Asset Intelligence reports. For example, an inventoried, licensed software title might be uninstalled after the client completes a successful hardware inventory cycle, but the software title will still appear as installed in Asset Intelligence reports until the client’s next scheduled hardware inventory reporting cycle.

Software packaging dependencies

Because Asset Intelligence reports are based on installed software title data collected using standard SMS or Configuration Manager client hardware inventory processes, some software title data might not be properly collected. For example, software installations that do not conform to standard installation processes or software installations that have been modified prior to installation might result in inaccurate Asset Intelligence reporting results.

Server role dependencies

When utilizing CAL reporting, it is important to remember that these reports were designed to provide visibility into the usage of specific products in specific scenarios—for example, a server running a Windows Server operating system supporting a single server role. Licensed software title usage in different scenarios might produce inaccurate results—for example, the case of a server running a Windows Server operating system supporting multiple roles, such as Exchange mail server or SQL Server database server. When deciding to use Asset Intelligence to report license usage and information, keep in mind that it was designed only to provide visibility into license usage. For example, even if your license agreement allows you to use certain software in a lab or classroom environment without charge, Asset Intelligence will be able to detect only installed software in use and report it as such. In such a case, relying solely on Asset Intelligence might result in overpayment.

Location and usage

When deciding to use Asset Intelligence to report license usage and information, keep in mind that it was designed only to provide visibility into license usage. For example, even if your license agreement allows you to use certain software in a lab or classroom environment without charge, Asset Intelligence will be able to detect only installed software in use and report it as such. In such a case, relying solely on Asset Intelligence might result in overpayment.

Legal Limitations

The information displayed in Asset Intelligence reports are subject to many limitations and the information displayed in them does not constitute legal, accounting, or other professional advice. The information provided by Asset Intelligence reports is for informational purposes only and should not be used as the sole source of information for determining software license usage compliance.

The following are example limitations involved in inventorying installed software and license usage in the enterprise using Asset Intelligence that might affect the accuracy of

Asset Intelligence reports:

Microsoft license usage quantity limitations

The quantity of purchased Microsoft software licenses is based on information supplied by administrators and should be closely reviewed to ensure that the correct number of software licenses is provided.

The Microsoft software license quantity reported contains information only for Microsoft software licenses acquired through volume licensing programs and does not reflect information for software licenses acquired through retail, Original Equipment Manufacturer (OEM), or other software license sales channels.

Software licenses acquired in the last 45 days might not be included in the Microsoft software license quantities reported because of software reseller reporting requirements and schedules.

Software license transfers as a result of company mergers or acquisitions might not be reflected in Microsoft software license quantities.

Nonstandard terms and conditions in a Microsoft Volume Licensing (MVLS) agreement might affect the number of software licenses reported and, consequently, might require additional review by a Microsoft representative.


Installed software title quantity limitations

The accuracy of installed software title quantities in Asset Intelligence reports relies on fully functioning SMS or Configuration Manager clients successfully completing hardware inventory reporting cycles and installation on appropriate computers. Additionally, there might be a delay between installation or uninstallation of a licensed software title after a successful hardware inventory reporting cycle that will not be reflected in Asset Intelligence reports run before the client reports its next scheduled hardware inventory.

License reconciliation limitations

The reconciliation of installed software title quantities to the quantity of purchased software licenses is calculated by using a comparison of the license quantity specified by the administrator and the installed software title quantities collected from SMS or Configuration Manager client hardware inventories based on the schedule set by the administrator. This comparison does not represent a final license position conclusion by Microsoft. The actual license position depends on the specific software title license and usage rights granted by the license terms


 

 

 

Single Site Design can offer below:
MS Limitations: One DP can be supported maximum of 4000 clients

Pro:

ü Need only One standard DP

ü Need to Use Nomad

ü Package flow over the wan can be well controlled with Nomad

ü This was success in the current SMS hierarchy

ü No BDP’s Required

ü No PDP’s required

ü NO DP Groups Required as only one DP

Con:

ü Nomad is third party Software and need to pay extra cost to the licensing

ü Over administration need to done for every time when you create a package & advertise

ü We can use BDP’s, PDPs and DP Groups to specifically can target

ü You can’t push more than one Package at a time in a bandwidth control manner as nomad will treat this as separate package

ü Not tested for PXE request handling over the WAN with this model

ü You may not required Multicasting with this model for OSD

ü If we want to place DP in Leatherhead then you can’t control the Bandwidth on this DP until you have a Site (Primary / Secondary site) – However this is not in the immediate scope

ü You can’t use Streaming DP’S for APP-V in this model for enterprise level

 

 

 

Software Updates in Configuration Manager:

MS Limitations: One WSUS / SUP server can be supported about 25,000 clients

Pro:

ü All clients will gets scanned from One Active SUP server

Con:

ü Managing all 7000+ systems scanning from one system over the WAN need to take consideration

ü In slow WAN we may expect WUA scanning errors because of Network connectivity issues

ü Nomad Packages not tested for OSD

ü

 

 

 

Operating System Deployment in Configuration Manager:

 

MS Limitations: Up to 10 PXE service points per site, with a maximum of 75 PXE service points per primary site database

 

Pro:

ü We can successfully build OS in Camphill

ü Scope for only Camphill datacenter and well connected networks

ü Need to depend on full Zero Touch and Burn in DVD / Flash Disk and send to the Slow links (rest of the world location except Camphill)

 

Con:

ü Boot Images Source (About 150 MB to 180 MB) will be stored in Camphill server

ü Every time you build your server need to transfer (150 MB to 180 MB) Boot Image data over the WAN

ü In slow WAN we may not build the OS

ü 90% to 95% locations need to build with DVD / USB Flash

ü State Migration Points can enabled in the well connected networks and can do the easy windows Desktop OS migration to other desktop OS or Clean Desktop OS


 

 

Reporting & SRS in Configuration Manager

MS Limitations:-
Report Viewer in Configuration Manager 2007 limits the result set returned by a report query to 10,000 rows. Report Viewer in Configuration Manager 2007 limits the number of rows returned to 1,000 rows when you click Values and the values list displays for a prompt.

Pro:

ü Enable on Central site can see enterprise level reports

Con:

ü Web Reports and SRS will exist on the same system or site


 

 

Remote Tools in Configuration Manager:


Pro:

ü Single SCCM Console

Con:

ü Multiple users can’t do a RDP

ü May need to allow then to install locally and use Remote Tools

ü May increase the Load on the WAN and user experience may decrease when use remote tools from WAN

ü This can remove Dame ware licensing cost

 

 

Wake On LAN in Configuration Manager:


Pro:

ü One WOL Server will be deployed entire the Network

ü All Magic Packets will be transmitted ( Unicast / subnet based broad cast)from Camphill to end computers

Con:

ü WAN Traffic may increase

 

Client & Server Communication:

Pro:

ü All configuration from one site one console

Con:

ü WAN Traffic may increase

ü Client Push or Client Deployment, Client Discovery information and all client communication will flow over the WAN regardless if clients are in slow Link

 

Internet based Clients:


MS Limitations:- see above

Pro:

ü SCCM Server need to configure as native mode and face external & internal clients

Con:

ü Not a good idea to expose the server without moving to DMZ

ü Below are the Scenarios that can be configure for SCCM in native mode to support Internet based clients as a best practice depend on the Scenario & requirement

· Scenario 1 with no SQL Server Replica

· Scenario 1 with SQL Server Replica

· Scenario 2 with Child Site

· Scenario 2 with Complete Hierarchy

· Scenario 3 with No SQL Server Replica

· Scenario 3 with SQL Server Replica

· Scenario 4 with Two Network Cards

· Scenario 4 with Internet Connections into the Intranet

· Scenario 4 with Intranet Connections into the Perimeter Network

ConfigMgr/ SCCM Pro / Cons

ConfigMgr 2007 Limitations

image 

 

What is DISTRIBUTION POINT (DP): A site system that has the role of storing package source files. Clients contact distribution points to obtain source files when they run advertised programs, advertised task sequences, or deployed software updates.
Types of Distribution Points:

clip_image002

Some distribution point types are not compatible with other distribution point types. For example, a branch distribution point cannot support Internet-based clients. The following table shows which types of distribution points can be combined and which are mutually exclusive.

clip_image004

1 Configuring a server share on a site system already configured to support Internet-based clients will cause content location requests to fail.

2 On branch distribution points, enable File Streaming to support streaming using server message blocks (SMB).

Bandwidth Control:
The following table summarizes the bandwidth controls as packages move through the Configuration Manager 2007 system.

clip_image006

Grouping Distribution Points : You can create groups of distribution points to facilitate the processes of copying packages to distribution points. Packages can then be targeted to a distribution point group rather than to individual distribution points. For example, you might create a group of distribution points as Region 1 DP’s and copy packages for only region1 Locations only to that distribution points.

Why to depend on Branch Distribution Point:

clip_image008

 

 

 

Internet based Clients Limitations

In native mode, clients communicate over HTTPS to the following site systems:

ü Management points

ü Default management point

ü Network load balanced management points

ü Proxy management point

ü Internet-based management point

ü Standard distribution points (not branch distribution points)

ü Software update points

ü State migration point


Features that Are Not Supported on the Internet

ü Branch distribution points (a branch distribution point cannot support Internet clients, and clients on the Internet cannot be configured as a branch distribution point)

ü Software distribution that is targeted to users (either directly or through Microsoft Windows security groups)

ü Client deployment over the Internet

ü Auto-site assignment

ü Network Access Protection (NAP)

ü Wake On LAN

ü Operating system deployment

ü Task sequences

ü Remote control

ü Out of band management in Configuration Manager 2007 SP1 and later

ü The client ping functionality used with the client status reporting feature in Configuration Manager 2007 R2

 

 

 

 

Asset Intelligence Reporting Limitations

Example Dependencies:

The accuracy of installed software title quantities and license information displayed in Asset Intelligence reports can vary from the actual amounts currently in use because of the complex dependencies involved in inventorying software license information for software titles in use in enterprise environments.

The following are example dependencies involved in inventorying installed software and license usage in the enterprise using Asset Intelligence that might affect the accuracy of Asset Intelligence reports:

Client hardware inventory dependencies:

Asset Intelligence installed software reports are based on data collected from SMS or Configuration Manager clients by extending hardware inventory to enable Asset Intelligence reporting. Because of this dependency on hardware inventory reporting, Asset Intelligence reports will reflect data only from SMS or Configuration Manager clients that successfully complete hardware inventory processes with the required Asset Intelligence WMI reporting classes enabled. In addition, because SMS or Configuration Manager clients perform hardware inventory processes on a schedule defined by the administrator, there might be a delay in data reporting that affects the accuracy of Asset Intelligence reports. For example, an inventoried, licensed software title might be uninstalled after the client completes a successful hardware inventory cycle, but the software title will still appear as installed in Asset Intelligence reports until the client’s next scheduled hardware inventory reporting cycle.

Software packaging dependencies

Because Asset Intelligence reports are based on installed software title data collected using standard SMS or Configuration Manager client hardware inventory processes, some software title data might not be properly collected. For example, software installations that do not conform to standard installation processes or software installations that have been modified prior to installation might result in inaccurate Asset Intelligence reporting results.

Server role dependencies

When utilizing CAL reporting, it is important to remember that these reports were designed to provide visibility into the usage of specific products in specific scenarios—for example, a server running a Windows Server operating system supporting a single server role. Licensed software title usage in different scenarios might produce inaccurate results—for example, the case of a server running a Windows Server operating system supporting multiple roles, such as Exchange mail server or SQL Server database server. When deciding to use Asset Intelligence to report license usage and information, keep in mind that it was designed only to provide visibility into license usage. For example, even if your license agreement allows you to use certain software in a lab or classroom environment without charge, Asset Intelligence will be able to detect only installed software in use and report it as such. In such a case, relying solely on Asset Intelligence might result in overpayment.

Location and usage

When deciding to use Asset Intelligence to report license usage and information, keep in mind that it was designed only to provide visibility into license usage. For example, even if your license agreement allows you to use certain software in a lab or classroom environment without charge, Asset Intelligence will be able to detect only installed software in use and report it as such. In such a case, relying solely on Asset Intelligence might result in overpayment.

Legal Limitations

The information displayed in Asset Intelligence reports are subject to many limitations and the information displayed in them does not constitute legal, accounting, or other professional advice. The information provided by Asset Intelligence reports is for informational purposes only and should not be used as the sole source of information for determining software license usage compliance.

The following are example limitations involved in inventorying installed software and license usage in the enterprise using Asset Intelligence that might affect the accuracy of

Asset Intelligence reports:

Microsoft license usage quantity limitations

The quantity of purchased Microsoft software licenses is based on information supplied by administrators and should be closely reviewed to ensure that the correct number of software licenses is provided.

The Microsoft software license quantity reported contains information only for Microsoft software licenses acquired through volume licensing programs and does not reflect information for software licenses acquired through retail, Original Equipment Manufacturer (OEM), or other software license sales channels.

Software licenses acquired in the last 45 days might not be included in the Microsoft software license quantities reported because of software reseller reporting requirements and schedules.

Software license transfers as a result of company mergers or acquisitions might not be reflected in Microsoft software license quantities.

Nonstandard terms and conditions in a Microsoft Volume Licensing (MVLS) agreement might affect the number of software licenses reported and, consequently, might require additional review by a Microsoft representative.


Installed software title quantity limitations

The accuracy of installed software title quantities in Asset Intelligence reports relies on fully functioning SMS or Configuration Manager clients successfully completing hardware inventory reporting cycles and installation on appropriate computers. Additionally, there might be a delay between installation or uninstallation of a licensed software title after a successful hardware inventory reporting cycle that will not be reflected in Asset Intelligence reports run before the client reports its next scheduled hardware inventory.

License reconciliation limitations

The reconciliation of installed software title quantities to the quantity of purchased software licenses is calculated by using a comparison of the license quantity specified by the administrator and the installed software title quantities collected from SMS or Configuration Manager client hardware inventories based on the schedule set by the administrator. This comparison does not represent a final license position conclusion by Microsoft. The actual license position depends on the specific software title license and usage rights granted by the license terms


 

 

 

Single Site Design can offer below:
MS Limitations: One DP can be supported maximum of 4000 clients

Pro:

ü Need only One standard DP

ü Need to Use Nomad

ü Package flow over the wan can be well controlled with Nomad

ü This was success in the current SMS hierarchy

ü No BDP’s Required

ü No PDP’s required

ü NO DP Groups Required as only one DP

Con:

ü Nomad is third party Software and need to pay extra cost to the licensing

ü Over administration need to done for every time when you create a package & advertise

ü We can use BDP’s, PDPs and DP Groups to specifically can target

ü You can’t push more than one Package at a time in a bandwidth control manner as nomad will treat this as separate package

ü Not tested for PXE request handling over the WAN with this model

ü You may not required Multicasting with this model for OSD

ü If we want to place DP in Leatherhead then you can’t control the Bandwidth on this DP until you have a Site (Primary / Secondary site) – However this is not in the immediate scope

ü You can’t use Streaming DP’S for APP-V in this model for enterprise level

 

 

 

Software Updates in Configuration Manager:

MS Limitations: One WSUS / SUP server can be supported about 25,000 clients

Pro:

ü All clients will gets scanned from One Active SUP server

Con:

ü Managing all 7000+ systems scanning from one system over the WAN need to take consideration

ü In slow WAN we may expect WUA scanning errors because of Network connectivity issues

ü Nomad Packages not tested for OSD

ü

 

 

 

Operating System Deployment in Configuration Manager:

 

MS Limitations: Up to 10 PXE service points per site, with a maximum of 75 PXE service points per primary site database

 

Pro:

ü We can successfully build OS in Camphill

ü Scope for only Camphill datacenter and well connected networks

ü Need to depend on full Zero Touch and Burn in DVD / Flash Disk and send to the Slow links (rest of the world location except Camphill)

 

Con:

ü Boot Images Source (About 150 MB to 180 MB) will be stored in Camphill server

ü Every time you build your server need to transfer (150 MB to 180 MB) Boot Image data over the WAN

ü In slow WAN we may not build the OS

ü 90% to 95% locations need to build with DVD / USB Flash

ü State Migration Points can enabled in the well connected networks and can do the easy windows Desktop OS migration to other desktop OS or Clean Desktop OS


 

 

Reporting & SRS in Configuration Manager

MS Limitations:-
Report Viewer in Configuration Manager 2007 limits the result set returned by a report query to 10,000 rows. Report Viewer in Configuration Manager 2007 limits the number of rows returned to 1,000 rows when you click Values and the values list displays for a prompt.

Pro:

ü Enable on Central site can see enterprise level reports

Con:

ü Web Reports and SRS will exist on the same system or site


 

 

Remote Tools in Configuration Manager:


Pro:

ü Single SCCM Console

Con:

ü Multiple users can’t do a RDP

ü May need to allow then to install locally and use Remote Tools

ü May increase the Load on the WAN and user experience may decrease when use remote tools from WAN

ü This can remove Dame ware licensing cost

 

 

Wake On LAN in Configuration Manager:


Pro:

ü One WOL Server will be deployed entire the Network

ü All Magic Packets will be transmitted ( Unicast / subnet based broad cast)from Camphill to end computers

Con:

ü WAN Traffic may increase

 

Client & Server Communication:

Pro:

ü All configuration from one site one console

Con:

ü WAN Traffic may increase

ü Client Push or Client Deployment, Client Discovery information and all client communication will flow over the WAN regardless if clients are in slow Link

 

Internet based Clients:


MS Limitations:- see above

Pro:

ü SCCM Server need to configure as native mode and face external & internal clients

Con:

ü Not a good idea to expose the server without moving to DMZ

ü Below are the Scenarios that can be configure for SCCM in native mode to support Internet based clients as a best practice depend on the Scenario & requirement

· Scenario 1 with no SQL Server Replica

· Scenario 1 with SQL Server Replica

· Scenario 2 with Child Site

· Scenario 2 with Complete Hierarchy

· Scenario 3 with No SQL Server Replica

· Scenario 3 with SQL Server Replica

· Scenario 4 with Two Network Cards

· Scenario 4 with Internet Connections into the Intranet

· Scenario 4 with Intranet Connections into the Perimeter Network

Asset Intelligence Tables and Properties

SAM Table Column 1 Column 2 Column 3 Column 4 Column 5 Column 6 Column 7 Column 8 Column 9 Column 10 Column 11 Column 12 Column 13 Column 14 Column 15 Column 16 Column 17 Column 18 Column 19 Column 20 Column 21 Column 22 Column 23 Column 24 Column 25 Column 26 Column 27 Column 28 Column 29 Column 30 Column 31 Column 32 Column 33 Column 34 Column 35 Column 36
v_LU_SoftwareList SoftwareID CommonName CommonVersion CommonPublisher CategoryID OfficialCategoryID FamilyID OfficialFamilyID Tag1ID Tag2ID Tag3ID ConflictStatus                                                
V_LU_Softwarehash SoftwarePropertiesHash Name Version Publisher SoftwareID LastUpdated                                                            
v_GS_INSTALLED_SOFTWARE_CATEGORIZED ResourceID TimeStamp RevisionID AgentID SoftwareCode0 ProductCode0 CM_DSLID0 ProductName0 ARPDisplayName0 ProductVersion0 Publisher0 VersionMajor0 VersionMinor0 ServicePack0 Language0 ProductID0 InstalledLocation0 InstallSource0 UninstallString0 LocalPackage0 UpgradeCode0 InstallDate0 RegisteredUser0 SoftwarePropertiesHash0 SoftwarePropertiesHashEx0 InstallDirectoryValidation0 EvidenceSource0 InstallType0 NormalizedName NormalizedPublisher NormalizedVersion FamilyName FamilyID CategoryName CategoryID SoftwareID
v_GS_INSTALLED_SOFTWARE_MS ResourceID GroupID RevisionID AgentID TimeStamp ChannelCode0 ChannelID0 MPC0 ProductCode0 SoftwareCode0                                                    
v_GS_SOFTWARE_LICENSING_PRODU ResourceID GroupID RevisionID AgentID TimeStamp ApplicationID0 Description0 EvaluationEndDate0 GracePeriodRemaining0 ID0 LicenseStatus0 MachineURL0 Name0 OfflineInstallationId0 PartialProductKey0 ProcessorURL0 ProductKeyID0 ProductKeyURL0 UseLicenseURL0                                  
v_GS_SOFTWARE_LICENSING_SERVI ResourceID GroupID RevisionID AgentID TimeStamp ClientMachineID0 IsKeyManagementServiceMachin0 KeyManagementServiceCurrentC0 KeyManagementServiceMachine0 KeyManagementServiceProductK0 PolicyCacheRefreshRequired0 RequiredClientCount0 Version0 VLActivationInterval0 VLRenewalInterval0                                          
v_GS_SOFTWARE_SHORTCUT ResourceID GroupID RevisionID AgentID TimeStamp BinFileVersion0 BinProductVersion0 Description0 FilePropertiesHash0 FilePropertiesHashEx0 FileSize0 FileVersion0 Language0 ParentName0 Product0 ProductCode0 ProductVersion0 Publisher0 ShortcutKey0 ShortcutName0 ShortcutType0 TargetExecutable0                            
v_GS_SoftwareFile ResourceID FileID ProductId FileName FileDescription FileVersion FileSize FileCount ModifiedDate CreationDate FilePath FileModifiedDate                                                
v_GS_SoftwareProduct ResourceID ProductID CompanyName ProductName ProductVersion ProductLanguage                                                            
v_GS_SoftwareUsageData No Data                                                                      
v_INSTALLED_SOFTWARE_DATA_Summary Count SoftwareCode00 SoftwarePropertiesHash00 ProductName00 Publisher00 ProductVersion00                                                            
v_LU_CAL_ProductList SoftwareCode SoftwareHash ProductCategory LicenseType LastUpdated IsDeleted                                                            
v_LU_MSProd MPC PartNumber MLSFamilyName MLSProductName VersionCode VersionSequence LanguageName ProductDistTypeName LicenseTypeName IsDeleted LastUpdated                                                  
v_LU_SoftwareCode SoftwareCode SoftwareID LastUpdated                                                                  
v_LU_SoftwareIdentity_Local_Repl NO data                                                                      
v_LU_SoftwareIdentity_Repl ID SoftwareID CommonName CommonVersion CommonPublisher CategoryID FamilyID Tag1ID Tag2ID Tag3ID SoftwareCode SoftwarePropertiesHash Name Version Publisher SourceSite LastUpdated IsDeleted rowversion creationversion LocaleID                              
v_LU_SoftwareList_Editable SoftwareID SoftwareCode SoftwarePropertiesHash CommonName CommonPublisher CommonVersion CategoryID CategoryName FamilyID FamilyName OfficialCategoryID OfficialCategoryName OfficialFamilyID OfficialFamilyName Tag1ID Tag1Name Tag2ID Tag2Name Tag3ID Tag3Name State IsDeleted                            
v_LU_SoftwareList_Local No Data                                                                      
v_LU_SoftwareSignature_Repl ID SoftwareID CommonName CommonVersion CommonPublisher CategoryID FamilyID Tag1ID Tag2ID Tag3ID SoftwareCode SoftwarePropertiesHash Name Version Publisher SourceSite LastUpdated IsDeleted rowversion creationversion LocaleID                              
v_ProductFileInfo FileID FileName FileDescription FileVersion FileSize CompanyName ProductName ProductVersion ProductLanguage                                                      
v_SoftwareFile FileID ProductID FileName FileVersion FileDescription FileSize                                                            
v_SoftwareProduct ProductID ProductName CompanyName ProductVersion ProductLanguage                                                              

Wednesday, December 22, 2010

SCCM - Roger Zander Sourceforge Tools

Roger Zander Sourceforge Tools And Utilities

SMS/SCCM Peer2Peer AddOn

SMSTorrent is a Peer2Peer AddOn for SMS2003/SCCM2007 Clients. SMS/SCCM Clients are able to share the local Package cache with other Clients using the BitTorrent filesharing protocol.

http://sourceforge.net/projects/smstorrent

SMS Site Settings tweak

SMSSettings provides a GUI to modify SMS2003 (Microsoft System Management Server 2003) Site Settings which are not accessible over the normal SMS Admin Interface.

http://sourceforge.net/projects/smssettings

Screen Lock

This Tool does lock the Screen, Mouse and Keyboard for a specified time.

http://sourceforge.net/projects/screenlock

SMS Client Center

Troubleshoot and manage SMS 2003 advanced clients

http://sourceforge.net/projects/smsclictr

SMS 2003 Offline Hardware Inventory

Capture SMS2003 Hardware Inventory on Systems without Network connectivity or Systems without an SMS Agent installed. This Tool creates a DDR (DataDiscoveryRecord) and an IDMIF File for each scanned system.

http://sourceforge.net/projects/smshwinv

Secure Autologon

Enable Windows Autologon without a cleartext password in the Registry. The password will be stored by the Local Security Authority (LSA).

http://sourceforge.net/projects/autologon

SMS2003 Object Backup

Backup and restore a definable set of SMS 2003 Objects (Packages, Programs, Advertisements, Collections...). SMSObjBackup can also be used for Site Migration (Objects can be moved to another SMS Primary Site Server)

http://sourceforge.net/projects/smsobjbackup

SMS 2003 Adv.Client local policy import

A command line tool to assign local software distribution policies to an SMS 2003 Advanced Client. The Software will be installed independent of collection memberships.

http://sourceforge.net/projects/smspolimp

SMS CloneDP

Manage the assigned Software Packages of a Microsoft SMS (SystemManagementServer) 2003 DistributionPoint

http://sourceforge.net/projects/smsclonedp

SMS 2003 Software Request Web Form

SMS 2003 Software Request Web Form with a simple Workflow (mail/web based).

http://sourceforge.net/projects/smsswreq

SMS Collection Commander

Initiate SMS 2003 advanced client actions on a collection: Ping, WakeUp, HW/SW Inventory, ReRun Advertisements, Show logged on user, Download/Refresh Policy, Repair SMS Agents, Import Clients to the Collection...

http://sourceforge.net/projects/smscollctr

SMS OSD Program Import

SMSOSDXML extends the SMS 2003 Admin Console to import OSD Program-Settings based on a XML File. SMS OSD automatically creates such XML Files (SMSDeploy.xml) for each OSD Program created in the Admin Console.

http://sourceforge.net/projects/smsosdxml

SMS Package Dependency Viewer

Show "Microsoft System Management Server 2003" Software Package dependencies in a TreeView.

http://sourceforge.net/projects/smsdepview

Wednesday, December 15, 2010

Computers Bright Mail

SELECT   distinct dbo.v_R_System.Name0 AS [Computer Name], dbo.v_Add_Remove_Programs.DisplayName0 AS [Software Name],
                      dbo.v_Add_Remove_Programs.Publisher0 AS Publisher, dbo.v_Add_Remove_Programs.Version0
FROM         dbo.v_Add_Remove_Programs INNER JOIN
                      dbo.v_R_System ON dbo.v_Add_Remove_Programs.ResourceID = dbo.v_R_System.ResourceID
WHERE     dbo.v_Add_Remove_Programs.DisplayName0 like '%Bright%'

SQL Query to find the collections Hierarchy : SCCM Colleections

SQL Query to find the collections Hierarchy

 

WITH folderHierarchy (CollectionID,[Name],ParentCollectionID,[Path])
AS
(

      SELECT
            CollectionID,
            [Name],
            ParentCollectionID,
            CAST('/'+[Name]+'/' AS VARCHAR(MAX)) AS [Path]
      FROM
            (SELECT
                  CollectionID,
                  [Name],
                  ParentCollectionID
             FROM v_Collection
                  INNER JOIN v_CollectToSubCollect
                  ON v_Collection.CollectionID = v_CollectToSubCollect.SubCollectionID) AS V_1
      WHERE
            ParentCollectionID = 'COLLROOT'

    UNION ALL
   SELECT
      child.CollectionID,
      child.Name,
      child.ParentCollectionID,
      parent.[Path]+child.[Name]+'/' AS [Path]
   FROM
      (SELECT
                  CollectionID,
                  [Name],
                  ParentCollectionID
             FROM v_Collection
                  INNER JOIN v_CollectToSubCollect
                  ON v_Collection.CollectionID = v_CollectToSubCollect.SubCollectionID) AS child
      INNER JOIN folderHierarchy AS parent
         ON parent.CollectionID = child.ParentCollectionID
)
SELECT
   fldr.[Path],
   fldr.[Name],
   fldr.CollectionID

FROM
   folderHierarchy AS fldr

 

image

Creating a Collection Query From SQL : Collections Migration from One server to other

Creating a Collection Query From SQL : Source : http://myitforum.com/cs2/blogs/cnackers/archive/2009/04/22/creating-a-collection-query-from-sql.aspx

Credit to Dave Fuller for which this information is based upon.

Creating a collection query that is based upon SQL can be done.  It’s a little complicated, but not all that bad once you’ve done it a few times.  There are many times where you have a fantastic SQL query you would love to use, but cannot figure how to get that same query in WQL.  When you create a collection query in the administrative console, it’s created in WQL and translated to SQL.  It is possible to create a SQL query and simple update a collection with that new SQL statement to process the collection membership.

Things to understand:

What you see as the “CollectionID” in the admin console is actually the “SiteID” in the SQL database. 

The CollectionID in the SQL Database, is actually the number of the collection as it was created, so if the last collection you created was your 965th collection, it’s CollectionID in SQL would actually be 965, even though the CollectionID you see in the admin console is “ABC00012”

If you have it setup so that you can see the node information, you will see the “Store Name” ID for that collection that you can use as well.

This process involves a few steps:

1) Create a target collection with a blank query, aka don’t define anything in the query statement

2) Get the collection SiteID (as it’s referred to in SQL) otherwise known as the Collection ID in reports, or the Store Name in the node information tab in the admin console

3) Run the following query in SQL query analyzer to find the CollectionID as it’s listed in SQL

Select CollectionID, SiteID from Collections where SiteID= ‘CollectionID/StoreName as seen in the console’

This will return the CollectionID you need to update the SQL statement with

4) Run the following update command to insert your SQL statement in the SQL statement query portion of the Collection.

Update Collection_Rules_SQL
set SQL = ‘YOUR SQL STATEMENT’
where CollectionID = ‘X’

5) You can run the following query to identify that your SQL statement is in fact in the correct place now

select SQL, WQL
from Collection_Rules_SQL
where CollectionID = ‘X’

This will also show you the WQL statement for any collection you want to see.

6) Update your collection to see if you have gotten the intended results

7) I would highly recommend you make sure you SQL statement works before inserting it into the collection SQL statement

IMPORTANT NOTE: If you modify the query in the admin console, you will overwrite the SQL statement you created.  You will have to re-update the SQL statement through query analyzer if you accidentally modify the query through the console

Finding the OU of a system in SMS/ConfigMgr

SELECT     dbo.v_R_System.Name0 AS [Computer Name], A.System_OU_Name0
FROM         dbo.v_RA_System_SystemOUName AS A INNER JOIN
                          (SELECT     ResourceID, MAX(LEN(System_OU_Name0)) AS len
                            FROM          dbo.v_RA_System_SystemOUName
                            GROUP BY ResourceID) AS B ON A.ResourceID = B.ResourceID AND LEN(A.System_OU_Name0) = B.len INNER JOIN
                      dbo.v_R_System ON B.ResourceID = dbo.v_R_System.ResourceID

 

 

 

 

If you want just for one computer then…

 

SELECT     dbo.v_R_System.Name0 AS [Computer Name], A.System_OU_Name0
FROM         dbo.v_RA_System_SystemOUName AS A INNER JOIN
                          (SELECT     ResourceID, MAX(LEN(System_OU_Name0)) AS len
                            FROM          dbo.v_RA_System_SystemOUName
                            GROUP BY ResourceID) AS B ON A.ResourceID = B.ResourceID AND LEN(A.System_OU_Name0) = B.len INNER JOIN
                      dbo.v_R_System ON B.ResourceID = dbo.v_R_System.ResourceID
WHERE     (dbo.v_R_System.Name0 = 'Computer Name')

Configuration Manager R3 – Prestaged Media Setup and Walkthrough

Configuration Manager R3 – Prestaged Media Setup and Walkthrough

This blog will be a walkthrough and setup guide for Configuration Manager (ConfigMgr) R3 prestaged media.  This will cover the basic steps required in order to use the new R3 feature in your environment.

First some background on prestaged media from Microsoft:

Prestaged media is an alternative way to deploy an operating system to computers. Prestaged media is a Windows Image (.wim) file that can be installed on bare metal computers by the computer manufacturer or at an enterprise staging center. This media includes a boot image and an operating system image that an administrator can predeploy to a hard disk prior.  Prestaged media reduces network traffic and the time required to provision a computer. Prestaged media works with existing task sequences to provide a complete operating system deployment.

Prestaged media is suitable for use in environments where you would want to deploy content to a computer, but do not want to or are unable to have the computer fully provisioned, for example during the computer manufacturing process or at an enterprise staging center. Computers are distributed within the enterprise with the prestaged media already loaded. When the computer starts for the first time, the computer will boot into WinPE and connect to the Configuration Manager site management point to check for available task sequences.

NOTE: When creating prestaged media, ensure that the boot image you are using has the appropriate network and mass storage drivers need for the system to complete the provisioning process.

Creating the prestaged media image

Right click on Task Sequences and select “Create Task Sequence Media”.

image

Select “Prestaged Media”.

image

Enter any information you want added to the .wim file, then specify the location and name of the file, then click Next.

image

Take note of what you put in the Created By field because whatever you put there, will end up the name of the drive as in these examples.

image

image

You can however change the field in the image properties.  If you leave it blank, then “SCCM” will be added automatically for you. 

image

image

Next, you can select whether or not to enable unknown computer support, password protect the media, as well as the certificate options.

image

Next, we need to select the boot image and operating system you want to stage to the computer.

image

Then we have our summary before the operation begins.

image

Click Close when the process is completed.

image

Importing the prestaged image into ConfigMgr

Next we need to import our newly created .wim into ConfigMgr.

image

Browse to the path where you put the prestaged wim we previously created. Then select Next.

image

Provide properties for the image, then select Next.

image

Review the summary and then select Next.

image

Click Close when the process has completed.

image

Next you will need to distribute the image out to the distribution points. Right-click on the image and select Manage Distribution Points.  Then select “Copy the package to new distribution points”. Then select Next.

image

Select the Distribution Points you want to copy the image to, then select Next.

image

Select Next.

image

Click Close when the process completes.  You can monitor distrmgr.log to review the distribution status.

image

Creating a Task Sequence to deploy the prestaged image to a computer

Right-click on Task Sequences and select New – Task Sequence.

image

Select “Create a new custom Task Sequence”.

image

Name the Task Sequence appropriately and then select Next.

image

Select Next.

image

After the process completes successfully, click Close.

image

Ensure the Task Sequence has the appropriate boot media. You can do this by selecting Properties on the Task Sequence.

image

Ensure the boot image selected is the same one as you used when creating the Prestaged Media image.

image

Next we need to edit the Task Sequence and add the appropriate steps.

First we need to add a “Format and Partition Disk” step.

image

If you are using Bitlocker, then you’ll need to create a 100mb partition, something similar to this example.

image

image

image

If you are not using bitlocker, then you can just create a single partition.

image

image

NOTE: You do not need a Bootsect.exe command as you may have seen with other documentation.  This is unnecessary as the Format and Partition disk step takes care of this for you. 

Next we need to add a “Apply Data Image” step. Select the Prestaged media image you had previously imported.

image

image

If you are not using bitlocker, then you can leave the Destination as “next available formatted partition”.

image

If you are using bitlocker, then you need to change the Destination to match your configuration.

image

Next we need to add another “Run Command Line” step to shutdown the computer and end the Task Sequence.

image

Using a command line of “wpeutil shutdown”.

image

The finalized Task Sequence should look something like this.

image

Next if you advertise this Task Sequence to the appropriate collection, then you can run this Task Sequence on a reference machine to apply the prestaged image to that machine. (Other Task Sequences have been removed from the screenshot)

image

Configuring a Task Sequence to “finish” a prestaged image

Prestaged media is designed to work with your existing Task Sequences.  We only need to make one minor change to the “Partition Disk” step in order for Prestaged media to work successfully. We need to add a Task Sequence variable step that says _SMSTSMediaType not equals OEMmedia. This tells the Task Sequence to skip this step when using Prestaged media, so that we don’t delete the content we’ve prestaged.

image

No change is required to the Apply Operating System step as the logic already exists to detect OEMMedia.

You will however, need to configure your Destination to match whether or not you are deploying bitlocker or whatever other custom setup you may have.

If you are using bitlocker, ensure this step matches the configuration you used when applying the prestaged image to the disk.

image

If you are not using bitlocker, then just use the default configuration.

image

Executing the Task Sequence on a prestaged machine

If you power on a computer that has a prestage image applied to it, it will automatically boot the WinPE image that is staged on the machine.

image

Then we can contact the ConfigMgr server and get our policies.

image

You will see it run through the first Task Sequence steps fairly quickly.

image

After a couple minutes you’ll see the system reboot.

image

Sysprep will then run, along with whatever final configurations you have in your Task Sequence and you should find yourself with a computer joined to the domain and ready to log in within a few minutes.  In my Hyper-V lab, without any additional software applications to install, the login prompt was presented in less than 10 minutes after starting the Task Sequence.

image